|
Description:
This Trojan uses social engineering methods to lure users into performing certain actions that may, directly or indirectly, cause malicious routines to be performed. Specifically, the download link for this malware is supposed to be a link for a digital certificate.
To get a one-glance comprehensive view of the behavior of this spyware, refer to the Threat Diagram shown below.
Malware Overview
This Trojan arrives as a file downloaded from a remote URL.
It drops a copy of itself in the Windows system folder and appends garbage code to the dropped copy to avoid easy detection. It creates a folder with attributes set to System and Hidden to prevent users from discovering and removing its components. It then creates non-malicious files. It modifies a registry entry to enable its automatic execution at system startup. It also injects itself into processes as part of its memory residency routine.
It attempts to access a Web site to download a file which contains information where the Trojan can download an updated copy of itself, and where to send its stolen data. This configuration file also contains a list of targeted bank-related Web sites from which it steals information. Note that the contents of the file, hence the list of Web sites to monitor, may change any time.
It attempts to steal sensitive online banking information, such as user names and passwords. This routine risks the exposure of the user’s account information, which may then lead to the unauthorized use of the stolen data.
It saves the stolen information in a file. It sends the gathered information via HTTP POST to a remote URL.
For additional information about this threat, see: Solution Technical Details Statistics
Description created: Oct. 22, 2009 12:05:57 AM GMT -0800
Search a new malware
Tell us how we did. Take our quick survey.
|