Hey guys, I'm very nooby when it comes to malware in general, so I figured this would be a good place to ask about this. So I had this infection way back some time ago, and I was wondering about its exact capabilities.
1. First of all, I can't even find any specifics on E.VBR. Is it the same as what Microsoft calls Alureon.E? (It was malwarebytes that detected it as E.VBR) Generally speaking, it seems like every website has a different description of the Alureon family. Does anybody know about this specific variant.
2. It appears to be one of the infections that steals information, like usernames and passwords/browsing habits. A few sources said they intercept this from network traffic, the microsoft page says it "gathers URLs from browsing history" and others say its a DNS changer so they spoof sites so you'll type your info in. It seems like there are so many differences, and I get that there are different variants and stuff, but there doesn't seem to be a consensus on how they steal the info. Does anybody know? Is there a way to find out?
3. This is a super dumb question, but where does the info that is stolen go? Does it go to a server that everybody else who uses alureon can access? Or is it just one guy running the entire alureon show? Or is there some public place like "alureonleaks.com" that post all the stuff they find (the stuff they probably can't sell) ?
I have more noob questions, so if anybody knows anything about the above, or just want to engage in some delightful discussion with a noob, please let me know!
1. First of all, I can't even find any specifics on E.VBR. Is it the same as what Microsoft calls Alureon.E? (It was malwarebytes that detected it as E.VBR) Generally speaking, it seems like every website has a different description of the Alureon family. Does anybody know about this specific variant.
2. It appears to be one of the infections that steals information, like usernames and passwords/browsing habits. A few sources said they intercept this from network traffic, the microsoft page says it "gathers URLs from browsing history" and others say its a DNS changer so they spoof sites so you'll type your info in. It seems like there are so many differences, and I get that there are different variants and stuff, but there doesn't seem to be a consensus on how they steal the info. Does anybody know? Is there a way to find out?
3. This is a super dumb question, but where does the info that is stolen go? Does it go to a server that everybody else who uses alureon can access? Or is it just one guy running the entire alureon show? Or is there some public place like "alureonleaks.com" that post all the stuff they find (the stuff they probably can't sell) ?
I have more noob questions, so if anybody knows anything about the above, or just want to engage in some delightful discussion with a noob, please let me know!