{"id":72547,"date":"2011-07-26T11:24:15","date_gmt":"2011-07-26T11:24:15","guid":{"rendered":"https:\/\/localhost\/wordpress\/?p=72547"},"modified":"2011-07-26T11:24:15","modified_gmt":"2011-07-26T11:24:15","slug":"irs-notification-letter-email-scam","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/irs-notification-letter-email-scam\/","title":{"rendered":"IRS Notification Letter Email scam"},"content":{"rendered":"<p>The <strong>Chepvil<\/strong> malware which comes via email as an attachment is using another trick to spread itself. You may receive an email stating to be from IRS.gov and with the subject line &#8211; &#8220;IRS Notification Letter&#8221;. The email is as shown below:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/1_irs.jpg\" alt=\"\" width=\"597\" height=\"473\" \/><\/p>\n<p>The attachment comes with the name &#8216;IRS document.rar&#8217;. Upon extraction, the user gets an executable file with a PDF file icon.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/2_irs.jpg\" alt=\"\" width=\"142\" height=\"146\" \/><\/p>\n<p>If a user opens this executable file, it then downloads one of these files &#8211; &#8216;pusk.exe&#8217;\/&#8217;pusk2.exe&#8217;\/&#8217;pusk3.exe&#8217;. As we can see from the http traffic:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/3_irs.JPG\" alt=\"\" width=\"744\" height=\"35\" \/><\/p>\n<p>The file pusk*.exe works as a rogueware application <strong>Windows XP Repair<\/strong> as shown below:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/4_irs1.JPG\" alt=\"\" width=\"580\" height=\"343\" \/><\/p>\n<p>As usual, it displays fake threat messages on the screen and thus forces the user to register the product in order to remove these fake threats.<\/p>\n<p>If you come across such emails do not open the attachments with them. Instead, delete them and keep your antivirus updated. <a href=\"https:\/\/www.quickheal.com\/\">Quick Heal<\/a> detects the malicious attached file as <strong>Trojan.Chepvil.K<\/strong> and also blocks the domain. So our users are already protected.<br \/>\nWe recommend that users do not open such attachments from unknown and suspicious looking emails.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/archive\/5_irs.JPG\" alt=\"\" width=\"297\" height=\"178\" \/><\/p>\n<p>Thanks Mahesh. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Chepvil malware which comes via email as an attachment is using another trick to spread itself. You may receive an email stating to be from IRS.gov and with the subject line &#8211; &#8220;IRS Notification Letter&#8221;. The email is as shown below: The attachment comes with the name &#8216;IRS document.rar&#8217;. Upon extraction, the user gets [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21,24],"tags":[22,23,39,26,40],"class_list":["post-72547","post","type-post","status-publish","format-standard","hentry","category-email","category-malware","tag-email-malware","tag-fraudulent-email","tag-irs","tag-rogueware","tag-trojan"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/72547"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=72547"}],"version-history":[{"count":0,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/72547\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=72547"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=72547"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=72547"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}