<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Heads Up - PayPal infection attempt - New?? in Security</title>
<link>http://www.dslreports.com/forum/r8498880</link>
<description></description>
<language>en</language>
<pubDate>Wed, 25 Nov 2009 08:07:56 EDT</pubDate>
<lastBuildDate>Wed, 25 Nov 2009 08:07:56 EDT</lastBuildDate>

<item>
<title>Re: Heads Up - PayPal infection attempt - New??</title>
<link>http://www.dslreports.com/forum/remark,8503688</link>
<description><![CDATA[<A HREF="/useremail/u/590730"><b>Randy Bell</b></A> : See also this sister thread: &raquo;<A HREF="/forum/remark,8500671~root=security,1~mode=flat">W32.Paylap@mm</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8503688</guid>
<pubDate>Fri, 14 Nov 2003 13:51:58 EDT</pubDate>
</item>

<item>
<title>Re: Heads Up - PayPal infection attempt - New??</title>
<link>http://www.dslreports.com/forum/remark,8503660</link>
<description><![CDATA[<A HREF="/useremail/u/667355"><b>wilburyan</b></A> : I clicked on the link, instead of getting the spoofed site I wasn't able to connect to it so my default search thru netscape searched for it for me.... The first 5 hits had the subject "E-mail scam" lol]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8503660</guid>
<pubDate>Fri, 14 Nov 2003 13:49:02 EDT</pubDate>
</item>

<item>
<title>Re: Heads Up - PayPal infection attempt - New??</title>
<link>http://www.dslreports.com/forum/remark,8500983</link>
<description><![CDATA[<A HREF="/useremail/u/795677"><b>illukka</b></A> :  hey great work Vampirefo! any chance of getting a sample?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8500983</guid>
<pubDate>Fri, 14 Nov 2003 05:00:21 EDT</pubDate>
</item>

<item>
<title>Re: Heads Up - PayPal infection attempt - New??</title>
<link>http://www.dslreports.com/forum/remark,8500913</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : I submitted this virus to a couple of the AV's and McAfee has added it as &raquo;<A HREF="http://vil.nai.com/vil/content/v_100822.htm" >vil.nai.com/vil/content/v_100822.htm</A><br><br>As you can see Vampirefo nailed this one rather well.  He also mentioned the IP addresses that the virus sends the data to.  I didn't want to publish those until I found out if someone was 'watching' those IP addresses as one was in the US.  The IP in question are 68.168.160.2 and 62.84.131.172.  NOTE full credit to Vamp for nailing this so quick.<br><br>I should also note that E-trust nailed it as Win32/Mimail.xariant.worm from the start so it would appear in this case they were ahead of McAfee.<br><br>- From McAfee -<br><br>This W32/Mimail variant attempts to steal credit card information by displaying a fake PayPal message as shown below. The user's information is stored in a file named ppinfo.sys , which is sent to a remote server. <br><br>This worm is received in an email message as follows:<br><br>From: "PayPal.com" donotreply@paypal.com <br>Subject: YOUR PAYPAL.COM ACCOUNT EXPIRES<br><br>Dear PayPal member, <br><br>PayPal would like to inform you about some important information regarding your PayPal account. This account, which is associated with the email address will be expiring within five business days. We apologize for any inconvenience that this may cause, but this is occurring because all of our customers are required to update their account settings with their personal information. We are taking these actions because we are implementing a new security policy on our website to insure everyone's absolute privacy. To avoid any interruption in PayPal services then you will need to run the application that we have sent with this email (see attachment) and follow the instructions. Please do not send your personal information through email, as it will not be as secure. IMPORTANT! If you do not update your information with our secure application within the next five business days then we will be forced to deactivate your account and you will not be able to use your PayPal account any longer. It is strongly recommended that you take a few minutes out of your busy day and complete this now. DO NOT REPLY TO THIS MESSAGE VIA EMAIL! This mail is sent by an automated message system and the reply will not be received. Thank you for using PayPal<br><br>Attachment (one of the following): <br><br>paypal.asp.scr <br>www.paypal.com.scr<br> <br>When the attachment is run, the following Window is displayed:<br><br>See the image at &raquo;<A HREF="http://vil.nai.com/vil/content/v_100822.htm" >vil.nai.com/vil/content/v_100822.htm</A><br>  <br><br>Mail Propagation <br>The worm emails itself to addresses found on the infected computer.  Target email addresses are harvested from files on the victim's machine.  The worm ignores address extraction from files that contain the following extensions:<br><br>avi <br>bmp <br>cab <br>com <br>dll <br>exe <br>gif <br>jpg <br>mp3 <br>mpg <br>ocx <br>pdf <br>psd <br>rar <br>tif <br>vxd <br>wav <br>zip <br> <br>Symptoms <br> <br>The following registry key is added to run the virus at startup:<br><br>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\<br>Run "SvcHost32" = C:\WINDOWS\svchost32.exe <br>The worm creates the following files:<br><br>c:\pp.gif (paypal icon) <br>c:\pp.hta (graphical interface) <br>c:\ppinfo.sys (your credit card details) <br>c:\WINDOWS\ee98af.tmp (virus body) <br>c:\WINDOWS\el388.tmp (harvested email addresses) <br>c:\WINDOWS\svchost32.exe (virus body) <br>c:\WINDOWS\zp3891.tmp <br><br>Note: c:\WINDOWS is just an example of a Windows directory name.  The worm does not use this exact name.  It simply uses the system WINDOWS directory.   d:\WINNT is another example of a Windows directory name. <br><br>The worm checks for an active Internet connection by pinging www.akamai.com  <br><br>Method Of Infection  <br>This virus spreads via email.  Manually running the attachment infects the local machine.<br> <br>Removal Instructions  <br>All Users:<br>Use specified engine and DAT files for detection and removal.<br><br>Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).<br><br>Aliases  <br>Name  <br>W32.Paylap@mm (NAV)  <br><SMALL>--<br>&raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - Logging Software for SonicWall and 3Com<br>&raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Logging Software for Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8500913</guid>
<pubDate>Fri, 14 Nov 2003 04:06:22 EDT</pubDate>
</item>

<item>
<title>Re: Heads Up - PayPal infection attempt - New??</title>
<link>http://www.dslreports.com/forum/remark,8499597</link>
<description><![CDATA[<A HREF="/useremail/u/832484"><b>broknsymetry</b></A> : Almost gave me a heart attack when I viewed clipboard4.gif from your zip file.  I thought McAfee was really giving me a filtering rule alert for svchost32.exe, ROFLMAO <IMG SRC="http://i.dslr.net/bb/vbull_coll/icon10.gif"><br><SMALL>--<br>Some scientist may at last disperse<BR>The mysteries of the universe<BR>But me, I can not even think<BR>Why pork is white and ham is pink<BR>--Ogden Nash</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8499597</guid>
<pubDate>Thu, 13 Nov 2003 23:00:45 EDT</pubDate>
</item>

<item>
<title>Re: Heads Up - PayPal infection attempt - New??</title>
<link>http://www.dslreports.com/forum/remark,8499523</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : Fast and good work Vampirefo as it would appear you have nailed it.<br><br>Where does it send the information too?<br><br>Blake<br><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8499523</guid>
<pubDate>Thu, 13 Nov 2003 22:51:13 EDT</pubDate>
</item>

<item>
<title>Re: Heads Up - PayPal infection attempt - New??</title>
<link>http://www.dslreports.com/forum/remark,8499460</link>
<description><![CDATA[<A HREF="/useremail/u/260736"><b>Vampirefo</b></A> : Ok, you have a new Trojan Dropper, very interesting one, it does a lot of things. It drops pp.gif and pp.hta in root and it runs pp.hta and asks for credit card number, Then it drops ee98af.tmp,and el388.tmp in windows folder. The el388.tmp (copies your e-mail addreses), It then drops a Trojan svchost32.exe in windows folder, then it adds itself to registry.<br> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SvcHost32 = 'G:\WINDOWS\svchost32.exe'<br><br>It then records all your e-mail address, contacts, and any e-mail address in any of your folders inbox, sent, deleted then it try's to connect to internet and send all of this information as well as your credit card number.<br><br>Here is some pics of what it does.<br><SMALL>--<br>TrojanHunter Stands For Privacy!!!!!!!</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/r0/download/467503~78e3c9b223deadfa448976d6fe0e8968/NewCompressedzippedFolder.zip"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/compress.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>NewCompresse&middot;&middot;&middot;lder.zip</big></A> <small>77,923 bytes</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8499460</guid>
<pubDate>Thu, 13 Nov 2003 22:44:01 EDT</pubDate>
</item>

<item>
<title>Re: Heads Up - PayPal infection attempt - New??</title>
<link>http://www.dslreports.com/forum/remark,8499339</link>
<description><![CDATA[<A HREF="/useremail/u/517760"><b>catseyenu</b></A> : query: 211.47.191.125<br><br># ENGLISH<br><br>KRNIC is not ISP but National Internet Registry similar with APNIC.<br>Please see the following end-user contacts for IP address information.<br><br>IP Address         : 211.47.191.64-211.47.191.127<br>Network Name       : HANINTERNET-LLINE-E2B<br>Connect ISP Name   : HANINTERNET<br>Connect Date       : 20021223<br>Registration Date  : 20030108<br><br>[ Organization Information ]<br>Orgnization ID     : ORG265243<br>Org Name           : E2B <br>State              : SEOUL<br>Address            : 8, Samseong-dong , Gangnam-gu<br>Zip Code           : 135-090<br><br>[ Admin Contact Information]<br>Name               : SIJUN JIN<br>Org Name           : E2B<br>State              : SEOUL<br>Address            : 8, Samseong-dong , Gangnam-gu<br>Zip Code           : 135-090<br>Phone              : +82-2-3775-0002<br>E-Mail             : DK_SUH@E2B.CO.KR<br><br>[ Technical Contact Information ]<br>Name               : SIJUN JIN<br>Org Name           : E2B<br>State              : SEOUL<br>Address            : 8, Samseong-dong , Gangnam-gu<br>Zip Code           : 135-090<br>Phone              : +82-2-3775-0002<br>E-Mail             : DK_SUH@E2B.CO.KR<br><br>--------------------------------------------------------------------------------<br><br>If the above contacts are not rechable, please see the following ISP contacts<br>for relevant information or network abuse complaints.<br><br>[ ISP IP Admin Contact Information ]<br>Name               : YoungDong Kim<br>Phone              : +82-2-860-8143<br>Fax                : +82-2-852-8535<br>E-Mail             : iservice@haninternet.co.kr<br><br>[ ISP IP Tech Contact Information ]<br>Name               : Raeeun Yeo<br>Phone              : +82-2-860-8144<br>Fax                : +82-2-852-8535<br>E-Mail             : ip@haninternet.co.kr<br><br>[ ISP Network Abuse Contact Information ]<br>Name               : Sangwon So<br>Phone              : +82-2-860-8002<br>Fax                : +82-2-852-8535<br>E-Mail             : support@haninternet.co.kr<br><br>Edit for Korean oops.<br><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8499339</guid>
<pubDate>Thu, 13 Nov 2003 22:30:02 EDT</pubDate>
</item>

<item>
<title>Re: Heads Up - PayPal infection attempt - New??</title>
<link>http://www.dslreports.com/forum/remark,8499328</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : The email address it was sent to was harvested from our web site as we don't use webmaster@linklogger.com for anything other then inbound email.<br><br>Of course the email didn't come from PayPal<br><br>Email Header etc.<br>-------------------------<br>Return-path: <br>Envelope-to: 1001040161@mail.golden.net<br>Delivery-date: Thu, 13 Nov 2003 20:56:43 -0500<br>Received: from exprod6mx13.postini.com ([12.158.35.153] helo=psmtp.com)<br>	by mail2.int.golden.net with smtp (Exim 4.12)<br>	id 1AKTCV-0004R5-00<br>	for 1001040161@mail.golden.net; Thu, 13 Nov 2003 20:56:43 -0500<br>Received: from source ([199.166.210.22]) by exprod6mx13.postini.com ([12.158.35.251]) with SMTP;<br>	Thu, 13 Nov 2003 19:56:40 CST<br>Received: from pcp289634pcs.owngsm01.md.comcast.net ([68.55.140.24] helo=68.55.140.24)<br>	by mail3.int.golden.net with smtp (Exim 4.12)<br>	id 1AKTCO-000Lin-00<br>	for webmaster@linklogger.com; Thu, 13 Nov 2003 20:56:36 -0500<br>Date: Thu, 13 Nov 2003 20:47:47 -0500<br>From: PayPal.com <br>X-Mailer: Microsoft Outlook Express 6.00.2800.1106<br>Reply-To: donotreply@paypal.com<br>Organization: None<br>X-Priority: 1 (High)<br>To: webmaster@linklogger.com<br>Subject: YOUR PAYPAL.COM ACCOUNT EXPIRES<br>MIME-Version: 1.0<br>Content-Type: multipart/mixed; boundary="----------716A2B1C01688342"<br>Message-Id: <br>X-original-rcpt: webmaster@linklogger.com<br>X-pstn-levels:     (S:16.1782 R:95.9108 P:95.9108 M:92.5706 C:96.3115 )<br>X-pstn-settings: 3 (1.0000:1.0000) r p m c <br>X-pstn-addresses: from  [2310/105] <br><br>------------716A2B1C01688342<br>Content-Type: text/plain; charset=us-ascii<br>Content-Transfer-Encoding: 7bit<br><br>Dear PayPal member,<br><br>PayPal would like to inform you about some important information regarding your PayPal account. This account, which is associated with this email address will be expiring within five business days.  We apologize for any inconvenience that this may cause, but this is occurring because all of our customers are required to update their account settings with their personal information.<br><br>We are taking these actions because we are implementing a new security policy on our website to insure everyone's absolute privacy. To avoid any interruption in PayPal services then you will need to run the application that we have sent with this email (see attachment) and follow the instructions. Please do not send your personal information through email, as it will not be as secure.<br><br>IMPORTANT! If you do not update your information with our secure application within the next five business days then we will be forced to deactivate your account and you will not be able to use your PayPal account any longer. It is strongly recommended that you take a few minutes out of your busy day and complete this now.<br><br>DO NOT REPLY TO THIS MESSAGE VIA EMAIL! This mail is sent by an automated message system and the reply will not be received.<br><br>Thank you for using PayPal.<br><br>------------716A2B1C01688342<br>Content-Type: application/octet-stream; name="paypal.asp.scr"<br>Content-Transfer-Encoding: base64<br>Content-Disposition: attachment; filename="paypal.asp.scr"<br><SMALL>--<br>&raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - Logging Software for SonicWall and 3Com&raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Logging Software for Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8499328</guid>
<pubDate>Thu, 13 Nov 2003 22:29:23 EDT</pubDate>
</item>

<item>
<title>Re: Heads Up - PayPal infection attempt - New??</title>
<link>http://www.dslreports.com/forum/remark,8499167</link>
<description><![CDATA[<A HREF="/useremail/u/328681"><b>ReaperOS2</b></A> : Hhhmmm. I received a different one today. It is using the web redirect, to make you think you are going to PayPal's website. But it sends you to 211.47.191.125.<br><br>The link is below, so do not click on it. You can see where it is being directed to.<br><br>For what it's worth, here's the message:<br><br>------------------------------------------------------<br><br>Status:  U<br>Return-Path: <br>Received: from microsoft.com ([195.19.105.182])<br>	by albert.mail.atl.earthlink.net (EarthLink SMTP Server) with SMTP id 1akiSG31A3Nl3qU0<br>	for ; Thu, 13 Nov 2003 09:55:26 -0500 (EST)<br>Date: Thu, 13 Nov 2003 15:14:31 +0000<br>From: PayPal <br>Subject: PayPaI officiaI notice<br>To: ReaperOS2 <br>References: <br>In-Reply-To: <br>Message-ID: <br>Reply-To: PayPal <br>Sender: PayPal <br>MIME-Version: 1.0<br>Content-Type: multipart/related; boundary="----=_NextPart_K19EJ_48GJ9J98J4AK_701B4H"<br>X-ELNK-AV: 0<br><br>------=_NextPart_K19EJ_48GJ9J98J4AK_701B4H<br>Content-Type: text/html<br>Content-Transfer-Encoding: 8bit<br><br> <br><A HREF="http://www.paypal.com%2Ecgi-bin%2Ewebscr%2E%63%6D%64=%5F%72%61%76%2D%66%6F%72%6D@%32%31%31%2E%34%37%2E%31%39%31%2E%31%32%35:%31%39%39/%63%67%69/%69%6E%64%65%78%2E%68%74%6D"><IMG SRC="cid:pic.gif"></A><br>as follows in 2007 CUD you can't miss it have got let me see... in 1989 nGHJFlq bjlQZilzYHJ Xe</font><br>in 1947 in 1899 in 1886 536 in 1988 1 In my view 214 I feel deeply for your sorrow in 1870</font><br>Just a moment! to see you in 2005 on that? Lovely day in 1968 mTG to sign here in 1992 I enjoy it... in 1987 be sure I trust you</font><br></A><br><br>------=_NextPart_K19EJ_48GJ9J98J4AK_701B4H<br>Content-Type: image/gif; name="pic.gif"<br>Content-Transfer-Encoding: base64<br>Content-Disposition: attachment; filename="pic.gif"<br>Content-ID: <br><br>[Removed pic.gif to limit lenght.]<br><br>------=_NextPart_K19EJ_48GJ9J98J4AK_701B4H--<br><br>-------------------------------------------------<br><br>Later,<br>Grim<br><SMALL>--<br>DVD Collector; <BR>"I'm already Warped! Do I need the software, too?"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8499167</guid>
<pubDate>Thu, 13 Nov 2003 22:08:45 EDT</pubDate>
</item>

<item>
<title>Heads Up - PayPal infection attempt - New??</title>
<link>http://www.dslreports.com/forum/remark,8498880</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : I received an email tonight that was obviously bogus and had an attachment which didn't set off McAfee so I'm thinking it must be new.  The subject was 'YOUR PAYPAL.COM ACCOUNT EXPIRES' and the body was a follows:<br>---------------------------<br>Dear PayPal member,<br><br>PayPal would like to inform you about some important information regarding your PayPal account. This account, which is associated with this email address will be expiring within five business days.  We apologize for any inconvenience that this may cause, but this is occurring because all of our customers are required to update their account settings with their personal information.<br><br>We are taking these actions because we are implementing a new security policy on our website to insure everyone's absolute privacy. To avoid any interruption in PayPal services then you will need to run the application that we have sent with this email (see attachment) and follow the instructions. Please do not send your personal information through email, as it will not be as secure.<br><br>IMPORTANT! If you do not update your information with our secure application within the next five business days then we will be forced to deactivate your account and you will not be able to use your PayPal account any longer. It is strongly recommended that you take a few minutes out of your busy day and complete this now.<br><br>DO NOT REPLY TO THIS MESSAGE VIA EMAIL! This mail is sent by an automated message system and the reply will not be received.<br><br>Thank you for using PayPal.<br>---------------------------<br><br>The attachment was named 'paypal.asp.scr'  Of course I didn't run it as the scr is a give away and after loading it into a hex editor its a virus.  Anyone want a copy for diagnoses send me an IM with your email address.<br><br>Blake]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,8498880</guid>
<pubDate>Thu, 13 Nov 2003 21:36:56 EDT</pubDate>
</item>

</channel>
</rss>
