Sponsored by..

Monday, 6 August 2012

LinkedIn spam / headtoheadblaster.org

This LinkedIn spam attempts to load malware from headtoheadblaster.org:

Date:      Mon, 6 Aug 2012 17:07:08 +0300
From:      "LinkedIn Invitations" [invitations@linkedin.com]
To:      [redacted]
Subject:      Your friend sent you an invitation to join LinkedIn group.

  
This is a notification that on August 5, Gage Herring sent you an invitation to become part of their professional network at LinkedIn.
Accept Gage Herring Invitation
  
On August 5, Gage Herring wrote:

> To: [redacted]
>
> I'd like to add you to my professional network on LinkedIn.
>
> Gage Herring   
  
You are receiving Reminder emails for pending invitations. Unsubscribe.
� 2012 LinkedIn Corporation. 2029 Stierlin Ct, Mountain View, CA 94043, USA.

==========


Date:      Mon, 6 Aug 2012 10:02:02 -0400
From:      "LinkedIn Invitations" [invitations@linkedin.com]
To:      [redacted]
Subject:      LinkedIn inviation notificaltion.

  
This is a notification that on August 5, Daniel Martinez sent you an invitation to join their professional network at LinkedIn.
Accept Daniel Martinez Invitation
  
On August 5, Daniel Martinez wrote:

> To: [redacted]
>
> I'd like to add you to my professional network on LinkedIn.
>
> Daniel Martinez   
  
You are receiving Reminder emails for pending invitations. Unsubscribe.
� 2012 LinkedIn Corporation. 2029 Stierlin Ct, Mountain View, CA 94043, USA.


The malicious payload is at [donotclick]headtoheadblaster.org/main.php?page=f6857febef53e332 (report here) although at the time of writing it does not seem to be resolving.

No comments: