Sponsored by..

Friday 3 August 2012

AT&T spam / searchlesswebwasher.info

Another AT&T spam, this time leading to a working malicious payload on searchlesswebwasher.info:

Date:      Fri, 3 Aug 2012 16:54:24 +0100
From:      "AT&T Online Services" <alert@email.att-mail.com>
Subject:      Your AT&T bill is ready to be paid now.

<td style="padding: 0px 10px 0px 10px;" width:33%="" valign="top">
att.com | Support | My AT&T Account    
<td style="padding: 0px 10px 0px 10px;" width:34%="" valign="top">
Your online bill is ready to be viewed
Dear Valued Customer,

A new bill for your AT&T account is ready.

Any operations completed after your bill period expires will not be shown in the bill amount listed directly below. If you have made a recent payment, please refer to the current balance on the Account Overview and the Bill & Payments pages.

Service     Account ending in     Bill Amount     Due Date
Internet and Home Phone     3     $808.32     08/06/2012

Log in to online account management to view your bill and bill notices, maintain your email account or make a payment. If you are not registered for online account management, you must do so to view and print your full bill and bill notices at www.att.com/managemyaccount.
Log in to online account management to view your bill, maintain your email account or make a payment.

Thank you for choosing AT&T. We value your business and look forward to serving you!

Thank you,
AT&T Online Services

Contact Us
AT&T Support - quick & easy support is available 24/7.


Moving Soon?
Stay connected with AT&T. Visit us online at att.com/move.

<td style="padding: 0px 10px 0px 10px;" width:33%="" valign="top">
AT&T Online Services
Get more time to do what you want. What would you do?
Show me how

Automatic Payments
Save time and pay your monthly bill automatically!
Sign up now

Special Offers
Visit our Special Offers to check out our best promotions.
Learn more

Online Information
AT&T Community
Home Phone
Special Offers
All replies are automatically deleted. For questions regarding this message, refer to the contact information listed above.

�2012 AT&T Intellectual Property. All rights reserved. AT&T, the AT&T logo and all other AT&T marks contained herein are trademarks of AT&T Intellectual Property and/or AT&T affiliated companies. All other marks contained herein are the property of their respective owners.
Privacy Policy

The malicious payload is at [donotclick]searchlesswebwasher.info/main.php?page=6df8994172330e77 (report here) hosted on which is part of a small range of IP addresses which can probably be safely blocked:

inetnum: -
netname:         GB13561-static
descr:           tomeaspl-static
country:         GR
admin-c:         GB13561-RIPE
tech-c:          GB13561-RIPE
status:          ASSIGNED PA
mnt-by:          CYTA-HELLAS
source:          RIPE # Filtered

person:          GEORGIOS BASILAKIS
address:         FILELLHNON 8
address:         HRAKLEIO KRHTHS
address:         GREECE
phone:           +302810327452
nic-hdl:         GB13561-RIPE
mnt-by:          CYTA-HELLAS
source:          RIPE # Filtered

descr:          CYTANET - For CYTA HELLAS
origin:         AS6866
mnt-by:         CYTANET-NOC
source:         RIPE # Filtered

No comments: