Showing posts with label zbot. Show all posts
Showing posts with label zbot. Show all posts

Thursday, September 02, 2010

Don't check that CV! Major Zeus Spam Campaign

In a bold new spam campaign, the criminals behind the Zeus Botnet have been distributing a spam email with a link to an executable file.

We first noticed this campaign in the UAB Spam Data Mine with a spam email message with the subject "you vacancy".

The body of that email read:


Thank you for the chat yesterday, it really helped me get a clearer idea
of recruitment as well as exploring any potential opportunity.

I have just spotted a mistake on the CV I sent in which my email was incorrect.

Apologies for any inconvenience caused if you have already sent me any information on anything we discussed.

My CV is an updated!
CV with the correct email on this link: http://good-resume.info/mycv.docx


The exact same email has also been seen in the UAB Spam Data Mine with several other subjects today:
908you vacancy
869Re: CV
864for CV
370Welcoming speech
115Greetings
112Hello
111Compliments
110Salutation
108Speech of welcome
100Civilities
99Hello message


The final link there that LOOKS like its going to download a Microsoft Word document, actually retrieves a file with the name:

mycv.doc.exe

The properties on that document claim to be:

BitDefender Management Console
SOFTWIN S.R.L.

The current detection rate on the malware at VirusTotal is 16/43, meaning that only 16 of 43 anti-virus products identify this as malware, although only one is calling it "zbot". Here's the VirusTotal Report for md5 = 10fd124206b15f878240f22a30eaf9fe

Our copy of the malware came from a computer with the IP address 58.222.143.148, which has been in bad company for some time. The IP is located on China Beijing Chinanet Jiangsu Province Network. Another example of Russian-speaking crooks hosting their malicious servers in China.

According to those great guys at ZeusTracker, that IP has been used for some really bad stuff.

caseoffinance.cc
dowsonstoke.cc
leadingcase.cc (Confirmed Zeus)
goldfieldforu.cc (Confirmed Zeus 8/24)
youmoneyway.cc (Confirmed Zeus 8/24)
a8228djjnedu7e8hd83ndd43d3d3.com
mikkymouse.com
first-wave-aug.com
iwfybfywi.com (Confirmed Zeus 8/19)
whiteagngo.com (Confirmed Zeus 9/2)
ekuns.com
fasterbuyers.com
hotsku.com (COnfirmed Zeus 9/1)
askuv.com (Confirmed Zeus 9/2)
good-resume.info
roundhome.net (Confirmed Zeus 8/24)
caramelloinze.net (Confirmed Zeus 9/2)
plitkinski.net
olandik.net (Confirmed Zeus 8/20)
instamfan.net (Confirmed Zeus 7/28)
tjkleen.net (Confirmed Zeus 8/9)
incornew.net (Confirmed Zeus 7/30)
autasienga.ru
jocudaidie.ru (Confirmed Zeus 7/15)
dahzunaeye.ru (Confirmed Zeus 6/23)
vohphozeeg.ru
eexiziedai.ru
railuhocal.ru (Confirmed Zeus 6/11)
blackfuril.ru
purplepron.ru (Confirmed Zeus 8/15)
cahgofoneu.ru (Confirmed Zeus 8/31)
iveeteepew.ru (Confirmed Zeus 6/23)
hazelpay.ru (Confirmed Zeus = 5/27)

We've got quite a few more details that we've already shared with law enforcement, but we wanted the public to be advised as well.

If you are a spam researcher and can tell me what botnet this is, please shoot me a note at 'gar at cis dot uab dot edu'. Here are some of the top sending IPs for this group:

72.16.178.42
81.180.66.34
187.36.133.238
186.82.57.113
186.112.107.35
77.127.135.151
195.135.239.5
76.97.210.124
195.228.164.14
24.36.173.168
93.32.50.228
211.17.116.17
24.80.8.180
190.48.237.121
212.29.192.202

Friday, August 06, 2010

Spam Campaign: Zeus's Greatest Hits spreads malware

Yesterday I had the pleasure of speaking on the subject of phishing to the Association of Certified Fraud Examiners Alabama chapter conference, hosted at the UAB School of Business, where my friend Tommie Singleton teaches Forensic Accounting.

After talking about the traditional phishing, and the statistics that we have about phishing through our UAB Phishing Operations and UAB Phishing Intelligence teams, I shared with the group that while phishing is continuing to be on the rise, compromise of banking credentials through malware is an ever growing threat.

To demonstrate the problem with malware, I opened one of my spam receiving email accounts as a user and clicked on several email messages.

I clicked on an email from July 30th that warned me that "FDIC has officially named your bank failed bank", clicked the attachment, and demonstrated my anti-virus product (on this machine I was using Microsoft Forefront) successfully protected me from the malware.

Then I clicked on an email from July 31st that claimed to have details on "Your order from Amazon.com". Again, my AV popped on the attachment.

Then I clicked on an email from August 2nd with the subject "DHL Tracking number 080231". Pop! Virus!

Then I clicked on an email from August 3rd with the subject "Notice of Underreported Incomeir" - "yeah, Incomeir" not Income. Those guys at IRS apparently don't have a spell-checker. Pop! Virus!

Then I clicked on an email that was about four hours old - "You have received a file from (email) via YouSendIt." No warning. So we unpacked the zip file and sent it to VirusTotal. 11 of 42 detections. Note that at VirusTotal, Microsoft was described as being a product that detected the malware, but VirusTotal was running a slightly newer (by a few hours) version of the AV than my laptop. Symantec and Trend and several other "big players" weren't detecting yet, but I told my audience that really didn't mean one was better than another - it was more or less a shooting of the dice who would be the "first detector."

So, what's going on with all of these new malware attachments? I would describe it as a "Zeus's Greatest Hits" campaign. Some of the most successful "Zbot spreading" spam campaigns are all being re-issued, only as attached-malware spam instead of "sending to website" spam. I've linked previous blog posts about Zeus campaigns to some of the top spam subjects in the list below. If we just look at spam for this week in the UAB Spam Data Mine, we see things like:

515 copies - "An unauthorized transaction billed to your bank account"
16,606 copies - DHL Tracking number #######
353 copies - FDIC has officially named your bank failed bank
17,143 copies - Hello
553 copies - Notice of Underreported Incomeir
10,829 copies - report
2,089 copies - Review your annual Social Security statement
166 copies - SALE OF BUSINESS Document
6,256 copies - Scan from a Xerox WorkCentre Pro N #######
412 copies - Unauthorized ACH transaction
387 copies - Welcome to Friendster
10,852 copies - You have received a file from (email) via YouSendIt.
2,479 copies - You have received an Greeting eCard
1,224 copies - Your Flight Ticket #####
301 copies - Your internet access is going to get suspended
7,513 copies - Your Order with Amazon.com
4736 - YOUR SALE TO CAN PTY LIMITED

How do we know that these emails might be related to one another? The primary reason is how I selected the list that you see above. In the UAB Spam Data Mine, I picked one of the common subjects that are being used to spread this malware, and said "Show me all the email subjects sent from the same IP address as emails which sent me the subject 'You have received an Greeting eCard' and limit myself to only consider emails from August 2010."

All of the subjects in the list above were part of the response. Now, there were also hundreds of thousands of other emails - mostly selling Viagra and watches, but ALL of the subjects above were sent from computers that also sent at least one email with the "You have received an Greeting eCard" email.

What is the malware? If you are "into" MD5s, you can check them out yourself. In the emails above, the technique is to send an executable file within a ZIP file attached to the email. Here are the most popular '.zip' attachments so far in August:

11075 | 21c4690e291dfa09cc2eef89501fd9b9 | dhl_viewer (35)
10415 | 3e11b5374aaf019fc091d51be43bfdfc | yousendit_reader (23)
7403 | a170953b22815478083d4853f7ebfe57 | report (33)
6018 | 3a88a7fdeac36395bd6b1f6185b13b2c | report.document.doc (33)
5332 | 57eaeb400b49774533c45099877911f8 | dhl_viewer (33)
4738 | bae1fff9774a4366ef73247fcf6cb394 | 08-05-2010(10).pdf (30)
3234 | d0c9552a39d20576f50bbcdc692a187c | amazon_invoice_viewer (30)
3212 | 8f025c1c63e1d11d3a5444eaba978ce7 | xerox workcentrereader (31)
2509 | ccf81bcb37af7cc0835904ec2a49c6ce | report (33)
1617 | 347d3c44ba6c3f6501406e697170192c | statement (32)
1099 | d8fbbf60aafaf400f008b3b8f2b32a41 | transaction report (28)
736 | 02154aba2c9ad2e2bcbe80b7a31246f3 | ecard (34)
576 | 4fa198977d4d3a10a7282a71cb315955 | invoice_viewer (30)
563 | 5cbcc4e1a1f1c2c37149e8db953213b0 | statement (29)
421 | 58d62a8c7fc5a690d4ff18c752a20eb6 | doc (27)
409 | 1c4031ae6c0e327f86dc4201a3532468 | facebook_passw_31.07.2010 (21)
393 | 7ce7bdbc4ce52261ba2f8773d2c196e7 | statement (27)
371 | 02857e7260d3e73811093c8826efe37e | tax report (28)
367 | 802871fdc77c47ff398de9bae8548635 | invoice_viewer (32)
362 | d410ba8345407ab17f2f3b0c98b225d0 | invoice_viewer (26)
361 | 8f0e7810523e1f9d715f951150e9c845 | tax statement (29)
341 | 5eab651ded4b0f9f949beac0dda62146 | report (28)
275 | 0acdecd08273284ce26cd99a0beed1fe | tax statement (33)
202 | 83234d04953e4b8e3f5688ec62567fe1 | changelog_30.07.2010 (35)
198 | 9a02b55cb88acf80b840504d672c21da | resume (23)
179 | d747c2928f1205c69e459b308a35fe1e | transaction report (14)
177 | 8b357aca247a729e07f0ee935c578c81 | transaction report (33)
175 | d5083f3dfefe3d6a9dc3ccd9c2fd622f | changelog_30.07.2010 (26)
138 | 3100bc960f80e8b078c3f8dd6d53de7b | dhl_tracking_ (24)
76 | 5e5b596bdf2f39b1fdfeb23821c75f41 | dhl_viewer (2)
73 | 68b13b6ecbb24322c9fe183b064eef9d | financial summary.xls (27)
51 | 5667dba64be7749c23148b564303fd11 | invoice (11)
37 | 5f2515a06e45acf9e3429ed78447e6a7 | core business advice notice ccc[1].doc (12)
33 | bbc7b06a0f0e6b09b8b7b07f3dab3b6b | statement (7)
31 | 489e4d09253414a8884fcf70326c81b9 | 090508 ccc equipment inventory v4.xls (11)
30 | 477a292406bfbbc474c35efdc92462a6 | business report.doc (12)
30 | 5bd1fb667558da6945518c28d485a37d | tax report (31)
28 | aaead684fe45133c628d3388451b7b6e | invoice_viewer (29)

The ones with low counts are mostly going to be the very newest versions (or ones that were sent in July and ended early on August 1st).

Some detects are pretty good ... for instance, that final "invoice_viewer" was first seen on August 5th (yesterday) and currently as 29 of 42 detects at VirusTotal. However, the number of malware detections on VirusTotal - RIGHT NOW - is the number in Parentheses after the malware attachment name. See the 7? and the 11? Remember that these are WORST when the email is FRESH. Some of these are from August 1st.

What about RIGHT NOW?

I'm going to scan the next two email atttached zips that arrive and show you the detections of FRESH email-delivered malware.

Oh - since the three most recent ".zip" attached emails were in this category, I'll mention this here. Another current email-delivered .zip campaign is "Your private photo attached" and contains a zip named with a random word (My last one was "accosting.zip"). It had a zero of 42 detect as a zip file.

That's because it's not malware. Its the "randomly created image" showing that I should buy pills from "yes82.ru".



Here are some of the emails from the campaign above:








Wednesday, February 03, 2010

Minipost: Fake Photo Zeus

Back on November 24th, we ran a story about a version of Zeus which pretended to be a friend letting you know that Some Jerk Posted Your Photo. The current spam is almost identical to the original, using the same subject lines of:

Subject: fw
Subject: hey
Subject: hi
Subject: re
Subject: some jerk has posted your photos
Subject: your photos

The text of the message is:
Hey, some jerk has posted your pictures (u understand what kind of pictures are there) and sent a link of them to all ur friends. I have already replied back. Said, that he is an idiot. See the link:

http://photosbank.aedswer.cz/id1073bv/get.php?email=youremail@yourdomain.com

Tamara Orozco



This is what the website looks like:



Although downloading the "PhotoArchive.exe" file is dangerous - its a Zeus Botnet that's currently only detected by 7 of 40 AV products according to this VirusTotal Report, just visiting the website is also dangerous, because it has a drive-by infector that loads from 109.95.115.36 / usasp22 / in.php

Here are some of the websites that we've seen used to host the malware so far today in the UAB Spam Data Mine:

archive.tygersg.cz
archive.uisaxr.bz
archive.zinnko.co.uk
archive.zinnko.com
archives.aedswer.cz
archives.tyerdert.co.nz
archives.tyerdery.co.uk
archives.uisaxr.bz
archives.zinnko.pl

letitbit.aedswek.cz
letitbit.aedswer.cz
letitbit.tyerdery.co.uk
letitbit.tygersk.com
letitbit.tygersm.cz
letitbit.zinnko.co.uk
letitbit.zinnko.pl

photobank.aedswer.cz
photobank.aedswet.cz
photobank.tyerderi.co.uk
photobank.tygersa.cz
photobank.tygersk.com
photobank.zinnko.cz

photosbank.aedswee.cz
photosbank.tyerdere.co.nz
photosbank.tyerderi.co.nz
photosbank.tyerderi.co.uk
photosbank.tyerdery.co.uk
photosbank.tygersg.cz
photosbank.tygersm.cz
photosbank.zinnko.com
photosbank.zinnko.vc

photoshock.tyerdere.co.nz
photoshock.tyerderi.co.uk
photoshock.tyerdero.co.nz
photoshock.uisaxr.me.uk
photoshock.zinnko.be
photoshock.zinnko.com.pl

photostock.aedswee.cz
photostock.aedswek.cz
photostock.aedswer.cz
photostock.aedswew.cz
photostock.tyerdere.co.nz
photostock.tyerderi.co.uk
photostock.uisaxr.me.uk
photostock.zinnko.co.uk
photostock.zinnko.com
photostock.zinnko.com.pl

Wednesday, January 27, 2010

Minipost: VISA Zeus

This is not the first time we've seen a Zeus dropper acting like a VISA phish . . . recently we've had the December 21st VISA and December 12th VISA campaigns. The emails are the same as the previous campaigns.

We've seen these 53 domain names so far today in the UAB Spam Data Mine:

ewasza.co.uk
ewasza.me.uk
ewasze.co.uk
ewasze.me.uk
ewaszi.co.uk
ewaszi.me.uk
ewaszu.co.uk
ewaszu.me.uk
ewaszy.co.uk
ewaszy.me.uk
freeimagesonly.be
freeimagesonly.com
freeimagesonly.co.uk
freeimagesonly.mobi
freeimagesonly.org.uk
gyueeerd.com.vc
gyueeerd.vc
gyueeerf.com.vc
gyueeerf.vc
gyueeerh.com.vc
gyueeerh.vc
gyueeers.com.vc
gyueeers.vc
gyueeeru.com.vc
gyueeeru.vc
iurseda.com.vc
iurseda.vc
iursedq.com.vc
iursedq.vc
iursedz.com.vc
iursedz.vc
medirams.com
norytiod.com.vc
norytiod.vc
norytioq.com.vc
norytioq.vc
norytior.com.vc
norytior.vc
norytiox.com.vc
norytiox.vc
sucipa.com.vc
sucipa.vc
sucipe.com.vc
sucipe.vc
sucipy.com.vc
sucipy.vc
suecond.co.nz
suecond.co.uk
suecond.eu
suecond.me.uk
sueconu.co.uk
sueconu.eu
sueconu.me.uk

They are used in an assortment of hostnames, including:

alerts.cforms.visa.com.suecond.co.nz
reports.cforms.visa.com.suecond.co.nz
statements.cforms.visa.com.suecond.co.nz
transactions.cforms.visa.com.suecond.co.nz

as well as a variety of patterns with random numbers in the middle, such as:

sessionid-1870Y9B7BZNSQB.cforms.visa.com.ewasza.co.uk
sessionid2SW8J2XJQ.cforms.visa.com.ewasza.co.uk
sessionid3PO2C59V.cforms.visa.com.ewasza.co.uk
sessionid-3U5UEDLI878OCD4.cforms.visa.com.ewasza.co.uk
sessionid-601GIB7UW4CW.cforms.visa.com.ewasza.co.uk
sessionid_73IG9LU216.cforms.visa.com.ewasza.co.uk
sessionid_78SEOF26UCWD3.cforms.visa.com.ewasza.co.uk
sessionid-I5AE0X91LP66P.cforms.visa.com.ewasza.co.uk
sessionid_ILRG2PA40.cforms.visa.com.ewasza.co.uk
sessionidLQEGFJMSS.cforms.visa.com.ewasza.co.uk
sessionid-OP5GMS06SF.cforms.visa.com.ewasza.co.uk
sessionid_OW0EZ0Z.cforms.visa.com.ewasza.co.uk
sessionid-SHTSQ7233OL.cforms.visa.com.ewasza.co.uk
sessionid_U3KJ7Q52MC.cforms.visa.com.ewasza.co.uk
sessionidVWMOE6307CRKXRM.cforms.visa.com.ewasza.co.uk

As usual, these are "Fast Flux" hosted, meaning that, for example, all of these IP addresses have been seen to resolve the domains today . . .

8.14.250.36
24.139.170.130
24.139.199.193
24.55.191.38
41.189.44.33
58.146.223.113
58.146.235.41
58.158.42.57
59.93.102.244
59.93.116.1
59.94.211.34
60.53.195.222
61.247.96.83
61.72.140.57
69.79.96.70
79.183.200.23
84.228.139.23
87.70.85.15
89.218.192.196
94.54.201.43
94.54.3.54
95.104.39.180
95.58.109.118
110.55.15.138
111.119.182.165
112.201.100.237
112.201.126.156
112.201.254.20
112.202.136.44
112.206.169.131
114.142.215.195
114.185.93.52
114.186.197.236
114.186.241.236
114.24.3.17
115.177.129.136
115.184.170.220
115.184.239.50
116.197.79.227
116.50.154.197
116.81.48.121
116.83.35.207
118.33.211.102
118.91.2.149
119.95.213.128
121.138.176.86
121.161.251.25
122.50.143.42
123.231.61.142
125.138.245.199
183.87.51.133
186.24.114.43
186.28.215.77
186.28.69.106
186.97.24.122
187.56.67.100
188.129.234.181
188.56.4.214
189.110.149.105
189.179.10.150
189.179.12.169
189.179.12.229
189.179.12.26
189.18.101.190
189.192.66.18
189.192.7.75
189.192.77.236
189.193.229.197
189.193.43.4
189.194.133.9
189.194.204.77
189.194.204.79
189.194.208.236
189.194.213.203
189.231.5.193
190.0.134.221
190.140.29.142
190.142.57.30
190.16.136.134
190.160.226.227
190.213.161.169
190.213.161.225
190.245.121.41
190.25.63.8
190.26.176.197
190.26.50.164
190.27.40.1
190.32.78.27
190.34.46.168
190.39.129.16
190.64.7.89
194.54.36.6
200.112.81.253
200.112.92.60
200.126.69.238
200.169.71.144
200.66.45.15
200.92.200.202
200.95.250.127
201.13.55.17
201.132.143.149
201.132.6.179
201.139.142.208
201.153.96.80
201.227.129.238
201.231.205.87
201.232.142.97
201.26.127.10
201.43.140.52
202.69.171.135
210.93.54.46
211.201.216.148
211.255.29.30
218.164.0.237
219.169.208.98
219.52.84.57

(More complete list of machines:

alerts.cforms.visa.com.suecond.co.nz
reports.cforms.visa.com.suecond.co.nz
statements.cforms.visa.com.suecond.co.nz
transactions.cforms.visa.com.suecond.co.nz
alerts.cforms.visa.com.ewasza.co.uk
reports.cforms.visa.com.ewasza.co.uk
statements.cforms.visa.com.ewasza.co.uk
transactions.cforms.visa.com.ewasza.co.uk
alerts.cforms.visa.com.ewasze.co.uk
reports.cforms.visa.com.ewasze.co.uk
statements.cforms.visa.com.ewasze.co.uk
transactions.cforms.visa.com.ewasze.co.uk
alerts.cforms.visa.com.ewaszi.co.uk
reports.cforms.visa.com.ewaszi.co.uk
statements.cforms.visa.com.ewaszi.co.uk
transactions.cforms.visa.com.ewaszi.co.uk
alerts.cforms.visa.com.ewaszu.co.uk
reports.cforms.visa.com.ewaszu.co.uk
statements.cforms.visa.com.ewaszu.co.uk
transactions.cforms.visa.com.ewaszu.co.uk
alerts.cforms.visa.com.ewaszy.co.uk
reports.cforms.visa.com.ewaszy.co.uk
statements.cforms.visa.com.ewaszy.co.uk
transactions.cforms.visa.com.ewaszy.co.uk
alerts.cforms.visa.com.freeimagesonly.co.uk
reports.cforms.visa.com.freeimagesonly.co.uk
statements.cforms.visa.com.freeimagesonly.co.uk
transactions.cforms.visa.com.freeimagesonly.co.uk
alerts.cforms.visa.com.suecond.co.uk
reports.cforms.visa.com.suecond.co.uk
statements.cforms.visa.com.suecond.co.uk
transactions.cforms.visa.com.suecond.co.uk
alerts.cforms.visa.com.sueconu.co.uk
reports.cforms.visa.com.sueconu.co.uk
statements.cforms.visa.com.sueconu.co.uk
transactions.cforms.visa.com.sueconu.co.uk
alerts.cforms.visa.com.ewasza.me.uk
reports.cforms.visa.com.ewasza.me.uk
statements.cforms.visa.com.ewasza.me.uk
transactions.cforms.visa.com.ewasza.me.uk
alerts.cforms.visa.com.ewasze.me.uk
reports.cforms.visa.com.ewasze.me.uk
statements.cforms.visa.com.ewasze.me.uk
transactions.cforms.visa.com.ewasze.me.uk
alerts.cforms.visa.com.ewaszi.me.uk
reports.cforms.visa.com.ewaszi.me.uk
statements.cforms.visa.com.ewaszi.me.uk
transactions.cforms.visa.com.ewaszi.me.uk
alerts.cforms.visa.com.ewaszu.me.uk
reports.cforms.visa.com.ewaszu.me.uk
statements.cforms.visa.com.ewaszu.me.uk
transactions.cforms.visa.com.ewaszu.me.uk
alerts.cforms.visa.com.ewaszy.me.uk
reports.cforms.visa.com.ewaszy.me.uk
statements.cforms.visa.com.ewaszy.me.uk
transactions.cforms.visa.com.ewaszy.me.uk
alerts.cforms.visa.com.suecond.me.uk
reports.cforms.visa.com.suecond.me.uk
statements.cforms.visa.com.suecond.me.uk
transactions.cforms.visa.com.suecond.me.uk
alerts.cforms.visa.com.sueconu.me.uk
reports.cforms.visa.com.sueconu.me.uk
statements.cforms.visa.com.sueconu.me.uk
transactions.cforms.visa.com.sueconu.me.uk
alerts.cforms.visa.com.freeimagesonly.org.uk
reports.cforms.visa.com.freeimagesonly.org.uk
statements.cforms.visa.com.freeimagesonly.org.uk
transactions.cforms.visa.com.freeimagesonly.org.uk
alerts.cforms.visa.com.gyueeerd.com.vc
reports.cforms.visa.com.gyueeerd.com.vc
statements.cforms.visa.com.gyueeerd.com.vc
transactions.cforms.visa.com.gyueeerd.com.vc
alerts.cforms.visa.com.gyueeerf.com.vc
reports.cforms.visa.com.gyueeerf.com.vc
statements.cforms.visa.com.gyueeerf.com.vc
transactions.cforms.visa.com.gyueeerf.com.vc
alerts.cforms.visa.com.gyueeerh.com.vc
reports.cforms.visa.com.gyueeerh.com.vc
statements.cforms.visa.com.gyueeerh.com.vc
transactions.cforms.visa.com.gyueeerh.com.vc
alerts.cforms.visa.com.gyueeers.com.vc
reports.cforms.visa.com.gyueeers.com.vc
statements.cforms.visa.com.gyueeers.com.vc
transactions.cforms.visa.com.gyueeers.com.vc
alerts.cforms.visa.com.gyueeeru.com.vc
reports.cforms.visa.com.gyueeeru.com.vc
statements.cforms.visa.com.gyueeeru.com.vc
transactions.cforms.visa.com.gyueeeru.com.vc
alerts.cforms.visa.com.iurseda.com.vc
reports.cforms.visa.com.iurseda.com.vc
statements.cforms.visa.com.iurseda.com.vc
transactions.cforms.visa.com.iurseda.com.vc
alerts.cforms.visa.com.iursedq.com.vc
reports.cforms.visa.com.iursedq.com.vc
statements.cforms.visa.com.iursedq.com.vc
transactions.cforms.visa.com.iursedq.com.vc
alerts.cforms.visa.com.iursedz.com.vc
reports.cforms.visa.com.iursedz.com.vc
statements.cforms.visa.com.iursedz.com.vc
transactions.cforms.visa.com.iursedz.com.vc
alerts.cforms.visa.com.norytiod.com.vc
reports.cforms.visa.com.norytiod.com.vc
statements.cforms.visa.com.norytiod.com.vc
transactions.cforms.visa.com.norytiod.com.vc
alerts.cforms.visa.com.norytioq.com.vc
reports.cforms.visa.com.norytioq.com.vc
statements.cforms.visa.com.norytioq.com.vc
transactions.cforms.visa.com.norytioq.com.vc
alerts.cforms.visa.com.norytior.com.vc
reports.cforms.visa.com.norytior.com.vc
statements.cforms.visa.com.norytior.com.vc
transactions.cforms.visa.com.norytior.com.vc
alerts.cforms.visa.com.norytiox.com.vc
reports.cforms.visa.com.norytiox.com.vc
statements.cforms.visa.com.norytiox.com.vc
transactions.cforms.visa.com.norytiox.com.vc
alerts.cforms.visa.com.sucipa.com.vc
reports.cforms.visa.com.sucipa.com.vc
statements.cforms.visa.com.sucipa.com.vc
transactions.cforms.visa.com.sucipa.com.vc
alerts.cforms.visa.com.sucipe.com.vc
reports.cforms.visa.com.sucipe.com.vc
statements.cforms.visa.com.sucipe.com.vc
transactions.cforms.visa.com.sucipe.com.vc
alerts.cforms.visa.com.sucipy.com.vc
reports.cforms.visa.com.sucipy.com.vc
statements.cforms.visa.com.sucipy.com.vc
transactions.cforms.visa.com.sucipy.com.vc
alerts.cforms.visa.com.freeimagesonly.be
reports.cforms.visa.com.freeimagesonly.be
statements.cforms.visa.com.freeimagesonly.be
transactions.cforms.visa.com.freeimagesonly.be
alerts.cforms.visa.com.freeimagesonly.com
reports.cforms.visa.com.freeimagesonly.com
statements.cforms.visa.com.freeimagesonly.com
transactions.cforms.visa.com.freeimagesonly.com
alerts.cforms.visa.com.medirams.com
reports.cforms.visa.com.medirams.com
statements.cforms.visa.com.medirams.com
transactions.cforms.visa.com.medirams.com
alerts.cforms.visa.com.suecond.eu
reports.cforms.visa.com.suecond.eu
statements.cforms.visa.com.suecond.eu
transactions.cforms.visa.com.suecond.eu
alerts.cforms.visa.com.sueconu.eu
reports.cforms.visa.com.sueconu.eu
statements.cforms.visa.com.sueconu.eu
transactions.cforms.visa.com.sueconu.eu
alerts.cforms.visa.com.freeimagesonly.mobi
reports.cforms.visa.com.freeimagesonly.mobi
statements.cforms.visa.com.freeimagesonly.mobi
transactions.cforms.visa.com.freeimagesonly.mobi
alerts.cforms.visa.com.gyueeerd.vc
reports.cforms.visa.com.gyueeerd.vc
statements.cforms.visa.com.gyueeerd.vc
transactions.cforms.visa.com.gyueeerd.vc
alerts.cforms.visa.com.gyueeerf.vc
reports.cforms.visa.com.gyueeerf.vc
statements.cforms.visa.com.gyueeerf.vc
transactions.cforms.visa.com.gyueeerf.vc
alerts.cforms.visa.com.gyueeerh.vc
reports.cforms.visa.com.gyueeerh.vc
statements.cforms.visa.com.gyueeerh.vc
transactions.cforms.visa.com.gyueeerh.vc
alerts.cforms.visa.com.gyueeers.vc
reports.cforms.visa.com.gyueeers.vc
statements.cforms.visa.com.gyueeers.vc
transactions.cforms.visa.com.gyueeers.vc
alerts.cforms.visa.com.gyueeeru.vc
reports.cforms.visa.com.gyueeeru.vc
statements.cforms.visa.com.gyueeeru.vc
transactions.cforms.visa.com.gyueeeru.vc
alerts.cforms.visa.com.iurseda.vc
reports.cforms.visa.com.iurseda.vc
statements.cforms.visa.com.iurseda.vc
transactions.cforms.visa.com.iurseda.vc
alerts.cforms.visa.com.iursedq.vc
reports.cforms.visa.com.iursedq.vc
statements.cforms.visa.com.iursedq.vc
transactions.cforms.visa.com.iursedq.vc
alerts.cforms.visa.com.iursedz.vc
reports.cforms.visa.com.iursedz.vc
statements.cforms.visa.com.iursedz.vc
transactions.cforms.visa.com.iursedz.vc
alerts.cforms.visa.com.norytiod.vc
reports.cforms.visa.com.norytiod.vc
statements.cforms.visa.com.norytiod.vc
transactions.cforms.visa.com.norytiod.vc
alerts.cforms.visa.com.norytioq.vc
reports.cforms.visa.com.norytioq.vc
statements.cforms.visa.com.norytioq.vc
transactions.cforms.visa.com.norytioq.vc
alerts.cforms.visa.com.norytior.vc
reports.cforms.visa.com.norytior.vc
statements.cforms.visa.com.norytior.vc
transactions.cforms.visa.com.norytior.vc
alerts.cforms.visa.com.norytiox.vc
reports.cforms.visa.com.norytiox.vc
statements.cforms.visa.com.norytiox.vc
transactions.cforms.visa.com.norytiox.vc
alerts.cforms.visa.com.sucipa.vc
reports.cforms.visa.com.sucipa.vc
statements.cforms.visa.com.sucipa.vc
transactions.cforms.visa.com.sucipa.vc
alerts.cforms.visa.com.sucipe.vc
reports.cforms.visa.com.sucipe.vc
statements.cforms.visa.com.sucipe.vc
transactions.cforms.visa.com.sucipe.vc
alerts.cforms.visa.com.sucipy.vc
reports.cforms.visa.com.sucipy.vc
statements.cforms.visa.com.sucipy.vc
transactions.cforms.visa.com.sucipy.vc


Tuesday, January 26, 2010

American Bankers Association version of Zeus Bot / Zbot

Today our top spam-delivered malware is coming to us in the guise of a message from the American Bankers Association.

Subject lines seen in the UAB Spam Data Mine include:

An unauthorized transaction billed from your bank account
An unauthorized transaction billed from your bank card
An unauthorized transaction billed to your bank account
An unauthorized transaction billed to your bank card
unauthorized transaction
unauthorized transaction billed from your bank account
unauthorized transaction billed from your bank card
unauthorized transaction billed to your bank account
unauthorized transaction billed to your bank card

While most of the emails come from the email address:

noreply@mail.aba.com

others are arriving with a message_id in the from address, such as:

message_ODRL6039id@mail.aba.com

The emails look like this:

An unauthorized transaction billed from your bank card.

Amount of transaction: $1781.30
Transaction ID: 7980-9779263

Please review the transaction report by clicking the link below:

get the transaction report

---------
Letter ID 9996-0347362324-49929775497-69019696317-70662423061-65867724-18065800918


where the "Amount of transaction" and "Transaction ID"

The website looks like this:



Hostnames that we saw in the spam include:

machine
-----------------------------------
getreport.aba.com.edfa4.com.vc
getreport.aba.com.edfa4.vc
getreport.aba.com.edfa5.com.vc
getreport.aba.com.edfa5.vc
getreport.aba.com.edfa6.com.vc
getreport.aba.com.edfa6.vc
getreport.aba.com.edfa7.com.vc
getreport.aba.com.edfa7.vc
getreport.aba.com.edfa8.com.vc
getreport.aba.com.edfa8.vc
getreport.aba.com.ferdsae.vc
getreport.aba.com.gertfdv.am
getreport.aba.com.sawesae.vc
getreport.aba.com.sawesag.com.vc
getreport.aba.com.sawesaj.com.vc
getreport.aba.com.sawesal.com.vc
getreport.aba.com.sawesao.vc
getreport.aba.com.sawesaq.vc
getreport.aba.com.sawesat.vc
getreport.aba.com.sawesau.vc
getreport.aba.com.uifersag.no.com
getreport.aba.com.uifersag.uy.com
getreport.aba.com.uifersar.cn.com
getreport.aba.com.uifersar.no.com
getreport.aba.com.uifersar.uy.com
getreport.aba.com.uifersat.cn.com
getreport.aba.com.uifersat.no.com
getreport.aba.com.uifersat.uy.com
getreport.aba.com.yhuusd.com.vc
getreport.aba.com.yhuusd.vc
getreport.aba.com.yhuush.vc

The malware that is dropped from this website, "transactionreport.exe" is almost entirely undetected according to this VirusTotal Report. Only six of forty-one AV products currently detect this malware, and only two of them are properly identifying it as Zeus.

Kaspersky calls it "Trojan-Spy.Win32.Zbot.gen", as does Sunbelt.

Authentium and F-Prot heuristically detect it as "El dorado", which is pretty close behavior-wise to Zbot. F-Secure and McAfee identify it as a risk, but don't classify it further.

Besides the obvious "transactionreport.exe", there is also a drive-by infector which originates at the IP address "109.95.114.251" on the path "/us01d/in.php". I'll update this post later this evening with more details about that malware path, but I would assume at this point its going to drop a PDF that leads to a fake AV product.

That IP address is famously associated with Zeus through the owner of its network - actually called in the WHOIS data "VISHCLUB" and described as being "Kanyovskiy Andriy Yuriyovich" of Kazakhstan - akanyovskiy@troyak.org. Perhaps send him an email and ask him how the life of crime is treating him. Apparently there are no laws against providing hosting for cybercriminals in Kazakhstan, but several sources say this IP address is actually in Great Britain, and I'm pretty sure they don't stand for this kind of behavior. Criminal emails such as:
Natalia Ilina - try@5mx.ru
Polina Kuznetsova - wsw@maillife.ru
Mikhail Vorobiev - bombs@maillife.ru
taffy@blogbuddy.ru
and kievsk@yandex.ru

all show up when you investigate previous Zeus infections that use this netblock with domain names like:

hostingdnssite.com
quicksitehostdns.com
platinumhostingservice.com
nekovo.ru
dnsserverbackupzones.com
windowsserverinfo.com
androzo.ru

and that's just so far in January 2010!

A Facebook version of the Zeus malware was active last night and this morning, but that's an on-going extension of the previously mentioned version.

Saturday, January 23, 2010

AOL Update spreads Zeus / Zbot

The UAB Spam Data Mine has been receiving emails like these all weekend . . .

Dear AOL Instant Messenger (AIM) user,

Your AIM account is flagged as inactive. Within the following 72 hours it’ll be deleted from the system.

If you plan to use this account in the future, you have to download and launch the latest update for the AIM. This update is critical.

In order to install the update use the following link. This link is generated exclusively for your account and is available within a certain period of time. As soon as this link is not available anymore you will get another letter.

Thank you,

AIM Service Team

This e-mail has been sent from an e-mail address that is not monitored. Please do not reply to this message. We are unable to respond to any replies.


The email subjects today are primarily three:

AOL Instant Messenger critical update
Your AOL Instant Messenger account is flagged as inactive
Your AOL Instant Messenger account will be deleted



The download link points to a file called:

aimupdate_7.1.6.475

File size: 130048 bytes
MD5 : 506b74fab91958e0a9714c4ef5a9f24d
SHA1 : bdb3ecffb2245a6a3f4bda3880aa562a13bff421

VirusTotal of course informs us that this is a Zeus / Zbot infector:

(See VirusTotal Report)

Before you even download the "executable", there is drive-by malware that hits the visitor.

== 109.95.114.251/usr5432/in.php is called as a result of an iframe on the page.

This leads to the download and loading of:

== 109.95.114.251/usr5432/xd/pdf.pdf
and then
== /usr5432/xd/sNode.php
and /usr5432/xd/swfobject.js

and then nekovo.ru/kissme/rec.php
which downloads nekovo.ru/abs.exe

abs.exe is only detectable by 5 of 41 anti-virus products according to VirusTotal, most of them detecting them as "Hiloti":

VirusTotal Report on Hiloti - abs.exe




Websites that have been used in this campaign, all using the path "products/aimController.php", include:


machine
--------------------------------
update.aol.com.favucca.co.im
update.aol.com.favuccaco.im
update.aol.com.favucca.com.im
update.aol.com.favuccacom.im
update.aol.com.favuccaim
update.aol.com.favucca.im
update.aol.com.favucca.net.im
update.aol.com.favuccanet.im
update.aol.com.favucca.org.im
update.aol.com.favuccaorg.im
update.aol.com.hasdxzzw.co.im
update.aol.com.hasdxzzw.com.im
update.aol.com.hasdxzzw.im
update.aol.com.hasdxzzw.net.im
update.aol.com.hasdxzzw.org.im
update.aol.com.oifeazx.com.pl
update.aol.com.oifeazxcom.pl
update.aol.com.oijeaxx.com.pl
update.aol.com.oijeaxxcom.pl
update.aol.com.oijeazx.com.pl
update.aol.com.oijeazxcom.pl
update.aol.com.oijhaxx.com.pl
update.aol.com.oijhaxxcom.pl
update.aol.com.oijhayx.com.pl
update.aol.com.oijhayxcom.pl
update.aol.com.oijqayx.com.pl
update.aol.com.oijqayxcom.pl
update.aol.com.oiybaqr.com.pl
update.aol.com.oiybaqrcom.pl
update.aol.com.oiybkqr.com.pl
update.aol.com.oiybkqrcom.pl
update.aol.com.oiyqaqr.com.pl
update.aol.com.oiyqaqrcom.pl
update.aol.com.oiyqayr.com.pl
update.aol.com.oiyqayrcom.pl
update.aol.com.oiyqayx.com.pl
update.aol.com.oiyqayxcom.pl
update.aol.com.onybkqr.com.pl
update.aol.com.onybkqrcom.pl
update.aol.com.onybksm.com.pl
update.aol.com.onybksmcom.pl
update.aol.com.onybksr.com.pl
update.aol.com.onybksrcom.pl
update.aol.com.onybmsm.com.pl
update.aol.com.onybmsmcom.pl
update.aol.com.pikie.com.pl
update.aol.com.pikoe.com.pl
update.aol.com.pikqe.com.pl
update.aol.com.pikye.com.pl
update.aol.com.pioqe.com.pl
update.aol.com.pioqo.com.pl
update.aol.com.saxxxzabe
update.aol.com.saxxxzfbe
update.aol.com.saxxxznbe
update.aol.com.saxxxzn.be
update.aol.com.terfkioa.com.pl
update.aol.com.terfkioa.net.pl
update.aol.com.terfkioc.com.pl
update.aol.com.terfkioc.net.pl
update.aol.com.terfkiod.com.pl
update.aol.com.terfkiod.net.pl
update.aol.com.terfkiof.com.pl
update.aol.com.terfkiof.net.pl
update.aol.com.terfkioq.com.pl
update.aol.com.terfkioq.net.pl
update.aol.com.terfkior.com.pl
update.aol.com.terfkios.com.pl
update.aol.com.terfkios.net.pl
update.aol.com.terfkiox.com.pl
update.aol.com.terfkiox.net.pl
update.aol.com.yhff10.com.pl
update.aol.com.yhff11.com.pl
update.aol.com.yhffd0.com.pl
update.aol.com.yhffd1.com.pl
update.aol.com.yhffd2.com.pl
update.aol.com.yhffd3.com.pl
update.aol.com.yhffd4.com.pl
update.aol.com.yhffd5.com.pl
update.aol.com.yhffd6.com.pl
update.aol.com.yhffd7.com.pl
update.aol.com.yhffd8.com.pl
update.aol.com.yhffd9.com.pl
update.aol.com.yhnki6u.com.pl
update.aol.com.yhnki6ucom.pl
update.aol.com.yhnkz6u.com.pl
update.aol.com.yhnkz6ucom.pl
update.aol.com.yhuki6u.com.pl
update.aol.com.yhuki6ucom.pl
update.aol.com.yhuoi6u.com.pl
update.aol.com.yhuoi6ucom.pl
update.aol.com.yhuoo6u.com.pl
update.aol.com.yhuoo6ucom.pl
update.aol.com.yhuou6u.com.pl
update.aol.com.yhuou6ucom.pl
update.aol.com.yhusssqb.com.pl
update.aol.com.yhusssqc.com.pl
update.aol.com.yhusssqd.com.pl
update.aol.com.yhusssqf.com.pl
update.aol.com.yhusssqg.com.pl
update.aol.com.yhusssqh.com.pl
update.aol.com.yhusssqj.com.pl
update.aol.com.yhusssqn.com.pl
update.aol.com.yhusssqq.com.pl
update.aol.com.yhusssqs.com.pl
update.aol.com.yhusssqu.com.pl
update.aol.com.yhusssqv.com.pl
update.aol.com.yhusssqw.com.pl
update.aol.com.yhusssqy.com.pl
update.aol.com.yhuui6u.com.pl
update.aol.com.yhuui6ucom.pl
update.aol.com.yhuyu6u.com.pl
update.aol.com.yhuyu6ucom.pl
update.aol.com.yhuyu6y.com.pl
update.aol.com.yhuyu6ycom.pl
update.aol.com.yhyki6u.com.pl
update.aol.com.yhyki6ucom.pl
(116 rows)

Monday, January 18, 2010

Sendspace Zbot spreader a Flashback to Dec 15-20

From December 15th to December 20th, the top Zbot or "Zeus" trojan spreader was a spam email campaign which claimed to have news about a photo that may depict the recipient. The "photo" was actually called "photo.exe" and the website from which it was to be downloaded was intended to look like "Sendspace.com", a popular file sharing service.

Beginning early in the morning of January 16th, the UAB Spam Data Mine began to notice that the Sendspace version of Zeus may be making a return. On January 16th, we received six copies of the spam, nearly identical to those received December 15-20. They came between 6:15 and 8:30 AM, and then stopped.

The spam messages ask a variation of question such as:

Hey! Is this photo yours?

Subject such as:
Fw:your photo
Re:your photo
Re:
Fw:look


and provide a link supposedly to a "sendspace" page for you to see the photo.

On January 17th, we saw another burst, beginning shortly after 8:00 AM, and ending about 10:15 AM, with 90 messages being received.

Then at 11:15 PM on January 17th the real campaign began, and has been flowing steadily ever since, although the spam is definitely on a rising trend - we've seen just over 700 copies today so far.

The URLs we've seen in the spam are these:

www.sendspace.com.iko999j0.com.pl
www.sendspace.com.iko999j0.compl
www.sendspace.com.iko999j1.com.pl
www.sendspace.com.iko999j1.compl
www.sendspace.com.iko999j1com.pl
www.sendspace.com.iko999j2.com.pl
www.sendspace.com.iko999j2.compl
www.sendspace.com.iko999j3.com.pl
www.sendspace.com.iko999j3com.pl
www.sendspace.com.iko999j4.com.pl
www.sendspace.com.iko999j5.com.pl
www.sendspace.com.iko999j5.compl
www.sendspace.com.iko999j6.com.pl
www.sendspace.com.iko999j6.compl
www.sendspace.com.iko999j7.com.pl
www.sendspace.com.iko999j7.compl
www.sendspace.com.iko999j7com.pl
www.sendspace.com.iko999j8.com.pl
www.sendspace.com.iko999j9.com.pl
www.sendspace.com.iko999j9com.pl
www.sendspace.com.iko999je.com.pl
www.sendspace.com.iko999je.compl
www.sendspace.com.iko999jq.com.pl
www.sendspace.com.iko999jqcom.pl
www.sendspace.com.iko999jr.com.pl
www.sendspace.com.iko999jrcom.pl
www.sendspace.com.iko999jt.com.pl
www.sendspace.com.iko999jw.com.pl
www.sendspace.com.iko999jw.compl
www.sendspace.com.iko999jwcom.pl
www.sendspace.comiko999j1.com.pl
www.sendspace.comiko999j4.com.pl
www.sendspace.comiko999j5.com.pl
www.sendspace.comiko999j7.com.pl
www.sendspace.comiko999j8.com.pl
www.sendspace.comiko999j9.com.pl
www.sendspace.comiko999je.com.pl
www.sendspace.comiko999jq.com.pl
www.sendspacecom.iko999j1.com.pl
www.sendspacecom.iko999j4.com.pl
www.sendspacecom.iko999j6.com.pl
www.sendspacecom.iko999j7.com.pl
www.sendspacecom.iko999j8.com.pl
www.sendspacecom.iko999j9.com.pl
www.sendspacecom.iko999je.com.pl
www.sendspacecom.iko999jw.com.pl
wwwsendspace.com.iko999j1.com.pl
wwwsendspace.com.iko999j3.com.pl
wwwsendspace.com.iko999j4.com.pl
wwwsendspace.com.iko999j7.com.pl
wwwsendspace.com.iko999j8.com.pl
wwwsendspace.com.iko999j9.com.pl

Note the two pairs of typos? Some ".compl" instead of ".com.pl" and some "sendspacecom" instead of "sendspace.com" and the "wwwsendspace" instead of "www.sendspace". Those are the reasons bad guys do test runs such as we saw on the 16th and 17th. They need to get their bugs worked out.

The webpage looks like this:





While they are at it, perhaps they'll remember to update their malware as well. The version being distributed in this campaign is the same version that was being distributed when the campaign ended on December 20th, which means that 34 out of 41 anti-virus products can detect it, according to this Virus Total Report.

The websites have a secondary infector. An IFRAME in the code calls a malicious website from "gerolli.co.uk". Last go-around it was pulling a file from the "/2img/" subdirectory there. This time around its pulling a file from "/3img/in.php", which when loaded causes "pdf.pdf" to be dropped on the machine, which leads to a Fake Anti-Virus product being installed within a few minutes.

The Zeus bot uses "stomaid.ru" as its Command & Control - just as it has since December 9th.

The computers hosting the "sendspace" version of this webpage are also hosting the "USAA" version that we discussed in yesterday's article - USAA Bank Latest Avalanche Scam.

If you want to see the December version websites, they are listed below:

www.sendspace.com.1citvil1.be
www.sendspace.com.beermeetibe
www.sendspace.com.beermeeti.be
www.sendspace.com.dftjilllcom
www.sendspace.com.dftjilll.com
www.sendspace.com.dftjilllnet
www.sendspace.com.dftjilll.net
www.sendspace.com.fbermeetibe
www.sendspace.com.fbermeeti.be
www.sendspace.com.fbsftiilcom
www.sendspace.com.fbsftiil.com
www.sendspace.com.fbsftiilnet
www.sendspace.com.fbsftiil.net
www.sendspace.com.febrmeeti.be
www.sendspace.com.feeekyyiebe
www.sendspace.com.feeekyyie.be
www.sendspace.com.feeetyyiebe
www.sendspace.com.feeetyyie.be
www.sendspace.com.feeezkyiebe
www.sendspace.com.feeezkyie.be
www.sendspace.com.feeeztyiebe
www.sendspace.com.feeeztyie.be
www.sendspace.com.feeezykiebe
www.sendspace.com.feeezykie.be
www.sendspace.com.feeezytiebe
www.sendspace.com.feeezytie.be
www.sendspace.com.feeezyyiebe
www.sendspace.com.feeezyyie.be
www.sendspace.com.feeezyyikbe
www.sendspace.com.feeezyyik.be
www.sendspace.com.feeezyykebe
www.sendspace.com.feeezyyke.be
www.sendspace.com.feekzyyie.be
www.sendspace.com.feermeetibe
www.sendspace.com.feermeeti.be
www.sendspace.com.feetzyyie.be
www.sendspace.com.fekezyyiebe
www.sendspace.com.fekezyyie.be
www.sendspace.com.fetezyyie.be
www.sendspace.com.ffmjilllcom
www.sendspace.com.ffmjilll.com
www.sendspace.com.ffmjilllnet
www.sendspace.com.ffmjilll.net
www.sendspace.com.ffmjtlllcom
www.sendspace.com.ffmjtlll.com
www.sendspace.com.ffmjtlllnet
www.sendspace.com.ffmjtlll.net
www.sendspace.com.ffmjttllcom
www.sendspace.com.ffmjttll.com
www.sendspace.com.fftjilllcom
www.sendspace.com.fftjilll.com
www.sendspace.com.fftjilllnet
www.sendspace.com.fftjilll.net
www.sendspace.com.fkeezyyiebe
www.sendspace.com.fkeezyyie.be
www.sendspace.com.ftcftiilcom
www.sendspace.com.ftcftiil.com
www.sendspace.com.ftcftiilnet
www.sendspace.com.ftcftiil.net
www.sendspace.com.fteezyyiebe
www.sendspace.com.fteezyyie.be
www.sendspace.com.ftsftiilcom
www.sendspace.com.ftsftiil.com
www.sendspace.com.ftsftiilnet
www.sendspace.com.ftsftiil.net
www.sendspace.com.ftsftiitcom
www.sendspace.com.ftsftiit.com
www.sendspace.com.ftsftiitnet
www.sendspace.com.ftsftiit.net
www.sendspace.com.ftsftiulcom
www.sendspace.com.ftsftiul.com
www.sendspace.com.ftsftiulnet
www.sendspace.com.ftsftiul.net
www.sendspace.com.ftsftkilcom
www.sendspace.com.ftsftkil.com
www.sendspace.com.ftsftkilnet
www.sendspace.com.ftsftkil.net
www.sendspace.com.ftsftmilcom
www.sendspace.com.ftsftmil.com
www.sendspace.com.ftsfttilcom
www.sendspace.com.ftsfttil.com
www.sendspace.com.ftsfttilnet
www.sendspace.com.ftsfttil.net
www.sendspace.com.hcitvil1.be
www.sendspace.com.hreseet01.be
www.sendspace.com.hufteejkibe
www.sendspace.com.hufteejki.be
www.sendspace.com.i1itvil1.be
www.sendspace.com.ic1tvil1.be
www.sendspace.com.ichtvil1.be
www.sendspace.com.ici1vil1.be
www.sendspace.com.icihvil1.be
www.sendspace.com.icit1il1.be
www.sendspace.com.icithil1.be
www.sendspace.com.icitv1l1.be
www.sendspace.com.icitvhl1.be
www.sendspace.com.icitvi11.be
www.sendspace.com.icitvih1.be
www.sendspace.com.icitvil1.be
www.sendspace.com.ihitvil1.be
www.sendspace.com.ireheet01.be
www.sendspace.com.ireseet01.be
www.sendspace.com.ireseht01.be
www.sendspace.com.iresehtt1.be
www.sendspace.com.iresett01.be
www.sendspace.com.ireshet01.be
www.sendspace.com.ireteht01.be
www.sendspace.com.irhseet01.be
www.sendspace.com.iteseht01.be
www.sendspace.com.jtualasabe
www.sendspace.com.jtualasa.be
www.sendspace.com.juzeepee0.jpn.com
www.sendspace.com.kjifatilacom
www.sendspace.com.kjifatila.com
www.sendspace.com.ktualasabe
www.sendspace.com.ktualasa.be
www.sendspace.com.lhfteejkibe
www.sendspace.com.lhfteejki.be
www.sendspace.com.lipskuiil.com
www.sendspace.com.lipskuiil.jpn.com
www.sendspace.com.lipskuiil.kr.com
www.sendspace.com.lipskuiil.no.com
www.sendspace.com.lipskuiil.uy.com
www.sendspace.com.lufheejkibe
www.sendspace.com.lufheejki.be
www.sendspace.com.lufteejkibe
www.sendspace.com.lufteejki.be
www.sendspace.com.lufteejkvbe
www.sendspace.com.lufteejkv.be
www.sendspace.com.lufteejvibe
www.sendspace.com.lufteejvi.be
www.sendspace.com.lufteevkibe
www.sendspace.com.lufteevki.be
www.sendspace.com.luftevjkibe
www.sendspace.com.luftevjki.be
www.sendspace.com.lufthejkibe
www.sendspace.com.lufthejki.be
www.sendspace.com.luhteejkibe
www.sendspace.com.luhteejki.be
www.sendspace.com.mjifatilacom
www.sendspace.com.mjifatila.com
www.sendspace.com.mjifatilwcom
www.sendspace.com.mjifatilw.com
www.sendspace.com.mjifatiwacom
www.sendspace.com.mjifatiwa.com
www.sendspace.com.mjifatwlacom
www.sendspace.com.mjifatwla.com
www.sendspace.com.mjifawilacom
www.sendspace.com.mjifawila.com
www.sendspace.com.mjifwtilacom
www.sendspace.com.mjifwtila.com
www.sendspace.com.mjiuatilacom
www.sendspace.com.mjiuatila.com
www.sendspace.com.mjiwatilacom
www.sendspace.com.mjiwatila.com
www.sendspace.com.mjufatilacom
www.sendspace.com.mjufatila.com
www.sendspace.com.mjwfatilacom
www.sendspace.com.mjwfatila.com
www.sendspace.com.mnvdtdt.co.uk
www.sendspace.com.mnvdtdt.me.uk
www.sendspace.com.mnvdtdt.orguk
www.sendspace.com.mnvdtdt.org.uk
www.sendspace.com.mnvdtdtorg.uk
www.sendspace.com.modeservicepp.co.kr
www.sendspace.com.modeservicepp.com
www.sendspace.com.modeservicepp.kr
www.sendspace.com.muifatilacom
www.sendspace.com.muifatila.com
www.sendspace.com.mwifatilacom
www.sendspace.com.mwifatila.com
www.sendspace.com.polaasa1qc.com
www.sendspace.com.pretopsd.co.uk
www.sendspace.com.pretopsdco.uk
www.sendspace.com.pretopsd.me.uk
www.sendspace.com.pretopsd.org.uk
www.sendspace.com.tjualasabe
www.sendspace.com.tjualasa.be
www.sendspace.com.tkualasabe
www.sendspace.com.tkualasa.be
www.sendspace.com.ttjalasabe
www.sendspace.com.ttjalasa.be
www.sendspace.com.ttkalasabe
www.sendspace.com.ttkalasa.be
www.sendspace.com.ttuajasabe
www.sendspace.com.ttuajasa.be
www.sendspace.com.ttuakasabe
www.sendspace.com.ttuakasa.be
www.sendspace.com.ttualakabe
www.sendspace.com.ttualaka.be
www.sendspace.com.ttualasabe
www.sendspace.com.ttualasa.be
www.sendspace.com.ttualaskbe
www.sendspace.com.ttualask.be
www.sendspace.com.ttualjsabe
www.sendspace.com.ttualjsa.be
www.sendspace.com.ttualksabe
www.sendspace.com.ttualksa.be
www.sendspace.com.ttujlasabe
www.sendspace.com.ttujlasa.be
www.sendspace.com.ttuklasabe
www.sendspace.com.ttuklasa.be
www.sendspace.com.ujifatilacom
www.sendspace.com.ujifatila.com
www.sendspace.com.vdslprr.co.uk
www.sendspace.com.vdslprr.me.uk
www.sendspace.com.vdslprr.org.uk
www.sendspace.com.vufteejkibe
www.sendspace.com.vufteejki.be
www.sendspace.com.wjifatilacom
www.sendspace.com.wjifatila.com

Monday, December 21, 2009

Some updates . . . Visa/Zeus and Google Jobs

On December 12th we covered a new "Visa.com" version of the Zeus distribution spam.
(See story: Ongoing Visa Scam Drops Zeus Zbot.

There are at least forty domains seen in today's spam. Please see the story above for more on the URL pattern, (the machine name may begin with "alerts", "reports", "statements", "transactions", or a "sessionid" with random characters after the "sessionid" version, but here is one sample URL for each domain:

alerts.visa.com.111ttillil.co.uk
alerts.visa.com.11fttillil.co.uk
alerts.visa.com.11tttillil.co.uk
alerts.visa.com.1jfttillil.co.uk
alerts.visa.com.yjfttillil.co.uk
reports.visa.com.dirpote1.be
alerts.visa.com.dirpote2.be
alerts.visa.com.dirpote3.be
alerts.visa.com.dirpote4.be
alerts.visa.com.dirpote5.be
alerts.visa.com.dirpote6.be
alerts.visa.com.dirpote8.be
alerts.visa.com.dttflji.be
alerts.visa.com.itdflji.be
alerts.visa.com.ittdlji.be
alerts.visa.com.ittfdji.be
alerts.visa.com.ittfldi.be
alerts.visa.com.ittfljd.be
alerts.visa.com.ittflji.be
alerts.visa.com.ittfljx.be
alerts.visa.com.ittflxi.be
alerts.visa.com.ittfxji.be
alerts.visa.com.itxflji.be
alerts.visa.com.ityxlji.be
alerts.visa.com.ixtflji.be
alerts.visa.com.xttflji.be
alerts.visa.com.ydtflji.be
alerts.visa.com.11t1jtiil.com
alerts.visa.com.11t1kt1il.com
alerts.visa.com.11t1kt1pl.com
alerts.visa.com.11t1ktiil.com
alerts.visa.com.11tfjtiil.com
alerts.visa.com.i1tfjtiil.com
alerts.visa.com.ictfjtiil.com
alerts.visa.com.ivtfjtiil.com
alerts.visa.com.11t1jtiil.net
alerts.visa.com.11t1ktiil.net
alerts.visa.com.11tfjtiil.net
alerts.visa.com.i1tfjtiil.net
alerts.visa.com.ivtfjtiil.net

Its too early to know for sure what malware this is, because currently only 4 of the 41 anti-virus products at VirusTotal detect it as anything at all. Sunbelt calls it Bredolab, the three others all say only that it is "suspicious". I'll try to run it through our malware VM later today and make a more definite judgement.

VirusTotal Report here

cardstatement.exe
File size: 188928 bytes
MD5 : d61c6195eda54b1009208ba823ccdac4

Google Jobs Update


We warned about a Google Jobs scam back on December 1st (see article: Google Jobs Scam -- Read the Fine Print!!). Google actually sued the scammers who were running that scheme on December 9th (see article: Google v. Pacific WebWorks. Unfortunately the spam, and the scamming, continues unabated.

One example would be the spam messages for this "spaces.live.com" blog:

http://cid-3d8eb92dd2d67dba.spaces.live.com/

which leads to the website "biznews7.org", which forwards to the website "news2010letter.com", which recruits people to join the scam by sharing their credit card number on the site "http://www.safetrialoffers.com/searchsecretsystems/le5/".

On that site, the same scam is still being run by this organization:

Search 4 Profit, LLC.
7614 Arvilla Avenue.
Sun Valley, CA 91352

The Fine Print still reads:

Terms and Disclosures. Billing authorization obtained pursuant to the Uniform Electronic Transaction Act and the Electronic Signatures in Global and National Transactions Act. By submitting this form, I am ordering Search Secret Systems for a 7-day bonus period for $1.97 billed to my credit Card; If you enjoy Search Secret Systems, simply do nothing. On the 7th day my credit card will automatically be charged an easy payment of $89.26 once a month for three months. After the three months you will not be billed again. You will then maintain unlimited access to our member site. During your three month program you may cancel anytime by calling 1-877-361-8622 M - F, 8am-8pm MST.




Amazingly, the phone number was answered and a person actually asked how they could help me! When we wrote the first article, the phone rang and rang, but no one ever answered.

Of course, there are still quite a few ways this is illegal, even if they do now answer the phone, including the CAN SPAM violations. The email "from" address is forged and there is no "unsubscribe" link of any sort, nor is there a physical mailing address, despite this being a commercial offer. Here's an example spam message:

Never work in an office again! I've been working for someone else my entire life. A few weeks ago I found out about working for Google online so I decided to check it out. I signed up and read a few articles and tried a few different things and within 6 weeks I was making enough to quit my full time job to work at home! If this sounds like something that interests your, check out URL
http://profiles.yahoo.com/blog/MVO2GFP4W7AEJ42YOXCPAVOTU4
A song, a song, high above the trees




Work for the world's largest employer today lori has Earned $2,069 This December Alone! Check it out here:
http://cid-5ccbbcb19ba7028f.spaces.live.com
O tidings of comfort and joy.


Saturday, December 12, 2009

Ongoing VISA scam drop Zeus Zbot

I guess the UAB Spam Data Mine is having a bad day! Our VISA card is being used in Kuwait!

Dear VISA card holder,

A recent review of your transaction history determined that your card was used at an ATM located in Kuwait, but for security reasons the requested transaction was refused.Please carefully review electronic report for your VISA card


Its also being used at an ATM located in:

Albania, Angola, Argentina, Australia, Bahamas, Cambodia, Central African Republic, China, Cuba, Cyprus, Egypt, Ethiopia, France, Greenland, Guam, Honduras, Italy, Jamaica, Japan, Jordan, Korea, Liberia, Lithuania, Luxembourg, Mauritania, Monaco, Mozambique, Nepal, New Zealand, Niger, Oman, Palau, Panama, Paraguay, Peru, Philippines, Romania, Russian Federation, Rwanda, Seychelles, Somalia, Sri Lanka, Switzerland, Taiwan, Tajikistan, Thailand, Turkmenistan, United Arab Emirates, United Kingdom, Uruguay, Zambia, and probably others.



We know that its real, because for security purposes they X'ed out part of our number, as you can see on this destination website below.



Of course, EVERY VISA card starts with a "4", so that isn't actually a very useful hint.

The subject lines in our emails were:

possible fraudulent transaction
possible fraudulent transaction and/or collusion
possible fraudulent transaction and/or collusion with your VISA card
possible fraudulent transaction has been executed
possible fraudulent transaction has been executed with your VISA card
possible fraudulent transaction is identified
possible fraudulent transaction is identified with your VISA card
possible fraudulent transaction occurred
possible fraudulent transaction occurred with your VISA card
possible fraudulent transaction with your VISA card


The "STATEMENT" link on the website is for an executable named "cardstatement.exe".

The copy we sent to VirusTotal was detected by 16 of 41 AV products according to this VirusTotal Report.

Its a big file. File size: 131072 bytes
MD5 : 1560a00d7e83a085ac76b5d514761baa

Several majors are already detecting it as "zbot".

We've seen the malware spammed on 118 different domain names since the start of the campaign, with more than 17,000 copies of the spam received in the UAB Spam Data Mine. In front of the domain name are several possible prefixes:

alerts.visa.com.(domain)
reports.visa.com.(domain)
statements.visa.com.(domain)
transactions.visa.com.(domain)
sessionid_(random).visa.com.(domain)
sessionid(random).visa.com.(domain)
sessionid-(random).visa.com.(domain)

Here are the 118 domain names we've seen so far:

lotet0.co.uk
lotet1.co.uk
lotet2.co.uk
loteti0.co.uk
luuuuud.co.uk
luuuuuk.co.uk
luuuuul.co.uk
luuuuuo.co.uk
miinu001.co.uk
miinui01.co.uk
miinuo01.co.uk
miinuoo1.co.uk
minutu11.co.uk
minutul1.co.uk
minuty11.co.uk
minutyi1.co.uk
mrreggh.co.uk
mrreggi.co.uk
mrreggj.co.uk
mrreggk.co.uk
nteeeera1.co.uk
ntueeepi1.co.uk
ntueeera1.co.uk
ntueeeri1.co.uk
thhfyb.co.uk
thhfym.co.uk
thhfys.co.uk
thhfyv.co.uk
umr1eep1.co.uk
umr1iep0.co.uk
umr1iep1.co.uk
umrteep1.co.uk
lotet0.me.uk
lotet1.me.uk
lotet2.me.uk
loteti0.me.uk
luuuuud.me.uk
luuuuuk.me.uk
luuuuul.me.uk
luuuuuo.me.uk
miinu001.me.uk
miinui01.me.uk
miinuo01.me.uk
miinuoo1.me.uk
minutu11.me.uk
minutul1.me.uk
minuty11.me.uk
minutyi1.me.uk
mrreggh.me.uk
mrreggi.me.uk
mrreggj.me.uk
mrreggk.me.uk
nteeeera1.me.uk
ntueeepi1.me.uk
ntueeera1.me.uk
ntueeeri1.me.uk
thhfyb.me.uk
thhfym.me.uk
thhfys.me.uk
thhfyv.me.uk
umr1eep1.me.uk
umr1iep0.me.uk
umr1iep1.me.uk
umrteep1.me.uk
lotet0.org.uk
lotet1.org.uk
lotet2.org.uk
loteti0.org.uk
luuuuud.org.uk
luuuuuk.org.uk
luuuuul.org.uk
luuuuuo.org.uk
miinu001.org.uk
miinui01.org.uk
miinuo01.org.uk
miinuoo1.org.uk
minutu11.org.uk
minutul1.org.uk
minuty11.org.uk
minutyi1.org.uk
mrreggh.org.uk
mrreggi.org.uk
mrreggj.org.uk
mrreggk.org.uk
nteeeera1.org.uk
ntueeepi1.org.uk
ntueeera1.org.uk
ntueeeri1.org.uk
thhfyb.org.uk
thhfym.org.uk
thhfys.org.uk
thhfyv.org.uk
umr1eep1.org.uk
umr1iep0.org.uk
umr1iep1.org.uk
umrteep1.org.uk
teh10ll1.be
teh11ll1.be
tehh1ll1.be
tehhtll1.be
tehhtpl1.be
tehhttl1.be
tih11ll1.be
luuuuuk.eu
luuuuul.eu
luuuuuo.eu
mrreggh.eu
mrreggi.eu
mrreggj.eu
nteeeera1.eu
ntueeera1.eu
ntueeeri1.eu
thhfyb.eu
thhfym.eu
thhfyv.eu
umr1eep1.eu
umr1iep1.eu
umrteep1.eu

Only a small handful of these are live. We're seeing mostly the ".be" domains right now, such as:

sessionidP2Q8MFCEG7EU5.visa.com.teh10ll1.be
sessionidLWIV86A.visa.com.teh11ll1.be
reports.visa.com.tehh1ll1.be
reports.visa.com.tehhtll1.be
sessionidOI26B5OXFSCBTV.visa.com.tehhtpl1.be
alerts.visa.com.tehhttl1.be
sessionid_5HR4GA8G3.visa.com.tih11ll1.be

but, those are the URLs seen in the freshest spam. The criminal seems pretty reliable about shifting to new domains when the old ones go offline.

Be very careful about visiting these pages . . . the new Zbot distribution websites also contain driveby infectors. The current one is being dropped via an IFRAME which points here:

"bersdf.com/grsfx/in.php"

That drops a malicious PDF called "pdf.pdf" and a malicious flash file called "swf.swf". It also looks like it calls a file called "sNode.php".

Here is a VirusTotal report for pdf.pdf (12 of 41 detects)

File size: 21784 bytes
MD5 : 254f1479f6546ad62651ae572a16b4e8

and a VirusTotal report for swf.swf (0 of 41 detects)

File size: 10735 bytes
MD5...: 48a36eaf2ca13802f539c9bf065781af

Seems rather strange that they would be pushing a "safe" Flash file. Could it really be a totally undetectable .SWF file exploit? Professional researchers, please help yourselves. Opinions wanted.

The additional droppers are currently fetching two files:

1file.exe (Virus report here - is a Zbot infector with 17 of 41 detects.
File size: 131072 bytes
MD5 : 1560a00d7e83a085ac76b5d514761baa

file.exe (Virus Report here) - is also a Zbot infector with 14 of 41 detects.
File size: 130048 bytes
MD5 : ded54d739fa2e4c66d4a488d3b855861

I guess the nice thing about that directory is that its an open browsable directory, complete with "ReadMe_!!!.txt" file.

Here's the source code for a nice little file called "install.sql". Perhaps we can learn a bit about how the Avalanche spammer works from this file.



======================================================
http://bersdf.com/grsfx/install.sql
======================================================

-- phpMyAdmin SQL Dump
-- version 2.6.1
-- http://www.phpmyadmin.net
--
-- Хост: localhost
-- Время создания: Июл 17 2009 г., 22:57
-- Версия сервера: 5.0.45
-- Версия PHP: 5.2.4
--
-- БД: `123321`
--

-- --------------------------------------------------------

--
-- Структура таблицы `browsers`
--

CREATE TABLE IF NOT EXISTS `browsers` (
`id` tinyint(4) NOT NULL auto_increment,
`name` varchar(16) default NULL,
PRIMARY KEY (`id`)
) ENGINE=MyISAM AUTO_INCREMENT=12 DEFAULT CHARSET=cp1251 AUTO_INCREMENT=12 ;

--
-- Дамп данных таблицы `browsers`
--

INSERT INTO `browsers` VALUES (1, 'Opera');
INSERT INTO `browsers` VALUES (2, 'Konqueror');
INSERT INTO `browsers` VALUES (3, 'Lynx');
INSERT INTO `browsers` VALUES (4, 'Links');
INSERT INTO `browsers` VALUES (5, 'MSIE etc');
INSERT INTO `browsers` VALUES (6, 'Netscape');
INSERT INTO `browsers` VALUES (7, 'Mozilla');
INSERT INTO `browsers` VALUES (8, 'Firefox');
INSERT INTO `browsers` VALUES (9, 'Unknown');
INSERT INTO `browsers` VALUES (10, 'MSIE 7');
INSERT INTO `browsers` VALUES (11, 'MSIE 8');

-- --------------------------------------------------------

--
-- Структура таблицы `countries`
--

CREATE TABLE IF NOT EXISTS `countries` (
`abrev` char(2) NOT NULL default '',
`name` varchar(44) character set cp1251 collate cp1251_general_cs default NULL,
KEY `abrev` (`abrev`)
) ENGINE=MyISAM DEFAULT CHARSET=cp1251;

--
-- Дамп данных таблицы `countries`
--

INSERT INTO `countries` VALUES ('AP', 'Asia/Pacific Region');
INSERT INTO `countries` VALUES ('EU', 'Europe');
INSERT INTO `countries` VALUES ('AD', 'Andorra');
INSERT INTO `countries` VALUES ('AE', 'United Arab Emirates');
INSERT INTO `countries` VALUES ('AF', 'Afghanistan');
INSERT INTO `countries` VALUES ('AG', 'Antigua and Barbuda');

(Gar-Note: Skipping Big Long Country List here)
--
-- Дамп данных таблицы `hit2plug`
--


-- --------------------------------------------------------

--
-- Структура таблицы `loads`
--

CREATE TABLE IF NOT EXISTS `loads` (
`id` int(11) NOT NULL auto_increment,
`sploit_id` int(11) NOT NULL default '0',
`time` varchar(16) NOT NULL default '',
`hash` varchar(32) NOT NULL default '',
PRIMARY KEY (`id`),
KEY `hash` (`hash`)
) ENGINE=MyISAM AUTO_INCREMENT=4231 DEFAULT CHARSET=latin1 AUTO_INCREMENT=4231 ;

--
-- Дамп данных таблицы `loads`
--


-- --------------------------------------------------------

--
-- Структура таблицы `os`
--

CREATE TABLE IF NOT EXISTS `os` (
`id` tinyint(4) NOT NULL auto_increment,
`name` varchar(32) NOT NULL default '',
PRIMARY KEY (`id`)
) ENGINE=MyISAM AUTO_INCREMENT=16 DEFAULT CHARSET=cp1251 AUTO_INCREMENT=16 ;

--
-- Дамп данных таблицы `os`
--

INSERT INTO `os` VALUES (1, 'Linux');
INSERT INTO `os` VALUES (2, 'Windows 95');
INSERT INTO `os` VALUES (3, 'Windows 98');
INSERT INTO `os` VALUES (4, 'Windows XP SP2');
INSERT INTO `os` VALUES (5, 'Windows 2000');
INSERT INTO `os` VALUES (6, 'Windows XP');
INSERT INTO `os` VALUES (7, 'Windows 2003');
INSERT INTO `os` VALUES (8, 'Windows Vista');
INSERT INTO `os` VALUES (9, 'Windows Mobile');
INSERT INTO `os` VALUES (10, 'Macintosh');
INSERT INTO `os` VALUES (11, 'FreeBSD');
INSERT INTO `os` VALUES (12, 'Unknown');

-- --------------------------------------------------------

-- --------------------------------------------------------

--
-- Структура таблицы `sploits`
--

CREATE TABLE IF NOT EXISTS `sploits` (
`id` int(11) NOT NULL auto_increment,
`name` varchar(32) NOT NULL default '',
`loads` int(11) NOT NULL default '0',
PRIMARY KEY (`id`)
) ENGINE=MyISAM AUTO_INCREMENT=667 DEFAULT CHARSET=latin1 AUTO_INCREMENT=667 ;

--
-- Дамп данных таблицы `sploits`
--

INSERT INTO `sploits` VALUES (1, 'RDS.DataSpace', 0);
INSERT INTO `sploits` VALUES (2, 'PDF.Collab', 0);
INSERT INTO `sploits` VALUES (3, 'PDF.Printf', 0);
INSERT INTO `sploits` VALUES (4, 'PDF.Icon', 0);
INSERT INTO `sploits` VALUES (5, 'Other', 0);

-- --------------------------------------------------------
============================
The guys at MaxMind will be excited to know that these criminals are customers of theirs for Geocoding the locations of their infected bots.

The creators of the "FSPACK" malware engine will also be proud to count these guys as customers.

It looks like we've got four exploits that are going to try to run when we visit, if you can trust the loader. RDS.DataSpace is OLD, like MS06-014. A note on SecurityFocus in 2007 says that the MPack Hacker Tool uses it. Apparently the FSPack hacker tool does too!

Wednesday, December 09, 2009

Yet Another Facebook spam - New Zeus / Zbot threat

As Solomon said, "What has been will be again, what has been done will be done again; there is nothing new under the sun." (Ecclesiastes 1:9) Today we have another round of the "Facebook Update Tool" which we actually blogged about on October 28th (See Facebook Phish: Users Beware! and on November 28th (See Beware Weekend Facebook Scam.

The path has changed since the last go-round, with two different URL patterns being used:

/globaldirectory/LoginFacebook.php
and
/global_directory/MyAccount.php

Email subjects are fairly limited to these choices:

Subject: Facebook Account Update
Subject: Facebook account update
Subject: Facebook Update Tool

Here's our actual message count for top Facebook subjects so far this morning:

784 | Facebook Password Reset Confirmation. Customer Message.
779 | Facebook Password Reset Confirmation. Support Message.
757 | Facebook Password Reset Confirmation. Customer Support.
755 | Facebook Password Reset Confirmation. Your Support.
753 | Facebook Password Reset Confirmation. Important Message
602 | Facebook account update
569 | Facebook Update Tool
550 | Facebook Account Update

All of the "Facebook Password Reset Confirmation" are emails with a '.zip' attachment intended to infect with Bredolab. These were covered in Yesterday's blog entry: Ongoing Badness: AmEx, Facebook and .CN. The Zeus / Zbot infector is in the campaign represented by the bottom three subjects on the list. With 189,301 messages received so far this early morning, that puts the Facebook Zeus at .9% of our email volume for this morning, and the Facebook Bredolab at 2% of our email volume for this morning. Let's be generous and say that 3% of all of our spam this morning is using a Facebook scam to try to infect us with malware.

For comparison, here are the top Facebook spam subjects for yesterday:

Z 2309 | Facebook Account Update
B 2292 | Facebook Password Reset Confirmation. Support Message.
Z 2261 | Facebook Update Tool
B 2256 | Facebook Password Reset Confirmation. Your Support.
B 2249 | Facebook Password Reset Confirmation. Customer Message.
B 2244 | Facebook Password Reset Confirmation. Important Message
B 2225 | Facebook Password Reset Confirmation. Customer Support.
Z 2185 | Facebook account update

Z = Zeus / Zbot; B = Bredolab

By the 24 hour clock, yesterday we received 917,872 spam email messages, so 1.2% of yesterday's entire spam volume was Bredolab infectors, and .7% of yesterday's entire spam volume was Facebook Zeus / Zbot, or roughly 2% of all spam for the day, although that's not really fair since Facebook Zeus started so late in the day.

Here's an example of the email body:
Dear Facebook user,

In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security.
Before you are able to use the new login system, you will be required to update your account.

Please click on the link below to update your account online now:

http://www.facebook.com.okolls.org.uk/globaldirectory/LoginFacebook.php?ref=124125189363830136816363239612373&email=weewoo@yourmail.com

If you have any questions, reference our New User Guide.

Thanks,
The Facebook Team




There are fifty new domain names used in this attack, with 36 of the domains resolving as live at this writing (5:15 AM December 9, 2009).

www.facebook.com.gertfra.co.uk
www.facebook.com.gertfra.me.uk
www.facebook.com.gertfra.org.uk
www.facebook.com.gertfrb.co.uk
www.facebook.com.gertfrb.me.uk
www.facebook.com.gertfrb.org.uk
www.facebook.com.gertfrp.co.uk
www.facebook.com.gertfrp.me.uk
www.facebook.com.gertfrp.org.uk
www.facebook.com.gertfrr.co.uk
www.facebook.com.gertfrr.me.uk
www.facebook.com.gertfrr.org.uk
www.facebook.com.gertfrt.co.uk
www.facebook.com.gertfrt.me.uk
www.facebook.com.gertfrt.org.uk
www.facebook.com.ihyeerg.co.uk
www.facebook.com.ihyeerg.me.uk
www.facebook.com.ihyeerg.org.uk
www.facebook.com.ihyeerj.co.uk
www.facebook.com.ihyeerj.me.uk
www.facebook.com.ihyeerj.org.uk
www.facebook.com.ihyeerk.co.uk
www.facebook.com.ihyeerk.me.uk
www.facebook.com.ihyeerk.org.uk
www.facebook.com.ihyeers.co.uk
www.facebook.com.ihyeers.me.uk
www.facebook.com.ihyeers.org.uk
www.facebook.com.ihyeeru.co.uk
www.facebook.com.ihyeeru.me.uk
www.facebook.com.ihyeeru.org.uk
www.facebook.com.jjjioi.co.uk
www.facebook.com.jjjioi.me.uk
www.facebook.com.jjjioi.org.uk
www.facebook.com.jjjiok.co.uk
www.facebook.com.jjjiok.me.uk
www.facebook.com.jjjiok.org.uk
www.facebook.com.jjjiop.co.uk
www.facebook.com.jjjiop.me.uk
www.facebook.com.jjjioy.co.uk
www.facebook.com.jjjioy.me.uk
www.facebook.com.jjjioy.org.uk
www.facebook.com.okolli.co.uk
www.facebook.com.okolli.me.uk
www.facebook.com.okolli.org.uk
www.facebook.com.okolln.co.uk
www.facebook.com.okollo.co.uk
www.facebook.com.okollo.me.uk
www.facebook.com.okollo.org.uk
www.facebook.com.okolls.co.uk
www.facebook.com.okolls.me.uk
www.facebook.com.okolls.org.uk

Despite the wide popularity of this on-going scam, it also calls into question the validity of traditional anti-virus solutions. Any signature-based malware solution is going to be challenged by rapidly changing malware such as these Zbot infectors. This morning's version of the malware is currently detected by only 9 of 41 anti-virus solutions as reported by this VirusTotal report.

updatetool.exe
File size: 131584 bytes
MD5 : 959efa29b4979bcc1d664d7e0726aa74

Security suites which include website blocking fare much better, protecting their customers not by knowing this virus, but by recognizing that the website is offensive. For instance, I am using the McAfee Site Advisor plug-in for Firefox, which recognized this site as offensive. The Google SafeBrowsing list used by Firefox also knows these are offensive sites, and TrendMicro's "Smart Protection Network" performs a similar function for their customers. When selecting an anti-virus solution, make sure that they are also proactively blocking websites known to distribute malware. Even when the criminal shifts to a new virus definition, the fact that these websites are known to be bad will prevent the malware from being downloaded.

Tuesday, December 01, 2009

Minipost: CDC Version of Zeus?

Emails like this:



You have received this e-mail because of the launching of State Vaccination H1N1 Program.

You need to create your personal H1N1 (swine flu) Vaccination Profile on the cdc.gov website. The Vaccination is not obligatory, but every person that has reached the age of 18 has to have his personal Vaccination Profile on the cdc.gov site. This profile has to be created both for the vaccinated people and the not-vaccinated ones. This profile is used for the registering system of vaccinated and not-vaccinated people.
Create your Personal H1N1 Vaccination Profile using the link:

create personal profile



using subjects like these:

Create your personal Vaccination Profile
Creation of personal Vaccination Profile
Creation of your personal Vaccination Profile
Governmental registration program on the H1N1 vaccination
Instructions on creation of your personal Vaccination Profile
State Vaccination H1N1 Program
State Vaccination Program
Your personal Vaccination Profile

Pointing to websites like this:

online.cdc.gov.lykasf.be
online.cdc.gov.lykasm.be
online.cdc.gov.lykasv.be
online.cdc.gov.lykasz.be
online.cdc.gov.nyugewc.be
online.cdc.gov.nyugewd.be
online.cdc.gov.nyugewm.be
online.cdc.gov.nyugewn.be
online.cdc.gov.nyugewq.be
online.cdc.gov.nyugewt.be
online.cdc.gov.nyugeww.be
online.cdc.gov.nyugewy.be
online.cdc.gov.nyugewz.be
online.cdc.gov.yhnbad.co.im
online.cdc.gov.yhnbad.com.im
online.cdc.gov.yhnbad.im
online.cdc.gov.yhnbad.net.im
online.cdc.gov.yhnbad.org.im
online.cdc.gov.yhnbak.co.im
online.cdc.gov.yhnbak.com.im
online.cdc.gov.yhnbak.im
online.cdc.gov.yhnbak.net.im
online.cdc.gov.yhnbak.org.im
online.cdc.gov.yhnbam.co.im
online.cdc.gov.yhnbam.com.im
online.cdc.gov.yhnbam.im
online.cdc.gov.yhnbam.net.im
online.cdc.gov.yhnbam.org.im
online.cdc.gov.yttt4l.co.im
online.cdc.gov.yttt4l.com.im
online.cdc.gov.yttt4l.im
online.cdc.gov.yttt4l.net.im
online.cdc.gov.yttt4l.org.im
online.cdc.gov.yttt4r.co.im
online.cdc.gov.yttt4r.com.im
online.cdc.gov.yttt4r.im
online.cdc.gov.yttt4r.net.im
online.cdc.gov.yttt4r.org.im




Dropping malware like this:

vacc_profile.exe
File size: 130048 bytes
MD5 : 5767b2c6d84d87a47d12da03f4f376ad

VirusTotal report showing 6 of 41 detects

(Tip o' the hat to Andrew F, who beat me to the punch with this one...)

Monday, November 30, 2009

IRS Spam Campaign leads to low detection malware

We're getting tons of strange IRS spam this morning.

Subjects like:

IRS - Please Read!
IRS - Tax Refund Notification!
IRS e-file refund notification!
IRS REFUND Notification - Please Read This!
IRS: Your Tax Refund Notification!
Notification - Tax Refund!
Notification - Your Tax Refund!
Tax Refund!
US Internal Revenue Service!
US Treasury Department - Tax Refund!

Bodies look like this:



-----------------------------

Internal Revenue Service
United States Department of the Treasury
After the last annual calculations of your fiscal activity we have determined that you are eligible to receive 533.41$ tax refund under section 501(c) (10) of the Internal Revenue Code. Please submit the Tax Refund Request Form and allow us 3-9 days to process it.

Yours faithfully,
Sarah Hall Ingram, Commissioner

This notification has been sent by the Internal Revenue Service, a bureau of the Department of the Treasury.

-----------------------
This would be a great place to remind people that if you have turned "javascript" on globally, when you visit ANY website, the code on that website runs, and so does the code on any website that is being loaded into your current webpage with an iframe.

In this case, there's an iframe that draws source from here, being blocked by Google Safe Browsing:

infosayt.com/heabes/index.php

An encrypted javascript is supposed to load from /ssp/index.php on each of the sites below.

The javascript on this page causes the page:

hxxp://refund-services.irs.issue.no.l398726.us/ssp/loadjavad.php?page=1

to be loaded, which drops an executable file called "load.exe". We expect that this page is regularly changed to allow a variety of malware to be dropped. At the moment, what it is dropping is a file that has these characteristics:

My Microsoft Forefront calls that: "Trojan:Win32/Oficla.E"
File size: 19968 bytes
MD5 : 8c111a22d26c84dffe3bc3e03907bc28

A VirusTotal Report gives 5 of 41 detects, meaning that MOST anti-virus software will currently return "no virus found" if you scan the file.

-------------------------
As I was working through my analysis, I found that this has actually already been written up quite nicely by CA in their Security Advisor blog by Mary Grace Gabriel.


Here's a list of webpages we've seen so today (November 30th):

refund-services.irs.issue.no.l320584.us
refund-services.irs.issue.no.l324603.us
refund-services.irs.issue.no.l32839.us
refund-services.irs.issue.no.l354923.us
refund-services.irs.issue.no.l362960.us
refund-services.irs.issue.no.l367360.us
refund-services.irs.issue.no.l372905.us
refund-services.irs.issue.no.l376054.us
refund-services.irs.issue.no.l380027.us
refund-services.irs.issue.no.l382703.us
refund-services.irs.issue.no.l383749.us
refund-services.irs.issue.no.l385372.us
refund-services.irs.issue.no.l387246.us
refund-services.irs.issue.no.l387266.us
refund-services.irs.issue.no.l392053.us
refund-services.irs.issue.no.l392086.us
refund-services.irs.issue.no.l398726.us
refund-services.irs.issue.no.l500328.us
refund-services.irs.issue.no.l507229.us
refund-services.irs.issue.no.l524820.us
refund-services.irs.issue.no.l528074.us
refund-services.irs.issue.no.l539028.us
refund-services.irs.issue.no.l539347.us
refund-services.irs.issue.no.l542043.us
refund-services.irs.issue.no.l562804.us
refund-services.irs.issue.no.l567387.us
refund-services.irs.issue.no.l568730.us
refund-services.irs.issue.no.l572463.us
refund-services.irs.issue.no.l57290.us
refund-services.irs.issue.no.l580382.us
refund-services.irs.issue.no.l583720.us
refund-services.irs.issue.no.l58736.us
refund-services.irs.issue.no.l587468.us
refund-services.irs.issue.no.l587938.us
refund-services.irs.issue.no.l590274.us
refund-services.irs.issue.no.l593380.us
refunds.irs.issue.no.l32839.us
refunds.irs.issue.no.l362960.us
refunds.irs.issue.no.l367360.us
refunds.irs.issue.no.l37204.us
refunds.irs.issue.no.l372905.us
refunds.irs.issue.no.l380027.us
refunds.irs.issue.no.l383749.us
refunds.irs.issue.no.l385372.us
refunds.irs.issue.no.l387246.us
refunds.irs.issue.no.l387266.us
refunds.irs.issue.no.l392053.us
refunds.irs.issue.no.l392059.us
refunds.irs.issue.no.l392086.us
refunds.irs.issue.no.l392503.us
refunds.irs.issue.no.l398726.us
refunds.irs.issue.no.l524820.us
refunds.irs.issue.no.l539347.us
refunds.irs.issue.no.l567387.us
refunds.irs.issue.no.l568730.us
refunds.irs.issue.no.l572035.us
refunds.irs.issue.no.l572463.us
refunds.irs.issue.no.l580382.us
refunds.irs.issue.no.l583720.us
refunds.irs.issue.no.l58736.us
refunds.irs.issue.no.l587468.us
refunds.irs.issue.no.l587938.us
refunds.irs.issue.no.l590274.us
refunds.irs.issue.no.l593380.us
ustreasurydept.irs.issue.no.l320584.us
ustreasurydept.irs.issue.no.l324603.us
ustreasurydept.irs.issue.no.l32839.us
ustreasurydept.irs.issue.no.l354923.us
ustreasurydept.irs.issue.no.l362960.us
ustreasurydept.irs.issue.no.l367360.us
ustreasurydept.irs.issue.no.l37204.us
ustreasurydept.irs.issue.no.l372905.us
ustreasurydept.irs.issue.no.l376054.us
ustreasurydept.irs.issue.no.l380027.us
ustreasurydept.irs.issue.no.l382703.us
ustreasurydept.irs.issue.no.l383749.us
ustreasurydept.irs.issue.no.l385372.us
ustreasurydept.irs.issue.no.l387246.us
ustreasurydept.irs.issue.no.l387266.us
ustreasurydept.irs.issue.no.l392053.us
ustreasurydept.irs.issue.no.l392503.us
ustreasurydept.irs.issue.no.l398726.us
ustreasurydept.irs.issue.no.l500328.us
ustreasurydept.irs.issue.no.l507229.us
ustreasurydept.irs.issue.no.l524820.us
ustreasurydept.irs.issue.no.l528074.us
ustreasurydept.irs.issue.no.l539028.us
ustreasurydept.irs.issue.no.l539347.us
ustreasurydept.irs.issue.no.l542043.us
ustreasurydept.irs.issue.no.l562804.us
ustreasurydept.irs.issue.no.l567387.us
ustreasurydept.irs.issue.no.l568730.us
ustreasurydept.irs.issue.no.l572035.us
ustreasurydept.irs.issue.no.l572463.us
ustreasurydept.irs.issue.no.l57290.us
ustreasurydept.irs.issue.no.l583720.us
ustreasurydept.irs.issue.no.l587468.us
ustreasurydept.irs.issue.no.l587938.us
ustreasurydept.irs.issue.no.l590274.us
ustreasury.irs.issue.no.l320584.us
ustreasury.irs.issue.no.l324603.us
ustreasury.irs.issue.no.l354923.us
ustreasury.irs.issue.no.l362960.us
ustreasury.irs.issue.no.l37204.us
ustreasury.irs.issue.no.l376054.us
ustreasury.irs.issue.no.l380027.us
ustreasury.irs.issue.no.l382703.us
ustreasury.irs.issue.no.l383749.us
ustreasury.irs.issue.no.l385372.us
ustreasury.irs.issue.no.l387246.us
ustreasury.irs.issue.no.l387266.us
ustreasury.irs.issue.no.l392053.us
ustreasury.irs.issue.no.l392059.us
ustreasury.irs.issue.no.l392086.us
ustreasury.irs.issue.no.l392503.us
ustreasury.irs.issue.no.l398726.us
ustreasury.irs.issue.no.l528074.us
ustreasury.irs.issue.no.l539028.us
ustreasury.irs.issue.no.l539347.us
ustreasury.irs.issue.no.l542043.us
ustreasury.irs.issue.no.l562804.us
ustreasury.irs.issue.no.l572035.us
ustreasury.irs.issue.no.l572463.us
ustreasury.irs.issue.no.l57290.us
ustreasury.irs.issue.no.l580382.us
ustreasury.irs.issue.no.l583720.us
ustreasury.irs.issue.no.l58736.us
ustreasury.irs.issue.no.l587468.us
ustreasury.irs.issue.no.l587938.us
ustreasury.irs.issue.no.l590274.us
ustreasury.irs.issue.no.l593380.us

These have been shared with appropriate authorities and will hopefully be shut down soon!

Monday, November 23, 2009

UAB Spam Data Mine finds Social Security Statement Zeus Bot

I'm frequently asked how it is that the UAB Spam Data Mine is consistently among the first in reporting new spam campaigns that contain harmful malware. I thought I would show you the manual version of the process this morning.

We start by finding the "top subjects" for the current time period. Because the UAB Spam Data Mine now processes inbound spam every 15 minutes, we can do searches to identify the top spam campaigns in the previous 15 minutes such as:

select count(subject), subject from spam where message_id like '%09Nov23.0715%' group by subject order by count(subject) desc;

Look for something interesting, such as:

53 | Watch for errors on Social Security statement
53 | Watch for errors on your Social Security statement
45 | Review your annual Social Security statement

In the previous 15 minutes period, nothing with "Social Security" showed up in the top 100 subjects. Now we have three items in the top 25. By the time I finished writing this article, the 0730 and 0745 runs were complete, and we now have more than 600 samples of the spam. However, using the techniques we've developed for "emerging threat detection", we were aware of the campaign immediately when the 0715 run showed something that was not present in the 0700 run.

Then we may dig in with a subject specific search:

select a.subject, b.machine, b.path from spam a, spam_link b where a.message_id = b.message_id and a.subject like '%Social Security statement%';


Bingo! 200 results with domains like:

statements.ssa.gov.fawaazq.be | /acu/IPS_INTR/controller.php
statements.ssa.gov.reedask.be | /acu/IPS_INTR/controller.php

Let's get JUST the list of machines used:

select machine from spam_link where machine like 'statements.ssa.gov%' group by machine;
machine
-------------------------------
statements.ssa.gov.reedasn.be
statements.ssa.gov.fawaazv.be
statements.ssa.gov.fawaazc.be
statements.ssa.gov.reedasg.be
statements.ssa.gov.ujbhgk.be
statements.ssa.gov.ujbhgx.be
statements.ssa.gov.fawaazs.be
statements.ssa.gov.fawaaza.be
statements.ssa.gov.ujbhgv.be
statements.ssa.gov.fawaaze.be
statements.ssa.gov.reedasu.be
statements.ssa.gov.reedasv.be
statements.ssa.gov.reedask.be
statements.ssa.gov.ujbhgz.be
statements.ssa.gov.fawaazz.be
statements.ssa.gov.reedasj.be
statements.ssa.gov.fawaazx.be
statements.ssa.gov.reedasb.be
statements.ssa.gov.fawaazf.be
statements.ssa.gov.ujbhgq.be
statements.ssa.gov.reedaso.be
statements.ssa.gov.ujbhgb.be
statements.ssa.gov.fawaazq.be
statements.ssa.gov.reedasm.be
statements.ssa.gov.ujbhgm.be
statements.ssa.gov.reedast.be
statements.ssa.gov.fawaazr.be
statements.ssa.gov.fawaazd.be
statements.ssa.gov.reedash.be
statements.ssa.gov.ujbhga.be
statements.ssa.gov.fawaazw.be
statements.ssa.gov.reedasy.be
(32 rows)

(Update: There are now 80 known machines for this campaign . . . here's how many emails we've seen for each one as of 8:20 PM, Central time)

729 | statements.ssa.gov.reedasv.be
431 | statements.ssa.gov.reedasm.be
395 | statements.ssa.gov.fawaaze.be
386 | statements.ssa.gov.fawaazx.be
378 | statements.ssa.gov.reedasg.be
360 | statements.ssa.gov.fawaazf.be
337 | statements.ssa.gov.fawaazz.be
317 | statements.ssa.gov.fawaazd.be
304 | statements.ssa.gov.ujbhgm.be
281 | statements.ssa.gov.reedasb.be
271 | statements.ssa.gov.ujbhgz.be
263 | statements.ssa.gov.reedast.be
254 | statements.ssa.gov.reedask.be
253 | statements.ssa.gov.fawaazw.be
242 | statements.ssa.gov.fawaaza.be
224 | statements.ssa.gov.ujbhgv.be
222 | statements.ssa.gov.fawaazv.be
209 | statements.ssa.gov.ujbhgc.be
199 | statements.ssa.gov.reedasj.be
197 | statements.ssa.gov.ujbhga.be
186 | statements.ssa.gov.reedaso.be
183 | statements.ssa.gov.fawaazq.be
181 | statements.ssa.gov.ujbhgj.be
170 | statements.ssa.gov.ujbhgq.be
166 | statements.ssa.gov.ujbhgx.be
161 | statements.ssa.gov.ujilld.be
160 | statements.ssa.gov.fawaazs.be
160 | statements.ssa.gov.ujillv.be
154 | statements.ssa.gov.ujillx.be
153 | statements.ssa.gov.uhyuhd.be
152 | statements.ssa.gov.ujbhgn.be
149 | statements.ssa.gov.fawaazr.be
147 | statements.ssa.gov.uhyuhu.be
144 | statements.ssa.gov.ujilln.be
136 | statements.ssa.gov.uhyuhl.be
132 | statements.ssa.gov.ujillc.be
131 | statements.ssa.gov.uhyuha.be
129 | statements.ssa.gov.ujillb.be
125 | statements.ssa.gov.ujills.be
125 | statements.ssa.gov.uhyuhj.be
125 | statements.ssa.gov.ujille.be
119 | statements.ssa.gov.uhyuhq.be
117 | statements.ssa.gov.ujillr.be
116 | statements.ssa.gov.gredfe.be
110 | statements.ssa.gov.reedasn.be
108 | statements.ssa.gov.ujillf.be
107 | statements.ssa.gov.uhyuhe.be
105 | statements.ssa.gov.gredve.be
101 | statements.ssa.gov.fawaazc.be
97 | statements.ssa.gov.reedasy.be
94 | statements.ssa.gov.grezfe.be
91 | statements.ssa.gov.uhyuho.be
86 | statements.ssa.gov.reedasu.be
83 | statements.ssa.gov.uhyuhg.be
76 | statements.ssa.gov.ujillw.be
75 | statements.ssa.gov.grenfe.be
74 | statements.ssa.gov.grewfe.be
72 | statements.ssa.gov.ujbhgk.be
58 | statements.ssa.gov.uhyuht.be
49 | statements.ssa.gov.ytttdsj.be
46 | statements.ssa.gov.ytttdsv.be
43 | statements.ssa.gov.ujbhgb.be
43 | statements.ssa.gov.ytttdsn.be
39 | statements.ssa.gov.reedash.be
38 | statements.ssa.gov.ytttdsk.be
38 | statements.ssa.gov.ytttdse.be
37 | statements.ssa.gov.ytttdsb.be
36 | statements.ssa.gov.ytttdsh.be
34 | statements.ssa.gov.ytttdsm.be
32 | statements.ssa.gov.ytttdsf.be
29 | statements.ssa.gov.ytttdso.be
29 | statements.ssa.gov.nionuie.be
28 | statements.ssa.gov.ytttdsy.be
27 | statements.ssa.gov.ytttdsu.be
27 | statements.ssa.gov.nionuis.be
26 | statements.ssa.gov.nionuia.be
25 | statements.ssa.gov.nionuig.be
22 | statements.ssa.gov.nionuiq.be
21 | statements.ssa.gov.nionuib.be
21 | statements.ssa.gov.nionuid.be


Looks serious. Let's pull a list of all the unique subjects:

select a.subject from spam a, spam_link b
where a.message_id = b.message_id and
b.machine like 'statements.ssa.gov%'
group by a.subject order by a.subject;

subject
----------------------------------------------------
Review annual Social Security statement
Review your annual Social Security statement
Watch for errors on Social Security statement
Watch for errors on your Social Security statement
(4 rows)

Pulling up some samples in an email tool shows us what the original emails looked like:



The emails claim that
Due to possible calculation errors, your annual Social Security statement may contain errors.

Use the link below to review your annual Social Security statement:


The emails say they came from:

"Social Security Administration auto-notifications@ssa.gov"

Next we visit the website to pull screen shots there as well:



After entering a (fake) Social Security Number, we are taking to another screen that offers us the option of "Generating a Report".



Clicking on "Generate Report" prompts us to download the malware:



Throwing that "statement.exe" to VirusTotal shows us a current detect rate of 5 out of 41 anti-virus products. This is very early in the detection cycle. There is no agreement on what this malware may be:

Authentium: W32/Bifrost.C.gen!Eldorado
AVG: Win32/Cryptor
F-Prot: W32/Bifrost.C.gen!Eldorado
McAfee-GW-Edition: Heuristic.BehavesLike.Win32.Trojan.H
Sunbelt: Trojan-Spy.Win32.Zbot.gen (v)

At this point none of the other AV products have a signature in place for this malware.

The malware file statistics:

File size: 129536 bytes
MD5...: 40469349c5be9033fd57f6e021e7d06e

Because so little is known about this malware, we then queue it as a "high priority item" for the UAB Malware Analysis group to look at. We'll be sure to update the blog with more information about the malware when it is available.

UAB Malware Brian Tanner confirmed for us that this is a Zbot trojan, and that it connects to the IP address 193.104.27.42, which has been used to deliver Zbot configuration files since at least October 26th.