Account
Please wait, authorizing ...

Don't have an account? Register here today.

×

Photofines with malware return (Analysis of Trojans)

As we reported yesterday in our Twitter seguinfo, in the last hours has returned to circulate the false mail that claims to come from the System of Traffic Fines (SMTA) (detransito.gov.ar) but that in reality are emails with the aim of deceiving and infecting the user.

From: Urgent
Submitted: Wednesday, 30 November 2011 23:19
Subject: Outstanding traffic fines

Date of issue: 30/11/2011 Republica Argentina

Dear Contributor,
We detect in our Traffic Fines System (SMTA) several infractions committed by your vehicle, because you did not notify yourself in the corresponding misdemeanor court we forward the Fines with your respective photos.
If you do not regularize the corresponding infractions in the next 90 days from the date of issuance of this communication your vehicle will be informed as a debtor and will become part of the Veraz, in accordance with Law n 12.549 of 1/04/2008.
The inclusion of your vehicle in the Veraz will prevent you from regularly selling your vehicle in the Argentine Republic.

We attach in this report the infractions made: PHOTO 1 - PHOTO 2 - PHOTO 3 (harmful links)
(Article 127, 2 of Automotive Tax and Articles 3 and 7 of Resolution n 629/001 ) The owner of the vehicle is notified by this means.

- Publicidad -

The information contained in this message may be privileged and confidential and protected from disclosure. If the reader of this message is not the intended recipient, or an employee or agent responsible for delivering this message to the intended recipient, you are hereby notified that any dissemination, distribution, or copy of this communication is strictly prohibited. If you have received this communication in error, please notify us immediately by replying to the message and deleting it from your computer.

@transito.gov.ar>

The links lead to the following sites, although surely in the next few hours the criminals will change them:
http://www.aviaco[DELETED].com/js/Notification.exe http://www.flowerk[DELETED].se//layout/Notification.exe http://viz[DELETED].org/en/products//vz222/Notification.exe The Notification.exe file is detected by few antivirus and is a downloader Trojan, developed in Delphi and packaged with UPX, which downloads another file from http://jupiterprosthodon[DELETED].com/images/android.exe.
Vuelven las fotomultas con malware (análisis de los troyanos)
This file is a banking Trojan also developed in Delphi and packaged with UPX, which is copied to the user's profile (C:\Documents and Settings\[USER]\Local Settings\Program Data\Unilessss\Winservices.exe) and executed. Once unpacked, the file has a size of 27 MB and in this particular attack it seeks to infect users of the Argentine banks Patagonia, Galicia, Francés, Comafi, StandardBank and Santander Río, to steal information corresponding to their bank accounts.

Once the user is infected, and enters the website of any of the banks mentioned, the malware takes control of the operating system, deletes the memory browser and replaces the bank's website with its own form, from where it requests the user's information and subsequently sends it to the criminal. In this image you can see this fake form:

Vuelven las fotomultas con malware (análisis de los troyanos) This is why the Trojan has such a large size, since it simulates the forms of all banks through images that are within the code of the same.
Vuelven las fotomultas con malware (análisis de los troyanos) Once stolen, the data is sent through a form hosted at www.houseimmobilELIMINATED].it/php/fostem.php and "encrypted" in hexadecimal.

Cristian from the Segu-Info Newsroom

See original.

No thoughts on “Photofines with malware return (Analysis of Trojans)”

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Suscribase Gratis
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS

Webinar: NxWitness el VMS rápido fácil y ultra ligero

Webinar: Por qué elegir productos con certificaciones de calidad

Por: Eduardo Cortés Coronado, Representante Comercial - SECO-LARM USA INC La importancia de utilizar productos certificados por varias normas internacionales como UL , Ul294, CE , Rosh , Noms, hacen a tus instalciones mas seguras y confiables además de ser un herramienta más de venta que garantice nuestro trabajo, conociendo qué es lo que certifica cada norma para así dormir tranquilos sabiendo que van a durar muchos años con muy bajo mantenimiento. https://www.ventasdeseguridad.com/2...

Webinar: Anviz ONE - Solución integral para pymes

Por: Rogelio Stelzer, Gerente comercial LATAM - Anviz Presentación de la nueva plataforma Anviz ONE, en donde se integran todas nuestras soluciones de control de acceso y asistencia, video seguridad, cerraduras inteligentes y otros sensores. En Anviz ONE el usuario podrá personalizar las opciones según su necesidad, de forma sencilla y desde cualquier sitio que tenga internet. https://www.ventasdeseguridad.com/2...

Webinar: Aplicaciones del IoT y digitalización en la industria logística

Se presentarán los siguientes temas: • Aplicaciones del IoT y digitalización en la industria logística. • Claves para decidir el socio en telecomunicaciones. • La última milla. • Nuevas estrategias de logística y seguimiento de activos sostenibles https://www.ventasdeseguridad.com/2...

Sesión 5: Milestone, Plataforma Abierta que Potencializa sus Instalaciones Manteniéndolas Protegidas

Genaro Sanchez, Channel Business Manager - MILESTONE https://www.ventasdeseguridad.com/2...
Load more...
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter