Infection Channel: Downloaded from the Internet
This malware was seen to include a password recovery tool that steals information stored in browsers.
To get a one-glance comprehensive view of the behavior of this Spyware, refer to the Threat Diagram shown below.

For the related story, you may read the blog post HTTPS, SSL No Match for PASSTEAL Malware.
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File size: 270,336 bytes
File type: EXE
Memory resident: Yes
Initial samples received date: 31 Oct 2012
Payload: Steals information
Arrival Details
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This spyware drops the following files:
- %User Temp%\{random}.exe (also detected as TSPY_PASSTEAL.A)
- %User Temp%\cvtres.exe
- %System Root%\DOCUMENTS
- %User Profile%\Application Data\{computer name}.txt (stolen credentials)
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003, or C:\Users\{user name}\AppData\Local\Temp on Windows Vista and 7.. %System Root% is the root folder, which is usually C:\. It is also where the operating system is located.. %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.)
Drop Points
This spyware uploads files to the following File Transfer Protocol (FTP) sites:
- ftp://{BLOCKED}.{BLOCKED}.67.232
NOTES:
This spyware steals user names and password stored in the Firefox browser.
Connect with us on
| | | |