Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Drop down and tweak it!

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » May 2012 » Banking Malware surfaces in South America

Banking Malware surfaces in South America


Contributed by: Email on 05/22/2012 02:33 PM [ comments Comments ]


Malware that masquerades like the Google Chrome installer is actually stealing data and stripping software used to protect online banking. It presently is targeting users in Peru and Brazil.

Trend Micro researchers report in a blog post that they have discovered a malicious file called ChromeSetup.exe hosted in domains such as Facebook, MSN, Globo.com, Terra.com and Google. Most appear tied to Brazil since .br or br. appears in the URLs.

This particularly nasty bit of malware, once downloaded, relays an infected machine's IP address and OS to a C&C server. If a user tries to access a legit bank site, the Trojan TSPY_Banker.EUIQ intercepts the page request and displays a "Loading system security" dialog box. What it really is doing is redirecting the user to a fake banking site.

To aid in a data heist, another component of the Banker malware, as it's called, uninstalls software called GbPlugin, which is designed to protect Brazilian bank customers during online banking. "It does this through the aid of gb_catchme.exe – a legitimate tool from GMER called Catchme, which was originally intended to uninstall malicious software. The bad guys, in this case, are using the tool for their malicious agendas," according to threats analyst Brian Cayanan.

"It looks like this malware is still under development and we may still see improvements in future variants. Roland (de la Paz) also mentions that he came across a likely related C&C that surface last October 2011, which indicates that the perpetrators behind this threat aren’t new in the scene," wrote Cayanan, who also worked with a third researcher, Roddell Santos, on the Banker malware investigation.

"While we may have a complete picture of this particular attack, the one missing piece now is the same thing that made us notice this malware from the millions of data that we have from our threat intelligence – how it is able to redirect user accesses from normal websites like Facebook or Google to its malicious IP to download malware," Cayanan wrote. "We will continue our investigation related to this incident and will update this blog with our findings.

"Online threats will continue to evolve and find ways into systems. As such, traditional web blocking technologies may fail to block access to malicious URLs, especially when these are masked with the use of legitimate domains like those of Facebook or Google."

The legit download for Chrome is Here.






« Careless Webmasters as WordPress Hosting Providers for Spammers · Banking Malware surfaces in South America · Daily Reviews Summary 05/23/12 (26 Reviews) @ NT Compatible »




Comments
comments powered by Disqus

MajorGeeks.Com » News » May 2012 » Banking Malware surfaces in South America

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition