Found in large spammimg runs, a series of URLs in the form
hxxp//
:session99599080480050.permitfg.com/confirm/req/
hxxp
://session
98960786197613.pmstdl.com/confirm/req/
hxxp
://session
98204351586916.downtohole.com/confirm/req/
hxxp
://session
00239061301752.fileuplarc.com/confirm/req/
The 14 digit number varies.
permitfg.com Registrar: PAKNIC (PRIVATE) LIMITED
pmstdl.com Registrar: REGIONAL NETWORK INFORMATION CENTER, JSC DBA RU-CENTER [Client Hold]
downtohole.com Registrar: PAKNIC (PRIVATE) LIMITED
fileuplarc.com Registrar: PLANETDOMAIN PTY LTD.
The URL loads a spoofed Facebook login page complete with the Facebook favicon.
The page contains:
Quote:
Facebook Login
Your version of Macromedia Flash Player is too old to continue. Download and install the latest version of Adobe Flash Player.
If you click on the link to download "updateflash.exe" you are downloading the dangerous Zbot trojan. The primary payload of Trojan:W32/Zbot variants focuses on stealing online banking information.
A few samples from over 2000 I have seen in the past week
Code:
session97698057793601.downtohole.com/confirm/req/
session97728784838062.downtohole.com/confirm/req/
session99427076617378.fileuplarc.com/confirm/req/
session99485503555366.fileuplarc.com/confirm/req/
session99525797920572.downtohole.com/confirm/req/
session99916841992131.downtohole.com/confirm/req/
session99932245150373.fileuplarc.com/confirm/req/
session99960289962058.fileuplarc.com/confirm/req/
The domains run on the same botnet, too:
fileuplarc.com has address 66.159.180.140
fileuplarc.com has address 71.217.16.172
fileuplarc.com has address 83.221.72.119
fileuplarc.com has address 114.134.131.217
fileuplarc.com has address 178.24.192.186
fileuplarc.com has address 217.50.208.61
downtohole.com has address 66.159.180.140
downtohole.com has address 71.217.16.172
downtohole.com has address 83.221.72.119
downtohole.com has address 114.134.131.217
downtohole.com has address 178.24.192.186
downtohole.com has address 217.50.208.61
permitfg.com has address 62.42.16.182
permitfg.com has address 82.158.170.45
permitfg.com has address 83.138.205.124
permitfg.com has address 85.85.109.1
permitfg.com has address 94.223.194.61
permitfg.com has address 201.173.234.222