HoNeYBiRD
Elite Member
- May 1, 2009
- 10,187
- 12,580
The Onliner Spambot has collected millions of email credentials and server login information in order to send spam through "legitimate" servers, defeating many spam filters.
How it worked:
The credentials have been scraped and collated from other data breaches, such as the LinkedIn hack and the Badoo hack, as well also other unknown sources. The list has about 80 million accounts with each line containing the email address and password, along with the SMTP server and the port used to send the email. The spammer tests each entry by connecting to the server to ensure that the credentials are valid and that spam can be sent. The accounts that don't work are ignored.
These 80 million email servers are then used to send the remaining 630 million targets emails, designed to scope out the victim, or so-called "fingerprinting" emails.
These emails appear innocuous enough, but they contain a hidden pixel-sized image. When the email is open, the pixel image sends back the IP address and user-agent information, used to identify the type of computer, operating system, and other device information. That helps the attacker know who to target with the Ursnif malware, by specifically targeting Windows computers, rather than sending malicious files to iPhone or Android users, which aren't affected by the malware.
Smart.
Source: http://www.zdnet.com/article/onliner-spambot-largest-ever-malware-campaign-millions/
https://www.troyhunt.com/inside-the-massive-711-million-record-onliner-spambot-dump/
The breach is already in the https://haveibeenpwned.com/ database, so you can check your addresses, if they are affected or not. Around 1/4th of the addresses were already in the database.
How it worked:
The credentials have been scraped and collated from other data breaches, such as the LinkedIn hack and the Badoo hack, as well also other unknown sources. The list has about 80 million accounts with each line containing the email address and password, along with the SMTP server and the port used to send the email. The spammer tests each entry by connecting to the server to ensure that the credentials are valid and that spam can be sent. The accounts that don't work are ignored.
These 80 million email servers are then used to send the remaining 630 million targets emails, designed to scope out the victim, or so-called "fingerprinting" emails.
These emails appear innocuous enough, but they contain a hidden pixel-sized image. When the email is open, the pixel image sends back the IP address and user-agent information, used to identify the type of computer, operating system, and other device information. That helps the attacker know who to target with the Ursnif malware, by specifically targeting Windows computers, rather than sending malicious files to iPhone or Android users, which aren't affected by the malware.
Smart.
Source: http://www.zdnet.com/article/onliner-spambot-largest-ever-malware-campaign-millions/
https://www.troyhunt.com/inside-the-massive-711-million-record-onliner-spambot-dump/
The breach is already in the https://haveibeenpwned.com/ database, so you can check your addresses, if they are affected or not. Around 1/4th of the addresses were already in the database.