Sponsored by..

Tuesday, 2 October 2012

Friendster spam / sonatanamore.ru

Friendster.. remember that? Before Facebook.. before Myspace.. there was Friendster. This spam email is not from Friendster though and leads to malware on sonatanamore.ru:


Date:      Tue, 2 Oct 2012 05:39:54 -0500
From:      Friendster Games [friendstergames@friendster.com]
Subject:      Regarding your Friendster password

  
  
Thank you for joining Friendster! Your system generated password is 0JR8YXB1YR. You may change your password in your Account Settings Page.
  

Friendster is the social gaming destination of choice. Connect and play with your friends & share your progress with your network.
Copyright � 2002 - 2012 Friendster, Inc. All rights reserved. Visit our site. - Terms of Service
To manage your notification preferences, go here
To stop receiving emails from us, you can unsubscribe here


The malicious payload is at [donotclick]sonatanamore.ru:8080/forum/links/column.php hosted on:
70.38.31.71 (iWeb, Canada)
202.3.245.13 (MANA, Tahiti)
203.80.16.81 (Myren, Malaysia)

Plain list of IPs and domains on those IPs for copy-and-pasting.
70.38.31.71
202.3.245.13
203.80.16.81
limonadiksec.ru
rumyniaonline.ru
denegnashete.ru
dimabilanch.ru
ioponeslal.ru
moskowpulkavo.ru
onlinebayunator.ru
omahabeachs.ru
uzoshkins.ru
sectantes-x.ru
sonatanamore.ru

No comments: