Saturday, November 17, 2007

Private Detective Spam

A disturbing new spam email was received thirty-four times this morning in my spam traps. The email has one of those social engineering bodies that I would imagine to be pure gold as far as its success rate convincing people to click on the attachment.

Here's the message:


I work in a private detective agency. My name is not important.
I want to warn you that i'm going to monitor your phone line.
Do you want to know who paid for shadowing you? Wait for my next letter.


P.S. I know, you don't believe me. But i think the record of your
yesterday's telephone conversation will change your point. The tape is
in archive. Archive password is 123qwe


The attachment is a ".rar" file, which is a compressed file format similar to a ".zip" file. The fact that many American computer users don't have software on their machines that knows how to open a RAR file may be the only thing that keeps some users safe!

When the file is extracted, it sits in the filelist with an icon which would make it seem to be an .MP3 File.



Although if you view it in a different manner, the fact that the file is a "Screen Saver" file.



The file name is actually:

"call1105.mp3 (many spaces here) .scr"

Of the thirty-four samples that I received at the beginning of the day:

Nine of them use the subject "attention".

Four use the subject "I'm watching you".

Six use the subject "We monitor your privacy".

Five use the subject "you are watched"

Four use the subject "Your phone is monitored"

Two use the subject "you're being monitored"

Two use "you are being monitored".

Two use "The tape of your conversation".

All have the password of "123qwe".

As of thirty minutes ago, there were twenty-one anti-virus companies that did NOT detect this as a virus in any way. Eleven companies, according to VirusTotal.com, mostly detected it as a generic "Dropper", though Symantec called it "Trojan.Peacomm.D", which is what it calls Storm Worm viruses.

F-Prot, F-Secure, Kaspersky, McAfee, Microsoft, Sophos, and others do not detect the virus at this time.

3 comments:

  1. The state agency I work for is seeing these also. We started receiving them this morning (9:19AM EST on 11/17), but they suddenly stopped coming in around 11:53AM. In that span we received approximately 100 infected attachments.

    This isn't the first malicious .scr attachment I've seen not get picked up by AV. On 11/15 we rec'd an attachment named "complaint.zip". Inside that was "complain.scr", about 223K in size. The email delivering it was supposedly from the Better Business Bureau, had a partial match on our agency name in the text, so it appeared targeted at us. Fortunately the name it was addressed to was obviously phony, so the recipient knew enough to alert us to it. This complain.scr scanned cleanly, too.

    ReplyDelete
  2. I have received one of thes e-mails and am glad to know it is spam, as i found it quite threatening.

    It is good that information is passed on about this kind of junk. I was able to look on google and find it to be a "trojan" . None of my anti-virus or spyware checks picked up on it.

    ReplyDelete
  3. Thanks for the post. Got one today and was curious but not enough to open it so I googled and found your entry.

    ReplyDelete

Trying a new setting. After turning on comments, I got about 20-30 comments per day that were all link spam. Sorry to require login, but the spam was too much.