Sponsored by..

Monday, 19 November 2012

"End of Aug. Statement Reqiured" spam / bamanaco.ru

This spam leads to malware on bamanaco.ru:

Date:      Mon, 19 Nov 2012 03:55:08 -0500
From:      ups [admin@ups.com]
Subject:      Re: FW: End of Aug. Statement Reqiured
Attachments:     Invoices-1119-2012.htm


as reqeusted I give you inovices issued to you per oct. 2012 ( Internet Explorer/Mozilla Firefox file)


The malicious payload is at [donotclick]bamanaco.ru:8080/forum/links/column.php hosted on the following IPs: (MYREN, Malaysia) (Psychz Networks, US)

These IPs have been used to deliver malware several times recently, you should block access to them if you can.

No comments: