|
Description:
To get a one-glance comprehensive view of the behavior of this spyware, refer to the Behavior Diagram shown below.
Spyware Overview
This spyware arrives as attachment to email messages spammed by another malware or a malicious user.
It drops a copy of itself. It drops non-malicious files. It executes one of the non-malicious files to hide its malicious routine. The said file is a damaged Kodak Viewer Express.
This spyware monitors the browsing habits of the user and waits until the said user logs on to eBay Web sites. It then connects to a certain Web site and attempts to place a bid.
It also connects to other Web sites. However, as of this writing, the said Web sites are inaccessible.
|