Attackers send out Trojan on behalf of Amazon

Status
Not open for further replies.

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
The mass mailing is one of the favorite ways criminals distribute malware. On June 26-27, 2014, Doctor Web's security researchers registered a large bulk of emails containing a dangerous Trojan. These emails were ostensibly sent by Amazon.

Since June 26, many users have been receiving fake, new order notifications, supposedly from this very well-known Internet company. The messages invite users to open an invoice attachment to access the details of their order. The message is written in English, and the text is the same in all currently known incidents. Only the order date and number vary:

Hi,
Thank you for your order. We’ll let you know once your item(s) have dispatched. You can view the status of your order or make changes to it by visiting Your Orders on Amazon.com.



The ZIP archive attached to the email contains the executable of BackDoor.Tishop.122 malware. Virus makers call this program Smoke Loader. This Trojan is designed to download other malicious applications onto an infected computer, and thus, systems lacking antivirus protection can be turned into bona fide malware menageries. After its launch BackDoor.Tishop.122 scans the environment for the presence of a "sandbox" or virtual machine, copies itself into a folder on the hard disk, adds its entry into the autorun section of the Windows Registry, and injects its code into a number of system processes. If the machine is connected to the Internet, the Trojan will attempt to download other malicious programs and run them on the infected computer.

Doctor Web urges users to exercise caution. Do not open email attachments from unknown senders, and do not try to view attached documents containing order information, unless you have actually ordered something in an online store. Such messages should be deleted immediately upon receipt.

Trojan/Rootkit Smoke Loader / Malware Hub
http://malwaretips.com/threads/smoke-loader.29840/
:D
 

marg

Level 12
Verified
May 26, 2014
583
Let me get this straight since I do order things from Amazon. The Email is spoofing Amazon or Amazon is actually sending this out?:confused:
 

WinXPert

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Jan 9, 2013
1,457
common sense, if you didnt order anything on that date, suspect something fishy
 
  • Like
Reactions: Oxygen and marg

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Outlook.com is very effective at blocking known malware attachments, as I was unable to download the compressed malware package.

upload_2014-7-16_22-20-11.png
 

Dubseven

Level 14
Verified
Aug 12, 2013
694
Lot of malwares attacks by PDF to companies, now doing the same to users.
Keep in mind to not open all PDF documents you see..
As i know this order thing contents a PDF document about the order.

Nevermind, nice methods by them.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top