Sponsored by..

Monday, 1 June 2015

Malware spam: "Uplata po pon 43421" / "Mirjana Prgomet [mirjana@fokus-medical.hr]"

I have no idea what "Uplata po pon" means, but this spam does come with a malicious attachment:

From:    Mirjana Prgomet [mirjana@fokus-medical.hr]
Date:    20 May 2015 at 08:26
Subject:    Uplata po pon 43421
There is no body text, but the only example I saw had an attachment name of report20520159260[1].doc which contained this malicious macro [pastebin] which downloads a malicious executable from:


This is saved as %TEMP%\eldshrt1.exe and has a VirusTotal detection rate of 3/56. There are probably other download locations with other variants of the document, but the payload should be the same in each case.

Automated analysis tools [1] [2] [3] indicate network traffic to the following locations: (Selectel Network, Russia) (Digital Ocean, US) (Digital Ocean, Netherlands) (Hetzner, Germany)

The Malwr report shows that it drops a Dridex DLL with a detection rate of 5/53.

Recommended blocklist:


1 comment:

andi.cro said...

"Uplata po pon.xxxx" or "Uplata po ponudi broj xxxx" means "Payment per offer no.xxxx"

Everybody wants to know who's pay them for something and they open that mail and att.

This is very successful way to spread malware!