I have't seen any fake BBB spam for a while, but here it is.. this new spam run leads to malware on
sushfpappsbf.ru.
Date: Wed, 20 Jun 2012 05:20:45 +0100
From: LamarHF4AF78ZFq@gmail.com
Subject: Urgent information from BBB
Attn: Owner/Manager
Here with the Better Business Bureau notifies you that we have received a complaint (ID 615337145)
from one of your customers with respect to their dealership with you.
Please open the COMPLAINT REPORT below to obtain more information on this matter and let us know of your point of view as soon as possible.
We are looking forward to your prompt reply.
Regards,
Lamar WILHELM
The malicious payload is at
[donotclick]sushfpappsbf.ru:8080/forum/showthread.php?page=5fa58bce769e5c2c (
report here) which is multihomed on the following IPs:
94.20.30.91 (Delta Telecom, Azerbaijan)
124.124.212.172 (Reliance Communications, India)
173.224.209.130 (Psychz Networks, US)
213.17.171.186 (Netia SA, Poland)
The following IPs and domain names are connected with this malware run and should be blocked if you can:
78.83.233.242
89.111.177.151
94.20.30.91
110.234.176.99
124.124.212.172
173.224.209.130
213.17.171.186
girlsnotcryz.ru
harmoniavslove.ru
huletydyshish.ru
monashkanasene.ru
pekarniamsk.ru
piloramamoskow.ru
saprolaunimaxim.ru
seledkindoms.ru
sumatranajuge.ru
sushfpappsbf.ru