Another run of the faked K J Watking & Co, containing an XLS spreadsheet... BAC439622TB.xls (example name) which has Macro based malware inside it....
Please find attached a remittance advice for recent BACS payment.
Any queries please contact us.
Heath David
Senior Accounts Payable Specialist
K J Watking & Co
Tel: 01469 432377
Interestingly they've used the same malware XLS has the earlier post today and just renamed it...
eg.
This malware run: BAC998947HJ.xls (hash: 061930c8fc246872dda3af5670d3ea44)
Ealier malware run: ID_00477M.xls: (hash: 061930c8fc246872dda3af5670d3ea44)
All varients were zero hour (0 hour) detected by:
Sanesecurity.Malware.24631.XlsHeur (phish.ndb)
and Additionally Sanesecurity.Rogue.0hr.20141210-1026 (rogue.hdb)
Update:
Since the macro malware downloads an exe... it's interesting to see how many times
the malware exe file has actually succeeded in being downloaded:
73,655 -- http://217 DOT 174 DOT 240 DOT 46 :8080/stat/stati.php
73,672 -- http://187 DOT 33 DOT 2 DOT 211 :8080/stat/stati.php
That's a few infected pc's there :(
Cheers,
Steve
Sanesecurity