Date: Thu, 27 Sep 2012 10:03:27 -0400
From: Habbo Hotel [email@example.com]
Subject: UPS Tracking Number H8244648923
USPS .com Customer Services for big savings! Can't see images? CLICK HERE.
UPS UPS SUPPORT 39
UPS - UPS TEAM 31 >>
Not Ready to Open
The UPS Store� can help with full service packing and shipping.
Learn More >>
UPS - Your UPS .com Customer Services
DEAR CUSTOMER , Delivery Confirmation: Failed
Track your Shipment now!
With best wishes , UPS .com Customer Services.
Shipping Tracking Calculate Time & Cost Open an Account
@ 2011 United Parcel Service of America, Inc. Your USPS Team, the UPS brandmark, and the color brown are
trademarks of United Parcel Service of America, Inc. All rights reserved.
This is a marketing e-mail for UPS services. Click here to update your e-mail preferences or to unsubscribe to
USPS .com Customer Services, 33 Glenlake Parkway, NE - Atlanta, GA 30580
Attn: Customer Communications Department
The malicious payload is at [donotclick]sectantes-x.ru:8080/forum/links/column.php hosted on the following IP addresses:
220.127.116.11 (Republic CyberBunker, Antarctica - Amsterdam more likely)
18.104.22.168 (RACSA, Costa Rica)
22.214.171.124 (Myren, Malaysia)
The following IPs and domains are all connected and should be blocked:
In addition, CyberBunker has a long history of spamming and tolerating criminals. Blocking the range 126.96.36.199/19 should afford your network some additional protection.