New virus in emails do not open: Unpaid invoice excel XLS malware

Tech Blog
February 23, 2015
Man looking at stats

These look to be SPAM e-mails but in fact it is a virus which contains a password stealer, see below.  

Unpaid invoice [ID:AFCBF43812] (random numbers) with a malicious Excel XLS attachment is another one from the current bot runs which try to download various Trojans and password stealers especially banking credential stealers, which may include cridex, dridex, dyreza and various Zbots, cryptolocker, ransomware and loads of other malware on your computer. They are using email addresses and subjects that will entice a user to read the email and open the attachment. A very high proportion are being targeted at small and medium size businesses, with the hope of getting a better response than they do from consumers.

Almost all of these also have a password stealing component, with the aim of stealing your bank, PayPal or other financial details along with your email or FTP ( web space) log in credentials. Many of them are also designed to specifically steal your Facebook and other social network log in details.

All the alleged senders, companies, names of employees and phone numbers mentioned in the emails are all innocent and are just picked at random. Some of these companies will exist and some won't. Don't try to respond by phone or email, all you will do is end up with an innocent person or company who have had their details spoofed and picked at random from a long list that the bad guys have previously found. The bad guys choose companies, Government departments and organisations with subjects that are designed to entice you or alarm you into blindly opening the attachment or clicking the link in the email to see what is happening.

This email has what appears to be a genuine Excel XLS spreadsheet attached which is malformed and contains a macro script virus. Modern versions of Microsoft office, that is Office 2010 and 2013 and Office 365 have Macros disabled by default, UNLESS you or your company have enabled them. If protected view mode is turned off and macros are enabled then opening this malicious word document will infect you, and simply previewing it in windows explorer or your email client might well be enough to infect you. Definitely DO NOT follow the advice they give to enable macros to see the content. Almost all of these malicious word documents appear to be blank when opened in protected view mode, which should be the default in Office 2010, 2013 and 365.

What can be infected by this  

At this time, these only affect windows computers. They do not affect a Mac, IPhone, Blackberry, Windows phone or Android phone. The malicious word or excel file can open on any system, and potentially the macro will run on windows or mac BUT the downloaded malware that the macro tries to download is windows specific, so will not harm or infect any other computer except a windows computer. You will not be infected if you do not have macros enabled in Excel or word.  

What to do if you have been infected  

Infected or even suspect your computer has been compromised contact us today for help and advise.  

Tel: 01482 420150  

Email: help@theonepoint.co.uk

We offer
Go to our Business Mobile service page to discover what we provide.
ExploreiPhone
We offer
Connectivity
Go to our Connectivity service page to discover what we provide.
Explore
Connectivity
We offer
VoIP
Go to our VoIP service page to discover what we provide.
ExploreVoIP Headset
We offer
Digital Services
Go to our Digital Services page to discover what we provide.
Explore
CRM (Customer Relationship Management)
We offer
Go to our Print service page to discover what we provide.
ExplorePrinter
We offer
IT Support
Go to our Print service page to discover what we provide.
ExploreIT Support

Register
your interest

We've Recieved
your interest

Someone will contact you soon.
Form Submission Failed. Try again!