Datasharp UK Ltd - Monthly Invoice & Report - ebilling@datasharp.co emails with an attached document, is being spammed out. The document contains a macro.
The Word document has a random attachment, however
these emails aren't from Datasharp UK Ltd
at all, they just being used to make the email look more genuine, ie. from a real company.
It's also worth remembering that the company itself may not have any knowledge of this attachment as it won't have come from their servers and IT systems.
They may not be able to tell you if it's malware or even help clean up your system.
|
Comment Update: "I Work for Datasharp - we are receiving a high volume of calls due to this email - please just treat as spam - delete and virus check No need to call in - the email was not sent from us. (14:38)"
|
Message Header:
From: {ebilling@datasharp.co}
Subject: DO-NOT-REPLY Datasharp UK Ltd - Monthly Invoice & Report
Date: Fri, 09 Jan 2015 14:42:47 +0700
|
Message Body:
THIS MESSAGE WAS SENT AUTOMATICALLY
Attached is your Invoice from Datasharp Hosted Services
for this month.
To view your bill please go to www.datasharp.co.uk. Allow
24 hours before viewing this information.
For any queries relating to this bill, please contact
hosted.services@datasharp.co.uk or call 01872 266644.
Please put your account number on your reply to prevent
delays
Kind Regards
Ebilling
|
Md5 Hashes:
625dd97b2495691ea687adb122749508 94e5abd0bffe71c4e6b73a81c362fa5b |
Malware Macro document information:
VirusTotal Report [1]
(hits 0/56 Virus Scanners)
VirusTotal Report [2]
(hits 0/56 Virus Scanners)
Malwr Report [1]
Decoded Macro [1] |
NOTE
The current round of Word and Excel attachments are targeted at Windows users.
Apple and Android software can open these attachments and may even manage to run the macro
embedded inside the attachment.
The auto-download file is normally a windows executable and so will not currently run on any operating system, apart from Windows.
However, if you are an Apple/Android user and forward the message to a Windows user, you will
them put them at risk of opening the attachment and auto-downloading the malware.
Currently
these attachments try to auto-download Dridex, which is designed to
steal login information regarding your bank accounts (either by key
logging, taking auto-screens hots or copying information from your
clipboard (copy/paste))
|
Cheers,
Steve