INCA Internet response team detected malicious e-mail disguised as Windstream service in Korea. Its title is "Your Windstream bill is available for viewing". It doesn't contain attachment; however, it has malicious link for trying to infect malicious file. It contains various malicious web sites, which is run by Blackhole Web Malware Exploitation Kit, attacker can monitor infection status and can attack with various exploits on real-time. Because there are a lot of malicious e-mails in Korea in these days, users need to be careful by these malicious e-mails.
2. The body of malicious e-mail
E-mail can be sent to uncertain users as following types. Its body contains various malicious URLs.
Title : Your Windstream bill is available for viewing
Its body contains various malicious URLs.
Upon clicking link, it will redirect browser to malicious web site and will be exposed by various exploits.
Web site shows following image due to js.js, installs various malicious files and redirects to normal msn.com.
js.js contains following contents.
It tries to install with using Adobe Flash Player, JAVA exploit.
This malicious file tries to access certain site by injected code on explorer.exe.
It can be worked by C&C(Command and Control).
Besides, attacker can monitor infected PCs and can control.
Recently, this kind of technique, inducing user to click type, is prevalent in Korea. Therefore, users need to be careful on using internet. To use PC safely from security threats of these malicious attachments, we recommend you download latest security updates and obey following "Security management tips" for general users.
INCA Internet (Security Response Center / Emergency Response Team) runs responding system against various security threats.