Faked 'Pearl UK Summer Offer'

Inhalt: 

NetRange: 66.119.58.0 - 66.119.58.255
CIDR: 66.119.58.0/24
CustName: Mountain West Technology Networks
Country: US

sent in:

27/02/2015 12:50:44: [qSheff] SPAM, queue=q1425037843-438492-13977, recvfrom=66.119.58.181, from=`maikel.theunissen@pearleurope.com', to=`localuser@tld', subj=`Pearl Summer Offer Sheet', size=22320,

Dear Customer,

Please find attached a copy of the Summer Offer sheet which we've
extended to the end of February!

To place an order please contact a member of the UK sales team.

Kind regards,

The UK Sales Team

Free Phone: 00800 8424 9328

Mike Truscott - Sales Manager UK

Tel: 07710 842822

Jason Allum - Southern Area Sales Manager

Tel: 07766 733322

...
Content-Transfer-Encoding: base64
Content-Type: application/zip;
name="Pearl UK Summer Offer Sheet 2015.zip"
Content-Disposition: attachment;
filename="Pearl UK Summer Offer Sheet 2015.zip";
size=12152

LibClamAV debug: Recognized ZIP file
LibClamAV debug: cache_check: b656af0460e7c207216059eef4e2c9f1 is negative
LibClamAV debug: in cli_unzip
LibClamAV debug: cli_unzip: central @2f10
LibClamAV debug: cli_unzip: ch - flags 0 - method 8 - csize 2ece - usize 6c00 - flen 24 - elen 0 - clen 0 - disk 0 - off 0
LibClamAV debug: cli_unzip: ch - fname: Pearl UK Summer Offer Sheet 2015.exe
LibClamAV debug: cli_unzip: lh - ZMDNAME:0:Pearl UK Summer Offer Sheet 2015.exe:27648:11982:eb8e121d:8:1:1
LibClamAV debug: CDBNAME:CL_TYPE_ZIP:11982:Pearl UK Summer Offer Sheet 2015.exe:11982:27648:0:1:3951956509:(nil)
LibClamAV debug: cli_unzip: extracted to /tmp/clamav-e7087e9ca0d61ee485ce06c2e9c1c36d.tmp/zip.000
LibClamAV debug: in cli_magic_scandesc (reclevel: 1/16)
LibClamAV debug: Recognized MS-EXE/DLL file
LibClamAV debug: cache_check: f952fc5b741c907acedcb8e3974f9175 is negative
LibClamAV debug: in cli_peheader
LibClamAV debug: versioninfo_cb: type: 10, name: 1, lang: 418, rva: 5260
LibClamAV debug: cli_peheader: parsing version info @ rva 5260 (1/1)
LibClamAV debug: VersionInfo (64fe): 'CompanyName'='Sunway Inc.' - VI:43006f006d00700061006e0079004e0061006d00650000000000530075006e00770061007900200049006e00
LibClamAV debug: VersionInfo (6536): 'FileDescription'='Sunway Installer' - VI:460069006c0065004400650073006300720069007000740069006f006e0000000000530075006e00770061007900200049006e007300740061006c006c006500
LibClamAV debug: VersionInfo (6582): 'FileVersion'='1.3.5.5' - VI:460069006c006500560065007200730069006f006e000000000031002e0033002e003500
LibClamAV debug: VersionInfo (65b2): 'InternalName'='Sunway Update' - VI:49006e007400650072006e0061006c004e0061006d0065000000530075006e0077006100790020005500700064006100
LibClamAV debug: VersionInfo (65ee): 'LegalCopyright'='Copyright 2007-2010 Sunway Inc.' - VI:4c006500670061006c0043006f007000790072006900670068007400000043006f007000790072006900670068007400200032003000300037002d0032003000310030002000530075006e00770061007900200049006e00
LibClamAV debug: VersionInfo (6652): 'OriginalFilename'='SunwayInfo.exe' - VI:4f0072006900670069006e0061006c00460069006c0065006e0061006d0065000000530075006e0077006100790049006e0066006f002e0065007800
LibClamAV debug: VersionInfo (669a): 'ProductName'='Sunway Update' - VI:500072006f0064007500630074004e0061006d00650000000000530075006e0077006100790020005500700064006100
LibClamAV debug: VersionInfo (66d6): 'ProductVersion'='1.3.5.5' - VI:500072006f006400750063007400560065007200730069006f006e00000031002e0033002e003500
LibClamAV debug: Matched signature for file type PE
LibClamAV debug: hashtab: Freeing hashset, elements: 8, capacity: 64
LibClamAV debug: Pearl UK Summer Offer Sheet 2015.exe.UNOFFICIAL found
LibClamAV debug: FP SIGNATURE: f952fc5b741c907acedcb8e3974f9175:27648:Pearl UK Summer Offer Sheet 2015.exe.UNOFFICIAL
LibClamAV debug: cli_magic_scandesc: returning 1 at line 2470
LibClamAV debug: FP SIGNATURE: b656af0460e7c207216059eef4e2c9f1:12152:Pearl UK Summer Offer Sheet 2015.exe.UNOFFICIAL
LibClamAV debug: cli_magic_scandesc: returning 1 at line 2470
Pearl UK Summer Offer Sheet 2015.zip: Pearl UK Summer Offer Sheet 2015.exe.UNOFFICIAL FOUND

f952fc5b741c907acedcb8e3974f9175:27648:Pearl UK Summer Offer Sheet 2015.exe

Themenbereich: