malware_mailの日記

個人メールアドレスに届いたマルウェアメールを記録

◎12/22

件名:Outstanding Statement

From:Prime Express Oldham <sales数字1~3桁@primeexpressuk.com>

本文:

 

Dear Customer

Your invoice is attached. Please remit payment at your earliest
convenience.

Thank you for your business –it is very much appreciated.

Sincerely,

PRIME EXPRESS TRAVEL

数字4桁 数字3桁 数字4桁

 

添付ファイル: Customer Statement (122017_数字7~10桁).7z

7zファイルの中身は、Customer Statement (122017_数字8桁).js

 

https://www.virustotal.com/#/file/34bc39aeeaeb7c0c299763a80cb6d74352b6f862f0fde9cf006d60e084202621/detection

 

https://www.virustotal.com/#/file/9db6ae9aeabf8d4b469ad345694e7c26afed51ef32ae33caa7fd7aa5551824ef/detection

 

https://www.virustotal.com/#/file/bc8ba5799130d6f8a1b45213c9a0baefd0e11648400a0ffcfb0ca8d70028ee14/detection

 

https://www.virustotal.com/#/file/d9660578b2e4928e0582792accc8fc39b74eb70b34409b7ae7610cef65f41e57/detection

 

https://www.virustotal.com/#/file/483335c1a4e42443d21c9356b608b48802ce8a67266501efb397e52be806eddf/detection