Malware Analysis‎ > ‎

E-Mail with Phishing Links


DO NOT access URLs posted here!

You have been warned.

Various components of the information below have been replaced. If something occurs between <> characters, then it describes the data that was originally there and likely to change across messages.

 TextExample Contents
 <email@address.here> jones23@example.com
 <username> jones23
 <HexChars> 1b20c361d
  


Showing 15 items
Message SubjectSending MTADate ReceivedLink DestinationMore Info
Sort 
 
Sort 
 
Sort 
 
Sort 
 
Sort 
 
RE: Instructions UNCLASSIFIED 85.92.140.111 March 13, 2010 www.sendspace.com/file/h96uh1 -and- depositfiles.com/files/xj1wvamc4 Details 
FOR OFFICIAL USE ONLY 193.142.214.134 March 7, 2010 www.mod.gov.ge/2007/video/movie.php?l=G&v=<URL_ENCODED_DATA> Analysis 
Exclusively for <username>, -80% 115.87.105.104 February 24, 2010 <hexChars>.yaquyobiy.cn Analysis 
Important notice: Google 112.121.128.19 February 18, 2010 vippush.com/ Analysis 
DoD Roles and Missions in Homeland Security 195.22.225.5 February 12, 2010 mv.net.md/dsb/DSB.zip -or- www.sendspace.com/file/rdxgzd Analysis 
You are in a higher tax bracket 86.46.20.218 February 11, 2010 rep1032.co.uk/reports/getreport.php?email=<email@address.here>  
User <username> Brand 80% off Sale 217.197.191.21 February 10, 2010 <hexChars>.fighthot.ru/  
<username> Sale Day, save 80%! 83.248.114.212 February 10, 2010 <HexChars>.tangynext.ru/  
User <username> Brand 81% off Sale 112.135.84.79 February 10, 2010 <multiplehostnames>.sheerboth.ru/  
User <username> Brand 77% off Sale 89.41.68.225 February 9, 2010 79d6a5a8b.coatdrive.ru/  
your photos 94.252.123.84 February 9, 2010 archive.yufrte.cz/id1073bv/get.php?email=<email@address.here>  
URGENT: Your VISA VbV Password has expired! 69.89.13.239 February 8, 2010 www.visa.com.0aa5a09ce.com/index.html  
re 86.61.158.197 February 8, 2010 photosbank.rwaswq.cz/id1073bv/get.php?email=<e-mail@address.here>  
some jerk has posted your photos 200.187.95.207 February 4, 2010 photobank.tygersa.cz/id1073bv/get.php?email= <e-mail address here>  
RE: TRC 216.210.109.128 April 1, 2009 213.235.249.198/pics/trc.exe  
Showing 15 items