The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security > Malware Advisories (RSS)
Google UNIX.COM


Malware Advisories (RSS) Malware Security Advisories Via RSS

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Troj_zbot.op iBot Malware Advisories (RSS) 0 07-17-2008 07:50 PM
Troj_zbot.nj iBot Malware Advisories (RSS) 0 07-09-2008 09:10 PM
Troj_zbot.mz iBot Malware Advisories (RSS) 0 06-30-2008 10:10 AM
Troj_zbot.lm iBot Malware Advisories (RSS) 0 06-27-2008 01:10 AM
Troj_zbot.mh iBot Malware Advisories (RSS) 0 06-18-2008 06:20 AM

Reply
 
Submit Tools LinkBack Thread Tools Search this Thread Display Modes
  #1  
Old 07-25-2008
iBot's Avatar
RSS Robot Girl
 

Join Date: Sep 2000
Posts: 14,296
Troj_zbot.pk

This Trojan arrives as a downloaded file from a certain URL.

It downloads a configuration file from a certain Web site. The said file contains information where the Trojan can download an updated copy of itself, and where to send its stolen data. This configuration file also contains targeted bank-related Web sites to monitor from which it steals information.

Once users access any of the monitored sites, this Trojan starts logging keystrokes.

It saves gathered information in a file then sends it to a remote site through HTTP post.

It creates a mutex to ensure that only one instance of itself is running in memory.

It checks for the presence of processes which are related to Outpost Personal Firewall and ZoneLabs Firewall Client. It then terminates the said processes.

It has rootkit capabilities, which enables it to hide its processes and files from the user.



More...
Reply With Quote
Google The UNIX and Linux Forums
Forum Sponsor
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes




All times are GMT -7. The time now is 10:26 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Complex Event Processing Blog

Content Relevant URLs by vBSEO 3.2.0