Sponsored by..

Wednesday, 16 December 2015

Malware spam: "Documentation: Your Order Ref: SGM249/013" / "Jonathan Carroll [Jonathan@john-s-shackleton.co.uk]"

This fake financial spam is not from John S. Shackleton (Sheffield) Ltd but is instead a simple forgery with a malicious attachment. It is the second spam in a day pretending to be from a steel company.

From     Jonathan Carroll [Jonathan@john-s-shackleton.co.uk]
Date     Wed, 16 Dec 2015 11:11:09 -0000
Subject     Documentation: Your Order Ref: SGM249/013

Your Order: SGM249/013
Our Order: 345522
Advice Note: 355187
Despatch Date: 22/12/15

Attachments:
s547369.DOC Shackleton Invoice Number 355187


John S. Shackleton (Sheffield) Ltd
4 Downgate Drive
Sheffield
S4 8BU

Tel: 0114 244 4767
Fax: 0114 242 5965

E-mail: sales@john-s-shackleton.co.uk
Web: www.johnsshackleton.co.uk

Phone us for a free stock brochure.

Our product range includes: Beams, Columns, Pfc's, Channels, Flats, Rounds, Squares,
Angles, Tees, Convex, ERW Tubes, Hollow Section, Cold Reduced Sheet, Hot Rolled Sheet
Galvanised Sheet, Zintec Sheet, Floorplate, Open Mesh Flooring, Handrail Standards,
Tube, Tubeclamps. Welded Mesh, Expanded Metal, Perforated Sheet, U Edging, Fencing
and Bright Bar.

IMPORTANT NOTE

Our Terms and Conditions of Sale apply to all quotations and the supply of all goods.
Copies of our Terms and Conditions of Sale are available on request or can be found
on our website www.johnsshackleton.co.uk . These
Terms and Conditions include a provision (see term 12) that title to goods supplied
shall not pass to a customer until payment is received by us in full for all goods
supplied. We only accept orders for the supply of goods on the basis our Terms and
Conditions of Sale apply.

I have only seen a single sample of this spam, with an attachment s547369.DOC which has a VirusTotal detection rate of 4/55. According to this Malwr Report it downloads a malicious binary from:

bbbfilms.com/98g654d/4567gh98.exe

This binary has a detection rate of 4/53 and is the same payload as found in this spam run, leading to the Dridex banking trojan.

No comments: