2015-02-09 - CHANITOR/VAWTRAK MALSPAM - SUBJECT: USPS DELIVERY NOTIFICATION

ASSOCIATED FILES:

 

NOTES:

 

EXAMPLE OF THE EMAILS

SCREENSHOT:

 

MESSAGE TEXT:

From: USPS <no-reply@usps.gov>
Date: Monday, February 9, 2015 at 8:06 AM CST
To:
Subject: USPS Delivery Notification

The package could not be delivered by our company's courrier.

REASON: Wrong postal code
PARCEL # : USPS11009489
SHIPMENT TYPE : OVERNIGHT

To reschedule a delivery, visit your post office with a printed copy of the shipping label.
The label has been attached to this notification, in .doc format.

For additional information about our services, you can visit our official website https://www.usps.com/

Thank you for using our services.
USPS Global.

Attachment: label_11009489.doc (83.1 KB)

 

INFECTION TRAFFIC

FROM RUNNING THE MALICIOUS WORD DOCUMENT ON A VM:

 

SNORT EVENTS FROM THE INFECTED VM

Emerging Threats and ETPRO rulesets from Sguil on Security Onion (without ET POLICY or ET INFO events):

Talos (Sourcefire VRT) ruleset from Snort 2.9.7.0 on Debian 7:

 

PRELIMINARY MALWARE ANALYSIS

EMAIL ATTACHMENT:

File name:  label_11009489.doc
File size:  61.5 KB ( 62976 bytes )
MD5 hash:  97f6d88dcfe5fdcbf6cde2a588ad48bc
Detection ratio:  5 / 57
First submission:  2015-02-09 14:22:02
VirusTotal link:  https://www.virustotal.com/en/file/0616f04ec50d2745f50b40b3ff6c7bf99924f8dea084569afa6fb3b971114b41/analysis/
Malwr.com link:  https://malwr.com/analysis/MzhhNTg5MGIwOTIwNDY0OTg2MDk3NTgwNjBhNTMxODU/

 

MALWARE FROM THE INFECTED VM - CHANITOR:

File name:  C:\Users\User-1\AppData\Local\Temp\444.exe
File name:  C:\Users\User-1\AppData\Roaming\Windows\winlogin.exe
File size:  149.5 KB ( 153088 bytes )
MD5 hash:  559213eb0689549b424bc3aeafce0086
Detection ratio:  5 / 57
First submission:  2015-02-09 15:02:10 UTC
VirusTotal link:  https://www.virustotal.com/en/file/c20ffd843f1568e635478286721636af0aae0928d4f0b2b910037efe79d620f4/analysis/
Malwr.com link:  https://malwr.com/analysis/MTExZWEyOTRkN2I3NDcxN2FlZTRmZDlkNTUxOThlOTU/

 

MALWARE FROM THE INFECTED VM - VAWTRAK:

File name:  C:\ProgramData\ZedfOZbeb\TugeBucb.fec
File size:  272.0 KB ( 278528 bytes )
MD5 hash:  337a01565dc614651d05a37c7cc8f477
Detection ratio:  7 / 57
First submission:  2015-02-09 16:19:19 UTC
VirusTotal link:  https://www.virustotal.com/en/file/71dcc32891588d60acbe7cbe04c038170e9f44120b03dba27a8ab6744674b875/analysis/
Malwr.com link:  https://malwr.com/analysis/YjVhZWJlZWJiZWI0NDJkN2FjYjE1NWZlMWYyZWQzOGE/

 

FINAL NOTES

Once again, here are the associated files:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.