ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

COQUI - A BANKING KEYLOGGER


  • Please log in to reply
COQUI - A BANKING KEYLOGGER

#1

SYNV0ID
SYNV0ID
    Offline
    10
    Rep
    42
    Likes

    Dark Satire

Posts: 39
Threads: 10
Joined: Mar 22, 2016
Credits: 0

Eight years registered
#1

Initially, it was assumed that Coqui would be a "banking Trojan", but due to lack of skills, the developer settled on a conditional keylogger that is activated only when it detects a victim on certain banking sites.

 

Coqui also contains anti-analysis methods such as Process Monitor, Process Hacker (anything with Process in the first part of the name). If these processes are detected, the main keylogger is opened and overwritten to render the analysis of the keylogger useless. The keylogger is also activated only if it detects a window related to banking transactions, as soon as this window goes out of focus (for example, the user opens a calculator), the keylogger is destroyed.

 

After starting the window monitor (ProcKill), it tries to disable the keylogger (using system (task kill / F / T / IM keylogger.exe) if it does not detect that the main window (the window in which the user is currently working) is related to something - or related to banks.

 

NOTE : It compares the list of bank-related titles to the current working window, this list can be expanded by simply adding window titles:

 

vHou2xJ.png

?url=https%3A%2F%2Fi.imgur.com%2FD4YqyrY

 

The current working window above is the command line, so it tries to disable the keylogger (in this case named svart.exe).

 

?url=https%3A%2F%2Fi.imgur.com%2FWbywCZ6

 

Now the current window above is the Wells Fargo (us bank) site, so the keylogger starts up and ProcKill checks if it works before starting it up again. If it is already running, it outputs "[!] Svart is already running!"

 

?url=https%3A%2F%2Fi.imgur.com%2F0GnzO4E

 

If the user changes their current working window and the keylogger is working, we may see a “SUCCESS” message indicating that the keylogger has been disabled due to the user changing the window.

 

?url=https%3A%2F%2Fi.imgur.com%2FTzZf87I

 

As for the keylogger, it's pretty simple: it retrieves the logged data by sending a GET request to the specified IP address. This IP address must have the Apache server running and logging GET requests.

 

The dropper.c file is responsible for stealing data and schedules it to run every 12 days to steal data.

 

The project is written entirely in C and has been published quite recently.

 

Download 

 

Hidden Content
You'll be able to see the hidden content once you reply to this topic or

Please Login or Register to see this Hidden Content

.


This leak has been reported as still working 2 times this month (2 times in total).
  • 3

#2

Maluma22071
Maluma22071
    Offline
    0
    Rep
    0
    Likes

    Member

  • PipPipPip
Posts: 49
Threads: 0
Joined: Nov 03, 2020
Credits: 0
Three years registered
#2
Im interesting

  • 0

#3

XSkullerBallers
XSkullerBallers
    Offline
    0
    Rep
    -1
    Likes

    Junkie

  • PipPipPipPipPipPip
Posts: 259
Threads: 6
Joined: Nov 18, 2020
Credits: 0

Deal with caution
User has an open scam report.
Three years registered
#3

thank you for this share


  • 0

#4

enubi
enubi
    Offline
    6
    Rep
    50
    Likes

    Advanced Member

  • PipPipPipPip
Posts: 123
Threads: 18
Joined: Sep 28, 2020
Credits: 0

Deal with caution
User has an open scam report.
Three years registered
#4

see


  • 0

?url=https%3A%2F%2Fi.ibb.co%2Fyd7sSpq%2F


#5

ricksy
ricksy
    Offline
    0
    Rep
    0
    Likes

    New Member

  • PipPip
Posts: 11
Threads: 3
Joined: Nov 23, 2020
Credits: 0

Three years registered
#5

thanks for the leak


  • 0

#6

pron1gger2143
pron1gger2143
    Offline
    0
    Rep
    0
    Likes

    Veteran

  • PipPipPipPipPipPipPip
Posts: 486
Threads: 0
Joined: Nov 24, 2020
Credits: 0

Three years registered
#6

poggers, I'll drop a like if it works


  • 0

#7

bugfinder
bugfinder
    Offline
    0
    Rep
    0
    Likes

    Member

Posts: 36
Threads: 1
Joined: Jan 08, 2016
Credits: 0
Eight years registered
#7

thanks.


  • 0

#8

finnessegod
finnessegod
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 8
Threads: 1
Joined: May 17, 2021
Credits: 0
Two years registered
#8

cool this works for sure 


  • 0


 Users browsing this thread: