The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security > Malware Advisories (RSS)
Google UNIX.COM


Malware Advisories (RSS) Malware Security Advisories Via RSS

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Bkdr_poison.ds iBot Malware Advisories (RSS) 0 04-25-2008 03:30 PM
Bkdr_poison.bj iBot Malware Advisories (RSS) 0 04-09-2008 07:40 PM
Bkdr_poison.ce iBot Malware Advisories (RSS) 0 03-26-2008 06:50 AM

Reply
 
Submit Tools LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 04-10-2008
iBot's Avatar
RSS Robot Girl
 

Join Date: Sep 2000
Posts: 14,302
Stumble this Post!
Bkdr_poison.bj

This backdoor may be dropped by other malware, specifically TROJ_PIDIEF.GJ.
Upon execution, it will inject its code into a legitimate process. It then drops a copy of itself. This backdoor creates a registry entry to enable its automatic execution at every system startup.
It then uses the system's default browser to open a hidden window. It does this by traversing a registry entry. It uses the said application to open a random TCP port to access a host name.
It then connects to a site. It logs user keystrokes and the title of the active window. It does the said routine to steal information. The stolen information is then saved as %System%\strcpy and later sent once connected.


More...
Reply With Quote
Google The UNIX and Linux Forums
Forum Sponsor
Reply

Thread Tools
Display Modes




All times are GMT -7. The time now is 11:09 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0