Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 6 January 2009

A New Year and Anti-Virus Products Are Still Losing

Posted on 14:07 by Unknown
One of our most popular blog posts in 2008 was back in August - Anti-Virus Products Still Fail on Fresh Viruses. I'm sad to report that in the New Year the situation is not just bad - its worse.

My students are back from the holidays, and I couldn't be happier! Tomorrow night I have 14 new graduate students who I'll be meeting in my Computer Security class where I teach at the University of Alabama at Birmingham. But this analysis was by one of my undergraduate research students who works on malware analysis for me.

Although the volume is greatly reduced from Christmas and New Years, we are continuing to see a regular flow of "eCards" into the UAB Spam Data Mine. Today's domain name of choice was "smartcardgreeting.com". The website hasn't changed since what I showed in the January 3rd post - Happy New Year! Here's a Virus! - but the malware is much less detectable.

How bad? Only ONE of thirty-nine products at VirusTotal.com was able to detect this malware as being a bad file:



The other malware he analyzed today was a fake ClassMates.com malware. ClassMates.com has been targeted on and off for most of the month of December with a spam message claiming to have a video for you to review. Of course the video doesn't actually play and instead prompts you to download a program which claims to be an AdobePlayer.

There were actually two separate groups of five domains involved in this attack.

adobflashplayer10.com
installadobereader.com
installcashion.com
newflasplayerforcm.com
newgoodclassmates.com


and

flashplayerforwindows.com
flashsiters.com
installationsflash.com
newsflashbbc.com
windowsflashplayer10.com

The latter group was registered on TodayNic.com, and used the Nameserver NS1.NEWHOSTINGFORUS.COM.

Each of which had a page called "reunion2009.htm" which contained the fake video, and the malware downloader and looked like this:



All of the sites were registered with the Chinese domain registrar, BizCN.com, and each used the same nameserver, NS1.AVAILABLEREG.COM.

The first piece of malware, Adobe_Player10.exe, actually has a mediocre detection rate of 16 out of 39 VirusTotal detections. Unfortunately, the only function of this malware is to drop the REAL malware, which is being downloaded from the site:

shangaicons.com/22.exe

22.exe is "double-packed", where the hacker takes his virus, packs it with a packer to avoid undetection, and then takes the results and packs them with a different packer as well. It resulted in a very hard to detect piece of malware, as evidenced by the fact that only ONE of 39 anti-virus products were able to detect this as well:



My student malware analyst was able to successfully unpack the 22.exe malware, and found that it is a root-kitted keylogger, in the same family we've been seeing. It steals passwords from your computer as you type them, and sends them with patterns like this:

C:\Program Files\Internet Explorer\iexplore.exe
http://%s%s?user_id=%.4u&version_id=%s&passphrase=%s&socks=%lu&version=%lu&crc=%.8x
URL: sniffer_ftp_%s
ftp_server=%s&ftp_login=%s&ftp_pass=%s&version=%lu
URL: sniffer_pop3_%s
pop3_server=%s&pop3_login=%s&pop3_pass=%s
URL: sniffer_imap_%s
imap_server=%s&imap_login=%s&imap_pass=%s
URL: sniffer_icq_%s
icq_user=%s&icq_pass=%s

to the Ukrainian IP address:

91.211.65.30

which we first reported seventeen days ago and asked for termination.

We saw about 375 copies of the ClassMates.com email today, with a wide assortment of subject lines, including:
  • Accomplishments by classmates and reunion information
  • Alumni Events: Classmates
  • An Invitation to Personal Classmates Day
  • Bringing Classmates Together January 2009
  • Classmates - ALUMNI Reunion Calendar
  • Classmates - Calendar 2009
  • Classmates - Custom Invitations
  • Classmates 2009 January - Invitation
  • Classmates Alumni Event Calendar
  • Classmates Day - January 2009.
  • Classmates Important Meeting Information
  • Classmates in January - Invitation to All Faculty to the Spring 2009 ...
  • Classmates in January...Invitation! - Page 1
  • Classmates Institutional Membership Invitation
  • Classmates International Honour Society Invitation Acceptance
  • Classmates invitation - Reunion party Greeting Card.
  • Classmates Membership Invitation
  • Classmates Membership Invitation from teachers
  • Classmates Message Boards
  • Classmates Organisation.Class Reunion Information
  • Classmates Organiser Warning - AN URGENT MESSAGE - Your Classmates Are Waiting
  • Classmates Organiser Warning - Classmates Organisation.Have any special memories from when we were in high school?
  • Classmates Organiser Warning - Don't Miss Tonight's Classmates Reunion !
  • Classmates Organiser Warning - How can someone miss a Classmates meeting?
  • Classmates Organiser Warning - How to Hold A Class Meeting And Promote Classmate Support
  • Classmates Organiser Warning - Meeting high school and junior college classmates
  • Classmates Organiser Warning - Webster meetings among former classmates
  • Classmates Party invitation...
  • Classmates Personal Invitation: Custom invitation
  • Classmates Preview, public invitation
  • Classmates Reunion - Invitation
  • Classmates Reunion - Are you ready to accept the invitation?
  • Classmates Reunion - Classmates Reunion - Special Preview Invitation
  • Classmates Reunion - Custom Invitations
  • Classmates Reunion - Invitation: Ready
  • Classmates Reunion - Personal Invitation Letter to visit Classmates Day
  • Classmates Reunion - Personalized Invitations
  • Classmates Reunion - Ready to view your Classmates Invitation?
  • Classmates Reunion - Your Classmates Invitation - He's Ready, Are You?
  • Classmates Reunion Calendar
  • Classmates Reunion Soon - [Class Reunion] Save the Date
  • Classmates Reunion Soon - All your classmates receiving invitations!
  • Classmates Reunion Soon - classmates meeting
  • Classmates Reunion Soon - Classmates Organisation.What Have You Been Up To
  • Classmates Reunion Soon - ClassMates.com about meeting classmates
  • Classmates Reunion Soon - Important Dates for Classmates Meeting
  • Classmates Reunion Soon - Mini-Reunion / Meeting with Classmates
  • Classmates Reunion Soon - UPDATE: Reunion Date Change
  • Classmates Reunion Soon - Video
  • Classmates Reunion Soon - You Have 1 Message Waiting for You. Classmates portal
  • Classmates Reunion Soon - Your Classmates Are Waiting to meet with you
  • Classmates Reunion Soon - Your classmates Day New Date.
  • Classmates Reunion Soon - Your classmates Day New Date..How can someone miss a Classmates meeting?
  • Classmates Reunion Soon - Your classmates Day New Date.Important Dates for Classmates Meeting
  • Classmates Video your personal invitation by John
  • Classmates/com: HappyScrappers January Invitation
  • Classmates/com: January is the time to learn at a low cost
  • Classmates: Be ready for Reunion Day.
  • Classmates: custom invitations 2009
  • Classmates: Display your invitations from your profile
  • Classmates: Invitation Design 2009
  • Classmates: Membership Invitation - American Studies Association
  • Classmates: Membership Invitation. 2009 season
  • Classmates: View Your Invitation - Click Here
  • Classmates: View your personal invitation video from Chris O'Malley
  • Classmates: Your complete invitation is viewable for 30 days after the event.
  • Classmates: Your Invitation Place
  • Classmates: your invitation to a private view
  • Do not miss the Classmates reunion
  • Do-Not-Miss Classmates reunion.
  • Events Calendar : Classmates
  • Friends waiting for your visit! Classmates
  • Get all of your classmates together Day - January 2009
  • Important Classmates Day's 2009
  • Invitation to the Classmates - January 12th | Earth ...
  • January - Classmates/com
  • January 16, 2009: Deadline for Classmates Invitation
  • January Invitation. Classmates
  • January Invitations, Classmates Invitations, Online ...
  • My Classmates news
  • Reconnect with your MBA classmates and favorite teachers
  • Search for Classmates
  • Spam Accomplishments by classmates and reunion information
  • The power of a personal invitation - Classmates
  • Traditional January Invitations, Classmates Party ...
  • Use Classmates.com to bring class together.
  • Welcome to Classmates Personal Invitation
  • Your Classmates Are Waiting. Classmates Invite all friends.
  • Your Classmates Are Waiting.Look an invitation.
  • Your classmates Day New Date.A Meeting with my HighSchool Classmates
  • Your classmates Day New Date.Important Meeting for Classmates
  • Your classmates Day!
  • Your classmates will be able to find your
  • Your High bring classmates together.



(The previous batch of domains, including "classmatersunion.com, indexguideclassmates.com, renewclassmates.com" all used the nameserver, NS1.GOODNEWYEARHOSTING.COM)

The Classmates malware domains are hosted by Fast Flux, and are using the same Fast Flux network as the current MBNA phishing sites, such as bankcardservices.mbna.co.uk.dlls-id01.eu.
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • What about the Social Security Numbers? (The Utah Data Breach and your SSN)
    The Utah Data Breach This week the continuing saga of the Utah Medicaid Data Breach continued to unfold. If you haven't been following...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Carder Christopher Schroebel gets Seven Years
    21 years old and thinking about Cybercrime as a career choice?  Think again.  Seattle-based U.S. Attorney Jenny Durkan told a press conferen...
  • Stop the Rumors: Quit SMSing about WalMart Gang Initiations
    My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here...
  • New BBC spam mocks Georgia's President, Spreads New Virus
    This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads ...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Digital Certificates Update
    A quick update from the previous post. The Digital Certificates spam campaign against Merrill Lynch continues, but the good guys seem to be ...
  • ATM Cashers in 26 Countries steal $40M
    CBS News in New York has a video on their website this morning title Cyber-attacks behind possibly record-breaking bank heist . Former FBI ...
  • A New Year and Anti-Virus Products Are Still Losing
    One of our most popular blog posts in 2008 was back in August - Anti-Virus Products Still Fail on Fresh Viruses . I'm sad to report tha...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ▼  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ▼  January (10)
      • Dear Santa (or, the American Recovery and Reinvest...
      • Downadup / Conflicker Worm: 8? 9? 10 Million Infec...
      • US Army hacked as Gaza protest
      • Gaza Conflict spam points to Fake CNN Infection site
      • A New Year and Anti-Virus Products Are Still Losing
      • Whatever happened to Alan Ralsky?
      • Happy New Year! Here's a Virus! (New Year's Post...
      • Morocco based "Team Evil" reroutes prominent Israe...
      • 2008: Looking back on a Year of Spam and Malware
      • What does a National Cyber Range do?
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile