From: Geir Myklebust (DHL NO) [Geir.Myklebust@dhl.com]
Date: 10 September 2014 10:35
Subject: FW: customer acct. no.: 4690086 - invoice 0257241 needs to be paid
Dear Sir.
The attached invoice from Villmarksmessen 2014 has still not been settled.
Please advise as soon as possible.
Thank you and regards,
Geir
Med vennlig hilsen/ Kind Regards
Geir Myklebust
Product Manager, Avd. Trade Fairs & Events
DHL Global Forwarding (Norway) AS
Avd. Trade Fairs & Events
Messeveien 14
2004 Lillestrøm
Postboks 154 Leirdal
NO-1009 OSLO
NORWAY
Direct line: + 47 90 95 58 26
Fax: + 47 64 00 71 87
Mobile: + 47 90 78 52 44
Dear Sir.The attached invoice from Villmarksmessen 2014 has still not been settled.Please advise as soon as possible.Thank you and regards,GeirMed vennlig hilsen/ Kind Regards
Geir Myklebust
Product Manager, Avd. Trade Fairs & EventsDHL Global Forwarding (Norway) AS
Avd. Trade Fairs & Events
Messeveien 14
2004 Lillestrøm
Postboks 154 Leirdal
NO-1009 OSLO
NORWAY
Direct line: + 47 90 95 58 26
Fax: + 47 64 00 71 87
Mobile: + 47 90 78 52 44
Attached is a ZIP file of various different names (e.g. invoice_0257241.zip), containing a malicious executable file invoice_3466198.exe which has a VirusTotal detection rate of 3/54.
The Comodo CAMAS report shows an attempted connection to voladora.com/Imagenes/qaws.cab which is currently coming up with a socket error. I would recommend that you block access to that domain. Further analysis is pending, I will update the post if I find more information.
UPDATE: a second malicious binary is doing the round, this time with a detection rate of 2/53. The ThreatTrack report [pdf] and Anubis report shows the malware performing lookups for a variety of domain names [pastebin] which are not currently resolving, but might be worth blocking.