<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-35783026</id><updated>2011-12-22T09:20:18.856-08:00</updated><category term='fake av'/><category term='facebook'/><category term='koobface'/><category term='phishing'/><category term='gumblar'/><category term='zbot'/><category term='cyberwar'/><category term='law enforcement'/><category term='digital certificates'/><category term='spam'/><category term='pharmaceuticals'/><category term='twitter'/><category term='malware'/><category term='twitter malware'/><category term='computer security careers'/><category term='public policy'/><category term='conficker'/><category term='china'/><category term='waledac'/><title type='text'>CyberCrime &amp; Doing Time</title><subtitle type='html'>A Blog about Cyber Crime and related Justice issues</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://garwarner.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default?start-index=101&amp;max-results=100'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>347</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-35783026.post-7092224841658971254</id><published>2011-11-16T09:06:00.000-08:00</published><updated>2011-11-16T09:14:13.911-08:00</updated><title type='text'>ACH / WireTransfer Failed spam goes crazy!</title><content type='html'>Yesterday we saw two HUGE spam campaigns that continue into this morning advertising various alternatives of "your wire transfer failed" as subject lines.&lt;br /&gt;&lt;br /&gt;We saw at least 86,197 copies of this spam on November 15th, that I am mentally dividing into "Named Institution / zfin" spam and "random intermediary" spam.&lt;br /&gt;&lt;br /&gt;The "zfin" spam was far more prevalent, with 62,331 copies of the 86,197 copies pointing to a URL that contained "zfin.php" in the path.&lt;br /&gt;&lt;br /&gt;The "zfin" spam has a mail message that reads something like this:&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;Dear Account Holder,&lt;br /&gt;&lt;br /&gt;Money Transfer sent by you or on your behalf was hold by our bank.&lt;br /&gt;&lt;br /&gt;Transaction ID: 17019302204565051&lt;br /&gt;Current status of transaction: on hold&lt;br /&gt;&lt;br /&gt;Please review transaction details as soon as possible.&lt;br /&gt;&lt;br /&gt;N. B. Abel&lt;br /&gt;Treasury Management&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;The "non-zfin" email has a message that reads something like this:&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;Dear Bank Account Operator,&lt;br /&gt;I regret to inform you that Wire transfer initiated by you or on your behalf was hold by us.&lt;br /&gt;&lt;br /&gt;Transaction: 238006864683285&lt;br /&gt;Current transaction status: Pending&lt;br /&gt;&lt;br /&gt;Please review transaction details as soon as possible.&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;In both versions a very large number of "intermediary" spam domains are used.  These are "page forwarders" that have been placed on compromised web servers.  The hackers have gathered a very large list of website userids and passwords where they can place new content at will, without the knowledge of the webmaster.  They log in as the webmaster, upload their "forwarder" page, and then use that newly created page as the destination in spam messages.&lt;br /&gt;&lt;br /&gt;More than 15% of the spam that we saw at the UAB Spam Data Mine yesterday belonged to this pair of campaigns, and the volume is still extremely high this morning.&lt;br /&gt;&lt;br /&gt;Many of the emails used the faked "from" domains:&lt;br /&gt;&lt;br /&gt; uba.org                           5785&lt;br /&gt; lba.org                           5762&lt;br /&gt; aba.com                           5724&lt;br /&gt; bankersonline.com                 5681&lt;br /&gt; cbanet.org                        5674&lt;br /&gt; vabankers.org                     5672&lt;br /&gt; mbaa.org                          5645&lt;br /&gt; nationalbankers.org               5634&lt;br /&gt; icba.org                          5620&lt;br /&gt; allbankers.org                    5604&lt;br /&gt; fiba.net                          5532&lt;br /&gt; direct.nacha.org                  5024&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Forty-seven destinations were listed by the "zfin" spam, where a Financial Institution was included in the subject line. These destinations heavily favored Argentinian domain names:&lt;br /&gt;&lt;br /&gt; adsr.com.ar                                        /zfin.php&lt;br /&gt; alarpargentina.com.ar                              /zfin.php&lt;br /&gt; amhbra.com.ar                                      /zfin.php&lt;br /&gt; berlinonbike.de                                    /zfin.php&lt;br /&gt; blbtranslations.com.ar                             /zfin.php&lt;br /&gt; cargadedatos.com.ar                                /zfin.php&lt;br /&gt; cienciarama.com                                    /zfin.php&lt;br /&gt; diagonalpro.com.ar                                 /zfin.php&lt;br /&gt; diloplas.com.ar                                    /zfin.php&lt;br /&gt; f-guazzaroni.com.ar                                /zfin.php&lt;br /&gt; grupoaie.com                                       /zfin.php&lt;br /&gt; healthsolution.com.ar                              /zfin.php&lt;br /&gt; hebamme-hindenberg.de                              /zfin.php&lt;br /&gt; horsejack.com.ar                                   /zfin.php&lt;br /&gt; horuz.com.ar                                       /zfin.php&lt;br /&gt; iguazuwonderful.com                                /zfin.php&lt;br /&gt; imevial.cl                                         /zfin.php&lt;br /&gt; juliancortary.com                                  /zfin.php&lt;br /&gt; mecanicamm.zzl.org                                 /zfin.php&lt;br /&gt; mikromesh.de                                       /zfin.php&lt;br /&gt; mileycyrusdaily.com                                /zfin.php&lt;br /&gt; monialberti.com.ar                                 /zfin.php&lt;br /&gt; ohoven.de                                          /zfin.php&lt;br /&gt; onpacker.de                                        /zfin.html&lt;br /&gt; picturereport.net                                  /zfin.php&lt;br /&gt; playamarinaestates.com                             /zfin.php&lt;br /&gt; regionalvanesaduran.com.ar                         /zfin.php&lt;br /&gt; saboresdecordoba.com                               /zfin.php&lt;br /&gt; safarisfotograficos.com.ar                         /zfin.php&lt;br /&gt; schoss-objekt.de                                   /zfin.php&lt;br /&gt; sindy.com.ar                                       /zfin.php&lt;br /&gt; sindy-arg.com.ar                                   /zfin.php&lt;br /&gt; tamandua-transporte.com.ar                         /zfin.php&lt;br /&gt; vanessahudgens.bz                                  /zfin.php&lt;br /&gt; video-professionell.de                             /zfin.php&lt;br /&gt; visiondelnoroeste.com.ar                           /zfin.php&lt;br /&gt; viveroelparaiso.com.ar                             /zfin.php&lt;br /&gt; whitehorsemedia.de                                 /zfin.php&lt;br /&gt; www.ava-kunden.de                                  /zfin.php&lt;br /&gt; www.bx000471.ferozo.com                            /zfin.php&lt;br /&gt; www.enpuntasdepie.com.ar                           /zfin.php&lt;br /&gt; www.profileinformatica.com.ar                      /zfin.php&lt;br /&gt; www.samavi.com.ar                                  /zfin.php&lt;br /&gt; www.seebek.com.ar                                  /zfin.php&lt;br /&gt; www.tecnosistemas.com.ar                           /zfin.php&lt;br /&gt; www.tecnotrucos.com.ar                             /zfin.php&lt;br /&gt; www.tetraisotopos.com                              /zfin.php&lt;br /&gt;&lt;br /&gt;By mixing a "prefix" with an "institution name" more than 10,000 unique subject lines were created.  702 Financial Institutions have been named so far . . .&lt;br /&gt;&lt;br /&gt;The prefix for the subject is selected from this list:&lt;br /&gt;&lt;br /&gt; ACH debit transfer was hold by&lt;br /&gt; ACH debit transfer was not accepted by&lt;br /&gt; ACH payroll payment was hold by&lt;br /&gt; ACH payroll payment was not accepted by&lt;br /&gt; ACH Transfer was hold by&lt;br /&gt; ACH Transfer was not accepted by&lt;br /&gt; Bill Payment was hold by&lt;br /&gt; Bill Payment was not accepted by&lt;br /&gt; Domestic Wire Transfer was hold by&lt;br /&gt; Domestic Wire Transfer was not accepted by&lt;br /&gt; Funds transfer was hold by&lt;br /&gt; Funds transfer was not accepted by&lt;br /&gt; Money Transfer was hold by&lt;br /&gt; Money Transfer was not accepted by&lt;br /&gt; Payment was hold by&lt;br /&gt; Payment was not accepted by&lt;br /&gt; Wire Transfer was hold by&lt;br /&gt; Wire Transfer was not accepted by&lt;br /&gt;&lt;br /&gt;and then suffixed with a financial institution name from the list found at the end of this email. . . .&lt;br /&gt;&lt;br /&gt;The "non-zfin" form of the list uses one of these subjects:  (Random number use is notated by #RND#)&lt;br /&gt;&lt;br /&gt; ACH payment canceled &lt;br /&gt; ACH payment rejected &lt;br /&gt; ACH transaction canceled &lt;br /&gt; ACH Transfer canceled &lt;br /&gt; ACH transfer rejected &lt;br /&gt; ACH transfer was hold by our bank &lt;br /&gt; Declined Direct Deposit payment &lt;br /&gt; Direct Deposit payment ID #RND# rejected &lt;br /&gt; Direct Deposit payment was cancelled &lt;br /&gt; Direct Deposit payment was declined &lt;br /&gt; Direct Deposit payment was rejected &lt;br /&gt; Disallowed Direct Deposit payment &lt;br /&gt; Fwd: Wire Transfer (#RND#) &lt;br /&gt; Fwd: Wire Transfer Confirmation &lt;br /&gt; Fwd: Wire Transfer Confirmation (FED #RND#)&lt;br /&gt; Fwd: Your Wire Transfer &lt;br /&gt; Notification about the rejected Direct Deposit payment &lt;br /&gt; Payment ID #RND# rejected &lt;br /&gt; Re: your Direct Deposit payment ID #RND#&lt;br /&gt; Regarding your Direct Deposit via ACH &lt;br /&gt; Rejected ACH payment &lt;br /&gt; Rejected ACH transaction &lt;br /&gt; Rejected ACH transfer &lt;br /&gt; Urgent notice about your electronic payments &lt;br /&gt; Your ACH transaction &lt;br /&gt; Your ACH transfer &lt;br /&gt; Your Direct Deposit payment ID #RND# was declined &lt;br /&gt; Your Direct Deposit payment via ACH was declined &lt;br /&gt; Your Direct Deposit payments were disallowed &lt;br /&gt; Your Direct Deposit payments were rejected &lt;br /&gt;&lt;br /&gt;These spam messages directed users to one of 1962 unique URLs that all SEEM to be compromised websites, with the exception of some "free hosting" sites, and a handful of URL shortening services.  That list is presented below, with the list reduced to 671 instances by eliminating all but a single example URL per host computer:&lt;br /&gt;&lt;br /&gt; 015cc13.netsolhost.com                             /7o1otl/index.html&lt;br /&gt; 119.245.150.188                                    /&lt;br /&gt; 163.30.58.134                                      /&lt;br /&gt; 164.125.9.9                                        /~kimjw/gigl.php&lt;br /&gt; 173.193.15.56                                      /~assalamt/13xwph/index.html&lt;br /&gt; 193.59.73.242                                      /&lt;br /&gt; 194.51.85.73                                       /~tlariviere/zmtg.html&lt;br /&gt; 195.244.192.61                                     /&lt;br /&gt; 200.13.224.125                                     /&lt;br /&gt; 200.58.114.11                                      /&lt;br /&gt; 202.43.73.66                                       /&lt;br /&gt; 203.174.34.130                                     /&lt;br /&gt; 210.239.8.82                                       /~kenmin/akatx.php&lt;br /&gt; 212.110.96.163                                     /&lt;br /&gt; 213.191.128.17                                     /&lt;br /&gt; 216.172.186.5                                      /~peacock/9f46fnr/index.html&lt;br /&gt; 38.103.167.38                                      /&lt;br /&gt; 4a.4b.354a.static.theplanet.com                    /~playcas/5be1urt/index.html&lt;br /&gt; 60.251.4.82                                        /&lt;br /&gt; 62.193.216.26                                      /&lt;br /&gt; 62.233.121.21                                      /&lt;br /&gt; 62.233.121.25                                      /&lt;br /&gt; 66.133.129.5                                       /~nsmarc1166/gbsmofb.html&lt;br /&gt; 74.86.158.236                                      /&lt;br /&gt; 82.140.32.161                                      /&lt;br /&gt; 82.223.150.99                                      /&lt;br /&gt; 83.243.20.173                                      /&lt;br /&gt; 84.32.77.200                                       /&lt;br /&gt; 87.98.187.244                                      /&lt;br /&gt; 90plan.ovh.net                                     /~aventureo/1k87cy0/index.html&lt;br /&gt; a.md                                               /9Q6&lt;br /&gt; abandonedontario.ca                                /&lt;br /&gt; abbastravel.com                                    /&lt;br /&gt; ad.f8.5546.static.theplanet.com                    /~outdoors/0nnpob/index.html&lt;br /&gt; adagadoxig.freecities.com                          /acjxur.html&lt;br /&gt; adamant.az                                         /deuhgi.html&lt;br /&gt; adanovan968.100megsfree5.com                       /oduarg705.html&lt;br /&gt; adi-tobyfatud.fcpages.com                          /oprirtir.html&lt;br /&gt; ady-ufodopyrub.envy.nu                             /bezuvee0.html&lt;br /&gt; afucezox706.bigheadhosting.net                     /nofloudabuse.html&lt;br /&gt; agrooyl.ro                                         /inlcude.html&lt;br /&gt; airteksystems.com                                  /&lt;br /&gt; airworkscompressors.com                            /&lt;br /&gt; ajubecujal-tope.freewebsitehosting.com             /lrosperousneslaa08.html&lt;br /&gt; akapela.gr                                         /7as4xe/index.html&lt;br /&gt; akat-tech.com                                      /&lt;br /&gt; alahpe.notlong.com                                 /&lt;br /&gt; alasimipi-akad.maddsites.com                       /poadkh.html&lt;br /&gt; ale-jygowesop.lookseekpages.com                    /leonijii785.html&lt;br /&gt; aleksrdest.com                                     /&lt;br /&gt; alfra-tools.be                                     /contents/index11.html&lt;br /&gt; alfra-tools.nl                                     /&lt;br /&gt; alided-isig.freewebportal.com                      /noninfecluoufyy45.html&lt;br /&gt; all-expo.eu                                        /0uktna/index.html&lt;br /&gt; alphametal.info                                    /&lt;br /&gt; alphashop.nl                                       /&lt;br /&gt; alugiceb34.lookseekpages.com                       /pptopwaner.html&lt;br /&gt; alzmetall.be                                       /shared_files/index11.html&lt;br /&gt; alzmetall.nl                                       /contents/index11.html&lt;br /&gt; amanibap105.envy.nu                                /pdiasamd.html&lt;br /&gt; amidopysud.greatnow.com                            /pytacinc.html&lt;br /&gt; amolijuza795.freewaywebhost.com                    /novdurabbebii57.html&lt;br /&gt; amylo.ca                                           /&lt;br /&gt; annelotte.com                                      /&lt;br /&gt; anu-efitodose.maddsites.com                        /pinuda.html&lt;br /&gt; anwaltskanzlei-apw.de                              /dxocq8/index.html&lt;br /&gt; apibopeco-isex.maddsites.com                       /pammtqqaw.html&lt;br /&gt; apnea-creativa.net                                 /&lt;br /&gt; apollox.net                                        /&lt;br /&gt; aqas-rijaxatoc.virtue.nu                           /polivlex.html&lt;br /&gt; aqo-awiwyzyhot.lookseekpages.com                   /phaxa12.html&lt;br /&gt; aquastats.nl                                       /&lt;br /&gt; ariane-services.com                                /~ph_laura/1trr7oh/index.html&lt;br /&gt; asewad722.freewebsitehosting.com                   /petrqeisec.html&lt;br /&gt; askara.ca                                          /&lt;br /&gt; assilphone.com                                     /46in4f/index.html&lt;br /&gt; assistantarea.com                                  /0dt038i/index.html&lt;br /&gt; astola.com.au                                      /03ajwnt/index.html&lt;br /&gt; athmajothi.com                                     /2kejqlu/index.html&lt;br /&gt; atlas.nseasy.com                                   /~athmajot/995rxv/index.html&lt;br /&gt; atomicdigitalcapture.com                           /4srpft/index.html&lt;br /&gt; atscaf.fr                                          /0w019w/index.html&lt;br /&gt; audier.nl                                          /1vz1hs/index.html&lt;br /&gt; aunesty.com                                        /34n6z2t/index.html&lt;br /&gt; aurorabraces.com                                   /&lt;br /&gt; autodc.fr                                          /5s82w4/index.html&lt;br /&gt; auvalon.sk                                         /0wffuo/index.html&lt;br /&gt; aviorr.com                                         /0jlklp6/index.html&lt;br /&gt; axux-oxylule.s-enterprize.com                      /nikeuu5.html&lt;br /&gt; aze-seqyqan.dreamstation.com                       /rorihigotikano.html&lt;br /&gt; aziatische-ingredienten.nl                         /52n8pw/index.html&lt;br /&gt; azuma.co.th                                        /&lt;br /&gt; babytake.com                                       /7r7hr4p/index.html&lt;br /&gt; badcompanyeredar.ba.ohost.de                       /2m23xd6/index.html&lt;br /&gt; balconesdelparque.com                              /3sdl39/index.html&lt;br /&gt; baldimanuela.it                                    /inlcude.html&lt;br /&gt; bandzaagmachine.nl                                 /&lt;br /&gt; banyanchildrenlibrary.com                          /qbbxnth/index.html&lt;br /&gt; barpetra.com                                       /hsldl6/index.html&lt;br /&gt; bb4f.net                                           /0pwbvz/index.html&lt;br /&gt; bedrijftekooptiel.nl                               /&lt;br /&gt; bedrijftekoopzetten.nl                             /&lt;br /&gt; benice.pytalhost.de                                /8ir8he9/index.html&lt;br /&gt; berufskolleg-brilon.de                             /2jt3oy/index.html&lt;br /&gt; beststockbook.com                                  /21jrj7g/index.html&lt;br /&gt; bidenurefu-upi.servetown.com                       /nixqczzn.html&lt;br /&gt; bifapuniho-nyna.digitalzones.com                   /jypajpa.html&lt;br /&gt; birchip.com                                        /c2xollw/index.html&lt;br /&gt; biru.web.id                                        /nemi5k/index.html&lt;br /&gt; bi-vent.de                                         /51kk7o/index.html&lt;br /&gt; bizalgerie.com                                     /92usm9/index.html&lt;br /&gt; bjay12.com                                         /2pamuex/index.html&lt;br /&gt; blog.forumfan.pl                                   /&lt;br /&gt; blog.tedinet.com                                   /kissnza/index.html&lt;br /&gt; boatbooks.ca                                       /&lt;br /&gt; boatlicences.com.au                                /msp9nc/index.html&lt;br /&gt; boncukhaliyikama.com                               /echhgst/index.html&lt;br /&gt; boroth.servers.rbl-mer.misp.co.uk                  /~attract/3vpite/index.html&lt;br /&gt; bosokovemi1800.maddsites.com                       /wizim.html&lt;br /&gt; bosugixe.sdhost.tk                                 /ugisogu.html&lt;br /&gt; brouze.fr                                          /inlcude.html&lt;br /&gt; brutalfun.net                                      /0p4tl4/index.html&lt;br /&gt; bumblebeeman.enixns.com                            /~bookmi/726d5mn/index.html&lt;br /&gt; buwynobolo.freehostyou.com                         /wlrbo.html&lt;br /&gt; buzeqok.222mb.tk                                   /aruvivy.html&lt;br /&gt; byqopoveni-apyl.fcpages.com                        /redberunnez290.html&lt;br /&gt; c2.16.344a.static.theplanet.com                    /~peterfur/hqrgv4/index.html&lt;br /&gt; caddcentre.org                                     /1do876d/index.html&lt;br /&gt; caddcentre.ws                                      /4yeqtja/index.html&lt;br /&gt; cadokeduzi207.100freemb.com                        /paxhokuh.html&lt;br /&gt; cafeamerika.de                                     /2n7a13/index.html&lt;br /&gt; cahev.com                                          /&lt;br /&gt; caqiwy-mora.greatnow.com                           /pgonham.html&lt;br /&gt; casinospoker-online.info                           /3z0ugvx/index.html&lt;br /&gt; casu-urenywyje.lookseekpages.com                   /sasg0211.html&lt;br /&gt; cazonof1845.greatnow.com                           /nisolicoo8933.html&lt;br /&gt; celluloidtamil.com                                 /inlcude.html&lt;br /&gt; cgworkshops.net                                    /inlcude.html&lt;br /&gt; ChaitanyaHolidays.in                               /&lt;br /&gt; champagne-ruelle-pertois.com                       /&lt;br /&gt; chateau-haut-gachin.com                            /&lt;br /&gt; chilp.it                                           /496e27&lt;br /&gt; ciata.be                                           /&lt;br /&gt; cihawuva.webclot.org                               /yruwevu.html&lt;br /&gt; cim-byzowofy.freewaywebhost.com                    /polairs.html&lt;br /&gt; citydibo1446.exactpages.com                        /protenluuu41.html&lt;br /&gt; citynewsservice.de                                 /g5nfpqn/index.html&lt;br /&gt; cizomixo.freehosting.bg                            /uxicutov.html&lt;br /&gt; classicknits.co.in                                 /6j3o6e/index.html&lt;br /&gt; click1.goshadowshopping.com                        /iyyvyncqkbpwvhkcwbmpkwtnthwhmyhthfmyfkmynymzmc_lkhdmzdwhjzw.html&lt;br /&gt; clickandclaimcouk.site.securepod.com               /5n4uxw/index.html&lt;br /&gt; cm.digiportal.com                                  /php/CR/cmregister.php%3Fdata=cR2NA4mi3ED%2B9KZ3KbHZoLUlSJRqo2hCZWTTw7FA86yfesTTa7T5mz8nIfQIsOEJqCYEjlrSL2Kb22pt1bCNT9YgXTqnV9Hq0szMhVjmIj7KYTbpAXf8d9rdvs9EUK7IwIuiNhR4mho%3D&lt;br /&gt; cocynuvoxo.virtue.nu                               /pabter255.html&lt;br /&gt; cojojibi.4sql.net                                  /amematy.html&lt;br /&gt; conred.com                                         /65q7jj/index.html&lt;br /&gt; contimac.eu                                        /&lt;br /&gt; copofude.freehost.artonat.com                      /ugisogux.html&lt;br /&gt; cornwell.cz                                        /f.html&lt;br /&gt; cos-ovaxyrex.mindnmagick.com                       /pashtetdqivuz.html&lt;br /&gt; cp05.digitalpacific.com.au                         /~austraqc/6g6dif/index.html&lt;br /&gt; crm.ndr.it                                         /&lt;br /&gt; cukydyvu.exactpages.com                            /uu3920.html&lt;br /&gt; cuzihyket1405.bigheadhosting.net                   /dosf882.html&lt;br /&gt; cygnus.inc.cl                                      /~planhost/jgf5m7/index.html&lt;br /&gt; cyta-qorizatovy.greatnow.com                       /onarban303.html&lt;br /&gt; czester.freehost.pl                                /&lt;br /&gt; dab-gynyto.1accesshost.com                         /ofyt745.html&lt;br /&gt; dachshund.ru                                       /&lt;br /&gt; dahlih.nl                                          /&lt;br /&gt; dashramspa.com                                     /79q2h6/index.html&lt;br /&gt; daxilymapo-ymeg.exactpages.com                     /atextn858.html&lt;br /&gt; degogoyi.hosto2.info                               /ruvivyfu.html&lt;br /&gt; deko-bett.de                                       /04eozwl/index.html&lt;br /&gt; dembs.com                                          /&lt;br /&gt; denohifi.builtfree.org                             /xqibitaa90.html&lt;br /&gt; desmidspijk.nl                                     /inlcude.html&lt;br /&gt; dhseminars.com                                     /5zn712w/index.html&lt;br /&gt; dialog-translations.com                            /00kzr4/index.html&lt;br /&gt; diamanza.50webs.com                                /&lt;br /&gt; dirimukysu.1accesshost.com                         /polarbead7610.html&lt;br /&gt; disasterrecovery.org                               /&lt;br /&gt; djxcube.com                                        /&lt;br /&gt; dollysgroceries.com                                /&lt;br /&gt; domuxurasu.envy.nu                                 /pyia234.html&lt;br /&gt; dos-ykyratih.fcpages.com                           /lromisemyngerii62.html&lt;br /&gt; douglasgwynnsmith.com                              /&lt;br /&gt; dubimajis1142.bigheadhosting.net                   /noncallapsabmeyy05.html&lt;br /&gt; durl.me                                            /mikas&lt;br /&gt; dykutimopa.servetown.com                           /nanablelutionuu14.html&lt;br /&gt; edenindustries.ca                                  /&lt;br /&gt; egifat-kysi.maddsites.com                          /wlsejenro.html&lt;br /&gt; ehykigicos1194.freehostyou.com                     /plogmafter111.html&lt;br /&gt; eishohwa.notlong.com                               /&lt;br /&gt; eja-upigewary.fcpages.com                          /nokh529.html&lt;br /&gt; ekuin.notlong.com                                  /&lt;br /&gt; ekuxylylak-zowo.100freemb.com                      /osazatu.html&lt;br /&gt; em003.czechian.net                                 /&lt;br /&gt; enafej1554.digitalzones.com                        /jity890.html&lt;br /&gt; enfantsdoprata.org                                 /&lt;br /&gt; enyqypuhys.lookseekpages.com                       /pvopyliticii404.html&lt;br /&gt; eqywazogif-uno.lookseekpages.com                   /paniauu96.html&lt;br /&gt; eterysam.1accesshost.com                           /deipmus.html&lt;br /&gt; europa-haus-leipzig.de                             /7k75p9/index.html&lt;br /&gt; evil-knievel.gmxhome.de                            /&lt;br /&gt; evy-evaqahup.freewebsitehosting.com                /odbug.html&lt;br /&gt; ewamosy1959.freewaywebhost.com                     /mttygesyy87.html&lt;br /&gt; ewivisabec-jig.envy.nu                             /opium206.html&lt;br /&gt; ewoutjonker.nl                                     /&lt;br /&gt; exirevoka.builtfree.org                            /kfhyra.html&lt;br /&gt; eyeicu.notlong.com                                 /&lt;br /&gt; ezexezeba703.100megsfree5.com                      /sawv636.html&lt;br /&gt; ezomusic.ez.funpic.de                              /&lt;br /&gt; ezuwaqi-zoqa.1accesshost.com                       /wereipacd.html&lt;br /&gt; fej-anepyveruw.fcpages.com                         /paradyseii170.html&lt;br /&gt; f-guazzaroni.com.ar                                /&lt;br /&gt; finsko.hostuju.cz                                  /&lt;br /&gt; fiwawax.10gb.tk                                    /uhezivog.html&lt;br /&gt; france-azur.nl                                     /&lt;br /&gt; fullmex.iblogger.org                               /inlcude.html&lt;br /&gt; fyparor1321.freecities.com                         /rushantassdanov.html&lt;br /&gt; galaxy.host-care.com                               /~perthbe1/fmkvw3/index.html&lt;br /&gt; gia-jp.net                                         /&lt;br /&gt; gibobe1829.freewebportal.com                       /mutmitchell.html&lt;br /&gt; gihujakabu.greatnow.com                            /promutzeis.html&lt;br /&gt; giloziz-ijub.envy.nu                               /rorf.html&lt;br /&gt; gofipipy-syg.100freemb.com                         /olofjolindur.html&lt;br /&gt; goksenmuhendislik.com                              /&lt;br /&gt; gozaqoba.eg.vg                                     /nezivogo.html&lt;br /&gt; gtpikes.com                                        /6cqmid/index.html&lt;br /&gt; gud-exonad.lookseekpages.com                       /nizibc.html&lt;br /&gt; gulohr.notlong.com                                 /&lt;br /&gt; guptaservices.com                                  /&lt;br /&gt; guwe-syginyn.100megsfree5.com                      /fapux250.html&lt;br /&gt; gyk-yrubecata.digitalzones.com                     /gacezoo7.html&lt;br /&gt; halliemgt.com                                      /59ybsd/index.html&lt;br /&gt; hamibukike-qan.builtfree.org                       /sonyxplosivoee56.html&lt;br /&gt; hammerrassebande.de                                /8jz5glg/index.html&lt;br /&gt; harmonie-travaux.com                               /1lvsq8k/index.html&lt;br /&gt; hax1234.ha.funpic.de                               /&lt;br /&gt; hepidyzozo.1accesshost.com                         /ppoisee90.html&lt;br /&gt; hero.host-care.com                                 /~pin/9es7srf/index.html&lt;br /&gt; hetigy-kyju.builtfree.org                          /urangahoua.html&lt;br /&gt; himalayanweavers.org                               /&lt;br /&gt; hipuhaq.simik.net                                  /nezivog.html&lt;br /&gt; hiralix.mblogger.info                              /vozalah.html&lt;br /&gt; hiranobag.co.jp                                    /&lt;br /&gt; hitcombo.com                                       /inlcude.html&lt;br /&gt; hitechcsi.com                                      /&lt;br /&gt; hiz-ysupyso.100megsfree5.com                       /pbiccehc.html&lt;br /&gt; hockeydykeincanada.ca                              /images/main.html&lt;br /&gt; hoepner-lacke.de                                   /89fj0g/index.html&lt;br /&gt; hoguzud.blogerpa.com                               /nezivog.html&lt;br /&gt; hokifuxu.greatnow.com                              /outsmature.html&lt;br /&gt; homesatthebeach.ca                                 /&lt;br /&gt; honestlawyer.ca                                    /&lt;br /&gt; honkafusion.ch                                     /o55zj1/index.html&lt;br /&gt; honkafusion.es                                     /bpmxh6/index.html&lt;br /&gt; honkafusion.fr                                     /1h0wgog/index.html&lt;br /&gt; honmononoyosa.sakura.ne.jp                         /&lt;br /&gt; hotelkayisi.com                                    /inlcude.html&lt;br /&gt; hsh-sh.de                                          /04y855/index.html&lt;br /&gt; icppo.ic.funpic.de                                 /&lt;br /&gt; icyryxure.digitalzones.com                         /paracletasiz.html&lt;br /&gt; iduposywa.freewebsitehosting.com                   /pumilaoo62.html&lt;br /&gt; iheartmypet.ca                                     /&lt;br /&gt; ihoje.notlong.com                                  /&lt;br /&gt; ijicuzajy-esu.arcadepages.com                      /ppkboris.html&lt;br /&gt; ijy-ymexegahix.freewebsitehosting.com              /nintwove.html&lt;br /&gt; ikiwulete.mindnmagick.com                          /jordert1711.html&lt;br /&gt; ikylec1342.o-f.com                                 /bobico.html&lt;br /&gt; ilidavy-pow.mindnmagick.com                        /zilku.html&lt;br /&gt; ilipinyqez1193.fcpages.com                         /rickaa3447.html&lt;br /&gt; inkwellgraphics.ca                                 /&lt;br /&gt; inteligus.pl                                       /0xp8fz/index.html&lt;br /&gt; interasia.co.in                                    /&lt;br /&gt; iphoneipadexperts.com                              /&lt;br /&gt; ipigipo-ese.lookseekpages.com                      /nocregs.html&lt;br /&gt; iqiturixug1179.lookseekpages.com                   /baljk891.html&lt;br /&gt; iqodew493.o-f.com                                  /bonsaa93.html&lt;br /&gt; iqopuc-himi.100freemb.com                          /nurlajidealmarky.html&lt;br /&gt; iru-ynonywecid.mindnmagick.com                     /rutipog.html&lt;br /&gt; is.gd                                              /2vNBBj&lt;br /&gt; i-sites.hu                                         /inlcude.html&lt;br /&gt; ivywej69.s-enterprize.com                          /purtygmress.html&lt;br /&gt; iwefedoj.dreamstation.com                          /viomondas.html&lt;br /&gt; iwynokybar-ovu.virtue.nu                           /phantomnrue.html&lt;br /&gt; ixoboqyqe-eme.greatnow.com                         /pajvar.html&lt;br /&gt; jabowabi.zbyte.org                                 /edoruvyh.html&lt;br /&gt; japodubyj254.envy.nu                               /alexee94.html&lt;br /&gt; japuseny.fcpages.com                               /paasoz.html&lt;br /&gt; jaylau.com                                         /&lt;br /&gt; jel-acofuhagi.envy.nu                              /gapereno7210.html&lt;br /&gt; jemadab1072.exactpages.com                         /owylfrudu.html&lt;br /&gt; jeqy-qogiqyw.100megsfree5.com                      /qeeml.html&lt;br /&gt; jimpruden.com                                      /html/main11.html&lt;br /&gt; jixucewa.arcadepages.com                           /hrovidableoo414.html&lt;br /&gt; joakimdo.com                                       /main11.html&lt;br /&gt; johannessendesign.com                              /&lt;br /&gt; john-adams.ca                                      /main11.html&lt;br /&gt; johnspassmonsterkingfish.com                       /&lt;br /&gt; jozacupub.mindnmagick.com                          /proliderousnyaa88.html&lt;br /&gt; ju-kreis-olpe.de                                   /13z229/index.html&lt;br /&gt; jup-oqupiwyf.lookseekpages.com                     /rickeskenmop.html&lt;br /&gt; jydinoxoto.dreamstation.com                        /phit47tiz37.html&lt;br /&gt; kakexo-xyho.builtfree.org                          /packran866.html&lt;br /&gt; kamiqudob.lookseekpages.com                        /memgaful8510.html&lt;br /&gt; karlo-b.de                                         /1wls5te/index.html&lt;br /&gt; kierwinski.pl                                      /&lt;br /&gt; kinditech.org                                      /&lt;br /&gt; kisyholy971.arcadepages.com                        /vsynu.html&lt;br /&gt; kizodyxy.1accesshost.com                           /pesrul7910.html&lt;br /&gt; klu-inkleur.nl                                     /&lt;br /&gt; kociqaw.websitehostfree.com                        /nezivog.html&lt;br /&gt; kon.wheel.sk                                       /4ypcij5/index.html&lt;br /&gt; kowalczyk.cz                                       /&lt;br /&gt; ks31295.kimsufi.com                                /~palmthre/3dg825m/index.html&lt;br /&gt; ks355256.kimsufi.com                               /~pool/bdw27yh/index.html&lt;br /&gt; kuczka.eu                                          /j9xiw3/index.html&lt;br /&gt; kukawow.heikalhost.tk                              /ugisogu.html&lt;br /&gt; kumquatphoto.com                                   /&lt;br /&gt; kutrite.ca                                         /&lt;br /&gt; laboiteabonheur.fr                                 /&lt;br /&gt; langleykinsmen.ca                                  /&lt;br /&gt; latiwusa.freewebportal.com                         /mipailmironuxko.html&lt;br /&gt; latunogu.blogstar.tk                               /ovyruwev.html&lt;br /&gt; lavegliacarlone.it                                 /inlcude.html&lt;br /&gt; lexisutherland.com                                 /4fbf35l/index.html&lt;br /&gt; lezisah.notlong.com                                /&lt;br /&gt; lieuwedevries.com                                  /&lt;br /&gt; lifeart-petra-eischeid.de                          /7pm4la2/index.html&lt;br /&gt; liveinconcerto.nl                                  /08e4wt2/index.html&lt;br /&gt; LNK.by                                             /ff843&lt;br /&gt; locker-ba.com.br                                   /site/inlcude.html&lt;br /&gt; loru-lazetes.o-f.com                               /ovtorko.html&lt;br /&gt; lozamita.freewebportal.com                         /pallelundttjoeg.html&lt;br /&gt; lusepewe.sertdisk.net                              /ugisogu.html&lt;br /&gt; lutesylo421.100megsfree5.com                       /mfyainyy7.html&lt;br /&gt; luyized.metrohosting.info                          /erygegy.html&lt;br /&gt; lywobaneb-omic.1accesshost.com                     /oo90rufat.html&lt;br /&gt; lyxnia.gr                                          /2khjpzg/index.html&lt;br /&gt; macservice.vn                                      /&lt;br /&gt; maddogphotography.ca                               /images/main11.html&lt;br /&gt; majs.ca                                            /&lt;br /&gt; mcars.pl                                           /&lt;br /&gt; mesinuangku.net                                    /2krnil/index.html&lt;br /&gt; migre.me                                           /69SRA&lt;br /&gt; miron.notlong.com                                  /&lt;br /&gt; mixland.ca                                         /&lt;br /&gt; mkmdevcenter.ca                                    /&lt;br /&gt; mohidumo.sooot.cn                                  /ubijemat.html&lt;br /&gt; molihove.goearni.info                              /gizazago.html&lt;br /&gt; moq-ydygafyko.greatnow.com                         /povuuk.html&lt;br /&gt; moruyime.pi6.info                                  /nezivog.html&lt;br /&gt; muguhesi.3host.tk                                  /furuser.html&lt;br /&gt; mysejofov1845.fcpages.com                          /selegaaa0808.html&lt;br /&gt; myuu.de                                            /&lt;br /&gt; n2testing.co.uk                                    /&lt;br /&gt; naf-tufamur.dreamstation.com                       /vherzodjor8810.html&lt;br /&gt; nailandhammer.net                                  /&lt;br /&gt; nakayimahotel.com                                  /&lt;br /&gt; nefelefi1879.fcpages.com                           /niskish.html&lt;br /&gt; netdekorasyoninsaat.com                            /&lt;br /&gt; ntlauf.nt.ohost.de                                 /inlcude.html&lt;br /&gt; nyjicited.freewebportal.com                        /nurdete.html&lt;br /&gt; nylaneri-mac.servetown.com                         /ditonii1167.html&lt;br /&gt; nytezuva-pyh.100megsfree5.com                      /eqq6911.html&lt;br /&gt; nz-wolfenhausen.de                                 /kpqnpk/index.html&lt;br /&gt; obehumekid.lookseekpages.com                       /ovenhrehv.html&lt;br /&gt; ochrona-almar.neostrada.pl                         /inlcude.html&lt;br /&gt; ocig-ujaforisoc.exactpages.com                     /podvouskiialezj.html&lt;br /&gt; oficinasvirtualesimc.cl                            /5j4k0ke/index.html&lt;br /&gt; oguce.notlong.com                                  /&lt;br /&gt; ohquudi.notlong.com                                /&lt;br /&gt; okeg-gyhydyq.dreamstation.com                      /oo67ao.html&lt;br /&gt; okywijejaf.maddsites.com                           /ssorpuonu1.html&lt;br /&gt; one-egizad.fcpages.com                             /vavilugxa.html&lt;br /&gt; onipuwavy-oge.dreamstation.com                     /pwuptro.html&lt;br /&gt; ontariobuildingtrades.com                          /5vfe149/index.html&lt;br /&gt; ooblu.com                                          /&lt;br /&gt; ooquoobe.notlong.com                               /&lt;br /&gt; opezopan.100freemb.com                             /pvodateconnection.html&lt;br /&gt; opibak-baw.freewebportal.com                       /mobodultyy04.html&lt;br /&gt; oqomijoh.virtue.nu                                 /nyculmoaa0.html&lt;br /&gt; oral-hekegudu.arcadepages.com                      /zrooo72000.html&lt;br /&gt; ostwestfalen-lippe.de                              /8ffzcx1/index.html&lt;br /&gt; otrasexshopmas.com                                 /81p88fk/index.html&lt;br /&gt; ourdogz.nl                                         /04x6pt/index.html&lt;br /&gt; oursdes4saisons.com                                /~oursdess/fjnopyy/index.html&lt;br /&gt; outsourcemanpower.com                              /~outso4/4jz88e/index.html&lt;br /&gt; outtheboxmusik.com                                 /1vpj9l/index.html&lt;br /&gt; ovarc.us                                           /3df0ta/index.html&lt;br /&gt; overnightclippingpath.com                          /a3g2pwc/index.html&lt;br /&gt; ovijujase.exactpages.com                           /rmren.html&lt;br /&gt; owehyrufiz.freewebportal.com                       /wubuyukiyndo.html&lt;br /&gt; owips.square7.ch                                   /pc6ypb1/index.html&lt;br /&gt; oxodopi-cuce.maddsites.com                         /uurnorld15.html&lt;br /&gt; oxu-yvurobuboh.freehostyou.com                     /topcaf881.html&lt;br /&gt; oxymarketing.com.br                                /inlcude.html&lt;br /&gt; oyuncumusun.com                                    /2sfjyh2/index.html&lt;br /&gt; ozcanymm.net                                       /&lt;br /&gt; ozinocug.o-f.com                                   /njuf.html&lt;br /&gt; p131879.webspaceconfig.de                          /d07a0hw/index.html&lt;br /&gt; p7902.typo3server.info                             /9f9bp6n/index.html&lt;br /&gt; paetzold-beratung.de                               /cvo8xq/index.html&lt;br /&gt; PageDr.com                                         /d1mqfg7/index.html&lt;br /&gt; pagedrakemusic.com                                 /1o1eis/index.html&lt;br /&gt; paintball-bohinj.si                                /00vb7md/index.html&lt;br /&gt; paiportacf.com                                     /7t62aei/index.html&lt;br /&gt; palathinkalktm.org                                 /hogm7g/index.html&lt;br /&gt; panmotorsports.com                                 /53412dc/index.html&lt;br /&gt; panteleon.de                                       /6t73qt/index.html&lt;br /&gt; panzercrom.com                                     /1yd59f/index.html&lt;br /&gt; paokvolos.gr                                       /13abr4/index.html&lt;br /&gt; paperequipment.com                                 /1lt2bt/index.html&lt;br /&gt; ParkGina.com                                       /2xi5al/index.html&lt;br /&gt; partnersarl.lu                                     /a6c9j6d/index.html&lt;br /&gt; pascal-bellefroid.be                               /627bqd6/index.html&lt;br /&gt; paspartoy.gr                                       /77j0m9/index.html&lt;br /&gt; passgo.ca                                          /&lt;br /&gt; paszczak.pl                                        /6vgjxor/index.html&lt;br /&gt; paynterparmesan.com.au                             /0tnx3ta/index.html&lt;br /&gt; pcapinvest.com                                     /t373ygr/index.html&lt;br /&gt; p-center.biz                                       /169mdzp/index.html&lt;br /&gt; pchelpch.pc.ohost.de                               /1fdlwp/index.html&lt;br /&gt; pcmswitch.co.uk                                    /1so14g/index.html&lt;br /&gt; pc-tuning.be                                       /5mgsw8z/index.html&lt;br /&gt; pcwbc.ca                                           /&lt;br /&gt; pdc.bplaced.net                                    /5c9tin/index.html&lt;br /&gt; pdrg.zxq.net                                       /5rte95/index.html&lt;br /&gt; pdsignatures.com                                   /o1l5a4/index.html&lt;br /&gt; peachesandcreamspas.com                            /&lt;br /&gt; peelcruise.com                                     /3xw40nk/index.html&lt;br /&gt; peluangusahaonlines.com                            /57tt9o/index.html&lt;br /&gt; penisenlargementcourse.com                         /bb8yhu/index.html&lt;br /&gt; perfilthermik.com                                  /lkpeam/index.html&lt;br /&gt; perso.ovh.net                                      /~polyverr/74r128/index.html&lt;br /&gt; personalinjuryaccidents.com                        /dogsyd/index.html&lt;br /&gt; peruvision.de                                      /95nivmn/index.html&lt;br /&gt; PeshawarJin.com                                    /13d4tx/index.html&lt;br /&gt; peveduto.com.br                                    /&lt;br /&gt; pheebaha.notlong.com                               /&lt;br /&gt; philipdc.ph.funpic.de                              /cx52om/index.html&lt;br /&gt; philippe-decotte.fr                                /~philippezm/i7nsv9i/index.html&lt;br /&gt; philippinetyphoons.com                             /25jy8gd/index.html&lt;br /&gt; phobiaman.co.uk                                    /9af3v8/index.html&lt;br /&gt; ph-online.net                                      /37tyaxa/index.html&lt;br /&gt; photosdumonde.info                                 /&lt;br /&gt; phprecdb.bplaced.net                               /7s4y1p/index.html&lt;br /&gt; pictureahealthierworld.org                         /4e7h78z/index.html&lt;br /&gt; piefaez.notlong.com                                /&lt;br /&gt; pies.edu.pk                                        /~piesedup/f0grdvr/index.html&lt;br /&gt; pifadew.bdlike.com                                 /buluvivy.html&lt;br /&gt; pinskylickstein.com                                /h3fywd/index.html&lt;br /&gt; pioneerweb.in                                      /a9zkq8i/index.html&lt;br /&gt; pite-olacelyb.100freemb.com                        /gvizdikvk.html&lt;br /&gt; pixa-design.de                                     /4xmbbut/index.html&lt;br /&gt; pixe.mx                                            /&lt;br /&gt; pixelyn.co.za                                      /~pbxnet/0p9gu8/index.html&lt;br /&gt; pkphotography.com                                  /93b6jfu/index.html&lt;br /&gt; plasticimages.com                                  /504mcxt/index.html&lt;br /&gt; playgroupstudio.com                                /4ycljge/index.html&lt;br /&gt; playweb.6po.pl                                     /&lt;br /&gt; plexuscomms.com.au                                 /chu594/index.html&lt;br /&gt; plummessage.com                                    /lt7joa/index.html&lt;br /&gt; pmtm.com                                           /78gr9so/index.html&lt;br /&gt; poizonroze.com                                     /1ujn1kg/index.html&lt;br /&gt; Pokerworld.com.au                                  /4mebwl2/index.html&lt;br /&gt; polidor.eu                                         /29e41h/index.html&lt;br /&gt; polimitlc.altervista.org                           /119976/index.html&lt;br /&gt; poliprodukt.pl                                     /frjawen.html&lt;br /&gt; popihug.indiv.in                                   /ugisogu.html&lt;br /&gt; poppenhouse.ru                                     /2x1gsy/index.html&lt;br /&gt; porezi.rs                                          /&lt;br /&gt; portonesautomaticos-ferrobone.cl                   /260je7o/index.html&lt;br /&gt; portrait-skulpturen.de                             /6d138g6/index.html&lt;br /&gt; prismproductions.net                               /0edicf/index.html&lt;br /&gt; prodomoelec.com                                    /&lt;br /&gt; pronutrition.ca                                    /&lt;br /&gt; prosolv.se                                         /&lt;br /&gt; puqupity-sase.bigheadhosting.net                   /lapwevuu04.html&lt;br /&gt; pushkardesigns.com                                 /&lt;br /&gt; putovuve.arcadepages.com                           /abee680.html&lt;br /&gt; qarehuq.hosthost.info                              /ruvyhupa.html&lt;br /&gt; qejazocuf-adus.dreamstation.com                    /nightshado257.html&lt;br /&gt; qejuticu.pubwebhost.com                            /ygegysed.html&lt;br /&gt; qezevosak.s-enterprize.com                         /dcbadur.html&lt;br /&gt; qibuxumu-gen.freewebportal.com                     /ovehdiligenz.html&lt;br /&gt; qim-tajomuhu.virtue.nu                             /xnryy596.html&lt;br /&gt; qoge-wigiqiber.freewebportal.com                   /hhaj.html&lt;br /&gt; qr.net                                             /fqv2&lt;br /&gt; queller-gemeinschaft.de                            /3rysoo/index.html&lt;br /&gt; quze-fegabugage.freewebportal.com                  /qbohrint.html&lt;br /&gt; qybo-hubybewu.freewebsitehosting.com               /nonplatentiluu21.html&lt;br /&gt; qyn-otomibezo.1accesshost.com                      /nobolybo13.html&lt;br /&gt; qyxozoxija.dreamstation.com                        /ptym2111.html&lt;br /&gt; racogad-upy.greatnow.com                           /plaloj.html&lt;br /&gt; ramebeny1368.greatnow.com                          /prompncyyy42.html&lt;br /&gt; rapidosports.com                                   /&lt;br /&gt; raum-wolfenhausen.de                               /39zvuv3/index.html&lt;br /&gt; redir.ec                                           /8aOr5&lt;br /&gt; rekufel.3host4.info                                /wuvyhup.html&lt;br /&gt; rerajo-qaz.digitalzones.com                        /onioo8.html&lt;br /&gt; restaurantposthalterey.de                          /1gml2xu/index.html&lt;br /&gt; rid-yzytawaj.1accesshost.com                       /bursopaff.html&lt;br /&gt; riteyolu.0fees.net                                 /lodugiz.html&lt;br /&gt; safe.mn                                            /3tJR&lt;br /&gt; safer63and881.com                                  /&lt;br /&gt; saform.com.pl                                      /&lt;br /&gt; sahecafa.3net.tk                                   /furuser.html&lt;br /&gt; saracens-fhc.ca                                    /&lt;br /&gt; scrapbookersbliss.com                              /&lt;br /&gt; seasonal56.ca                                      /&lt;br /&gt; semineedevis.ro                                    /&lt;br /&gt; sensalights.com                                    /in11.html&lt;br /&gt; senuyave.yk0.net                                   /wuvyhupa.html&lt;br /&gt; sezaylighting.com                                  /&lt;br /&gt; sezogoca-epy.mindnmagick.com                       /restole.html&lt;br /&gt; shangpalace.com.vn                                 /&lt;br /&gt; shorl.com                                          /difratresutyby&lt;br /&gt; siamrestaurant.ca                                  /&lt;br /&gt; simurl.com                                         /bepnac&lt;br /&gt; siperbinvestments.com                              /&lt;br /&gt; smx1.hostdime.com.mx                               /~periodic/0hfmuib/index.html&lt;br /&gt; snipr.com                                          /2oalgv&lt;br /&gt; snipurl.com                                        /2oalwc&lt;br /&gt; sojesif.hostingforfree.org                         /gagicyb.html&lt;br /&gt; sorupemu.4ever20bucks.info                         /kejaruv.html&lt;br /&gt; sothbys.ho.ua                                      /&lt;br /&gt; srisaipearls.com                                   /&lt;br /&gt; stepnik.de                                         /9u4ougo/index.html&lt;br /&gt; stykky.pl                                          /&lt;br /&gt; succesvol.su.funpic.org                            /&lt;br /&gt; sudarom-dyke.dreamstation.com                      /qfoiio6g.html&lt;br /&gt; surarena.rs                                        /inlcude.html&lt;br /&gt; sweetroute.com                                     /&lt;br /&gt; sytixytex140.s-enterprize.com                      /nicolahg.html&lt;br /&gt; taklitci.com                                       /&lt;br /&gt; tamilsudartv.com                                   /fejkb8e/index.html&lt;br /&gt; tasaqifa.hostingwithu.com                          /uhezivo.html&lt;br /&gt; tassilomusic.com                                   /&lt;br /&gt; taximihywe-pyri.bigheadhosting.net                 /kipusyy00.html&lt;br /&gt; tbspirit.com                                       /&lt;br /&gt; tcjc.ca                                            /&lt;br /&gt; tcproperties.co.za                                 /&lt;br /&gt; teamprimerib.com                                   /12evdr/index.html&lt;br /&gt; tegikobi.w9l.in                                    /edoruvy.html&lt;br /&gt; telusplanet.net                                    /~polihale/40ht0fa/index.html&lt;br /&gt; teqaqybu.freewebportal.com                         /nermox.html&lt;br /&gt; ternama.com                                        /&lt;br /&gt; tesuzuma-tah.freehostyou.com                       /zhavneree1971.html&lt;br /&gt; thaore.notlong.com                                 /&lt;br /&gt; thegrandehaven.com                                 /&lt;br /&gt; thesacredvoicegallery.com                          /&lt;br /&gt; thesurl.com                                        /11&lt;br /&gt; ticoyez.297m.com                                   /gudylog.html&lt;br /&gt; tie.ly                                             /_ggeqie&lt;br /&gt; tisilume.qualityprohost.com                        /sedejodu.html&lt;br /&gt; tllg.net                                           /aUm4&lt;br /&gt; tm-studio.com.pl                                   /&lt;br /&gt; tolenaars.nl                                       /&lt;br /&gt; topolema.koon.pl                                   /ivyfurus.html&lt;br /&gt; toronto-orienteering.com                           /pictures/main.html&lt;br /&gt; totavalaw-zejy.freewebportal.com                   /nunes.html&lt;br /&gt; toyamakitokito.web.fc2.com                         /&lt;br /&gt; trmfiltration.com                                  /&lt;br /&gt; trucksidefunding.ca                                /&lt;br /&gt; tujeqexo.000adz.com                                /nezivogo.html&lt;br /&gt; tuvoca1466.freewebportal.com                       /rdobyllo.html&lt;br /&gt; u-china-consulting.com                             /1qvkcx5/index.html&lt;br /&gt; uci-nyhiguve.fcpages.com                           /trobexso.html&lt;br /&gt; ucugywyl.fcpages.com                               /brntschrmnf.html&lt;br /&gt; ugi-ypuwewipax.freewebportal.com                   /otakunojoworo.html&lt;br /&gt; uhocekef.servetown.com                             /heaami.html&lt;br /&gt; ujugob-ytoz.100megsfree5.com                       /ivadpomidorivf.html&lt;br /&gt; ulmer-shop.de                                      /2rsl1a/index.html&lt;br /&gt; ultraline.it                                       /&lt;br /&gt; umy-qekuqi.dreamstation.com                        /irnuschel.html&lt;br /&gt; unbrockandice.ca                                   /images/in11.html&lt;br /&gt; unitedbookgroup.com                                /&lt;br /&gt; upihigajar.1accesshost.com                         /pipkertyn.html&lt;br /&gt; upmarketing.mx                                     /&lt;br /&gt; url.ie                                             /dia9&lt;br /&gt; usifof-ufy.o-f.com                                 /prosencaphalecii21.html&lt;br /&gt; usyrepihon-elaz.1accesshost.com                    /pronessorsii62.html&lt;br /&gt; vabefod-uron.greatnow.com                          /ldnrkaa5.html&lt;br /&gt; vahaxisasu.mindnmagick.com                         /vokolak.html&lt;br /&gt; valanali.cuccfree.com                              /icutovov.html&lt;br /&gt; vaneenoo.eu                                        /images/index11.html&lt;br /&gt; vbvastgoed.nl                                      /&lt;br /&gt; velvetropemiami.com                                /jl3o9c/index.html&lt;br /&gt; vesadofefy.freewaywebhost.com                      /nuhedreampirls.html&lt;br /&gt; vetmobile.ca                                       /&lt;br /&gt; video.web2001.cz                                   /&lt;br /&gt; viphoco.notlong.com                                /&lt;br /&gt; vlamos-homerealty.gr                               /&lt;br /&gt; voyibopa.cuscovirtual.tk                           /ivefuquw.html&lt;br /&gt; vugojape.mindnmagick.com                           /nonspors.html&lt;br /&gt; vuhyzeto1234.exactpages.com                        /wroromunticii71.html&lt;br /&gt; walther-reinhardt.de                               /bvbiohh/index.html&lt;br /&gt; wanaqecu.onlin-e.net                               /lodugiz.html&lt;br /&gt; wca8532g2.homepage.t-online.de                     /d2gcop/index.html&lt;br /&gt; webresourcecentral.com                             /2858sa/index.html&lt;br /&gt; webseosmoservices.com                              /&lt;br /&gt; welfare114.net                                     /&lt;br /&gt; welfens.de                                         /8tc00m/index.html&lt;br /&gt; wetyqifu1471.1accesshost.com                       /sluvataxo.html&lt;br /&gt; whistleradio.com                                   /&lt;br /&gt; wiyetipa.webhostingforfree.org                     /ymanibu.html&lt;br /&gt; wohi-xygumu.1accesshost.com                        /dystemhakem.html&lt;br /&gt; wp.tedinet.com                                     /bx0koa/index.html&lt;br /&gt; wsconsulting.ca                                    /&lt;br /&gt; wuda-lolexu.maddsites.com                          /murokchiok.html&lt;br /&gt; www.africanelections.org                           /4qtmbt/index.html&lt;br /&gt; www.athmainfosolutions.com                         /29ial3/index.html&lt;br /&gt; www.avtkhyber.com                                  /1tcnzx/index.html&lt;br /&gt; www.bakou.gr                                       /h1hmsp/index.html&lt;br /&gt; www.casainlegnohonka.it                            /wmi34d/index.html&lt;br /&gt; www.desmidspijk.nl                                 /&lt;br /&gt; www.dldsrl.it                                      /&lt;br /&gt; www.flooringin.ae                                  /&lt;br /&gt; www.garagevanstraelen.be                           /&lt;br /&gt; www.hadi-art.com                                   /&lt;br /&gt; www.honkafusion.it                                 /t8xfifq/index.html&lt;br /&gt; www.jenabakery.com                                 /&lt;br /&gt; www.lumhongye.com                                  /13f2em/index.html&lt;br /&gt; www.mesinuangku.net                                /~peluang4/sa0hxip/index.html&lt;br /&gt; www.parimpood.ee                                   /16e6beb/index.html&lt;br /&gt; www.pcrutchfield.com                               /1g9wxxn/index.html&lt;br /&gt; www.peluangusahaonlines.com                        /28dvhds/index.html&lt;br /&gt; www.pension-kleinekorte-guestrow.de                /&lt;br /&gt; www.phobiaman.co.uk                                /81ccngg/index.html&lt;br /&gt; www.photoeditingservices.co.uk                     /3sr31z5/index.html&lt;br /&gt; www.physicaltherapy.co.ke                          /9a54nqy/index.html&lt;br /&gt; www.pies.edu.pk                                    /2nktlke/index.html&lt;br /&gt; www.plasticsurgeryinstituteofcalifornia.com        /aojaas/index.html&lt;br /&gt; www.poodlesislandwear.com                          /eoqf7q/index.html&lt;br /&gt; www.postandparcel.net                              /52xxjn/index.html&lt;br /&gt; www.proalkoholici.cz                               /atb.html&lt;br /&gt; www.publishingoutsourcing.com                      /2e0dh9/index.html&lt;br /&gt; www.seriilanlar-antalya.com                        /&lt;br /&gt; www.stockkamp.com                                  /&lt;br /&gt; www.wouda-assu.nl                                  /&lt;br /&gt; xagemume.bdlike.com                                /iticuto.html&lt;br /&gt; xechuyendung.net                                   /&lt;br /&gt; xikuga486.1accesshost.com                          /anrrey216vorkuta.html&lt;br /&gt; xizakobiv1963.freewebsitehosting.com               /avevbroaren.html&lt;br /&gt; xoragam.hostingperron.com                          /cacejodu.html&lt;br /&gt; xumubowo.johaneswisnu.info                         /ejodugiz.html&lt;br /&gt; ycomefy1524.bigheadhosting.net                     /aanbelochik.html&lt;br /&gt; yeasheve.notlong.com                               /&lt;br /&gt; ygo-foxucobyzy.virtue.nu                           /mojoqens.html&lt;br /&gt; yiprint.com.tw                                     /&lt;br /&gt; yjoliveba.freewebsitehosting.com                   /demonidi9.html&lt;br /&gt; ymob-cezulu.freewaywebhost.com                     /quak0610.html&lt;br /&gt; ymoz-afydybime.mindnmagick.com                     /pichugana627.html&lt;br /&gt; yosulag.freehost.artonat.com                       /oruvyhup.html&lt;br /&gt; yulasuhu.adsfree.ru                                /xubijema.html&lt;br /&gt; yusaduy.123bemyhost.com                            /uhezivo.html&lt;br /&gt; yxydyt-caxa.mindnmagick.com                        /oxueywro.html&lt;br /&gt; yzic-kuligu.lookseekpages.com                      /oupslyng.html&lt;br /&gt; yzid-ufehupuse.servetown.com                       /mlitvyaj.html&lt;br /&gt; zawizifani366.freewaywebhost.com                   /qumusegu.html&lt;br /&gt; zebuana.de                                         /&lt;br /&gt; zeh-patinuli.lookseekpages.com                     /nicsfev.html&lt;br /&gt; zespol-millenium.home.pl                           /&lt;br /&gt; zil-vakahidyti.lookseekpages.com                   /umnyk.html&lt;br /&gt; zoom.nsjet.com                                     /~pochince/28nz9l/index.html&lt;br /&gt; zulu-ezaxodevic.freewebsitehosting.com             /dimenhofigan.html&lt;br /&gt; zymuzymugo271.s-enterprize.com                     /bcretkon.html&lt;br /&gt; zyvu-umodecy.1accesshost.com                       /rvm.html&lt;br /&gt; zyxukifuzo.1accesshost.com                         /dmimkac.html&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;====================&lt;br /&gt;List of Financial Institutions used by the "zfin" spam . . . &lt;br /&gt;&lt;br /&gt; 1st Bank Yuma &lt;br /&gt; 1st Capital Bank &lt;br /&gt; 1st Centennial Bank &lt;br /&gt; 1st Enterprise Bank &lt;br /&gt; 1st National Bank of Scotia &lt;br /&gt; 1st Pacific Bank of California &lt;br /&gt; 1st Source Bank &lt;br /&gt; Abacus Federal SAvings Bank &lt;br /&gt; ABC International Bank &lt;br /&gt; ABN AMRO Bank &lt;br /&gt; Abrams Centre National Bank &lt;br /&gt; Affinity Bank &lt;br /&gt; Agriland FCS &lt;br /&gt; AgTexas &lt;br /&gt; Aig Federal SAvings Bank &lt;br /&gt; Alamerica Bank &lt;br /&gt; Aliant Bank &lt;br /&gt; Allegiance Community Bank &lt;br /&gt; Alliance Bank &lt;br /&gt; Alliance Bank of Arizona &lt;br /&gt; Allied Irish Bank &lt;br /&gt; Alta Alliance Bank &lt;br /&gt; Amalgamated Bank of Chicago &lt;br /&gt; Amarillo National Bank &lt;br /&gt; Amcore Bank &lt;br /&gt; Amegy Bank of Texas &lt;br /&gt; Ameriana Bank and Trust &lt;br /&gt; America California Bank &lt;br /&gt; American Bank &lt;br /&gt; American Bank of Commerce &lt;br /&gt; American Bank of Texas &lt;br /&gt; American Business Bank &lt;br /&gt; American Express Bank Limited &lt;br /&gt; American National Bank &lt;br /&gt; American National Bank of Texas &lt;br /&gt; American River Bank &lt;br /&gt; American Riviera Bank &lt;br /&gt; American Savings Bank &lt;br /&gt; American State ABnk &lt;br /&gt; American State Bank &lt;br /&gt; Americas United Bank &lt;br /&gt; Amsouth Bank &lt;br /&gt; Amsterdam Savings Bank &lt;br /&gt; ANZ Bank &lt;br /&gt; Applied Card Systems &lt;br /&gt; Archer Bank &lt;br /&gt; Artisans Bank &lt;br /&gt; Atlantic Bank of New York &lt;br /&gt; Atlantic Pacific Bank &lt;br /&gt; Atlas Savings Bank &lt;br /&gt; AuburnBank &lt;br /&gt; Austin Bank &lt;br /&gt; Austin County State Bank &lt;br /&gt; Austin Telco Federal Creit Union &lt;br /&gt; Balboa Thrift and Loan Association &lt;br /&gt; Balcones Bank &lt;br /&gt; Ballston Spa National Bank &lt;br /&gt; Bank Atlantic &lt;br /&gt; Bank Calumet &lt;br /&gt; Bank Independent &lt;br /&gt; Bank of Agriculture and Commerce &lt;br /&gt; Bank of Akron &lt;br /&gt; Bank of Amador &lt;br /&gt; Bank of Baroda &lt;br /&gt; Bank of Castile &lt;br /&gt; Bank of Evergreen &lt;br /&gt; Bank Of Illinois &lt;br /&gt; Bank of India &lt;br /&gt; Bank of Los Altos &lt;br /&gt; Bank of Marin &lt;br /&gt; Bank of Marion &lt;br /&gt; Bank of New York &lt;br /&gt; Bank of Orange County &lt;br /&gt; Bank of Pensacola &lt;br /&gt; Bank of Petaluma &lt;br /&gt; Bank of Pine Hill &lt;br /&gt; Bank of Prattville &lt;br /&gt; Bank of Quincy &lt;br /&gt; Bank of Rantoul &lt;br /&gt; Bank of Rio Vista &lt;br /&gt; Bank of Sacramento &lt;br /&gt; Bank of Santa Barbara &lt;br /&gt; Bank of Santa Clarita &lt;br /&gt; Bank of Springfield &lt;br /&gt; Bank of Stockton &lt;br /&gt; Bank of Tampa &lt;br /&gt; Bank of the Orient &lt;br /&gt; Bank of the Sierra &lt;br /&gt; Bank of the Southwest &lt;br /&gt; Bank of the West &lt;br /&gt; Bank of Tidewater &lt;br /&gt; Bank of Tuscaloosa &lt;br /&gt; Bank of Vernon &lt;br /&gt; Bank of Walnut Creek &lt;br /&gt; Bank of Waukegan &lt;br /&gt; Bank One &lt;br /&gt; Bank United &lt;br /&gt; BankChampaign &lt;br /&gt; Bankers Trust Company &lt;br /&gt; BankFIRST &lt;br /&gt; BankUnited Express &lt;br /&gt; Barclays Bank &lt;br /&gt; Barrington Bank and Trust &lt;br /&gt; Bay Area Bank &lt;br /&gt; Bay Cities National Bank &lt;br /&gt; Bay Commercial Bank &lt;br /&gt; Beal Bank &lt;br /&gt; Belvidere Bank &lt;br /&gt; Benchmark Bank &lt;br /&gt; Beverly Bank &lt;br /&gt; Bluestem National Bank &lt;br /&gt; Borel Bank &lt;br /&gt; Borrego Springs Bank &lt;br /&gt; Brady National Bank &lt;br /&gt; Brenham National Bank &lt;br /&gt; Brickyard Bank &lt;br /&gt; Bridgehampton National Bank &lt;br /&gt; Broadway Bank &lt;br /&gt; Broadway Federal Bank &lt;br /&gt; Broadway Federal Bank FSB &lt;br /&gt; Broadway National Bank &lt;br /&gt; Brooklyn Federal Savings Bank &lt;br /&gt; Brown Brothers Harriman &lt;br /&gt; Busey Bank &lt;br /&gt; Business Bank of California &lt;br /&gt; Business First National Bank &lt;br /&gt; Butte Community Bank &lt;br /&gt; Caledonian Fund Services &lt;br /&gt; California Bank and Trust &lt;br /&gt; California Community Bank &lt;br /&gt; California Federal Bank &lt;br /&gt; California National Bank &lt;br /&gt; California Oaks State Bank &lt;br /&gt; California State Bank &lt;br /&gt; Canadaigua National Bank and Trust Company &lt;br /&gt; Canyon Community Bank &lt;br /&gt; Canyon National Bank &lt;br /&gt; Capital City Bank &lt;br /&gt; Capital Farm Credit &lt;br /&gt; Cardinal Services Corp &lt;br /&gt; Carlinville National Bank &lt;br /&gt; Carver Federal SAvings Bank &lt;br /&gt; Cathay Bank &lt;br /&gt; Cattaraugus County Bank &lt;br /&gt; Centier Bank &lt;br /&gt; Central California Bank &lt;br /&gt; Central Illinois Bank &lt;br /&gt; Central National Bank of Waco &lt;br /&gt; Central Trust and Savings Bank &lt;br /&gt; Central Valley Community Bank &lt;br /&gt; Century Bank &lt;br /&gt; CFS Bank &lt;br /&gt; Champlain National Bank &lt;br /&gt; Chang Hwa Commercial Bank Ltd &lt;br /&gt; Charlotte State Bank &lt;br /&gt; Charter National Bank &lt;br /&gt; Charter Oak Bank &lt;br /&gt; Chase Manhattan Bank &lt;br /&gt; Chicago Community Bank &lt;br /&gt; Chino Commercial Bank NA &lt;br /&gt; Circle Bank &lt;br /&gt; Citibank &lt;br /&gt; Citizens Bank &lt;br /&gt; Citizens Bank Baytown &lt;br /&gt; Citizens Bank of Northern California &lt;br /&gt; Citizens Business Bank &lt;br /&gt; Citizens Community Bank &lt;br /&gt; Citizen's Federal Savings Bank &lt;br /&gt; Citizens First Bank &lt;br /&gt; Citizens National Bank &lt;br /&gt; Citizens National Bank of Macomb &lt;br /&gt; Citizens State Bank &lt;br /&gt; Citrus Bank NA &lt;br /&gt; City Bank Lubbock &lt;br /&gt; City National Bank &lt;br /&gt; City National Bank of Florida &lt;br /&gt; City State Bank of Palacios &lt;br /&gt; CivicBank of Commerce &lt;br /&gt; Clarendon Hills Bank &lt;br /&gt; Claritybank &lt;br /&gt; Clay County Bank &lt;br /&gt; Clear Lake National Bank &lt;br /&gt; Coast Commercial Bank &lt;br /&gt; Coast National Bank &lt;br /&gt; Cohen Financial &lt;br /&gt; Cohoes SAvings Bank &lt;br /&gt; Coldwell Banker Commercial PR &lt;br /&gt; Columbia Bank &lt;br /&gt; Comerica &lt;br /&gt; Commerce Bank of Folsom &lt;br /&gt; Commerce National Bank &lt;br /&gt; Commercial Bank of California &lt;br /&gt; Commercial National Bank &lt;br /&gt; Commerzbank &lt;br /&gt; Commonwealth Business Bank &lt;br /&gt; Commonwealth Trust Company &lt;br /&gt; Community 1st Bank &lt;br /&gt; Community Bank &lt;br /&gt; Community Bank and Trust &lt;br /&gt; Community Bank of Elmhurst &lt;br /&gt; Community Bank of Florida &lt;br /&gt; Community Bank of Naples &lt;br /&gt; Community Bank of San Joaquin &lt;br /&gt; Community Bank of Santa Maria &lt;br /&gt; Community Bank of the Bay &lt;br /&gt; Community Bank Texas &lt;br /&gt; Community Banks of Northern California &lt;br /&gt; Community Business Bank &lt;br /&gt; Community Commerce Bank &lt;br /&gt; Community First Bank of Howard County &lt;br /&gt; Community Savings &lt;br /&gt; Community West Bank &lt;br /&gt; Compass Bank &lt;br /&gt; Coppermark Bank &lt;br /&gt; Cornerstone Community Bank &lt;br /&gt; Coronado First Bank &lt;br /&gt; Corus Bank &lt;br /&gt; County Bank &lt;br /&gt; Credit Suisse First Boston &lt;br /&gt; Cross County Federal Savings Bank &lt;br /&gt; Crown Bank &lt;br /&gt; Crystal Lake Bank &lt;br /&gt; DeAnza National Bank &lt;br /&gt; Delaware National Bank &lt;br /&gt; Delta Bank &lt;br /&gt; Delta National Bank &lt;br /&gt; Delta National Bank And Trust Company &lt;br /&gt; Demotte State Bank &lt;br /&gt; DEPFA BANK &lt;br /&gt; Desert Commercial Bank &lt;br /&gt; Deutsche Asset Management &lt;br /&gt; Deutsche Bank &lt;br /&gt; Devon Bank Online &lt;br /&gt; Downers Grove National Bank &lt;br /&gt; Downey Savings &lt;br /&gt; Eagle Bank &lt;br /&gt; East West Bank &lt;br /&gt; Edens Bank &lt;br /&gt; Edgar County Bank and Trust &lt;br /&gt; Effingham State Bank &lt;br /&gt; EFG Capital International Corp &lt;br /&gt; Eisenhower National Bank &lt;br /&gt; El Dorado Savings Bank &lt;br /&gt; El Paseo Bank &lt;br /&gt; Eldorado Bank &lt;br /&gt; Elgin Financial Savings Bank &lt;br /&gt; Elmira Savings Bank FSB &lt;br /&gt; Emerald Coast Bank &lt;br /&gt; Englewood Bank &lt;br /&gt; Esse Hypothekenbank &lt;br /&gt; Eureka Bank &lt;br /&gt; Eurohypo Aktiengesellschaft &lt;br /&gt; European American Bank &lt;br /&gt; Evans National Bank &lt;br /&gt; Evertrust Bank &lt;br /&gt; Excel National Bank &lt;br /&gt; Exchange Bank &lt;br /&gt; Fairport Saving Bank &lt;br /&gt; Falcon International Bank &lt;br /&gt; Far East National Bank &lt;br /&gt; Farm Credit Bank of Texas &lt;br /&gt; Farmers and Merchants Bank &lt;br /&gt; Farmers National Bank &lt;br /&gt; Farmers State Bank of Hoffman &lt;br /&gt; Federal Home Loan Bank &lt;br /&gt; Federal Home Loan Bank of Dallas &lt;br /&gt; Federal Land Bank &lt;br /&gt; Federal Reserve Bank of Chicago &lt;br /&gt; Federal Reserve Bank of Dallas &lt;br /&gt; Federal Reserve Bank of New York &lt;br /&gt; Federal Reserve Bank of San Francisco &lt;br /&gt; Federal Trust Bank &lt;br /&gt; Fidelity Federal Bank &lt;br /&gt; Fidelity Federal Savings Bank &lt;br /&gt; Fifth Third Bank &lt;br /&gt; Fireside Bank &lt;br /&gt; First American Bank &lt;br /&gt; First Bank &lt;br /&gt; First Bank and Trust &lt;br /&gt; First Bank and Trust Company &lt;br /&gt; First Bank of Clewiston &lt;br /&gt; First Bank of San Luis Obispo &lt;br /&gt; First California Bank &lt;br /&gt; First Chicago Capital &lt;br /&gt; First Choice Bank &lt;br /&gt; First Citrus Bank &lt;br /&gt; First City Bank &lt;br /&gt; First Commerce Bank &lt;br /&gt; First Commercial Bank &lt;br /&gt; First Commercial Bank of Florida &lt;br /&gt; First Community Bank &lt;br /&gt; First Convenience Bank &lt;br /&gt; First Federal Bank &lt;br /&gt; First Franklin Bank &lt;br /&gt; First General Bank &lt;br /&gt; First Gulf Bank &lt;br /&gt; First Home Bank &lt;br /&gt; First Indiana Bank &lt;br /&gt; First Internet Bank of Indiana &lt;br /&gt; First Mercantile Bank &lt;br /&gt; First Metro Bank &lt;br /&gt; First Mountain Bank &lt;br /&gt; First National Bank &lt;br /&gt; First National Bank and Trust &lt;br /&gt; First National Bank of Abilene &lt;br /&gt; First National Bank of Ashford &lt;br /&gt; First National Bank of Bellville &lt;br /&gt; First National Bank of Brookfield &lt;br /&gt; First National Bank of Central California &lt;br /&gt; First National Bank of Chillicothe &lt;br /&gt; First National Bank of Danville &lt;br /&gt; First National Bank of Dryden &lt;br /&gt; First National Bank of Eagle Lake &lt;br /&gt; First National Bank of Jasper &lt;br /&gt; First National Bank of Marengo &lt;br /&gt; First National Bank of Mineola Texas &lt;br /&gt; First National Bank of North County &lt;br /&gt; First National Bank of Northern California &lt;br /&gt; First National Bank of Northern New York &lt;br /&gt; First National Bank of Paris &lt;br /&gt; First National Bank of San Benito &lt;br /&gt; First National Bank of Scottsboro &lt;br /&gt; First National Bank of Steeleville &lt;br /&gt; First National Bank of Trenton &lt;br /&gt; First National Bank of Valparaiso &lt;br /&gt; First National Bank of Waterloo &lt;br /&gt; First Navy Bank &lt;br /&gt; First Niagara Bank &lt;br /&gt; First Northern Bank &lt;br /&gt; First of America &lt;br /&gt; First Priority Bank &lt;br /&gt; First Regional Bank &lt;br /&gt; First Savings Bank FSB &lt;br /&gt; First SAvings Bank of Hegewisch &lt;br /&gt; First Southern National Bank &lt;br /&gt; First Standard Bank &lt;br /&gt; First State Bank &lt;br /&gt; First State Bank Frankston &lt;br /&gt; First State Bank of Eldorado &lt;br /&gt; First State Bank of Shallowater &lt;br /&gt; First State Bank of the Florida Keys &lt;br /&gt; First State Bank of Western Illinois &lt;br /&gt; First United Bank &lt;br /&gt; First USA Bank &lt;br /&gt; First Victoria National Bank &lt;br /&gt; FirstBank of Palm Desert &lt;br /&gt; Five Star Bank &lt;br /&gt; Flatbush Federal Savings &lt;br /&gt; FLBA of Texas &lt;br /&gt; Florida Choice Bank &lt;br /&gt; Florida First Bank &lt;br /&gt; Folsom Lake Bank &lt;br /&gt; Foothill Independent Bank &lt;br /&gt; Fort Hood National Bank &lt;br /&gt; Founders Bank &lt;br /&gt; Founders Community Bank &lt;br /&gt; Franklin Bank &lt;br /&gt; Fremont Bank &lt;br /&gt; Frontier Bank &lt;br /&gt; Frost Bank &lt;br /&gt; Frost National Bank &lt;br /&gt; Fullerton Community Bank &lt;br /&gt; Gateway National Bank &lt;br /&gt; Geddes Federal Savings &lt;br /&gt; General Bank &lt;br /&gt; Genesee Regional Bank &lt;br /&gt; Gerard Klauer Mattison &lt;br /&gt; Gibraltar Bank &lt;br /&gt; Global Resource Bank &lt;br /&gt; Golden Security Bank &lt;br /&gt; Goleta National Bank &lt;br /&gt; Grabill Bank &lt;br /&gt; Grand Bank of Florida &lt;br /&gt; Grand National Bank &lt;br /&gt; Grapeland State Bank &lt;br /&gt; Guaranty Bank &lt;br /&gt; Guaranty Bond Bank &lt;br /&gt; Guaranty Federal Bank &lt;br /&gt; Gulf State Community Bank &lt;br /&gt; Habib American Bank &lt;br /&gt; Hanmi Bank &lt;br /&gt; Hardware State Bank &lt;br /&gt; Harris Trust and savings Bank &lt;br /&gt; Hendricks County Bank and Trust &lt;br /&gt; Heritage Bank East Bay &lt;br /&gt; Heritage Bank of Central Illinois &lt;br /&gt; Heritage Bank of Commerce &lt;br /&gt; Heritage Bank South Valley &lt;br /&gt; Heritage Commerce Corp &lt;br /&gt; Heritage Land Bank &lt;br /&gt; Heritage National Bank &lt;br /&gt; Hickory Point Bank and Trust &lt;br /&gt; Highwood Bank &lt;br /&gt; Hinsdale Bank and Trust &lt;br /&gt; Hinsdale Bank Trust Co &lt;br /&gt; Home National Bank &lt;br /&gt; Honda Bank &lt;br /&gt; Horizon Bank &lt;br /&gt; HSBC Bank &lt;br /&gt; Hudson Valley Bank &lt;br /&gt; Humboldt Bank Merchant Services &lt;br /&gt; Hypo Real Estate Bank International &lt;br /&gt; Illini State Bank &lt;br /&gt; Imperial Bank &lt;br /&gt; Imperial Capital LLC &lt;br /&gt; Independent National Bank &lt;br /&gt; Independent Online &lt;br /&gt; ING Capital LLC &lt;br /&gt; Intercredit Bank &lt;br /&gt; International Bancshares &lt;br /&gt; Interstate Bank of Oak Forest &lt;br /&gt; Invex Grupo Financiero &lt;br /&gt; Irwin Financial Corporation &lt;br /&gt; Israel Discount Bank of New York &lt;br /&gt; Itasca Bank and Trust Co &lt;br /&gt; Jackson County Bank &lt;br /&gt; Jacksonville Savings Bank &lt;br /&gt; Jefferson Heritage Bank &lt;br /&gt; Jefferson State Bank &lt;br /&gt; Jourdanton State Bank &lt;br /&gt; JP Morgan Chase Bank &lt;br /&gt; Key West Bank &lt;br /&gt; Kookmin Bank &lt;br /&gt; Lafayette Bank And Trust &lt;br /&gt; Lafayette Savings Bank &lt;br /&gt; Lake Forest Bank and Trust &lt;br /&gt; Lake Shore SAvings And Loan &lt;br /&gt; Lamar National Bank &lt;br /&gt; Landmark Bank &lt;br /&gt; LaSalle State Bank &lt;br /&gt; Lavine Financial Capital &lt;br /&gt; Legacy Bank of Texas &lt;br /&gt; Lehman Brothers &lt;br /&gt; Liberty Bank &lt;br /&gt; Liberty Federal Bank &lt;br /&gt; Liberty Federal Savings Bank &lt;br /&gt; Libertyville Bank &lt;br /&gt; LIFE Bank &lt;br /&gt; Lone Star Federal Land Bank Association &lt;br /&gt; Long Island Commercial Bank &lt;br /&gt; Long Island Savings Bank &lt;br /&gt; Los Angeles National Bank &lt;br /&gt; Lubbock National Bank &lt;br /&gt; Luther Burbank Savings &lt;br /&gt; Madison Bank &lt;br /&gt; Malaga Bank &lt;br /&gt; Mansfield Bank &lt;br /&gt; Manufacturers Bank &lt;br /&gt; Marathon National Bank &lt;br /&gt; Marina Bank &lt;br /&gt; Marketplace Bank &lt;br /&gt; Mazon State Bank &lt;br /&gt; Mellon 1st Business Bank &lt;br /&gt; Melon Bank by&lt;br /&gt; Mercantile Bank &lt;br /&gt; Mercantile Trust and Savings Bank &lt;br /&gt; Merchants and Southern Bank &lt;br /&gt; Merchants Bank of California &lt;br /&gt; Merchants Bank of Jackson &lt;br /&gt; Merchants National Bank of Aurora &lt;br /&gt; Meridian Bank &lt;br /&gt; Merrill Lynch &lt;br /&gt; MetroBank &lt;br /&gt; Metropolitan Bank &lt;br /&gt; MFB Financial &lt;br /&gt; Mission Community Bank &lt;br /&gt; Mission Oaks National Bank &lt;br /&gt; Modern Bank &lt;br /&gt; Mohave Community &lt;br /&gt; Mohave State Bank &lt;br /&gt; Monroe County Bank &lt;br /&gt; Montecito Bank and Trust &lt;br /&gt; Moody National Bank &lt;br /&gt; Morgan Stanley &lt;br /&gt; Morton Community Bank &lt;br /&gt; Murphy Wall State Bank &lt;br /&gt; Mutual Federal Savings Bank &lt;br /&gt; Mutual of Omaha Bank &lt;br /&gt; Nara Bank National Association &lt;br /&gt; NatBank &lt;br /&gt; National Bank &lt;br /&gt; National Bank of California &lt;br /&gt; National City Bank &lt;br /&gt; New Century Bank &lt;br /&gt; New South Federal Savings Bank &lt;br /&gt; Nexity Bank &lt;br /&gt; North Coast Bank &lt;br /&gt; North Community Bank &lt;br /&gt; North County Bank &lt;br /&gt; North County Savings Bank &lt;br /&gt; North Houston Bank &lt;br /&gt; North Valley Bank &lt;br /&gt; Northern Trust Bank &lt;br /&gt; Northern Trust Company &lt;br /&gt; Northfield Savings Bank &lt;br /&gt; NorthShore Trust Saving &lt;br /&gt; NorthStar Bank &lt;br /&gt; Oak Brook Bank &lt;br /&gt; Oak Lawn Bank &lt;br /&gt; Oak Valley Community Bank &lt;br /&gt; Oceanic Bank &lt;br /&gt; Oceanmark Bank &lt;br /&gt; Oceanside Bank of Jacksonville &lt;br /&gt; Old Florida Bank &lt;br /&gt; Old National Bank &lt;br /&gt; Old Second Bancorp &lt;br /&gt; Old Second Bank of Aurora &lt;br /&gt; OptimumBank &lt;br /&gt; Ossian State Bank &lt;br /&gt; Oswego Community Bank &lt;br /&gt; our bank &lt;br /&gt; Overton Bank and Trust &lt;br /&gt; Owen County State Bank &lt;br /&gt; Pacesetter Bank &lt;br /&gt; Pacific Crest Bank &lt;br /&gt; Pacific National Bank &lt;br /&gt; Pacific Trust Bank &lt;br /&gt; Palm Desert National Bank &lt;br /&gt; Palmer Bank &lt;br /&gt; Park Avenue Capital &lt;br /&gt; Park National Bank &lt;br /&gt; Partners Bank &lt;br /&gt; PathFinder Bank &lt;br /&gt; Peoples Bank of Graceville &lt;br /&gt; Peoples Bank of Lubbock &lt;br /&gt; Peoples Bank of North Alabama &lt;br /&gt; Peoples National Bank &lt;br /&gt; People's Trust Company &lt;br /&gt; Permanent Federal Savings Bank &lt;br /&gt; Perryton National Bank &lt;br /&gt; Pff Bank Trust &lt;br /&gt; Phillipine National Bank &lt;br /&gt; Pilgrim Bank &lt;br /&gt; Pinnacle Bank &lt;br /&gt; Pioneer Savings Bank &lt;br /&gt; Plains National Bank Financial &lt;br /&gt; Plaza Bank &lt;br /&gt; Plumas Bank &lt;br /&gt; Pna Bank &lt;br /&gt; Pointe Bank &lt;br /&gt; Ponce de Leon Federal Savings Bank &lt;br /&gt; Popular Bank of Florida &lt;br /&gt; Power Project Financing &lt;br /&gt; Premier Valley Bank &lt;br /&gt; Prosperity Bank &lt;br /&gt; Provident Bank &lt;br /&gt; Queens County Savings Bank &lt;br /&gt; Raiffeisen Zentralbank AG &lt;br /&gt; Randolf County Bank &lt;br /&gt; Redding Bank of Commerce &lt;br /&gt; Regents Bank &lt;br /&gt; Reliance Bank &lt;br /&gt; Ridgewood Bank &lt;br /&gt; Ripley County Bank &lt;br /&gt; River City Bank &lt;br /&gt; Riverside National Bank &lt;br /&gt; Robertson Stephens &lt;br /&gt; Rondout Savings Bank &lt;br /&gt; Roseville Banking Center &lt;br /&gt; Roslyn Savings Bank &lt;br /&gt; Royal Oaks Bank &lt;br /&gt; RZB Finance LLC &lt;br /&gt; Salin Bank and Trust Company &lt;br /&gt; San Diego National Bank &lt;br /&gt; San Jose National Bank &lt;br /&gt; Sand Ridge Bank &lt;br /&gt; Santa Barbara Bank and Trust &lt;br /&gt; Santa Monica Bank &lt;br /&gt; Saratoga National Bank &lt;br /&gt; Scott State Bank &lt;br /&gt; Seacoast National Bank &lt;br /&gt; Second Federal Savings &lt;br /&gt; Security Federal Savings Bank &lt;br /&gt; Seneca Federal Savings and Loan &lt;br /&gt; Sierra Vista Bank &lt;br /&gt; Silicon Valley Bank &lt;br /&gt; Silverado Bank &lt;br /&gt; Six Rivers National Bank &lt;br /&gt; Sonoma Valley Bank &lt;br /&gt; South Alabama Bank &lt;br /&gt; South County Bank &lt;br /&gt; South Pointe Bank &lt;br /&gt; Southern California Funding &lt;br /&gt; Southern Security Bank &lt;br /&gt; Southwest Bank &lt;br /&gt; Southwest Bank of Texas &lt;br /&gt; Sovereign Bank &lt;br /&gt; Spencer County Bank &lt;br /&gt; Star Bank &lt;br /&gt; Star Bank of Texas &lt;br /&gt; Star Financial Bank &lt;br /&gt; State Bank of Ashland &lt;br /&gt; State Bank of Countryside &lt;br /&gt; State Bank of India &lt;br /&gt; State Bank of Lizton &lt;br /&gt; State Bank of Long Island &lt;br /&gt; State Bank of Texas &lt;br /&gt; State Bank of The Lakes &lt;br /&gt; State Bank of Waterloo &lt;br /&gt; State Farm &lt;br /&gt; State National Bank of West Texas &lt;br /&gt; Staten Island Savings Bank &lt;br /&gt; Sterling Bank &lt;br /&gt; Sterling National Bank &lt;br /&gt; Stone City Bank &lt;br /&gt; Strategic Partners &lt;br /&gt; Success National Bank &lt;br /&gt; Suffolk County National Bank &lt;br /&gt; Sumitomo Bank of California &lt;br /&gt; Summit Bank &lt;br /&gt; Surety Bank &lt;br /&gt; Synergy Bank &lt;br /&gt; Tallahassee State Bank &lt;br /&gt; TCB Bank &lt;br /&gt; TCF National Bank &lt;br /&gt; Tempo Bank &lt;br /&gt; Terre Haute Savings Bank &lt;br /&gt; Texas Bank &lt;br /&gt; Texas Capital Bank &lt;br /&gt; Texas Champion Bank &lt;br /&gt; Texas First Banks &lt;br /&gt; Texas Independent Bank &lt;br /&gt; Texas Land Bank &lt;br /&gt; Texas State Bank &lt;br /&gt; The Astoria Federal Savings Bank &lt;br /&gt; The Bank &lt;br /&gt; The Bank and Trust &lt;br /&gt; The Carson Medlin Company &lt;br /&gt; The Dime Savings Bank of New York &lt;br /&gt; The First American Investment Banking Corporation &lt;br /&gt; The First National Bank of Hico &lt;br /&gt; The First National Bank of Long Island &lt;br /&gt; The First State Bank of North Dakota &lt;br /&gt; The Foothills Bank &lt;br /&gt; The Gifford State Bank &lt;br /&gt; The Independent Bankers Bank &lt;br /&gt; The Laredo National Bank &lt;br /&gt; The Mechanics Bank &lt;br /&gt; The SAvings Bank of Utica &lt;br /&gt; The South Holland Bank &lt;br /&gt; The State National Bank &lt;br /&gt; The Warwick Savings Bank &lt;br /&gt; TIB Bank of the Keys &lt;br /&gt; Tokai Bank of California &lt;br /&gt; Tompkins County Trust Company &lt;br /&gt; Town North Bank &lt;br /&gt; Tremont SAvings Bank &lt;br /&gt; Troy Bank and Trust &lt;br /&gt; Troy Savings Bank &lt;br /&gt; Trustbank &lt;br /&gt; Ulster Savings Bank &lt;br /&gt; Unicredito Italiano &lt;br /&gt; Union Bank of Arizona &lt;br /&gt; Union Bank of California &lt;br /&gt; Union Federal &lt;br /&gt; Union Federal Savings Bank &lt;br /&gt; Union Planters Bank &lt;br /&gt; Union State Bank &lt;br /&gt; United Bank &lt;br /&gt; United California Bank &lt;br /&gt; United Commercial Bank &lt;br /&gt; United Community Bank &lt;br /&gt; United Fidelity Bank &lt;br /&gt; United Security Bank &lt;br /&gt; United Southern Bank &lt;br /&gt; Universal Bank &lt;br /&gt; Upstate Niagara Cooperative &lt;br /&gt; us &lt;br /&gt; Valley Business Bank &lt;br /&gt; Valley Commerce Bank &lt;br /&gt; Valley Independent Bank &lt;br /&gt; Valrico State Bank &lt;br /&gt; Vantage Bank of Alabama &lt;br /&gt; Ventura County Business Bank &lt;br /&gt; Viewpoint Bank &lt;br /&gt; Village Banc of Naples &lt;br /&gt; Vineyard Bank &lt;br /&gt; Vintage Bank &lt;br /&gt; VirtualBank &lt;br /&gt; Visalia Community Bank &lt;br /&gt; Vista Bank &lt;br /&gt; Walden Savings Bank &lt;br /&gt; Warrington Bank &lt;br /&gt; Washington Federal Bank &lt;br /&gt; Washington Savings and Loan &lt;br /&gt; Wells Fargo Bank &lt;br /&gt; West Coast Bank &lt;br /&gt; West Suburban Bank &lt;br /&gt; Western Financial Bank &lt;br /&gt; Western Security Bank &lt;br /&gt; Western Springs Bank &lt;br /&gt; Western Springs National Bank &lt;br /&gt; Whisperwood National Bank &lt;br /&gt; Wilber National Bank &lt;br /&gt; Wilmington Trust &lt;br /&gt; Wilshire State Bank &lt;br /&gt; Wintrust Financial Corporation &lt;br /&gt; Woodforest National Bank &lt;br /&gt; Worth National Bank &lt;br /&gt; WSFS bank &lt;br /&gt; Yolo Community Bank &lt;br /&gt;&lt;br /&gt;==========================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-7092224841658971254?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/7092224841658971254'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/7092224841658971254'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/11/ach-wiretransfer-failed-spam-goes-crazy.html' title='ACH / WireTransfer Failed spam goes crazy!'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-5226443400058377831</id><published>2011-11-09T14:04:00.000-08:00</published><updated>2011-11-09T19:43:16.544-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><title type='text'>Operation Ghost Click: DNSChanger Malware Ring Dismantled</title><content type='html'>Since 2007 computers around the internet have been suffering from a secret ailment.  Sometimes when their owners clicked on a link, they didn't go where they were supposed to go!  The problem was caused by a fairly simple piece of malware called a DNSChanger.  This family of malware only does one thing -- it changes the DNS settings on your computer from the one that you are supposed to use, to one that a cyber criminal has chosen for you to use.  &lt;br /&gt;&lt;br /&gt;Today the FBI and NASA's Office of the Inspector General (NASA-OIG) announced "&lt;a href="http://www.fbi.gov/news/stories/2011/november/malware_110911/malware_110911"&gt;Operation: Ghost Click&lt;/A&gt;" and the arrests of six Estonian criminals who have been involved in this scam since 2007.&lt;br /&gt;&lt;br /&gt;Those arrested by the Estonian Police and Border Guard Board were:&lt;br /&gt;&lt;br /&gt;Vladimir Tsastsin, age 31&lt;br /&gt;Timur Gerassimenko&lt;br /&gt;Dmitri Jegorov&lt;br /&gt;Valeri Aleksejev&lt;br /&gt;Konstantin Poltev&lt;br /&gt;Anton Ivanov&lt;br /&gt;&lt;br /&gt;Andrey Taame, age 31, Russian, is still at large&lt;br /&gt;&lt;br /&gt;We were especially pleased by the sidebar entitled "Success Through Partnerships".&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;A complex international investigation such as Operation Ghost Click could only have been successful through the strong working relationships between law enforcement, private industry, and our international partners.&lt;br /&gt;&lt;br /&gt;Announcing today’s arrests, Preet Bharara, (above left) U.S. Attorney for the Southern District of New York, praised the investigative work of the FBI, NASA’s Office of Inspector General (OIG), the Estonian Police and Border Guard Board, and he specially thanked the National High Tech Crime Unit of the Dutch National Police Agency. In addition, the FBI and NASA-OIG received assistance from multiple domestic and international private sector partners, including Georgia Tech University, Internet Systems Consortium, Mandiant, National Cyber-Forensics and Training Alliance, Neustar, Spamhaus, Team Cymru, Trend Micro, &lt;a href="http://www.cis.uab.edu/forensics/"&gt;University of Alabama at Birmingham&lt;/A&gt;, and members of an ad hoc group of subject matter experts known as the DNS Changer Working Group (DCWG).&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;The Manhattan U.S. Attorney's office released a much more detailed announcement with the headline &lt;a href="http://www.fbi.gov/newyork/press-releases/2011/manhattan-u.s.-attorney-charges-seven-individuals-for-engineering-sophisticated-internet-fraud-scheme-that-infected-millions-of-computers-worldwide-and-manipulated-internet-advertising-business"&gt;Manhattan U.S. Attorney Charges Seven Individuals for Engineering Sophisticated Internet Fraud Scheme That Infected Millions of Computers Worldwide and Manipulated Internet Advertising Business: &lt;br /&gt;Malware Secretly Re-Routed More Than 4 Million Computers, Generating at Least $14 Million in Fraudulent Advertising Fees for the Defendants&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;Congratulations to all who were involved!  Especially to the FBI's Botnet Threat Focus Cell, NASA's incredible Office of the Inspector General, the FBI's Southern District of New York office, and those who attended Bar-Con in 2009. &lt;br /&gt;&lt;br /&gt;What is DNS?  DNS, or Domain Name Services, is what tells your computer how to find the website you are looking for by turning the name you type, such as www.fbi.gov, into an IP address, such as 205.128.73.105.  For most users, this happens by asking the Name Server at your Internet Service Provider.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Pay Per Click Fraud&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;If you were infected by this DNSChanger malware, instead of asking your ISP for that information, you would be asking a criminal.  MOST of the time the criminals would simply give you the same answer that your ISP would give you ... but whenever they  wanted to make some extra money, they could tell your computer the wrong answer!  &lt;br /&gt;&lt;br /&gt;In an example taken from the indictment, an infected user goes to Google and types in "itunes".  The first link that they are returned shows the destination "www.apple.com/itunes/" which the real Apple website where someone can download the iTunes software. &lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/ClickJacking.jpg"&gt;&lt;br /&gt;(source: Tsastsin Indictment)&lt;br /&gt;&lt;br /&gt;When an infected computer clicks the link, the user's computer would go to the criminal's nameserver who would send them to the wrong computer.  In this case, instead of going to "apple.com" the user is sent to "www.idownload-store-music.com" which looks just like the Apple store, but which charges your credit card to sell you iTunes!  The criminals received a payment each time they sent someone to this fake websites.  &lt;br /&gt;&lt;br /&gt;In other examples, the company where the traffic is sent to is a legitimate company.  For example, H&amp;R Block, the Tax preparation people, have an affiliate program.  If you have a website, you can put an ad on your website that advertises  the H&amp;R Block website.  If people click on your ad, you might receive a tiny amount of money, and if they buy something at the H&amp;R website, you might receive a larger amount of money.  Instead of advertising, the criminals made a link that redirected you to the H&amp;R Block website if you tried to visit www.irs.gov.  So, because you were using the criminal's nameserver, if you typed or clicked on "irs.gov" you could be redirected to H&amp;R Block, earning an "affiliate payment" for the criminals!&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Ad Replacement&lt;/H3&gt;&lt;br /&gt;The other way the criminal earned money was to replace your ads with their ads.  How does that earn money? The most common way is that when your computer is told to go get an advertisement from a certain website, such as Google or Bing or Yahoo, instead of showing you the advertisement from those organizations, it would show you an ad from an organization that was run by the criminal instead.  &lt;br /&gt;&lt;br /&gt;In an example for the court documents, a visitor to ESPN's webpage should have seen an advertisement for Dr. Pepper.  But when the infected computer visited the webpage, the criminal's nameserver redirected the request to an advertisement for a timeshare instead!&lt;br /&gt;&lt;br /&gt;More than 4 million computers in 100 countries, including 500,000 computers in the United States were infected with this malware.  The earnings generated by these young men from the false advertisements exceeded $14 Million Dollars!&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Blocking Antivirus&lt;/H3&gt;&lt;br /&gt;In addition to using the nameserver to send false advertisements, the criminals also used the nameserver to stop infected computers from being able to reach their anti-virus vendors.  This prevented the user from being able to install new anti-virus products or to update the definitions on their existing anti-virus products.  If the computer attempted to visit any major anti-virus, it would simply give an error saying the server was unavailable.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;The Charges&lt;/H3&gt;&lt;br /&gt;All the criminals are charged with:&lt;br /&gt;1. Wire fraud conspiracy&lt;br /&gt;2. Computer intrusion conspiracy&lt;br /&gt;3. Wire fraud&lt;br /&gt;4. Computer intrusion (furthering fraud)&lt;br /&gt;5. Computer intrusion&lt;br /&gt;&lt;br /&gt;In addition, the ringleader, Vladimir Tsastsin was charged with:&lt;br /&gt;6. Money laundering&lt;br /&gt;7. Engaging in monetary transactions of value over $10,000 involving fraud proceeds.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;So, Are you infected?&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;The Protective Order associated with this case lists the IP addresses involved in the fake nameserver business.&lt;br /&gt;&lt;br /&gt;85.255.112.0 through 85.255.127.255&lt;br /&gt;67.210.0.0 through 67.210.15.255&lt;br /&gt;93.188.160.0 through 93.188.167.255&lt;br /&gt;77.67.83.0 through 77.67.83.255&lt;br /&gt;213.109.64.0 through 213.109.79.255&lt;br /&gt;64.28.176.0 through 64.28.191.255&lt;br /&gt;&lt;br /&gt;The FBI has provided a helpful document that explains how to check your DNS settings to see whether you are using one of these "Rogue DNS Servers".  See &lt;a href="http://www.fbi.gov/news/stories/2011/november/malware_110911/DNS-changer-malware.pdf"&gt;DNSChanger Malware&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;If your IP address is on the list, you are encouraged to fill out the form &lt;a href="https://forms.fbi.gov/dnsmalware"&gt;Register as a Victim of DNS Malware&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;The criminals used many different data centers, some of which were featured more prominently in the case than others.&lt;br /&gt;&lt;br /&gt;Pilosoft, in New York City known as "The Manhattan Data Center" in the court documents.&lt;br /&gt;&lt;br /&gt;ColoSecure, in Chicago, Illinois&lt;br /&gt;&lt;br /&gt;ThePlanet, in Houston, Texas&lt;br /&gt;&lt;br /&gt;Multacom Corporation, in Canyon County, California&lt;br /&gt;&lt;br /&gt;Layered Technologies, in Plano, Texas&lt;br /&gt;&lt;br /&gt;Network Operation Center, in Scranton, Pennsylvania&lt;br /&gt;&lt;br /&gt;Wholesale Internet, in Kansas City, Missouri&lt;br /&gt;&lt;br /&gt;SingleHop, in Chicago, Illinois&lt;br /&gt;&lt;br /&gt;PremiaNet, in Las Vegas, Nevada&lt;br /&gt;&lt;br /&gt;Interserver, in Secaucus, New Jersey&lt;br /&gt;&lt;br /&gt;ISPrime, in Weehawken, New Jersey&lt;br /&gt;&lt;br /&gt;Global Net Access, in Atlanta, Georgia&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;The Challenge&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;The big challenge faced by this case was this -- if the FBI were to simply "turn off" all of these nameservers, four million computers would no longer be able to find anything on the Internet!  If your computer has been programmed by the DNSChanger malware to look up names using the criminals' nameserver, and that nameserver goes away, there is no "fall back" to use some other nameserver, your computer just stops being able to look up names!  If that had happened, when you typed in "www.facebook.com" your computer would say something like "No Such Server" or "Host Unknown".  Then you couldn't play Farmville!  How sad!&lt;br /&gt;&lt;br /&gt;To address this challenge, the FBI filed a Protective Order that identified all of the Rogue DNS Servers, and assigned the IP addresses belonging to those servers to the Internet Systems Consortium, or ISC.  ISC established "replacement DNS servers" that would behave properly, and replaced all of the "Rogue DNS servers" with properly configured DNS servers.  After this was accomplished, none of the infected computers would be redirected to the wrong content anymore, and they would once again be able to update their anti-virus software.&lt;br /&gt;&lt;br /&gt;The other benefit of this action is that ISC is now in a position to be able to compile a list of the computers that have been infected.  Each time a computer uses one of the formerly Rogue DNS servers, ISC will log that action so that we can have accurate knowledge of how many computers have been infected, and this class of victims can be offered assistance.&lt;br /&gt;&lt;br /&gt;The Protective Order was approved by the Honorable William H. Pauly III on November 3rd in the Southern District of New York.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;The Criminal Companies&lt;/H3&gt;&lt;br /&gt;The Estonian criminals controlled a number of corporations to enable this activity.  &lt;br /&gt;&lt;br /&gt;Rove Digital, in Estonia, was a software development company that created and managed the malware.&lt;br /&gt;&lt;br /&gt;Tamme Arendus, also in Estonia, was a real estate development business that acquired most of Rove's assets.&lt;br /&gt;&lt;br /&gt;SPB Group was the name of the company that leased the Manhattan Data Center from Pilosoft.&lt;br /&gt;&lt;br /&gt;Cernel Inc, in California, Internet Path Limited, in New York, Promnet Limited, in Ukraine, ProLite Limited, in Russia, Front Communications, in New York, and others were involved with registering thousands of IP addresses that were used by the criminals for various activities.&lt;br /&gt;&lt;br /&gt;Furox Aps (Gathi.com), Onwa Limited (Uttersearch.com), Lintor Limited (Crossnets.com) and others were used to create and broker advertising deals which would be used in the Replacement Ad schemese.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Other Things You Must Read&lt;/H3&gt;&lt;br /&gt;&lt;a href="http://blog.trendmicro.com/esthost-taken-down-–-biggest-cybercriminal-takedown-in-history/"&gt;TrendMicro's Malware Blog - EstHost Taken Down - Biggest Cybercriminal Takedown in History&lt;/A&gt; - An important link that must be pointed out.  Vladimir Tsastsin, the CEO of Rove Digital, was also the CEO of EstHost, one of the first registrars to have its ICANN Accreditation pulled because of criminal activity.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/a_cybercrime_hub.pdf"&gt;TrendMicro: A Cybercrime Hub&lt;/A&gt; - this report, in August 2009, laid out the basics of the criminal activity that Trend had been able to identify.  Industry contributions such as this are part of the "Partnership for Success" that the FBI spoke about today, and TrendMicro really lead the way on this case!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://voices.washingtonpost.com/securityfix/2008/09/estdomains_a_sordid_history_an.html"&gt;Brian Krebs authoritative journalism on Vladimir - "EstDomains: A Sordid History and a Storied CEO"&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.spamhaus.org/rokso/listing.lasso?file=1128"&gt;SpamHaus ROKSO file on Rove Digital&lt;/A&gt; - ROKSO File (Registry Of Known Spam Offenders) on Rove Digital&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.thedailybeast.com/newsweek/2009/12/29/the-world-s-top-10-spammers.html"&gt;Newsweek calls Rove Digital one of the "Top Ten Spammers"&lt;/A&gt; -(December 2009).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-5226443400058377831?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/5226443400058377831'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/5226443400058377831'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/11/operation-ghost-click-dnschanger.html' title='Operation Ghost Click: DNSChanger Malware Ring Dismantled'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-4183080845176443194</id><published>2011-11-04T05:14:00.000-07:00</published><updated>2011-11-09T19:43:30.006-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><title type='text'>Duqu: You're safe unless you use TrueType Fonts?</title><content type='html'>Two of the malware analysts in my lab have been complaining to me that the malware they see everyday is getting boring - the primary attacks that we see in the largest volume are the same thing over and over and over again.&lt;br /&gt;&lt;br /&gt;Let's be thankful for that!  The big news in the malware world yesterday came when Microsoft announced a work around for Duqu, named by researchers in the &lt;a href="http://www.crysys.hu"&gt;CrySyS Lab&lt;/A&gt; (the Laboratory for Cryptography and System Security at Budapest University of Technology and Economics) because it prefixes some created filenames with the letters "~DQ".&lt;br /&gt;&lt;br /&gt;On October 14, 2011, CrySyS contacted Symantec to get some help analyzing the malware, and Symantec released an extremely informative 67 page PDF report called &lt;a href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_duqu_the_precursor_to_the_next_stuxnet_research.pdf"&gt;W32.Duqu: The Precursor to the next Stuxnet&lt;/A&gt;.  (The link is to version 1.3 of the report, updated on November 1, 2011).&lt;br /&gt;&lt;br /&gt;There have been two IP addresses confirmed to be associated with Duqu and serving as Command &amp; Control.  The first IP was in India - 206.183.111.97.  The second was in Hungary - 77.241.93.160.  Traffic flow to either of these IP addresses would be a strong positive indicator of a Duqu infection!  Both sites are down now.  &lt;br /&gt;&lt;br /&gt;The first server was announced to be down on October 31st in stories such as this one -- &lt;a href="http://articles.economictimes.indiatimes.com/2011-10-29/news/30336502_1_stuxnet-computer-virus-symantec"&gt;India Shuts Server Linked to Duqu Computer Virus&lt;/A&gt; that shares some details of a server located at 200 employee data center Web Werks.&lt;br /&gt;&lt;br /&gt;The second server was at Combell in Belgium -- as described in stories such as this one -- &lt;a href="http://ca.reuters.com/article/technologyNews/idCATRE7A25KC20111103"&gt;Duqu Hackers Shift to Belgium After India Raid&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;Duqu is a data stealing program that shares several blocks of code with Stuxnet.  In fact, one of the two pieces of malware we've seen that is described as being Duqu is also detected as Stuxnet by some AV vendors.  &lt;br /&gt;&lt;br /&gt;Here's a VirusTotal report of the better detected of those pieces of code, which had the MD5 value e1e00c2d5815e4129d8ac503f6fac095.  This file is not "Duqu" but is rather "an .exe file related to Duqu" which is a much larger program (this one is only 9k in size).&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=20a3c5f02b6b79bcac9adaef7ee138763054bbedc298fb2710b5adaf9b74a47d-1320341989"&gt;(Click for VirusTotal Report)&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Non "generic" definitions for this malware included:&lt;br /&gt;&lt;br /&gt;Avast: Win32:Duqu-F&lt;br /&gt;Emsisoft: Trojan.Win32.Stuxnet!IK&lt;br /&gt;Ikarus: Trojan.Win32.Stuxnet&lt;br /&gt;Microsoft: Trojan:Win32/Duqu.E&lt;br /&gt;NOD32: probably a variant of Win32/Duqu.A&lt;br /&gt;TrendMicro: TROJ_DUQU.AJ&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Symantec mentioned MD5s&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=f1ee026692c8458bdd698884183150eb2b898a576bc1d94668bf9e0ec1bb7507-1320392300"&gt;9749d38ae9b9ddd81b50aad679ee87ec&lt;/A&gt;&lt;br /&gt;Wed Jun 01, 03:25:18 2011&lt;br /&gt;Stealing information&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=6b1ce29af44ea3c2cac3f7b74834ff0768c4ef539080f06087f4a0d7fe4a0a50-1320021815"&gt;4c804ef67168e90da2c3da58b60c3d16&lt;/A&gt;&lt;br /&gt;Mon Oct 17 17:07:47 2011&lt;br /&gt;Reconnaissance module&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=95f1ae81dff48763eb2d1977cc4db6add19ea09df40a6d326ef8395b1f8c5ef7-1320043408"&gt;856a13fcae0407d83499fc9c3dd791ba&lt;/A&gt;&lt;br /&gt;Mon Oct 17 16:26:09 2011&lt;br /&gt;Lifespan extender&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=0d35ebd7361ffa9c459291156613621ab0b8dd5a92cb8cd78b99f014fe7be0ec-1320031132"&gt;92aa68425401ffedcfba4235584ad487&lt;/A&gt;&lt;br /&gt;Tue Aug 09 21:37:39 2011&lt;br /&gt;Stealing information&lt;br /&gt;&lt;br /&gt;In each of those above, the link on the MD5 will show you the VirusTotal report.  I find it interesting that TrendMicro consistently names these files "TROJ_SHADOW.AG" which makes me wonder if they had independently discovered this malware family prior to the naming as Duqu by the CrySyS team.&lt;br /&gt;&lt;br /&gt;Symantec calls attention to the fact that several of these files show compile dates AFTER the public disclosure of the existence of Duqu.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Delivery Mechanism&lt;/H3&gt;&lt;br /&gt;Symantec disclosed in their report that one of the infections they were analyzing had been infected via a Word Document that exploited the system using a previously unknown 0-day attack.  &lt;br /&gt;&lt;br /&gt;We now know from Microsoft more about this exploit.  On November 3, 2011, Microsoft released this &lt;a href="http://technet.microsoft.com/en-us/security/advisory/2639658"&gt;Microsoft Security Advisory (2639658)&lt;br /&gt;Vulnerability in TrueType Font Parsing Could Allow Elevation of Privilege&lt;/A&gt;.  The advisory starts with an executive summary which says, in part: &lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;Microsoft is investigating a vulnerability in a Microsoft Windows component, the Win32k TrueType font parsing engine. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. The attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. We are aware of targeted attacks that try to use the reported vulnerability; overall, we see low customer impact at this time. This vulnerability is related to the Duqu malware.&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;Microsoft has released a work around.  The exploit is taking advantage of the fact that there is a problem in one of the DLL's called by TrueType in certain circumstances.  If a system denies access to that .DLL, T2EMBED.DLL, then the exploit would fail to work.&lt;br /&gt;&lt;br /&gt;The workaround can be executed like this, but Microsoft cautions that applications that rely on EMBEDDED TrueType fonts could then fail to display properly:&lt;br /&gt;&lt;br /&gt;(For older Windows versions)&lt;br /&gt;Echo y| cacls "%windir%\system32\t2embed.dll" /E /P everyone:N&lt;br /&gt;&lt;br /&gt;(For newer Windows versions)&lt;br /&gt;Takeown.exe /f "%windir%\system32\t2embed.dll"&lt;br /&gt;&lt;br /&gt;For more details on the workaround, please see &lt;a href="http://support.microsoft.com/kb/2639658"&gt;Microsoft Security Advisory: Vulnerability in TrueType font parsing could allow elevation of privileges&lt;/A&gt; which offers a "Fix It For Me" button to apply the work around for you.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Duqu Compared to Stuxnet&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;The Symantec report has 22 or so pages of original Symantec content, and then has as the majority of it's body the report by the CrySyS Lab, which has a section that compares the Duqu and Stuxnet code.  In particular, the Decryption function seems to be nearly identical.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-4183080845176443194?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/4183080845176443194'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/4183080845176443194'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/11/duqu-youre-safe-unless-you-use-truetype.html' title='Duqu: You&apos;re safe unless you use TrueType Fonts?'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-1331802500231186072</id><published>2011-10-19T10:37:00.001-07:00</published><updated>2011-11-09T19:43:45.979-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='spam'/><title type='text'>ACH spam uses intermediary sites to deliver malware punch</title><content type='html'>If you have an email address in the United States, either you or your spam filter is certainly familiar with this spam by now:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/ACH.spam.jpg"&gt;&lt;br /&gt;&lt;br /&gt;The spam with the subjects "ACH Payment (random numbers) Canceled" intends to imitate the National Automated Clearing House Association.  NACHA is the organization that banks use to handle the electronic transfer of funds between domestic banks for things such as "Direct Deposit" or electronic bill paying.&lt;br /&gt;&lt;br /&gt;The spam's message "The ACH transaction recently initiated from your checking acount was canceled by the other financial institution" is intended to elicit a panic response to get the recipient to click on the link in the email.&lt;br /&gt;&lt;br /&gt;The problem has been getting worse because of two "upgrades" by the spammers.  &lt;br /&gt;&lt;br /&gt;First - they are using "drive-by" infectors, in the form of the BlackHole Exploit Kit.  In the past a spam message such as this would have relied on trying to get you to download an '.exe' file and trick you into running it on your computer.  Now, simply visiting the website will often be enough to infect your machine.&lt;br /&gt;&lt;br /&gt;The second improvement, which comes and goes in waves, is that the criminals have compromised many "intermediary" web hosts to use in their spam.  If the spammer were sending you to "mybadsite.com" your security software would quickly learn that "mybadsite.com" is a potentially harmful destination and block you from visiting.  &lt;br /&gt;&lt;br /&gt;To make sure their spam is delivered, the spammers have stolen the credentials from many website owners and have used these credentials to add one tiny file to their existing legitimate website.  So, as a randomly chosen example, the spam link that claims to point to "nacha.org" may actually point to a page at "iscsconferencerecording.com".  That page belongs to the International Society of Communication Specialists, so it probably has a "positive" reputation among security companies, who may be loathe to block the site.&lt;br /&gt;&lt;br /&gt;What happens when we visit that page?&lt;br /&gt;&lt;br /&gt;The only contents on the page "am2wdh.html" are calls to two Javascript files on other websites.  In this case:&lt;br /&gt;&lt;br /&gt;   www.xmjhx.com /czc /js.js&lt;br /&gt;and&lt;br /&gt;   vscreative.com /images /js.js&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The first time I loaded this, it caused a document location to be set to "www.nachaemployee.com"&lt;br /&gt;&lt;br /&gt;A rerun of the same site pointed me instead to a blackhole exploit kit page at:&lt;br /&gt;&lt;br /&gt;  milloworks.com /main.php?  page=890639ab2b6c1ab8&lt;br /&gt;&lt;br /&gt;Which caused me to fetch:&lt;br /&gt; &lt;br /&gt;  milloworks.com /w.php ?f=70&amp;e=4&lt;br /&gt;&lt;br /&gt;This caused me to download the file:&lt;br /&gt;&lt;br /&gt;  www.vncoach.com /editors  /nachareport20111910.pdf.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Another attempt sent me to:&lt;br /&gt;&lt;br /&gt;  tgqswpqqh.org.in from which we attempt to load the Blackhole Exploit page from &lt;br /&gt;&lt;br /&gt;This drops a number of files on our computer, including Flash exploits, PDF exploits, and an EXE called "FIX_KB112755.exe" which gets downloaded from the IP address 213.123.52.133.  FIX_KB111088.exe and FIX_KB113547.exe were also downloaded from there.&lt;br /&gt;&lt;br /&gt;After the malware drops on the computer, we are forwarded through "dating-portal.net" where the affiliate engine sends us to an "Adult Friend Finder" sign-up website.&lt;br /&gt;&lt;br /&gt;The point of this story, however, is not really what malware gets dropped, but the use of so many hacked intermediary servers to do the dropping.&lt;br /&gt;&lt;br /&gt;In the first twelve hours of October 19, 2011, we saw 184 different websites used in this type of attack with an ACH spam subject line.  In order of occurrence, with the first observed URL each, here is what we've seen today:&lt;br /&gt;&lt;br /&gt;  HOSTNAME                                         PATH &lt;br /&gt;================================                ===================================&lt;br /&gt; preseis.com                               /7x1tyg6.html&lt;br /&gt; server.softhost.org                       /&lt;br /&gt; silverfruit.com.ec                        /t2jr.html&lt;br /&gt; newsletter.stable-jo.com                  /t43z.html&lt;br /&gt; www.Shoubra-prep.com                      /4x8l.html&lt;br /&gt; marcinjarzabek.cp5.win.pl                 /16ih2.html&lt;br /&gt; professionalroofing.co.uk                 /ph4xn5.html&lt;br /&gt; host272.hostmonster.com                   /~fdflockc/6xh9l1e.html&lt;br /&gt; sethsauction.com                          /6gh1u7.html&lt;br /&gt; www.corazondejesus.net                    /4cpjx.html&lt;br /&gt; murciaopina.com                           /tq3e.html&lt;br /&gt; www.digitalhomna.com                      /&lt;br /&gt; latinholdings.com.mx                      /4ghy.html&lt;br /&gt; 108cms.com                                /3n7s.html&lt;br /&gt; way2tutorial.com                          /g02lwbp.html&lt;br /&gt; nimbuscertifications.com                  /4qt4.html&lt;br /&gt; ultimateselena.org                        /0tpno.html&lt;br /&gt; www.efficientorganizationnw.com           /rk1pb.html&lt;br /&gt; trinity-work-shop.test-rackspeed.de       /&lt;br /&gt; hosting31.serverhs.org                    /~ecommerc/zu9iah7.html&lt;br /&gt; www.todotaringa.com                       /0pya.html&lt;br /&gt; stremyfoot.com                            /q37hdi.html&lt;br /&gt; www.ganarlaprimitiva.com                  /g5knqjr.html&lt;br /&gt; manaiz.com                                /a2w7q.html&lt;br /&gt; caspsurveys.org                           /zmu2.html&lt;br /&gt; www.ironsidegroup.pk                      /kq6bz.html&lt;br /&gt; temporary-toilets.com                     /mczkg.html&lt;br /&gt; 0342962.netsolhost.com                    /716txi.html&lt;br /&gt; babilhotel.com                            /5bf0html&lt;br /&gt; customcakesnw.com                         /not8.html&lt;br /&gt; tomralph.net                              /vsz8c.html&lt;br /&gt; www.panelpeople.com                       /1060.html&lt;br /&gt; goldencrownhotel.com                      /zf9w3uh.html&lt;br /&gt; www.launas.fr                             /jjssgx4.html&lt;br /&gt; dev.crm-warehouse.be                      /uclt4.html&lt;br /&gt; alassite.com                              /2hyl0.html&lt;br /&gt; 02be375.netsolhost.com                    /6mu1v.html&lt;br /&gt; evo2inc.com                               /o3wyn.html&lt;br /&gt; campossaab.net                            /g1hrhtml&lt;br /&gt; inzanepix.com                             /19v4sx.html&lt;br /&gt; specialrental.com                         /p5y6.html&lt;br /&gt; iscsconferencerecording.com               /am2wdh.html&lt;br /&gt; www.murciaopina.com                       /rt5dmy.html&lt;br /&gt; buynanoclean.com                          /3c6tp7.html&lt;br /&gt; froda.com                                 /5kbnak.html&lt;br /&gt; globaliellc.com                           /1o36z.html&lt;br /&gt; mslbx.com                                 /~servatus/soexlyy.html&lt;br /&gt; indexpoker.com                            /&lt;br /&gt; diversco.com                              /6fxo.html&lt;br /&gt; www.acclaimcabinetscom.au                 /7xoslgn.html&lt;br /&gt; mvlmobile.in                              /d34c.html&lt;br /&gt; weightlosspersonaltrainerconsulting.com   /1decnf9.html&lt;br /&gt; vandieautomatisering.nl                   /linhe.html&lt;br /&gt; intestinoirritable.ws                     /e66uc.html&lt;br /&gt; fmwwrestling.us                           /gsld0d.html&lt;br /&gt; abeauty.com.au                            /&lt;br /&gt; sokullupasahotel.com                      /fvn4upi.html&lt;br /&gt; ants.net.au                               /yxe4ma.html&lt;br /&gt; lkco.in                                   /a8l876j.html&lt;br /&gt; static-64-184-73-69nocdirect.com          /~afroland/eh8jvre.html&lt;br /&gt; damarchesi.it                             /6m2rdlx.html&lt;br /&gt; trinity-work-shop.de                      /5t5ub.html&lt;br /&gt; mycountylink.com                          /f6atze.html&lt;br /&gt; artigianatopasella.com                    /9ghy.html&lt;br /&gt; ohtobeyoungagain.com                      /t4cj.html&lt;br /&gt; syedaliahmad.com                          /3mlnfh.html&lt;br /&gt; www.geelongeisteddfod.com.au              /13pspj.html&lt;br /&gt; www.tommysparger.com                      /ci87qyp.html&lt;br /&gt; nt-ves.ac.th                              /&lt;br /&gt; diipbmis.nl                               /l374dcthtml&lt;br /&gt; bakulpharma.com                           /&lt;br /&gt; etno-plants.ro                            /&lt;br /&gt; professionalroofingco.uk                  /vmba.html&lt;br /&gt; altiaproducts.com                         /29f4.html&lt;br /&gt; dezoetezaak.nl                            /anxl5.html&lt;br /&gt; ozurfa.com.tr                             /ras5.html&lt;br /&gt; lexxstore.de                              /7nsenqhtml&lt;br /&gt; meirmodiin.org                            /~meirm/kk22.html&lt;br /&gt; siflindia.com                             /27swn2.html&lt;br /&gt; grapediscounts.com                        /fjlj9k.html&lt;br /&gt; fastincomebiz.com                         /hsd6g7b.html&lt;br /&gt; thebeadrotisserie.com                     /vel42.html&lt;br /&gt; 46.23.64.241                              /~jamias/lc50sf.html&lt;br /&gt; fastincomesystem.biz                      /u8g4tn.html&lt;br /&gt; surebg.co.za                              /xltlgs.html&lt;br /&gt; 110.4.42.93                               /bx94l.html&lt;br /&gt; www.resourceelementlimited.com            /&lt;br /&gt; graph2profit.com                          /utxfc.html&lt;br /&gt; shriganpatiproduction.net                 /r05qv4h.html&lt;br /&gt; micrene.com                               /ivowl1rhtml&lt;br /&gt; pdscientific.com                          /tl1s.html&lt;br /&gt; www.wanithai.com                          /u7pv30b.html&lt;br /&gt; ads-protection.com                        /fs3lax.html&lt;br /&gt; sl3-vgt.vgthosting.com                    /~worknetw/fj2bvn.html&lt;br /&gt; fb.servatusdev.com                        /~servdev/56iy2.html&lt;br /&gt; hedy-lamarr.org                           /n2tgsb.html&lt;br /&gt; niritech.com                              /pxkf.html&lt;br /&gt; 212.68.54.148                             /~radyoruz/qsdsw9m.html&lt;br /&gt; www.pushtiieshakti.com                    /783i.html&lt;br /&gt; empiresallies-secrets.com                 /k0bayr.html&lt;br /&gt; tarjetaspilos.com                         /9tvd.html&lt;br /&gt; voongo.com                                /asfti1/index.html&lt;br /&gt; searchtroop.net                           /04sh.html&lt;br /&gt; altagallura.it                            /bd5jhtml&lt;br /&gt; gran-mar.com.ar                           /4p6sbu7.html&lt;br /&gt; fullart.com.pe                            /3c55egr.html&lt;br /&gt; sanianishtar.info                         /7o2dd.html&lt;br /&gt; umtelecom.com                             /h10krhtml&lt;br /&gt; reformasyreparaciones.com                 /76kdp.html&lt;br /&gt; 206.217.196.47                            /~dumpsche/kes773.html&lt;br /&gt; acumenauditors.com.au                     /vfa9.html&lt;br /&gt; www.rippt.com                             /t8859u.html&lt;br /&gt; trunghieu.com                             /hsx1n3r.html&lt;br /&gt; delallosa.com                             /mtgy99y.html&lt;br /&gt; lainformacion.us                          /snkk1.html&lt;br /&gt; refritermo.com                            /j9ps4y.html&lt;br /&gt; www.grahajodoh.com                        /bqe6zk.html&lt;br /&gt; etakip.com                                /yg4jl9.html&lt;br /&gt; carifind.com                              /t718xhhtml&lt;br /&gt; jpvarleyllc.com                           /kna4wx.html&lt;br /&gt; www.shatteredhope.gr                      /lnsp.html&lt;br /&gt; autoblog.fastincomesystem.biz             /~cheers/gyjde.html&lt;br /&gt; reformhaus-mehnert.de                     /2vn9yr5.html&lt;br /&gt; indianbookshop.co.in                      /5b9fgs.html&lt;br /&gt; host272.hostmonstercom                    /~fdflockc/6xh9l1e.html&lt;br /&gt; enbramex.com                              /mpvsgi2.html&lt;br /&gt; onlinesurat.com                           /mb2d.html&lt;br /&gt; surrealtopia.com                          /hmsuu.html&lt;br /&gt; el-salto-fishing.com                      /agg0noo.html&lt;br /&gt; simplefact.mx                             /xln290.html&lt;br /&gt; bofco.in                                  /htrc.html&lt;br /&gt; iznillahcng.com                           /y5le.html&lt;br /&gt; static-64-184-73-69.nocdirect.com         /~afroland/eh8jvre.html&lt;br /&gt; vizonix.com                               /c1ptwqs/index.html&lt;br /&gt; visionciudadconsultores.com               /dwqopc/index.html&lt;br /&gt; winsbyinc.com                             /0sm9j5/index.html&lt;br /&gt; www.tradehalls.com                        /8eeh2.html&lt;br /&gt; 4income-solutions.com                     /93e3x.html&lt;br /&gt; locanda-stazzo-bona.com                   /&lt;br /&gt; jade.nseasy.com                           /~manishar/7xl9bd.html&lt;br /&gt; GUHDNS.COM                                /md8g.html&lt;br /&gt; livedata.it                               /ssao.html&lt;br /&gt; www.manojengg.com                         /scv2.html&lt;br /&gt; sexshop.com.tr                            /3igtv8.html&lt;br /&gt; perfumeylenceria.com                      /joiwku.html&lt;br /&gt; server10.namecheaphosting.com             /&lt;br /&gt; freunde-klinik-ottobeuren.de              /oryh1.html&lt;br /&gt; floristeriasdecoaromascostarica.com       /kh31.html&lt;br /&gt; portalinternational.us                    /5ecf2z.html&lt;br /&gt; molinas.eu                                /nz4ot.html&lt;br /&gt; clubfirst.org                             /2ba0jra.html&lt;br /&gt; thepentad.com                             /eg3eje/index.html&lt;br /&gt; www.dsmodular.com                         /qt21ta.html&lt;br /&gt; hotelmarinepalace.com                     /0493.html&lt;br /&gt; teresita.com.mx                           /hcrji4t.html&lt;br /&gt; 198.63.48.81                              /z116c.html&lt;br /&gt; punjnud.com                               /3sllgkihtml&lt;br /&gt; inkostudio.com                            /y0ao0c.html&lt;br /&gt; tuncakyavas.com                           /jfifrpb.html&lt;br /&gt; hkf.huber-babenhausen.de                  /xyy4dg3.html&lt;br /&gt; watson.timeweb.ru                         /~kostos/7euyd25.html&lt;br /&gt; vscreative.com                            /x882.html&lt;br /&gt; lemilano.fr                               /&lt;br /&gt; labeltula.it                              /e51rsq.html&lt;br /&gt; www.acclaimcabinets.com.au                /&lt;br /&gt; shelterpropertydealers.com                /97qf.html&lt;br /&gt; dotmile.com                               /cvpa4jj.html&lt;br /&gt; www.clubbayard.com                        /w6kzi.html&lt;br /&gt; myauto.co.nz                              /odmz0chtml&lt;br /&gt; whydodogs.org                             /jdab40.html&lt;br /&gt; bigrace2012.com                           /3ri1vt.html&lt;br /&gt; www.launas-hebergement.com                /fj9p1.html&lt;br /&gt; www.neoplastic.gr                         /0qedzw.html&lt;br /&gt; ittefaqpipe.com                           /2inp.html&lt;br /&gt; efficientorganizationnw.com               /ix84c.html&lt;br /&gt; indosyslife.com                           /cdwwto.html&lt;br /&gt; newmonicaarts.org                         /&lt;br /&gt; avicarusa.com                             /uyxasjr.html&lt;br /&gt; atlantidesardegna.it                      /61fyvx.html&lt;br /&gt; baratrucks.com                            /n6j5m.html&lt;br /&gt; heromw.com                                /602ka.html&lt;br /&gt; web3.biz                                  /4jdsydk.html&lt;br /&gt; eqsync.com                                /bx5wfm.html&lt;br /&gt; weblinksubmissions.com                    /1bgypq/index.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-1331802500231186072?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/1331802500231186072'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/1331802500231186072'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/10/ach-spam-uses-intermediary-sites-to.html' title='ACH spam uses intermediary sites to deliver malware punch'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-1834875119534886903</id><published>2011-08-17T03:37:00.000-07:00</published><updated>2011-11-09T19:43:45.979-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='spam'/><title type='text'>New York City "Uniform Traffic Ticket" tops spammed malware</title><content type='html'>Email attachments that contain malicious code are still being used to infect computers and steal the data found on those computers.  While it is easy to find people who discount this threat, believing no one would be foolish enough to open one of these email attachments, the criminals are working hard to make their approaches more convincing.&lt;br /&gt;&lt;br /&gt;Today we've seen more than 11,000 copies of their newest attempt come in to the UAB Spam Data Mine.  The email received looks like this:&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/NYCTicket.email.jpg"&gt;&lt;br /&gt;&lt;br /&gt;The email contains several falsified header indicators, including at the most basic level that it claims to come from "@nyc.gov".  In addition to this, however, there has been a "Received:" tag added to make it appear to have originated from a legitimate New York City IP address:&lt;br /&gt;&lt;br /&gt;Received: from nyc.gov ([167.153.240.51]) by xx.xx.xx.xx; Wed, 03 Aug 2011 12:20:46 +0530&lt;br /&gt;&lt;br /&gt;The City of New York is the registrant for every IP address beginning with "167.153.*.*" - in fact 167.153.240.51 is the IP address of the website "nyc.gov" where Mayor Bloomberg's homepage can be found.&lt;br /&gt;&lt;br /&gt;The other false information is the date.  Both the date in the Received: tag and the date in the "Date:" tag have been falsified to make it seem this email has been in your in box for several days by the time you see it.&lt;br /&gt;&lt;br /&gt;Just from the falsified header, we would predict that this email is going to be in the same family of malware as the "IRS Notification" and "UPS Notification" emails seen earlier this week, which also contained falsified Received: tags.&lt;br /&gt;&lt;br /&gt;The zip file contains an executable file disguised as a PDF file:&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/NYCTicket.icon.jpg"&gt;&lt;br /&gt;&lt;br /&gt;When the malware is launched, it connects to "sfkdhjnsfjg.ru" on 195.189.226.117.&lt;br /&gt;&lt;br /&gt;from there it fetches "/ftp/g.php" and "pusk3.exe" -- exactly the same as the IRS Notification spam and the UPS Notification spam.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=7bf9a672cfbd615e365a563a545266d89c22784027585e7db73aaa4621b756d9-1313575268"&gt;VirusTotal Report&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;HR&gt;&lt;br /&gt;Another group of spam messages this morning pretends to be a notice that you have received money via Western Union.&lt;br /&gt;&lt;br /&gt;The attachment is of course a virus:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=9143805c003116a6be2b075faa5c643d7ddefae506eb95166acf75dfd746d544-1313579515"&gt;VirusTotal Report&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt; Money Transfer Information&lt;br /&gt; MONEY TRANSFER INFORMATION&lt;br /&gt; Money Transfer Information 00375&lt;br /&gt; Money Transfer Notice&lt;br /&gt; MONEY TRANSFER NOTICE&lt;br /&gt; MONEY TRANSFER NOTICE 06457&lt;br /&gt; Western Union: Money Transfer For You&lt;br /&gt; WESTERN UNION: MONEY TRANSFER FOR YOU&lt;br /&gt; Western Union: Remittance Advice&lt;br /&gt; WESTERN UNION: REMITTANCE ADVICE&lt;br /&gt; Western Union: Transfer Of Money&lt;br /&gt; WESTERN UNION: TRANSFER OF MONEY&lt;br /&gt; Western Union: You Have Money Transfer&lt;br /&gt; WESTERN UNION: YOU HAVE MONEY TRANSFER&lt;br /&gt; Western Union: You have received a money transfer&lt;br /&gt; WESTERN UNION: YOU HAVE RECEIVED A MONEY TRANSFER&lt;br /&gt;&lt;br /&gt;&lt;HR&gt;&lt;br /&gt;&lt;br /&gt;Another top spammed malware attachment today delivers emails with these subjects:&lt;br /&gt;&lt;br /&gt; Re: End of July Statement Required&lt;br /&gt; Re: FW: End of July Stat.&lt;br /&gt; Re: FW: End of July Statement&lt;br /&gt; Re: FW: End of July Statement required&lt;br /&gt; Re: FW: End of July Statement Required&lt;br /&gt; Re: FW: End of July Statement REquired&lt;br /&gt; Re: FW: End of July Statement REquired!&lt;br /&gt; Re: FW: End of July Stat. required&lt;br /&gt; Re: FW: End of July Stat. Required&lt;br /&gt;&lt;br /&gt;The email body says simply:&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;Hallo,&lt;br /&gt;As requested i give you open Invoices issued to you as per 5th Aug. 2011&lt;br /&gt;Regards&lt;br /&gt;DEENA BUCKLEY&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;Here's the &lt;a href="http://www.virustotal.com/file-scan/report.html?id=29c436b608d15af6354ff60abf0266eff964efc5bde8c63cb8745090087c7465-1313567136"&gt;VirusTotal report&lt;/A&gt; for this one.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-1834875119534886903?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/1834875119534886903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/1834875119534886903'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/08/new-york-city-uniform-traffic-ticket.html' title='New York City &quot;Uniform Traffic Ticket&quot; tops spammed malware'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-7478455419372397500</id><published>2011-08-10T05:57:00.001-07:00</published><updated>2011-11-09T19:43:45.979-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='spam'/><title type='text'>Inter-company Invoice spam leads to Malware</title><content type='html'>This morning we are seeing a new spam campaign in the UAB Spam Data Mine.  Volumes are still low, but the count is rising steadily, and the detection so far is horrible.  When I started writing this post we had seen 710 copies.  It's now up to 1389 copies and counting!&lt;br /&gt;&lt;br /&gt; count |        mbox         &lt;br /&gt;-------+---------------------&lt;br /&gt;     1 | 2011-08-10 05:45:00&lt;br /&gt;     6 | 2011-08-10 06:00:00&lt;br /&gt;     3 | 2011-08-10 06:15:00&lt;br /&gt;    85 | 2011-08-10 06:30:00&lt;br /&gt;     1 | 2011-08-10 06:45:00&lt;br /&gt;     3 | 2011-08-10 07:00:00&lt;br /&gt;     1 | 2011-08-10 07:15:00&lt;br /&gt;   301 | 2011-08-10 07:30:00&lt;br /&gt;   252 | 2011-08-10 07:45:00&lt;br /&gt;   260 | 2011-08-10 08:00:00&lt;br /&gt;   247 | 2011-08-10 08:15:00&lt;br /&gt;   229 | 2011-08-10 08:30:00&lt;br /&gt;(12 rows)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The spam pretends to be an invoice from a random company.  So far this morning we've seen spam claiming to be an invoice from:&lt;br /&gt;&lt;br /&gt;Aleris International Corp.&lt;br /&gt;AMR Corporation Corp.&lt;br /&gt;Anic Corp.&lt;br /&gt;Arch Coal Corp.&lt;br /&gt;ATFT Corp&lt;br /&gt;Beazer Homes USA Corp.&lt;br /&gt;Boyd Gaming Corp.&lt;br /&gt;Brookdale Senior Living Corp.&lt;br /&gt;Hyland Software Corp.&lt;br /&gt;KPMG Corp.&lt;br /&gt;Kraft Foods Corp.&lt;br /&gt;Miltek Corp.&lt;br /&gt;Novellus Systems Corp.&lt;br /&gt;OSN Corp.&lt;br /&gt;PDC Corp.&lt;br /&gt;Safeco Corporation Corp.&lt;br /&gt;WLC Corp.&lt;br /&gt;&lt;br /&gt;Subject can be: &lt;br /&gt;&lt;br /&gt;Re: Fw: Inter-company inv. from (company)&lt;br /&gt;Re: Fw: Inter-company inv. from (company)&lt;br /&gt;Re: Fw: Inter-company invoice from (company)&lt;br /&gt;Re: Fw: Intercompany invoice from (company)&lt;br /&gt;Re: Fw: Corp. invoice from (company)&lt;br /&gt;&lt;br /&gt;A couple example emails follow:&lt;br /&gt;&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;Hi&lt;br /&gt;Attached the inter-company inv. for the period January 2010 til December 2010.&lt;br /&gt;&lt;br /&gt;Thanks a lot for support setting up this process.&lt;br /&gt;&lt;br /&gt;CHERYL Flowers&lt;br /&gt;Kraft Foods Corp. &lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;Hi&lt;br /&gt;&lt;br /&gt;Attached the inter-company inv. for the period January 2010 til December 2010.&lt;br /&gt;Thanks a lot&lt;br /&gt;&lt;br /&gt;Asher GIFFORD&lt;br /&gt;Anic Corp. &lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;Good day&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Attached the intercompany invoice for the period January 2010 til December 2010.&lt;br /&gt;&lt;br /&gt;Thanks a lot for supporting this process&lt;br /&gt;MAYOLA LEARY&lt;br /&gt;Aleris International Corp. &lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;&lt;br /&gt;The attachment may be named "Intinvoice" or "Invoice" followed by an underscore, a date, and an "invoice number" ".zip" such as:&lt;br /&gt;&lt;br /&gt;Intinvoice_08.6.2011_2222341965.zip&lt;br /&gt;or&lt;br /&gt;Intinvoice_08.4.2011_Q167829.zip&lt;br /&gt;or&lt;br /&gt;Invoice_08.6.2011_T40099.zip&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We've seen 1300+ copies so far in the UAB Spam Data Mine, and I have 15 in my personal email.&lt;br /&gt;&lt;br /&gt;So far, all have had the same attachment MD5, which yields a 6 of 43 detection rate on this &lt;a href="http://www.virustotal.com/file-scan/report.html?id=cb5a55e48f535a92f075e53c0424a079f33ac7366ac47b0d3fd8f61030921231-1312979163"&gt;VirusTotal Report&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;So far everyone is just saying it is "Suspicious" or "Generic" ... which is our invitation to infect ourselves and figure out what it does!&lt;br /&gt;&lt;br /&gt;When we launched the malware, we made a connection to "armaturan.ru" on 94.199.48.152.&lt;br /&gt;&lt;br /&gt;We also talked to "ss-partners.ru" on 77.120.114.100 &lt;br /&gt;and to "ledinit.ru" on 78.111.51.121&lt;br /&gt;&lt;br /&gt;The connection to armaturan.ru did:&lt;br /&gt;&lt;br /&gt;GET /forum/dl/ots.php?seller=4&amp;hash={8FA33B0C-3F04-405B-83BD-1CD82D298FF2}&lt;br /&gt;&lt;br /&gt;which seems to be uniquely registering our machine, and giving seller #4 credit for my infection?&lt;br /&gt;&lt;br /&gt;From ss-partners.ru we fetched a file:&lt;br /&gt;&lt;br /&gt;GET /dump/light.exe&lt;br /&gt;&lt;br /&gt;which dropped an approximately 70k file onto our local machine.&lt;br /&gt;&lt;br /&gt;Then we went back to armaturan.ru and sent another get:&lt;br /&gt;&lt;br /&gt;GET /forum/dl/getruns.php?seller=4&amp;hash={8FA33B0C-3F04-405B-83BD-1CD82D298FF2}&amp;ahash=5895b2509324d6a17b2b6ea09859a485&lt;br /&gt;&lt;br /&gt;Any bets on whether that ahash is the MD5 of the file I just downloaded?&lt;br /&gt;&lt;br /&gt;Looks like I just reported back to the C&amp;C that I successfully downloaded and installed malware with that MD5.&lt;br /&gt;&lt;br /&gt;At this point I checked my registry and found that I had a new Run command for next time I restart.  I'm supposed to run:&lt;br /&gt;&lt;br /&gt;C:\Documents and Settings\Administrator\Application Data\3B1F8DC4\3B1F8DC4.EXE&lt;br /&gt;&lt;br /&gt;Odd, I don't recall having a file named that?&lt;br /&gt;&lt;br /&gt;Actually, we confirmed that this is the file that was downloaded as "light.exe" above.  The VirusTotal report shows only 4 of 43 infection reports for this file as well.  See &lt;a href="http://www.virustotal.com/file-scan/report.html?id=5b961a0ecd4cdbb1bf2fc73e8761b040e95e170f94d243a3a5c9a7fdcf5267b6-1312979377"&gt;VirusTotal Report&lt;/A&gt;.  &lt;br /&gt;&lt;br /&gt;Unfortunately, it disproves my MD5 theory.  This is NOT the "ahash" value.  This file's MD5 is f58d5cbb564069eca8806d4e48d7a714.&lt;br /&gt;&lt;br /&gt;Launching the second file caused the machine to open an SSL tunnel to 78.111.51.121 and then sit idle. &lt;br /&gt;&lt;br /&gt;You may recognize that as the IP address for "ledinit.ru" earlier, but it didn't make a connection by name.  It went straight for the IP address.  If that IP sounds familiar, it's probably because there have been many other malware campaigns tied to the network "Azerbaijan Baku Sol Ltd", but I'm sure that's just because it's a very large network. &lt;br /&gt;&lt;br /&gt;78.111.51.100 is currently hosting three live Zeus C&amp;C servers.  Surely a coincidence.&lt;br /&gt;&lt;br /&gt;fileuplarc.com&lt;br /&gt;hunterdriveez.com&lt;br /&gt;asdfasdgqghgsw.cx.cc&lt;br /&gt;&lt;br /&gt;I'll email the owner and get those taken down right away! (smirk)&lt;br /&gt;&lt;br /&gt;-----------&lt;br /&gt;&lt;br /&gt;person:         Vugar Kouliyev&lt;br /&gt;address:        44, J.Jabbarli str., Baku, Azerbaijan&lt;br /&gt;mnt-by:         MNT-SOL&lt;br /&gt;e-mail:         vugar@kouliyev.com&lt;br /&gt;phone:          +994124971234&lt;br /&gt;nic-hdl:        VK1161-RIPE&lt;br /&gt;source:         RIPE # Filtered&lt;br /&gt;&lt;br /&gt;route:          78.111.48.0/20&lt;br /&gt;descr:          SOL ISP&lt;br /&gt;origin:         AS43637&lt;br /&gt;mnt-by:         MNT-SOL&lt;br /&gt;source:         RIPE # Filtered&lt;br /&gt;&lt;br /&gt;route:          78.111.51.0/24&lt;br /&gt;descr:          SOL ISP&lt;br /&gt;origin:         AS43637&lt;br /&gt;mnt-by:         MNT-SOL&lt;br /&gt;source:         RIPE # Filtered&lt;br /&gt;&lt;br /&gt;----------------&lt;br /&gt;&lt;br /&gt;Armaturan.ru on 94.199.48.152 also has a sordid history.&lt;br /&gt;&lt;br /&gt;That IP address, in Hungary, has been associated with at least two active SpyEye domains:  hdkajhslalskjd.ru and hhasdalkjjfasd.ru&lt;br /&gt;&lt;br /&gt;I suppose we'll have to ask Mr. Zsolt nicely if he would remove those domains.&lt;br /&gt;&lt;br /&gt;person:         Zemancsik Zsolt&lt;br /&gt;address:        Victor Hugo u. 18-22.&lt;br /&gt;address:        1132 Budapest&lt;br /&gt;address:        Hungary&lt;br /&gt;phone:          +36 203609059&lt;br /&gt;e-mail:         darwick@cyberground.hu&lt;br /&gt;nic-hdl:        DARW-RIPE&lt;br /&gt;mnt-by:         DARW-MNT&lt;br /&gt;source:         RIPE # Filtered&lt;br /&gt;&lt;br /&gt;route:          94.199.48.0/21&lt;br /&gt;descr:          Originated from 23VNet Network&lt;br /&gt;origin:         AS30836&lt;br /&gt;mnt-by:         NET23-MNT&lt;br /&gt;source:         RIPE # Filtered&lt;br /&gt;&lt;br /&gt;========&lt;br /&gt;ss-partners.ru is on servers from Bellhost.ru, a customer of Volia DC&lt;br /&gt;&lt;br /&gt;person:          Volia DC Admin contact&lt;br /&gt;address:         Ukraine, Kiev, Kikvidze st. 1/2&lt;br /&gt;phone:           +38 044 2852716&lt;br /&gt;abuse-mailbox:   abuse@dc.volia.com&lt;br /&gt;nic-hdl:         VDCA-RIPE&lt;br /&gt;mnt-by:          VOLIA-DC-MNT&lt;br /&gt;source:          RIPE # Filtered&lt;br /&gt;&lt;br /&gt;route:          77.120.96.0/19&lt;br /&gt;descr:          Volia more specific route&lt;br /&gt;origin:         AS25229&lt;br /&gt;mnt-by:         VOLIA-MNT&lt;br /&gt;mnt-lower:      VOLIA-MNT&lt;br /&gt;source:         RIPE # Filtered&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-7478455419372397500?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/7478455419372397500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/7478455419372397500'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/08/inter-company-invoice-spam-leads-to.html' title='Inter-company Invoice spam leads to Malware'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-8826375106682554852</id><published>2011-08-05T03:40:00.000-07:00</published><updated>2011-11-09T19:43:45.980-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='spam'/><title type='text'>Fake IRS emails continue to spread Gov-related Zeus</title><content type='html'>We've already seen nearly 500 copies of the new Government-related Zeus spam campaign so far this morning in the UAB Spam Data Mine.   As has been typical in this campaign that we first started tracking on July 13th, the detection has been fairly horrible each morning for the new malware version.  We lasted updated on this malware on July 29th in our story &lt;a href="http://garwarner.blogspot.com/2011/07/government-related-zeus-spam-continues.html"&gt;Government-related Zeus Spam Continues&lt;/A&gt;.  &lt;br /&gt;&lt;br /&gt;Today's version advertises the domain "tax-irs-report.com" and asks users to download the file 0000770950077US.pdf.exe from that site.&lt;br /&gt;&lt;br /&gt;190 different computers have sent us the spam for this campaign so far today.  118 of them from the USA, 40 from India.&lt;br /&gt;&lt;br /&gt;When we asked the UAB Spam Data Mine what other virus links we had been sent by this same group of 190 computers on other days, we got this list:&lt;br /&gt;&lt;br /&gt; receiving_date |           machine            |             path              &lt;br /&gt;----------------+------------------------------+-------------------------------&lt;br /&gt; 2011-07-13     | usbanking-security.com       | /tax_report.pdf.exe&lt;br /&gt; 2011-07-15     | federalsecusrity.com         | /pending-taxes.pdf.exe&lt;br /&gt; 2011-07-19     | irs-report-link.com          | /tax-report.pdf.exe&lt;br /&gt; 2011-07-19     | irs-taxes-report.com         | /tax-report.pdf.exe&lt;br /&gt; 2011-07-19     | taxreport-irs.com            | /tax-report.pdf.exe&lt;br /&gt; 2011-07-20     | alerts-federalresrve.com     | /rejected_wire.pdf.exe&lt;br /&gt; 2011-07-20     | nacha-alert.com              | /rejected_transaction.pdf.exe&lt;br /&gt; 2011-07-20     | nacha-alert.org              | /rejected_transfer.pdf.exe&lt;br /&gt; 2011-07-20     | reports-federalreserve.com   | /rejected_wire.pdf.exe&lt;br /&gt; 2011-07-21     | national-security-agency.com | /blocked_list.exe&lt;br /&gt; 2011-07-21     | national-security-agency.com | /token_security_update.exe&lt;br /&gt; 2011-07-21     | nsa-security.net             | /blocked-list.exe&lt;br /&gt; 2011-07-21     | nsa-security.net             | /token_security_update.exe&lt;br /&gt; 2011-07-22     | irs-downloads.com            | /00000700955160US.exe&lt;br /&gt; 2011-07-22     | irs-files.com                | /00000700955170US.exe&lt;br /&gt; 2011-07-26     | irs-alert.com                | /00000700955770US.exe&lt;br /&gt; 2011-07-27     | nacha-transactions.org       | /304694305894903.pdf.exe&lt;br /&gt; 2011-07-27     | taxes-refund.com             | /00000700975770US.exe&lt;br /&gt; 2011-07-27     | www.nacha-rejected.com       | /304694305894903.pdf.exe&lt;br /&gt; 2011-07-28     | fdic-updates.com             | /system_update_07_28.exe&lt;br /&gt; 2011-07-29     | federalreserve-alert.com     | /transaction_report.pdf.exe&lt;br /&gt; 2011-07-29     | taxes-security.com           | /00000700955060US.pdf.exe&lt;br /&gt; 2011-08-03     | irs-report.com               | /00000770950077US.exe&lt;br /&gt; 2011-08-05     | tax-irs-report.com           | /0000770950077US.pdf.exe&lt;br /&gt;(24 rows)&lt;br /&gt;&lt;br /&gt;So, at least some of today's spamming computers have been with this campaign since the beginning (July 13th).&lt;br /&gt;&lt;br /&gt;When today's malware is executed it sets a registry key in "HKEY_USERS\S-1-5(my user)-500\Software\Microsoft\Windows\CurrentVersion\Run" to relaunch itself from my current user account where it had copied itself as "C:\Documents and Settings\Administrator\Application Data\Afena\iror.exe"&lt;br /&gt;&lt;br /&gt;It makes connection to domains generated with a DGA (Domain Generation Algorithm).  Today's live domain was:&lt;br /&gt;&lt;br /&gt;olojkpcltulirqr.info  on   50.57.71.39&lt;br /&gt;&lt;br /&gt;from there it did a GET for /news/?s=158404&lt;br /&gt;&lt;br /&gt;It tried many other domains, but none of the others were live.  Some of them include:&lt;br /&gt;&lt;br /&gt;jruioljslsitjpfv.biz&lt;br /&gt;wlnzkqmohuhzqyra.info&lt;br /&gt;tjjhmtjlziebo.net&lt;br /&gt;jpkpbxkoxwijzijr.info&lt;br /&gt;&lt;br /&gt;As we have seen before, the malware ALSO fetches a copy of "heap_v206_mails.exe" after it successfully installs itself.&lt;br /&gt;&lt;br /&gt;The spam started at 4:45 AM (Central time), peaked at 5:15, and then began to trickle off.  (We group in 15 minute windows.)&lt;br /&gt;&lt;br /&gt; count | 15 minute spam block         &lt;br /&gt;-------+---------------------&lt;br /&gt;     3 | 2011-08-05 04:45:00&lt;br /&gt;     3 | 2011-08-05 05:00:00&lt;br /&gt;   406 | 2011-08-05 05:15:00&lt;br /&gt;    86 | 2011-08-05 05:30:00&lt;br /&gt;(4 rows)&lt;br /&gt;&lt;br /&gt;This morning's malware is largely undetected:&lt;br /&gt;&lt;br /&gt;A &lt;a href="http://www.virustotal.com/file-scan/report.html?id=22a89408c3156625a8cd71d9cfcd79b56aa6cda4f2e089f2ea6657d5fc11d0b8-1312540099"&gt;VirusTotal Report&lt;/A&gt; shows 6 of 43 AV products know that this is a virus.&lt;br /&gt;&lt;br /&gt;I have to praise Microsoft for being the only one of the six to correctly call this Zeus (Zbot).&lt;br /&gt;&lt;br /&gt;Email subjects we've seen on this morning's campaign:&lt;br /&gt;&lt;br /&gt; count |                              subject                              &lt;br /&gt;-------+-------------------------------------------------------------------&lt;br /&gt;    38 | Change Confirmation&lt;br /&gt;     4 | Does your company is registered outstanding tax debt&lt;br /&gt;     5 | Does your company is registered  tax debt&lt;br /&gt;     1 | Does your enterprise including unpaid tax debts&lt;br /&gt;     1 | Does your enterprise listed outstanding tax debts&lt;br /&gt;     1 | Does your enterprise listed unpaid tax debts&lt;br /&gt;    30 | Federal Tax payment rejected&lt;br /&gt;     1 | For your company including unpaid tax debts&lt;br /&gt;     1 | For your company is registered outstanding tax debts&lt;br /&gt;     1 | For your company is registered  tax debts&lt;br /&gt;     1 | For your company is registered unpaid tax debt&lt;br /&gt;     1 | For your company listed  tax debts&lt;br /&gt;     2 | For your enterprise listed  tax debt&lt;br /&gt;    70 | Internal Revenue Service&lt;br /&gt;    24 | Internal Revenue Service (IRS)&lt;br /&gt;    19 | Internal Revenue Service United States Department of the Treasury&lt;br /&gt;    32 | IRS.gov&lt;br /&gt;    31 | IRS.gov US&lt;br /&gt;    19 | Notice of Underreported Income&lt;br /&gt;    35 | Payment IRS.gov&lt;br /&gt;    50 | Support IRS.gov&lt;br /&gt;    40 | Treasury Inspector General for Tax Administration&lt;br /&gt;    42 | U.S. Department of the Treasury&lt;br /&gt;     1 | Your company including outstanding tax debts&lt;br /&gt;     1 | Your company including  tax debts&lt;br /&gt;     1 | Your company listed outstanding tax debt&lt;br /&gt;     2 | Your company listed  tax debts&lt;br /&gt;     1 | Your enterprise including outstanding tax debts&lt;br /&gt;     2 | Your enterprise is registered unpaid tax debts&lt;br /&gt;     1 | Your enterprise listed outstanding tax debt&lt;br /&gt;     1 | Your enterprise listed unpaid tax debt&lt;br /&gt;    39 | Your IRS payment rejected&lt;br /&gt;(32 rows)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A mix and match of sender name, sender-username, and sender-domain creates the from addresses:&lt;br /&gt;&lt;br /&gt; count |                             sender_name                             &lt;br /&gt;-------+---------------------------------------------------------------------&lt;br /&gt;    19 | "Internal Revenue Service"&lt;br /&gt;    18 | "Internal Revenue Service (IRS)"&lt;br /&gt;    27 | "Internal Revenue Service (IRS.gov)"&lt;br /&gt;    29 | "Internal Revenue Service United States Department of the Treasury"&lt;br /&gt;    23 | "Internal Revenue Service US Department of the Treasury"&lt;br /&gt;    29 | "IRS.gov"&lt;br /&gt;    18 | "IRS.gov United States Department of the Treasury"&lt;br /&gt;    30 | "IRS.gov US"&lt;br /&gt;    22 | "IRS.gov US Department of the Treasury"&lt;br /&gt;    21 | "IRS United States Department of the Treasury"&lt;br /&gt;    41 | "Payment IRS.gov"&lt;br /&gt;    37 | "Support IRS.gov"&lt;br /&gt;    23 | "The Consumer Financial Protection"&lt;br /&gt;    37 | "Treasury Inspector General for Tax Administration"&lt;br /&gt;    30 | "United States Department of the Treasury"&lt;br /&gt;    19 | "U.S. Department of the Treasury"&lt;br /&gt;    23 | "US_IRS"&lt;br /&gt;    17 | "USIRS"&lt;br /&gt;    35 | "US IRS.gov"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; count |     sender_username      &lt;br /&gt;-------+--------------------------&lt;br /&gt;    12 | admin&lt;br /&gt;     8 | adminnistration&lt;br /&gt;     9 | alerts&lt;br /&gt;    16 | cunsumer&lt;br /&gt;    29 | delivery&lt;br /&gt;    15 | e-file&lt;br /&gt;    10 | finance&lt;br /&gt;    33 | frboard-webannouncements&lt;br /&gt;    36 | govdelivery&lt;br /&gt;    26 | info&lt;br /&gt;    17 | information&lt;br /&gt;    14 | inspector&lt;br /&gt;     8 | internal_revenue_service&lt;br /&gt;    30 | Internal_Revenue_Service&lt;br /&gt;    18 | irs&lt;br /&gt;     6 | news&lt;br /&gt;    14 | news-alerts&lt;br /&gt;     8 | no-reply&lt;br /&gt;    28 | privacy_policy&lt;br /&gt;    22 | protection&lt;br /&gt;     5 | public&lt;br /&gt;     5 | report&lt;br /&gt;     9 | service&lt;br /&gt;    17 | stats&lt;br /&gt;    22 | subscriber&lt;br /&gt;    12 | subscriptions&lt;br /&gt;    13 | support&lt;br /&gt;    13 | usirc&lt;br /&gt;    14 | USIRS&lt;br /&gt;    13 | usttb&lt;br /&gt;    16 | webannouncements&lt;br /&gt;(31 rows)&lt;br /&gt;&lt;br /&gt; count |   sender_domain   &lt;br /&gt;-------+-------------------&lt;br /&gt;    93 | antifraud.irs.gov&lt;br /&gt;    73 | info.irs.gov&lt;br /&gt;    78 | irs.gov&lt;br /&gt;    91 | irs.security.gov&lt;br /&gt;    73 | irs.taxes.gov&lt;br /&gt;    90 | service.irs.gov&lt;br /&gt;(6 rows)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-8826375106682554852?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/8826375106682554852'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/8826375106682554852'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/08/fake-irs-emails-continue-to-spread-gov.html' title='Fake IRS emails continue to spread Gov-related Zeus'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-674418766081138865</id><published>2011-08-03T07:19:00.000-07:00</published><updated>2011-08-03T07:52:43.588-07:00</updated><title type='text'>Love Map Spam spreads Fake AV</title><content type='html'>The top malware spam of the morning is another Fake Antivirus product, but as you'll see in today's story, its a very familiar Fake AV product.&lt;br /&gt;&lt;br /&gt;About 1/2 of 1% of the spam we've seen this morning is a new campaign spreading a fake antivirus dropper.  The malware has a fair detection rating, with 17 of 43 AV products detecting the malware according to VirusTotal in their report for &lt;a href="http://www.virustotal.com/file-scan/report.html?id=2d527388f74db78dc06851ad5f224797f4d2f41261ef64b8a4f68f0fe38b835f-1312376470"&gt;MD5 = 635aceafb9ee4236e50e7d0f6c7a7895&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;The email bodies use some random misspellings, but look something like this:&lt;br /&gt;&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;WELCOME S'EXOHOLIC!  &lt;br /&gt;Are YOU real Se'X-tourist?&lt;br /&gt;Check -&gt;&gt;NEW PROJECT: WORLD MAP OF PUSSY&lt;br /&gt;With Best Wishes ...&lt;br /&gt;www. love-map .com&lt;br /&gt;&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;&lt;br /&gt;and then have an attachment, which is the malware.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;(the website, love-map.com, doesn't actually exist...)&lt;br /&gt;&lt;br /&gt;The attachment filename is "map_of_love###.zip"  where ### is a random number of length between 4 and 8 characters.&lt;br /&gt;&lt;br /&gt;Thanks to the UAB Spam Data Mine, it's fairly easy for us to link this new Fake AV spam campaign to previous ones.  For example -- we've seen 520 distinct sending IP addresses so far this morning, so let's ask "What was the most common email subject that those same sending IP addresses sent us yesterday?"&lt;br /&gt;&lt;br /&gt;43 of the IP addresses sent us an email yesterday with the subject "Your credit card is blocked"&lt;br /&gt;&lt;br /&gt;33 sent us "Your credit card has been blocked"&lt;br /&gt;&lt;br /&gt;That's the same campaign we've been seeing since we wrote about it on July 23rd (See: &lt;a href="http://garwarner.blogspot.com/2011/07/mastercard-spam-leads-to-fake-av.html"&gt;MasterCard Spam Leads to Fake AV&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;The other big fake AV campaign from yesterday was one pretending to be the US Postal Service.  We saw 814 copies of that spam yesterday, and 154 of them came from computers that also sent us today's "Love Map" malware.&lt;br /&gt;&lt;br /&gt;The USPS subjects were like:&lt;br /&gt;&lt;br /&gt; DELIVERY CONFIRMATION FROM USPS 0785164&lt;br /&gt; From USPS 0735590  &lt;br /&gt; USPS Attention 03867076 &lt;br /&gt; USPS: DELIVER CONFIRMATION - FAILED 1399475&lt;br /&gt; USPS Delivery Confirmation 1784864&lt;br /&gt; USPS id. 167163 &lt;br /&gt; Your USPS id. 12286791   &lt;br /&gt;&lt;br /&gt;With random upper and lowercasing, and random numbers in each subject.&lt;br /&gt;&lt;br /&gt;Here's a &lt;a href="http://www.virustotal.com/file-scan/report.html?id=679b8acf7fee1a2b7eb030f45420bf6fffe38c2b69196637bfecfd25b1d933d3-1312357821"&gt;VirusTotal report&lt;/A&gt; on yesterday's USPS Fake AV, which had MD5 =  a9a01f061d336774276fabb1827b91cc&lt;br /&gt;&lt;br /&gt;How closely related are the "MasterCard" fake AV and the USPS fake AV?  Well, they are actually IDENTICAL.  Its the same Malware.  Here's a report extract from yesterday showing the email subject and the MD5 of the attached malware:&lt;br /&gt;&lt;br /&gt; Your credit card is blocked                  | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card has been blocked            | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card is blocked                  | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card is blocked                  | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card has been blocked            | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card is blocked                  | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card is blocked                  | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card is blocked                  | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card has been blocked            | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card has been blocked            | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card has been blocked            | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card is blocked                  | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card is blocked                  | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card is blocked                  | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card is blocked                  | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your credit card has been blocked            | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; From USPS 38864359                           | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; USPS DELIVERY CONFIRMATION 954859            | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; From USPS 8815572                            | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; DELIVERY CONFIRMATION FROM USPS 6498394      | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; DELIVERY CONFIRMATION FROM USPS 73687208     | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; USPS DELIVERY CONFIRMATION 56547166          | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; USPS ATTENTION 578975                        | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; USPS: DELIVER CONFIRMATION - FAILED 9211453  | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; From USPS 5174072                            | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; USPS Attention 1201554                       | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your USPS id. 92444941                       | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; DELIVERY CONFIRMATION FROM USPS 575555       | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your USPS id. 82259351                       | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your USPS id. 139017                         | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; Your USPS id. 381458                         | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; From USPS 3877947                            | a9a01f061d336774276fabb1827b91cc&lt;br /&gt; USPS id. 45254864                            | a9a01f061d336774276fabb1827b91cc&lt;br /&gt;&lt;br /&gt;OK, back to today . . . &lt;br /&gt;&lt;br /&gt;Here are the "Love Map" spam subject lines we've seen it use so far:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; BABECITIES IN WORLD 2011&lt;br /&gt; BABEPLACES IN WORLD 2011&lt;br /&gt; BABIESPLACES IN WORLD 2011&lt;br /&gt; BABIESSPOTS IN WORLD 2011&lt;br /&gt; BABYCITIES IN WORLD 2011&lt;br /&gt; BABYSPOTS IN WORLD 2011&lt;br /&gt; GIRLSCITIES IN WORLD 2011&lt;br /&gt; GIRLSPLACES IN WORLD 2011&lt;br /&gt; GIRLSSPOTS IN WORLD 2011&lt;br /&gt; HOT BABE CITIES 2011&lt;br /&gt; HOT BABE PLACES 2011&lt;br /&gt; HOT BABE SPOTS 2011&lt;br /&gt; HOT BABIES CITIES 2011&lt;br /&gt; HOT BABIES SPOTS 2011&lt;br /&gt; HOT BABY CITIES 2011&lt;br /&gt; HOT BABY PLACES 2011&lt;br /&gt; HOT BABY SPOTS 2011&lt;br /&gt; HOT CITIES OF BABE 2011&lt;br /&gt; HOTCITIES OF BABIES 2011&lt;br /&gt; HOT CITIES OF BABY 2011&lt;br /&gt; HOTCITIES OF BABY 2011&lt;br /&gt; HOT CITIES OF GIRLS 2011&lt;br /&gt; HOTCITIES OF GIRLS 2011&lt;br /&gt; HOTCITIES OF PUSSY 2011&lt;br /&gt; HOT GIRLS PLACES 2011&lt;br /&gt; HOT GIRLS SPOTS 2011&lt;br /&gt; HOT PLACES OF BABE 2011&lt;br /&gt; HOT PLACES OF BABIES 2011&lt;br /&gt; HOTPLACES OF BABIES 2011&lt;br /&gt; HOT PLACES OF BABY 2011&lt;br /&gt; HOTPLACES OF BABY 2011&lt;br /&gt; HOT PLACES OF GIRLS 2011&lt;br /&gt; HOTPLACES OF GIRLS 2011&lt;br /&gt; HOT PLACES OF GIRLS IN WORLD&lt;br /&gt; HOTPLACES OF GIRLS IN WORLD&lt;br /&gt; HOT PLACES OF PUSSIES 2011&lt;br /&gt; HOTPLACES OF PUSSIES 2011&lt;br /&gt; HOT PLACES OF PUSSY 2011&lt;br /&gt; HOTPLACES OF PUSSY 2011&lt;br /&gt; HOT PUSSIES CITIES 2011&lt;br /&gt; HOT PUSSIES SPOTS 2011&lt;br /&gt; HOT PUSSY CITIES 2011&lt;br /&gt; HOT PUSSY PLACES 2011&lt;br /&gt; HOT PUSSY SPOTS 2011&lt;br /&gt; HOT SPOTS OF BABE 2011&lt;br /&gt; HOT SPOTS OF BABIES 2011&lt;br /&gt; HOTSPOTS OF BABIES 2011&lt;br /&gt; HOT SPOTS OF GIRLS 2011&lt;br /&gt; HOTSPOTS OF GIRLS 2011&lt;br /&gt; HOT SPOTS OF GIRLS IN WORLD&lt;br /&gt; HOT SPOTS OF PUSSIES 2011&lt;br /&gt; HOTSPOTS OF PUSSIES 2011&lt;br /&gt; HOT SPOTS OF PUSSY 2011&lt;br /&gt; HOTSPOTS OF PUSSY 2011&lt;br /&gt; JULY-2011: BABECITIES IN WORLD&lt;br /&gt; JULY-2011: BABEPLACES IN WORLD&lt;br /&gt; JULY-2011: BABIESCITIES IN WORLD&lt;br /&gt; JULY-2011: BABIESPLACES IN WORLD&lt;br /&gt; JULY-2011: BABYCITIES IN WORLD&lt;br /&gt; JULY-2011: BABYPLACES IN WORLD&lt;br /&gt; JULY-2011: GIRLSPLACES IN WORLD&lt;br /&gt; JULY-2011: GIRLSSPOTS IN WORLD&lt;br /&gt; JULY-2011: HOT BABE CITIES&lt;br /&gt; JULY-2011: HOT BABE PLACES&lt;br /&gt; JULY-2011: HOT BABE SPOTS&lt;br /&gt; JULY-2011: HOT BABIES CITIES&lt;br /&gt; JULY-2011: HOT BABY CITIES&lt;br /&gt; JULY-2011: HOT BABY PLACES&lt;br /&gt; JULY-2011: HOT BABY SPOTS&lt;br /&gt; JULY-2011: HOT CITIES OF BABE&lt;br /&gt; JULY-2011: HOTCITIES OF BABE&lt;br /&gt; JULY-2011: HOTCITIES OF BABIES&lt;br /&gt; JULY-2011: HOT CITIES OF BABY&lt;br /&gt; JULY-2011: HOTCITIES OF BABY&lt;br /&gt; JULY-2011: HOT CITIES OF GIRLS&lt;br /&gt; JULY-2011: HOTCITIES OF GIRLS&lt;br /&gt; JULY-2011: HOT CITIES OF PUSSIES&lt;br /&gt; JULY-2011: HOTCITIES OF PUSSIES&lt;br /&gt; JULY-2011: HOT CITIES OF PUSSY&lt;br /&gt; JULY-2011: HOTCITIES OF PUSSY&lt;br /&gt; JULY-2011: HOT GIRLS PLACES&lt;br /&gt; JULY-2011: HOT GIRLS SPOTS&lt;br /&gt; JULY-2011: HOT PLACES OF BABE&lt;br /&gt; JULY-2011: HOTPLACES OF BABE&lt;br /&gt; JULY-2011: HOT PLACES OF BABIES&lt;br /&gt; JULY-2011: HOTPLACES OF BABIES&lt;br /&gt; JULY-2011: HOT PLACES OF BABY&lt;br /&gt; JULY-2011: HOTPLACES OF BABY&lt;br /&gt; JULY-2011: HOT PLACES OF GIRLS&lt;br /&gt; JULY-2011: HOTPLACES OF GIRLS&lt;br /&gt; JULY-2011: HOTPLACES OF PUSSIES&lt;br /&gt; JULY-2011: HOT PLACES OF PUSSY&lt;br /&gt; JULY-2011: HOTPLACES OF PUSSY&lt;br /&gt; JULY-2011: HOT PUSSIES CITIES&lt;br /&gt; JULY-2011: HOT PUSSIES PLACES&lt;br /&gt; JULY-2011: HOT PUSSIES SPOTS&lt;br /&gt; JULY-2011: HOT PUSSY CITIES&lt;br /&gt; JULY-2011: HOT PUSSY PLACES&lt;br /&gt; JULY-2011: HOT PUSSY SPOTS&lt;br /&gt; JULY-2011: HOTSPOTS OF BABE&lt;br /&gt; JULY-2011: HOT SPOTS OF BABIES&lt;br /&gt; JULY-2011: HOTSPOTS OF BABIES&lt;br /&gt; JULY-2011: HOT SPOTS OF BABY&lt;br /&gt; JULY-2011: HOTSPOTS OF BABY&lt;br /&gt; JULY-2011: HOT SPOTS OF GIRLS&lt;br /&gt; JULY-2011: HOTSPOTS OF GIRLS&lt;br /&gt; JULY-2011: HOT SPOTS OF PUSSIES&lt;br /&gt; JULY-2011: HOTSPOTS OF PUSSIES&lt;br /&gt; JULY-2011: HOT SPOTS OF PUSSY&lt;br /&gt; JULY-2011: LOVE BABE CITIES&lt;br /&gt; JULY-2011: LOVE BABE PLACES&lt;br /&gt; JULY-2011: LOVE BABIES SPOTS&lt;br /&gt; JULY-2011: LOVE BABY CITIES&lt;br /&gt; JULY-2011: LOVE BABY PLACES&lt;br /&gt; JULY-2011: LOVE BABY SPOTS&lt;br /&gt; JULY-2011: LOVE CITIES IN WORLD&lt;br /&gt; JULY-2011: LOVE CITIES OF BABE&lt;br /&gt; JULY-2011: LOVECITIES OF BABE&lt;br /&gt; JULY-2011: LOVECITIES OF BABIES&lt;br /&gt; JULY-2011: LOVE CITIES OF BABY&lt;br /&gt; JULY-2011: LOVECITIES OF BABY&lt;br /&gt; JULY-2011: LOVECITIES OF GIRLS&lt;br /&gt; JULY-2011: LOVE CITIES OF PUSSIES&lt;br /&gt; JULY-2011: LOVECITIES OF PUSSIES&lt;br /&gt; JULY-2011: LOVE CITIES OF PUSSY&lt;br /&gt; JULY-2011: LOVECITIES OF PUSSY&lt;br /&gt; JULY-2011: LOVE GIRLS CITIES&lt;br /&gt; JULY-2011: LOVE GIRLS PLACES&lt;br /&gt; JULY-2011: LOVE GIRLS SPOTS&lt;br /&gt; JULY-2011: LOVE MAP OF BABE&lt;br /&gt; JULY-2011: LOVE MAP OF BABIES&lt;br /&gt; JULY-2011: LOVE-MAP OF BABIES&lt;br /&gt; JULY-2011: LOVE-MAP OF BABY&lt;br /&gt; JULY-2011: LOVE MAP OF GIRLS&lt;br /&gt; JULY-2011: LOVE-MAP OF GIRLS&lt;br /&gt; JULY-2011: LOVE MAP OF PUSSIES&lt;br /&gt; JULY-2011: LOVE-MAP OF PUSSIES&lt;br /&gt; JULY-2011: LOVE MAP OF PUSSY&lt;br /&gt; JULY-2011: LOVE-MAP OF PUSSY&lt;br /&gt; JULY-2011: LOVEPLACES IN WORLD&lt;br /&gt; JULY-2011: LOVE PLACES OF BABE&lt;br /&gt; JULY-2011: LOVEPLACES OF BABE&lt;br /&gt; JULY-2011: LOVE PLACES OF BABIES&lt;br /&gt; JULY-2011: LOVEPLACES OF BABIES&lt;br /&gt; JULY-2011: LOVE PLACES OF BABY&lt;br /&gt; JULY-2011: LOVEPLACES OF BABY&lt;br /&gt; JULY-2011: LOVE PLACES OF GIRLS&lt;br /&gt; JULY-2011: LOVEPLACES OF GIRLS&lt;br /&gt; JULY-2011: LOVE PLACES OF PUSSIES&lt;br /&gt; JULY-2011: LOVEPLACES OF PUSSIES&lt;br /&gt; JULY-2011: LOVE PLACES OF PUSSY&lt;br /&gt; JULY-2011: LOVE PUSSIES PLACES&lt;br /&gt; JULY-2011: LOVE PUSSIES SPOTS&lt;br /&gt; JULY-2011: LOVE PUSSY CITIES&lt;br /&gt; JULY-2011: LOVE PUSSY PLACES&lt;br /&gt; JULY-2011: LOVE SPOTS IN WORLD&lt;br /&gt; JULY-2011: LOVESPOTS IN WORLD&lt;br /&gt; JULY-2011: LOVE SPOTS OF BABE&lt;br /&gt; JULY-2011: LOVESPOTS OF BABE&lt;br /&gt; JULY-2011: LOVE SPOTS OF BABIES&lt;br /&gt; JULY-2011: LOVE SPOTS OF BABY&lt;br /&gt; JULY-2011: LOVE SPOTS OF GIRLS&lt;br /&gt; JULY-2011: LOVESPOTS OF GIRLS&lt;br /&gt; JULY-2011: LOVE SPOTS OF PUSSIES&lt;br /&gt; JULY-2011: LOVESPOTS OF PUSSIES&lt;br /&gt; JULY-2011: LOVE SPOTS OF PUSSY&lt;br /&gt; JULY-2011: LOVESPOTS OF PUSSY&lt;br /&gt; JULY-2011: PUSSYCITIES IN WORLD&lt;br /&gt; JULY-2011: PUSSYPLACES IN WORLD&lt;br /&gt; JULY-2011: SEXYCITIES IN WORLD&lt;br /&gt; JULY-2011: SEXY LOVE MAP&lt;br /&gt; JULY-2011: SEXY LOVE-MAP&lt;br /&gt; JULY-2011: SEXY PLACES IN WORLD&lt;br /&gt; JULY-2011: SEXYPLACES IN WORLD&lt;br /&gt; JULY-2011: SEXYSPOTS IN WORLD&lt;br /&gt; JULY-2011: SEXY WORLD MAP&lt;br /&gt; JULY-2011: WORLD MAP OF BABE&lt;br /&gt; JULY-2011: WORLD-MAP OF BABE&lt;br /&gt; JULY-2011: WORLD MAP OF BABIES&lt;br /&gt; JULY-2011: WORLD-MAP OF BABIES&lt;br /&gt; JULY-2011: WORLD MAP OF BABY&lt;br /&gt; JULY-2011: WORLD-MAP OF BABY&lt;br /&gt; JULY-2011: WORLD MAP OF GIRLS&lt;br /&gt; JULY-2011: WORLD-MAP OF GIRLS&lt;br /&gt; JULY-2011: WORLD-MAP OF PUSSIES&lt;br /&gt; JULY-2011: WORLD MAP OF PUSSY&lt;br /&gt; JULY-2011: WORLD-MAP OF PUSSY&lt;br /&gt; KNOW-HOW: BABECITIES IN WORLD&lt;br /&gt; KNOW-HOW: BABEPLACES IN WORLD&lt;br /&gt; KNOW-HOW: BABESPOTS IN WORLD&lt;br /&gt; KNOW-HOW: BABIESCITIES IN WORLD&lt;br /&gt; KNOW-HOW: BABIESSPOTS IN WORLD&lt;br /&gt; KNOW-HOW: BABYCITIES IN WORLD&lt;br /&gt; KNOW-HOW: BABYPLACES IN WORLD&lt;br /&gt; KNOW-HOW: BABYSPOTS IN WORLD&lt;br /&gt; KNOW-HOW: GIRLSPLACES IN WORLD&lt;br /&gt; KNOW-HOW: HOT BABE PLACES&lt;br /&gt; KNOW-HOW: HOT BABE SPOTS&lt;br /&gt; KNOW-HOW: HOT BABIES CITIES&lt;br /&gt; KNOW-HOW: HOT BABIES PLACES&lt;br /&gt; KNOW-HOW: HOT BABIES SPOTS&lt;br /&gt; KNOW-HOW: HOT BABY CITIES&lt;br /&gt; KNOW-HOW: HOT BABY PLACES&lt;br /&gt; KNOW-HOW: HOT BABY SPOTS&lt;br /&gt; KNOW-HOW: HOT CITIES OF BABE&lt;br /&gt; KNOW-HOW: HOTCITIES OF BABE&lt;br /&gt; KNOW-HOW: HOT CITIES OF BABIES&lt;br /&gt; KNOW-HOW: HOTCITIES OF BABIES&lt;br /&gt; KNOW-HOW: HOT CITIES OF BABY&lt;br /&gt; KNOW-HOW: HOTCITIES OF BABY&lt;br /&gt; KNOW-HOW: HOT CITIES OF PUSSIES&lt;br /&gt; KNOW-HOW: HOTCITIES OF PUSSY&lt;br /&gt; KNOW-HOW: HOT GIRLS CITIES&lt;br /&gt; KNOW-HOW: HOT GIRLS SPOTS&lt;br /&gt; KNOW-HOW: HOT PLACES OF BABE&lt;br /&gt; KNOW-HOW: HOTPLACES OF BABE&lt;br /&gt; KNOW-HOW: HOT PLACES OF BABIES&lt;br /&gt; KNOW-HOW: HOTPLACES OF BABIES&lt;br /&gt; KNOW-HOW: HOTPLACES OF BABY&lt;br /&gt; KNOW-HOW: HOT PLACES OF GIRLS&lt;br /&gt; KNOW-HOW: HOTPLACES OF GIRLS&lt;br /&gt; KNOW-HOW: HOT PLACES OF PUSSIES&lt;br /&gt; KNOW-HOW: HOT PLACES OF PUSSY&lt;br /&gt; KNOW-HOW: HOTPLACES OF PUSSY&lt;br /&gt; KNOW-HOW: HOT PUSSIES CITIES&lt;br /&gt; KNOW-HOW: HOT PUSSIES PLACES&lt;br /&gt; KNOW-HOW: HOT PUSSY PLACES&lt;br /&gt; KNOW-HOW: HOT SPOTS OF BABE&lt;br /&gt; KNOW-HOW: HOTSPOTS OF BABE&lt;br /&gt; KNOW-HOW: HOT SPOTS OF BABY&lt;br /&gt; KNOW-HOW: HOTSPOTS OF BABY&lt;br /&gt; KNOW-HOW: HOTSPOTS OF GIRLS&lt;br /&gt; KNOW-HOW: HOTSPOTS OF PUSSY&lt;br /&gt; KNOW-HOW: LOVE BABE CITIES&lt;br /&gt; KNOW-HOW: LOVE BABE SPOTS&lt;br /&gt; KNOW-HOW: LOVE BABIES CITIES&lt;br /&gt; KNOW-HOW: LOVE BABIES PLACES&lt;br /&gt; KNOW-HOW: LOVE BABY CITIES&lt;br /&gt; KNOW-HOW: LOVE CITIES IN WORLD&lt;br /&gt; KNOW-HOW: LOVECITIES IN WORLD&lt;br /&gt; KNOW-HOW: LOVECITIES OF BABE&lt;br /&gt; KNOW-HOW: LOVECITIES OF BABIES&lt;br /&gt; KNOW-HOW: LOVE CITIES OF BABY&lt;br /&gt; KNOW-HOW: LOVECITIES OF BABY&lt;br /&gt; KNOW-HOW: LOVE CITIES OF GIRLS&lt;br /&gt; KNOW-HOW: LOVECITIES OF PUSSIES&lt;br /&gt; KNOW-HOW: LOVE CITIES OF PUSSY&lt;br /&gt; KNOW-HOW: LOVECITIES OF PUSSY&lt;br /&gt; KNOW-HOW: LOVE GIRLS CITIES&lt;br /&gt; KNOW-HOW: LOVE GIRLS SPOTS&lt;br /&gt; KNOW-HOW: LOVE MAP OF BABE&lt;br /&gt; KNOW-HOW: LOVE MAP OF BABIES&lt;br /&gt; KNOW-HOW: LOVE MAP OF BABY&lt;br /&gt; KNOW-HOW: LOVE-MAP OF BABY&lt;br /&gt; KNOW-HOW: LOVE MAP OF GIRLS&lt;br /&gt; KNOW-HOW: LOVE-MAP OF GIRLS&lt;br /&gt; KNOW-HOW: LOVE MAP OF PUSSIES&lt;br /&gt; KNOW-HOW: LOVE-MAP OF PUSSIES&lt;br /&gt; KNOW-HOW: LOVE MAP OF PUSSY&lt;br /&gt; KNOW-HOW: LOVE-MAP OF PUSSY&lt;br /&gt; KNOW-HOW: LOVE PLACES IN WORLD&lt;br /&gt; KNOW-HOW: LOVEPLACES IN WORLD&lt;br /&gt; KNOW-HOW: LOVE PLACES OF BABE&lt;br /&gt; KNOW-HOW: LOVEPLACES OF BABE&lt;br /&gt; KNOW-HOW: LOVEPLACES OF BABIES&lt;br /&gt; KNOW-HOW: LOVE PLACES OF BABY&lt;br /&gt; KNOW-HOW: LOVEPLACES OF BABY&lt;br /&gt; KNOW-HOW: LOVE PLACES OF GIRLS&lt;br /&gt; KNOW-HOW: LOVEPLACES OF GIRLS&lt;br /&gt; KNOW-HOW: LOVE PLACES OF PUSSIES&lt;br /&gt; KNOW-HOW: LOVEPLACES OF PUSSIES&lt;br /&gt; KNOW-HOW: LOVE PLACES OF PUSSY&lt;br /&gt; KNOW-HOW: LOVEPLACES OF PUSSY&lt;br /&gt; KNOW-HOW: LOVE PUSSIES CITIES&lt;br /&gt; KNOW-HOW: LOVE PUSSIES PLACES&lt;br /&gt; KNOW-HOW: LOVE PUSSIES SPOTS&lt;br /&gt; KNOW-HOW: LOVE PUSSY CITIES&lt;br /&gt; KNOW-HOW: LOVE PUSSY PLACES&lt;br /&gt; KNOW-HOW: LOVE PUSSY SPOTS&lt;br /&gt; KNOW-HOW: LOVE SPOTS IN WORLD&lt;br /&gt; KNOW-HOW: LOVE SPOTS OF BABE&lt;br /&gt; KNOW-HOW: LOVESPOTS OF BABE&lt;br /&gt; KNOW-HOW: LOVESPOTS OF BABIES&lt;br /&gt; KNOW-HOW: LOVESPOTS OF BABY&lt;br /&gt; KNOW-HOW: LOVE SPOTS OF GIRLS&lt;br /&gt; KNOW-HOW: LOVESPOTS OF GIRLS&lt;br /&gt; KNOW-HOW: LOVE SPOTS OF PUSSIES&lt;br /&gt; KNOW-HOW: LOVESPOTS OF PUSSIES&lt;br /&gt; KNOW-HOW: LOVESPOTS OF PUSSY&lt;br /&gt; KNOW-HOW: PUSSYPLACES IN WORLD&lt;br /&gt; KNOW-HOW: PUSSYSPOTS IN WORLD&lt;br /&gt; KNOW-HOW: SEXY CITIES IN WORLD&lt;br /&gt; KNOW-HOW: SEXYCITIES IN WORLD&lt;br /&gt; KNOW-HOW: SEXY LOVE MAP&lt;br /&gt; KNOW-HOW: SEXY LOVE-MAP&lt;br /&gt; KNOW-HOW: SEXY PLACES IN WORLD&lt;br /&gt; KNOW-HOW: SEXYPLACES IN WORLD&lt;br /&gt; KNOW-HOW: SEXY SPOTS IN WORLD&lt;br /&gt; KNOW-HOW: SEXYSPOTS IN WORLD&lt;br /&gt; KNOW-HOW: SEXY WORLD MAP&lt;br /&gt; KNOW-HOW: SEXY WORLD-MAP&lt;br /&gt; KNOW-HOW: WORLD MAP OF BABE&lt;br /&gt; KNOW-HOW: WORLD-MAP OF BABE&lt;br /&gt; KNOW-HOW: WORLD MAP OF BABIES&lt;br /&gt; KNOW-HOW: WORLD-MAP OF BABIES&lt;br /&gt; KNOW-HOW: WORLD MAP OF BABY&lt;br /&gt; KNOW-HOW: WORLD-MAP OF BABY&lt;br /&gt; KNOW-HOW: WORLD MAP OF GIRLS&lt;br /&gt; KNOW-HOW: WORLD-MAP OF GIRLS&lt;br /&gt; KNOW-HOW: WORLD-MAP OF PUSSIES&lt;br /&gt; KNOW-HOW: WORLD MAP OF PUSSY&lt;br /&gt; LOVE BABE CITIES 2011&lt;br /&gt; LOVE BABE PLACES 2011&lt;br /&gt; LOVE BABE SPOTS 2011&lt;br /&gt; LOVE BABIES CITIES 2011&lt;br /&gt; LOVE BABIES PLACES 2011&lt;br /&gt; LOVE BABIES SPOTS 2011&lt;br /&gt; LOVE BABY CITIES 2011&lt;br /&gt; LOVE BABY PLACES 2011&lt;br /&gt; LOVE BABY SPOTS 2011&lt;br /&gt; LOVE CITIES IN WORLD 2011&lt;br /&gt; LOVE CITIES OF BABE 2011&lt;br /&gt; LOVECITIES OF BABE 2011&lt;br /&gt; LOVE CITIES OF BABIES 2011&lt;br /&gt; LOVECITIES OF BABIES 2011&lt;br /&gt; LOVE CITIES OF BABY 2011&lt;br /&gt; LOVECITIES OF BABY 2011&lt;br /&gt; LOVE CITIES OF GIRLS 2011&lt;br /&gt; LOVECITIES OF GIRLS 2011&lt;br /&gt; LOVE CITIES OF PUSSIES 2011&lt;br /&gt; LOVECITIES OF PUSSIES 2011&lt;br /&gt; LOVE CITIES OF PUSSY 2011&lt;br /&gt; LOVECITIES OF PUSSY 2011&lt;br /&gt; LOVE GIRLS CITIES 2011&lt;br /&gt; LOVE GIRLS PLACES 2011&lt;br /&gt; LOVE GIRLS SPOTS 2011&lt;br /&gt; LOVE MAP OF BABE 2011&lt;br /&gt; LOVE-MAP OF BABE 2011&lt;br /&gt; LOVE MAP OF BABIES 2011&lt;br /&gt; LOVE-MAP OF BABIES 2011&lt;br /&gt; LOVE MAP OF BABY 2011&lt;br /&gt; LOVE-MAP OF BABY 2011&lt;br /&gt; LOVE-MAP OF GIRLS 2011&lt;br /&gt; LOVE MAP OF PUSSIES 2011&lt;br /&gt; LOVE-MAP OF PUSSY 2011&lt;br /&gt; LOVE PLACES IN WORLD 2011&lt;br /&gt; LOVEPLACES IN WORLD 2011&lt;br /&gt; LOVE PLACES OF BABE 2011&lt;br /&gt; LOVEPLACES OF BABE 2011&lt;br /&gt; LOVE PLACES OF BABIES 2011&lt;br /&gt; LOVEPLACES OF BABIES 2011&lt;br /&gt; LOVEPLACES OF BABY 2011&lt;br /&gt; LOVE PLACES OF GIRLS 2011&lt;br /&gt; LOVEPLACES OF GIRLS 2011&lt;br /&gt; LOVE PLACES OF GIRLS IN WORLD&lt;br /&gt; LOVEPLACES OF GIRLS IN WORLD&lt;br /&gt; LOVE PLACES OF PUSSIES 2011&lt;br /&gt; LOVEPLACES OF PUSSIES 2011&lt;br /&gt; LOVE PLACES OF PUSSY 2011&lt;br /&gt; LOVEPLACES OF PUSSY 2011&lt;br /&gt; LOVE PUSSIES PLACES 2011&lt;br /&gt; LOVE PUSSIES SPOTS 2011&lt;br /&gt; LOVE PUSSY CITIES 2011&lt;br /&gt; LOVE PUSSY PLACES 2011&lt;br /&gt; LOVE PUSSY SPOTS 2011&lt;br /&gt; LOVE SPOTS IN WORLD 2011&lt;br /&gt; LOVESPOTS IN WORLD 2011&lt;br /&gt; LOVESPOTS OF BABE 2011&lt;br /&gt; LOVE SPOTS OF BABIES 2011&lt;br /&gt; LOVESPOTS OF BABIES 2011&lt;br /&gt; LOVE SPOTS OF BABY 2011&lt;br /&gt; LOVESPOTS OF BABY 2011&lt;br /&gt; LOVE SPOTS OF GIRLS 2011&lt;br /&gt; LOVESPOTS OF GIRLS 2011&lt;br /&gt; LOVE SPOTS OF GIRLS IN WORLD&lt;br /&gt; LOVE SPOTS OF PUSSIES 2011&lt;br /&gt; LOVESPOTS OF PUSSIES 2011&lt;br /&gt; LOVE SPOTS OF PUSSY 2011&lt;br /&gt; LOVESPOTS OF PUSSY 2011&lt;br /&gt; PUSSIESCITIES IN WORLD 2011&lt;br /&gt; PUSSIESPLACES IN WORLD&lt;br /&gt; PUSSIESSPOTS IN WORLD 2011&lt;br /&gt; PUSSYCITIES IN WORLD 2011&lt;br /&gt; PUSSYPLACES IN WORLD 2011&lt;br /&gt; PUSSYSPOTS IN WORLD 2011&lt;br /&gt; SEXY CITIES IN WORLD 2011&lt;br /&gt; SEXY LOVE MAP 2011&lt;br /&gt; SEXY LOVE-MAP 2011&lt;br /&gt; SEXY PLACES IN WORLD 2011&lt;br /&gt; SEXYPLACES IN WORLD 2011&lt;br /&gt; SEXY SPOTS IN WORLD&lt;br /&gt; SEXYSPOTS IN WORLD&lt;br /&gt; SEXY WORLD MAP 2011&lt;br /&gt; SUMMER-2011: BABECITIES IN WORLD&lt;br /&gt; SUMMER-2011: BABEPLACES IN WORLD&lt;br /&gt; SUMMER-2011: BABIESCITIES IN WORLD&lt;br /&gt; SUMMER-2011: BABIESPLACES IN WORLD&lt;br /&gt; SUMMER-2011: BABYCITIES IN WORLD&lt;br /&gt; SUMMER-2011: BABYPLACES IN WORLD&lt;br /&gt; SUMMER-2011: GIRLSCITIES IN WORLD&lt;br /&gt; SUMMER-2011: GIRLSPLACES IN WORLD&lt;br /&gt; SUMMER-2011: GIRLSSPOTS IN WORLD&lt;br /&gt; SUMMER-2011: HOT BABE SPOTS&lt;br /&gt; SUMMER-2011: HOT BABIES CITIES&lt;br /&gt; SUMMER-2011: HOT BABIES PLACES&lt;br /&gt; SUMMER-2011: HOT BABY PLACES&lt;br /&gt; SUMMER-2011: HOT CITIES OF BABE&lt;br /&gt; SUMMER-2011: HOTCITIES OF BABE&lt;br /&gt; SUMMER-2011: HOT CITIES OF BABIES&lt;br /&gt; SUMMER-2011: HOT CITIES OF BABY&lt;br /&gt; SUMMER-2011: HOTCITIES OF BABY&lt;br /&gt; SUMMER-2011: HOT CITIES OF GIRLS&lt;br /&gt; SUMMER-2011: HOT CITIES OF PUSSIES&lt;br /&gt; SUMMER-2011: HOT CITIES OF PUSSY&lt;br /&gt; SUMMER-2011: HOTCITIES OF PUSSY&lt;br /&gt; SUMMER-2011: HOT GIRLS CITIES&lt;br /&gt; SUMMER-2011: HOTPLACES OF BABE&lt;br /&gt; SUMMER-2011: HOT PLACES OF BABIES&lt;br /&gt; SUMMER-2011: HOTPLACES OF BABIES&lt;br /&gt; SUMMER-2011: HOT PLACES OF BABY&lt;br /&gt; SUMMER-2011: HOTPLACES OF BABY&lt;br /&gt; SUMMER-2011: HOT PLACES OF GIRLS&lt;br /&gt; SUMMER-2011: HOTPLACES OF GIRLS&lt;br /&gt; SUMMER-2011: HOT PLACES OF PUSSIES&lt;br /&gt; SUMMER-2011: HOTPLACES OF PUSSIES&lt;br /&gt; SUMMER-2011: HOT PLACES OF PUSSY&lt;br /&gt; SUMMER-2011: HOTPLACES OF PUSSY&lt;br /&gt; SUMMER-2011: HOT PUSSIES CITIES&lt;br /&gt; SUMMER-2011: HOT PUSSIES PLACES&lt;br /&gt; SUMMER-2011: HOT PUSSY CITIES&lt;br /&gt; SUMMER-2011: HOT PUSSY SPOTS&lt;br /&gt; SUMMER-2011: HOT SPOTS OF BABE&lt;br /&gt; SUMMER-2011: HOTSPOTS OF BABE&lt;br /&gt; SUMMER-2011: HOT SPOTS OF BABIES&lt;br /&gt; SUMMER-2011: HOTSPOTS OF BABIES&lt;br /&gt; SUMMER-2011: HOT SPOTS OF BABY&lt;br /&gt; SUMMER-2011: HOTSPOTS OF BABY&lt;br /&gt; SUMMER-2011: HOT SPOTS OF GIRLS&lt;br /&gt; SUMMER-2011: HOTSPOTS OF GIRLS&lt;br /&gt; SUMMER-2011: HOT SPOTS OF PUSSIES&lt;br /&gt; SUMMER-2011: HOTSPOTS OF PUSSIES&lt;br /&gt; SUMMER-2011: HOT SPOTS OF PUSSY&lt;br /&gt; SUMMER-2011: HOTSPOTS OF PUSSY&lt;br /&gt; SUMMER-2011: LOVE BABE CITIES&lt;br /&gt; SUMMER-2011: LOVE BABE PLACES&lt;br /&gt; SUMMER-2011: LOVE BABE SPOTS&lt;br /&gt; SUMMER-2011: LOVE BABIES CITIES&lt;br /&gt; SUMMER-2011: LOVE BABIES SPOTS&lt;br /&gt; SUMMER-2011: LOVE BABY CITIES&lt;br /&gt; SUMMER-2011: LOVE BABY PLACES&lt;br /&gt; SUMMER-2011: LOVE CITIES IN WORLD&lt;br /&gt; SUMMER-2011: LOVE CITIES OF BABE&lt;br /&gt; SUMMER-2011: LOVECITIES OF BABE&lt;br /&gt; SUMMER-2011: LOVECITIES OF BABIES&lt;br /&gt; SUMMER-2011: LOVE CITIES OF BABY&lt;br /&gt; SUMMER-2011: LOVECITIES OF BABY&lt;br /&gt; SUMMER-2011: LOVE CITIES OF PUSSIES&lt;br /&gt; SUMMER-2011: LOVECITIES OF PUSSIES&lt;br /&gt; SUMMER-2011: LOVE CITIES OF PUSSY&lt;br /&gt; SUMMER-2011: LOVECITIES OF PUSSY&lt;br /&gt; SUMMER-2011: LOVE GIRLS CITIES&lt;br /&gt; SUMMER-2011: LOVE GIRLS PLACES&lt;br /&gt; SUMMER-2011: LOVE GIRLS SPOTS&lt;br /&gt; SUMMER-2011: LOVE MAP OF BABE&lt;br /&gt; SUMMER-2011: LOVE-MAP OF BABE&lt;br /&gt; SUMMER-2011: LOVE MAP OF BABIES&lt;br /&gt; SUMMER-2011: LOVE-MAP OF BABIES&lt;br /&gt; SUMMER-2011: LOVE MAP OF BABY&lt;br /&gt; SUMMER-2011: LOVE-MAP OF BABY&lt;br /&gt; SUMMER-2011: LOVE-MAP OF GIRLS&lt;br /&gt; SUMMER-2011: LOVE MAP OF PUSSIES&lt;br /&gt; SUMMER-2011: LOVE-MAP OF PUSSIES&lt;br /&gt; SUMMER-2011: LOVE MAP OF PUSSY&lt;br /&gt; SUMMER-2011: LOVE-MAP OF PUSSY&lt;br /&gt; SUMMER-2011: LOVE PLACES OF BABE&lt;br /&gt; SUMMER-2011: LOVEPLACES OF BABE&lt;br /&gt; SUMMER-2011: LOVE PLACES OF BABIES&lt;br /&gt; SUMMER-2011: LOVEPLACES OF BABIES&lt;br /&gt; SUMMER-2011: LOVE PLACES OF BABY&lt;br /&gt; SUMMER-2011: LOVEPLACES OF BABY&lt;br /&gt; SUMMER-2011: LOVE PLACES OF GIRLS&lt;br /&gt; SUMMER-2011: LOVEPLACES OF GIRLS&lt;br /&gt; SUMMER-2011: LOVE PLACES OF PUSSIES&lt;br /&gt; SUMMER-2011: LOVEPLACES OF PUSSIES&lt;br /&gt; SUMMER-2011: LOVEPLACES OF PUSSY&lt;br /&gt; SUMMER-2011: LOVE PUSSIES CITIES&lt;br /&gt; SUMMER-2011: LOVE PUSSIES PLACES&lt;br /&gt; SUMMER-2011: LOVE PUSSIES SPOTS&lt;br /&gt; SUMMER-2011: LOVE PUSSY CITIES&lt;br /&gt; SUMMER-2011: LOVE PUSSY SPOTS&lt;br /&gt; SUMMER-2011: LOVE SPOTS IN WORLD&lt;br /&gt; SUMMER-2011: LOVESPOTS IN WORLD&lt;br /&gt; SUMMER-2011: LOVE SPOTS OF BABE&lt;br /&gt; SUMMER-2011: LOVESPOTS OF BABE&lt;br /&gt; SUMMER-2011: LOVE SPOTS OF BABIES&lt;br /&gt; SUMMER-2011: LOVESPOTS OF BABIES&lt;br /&gt; SUMMER-2011: LOVE SPOTS OF BABY&lt;br /&gt; SUMMER-2011: LOVESPOTS OF BABY&lt;br /&gt; SUMMER-2011: LOVE SPOTS OF GIRLS&lt;br /&gt; SUMMER-2011: LOVE SPOTS OF PUSSIES&lt;br /&gt; SUMMER-2011: LOVESPOTS OF PUSSIES&lt;br /&gt; SUMMER-2011: LOVE SPOTS OF PUSSY&lt;br /&gt; SUMMER-2011: LOVESPOTS OF PUSSY&lt;br /&gt; SUMMER-2011: PUSSYCITIES IN WORLD&lt;br /&gt; SUMMER-2011: PUSSYPLACES IN WORLD&lt;br /&gt; SUMMER-2011: SEXYCITIES IN WORLD&lt;br /&gt; SUMMER-2011: SEXY LOVE MAP&lt;br /&gt; SUMMER-2011: SEXY LOVE-MAP&lt;br /&gt; SUMMER-2011: SEXY PLACES IN WORLD&lt;br /&gt; SUMMER-2011: SEXYPLACES IN WORLD&lt;br /&gt; SUMMER-2011: SEXY SPOTS IN WORLD&lt;br /&gt; SUMMER-2011: SEXYSPOTS IN WORLD&lt;br /&gt; SUMMER-2011: SEXY WORLD MAP&lt;br /&gt; SUMMER-2011: SEXY WORLD-MAP&lt;br /&gt; SUMMER-2011: WORLD MAP OF BABE&lt;br /&gt; SUMMER-2011: WORLD-MAP OF BABE&lt;br /&gt; SUMMER-2011: WORLD MAP OF BABIES&lt;br /&gt; SUMMER-2011: WORLD MAP OF BABY&lt;br /&gt; SUMMER-2011: WORLD-MAP OF BABY&lt;br /&gt; SUMMER-2011: WORLD MAP OF GIRLS&lt;br /&gt; SUMMER-2011: WORLD-MAP OF GIRLS&lt;br /&gt; SUMMER-2011: WORLD MAP OF PUSSIES&lt;br /&gt; SUMMER-2011: WORLD-MAP OF PUSSIES&lt;br /&gt; SUMMER-2011: WORLD-MAP OF PUSSY&lt;br /&gt; WORLD MAP OF BABE 2011&lt;br /&gt; WORLD MAP OF BABIES 2011&lt;br /&gt; WORLD-MAP OF BABIES 2011&lt;br /&gt; WORLD-MAP OF BABY 2011&lt;br /&gt; WORLD MAP OF GIRLS 2011&lt;br /&gt; WORLD-MAP OF GIRLS 2011&lt;br /&gt; WORLD MAP OF PUSSY 2011&lt;br /&gt; WORLD-MAP OF PUSSY 2011&lt;br /&gt;(532 rows)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-674418766081138865?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/674418766081138865'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/674418766081138865'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/08/love-map-spam-spreads-fake-av.html' title='Love Map Spam spreads Fake AV'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-8658575455059098160</id><published>2011-07-31T18:31:00.001-07:00</published><updated>2011-08-01T05:50:33.347-07:00</updated><title type='text'>"Wrong Transaction" Hotel spam malware continues to evolve</title><content type='html'>One of the distinct advantages of having the UAB Spam Data Mine is that we are able to provide near-real-time intelligence about the evolution of malware campaigns being delivered by spam.  On July 27, 2011 we provided a warning about &lt;a href="http://garwarner.blogspot.com/2011/07/wrong-transaction-hotel-spam.html"&gt;Wrong Transaction Hotel Spam&lt;/A&gt; that was covered by Robert McMillan in &lt;a href="http://www.pcworld.com/businesscenter/article/236785/beware_of_wrong_transaction_hotel_spam.html"&gt;PC World&lt;/A&gt; and &lt;a href="http://www.computerworld.com/s/article/9218700/Beware_of_wrong_transaction_hotel_spam"&gt;ComputerWorld&lt;/A&gt;, and was also mentioned by Matt Liebowitz for &lt;a href="http://www.msnbc.msn.com/id/43948767/ns/technology_and_science-security/"&gt;MSNBC&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;Unfortunately, from an anti-virus perspective, consumers are no safer than they were when we first put out the warning four days ago.&lt;br /&gt;&lt;br /&gt;We're still seeing more than 1,000 copies per day of this malware (with the exception of the 29th) each day:&lt;br /&gt;&lt;br /&gt;&lt;PRE&gt; count | receiving_date&lt;br /&gt;-------+----------------&lt;br /&gt;  1516 | 2011-07-27&lt;br /&gt;  1828 | 2011-07-28&lt;br /&gt;   813 | 2011-07-29&lt;br /&gt;  1470 | 2011-07-30&lt;br /&gt;  1258 | 2011-07-31&lt;br /&gt;(5 rows)&lt;/PRE&gt;&lt;br /&gt;&lt;br /&gt;but the malware is constantly evolving.&lt;br /&gt;&lt;br /&gt;&lt;TABLE&gt;&lt;TR&gt;&lt;TD&gt;Count&lt;/TD&gt;&lt;TD&gt;Malware MD5&lt;/TD&gt;&lt;TD&gt;TimeRange&lt;/TD&gt;&lt;TR&gt;&lt;TR&gt;&lt;TD&gt;593&lt;/TD&gt;&lt;TD&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=45e144eddd021c08584f5d01b1645a128d52cf916b25ee0a1897421fad1328a7-1311804731"&gt;c15eb3c47800fec025b6a86a6409f144&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; 2011-07-27 03:00 AM to 2011-07-27 08:30 AM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1001&lt;/TD&gt;&lt;TD&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=c1c39ed4bbc5fa00e248eb7347bdd402b3394bc13cba2c1ffba3451a2a519f4c-1311867725"&gt;01e3bbd4b6f8c22a3516771f9b6792bc&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; 2011-07-27 12:45 PM to 2011-07-28 04:45 AM &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;318&lt;/TD&gt;&lt;TD&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=574f31bf08b88b74d669522fb5bcd7283936e5e5d206817f045ab0cdf79ea07f-1311933598"&gt;57d931256fd6d7184528ae983e34677b&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; 2011-07-27 08:00 AM to 2011-07-27 13:30 PM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;865&lt;/TD&gt;&lt;TD&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=43f181e363e3cf871cb9f33778950d2adebe1316b4c5ef86b11bd98427d1dc38-1311933260"&gt;6e2eae488317280dd813e3e2fc9e0275&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; 2011-07-28 04:15 AM to 2011-07-28 13:00 PM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;554&lt;/TD&gt;&lt;TD&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=8c1229842751633cc6481785a951a243efd14288830620e2d364856aca8310b4-1311893813"&gt;ad760ac5806a84a272e1eb76b315ac31&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; 2011-07-28 12:30 PM to 2011-07-28 20:15 PM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1116&lt;/TD&gt;&lt;TD&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=a0f5acf72995d475772848536208132aba096ff0e38a271deddabc4afb3f2a56-1312130415"&gt;4140ee10115174fe36a738d4d943f2af&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; 2011-07-29 13:45 PM to 2011-07-30 04:00 AM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;614&lt;/TD&gt;&lt;TD&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=96e2b145b4696a0b4c14454699f4eed2c290c4042edcf098f92edcc810a17d23-1312048485"&gt;e2d3d4ccf02ea924e6d11cb452235f4c&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; 2011-07-30 03:30 AM to 2011-07-30 16:15 PM &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;931&lt;/TD&gt;&lt;TD&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=33edc6b2b3cbeea9c2664c85c5e698c9d41fcf0722a1636f9b6b51cf940bc61e-1312109979"&gt;5bbe80ad216c89bcbb6891178dc4b5fa&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; 2011-07-30 14:45 PM to 2011-07-31 07:30 AM &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;409&lt;/TD&gt;&lt;TD&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=b11c3b0eeed2b3a28e1340cd0d4092c0baa3feb323eea03a9a4846a5e12421c2-1312129389"&gt;ca84d1a0c49eff5ca829b5fa531800e8&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; 2011-07-31 07:30 AM to 2011-07-31 13:15 PM&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;484&lt;/TD&gt;&lt;TD&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=9c3f7437ec5024ab67a91035a6aef03a574fe3ccc5b87d5e5ad9d79e32b7b7bb-1312151598"&gt;aa412182a164321a159f9b2e95be53bc&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt; 2011-07-31 13:15 PM to 2011-07-31 CURRENT TIME&lt;/TD&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;br /&gt;&lt;br /&gt;Each of the links in the table above will take you to the VirusTotal report showing how many of 43 different anti-virus products detected this particular malware at the time it was submitted to VirusTotal.&lt;br /&gt;&lt;br /&gt;I'll let you explore the links for yourself, but may I call attention to the fact the last one is detected by FOUR of forty-three AV products, and the one immediately prior to that by ONE of forty-three.&lt;br /&gt;&lt;br /&gt;Just to make sure there was not a problem, I decided to look at those last two and confirm that they actually were malware.&lt;br /&gt;&lt;br /&gt;We started with the sample starting with "aa412".  It unpacks successfully as an .exe named "Refund_Form" that uses an icon from Microsoft Office Excel to try to trick people into thinking it's a Spreadsheet.&lt;br /&gt;&lt;br /&gt;When we launched it, it made connections to:&lt;br /&gt;&lt;br /&gt;runescapegpge2011.ru - 84.247.61.25&lt;br /&gt;www.radio-80.com - 210.172.192.38&lt;br /&gt;heftyhips.com - 66.197.251.53&lt;br /&gt;&lt;br /&gt;That last would be exactly the same domain that the first sample we looked at on the 27th connected to.  It fetched "soft.exe" from www.radio-80.com.&lt;br /&gt;&lt;br /&gt;I'm going to go out on a limb and say this is malware.  "soft.exe" got renamed "defender.exe" and placed in our "C:\Documents and Settings\All Users\Application Data\" directory, which was scheduled to launch when the machine reboots.&lt;br /&gt;&lt;br /&gt;Defender.exe was declared to be malware by 6 of 43 anti-virus packages at VirusTotal.  &lt;a href="http://www.virustotal.com/file-scan/report.html?id=838e52d2d24a2d196c82381ca920eea8404e4a1acaabd32b2dab55d1899306f9-1312168802"&gt;Here's the report.&lt;/A&gt;  It's Fake anti-virus.&lt;br /&gt;&lt;br /&gt;Next, just to be thorough, we also checked out the version that started with "ca84d1".  Just like the first, it unpacked to a "Refund_Form.exe" file, although this one had a different MD5.  When we launched Refund_Form it made network connections to:&lt;br /&gt;&lt;br /&gt;runescapegpge2011.ru - 84.247.61.25&lt;br /&gt;ewingparkbmx2011.ru - failed to resolve&lt;br /&gt;&lt;br /&gt;It looks like this version is not functioning due to a dead domain, which may be the reason the "aa412" version was released.&lt;br /&gt;&lt;br /&gt;That "84.247.61.25" box is in Romania, currently using a domain name with "RuneScape" in the domain name.  The same IP has recently been called bedownloader2011.ru,  diamondexchange2011.ru,  watchfamilyguynow2011.ru and is also currently resolving as yomwarayom2001.ru.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Update 01AUG2011&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;At 3:15 this morning, the malware being distributed swapped to:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=7738dcd672505a326cad1e7829da273cc7b551ac5ea86971ea9cb1405df175bb-1312200938"&gt;2e749d608d29aef739f5b08e7f63225a&lt;/A&gt; (click for VirusTotal Report)&lt;br /&gt;&lt;br /&gt;The MD5 for the exe inside of the zip file with MD5 2e749d608d29aef739f5b08e7f63225a is:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=ab8d308fd59a8db8a130fcfdb6db56c4f7717877c465be98f71284bdfccdfa25-1312187723"&gt;a446ced5db1de877cf78f77741e2a804&lt;/A&gt; Filename: Refund-Form (dot) exe (1 of 43 detects at VirusTotal).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;At 4:30 this morning, and continuing to the present moment (07:45 AM Central Time), the malware being distributed swapped to:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=bfcb5923e3c0f152e63b5b56f20d7d3d28fb1bed56a1c280523416923c2a817f-1312193923"&gt;4b126c49c261ca0f65fce9e5d08811d6&lt;/A&gt; (click for VirusTotal Report)&lt;br /&gt;&lt;br /&gt;The MD5 for the exe inside of the zip file with MD5 4b126c49c261ca0f65fce9e5d08811d6 is:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=ca2313e0f2fa9efed00b481bf386656a7bb0f6cdde67a5da4d307a14f1b5013d-1312200838"&gt;2f0155c39ddcf490f3a310ba0546c627&lt;/A&gt; Filename: Refund_Form (dot) exe (5 of 43 detects at VirusTotal).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-8658575455059098160?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/8658575455059098160'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/8658575455059098160'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/07/wrong-transaction-hotel-spam-malware.html' title='&quot;Wrong Transaction&quot; Hotel spam malware continues to evolve'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-3215250803843289127</id><published>2011-07-28T04:12:00.000-07:00</published><updated>2011-07-29T03:36:08.092-07:00</updated><title type='text'>"Government-related" Zeus spam continues</title><content type='html'>As we discussed in yesterday's article, &lt;a href="http://garwarner.blogspot.com/2011/07/wrong-transaction-hotel-spam.html"&gt;"Wrong transaction" hotel spam&lt;/A&gt;, the UAB Spam Data Mine now has an ability to provide early alerting when a new spam campaign is directly linking to executable files.&lt;br /&gt;&lt;br /&gt;&lt;HR color="gold"&gt;&lt;br /&gt;Update:  New Zeus distribution site, July 29th AM:&lt;br /&gt;&lt;br /&gt;We are receiving spam emails this morning from "nacha.org" From: addresses that direct us to this Zeus distribution site.&lt;br /&gt;&lt;br /&gt;hxxp://federalreserve-alert.com/transaction_report.pdf.exe&lt;br /&gt;&lt;br /&gt;Here's the &lt;a href="http://www.virustotal.com/file-scan/report.html?id=1a30a352a65cf6ad2b9b8266617709672c777e58edaa625946d77aca427cd352-1311935053"&gt;VirusTotal report&lt;/A&gt;:  As of this timestamp (5:30 AM Central time) we see (5 of 43) detections.  Only 2 of those are calling this Zeus.&lt;br /&gt;&lt;br /&gt;&lt;HR color="gold"&gt;&lt;br /&gt;&lt;br /&gt;This morning we have a new example of this capability in the form of the two most recent installments of a long-running "government-related" Zeus campaign.  &lt;br /&gt;&lt;br /&gt;One of the two spammed destinations is:&lt;br /&gt;&lt;br /&gt;alert-irs.com  /00000700973770US.exe  MD5 = 0691a4856713edc97664e60db735747c&lt;br /&gt;&lt;br /&gt;This malware is currently showing a (12 of 43) detection rate at VirusTotal, as seen in this &lt;a href="http://www.virustotal.com/file-scan/report.html?id=4e4a01e8274ba7a3e323242bdaed9be784758f00f8cfa8681b1343d62b041037-1311851044"&gt;VirusTotal Report&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;The other spammed destination is:&lt;br /&gt;&lt;br /&gt;fdic-updates.com /system_update_07_28.exe  MD5 = 7a0303fdb809ac0c1a84123b106992c2&lt;br /&gt;&lt;br /&gt;This malware is currently showing a (8 of 43) detection rate at VirusTotal, as seen in this &lt;a href="http://www.virustotal.com/file-scan/report.html?id=6dd449d857bfef5c9ebbdbcf8af19c35e65cc23b7cf7ff091f914e43a018b252-1311850052"&gt;VirusTotal Report&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;Both files are 172,032 bytes in size, but currently the FDIC one is showing a dramatically wider distribution via email than the IRS one, which may be an indication of "targeting" by the latter.&lt;br /&gt;&lt;br /&gt;The FDIC version has been seen almost 500 times, despite the fact that the campaign is less than 45 minutes old as of this writing.  Here is the count per 15 minute block seen in the UAB Spam Data Mine:&lt;br /&gt;&lt;br /&gt;&lt;PRE&gt;     5 | ACH and Wire transfers disabled.      | 2011-07-28 06:00:00&lt;br /&gt;     3 | Banking security update.              | 2011-07-28 06:00:00&lt;br /&gt;     1 | Update for your banking account.      | 2011-07-28 06:00:00&lt;br /&gt;   107 | ACH and Wire transfers disabled.      | 2011-07-28 05:45:00&lt;br /&gt;   138 | Banking security update.              | 2011-07-28 05:45:00&lt;br /&gt;   108 | Security update for banking accounts. | 2011-07-28 05:45:00&lt;br /&gt;   122 | Update for your banking account.      | 2011-07-28 05:45:00&lt;br /&gt;     1 | Banking security update.              | 2011-07-28 05:30:00&lt;br /&gt;     1 | Security update for banking accounts. | 2011-07-28 05:30:00&lt;br /&gt;     1 | ACH and Wire transfers disabled.      | 2011-07-28 05:15:00&lt;br /&gt;     1 | Banking security update.              | 2011-07-28 05:15:00&lt;br /&gt;     1 | Security update for banking accounts. | 2011-07-28 05:15:00&lt;/PRE&gt;&lt;br /&gt;&lt;br /&gt;(Timestamps are US-Central Time, GMT -6)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The FDIC spam comes from email addresses that randomly associate these "usernames" with these "hostnames".  Everything in the first column was seen combined with everything in the second column.&lt;br /&gt;&lt;br /&gt;&lt;PRE&gt;admin            @   admin.fdic.gov&lt;br /&gt;adminnistration  @   administration.fdic.gov&lt;br /&gt;cunsumer         @   fdic.gov&lt;br /&gt;FDIC             @   security.fdic.gov&lt;br /&gt;finance          @&lt;br /&gt;govdelivery      @&lt;br /&gt;information      @&lt;br /&gt;inspector        @&lt;br /&gt;news             @&lt;br /&gt;no-reply         @&lt;br /&gt;privacy_policy   @&lt;br /&gt;protection       @&lt;br /&gt;public           @&lt;br /&gt;report           @&lt;br /&gt;service          @&lt;br /&gt;stats            @&lt;br /&gt;support          @&lt;br /&gt;webannouncements @&lt;/PRE&gt;&lt;br /&gt;&lt;br /&gt;Here's what the email actually says:&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;Dear clients, &lt;br /&gt;Your account &lt;strong&gt;ACH and Wire transactions&lt;/strong&gt; have been&lt;br /&gt;temporarily suspended for your settings, due to the &lt;br /&gt;expiration of your security version.  To download and install the&lt;br /&gt;&lt;strong&gt;newest Updates,&lt;/strong&gt; click &lt;a href=""&gt;here&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;As soon as it is Applied, your transaction abilities will be fully restored.&lt;br /&gt;&lt;br /&gt;Best regards,&lt;br /&gt;Online security department&lt;br /&gt;Federal Deposit Insurance Corporation&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The IRS related spam came first:&lt;br /&gt;&lt;br /&gt;&lt;PRE&gt;     2 | Internal Revenue Service     | 2011-07-28 04:15:00&lt;br /&gt;     2 | Federal Tax payment rejected | 2011-07-28 04:00:00&lt;br /&gt;     2 | Your IRS payment rejected    | 2011-07-28 04:00:00&lt;br /&gt;     2 | Internal Revenue Service     | 2011-07-28 03:45:00&lt;/PRE&gt;&lt;br /&gt;&lt;br /&gt;This is fairly typical spamming for this group.  They like to make a new Zeus variant, populate it on a website, and then spam it very hard at the beginning of the East Coast business day.  For example, here is the spam for:&lt;br /&gt;&lt;br /&gt; "nacha-rejected.com" &lt;br /&gt;&lt;br /&gt;&lt;PRE&gt;     2 | Rejected transaction | 2011-07-27 05:30:00&lt;br /&gt;     1 | Canceled  payment    | 2011-07-27 05:15:00&lt;br /&gt;     2 | Canceled transaction | 2011-07-27 05:15:00&lt;br /&gt;     3 | Payment rejected     | 2011-07-27 05:15:00&lt;br /&gt;     5 | Rejected transaction | 2011-07-27 05:15:00&lt;br /&gt;     2 | Canceled transaction | 2011-07-27 05:00:00&lt;br /&gt;     8 | Canceled transfer    | 2011-07-27 05:00:00&lt;br /&gt;     5 | Payment canceled     | 2011-07-27 05:00:00&lt;br /&gt;     3 | Payment rejected     | 2011-07-27 05:00:00&lt;br /&gt;     4 | Rejected transaction | 2011-07-27 05:00:00&lt;br /&gt;    92 | Canceled  payment    | 2011-07-27 04:45:00&lt;br /&gt;    74 | Canceled transaction | 2011-07-27 04:45:00&lt;br /&gt;    84 | Canceled transfer    | 2011-07-27 04:45:00&lt;br /&gt;    60 | Payment canceled     | 2011-07-27 04:45:00&lt;br /&gt;    75 | Payment rejected     | 2011-07-27 04:45:00&lt;br /&gt;    57 | Rejected transaction | 2011-07-27 04:45:00&lt;br /&gt;     2 | Payment canceled     | 2011-07-27 04:30:00&lt;br /&gt;     1 | Payment rejected     | 2011-07-27 04:30:00&lt;br /&gt;     1 | Canceled transaction | 2011-07-27 04:15:00&lt;br /&gt;     2 | Payment canceled     | 2011-07-27 04:15:00&lt;/PRE&gt;&lt;br /&gt;&lt;br /&gt;nacha-transactions.com&lt;br /&gt;&lt;br /&gt;&lt;PRE&gt;     1 | Payment rejected     | 2011-07-27 07:00:00&lt;br /&gt;     1 | Rejected transaction | 2011-07-27 06:45:00&lt;br /&gt;     4 | Canceled  payment    | 2011-07-27 06:30:00&lt;br /&gt;     2 | Canceled transfer    | 2011-07-27 06:30:00&lt;br /&gt;     1 | Payment canceled     | 2011-07-27 06:30:00&lt;br /&gt;     1 | Payment rejected     | 2011-07-27 06:30:00&lt;br /&gt;     1 | Canceled transaction | 2011-07-27 06:15:00&lt;br /&gt;     1 | Canceled transfer    | 2011-07-27 06:15:00&lt;br /&gt;     1 | Payment canceled     | 2011-07-27 06:15:00&lt;br /&gt;     1 | Payment rejected     | 2011-07-27 06:15:00&lt;/PRE&gt;&lt;br /&gt;&lt;br /&gt;taxes-refund.com&lt;br /&gt;&lt;br /&gt;&lt;PRE&gt;     1 | Internal Revenue Service        | 2011-07-27 08:00:00&lt;br /&gt;     1 | U.S. Department of the Treasury | 2011-07-27 08:00:00&lt;br /&gt;     1 | Internal Revenue Service        | 2011-07-27 07:45:00&lt;br /&gt;     2 | Internal Revenue Service (IRS)  | 2011-07-27 07:45:00&lt;br /&gt;     2 | Payment IRS.gov                 | 2011-07-27 07:45:00&lt;br /&gt;     1 | Internal Revenue Service        | 2011-07-27 07:30:00&lt;br /&gt;     1 | IRS.gov                         | 2011-07-27 07:30:00&lt;br /&gt;     1 | U.S. Department of the Treasury | 2011-07-27 07:30:00&lt;/PRE&gt;&lt;br /&gt;&lt;br /&gt;Three consecutive campaigns, one following the other, with the whole thing wrapping up before 8 AM Central time. (which would be 9 AM Eastern time). &lt;br /&gt;&lt;br /&gt;The NACHA spam leading to Zeus has been an issue for a very long time.  We've seen spam like this since all the way back to November 2009, but it's been fairly constant since February of this year when we shared the article &lt;a href="http://garwarner.blogspot.com/2011/02/ach-transaction-rejected-payments-lead.html"&gt;ACH Transaction Rejected Payment Spam&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Following the Botnet Back in Time&lt;/H3&gt;&lt;br /&gt;Because of the way we archive our email, it's possible for us to ask the UAB Spam Data Mine to reveal a deeper history for this particular spamming botnet by asking a question like:&lt;br /&gt;&lt;br /&gt;"Show me all the spam subjects that have been sent by IP addresses that sent me this morning's fdic-updates.com spam message"&lt;br /&gt;&lt;br /&gt;&lt;PRE&gt;     5 | 2011-07-28 06:00:00 | ACH and Wire transfers disabled.&lt;br /&gt;     3 | 2011-07-28 06:00:00 | Banking security update.&lt;br /&gt;     1 | 2011-07-28 06:00:00 | Update for your banking account.&lt;br /&gt;   107 | 2011-07-28 05:45:00 | ACH and Wire transfers disabled.&lt;br /&gt;   138 | 2011-07-28 05:45:00 | Banking security update.&lt;br /&gt;   108 | 2011-07-28 05:45:00 | Security update for banking accounts.&lt;br /&gt;   122 | 2011-07-28 05:45:00 | Update for your banking account.&lt;br /&gt;     1 | 2011-07-28 05:30:00 | Banking security update.&lt;br /&gt;     1 | 2011-07-28 05:30:00 | Security update for banking accounts.&lt;br /&gt;     1 | 2011-07-28 05:15:00 | ACH and Wire transfers disabled.&lt;br /&gt;     1 | 2011-07-28 05:15:00 | Banking security update.&lt;br /&gt;     1 | 2011-07-28 05:15:00 | Security update for banking accounts.&lt;br /&gt;     1 | 2011-07-27 23:30:00 | ho&lt;br /&gt;     1 | 2011-07-27 21:15:00 | RE:.. How do you do,&lt;br /&gt;     4 | 2011-07-27 20:00:00 | ho&lt;br /&gt;     1 | 2011-07-27 14:45:00 | VIDEO: Lockerbie bomber at pro-Gaddafi rally&lt;br /&gt;     1 | 2011-07-27 12:00:00 | Yo&lt;br /&gt;     1 | 2011-07-27 08:00:00 | Internal Revenue Service&lt;br /&gt;     1 | 2011-07-27 06:45:00 | Rejected transaction&lt;br /&gt;     2 | 2011-07-27 05:15:00 | Rejected transaction&lt;br /&gt;     2 | 2011-07-27 05:00:00 | Canceled transaction&lt;br /&gt;     2 | 2011-07-27 05:00:00 | Canceled transfer&lt;br /&gt;     3 | 2011-07-27 05:00:00 | Payment rejected&lt;br /&gt;    33 | 2011-07-27 04:45:00 | Canceled  payment&lt;br /&gt;    22 | 2011-07-27 04:45:00 | Canceled transaction&lt;br /&gt;    26 | 2011-07-27 04:45:00 | Canceled transfer&lt;br /&gt;    24 | 2011-07-27 04:45:00 | Payment canceled&lt;br /&gt;    30 | 2011-07-27 04:45:00 | Payment rejected&lt;br /&gt;    17 | 2011-07-27 04:45:00 | Rejected transaction&lt;br /&gt;     1 | 2011-07-27 04:30:00 | Payment canceled&lt;br /&gt;     1 | 2011-07-27 04:15:00 | Canceled transaction&lt;br /&gt;     1 | 2011-07-27 04:15:00 | Payment canceled&lt;br /&gt;     1 | 2011-07-26 17:15:00 | Attack on Guinea leader repelled&lt;br /&gt;     1 | 2011-07-26 06:00:00 | IRC.gov&lt;br /&gt;     1 | 2011-07-26 05:45:00 | VIDEO: Phoenix hit by second dust storm&lt;br /&gt;     1 | 2011-07-25 14:00:00 | Hi!&lt;br /&gt;     1 | 2011-07-23 19:45:00 | Giant space telescope reaches orbit&lt;br /&gt;     1 | 2011-07-23 19:45:00 | High Court challenge on care cuts&lt;br /&gt;     1 | 2011-07-23 19:45:00 | HMRC in cost-cutting 'challenge'&lt;br /&gt;     1 | 2011-07-23 19:45:00 | Mortgage lending remains subdued&lt;br /&gt;     1 | 2011-07-23 19:45:00 | Mum's stress reaches baby in womb&lt;br /&gt;     1 | 2011-07-23 19:45:00 | Nato hands over key Afghan city&lt;br /&gt;     1 | 2011-07-23 19:45:00 | Personal pension advice still bad&lt;br /&gt;     1 | 2011-07-23 19:45:00 | Scots economy escapes recession&lt;br /&gt;     1 | 2011-07-23 19:45:00 | Serbia arrests last war crimes fugitive&lt;br /&gt;     1 | 2011-07-23 19:45:00 | Strauss-Kahn daughter questioned&lt;br /&gt;     1 | 2011-07-23 19:45:00 | VIDEO: Key moments as MPs grill Murdochs&lt;br /&gt;     1 | 2011-07-23 18:30:00 | Heya&lt;br /&gt;     2 | 2011-07-22 19:45:00 | Hi&lt;br /&gt;     1 | 2011-07-22 19:00:00 | Hey&lt;br /&gt;     1 | 2011-07-22 19:00:00 | Hi&lt;br /&gt;     1 | 2011-07-22 13:45:00 | Heya&lt;br /&gt;     1 | 2011-07-22 07:15:00 | Read: A Must for High-Rise Emergencies&lt;br /&gt;     1 | 2011-07-22 05:00:00 | IRC.gov&lt;br /&gt;     1 | 2011-07-22 04:45:00 | Support IRS.gov&lt;br /&gt;     2 | 2011-07-22 03:45:00 | Change Confirmation&lt;br /&gt;     1 | 2011-07-22 03:45:00 | Does your enterprise including outstanding tax debts&lt;br /&gt;     1 | 2011-07-22 03:45:00 | Internal Revenue Service&lt;br /&gt;     1 | 2011-07-22 03:45:00 | Internal Revenue Service United States Department of the Treasury&lt;br /&gt;     1 | 2011-07-22 03:45:00 | IRC.gov&lt;br /&gt;     1 | 2011-07-22 03:45:00 | IRS.gov US&lt;br /&gt;     1 | 2011-07-22 03:45:00 | Notice of Underreported Income&lt;br /&gt;     3 | 2011-07-22 03:45:00 | Support IRS.gov&lt;br /&gt;     2 | 2011-07-22 03:45:00 | Treasury Inspector General for Tax Administration&lt;br /&gt;     2 | 2011-07-22 03:45:00 | U.S. Department of the Treasury&lt;br /&gt;     2 | 2011-07-22 03:45:00 | Your company including unpaid tax debts&lt;br /&gt;     1 | 2011-07-21 13:00:00 | Manhood raisers with price-offs!&lt;br /&gt;     1 | 2011-07-21 13:00:00 | Super lasting and good stiff!&lt;br /&gt;     1 | 2011-07-21 05:45:00 | New security update&lt;br /&gt;     2 | 2011-07-21 04:45:00 | Go id token update&lt;br /&gt;     6 | 2011-07-21 04:45:00 | Security token update&lt;br /&gt;     1 | 2011-07-21 04:45:00 | Token code update&lt;br /&gt;     2 | 2011-07-21 04:45:00 | Token software update&lt;br /&gt;     1 | 2011-07-20 07:30:00 | Canceled  payment&lt;br /&gt;     1 | 2011-07-20 07:30:00 | Rejected transaction&lt;br /&gt;     1 | 2011-07-20 07:00:00 | Payment rejected&lt;br /&gt;     1 | 2011-07-20 06:45:00 | Canceled  payment&lt;br /&gt;     1 | 2011-07-20 06:45:00 | Payment canceled&lt;br /&gt;    16 | 2011-07-20 06:30:00 | Canceled  payment&lt;br /&gt;     8 | 2011-07-20 06:30:00 | Canceled transaction&lt;br /&gt;    10 | 2011-07-20 06:30:00 | Canceled transfer&lt;br /&gt;     7 | 2011-07-20 06:30:00 | Payment canceled&lt;br /&gt;     8 | 2011-07-20 06:30:00 | Payment rejected&lt;br /&gt;     6 | 2011-07-20 06:30:00 | Rejected transaction&lt;br /&gt;    19 | 2011-07-20 06:15:00 | Canceled  payment&lt;br /&gt;    13 | 2011-07-20 06:15:00 | Canceled transaction&lt;br /&gt;    15 | 2011-07-20 06:15:00 | Canceled transfer&lt;br /&gt;    16 | 2011-07-20 06:15:00 | Payment canceled&lt;br /&gt;    17 | 2011-07-20 06:15:00 | Payment rejected&lt;br /&gt;    24 | 2011-07-20 06:15:00 | Rejected transaction&lt;br /&gt;     2 | 2011-07-20 05:00:00 | Wire transfer # 3240569823405844930&lt;br /&gt;     4 | 2011-07-20 05:00:00 | Wire transfer # 3463453123432454667&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer # 3858994783568734677&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer # 4577867895676542367&lt;br /&gt;     2 | 2011-07-20 05:00:00 | Wire transfer # 5645746324515345353&lt;br /&gt;     2 | 2011-07-20 05:00:00 | Wire transfer # 6754846773457536756&lt;br /&gt;     2 | 2011-07-20 05:00:00 | Wire transfer # 6785675623451222333&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer # 8565696735865742365&lt;br /&gt;     2 | 2011-07-20 05:00:00 | Wire transfer ID 2345578568567567544&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer ID 3265474356547356756&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer ID 3425215345565475468&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer id 3425233214234534634&lt;br /&gt;     5 | 2011-07-20 05:00:00 | Wire transfer ID 3425233214234534634&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer id 3452364365475463425&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer ID 4135146854351231151&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer ID 4353267658545629087&lt;br /&gt;     3 | 2011-07-20 05:00:00 | Wire transfer ID 5468513264769656536&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer id 5473785489567245623&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer ID 5687895416264572398&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer ID 5876978567345176586&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer ID 6768576565423453415&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer id 6857234568657433677&lt;br /&gt;     3 | 2011-07-20 05:00:00 | Wire transfer id 8479764976835672345&lt;br /&gt;     1 | 2011-07-20 05:00:00 | Wire transfer id 8658375686537546544&lt;br /&gt;    41 | 2011-07-20 05:00:00 | Your Wire fund transfer&lt;br /&gt;     1 | 2011-07-20 04:30:00 | Wire transfer ID 6431531354846843122&lt;br /&gt;     1 | 2011-07-19 04:45:00 | Change Confirmation&lt;br /&gt;     1 | 2011-07-19 04:45:00 | Does your company is registered outstanding tax debts&lt;br /&gt;     2 | 2011-07-19 04:45:00 | U.S. Department of the Treasury&lt;br /&gt;     1 | 2011-07-19 04:45:00 | Your IRS payment rejected&lt;br /&gt;     1 | 2011-07-19 04:30:00 | Change Confirmation&lt;br /&gt;     1 | 2011-07-19 04:30:00 | Does your company including  tax debts&lt;br /&gt;     1 | 2011-07-19 04:30:00 | Does your enterprise listed unpaid tax debts&lt;br /&gt;     2 | 2011-07-19 04:30:00 | Federal Tax payment rejected&lt;br /&gt;     1 | 2011-07-19 04:30:00 | For your company including unpaid tax debt&lt;br /&gt;     1 | 2011-07-19 04:30:00 | For your enterprise including  tax debt&lt;br /&gt;    13 | 2011-07-19 04:30:00 | Internal Revenue Service&lt;br /&gt;     4 | 2011-07-19 04:30:00 | Internal Revenue Service (IRS)&lt;br /&gt;     2 | 2011-07-19 04:30:00 | Internal Revenue Service United States Department of the Treasury&lt;br /&gt;     4 | 2011-07-19 04:30:00 | IRC.gov&lt;br /&gt;     5 | 2011-07-19 04:30:00 | IRS.gov US&lt;br /&gt;     8 | 2011-07-19 04:30:00 | Notice of Underreported Income&lt;br /&gt;     6 | 2011-07-19 04:30:00 | Payment IRS.gov&lt;br /&gt;     4 | 2011-07-19 04:30:00 | Support IRS.gov&lt;br /&gt;     5 | 2011-07-19 04:30:00 | Treasury Inspector General for Tax Administration&lt;br /&gt;     1 | 2011-07-19 04:30:00 | U.S. Department of the Treasury&lt;br /&gt;     2 | 2011-07-19 04:30:00 | Your enterprise has remained outstanding tax debts&lt;br /&gt;     3 | 2011-07-19 04:30:00 | Your IRS payment rejected&lt;br /&gt;     1 | 2011-07-19 04:15:00 | Internal Revenue Service&lt;br /&gt;     1 | 2011-07-18 10:30:00 | Love BlackJack? Check out the games at Winner Palace&lt;br /&gt;     1 | 2011-07-16 02:00:00 | Out of Office AutoReply: Please Review&lt;br /&gt;     1 | 2011-07-15 09:00:00 | For your company is registered unpaid tax debt&lt;br /&gt;     1 | 2011-07-15 09:00:00 | Internal Revenue Service&lt;br /&gt;     2 | 2011-07-15 08:45:00 | Change Confirmation&lt;br /&gt;     2 | 2011-07-15 08:45:00 | Federal Tax payment rejected&lt;br /&gt;     2 | 2011-07-15 08:45:00 | Internal Revenue Service&lt;br /&gt;     2 | 2011-07-15 08:45:00 | Internal Revenue Service (IRS)&lt;br /&gt;     4 | 2011-07-15 08:45:00 | Internal Revenue Service United States Department of the Treasury&lt;br /&gt;     3 | 2011-07-15 08:45:00 | IRC.gov&lt;br /&gt;     1 | 2011-07-15 08:45:00 | IRS.gov US&lt;br /&gt;     3 | 2011-07-15 08:45:00 | Payment IRS.gov&lt;br /&gt;     2 | 2011-07-15 08:45:00 | Support IRS.gov&lt;br /&gt;     1 | 2011-07-15 08:45:00 | Treasury Inspector General for Tax Administration&lt;br /&gt;     1 | 2011-07-15 08:45:00 | U.S. Department of the Treasury&lt;br /&gt;     2 | 2011-07-15 08:45:00 | Your IRS payment rejected&lt;br /&gt;     1 | 2011-07-15 07:30:00 | TV murder appeal prompts 40 calls&lt;br /&gt;     1 | 2011-07-14 21:30:00 | US senator requests hacking probe&lt;br /&gt;     1 | 2011-07-14 20:15:00 | Parties unite over BSkyB bid call&lt;br /&gt;     1 | 2011-07-14 19:45:00 | PM Kan urges 'nuclear-free Japan'&lt;br /&gt;     1 | 2011-07-14 18:00:00 | Man tells jury 'I killed Lynette'&lt;br /&gt;     1 | 2011-07-14 15:15:00 | VIDEO: Live: Debate on youth unemployment&lt;br /&gt;     1 | 2011-07-14 07:15:00 | Security update for banking accounts.&lt;br /&gt;    10 | 2011-07-14 07:00:00 | ACH and Wire transfers disabled.&lt;br /&gt;     5 | 2011-07-14 07:00:00 | Banking security update.&lt;br /&gt;     7 | 2011-07-14 07:00:00 | Security update for banking accounts.&lt;br /&gt;     5 | 2011-07-14 07:00:00 | Update for your banking account.&lt;br /&gt;     1 | 2011-07-13 11:30:00 | Hospitals warned over clot deaths&lt;br /&gt;     1 | 2011-07-13 07:45:00 | Does your enterprise listed unpaid tax debt&lt;br /&gt;     3 | 2011-07-13 07:45:00 | Federal Tax payment rejected&lt;br /&gt;     5 | 2011-07-13 07:45:00 | Internal Revenue Service United States Department of the Treasury&lt;br /&gt;     2 | 2011-07-13 07:45:00 | IRC.gov&lt;br /&gt;     7 | 2011-07-13 07:45:00 | Notice of Underreported Income&lt;br /&gt;     1 | 2011-07-13 07:45:00 | Treasury Inspector General for Tax Administration&lt;br /&gt;     2 | 2011-07-13 07:45:00 | U.S. Department of the Treasury&lt;br /&gt;     1 | 2011-07-13 07:45:00 | Your company listed outstanding tax debt&lt;br /&gt;     1 | 2011-07-13 07:45:00 | Your enterprise listed unpaid tax debt&lt;br /&gt;     1 | 2011-07-13 07:30:00 | Internal Revenue Service&lt;br /&gt;     2 | 2011-07-13 07:30:00 | Internal Revenue Service (IRS)&lt;br /&gt;     2 | 2011-07-13 07:30:00 | Internal Revenue Service United States Department of the Treasury&lt;br /&gt;     1 | 2011-07-13 07:30:00 | Notice of Underreported Income&lt;br /&gt;     3 | 2011-07-13 07:30:00 | Payment IRS.gov&lt;br /&gt;     1 | 2011-07-13 07:30:00 | Support IRS.gov&lt;br /&gt;     2 | 2011-07-13 07:30:00 | U.S. Department of the Treasury&lt;br /&gt;     2 | 2011-07-13 07:30:00 | Your IRS payment rejected&lt;br /&gt;     3 | 2011-07-13 05:45:00 | Business accounts updates&lt;br /&gt;     1 | 2011-07-13 05:45:00 | Dear corporate clients&lt;br /&gt;     1 | 2011-07-13 05:45:00 | New settings for wire transfers&lt;br /&gt;     1 | 2011-07-13 05:30:00 | Business accounts updates&lt;br /&gt;     5 | 2011-07-13 05:30:00 | Corporate banking security&lt;br /&gt;     3 | 2011-07-13 05:30:00 | Dear corporate clients&lt;br /&gt;    10 | 2011-07-13 05:30:00 | Federalreserve security update&lt;br /&gt;     4 | 2011-07-13 05:30:00 | New security settings&lt;br /&gt;     4 | 2011-07-13 05:30:00 | New security update&lt;br /&gt;     5 | 2011-07-13 05:30:00 | New settings for wire transfers&lt;br /&gt;     2 | 2011-07-13 05:30:00 | Wire transfers update&lt;/PRE&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We can also ask it to tell us what spammed destinations were being described by those messages and learn that what we see is:&lt;br /&gt;&lt;br /&gt;July 13th = usbanking-security.com&lt;br /&gt;July 15th = federalsecusrity.com&lt;br /&gt;July 19th = taxreport-irs.com&lt;br /&gt;July 19th = irs-taxes-report.com&lt;br /&gt;July 19th = irs-report-link.com&lt;br /&gt;July 20th = www.federalreserve.gov&lt;br /&gt;July 20th = reports-federalreserve.com&lt;br /&gt;July 20th = nacha-alert.org&lt;br /&gt;July 20th = nacha-alert.com&lt;br /&gt;July 20th = alerts-federalresrve.com&lt;br /&gt;July 21st = national-security-agency.com&lt;br /&gt;July 21st = federal-secueity-government.com&lt;br /&gt;July 22nd = irs-downloads.com&lt;br /&gt;July 22nd = irs-files.com&lt;br /&gt;July 26th = taxes-irs.net&lt;br /&gt;July 27th = www.nacha-rejected.com&lt;br /&gt;July 27th = taxes-refund.com&lt;br /&gt;July 28th = fdic-updates.com&lt;br /&gt;&lt;br /&gt;Again, the query run says "look at my spam history FOR THE IP ADDRESSES USED BY THE GOV-RELATED ZEUS DOMAIN THIS MORNING and see what else they've sent me previously."&lt;br /&gt;&lt;br /&gt;I've temporarily included only those links that were DIRECTLY linking to an executable, but we also have all of the "domain-shortener" spam that was sent on July 13th pretending to be a LinkedIn message.  In that case, the spam used 25 different shortener services, most of which seem to have been created specifically for that purpose:&lt;br /&gt;&lt;br /&gt;  1tja.com&lt;br /&gt;  4h.biz&lt;br /&gt;  4nu.net&lt;br /&gt;  coge.la&lt;br /&gt;  d3c.co&lt;br /&gt;  flyfrm.com&lt;br /&gt;  gli.im&lt;br /&gt;  gsfn.info&lt;br /&gt;  hi2.com&lt;br /&gt;  ion.so&lt;br /&gt;  ks.gs&lt;br /&gt;  lawurl.com&lt;br /&gt;  lllll.im&lt;br /&gt;  niy.me&lt;br /&gt;  nznet.info&lt;br /&gt;  sendtourl.com&lt;br /&gt;  shoor.tk&lt;br /&gt;  smlurl.info&lt;br /&gt;  sra.li&lt;br /&gt;  tiny.tw&lt;br /&gt;  vs0.net&lt;br /&gt;  widg.me&lt;br /&gt;  wurl.ca&lt;br /&gt;  yi.pe&lt;br /&gt;  zolp.net&lt;br /&gt;&lt;br /&gt;And yes, we can also tie today's spamming botnet to all of those fake LinkedIn spam messages that distributed Zeus on July 13th.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-3215250803843289127?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/3215250803843289127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/3215250803843289127'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/07/government-related-zeus-spam-continues.html' title='&quot;Government-related&quot; Zeus spam continues'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-6322063660934591377</id><published>2011-07-27T09:01:00.000-07:00</published><updated>2011-07-31T23:00:15.790-07:00</updated><title type='text'>"Wrong Transaction" Hotel Spam</title><content type='html'>(Updated information available here: &lt;a href="http://garwarner.blogspot.com/2011/07/wrong-transaction-hotel-spam-malware.html"&gt;Wrong Transaction Hotel Spam Continues to Evolve&lt;/A&gt;.)&lt;br /&gt;&lt;br /&gt;One of the features in the new version of the UAB Spam Data Mine is the ability to quickly run "malware links" and "malware attachments" reports for the current day, the previous day, or a date range.&lt;br /&gt;&lt;br /&gt;The objective of this functionality is to provide as close to "real time" intelligence on potential new email-based threats as possible.  You'll see what I mean below.&lt;br /&gt;&lt;br /&gt;I've been playing with it for the past several days, but just so you can join in the fun, let me show you the top results that come back when I do:&lt;br /&gt;&lt;br /&gt;\i malware.attachments.sql  &lt;TABLE BORDER="2"&gt;&lt;TR&gt;&lt;TD&gt;Spam Count&lt;/TD&gt;&lt;TD&gt;Attached MD5&lt;/TD&gt;&lt;TD&gt;Extension&lt;/TD&gt;&lt;TD&gt;Subject&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Renaissance Chicago made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Hyatt Regency Houston made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;br /&gt;&lt;TR&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Jefferson made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Renaissance Washington made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Sheraton Suites San Diego at Symphony Hall made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel The Westin Oaks made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Westin Diplomat Resort &amp; Spa made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Westin St. Francis made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Hilton Las Vegas made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;br /&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Intercontinental Buckhead Atlanta made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Rancho Bernardo Inn made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Ritz Carlton Kapalua made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Ritz-Carlton Marina Del Rey made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel The Latham made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel The Westin New York at Times Square made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Wrong transaction from your credit card in Ritz Carlton Naples Beach Resort &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel Four Seasons Resort Maui at Wailea made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Hotel The Whitehall made wrong transaction &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Wrong transaction from your credit card in Loews Miami Beach &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt; c15eb3c47800fec025b6a86a6409f144 &lt;/TD&gt;&lt;TD&gt; zip&lt;/TD&gt;&lt;TD&gt; Wrong transaction from your credit card in Woodrun V Townhomes &lt;/TD&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;br /&gt;&lt;br /&gt;Since we've never seen spam like this before, it's "new" and potentially interesting!&lt;br /&gt;&lt;br /&gt;One quick check of whether this is "interesting" is what happens when we ask forty-three different Anti-virus vendors whether the attached file is a virus or not.&lt;br /&gt;&lt;br /&gt;We do this by using the services of VirusTotal.com who gave us back this report: &lt;a href="http://www.virustotal.com/file-scan/report.html?id=45e144eddd021c08584f5d01b1645a128d52cf916b25ee0a1897421fad1328a7-1311765513"&gt;VirusTotal Report for c15eb3c47800fec025b6a86a6409f144&lt;/A&gt;.  At the time of this writing, having already received more than 800 copies of the spam, Sophos and Trend Micro call it "BredoLab", Rising AV of China calls it "suspicious", and NOD32 says it's a "Kryptik" variant.  The other thirty-nine AV companies currently don't have published definitions for this malware.&lt;br /&gt;&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;&lt;B&gt;UPDATE&lt;/B&gt;:  As of 12:36 PM Central Time on July 27th, we are now up to 12 of 43 detects.  See the &lt;a href="http://www.virustotal.com/file-scan/report.html?id=45e144eddd021c08584f5d01b1645a128d52cf916b25ee0a1897421fad1328a7-1311786748"&gt;Update VirusTotal Report Here&lt;/A&gt;.  Curiously, just yesterday someone asked me, do you ever see AV vendors change their mind on what something should be called?  You'll note that on the first report, Sophos called this Bredolab, but now they are calling it Zbot.  It will be curious to see how that rolls out, since no one else among the 12 detectors believes this to be Zeus (aka Zbot).&lt;br /&gt;&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The spam messages look like this:&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/hotel.transaction.jpg"&gt;&lt;br /&gt;&lt;br /&gt;We've already seen more than 400 different subjects that are part of this group!&lt;br /&gt;&lt;br /&gt;     7 | Hotel Courtyard by Marriott Houston Downtown  made wrong transaction&lt;br /&gt;     6 | Hotel Ritz-Carlton Marina Del Rey  made wrong transaction&lt;br /&gt;     6 | Hotel Hilton Las Vegas  made wrong transaction&lt;br /&gt;     6 | Hotel Renaissance Chicago  made wrong transaction&lt;br /&gt;     6 | Hotel Westin Diplomat Resort &amp; Spa  made wrong transaction&lt;br /&gt;     5 | Wrong transaction from your credit card in Icon&lt;br /&gt;     5 | Wrong transaction from your credit card in Ritz Carlton Naples Beach Resort&lt;br /&gt;     5 | Hotel The Westin Oaks  made wrong transaction&lt;br /&gt;     5 | Hotel Sheraton Suites San Diego at Symphony Hall  made wrong transaction&lt;br /&gt;     5 | Hotel Renaissance Washington  made wrong transaction&lt;br /&gt;     5 | Hotel Jefferson  made wrong transaction&lt;br /&gt;     5 | Hotel Westin St. Francis  made wrong transaction&lt;br /&gt;     5 | Hotel Rancho Bernardo Inn  made wrong transaction&lt;br /&gt;     5 | Hotel Intercontinental Buckhead Atlanta  made wrong transaction&lt;br /&gt;     5 | Hotel Hyatt Regency Houston  made wrong transaction&lt;br /&gt;&lt;br /&gt;(The complete list concludes at the bottom of this post . . . )&lt;br /&gt;&lt;br /&gt;One of the other great things we can do with the UAB Spam Data Mine though, is to ask "what other things are being sent by the computers that sent us this spam?"&lt;br /&gt;&lt;br /&gt;Look what happens when I ask "show me the top subjects from YESTERDAY that were spammed by IP addresses that spammed the hotel spam TODAY?"&lt;br /&gt;&lt;br /&gt;    62 | 2011-07-26     | Credit Card is one week overdue&lt;br /&gt;    51 | 2011-07-26     | Credit Card overdue&lt;br /&gt;    43 | 2011-07-26     | Your Credit Card is one week overdue&lt;br /&gt;    39 | 2011-07-26     | Payment by credit card overdue&lt;br /&gt;    39 | 2011-07-26     | Credit card payment of overstayed&lt;br /&gt;    25 | 2011-07-26     | Your financial debt overdue&lt;br /&gt;     6 | 2011-07-26     | Re: Re: hi bud&lt;br /&gt;     5 | 2011-07-26     | Get your first bonus just for registering.&lt;br /&gt;     4 | 2011-07-26     | We offer only top grade Replica watches at only a fraction of the original price,&lt;br /&gt;     4 | 2011-07-26     | Chase bonuses no more; register at Winner Palacce.&lt;br /&gt;     4 | 2011-07-26     | Seeking gaming glory? Sign up and get free bonus.&lt;br /&gt;     3 | 2011-07-26     | A dream come true sign up bonus at Winner Palacce.&lt;br /&gt;     3 | 2011-07-26     | Gaming glory beckons, register and get free bonus.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The top group - the most prominent in response to this query - was the "MasterCard" version of the Fake AV malware that we blogged about previously on July 23rd -- &lt;a href="http://garwarner.blogspot.com/2011/07/mastercard-spam-leads-to-fake-av.html"&gt;MasterCard Spam Leads to Fake AV&lt;/A&gt;.  SC Magazine's Angelina Moscaritolo wrote that up under the headline "&lt;a href="http://www.scmagazineus.com/rogue-av-masquerading-as-sc-awards-2011-finalist/article/208318/"&gt;Rogue AV Masquerading as SC Awards 2011 Finalist&lt;/A&gt;.  The same spamming botnet has been sending out Casino spam and Rolex watch spam for more than a month.  &lt;br /&gt;&lt;br /&gt;We had 120 different subjects from this small IP sample group yesterday -- many of the subjects are "customized" such as "gar@place.com Rolex.com For You - 77%" or "gar@otherplace.com Rolex.com For You - 55%"&lt;br /&gt;&lt;br /&gt;So, what do we predict the Hotel Spam will turn out to be?  There is a good chance it will be related to the MasterCard Fake AV Spam.  Well . . . one way to find out, right?&lt;br /&gt;&lt;br /&gt;The .zip file contained this file:&lt;br /&gt;&lt;br /&gt;&lt;IMG src = "http://www.cis.uab.edu/forensics/blog/hotelspam.start.jpg"&gt;&lt;br /&gt;&lt;br /&gt;When we launched the malware, it made connection to the webserver at "yomwarayom2001.ru" on IP address 84.247.61.25.  &lt;br /&gt;&lt;br /&gt;The first link we hit there was an exploit server -- probably the "BlackHole Exploit Kit" that has been very popular recently on similarly structured web pages.  We almost immediately ALSO fetched a file called "forum3/load.php?module=grabbers".&lt;br /&gt;&lt;br /&gt;This caused us to download a file "soft.exe" from yomwarayom2001.ru.&lt;br /&gt;&lt;br /&gt;In a couple minutes, a pop-up announced "Software Installed" and had an "OK" button.  Clicking OK caused a connection to "heftyhips.com" on IP 66.197.251.53.&lt;br /&gt;&lt;br /&gt;where the file "images/img.php?id=106" was fetched.&lt;br /&gt;&lt;br /&gt;Shortly thereafter we had a "Defender" icon on the desktop, which was this file:&lt;br /&gt;&lt;br /&gt;&lt;IMG src = "http://www.cis.uab.edu/forensics/blog/hotelspam.fakeav.jpg"&gt;&lt;br /&gt;&lt;br /&gt;Note that "Defender" claims to be written by AVG Software Development, a real antivirus company!&lt;br /&gt;&lt;br /&gt;That was enough to convince me we were still in "Fake AV" territory.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;The rest of the hotel spam subject list &lt;/H3&gt;&lt;br /&gt;&lt;br /&gt; Hotel Acqualina Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Ahwahnee  made wrong transaction&lt;br /&gt; Hotel Amsterdam Hospitality  made wrong transaction&lt;br /&gt; Hotel Anglers  made wrong transaction&lt;br /&gt; Hotel Argonaut  made wrong transaction&lt;br /&gt; Hotel Aria  made wrong transaction&lt;br /&gt; Hotel Arizona Biltmore  made wrong transaction&lt;br /&gt; Hotel Arrabelle at Vail Square  made wrong transaction&lt;br /&gt; Hotel Avalon  made wrong transaction&lt;br /&gt; Hotel Bellagio  and Casino  made wrong transaction&lt;br /&gt; Hotel Beverly Hills  &amp; Bungalows  made wrong transaction&lt;br /&gt; Hotel Beverly Wilshire, A Four Seasons   made wrong transaction&lt;br /&gt; Hotel Biltmore  made wrong transaction&lt;br /&gt; Hotel Boston Harbor   made wrong transaction&lt;br /&gt; Hotel Boston Marriott Copley Place  made wrong transaction&lt;br /&gt; Hotel Breakers Palm Beach  made wrong transaction&lt;br /&gt; Hotel Breakwater  made wrong transaction&lt;br /&gt; Hotel Camelback Inn, A JW Marriott Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Campton Place  made wrong transaction&lt;br /&gt; Hotel Carlton on Madison Avenue  made wrong transaction&lt;br /&gt; Hotel Casa Del Mar  made wrong transaction&lt;br /&gt; Hotel Chamonix  made wrong transaction&lt;br /&gt; Hotel Charleston Marriott  made wrong transaction&lt;br /&gt; Hotel Charleston Place  made wrong transaction&lt;br /&gt; Hotel Conrad Chicago  made wrong transaction&lt;br /&gt; Hotel Conrad Miami  made wrong transaction&lt;br /&gt; Hotel Courtyard by Marriott Capitol Hill/Navy Yard  made wrong transaction&lt;br /&gt; Hotel Courtyard by Marriott Houston Downtown  made wrong transaction&lt;br /&gt; Hotel Courtyard Washington Convention Center  made wrong transaction&lt;br /&gt; Hotel Crowne Plaza The Hamilton  made wrong transaction&lt;br /&gt; Hotel Delano  made wrong transaction&lt;br /&gt; Hotel Del Coronado  made wrong transaction&lt;br /&gt; Hotel Disney's Grand Californian  made wrong transaction&lt;br /&gt; Hotel Disney's Grand Floridian  made wrong transaction&lt;br /&gt; Hotel Disney's Polynesian Resort  made wrong transaction&lt;br /&gt; Hotel Doubletree by Hilton Orlando at SeaWorld  made wrong transaction&lt;br /&gt; Hotel Dunton Hot Springs  made wrong transaction&lt;br /&gt; Hotel Embassy Suites Chevy Chase Pavilion  made wrong transaction&lt;br /&gt; Hotel Embassy Suites - Convention Center  made wrong transaction&lt;br /&gt; Hotel Embassy Suites  made wrong transaction&lt;br /&gt; Hotel Embassy Suites North Charleston  made wrong transaction&lt;br /&gt; Hotel Embassy Suites Washington  made wrong transaction&lt;br /&gt; Hotel Enchantment Resort  made wrong transaction&lt;br /&gt; Hotel Encore at Wynn  made wrong transaction&lt;br /&gt; Hotel Fairmont Chicago  made wrong transaction&lt;br /&gt; Hotel Fairmont Heritage Place Ghiradelli Square  made wrong transaction&lt;br /&gt; Hotel Fairmont Kea Lani  made wrong transaction&lt;br /&gt; Hotel Fairmont Miramar   made wrong transaction&lt;br /&gt; Hotel Fairmont Scottsdale  made wrong transaction&lt;br /&gt; Hotel Fairmont  &amp; Towers  made wrong transaction&lt;br /&gt; Hotel Florida Choice Executive Pool Homes  made wrong transaction&lt;br /&gt; Hotel Four Seasons  Los Angeles at Beverly Hills  made wrong transaction&lt;br /&gt; Hotel Four Seasons  made wrong transaction&lt;br /&gt; Hotel Four Seasons Resort Lanai at Manele Bay  made wrong transaction&lt;br /&gt; Hotel Four Seasons Resort Maui at Wailea  made wrong transaction&lt;br /&gt; Hotel Four Seasons Resort Palm Beach  made wrong transaction&lt;br /&gt; Hotel Four Seasons Resort Scottsdale  made wrong transaction&lt;br /&gt; Hotel Four Seasons San Francisco  made wrong transaction&lt;br /&gt; Hotel Gansevoort South  made wrong transaction&lt;br /&gt; Hotel George  made wrong transaction&lt;br /&gt; Hotel Gramercy Park  made wrong transaction&lt;br /&gt; Hotel Grand Bohemian  made wrong transaction&lt;br /&gt; Hotel Grand Hyatt Atlanta in Buckhead  made wrong transaction&lt;br /&gt; Hotel Grand Hyatt Kauai Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Grand Hyatt New York  made wrong transaction&lt;br /&gt; Hotel Grand Hyatt San Francisco  made wrong transaction&lt;br /&gt; Hotel Grand Hyatt Seattle  made wrong transaction&lt;br /&gt; Hotel Grand Hyatt Washington  made wrong transaction&lt;br /&gt; Hotel Granduca  made wrong transaction&lt;br /&gt; Hotel Grand Wailea Resort  made wrong transaction&lt;br /&gt; Hotel Halekulani  made wrong transaction&lt;br /&gt; Hotel Hampton Inn Washington - Convention Center  made wrong transaction&lt;br /&gt; Hotel Helix Boutique  made wrong transaction&lt;br /&gt; Hotel Hilton Americas Houston  made wrong transaction&lt;br /&gt; Hotel Hilton Atlanta Airport  made wrong transaction&lt;br /&gt; Hotel Hilton Atlanta  made wrong transaction&lt;br /&gt; Hotel Hilton Boston Logan Airport  made wrong transaction&lt;br /&gt; Hotel Hilton Chicago  made wrong transaction&lt;br /&gt; Hotel Hilton Garden Inn Washington DC Franklin Square  made wrong transaction&lt;br /&gt; Hotel Hilton Grand Vacations Club  made wrong transaction&lt;br /&gt; Hotel Hilton Hawaiian Village  made wrong transaction&lt;br /&gt; Hotel Hilton Houston Plaza   made wrong transaction&lt;br /&gt; Hotel Hilton Houston Westchase  made wrong transaction&lt;br /&gt; Hotel Hilton Las Vegas  made wrong transaction&lt;br /&gt; Hotel Hilton Orlando Bonnet Creek  made wrong transaction&lt;br /&gt; Hotel Hilton Washington Embassy Row  made wrong transaction&lt;br /&gt; Hotel Hilton Washington  made wrong transaction&lt;br /&gt; Hotel Holiday Inn Port of Miami Downtown  made wrong transaction&lt;br /&gt; Hotel Homewood Suites  made wrong transaction&lt;br /&gt; Hotel Hyatt Grand Aspen  made wrong transaction&lt;br /&gt; Hotel Hyatt Regency Atlanta  made wrong transaction&lt;br /&gt; Hotel Hyatt Regency Grand Cypress  made wrong transaction&lt;br /&gt; Hotel Hyatt Regency Houston  made wrong transaction&lt;br /&gt; Hotel Hyatt Regency Huntington Beach  made wrong transaction&lt;br /&gt; Hotel Hyatt Regency Maui Resort and Spa  made wrong transaction&lt;br /&gt; Hotel Hyatt Regency San Francisco  made wrong transaction&lt;br /&gt; Hotel Hyatt Regency Scottsdale Resort  made wrong transaction&lt;br /&gt; Hotel Hyatt Regency Waikiki  made wrong transaction&lt;br /&gt; Hotel Hyatt Regency Washington  made wrong transaction&lt;br /&gt; Hotel Icon   made wrong transaction&lt;br /&gt; Hotel Indian Creek  made wrong transaction&lt;br /&gt; Hotel Inn at Perry Cabin  made wrong transaction&lt;br /&gt; Hotel Inn at the Ballpark  made wrong transaction&lt;br /&gt; Hotel Intercontinental Buckhead Atlanta  made wrong transaction&lt;br /&gt; Hotel InterContinental Chicago  made wrong transaction&lt;br /&gt; Hotel InterContinental  made wrong transaction&lt;br /&gt; Hotel Intercontinental San Francisco  made wrong transaction&lt;br /&gt; Hotel InterContinental The Barclay New York  made wrong transaction&lt;br /&gt; Hotel Jefferson  made wrong transaction&lt;br /&gt; Hotel Jerome  made wrong transaction&lt;br /&gt; Hotel Jumeirah Essex House  made wrong transaction&lt;br /&gt; Hotel JW Marriott  Buckhead Atlanta  made wrong transaction&lt;br /&gt; Hotel JW Marriott Desert Ridge Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel JW Marriott Las Vegas Resort, Spa &amp; Golf  made wrong transaction&lt;br /&gt; Hotel JW Marriott  Miami  made wrong transaction&lt;br /&gt; Hotel JW Marriott Orlando Grande Lakes  made wrong transaction&lt;br /&gt; Hotel JW Marriott  Pennsylvania Avenue  made wrong transaction&lt;br /&gt; Hotel JW Marriott San Francisco  made wrong transaction&lt;br /&gt; Hotel Kahala Resort  made wrong transaction&lt;br /&gt; Hotel Keswick Hall  made wrong transaction&lt;br /&gt; Hotel La Costa Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Lauberge Del Mar  made wrong transaction&lt;br /&gt; Hotel La Valencia  made wrong transaction&lt;br /&gt; Hotel Le Meridien San Francisco  made wrong transaction&lt;br /&gt; Hotel Le Parker Meridien  made wrong transaction&lt;br /&gt; Hotel Lodge At Koele  made wrong transaction&lt;br /&gt; Hotel Lodge At Torrey Pines  made wrong transaction&lt;br /&gt; Hotel Loews Coronado Bay Resort  made wrong transaction&lt;br /&gt; Hotel Loews  Miami Beach  made wrong transaction&lt;br /&gt; Hotel Loews Regency  made wrong transaction&lt;br /&gt; Hotel Loews Santa Monica Beach  made wrong transaction&lt;br /&gt; Hotel London West Hollywood  made wrong transaction&lt;br /&gt; Hotel Lowell  made wrong transaction&lt;br /&gt; Hotel Madera  made wrong transaction&lt;br /&gt; Hotel Madison  made wrong transaction&lt;br /&gt; Hotel Main Street Station  &amp; Casino  made wrong transaction&lt;br /&gt; Hotel Mandalay Bay  made wrong transaction&lt;br /&gt; Hotel Mandarin Oriental  made wrong transaction&lt;br /&gt; Hotel Mandarin Oriental Miami  made wrong transaction&lt;br /&gt; Hotel Marriott at Metro Center  made wrong transaction&lt;br /&gt; Hotel Marriott Chicago Downtown Magnificent Mile  made wrong transaction&lt;br /&gt; Hotel Marriott Houston Airport at George Bush Intercontinental  made wrong transaction&lt;br /&gt; Hotel Marriott Marquis San Francisco  made wrong transaction&lt;br /&gt; Hotel Marriott Resort  made wrong transaction&lt;br /&gt; Hotel Marriott San Francisco Fisherman's Wharf  made wrong transaction&lt;br /&gt; Hotel Mauna Kea Beach  made wrong transaction&lt;br /&gt; Hotel Mauna Lani Bay  &amp; Bungalows  made wrong transaction&lt;br /&gt; Hotel McCoy Peak Lodge  made wrong transaction&lt;br /&gt; Hotel Melrose  made wrong transaction&lt;br /&gt; Hotel Meridian Luxury Suites  made wrong transaction&lt;br /&gt; Hotel Michelangelo  made wrong transaction&lt;br /&gt; Hotel Millennium UN Plaza  made wrong transaction&lt;br /&gt; Hotel Monaco Boutique  made wrong transaction&lt;br /&gt; Hotel Monaco Washington DC  made wrong transaction&lt;br /&gt; Hotel Mona Lisa Suite  made wrong transaction&lt;br /&gt; Hotel Mondrian  made wrong transaction&lt;br /&gt; Hotel Mondrian Scottsdale  made wrong transaction&lt;br /&gt; Hotel Mondrian South Beach  made wrong transaction&lt;br /&gt; Hotel Morenas Resort Morrison-Clark Historic Inn  made wrong transaction&lt;br /&gt; Hotel M Resort Spa &amp; Casino  made wrong transaction&lt;br /&gt; Hotel New York Marriott Marquis  made wrong transaction&lt;br /&gt; Hotel Nolitan  made wrong transaction&lt;br /&gt; Hotel Oak Plantation Resort  made wrong transaction&lt;br /&gt; Hotel Ocean Key Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Ocean Point Resort &amp; Club  made wrong transaction&lt;br /&gt; Hotel Omni Berkshire Place  made wrong transaction&lt;br /&gt; Hotel Omni Chicago  made wrong transaction&lt;br /&gt; Hotel Omni Houston  made wrong transaction&lt;br /&gt; Hotel Omni  made wrong transaction&lt;br /&gt; Hotel One Bal Harbour Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Owl Creek Homes  made wrong transaction&lt;br /&gt; Hotel Palms Place  &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Palomar Boutique  made wrong transaction&lt;br /&gt; Hotel Palomar  made wrong transaction&lt;br /&gt; Hotel Park Hyatt Chicago  made wrong transaction&lt;br /&gt; Hotel Park Hyatt  made wrong transaction&lt;br /&gt; Hotel Park Hyatt Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Peabody Orlando  made wrong transaction&lt;br /&gt; Hotel Peninsula New York  made wrong transaction&lt;br /&gt; Hotel Phoenician  made wrong transaction&lt;br /&gt; Hotel Pierre A Taj  made wrong transaction&lt;br /&gt; Hotel Plaza Athenee  made wrong transaction&lt;br /&gt; Hotel Pocono Palace  made wrong transaction&lt;br /&gt; Hotel Prescott  made wrong transaction&lt;br /&gt; Hotel Raffles L'Ermitage Beverly Hills  made wrong transaction&lt;br /&gt; Hotel Rancho Bernardo Inn  made wrong transaction&lt;br /&gt; Hotel Rancho Las Palmas Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Red Rock Casino Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Renaissance Charleston  Historic District  made wrong transaction&lt;br /&gt; Hotel Renaissance Chicago  made wrong transaction&lt;br /&gt; Hotel Renaissance Houston  Greenway Plaza  made wrong transaction&lt;br /&gt; Hotel Renaissance New York  Times Square  made wrong transaction&lt;br /&gt; Hotel Renaissance Washington  made wrong transaction&lt;br /&gt; Hotel Renaissance Waverly  made wrong transaction&lt;br /&gt; Hotel Residence Inn by Marriott Capitol  made wrong transaction&lt;br /&gt; Hotel Rio Suite  and Casino  made wrong transaction&lt;br /&gt; Hotel Ritz-Carlton Battery Park  made wrong transaction&lt;br /&gt; Hotel Ritz-Carlton Boston Common  made wrong transaction&lt;br /&gt; Hotel Ritz-Carlton Central Park  made wrong transaction&lt;br /&gt; Hotel Ritz-Carlton Golf Resort  made wrong transaction&lt;br /&gt; Hotel Ritz Carlton Kapalua  made wrong transaction&lt;br /&gt; Hotel Ritz Carlton Key Biscayne  made wrong transaction&lt;br /&gt; Hotel Ritz-Carlton Laguna Niguel  made wrong transaction&lt;br /&gt; Hotel Ritz-Carlton  made wrong transaction&lt;br /&gt; Hotel Ritz-Carlton Marina Del Rey  made wrong transaction&lt;br /&gt; Hotel Ritz Carlton Naples Beach Resort  made wrong transaction&lt;br /&gt; Hotel Ritz Carlton Naples Golf Resort  made wrong transaction&lt;br /&gt; Hotel Ritz-Carlton Orlando, Grande Lakes Resort  made wrong transaction&lt;br /&gt; Hotel Ritz-Carlton Palm Beach  made wrong transaction&lt;br /&gt; Hotel Ritz-Carlton San Francisco  made wrong transaction&lt;br /&gt; Hotel Ritz Carlton South Beach  made wrong transaction&lt;br /&gt; Hotel Rouge  made wrong transaction&lt;br /&gt; Hotel Royal Hawaiian  made wrong transaction&lt;br /&gt; Hotel Royal Pacific Resort  made wrong transaction&lt;br /&gt; Hotel Royal Palms Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Sanctuary on Camelback Mountain  made wrong transaction&lt;br /&gt; Hotel Seattle Marriott Waterfront  made wrong transaction&lt;br /&gt; Hotel Se San Diego  made wrong transaction&lt;br /&gt; Hotel Shangri-La  made wrong transaction&lt;br /&gt; Hotel Sheraton Bal Harbour Beach Resort  made wrong transaction&lt;br /&gt; Hotel Sheraton Chicago  and Towers  made wrong transaction&lt;br /&gt; Hotel Sheraton Keauhou Bay Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Sheraton Maui Resort  made wrong transaction&lt;br /&gt; Hotel Sheraton Moana Surfrider  made wrong transaction&lt;br /&gt; Hotel Sheraton Suites Houston Near The Galleria  made wrong transaction&lt;br /&gt; Hotel Sheraton Suites San Diego at Symphony Hall  made wrong transaction&lt;br /&gt; Hotel Sheraton Waikiki  made wrong transaction&lt;br /&gt; Hotel Shore Club  made wrong transaction&lt;br /&gt; Hotel Shutters Beach  made wrong transaction&lt;br /&gt; Hotel Signature at MGM Grand  made wrong transaction&lt;br /&gt; Hotel Skylofts at MGM Grand  made wrong transaction&lt;br /&gt; Hotel SLS  at Beverly Hills  made wrong transaction&lt;br /&gt; Hotel Sofitel Lafayette Square  made wrong transaction&lt;br /&gt; Hotel Sonesta  Orlando Downtown  made wrong transaction&lt;br /&gt; Hotel Sorrento  made wrong transaction&lt;br /&gt; Hotel South Beach Marriott  made wrong transaction&lt;br /&gt; Hotel Star The Michelangelo  made wrong transaction&lt;br /&gt; Hotel St. Gregory Luxury  &amp; Suites  made wrong transaction&lt;br /&gt; Hotel St. Regis  made wrong transaction&lt;br /&gt; Hotel St. Regis Princeville Resort  made wrong transaction&lt;br /&gt; Hotel St. Regis Washington  made wrong transaction&lt;br /&gt; Hotel Sun Harbour Boutique  made wrong transaction&lt;br /&gt; Hotel Sutton Place  made wrong transaction&lt;br /&gt; Hotel Swissotel Chicago  made wrong transaction&lt;br /&gt; Hotel Taj Boston  made wrong transaction&lt;br /&gt; Hotel Taj Campton Place  made wrong transaction&lt;br /&gt; Hotel Tamarack by Destination Resorts Snowmass  made wrong transaction&lt;br /&gt; Hotel The Alexander  made wrong transaction&lt;br /&gt; Hotel The Alex  made wrong transaction&lt;br /&gt; Hotel The Carlyle, A Rosewood   made wrong transaction&lt;br /&gt; Hotel The Carlyle Suites  made wrong transaction&lt;br /&gt; Hotel The Chatwal  made wrong transaction&lt;br /&gt; Hotel The Cosmopolitan Las Vegas  made wrong transaction&lt;br /&gt; Hotel The Drake  made wrong transaction&lt;br /&gt; Hotel The Enclave  made wrong transaction&lt;br /&gt; Hotel The Equinox Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel The Fairmont Copley Plaza  made wrong transaction&lt;br /&gt; Hotel The Fairmont  made wrong transaction&lt;br /&gt; Hotel The Fairmont Olympic  made wrong transaction&lt;br /&gt; Hotel The Fairmont Orchid  made wrong transaction&lt;br /&gt; Hotel The Fairmont Washington  made wrong transaction&lt;br /&gt; Hotel The Hay-Adams  made wrong transaction&lt;br /&gt; Hotel The Helmsley Carlton House  made wrong transaction&lt;br /&gt; Hotel The Henley Park  made wrong transaction&lt;br /&gt; Hotel The Houstonian  Club &amp; Spa  made wrong transaction&lt;br /&gt; Hotel The Huntington and Nob Hill Spa  made wrong transaction&lt;br /&gt; Hotel The Iroquois  made wrong transaction&lt;br /&gt; Hotel The Langham Huntington  &amp; SPA  made wrong transaction&lt;br /&gt; Hotel The Latham  made wrong transaction&lt;br /&gt; Hotel The Lenox   made wrong transaction&lt;br /&gt; Hotel The Little Nell  made wrong transaction&lt;br /&gt; Hotel The Lucerne  made wrong transaction&lt;br /&gt; Hotel The New York Helmsley  made wrong transaction&lt;br /&gt; Hotel The Orchard  made wrong transaction&lt;br /&gt; Hotel The Palmer House Hilton  made wrong transaction&lt;br /&gt; Hotel The Peninsula Beverly Hills  made wrong transaction&lt;br /&gt; Hotel The Peninsula  made wrong transaction&lt;br /&gt; Hotel The Phoenician  made wrong transaction&lt;br /&gt; Hotel The Pierre  made wrong transaction&lt;br /&gt; Hotel The Plaza  made wrong transaction&lt;br /&gt; Hotel The Quincy  made wrong transaction&lt;br /&gt; Hotel The Ritz-Carlton Bachelor Gulch  made wrong transaction&lt;br /&gt; Hotel The Ritz-Carlton Buckhead  made wrong transaction&lt;br /&gt; Hotel The Ritz-Carlton Fort Lauderdale   made wrong transaction&lt;br /&gt; Hotel The Ritz-Carlton Georgetown  made wrong transaction&lt;br /&gt; Hotel The Ritz-Carlton Laguna Niguel   made wrong transaction&lt;br /&gt; Hotel The Ritz Carlton  made wrong transaction&lt;br /&gt; Hotel The Ritz-Carlton Orlando, Grande Lakes  made wrong transaction&lt;br /&gt; Hotel The Setai Fifth Avenue  made wrong transaction&lt;br /&gt; Hotel The Setai  made wrong transaction&lt;br /&gt; Hotel The St. Regis Aspen  made wrong transaction&lt;br /&gt; Hotel The St. Regis Monarch Beach  made wrong transaction&lt;br /&gt; Hotel The Venetian Resort  and Casino  made wrong transaction&lt;br /&gt; Hotel The Villa By Barton G  made wrong transaction&lt;br /&gt; Hotel The Washington Court On Capital Hil  made wrong transaction&lt;br /&gt; Hotel The Westin Atlanta Airport  made wrong transaction&lt;br /&gt; Hotel The Westin Chicago River North  made wrong transaction&lt;br /&gt; Hotel The Westin Embassy Row  made wrong transaction&lt;br /&gt; Hotel The Westin Grand  made wrong transaction&lt;br /&gt; Hotel The Westin Michigan Avenue  made wrong transaction&lt;br /&gt; Hotel The Westin Mission Hills Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel The Westin New York at Times Square  made wrong transaction&lt;br /&gt; Hotel The Westin Oaks  made wrong transaction&lt;br /&gt; Hotel The Westin Peachtree Plaza  made wrong transaction&lt;br /&gt; Hotel The Westin Seattle  made wrong transaction&lt;br /&gt; Hotel The Whitehall  made wrong transaction&lt;br /&gt; Hotel The Wit-A Doubletree  made wrong transaction&lt;br /&gt; Hotel Tides South Beach  made wrong transaction&lt;br /&gt; Hotel Topaz  made wrong transaction&lt;br /&gt; Hotel Trump International Sonesta Beach resort  made wrong transaction&lt;br /&gt; Hotel Trump International  &amp; Tower  made wrong transaction&lt;br /&gt; Hotel Trump International  Waikiki Beach Walk  made wrong transaction&lt;br /&gt; Hotel Trump  Las Vegas  made wrong transaction&lt;br /&gt; Hotel Trump Soho  made wrong transaction&lt;br /&gt; Hotel Universal Portofino Bay  a Loews   made wrong transaction&lt;br /&gt; Hotel Universal Royal Pacific Resort a Loews   made wrong transaction&lt;br /&gt; Hotel Vdara  &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Viceroy Palm Springs  made wrong transaction&lt;br /&gt; Hotel Villas Of Grand Cypress  made wrong transaction&lt;br /&gt; Hotel Wailea Marriott an Outrigger Resort  made wrong transaction&lt;br /&gt; Hotel Waldorf Astoria Orlando  made wrong transaction&lt;br /&gt; Hotel Waldorf Astoria  &amp; Towers  made wrong transaction&lt;br /&gt; Hotel Waldorf Towers  made wrong transaction&lt;br /&gt; Hotel Walt Disney World Swan and Dolphin  made wrong transaction&lt;br /&gt; Hotel Wardman Park Marriott  made wrong transaction&lt;br /&gt; Hotel Washington Court  on Capitol Hill  made wrong transaction&lt;br /&gt; Hotel Washington Suites Georgetown  made wrong transaction&lt;br /&gt; Hotel W Atlanta Midtown  made wrong transaction&lt;br /&gt; Hotel W Boston  made wrong transaction&lt;br /&gt; Hotel Westin Diplomat Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Westin Maui Resort &amp; Spa  made wrong transaction&lt;br /&gt; Hotel Westin Princeville Ocean Resort Villas  made wrong transaction&lt;br /&gt; Hotel Westin St. Francis  made wrong transaction&lt;br /&gt; Hotel W Hollywood  made wrong transaction&lt;br /&gt; Hotel Willard InterContinental  made wrong transaction&lt;br /&gt; Hotel Windsor Court   made wrong transaction&lt;br /&gt; Hotel W Los Angeles Westwood  made wrong transaction&lt;br /&gt; Hotel Woodrun Place Condo  made wrong transaction&lt;br /&gt; Hotel Woodrun V Townhomes  made wrong transaction&lt;br /&gt; Hotel W Seattle  made wrong transaction&lt;br /&gt; Hotel Wyndham Grand Desert  made wrong transaction&lt;br /&gt; Hotel Wynn Las Vegas  made wrong transaction&lt;br /&gt; Hotel XV Beacon  made wrong transaction&lt;br /&gt; Hotel ZaZa Houston  made wrong transaction&lt;br /&gt; Hotel Z Ocean  made wrong transaction&lt;br /&gt; Wrong transaction from your credit card in Acqualina Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Ahwahnee&lt;br /&gt; Wrong transaction from your credit card in Amsterdam Hospitality&lt;br /&gt; Wrong transaction from your credit card in Anglers&lt;br /&gt; Wrong transaction from your credit card in Argonaut&lt;br /&gt; Wrong transaction from your credit card in Aria&lt;br /&gt; Wrong transaction from your credit card in Arizona Biltmore&lt;br /&gt; Wrong transaction from your credit card in Arrabelle at Vail Square&lt;br /&gt; Wrong transaction from your credit card in Avalon&lt;br /&gt; Wrong transaction from your credit card in Bellagio  and Casino&lt;br /&gt; Wrong transaction from your credit card in Beverly Hills  &amp; Bungalows&lt;br /&gt; Wrong transaction from your credit card in Beverly Wilshire, A Four Seasons&lt;br /&gt; Wrong transaction from your credit card in Biltmore&lt;br /&gt; Wrong transaction from your credit card in Boston Harbor&lt;br /&gt; Wrong transaction from your credit card in Boston Marriott Copley Place&lt;br /&gt; Wrong transaction from your credit card in Breakers Palm Beach&lt;br /&gt; Wrong transaction from your credit card in Breakwater&lt;br /&gt; Wrong transaction from your credit card in Camelback Inn, A JW Marriott Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Campton Place&lt;br /&gt; Wrong transaction from your credit card in Carlton on Madison Avenue&lt;br /&gt; Wrong transaction from your credit card in Casa Del Mar&lt;br /&gt; Wrong transaction from your credit card in Chamonix&lt;br /&gt; Wrong transaction from your credit card in Charleston Marriott&lt;br /&gt; Wrong transaction from your credit card in Charleston Place&lt;br /&gt; Wrong transaction from your credit card in Conrad Chicago&lt;br /&gt; Wrong transaction from your credit card in Conrad Miami&lt;br /&gt; Wrong transaction from your credit card in Courtyard by Marriott Capitol Hill/Navy Yard&lt;br /&gt; Wrong transaction from your credit card in Courtyard by Marriott Houston Downtown&lt;br /&gt; Wrong transaction from your credit card in Courtyard Washington Convention Center&lt;br /&gt; Wrong transaction from your credit card in Crowne Plaza The Hamilton&lt;br /&gt; Wrong transaction from your credit card in Delano&lt;br /&gt; Wrong transaction from your credit card in Del Coronado&lt;br /&gt; Wrong transaction from your credit card in Disney's Grand Californian&lt;br /&gt; Wrong transaction from your credit card in Disney's Grand Floridian&lt;br /&gt; Wrong transaction from your credit card in Disney's Polynesian Resort&lt;br /&gt; Wrong transaction from your credit card in Doubletree by Hilton Orlando at SeaWorld&lt;br /&gt; Wrong transaction from your credit card in Dunton Hot Springs&lt;br /&gt; Wrong transaction from your credit card in Embassy Suites&lt;br /&gt; Wrong transaction from your credit card in Embassy Suites Chevy Chase Pavilion&lt;br /&gt; Wrong transaction from your credit card in Embassy Suites - Convention Center&lt;br /&gt; Wrong transaction from your credit card in Embassy Suites North Charleston&lt;br /&gt; Wrong transaction from your credit card in Embassy Suites Washington&lt;br /&gt; Wrong transaction from your credit card in Enchantment Resort&lt;br /&gt; Wrong transaction from your credit card in Encore at Wynn&lt;br /&gt; Wrong transaction from your credit card in Fairmont Chicago&lt;br /&gt; Wrong transaction from your credit card in Fairmont Heritage Place Ghiradelli Square&lt;br /&gt; Wrong transaction from your credit card in Fairmont Kea Lani&lt;br /&gt; Wrong transaction from your credit card in Fairmont Miramar&lt;br /&gt; Wrong transaction from your credit card in Fairmont Scottsdale&lt;br /&gt; Wrong transaction from your credit card in Fairmont  &amp; Towers&lt;br /&gt; Wrong transaction from your credit card in Florida Choice Executive Pool Homes&lt;br /&gt; Wrong transaction from your credit card in Four Seasons&lt;br /&gt; Wrong transaction from your credit card in Four Seasons  Los Angeles at Beverly Hills&lt;br /&gt; Wrong transaction from your credit card in Four Seasons Resort Lanai at Manele Bay&lt;br /&gt; Wrong transaction from your credit card in Four Seasons Resort Maui at Wailea&lt;br /&gt; Wrong transaction from your credit card in Four Seasons Resort Palm Beach&lt;br /&gt; Wrong transaction from your credit card in Four Seasons Resort Scottsdale&lt;br /&gt; Wrong transaction from your credit card in Four Seasons San Francisco&lt;br /&gt; Wrong transaction from your credit card in Gansevoort South&lt;br /&gt; Wrong transaction from your credit card in George&lt;br /&gt; Wrong transaction from your credit card in Gramercy Park&lt;br /&gt; Wrong transaction from your credit card in Grand Bohemian&lt;br /&gt; Wrong transaction from your credit card in Grand Hyatt Atlanta in Buckhead&lt;br /&gt; Wrong transaction from your credit card in Grand Hyatt Kauai Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Grand Hyatt New York&lt;br /&gt; Wrong transaction from your credit card in Grand Hyatt San Francisco&lt;br /&gt; Wrong transaction from your credit card in Grand Hyatt Seattle&lt;br /&gt; Wrong transaction from your credit card in Grand Hyatt Washington&lt;br /&gt; Wrong transaction from your credit card in Granduca&lt;br /&gt; Wrong transaction from your credit card in Grand Wailea Resort&lt;br /&gt; Wrong transaction from your credit card in Halekulani&lt;br /&gt; Wrong transaction from your credit card in Hampton Inn Washington - Convention Center&lt;br /&gt; Wrong transaction from your credit card in Helix Boutique&lt;br /&gt; Wrong transaction from your credit card in Hilton Americas Houston&lt;br /&gt; Wrong transaction from your credit card in Hilton Atlanta&lt;br /&gt; Wrong transaction from your credit card in Hilton Atlanta Airport&lt;br /&gt; Wrong transaction from your credit card in Hilton Boston Logan Airport&lt;br /&gt; Wrong transaction from your credit card in Hilton Chicago&lt;br /&gt; Wrong transaction from your credit card in Hilton Garden Inn Washington DC Franklin Square&lt;br /&gt; Wrong transaction from your credit card in Hilton Grand Vacations Club&lt;br /&gt; Wrong transaction from your credit card in Hilton Hawaiian Village&lt;br /&gt; Wrong transaction from your credit card in Hilton Houston Plaza&lt;br /&gt; Wrong transaction from your credit card in Hilton Houston Westchase&lt;br /&gt; Wrong transaction from your credit card in Hilton Las Vegas&lt;br /&gt; Wrong transaction from your credit card in Hilton Orlando Bonnet Creek&lt;br /&gt; Wrong transaction from your credit card in Hilton Washington&lt;br /&gt; Wrong transaction from your credit card in Hilton Washington Embassy Row&lt;br /&gt; Wrong transaction from your credit card in Holiday Inn Port of Miami Downtown&lt;br /&gt; Wrong transaction from your credit card in Homewood Suites&lt;br /&gt; Wrong transaction from your credit card in Hyatt Grand Aspen&lt;br /&gt; Wrong transaction from your credit card in Hyatt Regency Atlanta&lt;br /&gt; Wrong transaction from your credit card in Hyatt Regency Grand Cypress&lt;br /&gt; Wrong transaction from your credit card in Hyatt Regency Houston&lt;br /&gt; Wrong transaction from your credit card in Hyatt Regency Huntington Beach&lt;br /&gt; Wrong transaction from your credit card in Hyatt Regency Maui Resort and Spa&lt;br /&gt; Wrong transaction from your credit card in Hyatt Regency San Francisco&lt;br /&gt; Wrong transaction from your credit card in Hyatt Regency Scottsdale Resort&lt;br /&gt; Wrong transaction from your credit card in Hyatt Regency Waikiki&lt;br /&gt; Wrong transaction from your credit card in Hyatt Regency Washington&lt;br /&gt; Wrong transaction from your credit card in Icon&lt;br /&gt; Wrong transaction from your credit card in Indian Creek&lt;br /&gt; Wrong transaction from your credit card in Inn at Perry Cabin&lt;br /&gt; Wrong transaction from your credit card in Inn at the Ballpark&lt;br /&gt; Wrong transaction from your credit card in InterContinental&lt;br /&gt; Wrong transaction from your credit card in Intercontinental Buckhead Atlanta&lt;br /&gt; Wrong transaction from your credit card in InterContinental Chicago&lt;br /&gt; Wrong transaction from your credit card in Intercontinental San Francisco&lt;br /&gt; Wrong transaction from your credit card in InterContinental The Barclay New York&lt;br /&gt; Wrong transaction from your credit card in Jefferson&lt;br /&gt; Wrong transaction from your credit card in Jerome&lt;br /&gt; Wrong transaction from your credit card in Jumeirah Essex House&lt;br /&gt; Wrong transaction from your credit card in JW Marriott  Buckhead Atlanta&lt;br /&gt; Wrong transaction from your credit card in JW Marriott Desert Ridge Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in JW Marriott Las Vegas Resort, Spa &amp; Golf&lt;br /&gt; Wrong transaction from your credit card in JW Marriott  Miami&lt;br /&gt; Wrong transaction from your credit card in JW Marriott Orlando Grande Lakes&lt;br /&gt; Wrong transaction from your credit card in JW Marriott  Pennsylvania Avenue&lt;br /&gt; Wrong transaction from your credit card in JW Marriott San Francisco&lt;br /&gt; Wrong transaction from your credit card in Kahala Resort&lt;br /&gt; Wrong transaction from your credit card in Keswick Hall&lt;br /&gt; Wrong transaction from your credit card in La Costa Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Lauberge Del Mar&lt;br /&gt; Wrong transaction from your credit card in La Valencia&lt;br /&gt; Wrong transaction from your credit card in Le Meridien San Francisco&lt;br /&gt; Wrong transaction from your credit card in Le Parker Meridien&lt;br /&gt; Wrong transaction from your credit card in Lodge At Koele&lt;br /&gt; Wrong transaction from your credit card in Lodge At Torrey Pines&lt;br /&gt; Wrong transaction from your credit card in Loews Coronado Bay Resort&lt;br /&gt; Wrong transaction from your credit card in Loews  Miami Beach&lt;br /&gt; Wrong transaction from your credit card in Loews Regency&lt;br /&gt; Wrong transaction from your credit card in Loews Santa Monica Beach&lt;br /&gt; Wrong transaction from your credit card in London West Hollywood&lt;br /&gt; Wrong transaction from your credit card in Lowell&lt;br /&gt; Wrong transaction from your credit card in Madera&lt;br /&gt; Wrong transaction from your credit card in Madison&lt;br /&gt; Wrong transaction from your credit card in Main Street Station  &amp; Casino&lt;br /&gt; Wrong transaction from your credit card in Mandalay Bay&lt;br /&gt; Wrong transaction from your credit card in Mandarin Oriental&lt;br /&gt; Wrong transaction from your credit card in Mandarin Oriental Miami&lt;br /&gt; Wrong transaction from your credit card in Marriott at Metro Center&lt;br /&gt; Wrong transaction from your credit card in Marriott Chicago Downtown Magnificent Mile&lt;br /&gt; Wrong transaction from your credit card in Marriott Houston Airport at George Bush Intercontinental&lt;br /&gt; Wrong transaction from your credit card in Marriott Marquis San Francisco&lt;br /&gt; Wrong transaction from your credit card in Marriott Resort&lt;br /&gt; Wrong transaction from your credit card in Marriott San Francisco Fisherman's Wharf&lt;br /&gt; Wrong transaction from your credit card in Mauna Kea Beach&lt;br /&gt; Wrong transaction from your credit card in Mauna Lani Bay  &amp; Bungalows&lt;br /&gt; Wrong transaction from your credit card in McCoy Peak Lodge&lt;br /&gt; Wrong transaction from your credit card in Melrose&lt;br /&gt; Wrong transaction from your credit card in Meridian Luxury Suites&lt;br /&gt; Wrong transaction from your credit card in Michelangelo&lt;br /&gt; Wrong transaction from your credit card in Millennium UN Plaza&lt;br /&gt; Wrong transaction from your credit card in Monaco Boutique&lt;br /&gt; Wrong transaction from your credit card in Monaco Washington DC&lt;br /&gt; Wrong transaction from your credit card in Mona Lisa Suite&lt;br /&gt; Wrong transaction from your credit card in Mondrian&lt;br /&gt; Wrong transaction from your credit card in Mondrian Scottsdale&lt;br /&gt; Wrong transaction from your credit card in Mondrian South Beach&lt;br /&gt; Wrong transaction from your credit card in Morenas Resort Morrison-Clark Historic Inn&lt;br /&gt; Wrong transaction from your credit card in M Resort Spa &amp; Casino&lt;br /&gt; Wrong transaction from your credit card in New York Marriott Marquis&lt;br /&gt; Wrong transaction from your credit card in Nolitan&lt;br /&gt; Wrong transaction from your credit card in Oak Plantation Resort&lt;br /&gt; Wrong transaction from your credit card in Ocean Key Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Ocean Point Resort &amp; Club&lt;br /&gt; Wrong transaction from your credit card in Omni&lt;br /&gt; Wrong transaction from your credit card in Omni Berkshire Place&lt;br /&gt; Wrong transaction from your credit card in Omni Chicago&lt;br /&gt; Wrong transaction from your credit card in Omni Houston&lt;br /&gt; Wrong transaction from your credit card in One Bal Harbour Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Owl Creek Homes&lt;br /&gt; Wrong transaction from your credit card in Palms Place  &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Palomar&lt;br /&gt; Wrong transaction from your credit card in Palomar Boutique&lt;br /&gt; Wrong transaction from your credit card in Park Hyatt&lt;br /&gt; Wrong transaction from your credit card in Park Hyatt Chicago&lt;br /&gt; Wrong transaction from your credit card in Park Hyatt Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Peabody Orlando&lt;br /&gt; Wrong transaction from your credit card in Peninsula New York&lt;br /&gt; Wrong transaction from your credit card in Phoenician&lt;br /&gt; Wrong transaction from your credit card in Pierre A Taj&lt;br /&gt; Wrong transaction from your credit card in Plaza Athenee&lt;br /&gt; Wrong transaction from your credit card in Pocono Palace&lt;br /&gt; Wrong transaction from your credit card in Prescott&lt;br /&gt; Wrong transaction from your credit card in Raffles L'Ermitage Beverly Hills&lt;br /&gt; Wrong transaction from your credit card in Rancho Bernardo Inn&lt;br /&gt; Wrong transaction from your credit card in Rancho Las Palmas Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Red Rock Casino Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Renaissance Charleston  Historic District&lt;br /&gt; Wrong transaction from your credit card in Renaissance Chicago&lt;br /&gt; Wrong transaction from your credit card in Renaissance Houston  Greenway Plaza&lt;br /&gt; Wrong transaction from your credit card in Renaissance New York  Times Square&lt;br /&gt; Wrong transaction from your credit card in Renaissance Washington&lt;br /&gt; Wrong transaction from your credit card in Renaissance Waverly&lt;br /&gt; Wrong transaction from your credit card in Residence Inn by Marriott Capitol&lt;br /&gt; Wrong transaction from your credit card in Rio Suite  and Casino&lt;br /&gt; Wrong transaction from your credit card in Ritz-Carlton&lt;br /&gt; Wrong transaction from your credit card in Ritz-Carlton Battery Park&lt;br /&gt; Wrong transaction from your credit card in Ritz-Carlton Boston Common&lt;br /&gt; Wrong transaction from your credit card in Ritz-Carlton Central Park&lt;br /&gt; Wrong transaction from your credit card in Ritz-Carlton Golf Resort&lt;br /&gt; Wrong transaction from your credit card in Ritz Carlton Kapalua&lt;br /&gt; Wrong transaction from your credit card in Ritz Carlton Key Biscayne&lt;br /&gt; Wrong transaction from your credit card in Ritz-Carlton Laguna Niguel&lt;br /&gt; Wrong transaction from your credit card in Ritz-Carlton Marina Del Rey&lt;br /&gt; Wrong transaction from your credit card in Ritz Carlton Naples Beach Resort&lt;br /&gt; Wrong transaction from your credit card in Ritz Carlton Naples Golf Resort&lt;br /&gt; Wrong transaction from your credit card in Ritz-Carlton Orlando, Grande Lakes Resort&lt;br /&gt; Wrong transaction from your credit card in Ritz-Carlton Palm Beach&lt;br /&gt; Wrong transaction from your credit card in Ritz-Carlton San Francisco&lt;br /&gt; Wrong transaction from your credit card in Ritz Carlton South Beach&lt;br /&gt; Wrong transaction from your credit card in Rouge&lt;br /&gt; Wrong transaction from your credit card in Royal Hawaiian&lt;br /&gt; Wrong transaction from your credit card in Royal Pacific Resort&lt;br /&gt; Wrong transaction from your credit card in Royal Palms Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Sanctuary on Camelback Mountain&lt;br /&gt; Wrong transaction from your credit card in Seattle Marriott Waterfront&lt;br /&gt; Wrong transaction from your credit card in Se San Diego&lt;br /&gt; Wrong transaction from your credit card in Shangri-La&lt;br /&gt; Wrong transaction from your credit card in Sheraton Chicago  and Towers&lt;br /&gt; Wrong transaction from your credit card in Sheraton Keauhou Bay Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Sheraton Maui Resort&lt;br /&gt; Wrong transaction from your credit card in Sheraton Moana Surfrider&lt;br /&gt; Wrong transaction from your credit card in Sheraton Suites Houston Near The Galleria&lt;br /&gt; Wrong transaction from your credit card in Sheraton Suites San Diego at Symphony Hall&lt;br /&gt; Wrong transaction from your credit card in Sheraton Waikiki&lt;br /&gt; Wrong transaction from your credit card in Shore Club&lt;br /&gt; Wrong transaction from your credit card in Shutters Beach&lt;br /&gt; Wrong transaction from your credit card in Signature at MGM Grand&lt;br /&gt; Wrong transaction from your credit card in Skylofts at MGM Grand&lt;br /&gt; Wrong transaction from your credit card in SLS  at Beverly Hills&lt;br /&gt; Wrong transaction from your credit card in Sofitel Lafayette Square&lt;br /&gt; Wrong transaction from your credit card in Sonesta  Orlando Downtown&lt;br /&gt; Wrong transaction from your credit card in Sorrento&lt;br /&gt; Wrong transaction from your credit card in South Beach Marriott&lt;br /&gt; Wrong transaction from your credit card in Star The Michelangelo&lt;br /&gt; Wrong transaction from your credit card in St. Gregory Luxury  &amp; Suites&lt;br /&gt; Wrong transaction from your credit card in St. Regis&lt;br /&gt; Wrong transaction from your credit card in St. Regis Princeville Resort&lt;br /&gt; Wrong transaction from your credit card in St. Regis Washington&lt;br /&gt; Wrong transaction from your credit card in Sun Harbour Boutique&lt;br /&gt; Wrong transaction from your credit card in Sutton Place&lt;br /&gt; Wrong transaction from your credit card in Swissotel Chicago&lt;br /&gt; Wrong transaction from your credit card in Taj Boston&lt;br /&gt; Wrong transaction from your credit card in Taj Campton Place&lt;br /&gt; Wrong transaction from your credit card in Tamarack by Destination Resorts Snowmass&lt;br /&gt; Wrong transaction from your credit card in The Alex&lt;br /&gt; Wrong transaction from your credit card in The Alexander&lt;br /&gt; Wrong transaction from your credit card in The Carlyle, A Rosewood&lt;br /&gt; Wrong transaction from your credit card in The Carlyle Suites&lt;br /&gt; Wrong transaction from your credit card in The Chatwal&lt;br /&gt; Wrong transaction from your credit card in The Cosmopolitan Las Vegas&lt;br /&gt; Wrong transaction from your credit card in The Drake&lt;br /&gt; Wrong transaction from your credit card in The Enclave&lt;br /&gt; Wrong transaction from your credit card in The Equinox Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in The Fairmont&lt;br /&gt; Wrong transaction from your credit card in The Fairmont Copley Plaza&lt;br /&gt; Wrong transaction from your credit card in The Fairmont Olympic&lt;br /&gt; Wrong transaction from your credit card in The Fairmont Orchid&lt;br /&gt; Wrong transaction from your credit card in The Fairmont Washington&lt;br /&gt; Wrong transaction from your credit card in The Hay-Adams&lt;br /&gt; Wrong transaction from your credit card in The Helmsley Carlton House&lt;br /&gt; Wrong transaction from your credit card in The Henley Park&lt;br /&gt; Wrong transaction from your credit card in The Houstonian  Club &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in The Huntington and Nob Hill Spa&lt;br /&gt; Wrong transaction from your credit card in The Iroquois&lt;br /&gt; Wrong transaction from your credit card in The Langham Huntington  &amp; SPA&lt;br /&gt; Wrong transaction from your credit card in The Latham&lt;br /&gt; Wrong transaction from your credit card in The Lenox&lt;br /&gt; Wrong transaction from your credit card in The Little Nell&lt;br /&gt; Wrong transaction from your credit card in The Lucerne&lt;br /&gt; Wrong transaction from your credit card in The New York Helmsley&lt;br /&gt; Wrong transaction from your credit card in The Orchard&lt;br /&gt; Wrong transaction from your credit card in The Palmer House Hilton&lt;br /&gt; Wrong transaction from your credit card in The Peninsula&lt;br /&gt; Wrong transaction from your credit card in The Peninsula Beverly Hills&lt;br /&gt; Wrong transaction from your credit card in The Phoenician&lt;br /&gt; Wrong transaction from your credit card in The Pierre&lt;br /&gt; Wrong transaction from your credit card in The Plaza&lt;br /&gt; Wrong transaction from your credit card in The Quincy&lt;br /&gt; Wrong transaction from your credit card in The Ritz Carlton&lt;br /&gt; Wrong transaction from your credit card in The Ritz-Carlton Bachelor Gulch&lt;br /&gt; Wrong transaction from your credit card in The Ritz-Carlton Buckhead&lt;br /&gt; Wrong transaction from your credit card in The Ritz-Carlton Fort Lauderdale&lt;br /&gt; Wrong transaction from your credit card in The Ritz-Carlton Georgetown&lt;br /&gt; Wrong transaction from your credit card in The Ritz-Carlton Laguna Niguel&lt;br /&gt; Wrong transaction from your credit card in The Ritz-Carlton Orlando, Grande Lakes&lt;br /&gt; Wrong transaction from your credit card in The Setai&lt;br /&gt; Wrong transaction from your credit card in The Setai Fifth Avenue&lt;br /&gt; Wrong transaction from your credit card in The St. Regis Aspen&lt;br /&gt; Wrong transaction from your credit card in The St. Regis Monarch Beach&lt;br /&gt; Wrong transaction from your credit card in The Venetian Resort  and Casino&lt;br /&gt; Wrong transaction from your credit card in The Villa By Barton G&lt;br /&gt; Wrong transaction from your credit card in The Washington Court On Capital Hil&lt;br /&gt; Wrong transaction from your credit card in The Westin Atlanta Airport&lt;br /&gt; Wrong transaction from your credit card in The Westin Chicago River North&lt;br /&gt; Wrong transaction from your credit card in The Westin Embassy Row&lt;br /&gt; Wrong transaction from your credit card in The Westin Grand&lt;br /&gt; Wrong transaction from your credit card in The Westin Michigan Avenue&lt;br /&gt; Wrong transaction from your credit card in The Westin Mission Hills Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in The Westin New York at Times Square&lt;br /&gt; Wrong transaction from your credit card in The Westin Oaks&lt;br /&gt; Wrong transaction from your credit card in The Westin Peachtree Plaza&lt;br /&gt; Wrong transaction from your credit card in The Westin Seattle&lt;br /&gt; Wrong transaction from your credit card in The Whitehall&lt;br /&gt; Wrong transaction from your credit card in The Wit-A Doubletree&lt;br /&gt; Wrong transaction from your credit card in Tides South Beach&lt;br /&gt; Wrong transaction from your credit card in Topaz&lt;br /&gt; Wrong transaction from your credit card in Trump International Sonesta Beach resort&lt;br /&gt; Wrong transaction from your credit card in Trump International  &amp; Tower&lt;br /&gt; Wrong transaction from your credit card in Trump International  Waikiki Beach Walk&lt;br /&gt; Wrong transaction from your credit card in Trump  Las Vegas&lt;br /&gt; Wrong transaction from your credit card in Trump Soho&lt;br /&gt; Wrong transaction from your credit card in Universal Portofino Bay  a Loews&lt;br /&gt; Wrong transaction from your credit card in Universal Royal Pacific Resort a Loews&lt;br /&gt; Wrong transaction from your credit card in Vdara  &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Viceroy Palm Springs&lt;br /&gt; Wrong transaction from your credit card in Villas Of Grand Cypress&lt;br /&gt; Wrong transaction from your credit card in Wailea Marriott an Outrigger Resort&lt;br /&gt; Wrong transaction from your credit card in Waldorf Astoria Orlando&lt;br /&gt; Wrong transaction from your credit card in Waldorf Astoria  &amp; Towers&lt;br /&gt; Wrong transaction from your credit card in Waldorf Towers&lt;br /&gt; Wrong transaction from your credit card in Walt Disney World Swan and Dolphin&lt;br /&gt; Wrong transaction from your credit card in Wardman Park Marriott&lt;br /&gt; Wrong transaction from your credit card in Washington Court  on Capitol Hill&lt;br /&gt; Wrong transaction from your credit card in Washington Suites Georgetown&lt;br /&gt; Wrong transaction from your credit card in W Atlanta Midtown&lt;br /&gt; Wrong transaction from your credit card in W Boston&lt;br /&gt; Wrong transaction from your credit card in Westin Diplomat Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Westin Maui Resort &amp; Spa&lt;br /&gt; Wrong transaction from your credit card in Westin Princeville Ocean Resort Villas&lt;br /&gt; Wrong transaction from your credit card in Westin St. Francis&lt;br /&gt; Wrong transaction from your credit card in W Hollywood&lt;br /&gt; Wrong transaction from your credit card in Willard InterContinental&lt;br /&gt; Wrong transaction from your credit card in Windsor Court&lt;br /&gt; Wrong transaction from your credit card in W Los Angeles Westwood&lt;br /&gt; Wrong transaction from your credit card in Woodrun Place Condo&lt;br /&gt; Wrong transaction from your credit card in Woodrun V Townhomes&lt;br /&gt; Wrong transaction from your credit card in W Seattle&lt;br /&gt; Wrong transaction from your credit card in Wyndham Grand Desert&lt;br /&gt; Wrong transaction from your credit card in Wynn Las Vegas&lt;br /&gt; Wrong transaction from your credit card in XV Beacon&lt;br /&gt; Wrong transaction from your credit card in ZaZa Houston&lt;br /&gt; Wrong transaction from your credit card in Z Ocean&lt;br /&gt;(689 rows)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-6322063660934591377?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/6322063660934591377'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/6322063660934591377'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/07/wrong-transaction-hotel-spam.html' title='&quot;Wrong Transaction&quot; Hotel Spam'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-3363879471331329103</id><published>2011-07-23T07:28:00.000-07:00</published><updated>2011-07-23T10:16:40.585-07:00</updated><title type='text'>MasterCard spam leads to Fake AV</title><content type='html'>The FBI is doing a great job gaining international cooperation in going after cyber criminals.  Just last month yet another malware group was arrested, as the public learned about in the June 22, 2011 FBI press release, &lt;a href="http://www.fbi.gov/news/pressrel/press-releases/department-of-justice-disrupts-international-cybercrime-rings-distributing-scareware"&gt;Department of Justice disrupts international cybercrime rings distributing scareware&lt;/A&gt;.  In that case, criminals were arrested as part of a scareware ring that had infected more than 1 million computers and caused more than $72 million in losses!&lt;br /&gt;&lt;br /&gt;Unfortunately, the end of fake Anti-virus scareware has not yet arrived.  Here's an example from today's spam from the &lt;a hrer="http://www.cis.uab.edu/UABSpamDataMine"&gt;UAB Spam Data Mine&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Please see end for an update&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;We're seeing a significant "spam attached malware" campaign in the past 24 hours with six different attachment MD5s.&lt;br /&gt;&lt;br /&gt;uab_spam=&gt; select count(*), sender_domain, md5_hex, size from spam natural join spam_attach where sender_domain = 'mastercard.com' and receiving_date &gt;= '2011-07-22' group by sender_domain, md5_hex, size;&lt;br /&gt;&lt;br /&gt; count | received                |             md5_hex              | size  &lt;br /&gt;-------+-------------------------+---------------------------------+-------&lt;br /&gt;   318 | 7/22 03:15 - 7/22 10:15 | 241cc18918540d6c49dd8b45df31985d | 67584&lt;br /&gt;    20 | 7/22 10:45 - 7/22 11:00 | 5f8a95d194f7dcadabf442ed5705c4e0 | 79872&lt;br /&gt;   565 | 7/22 11:30 - 7/22 17:30 | 0256a71baefd0f625910bbc44147e432 | 68096&lt;br /&gt;  1133 | 7/22 17:45 - 7/23 04:00 | f4aea68ea94d7780a5b1abd709f7730f | 69632&lt;br /&gt;    67 | 7/22 12:00 - 7/23 08:15 | 277eb4dacd401a3c520dc5bb9ede70f0 | 77237&lt;br /&gt;   439 | 7/23 04:00 - 7/23 08:15 | fe88c3a276d11aa208dac7ae68f55cd3 | 67584&lt;br /&gt;(6 rows)&lt;br /&gt;&lt;br /&gt;Most popular email subjects:&lt;br /&gt;&lt;br /&gt; count |                    subject                    &lt;br /&gt;-------+-----------------------------------------------&lt;br /&gt;    24 | WARNING: Your credit card is locked!&lt;br /&gt;    26 | WARNING: Your credit card is blocked!&lt;br /&gt;    26 | ATTENTION: Your credit card has been blocked!&lt;br /&gt;  1116 | Your credit card is blocked&lt;br /&gt;    29 | ATTENTION: Your credit card is blocked!&lt;br /&gt;  1184 | Your credit card has been blocked&lt;br /&gt;    24 | CAUTION: Your credit card is locked!&lt;br /&gt;    29 | ATTENTION: Your credit card is locked!&lt;br /&gt;    31 | WARNING: Your credit card has been blocked!&lt;br /&gt;    19 | CAUTION: Your credit card has been blocked!&lt;br /&gt;    34 | CAUTION: Your credit card is blocked!&lt;br /&gt;(11 rows)&lt;br /&gt;&lt;br /&gt;The body of the email looks like the attached file:&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/jul23.mastercard.jpg"&gt;&lt;br /&gt;&lt;br /&gt;------------------&lt;br /&gt;Dear User,&lt;br /&gt;Your credit card is locked!&lt;br /&gt;From your credit card has been removed $ 3951,74&lt;br /&gt;Possibly illegal operation!&lt;br /&gt;More details in the attached file.&lt;br /&gt;Instantly contact your bank .&lt;br /&gt;Best regards, MASTERCARD Services.&lt;br /&gt;-------------------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The username portion of the email sender is random, using a classic mis-spelling that has been consistent for this sender (which is the same guy who has been doing the "government imitating" zeus).  "cunsumer"&lt;br /&gt;&lt;br /&gt;Usernames are a single word, followed by a ".", "_", or "-", followed by a two or three digit number.&lt;br /&gt;&lt;br /&gt;The most popular words (by far) are "manager" (770 time), and "support" (757 times), but we've also seen admin, adminnistration, alerts, cunsumer, delivery, e-file, finance, frboard-webannouncements, govdelivery, information, inspector, news, news-alerts, no-reply, protection, public, report, service, stats, subscriber, subscriptions, usttb, and webannouncements.&lt;br /&gt;&lt;br /&gt;The attached file is actually named as a ".com" file, using a random-seeming filename in the format "id" followed by a 5-7 digit number (such as id918538.com).&lt;br /&gt;&lt;br /&gt;Of the 2,649 IP addresses that have sent us the spam so far, they have come from 1,443 distinct sending IP addresses.  Some of our most popular senders have been:&lt;br /&gt;&lt;br /&gt; count |     sender_ip      &lt;br /&gt;-------+--------------------&lt;br /&gt;    10 | 113.172.171.155/32&lt;br /&gt;    10 | 190.99.213.191/32&lt;br /&gt;     9 | 75.145.37.117/32&lt;br /&gt;     9 | 187.126.15.108/32&lt;br /&gt;     9 | 110.164.112.159/32&lt;br /&gt;     8 | 188.81.213.237/32&lt;br /&gt;     8 | 201.240.80.96/32&lt;br /&gt;     8 | 79.82.153.66/32&lt;br /&gt;     8 | 110.138.30.34/32&lt;br /&gt;     7 | 180.253.110.135/32&lt;br /&gt;     7 | 151.64.138.215/32&lt;br /&gt;     7 | 79.178.152.194/32&lt;br /&gt;     6 | 95.37.41.218/32&lt;br /&gt;     6 | 201.240.215.105/32&lt;br /&gt;     6 | 94.20.98.220/32&lt;br /&gt;     6 | 122.167.44.208/32&lt;br /&gt;     6 | 71.197.255.106/32&lt;br /&gt;     6 | 113.190.138.153/32&lt;br /&gt;     6 | 90.177.147.202/32&lt;br /&gt;     6 | 178.150.237.124/32&lt;br /&gt;     6 | 65.10.178.64/32&lt;br /&gt;     6 | 178.204.204.172/32&lt;br /&gt;     6 | 24.90.102.247/32&lt;br /&gt;     6 | 93.75.103.25/32&lt;br /&gt;     6 | 190.235.93.183/32&lt;br /&gt;     6 | 82.51.62.237/32&lt;br /&gt;     6 | 77.236.26.169/32&lt;br /&gt;     6 | 110.164.106.145/32&lt;br /&gt;     6 | 178.222.27.142/32&lt;br /&gt;     6 | 113.53.181.86/32&lt;br /&gt;     6 | 123.17.157.159/32&lt;br /&gt;     6 | 151.25.53.47/32&lt;br /&gt;     5 | 201.68.209.20/32&lt;br /&gt;     5 | 180.180.150.248/32&lt;br /&gt;     5 | 120.62.24.122/32&lt;br /&gt;     5 | 59.182.51.42/32&lt;br /&gt;     5 | 182.53.176.152/32&lt;br /&gt;     5 | 194.28.88.58/32&lt;br /&gt;     5 | 85.186.178.173/32&lt;br /&gt;     5 | 41.140.170.143/32&lt;br /&gt;     5 | 71.200.55.41/32&lt;br /&gt;     5 | 200.91.255.142/32&lt;br /&gt;     5 | 190.43.147.223/32&lt;br /&gt;     5 | 125.24.202.30/32&lt;br /&gt;     5 | 41.140.43.44/32&lt;br /&gt;     5 | 59.184.128.238/32&lt;br /&gt;     5 | 95.58.34.230/32&lt;br /&gt;     5 | 117.201.20.59/32&lt;br /&gt;     5 | 186.6.177.39/32&lt;br /&gt;&lt;br /&gt;I chose the most recent MD5 and did a scan at VirusTotal, finding that only 3 of 43 Antivirus products were able to detect this as a virus, according to this &lt;a href="http://www.virustotal.com/file-scan/report.html?id=eb0f8cf71f561626dd923bc68577e1e0807f8b0ec9b4eb1c21ce58cb852f5995-1311425911"&gt;VirusTotal report&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;Since this was an email attachment, web reputation didn't really help here.  This would be a case where your spam blocking would be your best defense!&lt;br /&gt;&lt;br /&gt;When the file is launched, it attempts to make connections to a long list of domains that are probably made by a "DGA" or "Domain Generation Algorithm".  It's likely that at different times or days this list would be different.  My domains included:&lt;br /&gt;&lt;br /&gt;syqivolurypugi.com&lt;br /&gt;qotasifelaw.com&lt;br /&gt;tibumuqel.com&lt;br /&gt;suzehebaq.com&lt;br /&gt;sivycaqilugoq.com&lt;br /&gt;levulehup.com&lt;br /&gt;ledimajezociw.com&lt;br /&gt;rabuqibareme.com&lt;br /&gt;fopuvuwupode.com&lt;br /&gt;cinuherijugeg.com&lt;br /&gt;&lt;br /&gt;and more.&lt;br /&gt;&lt;br /&gt;bakagunaxepo.com responded as 193.164.132.20 &lt;= Gigahosting, Germany&lt;br /&gt;bipuwyqojivu.com responded as 85.17.239.165 &lt;= Leaseweb, Netherlands&lt;br /&gt;civivicuqekexo.com responded as 93.104.208.84 &lt;= Gigahosting&lt;br /&gt;levulehup.com responded as 204.45.120.27    &lt;= FDC Servers, Chicago&lt;br /&gt;levysavasezo.com responded as 85.17.239.215 &lt;= Leaseweb, Netherlands&lt;br /&gt;pafozykavygaj.com responded as 85.17.239.216 &lt;= Leaseweb, Netherlands&lt;br /&gt;pejozehywe.com responded as 50.2.7.242       &lt;= Eonix/GotHost&lt;br /&gt;suzehebaq.com responded as 206.217.134.44    &lt;= Colocrossing&lt;br /&gt;syqivolurypugi.com responded as 206.217.134.43 &lt;= Colocrossing&lt;br /&gt;waciroqohuli.com responded as 64.56.65.213  &lt;= VRTServers.net&lt;br /&gt;zarapetahuryp.com responded as 50.2.7.241  &lt;= Eonix/GotHost&lt;br /&gt;&lt;br /&gt;as a few examples . . . &lt;br /&gt;&lt;br /&gt;The purpose of the malware?  Seems to be just another Fake Anti-virus product.  Here's the scan that kicked off:&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/jul23.scanning.jpg"&gt;&lt;br /&gt;&lt;br /&gt;After the scan, I was of course constantly reminded of the grave danger I was in:&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/jul23.danger.jpg"&gt;&lt;br /&gt;&lt;br /&gt;First it did a get for "1038000112" from "bogekizase.com" on 66.197.213.6.&lt;br /&gt;&lt;br /&gt;All it got back from there was "OK."&lt;br /&gt;&lt;br /&gt;Most of the interaction was from tibumuqel.com on 79.143.178.101.&lt;br /&gt;&lt;br /&gt;tibumuqel.com was registered on July 15, 2011 using the contact info:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;         Ana Ivancic freon@cutemail.org&lt;br /&gt;         +385.20324535&lt;br /&gt;         Od Domina 5&lt;br /&gt;         Dubrovnik,Southern Dalmatia,HR 20000&lt;br /&gt;&lt;br /&gt;Searching on her details will show that "Ana" has registered plenty of other malware domains as well, usually with different email addresses.&lt;br /&gt;&lt;br /&gt;From the tibumuqel.com domain, we did a get for "10380001124255461742" which was redirected to "buy.html"&lt;br /&gt;&lt;br /&gt;That's also the box that my payment information was posted back to, although unfortunately, my credit card was declined.  8-(&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;That was my "purchase the fake AV product" screen, giving me my pricing options, and letting me know that this fake AV product was an SC Magazine 2011 award finalist!&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/jul23.purchasepage.jpg"&gt;&lt;br /&gt;&lt;br /&gt;What are our lessons learned?&lt;br /&gt;&lt;br /&gt;Anti-virus can't protect you by itself, as evidenced by the 3 of 43 AV products that new about this malware this morning.  You need a robust security strategy that includes:&lt;br /&gt;&lt;br /&gt;   a. Being Smart about what you click on.  (Start with CLICK ON NOTHING)&lt;br /&gt;   b. a web-reputation component (stopping traffic to bad websites)&lt;br /&gt;   c. a strong spam filter&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Update&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;While looking at a totally different spam message, I saved the attachment and scanned it at VirusTotal.  I thought the MD5 looked familiar, and ran a different search in the UAB Spam Data Mine.&lt;br /&gt;&lt;br /&gt;This query says "show me the most popular subjects since yesterday where the email had an attachment with the MD5 = "277eb..."&lt;br /&gt;&lt;br /&gt;uab_spam=&gt; select count(*), subject from spam natural join spam_attach where md5_hex = '277eb4dacd401a3c520dc5bb9ede70f0' and receiving_date &gt;= '2011-07-22' group by subject order by count desc;&lt;br /&gt;&lt;br /&gt;The search results reveal that in addition to the MasterCard spam ("Your credit card is blocked") the BINARY IDENTICAL malware is being distributed in a set of spam messages calling themselves a new "love card" game, and also as a "FedEx" message.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; count |                    subject                     &lt;br /&gt;-------+------------------------------------------------&lt;br /&gt;   187 | Your credit card is blocked&lt;br /&gt;   179 | Your credit card has been blocked&lt;br /&gt;     6 | Gift from Your Babbie&lt;br /&gt;     6 | LOVE-CARD from Your Babbie&lt;br /&gt;     5 | Nice Gift only for YOU&lt;br /&gt;     5 | Nice Gift from Your Babbie&lt;br /&gt;     5 | LOVE - CARD from YOUR BABY&lt;br /&gt;     5 | Gift for special YOU&lt;br /&gt;     4 | LOVE GIFT from Your GirlFriend&lt;br /&gt;     4 | Love-Card from Your Babbie&lt;br /&gt;     4 | Gift from YOUR BABBIE&lt;br /&gt;     4 | Gift from Your Love&lt;br /&gt;     4 | LOVE GIFT from Your Baby&lt;br /&gt;     4 | Gift for YOU&lt;br /&gt;     4 | LOVE - CARD only for YOU&lt;br /&gt;     4 | LoveCard from YOUR PUSSY&lt;br /&gt;     4 | LOVECARD for YOU&lt;br /&gt;     4 | Gift from YOUR PUSSY&lt;br /&gt;     3 | Love Gift from Y&lt;br /&gt;     3 | LOVE GIFT from YOUR BABBIE&lt;br /&gt;     3 | LOVECARD from YOUR BABBIE&lt;br /&gt;     3 | LOVECARD from Your Pussy&lt;br /&gt;     3 | NICE GIFT only for YOU&lt;br /&gt;     3 | LOVE GIFT from Your Love&lt;br /&gt;     3 | Nice Gift from YOUR LOVE&lt;br /&gt;     3 | NICE GIFT from Your GirlFriend&lt;br /&gt;     3 | Love-Card from Your GirlFriend&lt;br /&gt;     3 | Love-Card from YOUR BABY&lt;br /&gt;     3 | Love-Card from YOUR LOVE&lt;br /&gt;     3 | LOVE - CARD for YOU&lt;br /&gt;     3 | LOVECARD from Your Love&lt;br /&gt;     3 | LOVE - CARD from Your Pussy&lt;br /&gt;     3 | FedEx Delivery Confirmation 959256&lt;br /&gt;     3 | LOVE GIFT special for YOU&lt;br /&gt;     3 | Nice Gift from Your Baby&lt;br /&gt;     2 | Love-Card from Your Baby&lt;br /&gt;     2 | Love-Card from Your Love&lt;br /&gt;     2 | Love Gift special for YOU&lt;br /&gt;     2 | Love Gift from Your GirlFriend&lt;br /&gt;     2 | Nice Gift from YOUR BABBIE&lt;br /&gt;     2 | LOVECARD from YOUR PUSSY&lt;br /&gt;     2 | NICE GIFT from Your Pussy&lt;br /&gt;     2 | Love-Card for YOU&lt;br /&gt;     2 | GIFT from YOUR BABY&lt;br /&gt;     2 | Love Gift from YOUR BABY&lt;br /&gt;     2 | our Love&lt;br /&gt;     2 | GIFT from YOUR GIRLFRIEND&lt;br /&gt;     2 | Love Gift from Your Baby&lt;br /&gt;     2 | LOVECARD from YOUR GIRLFRIEND&lt;br /&gt;     2 | LOVECARD from YOUR LOVE&lt;br /&gt;     2 | LoveCard from YOUR BABY&lt;br /&gt;     2 | Nice Gift from YOUR PUSSY&lt;br /&gt;     2 | LOVE GIFT from YOUR GIRLFRIEND&lt;br /&gt;     2 | LOVECARD only for YOU&lt;br /&gt;     2 | LoveCard from YOUR LOVE&lt;br /&gt;     2 | Love-Card only for YOU&lt;br /&gt;     2 | LOVE-CARD from Your Love&lt;br /&gt;     2 | GIFT from Your GirlFriend&lt;br /&gt;     2 | LoveCard only for YOU&lt;br /&gt;     2 | GIFT from Your Pussy&lt;br /&gt;     2 | LOVE GIFT only for YOU&lt;br /&gt;     2 | NICE GIFT from YOUR BABY&lt;br /&gt;     2 | LoveCard from YOUR BABBIE&lt;br /&gt;     2 | Nice Gift from Your GirlFriend&lt;br /&gt;     2 | Love Gift from YOUR PUSSY&lt;br /&gt;     2 | Gift from Your GirlFriend&lt;br /&gt;     2 | Love Gift from Your Babbie&lt;br /&gt;     2 | NICE GIFT from YOUR GIRLFRIEND&lt;br /&gt;     2 | LOVE-CARD for YOU&lt;br /&gt;     2 | Nice Gift from YOUR BABY&lt;br /&gt;     2 | NICE GIFT from Your Love&lt;br /&gt;     2 | Gift from YOUR BABY&lt;br /&gt;     2 | LOVE-CARD only for YOU&lt;br /&gt;     2 | LOVE-CARD from YOUR PUSSY&lt;br /&gt;     2 | LOVE - CARD from YOUR GIRLFRIEND&lt;br /&gt;     2 | LOVE GIFT from YOUR LOVE&lt;br /&gt;     2 | LOVE-CARD from YOUR BABY&lt;br /&gt;     1 | Your Fed Ex id. 1261345&lt;br /&gt;     1 | From Fed Ex 1608374&lt;br /&gt;     1 | Fed Ex id. 72663522&lt;br /&gt;     1 | Fed Ex: DELIVER CONFIRMATION - FAILED 61010754&lt;br /&gt;     1 | From FEDEX 66810145&lt;br /&gt;     1 | FEDEX: DELIVER CONFIRMATION - FAILED 77170773&lt;br /&gt;     1 | Your FedEx id. 1629114&lt;br /&gt;     1 | Your Fedex id. 32327869&lt;br /&gt;     1 | FEDEX Attention 29219918&lt;br /&gt;     1 | Fed Ex Attention 67868668&lt;br /&gt;     1 | DELIVERY CONFIRMATION FROM Fedex 9190176&lt;br /&gt;     1 | Fedex: DELIVER CONFIRMATION - FAILED 41984219&lt;br /&gt;     1 | Fedex ATTENTION 6338557&lt;br /&gt;     1 | FEDEX Attention 046196&lt;br /&gt;     1 | Fed Ex Attention 387314&lt;br /&gt;     1 | Your Fedex id. 434089&lt;br /&gt;     1 | Fed Ex Delivery Confirmation 2241136&lt;br /&gt;     1 | Fed Ex DELIVERY CONFIRMATION 87476541&lt;br /&gt;     1 | Fed Ex: DELIVER CONFIRMATION - FAILED 3022529&lt;br /&gt;     1 | Fed Ex Delivery Confirmation 4749239&lt;br /&gt;     1 | FEDEX Delivery Confirmation 3963252&lt;br /&gt;     1 | FEDEX ATTENTION 856587&lt;br /&gt;     1 | FEDEX id. 1677134&lt;br /&gt;     1 | FedEx ATTENTION 76569153&lt;br /&gt;     1 | From Fed Ex 9733307&lt;br /&gt;     1 | FedEx Delivery Confirmation 35208363&lt;br /&gt;     1 | FEDEX: DELIVER CONFIRMATION - FAILED 806406&lt;br /&gt;     1 | DELIVERY CONFIRMATION FROM FedEx 290057&lt;br /&gt;     1 | From Fed Ex 630972&lt;br /&gt;     1 | Fedex ATTENTION 415495&lt;br /&gt;     1 | FEDEX Attention 72445407&lt;br /&gt;     1 | FEDEX Attention 9647476&lt;br /&gt;     1 | From Fed Ex 6560851&lt;br /&gt;     1 | FedEx id. 7689961&lt;br /&gt;     1 | FEDEX Attention 3225080&lt;br /&gt;     1 | Fedex Attention 0014817&lt;br /&gt;     1 | Fed Ex DELIVERY CONFIRMATION 17629587&lt;br /&gt;     1 | FEDEX DELIVERY CONFIRMATION 97113221&lt;br /&gt;     1 | FedEx Attention 76468884&lt;br /&gt;     1 | Fed Ex Delivery Confirmation 32603804&lt;br /&gt;     1 | FEDEX: DELIVER CONFIRMATION - FAILED 5347890&lt;br /&gt;     1 | FedEx Delivery Confirmation 20606057&lt;br /&gt;     1 | Fedex: DELIVER CONFIRMATION - FAILED 804651&lt;br /&gt;     1 | FedEx DELIVERY CONFIRMATION 9137898&lt;br /&gt;     1 | Fedex Delivery Confirmation 60516598&lt;br /&gt;     1 | Fed Ex Attention 166784&lt;br /&gt;     1 | From Fedex 491840&lt;br /&gt;     1 | From FEDEX 55788940&lt;br /&gt;     1 | Fed Ex ATTENTION 82103305&lt;br /&gt;     1 | From Fed Ex 0947757&lt;br /&gt;     1 | FedEx DELIVERY CONFIRMATION 399387&lt;br /&gt;     1 | Fed Ex Delivery Confirmation 15166031&lt;br /&gt;     1 | Fedex ATTENTION 692266&lt;br /&gt;     1 | FedEx: DELIVER CONFIRMATION - FAILED 229436&lt;br /&gt;     1 | From Fedex 490430&lt;br /&gt;     1 | FEDEX ATTENTION 021008&lt;br /&gt;     1 | DELIVERY CONFIRMATION FROM Fedex 443617&lt;br /&gt;     1 | FedEx Delivery Confirmation 73541619&lt;br /&gt;     1 | Fed Ex Delivery Confirmation 4746337&lt;br /&gt;     1 | DELIVERY CONFIRMATION FROM FedEx 571030&lt;br /&gt;     1 | FEDEX: DELIVER CONFIRMATION - FAILED 146965&lt;br /&gt;     1 | FEDEX id. 4571782&lt;br /&gt;     1 | FedEx ATTENTION 668706&lt;br /&gt;     1 | DELIVERY CONFIRMATION FROM Fed Ex 7294665&lt;br /&gt;     1 | From Fed Ex 072503&lt;br /&gt;     1 | Fed Ex DELIVERY CONFIRMATION 87980984&lt;br /&gt;     1 | From Fed Ex 04974153&lt;br /&gt;     1 | DELIVERY CONFIRMATION FROM Fed Ex 8260718&lt;br /&gt;     1 | Your FEDEX id. 095521&lt;br /&gt;     1 | LOVE-CARD from YOUR LOVE&lt;br /&gt;     1 | Your Fed Ex id. 11329550&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Love Card Version&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;The "Love card" version of the spam reads like this:&lt;br /&gt;&lt;br /&gt;-------&lt;br /&gt;&lt;br /&gt;GOOD AFTERNOON! Do you like games ?&lt;br /&gt;&lt;br /&gt;Service www. lovecard. ge Present New Game For Amateurs Strawberries&lt;br /&gt;This game is still freeware. You can find it in Attached. Please test it and send us Your comments and suggestions !&lt;br /&gt;With Best Wishes !.. www. love-card. org&lt;br /&gt;&lt;br /&gt;-------&lt;br /&gt;&lt;br /&gt;or&lt;br /&gt;&lt;br /&gt;-------&lt;br /&gt;&lt;br /&gt;Attention! Do you like games ?&lt;br /&gt;&lt;br /&gt;Service www. mylovecards. com Present New Game For Amateurs Strawberries&lt;br /&gt;This game is still freeware. You can find it in Attached. Please test it and send us Your comments and suggestions !&lt;br /&gt;With Best Wishes !.. www. love-card. org&lt;br /&gt;&lt;br /&gt;-----&lt;br /&gt;&lt;br /&gt;The "love card" version ends with "white on white" text in tiny letters that reads:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Are you tired of routine romance and love making? Are you looking for a little more fun and excitement? Games are light-hearted and lots of fun. They take the pressure off and allow you and your partner to really let loose. Whether you're trying to get to know each other better, spark the romance, or improve your sex life, a game is a fun way to do it! www. love-card. org is the recognised industry leader in adult games for lovers who want to explore a deeper level of intimacy, sexuality and romance. We have been offering couples in loving relationships pleasurable and educational entertainment to enhance their relationship since 1987. Developed with the assistance of professionals, our games and products are tasteful, sensitive and respectful.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;FedEx Version&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The "FedEx" version looks like this:&lt;br /&gt;&lt;br /&gt;GOOD DAY!&lt;br /&gt;DEAR CONSUMER , Delivery Confirmation: FAILED&lt;br /&gt;PLEASE PRINT OUT THE INVOICE COPY ATTACHED AND COLLECT THE PACKAGE AT OUR DEPARTMENT&lt;br /&gt;Pack it. Ship ip. No calculating , Your FedEx TEAM&lt;br /&gt; &lt;br /&gt;or&lt;br /&gt;&lt;br /&gt;Hello!&lt;br /&gt;DEAR USER , DELIVERY CONFIRMATION: FAILED&lt;br /&gt;PLEASE PRINT OUT THE INVOICE COPY ATTACHED AND COLLECT THE PACKAGE AT OUR DEPARTMENT&lt;br /&gt;With respect , FedEx .com Customer Services&lt;br /&gt;&lt;br /&gt;or &lt;br /&gt;&lt;br /&gt;Good day!&lt;br /&gt;DEAR USER , We were not able to delivery the post package&lt;br /&gt;Please print out the invoice copy attached and collect the package at our department&lt;br /&gt;Best Regards , Fedex Customer Services&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-3363879471331329103?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/3363879471331329103'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/3363879471331329103'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/07/mastercard-spam-leads-to-fake-av.html' title='MasterCard spam leads to Fake AV'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-336736464750424035</id><published>2011-07-17T04:42:00.000-07:00</published><updated>2011-07-17T05:12:04.577-07:00</updated><title type='text'>My Friend's Been Hacked!</title><content type='html'>Have you ever received an email like this?&lt;br /&gt;&lt;br /&gt;&lt;HR COLOR="GOLD"&gt;&lt;br /&gt;Subject: RE: URGENT RESPOND NEEDED‏&lt;br /&gt;&lt;br /&gt;Hello,&lt;br /&gt;I am sorry I didn't inform you about my traveling to Europe for a program called Empowering Youth to Fight Racism,HIV/AIDS,and Lack of Education,the program is taking place in three major countries in Europe which are Dublin,Scotland and England,I am persently in England,London.&lt;br /&gt;&lt;br /&gt;I misplaced my wallet on my way to the hotel where my money,and other valuable things were kept.I will like you to assist me with a soft loan urgently with the sum of $2,800 US Dollars to sort-out my hotel bills and get myself back home.&lt;br /&gt;&lt;br /&gt;I will appreciate whatever you can afford to send the money today.i'll pay you back as soon as i return,Let me know if you can assist. please use this information to send the money to me.I wait your quickly respond&lt;br /&gt;&lt;HR COLOR="GOLD"&gt;&lt;br /&gt;&lt;br /&gt;I posted a copy of that email on my blog in February of 2009 (See: &lt;a href="http://garwarner.blogspot.com/2009/02/traveler-scams-email-phishers-newest.html"&gt;Traveler Scams: Email Phishers Newest Scam&lt;/A&gt;).  Since that time ALMOST EVERY DAY I receive an email from someone thanking me for my post and telling me that one of their friends seems to have fallen victim.  Then they say "What do I do next?"&lt;br /&gt;&lt;br /&gt;Normally I tell them they need to contact their friend and have their friend report to their email provider that they have had their password stolen.&lt;br /&gt;&lt;br /&gt;Please note that this is DIFFERENT than just getting a weird email that says it came from a friend.  In this traveler scam, if you reply to the email, the bad guy will often reply with personal information about you "that only your friend could know."  That's because they are actually in your friend's email account reading emails from you to try to find a way to convince you to wire them money.&lt;br /&gt;&lt;br /&gt;Another indicator that someone may have had their email hacked is when there are several people on the "To:" or "CC:" line that you know your friend knows.  When spammers randomly forge a "from" address, it doesn't necessarily mean they have stolen your friend's password, but when SEVERAL of your friend's acquaintances are in the "To:" line, it means the criminal has access to your friend's address book or email messages.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Hotmail: My Friend's Been Hacked!&lt;/H3&gt;&lt;br /&gt;Microsoft has just announced this week a new way that you can help your friend (if both of you use hotmail.)  Dick Craddock writes in the "Inside Windows Live" blog on July 14th, &lt;a href="http://windowsteamblog.com/windows_live/b/windowslive/archive/2011/07/14/hey-my-friend-s-account-was-hacked.aspx"&gt;Hey!  My Friend's Account Was Hacked!&lt;/A&gt; about a new feature that is being offered to hotmail and live.com customers.&lt;br /&gt;&lt;br /&gt;With the new feature, when you are reading the offending email, you can pull down the "Mark As" menu and choose "My Friend's Been Hacked!:&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://windowsteamblog.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-53-82-metablogapi/0361.My_2D00_friends_2D00_been_2D00_hacked_2D00_on_2D00_the_2D00_Mark_2D00_as_2D00_menu_5F00_thumb_5F00_295FE0CE.jpg"&gt;&lt;br /&gt;&lt;br /&gt;When you take the time to mark the message like that, it sends a high priority request to Microsoft to put this account "on hold."   Now, there has to be some OTHER circumstances true as well, you can't use this to just cause trouble for people who annoy you, but when your report is combined with other factors about your friend's email usage -- such as sending an unusually high number of messages, or logging in from an IP in another country -- the account will be placed on hold.&lt;br /&gt;&lt;br /&gt;That immediately stops the criminal from being able to use the account to send spam, AND let's your friend begin an Account Recovery Process the next time they try to log in.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Yahoo! and Gmail?&lt;/H3&gt;&lt;br /&gt;What if your friend doesn't use Hotmail?&lt;br /&gt;&lt;br /&gt;Microsoft has now begun pushing the "My Friend's Been Hacked!" reports to Yahoo! and Gmail as well. So if YOU are a hotmail user, and your hacked friend is using Yahoo! or Gmail using the reporting mechanism on hotmail will still send an alert to Yahoo! or Google and let them know of the suspicious email you've received.&lt;br /&gt;&lt;br /&gt;Hopefully this will become a new industry standard practice and we'll be able to send reports from any of our mail clients!&lt;br /&gt;&lt;br /&gt;Here's some advice from other providers on what to do if a Friend seems to be compromised:&lt;br /&gt;&lt;br /&gt;- &lt;a href="http://mail.google.com/support/bin/topic.py?hl=en&amp;topic=29462"&gt;Gmail: Report A Security Problem&lt;/A&gt; &lt;br /&gt;&lt;br /&gt;- &lt;a href="http://knol.google.com/k/how-to-recover-a-hacked-or-compromised-gmail-account?pli=1#How_to_Recover_Your_Account"&gt;Google: How to Recover Your Email Account&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;- &lt;a href="http://www.facebook.com/security?sk=app_10442206389"&gt;Facebook Security&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;- &lt;a href="https://edit.yahoo.com/forgotroot/"&gt;Yahoo! Account Helper&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;(If you have a suggestion of a better link, please let me know . . .)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-336736464750424035?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/336736464750424035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/336736464750424035'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/07/my-friends-been-hacked.html' title='My Friend&apos;s Been Hacked!'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-2343320652050965448</id><published>2011-07-15T09:26:00.000-07:00</published><updated>2011-07-15T09:51:33.423-07:00</updated><title type='text'>FBI + Romanian DIICOT = 117 Search warrants and 100+ arrests</title><content type='html'>In one of the largest international cybercrime enforcement actions in history, the FBI and the Romanian DIICOT (Directorate for Investigating Infractions of Organized Crime and Terrorism) have performed at least 117 searches and arrested 21 in America and more than 90 in Romania.&lt;br /&gt;&lt;br /&gt;All across Romania, scenes such as this were being conducted:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/Romanian.arrested.jul14.jpg"&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/Romjul.1.jpg"&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/Romjul.2.jpg"&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/Romjul.3.jpg"&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/Romjul.4.jpg"&gt;&lt;br /&gt;&lt;br /&gt;The Romanian news source that provided the photos above shared this quote with Adrian Hood, Chief Prosecutor of DIICOT, Craiova Territorial Service:&lt;br /&gt;&lt;br /&gt;"Specifically, defendants are charged for activities from 2009 to 2011 involving posting notices of sale of fictitious, non-existent goods such as cars, motorcycles, boats, and electronics on e-commerce platforms such as www.eBay.com and www.craigslist.org through advertisements made with false information."&lt;br /&gt;&lt;br /&gt;(See the &lt;a href="http://www.adevarul.ro/locale/craiova/Craiova-_Perchezitii_ample_ale_politistilor_de_la_Crima_Organizata_si_Investigatii_Criminale_0_517148309.html"&gt;Original story&lt;/A&gt; for the Romanian original of that quote...&lt;br /&gt;&lt;br /&gt;The FBI has issued a press release on the matter today, &lt;a href="http://www.justice.gov/opa/pr/2011/July/11-crm-926.html"&gt;Organized Romanian Criminal Groups Targeted by DOJ and Romanian Law Enforcement&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;The case centers on criminals in Romania who would post luxury items and vehicles for sale on Internet auction websites, such as eBay.  They would then instruct the potential buyer that for safety of the transaction they would be using an escrow service and provide them instructions to wire the funds to the escrow service, rather than making their payment through the auction company.  US-based co-conspirators would then go pick up the money from American bank accounts.  These intermediaries are called "money mules" in the US, but in Romanian cybercrime parlance they are referred to as "arrows."&lt;br /&gt;&lt;br /&gt;According to the FBI Press Release . . . "Since May 2010, the FBI and the U.S. Attorney’s Office for the Southern District of Florida have arrested and prosecuted numerous individuals from Romania, Moldova and the United States allegedly involved in this fraud scheme.   Vadim Gherghelejiu, 29, of Moldova; Anatolie Bisericanu, 25, of Moldova; Jairo Osorno, 22, of Surfside, Fla.; Jason Eibinder, 22, of Sunny Isles Beach, Fla.; and Ciprian Jdera, 25, of Romania, have been convicted in the Southern District of Florida of conspiracy to commit wire fraud."&lt;br /&gt;&lt;br /&gt;On February 22, 2010, a Miami court returned an indictment against "Pedro Pulido, 41, of Pembroke Pines, Fla.; Ivan Boris Barkovic, 19, of Sunny Isles Beach; Beand Dorsainville, 20, of North Miami Beach, Fla.; Sergiu Petrov, aka “Serogia,” 27, of Moldova; Oleg Virlan, 32, of Moldova; Marian Cristea, 22, of Romania; and Andrian Olarita, 26, of Moldova, with conspiracy to commit wire fraud and substantive counts of wire fraud.    Pulido, Barkovic, Dorsainville and Olarita have pleaded guilty to conspiracy to commit wire fraud.   Petrov, Virlan and Cristea remain at large and are considered fugitives."&lt;br /&gt;&lt;br /&gt;Romanian news is buzzing today with news of many search warrants being issued all over Romania.  &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.adevarul.ro/locale/bucuresti/Perchezitii_in_Capitala_si_in_opt_orase_90_de_hoti_prinsi_de_FBI_si_adusi_la_DIICOT-_au_furat_pe_internet-de_la_americani-peste_20_de_milioane_de_dolari_0_517148293.html"&gt;FBI Searches Romania - 20 million dollars stolen by hackers in eight countries&lt;/A&gt; &lt;br /&gt;&lt;br /&gt;Photographers were present at many of today's Romanian arrests . . . &lt;br /&gt;&lt;br /&gt;Here a dentist, Horace Balanescu, and his wife are being arrested in Bumbesti-Jiu Romania:&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/Bumbesti.dentist.jpg"&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/Bumbesti.wife.jpg"&gt;&lt;br /&gt;(photos from "adevarul.ro")&lt;br /&gt;&lt;br /&gt;Romanian news says that there were more than 1,000 victims who collectively lost more than $20 million USD.&lt;br /&gt;&lt;br /&gt;We'll have more details here in the near future . . .&lt;br /&gt;&lt;br /&gt;Congratulations to all of the fine agents in Romania and the FBI who took part in this historical arrest, and to those at eBay and Craigslist and other companies who assisted with information.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-2343320652050965448?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/2343320652050965448'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/2343320652050965448'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/07/fbi-romanian-diicot-117-search-warrants.html' title='FBI + Romanian DIICOT = 117 Search warrants and 100+ arrests'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-503798458183613336</id><published>2011-06-25T06:11:00.000-07:00</published><updated>2011-06-25T20:07:43.983-07:00</updated><title type='text'>A New Car!  (or Zeus spam Campaign)</title><content type='html'>If you believe my email today, everyone is getting a new car but me.  &lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/NewCarSpam.jpg"&gt;&lt;br /&gt;&lt;br /&gt;There are actually many different spam message subjects that make up this campaign.  Those like the one above use a random person name in the subject line, like these:&lt;br /&gt;&lt;br /&gt;Remember [name]?&lt;br /&gt;It's [name]'s new car!&lt;br /&gt;Saw new [name]'s car?&lt;br /&gt;Do you remember [name]?&lt;br /&gt;&lt;br /&gt;There were also quite a few "non-random" ones.  Here's a sampling from yesterday's spam, when we received a total of more than 60,000 emails that are part of this malware distribution campaign:&lt;br /&gt;&lt;br /&gt; count |              subject&lt;br /&gt;-------+------------------------------------&lt;br /&gt;  1398 | info&lt;br /&gt;  1389 | Hello&lt;br /&gt;  1357 | look&lt;br /&gt;  1344 | Hello!&lt;br /&gt;  1343 | Hi!&lt;br /&gt;  1341 | hello!&lt;br /&gt;  1333 | Look!&lt;br /&gt;  1328 | hello&lt;br /&gt;  1320 | hello.&lt;br /&gt;  1314 | Hello.&lt;br /&gt;  1305 | hey buddy!&lt;br /&gt;  1286 | hi buddy!&lt;br /&gt;  1282 | Hey!&lt;br /&gt;   590 | Is this your boyfriend?&lt;br /&gt;   580 | Do you remember me?&lt;br /&gt;   577 | Remember me?&lt;br /&gt;   549 | Is This Your Boyfriend?&lt;br /&gt;   539 | Is this your girlfriend bro?&lt;br /&gt;   538 | Is This Your Girl Bro?&lt;br /&gt;   533 | Is This Your Boy?&lt;br /&gt;   529 | Is this your boy?&lt;br /&gt;   507 | Is this your girl bro?&lt;br /&gt;   487 | Is This Your Girlfriend Bro?&lt;br /&gt;   482 | Is this your girlfriend buddy?&lt;br /&gt;   480 | Is This your Girlfriend?&lt;br /&gt;&lt;br /&gt;Those numbers are the count of the email messages we received from that portion of the campaign that pretended to be related to LinkedIn.  In the graphic above, you can see that the "From" address is on "live.com" and the "Reply-To" is on "linkedin.com".  Actually neither one of those things were true.&lt;br /&gt;&lt;br /&gt;Here are the actual mail headers (although I've redacted a couple things from this one):&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/FakedEmailHeaders.jpg"&gt;&lt;br /&gt;&lt;br /&gt;In this image, the "fake" values are highlighted in green while the "real" values are highlighted in yellow.  This email did NOT come from LinkedIn's IP 63.211.90.176.  It really came from 173.200.78.57.  (Many hundreds of IPs were used.)&lt;br /&gt;&lt;br /&gt;We actually saw this same style of mail-header faking beginning last November, especially during a rampant &lt;a href="http://garwarner.blogspot.com/2010/11/usaa-phish-avalanche-uses-many.html"&gt;USAA Phishing campaign&lt;/A&gt; where the destination websites were all on '.tk' domains.  Although I didn't focus on that aspect in the story (instead we found the REAL sender IP addresses and wrote about those) it was partly because at the time I didn't understand how it was possible!&lt;br /&gt;&lt;br /&gt;All of the spam messages listed above, whether they are the "New Car" version or the "Is that Your Boyfriend?" or even the "Hello!" versions have a common website location being advertised.  They use random numbers in the hostname portion of the website address, but the all point to:&lt;br /&gt;&lt;br /&gt;    arcid_[RND#].oposumcruiser.com/arc/file/&lt;br /&gt;&lt;br /&gt;That website looks like this:&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/FakePhotoArchive.Zeus.jpg"&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;UPDATE!!&lt;/H3&gt;&lt;br /&gt;I've received an update from my friend Steven Burn who runs the websites of &lt;a href="http://www.it-mate.co.uk/"&gt;Ur I.T. Mate Group&lt;/A&gt;.  He pointed out to me that even if you don't download the .exe file from this page, you are still at risk just by visiting the site.  There is an IFRAME hidden in the source code of the page that directs all visitors to load the Blackhole Exploit Kit from another location.  As of this writing that other location is:&lt;br /&gt;&lt;br /&gt;    http://motorssmonito.com/forum.php?tp=778973f6b2977050 &lt;br /&gt;&lt;br /&gt;(Visit at your own risk - it WILL try to infect you! )&lt;br /&gt;&lt;br /&gt;The excellent folks at UCSB's Wepawet project provide this decoding of the page:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=6d8345e609c09499206999ba7295cb9e&amp;t=1309057037&amp;type=js"&gt;Wepawet decode of the MotorSSMonito blackhole exploit kit&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;which shows all the little tricks it tries to use to infect you, including loading malicious .jar files, .pdf files, .avi files, &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;/End Update - Thank you, Mr. Burn!&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;One of the characteristics of the "Avalanche" botnet that we believed was associated with the USAA phish back in November was that the destination website is "Fast Flux" hosted -- meaning that the IP address is being constantly changed by modifying the nameserver to resolve the domain name to many different locations.&lt;br /&gt;&lt;br /&gt;The first time I looked at this website, it was resolving to the IP address 112.71.69.76 in Japan.  But when I asked the nameserver for its location, it gave back eight different IP addresses:&lt;br /&gt;&lt;br /&gt;80.171.37.243&lt;br /&gt;81.203.1.104&lt;br /&gt;82.159.38.56&lt;br /&gt;85.86.48.130&lt;br /&gt;91.117.147.33&lt;br /&gt;112.71.69.76&lt;br /&gt;114.183.247.117&lt;br /&gt;217.50.208.196&lt;br /&gt;&lt;br /&gt;Only a few minutes later when I rechecked, I found the additional IP addresses:&lt;br /&gt;&lt;br /&gt;83.213.31.242&lt;br /&gt;90.168.201.126&lt;br /&gt;95.125.232.109&lt;br /&gt;212.225.173.8&lt;br /&gt;&lt;br /&gt;all resolving the "oposumcruiser.com" random hostnames.&lt;br /&gt;&lt;br /&gt;One of the many projects we have at the UAB Computer Forensics Research Lab is a Fast Flux tracker.  Some of the other domains that are currently fluxing on this same space include perfectcheck2011.com, safeyourwork.net, personalsyscheck.com and safetylife2011.org which use the nameservers ns1.lonfd.net and ns1.cazonet.com.  Most of those are autoforwarders for pharmaceutical websites such as sportsmedsrxpills.net which purports to be the "Canadian Health &amp; Care Mall".&lt;br /&gt;&lt;br /&gt;The fake website offers a download for you as an executable file "archive.exe"&lt;br /&gt;&lt;br /&gt;According to the AV products on the VirusTotal website, this is either the Zbot trojan (commonly known as Zeus) or Kazy.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=b9625af9bd04030c711749e0ad8f434cba5078c771e1b34142b9671dab7f04d2-1309007252#"&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/VirusTotal.jun25.jpg"&gt;&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;(Click the image to go to the &lt;a href="http://www.virustotal.com/file-scan/report.html?id=b9625af9bd04030c711749e0ad8f434cba5078c771e1b34142b9671dab7f04d2-1309007252#"&gt;VirusTotal Report&lt;/A&gt; for this malware &lt;br /&gt;&lt;br /&gt;MD5: a653ef80a47f5ec646a2ce0fdbc1068d&lt;br /&gt;&lt;br /&gt;Trojan-Spy.Win32.Zbot.buax, Gen:Variant.Kazy.28222, Win32/Spy.Zbot.YW,  Trojan/Win32.Zbot&lt;br /&gt;&lt;br /&gt;I put the malware in our Malware Analysis VM and watched to see what it would do.&lt;br /&gt;&lt;br /&gt;The version of the malware that I self-infected with made DNS calls for&lt;br /&gt;the following domains, many of which have not yet been registered.&lt;br /&gt;&lt;br /&gt;lrnsxmztnqiomiq.com&lt;br /&gt;rqnorekziuhmsxr.biz&lt;br /&gt;rqnorekziuhmsxr.org&lt;br /&gt;vlolhmcjlpqntm.net&lt;br /&gt;vlolhmcjlpqntm.com&lt;br /&gt;zqpyuykzovrsjw.info&lt;br /&gt;zqpyuykzovrsjw.biz&lt;br /&gt;wzmkrojrutomsg.net&lt;br /&gt;wzmkrojrutomsg.org&lt;br /&gt;nnpgpskekyrtyoq.info&lt;br /&gt;nnpgpskekyrtyoq.com&lt;br /&gt;stqbbjuqsoefcpcq.biz&lt;br /&gt;stqbbjuqsoefcpcq.com&lt;br /&gt;xljpkdlnzniocjpu.info&lt;br /&gt;&lt;br /&gt;It also modified many registry keys, primary related to Outlook Express, which means there was probably going to be some spamming going on if I left the infection up.&lt;br /&gt;&lt;br /&gt;The only one of these I can tell that WAS registered was here...using a&lt;br /&gt;privacy service.&lt;br /&gt;&lt;br /&gt;Domain Name: LRNSXMZTNQIOMIQ.COM&lt;br /&gt;&lt;br /&gt;   Administrative Contact:&lt;br /&gt;      Reinecker, Beverly  ap9cm76v4sv@nameprivacy.com&lt;br /&gt;      ATTN:&lt;br /&gt;      P.O. Box 430 c/o NameSecure&lt;br /&gt;      Herndon, VA 20171-430&lt;br /&gt;      US&lt;br /&gt;      570-708-8782&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;When it was live, it was hosted on 72.249.171.121.&lt;br /&gt;&lt;br /&gt;Also seen on that IP, according to bfk.de, are:&lt;br /&gt;&lt;br /&gt;www.realgirlfights.org  CNAME  realgirlfights.org&lt;br /&gt;lrnsxmztnqiomiq.com  A  72.249.171.121&lt;br /&gt;wqonlrwkuswjzmm.net  A  72.249.171.121&lt;br /&gt;lmnqnxypfulhgxo.biz  A  72.249.171.121&lt;br /&gt;kmxpiylvojgjcus.biz  A  72.249.171.121&lt;br /&gt;&lt;br /&gt;That IP is Colo4Dallas LP (AS36024) in Dallas, Texas.&lt;br /&gt;&lt;br /&gt;Steven Burn provided the following list of related domains, as well as the path which hosts their respective badness.  Again, please don't follow these links unless you are a malware researcher in a safe environment.&lt;br /&gt;&lt;br /&gt;cgywgtcwpngrzgk.net/news/?s=195341&lt;br /&gt;cpgfkybtkljjwvsk.org/news/?s=195341&lt;br /&gt;futplqwsqqiopntn.com/news/?s=195341&lt;br /&gt;ijqrqinymhjsvr.net/news/?s=195341&lt;br /&gt;imwftfprsbxzgiy.info/news/?s=195341&lt;br /&gt;iruwoekurjzrpko.biz/news/?s=195341&lt;br /&gt;jptptmlpqnzdnpl.biz/news/?s=195341&lt;br /&gt;jtpknvosaiwoxqs.info/news/?s=195341&lt;br /&gt;jwqqrkosoqqglvpk.biz/news/?s=195341&lt;br /&gt;jxatmxeojvhwhvd.com/news/?s=195341&lt;br /&gt;ktznowypsmswqtjl.net/news/?s=195341&lt;br /&gt;kxzjfqomtyjhhhzr.com/news/?s=195341&lt;br /&gt;lhourmoptjoejd.info/news/?s=195341&lt;br /&gt;lqwryghqqpiujsp.com/news/?s=195341&lt;br /&gt;mjeqpkukusnkkhtm.info/news/?s=195341&lt;br /&gt;mpwpxgmpjqkrpfzd.biz/news/?s=195341&lt;br /&gt;mrjuqpqqzqikin.org/news/?s=195341&lt;br /&gt;nfumumsidtqtynr.com/news/?s=195341&lt;br /&gt;oopmeozgtsxerenn.com/news/?s=195341&lt;br /&gt;orelrxnwtuiuplhn.biz/news/?s=195341&lt;br /&gt;ounwukdlrpflento.com/news/?s=195341&lt;br /&gt;pluufpyllzrqpnot.com/news/?s=195341&lt;br /&gt;ppjjvmomiiwtkyn.com/news/?s=195341&lt;br /&gt;prminhfvfmsckzjw.info/news/?s=195341&lt;br /&gt;psiscguokswppvys.biz/news/?s=195341&lt;br /&gt;pxcoprkgsoeyoiej.info/news/?s=195341&lt;br /&gt;quujzvhhutfvtlq.info/news/?s=195341&lt;br /&gt;rcjemwpzhygppmuo.net/news/?s=195341&lt;br /&gt;rggfymzrkzpnpsjl.com/news/?s=195341&lt;br /&gt;rheovalxkdmspe.net/news/?s=195341&lt;br /&gt;rhtjdemtypbpow.com/news/?s=195341&lt;br /&gt;rnosovkotqwbk.info/news/?s=195341&lt;br /&gt;rpjrewwqsditwtky.org/news/?s=195341&lt;br /&gt;rwfstvftrzwwtjxu.info/news/?s=195341&lt;br /&gt;rxtrpjvcuikyipt.net/news/?s=195341&lt;br /&gt;sklyzjonvkikpjt.org/news/?s=195341&lt;br /&gt;soilvjyksytnfp.net/news/?s=195341&lt;br /&gt;ssmkoqkrgimsnwe.com/news/?s=195341&lt;br /&gt;tjtoehpzjmtnigs.net/news/?s=195341&lt;br /&gt;ttzoxhbzvgpijlwk.biz/news/?s=195341&lt;br /&gt;twsrnyyfnvrqhht.org/news/?s=195341&lt;br /&gt;ydvkmqunnnnwqop.info/news/?s=195341&lt;br /&gt;yjlmfeinqhupvtnh.info/news/?s=195341&lt;br /&gt;yphxjkymmnqynogh.com/news/?s=195341&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-503798458183613336?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/503798458183613336'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/503798458183613336'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/06/new-car-or-zeus-spam-campaign.html' title='A New Car!  (or Zeus spam Campaign)'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-7290498013402599944</id><published>2011-05-16T06:41:00.001-07:00</published><updated>2011-05-16T09:38:46.647-07:00</updated><title type='text'>ACH Spammer switches to Shortened URLs</title><content type='html'>For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domains in place for a campaign that we have been calling "NACHA Spam".&lt;br /&gt;&lt;br /&gt;In this campaign, which we first wrote about in November 2009 (see: &lt;a href="http://garwarner.blogspot.com/2009/11/newest-zeus-nacha-electronic-payments.html"&gt;Newest Zeus: NACHA Electronic Payments&lt;/A&gt;, the criminals send emails suggesting that an Automated Clearing House (ACH) payment has failed.  It is thought that this may be a method of screening recipients as only people who deal with money transfer on a regular basis would be familiar with NACHA as having authority over ACH payments.&lt;br /&gt;&lt;br /&gt;In more recent versions of the campaign, including the one we wrote about in March 2011 (see: &lt;a href="http://garwarner.blogspot.com/2011/03/more-ach-spam-from-nacha.html"&gt;More ACH Spam from NACHA&lt;/A&gt;) we have seen dozens or even hundreds of newly created domain names used to host the malicious content.&lt;br /&gt;&lt;br /&gt;Here's a sample of the email body:&lt;br /&gt;&lt;br /&gt;&lt;HR COLOR="GOLD"&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;&lt;IMG SRC="http://nacha.org/images/nacha_logo.gif"&gt;&lt;br /&gt;The ACH transfer (ID: 1514969569958), recently initiated from your checking account (by you or any other person), was canceled by the Electronic Payments Association.&lt;br /&gt;&lt;br /&gt;Rejected transaction&lt;br /&gt;Transaction ID:  1514969569958&lt;br /&gt;Reason for rejection  See details in the report below&lt;br /&gt;Transaction Report  report_1514969569958.pdf.exe (self-extracting archive, Adobe PDF)&lt;br /&gt;&lt;br /&gt;13450 Sunrise Valley Drive, Suite 100 Herndon, VA 20171 (703) 561-1100&lt;br /&gt;&lt;br /&gt;2011 NACHA - The Electronic Payments Association&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;HR COLOR="GOLD"&gt;&lt;br /&gt;&lt;br /&gt;This morning's most popular subjects:&lt;br /&gt;&lt;br /&gt; count |         subject          &lt;br /&gt;-------+--------------------------&lt;br /&gt;   159 | ACH payment canceled&lt;br /&gt;   144 | ACH transfer rejected&lt;br /&gt;   143 | ACH payment rejected&lt;br /&gt;   143 | Rejected ACH payment&lt;br /&gt;   137 | Rejected ACH transaction&lt;br /&gt;   137 | ACH Transfer canceled&lt;br /&gt;   135 | Rejected ACH transfer&lt;br /&gt;   131 | Your ACH transfer&lt;br /&gt;   131 | ACH transaction canceled&lt;br /&gt;   130 | Your ACH transaction&lt;br /&gt;(10 rows)&lt;br /&gt;&lt;br /&gt; count | sender_email&lt;br /&gt;-------+-------------&lt;br /&gt;   135 | risk@nacha.org&lt;br /&gt;   134 | alerts@nacha.org&lt;br /&gt;   134 | risk_manager@nacha.org&lt;br /&gt;   133 | alert@nacha.org&lt;br /&gt;   133 | admin@nacha.org&lt;br /&gt;   129 | transactions@nacha.org&lt;br /&gt;   124 | ach@nacha.org&lt;br /&gt;   122 | payment@nacha.org&lt;br /&gt;   120 | transfers@nacha.org&lt;br /&gt;   117 | payments@nacha.org&lt;br /&gt;   109 | info@nacha.org&lt;br /&gt;(11 rows)&lt;br /&gt;&lt;br /&gt;The "new" feature of today's spam campaign is that the criminals have begun using URL shortening services to do their redirection.  Although this is new for the current campaign, we've seen it before.  We wrote a technical report on the subject last fall called &lt;a href="http://www.cis.uab.edu/forensics/TechReports"&gt;URL Shorteners Used by Online Drug Dealers&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;So far this morning, we've observed 34 different URL shortening services in play on this campaign:&lt;br /&gt;&lt;br /&gt; count |     machine     &lt;br /&gt;-------+-----------------&lt;br /&gt;   116 | 2mb.eu&lt;br /&gt;    93 | p1nk.me&lt;br /&gt;    92 | 80p.eu&lt;br /&gt;    92 | mzan.si&lt;br /&gt;    90 | linkr.fr&lt;br /&gt;    88 | redir.ec&lt;br /&gt;    84 | 2.gp&lt;br /&gt;    80 | udanax.org&lt;br /&gt;    79 | ks.gs&lt;br /&gt;    71 | whir.li&lt;br /&gt;    71 | qr.net&lt;br /&gt;    70 | TinyBP.com&lt;br /&gt;    68 | spedr.com&lt;br /&gt;    68 | urlzip.fr&lt;br /&gt;    66 | tiny.ly&lt;br /&gt;    60 | shortn.me&lt;br /&gt;    48 | mx.vc&lt;br /&gt;    16 | urli.nl&lt;br /&gt;    11 | snipurl.com&lt;br /&gt;     6 | shrt.st&lt;br /&gt;     3 | gd.is&lt;br /&gt;     3 | virg10.com&lt;br /&gt;     2 | rurls.ru&lt;br /&gt;     2 | zipurl.fr&lt;br /&gt;     2 | lu2su.net&lt;br /&gt;     1 | nutshellurl.com&lt;br /&gt;     1 | surl.hu&lt;br /&gt;     1 | icy.tsd.to&lt;br /&gt;     1 | squeerl.net&lt;br /&gt;     1 | 3cm.kz&lt;br /&gt;     1 | tuit.in&lt;br /&gt;     1 | tqb.qlnk.net&lt;br /&gt;     1 | mi13.tk&lt;br /&gt;     1 | minu.me&lt;br /&gt;(34 rows)&lt;br /&gt;&lt;br /&gt;Some of these are &lt;br /&gt;&lt;br /&gt;A full list of the more than 1,000 shortened URLs we've seen follows.  Remember, these are MALICIOUS URLs.  Don't go there if you aren't trained to deal with this kind of stuff.&lt;br /&gt;&lt;br /&gt; count |     machine     |     path     &lt;br /&gt;-------+-----------------+--------------&lt;br /&gt;     5 | spedr.com       | /4y7SQSmS&lt;br /&gt;     5 | redir.ec        | /tYvk&lt;br /&gt;     4 | snipurl.com     | /27vmxz&lt;br /&gt;     4 | redir.ec        | /EcPZ&lt;br /&gt;     4 | TinyBP.com      | /15kcx&lt;br /&gt;     4 | 2mb.eu          | /TUQBY8&lt;br /&gt;     4 | udanax.org      | /ZPLf&lt;br /&gt;     3 | 2mb.eu          | /W8Li1F&lt;br /&gt;     3 | mzan.si         | /GwQm&lt;br /&gt;     3 | qr.net          | /b4e0&lt;br /&gt;     3 | linkr.fr        | /rLao&lt;br /&gt;     3 | tiny.ly         | /dPnJ&lt;br /&gt;     3 | TinyBP.com      | /53wi&lt;br /&gt;     3 | whir.li         | /3z7g&lt;br /&gt;     3 | spedr.com       | /G9mJzD3W&lt;br /&gt;     3 | 2mb.eu          | /T2mMP3&lt;br /&gt;     3 | linkr.fr        | /Jw7M&lt;br /&gt;     3 | udanax.org      | /ZP0F&lt;br /&gt;     3 | urlzip.fr       | /W0T&lt;br /&gt;     3 | 80p.eu          | /ip&lt;br /&gt;     3 | virg10.com      | /6t6&lt;br /&gt;     3 | qr.net          | /b4ev&lt;br /&gt;     3 | 2mb.eu          | /fKVGJX&lt;br /&gt;     3 | mzan.si         | /N56x&lt;br /&gt;     3 | shortn.me       | /igWl&lt;br /&gt;...&lt;br /&gt;(1080 rows)&lt;br /&gt;&lt;br /&gt;(List truncated in interest of space -- for the full list of shortened URLs, click here:  &lt;a href="http://www.cis.uab.edu/forensics/blog/ACH.shortened.urls.txt"&gt;ACH.shortened.urls.txt&lt;/A&gt;.)&lt;br /&gt;&lt;br /&gt;While we haven't followed every link, all that we have followed so far redirected to a fake forum page on mnuyspe.co.be (193.105.121.158) where "drive-by" exploits are attempted.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-7290498013402599944?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/7290498013402599944'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/7290498013402599944'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/05/ach-spammer-switches-to-shortened-urls.html' title='ACH Spammer switches to Shortened URLs'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-8129188600010603294</id><published>2011-05-04T18:15:00.000-07:00</published><updated>2011-05-05T06:05:05.040-07:00</updated><title type='text'>Help stop the Osama bin Laden Videos on Facebook</title><content type='html'>If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with invitations to watch a video of Osama bin Laden being killed.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/OsamaFB.Examples.jpg"&gt;&lt;br /&gt;&lt;br /&gt;The behavior of this particular scam is too cause a link to be posted BY YOU on all of your friends' walls.  (There is another popular one going around -- "See Who Viewed Your Profile" -- that behaves in the same way.  &lt;a href="https://www.facebook.com/help/?faq=12903"&gt;Facebook confirms&lt;/A&gt; that there is no app that can do that, and encourages us to use the "REPORT" feature when we see that. &lt;br /&gt;&lt;br /&gt;If you click the link, many geeky "redirections" (described at end of article) happen before you end up on a page that looks like this:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/OsamaFB.Destination.jpg"&gt;&lt;br /&gt;&lt;br /&gt;The danger starts if you click "Watch Video".  DON'T DO IT!&lt;br /&gt;&lt;br /&gt;While it would be interesting to explore the Cross Site Scripting vulnerability that allows this to happen, the more important thing to share is "what should a FaceBook user who sees this activity do about this offending post on their wall?"&lt;br /&gt;&lt;br /&gt;Whenever you see something objectionable on your wall, the thing to do is REPORT IT!&lt;br /&gt;&lt;br /&gt;Hover your mouse over a message on your wall, and a grey "X" will appear at the top right of the message.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/OsamaFB.Report1.jpg"&gt;&lt;br /&gt;&lt;br /&gt;When you click the "X" by the top right corner of the wall post, you are presented with a drop down menu.  We're going to choose the bottom item -- "Report As Abuse"&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/OsamaFB.Report1b.jpg"&gt;&lt;br /&gt;&lt;br /&gt;Since the post is not "about me", we go to the lower section and choose "Spam or scam"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/OsamaFB.Report3.jpg"&gt;&lt;br /&gt;&lt;br /&gt;When we click "OK" we get an option to block the user.  Since this is an innocent mistake by our friend, we don't want to "block" the friend, so just check the bottom box that says "Report to Facebook."  If our friend is the sort of helpless, clueless individual that clicks on everything they see, eventually we would want to block this friend.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/OsamaFB.Report2.jpg"&gt;&lt;br /&gt;&lt;br /&gt;We get a nice "Thank you" from our friends at Facebook Security!  These really help the team!  They get the messages and use them to prioritize what things need to be addressed.  If many reports are received for the same link, or about the same user, those things get addressed more quickly.  Different types of reports go to different sub-groups so just because they are busy helping fight something like today's report doesn't mean that they ignore cyber-bullying.&lt;br /&gt;&lt;br /&gt;Facebook WANTS YOU to report things that bother you.  That's how they keep a clean neighborhood.&lt;br /&gt;&lt;br /&gt;Help them help you.  REPORT SCAMS!&lt;br /&gt;&lt;br /&gt;Then take a moment more and send your friend a friendly message letting them know what's going on.  They might want to let the rest of their friends know.&lt;br /&gt;&lt;br /&gt;Facebook security has several recommendations, including a couple that I honestly wouldn't have thought of.  (I'll put those first)&lt;br /&gt;&lt;br /&gt;&lt;OL&gt;&lt;br /&gt;&lt;LI&gt;Unlike the page which tricked you into showing fake video and report them immediately to Facebook. -- in addition to posting the message to your friends' walls, this tricky Facebook worm causes you to "Like" its page.  The more "Likes" a page has, the more people are convinced it's real, so it is helpful to go "UNLIKE" the page.  (if you've liked it, it will be a choice on the left side menu.)&lt;br /&gt;&lt;br /&gt;&lt;LI&gt;If a friend is posting suspicious messages to your wall, they may have malicious software on their computer, or may have clicked something bad themselves.  &lt;a href="https://www.facebook.com/help/?faq=14396"&gt;Facebook Help&lt;/A&gt; says the best thing to do is tell your friend to contact Facebook Help.&lt;br /&gt;&lt;br /&gt;&lt;LI&gt;If YOU are the one posting the message, this Facebook Help post is for you:  &lt;a href="https://www.facebook.com/help/?faq=14396"&gt;Wall posts were sent from my account, and I didn’t send them.&lt;/A&gt;  It has helpful hints about anti-virus, not clicking on spam, and how to reset your password.&lt;br /&gt;&lt;br /&gt;&lt;LI&gt;Have up-to-date anti-virus software&lt;br /&gt;&lt;br /&gt;&lt;LI&gt;Keep an eye for messages that often feature misspellings, poor grammar and nonstandard English.  If it doesn't look like a message your friend would type, REPORT IT!  It may be related to malware or a malicious app that is using your friend's account!&lt;br /&gt;&lt;br /&gt;&lt;LI&gt;Do not open spam mails, including clicking links contained within those messages.&lt;br /&gt;&lt;br /&gt;&lt;LI&gt;Don’t copy and paste any scripts in your Facebook profile. Several scams have worked by encouraging you to paste something odd in your profile.  Some of those scripts install apps, grant permissions, or make you do things you wouldn't want to do!&lt;br /&gt;&lt;br /&gt;&lt;LI&gt;If you’re using Chrome, make sure you don’t paste any scripts in your browser bar, as the browser tries to preload anything you type in the ‘awesome’ bar.&lt;/OL&gt;&lt;br /&gt;&lt;br /&gt;&lt;HR COLOR="GOLD"&gt;&lt;br /&gt;Geek Alert!&lt;br /&gt;&lt;br /&gt;Here's an example stream of what happens if you click one of these links ... &lt;br /&gt;In this case, the link is going to pass through several rounds of redirection, which we can see by doing a "wget" of the destination URL.  A "301" command makes your browser move on to another web address without really adding any new content.&lt;br /&gt;&lt;br /&gt;In the top example, the destination URL is tinyurl.com/3b8uayr&lt;br /&gt;&lt;br /&gt;wget http://tinyurl.com/3b8uayr&lt;br /&gt;Resolving tinyurl.com... 64.62.243.89, 64.62.243.90&lt;br /&gt;Connecting to tinyurl.com|64.62.243.89|:80... connected.&lt;br /&gt;HTTP request sent, awaiting response... 301 Moved Permanently&lt;br /&gt;Location: http://zamakoko.mo.tl/ [following]&lt;br /&gt;--19:51:27--  http://zamakoko.mo.tl/&lt;br /&gt;           =&gt; `index.html'&lt;br /&gt;Resolving zamakoko.mo.tl... 174.122.44.67&lt;br /&gt;Connecting to zamakoko.mo.tl|174.122.44.67|:80... connected.&lt;br /&gt;HTTP request sent, awaiting response... 301 Moved Permanently&lt;br /&gt;Location: http://on.fb.me/jM9tNF [following]&lt;br /&gt;--19:51:47--  http://on.fb.me/jM9tNF&lt;br /&gt;           =&gt; `jM9tNF'&lt;br /&gt;Resolving on.fb.me... 168.143.174.97&lt;br /&gt;Connecting to on.fb.me|168.143.174.97|:80... connected.&lt;br /&gt;HTTP request sent, awaiting response... 301 Moved Permanently&lt;br /&gt;Location: http://www.facebook.com/pages/0sama-tape/121566207922629 [following]&lt;br /&gt;--19:51:59--  http://www.facebook.com/pages/0sama-tape/121566207922629&lt;br /&gt;           =&gt; `121566207922629'&lt;br /&gt;Resolving www.facebook.com... 69.63.189.16&lt;br /&gt;Connecting to www.facebook.com|69.63.189.16|:80... connected.&lt;br /&gt;HTTP request sent, awaiting response... 302 Moved Temporarily&lt;br /&gt;Location: http://www.facebook.com/common/browser.php [following]&lt;br /&gt;--19:52:05--  http://www.facebook.com/common/browser.php&lt;br /&gt;           =&gt; `browser.php'&lt;br /&gt;Connecting to www.facebook.com|69.63.189.16|:80... connected.&lt;br /&gt;HTTP request sent, awaiting response... 200 OK&lt;br /&gt;Length: unspecified [text/html]&lt;br /&gt;&lt;br /&gt;    [ &lt;=&gt;                                                     ] 11,771        --.--K/s&lt;br /&gt;19:52:24 (1.40 MB/s) - `browser.php' saved [11771]&lt;br /&gt;&lt;br /&gt;Which leaves us sitting here:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.cis.uab.edu/forensics/blog/OsamaFB.Destination.jpg"&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-8129188600010603294?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/8129188600010603294'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/8129188600010603294'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/05/help-stop-osama-bin-laden-videos-on.html' title='Help stop the Osama bin Laden Videos on Facebook'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-6846091280333128848</id><published>2011-04-13T21:25:00.000-07:00</published><updated>2011-04-13T22:57:41.898-07:00</updated><title type='text'>Bold FBI Move Shutters COREFLOOD Bot</title><content type='html'>In February 2005, John Leyden told the story of &lt;a href="http://www.theregister.co.uk/2005/02/08/e-banking_trojan_lawsuit/"&gt;Joe Lopez&lt;/A&gt; a 42 year old businessman in Miami Florida who sued his bank after having $90,348 wired out of his account to Parex Bank in Riga, Latvia.  The US Secret Service examined his computer and found that his system was infected with the Coreflood trojan.&lt;br /&gt;&lt;br /&gt;Where did the money go?  According to USA Today's Byron Acohido, someone named &lt;a href="http://www.usatoday.com/tech/news/computersecurity/2005-11-02-cybercrime-online-accounts_x.htm"&gt;Yanson Arnold&lt;/A&gt; withdrew $20,000 of the money three days later.&lt;br /&gt;&lt;br /&gt;The story was featured on NBC Nightly News on December 14, 2004, in a story called &lt;a href="http://www.msnbc.msn.com/id/6713753/ns/nightly_news/#"&gt;The Fleecing Of America&lt;/A&gt; which indicated the money had been stolen via the CoreFlood Virus.&lt;br /&gt;&lt;br /&gt;In June of 2008, Joe Stewart, International Grandmaster of Malware Reverse Engineering, released a report called &lt;a href="http://www.secureworks.com/research/threats/coreflood/?threat=coreflood"&gt;Coreflood/AFcore Trojan Analysis&lt;/A&gt;.  He started his report by calling attention to five highlights:&lt;br /&gt;&lt;br /&gt;   1. One of the oldest botnets in continuous operation (+6 years)&lt;br /&gt;   2. Motive turned from DDoS to selling anonymity services to full-fledged bank fraud&lt;br /&gt;   3. Entire Windows domains infected at once (thousands of computers at some organizations)&lt;br /&gt;   4. Over 378,000 computers infected during 16-month time frame&lt;br /&gt;   5. Infected businesses, hospitals, government organizations, and even a state police agency&lt;br /&gt;&lt;br /&gt;When Joe worked with Spamhaus back then to investigate an active C&amp;C they found FIFTY GIGABYTES of compressed data, stolen over the course of two years, with a MySQL database that the criminal was using to track which information it had stolen from 378,758 unique bots over a period of 16 months.  At one point, Joe's report shows "a major hotel chain" with over 7,000 infected computers, and a State Police agency with over 110 infected computers!  Among the data stolen were 8,485 bank passwords, 3,233 credit card passwords, 151,000 email passwords, and 58,391 social networking site passwords. At that time, in 2008, the controller domains were: mcupdate.net, joy4host.com, and antrexhost.com.&lt;br /&gt;&lt;br /&gt;Here we are in April 2011 -- almost three years later, and "antrexhost.com" is still an active C&amp;C for the domain, which is still stealing money, despite being featured on NBC Nightly News, USA Today, and discussed by name by the White House's Howard Schmidt.   &lt;br /&gt;&lt;br /&gt;All of that may have come to an end today, as announced by today's FBI Press Release headline was &lt;a href="http://www.justice.gov/opa/pr/2011/April/11-crm-466.html"&gt;Department of Justice Takes Action to Disable International Botnet&lt;/A&gt;.  The botnet in question is known as Coreflood, and according to &lt;a href="http://newhaven.fbi.gov/dojpressrel/pressrel11/pdf/nh041311_4.pdf"&gt;court papers&lt;/A&gt; released by the FBI's New Haven Field Office, a pair of Command &amp; Control servers, located at 207.210.74.74 and 74.63.232.233 were controlling 2,336,542 infected computers as of February 2010.  Of those, 1,853,005 were located in the United States.&lt;br /&gt;&lt;br /&gt;207.210.74.74 is a server on the Global Net Access system, that hosted a domain called jane.unreadmsg.net.  vaccina.medinnovation.org was the C&amp;C name on 74.63.232.233&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From the request for a Temporary Restraining Order filed by Assistant US Attorney Edward Chang:&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;12. The Coreflood Botnet was used, among other things,&lt;br /&gt;to commit financial fraud. Infected computers in the Coreflood&lt;br /&gt;Botnet automatically recorded the keystrokes and Internet&lt;br /&gt;communications of unsuspecting users, including online banking&lt;br /&gt;credentials and passwords. The stolen data was then sent to one&lt;br /&gt;or more Coreflood C&amp;C servers, where it was stored for review by&lt;br /&gt;the Defendants and their co-conspirators. The Coreflood C&amp;C&lt;br /&gt;servers also stored the network and operating system&lt;br /&gt;characteristics of the infected computers. The Defendants and&lt;br /&gt;their co-conspirators used the stolen data, including online&lt;br /&gt;banking credentials and passwords, to direct fraudulent wire&lt;br /&gt;transfers from the bank accounts of their victims.&lt;br /&gt;&lt;br /&gt;13. The victims of the fraud scheme described above&lt;br /&gt;included, inter alia:&lt;br /&gt;&lt;br /&gt;a. A real estate company in Michigan, from whose bank&lt;br /&gt;account there were fraudulent wire transfers made in a&lt;br /&gt;total amount of approximately $115,771;&lt;br /&gt;&lt;br /&gt;b. A law firm in South Carolina, from whose bank account&lt;br /&gt;there were fraudulent wire transfers made in a total&lt;br /&gt;amount of approximately $78,421;&lt;br /&gt;&lt;br /&gt;c. An investment company in North Carolina, from whose&lt;br /&gt;bank account there were fraudulent wire transfers made&lt;br /&gt;in a total amount of approximately $151,201; and&lt;br /&gt;&lt;br /&gt;d. A defense contractor in Tennessee, from whose bank&lt;br /&gt;account there were fraudulent wire transfers attempted&lt;br /&gt;in a total amount of approximately $934,528, resulting&lt;br /&gt;in an actual loss of approximately $241,866.&lt;br /&gt;&lt;br /&gt;The full extent of the financial loss caused by the Coreflood &lt;br /&gt;Botnet is not known, due in part to the large number of infected&lt;br /&gt;computers and the quantity of stolen data.&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here are some of the hostnames that were used by Coreflood -- some dates are in the future, indicating that the bot had the ability to change to new names over time, to prevent just the sort of shutdown that occurred today:&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;&lt;br /&gt;C&amp;C SERVER ASSIGNED 207.210.74.74&lt;br /&gt;&lt;TABLE&gt;&lt;TR&gt;&lt;TD&gt;Month&lt;/TD&gt;&lt;TD&gt;Primary Domain&lt;/TD&gt;&lt;TD&gt; Alternate Domain&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1/2011&lt;/TD&gt;&lt;TD&gt; a-gps.vip-studions.net&lt;/TD&gt;&lt;TD&gt; old.antrexhost.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2/2011&lt;/TD&gt;&lt;TD&gt; dru.realgoday.net&lt;/TD&gt;&lt;TD&gt; marker.antrexhost.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;3/2011&lt;/TD&gt;&lt;TD&gt; brew.fishbonetree.biz&lt;/TD&gt;&lt;TD&gt; spamblocker.antrexhost.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4/2011&lt;/TD&gt;&lt;TD&gt; jane.unreadmsg.net&lt;/TD&gt;&lt;TD&gt; ads.antrexhost.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;5/2011&lt;/TD&gt;&lt;TD&gt; exchange.stafilocox.net&lt;/TD&gt;&lt;TD&gt; cafe.antrexhost.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;6/2011&lt;/TD&gt;&lt;TD&gt; ns1.diplodoger.com&lt;/TD&gt;&lt;TD&gt; coffeeshop.antrexhost.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;7/2011&lt;/TD&gt;&lt;TD&gt; a-gps.vip-studions.net&lt;/TD&gt;&lt;TD&gt; old.antrexhost.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;8/2011&lt;/TD&gt;&lt;TD&gt; dru.realgoday.net&lt;/TD&gt;&lt;TD&gt; marker.antrexhost.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/2011&lt;/TD&gt;&lt;TD&gt; brew.fishbonetree.biz&lt;/TD&gt;&lt;TD&gt; spamblocker.antrexhost.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;10/2011&lt;/TD&gt;&lt;TD&gt; jane.unreadmsg.net&lt;/TD&gt;&lt;TD&gt; ads.antrexhost.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;11/2011&lt;/TD&gt;&lt;TD&gt; exchange.stafilocox.net&lt;/TD&gt;&lt;TD&gt; cafe.antrexhost.com&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;12/2011&lt;/TD&gt;&lt;TD&gt; ns1.diplodoger.com&lt;/TD&gt;&lt;TD&gt; coffeeshop.antrexhost.com&lt;/TD&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;br /&gt;C&amp;C SERVER ASSIGNED 74.63.232.233&lt;br /&gt;&lt;br /&gt;&lt;TABLE&gt;&lt;TR&gt;&lt;TD&gt;Month&lt;/TD&gt;&lt;TD&gt; Primary Domain&lt;/TD&gt;&lt;TD&gt; Alternate Domain&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1/2011&lt;/TD&gt;&lt;TD&gt; taxadvice.ehostville.com&lt;/TD&gt;&lt;TD&gt; taxfree.nethostplus.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2/2011&lt;/TD&gt;&lt;TD&gt; ticket.hostnetline.com&lt;/TD&gt;&lt;TD&gt; accounts.nethostplus.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;3/2011&lt;/TD&gt;&lt;TD&gt; flu.medicalcarenews.org&lt;/TD&gt;&lt;TD&gt; logon.nethostplus.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4/2011&lt;/TD&gt;&lt;TD&gt; vaccina.medinnovation.org&lt;/TD&gt;&lt;TD&gt;  imap.nethostplus.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;5/2011&lt;/TD&gt;&lt;TD&gt; ipadnews.netwebplus.net&lt;/TD&gt;&lt;TD&gt; onlinebooking.nethostplus.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;6/2011&lt;/TD&gt;&lt;TD&gt; acdsee.licensevalidate.net&lt;/TD&gt;&lt;TD&gt; imap.nethostplus.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;7/2011&lt;/TD&gt;&lt;TD&gt; wellness.hostfields.net&lt;/TD&gt;&lt;TD&gt; pop3.nethostplus.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;8/2011&lt;/TD&gt;&lt;TD&gt; savupdate.licensevalidate.net&lt;/TD&gt;&lt;TD&gt;schedules.nethostplus.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/2011&lt;/TD&gt;&lt;TD&gt; wiki.hostfields.net&lt;/TD&gt;&lt;TD&gt;mediastream.nethostplus.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;10/2011&lt;/TD&gt;&lt;TD&gt;taxadvice.ehostville.com&lt;/TD&gt;&lt;TD&gt; taxfree.nethostplus.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;11/2011&lt;/TD&gt;&lt;TD&gt; ticket.hostnetline.com&lt;/TD&gt;&lt;TD&gt; accounts.nethostplus.net&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;12/2011&lt;/TD&gt;&lt;TD&gt; flu.medicalcarenews.org&lt;/TD&gt;&lt;TD&gt; logon.nethostplus.net&lt;/TD&gt;&lt;/TR&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;In addition to the affidavit for the TRO, FBI Special Agent Kenneth Keller got a most unusual &lt;a href="http://newhaven.fbi.gov/dojpressrel/pressrel11/pdf/nh041311_2.pdf"&gt;Seizure Warrant&lt;/A&gt;.  With the warrant, they requested that the court compel the Registrars of the 24 domain names posted above to change the DNS settings for the servers, so that they would resolve to SINKHOLE-00.SHADOWSERVER.ORG and SINKHOLE-01.SHADOWSERVER.ORG.&lt;br /&gt;&lt;br /&gt;To maximize the difficult of taking down this bot, the criminal spread his domain registrations all over the world.  He used Wild West Domains (US-AZ), Above.com (of Australia),  Big Rock Solutions (of Mumbai), LiquidNet (UK), Network Solutions (US-Virginia), Active Registrar (SIngapore), 1&amp;1 Internet (Germany), TuCows (Toronto), Dotster (US-Washington), MyDomain, Inc (US-Washington), DomainRegistry.com (US-New Jersey), and Melbourne IT (which is Yahoo!'s registrar of choice), Mesh Digital (UK), Misk.com (US-NY), Moniker (US-Florida), and Directi (India).&lt;br /&gt;&lt;br /&gt;Obviously a US court order has little impact in Mumbai or Singapore, so it was important to get this done when the "active" domains were US-based.&lt;br /&gt;&lt;br /&gt;A "SinkHole" in the cyber security world is a trick that is invoked to cause botnets who are trying to talk to a criminal server to instead talk to a computer owned by a researcher or investigator.  Its a great way for both measuring levels of infection and also for preventing the bad guy from being able to talk to his bots.&lt;br /&gt;&lt;br /&gt;In this case, the sinkhole went beyond this though.  Here comes the cool part from this &lt;a href="http://newhaven.fbi.gov/dojpressrel/pressrel11/pdf/nh041311_5.pdf"&gt;Temporary Restraining Order issued by the Honorable (and very smart!) Vanessa L. Bryant.&lt;/A&gt; &lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;WHEREAS the Government has shown good cause to believe: (a) that hundreds of thousands of computers are infected by Coreflood, known collectively as the "Coreflood Botnet"; (b) that the computers infected by Coreflood can be remotely controlled by the &lt;br /&gt;Defendants, using certain computer servers known as the "Coreflood C&amp;C Servers" and certain Domains"; (c) that, on or about April 12, 2011, the Government will execute seizure warrants for the Coreflood C&amp;C Servers and the Coreflood Domains; (d) that the Government's seizuer of the Coreflood C&amp;C Servers and the Coreflood Domains will leave the infected computers still running Coreflood; (e) that allowing Coreflood to continue running on the infected computers will cause a continuing and substantial injury to the owners and users of the infected computers, exposing them to a loss of privacy and an increased risk of further computer intrusions; and (f) that it is feasible to stop Coreflood from running on infected computers by establishing a substitute command and control server;&lt;br /&gt;&lt;br /&gt;WHEREAS the Coreflood Domains are listed in Schedule A, together with the corresponding registry, registar, and domain name service ("DNS") provider (collectively, the "Domain Service Providers") used by the Defendants with respect to each of the Coreflood Domains;&lt;br /&gt;&lt;br /&gt;WHEREAS the Government has shown good cause to believe that: (a) it is reasonably likely that the Government can show that the Defendants are committing wire fraud and bank fraud and are engaging in unauthorized interception of electronic communications, as alleged; (b) it is reasonably likely that the Government can show a continuing and substantial injury to a class of persons, viz., the owners and users of computers infected by Coreflood; and (c) it is reasonably likely that the Government can show that the requested restraining order will prevent or ameliorate injury to that class of persons;&lt;br /&gt;&lt;br /&gt;(etc...)&lt;br /&gt;&lt;br /&gt;Pursuant to the authority granted by 28 U.S.C. $ 566, the United States Marshal for the District of Connecticut ("USMS") shall execute and enforce this Order, with the assistance of the Federal Bureau of Investigation ("FBI") if needed, by establishing a substitute server at the Internet Systems Consortium...that will respond to requests addressed to the Coreflood DOmains by issuing instructions that will cause the Coreflood software on infected computers to stop running, subject to the limitation that such instructions shall be issued only to computers reasonably determined to be in the United States.&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;The Restraining Order gave blanket permission for anything that was using the DNS servers "NS1.CYBERWATCHFLOOR.COM" (204.74.66.143) or "NS1.CYBERWATCHFLOOR.COM" (204.74.67.143) to instead point to Special Agent Kenneth Keller's server 149.20.51.124.&lt;br /&gt;&lt;br /&gt;&lt;HR&gt;&lt;br /&gt;&lt;br /&gt;Of course, some people may not want the Department of Justice telling their computer what to do.  Because of that possibility, the FBI Press Release offers the option:&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;The Department of Justice and FBI, working with Internet service providers around the country, are committed to identifying and notifying as many innocent victims as possible who have been infected with Coreflood, in order to avoid or minimize future fraud losses and identity theft resulting from Coreflood. &lt;B&gt;Identified owners of infected computers will also be told how to "opt out" from the TRO, if for some reason they want to keep Coreflood running on their computers.&lt;/B&gt; &lt;/BLOCKQUOTE&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-6846091280333128848?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/6846091280333128848'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/6846091280333128848'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/04/bold-fbi-move-shutters-coreflood-bot.html' title='Bold FBI Move Shutters COREFLOOD Bot'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-1707928815966881046</id><published>2011-04-08T08:17:00.000-07:00</published><updated>2011-04-08T10:22:10.904-07:00</updated><title type='text'>The Epsilon Phishing Model</title><content type='html'>There is a saying "if you give a man a fish, he'll eat for a day, but if you teach a man to fish, he can feed himself for a lifetime."&lt;br /&gt;&lt;br /&gt;In the case of the Epsilon email breach the saying might be "if you teach a man to be phished, he'll be a victim for a lifetime."&lt;br /&gt;&lt;br /&gt;In order to illustrate my point, let's look at a few of the security flaws in the business model of email-based marketing, using Epsilon Interactive and their communications as some examples.&lt;br /&gt;&lt;br /&gt;NOTE: Epsilon has released another &lt;a href="http://www.epsilon.com/News &amp; Events/Press_Releases_2011/Alliance_Data_Provides_Statement_Surrounding_Unauthorized_Entry_Incident_at_Epsilon_Subsidiary/p1061-l3"&gt;Press Release&lt;/A&gt; to assure the public that no Personally Identifiable Information was released.  The point of this article is not to argue that point, but rather to say there is something flawed in training users to click on links in emails.&lt;br /&gt;&lt;br /&gt;&lt;H2&gt;Targeted Mailing Lists Help Avoid Detection&lt;/H2&gt;&lt;br /&gt;&lt;br /&gt;One of the advantages to phishers in using destination email addresses from the Epsilon Breach is that it helps keep their emails out of the hands of the security research and anti-phishing communities.  Phishers, especially the less-skilled ones, tend to buy or steal large email address lists.  Many researchers and anti-phishers (including us!) have managed to get their "spam-trap" email addresses onto those lists, which gives us visibility to spam campaigns.  At UAB, as an example, we receive more than a million spam email messages each day.  Some of these emails are phishing emails, which we then share with law enforcement and our strategic partners.  Using a combination of automated and manual tools, we review tens of thousands of URLs each day to learn the addresses of the criminals new phishing sites.  But what if a phisher only sends his phishing email to "confirmed" customer email addresses?  This greatly reduces the ability of the anti-phishing community to respond to these phishing sites.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H2&gt;Guaranteed Delivery "From:" Addresses&lt;/H2&gt;&lt;br /&gt;&lt;br /&gt;Another thing a phisher would like to accomplish is to make sure that his message arrives without being blocked.  Perhaps his victim is running spam filtering software.  What is the first things that would be desirable?  He would like his email to be sent from an address that will guarantee delivery.  The easiest way to make sure that spam is delivered is to make sure that the "From:" address is in the potential victim's address book.  This is why so many email messages arrive with the "from" and "to" addresses being the same.  The spammers assume that you will have your own address in your address book, and therefore spam-filtering rules will not be applied to that address.  &lt;br /&gt;&lt;br /&gt;How else could they do that?  Epsilon helpfully instructs their customers to add their email addresses to their address book.  If a phisher now imitates those addresses, their email will bypass many phishing filters:&lt;br /&gt;&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;This email was sent to you by Ethan Allen.&lt;br /&gt;Please add ethanallenstyle@email.ethanallen.com to your address book. This will ensure delivery to your inbox.&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;You are receiving this e-mail because you have requested information about CRESTOR(R) (rosuvastatin calcium) Tablets. Add CRESTOR@email.CRESTOR.com to your address book so future e-mails from us will not be marked as spam.&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;Add citicards@info.citibank.com to your address book to ensure delivery.&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;To ensure delivery to your inbox, please add Walgreens@email.walgreens.com to your address book.&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;This e-mail was sent to you by Eddie Bauer Friends. To ensure delivery to your inbox (not junk or bulk), please add info@eddiebauerfriends.com to your address book. &lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;To ensure receipt of your Red Roof RediCard emails, please add redicard@redroofinn.bfi0.com to your address book.&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;To ensure receipt of our emails, please add targetdailydeals@targetnewsletter.bfio.com to your Contacts or Address Book.&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;etc . . .&lt;br /&gt;&lt;br /&gt;So if the phisher makes his "from" address one of these "trusted" addresses, what happens?&lt;br /&gt;&lt;br /&gt;&lt;H2&gt;Teach a man (or woman) to Click&lt;/H2&gt;&lt;br /&gt;&lt;br /&gt;One of the main pieces of advice that security professionals give to audiences and readers when they are speaking or writing about the topic of phishing is &lt;B&gt;DO NOT CLICK ON LINKS IN YOUR EMAIL!&lt;/B&gt;&lt;br /&gt;&lt;br /&gt;This is exactly the opposite advice that customers in the Epsilon databases receive.  Epsilon and other email senders work on the theory of full-visibility communications.  They know which email messages they send to which users, and they prove their value to the companies they represent by providing deep intelligence on the "click behavior" of the customers they email on behalf of those companies.  Each link in an Epsilon email is customized with a URL that tells Epsilon who clicked on the link.&lt;br /&gt;&lt;br /&gt;The whole point of emails from Epsilon is to get customers to click on links!  I've truncated the URLs to protect privacy, but here's an example of one from Target.  Clicking on this one takes me to their "Daily Deals. One Day Only. Always Free Shipping."&lt;br /&gt;&lt;br /&gt;http://target.bfi0.com/145d56598layfousibljoi2iaaaaaaq5mirqsi2bcpuyaaaaa/C?V=bF9pbmRleAEBcHJvZmlsZV9pZAExMTM1MzYzMTY5AXppcF9jb2RlAQFfV0FWRV9JRF8BNjEwODA0MzQ5AV9QTElTVF9JRF8BMjE1NDI2MjUBZ19pbmRleAEBZW1haWxfYWRkcgFnYXJAYXNrZ2FyLmNvbQFfU0NIRF9UTV8BMjAxMTA0MDMxMjAwMDABcHJvZmlsZV9rZXkBMjU4NTkyMDM%3D&amp;k2hXe6YFbcPUoDxGzFz1FA&lt;br /&gt;&lt;br /&gt;which means I can get "juniors" denim skinny jeans for $12.49 today only!  (which also means my daughter probably gave my email account to Target....hmmmm.....)&lt;br /&gt;&lt;br /&gt;Here's a few examples:&lt;br /&gt;&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;Greetings from the National Geographic Online Store!&lt;br /&gt;&lt;br /&gt;You are invited to join an exclusive community of individuals interested in National Geographic. As a member, you will...  &lt;br /&gt;   * Help us choose catalog covers.&lt;br /&gt;   * Get sneak peeks at new products we=92re considering.&lt;br /&gt;   * Give valuable advice to people at National Geographic who decide what products we should offer.&lt;br /&gt;   * Get an insider=92s view of how our catalog and online store help fund the Society's Mission programs in the areas of research, &lt;br /&gt;&lt;br /&gt;conservation, exploration, and education.&lt;br /&gt;&lt;br /&gt;Click here to join the NG Store Insider panel. http://newsletters.nationalgeographic.com/1####....&lt;br /&gt;&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;Now through April 10, 2011&lt;br /&gt;&lt;br /&gt;$50 OFF YOUR PURCHASE OF $250 OR MORE*&lt;br /&gt;ENTER CODE &gt; =&lt;br /&gt;&lt;br /&gt;Txx3-4xxxxx-xx3xx2&lt;br /&gt;&lt;br /&gt;HAUTE SALE&lt;br /&gt;HURRY, ENDS TODAY!&lt;br /&gt;40% OFF select styles. In-store &amp; online.&lt;br /&gt;&lt;br /&gt;http://bebeonline.bebe.com/#####...&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;Introducing the NY DEAL of the DAY!  Extra savings on a must have style! In stores &amp; online. Today only! The Hudson wide leg pant,&lt;br /&gt;only $14.99 today only!  Check our homepage every day of this sale for our new DEAL!&lt;br /&gt;&lt;br /&gt;Shop now &gt;&lt;br /&gt;http://email.nyandcompany.com/1####...&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;&lt;br /&gt;Today Only! Save 30% at Gap Outlet&lt;br /&gt;&lt;br /&gt;To get this coupon, copy and paste this url:&lt;br /&gt;http://mail.goAAA.com/1#####...&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;------------------------&lt;br /&gt;DAILY DEALS. ALWAYS FREE SHIPPING.&lt;br /&gt;------------------------&lt;br /&gt;&lt;br /&gt;Fun, cool stuff at amazing prices, available for one day only.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Shop Now:&lt;br /&gt;http://targetenewsletter.bfi0.com/####...&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;BBC AMERICA NEWSLETTER&lt;br /&gt;Doctor Who in America for the Very First Time&lt;br /&gt;April 6, 2011&lt;br /&gt;Doctor Who: Brand New Season&lt;br /&gt;The Tardis is hopping the pond and the stakes have never been higher.  =&lt;br /&gt;&lt;br /&gt;WATCH THE EXTENDED TRAILER&lt;br /&gt;http://bbcamerica.bfi0.com/1####...&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;The statement for your account ending in 4616 is now available online. &lt;br /&gt;Log in to Online Banking to view your statement and pay your bill. &lt;br /&gt;Please visit&lt;br /&gt;http://email.capitalone.com/1####...&lt;br /&gt;&lt;HR COLOR="gold"&gt;&lt;br /&gt;&lt;br /&gt;&lt;B&gt;The point of every one of those emails is HEY YOU!  CLICK ON THIS LINK!!!&lt;/B&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;The Warnings &amp; The Future &lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;If you live in the United States and you have ever used a credit card, your inbox is already flooded with Epsilon notices, so I hesitate to show you very many.  We've heard of warnings from more than fifty companies, and personally seen the warnings from at least:&lt;br /&gt;&lt;br /&gt;1-800-Flowers begin_of_the_skype_highlighting              1-800-Flowers      end_of_the_skype_highlighting &lt;br /&gt;Abe Books&lt;br /&gt;AIR MILES Reward Program&lt;br /&gt;Ameriprise Financial&lt;br /&gt;Barclays Bank of Delaware (US Airways Dividend Miles MasterCard, DIRECTV Rewards, iTunes Rewards, LLBean etc... )&lt;br /&gt;Beachbody&lt;br /&gt;Brookstone&lt;br /&gt;Capital One&lt;br /&gt;Citibank (AT&amp;T Universal Card, Exxon Mobile, Home Depot, Shell)&lt;br /&gt;Disney Destinations&lt;br /&gt;Eddie Bauer&lt;br /&gt;Ethan Allen&lt;br /&gt;Hilton Honors&lt;br /&gt;Krogers&lt;br /&gt;Lacoste USA&lt;br /&gt;Marriott&lt;br /&gt;McKinsey Quarterly&lt;br /&gt;M&amp;T Bank&lt;br /&gt;New York &amp; Company&lt;br /&gt;Red Roof Inn &lt;br /&gt;Soccer.com&lt;br /&gt;Target&lt;br /&gt;Tastefully Simple&lt;br /&gt;TD Ameritrade&lt;br /&gt;TIAA-CREF&lt;br /&gt;Tivo&lt;br /&gt;Verizon&lt;br /&gt;World Financial Network National Bank (WFNNB) (Ann Taylor, Catherine's, Chadwick's, Eddie Bauer, Gander Mountain, HSN, Maurice's,  Newport News, Peeble's, The RoomPlace, United Retail Group, Victoria's Secret, Woman Within)&lt;br /&gt;Walgreens&lt;br /&gt;&lt;br /&gt;The warnings are missing the point of MY warning.  All of them assure you that they aren't going to ask you for your personal information, and that your personal information hasn't been lost, "only your email address."&lt;br /&gt;&lt;br /&gt;They tell you though NOT TO OPEN EMAILS FROM PEOPLE YOU DON'T KNOW.  I don't know anyone named "shellcreditcard@info.accountonline.com" and I certainly don't know anyone named "TargetNews@target.bfio.com"&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/epsilon.target.jpg" WIDTH="70%" HEIGHT="70%"&gt;&lt;br /&gt;&lt;br /&gt;Of course that also misses entirely the fact that ANYONE can make their "From:" email anything they would like it to be!  Email is not a form of trusted communication!  So, how does the end-user know that the email really came from a real sender?  Its a growing problem.  Certain vendors have had luck with certain large mail providers -- for example eBay and Gmail.  Because eBay signs all of their outbound email with a "digital signature" and Gmail knows what digital signature eBay uses, Gmail will reject any email that claims to be from eBay but really isn't.  &lt;br /&gt;&lt;br /&gt;There is a whole association, &lt;a href="https://otalliance.org/events/2011_Forum/OTASubmissions2011.html"&gt;The Online Trust Alliance&lt;/A&gt;, filled with &lt;a href="https://otalliance.org/about/Members.htm"&gt;great companies&lt;/A&gt; dedicated to trying to fix this problem, but where they stand right now is that acceptance has been limited, and "traditional" email solutions don't come out of the box with the ability to interact richly with these forms of signatures and authentications. &lt;br /&gt;&lt;br /&gt;Imagine for example that you are a global brand with more than 500,000 employees.  In order to "turn on" digital authentication, you have to make sure that every single email sent by any of your 500,000 employees has a valid "digital signature" that proves the email really came from you!  On the other end of the spectrum, if everyone locks down their email clients to only allow emails that are signed and certified, emails from individuals like you and me are likely to be thrown away!&lt;br /&gt;&lt;br /&gt;In the meantime, we're stuck with imperfect solutions -- the need of the corporation to get their messages delivered and clicked on -- and the need of the consumer to NOT CLICK on messages that may lead to malware infections.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;One-Click Malware - Drive-By Infections&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;Kaspersky Labs had a recent headline on this topic: &lt;a href="http://www.kaspersky.com/news?id=207576288"&gt;Malware in February: Cybercriminals Perfect Drive-By Tactics&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;In most of the top reported malware for February, the infection method was to convince a user to click on a link which took them to a "poisoned" webpage -- one on which some hostile code was present that could take advantage of security flaws in the webpage visitor's browser, PDF reader, flash player, or other code to place malware on the visitor's computer.  &lt;a href="http://www.securelist.com/en/analysis/204792166/Monthly_Malware_Statistics_February_2011"&gt;Kasperky's February Report&lt;/A&gt; showed more than 70 million times where a Kaspersky customer had tried to visit a website that would have infected their computer if they had not been blocked!&lt;br /&gt;&lt;br /&gt;The Warnings in the Epsilon Breaches can't warn you of that though.  If they gave you the advice I would give you, they would be saying "Please don't click on the things our marketing department sends you!" which would result in them losing their jobs.&lt;br /&gt;&lt;br /&gt;I have to say that the Citibank group of warnings do have a form that I appreciate.&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/epsilon.citi.jpg" WIDTH="80%" HEIGHT="80%"&gt;  &lt;br /&gt;&lt;br /&gt;As a means of proving email is REALLY from them, they provide the final four digits of your account number, your name, and the year you joined their card program on all of their official emails.  I have to say that I find this very effective.&lt;br /&gt;&lt;br /&gt;Unfortunately, yet another problem at Bigfoot/Epsilon ruined my joy on this one for today:&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/epsilon.certificate.error.jpg" WIDTH="70%" HEIGHT="70%"&gt;  &lt;br /&gt;&lt;br /&gt;The error tells me "Secure Connection Failed"  "images.bigfootinteractive.com:443 uses an invalid security certificate ... This could be a problem with the server's configuration or it could be someone trying to impersonate the server."&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/epsilon.certificate.large.jpg"&gt;  &lt;br /&gt;&lt;br /&gt;It's probably just something wrong as they try to re-issue security certificates related to tightening up their shop, but still it sends the wrong message at a critical time for their company!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-1707928815966881046?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/1707928815966881046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/1707928815966881046'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/04/epsilon-phishing-model.html' title='The Epsilon Phishing Model'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-5849536045591547813</id><published>2011-03-26T23:55:00.000-07:00</published><updated>2011-03-27T00:45:19.540-07:00</updated><title type='text'>Kingpin by Kevin Poulson of WIRED</title><content type='html'>I love to read, but it's been quite a long time since I had one of those "books I can't put down" evenings.  Tonight was one of those nights.  I had been delaying the start of reading "KINGPIN: How one hacker took over the billion-dollar cybercrime underground" not because I thought it would be a book I couldn't put down, but because honestly, I thought I knew the story already.&lt;br /&gt;&lt;br /&gt;If you were interested in the hacking scene around the turn of the millenium, you would definitely know the name Max Butler.  Max made a name for himself in the IDS world, helping with the earliest days of Snort, and running a database for IDS signatures called arachnIDS.  I remember when Max went to jail the first time, chatting with my friend Dan Clemens of &lt;a href="http://packetninjas.net/"&gt;PacketNinjas, LLC&lt;/a&gt;, who was also into IDS systems and snort in a heavy way, about the arrest.  It was troubling to see someone running a website called "WhiteHats.com" and ending up in jail.  The version of the story I thought I knew was that Max had been asked by the Feds to help them patch their systems from the BIND bug that was so popular in 1998-1999, but that Max couldn't resist the urge to &lt;br /&gt;put a back door into the patch.  &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/news/18"&gt;White Hat Hacker in Court&lt;/A&gt; - April 13, 2000 - "Open source hacker "Max Vision" aided the FBI while allegedly cracking the Pentagon."&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/news/203"&gt;Max Vision: FBI Pawn?&lt;/A&gt; - May 8, 2001 - "FBI agents called him 'the Equalizer': a security expert and confessed hacker who infiltrated the electronic underground to help the Bureau. When he drew the line at bugging a friend, they threw the book at him."&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/news/221"&gt;Max Vision Begins 18-Month Term&lt;/A&gt; - July 5, 2001 - "Intrusion detection guru joins a growing hacker population in federal stir."&lt;br /&gt;&lt;br /&gt;All of those stories are by Kevin Poulsen, who has "owned" this story from the very beginning.&lt;br /&gt;&lt;br /&gt;The popular theory at the time was that Max had been sent to DefCon and was only charged with his crimes after refusing to be a snitch for the Feds at DefCon.  See for instance this conversation thread from 2001, &lt;a href="http://www.broadbandreports.com/forum/r21769718-Max-Butler-AKA-Max-Vision-Iceman-Aphex-Now-Retired"&gt;Max Butler AKA Max Vision-Iceman-Aphex Now Retired&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;I've spoken to investigators at extremely large companies who actually used Max Butler to test the security of their systems as a Penetration Tester, only learning later that he was actually stealing from them at the same time!&lt;br /&gt;&lt;br /&gt;In addition to remembering the story very well from the "old days," I also know the story as a friend of the NCFTA who has had the chance to meet and work with FBI Special Agent Keith Mularski.  Keith's work, announced by the FBI in their October 20, 2008 press release, &lt;a href="http://www.fbi.gov/news/stories/2008/october/darkmarket_102008"&gt;'Dark Market' Takedown -- Exclusive Cyber Club for Crooks Exposed&lt;/A&gt; lead to the arrest of more than 50 cyber criminals who were in the credit card stealing and trading business.  (More details on DarkMarket arrests are available from &lt;a href="http://www.wired.com/threatlevel/2010/01/jilsi-pleads-guilty/"&gt;WIRED: Dark Market ring leader pleads guilty in London&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;Like the more recent arrest of &lt;a href="http://garwarner.blogspot.com/2008/05/tjx-and-dave-busters.html"&gt;Albert Gonzales AKA Segvec&lt;/A&gt; Max has a long story of helping the Feds and working against them at the same time.  Gonzales was a US Secret Service informant against the ShadowCrew, while simultaneously breaching the Heartland Payments systems, TJX, and many other places.&lt;br /&gt;&lt;br /&gt;The difference though, was that while Gonzales was a two-timing crook who was playing the system, Max started off as a troubled soul who wanted desperately to be the hero, but couldn't resist the thrill of the hack.&lt;br /&gt;&lt;br /&gt;Like I said, I thought I already knew the story.  Reading Kevin's book brought out so many details I couldn't possibly have known though.  Kevin did a great job getting into the early life of the characters, and exploring the formation of their personalities and motivations.  As Kevin reels out the lives of the characters, its clear to see that there were several types of criminals in the stories.  His ability to create a sympathetic protagonist out of a criminal who caused $80 Million in credit card fraud is a feat in itself.  &lt;br /&gt;&lt;br /&gt;This book belongs on the shelf next to Steven Levy's Hackers.  If you haven't read it yet, pick a rainy Saturday and start early in the day, you aren't going to be able to stop until you get to the last page.&lt;br /&gt;&lt;br /&gt;&lt;A href="http://www.amazon.com/exec/obidos/redirect?tag=haikuworld&amp;path=ASIN/0307588688"&gt;&lt;IMG SRC="http://ecx.images-amazon.com/images/I/51eCAV63sBL._SL160_.jpg"&gt;&lt;BR&gt;Order Kingpin from Amazon&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Be sure to read more stories by Kevin at WIRED by following his &lt;a href="http://www.wired.com/threatlevel/author/kevin_poulsen/"&gt;Author Page&lt;/A&gt; at &lt;a href="http://www.wired.com/threatlevel/"&gt;Threat Level&lt;/A&gt; and elsewhere.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-5849536045591547813?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/5849536045591547813'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/5849536045591547813'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/03/kingpin-by-kevin-poulson-of-wired.html' title='Kingpin by Kevin Poulson of WIRED'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-3801900563026609276</id><published>2011-03-14T14:43:00.000-07:00</published><updated>2011-03-14T15:12:15.168-07:00</updated><title type='text'>Federal Reserve Spam</title><content type='html'>Last week the big malware-spreading spam &lt;a href="http://garwarner.blogspot.com/2011/03/more-ach-spam-from-nacha.html"&gt;claimed to be from NACHA&lt;/A&gt; and warned about problems with an ACH money transfer.  The same bad guys are at it again, this week pretending to be the Federal Reserve bank.&lt;br /&gt;&lt;br /&gt;The UAB Spam Data Mine has received more than 3500 copies of the spam email messages, primarily using the subject lines:&lt;br /&gt;&lt;br /&gt;Wire Transfer #12976271232523 (a random number on each email)&lt;br /&gt;Wire transfer 0430972006146 was canceled (a random number on each email)&lt;br /&gt;Wire transfer was canceled&lt;br /&gt;Wire transfer was rejected&lt;br /&gt;Your Wire fund transfer&lt;br /&gt;Your Wire Transfer&lt;br /&gt;Your Wire Transfer #2491786220489 (a random number on each email)&lt;br /&gt;Your Wire Transfer, ID544349843700 (a random number on each email)&lt;br /&gt;&lt;br /&gt;The senders of the email message varied between one of five choices:&lt;br /&gt;&lt;br /&gt;alert@federalreserve.gov&lt;br /&gt;alerts@federalreserve.gov&lt;br /&gt;fedwire@federalreserve.gov&lt;br /&gt;info@federalreserve.gov&lt;br /&gt;information@federalreserve.gov&lt;br /&gt;&lt;br /&gt;As before, someone with a Yahoo email address had their account used on GoDaddy to register ".info" domains to be used in this campaign.  This time, we have spam samples for 487 of them.&lt;br /&gt;&lt;br /&gt;Both GoDaddy and Afilias have excellent abuse staffs, and the domains in question were quickly terminated.&lt;br /&gt;&lt;br /&gt; count |             machine              &lt;br /&gt;-------+----------------------------------&lt;br /&gt;     8 | A-WIREBLOG.INFO&lt;br /&gt;     8 | AWIRE.INFO&lt;br /&gt;     5 | A-WIRENOW.INFO&lt;br /&gt;     6 | A-WIREONLINE.INFO&lt;br /&gt;    11 | A-WIRESHOP.INFO&lt;br /&gt;     4 | A-WIRESITE.INFO&lt;br /&gt;     7 | A-WIRESTORE.INFO&lt;br /&gt;     8 | A-WIRETODAY.INFO&lt;br /&gt;     4 | BESTA-WIRE.INFO&lt;br /&gt;    10 | BESTD-WIRE.INFO&lt;br /&gt;     9 | BESTFEDERALWIRE.INFO&lt;br /&gt;     6 | BESTFEDWIRE-B.INFO&lt;br /&gt;     2 | BESTFEDWIRE-E.INFO&lt;br /&gt;     8 | BESTFEDWIRE-M.INFO&lt;br /&gt;     8 | BESTFEDWIRE-N.INFO&lt;br /&gt;     9 | BESTFEDWIRE-O.INFO&lt;br /&gt;     5 | BESTFEDWIRE-Q.INFO&lt;br /&gt;    10 | BESTFEDWIRE-R.INFO&lt;br /&gt;     4 | BESTFEDWIRE-T.INFO&lt;br /&gt;    14 | BESTFEDWIRE-U.INFO&lt;br /&gt;     7 | BESTFEDWIRE-Y.INFO&lt;br /&gt;     9 | BESTI-WIRE.INFO&lt;br /&gt;     5 | BESTP-WIRE.INFO&lt;br /&gt;     6 | BESTU-WIRE.INFO&lt;br /&gt;     8 | BESTWIREORGANISATION.INFO&lt;br /&gt;     4 | BESTWIREREPORTTRANSFER.INFO&lt;br /&gt;     5 | BESTWIRETRANSFERMONEY.INFO&lt;br /&gt;     6 | BESTX-WIRE.INFO&lt;br /&gt;     4 | BESTZ-ACH.INFO&lt;br /&gt;     7 | BESTZ-WIRE.INFO&lt;br /&gt;    11 | COPPER-WIRE-ORGANISATION.INFO&lt;br /&gt;     6 | COPPERWIREORGANISATION.INFO&lt;br /&gt;     8 | COPPER-WIRE-REPORT-TRANSFER.INFO&lt;br /&gt;     8 | COPPERWIREREPORTTRANSFER.INFO&lt;br /&gt;     5 | COPPERWIRETRANSFERMONEY.INFO&lt;br /&gt;     3 | CUSTOMWIREORGANISATION.INFO&lt;br /&gt;    13 | D-WIREBLOG.INFO&lt;br /&gt;     7 | DWIRECABLE.INFO&lt;br /&gt;    10 | DWIRECLOTH.INFO&lt;br /&gt;    10 | DWIREDIAMETER.INFO&lt;br /&gt;     8 | D-WIRE-FENCE.INFO&lt;br /&gt;     5 | DWIREFENCE.INFO&lt;br /&gt;     8 | DWIREFORMING.INFO&lt;br /&gt;     5 | D-WIRE.INFO&lt;br /&gt;     7 | DWIREMANUFACTURER.INFO&lt;br /&gt;    12 | D-WIRENOW.INFO&lt;br /&gt;     7 | D-WIREONLINE.INFO&lt;br /&gt;     3 | DWIRESHELF.INFO&lt;br /&gt;     9 | D-WIRESHOP.INFO&lt;br /&gt;    11 | D-WIRES.INFO&lt;br /&gt;     9 | D-WIRESITE.INFO&lt;br /&gt;    10 | D-WIRESTORE.INFO&lt;br /&gt;     9 | DWIRESUPPLIERS.INFO&lt;br /&gt;     6 | DWIRETECH.INFO&lt;br /&gt;     8 | D-WIRETODAY.INFO&lt;br /&gt;     7 | ELECTRICALWIRETRANSFERMONEY.INFO&lt;br /&gt;     9 | FEDERALWIREBLOG.INFO&lt;br /&gt;     8 | FEDERALWIRECABLE.INFO&lt;br /&gt;     7 | FEDERALWIRECLOTH.INFO&lt;br /&gt;     8 | FEDERALWIREDIAMETER.INFO&lt;br /&gt;     8 | FEDERAL-WIRE-FENCE.INFO&lt;br /&gt;     6 | FEDERALWIREFENCE.INFO&lt;br /&gt;     9 | FEDERALWIREFORMING.INFO&lt;br /&gt;     9 | FEDERAL-WIRE.INFO&lt;br /&gt;     6 | FEDERALWIRE.INFO&lt;br /&gt;     7 | FEDERALWIRENOW.INFO&lt;br /&gt;     5 | FEDERALWIREONLINE.INFO&lt;br /&gt;     6 | FEDERALWIRESHELF.INFO&lt;br /&gt;     6 | FEDERALWIRESHOP.INFO&lt;br /&gt;     6 | FEDERALWIRES.INFO&lt;br /&gt;     5 | FEDERALWIRESITE.INFO&lt;br /&gt;     8 | FEDERALWIRESIZES.INFO&lt;br /&gt;     8 | FEDERALWIRESTORE.INFO&lt;br /&gt;     9 | FEDERALWIRETECH.INFO&lt;br /&gt;     9 | FEDERALWIRETODAY.INFO&lt;br /&gt;     8 | FEDWIREANDBLUE.INFO&lt;br /&gt;     8 | FEDWIREANDSAVE.INFO&lt;br /&gt;     8 | FEDWIREANDSILVER.INFO&lt;br /&gt;     4 | FEDWIREANDSONS.INFO&lt;br /&gt;    12 | FEDWIREANDSOUL.INFO&lt;br /&gt;     2 | FEDWIREANDSTYLE.INFO&lt;br /&gt;     7 | FEDWIREANDTRAVEL.INFO&lt;br /&gt;    10 | FEDWIRE-BBLOG.INFO&lt;br /&gt;     8 | FEDWIRE-BE-CONNECTED.INFO&lt;br /&gt;     6 | FEDWIREBECONNECTED.INFO&lt;br /&gt;    10 | FEDWIRE-BE-COOL.INFO&lt;br /&gt;     7 | FEDWIREBECOOL.INFO&lt;br /&gt;    11 | FEDWIRE-BE.INFO&lt;br /&gt;    10 | FEDWIREBE.INFO&lt;br /&gt;     7 | FEDWIRE-B.INFO&lt;br /&gt;     8 | FEDWIREB.INFO&lt;br /&gt;     6 | FEDWIRE-BNOW.INFO&lt;br /&gt;     7 | FEDWIRE-BONLINE.INFO&lt;br /&gt;     8 | FEDWIRE-B-RICH.INFO&lt;br /&gt;     7 | FEDWIREBRICH.INFO&lt;br /&gt;     7 | FEDWIRE-BSHOP.INFO&lt;br /&gt;     3 | FEDWIRE-BS.INFO&lt;br /&gt;     7 | FEDWIRE-BSITE.INFO&lt;br /&gt;     6 | FEDWIRE-BSTORE.INFO&lt;br /&gt;     8 | FEDWIRE-BTODAY.INFO&lt;br /&gt;     5 | FEDWIRE-EBLOG.INFO&lt;br /&gt;     6 | FEDWIRE-E.INFO&lt;br /&gt;     8 | FEDWIREE.INFO&lt;br /&gt;     5 | FEDWIRE-E-MINOR.INFO&lt;br /&gt;     7 | FEDWIREEMINOR.INFO&lt;br /&gt;     6 | FEDWIRE-ENOW.INFO&lt;br /&gt;     9 | FEDWIRE-EONLINE.INFO&lt;br /&gt;     4 | FEDWIRE-ESHOP.INFO&lt;br /&gt;     9 | FEDWIRE-ES.INFO&lt;br /&gt;    10 | FEDWIRE-ESITE.INFO&lt;br /&gt;     5 | FEDWIRE-ESTORE.INFO&lt;br /&gt;     4 | FEDWIRE-ETODAY.INFO&lt;br /&gt;    11 | FEDWIRE-M-BASKETBALL.INFO&lt;br /&gt;     6 | FEDWIREMBASKETBALL.INFO&lt;br /&gt;    10 | FEDWIRE-MBLOG.INFO&lt;br /&gt;     4 | FEDWIRE-M.INFO&lt;br /&gt;    12 | FEDWIREM.INFO&lt;br /&gt;    13 | FEDWIRE-MNOW.INFO&lt;br /&gt;     4 | FEDWIRE-MONLINE.INFO&lt;br /&gt;     7 | FEDWIRE-MSHOP.INFO&lt;br /&gt;     3 | FEDWIRE-MS.INFO&lt;br /&gt;     3 | FEDWIRE-MSITE.INFO&lt;br /&gt;     3 | FEDWIRE-MSTORE.INFO&lt;br /&gt;    12 | FEDWIRE-MTODAY.INFO&lt;br /&gt;     6 | FEDWIRE-M-WARD.INFO&lt;br /&gt;     7 | FEDWIREMWARD.INFO&lt;br /&gt;    12 | FEDWIRE-NBLOG.INFO&lt;br /&gt;     9 | FEDWIRE-N.INFO&lt;br /&gt;     3 | FEDWIREN.INFO&lt;br /&gt;     5 | FEDWIRE-NNOW.INFO&lt;br /&gt;     4 | FEDWIRE-NONLINE.INFO&lt;br /&gt;     4 | FEDWIRE-N-SCALE.INFO&lt;br /&gt;    16 | FEDWIRENSCALE.INFO&lt;br /&gt;     6 | FEDWIRE-NSHOP.INFO&lt;br /&gt;     3 | FEDWIRE-NS.INFO&lt;br /&gt;     5 | FEDWIRE-NSITE.INFO&lt;br /&gt;     4 | FEDWIRE-NSTORE.INFO&lt;br /&gt;    11 | FEDWIRE-NTODAY.INFO&lt;br /&gt;     6 | FEDWIRE-OBLOG.INFO&lt;br /&gt;     5 | FEDWIRE-O-HENRY.INFO&lt;br /&gt;     7 | FEDWIREOHENRY.INFO&lt;br /&gt;     8 | FEDWIRE-O.INFO&lt;br /&gt;     5 | FEDWIREO.INFO&lt;br /&gt;     6 | FEDWIRE-ONOW.INFO&lt;br /&gt;    13 | FEDWIRE-OONLINE.INFO&lt;br /&gt;    11 | FEDWIRE-OSHOP.INFO&lt;br /&gt;     9 | FEDWIRE-OS.INFO&lt;br /&gt;    11 | FEDWIRE-OSITE.INFO&lt;br /&gt;     4 | FEDWIRE-OSTORE.INFO&lt;br /&gt;     8 | FEDWIRE-O-TICKET.INFO&lt;br /&gt;     5 | FEDWIREOTICKET.INFO&lt;br /&gt;     7 | FEDWIRE-OTODAY.INFO&lt;br /&gt;     9 | FEDWIRE-Q-AUDIO.INFO&lt;br /&gt;     5 | FEDWIREQAUDIO.INFO&lt;br /&gt;     9 | FEDWIRE-Q-AWARDS.INFO&lt;br /&gt;    10 | FEDWIREQAWARDS.INFO&lt;br /&gt;     7 | FEDWIRE-QBLOG.INFO&lt;br /&gt;     9 | FEDWIRE-Q-CELL.INFO&lt;br /&gt;     5 | FEDWIREQCELL.INFO&lt;br /&gt;     9 | FEDWIRE-Q-FEVER.INFO&lt;br /&gt;     9 | FEDWIREQFEVER.INFO&lt;br /&gt;     6 | FEDWIRE-Q.INFO&lt;br /&gt;     5 | FEDWIRE-Q-MAGAZINE.INFO&lt;br /&gt;     6 | FEDWIREQMAGAZINE.INFO&lt;br /&gt;     8 | FEDWIRE-QNOW.INFO&lt;br /&gt;     5 | FEDWIRE-QONLINE.INFO&lt;br /&gt;     8 | FEDWIRE-QSHOP.INFO&lt;br /&gt;     9 | FEDWIRE-QS.INFO&lt;br /&gt;     5 | FEDWIRE-QSITE.INFO&lt;br /&gt;     6 | FEDWIRE-QSTORE.INFO&lt;br /&gt;    12 | FEDWIRE-QTODAY.INFO&lt;br /&gt;     5 | FEDWIRE-RBLOG.INFO&lt;br /&gt;     5 | FEDWIRE-R.INFO&lt;br /&gt;     5 | FEDWIRER.INFO&lt;br /&gt;     8 | FEDWIRE-R-KELLY.INFO&lt;br /&gt;     3 | FEDWIRERKELLY.INFO&lt;br /&gt;    13 | FEDWIRE-RNOW.INFO&lt;br /&gt;     7 | FEDWIRE-RONLINE.INFO&lt;br /&gt;     3 | FEDWIRE-RSHOP.INFO&lt;br /&gt;    11 | FEDWIRE-RS.INFO&lt;br /&gt;     7 | FEDWIRE-RSITE.INFO&lt;br /&gt;     8 | FEDWIRE-RSTORE.INFO&lt;br /&gt;     5 | FEDWIRE-RTODAY.INFO&lt;br /&gt;     7 | FEDWIRE-TBLOG.INFO&lt;br /&gt;     6 | FEDWIRE-T-CELLS.INFO&lt;br /&gt;    12 | FEDWIRETCELLS.INFO&lt;br /&gt;     7 | FEDWIRE-T.INFO&lt;br /&gt;     9 | FEDWIRET.INFO&lt;br /&gt;     8 | FEDWIRE-T-MAGAZINE.INFO&lt;br /&gt;     6 | FEDWIRETMAGAZINE.INFO&lt;br /&gt;     4 | FEDWIRE-TNOW.INFO&lt;br /&gt;     9 | FEDWIRE-TONLINE.INFO&lt;br /&gt;     6 | FEDWIRE-T-PAIN.INFO&lt;br /&gt;     8 | FEDWIRETPAIN.INFO&lt;br /&gt;     8 | FEDWIRE-TSHOP.INFO&lt;br /&gt;     6 | FEDWIRE-TS.INFO&lt;br /&gt;     5 | FEDWIRE-TSITE.INFO&lt;br /&gt;     5 | FEDWIRE-TSTORE.INFO&lt;br /&gt;    14 | FEDWIRE-TTODAY.INFO&lt;br /&gt;     4 | FEDWIRE-UBLOG.INFO&lt;br /&gt;    11 | FEDWIRE-U.INFO&lt;br /&gt;     9 | FEDWIREU.INFO&lt;br /&gt;    12 | FEDWIRE-UNOW.INFO&lt;br /&gt;    12 | FEDWIRE-UONLINE.INFO&lt;br /&gt;    10 | FEDWIRE-USHOP.INFO&lt;br /&gt;    10 | FEDWIRE-US.INFO&lt;br /&gt;     5 | FEDWIRE-USITE.INFO&lt;br /&gt;    10 | FEDWIRE-USTORE.INFO&lt;br /&gt;     3 | FEDWIRE-UTODAY.INFO&lt;br /&gt;     7 | FEDWIRE-YBLOG.INFO&lt;br /&gt;     6 | FEDWIRE-Y-CAMP.INFO&lt;br /&gt;     7 | FEDWIREYCAMP.INFO&lt;br /&gt;    10 | FEDWIRE-Y.INFO&lt;br /&gt;     9 | FEDWIREY.INFO&lt;br /&gt;     6 | FEDWIRE-YNOW.INFO&lt;br /&gt;     7 | FEDWIRE-YONLINE.INFO&lt;br /&gt;     7 | FEDWIRE-YOU-CANT.INFO&lt;br /&gt;     8 | FEDWIREYOUCANT.INFO&lt;br /&gt;     6 | FEDWIRE-YOU.INFO&lt;br /&gt;     9 | FEDWIREYOU.INFO&lt;br /&gt;     9 | FEDWIRE-YOU-ROCK.INFO&lt;br /&gt;    10 | FEDWIREYOUROCK.INFO&lt;br /&gt;     2 | FEDWIRE-YOU-SAVE.INFO&lt;br /&gt;     4 | FEDWIREYOUSAVE.INFO&lt;br /&gt;    12 | FEDWIREYOUTUBE.INFO&lt;br /&gt;     5 | FEDWIRE-YSHOP.INFO&lt;br /&gt;     5 | FEDWIRE-YS.INFO&lt;br /&gt;     7 | FEDWIRE-YSITE.INFO&lt;br /&gt;     7 | FEDWIRE-YSTORE.INFO&lt;br /&gt;     8 | FEDWIRE-YTODAY.INFO&lt;br /&gt;     4 | FREEA-WIRE.INFO&lt;br /&gt;     7 | FREED-WIRE.INFO&lt;br /&gt;     9 | FREEFEDERALWIRE.INFO&lt;br /&gt;     8 | FREEFEDWIRE-B.INFO&lt;br /&gt;     7 | FREEFEDWIRE-E.INFO&lt;br /&gt;     9 | FREEFEDWIRE-M.INFO&lt;br /&gt;     5 | FREEFEDWIRE-N.INFO&lt;br /&gt;     7 | FREEFEDWIRE-O.INFO&lt;br /&gt;     2 | FREEFEDWIRE-Q.INFO&lt;br /&gt;     5 | FREEFEDWIRE-R.INFO&lt;br /&gt;     8 | FREEFEDWIRE-T.INFO&lt;br /&gt;    13 | FREEFEDWIRE-U.INFO&lt;br /&gt;    14 | FREEFEDWIRE-Y.INFO&lt;br /&gt;     7 | FREEI-WIRE.INFO&lt;br /&gt;     5 | FREEP-WIRE.INFO&lt;br /&gt;     8 | FREEU-WIRE.INFO&lt;br /&gt;     5 | FREEWIREORGANISATION.INFO&lt;br /&gt;     9 | FREEWIREREPORTTRANSFER.INFO&lt;br /&gt;     4 | FREEWIRETRANSFERMONEY.INFO&lt;br /&gt;     8 | FREEX-WIRE.INFO&lt;br /&gt;     7 | FREEZ-ACH.INFO&lt;br /&gt;     6 | FREEZ-WIRE.INFO&lt;br /&gt;     5 | GAUGEWIREORGANISATION.INFO&lt;br /&gt;     5 | GAUGEWIRETRANSFERMONEY.INFO&lt;br /&gt;     7 | I-MOBILE-WIRE.INFO&lt;br /&gt;     8 | IMOBILEWIRE.INFO&lt;br /&gt;     5 | IRONWIREORGANISATION.INFO&lt;br /&gt;     5 | IRONWIREREPORTTRANSFER.INFO&lt;br /&gt;     7 | IRONWIRETRANSFERMONEY.INFO&lt;br /&gt;     6 | I-WIREBLOG.INFO&lt;br /&gt;    10 | IWIREHOMES.INFO&lt;br /&gt;     8 | I-WIRE.INFO&lt;br /&gt;     7 | I-WIRE-INTERACTIVE.INFO&lt;br /&gt;     5 | IWIREINTERACTIVE.INFO&lt;br /&gt;    10 | IWIRENETWORKS.INFO&lt;br /&gt;    10 | I-WIRENOW.INFO&lt;br /&gt;    11 | I-WIREONLINE.INFO&lt;br /&gt;     7 | I-WIRESHOP.INFO&lt;br /&gt;     2 | I-WIRES.INFO&lt;br /&gt;     7 | I-WIRESITE.INFO&lt;br /&gt;     8 | I-WIRESTORE.INFO&lt;br /&gt;    14 | I-WIRE-TECH.INFO&lt;br /&gt;     5 | IWIRETECH.INFO&lt;br /&gt;    11 | I-WIRETODAY.INFO&lt;br /&gt;     7 | METALWIREORGANISATION.INFO&lt;br /&gt;     6 | METALWIREREPORTTRANSFER.INFO&lt;br /&gt;     6 | METALWIRETRANSFERMONEY.INFO&lt;br /&gt;     6 | MYA-WIRE.INFO&lt;br /&gt;     3 | MYD-WIRE.INFO&lt;br /&gt;     8 | MYFEDERALWIRE.INFO&lt;br /&gt;    12 | MYFEDWIRE-B.INFO&lt;br /&gt;     5 | MYFEDWIRE-E.INFO&lt;br /&gt;    13 | MYFEDWIRE-M.INFO&lt;br /&gt;     8 | MYFEDWIRE-N.INFO&lt;br /&gt;    10 | MYFEDWIRE-O.INFO&lt;br /&gt;     4 | MYFEDWIRE-Q.INFO&lt;br /&gt;    11 | MYFEDWIRE-R.INFO&lt;br /&gt;    11 | MYFEDWIRE-T.INFO&lt;br /&gt;    10 | MYFEDWIRE-U.INFO&lt;br /&gt;    11 | MYFEDWIRE-Y.INFO&lt;br /&gt;     7 | MYI-WIRE.INFO&lt;br /&gt;     6 | MYP-WIRE.INFO&lt;br /&gt;     5 | MYU-WIRE.INFO&lt;br /&gt;    12 | MYWIREORGANISATION.INFO&lt;br /&gt;     7 | MYWIREREPORTTRANSFER.INFO&lt;br /&gt;     9 | MYWIRETRANSFERMONEY.INFO&lt;br /&gt;     5 | MYX-WIRE.INFO&lt;br /&gt;     9 | MYZ-ACH.INFO&lt;br /&gt;     7 | MYZ-WIRE.INFO&lt;br /&gt;     4 | NEWA-WIRE.INFO&lt;br /&gt;     6 | NEWD-WIRE.INFO&lt;br /&gt;     5 | NEWFEDERALWIRE.INFO&lt;br /&gt;    12 | NEWFEDWIRE-B.INFO&lt;br /&gt;     5 | NEWFEDWIRE-E.INFO&lt;br /&gt;    12 | NEWFEDWIRE-M.INFO&lt;br /&gt;     7 | NEWFEDWIRE-N.INFO&lt;br /&gt;     7 | NEWFEDWIRE-O.INFO&lt;br /&gt;     8 | NEWFEDWIRE-Q.INFO&lt;br /&gt;    10 | NEWFEDWIRE-R.INFO&lt;br /&gt;     5 | NEWFEDWIRE-T.INFO&lt;br /&gt;    11 | NEWFEDWIRE-U.INFO&lt;br /&gt;     5 | NEWFEDWIRE-Y.INFO&lt;br /&gt;     6 | NEWI-WIRE.INFO&lt;br /&gt;     7 | NEWP-WIRE.INFO&lt;br /&gt;    18 | NEWU-WIRE.INFO&lt;br /&gt;    12 | NEWWIREORGANISATION.INFO&lt;br /&gt;     9 | NEWWIREREPORTTRANSFER.INFO&lt;br /&gt;     8 | NEWWIRETRANSFERMONEY.INFO&lt;br /&gt;     3 | NEWX-WIRE.INFO&lt;br /&gt;     6 | NEWZ-ACH.INFO&lt;br /&gt;    10 | NEWZ-WIRE.INFO&lt;br /&gt;    11 | PRECISIONWIREORGANISATION.INFO&lt;br /&gt;     3 | P-WIREBLOG.INFO&lt;br /&gt;    10 | PWIRECABLE.INFO&lt;br /&gt;     8 | PWIRECLOTH.INFO&lt;br /&gt;     4 | PWIREDIAMETER.INFO&lt;br /&gt;     8 | P-WIRE-FENCE.INFO&lt;br /&gt;     3 | PWIREFENCE.INFO&lt;br /&gt;     7 | PWIREFORMING.INFO&lt;br /&gt;     2 | P-WIRE.INFO&lt;br /&gt;    11 | PWIRE.INFO&lt;br /&gt;     9 | PWIREMANUFACTURER.INFO&lt;br /&gt;     8 | P-WIRENOW.INFO&lt;br /&gt;     9 | P-WIREONLINE.INFO&lt;br /&gt;     7 | PWIRESHELF.INFO&lt;br /&gt;     6 | P-WIRESHOP.INFO&lt;br /&gt;     7 | P-WIRES.INFO&lt;br /&gt;    12 | P-WIRESITE.INFO&lt;br /&gt;     7 | P-WIRESTORE.INFO&lt;br /&gt;     6 | PWIRESUPPLIERS.INFO&lt;br /&gt;     4 | P-WIRETODAY.INFO&lt;br /&gt;     6 | RESISTANCEWIRETRANSFERMONEY.INFO&lt;br /&gt;     7 | RIDINGTHEWIRE.INFO&lt;br /&gt;    12 | ROME-X-WIRE.INFO&lt;br /&gt;     9 | SILVERWIRETRANSFERMONEY.INFO&lt;br /&gt;    10 | SPOT-I-WIRE.INFO&lt;br /&gt;    11 | SPOTIWIRE.INFO&lt;br /&gt;     4 | STEEL-WIRE-ORGANISATION.INFO&lt;br /&gt;     9 | STEELWIREORGANISATION.INFO&lt;br /&gt;     3 | STEEL-WIRE-REPORT-TRANSFER.INFO&lt;br /&gt;     9 | STEELWIREREPORTTRANSFER.INFO&lt;br /&gt;     5 | STEELWIRETRANSFERMONEY.INFO&lt;br /&gt;     7 | THEA-WIRE.INFO&lt;br /&gt;     7 | THEDETROITWIRE.INFO&lt;br /&gt;     7 | THED-WIRE.INFO&lt;br /&gt;     3 | THEFEDERALWIRE.INFO&lt;br /&gt;    11 | THEFEDWIRE-B.INFO&lt;br /&gt;     5 | THEFEDWIRE-E.INFO&lt;br /&gt;     8 | THEFEDWIRE-M.INFO&lt;br /&gt;     7 | THEFEDWIRE-N.INFO&lt;br /&gt;     5 | THEFEDWIRE-O.INFO&lt;br /&gt;     7 | THEFEDWIRE-Q.INFO&lt;br /&gt;     6 | THEFEDWIRE-R.INFO&lt;br /&gt;     9 | THEFEDWIRE-T.INFO&lt;br /&gt;     3 | THEFEDWIRE-U.INFO&lt;br /&gt;    12 | THEFEDWIRE-Y.INFO&lt;br /&gt;     9 | THEI-WIRE.INFO&lt;br /&gt;     7 | THEP-WIRE.INFO&lt;br /&gt;     4 | THERIDEWIRE.INFO&lt;br /&gt;     2 | THEU-WIRE.INFO&lt;br /&gt;    11 | THEWIREDOGS.INFO&lt;br /&gt;     6 | THEWIREGUYS.INFO&lt;br /&gt;     6 | THE-WIRE.INFO&lt;br /&gt;     5 | THEWIREORGANISATION.INFO&lt;br /&gt;    14 | THEWIREREPORTTRANSFER.INFO&lt;br /&gt;     1 | THEWIRETRANSFERMONEY.INFO&lt;br /&gt;    10 | THEX-WIRE.INFO&lt;br /&gt;    10 | THEZ-ACH.INFO&lt;br /&gt;     6 | THEZ-WIRE.INFO&lt;br /&gt;     6 | TRAVEL-A-WIRE.INFO&lt;br /&gt;    10 | TRAVELAWIRE.INFO&lt;br /&gt;    12 | U-WIREBLOG.INFO&lt;br /&gt;     7 | UWIRECABLE.INFO&lt;br /&gt;    11 | UWIRECLOTH.INFO&lt;br /&gt;     9 | UWIREDIAMETER.INFO&lt;br /&gt;     7 | U-WIRE-FENCE.INFO&lt;br /&gt;     9 | UWIREFENCE.INFO&lt;br /&gt;     9 | UWIREFORMING.INFO&lt;br /&gt;     9 | U-WIRE.INFO&lt;br /&gt;     9 | UWIREMANUFACTURER.INFO&lt;br /&gt;     4 | U-WIRENOW.INFO&lt;br /&gt;     8 | U-WIREONLINE.INFO&lt;br /&gt;     9 | UWIRESHELF.INFO&lt;br /&gt;     7 | U-WIRESHOP.INFO&lt;br /&gt;     8 | U-WIRES.INFO&lt;br /&gt;     8 | U-WIRESITE.INFO&lt;br /&gt;     8 | U-WIRESTORE.INFO&lt;br /&gt;     5 | UWIRESUPPLIERS.INFO&lt;br /&gt;     6 | UWIRETECH.INFO&lt;br /&gt;     3 | U-WIRETODAY.INFO&lt;br /&gt;     6 | WALKINGTHEWIRE.INFO&lt;br /&gt;    12 | WIREORGANISATIONBLOG.INFO&lt;br /&gt;    10 | WIRE-ORGANISATION.INFO&lt;br /&gt;     5 | WIREORGANISATION.INFO&lt;br /&gt;     5 | WIREORGANISATIONNOW.INFO&lt;br /&gt;     9 | WIREORGANISATIONONLINE.INFO&lt;br /&gt;     6 | WIREORGANISATIONSHOP.INFO&lt;br /&gt;     5 | WIREORGANISATIONS.INFO&lt;br /&gt;     3 | WIREORGANISATIONSITE.INFO&lt;br /&gt;     9 | WIREORGANISATIONSTORE.INFO&lt;br /&gt;     6 | WIREORGANISATIONTODAY.INFO&lt;br /&gt;     7 | WIREREPORTCARDSTRANSFER.INFO&lt;br /&gt;     6 | WIRE-REPORT-CARD-TRANSFER.INFO&lt;br /&gt;     7 | WIREREPORTCARDTRANSFER.INFO&lt;br /&gt;     4 | WIREREPORTTRANSFERBLOG.INFO&lt;br /&gt;    11 | WIRE-REPORT-TRANSFER.INFO&lt;br /&gt;     6 | WIREREPORTTRANSFER.INFO&lt;br /&gt;     4 | WIREREPORTTRANSFERNOW.INFO&lt;br /&gt;     6 | WIREREPORTTRANSFERONLINE.INFO&lt;br /&gt;     4 | WIREREPORTTRANSFERSHOP.INFO&lt;br /&gt;    10 | WIREREPORTTRANSFERS.INFO&lt;br /&gt;     6 | WIREREPORTTRANSFERSITE.INFO&lt;br /&gt;     2 | WIREREPORTTRANSFERSTORE.INFO&lt;br /&gt;     7 | WIREREPORTTRANSFERTODAY.INFO&lt;br /&gt;     5 | WIRETRANSFERMONEYBLOG.INFO&lt;br /&gt;    13 | WIRE-TRANSFER-MONEY.INFO&lt;br /&gt;     7 | WIRETRANSFERMONEY.INFO&lt;br /&gt;     7 | WIRETRANSFERMONEYNOW.INFO&lt;br /&gt;     7 | WIRETRANSFERMONEYONLINE.INFO&lt;br /&gt;     7 | WIRETRANSFERMONEYSHOP.INFO&lt;br /&gt;     9 | WIRETRANSFERMONEYS.INFO&lt;br /&gt;     6 | WIRETRANSFERMONEYSITE.INFO&lt;br /&gt;    10 | WIRETRANSFERMONEYSTORE.INFO&lt;br /&gt;     1 | WIRETRANSFERMONEYTODAY.INFO&lt;br /&gt;     7 | WIRETRANSFERSTATIONMONEY.INFO&lt;br /&gt;     3 | X-CABLE.INFO&lt;br /&gt;     4 | XCIRCUITBOARDS.INFO&lt;br /&gt;     6 | X-CIRCUIT.INFO&lt;br /&gt;     7 | XCIRCUIT.INFO&lt;br /&gt;     5 | X-CONNECTION.INFO&lt;br /&gt;     6 | XELECTRICALCONDUCTOR.INFO&lt;br /&gt;     6 | X-FILAMENT.INFO&lt;br /&gt;     7 | XFILAMENT.INFO&lt;br /&gt;     8 | X-WIREBLOG.INFO&lt;br /&gt;     6 | XWIRE.INFO&lt;br /&gt;    10 | X-WIRENOW.INFO&lt;br /&gt;    11 | X-WIREONLINE.INFO&lt;br /&gt;     8 | X-WIRESHOP.INFO&lt;br /&gt;     3 | X-WIRES.INFO&lt;br /&gt;     2 | X-WIRESITE.INFO&lt;br /&gt;     6 | X-WIRESTORE.INFO&lt;br /&gt;     2 | X-WIRETODAY.INFO&lt;br /&gt;    13 | Z-ACH-ACCOUNTS.INFO&lt;br /&gt;     5 | ZACHACCOUNTS.INFO&lt;br /&gt;    10 | Z-ACHBLOG.INFO&lt;br /&gt;     8 | Z-ACH.INFO&lt;br /&gt;     9 | Z-ACHNOW.INFO&lt;br /&gt;    16 | Z-ACHONLINE.INFO&lt;br /&gt;     6 | Z-ACH-PAYMENT.INFO&lt;br /&gt;    10 | ZACHPAYMENT.INFO&lt;br /&gt;     5 | Z-ACH-PAYMENTS.INFO&lt;br /&gt;     6 | ZACHPAYMENTS.INFO&lt;br /&gt;     5 | Z-ACHSHOP.INFO&lt;br /&gt;     4 | Z-ACHS.INFO&lt;br /&gt;     8 | Z-ACHSITE.INFO&lt;br /&gt;     6 | Z-ACHSTORE.INFO&lt;br /&gt;     4 | Z-ACHTODAY.INFO&lt;br /&gt;     4 | Z-ACH-TRANSACTIONS.INFO&lt;br /&gt;    10 | ZACHTRANSACTIONS.INFO&lt;br /&gt;     5 | ZCABLE.INFO&lt;br /&gt;     9 | ZCIRCUITBOARDS.INFO&lt;br /&gt;     9 | ZCIRCUIT.INFO&lt;br /&gt;     6 | ZCONNECTION.INFO&lt;br /&gt;     5 | ZFILAMENT.INFO&lt;br /&gt;    10 | ZLINESEGMENT.INFO&lt;br /&gt;     3 | ZLINETRAINS.INFO&lt;br /&gt;     3 | ZLINK.INFO&lt;br /&gt;     4 | Z-WIREBLOG.INFO&lt;br /&gt;     7 | Z-WIRE-INTERACTIVE.INFO&lt;br /&gt;     9 | ZWIREINTERACTIVE.INFO&lt;br /&gt;     6 | Z-WIRENOW.INFO&lt;br /&gt;     8 | Z-WIREONLINE.INFO&lt;br /&gt;    11 | Z-WIRESHOP.INFO&lt;br /&gt;     7 | Z-WIRES.INFO&lt;br /&gt;    13 | Z-WIRESITE.INFO&lt;br /&gt;    15 | Z-WIRESTORE.INFO&lt;br /&gt;     7 | Z-WIRETODAY.INFO&lt;br /&gt;(487 rows)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-3801900563026609276?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/3801900563026609276'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/3801900563026609276'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/03/federal-reserve-spam.html' title='Federal Reserve Spam'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-1709289331572927683</id><published>2011-03-12T08:25:00.000-08:00</published><updated>2011-03-12T08:30:42.899-08:00</updated><title type='text'>UK Government counts the Cost of Cybercrime</title><content type='html'>The British government has released a report on the annual cost of cybercrime to the United Kingdom.  The study mechanism seems greatly flawed, in that it relies almost exclusively on published reports and expert opinions, rather than on any structured gathering of information from victims.&lt;br /&gt;&lt;br /&gt;The news was announced in the press this week, for example &lt;a href=" http://www.independent.co.uk/news/business/analysis-and-features/business-counts-the-cost-of-cyber-crime-2236158.html"&gt;in the Independent&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;They came up with a 2010 annual cost of cyber crime of £27 billion (or $43 billion US Dollars).  If the costs were projected evenly from the $2.2 trillion UK economy to the $14.1 trillion US economy, that would estimate our own costs of cybercrime at $275 billion (&lt;a href="http://topforeignstocks.com/2010/10/25/usa-vs-uk-government-finances-and-size-of-economy/"&gt;roughly 6.4 times larger economy&lt;/A&gt;.)  There is no basis to believe that projection is accurate, but the scale is probably similar.&lt;br /&gt;&lt;br /&gt;The study was paid for by the OCSIA, the Office of Cyber Security and Information Assurance.  It was conducted by &lt;a href="http://www.detica.com/news/office-of-cyber-security-and-detica-report-estimates-that-the-overall-cost/"&gt;Detica&lt;/A&gt;, a BAE Systems company.&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://www.cabinetoffice.gov.uk/sites/default/files/resources/the-cost-of-cyber-crime-full-report.pdf"&gt;full 32 page report&lt;/A&gt; is available from the Cabinet Office&lt;br /&gt;&lt;br /&gt;They place costs at:&lt;br /&gt;&lt;br /&gt;£3.1 billion to citizens with &lt;br /&gt;    £1.7 billion in Identity Theft &lt;br /&gt;    £1.4 billion to online scams.&lt;br /&gt;&lt;br /&gt;£2.2 billion to the government&lt;br /&gt;&lt;br /&gt;£21 billion businesses of which:&lt;br /&gt;&lt;br /&gt;   £9.2 billion in Intellectual Property theft&lt;br /&gt;   £7.6 billion in industrial espionage&lt;br /&gt;   £2.2 billion in extortion&lt;br /&gt;   £1.3 billion from direct theft&lt;br /&gt;   £1 billion in costs related to lost customer data&lt;br /&gt;&lt;br /&gt;The Intellectual Property theft was certainly not evenly distributed.  They put the most likely industries as:&lt;br /&gt;&lt;br /&gt; £1.8 billion = pharmaceuticals &amp; biotech&lt;br /&gt; £1.7 billion = electronic &amp; electrical material&lt;br /&gt; £1.6 billion = software &amp; computer services&lt;br /&gt; £1.3 billion = chemicals &lt;br /&gt; £800 million = automobiles &amp; parts&lt;br /&gt; £800 million = non-profits&lt;br /&gt; £400 million = aerospace &amp; defence&lt;br /&gt;&lt;br /&gt;The greatest risk in Intellectual Property theft was believed to be untrustworthy insiders who fell to the pressure of bribery.&lt;br /&gt;&lt;br /&gt;The Espionage Impact was largely in three areas:&lt;br /&gt;&lt;br /&gt; £2.1 billion = financial services&lt;br /&gt; £1.6 billion = mining&lt;br /&gt; £1.3 billion = aerospace and defence&lt;br /&gt; £900 million = software &amp; computer services&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-1709289331572927683?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/1709289331572927683'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/1709289331572927683'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/03/uk-government-counts-cost-of-cybercrime.html' title='UK Government counts the Cost of Cybercrime'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-1186724132670188978</id><published>2011-03-11T10:48:00.000-08:00</published><updated>2011-03-11T11:39:24.498-08:00</updated><title type='text'>More ACH Spam from NACHA</title><content type='html'>While we wait for the Japanese Earthquake scams to begin, we noticed another on-going spam campaign.  We wrote about the &lt;a href="http://garwarner.blogspot.com/2011/02/ach-transaction-rejected-payments-lead.html"&gt;ACH Transaction Rejected&lt;/A&gt; spam back in February, but another round is active, with another 350+ freshly registered domains.&lt;br /&gt;&lt;br /&gt;The body of the email this time around reads:&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;The ACH transfer (ID: 65388185980), recently sent from your checking account (by you or any other person), was cancelled by the other financial institution.  &lt;br /&gt;&lt;br /&gt;Please click here (link) to view details&lt;br /&gt;&lt;br /&gt;If you have any questions or comments, contact us at info@nacha.org.  Thank you for using http://www.nacha.org.&lt;br /&gt;&lt;br /&gt;/This messages is intended for use by addressee only and may contain privileged and confidential information.  If you are not the intended recipient, dissemination of this communication is prohibited.  If you have received this communication in error, please delete all copies of the message and attachments and notify the sender immediately. /&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The spam has one of the following ten subject lines:&lt;br /&gt;&lt;br /&gt;ACH payment canceled&lt;br /&gt;ACH payment rejected&lt;br /&gt;ACH transaction canceled&lt;br /&gt;ACH Transfer canceled&lt;br /&gt;ACH transfer rejected&lt;br /&gt;Rejected ACH payment&lt;br /&gt;Rejected ACH transaction&lt;br /&gt;Rejected ACH transfer&lt;br /&gt;Your ACH transaction&lt;br /&gt;Your ACH transfer&lt;br /&gt;&lt;br /&gt;Each claims to be from "nacha.org" - the National Automated Clearing House Association - the people who handle electronic payments between banks.&lt;br /&gt;&lt;br /&gt;The from addresses are:&lt;br /&gt;&lt;br /&gt;ach@nacha.org&lt;br /&gt;admin@nacha.org&lt;br /&gt;alert@nacha.org&lt;br /&gt;alerts@nacha.org&lt;br /&gt;info@nacha.org&lt;br /&gt;payment@nacha.org&lt;br /&gt;payments@nacha.org&lt;br /&gt;risk@nacha.org&lt;br /&gt;risk_manager@nacha.org&lt;br /&gt;transactions@nacha.org&lt;br /&gt;transfers@nacha.org&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here are the domain names we are seeing this time around.  I haven't checked all of them, but the ones I checked were GoDaddy.  (GoDaddy and Affilias have been notified, and many of the domains are already disabled.)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;              machine              &lt;br /&gt;-----------------------------------&lt;br /&gt; ACHDESCRIBES.INFO&lt;br /&gt; ACH-DETAILS-EMERGE.INFO&lt;br /&gt; ACHDETAILSEMERGE.INFO&lt;br /&gt; ACH-DETAILS.INFO&lt;br /&gt; ACHDETAILS.INFO&lt;br /&gt; ACH-DETAILS-MAGAZINE.INFO&lt;br /&gt; ACHDETAILSMAGAZINE.INFO&lt;br /&gt; ACHDETAILSNOW.INFO&lt;br /&gt; ACHDETAILSONLINE.INFO&lt;br /&gt; ACHDETAILSSHOP.INFO&lt;br /&gt; ACHDETAILSSITE.INFO&lt;br /&gt; ACHDETAILSSTORE.INFO&lt;br /&gt; ACHDETAILSTODAY.INFO&lt;br /&gt; ACHELEMENTS.INFO&lt;br /&gt; ACH-INFORMATION-ARCHITECTURE.INFO&lt;br /&gt; ACHINFORMATIONASSURANCE.INFO&lt;br /&gt; ACHINFORMATIONBLOG.INFO&lt;br /&gt; ACH-INFORMATION.INFO&lt;br /&gt; ACHINFORMATION.INFO&lt;br /&gt; ACHINFORMATIONLITERACY.INFO&lt;br /&gt; ACHINFORMATIONNOW.INFO&lt;br /&gt; ACHINFORMATIONONLINE.INFO&lt;br /&gt; ACH-INFORMATION-SCIENCES.INFO&lt;br /&gt; ACHINFORMATIONSCIENCES.INFO&lt;br /&gt; ACH-INFORMATION-SHARING.INFO&lt;br /&gt; ACHINFORMATIONSHARING.INFO&lt;br /&gt; ACHINFORMATIONSHOP.INFO&lt;br /&gt; ACHINFORMATIONS.INFO&lt;br /&gt; ACHINFORMATIONSITE.INFO&lt;br /&gt; ACHINFORMATIONSTORE.INFO&lt;br /&gt; ACHINFORMATIONTODAY.INFO&lt;br /&gt; ACHINFORMATIONWARFARE.INFO&lt;br /&gt; ACHINFORMS.INFO&lt;br /&gt; ACHREPORTBLOG.INFO&lt;br /&gt; ACH-REPORT-CARD.INFO&lt;br /&gt; ACHREPORTCARD.INFO&lt;br /&gt; ACH-REPORT-CARDS.INFO&lt;br /&gt; ACHREPORTCARDS.INFO&lt;br /&gt; ACH-REPORT-COVERS.INFO&lt;br /&gt; ACHREPORTCOVERS.INFO&lt;br /&gt; ACH-REPORT.INFO&lt;br /&gt; ACHREPORT.INFO&lt;br /&gt; ACHREPORTNOW.INFO&lt;br /&gt; ACHREPORTONLINE.INFO&lt;br /&gt; ACHREPORTSHOP.INFO&lt;br /&gt; ACHREPORTS.INFO&lt;br /&gt; ACHREPORTSITE.INFO&lt;br /&gt; ACHREPORTSTORE.INFO&lt;br /&gt; ACHREPORTTODAY.INFO&lt;br /&gt; ACHREVIEW.INFO&lt;br /&gt; ATRANSFERADMISSION.INFO&lt;br /&gt; ATRANSFERAGENT.INFO&lt;br /&gt; ATRANSFERAPPLICANTS.INFO&lt;br /&gt; A-TRANSFERBLOG.INFO&lt;br /&gt; ATRANSFERFILES.INFO&lt;br /&gt; ATRANSFERGUIDES.INFO&lt;br /&gt; ATRANSFER.INFO&lt;br /&gt; A-TRANSFERNOW.INFO&lt;br /&gt; A-TRANSFERONLINE.INFO&lt;br /&gt; ATRANSFERPRICING.INFO&lt;br /&gt; ATRANSFERREQUEST.INFO&lt;br /&gt; A-TRANSFERSHOP.INFO&lt;br /&gt; A-TRANSFERS.INFO&lt;br /&gt; A-TRANSFERSITE.INFO&lt;br /&gt; A-TRANSFER-STATION.INFO&lt;br /&gt; ATRANSFERSTATION.INFO&lt;br /&gt; A-TRANSFERSTORE.INFO&lt;br /&gt; A-TRANSFERTODAY.INFO&lt;br /&gt; B-ACH-ACCOUNTS.INFO&lt;br /&gt; BACHACCOUNTS.INFO&lt;br /&gt; B-ACHBLOG.INFO&lt;br /&gt; B-ACH.INFO&lt;br /&gt; B-ACHNOW.INFO&lt;br /&gt; B-ACHONLINE.INFO&lt;br /&gt; B-ACH-PAYMENT.INFO&lt;br /&gt; BACHPAYMENT.INFO&lt;br /&gt; B-ACH-PAYMENTS.INFO&lt;br /&gt; BACHPAYMENTS.INFO&lt;br /&gt; B-ACHSHOP.INFO&lt;br /&gt; B-ACHS.INFO&lt;br /&gt; B-ACHSITE.INFO&lt;br /&gt; B-ACHSTORE.INFO&lt;br /&gt; B-ACHTODAY.INFO&lt;br /&gt; B-ACH-TRANSACTIONS.INFO&lt;br /&gt; BACHTRANSACTIONS.INFO&lt;br /&gt; BESTACHDETAILS.INFO&lt;br /&gt; BESTACHINFORMATION.INFO&lt;br /&gt; BESTACHREPORT.INFO&lt;br /&gt; BESTA-TRANSFER.INFO&lt;br /&gt; BESTB-ACH.INFO&lt;br /&gt; BESTD-PAYMENT.INFO&lt;br /&gt; BESTG-PAYMENT.INFO&lt;br /&gt; BESTP-ACH.INFO&lt;br /&gt; BESTQ-ACH.INFO&lt;br /&gt; BESTQ-PAYMENT.INFO&lt;br /&gt; BESTQ-TRANSFER.INFO&lt;br /&gt; BESTR-TRANSFER.INFO&lt;br /&gt; BESTT-TRANSFER.INFO&lt;br /&gt; BESTV-ACH.INFO&lt;br /&gt; BESTW-ACH.INFO&lt;br /&gt; BESTZ-PAYMENT.INFO&lt;br /&gt; D-PAYMENTBLOG.INFO&lt;br /&gt; D-PAYMENT.INFO&lt;br /&gt; DPAYMENT.INFO&lt;br /&gt; DPAYMENTMETHOD.INFO&lt;br /&gt; DPAYMENTMETHODS.INFO&lt;br /&gt; D-PAYMENTNOW.INFO&lt;br /&gt; D-PAYMENTONLINE.INFO&lt;br /&gt; DPAYMENTOPTION.INFO&lt;br /&gt; DPAYMENTPROCESSING.INFO&lt;br /&gt; DPAYMENTPROCESSOR.INFO&lt;br /&gt; D-PAYMENTSHOP.INFO&lt;br /&gt; D-PAYMENTS.INFO&lt;br /&gt; D-PAYMENTSITE.INFO&lt;br /&gt; DPAYMENTSOLUTION.INFO&lt;br /&gt; DPAYMENTSOLUTIONS.INFO&lt;br /&gt; D-PAYMENTSTORE.INFO&lt;br /&gt; DPAYMENTTERMINAL.INFO&lt;br /&gt; D-PAYMENTTODAY.INFO&lt;br /&gt; DPAYMENTTRANSACTION.INFO&lt;br /&gt; ELECTRONIC-ACH-DETAILS.INFO&lt;br /&gt; ELECTRONICACHDETAILS.INFO&lt;br /&gt; ELECTRONIC-ACH-REPORT.INFO&lt;br /&gt; ELECTRONICACHREPORT.INFO&lt;br /&gt; FREEACHDETAILS.INFO&lt;br /&gt; FREEACHINFORMATION.INFO&lt;br /&gt; FREEACHREPORT.INFO&lt;br /&gt; FREEA-TRANSFER.INFO&lt;br /&gt; FREEB-ACH.INFO&lt;br /&gt; FREED-PAYMENT.INFO&lt;br /&gt; FREEG-PAYMENT.INFO&lt;br /&gt; FREEQ-ACH.INFO&lt;br /&gt; FREEQ-PAYMENT.INFO&lt;br /&gt; FREEQ-TRANSFER.INFO&lt;br /&gt; FREER-TRANSFER.INFO&lt;br /&gt; FREET-TRANSFER.INFO&lt;br /&gt; FREEV-ACH.INFO&lt;br /&gt; FREEW-ACH.INFO&lt;br /&gt; FREEZ-PAYMENT.INFO&lt;br /&gt; G-PAYMENTBLOG.INFO&lt;br /&gt; G-PAYMENT.INFO&lt;br /&gt; GPAYMENT.INFO&lt;br /&gt; GPAYMENTMETHOD.INFO&lt;br /&gt; GPAYMENTMETHODS.INFO&lt;br /&gt; G-PAYMENTNOW.INFO&lt;br /&gt; G-PAYMENTONLINE.INFO&lt;br /&gt; GPAYMENTPROCESSING.INFO&lt;br /&gt; GPAYMENTPROCESSOR.INFO&lt;br /&gt; G-PAYMENTSHOP.INFO&lt;br /&gt; G-PAYMENTS.INFO&lt;br /&gt; G-PAYMENTSITE.INFO&lt;br /&gt; GPAYMENTSOLUTIONS.INFO&lt;br /&gt; G-PAYMENTSTORE.INFO&lt;br /&gt; GPAYMENTTERMINAL.INFO&lt;br /&gt; G-PAYMENTTODAY.INFO&lt;br /&gt; GPAYMENTTRANSACTION.INFO&lt;br /&gt; MASTER-P-ACH.INFO&lt;br /&gt; MASTERPACH.INFO&lt;br /&gt; MYACHDETAILS.INFO&lt;br /&gt; MYACHINFORMATION.INFO&lt;br /&gt; MYACHREPORT.INFO&lt;br /&gt; MYA-TRANSFER.INFO&lt;br /&gt; MYB-ACH.INFO&lt;br /&gt; MYD-PAYMENT.INFO&lt;br /&gt; MYG-PAYMENT.INFO&lt;br /&gt; MYP-ACH.INFO&lt;br /&gt; MYQ-ACH.INFO&lt;br /&gt; MYQ-PAYMENT.INFO&lt;br /&gt; MYQ-TRANSFER.INFO&lt;br /&gt; MYR-TRANSFER.INFO&lt;br /&gt; MYT-TRANSFER.INFO&lt;br /&gt; MYV-ACH.INFO&lt;br /&gt; MYW-ACH.INFO&lt;br /&gt; MYZ-PAYMENT.INFO&lt;br /&gt; NEWACHDETAILS.INFO&lt;br /&gt; NEWACHINFORMATION.INFO&lt;br /&gt; NEWACHREPORT.INFO&lt;br /&gt; NEWA-TRANSFER.INFO&lt;br /&gt; NEWB-ACH.INFO&lt;br /&gt; NEWD-PAYMENT.INFO&lt;br /&gt; NEWG-PAYMENT.INFO&lt;br /&gt; NEWP-ACH.INFO&lt;br /&gt; NEWQ-ACH.INFO&lt;br /&gt; NEWQ-PAYMENT.INFO&lt;br /&gt; NEWQ-TRANSFER.INFO&lt;br /&gt; NEWR-TRANSFER.INFO&lt;br /&gt; NEWT-TRANSFER.INFO&lt;br /&gt; NEWV-ACH.INFO&lt;br /&gt; NEWW-ACH.INFO&lt;br /&gt; NEWZ-PAYMENT.INFO&lt;br /&gt; P-ACH-ACCOUNTS.INFO&lt;br /&gt; PACHACCOUNTS.INFO&lt;br /&gt; P-ACHBLOG.INFO&lt;br /&gt; P-ACH.INFO&lt;br /&gt; P-ACHNOW.INFO&lt;br /&gt; P-ACHONLINE.INFO&lt;br /&gt; P-ACH-PAYMENT.INFO&lt;br /&gt; PACHPAYMENT.INFO&lt;br /&gt; P-ACH-PAYMENTS.INFO&lt;br /&gt; PACHPAYMENTS.INFO&lt;br /&gt; P-ACHSHOP.INFO&lt;br /&gt; P-ACHS.INFO&lt;br /&gt; P-ACHSITE.INFO&lt;br /&gt; P-ACHSTORE.INFO&lt;br /&gt; P-ACHTODAY.INFO&lt;br /&gt; P-ACH-TRANSACTIONS.INFO&lt;br /&gt; PACHTRANSACTIONS.INFO&lt;br /&gt; Q-ACH-ACCOUNTS.INFO&lt;br /&gt; QACHACCOUNTS.INFO&lt;br /&gt; Q-ACHBLOG.INFO&lt;br /&gt; Q-ACH.INFO&lt;br /&gt; QACH.INFO&lt;br /&gt; Q-ACHNOW.INFO&lt;br /&gt; Q-ACHONLINE.INFO&lt;br /&gt; Q-ACH-PAYMENT.INFO&lt;br /&gt; QACHPAYMENT.INFO&lt;br /&gt; Q-ACH-PAYMENTS.INFO&lt;br /&gt; QACHPAYMENTS.INFO&lt;br /&gt; Q-ACHSHOP.INFO&lt;br /&gt; Q-ACHS.INFO&lt;br /&gt; Q-ACHSITE.INFO&lt;br /&gt; Q-ACHSTORE.INFO&lt;br /&gt; Q-ACHTODAY.INFO&lt;br /&gt; Q-ACH-TRANSACTIONS.INFO&lt;br /&gt; QACHTRANSACTIONS.INFO&lt;br /&gt; Q-PAYMENTBLOG.INFO&lt;br /&gt; Q-PAYMENT.INFO&lt;br /&gt; QPAYMENTMETHOD.INFO&lt;br /&gt; QPAYMENTMETHODS.INFO&lt;br /&gt; Q-PAYMENTNOW.INFO&lt;br /&gt; Q-PAYMENTONLINE.INFO&lt;br /&gt; QPAYMENTOPTION.INFO&lt;br /&gt; QPAYMENTPROCESSING.INFO&lt;br /&gt; QPAYMENTPROCESSOR.INFO&lt;br /&gt; QPAYMENTSCHEDULE.INFO&lt;br /&gt; Q-PAYMENTSHOP.INFO&lt;br /&gt; Q-PAYMENTS.INFO&lt;br /&gt; Q-PAYMENTSITE.INFO&lt;br /&gt; QPAYMENTSOLUTION.INFO&lt;br /&gt; QPAYMENTSOLUTIONS.INFO&lt;br /&gt; Q-PAYMENTSTORE.INFO&lt;br /&gt; QPAYMENTTERMINAL.INFO&lt;br /&gt; Q-PAYMENTTODAY.INFO&lt;br /&gt; QPAYMENTTRANSACTION.INFO&lt;br /&gt; QTRANSFERADMISSION.INFO&lt;br /&gt; QTRANSFERAGENT.INFO&lt;br /&gt; QTRANSFERAPPLICANTS.INFO&lt;br /&gt; Q-TRANSFERBLOG.INFO&lt;br /&gt; QTRANSFERFILES.INFO&lt;br /&gt; QTRANSFERGUIDES.INFO&lt;br /&gt; Q-TRANSFER.INFO&lt;br /&gt; QTRANSFER.INFO&lt;br /&gt; Q-TRANSFERNOW.INFO&lt;br /&gt; Q-TRANSFERONLINE.INFO&lt;br /&gt; QTRANSFERPRICING.INFO&lt;br /&gt; QTRANSFERREQUEST.INFO&lt;br /&gt; Q-TRANSFERSHOP.INFO&lt;br /&gt; Q-TRANSFERS.INFO&lt;br /&gt; Q-TRANSFERSITE.INFO&lt;br /&gt; Q-TRANSFER-STATION.INFO&lt;br /&gt; QTRANSFERSTATION.INFO&lt;br /&gt; Q-TRANSFERSTORE.INFO&lt;br /&gt; Q-TRANSFERTODAY.INFO&lt;br /&gt; RTRANSFERADMISSION.INFO&lt;br /&gt; RTRANSFERAGENT.INFO&lt;br /&gt; RTRANSFERAPPLICANTS.INFO&lt;br /&gt; R-TRANSFERBLOG.INFO&lt;br /&gt; RTRANSFERFILES.INFO&lt;br /&gt; RTRANSFERGUIDES.INFO&lt;br /&gt; R-TRANSFER.INFO&lt;br /&gt; RTRANSFER.INFO&lt;br /&gt; R-TRANSFERNOW.INFO&lt;br /&gt; R-TRANSFERONLINE.INFO&lt;br /&gt; RTRANSFERPRICING.INFO&lt;br /&gt; RTRANSFERREQUEST.INFO&lt;br /&gt; R-TRANSFERSHOP.INFO&lt;br /&gt; R-TRANSFERS.INFO&lt;br /&gt; R-TRANSFERSITE.INFO&lt;br /&gt; R-TRANSFER-STATION.INFO&lt;br /&gt; RTRANSFERSTATION.INFO&lt;br /&gt; R-TRANSFERSTORE.INFO&lt;br /&gt; R-TRANSFERTODAY.INFO&lt;br /&gt; TERMINAL-B-ACH.INFO&lt;br /&gt; TERMINALBACH.INFO&lt;br /&gt; THEACHDETAILS.INFO&lt;br /&gt; THEACHINFORMATION.INFO&lt;br /&gt; THEACHREPORT.INFO&lt;br /&gt; THEA-TRANSFER.INFO&lt;br /&gt; THEB-ACH.INFO&lt;br /&gt; THED-PAYMENT.INFO&lt;br /&gt; THEG-PAYMENT.INFO&lt;br /&gt; THEP-ACH.INFO&lt;br /&gt; THEQ-ACH.INFO&lt;br /&gt; THEQ-PAYMENT.INFO&lt;br /&gt; THEQ-TRANSFER.INFO&lt;br /&gt; THER-TRANSFER.INFO&lt;br /&gt; THET-TRANSFER.INFO&lt;br /&gt; THEV-ACH.INFO&lt;br /&gt; THEW-ACH.INFO&lt;br /&gt; THEZ-PAYMENT.INFO&lt;br /&gt; TTRANSFERADMISSION.INFO&lt;br /&gt; TTRANSFERAGENT.INFO&lt;br /&gt; TTRANSFERAPPLICANTS.INFO&lt;br /&gt; T-TRANSFERBLOG.INFO&lt;br /&gt; TTRANSFERFILES.INFO&lt;br /&gt; TTRANSFERGUIDES.INFO&lt;br /&gt; TTRANSFER.INFO&lt;br /&gt; T-TRANSFERNOW.INFO&lt;br /&gt; T-TRANSFERONLINE.INFO&lt;br /&gt; TTRANSFERPRICING.INFO&lt;br /&gt; TTRANSFERREQUEST.INFO&lt;br /&gt; T-TRANSFERSHOP.INFO&lt;br /&gt; T-TRANSFERS.INFO&lt;br /&gt; T-TRANSFERSITE.INFO&lt;br /&gt; T-TRANSFER-STATION.INFO&lt;br /&gt; TTRANSFERSTATION.INFO&lt;br /&gt; T-TRANSFERSTORE.INFO&lt;br /&gt; T-TRANSFERTODAY.INFO&lt;br /&gt; V-ACH-ACCOUNTS.INFO&lt;br /&gt; VACHACCOUNTS.INFO&lt;br /&gt; V-ACHBLOG.INFO&lt;br /&gt; V-ACH.INFO&lt;br /&gt; V-ACHNOW.INFO&lt;br /&gt; V-ACHONLINE.INFO&lt;br /&gt; V-ACH-PAYMENT.INFO&lt;br /&gt; VACHPAYMENT.INFO&lt;br /&gt; V-ACH-PAYMENTS.INFO&lt;br /&gt; VACHPAYMENTS.INFO&lt;br /&gt; V-ACHSHOP.INFO&lt;br /&gt; V-ACHS.INFO&lt;br /&gt; V-ACHSITE.INFO&lt;br /&gt; V-ACHSTORE.INFO&lt;br /&gt; V-ACHTODAY.INFO&lt;br /&gt; V-ACH-TRANSACTIONS.INFO&lt;br /&gt; VACHTRANSACTIONS.INFO&lt;br /&gt; W-ACH-ACCOUNTS.INFO&lt;br /&gt; WACHACCOUNTS.INFO&lt;br /&gt; W-ACHBLOG.INFO&lt;br /&gt; W-ACH.INFO&lt;br /&gt; W-ACHNOW.INFO&lt;br /&gt; W-ACHONLINE.INFO&lt;br /&gt; W-ACH-PAYMENT.INFO&lt;br /&gt; WACHPAYMENT.INFO&lt;br /&gt; W-ACH-PAYMENTS.INFO&lt;br /&gt; WACHPAYMENTS.INFO&lt;br /&gt; W-ACHSHOP.INFO&lt;br /&gt; W-ACHS.INFO&lt;br /&gt; W-ACHSITE.INFO&lt;br /&gt; W-ACHSTORE.INFO&lt;br /&gt; W-ACHTODAY.INFO&lt;br /&gt; WACHTRANSACTIONS.INFO&lt;br /&gt; WARRENGPAYMENT.INFO&lt;br /&gt; ZPAYMENTARRANGEMENT.INFO&lt;br /&gt; Z-PAYMENTBLOG.INFO&lt;br /&gt; ZPAYMENTCARD.INFO&lt;br /&gt; ZPAYMENTCARDS.INFO&lt;br /&gt; ZPAYMENTDATES.INFO&lt;br /&gt; ZPAYMENTDEADLINE.INFO&lt;br /&gt; ZPAYMENTDEFINITION.INFO&lt;br /&gt; ZPAYMENTINSTRUMENTS.INFO&lt;br /&gt; ZPAYMENTLOCATIONS.INFO&lt;br /&gt; Z-PAYMENTONLINE.INFO&lt;br /&gt; ZPAYMENTPLATFORM.INFO&lt;br /&gt; ZPAYMENTPROTECTION.INFO&lt;br /&gt; Z-PAYMENTSHOP.INFO&lt;br /&gt; Z-PAYMENTS.INFO&lt;br /&gt; Z-PAYMENTSITE.INFO&lt;br /&gt; Z-PAYMENTSTORE.INFO&lt;br /&gt; Z-PAYMENTTODAY.INFO&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-1186724132670188978?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/1186724132670188978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/1186724132670188978'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/03/more-ach-spam-from-nacha.html' title='More ACH Spam from NACHA'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-132082258659307686</id><published>2011-03-10T08:37:00.000-08:00</published><updated>2011-03-10T09:06:46.904-08:00</updated><title type='text'>ENISA on Botnets - Ten Tough Questions</title><content type='html'>Yesterday was the beginning of the "Workshop on Botnet Detection, Measurement, Disinfection &amp; Defence"  in Cologne, Germany.  ( &lt;a href="http://www.eco.de/antibotnet_workshop2011"&gt;agenda here&lt;/A&gt; )&lt;br /&gt;&lt;br /&gt;The tracks for Wednesday were "Anti-Botnet Policy Initiatives" and "Legal and Regulatory Issues" both featuring panelists from the Council of Europe and NATO.&lt;br /&gt;&lt;br /&gt;Today's tracks included "Anti-Botnet Policy Initiatives Part 2," "State of the Art on Measurements, Countermeasures, and Botnets," "Industry View on Fighting Botnets," "Research and Academia on Fighting Botnets."  Some great speakers are on the agenda, including Peter Kruse and Dennis Rand from CSIS Security Group, Mikko Hypponen from F-Secure, and Vitaly Kamluk from Kaspersky.&lt;br /&gt;&lt;br /&gt;Two significant documents were released at the conference this morning that pretty much need to go on the Must Read list for anyone interested in Botnets:&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Botnets: Detection, Measurement, Disinfection &amp; Defence&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;After a keynote address by Professor Dr. Udo Helmbrecht, the executive director of ENISA (European Network and Information Security Agency), Daniel Plohmann and Dr. Giles Hogben shared a presentation of ENISA's 154 page document called "Botnets: Detection, Measurement, Disinfection &amp; Defence", editor Dr. Giles Hogben, which you may find on their website here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.enisa.europa.eu/act/res/botnets/botnets-measurement-detection-disinfection-and-defence"&gt;http://www.enisa.europa.eu/act/res/botnets/botnets-measurement-detection-disinfection-and-defence&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;The document calls attention to the highest priorities that we should collectively address:&lt;br /&gt;  - Mitigation of existing botnets&lt;br /&gt;  - Prevention of new infections&lt;br /&gt;  - Minimizing the profitability of botnets and cybercrime&lt;br /&gt;&lt;br /&gt;In the first of these, there is a call for a new model of engaging, encouraging, and incentivizing Internet Service Providers to be an asset in the botnet fight.  Current business models and in some cases current laws both reduce the effectiveness of ISPs in helping to fight botnets.  Other MITIGATION issues encourage improved botnet identification and monitoring, increased information sharing, and bringing cybercrime laws into harmony internationally.  Other advice had to do with making sure the entire botnet can be killed before attempting a "partial shutdown."&lt;br /&gt;&lt;br /&gt;Under the PREVENTION category, public awareness, and improvements to software defenses are encouraged.&lt;br /&gt;&lt;br /&gt;Under the PROFITABILITY category, it is necessary to improve anti-fraud mechanisms, and to address the social level of the crimes rather than only the technological level, by increasing deterrence through tougher prosecution and sentencing of offenders.&lt;br /&gt;&lt;br /&gt;Specific guidance is provided for Regulators, End-users, Research Institutions, and &lt;br /&gt;any information holders.  &lt;br /&gt;&lt;br /&gt;With regards to the Research Institutions, the recommendation was that they should be "more strongly integrated, and where appropriate, empowered in the fight against botnets.  Research should focus on techniques which can be implemented in large-scale operations environments subject to typical cost constraints.  They should be supported in studying methods for the detection of botnets and the analysis of malware, in order to provide efficient tools to reduce the reaction time when dealing with complex and sophisticated malware threats.  As the results of research may be of interest for ongoing investigations, the process of publishing these results should reflect the responsibility associated with them."  (extracted from the Executive Summary, p. 7)&lt;br /&gt;&lt;br /&gt;Towards that end, I want to mention that the Anti-Phishing Working Group is trying to encourage this level of interaction between Researchers, Law Enforcement, and Industry through events such as next week's "eCrime Researchers Sync-Up."  My colleague, Kent Kerley, and I will be attending from the University of Alabama at Birmingham to work on building these international relationships, not just among EU nations, but around the world.  APWG sponsors the eCrime Researchers Summit, the eCrime Operations Summit, and now the eCrime Researchers Sync-up to try to encourage exactly the types of interactions described in this report.  To learn more about APWG events, visit the &lt;a href="http://www.ecrimeresearch.org/"&gt;APWG eCrime Research page&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Botnets: Ten Tough Questions&lt;/H3&gt;&lt;br /&gt;Second, ENISA's document called "Botnets: 10 Tough Questions" which is an 18 page summary of some of the major issues facing us regarding Botnets.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.enisa.europa.eu/act/res/botnets/botnets-10-tough-questions"&gt;Botnets: Ten Tough Questions&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;The Ten Tough Questions document is described as a document that "distills the major issues which need to be understood and addressed by decision-makers in all groups of stakeholders."&lt;br /&gt;&lt;br /&gt;Here's a list of the Questions to whet your appetite.  I highly recommend consuming both documents!&lt;br /&gt;&lt;br /&gt;Q1. How much trust to put in published figures?&lt;br /&gt;&lt;br /&gt;Q2. What are the main challenges associated with jurisdiction?&lt;br /&gt;&lt;br /&gt;Q3. What should be the main role of the EU/National Governments?&lt;br /&gt;&lt;br /&gt;Q4. Which parties should take which responsibilities?&lt;br /&gt;&lt;br /&gt;Q5. Where to invest money most efficiently?&lt;br /&gt;&lt;br /&gt;   (HINT!  EDUCATION AND RESEARCH!!)&lt;br /&gt;&lt;br /&gt;Q6. What are key incentives for cooperative information sharing?&lt;br /&gt;&lt;br /&gt;Q7. What are key challegnes for cooperative information sharing?&lt;br /&gt;&lt;br /&gt;Q8. Are there unseen/undetected botnets?&lt;br /&gt;&lt;br /&gt;Q9. Which aspects are still missing in the fight against botnets?&lt;br /&gt;&lt;br /&gt;Q10. What are future trends?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-132082258659307686?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/132082258659307686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/132082258659307686'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/03/enisa-on-botnets-ten-tough-questions.html' title='ENISA on Botnets - Ten Tough Questions'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-3301405575826486508</id><published>2011-03-09T14:08:00.001-08:00</published><updated>2011-03-09T14:33:26.625-08:00</updated><title type='text'>Ghostmarket Carders Sentenced in UK</title><content type='html'>Back in November we ran a story &lt;a href="http://www.met.police.uk/pressbureau/Bur02/op_pagode/co403-10_please_and_sentences.htm"&gt;Schoolboy Hackers steal $18 Million&lt;/A&gt; regarding the case against the operators of the online credit card trading forum known as Ghostmarket.  Today's post is just a quick follow-up to share details of their sentences from New Scotland Yard.&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.met.police.uk/pressbureau/Bur02/op_pagode/CO403-10webberchat.jpg" width=80% height=80%&gt;&lt;br /&gt;&lt;br /&gt;The defendants had harvested more than 130,000 compromised credit card numbers, and had successfully installed Zeus on more than 15,000 computers in 150 countries, gathering more than 4 million lines of data from the compromised computers.&lt;br /&gt;&lt;br /&gt;The Metropolitan Police of London sentenced the Ghostmarket criminals on March 2, 2011, as they share in this &lt;a href="http://www.met.police.uk/pressbureau/Bur02/page10.htm"&gt;Press Release&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;An audio clip by &lt;a href="http://www.met.police.uk/pressbureau/Bur02/op_pagode/CO403-10_di_wetherill_audioclip.mp3"&gt;Detective Inspector Colin Wetherill&lt;/A&gt; explains the accomplishment.&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.met.police.uk/pressbureau/Bur02/op_pagode/CO403-10Kelly.JPG"  width=50% height=50%&gt;&lt;br /&gt;[A] Gary Paul Kelly, 21 (14.04.89) unemployed of Clively Avenue, Clifton, Swinton, Manchester -- sentenced to Five Years&lt;br /&gt;&lt;br /&gt;Kelly was arrested on November 3, 2009 as a result of a search warrant of his home.  Detectives were able to build a working copy of the GhostMarket forum from the database files recovered from Kelly's PC. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.met.police.uk/pressbureau/Bur02/op_pagode/CO403-10webber.jpg"  width=50% height=50%&gt;&lt;br /&gt;[B] Nicholas Webber, 19 (10.10.91) a student of Cavendish Road, Southsea; -- sentenced to Five Years&lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.met.police.uk/pressbureau/Bur02/op_pagode/CO403-10thomas.jpg"  width=50% height=50%&gt;&lt;br /&gt;[C] Ryan Thomas, 18 (8.7.92) a web designer of Howard Road, Seer Green, Beaconsfield, Herts; -- sentenced to Four Years&lt;br /&gt;&lt;br /&gt;Webber and Thomas were arrested on October 12, 2009 while partying in a five star London hotel, paid for with stolen credit cards.  A big hint that they may be associated with the crime of carding and the GhostMarket website was that both were in possession of GhostMarket business cards in their name, calling the site "A new era in virtual marketing" and stating "I'm a carder, ask about me..."&lt;br /&gt;&lt;br /&gt;After being released on bail, the pair were rearrested at the Gatwick airport on January 29, 2010 as they returned from a trip to Palma, Majorca. &lt;br /&gt;&lt;br /&gt;&lt;IMG SRC="http://www.met.police.uk/pressbureau/Bur02/op_pagode/CO403-10ricardo.jpg"  width=50% height=50%&gt;&lt;br /&gt;[D] Shakira Ricardo, 21 (14.11.89) unemployed of Flat 13, J Shed, Kings Road, Swansea SA1; -- sentenced to 18 Months.&lt;br /&gt;&lt;br /&gt;A fifth defendant, Samantha Worley, pleaded guilty earlier and received a sentence of 200 hours community service.&lt;br /&gt;&lt;br /&gt;Full details of the charges against the five are available from &lt;a href="http://www.met.police.uk/pressbureau/Bur02/op_pagode/co403-10_please_and_sentences.htm"&gt;The Metropolitan Police of London&lt;/A&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-3301405575826486508?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/3301405575826486508'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/3301405575826486508'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/03/ghostmarket-carders-sentenced-in-uk.html' title='Ghostmarket Carders Sentenced in UK'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-6858589914118313681</id><published>2011-02-25T02:52:00.000-08:00</published><updated>2011-02-25T03:52:49.592-08:00</updated><title type='text'>"ACH Transaction Rejected" payments lead to Zeus</title><content type='html'>On February 23rd, our friends at Trend Micro reported that &lt;a href="http://about-threats.trendmicro.com/Spam.aspx?language=us&amp;name=ACH+Leads+to+Fake+Java+Update"&gt;ACH Leads to Fake Java Update&lt;/A&gt;.  Looking into this campaign in the &lt;a href="http://www.cis.uab.edu/UABSpamDataMine"&gt;UAB Spam Data Mine&lt;/A&gt; we found some interesting characteristics about the spam campaign.&lt;br /&gt;&lt;br /&gt;We've seen NACHA, the National Automated Clearing House Association, used as bait for a Zeus trap before.  See our article from November 2009, &lt;a href="http://garwarner.blogspot.com/2009/11/newest-zeus-nacha-electronic-payments.html"&gt;Newest Zeus = NACHA The Electronic Payments Association&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;The spam body, containing a random signator name and random domain reads:&lt;br /&gt;&lt;br /&gt;===========================================================================&lt;br /&gt;&lt;br /&gt;The ACH transaction , recently initiated from your bank account (by you or any&lt;br /&gt;other person), was rejected by the Electronic Payments Association.&lt;br /&gt;&lt;br /&gt;Please click here &lt;http://ACHTS.INFO&gt; to view details&lt;br /&gt;&lt;br /&gt;------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Benjamin Grant,&lt;br /&gt;Fraud Department&lt;br /&gt;&lt;br /&gt;==========================================================================&lt;br /&gt;&lt;br /&gt;Here are our counts by Subject so far for this campaign:&lt;br /&gt;&lt;br /&gt; count |          subject          &lt;br /&gt;-------+---------------------------&lt;br /&gt;  1656 | ACH Transfer cancelled&lt;br /&gt;  1620 | Your ACH Transfer&lt;br /&gt;  1558 | ACH Transfer rejected&lt;br /&gt;  1598 | Your ACH transaction&lt;br /&gt;  1610 | ACH transaction cancelled&lt;br /&gt;  1622 | ACH transaction rejected&lt;br /&gt;(6 rows)&lt;br /&gt;&lt;br /&gt;That's out of a volume of slightly more than 1 million emails per day.  Here it is with date added:&lt;br /&gt;&lt;br /&gt; count |          subject          | receiving_date&lt;br /&gt;-------+---------------------------+----------------&lt;br /&gt;    10 | ACH transaction cancelled | 2011-02-22&lt;br /&gt;    13 | ACH transaction rejected  | 2011-02-22&lt;br /&gt;    23 | ACH Transfer cancelled    | 2011-02-22&lt;br /&gt;    18 | ACH Transfer rejected     | 2011-02-22&lt;br /&gt;    15 | Your ACH transaction      | 2011-02-22&lt;br /&gt;    11 | Your ACH Transfer         | 2011-02-22&lt;br /&gt;  1600 | ACH transaction cancelled | 2011-02-23&lt;br /&gt;  1609 | ACH transaction rejected  | 2011-02-23&lt;br /&gt;  1633 | ACH Transfer cancelled    | 2011-02-23&lt;br /&gt;  1540 | ACH Transfer rejected     | 2011-02-23&lt;br /&gt;  1583 | Your ACH transaction      | 2011-02-23&lt;br /&gt;  1609 | Your ACH Transfer         | 2011-02-23&lt;br /&gt;(12 rows)&lt;br /&gt;&lt;br /&gt;What was extremely interesting about this campaign was the large number of domains it registered to be used in this abuse.  Fortunately, these were all "GoDaddy.com" domains and were quickly brought under control to prevent the spread of the malware.&lt;br /&gt;&lt;br /&gt;Here are our volume by spammed domain:&lt;br /&gt;&lt;br /&gt; count |             machine            &lt;br /&gt;-------+---------------------------------&lt;br /&gt;    26 | AC-CURE-HS.INFO&lt;br /&gt;    30 | ACCUREHS.INFO&lt;br /&gt;    33 | ACH-ACCOUNTS.INFO&lt;br /&gt;    26 | ACHACCOUNTS.INFO&lt;br /&gt;    29 | ACHDAUDIO.INFO&lt;br /&gt;    29 | ACHDBLOG.INFO&lt;br /&gt;    28 | ACHDCAMERA.INFO&lt;br /&gt;    25 | ACHDCOMPATIBLE.INFO&lt;br /&gt;    26 | ACHDFORMAT.INFO&lt;br /&gt;    30 | AC-HD.INFO&lt;br /&gt;    30 | ACHDNOW.INFO&lt;br /&gt;    26 | ACHDONLINE.INFO&lt;br /&gt;    24 | ACHDPHOTO.INFO&lt;br /&gt;    36 | ACHDPROGRAMMING.INFO&lt;br /&gt;    31 | ACHDRECEIVER.INFO&lt;br /&gt;    28 | ACHDRECORDING.INFO&lt;br /&gt;    34 | ACHDSHOP.INFO&lt;br /&gt;    34 | ACHDSIGNALS.INFO&lt;br /&gt;    39 | ACHDS.INFO&lt;br /&gt;    26 | ACHDSITE.INFO&lt;br /&gt;    27 | ACHDSTORE.INFO&lt;br /&gt;    25 | ACHDTODAY.INFO&lt;br /&gt;    31 | ACHFACID.INFO&lt;br /&gt;    36 | ACHFBANDS.INFO&lt;br /&gt;    34 | ACHFBLOG.INFO&lt;br /&gt;    45 | ACHFBROADCASTING.INFO&lt;br /&gt;    37 | ACHFCONTEST.INFO&lt;br /&gt;    27 | ACHFEXPOSURE.INFO&lt;br /&gt;    37 | AC-HF.INFO&lt;br /&gt;    27 | ACHFMOBILE.INFO&lt;br /&gt;    24 | ACHFNOW.INFO&lt;br /&gt;    26 | ACHFONLINE.INFO&lt;br /&gt;    34 | ACHFRADAR.INFO&lt;br /&gt;    25 | ACHFRECEIVER.INFO&lt;br /&gt;    22 | ACHFSHOP.INFO&lt;br /&gt;    37 | ACHFS.INFO&lt;br /&gt;    38 | ACHFSITE.INFO&lt;br /&gt;    31 | ACHFSPECTRUM.INFO&lt;br /&gt;    30 | ACHFSTORE.INFO&lt;br /&gt;    28 | ACHFTODAY.INFO&lt;br /&gt;    28 | ACHGBLOG.INFO&lt;br /&gt;    47 | ACHGENTERTAINMENT.INFO&lt;br /&gt;    35 | AC-HG-EXPOSURE.INFO&lt;br /&gt;    40 | ACHGEXPOSURE.INFO&lt;br /&gt;    44 | AC-HG.INFO&lt;br /&gt;    26 | ACHGMETAL.INFO&lt;br /&gt;    33 | ACHGNOW.INFO&lt;br /&gt;    27 | ACHGONLINE.INFO&lt;br /&gt;    17 | ACHGSHOP.INFO&lt;br /&gt;    26 | ACHGS.INFO&lt;br /&gt;    29 | ACHGSITE.INFO&lt;br /&gt;    27 | ACHGSPOT.INFO&lt;br /&gt;    29 | ACHGSTORE.INFO&lt;br /&gt;    26 | ACHGTODAY.INFO&lt;br /&gt;    26 | AC-HG-VACUUM.INFO&lt;br /&gt;    30 | ACHGVACUUM.INFO&lt;br /&gt;    27 | AC-HG-WELLS.INFO&lt;br /&gt;    31 | ACHGWELLS.INFO&lt;br /&gt;    28 | AC-HIGHSCHOOL.INFO&lt;br /&gt;    33 | ACHIGHSCHOOL.INFO&lt;br /&gt;    25 | ACH-PAYMENT.INFO&lt;br /&gt;    28 | ACH-PAYMENTS.INFO&lt;br /&gt;    30 | ACHPBLOG.INFO&lt;br /&gt;    41 | ACHPCERTIFICATION.INFO&lt;br /&gt;    39 | ACHPENTERPRISE.INFO&lt;br /&gt;    34 | ACHPHARDWARE.INFO&lt;br /&gt;    36 | ACHPIBLOG.INFO&lt;br /&gt;    27 | AC-HPI-CARS.INFO&lt;br /&gt;    33 | ACHPICARS.INFO&lt;br /&gt;    27 | AC-HPI-CHECKS.INFO&lt;br /&gt;    30 | ACHPICHECKS.INFO&lt;br /&gt;    32 | AC-HPI.INFO&lt;br /&gt;    33 | ACHPI.INFO&lt;br /&gt;    28 | AC-HP.INFO&lt;br /&gt;    26 | ACHPINOW.INFO&lt;br /&gt;    33 | ACHPINTEGRITY.INFO&lt;br /&gt;    27 | ACHPIONLINE.INFO&lt;br /&gt;    21 | AC-HPI-RACING.INFO&lt;br /&gt;    30 | ACHPIRACING.INFO&lt;br /&gt;    38 | ACHPISHOP.INFO&lt;br /&gt;    23 | ACHPIS.INFO&lt;br /&gt;    32 | ACHPISITE.INFO&lt;br /&gt;    20 | ACHPISTORE.INFO&lt;br /&gt;    26 | ACHPITODAY.INFO&lt;br /&gt;    30 | ACHPLINUX.INFO&lt;br /&gt;    25 | ACHPNOW.INFO&lt;br /&gt;    28 | ACHPONLINE.INFO&lt;br /&gt;    24 | ACHPPHOTO.INFO&lt;br /&gt;    23 | ACHPPRINTER.INFO&lt;br /&gt;    35 | ACHPSERVER.INFO&lt;br /&gt;    40 | ACHPSERVERS.INFO&lt;br /&gt;    40 | ACHPSHOP.INFO&lt;br /&gt;    31 | ACHPS.INFO&lt;br /&gt;    28 | ACHPSITE.INFO&lt;br /&gt;    32 | ACHPSTORE.INFO&lt;br /&gt;    34 | ACHPTODAY.INFO&lt;br /&gt;    21 | ACHSBLOG.INFO&lt;br /&gt;    32 | AC-HS.INFO&lt;br /&gt;    33 | ACHSNOW.INFO&lt;br /&gt;    35 | ACHSONLINE.INFO&lt;br /&gt;    36 | ACHSSHOP.INFO&lt;br /&gt;    38 | ACHSSITE.INFO&lt;br /&gt;    33 | ACHSSTORE.INFO&lt;br /&gt;    33 | ACHSTODAY.INFO&lt;br /&gt;    35 | ACHTBLOG.INFO&lt;br /&gt;    31 | AC-HT-CONSULTING.INFO&lt;br /&gt;    38 | ACHTCONSULTING.INFO&lt;br /&gt;    19 | AC-HT-EDITOR.INFO&lt;br /&gt;    31 | ACHTEDITOR.INFO&lt;br /&gt;    30 | AC-HT-ENTERPRISES.INFO&lt;br /&gt;    37 | ACHTENTERPRISES.INFO&lt;br /&gt;    31 | AC-HT.INFO&lt;br /&gt;    35 | AC-HT-MOBILE.INFO&lt;br /&gt;    32 | ACHTMOBILE.INFO&lt;br /&gt;    33 | ACHTNOW.INFO&lt;br /&gt;    26 | ACHTRANSACTIONBLOG.INFO&lt;br /&gt;    35 | ACHTRANSACTIONCODE.INFO&lt;br /&gt;    38 | ACH-TRANSACTION.INFO&lt;br /&gt;    29 | ACHTRANSACTION.INFO&lt;br /&gt;    29 | ACHTRANSACTIONISOLATION.INFO&lt;br /&gt;    23 | ACHTRANSACTIONLAYER.INFO&lt;br /&gt;    28 | ACHTRANSACTIONLOGIC.INFO&lt;br /&gt;    26 | ACHTRANSACTIONMONITORING.INFO&lt;br /&gt;    18 | ACHTRANSACTIONNOW.INFO&lt;br /&gt;    29 | ACHTRANSACTIONONLINE.INFO&lt;br /&gt;    27 | ACH-TRANSACTION-PROCESSING.INFO&lt;br /&gt;    32 | ACHTRANSACTIONPROCESSING.INFO&lt;br /&gt;    34 | ACH-TRANSACTION-PUBLISHERS.INFO&lt;br /&gt;    29 | ACHTRANSACTIONPUBLISHERS.INFO&lt;br /&gt;    17 | ACHTRANSACTIONSHOP.INFO&lt;br /&gt;    31 | ACH-TRANSACTIONS.INFO&lt;br /&gt;    28 | ACHTRANSACTIONS.INFO&lt;br /&gt;    29 | ACHTRANSACTIONSITE.INFO&lt;br /&gt;    31 | ACHTRANSACTIONSTORE.INFO&lt;br /&gt;    29 | ACHTRANSACTIONTODAY.INFO&lt;br /&gt;    28 | ACHTRANSFERAGENT.INFO&lt;br /&gt;    28 | ACHTRANSFERBLOG.INFO&lt;br /&gt;    33 | ACHTRANSFERCREDITS.INFO&lt;br /&gt;    26 | ACHTRANSFERFILES.INFO&lt;br /&gt;    37 | ACHTRANSFERGUIDE.INFO&lt;br /&gt;    31 | ACHTRANSFERGUIDES.INFO&lt;br /&gt;    34 | ACH-TRANSFER.INFO&lt;br /&gt;    30 | ACHTRANSFER.INFO&lt;br /&gt;    30 | ACHTRANSFERNOW.INFO&lt;br /&gt;    32 | ACHTRANSFERONLINE.INFO&lt;br /&gt;    35 | ACHTRANSFERPRICING.INFO&lt;br /&gt;    16 | ACHTRANSFERREQUEST.INFO&lt;br /&gt;    33 | ACHTRANSFERSHOP.INFO&lt;br /&gt;    32 | ACHTRANSFERS.INFO&lt;br /&gt;    35 | ACHTRANSFERSITE.INFO&lt;br /&gt;    34 | ACH-TRANSFER-STATION.INFO&lt;br /&gt;    31 | ACHTRANSFERSTATION.INFO&lt;br /&gt;    30 | ACHTRANSFERSTORE.INFO&lt;br /&gt;    29 | ACHTRANSFERTODAY.INFO&lt;br /&gt;    25 | ACHTRUSTASSETS.INFO&lt;br /&gt;    25 | ACHTRUSTBLOG.INFO&lt;br /&gt;    31 | ACHTRUSTCORPORATION.INFO&lt;br /&gt;    37 | ACHTRUSTDOCUMENT.INFO&lt;br /&gt;    32 | ACH-TRUST.INFO&lt;br /&gt;    31 | ACHTRUST.INFO&lt;br /&gt;    32 | ACHTRUSTINSTRUMENT.INFO&lt;br /&gt;    20 | ACHTRUSTINVESTMENTS.INFO&lt;br /&gt;    21 | ACHTRUSTLANDS.INFO&lt;br /&gt;    33 | ACHTRUSTNOW.INFO&lt;br /&gt;    30 | ACHTRUSTONLINE.INFO&lt;br /&gt;    27 | ACHTRUSTSHOP.INFO&lt;br /&gt;    23 | ACHTRUSTS.INFO&lt;br /&gt;    26 | ACHTRUSTSITE.INFO&lt;br /&gt;    26 | ACHTRUSTSTORE.INFO&lt;br /&gt;    35 | ACHTRUSTTODAY.INFO&lt;br /&gt;    22 | ACH-TRUST-WEBSITE.INFO&lt;br /&gt;    34 | ACHTRUSTWEBSITE.INFO&lt;br /&gt;    28 | ACHTSHOP.INFO&lt;br /&gt;    28 | ACHTS.INFO&lt;br /&gt;    38 | ACHTSITE.INFO&lt;br /&gt;    34 | ACHTSTORE.INFO&lt;br /&gt;    33 | ACHTTODAY.INFO&lt;br /&gt;    32 | ACHUBLOG.INFO&lt;br /&gt;    30 | AC-HU.INFO&lt;br /&gt;    27 | ACHUNOW.INFO&lt;br /&gt;    21 | ACHUONLINE.INFO&lt;br /&gt;    32 | ACHUSHOP.INFO&lt;br /&gt;    40 | ACHUSITE.INFO&lt;br /&gt;    32 | ACHUSTORE.INFO&lt;br /&gt;    24 | ACHUTODAY.INFO&lt;br /&gt;    35 | ACHYBLOG.INFO&lt;br /&gt;    28 | ACH-Y-CAMP.INFO&lt;br /&gt;    35 | ACHYCAMP.INFO&lt;br /&gt;    31 | ACH-Y.INFO&lt;br /&gt;    30 | ACHYNOW.INFO&lt;br /&gt;    28 | ACHYONLINE.INFO&lt;br /&gt;    25 | ACHYSHOP.INFO&lt;br /&gt;    31 | ACHYS.INFO&lt;br /&gt;    18 | ACHYSITE.INFO&lt;br /&gt;    27 | ACHYSTORE.INFO&lt;br /&gt;    39 | ACHYTODAY.INFO&lt;br /&gt;    29 | ACHZBLOG.INFO&lt;br /&gt;    30 | AC-HZ.INFO&lt;br /&gt;    26 | ACHZNOW.INFO&lt;br /&gt;    35 | ACHZONLINE.INFO&lt;br /&gt;    28 | ACHZSHOP.INFO&lt;br /&gt;    34 | ACHZS.INFO&lt;br /&gt;    33 | ACHZSITE.INFO&lt;br /&gt;    22 | ACHZSTORE.INFO&lt;br /&gt;    32 | ACHZTODAY.INFO&lt;br /&gt;     2 | ACTORTUO.INFO&lt;br /&gt;    27 | BASEBALLTRANSACTIONS.INFO&lt;br /&gt;    40 | BESTACHD.INFO&lt;br /&gt;    22 | BESTACHF.INFO&lt;br /&gt;    36 | BESTACHG.INFO&lt;br /&gt;    39 | BESTACHPI.INFO&lt;br /&gt;    34 | BESTACHP.INFO&lt;br /&gt;    29 | BESTACHS.INFO&lt;br /&gt;    32 | BESTACHT.INFO&lt;br /&gt;    26 | BESTACHTRANSACTION.INFO&lt;br /&gt;    37 | BESTACHTRANSFER.INFO&lt;br /&gt;    30 | BESTACHTRUST.INFO&lt;br /&gt;    29 | BESTACHU.INFO&lt;br /&gt;    31 | BESTACHY.INFO&lt;br /&gt;    28 | BESTACHZ.INFO&lt;br /&gt;     2 | BESTKRUST.INFO&lt;br /&gt;    33 | BESTTRANSFERACH.INFO&lt;br /&gt;     1 | BETAINFO.INFO&lt;br /&gt;     2 | BRENT-TOR.INFO&lt;br /&gt;     2 | CALMWEATHER.INFO&lt;br /&gt;     2 | CLOTHES-PEG-I.INFO&lt;br /&gt;    42 | COLLEGETRANSFERACH.INFO&lt;br /&gt;     3 | dfc4.co.cc&lt;br /&gt;     4 | dfc5.co.cc&lt;br /&gt;    22 | DISTRIBUTEDTRANSACTIONS.INFO&lt;br /&gt;    40 | DOMAINTRANSFERACH.INFO&lt;br /&gt;     2 | EDUCATIONALTOPIC.INFO&lt;br /&gt;    40 | ELECTRONIC-ACH.INFO&lt;br /&gt;    31 | ELECTRONICACH.INFO&lt;br /&gt;    21 | ELECTRONICACHTRUST.INFO&lt;br /&gt;    39 | ELECTRONIC-ACH-Y.INFO&lt;br /&gt;    28 | ELECTRONICACHY.INFO&lt;br /&gt;    27 | ELECTRONICTRANSACTIONS.INFO&lt;br /&gt;     2 | FLOORSURFACE.INFO&lt;br /&gt;    35 | FREEACHD.INFO&lt;br /&gt;    31 | FREEACHF.INFO&lt;br /&gt;    33 | FREEACHG.INFO&lt;br /&gt;    29 | FREEACHPI.INFO&lt;br /&gt;    37 | FREEACHP.INFO&lt;br /&gt;    24 | FREEACHS.INFO&lt;br /&gt;    33 | FREEACHT.INFO&lt;br /&gt;    27 | FREEACHTRANSACTION.INFO&lt;br /&gt;    26 | FREEACHTRANSFER.INFO&lt;br /&gt;    28 | FREEACHTRUST.INFO&lt;br /&gt;    31 | FREEACHU.INFO&lt;br /&gt;    33 | FREEACHY.INFO&lt;br /&gt;    31 | FREEACHZ.INFO&lt;br /&gt;    33 | FREETRANSFERACH.INFO&lt;br /&gt;     2 | FREEULX.INFO&lt;br /&gt;    39 | HEAT-TRANSFER-ACH.INFO&lt;br /&gt;    45 | HEATTRANSFERACH.INFO&lt;br /&gt;     2 | IGLOMINERALS.INFO&lt;br /&gt;     1 | INCORRECT-RESULT.INFO&lt;br /&gt;     2 | INTERACTIVEROUTE.INFO&lt;br /&gt;     1 | JOURNALISSUE.INFO&lt;br /&gt;    25 | LEAGUETRANSACTIONS.INFO&lt;br /&gt;     3 | LOVES-YOU-LX.INFO&lt;br /&gt;     2 | LYNXPOPULATIONS.INFO&lt;br /&gt;     2 | MAMBARANKING.INFO&lt;br /&gt;     2 | MAMBASCHOLARSHIP.INFO&lt;br /&gt;     2 | MB-CARD.INFO&lt;br /&gt;    32 | MEMORYTRANSACTIONS.INFO&lt;br /&gt;     2 | MERCURYLYNX.INFO&lt;br /&gt;    34 | MYACHD.INFO&lt;br /&gt;    36 | MYACHF.INFO&lt;br /&gt;    28 | MYACHG.INFO&lt;br /&gt;    31 | MYACHPI.INFO&lt;br /&gt;    22 | MYACHP.INFO&lt;br /&gt;    32 | MYACHT.INFO&lt;br /&gt;    40 | MYACHTRANSACTION.INFO&lt;br /&gt;    41 | MYACHTRANSFER.INFO&lt;br /&gt;    37 | MYACHTRUST.INFO&lt;br /&gt;    28 | MYACHU.INFO&lt;br /&gt;    34 | MYACHY.INFO&lt;br /&gt;    30 | MYACHZ.INFO&lt;br /&gt;     2 | MYPEGI.INFO&lt;br /&gt;    26 | MYTRANSFERACH.INFO&lt;br /&gt;    30 | NEWACHD.INFO&lt;br /&gt;    37 | NEWACHF.INFO&lt;br /&gt;    26 | NEWACHG.INFO&lt;br /&gt;    44 | NEWACHPI.INFO&lt;br /&gt;    28 | NEWACHP.INFO&lt;br /&gt;    31 | NEWACHS.INFO&lt;br /&gt;    29 | NEWACHT.INFO&lt;br /&gt;    32 | NEWACHTRANSACTION.INFO&lt;br /&gt;    27 | NEWACHTRANSFER.INFO&lt;br /&gt;    23 | NEWACHTRUST.INFO&lt;br /&gt;    26 | NEWACHU.INFO&lt;br /&gt;    19 | NEWACHY.INFO&lt;br /&gt;    30 | NEWACHZ.INFO&lt;br /&gt;    45 | NEWTRANSFERACH.INFO&lt;br /&gt;     1 | NEWULX.INFO&lt;br /&gt;     2 | NOVA-TU-O.INFO&lt;br /&gt;     2 | OTTAWALYNX.INFO&lt;br /&gt;     2 | PEGISHOP.INFO&lt;br /&gt;    34 | PLAYERTRANSACTIONS.INFO&lt;br /&gt;    24 | REPRESENTATIVETRANSACTIONS.INFO&lt;br /&gt;     3 | RESPOND-E-PT.INFO&lt;br /&gt;     2 | REWARDMILES.INFO&lt;br /&gt;     2 | RIMINFO.INFO&lt;br /&gt;     2 | ROUGHTOR.INFO&lt;br /&gt;    38 | SECUREDTRANSACTIONS.INFO&lt;br /&gt;     2 | SLOTESITE.INFO&lt;br /&gt;    23 | SPORTS-TRANSACTIONS.INFO&lt;br /&gt;    21 | SPORTSTRANSACTIONS.INFO&lt;br /&gt;     2 | STAR-TU-O.INFO&lt;br /&gt;     2 | STARTUOTICKET.INFO&lt;br /&gt;     2 | STEELRIM.INFO&lt;br /&gt;    29 | TECHTRANSFERACH.INFO&lt;br /&gt;    27 | THEACHD.INFO&lt;br /&gt;    37 | THEACHF.INFO&lt;br /&gt;    28 | THEACHG.INFO&lt;br /&gt;    20 | THEACHPI.INFO&lt;br /&gt;    31 | THEACHP.INFO&lt;br /&gt;    34 | THEACHS.INFO&lt;br /&gt;    30 | THEACHT.INFO&lt;br /&gt;    26 | THEACHTRANSACTION.INFO&lt;br /&gt;    30 | THEACHTRANSFER.INFO&lt;br /&gt;    22 | THEACHTRUST.INFO&lt;br /&gt;    27 | THEACHU.INFO&lt;br /&gt;    29 | THEACHY.INFO&lt;br /&gt;    33 | THEACHZ.INFO&lt;br /&gt;    34 | THETRANSFERACH.INFO&lt;br /&gt;     2 | TOR-MINERALS.INFO&lt;br /&gt;    26 | TRANSACTIONSSHOP.INFO&lt;br /&gt;    30 | TRANSACTIONSTODAY.INFO&lt;br /&gt;    22 | TRANSFERACHACCOUNTS.INFO&lt;br /&gt;    25 | TRANSFERACHBLOG.INFO&lt;br /&gt;    32 | TRANSFER-ACH.INFO&lt;br /&gt;    36 | TRANSFERACH.INFO&lt;br /&gt;    34 | TRANSFERACHNOW.INFO&lt;br /&gt;    24 | TRANSFERACHONLINE.INFO&lt;br /&gt;    33 | TRANSFERACHPAYMENT.INFO&lt;br /&gt;    34 | TRANSFERACHPAYMENTS.INFO&lt;br /&gt;    33 | TRANSFERACHSHOP.INFO&lt;br /&gt;    27 | TRANSFERACHS.INFO&lt;br /&gt;    39 | TRANSFERACHSITE.INFO&lt;br /&gt;    34 | TRANSFERACHSTORE.INFO&lt;br /&gt;    32 | TRANSFERACHTODAY.INFO&lt;br /&gt;    41 | TRANSFERADMISSION.INFO&lt;br /&gt;    34 | TRANSFERAPPLICANTS.INFO&lt;br /&gt;    35 | TRANSFERGUIDE.INFO&lt;br /&gt;    36 | TRANSFERGUIDES.INFO&lt;br /&gt;     2 | ULXS.INFO&lt;br /&gt;    23 | WEALTHTRANSFERACH.INFO&lt;br /&gt;     2 | WIRELESS-COMMUNICATIONS.INFO&lt;br /&gt;     2 | YMYSTICK.INFO&lt;br /&gt;     2 | YOU-LX.INFO&lt;br /&gt;     2 | YUM-RESTAURANTS.INFO&lt;br /&gt;     2 | YUMTHAI.INFO&lt;br /&gt;(355 rows)&lt;br /&gt;&lt;br /&gt;The last domains we saw spammed were slightly after 7 PM (Central time) on Feb 23rd:&lt;br /&gt;&lt;br /&gt;NEWACHTRANSFER.INFO&lt;br /&gt;FREEACHY.INFO&lt;br /&gt;ACHUSTORE.INFO&lt;br /&gt;NEWTRANSFERACH.INFO&lt;br /&gt;ACHGNOW.INFO&lt;br /&gt;TRANSFERADMISSION.INFO&lt;br /&gt;ACHPBLOG.INFO&lt;br /&gt;MYACHTRUST.INFO&lt;br /&gt;ACHYS.INFO&lt;br /&gt;THEACHPI.INFO&lt;br /&gt;ACHPSTORE.INFO&lt;br /&gt;&lt;br /&gt;all came in between 7 PM and 7:15 PM into the UAB Spam Data Mine.&lt;br /&gt;&lt;br /&gt;If you've read some of our &lt;a href="http://www.cis.uab.edu/forensics/TechReports"&gt;Technical Reports&lt;/A&gt; then you know that UAB has a unique capability to build "Spam Clusters" of messages related on many different factors.  One of our fairly standard checks is to ask "what other spam is coming from the machines that sent us this spam?"&lt;br /&gt;&lt;br /&gt;In this case, the answer was NOTHING.&lt;br /&gt;&lt;br /&gt;It was as if every single machine that sent this spam message had been uniquely compromised for the sole purpose of sending us this email.  Out of 9,610 sending IP addresses, only TWO of them had been seen previously sending spam to the UAB Spam Data Mine.  Two Viagra ad from 196.22.14.4 on February 18th and 19th and a set of seven Viagra ads from 112.135.85.114 on February 8th and 9th.  The other 9,608 sending IP addresses had not sent us any spam, at least in the past month.  That's so unusual that it is actually impossible.  There are so many bot-infected computers that randomly selecting any 9,000 internet-connected computers, there is NO CHANCE that none of them sent me spam.&lt;br /&gt;&lt;br /&gt;It turns out the spam messages had "dubious header records" inserted.&lt;br /&gt;&lt;br /&gt;To explore this deeper, I looked at the headers of 92 email messages I had personally received in this campaign (as opposed to the UAB Spam Data Mine receiving them -- the smaller data set is easier to manipulate for manual or quick scripting review.)&lt;br /&gt;&lt;br /&gt;It turned out that the 92 emails, which at first seemed to come from 92 different IPs, actually came from 14 machines, with the most popular ones being:&lt;br /&gt;&lt;br /&gt;Received: from static.vdc.vn [&lt;a href="http://www.projecthoneypot.org/ip_113.160.224.168"&gt;113.160.224.168&lt;/A&gt;]&lt;br /&gt;Received: from triband-mum-59.184.120.21.mtnl.net.in [&lt;a href="http://www.projecthoneypot.org/ip_59.184.120.21"&gt;59.184.120.21&lt;/A&gt;]&lt;br /&gt;Received: from 95.subnet125-164-81.speedy.telkom.net.id [&lt;a href="http://www.projecthoneypot.org/ip_125.164.81.95"&gt;125.164.81.95&lt;/A&gt;]&lt;br /&gt;&lt;br /&gt;All well known spammer IPs (click links to see their "Project Honeypot" reputations).&lt;br /&gt;&lt;br /&gt;While digging deeper, it seems that each of the spam messages was sent while authenticated into gmail.  As a quick spot check, I examined the 92 email messages that I received in my personal accounts.  Out of the 92, 92 of them had an "envelope-from" and a matching "Return-Path:" statement showing a gmail account that had been used to send the spam message:&lt;br /&gt;&lt;br /&gt;(envelope-from abominatingr@gmail.com)&lt;br /&gt;(envelope-from adjournt5@gmail.com)&lt;br /&gt;(envelope-from alwaysw7@gmail.com)&lt;br /&gt;(envelope-from anaestheticsnz556@gmail.com)&lt;br /&gt;(envelope-from analog@gmail.com)&lt;br /&gt;(envelope-from anthropologyi9@gmail.com)&lt;br /&gt;(envelope-from bagateller67@gmail.com)&lt;br /&gt;(envelope-from bawlct1@gmail.com)&lt;br /&gt;(envelope-from beachcombersbdu88@gmail.com)&lt;br /&gt;(envelope-from becomingly001@gmail.com)&lt;br /&gt;(envelope-from belligerency028@gmail.com)&lt;br /&gt;(envelope-from biweekliesqa38@gmail.com)&lt;br /&gt;(envelope-from butteriesldn@gmail.com)&lt;br /&gt;(envelope-from costs@gmail.com)&lt;br /&gt;(envelope-from dependenceq@gmail.com)&lt;br /&gt;(envelope-from dhakatx223@gmail.com)&lt;br /&gt;(envelope-from dismounts05@gmail.com)&lt;br /&gt;(envelope-from distinguishedxe4@gmail.com)&lt;br /&gt;(envelope-from dogwoodui449@gmail.com)&lt;br /&gt;(envelope-from dryadd@gmail.com)&lt;br /&gt;(envelope-from earthworkssmu44@gmail.com)&lt;br /&gt;(envelope-from episodesmf3@gmail.com)&lt;br /&gt;(envelope-from epistolarieskud474@gmail.com)&lt;br /&gt;(envelope-from excusingo6049@gmail.com)&lt;br /&gt;(envelope-from foxtrotteds@gmail.com)&lt;br /&gt;(envelope-from guyinghr6@gmail.com)&lt;br /&gt;(envelope-from hairiestrwv95@gmail.com)&lt;br /&gt;(envelope-from heartbreako0@gmail.com)&lt;br /&gt;(envelope-from helpedcf201@gmail.com)&lt;br /&gt;(envelope-from hotelierpv186@gmail.com)&lt;br /&gt;(envelope-from importunitymn2@gmail.com)&lt;br /&gt;(envelope-from indefinites@gmail.com)&lt;br /&gt;(envelope-from indispensably950@gmail.com)&lt;br /&gt;(envelope-from irishwoman0463@gmail.com)&lt;br /&gt;(envelope-from islander18@gmail.com)&lt;br /&gt;(envelope-from kinkedhby9@gmail.com)&lt;br /&gt;(envelope-from knottiestn@gmail.com)&lt;br /&gt;(envelope-from kropotkinci@gmail.com)&lt;br /&gt;(envelope-from litanies0@gmail.com)&lt;br /&gt;(envelope-from locomotivezq84@gmail.com)&lt;br /&gt;(envelope-from lugsfo@gmail.com)&lt;br /&gt;(envelope-from manfullym7@gmail.com)&lt;br /&gt;(envelope-from matzoshl229@gmail.com)&lt;br /&gt;(envelope-from memorizingxf7@gmail.com)&lt;br /&gt;(envelope-from micronsv1@gmail.com)&lt;br /&gt;(envelope-from mines2@gmail.com)&lt;br /&gt;(envelope-from morerkc896@gmail.com)&lt;br /&gt;(envelope-from murkierp9@gmail.com)&lt;br /&gt;(envelope-from northwesterlyl4@gmail.com)&lt;br /&gt;(envelope-from orbiting4@gmail.com)&lt;br /&gt;(envelope-from organsgqz3@gmail.com)&lt;br /&gt;(envelope-from painfullerujt3@gmail.com)&lt;br /&gt;(envelope-from paltryr63@gmail.com)&lt;br /&gt;(envelope-from phwpa1@gmail.com)&lt;br /&gt;(envelope-from pincushionsl206@gmail.com)&lt;br /&gt;(envelope-from polyglotsxn51@gmail.com)&lt;br /&gt;(envelope-from prohibitorys49@gmail.com)&lt;br /&gt;(envelope-from queenslandpu9@gmail.com)&lt;br /&gt;(envelope-from refracting05@gmail.com)&lt;br /&gt;(envelope-from repaymentsrdr@gmail.com)&lt;br /&gt;(envelope-from rerouteso6@gmail.com)&lt;br /&gt;(envelope-from reselljucd@gmail.com)&lt;br /&gt;(envelope-from rhinestoneo@gmail.com)&lt;br /&gt;(envelope-from ricksjn@gmail.com)&lt;br /&gt;(envelope-from ridgepolem843@gmail.com)&lt;br /&gt;(envelope-from sandieruj@gmail.com)&lt;br /&gt;(envelope-from scabbedl6@gmail.com)&lt;br /&gt;(envelope-from septuagenarians8917@gmail.com)&lt;br /&gt;(envelope-from siberiat1@gmail.com)&lt;br /&gt;(envelope-from slumberad148@gmail.com)&lt;br /&gt;(envelope-from soldieringr7065@gmail.com)&lt;br /&gt;(envelope-from solemnizedo36@gmail.com)&lt;br /&gt;(envelope-from soliloquizese3@gmail.com)&lt;br /&gt;(envelope-from southernersh477@gmail.com)&lt;br /&gt;(envelope-from speedilyby98@gmail.com)&lt;br /&gt;(envelope-from spokes356@gmail.com)&lt;br /&gt;(envelope-from subsidiaryuzxs5@gmail.com)&lt;br /&gt;(envelope-from surmountableoa062@gmail.com)&lt;br /&gt;(envelope-from ternsz27@gmail.com)&lt;br /&gt;(envelope-from thingslq@gmail.com)&lt;br /&gt;(envelope-from totalitiest2@gmail.com)&lt;br /&gt;(envelope-from tuberous37@gmail.com)&lt;br /&gt;(envelope-from ufab3@gmail.com)&lt;br /&gt;(envelope-from undergo@gmail.com)&lt;br /&gt;(envelope-from undertakenf5@gmail.com)&lt;br /&gt;(envelope-from undyingp8344@gmail.com)&lt;br /&gt;(envelope-from unquestionablyww4@gmail.com)&lt;br /&gt;(envelope-from untestedslq4201@gmail.com)&lt;br /&gt;(envelope-from vegemitebe042@gmail.com)&lt;br /&gt;(envelope-from victoriouswyt3@gmail.com)&lt;br /&gt;(envelope-from warmheartedw4@gmail.com)&lt;br /&gt;(envelope-from writhe78@gmail.com)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-6858589914118313681?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/6858589914118313681'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/6858589914118313681'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/02/ach-transaction-rejected-payments-lead.html' title='&quot;ACH Transaction Rejected&quot; payments lead to Zeus'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-2359983773249904600</id><published>2011-01-30T05:13:00.000-08:00</published><updated>2011-01-30T13:52:20.604-08:00</updated><title type='text'>Anonymous DDOSers Arrested and Searched</title><content type='html'>Back in December we shared a couple blog stories about a cyber attack being called Operation Payback.  In the first, &lt;a href="http://garwarner.blogspot.com/2010/12/internet-anarchy-anonymous-crowds-flex.html"&gt;Internet Anarchy: Anonymous Crowds Flex Their Muscles&lt;/A&gt; I discussed with UAB Justice Sciences Chair, John Sloan, some of the sociology behind these actions, especially the ideas of Diffuse Crowds and Convergence Theory.  In the second article, &lt;a href="http://garwarner.blogspot.com/2010/12/minipost-operation-payback-origin.html"&gt;Operation Payback Origins&lt;/A&gt; we dug deeper into the activities of the group behind Operation Payback, a group tied back to the internet forums at 4Chan who call themselves Anonymous.  On Friday, the FBI and other law enforcement agencies around the world began to show their hand.&lt;br /&gt;&lt;br /&gt;In a &lt;a href="http://www.fbi.gov/news/pressrel/press-releases/warrants_012711"&gt;January 27th FBI press release&lt;/A&gt;, the FBI announced that they had conducted forty search warrants around the country to gain evidence to identify some of the key US-based actors behind the DDOS attacks.  They also revealed that IDS signatures had been shared with many of the key Internet Service Providers in the country to help them identify which of their subscribers were using a DDOS attack tool called LOIC.  The press release contained a warning as well:&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;&lt;B&gt;The FBI also is reminding the public that facilitating or conducting a DDoS attack is illegal, punishable by up to 10 years in prison, as well as exposing participants to significant civil liability.&lt;/B&gt;&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;The LOIC, or Low Orbit Ion Cannon, is a tool reminiscent of the tools distributed during the controversy surrounding the Iranian Elections.  We wrote about those in an article called &lt;a href="http://garwarner.blogspot.com/2009/06/armchair-cyberwarriors-twitter-and.html"&gt;Armchair CyberWarriors, Twitter, and the Iran Election&lt;/A&gt;.  In the DDOS tools of ancient days (five to ten years ago -- "ancient" in Internet years), DDOS attacks were performed primarily by hacking many home computers to form a botnet, and then instructing those computers to overwhelm a target by generating massive amounts of traffic towards that target.  These attacks are called a "Distributed Denial of Service" attack, or DDOS.  What changed with Iran was that many individuals were being invited to join the attack by intentionally installing DDOS software on their machines.&lt;br /&gt;&lt;br /&gt;So, who are the forty FBI search warrants served against?  We won't know for a while.  In the United States, a search warrant is an investigative tool, used upon demonstration of "probable cause" to gather further information that will be used to create an indictment.  While law enforcement agencies typically do not identify who search warrants have been served upon, it is quite often the case, especially in protests such as this, that those served may choose to share that information to begin rallying public support for their upcoming case.  If the search warrant and other information gathered provides sufficient evidence to conclusively identify a criminal and document the crimes they have performed, the law enforcement agency will ask the prosecutor's office for an indictment.  (In Federal cases, this would be a prosecutor at a United States Attorney's Office, usually chosen because a significant victim or a significant number of victims are located in their jurisdiction.)  Even once the indictment has been issued, it is not unusual for the indictment to be "sealed" until the accused are arrested and have had a chance to appoint an attorney and to be "arraigned" when their charges are formally presented to them in a court setting.  In some other countries, such as England, the law enforcement agencies are not allowed to name the accused so early in the case.&lt;br /&gt;&lt;br /&gt;Speaking of England, they executed their own action against the Anonymous DDOSers of Operation Payback this week.  The UK's &lt;a href="http://cms.met.police.uk/news/arrests_and_charges/five_arrested_under_computer_misuse_act"&gt;Metropolitan Police released a statement&lt;/A&gt; about the arrests that shared the following details:&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;Detectives from the Metropolitan Police Service's Police Central e-Crime Unit (PCeU) have arrested five people in connection with offences under the Computer Misuse Act 1990.   The five males aged, 15, 16, 19, 20 and 26, are being held after a series of coordinated arrests at residential addresses in the West Midlands, Northants, Herts, Surrey and London at 07:00hrs today (27 January).&lt;br /&gt;&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;Anonymous responded in an &lt;a href="http://anonops.webs.com/ANONYMOUS-PRESS-RELEASE_27-01-2011.pdf"&gt;Open Letter to the UK Police&lt;/A&gt; saying&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;Not only does it reveal the fact that you do not seem to understand the present-day political and technological reality, we also take this as a serious declaration of war from yourself, the UK government, to us, Anonymous, the people.&lt;/BLOCKQUOTE&gt; &lt;br /&gt;&lt;br /&gt;and continuing:&lt;br /&gt;&lt;BLOCKQUOTE&gt;So our advice to you, the UK government, is to take this statement as a serious warning from the citizens of the world. We will not rest until our fellow anon protesters have been released.&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;These were not the first DDOSers arrested in this case.  The Dutch were the first to make an arrest.  First, one of the AnonOps spokespersons screwed up and left their name embedded in a PDF that they used for a press release.  Alex Tapanaris and his website both disappeared the same day, as reported by &lt;a href="http://www.opentopic.com/FrontPage/news/1059"&gt;Open Topic&lt;/A&gt; which shares a &lt;a href="http://i.imgur.com/XlNHQ.png"&gt;PDF showing the properties and the text&lt;/A&gt; of that press release.  The website &lt;a href=http://torrentfreak.com/anonymous-operation-payback-irc-operator-arrested-101210/"&gt;"TorrentFreak" posted speculations&lt;/A&gt; about the online monicker of the next Dutch hacker, also arrested back on December 10th.   These arrests lead the AnonOps attackers (Anonymous Operations = AnonOps) to then &lt;a href="http://thenewsportalonline.com/wikileaks-supporters-attack-dutch-police-in-operation-payback/116377/"&gt;attack the Dutch Ministry of Justice&lt;/A&gt;. &lt;br /&gt;&lt;br /&gt;&lt;H3&gt;How This Will Go Down&lt;/H3&gt;&lt;br /&gt;Obviously no one can say exactly how these cases will go down, but a brief look at history should help the current miscreants understand what they are likely to face.&lt;br /&gt;&lt;br /&gt;AnonOps conveniently forgets to tell people about others in their little cyber protest army who have been arrested for DDOS attacks in the past.  Dmitry Guzner, age 19, was the first.  New Jersey-based &lt;a href="http://www.huffingtonpost.com/2009/11/18/dmitriy-guzner-teen-sente_n_362713.html"&gt;Dmitry Guzner received a 366 day sentence&lt;/A&gt; for his involvement in DDOS attacks sponsored by 4Chan's Anonymous against the Church of Scientology.  Right on his heels was Brian Thomas Mettenbrink of Grand Island, Nebraska.  &lt;a href="http://www.theregister.co.uk/2010/05/25/second_scientology_ddoser_jailed/"&gt;Brian pleaded guilty&lt;/A&gt; to also being involved in the DDOS, and as part of his guilty plea "only" received a one year sentence.  (&lt;A href="http://news.softpedia.com/news/FBI-Executes-Tens-of-Search-Warrants-in-Connection-with-Anonymous-DDoS-Attacks-181330.shtml?utm_source=twitterfeed&amp;utm_medium=twitter"&gt;Thanks to @lconstantin of Softpedia for reminding us of those prior examples&lt;/A&gt;.)&lt;br /&gt;&lt;br /&gt;To put this in perspective, that's two hackers getting a year in jail each for attacking the Church of Scientology and causing "approximately $5,000 in damages."  How much do you suppose the damage was for taking Mastercard and Visa offline?&lt;br /&gt;&lt;br /&gt;Those who are choosing to involve themselves in this criminal behavior should take a look at the record of those who have gone before them before choosing to pick up their own criminal records.&lt;br /&gt;&lt;br /&gt;Here's some more reading for those interested in becoming criminals, spending a year in prison, and paying between $20,000 and $37,000 of their own money by participating in an AnonOps DDOS:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cis.uab.edu/forensics/blog/Dmitriy.Guzner.Plea.pdf"&gt;Dmitriy Guzner's Guilty Plea&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cis.uab.edu/forensics/blog/Dmitriy.Guzner.Sentence.pdf"&gt;Dmitriy Guzner's Sentencing Documents&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cis.uab.edu/forensics/blog/Mettenbrink.Indictment.pdf"&gt;Brian Mettenbrink's Indictment&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cis.uab.edu/forensics/blog/Mettenbrink.Plea.pdf"&gt;Brian Mettenbrink's Guilty Plea&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cis.uab.edu/forensics/blog/Mettenbrink.Sentencing.DOJ.pdf"&gt;Brian Mettenbrink's Sentencing Memo&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cis.uab.edu/forensics/blog/Mettenbrink.Sentencing.Appendix.pdf"&gt;Brian Mettenbrink's Sentencing documents, Attachments A-E&lt;/A&gt; including Brett having to pay the $20,000 fee that Scientology paid to Prolexic for DDOS protection.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Got Updates?&lt;/H3&gt;&lt;br /&gt;As we learn more about the forty search warrants from public sources, we'll add them here.  &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.atlantaprogressivenews.com/interspire/news/2011/01/29/fbi-raids-georgia-tech-students-dorm-over-wikileaks-chat-room-(update-1).html"&gt;The Atlanta Progressive News&lt;/A&gt; shares that one of the Search warrants was executed at a Georgia Tech Dorm room belonging to Zhiwei "Jack" Chen.  &lt;br /&gt;&lt;br /&gt;&lt;a href="http://robotics.tmcnet.com/news/2011/01/29/5275603.htm"&gt;Drifters Bar in Dixon Illinois&lt;/A&gt; was also searched during this investigation.  The bar's computer was disassembled and the hard drive imaged, but it is believed the computer sought probably belonged to a patron who was taking advantage of the free WiFi to participate in Operation Payback.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.guardian.co.uk/technology/2011/jan/28/anonymous-suspects-police-bail-wikileaks?CMP=twt_gu"&gt;The Guardian&lt;/A&gt; reveals that the UK 20 year old mentioned above is Chris Wood, who uses the AnonOps alias ColdBlood.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-2359983773249904600?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/2359983773249904600'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/2359983773249904600'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/01/anonymous-ddosers-arrested-and-searched.html' title='Anonymous DDOSers Arrested and Searched'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-7947558061060287901</id><published>2011-01-01T10:20:00.000-08:00</published><updated>2011-01-01T10:41:19.017-08:00</updated><title type='text'>2010 CyberCrime &amp; Doing Time: Year In Review</title><content type='html'>As we look back on 2010, I'd like to thank our 132,325 Visitors who read more than 214,000 stories on the blog which is a bit more than a 10% increase over our 2009 readership.  I thought it might be interesting to go through the year month by month and review what stories were most interesting to our readers, based on the number of times each article was read.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;January&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/01/usaa-bank-latest-avalanche-scam.html"&gt;USAA Bank Latest Avalanche Scam&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/01/iranian-cyber-army-returns-target.html"&gt;Iranian Cyber Army returns - target: Baidu.com&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/01/minipost-cnircyberwar.html"&gt;China Iran Cyberwar???&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;February&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/02/minipost-fake-photo-zeus.html"&gt;Fake Photo version of Zeus&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/02/confickerb-microsoft-warning-spam.html"&gt;Conficker.B Microsoft Warning Spam&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;March&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/03/most-dangerous-cities-for-cyber-crime.html"&gt;Most Dangerous Cities for Cyber Crime&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/03/pkk-hackers-arrested-in-turkey.html"&gt;PKK Hackers Arrested in Turkey&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;April&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/04/70-romanian-phishers-fraudsters.html"&gt;70 Romanian Phishers &amp; Fraudsters Arrested&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/04/fake-av-in-news.html"&gt;Fake AV In the News&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;May&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;I actually didn't blog in May between grading finals and getting ready for several firsts at UAB, including our first Computer Foreniscs Camp for high schoolers, and our first National Science Foundation Research Experiences for Undergraduates in Cybercrime Investigations.  &lt;br /&gt;&lt;br /&gt;(Note: We are already taking applications for the &lt;a href="http://www.cis.uab.edu/UABCrimeREU"&gt;UAB Crime REU&lt;/A&gt; which has three tracks, Criminal Justice, Forensic Science, and Computer Forensics.  If you know an undergrad with a passion for Cybercrime investigation who would like to earn $450 per week, plus room and board, have them follow that link for an application!)&lt;br /&gt;&lt;br /&gt;So, instead of giving you a CyberCrime &amp; Doing Time story, let's look at MY favorite Security Blog, &lt;a href = "http://www.krebsonsecurity.com/"&gt;Krebs On Security.com&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;My top story in May was probably the &lt;a href="http://krebsonsecurity.com/2010/05/fraud-bazaar-carders-cc-hacked/"&gt;Fraud Bazaar Carders.cc Hacked&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;June&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/06/anna-chapman-and-mikhail-semenko-vs-fbi_29.html"&gt;Anna Chapman and Mikhail Semenko vs. the FBI&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/06/pro-gaza-hackers-target-israeli.html"&gt;Pro-Gaza Hackers Target Israeli Websites&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/06/irs-malware-notice-of-underreported.html"&gt;IRS Malware: "Notice of Underreported Income" spam&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/06/four-russian-spy-couples-two-solo-acts.html"&gt;Four Russian Spay Couples (&amp; Two Solo Acts)&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/06/russian-spies-tradecraft-and-follow.html"&gt;Russian Spies - Tradecraft and Follow the Money&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/06/178-international-credit-card.html"&gt;178 International Credit Card Fraudsters Arrested&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;July&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/07/pakbugs-hackers-arrested.html"&gt;PakBugs Hackers Arrested&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/07/stealing-10-million-20-cents-at-time.html"&gt;Stealing $10 Million, 20 cents at a time&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/07/future-of-cyber-attack-attribution.html"&gt;The Future of Cyber Attack Attribution&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/07/ice-operation-in-our-sites.html"&gt;ICE Operation In Our Sites&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;August&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/08/phacephish-new-facebook-attack-gives.html"&gt;New Facebook Attack gives a One-Two Punch&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/08/major-fraud-ring-busted-in-largest.html"&gt;Major Fraud Ring Busted in Largest Chinese Cybercrime Operation&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;September&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/09/minipost-new-york-fbi-17-wanted-zeus.html"&gt;17 Zeus Money Mules wanted by New York FBI&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/09/here-you-have-spam-spreads-email-worm.html"&gt;"Here You Have" spam spreads email worm&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/09/here-you-have-hype-electronic-jihad.html"&gt;"Here You Have" Hype &amp; Electronic Jihad&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;October&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/10/fbis-operation-aching-mule.html"&gt;FBI's Operation ACHing Mule&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;November&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/11/lin-mun-poo-hacker-of-federal-reserve.html"&gt;Lin Mun Poo: Hacker of the Federal Reserve Bank and . . . ?&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/11/usaa-phish-avalanche-uses-many.html"&gt;USAA Phish: Avalanche Uses many "Redirectors"&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/11/another-m00p-group-member-arrested.html"&gt;Another M00P Group Member Arrested&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;December&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/12/oleg-nikolaenko-mega-d-botmaster-to.html"&gt;Oleg Nikolaenko, Mega-D Botmaster, to Stand Trial&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/12/minipost-operation-payback-origin.html"&gt;Operation: Payback Origins&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://garwarner.blogspot.com/2010/12/minipost-operation-payback-origin.html"&gt;Internet Anarchy: Anonymous Crowds Flex Their Muscles&lt;/A&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-7947558061060287901?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/7947558061060287901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/7947558061060287901'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2011/01/2010-cybercrime-doing-time-year-in.html' title='2010 CyberCrime &amp; Doing Time: Year In Review'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-8670522559568160210</id><published>2010-12-23T05:23:00.000-08:00</published><updated>2010-12-23T09:07:30.928-08:00</updated><title type='text'>36 Million Americans Buy Drugs Online -- Illegally!</title><content type='html'>On December 14th, the White House Intellectual Property Health and Safety Forum was held by Victoria Espinel, the first U.S. Intellectual Property Enforcement Coordinator (IPEC) appointed by President Obama.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Intellectual Property Rights Advancement under President Obama&lt;/H3&gt;&lt;br /&gt;In June the IPEC released the &lt;a href="http://www.whitehouse.gov/sites/default/files/omb/assets/intellectualproperty/intellectualproperty_strategic_plan.pdf"&gt;Joint Strategic Plan on Intellectual Property Enforcement&lt;/A&gt;, which was released by Victoria's office, with support from the Departments of Agriculture, Commerce, Health &amp; Human Services, Homeland Security, Justice, State, and the Executive Office of the President.  One of the strategic parts of that plan was "Identify Foreign Pirate Websites as Part of the Special 301 Process."&lt;br /&gt;&lt;br /&gt;The United States Trade Representative is required by Section 182 of the Trade Act of 1974 (Title 19 USC 2242) to produce an annual review of the global state of intellectual property rights, which is called the "Special 301 Report."  One portion of that annual review is the "Notorious Markets List."  Listed in the &lt;a href="http://www.ustr.gov/webfm_send/1906"&gt;2010 Special 301 Report&lt;/A&gt; as Notorious Markets are Baidu (China) for music piracy, TaoBao (China) and Alibaba (China) for game piracy, TV Ants (China) for sporting event piracy, AllofMP3.com (Russia) for music piracy, Webhards (Korea) for many types of illegal content, &lt;br /&gt;&lt;br /&gt;In the December 14th forum, the focus was not so much on "general" Intellectual Property or piracy, but Intellectual Property rights violations that have the capacity to impact the health and safety of Americans.  &lt;br /&gt;&lt;br /&gt;This focus area, especially with regards to the Internet portion, has been under development for several months, with President Obama calling for a meeting between ICANN and other stakeholders back in September.  See &lt;a href="http://www.securingpharma.com/40/articles/567.php"&gt;Obama seeks action on online pharmacies domain names&lt;/A&gt; as reported by the Securing Pharma website.  This action expands from a previous report back in May by LegitScript, a company working to verify online pharmacies.  After blasting the industry in general, and eNom in specific, for failing to respond to domain names registered through their company, (See Knujon report: &lt;a href="http://www.knujon.com/knujon_audit0610.pdf"&gt;Audit of the gTLD Internet Structure, Evaluation of COntractual Compliance and Review of Illicit Activity by Registrars&lt;/A&gt;, and the LegitScript/Knujon report: &lt;a href="http://www.legitscript.com/download/Rogues-and-Registrars-Report.pdf"&gt;Rogues and Registrars: Are some Domain Name Registrars safe havens for Internet Drug rings?&lt;/A&gt;), eNom came full circle and entered an agreement September 21, 2010 with LegitScript and the National Association of Boards of Pharmacies to ensure that rogue pharmacies are not able to use eNom to register their domain names.  (The criminals responded to this news by registering hundreds of horrible porn and bestiality websites using the name and contact information of LegitScript founder John Horton, as reported by &lt;a href="http://krebsonsecurity.com/2010/10/pill-gangs-besmirch-legitscript-founder/"&gt;Brian Krebs&lt;/A&gt;.)&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;The Forum&lt;/H3&gt;&lt;br /&gt;In case you missed it, CNN Image Source has a &lt;a href="http://imagesource.cnn.com/imagesource/ViewAsset.action?viewAsset=&amp;cnnId=07131427"&gt;One hour video&lt;/A&gt; of the panel, chaired by Victoria Espinel.  What a panel - Attorney General Eric Holder, DHS secretary Janet Napolitano, and John Morton, Director of Immigration and Customs Enforcement.  &lt;br /&gt;&lt;br /&gt;"We need more data to inform our policies and ensure that we are making smart decisions."&lt;br /&gt;&lt;br /&gt;"The Alliance for Safe Online Pharmacies estimate that there are between 30,000 and 40,000 active online drug sellers operating at any one time."&lt;br /&gt;&lt;br /&gt;(09:43:35)"The Partnership at Drugfree.org announced the results of a suvey of consumers of online drug purchasing behavior.  The survey's results?  1 in 6 adults, approximately 16% of adult population have bought or currently buy medications online without a doctor's prescription."&lt;br /&gt;&lt;br /&gt;The report was sponsored by the &lt;a href=""&gt;Alliance for Safe Online Pharmacies&lt;/A&gt; and sponsored by The Partnership at &lt;a href="http://www.drugfree.org/newsroom/thirty-six-million-americans-have-bought-medications-online-without-a-doctor’s-prescription-2"&gt;Drugfree.org&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;The survey was conducted by CARAVAN Survey.  1,015 adults were contacted by telephone from November 4-7, 2010.  The margin of error is +/- 3%.&lt;br /&gt;&lt;br /&gt;(09:45:30) A group of founding private sector partners announced today that they will form a non-profit to work with each other and the US Government to rid the Internet of illegal online pharmacies. Today they have issued priniciples that will guide those efforts.&lt;br /&gt;&lt;br /&gt;(09:46:00) The list of eleven companies participating in the initiative was invited to stand and be recognized:  American Express, eNom, Go Daddy, Google, Mastercard, Microsoft, Neustar, Network Solutions, PayPal, Visa, and Yahoo!&lt;br /&gt;&lt;br /&gt;In case any of them are reading this, UAB Computer Forensics Research Laboratory is ready, willing, and able to help!&lt;br /&gt;&lt;br /&gt;The next speaker was Attorney General Eric Holder, who has posted a transcript of his remarks &lt;a href="http://www.justice.gov/iso/opa/ag/speeches/2010/ag-speech-101214.html"&gt;on the Department of Justice website&lt;/A&gt;.  He pledged his support to the Strategic Plan, and shared some recent successes, including a counterfeit cancer drugs case in August, a Texas case involving he seizure of 6,000 counterfeit pills that actually contained ground-up sheetrock as an ingredient, and a groundbreaking $100 million case in Richmond Virginia.  (That last would be the case against Chong Lam, and Siu Yung Chan, who were &lt;a href="http://www.justice.gov/criminal/cybercrime/lamGuilty.pdf"&gt;found guilty on June 11&lt;/A&gt;.  They were arrested back in &lt;a href="http://www.cbc.ca/news/story/2008/01/18/counterfeit-bags.html"&gt;January 2008&lt;/A&gt; for smuggling more than 300,000 counterfeit handbags from China.  Eric Yuen was actually found not guilty.  &lt;br /&gt;&lt;br /&gt;Holder was praised during his introduction for re-establishing the DOJ Intellectual Property Task Force, &lt;a href="http://www.justice.gov/opa/pr/2010/February/10-ag-137.html"&gt;which he announced in February 2010&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;Secretary Napolitano spoke next (09:59:40), stressing that both CBP and ICE are seizing more counterfeit goods than ever (seizures increased 97% over 2009), and pledging support for IPEC's Strategic Plan.  The National Intellectual Property Rights Coordination Center (which I was able to visit December 7th, and which I blogged about recently regarding their Cyber Monday &lt;a href="http://garwarner.blogspot.com/2010/11/minipost-ipr-center-celebrates-cyber.html"&gt;Operation in Our Sites&lt;/A&gt; enforcements.)  ICE initiated more than 1,000 IPR cases in 2010, and criminal charges increased 79% over 2009.  DHS also participated in Operation Pangea and Operation Mercury this year, coordinated through the World Customs Organization.  Her full remarks are transcribed &lt;a href="http://www6.lexisnexis.com/publisher/EndUser?Action=UserDisplayFullDocument&amp;orgId=574&amp;topicId=25188&amp;docId=l:1323353109&amp;start=9"&gt;by LexisNexis&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;John Morton, whose full title is "Assistant Secretary of Homeland Security for Immigration and Customs Enforcement", also has his remarks transcribed &lt;a href="http://www6.lexisnexis.com/publisher/EndUser?Action=UserDisplayFullDocument&amp;orgId=574&amp;topicId=25188&amp;docId=l:1323353108&amp;start=5"&gt;thanks to LexisNexis&lt;/A&gt;.  He stressed that we needed to speak in plain English and get our message out, and the message is that "counterfeiting spells trouble for America."  It robs Americans of jobs, innovation, and creativity.  It is organized crime, and creates a risk of harm to consumers.  He mentioned counterfeit toothpaste, heart medicine, and air bags, and discussed counterfeit engine parts and ball bearings, not just in cars, but in aircraft with GE Engines.  Fake kevlar in Iraq, fake baby formula, fake CISCO routers, and counterfeit Christmas lights were also on his list.  One case he went deeper on was the Kevin Xu case in Houston that AG Holder also mentioned.  &lt;br /&gt;&lt;br /&gt;Xu imported more than $9 million in counterfeit medicines, including Plavix (heart medicine), Casodex (cancer medicine) and Zyprexa (schizophrenia and bipolar medicine).  He was &lt;a href="http://www.justice.gov/usao/txs/releases/August 2007/070824-Xu.htm"&gt;arrested in 2007&lt;/A&gt; and &lt;a href="http://www.justice.gov/criminal/cybercrime/XuSent.pdf"&gt;sentenced in January 2009&lt;/A&gt; to 78 months and $1.28 million in restitution.  Xu was arrested when he flew to Chicago to meet with undercover agents.  Forensic Chemists working for the FDA determined that his drugs had less of the active ingredient than claimed on the label and had countless impurities of unknown origin.  Some of the drugs had no active ingredient at all.  He had managed to get his counterfeits into the real supply chain in the United Kingdom, prompting &lt;a href="http://www.supplychainer.com/50226711/first_zyprexa_now_fake_plavix_found_in_uk_pharmaceutical_supply_chain.php"&gt;massive recalls of the drugs in June 2007&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;First Panel: Dangers of Counterfeit Pharmaceuticals&lt;/H3&gt;&lt;br /&gt;The First Panel was moderated by Tony West, Assistant Attorney General, Civil Division, including enforcement of the Food, Drug, and Cosmetic Act.&lt;br /&gt;&lt;br /&gt;Panelists included:&lt;br /&gt;John Clark, VP of Global Security at Pfizer (former assistant deputy at ICE)&lt;br /&gt;Tom Kubic, President of the Pharmaceutical Security Institute&lt;br /&gt;Carmen Catizone, President of the Natioanl Association of Boards of Pharmacies&lt;br /&gt;and John Taylor, Counselor to Commissioner of the FDA&lt;br /&gt;&lt;br /&gt;After introductions, John Clark of Pfizer did a presentation about counterfeit drugs.&lt;br /&gt;&lt;br /&gt;One counterfeit's ingredients were shown: roach powder, powdered brick, road paint, and floor wax.  Clark showed slides of the difference between a real drug manufacturer and a fake one.  He played a telephone interview where a drug maker was counseling his undercover agent on what he would need to set up his own manufacturing facilities.&lt;br /&gt;&lt;br /&gt;John Taylor shared information on how FDA provides consumer alerts, which are also a means to gather further information for investigators.  &lt;br /&gt;&lt;br /&gt;(continues in part 2 &lt;a href="http://imagesource.cnn.com/imagesource/ViewAsset.action?viewAsset=&amp;cnnId=07131429"&gt;CNN Image Source&lt;/A&gt; )&lt;br /&gt;&lt;br /&gt;Tom Kubic of PSI has been investigating and measuring counterfeits since 2002.  There has been a 700% increase in drug counterfeiting from 2002 to 2009.  They have identified at least 800 unique medicines that were counterfeited worldwide just in 2009.  (In 2002, there were around 250.)  The ones they have reviewed "are neither safe nor effective."&lt;br /&gt;&lt;br /&gt;Carmen Catizone made several points.  Quoted (with a slight paraphrase):&lt;br /&gt;&lt;br /&gt;When you obtain a medication that has been approved by the FDA, [prescribed] by a licensed practitioner, [dispensed] by a licensed pharmacy, that product is safe.&lt;br /&gt;When you go out of the system, you are dealing with criminals who have found it is easier to sell drugs online than to sell crack or heroin on the street.  Consumers and legislators don't understand that this is a serious consumer health risk.  Carmen says several years ago he was told by legislators they would not take action until they were shown the dead bodies. &lt;br /&gt;&lt;br /&gt;John Taylor follows up on Carmen's comment showing that the fakes don't have to produce death in order to be harmed.  In one case the supplier of an active ingredient  component TO the manufacturer caused an effective epilepsy drug to be suddenly ineffective.  Patients around the country began to have seizures!&lt;br /&gt;&lt;br /&gt;A guest from the audience joined the panel to share his story.  As an AIDS patient, taking nearly 10,000 pills a year, found that his injectable medications were now giving him pain that had not been previously present when injecting.  It turns out that his medicine, obtained from a national pharmacy chain, with a prescription, was a counterfeit.  For six week period, he has no idea what he was injecting into himself.&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Second Panel: Health and Safety Risks of the Counterfeiting of Trademarks&lt;/H3&gt;&lt;br /&gt;The Second Panel was moderated by Lanny Breuer, Assistant Attorney General, Criminal Division.  This panel focused more on computer and electronic components.  A bit off topic for today's blog post.&lt;br /&gt;&lt;br /&gt;Panelists include: &lt;br /&gt;Neal Rubin, VP and Director of Litigation at Cisco&lt;br /&gt;Keith Williams, President of Underwriter Laboratories&lt;br /&gt;Robert Barchiesi, President of the International Anti-Counterfeiting Coalition&lt;br /&gt;Brett Brenner, President of the Electrical Safety Foundation International&lt;br /&gt;&lt;br /&gt;(continues in part 3 &lt;a href="http://imagesource.cnn.com/imagesource/ViewAsset.action?viewAsset=&amp;cnnId=07131431"&gt;CNN Image Source&lt;/A&gt;)&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Conclusion&lt;/H3&gt;&lt;br /&gt;&lt;a href="http://imagesource.cnn.com/imagesource/ViewAsset.action?viewAsset=&amp;cnnId=07131433"&gt;CNN Image Source&lt;/A&gt; &lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Prior activities&lt;/H3&gt;&lt;br /&gt;&lt;br /&gt;Many of the companies named in the new announcement have already been taking strides to reduce the sale and advertising of online drugs.  In October, the National Assocation of Boards of Pharmacies released their report &lt;a href="http://safeonlinerx.typepad.com/files/nabp-internet-drug-outlet-report_oct-2010.pdf"&gt;Internet Drug Outlet Identification Program: Progress Report for Federal Regulators&lt;/A&gt; which shared some of the findings of the International Internet Week of Action (IIWA). During October 5-12, 2010, the Food &amp; Drug Administration, Interpol, and agencies in 45 countries took a concerted week of enforcement actions.  Interpol calls the enforcement actions &lt;a href="http://www.interpol.int/Public/ICPO/PressReleases/PR2010/PR083.asp"&gt;Operation Pangea III&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;During the operation which saw the 45 participating countries send intelligence to a dedicated operations centre at INTERPOL's General Secretariat headquarters in Lyon, Internet monitoring revealed 694 websites engaged in illegal activity, 290 of which have now been shut down. In addition, some 268,000 packages were inspected by regulators and customs, almost 11,000 packages were seized and just over 1 million illicit and counterfeit pills were confiscated - including antibiotics, steroids, anti-cancer, anti-depression and anti-epileptic pills, as well as slimming or food supplement pills. Some 76 individuals are currently under investigation or under arrest for a range of offences, including illegally selling and supplying unlicensed or prescription-only medicines.&lt;/BLOCKQUOTE&gt; &lt;br /&gt;&lt;br /&gt;Operation Pangea III featured a series of YouTube videos themed "Don't Be Your Own Killer".  Here are two examples:&lt;br /&gt;&lt;br /&gt;&lt;object width="640" height="390"&gt;&lt;param name="movie" value="http://www.youtube.com/v/KdEKm82BKkA&amp;hl=fr_FR&amp;feature=player_embedded&amp;version=3"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/KdEKm82BKkA&amp;hl=fr_FR&amp;feature=player_embedded&amp;version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="640" height="385"&gt;&lt;param name="movie" value="http://www.youtube.com/v/6q4AdY16egE?fs=1&amp;amp;hl=en_US"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/6q4AdY16egE?fs=1&amp;amp;hl=en_US" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="640" height="385"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/utpcsYRzsto?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/utpcsYRzsto?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;Other organizations and actions&lt;/H3&gt;&lt;br /&gt;In 2009, US Customs &amp; Border Protection (CBP) and Immigration and Customers Enforcement (ICE) seized over $260 million worth of couterfeit goods arriving at US ports.&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://iacc.org/"&gt;International AntiCounterfeiting Coalition&lt;/A&gt; (IACC) President, Robert Barchiesi, attended the forum as well.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-8670522559568160210?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/8670522559568160210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/8670522559568160210'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2010/12/36-million-americans-buy-drugs-online.html' title='36 Million Americans Buy Drugs Online -- Illegally!'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-8392613548056548889</id><published>2010-12-20T03:50:00.000-08:00</published><updated>2010-12-20T04:41:23.340-08:00</updated><title type='text'>DIICOT: Romanians Bust Up VOIP Ring</title><content type='html'>&lt;IMG SRC="http://www.cis.uab.edu/forensics/blog/diicot.14dec2010.jpg"&gt;&lt;br /&gt;&lt;br /&gt;Any day that starts with a video of DIICOT in action is a good day!  Over the weekend I saw Lucien Constantin share the good news on Softpedia that a &lt;a href="http://news.softpedia.com/news/VoIP-Fraud-Gang-Dismantled-in-Romania-173493.shtml"&gt;Major VOIP Fraud Gang was Dismantled in Romania&lt;/A&gt;.  Lucien was kind enough to point to the DIICOT press release from December 14th.&lt;br /&gt;&lt;br /&gt;A Google translated version of the press release can be found here: &lt;a href="http://bit.ly/VOIPRo"&gt;bit.ly/VOIPRo&lt;/A&gt;.  For those who prefer to read their own Romanian, see here:  &lt;a href="http://www.diicot.ro/index.php?option=com_content&amp;view=article&amp;id=444:comunicat-de-presa-14122010"&gt;DIICOT Press Release&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;DIICOT is the Directorate for Investigating Organized Crime and Terrorism, and they have been gaining a world-wide reputation for scooping up cyber criminals.  Regular readers of this blog will know I am in the DIICOT Fan Club, as we've previously written about on several occasions, including:&lt;br /&gt;&lt;br /&gt;23SEP2010: &lt;a href="http://garwarner.blogspot.com/2010/09/ebay-spear-phisher-liviu-mihail.html"&gt;eBay Spear Phisher Liviu Mihail Concioiu Arrested in Romania&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;12APR2010: &lt;a href="http://garwarner.blogspot.com/2010/04/nicolae-popescu-romanian-hacker-at.html"&gt;Nicolae Popescu, Romanian hacker, at large!&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;06APR2010: &lt;a href="http://garwarner.blogspot.com/2010/04/70-romanian-phishers-fraudsters.html"&gt;70 Romanian Phishers &amp; Fraudsters Arrested&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;16JUL2008: &lt;a href="http://garwarner.blogspot.com/2008/07/22-more-romanians-meet-long-arm-of-law.html"&gt;22 More Romanians meet the Long Arm of the Law&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;H3&gt;VOIP Raid&lt;/H3&gt;&lt;br /&gt;On 14DEC2010, there were 42 houses searched, with 31 in Constanta, 4 in Neamt, 3 in Brasov and others in Olt, Maramures, Cluj, and Dolj counties.&lt;br /&gt;&lt;br /&gt;From Oct 2009 to Feb 2010, Cătălin Zlate is accused of running a team of over 50 individuals to commit computer crimes and to use fraudulent access to data to commit VOIP Fraud.  Team members configured a VOIP client called "ZoIPer" to allow members to place Voice Over IP calls using fraudulently obtained credentials from other VOIP services.  During the period Oct 2009 to Feb 2010, they generated 23,500 calls or 315,000 minutes of long distance charges, stealing from companies in Romania, South Africa, United Kingdom, Italy, and the United States.&lt;br /&gt;&lt;br /&gt;Zlate is no stranger to computer crime.  He was actually &lt;a href="http://www.ziaruldeiasi.ro/regional/roman/convorbiri-telefonice-de-11-milioane-de-euro~ni6tgp"&gt;arrested in 2009&lt;/A&gt;, and sentenced to 1.5 years in jail for phishing.  Unfortunately, the court system in Romania allowed him to be released with a suspended sentence.  While I believe Romania has some of the best investigators and some of the hardest working police officers, they also have one of the most corrupt court systems in Europe.  All the police can do is keep doing their job, and pray for a change in the court system.  &lt;br /&gt;&lt;br /&gt;According to &lt;a href="http://www.evz.ro/detalii/stiri/sunati-va-rog-in-coreea-de-nord-v-am-pacalit-cu-11-milioane-de-euro-915651.html"&gt;EVZ.ro&lt;/A&gt;, Zlate used the handle "Roşcatu" and was involved in a phishing gang with Manuel Sorin Paun, AKA "Puia", Mangue Barry, AKA "Dumbo", and Bogdan Nistor, AKA "Bobo".  The four received "suspended sentences" of 2.5 years, 1.5 years, 3 years, and 3 years respectively for phishing, creating fake ATM cards, and withdrawing money from ATMs using those cards.  DIICOT has been following "Roşcatu"'s exploits since at least 2006.  The news of their previous conviction made the &lt;a href="http://www.ziuaconstanta.ro/print/index.php?id=267026"&gt;Ziu Constanta&lt;/A&gt; back on November 20, 2009.&lt;br /&gt;&lt;br /&gt;Zlate came back with a passion, founding a new business in March of 2010.&lt;br /&gt;&lt;br /&gt;That's when things really got out of hand.  Through a new fraud company called "Shadow Communication Company Ltd", from February through June 12, 2010, 1,541,187 fraudulent calls were made, running up 11,094,167 minutes of talk time!  The defendants were selling these fraudulently obtained minutes at about a 90% discount.  While the actual costs should have been more than 11 MILLION EUROS, they actually sold the minutes for just over 1 MILLION EUROS.  (Hint: If your telephone company is named something league "Shadow Communications" or "League of Evil", perhaps you should consider switching to AT&amp;T.)&lt;br /&gt;&lt;br /&gt;Charges brought against the group include:&lt;br /&gt;&lt;br /&gt; - Article 7, Paragraph 1.3 - membership and support of an organized criminal group&lt;br /&gt; - Article 18 Section 2 letter b of law 39/2003 - Money laundering&lt;br /&gt; - Article 23 Paragraph 1 letter a, b, &amp; c of law 656/2002 - Wireless access to a computer system to obtain data by breaching security measures&lt;br /&gt; - Article 42 Paragraph 2.3 of law 161/2003 - Possession of a computer program in order to commit offenses&lt;br /&gt; - Article 49 of law 161/2003 - Causing a loss of property through the introduction of computer code in order to obtain benefit for oneself or another&lt;br /&gt;&lt;br /&gt;42 people have been brought to Bucharest to be charged of these crimes.&lt;br /&gt;&lt;br /&gt;Here's the DIICOT video of the arrests and seizures:&lt;br /&gt;&lt;br /&gt;&lt;object width="640" height="390"&gt;&lt;param name="movie" value="http://www.youtube.com/v/QBWZBHRQCbo&amp;rel=0&amp;hl=en_US&amp;feature=player_embedded&amp;version=3"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/QBWZBHRQCbo&amp;rel=0&amp;hl=en_US&amp;feature=player_embedded&amp;version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Hopefully, this time the criminals will actually serve time in prison!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35783026-8392613548056548889?l=garwarner.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/8392613548056548889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35783026/posts/default/8392613548056548889'/><link rel='alternate' type='text/html' href='http://garwarner.blogspot.com/2010/12/diicot-romanians-bust-up-voip-ring.html' title='DIICOT: Romanians Bust Up VOIP Ring'/><author><name>UAB's Director of Research in Computer Forensics</name><uri>http://www.blogger.com/profile/10822366940133384061</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-35783026.post-8491148244382997765</id><published>2010-12-15T03:49:00.000-08:00</published><updated>2010-12-16T04:42:22.095-08:00</updated><title type='text'>Minipost: Operation: Payback origin</title><content type='html'>Yesterday in our story about Crowds, Mobs, and Anonymous, &lt;a href="http://garwarner.blogspot.com/2010/12/internet-anarchy-anonymous-crowds-flex.html"&gt;Internet Anarchy: Anonymous Crowds Flex their Muscles&lt;/A&gt;, we mentioned that Operation Payback started back in September.  Here is the letter that was sent to the media on September 19th:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_967CzTzPEuc/TQirBQqKIAI/AAAAAAAAAOg/4HLbsxj7fGY/s1600/Payback.Page1.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 248px; height: 320px;" src="http://2.bp.blogspot.com/_967CzTzPEuc/TQirBQqKIAI/AAAAAAAAAOg/4HLbsxj7fGY/s320/Payback.Page1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5550874578874146818" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_967CzTzPEuc/TQirBjAUyYI/AAAAAAAAAOo/8T4yuxaHjfA/s1600/Payback.Page2.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 249px; height: 320px;" src="http://1.bp.blogspot.com/_967CzTzPEuc/TQirBjAUyYI/AAAAAAAAAOo/8T4yuxaHjfA/s320/Payback.Page2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5550874583798958466" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;P&gt;&lt;br /&gt;&lt;br /&gt;After seeing Salon's story &lt;a href="http://www.salon.com/news/feature/2010/12/09/0/index.html"&gt;A brief history of Operation: Payback&lt;/A&gt;, which lists November 29, 2010 as the starting date, we thought it especially important to point out that this is NOT the start.  The adoption of Wikileaks was an expansion of a three month old campaign in an effort to legitimize and expand the number of attackers Anonymous had at their disposal.  For more on that "crowd action" mindset, the reader is referred back to &lt;a href="http://garwarner.blogspot.com/2010/12/internet-anarchy-anonymous-crowds-flex.html"&gt;yesterday's blog post&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;Some have been asking "how do you know this is 4chan related?"  Again, we refer readers back to early posts by Anonymous.&lt;P&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_967CzTzPEuc/TQnzqKTbUcI/AAAAAAAAAO4/yw13DVkzoww/s1600/Sep19.AIPlex.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 242px;" src="http://3.bp.blogspot.com/_967CzTzPEuc/TQnzqKTbUcI/AAAAAAAAAO4/yw13DVkzoww/s320/Sep19.AIPlex.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5551235921356739010" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;(Click to enlarge)&lt;br /&gt;"I know that many of you, many of you whom I have seen on 4chan over the years, have grown cynical of the usefulness of anons as an army, especially since the mess that was Chanology*."&lt;br /&gt;&lt;br /&gt;One of the places this image was posted back on September 20th was a hacker website run by a South African hacker.  To put the message into context, the post immediately before this one read:&lt;br /&gt;&lt;br /&gt;&lt;BLOCKQUOTE&gt;Anonymous vs Aiplex, MPAA, RIAA&lt;br /&gt;    &lt;FONT COLOR="red"&gt;This is happening right now. Join if you can.&lt;br /&gt;    /server irc.yescard.org&lt;br /&gt;    /join #savetpb&lt;/FONT&gt;&lt;br /&gt;    We're targeting all the sites mentioned in the topic, but Aiplex first.&lt;br /&gt;&lt;br /&g
