Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 3 February 2010

Minipost: Fake Photo Zeus

Posted on 10:49 by Unknown
Back on November 24th, we ran a story about a version of Zeus which pretended to be a friend letting you know that Some Jerk Posted Your Photo. The current spam is almost identical to the original, using the same subject lines of:

Subject: fw
Subject: hey
Subject: hi
Subject: re
Subject: some jerk has posted your photos
Subject: your photos

The text of the message is:
Hey, some jerk has posted your pictures (u understand what kind of pictures are there) and sent a link of them to all ur friends. I have already replied back. Said, that he is an idiot. See the link:

http://photosbank.aedswer.cz/id1073bv/get.php?email=youremail@yourdomain.com

Tamara Orozco



This is what the website looks like:



Although downloading the "PhotoArchive.exe" file is dangerous - its a Zeus Botnet that's currently only detected by 7 of 40 AV products according to this VirusTotal Report, just visiting the website is also dangerous, because it has a drive-by infector that loads from 109.95.115.36 / usasp22 / in.php

Here are some of the websites that we've seen used to host the malware so far today in the UAB Spam Data Mine:

archive.tygersg.cz
archive.uisaxr.bz
archive.zinnko.co.uk
archive.zinnko.com
archives.aedswer.cz
archives.tyerdert.co.nz
archives.tyerdery.co.uk
archives.uisaxr.bz
archives.zinnko.pl

letitbit.aedswek.cz
letitbit.aedswer.cz
letitbit.tyerdery.co.uk
letitbit.tygersk.com
letitbit.tygersm.cz
letitbit.zinnko.co.uk
letitbit.zinnko.pl

photobank.aedswer.cz
photobank.aedswet.cz
photobank.tyerderi.co.uk
photobank.tygersa.cz
photobank.tygersk.com
photobank.zinnko.cz

photosbank.aedswee.cz
photosbank.tyerdere.co.nz
photosbank.tyerderi.co.nz
photosbank.tyerderi.co.uk
photosbank.tyerdery.co.uk
photosbank.tygersg.cz
photosbank.tygersm.cz
photosbank.zinnko.com
photosbank.zinnko.vc

photoshock.tyerdere.co.nz
photoshock.tyerderi.co.uk
photoshock.tyerdero.co.nz
photoshock.uisaxr.me.uk
photoshock.zinnko.be
photoshock.zinnko.com.pl

photostock.aedswee.cz
photostock.aedswek.cz
photostock.aedswer.cz
photostock.aedswew.cz
photostock.tyerdere.co.nz
photostock.tyerderi.co.uk
photostock.uisaxr.me.uk
photostock.zinnko.co.uk
photostock.zinnko.com
photostock.zinnko.com.pl
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in zbot | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Digital Certificate Spammer Goes for Google Adwords
    From late May until last week, the Digital Certificate Malware spammer has been targeting banking brands. That has changed with last week...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Most Dangerous Cities for Cyber Crime?
    Symantec Riskiest Cybercrime Cities Symantec released a study today in conjunction with Sperling's Best Places today. According to thei...
  • Beware Weekend Facebook Scam!
    The cybercriminals seem to have completed their Black Friday shopping and returned to work this morning with a new Facebook scam. Its proba...
  • What does a National Cyber Range do?
    This week Aviation Week ran a story called DARPA Unveils Cyber Warfare Range . The article quotes Rance Walleston, the director of BAE Syst...
  • 2008: Looking back on a Year of Spam and Malware
    Happy New Year! As we get ready for the New Year, there are quite a few security folks making predictions for 2009. I think my friend Dan...
  • WIRED: November Jargon Watch & Forensics?
    One of my NASA buddies (hi, Lisa!) dropped by last week for coffee and to catch up on the world of information management. When I introduce...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ►  2013 (17)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ▼  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ▼  February (4)
      • Phishers target Blogger.com accounts
      • What the Bad Guys Know: We'll Click on ANYTHING!
      • Conficker.B Microsoft Warning spam rehashed
      • Minipost: Fake Photo Zeus
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ►  August (23)
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile