Fake ‘PayPal Account Modified’ emails lead to BlackHole Exploit Kit
- http://blog.webroot....le-exploit-kit/
Nov 14, 2012 - "A cybercriminal/group... continues to systematically rotate the impersonated brands and the actual malicious payload dropped by the market leading Black Hole Exploit Kit. The prospective target of their latest campaign? PayPal users...
Sample screenshot of the spamvertised email:
> https://webrootblog....its_malware.png
... Malicious domain name reconnaissance: puzzledbased .net – 183.180.134.217, AS2519 – Email: rodger_covach3060 @ spacewar .com
Name Server: NS1.TOPPAUDIO .COM
Name Server: NS2.TOPPAUDIO .COM
Although we couldn’t reproduce puzzledbased .net’s malicious activity, we know for certain that on 2012/11/01 at 15:19, hxxp ://netgear-india .net/detects/discover-important_message.php was responding to the same IP. We’ve already seen and profiled the malicious activity of the campaign using this URL in the “‘Your Discover Card Services Blockaded’ themed emails serve client-side exploits and malware analysis...
The following malicious domains are also part of the campaign’s infrastructure and respond to the same IP (183.180.134.217) as the client-side exploits serving domains:
rovo .pl
itracrions .pl
superdmntre .com
chicwhite .com
radiovaweonearch .com
strili .com
superdmntwo .com
unitmusiceditior .com
newtimedescriptor .com
steamedboasting .info
solla.at votela .net
stempare .net
tradenext .net
bootingbluray .net
The following malicious domain (stempare .net) was also seen in the recently profiled “‘American Express Alert: Your Transaction is Aborted’ themed emails serve client-side exploits and malware” campaign, indicating yet another connection between these campaigns..."
___
promotesmetasearch .net promotes malware
From the WeAreSpammers blog: http://wearespammers.../launch-of.html
- http://blog.dynamoo....es-malware.html
14 Nov 2012 - "This looks like a fake get-rich-quick scam email which is actually intended to distribute malware. Originating IP is 5.39.101.233 (OVH, Germany). Spamvertised domains are 8mailer .com on 5.39.101.225 (OVH, Germany) and promotesmetasearch .net on 46.249.38.27 (Serverius Holding, Netherlands). This last one is kind of interesting, because 1) it's all in French and 2) it contains a virus. The malware attempts to download an exploit kit from [donotclick]vodkkaredbuuull .chickenkiller .com/trm/requesting/requesting-pass_been_loaded.php which is kind of unfriendly, hosted on the same IP address.
The WHOIS details show a completely different name and address from the one quoted on the email:
Florence Buker
florence_buker05 @rockfan .com
7043 W Avenue A4
93536 Lancaster
United States
Tel: +1.4219588211
Clearly the owner of promotemetasearch .net is up to no good, and I would suggest the Anthony Tomei connection might well be completely bogus.
From: Anthony Tomei admin @8 mailer .com
Reply-To: info @ promotesmetasearch .net
To: donotemail @ wearespammers .com
Date: 14 November 2012 18:22
Subject: launch of
Dear Future Millionaire,
Making $100,000 per month is not hard. In fact, there are 2 ways you accomplish this easy task of making money in a short period of time.
The first way is to...
Anthony Tomei is an Expert Internet Network Marketer. Anthony is known as the Master Marketer and practically gives away all of his secrets, methods and marketing techniques... You should probably regard the domain chickenkiller .com as compromised and block it. Additionally, all the following IPs and domains are related and a probably malicious.
46.249.38.21
46.249.78.23
46.249.38.27
deficiencieshiss .net
personaloverly .net
spaceyourfilesbig.chickenkiller .com
vodkkaredbuuull.chickenkiller .com
firefoxslacker .pro
personaloverly .net
wowteammy113 .org
logicalforced .org
flashkeyed .org
incidentindie .org
sufficeextensible .org
laughspadstyle .org
check-update .org
softtwareupdate .org
internallycontentchecking .org
cordlesssandboxing .org
westsearch .org
perclickbank .org
trayscoffeecup .org
agreedovetails .org
commencemessengers .org
dfgs453t .org
disappointmentcontent .org
whiskeyhdx .org
uhgng43fgjl82309dfg99df1 .com
rethnds732 .com
odiushb327 .com
a6q7 .com
makosl .com
noticablyccleaner .com
leisurelyadventures .com
invitedns .com
srv50 .in
flacleaderboard.in
frwdlink .in
tgy56fd3fj.firm .in
warrantynetwork .co .in
kclicksnet .in
reelshandsoff .info
scatteredavtestorg .info
ap34 .pro
trafficgid .pro
stop2crimepeople .pro
huge4floorhouse .pro
exportlite .pro
weeembedding .pro
layer-grosshandel .pro
firefoxslacker .pro
s1topcrimefor .pro
opera-soft .pro
brauser-soft .pro
mp3soft .pro
pornokuca .net
licencesoftwareupda .net
settlementstored .net
licencesoftwareuppd .net
compartmentalizationwere .net
seniorhog .net
coinbatches .net
isnbreathy .net
mrautorun .ru
askedvisor .ru
srv50b .biz
vimeosseeing .biz
threatwalkthrough .biz
promotemetasearch .net ..."
Edited by AplusWebMaster, 14 November 2012 - 06:15 PM.