Thursday, 26 February 2015

Your Sales Invoice worldwind 131234 zip

Your Sales Invoice worldwind.co.uk arriving with not very good detection rates...

Headers:
From: {donotreply@worldwind.co.uk}
Subject: Your Sales Invoice

Message body:

Your document is attached with our regards.

The document is in PDF format and requires Adobe Reader to view
(obtainable from www.adobe.com)

Attached is a Zip file:
131234.zip
Inside the Zip is a Windows Executable:
131234.exe

Sha256 Hash:
f9a4c6e5f2bac899b95772bb1b380b4a6f376c71b6c14385aa9154197e1a677d  [1]

Malware Information:

VirusTotal Report [1] (hits 4/57 Virus Scanners)
Malwr Report [1]
Hybrid Analysis Report: [1]


Cheers,

Steve
Sanesecurity.com

No comments: