malware_mailの日記

個人メールアドレスに届いたマルウェアメールを記録

◎12/22

件名:Emailing: IMG_20171221_数字9桁, IMG_20171221_数字9桁, IMG_20171221_数字9桁_HDR

From:FIRSTNAME <FIRSTNAME@Toドメイン> (を偽装)

本文:

 


Your message is ready to be sent with the following file or link
attachments:

IMG_20171221_数字9桁
IMG_20171221_数字9桁
IMG_20171221_数字9桁_HDR


Note: To protect against computer viruses, e-mail programs may prevent
sending or receiving certain types of file attachments. Check your e-mail
security settings to determine how attachments are handled.

 

添付ファイル: IMG_20171221_一つ目の数字9桁.7z

7zファイルの中身は、IMG_20171221_別の数字9桁.js

 

https://www.virustotal.com/#/file/64aa532e071dad4255e4701640e8cb70da4612f68727ca00dc36e4e04cc85968/detection

 

https://www.virustotal.com/#/file/0170d66125d92ca2eed94e0535b4c798db3af7000cdbc285ff6638165fea86b3/detection

 

https://www.virustotal.com/#/file/76e1c8153caad3c1651d25701c6efdbd283c8d79e1cabe0d392e9387718de0ed/detection