{"id":2529,"date":"2018-02-16T23:07:16","date_gmt":"2018-02-16T12:07:16","guid":{"rendered":"http:\/\/activateit.net.au\/?p=2529"},"modified":"2018-02-16T23:33:38","modified_gmt":"2018-02-16T12:33:38","slug":"february-16-2018-another-bogus-quickbooks-email-links-to-malware","status":"publish","type":"post","link":"https:\/\/activateit.net.au\/?p=2529","title":{"rendered":"February 16, 2018: Another bogus Quickbooks email links to malware"},"content":{"rendered":"<p>Emmanuel Marshall from mailguard writes:<\/p>\n<p>This is the second email scam mimicking a Quickbooks notification. As you can see in the screenshot, the message is meant to look like an invoice notification message.<\/p>\n<p>Although this scams looks superficially similar to the one from earlier today, the sender addresses and underlying mechanisms of this attack are actually quite different.<\/p>\n<p>The fact that this scam is so superficially similar to the one intercepted earlier could indicate that the two attacks have been released by the same criminals, but because there are significant differences in the way the scams work, that is not necessarily the case. <\/p>\n<p>Malware as a service (MaaS) is a fast-growing phenomenon in the cybercrime world so it\u2019s quite likely that these two emails are actually the work of different scammers using the same off-the-shelf malware package, bought from an underground vendor and then adapted for their own specific purposes.<\/p>\n<p>This scam is designed to look like an invoice notification created through the Quickbooks system but of course, it is really just a ruse to get the victim to click on the \u2018view invoice link\u2019 in the message. This link takes the victim to a compromised WordPress domain, which then redirects them to an archived file which contains malicious JavaScript code.<\/p>\n<p>Malware created in JavaScript can perform a wide variety of functions; it is commonly used to install spyware and botnet worms on computer systems and to deliver ransomware.<\/p>\n<p>This message displays a wide variety of different \u2018subject\u2019 field variants, including:<\/p>\n<p>    Subject: Invoice 07766 from Mathers Shoes<br \/>\n    Subject: Invoice 06108 from Master Shopfitters<br \/>\n    Subject: Invoice 05247 from Skilled Design Consultants<br \/>\n    Subject: Invoice 07729 from Cafe Bellissimo<br \/>\n    Subject: Invoice 09510 from Hillyer Riches<br \/>\n    Subject: Invoice 09549 from Circa Property Pty Ltd<br \/>\n    Subject: Invoice 04977 from Fresh Outlook<br \/>\n    Subject: Invoice 05454 from Charles Lloyd Property Group<br \/>\n    Subject: Invoice 08418 from Pacific Shopping Centres Australia Pty Ltd<br \/>\n    Subject: Invoice 01552 from Stokegreen Group Pty Ltd<br \/>\n    Subject: Invoice 08240 from ATF Services<br \/>\n    Subject: Invoice 00743 from Allcraft Cabinet Works<br \/>\n    Subject: Invoice 04754 from Ross Engineering Pty Ltd<br \/>\n    Subject: Invoice 04977 from Spruce Property Presentation<br \/>\n    Subject: Invoice 00118 from Vision Real Estate Pty Ltd<br \/>\n    Subject: Invoice 00322 from Cunningham Property Consultant Pty Ltd<br \/>\n    Subject: Invoice 08605 from Thurley<br \/>\n    Subject: Invoice 09352 from G T Builders Pty Ltd<br \/>\n    Subject: Invoice 06516 from Total Construction Pty Ltd<\/p>\n<p>The message is also designed to display a range of different sender names and email addresses, including:<\/p>\n<p>    From: &#8220;Pearce-Higgins Simon&#8221; <sale@eliancomplianceservices.com><br \/>\n    From: &#8220;Empower Wealth&#8221; <admin@jwmitchell.com><br \/>\n    From: &#8220;Newquay Display Suites&#8221; <support@eliancomplianceservices.com><br \/>\n    From: &#8220;Hidden Beauty&#8221; <sale@plookie.com><br \/>\n    From: &#8220;Stoneleighton Developments Pty Ltd&#8221; <sale@kelseykmartin.com><br \/>\n    From: &#8220;Golf Club Properties Pty Ltd&#8221; <info@capitalgoldscam.com><br \/>\n    From: &#8220;Silk Homes&#8221; <admin@eliancomplianceservices.com><br \/>\n    From: &#8220;MAB Corporation Pty Ltd&#8221; <billing@manhoodgrooming.com><br \/>\n    From: &#8220;DCG&#8221; <admin@cadenaexportadora.com><br \/>\n    From: &#8220;Heng Sheng Asian Grocery&#8221; <no-reply@webcereals.com><br \/>\n    From: &#8220;Video Essentials&#8221; <admin@dolumcu.com><br \/>\n    From: &#8220;MacLaw 651 Pty Ltd&#8221; <mail@mckinleylosee.com><br \/>\n    From: &#8220;Kennedy Plumbing&#8221; <admin@aconferenceline.net><br \/>\n    From: &#8220;Millar Accounting Group&#8221; <admin@plookie.com><br \/>\n    From: &#8220;Property Dynamics&#8221; <sale@lowriderhaven.com><\/p>\n<p>If you see this message delete it immediately to avoid harm to your computer system.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Emmanuel Marshall from mailguard writes: This is the second email scam mimicking a Quickbooks notification. As you can see in the screenshot, the message is meant to look like an invoice notification message. Although this scams looks superficially similar to the one from earlier today, the sender addresses and underlying mechanisms of this attack are [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2530,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-2529","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"_links":{"self":[{"href":"https:\/\/activateit.net.au\/index.php?rest_route=\/wp\/v2\/posts\/2529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/activateit.net.au\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/activateit.net.au\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/activateit.net.au\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/activateit.net.au\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2529"}],"version-history":[{"count":4,"href":"https:\/\/activateit.net.au\/index.php?rest_route=\/wp\/v2\/posts\/2529\/revisions"}],"predecessor-version":[{"id":2541,"href":"https:\/\/activateit.net.au\/index.php?rest_route=\/wp\/v2\/posts\/2529\/revisions\/2541"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/activateit.net.au\/index.php?rest_route=\/wp\/v2\/media\/2530"}],"wp:attachment":[{"href":"https:\/\/activateit.net.au\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/activateit.net.au\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/activateit.net.au\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}