Monday, 15 February 2016

Malware spam: "Invoice (w/e 070216)" / Kelly Pegg []

This fake financial spam does not come from Response Recruitment but is instead a simple forgery with a malicious attachment:
From     Kelly Pegg []
Date     Mon, 15 Feb 2016 13:15:37 +0200
Subject     Invoice (w/e 070216)

Good Afternoon

Please find attached invoice and timesheet.

Kind Regards

Attached is a file SKM_C3350160212101601.docm which comes in several different variants. The macro in the document attempts to download a malicious executable from:

This dropped a malicious executable with a detection rate of 6/54 which according to these automated analysis tools [1] [2] calls home to: (B & K Verwaltungs GmbH, Germany)

I strongly recommend that you block traffic to that address. The payload is the Dridex banking trojan.

1 comment:

  1. If I opened this and it saved what can it do? Thanks
