banking spyware: which browser/OS and which banks ?

From: Stanley Long <slong@customcpu.com>
Date: Thu Jul 01 2004 - 08:44:29 AKDT

June 30 InternetStormCenter
http://isc.sans.org/index.php?isc=d34d1e3735b849f101349c9c483f6906
BHO (Browser 'Helper' Object)
While BHOs *are* specific to IE, Mozilla based variants have
"extensions", and all other browsers have a means to extend their
functionality.

 ... As far as we know, the binary will only run in Windows.
   {does this imply Mozilla and/or FireFox don't protect Windows? }
-------------------------------------------

 { the BHO catch-list of bank URLs - ref: page 5}

        http://isc.sans.org/presentations/banking_malware.pdf

 { .pdf of logs and analysis showing interception of UUID and password
info before they get encrypted by user's machine - ref: page 8}

---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Thu Jul 1 08:33:37 2004

This archive was generated by hypermail 2.1.8 : Thu Jul 01 2004 - 08:33:37 AKDT