Sponsored by..

Wednesday 23 November 2011

Virus: "Hello! Look, I've received an unfamiliar bill, have you ordered anything?"

Here's a piece of fairly clever social engineering:

Date:      Tue, 22 Nov 2011 12:48:52 +0200
From:      "LILLIE Stinson" [accounting@victimdomain.com]
To:      [victim@victimdomain.com]
Subject:      Need your help!

Hello! Look, I've received an unfamiliar bill, have you ordered anything?
Here is the bill

Please reply as soon as possible, because the amount is large and they demand the payment urgently.

Looking forward to your answer

Fingerprint: 9caf6417-d5b308e2

The link goes to a legitimate website that has been hacked, which then redirects to bsredret.ru on 94.199.51.108 (23VNet, Hungary). A Wepawet report for the target page can be found here.

There are a variety of similar emails doing the rounds at the moment, and the IP and URL with the payload seems to change every day. It might be prudent to warn any users you are responsible for to look out..

No comments: