A malicious email claims to have been sent by the law firm Deans & Lyons and is intended to inform recipients about new violations committed by the police following the Ferguson.
The message contains a link that appears to lead to a CNN, although the domain name should be enough of a clue to prevent users from following the link.
According to MX Lab , a company that provides solutions against email threats, accessing the URL downloads a ZIP containing a file with a double extension (BreakingNews_pdf_exe). This is a variant of the Upatre Trojan that is generally used to distribute various pieces of malware to the affected computer.
To convince the recipient to click on the link, the scammers claim that it is a report prepared by the law firm regarding the situation in Ferguson, Missouri. The multiple grammatical errors in the body of the message should raise suspicions in the recipient.
Analysis of the malicious file on Friday showed that only three out of 54 antivirus engines on VirusTotal were able to detect the threat. However, by now, that percentage has increased and 19 security products are now detecting the item as malicious.
The VirusTotal states that there are six PE resources available, five of which are Dutch and one is English.
A commenter on the website says that the threat leads to a version of Dyreza, also known as Dyre. It is a Trojan used to steal banking information, which has been used against many financial institutions in European countries, and in particular in Switzerland.
It has also been observed targeting customers of Salesforce, a cloud-based CRM provider, and is used to steal Bitcoin on commercial websites.
MX Labs reports that, once the download is complete, the URL redirects to a legitimate CNN page offering more details about the events in Ferguson.
The domain hosting the malicious file has been suspended and there is currently no longer a risk of malware from this address. However, cybercriminals may register a new domain for the attack and continue sending malicious emails.
The malware appears to have been distributed under multiple names, including “ybwbh.exe” and “file-7765943_exe”, suggesting that it is being distributed in multiple email campaigns.
Email attacks are particularly frequent and aggressive during the holiday season. Users are advised not to follow links contained in suspicious messages and to verify the information first.

