<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://www.forensicswiki.org/w/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://www.forensicswiki.org/w/index.php?title=Win32.Shiz&amp;feed=atom&amp;action=history</id>
		<title>Win32.Shiz - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://www.forensicswiki.org/w/index.php?title=Win32.Shiz&amp;feed=atom&amp;action=history"/>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Win32.Shiz&amp;action=history"/>
		<updated>2013-05-21T09:18:31Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.20.3</generator>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Win32.Shiz&amp;diff=10754&amp;oldid=prev</id>
		<title>Keydet89 at 17:16, 29 March 2011</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Win32.Shiz&amp;diff=10754&amp;oldid=prev"/>
				<updated>2011-03-29T17:16:30Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
			&lt;tr style='vertical-align: top;'&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
			&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 17:16, 29 March 2011&lt;/td&gt;
			&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 10:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 10:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== In Russian ===&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;=== In Russian ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.nobunkum.ru/issue003/banker-attacks/ Attacks on online banking systems]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;* [http://www.nobunkum.ru/issue003/banker-attacks/ Attacks on online banking systems]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;=== English ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;#160;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;* [http://www.threatexpert.com/report.aspx?md5=826c855b440611a944e25f072a533ea3 ThreatExpert Report]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[[Category: Malware]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;[[Category: Malware]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Keydet89</name></author>	</entry>

	<entry>
		<id>http://www.forensicswiki.org/w/index.php?title=Win32.Shiz&amp;diff=10753&amp;oldid=prev</id>
		<title>.FUF: Created page with &quot;{{expand}}  ''Win32.Shiz'' (other name: ''Trojan.PWS.Ibank'') is a malicious program designed for online banking fraud.  Current versions of this program support almost all onlin...&quot;</title>
		<link rel="alternate" type="text/html" href="http://www.forensicswiki.org/w/index.php?title=Win32.Shiz&amp;diff=10753&amp;oldid=prev"/>
				<updated>2011-03-23T21:12:23Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{expand}}  &amp;#039;&amp;#039;Win32.Shiz&amp;#039;&amp;#039; (other name: &amp;#039;&amp;#039;Trojan.PWS.Ibank&amp;#039;&amp;#039;) is a malicious program designed for online banking fraud.  Current versions of this program support almost all onlin...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{expand}}&lt;br /&gt;
&lt;br /&gt;
''Win32.Shiz'' (other name: ''Trojan.PWS.Ibank'') is a malicious program designed for online banking fraud.&lt;br /&gt;
&lt;br /&gt;
Current versions of this program support almost all online banking systems in Russian Federation (BS-Client, Sberbank, etc) as well as many online poker clients.&lt;br /&gt;
&lt;br /&gt;
The program can be used to steal usernames and passwords used to access online banking system, cryptographic keys stored as files (e. g. on USB Flash drives or hard disk drives), URLs used to access online banking system and certificates stored in web-browsers. If online banking system uses access control lists based on IP addresses then Win32.Shiz can set up a SOCKS proxy-server on a compromised computer.&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
=== In Russian ===&lt;br /&gt;
* [http://www.nobunkum.ru/issue003/banker-attacks/ Attacks on online banking systems]&lt;br /&gt;
&lt;br /&gt;
[[Category: Malware]]&lt;/div&gt;</summary>
		<author><name>.FUF</name></author>	</entry>

	</feed>