Home / malwarePDF  

Nilage.AUT


First posted on 01 March 2007.
Source: SecurityHome

Aliases :

Nilage.AUT is also known as Trojan-PSW.Win32.Nilage.aut, Trj/Lineage.BLQ, TSPY_NILAGE.AUT.

Explanation :

Nilage.AUT, a variant of Nilage, is a Trojan. Nilage.AUT drops and loads a password stealing component on an infected system and steals sensitive information from an infected computer. Nilage.AUT attempts to download and install other malware to the system.

Once Nilage.AUT has been executed it will drop the following file:



It will register its DLL component as a Browser Helper Object (BHO) so that every time Internet Explorer is loaded, Nilage.AUT is also loaded:



Everytime the DLL component is executed, it will drop and execute its .EXE component in the following path and filename:



Payload

The main payload of Nilage.AUT is to steal information regarding Online games such as Lineage and Maple Story. Both are popular in Korea.

Nilage.AUT includes keylogging functionality.

Nilage.AUT steals information with regards to the following details:

Class Names



Running Process Names



Visited URL:



The gathered information including username and passwords are stored in this hard coded path and filename:



Gathered information is sent to the hacker by posting the file to the following links:



It also gathers data from these links for it malicious acts:



Asside from being a password stealer, Nilage.AUT is also a downloader. It downloads and executes other malware from the following link:


And saves the download to the following path name filename:


To ensure that an error will not occur, it will delete the existing file before downloading the new file.

Note: As of this writing the link above is no longer available.


Nilage.AUT does not fully support all operating system:



Nilage.AUT is coded using Borland Delphi.

Last update 01 March 2007

 

TOP

Malware :

Family: