http://{BLOCKED}lycheezballz.com/sg5bp2.exe

 Analysis by: Jerowin Santillan

 URL BLOCKING DATE/TIME: 28 Jun 2013 06:03:00 PM GMT-8
 RATING: HIGH
 DOMAIN: rolypolycheezballz.com
 CATEGORY: Disease Vector
 DESCRIPTION:

TSPY_ZBOT.ADD may be downloaded from this remote site. This ZBOT variant was used in a spam run which takes advantage of the UK Tax Return deadline. The said spam message pretends to come from HM Revenue and Customs in the UK and informs users of a certain VAT return receipt.