Adware, malware, spyware, hijacker discussion and information

[Gain Knowledge]  [Install Prevention]  [Maintain Security]  [Spyware Removal Help]


It is currently Sat Jul 31, 2010 2:14 pm

All times are UTC - 7 hours




Post new topic Reply to topic  [ 2 posts ] 
Author Message
 Post subject: Bank of America Digital Certificates - New Generation of Phi
PostPosted: Mon Jun 01, 2009 4:56 pm 
Offline
Site Admin
Site Admin
User avatar

Joined: Fri Jan 28, 2005 5:16 pm
Posts: 15493
Location: PHX, AZ
We've seen several attempts in the past for criminals to try to get your passwords by the social engineering trick of a "Digital Certificate". Beginning in today's spam we're seeing another round that seems more directed at existing users of the Bank of America Digital Certificate program. Previous Bank of America Digital Certificate scams were covered in this blog in our stories including: Banking Digital Certificate Malware in Spam, Bank of America Demo Account - DO NOT CLICK, and LaSalle acquisition by Bank of America spreads malware.

The current email warns that "The Digital Certificate for your Bank of America Direct online account has expired." and provides a link to a website to update the information. All of the links on the website shown below point to the real Bank of America Direct Digital Certificate program, except the "CONTINUE" button.

According to the WHOIS policy for .EU domains, I am not allowed to share with you in my blog the patently false registration information for the domain 1il1il1.eu.

You would have to WHOIS the information yourself from: http://www.eurid.eu, which is probably part of why criminals like .eu domains so much.

We actually received more than fifty copies of this new scam, with the earliest arriving May 29th at 9:30 AM. For most of them, several domains are used, and for some we have multiple copies, with fjtiili.com, hftiili.be, fgtsssa.com, and idfsre.com being the most popular among those we've seen in the spam:
    lstrass.com
    nfillil.net.sg
    fjtiili.com
    fgtsssa.co.uk
    idfgtid.li
    idfgtid.cz
    idfsre.com
    hftiili.be
    fgtsssa.com
0-= Continued @ CyberCrime & Doing Time

_________________
Image


Top
 Profile Send private message  
 
 Post subject: Re: Bank of America Digital Certificates - New Generation of Phi
PostPosted: Tue Jun 02, 2009 1:40 pm 
Offline
Site Admin
Site Admin
User avatar

Joined: Fri Jan 28, 2005 5:16 pm
Posts: 15493
Location: PHX, AZ
Bank of America certificate scam propagating Waledac, Virut
Angela Moscaritolo
June 02, 2009

The SANS Internet Storm center said in a post on Monday that a quick analysis of this malware showed “probable signs” of Waledac -- the notorious worm capable of harvesting and forwarding password information and receiving commands from a remote server. Sean-Paul Correll, threat researcher for Panda Security confirmed to SCMagazineUS.com on Tuesday that the threat is being detected as Waledac.

Marshal8e6's Hay said that after initial analysis of this threat, one of the components of the attack looks like a variant of Virut, which is capable of downloading anything the command and control server wants to install on the infected system, Marshal8e6 said in a recent blog post.

"If the user is compromised by Virut, then potentially all sorts of other malware may end up on the PC,” Hay said.

In February, Microsoft warned that a particularly nasty variant of the Virut virus had been unleashed. The virus was responsible for shutting down the court system in Houston after about 475 of the city's 16,000 computers were infected.

nwz Continued @ SCMagazine

_________________
Image


Top
 Profile Send private message  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

All times are UTC - 7 hours


Who is online

Users browsing this forum: Google and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  

Who is online

Who is online In total there are 2 users online :: 1 registered, 0 hidden and 1 guest (based on users active over the past 5 minutes)
Most users ever online was 115 on Tue Jul 13, 2010 5:32 pm

Users browsing this forum: Google and 1 guest

New posts    No new posts    Forum locked
Powered by phpBB