Home / malwarePDF  

Trojan-Spy:W32/Banker.GMH


First posted on 07 December 2007.
Source: SecurityHome

Aliases :

Trojan-Spy:W32/Banker.GMH is also known as Trojan-Spy.Win32.Banker.gmh.

Explanation :

This Trojan steals banking information and has the capability to update itself.

Upon execution, this malware drops the following file:


Note: %windir% is by default, C:Windows.

It checks to see if iexplore.exe is running. If it isn't, it will run IE in the background and will inject the dropped DLL file as a Browser Helper Object.

It creates these auto-start registry keys:


It downloads the following file:


It saves the file as %temp%aol92.exe and executes it.
Note: %temp% is normally C:Documents and Settings\Local SettingsTemp.

This malware monitors the URLs visited by the user. If the visited URL has the following banking-related strings, it will start collecting information:


Stolen information will then be sent to the following link using http POST command:

Last update 07 December 2007

 

TOP

Malware :

Family: