Close Call

Today, a colleague had this email:

A Spear Phishing attack
A Spear Phishing attack

from “customercare@parcel-tracking.net”. It fooled two people: The original recipient forwarded it to a colleague to deal with, who clicked on the link, and got this:

Nice mock-up....
Nice mock-up….

With graphics nicely nicked from the genuine Royal Mail site. The URL calling the site had a ID embedded, presumably to mark the recipient out as a sucker if they click, so I changed it for my investigation. The Captcha image remains the same, even if you vary the ID.

If you enter the code, you get prompted to download a .zip file with a random filename, and inside the zip file is a windows executable, disguised with a icon for Adobe Acrobat Reader.

Should you be convinced enough to run the attachment, you’ll get a pop-up demanding money to unencrypt your files, and this is no idle threat: running this inside an isolated Windows XP Virtual Machine really does damage files in My Documents- this is known as ransomware. Fortunately, the security measures on the computer used by this user stopped it.

Time for a reminder: think before opening. Questions the user *should* have asked:

1. Why would Royal Mail know my email address?

2. Why would they not just post a card through the letterbox?

3. Why “nobody was at home” for a business address?

4. Why would I need to download and run something just for a receipt?

To be fair, item 4 is picking flies a bit: some websites demand plug-ins or other crap, so differentiating the genuine from the scam gets harder.

Also, the site and email are quite a nice mock-up, using elements from the real site. Fairly convincing, and it also had the correct business name, which is a clever touch.

[edit]
It’s also worth noting that our (up-to-date) anti-virus didn’t catch this, either the original email or the downloaded file. It seems to be a zero-day attack.

11 thoughts on “Close Call”

  1. Good call. Can I add numbers 5 and 6?

    5. If the English doesn’t read as if it were written by your English teacher, it probably merits concern.

    6. How many people do you know who place the pound sign after the amount?

  2. i wonder, but dont have the balls to test , if these ransonware shites can fuck with NAS storage
    or cloud storage with version control

    Someone at work got suckered by a “click here to upgrade” email which appear to be from his ISP
    ISP in question is in the middle of a MAIL platform migration.

  3. @kate: Agreed. I’d add another myself: why would the Royal Mail use “parcel-tracking.net” (which was registered today), and not “royalmail.com”?

  4. @species5618 It didn’t get at the mapped network drives, thankfully, which was a big concern. I suppose if you wanted to test, you could use a test account with limited permissions, but needless to say, I tested in a VM with the network adaptor disabled, and a local user.

  5. Police won’t give a shit 🙂 . I’ve reported the URL as suspicious,hopefully it will get around the web filters and browser warning DBs.

  6. parcel-tracking.net now seem to do a proper redirect to the royal email
    but the IP still seem to be somewhere in Russia

    Key Value
    Response HTTP/1.1 302 Found
    Server nginx/0.8.54
    Date Tue, 25 Feb 2014 09:14:14 GMT
    Content-Type text/html; charset=UTF-8
    X-Powered-By PHP/5.3.3
    Location http://www.royalmail.com/

  7. Not convinced “the authorities” have enough clout to taken down / fix a site registered in Australia and hosted in Russia in a few days.

Comments are closed.