Home / malwarePDF  

TrojanSpy:Win32/Banker.APL


First posted on 05 January 2017.
Source: Microsoft

Aliases :

There are no other names known for TrojanSpy:Win32/Banker.APL.

Explanation :

Installation
This threat creates files on your PC, including:

  • \adekaophahu.lnk


Payload

Collects your sensitive information

This threat can collect your sensitive information without your consent, including:
  • The keys you press
  • The applications you open
  • Your web browsing history
  • Your credit card information
  • Your user names and passwords


It can also imitate a legitimate website to lure you into revealing sensitive information.

Additional information

Creates a mutex

This threat can create one or more mutexes on your PC, including:
  • {C20CD437-BA6D-4ebb-B190-70B43DE3B0F3}
  • ABVCGDF[VERS49.3]


It might use these mutexes as infection markers to prevent more than one copy itself running on your PC.

This malware description was published using automated analysis of file SHA1 1fc209c2265c7144886063f7ba3c8241c44bf163.

Last update 05 January 2017

 

TOP