Intuit invoices from Sequoia used for malware

Summary

This blueAPACHE post reports: Another phishing attack, but with a local financial entity and a real Inuit email address. As we have mentioned in previous blog entries, it is often easy to identify the less mature malware attacks by simply checking the email addresses or holding you mouse over any links to show their true destination. It concerns emPOWER Security, Human Risk Management. Published in 2016. Figures, product names and event details reflect that time; for current information see the linked service pages.

Key facts

Label Value
Publication year 2016
Services referenced emPOWER Security, Human Risk Management
Topic Intuit invoices from Sequoia used for malware

Article

Another phishing attack, but with a local financial entity and a real Inuit email address. As we have mentioned in previous blog entries, it is often easy to identify the less mature malware attacks by simply checking the email addresses or holding you mouse over any links to show their true destination. Today, we received notification of emails that present as invoices from Sequoia Financial Group; a legitimate financial services company in Melbourne and Sydney. The email appears genuine, seemingly sent from the popular Intuit Quickbooks accounting software. The sender address is quickbooks@notification.intuit.com, appearing exactly as would expect for an online invoice notification. None of the normal fake email tell tale signs were present – this looked for all intents and purposes to be correct. Except it isn’t. Sequoia The problem is the view invoice link. The link is difficult to read when hovering your mouse over, as it is automatically generated through a popular mail management program. Clicking to access the invoice will automatically download a file entitled Invoice_70861.zip. The file inside the downloaded zip file is Invoice_70861.js. If you open this file to read the invoice, the trojan is installed and no file is displayed. The trojan then accesses the Kernel Security Device Driver (KsecDD) of Windows, reads personal information, creates writeable files in a temporary directory, writes PE32 executable console files to disk, creates mutants, reads Windows trust settings and system certificate settings, connects to LPC ports, enters URL in binary, connects to two domains (USA and UK based IP address), and contacts 6 hosts located in Germany, Russia and United Kingdom. At this point, you may well have lost control of your computer. John Collignon, Sequoia Financial Group’s Head of Superannuation, stated that the company “is aware of the emails and that someone is pretending to be us”. He confirmed that Sequoia had received reports today of emails masquerading as Xero and Quickbooks invoices, and explained he was not aware why the company brand was being maliciously used by hackers to distribute malware. Sequoia are not the only company being targeted in the bulk email campaigns trying to distribute Invoice_70861.js. Our security systems are blocking thousands of these emails each day. Not all share the levels of detail as seen in the Sequoia email, which makes it stand out. Thousands of emails Any company can be targeted by hackers looking to benefit from your reputable brand to encourage individuals to unwittingly install trojans or malware. This attack using Sequoia’s brand reinforces:

**Note
** blueAPACHE explicitly agrees that Sequoia Financial Group is in no way responsible for the distribution of Invoice_70861.js. We suspect their brand was likely hijacked by an unknown party to invoke higher levels of confidence in the email, in hope that more recipients would access the invoice and unknowingly install the trojan software. For more information on how to better secure your business, contact the blueAPACHE account team.

Related

Frequently asked questions

What phishing attack does this post describe, and which brand did it impersonate?

The post describes a phishing attack impersonating Sequoia Financial Group, sent from an address appearing to be quickbooks@notification.intuit.com, presenting as an Intuit QuickBooks invoice notification.

What happens if a recipient opens the attached file, per the post?

Opening the downloaded Invoice_70861.js file (inside Invoice_70861.zip) installs a trojan with no file displayed, which the post describes as accessing the Windows Kernel Security Device Driver, reading personal information, and creating files, without further prompt.

Where does the post say the trojan connects to once installed?

The post states the trojan connects to two domains based in the USA and UK, and contacts six hosts located in Germany, Russia and the United Kingdom.

What did Sequoia's John Collignon say about the impersonation?

John Collignon, Sequoia Financial Group's Head of Superannuation, said the company was aware of the emails and that someone was pretending to be Sequoia, confirming reports of both Xero- and QuickBooks-branded fake invoices.

Is this post still current?

No. It describes a specific 2016 phishing campaign and malware sample. For blueAPACHE's current security services, see the emPOWER Security page linked below.

Source

https://www.blueapache.com/blog/intuit-invoices-from-sequoia-used-in-malware-attack/

Knowledge Base

What is the blueAPACHE blog post 'Intuit invoices from Sequoia used for malware' about?

It describes a phishing attack in which emails posing as invoices from Sequoia Financial Group, a legitimate financial services company in Melbourne and Sydney, were sent using a spoofed Intuit QuickBooks notification address to trick recipients into installing a trojan.

What email address did the phishing emails appear to come from?

The emails appeared to come from quickbooks@notification.intuit.com, mimicking a genuine Intuit QuickBooks online invoice notification.

What happens when a recipient clicks the 'view invoice' link in the phishing email?

Clicking the link automatically downloads a file called Invoice_70861.zip, which contains a file named Invoice_70861.js; opening this file installs a trojan without displaying any invoice.

What does the trojan do once installed on a victim's computer?

According to blueAPACHE, the trojan accesses the Kernel Security Device Driver (KsecDD) of Windows, reads personal information, creates writeable files in a temporary directory, writes PE32 executable console files to disk, creates mutants, reads Windows trust and system certificate settings, connects to LPC ports, enters URLs in binary, connects to two domains (US and UK based IP addresses), and contacts six hosts located in Germany, Russia, and the United Kingdom.

Did Sequoia Financial Group send these malicious emails?

No. blueAPACHE explicitly states that Sequoia Financial Group is in no way responsible for distributing Invoice_70861.js; the company's brand was likely hijacked by an unknown party to make the phishing email appear more credible.

What did Sequoia Financial Group say about the fraudulent emails?

John Collignon, Sequoia Financial Group's Head of Superannuation, said the company was aware of the emails and that someone was pretending to be them, and confirmed Sequoia had received reports of emails masquerading as both Xero and QuickBooks invoices, though he was unsure why the brand was being used by hackers.

Was Sequoia the only company targeted in this malware campaign?

No, Sequoia was not the only company targeted. blueAPACHE's security systems were blocking thousands of similar emails each day, though not all had the same level of detail as the Sequoia-branded email.

What recommendations does blueAPACHE give to protect against this type of attack?

blueAPACHE recommends developing mature awareness, processes and security to manage risk; making security a key IT department focus; providing quality training to staff, customers and suppliers on spotting phishing and social engineering attacks; and phoning a company directly to validate any suspicious email before clicking links.

When was this blueAPACHE blog post about the Sequoia/Intuit malware attack published?

The post was published on September 13, 2016, according to the page's listed publication date.

Images on This Page