Home→Descriptions→Trojan-Banker.Win32.Banz.cri
| Detected | Jun 09 2010 20:29 GMT |
| Released | Jun 10 2010 02:20 GMT |
| Published | Jun 16 2010 12:17 GMT |
This malicious program is designed to steal user data that has to do with banking systems, e-money and plastic cards issued by Brazilian banks. It is a Windows PE EXE file. It is 942047 bytes in size. It is written in Delphi.
In order to ensure that the Trojan is launched automatically each time the system is restarted, the Trojan registers its executable file in the system registry:
The program also modifies the following system registry key value:
When launched, the malicious program downloads a configuration file from
http://juliana9090v.dominiotemporario.com/configex.txtThe program reads settings needed for its operation from the configuration file.
The program then monitors the active browser and, when the user visits certain pages, intercepts all the information entered into web form fields. Specifically, it monitors the following addresses:
www.bradesco.com.br https://www2.realsecureweb.com.brThe malicious program also intercepts credit card numbers entered by the user on various websites.
All the information collected is sent to the attacker’s address as well as to email addresses specified in the configuration file.
The following SMTP server is used to send mail:
smtp.tutopia.com.br
Trojan-Banker programs are designed to steal user account data relating to online banking systems, e-payment systems and plastic card systems. The data is then transmitted to the malicious user controlling the Trojan. Email, FTP, the web (including data in a request), or other methods may be used to transit the stolen data.