Moar Intuit Spam

Ugh, another day … another Intuit-themed Spam run. Instead of including malicious links with the URL pattern /intu.html todays spam run linked to /int-market.html. The bad links redirected victims to a Blackhole Exploit kit at migdaliasbistro[.]net.

This exploit kit dropped a Bugat/Feodo payload with the MD5 e6e3f2dd452fad8d88E8156a4fa7ca2f.

This payload retrieved its configuration file/target list via a POST request to a command and control server at hbirjhcnsuiwgtrq[.]ru/rwx/B2_9w3/in/.

Note that the domain migdaliasbistro[.]net was hosted on a fast-flux network. This domain had A records with a TTL of 900 seconds and currently resolved to 41.64.21.71 as well as 213.179.193.132. A quick review of these IPs shows that they previously hosted Blackhole Exploit kits used in previous campaigns that weve covered in our posts “Triple Barrel Spam Cannon” and “Your Intuit Order“. Domains previously hosted on these IPs include:

  • perikanzas.com
  • 110hobart.com
  • energirans.net
  • hapturing.net
  • housespect.net
  • synergyledlighting.net

The command and control server domain at hbirjhcnsuiwgtrq[.]ru was also hosted on a fast-flux network. This domain’s A record had a TTL of 60 seconds and currently resolved to the following IPs:

83.170.91.152
87.120.41.155
94.20.30.91
98.103.133.13
46.137.85.218
62.183.104.36
173.203.211.157

The fast-flux network used to host the command and control domain at hbirjhcnsuiwgtrq[.]ru appears to be a separate and distinct from the network hosting the exploit kit at migdaliasbistro[.]net. Note that the IPs hosting the hbirjhcnsuiwgtrq[.]ru domain overlap with the IPs mentioned in “The Redret Connection“.

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: