Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Spam Reports

September 20th, 2012, 08:08 GMT · By

BillMeLater Debt Notifications Carry Trojan

SHARE:

Adjust text size:

Fake BillMeLater notification
Enlarge picture
Have you received a threatening notification in which you were told about a debt to PayPal’s BillMeLater service? If you have, you should know that you are a target of a cybercriminal scheme whose main goal is to spread a nasty Trojan.

Bearing subject lines such as “Immediately pay off the debt!”, “We will file a charge against you.”, or “You must immediately pay off the debt!” the emails read something like this:

We notified you several times about your debt to Bill Me Later.

In the event that you fail to voluntarily satisfy our requirements for payment of your debts to Bill Me Later, we will have to turn to the court with the purpose of enforced collection of the debt, which may entail additional expenses for you.

For example, the expenses in the amount of safe duty, the cost of representative’s services for the compearance, the compensatory interest for the use or detention of money for each day of delay and execution fee.

Based on the foregoing we offer you to pay the debt in the amount of $349.00


The bottom of the notification contains a “PRINT THE INVOICE” button, which, according to MX Lab experts, leads to a website that’s designed to serve an archive file - INVOICE_FORM.zip – that hides a malicious payload.

Once it’s decompressed, the .zip file reveals an executable named INVOICE_FORM.exe. This is actually a new version of the Trojan identified by Kaspersky as HEUR:Trojan.Win32.Generic.

Currently, only 6 of the antivirus companies present on VirusTotal identify the file as a threat.

While this particular notification appears to be perfectly designed, containing all the appropriate logos and seemingly originating from eBay, if we take a close look at the actual message, it’s clear that it’s not legitimate.

We advise users to check out all the details of such emails before rushing to click on the links they contain.
FILED UNDER:
spam
Trojan
scam


2,386 hits · 5 comments
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


FBI: Networks of Financial Institutions Targeted with Malware, RATs and Keyloggers

Masters of Grum Attempt to Rebuild Spam Botnet

Fake LinkedIn Reminders Possibly Connected to Data Breach

Facebook Account Confirmation Spam Leads to Rogue Pharmacy, Other Threats

ADP Dealer Services Invoice, FDIC Emails Lead to BlackHole Exploit Kit

READER COMMENTS:


Comment #1 by: Bercis on 26 Sep 2012, 07:06 UTC reply to this comment

I received this mail just now google it immediately and saw your article. I didn't even use this service but anyway I freaked out
Thank you very much for warning


Comment #2 by: Ozzie42 on 27 Sep 2012, 07:56 UTC reply to this comment

I just had this e-mail as well. Knowing full well that I owe nobody anything I checked the web before looking at the invoice. The giveaway if you look carefully is that the senders address contains "billmelateer" with 2 ees! Thanks for the warning.


Comment #3 by: bob on 28 Sep 2012, 12:34 UTC reply to this comment

I received this email but it was from "billmelateer.com"


Comment #4 by: daughter on 17 Oct 2012, 23:27 UTC reply to this comment

Thank you - my father (non eBay and PayPal user) recieved this and was concerned. We were glad to find your article confirming we should delete and not open the link!


Comment #5 by: el boy on 13 Nov 2012, 20:23 UTC reply to this comment

I got many scam emails like this all the time and they just make me laugh

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM