Sophos

Troj/Banker-ELN

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from June 2008 (4.30)
Protection available since 6 May 2008 15:11:32 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Banker-ELN attempts to redirect connections to a banking website to a spoof site.

Troj/Banker-ELN modifies the file <System>\drivers\etc\hosts, redirecting connections to the following web addresses to a fixed IP address:

www.banamex.com
banamex.com.mx
bancanetempresarial.banamex.com.mx
boveda.banamex.com
www.banamex.com.mx
www.bancanetempresarial.banamex.com.mx
www.boveda.banamex.com

The Trojan then opens the spoof site in the default browser.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer