---
title: "Photofines with malware return (Analysis of Trojans) - Ventas de Seguridad"
description: "The latest news for Latin American integrators, contractors and wholesalers in electronic security."
url: "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15028-photofines-with-malware-return-analysis-of-trojans.html"
date: "2026-07-23T14:01:41+00:00"
language: "en-GB"
---

#  [ Photofines with malware return (Analysis of Trojans)](https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15028-photofines-with-malware-return-analysis-of-trojans.html "Photofines with malware return (Analysis of Trojans)")

      Details     01 December 2011           As we reported yesterday in our Twitter seguinfo, in the last hours has returned to circulate the false mail that claims to come from the System of Traffic Fines (SMTA) (detransito.gov.ar) but that in reality are emails with the aim of deceiving and infecting the user. From: Urgent Sent: Wednesday, November 30, 2011 23:19 Subject: Pending traffic fines Date of issue: 30/11/2011 Argentine Republic Dear taxpayer: We detect in our System of Fines of... As we reported yesterday in our Twitter seguinfo, in the last hours has returned to circulate the false mail that claims to come from the System of Traffic Fines (SMTA) (detransito.gov.ar) but that in reality are emails with the aim of deceiving and infecting the user.
> From: Urgent
> Submitted: Wednesday, 30 November 2011 23:19
> Subject: Outstanding traffic fines
>
> Date of issue: 30/11/2011 Republica Argentina
>
> Dear Contributor,
> We detect in our Traffic Fines System (SMTA) several infractions committed by your vehicle, because you did not notify yourself in the corresponding misdemeanor court we forward the Fines with your respective photos.
> If you do not regularize the corresponding infractions in the next 90 days from the date of issuance of this communication your vehicle will be informed as a debtor and will become part of the Veraz, in accordance with Law n 12.549 of 1/04/2008.
> The inclusion of your vehicle in the Veraz will prevent you from regularly selling your vehicle in the Argentine Republic.
>
> We attach in this report the infractions made: PHOTO 1 - PHOTO 2 - PHOTO 3 (harmful links)
> (Article 127, 2 of Automotive Tax and Articles 3 and 7 of Resolution n 629/001 ) The owner of the vehicle is notified by this means.
>
> - Publicidad -
>
>
>
>
>
>
>
> The information contained in this message may be privileged and confidential and protected from disclosure. If the reader of this message is not the intended recipient, or an employee or agent responsible for delivering this message to the intended recipient, you are hereby notified that any dissemination, distribution, or copy of this communication is strictly prohibited. If you have received this communication in error, please notify us immediately by replying to the message and deleting it from your computer.
>
> @transito.gov.ar&gt;

The links lead to the following sites, although surely in the next few hours the criminals will change them:
*http://www.aviaco\[DELETED\].com/js/Notification.exe* *http://www.flowerk\[DELETED\].se//layout/Notification.exe* *http://viz\[DELETED\].org/en/products//vz222/Notification.exe* The Notification.exe file is detected by few antivirus and is a *downloader* Trojan, developed in Delphi and packaged with UPX, which downloads another file from *http://jupiterprosthodon\[DELETED\].com/images/android.exe*.
![Vuelven las fotomultas con malware (análisis de los troyanos)](https://www.ventasdeseguridad.com/media/feedgator/images/9_bancos.png)
This file is a banking Trojan also developed in Delphi and packaged with UPX, which is copied to the user's profile (*C:\\Documents and Settings\\\[USER\]\\Local Settings\\Program Data\\Unilessss\\Winservices.exe*) and executed. Once unpacked, the file has a size of 27 MB and in this particular attack it seeks to infect users of the Argentine banks Patagonia, Galicia, Francés, Comafi, StandardBank and Santander Río, to steal information corresponding to their bank accounts.Once the user is infected, and enters the website of any of the banks mentioned, the malware takes control of the operating system, deletes the memory browser and replaces the bank's website with its own form, from where it requests the user's information and subsequently sends it to the criminal. In this image you can see this fake form:

![Vuelven las fotomultas con malware (análisis de los troyanos)](https://www.ventasdeseguridad.com/media/feedgator/images/9_bancos2.png) This is why the Trojan has such a large size, since it simulates the forms of all banks through images that are within the code of the same.
![Vuelven las fotomultas con malware (análisis de los troyanos)](https://www.ventasdeseguridad.com/media/feedgator/images/9_bancos3.png) Once stolen, the data is sent through a form hosted at *www.houseimmobilELIMINATED\].it/php/fostem.php* and "encrypted" in hexadecimal.Cristian from the Segu-Info Newsroom

**[See original.](http://feedproxy.google.com/~r/NoticiasSeguridadInformatica/~3/ufJIK9O2fWw/vuelven-las-fotomultas-con-malware-con.html "Vuelven las fotomultas con malware (análisis de lo")**

      ###  No comments

• If you're already registered, please log in first. Your email will not be published.

###  Comments are closed

 The comments for this content are closed.

## Schema

```json
{ "@context": "https://schema.org", "@type": "BreadcrumbList", "itemListElement": [ { "@type": "ListItem", "position": 1, "name": "Inicio", "item": "https://www.ventasdeseguridad.com/en" }, { "@type": "ListItem", "position": 2, "name": "Latest News", "item": "https://www.ventasdeseguridad.com/en/news/latest-news.html" }, { "@type": "ListItem", "position": 3, "name": "Cyber Security", "item": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security.html" }, { "@type": "ListItem", "position": 4, "name": "Photofines with malware return (Analysis of Trojans)", "item": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15028-photofines-with-malware-return-analysis-of-trojans.html" } ] }
```

```json
{ "@context": "https://schema.org", "@type": "VideoObject", "name": "Photofines with malware return (Analysis of Trojans)", "description": "As we reported yesterday in our Twitter seguinfo, in the last hours has returned to circulate the false mail that claims to come from the System of Traffic Fines (SMTA) (detransito.gov.ar) but that in reality are emails with the aim of deceiving and infecting the user. From: Urgent Sent: Wednesday, November 30, 2011 23:19 Subject: Pending traffic fines Date of issue: 30/11/2011 Argentine Republic Dear taxpayer: We detect in our System of Fines of...", "thumbnailUrl": "https://www.ventasdeseguridad.com/", "uploadDate": "2011-12-01T09:36:36-05:00", "contentUrl": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15028-photofines-with-malware-return-analysis-of-trojans.html" }
```

```json
{ "@context": "https://schema.org", "@type": "NewsArticle", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15028-photofines-with-malware-return-analysis-of-trojans.html" }, "headline": "Photofines with malware return (Analysis of Trojans) - Ventas de Seguridad", "description": "The latest news for Latin American integrators, contractors and wholesalers in electronic security.", "image": { "@type": "ImageObject", "url": "https://www.ventasdeseguridad.com/" }, "publisher": { "@type": "Organization", "name": "Ventas de Seguridad", "logo": { "@type": "ImageObject", "url": "https://www.ventasdeseguridad.com/images/metatags/16x9/vds.png" } }, "author": { "@type": "Person", "name": "Max Jaramillo", "url": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15028-photofines-with-malware-return-analysis-of-trojans.html" }, "datePublished": "2011-12-01T09:36:36-05:00", "dateCreated": "2011-12-01T09:26:00-05:00", "dateModified": "2022-04-25T18:22:46-05:00" }
```

```json
{ "@context": "https://schema.org", "@type": "Article", "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15028-photofines-with-malware-return-analysis-of-trojans.html" }, "headline": "Latest News", "description": "The latest news for Latin American integrators, contractors and wholesalers in electronic security.", "image": { "@type": "ImageObject", "url": "https://www.ventasdeseguridad.com/images/metatags/16x9/vds.png" }, "publisher": { "@type": "Organization", "name": "Latin Press, Inc.", "logo": { "@type": "ImageObject", "url": "https://www.ventasdeseguridad.com/images/metatags/16x9/lpi-eventos-online.png" } }, "author": { "@type": "Person", "name": "Ventas de Seguridad", "url": "https://www.ventasdeseguridad.com/en/news/latest-news/434-computer-security/15028-photofines-with-malware-return-analysis-of-trojans.html" } }
```
