Wednesday, April 30, 2008

Extreme threat on comprimised website

This link came via a google "pagead". Likely, more than one has got past me. The link redirects to an html page, which loads two (2) iframes and gives a link to and exe. No doubt the exe will load a trojan or word.

I was unable to get a copy of the exe.

http://yboats.com/video_233.php

----
UPDATE: Just after posting this the webpage was deleted. I got a copy of the webpage.
----
UPDATE 2008-05-01: The webpage has returned today.

Sunday, April 27, 2008

Interesting spam domain name

medicalofficebillingmob.com

Thursday, April 24, 2008

The Storm Worm

Notes on articles sent to me by John

Storm Worm DDoS Attack
http://www.secureworks.com/research/threats/storm-worm/
February 8, 2007
NOTE: This is an excellent article which outlines the worm's capabilities.

Storm Worm's Fast Flux Networks
http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html
September 05, 2007

Storm Worm's DDoS Attitude
http://ddanchev.blogspot.com/2007/09/storm-worms-ddos-attitude.html
September 11, 2007

The Storm Worm
http://www.schneier.com/blog/archives/2007/10/the_storm_worm.html
October 04, 2007

Storm Worm botnet partitions for sale
http://blogs.zdnet.com/security/?p=592October 15th, 2007

Microsoft: We took out Storm botnet
http://www.computerworld.com.au/index.php/id;939095798;fp;4;fpid;1398720840
04/23/2008

http://www.linuxsecurity.com/docs/malware-trends.pdf

Friday, April 11, 2008

Viagra from Wallmart?

Notice is has two ells, not one.

Here is a clipping from that spam.

Subject: buy now Viagra 60mg x 30 pills
Date: Fri, 11 Apr 2008 19:47:47 -0500
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset="windows-1250";
reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106

Price for Viagra 50mg x 60 pills US $ 2.00 Per Pill
http://wallmartusa.com

No MX records no SPAM

Recently on slashdot.org a freind note this blog.

As such, I have control of unmailable.com and have been testing the server parameters. Under this I sent email to the domain to check the system. I received email, of course.

Here are the slashdot comments by woolio (who apparently needs to learn about admining a server.)

http://slashdot.org/comments.pl?sid=518480&cid=23033582

You don't have an MX (DNS) record for your domain!

Without designating where the mail should go, you won't get much (if any).

Mail servers *do not* use ordinary "A" type DNS records for email!

Are you even running a SMTP server? It doesn't look like it...

----

Interesting. I did not think to check for an MX record.

Yes, the SMTP server is running. I get email.

Also, the comment that "mail servers" [*do not* use ordinary "A" type] records is incorrect. "A" records are used to send email, that is the default for all mail servers. This has always has been the case. Apparently, "spammers" do use the "A" record.

To that, this begs the question: How long before spammers figure this out?

Jesse

----
2008/04/17
ERROR. ERROR. ERROR.
unmailable.com does have an MX record. I don't know why it is not being spammed. More later.

Jesse

Monday, April 7, 2008

Spammer create own tinyurl,com

Note the extremely small type on the page. The advertising seems to be direct links to their own spam sites.


http://bittyurl.com/

Friday, April 4, 2008

Another Phisher

This times it is a Wells Fargo fake the target is

http://www.afasterway.com/wp/wp-update/update-wells-info/

Tuesday, April 1, 2008

Phishing with EXE target

Some people know better than to click on a file the ends in exe. Then again this is one of the most commong fishing methods.

Currently the website http://ricekorea.co.kr/video.exe has the honor.

Its amazing how dumb these websites are. The main website is running PHP so they may never know about this.


compservice.land.ru
houseofgolden.com
kosma-beauty.de
vallejo.onored.com 2008-04-03
fernbedienung.ch 2008-04-03


Here is a slightly different one. Most links go to an emediausa.com, but a few go to:

http://www.erieri.com/Downloads/QuarterlyUpdates/ERI_SA_Install.exe

Phishing continues for google (adwords), HSBC & other

For over a week, the Phishers have been phishing for account information. This must work because the continue to run them. My guess is they use this credit card information to finance new domain names.... Like the don't have enough. I estimate they at their disposal about 300K+ domain names. More as I get it.

2008-04-02
Here is more on that list:
google (adwords)
HSBC
wachovia
citibusiness (Citibank)
BancorpSouth (bxs.com)
2008-04-04
VaultCoach.cn
TheIBankUsa.cn
IsMyBank.cn