According to security researchers at Tech Help List, a new malicious campaign aimed at spreading the Asproxhas begun. The campaign is based on sending fake email notifications, informing users of a supposed message from the Viber service, which has not been received.
The email is titled “Missed Call,” luring potential victims, while the body of the email contains a link that supposedly leads to the recorded audio message as well as the date and time it was sent. In reality, the URL points to a compromised web server.
The cybercriminals behind this particular campaign appear to be acting with "professionalism", as they have taken several precautions to hide the malicious activity: They check the user agent to make sure that the visitor is using Internet Explorer, verify the IP address and block multiple login attempts, since this is generally the behavior of malware researchers.
According to Tech Help List, further protection measures have been taken, such as “that the EXE may have a unique hash that changes every 3 minutes, every 6 minutes, two or three times a day, or sometimes the same EXE is used all day long.”
If all the above conditions are met, the Trojan is downloaded and when executed, it automatically joins the user as a member of the botnet . Analysis by Tech Help List shows that five to ten IP addresses are available to the malware, for communication with the operators and receiving instructions.
The botnet can be exploited for various illegal activities
Asprox was originally created to distribute massive amounts of spam, but it can also be used to scan websites for vulnerabilities, steal credentials, and commit click fraud.
The botnet's activity dates back to 2008 and its size varies over time.
Last June, FireEye researchers discovered that Asprox could be exploited to distribute more than 10,000 spam messages on a daily basis. During various campaigns, which typically last several days, it has been observed that as many as 500,000 malicious messages could be delivered to unsuspecting customers.
