We shipped your crap.
Here s the tracking invoice :
http://ift.tt/2g2omJw action=download

Let us know when it arrives.
Thanks

Phishing analysis :

CLICK : http://ift.tt/2g2omJw action=download
OPEN : http://ift.tt/2fKSA0R
RESULT : Download a file called : inv11172016.doc

File analysis :

ESET-NOD32 : VBA/Kryptik.T
F-Secure : Trojan:W97M/Nastjencro.A
Fortinet : WM/Agent.5110!tr
Kaspersky : HEUR:Trojan.Script.Agent.gen
McAfee : W97M/Dropper.cu
McAfee-GW-Edition : W97M/Dropper.cu
NANO-Antivirus : Trojan.Ole2.Vbs-heuristic.druvzi
Panda : O97M/Downloader 20161117
Qihoo-360 : virus.office.gen.75
Symantec : W97M.Downloader
TrendMicro : W2KM_HANCITOR.YYSXC
TrendMicro-HouseCall : W2KM_HANCITOR.YYSXC

inv11172016.doc is a virus.

Email analysis :

NOTE : Return-Path :
NOTE : 162.252.121.130 ()
NOTE : Mime-Version : 1.0
NOTE : Content-Transfer-Encoding : 7bit
NOTE : X-Mailer : iPad Mail (11D169)
NOTE : Message-Id :
NOTE : Content-Type : text/html; charset=”utf-8″
NOTE : Received : from unknown (HELO restaurantcocotte.com) (162.252.121.130)

NOTE : RE: shipping done

http://ift.tt/2fKYsqN

Advertisements