Trojan.Spy.Banker.ABGS uses a text file disguised as a DLL, which holds filenames to be looked up and renamed. The spy-banker sends an e-mail to its herder using smtp.tutopia.com.br as the mail gateway. This message announces that the respective computer is infected and that it is now part of the malicious defrauding system. The virus uses a fake web browser window that looks identical to the banks login system. Of course, if the user logs in, his/her credentials will actually land in the attackers.”]
Source: https://www.bitdefender.com/blog/hotforsecurity/weekly-malware-review-trojan-spy-banker-abgs/