Another spam with a nice attachment from the XimianEvolution spammer.
VT hadn't seen this one before:
https://www.virustotal.com/en/file/583f1fa9645a1e285f5659bab988404da907171a8033
1cfedc19da29c321b078/analysis/1413934061/
Get your copy here:
http://www.filedropper.com/daticket
ID'd variously as: Aspxor / Zortob / Kuluoz / PWSZbot / Weelsof-IV
Pathetic detection rate, given I've been sitting on it for 24 hours.
Here is your list of Anti-virus FAILURES:
AVware Agnitum AhnLab-V3 Antiy-AVL
Avira Baidu-International Bkav CAT-QuickHeal
CMC ClamAV Comodo Ikarus
Jiangmin K7AntiVirus K7GW Kingsoft
Malwarebytes NANO-Antivirus Norman Qihoo-360
Symantec TheHacker TotalDefense TrendMicro
VIPRE Zillya Zoner nProtect
=========================================
Return-Path:
Received: from circlair.com ([156.1.40.30])
From: "Delta Air Lines"
X-Mailer: XimianEvolution1.4.6
Dear Customer,
ELECTRONIC TICKET / ET-29778907
SEAT / 53E/ZONE 2
DATE / TIME 19 NOVEMBER, 2014, 11:25 AM
ARRIVING / Toledo
FORM OF PAYMENT / CC
TOTAL PRICE / 231.43 USD
REF / KE.4221 ST / OK
BAG / 4PC
Your ticket is attached.
You can print your ticket.
Thank you
Delta Air Lines.
=========================================
Who the hell wants to fly these days anyways? And risk catching ebola?
--- NewsGate v1.0 gamma 2
* Origin: News Gate @ Net396 -Huntsville, AL - USA (1:396/4)
|