Threat Database Stealers Infostealer.Banprox

Infostealer.Banprox

By JubileeX in Stealers

Threat Scorecard

Popularity Rank: 19,690
Threat Level: 90 % (High)
Infected Computers: 379
First Seen: October 5, 2011
Last Seen: October 1, 2025
OS(es) Affected: Windows

Infostealer.Banprox is a dangerous Trojan that reroutes network traffic from certain websites, mainly banks, to an infected proxy in order to steal confidential data from the targeted computer. After an installation, Infostealer.Banprox drops some corrupt files and modifies the registry in order to download a configuration script from an external server, which has a list of the targeted websites and the infected proxy. You should uninstall Infostealer.Banprox as quickly as possible.

File System Details

Infostealer.Banprox may create the following file(s):
# File Name Detections
1. [APP_NAME]_setup_[RANDOM CHARACTERS].exe
2. [NAME].jpg.exe
3. sys32config.dll
4. Emotion[NUMBER].exe
5. FOTO-[RANDOM CHARACTERS].exe

Registry Details

Infostealer.Banprox may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"AutoConfigURL"

Analysis Report

General information

Family Name: Trojan.GrwtpStealer
Signature status: No Signature

Known Samples

MD5: 31185c66d19b18a809bc6750547f3776
SHA1: f5df90ecf1ac2b5ea5f8d774fe4de87f1da4308d
SHA256: 9FFB19E556FB5393CD63F676EF2E5650BA41C916945E6E5C3C59ACDE948DA627
File Size: 3.46 MB, 3457024 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.2.878.0
Comments Bootstrap Loader for ePower
Company Name Infineon Technologies
File Description BSL-Tool
File Version 1.2.878
Internal Name BSL_Tool.exe
Legal Copyright Copyright © Infineon Technologies 2013
Original Filename BSL_Tool.exe
Product Name BSL-Tool
Product Version 1.2.878

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 614
Potentially Malicious Blocks: 2
Whitelisted Blocks: 146
Unknown Blocks: 466

Visual Map

0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 ? ? 0 0 ? 0 ? ? ? ? ? 0 0 ? ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? x 0 ? ? 0 ? ? 0 ? 0 ? ? ? 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 ? 0 ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? 0 0 ? ? ? ? 0 0 ? 0 ? 0 0 0 0 ? x ? ? 0 ? 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
  • OutputDebugString

Trending

Most Viewed

Loading...