“Obama Quits” Spam Harvests PCs for Zombie Botnet   - 1,173 Views,

Summary: The Waledec botnet is using spam that claims that "Obama Quits", explaining that "Barack Obama abandoned sinking ship" and that Obama doesn't want any more to be president, in order to lure unsuspecting users to add their PCs to its group of zombied computers that it uses to do its dirty work. Other subject lines include "Who Will Be Our President Now?", "End time for the USA", and "Haven't you heard latest news about our president-elect?"

Previous Article « France to Ban Cell Phones for Children
Read Next Article » Porn Industry Looks for Financial Bailout from Congress

  Follow Anne on Twitter     Friend Anne on Facebook

The Waledec botnet is using spam that claims that “Obama Quits”, explaining that “Barack Obama abandoned sinking ship” and that Obama doesn’t want any more to be president, in order to lure unsuspecting users to add their PCs to its group of zombied computers that it uses to do its dirty work. Other subject lines include “Who Will Be Our President Now?”, “End time for the USA”, and “Haven’t you heard latest news about our president-elect?”

The spam explains that “Barack Obama’s inauguration that was planned on 20th January 2009 is under the threat of failure,” and goes on to say that “On the Eve of Inauguration Day President-elect Barack Obama made statement. He declared that he is definitely NOT ready for this position. Analysts say that Barack Obama has refused to be next president because he recognized inconsistency of his plan of stimulating USA economy.” (Note the broken and poor English.)

The “Obama Quits” spam takes the user to a plausible-looking website which talks all about how Obama has decided to reject the highest office in the United States, and links to a file that is supposedly his speech on the subject. The file bears names such as ‘barakspeech.exe’, ‘obamaspeech.exe’, ’statement.exe’, ‘obamanews.exe’, ‘president.exe’, ‘barack.exe’, and ‘usa.exe’.

A pretty safe rule is never download something with an .exe at the end, although that rule alone won’t keep your computer from being taken over.

According to Phil Hay, of security firm Marshal8e6 TRACE Labs, “The web site that these spam messages link to looks official and convincing at first glance. Closer examination reveals numerous spelling and grammatical errors on the site which could alert wary email users that this is a trick. Unfortunately we expect that many users who are lured to these sites will invariably click on the link and infect themselves.”

Some of the domains that are implicated in the “Obama Quits” Waledec botnet sweep include superobamaonline.com, greatobamaguide.com, and superobamadirect.com.

“Obama Quits” Spam Harvests PCs for Zombie Botnet

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « France to Ban Cell Phones for Children
Read Next Article » Porn Industry Looks for Financial Bailout from Congress

Read more:

»  The Real Profile of a Zombie Botnet Waking Up and Taking Over an ISP’s Customers Computers

»  Robert Scoble Quits Microsoft to Join PodTech.net

»  BBC Rents a Russian Botnet and Spams and DOSes in Name of Journalism

»  Killing Network Spam Zombies Made Easy

For additional similar stories check out our archives on Spam, Virus & AntiVirus

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 1/19/2009
The Internet Patrol
Patrolling the Internet for You!