The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security > Malware Advisories (RSS)
Google UNIX.COM


Malware Advisories (RSS) Malware Security Advisories Via RSS

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Troj_zbot.pk iBot Malware Advisories (RSS) 0 07-25-2008 09:20 PM
Troj_zbot.pg iBot Malware Advisories (RSS) 0 07-25-2008 09:20 PM
Troj_zbot.oy iBot Malware Advisories (RSS) 0 07-23-2008 04:20 AM
Troj_zbot.ox iBot Malware Advisories (RSS) 0 07-21-2008 07:00 PM
Troj_zbot.mh iBot Malware Advisories (RSS) 0 06-18-2008 06:20 AM

Reply
 
Submit Tools LinkBack Thread Tools Display Modes
  #1  
Old 07-28-2008
iBot's Avatar
RSS Robot Girl
 

Join Date: Sep 2000
Posts: 14,297
Troj_zbot.pr

This malware arrives as a file downloaded from a certain URL.

Upon execution, it drops a copy of itself in the system folder. It creates a folder with attributes System and Hidden. It then creates the non-malicious files.

It injects itself into certain legitimate processes as part of its memory residency routine.

It attempts to access a Web site to download a file which contains information on where this malware can download an updated copy of itself, and where to send its stolen data. This configuration file also contains a list of targeted bank-related Web sites to monitor from which this malware steals information.

Once users access any of the monitored sites, this malware starts logging keystrokes. It attempts to retrieve information from Web sites of certain financial-related institutions, such as user names and passwords. This routine risks the exposure of the user's account information, which may then lead to the unauthorized use of the stolen data.

The information stolen by this malware is saved in a file and is then sent to a server via HTTP post.



More...
Reply With Quote
Google The UNIX and Linux Forums
Forum Sponsor
Reply

Thread Tools
Display Modes




All times are GMT -7. The time now is 06:48 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Complex Event Processing Blog

Content Relevant URLs by vBSEO 3.2.0