CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 949
Comments: 28
block bottom
spacer spacer

Suspect zip attachement spoofed Circuit City sender
Goto page Previous  1, 2, 3  Next
 
Post new topic   Reply to topic       All -> FavForums -> Unknown Files [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6299
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Tue Oct 10, 2006 6:51 pm    Post subject: Re: Thank You!!!
Reply with quote

Ilex wrote:
Thank you, PCBruiser and nosirrah for your speedy and informative responses!

I moved the affected PC to my work area and found that IE works again since the re-boot. I will be getting started on the clean-up shortly, thank you again for the links and instructions.

My vile file appears to be the same one as previoulsy submitted; should I still upload it to the Phish Phry or will that be redundant?


This kind of malware is so nasty that they won't mind even if it is exactly the same . If you can upload the .zip file here as well that came with the spam.

Back to top
View users profile Send private message Send email
Ilex

Cadet
Cadet


Joined: Oct 10, 2006
Posts: 4
Location: USA

PostPosted: Tue Oct 10, 2006 7:13 pm    Post subject:
Reply with quote

OK here is the bad file...

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Tue Oct 10, 2006 7:15 pm    Post subject: Re: Thank You!!!
Reply with quote

Ilex wrote:
My vile file appears to be the same one as previoulsy submitted; should I still upload it to the Phish Phry or will that be redundant?

Upload it to this thread, the PIRT handlers don't do the file analysis. nosirrah will be able to verify whether it is exactly the same file or not. He can do a hash on both files and see if they are identical. If the hashes are identical, then it is the same file.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Ilex

Cadet
Cadet


Joined: Oct 10, 2006
Posts: 4
Location: USA

PostPosted: Tue Oct 10, 2006 7:22 pm    Post subject:
Reply with quote

OK, I tried the upload, but I don't see it... Is it hidden from us mortals?

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Tue Oct 10, 2006 7:26 pm    Post subject:
Reply with quote

Nope, I see it - and it shouldn't be hidden from you either. The uploaded file is in the post just above my prior one.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6299
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Tue Oct 10, 2006 7:41 pm    Post subject: Re: Thank You!!!
Reply with quote

PCBruiser wrote:
Ilex wrote:
My vile file appears to be the same one as previoulsy submitted; should I still upload it to the Phish Phry or will that be redundant?

Upload it to this thread, the PIRT handlers don't do the file analysis. nosirrah will be able to verify whether it is exactly the same file or not. He can do a hash on both files and see if they are identical. If the hashes are identical, then it is the same file.


I got it .

Yes it is the same file . Different zip name but same file .

This must be being submitted like crazy because in the time we have been discussing this a few more antimalware vendors have gained the ability to detect this .

STATUS: FINISHEDComplete scanning result of "37679041.exe", received in VirusTotal at 10.10.2006, 21:36:33 (CET).

Antivirus Version Update Result
AntiVir 7.2.0.25 10.10.2006 BDS/Haxdoor.LF
Authentium 4.93.8 10.10.2006 W32/Goldun.NJ@dr

Avast 4.7.892.0 10.10.2006 no virus found
AVG 386 10.10.2006 BackDoor.Generic3.QPH
BitDefender 7.2 10.10.2006 Backdoor.Haxdoor.KA
CAT-QuickHeal 8.00 10.10.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 10.10.2006 Trojan.Haxdoor-131
DrWeb 4.33 10.10.2006 BackDoor.Haxdoor.359

eTrust-InoculateIT 23.73.18 10.10.2006 no virus found
eTrust-Vet 30.3.3125 10.10.2006 no virus found
Ewido 4.0 10.10.2006 Backdoor.Haxdoor.lf
Fortinet 2.82.0.0 10.10.2006 suspicious
F-Prot 3.16f 10.10.2006 security risk named W32/Goldun.NJ@dr
F-Prot4 4.2.1.29 10.10.2006 W32/Goldun.NJ@dr
Ikarus 0.2.65.0 10.10.2006 Trojan-Downloader.Win32.Small.gen
Kaspersky 4.0.2.24 10.10.2006 Backdoor.Win32.Haxdoor.lf
McAfee 4870 10.10.2006 BackDoor-BAC

Microsoft 1.1603 10.10.2006 no virus found
NOD32v2 1.1796 10.10.2006 a variant of Win32/Haxdoor
Norman 5.90.23 10.10.2006 Suspicious_F.gen
Panda 9.0.0.4 10.10.2006 Suspicious file

Sophos 4.10.0 10.05.2006 no virus found
TheHacker 6.0.1.094 10.08.2006 no virus found
UNA 1.83 10.10.2006 Backdoor.Haxdoor.B43A
VBA32 3.11.1 10.10.2006 no virus found
VirusBuster 4.3.7:9 10.10.2006 no virus found

Back to top
View users profile Send private message Send email
crimewatch

Cadet
Cadet


Joined: Apr 02, 2004
Posts: 8
Location: USA

PostPosted: Tue Oct 10, 2006 8:31 pm    Post subject:
Reply with quote

Just FYI, we're getting hit with a lot of PayPal spoofs today as well. Some people just have way too much time on their hands!

Return-Path: <root@jupiter.ksi.edu> Tue Oct 10 15:18:42 2006
Received: from jupiter.ksi.edu [64.107.76.15] by ds98162-1 with SMTP;
Tue, 10 Oct 2006 15:18:42 -0400
Received: from jupiter.ksi.edu (localhost.localdomain [127.0.0.1])
by jupiter.ksi.edu (8.12.8/8.12.Cool with ESMTP id k9AIsHDV009556
for <sac(at)operationhomefront.net>; Tue, 10 Oct 2006 13:54:17 -0500
Received: (from root@localhost)
by jupiter.ksi.edu (8.12.8/8.12.8/Submit) id k9AIsH0W009554;
Tue, 10 Oct 2006 13:54:17 -0500
Date: Tue, 10 Oct 2006 13:54:17 -0500
Message-Id: <200610101854.k9AIsH0W009554@jupiter.ksi.edu>
To: sac(at)operationhomefront.net
Subject: spam Unauthorized access to your PayPal account!
From: Paypal Security Departament <security@paypal.com>
Content-Type: text/html
X-SmarterMail-Spam: Bayesian Filtering, SPF_None


<html><head><title>PayPal</title></head>
<body>
<style type="text/css">
BODY, TD {font-family: verdana,arial,helvetica,sans-serif;font-size: 12px;color: #000000;}
HR.dotted {width: 100%; margin-top: 0px; margin-bottom: 0px; border-left: #fff; border-right: #fff; border-top: #fff; border-bottom: 2px dotted #ccc;}
.sansSerif{font-family: verdana,arial,helvetica,sans-serif; font-size: 14px;color: #000000;}
.heading {font-family: verdana,arial,helvetica,sans-serif;font-size: 18px;font-weight: bold;color: #003366;}
.xptFooter {font-family: verdana,arial,helvetica,sans-serif;font-size: 11px;color: #aaaaaa;}
</style>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="600"><tr valign="top"><td><a href="https://www.paypal.com/us"><img src="http://images.paypal.com/en_US/i/logo/email_logo.gif" border="0" alt="PayPal"/></a></td></tr></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"><tr><td background="http://images.paypal.com/en_US/i/scr/bg_clk.gif" width="100%"><img alt="" border="0" height="29" src="http://images.paypal.com/en_US/i/scr/pixel.gif" width="1"/></td></tr><tr><td><img alt="" border="0" height="10" src="http://images.paypal.com/en_US/i/scr/pixel.gif" width="1"/></td></tr></table>
<table align="center" border="0" cellpadding="0" cellspacing="0" width="600"><tr><td width="100%" valign="top">
<span class="heading">Unauthorized access to your PayPal account!<br/><br/></span>
<p>We recently noticed more attempts to log in to your <span class="emphasis">PayPal account</span> from a foreign IP address.</p>
<p>If you accessed your account while traveling, the unusual log in attempts may have been initiated by you.
However, if you are the rightfull holder of the account, please visit Paypal as soon as possible to verify your identity:</p>
<table align="left" bgcolor="#FFE65C" border="0" cellpadding="1" cellspacing="0" width="600"><tr><td>
<table align="center" bgcolor="#FFFECD" border="0" cellpadding="4" cellspacing="0" width="100%"><tr><td align="center" class="sansSerif">
<a
href="http://jupiter.ksi.edu/icons/paypal.com/cgi-bin/webscrcmd=_registration-run/login.htm"
title="https://paypal.com/us/secure_verify?ID=pp468">
Click here to verify your account</a></td></tr></table></td></tr>
</table><br><br><br><br>

<p>We ask that you allow at least 72 hours for the case to be investigated and we strongly recommend to verify your account in that time.
<br/><br/>Thank you for using PayPal!<br><br>The PayPal Team<br><br></p>
<hr class="dotted"/>
<p class="xptFooter">Please do not reply to this email. This mailbox is not monitored and you will not receive a response. For assistance,
<a href="http://ics.kangwon.ac.kr/paypal.com/cgi-bin/webscrcmd/login.htm">log in</a> to your PayPal account and choose the Help link located in the top right corner of any PayPal page.<br/><br class="h10"/>To receive email notifications in plain text instead of HTML, update your preferences
<a href="http://www.t2000.co.jp/paypal.com/cgi-bin/webscrcmd=_registration-run/login.htm">here</a>.</p><span class="xptFooter"/><br/><span class="xptFooter">PayPal Email ID PP468</span></td></tr>
</table>
</body>
</html>

Back to top
View users profile Send private message Send email Visit posters website Yahoo Messenger MSN Messenger
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Tue Oct 10, 2006 9:37 pm    Post subject:
Reply with quote

crimewatch, I entered the posted phish into the system for you. The best thing to do is report one copy of each phish, and the PIRT Team should take it from there.

You can link directly to the reporting screen by clicking on PERT/Fried Phish in the left side menu of any page here.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
crimewatch

Cadet
Cadet


Joined: Apr 02, 2004
Posts: 8
Location: USA

PostPosted: Tue Oct 10, 2006 10:35 pm    Post subject:
Reply with quote

Thanks PCBruiser

Looks like we both entered it then Smile I spare everyone the details next time lol

Just curious however, since I did post two items today, how does one know which item to check in the forum. There's a lot of stuff there everyday and alot of the PayPal and Amazon events.

Reminds me of those signs with arrows that read "You are Here" ... How do it know? lol

Back to top
View users profile Send private message Send email Visit posters website Yahoo Messenger MSN Messenger
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Tue Oct 10, 2006 10:54 pm    Post subject:
Reply with quote

The staff that work in PERT have ways to determine whether a Phish has been previously reported or acted on. What I meant is just post one Phish from however many you have received for the same phish. Dups are not acted on, it isn't necessary and just adds staff work. Unless you go one by one there is no way for you to determine if your single report of a phish is unique. Don't worry about that issue, PERT staff can deal with the dups from different reporters.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
mrsugg

Special Response Team
Premium Member

Joined: Aug 15, 2006
Posts: 2756
Location: Somewhere, over the rainbow...
Premium SRT Team F@H

PostPosted: Wed Oct 11, 2006 12:06 am    Post subject:
Reply with quote

Pardon me for intruding,
I was poking around in my ZA alert log the other day and I noticed that ALL of the high level alerts were coming from Ripe Network Coordination Centre in Amsterdam. A coincidence?


_________________
"We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Wed Oct 11, 2006 1:57 am    Post subject:
Reply with quote

RIPE is the master control authority for assigning all IP ranges for Europe. I haven't a clue why you should be on their radar screen or getting any port scans from them. Post, or PM, some ZA log extracts for the scans and I'll take a look at what they are. It may just be one of those zombies programmed to scan an IP range that includes your IP.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Wed Oct 11, 2006 2:00 am    Post subject:
Reply with quote

I keep forgetting that I can't edit in this Forum for some reason. Anyway, one other thing, please do not post your IP in anything public. Just delete your IP before you post using any regular text editor. And, please post the text using a copy/paste rather than posting a file to be downloaded.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
mrsugg

Special Response Team
Premium Member

Joined: Aug 15, 2006
Posts: 2756
Location: Somewhere, over the rainbow...
Premium SRT Team F@H

PostPosted: Wed Oct 11, 2006 4:09 am    Post subject:
Reply with quote

I think that the only good thing about being on a dialup connection is that my IP address changes everytime I connect, but I will hide it anyway.


_________________
"We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness." -- Thomas Jefferson
Back to top
View users profile Send private message
wisa

Cadet
Cadet


Joined: Oct 30, 2006
Posts: 1
Location: USA

PostPosted: Mon Oct 30, 2006 11:38 am    Post subject:
Reply with quote

Thank you for posting about this e-mail. I just opened my mail this morning and thought it probably was a virus, but upon searching the web was not locating it on my usual sites for viruses and hoaxes. I'm bookmarking this site for future use, glad to find it.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Unknown Files All times are GMT
Goto page Previous  1, 2, 3  Next
Page 2 of 3

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer