This earlier spam run about various brands of 55 inch TVs from Amazon has been updated and is now directing victims to a malware landing page on the domain
ozonatorz.com:
|
Thank you for shopping with us. Wed
like to let you know that Amazon has received your order, and is
preparing it for shipment. Your estimated delivery date is below. If you
would like to view the status of your order or make any changes to it,
please visit Your Orders on Amazon.com.
|
|
|
|
Your estimated delivery
date is:
Thursday, May 30, 2013 -
Friday, May 31, 2013
Your shipping speed:
Next Day Air
|
Your order was sent to:
Benjamin Phillips
2724 3rdCotton Avenue
Cohoes, CA 62229-6646
United States
|
|
|
|
Order Details
|
|
|
|
Item Subtotal:
|
$979.98
|
Shipping &
Handling:
|
$0.00
|
|
Total Before
Tax:
|
$979.98
|
Estimated Tax:
|
$0.00
|
|
|
Order Total:
|
$979.98
|
|
|
|
|
Thank you for
shopping with us.
Amazon.com
|
|
|
Unless otherwise noted, items are sold by Amazon.com LLC
and taxed if shipped to Kansas, North Dakota, New York, Kentucky or
Washington. If your order contains one or more items from an Amazon.com
partner it may be subject to state and local sales tax, depending on the
state to which the item is being shipped. Learn more about tax and seller
information.
This email was sent from a notification-only address that
cannot accept incoming email. Please do not reply to this message.
|
|
|
|
The malicious payload is on
[donotclick]ozonatorz.com/news/basic_dream-goods.php (
report here) hosted on:
41.89.6.179 (Kenya Education Network, Kenya)
141.28.126.201 (Hochschule Furtwangen, Germany)
177.5.244.236 (Brasil Telecom, Brazil)
208.68.36.11 (Digital Ocean, US)
These IPs form part of a much larger network of malicious sites
listed here, but if we concentrate of these IPs only we get the following blocklist:
41.89.6.179
141.28.126.201
177.5.244.236
208.68.36.11
aviachecki.ru
avtotracki.ru
balckanweb.com
biati.net
buyparrots.net
federal-credit-union.com
giwmmasnieuhe.ru
icensol.net
mydkarsy.com
nvufvwieg.com
ozonatorz.com
rusistema.ru
smartsecurityapp2013.com
techno5room.ru
testerpro5.ru
trackerpro5.ru
twintrade.net
zeouk-gt.com
No comments:
Post a Comment