Date: Tue, 18 Jun 2013 01:21:34 -0800 [05:21:34 EDT]
Subject: Your UPS Invoice is Ready
UPS Billing Center
This is an automatically generated email. Please do not reply to this email address.
Dear UPS Customer,
Thank you for your business.
New invoice(s) are available for the consolidated payment plan(s) / account(s) enrolled in the UPS Billing Center.
Please visit the UPS Billing Center to view your paid invoice.
Questions about your charges? To get a better understanding of surcharges on your invoice, click here.
Discover more about UPS:
Explore UPS Freight Services
Learn About UPS Companies
Sign Up For Additional Email From UPS
Read Compass Online
© 2013 United Parcel Service of America, Inc. UPS, the UPS brandmark, and the color brown are trademarks of United Parcel Service of America, Inc. All rights reserved.
Please do not reply directly to this e-mail. UPS will not receive any reply message.
For questions or comments, visit Contact UPS.
This communication contains proprietary information and may be confidential. If you are not the intended recipient, the reading, copying, disclosure or other use of the contents of this e-mail is strictly prohibited and you are instructed to please delete this e-mail immediately.
The link in the email goes through a legitimate hacked site but then ends up on a malicious payload at [donotclick]rmacstolp.net/news/fishs_grands.php (report here and here). The payload appears to be the Blackhole Exploit kit, but the site seems to be either not working or (more likely) is being resistant to analysis.
If not called properly, the malware appears to serve up random payload pages.. I think they may be fake ones to evade detection. Here are some of them:
rmacstolp.net is hosted on the following IPs:
184.108.40.206 (Global Village Telecom, Brazil)
220.127.116.11 (Greendot, Trinidad and Tobago)
18.104.22.168 (Universitatea Transilvania Brasov, Romania)
22.214.171.124 (LINKdotNET Telecom Limited, Pakistan)