Tuesday 13 March 2012

"I'm in trouble! " spam / ckjsfhlasla.ru

Another recycled spam campaign leading to malware:

Date:      Tue, 13 Mar 2012 01:52:30 +0700
From:      "Greyson Montoya"
Subject:      I'm in trouble!
Attachments:     Image_DIG33080106.htm

I was at a party yesterday, got drunk, couldn't drive the car, somebody gave me a lift on my car, and crossed on the red light!
I've just got the pictures, maybe you know him???

I have attached the photo to the mail (Open with Internet Explorer).

I need to find him urgently!

Thank you

The malicious web page is at ckjsfhlasla.ru:8080/images/aublbzdni.php which is hosted on exactly the same IP addresses as this spam run yesterday. Blocking these IPs would be prudent.

