Home Malware Programs Trojans Troj/Agent-ZWM

Troj/Agent-ZWM

Posted: February 5, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 23
First Seen: February 5, 2013
Last Seen: January 23, 2023
OS(es) Affected: Windows

Troj/Agent-ZWM is a Trojan that is involved in a spam malware attack. Troj/Agent-ZWM propagates via spam email pretending to be income tax emails. The spam attack which is used by scammers to distribute Troj/Agent-ZWM to vulnerable PCs takes advantage of an important date in the US tax system's calendar. 31st of January is the deadline for US employers to deliver the W-2 form to all of their workers, used to help calculate the total wages earned by an individual during the course of the year. The fake income tax email message contains a ZIP file attached, whose filename will differ depending on the recipient. For example, if the email is sent to chris@example.com, the .zip file will be called 'chris.zip'. The ZIP file contains an executable file called 'Individual Income Tax Returns.exe'. The malicious file is detected as Troj/Agent-ZWM. Troj/Agent-ZWM allows remote attackers to gain full access and control over the victimized machine.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



ae822e0645c7b73db3af0f5deccfe63a.exe File name: ae822e0645c7b73db3af0f5deccfe63a.exe
Size: 126.46 KB (126464 bytes)
MD5: ae822e0645c7b73db3af0f5deccfe63a
Detection count: 17
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 11, 2013
FW_ 2010 and 2011 Tax Documents; Accountant's Letter.eml File name: FW_ 2010 and 2011 Tax Documents; Accountant's Letter.eml
Size: 138.19 KB (138192 bytes)
MD5: dff96f2dc22105a4397a4280bba4e810
Detection count: 15
Mime Type: unknown/eml
Group: Malware file
Last Updated: February 11, 2013
FW .msg File name: FW .msg
Size: 417.28 KB (417280 bytes)
MD5: 2235b17540da2487bdd50a00f594f2c8
Detection count: 14
Mime Type: unknown/msg
Group: Malware file
Last Updated: February 11, 2013
KED-20120307-1e477e20bfbe9116e94dd408cb78ad6123dd4893 File name: KED-20120307-1e477e20bfbe9116e94dd408cb78ad6123dd4893
Size: 98.91 KB (98919 bytes)
MD5: de11cc8c740cb4bf4ff08e8dc16a4fe4
Detection count: 13
Group: Malware file
Last Updated: February 11, 2013
Individual Income Tax Returns.exe File name: Individual Income Tax Returns.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Additional Information

The following messages's were detected:
# Message
1Subject: FW: 2010 and 2011 Tax Documents; Accountant's Letter
Message body:
I forward this file to you for review. Please open and view it.
Attached are Individual Income Tax Returns and W-2s for 2010 and 2011, plus an accountant's letter.
This email message may include single or multiple file attachments of varying types.
It has been MIME encoded for Internet e-mail transmission.

Loading...