Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 7 November 2008

Election Malware Targets Sore Losers - McCain Video Loads Virus

Posted on 09:33 by Unknown
We reported on Wednesday morning that Obama's historic victory was being used by cyber criminals in a spam campaign which attempted to trick email readers into watching a video of Obama's acceptance speech. Clicking the email link took readers to a website which seemed to have a video, but which prompted users to install "Adobe_Flash9.exe", which was not a video player upgrade, but actually a computer virus.

Today the spammer's have decided to take a more negative spin on their spam campaign. While "round one" of the malware seemed to try to appeal to those who were happy that Obama had won, "round two" is trying to trick the Haters into infecting themselves. More than 450 emails have already been received at the UAB Spam Data Mine with such negative subject lines as these:

Barack Obama can lost presidents chair
Barack Obama can lost President's Chair
Barack Obama in Danger - McCain will fight for president post
Barack Obama president resignation - 23/7 News
From Billy Mccain
IMPEACH Barrack Obama | USA government news
McCain Lawmakers Impeach Obama
McCain Lawyers Want to Stop Obama
McCain said today: 'Impeach Obama'
McCain strike against Obama political way
McCain vs Obama - There is a higher potential for confrontation between opposing political forces
McCain want to stop Obama
Moms who voted for Obama
Obama faces impeachment
Obama Impeachment Resources: McCain Look at the Impeachment Process
Obama vs McCain 'Political Strike' May Undermine Labor Group
Scandal: Obama Resignation Letter
Scandal: Re-elections John McCain Will be a Dictator?
Scandal: Re-elections John McCain will defeat Barack Obama
Scandal: Re-elections McCain will win
Scandal: Re-elections Obama: McCain Will Close With Attacks
Scandal: Re-elections Why John McCain will keep fighting
Scandal: Re-elections Why McCain Will Win
The Impeachment of new president Obama
Video: Obama post-resignation speech
Why MccAin Want to Stop Obama From president vacancy?
WScandal: Re-elections hich John McCain will show up to debate?


The website looks like this: (Click the image for a larger version)




As before, the domain names are all newly registered with in China with the Registrar Bizcn.com. The domain names now are:

baraokl.com
oritrsunwart.com
preibrsu.com
serensy.com

Visiting any of the webpages will cause the same "pop-up" which claims that an update is needed to the "Adobe Media Player". Its NOT the same executable that was being used Wednesday morning, but a "re-packing" of the same malware. In other words, it does the same thing, but its still going to need new anti-virus signatures to detect it.

The virus this time around is

File size: 25173 bytes
MD5...: 642a588272e9fe723fb2f1dd8fccede5

Here's a link to the VirusTotal report which shows 22 of 36 AV products currently detect this version of the malware.

Students studying computer forensics at UAB have analyzed this version of the malware and confirmed that the stolen data is sent to the same Ukrainian computer address as the original Obama acceptance speech video and the recent Colonial Bank Digital Certificate malware, 91.203.93.57.

We've sent a request for cooperation for shutdown to the abuse address of record for that IP, abuse@uatelecom.com.ua (good luck, right?)

The malware is hidden on the computer with the name: \9129837.exe and invoked whenever Internet Explorer is active on the computer.

Stolen userids and passwords are sent to the Ukrainian computer using strings that follow this pattern:

http://%s%s?user_id=%.4u&version_id=%s&passphrase=%s&socks=%lu&version=%lu&crc=%.8x
URL: sniffer_ftp_%s
ftp_server=%s&ftp_login=%s&ftp_pass=%s&version=%lu
URL: sniffer_pop3_%s
pop3_server=%s&pop3_login=%s&pop3_pass=%s
URL: sniffer_imap_%s
imap_server=%s&imap_login=%s&imap_pass=%s
URL: sniffer_icq_%s
icq_user=%s&icq_pass=%s

The packer used to make it more difficult to analyze the malware is called "FSG".

Bottom line - don't click on links in email. If you DID click on this link, you need very badly to check out your computer for potential malware.
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • New BBC spam mocks Georgia's President, Spreads New Virus
    This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads ...
  • A New Year and Anti-Virus Products Are Still Losing
    One of our most popular blog posts in 2008 was back in August - Anti-Virus Products Still Fail on Fresh Viruses . I'm sad to report tha...
  • Digital Certificates Update
    A quick update from the previous post. The Digital Certificates spam campaign against Merrill Lynch continues, but the good guys seem to be ...
  • ATM Cashers in 26 Countries steal $40M
    CBS News in New York has a video on their website this morning title Cyber-attacks behind possibly record-breaking bank heist . Former FBI ...
  • Amero to Replace Dollar? Could Storm Worm Be Right?
    According to the newest version of the Storm Worm, the Amero is about to replace the dollar: The U.S. Government began to realize the plan t...
  • FAL$E HOPE$ @ CHRI$TMA$
    FAL$E HOPE$ was a Federal Trade Commission operation announced on December 12, 2006, which cracked down on Bogus Business Opportunities. C...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Minipost: NY Zeus "At Large" Codreanu and Adam captured
    We've previously posted about the FBI's Operation ACHing Mule (that's A-C-H as in Automated-Clearing-House, the way American ba...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (101)
    • ►  December (7)
    • ▼  November (17)
      • Mumbai Bombings: Coordinated Bombings in India are...
      • Bank of America Demo Account - DO NOT CLICK
      • AsProx: The Phisher King?
      • Igor Klopov sentenced
      • Facebook Users Beware
      • Enlisting YOUR BANK to steal your identity
      • Post McColo Spam - What do we see?
      • Unprecedented Drop in Spam
      • Internet Landfill: McColo Corporation
      • Microsoft Reveals Malware and Spam Trends
      • Election Malware and Obama Pill Ads?
      • Election Malware Targets Sore Losers - McCain Vide...
      • Yesterday's Obama Spammer Now Imitates Colonial Bank
      • Computer Virus masquerades as Obama Acceptance Spe...
      • ICE: Operation Predator - Solving Intertwined Chil...
      • More Merger Malware Wachovia Wells Fargo
      • MS08-067: New RPC Worm from China
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile