Threat Database Worms W32.Pixipos

W32.Pixipos

By GoldSparrow in Worms

Threat Scorecard

Ranking: 16,674
Threat Level: 10 % (Normal)
Infected Computers: 97
First Seen: April 3, 2014
Last Seen: August 15, 2023
OS(es) Affected: Windows

W32.Pixipos is a worm that steals private details from point of sales systems and proliferates through removable drives using the potentially infected files. Once executed, W32.Pixipos creates the potentially infected file. W32.Pixipos creates the registry entry so that it can load automatically whenever the PC user boots up Windows. W32.Pixipos collects data from point of sales (PoS) systems and uploads the data to the distant location.

File System Details

W32.Pixipos may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\win.sxs
2. %DriveLetter%\autorun.inf

Registry Details

W32.Pixipos may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Taskbar" = "%UserProfile%\Application Data\win.sxs"

URLs

W32.Pixipos may call the following URLs:

Yo.u-know-who.com/ss/gate.php

Trending

Most Viewed

Loading...