English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Trojan-Banker.Win32.Banz.cri

Detected Jun 09 2010 20:29 GMT
Released Jun 10 2010 02:20 GMT
Published Jun 16 2010 12:17 GMT

Manual description Auto description
This description was created by experts at Kaspersky Lab. It contains the most accurate information available about this program.

Technical Details
Payload

Technical Details

This malicious program is designed to steal user data that has to do with banking systems, e-money and plastic cards issued by Brazilian banks. It is a Windows PE EXE file. It is 942047 bytes in size. It is written in Delphi.

Installation

In order to ensure that the Trojan is launched automatically each time the system is restarted, the Trojan registers its executable file in the system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"wscntfx" = "%filepath%"
Where "%filepath%" is the full path to the malicious file.

The program also modifies the following system registry key value:

[HKÑU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User
Agent\Post Platform]
" Embedded Web Browser from: http://bsalsa.com/" = ""


Payload

When launched, the malicious program downloads a configuration file from

http://juliana9090v.dominiotemporario.com/configex.txt
The program reads settings needed for its operation from the configuration file.

The program then monitors the active browser and, when the user visits certain pages, intercepts all the information entered into web form fields. Specifically, it monitors the following addresses:

www.bradesco.com.br
https://www2.realsecureweb.com.br
The malicious program also intercepts credit card numbers entered by the user on various websites.

All the information collected is sent to the attacker’s address as well as to email addresses specified in the configuration file.

The following SMTP server is used to send mail:

smtp.tutopia.com.br


Bookmark and Share
Share
Trojan-Banker

Trojan-Banker programs are designed to steal user account data relating to online banking systems, e-payment systems and plastic card systems. The data is then transmitted to the malicious user controlling the Trojan. Email, FTP, the web (including data in a request), or other methods may be used to transit the stolen data.