
SonicWALL UTM Research team discovered a wave of YouSendIt spam campaign involving newer variant of Bredolab Trojan in the last 24 hours. The spam emails arrive with a zip archived attachment which contains the Bredolab Trojan executable.
The e-mail pretends to be arriving from YouSendIt which is an online file sharing service. YouSendIt lets users send, receive and track files on-demand. This is the first time SonicWALL has observed YouSendIt storage service provider being used to spoof emails by Bredolab authors while spamming the newer variant of the Trojan.
Attachment: YouSendIt_reader.zip (contains YouSendIt_reader.exe)
Subject: You have received a file from @.com via YouSendIt. (The subject varies based on the from email address)
Email Body:
------------------------
Katelyn Goodman has sent you the following via YouSendIt
File attached to this letter.
YouSendIt, Inc. | Privacy Policy
1919 S. Bascom Ave., Campbell, CA 95008
------------------------
A sample email message looks like:
The executable files inside the attachment looks like this:
If the user opens the malicious attachment then it performs following activities on the victim's machine:
(The process name is a randomized number in memory)
SonicWALL Gateway AntiVirus provides protection against this Bredolab Trojan variant with GAV: Bredolab.SI (Trojan) signature.

Share This Article

An Article By
An Article By
Security News
Security News