Archive for the ‘Banker Trojans’ Category

Banco do Brasil: a well targeted institution

September 9th, 2009

The Banker Trojan… and its deep Brazilian roots. I feel for those Banco do Brasil customers.

The latest file comes from:

www.bancodobrasii.net/Componente_Adicional

or more precisely from 203.143.180.34/webilg/images/componente_seguranca.exe

This is a program that supposedly makes your online banking more secure (or so it says).

banco1

The idea is good (especially that Virtual Keyboard) but not if the credentials are sent to the bad guys.

banco2

Our analysis tool reveals how many ‘hooks’ the file is creating.

banco3

Virus Total detection:

banco4

Jerome Segura

Malware ID: 89c100064db6a78c73a68ca86d4633bc.zip

  • Posted in Banker Trojans
  • |
  • (0) comments
  • |
  • Add your comments

Chica del mes malware

July 31st, 2009

This time it is Hispanic malware I’m going to talk about.

A porn site in Spanish language loads other pages as ‘pop under’.

rubias

Warning, offensing language.

rub

The site chicadelmes.com hosts malware:

chica

In the form of another pop under:

rubias3

chicadelmes.com/peliculas-porno-gratis.exe

Jerome Segura

Malware ID: ebdfd63d41a64006e8dda6fe4c952632.zip

  • Posted in Banker Trojans
  • |
  • (0) comments
  • |
  • Add your comments

Defaced Brazilian site pushes Brazilian malware

July 21st, 2009

It’s all very Brazilian ;-)

de1

de2

The malware file comes from a PHP page off that site. It’s supposed to be a “PowerPoint presentation” with a name like Antivir.exe… what gives?

e11

Banker Trojan:

de3

Jerome Segura

Malware ID: 037046cd3f98542f23d0a2748fb009ad.zip

  • Posted in Banker Trojans
  • |
  • (0) comments
  • |
  • Add your comments




Location

You are currently browsing the archives for the Banker Trojans category.




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (109)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.