"CAETANO FORMULA" Email Scam Uses Unimpressive Bait
A new scam is being distributed using malicious spam emails. The name given to it is the "CAETANO FORMULA" scam.
The malicious emails are used to spread the Agent Tesla remote access trojan. The malicious file is attached to the email, posing as a purchase order.
The email asks victims to "please confirm the new order and quote", and is tailored to appear as though it's sent by Caetano Formula - a legitimate representative of Dacia and Renault in Europe.
The malicious file observed in one instance of the malicious emails was called "New Order#124589#.gz". The string of numbers used may vary across different emails. The malware is contained inside the archive .gz file.
Agent Tesla, the payload inside the malicious attachment, behaves a lot like an info stealer and can steal data from various software clients, as well as log keystrokes.
The full text of the scam email goes as follows:
Subject: New Order#124589#
Dear Sir,
Please Confirm The New Order and Quote.
Thanks!
gaia
Sales manager
CAETANO FORMULA (GAIA)
Baviera Building - Rua do Barreiro,
547 - Madalena 4405-730 Vila Nova De Gaia Porto
Official Service Appointment: 808 919 962
Parts: 910 086 855
General: 223 777 850
Email: gaia at caetanoformula dot pt
hxxps://www.caetanoformularenault.pt/