PSW.QQPass.comr Details

  • Category PSW
  • Discovered 7/8/2017 8:07:19 AM
  • Modified 7/10/2017 12:05:05 PM
  • Threat Level Low
  • Category Description
    This family of Trojans steals passwords, normally system passwords from victim machines. They search for system files which contain confidential information such as passwords and Internet access telephone numbers and then send this information to an email address coded into the body of the Trojan. The 'master' or user of the illegal program will then retrieve and misuse this information. Most common behavior: 1. Ask for password using fake window 2. Change ICQ, MSN and AOL configuration 3. Get cached Windows passwords

The following Files were created:
..\ExtractedData\Virussing 20150319 FREE STD 12345\samples\exe32\virussign.com_118b22afe646713803c573e1378f4551.vir.exe 76300  118b22afe646713803c573e1378f4551
..\ExtractedData\Virussing 20150319 FREE STD 12345\samples\exe32\virussign.com_0f5fdaea4b5e509573e5d2e8e0c09a81.vir.exe 76300  0f5fdaea4b5e509573e5d2e8e0c09a81
..\ExtractedData\Virussing 20150319 FREE STD 12345\samples\exe32\virussign.com_113fa478846e713fee14083fc7922234.vir.exe 76300  113fa478846e713fee14083fc7922234
..\Extracted data\Virussign PRO 20150318 123\samples\exe32\virussign.com_06c1c186bab0ca7ee5a8b03296f61f06.vir.exe 76300  06c1c186bab0ca7ee5a8b03296f61f06
..\Extracted Data\Virussing PRO 20150319 123\samples\exe32\virussign.com_1267661dae17f63a068d8203d06e4398.vir.exe 76300  1267661dae17f63a068d8203d06e4398
..\ExtractedData\Virussing FREE STD 20150318 12345\samples\exe32\virussign.com_02990e79523b7f9019d37f1bf9257c42.vir.exe 76300  02990e79523b7f9019d37f1bf9257c42
..\Extracted Data\Virussing 20150310 STD 12345 PRO 123\samples\exe32\virussign.com_0c1351a1829ae4b009a648001b494ef1.vir.exe 76300  0c1351a1829ae4b009a648001b494ef1
..\ExtractedData\Virussing FREE STD 20150318 12345\samples\exe32\virussign.com_0119bf8ad75fa975b07148336fc17325.vir.exe 76300  0119bf8ad75fa975b07148336fc17325
..\Extracted Data\Virussing PRO 20150319 123\samples\exe32\virussign.com_101e7d5c3f85897a8a28a4f9193e82c8.vir.exe 76300  101e7d5c3f85897a8a28a4f9193e82c8
..\Download Data 1\virussign.com_20150319_Professional_05\samples\exe32\virussign.com_110fcd7fd6b681a6206630eb91e2e35a.vir.exe 76300  110fcd7fd6b681a6206630eb91e2e35a

