Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 22nd, 2007, 12:49 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,804
Default Dutchies, probably new phishing

In Dutch and in English:

English:

I've just seen an email in my Mailwasher Pro.
It "looks" like it is coming from a Dutch bank ABNAmro.
The mail is in Dutch.
It is about a new SSL3 protocol.
Attached seems to be a file ms_ssl3_upd.exe
This can't be true.
I haven't yet opened it.

Here is the text of the email in Dutch:

===

Geachte gebruiker!

Onze bank houdt regelmatig toezicht over de laatste vorderingen ter tegenstrijding van netpiraten en treft steeds preventiemaatregelen om zijn klanten tegen opscheppers te beschermen. Een groep vakmensen op het gebied van computerveiligheid is te weten gekomen van een grove fout in het protocol SSL, die door een hacker kan worden gebruikt om toegang te krijgen tot uw bankrekening.

Vanaf morgen wordt er in het toegangsysteem tot klantenrekeningen een nieuw protocol SSL3 in gebruik genomen, dat op het huidige moment als het meest veilig wordt beschouwd. De klanten die gebruik maken van Internet-browsers zonder SSL3 kunnen dus geen toegang krijgen tot hun bankrekeningen via het Intenet.

U dient uw browser te vernieuwen. Onze vakmensen hebben de vernieuwingen voor alle browsertypes uitgewerkt. De vernieuwing is aan deze brief bijgelegd. U hoeft de programma-module gewoon te starten en de vernieuwing wordt automatisch opgeslagen.

De programmamodule ms_ssl3_upd.exe is bijgelegd.

Bedankt voor uw ondersteuning en wij hopen verder met u samen te werken.

===
  #2  
Old March 22nd, 2007, 02:07 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: Dutchies, probably new phishing

Save that file to disk (don´t execute it), upload it to VirusTotal and Jotti.
Then, send it compressed and password-protected to AV companies with a short description in the body message.
__________________
"Pouvoir ā l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.

Last edited by lucas1985 : March 22nd, 2007 at 02:15 PM.
  #3  
Old March 22nd, 2007, 02:32 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,717
Default Re: Dutchies, probably new phishing

I got that too.
The attachment:
875.exe - infected by Trojan-Spy.Win32.Banker.cmb

I posted in the Dutch section at CC:
http://www.castlecops.com/postlite183420-.html
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #4  
Old March 22nd, 2007, 03:33 PM
gerardwil gerardwil is online now
Massive Poster
 
Join Date: Jan 2004
Posts: 4,509
Default Re: Dutchies, probably new phishing

I guess to follow soon one from Barclays
(by the way I get warned of this via my handy, but a little late. I read about it 24 hours before my handy warning)

Gerard
  #5  
Old March 22nd, 2007, 04:05 PM
Old Monk's Avatar
Old Monk Old Monk is offline
Frequent Poster
 
Join Date: Feb 2005
Location: Sheffield, UK
Posts: 632
Default Re: Dutchies, probably new phishing

Quote:
Originally Posted by gerardwil
I guess to follow soon one from Barclays
(by the way I get warned of this via my handy, but a little late. I read about it 24 hours before my handy warning)

Gerard

Hi

I got a phish Barcays mail last week at work. Forwarded it to Barclays security. Pretty amateurish one though.
__________________
Cheers

Jon
  #6  
Old March 22nd, 2007, 04:10 PM
gerardwil gerardwil is online now
Massive Poster
 
Join Date: Jan 2004
Posts: 4,509
Default Re: Dutchies, probably new phishing

Hi Jan (FanJ),

I am sure you have noticed that is pretty poor Dutch language.

Gerard
  #7  
Old March 22nd, 2007, 04:38 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,717
Default Re: Dutchies, probably new phishing

Yeah, makes you wonder how they ended up using:

"protecting our customers against braggers"
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #8  
Old March 22nd, 2007, 04:39 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,804
Default Re: Dutchies, probably new phishing

Hi Lucas,

Thanks; that was exactly what I was planning to do ( ), but other things got in the way before I had the opportunity to look further at it.

Hoi Pieter en Gerard,
Sorry dat het even duurde voordat ik er verder naar kon gaan kijken.
Bedankt voor jullie berichten !
Pieter, het wordt echt tijd dat ik me daar ook eens laat zien
Begrijp ik dat het niet zoveel nut meer heeft om het bestand op te sturen naar de diverse AV/AT/AS firma's?
LOL Gerard, zoiets dacht ik ook meteen.

Groetjes, Jan.
  #9  
Old March 22nd, 2007, 04:42 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,717
Default Re: Dutchies, probably new phishing

The file was made available to the AV's FanJ.
dvk01 helped me do that, since I was at work when I got that mail.

Groetjes,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #10  
Old March 22nd, 2007, 04:45 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,804
Default Re: Dutchies, probably new phishing

OK, thanks a lot Pieter (and Derek) !
  #11  
Old March 22nd, 2007, 04:45 PM
gerardwil gerardwil is online now
Massive Poster
 
Join Date: Jan 2004
Posts: 4,509
Default Re: Dutchies, probably new phishing

Quote:
Originally Posted by FanJ
Begrijp ik dat het niet zoveel nut meer heeft om het bestand op te sturen naar de diverse AV/AT/AS firma's?
Groetjes, Jan.

I guess it is well known now everywhere
Greetz,

Gerard
  #12  
Old March 22nd, 2007, 05:55 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,804
Default Re: Dutchies, probably new phishing

Hi,

In the meanwhile I understood that today a warning was broadcasted here in Holland on the radio.

The filename of the nasty that I got, is: 599.exe

~ Online virus scan results removed. Please send any samples to the respective antivirus vendors. Menorcaman ~

Last edited by Menorcaman : March 22nd, 2007 at 06:19 PM.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:06 AM.


Powered by vBulletinŪ Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright Đ2002 - 2013, Wilders Security Forums