FYI...
Fake 'Invoice' SPAM - delivers Locky and Trickbot
- https://myonlinesecu...microsoft-word/
19 Oct 2017 - "Another change from the Necurs botnet delivering Locky and Trickbot again today with an email with the subject of 'Emailed Invoice – 459572' (random numbers) pretending to come from random names at your own email address or company domain...
They have changed to using word docs again but they are -not- using macros but using the DDE “exploit” or feature which -allows- linked files. These are very similar to embedded ole objects but instead of the object
(normally a script file) being embedded in the word doc & you clicking it to allow it to run, these link to a remote website without you seeing the link. This link describes it in better detail:
> https://blog.barkly....ttack-no-macros
One of the emails looks like:
From: Stacie Osborne <Stacie@ victim domain .tld>
Date: Thu 19/10/2017 11:15
Subject: Emailed Invoice – 459572
Attachment: I_459572.doc
Body content:
As requested
regards
Stacie Osborne ...
Screenshot of word doc:
> https://myonlinesecu..._459572_doc.png
I_459572.doc - Current Virus total detections 9/60*. Payload Security**
The word doc uses this DDE “feature” to contact (in this example, there will be loads of others)
http ://alexandradickman .com/KJHDhbje71 where a base64 encoded file is opened and decoded.
This has 3 hardcoded URLS inside it (again there will be others in other examples)
“http ://shamanic-extracts .biz/eurgf837or”,
”http ://centralbaptistchurchnj .org/eurgf837or”,
”http ://conxibit .com/eurgf837or” which gives a txt file which is -renamed- to rekakva32.exe
(VirusTotal 6/65[3]) (Payload Security[4])... The basic rule is NEVER open any attachment to an email, unless you are expecting it..."
* https://www.virustot...sis/1508408047/
** https://www.hybrid-a...vironmentId=100
DNS Requests
98.124.251.65
83.242.103.81
98.124.251.65
Contacted Hosts
98.124.251.65
62.212.154.98
83.242.103.81
3] https://www.virustot...sis/1508408465/
4] https://www.hybrid-a...vironmentId=100
Contacted Hosts
188.190.71.132
___
Fake 'eFax' SPAM - delivers Trickbot
- https://myonlinesecu...banking-trojan/
19 Oct 2017 - "An email with the subject of 'eFax' pretending to come from eFax service but actually coming from a whole range of look-a-like domains with a malicious word doc attachment is today’s latest spoof of a well-known company, bank or public authority delivering Trickbot banking Trojan... the criminals sending these have registered various domains that look-like genuine Company, Bank, Government or message sending services...
Screenshot: https://myonlinesecu...ervicexx_ml.png
efax190238535-34522.doc - Current Virus total detections 4/59*. Payload Security**
This malware file downloads from
http ://acupuncturenorthwest .com/kas47.png which of course is -not- an image file but a renamed .exe file that gets renamed to Fcd-4.exe (VirusTotal 12/64[3]). An alternative download location is
http ://www.agcofruit .com/kas47.png
This email attachment contains a genuine word doc with a macro script that when run will infect you.
The word doc looks like:
> https://myonlinesecu...5-34522_doc.png
... DO NOT follow the advice they give to enable macros or enable editing to see the content... The basic rule is NEVER open any attachment to an email, unless you are expecting it..."
* https://www.virustot...sis/1508420918/
** https://www.hybrid-a...vironmentId=100
DNS Requests
74.50.21.13
64.182.208.184
Contacted Hosts
74.50.21.13
64.182.208.184
79.170.7.139
185.125.46.77
3] https://www.virustot...f884d/analysis/
Fcd-4.exe
acupuncturenorthwest .com: 74.50.21.13: https://www.virustot...13/information/
> https://www.virustot...dfff7/analysis/
agcofruit .com: 192.185.118.67: https://www.virustot...67/information/
> https://www.virustot...70065/analysis/
___
Locky Ransomware’s Recent SPAM
- http://blog.trendmic...pam-activities/
Oct 19, 2017 - "... A closer look at Locky’s activities reveals a constant: the use of spam. While spam remains to be a major entry point for ransomware, others such as Cerber also employ vectors like exploit kits. Locky, however, appears to concentrate its distribution through large-scale spam campaigns regardless of the variants released by its operators/developers... We’ve also found how the scale and scope of Locky’s distribution are fueled by the Necurs botnet, a spam distribution infrastructure comprising zombified devices. It churns out a sizeable amount of spam emails carrying information stealers like Gameover ZeuS, ZBOT or Dridex, and other ransomware families such as CryptoLocker, CryptoWall, and Jaff. Necurs is Locky’s known and long-time partner in crime, and it’s no coincidence that the surge of Locky-bearing spam emails corresponds with the uptick in Necurs’ own activity. In fact, we saw that Necurs actively pushed Locky from August to October:
> https://blog.trendmi...ocky-spam-2.jpg
It’s also worth noting that Necurs also distributed Locky via URL-only spam emails — that is, the messages didn’t have -any- attachments, but rather -links- that divert users to -compromised- websites hosting the ransomware. The use of HTMLs embedded with -links- to the -compromised- site also started gaining traction this year... the continuous changes in Locky’s use of file attachments are its way of adjusting its tools to evade or bypass traditional security. But despite the seeming variety, there are common denominators in Locky’s social engineering, particularly in the email subjects and content. They appear to have the same old flavors, but with relatively different twists. Some of the recent lures we saw were:
- Fake voice message notifications (vishing, or the use of voice-related systems in phishing attacks)
- HTML attachments posing as invoices
- Archive files masquerading as business missives from multinationals, e.g., audit and budget reports
- Fraudulent emails that involve monetary transactions such as bills, parcel/delivery confirmations, and payment receipts..."
(More detail at the trendmicro URL above.)
Edited by AplusWebMaster, 19 October 2017 - 09:15 AM.