efax Spam Containing Malware
Beware of efax that may come to your email inbox. This week I receive my first efax spam with a source address of "Fax Message [message@inbound.efax.com]" which contained a link to www.dropbox.com that contained malware. The link has since been removed.
On efax's website, the indicate that you are receiving fax spam to submit the fax via to online form and they "will attempt to prevent further transmission of junk faxes from the source.[2]
[1] http://www.efax.com/help/faq
[2] http://www.efax.com/privacy?tab=reportSpam
-----------
Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu
×
Diary Archives
Comments
Thanks
Anonymous
Jun 8th 2014
1 decade ago
Anonymous
Jun 8th 2014
1 decade ago
http://blog.dynamoo.com/2014/05/fake-natwest-email-downloads-malware.html
ClamAV Sanesecurity signatures are blocking them...
http://sanesecurity.com/
Anonymous
Jun 9th 2014
1 decade ago
https:// www[dot]dropbox[dot]com/meta_dl/eyJzdWJfcGF0aCI6ICIiLCAidGVzdF9saW5rIjogZmFsc2UsICJzZXJ2ZXIiOiAiZGwuZHJvcGJveHVzZXJjb250ZW50LmNvbSIsICJpdGVtX2lkIjogbnVsbCwgImlzX2RpciI6IGZhbHNlLCAidGtleSI6ICJpcWVxeDdocmpobnJpeHoifQ/AANvZsHohmMz8XZLiCizpVrbOVy_Unf1bJ2NSGSwCy9E5w?dl=1
Anonymous
Jun 9th 2014
1 decade ago
Anonymous
Jun 9th 2014
1 decade ago
It ended up being cryptolocker.
We are now implementing the protections in a reactive way.
Anonymous
Jun 9th 2014
1 decade ago
http://phishme.com/inside-look-dropbox-phishing-cryptowall-bitcoins/
Let me know if you need the malware sample.
Regards,
--Ronnie
@iHeartMalware
Anonymous
Jun 9th 2014
1 decade ago
BTW one of my users here at the office got hit by one of these... at least one of the playloads was CryptoLocker.
Anonymous
Jun 9th 2014
1 decade ago
Anonymous
Jun 10th 2014
1 decade ago
----------------
From: Voice Mail [mailto:voicemail_sender@voicemail.com]
Sent: Tuesday, June 10, 2014 8:29 AM
To: [REDACTED]
Subject: [BULK] voice message from 765-398-7466 for mailbox 215
Importance: Low
You have received a voice mail message from 765-398-7466 Message length is 00:00:33. Message size is 290 KB.
Download your voicemail message from dropbox service (Dropbox Inc.):
https://www.dropbox.com/meta_dl/eyJzdWJfcGF0aCI6ICIiLCAidGV.....
----------------
Anonymous
Jun 10th 2014
1 decade ago