Oficla trojan found in emails with subject “Please look my CV. Thank you.”
May 13, 2010 6 Comments
MX Lab started to intercept emails with the subject “Please look my CV. Thank you.” with the trojan Gen:Variant.Bredo.4 (Bitdefender, F-Secure), TrojanDropper:Win32/Oficla.G (Microsoft), Trojan.Sasfis (Symantec) or Mal/FakeAV-BW (Sophos).
This distribution is sent from the spoofed email address.
The body of the email:
Hello!
I have figured out that you have an available job.
I am quiet intrested in it. So I send you my resume,Looking forward to your reply.
Thank you.
The email contains the file ZIP archive My_Resume_221.zip containing the 64 kB large executable My_Resume_221.exe.
The following files are created:
%Temp%\1.tmp
%System%\pgsb.lto
The registry key “HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid” is created.
The registry key “[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]” will be modified.
The trojan can retrieve data from:
* hxxp://davidopolko.ru/
At the time of writing, 16 of the 41 AV engines did detect the trojan. Virus Total permlink and MD5: c571e7e7f09bb845a2f38a4b8ffb02c9
MX Lab customers are protected against this email based threat.

Pingback: Oficla trojan found in emails with subject “Please look my CV. Thank you.” | Computer Security Articles
Just had this sent to me, thought was a bit dodgy so googled it. You come up so thanks for confirming, the temptation to open has been eliminated! ;)
My friend owns a small business, he got this kind of .zip file. We did a search and landed on this page. thanks for info
It’s a bit of a wonder that an unsolicited cv with a poor quality covering email would get opened by businesses rather than sent straight to the trash. But I guess it must often enough to be viable.
thanks for the blog post ill keep my eyes open
keep up the good work mxlab