Banload.BBX downloads other members of the Banker and Banload family from the internet.
It arrives on the system with the filename HUMORTADELA.exe.
Upon execution, it connects to the following sites:
And saves these files to the following hard-coded paths in the user's system:
The said files are already detected as Trojan-Spy.Win32.Bancos.uy and Trojan-Downloader.Win32.Banload.bby respectively.
As a stealth mechanism, it displays the following fake error message to fool the users into believeing that the malware did not run on their system.