Last Updated: 2012-09-09 02:16:17 UTC
by Guy Bruneau (Version: 1)
We received another piece of spam (thanks Curtis) pretending to be from the Better Business Bureau. Analysis of the file transferred (W6w8sCyj.exe) from prog.it appears to be a piece of malware (Win32/Cridex.Q) use to communicates via SSL with a C&C server.
List of domains/IP to watch for and block:
The email looks like this:
Better Business Bureau©
Start With Trust©
Sat, 08 Sep 2012 01:54:02 +0700
RE: Case # 78321602 <http[:]//prog.it/EH564Bf/index.html>
The Better Business Bureau has got the above mentioned complaint from one of your customers concerning their business relations with you. The details of the consumer's concern are contained in attached document. Please give attention to this case and advise us of your opinion as soon as possible. We encourage you to open the COMPLAINT REPORT to answer on this complaint.
We look forward to your prompt response.
Better Business Bureau
Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu