Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 28 October 2009

FACEBOOK PHISH! Users Beware!

Posted on 07:30 by Unknown
The FDIC spam campaign that we reported on yesterday in our story Fake FDIC Spam Campaign Spreads Zeus has already moved on to its next attack. Now its trying to steal your Facebook passwords in what appears at first glance to be a "traditional" phishing attack. (Please see the end of this article for an update on how this "phish" actually is another Zeus malware infection vector.)



The UAB Spam Data Mine has already received more than 250 copies of the new phishing email this morning, which claims:

In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security.

Before you are able to use the new login system, you will be required to update your account.

Click (here) to update your account online now.

If you have any questions, reference our New User Guide

Thanks,
The Facebook Team


The email is fake, of course, and so are the websites they point to. So far we've identified 31 unique domain names registered by the criminal for use in this Facebook account.

The website looks like this:



UAB Malware Analyst Brian Tanner took the new Facebook Phish for a drive through the lab, and confirmed that this is NOT JUST A PHISH - in fact it might not be a traditional phish at all. Its actually a Zeus Bot installer, pointing at the same command & control site as yesterday's FDIC version of Zeus:



Clicking on the prompted "UpdateTool.exe" is the infection vector for Zeus. According to the VirusTotal Report for this malware, only 8 of 41 AV products are currently labelling this executable as malware.

File size: 105472 bytes
MD5 : 1198d2ddf09061fbfb70de423cde059f

Update 29OCT09 AM


Spam for this campaign is still coming fast and furious to the UAB Spam Data Mine. More than 200 fresh copies were received already this morning.

File size: 105984 bytes
MD5...: 6aad88ba4805b2daa4fc6106a5376065

A
VirusTotal report
for the current version is showing 9 of 41 detections.

Update - 01NOV2009


From October 27th until November 1st, we've seen 242 different domain names used by this campaign. Here are the ones that are currently live at this point in time (5:25 PM) --

www.facebook.com.heratsb.eu
www.facebook.com.heratsd.eu
www.facebook.com.heratsf.eu
www.facebook.com.heratsg.eu
www.facebook.com.heratsh.eu
www.facebook.com.heratsk.eu
www.facebook.com.heratsl.eu
www.facebook.com.heratsm.eu
www.facebook.com.heratsn.eu
www.facebook.com.heratso.eu
www.facebook.com.heratsq.eu
www.facebook.com.heratsr.eu
www.facebook.com.heratss.eu
www.facebook.com.heratst.eu
www.facebook.com.heratsy.eu
www.facebook.com.lllujiob.eu
www.facebook.com.lllujioc.eu
www.facebook.com.lllujiod.eu
www.facebook.com.lllujiof.eu
www.facebook.com.lllujiog.eu
www.facebook.com.lllujioh.eu
www.facebook.com.lllujioi.eu
www.facebook.com.lllujioj.eu
www.facebook.com.lllujion.eu
www.facebook.com.lllujiot.eu
www.facebook.com.lllujiov.eu
www.facebook.com.lllujiox.eu
www.facebook.com.lllujioy.eu
www.facebook.com.lllujioz.eu
www.facebook.com.ttteraa.eu
www.facebook.com.ttterab.eu
www.facebook.com.ttterac.eu
www.facebook.com.ttterad.eu
www.facebook.com.ttterae.eu
www.facebook.com.ttteraf.eu
www.facebook.com.ttterag.eu
www.facebook.com.ttteran.eu
www.facebook.com.ttteraq.eu
www.facebook.com.ttterav.eu
www.facebook.com.ttterax.eu
www.facebook.com.ttteraz.eu

Here is the full list . . .

www.facebook.com.edilokqf.eu
www.facebook.com.edilokqi.eu
www.facebook.com.edilokqm.eu
www.facebook.com.edilokqn.eu
www.facebook.com.edilokqr.eu
www.facebook.com.edilokqs.eu
www.facebook.com.edilokqu.eu
www.facebook.com.edilokqv.eu
www.facebook.com.edilokqw.eu
www.facebook.com.edilokqx.eu
www.facebook.com.eiye1ua.eu
www.facebook.com.eiye1uc.eu
www.facebook.com.eiye1ue.eu
www.facebook.com.eiye1uf.eu
www.facebook.com.eiye1ug.eu
www.facebook.com.eiye1ur.eu
www.facebook.com.eiye1us.eu
www.facebook.com.eiye1ut.eu
www.facebook.com.eiye1uv.eu
www.facebook.com.fasazab.eu
www.facebook.com.fasazad.eu
www.facebook.com.fasazae.eu
www.facebook.com.fasazaf.eu
www.facebook.com.fasazag.eu
www.facebook.com.fasazam.eu
www.facebook.com.fasazan.eu
www.facebook.com.fasazav.eu
www.facebook.com.heratsb.eu
www.facebook.com.heratsd.eu
www.facebook.com.heratsf.eu
www.facebook.com.heratsg.eu
www.facebook.com.heratsh.eu
www.facebook.com.heratsk.eu
www.facebook.com.heratsl.eu
www.facebook.com.heratsm.eu
www.facebook.com.heratsn.eu
www.facebook.com.heratso.eu
www.facebook.com.heratsq.eu
www.facebook.com.heratsr.eu
www.facebook.com.heratss.eu
www.facebook.com.heratst.eu
www.facebook.com.heratsy.eu
www.facebook.com.herrazzb.eu
www.facebook.com.herrazzd.eu
www.facebook.com.herrazzf.eu
www.facebook.com.herrazzg.eu
www.facebook.com.herrazzh.eu
www.facebook.com.herrazzj.eu
www.facebook.com.herrazzk.eu
www.facebook.com.herrazzo.eu
www.facebook.com.herrazzr.eu
www.facebook.com.herrazzt.eu
www.facebook.com.herrazzu.eu
www.facebook.com.herrazzv.eu
www.facebook.com.herrazzy.eu
www.facebook.com.ibbaswza.eu
www.facebook.com.ibbaswzd.eu
www.facebook.com.ibbaswze.eu
www.facebook.com.ibbaswzf.eu
www.facebook.com.ibbaswzr.eu
www.facebook.com.iokasqzc.eu
www.facebook.com.iokasqze.eu
www.facebook.com.iokasqzh.eu
www.facebook.com.iokasqzr.eu
www.facebook.com.iokasqzt.eu
www.facebook.com.iokasqzy.eu
www.facebook.com.ioooliob.eu
www.facebook.com.iooolioc.eu
www.facebook.com.iooolioe.eu
www.facebook.com.ioooliog.eu
www.facebook.com.iooolioq.eu
www.facebook.com.iooolior.eu
www.facebook.com.iooolios.eu
www.facebook.com.ioooliot.eu
www.facebook.com.ioooliov.eu
www.facebook.com.ioooliow.eu
www.facebook.com.ioooliox.eu
www.facebook.com.iooolioy.eu
www.facebook.com.lef1asza.eu
www.facebook.com.lefassza.eu
www.facebook.com.lefaszab.eu
www.facebook.com.lefaszac.eu
www.facebook.com.lefaszad.eu
www.facebook.com.lefaszak.eu
www.facebook.com.lefaszam.eu
www.facebook.com.lefaszan.eu
www.facebook.com.lefaszav.eu
www.facebook.com.lefaszax.eu
www.facebook.com.lefaszxa.eu
www.facebook.com.lefawsza.eu
www.facebook.com.lllujiob.eu
www.facebook.com.lllujioc.eu
www.facebook.com.lllujiod.eu
www.facebook.com.lllujiof.eu
www.facebook.com.lllujiog.eu
www.facebook.com.lllujioh.eu
www.facebook.com.lllujioi.eu
www.facebook.com.lllujioj.eu
www.facebook.com.lllujion.eu
www.facebook.com.lllujiot.eu
www.facebook.com.lllujiov.eu
www.facebook.com.lllujiox.eu
www.facebook.com.lllujioy.eu
www.facebook.com.lllujioz.eu
www.facebook.com.mibbbad.co.uk
www.facebook.com.mibbbad.me.uk
www.facebook.com.mibbbad.org.uk
www.facebook.com.mibbbah.co.uk
www.facebook.com.mibbbah.me.uk
www.facebook.com.mibbbah.org.uk
www.facebook.com.mibbbal.co.uk
www.facebook.com.mibbbal.me.uk
www.facebook.com.oooeasec.eu
www.facebook.com.oooeasef.eu
www.facebook.com.oooeaseg.eu
www.facebook.com.poresawa.eu
www.facebook.com.poresawd.eu
www.facebook.com.poresawe.eu
www.facebook.com.poresawg.eu
www.facebook.com.poresawj.eu
www.facebook.com.poresawo.eu
www.facebook.com.poresawq.eu
www.facebook.com.poresaws.eu
www.facebook.com.poresawt.eu
www.facebook.com.poresawu.eu
www.facebook.com.poresawv.eu
www.facebook.com.poresawx.eu
www.facebook.com.qqqqasc.eu
www.facebook.com.qqqqasd.eu
www.facebook.com.qqqqasf.eu
www.facebook.com.qqqqasg.eu
www.facebook.com.qqqqash.eu
www.facebook.com.qqqqasj.eu
www.facebook.com.qqqqask.eu
www.facebook.com.qqqqasl.eu
www.facebook.com.qqqqaso.eu
www.facebook.com.qqqqasr.eu
www.facebook.com.qqqqasy.eu
www.facebook.com.saaasaj.eu
www.facebook.com.saaasak.eu
www.facebook.com.saaasam.eu
www.facebook.com.saaasav.eu
www.facebook.com.saaasay.eu
www.facebook.com.saxzask.co.uk
www.facebook.com.saxzask.me.uk
www.facebook.com.saxzask.org.uk
www.facebook.com.saxzasl.co.uk
www.facebook.com.saxzasl.me.uk
www.facebook.com.saxzasl.org.uk
www.facebook.com.saxzasv.co.uk
www.facebook.com.saxzasv.me.uk
www.facebook.com.saxzasv.org.uk
www.facebook.com.saxzasy.co.uk
www.facebook.com.sazzawe.co.uk
www.facebook.com.sazzawe.eu
www.facebook.com.sazzawe.me.uk
www.facebook.com.sazzawf.co.uk
www.facebook.com.sazzawf.eu
www.facebook.com.sazzawf.me.uk
www.facebook.com.sazzawk.co.uk
www.facebook.com.sazzawk.eu
www.facebook.com.sazzawk.me.uk
www.facebook.com.sazzawl.co.uk
www.facebook.com.sazzawl.eu
www.facebook.com.sazzawl.me.uk
www.facebook.com.sazzawy.co.uk
www.facebook.com.sazzawy.eu
www.facebook.com.sazzawy.me.uk
www.facebook.com.ttteraa.eu
www.facebook.com.ttterab.eu
www.facebook.com.ttterac.eu
www.facebook.com.ttterad.eu
www.facebook.com.ttterae.eu
www.facebook.com.ttteraf.eu
www.facebook.com.ttterag.eu
www.facebook.com.ttteran.eu
www.facebook.com.ttteraq.eu
www.facebook.com.ttterav.eu
www.facebook.com.ttterax.eu
www.facebook.com.ttteraz.eu
www.facebook.com.ujtqwaq1.co.uk
www.facebook.com.ujtqwaq1.eu
www.facebook.com.ujtqwaq1.me.uk
www.facebook.com.ujtqwaq1.org.uk
www.facebook.com.ujtqwaqb.co.uk
www.facebook.com.ujtqwaqb.eu
www.facebook.com.ujtqwaqb.me.uk
www.facebook.com.ujtqwaqb.org.uk
www.facebook.com.ujtqwaqk.co.uk
www.facebook.com.ujtqwaqk.eu
www.facebook.com.ujtqwaqk.me.uk
www.facebook.com.ujtqwaqk.org.uk
www.facebook.com.ujtqwaqm.co.uk
www.facebook.com.ujtqwaqm.eu
www.facebook.com.ujtqwaqm.org.uk
www.facebook.com.ujtqwaqo.co.uk
www.facebook.com.ujtqwaqo.eu
www.facebook.com.ujtqwaqo.me.uk
www.facebook.com.ujtqwaqo.org.uk
www.facebook.com.xxxasqwa.eu
www.facebook.com.xxxasqwe.eu
www.facebook.com.xxxasqwi.eu
www.facebook.com.xxxasqwk.eu
www.facebook.com.xxxasqwl.eu
www.facebook.com.xxxasqwo.eu
www.facebook.com.xxxasqwp.eu
www.facebook.com.xxxasqwr.eu
www.facebook.com.xxxasqwt.eu
www.facebook.com.xxxasqwu.eu
www.facebook.com.xxxasqwy.eu
www.facebook.com.xxxasqwz.eu
www.facebook.com.yhheaszb.eu
www.facebook.com.yhheaszc.eu
www.facebook.com.yhheasze.eu
www.facebook.com.yhheaszf.eu
www.facebook.com.yhheaszh.eu
www.facebook.com.yhheaszi.eu
www.facebook.com.yhheaszq.eu
www.facebook.com.yhheaszu.eu
www.facebook.com.yhheaszv.eu
www.facebook.com.yhheaszy.eu
www.facebook.com.yy1azsva.eu
www.facebook.com.yy1azsvc.eu
www.facebook.com.yy1azsvq.eu
www.facebook.com.yy1azsvz.eu
www.facebook.com.yyy1asvf.eu
www.facebook.com.yyy1azsy.eu
www.facebook.com.yyy1azvg.eu
www.facebook.com.yyy1zsve.eu
www.facebook.com.yyyaszai.eu
www.facebook.com.yyyaszal.eu
www.facebook.com.yyyaszao.eu
www.facebook.com.yyyaszap.eu
www.facebook.com.yyyaszaq.eu
www.facebook.com.yyyaszar.eu
www.facebook.com.yyyaszau.eu
www.facebook.com.yyyaszay.eu
www.facebook.com.yyyazsvd.eu
www.facebook.com.zaaaasaa.eu
www.facebook.com.zaaaasag.eu
www.facebook.com.zaaaasaq.eu
www.facebook.com.zaaaasaz.eu
Email ThisBlogThis!Share to XShare to Facebook
Posted in phishing, spam, zbot | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Aggrevated Identity Theft Law in Action
    There are so many interesting angles to the story this week about a case in Tucson, Arizona. The conviction actually went down in March 200...
  • More Merger Malware Wachovia Wells Fargo
    Today I received a message from Robert K. Steel, the President and CEO of Wachovia Bank. Actually I received several hundred messages from ...
  • Italian Court declares itself Friend of Pirates (or does it?)
    I couldn't believe this one. The Associated Press reported yesterday that Italian high court says file-swapping is not illegal . In this...
  • AffPower Indictments Scare Affiliates!
    Today I heard the news that the "AffPower" drug network is being shut down, starting with 18 arrests in Texas, Florida, Colorado, ...
  • Bank of America Demo Account - DO NOT CLICK
    Beginning on November 25th, the UAB Spam Data Mine has been receiving messages claiming to be from Bank of America which will explain to us ...
  • Radical Muslim Hackers Declare CyberWar on Israel
    This weekend more than 300 Israeli websites have been defaced in a period of 48 hours. In a website "defacement" a hacker violate...
  • Securing Cyberspace in the 44th Presidency: Part Two
    Yesterday I provided some context for the Center for Strategic and International Studies report which was published yesterday: Security Cyb...
  • Dear CEO . . . You are Commanded to Go Phishing!
    This week has been busy with yet another Spear Phishing campaign being launched against the Execs of US-based companies. This is not a new ...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ▼  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ▼  October (16)
      • Facebook Safety & Million Member Facebook Groups
      • FACEBOOK PHISH! Users Beware!
      • Fake FDIC spam campaign spreads Zeus malware
      • FBI and SOCA make a media splash at RSA Europe
      • Phishing For Love: Banking Insiders
      • TowerNet CapitalOne: Avalanche returns after 15 mo...
      • Zipped Malware Attachments in Spam: Here comes Con...
      • Hacked Newspaper loads Google News with malware sites
      • Targeted URLs in spam . . .OWA Settings update
      • IRS Zeus via Geocities
      • A weekend of Old News
      • The FBI's Biggest Domestic Phishing Bust Ever
      • Microsoft "Your e-mail will be blocked" phish
      • A Day in the Life of Spam
      • Cyber Security Awareness Month: Day Two
      • Cyber Security Awareness Month: Day One
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile