Subject.
Auto-Generated NotificationBody.
Attention all Apex ACH System Customers!
We inform you that on October 7, 2008 a partial loss of data took place in our database. Due to this problem urgent request to take the procedure of account verification. Verification form is located here:
[link removed]
However, failure to confirm your records may result in account suspension.
This is an automated message. Please do not reply.
Apex ACH System Customer Service
Website.
Visiting the website will automatically run an excutable. A few moments later the PC will reboot and another file will be downloaded & installed on the PC. Belongs to the Vundo familly.
IP details.QUOTEHKEY_CLASSES_ROOT\CLSID\{35CEC8A3-2BE6-11D2-8773-92E220524153}\InprocServer32 "(Default)"
Type: REG_SZ
Data: C:\WINDOWS\system32\jykulin.dll
paylinks.cu-network.com - 89.187.49.250
Domain Name: CU-NETWORK.COM
Registrar: HICHINA ZHICHENG TECHNOLOGY LTD.
Whois Server: grs.hichina.com
Referral URL: www.net.cn
Name Server: NS1.CU-NETWORK.COM
Name Server: NS2.CU-NETWORK.COM
Status: ok
Updated Date: 07-oct-2008
Creation Date: 07-oct-2008
Expiration Date: 07-oct-2009

