FYI…(the story in the
previous post is legit, whereas the the scams [below] continue):
-
http://isc.sans.org/diary.php?date=2005-09-01
Updated September 1st 2005 23:47 UTC
"
Katrina Malware
It didn't take long. This morning, we received an email which is promising news about the Hurricane. However, the site it links to appears to provide malware in addition to a brief news article. The text of the email (the original is in HTML):
Subject: Re: Katrina killed as many as 80 people…
Katrina Donation Scams
A couple of the domains we discovered yesterday removed the paypal button. Again, please let us know if you find any suspect domains. There are now about 230 .com domains that contain the strings 'katrina' and 'hurrican'.
We could use your help checking out domains we found that 'sound suspect'. These have been filtered from the .com zone file using keywords like 'katrina'. Lots of innocent domains, so don't use it as a block list just yet. We are trying to anotate this list as needed. NOTE: If you send us an anotation to add, we will add an e-mail address of yours to 'sign' the comment. The email address will be obfuscated. Unsigned comments come from our ISC handler team.
>>>
http://isc.sans.org/katrina.com.txt …"
…and:
-
http://www.websensesecuritylabs.com/alerts…php?AlertID=272
September 01, 2005
Malicious Website / Malicious Code:
Katrina News Email Scam
"Websense Security Labs™ has received multiple reports of a new email scam, which attempts to lure users into visiting a malicious website.
The message gives a brief news update on Hurricane Katrina and provides a link to the full news story. This website contains encoded JavaScript, which attempts to exploit two HTML Help vulnerabilities. Microsoft has addressed these vulnerabilities with
http://www.microsoft.com/technet/security/…n/MS05-001.mspx.
In the event that either of the exploits are successful, a Trojan downloader is placed on the workstation. The Trojan begins downloading a second malicious file, which is also a Trojan. The second Trojan has backdoor functionality that gives the attacker complete control of the workstation. The technique, exploit, and Trojan used in this attack are nearly identical to the Iraqi News Email Scam that began circulating in early August.
The first website involved in the attack is hosted in Mexico; the second is in the United States. Both were online at the time of this alert.
Websense Security Labs™ has also observed several hundred new websites, which are requesting donations for Hurricane Katrina relief. Many of these sites are believed to be fraudulent. We strongly recommend you verify the authenticity of any charity before making a donation.
Sample email text:
Just before daybreak Tuesday, Katrina, now a tropical storm, was 35 miles northeast of Tupelo, Miss., moving north-northeast with winds of 50 mph.
Forecasters at the National Hurricane Center said the amount of rainfall has been adjusted downward Monday.
Mississippi Gov. Haley Barbour said Tuesday that Hurricane Katrina killed as many as 80 people in his state and burst levees in Louisiana flooded New Orleans.
Read More.. …"
