Sponsored by..

Tuesday 17 May 2016

Malware spam: "Per E-Mail senden: DOC0000329040"

This German-language spam comes with a malicious attachment. It appears to come from the victim themselves, but this is just a simple forgery.
From:    victim@victimdomain.tld
Date:    17 May 2016 at 13:28
Subject:    Per E-Mail senden: DOC0000329040

Folgende Dateien oder Links k├Ânnen jetzt als Anlage mit Ihrer Nachricht
gesendet werden:

Attached is a ZIP file that matches the reference number in the subject and body text. I have only seen one sample, downloading a binary from:


The VirusTotal detection rate is 4/57, the comments in that report indicate that this is Locky ransomware and the C&C servers are at: (SmartApe, Russia) (Radore Veri Merkezi Hizmetleri, Turkey) (ITL, Ukraine) (Total Server Solutions, US)

Recommended blocklist:

No comments: