malware_mailの日記

個人メールアドレスに届いたマルウェアメールを記録

◎9/21

件名:Invoice RE-2017-09-21-数字5桁

From:Amazon Marketplace <ランダム英大小文字列@marketplace.amazon.co.uk> (を偽装)

本文:

------------- Begin message -------------

Dear customer,

We want to use this opportunity to first say "Thank you very much for your purchase!"

Attached to this email you will find your invoice.

Kindest of regards,
your Amazon Marketplace

==

 

[commMgrTok:ランダム英大文字列]

------------- End message -------------

For Your Information: To help arbitrate disputes and preserve trust and safety, we retain all messages buyers and sellers send through Amazon.co.uk. This includes your response to the message below. For your protection we recommend that you only communicate with buyers and sellers using this method.

Important: Amazon.co.uk's A-to-z Guarantee only covers third-party purchases paid for through our Amazon Payments system via our Shopping Cart or 1-Click. Our Guarantee does not cover any payments that occur off Amazon.co.uk including wire transfers, money orders, cash, check, or off-site credit card transactions.

We want you to buy with confidence whenever you purchase products on Amazon.co.uk. Learn more about Safe Online Shopping (ttp://www.amazon.co.uk/gp/help/customer/display.html?nodeId=11081621) and our safe buying guarantee (ttp://www.amazon.co.uk/gp/help/customer/display.html?nodeId=3149571).

 

[commMgrTok:ランダム英大文字列]

 

添付ファイル:RE-2017-09-21-数字5桁.7z

7zファイルの中身はRE-2017-09-21-別の数字5桁.vbs

 

https://www.virustotal.com/#/file/1421538fda482d7025227574edfa44b3a24f9a3903ddab6bca61534edbb04181/detection

 

https://www.virustotal.com/#/file/8bde04b34fec5a2c7d4145d23eb689cc79a5d6442c29ebe6a964e43dcf11eb75/detection

 

https://www.virustotal.com/#/file/3efea875628d5f96061e5664205f44f9e66bae62c0635b4c7cb5109ddd224525/detection

 

https://www.virustotal.com/#/file/eed377efac91c057c6b9f61831df1f68e50211d7d8684bfdd9faa79542c14bca/detection

 

https://www.virustotal.com/#/file/b5bba9b078d5d8d842856371841e241fd39381dda39793bffa07229f6620fc5a/detection