From: operator@blah.blah Sent: 20 November 2009 15:21
To: Blah
Subject: please update your blah@blah.blah mailbox
Dear owner of the blah@blah.blah mailbox, You have to change the security mode of your account, from standart to secure. Please change the security mode by using the link below:
http://accounts.blah.blah.verzzi.org.uk/webmail/settings/noflash.php?mode=standart&id=[snip]&email=blah@blah.blah
So far verzzi.co.uk and verzzi.org.uk seem to be domains that are used for this, there are probably many others.
Target page is a fake Flash download:
Target file is flashinstaller.exe with patchy or generic detection at best, according to VirusTotal.
ThreatExpert report is here which could be useful if you are trying to disinfect a machine.
When infected, the machine calls home to 193.104.27.42 in the Ukraine, allegedly belonging to "Vladimir Vasulyovich Kamushnoy" but that could be fake.
Fake WHOIS details for verzzi.co.uk and verzzi.org.uk:
The Verzzi domains are hosted on a fast flux botnet, so the good news is that it won't be very reliable if some muppet DOES visit the site.
Domain name:
verzzi.co.uk
Registrant:
Suzanne Mendez
Registrant type:
Non-UK Individual
Registrant's address:
Taylor Street Apt. 22
Wilrijk
2771
Belgium
Registrar:
Webfusion Ltd t/a 123-Reg.co.uk [Tag = 123-REG]
URL: http://www.123-reg.co.uk
Relevant dates:
Registered on: 18-Nov-2009
Renewal date: 18-Nov-2011
Last updated: 19-Nov-2009
Registration status:
Registration request being processed.
Name servers:
ns1.elkinsrealty.net
ns1.winderz.net
elkinsrealty.net is one nameserver domain, with obviously fake WHOIS details
Domain Name : elkinsrealty.netAnd for Winderz.net:
PunnyCode : elkinsrealty.net
Creation Date : 2009-07-02 19:50:00
Updated Date : 2009-11-20 01:11:11
Expiration Date : 2010-07-02 19:49:56
Registrant:
Organization : Elkins Realty
Name : O Berg
Address : 2150 1st Ave
City : San Diego
Province/State : beijing
Country :
Postal Code : 92101
Administrative Contact:
Name : Elkins Realty
Organization : O Berg
Address : 2150 1st Ave
City : San Diego
Province/State : beijing
Country :
Postal Code : 92101
Phone Number : 86--6195728001
Fax : 86--6195728002
Email : OBerg@gmail.com
Technical Contact:
Name : Elkins Realty
Organization : O Berg
Address : 2150 1st Ave
City : San Diego
Province/State : beijing
Country :
Postal Code : 92101
Phone Number : 86--6195728001
Fax : 86--6195728002
Email : OBerg@gmail.com
Billing Contact:
Name : Elkins Realty
Organization : O Berg
Address : 2150 1st Ave
City : San Diego
Province/State : beijing
Country :
Postal Code : 92101
Phone Number : 86--6195728001
Fax : 86--6195728002
Email : OBerg@gmail.com
ns1.winderz.net and ns1.elkinsrealty.net are on 198.177.253.152 (Allerion Inc, Altlanta)
Registrant:
R Opitz, Brian
341 Church Road
West Sunbury, PA 16061
US
Domain Name: WINDERZ.NET
Administrative Contact, Technical Contact:
R Opitz, Brian straus2009@live.com
341 Church Road
West Sunbury, PA 16061
US
7246372446
Record expires on 17-Nov-2010.
Record created on 17-Nov-2009.
Database last updated on 20-Nov-2009 10:46:04 EST.
Domain servers in listed order:
NS1.WINDERZ.NET 198.177.253.152
NS2.WINDERZ.NET 210.217.45.138
ns2.elkinsrealty.net is on 210.217.15.41 (Korea Telecom)
ns2.winderz.net is on 210.217.45.138 (Korea Telecom)
In this case the email "came" from operator@victimdomain - filtering your own domain at the gateway (or the "operator" address) could be useful.
Update: full list so far..
dirddrf.be
dlsports.be
ftpddrs.be
modertps.be
verzzi.co.uk
verzzi.org.uk
verzzq.co.uk
verzzq.me.uk
verzzq.org.uk
verzzg.co.uk
verzzg.me.uk
verzzg.org.uk
verzzm.co.uk
verzzm.me.uk
verzzm.org.uk
verzzn.co.uk
verzzn.me.uk
verzzn.org.uk
Same thing, only this time it's verzzq.org.uk
ReplyDeleteSuzanne Mendez is a busy woman:
Domain name:
verzzq.org.uk
Registrant:
Suzanne Mendez
Registrant type:
Non-UK Individual
Registrant's address:
Taylor Street Apt. 22
Wilrijk
2771
Belgium
Registrar:
Webfusion Ltd t/a 123-Reg.co.uk [Tag = 123-REG]
URL: http://www.123-reg.co.uk
Relevant dates:
Registered on: 18-Nov-2009
Renewal date: 18-Nov-2011
Last updated: 19-Nov-2009
Registration status:
Registration request being processed.
Name servers:
ns1.elkinsrealty.net
ns1.winderz.net
WHOIS lookup made at 17:06:39 20-Nov-2009
Now she's hitting me from verzzn.org.uk
ReplyDeleteMaybe "she" registered ALL the "verzz[*].org.uk domains!
Oddly, not all the verzz* domains have been registered. The .be ones are even odder, can't see a patter there at all.
ReplyDeleteYep just been hit by dirddrf.be, reported to the .be registry because you'll need good luck to find all of the multiple server locations.
ReplyDelete