Home / malwarePDF  

HackTool:Win32/Dialupas


First posted on 01 November 2012.
Source: Microsoft

Aliases :

HackTool:Win32/Dialupas is also known as Trojan/Win32.Klone (AhnLab), Win32/PSWTool.Dialupass.F application (ESET), HackTool.Win32.Dialupas (Ikarus), not-a-virus:PSWTool.Win32.NetPass.boz (Kaspersky), Tool-PassView (McAfee), PasswordRevealer (Symantec).

Explanation :



HackTool:Win32/Dialupas is a tool that can steal the automatically stored passwords used to connect to the Internet using a dial up network.

It can run in hidden mode, without your knowledge. It stores the passwords in a text file. Its user interface may look like this:



In the wild, the following malware have been observed to steal passwords using this tool:

  • Backdoor:Win32/Fynloski.A
  • HackTool:MSIL/Binder.B
  • Trojan:Win32/Dusvext.B
  • Trojan:Win32/Recal
  • TrojanDropper:MSIL/VB.X
  • TrojanDropper:Win32/Agent.BAD
  • TrojanSpy:MSIL/VB.M
  • VirTool:MSIL/Injector.AQ
  • VirTool:MSIL/Injector.CW
  • VirTool:Win32/Obfuscator.NL
  • VirTool:Win32/Vbinder.CO
  • Worm:Win32/Autorun.ZG




Analysis by Mihai Calota

Last update 01 November 2012

 

TOP