Fake email Adobe Invoice, regarding an Adobe Creative Cloud Service invoice, contains trojan

MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject “Adobe Invoice” which is quite similar to a previous malicious campaign but in that case a Word document was used.

This email is send from the spoofed address “Adobe Billing <billing@adobe.com>” and has the following body:

Dear Customer,

Thank you for signing up for Adobe Creative Cloud Service.

Attached is your copy of the invoice.
Thank you for your purchase.

Thank you,
The Adobe Team
Adobe Creative Cloud Service


The attached ZIP file has the name adb-102288-invoice.zip and contains the 117 kB large file c3.exe.

The trojan is known as PE:Malware.FakePDF@CV!1.9C3A or Win32.Trojan.Inject.Auto.

At the time of writing, 2 of the 53 AV engines did detect the trojan at Virus Total so be careful when handling this email.

Use the Virus Total permalink for more detailed information.
SHA256: 39475a931af23d7d61e2898bcd2e5f69f8e6770848a306980ea8ef6dcfc2bc08