Date: Fri, 17 Aug 2012 06:50:08 -0400
From: "Global Express" [ups-services@ups.com]
Subject: Re: FW: End of Aug. Stat. Required
Attachments: Invoices-26-2012.htm
Hallo,
as reqeusted I give you inovices issued to you per july.
Regards
The malicious payload is at [donotclick]panalki.ru:8080/forum/showthread.php?page=5fa58bce769e5c2c (report here) hosted on a bunch of familiar looking IP addresses which should be blocked if you can.
50.56.92.47 (Slicehost, US)
190.120.228.92 (Infolink, Panama)
203.80.16.81 (Myren, Malaysia)
No comments:
Post a Comment