Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

January 13th, 2012, 08:56 GMT · By Eduard Kovacs

BLOG

ConEdison Billing Notification Emails Hide Zbot Trojan

SHARE:

Adjust text size:

Executable file containing the malicious ZBot Enlarge picture - Executable file containing the malicious ZBot
Emails that pretend to come from New York-based energy company ConEdison, informing recipients that their latest bill is attached, actually hide a dangerous variant of the Zbot malware.

M86 Security Labs inform that the email bears the subject “Billing-Summary-ConEdison as of <Date>” and the attachment that comes in the form of a zip archive contains an executable file that hides the malicious Trojan.

Fortunately, the file’s icon isn’t changed to make it look more innocent which means that recipients can immediately tell that the so-called bill is actually an executable.

This particular variant, found by security experts, can’t communicate with its C&C server because it was taken down and half of the antivirus vendors present on VirusTotal detect the attachment as being malicious.

However, users are advised to be on the lookout for these emails and ignore them as much as possible.
FILED UNDER:
spam
ZBOT
Trojan

TELL US WHAT YOU THINK:

610 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


QR Codes from Spam Emails Point to Pharmacy Schemes

Carrier IQ Detection Tools Modified to Become SMS Trojans

Rogue Pharmacy Sites Advertised in LinkedIn Emails

Fraud Websites Make the Global Top 250 Alexa Ranking List

Facebook Pays for Each Share to Help Baby Fight Cancer, Hoax

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM