Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Saturday, December 30, 2023

Vietnam's Massive CAPTCHA crackers vs. Microsoft DCU

Earlier this month, Microsoft's Digital Crimes Unit was featured in a WIRED article by Lily Hay Newman - Microsoft’s Digital Crime Unit Goes Deep on How It Disrupts Cybercrime. In part, the article discusses MS-DCU's case against the hackers that they call Storm-1152. According to DCU, Storm-1152 used their CAPTCHA-cracking capabilities to assist other criminals in the massive creation of Microsoft email accounts, such as Hotmail and Outlook accounts. How many? How about 750 MILLION email accounts created for illicit purposes! In their announcement about Storm-1152, DCU's Amy Hogan-Burney calls out several of the websites run by the group, including Hotmailbox[.]me, 1stCAPTCHA[.]com, AnyCAPTCHA[.]com, and NoneCAPTCHA[.]com.   (I'm not familiar with NoneCAPTCHA, but it looks like it was just a redirect domain to 1stCAPTCHA.)  Amy shares that the group is based in Vietnam and names three of their operators: Duong Dinh Tu, Linh Van Nguyễn (also known as Nguyễn Van Linh), and Tai Van Nguyen.

hotmailbox[.]me

1stCaptcha[.]com

AnyCaptcha[.]com

Some example code is still on github that illustrates how these massive CAPTCHA solvers were used.  For example "CuongPhan1408" has a 1stCaptcha written in GoLang and shows examples in his code of solving Discord account creations using "HCaptchaTaskProxyless" and using "FunCaptchaTaskProxyless" to defeat Microsoft's Live signups.  FunCaptcha is the tool created by Arkose Labs which is currently used by Microsoft to confirm that emails are only created by humans. 

Github user HecTran12 shares code that links to the now-seized-by-Microsoft website 1stcaptcha[.]com which could previously be installed with "pip install 1stcaptcha." HecTran12's FunCaptcha example solves Outlook[.]com captchas to make new Outlook accounts. 

Github user "Xtekky" shares his AnyCaptcha[.]com-based code called "Outlook Gen" which is Python code that links to the Microsoft-seized website "AnyCaptcha[.]com" to create Outlook accounts in volume.  The code has 45 stars and 15 forks on Github.

Clearly the USERS of Outlook Gen, based on the forks, included many people from many parts of the world.  XTekky has many interesting tools on his Telegram and Discord channels, including "tools" for creating views and likes on TikTok using bots. He demonstrates by sharing a "why so many likes?" video on his TikTok which has been liked 912,400 times.  This relies on his TikTok Slider CAPTCHA Solver, which he claims has 100% accuracy in defeating the TikTok captcha.  XTekky also has a Discord "Question-based" CAPTCHA solver, which uses OpenAI's ChatGPT to solve the questions and provide the answers.  

With three major CAPTCHA-solving tools taken down by Microsoft, what's filling their place?  Based on examining new starring and forking from Github users who liked the old projects, it looks like Russia-based "AntiCaptchaOfficial" is the likely leader.  It claims to solve images with text, Recaptcha v2/v3 Enterprise or non-Enterprise, Funcaptcha Arcoselabs, GeeTest and hCaptcha Enterprise or non-Enterprise, and currently charges rates averaging $0.0005 per solved CAPTCHA. That would be 2,000 account creations per $1. 

Microsoft credits Arkose Labs with their help in investigating the case against Storm-1152, but if the stats page at "anti-Captcha[.]com" can be believed, their site is currently cracking 10,000+ Arkose Labs CAPTCHAs per minute.  Only reCAPTCHA v2 is experiencing more cracks per minute (currently 19,000+). Arkose should be pleased that they are one of the most expensive CAPTCHAs to solve.  Anti-Captcha is currently charging $3 per 1,000.  Their website claims that they are helping disadvantaged workers around the world. 


"With your help, they now have a choice between working in toxic factory conditions or on a computer." 

Their stories don't seem to say "Rather than work in a toxic factory, I help cybercriminals commit fraud and theft by making fake accounts on Outlook, Google, TikTok, Discord and more."





Sunday, November 15, 2020

ENISA: Top 15 Threats: Spam, Phishing, and Malware!

Part One of this post, describing the many components of "The Enisa Cybersecurity Threat Landscape" went over ENISA's Year in Review, the emphasis on Cyber Threat Intelligence, Sector specific threats, Research Topics, and Emerging Trends.  This is "Part Two" where we review the 16 documents that ENISA released to cover their "Top 15 Cyber Threats" report. In particular, we look at the Top 5.

ENISA's Top 15 Threats report starts with this summary document: 


The list of the Top 15 Threats is an annual list from ENISA, with only slight changes in positions for the various threats since last year. Malware remains in the Number 1 spot, and Web-based attacks remains Number 2. Phishing actually increased from 4th to 3rd position. Spam also rose this year, from 6th to 5th position. The threat making the greatest movement was Identity Theft, jumping from 13th to 7th position!
    
  A full report from ENISA is available for each of the topics below. Click to access each one. I'll only comment on a few in this blog post!
    1. Malware
    2. Web-based Attacks
    3. Phishing
    4. Web Application Attacks
    5. Spam 
    6. DDOS 
    7. Identify Theft
    8. Data Breach 
    9. Insider Threat
    10. Botnets
    11. Physical manipulation, damage, theft and loss
    12. Information Leakage 
    13. Ransomware
    14. Cyber espionage
    15. Cryptojacking 

#1 Cyber Threat - Malware


ENISA ranks Malware as the #1 threat again, pointing out several troubling trends.  Detection of malware on Business-owned Windows computers went up 13% from the previous year, and 71% of malware infections had spread from one infected user to another.  46.5% of malware delivered by email used a ".docx" file extension, indicating that our continued unsafe business practice of sharing Word documents by email continues to put our organizations and our employees at risk!  Another change was that 67% of malware was delivered via an encrypted HTTPS connection -- the "increased safety" of having encrypted web pages has also greatly increased our difficulty in understanding when an employee is receiving malware by visiting a webpage.

The number one malware family in this reporting period was Emotet, which targeted US-based businesses 71% of the time and UK targets 24% of the time.  

An increasing number of banking trojans were also seen that targeted the Android operating system.  Top families included Asacub, SVPeng, Agent, Faketoken, and HQWar.

 The so-called File-less Malware was also a significant attack method, often using Windows Management Instrumentation or PowerShell scripts to perform complex attacks more or less "at the command line" rather than by downloading a Windows PE Executable.

For C2-based malware, a growing trend in having Russian-based Command & Control servers was observed, with the likelihood of a Russian-host going up 143% from the previous reporting period.  these malware families included Emotet, JSECoin, XMRig, CryptoLoot, Coinhive, Trickbot, Lokibot, and AgentTesla (according to MalwareBytes, quoted in the report.)

ENISA says that 94% of all malware deliveries were via email during 2019, quoting from the EC3 Internet Organised Crime Threat Assessment.   Many such attacks were enabled by employee behavior and gained extended reach due to vulnerabilities in Windows, several of which allowed Remote Code Execution, making malware attacks "wormable" and able to spread throughout the enterprise, often due to poor patch management.

Proposed actions in this report include the need for better in-bound screening, including the ability to decrypt and inspect SSL/TLS traffic as it comes into the network, including web, email, and mobile applications.  Security policies must also be updated to include what processes and escalations must occur "post-detection" in the case of an infection.  Log monitoring must be improved.  

One suggestion that I strongly agree with -- "Organizations need to disable or reduce access to PowerShell functions" -- so much malware this year, especially ransomware, would be stopped cold in its tracks if PowerShell were not so prevalently deployed and enabled in our organizations!  

Although it is not mentioned by ENISA, my favorite document for understanding PowerShell threats is "The art and science of detecting Cobalt Strike" from our friends at Talos Intelligence!  More than any other attack platform, Cobalt Strike is being abused by malicious actors in order to fully compromise domains, often for the purpose of exfiltrating and encrypting for ransomware.

Please refer to the full report for additional recommendations.

#2 Cyber Threat - Web-Based Attacks


Web-Based Attacks are broken into four main vectors by ENISA.  Drive-by downloads, Watering hole attacks, Form-jacking, and Malicious URLs. 

As noted in part one, due to the age of the reporting window (January 2019 to April 2020) some of the particular attacks noted are more historical and of less keen interest by this time, however a couple trends are worth calling attention to.

"MageCart" attacks continue to be a prominent method for acquiring financial credentials.  Because of the vast popularity of a small handful of online "checkout" systems, many organized crime groups are investing heavily in hackers who have "nation-state" level capabilities in order to create new zero day attacks into these systems.  Shoppers are basically defenseless as their order information is transparently transmitted to criminals while they shop at even the largest and most prominent "trust-worthy" online vendors. 

In addition to browser vulnerabilities that can make watering hole attacks quite successful, attackers are also attacking popular web browser extensions, which often have less rigorous security updates than the base browser products themselves.

Content Management Systems also present an enormous footprint of vulnerability as platforms such as WordPress provide millions of vulnerable websites that can be used at will by hackers to host both phishing sites and malware payload files.

#3 Cyber Threat - Phishing


Phishing has historically been email-based crime that lures a target to an illicit website via a social engineering email.  It is the key to $26 Billion in losses due to Business Email Compromise, as well as to a growing number of scams linked to the COVID-19 Pandemic.  In the FIRST MONTH of the COVID-19 Pandemic, ENISA reports that phishing attacks increased 667%!  As previously mentioned, these dangerous emails are now very likely to contain a trojaned Microsoft Office family document.  

ENISA warns that phishing URLs are now being seen more frequently delivered via SMS, WhatsApp, and Social Media platforms, expanding beyond the original email platform.

While phishing historically targeted financial institutions, ENISA says that webmail became the leading target of phishing in Q1 of 2019, with Microsoft 365 services being particularly targeted.

User education and user reporting remains a critical strategy, especially as ENISA says that 99% of phishing emails require human interaction in order to be effective.

The most effective means to combat phishing continues to be the implementation of 2FA. If a phisher cannot gain access to an account with simple userid and password, many schemes would be immediately blocked.

From a financial perspective, wiring money should ALWAYS require out of band confirmation.  The cost of not getting the confirmation is simply too high, with some Business Email Compromise attacks costing tens of millions of dollars!

#5 Cyber Threat - Spam 


As the ENISA report on Spam menions, after 41 years of dealing with spam, "nothing compared with the spam activity seen this year with the COVID-19 pandemic!"

During the reporting period, Emotet, Necurs, and Gamut were some of the top spamming families.

Some other findings: 
85% of all emails exchanged in April of 2019 were spam, a 15-month high.
13% of data breaches could be traced back to malicious spam.
83% of companies were unprotected against email-based brand impersonation (DMARC)
42% of CISOs reported dealing with at least one spam-based security incident.

To bring this category up to date, we noticed that ENISA was fond of the Quarterly Spam & Phishing reports from Kaspersky.  Please find below links to the 2020 Q1, Q2, and Q3 reports from Kasperky, which will technically be part of NEXT year's ENISA reporting:

Kaspersky found that throughout the third quarter, spam was at least 48.9% of all email sent, a slight decline from Q2, however the portion of spam containing malicious emails was up significantly.  Kaspersky identified 51 Million malicious attachments in that quarter, with 8.4% of them being the keylogger commonly known as Agent Tesla (Kaspersky uses the name "Trojan-PSW.MSIL.Agensla.gen"). Microsoft Office documents exploiting CVE-2017-11882 were the second most common.

They also noted 103 million phishing attacks, with the top targeted sectors being Online Stores (19.2%) and Global Web Portals (14.48%) which would include Office365.  Only 10.8% of the phishing attacks observed by Kaspersky targeted banks!


My favorite spam campaign here was the "FTC Official Personal Data Protection Fund" which claimed that the Federal Trade Commission had found that the recipient was a victim of "personal data leakage" and they were eligible to be compensated for that loss, if they just filled out a simple form on their website (which harvested personal data, including credit card and social security number.) 


Thursday, March 28, 2019

Dissect Cyber wins major DHS S&T Award for their BEC Work

Congratulations to our great friends at Dissect Cyber for receiving the DHS S&T Global Award for their work on BEC scams!

The FBI has been warning companies for several years now of the growing prominence of Business Email Compromise (BEC) scams as being one of the top forms of cyber crime based on the volume of dollars stolen.  A single BEC scam can often lead to six-figure and even seven-figure losses!  According to a June 2018 BEC report from the Internet Crimes Complaint Center, so far the FBI has documented $12,536,948,299 in losses stolen from 78,617 businesses.

Dissect Cyber decided that the best way to attack these scams and help protect those at-risk companies was to create an early warning system called Cyber Notify, based on their analysis of the vulnerable (and detectable) points of a BEC scam that is ABOUT TO HAPPEN!  To understand why their solution is so powerful, let's look at how a BEC fraud group is structured.

BEC Org Charts

Some of the leading experts in Business Email Compromise have documented the significant role in these scams played by West African cyber criminals.  Experts such as John Wilson, Crane Hassold, and Ronnie Tokazowski at Agari are doing some great work Investigating BEC Scams actors to learn more about how they commit their crimes.  The SecureWorks experts are documenting the role of malware in BEC crimes, and produced a great chart explaining the roles of the various actors, reproduced here from their report "Golden Galleon: How A Nigerian Cybercrime Crew Plunders the Shipping Industry."

SecureWorks BEC Org Chart
In that document, American researchers assigned names to each of the roles that make up a BEC scam.  One of those roles in the SecureWorks report is "Cloner" which is described as the person who "Registers domain names for impersonating email addresses."

The West African fraud experts at AA419 (Artists Against 419) provide a similar chart, but label their content based on the names the fraudsters use themselves.  In their diagram, the "Cloner" role is called within the West African fraudster community, a "Faker Maker."  While they do create domain names that closely imitate real organization names to be used in email, they often are also responsible for creating entire fraudulent organizations, complete with corresponding web sites, in order to facilitate their fraud, including fake travel agencies, fake government organizations, fake shipping companies, fake job websites, and fake lotteries.

AA419 BEC Org Chart
The AA419 staff did an excellent blog post explaining the critical role of The Faker Maker in December 2017.

Enter Dissect Cyber and Cyber Notify

I've known and worked with April Lorenzen, the founder of Dissect Cyber and Zetalytics, and her staff and products for many years.  She has been passionate about building tools for law enforcement and investigators to quickly understand the relationships between domain names, their name servers, and the IP addresses which host them.  She's also been generous enough to share her tools with researchers in my lab, including sharing them with our UAB Cyber Detective Camp last summer!  Whether we are doing phishing investigations, malware investigations, or illicit pharmaceutical investigations, Dissect Cyber has been a great partner!

Based on the organizational charts above, what Dissect Cyber realized was that part of the PRECURSOR events to having a new BEC attack often involve the creation of a "look-alike domain" that will imitate the company being targeted.  We've blogged many times about how BEC attacks work, such as our article "Business Email Compromise: Putting a Wisconsin Case Under the Microsope." Often, such as in two of the victim cases described in the Wisconsin case, the criminals are monitoring the emails of key executives, having already planted email-stealing malware on their computers, watching for an opportunity when they are traveling or otherwise unavailable.  During that scheduled outage, an employee will receive an "urgent command" that they must quickly pay an invoice, wire some funds for a merger, or some other large financial transaction.  By having the email come from a domain that is VERY SIMILAR to the true email domain, the employee often does not realize that this is not really The Big Boss, and they will comply with the financial transfer order they receive.

This is where Dissect Cyber comes in.  Because they have full visibility of EVERY NEWLY CREATED DOMAIN ON THE INTERNET, they created the Cyber Notify system to check each new domain to see if it might be a counterfeit look-alike domain. If so, their team of highly trained and vetted professionals (at the moment, all members of the alert team are military veterans), reach out to the imitated organization to help them understand that they may be about to be targeted with a BEC attack.

According to the press release from Dissect Cyber, this work has helped 1,500 companies prevent themselves from losing $407 million dollars which was requested to be wire transferred by the scammers who had created these fake domains!  Priority notifications are given to those companies that are part of the nation's Critical Infrastructure as defined by DHS.  Why?  While the techniques that have been broadly been used to steal money by West African scammers are the majority of the financial losses as reported by the IC3.gov team, the scarier fake domain attacks may be foreign nation state actors who are using the techniques refined by the West Africans to send dangerous emails that could have an impact on anything from our power grids to our water supply to employees of those critical infrastructure companies!

Congratulations, Dissect Cyber!  I hope that Cyber Notify (cybernotify.org) will grow, expand, and continue to innovate in ways to help us all protect our vulnerable small and medium-sized businesses from fraud, while also protecting our Critical Infrastructure businesses from nation state espionage hackers!


Sunday, September 16, 2018

Dangerous Invoices and Dangerous Infrastructure

One of the things I've learned in twenty-nine years investigating malware is that MOST bad guys are lazy and cheap.  One of the main ways that shows up is in the reuse of infrastructure.  Or as one of my criminology friends says it "most criminals are caught by identifying patterns of habit and convenience."  That's why it can sometimes be useful to examine a malware sample, even if it fails to trigger due to age.  It is likely that OTHER samples are using the same infrastructure or deployment system.

My friends at Cofense published their finding last week that Microsoft Office macros are still the number one way that malware is being delivered via email, accounting for 45% of all malware delivery mechanisms they have recently studied.  Anyone with a spam collection can quickly reach that same conclusion.  A couple such campaigns even showed up in my personal email this week.

Here's three emails from consecutive days last week sent to one of my personal email domains:

A Purchase Order from "ADNOC" (Sep 6, 2018)

A Purchase Order from H&H Nails (Sep 5, 2018)

A Purchase Order from SS Braid (Sep 4, 2018)
The most convincing phish, as PhishMe and later Cofense have repeatedly demonstrated by studying what millions of customers actually click on, are those which imitate a common business practice, such as these Purchase Orders. In an attempt to be helpful, many will open a Purchase Order received in email, even if they don't recognize the company name, often as a means of directing the PO to the appropriate department.  Big Mistake!

Working from oldest to newest: 

SS BRAID PO.doc was recognized as being malicious by 33 of 59 AV vendors at VirusTotal - a helpful analysis from VMRay, linked in the comments section tells us that the sample attempts to download "kc.exe" from the site rollboat[.]tk.
MD5
02b6f049f4d8246ee982d8c34a160311
sale contract.doc was recognized as being malicious by 29 of 59 AV vendors at VirusTotal - and in this case, Dr.Web shared their analysis with VirusTotal, also revealing that the action of open the document would launch the same "kc.exe" file from rollboat, as the other file.
MD5
736de7cd6a9c76bd7df49e6b3df6000e
SHA-1
1315994222d45410c8508cf614378e35c4f56c94


As it turns out, in the three consecutive daily email blasts identified above, each sample had two email attachments, and they were all the same attachments only with different names.
The three 386KB files all had the same hashes, and the three 176KB files also all had the same hashes.  So, for at least September 4, 5, and 6, 2018, kc.exe was the target that the malicious actor wanted us to launch on our computer.  The file is no longer available, which could stall the investigation, but let's look at Habit and Convenience.  If the actor is already hosting on rollboat[.]tk, is it not likely he'll keep doing so until someone prevents him?

Each of the subdirectories contained additional malicious files.  By the directory time stamps, its clear that this criminal continued delivering his malware that began on Sep 4, Sep 5, Sep 6, at least through Sep 14th (Friday).  Since everyone needs a weekend, and business-process-imitating malware is most profitable on weekdays, the criminals haven't uploaded any new malware on Saturday September 15th, or Sunday September 16th.  

The leftover cnn.exe file from September 6th is well-detected (32 of 67 at VirusTotal) although Microsoft, Symantec, and TrendMicro all report the executable as "clean."  The more recent ogox.exe file from September 14th has a slightly poorer 1 in 3 detection (20 of 67 at VirusTotal), as is typical for Friday malware only 60 hours later.  (The various AV engines will all tell you that's because blah blah blah.  I'm running their code. I just infected myself with their AV running. Whatever.) 

Invoice.exe = (14 of 67 on VirusTotal)  - (checks smtp.gmail.com and then self-terminates)
MD5
1261b8382cfa2b905f0f52a3aef49ce4
SHA-1
e80c07f700cf817a1eca1f8186f820492f8a2fbc
Order.exe = (34 of 68 on VirusTotal
MD5
57b430ea422d1f33fef19f02fb85c7f0
SHA-1
60a64400207fd9835899189aa0c3cbca027fe8cf

MD5
0fa8876252c632b64afad8fd7fa6344f
SHA-1
ab372d169743758bb81abaa4bc303d5303f6d913

ogo.exe = (44 of 68 on VirusTotal
MD5
f321b38b171a3cbc1eff4a41ac5bbe47
SHA-1
da61f88e2e95a23e58d96cf845c523fd10023cb7

Regardless of what this malware actually does, the two take-aways here?  Malware continues to spread by imitating common business practices, such as processing Invoices and Purchase Orders.  And Criminals continue to rely on Habit and Convenience, which means they are still able to be tracked by looking at their infrastructure choices.

Update

Monday morning, back to work!  Sure enough, we checked the rollboat directory for fresh files this morning:

VirusTotal 19 of 65
MD5
793a3a5e434add85d24df212bf3a72d0
SHA-1
cedcb4b74baf0ba7b39aeea1983bd2f48586e9a4



MD5
d13f100887011e3110b224779c11594b
SHA-1
22971ed9a43f7f8e9b8b55de9d28406bb83cffb1



VirusTotal 20 of 67 
MD5
de1a7961917537084aa383fd398beac5
SHA-1
a52e447bfe24760c31142f9a3b0efc90cd7c2366

I'll also note that this morning on my Windows 10 machine running current Chrome, the file downloads were prevented - marked "This file is dangerous, so Chrome has blocked it."  When I told Chrome to let me download one any way, Windows Defender stopped it.  Sharing information DOES help!







Tuesday, July 10, 2018

Chinese arrest 20 in major Crypto Currency Mining scam

According to Chinese-language publication Legal Daily police in two districts of China have arrested 20 people for their roles in a major crypto currency mining operation that earned the criminals more than 15 million yuan (currently about $2M USD).

The hackers installed mining software developed by Dalian Yuping Network Technology Company ( 大连昇平网络科技有限 ) that was designed to steal three types of coins.  Digibyte Coins (DGB, currently valued at USD$0.03 each),  Siacoin (SC, currently valued at $0.01 each) and DeCred coins (DCR coins, currently valued at $59.59 each).

It is believed that these currencies were chosen for the dual reason that they are easier to mine, due to less competition, and that they are less likely to be the target of sophisticated blockchain analysis tools.

The Game Cheat Hacker

The investigation began when Tencent detected the presence of a hidden Trojan horse with silent mining capabilities built into a cheat for a popular first person shooter video game. The plug-in provided a variety of cheats for the game, including "automatic aiming", "bullet acceleration", "bullet tracking" and "item display."  
Tencent referred the case to the Wei'an Municipal Public Security Bureau, who handled the case extremely well.  As they learned more about the trojans, they identified first the social media groups and forums where the trojan was being spread, and traced the identity of the person uploading the trojaned game cheat to a criminal named Yang Mobao. Mobao participated as a forum moderator on a site called the "Tianxia Internet Bar Forum" and members who received the cheat from him there widely shared it in other forums and social media sites, including many file shares on Baidu.
Mobao was popularizing the cheat program by encouraging others to make suggestions for new functionality.  The users who were using the tool did not suspect that they were actually mining crypto-currency while using the cheat.  More than 30,000 victims were using his cheat software and secretly mining crypto-currency for him.
Yang Mobao had a strong relationship with gamers from his business of selling gaming video cards to Internet cafes.  He installed at least 5,774 cards in at least 2,465 Internet cafes across the country, preloading the firmware on the cards to perform mining.  It turns out that these cards ALSO were trojaned!  As a major customer of Dalian Yuping, Moubao was offered a split of the mining proceeds from the cards he installed, earning him more than 268,000 yuan.
Yang is described as a self-taught computer programmer who had previously worked management Internet cafes.  After experiencing some profit from the scheme above, he modified the malware embedded in some of the video cards and installed his own miner, mining the HSR coin and transferring the proceeds to a wallet he controlled.

The Video Card Maker

After Yang Mobao confessed to his crimes, the cybercrime task force sent 50 agents to Dalian, in Liaoning Province.  The Task Force learned that Dalian Yuping Network Technology had been approached by advertisers, who paid them embed advertising software on their video cards, which were then installed in 3.89 million computers, mostly high-end gaming systems installed in video cafes.  The company's owner, He Mou, and the company's Financial Controller, his wife Chen Mou, had instructed the company's head of R&D, Zhang Ning, to investigate mining software and to experiment with various mining trojans.  In addition to the illegal advertising software embedded in those 3.89 million video cards, their crypto currency mining software was embedded into 1 million additional video cards which were sold and deployed in Internet cafes across the country.
Each time one of those machines successfully mined a coin, the coin was transferred to a wallet owned by He Mou.  Chen Mou could then cash them out at any time in the future.
 16 suspects at the company were interrogated and 12 criminally detained for the crime of illegally controlling computer information systems.  Zhao was sentenced to four years himself.
(I learned of this story from CoinDesk's Wolfie Zhao, and followed up on it from the Legal Daily story he links to as well as a report in Xinhuanet, by Reporter Xy Peng and correspondent Liu Guizeng Wang Yen.) (记者 徐鹏 通讯员 刘贵增 王艳)

Friday, June 15, 2018

Fake Malware Pop-up Example

I don't believe I've ever done a video blog, but I wanted to show you what it looks like when we look at a fake malware pop-up.  While I was prepping a lecture for a class I'm teaching by looking at something on Encyclopedia Britannica, I experienced a fake malware popup.

Here's what I saw:

"Serifed.Stream" malicious pop-up
The best way to explain this is to show it to you.  To do so, I've saved a little video of the what we saw.


In that walk through, you can see that the advertisement that led to the pop-up goes through a series of hops:

westerndigitalmeasure.com (192.241.254.144)  was the first site I hit, which had me do a POST to /j/pcl.php

(By the way, Westerndigitalmeasure.com is hosted at Cloudflare)

That PHP code sent me to "orgeles-hantests.com" (52.72.0.63) which immediately did a meta refresh to another page on orgeles-hantests.com which had a "redirect?target=(very long string here)"

That sent me to the host "redirect.orgeles-hantests.com" (54.89.11.221) which did another meta refresh to the site "server3.divinedessert.info" (67.207.82.78).

And divinedessert forwarded me to "serifed.stream" which is where we saw the fake Microsoft malware warning, which, by the way, captured and passed on my Internet service provider name and my home IP address in the URL.

We asked the URL scanner at VirusTotal check out "serifed.stream" and "serifed.stream/live/" but got the same result both ways.   0 of 68 URL reputation engines believe the site to be malicious.

Don't Worry, Be Happy, says 68 different URL Reputation Services

When we look by IP address, things aren't much better.  Of the hundreds of ".stream" addresses hosted on that same IP address, 185.44.65.141, which, by the way, is hosted in Iran, almost NOBODY found them to be malicious:



That last one shown, with 5 of 68 URL reputation services saying it might be bad, could also be interpreted as 63 out of 68 URL reputation services would have let your users see the bad content.  HOPEFULLY, they might have blocked a redirector somewhere in between, but honestly, I don't know . . . (this is the part where all of them will complain VirusTotal doesn't capture the totality of their user experience.  Yeah, yeah, yeah, cry me a river. I'm running AV and it happened to me!  Did you see the video?)



How to conclude?  I don't know.  Perhaps by just saying "the criminals are still ahead of us in this game, and this is why we can't have nice things."




Monday, May 28, 2018

Affiliate Movie Streaming Scam Service

Dear readers,

I'm sharing some information here wondering if anyone can identify the criminal affiliate program at the root of this scam service.

The scam begins with what seems to be an automated bot-response posted on Facebook.  One of the outstanding questions -- can anyone identify a bot that is making these spammy posts?  These are a few examples from many thousands observed over the past week.

Step One: Unknown malware uses stolen Facebook credentials to post a spammy comment link.







We'll just do one walk through here, but each of these functions in the same way.  The spam post, which often will be added as a comment to a publicly shared post that mentions a movie, links to a Facebook page.  Let's walk through the Ogbani Wanyu post first.

Step Two: The Spam link points to a Facebook page created to share a shortened URL.

Recently popular movies have Facebook pages created that claim to offer the ability to watch full movies and share a shortened URL, usually bit.ly links, but we've also seen Goo.gl links.


Step Three: A shortened URL redirects to a Blogspot page (sometimes other types of pages)


The bit.ly shortened URL on the fake IMDB page has received 4,298 clicks as of this writing.  Important to note that we've seen A COUPLE HUNDRED of these pages so far!  Each shortened URL points to a different redirection page.  So far about 80% of those we've traced go to Blogspot pages.

Step Four: A Blogspot page hosts a movie streaming service affiliate page

These Blogspot pages promise free streaming of many movies that are still out in the theaters.  Currently these include Solo (the new Star Wars movie), Avengers Infinity Wars, Deadpool 2, Rampage, and many other movies that are very recently released in the theaters.




Some of the top affiliates in this program actually send their bit.ly shortened URL to a free ".tk" domain which then uses randomization to send the traffic to one of their dozens of Blogspot blogs.  That is the situation with Gmail user ugutganteng2345@gmail.com who has at least 50 blogs just associated to that gmail account!  Each link takes the visitor to yet another movie streaming redirector site:



Step Five: Try to stream a Movie ... redirects to the streaming service and credits the affiliate

So, let's try to stream "Ant-Man and the Wasp" which, as of this writing, hasn't even been released to theaters yet.  


We are now redirected to the streaming service ... in this case, the site is "box.imdbmov.com" but that is one of dozens as well.  Note the "sub=doelsumbang" ... that part of the URL is revealing the affiliate name that should receive credit for the income generated from this click.

Many of the affiliate blogspot pages point to streaming services that have names similar to the old PutLocker criminal streaming service.



Step Six: Register your "Free Account" 

Oops!  We can't watch the movie yet!  We haven't registered our "Free Account!" 



Stream your favorite movies FOR FREE!  Sign up FOR FREE!   FREE Unlimited Access!


Step  Seven:  Provide your Credit Card for the Free Service!


Step Eight: Get Billed $39.95 per month

So, how much do you suppose this Free service will cost you?

That's right....$39.95 per month ... FOREVER.


But wait!  I thought it was FREE!?!?!? 

Did you read the Terms & Conditions?   Free trials are for 24 hours, after which, they automatically convert to premium accounts, billable at $39.95 per month.

Upon completion of the free trial period, your signup to the Site will renew automatically on a monthly basis billed as stipulated in your signup process, until cancelled regardless of the length of your free trial period. Please note, prices for the service may vary depending on country, device, service offered and promotions. The first day following the expiration of your free trial period will be your anniversary date for billing purposes during your Monthly Package Term. Your Payment Method will be charged the recurring monthly package fees and any applicable sales tax on the day following the expiration of your free trial period unless you have chosen to cancel your package prior to the conclusion of the free trial period. YOU MUST CANCEL YOUR MONTHLY PACKAGE PRIOR TO THE END OF THE FREE TRIAL OFFER TO AVOID CHARGES TO YOUR PAYMENT METHOD. You will not receive any notification from Silveris s.r.o. online at the expiration of your free trial. Please note the expiration date of your free trial for your records.

The Ask: Do you know more about this scam?

If you have additional information about any parts of this scam, we'd love to hear from you.  Examples of things we'd like to know:

1. Where does this program sign up affiliates?

2. What malware is making the Facebook spam comment posts?

3. Who runs the affiliate program?

Other Gaming, Movie, Book, websites offering the same scammy terms of service:


Alpha-fun.net  Alphafuntime.com  AngeBliss.com  Angejoy.com Angel-bliss.net Animaflor.net Anima-fun.net  AnimaMuse.net  Aurora-star.net  Aurorawin.com  Blazeheaven.com Blissfulden.net  Bookrefuge.net  Cheerfun.net Cravebliss.com Cravemuse.com  Crescentfire.net Crescentflame.com  desert-star.net  Dusksky.net  Edenjoy.net Equi-fun.net Fairiefire.com Fairieglow.com  Fairydelight.net  FiestaBliss.net Filmpleasure.com Fireglows.net  Fire-stars.com  
Flame-paradise.com Flamestars.com Flametime.net  FuegoFun.com  FuegoFunlife.com Fuego-star.com  FuegoZone.com  FunFate.net  Funhamper.com  Funhoyden.com Funmuse.net  Funorbit.net  Funrange.net  Funsphere.net  Funvictory.net  Glitterbliss.net  Golden-orbs.com  gothic-night.net  HavenDay.com  Havenwin.com  HugeGames.net  Inksmedia.com JinxedFun.com  Joyorb.com Joysphere.com  Lemonyfun.com  LevityTime.net LuckBliss.com  MarvelBliss.com  Masters-media.net Medievalnight.net  Moonflame.net  Musenow.net Muse-park.net  Musestar.net  OasisPrima.com  OldiesMusicCity.net Orbbliss.com Orbfun.net  Orbjoy.com  Palmtreefun.net  Palmtreemedia.net  Pixiebuzz.com  Pixiefun.net PlayLatex.com Playchain.net Polkafun.net  Sherglee.com  Shinebliss.com  SilvberOrbs.net  Sparkhaven.com  Spring-box.net Star-muse.com  Takencheer.com  Takendelight.com Twilightfun.net Twinkle-fun.net  Vaultfun.net  Yaydigital.net Zen-Muse.net 

A Small  Sampling of Blogs related to this scam:

http://anuapambuh001.blogspot.com/   
http://anyar456.blogspot.com/ 
http://asdfghjkfdgsdfaf.blogspot.com/ 
http://avengerinfiniitywar.blogspot.com/ 
http://avengers---boxoffice.blogspot.com/ 
http://avengers--infinity--war.blogspot.com/ 
http://avengersmarvell.blogspot.com/  
http://avenjerinfinitiwar2018.blogspot.com/ 
http://birudihatiku33.blogspot.com/ 
http://blackoval21.blogspot.com/ 
http://boxoffic---download.blogspot.com/ 
http://boxoffice----movie2018.blogspot.com/ 
http://boxoffice--acrimony--hd.blogspot.com/  
http://cap-halloween2018.blogspot.com/ 
http://ciaxs-movie.blogspot.com/  
http://cilokdicolookk505.blogspot.com/ 
http://cimenkabbook404.blogspot.com/  
http://deaaddpolll.blogspot.com/ 
http://deadpooll2freehd.blogspot.com/  
http://fastlifepainpayne.blogspot.com/  
http://filmimdb112.blogspot.com/ 
http://gghocher.blogspot.com/ 
http://gomovieonline90.blogspot.com/ 
http://goo212.blogspot.com/ 
http://happytoenjoythemovie.blogspot.com/  
http://home--boxoffice.blogspot.com/ 
http://jarwogembung.blogspot.com/  
http://kicebboong19.blogspot.com/ 
http://kolangkalingeduarew.blogspot.com/ 
http://kopisusuhitamkupu2.blogspot.com/ 
http://kurakurabuntung.blogspot.com/ 
http://liernjink.blogspot.com/ 
http://madea---lionsgate--boxoffice.blogspot.com/ 
http://madeamovielionsgate.blogspot.com/  
http://madeamoviie.blogspot.com/ 
http://mercyduffyunik.blogspot.com/
http://minininin21.blogspot.com/
http://moviekadutgood.blogspot.com/
http://moviesonlain212.blogspot.com/
http://moviestriming2018r.blogspot.com/
http://moviestriming222.blogspot.com/
http://nylenehnjk.blogspot.com/
http://oleholehemas.blogspot.com/
http://putlokeress12334.blogspot.com/
http://ratuangin79.blogspot.com/
http://rekuripure.blogspot.com/
http://septiselviana.blogspot.com/
http://tanduransubbur.blogspot.com/
http://tero-retewgold.blogspot.com/
http://terogew-oleb.blogspot.com/
http://the-golden-of-madea.blogspot.com/
http://the-venom-movie-online21.blogspot.com/
http://thebeastmovies2018.blogspot.com/
http://thefirstpurgehd.blogspot.com/
http://top-movie-newsmadea.blogspot.com/
http://trainemovies.blogspot.com/
http://transparanmovie.blogspot.com/
http://tyler--e--perry.blogspot.com/
http://tylerperry55.blogspot.com/
http://venom-movie-hd2018.blogspot.com/
http://welcome-tyler-perry21.blogspot.com/
http://wwwtyllerperry.blogspot.com/
http://zoss01.blogspot.com/
https://beastacrimony.blogspot.com/
https://camat-jos.blogspot.com/
https://inditinditanbae.blogspot.com/
https://luckgd69.blogspot.com/
https://madea-infamily.blogspot.com/
https://mocmov.blogspot.com/
https://reta-x.blogspot.com/
https://wakandawakandablackpanther.blogspot.com/