MX Lab just intercepted an email with the subject “A new settings file for the jp@******.com has just been released”, similar to the latest ZBot variant, but with a major difference in distribution. This time the email conatins the ZIP archive install.zip with the executable install.exe.
Body of the email:
Dear user of the ****.com mailing service!
We are informing you that because of the security upgrade of the mailing service your mailbox jp@****.com settings were changed. In order to apply the new set of settings open zip attached file.
Best regards, ****.com Technical Support.
Further investigation shows us that this virus is listening to the name W32/FakeRean.A.gen!Eldorado (F-Prot), TrojanDownloader:Win32/FakeRean (Microsoft), W32/PackSpam.A!worm (Fortinet) or W32/FakeAV.AE!genr (Norman).
Virus Total permlink and MD5: 7d96ce7f588613f0343049918de70665. Only 15 of the 41 AV engines detected the trojan correctly. For more information regarding this tojan you could check out the Microsoft Malware Protection Center.

