Although the executable file, which Microsoft has labelled TrojanDownloader:Win32/Poison.A, only produces an error message on a computer not connected to the internet, once the malicious code has been successfully run it copies itself into a system folder and from there begins to keylog.
A modern virus scanner’s behaviour monitoring system should be alerted at this point. The spying functionality that is downloaded once an internet connection is present comes from the free “Poison Ivy” trojan builder tool, which can provide the payload directly as shell code.
Normally, a downloader pulls an executable file from the internet, saves it on the disk, and executes it – activity that should alert a virus scanner’s behaviour monitor. This example once again shows how important it is to install a virus scanner with a behaviour monitor.
No comments:
Post a Comment