A screenshot of the mail looks like this:Subject: {first name surname}:{serial time and number}
Estou te passando, mas nao mostre a ninguem
Please. Vai zipado com senha viu!!
Senha do Zip: 102030
..
Baixar Zip 212 KB <--link to http://dl.dropbox.com/[edit]/View.zip?....
[edit].ar:00:03:26:6830051160[edit]361
As you can see in the screenshot, something interesting about this case, is that the link points to Dropbox.com, a free service for saving and sharing files. There the criminals have hosted the Trojan with the name Visualize.zip.
By using a dropbox.com link, the offender manages to bypass email filtering by the link's reputation. They also achieve this when they use shorteners recognized as bit.ly or tinyurl.
The malware in question is detected, at least by Kaspersky, as Trojan.Win32.VBKrypt and once the PC is infected, every time the user connects to the Windows Live/Hotmail webmail, it sends to the contacts of that email account, a message like the one described, without being noticed by the PC user.
Because of the reports received, many people fall into deception when they see that the mail comes from someone they know. It spreads as you can see among contacts of well-known people.
It should be clarified that so far we are not aware that any vulnerability of Hotmail or Windows Live is being exploited, they have simply managed the criminals to detect the connection to Hotmail and abuse that by making malicious shipments without the owner of the account noticing.
From Segu-Info we have already reported the problem to Dropbox.com, and in less than an hour they confirmed the cancellation of the file and the user:
To avoid these types of problems, just keep in mind these simple tips:Kevin - Dropbox Support, May-06 01:46 pm (PDT):
This user has been banned for Terms of Service violation.
Thanks for bring this to our attention.
Best
Kevin
• In the event of an unusual subject email, do not open it.
• If the email is from a stranger, do not open it.
• If the email comes with unsolicited or unexpected attachments or links, don't open them even if it comes from someone you know.
• If the mail comes in a language other than the usual one, do not open it.
• If you are curious to see what it is, resist and a problem will be avoided.
Raúl de la Redacción de Segu-Info

