Headers:
From: {message@inbound.efax.com}
Subject: eFax message from "POTS modem 2 " - 1 page(s), Caller-ID: 1-630-226-2563
Message body:
Attached is a Zip file:
Inside the Zip is a Windows Executable:
fax_2342.zip
fax_2342.exe
Md5 Hashes:
436da4d7aee7f8f4a8806b14b376cecf [1]
Malware Information:
Description:
VirusTotal Report [1] (hits 12/57 Virus Scanners)
Malwr Report [1]
Hybrid Analysis Report [1]
The malware in the zip is
Dyre, is Zeus-like banking Trojan, which is trying to capture as much information about your online banking details as possible.
It's also being used to then send out the same malware to everyone else by using your own copy of outlook and your bandwidth.
Cheers,
Steve
Sanesecurity.com
16 comments:
just received an email with this "efax". didn't open the attachment. what type of malware is it?
received the same potentially toxic attachment
It's Upatre malware, I've updated the blog entry a little with a description.
I just got one too. We do not subscribe to eFax, do not have a signon, and my AV sent it straight into the "Infected" file so I did not open it.
I just received this too, we do not subscribe to eFax, AND my AV sent it straight into the "Infected" file.
awesome. thank you. :)
Just received the identical trojan e-mail.
Received this morning in business email. Searched the phone # listed and your site popped up. What a wonderful service you provide!
Our business received the exact same email and I also searched the number and your site popped up. Thank you for the information!
I just got this email as well. Seemed a little phishy, so I googled the number and found this site. Thanks for sharing the info, what a great service you guys are providing.
Thanks very much for posting about this. We received this email too and I immediately deleted it.
Received exactly the same email, this morning.
received to business email just now. Thank you for posting the warning
Also just received this bogus eFax email. Did a reverse phone number look-up on the "630-226-2563" and got this...
Ameritech Landline in Lemont, IL
I just received the same thing today. Reported it as Junk.
Yup. Many thanks for posting this. from,
Richmond Hill, Ontario
Post a Comment