Amazon

Showing posts with label macro. Show all posts
Showing posts with label macro. Show all posts

Monday, 19 January 2015

FMG Support Group Ltd Insurance Inspection Arranged repairermessages@fmg.co.uk document malware

FMG Support Group Ltd Insurance Inspection Arranged repairermessages@fmg.co.uk  malware  are being spammed out.

The Word document has a random attachment, however these emails aren't from FMG Support Group Ltd at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header:
From: {repairermessages@fmg.co.uk}
Date: Mon, 19 Jan 2015 13:32:03 +0530
Subject: Insurance Inspection Arranged AIG02377973

Message Body:
FMG is committed to reducing its impact on the environment. Please don't print this email unless absolutely necessary.

Have you been impressed by one of our people?
If so, we'd love to hear about it. You can nominate someone for a Spirit award by emailing spirit@fmg.co.uk

FMG Support Group Ltd. Registered in England. No. 06489429.
Registered office: FMG House, St Andrews Road, Huddersfield, HD1 6NA.

Tel: 0844 243 8888
Email: info@fmg.co.uk

This email may contain confidential information and/or copyright material. This email is intended for the use of the addressee only. Any unauthorised use may be unlawful. If you received this email by mistake, please advise the sender by using the reply facility in your email software.

Outbound Message checked by Websense Mail Control.======================================================
This email, its content and any files transmitted with
it are confidential and intended solely for the use of
the individual(s) to whom it is addressed.
If you are not the intended recipient, be advised that
you have received this email in error and that any use,
dissemination, forwarding, printing or copying of
this email is strictly prohibited.
======================================================
Attachment:
AIG02377973-InsuranceInspectionArranged.doc

Md5 Hashes:
119f0030694bce7af3c2c1ba9fd5622d
5b242c0c6a76929c2d0040e39c8b87dd

Malware Macro document information:

VirusTotal Report [1] (hits 0/57 Virus Scanners)

VirusTotal Report [2] (hits 0/57 Virus Scanners)


Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as:

Sanesecurity.Malware.24676.DocHeur
Sanesecurity.Malware.24682.OffHeur

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Thursday, 15 January 2015

Payment request of (14 JAN 2015) malware

Payment request of (14 JAN 2015) invoice from random emails and companies are being spammed out.
The Word/Excel document has a random attachment, however these emails aren't from these companies  at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header: (Note: the email address and amount are random)
Date: Thu, 15 Jan 2015 10:20:28 +0200
Subject: Payment request of 3511.15 (14 JAN 2015)
From: Merlin Boone {Jeffry.ce@cm-93-156-251-163.telecable.es}

Message Body (Note:  the amount, company person and name are random)
Dear Sirs,

Sub: Remitance of GBP 3511.15

This is with reference to the above, we request you to kindly remit GBP 3511.15 in favor of our bank account.
For more information on our bank details please refer to the attached document.

Thanking you,
Merlin BooneAccounts Payable
Attachment: (Note: the filename is random)
ADV0504GO.doc
5157090EZ.xls

Md5 Hashes:
44d5e293fc3e4a68aca41b5651f5b897 [1]
7f3c2b0c5abe311f4e40b2a938a8ed75 [2]
38665c6364dd127b4b8bf98e033c4ec7 [3]
984597f7d4e83599baac04c7708394b2 [4]

3cc59cb545020d0d44c8ec9e7e04dc25
551bf7d91d5a6ab6b887956d5ce08571
612feaa36adcccc9281970b73ac7d7ef

Malware Macro document information:

VirusTotal Report [1]
(hits 3/57 Virus Scanners)

VirusTotal Report [2]
(hits 3/57 Virus Scanners)

VirusTotal Report [3]
(hits 3/57 Virus Scanners)

VirusTotal Report [4]
(hits 3/57 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Wednesday, 14 January 2015

SEPA REMITTANCE ADVICE malware

SEPA REMITTANCE ADVICE macro based malware being spammed out.

The Word document has a random attachment, however these emails aren't from the company they appear to be from at all, they just being used to make the email look more genuine:
It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header (Note: Random from address)
From: Nichole England {Jared.4bbd@ono.com}
Subject: SEPA REMITTANCE ADVICE 6513.56 EUR 12 JAN 2014

Message Body: (Note: Name and amount is random)
Good Afternoon
Please see attached a copy of remittance advice for SEPA payment of 6513.56  EUR made on 12/01/2015
Regards,
Nichole England
Senior Accounts Payable
Attachment (Note: Random document name)
E538XH.doc

Md5 Hashes:
57dbc8da6e0ae797d5f0c7e22722cf37
9875233ba6f2c6d10fbf3c91f0b46a96

Malware Macro document information:

VirusTotal Report [1]  (hits 0/57 Virus Scanners)

VirusTotal Report [2]  (hits 0/57 Virus Scanners)


Malwr Report [1]

Malwr Report [2]


Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Les Mills Invoice goods/services lmuk.accounts@lesmills.com malware

Les Mills Invoice goods/services lmuk.accounts@lesmills.com macro based malware being spammed out.

The Word document has a random attachment, however these emails aren't from Les Mills at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header:
From: {lmuk.accounts@lesmills.com}
Date: Wed, 14 Jan 2015 09:41:56 +0200
Subject: Les Mills Invoice

Message Body:
Dear Customer,
Please find attached an invoice for Les Mills goods/services.  Please note that for Licence Fee invoices the month being billed is the month in which the invoice has been raised unless otherwise stated within.
If you have any queries please email lmuk.accounts@lesmills.com or call 0207 264 0200 and select option 3 to speak to a member of the team.
Best regards,
Les Mills Finance Team
Attachment:
Les Mills SIV035931.doc

Md5 Hashes:
0dd754a987d5f20624e55cb4ec1afeae
c6e31e9db8466b6ce1b1c06a268a7d26

Malware Macro document information:

VirusTotal Report [1]
(hits 0/57 Virus Scanners)

VirusTotal Report [2]
(hits 0/57 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Tuesday, 13 January 2015

Card Receipt AquAid Tracey Smith tracey.smith@aquaid.co.uk receipt of payment document malware

Card Receipt 01.12.2015 AquAid Tracey Smith tracey.smith@aquaid.co.uk receipt of payment emails are back once again and trying to trick you into opening a word document, containing a malicious macro.

AquAid malware run of a macro infected "Card Receipt" word document has a random attachment,
however these emails aren't from AquAid at all, they just being used to make the email look more
genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this attachment as it won't have come from their servers and IT systems.

They may not be able to tell you if it's malware or even help clean up your system.

Message Headers (Note that the email address is random):
From: "Tracey Smith" {tracey.smith@aquaid.co.uk}
Subject: Card Receipt 01.12.2015
Date: Tue, 13 Jan 2015 08:49:46 +0200

Message Body:

 Hi

Please find attached receipt of payment made to us today

Regards

Tracey
Tracey Smith| Branch Administrator
AquAid | Birmingham & Midlands Central
Unit 35 Kelvin Way Trading Estate | West Bromwich | B70 7TP
Telephone:        0121 525 4533
Fax:                  0121 525 3502
Mobile:              07795328895
Email:               tracey.smith@aquaid.co.uk

AquAid really is the only drinks supplier you will ever need with our huge product range. With products ranging from bottled and mains fed coolers ranging up to coffee machines and bespoke individual one off units we truly have the right solution for all environments. We offer a refreshing ethical approach to drinks supply in that we support both Christian Aid and Pump Aid with a donation from all sales.  All this is done while still offering a highly focused local service and competitive pricing. A personalised sponsorship certificate is available for all clients showing how you are helping and we offer £25 for any referral that leads to business.

*********************************************************************
AquAid Franchising Ltd is a company registered in England and Wales with registered number 3505477 and registered office at 51 Newnham Road, Cambridge, CB3 9EY, UK. This message is intended only for use by the named addressee and may contain privileged and/or confidential information. If you are not the named addressee you should not disseminate, copy or take any action in reliance on it. If you have received this message in error please notify the sender and delete the message and any attachments accompanying it immediately. Neither AquAid nor any of its Affiliates accepts liability for any corruption, interception, amendment, tampering or viruses occurring to this message in transit or for any message sent by its employees which is not in compliance with AquAid corporate policy.
One example of the random attachment file name:
CARD015 151239.doc

Md5 Hashes:
0bc08e20e1e7b850b04616a85f572296
eb0209febd5951a28e6680b56c75d740

Macro document information:

VirusTotal Report [1]
(hits 1/56 Virus Scanners)

VirusTotal Report [2]
(hits 1/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24646.DocHeur

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Monday, 12 January 2015

Jason Bracegirdle JPS Projects Ltd - Summary Paid Against - {jason.bracegirdle@jpsprojectsltd.co.uk}

Summary Paid Against - Jason Bracegirdle JPS Projects Ltd - Copy of Weekly Summary {jason.bracegirdle@jpsprojectsltd.co.uk} macro based malware being spammed out.

The Word document has a random attachment, however these emails aren't from JPS Projects Ltd  at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this attachment as it won't have come from their servers and IT systems.

They may not be able to tell you if it's malware or even help clean up your system.
Message Header:
From: "Jason Bracegirdle JPS Projects Ltd" {jason.bracegirdle@jpsprojectsltd.co.uk}
Subject: Summary Paid Against
Date: Mon, 12 Jan 2015 20:47:34 +0900

Message Body:
Please find attached summary which was paid against

Jas

Jason Bracegirdle  Managing Director

M: 07912 883455
O: 02031 741416
F: 02030 700632
E: 
jason.bracegirdle@jpsprojectsltd.co.uk
W:  www.jpsprojectsltd.co.uk

Manchester
402 Chaddck Lane
Astley
Manchester
M29 7JS
London

Unit 9,
Bunns Lane Works,
Bunns Lane,
Mill Hill,
London
NW7 2AJ

This e-mail is confidential and is intended solely for the use of the
individual or entity to whom it is addressed. If you are not the intended
recipient and you have received this e-mail in error then any use,
dissemination, forwarding, printing or copying of this e-mail is strictly
prohibited. You should contact the sender by return e-mail and delete and
destroy all the information from your system. Any views or opinions
presented are solely those of the author and do not necessarily represent
those of JPS. This email does not form part of a legally binding agreement.
We have taken precautions to minimise the risk of transmitting software
viruses or trojans, but we advise that you carry out your own virus checks
on any attachments to this message. We cannot accept liability for any loss
or damage caused to your software, hardware or system.

More information about JPS can be found at our website at:
http://www.jpsprojectsl
Attachment:
Copy of Weekly Summary 28 12 2014 w.e 28.12.14.doc

Md5 Hashes:
030bbc1dc435a612d4ed7a049470ddb5
4cbc955ea75fa3edff0f73c2ca859119

Malware Macro document information:

VirusTotal Report [1]
(hits 0/56 Virus Scanners)

VirusTotal Report [2]
(hits 0/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Summary Paid Against - Jason Bracegirdle JPS Projects Ltd {jason.bracegirdle@jpsprojectsltd.co.uk} document malware

Summary Paid Against - Jason Bracegirdle JPS Projects Ltd {jason.bracegirdle@jpsprojectsltd.co.uk} macro based malware being spammed out.

The Word document has a random attachment, however these emails aren't from JPS Projects Ltd  at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this attachment as it won't have come from their servers and IT systems.

They may not be able to tell you if it's malware or even help clean up your system.
Message Header:
From: "Jason Bracegirdle JPS Projects Ltd" {jason.bracegirdle@jpsprojectsltd.co.uk}
Subject: Summary Paid Against
Date: Mon, 12 Jan 2015 20:47:34 +0900

Message Body:
Please find attached summary which was paid against

Jas

Jason Bracegirdle  Managing Director

M: 07912 883455
O: 02031 741416
F: 02030 700632
E: 
jason.bracegirdle@jpsprojectsltd.co.uk
W:  www.jpsprojectsltd.co.uk

Manchester
402 Chaddck Lane
Astley
Manchester
M29 7JS
London
Unit 9,
Bunns Lane Works,
Bunns Lane,
Mill Hill,
London
NW7 2AJ

This e-mail is confidential and is intended solely for the use of the
individual or entity to whom it is addressed. If you are not the intended
recipient and you have received this e-mail in error then any use,
dissemination, forwarding, printing or copying of this e-mail is strictly
prohibited. You should contact the sender by return e-mail and delete and
destroy all the information from your system. Any views or opinions
presented are solely those of the author and do not necessarily represent
those of JPS. This email does not form part of a legally binding agreement.
We have taken precautions to minimise the risk of transmitting software
viruses or trojans, but we advise that you carry out your own virus checks
on any attachments to this message. We cannot accept liability for any loss
or damage caused to your software, hardware or system.

More information about JPS can be found at our website at:
http://www.jpsprojectsl
Copy of Weekly Summary 28 12 2014 w.e 28.12.14.doc

Md5 Hashes:
030bbc1dc435a612d4ed7a049470ddb5
4cbc955ea75fa3edff0f73c2ca859119

Malware Macro document information:

VirusTotal Report [1]
(hits 0/56 Virus Scanners)

VirusTotal Report [2]
(hits 0/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Friday, 9 January 2015

Datasharp UK Ltd - Monthly Invoice & Report - ebilling@datasharp.co word malware

Datasharp UK Ltd - Monthly Invoice & Report - ebilling@datasharp.co emails with an attached document, is being spammed out.  The document contains a macro.

The Word document has a random attachment, however these emails aren't from Datasharp UK Ltd
at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this attachment as it won't have come from their servers and IT systems.

They may not be able to tell you if it's malware or even help clean up your system.
Comment Update: "I Work for Datasharp - we are receiving a high volume of calls due to this email - please just treat as spam - delete and virus check No need to call in - the email was not sent from us. (14:38)"
Message Header:
From: {ebilling@datasharp.co}
Subject: DO-NOT-REPLY Datasharp UK Ltd - Monthly Invoice & Report
Date: Fri, 09 Jan 2015 14:42:47 +0700

Message Body:
THIS MESSAGE WAS SENT AUTOMATICALLY
Attached is your Invoice from Datasharp Hosted Services for this month.
To view your bill please go to www.datasharp.co.uk.  Allow 24 hours before viewing this information.
For any queries relating to this bill, please contact hosted.services@datasharp.co.uk or call 01872 266644.
Please put your account number on your reply to prevent delays
Kind Regards
Ebilling

Invoice_2839240.doc

Md5 Hashes:
625dd97b2495691ea687adb122749508
94e5abd0bffe71c4e6b73a81c362fa5b

Malware Macro document information:

VirusTotal Report [1]
(hits 0/56 Virus Scanners)

VirusTotal Report [2]
(hits 0/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.RogueDoc.0hr.20150109-0752


NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Thursday, 8 January 2015

NOVEMBER INVOICE ADVISE Senior Accountant document malwar

INVOICE ADVISE and NOVEMBER INVOICE ADVISE another 4 variants of the Senior Accountant documents, are being spammed out containing a macro embedded in a excel and word document

The Excel and Word documents have a random attachment and use a random company name...they just being used to make the email look more genuine, ie. from a real company.

Message Header:
Subject: NOVEMBER INVOICE ADVISE
Subject: NOVEMBER INVOICE
Subject: INVOICE ADVISE
Subject: INVOICE ADVISE 08/01/2015

Example Message Body (Note: Name, Job Title and Company Name are random)
Good morning
Happy New Year
Please could you advise on the  November GBP invoice in the attachment for me?
Many thanks
Kind Regards
Caroline Hunter
Senior Accountant
OXFORD TECHNOLOGY VCT PLC
Random Attachment name:
RBAC_3800PI.xls or INV_5742CZ.doc

Md5 Hashes:
a8a9cc665f4cadb8bc32fdd9fe526ac6
61a314f2b18f93d65724abb84f0df3b9
93d2d7ad85e4e1f4f2ecf7c4065c4191
ce576a41bb0ad53c42aa4f2f534fb3bc

Malware Macro document information:

VirusTotal Report [1]
(hits 1/56 Virus Scanners)

VirusTotal Report [2]
(hits 1/56 Virus Scanners)

VirusTotal Report [3]
(hits 1/56 Virus Scanners)

VirusTotal Report [4]
(hits 1/56 Virus Scanners)


Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24671.DocHeur

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Ieuan James invoice EME018.docx {emerysieuan@gmail.com macro} malware

Ieuan James invoice  {emerysieuan@gmail.com} invoice EME018.docx is being spammed out containing a macro embedded in a word document...

Message Header:
From: Ieuan James {emerysieuan@gmail.com}
Subject: invoice EME018.docx
X-Mailer: iPhone Mail (12B411)

Example Message Body:
N/A
Attachment name:
invoice EME018.doc

Md5 Hashes:
8c355ebd6582ce9bc1e2187eb826f1cb

Malware Macro document information:

VirusTotal Report [1]
(hits 1/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as:Sanesecurity.RogueDoc.0hr.20150108-0806
Sanesecurity.Malware.24679.DocHeur
NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Wednesday, 7 January 2015

Eliza Fernandes NUCSOFT-Payroll December document malware

Eliza Fernandes NUCSOFT-Payroll December document, is being spammed out containing a macro
embedded in a word document

The Word document has a random attachment, however these emails aren't from NUCSOFT
at all, they just being used to make the email look more genuine, ie. from a real company.

Message Header:
From: "Eliza Fernandes" {eliza_fernandes@nucsoft.co.in}
Date: Wed, 07 Jan 2015 13:56:00 +0530
Subject: NUCSOFT-Payroll December 2014

Message Body:
Please find the data for payroll processing.

Please forward the PDF of summary.

Regards,
Eliza Fernandes

NUCSOFT Ltd.
Finance Dept.
---------------------------------------------------------------------
This message contains privileged and confidential information and is 
intended only for an individual named. If you are not the intended 
recipient, you should not disseminate, distribute, store, print, 
copy or deliver this message. Please notify the sender immediately 
by e-mail if you have received this e-mail by mistake and delete 
this e-mail from your system. E-mail transmission cannot be 
guaranteed to be secure or error-free as information could be 
intercepted,
---------------------------------------------------------------------
NUCSOFT : With You - Until Success  and Beyond....
Visit us at http://www.nucsoft.com
---------------------------------------------------------------------

Payroll Dec'14.doc

Md5 Hashes:
a5a79e75d3bb52de745ed45a6be86cbe

Malware Macro document information:

VirusTotal Report [1]
(hits 2/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24646.DocHeur


NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Tuesday, 6 January 2015

PAYMENT ADVICE Senior Accountant bacs malware document

A bacs PAYMENT ADVICE from Senior Accountant's are being spammed out.

The Word document has a random attachment, however these emails aren't from Senior Accountant's
at all, they just being used to make the email look more genuine, ie. from a real company.

Message Headers (Note that the Name and email address is random):
From: "Deann, Senior Accountant" {zoaudydiqw@metaphorivr.com}
Subject: PAYMENT ADVICE 06-JAN-2015
Date: Tue, 06 Jan 2015 19:25:25 +0800

Message Body: (Note that the amount and Name is random):
Dear all,
Payment has been made to you in amount GBP 16916,66 by BACS.
See attachment.
Regards,
Deann
Senior Accountant


One example of the random attachment file name:
BACS278606_218.doc

Md5 Hashes:
55d6c57bdad8a1e4210c1ff89cd88f78
661e6777cc51c335835a16bb2b79f42c
67fd8aac791e49bc90e851fa994bd525
ce596594218922c9d7429e7de11de3dd

Malware Macro document information:

VirusTotal Report [1]
(hits 0/56 Virus Scanners)

VirusTotal Report [2]
(hits 0/56 Virus Scanners)

VirusTotal Report [3]
(hits 0/56 Virus Scanners)

VirusTotal Report [4]
(hits 0/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24646.DocHeur


NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Card Receipt aquaid Tracey Smith malware word document

Card Receipt aquaid Tracey Smith emails are back once again in a targeted malware run.

"AquAid's" malware run of a macro infected "Card Receipt" word document has a random attachment,
however these emails aren't from Aquaid at all, they just being used to make the email look more
genuine, ie. from a real company.

Message Headers (Note that the email address is random):
From: "Tracey Smith" {tracey.smith550@aquaid.co.uk}
Subject: Card Receipt
Date: Tue, 06 Jan 2015 09:56:42 +0200

Message Body:

Hi

Please find attached receipt of payment made to us today

Regards
Tracey
Tracey Smith| Branch Administrator
AquAid | Birmingham & Midlands Central
Unit 35 Kelvin Way Trading Estate | West Bromwich | B70 7TP

Telephone:        0121 525 4533
Fax:                  0121 525 3502
Mobile:              07795328895
Email:               tracey.smith@aquaid.co.uk

AquAid really is the only drinks supplier you will ever need with our huge product range. With products ranging from bottled and mains fed coolers ranging up to coffee machines and bespoke individual one off units we truly have the right solution for all environments. We offer a refreshing ethical approach to drinks supply in that we support both Christian Aid and Pump Aid with a donation from all sales.  All this is done while still offering a highly focused local service and competitive pricing. A personalised sponsorship certificate is available for all clients showing how you are helping and we offer £25 for any referral that leads to business.

*********************************************************************
AquAid Franchising Ltd is a company registered in England and Wales with registered number 3505477 and registered office at 51 Newnham Road, Cambridge, CB3 9EY, UK. This message is intended only for use by the named addressee and may contain privileged and/or confidential information. If you are not the named addressee you should not disseminate, copy or take any action in reliance on it. If you have received this message in error please notify the sender and delete the message and any attachments accompanying it immediately. Neither AquAid nor any of its Affiliates accepts liability for any corruption, interception, amendment, tampering or viruses occurring to this message in transit or for any message sent by its employees which is not in compliance with AquAid corporate policy.


One example of the random attachment file name:
CAR015 151239.doc

Md5 Hashes:
2e8dc58a36806e13cd61e4a25f38c9ee
e7d6aa728aa28487400cb2ae82051531

Malware Macro document information:

VirusTotal Report [1]
(hits 0/56 Virus Scanners)

VirusTotal Report [2]
(hits 0/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24646.DocHeur


NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Tuesday, 23 December 2014

CHRISTMAS OFFERS: Jayne route2fitness.co.uk: (attached word malware)

Looks like some new word macro malware is incoming...
with no message body.... but does have an attached file:

From: "Jayne" Jayne@route2fitness.co.uk
Subject: CHRISTMAS OFFERS.docx


Currently the attached filename is: CHRISTMAS OFFERS.doc

As suspected it's a word macro malware.

Sanesecurity signatures are blocking this one as:

Sanesecurity.Malware.24646.DocHeur.UNOFFICIAL FOUND

Hashes so far... and ALL VirusTotal scanners are showing clean :(

76990032cc123694595913f1cc799e0e
9d0b2db07a5c5a903e0d599c8fcc63ca

Decoded macro here: (pastebin)

Route 2 Fitness is a Sports Club and won't have anything to do with the malware,
they are just being used as a target :(

Just to show you the sort of numbers involved in these virus runs... per hour... that one site is
receiving...




NOTE


The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))



Cheers,

Steve
Sanesecurity.com