|From: PDF@Exploit| |To: Zeus@Trojan| |Subject: Steals Bank Credentials|

Written by traversecode on . Posted in Bot Analysis, Exploit Analysis, Malware Analysis

INTRODUCTION: I guess the Title would say what this post will contain. This post explains how an Exploit code embedded in PDF uses a Vulnerability and installs a Zeus Trojan in a victims machine and what banks the Trojan targets to steal user credential. THE FLOW: In the above Diagram, the user is either Social Engineered or visits malicious website and happen to view a malicious PDF doc which contains the exploit code. Based on the version of Adobe Reader used by the user,

Get – ‘Site’ – Go

Written by traversecode on . Posted in Exploit Analysis

Introduction:When we say ‘Internet’ the word that immediately strikes our mind is ‘Browser’. Browser acts as a Major component in the Cyber world. From layman to professionals use browser for different needs. Checking mails, online banking transactions, browsing forums, booking tickets, online shopping, ordering pizza, etc are done using browser. When we talk about banking transactions, online tickets, online shopping we’ve to understand how secured we are without exposing our sensitive

Trojan.MalScript!html

Written by traversecode on . Posted in Exploit Analysis

Introduction: This Analysis report will explain in detail on how a Malscript is used to infect users and how this code is injected in the web server. It explains a tricky technique used by the Malware writer. Analysis of Malscript Injected website: Screen shot of the Website: When users view the above website it loads all the contents of the page, more likely it loads CSS (Cascading Style Sheets) which carries the encoded malicious code. This doesn’t mean that CSS itself is malicious,