In need of a "creative phishing campaign of the year"? Try this, perhaps the largest phishing attack spoofing MySpace and collecting all the login details at a central location, that's been active for over a month and continues to be. A Chinese phishing group have come up with legitimate looking MySpace profiles (profile.myspace.com) in the form of subdomains at their original .cn domains, and by doing so achieve its ultimate objective - establish trust through typosquatting, remain beneath the security vendors radar by comment spamming the URLs inside MySpace, and obtain the login details of everyone who got tricked.
- all of the participating domains are using identical DNS servers, whereas their DNS records are set to change every 3 minutes
- each and every domain is using a different comment spam message, making it easy to assess the potential impact of each of them
- the URLs are not spammed like typical phishing emails, but comment spammed within MySpace by using legitimate accouts, presumably once that have already fallen victim into the campaign, and mostly to remain beneath the radar of security vendors if the URLs were spammed in the usual manner
- all of the URLs are the subdomains are currently active, and the login details get forwarded to a central location 319303.cn/login.php
(form action = "http://319303.cn/login.php" method = "post" name = "theForm" id = "theForm)
(form action = "http://secure.myspace.com/index.cfm?fuseaction=login.process" method = "post" id = "LoginForm")
profile.myspace.com.fuseaction.id.0ed37i8xdd.378d38.cn
profile.myspace.com.index.fuseaction.id.370913.cnprofile.myspace.com.fuseaction.id.0ed37i8xdd.125723.cn
profile.myspace.com.fuseaction.id.Dx78x00iJe5.982728.cnprofile.myspace.com.fuseaction.user.id.28902334.arutncbt.cn
profile.myspace.com.fuseaction.id.0nd8di8xfd.125723.cnprofile.myspace.com.fuseaction.id.0ed37i8xdd.109820.cn
378d38.cn
978bg33.cn370913.cn
107882.cn103238.cn
978nd03.cn107882.cn
pcc2ekxz.cn125723.cn
pckeez.cnAssessing the comment messages used on ten phishing domains for internal comment spamming at MySpace :
978bg33.cn - "sometimes i cannot believe the pics people put on their myspaces"
982728.cn - "I cannot believe this freaking whore would put pics like that on her myspace page.. how trashy.."977y62.cn - "did you see what happened? OMG you gotta see Mike's profile."
125723.cn - "did you see what happened? OMG you gotta see Mike's profile."pckeez.cn - "can you believe we went to highschool with this chick?"
pcc2ekxz.cn - "can't believe a 18 year old chick would put half-nude pics on myspace. whore alert."arutncbt.cn - "wow her brother is gonna be so pissed when he sees the pictures she put on her myspace"
125723.cn - "Did you hear what happened Omg you gotta see the profile.. So sad!"109820.cn - "sometimes i just cannot believe the pics that people put on their myspaces LMAO!"
Now if that's not enough to disturb you, each and every of the .cn domains are resolving to what looks like U.S based hosts only that will change every 3 minutes. Not necessarily as dynamic as previously discussed fast-flux networks, but these are worth keeping an eye on :
978bg33.cn
Here are some central DNS servers that all the .cn domains use :
ns1.52352a0c60a9c29.com
ns3.926817a885d86e1.comns2.terimadisirida.net
Does all the data lead us to conclude that this could be the most "creative phishing campaign of the year"? Let's have it offline first.
No comments:
Post a Comment