Bredolab surges to new heights thanks to Cutwail botnet

Several sources reported a surge of the Bredolab trojan in the middle of October but MX Lab did noticed an real increase on October 27th.

The following graph shows the virus detection from October 7th until November 5th (from right to left) with small peaks at the beginning of October while at the end the virus outbreak really started for us. Virus detection and interception rate increased 5x to 6x times compared to the normal average.

We noticed Bredolab appearing in different campaigns where Facebook Password Reset Confirmation was perhaps one of the most widespread campaigns targeting social network users. But let’s not forget DHL tracking emails or the Western Union Payment.

So what is going on? Bredolab is being distributed mainly over the Cutwail (or Pandex) botnet. One of the reasons is that this botnet is trying to infect new computers to be added to the botnet as zombies. A larger botnet can be used to distribute even more emails containing mailware and infect even more systems or send out new large spam campaigns.

The Cutwail botnet activity decreased from sending around 45% of spam at the beginning of the year to only 11% in September. Other botnets increased in size and activity. One of the newer botnets is called Maazbem and was responsible for a large casino-related spam email campaign earlier in May 2009.

The malware authors of Cutwail are trying to make up some of those losses and to regain a dominant position in the botnet scene. So far, approximately 3.6 Billion Bredolab emails are likely to be send out each day, worldwide.

In order to do so they publish new variants on a regular base to avoid detection by AV engines. As we could see during the last few days, virus detection was sometimes very low when a new variant was out and the file was offered tyo Virus Total for inspection.

At Virus Total, a great tool by the way, we often noticed that the 41 AV engines did had difficulties in detecting the new variant resulting in less protection for an end user system. In some cases, not even 30% of the engines did detect the trojan after more than 6 hours when the variant first appeared.

It is clear that the traditional signature or heuristic based AV engines fail to offer a good security in a very short time frame. A time frame that is so important to detect and handle malware correctly. At MX Lab we can only recommend to deploy anti virus engines in multiple layers with a zero hour anti virus solution as the main and first line of defense.

Cutwail variant in UPS Delivery Problem email

In the ongoing virus story, MX Lab intercepts a new variant of the Cutwail trojan masked in emails from UPS regarding a delivery problem with the subject: UPS Delivery Problem.

The content of the email:

Dear customer!

Unfortunately we were not able to deliver the postal package which was sent on the 20th of June in time
because the addressee’s address is incorrect.
Please print out the invoice copy attached and collect the package at our office.

United Parcel Service of America.

[Update November 7th, 2009 - 02:10 AM local Belgian time]

The Cutwail trojan has changed again and also the email characteristics are different. The subject states “Congratulations”

The content of the email:

Congratulations!! You have won todays Macbook Air.

Please open attached file and see datails.

The email contains the ZIp archive winner.zip with the executable winner.exe.

Virus Total link and MD5: 3b9c3d653c3e5cb40c93e9599ee507de

Western Union money transfer email contains new variant of Bredolab

MX Lab intercepts a new trojan W32/Bredolab!Generic variant attached in emails from Western Union with the instructions on how to receive the money transfer.

Possible subjects:

Western Union transfer is available for withdrawl.
Western Union. You should receive money transfer! Order 7909.

Senders:

<contact@westernunion.com>
<service@westernunion.com>

Content of the email:

Hello.

The amount of money transfer: 5887 USD.
Money is available to withdrawl.

You may find the Money Control Number and receiver’s details in document attached to this email.

Western Union.
Customer Service Center.

We did noticed that with this campaign, since November 5th 2009, the attached ZIP archive is only 4 kB big and when extracted the executable is 0 kB big! It seems there is some issue with the email distribution but we expect that this can change quickly.

Virus Total link and MD5: e6069e83c06da868637489466daed9d3.

Follow

Get every new post delivered to your Inbox.

Join 109 other followers