From: Electronic Payments Association [mailto:email@example.com]
Sent: 12 November 2009 14:58
Subject: Please review the transaction report
Dear bank account holder, The ACH transaction, recently initiated from your bank account (by you or any third party), was rejected by the Electronic Payments Association. Please review the transaction report by clicking the link below:
Unauthorized ACH Transaction Report
Copyright ©2009 by NACHA - The Electronic Payments Association
The underlying link goes to nacha.org.fffazsf.org.uk which is itself hosted on some sort of Fast Flux botnet. The landing page attempts to get a user to download report.exe ( a Zbot variant). It also opens an IFRAME to 220.127.116.11 in China, a well-known malware domain.
VirusTotal shows patchy detections, still being analysed by ThreatExpert.
The domain name registration is obviously fake:
Domain name: fffazsf.org.ukDig deeper at pa-estate.com and we see a familiar email address:
Registrant: Matthew Hughes
Registrant type: Non-UK Individual
Registrant's address: 203 Striding Ridge Drive Goldsboro 3881 Belgium
Registrar: Webfusion Ltd t/a 123-Reg.co.uk [Tag = 123-REG]
Registered on: 12-Nov-2009
Renewal date: 12-Nov-2011
Last updated: 12-Nov-2009
Registration status: Registration request being processed.
Name servers: ns1.pa-estate.com ns1.tradesdomains.net
Name : Michell
Organization : Michell
Address : 8663 Sudley Road
City : Manassas
Province/State : beijing
Country : United States
Postal Code : 20108
Phone Number : 571-866-7585793
Fax : 571-866-7585793
Email : Michell.Gregory2009@yahoo.com
A Google Search for that address comes up with over 24,000 references!
tradesdomains.net is registered differently:
512 Stonegate Pl
ns1.pa-estate.com and ns1.tradesdomains.net are hosted at 18.104.22.168 (Global Net Access, LLC ) which also hosts puioypai.org which looks suspect too. ns2.tradesdomains.net is on 22.214.171.124 (Bahnhof Internet, Sweden).
Added: the email comes from several different addresses, including:
- Your ACH transaction was rejected by The Electronic Payments Association (NACHA)
- Please review the transaction report
- Your ACH transaction was rejected