TSPY_BANCOS.LFJ
April 29, 2013
PLATFORM:
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)
OVERALL RISK RATING:
REPORTED INFECTION:
SYSTEM IMPACT RATING:
INFORMATION EXPOSURE:

Threat Type: Spyware
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size: 377,344 bytes
File Type: EXE
Memory Resident: No
Initial Samples Received Date: 26 Apr 2013
Arrival Details
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
HOSTS File Modification
This spyware modifies the system's HOSTS files to redirect users once the following Web site(s) are accessed:
- bancaribe.com.ve
- www.bancaribe.com.ve
- bancodevenezuela.com
- www.bancodevenezuela.com
It adds the following strings to the Windows HOSTS file:
- {BLOCKED}.{BLOCKED}.159.19 {BLOCKED}ibe.{BLOCKED}m.ve
- {BLOCKED}.{BLOCKED}.159.19 www.{BLOCKED}ibe.com.ve
- {BLOCKED}.{BLOCKED}.159.19 {BLOCKED}evenezuela.com
- {BLOCKED}.{BLOCKED}.159.19 www.{BLOCKED}evenezuela.com