Well that’s what it looks like. Criminals apparently from Bangalore have been distributing loads of malware spams from addresses like Nich***.Davi**.5208@vosa.gsi.gov.uk, and they’re getting through spam filters.
The messages continue:
Subject: DVSA RECEIPT Good afternoon Please find attached your receipt, sent as requested. Kind regards (See attached file) Fixed Penalty Office Driver and Vehicle Standards Agency | The Ellipse, Padley Road, Swansea, SA1 8AN Phone: 0300 123 9000 Find out more about government services at www.gov.uk/dvsa ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. Any views or opinions presented may be those of the originator and do not necessarily represent those of DVSA. If you were not the intended recipient, you have received this email and any attached files in error; in which case any storage, use, dissemination, forwarding, printing, or copying of this email or its attachments is strictly prohibited. If you have received this communication in error please destroy all copies and notify the sender [and postmaster@dvsa.gsi.gov.uk ] by return email. DVSA's computer systems may be monitored and communications carried on them recorded, to secure the effective operation of the system and for other lawful purposes. Nothing in this email amounts to a contractual or other legal commitment on the part of DVSA unless confirmed by a communication signed on behalf of the Secretary of State. It should be noted that although DVSA makes every effort to ensure that all emails and attachments sent by it are checked for known viruses before transmission, it does not warrant that they are free from viruses or other defects and accepts no liability for any losses resulting from infected email transmission. Visit www.gov.uk/dvsa for information about the Driver Vehicle and Standards Agency. ********************************************************************* The original of this email was scanned for viruses by the Government Secure Intranet virus scanning service supplied by Vodafone in partnership with Symantec. (CCTM Certificate Number 2009/09/0052.) This email has been certified virus free. Communications via the GSi may be automatically logged, monitored and/or recorded for legal purposes.
This all looks pretty genuine – they probably copied it verbatim with the exception of the “good afternoon”.
The payload is a Microsoft Word document with macros, but I’ve yet to figure out exactly what it’s doing. In the parlance of the security “industry” it’d be a zero-day exploit, but that’s not interesting. What did come as a bit of a surprise to me is that GSI doesn’t seem to bother with SPF records, which would have helped detect the fake. Bayesian analysis throws up nothing, and it’s coming from a clean IP address that has yet to be listed. The only things wrong with it are that there’s no reverse lookup, and no SPF on vosa.gsi.gov.uk to flag it as dodgy.
The civil service clearly hasn’t got this security business clear yet.