Rewterz Threat Alert – DNS Compromise Attack Phishing Spam
Severity
Medium
Analysis Summary
A new finance spam campaign with HTML attachments has been discovered that utilizes Google’s public DNS resolver to retrieve JavaScript commands embedded in a domain’s TXT record. These commands will then redirect a user’s browser to a aggressive trading advertisement site, which has been reported as a scam.
All the emails were very simple emails with a HTML attachment look like this:
All the emails came from IP numbers that have previously been seen to be used by Necurs botnet. The domains listed in the from box do not track back to the IP numbers they came from.