Emails with the subject "UPS INVOICE NR9094991" and "Delivery Problem NR2204780" contains trojanAx3soft noted the highest virus detection rate from these months, which owes to the combination of the “Thank you for buying iTunes Gift Certificate!” and the latest UPS related emails with subjects like “UPS INVOICE NR9094991″ or ”Delivery Problem NR2204780″ The similar subjects are (the numbers are choosed randomly): UPS INVOICE NR9094991 The body of the email: Hello! Hello! The zip archive upsinvoice3325037.zip is contained in the email and it is available to extract the file UPSINVIOCE.exe which has 36 kB capacity. The trojan is known as W32/FakeAlert.NW (F-Prot), Trojan.Win32.VBKrypt.yj (Kaspersky), Win32/Oficla.EU (NOD32), Troj/Bredo-CX (Sophos) or Trojan.Sasfis (Symantec). Creat files as followings: %Temp%\1.tmp Load the following modules into the address space of other processes: %Windir%\scindl.dll —> %Windir%\scindl.dll —> %Windir%\scindl.dll —> the trojan tries to establish a remote connection with IPs on port 80 as followings: 85.87.17.230 Download data from the following hosts: * hxxp://funnylive2010.ru/ms/bb.php?v=200&id=653227819&b=newsp&tm=2 How-to's1. Malwarebytes' Anti-Malware is an anti-malware application that can thoroughly remove even the most advanced malware. It includes a number of features, including a built in protection monitor that blocks malicious processes before they even start. visit http://www.ids-sax2.com/Malwarebytes-Anti-Malware.htm and download Malwarebytes' Anti-Malware to help you. 2. We have added some new policies of Ax3soft Sax2 to detect the Trojan, please update the policy basic knowledge of Sax2 in time. Appendix:For more information, please visit http://www.ids-sax2.com/ComputerSecurityNewsletter.htm If you want to unsubscribe, please click here. |