Torpig

Dies ist eine alte Version dieser Seite, zuletzt bearbeitet am 16. Januar 2011 um 13:26 Uhr durch Yobot (Diskussion | Beiträge) ({{Expand}} cleanup + general fixes using AWB (7548)). Sie kann sich erheblich von der aktuellen Version unterscheiden.

Torpig, also known as Sinowal or Anserin (mainly spread together with Mebroot rootkit), is a type of botnet spread by a variety of trojan horses which can affect computers that use Microsoft Windows. Torpig circumvents anti-virus applications through the use of rootkit technology and scans the infected system for credentials, accounts and passwords as well as potentially allowing attackers full access to the computer. It is also purportedly capable of modifying data on the computer.

As of November 2008 it has been responsible for stealing the details of about 500,000 online bank accounts and credit and debit cards and is described as "one of the most advanced pieces of crimeware ever created".[1]

In early 2009, a team of security researchers from University of California, Santa Barbara took control of the botnet for ten days. During that time, they extracted an unprecedented amount (over 70GB) of stolen data and redirected 1.2 million Ip's on to their private comand and control server. The report[2] goes into great detail about how the botnet operates.

See also

References

Vorlage:Reflist

Vorlage:Botnets

  1. BBC News: Trojan virus steals bank info
  2. UCSB Torpig report