This link came via a google "pagead". Likely, more than one has got past me. The link redirects to an html page, which loads two (2) iframes and gives a link to and exe. No doubt the exe will load a trojan or word.
I was unable to get a copy of the exe.
http://yboats.com/video_233.php
----
UPDATE: Just after posting this the webpage was deleted. I got a copy of the webpage.
----
UPDATE 2008-05-01: The webpage has returned today.
Wednesday, April 30, 2008
Sunday, April 27, 2008
Thursday, April 24, 2008
The Storm Worm
Notes on articles sent to me by John
Storm Worm DDoS Attack
http://www.secureworks.com/research/threats/storm-worm/
February 8, 2007
NOTE: This is an excellent article which outlines the worm's capabilities.
Storm Worm's Fast Flux Networks
http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html
September 05, 2007
Storm Worm's DDoS Attitude
http://ddanchev.blogspot.com/2007/09/storm-worms-ddos-attitude.html
September 11, 2007
The Storm Worm
http://www.schneier.com/blog/archives/2007/10/the_storm_worm.html
October 04, 2007
Storm Worm botnet partitions for sale
http://blogs.zdnet.com/security/?p=592October 15th, 2007
Microsoft: We took out Storm botnet
http://www.computerworld.com.au/index.php/id;939095798;fp;4;fpid;1398720840
04/23/2008
http://www.linuxsecurity.com/docs/malware-trends.pdf
Storm Worm DDoS Attack
http://www.secureworks.com/research/threats/storm-worm/
February 8, 2007
NOTE: This is an excellent article which outlines the worm's capabilities.
Storm Worm's Fast Flux Networks
http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html
September 05, 2007
Storm Worm's DDoS Attitude
http://ddanchev.blogspot.com/2007/09/storm-worms-ddos-attitude.html
September 11, 2007
The Storm Worm
http://www.schneier.com/blog/archives/2007/10/the_storm_worm.html
October 04, 2007
Storm Worm botnet partitions for sale
http://blogs.zdnet.com/security/?p=592October 15th, 2007
Microsoft: We took out Storm botnet
http://www.computerworld.com.au/index.php/id;939095798;fp;4;fpid;1398720840
04/23/2008
http://www.linuxsecurity.com/docs/malware-trends.pdf
Friday, April 11, 2008
Viagra from Wallmart?
Notice is has two ells, not one.
Here is a clipping from that spam.
Subject: buy now Viagra 60mg x 30 pills
Date: Fri, 11 Apr 2008 19:47:47 -0500
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset="windows-1250";
reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
Price for Viagra 50mg x 60 pills US $ 2.00 Per Pill
http://wallmartusa.com
Here is a clipping from that spam.
Subject: buy now Viagra 60mg x 30 pills
Date: Fri, 11 Apr 2008 19:47:47 -0500
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset="windows-1250";
reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
Price for Viagra 50mg x 60 pills US $ 2.00 Per Pill
http://wallmartusa.com
No MX records no SPAM
Recently on slashdot.org a freind note this blog.
As such, I have control of unmailable.com and have been testing the server parameters. Under this I sent email to the domain to check the system. I received email, of course.
Here are the slashdot comments by woolio (who apparently needs to learn about admining a server.)
http://slashdot.org/comments.pl?sid=518480&cid=23033582
You don't have an MX (DNS) record for your domain!
Without designating where the mail should go, you won't get much (if any).
Mail servers *do not* use ordinary "A" type DNS records for email!
Are you even running a SMTP server? It doesn't look like it...
----
Interesting. I did not think to check for an MX record.
Yes, the SMTP server is running. I get email.
Also, the comment that "mail servers" [*do not* use ordinary "A" type] records is incorrect. "A" records are used to send email, that is the default for all mail servers. This has always has been the case. Apparently, "spammers" do use the "A" record.
To that, this begs the question: How long before spammers figure this out?
Jesse
----
2008/04/17
ERROR. ERROR. ERROR.
unmailable.com does have an MX record. I don't know why it is not being spammed. More later.
Jesse
As such, I have control of unmailable.com and have been testing the server parameters. Under this I sent email to the domain to check the system. I received email, of course.
Here are the slashdot comments by woolio (who apparently needs to learn about admining a server.)
http://slashdot.org/comments.pl?sid=518480&cid=23033582
You don't have an MX (DNS) record for your domain!
Without designating where the mail should go, you won't get much (if any).
Mail servers *do not* use ordinary "A" type DNS records for email!
Are you even running a SMTP server? It doesn't look like it...
----
Interesting. I did not think to check for an MX record.
Yes, the SMTP server is running. I get email.
Also, the comment that "mail servers" [*do not* use ordinary "A" type] records is incorrect. "A" records are used to send email, that is the default for all mail servers. This has always has been the case. Apparently, "spammers" do use the "A" record.
To that, this begs the question: How long before spammers figure this out?
Jesse
----
2008/04/17
ERROR. ERROR. ERROR.
unmailable.com does have an MX record. I don't know why it is not being spammed. More later.
Jesse
Monday, April 7, 2008
Spammer create own tinyurl,com
Note the extremely small type on the page. The advertising seems to be direct links to their own spam sites.
http://bittyurl.com/
http://bittyurl.com/
Friday, April 4, 2008
Another Phisher
This times it is a Wells Fargo fake the target is
http://www.afasterway.com/wp/wp-update/update-wells-info/
http://www.afasterway.com/wp/wp-update/update-wells-info/
Tuesday, April 1, 2008
Phishing with EXE target
Some people know better than to click on a file the ends in exe. Then again this is one of the most commong fishing methods.
Currently the website http://ricekorea.co.kr/video.exe has the honor.
Its amazing how dumb these websites are. The main website is running PHP so they may never know about this.
compservice.land.ru
houseofgolden.com
kosma-beauty.de
vallejo.onored.com 2008-04-03
fernbedienung.ch 2008-04-03
Here is a slightly different one. Most links go to an emediausa.com, but a few go to:
http://www.erieri.com/Downloads/QuarterlyUpdates/ERI_SA_Install.exe
Currently the website http://ricekorea.co.kr/video.exe has the honor.
Its amazing how dumb these websites are. The main website is running PHP so they may never know about this.
compservice.land.ru
houseofgolden.com
kosma-beauty.de
vallejo.onored.com 2008-04-03
fernbedienung.ch 2008-04-03
Here is a slightly different one. Most links go to an emediausa.com, but a few go to:
http://www.erieri.com/Downloads/QuarterlyUpdates/ERI_SA_Install.exe
Phishing continues for google (adwords), HSBC & other
For over a week, the Phishers have been phishing for account information. This must work because the continue to run them. My guess is they use this credit card information to finance new domain names.... Like the don't have enough. I estimate they at their disposal about 300K+ domain names. More as I get it.
2008-04-02
Here is more on that list:
google (adwords)
HSBC
wachovia
citibusiness (Citibank)
BancorpSouth (bxs.com)
2008-04-04
VaultCoach.cn
TheIBankUsa.cn
IsMyBank.cn
2008-04-02
Here is more on that list:
google (adwords)
HSBC
wachovia
citibusiness (Citibank)
BancorpSouth (bxs.com)
2008-04-04
VaultCoach.cn
TheIBankUsa.cn
IsMyBank.cn
Subscribe to:
Posts (Atom)