Obama Spam Malcode Campaigns
by Jose NazarioAt least two different malcode campaigns are afoot using the Barack Obama victory in yesterday’s U.S. presidential elections as the theme. They entice you to visit a website and then, oops, you need to download something:
Sure enough, that’s a Papras variant. An infostealer, uploads to the Ukraine. Rootkit included.
Some of the domains are using fast flux hosting:
Click to enlarge.
Two, possibly three, different campaigns are afoot. Here are the URLs I’ve seen in my inbox spamtrap today, you can see that these are different styles of URLs suggesting different campaigns:
hxxp://selfservice.demystifying.sitesurvey.rr0nzLn8m.selfservice.customerlogin.1puTDHrOM.vcoenutrmsi.com/ president.htm?/productsremote/slapiservlet/OSL.htm?LOGIN=5RUnWrr0nz&VERIFY=Ln8mxN1puTDHrOM hxxp://sitesurvey.memberverify.slapiservlet.MsjhYXouh.selfservice.memberverify.Vc5vE3oOC.lopbiuemis.com/ president.htm?/privatelogin/slapiservlet/OSL.htm?LOGIN=S5ZEoMsjhY&VERIFY=XouhveVc5vE3oOC hxxp://comreportid.verifyonenet.portalserver.c91SJDrOw.slapiservlet.customerlogin.tlFqJUdfI.bfiinwach.com/ president.htm?/onlineupdate/memberverify/OSL.htm?LOGIN=K3IrVc91SJ&VERIFY=DrOwLutlFqJUdfI hxxp://configlogin.onlineupdatemirror.sitesurvey.B7wAhptoO.securitychallenge.ptcontrol.8dBBSHuMF.wconlinenrue.com/ president.htm?/exacttrget/linkbrowse/OSL.htm?LOGIN=GwXLYB7wAh&VERIFY=ptoOqP8dBBSHuMF hxxp://ynkkm.ideaever.com/ hxxp://glptiz.ideaever.com/ hxxp://xxbomm.ideaever.com/
And a Spanish-language campaign is afoot, too. Talk about piggy backing the news.
Around the net:
- Election Day Is Over, but Election Malware Stays on the Campaign Trail from the Avert Labs blog.
- If you missed President Elect Obamas speech have some malware instead from the SANS ISC
- US Presidential Malware – Barack Obama Interview Lure from the Websense blog
- Computer Virus masquerades as Obama Acceptance Speech Video from noted spam researcher Gary Warner
- US Presidential malware from the F-Secure blog.
And many others.
Popularity: 1% [?]

