<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Botnet</title><link>http://pandalabs.pandasecurity.com/archive/tags/Botnet/default.aspx</link><description>Tags: Botnet</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Malware Campaign Impersonates Barack Obama's Website</title><link>http://pandalabs.pandasecurity.com/archive/Malware-Campaign-Impersonates-Barack-Obama_2700_s-Website.aspx</link><pubDate>Sat, 17 Jan 2009 22:32:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:952</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/952.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=952</wfw:commentRss><description>&lt;p class="MsoNormal"&gt;Today we discovered a &lt;a href="http://www.pandasecurity.com/enterprise/security-info/glossary/glossary.aspx#BOTNET" target="_blank"&gt;botnet&lt;/a&gt; controlled, fast-flux operated malware campaign
impersonating the United States President-elect Barack Obama&amp;rsquo;s website.&lt;span&gt;&amp;nbsp; &lt;/span&gt;The fake website looks just like the real
thing and attempts to bait viewers into clicking a story entitled, &amp;ldquo;Barack
Obama has refused to be a president&amp;rdquo;.&amp;nbsp; When the user clicks on the link, the malware (&lt;a href="http://www.pandasecurity.com/enterprise/security-info/about-malware/encyclopedia/overview.aspx?lst=vis&amp;amp;idvirus=204499&amp;amp;sitepanda=empresas"&gt;W32\Iksmas.A.worm&lt;/a&gt;) begins to download all of the necessary files needed to host the fake site on the victims computer.&amp;nbsp; &lt;br /&gt;
&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-left:0.5in;"&gt;&lt;strong&gt;&lt;em&gt;Excerpt:&lt;/em&gt;&lt;/strong&gt;&lt;em&gt; Barack Obama&amp;#39;s inauguration that was
planned on 20th January 2009 is under the threat of failure. On the Eve of
Inauguration Day President-elect Barack Obama made statement. He declared that
he is definitely NOT ready for this position. Analysts say that Barack Obama
has refused to be next president because he recognized inconsistency of his
plan of stimulating USA
economy&lt;/em&gt;&lt;/p&gt;


&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;a href="http://support.us.pandasecurity.com/Corporate/site.jpg" title="Fake Barack Obama Site" target="_blank"&gt;&lt;img alt="Barack Obama (Malware Site)" border="0" height="445" src="http://support.us.pandasecurity.com/Corporate/Post/site.jpg" title="Barack Obama (Malware Site)" width="615" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt; The attack appears to have originated from China as the
domains were purchased from a Chinese domain registrar called XINNET TECHNOLOGY
CORPORATION. &lt;span&gt;&amp;nbsp;&lt;/span&gt;Xinnet has a &lt;a href="http://spamtrackers.eu/wiki/index.php?title=Xin_Net" target="_blank"&gt;history
of abuse problems&lt;/a&gt; and we have contacted them to remove the domain
names.&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;strong&gt;The file names of the malware are&lt;/strong&gt;: &lt;/p&gt;


&lt;ul&gt;
&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;doc.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;statement.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;obamaspeech.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;blog.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;barack.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;usa.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;baracknews.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;pdf.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;news.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;obamasblog.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;barakblog.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;statement.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;president.exe&lt;/li&gt;

&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;obamanews.exe&lt;/li&gt;
&lt;/ul&gt;


&lt;p class="MsoNormal"&gt;&lt;strong&gt;Visual Representation
of the domains:&lt;/strong&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://support.us.pandasecurity.com/Corporate/Post/visual.jpg"&gt;&lt;img alt="Visual Representation of Malware Site" border="0" height="494" src="http://support.us.pandasecurity.com/Corporate/Post/visual.jpg" title="Visual Representation of Malware Site" width="638" /&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;strong&gt;Fast&lt;/strong&gt;-&lt;strong&gt;Flux Representation (1 of 40 domains)&lt;/strong&gt;:&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;span&gt;
 
&lt;a href="http://support.us.pandasecurity.com/Corporate/Post/fastflux.jpg" target="_blank"&gt;&lt;img alt="Barack Obama - Fast-Flux" border="0" height="285" src="http://support.us.pandasecurity.com/Corporate/Post/fastflux.jpg" title="Barack Obama - Fast-Flux" width="675" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;strong&gt;Updated list to 75 domain names as of 1/20/09&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&lt;strong&gt;&lt;span style="color:red;"&gt;Note:&lt;span&gt;&amp;nbsp; &lt;/span&gt;These domains
are included for informational purposes only.&lt;span&gt;&amp;nbsp;
&lt;/span&gt;Please do not attempt to visit the sites.&lt;/span&gt;&lt;/strong&gt;&lt;span style="color:red;"&gt;&lt;/span&gt;&lt;/p&gt;



&lt;p class="MsoNormal" style="line-height:normal;"&gt;httx://bestbarack.com&lt;br /&gt;httx://bestbaracksite.com&lt;br /&gt;httx://bestchristmascard.com&lt;br /&gt;httx://bestmirabella.com&lt;br /&gt;
httx://bestobamadirect.com&lt;br /&gt;httx://bestyearcard.com&lt;br /&gt;httx://blackchristmascard.com&lt;br /&gt;httx://cardnewyear.com&lt;br /&gt;
httx://cheapdecember.com&lt;br /&gt;httx://christmaslightsnow.com&lt;br /&gt;httx://decemberchristmas.com&lt;br /&gt;httx://directchristmasgift.com&lt;br /&gt;
httx://eternalgreetingcard.com&lt;br /&gt;httx://expowale.com&lt;br /&gt;httx://freechristmassite.com&lt;br /&gt;httx://freechristmasworld.com&lt;br /&gt;
httx://freedecember.com&lt;br /&gt;httx://funnychristmasguide.com&lt;br /&gt;httx://goodnewsdigital.com&lt;br /&gt;httx://goodnewsreview.com&lt;br /&gt;
httx://greatbarackguide.com&lt;br /&gt;httx://greatmirabellasite.com&lt;br /&gt;httx://greatobamaguide.com&lt;br /&gt;
httx://greatobamaonline.com&lt;br /&gt;httx://greetingcardcalendar.com&lt;br /&gt;httx://greetingcardgarb.com&lt;br /&gt;
httx://greetingguide.com&lt;br /&gt;httx://greetingsupersite.com&lt;br /&gt;httx://holidayxmas.com&lt;br /&gt;httx://itsfatherchristmas.com&lt;br /&gt;
httx://jobarack.com&lt;br /&gt;httx://justchristmasgift.com&lt;br /&gt;httx://lifegreetingcard.com&lt;br /&gt;httx://linkworldnews.com&lt;br /&gt;
httx://livechristmascard.com&lt;br /&gt;httx://livechristmasgift.com&lt;br /&gt;httx://mirabellaclub.com&lt;br /&gt;httx://mirabellamotors.com&lt;br /&gt;
httx://mirabellanews.com&lt;br /&gt;httx://mirabellaonline.com&lt;br /&gt;httx://newlifeyearsite.com&lt;br /&gt;httx://newmediayearguide.com&lt;br /&gt;
httx://newyearcardcompany.com&lt;br /&gt;httx://newyearcardfree.com&lt;br /&gt;httx://newyearcardonline.com&lt;br /&gt;
httx://newyearcardservice.com&lt;br /&gt;httx://reportradio.com&lt;br /&gt;httx://smartcardgreeting.com&lt;br /&gt;httx://spacemynews.com&lt;br /&gt;
httx://superchristmasday.com&lt;br /&gt;httx://superchristmaslights.com&lt;br /&gt;httx://superobamadirect.com&lt;br /&gt;
httx://superobamaonline.com&lt;br /&gt;httx://superyearcard.com&lt;br /&gt;httx://thebaracksite.com&lt;br /&gt;httx://themirabelladirect.com&lt;br /&gt;
httx://themirabellaguide.com&lt;br /&gt;httx://themirabellahome.com&lt;br /&gt;httx://topgreetingsite.com&lt;br /&gt;httx://topwale.com&lt;br /&gt;
httx://uperobamadirect.com&lt;br /&gt;httx://waledirekt.com&lt;br /&gt;httx://waleonline.com&lt;br /&gt;httx://waleprojekt.com&lt;br /&gt;
httx://wapcitynews.com&lt;br /&gt;httx://whitewhitechristmas.com&lt;br /&gt;httx://worldgreetingcard.com&lt;br /&gt;httx://worldnewsdot.com&lt;br /&gt;
httx://worldnewseye.com&lt;br /&gt;httx://worldtracknews.com&lt;br /&gt;httx://yourchristmaslights.com&lt;br /&gt;httx://yourdecember.com&lt;br /&gt;
httx://yourmirabelladirect.com&lt;br /&gt;httx://yourregards.com&lt;br /&gt;httx://youryearcard.com
&lt;/p&gt;

&lt;p class="MsoNormal"&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=952" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Botnet/default.aspx">Botnet</category></item></channel></rss>