data:image/s3,"s3://crabby-images/b9bbd/b9bbdcc60482ec0272ad1f623a8b36b37bd404b4" alt=""
Basically, SpyEye uses a daemon for Linux. It listens on a specific port, collect logs and store information in database. The logs use special compression library termed as LZO for real time data compression. Actually, the LZO is primarily known for its speed over compression ratio. The compression in itself is really fast in LZO and it does not require any memory for decompression. LZO use algorithms that are thread safe, lossless and portable. This provides a glimpse of high compression used for log transmission over the internet from the bots to the backend collector daemon. This simply sets the traffic control in a strict manner thereby economize traffic to transfer logs directly without much interference.
The SpyEye collector looks like as follows
data:image/s3,"s3://crabby-images/13f3b/13f3b6861c627d133319a827cb5a8d61c1856abd" alt=""
SpyEye has its own SDK and development platform which is designed for generating plugins for infecting victims and stealing specific information. Through plugins, data can be easily transferred to collector. SpyEye provides relative function as a part of its API as follows
void TakeGateToCollector(LPVOID lpGateFunc);
This function is used in the SpyEye plug-in development as follows
data:image/s3,"s3://crabby-images/afb1c/afb1c6ca2863605b8ed4ab4c487b58a22ef59533" alt=""
The page is dumped as
data:image/s3,"s3://crabby-images/42473/42473919081861a4ac0a10933bef8ea59bbc30ce" alt=""
The collector is configured in the builder part of SpyEye as follows
data:image/s3,"s3://crabby-images/f2130/f2130673b2052e1af64579c3293f703952b49409" alt=""
The collected logs provide statistics as follows
data:image/s3,"s3://crabby-images/6b951/6b95136b8c1dd423fb944081b60098e08ea208ec" alt=""
SpyEye uses a good technique and provision of storing information irrespective of user centric access.