Sponsored by..

Friday 26 June 2015

Malware spam: "Notification of Vehicle Tax DD Payment Schedule (Ref: 000000-000005-274421-001)" / "directdebit@taxdisc.service.gov.uk"

This spam does not come from the UK government , but instead is a simple forgery with a malicious payload:

From: directdebit@taxdisc.service.gov.uk
Date: Fri, 26 Jun 2015 15:58:38 +0700
Subject: Notification of Vehicle Tax DD Payment Schedule (Ref: 000000-000005-274421-001)

Important: Confirmation of your successful
Direct Debit instruction

Dear customer
Vehicle registration number: FG08OEE
Thank you for arranging to pay the vehicle tax by Direct Debit.
Please can you check that the details attached below, and your payment schedule are correct.
If any of the above financial details are incorrect please contact your bank as soon as possible.
However, if your details are correct you don’t need to do anything and your Direct Debit will be processed as normal. You have the right to cancel your Direct Debit at any time. A copy of the Direct Debit Guarantee is included with this letter.
For your information, the collection will be made using this reference, and this is how your payment will be detailed on your bank statements:
  • DVLA Identifier: 295402
  • Reference: FG08OEE
Your vehicle tax will automatically renew unless you notify us of any changes. We will send a new payment schedule at the time of renewal.
Yours sincerely

Rohan Gye
Vehicles Service Manager

Driver a& Vehicle Licencing Agency logo

Attached to the message is a file FG08OEE.doc with a VirusTotal detection rate of 2/55. The macro in it proved resistant to manual analysis, but the Hybrid Analysis does the job easily enough, spotting a download from:


This file was also being used in another spam run earlier today.


1 comment:

Donald said...

Just this week i received identicle notification and decided to keep it till nearer the time with my payment. Being suspicious of the almost all black print I decided to check it out and here we are at this site. I will now be reporting this and put it to spam