New Oficla trojan in messages with subject “Changelog 07.06.2010″


MX Lab intercepted a new variant of the trojan Oficla in messages with the subject “Changelog 07.06.2010″. The from address is spoofed and choosen randomly.

Some samples of the email body:

Hello,
as promised,
Willis

Dear ladies and gentlemen,
as promised,
Jolene

Good morning,
as promised,
Jolene

The message contains the file Changelog_07.06.20010.zip. The archive contains the 52 kB large file Changelog_07.06.20010.DOC.exe file.

The trojan is known as Win32/Oficla.GN (NOD32), W32/Oficla.Z (F-Prot), Trojan:W32/Agent.DJOH (F-Secure) or Trojan.Win32.Oficla.av (Kaspersky).

Virus Total permlink and MD5: 08c70fb3db93d29a2edcbf1593ad48f8.

Comments are closed.

Follow

Get every new post delivered to your Inbox.

Join 348 other followers

%d bloggers like this: