Home / malwarePDF  

TrojanSpy:Win32/Banker.AMV


First posted on 06 August 2014.
Source: Microsoft

Aliases :

There are no other names known for TrojanSpy:Win32/Banker.AMV.

Explanation :

Threat behavior

Installation

TrojanSpy:Win32/Banker.AMV creates the following files on your PC:

  • c:\documents and settings\administrator\local settings\temp\icone.cur


Payload

Contacts remote hosts

TrojanSpy:Win32/Banker.AMV can contact the following remote hosts:

  • 86.124.95.159 using port 80
  • mirrorproject1.ddns.com.br using port 7751

Commonly, malware contacts a remote host to:
  • Confirm Internet connectivity
  • Report a new infection to its author
  • Receive configuration or other data
  • Download and run files (including updates and other malware)
  • Receive instruction from a remote hacker
  • Upload information taken from your PC
This malware description was produced and published using automated analysis of file SHA1 fbb37ea9ef1b85bf7fc92056956d3242e17e06ed.Symptoms

System changes

The following could indicate that you have this threat on your PC:

  • You have these files:

    c:\documents and settings\administrator\local settings\temp\icone.cur

Last update 06 August 2014

 

TOP