Date: Fri, 7 Dec 2012 10:53:57 +0200The malicious payload is at [donotclick]pelamutrika.ru:8080/forum/links/column.php hosted on the following familiar IP addresses which you should definitely try to block:
From: Badoo [noreply@badoo.com]
Subject: You have been sent a file (Filename: [victimname]-64.pdf)
Sendspace File Delivery Notification:
You've got a file called [victimname]-792244.pdf, (337.19 KB) waiting to be downloaded at sendspace.(It was sent by CHASSIDY PROCTOR).
You can use the following link to retrieve your file:
Download Link
The file may be available for a limited time only.
Thank you,
sendspace - The best free file sharing service.
----------------------------------------------------------------------
Please do not reply to this email. This auto-mailbox is not monitored and you will not receive a response.
202.180.221.186 (GNet, Mongolia)
208.87.243.131 (Psychz Networks, US)
No comments:
Post a Comment