Page 22 of 22 FirstFirst ... 121819202122
Results 211 to 213 of 213

Thread: SPAM frauds, fakes, and other MALWARE deliveries...

  1. #211
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    4,289

    Thumbs down Something evil on 85.214.64.153

    FYI...

    Something evil on 85.214.64.153
    - http://blog.dynamoo.com/2013/06/some...521464153.html
    17 June 2013 - "85.214.64.153 is an IP belonging to Strato AG in Germany, it appears to host some legitimate sites but the server seems to be serving up the Neutrino exploit kit (example*) which is being injected into -hacked- websites (specifically, malicious code is being appended to legitimate .js files on those sites)... Dynamic DNS domains are being abused in this attack... These sites are mostly flagged as malicious by Google, you can see some indicators of badness here** and here***..."
    (More detail at the dynamoo URL above.)
    * http://urlquery.net/report.php?id=3112582

    ** https://www.virustotal.com/en/ip-add...3/information/

    *** http://urlquery.net/search.php?q=85....3-06-17&max=50

    Diagnostic page for AS6724 (STRATO)
    - https://www.google.com/safebrowsing/...c?site=AS:6724
    "... over the past 90 days, 7173 site(s)... served content that resulted in malicious software being downloaded and installed without user consent. The last time Google tested a site on this network was on 2013-06-17, and the last time suspicious content was found was on 2013-06-17... we found 909 site(s) on this network... that appeared to function as intermediaries for the infection of 7496 other site(s)... We found 1434 site(s)... that infected 14549 other site(s)..."
    ___

    Account takeover attempts nearly double ...
    - https://net-security.org/secworld.php?id=15077
    17 June 2013 - "ThreatMetrix* announced its Cybercrime Index, a series of Web fraud data aggregated from 1,500 customers, 9,000 websites and more than 1.7 billion cyber events. In a recent six-month snapshot ending March 31, ThreatMetrix determined that attacks on new account registrations using spoofed and synthetic identities saw the highest rate of attacks followed by account logins and payment fraud...
    > http://www.threatmetrix.com/wp-conte...me-Index1.jpeg
    Based on data taken from October 2012 through March 2013, they saw account takeover attempts nearly double (168%). These types of attacks have traditionally focused on banking and brokerage sites, but have recently escalated across e-commerce sites that store credit card details and SaaS companies that hold valuable customer data that do not yet have the heightened level of protection as banking sites..."
    * http://www.threatmetrix.com/threatme...over-6-months/
    ___

    Rogue ads target EU users - Win32/Toolbar.SearchSuite through the KingTranslate PUA
    - http://blog.webroot.com/2013/06/17/r...translate-pua/
    June 17, 2013 - "... Tens of thousands of socially engineered European ads, who continue getting exposed to the rogue ads served through Yieldmanager’s network, are promoting more Potentially Unwanted Applications (PUAs) courtesy of Bandoo Media Inc and their subsidiary Koyote-Lab Inc...
    Sample screenshots of the rogue KingTranslate PUA landing/download page:
    1) https://webrootblog.files.wordpress....ng?w=659&h=496
    2) https://webrootblog.files.wordpress....ng?w=592&h=550
    ... Rogue URL: kingtranslate .com – 109.201.151.95
    Detection rate for the PUA: KingTranslateSetup-r133-n-bc.exe – MD5: 51d98879782d176ababcd8d47050f89f * ... Win32/Toolbar.SearchSuite...
    We advise users to avoid using this application and to consider other free, legitimate translation services such as, for instance, Google Translate or Bing’s Translator."
    * https://www.virustotal.com/en/file/3...7d00/analysis/
    File name: KingTranslateSetup-r120-n-bu.exe
    Detection ratio: 3/46
    Analysis date: 2013-06-16
    ___

    Dun & Bradstreet Complaint Spam
    - http://threattrack.tumblr.com/post/5...complaint-spam
    June 17, 2013 - "Subjects Seen:
    FW : Complaint - [removed]
    Typical e-mail details:
    Dun & Bradstreet has received the above-referenced complaint from one of your customers regarding their dealings with you. The details of the consumer’s concern are included on the reverse. Please review this matter and advise us of your position.
    In the interest of time and good customer relations, please provide the DnB with written verification of your position in this matter by June 28, 2013. Your prompt response will allow DnB to be of service to you and your customer in reaching a mutually agreeable resolution. Please inform us if you have contacted your customer directly and already resolved this matter.
    The Dun & Bradstreet develops and maintains Reliability Reports on companies across the United States and Canada . This information is available to the public and is frequently used by potential customers. Your cooperation in responding to this complaint becomes a permanent part of your file with the Better Business Bureau. Failure to promptly give attention to this matter may be reflected in the report we give to consumers about your company.
    We encourage you to print this complaint (attached file), answer the questions and respond to us.
    We look forward to your prompt attention to this matter.


    Malicious URLs
    iguttersupply .com/ponyb/gate.php
    micromeshleafguard .com/ponyb/gate.php
    ornamentalgutters .com/ponyb/gate.php
    radiantcarbonheat .com/ponyb/gate.php
    sistersnstyle .co/4bnsSjBb.exe
    destinationgreece .com/7tW.exe
    backup.hellaswebnews .com/8P6j4.exe
    elenaseller .net/jKK1NMDt.exe


    Malicious File Name and MD5:
    Case_<random>.zip (3001dc82f5cb98b60326e7f8490488cf)
    Case_<random>.exe (9c862af9a540563488cdc1c61b9ef5f8)

    Screenshot: https://gs1.wac.edgecastcdn.net/8019...osN1qz4rgp.png
    ___

    Fake NewEgg .com SPAM / profurnituree .com
    - http://blog.dynamoo.com/2013/06/newe...itureecom.html
    17 June 2013 - "This fake NewEgg .com spam leads to malware on profurnituree .com:
    Date: Mon, 17 Jun 2013 20:09:35 +0300 [13:09:35 EDT]
    From: Newegg Auto-Notification [indeedskahu02 @services.neweg .com]
    Subject: Newegg.com - Payment Charged ...


    Screenshot: https://lh3.ggpht.com/-aC2D_mxMnTE/U...00/newegg3.png

    The link goes through a legitimate -hacked- site and ends up on a malware landing page at [donotclick]profurnituree .com/news/posts_applied_deem.php (report here*) although the payload appears to be 404ing (I wouldn't trust that though). The domain is hosted on the following IPs:
    124.232.165.112 (China Telecom, China)
    186.215.126.52 (Global Village Telecom, Brazil)
    190.93.23.10 (Greendot, Trinidad and Tobago)
    202.147.169.211 (LINKdotNET Telecom Limited, Pakistan)
    The domain registration details are fake... Below is a partial blocklist which I recommend you use in conjunction with this list.
    124.232.165.112
    186.215.126.52
    190.93.23.10
    202.147.169.211
    ..."
    * http://urlquery.net/report.php?id=3180371

    Last edited by AplusWebMaster; 2013-06-17 at 20:58.
    This machine has no brain.
    ....... Use your own.
    Browser check for updates here.
    .

  2. #212
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    4,289

    Thumbs down Fake UPS, Wells Fargo SPAM...

    FYI...

    Fake UPS SPAM / rmacstolp .net
    - http://blog.dynamoo.com/2013/06/ups-...cstolpnet.html
    18 June 2013 - "This fake UPS spam leads to malware on rmacstolp .net:
    Date: Tue, 18 Jun 2013 01:21:34 -0800 [05:21:34 EDT]
    From: UPSBillingCenter @upsmail .net
    Subject: Your UPS Invoice is Ready
    UPS Billing Center
    This is an automatically generated email. Please do not reply to this email address.
    Dear UPS Customer,
    Thank you for your business.
    New invoice(s) are available for the consolidated payment plan(s) / account(s) enrolled in the UPS Billing Center.
    Please visit the UPS Billing Center to view your paid invoice.
    Questions about your charges? To get a better understanding of surcharges on your invoice, click here.
    Discover more about UPS:
    Visit ups .com
    Explore UPS Freight Services
    Learn About UPS Companies
    Sign Up For Additional Email From UPS
    Read Compass Online
    © 2013 United Parcel Service of America, Inc. UPS, the UPS brandmark, and the color brown are trademarks of United Parcel Service of America, Inc. All rights reserved.
    For more information on UPS's privacy practices, refer to the UPS Privacy Policy.
    Please do not reply directly to this e-mail. UPS will not receive any reply message.
    For questions or comments, visit Contact UPS.
    This communication contains proprietary information and may be confidential. If you are not the intended recipient, the reading, copying, disclosure or other use of the contents of this e-mail is strictly prohibited and you are instructed to please delete this e-mail immediately.
    Privacy Policy
    Contact UPS


    The link in the email goes through a legitimate -hacked- site but then ends up on a malicious payload at [donotclick]rmacstolp .net/news/fishs_grands.php (report here* and here**). The payload appears to be the Blackhole Exploit kit, but the site seems to be either not working or (more likely) is being resistant to analysis. If not called properly, the malware appears to serve up random payload pages.. I think they may be fake ones to evade detection. Here are some of them:
    [donotclick]shop.babeta .ru/ftyxsem.php
    [donotclick]kontra-antiabzocker .net/cpdedlp.php
    [donotclick]www.cyprusivf .net/iabsvkc.php
    [donotclick]clubempire .ru/ayrwoxt.php
    [donotclick]artstroydom .com/rwlqqtq.php
    [donotclick]www.masthotels .gr/ysmaols.php
    rmacstolp .net is hosted on the following IPs:
    186.215.126.52 (Global Village Telecom, Brazil)
    190.93.23.10 (Greendot, Trinidad and Tobago)
    193.254.231.51 (Universitatea Transilvania Brasov, Romania)
    202.147.169.211 (LINKdotNET Telecom Limited, Pakistan)
    Recommended blocklist:
    186.215.126.52
    190.93.23.10
    193.254.231.51
    202.147.169.211
    ..."
    * http://wepawet.iseclab.org/view.php?...562967&type=js

    ** http://urlquery.net/report.php?id=3197446
    ___

    Fake - Wells Fargo attachment Spam
    - http://threattrack.tumblr.com/post/5...ttachment-spam
    June 18, 2013 - "Subjects Seen:
    IMPORTANT Documents- WellsFargo
    Typical e-mail details:
    Please check attached documents.
    Chuck_Vega
    Wells Fargo Advisors
    817-889-5857 office
    817-353-6685 cell Chuck_Vega @wellsfargo.com
    ATTENTION: THIS E-MAIL MAY BE AN ADVERTISEMENT OR SOLICITATION FOR PRODUCTS AND SERVICES.
    To unsubscribe from marketing e-mails from:
    · An individual Wells Fargo Advisors financial advisor: Reply to one of his/her e-mails and type “Unsubscribe” in the subject line.
    · Wells Fargo and its affiliates: Unsubscribe at wellsfargoadvisors.com/unsubscribe.
    Neither of these actions will affect delivery of important service messages regarding your accounts that we may need to send you or preferences you may have previously set for other e-mail services.
    For additional information regarding our electronic communication policies, visit wellsfargoadvisors .com/disclosures/email-disclosure.html .
    Investments in securities and insurance products are:
    NOT FDIC-INSURED/NO BANK-GUARANTEES/MAY LOSE VALUE
    Wells Fargo Advisors, LLC is a nonbank affiliate of Wells Fargo & Company, Member FINRA/SIPC. 1 North Jefferson, St. Louis, MO 63103


    Malicious URLs
    thinkgreensupply .com/ponyb/gate.php
    pacificcontractsources .com/ponyb/gate.php
    tpi-ny.com/ponyb/gate .php
    50shadesofshades .com/ponyb/gate.php
    sistersnstyle .co/4bnsSjBb.exe
    destinationgreece .com/7tW.exe
    backup.hellaswebnews .com/8P6j4.exe
    elenaseller .net/jKK1NMDt.exe


    Malicious File Name and MD5:
    WellsFargo_<random>.zip (3001dc82f5cb98b60326e7f8490488cf)
    WellsFargo_<random>.exe (3c671b9f969a7ba0a9d9b532840c4ea2)

    Screenshot: https://gs1.wac.edgecastcdn.net/8019...lxa1qz4rgp.png

    Last edited by AplusWebMaster; Yesterday at 18:15.
    This machine has no brain.
    ....... Use your own.
    Browser check for updates here.
    .

  3. #213
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    4,289

    Thumbs down Something evil on 205.234.139.169

    FYI...

    Something evil on 205.234.139.169
    - http://blog.dynamoo.com/2013/06/some...234139169.html
    19 June 2013 - "205.234.139.169 (Hostforweb, US) appears to be hosting a bunch of Java exploits being served up on subdomains of hacked GoDaddy domains. The malware looks like it is being served up in some sort of injection attack. Here are some example URLs of badness:
    [donotclick]blog2.stefuraassociatesinc .com:6842/ServerAdministrator/keys/pairs/applet.jnlp
    [donotclick]blog2.stefuraassociatesinc .com:6842/ServerAdministrator/keys/pairs/contact.php
    [donotclick]blog2.stefuraassociatesinc .com:6842/ServerAdministrator/keys/pairs/xXsdYVRQe.class
    [donotclick]blog2.stefuraassociatesinc .com:6842/ServerAdministrator/keys/pairs/xXsdYVRQe/class.class
    [donotclick]blog2.stefuraassociatesinc .com:6842/ServerAdministrator/keys/pairs/jfygZbFu
    URLquery* and VirusTotal** are not very conclusive, but if it walks like a duck and quacks like a duck.. well, you know the rest.
    The following domains appear to be hosted on the server. You should assume that they are all malicious, ones already flagged by Google ..."
    (More detail at the dynamoo URL above.)
    * http://urlquery.net/search.php?q=205...3-06-19&max=50

    ** https://www.virustotal.com/en/ip-add...9/information/
    ___

    Fake HP Digital Device Spam
    - http://threattrack.tumblr.com/post/5...al-device-spam
    June 19, 2013 - "Subjects Seen:
    Scanned Copy
    Typical e-mail details:
    Please open the attached document. This document was digitally sent to you using an HP Digital Sending device.
    To view this document you need to use the Adobe Acrobat Reader.


    Malicious URLs
    bagdup .com/ponyb/gate.php
    baggagereviews .com/ponyb/gate.php
    bagpreview .com/ponyb/gate.php
    mpricecs .com .au/ceAZfkX6.exe
    serw.myroitracking .com/nokxk.exe
    omnicomer .com/qT6DM.exe
    sweethomesorrento .it/kNH827.exe


    Malicious File Name and MD5:
    HP_Scan_<random>.zip (d17aab950060319ea41b038638375268)
    HP_Scan_<random>.exe (eab3a43d077661ca1c9549df49477ddb)

    Screenshot: https://gs1.wac.edgecastcdn.net/8019...dIV1qz4rgp.png

    HP Spam / HP_Scan_06292013_398.zip FAIL
    - http://blog.dynamoo.com/2013/06/hp-s...8zip-fail.html
    June 19, 2013 - "I've been seeing these spams for a couple of days now..
    Date: Wed, 19 Jun 2013 09:39:27 -0500 [10:39:27 EDT]
    From: HP Digital Device [HP.Digital0 @victimdomain ]
    Subject: Scanned Copy
    Please open the attached document. This document was digitally sent to you using an HP Digital Sending device.
    To view this document you need to use the Adobe Acrobat Reader...


    The is an attachment called HP_Scan_06292013_398.zip. Obviously this is an attempt to deliver malware.. but the attachment is too small to have a payload. Initially I thought that it was some random part of somebody's security infrastructure stripping it off until I got a really clean copy.. and the ZIP file was just 8 bytes:
    12 BA E8 AC 16 AC 7B AE
    Another sample version looks like this, with just 6 bytes:
    12 BA E8 AC 16 AC
    Googling for 12BAE8AC16AC or 12BAE8AC16AC7BAE gets nothing at all (well, except it will now I've blogged about it)..."
    ___

    65+ websites compromised to deliver malvertising
    - https://net-security.org/malware_news.php?id=2519
    June 19, 2013 - "At least 65 different sites serving ads that ultimately led to malware have been spotted by Zscaler researchers*. The massive malvertising campaign started with injected code into the ads served on the sites, and were delivered from several domains, all resolving to the following IP address: 89.45.14.87... The compromised sites were an assortment of random small and medium-sized sites, and among them was the official site for Government Security News..."
    * http://research.zscaler.com/2013/06/...vertising.html
    June 18, 2013 - "On Monday, Government Security News (GSN), reported that their website had been compromised during a mass infection. While in the case of the GSN infection, the injected content was delivered from googlecodehosting.com, we have determined that the same content was also delivered from googlecodehosting.org and googlecodehosting.net, all of which resolve to 89.45.14.87 and are now offline. In reviewing our logs for sites with the aforementioned referrers, indicating that they too were/are compromised, we have thus far identified 65 different sites... Referers for the GSN site appeared as early as Jun 14th, suggesting that the site was likely compromised for a couple of days before they became aware of the situation and took steps to clean the site..."

    Last edited by AplusWebMaster; Today at 20:33.
    This machine has no brain.
    ....... Use your own.
    Browser check for updates here.
    .

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •