Analysis by: Michael Cabel

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Spyware

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It steals certain information from the system and/or the user.

  TECHNICAL DETAILS

File Size: 14,336 bytes
File Type: DLL
Memory Resident: Yes
Initial Samples Received Date: 03 Nov 2011

Arrival Details

This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This spyware injects itself into the following processes as part of its memory residency routine:

  • lsass.exe

Information Theft

This spyware steals the following information:

  • Logon Type
  • Message Type
  • Domain
  • User Name
  • Password