– Payment Charged

On 2012-04-09 we observed a spam template. The spam message that we observed had a subject line of “ – Payment Charged” and was sent from a Cutwail spambot.

The observed spam contained a malicious link to There were likely other spam messages associated with this campaign that contained different malicious links and had different subject lines.

The above malicious page,, contained the following javascript redirectors:

<script type=”text/javascript” src=””></script&gt;
<script type=”text/javascript” src=””></script&gt;

These javascript redirectors bounced victims to an exploit kit at

This exploit kit dropped a Pony downloader with the following properties:

Size: 147496

This Pony downloader was signed with a digital certificate labeled “4mb5gWTlIemu0h0”.

This Pony downloader was configured to send stolen FTP and other wed admin credentials to dropzones at:

Hrm, notice that the domain, home to a Pony drop in this campaign, was also home to a Blackhole Exploit kit in a previous American Express-themed spam campaign.

The above Pony downloader, DFDA409D8BCC7CDDBBB39A40E388E8BA, was also configured to download a Gameover Zeus payload from the following locations:

This Zeus payload had the following properties:

Size: 305704
MD5: D76F25DF18F89830323CD6DECD657574

Interesting … this Zeus payload was signed with the same digital cert as the above Pony downloader. The Zeus payload’s digital cert had the same “4mb5gWTlIemu0h0” label.

This Zeus variant had a botid of “NRa10”.


One Comment

  1. Posted October 1, 2012 at 11:27 pm | Permalink | Reply

    Magnificent site. Plenty of helpful information here. I am sending it to some pals ans also sharing in delicious.
    And certainly, thanks on your sweat!

One Trackback

  1. By Your Flightticket | colors on April 16, 2012 at 5:31 am

    […] have we seen that digital cert before? Oh yeah, the campaign from April 9, 2012 also signed its Pony and Zeus payloads with the same digital […]

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: