USPS Spam Delivering Asprox Variant
ID: b35cf9a3-06ba-57b4-ac4d-2b9d20650ac9
STIX ID: report--b35cf9a3-06ba-57b4-ac4d-2b9d20650ac9
Feed Name: Zscaler Security Research Blog
Threat Score
This report analyzes an active Asprox botnet campaign delivered through USPS-themed spam that downloads a ZIP containing a malicious executable. The malware disguises itself as a document icon, installs copies in the user's Local Application Data, creates an autostarter for persistence, and phones home by POSTing bzip2-compressed data encrypted with a 16-byte RC4 key over ports 443 and 8080; the report includes sample IPs and a VirusTotal hash.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
