|
|
Yesterday we discovered a new Zeus campaign.
Most of the messages associated with the new spam campaign are linked to the Asprox botnet. This time, the focus is on FedEx. Most of the attachments start with either FedExDoc[randomnumbers].exe or FedExInvoice[randomnumbers].exe. Those attachments are recognized as the Bredolab Trojan, which will download the Zeus component.
This Zeus variant has a control host on hxxp://x5vsm5.ru, but also downloads from hxxp://trachsel.biz.
The targets of these samples are a large number of banks outside the United States. We still see common U.S. targets…
and also some banks from Europe, the Middle East, Asia, and South America…
as well as several other banks.
Watch out for Zeus’ going global.
|
|
Tags: bueno, pedro bueno
Submit your own comments / message for this post