Today’s #malware sample is in #Spanish, leveraging a #ezmlm mailing list on the back end at facturanuevagenerada [DOT[ com which does not have an associated web site – just a placeholder.
#email #SRC 62.149.155.137 assigned to #aruba.it a hosting provider over in the #EU
Of interest:
#User-Agent: #Roundcube Webmail/1.6.0
#IP is not listed as an #openProxy
#spammers #scammers #malicious #suspectfiles #malware #triage #ioc #_ioc #infosec #informationSecurity #IncidentResponce #IR #spam #infosec #infomantionSecurity #virustotal #ABUSE #emailabuse
#filescan #virustotal
1/3