Home / malwarePDF  

Trojan-Spy:W32/Banker.CPV


First posted on 01 June 2007.
Source: SecurityHome

Aliases :

Trojan-Spy:W32/Banker.CPV is also known as Trojan-Spy.Win32.Banker.cpv, Banker.cpv.

Explanation :

This is a trojan that steals bank-related credentials. It also has keylogging capabilities.

This malware drops the following files:


It also installs its component as a Browser Helper Object so that every time that Internet Explorer is running, this malware also runs.


This malware steals bank-related informations as well as passwords. It also has keylogging capability. It checks the sites that the infected user is visiting and compares it to the following bank-related strings:


It can also steal information such as:


Here is a sample log file:




It sends a POST command to the following site to send all the stolen information from the infected machine:

Last update 01 June 2007

 

TOP

Malware :

Family: