Warning regarding your account contains the trojan Kobcka
April 5, 2010
MX Lab intercepted some emails regarding a temporary locked account because someone may have been accessing the account. The email is not send on behalf of a company, like for example a bank, but is send out from a random spoofed email address. The subject is: “***.be account notification” where *** represents the domain name of the intended recipient.
The content of the email:
Dear Customer,
This e-mail was send by ***.be to notify you that we have temporanly prevented access to your account.
We have reasons to beleive that your account may have been accessed by someone else. Please run attached file and Follow instructions
(C) ***.be
An attached file Instructions.zip contains the 32 kB large file Instructions.exe after extraction. The trojan is known as Trojan.Downloader.Kobcka.S (F-Secure), W32/Trojan2.MGAA (F-Prot) or a variant of Win32/Wigon.NT (NOD).
Virus Total permlink and MD5: 24e9815a542f560786c9f7ff36871131.
