
SonicWALL UTM Research team saw a new spam campaign pretending to contain a Debt Invoice, starting July 16, 2009. The spammed e-mail message is in Spanish and contains a fake invoice attachment which is the new ZBot Downloader Trojan.
English Translation of the e-mail:
Attachment: Factura66.zip (contains Factura66.doc .exe)
Subject: Outstanding debt
Email Body:
------------------------
Please note that an invoice is outstanding.
------------------------
The executable file inside the zip attachment has an icon disguised as a Microsoft Word document and it looks like following:
The original e-mail message looks like:
The Downloader Trojan when executed performs following activity:
The new ZBot variant performs following activity:
The Downloader Trojan is also known as Win32/TrojanDownloader.Delf.OVB trojan , Trojan-Spy:W32/Zbot.OWF , and Trojan.Win32.Regrun .
SonicWALL Gateway AntiVirus provides protection against this malware via GAV: Regrun.DGJ (Trojan), GAV: Zbot.JF_10 (Trojan) and GAV: Zbot.TE (Trojan) signatures.
Share This Article

An Article By
An Article By
Security News
Security News