The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security > Malware Advisories (RSS)
.
google unix.com



Malware Advisories (RSS) Malware Security Advisories Via RSS

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Troj_zbot.pk iBot Malware Advisories (RSS) 0 07-26-2008 12:20 AM
Troj_zbot.oy iBot Malware Advisories (RSS) 0 07-23-2008 07:20 AM
Troj_zbot.ox iBot Malware Advisories (RSS) 0 07-21-2008 10:00 PM
Troj_zbot.om iBot Malware Advisories (RSS) 0 07-17-2008 10:50 PM
Troj_zbot.mh iBot Malware Advisories (RSS) 0 06-18-2008 09:20 AM

Reply
 
Submit Tools LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 07-27-2008
iBot's Avatar
Forum Robot Girl
 

Join Date: Sep 2000
Posts: 20,502
Troj_zbot.pq

This Trojan arrives on a system as a file dropped by other malware or as a downloaded file from http://{BLOCKED}v.ru/test/ldr.exe.

It downloads an encrypted configuration file from http://{BLOCKED}v.ru/test/cfg.bin. Once decrypted, the downloaded configuration file contains a list of financial-related Web sites which this Trojan monitors. Note that the contents of the file, hence the list of Web sites to monitor, may change any time.

This Trojan attempts to steal sensitive online banking information. When a user attempts to access any of the monitored sites in the configuration file, it captures user input, specifically those entered in the input boxes designed for user names and passwords. This routine risks the exposure of the user's account information, which may then lead to the unauthorized use of the stolen data.

The gathered information is then sent to http://{BLOCKED}v.ru/test/s.php via HTTP POST.

This Trojan terminates itself once firewall-related processes are running in the system.



More...
Reply With Quote
Google The UNIX and Linux Forums
Sponsored Links
Reply

Bookmarks

Tags
None

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:




All times are GMT -4. The time now is 06:43 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66