
SonicWALL UTM Research team continued to monitor the Bredolab email spam campaigns with the theme related to popular social networking website Facebook and courier service DHL. These spam campaign related emails started appearing early morning today and were still being spammed at the time of writing this alert.
SonicWALL has already received more than 400,000 e-mail copies from these spam campaigns. The email messages in both these spam campaigns have a zip archived attachment which contain the new variant of Bredolab Trojan executable. The sample e-mail format from each spam campaign is shown below:
Campaign #1 - DHL Services
Subject:
Attachment: DHL_package_1737.zip (contains DHL_package_1737.exe)
Email Body:
------------------------
Hello!
The courier service was not able to deliver your parcel at your address.
Cause: Mistake in address.
You may pickup the parcel at our post office personally.
The delivery advice is attached to this e-mail.
Print this label to get this package at our post office..
Please do not reply to this e-mail, it is an unmonitored mailbox!
Thank you,
DHL Services
------------------------
The e-mail message looks like below:
Campaign #2 - Facebook Password Reset spam
Subject:
Attachment: Facebook_password_1574.zip (contains Facebook_password_1574.exe)
Email Body:
------------------------
Hey !
Because of the measures taken to provide safety to our clients, your password has been changed
You can find your new password in attached document.
Thanks,
The Facebook Team.
------------------------
The e-mail message looks like below:
The executable file inside the zip attachment has an icon disguised as a Microsoft Word document file:
Installation
Files Installed
Registry Changes
SonicWALL Gateway AntiVirus provides protection against this Trojan via GAV: Bredolab.CL (Trojan), GAV: Bredolab.CL_2 (Trojan) and GAV: Oficla.FO_2 (Trojan)
Share This Article

An Article By
An Article By
Security News
Security News