
SonicWALL UTM Research Team observed a new ZBot variant being distributed in the wild via drive-by download sites.
This ZBot variant was first seen in the wild on December 31, 2008 via following malicious site:
The malware when executed performs following tasks:
This ZBot variant is also known as Trojan-Spy.Win32.Zbot.ipx (Kaspersky), Win32/Spy.Zbot.DH (ESET), and Generic PWS.y (McAfee). SonicWALL Gateway Antivirus detects this ZBot variant as GAV: ZBot.IPX (Trojan)
Share This Article

An Article By
An Article By
Security News
Security News