{"id":16120,"date":"2014-03-14T10:10:25","date_gmt":"2014-03-14T16:10:25","guid":{"rendered":"https://www.webroot.com/blog/?p=16120"},"modified":"2018-10-05T13:19:11","modified_gmt":"2018-10-05T19:19:11","slug":"spamvertised-bogus-online-casino-themed-emails-lead-w32casino","status":"publish","type":"post","link":"https://www.webroot.com/blog/2014\/03\/14\/spamvertised-bogus-online-casino-themed-emails-lead-w32casino\/","title":{"rendered":"Multiple spamvertised bogus online casino themed campaigns intercepted in the wild"},"content":{"rendered":"<p>Regular readers of Webroot&#8217;s Threat Blog are familiar with our <a href=\"https://www.webroot.com/blog/2012\/05\/22\/spamvertised-bogus-online-casino-themed-emails-serving-adware\/\"><strong>series of posts<\/strong><\/a>\u00a0detailing the proliferation of social engineering driven, privacy-violating campaigns serving W32\/Casino variants. Relying on <a href=\"https://www.webroot.com/blog/2012\/05\/30\/pop-ups-at-popular-torrent-trackers-serving-w32casonline-adware\/\"><strong>affiliate based revenue sharing schemes<\/strong><\/a>\u00a0and\u00a0<a href=\"https://www.webroot.com/blog/2012\/06\/28\/spamvertised-bogus-online-casino-themed-emails-serving-w32casonline\/\"><strong>spamvertised<\/strong><\/a> campaigns as the primary <a href=\"https://www.webroot.com/blog/2012\/08\/09\/millions-of-spamvertised-emails-lead-to-w32casonline\/\"><strong>distribution vectors<\/strong><\/a>, the rogue operators behind them continue tricking <a href=\"https://www.webroot.com/blog/2013\/06\/12\/tens-of-thousands-of-spamvertised-emails-lead-to-w32casonline\/\"><strong>tens of thousands of gullible users<\/strong><\/a> into installing the malicious applications.<\/p>\n<p>We&#8217;ve recently intercepted a series of spamvertised campaigns distributing W32\/Casino variants. Let&#8217;s profile the campaigns, provide actionable intelligence on the rogue domains involved in the campaigns, as well as related MD5s known to have interacted with the same rogue infrastructure.<\/p>\n<p>More details:<\/p>\n<p><!--more--><\/p>\n<p><strong>Sample screenshots of the landing pages for the rogue casinos:<\/strong> <a href=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA.png\"><img decoding=\"async\" loading=\"lazy\" width=\"959\" height=\"655\" class=\"size-full wp-image-16123 aligncenter\" src=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA.png\" alt=\"Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA\" srcset=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA.png 959w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA-300x204.png 300w\" sizes=\"(max-width: 959px) 100vw, 959px\" \/><\/a> <a href=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_01.png\"><img decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"768\" class=\"size-full wp-image-16124 aligncenter\" src=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_01.png\" alt=\"Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_01\" srcset=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_01.png 1024w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_01-300x225.png 300w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a> <a href=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_02.png\"><img decoding=\"async\" loading=\"lazy\" width=\"951\" height=\"623\" class=\"size-full wp-image-16125 aligncenter\" src=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_02.png\" alt=\"Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_02\" srcset=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_02.png 951w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_02-300x196.png 300w\" sizes=\"(max-width: 951px) 100vw, 951px\" \/><\/a> <a href=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_03.png\"><img decoding=\"async\" loading=\"lazy\" width=\"989\" height=\"593\" class=\"size-full wp-image-16126 aligncenter\" src=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_03.png\" alt=\"Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_03\" srcset=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_03.png 989w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_03-300x179.png 300w\" sizes=\"(max-width: 989px) 100vw, 989px\" \/><\/a> <a href=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_04.png\"><img decoding=\"async\" loading=\"lazy\" width=\"935\" height=\"627\" class=\"size-full wp-image-16127 aligncenter\" src=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_04.png\" alt=\"Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_04\" srcset=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_04.png 935w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_04-300x201.png 300w\" sizes=\"(max-width: 935px) 100vw, 935px\" \/><\/a> <a href=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_05.png\"><img decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"576\" class=\"size-large wp-image-16128 aligncenter\" src=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_05-1024x576.png\" alt=\"Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_05\" srcset=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_05-1024x576.png 1024w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_05-300x168.png 300w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_05.png 1093w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a> <a href=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_06.png\"><img decoding=\"async\" loading=\"lazy\" width=\"1024\" height=\"507\" class=\"size-large wp-image-16129 aligncenter\" src=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_06-1024x507.png\" alt=\"Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_06\" srcset=\"https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_06-1024x507.png 1024w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_06-300x148.png 300w, https:\/\/blog-en.webroot.com\/wp-content\/uploads\/2014\/03\/Online_Casino_Gambling_W32_Casino_Potentially_Unwanted_Applicationc_PUA_06.png 1217w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/p>\n<p><strong>Spamvertised URLs:<\/strong><br \/>\nhxxp:\/\/bit.ly\/1brCoxg<br \/>\nhxxp:\/\/bit.ly\/1bQRudq<br \/>\nhxxp:\/\/bit.ly\/1mLQr5I<br \/>\nhxxp:\/\/bit.ly\/MCOyaL<br \/>\nhxxp:\/\/bit.ly\/1ec3UMN<br \/>\nhxxp:\/\/bit.ly\/1hN6Vbd<br \/>\nhxxp:\/\/bit.ly\/1mQ3XFu<br \/>\nhxxp:\/\/bit.ly\/17DJ4pZ<br \/>\nhxxp:\/\/bit.ly\/1ec2JNa<br \/>\nhxxp:\/\/bit.ly\/1fBY6d5<\/p>\n<p><strong>W32.Casino PUA domains reconnaisance:<\/strong><br \/>\nhxxp:\/\/rubyfortune.com &#8211; 78.24.211.177<br \/>\nhxxp:\/\/grandparkerpromo.com &#8211; 95.215.61.160<br \/>\nhxxp:\/\/kingneptunescasino1.com &#8211; 67.211.111.169<br \/>\nhxxp:\/\/riverbelle1.com &#8211; 193.169.206.233<br \/>\nhxxp:\/\/europacasino.com &#8211; 87.252.217.13<br \/>\nhxxp:\/\/vegaspartnerlounge.com &#8211; 66.212.242.136<\/p>\n<p><strong>Sample detection rates for the W32\/Casino PUA:<\/strong><br \/>\n<a href=\"https:\/\/www.virustotal.com\/en\/file\/135caecdb6399309e682c50a6555b2399caddbc15d586eb3e6daaa46aa946290\/analysis\/1394642298\/\"><strong>MD5: b80db6ec0e6c968499ce01232fbfdc5c<\/strong><\/a> &#8211; detected by 3 out of 50 antivirus scanners as as W32\/Casino.P.gen!Eldorado<br \/>\n<a href=\"https:\/\/www.virustotal.com\/en\/file\/48a6ca872752c457b4844cbcf11e0bab80f0fee84d37659c1a70c8025c32e503\/analysis\/1394642439\/\"><strong>MD5: 8326886267203e07145f63adf2e8f0a1<\/strong><\/a> &#8211; detected by 3 out of 50 antivirus scanners as Heuristic.BehavesLike.Win32.Suspicious-DTR.S<br \/>\n<a href=\"https:\/\/www.virustotal.com\/en\/file\/353a47127596e06e3424d7dcb81ae5eeed83e492b3c911b82a47b7899ee0ea88\/analysis\/1394643637\/\"><strong>MD5: a2a545adf4498e409f7971f326333333<\/strong><\/a> &#8211; detected by 3 out of 50 antivirus scanners as W32\/Casino.P.gen!Eldorado<br \/>\n<a href=\"https:\/\/www.virustotal.com\/en\/file\/4cfa780d93d15d05b38544c4db3f2a9284b2dd29fd06675729775e3717032c42\/analysis\/1394643413\/\"><strong>MD5: 1cd6db7edbbc07d1c68968f584c0ac82<\/strong><\/a> &#8211; detected by 3 out of 49 antivirus scanners as W32\/Casino.P.gen!Eldorado<\/p>\n<p><strong>Once executed the sample phones back to:<\/strong><br \/>\nclatz.fileslldl.eu &#8211; 87.248.203.254<\/p>\n<p><strong>Known to have been downloaded from the same IP (87.248.203.254) are also the following W32\/Casonline variants:<\/strong><br \/>\nMD5: 06c6b0381cde4720a5204ac38a5f22b9<br \/>\nMD5: 1022bef242c7361866f7af512ec893e0<br \/>\nMD5: c1a6055f5d240d3681febc6bd77701eb<br \/>\nMD5: e5fd6aa437b3520f35337d2dd7139f9a<br \/>\nMD5: 6f6713077249800818f26b7469eaf175<br \/>\nMD5: 6ebdf6f7187effe7b52463cf7241297a<br \/>\nMD5: 6ed118798a19a5dbf63a9279f33e0542<br \/>\nMD5: 6b651437a4553b91139178a930247035<br \/>\nMD5: e1beeae4d07942c7fca6eea945c9bdcd<br \/>\nMD5: 6ab968f86300ca677e9700f7c2dee8be<br \/>\nMD5: 6a872111b70e401cf083a7d27b45a74e<br \/>\nMD5: f85fa2bb2dff0333650db371e323e962<\/p>\n<p><strong><a href=\"https:\/\/www.webroot.com\/us\/en\/home\/products\/complete\">Webroot\u00a0SecureAnywhere<\/a><\/strong>\u00a0users are proactively protected from these threats.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Regular readers of Webroot&#8217;s Threat Blog are familiar with our series of posts\u00a0detailing the proliferation of social engineering driven, privacy-violating campaigns serving W32\/Casino variants. Relying on affiliate based revenue sharing schemes\u00a0and\u00a0spamvertised campaigns as the primary distribution vectors, the rogue operators behind them continue tricking tens of thousands of gullible users into installing the malicious applications. [&hellip;]<\/p>\n","protected":false},"author":65,"featured_media":17052,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[17385,17381,17389,17383,4811,3871,17387,11559,5257,16325,23177,4893,3875,5721,17391,5883,17395,17399,17393,23179],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/16120"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=16120"}],"version-history":[{"count":16,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/16120\/revisions"}],"predecessor-version":[{"id":25801,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/16120\/revisions\/25801"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17052"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=16120"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=16120"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=16120"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=16120"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}