Author Topic: Fake American Express mails  (Read 3097 times)

0 Members and 1 Guest are viewing this topic.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Fake American Express mails
« on: February 18, 2017, 08:58:24 PM »
Just recived 4 fake American Express mails with same attachment (same MD5)

No detection on VT
First submission 2017-02-18 15:48:31 UTC ( 4 hours, 8 minutes ago )
https://virustotal.com/en/file/8f4d9765a806a426a7b6b18e900dfae69ad741a014a6ad90e487423960627a7b/analysis/1487446790/



Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Fake American Express mails
« Reply #1 on: February 19, 2017, 04:23:25 AM »
A fake page trying to trick the user into putting his details in...Interesting

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Fake American Express mails
« Reply #2 on: February 19, 2017, 10:32:30 AM »
A fake page trying to trick the user into putting his details in...Interesting
We call it Phishing   :D


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89676
  • No support PMs thanks
Re: Fake American Express mails
« Reply #3 on: February 19, 2017, 11:23:06 AM »
Just recived 4 fake American Express mails with same attachment (same MD5)

No detection on VT
First submission 2017-02-18 15:48:31 UTC ( 4 hours, 8 minutes ago )
https://virustotal.com/en/file/8f4d9765a806a426a7b6b18e900dfae69ad741a014a6ad90e487423960627a7b/analysis/1487446790/

This social engineering (phishing) scam has been going on for years, just change the name of the carrier to any of the major carriers. If you aren't expecting a parcel, then it is most likely fake.

If you are expecting a parcel, who you ordered goods from should have given you a tracking reference number, visit the carriers site, don't use the link in an unsolicited email.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Fake American Express mails
« Reply #4 on: February 19, 2017, 01:03:32 PM »
@Pondus: Whats the URL of the page thatwants to have your credentials?
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Fake American Express mails
« Reply #6 on: February 19, 2017, 06:17:01 PM »
A fake page trying to trick the user into putting his details in...Interesting
We call it Phishing   :D

This phishing site is a week old.No detection though:
https://virustotal.com/en/file/7015912b8da817db50a2eb45b43e100bf45eef54785843498c429254b2cea9a4/analysis/1486498511/

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34059
  • malware fighter
Re: Fake American Express mails
« Reply #7 on: February 19, 2017, 07:28:59 PM »
Hi True Indian,

The url is now being flagged by ESET. See script and obfuscation patterns here: -https://aw-snap.info/file-viewer/?tgt=https%3A%2F%2Fiao.org.il%2Fwp-content%2Fuploads%2Fcreative.php&ref_sel=GSP2&ua_sel=ff&fs=1
(visit if you know what you are doing) There is a heuristical DNS block active for that domain there: http://urlquery.net/report.php?id=1487535990195

We see php malware here at work, like creative.php, and we could use programs like php-malware finder to detect:
https://github.com/creativeprogramming/php-malware-finder

Inbuilt:
Quote
Detect:
        - phpencode.org
        - http://www.pipsomania.com/best_php_obfuscator.do
        - http://atomiku.com/online-php-code-obfuscator/
        - http://www.webtoolsvn.com/en-decode/
        - http://obfuscator.uk/example/
        - http://w3webtools.com/encode-php-online/
        - http://www.joeswebtools.com/security/php-obfuscator/
        - https://github.com/epinna/weevely3
        - http://cipherdesign.co.uk/service/php-obfuscator
        - http://sysadmin.cyklodev.com/online-php-obfuscator/
        - http://mohssen.org/SpinObf.php
        - https://code.google.com/p/carbylamine/
        - https://github.com/tennc/webshell

It is an old form of misdirected creativity: https://blog.sucuri.net/2013/08/more-creative-backdoors-using-filename-typos.html

polonus
« Last Edit: February 19, 2017, 09:45:42 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline savcin

  • Avast team
  • Full Member
  • *
  • Posts: 113
Re: Fake American Express mails
« Reply #8 on: February 20, 2017, 02:21:28 PM »
MultiString detection has been created.