
The Dell SonicWALL Threats Research team came across a new Banker Trojan targeting a Brazilian Government Department of Treasury owned electronic invoice website, attempting to steal sensitive user information. The Trojan arrives as a Windows Control Panel Item file and is a UPX packed DLL written in Delphi. It pretends to be a proof of NF-e invoice and executes if the user attempts to open it.
Infection Cycle:
Upon execution, the Trojan checks for the presence of VMWare environment and terminates if detected.
It connects to a remote server in Brazil grupomasterplan.com.br to download multiple malicious executables in an encrypted format. The downloaded files are disguised as JPEG images as seen below:

The following files are dropped on the infected system:
The Trojan installs multiple hooks and launches the Brazilian Government Department of Treasury owned website in Internet Explorer as seen below:
Site description in english (Courtesy: Google Translation):
If the user enters the Access-Key and Access-Code information, even though this is the official government website the access information will be compromised because of the hooks installed:
SonicWALL Gateway AntiVirus provides protection against this threat via the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News