Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Wednesday, 19 October 2011

ACH spam uses intermediary sites to deliver malware punch

Posted on 10:37 by Unknown
If you have an email address in the United States, either you or your spam filter is certainly familiar with this spam by now:



The spam with the subjects "ACH Payment (random numbers) Canceled" intends to imitate the National Automated Clearing House Association. NACHA is the organization that banks use to handle the electronic transfer of funds between domestic banks for things such as "Direct Deposit" or electronic bill paying.

The spam's message "The ACH transaction recently initiated from your checking acount was canceled by the other financial institution" is intended to elicit a panic response to get the recipient to click on the link in the email.

The problem has been getting worse because of two "upgrades" by the spammers.

First - they are using "drive-by" infectors, in the form of the BlackHole Exploit Kit. In the past a spam message such as this would have relied on trying to get you to download an '.exe' file and trick you into running it on your computer. Now, simply visiting the website will often be enough to infect your machine.

The second improvement, which comes and goes in waves, is that the criminals have compromised many "intermediary" web hosts to use in their spam. If the spammer were sending you to "mybadsite.com" your security software would quickly learn that "mybadsite.com" is a potentially harmful destination and block you from visiting.

To make sure their spam is delivered, the spammers have stolen the credentials from many website owners and have used these credentials to add one tiny file to their existing legitimate website. So, as a randomly chosen example, the spam link that claims to point to "nacha.org" may actually point to a page at "iscsconferencerecording.com". That page belongs to the International Society of Communication Specialists, so it probably has a "positive" reputation among security companies, who may be loathe to block the site.

What happens when we visit that page?

The only contents on the page "am2wdh.html" are calls to two Javascript files on other websites. In this case:

www.xmjhx.com /czc /js.js
and
vscreative.com /images /js.js


The first time I loaded this, it caused a document location to be set to "www.nachaemployee.com"

A rerun of the same site pointed me instead to a blackhole exploit kit page at:

milloworks.com /main.php? page=890639ab2b6c1ab8

Which caused me to fetch:

milloworks.com /w.php ?f=70&e=4

This caused me to download the file:

www.vncoach.com /editors /nachareport20111910.pdf.exe





Another attempt sent me to:

tgqswpqqh.org.in from which we attempt to load the Blackhole Exploit page from

This drops a number of files on our computer, including Flash exploits, PDF exploits, and an EXE called "FIX_KB112755.exe" which gets downloaded from the IP address 213.123.52.133. FIX_KB111088.exe and FIX_KB113547.exe were also downloaded from there.

After the malware drops on the computer, we are forwarded through "dating-portal.net" where the affiliate engine sends us to an "Adult Friend Finder" sign-up website.

The point of this story, however, is not really what malware gets dropped, but the use of so many hacked intermediary servers to do the dropping.

In the first twelve hours of October 19, 2011, we saw 184 different websites used in this type of attack with an ACH spam subject line. In order of occurrence, with the first observed URL each, here is what we've seen today:

HOSTNAME PATH
================================ ===================================
preseis.com /7x1tyg6.html
server.softhost.org /
silverfruit.com.ec /t2jr.html
newsletter.stable-jo.com /t43z.html
www.Shoubra-prep.com /4x8l.html
marcinjarzabek.cp5.win.pl /16ih2.html
professionalroofing.co.uk /ph4xn5.html
host272.hostmonster.com /~fdflockc/6xh9l1e.html
sethsauction.com /6gh1u7.html
www.corazondejesus.net /4cpjx.html
murciaopina.com /tq3e.html
www.digitalhomna.com /
latinholdings.com.mx /4ghy.html
108cms.com /3n7s.html
way2tutorial.com /g02lwbp.html
nimbuscertifications.com /4qt4.html
ultimateselena.org /0tpno.html
www.efficientorganizationnw.com /rk1pb.html
trinity-work-shop.test-rackspeed.de /
hosting31.serverhs.org /~ecommerc/zu9iah7.html
www.todotaringa.com /0pya.html
stremyfoot.com /q37hdi.html
www.ganarlaprimitiva.com /g5knqjr.html
manaiz.com /a2w7q.html
caspsurveys.org /zmu2.html
www.ironsidegroup.pk /kq6bz.html
temporary-toilets.com /mczkg.html
0342962.netsolhost.com /716txi.html
babilhotel.com /5bf0html
customcakesnw.com /not8.html
tomralph.net /vsz8c.html
www.panelpeople.com /1060.html
goldencrownhotel.com /zf9w3uh.html
www.launas.fr /jjssgx4.html
dev.crm-warehouse.be /uclt4.html
alassite.com /2hyl0.html
02be375.netsolhost.com /6mu1v.html
evo2inc.com /o3wyn.html
campossaab.net /g1hrhtml
inzanepix.com /19v4sx.html
specialrental.com /p5y6.html
iscsconferencerecording.com /am2wdh.html
www.murciaopina.com /rt5dmy.html
buynanoclean.com /3c6tp7.html
froda.com /5kbnak.html
globaliellc.com /1o36z.html
mslbx.com /~servatus/soexlyy.html
indexpoker.com /
diversco.com /6fxo.html
www.acclaimcabinetscom.au /7xoslgn.html
mvlmobile.in /d34c.html
weightlosspersonaltrainerconsulting.com /1decnf9.html
vandieautomatisering.nl /linhe.html
intestinoirritable.ws /e66uc.html
fmwwrestling.us /gsld0d.html
abeauty.com.au /
sokullupasahotel.com /fvn4upi.html
ants.net.au /yxe4ma.html
lkco.in /a8l876j.html
static-64-184-73-69nocdirect.com /~afroland/eh8jvre.html
damarchesi.it /6m2rdlx.html
trinity-work-shop.de /5t5ub.html
mycountylink.com /f6atze.html
artigianatopasella.com /9ghy.html
ohtobeyoungagain.com /t4cj.html
syedaliahmad.com /3mlnfh.html
www.geelongeisteddfod.com.au /13pspj.html
www.tommysparger.com /ci87qyp.html
nt-ves.ac.th /
diipbmis.nl /l374dcthtml
bakulpharma.com /
etno-plants.ro /
professionalroofingco.uk /vmba.html
altiaproducts.com /29f4.html
dezoetezaak.nl /anxl5.html
ozurfa.com.tr /ras5.html
lexxstore.de /7nsenqhtml
meirmodiin.org /~meirm/kk22.html
siflindia.com /27swn2.html
grapediscounts.com /fjlj9k.html
fastincomebiz.com /hsd6g7b.html
thebeadrotisserie.com /vel42.html
46.23.64.241 /~jamias/lc50sf.html
fastincomesystem.biz /u8g4tn.html
surebg.co.za /xltlgs.html
110.4.42.93 /bx94l.html
www.resourceelementlimited.com /
graph2profit.com /utxfc.html
shriganpatiproduction.net /r05qv4h.html
micrene.com /ivowl1rhtml
pdscientific.com /tl1s.html
www.wanithai.com /u7pv30b.html
ads-protection.com /fs3lax.html
sl3-vgt.vgthosting.com /~worknetw/fj2bvn.html
fb.servatusdev.com /~servdev/56iy2.html
hedy-lamarr.org /n2tgsb.html
niritech.com /pxkf.html
212.68.54.148 /~radyoruz/qsdsw9m.html
www.pushtiieshakti.com /783i.html
empiresallies-secrets.com /k0bayr.html
tarjetaspilos.com /9tvd.html
voongo.com /asfti1/index.html
searchtroop.net /04sh.html
altagallura.it /bd5jhtml
gran-mar.com.ar /4p6sbu7.html
fullart.com.pe /3c55egr.html
sanianishtar.info /7o2dd.html
umtelecom.com /h10krhtml
reformasyreparaciones.com /76kdp.html
206.217.196.47 /~dumpsche/kes773.html
acumenauditors.com.au /vfa9.html
www.rippt.com /t8859u.html
trunghieu.com /hsx1n3r.html
delallosa.com /mtgy99y.html
lainformacion.us /snkk1.html
refritermo.com /j9ps4y.html
www.grahajodoh.com /bqe6zk.html
etakip.com /yg4jl9.html
carifind.com /t718xhhtml
jpvarleyllc.com /kna4wx.html
www.shatteredhope.gr /lnsp.html
autoblog.fastincomesystem.biz /~cheers/gyjde.html
reformhaus-mehnert.de /2vn9yr5.html
indianbookshop.co.in /5b9fgs.html
host272.hostmonstercom /~fdflockc/6xh9l1e.html
enbramex.com /mpvsgi2.html
onlinesurat.com /mb2d.html
surrealtopia.com /hmsuu.html
el-salto-fishing.com /agg0noo.html
simplefact.mx /xln290.html
bofco.in /htrc.html
iznillahcng.com /y5le.html
static-64-184-73-69.nocdirect.com /~afroland/eh8jvre.html
vizonix.com /c1ptwqs/index.html
visionciudadconsultores.com /dwqopc/index.html
winsbyinc.com /0sm9j5/index.html
www.tradehalls.com /8eeh2.html
4income-solutions.com /93e3x.html
locanda-stazzo-bona.com /
jade.nseasy.com /~manishar/7xl9bd.html
GUHDNS.COM /md8g.html
livedata.it /ssao.html
www.manojengg.com /scv2.html
sexshop.com.tr /3igtv8.html
perfumeylenceria.com /joiwku.html
server10.namecheaphosting.com /
freunde-klinik-ottobeuren.de /oryh1.html
floristeriasdecoaromascostarica.com /kh31.html
portalinternational.us /5ecf2z.html
molinas.eu /nz4ot.html
clubfirst.org /2ba0jra.html
thepentad.com /eg3eje/index.html
www.dsmodular.com /qt21ta.html
hotelmarinepalace.com /0493.html
teresita.com.mx /hcrji4t.html
198.63.48.81 /z116c.html
punjnud.com /3sllgkihtml
inkostudio.com /y0ao0c.html
tuncakyavas.com /jfifrpb.html
hkf.huber-babenhausen.de /xyy4dg3.html
watson.timeweb.ru /~kostos/7euyd25.html
vscreative.com /x882.html
lemilano.fr /
labeltula.it /e51rsq.html
www.acclaimcabinets.com.au /
shelterpropertydealers.com /97qf.html
dotmile.com /cvpa4jj.html
www.clubbayard.com /w6kzi.html
myauto.co.nz /odmz0chtml
whydodogs.org /jdab40.html
bigrace2012.com /3ri1vt.html
www.launas-hebergement.com /fj9p1.html
www.neoplastic.gr /0qedzw.html
ittefaqpipe.com /2inp.html
efficientorganizationnw.com /ix84c.html
indosyslife.com /cdwwto.html
newmonicaarts.org /
avicarusa.com /uyxasjr.html
atlantidesardegna.it /61fyvx.html
baratrucks.com /n6j5m.html
heromw.com /602ka.html
web3.biz /4jdsydk.html
eqsync.com /bx5wfm.html
weblinksubmissions.com /1bgypq/index.html
Read More
Posted in malware, spam | No comments

Wednesday, 17 August 2011

New York City "Uniform Traffic Ticket" tops spammed malware

Posted on 03:37 by Unknown
Email attachments that contain malicious code are still being used to infect computers and steal the data found on those computers. While it is easy to find people who discount this threat, believing no one would be foolish enough to open one of these email attachments, the criminals are working hard to make their approaches more convincing.



Today we've seen more than 11,000 copies of their newest attempt come in to the UAB Spam Data Mine. The email received looks like this:







The email contains several falsified header indicators, including at the most basic level that it claims to come from "@nyc.gov". In addition to this, however, there has been a "Received:" tag added to make it appear to have originated from a legitimate New York City IP address:



Received: from nyc.gov ([167.153.240.51]) by xx.xx.xx.xx; Wed, 03 Aug 2011 12:20:46 +0530



The City of New York is the registrant for every IP address beginning with "167.153.*.*" - in fact 167.153.240.51 is the IP address of the website "nyc.gov" where Mayor Bloomberg's homepage can be found.



The other false information is the date. Both the date in the Received: tag and the date in the "Date:" tag have been falsified to make it seem this email has been in your in box for several days by the time you see it.



Just from the falsified header, we would predict that this email is going to be in the same family of malware as the "IRS Notification" and "UPS Notification" emails seen earlier this week, which also contained falsified Received: tags.



The zip file contains an executable file disguised as a PDF file:







When the malware is launched, it connects to "sfkdhjnsfjg.ru" on 195.189.226.117.



from there it fetches "/ftp/g.php" and "pusk3.exe" -- exactly the same as the IRS Notification spam and the UPS Notification spam.



VirusTotal Report






Another group of spam messages this morning pretends to be a notice that you have received money via Western Union.



The attachment is of course a virus:



VirusTotal Report.



Money Transfer Information

MONEY TRANSFER INFORMATION

Money Transfer Information 00375

Money Transfer Notice

MONEY TRANSFER NOTICE

MONEY TRANSFER NOTICE 06457

Western Union: Money Transfer For You

WESTERN UNION: MONEY TRANSFER FOR YOU

Western Union: Remittance Advice

WESTERN UNION: REMITTANCE ADVICE

Western Union: Transfer Of Money

WESTERN UNION: TRANSFER OF MONEY

Western Union: You Have Money Transfer

WESTERN UNION: YOU HAVE MONEY TRANSFER

Western Union: You have received a money transfer

WESTERN UNION: YOU HAVE RECEIVED A MONEY TRANSFER








Another top spammed malware attachment today delivers emails with these subjects:



Re: End of July Statement Required

Re: FW: End of July Stat.

Re: FW: End of July Statement

Re: FW: End of July Statement required

Re: FW: End of July Statement Required

Re: FW: End of July Statement REquired

Re: FW: End of July Statement REquired!

Re: FW: End of July Stat. required

Re: FW: End of July Stat. Required



The email body says simply:



Hallo,

As requested i give you open Invoices issued to you as per 5th Aug. 2011

Regards

DEENA BUCKLEY




Here's the VirusTotal report for this one.





Read More
Posted in spam | No comments

Wednesday, 10 August 2011

Inter-company Invoice spam leads to Malware

Posted on 05:57 by Unknown
This morning we are seeing a new spam campaign in the UAB Spam Data Mine. Volumes are still low, but the count is rising steadily, and the detection so far is horrible. When I started writing this post we had seen 710 copies. It's now up to 1389 copies and counting!



count | mbox

-------+---------------------

1 | 2011-08-10 05:45:00

6 | 2011-08-10 06:00:00

3 | 2011-08-10 06:15:00

85 | 2011-08-10 06:30:00

1 | 2011-08-10 06:45:00

3 | 2011-08-10 07:00:00

1 | 2011-08-10 07:15:00

301 | 2011-08-10 07:30:00

252 | 2011-08-10 07:45:00

260 | 2011-08-10 08:00:00

247 | 2011-08-10 08:15:00

229 | 2011-08-10 08:30:00

(12 rows)





The spam pretends to be an invoice from a random company. So far this morning we've seen spam claiming to be an invoice from:



Aleris International Corp.

AMR Corporation Corp.

Anic Corp.

Arch Coal Corp.

ATFT Corp

Beazer Homes USA Corp.

Boyd Gaming Corp.

Brookdale Senior Living Corp.

Hyland Software Corp.

KPMG Corp.

Kraft Foods Corp.

Miltek Corp.

Novellus Systems Corp.

OSN Corp.

PDC Corp.

Safeco Corporation Corp.

WLC Corp.



Subject can be:



Re: Fw: Inter-company inv. from (company)

Re: Fw: Inter-company inv. from (company)

Re: Fw: Inter-company invoice from (company)

Re: Fw: Intercompany invoice from (company)

Re: Fw: Corp. invoice from (company)



A couple example emails follow:






Hi

Attached the inter-company inv. for the period January 2010 til December 2010.



Thanks a lot for support setting up this process.



CHERYL Flowers

Kraft Foods Corp.





Hi



Attached the inter-company inv. for the period January 2010 til December 2010.

Thanks a lot



Asher GIFFORD

Anic Corp.





Good day





Attached the intercompany invoice for the period January 2010 til December 2010.



Thanks a lot for supporting this process

MAYOLA LEARY

Aleris International Corp.







The attachment may be named "Intinvoice" or "Invoice" followed by an underscore, a date, and an "invoice number" ".zip" such as:



Intinvoice_08.6.2011_2222341965.zip

or

Intinvoice_08.4.2011_Q167829.zip

or

Invoice_08.6.2011_T40099.zip





We've seen 1300+ copies so far in the UAB Spam Data Mine, and I have 15 in my personal email.



So far, all have had the same attachment MD5, which yields a 6 of 43 detection rate on this VirusTotal Report.



So far everyone is just saying it is "Suspicious" or "Generic" ... which is our invitation to infect ourselves and figure out what it does!



When we launched the malware, we made a connection to "armaturan.ru" on 94.199.48.152.



We also talked to "ss-partners.ru" on 77.120.114.100

and to "ledinit.ru" on 78.111.51.121



The connection to armaturan.ru did:



GET /forum/dl/ots.php?seller=4&hash={8FA33B0C-3F04-405B-83BD-1CD82D298FF2}



which seems to be uniquely registering our machine, and giving seller #4 credit for my infection?



From ss-partners.ru we fetched a file:



GET /dump/light.exe



which dropped an approximately 70k file onto our local machine.



Then we went back to armaturan.ru and sent another get:



GET /forum/dl/getruns.php?seller=4&hash={8FA33B0C-3F04-405B-83BD-1CD82D298FF2}&ahash=5895b2509324d6a17b2b6ea09859a485



Any bets on whether that ahash is the MD5 of the file I just downloaded?



Looks like I just reported back to the C&C that I successfully downloaded and installed malware with that MD5.



At this point I checked my registry and found that I had a new Run command for next time I restart. I'm supposed to run:



C:\Documents and Settings\Administrator\Application Data\3B1F8DC4\3B1F8DC4.EXE



Odd, I don't recall having a file named that?



Actually, we confirmed that this is the file that was downloaded as "light.exe" above. The VirusTotal report shows only 4 of 43 infection reports for this file as well. See VirusTotal Report.



Unfortunately, it disproves my MD5 theory. This is NOT the "ahash" value. This file's MD5 is f58d5cbb564069eca8806d4e48d7a714.



Launching the second file caused the machine to open an SSL tunnel to 78.111.51.121 and then sit idle.



You may recognize that as the IP address for "ledinit.ru" earlier, but it didn't make a connection by name. It went straight for the IP address. If that IP sounds familiar, it's probably because there have been many other malware campaigns tied to the network "Azerbaijan Baku Sol Ltd", but I'm sure that's just because it's a very large network.



78.111.51.100 is currently hosting three live Zeus C&C servers. Surely a coincidence.



fileuplarc.com

hunterdriveez.com

asdfasdgqghgsw.cx.cc



I'll email the owner and get those taken down right away! (smirk)



-----------



person: Vugar Kouliyev

address: 44, J.Jabbarli str., Baku, Azerbaijan

mnt-by: MNT-SOL

e-mail: vugar@kouliyev.com

phone: +994124971234

nic-hdl: VK1161-RIPE

source: RIPE # Filtered



route: 78.111.48.0/20

descr: SOL ISP

origin: AS43637

mnt-by: MNT-SOL

source: RIPE # Filtered



route: 78.111.51.0/24

descr: SOL ISP

origin: AS43637

mnt-by: MNT-SOL

source: RIPE # Filtered



----------------



Armaturan.ru on 94.199.48.152 also has a sordid history.



That IP address, in Hungary, has been associated with at least two active SpyEye domains: hdkajhslalskjd.ru and hhasdalkjjfasd.ru



I suppose we'll have to ask Mr. Zsolt nicely if he would remove those domains.



person: Zemancsik Zsolt

address: Victor Hugo u. 18-22.

address: 1132 Budapest

address: Hungary

phone: +36 203609059

e-mail: darwick@cyberground.hu

nic-hdl: DARW-RIPE

mnt-by: DARW-MNT

source: RIPE # Filtered



route: 94.199.48.0/21

descr: Originated from 23VNet Network

origin: AS30836

mnt-by: NET23-MNT

source: RIPE # Filtered



========

ss-partners.ru is on servers from Bellhost.ru, a customer of Volia DC



person: Volia DC Admin contact

address: Ukraine, Kiev, Kikvidze st. 1/2

phone: +38 044 2852716

abuse-mailbox: abuse@dc.volia.com

nic-hdl: VDCA-RIPE

mnt-by: VOLIA-DC-MNT

source: RIPE # Filtered



route: 77.120.96.0/19

descr: Volia more specific route

origin: AS25229

mnt-by: VOLIA-MNT

mnt-lower: VOLIA-MNT

source: RIPE # Filtered





Read More
Posted in spam | No comments

Friday, 5 August 2011

Fake IRS emails continue to spread Gov-related Zeus

Posted on 03:40 by Unknown
We've already seen nearly 500 copies of the new Government-related Zeus spam campaign so far this morning in the UAB Spam Data Mine. As has been typical in this campaign that we first started tracking on July 13th, the detection has been fairly horrible each morning for the new malware version. We lasted updated on this malware on July 29th in our story Government-related Zeus Spam Continues.

Today's version advertises the domain "tax-irs-report.com" and asks users to download the file 0000770950077US.pdf.exe from that site.

190 different computers have sent us the spam for this campaign so far today. 118 of them from the USA, 40 from India.

When we asked the UAB Spam Data Mine what other virus links we had been sent by this same group of 190 computers on other days, we got this list:

receiving_date | machine | path
----------------+------------------------------+-------------------------------
2011-07-13 | usbanking-security.com | /tax_report.pdf.exe
2011-07-15 | federalsecusrity.com | /pending-taxes.pdf.exe
2011-07-19 | irs-report-link.com | /tax-report.pdf.exe
2011-07-19 | irs-taxes-report.com | /tax-report.pdf.exe
2011-07-19 | taxreport-irs.com | /tax-report.pdf.exe
2011-07-20 | alerts-federalresrve.com | /rejected_wire.pdf.exe
2011-07-20 | nacha-alert.com | /rejected_transaction.pdf.exe
2011-07-20 | nacha-alert.org | /rejected_transfer.pdf.exe
2011-07-20 | reports-federalreserve.com | /rejected_wire.pdf.exe
2011-07-21 | national-security-agency.com | /blocked_list.exe
2011-07-21 | national-security-agency.com | /token_security_update.exe
2011-07-21 | nsa-security.net | /blocked-list.exe
2011-07-21 | nsa-security.net | /token_security_update.exe
2011-07-22 | irs-downloads.com | /00000700955160US.exe
2011-07-22 | irs-files.com | /00000700955170US.exe
2011-07-26 | irs-alert.com | /00000700955770US.exe
2011-07-27 | nacha-transactions.org | /304694305894903.pdf.exe
2011-07-27 | taxes-refund.com | /00000700975770US.exe
2011-07-27 | www.nacha-rejected.com | /304694305894903.pdf.exe
2011-07-28 | fdic-updates.com | /system_update_07_28.exe
2011-07-29 | federalreserve-alert.com | /transaction_report.pdf.exe
2011-07-29 | taxes-security.com | /00000700955060US.pdf.exe
2011-08-03 | irs-report.com | /00000770950077US.exe
2011-08-05 | tax-irs-report.com | /0000770950077US.pdf.exe
(24 rows)

So, at least some of today's spamming computers have been with this campaign since the beginning (July 13th).

When today's malware is executed it sets a registry key in "HKEY_USERS\S-1-5(my user)-500\Software\Microsoft\Windows\CurrentVersion\Run" to relaunch itself from my current user account where it had copied itself as "C:\Documents and Settings\Administrator\Application Data\Afena\iror.exe"

It makes connection to domains generated with a DGA (Domain Generation Algorithm). Today's live domain was:

olojkpcltulirqr.info on 50.57.71.39

from there it did a GET for /news/?s=158404

It tried many other domains, but none of the others were live. Some of them include:

jruioljslsitjpfv.biz
wlnzkqmohuhzqyra.info
tjjhmtjlziebo.net
jpkpbxkoxwijzijr.info

As we have seen before, the malware ALSO fetches a copy of "heap_v206_mails.exe" after it successfully installs itself.

The spam started at 4:45 AM (Central time), peaked at 5:15, and then began to trickle off. (We group in 15 minute windows.)

count | 15 minute spam block
-------+---------------------
3 | 2011-08-05 04:45:00
3 | 2011-08-05 05:00:00
406 | 2011-08-05 05:15:00
86 | 2011-08-05 05:30:00
(4 rows)

This morning's malware is largely undetected:

A VirusTotal Report shows 6 of 43 AV products know that this is a virus.

I have to praise Microsoft for being the only one of the six to correctly call this Zeus (Zbot).

Email subjects we've seen on this morning's campaign:

count | subject
-------+-------------------------------------------------------------------
38 | Change Confirmation
4 | Does your company is registered outstanding tax debt
5 | Does your company is registered tax debt
1 | Does your enterprise including unpaid tax debts
1 | Does your enterprise listed outstanding tax debts
1 | Does your enterprise listed unpaid tax debts
30 | Federal Tax payment rejected
1 | For your company including unpaid tax debts
1 | For your company is registered outstanding tax debts
1 | For your company is registered tax debts
1 | For your company is registered unpaid tax debt
1 | For your company listed tax debts
2 | For your enterprise listed tax debt
70 | Internal Revenue Service
24 | Internal Revenue Service (IRS)
19 | Internal Revenue Service United States Department of the Treasury
32 | IRS.gov
31 | IRS.gov US
19 | Notice of Underreported Income
35 | Payment IRS.gov
50 | Support IRS.gov
40 | Treasury Inspector General for Tax Administration
42 | U.S. Department of the Treasury
1 | Your company including outstanding tax debts
1 | Your company including tax debts
1 | Your company listed outstanding tax debt
2 | Your company listed tax debts
1 | Your enterprise including outstanding tax debts
2 | Your enterprise is registered unpaid tax debts
1 | Your enterprise listed outstanding tax debt
1 | Your enterprise listed unpaid tax debt
39 | Your IRS payment rejected
(32 rows)


A mix and match of sender name, sender-username, and sender-domain creates the from addresses:

count | sender_name
-------+---------------------------------------------------------------------
19 | "Internal Revenue Service"
18 | "Internal Revenue Service (IRS)"
27 | "Internal Revenue Service (IRS.gov)"
29 | "Internal Revenue Service United States Department of the Treasury"
23 | "Internal Revenue Service US Department of the Treasury"
29 | "IRS.gov"
18 | "IRS.gov United States Department of the Treasury"
30 | "IRS.gov US"
22 | "IRS.gov US Department of the Treasury"
21 | "IRS United States Department of the Treasury"
41 | "Payment IRS.gov"
37 | "Support IRS.gov"
23 | "The Consumer Financial Protection"
37 | "Treasury Inspector General for Tax Administration"
30 | "United States Department of the Treasury"
19 | "U.S. Department of the Treasury"
23 | "US_IRS"
17 | "USIRS"
35 | "US IRS.gov"


count | sender_username
-------+--------------------------
12 | admin
8 | adminnistration
9 | alerts
16 | cunsumer
29 | delivery
15 | e-file
10 | finance
33 | frboard-webannouncements
36 | govdelivery
26 | info
17 | information
14 | inspector
8 | internal_revenue_service
30 | Internal_Revenue_Service
18 | irs
6 | news
14 | news-alerts
8 | no-reply
28 | privacy_policy
22 | protection
5 | public
5 | report
9 | service
17 | stats
22 | subscriber
12 | subscriptions
13 | support
13 | usirc
14 | USIRS
13 | usttb
16 | webannouncements
(31 rows)

count | sender_domain
-------+-------------------
93 | antifraud.irs.gov
73 | info.irs.gov
78 | irs.gov
91 | irs.security.gov
73 | irs.taxes.gov
90 | service.irs.gov
(6 rows)
Read More
Posted in spam | No comments

Sunday, 31 October 2010

With GlavMed gone, who is the King of Pharm Spam?

Posted on 06:38 by Unknown
Last week the anti-spam community was abuzz with the news that Igor Gusev, the CEO of DespMedia, and the man behind GlavMed and SpamItDotBiz had been charged in absentia for running an unregulated internet company. The New York Times had an excellent story on the potential impact on spam.

At the end of this Russia Today article the author suggests "Glavmed partners are preparing to join a new pharmaceutical partnership program if the current one is shut down. Then it will be business as usual."

Where might they be going? Based on what we are seeing in the spam there are a few obvious choices. Most of the spam we have been receiving at the end of last week and through the weekend - more than 20% of our total spam volume - points us to domains that look like this:



Although "US Drugs" has had many look and feels, the thing that ties together this affiliate program is the phone number (800) 998-7978

This phone number is on many different pharma websites, some of which have harder narcotics, such as Vicodin, Percocet, and Hydrocodone such as "buy--viagra.net". These websites are often hosted on a Russian ASN belonging to Galant Ltd, but one of the spam campaigns is currently on Moldovan site AS49544, Complife, which we have seen hosting 1,783 distinct spammed pharmaceutical domains since October 19th on the IP 194.0.221.4 (click for list).

Another of the pharm sites that also uses the telephone (800) 998-7978 looks like this:



This group is currently hosted in Romania, on the IP address 86.55.211.152 (click for list) which has hosted 641 pharma domains since October 26th! prior to that, 2,271 times these domain names were hosted on 86.55.243.102 (click for list).

That leading group is followed by a close second, also almost 20% of our spam volume - for Pharmacy Express:



One of the main locations of this spam campaign's websites has been 188.95.159.61 (click for list) which has hosted 1,060 pharma domains since September 21st! Going back further, there were OEM Software sites and Casino spam sites hosted on the same IP.

Those two prominent spam affiliate programs are followed by a host of also-rans, including:

MediTrust



Acai News

Read More
Posted in pharmaceuticals, spam | No comments

Thursday, 2 September 2010

Don't check that CV! Major Zeus Spam Campaign

Posted on 20:22 by Unknown
In a bold new spam campaign, the criminals behind the Zeus Botnet have been distributing a spam email with a link to an executable file.

We first noticed this campaign in the UAB Spam Data Mine with a spam email message with the subject "you vacancy".

The body of that email read:


Thank you for the chat yesterday, it really helped me get a clearer idea
of recruitment as well as exploring any potential opportunity.

I have just spotted a mistake on the CV I sent in which my email was incorrect.

Apologies for any inconvenience caused if you have already sent me any information on anything we discussed.

My CV is an updated!
CV with the correct email on this link: http://good-resume.info/mycv.docx


The exact same email has also been seen in the UAB Spam Data Mine with several other subjects today:
908you vacancy
869Re: CV
864for CV
370Welcoming speech
115Greetings
112Hello
111Compliments
110Salutation
108Speech of welcome
100Civilities
99Hello message


The final link there that LOOKS like its going to download a Microsoft Word document, actually retrieves a file with the name:

mycv.doc.exe

The properties on that document claim to be:

BitDefender Management Console
SOFTWIN S.R.L.

The current detection rate on the malware at VirusTotal is 16/43, meaning that only 16 of 43 anti-virus products identify this as malware, although only one is calling it "zbot". Here's the VirusTotal Report for md5 = 10fd124206b15f878240f22a30eaf9fe

Our copy of the malware came from a computer with the IP address 58.222.143.148, which has been in bad company for some time. The IP is located on China Beijing Chinanet Jiangsu Province Network. Another example of Russian-speaking crooks hosting their malicious servers in China.

According to those great guys at ZeusTracker, that IP has been used for some really bad stuff.

caseoffinance.cc
dowsonstoke.cc
leadingcase.cc (Confirmed Zeus)
goldfieldforu.cc (Confirmed Zeus 8/24)
youmoneyway.cc (Confirmed Zeus 8/24)
a8228djjnedu7e8hd83ndd43d3d3.com
mikkymouse.com
first-wave-aug.com
iwfybfywi.com (Confirmed Zeus 8/19)
whiteagngo.com (Confirmed Zeus 9/2)
ekuns.com
fasterbuyers.com
hotsku.com (COnfirmed Zeus 9/1)
askuv.com (Confirmed Zeus 9/2)
good-resume.info
roundhome.net (Confirmed Zeus 8/24)
caramelloinze.net (Confirmed Zeus 9/2)
plitkinski.net
olandik.net (Confirmed Zeus 8/20)
instamfan.net (Confirmed Zeus 7/28)
tjkleen.net (Confirmed Zeus 8/9)
incornew.net (Confirmed Zeus 7/30)
autasienga.ru
jocudaidie.ru (Confirmed Zeus 7/15)
dahzunaeye.ru (Confirmed Zeus 6/23)
vohphozeeg.ru
eexiziedai.ru
railuhocal.ru (Confirmed Zeus 6/11)
blackfuril.ru
purplepron.ru (Confirmed Zeus 8/15)
cahgofoneu.ru (Confirmed Zeus 8/31)
iveeteepew.ru (Confirmed Zeus 6/23)
hazelpay.ru (Confirmed Zeus = 5/27)

We've got quite a few more details that we've already shared with law enforcement, but we wanted the public to be advised as well.

If you are a spam researcher and can tell me what botnet this is, please shoot me a note at 'gar at cis dot uab dot edu'. Here are some of the top sending IPs for this group:

72.16.178.42
81.180.66.34
187.36.133.238
186.82.57.113
186.112.107.35
77.127.135.151
195.135.239.5
76.97.210.124
195.228.164.14
24.36.173.168
93.32.50.228
211.17.116.17
24.80.8.180
190.48.237.121
212.29.192.202
Read More
Posted in spam, zbot | No comments

Saturday, 21 August 2010

"(Famous person) died" spam

Posted on 17:23 by Unknown
According to my spam inbox, today was a horrible day to be a celebrity:

Alicia Keys died
Angelina Jolie died
Beyonce Knowles died
Bon Jovi died
Brad Pitt died
Cameron Diaz died
David Beckham died
Gwen Stefani died
J.K. Rowling died
Jay-Z died
Jennifer Aniston died
Jennifer Lopez died
Johnny Depp died
Justin Timberlake died
Kanye West died
Madonna died
Miley Cyrus died
Nicole Kidman died
Oprah Winfrey died
Ronaldinho died
Tiger Woods died
Tom Cruise died

In the UAB Spam Data Mine we received between 450 and 539 copies of each of these spam messages.

The body of the email has the same text for each, with only the name varying. The name used in the body of the email doesn't necessarily match the name in the subject line. Here's an example:


Cameron Diaz died along with 34 other people when the Air Force CT-43 "Bobcat" passenger plane carrying the group on a trip crashed into a mountainside while approaching the Dubrovnik airport in Croatia during heavy rain and poor visibility.

Please see attachment


The attachment is called "News.html" is "base64" encoded, but if you click on it, it will launch in a web browser.

The HTML is composed of javascript functions which takes substrings of pieces of code and composes them together to make a URL:


new String("hre3y9b".substr(0,3)+"hv5f5hv".substr(3,1))]=
new String("http:P5v".substr(0,5)+ "//panHSOY".substr(0,5)+
"3aPiplusP3a".substr(3,5) + ".com.V4Hq".substr(0,5)+
"mx/1.0Xq".substr(0,5) + "HFkhtmlFHk".substr(3,4))


So, the "hre3y9b" becomes "hre" the "hv5f5hv" becomes an "f" for "href" etc . . .

It eventually turns into:

hxxp://paniplus.com.mx/1.html

(the "xx" instead of "tt" is to prevent this from being live)

That page has two URLs on it, one pointing to the free domain website 'cz.cc':

cetogilco.cz.cc / scanner10 / ?afid=24

This page goes to a fake anti-virus site . . .

The second URL points to:

analyticspool.in / wiki / index.php ?sid=151 &search=ecard &refresh=on


From cetogilco.cz.cc the file "antivirus.exe" is downloaded.

A VirusTotal Report for this malware, showing 18 of 41 detects, is available. The MD5 is cb38da67e9a96afb0b3674eddee26472.
Read More
Posted in spam | No comments

Monday, 9 August 2010

Viagra Spammers as Hackers?

Posted on 13:27 by Unknown
This summary is not available. Please click here to view the post.
Read More
Posted in pharmaceuticals, spam | No comments

Wednesday, 28 October 2009

FACEBOOK PHISH! Users Beware!

Posted on 07:30 by Unknown
The FDIC spam campaign that we reported on yesterday in our story Fake FDIC Spam Campaign Spreads Zeus has already moved on to its next attack. Now its trying to steal your Facebook passwords in what appears at first glance to be a "traditional" phishing attack. (Please see the end of this article for an update on how this "phish" actually is another Zeus malware infection vector.)



The UAB Spam Data Mine has already received more than 250 copies of the new phishing email this morning, which claims:

In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security.

Before you are able to use the new login system, you will be required to update your account.

Click (here) to update your account online now.

If you have any questions, reference our New User Guide

Thanks,
The Facebook Team


The email is fake, of course, and so are the websites they point to. So far we've identified 31 unique domain names registered by the criminal for use in this Facebook account.

The website looks like this:



UAB Malware Analyst Brian Tanner took the new Facebook Phish for a drive through the lab, and confirmed that this is NOT JUST A PHISH - in fact it might not be a traditional phish at all. Its actually a Zeus Bot installer, pointing at the same command & control site as yesterday's FDIC version of Zeus:



Clicking on the prompted "UpdateTool.exe" is the infection vector for Zeus. According to the VirusTotal Report for this malware, only 8 of 41 AV products are currently labelling this executable as malware.

File size: 105472 bytes
MD5 : 1198d2ddf09061fbfb70de423cde059f

Update 29OCT09 AM


Spam for this campaign is still coming fast and furious to the UAB Spam Data Mine. More than 200 fresh copies were received already this morning.

File size: 105984 bytes
MD5...: 6aad88ba4805b2daa4fc6106a5376065

A
VirusTotal report
for the current version is showing 9 of 41 detections.

Update - 01NOV2009


From October 27th until November 1st, we've seen 242 different domain names used by this campaign. Here are the ones that are currently live at this point in time (5:25 PM) --

www.facebook.com.heratsb.eu
www.facebook.com.heratsd.eu
www.facebook.com.heratsf.eu
www.facebook.com.heratsg.eu
www.facebook.com.heratsh.eu
www.facebook.com.heratsk.eu
www.facebook.com.heratsl.eu
www.facebook.com.heratsm.eu
www.facebook.com.heratsn.eu
www.facebook.com.heratso.eu
www.facebook.com.heratsq.eu
www.facebook.com.heratsr.eu
www.facebook.com.heratss.eu
www.facebook.com.heratst.eu
www.facebook.com.heratsy.eu
www.facebook.com.lllujiob.eu
www.facebook.com.lllujioc.eu
www.facebook.com.lllujiod.eu
www.facebook.com.lllujiof.eu
www.facebook.com.lllujiog.eu
www.facebook.com.lllujioh.eu
www.facebook.com.lllujioi.eu
www.facebook.com.lllujioj.eu
www.facebook.com.lllujion.eu
www.facebook.com.lllujiot.eu
www.facebook.com.lllujiov.eu
www.facebook.com.lllujiox.eu
www.facebook.com.lllujioy.eu
www.facebook.com.lllujioz.eu
www.facebook.com.ttteraa.eu
www.facebook.com.ttterab.eu
www.facebook.com.ttterac.eu
www.facebook.com.ttterad.eu
www.facebook.com.ttterae.eu
www.facebook.com.ttteraf.eu
www.facebook.com.ttterag.eu
www.facebook.com.ttteran.eu
www.facebook.com.ttteraq.eu
www.facebook.com.ttterav.eu
www.facebook.com.ttterax.eu
www.facebook.com.ttteraz.eu

Here is the full list . . .

www.facebook.com.edilokqf.eu
www.facebook.com.edilokqi.eu
www.facebook.com.edilokqm.eu
www.facebook.com.edilokqn.eu
www.facebook.com.edilokqr.eu
www.facebook.com.edilokqs.eu
www.facebook.com.edilokqu.eu
www.facebook.com.edilokqv.eu
www.facebook.com.edilokqw.eu
www.facebook.com.edilokqx.eu
www.facebook.com.eiye1ua.eu
www.facebook.com.eiye1uc.eu
www.facebook.com.eiye1ue.eu
www.facebook.com.eiye1uf.eu
www.facebook.com.eiye1ug.eu
www.facebook.com.eiye1ur.eu
www.facebook.com.eiye1us.eu
www.facebook.com.eiye1ut.eu
www.facebook.com.eiye1uv.eu
www.facebook.com.fasazab.eu
www.facebook.com.fasazad.eu
www.facebook.com.fasazae.eu
www.facebook.com.fasazaf.eu
www.facebook.com.fasazag.eu
www.facebook.com.fasazam.eu
www.facebook.com.fasazan.eu
www.facebook.com.fasazav.eu
www.facebook.com.heratsb.eu
www.facebook.com.heratsd.eu
www.facebook.com.heratsf.eu
www.facebook.com.heratsg.eu
www.facebook.com.heratsh.eu
www.facebook.com.heratsk.eu
www.facebook.com.heratsl.eu
www.facebook.com.heratsm.eu
www.facebook.com.heratsn.eu
www.facebook.com.heratso.eu
www.facebook.com.heratsq.eu
www.facebook.com.heratsr.eu
www.facebook.com.heratss.eu
www.facebook.com.heratst.eu
www.facebook.com.heratsy.eu
www.facebook.com.herrazzb.eu
www.facebook.com.herrazzd.eu
www.facebook.com.herrazzf.eu
www.facebook.com.herrazzg.eu
www.facebook.com.herrazzh.eu
www.facebook.com.herrazzj.eu
www.facebook.com.herrazzk.eu
www.facebook.com.herrazzo.eu
www.facebook.com.herrazzr.eu
www.facebook.com.herrazzt.eu
www.facebook.com.herrazzu.eu
www.facebook.com.herrazzv.eu
www.facebook.com.herrazzy.eu
www.facebook.com.ibbaswza.eu
www.facebook.com.ibbaswzd.eu
www.facebook.com.ibbaswze.eu
www.facebook.com.ibbaswzf.eu
www.facebook.com.ibbaswzr.eu
www.facebook.com.iokasqzc.eu
www.facebook.com.iokasqze.eu
www.facebook.com.iokasqzh.eu
www.facebook.com.iokasqzr.eu
www.facebook.com.iokasqzt.eu
www.facebook.com.iokasqzy.eu
www.facebook.com.ioooliob.eu
www.facebook.com.iooolioc.eu
www.facebook.com.iooolioe.eu
www.facebook.com.ioooliog.eu
www.facebook.com.iooolioq.eu
www.facebook.com.iooolior.eu
www.facebook.com.iooolios.eu
www.facebook.com.ioooliot.eu
www.facebook.com.ioooliov.eu
www.facebook.com.ioooliow.eu
www.facebook.com.ioooliox.eu
www.facebook.com.iooolioy.eu
www.facebook.com.lef1asza.eu
www.facebook.com.lefassza.eu
www.facebook.com.lefaszab.eu
www.facebook.com.lefaszac.eu
www.facebook.com.lefaszad.eu
www.facebook.com.lefaszak.eu
www.facebook.com.lefaszam.eu
www.facebook.com.lefaszan.eu
www.facebook.com.lefaszav.eu
www.facebook.com.lefaszax.eu
www.facebook.com.lefaszxa.eu
www.facebook.com.lefawsza.eu
www.facebook.com.lllujiob.eu
www.facebook.com.lllujioc.eu
www.facebook.com.lllujiod.eu
www.facebook.com.lllujiof.eu
www.facebook.com.lllujiog.eu
www.facebook.com.lllujioh.eu
www.facebook.com.lllujioi.eu
www.facebook.com.lllujioj.eu
www.facebook.com.lllujion.eu
www.facebook.com.lllujiot.eu
www.facebook.com.lllujiov.eu
www.facebook.com.lllujiox.eu
www.facebook.com.lllujioy.eu
www.facebook.com.lllujioz.eu
www.facebook.com.mibbbad.co.uk
www.facebook.com.mibbbad.me.uk
www.facebook.com.mibbbad.org.uk
www.facebook.com.mibbbah.co.uk
www.facebook.com.mibbbah.me.uk
www.facebook.com.mibbbah.org.uk
www.facebook.com.mibbbal.co.uk
www.facebook.com.mibbbal.me.uk
www.facebook.com.oooeasec.eu
www.facebook.com.oooeasef.eu
www.facebook.com.oooeaseg.eu
www.facebook.com.poresawa.eu
www.facebook.com.poresawd.eu
www.facebook.com.poresawe.eu
www.facebook.com.poresawg.eu
www.facebook.com.poresawj.eu
www.facebook.com.poresawo.eu
www.facebook.com.poresawq.eu
www.facebook.com.poresaws.eu
www.facebook.com.poresawt.eu
www.facebook.com.poresawu.eu
www.facebook.com.poresawv.eu
www.facebook.com.poresawx.eu
www.facebook.com.qqqqasc.eu
www.facebook.com.qqqqasd.eu
www.facebook.com.qqqqasf.eu
www.facebook.com.qqqqasg.eu
www.facebook.com.qqqqash.eu
www.facebook.com.qqqqasj.eu
www.facebook.com.qqqqask.eu
www.facebook.com.qqqqasl.eu
www.facebook.com.qqqqaso.eu
www.facebook.com.qqqqasr.eu
www.facebook.com.qqqqasy.eu
www.facebook.com.saaasaj.eu
www.facebook.com.saaasak.eu
www.facebook.com.saaasam.eu
www.facebook.com.saaasav.eu
www.facebook.com.saaasay.eu
www.facebook.com.saxzask.co.uk
www.facebook.com.saxzask.me.uk
www.facebook.com.saxzask.org.uk
www.facebook.com.saxzasl.co.uk
www.facebook.com.saxzasl.me.uk
www.facebook.com.saxzasl.org.uk
www.facebook.com.saxzasv.co.uk
www.facebook.com.saxzasv.me.uk
www.facebook.com.saxzasv.org.uk
www.facebook.com.saxzasy.co.uk
www.facebook.com.sazzawe.co.uk
www.facebook.com.sazzawe.eu
www.facebook.com.sazzawe.me.uk
www.facebook.com.sazzawf.co.uk
www.facebook.com.sazzawf.eu
www.facebook.com.sazzawf.me.uk
www.facebook.com.sazzawk.co.uk
www.facebook.com.sazzawk.eu
www.facebook.com.sazzawk.me.uk
www.facebook.com.sazzawl.co.uk
www.facebook.com.sazzawl.eu
www.facebook.com.sazzawl.me.uk
www.facebook.com.sazzawy.co.uk
www.facebook.com.sazzawy.eu
www.facebook.com.sazzawy.me.uk
www.facebook.com.ttteraa.eu
www.facebook.com.ttterab.eu
www.facebook.com.ttterac.eu
www.facebook.com.ttterad.eu
www.facebook.com.ttterae.eu
www.facebook.com.ttteraf.eu
www.facebook.com.ttterag.eu
www.facebook.com.ttteran.eu
www.facebook.com.ttteraq.eu
www.facebook.com.ttterav.eu
www.facebook.com.ttterax.eu
www.facebook.com.ttteraz.eu
www.facebook.com.ujtqwaq1.co.uk
www.facebook.com.ujtqwaq1.eu
www.facebook.com.ujtqwaq1.me.uk
www.facebook.com.ujtqwaq1.org.uk
www.facebook.com.ujtqwaqb.co.uk
www.facebook.com.ujtqwaqb.eu
www.facebook.com.ujtqwaqb.me.uk
www.facebook.com.ujtqwaqb.org.uk
www.facebook.com.ujtqwaqk.co.uk
www.facebook.com.ujtqwaqk.eu
www.facebook.com.ujtqwaqk.me.uk
www.facebook.com.ujtqwaqk.org.uk
www.facebook.com.ujtqwaqm.co.uk
www.facebook.com.ujtqwaqm.eu
www.facebook.com.ujtqwaqm.org.uk
www.facebook.com.ujtqwaqo.co.uk
www.facebook.com.ujtqwaqo.eu
www.facebook.com.ujtqwaqo.me.uk
www.facebook.com.ujtqwaqo.org.uk
www.facebook.com.xxxasqwa.eu
www.facebook.com.xxxasqwe.eu
www.facebook.com.xxxasqwi.eu
www.facebook.com.xxxasqwk.eu
www.facebook.com.xxxasqwl.eu
www.facebook.com.xxxasqwo.eu
www.facebook.com.xxxasqwp.eu
www.facebook.com.xxxasqwr.eu
www.facebook.com.xxxasqwt.eu
www.facebook.com.xxxasqwu.eu
www.facebook.com.xxxasqwy.eu
www.facebook.com.xxxasqwz.eu
www.facebook.com.yhheaszb.eu
www.facebook.com.yhheaszc.eu
www.facebook.com.yhheasze.eu
www.facebook.com.yhheaszf.eu
www.facebook.com.yhheaszh.eu
www.facebook.com.yhheaszi.eu
www.facebook.com.yhheaszq.eu
www.facebook.com.yhheaszu.eu
www.facebook.com.yhheaszv.eu
www.facebook.com.yhheaszy.eu
www.facebook.com.yy1azsva.eu
www.facebook.com.yy1azsvc.eu
www.facebook.com.yy1azsvq.eu
www.facebook.com.yy1azsvz.eu
www.facebook.com.yyy1asvf.eu
www.facebook.com.yyy1azsy.eu
www.facebook.com.yyy1azvg.eu
www.facebook.com.yyy1zsve.eu
www.facebook.com.yyyaszai.eu
www.facebook.com.yyyaszal.eu
www.facebook.com.yyyaszao.eu
www.facebook.com.yyyaszap.eu
www.facebook.com.yyyaszaq.eu
www.facebook.com.yyyaszar.eu
www.facebook.com.yyyaszau.eu
www.facebook.com.yyyaszay.eu
www.facebook.com.yyyazsvd.eu
www.facebook.com.zaaaasaa.eu
www.facebook.com.zaaaasag.eu
www.facebook.com.zaaaasaq.eu
www.facebook.com.zaaaasaz.eu
Read More
Posted in phishing, spam, zbot | No comments

Tuesday, 27 October 2009

Fake FDIC spam campaign spreads Zeus malware

Posted on 08:47 by Unknown
The UAB Spam Data Mine is continuing to experience high volumes of spam claiming to be from the Federal Deposit Insurance Corporation. FDIC.gov spam is using two email subjects:

FDIC has officially named your bank a failed bank
you need to check your Bank Deposit Insurance Coverage

The email messages claim to be from the email address consumeralerts@fdic.gov, which is a real email address used by the FDIC, but obviously being forged by the malware distributors in this situation.

Here's an example email:



You have received this message because you are a holder of a FDIC-insured bank account. Recently FDIC has officially named the bank you have opened your account with as a failed bank, thus, taking control of its assets.

You need to visit the official FDIC website and perform the following steps to check your Deposit Insurance Coverage:

* Visit FDIC website: http://www.fdic.gov/bankinsured/failed/personalfile/holder.php?email=youremail@yourdomain.com&id=233388521333599678361293755617839671

* Download and open your personal FDIC Insurance File to check your Deposit Insurance Coverage

Federal Deposit Insurance Corporation


The website to which you are directed looks like this:



The website offers a copy of "your personal FDIC Insuranace file" to see whether your coverage has been impacted. The website seems to offer this file as either an Adobe PDF file or a Microsoft Word file. In reality, the first is named "pdf.exe" and the second is named "word.exe", which are both the same file - a 105,472 byte executable file.

A VirusTotal report indicates that currently 9 anti-virus products are able to label this version of the malware, which we expect will be changed regularly by the criminals:

File size: 105472 bytes
MD5 : f4007a6af6dc841cd2961a8b3d2fbb8e

The detections declare it to be Zeus Bot, and UAB Malware Analyst Brian Tanner examined the malware in the lab and confirmed the same, identifying the location of the command & control server and sharing that information with appropriate law enforcement officials.


So far UAB researchers have identified 93 unique domains registered and used by the criminals for this campaign:

www.fdic.gov.h1erfae.eu
www.fdic.gov.h1erfai.eu
www.fdic.gov.h1erfaj.eu
www.fdic.gov.h1erfaq.eu
www.fdic.gov.h1erfar.eu
www.fdic.gov.h1erfat.eu
www.fdic.gov.h1erfau.eu
www.fdic.gov.h1erfaw.eu
www.fdic.gov.h1erfay.eu
www.fdic.gov.milki1a.co.uk
www.fdic.gov.milki1a.me.uk
www.fdic.gov.milki1e.me.uk
www.fdic.gov.milki1i.co.uk
www.fdic.gov.milki1l.co.uk
www.fdic.gov.milki1l.me.uk
www.fdic.gov.milki1y.me.uk
www.fdic.gov.nyuh1awa.eu
www.fdic.gov.nyuh1awb.eu
www.fdic.gov.nyuh1awc.eu
www.fdic.gov.nyuh1awd.eu
www.fdic.gov.nyuh1awe.eu
www.fdic.gov.nyuh1awf.eu
www.fdic.gov.nyuh1awg.eu
www.fdic.gov.nyuh1awh.eu
www.fdic.gov.nyuh1awm.eu
www.fdic.gov.nyuh1awn.eu
www.fdic.gov.nyuh1aws.eu
www.fdic.gov.nyuh1awt.eu
www.fdic.gov.nyuh1awv.eu
www.fdic.gov.nyuh1awx.eu
www.fdic.gov.nyuh1awz.eu
www.fdic.gov.ookilfd.eu
www.fdic.gov.ookilfe.eu
www.fdic.gov.ookilff.eu
www.fdic.gov.ookilfg.eu
www.fdic.gov.ookilfh.eu
www.fdic.gov.ookilfj.eu
www.fdic.gov.ookilfk.eu
www.fdic.gov.ookilfs.eu
www.fdic.gov.ookilfv.eu
www.fdic.gov.ookilfx.eu
www.fdic.gov.pouikib.eu
www.fdic.gov.pouikic.eu
www.fdic.gov.pouikie.eu
www.fdic.gov.pouikig.eu
www.fdic.gov.pouikiq.eu
www.fdic.gov.pouikir.eu
www.fdic.gov.pouikis.eu
www.fdic.gov.pouikit.eu
www.fdic.gov.pouikiv.eu
www.fdic.gov.pouikiw.eu
www.fdic.gov.pouikix.eu
www.fdic.gov.pouikiy.eu
www.fdic.gov.tt1qwa1.co.uk
www.fdic.gov.tt1qwa1.eu
www.fdic.gov.tt1qwa1.me.uk
www.fdic.gov.tt1qwae.eu
www.fdic.gov.tt1qwae.me.uk
www.fdic.gov.tt1qwaq.co.uk
www.fdic.gov.tt1qwaq.eu
www.fdic.gov.tt1qwaq.me.uk
www.fdic.gov.tt1qwar.co.uk
www.fdic.gov.tt1qwar.eu
www.fdic.gov.tt1qwar.me.uk
www.fdic.gov.tt1qwat.co.uk
www.fdic.gov.tt1qwat.eu
www.fdic.gov.tt1qwat.me.uk
www.fdic.gov.tygerah.co.uk
www.fdic.gov.tygerah.eu
www.fdic.gov.tygerah.me.uk
www.fdic.gov.tygerak.co.uk
www.fdic.gov.tygerak.eu
www.fdic.gov.tygerak.me.uk
www.fdic.gov.tygerat.co.uk
www.fdic.gov.tygerat.eu
www.fdic.gov.tygerat.me.uk
www.fdic.gov.tygeraw.co.uk
www.fdic.gov.tygeraw.eu
www.fdic.gov.tygeraw.me.uk
www.fdic.gov.tygeraz.co.uk
www.fdic.gov.tygeraz.eu
www.fdic.gov.tygeraz.me.uk
www.fdic.gov.yh1qab.co.uk
www.fdic.gov.yh1qab.eu
www.fdic.gov.yh1qab.me.uk
www.fdic.gov.yh1qak.co.uk
www.fdic.gov.yh1qak.eu
www.fdic.gov.yh1qal.co.uk
www.fdic.gov.yh1qal.eu
www.fdic.gov.yh1qal.me.uk
www.fdic.gov.yh1qao.co.uk
www.fdic.gov.yh1qaz.co.uk
www.fdic.gov.yh1qaz.eu

Of these, 38 domains are currently live:

www.fdic.gov.h1erfau.eu
www.fdic.gov.ookilfd.eu
www.fdic.gov.ookilfe.eu
www.fdic.gov.ookilff.eu
www.fdic.gov.ookilfg.eu
www.fdic.gov.ookilfh.eu
www.fdic.gov.ookilfj.eu
www.fdic.gov.ookilfk.eu
www.fdic.gov.ookilfs.eu
www.fdic.gov.ookilfv.eu
www.fdic.gov.ookilfx.eu
www.fdic.gov.pouikib.eu
www.fdic.gov.pouikic.eu
www.fdic.gov.pouikie.eu
www.fdic.gov.pouikig.eu
www.fdic.gov.pouikiq.eu
www.fdic.gov.pouikir.eu
www.fdic.gov.pouikis.eu
www.fdic.gov.pouikit.eu
www.fdic.gov.pouikiv.eu
www.fdic.gov.pouikiw.eu
www.fdic.gov.pouikix.eu
www.fdic.gov.pouikiy.eu
www.fdic.gov.tygerah.co.uk
www.fdic.gov.tygerah.eu
www.fdic.gov.tygerah.me.uk
www.fdic.gov.tygerak.co.uk
www.fdic.gov.tygerak.eu
www.fdic.gov.tygerak.me.uk
www.fdic.gov.tygerat.co.uk
www.fdic.gov.tygerat.eu
www.fdic.gov.tygerat.me.uk
www.fdic.gov.tygeraw.co.uk
www.fdic.gov.tygeraw.eu
www.fdic.gov.tygeraw.me.uk
www.fdic.gov.tygeraz.co.uk
www.fdic.gov.tygeraz.eu
www.fdic.gov.tygeraz.me.uk



UPDATE!

- 27OCT09 4PM in Alabama:

The FDIC's Sandra L. Thompson, Director of the Division of Supervision and Consumer Protection has provided an update to this emerging threat on their website:

http://www.fdic.gov/news/news/SpecialAlert/2009/sa09183.html

We're currently down to 16 "live" sites that we've seen in this afternoon's FDIC spam:

www.fdic.gov.ookilfh.eu
www.fdic.gov.ookilfj.eu
www.fdic.gov.ookilfs.eu
www.fdic.gov.pouikib.eu
www.fdic.gov.pouikic.eu
www.fdic.gov.pouikie.eu
www.fdic.gov.pouikig.eu
www.fdic.gov.pouikiq.eu
www.fdic.gov.pouikir.eu
www.fdic.gov.pouikis.eu
www.fdic.gov.pouikit.eu
www.fdic.gov.pouikiv.eu
www.fdic.gov.pouikiw.eu
www.fdic.gov.pouikix.eu
www.fdic.gov.pouikiy.eu
www.fdic.gov.pouikif.eu
Read More
Posted in spam, zbot | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Vista Security Features
    BitLocker Drive Encryption A Real-world Windows Vista BitLocker Tip BitLocker Drive Encryption BitLocker Drive Encryption Frequently Asked Q...
  • A Prominent American Express Phish
    Every once in a while we see a spam campaign where we dig in to the complexity, expecting to find malware, and find that the criminal has ju...
  • Money Laundering $1 at a time - a win for the UK's PCeU
    In London a little-known police unit called the Police Central E-Crime Unit (PCeU) has scored another big win. For several years people hav...
  • 2008: Looking back on a Year of Spam and Malware
    Happy New Year! As we get ready for the New Year, there are quite a few security folks making predictions for 2009. I think my friend Dan...
  • Most Dangerous Cities for Cyber Crime?
    Symantec Riskiest Cybercrime Cities Symantec released a study today in conjunction with Sperling's Best Places today. According to thei...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Lin Mun Poo: Hacker of the Federal Reserve and ...?
    ** UPDATE: Poo arraigned and in custody ** On October 21, 2010, Malaysian citizen Lin Mun Poo landed at the JFK airport in New York and and ...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ▼  2013 (17)
    • ▼  November (1)
      • Tempting Photo Attachments Lead to Fake AV
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ►  August (23)
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile