Buy now and install on all your devices from one easy email. X

Spamvertised bogus online casino themed emails serving W32/Casonline

By Dancho Danchev

Cybercriminals are currently spamvertising hundreds of thousands of emails enticing end and corporate users into clicking on links leading to bogus online casinos requiring the installation of an executable file.

This is the second bogus casino themed campaign I've intercepted in recent months, and the third time when I profile the distribution and infection vectors of W32/Casonline.

More details:

Screenshot of a spamvertised bogus online casino site:

Online gambling casino image 1

Second screenshot of a spamvertised bogus online casino site:

Online gambling casino image 2

Third screenshot of a spamvertised bogus online casino site:

Online gambling casino image 3

Just like in the previously profiled spamvertised campaign, the cybercriminals behind this campaign are monetizing the traffic by participating in a revenue sharing affiliate network called StarPartner. The affiliate network offers:

Screenshots of the affiliate network's web site:

Online gambling casino image 4

Second screenshot of the affiliate network's web site:

Online gambling casino image 5

Go through related posts on previously spamvertised W32/Casonline campaigns:

Spamvertised

URLs: hxxp://www.allslotscasino.com; hxxp://www.crazyvegas.com; hxxp://www.ceudicestar.net

Sample detection rate for the advertised executables:

AllSlots.exe – detected by 7 out of 41 antivirus scanners as GAME/Casino.Gen; W32/Casino.P.gen!Eldorado

MD5: 76585c23167e0dcf49d55dede37ab999

CrazyVegas.exe – detected by 8 out of 41 antivirus scanners as GAME/Casino.Gen; TROJ_GEN.R3EH1FF

MD5: 72fc925d80f31501130bb1642f6a8f68

SilverOakCasinoInstaller.exe – detected by 3 out of 41 antivirus scanners as GAME/Casino.Gen2; Win32/RealTimeGaming_i

MD5: 0084f53acd115c3c7b7917f34f1b3ddc

Webroot SecureAnywhere users are proactively protected from these 'potentially unwanted applications'.

You can find more about Dancho Danchev at his LinkedIn Profile. You can also follow him on Twitter.

Past Newsletters

2014 Newsletters
March Newsletter
June Newsletter
2013 Newsletters
October Newsletter
July Newsletter
April Newsletter
January Newsletter
2012 Newsletters
December Newsletter
November Newsletter
October Newsletter
September Newsletter
August Newsletter
July Newsletter
June Newsletter
May Newsletter
April Newsletter
March Newsletter
February Newsletter
January Newsletter
2011 Newsletters
December Newsletter
November Newsletter
October Newsletter
September Newsletter
August Newsletter
July Newsletter
June Newsletter