Sponsored by..

Thursday 1 March 2012

"Scan from a Hewlett-Packard Officejet" spam / caskjfhlkaspsfg.ru

Another malicious spam, this time with an attachment containing obfuscated code leading to caskjfhlkaspsfg.ru.

Date:      Thu, 1 Mar 2012 09:43:50 +0530
From:      ARLYNEO93ESQUIVEL@gmail.com
Subject:      Fwd: Re: Fwd: Scan from a Hewlett-Packard Officejet #603320
Attachments:     HP_Scan-27-499614.htm

Attached document was scanned and sent

to you using a Hewlett-Packard HP SmartJet 4931F.

Sent by: ARLYNE
Pages : 9
Attachment Type: .HTM [Internet Explorer/Mozilla Firefox]

The malware is on caskjfhlkaspsfg.ru:8080/images/aublbzdni.php , as with other recent .ru:8080 attacks, this is multihomed on a familiar set of IP addresses: (Steadfast Networks, US) (Colopronto, US) (Corbina Telecom, Russia) (Netia Telekom, Poland) (Optimate-server, Germany) (Websitewelcome, US) (Tata Teleservices, India) (Bharti Infotel, India) (Kwangun University, Korea) (Slicehost, US) (Slicehost, US) (Slicehost, US) (Telemax, Peru) (ECSuite, US) (Century Telecom Ltda, Brazil) (Slicehost, US) (Commission For Science And Technology, Pakistan) (Sejong Telecom, Korea)

A bare list for copy-and-pasting:

1 comment:

Spamlazer said...

Thanks for info...I just got one of these...now deleted