Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 22 August 2008

Celebrity Spam-Off: Will Paris Hilton Overtake Angelina as Top Spam Bait?

Posted on 14:30 by Unknown
Based on the high volume of "Paris Hilton" spam today (21% of all spam messages received had "Paris Hilton" in the subject line), you're probably wondering "Is Paris Hilton the most popular Spam Celebrity?" No. Actually you are probably aren't wondering that, but its Friday afternoon, and I'm tired of being serious. So, while we waited for the UAB Spam Data Mine to finish a report about spam for a law enforcement case, we went ahead and produced . . .

The August Celebrity Spam Score Card



CelebrityPercentage of August Spam
Angelina Jolie5.2%
Britney Spears3.8%
Paris Hilton3.2%
George Bush0.6%
Barrack Obama0.5%
Lindsey Lohan0.36%
John McCain0.32%
Brad Pitt0.27%
Spongebob0.19%
Pamela Anderson0.16%
Heath Ledger0.14%
Madonna0.12%


Receiving less than 1/10th of 1% of all spam in August were:


Tony Blair
Sara Jessica Parker
Avrile Lavine
J Lo
Miley Cyrus
Christian Bale
Paul McCartney

Face it. Americans want to know what's going on in the lives of our celebrities. The spammers know this. But please resist the bait.

Paris Hilton did not give birth to aliens. Paris Hilton did not lecture on Dickens and Dostoevsky. John McCain did not name Paris Hilton as his running mate. There is not really a movie of Paris Hilton doing THAT with HIM/HER/THEM. Paris HIlton was not nominated for the Nobel Prize, no matter what your spam says. If you follow the link, the website you visit will try to infect your computer with malware.

If you want to know what Angelina Jolie did, subscribe to People magazine. If you want to know what Paris Hilton probably didn't do, read the National Enquirer. But whatever you do: don't click the links in your email!

Oh - for comparison - CNN edged out Angelina Jolie ever so slightly with 5.4% of all the spam for the month of August so far. MSNBC was only a handful of emails behind Paris Hilton, with 3.2% of all spam messages for August so far.

And now for the serious part . . .


120 subject lines used to advertise the virus being pushed by all the Paris/Britney spam we received today.
I'll include a few of the tamer ones here, but many are too offensive for a sensible blog post:

Aliens Deny Impregnating Paris Hilton
Britney Finally Passes Rolling Stones Audition
Britney mind control claims: manager says K-Fed responsible
Britney Spears and Paris Hilton to Visit Burma
Paris Hilton Pregnant By Aliens
Paris Hilton Returned By Aliens
Paris Hilton Seeks New Best Friend Competition


3,732 IP addresses of compromised computers that sent us those Paris/Britney virus links.



175 unique malware links those messages wanted us to click on.


121 websites that were compromised to make them host the virus.

Most have now been shutdown. There are two versions of the virus being distributed. If you have been infected by this virus, the primary symptom will be that your computer will seem to have a new anti-virus program scanning your system, and probably changing your Windows wallpaper.

These sites are all still distributing "play.exe", which is 74,752 bytes in size and has the MD5 of 15e20faa53450a4ff64ef6b3541889fb. Its very well detected, based on this VirusTotal report showing that 32 of 36 anti-virus products know its a virus.

1000millasargentina.com.ar
3kman.com.ar
agmerparana.com.ar
bandaantidoto.com
beta.theindustryresource.com
edr.co.in
elportal.info
evergreen-studio.com
gfportfolio.com.ar
glycerine.servebeer.com
madurezcero.com
marketah.mysteria.cz
roskiman.com
sadsystems.com.ar.elserver.com
scoutik.mysteria.cz
thomasregisterofnj.com
www.bwlapdance.com
www.lenapiel.com

These 26 sites are still actively distributing the other version, which can be called "stream.exe" or "player.exe". They are 78,848 bytes and have the MD5 of a3aec9130af6f69c715dc6eb89949079, which, according to this Virus Total Report is slightly less detectable, with 26 of 36 anti-virus products detecting it.

1000millasargentina.com.ar
3kman.com.ar
7yascokgec.com
agmerparana.com.ar
bandaantidoto.com
beta.theindustryresource.com
crosmedia.ro
dkya.com.ar
elobservadorag.com.ar
elportal.info
eryvelton.adm.br
evergreen-studio.com
fmorigenes.com
glycerine.servebeer.com
hey.ba
madurezcero.com
marketah.mysteria.cz
mundoartegaleria.com
roskiman.com
scoutik.mysteria.cz
thomasregisterofnj.com
vakhariaretail.com
www.bodegasadan.com
www.bwlapdance.com
www.lenapiel.com
www.stoplosslevel.com


Good luck, and have a great weekend.

Gary Warner
Director of Research
UAB Computer Forensics
& Celebrity Spam Score Keeper

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Indictments reveal $77 Million in Illegal Pill Sales
    Congratulations to the Daytona Beach FBI, US Attorney Robert O'Neill, and their colleagues at IRS and FDA. The Daytona Beach News report...
  • Most Dangerous Cities for Cyber Crime?
    Symantec Riskiest Cybercrime Cities Symantec released a study today in conjunction with Sperling's Best Places today. According to thei...
  • Morocco based "Team Evil" reroutes prominent Israeli websites
    After more than 10,000 websites being defaced in protest of Israeli actions in Gaza, Morrocco-based defacement team "Team Evil" ha...
  • Minipost: Google v. Pacific WebWorks
    I blogged recently about the "Google Jobs" scammers who were abusing Twitter, Blogspot, Google Reader, and spaces.live.com by crea...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • WIRED: November Jargon Watch & Forensics?
    One of my NASA buddies (hi, Lisa!) dropped by last week for coffee and to catch up on the world of information management. When I introduce...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ►  2013 (17)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ▼  August (23)
      • Hurricane Gustav: Fraud Watch
      • Banking Digital Certificate Malware in Spam
      • E-cards Run Wild. Where are the Anti-Virus Compan...
      • Leave Those Viruses at SCHOOL!
      • Celebrity Spam-Off: Will Paris Hilton Overtake An...
      • Shadow Botnet case may yield spammer Leni Neto
      • More Online Pharmacy Affiliates Indicted
      • Evidence that Georgia DDOS attacks are "populist" ...
      • One third of current spam points to malware sites
      • New BBC spam mocks Georgia's President, Spreads Ne...
      • Can You Pick the Real MSNBC.Com Breaking News?
      • MSNBC Breaking News replaces CNN Spam Wave
      • Anti-Virus Products Still Fail on Fresh Viruses
      • iTunes Store Phish
      • Features and Tutorials
      • The UAB Spam Data Mine: Looking at Malware Sites
      • TJX Update: The San Diego Indictments
      • TJX Update: The Boston Indictments
      • Linking all the News Spam together (CNN.com Daily ...
      • CNN Spam Diversifies . . .
      • TJX Reminder: "We Will Arrest You, and We Will Sen...
      • CNN Lends Authenticity to News Spam
      • Another Insider Busted: Countrywide Financial Analyst
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile