Fake email from Stanford Health Care contains trojan Upatre.GK


MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subjects like:

check out
Health Care
Impotant
Special offer
Stanford Medecine

This email is send from different spoofed address and has the following body:

see attachment.

Jessica Epstein
Office Assistant IV
Stanford Health Care
1190 Welch Road, MC 5794 • Palo Alto, CA 94304
O: 650.736.1944 C: 650.847.0495
jepstein@stanfordhealthcare.org

The attached file is named:

Standford_service_data.zip
Standford_department_data.zip
Standford_special_information.zip
Customer_department_offer.zip

The Zip file contains the 21 kB large executable with the same name as the ZIP file.

The trojan is known as Upatre.GK  or Trojan.Win32.YY.Gen.7.

At the time of writing, 2 of the 57 AV engines did detect the trojan at Virus Total.

Use the Virus Total or Malwr for more detailed information.
SHA256: 5da21bd031ae19d0ebd95d9b18fb1d565ed2537c551bc85195e77b747f082520

One thought on “Fake email from Stanford Health Care contains trojan Upatre.GK

Comments are closed.