Threat behavior
TrojanDownloader:Win32/Bancos.CP is a trojan that downloads and executes arbitrary files and may attempt to delete components of a security application used by Brazilian banks to protect customers from Internet banking fraud.
Installation
TrojanDownloader:Win32/Bancos.CP runs from its original location. It has been observed using filenames such as "alteracao-439494-4343.exe". The malware drops a batch script named "cabbit.bat" which is executed after downloading other malware.
Payload
Downloads and executes arbitrary files
This trojan variant attempts to contact a predefined remote server to download other malware. At the time of this writing, the other malware included variants of Win32/Bancos and Win32/Banload. This trojan was observed connecting to the remote server "71.174.51.86" and retrieving three executables as the following:
c:\ethernet3233.exe
c:\bet3233.exe
%windir%\system32\crepusculox.exe
The batch script "cabbit.bat" is then run - the script contains instructions to start each of the executables listed above. Each of the downloaded components performs other actions. For example one of the downloaded executables (TrojanDownloader:Win32/Bancos.CQ) may attempt to delete components of a security application used by Brazilian banks to protect customers from Internet banking fraud.
Other variants of this malware may contact other server addresses such as "69.64.36.29" and download a varying number of additional malware.
Additional Information
Analysis by David Wood
Prevention