Google Search

Showing posts with label PowerPoint. Show all posts
Showing posts with label PowerPoint. Show all posts

Saturday, March 23, 2013

Arsenal Lotto scam spammed out via PowerPoint file

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

ArsenalThe scammers must be getting more and more desperate to get their claws on our money.

Their criminal business model is messed up somewhat by anti-spam filters blocking their fraudulent messages from reaching potential victims.

What's a bad guy to do?

Well, they could do what this scammer has done - wrap their scam email up into a format that anti-spam software might not look at so closely.

Subject: Please quote your !
From: Arsenal
Attached file: Arsenal.ppt

Message body:
Please find attachement

The scammer doesn't give away much information in the email itself, but only the attachment (a PowerPoint file) and you'll read that Arsenal Football Club have awarded you a £2,350,000 prize in their lottery.

Arsenal lotto scam - click for larger version

All you have to do is contact their representative in China, a Dr Cheng Dingxiang, with your personal information (presumably he will request your bank information soon and an administration fee) and before you know it riches will be yours!

Clearly the scammers are getting desperate.

Hopefully no-one IT-savvy would fall for such a scam - and be instantly suspicious that the communication arrived not only via email, but within a PowerPoint file as well.

But always remember that there may be vulnerable people out there who *do* fall for scams like this, and are at risk of ending up out of pocket as a result. Always be on the lookout to help vulnerable friends and family avoid scams like this - however ridiculous they may appear to you.

You might want recommend to your friends and family that they grab a copy of the Sophos Threatsaurus, where we explain the facts about threats to your computers and to your data in simple, easy-to-follow language.

Here'a one-minute video that tells you more:

Follow @gcluley


View the original article here

Sunday, February 3, 2013

PowerPoint about the Mayan "end of the world" secretly boobytrapped with malware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Will the world end in 2012Earlier this week my colleagues Peter Szabo and Richard Wang respectively discovered and wrote about malware disguised as a Microsoft Excel spreadsheet used to generate Sudoku puzzles to help pass the time.

This morning I was contacted by another SophosLabs researcher, Scott Sitar, about a booby-trapped PowerPoint presentation titled "Will the world end in 2012?"

Like the Excel spreadsheet, this file contained Visual Basic macro code that drops an executable file called VBA[X].exe, where [X] is a random capital letter. In fact, the macro was functionally identical to that found in the Sudoku puzzle.

Also like the Sudoku generator, this sample required the user to enable macros, but didn't include the helpful tip on how to do it or really any good reason you might need a macro to learn about the end times.

What are these macros up to? They are designed to construct a valid Windows PE file (Portable Executable) from arrays of single bytes.

While this isn't particularly new, it would throw off the average user from understanding what these macros are designed to do even if they bothered to take a look.

Screenshot of malicious VB macros

Owl image retrieved by malwareThe EXE file that is extracted is what we call a dropper. It extracts another Windows PE file which downloads a picture of an owl, then contacts a command and control server.

It is designed to download another payload it will rename as Wmupdate.exe, but during our testing no instructions were sent from the command-and-control server to retrieve this payload.

Scott mentioned his suspicions that these were being automatically generated and not necessarily handcrafted by their creators. I think he's right.

I took a look around and discovered the original, uninfected files that these dangerous macros had been added to.

The presentation about the world ending was created by a preacher in the United States who appears to have nothing to do with this booby-trapped version. Don't go looking for this presentation though!

His legitimate WordPress blog has been compromised and is currently performing search engine manipulation duties for Viagra pushers, "off-shore" casinos, forex fraud and payday loans.

SEO keywords on compromised blog

If you do want to see what this presentation has to say, I was able to find it online in a safe to view format.

While macro viruses certainly aren't a new phenomenon, they aren't something many people think about.

Be careful with documents you acquire from random sources and never enable macros in documents you download or receive as email attachments.

You never know what might be lurking in there, but I suspect it won't be the end of the world.

A special thanks to Scott Sitar in SophosLabs Vancouver for spotting this and doing all of the analysis necessary to share this story.

Sophos Anti-Virus on all platforms blocks this malware as follows:

WM97/ExeDrop-G: The malicious Office macro
Troj/DwnLdr-KLB: The Windows malware dropped by the above

Follow @chetwisniewski


View the original article here