Troj/Trackr-Gen

Category: Viruses and Spyware Protection available since:21 Nov 2011 18:09:08 (GMT)
Type: Trojan Last Updated:01 Mar 2013 02:11:32 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

This Trojan steals Credit card Track1 and Track2 information from PoS systems. We have seen this used in targeted attacks.

Examples of Troj/Trackr-Gen include:

Example 1

File Information

Size
129K
SHA-1
17f20105db8c8d3c7160b906415343415c665d1d
MD5
3696d72af97cad345375bea91561146e
CRC-32
e3f703fd
File type
application/x-ms-dos-executable
First seen
2011-07-20

Example 2

File Information

Size
135K
SHA-1
2e3e8a3454262016d1d453c702a0dc8b42e29d5f
MD5
99a307128daa407147d1c69d2824d703
CRC-32
285fd5e2
File type
Windows executable
First seen
2012-12-09

Other vendor detection

Kaspersky
HEUR:Trojan.Win32.Generic

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\jusched.exe
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    jusched
    c:\Documents and Settings\test user\Application Data\jusched.exe
Processes Created
  • c:\Documents and Settings\test user\application data\jusched.exe
IP Connections
  • 84.22.106.94:80

Example 3

File Information

Size
59K
SHA-1
32538bc513641cc37b21c93b3aaee142ccf59ffa
MD5
2139e613dc20df19daa6d90a0ff05591
CRC-32
5b78995b
File type
Windows executable
First seen
2013-01-02

Other vendor detection

Avira
TR/Downloader.Gen
Kaspersky
HEUR:Trojan.Win32.Generic

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\adobeflash.exe
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    adobeflash
    c:\Documents and Settings\test user\Application Data\adobeflash.exe
Processes Created
  • c:\Documents and Settings\test user\application data\adobeflash.exe
IP Connections
  • 204.188.242.201:80

download Try Sophos products for free
Download now