Threat Database Trojans TSPY_ZBOT.ADD

TSPY_ZBOT.ADD

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 12
First Seen: August 21, 2013
Last Seen: May 8, 2022
OS(es) Affected: Windows

TSPY_ZBOT.ADD is a Zbot Trojan that is distributed via fake HMRC emails attacking taxpayers in the United Kingdom. TSPY_ZBOT.ADD is included in a spam campaign that abuses the name of Her Majesty's Revenue and Customs (HMRC). The spam VAT return emails are being used to distribute ZeuS (ZBOT), the data-stealing Trojan. The file attachment that is added to the bogus HMRC emails is an archive called something like 'VAT_7808740.zip', which is not a receipt for the VAT return. Instead, it covers a security threat, identified as TSPY_FAREIT.ADI. While being installed on a targeted PC, TSPY_ZBOT.ADD looks for information pertaining to file managers, email, FTP clients and a variety of web browsers, involving Google Chrome, Internet Explorer, Mozilla Firefox, Opera, K-Meleon, Flock Browser, FastStone and RockMelt. In addition to stealing data, TSPY_FAREIT.ADI delivers a spyware Trojan, identified as TSPY_ZBOT.ADD.

File System Details

TSPY_ZBOT.ADD may create the following file(s):
# File Name Detections
1. VAT_7808740.zip

Trending

Most Viewed

Loading...