Virus: TR/Spy.Banker.vk.1 Date discovered: 31/08/2006 Type: Trojan In the wild: No Reported Infections: Low Distribution Potential: Low Damage Potential: Medium Static file: Yes File size: 448.328 Bytes MD5 checksum: f50D69bac27736ecd238039405bf3b60 VDF version: 6.31.01.124
General Method of propagation: • No own spreading routine Aliases: • Kaspersky: Trojan-Spy.Win32.Banker.aww • TrendMicro: TSPY_BANKER.EZL • VirusBuster: TrojanSpy.Banker.EKW • Bitdefender: Generic.Banker.Delf.11A1B4E9 Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Records keystrokes • Registry modification • Steals information Files It deletes the following files: • %temporary internet files% \*.gif • %temporary internet files% \*.css • %temporary internet files% \*.php • %temporary internet files% \*.xml • %temporary internet files% \*.bmp • %temporary internet files% \*.htm • %temporary internet files% \*.cab • %temporary internet files% \*.crl • %cookies% \*.txt Registry One of the following values is added in order to run the process after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run • "boby."="%SYSDIR% \Isass.scr" The following registry key is added: – [HKCU\boby] Stealing It tries to steal the following information: – Passwords typed into 'password input fields' – A logging routine is started after one of the following websites are visited: • https://www2.bancobrasil.com.br/aapf/aai/**********; https://www2.bancobrasil.com.br/aapf/extratos/**********; https://www2.bancobrasil.com.br/aapf/aai/**********; https://office.bancobrasil.com.br/servlet/**********; https://office.bancobrasil.com.br/gov/**********; https://www2.bancobrasil.com.br/aapf/aai/**********; http://www.bb.com.br/appbb/portal/bb/ds/**********; http://www.bb.com.br/appbb/portal/voce/fin/fnc/**********; http://www.bb.com.br/appbb/portal/bb/pp/**********; http://www.bb.com.br/appbb/portal/voce/mcif/**********; http://www.bb.com.br/appbb/portal/hs/crediario/**********; http://www.bb.com.br/appbb/portal/ip/srv2/**********; http://www.bb.com.br/appbb/portal/voce/ep/srv2/**********; http://www.bb.com.br/appbb/portal/voce/fin/**********; http://www.bb.com.br/appbb/portal/voce/ep/car/**********; http://www.bb.com.br/appbb/portal/voce/cons/**********; http://www.bb.com.br/appbb/portal/on/seg/**********; http://www.bb.com.br/appbb/portal/on/prv/**********; http://www.bb.com.br/appbb/portal/on/cap/**********; http://www.bb.com.br/appbb/portal/bb/simp/**********; http://www.bb.com.br/appbb/portal/voce/ep/srv2/**********; http://www.bb.com.br/appbb/portal/gov/**********; http://www.bb.com.br/appbb/portal/fz2/**********; http://www.bb.com.br/appbb/portal/********** – It captures: • Login information –Form windows are displayed as shown in the pictures below: File details Programming language: The malware program was written in Delphi. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • PE Compact
Description inserted by Monica Ghitun on Thursday, August 31, 2006 Description updated by Monica Ghitun on Friday, September 15, 2006
Back
.
.
.
.