banner A little bit of yourself in this section. There are 3 three text graphics associated to this section; Subscribe me, Advertisements and About Me. I hope either one will suit your need.

Updates: Currently I'm testing on wordpress 2.5. I hope to release this theme real soon. So stay tune and dont forget to subscribe my blog. You can add more text here. Overflown text will be hidden, so make sure to end your text just right here. More...
Apr
1st

Unusual banking trojan found today

Author: Chewy | Files under Uncategorized
We've seen tons of banking trojans lately, but now we've run into something quite unique.

This new banking trojan was found today from a drive-by-download site. We've added detection for it as Win32.Pril.A

It not only infects the MBR of the machine, but also reflashes the boot code in the Flash BIOS, making disinfection problematic.

Once an infected machine is online, the trojan monitors the users actions, waiting him to go to go to one of several hundred online banks, located all over the world.

samplexml

Once the user has logged on, the banking trojan uses PCMCIA to inject code into the VGA! As an end result, the trojan creates a man-in-the-browser attack against the victim.

Now, the really surprising part is what the trojan does. Normal banking trojans would insert extra transactions or change the deposit account numbers on-the-fly. However, Win32.Pril.A doesn't withdraw money from you - it actually inserts money TO your account. This looked so weird we had to test it several times, on all of our accounts.

The drive-by-download site is still up. Normally, we wouldn't list the URL for such a site, or we would at least obfuscate it in a screenshot. However this time we'll make an exception. We will even make the link clickable: http://aprilbanking.cjb.net/

On 01/04/08 At 07:22 AM

Post a Comment