Devaki(Manager of Importation)Ras Trading Co (Libya) email with a New_Order_PO3482045_pdf.jar attachment...
Headers:
Message body:
From: "IMPORT" {devaki.trg@ushafire.in}
There's a Jar file attached to the email:
Greetings! Kindly Find attached our final Purchase order for March 2015, Please send us invoice. We Plead you to give us discount with your best price. I await the invoice asap. Best Regards Devaki(Manager of Importation)Ras Trading Co (Libya):Algeria St. , near Kick off ShopsGaryunis Area, Benghazi, Libya
New_Order_PO3482045_pdf.jar
Inside the Jar file is a Windows Executable file (Note the dual extension trick):
Sha256 Hashes (one example)
New Order PO3482045,pdf.exe
6a9f2769769bd32c6f31b6ac45c7d8a6decd6263692bb21418f80f494a69e8e0 [1]
Malware Anti-Virus Reports (one example)
VirusTotal Report [1] (hits 10/57 Virus Scanners)
Malwr Report [1]
Hybrid Analysis Report [1]
Cheers,
Steve
Sanesecurity.com
No comments:
Post a Comment