Greeting e-card from Hallmark leads to download of Net-Worm.Win32.Mytob


MX Lab reports that a new campaign regarding greeting e-card that lead to malware is in circulation.

The messages have the subject “You have received a greeding e-card !” and come from the spoofed email address <[email protected]> to make it look genuine and coming from Hallmark itself, which is obviously not the case.

The email looks like this:

The link under “To see it, click here” and “We invite you to make a friend’s day and send one.” will lead you to a server that hosts the 2,9 MB large file ecard.exe which is malware known as Net-Worm.Win32.Mytob (Ikarus) or Win32:Malware-gen (Avast).

Virus Total permlink and MD5: 220934c050bb2335889b56a807026109.

Warning regarding your account contains trojan FakeAV


Yesterday, MX Lab intercepted some emails regarding a temporary locked account because someone else may have been accessing the account (read the article). Today, a new trojan variant is attached in the ZIP archive in a similar campaign. The trojan is known as Trojan.Win32.FakeAV (Ikarus, Sophos) or Trojan:W32/Agent.DIUK (F-Secure).

The email is send out from a random spoofed email address. The subject is: “***.be account notification” where *** represents the domain name of the intended recipient.

The content of the email:

Dear Customer,

This e-mail was send by ***.be to notify you that we have temporanly prevented access to your account.

We have reasons to beleive that your account may have been accessed by someone else. Please run attached file and Follow instructions

(C) ***.be

An attached file Instructions.zip contains the 144 kB large file Instructions.exe after extraction.

The following files are created:

%CommonDesktopDir%\ReaderAdobe.exe
%CommonDesktopDir%\ReaderAdobe30643.exe
%CommonDocuments%\My Music\Sample Music\BeethovensScherzo.exe
%CommonDocuments%\My Pictures\Sample Pictures\Bluehills17865.exe
%CommonPrograms%\Accessories\Accessibility\WizardAccessibility.exe
%CommonPrograms%\Administrative Tools\ServicesComponent.exe
%CommonPrograms%\Administrative Tools\ServicesComponent21682.exe
%CommonPrograms%\ReaderAdobe.exe
%Profiles%\Default User\Start Menu\Programs\Accessories\PromptCommand.exe
%Programs%\Accessories\BookAddress.exe
%Windir%\AppPatch\MicrosoftOperating5.1.2600.21802.0408032158.exe
%Windir%\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\FrameworkUtilities.exe
%Windir%\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\VisualVisualBasic.exe
%Windir%\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\VisualStudio.exe
%Windir%\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\FrameworkSystem.exe
%Windir%\assembly\NativeImages_v2.0.50727_32\System.Transactions\f103eb6750b18845ae26e7fb5d490394\Microsofttransactions.exe
%Windir%\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\10b68212c5158047877d5f404cc639f7\SystemMicrosoft.exe
%Windir%\Cache\Adobe Reader 6.0.1\ENUBIG\dllMsiExecInstMsi.exe
%Windir%\Cache\Adobe Reader 6.0.1\ENUBIG\WindowsUnicode006.000.001.exe
%FontsDir%\FontSystem.exe
%FontsDir%\SystemEGA80WOA4.00.950.exe
%Windir%\Microsoft.NET\Framework\Microsoftsbsmscorrc.exe
%Windir%\Microsoft.NET\Framework\sbscmp10Microsoft.exe
%Windir%\Microsoft.NET\Framework\v1.0.3705\FrameworkMicrosoft.exe
%Windir%\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\uiwrapperresuiwrapperres8.0.50727.42.exe
%Windir%\NOTEPADManager.exe
%Windir%\pchealth\UploadLB\Binaries\SystemMicrosoft.exe
%Windir%\Resources\Themes\Luna\Shell\Metallic\WindowsWindows.exe
%System%\mui407\xpsp2resxpsp2res.exe
%System%\mui418\MicrosoftSystem.exe
[file and pathname of the sample #1]
%Windir%\WindowsWINHLP321711.exe
%Windir%\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\OperatingWindows6.02.0408032158.exe
%Windir%\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcrtmsvcrt7.0.2600.0.0108171148.exe
%Windir%\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13\WindowsMicrosoft5.1.3102.2180.exe
%Windir%\WinSxS\x86_Microsoft.Windows.Networking.RtcDll_6595b64144ccf1df_5.2.2.3_x-ww_d6bd8b95\WindowsMicrosoft5.2.4949.21802.0408032158.exe

The following processes are created:

%CommonDesktopDir%\readeradobe.exe
%CommonDesktopDir%\readeradobe30643.exe
%CommonDocuments%\my music\sample music\beethovensscherzo.exe
%CommonDocuments%\my pictures\sample pictures\bluehills17865.exe
%CommonPrograms%\accessories\accessibility\wizardaccessibility.exe

Several modifications to the Windows registry are being made and the following internet downloads were started:

hxxp://logs.newsafetyplace.com/httpss/ldr123.php?v=23&step=1&hostid=ECCB2C6A77FA57971BADB6A24FDB1C34
hxxp://logs.newsafetyplace.com/httpss/ldr123.php?v=23&step=2&hostid=ECCB2C6A77FA57971BADB6A24FDB1C34
hxxp://logs.newsafetyplace.com/httpss/ldr123.php?v=23&step=3&hostid=ECCB2C6A77FA57971BADB6A24FDB1C34

Virus Total permlink and MD5: dab29feb1a1faa0085e8b2adab569dd3.

Follow

Get every new post delivered to your Inbox.

Join 1,551 other followers