Sponsored by..

Monday 22 September 2014

"Your online Gateway.gov.uk Submission" spam

This fake spam from the UK Government Gateway leads to malware:

From:     Gateway.gov.uk
Date:     22 September 2014 12:54
Subject:     Your online Gateway.gov.uk Submission


Electronic Submission Gateway

Thank you for your submission for the Government Gateway.
The Government Gateway is the UK's centralized registration service for e-Government services.

To view/download your form to the Government Gateway please visit http://www.gateway.gov.uk/

This is an automatically generated email. Please do not reply as the email address is not
monitored for received mail.
gov.uk - the best place to find government services and information - Opens in new window

The best place to find government services and information

The link in the email does not go to gateway.gov.uk at all, but in this case the the link goes to the following:
http://maedarchitettura.it/wfntvkppqi/wnazvamlzv.html ->
http://www.maedarchitettura.it/wfntvkppqi/wnazvamlzv.html ->
http://maedarchitettura.it/wfntvkppqi/GatewaySubmission.zip

The ZIP file contains a malicious executable GatewaySubmission.exe which has a VirusTotal detection rate of 1/55. The Anubis report shows that it attempts to make a connection to ruralcostarica.com which is probably worth blocking.

No comments: