Someone spamming out samples to a trojanforge pony panel
Downloads in the word doc macros:
url1 = "http://www.megreen.com.sg/image/belg/microsoft.exe"
url2 = "http://www.megreen.com.sg/image/belg/microsoftKey.exe"
url3 = "http://www.megreen.com.sg/image/belg/microsoftNet.exe"
TF pony panel: dunlam007.ru/belg/gate.php - 31.220.20.150
ftp.dunlam007.ru
user: u118891974.bgpony
pass: doggod123
Downloads in the word doc macros:
url1 = "http://www.megreen.com.sg/image/belg/microsoft.exe"
url2 = "http://www.megreen.com.sg/image/belg/microsoftKey.exe"
url3 = "http://www.megreen.com.sg/image/belg/microsoftNet.exe"
TF pony panel: dunlam007.ru/belg/gate.php - 31.220.20.150
ftp.dunlam007.ru
user: u118891974.bgpony
pass: doggod123