More NACHA spam, this time pointing to cgredret.ru (which we’ve seen before) which delivers a malicious payload.
Date: Thu, 22 Dec 2011 03:37:35 +0530
From: “NACHA”
To: clongmore@arrowuk.com
Subject: ACH Transfer rejectedACH transaction, initiated from your checking account, was canceled.
Canceled transaction:
Transfer ID: B2793447923US
Transfer Report: View
GALINA Gunter
NACHA – The Electronic Payment Association
cgredret.ru has moved since yesterday and is now on 79.137.237.68. Unsurprisingly, it is now on Digital Network JSC in Russia (aka DINETHOSTING). Block access to 79.137.224.0/20 if you can.
Leave a reply