
SonicWALL UTM Research team received reports of a new spam campaign pretending to be arriving from US Postal Service spreading in the wild. It contains the new variant of Dofoil Trojan that SonicWALL blocks as GAV: Dofoil.L. This worm also downloads other malware components including trojans and FakeAV malware.
The sample e-mail format of the spam campaign includes the following:
Subject:
Attachment: Post_Label#id{Random Numbers}.zip
The ZIP file attachment contains the malicious executable that disguises itself with the use of Microsoft Word icon as shown below:
Example of the email spam:
If the user downloads and executes the malicious executable inside the zip attachment, it performs the following activity:
Downloads other malware:
Added Registry:
Network Activity:
HTTP GET Requests:
DNS Requests:
Hosts File Modification:
This malware added the following entries to block access to torrent websites.
FakeAV
After Installing the FakeAV application, it will show a Fake Windows Error Alert as seen below:



Clicking the "Scan and fix" Button will scan for errors and show a fake result:
Clicking the "Fix Errors" button prompts the user to buy the fake security software.
SonicWALL Gateway AntiVirus provides protection against this threat via the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News