Amazon

Wednesday, 10 December 2014

XLS macro malware: Anglia Engineering Solutions Ltd

Looks like another XLS macro run has just started... this time it's faked from this company...


Subject: Remittance Advice from Anglia Engineering Solutions Ltd [ID 694878F]

Dear ,

We are making a payment to you.

Please find attached a copy of our remittance advice, which will reach your bank account on 11/12/2014.

If you have any questions regarding the remittance please contact us using the details below.

Kind regards

Bertha Hahn

Anglia Engineering Solutions Ltd
Tel: 01469 382553


There are currently 4 variants all of which were zero hour (0 hour) detected by:

Sanesecurity.Malware.24631.XlsHeur

Additionally Sanesecurity.Rogue.0hr.20141210-1026 blocks the following hashes on VirusTotal and
currently all not detected by any of the 56 Virus Scanners:

061930c8fc246872dda3af5670d3ea44
20a66473d970a3b91aa0e6184e6d7e76
b5153a417ab4e4a2017a08909c771dfd
ed3f7389bd63fb1dd6c35279e7009046

Cheers,

Steve
www.sanesecurity.com

Friday, 5 December 2014

XLS macro malware: K J Watking & Co

Looks like they've now switched to XLS (Excel) based macro malware instead of DOC (Word) based...

Various names from K J Watking & Co seems to be the company being used....

 
 
Four versions so far...
 
08e73d8f175eb9e9b557f0403019a302
8efa7edba64776a05c7fea4d07eb5021
92d499bb61395f29d2c09616894ba429
bddacd683e959f02ea8f590b989b2b83
 
Detected as:

rogue.hdb: Sanesecurity.Rogue.0hr.20141205-0827
rogue.hdb: Sanesecurity.Rogue.0hr.20141205-0901
phish.ndb: Sanesecurity.Malware.24629.XlsHeur
 
 

Wednesday, 12 November 2014

word malware continues

Word document based malware continues to changed it formats

Here's the latest two versions...

This one "from" Sandra Whitmore of Nazarethcare:



 And this one "from" Soo Sutton of Power EC Ltd:



Note that in both cases Thunderbird is showing an unknown size for the document.

Again, Sanesecurity.Malware.24528.DocHeur works a treat again and blocks them before
doing any damage.

Malware Detected as: Sanesecurity.Malware.24528.DocHeur
ClamAV 3rd Party signatures: http://sanesecurity.com
#clamav #sanesecurity #malware


Thursday, 6 November 2014

Fake Amazon word document malware

Just receiving some word document malware, supposedly from Amazon....



It was blocked by an existing signatures...

Malware Detected as: Sanesecurity.Malware.24528.DocHeur
ClamAV 3rd Party signatures: http://sanesecurity.com
#clamav #sanesecurity #malware

Current md5 hashes...

1b952f7556a5046a03f2d77877dcf507
d078b7afea87ceefc5064200a5412ae4
ef3aadf9aa910b00d99614b8cef7df0f

VirusTotal Result (5/54) @ 12.29














Tuesday, 4 November 2014

Remittance Advice November word malware

More malware infected word documents on their way...


From: "Doreen Todd"
Subject: Remittance Advice November WT1841041R
Reply-To: "Doreen Todd"


Dear Sir/Madam

Please find attached the details of the payment credited to your account =
for the sum of 1739.67 GBP

Regards


Doreen Todd

Accounts Payable Department DUCO


Malware Detected as: Sanesecurity.Malware.24528.DocHeur
ClamAV 3rd Party signatures: http://sanesecurity.com
#clamav #sanesecurity #malware  


12:26: VirusTotal Results: 12, 3 and 4
15:41: Eset have just added detection, so after 3 hours we have 1/54 AV's picking it up