Sent: 16 January 2013 02:22The malicious payload is at [donotclick]dozakialko.ru:8080/forum/links/column.php (report here) hosted on the following IPs:
Subject: American Express Alert: Your Transaction is Aborted
Your Wed, 16 Jan 2013 01:22:07 -0100 Incoming Transfer is Terminated
Your American Express Card account retired ZUE36213 with amount of 5070 USD.
Transaction Time:Wed, 16 Jan 2013 01:22:07 -0100
Payment Due Date:Wed, 16 Jan 2013 01:22:07 -0100
One small way to help the environment – get paperless statements
Issue a payment
You currently reading the LIMITED DATA version of the Statement-Ready Information.
Switch to the DETAILED DATA version.
Thank you for your Cardmembership.
American Express Information center
126.96.36.199 (Garant-Park-Telecom, Russia)
188.8.131.52 (Proservis UAB, Lithunia)
184.108.40.206 (ip4 GmbH, Germany)
Plain list of IPs and related domains for copy-and-pasting:
Leave a reply