From: James Wheatley [wheatjam@gmail.com]There seem to be a few variants of the attachment, these have a detection rate of about 4/55 [1] [2] and analysis of those two examples [3] [4] download a malicious binary from:
Date: 17 December 2015 at 09:50
Subject: James Wheatley sent you an document file!
---
---
Sent by WhatsApp
www.nz77.de/65dfg77/kmn653.exe
old.durchgegorene-weine.de/65dfg77/kmn653.exe
This payload is the same as the one found in this spam run earlier today.
2 comments:
Wow that's spooky, Just Googled James Wheatley's email address as I was obviously suspicious and first result is your blog. Hope you and the family are well Regards, Mike W (Avantime)
:)
If they wanted to target us they should send out an email with "free Avantime centre caps" in the subject..
Post a Comment