As a general rule of thumb, never open a zip file attachment from someone you don't know. Even then scan it for viruses before opening it.
Here's what to look out for;
The e-mail subject was INTERNAL FAX
The attachment name I received was FAX827-482-9123.zip . The infectious software is contained inside the zip file. It also contained an attachment named ATT00001.txt (which is not a virus).
RansomWare message body text;
You have received fax from EPSON09964727 at sidsolve.com
Scan date: Wed, 26 Nov 2014 10:18:44 -0500
Number of page(s): 61
Resolution: 400x400 DPI
Name: FAX827-482-9123.pdf
_________________________________
Attached file is scanned image in PDF format.
The message came from XTLAMJHEK (74.252.107.66) around the Orlando, Florida area. The sender's address was 8GEGBYXZ.4384595@bleuit.com . The return path is cidejilk@bleuit.com . The sender spoofed a fake address named fax@sidsolve.com. This would likely be customized to the victim's domain. The company that owns the domain is based on Guernsey in the Channel Islands.
No comments:
Post a Comment
I won't post comments with links. If you'd like a link on site contact me directly.