Удалить вирус на сайте ardi-design.ru
Здравствуйте.
Return-path: <clemonafeedback@fedpol.admin.ch>
Envelope-to: abuse@hetzner.de
Delivery-date: Thu, 21 Jan 2016 14:39:10 +0100
Received: from [162.23.32.11] (helo=mail13.admin.ch)
by mail.hetzner.company with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.80)
(envelope-from <clemonafeedback@fedpol.admin.ch>)
id 1aMFS6-0005pe-Nk
for abuse@hetzner.de; Thu, 21 Jan 2016 14:39:10 +0100
Received: from mail01.admin.ch (mail01.admin.ch [162.23.97.166])
(using TLSv1 with cipher CAMELLIA256-SHA (256/256 bits))
(Client did not present a certificate)
by mail13.admin.ch (mailout) with ESMTPS id 7060A200A04F
for <abuse@hetzner.de>; Thu, 21 Jan 2016 14:37:54 +0100 (CET)
by mail03.admin.ch (mailhost) with ESMTPS id 131A1400A085
for <abuse@hetzner.de>; Thu, 21 Jan 2016 14:37:54 +0100 (CET)
Received: from sb00111a.adb.intra.admin.ch ([169.254.3.213]) by
SB00102A.adb.intra.admin.ch ([10.135.87.102]) with mapi id 14.03.0266.001;
Thu, 21 Jan 2016 14:37:53 +0100
From: <clemonafeedback@fedpol.admin.ch>
To: <abuse@hetzner.de>
Subject: URGENT Crypto-Malware distribution by ardi-design.ru cle-141181
Thread-Topic: URGENT Crypto-Malware distribution by ardi-design.ru
cle-141181
Thread-Index: AdFUUL6StFjUjlWQRYa+8mhexMwNbQ==
Date: Thu, 21 Jan 2016 13:37:53 +0000
Accept-Language: de-CH, en-US
Content-Language: de-DE
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.135.87.13]
Content-Type: multipart/alternative;
boundary="_000_50C0A5E8A6EC5243BBDC3B3E2F2644BB9406C9BCsb001 11aadbintr_"
MIME-Version: 1.0
X-TM-AS-MML: disable
X-Spam-Level: 4.7 (****)
Message-ID: 1aMFS6-0005pe-Nk@mail.hetzner.company
Delivered-To: vmail-abuse@hetzner.de
--_000_50C0A5E8A6EC5243BBDC3B3E2F2644BB9406C9BCsb00111aadbintr_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Dear Madam/Sir
Today, a spam wave was sent to various persons. The spam email impersonated=
the federal office of police and informed the recipients that a court docu=
ment is ready for
the download on the website ardi-design.ru (full URL
ardi-design.ru/= ZTzo7F3j/VwzfSU.php), which is a copy of the offical website of the Federal=
Office of Police. On the website, the user has to enter a code and the dow=
nload of a zip file starts from disk.yandex.ru<
disk.yandex.ru>
If the user does start the download of the alleged court documents and open=
s the zip file, his computer is infected with the malware Cryptolocker.
We kindly request to take appropriate action
--_000_50C0A5E8A6EC5243BBDC3B3E2F2644BB9406C9BCsb00111aadbintr_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left:=
#800000 2px solid; } --></style>
</head>
<body>
<font face=3D"Arial" size=3D"2"><span style=3D"font-size:11pt;">
<div>Dear Madam/Sir</div>
<div> </div>
<div> </div>
<div>Today, a spam wave was sent to various persons. The spam email imperso=
nated the federal office of police and informed the recipients that a court=
document is ready for</div>
<div>the download on the website ardi-design.ru (full URL<font face=3D"Time=
s New Roman" size=3D"3"><span style=3D"font-size:12pt;"> </span></font><a h=
ref=3D"
ardi-design.ru/ZTzo7F3j/V... color=3D"#0563C1"><=
u>
ardi-design.ru/ZTzo7F3j/V...,
which is a copy of the offical website of the Federal Office of Police. On =
the website, the user has to enter a code and the download of a zip file st=
arts from <a href=3D"
disk.yandex.ru"><font color=3D"#0563C1"><u>disk=
.yandex.ru</u></font></a></div>
<div><font face=3D"Times New Roman" size=3D"3"><span style=3D"font-size:12p=
t;"> </span></font></div>
<div>If the user does start the download of the alleged court documents and=
opens the zip file, his computer is infected with the malware Cryptolocker=
.</div>
<div> </div>
<div>We kindly request to take appropriate action</div>
<div> </div>
<div> </div>
<div style=3D"margin-bottom:10pt;">Yours Sincerely</div>
<div style=3D"margin-bottom:10pt;">CYCO—Cybercrime Coordination Unit =
Switzerland</div>
<div><font size=3D"3"><span style=3D"font-size:12pt;"><a href=3D"
www=
.kobik.ch"><font size=3D"2" color=3D"#0563C1"><span style=3D"font-size:10pt=
;"><u>
www.kobik.ch</u></span></font> </a></span></font
></div>
<div><font face=3D"Times New Roman" size=3D"3"><span style=3D"font-size:12p=
t;"> </span></font></div>
<div><font face=3D"Times New Roman" size=3D"3"><span style=3D"font-size:12p=
t;"> </span></font></div>
</span></font>
</body>
</html>
--_000_50C0A5E8A6EC5243BBDC3B3E2F2644BB9406C9BCsb00111aadbintr_--