Tuesday, August 25, 2015

Another day...

...another attack in which the "Premium" Security Guys (McAfee & Symantec) are AWOL:

- Email traversing the internet this morning with a subject of "Invoice 26949 from I SPI Ltd".  The M$ Word attachment is named  Report For Inv_26949_from_I__SPI_Ltd_7888.doc



- Per this Websense File Sandbox Report, the malware modifies 23 Files, 2 Processes and 417 Registry Settings.  However, the "Premium" Security/AV Guys currently find no problem with the file:



- Additionally, per the above Websense File Sandbox report, you'll notice that the malware also phones home to a site in Poland to download an additional exe.  You may therefore ask, "can the "Premium" Security Guys at least protect me from this portion of the blended threat?"   Ummm... no:




No comments:

Post a Comment