Home Malware Programs Trojans Troj/Bredo-ABB

Troj/Bredo-ABB

Posted: July 31, 2012

Threat Metric

Ranking: 16,781
Threat Level: 9/10
Infected PCs: 171
First Seen: July 31, 2012
Last Seen: October 15, 2023
OS(es) Affected: Windows

Troj/Bredo-ABB or Gen:Variant.Barys.7136 is a recently-detected Trojan that's distributed by fraudulent e-mail messages that claim to be from Groupon – a discount website that e-mails its bargains straight to the mailboxes of its members. Unlike normal Groupon e-mails, Troj/Bredo-ABB e-mails include a zipped file attachment that infects your PC with Troj/Bredo-ABB. The recently-identified nature of Troj/Bredo-ABB has left its payload and overall capabilities uninspected as of the time of this writing, but SpywareRemove.com malware experts have noted that similarly-distributed Trojans often include downloading or backdoor capabilities that can install other PC threats or violate the security of your computer. Ideally, Troj/Bredo-ABB's e-mails should be deleted as soon as they're seen, although anti-malware applications should be utilized to remove Troj/Bredo-ABB in cases of definite infection.

Troj/Bredo-ABB: the Discount Offer on a Trojan

Troj/Bredo-ABB is an actively-distributed PC threat and should be considered a particular risk to PCs with outdated anti-malware software (or, of course, no anti-malware software at all). Similar but not as recently distributed members of Troj/Bredo-ABB's Bredo family include Troj/Bredo-VV, Troj/Bredo-QI, Troj/Bredo-RK and Troj/Bredo-ZT. Troj/Bredo-ABB's favorite distribution means is through fraudulent Groupon e-mails that are formatted to appear similar to official communications, complete with mentions of the Groupon Promise, a mobile app and an inclusion of the Groupon logo.

Details that differentiate Troj/Bredo-ABB's e-mails from the real things include typos on the current subject line ('Groupon dicount gifts') and, of course, a request that you download and view a ZIP file attachment to receive a discount coupon. Any attempt to access the supposed gift coupon that's being offered in these e-mails only will infect your computer with Troj/Bredo-ABB. Troj/Bredo-ABB, in its turn, has a high probability to install other forms of hostile software or attack your PC's security software/settings, and SpywareRemove.com malware experts recommend is immediate deletion via any available anti-malware product.

The ABCs of E-Mail Safety with Troj/Bredo-ABB

Since the real Groupon will never ask that you open a file attachment, SpywareRemove.com malware researchers note that this detail is an easy way to identify fraudulent Groupon messages, including Troj/Bredo-ABB's, which should be deleted on sight.

In case you need to open a file attachment from such a suspicious source, you should always scan the file prior to opening it, which some anti-malware programs will perform automatically. Anti-malware software should be able to detect the unzipped Trojan as Troj/Bredo-ABB, and some anti-malware programs may also detect the ZIP, itself, as Mal/BredoZp-B. However, since Troj/Bredo-ABB is a very new PC threat, anti-malware applications that are using old databases may be ill-equipped to identify or remove Troj/Bredo-ABB, and SpywareRemove.com malware researchers always advise that you maintain your security tools up-to-date with their most recent patches.

Technical Details

Additional Information

The following messages's were detected:
# Message
1'Hi there! You're going to love it We are glad to inform you that one of your friends has found a great deal on Groupon.com! And even shared it with you! Yeah! Now Groupon.com gives an opportunity to share a discount gift with a friend! Enjoy your discount gift in the attachement and share it with one of your friend as well. All the details in the file attached. be in a hurry this weekend special is due in 2 days!'

Loading...