This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads a new virus.
The mail is delivered with three distinct subjects so far:
A copycat spammer is using headlines:
Weekly BBC NEWS.
to send spam messages claiming a headline that the President of
Georgia is gay.
The Headlines within the email message choose from:
Mikheil Saakashvili gay scandal! New of this week!
Saakashvili have a funny woman organ (pu..sy)! see it!
Funny Saakashvili gay video...See now!Sensation!
Sensation! president of Georgia... GAY! See now!
Last news! Saakashvili (president of Georgia) the gay!
President of Georgia - intim (GAY) video! see now!
The spams contain a linked image of the President from the BBC:
We've received 300+ copies so far . . .
Malware loads from these locations:
All of those locations actually cause the virus to be delivered from a single location, the IP address:
The name of the malware is "name.avi.exe", and at the moment, only FOUR out of 36 anti-virus products detect it.
Clearly the spam is from someone who doesn't have a solid command on the English language.
So far the emails have been received from more than 40 IP addresses. Spot-checking these IP addresses for previous spam activity finds nothing in the UAB Spam Data Mine, suggesting these machines are not part of a previously used spamming botnet.
126.96.36.199 - Vietnam
188.8.131.52 - India
184.108.40.206 - JetBlue Airways, Salt Lake City, Utah
220.127.116.11 - ADVA Technologies, Sandhurst, GB
18.104.22.168 - Cable Bahamas
22.214.171.124 - Alabanza, Inc - Baltimore, Maryland
126.96.36.199 - NOC4Hosts, Tampa, Florida
188.8.131.52 - US Cellular, Knoxsville, Tennessee
184.108.40.206 - JSC Center Telecom - Russian Federation
220.127.116.11 - Moscow Local Telephone - Russian Federation
18.104.22.168 - Web Media Services - Russian Federation
22.214.171.124 - Colocation facility - Netherlands
126.96.36.199 - Severen Telecom, Russian Federation
188.8.131.52 - Czech Republic
184.108.40.206 - Bucharest, Romania
220.127.116.11 - Turk Telekom, Ankara, Turkey
18.104.22.168 - Poland
22.214.171.124 - St. Petersburg Telephone, Russian Federation
126.96.36.199 - ??
188.8.131.52 - Verizon
184.108.40.206 - Verizon
220.127.116.11 - Verizon
18.104.22.168 - Taiwan
22.214.171.124 - Italy
126.96.36.199 - Wilamette University, Salem, Oregon
188.8.131.52 - Italy
184.108.40.206 - Germany
220.127.116.11 - Federal Agency of Education, Moscow, Russia
18.104.22.168 - Austin Community College, Austin, TX
22.214.171.124 - Colombia
126.96.36.199 - Mexico
188.8.131.52 - Chile
184.108.40.206 - Colombia
220.127.116.11 - Cumberland Technologies, Mechanicsburg, PA
18.104.22.168 - SEI Data, Dillsboro, Indiana
22.214.171.124 - Korea
126.96.36.199 - Germany
188.8.131.52 - Spain
184.108.40.206 - Spain
220.127.116.11 - Albanza
18.104.22.168 - BTNet
22.214.171.124 - China