- cg33.ru
- cv2e.ru
- cv32.ru
- mc2n.ru
- oc32.ru
- vwsc.ru
Update: here's another one - mj5f.ru
Subject: Bank of America Installation and Upgrade Warning.This leads to a very convoluted URL with an executable Setup_BankofAmericaclientno4508832.exe - virus detection for this one is a bit poor. Malware is identified variously as TR/ATRAPS.Gen (AntiVir & WebWasher), DeepScan:Generic.Malware.dld!!.083539B0 (BitDefender) and one or two others come up with a generic detection.
From: "Bank Of America Update Service Department"
Date: Wed, August 27, 2008 2:23 pm
Attention All Bank of America Customers.
Security & Fraud Protection Update.
At Bank of America, were committed to keeping your information confidential and
secure, and we take that responsibility very seriously.
Our Fraud detection solution helps to protect your business against the risk of
fraudulent transactions alerting you to potential risks.
We have developed the following protection tools to insure you confidentiality.
You can download the latest security pack from our Customer Service Department>>
Sincerely, Jodie William.
2008 Bank of America Corporation. All rights reserved.
Subject: Colonial Bank Emergency Alert System.VirusTotal detections are a mixed bag:
From: "Colonial Bank Account Support"
Date: Tue, August 26, 2008 8:35 pm
Dear Colonial Bank Customers. Protect your passwords!
- Never write down your passwords.
- Never share passwords with anyone.
- Change your password every few months.
- Change your password if you think it has been compromised.
For a password to be strong and hard to break, it should be at least nine characters
long, contain characters from each of the following three groups: letters (uppercase
and lowercase), numerals, symbols (all characters not defined as letters or
numerals), not contain your name or user name and not be a common word or name.
Be sure your computer is up-to-date with security patches, anti-virus, and
anti-spyware protection.
Download our latest all-in-one Internet software from our Customer Service
Department to make your online life completely secured.
Press here to Start>>
Sincerely, Parker Wheeler.
2003-2008 Colonial bank Support Team
File ColonialDigicertx_509.exe received on 08.26.2008 23:52:05 (CET) | |||
Antivirus | Version | Last Update | Result |
AhnLab-V3 | 2008.8.21.0 | 2008.08.26 | - |
AntiVir | 7.8.1.23 | 2008.08.26 | HEUR/Crypted |
Authentium | 5.1.0.4 | 2008.08.26 | - |
Avast | 4.8.1195.0 | 2008.08.26 | - |
AVG | 8.0.0.161 | 2008.08.26 | - |
BitDefender | 7.2 | 2008.08.26 | DeepScan:Generic. Malware.dld!!.6B08AD0D |
CAT-QuickHeal | 9.50 | 2008.08.26 | (Suspicious) - DNAScan |
ClamAV | 0.93.1 | 2008.08.26 | PUA.Packed.MEW-1 |
DrWeb | 4.44.0.09170 | 2008.08.26 | - |
eSafe | 7.0.17.0 | 2008.08.26 | Win32.Stration |
eTrust-Vet | 31.6.6050 | 2008.08.26 | - |
Ewido | 4.0 | 2008.08.26 | - |
F-Prot | 4.4.4.56 | 2008.08.26 | - |
F-Secure | 7.60.13501.0 | 2008.08.26 | Suspicious:W32/Malware!Gemini |
Fortinet | 3.14.0.0 | 2008.08.26 | - |
GData | 19 | 2008.08.26 | - |
Ikarus | T3.1.1.34.0 | 2008.08.26 | Trojan-Proxy.Win32.Small.DT |
K7AntiVirus | 7.10.428 | 2008.08.25 | - |
Kaspersky | 7.0.0.125 | 2008.08.26 | - |
McAfee | 5370 | 2008.08.26 | - |
Microsoft | 1.3807 | 2008.08.25 | PWS:Win32/Uloadis.A |
NOD32v2 | 3390 | 2008.08.26 | - |
Norman | 5.80.02 | 2008.08.26 | W32/Suspicious_M.gen2 |
Panda | 9.0.0.4 | 2008.08.26 | - |
PCTools | 4.4.2.0 | 2008.08.26 | Packed/MEW |
Prevx1 | V2 | 2008.08.26 | - |
Rising | 20.59.11.00 | 2008.08.26 | - |
Sophos | 4.32.0 | 2008.08.26 | Mal/EncPk-BA |
Sunbelt | 3.1.1582.1 | 2008.08.26 | VIPRE.Suspicious |
Symantec | 10 | 2008.08.26 | - |
TheHacker | 6.3.0.6.060 | 2008.08.23 | W32/Behav-Heuristic-066 |
TrendMicro | 8.700.0.1004 | 2008.08.26 | Cryp_MEW-11 |
VBA32 | 3.12.8.4 | 2008.08.26 | - |
ViRobot | 2008.8.26.1350 | 2008.08.26 | - |
VirusBuster | 4.5.11.0 | 2008.08.26 | Packed/MEW |
Subject: hey
From: "hvgoxscw"
Date: Sun, August 10, 2008 7:59 pm
You have 2 options here,
Option 1 - You can put ANY text you want in here.
Option 2 - We will fill it in with the text only portion of the
html message if you put the macro for you: [url removed]
in here.
NOTE: Some email clients don't disply html data. In that case what you
put here will be seen by the recipient. If the email client does
display html data then this will NOT be seen by the recipient.
Based on this you may wish to put a text version of your add here;
however, you can also put some macros here to make the message
more random.
Subject: Hey, take a look!!In this case the target file to download is msgr8.5us.exe, VirusTotal detection is pretty good.
From: "Yahoo Daily News"
Hello friend !
You have just received a yahoo messenger ultimate version !!
Click Download Now to begin downloading and installing Yahoo Messenger ultimate version 10 ver 10.1
1. Download Now Click Download Now to begin downloading and installing Yahoo! Messenger ultimate version 10.
ver. 10.1
2. When prompted, please click the Run button in each window that appears.
Other versions: XP (9.0 Beta), Vista, Mac, Web, Mobile
Thank you for using our services !!!
Please take this opportunity to let your friends use about this new software by sending them the source.
Copyright © 2008 Yahoo! Inc. All rights reserved. Copyright/IP Policy | Terms of Service |Guide to Online Security
Relevant advertising creates a better web experience. See how
NOTICE: We collect personal information on this site.
To learn more about how we use your information, see our Privacy Policy