Lloyds Commercial Bank: "Important - Commercial Documents"
From: Lloyds Commercial Bank [firstname.lastname@example.org]
Date: 8 October 2014 11:09
Subject: Important - Commercial Documents
Important account documents
Case number: 66324010
Please review BACs documents.
Click link below, download and open document. (PDF Adobe file)
Please note that the Terms and Conditions available below are the Bank's most recently issued versions. Please bear in mind that earlier versions of these Terms and Conditions may apply to your products, depending on when you signed up to the relevant product or when you were last advised of any changes to your Terms and Conditions. If you have any questions regarding which version of the Terms and Conditions apply to your products, please contact your Relationship Manager. .
Senior Manager, Lloyds Commercial Banking
Calls may be monitored or recorded in case we need to check we have carried out your instructions correctly and to help improve our quality of service.
Please remember we guarantee the security of messages sent by email.
NatWest: "You have a new Secure Message - file-2620"
From: NatWest [email@example.com]
Date: 8 October 2014 10:29
Subject: You have a new Secure Message - file-2620
You have received a encrypted message from NatWest Customer Support
In order to view the attachment please open it using your email client ( Microsoft Outlook, Mozilla Thunderbird, Lotus )
Please download your ecnrypted message at:
(Google Disk Drive is a file hosting service operated by Google, Inc.)
If you have concerns about the validity of this message, please contact the sender directly. For questions please contact the NatWest Bank Secure Email Help Desk at 0131 556 3068.
The link in the email runs through a script which will attempt to download a ZIP file pdf-to-view_864129_pdf.zip onto the target machine which in turn contains a malicious executable pdf-to-view_864129_pdf.exe which has a VirusTotal detection rate of 6/53.
The Malwr report indicates that the malware phones home to the following locations which are worth blocking, especially 126.96.36.199 (Leaseweb, Netherlands) which looks like a C&C server.