Sponsored by..

Tuesday, 12 May 2009

"Western Union Transfer MTCN: 2474153681" trojan

Another EXE-in-ZIP trojan, this time disguised as an Excel spreadsheet. The pitch is:

Subject: Western Union Transfer MTCN: 2474153681
From: "Western Union Support Team" support@westernunion.com
Date: Tue, May 12, 2009 11:00 pm

Dear Customer!

The money transfer you have sent on the 22nd of April was not collected by the
recipient.
According to the Western Union contract the transfers which are not received in 15
days are to be returned to sender.
To collect cash you need to print the invoice attached to this email and visit the
nearest Western Union agency.

Thank you!
In this case there was an attachment called Invoice_8773.zip containing a file named Invoice_8773.exe. Because of the really stupid way that Windows (by default) hides the file extensions and the fact that the bad guys have given this executable a convincing icon, it will look something like this when unzipped:

VirusTotal identifies is as a variant of Zbot, the ThreatExpert prognosis has more details in case you are trying to clean it up.

If you can block EXE-in-ZIP files at your mail perimeter, then that is always the best defence against this kind of attack.

No comments: