Sponsored by..

Tuesday 17 September 2013

FDIC spam / horse-mails.net

This fake FDIC spam leads to malware on www.fdic.gov.horse-mails.net:

Date:      Tue, 17 Sep 2013 15:28:52 +0330 [07:58:52 EDT]
From:      insurance.coverage@fdic.gov
Subject:      FDIC: About your business account

Dear Business Customer,

We have important news regarding your financial institution.

Please View to see further details.

This includes information on the acquiring bank (if applicable), how your accounts and loans are affected, and how vendors can file claims against the receivership
FDÌC     Questions for FDÌC?
Contact Us

The FDÌC receives no Congressional appropriations - it is funded by premiums that banks and thrift institutions pay for deposit insurance coverage and from earnings on investments in U.S. Treasury securities. The FDÌC insures approximately $9 trillion of deposits in U.S. banks and thrifts - deposits in virtually every bank and thrift in the country.

Federal Insurance Company · 3501 Fairfax Drive · Arlington VA 22225 · 877-275-3342 

The link goes through a legitimate hacked site and onto a malware landing page at [donotclick]www.fdic.gov.horse-mails.net/news/fdic-insurance.php which belongs to the Amerika gang and is hosted on the following IPs (the recommend blocklist is at the end of the post):
37.221.163.174 (Voxility S.R.L., Romania)
95.111.32.249 (Megalan / Mobiltel EAD, Bulgaria)
109.71.136.140 (OpWan SARL, France)
174.142.186.89 (iWeb Technologies, Canada)
216.218.208.55 (Hurricane Electric, US)

Of interest, the legitimate hacked site that is linked to tries to do some OS detection which is a new feature (pictured below)


Recommended blocklist (use in conjunction with this):
37.221.163.174
95.111.32.249
109.71.136.140
174.142.186.89
216.218.208.55
airfare-ticketscheap.com
bnamecorni.com
bundle.su
cernanrigndnisne55.net
cerovskiprijatnomnebi25.net
demuronline.net
evreisorinejsopgmrjnet28.net
fiscdp.com.airfare-ticketscheap.com
germaniavampizdanahuj.net
gormonigraetnapovalahule26.net
grannyhair.ru
gstarstats.ru
horse-mails.net
maxichip.com
micnetwork100.com
mirrorsupply.com
nacha.org.samsung-galaxy-games.net
nvufvwieg.com
pidrillospeeder.com
smartsecureconnect.com
softwareup.pw
tor-connect-secure.com
vineostat.ru
vip-proxy-to-tor.com
www.fdic.gov.horse-mails.net
www.fiscdp.com.airfare-ticketscheap.com
www.irs.gov.successsaturday.net
www.nacha.org.demuronline.net
www.nacha.org.multiachprocessor.com
www.nacha.org.samsung-galaxy-games.net
www.nacha.org.smscente.net

No comments: