
SonicWALL UTM Research team observed a new Trojan being spammed via Fake order spam campaign starting September 19, 2009. The email has a zip archived attachment which contains the new Murlo Trojan variant.
SonicWALL has received more than 100,000 e-mail copies of this malware so far. The e-mail looks like:
Attachment: nz.zip (contains nz.exe)
Subject: Thank you for setting the order No.475456
Email Body:
------------------------
Dear customer!
Thank you for ordering at our online store.
Your order: Sony VAIO A1133651A, was sent at your address.
The tracking number of your postal parcel is indicated in the document attached to this letter.
Please, print out the postal label for receiving the parcel.
Internet Store.
------------------------
The e-mail message looks like below:
The executable file inside the zip attachment is packed with PEPACK v1.0 and it looks like:
The Trojan when executed performs following host level activity:
The Trojan is also known as Trojan.Downloader.JMJA , Trojan-Downloader.Murlo , and TR/Dldr.Murlo.cba .
SonicWALL Gateway AntiVirus provides protection against this malware via GAV: Murlo.CBA (Trojan) signature..

Share This Article

An Article By
An Article By
Security News
Security News