From: operator@blah.blah Sent: 20 November 2009 15:21
To: Blah
Subject: please update your blah@blah.blah mailbox
Dear owner of the blah@blah.blah mailbox, You have to change the security mode of your account, from standart to secure. Please change the security mode by using the link below:
http://accounts.blah.blah.verzzi.org.uk/webmail/settings/noflash.php?mode=standart&id=[snip]&email=blah@blah.blah
So far verzzi.co.uk and verzzi.org.uk seem to be domains that are used for this, there are probably many others.
Target page is a fake Flash download:
Target file is flashinstaller.exe with patchy or generic detection at best, according to VirusTotal.
ThreatExpert report is here which could be useful if you are trying to disinfect a machine.
When infected, the machine calls home to 193.104.27.42 in the Ukraine, allegedly belonging to "Vladimir Vasulyovich Kamushnoy" but that could be fake.
Fake WHOIS details for verzzi.co.uk and verzzi.org.uk:
The Verzzi domains are hosted on a fast flux botnet, so the good news is that it won't be very reliable if some muppet DOES visit the site.
Domain name:
verzzi.co.uk
Registrant:
Suzanne Mendez
Registrant type:
Non-UK Individual
Registrant's address:
Taylor Street Apt. 22
Wilrijk
2771
Belgium
Registrar:
Webfusion Ltd t/a 123-Reg.co.uk [Tag = 123-REG]
URL: http://www.123-reg.co.uk
Relevant dates:
Registered on: 18-Nov-2009
Renewal date: 18-Nov-2011
Last updated: 19-Nov-2009
Registration status:
Registration request being processed.
Name servers:
ns1.elkinsrealty.net
ns1.winderz.net
elkinsrealty.net is one nameserver domain, with obviously fake WHOIS details
Domain Name : elkinsrealty.netAnd for Winderz.net:
PunnyCode : elkinsrealty.net
Creation Date : 2009-07-02 19:50:00
Updated Date : 2009-11-20 01:11:11
Expiration Date : 2010-07-02 19:49:56
Registrant:
Organization : Elkins Realty
Name : O Berg
Address : 2150 1st Ave
City : San Diego
Province/State : beijing
Country :
Postal Code : 92101
Administrative Contact:
Name : Elkins Realty
Organization : O Berg
Address : 2150 1st Ave
City : San Diego
Province/State : beijing
Country :
Postal Code : 92101
Phone Number : 86--6195728001
Fax : 86--6195728002
Email : OBerg@gmail.com
Technical Contact:
Name : Elkins Realty
Organization : O Berg
Address : 2150 1st Ave
City : San Diego
Province/State : beijing
Country :
Postal Code : 92101
Phone Number : 86--6195728001
Fax : 86--6195728002
Email : OBerg@gmail.com
Billing Contact:
Name : Elkins Realty
Organization : O Berg
Address : 2150 1st Ave
City : San Diego
Province/State : beijing
Country :
Postal Code : 92101
Phone Number : 86--6195728001
Fax : 86--6195728002
Email : OBerg@gmail.com
ns1.winderz.net and ns1.elkinsrealty.net are on 198.177.253.152 (Allerion Inc, Altlanta)
Registrant:
R Opitz, Brian
341 Church Road
West Sunbury, PA 16061
US
Domain Name: WINDERZ.NET
Administrative Contact, Technical Contact:
R Opitz, Brian straus2009@live.com
341 Church Road
West Sunbury, PA 16061
US
7246372446
Record expires on 17-Nov-2010.
Record created on 17-Nov-2009.
Database last updated on 20-Nov-2009 10:46:04 EST.
Domain servers in listed order:
NS1.WINDERZ.NET 198.177.253.152
NS2.WINDERZ.NET 210.217.45.138
ns2.elkinsrealty.net is on 210.217.15.41 (Korea Telecom)
ns2.winderz.net is on 210.217.45.138 (Korea Telecom)
In this case the email "came" from operator@victimdomain - filtering your own domain at the gateway (or the "operator" address) could be useful.
Update: full list so far..
dirddrf.be
dlsports.be
ftpddrs.be
modertps.be
verzzi.co.uk
verzzi.org.uk
verzzq.co.uk
verzzq.me.uk
verzzq.org.uk
verzzg.co.uk
verzzg.me.uk
verzzg.org.uk
verzzm.co.uk
verzzm.me.uk
verzzm.org.uk
verzzn.co.uk
verzzn.me.uk
verzzn.org.uk
4 comments:
Same thing, only this time it's verzzq.org.uk
Suzanne Mendez is a busy woman:
Domain name:
verzzq.org.uk
Registrant:
Suzanne Mendez
Registrant type:
Non-UK Individual
Registrant's address:
Taylor Street Apt. 22
Wilrijk
2771
Belgium
Registrar:
Webfusion Ltd t/a 123-Reg.co.uk [Tag = 123-REG]
URL: http://www.123-reg.co.uk
Relevant dates:
Registered on: 18-Nov-2009
Renewal date: 18-Nov-2011
Last updated: 19-Nov-2009
Registration status:
Registration request being processed.
Name servers:
ns1.elkinsrealty.net
ns1.winderz.net
WHOIS lookup made at 17:06:39 20-Nov-2009
Now she's hitting me from verzzn.org.uk
Maybe "she" registered ALL the "verzz[*].org.uk domains!
Oddly, not all the verzz* domains have been registered. The .be ones are even odder, can't see a patter there at all.
Yep just been hit by dirddrf.be, reported to the .be registry because you'll need good luck to find all of the multiple server locations.
Post a Comment