English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Trojan-Banker.Win32.Banker.ra

Detected May 11 2005 12:36 GMT
Released May 11 2005 14:32 GMT

This is a description which has been automatically generated following analysis of this program on a test machine. This description may contain incomplete or inaccurate information.

Summary


Technical details

File size of 676352 bytes.


Installation

Makes copies of itself with the following names once launched:

  • Windows system directory (usually, C:\Windows\System32) %System%\lsass.scr

Ensures Using the system registry, system services or special system files, the program can launch itself or launch the creation of its files every time the Windows OS is subsequently booted autorun of the following installed files:

by adding values to autorun keys in the system registry:

[ System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ] "<­file of source program ­>" = " Windows system directory (usually, C:\Windows\System32) %System%\lsass.scr"


Malicious activity

Steals confidential user information from A malicious program designed to steal user information related to banking and electronic payment systems and bank cards. The information is sent to a cybercriminal via email, ftp, the web or other methods.
Read more details here: http://www.viruslist.com/en/analysis?pubid=204792037
the following banks, financial institutions, payment systems
:

  • Bradesco group
  • Caixa
  • Banco Santander group
  • ABN AMRO banking group
  • Unibanco
  • Banco do Brasil

Connects to to the following Internet addresses:

  • ***.221.4.5:28160


Other activities

Searches for the following windows:
TitleIexplorer


Bookmark and Share
Share
Trojan-Banker

Trojan-Banker programs are designed to steal user account data relating to online banking systems, e-payment systems and plastic card systems. The data is then transmitted to the malicious user controlling the Trojan. Email, FTP, the web (including data in a request), or other methods may be used to transit the stolen data.


Other versions

Aliases

Trojan-Banker.Win32.Banker.ra (Kaspersky Lab) is also known as:

  • Trojan-Spy.Win32.Banker.ra (Kaspersky Lab)
  • Mal/Behav-053 (Sophos)
  • Trojan.Bancos-1040 (ClamAV)
  • Heuristic.WinPE-Statistical (Panda)
  • W32/Banker.CPG (FPROT)
  • TrojanSpy:Win32/Banker (MS(OneCare))
  • Trojan.PWS.Banker.based (DrWeb)
  • Generic.Banker.Delf.A5E3FE70 (BitDef7)
  • Win32:Banker-AKX (AVAST)
  • Trojan-Spy.Win32.Bancos.JU (Ikarus)
  • PSW.Banker.B (AVG)
  • TR/Spy.Banker.Gen (AVIRA)
  • Infostealer.Bancos.gen (NAV)
  • PWS-Banker.gen.b (NAI)
  • Possible_Bnkr-1 (PCCIL)
  • Trojan.Spy.Banker.tx (Rising)