
Updated on August 02, 2010 11:30 AM PST
SonicWALL UTM Research team has observed an increase in spam campaigns involving new variants of Zeus banking Trojan in last 24 hours. These spam campaigns included two new themes like Social Security Annual statement pretending to be arriving from Social Security Administration and Fraudulent Credit Card transaction report pretending to arriving from ATM Electronic Report system.
SonicWALL has received more than 100,000 e-mail copies from these spam campaigns till now. The email messages in all these spam campaigns have a zip archived attachment which contain the new variants of Zbot Trojan executable. The sample e-mail format from each spam campaign is shown below:
Campaign #1 - Social Security Annual statement
Attachment: statement.zip (contains statement.exe)
Subject: Review your annual Social Security statement
Email Body:
------------------------
Due to possible calculation errors, your annual Social Security statement may contain errors.
Open attached file to review your annual Social Security statement.
------------------------
The email message looks like:
Campaign #2 - Fraudulent Credit Card Transaction report
Attachment: report.zip (contains report.exe)
Subject: Possible Fraudulent Transaction
Email Body:
------------------------
Dear VISA card holder,
A recent review of your transaction history determined that your card was used at an ATM located in Peru, but for security reasons the requested transaction was refused.Please carefully review electronic report for your VISA card (attach to this letter)
------------------------
The email message looks like:
Campaign #3 - Password Reset
Attachment: password.zip (contains password.exe)
Subject: Password Reset Confirmation
Email Body:
------------------------
Hello,
Because of the measures taken to provide safety to our clients, your password has been changed. You can find your new password in attached document.
Thanks,
------------------------
The email message looks like:
The executable files inside the attachment looks like:
If the user downloads and executes the malicious executable inside the zip attachment, it performs following activity:
SonicWALL Gateway AntiVirus provided proactive protection against above spam campaigns by following signatures:
SonicWALL UTM Research team observed a big spike in the Zeus spam campaign over the weekend and SonicWAL Gateway AntiVirus continued to provide proactive protection via following signature:

Share This Article

An Article By
An Article By
Security News
Security News