Wednesday, January 16, 2008

Storm Loves You!

The Storm Worm (yes, I know its not a worm, but that's what its called!) has mutated once again and is back in the full swing of "SP" mode, or "Storm Propagation" mode.

Beginning around 3 AM on January 15th, we started seeing new spam messages attempting to infect people with the Storm malware by tricking them into viewing a dangerous website.

Not sure if this is a COMPLETE list of subjects and bodies, but I'm seeing quite a few of them. I'm guessing you can mix and match some of the nouns and adjectives in the subjects below. I'm also guessing that the subjects and bodies may be interchangable.

The big news is that the URLs are no longer using Fast Flux domain names, which means that the Storm folks have to go back to using IP addresses as URLs.

Here are some of the Subjects used by the current storm campaign.

A Is For Attitude
A Kiss So Gentle
A Rose for My Love
A Toast My Love
A Token of My Love
Come Dance with Me
Come Relax with Me
Destiny
Eternity of Your Love
Hugging My Pillow
I am Complete
I Love Thee
I Love You Soo Much
In Your Arms
Inside My Heart
Last Night
Love Remains
Magic Power of Love
Miracle of Love
Our Journey
Our Love is Free
Pages from My Heart
Sending You All My Love
Sent with Love
The Mood for Love
When Love Comes Knocking
When You Fall in Love
You... In My Dreams
You're my Dream
You're the One
Your Love has Opened


Bodies:

A Is For Attitude (URL)
A Dream is a Wish (URL)
A Toast My Love (URL)
Come Dance with Me (URL)
Eternity of Your Love (URL)
Hugging My Pillow (URL)
If Loving You (URL)
I Love Thee (URL)
I Love You Soo Much (URL)
Inside My Heart (URL)
Last Night (URL)
Our Journey (URL)
Our Love is Strong (URL)
Our Love Nest (URL)
Sending You All My Love (URL)
Sent with Love (URL)
Miracle of Love (URL)
Path We Share (URL)
The Miracle of Love (URL)
The Mood for Love (URL)
The Moon & Stars (URL)
Words in my Heart (URL)
You're In My Thoughts (URL)
Wrapped in Your Arms (URL)
You're In My Thoughts (URL)

A few IPs I've got spam for:

24.13.25.195
24.29.57.5
24.98.163.49
24.147.84.166
24.158.201.51
24.182.164.166
58.8.154.229
59.93.124.61
61.254.150.135
62.30.214.249
64.130.186.121
64.131.210.85
65.127.69.227
65.189.144.143
66.56.162.236
66.65.246.186
67.170.38.85
68.52.93.226
68.91.149.33
69.153.229.224
69.236.21.121
70.119.36.227
70.237.140.25
70.237.219.11
70.251.159.54
71.224.194.223
71.228.87.148
75.18.129.8
75.46.65.147
75.74.12.93
75.132.167.64
75.176.123.128
75.181.155.252
76.86.247.98
76.87.138.125
76.108.103.196
76.211.9.128
76.223.80.123
76.117.96.98
76.255.55.200
77.244.67.25
79.120.46.50
79.176.169.98
116.126.30.18
125.184.241.30
190.47.48.223
190.50.109.86
190.172.254.93
200.8.248.51
200.126.102.5
201.223.179.88
208.38.67.197
218.238.54.74
218.190.195.185
220.77.192.117
220.79.184.205

--

--------------

Gary Warner
Director of Research in Computer Forensics
The University of Alabama at Birmingham

Friday, January 11, 2008

New IRS Virus page taxes users

A phishing site hosts fraudulent bank pages, and an IRS look-alike virus

A new round of spam, first noticed on January 8th, has been observed by anti-phishing researchers at the University of Alabama at Birmingham. In many ways the spam is typical phishing emails, trying to trick users into visiting a fraudulent website. This family of emails uses the domains listed below to host several different phishing campaigns, each in a different subdirectory. For example:

/_mem_bin/formslogin.asp = Intelligent Finance
/default.aspx = NatWest Bank
/confirm.asp = Royal Bank of Scotland

But in addition to the traditional phishing, or bank fraud websites, which try to steal userids and passwords for online banking accounts, this spam campaign also includes a fake Internal Revenue Service website - and it isn't asking for your password!

/importantpubs/index.htm = Internal Revenue Service

After giving a warning to "Business/Corporate Treasury Managers and Accountants", the fraudulent IRS website claims to have "important recent changes to business and corporate tax laws".




Each of the links which claim to be a new document with important tax information actually is a link to a virus! With file names like:

ALL_TAXPAYERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
ESTATE_AND_TRUST_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
EXCISE_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
EXEMPT_ORG_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
FOREIGN_ISSUES_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
INDIVIDUALS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
IRA_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE

the virus attempts to trick users into opening the file. If successful, the user will think he is getting information to share his taxes with the IRS, but actually the user will begin to share their information with criminals instead!

Some of the domains hosting this virus so far:

New Sites
jan77.net
aut33.com
pid28.com
com61.net
inf32.net
sid24.net
chcpi.com
chk08.net
dll57.com
idp56.us
user94.net
Older sites
ssl--jan08.com
ssl--site.com
ssl-jan08site.com
url-sslsite.com
update-ssl.com
url-ssl.com
confirm--07jan.com
6jan-update.in
securesafesite.net
myupdatesite.net
comssl.net
secure--confirm.net
06jan--confirm.net
7jan--verify.net

REMEMBER! The IRS is not going to send you an email to warn you about new documents or ask you to login. Several major anti-virus products do not yet detect this virus! Be safe! Do not click on links sent to you in email. If you need new tax documents, visit the real website at: http://www.irs.gov/.



As we have seen in so much recent malware, the websites are being rotated to include hosting on many servers. Here are the sites which are serving the malware according to our most recent query, but there may be many many more.


83.9.136.40 - Warsaw, Poland
77.253.113.235 - Warsaw, Poland
24.93.127.106 - Columbus, Ohio
69.201.136.16 - New York, New York
128.118.145.125 - Penn State University
87.209.100.8 - Amsterdam, the Netherlands
144.162.93.16 - Dallas County Community College
80.85.229.201 - Tarnow, Poland

_-_
gary warner
https://info.cis.uab.edu/forensics/

Thursday, January 03, 2008

Ralsky: Going Down

***IMPORTANT UPDATE*** January 11, 2008!
Today Alan Ralsky was taken into custody - arrested after arriving from Germany and taken into custody.
**********************

Congratulations to First Assistant US Attorney Terrence Berg and his colleagues in Detroit for being willing to prosecute one of the top spammers, as revealed in a 41-count indictment unveiled today in Detroit!

According to the January 3, 2008 announcement by the US Department of Justice today, Scott Bradley and Judy Devenow were in court after being arrested today to hear the charges. John Hui was arrested in New York on January 2nd. The other defendants are at large and being sought. (Hint: You might check the Dominican Republic? Oh wait. Wrong spammer. That was Rizler.)

The full list of defendents is given below:

Alan M. Ralsky, 52, of West Bloomfield, Michigan

Scott K. Bradley, 46, of West Bloomfield, Michigan

Judy M. Devenow, 55, of Lansing, Michigan

John S. Bown, 47, of Poway, California

William C. Neil, 45, of Fresno, California

Anki K. Neil, 36, of Fresno, California

James E. Bragg, 39, of Queen Creek, Arizona

James E. Fite, 34, of Whittier, California

Peter Severa, age unknown, of Russia

How Wai John Hui, 49, of Vancouver, Canada and Hong Kong

Francis A. Tribble, of Los Angeles, California

Ralsky, who has his own Wikipedia page became one of the most famous spammers after an interview with the Detroit News in 2002. Pictures of his ill-gotten mansion are available at Archive.org.

The FBI raided Ralsky's home in 2005, and apparently today's indictments are the conclusion of that investigation, which DOJ says is now three years old!

While a total pricetag may never be placed on all of Ralsky's illegal profits, DOJ says he earned $3 Million just in the summer of 2005!

Ralsky has long been on the excellent Spamhaus Registry of Known Spam Offenders and was featured in the book "Spam Kings". Brian McWilliams, the author of Spam Kings, called Ralsky "the most successful spammer" in this Tech Soup Interview in 2004. Partly because he was still in business after the successful 2001 Verizon lawsuit against him. Three years later and he's still spamming!

Joel Kurth did an excellent profile on Ralsky in August of 2002 for the Detroit News, where Ralsky admits to maintaining a 150 million email address mailing list (though he points out there were 87 million email addresses that he does NOT send spam to because they unsubscribed.)

I wonder how many millions more people he's offended since 2002?

Congratulations again, Detroit, CCIPS, and thanks to the FBI, Postal Inspectors, and IRS Agents who assisted in bringing this to indictment.

Now if they can just get the other 8 co-defendants into custody . . .

Wednesday, January 02, 2008

And on January 1st EVERYBODY SPAM!

Its been a while since I've looked at a virus with a date-triggered behavior change, but that seems to be the case with the one I'm currently looking into.

I spent most of the day yesterday playing with a new spamming virus which "triggered" on January 1st to begin spamming "VPXL" male organ enlargement pills, after being dormant on a machine for almost two weeks.

I would very much appreciate any reports (which will be kept anonymous) regarding how wide-spread this virus may be, or whether anyone can identify the original point of infection.

This is currently the most widely spread spam campaign being observed by our Spam Data Mine at UAB. Its the same group that has been previously using the brands "King Replica" for counterfeit watches and "EliteHerbal" for pills.

The machine I was studying became infected on December 17th, after a "drive-by infection" sent it to the website "www.injectpanel.com" where it hit a file called "/us/ret.php", which caused it to download "index[1].exe". (We are working to get this site shutdown already).

Infected machines will be easily identified (now that Jan 1 has passed), by an enormous number of outbound SMTP connections.

Infected machines will probably have a large number of files in their root directory ending in ".tmp". Some of these files may be 42,496 bytes in size, which are copies of the .exe, while others will be 0 bytes in size.

Infected machines ARE rootkitted, with a couple files of true interest:
c:\windows\system32\wsnpoem\audio.dll
c:\windows\system32\wsnpoem\video.dll

(I found these with "RootKit Revealer", a Most Useful Tool!)

Infected machines will contact on each boot "www.injectpanel.com", and may also connect on each boot "www.botsys.net".

AV vendor PREVX had received 11 copies of this virus since December 18th, most commonly called "index[1].exe".

VirusTotal received its first copy on December 30th, and had a 43% detection. It was NOT detected by ClamAV, F-Prot, McAfee, NOD, Sunbelt, or Symantec. As of Jan 1, it showed 53% detection. (17 of 32 AV products could detect the virus.)

The copy I was dealing with had the MD5:

b7f085411871026218cc30b4a6c0363e

Other secondary infections have been seen being "dropped" from injectpanel.com. Including "Nurech" (AKA "Chepvil"), which also showed only a 13 of 32 detection rate on Jan 1.

Nurech places a large number of files in the Windows\System32 directory.
Some example names were:
imapi.exe
mnmsrvc.exe
msdtc.exe
netdde.exe
alg.exe.tmp
cisvc.exe.tmp

These will be copied to a "numbered" temp file, such as:

124671.exe
147359.exe

which can be found in memory and in the C:\Windows\Temp\ directory.

The file size of these files is "8,704".

MD5 for Nurech = 337915d40c893b64ef57fe3866dadb8f

If anyone else is experiencing these viruses, I'd love to learn any more details you might be able to share, but most importantly I'm trying to gage how widespread the infection is.

Windows XP Machines infected with Nurech may demonstrate the characteristic of "falling off" networks, getting stuck in an "acquiring network device" state. (Which may be an overwhelmed TCP stack from the many many copies of "svchost" that are trying to drive TCP connections.)

Thanks for any help!

Gary Warner
Director of Research in Computer Forensics
http://www.cis.uab.edu/forensics/

Wednesday, December 26, 2007

A Stormy Christmas and a Botnet New Year

The newest round of Storm Worm Propagation emails has come out, and its
again, largely undetected malware.

The main URLs we are seeing at this point are:

uhavepostcard.com <== (majority use this one)

happycards2008.com <== (all of these dated today)

There are more than 100 samples using these two URLs so far. The first
was received December 24th at 12:10 PM. The most recent was received
just moments ago.

- -------
Subjects include:

A fresh new year
A fresh new year...
As you embrace another new year
Blasting new year
Happy 2008 To You!
Happy 2008!
Happy New Year To (emailhere)
Happy New Year To You!
Happy New Year!
It's the new Year
Joyous new year
Lots of greetings on new year
Message for new year
New Hope and New Beginnings...
New Year Ecard
New Year Postcard
New Year wishes for you
Opportunities for the new year
Wishes for the new year

---------

A scan of the current malware on VirusTotal just now showed a 37.5%
detection rate. The version scanned was 142,337 bytes and had the MD5
checksum of:

44dc7307c81eb9fe0a0cf9147a9932ef

Notable non-detections include F-Prot, Kaspersky, McAfee, and Sophos

Those detecting named the malware as follows:

AntiVir = TR/Rootkit.Gen
Avast = Win32:Zhelatin-ASX
BitDefender = DeepScan:Generic.Malware.FMH@mmign.55A134E9
ClamAV = Trojan.Zhelatin
DrWeb = Trojan.Spambot.2386
Fortinet = W32/Tibs.G@mm
Microsoft = Backdoor:WinNT/Nuwar.B!sys
NOD32v2 = probably a variant of Win32/Fuclip
Panda = suspicious file
Prevx1 = Stormy:Worm-All Variants
Symantec = Trojan.Peacomm
Webwasher = Trojan.Rootkit.Gen

PREVX.com says this version was first seen on December 26th and has been
reported by one user in Spain. (That's where VirusTotal is, so I guess
that's me and others using VirusTotal.)

A Christmas version of the Storm Worm Propagation email may still be lurking in in-boxes as employees return from their holiday vacations. The Christmas version primarily used the malware domain:

merrychristmasdude.com

and used these subject lines. Visiting those sites now actually downloads the same "happy-2008.exe" malware as the New Year propagation uses, since these are in reality the same infected computers acting as the web hosts.

The Christmas subject lines were:

Christmas Email
Cold Winter Nights
Feel the Holiday Spirit
Find Some Christmas Tail
Ho Ho Ho.s
How.s It Goin
I love this Carol!
Jingle Bells, Jingle Bells
Looking for something hot this Christmas
Merry Christmas From your Secret Santa
Merry Christmas To All
Mrs. Clause
Mrs. Clause Is Out Tonight!
Santa Said, HO HO HO
Seasons Greetings
The Perfect Christmas
The Twelve Girls of Christmas
Time for a little Christmas Cheer.
Warm Up this Christmas
Your Secret Santa

The domain names for all of these are set up in a "round robin". For instance, I use "nslookup" to query "merrychristmasdude.com" ten times in a row and get the following list of IP replies:

66.78.160.196
24.126.208.180
86.125.107.157
70.249.186.39
79.172.83.168
91.142.197.135
62.43.161.233
78.60.109.65
91.122.89.214
75.58.60.145

A much longer list of IP addresses which answer queries for all three of these domain names:

12.207.192.66
12.215.209.21
12.219.197.139
12.227.173.1
24.165.167.150
24.181.224.249
24.181.42.5
24.182.40.236
24.2.46.250
24.210.99.223
24.3.160.88
24.95.77.206
58.226.226.6
58.8.20.129
59.112.81.137
59.113.187.86
59.12.125.252
59.15.71.112
59.3.40.145
59.86.244.147
59.92.78.2
59.93.39.233
59.95.191.39
60.249.4.119
60.50.100.42
60.53.25.73
60.56.115.109
60.9.222.137
61.15.254.115
61.32.177.59
61.72.147.153
61.80.150.87
62.65.232.246
64.85.228.164
65.189.233.73
65.31.39.88
66.142.52.23
66.31.113.211
67.164.126.186
67.173.35.121
67.177.191.148
67.181.90.28
67.186.43.176
67.187.30.81
68.127.51.120
68.167.71.243
68.187.46.125
68.204.186.99
68.248.237.55
68.54.157.173
68.54.234.64
68.63.133.158
68.79.7.249
68.80.244.129
68.81.122.156
68.81.195.121
69.154.137.176
69.183.216.161
69.215.175.83
69.225.12.176
69.226.25.20
69.247.40.180
69.248.212.75
69.254.83.191
70.115.222.172
70.126.163.174
70.243.43.6
70.245.14.188
70.249.186.39
71.200.198.181
71.205.208.104
71.224.88.232
71.227.249.98
71.230.219.209
71.230.66.163
71.237.134.222
71.86.54.0
71.96.13.37
72.40.18.255
72.48.192.221
72.8.101.213
74.128.121.44
74.138.172.43
74.164.251.210
74.75.193.213
75.131.212.194
75.132.160.97
75.21.75.238
75.35.110.9
75.35.252.137
75.37.39.88
75.50.232.119
75.61.64.23
75.68.231.167
75.73.216.43
75.85.190.206
76.107.42.125
76.111.115.55
76.119.119.58
76.15.46.122
76.171.99.77
76.173.57.101
76.212.92.117
76.22.76.57
76.229.114.65
76.243.202.32
76.25.147.99
76.254.139.102
76.65.181.160
76.68.144.93
77.41.47.214
77.48.16.49
77.57.127.78
77.99.143.61
78.107.182.172
78.107.190.69
78.92.91.186
79.112.4.123
79.120.35.238
79.120.56.38
79.126.167.63
79.139.178.64
79.165.162.240
79.182.0.73
80.73.89.69
81.190.78.83
81.210.133.54
82.1.108.104
82.181.41.160
82.233.232.162
82.79.129.214
83.5.77.234
83.54.12.240
84.10.43.106
84.126.102.227
84.31.89.195
85.180.66.14
86.102.1.205
86.125.170.161
86.61.66.60
86.63.107.2
87.207.117.102
87.8.161.149
88.156.9.155
88.164.68.15
89.110.51.47
89.137.201.205
89.161.22.219
89.178.170.110
89.20.119.182
89.215.180.33
89.228.40.58
89.36.102.75
89.38.163.176
90.150.126.235
90.150.215.50
90.157.92.141
91.106.18.142
91.122.147.67
91.122.19.127
91.18.246.67
98.194.162.228
98.196.29.67
99.145.19.221
99.241.144.189
117.199.240.218
121.1.85.140
121.124.15.53
121.146.205.123
121.150.127.150
121.158.220.126
121.162.87.237
121.165.21.31
121.172.10.95
121.173.45.111
121.179.107.71
121.246.163.37
121.246.86.244
121.247.143.131
121.247.165.149
121.247.66.110
121.96.253.35
122.164.35.171
122.202.44.89
122.32.53.35
122.36.84.38
122.50.173.172
122.99.16.4
123.201.0.167
123.202.81.199
123.203.20.137
123.215.177.241
123.236.114.63
124.120.35.98
124.120.36.238
124.125.116.171
124.199.33.113
124.244.198.114
124.82.112.191
125.137.205.157
125.208.107.18
125.233.65.153
125.235.36.97
125.24.82.14
168.243.219.228
190.17.101.223
190.21.9.139
195.189.153.21
196.217.102.238
200.84.241.161
200.94.163.191
201.172.192.141
201.222.110.245
201.231.140.173
201.241.57.55
201.255.181.193
201.27.179.128
203.223.220.24
203.255.10.96
206.45.91.55
209.102.185.215
210.105.165.204
210.109.244.10
211.109.96.223
211.195.3.79
211.201.18.155
211.204.48.194
211.54.167.69
213.169.180.110
217.123.175.129
218.156.143.96
218.174.73.42
220.118.185.247
220.121.81.72
220.19.166.13
220.225.184.83
220.76.90.93
220.78.225.208
221.147.22.23
222.114.18.22
222.238.245.88
222.98.228.236

Good luck, and thanks for any help terminating the three domain names in question:


Merry Christmas and Happy New Year, CyberCrime Fighters . . .

_-_
gary warner
http://www.cis.uab.edu/forensics/

Thursday, December 13, 2007

"Google Referrer Only" malware sites

This summary is not available. Please click here to view the post.

Saturday, December 08, 2007

Off Topic: Browser and OS Trends

WARNING!! I'm going a bit off topic today.

This post started off to be about JavaScript enabled browsing by end-users. Security professionals have long recommended that JavaScript be disabled by default, and enabled only for those sites which require JavaScript and which are trusted by the user as a "Trusted Site".

In Internet Explorer this is done in a fashion that confuses most end-users, by creating a "Trusted Zone" and setting different security properties in the Trusted Zone than in the Global Zone. (Directions for using Trusted Zones are here)

In FireFox, the best way to accomplish this is by running the Plug-In "No Script", which disables scripting by default and allows the user to click to enable scripts on Trusted Sites that seem broken if they scripting is disabled. (The NoScript homepage is here)

Bottom Line: Unless a site requires Java support and you trust it, you should not be browsing with Java Enabled!

Unfortunately, as I reviewed three groups of web statistics - from visitors to this blog, from visitors to my haiku poetry website, and from visitors to my genealogy website, Almost EVERYONE had Java enabled. Between 97.7% and 98.5%!!

Then I laughed at myself as I realized that I was using Google Analytics to do that measurement, and Google Analytics doesn't record the visit unless Java is enabled. Which now has me puzzling over how ANYONE was recorded who had no Java.

But I still had some interesting, though slighly off-topic results to share with you, Dear Reader . . .




If we watch the media in its various forms, we are being bombarded with a few basic messages:
- The Age of the Macintosh is upon us
- Linux Threatens Windows
- Windows Vista is the Path to Security
- Internet Explorer 7 is the Path to Security

I thought it would be interesting to look at some statistics to see if these messages reflect the reality of the Average Internet User.

After careful reflection, I realized I don't have the ability to measure The Average Internet User, so instead I looked at some Google Analytics for three websites that I have tagged. The three are of course English-language biased, but then so is most of the media I consume, so I think that's ok.



Sample One: People who read this blog.

This blog is about CyberCrime, and usually CyberCrime in the United States. One hopes that the readers are people who care about CyberCrime and perhaps by a bit of a stretch, protecting their computers.

For the sample period I looked at there were 3,400 unique visitors to this blog from 85 countries and all 50 states, but with 78% of the readers coming from the US.












Windows88.65%
Mac7.91%
Linux3.09%
Windows breakdown
XP83%
Vista10%
20005%
Server 20031%
980.8%











Internet Explorer58.01%
FireFox34.69%
Safari4.44%
Opera1.13%
IE breakdown
IE 7.x50.24%
IE 6.x49.42%
IE 5.x0.34%





Sample Two: People who visit my haiku poetry website.

The Haiku Poetry fans, as you might imagine, are a bit different than the readers here. 6,600 unique visitors from 98 countries and all 50 states, with only 54% of the readership coming from within the US.











Windows88.49%
Mac8.86%
Linux2.53%
Windows breakdown
XP85%
Vista6%
984%
20003%











Internet Explorer67.26%
FireFox24.57%
Safari5.64%
Mozilla1.43%
IE breakdown
IE 6.x58%
IE 7.x39%
IE 5.x2%



SLIGHTLY higher Macintosh adoption (not statistically significant), slightly lower Linux adoption (also not statistically significant), but a much greater chance of using "old" Internet Explorer, not being on Vista, and still running Windows 98.




Sample Group 3: People who visit my genealogy websites

This was the smallest group, with 1200 unique visitors representing 37 countries, but with 86% of the traffic coming from within the United States. Genealogists tend to be older and thriftier people than Security professionals. Probably on a "technology" basis, they are more similar to the haiku poets than the security professionals. I included this as a hope towards a "lower tech but US based" sample, to see whether the haiku poets trends were representing their tech level, or their nation of residence.












Windows88.7%
Mac5.67%
Linux5.25%
Windows breakdown
XP86.5%
Vista7.5%
20003.2%
Server 20031.3%
981.2%











Internet Explorer70.14%
FireFox20.35%
Mozilla4.4%
Safari3.48%
IE breakdown
IE 6.x50.15%
IE 7.x49.04%
IE 5.x.08%




Conclusions?

Macintosh users, from my unscientific study, still represent less than 9% of the installed user base.

Linux users are still a small enough number for the average webmaster to safely ignore them.

Vista still represents less than 10% of the installed user base.

FireFox has an impressive market share and must be considered by all webmasters, but trails both IE 6 and IE 7 when considered individually.

Despite the security benefits of IE7, slightly less than half of those who could use it are using it. (From my experience this is because many web-based applications still don't work in IE7.)

Thursday, November 29, 2007

Russian Malware, Welcome to Texas!

Last week a whole group of formerly Russian malware infection websites migrated to a new home in Texas. The move seems to have been made on November 18th, when the virus sites that were formerly on the netblock with 81.95.146.236 moved wholesale to IP addresses in the netblock of 74.52.55.179.

Appropriate folks have all the details, but I wanted to talk today about the infection technique being used by one of the 46 domains, http://entireall.info/.

The way the PHP code on the website works, whatever you are sent on the command line becomes the name of an ".exe" file that is available for download.

So, if you have been sent a spam, or a messagebook-comment-spam to get the new version of Adobe Flash Version 11, then the site will obligingly give you a file called "Adobe_Flash_v11.exe"

As of this timestamp, the root directory of this site is advertising itself as an "Adobe_Flash_v11.exe" updater. VirusTotal.com indicates that only 21% of its 32 anti-virus checks detect this as a virus.

Which brings me to the real topic of today's blog: Constantly Repacked Malware

If you had a link though for "Gar_New_Virus", such as:

(badsite here)/search.php?qq=Gar_New_Virus

Then that would be the name of the file it would offer to download, sticking a ".exe" on the end of it for you.

This site functions in a similar way to other malware sites, typically related to pornographic movie spam, such as "ThisFreeMovies.com", which will send you to download "VideoAccessCodecInstall" because you are lacking the proper Windows Media Player Codec to view a movie. The malware site will obligingly announce that it is the update site for VideoAccessCodecInstall and have a file VideoAccessCodecInstall.exe for you to download.

This latter file is currently undetectable by 21 of the 32 anti-virus products at Virus-Total, including no detection from F-Prot, Kaspersky, McAfee, and Symantec.

Those that do detect it, place it in a family called "Zlob" or "Zlobar".

These sites have been live for several months. Why do the major anti-virus products not detect their malware? It has to do with the fact that they are constantly "re-packing" the offensive code so that traditional signature-based anti-virus products are constantly playing catch up.

On the older of the two malware samples I downloaded just now, the detections identify ZLob:


  • AntiVir = DR/Zlob.Gen
  • AVG = Downloader.Zlob
  • CAT-Quickheal = TrojanDownloader.Zlob.gen
  • ClamAV = Trojan.Dropper-2557
  • F-Secure = W32/Zlob.ARDM
  • Microsoft = TrojanDownloader:Win32/Zlob.AMM
  • Norman = W32/Zlob.ARDM
  • Rising = Trojan.DL.Win32.Zlob.def
  • Sophos = Troj/Zlobar-Fam
  • TheHacker = Trojan/Downloader.gen
  • Webwasher-Gateway = Trojan.Dropper.Zlob.Gen
  • The other 21 products detect nothing.


But look what happens on the nearly identical virus which was packed more recently!


  • AntiVir = TR/Crypt.XPACK.GEn
  • Authentium = could be infected with an unknown virus
  • AVG = Downloader.Zlob.NP
  • eSafe = suspicious Trojan/Worm
  • F-Prot = W32/Heuristic-119!Eldorado
  • NOD32v2 = probably unknown NewHeur_PE virus
  • Webwasher-Gateway = Trojan.Crypt.XPACK.Gen
  • The other 25 products detect nothing.


We need to develop new methods for anti-virus products to deal more appropriately with "repacked" malware. Congratulations to those that are using Heuristic detection, or marking the file as suspicious because of the strange packing, but we need to know that these things are bad and warn the users!

Tuesday, November 27, 2007

The Identity Theft Enforcement and Restitution Act of 2007

Senator Patrick Leahy introduced a much-needed Identity Theft bill in the Senate on October 30th. The bill, S.2168, cited as the "Identity Theft Enforcement and Restitution Act of 2007", passed by "Unanimous Consent" on November 15th, and we now anticipate rapid action from the House.

Key improvements from the bill include:

A change which removes the previous threshold of requiring $5,000 in damages to make identity theft or spyware a Federal Offense;

A change which makes the placing of spyware or keyloggers on more than 10 computers a FELONY offense;

A change to instruct Criminal Restitution to "pay an amount equal to the value of the time reasonably spent by the victim in an attempt to remediate the intended or actual harm incurred by the victim from the offense";

A change to ensure that Identity Theft resulting from theft of mail be considered under the guidelines for "Aggravated Identity Theft";

A change to the sentencing guidelines in Section 1030 Title 18 subsection (a)(5) "Malicious Spyware, Hacking, and Keyloggers", to increase first offense sentences to include a fine and prison terms up to five years. For a second offense under the same section, the prison term would be raised to up to ten years. Language was also added regarding "an attempt to commit an offense punishable under this subparagraph". ("Attempted hacking"?);

A change to Section 1030(a)(7) that would enhance and clarify the definition of Cyber Extortion;

A change allowing a much greater forfeiture of personal property gained as a result of finances obtained via identity theft;

The bill also directs the United States Sentencing Commission to consider 13 points as they seek to increase sentences for these types of offenses.




So what happens next?

Senator Leahy described the bill as being "requested by the Department of Justice", and "supported by a broad coalition of business, high-tech and consumer groups, including Microsoft, Consumers Union, the Cyber Security Industry Alliance, the Business Software Alliance, AARP, and the Chamber of Commerce." (A letter from the Chamber of Commerce was actually read into the Congressional Record in support of the Bill.)

In traditional law-making, bills are introduced in the House and passed to the Senate. This one appears to me to be reversing the process, which means it is now necessary for the House to accept this bill as one of their own. It is now a pressing matter that this bill be voted on by the House and get passed before we all go home for Christmas.

What can you do? Make sure that your Congressman knows about this important bill, and encourage them to get the vote scheduled and to vote in the affirmative for the bill.

Sunday, November 25, 2007

Naked Britney Does It Again!

Today I'm preparing for a lecture tomorrow about Malware and Phishing Risks. When I speak on phishing, I frequently mention that the two reasons that people fall for phishing scams for two primary reasons: Fear, and Greed. They are made afraid that their account is about to be lost, or has already been abused by criminals, or they are enticed the promise of a financial reward for behaving in the way the phisher desires.

When we talk about Malware, we have to add another motivation to the risks: Lust.

This week, we have another round of malware which rides on the desire of email recipients to see Britney Spears naked. The first example is a fairly standard reminder that most anti-virus products do not detect most malware during the first few days of their attack.

In this example, email recipients are told that the attachment to the email contains a "New Britney naked video". What the attached zip file actually contains is a file called "brit.exe", which, of course, turns the infected machine into a bot. Does anti-virus detect it? 53% of AV engines detect it at this time:



The second set of spam uses an assortment of "Britney" subject lines, including:

Britney showed it again!

which connects to a variety of sites with several paths to infection.

Several of the sites linked to from the emails, including: velart.net, blurcolombia.com, agrisanterre.com, which had been modified to include an "iframe" which pulled additional code from "meoryprof.info".

The second one I looked at linked to the website of the "Associação Nacional de Pesquisa e Pós-Graduação em Psicologia". On that page, there is a crazy bit of encoded Javascript at the top. When it is decoded, one finds that it links to two sites:

(CAUTION: THESE ARE BAD SITES! DO NOT VISIT!)

http://ramoneymayker.info/

http://spl.vip-ddos.org/

Nope. Nothing suspicious about THOSE names. "VIP Distributed Denial of Service dot org?" I wonder what happens when that box infects a PC?

The owner of "vip-ddos.org" also owns "botnet.cc". Gee. He must have been counting on his encryption preventing us from seeing those names. (AGAIN, don't visit. Even going to the homepage loads malware from certain Malaysian computers.... VIP-DDOS is actually also the name of a popular Chinese attack tool.

So what does it take to become infected by a Drive By Downloader? The temporary temptation to click on a link in an email promising a new Britney picture.

Saturday, November 17, 2007

Private Detective Spam

A disturbing new spam email was received thirty-four times this morning in my spam traps. The email has one of those social engineering bodies that I would imagine to be pure gold as far as its success rate convincing people to click on the attachment.

Here's the message:


I work in a private detective agency. My name is not important.
I want to warn you that i'm going to monitor your phone line.
Do you want to know who paid for shadowing you? Wait for my next letter.


P.S. I know, you don't believe me. But i think the record of your
yesterday's telephone conversation will change your point. The tape is
in archive. Archive password is 123qwe


The attachment is a ".rar" file, which is a compressed file format similar to a ".zip" file. The fact that many American computer users don't have software on their machines that knows how to open a RAR file may be the only thing that keeps some users safe!

When the file is extracted, it sits in the filelist with an icon which would make it seem to be an .MP3 File.



Although if you view it in a different manner, the fact that the file is a "Screen Saver" file.



The file name is actually:

"call1105.mp3 (many spaces here) .scr"

Of the thirty-four samples that I received at the beginning of the day:

Nine of them use the subject "attention".

Four use the subject "I'm watching you".

Six use the subject "We monitor your privacy".

Five use the subject "you are watched"

Four use the subject "Your phone is monitored"

Two use the subject "you're being monitored"

Two use "you are being monitored".

Two use "The tape of your conversation".

All have the password of "123qwe".

As of thirty minutes ago, there were twenty-one anti-virus companies that did NOT detect this as a virus in any way. Eleven companies, according to VirusTotal.com, mostly detected it as a generic "Dropper", though Symantec called it "Trojan.Peacomm.D", which is what it calls Storm Worm viruses.

F-Prot, F-Secure, Kaspersky, McAfee, Microsoft, Sophos, and others do not detect the virus at this time.

Thursday, November 15, 2007

250,000 node Bot Herder Busted (Or is he??)

3G Communications Group offers many security services for their clients:



According to the 3G Communications Group website, "More than a million bot-infected computers", and they should know, since one of their Network Security professionals was running 250,000 of them.

3G terminated their 26 year old employee John Schiefer last week as the facts began to emerge. According to a Press Release from the US Attorney's Office in the Central District of California, Schiefer "and several associates" developed malware which they used to build botnets of up to 250,000 computers, which were primarily used for stealing credentials from Paypal and other sites the owners visited.

The case has been called newsworthy because it is the first time that wiretap charges are being leveled at a botmaster.

Schiefer has agreed to plead guilty to:

1. Accessing protected computers to conduct fraud.

2. Disclosing illegally intercepted electronic communications.

3. Wire fraud.

4. Bank fraud.

Schiefer operated online with the handle "AcidStorm". I can't prove that the two are related, but an AcidStorm on one webserver that I visited posts advertisements for well known anti-spyware software, with a convenient link for downloading. The software is real, and the description he gives in the post is real, but why does he suggest you download the software from RapidShare rather than directing you to the real website?

It would be interesting if this was the SAME AcidStorm, because this AcidStorm has uploaded SEVERAL illegally shared (and possibly hacked) programs SINCE pleading guilty on November 9.





Pimp Daddy of Freebies, indeed! *THIS* Acidstorm is at best a software pirate. It will be interesting to see if he is also planting Trojans in his Warez.

Thursday, November 08, 2007

More Good News . . .

No time to give details (lecture in 45 minutes) but . . .

READ THIS: SEVENTEEN INDICTED for phishing, spamming, etc, etc.

Yes, that would be the Vadim Vassilenko who ran "The International Association for the Advancement of Criminal Activity."

Some organizational names are like waving a red flag before a bull.

VADIM VASSILENKO, YELENA BARYSHEVA and JOHN WASHINGTON were indicted today.

A full list of the indicted are on the weblink above.

And Now Some Good News . . .

Todd Moeller and Adam Vitale will join the short list of individuals who know what it feels like to be sentenced under the CAN-SPAM Act. The two were part of an online spam gang that called themselves the "g00dfellas", where Vitale went by the handle "Batch1" or "n1Hustler4Life", while Moeller called himself "Trill".

Before the period of time in question (April 2005 to August 2005) Moeller claimed to be in control of 35,000 spam-sending proxies, which he could use to hide the true origins of his email. He boasted that he could send millions of spam messages per hour. In the operation which ended in their arrest, for a $1,500 payment, and the promise of 50% of eventual sales of an imaginary anti-spyware software product, AOL intercepted 1,277,401 spam messages which had been sent from 73 unique IP addresses


Moeller was sentenced today
after Pleading Guilty on June 20, 2007 to


conspir[ing] with VITALE to send spam e-mails to AOL subscribers, and sent spam e-mails to AOL subscribers using techniques to hide the spam e-mails’ true origin, including the use of computers to relay and retransmit the spam e-mails and altering the spam e-mails’ header information.


Although the DOJ Press Release of the guilty plea indicated that Moeller could have received 11 years sentence, he got off with the relatively light sentence of 27 months in prison. While boasting of his spamming to the potential customer, who turned out to be a Secret Service Confidential Informant, Moeller claimed he was earning $40,000 per month by sending spam that attempted to manipulate the values of certain stocks. In this case, Moeller agreed to spam the CI's product for a 50% take on the sales.

In Adam Vitale's Guilty Plea it says that:


Forensic examination of the spam e-mails indicated that VITALE and MOELLER used two
different techniques to conceal from the recipients the source of the spam e-mails and allow VITALE and MOELLER to continue their illegal activity: (1) VITALE and MOELLER used computers connected to the Internet to relay or re-transmit the spam e-mails to make it look like the spam came from those computers, and not ones
that could be traced to VITALE and MOELLER; and (2) VITALE and MOELLER altered the header information in their spam e-mails to make it appear the spam e-mails came from a sender other than VITALE and MOELLER.


Vitale is scheduled to be sentenced on November 13th.

Thursday, November 01, 2007

Ron Paul spam and Online Support

Do you ever write something that you think is going to be ignored, like most of the things your write, and suddenly it takes on a life of its own?

At The University of Alabama at Birmingham (UAB), I am the Director of Research in Computer Forensics. What does that mean? It means that I work on three things:

Three Things



I train students who will have CyberCrime related jobs in the future, including Computer Forensics techs, CyberCrime Investigators, Special Agents, and Computer Scientists. Some of my current students are interning with the FBI, the US Secret Service, and the Jefferson County Sheriff just to name a few places.

I do research on CyberCrime related issues, including Phishing, Spam, and Malware. Besides writing about Ron Paul Spam, I've also written about many aspects of the Storm Worm, and have had my research presented at many law enforcement and computer security meetings. My students and I meet with people working in law enforcement and struggling with CyberCrime issues and work on better solutions to these problems. Several students have seen their research projects turned in to active law enforcement investigations.

I do public awareness and training for the public and current professionals. With October being Cyber Security Awareness Month, that was a pretty busy time for me, doing presentations on Spam, Phishing, Botnets, and participating in a Threat Assessment panel for the Congressional Internet Caucus".

Phishing



With regards to phishing, I'm a member of the CastleCops PIRT Squad where our all volunteer staff works to notify webmasters, banks, and law enforcement when someone has placed a phishing site on the Internet, and to provide them data to help them shut it down, and determine who did the attack. I'm also an active member of the Digital PhishNet where I serve on the Technology Committee, and the AntiPhishing Working Group where I co-chair the Working With Law Enforcement committee.

Spam



With regards to spam, I've presented twice at the FBI's "Slam Spam" conference, and have met with more than a hundred law enforcement professionals, security researchers, and lawyers regarding spam and related issues, including the folks who run the Federal Trade Commissions anti-spam lab, which is a fine place to report spam messages -- http://www.ftc.gov/spam/. As soon as UAB is prepared to receive your spam submissions, I'll certainly let you know here!

One of the main research projects we are working on in the Computer Forensics area is our Spam Data Mine for Law Enforcement Applications. We've had a paper accepted for presentation at the Association for Computational Machinery's Symposium on Applied Computing Conference in Brazil, and continue to develop our techniques. My co-authors and co-researchers have developed algorithms that "parse" the interesting parts of incoming spam email messages, and then attempt to "cluster" the messages into groups based on similarities between the parsed attributes. We have really big really fast computers to work on this project, and as our inbound spam volume increases, we have a great team of researchers in the department who specialize in "Grid Computing" who are looking forward to helping us shape our algorithms so they can take advantage of hundreds of processors to allow even more messages to be considered in our clustering and calculations.

In future phases of this research we look forward to having new spam campaigns automatically identified and browsable on a website dedicated to this project.

All of that to make clear to the many dozens of Ron Paul Supporters who have taken their valuable time to send me their thoughts, including a few profane ones, that I am not making this crap up.

How many people do I think were behind the Ron Paul spam? One. And not one that is officially recognized in any capacity by the Ron Paul campaign.

Let me make something very clear. I never said anything that was intended to imply Ron Paul does not have a lot of online support. Is it interesting that others have seen online regularities? Yes. But that doesn't mean that there not truly a large number of online supporters. In fact, I'll go a bit beyond that and give the Paul-ites some ammunition they can use.

One online research site measures vast amounts of Internet traffic, and then makes estimates of how many UNIQUE AMERICAN COMPUTERS visit a given website. Let's look at how some of the candidate websites stack up:











Fred08.com287,000
HillaryClinton.com209,000
BarackObama.com192,000
RonPaul2008.com155,000 UNIQUE IPs
JohnEdwards.com115,000
MittRomney.com103,000
JohnMcCain.com73,000
JoinRudy2008.com68,000



Want my source? I'll bet you do. Tell the mad dogs in your midst to stop the obscene phone calls and I'll post it later. haha!

There. Gary Warner of UAB says that Ron Paul's online following is dramatically larger than the offline polls would lead one to believe.

Can we go back to talking about Viagra now?

A Dark and STORMy Night

Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor.

On the evening of October 29th, the Storm worm continued to send spam messages about funny cats or krazy kats, but the websites began to change.



By October 30, many of the spam messages we received had also been modified to match the new theme. Subjects included:

Halloween Fun
To much fun
Watch him dance
You have received an ecard

With bodies such as:

I know you will like this. Heck you might even pass it on. LOL

Just a little Halloween fun.

This thing is to fun. I sent it to everyone. I hope you don.t mind.

Someone has sent you a card to make you laugh. Come see it online!

The volume of Storm recruitment email we are receiving has dramatically reduced this month, though the botnet is still sending quite a bit of Pump and Dump spam. It seems that the Storm Botnet masters still keep track of the holidays. Fourth of July, Labor Day, First Day of NFL Season, and now Halloween.

Monday, October 29, 2007

First 2008 Presidential Spam Campaign?

Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it possible we have the First 2008 Presidential Spam Campaign?

I thought it odd when I logged in to my computer this morning and found an email in which someone declared Ron Paul to be the winner of the Republican Debate yesterday, but then, I have all sorts of odd friends. By the time I had received my fifteenth copy of the email, I knew this was something more than a deluded pseudo-Republican. I thought at first this was a virus, but now it seems to be a plain ole Spam Campaign.

The question, I suppose, is what should be done about it? Will we see fans of other campaigns hiring out spam campaigns devoted to extolling the views and records of their candidates? Will there be an evolving message body on the Ron Paul spam to keep pace with the upcoming events on the campaign trail? Its too early to tell, but we will continue to document the trend from the Spam Lab at UAB.

Here's the body of the email . . .





Hello Scott,

Ron Paul is for the people, unless you want your children to
have human implant RFID chips, a National ID card and create
a North American Union and see an economic collapse far worse
than the great depression. Vote for Ron Paul he speaks the
truth and the media and government is afraid of him. This is
the last honest politican left to bring this country out of
this rut from the War Profiteers and bush Administration has
created. Get motivated America, don't believe the lies of the
media he has also WON the GOP Debate On Sunday! Value Freedom
and Liberty instead of corporate lies and corruption. Bypass
this media blackout they are doing to Ron Paul, tell your family
and friends and get involved in a local group at meetup.com make
your voice heard! He will end the War In Iraq immediately,
He will eliminate the IRS and wasteful government spending, and
eliminate the Federal Reserve and restore power to the people
and the only person not a member on the CFR. Can any other runner
make these claims or give Americans the true freedom we were all
raised to believe? We are all economic slaves to the banks and the
illegal federal Reserve. This is why our currency is worth nothing
because of Hidden Inflation Tax and the IRS taking everything
you make!

** RON PAUL WILL STOP THE IRAQ WAR IMMEDIATELY! **

He has NEVER voted:
* to raise taxes
* for an unbalanced budget
* to raise congressional pay
* for a federal restriction on gun ownership
* to increase the power of the executive branch

He HAS voted:
* against the Iraq war
* against the inappropriately named USA PATRIOT act
* against regulating the internet
* against the Military Commissions Act

He will eliminate the IRS, Wasteful Government Spending &
Stop The Iraq War Immediately!

Most importantly, he voted NO on anything in Congress that
is not allowed by the Constitution. And he Despises any
politican that does not do their job for the people and lives
up to the constitution!

Google.com & Youtube.com Search: "Ron Paul"
Join The Revolution!

***************************************
We Need A Real President That Will Restore And Protect
Americans! Stop The War! Protect Our Borders!
*********VOTE RON PAUL 2008************
ubPOJg






The subject line seems to be selected from a small number of subject lines, and then appended with a random character cluster (perhaps to break spam filters?):

Subject lines:

Vote Ron Paul 2008! ZyhYKbw

Iraq Scam Exposed, Ron Paul TLshVzn

Ron Paul Exposes Federal Reserve bpIHP

Ron Paul Stops Iraq War! gPsLhM

Iraq Scam Exposed, Ron Paul wjtsLBp

Ron Paul Stops Iraq War! LcskHxT

Government Wasteful Spending Eliminated by Ron Paul vpntZRr

Vote Ron Paul 2008! pboLKjr

Who Is Ron Paul? ZTobxay

Ron Paul Exposes Federal Reserve JrZXihF

Ron Paul Stops Iraq War! LyNdrha

Ron Paul Eliminates The IRS! fiqfRZZ

Government Wasteful Spending Eliminated by Ron Paul BtkmlDF

Ron Paul Wins GOP Debate! HMzjoqO

Ron Paul Exposes Federal Reserve SBHBcSO

Government Wasteful Spending Eliminated By Ron Paul mEoHUiR

Government Wasteful Spending Eliminated By Ron Paul HRAyaaI


The spam seems to invent a random first and last name, and combine that with a true email address from the infected machine. Here are sample senders from my inbox:


curtice andrzej - sph@research-int.com - [77.181.200.157] (Germany)

byrann shan - phyllis@faxsav.com - [86.9.35.98] (the UK)

humbert jerrimy - alessand@tvldyn.com - [87.210.63.248] (the Netherlands)

jamey jamal - fataneh@i-qts.com - [124.84.175.218] (Japan)

algernon heung-do - melville@surecom.com - [124.84.175.218] (Japan)

christoforo sharad - fang@ohiohills.com - [124.84.175.218] (Japan)

fabe rosemary - hywel@msn.com - [124.84.175.218] (Japan)

hamil orlando - osulliva@surecom.com - [58.140.151.170] (Korea)

cristobal dai - irma@seagate.com - [58.140.151.170] (Korea)

frants cresswell - aziz@3com.com - [190.86.81.131] (El Salvador)

claudius quinn - avi@shoyher.com - [200.166.91.2] (Brazil)

chaim billie - mukund@atomis.com - [200.166.91.2] (Brazil)

chris field - hal@connecthouston.com - [79.3.4.33] (Italy)

alonso sidharta - cindy@e-business-associates.com - [58.141.39.110](Korea)

linn ming-hor - jikun@four-soft.com - [196.207.13.18] (Nigeria)

jerad anant - gorog@franceloisirs.com - [218.209.109.27] (Korea)

Friday, October 26, 2007

How Many Websites Can a Hacker Hack without Being Prosecuted?

Apparently the answer to that is TENS OF THOUSANDS, or more.

IskorpitX, the tutor of an entire generation of Turkish hackers, will shortly be able to claim that he has broken into 200,000 websites. (He's currently at 191,000 according to one popular hacker watching website).

Brasilian hacker, Fatal Error, runs a distant second, having broken in to "only" 32,000 websites according to the same source.

Wouldn't you say that would make them "targets of interest" for law enforcement activity? Sadly, that is not the case. Perhaps, you think to yourself, they have only attacked "low value" websites. Perhaps they are brand new to the scene? If only that were the case! Fatal Error, who lists many US Government websites, and even my home state of Alabama government websites, among his victims, has been actively attacking websites since 2002.

IskorpitX has been defacing websites since at least 2003, and has the governments of Argentina, Australia, Brazil, China, Columbia, France, India, Italy, Korea, Malaysia, Peru, the Philippines, Thailand, Venezuela and South Africa among his many victims. Of course the US government is on the list as well (such as the National Endowment for the Humanities), as well as Harvard University and Bank of America.

IskorpitX even has his own YouTube videos!

http://www.youtube.com/watch?v=ahqSeJvM2XU

http://www.youtube.com/watch?v=jTah9ckvV3Y

Other Turkish "Cyber Warriors" have even done television news interviews about why they hack websites!

http://www.youtube.com/watch?v=w4QgEsuTZrM


Here's one interesting hacker this week and the victims which are still laying around in Google's Cache:

I found it interesting because this hacker is doing SQL Exploits such as we've seen on several high profile attacks in the past including the National Institutes of Health and the United Nations. In this case, a content management system is being SQL injected to replace "titles" of things with the name of the hacker.

Google for the string "OwneD by RootDamages by FasT", and you'll find some interesting victims among the 26,100 pages being returned.

How about The Department of Veterans Affairs and their Cooperative Studies program?

www.vacsp.gov/news.cfm
www.csp.gov/news.cfm

(Although the Malaysian government also got a visit:

www.mygeoportal.gov.my/faq.cfm

Or the Michigan Bar Association?

www.michbar.org/news.cfm

Systems Integrator "Regan Technologies"?

www.rtcorp.com/news.cfm

The Esalen Center for Theory & Research still has pages with the title "OwneD by RootDamages by FasT", such as:

http://www.esalenctr.org/display/confpage.cfm?confid=10&pageid=105&pgtype=1

As does Applied Robotics:

http://www.arobotics.com/about/company_news/news_details.cfm?ID=17

But they weren't just limited to News articles. I think I'd feel very safe using a shopping cart where every product in the online store had been renamed to "OwneD by RootDamages by FasT", such as those at MetroPole360:

http://www.metropole360.com/productcat.cfm?productCatID=3

But you don't have to be a business to have an insecure webserver. Just ask the National Limousine Association, or the NorWest Dog Training Club:

http://209.85.165.104/search?q=cache:d_YOcnX94A4J:norwestdogtraining.co.nz/Newsletter.cfm

http://209.85.165.104/search?q=cache:aN6AmMtGh0kJ:www.limo.org/scriptContent/t_inside.cfm

One subject "that comes up over and over again on Ducati Online" is "OwneD by RootDamages by FasT" according to this news article:

http://www.ducati.net/faq.cfm?id=4

They're even having a conference on the topic in Brasil at the Psychology Congress. September 7th was their conference on "OwneD by RootDamages by FasT". They expected 6 thousand people to attend.

So how many websites will these hackers be allowed to deface before someone decides to arrest them?

Monday, October 15, 2007

Is Your Fifth Grader Smarter Than a Laughing Cat?

Have you seen the television show "Are You Smarter Than a Fifth Grader?" I've been thinking about a variation of that question as I consider the newest version of The Storm Worm.

This morning on the "Good Morning, Alabama" show as I discussed the Storm Worm, the weatherman laughed and said "Fortunately, I pretty much stay awy from laughing cats". So do most adults with bank accounts. Ask the question another way though. "Is there anyone who uses your computer who is into laughing cats?"

Laughing Cat Storm Worm


Twenty of the Twenty-nine anti-virus products I scanned this particular virus with (using Virus Total), did not report an infection. As of this writing, ClamAV, F-Prot, F-Secure, Microsoft, Panda, and Symantec were among the anti-virus programs who said "No Virus Found" to this current malware. ( Click for Results of this scan.)

Previous versions of the Storm Worm have used things such as Greeting Cards, an NFL Game Tracker, Labor Day greetings, Fourth of July greetings, and even Virus Alerts as means to trick people into visiting the malware site.

UAB's Computer Forensics research area will continue to study and document the storm worm until we can find a way to identify the criminals and bring them to justice.

I'll be giving a Public Lecture on Botnets this Friday (October 19th) at the Hull University Center Auditorium.

Saturday, September 22, 2007

Is the Internet a Prosecution-Free Zone?

Jörg Ziercke, the chief of the Bundeskriminalamt (BKA) in Germany, was quoted in a
press release on the BFK website, following a simultaneous phishing raid in Bad Homburg, Düsseldorf, Köln, Frankfurt and Elmshorn. His words lay down an interesting challenge:

"This case shows once more: Criminal organizations are increasingly using the Internet in order to make enormous profits with an allegedly low risk of discovery." He said that prosecutors are constantly facing new challenges regarding Cyber Crime, but that "the Internet cannot develop into a prosecution-free zone."

That's exactly what's at risk. We have to decide whether the Internet is going to be patrolled and prosecuted just like the streets and alleys of our cities, or whether we are going to allow crime to occur unabated there.

In the BKA case, two women, aged 22 and 23, and six men, aged from 20 to 36 years old, have been imprisoned pending their court appearance. Two others are also charged but were not taken into custody.

Sounds good, and congratulations to the BKA! But what about all the other phishers? So far in September, we've made positive confirmation on more than THREE THOUSAND phishing sites in UAB's Computer Forensics Research lab. We can't continue to allow it to take 18 months before a phishing investigation leads to charges.

The more evidence we gather, and the more relationships we find between phishing campaigns, the greater the chance that we can get some law enforcement action.

Remember, if you hear of someone who has been a victim of Identity Theft, Phishing, or any other Cyber Crime, please make sure they fill out a complaint at the Internet Crime and Complaint Center, http://www.ic3.gov/.

Also, if there has not been a financial loss, phishing sites still need to be reported! When you receive a phishing email, please help by sending it to:

pirt@castlecops.com

or by using the webform at:

http://www.castlecops.com/pirt

Let's make sure the Internet doesn't become a "Prosecution-Free Zone".