MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject “Re:grzywna”.
This email is send from the spoofed addresses from the domain vp.pl and has an empty email body.
The attached file grzywna 26.12.2014_kopią_doc contains the 106 kB large file grzywna 26.12.2014_kopią_doc.
The trojan is known as Win32.Trojan.Inject.Auto
At the time of writing, 1 of the 56 AV engines did detect the trojan at Virus Total.