MalwareTips.com
Current time: 06-18-2013, 07:36 AM
Hello,is this your first visit?! If NOT use this login panel!
Nick:  
Password:     
If YES, you should join
our amazing community!
Create an account!
Follow us
Facebook MalwareTips.com Twitter MalwareTips.com Google Plus  MalwareTips.com
  • Portal
    Home
  • News
    Headlines
  • Forums
    Community
  • Tutorials
    How-to's
  • Malware Help
    Assistance
    • Removal assistance
    • Malware removal guides
    • Security wizard
  • Reviews
    Products review
    • Video reviews
    • Written reviews
  • Giveaways
    Free stuff
    • Giveaways and promo
    • Discounts
    • Desktop enhancements
  • Malware Hub
    Virus Pipe
    • Virus Exchange
    • Virus List
  • Blogs
    Research

User Control Panel View New Posts View Today's Posts House Rules

MalwareTips.com / Security Discussions / Malware Talk v
« Previous 1 ... 3 4 5 6 7 ... 13 Next »
/ Fake Google Chrome Installer Steals Banking Details
Post Reply 
Threaded Mode | Linear Mode
Fake Google Chrome Installer Steals Banking Details
05-19-2012, 05:29 AM
Post: #1
Jack Offline
Community Admin
Posts: 6,260
Joined: Jan 2011
Reputation: 2359
Fake Google Chrome Installer Steals Banking Details
Information Week Wrote:Beware fake Chrome installers for Windows.

A file named "ChromeSetup.exe" is being offered for download on various websites, and the link to the file appears to be legitimately hosted on Facebook and Google domains. In reality, the software won't install Google's Chrome browser, but an information-stealing Trojan application known as Banker, according to antivirus vendor Trend Micro.

Once the malware--which appears to be targeting Latin American users, especially in Brazil and Peru--is executed, it relays the IP address and operating system version to one of two command-and-control (C&C) servers, then downloads a configuration file. After that, whenever a user of the infected PC visits one of a number of banking websites, the malware intercepts the HTTP request, redirects the user to a fake banking page, and also pops up a dialog box informing the user that new security software will be installed.

In fact, the malware has been designed uninstall GbPlugin, which is "software that protects Brazilian bank customers when performing online banking transactions," said Trend Micro security researcher Brian Cayanan in a blog post. "It does this through the aid of gb_catchme.exe--a legitimate tool from GMER called Catchme, which was originally intended to uninstall malicious software. The bad guys, in this case, are using the tool for their malicious agendas."

Read more: http://www.informationweek.com/news/secu.../240000575
Visit this user's website Find all posts by this user
Quote this message in a reply
05-19-2012, 06:07 AM
Post: #2
McLovin Offline
Gold Member (Level 7)
Posts: 7,825
Joined: Apr 2011
Reputation: 1306
RE: Fake Google Chrome Installer Steals Banking Details
How can you not tell that it's a fake Google Chrome installer. Mind you there are a lot of people out there that fall for a lot of things.

McLovins' Configuration | CyberTechTips.com
Visit this user's website Find all posts by this user
Quote this message in a reply
05-19-2012, 07:38 AM
Post: #3
Spirit Away
Silver Member (Level 6)
Posts: 1,811
Joined: May 2012
Reputation: 762
RE: Fake Google Chrome Installer Steals Banking Details
Install Only from Homesite or sites like softpedia,cnet.
Visit this user's website Find all posts by this user
Quote this message in a reply
05-19-2012, 07:52 AM
Post: #4
McLovin Offline
Gold Member (Level 7)
Posts: 7,825
Joined: Apr 2011
Reputation: 1306
RE: Fake Google Chrome Installer Steals Banking Details
(05-19-2012 07:38 AM)Stonecold Wrote:  Install Only from Homesite or sites like softpedia,cnet.

Yes, install and download from sites that have a very high reputation or have very good reviews.

McLovins' Configuration | CyberTechTips.com
Visit this user's website Find all posts by this user
Quote this message in a reply
05-19-2012, 08:08 AM
Post: #5
Umbra Polaris Offline
Testing and Reviews Group
Posts: 7,679
Joined: May 2011
Reputation: 1897
RE: Fake Google Chrome Installer Steals Banking Details
(05-19-2012 07:52 AM)McLovin Wrote:  
(05-19-2012 07:38 AM)Stonecold Wrote:  Install Only from Homesite or sites like softpedia,cnet.

Yes, install and download from sites that have a very high reputation or have very good reviews.

or check the hashes if you are not sure.

[Image: IoZEnVB.gif]

[Image: vRQkbKX.gif]
My Config/Reviews/Guides
Visit this user's website Find all posts by this user
Quote this message in a reply
 Kudos from: WinAndLinuxTutorials(+1)
05-19-2012, 08:34 AM
Post: #6
Spirit Away
Silver Member (Level 6)
Posts: 1,811
Joined: May 2012
Reputation: 762
RE: Fake Google Chrome Installer Steals Banking Details
(05-19-2012 08:08 AM)umbrapolaris Wrote:  
(05-19-2012 07:52 AM)McLovin Wrote:  
(05-19-2012 07:38 AM)Stonecold Wrote:  Install Only from Homesite or sites like softpedia,cnet.

Yes, install and download from sites that have a very high reputation or have very good reviews.

or check the hashes if you are not sure.
+1 This is the best way to check original and unbroken installer for every software
Visit this user's website Find all posts by this user
Quote this message in a reply
07-02-2012, 02:02 PM
Post: #7
computersaver Offline
New member (Level 1)
Posts: 4
Joined: Jul 2012
Reputation: 0
RE: Fake Google Chrome Installer Steals Banking Details
O my God. I don't believe this. Google is making spam for its user Sad
Find all posts by this user
Quote this message in a reply
07-02-2012, 02:07 PM
Post: #8
Malware Maniac Offline
Advanced Member (Level 5)
Posts: 681
Joined: May 2012
Reputation: 102
RE: Fake Google Chrome Installer Steals Banking Details
(07-02-2012 02:02 PM)computersaver Wrote:  O my God. I don't believe this. Google is making spam for its user Sad

No. There is a fake installer that in the description say stealing banking details.

Malware Maniac - All Malware should be removed by a Maniac.
[Image: Hm73c]
Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Post Reply 


Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  How the 3rd-party customisation tool for Dota2 steals passwords Earth 0 130 05-29-2013 10:30 AM
Last Post: Earth
  Reveton Ransomware now steals your passwords Earth 0 167 05-22-2013 04:44 PM
Last Post: Earth
  Rogue/Fake/Malicious - Chrome Extension Earth 4 529 01-31-2013 10:11 PM
Last Post: Earth
  Hackers outwit online banking identity security systems Jack 3 888 02-08-2012 05:07 PM
Last Post: Jack
  Bing ad serves malware to would-be Google Chrome switchers Jack 2 730 08-12-2011 07:44 AM
Last Post: jamescv7

  • View a Printable Version
  • Send this Thread to a Friend
  • Subscribe to this thread


User(s) browsing this thread: 2 Guest(s)

 


Proudly powered by MyBB.
Copyright - MalwareTips.com © 2012. All rights reserved. | Webdesign by End Soft Design
Contact Us | Privacy policy | Return to Top | Return to Content | Lite (Archive) Mode | RSS Syndication | Members List | Forum Team

MalwareTips.com is an independent website.All trademarks mentioned on this page are the property of their respective owners.