W32/Heloc| Name | W32/Heloc | | Aliases | Webber, TrojanProxy.Win32.Webber, W32/Heloc-mm | | Discovered on | 16th July 2003 |
Virus Information - W32/Heloc:
W32/Heloc is a mass mailing trojan. This
trojan will infect Windows systems. The trojan spreads through email.
The subject of the infected mail will be;
Re: Your credit application
The body of the mail will be :
Dear sir,
Thank you for your online
application for a Citibank Home Equity Loan. In order to be approved for
any loan application we pull your Credit Profile and Chexsystems information,
which didn't satisfy our minimum needs. Consequently, we regret to say
that we cannot approve you for Citibank Home Equity Loan at this time.
*Attached are copy of
your Credit Profile and Your Application that you submitted with us. Please
take a close look at it, you will receive hard copy by mail withing next
few days.
The infected attachment will be;
web.da.us.citi.heloc.pif
Upon execution of the infected attachment, the trojan downloads
a file to Windows System folder from a pre-configured website and executes
it. This is a proxy server component, which will be hidden. The trojan
collects the cached password and IP address of the infected computer and
passes the same to the pre-configured website.

|