![]() |
|
|
|
|
|||||||
| Forums | Portal | Register | Forum Rules | FAQ | Contribute | Members List | Arcade | Search | Today's Posts | Mark Forums Read |
| Malware Advisories (RSS) Malware Security Advisories Via RSS |
|
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Troj_zbot.mh | iBot | Malware Advisories (RSS) | 0 | 06-18-2008 06:20 AM |
|
|
Submit Tools | LinkBack | Thread Tools | Display Modes |
|
||||
|
Troj_zbot.lm
This Trojan arrives on a system as a file dropped by other malware or as a downloaded file from a certain Web site.
When executed, it downloads an encrypted configuration file from and is saved as %System%\wsnpoem\audio.dll. (Note: %System% is the Windows system folder, which is usually C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.) Once decrypted, the downloaded configuration file contains the following financial-related Web sites which this spyware monitors:
When a user attempts to access any of the monitored sites in the configuration file, it captures user input (specifically those entered in the input boxes designed for usernames and passwords) and saves it in one of its dropped .DLL component files. This routine risks the exposure of the user's account information, which may then lead to the unauthorized use of the stolen data. The gathered information is then sent to http://{BLOCKED}sia.name/s.php via HTTP POST. More... |
||||
| Google The UNIX and Linux Forums |
| Forum Sponsor | ||
|
|