« Spam and email threat analysis for the week ending Oct 30, 2011 | Blog Home | A short anatomy of a work at home scam »

Bookmark and Share

QuickBooks Security Tool email scam leads to malware

This morning I received a new scam email claiming to come from security@quickbooks.com, containing the following come-on text:


You will not be able to access your Intuit QuickBooks account without Intuit Security Tool (ISTâ„¢) after 31th of October, 2011.
You can download Intuit Security Tool here...


The camouflaged link had a .nl domain, so I plugged it into Wannabrowser and followed multiple redirects, ending up in Russia.

The first location, a compromised, or exploited server in The Netherlands (within 87.233.0.0/18), contained three links to JavaScript files on three different compromised domains. All three files were named js.js and contained another redirection to a subdomain of a domain named "serveirc.com" - hosted on no-ip.com, which bills itself as: "Dynamic DNS, Static DNS for Your Dynamic IP." The redirect from no-ip.com went to a server in Moscow, Russia, where I have traced much badware in recent weeks. The destination page is either cloaked to me, or devoid of content (possibly from SpamCop reports, such as I filed).

The Russian company hosting these exploits is named "Serverfarm" and owns the domain: MSM.RU. The IP hosting the QuickBooks scam exploit (95.163.89.193) is part of the CIDR: 95.163.0.0/16 - which is already on my Russian Blocklist, for hosting previous exploits.

FYI: the payload page is named: /main.php?page=b0374286c079f294

This scam is no different than its predecessors, the Scan From A Xerox Workstation and Scan From An HP Printer, both of which led to malware exploit kits that infected victim computers with the Zeus Trojan and a botnet installer. Delete such emails on sight.

Note: if you are a QuickBooks (actually intuit.com) customer and receive a questionable email claiming to be from them, hover your mouse over the links without clicking on them, to make sure they all point to intuit.com. This scam had a link on the word "here" which was the only one leading to the exploit site. Look closely at the links in action words. The actual destination will be revealed in your statue bar. If the action link doe not go directly to intuit.com, it is a scam, meant to harm your computer and steal money from your business.

Bookmark and Share  

Trend Micro Internet Security products, for home and office users, use in-the-cloud malware definitions that are updated every day, all day, as soon as new or altered strains of viruses and other malware are detected in the wild and analyzed. By offloading the bulk of these ever changing virus definitions to cloud servers, the load on your computers is greatly reduced. All users of Trend security programs are instantly protected from hostile web pages laden with malware exploits and hostile email, by the Trend Micro Smart Protection Network.

Creative Commons License This weblog is licensed under a Creative Commons License.
The content on this blog may be reprinted provided you do not modify the content and that you give credit to Wizcrafts and provide a link back to the blog home page, or individual blog articles you wish to reprint. Commercial use, or derivative work requires written permission from the author.

About the author
Wiz FeinbergWiz's Blog is written by Bob "Wiz" Feinberg, an experienced freelance computer consultant, troubleshooter and webmaster. Wiz's specialty is in computer and website security and combating spam. Wizcrafts Computer Services was established in 1996.

I produce this blog and website at my own expense. If you find this information valuable please consider making a donation via PayPal.

We are hosted on Bluehost and couldn't be happier!

Fight website spammers