Advertisement
malwageddon

FAX phishing email campaign

Jul 18th, 2013
142
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.40 KB | None | 0 0
  1. NOTE: Information is based on a sample of FAX phishing email seen on 2013-07-18
  2.  
  3. -------------------------------------------------------------------
  4. Received: from (192.168.1.13) by livenirvana.com (75.144.236.193)
  5. From: "FAX" <fax@your-fax.com>
  6. Subject: New incoming fax
  7. Attachment: Content-Type: application/zip; name="fax01001016503.zip"
  8.  
  9. Body:
  10.  
  11. Dear Customer,You have received a new fax.
  12. Date/Time: 2013:07:18 10:13:51
  13. Number of pages:5
  14. Received from: 0845 3000 000
  15. Regards,FAX
  16.  
  17. -------------------------------------------------------------------
  18.  
  19. MD5s
  20. ZIP - afbe8430f82b7cb051c24036b19d4ebc
  21. EXE - 52bfde0a7073611ab3f952168eb88308 VT (8/46) https://www.virustotal.com/en/file/625536d555e36144e32b33f294c250c7aaec4d040efa75cabb0e8ca700c76c3b/analysis/
  22.  
  23. GETs:
  24. ftp.alenetoo.com/2YLt.exe
  25. getreadytochangeyourlife.com/wJwU.exe
  26. www.artwork.1stpads.com/ijiK.exe
  27. www.bansontrade.co.uk/ULiC.exe
  28.  
  29. POSTs:
  30. dreamonseniorswish.org/forum/viewtopic.php
  31. nursenextdoor.com/forum/viewtopic.php
  32. phonebillssuck.com/forum/viewtopic.php
  33. prospexleads.com/forum/viewtopic.php
  34.  
  35. additional sending hosts:
  36. Received: from (192.168.1.186) by gil.com.au (216.255.10.52)
  37. Received: from (192.168.1.19) by ponyexpress.net (209.113.197.194)
  38. Received: from (192.168.1.116) by afes.com (108.176.1.241)
  39. Received: from (192.168.1.188) by compufort.com (41.215.215.183)
  40. Received: from (192.168.1.29) by unb.ca (77.30.46.33)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement