{"id":51823,"date":"2016-08-09T11:42:59","date_gmt":"2016-08-09T18:42:59","guid":{"rendered":"https:\/\/blogs.mcafee.com\/?p=51823"},"modified":"2025-05-27T22:51:40","modified_gmt":"2025-05-28T05:51:40","slug":"banload-trojan-targets-brazilians-with-malware-downloads","status":"publish","type":"post","link":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/","title":{"rendered":"Banload Trojan Targets Brazilians With Malware Downloads"},"content":{"rendered":"<p>McAfee Labs has recently encountered new variants of the Banload Trojan. Banload has been around since the last decade. This malware generally arrives on a victim\u2019s system through a spam email containing an archived file or bundled software as an attachment. In a few cases, this malware may also be dropped by other malware or a drive-by download. When executed, Banload downloads other malware, often banking Trojans, on the victim\u2019s system to carry out further infections. We have observed this malware is using the functionality of the legitimate freeware Mep Installer to carry out the infection cycle.<\/p>\n<p>Mep Installer builds installation programs for Windows based on Inno Setup.\u00a0When Mep Installer executes, it creates a temporary installation file in the %TEMP% directory. This file has the following execution command:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51832\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_command-300x27.png\" alt=\"banload_command\" width=\"489\" height=\"44\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_command-300x27.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_command-768x69.png 768w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_command.png 912w\" sizes=\"auto, (max-width: 489px) 100vw, 489px\" \/><\/p>\n<p>Mep Installer has its signature at the offset used in the preceding\u00a0command:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51831\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/Signature-300x31.png\" alt=\"Signature\" width=\"484\" height=\"50\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/Signature-300x31.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/Signature.png 593w\" sizes=\"auto, (max-width: 484px) 100vw, 484px\" \/><\/p>\n<p>This temporary installation file checks for the Mep Installer signature. If found, the file will read data from the third argument, which is a zlib-compressed file. The following is a snippet of the compressed data:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51830\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_ZlibCompress-300x70.png\" alt=\"banload_ZlibCompress\" width=\"489\" height=\"114\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_ZlibCompress-300x70.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_ZlibCompress.png 631w\" sizes=\"auto, (max-width: 489px) 100vw, 489px\" \/><\/p>\n<p>The temporary installation file has a zlib decompression procedure. After decompression it drops the executable and runs it.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51834\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_Mep_Cycle-300x29.png\" alt=\"banload_Mep_Cycle\" width=\"486\" height=\"47\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_Mep_Cycle-300x29.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_Mep_Cycle.png 636w\" sizes=\"auto, (max-width: 486px) 100vw, 486px\" \/><\/p>\n<h2><strong>Infection chain<\/strong><\/h2>\n<p>We have observed that Banload hooks the\u00a0Mep Installer to trick users into installing the\u00a0Portuguese version of this software. Once the user gets a Banload-infected Mep Installer, the malware\u00a0uses same functionality as the\u00a0genuine Mep Installer to avoid suspicion. The infected version carries the malware inside the zlib-compressed file.<\/p>\n<p>The malware executes with the same command as with\u00a0the\u00a0legitimate Mep Installer:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51828\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_nal_command-300x40.png\" alt=\"banload_nal_command\" width=\"481\" height=\"64\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_nal_command-300x40.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_nal_command.png 626w\" sizes=\"auto, (max-width: 481px) 100vw, 481px\" \/><\/p>\n<p>Upon decompression the temp file\u00a0drops the malware in the Windows directory, as shown below:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51827\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_mal_run-300x70.png\" alt=\"banload_mal_run\" width=\"480\" height=\"112\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_mal_run-300x70.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_mal_run.png 607w\" sizes=\"auto, (max-width: 480px) 100vw, 480px\" \/><\/p>\n<p>This malware uses the temporary file of the genuine installer to carry out the infection. Banload also displays a fake Mep Installer signature to appear to be legitimate.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51833\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_mal_cycle-300x47.png\" alt=\"banload_mal_cycle\" width=\"479\" height=\"75\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_mal_cycle-300x47.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_mal_cycle.png 637w\" sizes=\"auto, (max-width: 479px) 100vw, 479px\" \/><\/p>\n<h2><strong>Obscuring techniques<\/strong><\/h2>\n<p>The malware uses a number of tricks to avoid execution in controlled environments such as\u00a0virtual machines, sandboxes, etc. It also checks for network monitoring tools like CommView, TCPView, etc.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51835\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_tricks-300x228.png\" alt=\"banload_tricks\" width=\"478\" height=\"363\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_tricks-300x228.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_tricks.png 598w\" sizes=\"auto, (max-width: 478px) 100vw, 478px\" \/><\/p>\n<p>The malware uses the following code patch to check for virtual machines:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51836\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_AntiVM-300x57.png\" alt=\"banload_AntiVM\" width=\"480\" height=\"91\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_AntiVM-300x57.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_AntiVM.png 618w\" sizes=\"auto, (max-width: 480px) 100vw, 480px\" \/><\/p>\n<p>Banload\u00a0terminates if the system\u2019s language ID does not match to 0x0416, Portuguese.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51826\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_languagID-300x56.png\" alt=\"banload_languagID\" width=\"476\" height=\"89\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_languagID-300x56.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_languagID.png 627w\" sizes=\"auto, (max-width: 476px) 100vw, 476px\" \/><\/p>\n<p>The malware also creates a mutex to ensure that only one instance of the malware is running at a time. The malware author uses standard RC4 algorithm to hide the payload\u2019s URL. The encrypted URL looks like this:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51829\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_URl_encrypted-300x52.png\" alt=\"banload_URl_encrypted\" width=\"482\" height=\"84\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_URl_encrypted-300x52.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_URl_encrypted.png 567w\" sizes=\"auto, (max-width: 482px) 100vw, 482px\" \/><\/p>\n<p>The following are some of the decrypted URLs from which the malware\u00a0downloads payloads to carry out further infections:<\/p>\n<ul>\n<li>http:\/\/[BLOCKED].br\/modulorato\/rato.zip<\/li>\n<li>http:\/\/ [BLOCKED].com.br\/banner.zip<\/li>\n<li>http:\/\/ [BLOCKED].net.br\/KL\/Windows.zip<\/li>\n<li>http:\/\/ [BLOCKED].com.br\/backup\/site\/CACminde.zip<\/li>\n<li>http:\/\/ [BLOCKED].com.br\/KL\/ljinguID.zip<\/li>\n<li>http:\/\/maranhao. [BLOCKED].com.br\/modulo\/maranhao.zip<\/li>\n<li>https:\/\/storage.googleapis.com\/[BLOCKED]\/ [BLOCKED].zip<\/li>\n<li>https:\/\/storage.googleapis.com\/[BLOCKED]\/ [BLOCKED].zip<\/li>\n<li>https:\/\/www.4shared.com\/web\/directDownload\/[BLOCKED]\/goqt4x. [BLOCKED]<\/li>\n<li>https:\/\/www.4shared.com\/web\/directDownload\/[BLOCKED]\/gk5y6n. [BLOCKED]<\/li>\n<li>https:\/\/storage.googleapis.com\/[BLOCKED]\/[BLOCKED].zip<\/li>\n<li>https:\/\/www.4shared.com\/web\/directDownload\/[BLOCKED]\/gbo7i6. [BLOCKED]<\/li>\n<li>http:\/\/www. [BLOCKED].org\/ddlevelsfiles\/imgs.zip<\/li>\n<li>https:\/\/www.4shared.com\/web\/directDownload\/[BLOCKED]\/gpms2b. [BLOCKED]<\/li>\n<\/ul>\n<p>The downloaded files are encrypted and are decrypted by the malware at\u00a0runtime. The downloaded file may look like this:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51825\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_downloaded_encrypted-300x44.png\" alt=\"banload_downloaded_encrypted\" width=\"483\" height=\"71\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_downloaded_encrypted-300x44.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_downloaded_encrypted.png 624w\" sizes=\"auto, (max-width: 483px) 100vw, 483px\" \/><\/p>\n<p>After decrypting this, we get this Zip file:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-51824\" src=\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_downloaded_decrypted-300x43.png\" alt=\"banload_downloaded_decrypted\" width=\"481\" height=\"69\" srcset=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_downloaded_decrypted-300x43.png 300w, https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_downloaded_decrypted.png 625w\" sizes=\"auto, (max-width: 481px) 100vw, 481px\" \/><\/p>\n<h2><strong>Summary<\/strong><\/h2>\n<p>This malware targets Brazilians by using the Mep Installer&#8217;s Portuguese version, checking for the Portuguese language ID, and most of the URLs listed above are from Brazil. McAfee products detect this malware as Downloader-FBIC! McAfee advises all users to keep their antimalware products up to date.<\/p>\n<p><strong>Analyzed hashes, SHA256<\/strong><\/p>\n<ul>\n<li>C5D3EC816D9029A5EDC6F0C64E1E9CAC02CF73A8A4828C3088C34FEF7338CC21<\/li>\n<li>98F38A78E8DCEE34DCFFB53D5A3E678E5572DDC2DFF2E0EF832FCBCEF3F5E7DC<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>McAfee Labs has recently encountered new variants of the Banload Trojan. Banload has been around since the last decade. This&#8230;<\/p>\n","protected":false},"author":674,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[442],"tags":[1814,4452,180],"coauthors":[3973],"class_list":["post-51823","post","type-post","status-publish","format-standard","hentry","category-mcafee-labs","tag-computer-security","tag-cybersecurity","tag-malware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Banload Trojan Targets Brazilians With Malware Downloads | McAfee Blog<\/title>\n<meta name=\"description\" content=\"McAfee Labs has recently encountered new variants of the Banload Trojan. Banload has been around since the last decade. This malware generally arrives on\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Banload Trojan Targets Brazilians With Malware Downloads | McAfee Blog\" \/>\n<meta property=\"og:description\" content=\"McAfee Labs has recently encountered new variants of the Banload Trojan. Banload has been around since the last decade. This malware generally arrives on\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/\" \/>\n<meta property=\"og:site_name\" content=\"McAfee Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/McAfee\/\" \/>\n<meta property=\"article:published_time\" content=\"2016-08-09T18:42:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-05-28T05:51:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_command.png\" \/>\n\t<meta property=\"og:image:width\" content=\"912\" \/>\n\t<meta property=\"og:image:height\" content=\"82\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"McAfee\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@McAfee\" \/>\n<meta name=\"twitter:site\" content=\"@McAfee\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"McAfee\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/\"},\"author\":{\"name\":\"McAfee\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa\"},\"headline\":\"Banload Trojan Targets Brazilians With Malware Downloads\",\"datePublished\":\"2016-08-09T18:42:59+00:00\",\"dateModified\":\"2025-05-28T05:51:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/\"},\"wordCount\":655,\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_command-300x27.png\",\"keywords\":[\"computer security\",\"cybersecurity\",\"malware\"],\"articleSection\":[\"McAfee Labs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/\",\"name\":\"Banload Trojan Targets Brazilians With Malware Downloads | McAfee Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_command-300x27.png\",\"datePublished\":\"2016-08-09T18:42:59+00:00\",\"dateModified\":\"2025-05-28T05:51:40+00:00\",\"description\":\"McAfee Labs has recently encountered new variants of the Banload Trojan. Banload has been around since the last decade. This malware generally arrives on\",\"breadcrumb\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#primaryimage\",\"url\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_command-300x27.png\",\"contentUrl\":\"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_command-300x27.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Other Blogs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"McAfee Labs\",\"item\":\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Banload Trojan Targets Brazilians With Malware Downloads\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#website\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"name\":\"McAfee Blog\",\"description\":\"Internet Security News\",\"publisher\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#organization\",\"name\":\"McAfee\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png\",\"width\":1286,\"height\":336,\"caption\":\"McAfee\"},\"image\":{\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/x.com\/McAfee\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/www.youtube.com\/McAfee\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa\",\"name\":\"McAfee\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/1ffadfeeda1f4f9e7891a81f27a9ecf4\",\"url\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png\",\"contentUrl\":\"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png\",\"caption\":\"McAfee\"},\"description\":\"We're here to make life online safe and enjoyable for everyone.\",\"sameAs\":[\"https:\/\/www.facebook.com\/McAfee\/\",\"https:\/\/www.linkedin.com\/company\/mcafee\/\",\"https:\/\/x.com\/McAfee\"],\"url\":\"https:\/\/www.mcafee.com\/blogs\/author\/mcafee\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Banload Trojan Targets Brazilians With Malware Downloads | McAfee Blog","description":"McAfee Labs has recently encountered new variants of the Banload Trojan. Banload has been around since the last decade. This malware generally arrives on","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Banload Trojan Targets Brazilians With Malware Downloads | McAfee Blog","og_description":"McAfee Labs has recently encountered new variants of the Banload Trojan. Banload has been around since the last decade. This malware generally arrives on","og_url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/","og_site_name":"McAfee Blog","article_publisher":"https:\/\/www.facebook.com\/McAfee\/","article_author":"https:\/\/www.facebook.com\/McAfee\/","article_published_time":"2016-08-09T18:42:59+00:00","article_modified_time":"2025-05-28T05:51:40+00:00","og_image":[{"width":912,"height":82,"url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/banload_command.png","type":"image\/png"}],"author":"McAfee","twitter_card":"summary_large_image","twitter_creator":"@McAfee","twitter_site":"@McAfee","twitter_misc":{"Written by":"McAfee","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#article","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/"},"author":{"name":"McAfee","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa"},"headline":"Banload Trojan Targets Brazilians With Malware Downloads","datePublished":"2016-08-09T18:42:59+00:00","dateModified":"2025-05-28T05:51:40+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/"},"wordCount":655,"publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_command-300x27.png","keywords":["computer security","cybersecurity","malware"],"articleSection":["McAfee Labs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/","url":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/","name":"Banload Trojan Targets Brazilians With Malware Downloads | McAfee Blog","isPartOf":{"@id":"https:\/\/www.mcafee.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#primaryimage"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#primaryimage"},"thumbnailUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_command-300x27.png","datePublished":"2016-08-09T18:42:59+00:00","dateModified":"2025-05-28T05:51:40+00:00","description":"McAfee Labs has recently encountered new variants of the Banload Trojan. Banload has been around since the last decade. This malware generally arrives on","breadcrumb":{"@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#primaryimage","url":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_command-300x27.png","contentUrl":"https:\/\/securingtomorrow.mcafee.com\/wp-content\/uploads\/banload_command-300x27.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/banload-trojan-targets-brazilians-with-malware-downloads\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.mcafee.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"Other Blogs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/"},{"@type":"ListItem","position":3,"name":"McAfee Labs","item":"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/"},{"@type":"ListItem","position":4,"name":"Banload Trojan Targets Brazilians With Malware Downloads"}]},{"@type":"WebSite","@id":"https:\/\/www.mcafee.com\/blogs\/#website","url":"https:\/\/www.mcafee.com\/blogs\/","name":"McAfee Blog","description":"Internet Security News","publisher":{"@id":"https:\/\/www.mcafee.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mcafee.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mcafee.com\/blogs\/#organization","name":"McAfee","url":"https:\/\/www.mcafee.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2023\/02\/mcafee-logo.png","width":1286,"height":336,"caption":"McAfee"},"image":{"@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/x.com\/McAfee","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/www.youtube.com\/McAfee"]},{"@type":"Person","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/47851fdb92fad9456152405839c92efa","name":"McAfee","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mcafee.com\/blogs\/#\/schema\/person\/image\/1ffadfeeda1f4f9e7891a81f27a9ecf4","url":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png","contentUrl":"https:\/\/www.mcafee.com\/blogs\/wp-content\/uploads\/2020\/08\/Original-Logo-96x96.png","caption":"McAfee"},"description":"We're here to make life online safe and enjoyable for everyone.","sameAs":["https:\/\/www.facebook.com\/McAfee\/","https:\/\/www.linkedin.com\/company\/mcafee\/","https:\/\/x.com\/McAfee"],"url":"https:\/\/www.mcafee.com\/blogs\/author\/mcafee\/"}]}},"_links":{"self":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/51823","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/users\/674"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/comments?post=51823"}],"version-history":[{"count":2,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/51823\/revisions"}],"predecessor-version":[{"id":214570,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/posts\/51823\/revisions\/214570"}],"wp:attachment":[{"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/media?parent=51823"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/categories?post=51823"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/tags?post=51823"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.mcafee.com\/blogs\/wp-json\/wp\/v2\/coauthors?post=51823"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}