The output of command, there is a service (Spiservice) which running on port 8043. The SpiService.exe is associated with XFS, the Extension for Financial Services DLL library (MSXFS.dll) that is specifically used by ATMs. The library provides a special API for the communication with the ATM’s PIN pad and the cash dispenser. The ATM tested by the expert is running Aglis XFS for Opteva version 184.108.40.206. Attempting to connect to the service via a web browser, experts noticed it calls many libraries, including a library called VDMXFS.dll.
Remote code execution
Opteva version 4.x
The attack can be mitigated by utilizing a properly configured, terminal-based firewall.