Email with subject “Re: Job Interview” leads to site that hosts the Koobface trojan in resume.exe file


MX Lab started to intercept messages with the subject “Re: Job Interview” from various different spoofed email addresses.

The body of the email:

Dear Employee,

Could I get an update on your resume? Your cooperation will be appreciated in this matter.

The resume we have on file for you is http://www.careerbuilder.com/ShareInfo/Resume.aspx?DID=J93JSN0382.

Best regards,

Cristian Anderson

The email does not have any attachment but only a visible link to the web site Career Builder where you can submit your resume: http://www.careerbuilder.com/ShareInfo/Resume.aspx?DID=J93JSN0382. When using this link, you’ll get an 404 - Page not found error.

But the danger lies with the real link inside the HTML code - hxxp://www.hotelvillaserena.it/resume.exe - that leads to a web site that hosts the malware.

The resume.exe file is 36 kB large and the trojan is known as Mal/Koobface-E (Sophos), VirTool:Win32/VBInject.gen!DG (Microsoft), Win32/Koobface.NX (E-Trust) or Trojan.Win32.VBKrypt (Ikarus).

At the time of writing, only 10 of the 40 AV engines at Virus Total did detect the threath. Virus Total permlink and MD5: 612fc8fc11fa90ef93ba3b681512a00f.

Oficla/Sasfis trojan now detected in emails regarding contract


MX Lab intercepted a new trojan variant from Oficla/Sasfis in email regarding labour contracts. The from email address is randomly choosen and contains spoofed email addresses.

Possible subjects are:

Contract of settlements
Contract of retirement
Loan contract
Permit for retirement
Rent contract
Your new labour contract

The body of the email:

Good day,
We have prepared a contract and added the paragraphs that you wanted to see in it.
Our lawyers made alterations on the last page. If you agree with all the provisions we are ready to make the payment on Friday for the first consignment.
We are enclosing the file with the prepared contract.
If necessary, we can send it by fax.
Looking forward to your decision.
“Benito Swan

The email contains the attachment Contract_29_04_2010.zip and once extracted the 36 kB large file Contract_29_04_2010____doc__[many_undercores]___.exe emerges.

The trojan is known as Win32/Oficla.GN (NOD32), Trojan.Win32.Oficla (Ikarus), Trojan.Oficla.38 (Dr Web) but also as VirTool:Win32/VBInject.FO (Microsoft) or Trojan.Sasfis (Symantec).

The following files will be created:

%Temp%\1.tmp
%System%\thxr.wgo
%Temp%\2.tmp

The registry key “HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid” is created.
The registry key “[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]” will be modified.

The trojan can establish a remote connection with the IP 174.120.228.122 and 193.105.174.108 on port 80 and retrieve data from:

* hxxp://www.brightspottech.com/loader_40.exe
* hxxp://hulejsoops.ru/images/bb.php?v=200&id=544932909&b=build001&tm=2

At the time of writing, 16 of the 41 AV engines at Virus Total did detect the threat. Virus Total permlink and MD5: 73f9b5732155d68b908f4acdaadff2ec

Follow

Get every new post delivered to your Inbox.

Join 1,551 other followers