Home / malwarePDF  

PWS:Win32/Cuepilini.A


First posted on 01 January 2015.
Source: Microsoft

Aliases :

There are no other names known for PWS:Win32/Cuepilini.A.

Explanation :

Threat behavior

PWS:Win32/OnLineGames.LH is a trojan that steals account information from popular online games and sends it to a remote server.

Installation

PWS:Win32/OnLineGames.LH is usually dropped as, and replaces the legitimate file "\ws2help.dll".

Note: refers to a variable location that is determined by the malware by querying the operating system. The default installation location for the System folder for Windows 2000 and NT is C:\Winnt\System32; and for XP, Vista, and 7 is C:\Windows\System32.

Payload

Steals online game information

PWS:Win32/OnLineGames.LH attempts to steal the following information:

  • User name
  • Password
  • Character information




Analysis by Chun Feng



Symptoms

There are no common symptoms associated with this threat. Alert notifications from installed antivirus software may be the only symptoms.

Last update 01 January 2015

 

TOP