Home / malwarePDF  


First posted on 24 July 2014.
Source: Symantec

Aliases :

There are no other names known for Infostealer.Ecsudown.

Explanation :

When the Trojan is executed, it creates the following file:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\mscsres.exe

The Trojan connects to one of the following servers:
The Trojan monitors Internet Explorer and attempts to steal online banking credentials from specific websites.

The Trojan sends the stolen information to one of the following remote servers:
The Trojan accesses one of the following websites to obtain an encrypted configuration file:
Note: The configuration file contains a URL to an updated version of the Trojan.

Last update 24 July 2014