Amazon

Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Monday, 19 January 2015

FMG Support Group Ltd Insurance Inspection Arranged repairermessages@fmg.co.uk document malware

FMG Support Group Ltd Insurance Inspection Arranged repairermessages@fmg.co.uk  malware  are being spammed out.

The Word document has a random attachment, however these emails aren't from FMG Support Group Ltd at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header:
From: {repairermessages@fmg.co.uk}
Date: Mon, 19 Jan 2015 13:32:03 +0530
Subject: Insurance Inspection Arranged AIG02377973

Message Body:
FMG is committed to reducing its impact on the environment. Please don't print this email unless absolutely necessary.

Have you been impressed by one of our people?
If so, we'd love to hear about it. You can nominate someone for a Spirit award by emailing spirit@fmg.co.uk

FMG Support Group Ltd. Registered in England. No. 06489429.
Registered office: FMG House, St Andrews Road, Huddersfield, HD1 6NA.

Tel: 0844 243 8888
Email: info@fmg.co.uk

This email may contain confidential information and/or copyright material. This email is intended for the use of the addressee only. Any unauthorised use may be unlawful. If you received this email by mistake, please advise the sender by using the reply facility in your email software.

Outbound Message checked by Websense Mail Control.======================================================
This email, its content and any files transmitted with
it are confidential and intended solely for the use of
the individual(s) to whom it is addressed.
If you are not the intended recipient, be advised that
you have received this email in error and that any use,
dissemination, forwarding, printing or copying of
this email is strictly prohibited.
======================================================
Attachment:
AIG02377973-InsuranceInspectionArranged.doc

Md5 Hashes:
119f0030694bce7af3c2c1ba9fd5622d
5b242c0c6a76929c2d0040e39c8b87dd

Malware Macro document information:

VirusTotal Report [1] (hits 0/57 Virus Scanners)

VirusTotal Report [2] (hits 0/57 Virus Scanners)


Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as:

Sanesecurity.Malware.24676.DocHeur
Sanesecurity.Malware.24682.OffHeur

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Friday, 16 January 2015

Me new photo ;) and hola mi foto :) malware

Me new photo ;) malware in the form of a html email with a zip attachment:


Headers:
From:     "Juliya" {cauterizes580@netdealzbetter.com>
Subject: Me new photo ;)
}
Message body1:

Me new photo ;)

Message body2:
hola mi foto :)


The auto-downloaded Zip file is:

my_photo.zip

On the Windows machine, Inside the zip, is Windows executable:
my_photo_48378957348957489375893475893.exe

Md5 Hashes:
1e65c5db4c5112bf9b5ebc7e5286567e
Malware Information:
VirusTotal Report [1] (hits 2/57 Virus Scanners)

Hybrid-Analysis Report [1]

Cheers,

Steve
Sanesecurity.com

UK Fuels E-bill ebillinvoice.com velocitycardmanagement.com malware

UK Fuels Ltd - UK Fuels E-bill velocitycardmanagement.com ebillinvoice.com malware  are being spammed out.
The Word document has a random attachment, however these emails aren't from UK Fuels Ltd at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header:
 Date: Fri, 16 Jan 2015 10:08:44 +0300
From: invoices@ebillinvoice.com
Subject: UK Fuels E-bill

Message Body:
Dear Customer

Please find attached your invoice for Week 02 2015.

In order to open the attached DOC file you will need
the software Microsoft Word.

If you have any queries regarding your e-bill you can contact us at invoices@ebillinvoice.com. Alternatively you can log on to your account at www.velocitycardmanagement.com to review your transactions and manage your account online.

Yours sincerely

Customer Services
UK Fuels Ltd

======================================================
This email, its content and any files transmitted with
it are confidential and intended solely for the use of
the individual(s) to whom it is addressed.
If you are not the intended recipient, be advised that
you have received this email in error and that any use,
dissemination, forwarding, printing or copying of
this email is strictly prohibited.
======================================================
Attachment:
35056_02_2015.DOC

Md5 Hashes:
f26cb0d400e1f842605077de2c231726 [1]
fea2f5617fdf6f672ee117574734f859 [2]
436cffad2557fd4c083414a71527b73e [3]

Malware Macro document information:

VirusTotal Report [1] (hits 0/57 Virus Scanners)

VirusTotal Report [2] (hits 0/57 Virus Scanners)

VirusTotal Report [3] (hits 0/57 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as:

Sanesecurity.Malware.24676.DocHeur
Sanesecurity.Malware.24682.OffHeur

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

UK Fuels E-bill invoices@ebillinvoice.com document malware

UK Fuels E-bill  invoices@ebillinvoice.com  are being spammed out.
The Word document has a random attachment, however these emails aren't from UK Fuels Ltd at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header: (Note: the email address and amount are random)
 Date: Fri, 16 Jan 2015 10:08:44 +0300
From: invoices@ebillinvoice.com
Subject: UK Fuels E-bill

Message Body (Note:  the amount, company person and name are random)
Dear Customer

Please find attached your invoice for Week 02 2015.

In order to open the attached DOC file you will need
the software Microsoft Word.

If you have any queries regarding your e-bill you can contact us at invoices@ebillinvoice.com. Alternatively you can log on to your account at www.velocitycardmanagement.com to review your transactions and manage your account online.

Yours sincerely

Customer Services
UK Fuels Ltd

======================================================
This email, its content and any files transmitted with
it are confidential and intended solely for the use of
the individual(s) to whom it is addressed.
If you are not the intended recipient, be advised that
you have received this email in error and that any use,
dissemination, forwarding, printing or copying of
this email is strictly prohibited.
======================================================
Attachment: (Note: the filename is random)
35056_02_2015.DOC

Md5 Hashes:
f26cb0d400e1f842605077de2c231726 [1]
fea2f5617fdf6f672ee117574734f859 [2]
436cffad2557fd4c083414a71527b73e [3]

Malware Macro document information:

VirusTotal Report [1] (hits 0/57 Virus Scanners)

VirusTotal Report [2] (hits 0/57 Virus Scanners)

VirusTotal Report [3] (hits 0/57 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as:

Sanesecurity.Malware.24676.DocHeur
Sanesecurity.Malware.24682.OffHeur

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Thursday, 15 January 2015

ADP Invoice for week ending 01/11/2015 {Darrel.Doss@adp.com} malware

ADP Invoice for week ending 01/11/2015 {Darrel.Doss@adp.com} malware in the form of a html email, with an attached Zip.

Headers:
From: "Darrel.Doss@adp.com" {Darrel.Doss@adp.com}
Date: Thu, 24 Jul 2014 09:35:35 GMT
Subject: ADP Invoice for week ending 01/11/2015

Message body:

Your most recent ADP invoice is attached for your review.

If you have any questions regarding this invoice, please contact your ADP service team at the number provided on the invoice for assistance.

Please note that your bank account will be debited within one banking business day for the amount(s) shown on the invoice.

Thank you for choosing ADP for your business solutions.

Important: Please do not respond to this message. It comes from an unattended mailbox.
The auto-downloaded Zip file is: (Note: the downloaded filename is random)
invoice_418270412.pdf.zip

On the Windows machine, Inside the zip, is Windows executable (Note the dual extension)
invoice_418270412.pdf.scr

Md5 Hashes:
f98d0db9c365cf08235fc30c41276ef8
Malware Information:
VirusTotal Report [1] (hits 10/57 Virus Scanners)

hybrid-analysis Report [1] [Very Detailed]

Malwr Report [1]

Summary:

Performs some HTTP requests
Steals private information from local Internet browsers
Creates an Alternate Data Stream (ADS)
Installs itself for autorun at Windows startup
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24689.ZipHeur

Cheers,

Steve
Sanesecurity.com

Payment Advice - Advice Ref HSBC Advising Service malware

Payment Advice - Advice Ref HSBC Advising Service malware in the form of a html email, with a link to auto-download a ZIP file.  {Bankline.Administrator@nutwest.com}

WARNING: downloaded zip file is reported as: Cryptolocker.Suspicious by QuickHeal Anti-Virus (not confirmed)

Headers: (Note: The Ref. is Random)
From: "HSBC Advising Service" {Bankline.Administrator@nutwest.com}
Subject: Payment Advice - Advice Ref:[GB109055] / CHAPS credits

Message body:

Sir/Madam,

Please download document from dropbox, payment advice is issued at the
request of our customer. The advice is for your reference only.

Download link:

http://www.bosleymanagement DOT com/NATWEST_RELEASES/bankline.html

Yours faithfully,
Global Payments and Cash Management
HSBC

This is an auto-generated email, please DO NOT REPLY. Any replies to
this email will be disregarded.

Security tips

1. Install virus detection software and personal firewall on your
computer. This software needs to be updated regularly to ensure you have
the latest protection.
2. To prevent viruses or other unwanted problems, do not open
attachments from unknown or non-trustworthy sources.
3. If you discover any unusual activity, please contact the remitter of
this payment as soon as possible.

*******************************************************************
This e-mail is confidential. It may also be legally privileged. If you
are not the addressee you may not copy, forward, disclose
or use any part of it. If you have received this message in error,
please delete it and all copies from your system and notify the
sender immediately by return e-mail.

Internet communications cannot be guaranteed to be timely, secure, error
or virus-free. The sender does not accept liability
for any errors or omissions.
*******************************************************************
"SAVE PAPER - THINK BEFORE YOU PRINT!"
The auto-downloaded Zip file is: (Note: the downloaded filename is random)
doc140_pdf.zip

On the Windows machine, Inside the zip, is Windows executable (Note the dual extension)
doc726_pdf.exe

Md5 Hashes:
ac5bcb9d2d7f2dc9e36649f25232ee7f
10f19f8b9fba32aa2d53bcf48e277c67
bb983668e38ab0bd7ca93b42850b0e8f
Malware Information:
VirusTotal Report [1] (hits 5/57 Virus Scanners)
VirusTotal Report [2] (hits 5/57 Virus Scanners)

Joti Report [2] (hits 3/22 Virus Scanners)

Malwr Report [1]
Malwr Report [2]

Summary:

Error: Analysis failed: The package "modules.packages.zip" start function raised an error: Unable to execute the initial process, analysis aborted.

Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24688

Cheers,

Steve
Sanesecurity.com

Payment request of (14 JAN 2015) malware

Payment request of (14 JAN 2015) invoice from random emails and companies are being spammed out.
The Word/Excel document has a random attachment, however these emails aren't from these companies  at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header: (Note: the email address and amount are random)
Date: Thu, 15 Jan 2015 10:20:28 +0200
Subject: Payment request of 3511.15 (14 JAN 2015)
From: Merlin Boone {Jeffry.ce@cm-93-156-251-163.telecable.es}

Message Body (Note:  the amount, company person and name are random)
Dear Sirs,

Sub: Remitance of GBP 3511.15

This is with reference to the above, we request you to kindly remit GBP 3511.15 in favor of our bank account.
For more information on our bank details please refer to the attached document.

Thanking you,
Merlin BooneAccounts Payable
Attachment: (Note: the filename is random)
ADV0504GO.doc
5157090EZ.xls

Md5 Hashes:
44d5e293fc3e4a68aca41b5651f5b897 [1]
7f3c2b0c5abe311f4e40b2a938a8ed75 [2]
38665c6364dd127b4b8bf98e033c4ec7 [3]
984597f7d4e83599baac04c7708394b2 [4]

3cc59cb545020d0d44c8ec9e7e04dc25
551bf7d91d5a6ab6b887956d5ce08571
612feaa36adcccc9281970b73ac7d7ef

Malware Macro document information:

VirusTotal Report [1]
(hits 3/57 Virus Scanners)

VirusTotal Report [2]
(hits 3/57 Virus Scanners)

VirusTotal Report [3]
(hits 3/57 Virus Scanners)

VirusTotal Report [4]
(hits 3/57 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

faktura malware

faktura subject malware in the form of a html email, with an attached ZIP file...

Headers:
From: {adwokat.zabrze@interia.eu}
Subject: Re:faktura
Message body:

Witam

Przesyłam w załączeniu fakturę. Proszę doliczyć do najbliższej opłaty.
Attached to the email is a ZIP file:
DOC150114-faktura.doc.zip

On the Windows machine, Inside the zip, is Windows executable (Note the dual extension)
DOC150114-faktura.doc.exe

Md5 Hashes:
3bcfe0c5364fa07f09ae44306da8dd82

Malware Information:

VirusTotal Report [1]
(hits 8/57 Virus Scanners)

Malwr Report [1]

Summary:


File has been identified by at least one AntiVirus on VirusTotal as malicious
Executed a process and injected code into it, probably while unpacking
Installs itself for autorun at Windows startup


Cheers,

Steve
Sanesecurity.com

Payment request of invoice document malware

Payment request of invoice from random emails and companies are being spammed out.
The Word document has a random attachment, however these emails aren't from these companies  at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header: (Note: the email address and amount are random)
Subject: Payment request of 3682.49 (14 JAN 2015)
From: Lucinda Zamora {Mabel.ca9@mitchhughes.net}

Message Body (Note:  the amount, company person and name are random)
Dear Sirs,
Sub: Remitance of GBP 3682.49
This is with reference to the above, we request you to kindly remit GBP 3682.49 in favor of our bank account.
For more information on our bank details please refer to the attached document.
Thanking you,
Lucinda Zamora
Accounting Team
Attachment: (Note: the filename is random)
ADV9814QV.doc

Md5 Hashes:
44d5e293fc3e4a68aca41b5651f5b897 [1]
7f3c2b0c5abe311f4e40b2a938a8ed75 [2]
38665c6364dd127b4b8bf98e033c4ec7 [3]
984597f7d4e83599baac04c7708394b2 [4]

Malware Macro document information:

VirusTotal Report [1]
(hits 3/57 Virus Scanners)

VirusTotal Report [2]
(hits 3/57 Virus Scanners)

VirusTotal Report [3]
(hits 3/57 Virus Scanners)

VirusTotal Report [4]
(hits 3/57 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Invoice from Hexis {Invoice@hexis.co.uk} document malware

Invoice from Hexis {Invoice@hexis.co.uk} S-INV-CREATIFX document malware is being spammed out.
The Word document has a random attachment, however these emails aren't from HEXIS (UK) LIMITED  at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.

Update: Direct from Hexis themselves...  note, although they say they've been "hacked" they haven't been, it's just being faked:

Dear Customer,

Hexis UK Ltd has had their E-mail account hacked early this morning the hacker is sending emails that look like they are coming from Hexis with the following email address (invoice@hexis.co.uk).

If you receive an email from Hexis and are not expecting it then please DO NOT OPEN the email & simply delete it.

Please note that due to huge amount of emails that have been sent, we are receiving a very very high telephone demand from thousands of people.

Should you wish to place an order with Hexis then please bare with us or email us at sales@hexis.co.uk


We thank you for your understanding.

Message Header:
From: Invoice from Hexis {Invoice@hexis.co.uk}
Subject: Invoice

Message Body:
Sent 15 JAN 15 08:30

HEXIS (UK) LIMITED
7 Europa Way
Britannia Park
Lichfield
Staffordshire
WS14 9TZ

Telephone 01543 411221
Fax 01543 411246
Attachment:
S-INV-CREATIFX-465219.doc

Md5 Hashes:
7071702019e845579cefd35724d87944
b2356ce5a8f311df482d5b2a92e567ff

Malware Macro document information:

VirusTotal Report [1]
(hits 3/57 Virus Scanners)

VirusTotal Report [2]
(hits 0/21 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Wednesday, 14 January 2015

SEPA REMITTANCE ADVICE malware

SEPA REMITTANCE ADVICE macro based malware being spammed out.

The Word document has a random attachment, however these emails aren't from the company they appear to be from at all, they just being used to make the email look more genuine:
It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header (Note: Random from address)
From: Nichole England {Jared.4bbd@ono.com}
Subject: SEPA REMITTANCE ADVICE 6513.56 EUR 12 JAN 2014

Message Body: (Note: Name and amount is random)
Good Afternoon
Please see attached a copy of remittance advice for SEPA payment of 6513.56  EUR made on 12/01/2015
Regards,
Nichole England
Senior Accounts Payable
Attachment (Note: Random document name)
E538XH.doc

Md5 Hashes:
57dbc8da6e0ae797d5f0c7e22722cf37
9875233ba6f2c6d10fbf3c91f0b46a96

Malware Macro document information:

VirusTotal Report [1]  (hits 0/57 Virus Scanners)

VirusTotal Report [2]  (hits 0/57 Virus Scanners)


Malwr Report [1]

Malwr Report [2]


Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

INCOMING FAX REPORT malware

INCOMING FAX REPORT malware in the form of a html email, with an attached ZIP file.

Headers:
Date: Wed, 14 Jan 2015 09:42:22 +0800
From: "Incoming Fax" {no-reply@}
Subject: INCOMING FAX REPORT : Remote ID: 495-768-4745
Message body:

*********************************************************
INCOMING FAX REPORT
*********************************************************

Date/Time: Wed, 14 Jan 2015 09:42:22 +0800
Speed: 4801bps
Connection time: 02:06
Pages: 0
Resolution: Normal
Remote ID: 486-214-1247
Line number: 1
DTMF/DID:
Description: Internal Docs

Fax message attached in PDF format (Adobe Photoshop).
Attached to the email is a ZIP file:
FaxMessage69831_82741-84712.pdf.zip

On the Windows machine, Inside the zip, is Windows executable (Note the dual extension)
FaxMessage69831_82741-84712.pdf.scr

Md5 Hashes:
d54494741cfc549942c5e79a1213f200

Malware Information:

VirusTotal Report [1]
(hits 26/57 Virus Scanners)

Malwr Report [1]

Summary:






Cheers,

Steve
Sanesecurity.com

Les Mills Invoice goods/services lmuk.accounts@lesmills.com malware

Les Mills Invoice goods/services lmuk.accounts@lesmills.com macro based malware being spammed out.

The Word document has a random attachment, however these emails aren't from Les Mills at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header:
From: {lmuk.accounts@lesmills.com}
Date: Wed, 14 Jan 2015 09:41:56 +0200
Subject: Les Mills Invoice

Message Body:
Dear Customer,
Please find attached an invoice for Les Mills goods/services.  Please note that for Licence Fee invoices the month being billed is the month in which the invoice has been raised unless otherwise stated within.
If you have any queries please email lmuk.accounts@lesmills.com or call 0207 264 0200 and select option 3 to speak to a member of the team.
Best regards,
Les Mills Finance Team
Attachment:
Les Mills SIV035931.doc

Md5 Hashes:
0dd754a987d5f20624e55cb4ec1afeae
c6e31e9db8466b6ce1b1c06a268a7d26

Malware Macro document information:

VirusTotal Report [1]
(hits 0/57 Virus Scanners)

VirusTotal Report [2]
(hits 0/57 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Tuesday, 13 January 2015

Notice of payment - payment_notice - National Bank of Canada - malware

Notice of payment - payment_notice - National Bank of Canada - malware is now arriving in the form of a html email, with an attached ZIP file.

Headers:
Date: Wed, 14 Jan 2015 01:23:27 +0700
From: "sac.sbi@sibn.bnc.ca" {sac.sbi@sibn.bnc.ca}
Subject: Notice of payment
Message body:

You can view and print the notice of payment using the Netscape or Microsoft
Explorer browsers, versions 6.2 and 5.5.  You can export and store the
notice of payment data in your spreadsheet by choosing the attached file in
pdf format ".pdf".

If you have received this document by mistake, please advise us immediately
and return it to us at the following E-mail address:  "sac.sbi@sibn.bnc.ca".
Thank you.

National Bank of Canada
600 de La Gauchetire West, 13th Floor
Montreal, Quebec H3B 4L2


CP066684
CPI080000004345

CONFIDENTIALITÉ : Ce document est destiné uniquement à la personne ou à
l'entité à qui il est adressé.
L'information apparaissant dans ce document est de nature légalement
privilégiée et confidentielle. Si vous n'êtes pas le destinataire visé ou la
personne chargée de le remettre à son destinataire, vous êtes, par la
présente, avisé que toute lecture, usage, copie ou communication du contenu
de ce document est strictement interdit. De plus, vous êtes prié de
communiquer avec l'expéditeur sans délai ou d'écrire à
confidentialite@bnc.ca et de détruire ce document immédiatement.

CONFIDENTIALITY: This document is intended solely for the individual or
entity to whom it is addressed. The information contained in this document
is legally privileged and confidential. If you are not the intended
recipient or the person responsible for delivering it to the intended
recipient, you are hereby advised that you are strictly prohibited from
reading, using, copying or disseminating the contents of this document.
Please inform the sender immediately or write to confidentiality@nbc.ca and
delete this document immediately.

Attached to the email is a ZIP file:

payment_notice.pdf.zip

On the Windows machine, Inside the zip, is Windows executable (Note the dual extension)
payment_notice.pdf.scr

Md5 Hashes:
ad24f44fb0e99274dbb79cf9196e0ff5

Malware Information:

VirusTotal Report [1] (hits 14/57 Virus Scanners)

Malwr Report [1]

Summary:




Installs itself for autorun at Windows startup

Cheers,

Steve
Sanesecurity.com

Your FED TAX payment Rejected - TAX@irs.gov - malware

Your FED TAX payment Rejected malware is now arriving in the form of a html email,
with an attached ZIP file.

Headers:
Date: Tue, 13 Jan 2015 13:27:05 -0500
From: "TAX@irs.gov" {tax@irs.gov}
Subject: Your FED TAX payment (ID:MKPIRS625698164) was Rejected
Message body:

*** PLEASE DO NOT RESPOND TO THIS EMAIL ***

Your federal Tax payment (ID: MKPIRS625698164), recently sent from your  checking account was returned by the your financial institution.

For more information, please download attached notification. (Security Adobe PDF file)

Transaction Number: MKPIRS625698164}

Payment Amount: $ 5170.18
Transaction status: Rejected           
                                      
ACH Trace Number: 5555555555                
Transaction Type: ACH Debit Payment-DDA      

Internal Revenue Service
Metro Plex 1, 8401 Corporate Drive, Suite 300, Landover, MD 20785.

Attached to the email is a ZIP file:

FEDERAL_tax_notify.pdf.zip

On the Windows machine, Inside the zip, is Windows executable (Note the dual extension)
FEDERAL_tax_notify.pdf.scr

Md5 Hashes:
45f3c660daf2e9013c34a5708242af92

Malware Information:

VirusTotal Report [1]
(hits 13/57 Virus Scanners)

Malwr Report [1]

Summary:



Steals private information from local Internet browsers
Creates an Alternate Data Stream (ADS)
Installs itself for autorun at Windows startup


Cheers,

Steve
Sanesecurity.com

You have a new Secure Message "NatWest" {secure.message@natwest.com} malware

You have a new Secure Message "NatWest" {secure.message@natwest.com} malware has arrived in the form of a html email, with an attached ZIP file:

Headers:
From: "NatWest" {secure.message@natwest.com}
Subject: You have a new Secure Message
Message body:

You have received a encrypted message from NatWest Customer Support

In order to view the attachment please open it using your email client ( Microsoft Outlook, Mozilla Thunderbird, Lotus )

If you have concerns about the validity of this message, please contact the sender directly. For questions please contact the NatWest Bank Secure Email Help Desk at 0131 556 0993.

Attached is a Zip file:
SecureMessage.pdf.zip
Inside the Zip file, is a Windows Executable trying to pretend it's a PDF file:
SecureMessage.pdf.scr

MD5 Hash:

3f50268f9171bb1c5790954acd942f41
Scanner Reports:

VirusTotal [1] (9/56 hits)
Malwr Report [1]


Cheers,

Steve
Sanesecurity.com

Monday, 12 January 2015

eFax message from "unknown" malware

eFax message from "unknown" malware is now arriving with a dangerous zip attachment... (You have received a 1 page fax):

Headers:
Date: Mon, 12 Jan 2015 23:05:03 +0800
From: "eFax"
Subject: eFax message from "unknown" - 1 page(s), Caller-ID: 1-653-767-7935
Message body:
Fax Message [Caller-ID: 1-653-767-7935]
You have received a 1 page fax at Mon, 12 Jan 2015 23:05:03 +0800.
* The reference number for this fax is atl_did1-1400166434-08802401438-231.

View this fax using your PDF reader.

Please visit www.efax.com/en/online_fax_FAQ if you have any questions regarding this message or your service.

Thank you for using the eFax service!
The link in the email takes you to a website, which:

a) Kindly tells you...
JUST UNZIP AND OPEN IN YOUR PDF READER


Nice and helpful....

b) Auto-downloads a zip file... On the Windows machine, Inside the zip, is Windows executable:
pdf_efax_12986502-01-12.pif

Virus Scanner Reports:
Md5 Hash:  aca37373abb0b0f49795b404683b8e8b
VirusTotal Report: [1] (2/56 scanners report a hit)
Malwr Report


Cheers,

Steve
Sanesecurity.com

Jason Bracegirdle JPS Projects Ltd - Summary Paid Against - {jason.bracegirdle@jpsprojectsltd.co.uk}

Summary Paid Against - Jason Bracegirdle JPS Projects Ltd - Copy of Weekly Summary {jason.bracegirdle@jpsprojectsltd.co.uk} macro based malware being spammed out.

The Word document has a random attachment, however these emails aren't from JPS Projects Ltd  at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this attachment as it won't have come from their servers and IT systems.

They may not be able to tell you if it's malware or even help clean up your system.
Message Header:
From: "Jason Bracegirdle JPS Projects Ltd" {jason.bracegirdle@jpsprojectsltd.co.uk}
Subject: Summary Paid Against
Date: Mon, 12 Jan 2015 20:47:34 +0900

Message Body:
Please find attached summary which was paid against

Jas

Jason Bracegirdle  Managing Director

M: 07912 883455
O: 02031 741416
F: 02030 700632
E: 
jason.bracegirdle@jpsprojectsltd.co.uk
W:  www.jpsprojectsltd.co.uk

Manchester
402 Chaddck Lane
Astley
Manchester
M29 7JS
London

Unit 9,
Bunns Lane Works,
Bunns Lane,
Mill Hill,
London
NW7 2AJ

This e-mail is confidential and is intended solely for the use of the
individual or entity to whom it is addressed. If you are not the intended
recipient and you have received this e-mail in error then any use,
dissemination, forwarding, printing or copying of this e-mail is strictly
prohibited. You should contact the sender by return e-mail and delete and
destroy all the information from your system. Any views or opinions
presented are solely those of the author and do not necessarily represent
those of JPS. This email does not form part of a legally binding agreement.
We have taken precautions to minimise the risk of transmitting software
viruses or trojans, but we advise that you carry out your own virus checks
on any attachments to this message. We cannot accept liability for any loss
or damage caused to your software, hardware or system.

More information about JPS can be found at our website at:
http://www.jpsprojectsl
Attachment:
Copy of Weekly Summary 28 12 2014 w.e 28.12.14.doc

Md5 Hashes:
030bbc1dc435a612d4ed7a049470ddb5
4cbc955ea75fa3edff0f73c2ca859119

Malware Macro document information:

VirusTotal Report [1]
(hits 0/56 Virus Scanners)

VirusTotal Report [2]
(hits 0/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve