Be on the Alert
I am seeing a large amount of spam hit our network that has been successful at fooling our spam filter. The
emails contain .zip and .html extensions with various file names. The subject also varies. Some subjects
that I have seen are:
Your Funds Will Be Transferred
From Jan RIchter (name varies)
Newest Products
Latest Software
The zip file is being analyzed to determine what payload may be involved. You may want to remind your email
users to refrain from opening any attachments that they weren't expecting to receive.
UPDATE: We have received some information from one of our readers that the zip file that he received contained
a multiple exploit-kit downloader. He indicated that there are over 120,000 successful downloads of the exe file.
They have discovered that IP address 173. 204. 119 . 122 is where the file appears to be hosted at and is being
updated with new binaries consistently. The downloader appears to grab a few files with random file names and
have been observed connecting too imagehut4 .cn, allxt .com, hitinto .com. Jason indicates that all files appear
to run fully under Windows VMWARE and are resistant to detection by many of the common threat programs.
Many thanks to Jason for supplying us with the information.
We also have received a report of emails that are hitting which tell the recipient that they letter cannot be opened
due to low screen resolution. It says that they need to open the attached zip file for the message. Again the filename
for the zip file varies. Thanks to Jason R for this information.
Deb Hale Long Lines, LLC
Comments
Attachments contain link to Trojan.Malscript!html
Viral
Jonathan
Jul 15th 2010
1 decade ago
Nathan
Jul 15th 2010
1 decade ago
Jim
Jul 15th 2010
1 decade ago
Jon
Jul 15th 2010
1 decade ago
Mike
Jul 15th 2010
1 decade ago
- http://www.symantec.com/connect/blogs/spammers-harvesting-high-gear
July 15, 2010 - "... observed a dramatic increase in the directory harvest attack (DHA) method. There was a staggering -15- times increase in DHA attacks during the first week of July 2010 when compared to the same period in June 2010. The spike was observed in the second week of June and is still rife..."
It -will- take some time for SPAM blockers and AV to catch up with this...
.
PC.Tech
Jul 15th 2010
1 decade ago
There are lots of MTA configuration options that will slow down DHAs. It's not up to the spam blocker or AV to handle that part.
If it is a botnet attack as the Symantec analysis suggests, then simply implementing the Spamhaus Zen DNSBL at SMTP time would likely keep it from having any effect on you.
John Hardin
Jul 15th 2010
1 decade ago
We reverted to quarantining .htm/.html based attachments into a select quarantine and reviewing manually. The
BigFatDonkey
Jul 15th 2010
1 decade ago
http://sanesecurity.co.uk/index.htm
Sanesecurity
Jul 16th 2010
1 decade ago