Sponsored by..

Wednesday, 17 September 2014

"You've received a new fax". No you haven't, you've received a new bit of malware.

This tired old spam format comes with warmed-over malware attachment.
From:     Fax [fax@victimdomain.com]
Date:     17 September 2014 09:32
Subject:     You've received a new fax

New fax at SCAN6405035 from EPSON by https://victimdomain.com
Scan date: Wed, 17 Sep 2014 16:32:29 +0800
Number of pages: 2
Resolution: 400x400 DPI

You can secure download your fax message at:


(Google Disk Drive is a file hosting service operated by Google, Inc.)
The link in the email downloads an archive file Message_Document_pdf.zip from the same estudiocarraro.com.br site. This has a VirusTotal detection rate of 3/54. The ThreatTrack report shows that the malware attempts to phone home to:


Recommended blocklist:

No comments: