[Caution] Spreading malicious file with modulated Zeus bot Unicode

1. Information

INCA Internet response team detected that malicious files called as Zeus Bot(Zbot) are spreading as a Wire Transfer cancellation mail. Zeus and Spyeye targeting for online banking have been found frequently. And they are categorized as one of cyber threats malicious files. Especially, this malicious file uses modulated Unicode extension exploit to induce users as normal PDF file. Therefore, users need to be careful on using this malicious file.

- Spreading ZeuS & Spyeye targeting for online banking user
- Modulating EXE file to document files (PDF, DOC, TXT, XLS)
- Using classical technique including as an attachment on email and inducing user to click.

[Caution] Detected malicious files disguised as online hotel reservation

2. Spreading cases

This malicious file is sent to anonymous users as a cancellation notice of Wire Transfer.

Its title and the body of the message consisted of cancellation notice of Wire Transfer and induce to download its attachment (Report.zip).

WinZip v8.1 an old version can't extract this file.

WinZip v16.0 can extract this file, however; PDF file shows its Type as executable program.

So, if user checked 'Do not show hidden files and folders' of Hidden files and folders in Folder Options, executable file will hide its extension.

Report.zip contains .exe file by its code. Besides, to hide its extension, it uses Unicode Character 'RIGHT-TO-LEFT OVERRIDE' (U+202E).



Here's detail of Hex Code(E2 80 AE).

This technique is used for APT including various issues. At that time, the name of the file was NKorea demands its own probe into ship sinking.RAR, and after extracting .DOC file was created(Actually this file was malicious .SCR )

This malicious file, modified by Unicode modulation, has .exe and has wrong spell from PDF to FDP.

Except this case, various modulated cases have been found.

3. Summary

Changing extension technique from EXE, SCR, or COM to TXT, PDF, DOC, XLS, or HWP have been found in these years.
This technique can be used for APT. Besides, including executable files on e-mail must be suspicious from being infected by malicious files. To use PC safely from security threats of these malicious attachments, we recommend you download latest security updates and obey following "Security management tips" for general users.

Security management tips

1. Maintain the latest security update on OS and applications
2. Use anti-virus SW from believable security company and keep updating the latest engine and using real time detecting function “ON”
3. Do not see and download attached file from suspicious e-mail.
4. Keep caution to link from instant messenger and SNS.

INCA Internet (Security Response Center / Emergency Response Team) runs responding system against various security threats.


  1. Talking about useful files, I recommend you to check this out. Especially if you need to write your resume soon and get the job of your dream.

  2. Thanks for sharing.I found a lot of interesting information here. A really good post, very thankful and hopeful that you will write many more posts like this one.

  3. The website is looking bit flashy and it catches the visitors eyes. Design is pretty simple and a good user friendly interface.

  4. I've never been involved in structural engineering past college, but I don't see a design standard like that as outside the realm of possibility. The thought could have been, 'we're reasonably close to two major Get Essay Done

  5. A mobile app or mobile application is a computer program or software application designed to run on a mobile device such as a phone/tablet or watch. Some Good apps for our iOS and Android Devices are


  6. TutuApp APK Free for iOS, Android Latest Version 2019. TutuApp APK is free App Store to provide paid and premium apps free.
    The Best App Store to get premium and paid apps free.
    cartoon hd

  7. Very interesting post. Spreading malicious file with modulated Zeus bot Unicode. 1. Information INCA Internet response team detected ... And they are categorized as one of cyber threats malicious files. Especially, this malicious file uses ...

    see: best Ias coaching chandigarh

  8. The information you provide is very valuable to us. read manga online

  9. I have found one of the best Cartoon HD APK for watching movie, videos and web series and also, you can download any videos or movies for free.


  10. Thanks for Nice and Informative Post. This article is really contains lot more information about This Topic.
    hotmail login
    gmail sign up


  11. نقل عفش مشرف شركة نقل العفش مشرف
    نقل عفش الاحمدي شركة نقل العفش الاحمدي
    نقل عفش نقل عفش
    فني صحي الكويت فني صحي
    نقل عفش المنطقة العاشرة شركة نقل عفش المنطقه العاشره

  12. Companies offering Biology Research Paper Writing Services should help students perform well by delivering papers prior to the deadline as early delivery of Custom Biology Research Papers and Custom Biology Term Papers is very important.

  13. township hack 2020
    Have you ever fantasized about ruling your city? If yes, then Township is a perfect match for you. Township Cheats is a popular online game tool that offers a unique combination of town-building and farming elements. At the beginning of the game, you will start adventuring in a small plot of land, which will later be converted into a self-sustained town.

  14. Final Cut Pro is a effective tool that has many functions which might be tremendously valued and needed for video editing.
    See this: download final cut pro for windows The best problem with the software program is that it’s to be had best for folks that are lucky sufficient to be Mac customers.

  15. The main studies team has experimented and determined the scientifically validated natural nutritional formula Biotox Gold. It is attempting to help people like you and me who are laid low with obesity and obese problems.
    Here the group has shared the name of the game challenge about the use of the Ancient Indonesian 30-2d morning ritual to hold burning cussed pure fat evidently. Also read: https://thriveglobal.com/stories/5-tips-for-a-healthy-lifestyle/
    At the same time, your body will assist to wipe out the harmful pollution from your body and boosts the immune gadget to get again your well being.

  16. I must say that share it via hotmail.com website it would be amaizng.

  17. I want to thank you for the efforts you have made in the process of writing this article. I hope your best work in the future is the same.
    geometry dash

  18. recently found many useful information in your website especially this blog page. Among the lots of comments on your article