Security News PSA: Don't Open SPAM Containing Password Protected Word Docs

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
I wanted to alert everyone of a new malware distributing SPAM campaign that I just received that contains a password protected Word document, which pretends to be about a payment I would be receiving shortly. As I always love free money, I had to take a look and see what I was getting for free.

The SPAM emails are being sent with a subject like "Important Information from Troy Watt", with the names most likely being different between recipients. These emails then contain a password protected Word docx attachment with names like l_%74kk03ca52q_Troy Watt.docx.

You may wondering what use is a password protected word document if the recipient doesn't know the password. Well, you have nothing to fear as our buddy Troy decided to include that in his email to me:

-----------------------------------------------------------------------------------------------------------------------------
Good morning
This contact details ([recipient_email]) was specified as the recipient of the payment. The Transaction should appear in 1 days.
The Passwd is 0qArccIMK. You need to paste it to be able to open the document.
------------------------------------------------------------------------------------------------------------------------------


Troy Watt

As you can see, these DLL files are installed into and loaded from the %AppData% folder and will have the ogg extension and a random numeric name. For example, 35116.ogg as seen in the alert above.

Unfortunately, I could not figure out what this thing does, but I have to assume Troy tricked me and its not transferring money into my account. Furthermore, the DLL is only 4KB in size, which is quite small, and has very few viewable strings without being unpacked.


According to security researcher -0day, this campaign is installing the Ursniff keylogger and data stealing Trojan. It also turns out I wrote about this back in April and forgot. Oops.
The takeaway from this article is to be careful and not open any password protected document unless you are expecting them and know who they are coming from.

Updated 7/12/17 4:05 PM EST: 0day tweeted today that this was the Ursniff keylogger being installed.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top