IRS, NACHA, Etc. Mal-spam
ID: d4d9be2a-b09d-55fd-b091-782fc38938c2
STIX ID: report--d4d9be2a-b09d-55fd-b091-782fc38938c2
Feed Name: Zscaler Security Research Blog
A widespread mal-spam campaign impersonating the IRS used numerous URL shorteners (e.g., shortn.me, ur.ly and others) to chain redirects to obfuscated JavaScript that led to the Blackhole exploit kit and ultimately a Zeus-like banking trojan drop. The campaign was distributed through the Cutwail/Pushdo botnet, produced thousands of shortened URLs to avoid detection, and includes an observed drop with MD5 8a5bf0dd71a1b8ea8155963b252e2105 (VirusTotal: 13/42 at time of report).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
