01
Aug
08

Malspam Campaign, will it ever stop?

There’s no end in sight for the malspam campaign that we’ve been blogging about. This is a new round of spam emails we’ve received again with current events in the subject and body to get the user to click the link. The file get_flash_update.exe is still being pushed with these websites. They are still changing the landing page as you’ll see below. Some are on the same domains, but different landing pages (livestreaming.html, top.html, whatsup.html).

spam

Warning: These sites are active. Proceed at your own risk.

hxxp://chantal-carlioz.fr/livestreaming.html
hxxp://didierbrockly.info/livestreaming.html
hxxp://jabezinformatica.com/livestreaming.html
hxxp://jugendtanzgruppe.de/livestreaming.html
hxxp://ministerstwo.nazwa.pl/livestreaming.html
hxxp://moveonforu.oranc.co.kr/livestreaming.html
hxxp://quimigama.net/livestreaming.html
hxxp://rmodelismo.com/livestreaming.html
hxxp://rogger.it/livestreaming.html
hxxp://sabineanton.de/livestreaming.html
hxxp://scemprestimoconsignado.com.br/livestreaming.html
hxxp://steveellery.com/livestreaming.html
hxxp://thalies.com/livestreaming.html
hxxp://www.femyp.com/livestreaming.html
hxxp://www.firma-thummerer.de/livestreaming.html
hxxp://www.nawaro-management.de/livestreaming.html
hxxp://www.outwork-for-you.de/livestreaming.html
hxxp://www.porzellanklinik-hinz.de/livestreaming.html
hxxp://www.restekiste.com/livestreaming.html
hxxp://www.tch-clubhaus.de/livestreaming.html
hxxp://z0l7.com/livestreaming.html

hxxp://duka-coaching.dk/top.html
hxxp://www.promo2.es/top.html
hxxp://fedecopy.com.ar/top.html
hxxp://www.urresti.es/top.html
hxxp://www.browsetomy.gmxhome.de/top.html
hxxp://www.aquasphere.cz/top.html

hxxp://halkjaer.biz/whatsup.html
hxxp://frankietomattos.com/whatsup.html
hxxp://duka-coaching.dk/whatsup.html
hxxp://manuelarodriguez.com.br/whatsup.html
hxxp://snoopen.de/whatsup.html


2 Responses to “Malspam Campaign, will it ever stop?”


  1. 1 klepto Aug 3rd, 2008 at 6:46 am

    any ideas what cryptor/packer they are using on these files?

  2. 2 lithium Aug 3rd, 2008 at 6:17 pm

    I haven’t had the chance to look at it but here are the first 64 bytes from the EP. Now I need to find the time to disassemble. 68 74 0E FB 00 33 EB 5D 33 D9 3A C6 81 C8 E8 E6 74 02 33 D0 53 8B FA 40 5D 42 BE 00 00 20 00 40 85 C8 4F F9 8D 1D C8 2D 47 01 84 C4 8B D5 81 F8 19 E0 81 02 68 95 F4 A9 00 4D 84 CB 84 CA 57 4F




 

August 2008
M T W T F S S
« Jul   Sep »
 123
45678910
11121314151617
18192021222324
25262728293031