![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjU3f67K6C0NBokv04V37IYb3DgiTWa7OqhYK9KLn1zOV5r2-ZvW_f2syAYwe10QTwKlZcGWVmmhhG55RFY6tig_hDj_f5v2h6jeWOfuRWYMniYMtooVpvmKTEEMF9oi_dDXZG18tettOE/s200/ru8080.png)
Date: Tue, 11 Dec 2012 10:46:43 -0300The malicious payload is at [donotclick]aseniakrol.ru:8080/forum/links/column.php hosted on a bunch of IPs that have been used for malware before:
From: Tarra Comer via LinkedIn [member@linkedin.com]
Subject: Re: Your Changelog UPDATED
Hi,
as promised your changelog - View
I. Easley
202.180.221.186 (GNet, Mongolia)
212.162.52.180 (Secure Netz, Germany)
212.162.56.210 (Secure Netz, Germany)
No comments:
Post a Comment