Sponsored by..

Monday 2 July 2012

American Airlines spam / ghanarpower.net

This fake spam leads to malware on ghanarpower.net:


Date:      Mon, 2 Jul 2012 16:54:15 +0200
From:      "Cornelius Meyers" <notify@aa.globalnotifications.com>
Subject:      Online American Airlines receipt.


   
Record Locator: MWNMLP

Date of Issue: 2JULY12


Thank you for choosing American Airlines / American Eagle, a member of the oneworld� Alliance.

This receipt is for the purchase of your Preferred Seat(s) which are detailed on your itinerary and receipt confirmation.

If you have any questions regarding your reservations, please call 1-800-433-7300 or visit www.aa.com.



   

   

   
Record Locator: MWNMLP


PASSENGER
CHADBOURN HAWLEY
   
DOCUMENT NUMBER / DATE
0010634774011/2JULY12
   
DESCRIPTION
PREFERRED SEATS
   
AMOUNT
17.67 USD
   
TAX
1.33
   
TOTAL
19.00 USD

Payment Type: Visa XXXXXXXXXXXX1392     Total: $19.00

================


Date:      Mon, 2 Jul 2012 17:59:25 +0430
From:      "Spencer Hurley" <notify@aa.globalnotifications.com>
Subject:      Preferred seat purchase receipt.


   
Record Locator: XTSPJI

Date of Issue: 2JULY12


Thank you for choosing American Airlines / American Eagle, a member of the oneworld� Alliance.

This receipt is for the purchase of your Preferred Seat(s) which are detailed on your itinerary and receipt confirmation.

If you have any questions regarding your reservations, please call 1-800-433-7300 or visit www.aa.com.



   

   

   
Record Locator: XTSPJI


PASSENGER
CHADBOURN HAWLEY
   
DOCUMENT NUMBER / DATE
0010634774011/2JULY12
   
DESCRIPTION
PREFERRED SEATS
   
AMOUNT
17.67 USD
   
TAX
1.33
   
TOTAL
19.00 USD

Payment Type: Visa XXXXXXXXXXXX1293     Total: $19.00

The malicious payload is the same as used in this attack - blocking it and the related IPs and domains is probably wise.

TD Ameritrade Spam / ghanarpower.net

This convincing-looking TD Ameritrade spam leads to malware at ghanarpower.net:

 ________________________________________
Your account ending in XXX7     Log on

________________________________________

Your statement is now available online

Dear Valued Client,

Your statement for your TD Ameritrade account ending in XXX7 is now available online.

Access your statements
To view your statement (along with previous statements), please Log On to your account and choose "History & Statements" (under Accounts). Then click the "Statements" tab, select the appropriate month(s) under the "View statements" drop-down menu, then click the "View" button.

We're here to help
If you have any questions, please log on to your account and click "Message Center" (under Home) to write us. A representative will respond through your Message Center inbox. You can also call Client Services at 800-669-3900. We're available 24 hours a day, seven days a week.

Sincerely,


Tom Bradley
President, Retail Distribution
TD Ameritrade


The malware can be found on [donotclick]ghanarpower.net/main.php?page=8c6c59becaa0da07 (report here) hosted on (188.165.1.192, OVH Ireland).

The following IPs and domains are connected to this attack and should also be blocked:
ecocabmedia.net   
ghanarpower.net
lessthansmoothmasculine.com   
68.171.101.22
92.201.139.15
188.165.1.192
109.164.221.176
211.157.105.160

Thursday 28 June 2012

Pinterest Spam / medicarewichi.com

Spammers will try anything.. this email pretends to be from Pinterest but it actually appears to lead to a fake pharma site at medicarewichi.com.

From: Pinterest [mailto:pinbot@pinterest.com]
Sent: 28 June 2012 14:41
Subject: New pins added

Hi!

    With millions of new pins added every week, we connecting people all over the world based on shared tastes and interests.        Explore pins   

©2012 Pinterest, Inc. | All Rights Reserved.
Privacy Policy | Terms and Conditions


The spamvertised site is hosted on 91.238.180.92 which looks like a cesspit of toxic sites and is probably best blocked.

Malware sites to block 28/6/12

These malicious sites and IPs are connected with this spam run. I recommend blocking them.

31.17.189.212
41.66.137.155
41.168.5.140
50.57.43.49
50.57.88.200
62.76.45.241
62.76.188.120
62.76.189.62
62.76.191.172
62.213.64.161
64.120.134.7
66.90.76.62
83.143.134.23
83.170.91.152
85.17.72.34
85.214.204.32
87.204.199.100
91.210.189.68
91.221.70.19
94.75.231.156
95.142.167.193
95.168.185.214
95.168.185.215
95.168.185.216
95.168.185.217
95.168.185.218
95.211.18.79
110.234.150.163
110.234.176.99
128.134.57.112
173.203.96.79
178.33.105.222
178.63.208.37
178.63.249.35
178.63.249.45
184.106.189.124
184.106.200.41
188.72.199.247
188.72.220.158
188.212.156.170
190.81.107.70
194.109.21.8
195.14.104.76
200.169.13.84
208.158.5.195
209.114.47.158
211.44.250.173
219.94.194.242

caoodntkioaojdf.ru
clkjshdflhhshdf.ru
ckjsfhlasla.ru
ckjhasbybnhdjf.ru
cruikdfoknaofa.ru
debiudlasduisioa.ru
dkjhasjllasllalaa.ru
dhjikjsdhfkksjud.ru
dinamitbtzusons.ru
dkijhsdkjfhsdf.ru
dnvfodooshdkfhha.ru
doorpsjjaklskfjak.ru
dpasssjiufjkaksss.ru
dppriakjsdjfhss.ru
dsakhfgkallsjfd.ru
forumenginesspb.ru
hamlovladivostok.ru
harmoniavslove.ru
insomniacporeed.ru
kroshkidlahlebans.ru
monashkanasene.ru
opimmerialtv.ru
pekarniamsk.ru
piloramamoskow.ru
porscheforumspb.ru
rushsjhdhfjsldif.su
seledkindoms.ru
semelyontour.ru
spbfotomontag.ru
somaniksuper.ru
spiritzandmore.com
sshgjksdfhhsd.ru
superproomgh.ru
sushfpappsbf.ru
tarantsikvasiliy.ru
zolindarkksokns.ru

NACHA Spam / porscheforumspb.ru

This fake NACHA spam leads to malware on porscheforumspb.ru:

Date:      Wed, 27 Jun 2012 06:18:09 -0430
From:      "Electronic Payments Association" [donotreply@nacha.org]
Subject:      Fwd: ACH Transfer rejected

The ACH transfer, initiated from your bank account, was canceled.

Canceled transfer:

Bath Nr.: FE-45452995330US

Transaction Report: View



ADELINE Jewell

Automated Clearing House, NACHA

The malicious payload is on [donotclick]porscheforumspb.ru:8080/forum/showthread.php?page=5fa58bce769e5c2c (report here), hosted on the following IPs:

110.234.176.99 (Tulip Telecom, India)
128.134.57.112 (Seoul Kwangun University, Korea)
190.81.107.70 (Telmex, Peru)

LinkedIn spam / 74.63.252.106

This fake LinkedIn spam leads to malware on 74.63.252.106:

Date:      Thu, 28 Jun 2012 00:52:04 +0200
From:      "2012, LinkedIn Corporation" [sdexheimer@itrs.com.br]
To:      [y009-xc6.ftdsf@catchamail.com]
Subject:      Relationship LinkedIn Mail

LinkedIn
REMINDERS

Invitation reminders:
• From Kevin Sellers (VP Analytic Services at Glencore)


PENDING MESSAGES

• There are a total of 9 messages awaiting your response. Visit your InBox now.

Don't want to receive email notifications? Adjust your message settings.

LinkedIn values your privacy. At no time has LinkedIn made your email address available to any other LinkedIn user without your permission. © 2012, LinkedIn Corporation.


The malicious payload is at [donotclick]74.63.252.106/getfile.php?u=71fd37ed (report here) which is part of a small netblock of 74.63.252.96/27 rented out by Limestone Networks in the US. Some attempt has been made to prevent analysis by generating a fake 403 page if you try to analyse it directly.

Wednesday 27 June 2012

If you know what this is..

If you know what this is.. well, you'll guess it was a) hard to find and b) expensive.. ;)

Thursday 21 June 2012

Malware sites to block 21/6/12

These sites and IPs are all connected to recent malicious spam runs. Blocking them either by IP address or domain name would probably be prudent.

46.162.27.165
64.79.106.188
91.227.220.114
109.164.221.176
109.169.86.139
173.234.9.84
187.5.116.251
192.84.186.206
199.101.99.155
abc-spain.net
abilenepaint.net
asiazmile.net
autobouracky.net
autosnort.net
chicleart.net
computerpills.net
cool-mail.net
energirans.net
grapecomputers.net
gtautond.com
hiring-decisions.com
hseclub.net
installandwork.com
itscholarshipz.net
jobforfamily.com
keurigminis.net
mynourigen.net
leadgems.net
perfectbusinesschance.net
savecoralz.net
synergyledlighting.net
systemtestnow.com
workandlivenow.com
workathomeforyou.net
yourfreeworkathome.net
yourlifechance.net

Wednesday 20 June 2012

UPS Spam / abilenepaint.net

This fake UPS spam leads to malware on abilenepaint.net:

Date:      Wed, 20 Jun 2012 21:15:55 +0500
From:      "UPS Quantum View" [auto-notify@ups.com]
Subject:      Track your UPS shipment online.

Discover more about UPS:
Visit www.ups.com
Sign Up For Additional E-Mail From UPS
Read Compass Online

   

This message was sent to you at the request of ICRealtime Security Solutions LLC to notify you that the electronic shipment information below has been transmitted to UPS. The physical package(s) may or may not have actually been tendered to UPS for shipment. To verify the actual transit status of your shipment, click on the tracking link below or contact ICRealtime Security Solutions LLC directly.

Important Delivery Information

Scheduled Delivery: 09-May-2012

Shipment Detail
Ship To:
xxxxxxxxxxxxxxxxxxxx
CSI SECURITY
2269 JEFFERIES HWY.
WALTERBORO
SC
29488
US

Number of Packages:     1
UPS Service:     GROUND
Weight:     9.0 LBS

Tracking Number:     1ZX603R40369384687
Reference Number 1:     47479
Reference Number 2:     20872

Click here to track if UPS has received your shipment or visit
http://www.ups.com/WebTracking/track?loc=en_US on the Internet.



____2@@2@@2wowT7qQAXmBSs4ogrWusagY4wa____

� 2012 United Parcel Service of America, Inc. UPS, the UPS brandmark, and the color brown are trademarks of United Parcel Service of America, Inc. All rights reserved.
For more information on UPS's privacy practices, refer to the UPS Privacy Policy.
Please do not reply directly to this e-mail. UPS will not receive any reply message.
For questions or comments, visit Contact UPS.

This communication contains proprietary information and may be confidential.� If you are not the intended recipient, the reading, copying, disclosure or other use of the contents of this e-mail is strictly prohibited and you are instructed to please delete this e-mail immediately.
Privacy Notice
Contact UPS


The malicious payload is at [donotclick]abilenepaint.net/main.php?page=c3c45bf60719e629 (report here)  hosted on 109.169.86.139 (Rapidswitch / iomart Hosting Ltd / ThrustVPS, UK) which is the same host used in this attack.

Verizon Wireless spam / keurigminis.net

This spam leads to malware on keurigminis.net:
Date:      Wed, 20 Jun 2012 16:37:06 +0100
From:      "AccountNotify@verizonwireless.com" [eAccountNotify@verizonwireless.com]
Subject:      Verizon wireless online bill.



   
    �
Important account information from Verizon Wireless
Your current bill for your account ending in XXXX-XX001 is now available online in My Verizon
Total Balance Due: $46.62
Scheduled Automatic Payment Date: 05/29/2012
Keep in mind that payments and/or adjustments made to your account after your bill was generated will be deducted from your automatic payment amount.

 View and Pay Your Bill

Thank you for choosing Verizon Wireless.

   

   
My Verizon is also available 24/7 to assist you with:
Viewing your usage
Updating your plan
Adding Account Members
Paying your bill
Finding accessories for your devices
And much, much more...
   


2011 Verizon Wireless
Verizon Wireless | One Verizon Way | Mail Code: 180WVB | Basking Ridge, NJ 07920
We respect your privacy. Please review our privacy policy for more information

If you are not the intended recipient and feel you have received this email in error; or if you
would like to update your customer notification preferences, please click here.
The malicious payload is at [donotclick]keurigminis.net/main.php?page=c3c45bf60719e629 (report here) hosted on 109.169.86.139 (Rapidswitch / iomart Hosting Ltd / ThrustVPS, UK).

BBB Spam / sushfpappsbf.ru

I have't seen any fake BBB spam for a while, but here it is.. this new spam run leads to malware on sushfpappsbf.ru.
Date:      Wed, 20 Jun 2012 05:20:45 +0100
From:      LamarHF4AF78ZFq@gmail.com
Subject:      Urgent information from BBB

Attn: Owner/Manager

Here with the Better Business Bureau notifies you that we have received a complaint (ID 615337145)
from one of your customers with respect to their dealership with you.

Please open the COMPLAINT REPORT below to obtain more information on this matter and let us know of your point of view as soon as possible.

We are looking forward to your prompt reply.
Regards,

Lamar WILHELM


The malicious payload is at [donotclick]sushfpappsbf.ru:8080/forum/showthread.php?page=5fa58bce769e5c2c (report here) which is multihomed on the following IPs:

94.20.30.91 (Delta Telecom, Azerbaijan)
124.124.212.172 (Reliance Communications, India)
173.224.209.130 (Psychz Networks, US)
213.17.171.186 (Netia SA, Poland)

The following IPs and domain names are connected with this malware run and should be blocked if you can:

78.83.233.242
89.111.177.151
94.20.30.91
110.234.176.99
124.124.212.172
173.224.209.130
213.17.171.186
girlsnotcryz.ru
harmoniavslove.ru
huletydyshish.ru
monashkanasene.ru
pekarniamsk.ru
piloramamoskow.ru
saprolaunimaxim.ru
seledkindoms.ru
sumatranajuge.ru
sushfpappsbf.ru

Monday 18 June 2012

"UPS Quantum View" spam / leadgems.net

A new version of this malicious spam run is under way, this time with a malicious payload at leadgems.net.

The payload page is at [donotclick]leadgems.net/main.php?page=940489e6fc8f17ed (report here) which is hosted on 192.84.186.206 (Seinajoki University of Applied Sciences, Finland).. presumably a hacked server.

Blocking access to 192.84.186.206 will prevent any other malicious sites on the same server from causing a problem.

Friday 15 June 2012

"Your UPS shipment tracking number" / autobouracky.net

Another UPS spam leading to malware, this time on autobouracky.net:

From:     UPS Quantum View auto-notify@ups.com
Date:     15 June 2012 14:34
Subject:     Your UPS shipment tracking number.

Discover more about UPS:
Visit www.ups.com
Sign Up For Additional E-Mail From UPS
Read Compass Online
My Choice

   

This message was sent to you at the request of ICRealtime Security Solutions LLC to notify you that the electronic shipment information below has been transmitted to UPS. The physical package(s) may or may not have actually been tendered to UPS for shipment. To verify the actual transit status of your shipment, click on the tracking link below or contact ICRealtime Security Solutions LLC directly.

Important Delivery Information

Scheduled Delivery: 09-May-2012

Shipment Detail
Ship To:
xxxxxxxxxx
CSI SECURITY
2269 JEFFERIES HWY.
WALTERBORO
SC
29488
US

Number of Packages:     1
UPS Service:     GROUND
Weight:     9.0 LBS

Tracking Number:     1ZX603R40369384687
Reference Number 1:     47479
Reference Number 2:     20872

Click here to track if UPS has received your shipment or visit
http://www.ups.com/WebTracking/track?loc=en_US on the Internet.



____2@@2@@2wowT7qQAXmBSs4ogrWusagY4wa____

© 2012 United Parcel Service of America, Inc. UPS, the UPS brandmark, and the color brown are trademarks of United Parcel Service of America, Inc. All rights reserved.
For more information on UPS's privacy practices, refer to the UPS Privacy Policy.
Please do not reply directly to this e-mail. UPS will not receive any reply message.
For questions or comments, visit Contact UPS.

This communication contains proprietary information and may be confidential.  If you are not the intended recipient, the reading, copying, disclosure or other use of the contents of this e-mail is strictly prohibited and you are instructed to please delete this e-mail immediately.
Privacy Notice
Contact UPS

The malicious payload is at [donotclick]autobouracky.net/main.php?page=0e1cb9b71ef021b2 (report here) which is hosted on 173.208.252.207 (Datashack, US).

rzmanagement.ru / "Rock Zone Management" fake job offer

Another fake job offer in this long running scam:

Date:      Fri, 15 Jun 2012 23:17:59 +0900
Subject:      Job Application Pending

Hello xxxxxxxxx


Thank you for submitting your information for potential employment opportunities.
We look forward to reviewing your application,
but can not do so until you complete our internal application.

Prior to begin able to be considered, you will first need you to formally apply.
Please go here to begin the process:

http://rzmanagement.ru

Also, the following perks are potentially available:

- Paid Time Off
- Health Benefits Package
- Higher than average salaries
- Tuition Reimbursement
- Extensive 401(k)program

Please take the time to follow the directions and complete the entire application process.

******************
There is no job on offer, the idea of the spam is to get you to sign up for a credit check and some get-rich-quick schemes.

rzmanagement.ru is hosted on 91.217.162.214 (Voejkova Nadezhda, Ukraine) which hosts several other scam sites. You might want to consider blocking access to 91.217.162.0/24 if these are bothering you.

"Verizon wireless online bill" spam / savecoralz.net

This fake Verizon Wireless spam leads to malware on savecoralz.net:
Date:      Thu, 14 Jun 2012 18:20:21 +0200
From:      "AccountNotify@verizonwireless.com" [eAccountNotify@verizonwireless.com]
Subject:      Verizon wireless online bill.



   
    �
Important account information from Verizon Wireless
Your current bill for your account ending in XXXX-XX001 is now available online in My Verizon
Total Balance Due: $46.62
Scheduled Automatic Payment Date: 05/29/2012
Keep in mind that payments and/or adjustments made to your account after your bill was generated will be deducted from your automatic payment amount.

> View and Pay Your Bill

Thank you for choosing Verizon Wireless.

   

   
My Verizon is also available 24/7 to assist you with:
Viewing your usage
Updating your plan
Adding Account Members
Paying your bill
Finding accessories for your devices
And much, much more...
   


2011 Verizon Wireless
Verizon Wireless | One Verizon Way | Mail Code: 180WVB | Basking Ridge, NJ 07920
We respect your privacy. Please review our privacy policy for more information

If you are not the intended recipient and feel you have received this email in error; or if you
would like to update your customer notification preferences, please click here.
   
The malicious payload is exactly the same as used in this attackwhich is running at the same time.

UPS Spam / savecoralz.net and autosnort.net

This fake UPS spam leads to malware on savecoralz.net:

Date:      Thu, 14 Jun 2012 20:52:08 +0200
From:      "UPS Quantum View" [auto-notify@ups.com]
Subject:      Track your UPS delivery online.

Discover more about UPS:
Visit www.ups.com
Sign Up For Additional E-Mail From UPS
Read Compass Online

  

This message was sent to you at the request of ICRealtime Security Solutions LLC to notify you that the electronic shipment information below has been transmitted to UPS. The physical package(s) may or may not have actually been tendered to UPS for shipment. To verify the actual transit status of your shipment, click on the tracking link below or contact ICRealtime Security Solutions LLC directly.

Important Delivery Information

Scheduled Delivery: 09-May-2012

Shipment Detail
Ship To:
xxxxxxxxxx
CSI SECURITY
2269 JEFFERIES HWY.
WALTERBORO
SC
29488
US

Number of Packages:     1
UPS Service:     GROUND
Weight:     9.0 LBS

Tracking Number:     1ZX603R40369384687
Reference Number 1:     47479
Reference Number 2:     20872

Click here to track if UPS has received your shipment or visit
http://www.ups.com/WebTracking/track?loc=en_US on the Internet.



____2@@2@@2wowT7qQAXmBSs4ogrWusagY4wa____

� 2012 United Parcel Service of America, Inc. UPS, the UPS brandmark, and the color brown are trademarks of United Parcel Service of America, Inc. All rights reserved.
For more information on UPS's privacy practices, refer to the UPS Privacy Policy.
Please do not reply directly to this e-mail. UPS will not receive any reply message.
For questions or comments, visit Contact UPS.

This communication contains proprietary information and may be confidential.� If you are not the intended recipient, the reading, copying, disclosure or other use of the contents of this e-mail is strictly prohibited and you are instructed to please delete this e-mail immediately.
Privacy Notice
Contact UPS

Other subjects include:
Your UPS delivery tracking number.
Your UPS shipment tracking number.


The malicious payload is at [donotclick]savecoralz.net/main.php?page=2a709dab1e660eaf (report here) hosted on the following IPs:

109.164.221.176 (Swisscom, Switzerland)
46.162.27.165 (Interphone, Ukraine)

The domain autosnort.net is hosted on the same IPs and is probably also malicious.

Plain list for copy-and-pasting:

109.164.221.176
46.162.27.165
savecoralz.net
autosnort.net

Thursday 14 June 2012

Apparently FilesTube are handling tax payments now..

Apparently FilesTube are handling tax payments now.. or maybe some malware spammer has gotten their campaign confused.

Date:      Thu, 14 Jun 2012 06:14:40 +0300
From:      "FilesTube" [filestube@filestube.com]
Subject:      Tax Payment N 98426758 is failed.

Hello,


Your Federal Tax Payment ID: 08432389 has been rejected.

Return Reason Code C11 � The identification number used in the Company Identification Field is not valid.


Please, check the information and refer to Code U 56 to get details about

your company payment in transaction contacts section:



http://eftps.gov/N6936721773



CARLY BLOCK,

The Electronic Federal Tax Payment System

The link goes to a malicious page at [donotclick]sumatranajuge.ru:8080/forum/showthread.php?page=5fa58bce769e5c2c (report here) which is multihomed on the following IPs:

78.83.233.242 (Spectrum Net JSC, Bulgaria)
110.234.176.99 (Tulip Telecom, India)
173.224.209.130 (Psychz Networks, US)
213.17.171.186 (Netia SA, Poland)

Plain list for copy-and-pasting:
78.83.233.242
110.234.176.99
173.224.209.130
213.17.171.186


Related domains:
huletydyshish.ru
saprolaunimaxim.ru
seledkindoms.ru
girlsnotcryz.ru
sumatranajuge.ru

"American Airlines Order" / saprolaunimaxim.ru

This fake American Airlines spam leads to malware on saprolaunimaxim.ru:

From: "Tereasa Mcwilliams" [lourdes@petalfresh.net]
Date: 14 June 2012 01:36:47 GMT+01:00
Subject: FWD: American Airlines Order


Dear Customer,

FLIGHT NUMBER A47-282
DATE & TIME / JUNE 26, 2012, 12:148 PM
ARRIVING: NEW YORK JFK
TOTAL PRICE : 285.54 USD

Please download and print out your ticket here:
DOWNLOAD

Amercian Airlines

The malicious payload is at [donotclick]saprolaunimaxim.ru:8080/forum/showthread.php?page=5fa58bce769e5c2c (report here) which is the same as used in this attack two days ago, however since then the IPs have changed to:

78.83.233.242 (Spectrum Net JSC, Bulgaria)
173.224.209.130 (Psychz Networks, US)

The following domains and IPs are related and should be blocked if you can:
50.57.43.49
50.57.88.200
78.83.233.242
89.108.75.155
89.111.177.151
173.224.209.130
187.85.160.106
girlsnotcryz.ru
hamlovladivostok.ru
holigaansongeer.ru
huletydyshish.ru
insomniacporeed.ru
paranoiknepjet.ru
pekarniamsk.ru
piloramamoskow.ru
pistolitnameste.ru
puleneprobivaemye.ru
pushkidamki.ru
saprolaunimaxim.ru
seledkindoms.ru
spbfotomontag.ru
uzindexation.ru

Wednesday 13 June 2012

LinkedIn spam / 74.91.112.248

This fake LinkedIn spam appears to lead to a malicious payload on 74.91.112.248:

Date:      Wed, 13 Jun 2012 14:58:15 +0200
From:      "LinkedIn©" [mvclient@mediavisions.net]
Subject:      Express LinkedIn Mail

LinkedIn
REMINDERS

Invitation reminders:
• From kristen redshaw (Country General Manager at Toshiba)


PENDING MESSAGES

• There are a total of 3 messages awaiting your response. Visit your InBox now.

Don't want to receive email notifications? Adjust your message settings.

LinkedIn values your privacy. At no time has LinkedIn made your email address available to any other LinkedIn user without your permission. © 2012, LinkedIn Corporation.

The malicious payload is on [donotclick]74.91.112.248/page.php?p=88fe38de which is hosted on Nuclear Fallout Enterprises in the US.

"Your credit card is blocked" spam / seledkindoms.ru

This spam leads to malware on seledkindoms.ru:
Date:      Wed, 13 Jun 2012 05:27:07 -0500
From:      Michel Boudreaux via LinkedIn [member@linkedin.com]
Subject:      Your credit card is blocked

Dear Client,



CAUTION: Your credit card is blocked!



With your credit card was removed USD 58,05

Possibly illegal transaction!



VIEW YOUR STATEMENT





Immediately contact your bank .

Best Wishes, VISA Customer Services.


The malicious payload is at [donotclick]seledkindoms.ru:8080/forum/showthread.php?page=5fa58bce769e5c2c hosted on the following IPs:

50.57.43.49 (Slicehost, US)
89.108.75.155 (Agava Ltd, US)

Here's another spam with the same payload:

Date:      Wed, 13 Jun 2012 06:21:51 +0200
From:      "Classmates . com" [classmatesemail@accounts.classmates.com]
Subject:      clongmore, Please confirm your email address with Classmates

        Help us ensure your Classmates� notifications   
      
      
      
Hi xxxxxxxxxx,
Thanks for joining Classmates�. Please click the button below to help us ensure future email delivery.
Yes, this is xxxxxxxxxx �
Not xxxxxxxxxx, please click here.
      
   
   
Your account details
Registration Number: 3164106744
Email Address: xxxxxxxxxx
Your Password: 534B962E Change password
   
   
   
You can change your password to whatever you want.

Change it now �
   
      
      
   
    Tips on finding the posts, photos and stories that people
are sharing with your community.
      
      
    TO PROTECT YOUR PRIVACY:
Do not forward this email to anyone not authorized by you to access your profile. For more information, see our Privacy Policy.

You are receiving this email as part of your Memory Lane membership.

We are unable to respond to messages sent to this automated email address, so if you have questions or have received this message in error, visit the Online Help Center.

Memory Lane, Inc., d/b/a Classmates.com 333 Elliott Ave. W., Seattle, WA 98119
� 1995-2012 Memory Lane, Inc., d/b/a Classmates.com. All Rights Reserved.  

ff