Sponsored by..

Friday 5 April 2013

"Copies of Policies" spam / ifikangloo.ru

This spam leads to malware on ifikangloo.ru:

From: KaelSaine@mail.com [mailto:KaelSaine@mail.com]
Sent: 05 April 2013 11:43
Subject: Fwd: LATONYA - Copies of Policies

Unfortunately, I cannot obtain electronic copies of the SPII policy.

Here is the Package and Umbrella,

and a copy of the most recent schedule.


LATONYA Richmond, 
The link in the email leads to a legitimate hacked site and then on to [donotclick]ifikangloo.ru:8080/forum/links/column.php (report here) hosted on the same IPs used in this attack:
91.191.170.26 (Netdirekt, Turkey)
208.94.108.238 (Fibrenoire, Germany)

Blocklist:
91.191.170.26
208.94.108.238
ifikangloo.ru
ifinaksiao.ru
igionkialo.ru
ijsiokolo.ru
illuminataf.ru
imanraiodl.ru
itriopea.ru
ivanikako.ru
ixxtigang.ru
izamalok.ru
izjianokr.ru


No comments: