Hello, received this via mail
Source:
VT
https://www.virustotal.com/file/c6c97b4 ... 358070390/ > 15/46
Download malwares, i have not the material to debug them but names seem explicit enought.
Pony panel:
socks: https://www.virustotal.com/file/f76dc9f ... 358072530/ > 14/46
sti: https://www.virustotal.com/file/4453c83 ... 358072532/ > 20/46
spambot activity:
clickfraud activity:
• dns: 1 ›› ip: 151.1.24.232 - adresse: RESIDENCEMORESCO.COM
• dns: 1 ›› ip: 119.59.120.14 - adresse: OMYEEM.COM
• dns: 1 ›› ip: 195.182.210.221 - adresse: EGENERATION.IT
Server are probably compromised and egeneration.it/css/ residencemoresco.com/ita/ lead on Keitaro.
Found via bruteforce:
https://www.virustotal.com/file/c2d9c35 ... 358075568/ > 5/46
Seem Malekal wrote on this http://www.malekal.com/2013/01/09/spam- ... ucher-zip/
Different mail different domains, same file.
Source:
Code: Select all
x-store-info:fHNTDlzCF8Nxw6HwcfGQy+S7Ax/lqLSmNphQ3OF+T9E=
Authentication-Results: hotmail.com; spf=fail (sender IP is 81.176.66.76) smtp.mailfrom=tracking@ups.com; dkim=none header.d=ups.com; x-hmca=fail
X-SID-PRA: tracking@ups.com
X-AUTH-Result: FAIL
X-SID-Result: FAIL
X-Message-Status: n:n
X-Message-Delivery: Vj0xLjE7dXM9MDtsPTE7YT0wO0Q9MjtHRD0yO1NDTD02
X-Message-Info: 5cuOr7VrmjBwCXgOIB2nrvf4ZaCDc222MVL8F3m6AMtRnltspNEVQWHYtcWTSj+UT+9KXsUkBqSTqplqKpA4sTv87aOz/cGlvTMMvZaSXEPIaYjBvAExCELI8m9TvsVDEEphW5MkxxfjSVDnujHN3WptbUPViMmd
Received: from hgc.hostingcenter.ru ([81.176.66.76]) by BAY0-MC1-F12.Bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900);
Sun, 13 Jan 2013 01:13:41 -0800
Received: from Unknown (p54BF5C74.dip.t-dialin.net [84.191.92.116])
by hgc.hostingcenter.ru (Postfix) with ESMTPA id AEEFB215C9
for <phoenixbytes@live.fr>; Sun, 13 Jan 2013 13:13:39 +0400 (MSK)
Message-ID: <29E42DE23C724658A3C75DB3876F36E7@qavl>
From: "UPS" <tracking@ups.com>
To: <phoenixbytes@live.fr>
Subject: Delivery Ivnoice
Date: Sun, 13 Jan 2013 03:13:27 -0600
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_034B_01CDF13B.F47364A0"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.5931
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.6109
Return-Path: tracking@ups.com
X-OriginalArrivalTime: 13 Jan 2013 09:13:41.0624 (UTC) FILETIME=[47C28780:01CDF16E]
This is a multi-part message in MIME format.
------=_NextPart_000_034B_01CDF13B.F47364A0
Content-Type: text/plain;
charset="windows-1251"
Content-Transfer-Encoding: quoted-printable
Delivery Information
Tracking number : http://valentinastocchi.com/tracking.ups.com/Z [Trac=
k this delivery]
Number of packages : 1
UPS Service : Express
Weight : 1508202732183583.0
=20
=20
Please note that in case of a failure to contact your local UPS offic=
e within 21 days the parcel will be returned to sender.
------=_NextPart_000_034B_01CDF13B.F47364A0
Content-Type: text/html;
charset="windows-1251"
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>UPS Service</TITLE>
<META content=3D"text/html; charset=3Dwindows-1251" http-equiv=3DContent-=
Type>
<META name=3DGENERATOR content=3D"MSHTML 8.00.6001.19154">
<BODY>
<DIV><IMG border=3D0 hspace=3D0 alt=3D""=20
src=3D"http://upsstore.5302078.attractionsbook.com/parse/image.php?image_=
id=3D94093"=20
width=3D744 height=3D210></DIV>
<DIV> <FONT size=3D6><STRONG> Delivery=20
Information</STRONG></FONT></DIV>
<DIV> </DIV>
<DIV><FONT size=3D5> Tracking number : <A=20
href=3D"http://valentinastocchi.com/tracking.ups.com/">Z1508202732183583=20
[Track this delivery]</A></FONT></DIV>
<DIV><FONT size=3D5></FONT> </DIV>
<DIV><FONT size=3D5> Number of packages : 1</FONT></DIV>
<DIV><FONT size=3D5></FONT> </DIV>
<DIV><FONT size=3D5> UPS Service : Express</FONT></DIV>
<DIV><FONT size=3D5></FONT> </DIV>
<DIV><FONT size=3D5> Weight :=20
0.4</FONT><BR> </DIV>
<DIV> </DIV>
<DIV> </DIV>
<DIV> </DIV>
<DIV> Please note that in case of a failure to contact =
your=20
local UPS office within 21 days the parcel will be returned to sender.</D=
IV>
<DIV></DIV></BODY></HTML>
------=_NextPart_000_034B_01CDF13B.F47364A0--
VT
https://www.virustotal.com/file/c6c97b4 ... 358070390/ > 15/46
Download malwares, i have not the material to debug them but names seem explicit enought.
Code: Select all
socks.exe load a driver: https://www.virustotal.com/file/e0b193d ... 358078288/ > 40/46www.residencemoresco.com/ita/hermes.exe
www.residencemoresco.com/ita/sti.exe
egeneration.it/css/socks.exe
egeneration.it/css/hermes.exe
omyeem.com/plugins/socks.exe <- spambot
omyeem.com/plugins/sti.exe
173.236.100.226/~italiang/JavaJREinstaller_KB62519857.exe <- Pony
Pony panel:
Code: Select all
hermes: https://www.virustotal.com/file/3332731 ... 358072526/ > 21/46http://95.170.86.85/pony/admin.php
fail: http://95.170.86.85/pony/setup.php
socks: https://www.virustotal.com/file/f76dc9f ... 358072530/ > 14/46
sti: https://www.virustotal.com/file/4453c83 ... 358072532/ > 20/46
spambot activity:
clickfraud activity:
• dns: 1 ›› ip: 151.1.24.232 - adresse: RESIDENCEMORESCO.COM
• dns: 1 ›› ip: 119.59.120.14 - adresse: OMYEEM.COM
• dns: 1 ›› ip: 195.182.210.221 - adresse: EGENERATION.IT
Server are probably compromised and egeneration.it/css/ residencemoresco.com/ita/ lead on Keitaro.
Found via bruteforce:
https://www.virustotal.com/file/c2d9c35 ... 358075568/ > 5/46
Code: Select all
And
http://omyeem.com/plugins/564.exe
Code: Select all
Same file as JavaJREinstaller_KB62519857.exehttp://www.residencemoresco.com:80/ita/pony.exe
Seem Malekal wrote on this http://www.malekal.com/2013/01/09/spam- ... ucher-zip/
Different mail different domains, same file.
Code: Select all
gouter-matrimonial.be/tracking.ups.com
hotel-alhambra.fr/tracking.ups.com
• dns: 1 ›› ip: 213.186.33.19 - adresse: GOUTER-MATRIMONIAL.BE
• dns: 1 ›› ip: 87.106.155.90 - adresse: HOTEL-ALHAMBRA.FR
Attachments
infected
(155.98 KiB) Downloaded 89 times
(155.98 KiB) Downloaded 89 times
infected
(614.67 KiB) Downloaded 95 times
(614.67 KiB) Downloaded 95 times