Amazon

Monday, 20 April 2015

new credit terms / credit card balance malware

new credit terms / credit card balance malware with zip attachment...

Headers:
Subject: credit card balance
Subject: new credit terms
Message body:
Dear client,
We are pleased to inform you that our bank is ready to offer you a bank
loan. We would like to ask you to open the Attachment to this letter and
read the terms.

HSBC

We maintain strict security standards and procedures to prevent
unauthorised access to information about you. HSBC will never contact
you by e-mail or otherwise to ask you to validate personal information
such as your user ID, password, or account numbers. If you receive such
a request, please call our Direct Financial Services hotline.

Please do not reply to this e-mail. Should you wish to contact us,
please send your e-mail to commercialbanking@hsbc.com.hk and we will
respond to you.

Note: it is important that you do not provide your account or credit
card numbers, or convey any confidential information or banking
instructions, in your reply mail.

Copyright. The Hongkong and Shanghai Banking Corporation Limited 2015.
All rights reserved.
Attached to the email is a Zip file (Note: filename is random)
dalia_mas.zip
Inside the Zip file is a Windows Executable file (Note: filename is random)
Examples:

Blya.exe
Monkey.exe
Sha256 Hashes:
d53b2b9716054c9243542943998d93e454252e91d39cf1758e2c49483e440e70 [1]
2c5b22658070ea38c1dccd1a0e52edce2cb86be017b79055d62edfaad49bfd32 [2]
Anti virus reports:
VirusTotal Report: [1] (Detection 3/57)
VirusTotal Report: [2] (Detection 3/57)

Cheers,
Steve
Sanesecurity.com

Here is a document that you asked

Here is a document that you asked with zip attachment...

Headers:
From: {random email}
Subject: {random}
Message body:
hi

Here is a document that you asked
Attached to the email is a Zip file (Note: filename is random}
scan 59334.zip
Inside the Zip file is a Windows Executable file:
scan 59334.scr
Sha256 Hashes:
 2191354418154983ab885cc8063bd5c9a50bda057794c61ee7556930e4f33fbb [1]

Malware Anti-Virus Reports:
VirusTotal Report: [1] (hits 2/57 Virus Scanners)
Malwr Report: [1]

Summary:

Creates a windows hook that monitors keyboard input (keylogger)
Creates Zeus (Banking Trojan) mutexes
Creates an Alternate Data Stream (ADS)
Installs itself for autorun at Windows startup

Cheers,
Steve
Sanesecurity.com

Hector Malvido Pending payment handyman1181@hotmail.com

Hector Malvido Pending payment handyman1181@hotmail.com with an attached filename-1.doc word document containing a macro.

These emails aren't from these companies at all , they are just being used to make the email look more genuine, ie. from a real company.
Note
It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.

Headers:
From: Hector Malvido {handyman1181@hotmail.com}
Subject: Pending payment
Message Body:
This invoice shows in my records that has not being pay can you review
your records please 

 Attachment:
filename-1.doc
Sha256 Hashes:
74eb3307d32306e95960c99ee4bb040834647f3fd1f2b19f5c01f72cbca1d291
d902635d0fb1e4b4f1856ccdd92a0c5ddb7bcc24bab3e8eb2a2933d5cbe88f0a
ee7eb51b3ffba80546330499dd67928b4d312c1dbb5fb29866e24a062d9378f9
686e9a383b55bc3b172b448fb0a4ba17cd516bf536927b448e2e930be21c7802
b27453540d85d2f2d75c3b9d4202cae18f00dfaab490873ce798ecbf56a58656
6b2223e9a39147e93c1529755dc480d193ac172b89fd66d2d3fe8edf423c12f5
Malware Virus Scanner Reports:
VirusTotal Report: [1] (Detection 3/57)
VirusTotal Report: [2] (Detection 3/57)
VirusTotal Report: [3] (Detection 3/57)
VirusTotal Report: [4] (Detection 3/57)
VirusTotal Report: [5] (Detection 3/57)
VirusTotal Report: [6] (Detection 3/57)


NOTE

The current round of Word/Excel/XML attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to

steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))

Cheers,
Steve

Your Netflix Membership has been suspended phishing email.

Your Netflix Membership has been suspended phishing email.

Headers:
From: "Netflix"{membership.no-reply@netflix.ssl.com}
Subject: Your Netflix Membership has been suspended [#386729]
 body:
Validation failed

During a routine check of your account we have failed to validate the billing method we have on record for your account.

To continue using the Netflix service you will need to update/verify your billing information.
CONTINUE

Please note that failure to complete the validation process will result in the suspension of your netflix membership.

We thank you for your understanding.

Netflix Billing Support


Tweet

Like

Forward

Preferences  |  Unsubscribe

The link in the above message body is:
http://net-auth1.net/
The link then redirects you to a fake phishing site:
http://netflix.co.uk.membershipservices.cgi-bin.webobjects.mynetflix.woa.verify7.net-auth1.co.uk/f7c70cf252103e78ced2edb44714cb93/Login.php

The phishing site looks this this and asks you to login (which isn't a good idea):



Cheers,

Steve
Sanesecurity.com

Friday, 17 April 2015

Julie Mckenzie Credit Card Statement swift-cut.co.uk

 Credit Card Statement swift-cut.co.uk with an attached Swift Credit Card.doc word document containing a macro.

These emails aren't from these companies at all , they are just being used to make the email look more genuine, ie. from a real company.
Note
It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.

Headers:
From: "Julie Mckenzie" {julie40@swift-cut.co.uk}
Subject: Credit Card Statement
Message Body:
Hi
Attached your credit card statement.
Can you return with receipts by Friday 17th April.
Thanks
Julie


Julie McKenzie
Sales Administrator
Tel +44 (0)1543 473300
E-mail julie@swift-cut.co.uk


 Attachment:
 Swift Credit Card.doc
Sha256 Hashes:
678186db4206aa36e415f8953a5c37e2e3ad3f53114b16144f9128f5e21763ac [1]
215ce6f4fcf5327b39ab4c601f912e348b178b1d0ed335e52dd415039a05df4e [2]
0deaedf5c44702c9ab785b172c5089c3dca3f9a164d6caa6dfaeb8fee7da3fef  [3]
a41fe1a4694e573ad4de989afba58e252b40122cc271ee709818d746028edb8a [4]
d0e00cf1c866723a3f7e8790df342f13ae7a168989aa7640cf3f18bea64d90b1 [5]
c06a4542411deaf37c92a6275eacf873baaefecaa607308d37807819361df8c5 [6]
Malware Virus Scanner Reports:
VirusTotal Report: [1] (Detection 2/57)
VirusTotal Report: [2] (Detection 2/57)
VirusTotal Report: [3] (Detection 2/57)
VirusTotal Report: [4] (Detection 2/57)
VirusTotal Report: [5] (Detection 2/57)
VirusTotal Report: [6] (Detection 2/57)

Payload Info (thanks to Artifice)

http://marketingchannelideas.com/24/733 DOT exe [7]
VirusTotal Report: [7] (Detection 4/57)

NOTE

The current round of Word/Excel/XML attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to

steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))

Cheers,
Steve