Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 8 January 2009

Gaza Conflict spam points to Fake CNN Infection site

Posted on 08:15 by Unknown
Beginning at 7:30 this morning, the UAB Spam Data Mine began receiving emails claiming to have news about the Gaza conflict from CNN News.



(A typical email)

Each of the many emails we've received points to a website that looks like this:




(click for larger image)

All of the links on the website are functional, and all really resolve to the real CNN website, with two exceptions. Attempting to play the video will result in the download of malware, and following the Adobe Player button will also result in the download of malware.

During the summer of 2008, one of the most successful spam campaigns of the year also imitated a CNN news story, leading to many home and business computers being infected by a virus.

At this time, many major anti-virus products still do not detect this malware as a virus. According to this Virus Total report only 11 of 38 anti-virus products will trigger on this file as containing a virus. (Follow the link to see if your product does or does not.)

The spam messages refer visitors to one of five different domains, each of which was registered at BizCN.com, a Chinese domain registrar who has been abused by this particular group for many months. Analysis of the malware confirms that this incident has nothing at all to do with the CyberWar being waged by pro- and anti-Israeli hackers. This is instead pure social engineering.

Just as with the many "online banking videos", the "digital certificate malware", the "Fake Bank Merger malware, yesterday's "Classmates.com reunion video", and the fake "Obama acceptance speech, this is a piece of malware which is designed to steal your passwords and send the stolen information to the criminal's server in the Ukraine, which is currently 91.211.65.30.

UAB Student and Malware Analyst, Brian Tanner, examined the Adobe_Player10.exe malware and identified that it causes your computer to download a second piece of malware from http://powerpekin.com/servicepack1.exe. That malware, which has the MD5 of 1f337515a3e96fd317dfb24e9fe67448, was only detected by 2 of 38 products at Virus Total. He then unpacked the servicepack1.exe malware and examined it to determine the stolen data was being sent to 91.211.65.30.

The domains used by this spam include:

downloadplayersnews.com
installflashadobeplaye10.com
newsinstalls.com
startinstalladobe.com

As with yesterday's ClassMates.com incident, the websites are being hosted via Fast Flux hosting, and the same fast flux hosts are being used for phishing as well, currently against MBNA bank and Sparkasse of Germany.

The false registration information provided on the domains claims that an imaginary employee of the BBC (Monnie Moulhem) residing in Spring Hill Florida registered the domains.

The computer which is being used as the "Nameserver" for these malware distribution domains resides at 74.63.217.81 -- which is the same computer which served as the nameserver for yesterday's Classmates.com malware.

While we know that many other subject lines will be used as the campaign progresses, some that we have seen so far include the subject lines:

Gaza emergency - UNICEF
Gaza Groups Report on War
Gaza: Israeli War Crimes?
In what became known as Israel's War of Independence
Israel Assaults Hamas in Gaza
Israel At 'War to the Bitter End,' Strikes Key Hamas...
Israel launches deadly Gaza attacks
Israel Puts War Footage
Israel warns Gaza of impending invasion - Israel-Palestinians ...
Israel: Preparing for War
Israel-Gaza conflict: Tens of thousands in London protest Gaza ...
IsraelGaza Strip barrier
Israeli war strategy.IDF in urban combat.
Israel's War Crimes
Israels War on Hamas:A Dozen Thoughts
News from Israel,Ynetnews - Israel at War
Now Israel declares 'war to the bitter end' - Middle East, World ...
Religious war in Gaza - Israel Opinion, Ynetnews
The 20072008 Israel-Gaza conflict refers to a series of battles between Palestinian militants
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • What about the Social Security Numbers? (The Utah Data Breach and your SSN)
    The Utah Data Breach This week the continuing saga of the Utah Medicaid Data Breach continued to unfold. If you haven't been following...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Carder Christopher Schroebel gets Seven Years
    21 years old and thinking about Cybercrime as a career choice?  Think again.  Seattle-based U.S. Attorney Jenny Durkan told a press conferen...
  • Stop the Rumors: Quit SMSing about WalMart Gang Initiations
    My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here...
  • New BBC spam mocks Georgia's President, Spreads New Virus
    This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads ...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Digital Certificates Update
    A quick update from the previous post. The Digital Certificates spam campaign against Merrill Lynch continues, but the good guys seem to be ...
  • ATM Cashers in 26 Countries steal $40M
    CBS News in New York has a video on their website this morning title Cyber-attacks behind possibly record-breaking bank heist . Former FBI ...
  • A New Year and Anti-Virus Products Are Still Losing
    One of our most popular blog posts in 2008 was back in August - Anti-Virus Products Still Fail on Fresh Viruses . I'm sad to report tha...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ▼  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ▼  January (10)
      • Dear Santa (or, the American Recovery and Reinvest...
      • Downadup / Conflicker Worm: 8? 9? 10 Million Infec...
      • US Army hacked as Gaza protest
      • Gaza Conflict spam points to Fake CNN Infection site
      • A New Year and Anti-Virus Products Are Still Losing
      • Whatever happened to Alan Ralsky?
      • Happy New Year! Here's a Virus! (New Year's Post...
      • Morocco based "Team Evil" reroutes prominent Israe...
      • 2008: Looking back on a Year of Spam and Malware
      • What does a National Cyber Range do?
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile