Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 15 August 2008

New BBC spam mocks Georgia's President, Spreads New Virus

Posted on 06:22 by Unknown
This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads a new virus.

The mail is delivered with three distinct subjects so far:

A copycat spammer is using headlines:

BBC NEWS.
Weekly BBC NEWS.
Your subscription.

to send spam messages claiming a headline that the President of
Georgia is gay.

The Headlines within the email message choose from:

Mikheil Saakashvili gay scandal! New of this week!
Saakashvili have a funny woman organ (pu..sy)! see it!
Funny Saakashvili gay video...See now!Sensation!
Sensation! president of Georgia... GAY! See now!
Last news! Saakashvili (president of Georgia) the gay!
President of Georgia - intim (GAY) video! see now!


The spams contain a linked image of the President from the BBC:



We've received 300+ copies so far . . .

Malware loads from these locations:

http://194.30.13.57/upload1/upload.php
http://aguadodecea.com/upload1/upload.php
http://elitezeitung.de/upload1/upload.php
http://farmaciacardelus.com/upload1/upload.php
http://freeweb.8k.ro/upload1/upload.php
http://hespistani.com/upload1/upload.php
http://magicweb.es/upload1/upload.php
http://marpersa.110mb.com/upload1/upload.php
http://miami-fitness.de/upload1/upload.php
http://outragerecords.com/upload1/upload.php
http://pendulumsandmore.com/upload1/upload.php
http://thecar.fr/upload1/upload.php
http://transporter.tv/upload1/upload.php
http://vishalkullarwar.com/upload1/upload.php
http://www.oris-uk.com/upload1/upload.php
http://xrevolution.de/upload1/upload.php

All of those locations actually cause the virus to be delivered from a single location, the IP address:

79.135.167.49

The name of the malware is "name.avi.exe", and at the moment, only FOUR out of 36 anti-virus products detect it.



Clearly the spam is from someone who doesn't have a solid command on the English language.

So far the emails have been received from more than 40 IP addresses. Spot-checking these IP addresses for previous spam activity finds nothing in the UAB Spam Data Mine, suggesting these machines are not part of a previously used spamming botnet.

58.186.135.166 - Vietnam
59.180.133.160 - India
64.25.16.52 - JetBlue Airways, Salt Lake City, Utah
65.109.64.212 - ADVA Technologies, Sandhurst, GB
65.17.231.160 - Cable Bahamas
65.75.75.34 - Alabanza, Inc - Baltimore, Maryland
66.232.98.237 - NOC4Hosts, Tampa, Florida
67.96.77.3 - US Cellular, Knoxsville, Tennessee
78.132.144.87 - JSC Center Telecom - Russian Federation
79.139.129.137 - Moscow Local Telephone - Russian Federation
80.255.244.19 - Web Media Services - Russian Federation
80.72.23.56 - Colocation facility - Netherlands
81.23.99.50 - Severen Telecom, Russian Federation
85.71.224.34 - Czech Republic
86.126.61.166 - Bucharest, Romania
88.246.83.148 - Turk Telekom, Ankara, Turkey
88.254.4.69 - Poland
89.107.158.235 - St. Petersburg Telephone, Russian Federation
89.110.58.84 - ??
94.28.200.128 - Verizon
96.234.41.61 - Verizon
96.235.33.22 - Verizon
123.193.82.34 - Taiwan
151.8.226.253 - Italy
158.104.100.27 - Wilamette University, Salem, Oregon
159.213.32.206 - Italy
189.20.97.3 - Germany
194.8.120.227 - Federal Agency of Education, Moscow, Russia
195.161.9.2 - Austin Community College, Austin, TX
198.213.3.242 - Colombia
200.11.45.83 - Mexico
200.52.83.57 - Chile
200.73.29.90 - Colombia
205.166.61.190 - Cumberland Technologies, Mechanicsburg, PA
206.162.192.100 - SEI Data, Dillsboro, Indiana
211.110.195.30 - Korea
212.163.164.16 - Germany
212.8.197.5 - Spain
212.85.33.141 - Spain
216.147.32.118 - Albanza
217.35.209.165 - BTNet
220.248.143.44 - China
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • New BBC spam mocks Georgia's President, Spreads New Virus
    This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads ...
  • A New Year and Anti-Virus Products Are Still Losing
    One of our most popular blog posts in 2008 was back in August - Anti-Virus Products Still Fail on Fresh Viruses . I'm sad to report tha...
  • Digital Certificates Update
    A quick update from the previous post. The Digital Certificates spam campaign against Merrill Lynch continues, but the good guys seem to be ...
  • ATM Cashers in 26 Countries steal $40M
    CBS News in New York has a video on their website this morning title Cyber-attacks behind possibly record-breaking bank heist . Former FBI ...
  • Amero to Replace Dollar? Could Storm Worm Be Right?
    According to the newest version of the Storm Worm, the Amero is about to replace the dollar: The U.S. Government began to realize the plan t...
  • FAL$E HOPE$ @ CHRI$TMA$
    FAL$E HOPE$ was a Federal Trade Commission operation announced on December 12, 2006, which cracked down on Bogus Business Opportunities. C...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Minipost: NY Zeus "At Large" Codreanu and Adam captured
    We've previously posted about the FBI's Operation ACHing Mule (that's A-C-H as in Automated-Clearing-House, the way American ba...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ▼  August (22)
      • Hurricane Gustav: Fraud Watch
      • Banking Digital Certificate Malware in Spam
      • E-cards Run Wild. Where are the Anti-Virus Compan...
      • Leave Those Viruses at SCHOOL!
      • Celebrity Spam-Off: Will Paris Hilton Overtake An...
      • Shadow Botnet case may yield spammer Leni Neto
      • More Online Pharmacy Affiliates Indicted
      • Evidence that Georgia DDOS attacks are "populist" ...
      • One third of current spam points to malware sites
      • New BBC spam mocks Georgia's President, Spreads Ne...
      • Can You Pick the Real MSNBC.Com Breaking News?
      • MSNBC Breaking News replaces CNN Spam Wave
      • Anti-Virus Products Still Fail on Fresh Viruses
      • iTunes Store Phish
      • The UAB Spam Data Mine: Looking at Malware Sites
      • TJX Update: The San Diego Indictments
      • TJX Update: The Boston Indictments
      • Linking all the News Spam together (CNN.com Daily ...
      • CNN Spam Diversifies . . .
      • TJX Reminder: "We Will Arrest You, and We Will Sen...
      • CNN Lends Authenticity to News Spam
      • Another Insider Busted: Countrywide Financial Analyst
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile