Home Malware Programs Remote Administration Tools Espionage

Espionage

Posted: March 28, 2006

Espionage is a very dangerous RAT virus, designed for remote
controlling of the infected PC and spying on user activity. The application
includes such dangerous functions as "Anti Virus killer" and "Firewall
killer". It can disable almost any AV and Firewall protection. This
virus can be used as HTTP server. It means that the intruder can use
his web browser to view and steal all the information, stored in
victim's PC. This RAT also has a "surveillance" function. It uses
victim's webcam and microphone to spy on user. It also logs keystrokes
and makes screenshots from the infected PC. The author of this pest is
a hacker called erebus. The application was created in Visual Basic and
compressed with ASPack. Several versions originated (Espionage

File System Modifications

  • The following files were created in the system:
    # File Name
    1 cap.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunwinsvchost
Loading...