|
Gip 1.13 Password Hijacker Information
| Name: |
Gip 1.13 |
| Category: |
Password Hijacker |
| Advice: |
Remove |
| Risk: |
High Risk
High risk threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction. May open up communication ports, use polymorphic tactics, stealth installations, and/or anti-spy counter measures. May use a security flaw in the operating system to gain access to your computer. |
| Description:
|
A variant of the Key Logger that captures passwords as they are entered or transmitted.
Sends information about system Work on Windows 95/98/2000/NT. Get dial-up passwords with ISP Phone numbers. Get passwords from Icq99a/Icq99b/2000a. Get passwords from edit boxes Auto Send mails every X days Auto-update, so victim always have the newest veOpen the URL "http://spiders.stsland.ru/trojans.html". It will a web-page now click on the "download" link of 'Gip Wizard'. It will open the 'File Download' dialog box click on save button to save a .zip file "gip.zip". Unzip the file in a folder and Double click the file "Config.exe" and "GipWizard.exe" to install/run the Spyware.
|
| Signatures:
|
process: Config.exe: MD5 Hash: 768209a23de8c03d481...
process: Config.exe: MD5 Hash: 768209a23de8c03d481...
process: GIP113doc.exe: MD5 Hash: 16b88fcfee162c85fb0...
process: GIP113doc.exe: MD5 Hash: 16b88fcfee162c85fb0...
process: GIP113jpg.exe: MD5 Hash: 3793f94d9cc35425c2b...
process: GIP113jpg.exe: MD5 Hash: 3793f94d9cc35425c2b...
process: GipWizard.exe: MD5 Hash: f1f3f1bd62e79d48615...
process: GipWizard.exe: MD5 Hash: f1f3f1bd62e79d48615...
process: GIP113jpg.exe: MD5 Hash: 0f1f3d33b1229a38a43...
process: GIP113jpg.exe: MD5 Hash: 0f1f3d33b1229a38a43...
process: winupdate.exe: MD5 Hash: a46ec6c1becc50ef8e8...
process: GIP113jpg.exe: MD5 Hash: 3793f94d9cc35425c2b...
process: Gip1131.exe: MD5 Hash: bbbef6e66d6069374c1...
process: Gip1131.exe: MD5 Hash: bbbef6e66d6069374c1.. |
| Type: |
Password Hijacker - |
Top Password Hijacker Visited Pages:
Hotmail Hacker X-Edition - 976 visits
MSN Hotmail Password Stealer - Alias: PWS-Kcom.gen, Trojan.PSW.Akcom.g - 862 visits
Y! Jacked v1.3 - 569 visits
Magic PS Yahoo! Messenger - Alias: Trojan.PSW.Sagic, Trojan.PSW.Sagic.11 - 543 visits
Fake login Yahoo - 326 visits
Passware Kit - 288 visits
Cache Password - 196 visits
Ace Password Sniffer 1.1 - 80 visits
PassView - 78 visits
Matiteman Mail Pass Stealer - Alias: Trojan.PSW.Mtmpas.b - 76 visits
Random Password Hijacker Pages:
Trojan-PSW.Win32.Antigen.a
Real McCoy AIM Password Stealer
Sincom Trojan
Frame4
Ace Password Sniffer 1.1
Kcom.gen - Alias: PWS-Kcom.gen, Trojan.PSW.Akcom.f
PSW.Stealth.d - Alias: PWS-AC, W32/CIH.1003.A
TheRipperz IP Mail Notifier - Alias: Backdoor.BadCo.10, BadCo
New Moscow Mail Trojan - Alias: Trojan.PSW.Platan.5.d, Trojan.PSW.Nemotron for Configurator.exe
GLXview
|