The malicious email itself is a copy and paste of a legitimate email from Blackberry. And though the attachment indeed raises suspicion, there's no malicious or compromised URL in it. 17/36 AV engines identify the malware in VirusTotal.
ThreatScope analysis, which is a part of the Websense CSI service, reports that running the attachment drops other executable files and modifies the system registry to automatically start these malware programs when the system starts.
Author: Mary Grace Timcang, Websense.
Reading our newsletter every Monday will keep you up-to-date with security news.
Receive a daily digest of the latest security news.