Home Malware Programs Trojans TrojanPWS.Zbot.y

TrojanPWS.Zbot.y

Posted: November 30, 2011

Threat Metric

Threat Level: 9/10
Infected PCs: 53
First Seen: November 30, 2011
OS(es) Affected: Windows

TrojanPWS.Zbot.y is a dangerous Trojan that is included in a United Parcel Service (UPS) spam email pretending that 'A new invoice is now available in the UPS Billing Centre. Please refer to attached file for more details'. The subject of the fake email message is 'Your UPS Invoice is Ready'. The bogus UPS email includes an attachment named 'UPS-Billing-Invoice-Notification-809288436661915.zip'. Each states to come from UPS Billing Center, that you can view, manage and pay your UPS invoices from a single online location. The zip file includes the 'UPS-Bailling_Notification-Details.exe', which is TrojanPWS.Zbot.y, a banking Trojan used to steal banking credentials that involve confidential data such user name, password and credit card number from the victim. By harvesting cookies and accessing other sensitive details, attackers can extract a lot of personal data which can be used to raise their chances to obtain access to the victim's online banking account. If you receive such UPS emails, do not open the attachment. Delete the unsolicited email messages from your inbox as soon as possible.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 167.93 KB (167936 bytes)
MD5: 614404754b44bced9d69c8cef4c2b9bf
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 1, 2011

More files
Loading...