AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.html?storyid=2208
Last Updated: 2007-02-09 22:40:01 UTC ~ "There is spam making the rounds that is targeting customers of ISPs. The template of the e-mail is attached below and the attackers are using some sort of method to specifically mention the proper ISP name being used by the victim. In short, it's trying to get you to upload scripts to your webserver and run them. So far, the reverse engineering is ongoing, but it is obfuscated PHP or ASP code that will run once you go that page. So far, I've seen that it sends an email to firstbts @ gmail.com and tries to get a 0-byte file from [removed]. I'm creating a VMware image to continue to reverse engineer, but these e-mails are scams of the typical social engineering variety. It seems most Anti-Virus picks this up already.
== START EMAIL ==
Dear <> valued members
Regarding our new security regulations, as a part of our yearly maintenance we have provided a security guard script in the attachment. So, to secure your websites, please use the attached file and (for UNIX/Linux Based servers) upload the file "guard.php" in: "./public_html" or (for Windows Based servers which use ASP) upload the file "guard.asp" in: "./wwwroot" in your site. If you do not know how to use it, you can use the following instruction…
Thank you for using our services and products. We look forward to providing you with a unique and high quality service.
Best Regards
<>
== END EMAIL == "
<_<
- http://isc.sans.org/diary.html?storyid=2208
Last Updated: 2007-02-09 22:40:01 UTC ~ "There is spam making the rounds that is targeting customers of ISPs. The template of the e-mail is attached below and the attackers are using some sort of method to specifically mention the proper ISP name being used by the victim. In short, it's trying to get you to upload scripts to your webserver and run them. So far, the reverse engineering is ongoing, but it is obfuscated PHP or ASP code that will run once you go that page. So far, I've seen that it sends an email to firstbts @ gmail.com and tries to get a 0-byte file from [removed]. I'm creating a VMware image to continue to reverse engineer, but these e-mails are scams of the typical social engineering variety. It seems most Anti-Virus picks this up already.
== START EMAIL ==
Dear <> valued members
Regarding our new security regulations, as a part of our yearly maintenance we have provided a security guard script in the attachment. So, to secure your websites, please use the attached file and (for UNIX/Linux Based servers) upload the file "guard.php" in: "./public_html" or (for Windows Based servers which use ASP) upload the file "guard.asp" in: "./wwwroot" in your site. If you do not know how to use it, you can use the following instruction…
Thank you for using our services and products. We look forward to providing you with a unique and high quality service.
Best Regards
<>
== END EMAIL == "
<_<