Link LinkedIn Mail leads to Incognito exploit kit
We have logged a new email that looks like to be sent by LinedIn:

The email header info shows it is a scam:
Received: from lhost10.forahost.net (server-178.211.48.24.as42926.net [178.211.48.24]) Received: from c9069568.static.spo.virtua.com.br ([201.6.149.104]:49583 helo=fixnot.com.tr) by lhost10.forahost.net Date: Fri, 04 May 2012 08:34:11 -0700 From: "Order" @fixnot.com.tr Subject: Link LinkedIn Mail |
The email body contains also few malicious links:
hxxp:// gopeshmathur .com/ZgUBqavg/index.html |
The dumped content of the URL is clear a Incognito exploit kit:

All the new malicious links are still alive and they redirect users to:

The Java exploit JAR files are downloaded from:
hxxp:// 50.116.8. 93 /data/Pol.jar hxxp:// 69.163.34 .114 /data/Pol.jar |
File: Pol.jar Size: 15404 bytes MD5: 020B0B477706596E71DE25286ED77991 SHA1: C196A7B07BFE3D3593E93F7D98E910FA8E63AFF6 SHA256: F76AC6983135C7A69B5F07BC762F1AA478E2D49489090AC66882BC8065D1862B SHA384: 9C6BF2971E1F86588A9A08A3F18C096FBC62A42CE6927E0A7D0AFDB56DA01DBC4A6F72F742CC62B510FC1085221753D5 SHA512: 5464424E028620C4821B740B89787C7A75E6A56401F98BD15BA94F1A9268D54411E41E97DAE86468F4BDA54160A023DCC45F134E97BC6655E31C9274F8A21FC0 |
The JAR file exploits the vulnerability in the Java Runtime Environment component of Oracle Java SE (CVE-2012-0507), more details from the oracle.com website:
Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are 7 Update 2 and before, 6 Update 30 and before and 5.0 Update 33 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java Runtime Environment accessible data as well as read access to a subset of Java Runtime Environment accessible data and ability to cause a partial denial of service (partial DOS) of Java Runtime Environment.
Other malicious Incognito exploit kit URLs:
hxxp:// ftp.coden .com .br /BhxC8VrP/index.html hxxp:// generalcontractorsnc .com/nUUyHyvy/index.html hxxp:// mccgedvalenca .com .br/JFs10e34/index.html hxxp:// radiooisvira .com /mRpNLgWY/index.html hxxp:// statisticsolympiad .org /gR2aietM/index.html |
URLVoid scan reports:
http://www.urlvoid.com/scan/gopeshmathur .com
http://www.urlvoid.com/scan/jombangit .com
http://www.urlvoid.com/scan/shahinvestment .com
http://www.urlvoid.com/scan/mazyamana .com
http://www.ipvoid.com/scan/72.5.102.224
http://www.urlvoid.com/scan/ftp.coden .com .br
http://www.urlvoid.com/scan/generalcontractorsnc .com
http://www.urlvoid.com/scan/mccgedvalenca .com .br
http://www.urlvoid.com/scan/statisticsolympiad .org
http://www.urlvoid.com/scan/radiooisvira .com



