malware_mailの日記

個人メールアドレスに届いたマルウェアメールを記録

◎9/8

件名:Microsoft Store E-invoice for your order #数字10桁

From:Microsoft <do_not_reply@eu.microsoft.com> (を偽装)

本文:


Dear Customer,
Thank you for shopping with Microsoft Store

Please find attached or download your official Microsoft Store Invoice.
Please retain a copy of this invoice for your records. Your Microsoft
invoice may also be required to obtain warranty services.

Thank you

Microsoft Store 2017

downloadのところに 種々のドメイン/MS_INV_1046.7z へのリンク

https://www.virustotal.com/#/url/b4e6df34da0ad4a05d99894fec2f66ea5dff6b37470ca2ce6d5382f104f53930/detection

https://www.virustotal.com/#/url/8deb208979a3b31f9c6448f95bc5c6000937d5156e793adf8da9e0df594d2194/detection

二つ目は403 Forbidden

一つ目はダウンロードできて、

https://www.virustotal.com/#/file/958569e5942e3e4aa2df592f1c2cdd24cf187a237a0073c6ef1462a6c89a8590/detection

 7zの中身はMS_INV_1046.vbs

https://www.virustotal.com/#/file/39d986b3a62f4d1b2e43c8295a2a645187e08417b6c0d2d8b08a9f7e75343936/detection

 

添付ファイル:MS_INV_数字4桁.7z

https://www.virustotal.com/#/file/97963e743919d842fb3bd0f662d0da82c9bf52f994fa53264c1dd6a81f1b53a9/detection

 

7zの中身は、MS_INV_2318.vbs

https://www.virustotal.com/#/file/c31f0734507ffd134196969ed4561d77efe0acd0f0897dcf64f8266573bbec50/detection