This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Rash of new SPAM pushes malware ...screensavers

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://sunbeltblog.blogspot.com/2008/03/ra…es-malware.html
March 09, 2008 - "Over the past 24 hours, we’ve have seen a rash of malicious spam pushing screensavers that are, in reality, backdoor trojans (VirustTotal report here*, with very poor detection by most engines). It is unknown how widespread these spams are… both of the sites that we have observed hosting these screensavers appear compromised. One is already down, and we are in the process of attempting to get the other one taken down…"
* http://www.virustotal.com/analisis/67abb89…0c0c7d80a96a22f

(Screenshots available at the sunbeltblog URL above.)

:ph34r:
FYI…

- http://sunbeltblog.blogspot.com/2008/03/da…re-gang-re.html
March 10, 2008 - "…brief follow up… wave of “3D Screensaver” spam that we have been seeing. Further investigation into this malware points back to the infamous malware loading group “Loads.cc”. Interestingly, the Loads.cc web site was taken off-line in late January after suffering a DDoS attack from a rival malware gang which utilized a Barracuda bot-net to perform its task. While the “Loads.cc” domain (which is used by affiliates to sign up to have their malware installed by the botnet and monitor statistics) is no longer working (it resolves to 127.0.0.1), we were able to easily discover a new domain in use thus proving that Loads.cc is back in operation… This malware gang is responsible for the distribution and installation of massive amounts of malware: Spambots, keyloggers, DDoS bots, adware and rootkits. The the whole kitten kaboodle. So, it cannot be stressed enough that this is very dangerous malware and to stay away from these Trojaned screensavers. After installing the “screen saver”, the malware announces it’s presense by using an HTTP GET request for a PHP script. This PHP script (manda.php) may or may not return a URL of additional malware to for the bot to retrieve and install – malware that other authors have paid loads.cc to install.
GET http: //[removed].info/admin/manda.php?id=[user_id]&v=scr
The malware is then copied to the following location where it silently sits awaiting commands from the C&C server:
%HOMEDRIVE%\Documents and Settings\LocalService\Local Settings\Application Data\cftmon.exe …"

(Screenshots available at the URL above.)

:rant2: :ph34r:
FYI…

Rent-a-bot gang…
- http://www.channelregister.co.uk/2008/03/1…cc_rises_again/
13 Mar 2008 - "A notorious malware gang that rented out botnets by the hour has resurfaced after being knocked off line two months ago by a rival band of criminals. The Loads.cc group has been spotted by researchers at Sunbelt Software pushing toxic 3D screensavers on unsuspecting end users. The software installs malware that points to a server controlled by Loads.cc and then lies in wait for instructions from a command and control server… The gang came to prominence by renting out a botnet that fellow online criminals could use to install and maintain their malware. In October, it boasted more than 35,000 infected machines, according to this post* by researcher Dancho Danchev. Prices ranged from $110 to $220 per thousand infections depending on where they were located…"
* http://ddanchev.blogspot.com/2007/10/botne…nd-service.html

:ph34r: :ph34r: