Home / malwarePDF  

TrojanSpy:Win32/Banker.AMU


First posted on 06 August 2014.
Source: Microsoft

Aliases :

There are no other names known for TrojanSpy:Win32/Banker.AMU.

Explanation :

Threat behavior

Installation

TrojanSpy:Win32/Banker.AMU creates the following files on your PC:

  • c:\documents and settings\administrator\local settings\temp\icone.cur


Payload

Contacts remote hosts
TrojanSpy:Win32/Banker.AMU can contact the following remote hosts:

  • tudopranos1995.ddns.net using port 7751
  • tudopranossss.com using port 80

Commonly, malware contacts a remote host to:
  • Confirm Internet connectivity
  • Report a new infection to its author
  • Receive configuration or other data
  • Download and run files (including updates and other malware)
  • Receive instruction from a remote hacker
  • Upload information taken from your PC
This malware description was produced and published using automated analysis of file SHA1 9156893b37ede5b699dcb44ba0d9335099cde2bc.Symptoms

System changes

The following could indicate that you have this threat on your PC:

  • You have these files:

    c:\documents and settings\administrator\local settings\temp\icone.cur

Last update 06 August 2014

 

TOP