Mo-logger 1.0
(Trojan-Spy.Win32.Banker.gmp)

by Cool_Mofo_2

Released in July 2007

 





Server:
dropped file:
c:\WINDOWS\system\isas32.exe
size: 90,293 bytes 

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Update"
data: C:\WINDOWS\system\isas32.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Update"
data: C:\WINDOWS\system\isas32.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce "Windows Update"
data: C:\WINDOWS\system\isas32.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx "Windows Update"
data: C:\WINDOWS\system\isas32.exe 


tested on Windows XP
July 24, 2007

MegaSecurity