Malware Conceals Itself as Boss’s Letter


Recommended Posts

Nov2. 2009

Malware Conceals Itself as Boss's Letter

by Maria Alarcon (Anti-spam Research Engineer)

Trend Micro threat analysts found spammed messages that pretend to be a letter coming from the "boss". It bears the subject "get back to my office for more details" and instructs users to read the attached ZIP file, which contains a letter. The ZIP attachment is, of course, not a letter but an .EXE file (info.exe) detected by Trend Micro as TROJ_CUTWAIL.GT.

Upon execution, TROJ_CUTWAIL.GT creates registry entries to automatically execute at every system startup. It also drops a Trojan dropper detected as TROJ_DROPR.ST. Cutwail is known as the 'spam engine' of the notorious botnet, PUSHDO, which spammed around 7.7 billion spam a day last Q2.

TrendLabs for more details & screenshots – http://blog.trendmic...s-bosss-letter/

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...