site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
4643
Share Topic
Posting?
Post a:
Post a:
Links: ·Phish Tracker ·Anti-Phishing Work Group ·Avoid Phishing
page: 1 · 2
AuthorAll Replies


Dennis
Premium,Mod
join:2001-01-26
Algonquin, IL
kudos:4
Reviews:
·AT&T U-Verse
Host:
Chicago
Users find Hot Deals
Users find Hot Dea..
Requests for Hot D..
Home Improvement

2 edits

[Phish] email from CDC "personal vaccination profile"

Anybody else see this junk? Just got two of them within a minute....wonder how many people it will fool.
quote:
.

You have received this e-mail because of the launching of State Vaccination H1N1 Program.
You need to create your personal H1N1 (swine flu) Vaccination Profile on the cdc.gov website. The Vaccination is not obligatory, but every person that has reached the age of 18 has to have his personal Vaccination Profile on the cdc.gov site. This profile has to be created both for the vaccinated people and the not-vaccinated ones. This profile is used for the registering system of vaccinated and not-vaccinated people.

Create your Personal H1N1 Vaccination Profile using the link:
http://online.cdc.gov.nyugewn.be/h1n1flu/profile.php?&session_id=99590321188358936408690441704006503511632965498306089994694&email=redacted@aol.com 
 
Create Personal Profile



Centers for Disease Control and Prevention (CDC) · 1600 Clifton Rd · Atlanta GA 30333 · 800-CDC-INFO (800-232-4636)


headers if anyone cares

quote:
Return-Path:
X-Original-To: homes@dennisjudd.com
Delivered-To: djudd@blackraven.com
Received: from h081217115121.dyn.cm.kabsi.at (h081217115121.dyn.cm.kabsi.at [81.217.115.121])
by blackraven.com (Postfix) with ESMTP id 2C5F696B56
for ; Tue, 1 Dec 2009 10:10:29 -0600 (CST)
Message-ID:
From: "Centers for Disease Control and Prevention"
To:
Subject: Instructions on creation of your personal Vaccination Profile
Date: Tue, 1 Dec 2009 17:10:14 +0100
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0007_01CA72A0.C43C2410"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180


Gonna have to go fire up the unix box to see what that site tries to do.....
--
My Blog. Because I desperately need the acknowledgement of others.

Visit the Judd Family website to see my kids!


SYNACK
Just Firewall It
Premium,Mod
join:2001-03-05
Venice, CA

Well, it wants you to download a vaccination report, which is an executable.

Probably no phish, but malware.



psafux
Premium,VIP
join:2005-11-10
kudos:2

reply to Dennis
Firefox has the site flagged.

If you go to the site, you will see:

Your Personal H1N1 Vaccinating Profile is an electronic document, which contains your name, your contact details and your medical data (what kind of illnesses you have sustained in your childhood or what kind of allergy you have to some certain drug). All instructions you need are included in the archive below:

The file is:

"http://DO NOT DOWNLOAD THIS FILE/h1n1flu/vacc_profile.exe"
--
Yes. the cat in my avatar is indeed mine.



Dennis
Premium,Mod
join:2001-01-26
Algonquin, IL
kudos:4
Reviews:
·AT&T U-Verse
Host:
Chicago
Users find Hot Deals
Users find Hot Dea..
Requests for Hot D..
Home Improvement

reply to Dennis

Click for full size
yeah just finished checking it out....got delayed with somebody stopping by my desk.


srcd

@sbcglobal.net

reply to Dennis
Yes, I received this email as well. I fell for it and got a virus. DO NOT CLICK ON THIS LINK!!



Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX

reply to Dennis
Has anyone downloaded the executable on this and submitted it to VirusTotal or Jotti? I would be curious to see what malware it is and how well it is detected by the 40 major AV apps.

Although if I were to guess, my first one would be the Zeus/zBot trojan.
--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL
kudos:9

reply to Dennis
Less than a 10% current detection rate on the Virus Total submit:»www.virustotal.com/analisis/be45···59688624

Appears to be a fresh version of a banking infostealer / backdoor/ keylogger.

MGD



Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX

1 edit

said by MGD:

Less than a 10% current detection rate on the Virus Total submit:»www.virustotal.com/analisis/be45···59688624

Appears to be a fresh version of a banking infostealer / backdoor/ keylogger.

MGD
Interesting: AntiVir (Avira - not the fake AV that uses the same name) is one of those less than 10% that detects this one. I knew there was a good reason for switching to it.
--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7
Reviews:
·AT&T U-Verse

reply to Dennis
There are currently two of those "phish" on phishtracker. They come from the rock phishers. They try to run a Windows executable "vacc_profile.exe" and at present AV detection of this is weak. See also »phish #42363 - malware alert
--
AT&T Uverse; Zyxel NBG334W router (behind the 2wire gateway); openSuSE 11.0; firefox 3.0.15


MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL
kudos:9

I see Phish submit 42363:»/phishtrack?pi···3&urls=1 is for the same NYUGEWN.BE fraud domain, while Phish submit 42364:»/phishtrack?pi···4&urls=1 is for a fraud domain YHNBAM.CO.IM

The fraudulently registered NYUGEWN.BE per ICANN regulations is eligible for immediate revocation:

===================================
Domain Name NYUGEWN.BE
Status REGISTERED
Registered December 1, 2009
Last update December 1, 2009 1:57 PM

Licensee
Name: Tom McCarthy
Organisation: Tom McCarthy

Language English

Address: 13895 Keiber Rd.,
48838 Antwerp
Belgium

Phone +32.7812713

Email rickys36246@hotmail.com

Agent technical contacts:

Name Active 24 ASA - Registry Department
Organisation Active 24 ASA

Language English:

Address Pilestredet 75C
P.O. box 5198 Majorstua
N-0302 Oslo
Norway
Phone +47.21933000
Fax +47.21933001
Email registry[@]registry.active24.com

Agent
Organisation Active 24 ASA

Website www.active24.be/
Nameservers

ns1.davies-estates.com
ns1.pandachine.com
===================================
File: registry[@]registry.active24.com & »www.dns.be/public/whois/FileComp···=nyugewn

The fraudulent registration listing as being in Antwerp, Belgium., belongs to this individual / business:

Outdoor Optic Shop

Tom McCarthy
13895 Keiber Rd.
Greenville, Mi 48838
616-754-5530

»www.armedforcesjournal.com/black···irectory

Not sure if the owner's card data was used for payment.

The DNS servers domains are the best targets, since these phish viri spams are bot mailed, and bot hosted. Also likely to be fast flux dns.

MGD


MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL
kudos:9

1 edit

reply to Dennis

said by Dennis:

Anybody else see this junk? Just got two of them within a minute....wonder how many people it will fool.
Probably a lot, massive mailings, and the variable Subject lines:

VIRUS ALERT = Subject: Creation of personal Vaccination Profile = VIRUS ALERT

VIRUS ALERT = Subject: State Vaccination Program = VIRUS ALERT

VIRUS ALERT = Subject: Instructions on creation of your personal Vaccination Profile = VIRUS ALERT

VIRUS ALERT = Subject: Creation of your personal Vaccination Profile = VIRUS ALERT

will catch a lot of victims. Look for a huge increase in the RBN's US based botnet, and financial fraud.

=========================
whois.nic.im

Domain Name: YHNBAM.CO.IM

Expiry Date: 02/12/2010 00:59:59

Domain Managers
Name: Tom McCarthy
Address
13895 Keiber Rd
48838
United States
Domain Owners / Registrant
Name: Tom McCarthy
Address
13895 Keiber Rd
48838
United States

Name Server: ns1.a-personalhire.com.
Name Server: ns1.shuzmen.com.

Registrant Search:"Tom McCarthy" owns about 78 other domains
=========================

MGD


cowboyro

join:2000-10-11
Shelton, CT

reply to Dennis
Infostealer.Banker.C according to SAV 10 defs 12/1/2009 rev24



nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7

That sounds right. It is apparently a new variant that few AVs are catching.


MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL
kudos:9

said by nwrickert:

That sounds right. It is apparently a new variant that few AVs are catching.
I submitted it to the Norman Sandbox for analysis:

vacc_profile.exe : Not detected by Sandbox (Signature: NO_VIRUS)

[ DetectionInfo ]
* Filename: C:\analyzer\scan\vacc_profile.exe.
* Sandbox name: NO_MALWARE
* Signature name: NO_VIRUS.
* Compressed: NO.
* TLS hooks: NO.
* Executable type: Application.
* Executable file structure: OK.
* Filetype: PE_I386.

[ General information ]
* File length: 130560 bytes.
* MD5 hash: e711a0227e4f9de1550fb6c194c77e30.

Also sent it to Sunbelt's sandox for analysis, waiting on reply.

MGD


hortnut
Huh?

join:2005-09-25
Somewhere
Reviews:
·Comcast
·BCTelco
·Skype

reply to Dennis
No I have not, if I see anything like this - use the delete button.

OTOH - it is good for someone as yourself to see how this thing works - malware load? or social engineering?
--
Darn, its gettin that time to go to Wallymart to gits me picture taken agin.



Dennis
Premium,Mod
join:2001-01-26
Algonquin, IL
kudos:4

reply to Dennis
Dear god they just don't stop...I'm just constantly getting them (and submitting them to phish tracker). If this keeps up I'm gonna setup a rule in outlook.


MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL
kudos:9

Good post Dennis See Profile
I sent it over to Threat Expert's sandbox, this is vicious, lethal, and will do some serious damage, excellent analysis:









Registry modifications, changes deletions & additions. Appears that safe boot and restore may not be partial recovery options.
ThreatExpert···Mods.txt 22318 bytes



===============================
There were registered attempts to establish connection with the remote hosts.

The connection details are:

Remote Host Port Number
193.104.41.75 80
97.74.144.118 80

The data identified by the following URLs was then requested from the remote web server(s):

>http://193.104.41.75/cbd/75.bro
>http://193.104.41.75/kissme/rec.php
>http://promed-net.com/css/absderce2.exe
>http://193.104.41.75/ip.php
===============================

Ref:»www.threatexpert.com/report.aspx···94c77e30

MGD


TSI Gabe
Premium,VIP
join:2007-01-03
Chatham, ON
kudos:2

My desktop doesn't even know what the heck an "EXE" is, so no big deal there


MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL
kudos:9

1 edit

reply to nwrickert

said by nwrickert:

There are currently two of those "phish" on phishtracker. They come from the rock phishers. They try to run a Windows executable "vacc_profile.exe" and at present AV detection of this is weak. See also »phish #42363 - malware alert
Indeed, classic RBN rockphish traits. Four of the names servers in use for the above two domains:

ns1.davies-estates.com
ns1.pandachine.com
ns1.a-personalhire.com
ns1.shuzmen.com

Since this is US targeted it is common for them to have at least one IP per dns domain hosted in the US.

a-personalhire.com is also used in conjunction with ns1.poolandmonster.com in another Zbot campaign which involves another 13 Belgian Domains in addition to the known nyugewn.be. Classic Rockphish style:

hssaze.be = VIRUS & FRAUD DOMAIN
hssazg.be = VIRUS & FRAUD DOMAIN
hssazh.be = VIRUS & FRAUD DOMAIN
hssazi.be = VIRUS & FRAUD DOMAIN
hssazj.be = VIRUS & FRAUD DOMAIN
hssazl.be = VIRUS & FRAUD DOMAIN
hssazo.be = VIRUS & FRAUD DOMAIN
hssazp.be = VIRUS & FRAUD DOMAIN
hssazq.be = VIRUS & FRAUD DOMAIN
hssazr.be = VIRUS & FRAUD DOMAIN
hssazt.be = VIRUS & FRAUD DOMAIN
hssazw.be = VIRUS & FRAUD DOMAIN
hssazy.be= VIRUS & FRAUD DOMAIN

»www.malwareurl.com/ns_listing.ph···hire.com

Obviously a major planned operation, someone's bot net and bank card / login database was close to "E".

MGD

AnnaZed

join:2009-12-01
Pasadena, CA

reply to Dennis
We got 10 of these within 20 minutes in 3 different email boxes. Our boss (Luddite) almost clicked on his.


Saturday, 11-Feb 23:48:34 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online! © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics