Page 5 of 8 FirstFirst 12345678 LastLast
Results 41 to 50 of 75

Thread: Another "Storm" Wave ...

  1. #41
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation

    Add another domain:
    - http://blogs.pcmag.com/securitywatch...y_new_year.php
    December 28, 2007 - "...Consider the following unsolicited e-mail:
    From: ccs @ gotapco.com
    Sent: Friday, December 28, 2007
    To: Larry Seltzer
    Subject: Happy 2008!
    Wishes for the New 2008 Year
    hxxp: // newyearwithlove .com
    DON'T GO TO THAT DOMAIN! If you do, or to one of several others with similar names, you'll be redirected to an HTTP request for an EXE file pushing a trojan horse program. The domains are all registered with an unresponsive Russian registrar. Thirteen different name servers on different networks are listed as authoritative in order to make it harder to bring the domain down. Even more may be added, if necessary, to keep the domain up..."
    -----------------------

    - http://preview.tinyurl.com/yud8re
    December 27, 2007 (Computerworld) - "...According to WHOIS look-ups, both the happycards2008.com and newyearcards2008.com domains were registered with a Russian domain registrar named RUcenter only yesterday; the listed contact for the two domain is a "Bill Gudzon" of Los Angeles, Calif., but the contact phone number gave only a constant busy signal. Since the newest Storm attack began on Monday with spam touting Christmas-themed strippers, the code has repacked hundreds of times, a trick malware authors use to deceive signature-based antivirus software. Prevx, said Giuliani*, has already detected more than 400 variants of the version now in circulation."
    * http://www.prevx.com/blog/74/Storm-W...ird-round.html

    Last edited by AplusWebMaster; 2007-12-28 at 23:41.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  2. #42
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation

    FYI...

    Is a New Year's Storm a’brewin?
    - http://preview.tinyurl.com/3apa67
    December 31, 2007 10:40 AM (Symantec Security Response Weblog) - "...The Peacomm gang doesn’t seem content with their recent spam run and have launched a new one. Symantec is currently observing a spam run to celebrate New Years, 2008... Contained in the email is a URL to one of several possible Web sites. What is interesting is the number of recently registered domains involved in this spam run. It looks like another Clause family member- “Larry Clause”- has been very busy over the past few days, registering a number of domains with NIC.RU to aid the spam run. So far we have observed the following sites all involved in the spam run with most being registered to a Larry Clause:
    • familypostcards2008.com
    • freshcards2008.com
    • happy2008toyou.com
    • happycards2008.com
    • happysantacards.com
    • hellosanta2008.com
    • hohoho2008.com
    • newyearcards2008.com
    • newyearwithlove.com
    • parentscards.com
    • postcards-2008.com
    • Santapcards.com
    • Santawishes2008.com
    If clicked on the user is presented with a plain page with the following text:
    'Your download should begin shortly. If your download does not start in approximately 15 seconds, you can click here to launch the download and then press Run. Enjoy!'

    Their use of fast flux hosting on botnets makes it very difficult to stop the hosting of this risk... be very cautious of opening greeting cards, especially from people you do not know. Always keep your antivirus software up-to-date and follow safe computing practices..."

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  3. #43
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Active Storm Worm Domains - Christmas, New Year’s Campaign

    Updates...

    Active Storm Worm Domains - Christmas, New Year’s Campaign
    - http://preview.tinyurl.com/2ueud4
    January 2, 2008 (Arbornetworks) - "Based on a bunch of sources:
    familypostcards2008.com
    freshcards2008.com
    happy2008toyou.com
    happycards2008.com
    happysantacards.com
    hellosanta2008.com
    hohoho2008.com
    merrychristmasdude.com
    newyearcards2008.com
    newyearwithlove.com
    parentscards.com
    postcards-2008.com
    santapcards.com
    santawishes2008.com
    uhavepostcard.com

    All of these are worth blocking by DNS methods (become the local SOA, NXDOMAIN them) and looking for in your emails (look for a simple URL with those domain names near the end of a very short email)...
    UPDATE: Added parentscards.com, which is now in use."
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  4. #44
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Angry Storm Social-Engineering Manages a >200% Increase in Size

    FYI...

    - http://preview.tinyurl.com/3cj8m3
    January 3, 2008 (TrendMicro blog) - "...The good folks over at the German HoneyNet Project* have some interesting statistics which indicate that, due to renewed efforts over the course of the Christmas and New Year’s holiday, the puppet masters controlling the Storm Botnet managed to increase the Storm Botnet size by more than 200%... given that the newest iterations of Storm includes (and revolves around) a new promulgation of a rootkit component**, it can be somewhat difficult to ascertain specific detection numbers... Social engineering continues to be a major, major threat vector..."

    * http://honeyblog.org/archives/156-Me...torm-Worm.html

    ** http://blog.trendmicro.com/storm-get...for-christmas/

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  5. #45
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Unhappy

    FYI...

    Phishing from the Storm Botnet
    - http://www.f-secure.com/weblog/archives/00001359.html
    January 9, 2008 - "Last night there was a phishing run using the domain i-halifax.com. The IP address of the site was changing every second or so. The server i-halifax.com was an active fast flux site and was hosted within a botnet. Interestingly, when we picked out a random IP address from the list and resolved that address to other sites hosted in the past, we found something familiar: Hmm… hellosanta2008.com… postcards-2008.com? Sounds like Storm. So somebody is now using machines infected with and controlled by Storm to run phishing scams. We haven't seen this before. But we've been expecting something along these lines. From our end-of-year Data Security Wrap-up:
    'October brought evidence of Storm variations using unique security keys. The unique keys will allow the botnet to be segmented allowing "space for rent". It looks as if the Storm gang is preparing to sell access to their botnet.'
    This may be what's happening now."
    (Screenshots available at the URL above.)

    - http://www.fortiguardcenter.com/advi...A-2008-02.html
    2008.January.07 - "...As of writing, the phishing run is targeting Barclays customers. All of the emails have a similar body..., and display a typical social engineering speech directed towards users who have a moderate level of awareness. These users are ones who may have heard online banking is subject to some fraudulent computer attacks, but cannot identify one. Phishers often use this social engineering approach for 3 reasons:
    1. A security check is a good pretext to ask people to log in to their account
    2. The "fear factor" carried by a a security check is a strong incentive for people to actually carry forward
    3. Users may feel that since it is a security check, it cannot be an attack the email is referring to ..."
    UPDATES: As of 16:00 January 7, 2008 the notified registrar appears to have taken action as the fraudulent Barclays domain in question (linked to by the phishing emails) no longer responds to queries. As of January 8, 2008 new emails emanating from the Storm botnet have been observed by the Fortinet Global Security Research Team which use the same social and domain engineering, however target a different bank: Halifax. This is a precursor that other banks may be targeted as well..."
    (Screenshots available at the Fortinet URL above.)

    - http://blog.trendmicro.com/a-new-storm-twist-phishing/
    January 8, 2008 - "...several domains which where only registered yesterday “popped up” on our internal early warning systems overnight, and surprisingly enough, we started seeing these hosts serving up phishing pages (partial screenshot of Royal Bank of Scotland phish above) today. Another interesting aspect of this turn of events is that these hosts are part of the Storm fast-flux botnet, and we detected them while watching domain activity normally associated with suspected RBN (Russian Business Network) -associated activities. We can only suspect that perhaps a portion of the Storm botnet is being rented out to phishers..."

    Last edited by AplusWebMaster; 2008-01-10 at 12:11.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  6. #46
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Question Stormy Skies - Clearing?

    Hmmm...

    Stormy Skies - Clearing?
    - http://asert.arbornetworks.com/2008/...kies-clearing/
    January 9th, 2008 - "Seems like NIC.RU has been cleaning house a bit. The recent Storm worm domains appear to have all been cleared up. This domain appears to be dead in both the whois records - it says the domain is locked - and DNS databases.

    UPDATED: a short while after it was originally posted to note that -all- domains are dead, not just one or two."

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  7. #47
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation

    FYI...

    Malicious Code: New Storm Tactic: Valentine's Day
    - http://www.websense.com/securitylabs...hp?AlertID=838
    January 15, 2008 - "Websenseฎ Security Labs™ has received reports and confirmed that the Storm worm has once again switched lure tactics. The worm has now adopted a Valentine's Day twist in its attempts to infect users with malicious code... As with previous Storm emails, various subjects and bodies will be used... 3 different email lures containing 3 different subject lines and message..."

    - http://www.f-secure.com/weblog/archives/00001363.html
    January 15, 2008 - "Yet another wave of the Storm worm are now being spammed widely and this time it's all about love. They were late for Christmas, just in time for new year and really early for Valentine. The filename being downloaded now is withlove.exe..."

    - http://asert.arbornetworks.com/2008/...nes-day-theme/
    January 15th, 2008 - "...inspection reveals it’s a pointer to a storm node...
    Subject lines seen so far:
    * A Toast My Love
    * Your Love Has Opened
    * Sending You My Love ..."

    (Screenshots available at all URLs above.)

    Last edited by AplusWebMaster; 2008-01-16 at 06:37.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  8. #48
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation Malicious Code: New Storm Tactic: Valentine's Day... (more)

    FYI...

    - http://isc.sans.org/diary.html?storyid=3855
    Last Updated: 2008-01-16 10:26:18 UTC - "...The e-mails Storm is sending are same as in last couple of waves – a subject designed to catch your attention and the body with a URL consisting of only an IP address... only 4 anti-virus programs out of 32 on VirusTotal properly detected it with virtually no coverage amongst the most popular anti-virus programs. These results are not completely correct since some AV programs are able to block Storm when the user tries to execute it, due to behavior analysis. That being said, it still shows that the server side packing/obfuscation Storm uses works..."

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  9. #49
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation

    FYI... (current "Subject" and attachment list - Storm e-mail SPAM list)

    - http://preview.tinyurl.com/2r6gma
    January 16, 2008 (Symantec Security Response Weblog) - "...The subjects and bodies we have seen so far include the following (many are recycled from the Storm worm's 2007 Valentine's Day campaign):

    • A Dream is a Wish • A Is For Attitude • A Kiss So Gentle • A Rose
    • A Rose for My Love • A Toast My Love • Come Dance with Me
    • Come Relax with Me • Dream of You • Eternal Love
    • Eternity of Your Love • Falling In Love with You • For You....My Love
    • Heavenly Love • Hugging My Pillow • I Love You Because
    • I Love You Soo Much • I Love You with All I Am • I Would Dream
    • If Loving You • In Your Arms • Inside My Heart • Love Remains
    • Memories of You|A Token of My Love • Miracle of Love
    • Our Love is Free • Our Love Nest • Our Love Will Last
    • Pages from My Heart • Path We Share • Sending You All My Love
    • Sending You My Love • Sent with Love • Special Romance
    • Surrounded by Love • The Dance of Love • The Mood for Love
    • The Time for Love • When Love Comes Knocking • When You Fall in Love
    • Why I Love You • Words in my Heart • Wrapped in Your Arms
    • You... In My Dreams • Your Friend and Lover • Your Love Has Opened
    • You're my Dream

    Attachment Name:
    • withlove.exe
    • with_love.exe ..."

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  10. #50
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Arrow Storm Tracker

    Interesting site - "Storm Tracker":

    > http://www.trustedsource.org/TS?do=t...=storm_tracker
    Daily New Web Proxy IPs
    Most Active Storm Web Proxy IPs
    Top Storm Domains
    Newly Activated Storm Web Proxy IPs
    Recently Seen Storm Web Proxy IPs
    Geolocation of Storm Web Proxy IPs

    .
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •