Caution with emails that have an attached CV – a résumé of a job applicant, because some hackers still use old JavaScript attachments to “deliver” CryptoWall which could create a major problem on users' systems.
In an article of his that was published on the SpiderLabs Blog, Brian Bebeau reported that recently, a massive email campaign was observed that contained an attached CV from a job candidate. The attached file, with the extension «.js»», was plain-text and contained Javascript.
After a few days, the next massive spam was more serious and the attached file it contained was zipped. The hackers tried to give the attachment a MIME type «image/png» in order to appear as an image to the recipients.
If someone retrieved the image, it turned out to be a Windows .exe file.
Bebeau wrote that after analyzing the file, they discovered that it is a variant of the Cryptowall ransomware. Thus, if someone opened the attachment to view the résumé or an image, they could end up with their entire system in trouble.
He also mentioned that a certain group of spammers also uses JavaScript to hide their phishing attachments. Instead of a CV, they attached the all-time classic account phish.
Bebeau wrote that people can verify an email's legitimacy by examining the senders' addresses before opening the attachments contained in the message.
If the attachment is an HTML file, it may contain a piece of JavaScript that directs users to open the JavaScript. If they open the attachment in javaScript – enabled broswer, a form appears that asks for their personal information.
The form asks for their social security number and their credit card number along with their name and address. And if someone fills it out and clicks submit, all their data is sent to a central server in Russia.
According to Bebeau, if people can examine an attachment carefully and detect any malicious JavaScript, then it would be beneficial to block it permanently.
He wrote that the Trustwave SEG cloud blocked about 200 of these phishing messages within three days. Users should not open the JavaScript even if an email asks them to do so.


