Amazon

Showing posts with label PAYMENT ADVICE. Show all posts
Showing posts with label PAYMENT ADVICE. Show all posts

Thursday, 15 January 2015

Payment Advice - Advice Ref HSBC Advising Service malware

Payment Advice - Advice Ref HSBC Advising Service malware in the form of a html email, with a link to auto-download a ZIP file.  {Bankline.Administrator@nutwest.com}

WARNING: downloaded zip file is reported as: Cryptolocker.Suspicious by QuickHeal Anti-Virus (not confirmed)

Headers: (Note: The Ref. is Random)
From: "HSBC Advising Service" {Bankline.Administrator@nutwest.com}
Subject: Payment Advice - Advice Ref:[GB109055] / CHAPS credits

Message body:

Sir/Madam,

Please download document from dropbox, payment advice is issued at the
request of our customer. The advice is for your reference only.

Download link:

http://www.bosleymanagement DOT com/NATWEST_RELEASES/bankline.html

Yours faithfully,
Global Payments and Cash Management
HSBC

This is an auto-generated email, please DO NOT REPLY. Any replies to
this email will be disregarded.

Security tips

1. Install virus detection software and personal firewall on your
computer. This software needs to be updated regularly to ensure you have
the latest protection.
2. To prevent viruses or other unwanted problems, do not open
attachments from unknown or non-trustworthy sources.
3. If you discover any unusual activity, please contact the remitter of
this payment as soon as possible.

*******************************************************************
This e-mail is confidential. It may also be legally privileged. If you
are not the addressee you may not copy, forward, disclose
or use any part of it. If you have received this message in error,
please delete it and all copies from your system and notify the
sender immediately by return e-mail.

Internet communications cannot be guaranteed to be timely, secure, error
or virus-free. The sender does not accept liability
for any errors or omissions.
*******************************************************************
"SAVE PAPER - THINK BEFORE YOU PRINT!"
The auto-downloaded Zip file is: (Note: the downloaded filename is random)
doc140_pdf.zip

On the Windows machine, Inside the zip, is Windows executable (Note the dual extension)
doc726_pdf.exe

Md5 Hashes:
ac5bcb9d2d7f2dc9e36649f25232ee7f
10f19f8b9fba32aa2d53bcf48e277c67
bb983668e38ab0bd7ca93b42850b0e8f
Malware Information:
VirusTotal Report [1] (hits 5/57 Virus Scanners)
VirusTotal Report [2] (hits 5/57 Virus Scanners)

Joti Report [2] (hits 3/22 Virus Scanners)

Malwr Report [1]
Malwr Report [2]

Summary:

Error: Analysis failed: The package "modules.packages.zip" start function raised an error: Unable to execute the initial process, analysis aborted.

Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24688

Cheers,

Steve
Sanesecurity.com

Tuesday, 6 January 2015

PAYMENT ADVICE Senior Accountant bacs malware document

A bacs PAYMENT ADVICE from Senior Accountant's are being spammed out.

The Word document has a random attachment, however these emails aren't from Senior Accountant's
at all, they just being used to make the email look more genuine, ie. from a real company.

Message Headers (Note that the Name and email address is random):
From: "Deann, Senior Accountant" {zoaudydiqw@metaphorivr.com}
Subject: PAYMENT ADVICE 06-JAN-2015
Date: Tue, 06 Jan 2015 19:25:25 +0800

Message Body: (Note that the amount and Name is random):
Dear all,
Payment has been made to you in amount GBP 16916,66 by BACS.
See attachment.
Regards,
Deann
Senior Accountant


One example of the random attachment file name:
BACS278606_218.doc

Md5 Hashes:
55d6c57bdad8a1e4210c1ff89cd88f78
661e6777cc51c335835a16bb2b79f42c
67fd8aac791e49bc90e851fa994bd525
ce596594218922c9d7429e7de11de3dd

Malware Macro document information:

VirusTotal Report [1]
(hits 0/56 Virus Scanners)

VirusTotal Report [2]
(hits 0/56 Virus Scanners)

VirusTotal Report [3]
(hits 0/56 Virus Scanners)

VirusTotal Report [4]
(hits 0/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24646.DocHeur


NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve