Online Threat Alerts (OTA) - Alerting you to scams and frauds.

.JAR Java Archive Virus Email Message Attachments
.JAR Java Archive Virus Email Message Attachments

Online users, do not open email attachments with file extensions or names ending with ".jar". This is because cybercriminals are sending out fake emails to potential victims with a malicious Java file (.jar) attached. The fake emails have a deceptive message, which instructs the recipients to open the same attached malicious Java file. But, any attempts to open the attached malicious ".jar" file will result in the recipients' computers getting infected with a virus, spyware, ransomware or other malware. Therefore, online users are asked not to open email attachments with names ending with ".jar", even if the email messages appear to have been sent from someone they know, or a legitimate organization

A Sample of an Email with a Malicious “.jar” File Attached

an Email with a Malicious “.jar” Attachment

"SCAN COPY PDF...1001.jar"

The malicious attachment (.jar) contains a malware called “Backdoor:Java/Adwind” that installs a malicious component or codes onto your computer, which opens a backdoor on it. Once the backdoor is open on your computer, the cybercriminals behind the malicious email message will be able to access your computer silently, infect your computer with other malware, steal your information, and may use your computer to commit other cybercrimes that will be traced back to your computer. If this should happen to you, do not be surprised if one day you see the police at your doorsteps with a warrant to search your home and confiscate your computer, because some form of online criminal activities, which you know nothing about, were traced back to your location and computer.

Most antivirus software will detect and remove the malicious attachment before it infects your computer. But, the smart thing to do, is to delete the email message.

Online users who have received the fake email messages and have been tricked into opening the malicious “.jar” attachment are asked to do a full scan of their computers with their antivirus software.

Related article:

19

Comment sectionComments / Answers (19)

Remove sensitive information from your post. Your IP address will be used to display your estimated location.

Comment count 19

by info

Here is another malicious email:

------ Forwarded Message
From: April Leal
Date: Thu, 23 Nov 2017 18:42:58 0200
To: me
Subject: FW: Purchase Order 22344E from Barclay Butera Inc. - NB

Delete


by info

Here is another malicious attachment:

"From: AthAA
To: All Faculty and Staff
Subject: IMPORTANT
Please refer to the attachment carefully
Thank you
Attachment: Payment_Invoice.JAR"

Delete


by info

Here is another scam:

"Subject: Inquiry T09824
Date: Thu 21/09/2017 03:00
From: "B.hrain Stephen"
To: undisclosed-recipients:
Attachment: T09824_PTRl.pdf Terms.jpg.jar 497 KB

Dear Sir

Please kindly find the attached and quote us your best price ASAP.

NOTE: Include our order number in your quotation.

Best Regards...

B.hrain

Senior Engineer
PRTRO-LINE GLOBAL CO. LTD
UNIT1, Samiullah, Vasai, India
Tel: 918950598722
FAX: 9189504723/4"

Delete


by info

Received via email:

"The file "I left this for you.pdf.jar" is on all the disk drives of one of my computers, including the pen drive. When I delete the file, it takes 5 seconds and it comes back again. I opened the file through Winrar and found it to be a malicious program. I've already tried antivirus and Google search and got no results. I'll send the file for you to review.
I hope you can help me.

Thank you very much!
Best regards
Gildicley"


--- ----
Start the computers in Safe Mode and then scan them for viruses. Or, if you have Avast antivirus, use their Boot-Time scan.

Delete


by info

Here is another malicious email:

"Re: Re: CHEQUE PAYMENT
Mon 18/09/2017 06:35
From: ACCOUNTANT
Attachment: CHEQUE READY.jar

DEAR SIR,

PLEASE KINDLY COLLECT YOUR PAYMENT AS PER ATTACHMENT CHEQUE.

confirm mentioned account number with IBAN number OK.

Thank you,
Best regards
Azad abdul
Account Manager
Traffic Control Center
Tel : 33849994
: 70083195"

Delete



by an anonymous user from: Toledo, Ohio, United States

Scammers address 2500 terrace ave. In California they email me saying they were from CC company. Can't find an address for the true company. Google map it.

Delete


by info

Here is another malicious email:

-- start of scam --
Subject: PO 605-D382
Date: Wed 30/08/2017 22:06
From: "Kang Wooyoung"
Attachment: PO 605-D382.jar (554 KB)

Dear Sir,

Please we want to make new order for the enclosed products
Kindly find attached our purchase order and give us your current available product price list,

Best FOB Prices with clear photos of your latest catalog, Payment term ( LC or TT ), MOQ & ETD.
Also put into consideration time as I will want this products delivered Ending of next month latest.

Awaiting your prompt response, please.

Thank and Best Regards,

Kang Wooyoung

Sales Manager

Office: 17-1-4 U Ghe Street, Tam Phu Wards,
Thu Duc Dist. Ho Chi Minh City
Tel: 08.2218.1960 - 08.2229.1970 -
Fax: 08.5422.4738
kang.wooyoung-gmail.com
Web: www.inminhlang.com

Delete


by info

Here is another malicious email:

"Subject: PURCHASE ORDER
Attachment: attached Purchase order.jar

Dear sir/ Madam,

Pleasure to book for the attached Purchase order,

Kindly send us order confirmation without delay indicating the following as clearly specified in our order.

Can you please provide us with your proforma Invoice and transaction sheet for the required payment.

If we place this order within this month, Please confirm to us your arrangement & supply the material to our project site.

Thanks & Regards,
Nadim Mulla
Purchase Department
[Inline image URL : ]

D One Marine LLC T: 971 4 4426395 Ext.108 F: 971 4 4426895 M: 971 559353417 QQ 2032766852

P.O. Box 64464 Loc: WS#110,Dubai Maritime City,Dubai UAE purchase3-d1marine.co www.d1marine.com"

Delete


by an anonymous user from: Wellington, New Zealand

This is a question... If you download a popular .jar file that a lot of famous you-tubers have opened and installed is there still a chance that it could have a virus?

Thanks

Delete


by info

Not all .jar files are viruses. Therefore, download the file, go to www.virustotal.com, upload the file to the same website and scan it for viruses. After scanning, the website will tell you if the file is malicious or not.

Delete


by an anonymous user from: Chennai, Tamil Nadu, India

May I know from where can I get sample .jar malware? From where can I download them? I need to analyse them in a virtual environment as part of my learning. Any help would be really helpful.

Delete


by an anonymous user from: Kuala Lumpur, Wilayah Persekutuan, Malaysia

My colleague just got one today and she is so scared. She sent to me and asked me to have a look. I asked her to delete and ignore it.

"Attachment: lawsuit file document.jar

Subject: URGENT (Vessel Arrest on court Order).
Date: Thu, 6 Jul 2017 06:54:59 0600 (BDT)
From: KudrI & Djamaris
Reply-To: office-kndlawyers.com

Dear Sir,

We have been appointed to proceed with legal steps in arresting your vessel due to your inability to clear your long overdue payment with our client. Our client claims that several reminder has been sent to you on this subject matter without getting any response from you.

Find attached lawsuit filed by our client including Court and lawyer cost. Kindly review and revert with your comment. Meanwhile, vessel will be arrested by the court till further notice.

Your urgent response will be appreciated.

THANK YOU AND BEST REGARDS

KudrI & Djamaris
Attorneys - Counsellor at Law
Mayapada Tower 5th floor
Jl. Jend. Sudirman Kav.28,
Jakarta 12920, Indonesia
Telephone.: 62 21 522 5453
Fax.: 62 21 522 5452
Email.: office-kndlawyers.com"

Delete


by an anonymous user from: Cardiff, Wales, United Kingdom

Got one of these today:

"Attachment New Order. jar (590kb)

Dear Sir

I have called your office phone but cannot connect to you, could you please look into the attached New Order immediately and then arrange to send us proforma invoice.

Awaiting your swift response.

Best Regards

Assem Abdulsalam
Head of Middle East
Ascensia Diabetes Care
P.O. Box 02 Jeddah 21411
KSA
Phone: 966 12 660 4757
Cell: 966 505 646969"

Needless to say I marked it as Spam without opening it.

Delete


by info

Here is another malicious email:

"Subject: Urgent Order
Date: Tue 06/06/2017 21:48
From: ag.kum.aiguo-qq.com
Attachment: FOB.pdf.jar (473 KB)

Dear We have emailed your company a week ago about our interested in your products and we have not heard from your company. I hope all is well with you, Please quote your best prices on FOB as attached

Please kindly send us your catalog.
Best Regards
Mr. Chiang Lin (Manager)
Taiwan Semiconductor Manufacturing Company Limited
ag.kum.aiguo-qq.com, ag.kum.aiguo-outlook.com
skype: Chiang Lin"

Delete


by info

Here is another malicious email:

-- start of malicious email --
"Subject: Purchase Contract/ PON02017/072/
Date: Mon 05/06/2017 04:07
From: Beatriz Salazar
Attachments: PO201(07).zip 574 KB

Dear Sir,

How are you?
I attach the approved proforma of our order PON02017/072/
please quote FOB to Port of St. Petersburg Russia 4x 20ft FCL
I await your reply.

Thanks you.
Beatriz Salazar
Megapolis Group
Corporate Head Office Russia
27 Kalanchevskaya Street
Moscow 107078
Russian Federation

Tel. 7 495 620-91-91
7 495 974-25-15
Telex 412089 ALFARU
Fax: 7 (495) 642 9828
e-mail: dbtc.career-db.com
-- end of malicious email --

Delete


by info

Here is another malicious email message:

"Subject: proforma invoice
Sun 04/06/2017 23:42
From: Customer Account Executive - CS
Attachments: PROFORMAL INVOICE.jar 501 KB

Kindly send us order confirmation without delay indicating the following as clearly specified in our order.

Can you please provide us with your Proforma Invoice and transaction sheet for the required payment.

If we place this order within this month, Please confirm to your arrangement & supply the material to our project site.

Best Regards

Senior Project Engineer And Sales Engineer
Awaiting for your favorable feedback.
If there is any clarification please feel free to contact me."

Delete


by info

Here is another scam:

"From: Linn Beckler
Sent: 31 May 2017 17:58
Attachment: COURT CASE DETAILED BRIEFING30-05-2017_obfuscated.jar
Subject: Re: Court Case #129 Ref No #763722

Hello Good Day,

A COURT CASE has been established against you on Tuesday 30th May, 2017 by the housing agency.
Find the attached for the detail and contact your Lawyer immediately.

Yours,
Bar. Linn Beckler"

Delete


by info

Here is another malicious email:

"Subject: Urgent Order
Date: Wed 31/05/2017 03:48
From: ag.kum.aiguo-qq.com
Attachment: FOB.pdf.jar 473 KB

Dear
We have emailed your company a week ago about our interested in your products and we have not heard from your company.
I hope all is well with you, Please quote your best prices on FOB as attached Please kindly send us your catalog.

Best Regards Mr. Chiang Lin (Manager)
Taiwan Semiconductor Manufacturing Company Limited
ag.kum.aiguo-qq.com, ag.kum.aiguo-outlook.com skype: Chiang Lin"

Delete


by info

Here is a fake email message with a malicious .jar file:

"Subject: Time Sheet and Security Sign on Sheet
Date: Sun 23/04/2017 19:50
From: AIG Security Group

Good morning

Please find attached the Time sheet for week 05.04.2017-11.04.2017 and security sign sheet.

Thank You

Janise Coleman
AIG Security Group

Address: 184 Grange Rd, Fairfield
VIC 3078, Australia
Phone: 61 1300 600 578"

Delete


waiting