FedEx INC report DWMYSUXV87 - Malware dowloader for P2P Gameover Zeus


From: FedEx INC [mailto:foy_bradly@yahoo.com]
Sent: Friday, September 20, 2013 2:25 AM
Subject: FedEx INC report DWMYSUXV87

FedEx Notification


Our company`s courier couldn`t make the delivery of parcel.

REASON: Postal code contains an error
DELIVERY STATUS: sort order
SERVICE: One-day shipping
NUMBER OF parcel: DWMYSUXV87
FEATURES: No



Print the attachment for details.

An additional information:

If the parcel isn`t received within 15 working days we will have the right to claim compensation from you for it`s keeping in the amount of $4.44 for each day of keeping of it.
Thank you for using our service.
FedEx Global 

Payload

Sandbox 

http://022395d.netsolhost. com/ot4sExc.exe 205.178.152.33
http://louvozza.c om/forum/viewtopic.php 174.140.169.145
http://meetandmatch. co.uk/ZjZ5jJy.exe 64.40.145.4
http://richardsonlookoutcottages .nb.ca/vkiMdL.exe 69.49.101.51
http://www.ishootyou .gr/SpvumF.exe 174.123.99.194

Zeus P2P ips

98.247.208.86
92.4.217.3
86.148.74.94
85.100.41.9
81.232.67.169
79.113.213.51
76.71.254.157
70.140.103.201
69.49.101.51
64.40.145.4
46.223.150.132
220.73.4.187
217.35.75.232
213.219.135.107
213.123.225.152
212.205.108.5
207.190.72.148
205.178.152.33
203.81.192.36
190.73.70.73
174.76.94.24
174.140.169.145
174.123.99.194
173.202.183.58
173.202.183.58
160.80.52.122
121.73.96.226
108.234.133.110
108.210.217.163
107.193.222.108

107.193.222.108


Headers

X-sender:foy_bradly@yahoo.com
X-receiver:
X-EndOfInjectedXHeaders:67
X-pp-pending:627cc214-8522-4f99-b564-55e19c383c56
Received: from nm12-vm1.bullet.mail.bf1.yahoo.com (98.139.213.38) by
xx with Microsoft SMTP Server id 14.1.438.0;
 Fri, 20 Sep 2013 07:27:09 +0100
Received: from [66.196.81.173] by nm12.bullet.mail.bf1.yahoo.com with NNFMP;
 20 Sep 2013 06:24:47 -0000
Received: from [98.139.212.198] by tm19.bullet.mail.bf1.yahoo.com with NNFMP;
 20 Sep 2013 06:24:47 -0000
Received: from [127.0.0.1] by omp1007.mail.bf1.yahoo.com with NNFMP; 20 Sep
 2013 06:24:47 -0000
X-Yahoo-Newman-Property: ymail-5
X-Yahoo-Newman-Id: 585745.5645.bm@omp1007.mail.bf1.yahoo.com
Received: (qmail 20509 invoked by uid 60001); 20 Sep 2013 06:24:47 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1379658287; bh=cW0ZjbyBwCAg0DXlvISgrv+JbI36mOGeN7/9nG8RIjw=; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:Message-ID:Date:From:Reply-To:Subject:To:Cc:MIME-Version:Content-Type; b=od1/g0YghRpqqxIxclHcFZYrECn2sghZOwGxswu/lu7vwlUeDye/i4QuqjRjro1qNrN5CsJiJKkRr/06Rv89eYAlq6wexOteOE0QkBWVLSDt7lmo/4IIWpKQLp2/WULK0Zp/wX89QDBXUbPwF5MIgkTsyr1k5nZo4bjveRidCCk=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
  s=s1024; d=yahoo.com;
  h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:Message-ID:Date:From:Reply-To:Subject:To:Cc:MIME-Version:Content-Type;
  b=ghJNqIm0WudHdNE4Q4JF+RC4fwwiqTcot+nfw9rFpdmunRF8a9JXy/D8MszhQPhSzMeM7fLTi1wma9rMWhIH/WBsfVBCsfIid+NO7T9DtsHnDhwkO86zBbbhMedrUoWUMQ2nqadxxYC+IYKCIhAEgWBoZnLrCnQw49lgMg+b+AA=;
X-YMail-OSG: 5yyNFioVM1mMkq.HDzI84f41BQ2gp6rFippUtXXo1gVrVAe
 4OCQG4u_vezK4NguEzGlI
Received: from [190.78.172.115] by web162704.mail.bf1.yahoo.com via HTTP; Thu,
 19 Sep 2013 23:24:46 PDT
X-Rocket-MIMEInfo: 002.001,RmVkRXggTm90aWZpY2F0aW9uT3VyIGNvbXBhbnlgcyBjb3VyaWVyIGNvdWxkbmB0IG1ha2UgdGhlIGRlbGl2ZXJ5IG9mIHBhcmNlbC4gICAgICAgCiAgICAgICAgClJFQVNPTjogUG9zdGFsIGNvZGUgY29udGFpbnMgYW4gZXJyb3IgICAgICAgCkRFTElWRVJZIFNUQVRVUzogc29ydCBvcmRlciAgICAgICAKU0VSVklDRTogT25lLWRheSBzaGlwcGluZyAgICAgICAKTlVNQkVSIE9GIHBhcmNlbDogRFdNWVNVWFY4NyAgICAgICAgIApGRUFUVVJFUzogTm8gICAgICAgIAogICAgICAKICAgICAgIApQcmludCB0aGUBMAEBAQE-
X-Mailer: YahooMailWebService/0.8.157.561
Message-ID: <1379658286.20116.YahooMailNeo@web162704.mail.bf1.yahoo.com>
Date: Thu, 19 Sep 2013 23:24:46 -0700
From: FedEx INC <foy_bradly@yahoo.com>
Reply-To: FedEx INC <foy_bradly@yahoo.com>
Subject: FedEx INC report DWMYSUXV87
To:

CC: 
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="958549312-2053415236-1379658286=:20116"
Return-Path: foy_bradly@yahoo.com
X-MS-Exchange-Organization-OriginalArrivalTime: 20 Sep 2013 06:27:09.7580
 (UTC)
X-MS-Exchange-Forest-ArrivalHubServer: EXCHANGE.quantanet.local
X-MS-Exchange-Organization-OriginalClientIPAddress: 98.139.213.38
X-MS-Exchange-Organization-OriginalServerIPAddress: 172.16.63.35
X-MS-Exchange-Organization-AuthSource: EXCHANGE.quantanet.local
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Organization-MessageDirectionality: Incoming
X-MS-Exchange-Organization-Cross-Premises-Headers-Processed: EXCHANGE.quantanet.local
X-MS-Exchange-Organization-OriginalSize: 187224
X-MS-Exchange-Forest-MessageScope: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-Organization-MessageScope: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-Organization-HygienePolicy: Standard
X-MS-Exchange-Organization-Recipient-Limit-Verified: True
X-MS-Exchange-Forest-RulesExecuted: EXCHANGE
X-MS-Exchange-Organization-Rules-Execution-History: Block from sending
 external mail%%%Replies to ELC booking confirmations

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.