Threat Database Stealers Infostealer.Banprox

Infostealer.Banprox

By JubileeX in Stealers

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 368
First Seen: October 5, 2011
Last Seen: June 18, 2023
OS(es) Affected: Windows

Infostealer.Banprox is a dangerous Trojan that reroutes network traffic from certain websites, mainly banks, to an infected proxy in order to steal confidential data from the targeted computer. After an installation, Infostealer.Banprox drops some corrupt files and modifies the registry in order to download a configuration script from an external server, which has a list of the targeted websites and the infected proxy. You should uninstall Infostealer.Banprox as quickly as possible.

File System Details

Infostealer.Banprox may create the following file(s):
# File Name Detections
1. [APP_NAME]_setup_[RANDOM CHARACTERS].exe
2. [NAME].jpg.exe
3. sys32config.dll
4. Emotion[NUMBER].exe
5. FOTO-[RANDOM CHARACTERS].exe

Registry Details

Infostealer.Banprox may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\"AutoConfigURL"

Trending

Most Viewed

Loading...