All Things Techie With Huge, Unstructured, Intuitive Leaps
Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Watch out for the "What's App Web" Spam Virus/Malware


I just got this piece of crap spam malware/virus injector in my mail.  It came directly from a friend's gmail account so obviously he picked up the malware from somebody.

Don't click on it.  Notice the spelling error in the word "length".  The domain with the link comes from maloureyes.com. That doesn't mean anything, because typically these spammers hack a relatively untended website, inject their crap from there without the owner being the wiser.

Interesting that they would try to play off the Whats App name.  Don't be fooled.

Malware Spam Says That Your Mailbox Has Reached Its Limit

I am seeing a new kind of spam lately.  The sender says that it is "Email Administrator" and the subject is "Notification Alert".  The message tells me that I have exceeded my limit of my mailbox, and I need to click a link to fix it.  Here is the text of the message:

Email Administrator <administrateur@rdp.com>
12:05 PM (2 hours ago)


Dear Account User,

Your mailbox has exceeded the limit of 30 GB, which is as set by your manager, you are currently at 30.9GB, very soon you will not be able to create new e-mail to send or receive again until you validate your mailbox.To re-validate your mailbox, click on the link below and follow the instruction for your upgrade.

Click Here To Upgrade


Regards,

Email  Administrator Member Services
****************************** **************************
If you received this in Spam, please kindly move it to inbox.

You notice that the administrator is using the French spelling.  That would suggest that the perpetrator is from a French speaking country in Africa, like Senegal, Algeria, Burkina Faso or any other former French colony.

The other thing to note, is that they are using an email address not from the same domain.  That should raise red flags.

What I did do, is investigate the links where you have to click to load the malware.  (Don't try this at home folks.  I am a professional, and I have a machine that I can trash.  I use it to trap viruses and have a look at them).

There are two domains in the various messages.  Here are the domains:

www.ayotec.co.uk
www.kleine-bucher.de

These are legitimate domains.  What these guys do, is hack websites that are not updated regularly or the source code for the web sites are checked infrequently.  They simply add another landing page that isn't visible to the website with a link, but can be reached directly with a URL.  They hide their malware there, and as a result, the originator is untraceable.

Just another day in the war on Malware and Spam.

Virus Injection Domain ~ Someone in Portugal Please Lay a Beating on this guy

I have an acquaintance named Dwight who is a nice guy. I met him at a dinner party in Nassau at a mutual friends place. Nassau is a small place and I occasionally ran into him. Dwight was transferred back to Florida. I haven't heard from him in a long while. Thus I was pleased when I saw an email from him in my inbox. However, I was not pleased when I saw that it was a virus generated email going through his contact list sending out links that will infect your machine.

I am sure you have seen these latest viruses. You get an email from one of your trusted contacts that says "Hey look at this". When you click on it, BANG -- you're infected.

Well, its time to fight back. Here is the domain name registration of the sub-human sending out these viruses. It is from Portugal. If there is anyone in Portugal who is an anti-social psychopath who is just itching to lay a beating on someone, go to the town or Porto (yes where port comes from). Find the street Rua Barao de Nova Sintra, and the building number is No. 433. Ring the bell for apartment 3530 and beat the living crap out of the guy, and while you are at it, smash all of the computers and cell phones.

The domain of virus injector is: dunil.pt. Don't click on it.

WHOIS information for dunil.pt:

Nome de dom?nio / Domain Name: dunil.pt
Data de registo / Creation Date (dd/mm/yyyy): 04/12/2000
Data de expira??o / Expiration Date (dd/mm/yyyy): 28/02/2013
Estado / Status: ACTIVE
Titular / Registrant

Dunil - Confeccoes Lda
Rua Barao de Nova Sintra, No. 433
Apartado 3530

4306-901 Porto

Email: dunil@ip.pt

Entidade Gestora / Billing Contact
G9SA - Telecomunicacoes S.A .
Email: geral@g9sa.pt

Respons?vel T?cnico / Tech Contact
Joao Carlos Ramos Perdigoto
Email: perdigot@interacesso.pt

Update: Got another virus mailing from Dwight's machine. This one came from Malaysia. (They shouldn't let half-civilized monkey goons play on the internet). Here are the domain registration details:

Chan Kee Siak
Exabytes Network Sdn Bhd
1-18-8, Suntech @ Penang Cybercity
Lintang Mayang Pasir 3, Bayan Baru
11950 Bayan Lepas
Pulau Pinang
Malaysia
@exabytes.com.my
(Tel) 604-6308283
(Fax) 604-6308288

g [Registrant Code] DENAI1.ORG
Denai Solutions Sdn Bhd
(531969-A)
38-5-2 Jalan 1/101C
Cheras Business Center, Cheras
56100 Kuala Lumpur
Wilayah Persekutuan
(Tel) 03-91334299
(Fax) 03-91411266

h [Administrative Contact Code] KHIZYAHA0.CON
Khuzaif Yahaya
Denai Solutions Sdn Bhd
Level 12, Bangunan MAS
Jalan Sultan Ismail
50250 Kuala Lumpur
Wilayah Persekutuan
Malaysia
@hotmail.com
(Tel) 03-20523909
(Fax) 03-21649405