<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Mal/Zbot-I</title>
	<atom:link href="http://blog.mxlab.eu/tag/malzbot-i/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Mal/Zbot-I</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>New ZBot trojan detected in UPS tracking emails</title>
		<link>http://blog.mxlab.eu/2009/05/27/new-zbot-trojan-detected-in-ups-tracking-emails/</link>
		<comments>http://blog.mxlab.eu/2009/05/27/new-zbot-trojan-detected-in-ups-tracking-emails/#comments</comments>
		<pubDate>Wed, 27 May 2009 22:40:56 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Mal/Zbot-I]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[zbot]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=464</guid>
		<description><![CDATA[Email messages coming from UPS with the subject &#8220;Postal Tracking #FDD4Q22514LDU4N&#8221; and the attached file UPS_DOC_986001.zip are part of a new malware distribution by email. MX Lab intercepted the first samples of a new variant that is only detected by 5 of the 40 AV engines of Virus Total. The body of the email: Hello! [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=464&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Email messages coming from UPS with the subject &#8220;Postal Tracking #FDD4Q22514LDU4N&#8221; and the attached file UPS_DOC_986001.zip are part of a new malware distribution by email. MX Lab intercepted the first samples of a new variant that is only detected by 5 of the 40 AV engines of Virus Total.</p>
<p>The body of the email:</p>
<blockquote><p>Hello!</p>
<p>We were not able to deliver postal package you sent on the 14th of March in time<br />
because the recipient’s address is not correct.<br />
Please print out the invoice copy attached and collect the package at our office.</p>
<p>Your United Parcel Service of America</p></blockquote>
<p>The trojan will create the following files:</p>
<blockquote><p>%AppData%\wiaserva.log<br />
%Temp%\WER699f.dir00\appcompat.txt<br />
%Temp%\WER699f.dir00\explorer.exe.hdmp<br />
%Temp%\WER699f.dir00\explorer.exe.mdmp<br />
%Temp%\WER699f.dir00\manifest.txt<br />
%System%\wbem\grpconv.exe</p></blockquote>
<p>%AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.</p>
<p>The following directy is created: %Temp%\WER699f.dir00.<br />
A new process is created in the system: %System%\wbem\grpconv.exe along with some Windows registry modifications.</p>
<p>The following URL is being used: hxxp://dollarpoint.ru/abc/controller.php?action=bot&amp;entity_list=&amp;uid=&amp;first=1&amp;guid=13441600&amp;rnd=8520045</p>
<p>Virus Total <a href="http://www.virustotal.com/reanalisis.html?0834935e7219fe9b598ce7dcf7ade312fd1a87e8ee780541f436f6eecccb4896-1243463193" target="_blank">link</a> and MD5: de90a24f3dfb5c1c8d4a0a3104f3dd4a.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/464/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=464&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/05/27/new-zbot-trojan-detected-in-ups-tracking-emails/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New Western Union MTCN trojan</title>
		<link>http://blog.mxlab.eu/2009/05/26/new-western-union-mtcn-trojan/</link>
		<comments>http://blog.mxlab.eu/2009/05/26/new-western-union-mtcn-trojan/#comments</comments>
		<pubDate>Tue, 26 May 2009 21:46:11 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Mal/Zbot-I]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Western Union]]></category>
		<category><![CDATA[zbot]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=460</guid>
		<description><![CDATA[MX Lab intercepted a new ZBot trojan today that is being distributed in the famous &#8220;Western Union MTCN&#8221; format. The message subject is &#8220;Western Union Transfer MTCN: 5815328212&#8243;. The attached file is a compresses zip archive WesternUnion_SPL90710021.zip containing the malware WesternUnion_SPL90710021.exe. Please note that the numbers in the subject line and/or attachment and executable can [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=460&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a new ZBot trojan today that is being distributed in the famous &#8220;Western Union MTCN&#8221; format. The message subject is &#8220;Western Union Transfer MTCN: 5815328212&#8243;. The attached file is a compresses zip archive WesternUnion_SPL90710021.zip containing the malware WesternUnion_SPL90710021.exe. Please note that the numbers in the subject line and/or attachment and executable can change.</p>
<p>The body of the email contains:</p>
<blockquote><p>Dear customer!</p>
<p>The money transfer you have sent on the 20th of April wasn&#8217;t received by the recipient.<br />
According to the Western Union contract the transfers which are not collected in 15 days are to be returned to sender.<br />
To collect funds you need to print the invoice attached to this e-mail and visit the nearest Western Union branch.</p>
<p>Thank you!</p></blockquote>
<p>When we submitted the virus sample to Virus Total, on 26/05/2009 at 21:27:10 (UTC), we only had 6 of the 40 AV engines detecting the malware. When looking at the details and virus naming we assume that they are being detected by some heuristic features that the AV engines have: Gen:Trojan.Heur.3004FB9EBC (BitDefender, GData), Suspicious file (Panda), (Suspicious) &#8211; DNAScan (CAT-QuickHeal). A-Squared and Microsoft have a real virus name: Gen.Trojan!IK and TrojanDownloader:Win32/Bredolab.G.</p>
<p>The trojan will create the following files:</p>
<blockquote><p>%AppData%\wiaserva.log <br />
 %Temp%\WER699f.dir00\appcompat.txt <br />
%Temp%\WER699f.dir00\explorer.exe.hdmp<br />
%Temp%\WER699f.dir00\explorer.exe.mdmp <br />
%Temp%\WER699f.dir00\manifest.txt <br />
%System%\wbem\grpconv.exe </p></blockquote>
<p>%AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.</p>
<p>The following directy is created: %Temp%\WER699f.dir00.<br />
A new process is created in the system: %System%\wbem\grpconv.exe along with some Windows registry modifications.</p>
<p>The following URL is being used: hxxp://dollarpoint.ru/abc/controller.php?action=bot&amp;entity_list=&amp;uid=&amp;first=1&amp;guid=13441600&amp;rnd=8520045</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/8a45f57a2d32ee905c653bcd69aac18441602a82bc1a10690c38c9fa81c9ffde-1243373550" target="_blank">permalink</a> and MD5 hash: 53d15dc652a2534572981bab1e2eddf3.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/460/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/460/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/460/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/460/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/460/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/460/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/460/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/460/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/460/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/460/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=460&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/05/26/new-western-union-mtcn-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New version of the Zbot-I trojan</title>
		<link>http://blog.mxlab.eu/2009/05/17/new-version-of-the-zbot-i-trojan/</link>
		<comments>http://blog.mxlab.eu/2009/05/17/new-version-of-the-zbot-i-trojan/#comments</comments>
		<pubDate>Sun, 17 May 2009 21:56:09 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Mal/Zbot-I]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[zbot]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=452</guid>
		<description><![CDATA[A message with the subject line &#8220;Fwd: Look and tell&#8230;&#8221; that has been intercepted by the zero hour anti virus at MX Lab caught our attention. When submitting the details to Virus Total, only 14 of the 40 AV engines did detect this one. The email has the ZIP file attached named Info04.zip and when [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=452&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>A message with the subject line &#8220;Fwd: Look and tell&#8230;&#8221; that has been intercepted by the zero hour anti virus at MX Lab caught our attention. When submitting the details to Virus Total, only 14 of the 40 AV engines did detect this one. The email has the ZIP file attached named Info04.zip and when extracted we got Info04.Doc_[lots of underscores]_&#8230;_.exe.</p>
<p>The body of the email:</p>
<blockquote><p>Hello, webmaster.</p>
<p>I received it with my morning mail but it seems to me everything is yours.<br />
Look and tell to delete it or don&#8217;t.</p>
<p>&#8211;<br />
Best regards,<br />
webmaster       mailto:webmaster@sylvia-gerl.net</p></blockquote>
<p>This version of malware itself doesn&#8217;t do much harm when looking to the activity. It will create a new file%Temp%\svchost [file and pathname of the sample #1], create a new service svchost.exe, add one Windows registry.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/3f2b38eb3a4aac764b71707108dbc9fe" target="_blank">permlink</a> and MD5:16a2124b53d9d4746c77b9682a795e36.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/452/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/452/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/452/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=452&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/05/17/new-version-of-the-zbot-i-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>