We received another piece of spam (thanks Curtis) pretending to be from the Better Business Bureau. Analysis of the file transferred (W6w8sCyj.exe) from prog.it appears to be a piece of malware (Win32/Cridex.Q) use to communicates via SSL with a C&C server.
List of domains/IP to watch for and block: ajaxworkspace.com The email looks like this: Better Business Bureau© RE: Case # 78321602 <http[:]//prog.it/EH564Bf/index.html> Dear Sirs, The Better Business Bureau has got the above mentioned complaint from one of your customers concerning their business relations with you. The details of the consumer's concern are contained in attached document. Please give attention to this case and advise us of your opinion as soon as possible. We encourage you to open the COMPLAINT REPORT to answer on this complaint. We look forward to your prompt response. Faithfully yours, ________________________________
----------- Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu |
Guy 523 Posts ISC Handler Sep 9th 2012 |
Thread locked Subscribe |
Sep 9th 2012 9 years ago |
That's pretty lame: "We encourage you to open the COMPLAINT REPORT..." Yes, Please, *PLEASE* open the attachment, pretty PLEASE? Its like they are beggin you to be a luzer.
![]() |
Anonymous |
Quote |
Sep 9th 2012 9 years ago |
Sign Up for Free or Log In to start participating in the conversation!