SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Zbot.F_3
Zbot.F_3 is a Trojan horse that attempts to steal confidential banking information from the compromised computer. It may also download configuration files and updates from the Internet. It is spread mainly through drive-by downloads and phishing schemes. Zbot is also called as Zeus.

        Process Related Changes
        It creates the following process(es):
        • C:\Windows\system32\msiexec.exe

        Network Activity
        We observed the following DNS query/queries:
        • update.microsoft.com

        It attempts to connect to the following remote servers:
        • 62.76.xxxxxx:80
        • update.microsoft.com.nsatc.net:80 (157.56xxxxxx)


        Relevant Information