This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It uses a convincing Graphical User Interface to make the users think that the software is legitimate.
It steals certain information from the system and/or the user. It sends the information it gathers to remote sites.
File size: 77,312 bytes
File type: EXE
Memory resident: No
Initial samples received date: 01 Feb 2011
Payload: Steals information, Downloads files
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Download Routine
This Trojan connects to the following website(s) to download and execute a malicious file:
- http://www.{BLOCKED}n.org.br/sis/arquivos/nota_fiscal.exe - detected by Trend Micro as TSPY_BANKER.BOB
Information Theft
This Trojan steals the following information:
- CPF (Brazil's version of social security number)
It sends the information it gathers to remote sites.
Other Details
This Trojan does the following:
- It displays the following GUI:

Connect with us on
| | | |