Friday, 31 October 2014

"Your Amazon.co.uk order has dispatched" spam has a malicious DOC attachment

This fake Amazon email comes with a malicious Word document attached:

From:     Amazon.co.uk [auto-shipping@amazon.co.uk]
Reply-To:     "auto-shipping@amazon.co.uk" [auto-shipping@amazon.co.uk]
Date:     31 October 2014 09:12
Subject:     Your Amazon.co.uk order has dispatched (#203-2083868-0173124)

The Word document contains a malicious macro [pastebin] but is currently undetected at VirusTotal (the Malwr report doesn't say much but is here).

The macro then downloads http://ctmail.me/1.exe and executes it. This malicious binary has a a detection rate of 4/52, and according to the Malwr report it contacts the following URLs:$4UsZiwg@/fJ_6E%24$~J%249BH/y93%266@@L3%3DL%26b88UmM/%24%24$%2C_5KQk%2BeQpaGr/&4b0ERginAuG/zx$.G6K%3F is Hostway in Belgium, is Wien Energie, Austria. The malware also downloads a DLL as 2.tmp which has a detection rate of 3/54.

Recommended blocklist 1:

UPDATE 1 - 2014-11-03

A very similar email is doing the rounds this morning with a different version of the attachment (called ORDER-203-2083868-0173124.doc) which has a VirusTotal detection rate of 0/54 and contains this malicious macro [pastebin]. This downloads a file from http://hilfecenter-harz.de/1.exe which also has zero detections at VirusTotal. According the the Malwr report this binary connects to the following URLs:$%2DKWssW9Yh/L3$%2Cqc%3F3@2+f.=hcf_c+vyqly%2Co.7/l%20nloj%7E%3F$sO%3DheysYSV/n5%3Fs/

It also downloads a malicious DLL which has a VirusTotal detection rate of 7/54 which identifies this as a version of Cridex.

Recommended blocklist 2:

UPDATE 2  - 2014-11-03

A second version of the attachment is also being circulated, this time with a slightly different macro [pastebin] which downloads the same binary as before from http://garfield67.de/1.exe. I have updated blocklist 2.

UPDATE 3 - 2014-11-06

The spam has been updated with a new date and there are now three new malicious Word documents [1] [2] [3] [Malwr report] which contains one of two macros [1] [2] that download a malware binary from one of the two following locations:


This file is saved as %TEMP%\LNZMTDCWLZX.exe and has a VirusTotal detection rate of 4/53. The Malwr report shows that it connects to:

It also drops a DLL which has a VirusTotal detection rate of 8/53 which is identified as Cridex.


Steve Basford said...

Malware Detected as: Sanesecurity.Malware.24528.DocHeur

Sze said...

MY PC has infected this virus, how can I remove it? thanks in advance for your help.

Sze said...

Is that mean I put these blocklist address in my router disallowed list may avoid this malware to download further files in the future?

Sze said...

I did open this attachment but searched om whole C drive but could not find 1.exe or 2.tmp do you thini my PC has infected this virus? my PC is window XP and Office XP

Conrad Longmore said...

You need to have macros enabled in Word for the infection to be successful, as far as I can tell.

The dropped DLL is widely detected now, for this I would receommend Malwarebytes to check and clean the system.

Sze said...

Thanks for answing, my Microsoft words set disable macro, I remember Word automatic closed in a second after I accident opened this attachment, do you think my PC didn't infect it?

Pilgrim Little Spear said...

Hallo, I got that mail today 06.11.14 and I tried to open the word document. It was refused, because of the Macro settings, but the file was downloaded in .temp . I deleated the word document as soon as possible. How can I prove my computer is not infected?