Win32/Zeus (alias Zbot)
Re: Trojan Zeus (alias ZBot)
Just received by mail (Zbot / Zeus)
rapport.pdf.exe
https://www.virustotal.com/file/7c7d876 ... 333532039/
MD5: a025d1e92bb21a1f494059fb12280802
Detection ratio: 5 / 42
rapport.pdf.exe
https://www.virustotal.com/file/7c7d876 ... 333532039/
MD5: a025d1e92bb21a1f494059fb12280802
Detection ratio: 5 / 42
You do not have the required permissions to view the files attached to this post.
Re: Trojan Zeus (alias ZBot)
PWS:Win32/Zbot.gen!AFEvilcry wrote:A gift from ZeuS for passengers of US Airways
http://www.securelist.com/en/blog/20819 ... US_Airways
In the footer available the list of ZeuS MD5 hashes involved.
https://twitter.com/#!/msftmmpc/status/ ... 8585039873
Re: Trojan Zeus (alias ZBot)
MD5: 42DDF04F7C2E0B9D7F76B332A549EBE6
5/42 - https://www.virustotal.com/file/618d1ea ... 333628305/
dropper + unpacked in attachment
5/42 - https://www.virustotal.com/file/618d1ea ... 333628305/
dropper + unpacked in attachment
You do not have the required permissions to view the files attached to this post.
Re: Trojan Zeus (alias ZBot)
Just recieved by mail
rapport.pdf.exe (Zeus / Zbot)
https://www.virustotal.com/file/d652e56 ... 334054761/
MD5: b849d83081ff7bfe236d32893de8adb9
Detection ratio: 5 / 42
rapport.pdf.exe (Zeus / Zbot)
https://www.virustotal.com/file/d652e56 ... 334054761/
MD5: b849d83081ff7bfe236d32893de8adb9
Detection ratio: 5 / 42
You do not have the required permissions to view the files attached to this post.
Re: Trojan Zeus (alias ZBot)
Gangs continue to earn on ZBot http://www.trusteer.com/blog/zeus-targe ... nterprises
Re: Trojan Zeus (alias ZBot)
Zeus / Zbot
rapport.pdf1
https://www.virustotal.com/file/dbf4757 ... 334137361/
MD5: b3dde60b637221449e2a61328e5fc55a
Detection ratio: 6 / 40
rapport.pdf1
https://www.virustotal.com/file/dbf4757 ... 334137361/
MD5: b3dde60b637221449e2a61328e5fc55a
Detection ratio: 6 / 40
You do not have the required permissions to view the files attached to this post.
Re: Trojan Zeus (alias ZBot)
Guys, I wondered that most ZBot c&c hosted at Europe and US area...
And another, why is still functioning...and not taken down?

Source - https://zeustracker.abuse.ch/
And another, why is still functioning...and not taken down?

Source - https://zeustracker.abuse.ch/
- EP_X0FF
- Global Moderator
- Posts: 4872
- Joined: Sun Mar 07, 2010 5:35 am
- Location: Russian Federation
- Contact:
Re: Trojan Zeus (alias ZBot)
This is called freedom.rkhunter wrote:And another, why is still functioning...and not taken down?
Ring0 - the source of inspiration
Re: Trojan Zeus (alias ZBot)
Critical analysis of Microsoft Operation B71 (against ZBot/Zeus/SpyEye botnet)
http://blog.fox-it.com/2012/04/12/criti ... ation-b71/
http://blog.fox-it.com/2012/04/12/criti ... ation-b71/