Sinowal

Description

(Fortinet) The installer drops a dynamic-link library (DLL) onto the local hard disk. The DLL acts as a loader module and will load other components, if any exist, and download a manager module which plays a central role in conducting banking fraud. The manager module downloads several plug-in modules from the C&C server, aimed at different target applications. These modules are used to steal sensitive information including bank account details, email addresses and FTP accounts. All plug-in modules contact the manager module through a named pipe, while the manager module communicates directly with the C&C server, uploading stolen information, reporting the local status of the trojan and downloading configuration and plug-in modules, as well as script commands for the plug-in modules to run.

Names

Name
Sinowal
Anserin
Mebroot
Quarian
Theola
Torpig

Category

Malware

Type

  • Banking trojan
  • Backdoor
  • Info stealer
  • Credential stealer
  • Downloader
  • Exfiltration

Information

Malpedia

Other Information

Uuid

40636fe0-6160-4e7e-a7d0-e0dbc599d7aa

Last Card Change

2020-05-22