Threat Description

Banker.ARK

Details

Aliases: Banker.ARK, TSPY_BANKER.BVE, TR/Spy.Banker.abn.2, TrojanSpy:Win32/Banker!06E9
Category: Malware
Type: Trojan-Spy
Platform: W32

Summary



Banker is a family of spying trojans that attempt to steal information that is required to access the websites of certain online banks and online payment systems. Banker trojans usually steal logins, passwords, PINs, check words, and other info related to logging onto financial websites. This variant of Banker attempts to attack some Online Brazilian Bank Account Holders.



Removal



Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details



This memory resident Trojan-Spy Malware drops a copy of itself in the Windows System folder with filename SYSTEM32.EXE. Moreover, it drops several copies of itself in the following fixed locations and filename depending the operating system:

For Windows 2000 and XP:

  • C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\system32.exe
  • C:\Documents and Settings\All Users\start menu\programs\startup\system32.exe

For Windows 98:

  • C:\Windows\Menu Iniciar\Iniciar\system32.exe

It then adds the following registry entry as its auto start technique:

  • [HKEY_LOCAL_MACHINE\SOFTWARE\ Microsoft\Windows\CurrentVersion\Run]"system32" = "%sysdir%\system32.exe"

*NOTE %SysDir% is Windows System folder.

Banker steals logon credentials, that are related to some Brazilian Banks, by logging keystrokes when the Internet Browser title bar contains any of the following strings:

  • CAIXA
  • caixa
  • check
  • http://www.spc.com.br/consulta.php
  • pay.checkcheck.com.br
  • PayPal - Welcome
  • sant
  • santandernet.com.br
  • spc.Internet Banking
  • unib
  • Unibanco.com

Banker uses the following account details to send the stolen information to yes@baby.com:

  • Smtp server : smtp.sao.[REMOVED][removed].com.br
  • E-mail acccount : bandidodimas@[REMOVED].com.br
  • Password : f1l1pp3

Information stolen includes the following details:

  • Bank Name
  • Computer Name
  • IE-Version
  • IP Address
  • MAC Address
  • Password
  • System Date
  • System Time
  • Username


Detection


F-Secure Anti-Virus detects this malware with the following updates:
Detection Type: PC
Database: 2006-07-26_01




SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More