Home Malware Programs Trojans Trojan-Ransom.Win32.Gimemo.ashm

Trojan-Ransom.Win32.Gimemo.ashm

Posted: February 4, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 38
First Seen: February 4, 2013
OS(es) Affected: Windows

Trojan-Ransom.Win32.Gimemo.ashm is a Trojan that is a component of a spam email campaign targeting Business Direct customers of British Telecom. The fake British Telecom emails pretend to come from British Telecom, a British multinational telecommunications services company, popularly known as BT headquartered in London, United Kingdom. The bogus British Telecom email messages bear the title 'BT Business Direct Order' and have a confirmation message for sending the order on the certain date. However, till the next day or other premium delivery service option is not chosen by the PC user, then the order will take 1-3 days to arrive. Instead, if the message is sent through a Letterpost, the timing would be a little longer. To make the spam email look and sound legitimate, it also includes a message like the order might have been shipped in different boxes, which means that separate shipment numbers might be appropriate for the same. At first glance, the unsolicited British Telecom emails look authentic though the attached HTML file takes the affected recipients to a fraudulent Russian host, the BlackHole exploit kit exploring the computer user's system for security holes and the vulnerabilities being employed to spread the Cridex malware threat.

Loading...