{"id":3478,"date":"2010-10-19T11:43:00","date_gmt":"2010-10-19T18:43:00","guid":{"rendered":"http:\/\/blog.webroot.com\/?p=3478"},"modified":"2024-01-24T14:00:07","modified_gmt":"2024-01-24T21:00:07","slug":"just-what-the-heck-am-i-supposed-to-do-with-this","status":"publish","type":"post","link":"https://www.webroot.com/blog/2010\/10\/19\/just-what-the-heck-am-i-supposed-to-do-with-this\/","title":{"rendered":"Hey Malware Guy: Just What the Heck Am I Supposed to Do With This?"},"content":{"rendered":"<p class=\"getsocial\" style=\"text-align: left;\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2005.png\" alt=\"\" \/><a title=\"Add to Facebook\" href=\"http:\/\/www.facebook.com\/sharer.php?u=http:\/\/blog.webroot.com\/2010\/10\/19\/just-what-the-heck-am-i-supposed-to-do-with-this\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2015.png\" alt=\"Add to Facebook\" \/><\/a><a title=\"Add to Digg\" href=\"http:\/\/digg.com\/submit?phase=2&amp;url=http%3A%2F%2Fblog.webroot.com%2F2010%2F10%2F19%2Fjust-what-the-heck-am-i-supposed-to-do-with-this&amp;title=Hey%20Malware%20Guy%3A%20Just%20What%20the%20Heck%20Am%20I%20Supposed%20to%20Do%20W...\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2025.png\" alt=\"Add to Digg\" \/><\/a><a title=\"Add to Del.icio.us\" href=\"http:\/\/del.icio.us\/post?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F10%2F19%2Fjust-what-the-heck-am-i-supposed-to-do-with-this&amp;title=Hey%20Malware%20Guy%3A%20Just%20What%20the%20Heck%20Am%20I%20Supposed%20to%20Do%20With%20This%3F\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2035.png\" alt=\"Add to Del.icio.us\" \/><\/a><a title=\"Add to Stumbleupon\" href=\"http:\/\/www.stumbleupon.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F10%2F19%2Fjust-what-the-heck-am-i-supposed-to-do-with-this&amp;title=Hey%20Malware%20Guy%3A%20Just%20What%20the%20Heck%20Am%20I%20Supposed%20to%20Do%20With%20This%3F\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2045.png\" alt=\"Add to Stumbleupon\" \/><\/a><a title=\"Add to Reddit\" href=\"http:\/\/reddit.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F10%2F19%2Fjust-what-the-heck-am-i-supposed-to-do-with-this&amp;title=Hey%20Malware%20Guy%3A%20Just%20What%20the%20Heck%20Am%20I%20Supposed%20to%20Do%20With%20This%3F\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2055.png\" alt=\"Add to Reddit\" \/><\/a><a title=\"Add to Blinklist\" href=\"http:\/\/www.blinklist.com\/index.php?Action=Blink\/addblink.php&amp;Description=&amp;Url=http%3A%2F%2Fblog.webroot.com%2F2010%2F10%2F19%2Fjust-what-the-heck-am-i-supposed-to-do-with-this&amp;Title=Hey%20Malware%20Guy%3A%20Just%20What%20the%20Heck%20Am%20I%20Supposed%20to%20Do%20With%20This%3F\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2065.png\" alt=\"Add to Blinklist\" \/><\/a><a title=\"Add to Twitter\" href=\"http:\/\/twitter.com\/home\/?status=Hey%20Malware%20Guy%3A%20Just%20What%20the%20Heck%20Am%20I%20Supposed%20t...+%40+http%3A%2F%2Fblog.webroot.com%2F2010%2F10%2F19%2Fjust-what-the-heck-am-i-supposed-to-do-with-this\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2075.png\" alt=\"Add to Twitter\" \/><\/a><a title=\"Add to Technorati\" href=\"http:\/\/www.technorati.com\/faves?add=http:\/\/blog.webroot.com\/2010\/10\/19\/just-what-the-heck-am-i-supposed-to-do-with-this\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2085.png\" alt=\"Add to Technorati\" \/><\/a><a title=\"Add to Yahoo Buzz\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=http%3A%2F%2Fblog.webroot.com%2F2010%2F10%2F19%2Fjust-what-the-heck-am-i-supposed-to-do-with-this&amp;headline=Hey%20Malware%20Guy%3A%20Just%20What%20the%20Heck%20Am%20I%20Supposed%20to%20Do%20With%20This%3F\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2095.png\" alt=\"Add to Yahoo Buzz\" \/><\/a><a title=\"Add to Newsvine\" href=\"http:\/\/www.newsvine.com\/_wine\/save?u=http%3A%2F%2Fblog.webroot.com%2F2010%2F10%2F19%2Fjust-what-the-heck-am-i-supposed-to-do-with-this&amp;h=Hey%20Malware%20Guy%3A%20Just%20What%20the%20Heck%20Am%20I%20Supposed%20to%20Do%20With%20This%3F\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2105.png\" alt=\"Add to Newsvine\" \/><\/a><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2115.png\" alt=\"\" \/><\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/10\/20101019_tacticlol_banking_message.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignleft size-full wp-image-3479\" title=\"20101019_tacticlol_banking_message_crop\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/10\/20101019_tacticlol_banking_message_crop.png\" alt=\"\" width=\"326\" height=\"166\" \/><\/a>The <strong>Tacticlol<\/strong> downloader, responsible for a lot of infections <a href=\"http:\/\/blog.webroot.com\/2009\/09\/15\/shipping-confirmation-malware-on-the-rise\/\" target=\"_blank\" rel=\"noopener\">over the past year<\/a>, propagates in two ways: via drive-by downloads, and as a .zip archive attached to messages. Maybe the spam filtering companies finally caught on to the trick, or maybe the Tacticlol distributors are just trying to mix it up, but the latest sample to come over the transom has me scratching my head.<\/p>\n<p>Like most others, this sample came attached to an email made to look like a message that UPS would never send. Once again, the message tries to convince the recipient that the attached file is a shipping label the recipient needs to open and print before he or she can &#8220;receive the parcel.&#8221; And, as always, the attachment contains an executable installer for the Trojan.<\/p>\n<blockquote>\n<pre>Dear customer\n\nYour parcel has arrived at the post office on October 9. Our\nDriver was unable to deliver the parcel to your address.\nTo receive a parcel you must go to the nearest UPS office and\nshow your mailing label.\nMailing label is attached to this letter.\n\nYou need to print mailing label, and show it in UPS office to\nreceive the parcel.\n\nThank you for your attention.\nUPS International Services.<\/pre>\n<\/blockquote>\n<p>But this time, instead of sending a .zip archive <em>with a .zip extension<\/em>, they sent a message with a .zip archive that has <em>a .jpg extension<\/em>. And, yeah, that just doesn&#8217;t work.<\/p>\n<p>The file isn&#8217;t a JPEG image file. If you try to open it in a browser or an image editor, the editor simply errors out and tells you it isn&#8217;t an image file, and the story ends right there. I&#8217;m sure some Russian malware distributor has been <a href=\"http:\/\/media.photobucket.com\/image\/double-facepalm\/KevlarPaperclip\/double-facepalm.jpg\" target=\"_blank\" rel=\"noopener\">double-facepalming<\/a> over the waste of a perfectly good scam. Social engineering: You&#8217;re doing it wrong.<\/p>\n<p><!--more--><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/10\/20101019_tacticlol_banking_ue.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-medium wp-image-3482\" title=\"20101019_tacticlol_banking_ue\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/10\/20101019_tacticlol_banking_ue.png?w=300\" alt=\"\" width=\"300\" height=\"84\" \/><\/a><\/p>\n<p>However, if you&#8217;re a curious malware researcher, you just open the file in an editor and see the PK in the file header, and realize you&#8217;re dealing with an archive. (&#8220;PK&#8221; &#8212; as in <a href=\"http:\/\/www.pkware.com\/\" target=\"_blank\" rel=\"noopener\">PK-Zip<\/a> &#8212; is always the first two characters in a .zip archive.)<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/10\/20101019_tacticlol_banking_gt2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3483\" title=\"20101019_tacticlol_banking_gt2\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/10\/20101019_tacticlol_banking_gt2.png\" alt=\"\" width=\"637\" height=\"75\" \/><\/a><\/p>\n<p>Confirming this using a tool like GT2, I could see the file name of the real payload inside the archive looks achingly familiar: <strong>Label_UPS_Nr343.exe<\/strong><\/p>\n<p><a href=\"http:\/\/blog.webroot.com\/2010\/04\/08\/this-pc-will-self-destruct-in-ten-seconds\/\" target=\"_blank\" rel=\"noopener\">They&#8217;re still using &#8220;<strong>Nr<\/strong>,&#8221;<\/a> the abbreviation (\u043d\u0440) for the word &#8220;number&#8221; (\u043d\u043e\u043c\u0435\u0440, phonetically <em>nomer<\/em>) in Russian. Come on, guys, could you at least pretend you&#8217;re trying? Make that a triple facepalm for this social engineering dropout&#8217;s demonstration of willful ignorance. <strong>Demonstration no. 1,<\/strong> even.<\/p>\n<p>I&#8217;m not sure exactly how a non-researcher would end up infected. Most smart people would realize that, even if UPS was sending them a letter, the freight shipper would never refer to their own depot as &#8220;the post office&#8221; as this message does. And even if the user didn&#8217;t simply delete the message, and tried in vain to open an archive dressed up as an image file, the computer would only warn you about the file being the wrong type, and quit trying to open it.<\/p>\n<p>Fortunately, I&#8217;m not so easily dissuaded, and I like to break stuff. In my next post, I&#8217;ll describe some of the awesomely annoying malwarey goodness that came from this one downloader.<br \/>\n<a title=\"wordpress blog stats\" href=\"http:\/\/www.statcounter.com\/wordpress.com\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"http:\/\/c.statcounter.com\/4868061\/0\/92d716bc\/1\/\" alt=\"wordpress blog stats\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Tacticlol downloader, responsible for a lot of infections over the past year, propagates in two ways: via drive-by downloads, and as a .zip archive attached to messages. Maybe the spam filtering companies finally caught on to the trick, or maybe the Tacticlol distributors are just trying to mix it up, but the latest sample [&hellip;]<\/p>\n","protected":false},"author":65,"featured_media":17052,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[8063,8053,8061,6597,4421,3855,3619,7107,8057,3477,4431,6593,7391,4157,3875,22441,3491,8571,8209],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/3478"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=3478"}],"version-history":[{"count":2,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/3478\/revisions"}],"predecessor-version":[{"id":32605,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/3478\/revisions\/32605"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17052"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=3478"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=3478"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=3478"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=3478"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}