Home Malware Programs Trojans HPmal/Zbot-C

HPmal/Zbot-C

Posted: January 29, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 5
First Seen: January 29, 2013
Last Seen: November 1, 2021
OS(es) Affected: Windows

HPmal/Zbot-C is a variant of Zbot Trojan that affects financial institutions based in Canada involving a company that processes payments from Point Of Sale devices and credit and debit cards. HPmal/Zbot-C will gather login credentials inserted into forms and embed a code into the websites so that attacked computer users reveal more information such as answers to secret questions, PIN numbers and mother's maiden name. HPmal/Zbot-C grabs the screen, accesses form field and logs keystrokes to gain information on the corrupted machine. A screenshot is captured each time the computer owner clicks the left mouse button while surfing the payment processing website. Each screen capture is focused on the mouse button and is sent back to the botnet owner. Form data is also gathered and sent back, incorporating usernames and passwords. The configuration files of HPmal/Zbot-C also involve a section called 'Keylogger processes' that provides a list of processes from which key strokes will be logged. Every time the attacked PC user enters usernames, passwords and card details into one of the programs all the keystrokes will be sent back to the botnet owner. Together with programs used for remote access such as SCP, Putty, GotoMyPC, VNC, and PCAnywhere, there are process names such as '*pos*', '*store*', '*sales*' and '*merchant*' that are possibly related to processing payment card data. HPmal/Zbot-C also attacks financial programs such as Quickbooks and Sage.

Loading...