Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 15 August 2008

New BBC spam mocks Georgia's President, Spreads New Virus

Posted on 06:22 by Unknown
This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads a new virus.

The mail is delivered with three distinct subjects so far:

A copycat spammer is using headlines:

BBC NEWS.
Weekly BBC NEWS.
Your subscription.

to send spam messages claiming a headline that the President of
Georgia is gay.

The Headlines within the email message choose from:

Mikheil Saakashvili gay scandal! New of this week!
Saakashvili have a funny woman organ (pu..sy)! see it!
Funny Saakashvili gay video...See now!Sensation!
Sensation! president of Georgia... GAY! See now!
Last news! Saakashvili (president of Georgia) the gay!
President of Georgia - intim (GAY) video! see now!


The spams contain a linked image of the President from the BBC:



We've received 300+ copies so far . . .

Malware loads from these locations:

http://194.30.13.57/upload1/upload.php
http://aguadodecea.com/upload1/upload.php
http://elitezeitung.de/upload1/upload.php
http://farmaciacardelus.com/upload1/upload.php
http://freeweb.8k.ro/upload1/upload.php
http://hespistani.com/upload1/upload.php
http://magicweb.es/upload1/upload.php
http://marpersa.110mb.com/upload1/upload.php
http://miami-fitness.de/upload1/upload.php
http://outragerecords.com/upload1/upload.php
http://pendulumsandmore.com/upload1/upload.php
http://thecar.fr/upload1/upload.php
http://transporter.tv/upload1/upload.php
http://vishalkullarwar.com/upload1/upload.php
http://www.oris-uk.com/upload1/upload.php
http://xrevolution.de/upload1/upload.php

All of those locations actually cause the virus to be delivered from a single location, the IP address:

79.135.167.49

The name of the malware is "name.avi.exe", and at the moment, only FOUR out of 36 anti-virus products detect it.



Clearly the spam is from someone who doesn't have a solid command on the English language.

So far the emails have been received from more than 40 IP addresses. Spot-checking these IP addresses for previous spam activity finds nothing in the UAB Spam Data Mine, suggesting these machines are not part of a previously used spamming botnet.

58.186.135.166 - Vietnam
59.180.133.160 - India
64.25.16.52 - JetBlue Airways, Salt Lake City, Utah
65.109.64.212 - ADVA Technologies, Sandhurst, GB
65.17.231.160 - Cable Bahamas
65.75.75.34 - Alabanza, Inc - Baltimore, Maryland
66.232.98.237 - NOC4Hosts, Tampa, Florida
67.96.77.3 - US Cellular, Knoxsville, Tennessee
78.132.144.87 - JSC Center Telecom - Russian Federation
79.139.129.137 - Moscow Local Telephone - Russian Federation
80.255.244.19 - Web Media Services - Russian Federation
80.72.23.56 - Colocation facility - Netherlands
81.23.99.50 - Severen Telecom, Russian Federation
85.71.224.34 - Czech Republic
86.126.61.166 - Bucharest, Romania
88.246.83.148 - Turk Telekom, Ankara, Turkey
88.254.4.69 - Poland
89.107.158.235 - St. Petersburg Telephone, Russian Federation
89.110.58.84 - ??
94.28.200.128 - Verizon
96.234.41.61 - Verizon
96.235.33.22 - Verizon
123.193.82.34 - Taiwan
151.8.226.253 - Italy
158.104.100.27 - Wilamette University, Salem, Oregon
159.213.32.206 - Italy
189.20.97.3 - Germany
194.8.120.227 - Federal Agency of Education, Moscow, Russia
195.161.9.2 - Austin Community College, Austin, TX
198.213.3.242 - Colombia
200.11.45.83 - Mexico
200.52.83.57 - Chile
200.73.29.90 - Colombia
205.166.61.190 - Cumberland Technologies, Mechanicsburg, PA
206.162.192.100 - SEI Data, Dillsboro, Indiana
211.110.195.30 - Korea
212.163.164.16 - Germany
212.8.197.5 - Spain
212.85.33.141 - Spain
216.147.32.118 - Albanza
217.35.209.165 - BTNet
220.248.143.44 - China
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • What about the Social Security Numbers? (The Utah Data Breach and your SSN)
    The Utah Data Breach This week the continuing saga of the Utah Medicaid Data Breach continued to unfold. If you haven't been following...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Carder Christopher Schroebel gets Seven Years
    21 years old and thinking about Cybercrime as a career choice?  Think again.  Seattle-based U.S. Attorney Jenny Durkan told a press conferen...
  • Stop the Rumors: Quit SMSing about WalMart Gang Initiations
    My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here...
  • New BBC spam mocks Georgia's President, Spreads New Virus
    This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads ...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Digital Certificates Update
    A quick update from the previous post. The Digital Certificates spam campaign against Merrill Lynch continues, but the good guys seem to be ...
  • ATM Cashers in 26 Countries steal $40M
    CBS News in New York has a video on their website this morning title Cyber-attacks behind possibly record-breaking bank heist . Former FBI ...
  • A New Year and Anti-Virus Products Are Still Losing
    One of our most popular blog posts in 2008 was back in August - Anti-Virus Products Still Fail on Fresh Viruses . I'm sad to report tha...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ▼  August (22)
      • Hurricane Gustav: Fraud Watch
      • Banking Digital Certificate Malware in Spam
      • E-cards Run Wild. Where are the Anti-Virus Compan...
      • Leave Those Viruses at SCHOOL!
      • Celebrity Spam-Off: Will Paris Hilton Overtake An...
      • Shadow Botnet case may yield spammer Leni Neto
      • More Online Pharmacy Affiliates Indicted
      • Evidence that Georgia DDOS attacks are "populist" ...
      • One third of current spam points to malware sites
      • New BBC spam mocks Georgia's President, Spreads Ne...
      • Can You Pick the Real MSNBC.Com Breaking News?
      • MSNBC Breaking News replaces CNN Spam Wave
      • Anti-Virus Products Still Fail on Fresh Viruses
      • iTunes Store Phish
      • The UAB Spam Data Mine: Looking at Malware Sites
      • TJX Update: The San Diego Indictments
      • TJX Update: The Boston Indictments
      • Linking all the News Spam together (CNN.com Daily ...
      • CNN Spam Diversifies . . .
      • TJX Reminder: "We Will Arrest You, and We Will Sen...
      • CNN Lends Authenticity to News Spam
      • Another Insider Busted: Countrywide Financial Analyst
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile