TSPY_QHOST.VP
Windows 2000, XP, Server 2003
Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It attempts to steal sensitive online banking information, such as user names and passwords. This routine risks the exposure of the user's account information, which may then lead to the unauthorized use of the stolen data. It attempts to steal information, such as user names and passwords, used when logging into certain banking or finance-related websites.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
HOSTS File Modification
This Trojan modifies the system's HOSTS files to redirect users once the following Web site(s) are accessed:
- caixa.gov.br
- http://www.real.com.br
- http://www.caixa.com.br
- caixa.com.br
- http://www.banrisul.com.br
- http://www.cef.com.br
- santander.com.br
- real.com.br
- http://www.santander.com.br
- http://www.bb.com.br
- cef.com.br
- bancoreal.com.br
- bradesco.com.br
- http://www.americanexpress.com.br
- http://www.bancodobrasil.com.br
- bb.com.br
- http://www.bancoreal.com.br
- banrisul.com.br
- americanexpress.com.br
- bancodobrasil.com.br
- http://www.itau.com.br
- itau.com.br
- http://www.caixa.gov.br
- http://www.bradesco.com.br
- banespa.com.br
- http://www.banespa.com.br
Information Theft
This Trojan attempts to steal sensitive online banking information, such as user names and passwords. This routine risks the exposure of the user's account information, which may then lead to the unauthorized use of the stolen data.
It attempts to steal information from the following banks and/or other financial institutions:
- American Express
- Banco Real
- Banco do Brasil
- Banespa
- Banrisul
- Bradesco
- Caixa
- Itau
- Santander
Other Details
Based on analysis of the codes, it has the following capabilities:
- Redirects users to {BLOCKED}.{BLOCKED}.97.162 because of modifications made to the HOSTS file
- Modifies the HOSTS file in the following locations:
- %System%\drivers\etc\hosts (On Windows NT, 2000, XP, and Server 2003)
- %Windows%\host.sam (on Windows 98 and ME)
Variant Information
This Trojan has the following MD5 hashes:
- 9bfd9e8681280b7594324dd449693b49
It has the following SHA1 hashes:
- 3f3cb2bb65299d53f8bbdea81a94e4aa271be089
SOLUTION
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.
Step 2
Remove these strings added by the malware/grayware/spyware in the HOSTS file
- {BLOCKED}.{BLOCKED}.97.162 caixa.gov.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.{BLOCKED}al.com.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.{BLOCKED}ixa.com.br
- {BLOCKED}.{BLOCKED}.97.162 caixa.com.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.{BLOCKED}nrisul.com.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.{BLOCKED}f.com.br
- {BLOCKED}.{BLOCKED}.97.162 santander.com.br
- {BLOCKED}.{BLOCKED}.97.162 real.com.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.{BLOCKED}ntander.com.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.{BLOCKED}.com.br
- {BLOCKED}.{BLOCKED}.97.162 cef.com.br
- {BLOCKED}.{BLOCKED}.97.162 bancoreal.com.br
- {BLOCKED}.{BLOCKED}.97.162 bradesco.com.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.{BLOCKED}ericanexpress.com.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.{BLOCKED}ncodobrasil.com.br
- {BLOCKED}.{BLOCKED}.97.162 bb.com.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.{BLOCKED}ncoreal.com.br
- {BLOCKED}.{BLOCKED}.97.162 banrisul.com.br
- {BLOCKED}.{BLOCKED}.97.162 americanexpress.com.br
- {BLOCKED}.{BLOCKED}.97.162 bancodobrasil.com.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.{BLOCKED}au.com.br
- {BLOCKED}.{BLOCKED}.97.162 itau.com.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.{BLOCKED}ixa.gov.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.{BLOCKED}adesco.com.br
- {BLOCKED}.{BLOCKED}.97.162 banespa.com.br
- {BLOCKED}.{BLOCKED}.97.162 http://www.banespa.com.br
Step 3
Scan your computer with your Trend Micro product to delete files detected as TSPY_QHOST.VP. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Did this description help? Tell us how we did.