<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malc0de &#187; Spam</title>
	<atom:link href="http://www.blog.malc0de.com/category/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blog.malc0de.com</link>
	<description></description>
	<lastBuildDate>Tue, 23 Mar 2010 01:25:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Fake UPS spam distributes Trojan Bredolab</title>
		<link>http://www.blog.malc0de.com/2010/01/12/fake-ups-spam-distributes-trojan-bredolab/</link>
		<comments>http://www.blog.malc0de.com/2010/01/12/fake-ups-spam-distributes-trojan-bredolab/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 04:15:51 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[bredolab]]></category>
		<category><![CDATA[fake UPS spam]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=591</guid>
		<description><![CDATA[Early December I wrote about a fake DHL spam campaign which was found to be distributing Trojan Bredolab. The new spam campaign is very similar to the last but this time appears to be from UPS. Example Subject: UPS Tracking Number 5845190 &#8220;Hello! The courier company was not able to deliver your parcel by your address. ]]></description>
			<content:encoded><![CDATA[<p>Early December I wrote about a <a href="http://www.blog.malc0de.com/2009/12/17/fake-dhl-spam-distributes-bredolab/">fake DHL spam campaign </a>which was found to be distributing Trojan Bredolab. The new spam campaign is very similar to the last but this time appears to be from UPS.</p>
<p>Example</p>
<p><strong>Subject: UPS Tracking Number 5845190</strong></p>
<p><strong><em>&#8220;Hello!<br />
The courier company was not able to deliver your parcel by your address.<br />
Cause: Error in shipping address.</em></strong></p>
<p><strong><em>You may pickup the parcel at our post office personaly!</em></strong></p>
<p><strong><em>Please attention!<br />
The shipping label is attached to this e-mail.<br />
Please print this label to get this package at our post office.</em></strong></p>
<p><strong><em>Please do not reply to this e-mail, it is an unmonitored mailbox.</em></strong></p>
<p><strong><em>Thank you.<br />
United Parcel Service of America.</em></strong></p>
<p><strong><strong>[attachment UPS_invoice_NR12944.zip"</strong></strong></p>
<p><strong><span style="font-weight: normal;">VirusTotal results for the attachment can be found </span><a href="http://www.virustotal.com/analisis/fb61286b4f1c926786949e79af1302d0bf3b445166cacf3f7d75ad7b6dd608ff-1263332647"><span style="font-weight: normal;">here</span></a><span style="font-weight: normal;">. Domains known to be  contacted by Trojan </span><a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Search.aspx?query=Bredolab"><span style="font-weight: normal;">Bredolab</span></a><span style="font-weight: normal;"> listed below.</span></p>
<p><span style="font-weight: normal;">20091217:http://mmsfoundsystem.ru, 193.104.12.20<br />
20091227:http://preflopp.com, 95.211.8.170<br />
20100105:http://greatmoder.cn, 122.115.63.19<br />
20100108:http://213.108.56.125, 213.108.56.125</span></p>
<p></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2010/01/12/fake-ups-spam-distributes-trojan-bredolab/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Fake DHL Spam Distributes Bredolab</title>
		<link>http://www.blog.malc0de.com/2009/12/17/fake-dhl-spam-distributes-bredolab/</link>
		<comments>http://www.blog.malc0de.com/2009/12/17/fake-dhl-spam-distributes-bredolab/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 20:20:09 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[bredolab]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=570</guid>
		<description><![CDATA[Watch out for the fake DHL emails claiming your item wasn&#8217;t shipped. e.g. &#8220;Hello! The courier company was not able to deliver your parcel by your address. Cause: Error in shipping address. You may pickup the parcel at our post office personaly. Please attention! The shipping label is attached to this e-mail. Print this label ]]></description>
			<content:encoded><![CDATA[<p>Watch out for the fake DHL emails claiming your item wasn&#8217;t shipped.</p>
<p>e.g.</p>
<p><em>&#8220;Hello!</p>
<p>The courier company was not able to deliver your parcel by your address.<br />
Cause: Error in shipping address.</p>
<p>You may pickup the parcel at our post office personaly.</p>
<p>Please attention!<br />
The shipping label is attached to this e-mail.<br />
Print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox!</p>
<p>Thank you,<br />
DHL Services.</em>&#8221;</p>
<p>The email contains the following attachment </p>
<p>&#8220;DHL_Office_Get_Your_Parcel_NR.4957.zip&#8221;</p>
<p>Which is detected as TrojanDownloader:Win32/Bredolab.AB.  Win32/Bredolab is a downloader which is able to download and execute arbitrary files from a remote host. Additional information can be found <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32/Bredolab">here</a> Currently this sample is detected by  27 out of 41 <a href="http://www.virustotal.com/analisis/a9b7b3eca1fc69154093a0ae15d8b528f5b7e89e4dc7d660f979ece7068ea405-1261079478"> antivirus vendors</a>. </p>
<p>List of Bredolab drop sites being used. </p>
<p>20091201:hxxp://greatmoder.cn, 125.65.110.46<br />
20091201:hxxp://greatmoder.cn, 125.65.110.46<br />
20091201:hxxp://statcount.cn, 218.93.205.228<br />
20091201:hxxp://statcount.cn, 218.93.205.228<br />
20091202:hxxp://greatmoder.cn, 125.65.110.46<br />
20091202:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091203:hxxp://greatmoder.cn, 125.65.110.46<br />
20091203:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091204:hxxp://greatmoder.cn, 125.65.110.46<br />
20091204:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091205:hxxp://greatmoder.cn, 125.65.110.46<br />
20091205:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091205:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091206:hxxp://91.213.126.93, 91.213.126.93<br />
20091206:hxxp://greatmoder.cn, 125.65.110.46<br />
20091206:hxxp://greatmoder.cn, 125.65.110.46<br />
20091206:hxxp://greatmoder.cn, 125.65.110.46<br />
20091206:hxxp://greatmoder.cn, 125.65.110.46<br />
20091206:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091206:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091207:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091207:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091207:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091208:hxxp://mmsfoundsystem.ru, 193.104.12.20<br />
20091208:hxxp://mmsfoundsystem.ru, 193.104.12.20<br />
20091208:hxxp://mmsfoundsystem.ru/, 193.104.12.20<br />
20091208:hxxp://mmsfoundsystem.ru, 193.104.12.20<br />
20091217:hxxp://mmsfoundsystem.ru, 193.104.12.20</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2009/12/17/fake-dhl-spam-distributes-bredolab/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>List of Zeus/Zbot Command and Control Servers</title>
		<link>http://www.blog.malc0de.com/2009/12/16/list-of-zeuszbot-command-and-control-servers/</link>
		<comments>http://www.blog.malc0de.com/2009/12/16/list-of-zeuszbot-command-and-control-servers/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 04:26:14 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[C&C servers]]></category>
		<category><![CDATA[Zbot]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=546</guid>
		<description><![CDATA[Over the past few months there has been a number of ongoing spam campaigns that have been distributing Zeus/Zbot. You might have read about a few of them or you may have fallen victim. A good source of information regarding the zbot/zeus spam campaigns can be found here. When Zbot/Zeus is executed it will drop ]]></description>
			<content:encoded><![CDATA[<p>Over the past few months there has been a number of ongoing spam campaigns that have been distributing Zeus/Zbot. You might have read about a few of them or you may have fallen victim. A good source of information regarding the zbot/zeus spam campaigns can be found <a href="http://garwarner.blogspot.com/search/label/zbot">here</a>.</p>
<p>When Zbot/Zeus is executed it will drop a copy of itself in the system folder (c:/windows/system32). It also modifies the registry in order to execute each time Windows starts. Examples of which registry keys are added/modified can be found <a href="http://www.threatexpert.com/report.aspx?md5=74af2ba42786b3cb4d1a6b038219334d">here</a></p>
<p>The bot uses covert methods of injecting additional fields into online Internet banking websites, asking users to answer questions that the authentic website would not ask. This information is then forwarded to a remote database silently in the background with the victim never realizing what happened.  The image below is a graphical representation that gives you an idea how this works.</p>
<div id="attachment_549" class="wp-caption aligncenter" style="width: 510px"><img class="size-full wp-image-549 " title="bankjet" src="http://www.blog.malc0de.com/wp-content/uploads/2009/12/bankjet.gif" alt="Example of injected HTML" width="500" height="611" /><p class="wp-caption-text">Example of injected HTML</p></div>
<p>Zbot/Zeus sends information and receives instructions by contacting specific IP&#8217;s that are hardcoded into the binary. From the samples I have seen the following file names are being used by zbot/zeus to phone home.</p>
<p>/rec.php<br />
/ip.php<br />
/config.bin<br />
/cfg.bin<br />
/cfg2.bin</p>
<p>Searching the malware database I maintain reveals a list of C&amp;C servers geographically dispersed around the globe. The list of domains/IP&#8217;s is rather large so I just consolidated into a text file that can be found <a href="http://malc0de.com/images/zbot_cc_servers.txt">here</a>. Converting the IP addresses to latitude and longitude generate the red dots on the map below which represent the C&amp;C servers.</p>
<p style="text-align: center;"><img class="aligncenter" title="Zeus C&amp;C Servers " src="http://malc0de.com/images/zeus2.jpg" alt="" width="500" height="345" /></p>
<p>An updated list of domains distributing Zeus/Zbot can be found at the following link: <a href="http://malc0de.com/database/index.php?search=bot.exe"> malc0de.com Zbot Domains</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2009/12/16/list-of-zeuszbot-command-and-control-servers/feed/</wfw:commentRss>
		<slash:comments>1694</slash:comments>
		</item>
		<item>
		<title>promed-net[dot]com acting as malware distribution point</title>
		<link>http://www.blog.malc0de.com/2009/12/01/promed-netdotcom-acting-as-a-malware-distribution-point/</link>
		<comments>http://www.blog.malc0de.com/2009/12/01/promed-netdotcom-acting-as-a-malware-distribution-point/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 05:23:44 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=533</guid>
		<description><![CDATA[The domain promed-net[dot]com which is currently registered/hosted with Go-Daddy has been acting as a malware distribution point for at least the past 30 days.  Malware such as Win32.Krap.ah and Trojan:Win32/Hiloti.genA. I&#8217;ve also seen this domain participating in several of the many ongoing Trojan Zeus/Zbot Spam campaigns. The latest being Fake CDC emails claiming you need to set up ]]></description>
			<content:encoded><![CDATA[<p>The domain promed-net[dot]com which is currently registered/hosted with Go-Daddy has been acting as a malware distribution point for at least the past 30 days.  Malware such as Win32.Krap.ah and Trojan:Win32/Hiloti.genA. I&#8217;ve also seen this domain participating in several of the many ongoing Trojan Zeus/Zbot Spam campaigns. The latest being Fake CDC emails claiming you need to set up a H1N1 profile.</p>
<p>Example</p>
<p><em>&#8220;You need to create your personal H1N1 (swine flu) Vaccination Profile on the cdc.gov website. The Vaccination is not obligatory, but every person that has reached the age of 18 has to have his personal Vaccination Profile on the cdc.gov site. This profile has to be created both for the vaccinated people and the not-vaccinated ones. This profile is used for the registering system of vaccinated and not-vaccinated people&#8221;</em></p>
<p>If you happen to click the link you now have the notorious <a href="http://www.virustotal.com/analisis/4f1a5551a5fec27950ad99b6c63d568c7c712577121e6b1aa4cdf1ec7549c227-1259689175">Trojan Zbot</a> installed on your system which will then contact promed-net[dot]com to install additional malware. One example can be seen in this <a href="http://www.threatexpert.com/report.aspx?md5=5767b2c6d84d87a47d12da03f4f376ad">ThreatExpert</a> report. More information can be found <a href="http://malc0de.com/tools/db.php?search=promed-net.com">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2009/12/01/promed-netdotcom-acting-as-a-malware-distribution-point/feed/</wfw:commentRss>
		<slash:comments>202</slash:comments>
		</item>
		<item>
		<title>Fake Verizon Wireless Spam Distributes Trojan.Sasfis</title>
		<link>http://www.blog.malc0de.com/2009/11/18/fake-verizon-wireless-emails-distributes-trojan-sasfis/</link>
		<comments>http://www.blog.malc0de.com/2009/11/18/fake-verizon-wireless-emails-distributes-trojan-sasfis/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 02:35:15 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[fake verizon spam]]></category>
		<category><![CDATA[Trojan.Sasfis]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=524</guid>
		<description><![CDATA[A fake Verizon Wireless email with the subject &#8220;Your credit balance is over its limit&#8221; is currently making rounds. Dear Verizon Wireless customer, Your credit balance is over its limit. Please use the attached Verizon Wireless Balance Checker Tool to review and analyze your payments. Yours sincerely, Verizon Wireless Customer Services The email contains an ]]></description>
			<content:encoded><![CDATA[<p>A fake Verizon Wireless email with the subject &#8220;Your credit balance is over its limit&#8221; is currently making rounds.</p>
<p><em>Dear Verizon Wireless customer,</em></p>
<p><em> </em></p>
<p><em>Your credit balance is over its limit. Please use the attached Verizon Wireless Balance Checker Tool to review and analyze your payments.</em></p>
<p><em>Yours sincerely,<br />
Verizon Wireless Customer Services</em></p>
<p>The email contains an attachment called &#8220;balancechecker.zip&#8221; which is really Trojan Sasfis/Oficla. If executed Sasfis will run silently in the background and download and install additional malware.</p>
<p><a href="http://www.virustotal.com/analisis/c98767c0a51b0ca83d1708beb89f03296394f11f4fd17fc93f3b6d6fbf1686a9-1258535039">http://www.virustotal.com/analisis/c98767c0a51b0ca83d1708beb89f03296394f11f4fd17fc93f3b6d6fbf1686a9-1258535039</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2009/11/18/fake-verizon-wireless-emails-distributes-trojan-sasfis/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Fake IRS sites distribute Zbot Variants</title>
		<link>http://www.blog.malc0de.com/2009/10/01/fake-irs-sites-distributes-zbot/</link>
		<comments>http://www.blog.malc0de.com/2009/10/01/fake-irs-sites-distributes-zbot/#comments</comments>
		<pubDate>Fri, 02 Oct 2009 02:08:40 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[fake irs websites]]></category>
		<category><![CDATA[tax-statement.exe]]></category>
		<category><![CDATA[trojan zbot]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=443</guid>
		<description><![CDATA[The distribution of Zbot continues, this time by a file called tax-statement.exe and domains named (irs.gov.fedas1ao.com, irs.gov.y11derd.com, irs.gov.juhh1wo.com). Its unclear what the initial vector is however given the way the domains and file name have been crafted its likely related to spam. All the domains being used so far and the dates they were first ]]></description>
			<content:encoded><![CDATA[<p>The distribution of Zbot continues, this time by a file called tax-statement.exe and domains named (irs.gov.fedas1ao.com, irs.gov.y11derd.com, irs.gov.juhh1wo.com). Its unclear what the initial vector is however given the way the domains and file name have been crafted its likely related to spam. All the domains being used so far and the dates they were first seen can be found <a href="http://malc0de.com/tools/db.php?search=tax-statement.exe">here</a>.</p>
<p>Upon execution of tax-statement.exe the following changes will be made to the registry.</p>
<p>HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}<br />
	HKEY_USERS\.DEFAULT\Software\Microsoft\Protected Storage System Provider</p>
<p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network]<br />
        UID = &#8220;%ComputerName%_0002DE7F&#8221;</p>
<p>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}]</p>
<p>	{3039636B-5F3D-6C64-6675-696870667265} = F7 09 F2 0D<br />
	{33373039-3132-3864-6B30-303233343434} = 47 09 F2 0D</p>
<p>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]<br />
	ProxyEnable = 0&#215;00000000</p>
<p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]<br />
        Userinit =</p>
<p>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]<br />
        Cookies =<br />
        History =</p>
<p>From a network  perspective the following GET requests are generated</p>
<p>http://195.93.208.18/lcc/ip.gif</p>
<p>http://195.93.208.18/ip.php</p>
<p><em><strong>Threat characteristics of ZBot</strong> &#8211;  banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system.</em></ul>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2009/10/01/fake-irs-sites-distributes-zbot/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

