Backdoor.ZBot.LZC
Backdoor.ZBot.LZC is a detection name used to identify a variant belonging to the ZBot family of malware, one of the most widespread and long-running families of backdoor and banking trojans. Like other members of this family, Backdoor.ZBot.LZC is designed to give attackers unauthorized remote access to an infected computer while quietly working in the background to steal sensitive information from the victim.
Table of Contents
What Backdoor.ZBot.LZC Does
As a backdoor, this threat is built to open a hidden channel between the infected machine and a remote server controlled by cybercriminals. Once that connection is established, attackers can typically send commands to the compromised system, download and execute additional malicious files, and exfiltrate data without the user's knowledge. Threats in the ZBot family are historically associated with harvesting login credentials, online banking details, and other private information by monitoring browser activity, intercepting keystrokes, or capturing form data entered on websites. Many variants in this family are also capable of modifying system settings, disabling security features, and maintaining persistence so they continue running even after the computer is restarted. It is typical for such backdoors to operate silently, avoiding obvious symptoms so they can remain active on a system for as long as possible.
How It Usually Gets Onto Computers
Backdoors like this one are commonly distributed through deceptive means rather than exploiting a single specific vulnerability. Typical infection vectors for this category of malware include malicious email attachments disguised as invoices, shipping notices, or other routine documents; links embedded in phishing messages; bundled downloads from untrustworthy websites or peer-to-peer networks; fake software updates; and cracked or pirated software installers. Users can also be infected through malicious advertisements or compromised websites that silently trigger downloads. Because these delivery methods rely heavily on tricking the user, exercising caution with unexpected emails, downloads, and links is an important line of defense.
Risks for the User
The presence of a backdoor such as Backdoor.ZBot.LZC on a system poses serious risks. Because the malware is designed to steal credentials and financial information, victims may face unauthorized access to banking, email, or other online accounts. The remote-access capability typical of this malware family also means attackers could install further malicious software, use the infected computer as part of a larger network of compromised machines, or access personal files and communications. In addition, having a backdoor active on a device generally weakens overall system security, making the computer more vulnerable to additional infections.
Signs of Infection
Backdoors are typically built to avoid detection, so infected systems may show few or no obvious symptoms. However, users should watch for warning signs commonly associated with this type of malware, including unexplained slowdowns, unusual network activity, unfamiliar processes running in the background, security tools being disabled unexpectedly, changes to browser or system settings that were not made by the user, and unauthorized transactions or login attempts on online accounts.
How to Stay Protected
Protecting against threats like Backdoor.ZBot.LZC involves practicing safe computing habits: keep the operating system and software updated, avoid opening attachments or clicking links from unknown or unexpected sources, download software only from official and reputable sites, and use reputable security software to scan for and remove malicious files. Regularly backing up important data and monitoring financial accounts for suspicious activity can also help reduce the impact of an infection should one occur.
Analysis Report
General information
| Family Name: | Backdoor.ZBot.LZC |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
c740825e762598fb24f5b278039b90c4
SHA1:
09774ed78fb38ed445ac4e6b27bfdcd07e01a8ef
SHA256:
9475C168FA03B9533FBAF98D990413D7300C386478CE0872D8D67B0F696A570E
File Size:
331.78 KB, 331776 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.File Traits
- 2+ executable sections
- No Version Info
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 284 |
|---|---|
| Potentially Malicious Blocks: | 162 |
| Whitelisted Blocks: | 122 |
| Unknown Blocks: | 0 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- ZBot.LZC