Skip to main content

Banker.ARK

Classification

Category:

Malware

Type:

Trojan-spy

Aliases:

  • Banker.ARK
  • TSPY_BANKER.BVE
  • TR/Spy.Banker.abn.2
  • TrojanSpy:Win32/Banker!06E9

Summary

Banker is a family of spying trojans that attempt to steal information that is required to access the websites of certain online banks and online payment systems. Banker trojans usually steal logins, passwords, PINs, check words, and other info related to logging onto financial websites. This variant of Banker attempts to attack some Online Brazilian Bank Account Holders.

Removal

Technical Details

This memory resident Trojan-Spy Malware drops a copy of itself in the Windows System folder with filename SYSTEM32.EXE. Moreover, it drops several copies of itself in the following fixed locations and filename depending the operating system:

For Windows 2000 and XP:

  • C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\system32.exe
  • C:\Documents and Settings\All Users\start menu\programs\startup\system32.exe

For Windows 98:

  • C:\Windows\Menu Iniciar\Iniciar\system32.exe

It then adds the following registry entry as its auto start technique:

  • [HKEY_LOCAL_MACHINE\SOFTWARE\ Microsoft\Windows\CurrentVersion\Run]"system32" = "%sysdir%\system32.exe"

*NOTE %SysDir% is Windows System folder.

Banker steals logon credentials, that are related to some Brazilian Banks, by logging keystrokes when the Internet Browser title bar contains any of the following strings:

  • CAIXA
  • caixa
  • check
  • https://www.spc.com.br/consulta.php
  • pay.checkcheck.com.br
  • PayPal - Welcome
  • sant
  • santandernet.com.br
  • spc.Internet Banking
  • unib
  • Unibanco.com

Banker uses the following account details to send the stolen information to yes@baby.com:

  • Smtp server : smtp.sao.[REMOVED][removed].com.br
  • email acccount : bandidodimas@[REMOVED].com.br
  • Password : f1l1pp3

Information stolen includes the following details:

  • Bank Name
  • Computer Name
  • IE-Version
  • IP Address
  • MAC Address
  • Password
  • System Date
  • System Time
  • Username

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.