Comments

invoice 8014042 October – Word doc malware — 5 Comments

  1. The payload is being hosted here
    w w w.mirafarm.ro/html/js/ bin.exe

    I’ve emailed their abuse team and asked for it to be removed.
    Malwarebytes classifies it as Backdoor.bot

  2. Subject: Test 137847Q Reject
    Subject: Test 734546V Reject
    Subject: Test 8141131O Reject

    Pattern based filters are great. Stop wasting your zombie bandwidth you retard and get a viable target.
    None of these are getting through to our mailboxes.
    Change the subject or the body and I change the filter.
    Waiting for you to stop.

Leave a Reply

Your email address will not be published. Required fields are marked *