E-ZPass Spam leads to Location Aware Malware

If you drive in a city with toll roads, you are familiar with the E-Z Pass System. If you are, you may have been tempted to click on an email that looked like this:
A quick search in the Malcovery Security Spam Data Mine revealed these related emails:

But the destination websites are certainly not on E-Z Pass's domains!
When we visit one of the URLs, we are prompted to download a .zip file, containing a .exe file.

Both are conveniently named for the City and ZIP Code from which we are connected.

For example:

When we run this malware, it attempts to make contact with the following C&C locations:
At Malcovery Security, we've been tracking the ASProx botnet for some time. Most of these IP addresses were already known to belong to the ASProx botnet for some time. This is the same botnet that sent the Holiday Delivery Failure spam imitating Walmart, CostCo, and BestBuy over the holidays and that send the Court Related Malware through the early months of 2014.

Thanks to some updates from new friends on Twitter, we wanted to give an update on what we are seeing in the Malcovery Spam Data Mine. Because every advertised URL is unique, we have taken the approach of replacing the "unique stuff" with "...STUFF..." in the URLs below. The important part is that we realize that anything that you see in your logs that includes either "tmp/api" or "wp-content/api" or "components/api" and then some "STUFF" and then "=/toll" is going to be one of these URLs that is part of the current E-Z Pass spam, which began on July 8th and is still continuing here on July 12th. If you have access to Very Large Logs, we'd love to get YOUR URLs of this pattern to see if we can help webmasters identify and shut this stuff down. Note the alphabetical progression through compromised domain names? These are sorted by timestamp, not by domain name. It just so happens those are the same thing. We believe the criminals have a very large list of pre-compromised domains that they can use at will. Possibly these are just harvested passwords from other malware campaigns.

This malware is the ASProx malware. If anyone has more details on the "what happens next?" part of the malware, please do share. What we have observed and been told is that infected machines are primarily used for advertising click-fraud, but happy to learn more about those aspects and share what we learn.

  1. Nice find, Gary. do you know how the malware selected the city and zip? Was it random, or did it appear targeted based on your location or your toll road usage?

    I found a vulnerability in the Texas equivalent of E-Z Pass - TXTAG - that could be used to create highly targeted malware such as this. The login scheme makes it very easy for someone to access accounts through brute force, which would gain an attacker access to names, home addresses, toll road usage history, email, and more. I don't have an E-Z Pass account but wonder if it has the same issues.

    Here is my write-up: http://dnlongen.blogspot.com/2014/04/credit-cards-for-12-million-drivers.html

    David - it is using a Geolocation service. It nailed my zipcode both at home and at work when I didn't tunnel. When I tunneled, it gave me cities and zips corresponding to where my remote server was located.

    It has nothing to do with any records because I got two of them and I don't ever drive, nor anyone in my family. Also, I didn't know what EZ Pass was, so I looked it up. It is in the eastern states, and I nor my family have never even been anywhere near those states, plus, again I am not a driver, so I believe it is just random.

    3. I live in Australia...never heard of EZ Pass so I looked it up. Was worried as it said debt collection but my own travel tag is in credit. Glad I do my homework before clicking on these things.

