NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Spam Reports

Spam Reports


Zbot Spam Claims Email Accounts Were Deactivated

The malicious attachment contains a trojan downloader

By Lucian Constantin, Web News Editor

18th of November 2009, 10:10 GMT

Adjust text size:


Zbot distributors send fake mailbox deactivation notifications
Enlarge picture
Malware distributors are hard at work again to infect computer users with the notorious Zeus banking trojan. Their newest spam campaign informs users that their email accounts have been deactivated and instructs them to run an infected file.

The malicious emails come with a "your mailbox has been deactivated" subject and claim that the user is being contacted in regards to unusual activity identified on their mailbox. "As a result, your mailbox has been deactivated. To restore your mailbox, you are required to extract and run the attached mailbox utility," the messages read.

One notable social engineering component used in this campaign is that emails are forged to appear as arriving from a notifications@ address with the same domain as the user's account. Therefore, if someone's email address is something@example.com, the spam mail will have its From field spoofed to be notifications@example.com.

"We've seen this trick before (of pretending to be from the administrators of your email system) but the reason why it is still being used is because it works. Users panic if they think they might be at risk of having their umbilical cord to the internet cut off and may race to open the attachment before thinking about the malice that might lie behind it," Graham Cluley, senior technology consultant at antivirus vendor Sophos, notes.

The file attached to the spam emails is called utility.zip and contains an executable identified as Mal/EncPk-LP by Sophos products. According to Dancho Danchev, an independent security consultant who analyzed the sample, this piece of malware has the purpose of deploying other trojan downloaders from various hosts, which eventually end up installing the TrojWare.Win32.TrojanSpy.Zbot.Gen. "All of these IPs are not surprisingly known Zeus crimeware hosts," Mr. Dancho reports.

Zbot, also known as Zeus, is a family of sophisticated information stealing trojans, which are able to hijack online banking credentials and surreptitiously transfer money to accounts controlled by the attackers. It seems that email spam has become the preferred method of distribution for the authors of these trojans. Recent such campaigns have targeted UK Vodafone and Verizon mobile customers or Facebook users.

TAGS:

deactivated mailbox | mailbox utility | Zbot | banking trojan | spam campaign
Read by 1,464 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Zbot Pushers Target UK Vodafone and Verizon Customers

Beware of Zbot-Flavored Facebook Phishing

Prevx Leads the Fight Against Online Banking Trojans

Over $500,000 Stolen from Construction Firm's Bank Account

Victims of Malware-Related, Fraudulent Bank Transfers Increase in Number

Planted Malware Leaves Kentucky County Short of $415,000

Fake Outlook Re-Configuration Emails Spread New Zbot Variant

Your Delivery Failed – Have This Trojan Instead

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM