Threat Database Trojans TSPY_ZBOT.BBH

TSPY_ZBOT.BBH

By Sumo3000 in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 202
First Seen: May 24, 2013
Last Seen: January 20, 2023
OS(es) Affected: Windows

TSPY_ZBOT.BBH is a Trojan with spyware functionalities that aims at stealing information, such as user names and passwords, used when logging into particular banking or finance-related websites. TSPY_ZBOT.BBH may be unknowingly downloaded by a computer user while visiting the infected websites. TSPY_ZBOT.BBH embeds itself into the processes 'dwm.exe', 'rdpclip.exe', 'ctfmon.exe', 'wscntfy.exe', 'taskeng.exe' and 'taskhost.exe ' as part of its memory residency routine. TSPY_ZBOT.BBH adds the registry entries so that it can be executed automatically whenever the computer user starts the PC. TSPY_ZBOT.SMD also makes other system changes by adding the registry keys. TSPY_ZBOT.BBH also downloads the malevolent files. TSPY_ZBOT.BBH connects to the specific domains to download its configuration file. TSPY_ZBOT.BBH transfers the grabbed information via HTTP POST to the particular web address.

File System Details

TSPY_ZBOT.BBH may create the following file(s):
# File Name Detections
1. %Application Data%\[RANDOM CHARACTERS1]\[RANDOM CHARACTERS].exe
2. %Application Data%\[RANDOM CHARACTERS2]\[RANDOM CHARACTERS].[RANDOM CHARACTERS]

Registry Details

TSPY_ZBOT.BBH may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\[RANDOM CHARACTERS]
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run [RANDOM CLSID] = %Application Data%\[RANDOM CHARACTERS1]\[RANDOM CHARACTERS].exe

Trending

Most Viewed

Loading...