Author Topic: Bank of America video malware  (Read 3525 times)

0 Members and 1 Guest are viewing this topic.

February 27, 2009, 08:54:39 pm
Read 3525 times

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
You have probably seen this article about the Gozi trojan at a fake Bank of America site

http://garwarner.blogspot.com/2009/02/another-password-stealer-hides-as-bank.html

This is the site url

Code: [Select]
hxxp://sitekey.bankofamerica.reload.signonscreen-bhe9i94o8.content.viewvideopatch.com/control.htm?/emberUIWeb/LOGIN=tipc8oud4wsscu1
which starts a download of

Code: [Select]
hxxp://sitekey.bankofamerica.reload.signonscreen-bhe9i94o8.content.viewvideopatch.com/BofAsetup.exe

This is the VT result

http://www.virustotal.com/analisis/dbbb666c43a660855db135304b964287

Ruining the bad guy's day