
The Sonicwall UTM research team received reports of a new Banking Trojan in the wild. Banking Trojans steal logon credentials and target specific banks. This Banking Trojan targets users of ITAU bank based in Brazil. The Trojan steals bank logon credentials by redirecting traffic through a remote webserver.
The Trojan adds the following files to the filesystem:
h4714log.txt contains the following data:
tipo=infnomepc={USERNAME}mac=08-00-27-{removed}The Trojan adds the following key to the Windows registry to enable startup after reboot:
Upon infection the Trojan replaces itself with {run location}abcde.txt and then runs mbservice.exe. mbservice.exe runs in the background inspecting window title strings. It contains code that looks for a specific window title string "BANCO ITAU - FEITO PARA VOCE" running in Internet Explorer.

The Trojan targets users of ITAU bank. Below is a screenshot of their main page:

The Trojan redirects all traffic through a remote webserver and was observed leaking the following data from h4714log.txt:

The Trojan also leaks data typed into the "Agency" and "Account" boxes and passwords using the virtual keyboard:


SonicWALL Gateway AntiVirus provides protection against this threat via the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News