• Search Blog Archives

Follow us: 
Like us on Facebook Follow us on Twitter Visit us on YouTube Get Websense Security Labs alerts delivered to your inbox Follow us on LinkedIn

New Malspam: Please review my CV, Thank you!
Posted: 11 May 2010 08:33 PM

Websense® Security Labs™ ThreatSeeker™ Network has discovered a new job-search related malware spam outbreak today. The spam is designed to be sent to the inboxes of Human Resources people to infect their computers, and asks them to review a CV without claiming what position the application is for. Moreover, some attachments are disguised as picture files which might catch some email recipients off-guard and make them open the attachment. We have seen more than 230,000 samples in 4 hours this morning, and the number is increasing quickly.

 

Snapshot of the spam:

 

 

 

Inside the ZIP file is an executable that contains the Oficla bot. This connects to a URL in the davidopolko.ru for its C&C functions. It also connects to topcarmitsubishi.com.br, get-money-now.net, mamapapalol.com and li1i16b0.com. Just over half of the AV vendors have detection for this attack according to VirusTotal.

 

Once run it changes the wallpaper telling you that your PC is infected.

 

 

After which it downloads and installs a Rogue AV called Security essentials 2010.

 

 

Update: Added more domains the malware connects to.

 

Websense Messaging and Websense Web Security customers are protected against this attack.

Tim Xia


Leave a Comment

(required) 

Email address: (required) 
 
  
 


©2012 Websense, Inc. All Rights Reserved.