Amazon

Showing posts with label Les Mills Invoice. Show all posts
Showing posts with label Les Mills Invoice. Show all posts

Wednesday, 14 January 2015

Les Mills Invoice goods/services lmuk.accounts@lesmills.com malware

Les Mills Invoice goods/services lmuk.accounts@lesmills.com macro based malware being spammed out.

The Word document has a random attachment, however these emails aren't from Les Mills at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header:
From: {lmuk.accounts@lesmills.com}
Date: Wed, 14 Jan 2015 09:41:56 +0200
Subject: Les Mills Invoice

Message Body:
Dear Customer,
Please find attached an invoice for Les Mills goods/services.  Please note that for Licence Fee invoices the month being billed is the month in which the invoice has been raised unless otherwise stated within.
If you have any queries please email lmuk.accounts@lesmills.com or call 0207 264 0200 and select option 3 to speak to a member of the team.
Best regards,
Les Mills Finance Team
Attachment:
Les Mills SIV035931.doc

Md5 Hashes:
0dd754a987d5f20624e55cb4ec1afeae
c6e31e9db8466b6ce1b1c06a268a7d26

Malware Macro document information:

VirusTotal Report [1]
(hits 0/57 Virus Scanners)

VirusTotal Report [2]
(hits 0/57 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve