-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Hi folks,
We've received a significant number of emails today which appear to be
receipts from iTunes Store purchases[1]. Those I've sampled each
purport a large purchase, a smaller credit, and a net charge to the
recipient's iTunes account, with links to "Write a review" and "Report a
problem". The targets of those links are gibberish domains (all so far
within the .info TLD), and visiting them redirects to a site
distributing an .exe ("Flash_installer.exe" was the one I got) that
matches VirusTotal's hashes for a roll of ZeuS[2].
VirusTotal indicates that the NOD32 engine *does* identify this file
as "Win32/Spy.Zbot.ZR".
Of the 16 I've received since noticing the pattern, 10 were marked as
SPAM? by PureMessage.
If you run across anyone who did follow the links in an attempt to
prevent the fictitious charges to their account, it's worth
verifying that NOD32 caught it.
Cheers,
- -sth
[1]http://www.uvm.edu/~sthooker/itunes_driveby_20101001.png
[2]http://www.virustotal.com/file-scan/report.html?id=68d5a7c10a89e1e02217e60d11195adfbd73dfdff12c94fec76e203143372dd4-1285946464
[3]http://www.virustotal.com
- --
Sam Hooker | [log in to unmask]
Systems Architecture and Administration
Enterprise Technology Services
The University of Vermont
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Darwin)
Comment: Use GnuPG with Firefox : http://getfiregpg.org (Version: 0.8)
iQIcBAEBCgAGBQJMphQkAAoJEPoh2/xXOP2jHmoQAJMnZ8KfxZgrZrykfN7k/P8T
4udvnE76CJodOZpzfAnLx+Y7jyVyGLel2VFg6rtFCev7suEByvt421iwUfg3yYsh
q1t7/SKEUkUm3hUeK+CfH+Jf55U8OJCQfre2w5CBlWqCPMyICutVciSsmnp49Acv
ArGHH3cOvWmMNhwJk15Ec1Etl4XWCzpxiG9RllLPjfWN5cWNg7E/DLvNx0gefnjc
e4GA/FABlpxnz7wCSskik3OXIspIx2620Qk4+Ht/uNHrjAJXERhqKardnUD5mwHt
jrD7Fz8KtDZiCre0owXtkneVIItRU3cfeRvSgPfkeuhWE2csb3sgIwpkh5UHzVju
y8DSUeMFZQ/aBY2ZSpPVllvMBii0on8GaoWMhRNPrDxnTbAh184+lpga1BXiXRgU
2rQvZiH+MltEypHWirsJiret44ngvhmsXfm/bZ3/+pFUD9D8eu2d2pSVmfdNkdoC
zlZlpmnHPdHYjJXl9SxK9kCNzzhSetS0kNk5w1r49CXaIVFl3vuRpEOgSxuNoIQM
H2V9AD8Lswa8+dd7WQHvhk5ebpNuWWyXQcfpTf6ZC8e1f+WaE0rkhadCo34a5J5k
rx0o/RQ1/t1dT6IXER5bz1sWmHPZNM6BUNx9xfWPRlcstv+ZYk6qLE37Apd4mF33
YqULTkUpnqYPvMoZp9N3
=wWvv
-----END PGP SIGNATURE-----
|