Comments

More Mailchimp abuse fake invoice delivering Gootkit banking trojan — 5 Comments

  1. Thanks for posting this! We have just learnt that one of our contacts has been spoof invoiced in our name: how can we be sure that our MailChimp lists have not been compromised/hacked?

    • check with mailchimp. If you use WordPress, check the mailchimp plugin & see what it is sending. I think there should be some record of what has been sent in your mailchimp dashboard

  2. same attack from Jill… using a subject I am genuinely interested in.
    worse – it fools the spamcop auto identifiers making it return “internal IP prolem” so that it can’t be reported to domain admins.
    **** copy/paste of headers and body:

    Delivered-To: carlosfcgcunha@gmail.com
    Received: by 10.80.131.71 with SMTP id 65csp1916851edh;
    Thu, 22 Feb 2018 04:00:19 -0800 (PST)
    X-Google-Smtp-Source: AH8x227iCgObm7EJyLFr3/FzaA+3hG3RQeC9LYxc5uVw6UqNIMqtwsDq0sg7bv3KWGw+F+7S88cL
    X-Received: by 2002:a25:6a57:: with SMTP id f84-v6mr4335799ybc.39.1519300819811;
    Thu, 22 Feb 2018 04:00:19 -0800 (PST)
    ARC-Seal: i=1; a=rsa-sha256; t=1519300819; cv=none;
    d=google.com; s=arc-20160816;
    b=qjoaILovXsSr5F8LxpTnHogmwUn+lrl3vBv8ba9fOUCjTpN6KVwj/bCR681LdZIykG
    HKkKwMcp3/IExkIpAYTQfRrACswVviDJOqeIoCIERmou8TMiUv0BktiJHDCAwSVVl8he
    eEx8hPqcVFowfZMoM+iRk+XK8LDe7bBC9tN5YW3tSy30uGWnSZ9OhTGRxW43e2fbVdaw
    g2e5MB89CDOMH79kMskxSc+okDoli/lSSuZSFyoE1DNr9W2iik4IlXUurNCGx4fUImJF
    vbwQZEo3GqTaMovIFBXHllNUL+jxQUGmFj93vBVtB+6UXIQep1Ox7GuuZSNU35vQxDTZ
    kSjQ==
    ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
    h=mime-version:sender:list-unsubscribe:list-id:feedback-id:message-id
    :date:to:reply-to:from:subject:dkim-signature:dkim-signature
    :arc-authentication-results;
    bh=xxcHxWUUuUfX0Gbz1MTK7vBA8/PxhkbxppyKVjCXWfE=;
    b=QrIcFnJNpDlLAECx9LImfcJfUufzGyKAjr2EW/woUA6IONbOdT9tKc6YNyySa5U55d
    V4xFiTTukUxOcE8d7bKP6Kmuunddbb72dwCa0FSBwClEuCLNfvfKg+K99Jdd+lslVYl7
    ylT5rVlG2gWZt8XxOtQLXa51uN06f+z+Kjjv1R2JtN8uq67+2tilfLv0IKkdFzmSGVDa
    tcHca2YqEyocBlhbLcZFgvQFvSD06l3lZPq7TCOv5NW94PtACt+cbViVWbIDXGJJ8jKS
    69QWXGhwbv1kTCJMI3dzJUAnx5TkypzneiHlQTUd0q5gkDs+Ti9RDFqtQ9rMk09VO7jz
    Eypw==
    ARC-Authentication-Results: i=1; mx.google.com;
    dkim=pass header.i=@mail47.sea21.rsgsv.net header.s=k1 header.b=ybHAHW7U;
    dkim=pass header.i=@gmail.mcsv.net header.s=k1 header.b=Tah5PGwB;
    spf=pass (google.com: domain of bounce-mc.us2_4542142.2583569-carlosfcgcunha=gmail.com@mail47.sea21.rsgsv.net designates 148.105.12.47 as permitted sender) smtp.mailfrom=bounce-mc.us2_4542142.2583569-carlosfcgcunha=gmail.com@mail47.sea21.rsgsv.net
    Return-Path:
    Received: from mail47.sea21.rsgsv.net (mail47.sea21.rsgsv.net. [148.105.12.47])
    by mx.google.com with ESMTPS id g206si2087325ywc.687.2018.02.22.04.00.19
    for
    (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
    Thu, 22 Feb 2018 04:00:19 -0800 (PST)
    Received-SPF: pass (google.com: domain of bounce-mc.us2_4542142.2583569-carlosfcgcunha=gmail.com@mail47.sea21.rsgsv.net designates 148.105.12.47 as permitted sender) client-ip=148.105.12.47;
    Authentication-Results: mx.google.com;
    dkim=pass header.i=@mail47.sea21.rsgsv.net header.s=k1 header.b=ybHAHW7U;
    dkim=pass header.i=@gmail.mcsv.net header.s=k1 header.b=Tah5PGwB;
    spf=pass (google.com: domain of bounce-mc.us2_4542142.2583569-carlosfcgcunha=gmail.com@mail47.sea21.rsgsv.net designates 148.105.12.47 as permitted sender) smtp.mailfrom=bounce-mc.us2_4542142.2583569-carlosfcgcunha=gmail.com@mail47.sea21.rsgsv.net
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=k1; d=mail47.sea21.rsgsv.net; h=Subject:From:Reply-To:To:Date:Message-ID:List-ID:List-Unsubscribe:Sender: Content-Type:MIME-Version; i=jill=3Dinfinitycottage.com@mail47.sea21.rsgsv.net; bh=xxcHxWUUuUfX0Gbz1MTK7vBA8/PxhkbxppyKVjCXWfE=; b=ybHAHW7UVjCe2/XYP1LA5950pTOQuU185GPKZ0rr3mYrkrkyRvpMDu3+uY8wGaQHz+/IyVYVUxSv
    s5YXNeZaRSrAQQGMFc9sN9zX2rDpkoyH0eCVugfSjn65VKMFvndNl6wbZAPSJfwg9vDtisQppatc
    ns5CQfuW3IlMJv1sRVk=
    DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=k1; d=gmail.mcsv.net; h=Subject:From:Reply-To:To:Date:Message-ID:Feedback-ID:List-ID: List-Unsubscribe:Sender:Content-Type:MIME-Version; bh=xxcHxWUUuUfX0Gbz1MTK7vBA8/PxhkbxppyKVjCXWfE=; b=Tah5PGwBL0OCd82SyEeTLYV4V4EyHYJp62IFAfj3aFJHLWZ0H+JjhDvUiocpJV0AEtMbrzlpE0x1
    3eXg+PMbyiwq+CmXpZQH3240v+yrAcC/pAVbvL+avJN6kJ1icAOpHcf4w0L6Z7WKGQaoi20Rs6DJ
    CgysT7IV1gbZ4hb48s8=
    Received: from (127.0.0.1) by mail47.sea21.rsgsv.net id hhqod62ddl4q for ; Thu, 22 Feb 2018 11:59:57 +0000 (envelope-from )
    Subject: Invoice for Company: 22/02/2018
    From: Infinity Cottage
    Reply-To: Infinity Cottage
    To: “World Animal Day | 4 October”
    Date: Thu, 22 Feb 2018 11:59:57 +0000
    Message-ID:
    X-Mailer: MailChimp Mailer – **CID2f31f7b73b45d51b0213**
    X-Campaign: mailchimp0cec3aca2a26beb86125d769a.2f31f7b73b
    X-campaignid: mailchimp0cec3aca2a26beb86125d769a.2f31f7b73b
    X-Report-Abuse: Please report abuse for this campaign here: http://www.mailchimp.com/abuse/abuse.phtml?u=0cec3aca2a26beb86125d769a&id=2f31f7b73b&e=45d51b0213
    X-MC-User: 0cec3aca2a26beb86125d769a
    Feedback-ID: 4542142:4542142.2583569:us2:mc
    List-ID: 0cec3aca2a26beb86125d769amc list
    X-Accounttype: pd
    List-Unsubscribe: ,
    Sender: Infinity Cottage
    x-mcda: FALSE
    Content-Type: multipart/alternative; boundary=”_———-=_MCPart_170323307″
    MIME-Version: 1.0

    –_———-=_MCPart_170323307
    Content-Type: text/plain; charset=”utf-8″; format=”fixed”
    Content-Transfer-Encoding: quoted-printable

    ** Invoice for World Animal Day | 4 October
    ————————————————————
    Hello,
    Please view/download (hxxps://vnntravel.com/company%20invoice%202-22-2018.z=
    ip) company invoice.
    Or you can find your invoice here (hxxps://menvisinhbifina.com/22.02.18.doc=
    ) .

    Regards,

    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
    =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
    Copyright =C2=A9 2018 Infinity Cottage, All rights reserved.

    Our mailing address is:
    Infinity Cottage
    jill@infinitycottage.com
    PO Box 1367
    Sale, Victoria 3853
    Australia

    Want to change how you receive these emails?
    You can ** update your preferences (https://infinitycottage.us2.list-manage=
    .com/profile?u=3D0cec3aca2a26beb86125d769a&id=3Dfd6ccf95d8&e=3D45d51b0213)
    or ** unsubscribe from this list (https://infinitycottage.us2.list-manage.c=
    om/unsubscribe?u=3D0cec3aca2a26beb86125d769a&id=3Dfd6ccf95d8&e=3D45d51b0213=
    &c=3D2f31f7b73b)
    .
    –_———-=_MCPart_170323307
    Content-Type: text/html; charset=”utf-8″
    Content-Transfer-Encoding: quoted-printable

    Copyright =C2=A9 2018 Infinity Cottage, All=
    rights reserved.

    Our mailing address is:
    Infinity Cottagejill@infinitycottage.comPO Box 1367Sale, Victoria 3853 AustraliaAdd us to your address book

    Want to change how you receive these emails?
    You can update=
    your preferences
    or unsubscribe from this list.

    **** end of copy/paste

Leave a Reply

Your email address will not be published. Required fields are marked *