Michael Jackson X-file scam steals passwords

06.07.2009
Security vendors have been reporting a wave of Michael Jackson spam emails designed to disseminate a Zbot banking password variant.

According to the , emails with the subject line: 'Michael Jackson Was Killed...' have been found in the security company's user community.

Within the messages recipients read:

The link then redirects to a site hosted at 87.97.116.131. This is hosted in an x-file-esque directory "x-files/x-file-mjacksonkiller.exe", not live at the time of writing.

When the PC Tools users visited the site, it hosted a malformed pdf and Zbot banking password stealing variant.