
SonicWALL UTM Research team observed a new wave of the Fake CDC H1N1 program spam campaign starting today morning. The e-mail contains a URL pointing to a fake CDC website that hosts the new variant of ZBot Trojan. This is the first time SonicWALL has seen U.S. Center of Disease Control as a spoofed institution.
The email pretends to arrive from U.S. Centers for Disease Control & Prevention and informs the user about launch of a State Vaccination H1N1 program. It advises the user to create their personal H1N1 vaccination profile on CDC website for which the URL is contained in the e-mail. If the user clicks on this URL, it leads to a fake CDC website that asks the user to download their H1N1 vaccination profile document archive. This leads to the download of an executable file vacc_profile.exe which is the new ZBot Trojan variant.
The e-mail looks like:
Subject:
Email Body:
------------------------
You have received this e-mail because of the launching of State Vaccination H1N1 Program.
You need to create your personal H1N1 (swine flu) Vaccination Profile on the cdc.gov website. The Vaccination is not obligatory, but every person that has reached the age of 18 has to have his personal Vaccination Profile on the cdc.gov site. This profile has to be created both for the vaccinated people and the not-vaccinated ones. This profile is used for the registering system of vaccinated and not-vaccinated people.
Create your Personal H1N1 Vaccination Profile using the link:
create personal profile
------------------------
The e-mail message looks like below:
The site that opens up when user clicks on the URL inside the e-mail is shown below:
As seen in the screenshot the malicious site prompts the user to download and open the Profile documente which in reality is the malware executable file:
The new ZBot variant performs following activities upon execution:
(Copy of itself)
The Trojan is also known as trojan Trojan.Win32.Scar.auxg and TR/Crypt.XPACK.Gen .
SonicWALL Gateway AntiVirus provides protection against this malware via GAV: Zbot.BFV (Trojan) signature.
Share This Article

An Article By
An Article By
Security News
Security News