An empirical analysis of malicious internet banking software behavior

  • Authors:
  • André Ricardo A. Grégio;Dario Simões Fernandes;Vitor Monte Afonso;Paulo Lício de Geus;Victor Furuse Martins;Mario Jino

  • Affiliations:
  • CTI Renato Archer, Campinas, SP, Brazil;University of Campinas, Campinas, SP, Brazil;University of Campinas, Campinas, SP, Brazil;University of Campinas, Campinas, SP, Brazil;University of Campinas, Campinas, SP, Brazil;University of Campinas, Campinas, SP, Brazil

  • Venue:
  • Proceedings of the 28th Annual ACM Symposium on Applied Computing
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

"Bankers" are special types of malware whose targets are Internet banking users, mainly to obtain their credentials. Banker infections cause losses of billions of dollars worldwide. Thus, better understanding and detection of bankers is required. Due to their interactive nature, obtaining bankers' behaviors can be a difficult task for current dynamic analyzers. Also, existing tools specially crafted to detect bankers are usually limited to a specific type. In this article, we propose BanDIT, a dynamic analysis system that identifies behavior related to bankers combining visual analysis, network traffic pattern matching and filesystem monitoring. We analyzed over 1,500 malware samples to identify those whose target were online banks and reported the compromised IP and e-mail addresses found. We present an evaluation of their behavior and show that BanDIT was able to identify 98.8% of bankers in a manually labeled banker samples set.