Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Trojan-Spy:W32/Zbot.PUA


Aliases:


Trojan-Spy:W32/Zbot.PUB
Rootkit.39841, Trojan-Spy.Win32.Zbot.aovj

Malware
Trojan-Spy
W32

Summary

This type of trojan secretly installs spy programs and/or keylogger programs.



Disinfection & Removal

Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

For more general information on disinfection, please see Removal Instructions.



Technical Details

Trojan-Spy:W32/Zbot.PUA is notable for being specifically designed to steal SMS messages containingm obile transaction authentication number (mTANs), which are like single-use passwords sent by banks to to their account holders' mobile phones to verify online transactions.

By stealing this information, attackers raiding a online bank account are able to perform transactions they would otherwise be unable to complete without offline authorization.

The trojan-spy first uses standard social engineering tactics (either phishing or pharming) to deceive a user into giving out the username and password for their online bank accounts. The added twist for this this trojan-spy is that it also asks for the user's mobile phone details.

Based on the provided information, the trojan-spy then sends an SMS message to the user's phone, containing a link to a malicious mobile component, which we detect as Trojan:SymbOS/ZeusMitmo.A. This trojan is responsible for monitoring and stealing the SMS messages containing mTANs.

In our analysis, the mobile malware installed is a Symbian-signed file for S60 3rd Edition mobile phones. The file is named cert.sis; it may also be deceptively billed as a "Nokia Update". The mobile component has also been reported to be available in .jad files for Blackberry devices.

This trojan-spy is also discussed in the following Labs Weblog post:





Description Created: 2010-09-28 04:34:23.0
Description Last Modified: 2010-09-28 05:22:15.0



Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.

Scan and clean your PC




F-Secure Online Scanner will scan and clean your PC in just a few minutes for free