Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 27 January 2010

Minipost: VISA Zeus

Posted on 20:08 by Unknown
This is not the first time we've seen a Zeus dropper acting like a VISA phish . . . recently we've had the December 21st VISA and December 12th VISA campaigns. The emails are the same as the previous campaigns.

We've seen these 53 domain names so far today in the UAB Spam Data Mine:

ewasza.co.uk
ewasza.me.uk
ewasze.co.uk
ewasze.me.uk
ewaszi.co.uk
ewaszi.me.uk
ewaszu.co.uk
ewaszu.me.uk
ewaszy.co.uk
ewaszy.me.uk
freeimagesonly.be
freeimagesonly.com
freeimagesonly.co.uk
freeimagesonly.mobi
freeimagesonly.org.uk
gyueeerd.com.vc
gyueeerd.vc
gyueeerf.com.vc
gyueeerf.vc
gyueeerh.com.vc
gyueeerh.vc
gyueeers.com.vc
gyueeers.vc
gyueeeru.com.vc
gyueeeru.vc
iurseda.com.vc
iurseda.vc
iursedq.com.vc
iursedq.vc
iursedz.com.vc
iursedz.vc
medirams.com
norytiod.com.vc
norytiod.vc
norytioq.com.vc
norytioq.vc
norytior.com.vc
norytior.vc
norytiox.com.vc
norytiox.vc
sucipa.com.vc
sucipa.vc
sucipe.com.vc
sucipe.vc
sucipy.com.vc
sucipy.vc
suecond.co.nz
suecond.co.uk
suecond.eu
suecond.me.uk
sueconu.co.uk
sueconu.eu
sueconu.me.uk

They are used in an assortment of hostnames, including:

alerts.cforms.visa.com.suecond.co.nz
reports.cforms.visa.com.suecond.co.nz
statements.cforms.visa.com.suecond.co.nz
transactions.cforms.visa.com.suecond.co.nz

as well as a variety of patterns with random numbers in the middle, such as:

sessionid-1870Y9B7BZNSQB.cforms.visa.com.ewasza.co.uk
sessionid2SW8J2XJQ.cforms.visa.com.ewasza.co.uk
sessionid3PO2C59V.cforms.visa.com.ewasza.co.uk
sessionid-3U5UEDLI878OCD4.cforms.visa.com.ewasza.co.uk
sessionid-601GIB7UW4CW.cforms.visa.com.ewasza.co.uk
sessionid_73IG9LU216.cforms.visa.com.ewasza.co.uk
sessionid_78SEOF26UCWD3.cforms.visa.com.ewasza.co.uk
sessionid-I5AE0X91LP66P.cforms.visa.com.ewasza.co.uk
sessionid_ILRG2PA40.cforms.visa.com.ewasza.co.uk
sessionidLQEGFJMSS.cforms.visa.com.ewasza.co.uk
sessionid-OP5GMS06SF.cforms.visa.com.ewasza.co.uk
sessionid_OW0EZ0Z.cforms.visa.com.ewasza.co.uk
sessionid-SHTSQ7233OL.cforms.visa.com.ewasza.co.uk
sessionid_U3KJ7Q52MC.cforms.visa.com.ewasza.co.uk
sessionidVWMOE6307CRKXRM.cforms.visa.com.ewasza.co.uk

As usual, these are "Fast Flux" hosted, meaning that, for example, all of these IP addresses have been seen to resolve the domains today . . .

8.14.250.36
24.139.170.130
24.139.199.193
24.55.191.38
41.189.44.33
58.146.223.113
58.146.235.41
58.158.42.57
59.93.102.244
59.93.116.1
59.94.211.34
60.53.195.222
61.247.96.83
61.72.140.57
69.79.96.70
79.183.200.23
84.228.139.23
87.70.85.15
89.218.192.196
94.54.201.43
94.54.3.54
95.104.39.180
95.58.109.118
110.55.15.138
111.119.182.165
112.201.100.237
112.201.126.156
112.201.254.20
112.202.136.44
112.206.169.131
114.142.215.195
114.185.93.52
114.186.197.236
114.186.241.236
114.24.3.17
115.177.129.136
115.184.170.220
115.184.239.50
116.197.79.227
116.50.154.197
116.81.48.121
116.83.35.207
118.33.211.102
118.91.2.149
119.95.213.128
121.138.176.86
121.161.251.25
122.50.143.42
123.231.61.142
125.138.245.199
183.87.51.133
186.24.114.43
186.28.215.77
186.28.69.106
186.97.24.122
187.56.67.100
188.129.234.181
188.56.4.214
189.110.149.105
189.179.10.150
189.179.12.169
189.179.12.229
189.179.12.26
189.18.101.190
189.192.66.18
189.192.7.75
189.192.77.236
189.193.229.197
189.193.43.4
189.194.133.9
189.194.204.77
189.194.204.79
189.194.208.236
189.194.213.203
189.231.5.193
190.0.134.221
190.140.29.142
190.142.57.30
190.16.136.134
190.160.226.227
190.213.161.169
190.213.161.225
190.245.121.41
190.25.63.8
190.26.176.197
190.26.50.164
190.27.40.1
190.32.78.27
190.34.46.168
190.39.129.16
190.64.7.89
194.54.36.6
200.112.81.253
200.112.92.60
200.126.69.238
200.169.71.144
200.66.45.15
200.92.200.202
200.95.250.127
201.13.55.17
201.132.143.149
201.132.6.179
201.139.142.208
201.153.96.80
201.227.129.238
201.231.205.87
201.232.142.97
201.26.127.10
201.43.140.52
202.69.171.135
210.93.54.46
211.201.216.148
211.255.29.30
218.164.0.237
219.169.208.98
219.52.84.57

(More complete list of machines:

alerts.cforms.visa.com.suecond.co.nz
reports.cforms.visa.com.suecond.co.nz
statements.cforms.visa.com.suecond.co.nz
transactions.cforms.visa.com.suecond.co.nz
alerts.cforms.visa.com.ewasza.co.uk
reports.cforms.visa.com.ewasza.co.uk
statements.cforms.visa.com.ewasza.co.uk
transactions.cforms.visa.com.ewasza.co.uk
alerts.cforms.visa.com.ewasze.co.uk
reports.cforms.visa.com.ewasze.co.uk
statements.cforms.visa.com.ewasze.co.uk
transactions.cforms.visa.com.ewasze.co.uk
alerts.cforms.visa.com.ewaszi.co.uk
reports.cforms.visa.com.ewaszi.co.uk
statements.cforms.visa.com.ewaszi.co.uk
transactions.cforms.visa.com.ewaszi.co.uk
alerts.cforms.visa.com.ewaszu.co.uk
reports.cforms.visa.com.ewaszu.co.uk
statements.cforms.visa.com.ewaszu.co.uk
transactions.cforms.visa.com.ewaszu.co.uk
alerts.cforms.visa.com.ewaszy.co.uk
reports.cforms.visa.com.ewaszy.co.uk
statements.cforms.visa.com.ewaszy.co.uk
transactions.cforms.visa.com.ewaszy.co.uk
alerts.cforms.visa.com.freeimagesonly.co.uk
reports.cforms.visa.com.freeimagesonly.co.uk
statements.cforms.visa.com.freeimagesonly.co.uk
transactions.cforms.visa.com.freeimagesonly.co.uk
alerts.cforms.visa.com.suecond.co.uk
reports.cforms.visa.com.suecond.co.uk
statements.cforms.visa.com.suecond.co.uk
transactions.cforms.visa.com.suecond.co.uk
alerts.cforms.visa.com.sueconu.co.uk
reports.cforms.visa.com.sueconu.co.uk
statements.cforms.visa.com.sueconu.co.uk
transactions.cforms.visa.com.sueconu.co.uk
alerts.cforms.visa.com.ewasza.me.uk
reports.cforms.visa.com.ewasza.me.uk
statements.cforms.visa.com.ewasza.me.uk
transactions.cforms.visa.com.ewasza.me.uk
alerts.cforms.visa.com.ewasze.me.uk
reports.cforms.visa.com.ewasze.me.uk
statements.cforms.visa.com.ewasze.me.uk
transactions.cforms.visa.com.ewasze.me.uk
alerts.cforms.visa.com.ewaszi.me.uk
reports.cforms.visa.com.ewaszi.me.uk
statements.cforms.visa.com.ewaszi.me.uk
transactions.cforms.visa.com.ewaszi.me.uk
alerts.cforms.visa.com.ewaszu.me.uk
reports.cforms.visa.com.ewaszu.me.uk
statements.cforms.visa.com.ewaszu.me.uk
transactions.cforms.visa.com.ewaszu.me.uk
alerts.cforms.visa.com.ewaszy.me.uk
reports.cforms.visa.com.ewaszy.me.uk
statements.cforms.visa.com.ewaszy.me.uk
transactions.cforms.visa.com.ewaszy.me.uk
alerts.cforms.visa.com.suecond.me.uk
reports.cforms.visa.com.suecond.me.uk
statements.cforms.visa.com.suecond.me.uk
transactions.cforms.visa.com.suecond.me.uk
alerts.cforms.visa.com.sueconu.me.uk
reports.cforms.visa.com.sueconu.me.uk
statements.cforms.visa.com.sueconu.me.uk
transactions.cforms.visa.com.sueconu.me.uk
alerts.cforms.visa.com.freeimagesonly.org.uk
reports.cforms.visa.com.freeimagesonly.org.uk
statements.cforms.visa.com.freeimagesonly.org.uk
transactions.cforms.visa.com.freeimagesonly.org.uk
alerts.cforms.visa.com.gyueeerd.com.vc
reports.cforms.visa.com.gyueeerd.com.vc
statements.cforms.visa.com.gyueeerd.com.vc
transactions.cforms.visa.com.gyueeerd.com.vc
alerts.cforms.visa.com.gyueeerf.com.vc
reports.cforms.visa.com.gyueeerf.com.vc
statements.cforms.visa.com.gyueeerf.com.vc
transactions.cforms.visa.com.gyueeerf.com.vc
alerts.cforms.visa.com.gyueeerh.com.vc
reports.cforms.visa.com.gyueeerh.com.vc
statements.cforms.visa.com.gyueeerh.com.vc
transactions.cforms.visa.com.gyueeerh.com.vc
alerts.cforms.visa.com.gyueeers.com.vc
reports.cforms.visa.com.gyueeers.com.vc
statements.cforms.visa.com.gyueeers.com.vc
transactions.cforms.visa.com.gyueeers.com.vc
alerts.cforms.visa.com.gyueeeru.com.vc
reports.cforms.visa.com.gyueeeru.com.vc
statements.cforms.visa.com.gyueeeru.com.vc
transactions.cforms.visa.com.gyueeeru.com.vc
alerts.cforms.visa.com.iurseda.com.vc
reports.cforms.visa.com.iurseda.com.vc
statements.cforms.visa.com.iurseda.com.vc
transactions.cforms.visa.com.iurseda.com.vc
alerts.cforms.visa.com.iursedq.com.vc
reports.cforms.visa.com.iursedq.com.vc
statements.cforms.visa.com.iursedq.com.vc
transactions.cforms.visa.com.iursedq.com.vc
alerts.cforms.visa.com.iursedz.com.vc
reports.cforms.visa.com.iursedz.com.vc
statements.cforms.visa.com.iursedz.com.vc
transactions.cforms.visa.com.iursedz.com.vc
alerts.cforms.visa.com.norytiod.com.vc
reports.cforms.visa.com.norytiod.com.vc
statements.cforms.visa.com.norytiod.com.vc
transactions.cforms.visa.com.norytiod.com.vc
alerts.cforms.visa.com.norytioq.com.vc
reports.cforms.visa.com.norytioq.com.vc
statements.cforms.visa.com.norytioq.com.vc
transactions.cforms.visa.com.norytioq.com.vc
alerts.cforms.visa.com.norytior.com.vc
reports.cforms.visa.com.norytior.com.vc
statements.cforms.visa.com.norytior.com.vc
transactions.cforms.visa.com.norytior.com.vc
alerts.cforms.visa.com.norytiox.com.vc
reports.cforms.visa.com.norytiox.com.vc
statements.cforms.visa.com.norytiox.com.vc
transactions.cforms.visa.com.norytiox.com.vc
alerts.cforms.visa.com.sucipa.com.vc
reports.cforms.visa.com.sucipa.com.vc
statements.cforms.visa.com.sucipa.com.vc
transactions.cforms.visa.com.sucipa.com.vc
alerts.cforms.visa.com.sucipe.com.vc
reports.cforms.visa.com.sucipe.com.vc
statements.cforms.visa.com.sucipe.com.vc
transactions.cforms.visa.com.sucipe.com.vc
alerts.cforms.visa.com.sucipy.com.vc
reports.cforms.visa.com.sucipy.com.vc
statements.cforms.visa.com.sucipy.com.vc
transactions.cforms.visa.com.sucipy.com.vc
alerts.cforms.visa.com.freeimagesonly.be
reports.cforms.visa.com.freeimagesonly.be
statements.cforms.visa.com.freeimagesonly.be
transactions.cforms.visa.com.freeimagesonly.be
alerts.cforms.visa.com.freeimagesonly.com
reports.cforms.visa.com.freeimagesonly.com
statements.cforms.visa.com.freeimagesonly.com
transactions.cforms.visa.com.freeimagesonly.com
alerts.cforms.visa.com.medirams.com
reports.cforms.visa.com.medirams.com
statements.cforms.visa.com.medirams.com
transactions.cforms.visa.com.medirams.com
alerts.cforms.visa.com.suecond.eu
reports.cforms.visa.com.suecond.eu
statements.cforms.visa.com.suecond.eu
transactions.cforms.visa.com.suecond.eu
alerts.cforms.visa.com.sueconu.eu
reports.cforms.visa.com.sueconu.eu
statements.cforms.visa.com.sueconu.eu
transactions.cforms.visa.com.sueconu.eu
alerts.cforms.visa.com.freeimagesonly.mobi
reports.cforms.visa.com.freeimagesonly.mobi
statements.cforms.visa.com.freeimagesonly.mobi
transactions.cforms.visa.com.freeimagesonly.mobi
alerts.cforms.visa.com.gyueeerd.vc
reports.cforms.visa.com.gyueeerd.vc
statements.cforms.visa.com.gyueeerd.vc
transactions.cforms.visa.com.gyueeerd.vc
alerts.cforms.visa.com.gyueeerf.vc
reports.cforms.visa.com.gyueeerf.vc
statements.cforms.visa.com.gyueeerf.vc
transactions.cforms.visa.com.gyueeerf.vc
alerts.cforms.visa.com.gyueeerh.vc
reports.cforms.visa.com.gyueeerh.vc
statements.cforms.visa.com.gyueeerh.vc
transactions.cforms.visa.com.gyueeerh.vc
alerts.cforms.visa.com.gyueeers.vc
reports.cforms.visa.com.gyueeers.vc
statements.cforms.visa.com.gyueeers.vc
transactions.cforms.visa.com.gyueeers.vc
alerts.cforms.visa.com.gyueeeru.vc
reports.cforms.visa.com.gyueeeru.vc
statements.cforms.visa.com.gyueeeru.vc
transactions.cforms.visa.com.gyueeeru.vc
alerts.cforms.visa.com.iurseda.vc
reports.cforms.visa.com.iurseda.vc
statements.cforms.visa.com.iurseda.vc
transactions.cforms.visa.com.iurseda.vc
alerts.cforms.visa.com.iursedq.vc
reports.cforms.visa.com.iursedq.vc
statements.cforms.visa.com.iursedq.vc
transactions.cforms.visa.com.iursedq.vc
alerts.cforms.visa.com.iursedz.vc
reports.cforms.visa.com.iursedz.vc
statements.cforms.visa.com.iursedz.vc
transactions.cforms.visa.com.iursedz.vc
alerts.cforms.visa.com.norytiod.vc
reports.cforms.visa.com.norytiod.vc
statements.cforms.visa.com.norytiod.vc
transactions.cforms.visa.com.norytiod.vc
alerts.cforms.visa.com.norytioq.vc
reports.cforms.visa.com.norytioq.vc
statements.cforms.visa.com.norytioq.vc
transactions.cforms.visa.com.norytioq.vc
alerts.cforms.visa.com.norytior.vc
reports.cforms.visa.com.norytior.vc
statements.cforms.visa.com.norytior.vc
transactions.cforms.visa.com.norytior.vc
alerts.cforms.visa.com.norytiox.vc
reports.cforms.visa.com.norytiox.vc
statements.cforms.visa.com.norytiox.vc
transactions.cforms.visa.com.norytiox.vc
alerts.cforms.visa.com.sucipa.vc
reports.cforms.visa.com.sucipa.vc
statements.cforms.visa.com.sucipa.vc
transactions.cforms.visa.com.sucipa.vc
alerts.cforms.visa.com.sucipe.vc
reports.cforms.visa.com.sucipe.vc
statements.cforms.visa.com.sucipe.vc
transactions.cforms.visa.com.sucipe.vc
alerts.cforms.visa.com.sucipy.vc
reports.cforms.visa.com.sucipy.vc
statements.cforms.visa.com.sucipy.vc
transactions.cforms.visa.com.sucipy.vc


Email ThisBlogThis!Share to XShare to Facebook
Posted in zbot | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Stop the Rumors: Quit SMSing about WalMart Gang Initiations
    My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • What about the Social Security Numbers? (The Utah Data Breach and your SSN)
    The Utah Data Breach This week the continuing saga of the Utah Medicaid Data Breach continued to unfold. If you haven't been following...
  • Computer Virus masquerades as Obama Acceptance Speech Video
    Less than twelve hours after President-Elect Obama's historic acceptance speech, computer criminals have already crafted a malware attac...
  • Work at Home . . . for a Criminal?
    How do you tell if a "Work at Home" invitation is a scam? Here's a clue: It comes in your email. In today's Blog, I tho...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ▼  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ▼  January (7)
      • Minipost: VISA Zeus
      • American Bankers Association version of Zeus Bot /...
      • AOL Update spreads Zeus / Zbot
      • Sendspace Zbot spreader a Flashback to Dec 15-20
      • USAA Bank latest Avalanche Scam
      • Minipost: #CNIRcyberwar ? ? ?
      • Iranian Cyber Army returns - target: Baidu.com
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile