|
Description:
Trend Micro received multiple samples of this spyware from multiple, independent sources, including customer reports and internal sources. These indicate that this spyware type poses a high risk to users due to the increased possibility of infection.
To get a one-glance comprehensive view of the behavior of this malware, refer to the Threat Diagram shown below.
Malware Overview
This spyware arrives as a file downloaded from a remote URL.
It drops a copy of itself in the Windows system folder and appends garbage code to the dropped copy to avoid easy detection. It creates a folder with attributes set to System and Hidden to prevent users from discovering and removing its components. It then creates non-malicious files. It modifies a registry entry to enable its automatic execution at system startup. It also injects itself into processes as part of its memory residency routine.
It attempts to access a Web site to download a file which contains information where the spyware can download an updated copy of itself, and where to send its stolen data. This configuration file also contains a list of targeted bank-related Web sites from which it steals information. Note that the contents of the file, hence the list of Web sites to monitor, may change any time.
It attempts to steal sensitive online banking information, such as user names and passwords. This routine risks the exposure of the user’s account information, which may then lead to the unauthorized use of the stolen data.
It saves the stolen information in a file. It sends the gathered information via HTTP POST to a remote URL.
It accesses a remote site to download its configuration file. The downloaded file contains information where it can download an updated copy of itself, and where to send its stolen data.
|