Thursday 20 September 2012

Federal Tax Payment Spam / soisokdomen.ru

This fake tax payment spam leads to malware on soisokdomen.ru:

Date:      Thu, 20 Sep 2012 09:10:47 -0300
From:      Badoo [noreply@badoo.com]
Subject:      Re: Fwd: Tax Payment COM1684-645 is failed.


Your Federal Tax Payment has been rejected.

Please, check the information and refer to Code I 94 to get details about

your company payment:



The Electronic Federal Tax Payment System
The malicious payload (probably Blackhole 2) is at [donotclick]soisokdomen.ru:8080/forum/links/column.php hosted on the following familiar looking IP addresses:

Blocking these would be prudent.

