Date: Wed, 20 Feb 2013 04:28:14 +0600The malicious payload is at [donotclick]fulinaohps.ru:8080/forum/links/column.php (report here) hosted om the following IPs:
Subject: Fwd: ACH and Wire transfers disabled.
Dear Online Account Operator,
Your ACH transactions have been
18.104.22.168 (EUserv Internet, Germany)
22.214.171.124 (PS Internet Company, Kazakhstan)
126.96.36.199 (Chungwa Telecom, Taiwan)
These are the same IPs as used in this attack, you should block them if you can.