Amazon

Wednesday, 10 December 2014

Fake ACH Bank account information form

Busy malware day today... another new one just arriving...

From: "Josiah Nickerson"
Subject: ACH - Bank account information form

Please fill out and return the attached ACH form along with a copy of a voided check.

Josiah Nickerson,

JPMorgan Chase
GRE Project Accounting
Vendor Management & Bid/Supervisor
Fax-602-221-2251
Josiah.Nickerson@jpmchase.com
GRE Project Accounting


Email comes with a Check_Copy_Void.zip attachment (hash: 501f2cc2cf1e7f5c7bdc795070f33321)
which contains a Check_Copy_Void.scr malware

VirusTotal Report [7/56]

You have received a new fax malware (zip)

Another malware fax run, which says it's a pdf file but really it's a zip file, containing an exe attachment:

From: "INTERNAL FAX"
Subject: You have received a new fax

You have received fax from EPSON06789041 at newxxxxxxxx.co.uk

Scan date: Wed, 10 Dec 2014 13:14:17 -0700

Number of page(s): 10

Resolution: 400x400 DPI

Name: fax187498127.pdf

_________________________________
Attached file is scanned image in PDF format.



The attachment is: fax4189052.exe (hash: ef7331bc368ae1e5acddd637ab33a352)

VirusTotal result so far...[4/56]

new photo malware

Received some emails saying that I've got to look at a new photo...


hi my new photo :) if u like my photo send me u




.... lovely.... except... it contains a zip attachment... my_photo.zip

Inside the zip file is a poor attempt at filename hiding...

my_photo_home_38472398472398749283.exe

Here's the current scanner situation..

VirusTotal Results 17/56 (df0620c00068fc83a539d95fda4bbb7f)


Voice redirected message malware

Received a few of these today....

Date: Wed, 10 Dec 2014 13:49:50 +0000
From: "Message Admin" dropibox.com
>
To: enquiries@xxxxxxxxxx.co.uk
Subject: Voice Message
Message-ID: <0298040680 span="" style="color: red;">dropibox.com>
X-Sender: admin@dropibox.com
User-Agent: Roundcube Webmail/1.0.1

Voice redirected message
http://offroadshop DOT sk/dropbox/invoice1
Sent: Wed, 10 Dec 2014 13:49:50 +0000

Note: the letter i in the dropbox name... dropibox.com

Needless to say, the clickable link delivers malware.

XLS Macro malware: K J Watking & Co

Another run of the faked  K J Watking & Co, containing an XLS spreadsheet... BAC439622TB.xls (example name) which has Macro based malware inside it....


Please find attached a remittance advice for recent BACS payment.
Any queries please contact us.
Heath David
Senior Accounts Payable Specialist
K J Watking & Co
Tel: 01469 432377
 Interestingly they've used the same malware XLS has the earlier post today and just renamed it...

eg.

This malware run: BAC998947HJ.xls (hash: 061930c8fc246872dda3af5670d3ea44)
Ealier malware run: ID_00477M.xls: (hash: 061930c8fc246872dda3af5670d3ea44)
All varients were zero hour (0 hour) detected by:

Sanesecurity.Malware.24631.XlsHeur (phish.ndb)
and  Additionally Sanesecurity.Rogue.0hr.20141210-1026 (rogue.hdb)

Update:

Since the macro malware downloads an exe... it's interesting to see how many times
the malware exe file has actually succeeded  in being downloaded:

73,655 -- http://217 DOT 174 DOT 240 DOT 46 :8080/stat/stati.php
73,672 -- http://187 DOT 33 DOT 2 DOT 211 :8080/stat/stati.php

That's a few infected pc's there :(

Cheers,
Steve
Sanesecurity