The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Special Forums > Security > Malware Advisories (RSS)
.
google unix.com



Malware Advisories (RSS) Malware Security Advisories Via RSS

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Troj_zbot.op iBot Malware Advisories (RSS) 0 07-17-2008 10:50 PM
Troj_zbot.nj iBot Malware Advisories (RSS) 0 07-10-2008 12:10 AM
Troj_zbot.mz iBot Malware Advisories (RSS) 0 06-30-2008 01:10 PM
Troj_zbot.lm iBot Malware Advisories (RSS) 0 06-27-2008 04:10 AM
Troj_zbot.mh iBot Malware Advisories (RSS) 0 06-18-2008 09:20 AM

Closed Thread
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 07-17-2008
iBot's Avatar
iBot iBot is offline
Forum Robot Girl
  
 

Join Date: Sep 2000
Posts: 21,980
Troj_zbot.om

This spyware arrives on a system as a file dropped by other malware or as a downloaded file from a remote site.

Upon execution, this spyware drops a copy of itself in the Windows system folder and appends garbage code to the dropped copy to avoid easy detection.

It creates a folder with its attributes set to System and Hidden to prevent users from discovering and removing its components. The said folder contains non-malicious files.

A .BIN file is downloaded from a remote site. For its autostart technique, it modifies a registry key and entry.

This spyware downloads an encrypted configuration file. Once decrypted, the downloaded configuration file contains financial-related Web sites which this spyware monitors. Note that the contents of the file, hence the list of Web sites to monitor, may change any time.

This spyware also creates a remote thread to inject itself into the legitimate process to stay memory resident. This routine enables this spyware to run even when the system is in safe mode.

This spyware attempts to steal sensitive online banking information. When a user attempts to access any of the monitored sites in the configuration file, it captures user input (specifically those entered in the input boxes designed for user names and passwords).

This routine risks the exposure of the user's account information, which may then lead to the unauthorized use of the stolen data.

Stolen information is stored in the affected system. The gathered information is then sent via HTTP POST.



More...
Sponsored Links
Closed Thread

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 10:34 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language translation by Google.
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0