Description
Zlob is a trojan first detected in late 2005 that masqueraded as a required video codec delivered through malicious ActiveX components. Once installed it showed popup warnings that imitated Windows security alerts and tricked users into installing rogue anti-spyware programs, and some variants such as DNSChanger changed system DNS settings to reroute traffic. An FBI operation shut down the malware's source servers in late 2011, and the replacement servers closed in July 2012.
Stats
- First seen
- February 2022
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Dropped:Generic.Zlob.88DA37A6 |
| Dropped:Generic.Zlob.95C66FE5 |
| Gen:Variant.Zlob.1 |
| Generic.Zlob.FF76C548 |
| Script-JS.Downloader.Zlob |
| Trojan.Downloader.JS.Zlob.A |
| Trojan.Downloader.Zlob.ABIP |
| Trojan.HTML.Zlob.AG |
| Trojan.HTML.Zlob.W |
| Trojan.JS.Zlob.A |