malware_mailの日記

個人メールアドレスに届いたマルウェアメールを記録

◎9/21

件名:New voice message 数字11桁 in mailbox 数字12桁 from "数字11桁" <数字10桁>

From:Voicemail Service <vmservice@Toドメイン> (を偽装)
本文:

Dear user:

just wanted to let you know you were just left a 0:数字2桁 long message (number 数字11桁)
in mailbox 数字12桁 from "数字11桁" <数字10桁>, on Wed, 20 Sep 2017 19:28:34 +0200
so you might want to <a href="ttp://種々のドメイン/voice.html>check</a> it when you get a chance. Thanks!

--Voicemail Service

添付ファイル:msg数字4桁.7z

7zファイルの中身はIM数字9~10桁.vbs

 

https://www.virustotal.com/#/file/84cb45d5551860378e4f05d1557db58363a8ba317fcac0b06dc3049ec3c63833/detection

 

https://www.virustotal.com/#/file/4c91ab48220d43adb470cade60cad3e588ca42d3d37cf5b3c9894743e109e332/detection

 

https://www.virustotal.com/#/file/28a3b211328fe9058bddf876638d9efcf28f5cfc597a03dfc88ff082d614032d/detection

 

https://www.virustotal.com/#/file/5dcd319f6b7b7d78589858f31129bada850b6829600f75d61594116aecc345d1/detection

 

https://www.virustotal.com/#/file/bf1b503b2bb24f79992325d360de522156c35957ee07d9438c2a65a91c71d3fc/detection

 

https://www.virustotal.com/#/file/ac3820e0cf2c0237c9e6b46a40d86122592bbf4f7c21f65c0bd46b4cd1a90d6c/detection

広告を非表示にする