From: Susanne@victimdomain.tld [Susanne@victimdomain.tld]The sender's name varies, but is always in the same domain as the victim.
Date: 4 May 2018, 10:22
Subject: Best porno ever
Hi [redacted],
Best gay,teen,animal porno ever
Please click the following link to activate your account.
hxxp:||46.161.40.145:3314
Regards,
Susanne
I only saw four different links in the body text:
Warning live links - do not click
http://46.161.40.145:3314/
http://37.1.211.221:1699/
http://31.207.47.125/3FgtbvCf
http://77.72.84.115/
None of these sites were working when I tested them. Hosting IPs are:
46.161.40.145 (Ankas Ltd, Moldova)
37.1.211.221 (3NT Solutions, UK)
31.207.47.125 (Hostkey, Netherlands)
77.72.84.115 (Netup, UK)
3NT Solutions are a well-known purveyor of badness and I recommend blocking everthing, What the payload is here is unclear, but you can guarantee that's it's nothing good. And probably not smut either.
1 comment:
New link:
Warning: NO CLICK
http://194.165.16.165:4451
Best regards,
DaviF
Post a Comment