Western Union MTCN trojan variant


MX Lab intercepted emails with attached malware Trojan-Spy.Win32.Zbot.tnt regarding a failed money transfer that is handled by Western Union. The email subject is “Western Union Transfer MTCN: 9439449215″ - note that the number is random and will change with each message - and is coming from [email protected] - is obviously spoofed.

The body of the email:

Dear Client!

The money transfer you have sent on the 9th of March has not been received by the recipient.

According to the Western Union contract the transfers which are not collected in 15 business days are to be returned to sender.

To collect funds you need to print the invoice attached to this e-mail and visit the nearest Western Union agency.

Thank you!

The email has a Zip file attached with the name Invoice_8773.zip which contains the executable Invoice_8773.exe. The malware has the same characteristics as our previous malware detection in the past.

VirusTotal permalink and MD5:fa491105bd5c3baedad78f28586ff91e.

Swine flu inspires spammers


While the media cover each new outbreak of the swine flu, also known as the Mexican flu here in Belgium, spammers get inspired to use the subject in their spam campaigns. Here we have some examples.

There are two spam outbreaks regarding the swine flu. The first outbreak had ‘swine flu’ in the subject line and direct the reader to online pharmacy stores. We have intercepted similar samples here at MX Lab.

Following one of the links will lead you to the Canadian Health & Care Mall web site.

While other links will lead you to the well know Canadian Pharmacy, one of our favourites at MX Lab.

The second outbreak was to harvest emails for spammers. The subjects where randomly generated and ‘swine flu’ appeared in the body of the spam email. These mails where sent in huge numbers to check the validity of large groups of email addresses to build new spam campaigns.

Follow

Get every new post delivered to your Inbox.

Join 348 other followers