Infection Channel: Downloaded from the Internet, Dropped by other malware
This Trojan may be downloaded by other malware/grayware/spyware from remote sites.
File size: 306,598 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 26 Apr 2012
Payload: Connects to URLs/IPs
Arrival Details
This Trojan may be downloaded by other malware/grayware/spyware from remote sites.
It may be downloaded from the following remote sites:
- {BLOCKED}.{BLOCKED}.196.130
Autostart Technique
This Trojan enables its automatic execution at every system startup by dropping the following copies of itself into the Windows Common Startup folder:
Other System Modifications
This Trojan adds the following registry entries as part of its installation routine:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
GlobalUserOffline = "0"
Information Theft
This Trojan accesses the following site to download its configuration file:
- http://{BLOCKED}.{BLOCKED}.196.130/bfs/update.dat
Its configuration file contains the following information:
- Title strings of target banks
- IP address or website address to where this spyware redirects the user
NOTES:
This spyware registers infection to its C&C server by issuing the following HTTP request:
http://{BLOCKED}.{BLOCKED}.228.178/painel/?add=1&inf=Browser Executando {Operating System}
It monitors the browser activities of the affected system, specifically the address bar or title bar. It redirects the browser to a phishing site whenever a user visits banking sites whose strings in the address/title bar matches the ones declared in this malware's configuration file.
Note that the content of the configuration file may vary. As of this writing, it contains the following bank-related strings and respective redirect IP addresses:
String: www.sicredi.com.br
Redirect site: http://{BLOCKED}.{BLOCKED}.243.130
String: Banco Ita - Feito Para Voc
Redirect site: http://{BLOCKED}.{BLOCKED}.243.131
String: Caixa Econ - mica Federal
Redirect site: http://{BLOCKED}.{BLOCKED}.243.132
String: Banco Santander Brasil | Pessoa Jur dica | Atendimento empresarial, empresas
Redirect site: http://{BLOCKED}.{BLOCKED}.243.133
Connect with us on
| | | |