Home / malwarePDF  


First posted on 21 February 2014.
Source: Symantec

Aliases :

There are no other names known for Infostealer.Rezbau.

Explanation :

The Trojan is spread through spam emails.

When the Trojan is executed, it copies itself to the following location:
%UserProfile%\Startup\[THREAT FILE NAME].exe

Note: [THREAT FILE NAME] may be any of the following legitimate file names:
The Trojan gathers the following information from the compromised computer:
CPU informationHost nameInstalled programsOperating system informationStartup informationTimezoneUser nameScreenshots

The Trojan may then send the gathered information to the following remote locations:

Last update 21 February 2014