A Look At The New Gameover Zeus Variant
ID: d3c4b535-1a9e-5ab7-b896-d7adaeab85d0
STIX ID: report--d3c4b535-1a9e-5ab7-b896-d7adaeab85d0
Feed Name: Zscaler Security Research Blog
This Zscaler ThreatLabZ report analyzes a July 2014 resurgence of a Gameover Zeus (Zbot) banking-Trojan variant distributed via Cutwail spam attachments that download the payload, drop and run epoxs.exe from a Temp subfolder, create persistence via HKCU Run, inject into system processes and use a DGA with fast-flux C2 infrastructure to retrieve banking web-inject configurations. The analysis documents infection workflow, sample DGA domains, dropped batch cleanup behavior, and notes a reduction in resilience compared to prior P2P-enabled and rootkit-equipped variants while infections remain relatively low.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
