Win32/Spy.Matles [Threat Name] go to Threat

Win32/Spy.Matles.A [Threat Variant Name]

Category trojan
Size 53248 B
Detection created Jul 26, 2009
Detection database version 4280
Aliases Backdoor.Win32.Agent.ailr (Kaspersky)
  TrojanSpy:Win32/Matles.A (Microsoft)
  Infostealer (Symantec)
Short description

Win32/Spy.Matles.A is a trojan that steals sensitive information. The trojan attempts to send gathered information to a remote machine.

Installation

When executed, the trojan copies itself into the following location:

  • C:\­Windows\­System32\­%malwarefilename%.exe

The file is then executed.


In order to be executed on every system start, the trojan sets the following Registry entry:

  • [HKEY_LOCAL_MACHINE\­SOFTWARE\­Microsoft\­Windows\­CurrentVersion\­Run]
    • "win32" = "%malwarefilepath%"
Information stealing

Win32/Spy.Matles.A is a trojan that steals sensitive information.


The trojan is able to log keystrokes.


The collected information is stored in the following file:

  • C:\­Windows\­System32\­log.log

The following information is collected:

  • computer IP address
  • computer name

The trojan attempts to send gathered information to a remote machine.


The trojan sends the information via e-mail. The SMTP protocol is used.

Please enable Javascript to ensure correct displaying of this content and refresh this page.