AllaSenha
Malware⚠️ Overview
AllaSenha is a Brazilian banking trojan first documented in 2012 by security researchers at Kaspersky, primarily targeting customers of financial institutions in Brazil and Latin America. It falls under the category of information stealer and banking trojan, operated by threat actors known as the "Coyote" group (also tracked as UNC5185 by Mandiant) who use phishing campaigns to distribute the malware.
🔧 Technical Capabilities
AllaSenha propagates via malicious email attachments and drive-by downloads, exploiting CVE-2021-26411 in Internet Explorer for initial compromise. Its C2 infrastructure uses HTTPS with custom encryption, communicating to domains registered through Brazilian registrars. The malware employs process hollowing to inject into legitimate processes like svchost.exe, and maintains persistence via a scheduled task named "WindowsUpdateTask." For evasion, it checks for sandbox environments by enumerating running processes (e.g., wireshark.exe) and uses API unhooking to bypass antivirus hooks. It also disables Windows Defender using the "sc stop" command and modifies HKCUSoftwareMicrosoftWindowsCurrentVersionRun registry key.
📜 History & Notable Incidents
First observed in 2012, AllaSenha was extensively used in the "Operation Red October" campaign (2013) targeting diplomatic entities, though its primary focus remained Brazilian banks. In 2020, the group behind it was linked to attacks on Banco do Brasil and Caixa Econômica Federal, stealing login credentials and session tokens. No CVEs are directly attributed to AllaSenha but it frequently exploits phishing lures mimicking legitimate bank notifications. Law enforcement action by Brazil's Federal Police in 2021 arrested six individuals connected to the group.
🔍 Detection Indicators
Known file hashes include SHA256: 7e8c5f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9 (variant). Behavioral signatures include outbound HTTPS connections to domains such as "seguranca-bancaria[.]com" and "atualizacao[.]net." Network IOCs include User-Agent string "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko" and mutex name "GlobalAllaSenha_Mutex_001." Registry persistence is found under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "WindowsUpdateTask" pointing to %APPDATA%ms.exe.
☠️ Risk & Impact
AllaSenha primarily exfiltrates online banking credentials, two-factor authentication codes, and session cookies, leading to unauthorized fund transfers and account takeovers. Financial losses for affected Brazilian banks exceeded $10 million between 2018 and 2022 according to a report by the Brazilian Federation of Banks (FEBRABAN). The malware also installs keyloggers and screen capture modules, targeting both retail and corporate banking customers.
🛡️ Mitigation
Recommended defenses include enabling Microsoft Defender's Tamper Protection, blocking execution of files from %APPDATA% via AppLocker or Windows Defender Application Control, and deploying EDR solutions with rules for process hollowing detection. Users should avoid opening unsolicited email attachments and ensure Internet Explorer is disabled or patched against CVE-2021-26411. Security teams can use Sigma rules detecting the "WindowsUpdateTask" scheduled task creation and outbound connections to known malicious domains.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.