Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 14 October 2009

Targeted URLs in spam . . .OWA Settings update

Posted on 16:40 by Unknown
All of our trap domains are seeing a new spam campaign today where the website being spammed actually SEEMS to be the email recipient's own domain.

The webpage claims to be a new Microsoft Outlook Web Access update.

Sample email:


Dear user of the mydomain.com mailing service!

We are informing you that because of the security upgrade of the mailing service your mailbox (mymail@mydomain.com) settings were changed. In order to apply the new set of settings click on the following link:

http://mydomains.com/owa/service_directory/settings.php?email=mymail@mydomain.com&from=mydomain.com&fromname=mymail

Best regards, mydomain.com Technical Support


The email subjects which have been used have been:

A new settings for for the mymail@mydomain.com mailbox has just been released
For the owner of the mymail@mydomain.com mailbox
The settings for the mymail@mydomain.com mailbox were changed

In this entire post, remember that where "mymail@mydomain.com" will be replaced by the actual email recipient's userid and domain name.

The websites look like this:



Of course the link is a new version of the Zeus / Zbot trojan.

http://mydomain.com.bertdffe.co.uk/owa/service_directory/settings.php
http://mydomain.com.bertdffe.eu/owa/service_directory/settings.php
http://mydomain.com.bertdffm.co.uk/owa/service_directory/settings.php
http://mydomain.com.bertdffm.eu/owa/service_directory/settings.php
http://mydomain.com.bertdffo.eu/owa/service_directory/settings.php
http://mydomain.com.bertdffw.co.uk/owa/service_directory/settings.php
http://mydomain.com.bertdffw.eu/owa/service_directory/settings.php
http://mydomain.com.nerrasssb.eu/owa/service_directory/settings.php
http://mydomain.com.nerrassso.eu/owa/service_directory/settings.php
http://mydomain.com.nerrasssp.co.uk/owa/service_directory/settings.php
http://mydomain.com.nerrasssp.eu/owa/service_directory/settings.php
http://mydomain.com.nerrassst.co.uk/owa/service_directory/settings.php
http://mydomain.com.nerrassst.eu/owa/service_directory/settings.php
http://mydomain.com.nerrasssu.co.uk/owa/service_directory/settings.php
http://mydomain.com.nerrasssu.eu/owa/service_directory/settings.php
http://mydomain.com.nerrasssw.co.uk/owa/service_directory/settings.php
http://mydomain.com.nerrasssw.eu/owa/service_directory/settings.php
http://mydomain.com.nerrasssx.co.uk/owa/service_directory/settings.php
http://mydomain.com.nerrasssx.eu/owa/service_directory/settings.php
http://mydomain.com.nerrasssy.co.uk/owa/service_directory/settings.php
http://mydomain.com.nerrasssy.eu/owa/service_directory/settings.php
http://mydomain.com.oikkkkua.co.uk/owa/service_directory/settings.php
http://mydomain.com.oikkkkua.eu/owa/service_directory/settings.php
http://mydomain.com.oikkkkuf.co.uk/owa/service_directory/settings.php
http://mydomain.com.oikkkkuf.eu/owa/service_directory/settings.php
http://mydomain.com.oikkkkuh.co.uk/owa/service_directory/settings.php
http://mydomain.com.oikkkkuh.eu/owa/service_directory/settings.php
http://mydomain.com.oikkkkuy.co.uk/owa/service_directory/settings.php
http://mydomain.com.oikkkkuy.eu/owa/service_directory/settings.php
http://mydomain.com.polikka.eu/owa/service_directory/settings.php
http://mydomain.com.polikki.co.uk/owa/service_directory/settings.php
http://mydomain.com.polikki.eu/owa/service_directory/settings.php
http://mydomain.com.polikko.co.uk/owa/service_directory/settings.php
http://mydomain.com.polikko.eu/owa/service_directory/settings.php
http://mydomain.com.polikkp.co.uk/owa/service_directory/settings.php
http://mydomain.com.polikkp.eu/owa/service_directory/settings.php
http://mydomain.com.wsasdec.eu/owa/service_directory/settings.php
http://mydomain.com.wsasdep.co.uk/owa/service_directory/settings.php
http://mydomain.com.wsasdep.eu/owa/service_directory/settings.php
http://mydomain.com.wsasder.co.uk/owa/service_directory/settings.php
http://mydomain.com.wsasder.eu/owa/service_directory/settings.php
http://mydomain.com.wsasdev.co.uk/owa/service_directory/settings.php
http://mydomain.com.wsasdev.eu/owa/service_directory/settings.php
http://mydomain.com.wsasdez.co.uk/owa/service_directory/settings.php
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • More Merger Malware Wachovia Wells Fargo
    Today I received a message from Robert K. Steel, the President and CEO of Wachovia Bank. Actually I received several hundred messages from ...
  • Radical Muslim Hackers Declare CyberWar on Israel
    This weekend more than 300 Israeli websites have been defaced in a period of 48 hours. In a website "defacement" a hacker violate...
  • Aggrevated Identity Theft Law in Action
    There are so many interesting angles to the story this week about a case in Tucson, Arizona. The conviction actually went down in March 200...
  • Bank of America Demo Account - DO NOT CLICK
    Beginning on November 25th, the UAB Spam Data Mine has been receiving messages claiming to be from Bank of America which will explain to us ...
  • AffPower Indictments Scare Affiliates!
    Today I heard the news that the "AffPower" drug network is being shut down, starting with 18 arrests in Texas, Florida, Colorado, ...
  • Securing Cyberspace in the 44th Presidency: Part Two
    Yesterday I provided some context for the Center for Strategic and International Studies report which was published yesterday: Security Cyb...
  • Italian Court declares itself Friend of Pirates (or does it?)
    I couldn't believe this one. The Associated Press reported yesterday that Italian high court says file-swapping is not illegal . In this...
  • Internet Landfill: McColo Corporation
    Brian Krebs has turned his sights on another Internet Landfill, this time the McColo Corporation. Today his column is titled: Major Source...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ▼  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ▼  October (16)
      • Facebook Safety & Million Member Facebook Groups
      • FACEBOOK PHISH! Users Beware!
      • Fake FDIC spam campaign spreads Zeus malware
      • FBI and SOCA make a media splash at RSA Europe
      • Phishing For Love: Banking Insiders
      • TowerNet CapitalOne: Avalanche returns after 15 mo...
      • Zipped Malware Attachments in Spam: Here comes Con...
      • Hacked Newspaper loads Google News with malware sites
      • Targeted URLs in spam . . .OWA Settings update
      • IRS Zeus via Geocities
      • A weekend of Old News
      • The FBI's Biggest Domestic Phishing Bust Ever
      • Microsoft "Your e-mail will be blocked" phish
      • A Day in the Life of Spam
      • Cyber Security Awareness Month: Day Two
      • Cyber Security Awareness Month: Day One
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile