Content

Uploader-AB

Type
Program
SubType
Win32
Discovery Date
01/25/2006
Minimum DAT
4682 (01/25/2006)
Updated DAT
4764 (05/17/2006)
Minimum Engine
5.1.00
Description Added
01/25/2006
Description Modified
03/03/2006 12:12 AM (PT)

Tab Navigation

Characteristics

Uploader-AB is a set of files that have the following names

"harvest.exe"
"sox1.exe"
"soxload.exe"

and are built using visual basic. Upon execution of "harvest.exe" which goes by the name "outlook wabber" harvests email addresses and visited url's as well as internet search keywords and logs them into a file "pstore.txt".

This file is created inside a folder by name "drv32dta" which is present in %Sysdir%.

(Where %Sysdir% is the Windows System directory, for example C:\WINDOWS\SYSTEM32)

The other components like 'sox1.exe" and "soxload.exe" could be related to
Proxy-wiper

Some of these files create batch files to delete the temporary files that they create. During analysis it was observed that the logged file "pstore.txt" was not uploaded to any site.

Aliases

Aliases

  • Trojan Horse - Symantec
  • Trojan-Spy.Win32.Sters.h - Kaspersky