PE Targeted Win32/zbot trojan?

MickZA

Executive Member
Joined
Jan 19, 2007
Messages
7,575
Reaction score
17
Location
Port Elizabeth
Dear Tax Payer,


Kindly find attached your traffic statement.


Regards,
Nelson Mandela Bay Municipality © 2013


By Mail:

The City Manager
P.O. Box 116
Port Elizabeth
6000

By phone:

Enquiries/Complaints All Sections

- Account enquiries - 041 506 5555 (during business hours)
- Service delivery complaints/ enq - 0800 20 50 50 (24/7)
- Staff related complaints 041-506 5333 (24/7)

I suspect a PE based concerns mailing list has been hi-jacked for this one as it seems more accurately targeted than the usual ones I encounter.

Anyone else in the PE area get it?
 
Spear phishing:
Phishing attempts directed at specific individuals or companies have been termed spearphishing. Attackers may gather personal information about their target to increase their probability of success.
 
Spear phishing:
Phishing attempts directed at specific individuals or companies have been termed spearphishing. Attackers may gather personal information about their target to increase their probability of success.

Could be.

Oops, who is after you? NSA? Chinese Govt? Or some obscure crime syndicate? While said tongue in the cheek, not totally so. South Africa has been the target of numerous bespoke "information collection" attempts of late.

Here is but one such attempt discovered at the beginning of the year:
http://www.wired.com/threatlevel/2013/01/red-october-spy-campaign/

Of note are the countries excluded (No, not Namibia! No, also not Zimbabwe ...)

There have been other attempts detected as well. Many of us South Africans had better catch a wake up, we are on the net and connected, also targeted.

These attacks are indirect in some cases: I know Peter, Peter knows John, John has access to "the nice stuff" (thank you Facebook, LinkedIn etc), so I'm a target. In this case your location may have prompted the attempt format, if it is such.

I suggest uploading it, but only if it's possible to do so "safely":
https://www.virustotal.com/en/
http://anubis.iseclab.org/


PS: It occurs to me that pics would not work for South Africa. Put a big black Merc in there and we have a level 1 situation.
Also, on second thoughts, it's probably not the NSA after you, they do routers and switches ... :confused:
 
I suggest uploading it, but only if it's possible to do so "safely":
https://www.virustotal.com/en/
SHA256: 178f1b87ebd8080143cade89efac9f77e8192f031831d2fe8d3b53dfba47a02d
File name: Traffic Statement.zip
Detection ratio: 26 / 48
Analysis date: 2013-09-24 06:20:37 UTC ( 10 minutes ago )

Scary - only 26 of 48 Antivirus engines detected it (although some seem to be very dodgy).

Amongst those that failed to detect it:

Avast
ClamAV
F-Prot
PCTools (amazed that's still around)
SUPERAntiSpyware (thought that was malware anyway)
TrendMicro
 
Here is a statement issued by the Nelson Mandela Bay Municipality regarding a hoax email doing the rounds:

Hoax e-mail encouraging traffic fines payment

We became aware of a hoax e-mail doing the rounds that encourages the public to pay traffic fines.

The Nelson Mandela Bay Municipality is not responsible for its origin and suspect that the banking details could be fake even though the contact details could be legitimate.

Please note that the municipality will only notify traffic law transgressors via the post (NOT E-MAIL) before payment will be required at the Traffic Department, Customer Care Centres or ABSA Bank.

Please circulate this message urgently to avoid the theft of a fellow citizen’s hard-earned money.

Issued on behalf of the Nelson Mandela Bay Municipality by Media Management Officer Kupido Baron
 
Scary - only 26 of 48 Antivirus engines detected it (although some seem to be very dodgy).

I got three "Wells Fargo" emails yesterday. Only one obscure AV detected it. I reached out to a Kaspersky contact, making him aware of the VT rep:
Thanks much for the info!
I've checked the file on VT and it is malware indeed.
We detect it as "Trojan-Spy.Win32.Zbot.pzmk". There was a whole bunch of executable malicious attachments spammed out last night.

Bottom line, your AV might detect it and possibly protect you, but never open anything suspicious. However there is no patch for human stupidity. :erm:
 
Top
Sign up to the MyBroadband newsletter
X