The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security > Malware Advisories (RSS)
Google UNIX.COM


Malware Advisories (RSS) Malware Security Advisories Via RSS

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Troj_zbot.mh iBot Malware Advisories (RSS) 0 06-18-2008 06:20 AM

Reply
 
Submit Tools LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-27-2008
iBot's Avatar
RSS Robot Girl
 

Join Date: Sep 2000
Posts: 14,302
Troj_zbot.lm

This Trojan arrives on a system as a file dropped by other malware or as a downloaded file from a certain Web site.
When executed, it downloads an encrypted configuration file from and is saved as %System%\wsnpoem\audio.dll.
(Note: %System% is the Windows system folder, which is usually C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)
Once decrypted, the downloaded configuration file contains the following financial-related Web sites which this spyware monitors:Note that the contents of the file, hence the list of Web sites to monitor, may change any time.
When a user attempts to access any of the monitored sites in the configuration file, it captures user input (specifically those entered in the input boxes designed for usernames and passwords) and saves it in one of its dropped .DLL component files.
This routine risks the exposure of the user's account information, which may then lead to the unauthorized use of the stolen data.
The gathered information is then sent to http://{BLOCKED}sia.name/s.php via HTTP POST.


More...
Reply With Quote
Google The UNIX and Linux Forums
Forum Sponsor
Reply

Thread Tools
Display Modes




All times are GMT -7. The time now is 06:29 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0