Author Topic: New alert, is this detected by avast...Trojan Zbot inside zip file  (Read 24113 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Alan1998 alerted me to this: Site: brennerveiculos dot com dot br/cache/efax_9057733019_pdf.zip
This is a malware threat outbreak : http://tools.cisco.com/security/center/viewThreatOutbreakAlert.x?alertId=31347
It is related to the Zeus trojan: http://www.malwaredomainlist.com/mdl.php?inactive=on&sort=Date&search=&colsearch=All&ascordesc=DESC&quantity=All&page=0?iframe=true Trojan Zbot inside zip file -> https://malwr.com/analysis/YzY1ODgwMzU5MTNjNDkzMDkyOTExNzA1NjNjZTQwNzY/
So far only one to detect on VT:
Quote
{"timestamp": "1382274374", "sha256": "b0f86ff6803336a76241bdd22daa46ea6fed5859147d85acb0030d3e4d49d4aa", "analysis_url": "/en/url/b0f86ff6803336a76241bdd22daa46ea6fed5859147d85acb0030d3e4d49d4aa/analysis/1382274374/", "result": 1, "verbose_msg": "Invalid URL"}]

polonus
« Last Edit: October 20, 2013, 03:07:42 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #1 on: October 20, 2013, 03:16:49 PM »
The server on brennerveiculos dot com is not reachable for me at the moment.

I am getting no Data.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #3 on: October 20, 2013, 03:42:23 PM »
Hi Steven Winderlich and Pondus,

Thanks you both for that good news.
It has been taken down and for a good reason.
At least Alan1998 has some good answers,
why he should not go and download that file.
Others are secure to have missed that threat.
Again for how long seeing the IP and domain history here:
http://myip.ms/info/whois/200.143.116.25/k/588959722/website/brennerveiculos.com.br

polonus
« Last Edit: October 20, 2013, 03:45:50 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #4 on: October 20, 2013, 03:44:39 PM »
Normally these sites are just up for a few hours or sometimes some days.

And then when antiviruses start to detect them they go dowm, use another server and start from the beginning. ;)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #5 on: October 20, 2013, 03:50:38 PM »
Yes and this PHISH from that IP seems still up and kicking: Up(nil):   200.143.116.25    to 200.143.116.25   caciva dot com dot br   hxtp://www.caciva.com.br/imagens/banners/paypals/   DNS status DNSBL   listed

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #6 on: October 20, 2013, 03:54:31 PM »
Yes and this PHISH from that IP seems still up and kicking: Up(nil):   200.143.116.25    to 200.143.116.25   caciva dot com dot br   hxtp://www.caciva.com.br/imagens/banners/paypals/   DNS status DNSBL   listed

pol
Listed at PhishTank
http://www.phishtank.com/phish_detail.php?phish_id=1371684

and that means protection for those who use OpenDNS

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #7 on: October 20, 2013, 06:54:14 PM »
I caught it. I also have Zeus on the Virtual Machine. The URL was in the proccess of being taken down when I found it. very slow. Took a few tries to get the file.

The file was saved as .scr (Screen Saver). It is Zeus though.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #8 on: October 20, 2013, 06:58:10 PM »
I had no luck to get the file. Not even in a VM with Ubuntu 13.10.

Site seems to be down.

Can you upload the file somewhere and post the link here?
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #9 on: October 20, 2013, 08:07:03 PM »
Will try to yes.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #10 on: October 20, 2013, 08:10:45 PM »
Deleted by OP
« Last Edit: October 20, 2013, 08:52:43 PM by alan1998 »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #11 on: October 20, 2013, 08:43:37 PM »
File is blocked by Mediafire.

Do you have another source to upload?

Like Google Drive or something else?

You could upload it on Wikisend: http://wikisend.com/
« Last Edit: October 20, 2013, 08:48:34 PM by Steven Winderlich »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #12 on: October 20, 2013, 08:58:24 PM »
It works. And the file is blocked as FileRep Metagen (Drp)
and Dropper-Gen by Avast.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #13 on: October 20, 2013, 09:00:29 PM »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #14 on: October 20, 2013, 09:02:28 PM »
I dont have a WindowsVM at the moment just Ubuntu and Linux Mint.

But i will set up one when i have time.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10