From: MyFax [no-replay@my-fax.com]Clicking the link leads to a page like this:
Date: 22 January 2015 at 15:08
Subject: Fax #4356342
Fax message
http://[redacted]/.-NEW_RECEIVED.FAX/fax.html
Sent date: Thu, 22 Jan 2015 15:08:30 +0000
The download leads to an EXE-in-ZIP download which is a little different every time [1] [2] [3] [virustotal]. Detection rates are around 6/55.
The Malwr report shows communication with the following URLs:
http://202.153.35.133:51025/2201us22/HOME/0/51-SP3/0/
http://202.153.35.133:51025/2201us22/HOME/1/0/0/
http://when-to-change-oil.com/mandoc/story_su22.pdf
http://202.153.35.133:51014/2201us22/HOME/41/7/4/
Of these 202.153.35.133 is the essential one to block traffic to, belonging to Excell Media Pvt Ltd in India. A file axybT95.exe is also dropped according to the report, which has a detection rate of 7/48.
I haven't seen a huge number of these, the format of the URLs looks something like this:
http://[redacted]/.-NEW_RECEIVED.FAX/fax.html
http://[redacted]/NEW_FAX-MESSAGES/fax.letter.html
http://[redacted]/_~NEW.FAX.MESSAGES/incoming.html
1 comment:
More files associated with risk:
c:\users\useraccount\appdata\local\temp\temp2_fax-message921497.zip\fax-message921497.scr
c:\users\useraccount\appdata\local\temp\mscodecs.exe
Hash for both:97ab139588ee98d140143f606115165e
Post a Comment