Another day, another scr malware spam (May 8, 2014)

Do you have a question? Post it now! No Registration Necessary.  Now with pictures!


https://www.virustotal.com/en/file/a85f5c92979d6a85c62ae2bfbe69fece39d51964aff8a6c3ae7210bfc0575334/analysis/1399558899/

First submission was an hour ago.

The absolutely spectacular detection rate by the AV industry is:  5/52

AntiVir   TR/Crypt.XPACK.Gen2
Bkav      HW32.Pedka.asoa
CMC       Trojan.Win32.Krap.1!O
Sophos    Mal/Generic-S
VBA32     BScope.Trojan-Dropper.Injector

PS:  I'm not seeing Avira showing up at VT.  Curious.

The file can be downloaded from here:

http://filepost.com/files/dc27am49/FAX-738574.zip/

Anubis report:

http://anubis.iseclab.org/?action=result&task_id=1ea5a1b3b300d7b74812275684686f564

DNS Queries:
pharmaholic.com       DNS_TYPE_A       162.213.253.14

HTTP Conversations:       
From ANUBIS:1028 to 162.213.253.14:80 - [pharmaholic.com]
Request: GET /images/banners/0805USmp.rar
Response: 200 "OK"

0805USmp.rar can be downloaded from here:

http://filepost.com/files/9a1f4m4a/0805USmp.rar/

That file was first (and perhaps only once) analyzed by VT 1 hour 20
minutes ago.  0/52 detection rate:

https://www.virustotal.com/en/file/9e3988b7082a0e9d100ec33dbea04df38a343af06ee82e9e52c83eb970921bc9/analysis/


Spam:

=================
Received:     from 76-10-225-162.ntegrated.net ([76.10.225.162])
Date:         Thu, 8 May 2014 09:03:08 -0600
User-Agent:   Mozilla/5.0 (Windows NT 6.1; rv:24.0) Gecko/20100101
              Thunderbird/24.2.0
Subject:      INCOMING FAX REPORT : Remote ID: 363-634-mung

*********************************************************
INCOMING FAX REPORT
*********************************************************

Date/Time: Thu, 8 May 2014 09:99:45 GMT
Speed: 4161bps
Connection time: 03:09
Pages: 5
Resolution: Normal
Remote ID: 849-645-mung
Line number: 6
DTMF/DID:
Description: Internal report

*********************************************************

Site Timeline