New Spam with JS Redirect Malware

8 07 2010

Our team just received a copy of the new Spam that contains the  “Delivery Status Notification Failed” Alert. The spam contains some of the old Spammer tricks to have you download the malicious payload. The HTML file includes a Java Script Payload that will try to redirect  you to an malware site.

The malicious JS Script will try to connect to malware sites that include Trojan Agents or the Fake Anti-virus attack.

Reference  Malware Info: Sophos

<Spam Sample>
From: Userxyz@msn.com
To: Allusers@msn.com

Note: Forwarded message is attached.

This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed.

cloakroomsjph@rostrvm.com

Final-Recipient: rfc957;cloakroomsjph@rostrvm.com
Action: failed
Status: 0.0.0

(See attached file: Delivery Status Notification (Failure).zip) includes the JS_REDIRECT MALWARE!

<!>

Nice Try Cyber Criminals!