{"id":14945,"date":"2013-10-28T00:00:37","date_gmt":"2013-10-28T06:00:37","guid":{"rendered":"https://www.webroot.com/blog/?p=14945"},"modified":"2018-10-05T13:01:04","modified_gmt":"2018-10-05T19:01:04","slug":"fake-whatsapp-voice-message-notification1-new-voicemail-themed-emails-lead-malware-2","status":"publish","type":"post","link":"https://www.webroot.com/blog/2013\/10\/28\/fake-whatsapp-voice-message-notification1-new-voicemail-themed-emails-lead-malware-2\/","title":{"rendered":"Fake WhatsApp &#8216;Voice Message Notification\/1 New Voicemail&#8217; themed emails lead to malware"},"content":{"rendered":"<p>WhatsApp users, watch out! The cybercriminal(s) behind the most recently profiled campaigns impersonating <a href=\"https://www.webroot.com/blog/2013\/10\/02\/t-mobile-mms-message-arrived-themed-emails-lead-malware\/\"><strong>T-Mobile<\/strong><\/a>, and <a href=\"https://www.webroot.com/blog/2013\/10\/21\/u-k-users-targeted-fake-confirming-sky-offer-themed-malware-serving-emails\/\"><strong>Sky<\/strong><\/a>, have just launched yet another malicious spam campaign, this time targeting WhatsApp users with fake &#8220;Voice Message Notification\/1 New Voicemail&#8221; themed emails. Once unsuspecting users execute the fake voice mail attachment, their PCs will attempt to drop additional malware on the hosts. The good news? We&#8217;ve got you (proactively) covered.<\/p>\n<p><!--more--><\/p>\n<p><strong>Sample screenshot of the spamvertised email:<\/strong><\/p>\n<p><a href=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/WhatsApp_Email_Spam_Malware_Malicious_Software_Social_Engineering_Cybercrime.png\"><img decoding=\"async\" loading=\"lazy\" width=\"501\" height=\"481\" class=\"size-full wp-image-14947 aligncenter\" src=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/WhatsApp_Email_Spam_Malware_Malicious_Software_Social_Engineering_Cybercrime.png\" alt=\"WhatsApp_Email_Spam_Malware_Malicious_Software_Social_Engineering_Cybercrime\" srcset=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/WhatsApp_Email_Spam_Malware_Malicious_Software_Social_Engineering_Cybercrime.png 501w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/WhatsApp_Email_Spam_Malware_Malicious_Software_Social_Engineering_Cybercrime-300x288.png 300w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2013\/10\/WhatsApp_Email_Spam_Malware_Malicious_Software_Social_Engineering_Cybercrime-32x32.png 32w\" sizes=\"(max-width: 501px) 100vw, 501px\" \/><\/a><\/p>\n<p><strong>Detection rate for the malicious attachment:<\/strong> <a href=\"https:\/\/www.virustotal.com\/en\/file\/ad4b4fc2cf32922405fe7cd8eb252aa22607004b5c70ac5c8109ef314ad36964\/analysis\/\"><strong>MD5:\u00a00458a01e42544eacf00e6f2b39b788e0<\/strong><\/a> &#8211; detected by 31 out of 48 antivirus scanners as\u00a0Trojan.Win32.Sharik.qhd<\/p>\n<p><strong>Once executed, the sample creates the following Registry Keys on the affected hosts:<\/strong><br \/>\nHKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.sewwe<br \/>\nHKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.sewwe\\ShellNew<br \/>\nHKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\S6.Document<br \/>\nHKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\S6.Document\\DefaultIcon<br \/>\nHKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\S6.Document\\shell<br \/>\nHKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\S6.Document\\shell\\open<br \/>\nHKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\S6.Document\\shell\\open\\command<br \/>\nHKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\S6.Document\\shell\\print<br \/>\nHKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\S6.Document\\shell\\print\\command<br \/>\nHKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\S6.Document\\shell\\printto<br \/>\nHKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\S6.Document\\shell\\printto\\command<br \/>\nHKEY_CURRENT_USER\\Software\\Local AppWizard-Generated Applications<br \/>\nHKEY_CURRENT_USER\\Software\\Local AppWizard-Generated Applications\\S6<br \/>\nHKEY_CURRENT_USER\\Software\\Local AppWizard-Generated Applications\\S6\\Settings<\/p>\n<p>It then attempts to download additional malware from the well known C&amp;C server at <strong>networksecurityx.hopto.org<\/strong><\/p>\n<p><strong><a href=\"https:\/\/www.webroot.com\/us\/en\/home\/products\/complete\">Webroot\u00a0SecureAnywhere<\/a><\/strong>\u00a0users are proactively protected from this threat.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>WhatsApp users, watch out! The cybercriminal(s) behind the most recently profiled campaigns impersonating T-Mobile, and Sky, have just launched yet another malicious spam campaign, this time targeting WhatsApp users with fake &#8220;Voice Message Notification\/1 New Voicemail&#8221; themed emails. Once unsuspecting users execute the fake voice mail attachment, their PCs will attempt to drop additional malware [&hellip;]<\/p>\n","protected":false},"author":65,"featured_media":17052,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[5595,5583,5587,5593,4849,5581,5585,5577,3877,4065,3477,5597,3875,3529,5591,5589,5579],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/14945"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=14945"}],"version-history":[{"count":8,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/14945\/revisions"}],"predecessor-version":[{"id":25747,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/14945\/revisions\/25747"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17052"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=14945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=14945"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=14945"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=14945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}