“Your Amazon.co.uk order has dispatched (#203-2083868-0173124)” Spam / Virus

A family member had an email today titled “Your Amazon.co.uk order has dispatched (#203-2083868-0173124)” with attachment ORDER-203-2083868-0173124.doc

Upon opening it requires Macros to be enabled (Macro is here), once enabled it contacts
http://garfield67.de/1.exeVirustotal Report // Malwr Report
And downloads the file and saves it to (or similar):

It then communicates with CnC server:

inetnum: –
netname: HWUK-VPS1
descr: Virtual Private Servers
country: EU
admin-c: HM2016-RIPE
tech-c: HM2016-RIPE
source: RIPE # Filtered

This entry was posted in Uncategorized. Bookmark the permalink.

1 Response to “Your Amazon.co.uk order has dispatched (#203-2083868-0173124)” Spam / Virus

  1. Pingback: Failed Fax Transmission to 01616133969@fax.tc | thecomputerperson

Comment on this topic

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s