Headers:
Message body:
From: "Lonnie Colflesh" {reckons@eshowe.org} Subject: presses de provence (impression directe sarl)
Hi, ====================================================== PRESSES DE PROVENCE IMPRESSION DIRECTE SARL 20 Bis Avenue Des 2 Routes 84000 Avignon Avignon FRANCE +33 490 38 36 75
There's a Zip file attached to the email:
Inside that Zip, is another Zip file:
sales@domain.co.uk.zip
presses_de_provence_impression_directe_sarl.zip
Inside that Zip file is an Scr file (Note: dangerous executable):
Md5 Hashes:
presses_de_provence_impression_directe_sarl.scr
91eb6b3e264ef8b93ba2a5097ae91ecc [1]
Malware Information:
VirusTotal Report [1] (hits 4/55 Virus Scanners)
Malwr Report [1]
Hybrid Analysis Report [1]
Cheers,
Steve
Sanesecurity.com
1 comment:
Hi Steve , a similar one here
http://myonlinesecurity.co.uk/l-e-lughese-attrezzature-per-lelettromeccanica-fake-word-malware/
so it is likely that we will see numerous different versions of this
Post a Comment