|
|
BS Spy RAT Information
| Name: |
BS Spy |
| Category: |
RAT |
| Advice: |
Remove |
| Risk: |
Severe Risk
Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine. |
| Description:
|
B-S Spy is a RAT designed to steal information (passwords) from a remote user with the software unknowingly installed. B-S Spy steals passwords and transmits them via email to the attacker.
BS Spy is password-stealing Trojan horse. It collects user passwords for MSN Messenger or Yahoo! Messenger and sends them to the hacker. BS Spy is written in Microsoft Visual Basic version 6.
B-S Spy works on Windows 95, 98, ME, NT, 2000 and XP, and is designed to work together with Microsoft MSN Messenger and Yahoo! Messenger.
The Trojan uses the same icon as MSN Messenger or Yahoo! Messenger in an attempt to disguise itself as those programs.
B-S Spy is difficult to detect by design. May hide from process list. May install with variable names in variable locations.
|
| Signatures:
|
process: b-s editserver.exe: MD5 Hash: a79e2b6cb6fc7af87f6...
process: msn-server.exe: MD5 Hash: 929b8f2fcb0a7b1045a...
process: net-server.exe: MD5 Hash: d49bb4299e472c4e6af...
process: ya-server.exe: MD5 Hash: cf66abd583d9e73f5eb...
process: msmsngs.exe: MD5 Hash: ...
process: ypager.exe: MD5 Hash: ...
process: yupdater.exe: MD5 Hash: ...
process: msmsngs.exe: MD5 Hash: ...
process: ypager.exe: MD5 Hash: ...
process: yupdater.exe: MD5 Hash: .. |
| Type: |
RAT - A Trojan software is any software on a user's computer that the user is not aware or intentionally installed. Most Trojan software is designed to perform some sort of actions that could jeopardize the user's security or privacy. |
Top RAT Visited Pages:
SubSeven - Alias: BackDoor-G22, BackDoor-Sub7 - 292 visits
NetBus v.1.70 - 207 visits
The Prayer - Alias: BackDoor-DI, Backdoor.Prayer.15 - 75 visits
Cyrex msn trojan - Alias: BackDoor-AOB, Backdoor.VB.dm, Backdoor.VB.dm, Cyrex msn trojan, W32/Delf.B - 69 visits
Global Killer - Alias: Backdoor.GlobalKiller 1.0, Global Killer 1.0 - 54 visits
Systray BackDoor - 52 visits
AutoSpY - Alias: Backdoor.AutoSpy - 47 visits
Secret Agent - Alias: Backdoor.Antinuke.10, Secret Agent 1.0 - 46 visits
Undetected - Alias: Backdoor.tds.4f, Backdoor.tds.se.23, Backdoor.tds.se.23a, Backdoor.tds.se.30, Backdoor.TDS.SE.31, Ba - 41 visits
Netbus - Alias: Backdoor.Netbus - 41 visits
Random RAT Pages:
EES Streaming Audio Trojan - Alias: W32/StreamingAudio
Sect
Traitor21 - Alias: Backdoor.Traitor
Intruzzo - Alias: Backdoor.Intruzzo, Backdoor.Intruzzo.b, Backdoor.Intruzzo.d, Intruder
H2000 - Alias: Backdoor.Mnets
FraggleRock - Alias: BackDoor-LT, Backdoor.FR.155, Backdoor.Fraggle.143, Backdoor.Fraggle.144, Backdoor.Fraggle.150, Back
Prosiak
CoolCat
Akosch - Alias: Backdoor.Akosch m1-4)
Chacara Corporation Invader 2
|
|