FYI...
Fake 'receipt' SPAM - xls malware
- http://myonlinesecurity.co.uk/pws-lt...sheet-malware/
4 Dec 2015 - "An email with the subject of 'receipt of payment' pretending to come from Perpetual Watchservices <perpetualwatchservices@ yahoo .co.uk> with a malicious word doc or Excel XLS spreadsheet attachment is another one from the current bot runs... The email looks like:
Hi ,
thank you for payment , please find attachment with receipt.
Best regards,
Irina
PWS LTD
41-A Great Underbank
Stockport
SK1 1NE
Opening Times: Monday- Friday 8:30-4:30
0161-480-90880161-480-9088
4 December 2015: Receipt-13764(1).doc - Current Virus total detections 4/54*
... hybrid analysis** shows us that it downloads what looks like a Dridex banking Trojan from
gwsadmin.globalwinestocks .com/325r3e32/845t43f.exe (VirusTotal 3/54***)... DO NOT follow the advice they give to enable macros or enable editing to see the content. Most of these malicious word documents appear to be blank or look something like these images when opened in protected view mode, which should be the default in Office 2010, 2013 and 365:
> http://myonlinesecurity.co.uk/wp-con...1-1024x412.png
... The basic rule is NEVER open any attachment to an email, unless you are expecting it..."
* https://www.virustotal.com/en/file/6...is/1449224485/
** https://www.hybrid-analysis.com/samp...nvironmentId=2
*** https://www.virustotal.com/en/file/7...is/1449224741/