Monday, November 09, 2009

Zeus Malware Moves to Myspace

Beginning about 90 minutes ago, the Zeus malware, also known as Zbot, began a new spam distribution campaign to infect more victims. The newest campaign follows the model of last week's Facebook UpdateTool, only now targeting MySpace users.

This update is pretty much in "Breaking News" mode at the moment, we haven't yet run the malware through the lab for a full analysis, but here's what we can tell you so far:

1. There are 30 recently created domains being used as targets in the spam messages. Here are the host names we've seen so far in spam messages:

accounts.myspace.com.deaaaf.co.uk
accounts.myspace.com.deaaaf.me.uk
accounts.myspace.com.deaaaf.org.uk
accounts.myspace.com.deaaag.me.uk
accounts.myspace.com.deaaag.org.uk
accounts.myspace.com.deaaas.me.uk
accounts.myspace.com.deaaas.org.uk
accounts.myspace.com.iiolii.co.uk
accounts.myspace.com.iiolii.me.uk
accounts.myspace.com.iiolii.org.uk
accounts.myspace.com.iiolik.co.uk
accounts.myspace.com.iiolik.me.uk
accounts.myspace.com.iiolik.org.uk
accounts.myspace.com.iiolio.co.uk
accounts.myspace.com.iiolio.me.uk
accounts.myspace.com.iiolio.org.uk
accounts.myspace.com.iioliu.co.uk
accounts.myspace.com.iioliu.me.uk
accounts.myspace.com.iioliu.org.uk
accounts.myspace.com.ttesza.co.uk
accounts.myspace.com.ttesza.org.uk
accounts.myspace.com.tteszf.co.uk
accounts.myspace.com.tteszf.me.uk
accounts.myspace.com.tteszf.org.uk
accounts.myspace.com.tteszg.co.uk
accounts.myspace.com.tteszg.me.uk
accounts.myspace.com.tteszg.org.uk
accounts.myspace.com.tteszk.co.uk
accounts.myspace.com.tteszk.me.uk
accounts.myspace.com.tteszk.org.uk

2. Spam messages are using a variety of subject lines, including:

message id #5332015152732 (note: each message has a random id #)
MySpace Account update
Please update your MySpace account
Update your MySpace account
You are required to update your MySpace account
Your MySpace account

3. The text of the email messages contains:

Dear MySpace user!

Please be informed that you are required to update your MySpace account.

Please update your MySpace account by clicking here:

http://accounts.myspace.com.iiolii.me.uk/msp/index.php?fuseaction=update&code=(random)&email=(email address)

If you're unable to click on the link above, copy and paste it into your browser's address bar.

-------------------------

At MySpace we care about your privacy. This email is never sent unsolicited.

If you think you've received this email in error, or if you have any questions or concerns regarding your privacy, please contact us at:

privacy@myspace.com

MySpace, Inc.
8391 Beverly Blvd. #349
Los Angeles, CA 90048
USA

©2003-2009 MySpace.com. All Rights Reserved.


4. The websites look like this:



5. Logging in takes you to a page that looks like this:



6. The malware is NOT being distributed from these sites. The malware link actually points to a domain created this morning called:

myspace-files.com

which was registered through "Answerable.com", using PrivacyProtection.

We tried to give Answerable a call, but the crappy VOIP forwarding service they are using to connect to their technical support left me with an agent crackling and saying "I'm sorry, I can't understand you." On the third try, I got a very helpful woman in India who referred me to "support.publicdomainregistry.com" to fill out an abuse desk. We've requested that the domain be terminated.

A VirusTotal report shows that while most of the AV products do not yet detect this malware (14 of 41 can detect it), those which do label it either as Zbot or Bifrost.

File size: 108544 bytes
MD5 : 9014141626efee1175ebee3135f3accf

First Update: 10:20 AM


The malware is now back on the same server as advertised by the spam. Seems something happened to their old malware domain. (evil grin). The new path is:

/msp/updatetool.exe

A Fresh VirusTotal Report shows that the malware has changed in both size and signature. Detection is still 14 of 41, but its a different 14.

File size: 105472 bytes
MD5 : 4c7693219eaa304e38f5f989a8346e51

Second Update: 4:20 PM



There have been sixty-nine unique domains seen in this campaign so far today. The currently live domains at this timestamp are:

accounts.myspace.com.iuuuujef.co.uk
accounts.myspace.com.iuuuujef.me.uk
accounts.myspace.com.iuuuujef.org.uk
accounts.myspace.com.iuuuujeg.co.uk
accounts.myspace.com.iuuuujeg.me.uk
accounts.myspace.com.iuuuujeg.org.uk
accounts.myspace.com.iuuuujek.co.uk
accounts.myspace.com.iuuuujek.me.uk
accounts.myspace.com.iuuuujek.org.uk
accounts.myspace.com.iuuuujer.co.uk
accounts.myspace.com.iuuuujer.me.uk
accounts.myspace.com.yyyyiuj.co.uk
accounts.myspace.com.yyyyiuj.me.uk
accounts.myspace.com.yyyyiuj.org.uk
accounts.myspace.com.yyyyiuk.co.uk
accounts.myspace.com.yyyyiuk.me.uk
accounts.myspace.com.yyyyiuk.org.uk
accounts.myspace.com.yyyyiuo.co.uk
accounts.myspace.com.yyyyiuo.me.uk
accounts.myspace.com.yyyyiuo.org.uk
accounts.myspace.com.yyyyiur.co.uk
accounts.myspace.com.yyyyiur.me.uk
accounts.myspace.com.yyyyiur.org.uk


These have been reported to the Fox Interactive Media and MySpace abuse teams for termination.

No comments:

Post a Comment

Trying a new setting. After turning on comments, I got about 20-30 comments per day that were all link spam. Sorry to require login, but the spam was too much.