
Decade-Old GameOver Zeus DGA Signature Still Catching Live Malware
A 13KB courier-notice loader trips a 2014-era Snort rule for GameOver Zeus ten times over, tying back to a larger unsigned Zeus/ZBot binary through nothing but a shared PEiD packer. Nearby domain infrastructure shows certificates reissued within the past two weeks, but the two layers are never shown to be directly connected.
Ten Snort and Emerging Threats alerts fired against a 13-kilobyte Windows executable disguised as a courier tracking notice — five of them the exact same rule, "MALWARE-CNC Win.Trojan.Zeus v3 DGA DNS query detected." That rule was written for GameOver Zeus, the peer-to-peer variant of the Zeus banking trojan that law enforcement spent years trying to dismantle starting in 2014.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read