Last weekend McAfee observed scams spread across the world that claimed to have come from Visa Customer Services. The mail had the subject “Your credit card has been blocked – Central European (ISO).”

Scam mail
- ups_invoice_id865165475837266465.doc________________.exe (UPS Scam)
- mastercard_invoce_id65729217565333.doc________________.exe
- visa_complete_nr62178865627245.doc________________.exe
The dropped malware randomly chooses the rogue AV payload (XP Security 2012 or Personal Shield Pro, to name two) from the remote server. McAfee products detect these payloads as FakeAlert-AB.dldr.

Unlike earlier variants, these binaries did not have the icon of a document file, so they were not covert enough to hide from users. Our cloud-based Artemis technology revealed that this scam was a global target.
The figure below from Artemis shows this malware has spread across the world.

All McAfee customers are protected against this malware. McAfee Labs reminds the public to pursue safe email practices.
By: Arun Pradeep