From: Fax [fax@victimdomain]There seems to be an uptick of goo.gl spam.. if you receive something like this you can report it to goo.gl/spam-report as malware.
Date: 31 July 2014 11:23
Subject: You've received a new fax
New fax at SCAN5735232 from EPSON by https://victimdomain
Scan date: Thu, 31 Jul 2014 19:23:11 +0900
Number of pages: 2
Resolution: 400x400 DPI
You can download your fax message at:
https://goo.gl/1rBYjl
(Google Disk Drive is a file hosting service operated by Google, Inc.)
------------------------------
From: FAX [fax@qcom.co.uk]
Reply-to: FAX [fax@qcom.co.uk]
fax@localhost
Date: 31 July 2014 10:53
Subject: You have received a new fax message
You have received fax from EPS76185555 at victimdomain
Scan date: Thu, 31 Jul 2014 16:53:10 +0700
Number of page(s): 2
Resolution: 400x400 DPI
Download file at google disk drive service - dropbox.
https://goo.gl/t8jteI
_________________________________
File is scanned image in PDF format.
Adobe(A) Reader(R) can be downloaded from the following URL: https://www.adobe.com/
I've seen three different URLs:
goo.gl/1rBYjl
goo.gl/t8jteI
goo.gl/RmGnbr
These lead to the following download locations:
pinkfeatherproductions.com/wp-content/uploads/2014/06/Document-95722.zip
autoescuelajoaquin.com/images/Document-95722.zip
esys-comm.ro/images/Document-95722.zip
Obviously, this is a ZIP file. It contains a malicious executable Document-95722.scr which has a VirusTotal detection rate of just 1/54. The CAMAS report shows that the malware reaches out to the following locations to download further components:
andribus.com/images/images.rar
owenscrandall.com/images/images.rar
Incidentally, if you add a "+" to the end of the goo.gl URL you can see how many people have clicked through. For example:
164 clicks isn't a lot, but there are multiple URLs in use.
Recommended blocklist:
andribus.com
owenscrandall.com
esys-comm.ro
autoescuelajoaquin.com
pinkfeatherproductions.com
2 comments:
Thank you for this. That link to report spam on the shortner was impossible to find otherwise.
Just got another email that is the exact same as what you have but instead of using the goo.gl shortening it's using tinyurl
address here: https://tinyurl.com/ndln9gy
Post a Comment