malware_mailの日記

個人メールアドレスに届いたマルウェアメールを記録

◎10/3

件名:INVOICE

From:FIRSTNAME LASTNAME <sales@Toドメイン> (を偽装)

本文:

Dear Sir,

PLEAS FIND ATTACHED YOUR INVOICE AS REQUESTED.

Thank you and Kind regard's

FIRSTNAME
For Techno-Packaging.

P Please consider the environment – only print this e-mail if absolutely necessary

添付ファイル:A_数字8桁.7z やA_数字11桁.7z

7zファイルの中身は、

8b00c813-0a69-4468-9203-524065ac3320.js

0f140ea3-1004-49d5-9b4f-d3227a2de902.js

など。

 

https://www.virustotal.com/#/file/8eb54b56dc1c29f9f08404ab2b96c2b3998d5b4d1fb1fafdd3e482f32fbec6f4/detection

 

https://www.virustotal.com/#/file/5a55b3513e4a77bac92e7dca071feaf9ef2406de220ccba465a9f2b863e2991e/detection

 

https://www.virustotal.com/#/file/0b22298a4965c5f60f2b13f74772ef8f8e7054fc2f42b238781d954f2741482a/detection

 

https://www.virustotal.com/#/file/b1f437acf60561f72b041cc58dad1fb0a4b8fab46517243674294bd4dc6f3f7c/detection