Casino PUA software SPAM ...
- http://blog.webroot....o-w32casonline/
June 12, 2013 - "Fraudsters are currently spamvertising tens of thousands of emails enticing users into installing rogue, potentially unwanted (PUAs) casino software. Most commonly known as W32/Casonline, this scam earns revenue through the rogue online gambling software’s affiliate network... (multiple screenshots at the URL above)... Spamvertised URLs:
hxxp ://luckynuggetcasino .com – 67.211.111.163
hxxp ://888casino .com – 213.52.252.59
hxxp ://spinpalace.com – 109.202.114.65
hxxp ://alljackpotscasino.com – 64.34.230.122
hxxp ://allslotscasino.com – 64.34.230.149
... (multiple) MD5s... have also phoned back to the same IP (213.52.252.59)... (Low detection rates per Virustotal - links at the webroot URL above)...
We advise users to avoid interacting with any kind of content distributed through spam messages, especially clicking on any of the links found in such emails...."
___
Fake BBB SPAM / trleaart .net
- http://blog.dynamoo....rleaartnet.html
12 June 2013 - "This fake BBB spam with a "PLAINT REPORT" (sic) leads to malware on trleaart .net:
From: Better Business Bureau [mailto:rivuletsjb72 @bbbemail .org]
Sent: 11 June 2013 18:04
Subject: Better Business Beareau Complaint ¹ S3452568
Importance: High
Sorry, your e-mail does not support HTML format. Your messages can be viewed in your browser
Better Business Bureau ©
Start With Trust
Tue , 11 Jun 2013
Issue N. S3452568
The Better Business Bureau has been booked the above said claim letter from one of your customers in respect of their dealings with you. The detailed description of the consumer's trouble are available visiting a link below. Please pay attention to this matter and inform us about your mind as soon as possible.
We amiably ask you to open the PLAINT REPORT to answer on this claim.
We awaits to your prompt response.
Faithfully yours
Daniel Cox
Dispute Advisor...
Better Business Bureau...
Screenshot: https://lh3.ggpht.co...c/s400/bbb2.png
The link goes through a legitimate -hacked- site and end up with a malware landing page on [donotclick]trleaart .net/news/members_guarantee.php (report here*) hosted on the following IPs:
160.75.169.49 (Istanbul Technical University, Turkey)
186.215.126.52 (Global Village Telecom, Brazil)
190.93.23.10 (Greendot, Trinidad and Tobago)
193.254.231.51 (Universitatea Transilvania Brasov, Romania)
This network of evil sites is rather large... in the meantime here is a partial blocklist:
160.75.169.49
186.215.126.52
190.93.23.10
193.254.231.51 ..."
* http://urlquery.net/....php?id=3067317
___
Malware sites to block 12/6/13
- http://blog.dynamoo....lock-12613.html
12 June 2013 - "This is a refresh of this list of domains and IPs controlled by what I call the "Amerika" gang, and it follows on from this BBB spam run earlier. Note that IPs included in this list show recent malicious activity, but it could be that they have now been fixed. I also noticed that a couple of the domains may have been sinkholed, but it will do you no harm to block them anyway..."
(LONG list at the dynamoo URL above - includes "Plain IPlist for copy-and-pasting".)
___
Fake "Activation Needed" emails...
- http://security.intu.../alert.php?a=82
6/11/13 - "People are receiving -fake- emails with the title "Important Activation Needed/"
Below is a copy of part of the email people are receiving:
Screenshot: http://security.intu...s/importact.jpg
... This is the end of the -fake- email.
Steps to Take Now
Do not open the attachment in the email...
Delete the email..."
___
GAMARUE malware uses Sourceforge to host files
- http://blog.trendmic...-to-host-files/
June 11, 2013 - "In our monitoring of the GAMARUE malware family, we found a variant that used the online code repository SourceForge to host malicious files... SourceForge is a leading code repository for many open-source projects, which gives developers a free site that allows them to host and manage their projects online. It is currently home to more than 324,000 projects and serves more than 4 million downloads a day... GAMARUE malware poses a serious risk to users; attackers are able to gain complete control of a system and use it to launch attacks on other systems, as well as stealing information. Among the most common ways it reaches user systems are: infected removable drives, or the user has visited sites compromised with the Blackhole Exploit Kit. This attack is made up of four files. The first is a shortcut, which appears to be a shortcut to an external drive. (This is detected as LNK_GAMARUE.RMA.) Instead of a drive, however, it points to a .COM file (detected as TROJ_GAMARUE.LMG)...
> http://blog.trendmic...aruediagram.png
GAMARUE Infection Chain
Once the executable file is decrypted, it downloads updates to itself, as well as malicious files from a SourceForge project. In effect, it uses SourceForge to unwittingly host malicious files... The malicious files in the above example were hosted under the tradingfiles project. The same user created two more projects that were also used to host malicious GAMARUE files: ldjfdkladf and stanteam. New files were uploaded in these projects from June 1 onwards..."
- https://net-security...ews.php?id=2517
June 12, 2013 - "... the infection with a variant of the information-stealing Gamarue starts with a shortcut file to an external file, and ends with malicious files being downloaded from one of three (obviously bogus) Sourceforge projects: "tradingfiles," "stanteam," and "ldjfdkladf". The first two have already been deleted, and the third one emptied of all files. The account of the user who created them has been deleted (whether or not by Sourceforge or the user it's impossible to tell), but according to the researchers new files were uploaded into these projects from June 1 onwards..."
___
Fake Xerox WorkCentre Spam
- http://threattrack.t...workcentre-spam
June 12, 2013 - "Subjects Seen:
Scan from a Xerox WorkCentre
Typical e-mail details:
Please download the document. It was scanned and sent to you using a Xerox multifunction device.
File Type: pdf
Download: Scanned from a Xerox multi~3.pdf
multifunction device Location: machine location not set
Device Name: Xerox6592
For more information on Xerox products and solutions, please visit xerox .com
Malicious URLs
forum.xcpus .com:8080/webstats/counter.php
buildmybarwebsite .com/webstats/counter.php
continentalfuel .com/webstats/counter.php
apparellogisticsgroup .net/Aq70QrZ.exe
ftp(DOT)celebritynetworks .com/dNYC.exe
portal.wroctv .com/inZGwEH.exe
videotre .tv .it/UmQ.exe
Malicious File Name and MD5:
Scan_<random>.zip (0375c95289fc0e2dd94b63c105c24373)
Scan_<random> (8fcba93b00dba3d182b1228b529d3c9e)
Screenshot: https://gs1.wac.edge...uzKT1qz4rgp.png
- http://blog.dynamoo....entre-spam.html
12 June 2013 - "This fake Xerox WorkCentre spam comes with a malicious attachment and appears to come from the victim's own domain:
Date: Wed, 12 Jun 2013 10:36:16 -0500 [11:36:16 EDT]
From: Xerox WorkCentre [Xerox.Device9@victimdomain.com]
Subject: Scan from a Xerox WorkCentre
Please download the document. It was scanned and sent to you using a Xerox multifunction device.
File Type: pdf
Download: Scanned from a Xerox multi~3.pdf
multifunction device Location: machine location not set
Device Name: Xerox2023
For more information on Xerox products and solutions, please visit http ://www.xerox .com
Attached is a ZIP file, in this case called Scan_06122013_29911.zip which in turn contains an executable Scan_06122013_29911.exe. Note that the date is encoded into the filename so future versions will be different. VirusTotal results are 23/47* which is typically patchy. Comodo CAMAS reports** that the malware attempts to phone home to forum.xcpus .com on 71.19.227.135 and has the following checksums:
MD5 8fcba93b00dba3d182b1228b529d3c9e
SHA1 54f02f3f1d6954f98e14a9cee62787387e5b072c
SHA256 544c08f288b1102d6304e9bf3fb352a8fdfb59df93dc4ecc0f753dd30e39da0c
... the ThreatTrack report [pdf]*** is more detailed and also identifies the following domains and IPs which are probably worth blocking or looking out for:
71.19.227.135
205.178.152.164
198.173.244.62
204.8.121.24
195.110.124.133
173.246.106.150 ..."
* https://www.virustot...sis/1371077066/
File name: Scan_06122013_29911.exe
Detection ratio: 23/47Analysis date: 2013-06-12
** http://camas.comodo....f753dd30e39da0c
*** http://www.dynamoo.c...28b529d3c9e.pdf
___
Fake Fedex SPAM / oxfordxtg .net
- http://blog.dynamoo....fordxtgnet.html
12 June 2013 - "This fake FedEx spam leads to malware on oxfordxtg .net:
Date: Thu, 13 Jun 2013 01:18:09 +0800 [13:18:09 EDT]
From: FedEx [wringsn052 @emc.fedex .com]
Subject: Your Fedex invoice is ready to be paid now.
FedEx® FedEx Billing Online - Ready for Payment
fedex.com
Hello [redacted]
You have a new outstanding invoice(s) from FedEx that is ready for payment.
The following ivoice(s) are to be paid now :
Invoice Number
5135-13792
To pay or review these invoices, please sign in to your FedEx Billing Online account by clicking on this link: http ://www.fedex .com/us/account/fbo
Note: Please do not use this email to submit payment. This email may not be used as a remittance notice. To pay your invoices, please visit FedEx Billing Online, http ://www.fedex .com/us/account/fbo
Thank you,
Revenue Services
FedEx...
Screenshot: https://lh3.ggpht.co...s1600/fedex.png
The link in the email goes through a legitimate hacked site and ends up on a malware payload page at [donotclick]oxfordxtg .net/news/absence_modern-doe_byte.php (report here*) hosted on:
124.42.68.12 (Langfang University, China)
190.93.23.10 (Greendot, Trinidad and Tobago)
The following partial blocklist covers these two IPs, but I recommend you also apply this larger blocklist of related sites** as well.
124.42.68.12
190.93.23.10 ..."
* http://urlquery.net/....php?id=3082461
** http://blog.dynamoo....lock-12613.html
___
Fake "'Anonymous' sent you a payment" emails...
- http://security.intu.../alert.php?a=83
6/12/13 - " People are receiving -fake- emails with the title "X sent you a payment (where X is a person's name)." Below is a copy of the email people are receiving:
Screenshot: http://security.intu...mentnetwork.jpg
This is the end of the fake email.
Steps to Take Now
Do -not- open the attachment in the email...
Delete the email..."
Edited by AplusWebMaster, 12 June 2013 - 05:53 PM.