Threat Database Trojans Trojan-Banker.Win32.Banbra.atfl

Trojan-Banker.Win32.Banbra.atfl

By Sumo3000 in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 206
First Seen: September 6, 2012
Last Seen: April 30, 2020
OS(es) Affected: Windows

Trojan-Banker.Win32.Banbra.atfl is a banker Trojan that is signed with a valid digital certificate issued by a CA. It appears like a fake company data was used to get the certificate. Vybercrooks buy valid digital certificates from CAs using fake data and then start signing Trojan-Banker.Win32.Banbra.atfl with them. Valid or stolen digital certificates are used by cybercrooks to create files that can go undetected and be found as genuine. Trojan-Banker.Win32.Banbra.atfl is created to harvest a victim's confidential information such as online banking

details and passwords. Once collected, the stolen data is sent to remote cybercriminals.

SpyHunter Detects & Remove Trojan-Banker.Win32.Banbra.atfl

File System Details

Trojan-Banker.Win32.Banbra.atfl may create the following file(s):
# File Name MD5 Detections
1. upd.exe b4ed234d07993acb2230240b880a67b3 55
2. upd.exe 228118c6e84c9740b8dc16c4562ae563 32
3. upd.exe f3b2f2d4a56209ef5cd6154147878487 29
4. upd.exe 6c4a94fcc6d8d07879a54ba2fa51187d 25
5. upd.exe 96d4fbfcda7c47e38c2918cf78f1b6a4 9
6. processexplorerpe.exe 7efc0144a0220b47450473be5854d19c 8
7. processexplorerpe.exe 55c0548290a5dc43bc54a6a15ccd42fd 5
8. processexplorerpe.exe 8422eb501e6d707ade71aebdcde39c7a 3
9. upload.exe 006fc25a884f03b5f699836723c5a273 3
10. upd.exe 1b0f810c56ecb58f962e2a38bc1124be 2
11. upd.exe 7025680901bd7b0eeceb8b021d316cd5 2
12. upd.exe 0e0cfbdf4b2f00253e1c8960028e388d 2
13. upd.exe 0d47d2a7a894e6d92bad09cdfdbc376e 2
14. file.exe 11ba5cbef5f2ad873b8f67f8d7dea30f 0
15. file.exe e40bba94c1b9617c784887b62d6ac3ac 0
16. file.exe e15fd888602927f4d0508bdca2e404a9 0

Registry Details

Trojan-Banker.Win32.Banbra.atfl may create the following registry entry or registry entries:
Regexp file mask
%APPDATA%\explinance.exe
%APPDATA%\rppxml.exe
%HOMEDRIVE%\10a0699fa37928d39c\spfirewall.exe

Trending

Most Viewed

Loading...