We recently came across a Trojan that steals image files of .jpg, .jpeg extensions, and Windows memory dumps (.dmp) from victims’ machines and uploads them to an FTP address hardcoded in the malware. This Trojan silently opens a command line and copies those image files found on the C, D, and E drives to the Read more…
Tags: dmp stealing, Image stealing, image stealing trojan, image theft, images uploaded to FTP, JPEG, jpg, PixSteal Trojan, steganography
As we see new threats arrive daily employing unique and complex capabilities, it is surprising to find a Swedish bot using a control server that was active in 2009. Generally malware authors keep changing their control servers–especially after reports about them surface–but not in this case. This network belongs to prq.se, which hosts at IP Read more…
Posts tagged under jpg