On TV.com: The Shocking HEROES Death, Revealed
BNET Business Network:
BNET
TechRepublic
ZDNet

April 9th, 2009

Fake "Conficker Infection Alert" spam campaign circulating

Posted by Dancho Danchev @ 6:01 am

Categories: Anti Virus, Botnets, Browsers, Hackers, Malware, Passwords, Spam and Phishing, Viruses and Worms

Tags: Security, Scareware, Conficker, Waledac, Spam Campaign, Microsoft Corp., Microsoft Windows, Dancho Danchev, Operating Systems

Researchers at Marshal8e6’s TRACElabs have intercepted a spam campaign that’s issuing bogus “Conficker Infection Alerts” and redirecting users to rogue security software upon clicking on the links.

The event-based social engineering campaign is also impersonating various Microsoft security departments in order to improve its truthfulness. This is the second attempt in recent weeks to hijack anticipated traffic, following last week’s campaign consisting of typosquatted conficker removal tool domains aiming to impersonate the legitimate ones.

Here’s the message, its associated subjects and related rogue security software domains used in the spam campaign:

“Dear Microsoft Customer,

Starting 04/01/2009 the ‘Conficker’ worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected.

To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.

Please visit the Windows Computer Safety Center by simply clicking here to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.

Regards,
Microsoft Windows Agent #2 (Hollis)
Microsoft Windows Computer Safety Division
Email Ref Code: RANDOM NUMBER”

Typical messages include: Infection Alert; Conficker Infection Alert; Microsoft Alert; Security Breach, with the end user redirected to the following scareware domains upon clicking on the links: antivirus-av-ms-check .com; antivirus-av-ms-checker .com; ms-anti-vir-scan .com; mega-antiviral-ms .com.

Such event-based scareware/malware/spam campaigns are constantly evolving from the static theme picked up from the front page of a major news portal, to the real-time syndicating of hot keywords and hijacking of popular titles in order to occupy the top search positions at a specific online video sharing service. Ironically, the original Conficker variant was directly aiming to monetize the infected hosts by pushing rogue security software and earning revenue in the process, at least temporarily until the affiliate network went in a cover-up phase, and Conficker introduced a new variant that was no longer generating so much noise that could potentially result in more leads to the original authors — they wish.

Ignoring the Conficker copycats and the scareware distributors for a second, yesterday, the latest Conficker variant introduced a new payload with TrendMicro continuing to investigate its real intentions. These cosmetic changes are prone to take place in the weeks to come, until the Conficker authors start monetizing the infected hosts by either partitioning the botnet, or directly start offering managed cybercrime facilitating services.

TrendMicro’s assessment proves one thing - that the cybercrime ecosystem is way too small even for big botnet operators to avoid each other. The changes made to WORM_DOWNAD.E. attempts to download another encrypted file from a well known domain of the Waledac botnet, which on the other hand is also known to have been sharing infrastructure with the original Storm Worm botnet.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 20 Talkback(s)
1 plus 1 equals 2
The title of this message is spammy, and thus
following your logic it is incorrect.
YAY!!!!!!!!!!



Edit: needed more exclamation points.... (Read the rest)
Posted by: AzuMao Posted on: 10/23/09  (Edited: 10/23/09 @ 10:13) You are currently: a Guest | | Terms of Use
I see the Hyenas have come to feed  kozmcrae | 04/09/09
^ speaking of hyenas  ejhonda | 04/09/09
It sure does!  InAction Man | 04/09/09
And another TROLL jumps to defend the first...  Wolfie2K3 | 04/09/09
And another one counter attacks  InAction Man | 04/09/09
How pleasant...  readwryt@... | 04/10/09
A basement... you would like to have one wouldn't you?  InAction Man | 04/10/09
The ability to troll  wcb42ad | 04/10/09
You're new here, aren't you.  kozmcrae | 04/10/09
'effected' ha ha, how about 'affected'?  eggmanbubbagee@... | 04/09/09
RE: Fake  NStalnecker | 04/09/09
RE: Fake  readwryt@... | 04/10/09
1 plus 1 equals 2  AzuMao | 10/23/09
RE: Fake  JohnGroot@... | 04/10/09
It is not a fake  Romano4444 | 04/10/09
You should see GuidingLight.  kozmcrae | 04/10/09
RE: Fake  dougseaton | 04/10/09
Who owns domain names?  graham.lv | 04/10/09
Confickker For Macs!  Loverrock Davidson | 04/11/09
RE; It's not a fake  Col Mustard | 04/13/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline