 DennisPremium,Mod join:2001-01-26 Algonquin, IL kudos:4 Reviews:
·AT&T U-Verse Host: Chicago Users find Hot Deals Users find Hot Dea.. Requests for Hot D.. Home Improvement
2 edits | [Phish] email from CDC "personal vaccination profile"Anybody else see this junk? Just got two of them within a minute....wonder how many people it will fool. quote: .
You have received this e-mail because of the launching of State Vaccination H1N1 Program. You need to create your personal H1N1 (swine flu) Vaccination Profile on the cdc.gov website. The Vaccination is not obligatory, but every person that has reached the age of 18 has to have his personal Vaccination Profile on the cdc.gov site. This profile has to be created both for the vaccinated people and the not-vaccinated ones. This profile is used for the registering system of vaccinated and not-vaccinated people.
Create your Personal H1N1 Vaccination Profile using the link:
http://online.cdc.gov.nyugewn.be/h1n1flu/profile.php?&session_id=99590321188358936408690441704006503511632965498306089994694&email=redacted@aol.com
Create Personal Profile
Centers for Disease Control and Prevention (CDC) · 1600 Clifton Rd · Atlanta GA 30333 · 800-CDC-INFO (800-232-4636)
headers if anyone cares
quote: Return-Path: X-Original-To: homes@dennisjudd.com Delivered-To: djudd@blackraven.com Received: from h081217115121.dyn.cm.kabsi.at (h081217115121.dyn.cm.kabsi.at [81.217.115.121]) by blackraven.com (Postfix) with ESMTP id 2C5F696B56 for ; Tue, 1 Dec 2009 10:10:29 -0600 (CST) Message-ID: From: "Centers for Disease Control and Prevention" To: Subject: Instructions on creation of your personal Vaccination Profile Date: Tue, 1 Dec 2009 17:10:14 +0100 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0007_01CA72A0.C43C2410" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.2180 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
Gonna have to go fire up the unix box to see what that site tries to do..... -- My Blog. Because I desperately need the acknowledgement of others.
Visit the Judd Family website to see my kids! |
|
 SYNACKJust Firewall ItPremium,Mod join:2001-03-05 Venice, CA | Well, it wants you to download a vaccination report, which is an executable.
Probably no phish, but malware. |
|
 psafuxPremium,VIP join:2005-11-10 kudos:2 | reply to Dennis Firefox has the site flagged.
If you go to the site, you will see:
Your Personal H1N1 Vaccinating Profile is an electronic document, which contains your name, your contact details and your medical data (what kind of illnesses you have sustained in your childhood or what kind of allergy you have to some certain drug). All instructions you need are included in the archive below:
The file is:
"http://DO NOT DOWNLOAD THIS FILE/h1n1flu/vacc_profile.exe" -- Yes. the cat in my avatar is indeed mine. |
|
 DennisPremium,Mod join:2001-01-26 Algonquin, IL kudos:4 Reviews:
·AT&T U-Verse Host: Chicago Users find Hot Deals Users find Hot Dea.. Requests for Hot D.. Home Improvement
| reply to Dennis
yeah just finished checking it out....got delayed with somebody stopping by my desk. |
|
 | reply to Dennis Yes, I received this email as well. I fell for it and got a virus. DO NOT CLICK ON THIS LINK!! |
|
 Doctor FourMy other vehicle is a TARDISPremium join:2000-09-05 Dallas, TX | reply to Dennis Has anyone downloaded the executable on this and submitted it to VirusTotal or Jotti? I would be curious to see what malware it is and how well it is detected by the 40 major AV apps.
Although if I were to guess, my first one would be the Zeus/zBot trojan. -- "The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
|
|
 MGDPremium,MVM join:2002-07-31 Fort Lauderdale, FL kudos:9 | reply to Dennis Less than a 10% current detection rate on the Virus Total submit:»www.virustotal.com/analisis/be45···59688624
Appears to be a fresh version of a banking infostealer / backdoor/ keylogger.
MGD |
|
 Doctor FourMy other vehicle is a TARDISPremium join:2000-09-05 Dallas, TX 1 edit | Interesting: AntiVir (Avira - not the fake AV that uses the same name) is one of those less than 10% that detects this one. I knew there was a good reason for switching to it. -- "The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
|
|
 nwrickertsand groperPremium,MVM join:2004-09-04 Geneva, IL kudos:7 Reviews:
·AT&T U-Verse
| reply to Dennis There are currently two of those "phish" on phishtracker. They come from the rock phishers. They try to run a Windows executable "vacc_profile.exe" and at present AV detection of this is weak. See also »phish #42363 - malware alert -- AT&T Uverse; Zyxel NBG334W router (behind the 2wire gateway); openSuSE 11.0; firefox 3.0.15 |
|
 MGDPremium,MVM join:2002-07-31 Fort Lauderdale, FL kudos:9 | I see Phish submit 42363:»/phishtrack?pi···3&urls=1 is for the same NYUGEWN.BE fraud domain, while Phish submit 42364:»/phishtrack?pi···4&urls=1 is for a fraud domain YHNBAM.CO.IM
The fraudulently registered NYUGEWN.BE per ICANN regulations is eligible for immediate revocation:
=================================== Domain Name NYUGEWN.BE Status REGISTERED Registered December 1, 2009 Last update December 1, 2009 1:57 PM
Licensee Name: Tom McCarthy Organisation: Tom McCarthy
Language English
Address: 13895 Keiber Rd., 48838 Antwerp Belgium
Phone +32.7812713
Email rickys36246@hotmail.com
Agent technical contacts:
Name Active 24 ASA - Registry Department Organisation Active 24 ASA
Language English:
Address Pilestredet 75C P.O. box 5198 Majorstua N-0302 Oslo Norway Phone +47.21933000 Fax +47.21933001 Email registry[@]registry.active24.com
Agent Organisation Active 24 ASA
Website www.active24.be/ Nameservers
ns1.davies-estates.com ns1.pandachine.com =================================== File: registry[@]registry.active24.com & »www.dns.be/public/whois/FileComp···=nyugewn
The fraudulent registration listing as being in Antwerp, Belgium., belongs to this individual / business:
Outdoor Optic Shop
Tom McCarthy 13895 Keiber Rd. Greenville, Mi 48838 616-754-5530
»www.armedforcesjournal.com/black···irectory
Not sure if the owner's card data was used for payment.
The DNS servers domains are the best targets, since these phish viri spams are bot mailed, and bot hosted. Also likely to be fast flux dns.
MGD |
|
|
|
 MGDPremium,MVM join:2002-07-31 Fort Lauderdale, FL kudos:9 1 edit | reply to Dennis said by Dennis:Anybody else see this junk? Just got two of them within a minute....wonder how many people it will fool. Probably a lot, massive mailings, and the variable Subject lines:
VIRUS ALERT = Subject: Creation of personal Vaccination Profile = VIRUS ALERT
VIRUS ALERT = Subject: State Vaccination Program = VIRUS ALERT
VIRUS ALERT = Subject: Instructions on creation of your personal Vaccination Profile = VIRUS ALERT
VIRUS ALERT = Subject: Creation of your personal Vaccination Profile = VIRUS ALERT
will catch a lot of victims. Look for a huge increase in the RBN's US based botnet, and financial fraud.
========================= whois.nic.im
Domain Name: YHNBAM.CO.IM
Expiry Date: 02/12/2010 00:59:59
Domain Managers Name: Tom McCarthy Address 13895 Keiber Rd 48838 United States Domain Owners / Registrant Name: Tom McCarthy Address 13895 Keiber Rd 48838 United States
Name Server: ns1.a-personalhire.com. Name Server: ns1.shuzmen.com.
Registrant Search:"Tom McCarthy" owns about 78 other domains =========================
MGD |
|
 | reply to Dennis Infostealer.Banker.C according to SAV 10 defs 12/1/2009 rev24 |
|
 nwrickertsand groperPremium,MVM join:2004-09-04 Geneva, IL kudos:7 | That sounds right. It is apparently a new variant that few AVs are catching. |
|
 MGDPremium,MVM join:2002-07-31 Fort Lauderdale, FL kudos:9 | said by nwrickert:That sounds right. It is apparently a new variant that few AVs are catching. I submitted it to the Norman Sandbox for analysis:
vacc_profile.exe : Not detected by Sandbox (Signature: NO_VIRUS)
[ DetectionInfo ] * Filename: C:\analyzer\scan\vacc_profile.exe. * Sandbox name: NO_MALWARE * Signature name: NO_VIRUS. * Compressed: NO. * TLS hooks: NO. * Executable type: Application. * Executable file structure: OK. * Filetype: PE_I386.
[ General information ] * File length: 130560 bytes. * MD5 hash: e711a0227e4f9de1550fb6c194c77e30.
Also sent it to Sunbelt's sandox for analysis, waiting on reply.
MGD |
|
 hortnutHuh? join:2005-09-25 Somewhere Reviews:
·Comcast
·BCTelco
·Skype
| reply to Dennis No I have not, if I see anything like this - use the delete button.
OTOH - it is good for someone as yourself to see how this thing works - malware load? or social engineering? -- Darn, its gettin that time to go to Wallymart to gits me picture taken agin.
|
|
 DennisPremium,Mod join:2001-01-26 Algonquin, IL kudos:4 | reply to Dennis Dear god they just don't stop...I'm just constantly getting them (and submitting them to phish tracker). If this keeps up I'm gonna setup a rule in outlook. |
|
 MGDPremium,MVM join:2002-07-31 Fort Lauderdale, FL kudos:9 | Good post Dennis  I sent it over to Threat Expert's sandbox, this is vicious, lethal, and will do some serious damage, excellent analysis:






Registry modifications, changes deletions & additions. Appears that safe boot and restore may not be partial recovery options.
 ThreatExpert···Mods.txt 22318 bytes

=============================== There were registered attempts to establish connection with the remote hosts.
The connection details are:
Remote Host Port Number 193.104.41.75 80 97.74.144.118 80
The data identified by the following URLs was then requested from the remote web server(s):
>http://193.104.41.75/cbd/75.bro >http://193.104.41.75/kissme/rec.php >http://promed-net.com/css/absderce2.exe >http://193.104.41.75/ip.php ===============================
Ref:»www.threatexpert.com/report.aspx···94c77e30
MGD |
|
 TSI GabePremium,VIP join:2007-01-03 Chatham, ON kudos:2 | My desktop doesn't even know what the heck an "EXE" is, so no big deal there  |
|
 MGDPremium,MVM join:2002-07-31 Fort Lauderdale, FL kudos:9 1 edit | reply to nwrickert said by nwrickert:There are currently two of those "phish" on phishtracker. They come from the rock phishers. They try to run a Windows executable "vacc_profile.exe" and at present AV detection of this is weak. See also » phish #42363 - malware alert Indeed, classic RBN rockphish traits. Four of the names servers in use for the above two domains:
ns1.davies-estates.com ns1.pandachine.com ns1.a-personalhire.com ns1.shuzmen.com
Since this is US targeted it is common for them to have at least one IP per dns domain hosted in the US.
a-personalhire.com is also used in conjunction with ns1.poolandmonster.com in another Zbot campaign which involves another 13 Belgian Domains in addition to the known nyugewn.be. Classic Rockphish style:
hssaze.be = VIRUS & FRAUD DOMAIN hssazg.be = VIRUS & FRAUD DOMAIN hssazh.be = VIRUS & FRAUD DOMAIN hssazi.be = VIRUS & FRAUD DOMAIN hssazj.be = VIRUS & FRAUD DOMAIN hssazl.be = VIRUS & FRAUD DOMAIN hssazo.be = VIRUS & FRAUD DOMAIN hssazp.be = VIRUS & FRAUD DOMAIN hssazq.be = VIRUS & FRAUD DOMAIN hssazr.be = VIRUS & FRAUD DOMAIN hssazt.be = VIRUS & FRAUD DOMAIN hssazw.be = VIRUS & FRAUD DOMAIN hssazy.be= VIRUS & FRAUD DOMAIN
»www.malwareurl.com/ns_listing.ph···hire.com
Obviously a major planned operation, someone's bot net and bank card / login database was close to "E".
MGD |
|
 | reply to Dennis We got 10 of these within 20 minutes in 3 different email boxes. Our boss (Luddite) almost clicked on his. |
|