Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Phishing/Spam Pretending to be from BBB - SANS Internet Storm Center SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Phishing/Spam Pretending to be from BBB

We received another piece of spam (thanks Curtis) pretending to be from the Better Business Bureau. Analysis of the file transferred (W6w8sCyj.exe) from appears to be a piece of malware (Win32/Cridex.Q) use to communicates via SSL with a C&C server.

List of domains/IP to watch for and block:

The email looks like this:

Better Business Bureau©
Start With Trust©
Sat, 08 Sep 2012 01:54:02 +0700

RE: Case # 78321602 <http[:]//>

Dear Sirs,

The Better Business Bureau has got the above mentioned complaint from one of your customers concerning their business relations with you. The details of the consumer's concern are contained in attached document. Please give attention to this case and advise us of your opinion as soon as possible. We encourage you to open the COMPLAINT REPORT to answer on this complaint.

We look forward to your prompt response.

Faithfully yours,
Ann Hegley
Dispute Counselor
Better Business Bureau




Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu


523 Posts
ISC Handler
Sep 9th 2012
That's pretty lame: "We encourage you to open the COMPLAINT REPORT..." Yes, Please, *PLEASE* open the attachment, pretty PLEASE? Its like they are beggin you to be a luzer. :-(

Sign Up for Free or Log In to start participating in the conversation!