Sponsored by..

Wednesday 3 October 2012

"Corporate eFax message" spam / 69.194.194.222

This fake fax spam leads to malware on 69.194.194.222:


Date:      Wed, 03 Oct 2012 15:00:43 +0200
From:      "eFax" [4FBED27@fashioninsomniacs.com]
Subject:      Corporate eFax message - 8 pages




Fax Message [Caller-ID: 368-848-8852]
You have received a 8 pages fax at Wed, 03 Oct 2012 15:00:43 +0200.

* The reference number for this fax is min1_20121003150043.438820.

View this fax using your PDF reader.

Click here to view this message

Please visit www.eFax.com/en/efax/twa/page/help if you have any questions regarding this message or your service.
Thank you for using the eFax service!
Home | Contact | Login
� 2011 j2 Global Communications, Inc. All rights reserved.
eFax� is a registered trademark of j2 Global Communications, Inc.
This account is subject to the terms listed in the eFax� Customer Agreement.

==========


Date:      Wed, 03 Oct 2012 17:12:57 +0530
From:      "eFax.Corporate" [2FEDD7BC@kelprint.fr]
Subject:      Corporate eFax message - 1 pages




Fax Message [Caller-ID: 033-717-5099]
You have received a 1 pages fax at Wed, 03 Oct 2012 17:12:57 +0530.

* The reference number for this fax is min1_20121003171257.5227.

View this fax using your PDF reader.

Click here to view this message

Please visit www.eFax.com/en/efax/twa/page/help if you have any questions regarding this message or your service.
Thank you for using the eFax service!
Home | Contact | Login
� 2011 j2 Global Communications, Inc. All rights reserved.
eFax� is a registered trademark of j2 Global Communications, Inc.
This account is subject to the terms listed in the eFax� Customer Agreement.

==========


Date:      Wed, 03 Oct 2012 07:25:36 -0400
From:      "eFax" [965F7212@dyer.com.hk]
Subject:      Corporate eFax message - 7 pages




Fax Message [Caller-ID: 300-811-6555]
You have received a 7 pages fax at Wed, 03 Oct 2012 07:25:36 -0400.

* The reference number for this fax is min1_20121003072536.6902337.

View this fax using your PDF reader.

Click here to view this message

Please visit www.eFax.com/en/efax/twa/page/help if you have any questions regarding this message or your service.
Thank you for using the eFax service!
Home | Contact | Login
� 2011 j2 Global Communications, Inc. All rights reserved.
eFax� is a registered trademark of j2 Global Communications, Inc.
This account is subject to the terms listed in the eFax� Customer Agreement.


The malicious payload is at [donotclick]69.194.194.222/links/assure_numb_engineers.php (Solar VPS, US). Blocking this IP address may be wise as they tend to be used in more than one campaign.

No comments: