This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Blocking inbound malware - BPay file 9Y473M844O9X

Hi all,

Since Thursday/Friday last week we have been receiving thousands of emails directed to our internal users, groups and mailing lists. The recipients are not randomly generated, so either someone found or has purchased a list of our addresses or some disgruntled script kidie is playing games. The attacks certainly appear to be targeted from a botnet last week, as the emails were originating from not any single subnet.

Anyway, I have submitted these files to Sophos, Avira and ESET. The email has somewhat dictionary based email contents (bypass basic search blocks) to trick the user to open the attached .doc or .docx file. If the doc is opened and macro is given permission to run it downloads and exe and no doubt more annoying stuff happens. ESET blocks the exe, Sophos is blocking bad hosts based on RBL checks, but Sophos so far is not picking up this .doc file and quarantining it at SMTP time. I have now resorted to blocking based on MIME types until Sophos starts blocking them properly - which as you can imagine, a lot of business emails contain Word documents.

Email example:

Subject: BPay file 9Y473M844O9X
Body:
Transaction Total: 35000.37 USD

Transaction Number: IDEWNL0EAG5CN

Recent Status: Please view enclosed file.

Snapshot of word doc contentsImgur: The most awesome images on the Internet

All references of BPay, Transaction, Status, file, DOC, MS Word and a whole bunch of others are interchangeable to try and circumvent detection. The file name and size are also different in every occurrence.

Has anyone found a decent method of blocking these?


This thread was automatically locked due to age.
Parents
  • Fresh round of Macroware attempted to get in today. Still no word from Sophos.

    Date Size Reason From To Subject
    4/11/2015 7:53 263kB MIME Type (application/mswo Seemingly random address Internal address Case 1X20
    4/11/2015 7:50 264kB MIME Type (application/mswo Seemingly random address Internal address Payment 7ZHU982TUA4Z
    4/11/2015 7:50 253kB MIME Type (application/mswo Seemingly random address Internal address Status NM57SYM7TTA45XY
    4/11/2015 7:49 254kB MIME Type (application/mswo Seemingly random address Internal address Case 685NELN
    4/11/2015 7:46 258kB MIME Type (application/mswo Seemingly random address Internal address Payment 9H9IW5GV462V544
    4/11/2015 7:45 263kB MIME Type (application/mswo Seemingly random address Internal address Status OEI0HNVF
    4/11/2015 7:41 257kB MIME Type (application/mswo Seemingly random address Internal address Payment M8U16GFQ5W30
    4/11/2015 7:39 257kB MIME Type (application/mswo Seemingly random address Internal address Status 6DE4WY1
    4/11/2015 7:38 261kB MIME Type (application/mswo Seemingly random address Internal address Payment T50R9YG323C
    4/11/2015 7:33 260kB MIME Type (application/mswo Seemingly random address Internal address Case 4L180OJ3LM7D
    4/11/2015 7:33 261kB MIME Type (application/mswo Seemingly random address Internal address Transaction X1L5YLN1KBA
    4/11/2015 7:32 269kB MIME Type (application/mswo Seemingly random address Internal address Payment R32GOVS
    4/11/2015 7:31 260kB MIME Type (application/mswo Seemingly random address Internal address Order P678463D9
    4/11/2015 7:24 263kB MIME Type (application/mswo Seemingly random address Internal address Order JTUU582
    4/11/2015 7:23 260kB MIME Type (application/mswo Seemingly random address Internal address Status C45E8653J062M4
    4/11/2015 7:21 263kB MIME Type (application/mswo Seemingly random address Internal address Transaction 06ISKKV2Y
    4/11/2015 7:20 263kB MIME Type (application/mswo Seemingly random address Internal address Payment 627PX6AD08N
    4/11/2015 7:19 263kB MIME Type (application/mswo Seemingly random address Internal address Order 92TVSDMQLX6TX7G
    4/11/2015 7:19 269kB MIME Type (application/mswo Seemingly random address Internal address Payment C133GW
    4/11/2015 7:18 263kB MIME Type (application/mswo Seemingly random address Internal address Case E9D3X0R
    4/11/2015 7:17 263kB MIME Type (application/mswo Seemingly random address Internal address Transaction WMQW86M4D287H
    4/11/2015 7:14 266kB MIME Type (application/mswo Seemingly random address Internal address Order YG88US23H7ISS2
    4/11/2015 7:11 269kB MIME Type (application/mswo Seemingly random address Internal address Payment YA8BGS2CO90
    4/11/2015 7:11 266kB MIME Type (application/mswo Seemingly random address Internal address Case T06V2V2
    4/11/2015 7:10 271kB MIME Type (application/mswo Seemingly random address Internal address Payment 8CVCL05PDF
    4/11/2015 7:07 266kB MIME Type (application/mswo Seemingly random address Internal address Case 038T1UQO3IR6
    4/11/2015 7:05 271kB MIME Type (application/mswo Seemingly random address Internal address Transaction 3YY04FD3C
    4/11/2015 7:00 267kB MIME Type (application/mswo Seemingly random address Internal address Transaction 052MPU3AGS18
    4/11/2015 6:56 297kB MIME Type (application/mswo Seemingly random address Internal address Case GKF3L0HLGLKDME
    4/11/2015 6:53 270kB MIME Type (application/mswo Seemingly random address Internal address Case 6B5N9W97Y
    4/11/2015 6:51 270kB MIME Type (application/mswo Seemingly random address Internal address Status TM403E294X
    4/11/2015 6:50 274kB MIME Type (application/mswo Seemingly random address Internal address Order 64IJM01S
    4/11/2015 6:48 270kB MIME Type (application/mswo Seemingly random address Internal address Status V9862G02Q76U9
    4/11/2015 6:45 270kB MIME Type (application/mswo Seemingly random address Internal address Transaction A0G55RK35HLV7H46
    4/11/2015 6:45 271kB MIME Type (application/mswo Seemingly random address Internal address Transaction UHJDVE
    4/11/2015 6:42 271kB MIME Type (application/mswo Seemingly random address Internal address Case OVEK88VGD2
    4/11/2015 6:42 271kB MIME Type (application/mswo Seemingly random address Internal address Status WV9381I1G
    4/11/2015 6:40 298kB MIME Type (application/mswo Seemingly random address Internal address Case MDYQ1ZA6B99EB
    4/11/2015 6:39 274kB MIME Type (application/mswo Seemingly random address Internal address Case 9655NBMZ57V
    4/11/2015 6:37 271kB MIME Type (application/mswo Seemingly random address Internal address Transaction Z7F9CK6RDT86
    4/11/2015 6:36 298kB MIME Type (application/mswo Seemingly random address Internal address Order PY93NSW1N7Y490
    4/11/2015 6:35 273kB MIME Type (application/mswo Seemingly random address Internal address Status 83EU8R6LO
    4/11/2015 6:35 271kB MIME Type (application/mswo Seemingly random address Internal address Transaction 248ETK296D1
    4/11/2015 6:31 274kB MIME Type (application/mswo Seemingly random address Internal address Transaction R0L72MBE6
    4/11/2015 6:30 273kB MIME Type (application/mswo Seemingly random address Internal address Status PK1OK1W80
Reply
  • Fresh round of Macroware attempted to get in today. Still no word from Sophos.

    Date Size Reason From To Subject
    4/11/2015 7:53 263kB MIME Type (application/mswo Seemingly random address Internal address Case 1X20
    4/11/2015 7:50 264kB MIME Type (application/mswo Seemingly random address Internal address Payment 7ZHU982TUA4Z
    4/11/2015 7:50 253kB MIME Type (application/mswo Seemingly random address Internal address Status NM57SYM7TTA45XY
    4/11/2015 7:49 254kB MIME Type (application/mswo Seemingly random address Internal address Case 685NELN
    4/11/2015 7:46 258kB MIME Type (application/mswo Seemingly random address Internal address Payment 9H9IW5GV462V544
    4/11/2015 7:45 263kB MIME Type (application/mswo Seemingly random address Internal address Status OEI0HNVF
    4/11/2015 7:41 257kB MIME Type (application/mswo Seemingly random address Internal address Payment M8U16GFQ5W30
    4/11/2015 7:39 257kB MIME Type (application/mswo Seemingly random address Internal address Status 6DE4WY1
    4/11/2015 7:38 261kB MIME Type (application/mswo Seemingly random address Internal address Payment T50R9YG323C
    4/11/2015 7:33 260kB MIME Type (application/mswo Seemingly random address Internal address Case 4L180OJ3LM7D
    4/11/2015 7:33 261kB MIME Type (application/mswo Seemingly random address Internal address Transaction X1L5YLN1KBA
    4/11/2015 7:32 269kB MIME Type (application/mswo Seemingly random address Internal address Payment R32GOVS
    4/11/2015 7:31 260kB MIME Type (application/mswo Seemingly random address Internal address Order P678463D9
    4/11/2015 7:24 263kB MIME Type (application/mswo Seemingly random address Internal address Order JTUU582
    4/11/2015 7:23 260kB MIME Type (application/mswo Seemingly random address Internal address Status C45E8653J062M4
    4/11/2015 7:21 263kB MIME Type (application/mswo Seemingly random address Internal address Transaction 06ISKKV2Y
    4/11/2015 7:20 263kB MIME Type (application/mswo Seemingly random address Internal address Payment 627PX6AD08N
    4/11/2015 7:19 263kB MIME Type (application/mswo Seemingly random address Internal address Order 92TVSDMQLX6TX7G
    4/11/2015 7:19 269kB MIME Type (application/mswo Seemingly random address Internal address Payment C133GW
    4/11/2015 7:18 263kB MIME Type (application/mswo Seemingly random address Internal address Case E9D3X0R
    4/11/2015 7:17 263kB MIME Type (application/mswo Seemingly random address Internal address Transaction WMQW86M4D287H
    4/11/2015 7:14 266kB MIME Type (application/mswo Seemingly random address Internal address Order YG88US23H7ISS2
    4/11/2015 7:11 269kB MIME Type (application/mswo Seemingly random address Internal address Payment YA8BGS2CO90
    4/11/2015 7:11 266kB MIME Type (application/mswo Seemingly random address Internal address Case T06V2V2
    4/11/2015 7:10 271kB MIME Type (application/mswo Seemingly random address Internal address Payment 8CVCL05PDF
    4/11/2015 7:07 266kB MIME Type (application/mswo Seemingly random address Internal address Case 038T1UQO3IR6
    4/11/2015 7:05 271kB MIME Type (application/mswo Seemingly random address Internal address Transaction 3YY04FD3C
    4/11/2015 7:00 267kB MIME Type (application/mswo Seemingly random address Internal address Transaction 052MPU3AGS18
    4/11/2015 6:56 297kB MIME Type (application/mswo Seemingly random address Internal address Case GKF3L0HLGLKDME
    4/11/2015 6:53 270kB MIME Type (application/mswo Seemingly random address Internal address Case 6B5N9W97Y
    4/11/2015 6:51 270kB MIME Type (application/mswo Seemingly random address Internal address Status TM403E294X
    4/11/2015 6:50 274kB MIME Type (application/mswo Seemingly random address Internal address Order 64IJM01S
    4/11/2015 6:48 270kB MIME Type (application/mswo Seemingly random address Internal address Status V9862G02Q76U9
    4/11/2015 6:45 270kB MIME Type (application/mswo Seemingly random address Internal address Transaction A0G55RK35HLV7H46
    4/11/2015 6:45 271kB MIME Type (application/mswo Seemingly random address Internal address Transaction UHJDVE
    4/11/2015 6:42 271kB MIME Type (application/mswo Seemingly random address Internal address Case OVEK88VGD2
    4/11/2015 6:42 271kB MIME Type (application/mswo Seemingly random address Internal address Status WV9381I1G
    4/11/2015 6:40 298kB MIME Type (application/mswo Seemingly random address Internal address Case MDYQ1ZA6B99EB
    4/11/2015 6:39 274kB MIME Type (application/mswo Seemingly random address Internal address Case 9655NBMZ57V
    4/11/2015 6:37 271kB MIME Type (application/mswo Seemingly random address Internal address Transaction Z7F9CK6RDT86
    4/11/2015 6:36 298kB MIME Type (application/mswo Seemingly random address Internal address Order PY93NSW1N7Y490
    4/11/2015 6:35 273kB MIME Type (application/mswo Seemingly random address Internal address Status 83EU8R6LO
    4/11/2015 6:35 271kB MIME Type (application/mswo Seemingly random address Internal address Transaction 248ETK296D1
    4/11/2015 6:31 274kB MIME Type (application/mswo Seemingly random address Internal address Transaction R0L72MBE6
    4/11/2015 6:30 273kB MIME Type (application/mswo Seemingly random address Internal address Status PK1OK1W80
Children
No Data