{"id":73,"date":"2022-12-02T18:04:06","date_gmt":"2022-12-02T18:04:06","guid":{"rendered":"https:\/\/freshphish.info\/?p=73"},"modified":"2024-02-11T20:06:43","modified_gmt":"2024-02-12T01:06:43","slug":"getting-malware-past-email-filter","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=73","title":{"rendered":"Getting Malware Past Email Filter"},"content":{"rendered":"\n<p>In every email environment I&#8217;ve managed, one of the first things I do if it&#8217;s not already done is set up a rule to block all email attachments that are executable. If it&#8217;s a .exe, .bat, .com or any other file extension that is executable, it is blocked. In addition the file-type of .iso, which is a disk image file, is blocked. These can be treated similarly to compressed or .zip files in that they are a container for other files but I&#8217;ve never seen one sent by email for a legitimate purpose. No one should be sending executable attachments these days. If you need to send one, I&#8217;m sure you are smart enough to find a way to get it to your intended recipient.<\/p>\n\n\n\n<p>In this case, a malicious actor found a way to get an executable attachment passed an email filter. How? By sending an html file attachment with a .zip file encoded in it which is automatically &#8220;downloaded&#8221; by the web browser. The browser does not reach across the network\/Internet to get the zip file. It is encoded in the html. One example shows clearly the file name the zip file is given. The other has the operation completely obfuscated and names the file a random filename, as can be shown in the screen captures below.<\/p>\n\n\n\n<p>Once the html file is opened using a web browser, the file is automatically downloaded and the user can click on it to open it. Once opened, it displays a .iso disk image file. Another example generates a .vhd or virtual hard disk file used by Windows virtual machines. If the resulting file is opened, it provides a folder and several files. If the main file that looks to be the one the victim is &#8220;supposed to&#8221; open, it executes a Powershell script, pulls in data from a base64 encoded file found in the folder structure and writes a binary file that is then executed using Windows built-in rundll.exe.<\/p>\n\n\n\n<p>I did not run forensics to determine what the malware is attempting to do. I am most fascinated by the way the malicious actor got the files past the email gateway. The good news is that the only people that would be capable of actually extracting and running the malware would be those very knowledgeable in information technology and one would think they&#8217;d also be smart enough to NOT do this outside of a well-controlled environment.<\/p>\n\n\n\n<p>Here is an animation of opening the malware.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1355\" height=\"800\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/openinghtmlattachment.gif\" alt=\"\" class=\"wp-image-74\"\/><figcaption class=\"wp-element-caption\"> Animation of the opening of the malicious html file and examination of the resulting files.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"614\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/recognizable0ccasionally-1024x614.jpg\" alt=\"\" class=\"wp-image-75\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/recognizable0ccasionally-1024x614.jpg 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/recognizable0ccasionally-300x180.jpg 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/recognizable0ccasionally-768x461.jpg 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/recognizable0ccasionally.jpg 1250w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">The malware created the text file shown below the list of folders in the public profile folder.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"511\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/recognizable0ccasionallycontents-1024x511.jpg\" alt=\"\" class=\"wp-image-76\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/recognizable0ccasionallycontents-1024x511.jpg 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/recognizable0ccasionallycontents-300x150.jpg 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/recognizable0ccasionallycontents-768x383.jpg 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/recognizable0ccasionallycontents.jpg 1253w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Here are the contents of the binary .txt file.<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"508\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/sepdetectedit-1024x508.jpg\" alt=\"\" class=\"wp-image-77\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/sepdetectedit-1024x508.jpg 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/sepdetectedit-300x149.jpg 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/sepdetectedit-768x381.jpg 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/sepdetectedit.jpg 1247w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Symantec Endpoint Protection detected the html file as malicious.<\/figcaption><\/figure>\n\n\n\n<p>&#8211;Matt<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In every email environment I&#8217;ve managed, one of the first things I do if it&#8217;s not already done is set<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=73\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">Getting Malware Past Email Filter<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[29,28,27,4],"class_list":["post-73","post","type-post","status-publish","format-standard","hentry","category-phish","tag-html-file","tag-iso-file","tag-malware","tag-phish"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.9 - aioseo.com -->\n\t<meta name=\"description\" content=\"In every email environment I&#039;ve managed, one of the first things I do if it&#039;s not already done is set up a rule to block all email attachments that are executable. If it&#039;s a .exe, .bat, .com or any other file extension that is executable, it is blocked. In addition the file-type of .iso, which\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Matt\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/freshphish.info\/?p=73\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.9\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Fresh Phish - All the freshest phish\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Getting Malware Past Email Filter - Fresh Phish\" \/>\n\t\t<meta property=\"og:description\" content=\"In every email environment I&#039;ve managed, one of the first things I do if it&#039;s not already done is set up a rule to block all email attachments that are executable. If it&#039;s a .exe, .bat, .com or any other file extension that is executable, it is blocked. In addition the file-type of .iso, which\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/freshphish.info\/?p=73\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-12-02T18:04:06+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-02-12T01:06:43+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Getting Malware Past Email Filter - Fresh Phish\" \/>\n\t\t<meta name=\"twitter:description\" content=\"In every email environment I&#039;ve managed, one of the first things I do if it&#039;s not already done is set up a rule to block all email attachments that are executable. If it&#039;s a .exe, .bat, .com or any other file extension that is executable, it is blocked. In addition the file-type of .iso, which\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=73#blogposting\",\"name\":\"Getting Malware Past Email Filter - Fresh Phish\",\"headline\":\"Getting Malware Past Email Filter\",\"author\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/freshphish.info\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/openinghtmlattachment.gif\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=73\\\/#articleImage\",\"width\":1355,\"height\":800},\"datePublished\":\"2022-12-02T18:04:06-05:00\",\"dateModified\":\"2024-02-11T20:06:43-05:00\",\"inLanguage\":\"en-US\",\"commentCount\":1,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=73#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=73#webpage\"},\"articleSection\":\"Phish, html file, iso file, malware, phish\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=73#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/freshphish.info\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=12#listItem\",\"name\":\"Phish\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=12#listItem\",\"position\":2,\"name\":\"Phish\",\"item\":\"https:\\\/\\\/freshphish.info\\\/?cat=12\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=73#listItem\",\"name\":\"Getting Malware Past Email Filter\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=73#listItem\",\"position\":3,\"name\":\"Getting Malware Past Email Filter\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=12#listItem\",\"name\":\"Phish\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\",\"name\":\"Fresh Phish\",\"description\":\"All the freshest phish\",\"url\":\"https:\\\/\\\/freshphish.info\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\",\"url\":\"https:\\\/\\\/freshphish.info\\\/?author=1\",\"name\":\"Matt\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=73#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/82f14a734f69eb729d8b59b4a2438ea6e14bd793d23b22d4299ec5228b06260a?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Matt\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=73#webpage\",\"url\":\"https:\\\/\\\/freshphish.info\\\/?p=73\",\"name\":\"Getting Malware Past Email Filter - Fresh Phish\",\"description\":\"In every email environment I've managed, one of the first things I do if it's not already done is set up a rule to block all email attachments that are executable. If it's a .exe, .bat, .com or any other file extension that is executable, it is blocked. In addition the file-type of .iso, which\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=73#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"datePublished\":\"2022-12-02T18:04:06-05:00\",\"dateModified\":\"2024-02-11T20:06:43-05:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/#website\",\"url\":\"https:\\\/\\\/freshphish.info\\\/\",\"name\":\"Fresh Phish\",\"description\":\"All the freshest phish\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Getting Malware Past Email Filter - Fresh Phish","description":"In every email environment I've managed, one of the first things I do if it's not already done is set up a rule to block all email attachments that are executable. If it's a .exe, .bat, .com or any other file extension that is executable, it is blocked. In addition the file-type of .iso, which","canonical_url":"https:\/\/freshphish.info\/?p=73","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/freshphish.info\/?p=73#blogposting","name":"Getting Malware Past Email Filter - Fresh Phish","headline":"Getting Malware Past Email Filter","author":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"publisher":{"@id":"https:\/\/freshphish.info\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/freshphish.info\/wp-content\/uploads\/2022\/12\/openinghtmlattachment.gif","@id":"https:\/\/freshphish.info\/?p=73\/#articleImage","width":1355,"height":800},"datePublished":"2022-12-02T18:04:06-05:00","dateModified":"2024-02-11T20:06:43-05:00","inLanguage":"en-US","commentCount":1,"mainEntityOfPage":{"@id":"https:\/\/freshphish.info\/?p=73#webpage"},"isPartOf":{"@id":"https:\/\/freshphish.info\/?p=73#webpage"},"articleSection":"Phish, html file, iso file, malware, phish"},{"@type":"BreadcrumbList","@id":"https:\/\/freshphish.info\/?p=73#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/freshphish.info#listItem","position":1,"name":"Home","item":"https:\/\/freshphish.info","nextItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=12#listItem","name":"Phish"}},{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=12#listItem","position":2,"name":"Phish","item":"https:\/\/freshphish.info\/?cat=12","nextItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?p=73#listItem","name":"Getting Malware Past Email Filter"},"previousItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?p=73#listItem","position":3,"name":"Getting Malware Past Email Filter","previousItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=12#listItem","name":"Phish"}}]},{"@type":"Organization","@id":"https:\/\/freshphish.info\/#organization","name":"Fresh Phish","description":"All the freshest phish","url":"https:\/\/freshphish.info\/"},{"@type":"Person","@id":"https:\/\/freshphish.info\/?author=1#author","url":"https:\/\/freshphish.info\/?author=1","name":"Matt","image":{"@type":"ImageObject","@id":"https:\/\/freshphish.info\/?p=73#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/82f14a734f69eb729d8b59b4a2438ea6e14bd793d23b22d4299ec5228b06260a?s=96&d=mm&r=g","width":96,"height":96,"caption":"Matt"}},{"@type":"WebPage","@id":"https:\/\/freshphish.info\/?p=73#webpage","url":"https:\/\/freshphish.info\/?p=73","name":"Getting Malware Past Email Filter - Fresh Phish","description":"In every email environment I've managed, one of the first things I do if it's not already done is set up a rule to block all email attachments that are executable. If it's a .exe, .bat, .com or any other file extension that is executable, it is blocked. In addition the file-type of .iso, which","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/freshphish.info\/#website"},"breadcrumb":{"@id":"https:\/\/freshphish.info\/?p=73#breadcrumblist"},"author":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"creator":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"datePublished":"2022-12-02T18:04:06-05:00","dateModified":"2024-02-11T20:06:43-05:00"},{"@type":"WebSite","@id":"https:\/\/freshphish.info\/#website","url":"https:\/\/freshphish.info\/","name":"Fresh Phish","description":"All the freshest phish","inLanguage":"en-US","publisher":{"@id":"https:\/\/freshphish.info\/#organization"}}]},"og:locale":"en_US","og:site_name":"Fresh Phish - All the freshest phish","og:type":"article","og:title":"Getting Malware Past Email Filter - Fresh Phish","og:description":"In every email environment I've managed, one of the first things I do if it's not already done is set up a rule to block all email attachments that are executable. If it's a .exe, .bat, .com or any other file extension that is executable, it is blocked. In addition the file-type of .iso, which","og:url":"https:\/\/freshphish.info\/?p=73","article:published_time":"2022-12-02T18:04:06+00:00","article:modified_time":"2024-02-12T01:06:43+00:00","twitter:card":"summary_large_image","twitter:title":"Getting Malware Past Email Filter - Fresh Phish","twitter:description":"In every email environment I've managed, one of the first things I do if it's not already done is set up a rule to block all email attachments that are executable. If it's a .exe, .bat, .com or any other file extension that is executable, it is blocked. In addition the file-type of .iso, which"},"aioseo_meta_data":{"post_id":"73","title":null,"description":null,"keywords":[],"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":[],"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2022-12-02 18:04:07","updated":"2025-06-04 04:43:01","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/freshphish.info\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/freshphish.info\/?cat=12\" title=\"Phish\">Phish<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tGetting Malware Past Email Filter\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/freshphish.info"},{"label":"Phish","link":"https:\/\/freshphish.info\/?cat=12"},{"label":"Getting Malware Past Email Filter","link":"https:\/\/freshphish.info\/?p=73"}],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/73","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=73"}],"version-history":[{"count":2,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/73\/revisions"}],"predecessor-version":[{"id":79,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/73\/revisions\/79"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=73"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=73"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=73"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}