TROJ_ZBOT.CKA
Overview

QUICK LINKS  

Understanding New Pattern Format |

Malware type: Trojan

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:

Low

Reported infections:

Low

Damage potential:

High

Distribution potential:

Low

Description: 

This Trojan uses social engineering methods to lure users into performing certain actions that may, directly or indirectly, cause malicious routines to be performed. Specifically, the download link for this malware is supposed to be a link for a digital certificate.

To get a one-glance comprehensive view of the behavior of this spyware, refer to the Threat Diagram shown below.

TROJ_ZBOT.CKA Threat Diagram

Malware Overview

This Trojan arrives as a file downloaded from a remote URL.

It drops a copy of itself in the Windows system folder and appends garbage code to the dropped copy to avoid easy detection. It creates a folder with attributes set to System and Hidden to prevent users from discovering and removing its components. It then creates non-malicious files. It modifies a registry entry to enable its automatic execution at system startup. It also injects itself into processes as part of its memory residency routine.

It attempts to access a Web site to download a file which contains information where the Trojan can download an updated copy of itself, and where to send its stolen data. This configuration file also contains a list of targeted bank-related Web sites from which it steals information. Note that the contents of the file, hence the list of Web sites to monitor, may change any time.

It attempts to steal sensitive online banking information, such as user names and passwords. This routine risks the exposure of the user’s account information, which may then lead to the unauthorized use of the stolen data.

It saves the stolen information in a file. It sends the gathered information via HTTP POST to a remote URL.

For additional information about this threat, see:
Solution
Technical Details
Statistics

Description created: Oct. 22, 2009 12:05:57 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.

Quick Links