From: RBC - Royal Bank [service@rbc-secure-message.com]
Date: 15 February 2017 at 17:50
Subject: RBC - Secure Message
Signed by: rbc-secure-message.com
|
|
Attached is a file RBCSecureMessage.doc which contains some sort of macro-based malware. It displays the following page to entice victims to disable their security settings.
Automated analysis is inconclusive [1] [2]. The domain rbc-secure-message.com is fake and has been registered solely for this purpose of malware distribution. In all the samples I saw, the sending IP was 64.91.248.146 (Liquidweb, US) but it does look like all these IPs in the neighbourhood are involved in the same activity:
64.91.248.137
64.91.248.146
64.91.248.148
64.91.248.150
I recommend you block 64.91.248.128/27 at your email gateway to be sure.
No comments:
Post a Comment