http://{blocked}ilei.ru/bin/sa ejuogi.bin

 Analysis by: Sheiree Salvago

 URL BLOCKING DATE/TIME: 29 May 2010 05:00:00 AM GMT-8
 RATING: HIGH
 DOMAIN: ootaivilei.ru/
 CATEGORY: Disease Vector
 DESCRIPTION:

This is where TSPY_ZBOT.BWF downloads its configuration file. This configuration file contains the list of targeted banks, where it can download an updated copy of itself and where to send the stolen information.

Related Malware