Home Malware Programs Trojans Client Maximus

Client Maximus

Posted: September 14, 2017

Threat Metric

Ranking: 10,502
Threat Level: 8/10
Infected PCs: 2,349
First Seen: September 14, 2017
Last Seen: September 3, 2023
OS(es) Affected: Windows

The Client Maximus is a banking Trojan that modifies the Web-browsing sessions of its victims to facilitate fraudulent financial transactions. Because the Client Maximus, like most spyware, is designed to operate without detection, PC users should protect themselves with appropriate security products that detect similar threats, regardless of the lack of symptoms. Always use anti-malware programs for uninstalling the Client Maximus before taking further actions as recommended by your bank to re-secure any compromised accounts.

Banking Trojans Hitting South America to the Max

Brazil is one of the threatening software industry's preferred targets for deploying banking Trojans, which may collect account credentials or use more sophisticated methods of transferring money from a victim's account to a con artist. However, most specimens are limited in programming sophistication noticeably, when compared to the similar underground industries in Europe and North America. That may be changing with the Client Maximus, a banking-specialized form of spyware that seems to be purpose-built for the customers of Brazilian financial institutions.

The Client Maximus installs itself by exploiting a script vulnerability in Windows machines transitioning into running a corrupted JavaScript function. First, the installer makes multiple checks against common signs of security or AV analysis environments, guaranteeing that the Client Maximus only infects a 'normal' PC. Like similar forms of spyware, once the Client Maximus is operational, it maintains system persistence via a DLL-hijacking function that hides the Client Maximus as part of a process associated with Microsoft, Adobe or VMWare.

The Trojan monitors the user's Web-browsing activities for access to specific websites, although the list of domains under monitoring is obfuscated from analysis by third parties. If it detects that the user is loading a Brazilian banking site, it notifies the remote attacker, who can enable a UI overlay. With this secondary interface, the con artist sends additional requests for confidential information and manipulates the victim into authorizing a fraudulent financial transaction. Other than not being able to be minimized, malware experts conclude that there are limited to no symptoms to indicate that an attack is taking place.

Minimizing the Role of Trojans in Your Online Banking

Although Brazil has been a focal point for banking-oriented spyware for years, the Client Maximus is a potential milestone that shows a ramping up in the quality of the deployed threats' programming. It includes redundant backup functions for responding to different environments, various checks against AV vendors' analytical tools, and a hands-on payload driven by the threat actor abusing his remote access to the infected computer. The most significant symptoms of the Client Maximus attacks are limited to the unusual requests for additional banking information, which threat actors can disguise as being part of the banking institution's security protocols.

The Client Maximus doesn't maintain its presence on an infected PC as a visibly separate application, and any users should rely on their anti-malware solutions for identifying this threat. Infection methods for threats of this type usually model themselves after email attachments, which malware experts usually find crafted to look like invoices, delivery notices or local news articles. Always respond to a potential infection by letting your anti-malware products delete the Client Maximus immediately, and consulting your bank for other steps to take, such as changing a compromised password.

It's the nature of the Trojan industry to adapt itself to the landscape it's attacking. For Brazil, the problems presented by banking Trojans like the Client Maximus only are becoming thornier.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\System32\zh-TW\windowsanytimeupgradeResults.exe.mui File name: windowsanytimeupgradeResults.exe.mui
Size: 3.58 KB (3584 bytes)
MD5: 4599f72c52d67559f8acfa441f506a68
Detection count: 843
Mime Type: unknown/mui
Path: %WINDIR%\System32\zh-TW\windowsanytimeupgradeResults.exe.mui
Group: Malware file
Last Updated: October 29, 2022
a59b2db51976d406e554ede957cef186f28a59bc2ca8b20b5451fdfd1c08a73c.exe File name: a59b2db51976d406e554ede957cef186f28a59bc2ca8b20b5451fdfd1c08a73c.exe
Size: 318.97 KB (318976 bytes)
MD5: 48bad27fb46713dd82015652fead8230
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
9adde83cd144844dcbea3a7a28ef78a761e8f8166ecbfdf7afb91208d20122c6.exe File name: 9adde83cd144844dcbea3a7a28ef78a761e8f8166ecbfdf7afb91208d20122c6.exe
Size: 352.25 KB (352256 bytes)
MD5: 612ea6d5083c5ccbdffadc7fca61fb3e
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
9a3273dca6cc2e9e7d34b29e4c55ffb2098f4d5f1031396ee4eae15afd6f3f6d.exe File name: 9a3273dca6cc2e9e7d34b29e4c55ffb2098f4d5f1031396ee4eae15afd6f3f6d.exe
Size: 320.51 KB (320512 bytes)
MD5: 1f5e5aee1d18a6fc95b14fc1984cbb5a
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
907accd8c51937693c56c52bf55398f2b583643f600e1aca1b69bca054c4c4ee.exe File name: 907accd8c51937693c56c52bf55398f2b583643f600e1aca1b69bca054c4c4ee.exe
Size: 320.51 KB (320512 bytes)
MD5: e8ebe596b60ca9e1bf59d40a311b408b
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
f7f1c544ac69ffe8565464fa5fb3145380c75bf5cf8d56ce91287d95ff07e969.exe File name: f7f1c544ac69ffe8565464fa5fb3145380c75bf5cf8d56ce91287d95ff07e969.exe
Size: 352.76 KB (352768 bytes)
MD5: 6a033c9c9f4860e4cec71b4d4e66e2f7
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
f775537ba598985f360ec574a942e2fccd23f6cd541cfec76bd5db08b50e63c2.exe File name: f775537ba598985f360ec574a942e2fccd23f6cd541cfec76bd5db08b50e63c2.exe
Size: 352.25 KB (352256 bytes)
MD5: 74c2e4ba19a2f4e03f02a27aa72ab557
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
e06c427c8fdf65100ac7341be12ec85bdf13c6ecdc07b92b35a75b1ed5a245c7.exe File name: e06c427c8fdf65100ac7341be12ec85bdf13c6ecdc07b92b35a75b1ed5a245c7.exe
Size: 293.63 KB (293632 bytes)
MD5: 89acea6eb95777b01f94ad7e2aea3245
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
Deigo.lnk File name: Deigo.lnk
Size: 949B (949 bytes)
MD5: d844f0beb02855da6e14a97f61b9008c
Detection count: 15
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
Last Updated: September 18, 2017
db97efe49fddd94ec9ed0dc30be0d768ec29e8816e4588a18f39863db76f4170.exe File name: db97efe49fddd94ec9ed0dc30be0d768ec29e8816e4588a18f39863db76f4170.exe
Size: 293.12 KB (293120 bytes)
MD5: b1eac6c15953a896bc4ce7214a153f4b
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
d6f611587b8344c3db1f0287cb733591233e43fe1bb977af6f365b2f78f5e408.exe File name: d6f611587b8344c3db1f0287cb733591233e43fe1bb977af6f365b2f78f5e408.exe
Size: 320.51 KB (320512 bytes)
MD5: 464a59225303b20edce15118744490af
Detection count: 13
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
d65f6db00ed2e098db351f4ed84cc80e145d4356125ec603c811a452b4bf7435.exe File name: d65f6db00ed2e098db351f4ed84cc80e145d4356125ec603c811a452b4bf7435.exe
Size: 320.51 KB (320512 bytes)
MD5: 1d1f6119027a6a215e3c23555737806d
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
d17edb0235024927fbb68d3359e7a8a9da808429ea09edf1262de84793d70ba8.exe File name: d17edb0235024927fbb68d3359e7a8a9da808429ea09edf1262de84793d70ba8.exe
Size: 317.44 KB (317440 bytes)
MD5: c37c10389755ae942e1929f6cafbe155
Detection count: 11
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
cxofkwsf.vbs File name: cxofkwsf.vbs
Size: 213B (213 bytes)
MD5: e3f926303147c3697c86f3e807ce19e2
Detection count: 10
Mime Type: unknown/vbs
Group: Malware file
Last Updated: September 18, 2017
ats.lnk File name: ats.lnk
Size: 996B (996 bytes)
MD5: 2137f22dd0adbfd76c4358cecd391e27
Detection count: 7
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
Last Updated: January 8, 2020
rvwzeyouxpfunp.vbs File name: rvwzeyouxpfunp.vbs
Size: 195B (195 bytes)
MD5: bc057ca73bbddb77ae1bd9984dd6022f
Detection count: 7
Mime Type: unknown/vbs
Group: Malware file
Last Updated: January 8, 2020
c2626a33e0d9cb3ccc89786f25efc4fb32b9ae487c2472d70d4004131c7aa462.exe File name: c2626a33e0d9cb3ccc89786f25efc4fb32b9ae487c2472d70d4004131c7aa462.exe
Size: 292.86 KB (292864 bytes)
MD5: c4af95b65d7e32011187a887d624b958
Detection count: 6
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
c1df4a05d0d4884310cda3b143518b4a2ed9bddc1c364b8b23dcd45d4aef26c9.exe File name: c1df4a05d0d4884310cda3b143518b4a2ed9bddc1c364b8b23dcd45d4aef26c9.exe
Size: 320.51 KB (320512 bytes)
MD5: 5a0b2e29adc782971d4b4911933858ab
Detection count: 4
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
c1abcdc498852eb94f649948416f380bdc55304d10b7a70d5fc2676d9cb380a0.exe File name: c1abcdc498852eb94f649948416f380bdc55304d10b7a70d5fc2676d9cb380a0.exe
Size: 292.86 KB (292864 bytes)
MD5: 17a6941c99a55a31ddeae8c75419f989
Detection count: 3
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
bcbc6f9ed5f19266365727473f1b0481fd217e4a6eea7a054a5ac93003855974.exe File name: bcbc6f9ed5f19266365727473f1b0481fd217e4a6eea7a054a5ac93003855974.exe
Size: 539.64 KB (539648 bytes)
MD5: 6e0ac45009d98b50283c545dd9489ae3
Detection count: 2
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017
af0da86ffca86d1af7a541026d4a9b99522e155085a094fc130e945977bc77b6.exe File name: af0da86ffca86d1af7a541026d4a9b99522e155085a094fc130e945977bc77b6.exe
Size: 320 KB (320000 bytes)
MD5: ff55de62b8f71e855fe20773e53fb574
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 18, 2017

More files
Loading...