A week ago our colleagues at IBM published a blog post about a new stealer named "CoreBot". The post points out that CoreBot has a modular plugin system, is capable of stealing private information including certificates and has a DGA (domain generation algorithm) implemented. We got our hands to 4 different samples and analyzed them. [...]