Headers: (example)
Message body (example)
From: "HSBC" {no-replay@hsbci.co.uk}
Subject: HSBC Payment Advice
Attached to the email is a Zip file (Note: Random filename):
Sir/Madam
Upon your request, attached please find payment e-Advice for your
reference.
Yours faithfully
HSBC
HSBC-78278.zip
On the Windows machine, Inside the zip, is Windows executable
CashPro.exe
Md5 Hashes:
Malware Information:
f0153b97415d4d4029209ab571f29bf8 [1]
VirusTotal Report [1] (hits 2/51 Virus Scanners)
Malwr Report [1]
Summary:
- Steals private information from local Internet browsers
- Collects information to fingerprint the system (MachineGuid, DigitalProductId, SystemBiosDate)
- Creates an Alternate Data Stream (ADS)
- Installs itself for autorun at Windows startup
Hybrid Analysis Report [1]
Cheers,
Steve
Sanesecurity.com
2 comments:
Got it as well.
Me too:
MD5 (CashPro.exe) = f0153b97415d4d4029209ab571f29bf8
Post a Comment