FYI...
Fake Quickbooks emails lead to malware
-
http://www.gfi.com/b...re-shenanigans/
Oct 3, 2012 - "We have some more rogue emails following the familiar pattern of the last few days – this time around,
a fake Quickbooks themed email which promises “free shipping for Quickbooks customers”:
>
http://www.gfi.com/b...ckbooksspam.jpg
It points to a website that shows the end-user a “connecting to server” message, eventually
redirecting to an IP address that has been / is still
associated with Blackhole Exploit Kit and Java exploits.
>
http://www.gfi.com/b...kbooksspam2.jpg
... it’s a bad time to be randomly opening dubious emails..."
Fake QB/IRS order forms emails
-
http://security.intu.../alert.php?a=62
10/03/2012
>
http://security.intu...ges/phish63.jpg
___
Something evil on 66.45.251.224/29 and 199.71.233.226
-
http://blog.dynamoo....122429-and.html
3 Oct 2012 - "The IP address
199.71.233.226 (Netrouting, US) and the range
66.45.251.224/29 (Interserver, US) are currently being used to distribute
malware through advertising. Of these the 66.45.251.224/29 has been suballocated to an anonymous person, which I didn't even know was permitted... The domains listed below are on those IP addresses, all appear to be disributing malware (see example*) and they seem to have fake or anonymous WHOIS details. Blocking traffic to
66.45.251.224/29 (66.45.251.224 - 66.45.251.231) and
199.71.233.226 should be effective in countering this threat..."
Update:
95.211.193.36 (Leaseweb, Netherlands) and
77.95.230.77 (Snel Internet Services, Netherlands) may also be distributing malware in connection with this (report here**).
(More info at the blog.dynamoo URL above.)
*
http://www.google.co...=juniorppv.info
"Site is listed as suspicious... Malicious software includes 8 trojan(s)..."
**
http://wepawet.isecl...d...972&type=js
___
Friendster SPAM / sonatanamore .ru
-
http://blog.dynamoo....tanamoreru.html
2 Oct 2012 - "Friendster.. remember that? Before Facebook.. before Myspace.. there was Friendster. This spam email is -not- from Friendster though and
leads to malware on sonatanamore .ru:
Date: Tue, 2 Oct 2012 05:39:54 -0500
From: Friendster Games [friendstergames@friendster.com]
Thank you for joining Friendster! Your system generated password is 0JR8YXB1YR. You may change your password in your Account Settings Page.
Friendster is the social gaming destination of choice. Connect and play with your friends & share your progress with your network.
Copyright ? 2002 - 2012 Friendster, Inc. All rights reserved. Visit our site. - Terms of Service
To manage your notification preferences, go here
To stop receiving emails from us, you can unsubscribe here
The malicious payload is at [donotclick]sonatanamore .ru:8080/forum/links/column.php hosted on:
70.38.31.71 (iWeb, Canada)
202.3.245.13 (MANA, Tahiti)
203.80.16.81 (Myren, Malaysia)
Plain list of IPs and domains on those IPs for copy-and-pasting.
70.38.31.71, 202.3.245.13, 203.80.16.81 ..."
(More listed at the blog.dynamoo URL above.)
Edited by AplusWebMaster, 04 October 2012 - 07:07 AM.