Clicky

Pages

Showing posts with label worm;Qakbot. Show all posts
Showing posts with label worm;Qakbot. Show all posts

Wednesday, May 25, 2011

W32.Qakbot aka W32/Pinkslipbot or infostealer worm

W32.Qakbot aka W32/Pinkslipbot

  W32.Qakbot in Detail by Symantec Nicolas Falliere

W32.Qakbot is a worm that has been seen spreading through network shares, removable drives, and infected webpages, and infecting computers since mid-2009. Its primary purpose is to steal online banking account information from compromised computers. The malware controllers use the stolen information to access client accounts within various financial service websites with the intent of moving currency to accounts from which they can withdraw funds. It employs a classic keylogger, but is unique in that it also steals active session authentication tokens and then piggy backs on the existing online banking sessions. It then quickly uses that information for malicious purposes.

The following screenshot is from the paper you see above 


  General File Information


MD5  076bc0533d63826e1e809ad9fcbe2fb8
SHA1 33d9b4a712c29304478da235f17cd28978a93d2f
File size :55808 bytes
Type:  PE32 exe
Distribution: mostly web (worm - spreads through shares, drives, webpages etc)
 
MD5 120d845ac973b4a0cde2bc88d8530b3d
SHA1 120d845ac973b4a0cde2bc88d8530b3d
File size :87040 bytes
Type:  PE32 exe
Distribution: mostly web (worm - spreads through shares, drives, webpages etc)

MD5 150d006eab34528e3305fbbb5ad82164
SHA1 551a9f3ce5b86cf77df90eda61be233c821be6b2
File size :267776 bytes
Type:  PE32 exe
Distribution: mostly web (worm - spreads through shares, drives, webpages etc)



Download