Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Endpoint Management & Virtualization
    • Storage and Clustering
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
Security ResponseRSS

This Utility Has Zero Business with Your Mailbox

Mayur Kulkarni
November 19th, 2009
Tags: Endpoint Protection (AntiVirus), Malicious Code, Online Fraud, Security, Spam, Trojan.Zbot, Zeus, Security Response
Facebook Twitter

We are monitoring new malicious attacks that look similar to the fake "Microsoft Outlook reconfigure" spam campaign messages we have been observing for the last couple of months. That malicious campaign was followed by attacks on social networking sites, transforming from malicious code attacks into URL-based phishing attacks. These new attacks have similar traits, such as the spoofed “From” headers, which aggressively target and baffle enterprise users, and a subject line that is intended to cause panic (for obvious reasons—have a look at the example image below).

thisutility.png

As seen in the message above, the mail attachment is a zipped file named “utility.zip” that extracts an executable detected as Trojan.Dropper by Symantec antivirus. Using HTTP, this threat contacts a known C&C server for Zeus/Zbot in Ukraine. (The Zeus/Zbot family of threats is known to distribute malware using attachments and URLs in spam campaigns.)

These attacks seem to be around in rotation and are intended to confuse users with variations in alert types. Users should not open suspicious attachments because no legitimate site will send an executable to reactivate a mailbox, especially as a zipped file. As observed in the past, these attacks return with URLs instead of attachments in the days following the initial email. Users need to be careful before clicking URLs and/or downloading an application that wrongfully claims to restore/repair/activate their mailbox.

0 votes
  • Mayur Kulkarni's blog
  • Comments RSS Feed

About Security Response Blog

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.
Filter by:

Recent Blog Posts

  • Beyond the Initial Compromise
    Greg Ahmad - March 18, 2010
  • Passwords—Can’t Live With ‘em, Can’t Live Without ‘em
    Kevin Haley - March 17, 2010
  • New Healthcare IT Landscape and Related Security Needs
    Alessandro Tatti - March 17, 2010
  • Fraudsters Running a Classified Ad Campaign
    Mathew Maniyara - March 16, 2010
  • Mass Phishing of Retail Electronic Payment Brands
    Mathew Maniyara - March 15, 2010

Blog Tags

10.x 11.x 9.x and Earlier Antivirus2010 Backdoor.Tidserv Brightmail Gateway Emerging Threats Endpoint Encryption Endpoint Protection (AntiVirus) Endpoint Protection Small Business Enterprise Security Manager Evolution of Security General Symantec IT Healthcare Landscape IT Risk Management Internet Security Threat Report Live PC Care Malicious Code Misleading Applications Mobile & Wireless Online Fraud Password Management Restore Security Security Risks Spam Sykipot SymbOS.Exy Symbian Trojan.FakeAV Trojan.Zbot VirusDoctor Vulnerabilities & Exploits Windows Zeus
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Privacy Policy
  • Symantec.com