sábado, 11 de abril de 2015

Simple FedEx Email Slips Malware on the Computer

A Great Part of the Success Phishing is Enjoying is Due to Users’ Curiosity upon Receiving a Message and Documents that, they Aren't Expecting. A FedEx Campaign Spotted Recently Counts on this and Keeps the Body of the Message as Simple as Possible. The Cyber Crooks Drop a Single Line in the Email and include an Attachment that Purports to be an Invoice or a Document that Could Offer More Details about the Nature of the Notification. Launching the Attached File is actually the End Goal of the Scammers, since it Adds a Malware Dropper on the System. After Contacting a Remote Server, the Dropper Requests to Download a Threat Hosted at that Location, which Can Pilfer Sensitive Data from the System or Add it to a Network of Compromised Computers Called Bots, Expanding the Limits of the Botnet. The Message in the Malicious Email Simply Says, “Please take care of the environment, print only if necessary”. With No Details about the Nature of the Message, the Curiosity of the Recipient is Exploited and Many Cannot Abstain from Opening the File, which is Present in Archived Form (ZIP).


In Some Cases, Curiosity is Not the Only Reason for Deploying the Malicious Item on the Computer, as it May Happen that, the Recipient is actually Expecting a FedEx Notification. FedEx, or Any Other Professional Company, Won't Engage in Sending Out Alerts that are Vague. The Name of the Recipient, as well as, the Matter the Email is in Relation to, are Known to the Company and are Most of the Times Good Indicators that, the Message is Legitimate. Apart from these Hints, if the Message Claims to Deliver only One Text Document and it Doesn't Appear to be a Large One, Attached Archives should be Regarded with Suspicion. Unimpeded Visibility of the Data is Generally a Good Sign but, this is Not Always the Case. Cybercriminals Can Embed Malicious Scripts in Word Documents and Send them Out without Having to Compress them.




Info Source:

http://www.hoax-slayer.com/fedex-document-malware-email.shtml



0 comentários:

Enviar um comentário