This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

IE7.0.exe from [removed] - SPAM malware

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.html?storyid=2537
Last Updated: 2007-03-29 23:29:59 UTC
"We've received a number of reports of spam appearing to come from "[removed]" containing a link to a file called IE7.0.exe …
File:
Name IE7.0.exe
Size 33280
md5 8e12a8281a6c6ebdbd75c26a93e69437
sha1 de94c34d51e8c04df174e27bc04eed134aca57d7
Date scanned 03/30/2007 00:22:04 (CET)
Norman Sandbox doesn't detect it and it seems to not want to run in certain virtual machines either. Check your logs on proxy servers etc. for IE7.0.exe, it's being hosted in multiple places around the world…"

Fake Internet Explorer 7 Installer Phishing Attacks
- http://www.us-cert.gov/current/#ie7spam
added March 30, 2007

- http://www.f-secure.com/weblog/archives/ar…7.html#00001155
(Screenshot available.)


:angry:
FYI…

- http://isc.sans.org/diary.html?storyid=2768
Last Updated: 2007-05-07 15:01:20 UTC ~ "A new wave of "Internet Explorer 7.0 Beta" spam is currently being reported. All links to an "update.exe" file, which is hosted on various URLs. The e-mail message is adopting spam methods by "hiding" the image link among chunks of text copied from web sites.

Characteristics:
From: admin @ microsoft.com
Subject: Internet Explorer 7.0 Beta

URL:
we have seen these so far (but there are likely many more):
httx://xoozee. cd/update.exe
httx://merzingo. cd/update.exe
httx://endfriends. cd/update.exe
httx://netdesks. cd/update.exe
httx://pleasedostock. hk/update.exe
httx://wordcasts. cd/update.exe
httx://abyssrecycling. co.uk/images/update.exe
httx://accentstaffing. com/images/update.exe
httx://bcweblist. com/images/update.exe
httx://actorsandactresses. co.uk/images/update.exe
httx://mikelike .cd/update.exe

It doesn't look like a feasable idea to block all these sites. However, you probably should filter e-mail from '[removed]' (that particular "From" address has been used in the past)…"

<_<