[Warning] Detected malicious file disguised as of VISA card

1. Introduction

INCA Internet response team detected malicious file disguised as of VISA card. In case of this e-mail is usually being sent for overseas users. Not only for this, invoice information of global logistics company, request of changing password on certain web site including SNS, e-ticket and attachment of fake image file are booming for same purpose. In general, we have our credit card and VISA is one of famous brand of credit card, therefore; we might become potential victims.

Besides, this kind of e-mail can be sent as SPAM mail and infected PC can be another host for sending same mail.

[Warning] Malicious e-mails disguising as image file were found.

[Warning] Identified malicious file masqueraded as an e-mail attachment file.

[Caution] Malicious files disguising as sent logistics services companies

2. Spreading path and symptom of infection

This malicious file can be spread via attachment on e-mail and contains VISA related contents, its sender name is from LinkedIn. If a user who use both LinkedIn and VISA card service, potential risks will be higher.

E-mail is as following

From :
LinkedIn Password (password@linkedin.com) -> Fake address

Title :
 Your credit card has been blocked

Body :
 Dear Client,

CAUTION: Your credit card is locked!

Your credit card was withdrawn $ 424,13

Possibly illegal operation!

More info in the attached file.
 Immediately contact your bank .

Best Wishes, VISA Customer Services.

Attachment :

Attachment(VisaCard-N47619822.zip) contains malicious "VISA_ID48832743.exe" and its icon looks like MS Word file.

Upon executing "VISA_ID48832743.exe", user will be infected by malicious file and creates its clone on [Application Data] and execute.

And then, it will run normal "Explorer.exe" and try to access certain hosts. Finally it performs various malicious behaviors by C&C server.

Following figure shows accessing status.

3. Summary

Various cases of installing malicious files with disguised as credit card or normal notices from certain company are continuously detected. Therefore, users need to be careful from these security threats. To use PC safely from security threats of these malicious attachments, we recommend you download latest security updates and obey following "Security management tips" for general users.

Security management tips

1. Maintain the latest security update on OS and applications
2. Use anti-virus SW from believable security company and keep updating the latest engine and using real time detecting function
3. Do not see and download attached file from suspicious e-mail.
4. Keep caution to link from instant messenger and SNS.

INCA Internet (Security Response Center / Emergency Response Team) runs responding system against various security threats.
nProtect Anti-Virus/Spyware v3.0 diagnoses and treats various variant files.

Free installation link of nProtect AVS : http://avs.nprotect.com/


  1. Thank you very much, guys, for posting this guide! We really appreciate that!

  2. Oh! This article has suggested to me many new ideas. I will embark on doing it. Hope you can continue to contribute your talents in this area. Thank you.
    light novel

  3. Very good, I think I found the knowledge I needed. I will see and refer some information in your post. thank you

  4. This is a great article, with lots of information in it, These types of articles interest users in your site. Please continue to share more interesting articles! Thank you!fnaf

  5. افضل شركة تنظيف فلل بالرياض http://tiny.cc/lmph5y  ؛ بالطبع ندرك جميعاً أن النظافة من أهم المتطلبات التي نحتاج توافرها في حياتنا ولا شك أن النظافة تمنحنا شعوراً بالراحة النفسية والقدرة على القيام بمهام الحياة بشكل أفضل ,كما أنها توفر لنا صحة أفضل حيث أن هناك العديد من الأمراض التي تنتشر نتيجة قلة النظافة وزيادة التلوث وهو ما يؤثر سلبياً على صحتنا.
    لا يخلو منزلٌ من حاجته إلى عملية تنظيفٍ شاملةٍ وجذريةٍ على فترات متفاوتةٍ ونحن في شركة دريم هاوس للخدمات المنزلية نقدمُ لعملائنا الكرام خدمةَ التنظيفِ لكل جزء من أجزاءِ المنزل مهما كان حجمه ومساحته مع تخصيصِ أدواتٍ وموادٍ معينة لكل من الحمامات والمطابخ والأثاث والمفروشات والنوافذ والأبواب والأرضيات بمختلف أنواعها، ونحن نختار مواد التنظيف المعتمدة عالميًا والفعالة في أداء مهمتها، حيث نترك لك المكان وكأنه تم إنشاؤه من جديد
    ومن هنا بدأت شركتنا الاهتمام بمجال النظافة وتوفير خدمة راقية ومميزة تليق بعملائنا ,حيث تتميز شركتنا أنها أهم شركة نظافة فلل بالرياض من خلال مجموعة من العروض المميزة والتي تتميز بجودة عالية وأسعار تتناسب مع كافة الاحتياجات والطبقات. .… اقرأ المزيد

    المصدر: شركة تنظيف فلل بالرياض

    افضل شركة تنظيف موكيت بالرياض  http://tiny.cc/drph5y هل تغيرت ألوان الموكيت لديك ؟ هل تعانين من بقع في الموكيت أو السجاد ولا تجد الوقت الكافي لإزالتها, أو حالتك الصحية لا تسمح لك بذلك ؟؟ هل لديك بعض أنواع الموكيت أو السجاد باهظة الثمن كالسجاد الإيراني ,أو التركي ونحوه وتخشى إتلافها جراء عملية التنظيف أو بعض المساحيق الخاطئة ؟.
    قدم شركتنا عروض متميزة للغاية لتنظيف الموكيت وكذلك تنظيف شقق في جميع أنحاء مدينة الرياض ,من خلال مجموعة من العاملين الموثوق بهم تماماً وعلى أعلى درجة من الكفاءة والإتقان في عملهم ,حيث يقوم العاملين لدينا بتنظيف المنازل بالكامل سواء الغرف أو المجالس أو المطابخ وكذلك دورات المياه .
    والتي تتطلب قدر عالي من الإتقان لأنها من أهم الأجزاء في أي منزل التي تحتاج قدر عالي من النظافة فهي أساس نظافة المنزل بأكمله وهي من أكثر الأماكن التي تحتوي على ميكروبات وجراثيم قد تؤدي للعديد من الأمراض
    تقدم الشركة خدمات تنظيف وبأفضل مستوى للموكيت و السجاد و بأجود أنواع العمالة المدربة وبأسعار تناسب جميع العملاء.… اقرأ المزيد

    المصدر: شركة تنظيف موكيت بالرياض

  6. This is the absolutely very first time I see right here. I placed many satisfying things on your blog site, especially its conversation. From the deals of reviewing your fast evaluations, I think I am not the just one having all the pleasure below! Maintain the amazing.
    If you surf on the internet more often then beware of click baits which causes data breaches or harms the systems performance, use McAfee antivirus with a McAfee Activate 25 Digit Code to avail the best features.

  7. i used https://robloxfever.com/ for detecting those files , it worked well

  8. https://robloxfever.com/August 6, 2019 at 7:47 PM

    I used the similar approach for detection , Thank you

  9. This is a great little post with some valuable tips. I totally agree. The way you bring passion and engagement into the things you do can really change your outlook on live!

  10. Are you looking to buy the Best Custom Essay Paper from the best writers? When given assignments, many students look for Top-Ranked Essay Writing Service and through a basic web search, you can find many online companies offering help with Best Custom Essay Ever.

  11. windows spotlight quiz is an application used in windows 10 it changes the background images in users login windows.
    it shows HD images to users. it's a latest feature added by microsoft in windows 10.

  12. Quickbooks provides best accounting services as through this you can create or manage your business accounts details and records of tax bills, payments, transactions, etc online in fast and easy and way and in case you need any help assistance you can contact Quickbooks tech support
    and ask for Quickbooks assistance

  13. Geek squad is a popular brand in the field of tech assistance provider with 24*7 service so in case you need any tech help regarding your tech devices you can contact them and ask for Geek squad support and ask for Geek squad tech support

  14. free robux generator is the best and reliable online gaming currency generation website to offer you to the best and reliable online gaming currency generation website to unlock new gaming accessories and characters.

  15. free robux generator is the best and reliable online gaming currency generation website which allows you to unlock new gaming accessories and characters to get the better look to the game.This is because of the free robux hack provided by us.

  16. This comment has been removed by the author.

  17. how to get free robux ?
    Get free Robux with the only legit Robux Generator, it works on all OS and devices. Try out robux generator tool and bypass the human verification in just a small survey.

  18. need Free vbucks ?
    The best app to create unlimited vbucks is the vbucks generator tool. you can download it from our website. these vbucks are not transferred from one account to another. you can unlock your favorite characters with the help of these vbucks

  19. api-ms-win-crt-runtime-l1-1-0.dll is missing from your computer you can remove the dll errors and 0x334 error from your computer with help of this guide.


  20. تسليك مجارى بالاحساء تسليك مجارى بالاحساء
    تسليك مجارى بالدمام تسليك مجارى بالدمام
    تنظيف بيارات بالرياض تنظيف بيارات بالرياض

  21. This is a very interesting post and all the details are in this post are awesome.
    hotmail login

  22. for any business, accounting is an important factor and you can do that with the help of Quickbooks which is an advanced accounting tool that offers multiple accounting features and in case you need any help assistance regarding Quickbooks you can contact Quickbooks support and ask for Quickbooks assistance

  23. I really wanted to send a small word to say thanks to you for the fantastic points you are writing on this site.
    gmail sign up

  24. fireboy and watergirl is a journey of friends having common goal to win risky game. They need solidarity and coordination to get successful key.

  25. Hello readers of this blog! Do you need to order essays online fast, because you have no time to do your own literary masterpiece!? So, forget everything else and I've a great idea for you. You can contact our online free paper writer agency via the webpage and then you will see how professional writers will help you to do prime essays!!!

  26. Mind blowing! Your wording is unique.Please write an article on custom beard oil boxes .Thanks again.