This Trojan steals Credit card Track1 and Track2 information from PoS systems. We have seen this used in targeted attacks.
Examples of Troj/Trackr-Gen include:
Example 1
File Information
- Size
- 129K
- SHA-1
- 17f20105db8c8d3c7160b906415343415c665d1d
- MD5
- 3696d72af97cad345375bea91561146e
- CRC-32
- e3f703fd
- File type
- application/x-ms-dos-executable
- First seen
- 2011-07-20
Example 2
File Information
- Size
- 135K
- SHA-1
- 2e3e8a3454262016d1d453c702a0dc8b42e29d5f
- MD5
- 99a307128daa407147d1c69d2824d703
- CRC-32
- 285fd5e2
- File type
- Windows executable
- First seen
- 2012-12-09
Other vendor detection
- Kaspersky
- HEUR:Trojan.Win32.Generic
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Application Data\jusched.exe
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- jusched
- c:\Documents and Settings\test user\Application Data\jusched.exe
Processes Created
- c:\Documents and Settings\test user\application data\jusched.exe
IP Connections
Example 3
File Information
- Size
- 59K
- SHA-1
- 32538bc513641cc37b21c93b3aaee142ccf59ffa
- MD5
- 2139e613dc20df19daa6d90a0ff05591
- CRC-32
- 5b78995b
- File type
- Windows executable
- First seen
- 2013-01-02
Other vendor detection
- Avira
- TR/Downloader.Gen
- Kaspersky
- HEUR:Trojan.Win32.Generic
Runtime Analysis
Copies Itself To
- c:\Documents and Settings\test user\Application Data\adobeflash.exe
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- adobeflash
- c:\Documents and Settings\test user\Application Data\adobeflash.exe
Processes Created
- c:\Documents and Settings\test user\application data\adobeflash.exe
IP Connections