PSW.Tepfer.gen Details

  • Category PSW
  • Discovered 3/15/2019 7:53:02 PM
  • Modified 3/18/2019 2:32:20 PM
  • Threat Level Low
  • Category Description
    This family of Trojans steals passwords, normally system passwords from victim machines. They search for system files which contain confidential information such as passwords and Internet access telephone numbers and then send this information to an email address coded into the body of the Trojan. The 'master' or user of the illegal program will then retrieve and misuse this information. Most common behavior: 1. Ask for password using fake window 2. Change ICQ, MSN and AOL configuration 3. Get cached Windows passwords

The following Files were created:
..\ExtractedData\Virussing Data\20130723\samples\exe32\virussign.com_96ef4ebd5ee45fadeac0f2229e0b5e0f.vir.exe 93696  96ef4ebd5ee45fadeac0f2229e0b5e0f
..\Download\18 july\samples\exe32\virussign.com_e25648928b4a8256f441e29e458a66a0.vir.exe 93696  e25648928b4a8256f441e29e458a66a0
..\Download\20 july\samples\exe32\virussign.com_7c3e14729a66c2ea16326974c960c720.vir.exe 93696  7c3e14729a66c2ea16326974c960c720
..\Extracted Data\July\13\samples\exe32\virussign.com_e69b03ba0d14125c5a266c664c54e5a4.vir.exe 93696  e69b03ba0d14125c5a266c664c54e5a4
..\ExtractedData\Virussing Data\20130723 II\virussign.com_20130723_professional_05\samples\exe32\virussign.com_0d78300a5a570f61cc16843a2e7b7d2a.vir.exe 93696  0d78300a5a570f61cc16843a2e7b7d2a
..\Download\20 july\samples\exe32\virussign.com_66f8dc82710559f8af57572b0f6f1aa2.vir.exe 93696  66f8dc82710559f8af57572b0f6f1aa2
..\ExtractedData\Virussing Data\20130723\virussign.com_20130723_professional_01\samples\exe32\virussign.com_7cebeb26bb3055acb3e1954fd09e5426.vir.exe 93696  7cebeb26bb3055acb3e1954fd09e5426
..\Download\18 july\samples\exe32\virussign.com_2a5ca9bf81b6b82fb9c53daf4902fd72.vir.exe 93696  2a5ca9bf81b6b82fb9c53daf4902fd72
..\Download\20 july\samples\exe32\virussign.com_0a6cf80076dd1542dff56d9220c3ec12.vir.exe 93696  0a6cf80076dd1542dff56d9220c3ec12
..\Extracted Data\July\13\samples\exe32\virussign.com_eafc17b5810132abd632ffd83fb81bd1.vir.exe 93696  eafc17b5810132abd632ffd83fb81bd1

The following Registry Entries were created:

