2006/12/26

medsupplysurpluse.com

From GenericMedications@medsupplysurpluse.com I've received this message:

This is an automatically generated Delivery Status Notification. Delivery to the following recipients failed. dddgetin@medisaie.com


I have never sended this mmessage.. I think is another solution by spammers.

Also, this message contains an html page with this trojan: Js/Redir.AH.

This trojan has this damages:

JS.Redir.ah is a malicious JavaScript that is usually embedded in an HTML page that arrives on a system as an attachment to a spammed email message.

Once the recipient opens the attachment, this script loads the web page http://{BLOCKED}ghtBooksDirect.info/?b40eF7ce8fc50T34b5400d5593Bf11ea. The said web page contains another malicious JavaScript.


From aladdin