MalwareMustDie

Phishing Infection of "paypalcgi-bin=" and "cgi-binonline"

Oct 26th, 2012
2,204
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
HTML 7.98 KB | None | 0 0
  1. #MalwareMustDie | Fri Oct 26 23:00:49 JST 2012 | @unixfreaxjp
  2.  
  3. // Found interesting urls..
  4. h00p://milapapier.pl/wp-content/uploads/2012/10/cn/2012/Alert/verification/update.account/paypalmember/cgi-binonline-security=paypalcgi-bin=_connexiononline_securSecurity-paypal.htm
  5.  
  6. ---------------------------------investigations--------------------------------------------------------
  7.  
  8. // tor wouldn't access it..
  9. "h00p_proxy = blash"
  10. --output-document="./sample"
  11. --referer="h00p://www.google.com/search?q=youtube"
  12. --user-agent="Mozila/4.3 (X11; U; MacOSX i686)"
  13. "h00p://milapapier.pl/wp-content/uploads/2012/10/cn/2012/Alert/verification/update.account/paypalmember/cgi-binonline-security=paypalcgi-bin=_connexiononline_securSecurity-paypal.htm"
  14.  
  15. --21:55:01--  h00p://milapapier.pl/wp-content/uploads/2012/10/cn/2012/Alert/veri
  16. fication/update.account/paypalmember/cgi-binonline-security=paypalcgi-bin=_conne
  17. xiononline_securSecurity-paypal.htm
  18.            => `./sample'
  19. Connecting to 192.168.7.11:8118... connected.
  20. Proxy request sent, awaiting response... 403 Forbidden
  21. 21:55:04 ERROR 403: Forbidden.
  22.  
  23. // gatling IP also won't....
  24.  
  25. --output-document="./sample" --referer="h00p://www.google.com/search?q=youtube" --user-agent="Mozilla/4.3 (X11; U; MacOSX i686)" "h00p://milapapier.pl/wp-content/uploads/2012/10/cn/2012/Alert/verification/update.account/paypalmember/cgi-binonline-security=paypalcgi-bin=_connex
  26. iononline_securSecurity-paypal.htm"
  27. --21:46:15--  h00p://milapapier.pl/wp-content/uploads/2012/10/cn/2012/Alert/veri
  28. fication/update.account/paypalmember/cgi-binonline-security=paypalcgi-bin=_conne
  29. xiononline_securSecurity-paypal.htm
  30.            => `./sample'
  31. Resolving milapapier.pl... 79.96.188.139
  32. Connecting to milapapier.pl|79.96.188.139|:80... connected.
  33. h00p request sent, awaiting response... 403 Forbidden
  34. 21:46:17 ERROR 403: Forbidden.
  35.  
  36. --------------------------who's the owner? what site? what server?--------------------
  37.  
  38. // regist details...
  39.  
  40. DOMAIN NAME:           milapapier.pl
  41. registrant type:       organization
  42. nameservers:           dns3.home.pl. [95.211.105.225]
  43.                        dns.home.pl. [62.129.252.30]
  44.                        dns2.home.pl. [62.129.252.40]
  45. created:               2009.07.28 14:42:40
  46. last modified:         2012.07.14 11:23:16
  47. renewal date:          2013.07.28 14:42:40
  48. dnssec:                Unsigned
  49.  
  50. REGISTRAR:
  51. Home.pl S.A.
  52. pl. Rodla 9
  53. 70-419 Szczecin
  54. Polska/Poland
  55. +48.914325555
  56. +48.801445555
  57.  
  58. //host checks...I am on solaris now :-)
  59. milapapier.pl has address 79.96.188.139
  60. milapapier.pl mail is handled by 10 milapapier.home.pl.
  61. milapapier.pl has SOA record dns.home.pl. admin.home.pl.
  62.               1342257796 10800 3600 604800 3600
  63. milapapier.pl name server dns.home.pl.
  64. milapapier.pl name server dns3.home.pl.
  65. milapapier.pl name server dns2.home.pl.
  66.  
  67. // snip dig for the rest...
  68. dns.home.pl.   2762 IN A   62.129.252.31
  69. dns.home.pl.   2762 IN A   62.129.252.30
  70. dns2.home.pl.  2762 IN A   62.129.252.40
  71. dns2.home.pl.  2762 IN A   62.129.252.41
  72. dns3.home.pl.  2762 IN A   95.211.105.225
  73.  
  74.  
  75. // what do we have here....
  76. PORT      STATE  SERVICE
  77. 20/tcp    closed ftp-data
  78. 21/tcp    open   ftp
  79. 24/tcp    closed priv-mail
  80. 25/tcp    open   smtp
  81. 80/tcp    open   h00p
  82. 81/tcp    closed hosts2-ns
  83. 110/tcp   open   pop3
  84. 111/tcp   closed rpcbind
  85. 143/tcp   open   imap
  86. 443/tcp   open   h00ps
  87. 444/tcp   closed snpp
  88. 465/tcp   open   smtps
  89. 587/tcp   open   submission
  90. 990/tcp   open   ftps
  91. 993/tcp   open   imaps
  92. 995/tcp   open   pop3s
  93. 996/tcp   closed xtreelic
  94. 1433/tcp  closed ms-sql-s
  95. 3306/tcp  open   mysql
  96. 5432/tcp  open   postgres
  97. 49400/tcp closed compaqdiag
  98. 54320/tcp closed bo2k
  99. 61439/tcp closed netprowler-manager
  100. 61440/tcp closed netprowler-manager2
  101. 61441/tcp closed netprowler-sensor
  102. 65301/tcp closed pcanywhere
  103.  
  104. TCP/IP fingerprint:
  105. TCP ISN Seq. Numbers: 449DBB18 FA2DD2E9 9ECE7486 AAA0C984 7BA81B40 10CD69CD
  106. SInfo(V=3.70%P=i686-redhat-linux-gnu%D=10/26%Time=508A8C48%O=21%C=20)
  107. TSeq(Class=TR%IPID=Z)
  108. T1(Resp=Y%DF=Y%W=3890%ACK=S++%Flags=AS%Ops=MNNTNW)
  109. T2(Resp=N)
  110. T3(Resp=N)
  111. T4(Resp=Y%DF=Y%W=0%ACK=O%Flags=R%Ops=)
  112. T5(Resp=Y%DF=Y%W=0%ACK=S++%Flags=AR%Ops=)
  113. T6(Resp=Y%DF=Y%W=0%ACK=O%Flags=R%Ops=)
  114. T7(Resp=Y%DF=Y%W=0%ACK=S++%Flags=AR%Ops=)
  115. PU(Resp=N)
  116.  
  117. // I saw the posix system...
  118.    What kind of website is it?
  119.    check the ggl cache...lynx!!
  120.  
  121. // looks a good websites...
  122. // so ftp accounts was used to
  123. // URL: h00p://webcache.googleusercontent.com/search?q=cache:OEcJIzQH57IJ:milapapier.pl/+&cd=1&hl=en&ct=clnk&client=firefox-a
  124.  
  125. Mila Papier
  126. Handel Papierem | Giełda Papieru | Tablica Ogłoszeń |
  127.  
  128.    Home
  129.    Tablica Ogłoszeń
  130.        Sprzedaj Papier
  131.        Kup papier
  132.        Poszukuję
  133.        Współpraca
  134.    Papier
  135.        Tuleje tekturowe
  136.        Oferta
  137.        Słownik
  138.        Formaty
  139.    Oferta Maszyn
  140.        Zgłoś ofertę
  141.        Bobiniarka
  142.        Przekrawacze
  143.        Inne
  144.        Prasy
  145.    Katalog Firm
  146.        Katalog Firm
  147.        Dodaj stronę
  148.    Kontakt
  149.  
  150. Potrzebny Flash Player w wersji 10 lub nowszej.
  151. Istniejemy na rynku od blisko 15 lat i specjalizujemy się w sprzedaży papieru oraz maszyn papierniczych.
  152. Papier
  153.  
  154. Zajmujemy się hurtową sprzedażą papieru, tektur i kartonów oraz papieru....
  155.  :
  156.  blah
  157.  :
  158.   // got the contact info...
  159.  :
  160.  :
  161. Kontakt
  162.  
  163. Siedziba firmy
  164.  
  165. Mila Papier Sp. z o.o.
  166. ul. Osiedle Leśne 17-18
  167. 66-470 Kostrzyn nad Odrą
  168. NIP: 5992879273
  169. Regon: 211301675
  170.  
  171. Mobile : 0048 607 81 51 70 PL DE RU
  172. Mobile : 0048 781 50 20 40 PL EN
  173. Phone : 0048 95 729 9479
  174. Fax : 0048 95 729 9479
  175. Email PL : [email protected]   // polandian honest business site...
  176.  
  177. -------------------------------------------------------------
  178. // cant get this without cracking the server...
  179. // I ain't gonna DO the decent people's server!
  180. // So get other references:
  181.  
  182. h00p://usefulnews.org/wp-admin/js/cgi-binonline-security=paypalcgi-bin=_con
  183. h00p://www.forrestgarvin.com/www/paypalmember/cgi-binonline-security=paypalcgi-bin=_connexiononline_secur/
  184. h00p://www.thewatchscene.com/wp-content/themes/twentyten/paypal/security/secure/webscr.php?cmd=_login-run&dispatch=5885d80a13c0db1f998ca054efbdf2c29878a435fe324eec2511727fbf3e9efccfea7b32c60498b6947205eb6fe703a8cfea7b32c60498b6947205eb6fe703a8
  185. h00p://mestniy.ru/wp-admin/css/cgi-binonline-security=paypalcgi-bin=_connexiononline_securSecurity-paypal.htm
  186. h00p://joshuaprakarsajaya.com/wp-includes/js/tinymce/cn/2012/Alert/verification/update.account/paypalmember/cgi-binonline-security=paypalcgi-bin=_connexiononline_securSecurity-paypal.htm
  187.  
  188. The reference #2
  189. h00p://usefulnews.org/wp-admin/js/cgi-binonline-security=paypalcgi-bin=_con
  190.  
  191. // this is what happened if u access...
  192. h00p/1.1 404 Not Found
  193. Date: Fri, 26 Oct 2012 13:28:47 GMT
  194. Server: Apache/2.2.23 (Unix) mod_ssl/2.2.23 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.35
  195. X-Powered-By: PHP/5.2.17
  196. X-Pingback: h00p://usefulnews.org/xmlrpc.php
  197. Expires: Wed, 11 Jan 1984 05:00:00 GMT
  198. Cache-Control: no-cache, must-revalidate, max-age=0
  199. Pragma: no-cache
  200. Set-Cookie: PHPSESSID=e271ef59454c3095766ba6d7fb2621ab; path=/
  201. Last-Modified: Fri, 26 Oct 2012 13:28:48 GMT
  202. Connection: close
  203. Content-Type: text/html; charset=UTF-8
  204. // the others are as per case #1....
  205.  
  206. // What's this? Phising sites(DORK result)...PoC↓
  207. h00p://www.phishtank.com/phish_detail.php?phish_id=1585491
  208. h00p://www.phishtank.com/phish_detail.php?phish_id=1598929
  209. h00p://www.phishtank.com/phish_detail.php?phish_id=1591936
  210. h00p://www.phishtank.com/phish_detail.php?phish_id=1584873
  211. h00p://www.phishtank.com/phish_detail.php?phish_id=1584274
  212.  
  213. //RESULT
  214. // Is a confirmed phishing matters, hands over this to the phising guys..case closed!
  215. // how they got this phising page in their sites? Credential leaks, definetaly.
  216. // the keyword is the "paypalcgi-bin=" and "cgi-binonline-security="
  217. // block the above keyword in your network and you'll be save from this scheme...
  218.  
  219. #MalwareMustDie!!!!! Phishing toooo!!
Add Comment
Please, Sign In to add comment