malware_mailの日記

個人メールアドレスに届いたマルウェアメールを記録

◎10/10

件名:Document invoice_数字4~5桁_sign_and_return.pdf is complete

From:RightSignature.com <documents@rightsignature.com> (を偽装)

MIMEバウンダリ文字列誤りで本文も添付ファイルも見えませんが、

メールソースから本来の内容を抜き出すと

本文:

Hello,

This document has been signed and is now complete.

Filename: invoice_数字4~5桁_sign_and_return.pdf
Reference #: 0FB40360DA0B5FA1364D91
Subject: Please sign
Message: Please sign this document.

For your convenience, a pdf of the completed document is attached to this email.


Thank you for using RightSignature!


--

RightSignature is the easiest, fastest way to get documents signed.
RightSignature LLC, 8 E Figueroa St., Santa Barbara, CA 93101
ttps://RightSignature.com/ | support@rightsignature.com

 

 添付ファイル:invoice_数字4~5桁_sign_and_return.7z

 7zファイルの中身は、invoice_別の数字5桁_sign_and_return.vbs

https://www.virustotal.com/#/file/1bc29aed4bafe13a30f92c90c2f94743baa20c8d7032fe81c425ad1375ec21f1/detection

 

https://www.virustotal.com/#/file/544054a4d329103ac3deb0a363012fa1172312d4dff5579cb99d3a0c7dff7655/detection

 

https://www.virustotal.com/#/file/f9aa7f7038e2a9c1a761fa26e18a3cf92863393e4052361e4a4ba1aa92eca7e9/detection

 

https://www.virustotal.com/#/file/6efc84b593711f4c6c641985a53a74e533d6b086e9b2c18b3deae7c812b8d3b5/detection

 

https://www.virustotal.com/#/file/5da166f4676bd973cea79fa2fba4588b55d8b3772efffec147747606502508c4/detection