Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 10 November 2008

Election Malware and Obama Pill Ads?

Posted on 08:46 by Unknown
Just a quick post to update the situation we described in our previous posts that we are now thinking of as Election Malware Round One and Election Malware Round Two. Round One was the Obama Acceptance Speech video and Round Two was the McCain video. Technically, I guess that means we are currently looking at Round Two B, since the webpage hasn't changed - we just have a fresh batch of domain names.


Election Malware: Round Three


We made contact over the weekend with a real live human at Bizcn.com, who terminated all the domains listed above. Unfortunately, the spammer created new ones and this morning (10NOV08) at 7:52 AM we began to see his latest round of spam. In the first three hours of this spam campaign, the spam is evenly split between three domains created last night:

- miteodemo.com
- oirerbio.com
- demovideons.com

All three domains use the nameserver ns1.vistausan.com, which was also freshly registered last night at bizcn.com.

Computers which are currently hosting proxy redirectors for the domains above also provided redirection services for some of the "Round two" domain names. Some examples currently hosting would be:

118.219.111.107
190.47.161.2
221.184.68.214
89.36.135.102
91.90.229.209

But these are "fluxing" - they will change over the course of the hours as we wait for bizcn.com to shut down these newest domains and their nameserver domain. The shutdown request, in Chinese and English, was sent just now (10:40 AM Central Time)

Barack Sex Video malware


The only other piece of malware we are seeing delivered via election headlines is a very well detected trojan claiming to be a Barack Obama sex video. The great majority of products detect this malware at VirusTotal.com.

The porn video attachment name we are seeing most often is "zeland-01.zip".

Michelle Obama's Name used in Pill Spam


Why anyone would think that email recipients would buy Viagra after reading headlines like these is beyond my comprehension. Two heavily spammed subjects today used to sell Canadian Pharmacy pills are tied to Michelle Obama's name.

All of these 20 domain names were seen advertised in spam using the subject "Bush kills Michelle Obama":

bxoaxcs.cn
cpknetj.cn
cvmovzf.cn
fihithm.cn
hddbzqq.cn
imvbokv.cn
ixwewyi.cn
kycsgsf.cn
lrlbbgf.cn
pagegim.cn
ppnbokc.cn
rornzxl.cn
rzbopdh.cn
rzrsaak.cn
szosojb.cn
teqixyb.cn
ticewyt.cn
umcaxtx.cn
wjqsclb.cn
wplbhdi.cn

These 26 domains names were all used in spam with the subject line "Michelle Obama nude":

aojeyer.cn
cnrogvy.cn
dlyumlv.cn
dvrujfi.cn
fqosaeq.cn
gohbrtf.cn
iemokpg.cn
ihyefos.cn
ixwewyi.cn
kuxulne.cn
kxhoyed.cn
kzinwkm.cn
mmaagwd.cn
oaleqte.cn
ocbibxf.cn
rnjonlg.cn
rzrsaak.cn
sujidbk.cn
syootqj.cn
tomnhac.cn
uqpnjrn.cn
uwkajlr.cn
wjqsclb.cn
xyynwye.cn
zgmnvfe.cn
zyuunvw.cn

Each of those domain names actually forwards to another domain name when visited, which sells Canadian Pharmacy pills. Spammers use this technique to remove their spam from website orders from the domains they control, because some affiliate programs actually do refuse payment from those who can be shown to be spamming. By using this forwarding technique, spammers can claim their domains were NOT used in spam messages.
Read More
Posted in | No comments

Friday, 7 November 2008

Election Malware Targets Sore Losers - McCain Video Loads Virus

Posted on 09:33 by Unknown
We reported on Wednesday morning that Obama's historic victory was being used by cyber criminals in a spam campaign which attempted to trick email readers into watching a video of Obama's acceptance speech. Clicking the email link took readers to a website which seemed to have a video, but which prompted users to install "Adobe_Flash9.exe", which was not a video player upgrade, but actually a computer virus.

Today the spammer's have decided to take a more negative spin on their spam campaign. While "round one" of the malware seemed to try to appeal to those who were happy that Obama had won, "round two" is trying to trick the Haters into infecting themselves. More than 450 emails have already been received at the UAB Spam Data Mine with such negative subject lines as these:

Barack Obama can lost presidents chair
Barack Obama can lost President's Chair
Barack Obama in Danger - McCain will fight for president post
Barack Obama president resignation - 23/7 News
From Billy Mccain
IMPEACH Barrack Obama | USA government news
McCain Lawmakers Impeach Obama
McCain Lawyers Want to Stop Obama
McCain said today: 'Impeach Obama'
McCain strike against Obama political way
McCain vs Obama - There is a higher potential for confrontation between opposing political forces
McCain want to stop Obama
Moms who voted for Obama
Obama faces impeachment
Obama Impeachment Resources: McCain Look at the Impeachment Process
Obama vs McCain 'Political Strike' May Undermine Labor Group
Scandal: Obama Resignation Letter
Scandal: Re-elections John McCain Will be a Dictator?
Scandal: Re-elections John McCain will defeat Barack Obama
Scandal: Re-elections McCain will win
Scandal: Re-elections Obama: McCain Will Close With Attacks
Scandal: Re-elections Why John McCain will keep fighting
Scandal: Re-elections Why McCain Will Win
The Impeachment of new president Obama
Video: Obama post-resignation speech
Why MccAin Want to Stop Obama From president vacancy?
WScandal: Re-elections hich John McCain will show up to debate?


The website looks like this: (Click the image for a larger version)




As before, the domain names are all newly registered with in China with the Registrar Bizcn.com. The domain names now are:

baraokl.com
oritrsunwart.com
preibrsu.com
serensy.com

Visiting any of the webpages will cause the same "pop-up" which claims that an update is needed to the "Adobe Media Player". Its NOT the same executable that was being used Wednesday morning, but a "re-packing" of the same malware. In other words, it does the same thing, but its still going to need new anti-virus signatures to detect it.

The virus this time around is

File size: 25173 bytes
MD5...: 642a588272e9fe723fb2f1dd8fccede5

Here's a link to the VirusTotal report which shows 22 of 36 AV products currently detect this version of the malware.

Students studying computer forensics at UAB have analyzed this version of the malware and confirmed that the stolen data is sent to the same Ukrainian computer address as the original Obama acceptance speech video and the recent Colonial Bank Digital Certificate malware, 91.203.93.57.

We've sent a request for cooperation for shutdown to the abuse address of record for that IP, abuse@uatelecom.com.ua (good luck, right?)

The malware is hidden on the computer with the name: \9129837.exe and invoked whenever Internet Explorer is active on the computer.

Stolen userids and passwords are sent to the Ukrainian computer using strings that follow this pattern:

http://%s%s?user_id=%.4u&version_id=%s&passphrase=%s&socks=%lu&version=%lu&crc=%.8x
URL: sniffer_ftp_%s
ftp_server=%s&ftp_login=%s&ftp_pass=%s&version=%lu
URL: sniffer_pop3_%s
pop3_server=%s&pop3_login=%s&pop3_pass=%s
URL: sniffer_imap_%s
imap_server=%s&imap_login=%s&imap_pass=%s
URL: sniffer_icq_%s
icq_user=%s&icq_pass=%s

The packer used to make it more difficult to analyze the malware is called "FSG".

Bottom line - don't click on links in email. If you DID click on this link, you need very badly to check out your computer for potential malware.
Read More
Posted in | No comments

Thursday, 6 November 2008

Yesterday's Obama Spammer Now Imitates Colonial Bank

Posted on 07:11 by Unknown
In yesterday's blog, we talked about Obama spam spreading a virus. In that attack there were five domain names, all registered in China on Bizcn.com, being used to download a computer program which would steal your passwords and send them to criminals.

Today we have a new spam campaign which uses five domain names, all registered in China on Bizcn.com, being used to download a computer program which would steal your passwords and send them to criminals.

Both of the groups of five domains used a nameserver which was located on the IP address 69.162.111.11 (which is in Dallas, Texas).

When you visited the webpage yesterday, a pop up box asked you to download a video player. Today when you visit one of the Colonial webpages, a pop up box asks you to download a digital certificate.

Yesterday we received over 500 copies of the Obama spam with various subjects.

Today we've received over 300 copies of the Colonial Bank spam with subjects including:Colonial Bank - authorized users performing appropriate functions
Colonial Bank Warning: services specific high-risk geographical areas.
Colonial Bank - Display of Information
Colonial Bank Warning: system disables passwords that haven't been used by a customer in 90 days.
Colonial Bank Warning: subject to monitoring and validation for authenticity and appropriateness.
Colonial Bank Treasury Services
Colonial Bank Warning: terminate your Internet banking session
Colonial Bank Warning: Electronic requests received over the Internet
Colonial Bank has developed an update for log in page
Colonial Bank also provides extensive information regarding identity theft prevention
Colonial Bank would like to announce latest update
Colonial Bank Warning: access the Bank's servers.
Colonial Bank Warning: software designed to protect against inappropriate requests.
Colonial Bank security # latest patches and updates installation.
Colonial Bank recommend that you use fraud prevention procedures
Colonial Bank Update.
Colonial Bank - Network Security and Monitoring
Colonial Bank - your password will never be displayed on your computer screen
Colonial Bank Warning: retrieving web pages or sending inquiries
Colonial Bank security # Ensure that your operating system has all latest patches and updates installed.
Colonial Bank Alert: SERVER UPDATE.
Colonial Bank recommend that you use security update
Colonial Bank - data sent over the encrypted connection has been altered in transit.
Colonial Bank has developed a Fraud Prevention Checklist
Colonial Bank recommend to review your account security
Colonial Bank Security and Identity Protection Newsletter
Colonial Bank Warning: prevent access to online banking from an IP network
Colonial Bank has developed special file protection
Colonial Bank Warning: ur Internet banking system encrypts stored password files
Colonial Bank Commercial Customer Service
Colonial Bank has developed new free protection tool
Colonial Bank - all information sent between a client and a server encrypted
Colonial Bank Warning: initial registration
Colonial Bank would like to inform you security updates
Colonial Bank security # Ensure that your operating system updated.
Colonial Bank Alert - Update.
Colonial Bank has developed a new 128 bit sofware
Colonial Bank security # apply updates
Colonial Bank - providing a high degree of confidentiality.
Colonial Bank News - security development
Colonial Bank - effort to limit access to its servers
Colonial Bank Java Update Includes Security Fixes - Security Fix.
Colonial Bank Warning: using the Secure Sockets Layer (SSL) protocol.
Colonial Bank Customer Warning.
UPDATE ALERT CONFIGURATION Colonial Bank.
Colonial Bank - Secure Data Transfer
Colonial Bank would like to inform you
Colonial Bank - the user and the server are in a secure environment.
Colonial Bank would like to inform you lates development
Colonial Bank Online server update.
Colonial Bank Warning: Your Password, and certain other private information
Colonial Bank has developed new anti-Fraud feature
Colonial Bank Update Alert.
Colonial Bank Security Response Center (MSRC) : UPDATE.
Colonial Bank Warning: termination of Inactive Connections
Colonial Bank Emergency Alert System.
Colonial Bank Connection Security
Colonial Bank upgrade warning.
Colonial Bank Warning: allowing only the traffic that is necessary to send acceptable data requests
Colonial Bank Warning: if you are not actively using the system.
Colonial Bank Warning: this is accomplished by filtering Internet traffic
Colonial Bank Update - News.
Colonial Bank would like to stop fraud practice
Colonial Bank - these actions may include the implementation of restrictions
Colonial Bank - Data traveling between the user and the server is encrypted
Colonial Bank Warning: suspicious or potentially harmful activity
Colonial Bank Time Warner Security - Customer Service.
Colonial Bank Installation and Upgrade Warning.
Server Update Services Colonial Bank.
Colonial Bank has developed serious protection
Colonial Bank Urgent Customer Alert: "Joomla!" Security Update.
Colonial Bank - Other Security Measures
Colonial Bank WindowsXP/2000 customers Attention!
Colonial Bank - Security Fix.
Colonial Bank Warning: the sending software
Colonial Bank Guards and Protects Your Information
Colonial Bank would like to make you aware of online fraud
Colonial Bank - Our Internet banking system
Colonial Bank Security
Colonial Bank - an encrypted SSL connection required
Colonial Bank is committed to providing you with a convenient, safe and secure online banking
Colonial Bank Warning: we also monitor Internet traffic
Colonial Bank - takes several measures.
Visit a Colonial Bank Financial Center
Colonial Bank Services
Colonial Bank Warning: Electronic requests are filtered through a combination of computer hardware and software
Colonial Bank would like to open new security features
Colonial Bank Warning: automatically determining
Colonial Bank - an encrypted SSL connection is equipped with a mechanism for detecting tampering
Colonial Bank recommend that you use updated browser
Colonial Bank recommend that you use 128 bit file
Colonial Bank Regular Update Alert.
Colonial Bank Customer Support - Security Updates.

Here is today's webpage:



The domain names used today are:

coloneldi.com/security.php
gdieuntso.com/security.php
porentud.com/security.php
reteinr.com/security.php
rutriyn.com/security.php

Each of these domains was registered today (November 6, 2008) on Bizcn.com.

Visiting the Colonial pages above drops ColonialSETUP.exe

VirusTotal (17/36)

http://www.virustotal.com/analisis/9dfd058ab879365aa719e4a0055b2b46

File size: 3369 bytes

MD5...: 60e39dd91cd4676c70d4ee844eb5a6c7

The phase one malware makes connection to the following URL to download
the phase two malware:

chload.com/u1.exe

chload.com was registered TODAY on Register.com

the nameserver for chload.com is ns1.ldern.com

That is also the nameserver for:

customlod.com
upgradell.com
solecokes.com
lodnew.com

which have all ALSO been used to download Phase Two malware for Digital
Certificate spam.

The second phase malware (u1.exe) was also analyzed by VirusTotal.

http://www.virustotal.com/analisis/a0c5718489e7022da2f5bf35ef03adc8

It showed a 21/36 detection rate:
File size: 25161 bytes
MD5...: 6a1e70482b86500229ebdc99b13792ba

u1.exe installs itself as "comctl32.dll" and includes root kit and
keylogging technology. I have not had a chance yet to see where the
keylogged data is sent.

A request to terminate chload.com and ldern.com has been sent to
register.com.

A request to terminate the following domains has been sent to bizcn.com.

coloneldi.com
gdieuntso.com
porentud.com
reteinr.com
rutriyn.com
Read More
Posted in | No comments

Wednesday, 5 November 2008

Computer Virus masquerades as Obama Acceptance Speech Video

Posted on 09:41 by Unknown
Less than twelve hours after President-Elect Obama's historic acceptance speech, computer criminals have already crafted a malware attack based on the speech. The UAB Spam Data Mine has observed more than 300 spam messages which invite email readers to view the speech with a spam message that looks like this:

Barack Obama Elected 44th President of United States

Barack Obama, unknown to most Americans just four years ago, will become the 44th president and the first African-American president of the United States.
Watch His amazing speech at November 5!

Proceed to the election results news page>>

2008 American Government Official Website
This site delivers information about current U.S. Foreign policy and about American life and culture.



The spam subject lines include:

A new president, a new congress ...
Barack Obama wins
Can Obama win popular vote but lose election?
Did Obama Win Yet?
Election 2008: Time lapse of U.S. counties
Election Center 2008 - Election Results
Election Night Results
Fear of a Black President
New president's
Obama win an Electoral College majority
Obama win Defined by Race
Obama win preferred in world poll
Obama win sets stage for showdown
Obama Wouldnt Be First Black President
Obama's Win Reshapes the Race
Priorities for the New President
Priorities for the New President - TIME
The new President's cabinet?
USA Election 2008 Results
Will American Voters Elect a Black President
World Welcomes Obama's Win

The Sender of the email pretends to be one of:

news@cnn.com
news@usatoday.com
news@online.com
news@c18-ss-1-lb.cnet.com
news@president.com
news@unitedstates.com
news@bbc.com


using sender names such as:
2008 president center
Election results
Elections center
Election Results center
President election results

There are five different websites which are used to host the fake website, each of which looks exactly like this:



The domain names used in this attack are:

bfiinwach.com - registered November 4th, BizCN.com
gerimumsoe.com - registered November 4th, BizCN.com
lopbiuemis.com - registered November 4th, BizCN.com
vcoenutrmsi.com - registered November 4th, BizCN.com
wconlinenrue.com - registered November 4th, BizCN.com

(the domain spritsonline.net is also owned by this criminal and is used to host the NameServer for the other five domains.)


The spam message sends users to the page "president.htm" which claims that you need a new Adobe_flash9.exe player in order to view the video.


The virus has been reported to VirusTotal.com, where it was first reported at:

11.05.2008 17:24:35 (CET)

Currently 14 of 36 anti-virus products represented at VirusTotal have detection for this version of the malware, which is a keylogger in a family sometimes called "SnifULA".

The virus file is 31232 bytes in size, and has the MD5 value: 47c86509a78dc1edb42f2964bea86306

This is the same keylogger family which has been behind all of the Digital Certificate bank malware that we have reported to you on so many occasions previously, including yesterday's story on the malware pretending to be a merger letter regarding Wachovia and Wells Fargo.

As evidence of that, we offer the fact that the five domains above are all being hosted on a fast flux network, and that many of the compromised home computers in that network have also hosted the domains for yesterday's Wachovia/WellsFargo malware.

Student Malware Analysts in the UAB Computer Forensics department have analyzed the malware and indicate that the stolen login credentials are being sent to the Ukraine. The virus steals userids and passwords, and posts them to this IP address:

91.203.93.57

IP Location: Ukraine Ukraine Pool For Co-location Customers
IP Address: 91.203.93.57
Blacklist Status: Clear
Whois Record

inetnum: 91.203.93.1 - 91.203.93.128
netname: ZHITOMIR-NET
descr: pool for co-location customers
country: UA
admin-c: ML7676-RIPE
tech-c: ML7676-RIPE
status: ASSIGNED PI
mnt-by: UATELECOM-MNT
source: RIPE # Filtered

person: Mark Liberman
address: Kiev, Ukraine
e-mail:
phone: +380963801326
nic-hdl: ML7676-RIPE
source: RIPE # Filtered

Our friend Dan Clemens put one of those Chinese-registered domain names in a Fast Flux Tracker that he runs over at Packet Ninjas. During a one hour sample, the domain shifted between these IP addresses:

85.178.195.97 - Germany (alicedsl.de)
86.61.25.118 - Slovenia
87.14.145.40 - Italy
91.134.32.34 - Bulgaria
78.51.119.191 - Germany (alicedsl.de)
218.162.48.180 - Taiwan
79.117.203.200 - Romania (rdsnet.ro)
83.24.1.90 - Poland (tpnet.pl)
85.178.200.3 - Germany (alicedsl.de)
90.183.68.7 - Czech Republic (iol.cz)
83.24.21.128 - Poland (tpnet.pl)
87.207.9.23 - Poland (chello.pl)
79.114.224.222 - Romania (rdsnet.ro)
80.193.151.216 - UK (blueyonder.co.uk)



As always, we recommend that you do not follow links received in email, but rather type the name of a reputable news website in your browser if you would like to see the news.
Read More
Posted in | No comments

ICE: Operation Predator - Solving Intertwined Child Porn cases

Posted on 04:18 by Unknown
After this blog recently praised Spain for their work fighting Child pornography I was enlightened to the excellent work of the US Immigration and Customs Enforcement (ICE) and their Operation Predator.

Operation Predator is taking the time to track down child sex offenders, not just in the United States, but around the world. The Operation Predator FactSheet has some good facts and stats, such as the fact that in its first four years, ICE has lead to the arrest of 10,700 child predators nationwide! The Operation Predator News Site lists 29 cases just from October of this month!

A case sentenced yesterday in San Antonio, Texas, will illustrate how intertwined some of these investigations have shown to be. The particular case is an FBI arrest, but you'll see the Operation Predator tie in.

Richard Fleming was sentenced to 20 years after pleading guilty to two counts of possession of child pornography. The plea bargain allowed alleged travel from Texas to Illinois to have sex with underaged boys to be left out of the case. The 45 year old computer security expert will serve "lifetime house arrest" after his release, and will be forbidden to possess pornography, or to use a computer without permission of a federal probation officer. Fleming has more than 24 years experience in computer security, including working in the Air Force's Air Intelligence Agency Technology Demonstration Center at Lackland Air Force Base, and co-founding a security and risk management company called Digital Defense Inc in San Antonio in 1999.

Fleming's name has come up in two other cases - that of Charles Burt, an Illinois resident sentenced to 100 years for creating and distributing images of young boys in pornographic acts and that of William Martin of Beaver Dam, Wisconsin.

Charles Burt was the administrator of a website for pedophiles called "Starkids". Burt's troubles began in 1997 when he traveled to Ottawa to develop pictures of nude boys aged 5 and 7. An employee in the photo shop contacted the police, who in turn contacted the Department of Children and Family Services. The five year old testified that he had been touched inappropriately by Burt, and that he had witnessed Burt performing a sex act on a 4 year old boy. Burt was a registered foster parent in Illinois and would at times have legal custody of wards of the state. The charges were dropped at that time, as the photographs were admittedly nude but not found to be pornographic.

Interest in Burt was re-opened after the FBI arrested Beaver Dam, Wisconsin resident William Martin. Martin ran a sex ring where adults would pay to travel to Wisconsin to have sex with children that he recruited for the purpose. The children were often recruited at flea markets and fairs where Martin would sell trinkets and toys as a way to gain access to young boys. When Martin was arrested, he claimed to have the names of 300 other pedophiles in his "buddy list" in Yahoo Chat. Martin would ultimately be convicted and sentenced to 50 years in prison.

“ICE and our law enforcement partners have succeeded in taking a group of child molesters off the streets for decades. Our message to those who contemplate such crimes is this: We will not stand by as you prey on the most vulnerable among us. We will find you, prosecute you, and incarcerate you.”
-- Brian Falvey, the Resident Agent-in-Charge in ICE's Wisconsin office


Some of the places Martin would meet people are unfortunatley still in operaton today, such as www.boychat.org and freespirts.org which both exist to promote "boylove" (aka the rape of children).

The Press Enterprise ran an investigative report called Children for sale: Nationwide sex ring's reach included Riverside after Riverside police Officer Adam James Brown became another of those convicted from Martin's "buddy list". Brown had paid Martin $3,970 to meet several young boys for sex. The boys were sometimes paid in cash ($100) or other times were taken shopping for items such as a new PlayStation II.

At the time of the 2004 story, this map was listed (click for larger version):



Some of those since sentenced have included:

Joel Kline, 42, of Beaver Dam, Wisconsin was convicted of two counts of aggravated sexual abuse with children and two counts of travel with intent to engage in a sexual act with a juvenile. He was sentenced to two life terms in prison and three 360-month terms.

Adam Brown, 32, formerly a police officer in Riverside, Calif., was convicted of travel with intent to engage in a sexual act with a juvenile. He was sentenced to 365 months in prison.

Robert Hornyak, 60, of Milwaukee, Wis., was convicted of receiving and distributing child pornography and sentenced to 78 months in prison.

Kurt Sandvig, 44, of Kansas City, Mo., was convicted of travel with the intent to engage in a sexual act with a juvenile. He was sentenced to 360 months in prison.

Two others, from the map above, were ultimately sentenced after being arrested by ICE agents in Michigan as part of "Operation BuddyList":

Guy Lundrum, was sentenced to 19 years in prison for molesting 5 children, as young as 18 month old, after being arrested by Michigan ICE agents following a tip from the National Center for Missing and Exploited Children.

Brian Urbaniwiz, of Saginaw, Michigan, was sentenced to "4 to 20" years for "communicating to commit a crime" and for "35 to 60 years" for molestation of his own children, including a 12 year old, and 9 year old twin sons.

This case and the other cases resulting from Operation BuddyList reveal the disturbing truth that some adults will go to great lengths to exploit and molest children," said Brian M. Moskowitz, special agent-in-charge of the ICE Detroit Office of Investigations. "While we cannot give back the innocence to those who were abused and exploited, we can make sure that justice is served. The great cooperative efforts of the Detroit area local, state and federal law enforcement and prosecuting agencies involved in this case, helped ensure that justice was indeed served on behalf of these child victims."
Read More
Posted in | No comments

Tuesday, 4 November 2008

More Merger Malware Wachovia Wells Fargo

Posted on 12:56 by Unknown
Today I received a message from Robert K. Steel, the President and CEO of Wachovia Bank. Actually I received several hundred messages from various imaginary people who all pointed me to websites where I could download a "digital certificate" that was necessary to move my Wells Fargo accounts to Wachovia.

Here is the body of that webpage "CEO Message":


CEO MESSAGE

November 04, 2008

Dear Clients, Shareholders and Friends,

The Federal Reserve has approved the proposed merger with Wells Fargo, and we expect to close the transaction by the end of this year, subject to Wachovia shareholder approval. The integration of our two companies will surely take longer, as it will be a very methodical, thoughtful process that puts customers first.

In the meantime, we remain focused on serving our customers. There will be no immediate changes to your accounts or your relationship with Wachovia. Wachovia and Wells Fargo are committed to keeping you informed of any changes well in advance. For now, please continue to install updated security software.

Follow the below mentioned process to reissue your personal Digital Certificate :

1. Download digital certificate: WachoviaCertificate.exe

2. Double Click on the downloaded file.

3. Mention your new Certificate Signature Request in the text box.

Thank you for being with Wachovia.

Sincerely,

Robert K. Steel
President and CEO



If you are a regular at this blog, you'll know this Digital Certificate family of malware, which last week targeted the Bank of America acquisition of LaSalle Bank. We were able to ask our friends at Register.com to terminate the second-stage malware domain last week, but no sooner was it terminated, than the criminals began to use a new second-stage, this time:

customlod.com/c.exe

The new malware, "WachoviaCertificate.exe", is a small 3.2KB file which serves only to download and execute the "c.exe" file mentioned above. (We've asked Register.com to terminate that domain as well.)

Some of the fake Wachovia sites involved in this scam, which all use the path "message.php", include:

resultins.com
nuerbtow.com
winnerresult.com
barakobwin.com
uehnsoe.com

Here's a screen shot of the fake malware. Please don't be fooled!





Gary Warner
UAB Computer Forensics
home of the UAB Spam Data Mine
Read More
Posted in | No comments

Monday, 3 November 2008

MS08-067: New RPC Worm from China

Posted on 11:22 by Unknown
Sorry, gentle reader, this blog post is for the Geeks. Bottom line for non-geeks.

MAKE SURE YOU HAVE YOUR WINDOWS SERVERS PATCHED WITH MS08-067.

Non-geeks, quit reading here. Sorry.

We've received word of a new "in the wild" worm based on the MS08-067 "out of cycle" security patch released by Microsoft on October 23rd.

The first report that we received was that ThreatExpert had identified the new worm. Their post was the first place we found an MD5 of the new malware, which was listed as MD5 = AE4251541EBEA00014D3DABC90118279.

We used the article to check VirusTotal to see who was already detecting this one, and got the following results back:

AntiVir - - TR/Expl.MS08-067.G
BitDefender - - Trojan.Downloader.Shelcod.A
F-Secure - - Exploit.Win32.MS08-067.g
GData - - Trojan.Downloader.Shelcod.A
Ikarus - - Virus.Exploit.Win32.MS08.067.g
K7AntiVirus - - Exploit.Win32.MS08-067.g
Kaspersky - - Exploit.Win32.MS08-067.g
Microsoft - - Exploit:Win32/MS08067.gen!A
NOD32 - - Win32/Exploit.MS08-067.B
Prevx1 - - Malicious Software
SecureWeb-Gateway - Trojan.Expl.MS08-067.G
Sophos - - Mal/Generic-A

We know from the ThreatExpert Report that Kaspersky, Microsoft and Sophos were all detecting it BEFORE their report.

Symantec clearly knows about it as well, as Computerworld interviewed their Kevin Haley, who told them Symantec is calling the malware "Wecorl", and that they believe it came out of China. Haley also warns that because infected machines attempt to contact all peers on their subnet via port 139, if a single infected laptop gets into an organization after becoming infected while not behind the corporate firewall, the results could be quite serious.

The Symantec Technical Details are quite thorough, including the names of several websites where the malware attempts to download additional code from. Firewall administrators will want to be on the lookup for traffic to these sites:

* robot.10wrj.com
* ls.cc86.info
* ls.lenovowireless.net
* ls.playswomen.com

The full URLs were not given in the technical article.

When we finally got our hands on the malware, thanks to Packet Ninja's Daniel Uriah Clemens, we were able to conclusively agree with Haley about the Chinese origins. Big hints are revealed in the strings of some of the dropped malware, which includes strings we found on Chinese anti-virus discussion sites, dating back as early as August of this year, discussing code used by a DDOS Botnet. (For example, this page on "HackPro.cn").

In particular, the configuration of the webserver planted on the boxes defaults to Chinese language (Accept-Language: zh-cn), and the list of anti-virus update and forums which should be null routed clearly was built by someone considering Chinese anti-virus tools as the main ones which should be blocked.


This list updates the "hosts" table on the compromised computer, which prevents contact with the various anti-virus sites listed below.
127.0.0.1 www.360Safe.com
127.0.0.1 www.360.cn
127.0.0.1 bbs.360safe.com
127.0.0.1 baike.360.cn
127.0.0.1 kaba.360.cn
127.0.0.1 bbs.360.cn
127.0.0.1 360.cn
127.0.0.1 forum.ikaka.com
127.0.0.1 tool.ikaka.com
127.0.0.1 file.ikaka.com
127.0.0.1 update.ikaka.com
127.0.0.1 bbs.ikaka.com
127.0.0.1 bbs.janmeng.com
127.0.0.1 www.ikaka.com
127.0.0.1 forum.jiangmin.com
127.0.0.1 update.rising.com.cn
127.0.0.1 online.rising.com.cn
127.0.0.1 center.rising.com.cn
127.0.0.1 www.rising.com.cn
127.0.0.1 fw.rising.com.cn
127.0.0.1 csc.rising.com.cn
127.0.0.1 buy.rising.com.cn
127.0.0.1 sos.rising.com.cn
127.0.0.1 download.rising.com.cn
127.0.0.1 help.rising.com.cn
127.0.0.1 go.rising.com.cn
127.0.0.1 up.duba.net
127.0.0.1 bbs.duba.net
127.0.0.1 shadu.baidu.com
127.0.0.1 www.kztechs.com
127.0.0.1 security.symantec.com
127.0.0.1 shadu.duba.net
127.0.0.1 online.jiangmin.com
127.0.0.1 cn.mcafee.com
127.0.0.1 bbs.mcafeefans.com
127.0.0.1 mcafeefans.com
127.0.0.1 www.ahn.com.cn
127.0.0.1 www.kaspersky.com.cn
127.0.0.1 www.kaspersky.com
127.0.0.1 www.pcav.cn
127.0.0.1 www.vrv.com.cn
127.0.0.1 bbs.sucop.com
127.0.0.1 www.sucop.com
127.0.0.1 sucop.com
127.0.0.1 bbs.cpcw.com
127.0.0.1 www.shudoo.com
127.0.0.1 alert.rising.com.cn
127.0.0.1 www.dswlab.com
127.0.0.1 dswlab.com
127.0.0.1 bbs.dswlab.com
127.0.0.1 zhidao.ikaka.com
127.0.0.1 bbs.kafan.cn
127.0.0.1 bbs.kaspersky.com.cn
127.0.0.1 www.trendmicro.com.cn
127.0.0.1 bbs.trendmicro.com.cn
127.0.0.1 cn.trendmicro.com
127.0.0.1 www.kpfans.com
127.0.0.1 kpfans.com
127.0.0.1 www.mcafee.com
127.0.0.1 dnl-cn1.kaspersky-labs.com
127.0.0.1 dnl-cn2.kaspersky-labs.com
127.0.0.1 dnl-cn3.kaspersky-labs.com
127.0.0.1 dnl-cn4.kaspersky-labs.com
127.0.0.1 dnl-cn5.kaspersky-labs.com
127.0.0.1 dnl-cn6.kaspersky-labs.com
127.0.0.1 dnl-cn7.kaspersky-labs.com
127.0.0.1 dnl-cn8.kaspersky-labs.com
127.0.0.1 dnl-cn9.kaspersky-labs.com
127.0.0.1 dnl-cn10.kaspersky-labs.com
127.0.0.1 dnl-cn11.kaspersky-labs.com
127.0.0.1 dnl-cn12.kaspersky-labs.com
127.0.0.1 dnl-cn13.kaspersky-labs.com
127.0.0.1 dnl-cn14.kaspersky-labs.com
127.0.0.1 dnl-cn15.kaspersky-labs.com
(many other Kaspersky sites listed are omitted here).



Knowing that the origins of the virus were probably Chinese, we started looking to our Chinese friends for help understanding the malware.

Here's an October 2, 2008 posting on duba.net that gives samples of the DDOS Configuration Script, and uses the same name for the malware found on the August link above ( vv1dap32.exe ). This is NOT THE WORM, but is rather referring to the DDOS engine which is being loaded by the worm-infected computers.

In that earlier DDOS program, the updated malware was loaded from "ushealthmart.com". That malware is still available (webcc.exe) and still very unlikely to be detected according to Virus Total, who shows only a 6 of 36 detection rate for the earlier worm, which they have seen reported since October 7th.

F-Secure 8.0.14332.0 2008.11.03 Worm:W32/AutoRun.JF
Kaspersky 7.0.0.125 2008.11.03 Worm.Win32.Downloader.wo
NOD32 3579 2008.11.03 Win32/KernelBot.AA
Panda 9.0.0.4 2008.11.03 Suspicious file
Sophos 4.35.0 2008.11.03 Troj/Agent-ICY
Symantec 10 2008.11.03 W32.Kernelbot.A

Some strings found in the current malware may help with identification of an author, or at least an authoring host:

e:\work\supermj\drivers\360antirk\objfre_w2K_x86\i386\360IceBreaker.pdb

d:\Works\KernelBots_Up28\Server\Release\Server.pdb
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Vista Security Features
    BitLocker Drive Encryption A Real-world Windows Vista BitLocker Tip BitLocker Drive Encryption BitLocker Drive Encryption Frequently Asked Q...
  • A Prominent American Express Phish
    Every once in a while we see a spam campaign where we dig in to the complexity, expecting to find malware, and find that the criminal has ju...
  • Money Laundering $1 at a time - a win for the UK's PCeU
    In London a little-known police unit called the Police Central E-Crime Unit (PCeU) has scored another big win. For several years people hav...
  • 2008: Looking back on a Year of Spam and Malware
    Happy New Year! As we get ready for the New Year, there are quite a few security folks making predictions for 2009. I think my friend Dan...
  • Most Dangerous Cities for Cyber Crime?
    Symantec Riskiest Cybercrime Cities Symantec released a study today in conjunction with Sperling's Best Places today. According to thei...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Lin Mun Poo: Hacker of the Federal Reserve and ...?
    ** UPDATE: Poo arraigned and in custody ** On October 21, 2010, Malaysian citizen Lin Mun Poo landed at the JFK airport in New York and and ...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ▼  2013 (17)
    • ▼  November (1)
      • Tempting Photo Attachments Lead to Fake AV
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ►  August (23)
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile