From: firstname.lastname@example.org [mailto:email@example.com] On Behalf Of LinkedIn
Sent: 20 February 2013 20:02
Subject: ADP Immediate Notification
ADP Immediate Notification
Reference #: 001737199
Thu, 21 Feb 2013 02:01:39 +0600
Dear ADP Client
Your Transfer Record(s) have been created at the web site:
Please see the following notes:
• Please note that your bank account will be debited within one banking business day for the amount(s) shown on the report(s).
• Please do not respond or reply to this automated e-mail. If you have any questions or comments, please Contact your ADP Benefits Specialist.
This note was sent to acting users in your system that approach ADP Netsecure.
As usual, thank you for choosing ADP as your business affiliate!
HR. Payroll. Benefits.
The ADP logo and ADP are registered trademarks of ADP, Inc.
In the business of your success is a service mark of ADP, Inc.
© 2013 ADP, Inc. All rights reserved.
The malicious payload is meant to be [donotclick]faneroomk.ru:8080/forum/links/column.php but right at the moment it is not resolving.
We can perhaps do a little digging around to see what's going on here. The WHOIS details show the notorious Russian "Private Person".
whois -h whois.ripn.net faneroomk.ru ...
% By submitting a query to RIPN's Whois Service
% http://www.ripn.net/about/servpol.html#3.2 (in Russian)
% http://www.ripn.net/about/en/servpol.html#3.2 (in English).
nserver: ns1.faneroomk.ru. 220.127.116.11
nserver: ns2.faneroomk.ru. 18.104.22.168
nserver: ns3.faneroomk.ru. 22.214.171.124
nserver: ns4.faneroomk.ru. 126.96.36.199
nserver: ns5.faneroomk.ru. 188.8.131.52
state: REGISTERED, NOT DELEGATED, UNVERIFIED
person: Private Person
Last updated on 2013.02.21 17:16:40 MSK
Anyway. it's probably a good idea to block the domain and those NS IPs. The following IPs and domains are all related: