NOD32 and Antivirus News
Threat and Security News

Nuwar Phishing

January 8th, 2008
by Pierre-Marc Bureau
Researcher at ESET

There was another twist today in the Nuwar story: it is now being used to host phishing sites. The gang behind this prolific malware has registered several domain names similar those used by well-known banks such as Barclays and Halifax and is directing web requests for these misspelled domain names to computers infected with Nuwar. The infected computers run web servers that serve a fake login page to steal the user name and password of any visitor who enters their information. One way to determine that this phishing scheme is related to Nuwar is to perform a domain name server lookup for the rogue domain name. A new IP address will be returned every time, and while some banks’ web sites do have multiple IP addresses assigned to them for redundancy and load-balancing, the sheer number of IP addresses returned is typical of fast flux domains (see http://en.wikipedia.org/wiki/Fast_flux for more information). Performing an HTTP request directly to the returned IP address instead of the rogue domain name will return the download message we discussed in our last post.

There is one important difference between Nuwar’s phishing pages and the real bank’s login pages: the banks’ uses encryption. We strongly recommend always verifying that your transaction is encrypted before entering any sensitive information in a web form.

Other interesting reading on Nuwar:

Storm goes phishing: http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080108

Measuring the Success Rate of Storm worm:

http://honeyblog.org/archives/156-Measuring-the-Success-Rate-of-Storm-Worm.html


Original: http://www.eset.com/threat-center/blog/?p=98



NOD32 AntiVirus Products    Products    NOD32 FAQs    FAQs    Buy NOD32 AntiVirus Online    NOD32 4 Students    NOD32 Student and non-profit Discounts    NOD32 4 Non-Profit    NOD32 online purchase    Buy NOD32 Online    nod32 anti-virus

BetterAntiVirus.COM. & BETTERANTIVIRUS.COM. are a US based reseller of Eset Software's NOD32 Solutions
BetterAntiVirus.COM. & BETTERANTIVIRUS.COM. and it's contents is Copyright © 2007 - Web Your Business Inc.
NOD32USA.COM. & BETTERANTIVIRUS.COM. & Web Your Business. are trademarks of Web Your Business Inc.
All rights reserved by their respective owners.