Welcome to the Virus Encyclopedia of Panda Security.
It spreads and affects other computers.
It sends the information it has captured to a remote user.
It affects the productivity of the computer, the network to which it’s connected or other remote sites.
It uses anti-monitoring techniques in order to prevent it being detected by antivirus companies.
, via email.
|First detected on:||March 16, 2006|
|Detection updated on:||March 16, 2006|
Brontok.AL is a worm that spreads by copying itself, without infecting other files.
It captures certain information entered or saved by the user, with the corresponding threat to privacy:
It sends the gathered information to a remote user by any available means: email, FTP, etc.
It affects productivity, preventing tasks from being carried out:
- In the affected computer:
it displays pop-up windows; causes system slowdowns; it converts the computer into a platform for taking malicious action surreptitiously: spam sending, launch of Denial of Service attacks, malware distribution, etc.
It uses several methods in order to avoid detection by antivirus companies:
- Its code is encrypted and it is only decrypted when it is going to run. Because of this, its code is not legible through a memory dump.
Brontok.AL uses the following propagation or distribution methods:
- Exploiting vulnerabilities with the intervention of the user: exploiting vulnerabilities in file formats or applications. To exploit them successfully it needs the intervention of the user: opening files, viewing malicious web pages, reading emails, etc.
- Email: sending emails that include a copy of itself as an attachment. The computer is infected when the attachment is run.