home bbs files messages ]

Just a sample of the Echomail archive

<< oldest | < older | list | newer > | newest >> ]

 Message 1460 
 August Abolins to All 
 trojan inside xls file 
 10 Mar 20 17:11:13 
 
MSGID: 2:221/360.0 5e67ae0e
PID: JamNNTPd/OS2 1.3 20191227
TID: GE/2 1.2
CHRS: UTF-8 2
TZUTC: 0200
I forgot to mention..  that the file arrived as:


invoice_867545.xls   ..but when sent to Virus total, it was a different name:

  Results at VirusTotal:

  6 engines detected this file

  invoice_507574.xls
  64.00 KB


BTW.. I sent it to Google Sheets (to see if I could peek at the payload
mechanism details  ..apparently it operates via a macro), but it seems to be
neutered there without any reason.


  http://pics.rsh.ru/img/scam-invoice-0_xljlzkeh.jpg

  http://pics.rsh.ru/img/scam-invoice-1_ow9bs085.jpg



-- 
Kad esat sagriezis maizi, to vairs nevarat salikt.

--- TB68.4.1/Win7
 * Origin: nntp://rbb.fidonet.fi - Lake Ylo - Finland (2:221/360.0)
SEEN-BY: 1/123 19/10 90/1 103/705 154/10 203/0 221/0 1 6 360 227/114
SEEN-BY: 229/101 426 452 1014 240/5832 249/206 317 400 280/464 5003
SEEN-BY: 288/100 292/854 310/31 317/3 322/757 342/200 396/45 423/81
SEEN-BY: 423/120 712/848 770/1 2452/250
PATH: 221/360 1 280/464 229/426


<< oldest | < older | list | newer > | newest >> ]

(c) 1994,  bbs@darkrealms.ca