Categorized | Security

Emails with subject “LinkedIn Messages, 9/30/2010″ lead to malware

MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject “LinkedIn Messages, 9/30/2010″.

The email is send from the spoofed address “LinkedIn Communication <communication@linkedin.com> (sent by messages-noreply@bounce.linkedin.com)”, email headers are forged and the message has the following body with complete LinkedIn branding:

The message is very similar to the LinkedIn Alert email threat we have seen a few days ago but has now some other approach to distribute the malware after clicking a link in the message.

All the URL redirect the visitor to a web site and then redirects them immediatly to hxxp://hetfonteintje.com/1.html. When the webpage is loaded you will get an image to see to install the Adobe Flash Player. The file flash_player_07.78.exe is offered to be downloaded.

The trojan is known as Trojan-Spy.Win32.Zbot.aptt (Kaspersky), Win32/Spy.Zbot.ZR (NOD32), Trojan.Zbot (PCTools), Trojan.Generic.KD.44402 (F-Secure).

The following files will be created:

%AppData%\Yguze\ubce.exe
%AppData%\Ywimuq\ipafe.tiy
%AppData%\Ywimuq\ipafe.tmp
%Temp%\tmp0e1f500d.bat

The following directories are created:

%AppData%\Yguze
%AppData%\Ywimuq

A new process is created:

ubce.exe

Several Windows registry changes will be exectued and the trojan will establish a connection with the host ohmaebahsh.ru on port 80 and perform a GET request for bin/koethood.bin.

Virus Total permlink and MD5: b77b6eac5d9e9d088b400652405c4b19.

View full post on mxlab – all about anti virus and anti spam

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago