From: Elouise Massey [Elouise.Massey@supertouch.com]In the sample I received, the attachment was corrupt but should have been a file a malicious Word document S-CON-A248-194387.doc. The document and payload is exactly the same as the one being sent out today with this spam run (read that post for more details) and is very poorly detected, although blocking access to the following IPs and domains might help mitigate against it:
Date: 23 October 2014 10:52
Subject: Order Confirmation
Hello,
Thank you for your order, please check and confirm.
Kind Regards
Elouise
Allied International Trading Limited
Unit 1A
Hubert Road
Brentwood
Essex
CM14 4JE
United Kingdom
Telephone 0845 130 9922
Fax 0845 130 9933
87.106.84.226
84.40.9.34
jvsfiles.com
No comments:
Post a Comment