Sophos

9 August 2008 14:05 GMT

AntiVirus2008 & Zbot - presents from Irina.

Earlier on today we started seeing a malicious Trojan dropper being sent out via spam. Messages hitting our spam traps carrying the malicious attachment bore rather predictable social engineering, in this case purporting to be from a lady called Irina:

irina-email.png

The attachments is a ZIP file (photo.zip) which contains a single executable attachment. This is a malicious Trojan dropper, detection for which has been added as Troj/Mdrop-BUP.

And the purpose of Irina’s little gift? When the file is run, a photo (supposedly of Irina) is displayed:

irina_f.png

The desktop background is changed, to display a fake warning message:

irina2.jpg

In the background, two pieces of malware are silently installed, both from notorious families that have been very active recently.

Whether there are links between the groups behind Zbot and AntiVirus 2008 ’scareware’ is unknown. I doubt it, more likely someone is simply making money by getting paid to infect victims with each. Don’t let your (lack of) security help them.

Fraser Howard, SophosLabs UK