Swine Flu Malware Infects Your PC, Not You

Night Hawk

caught multibooting
Guru
Gold Member
VIP
Local time
1:09 PM
Messages
8,373
Location
New England
Swine Flu Malware Infects Your PC, Not You

12.02.09

by Reuters


BOSTON (Reuters) - Hackers are spreading a vicious computer virus through spam email messages that urge recipients to visit a bogus website offering vaccinations to protect them against another virus—the one that causes swine flu.

The email purports to be from the U.S. Centers for Disease Control, directing them to what looks like an official government website to fill out a vaccination form, said researchers from security firms Symantec Corp and AppRiver.

Security researchers said they began seeing millions of spam messages on Tuesday as part of a scheme to infect computers with malicious software that lets hackers take control of computers.

More at: Swine Flu Malware Infects Your PC, Not You - Reviews by PC Magazine
 

My Computers My Computers

  • At a glance

    W7 Ultimate x64/W10 Pro x64/W11 Pro Triple Bo...AMD Phenom II X4 975 Deneb 3.6ghz - 965 2nd r...Kingston Hyper X DDR3 1600 1.5v 16gb - Hyper ...MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 o...
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    Custom builds = 2
    OS
    W7 Ultimate x64/W10 Pro x64/W11 Pro Triple Boot - Main PC W7 Remote PC Micro ATX W7 Pro x64/W11 Pro
    CPU
    AMD Phenom II X4 975 Deneb 3.6ghz - 965 2nd remote pc
    Motherboard
    Gigabyte GA-790XTA-UD4-Gigabyte GA-880GM-D2H remote pc
    Memory
    Kingston Hyper X DDR3 1600 1.5v 16gb - Hyper X Fury 8gb 2nd
    Graphics Card(s)
    MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 on mini tower
    Sound Card
    Creative Labs X-Fi Xtreme Audio P - Realtek onooard 2nd case
    Monitor(s) Displays
    ASUS VW199T-P 19" HP 2082a Main-HP 2082a 20" remote pc
    Screen Resolution
    Asus 1440x900 - HP 1600x900
    Hard Drives
    WD Black 1TB HD per OS W7, W10, and pending W11 presently on 500gb OS Drive - Pending Triple 1TB HDs for Spanned Storage/backup volume
    Single 2TB external USB enclosure, single 1TB System 7 Host/Boot drive, Pending 8TB external HD for system image b
    PSU
    Corsair 750TX - primary / Corsair CX600 - second
    Case
    Antec 900-2 - SSD compatible / NZXT Vulcan mini tower
    Cooling
    Zalman CNPS9900A
    Keyboard
    AZIO L70 Backlit Letters Gaming - ONN Cordless/USB
    Mouse
    MSI DS200 Programmable, Logitech Cordless
    Internet Speed
    30mbps upgrade - primary hard wired - mini tower usb WiFi
    Antivirus
    GFI VIPRE Internet Security 2014 on W7 2016 beta on W10,
    Browser
    Cyberfox, WaterFox 64bit FF variants, FireFox x64, Pale Moon
    Other Info
    Accomdata fan cooled usb 2.0 PIDE/Sata II, III external enclosure.
    Sambient usb/eSata PATA/Sata II, III external enclosure.
  • At a glance

    W7 Pro x64/W11 ProAMD Deneb 3.6ghz - 965Kingston Hyper X Fury 8gbMSI HD Radeon 6450 DVI Output
    Computer type
    PC/Desktop
    System Manufacturer/Model Number
    CUSTOM ASSEMBLY
    OS
    W7 Pro x64/W11 Pro
    CPU
    AMD Deneb 3.6ghz - 965
    Motherboard
    Gigabyte GA-880GM-D2H remote pc
    Memory
    Kingston Hyper X Fury 8gb
    Graphics Card(s)
    MSI HD Radeon 6450 DVI Output
    Sound Card
    Realtek onooard Creative or Other separate PENDING
    Monitor(s) Displays
    VIZIO 32" LCD TV Separate LCD Pending
    Screen Resolution
    1600x1080
    Hard Drives
    WD 500GB OS Host/Boot WD Green 1TB Storage/Backup
    PSU
    Corsair 600W - THERMALTAKE 600W spare case
    Case
    NZXT Vulcan mini tower
    Cooling
    Twin 120mm Top Fans - 240mm Side Cover
    Keyboard
    ONN Cordless/USB Logitech Cordless
    Mouse
    ONN USB/Cordless - Logitech Cordless
    Internet Speed
    DSL 5G
    Browser
    MS Edge, FireFox, WaterFox x64, FireFox Nightly
    Other Info
    OS Testing-Remote Access to Main TeamViewer
This is what the spammed email looks like. If recipients click on the link, it takes them to a bogus website where they're asked to register their details for a vaccination. Clicking through takes them to a "Download Archive" link, which triggers the malicious executable.
 

Attachments

  • Capture9.JPG
    Capture9.JPG
    35 KB · Views: 7

My Computer My Computer

At a glance

XP Pro/Vista Ultimate (64)/Windows 7 Ultimate...Core 2 Duo E8500 @ stock8Gb (4 X 2Gb) Corsair Dominator 1066Mhz DDR2XFX ATI Radeon 4870 1Gb
OS
XP Pro/Vista Ultimate (64)/Windows 7 Ultimate Signature Edition(64)
CPU
Core 2 Duo E8500 @ stock
Motherboard
Gigabyte EP45-UD3R
Memory
8Gb (4 X 2Gb) Corsair Dominator 1066Mhz DDR2
Graphics Card(s)
XFX ATI Radeon 4870 1Gb
Sound Card
Onboard 7.1
Monitor(s) Displays
BenQ E2200Hd, Asus VW161D, HP L1506
Screen Resolution
1920 X 1080
Hard Drives
Seagate 7200.12 500Gb
2 X Hitachi 1Tb
PSU
CoolerMaster 650 EPD
Case
Thermaltake
Cooling
2 X Noctua 120mm's, Stock Intel
Keyboard
Logitech
Mouse
Logitech
I just ran into another reference with a different title on the article pointing where the servers are according to McAfee.

According to rival security company McAfee, the fake CDC site is being hosted on servers located in Argentina, Chile, Colombia, Brazil, India and Malaysia.

Messages arrive bearing subject lines such as "State Vaccination H1N1 Program, "Governmental registration program on the H1N1 vaccination" and "Create your personal Vaccination Profile," McAfee added.

The full page report is seen at Botnet continues massive H1N1 malware campaign
 

My Computers My Computers

  • At a glance

    W7 Ultimate x64/W10 Pro x64/W11 Pro Triple Bo...AMD Phenom II X4 975 Deneb 3.6ghz - 965 2nd r...Kingston Hyper X DDR3 1600 1.5v 16gb - Hyper ...MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 o...
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    Custom builds = 2
    OS
    W7 Ultimate x64/W10 Pro x64/W11 Pro Triple Boot - Main PC W7 Remote PC Micro ATX W7 Pro x64/W11 Pro
    CPU
    AMD Phenom II X4 975 Deneb 3.6ghz - 965 2nd remote pc
    Motherboard
    Gigabyte GA-790XTA-UD4-Gigabyte GA-880GM-D2H remote pc
    Memory
    Kingston Hyper X DDR3 1600 1.5v 16gb - Hyper X Fury 8gb 2nd
    Graphics Card(s)
    MSI HD Radeon 5750 1gb - MSI HD Radeon 6450 on mini tower
    Sound Card
    Creative Labs X-Fi Xtreme Audio P - Realtek onooard 2nd case
    Monitor(s) Displays
    ASUS VW199T-P 19" HP 2082a Main-HP 2082a 20" remote pc
    Screen Resolution
    Asus 1440x900 - HP 1600x900
    Hard Drives
    WD Black 1TB HD per OS W7, W10, and pending W11 presently on 500gb OS Drive - Pending Triple 1TB HDs for Spanned Storage/backup volume
    Single 2TB external USB enclosure, single 1TB System 7 Host/Boot drive, Pending 8TB external HD for system image b
    PSU
    Corsair 750TX - primary / Corsair CX600 - second
    Case
    Antec 900-2 - SSD compatible / NZXT Vulcan mini tower
    Cooling
    Zalman CNPS9900A
    Keyboard
    AZIO L70 Backlit Letters Gaming - ONN Cordless/USB
    Mouse
    MSI DS200 Programmable, Logitech Cordless
    Internet Speed
    30mbps upgrade - primary hard wired - mini tower usb WiFi
    Antivirus
    GFI VIPRE Internet Security 2014 on W7 2016 beta on W10,
    Browser
    Cyberfox, WaterFox 64bit FF variants, FireFox x64, Pale Moon
    Other Info
    Accomdata fan cooled usb 2.0 PIDE/Sata II, III external enclosure.
    Sambient usb/eSata PATA/Sata II, III external enclosure.
  • At a glance

    W7 Pro x64/W11 ProAMD Deneb 3.6ghz - 965Kingston Hyper X Fury 8gbMSI HD Radeon 6450 DVI Output
    Computer type
    PC/Desktop
    System Manufacturer/Model Number
    CUSTOM ASSEMBLY
    OS
    W7 Pro x64/W11 Pro
    CPU
    AMD Deneb 3.6ghz - 965
    Motherboard
    Gigabyte GA-880GM-D2H remote pc
    Memory
    Kingston Hyper X Fury 8gb
    Graphics Card(s)
    MSI HD Radeon 6450 DVI Output
    Sound Card
    Realtek onooard Creative or Other separate PENDING
    Monitor(s) Displays
    VIZIO 32" LCD TV Separate LCD Pending
    Screen Resolution
    1600x1080
    Hard Drives
    WD 500GB OS Host/Boot WD Green 1TB Storage/Backup
    PSU
    Corsair 600W - THERMALTAKE 600W spare case
    Case
    NZXT Vulcan mini tower
    Cooling
    Twin 120mm Top Fans - 240mm Side Cover
    Keyboard
    ONN Cordless/USB Logitech Cordless
    Mouse
    ONN USB/Cordless - Logitech Cordless
    Internet Speed
    DSL 5G
    Browser
    MS Edge, FireFox, WaterFox x64, FireFox Nightly
    Other Info
    OS Testing-Remote Access to Main TeamViewer
Back
Top