malware_mailの日記

個人メールアドレスに届いたマルウェアメールを記録

◎9/1

件名:New voice message 14309523681 in mailbox 143095236811 from "14309523681" <9991269090>

From:"Voicemail Service" <vmservice@Toドメイン(を偽装)>

本文:

Dear user: just wanted to let you know you were just left a 0:54 long message (number 14309523681) in mailbox 143095236811 from "14309523681" <9991269090>, on Fri, 01 Sep 2017 17:46:02 +0700 so you might want to check it when you get a chance. Thanks! --Voicemail Service

 といった内容(数字や日時部分は変化する)

添付ファイル:MSG0000000538.7z

7zの中身は

MSG0000000549.vbs

MSG0000000140.vbs

MSG0000000678.vbs

MSG0000000226.vbs

といったところ

 

それぞれ

https://www.virustotal.com/#/file/458b49ce533693a253beca0e9dac81dd4659aa3434eb007de30e05c2a2d0bcd0/detection

https://www.virustotal.com/#/file/181a9abbcf78e6f56c06c2dff127809b3227c1471d4b5ce684941902974b0280/detection

https://www.virustotal.com/#/file/6913abf941950c9dab0a3de08557d485f5a3f7d8d67da10ec74c1671c18ef2e4/detection

https://www.virustotal.com/#/file/666323b85a400a94aec1b2c32c4afa1d156cd18c3e5d657eb8f828e11c24aa6f/detection