Similar Searches

Related Posts

  • ZBOT Variant Spoofs the NIC to Spam Other Government Agencies (February 14, 2010)

    Spammers are becoming bolder, targeting even government agencies such as the National Intelligence Council (NIC) to further their malicious causes. Trend Micro fraud analysts were recently alerted to the discovery of spammed messages that purported to come from the NIC—the Intelligence Community ...

  • Zbot Spam Campaign Continues (October 16, 2009)

    A slightly modified Zbot spam campaign currently making rounds pretend to come from the IT support of various companies. It informs users that a security update in the mailing service caused changes in their mailbox settings. They are instructed to open the ZIP attachment and run the .EXE file, INSTALL.EXE ...

  • ZBOT Targets Facebook Again (December 15, 2009)

    ZBOT has currently been spotted engaging in another spam run targeting Facebook yet again.By clicking the link embedded in the email, users will land on a Facebook phishing page....

  • Tailor-Made ZBOT Spam Targets Various Companies (October 14, 2009)

    Trend Micro threat analysts were recently alerted to a phishing attempt targeting random employees of several companies. The email posed as a notification from the company’s “system administrator,” reminding the employee to update his/her system’s software due to a recent server software upgrade. The spammed email contained a URL using ...

  • Social Engineering Watch: Another IRS Scam (September 16, 2009)

    Trend Micro warns users of the latest spam campaign that targets US taxpayers with Foreign Bank and Financial accounts. The said spam rides on the September 23 extended deadline set by the Internal Revenue Service (IRS) for filing ‘FBAR’ or the Report of Foreign Bank and Financial Accounts. The spammed ...

Related News

Related Posts

  • ZBOT Variant Spoofs the NIC to Spam Other Government Agencies (February 14, 2010)

    Spammers are becoming bolder, targeting even government agencies such as the National Intelligence Council (NIC) to further their malicious causes. Trend Micro fraud analysts were recently alerted to the discovery of spammed messages that purported to come from the NIC—the Intelligence Community ...

  • Zbot Spam Campaign Continues (October 16, 2009)

    A slightly modified Zbot spam campaign currently making rounds pretend to come from the IT support of various companies. It informs users that a security update in the mailing service caused changes in their mailbox settings. They are instructed to open the ZIP attachment and run the .EXE file, INSTALL.EXE ...

  • ZBOT Targets Facebook Again (December 15, 2009)

    ZBOT has currently been spotted engaging in another spam run targeting Facebook yet again.By clicking the link embedded in the email, users will land on a Facebook phishing page....

  • Tailor-Made ZBOT Spam Targets Various Companies (October 14, 2009)

    Trend Micro threat analysts were recently alerted to a phishing attempt targeting random employees of several companies. The email posed as a notification from the company’s “system administrator,” reminding the employee to update his/her system’s software due to a recent server software upgrade. The spammed email contained a URL using ...

  • Social Engineering Watch: Another IRS Scam (September 16, 2009)

    Trend Micro warns users of the latest spam campaign that targets US taxpayers with Foreign Bank and Financial accounts. The said spam rides on the September 23 extended deadline set by the Internal Revenue Service (IRS) for filing ‘FBAR’ or the Report of Foreign Bank and Financial Accounts. The spammed ...

Another ZBOT Spam Run

Trend Micro threat analysts were alerted to the discovery of another ZBOT spam campaign. The emails bear subjects such as “your photos” and “some jerk has posted your photos.” They inform the recipients that someone has posted their photos without their permission on a site and has sent the link to their friends. The recipient is intended to beleive that the “sender” is acting as a “good samaritan,” emailing the one who supposedly posted the said pictures.The URL, of course, points to a website that distributes a malware detected by Trend Micro as TSPY_ZBOT.CJA.

When executed TSPY_ZBOT.CJA connects to several websites to download another malicious file detected as TROJ_DROPR.KB. The spyware also has rootkit capabilities that enable it to hide its processes. ZBOT/ZeuS is one of the most notorious botnets with regard to identity, financial, and information theft.

Users are strongly advised not to open emails from unknown sources. Trend Micro protects users from this attack via the Smart Protection Network, which blocks the spammed messages and prevents the download of the related malicious files.

Post from: TrendLabs | Malware Blog - by Trend MicroAnother ZBOT Spam Run


Read the original story


Source: Bernadette Irinco (Technical Communications) @ TrendLabs | Malware Blog - by Trend Micro

Write a Comment

Copyright © 2010 The Security Blog. All rights reserved.
Web Statistics Homeland Security blogs & blog posts