Threat Database Trojans TSPY_BANKER.ZIP

TSPY_BANKER.ZIP

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 2
First Seen: June 3, 2013
Last Seen: January 10, 2022
OS(es) Affected: Windows

TSPY_BANKER.ZIP is a Trojan that is distributed via hacked Brazil government websites. The eleven distinct harmful applications are dispersed via these websites, with the program files called 'update,' 'upgrade,' 'Adobe,' and 'FlashPlayer,' alternatively their distinct combinations. Apart from these file names, there are separate domain names for the applications too to which they are linked up to drop other security threats. The file names further connect to a number of C&C (command-and-control) systems. The harmful applications are identified as TROJ_BANDROP.ZIP and all of them operate the same way. TROJ_BANDROP.ZIP install dual files on the target computer user's PC, particularly an .exe file detected as TSPY_BANKER.ZIP together with one alleged image program (.gif file) found as JAVA_BANKER.ZIP within the attacked computer's short-lived folder. The malevolent .exe file makes alterations to the Windows Registry of the targeted computer running Windows, so the security tool's power is decreased, followed with finally installing the .gif program file.

File System Details

TSPY_BANKER.ZIP may create the following file(s):
# File Name Detections
1. winworker.exe
2. svchost64.exe
3. svcnost.exe
4. AdvService.exe
5. svchast.exe
6. InstallAssist.exe
7. Protector-mowh.exe
8. Explorer.exe
9. xdbkdu.dll
10. svchost.exe
11. nMNtfaARw2l97e30p5ev.exe
12. players.exe
13. WINL0GON.exe
14. wgsdgsdgdsgsd.dll
15. n.

Trending

Most Viewed

Loading...