Date: Wed, 4 Apr 2012 11:33:37 +0100
Subject: Dowload your Intuit.com invoice.
Dear customer: Thank you for ordering from Intuit Market. We are processing and will message you when your order ships. If you ordered multiple items, we may sned them in more than one delivery (at no extra cost to you) to ensure quicker delivery. If you have questions about your order please call 1-900-374-9959 ($2.89/min).
Please download your complete order id #5400523 from the attachment.(Open with Internet Explorer)
�2012 Intuit, Inc. All rights reserved. Intuit, the Intuit Logo, Quickbooks, Quicken and TurboTax, among others, are registered trademarks of Intuit Inc.
The malware is a Phoenix exploit kit at dhjhgfkjsldkjdj.ru:8080/navigator/jueoaritjuir.php (Wepawet Report here) which is multihomed on the IPs below, a very similar list to this recent spam run.
220.127.116.11 (AfricaINX, South Africa)
18.104.22.168 (Neotel Pty, South Africa)
22.214.171.124 (ChinaNet Hunan, China)
126.96.36.199 (Microlink, Latvia)
188.8.131.52 (Spectrum Net JSC, Bulgaria)
184.108.40.206 (Vimpelcom, Russia)
220.127.116.11 (Kazakhtelecom, Kazakhstan)
18.104.22.168 (Bharti Infotel Ltd, India)
22.214.171.124 (Ardh Global, Indonesia)
126.96.36.199 (State Technical University of Saint-Petersburg, Russia)
188.8.131.52 (Comite Gestor Da Internet, Brazil)
184.108.40.206 (Satata Neka Tama, Indonesia)
220.127.116.11 (Commission For Science And Technology, Pakistan)
18.104.22.168 (Commission For Science And Technology, Pakistan)
22.214.171.124 (Sejong Telecom, Korea)
126.96.36.199 (SK Broadband Co Ltd, Korea)
188.8.131.52 (Sakura Internet, Japan)
Plain list for copy-and-pasting: