Friday, January 19, 2018

Zeus Panda Trojan


These days it's very common to search on internet for the things which we don't know and want to learn. Hackers are taking advantage of the same and injecting malicious payload to the files and make it easily available in normal links. Spreading Trojans through emails is also very common these days.

Researchers have recently come across new variant of "Zeus Panda Trojan" which is spreading via email.

Zeus Trojan Overview


A malspam campaign has been detected which is dropping the Zeus Panda banking Trojan. The email arrives with the subject 'bonifico gennaio' from 'srlsindaco.comune.casalvieri@tiscali.it'. It has an attachment which, in the example analysed, is called 'gennaio_sales.xls'. This is a Microsoft Excel document with malicious macro to install Zeus Panda.


The attacker using email addresses and subjects that will scare or entice a user to read the email and open the attachment. A very high proportion are being targeted at small and medium size businesses, with the hope of getting a better response than they do from consumers.

Email Sample

















Indicators Of Compromise (IOC’s)

SHA-256
  • 6dbc95b9f11dd56f557f7912fe89c71c03b2f22d52b7884a6a290f898f9b8cba
  • 3b2cc469e27aca58abc43a3eaa94dab4bee615c29f7995814e0b0a3d238f5408

Domain Associated
  • flavosoftorrent.ml
  • 7AB7F6AE8747.tk

Email Associated

For Microprocessor flaw check flawinmicroprocessor.blogspot.in

1 comment: