Originally posted on opensc.ws the 2nd of January 2010, the Spy Eye information theif appears to be a very promising info-stealer with much functionality, similar to that of the notourius ZBot. Spy Eye, which could originally be purchased for 500 USD, currently costs 1000 USD and contains much functionality including the following: Form-grabbing Password stealing [...]
Posts Tagged ‘Malware’
Enter Spy Eye – The Rise of Another Botnet
Posted: 27th May 2010 by sharpe in MalwareTags: Malware, Spy Eye, ZBot
The Very Capable Win32.Silon Information Thief
Posted: 12th May 2010 by sharpe in MalwareTags: Malware, Win32/Silon
The Win32.Silon information thief (hereafter referenced as Silon) is a relitively new information stealer, which surfaced early 2009. It has the ability to steal log-in information and commit financial fraud via many popular online banks. Currently it has been seen it the following two versions (dubbed by CSIS): Win32/Silon.A (SA) Win32/Silon.B (SB) Due to the [...]
FISH version 0.0.3 beta with numerous improvements is now available for download. Expect to see trememdous performance increases in this release as well as many other improvements including the following: Version 0.0.3 (second public release): This version is at least 30 times faster than version 0.0.2 Implemented a new hash function Optimised the iterative function [...]
“Default User” Temporary Internet File weirdness
Posted: 27th July 2009 by sharpe in MalwareTags: Malware
The other day I was looking at a friend’s computer. I was browsing his user profile directory in search of something intersting to show him and came across something that I had never seen before; the Default User’s Temporary Internet Files directory was filled with temporary Internet files (hence its name ) as though this [...]
NASTI – Nickos And Sharpes Tool for Identifying potentially malicious files
Posted: 12th June 2009 by sharpe in UtilitiesTags: Malware
Recently whilst analysing the PSP2-BBB banker trojan, I discovered that this particular trojan, as well as many others, downloaded malicious payloads to the currently logged on user’s “Temp” and “Temporary Internet Files” directories, located in the “Local Settings” directory, on a Win32 system, and saved them as temp files with a random four character name [...]