CryptoWall Ransomware Attached to Intuit Spam

Status
Not open for further replies.

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
A new spam campaign leveraging Intuit brand name has been spotted to deliver messages with CryptoWall malware attached claiming to be the copy of a remittance file.

The message comes with the subject “Payroll Received by Intuit” and informs that the payment proof has been attached, inciting users to open it.

The item in the attachment is a ZIP archive, which contains an executable with the name “Remittance.exe.” Conrad Longmore from Dynamo’s Blog uploaded the file to VirusTotal service where the detection rate was 9/53.

Further investigation, which led to an analysis from Threat Track, revealed that the malware sample was actually a variant of CryptoWall ransomware, which, once infecting a computer system, proceeds to encrypt specific file types, including DOC, XLS, and TXT, videos and images.

CryptoWall is known to be distributed via spam email, and it is believed that it was released around April this year as part of an exploit kit called RIG. At first, the prevalent attack vector were advertisments served on numerous websites.

The spam message caught by Longmore appears to be very elaborate, providing instructions with a deadline and using a language that would incite potential victims to check the matter in detail.
 

EmiLLiaN

Level 1
Verified
Aug 1, 2014
34
Thank's for the news.

Nice one thinked from the author's of the ransomware :rolleyes:
 

Moose

Level 22
Jun 14, 2011
2,271
Greeting!;)

I appreciate the news update and information. Many thanks!:)

Keep us updated!:confused:
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top