Monday, May 19, 2008

38 Indicted in Los Angeles and Connecticut Phishing Cases

On April 23rd, Attorney General Michael B. Mukasey gave a speech in Washington DC where he revealed his new stance on International Organized Crime. He said in the speech that in the days of Robert Kennedy it was said mobsters would be "prosecuted for spitting on the sidewalk", and promised that he had 120 prosecutors and 500 FBI agents today who were going to be just as tough. He released a strategy document called Overview of the Law Enforcement Strategy to Combat International Organized Crime. In this document, he stresses that they are going to "Marshal Information and Intelligence" to "Prioritize and Target the Most Significant IOC Threats", and "Attack From All Angles". today's phishing indictments have turned out to be. To make it clear that this includes cybercrime, Threat #5 and the accompanying example from that document are given here:


THREAT 5: International organized criminals use cyberspace to target U.S. victims and infrastructure. International organized criminals use an endless variety of cyberspace schemes to steal hundreds of millions of dollars at a cost to consumers and the U.S. economy. These schemes also jeopardize the security of personal information, the stability of business and government infrastructures, and the security and solvency of financial investment markets.

One example of the intersection between organized crime and cybercrime is found in Romania. There, traditional Romanian organized crime figures, previously arrested for crimes such as extortion, drug trafficking and human smuggling, are collaborating with other criminals to bring segments of the young hacker community under their control. They organize these new recruits into cells based on their cyber-crime specialty and they routinely target U.S. businesses and citizens in a variety of fraud schemes.

One of the most lucrative schemes involves online auction fraud, where U.S. citizens are tricked into buying or selling goods, and never receive the funds or merchandise. One particular online criminal, using the online nickname “Vladuz” engaged in multiple fraud schemes, including hacking into the computers of eBay, the largest online auction retailer. On April 17, 2008, Vlad Duiculescu, a/k/a “Vladuz” was arrested in Romania by Romanian police officials and charged with crimes related to these schemes. It is believed that Vladuz is a participant in a ring of Romanian hackers who work together to develop joint U.S. targets for online frauds, share hacking techniques and launder proceeds from multiple crimes committed in the United States. U.S. prosecutors and law enforcement agents worked in Romania with Romanian officials to ensure that a case could be successfully prosecuted in Romania.



I've just reviewed the 77-page indictment unsealed today, and its clear the Attorney General is making good on his promise. To make sure the Romanians didn't miss it, Deputy Attorney General Mark Filip was in Bucharest Romania to do the press release alongside his Romanian counterparts. Here is a copy of the press release in Romanian.



At his Press Conference in Bucharest the DAG said:


The anonymity of the Internet makes it an ideal tool for this kind of fraud, and law enforcement agencies in the United States have conducted several recent investigations in partnership with our Romanian colleagues. We are proud to do so, and we are learning from each other as we jointly help to protect our citizens and people in other countries from this sort of theft and crime.

For the people arrested today, the indictments charge that the defendants sent out mass quantities of e-mails, known as "spam," to lure victims to go to fraudulent Websites that appeared to be legitimate banking or financial businesses. At those sites, victims were tricked into entering personal information such as financial and identity information and personal passwords—a scheme known as "phishing." That information was then harvested by “suppliers” who, in turn, sent the information to “cashiers” via real-time Internet chat sessions.

The cashiers used hardware encoders and related software to record the fraudulently obtained information onto the magnetic strips on the back of credit and debit cards. They then directed “runners” to withdraw money from automated teller machines. A portion of the withdrawals was wired by money transfer services, such as Western Union, back to the supplier. We believe these criminals defrauded literally thousands of individual victims out of several million dollars.

These arrests and charges are the result of a joint operation by the FBI and the Romanian General Inspectorate of Police, and the cases demonstrate the close cooperation our two countries have developed to fight international organized crime.


Some of the schemes were quite interesting. In a "Smishing" scam described in the indictment, an SMS Text Message would be received that says "We're confirming that you've signed up for our service. You will be charged $2 per day unless you cancel your order on this URL: www.trustme.com -- this would result in malware being planted on the visitor's browser.

Chat logs were included in the indictment, such as Panait sending a message to Tran, telling him "bro this are from my spam . . . super fresh . . . I will spam more . . . spammed like hell . . . used 7 remote desktops and 13 smtp servers, 5 root, and sent over 1.3 million emails."

Logs from August 2006 all the way up to January 2008 were included, that make it clear the roles of each of the defendants. Discussions and logs include counterfeit cards made for:

Allegheny Federal Credit Union, American National Bank of Texas, Arizona Federal Credit Union, Artesian City Federal Credit Union, Bank of America, BB&T (Banker's Bank & Trust), Boeing Employee's Credit Union, Bowdoinham Federal Credit Union, Capital One Bank, Citibank, Credit Union One, Downey Savings & Loan, epassporte, E-Trade, First Merit Bank, Flagstar Bank, Franklin Mint Federal Credit Union, Iowa League Corporate Central Credit Union, Jeffco Schools Credit Union, Langley Federal Credit Union, Mountain America Credit Union, NASA Federal Credit Union, North Island Credit Union, PointBank, Premier Credit Union, Premier Credit Union, Southern Lakes Credit Union, Southwest Federal Credit Union, Teacher's Credit Union, Telco Credit Union & Affiliates, Valley National Bank, Washington State Employees Credit Union, and the Waterbury Teachers' Federal Credit Union.

Caroline Tath and Tran were making their cash cards with laptop computers, Tath had a Dell Inspiron and an HP laptop, Gigatech flash drives, an MSR-206 encoder, an Operah card reader, and a software system called "CC2Bank 1.3", which was used to make the cards. Tran used a Sony Vaio laptop, and also provided software to defendant Lee, including a program called "TheJermMSR206". Lee used a Sony Vaio laptop and an MSR505C encoder.

Some of the defendants used their counterfeit cards to buy goods at WalMart and CostCo. Others purchased stock on E-Trade accounts, or used E-Trade accounts to purchase Postal Money Orders. Many cards were used to withdraw cash from ATM's in Los Angeles and Orange County. Some of those funds were transferred via Western Union or MoneyGram to Romania, where the data to make the cards had been received from on a "50/50" cashier's deal.

At least one defendant also shipped "refurbished notebook computers" to co-defendants in Romania.

Some of the ATM withdrawals were made using hotel room keys with the PINs written on the back in sharpie.

Romanians (indicted in Los Angeles):

Ovidiu-Ionut Nicola-Roman
Petru Bogdan Belbita
Stefan Sorin Ilinca, AKA AzZ, AKA Kahn, AKA Kahnpath
Sorin Alin Panait, AKA scumpic4u
Costel Bulugea, AKA The.Vortex
Nicolae Dragos Draghici, AKA Marius Bogdan, AKA Nonick
Florin Georgel Spiru, AKA niggaplease
Marian Daniel Ciulean, AKA spuickeru
Irinel Nicusor Stancu, AKA sicaalex
Didi Gabriel Constantin, AKA StauLaSoare, AKA Estaulasoare, AKA snoop
Mihai Draghici
Marius Sorin Tomescu, AKA Andrei
Lucian Zamfirache, AKA Krobelus
Laurentiu Cristian Busca, AKA italianu
Dan Ionescu, AKA m1nja
Marius (Last Name Unknown), AKA 13081981
Alex Gabriel Paralescu, AKA paraiul
Andreea Nicoleta Stancuta, AKA godfather

Romanians indicted in Connecticut:
(See FBI New Haven's Press Release )

residents of Craiova:
Ciprian Dumitru Tudor
Ovidiu-Ionut Nicola-Roman
Mihai Cristian Dumitru
Petru Bogdan Belbita, AKA "CA is SK", AKA Robert Wilson

residents of Galati
Radu Mihai Dobrica
Cornel Ionut Tonita
Cristian Navodaru

Perhaps more interesting would be the international partners who were also indicted, including:

Hiep Thanh Tran, AKA John Tran, AKA Sam Lam -- a US resident from Vietnam

Hassan Parvez, AKA XID - from Pakistan

US Citizens:
Sonny Duc Vo, Alex Chung Luong, and
Leonard Gonzales, AKA Bonecrusher

Vietnam Citizens:
Nga Ngo, AKA Christina Ngo
Thai Hoang Nguyen, Loi Tan Dang, Dung Phan - Vietnam

Cambodian Citizen:
Caroline Tath

Rolando Soriano, AKA Loco, AKA Danny Villalopez - from Mexico

Four other hackers remain at large, known only by their aliases:

Cryptmaster, PaulXSS, euro_pin_atm, and SeleQtor

We can look forward to the next big bust, because there seems no indication these fools are slowing down. When we visit some of the chat rooms where "kahnpath", for example, used to advertise his wares, we are immediately greeted with ads for people looking for "Cashout partners", and trying to sell an MSR-206 card writer for $400.

Saturday, May 17, 2008

Spanish Arrest D.O.M. Team

Spanish police announced the arrest today of five members of a prolific hacking team known as "D.O.M.". The D.O.M. team has been a political activism team active for quite some time. Zone-H, the "scoreboard of the underground", lists D.O.M as being #5 in prevalence of "Special" defacements - those against governments or major corporations or organizations. For all types of attacks, D.O.M is listed as #26, with 21,191 attacks credited to their account.

Update: Press Release from Spanish Police shows that the arrest operation was coordinated by "el Grupo de Seguridad Lógica de la Brigada de Investigación Tecnológica de la Policía Nacional" with cooperation from " agentes de la Brigada Provincial de Policía Judicial de Burgos, Málaga, Valencia y Sabadell". Congratulations to them all on their police work!

Recent defacements by the group list their members as:

an0de, ka0x, Xarnuz, and Piker

while hacks from earlier in the year listed:

crane0x, ka0x, Xarnuz, and S0cratex

We're not sure yet which were actually arrested, as the Spanish are protecting the identities of the group who are mostly minors, with two of those arrested being only 16 years old, and the other three being 19 and 20. Those arrested resided in four Spanish cities - Barcelona, Malaga, Valencia, and Burgos.

A Spanish speaking group, the actual membership has varied over time to include members from Spain, Argentina, and Mexico. For a short time a Brazilian hacker, "nwx0x" was also a member of their group, and "vpn0" and "Nitronet" have also been seen to claim membership. Their recent defacements have been Environmental Activism, decrying the pollution of rivers and the building of paper mills. The Spanish investigation began after a member of the group hacked the "Izquierda Unida" website and left supposedly "obscene messages" and caricatures of politicians on the site on March 3rd, a week prior to the March 9th election.

The actually words were:

"Tenemos algo en común, le dijo un presidente a un embustero..."
(roughly, "we have something in common, said the President to the liar/cheater" - which doesn't sound nearly as nasty as "obscene messages").

and the caricature may still be found on ImageShack, where it was originally hosted:





A spanish blogger at the time provided some clues as to what happened, including giving links to ka0x's profile on "spanish-hackers.com" (now offline) and pointing them to the current "D.O.M" website -- domlabs.org

Some of the more high-profile attacks credited to the group, at least from an American perspective, would include having hit the US government's National Cancer Institute with an SQL injection attack back in July of 2007, ( archived from Zone-H). In February, an0de defaced an MIT server with an anti-American, anti-Bush message, archive from Zone-H .

Members of the group are said to have hit NASA back in March, but it is unclear whether "Spanish Hackers Team"'s March defacement of "climate.gsfc.nasa.gov" is the same reference. Certainly its the same server that the closely allied hacker "SSH-2" hit as recently as April 25th, but we do have a positive reference of D.O.M member "an0de" hitting the NASA server "issues.worldwind.arc.nasa.gov" back in August 2007.

In a typical environmentally-motivated hack of Groton South Dakota's government website by the group in April 2007, the hacker used a gmail address: 3sk0rbut0@gmail.com and posted the message:


Defaced by ka0x

This is a cyber-protest against climatic change!!
Stop contamination!
(censored) to all governs that allow the contamination of the world!

we are: [ Arp; ka0x; an0nyph; xarnuz; Tequila ]

(SPain - Mexico - Argentina}



The spanish police say they are responsible for more than 21,000 website defacements including many government sites. (A statistic they surely got from Zone-H!) That matches what we see in the Zone-H archives, where hacks against the governments of India, Thailand, Turkey, Columbia, China, Malaysia, and others are readily found in the archives.

For several years the team ran a website, called "DomTeam.info", although their hosting was sketchy at best as they were run off numerous webservers. The original registration, from back in September of 2005, shows the email address "arcax.ath@gmail.com" as the contact address. "ATH" was another hacker group called "Arrow Team Hispanic", where Arcax partnered with KingMetal to cause script-kiddie type trouble to websites.

From the whois data from October of 2005, we find the meaning of the "D.O.M" name, as the whois information was changed to being registered to "Dark Owned Mafia". The members actually listed themselves in the WHOIS information later in 2005, when the whois "Street Address" was given as: "XgdnX - Davidu - Rootbox - ArCaX-ATH", the then current members of the group. That would remain the team's street address until November of 2007 when the domain was shut down by the Registrar (Melbourne IT).

ArCaX-ATH posted his "retirement from the underground" message on April 4, 2007, claiming at that time that he had been personally responsible for 10,880 website defacements. Here's that farewell message:


Bueno esto es algo que notaba desde hace algunos meses, mi poco tiempo para hacer las cosas del grupo D.O.M... y que muchos estaban anciosos de poder leer, así que hay les otorgo el siguiente regalo, baj la una reunión de costumbre. el domingo pasado he decidido delante de todos los miembros del grupo y con aprobación de los mimos, he decidido retirarme completamente de la scene Underground sin aviso por nuevo reintegro ni nada por el estilo, tenia pensado en hacerlo en octubre de este año cuando el team cumpliera los 2 años ... pero ya no podía tener en espera a los demás compañeros del grupo, aunque el echo de mi retirada no quiere decir que el grupo también se pare, se que anonyph los demás lo llevaran por el buen camino; agradezco en especial a her0 y ka0x que me llevaron a tomar la decisión correcta para el team. también se ha decido que la web de DOM no seguiría con portal ya que un portal requiere un cuidado exhaustivo con los foros y demás, se ha decido que me quedase con los 2 dominios (INFO y BIZ) para utilizarlo en mi blog personal, y otros proyectos personales... de ArCaX-ATH tendrán para rato eso sí, solo que con menos frecuencia que antes....


Although he was withdrawing, he states that "anonyph" will carry the team forward in the right direction.

ka0x was the one, however, who took the reins to set up the new website on January 31, 2008, and we find his gmail account listed in the registration for "domlabs.org" -- "ka0x01@gmail.com", with a (probably fake) Peruvian street address.

Using the same email, ka0x posted several exploits that he had written to the milw0rm collection of attack tools, including Remote SQL injection programs written in Perl, and a program to insert your own user information into an LDAP directory, which was bannered with this:


Title: LDAP injections
Author: ka0x
contact: ka0x01[!]gmail.com
D.O.M TEAM 2007
we: ka0x, an0de, xarnuz, s0cratex
from spain



Ten exploits and two papers are credited to ka0x on his milw0rm author page, including an 11 page paper on "Blind MySQL Injection" where he also lists the gmail address of one of his fellow team members, Piker, at piker0x90@gmail.com.

an0de also kept a blog at: http://buclenoapto.wordpress.com/

Thursday, May 15, 2008

Certificate Dangers?

The German Import House has a catalog where you can by a Dirndl dress or an Oktoberfest Party Hat.

https://germanimporthouse.sslpowered.com/germanimporthouse/nfoscomm/catalog/

The catalog gives its visitors the added sense of security by turning the address bar in my Firefox browser yellow, and adding a padlock to the address bar. When I float my mouse over the padlock, I get the "Authenticated by Equifax" popup.

When I click on it, it says:



SSL Server Certificate

Issued to
Common Name *.sslpowered.com
Serial Number: 08:90:D2

Issued By
Equifax Secure Certificate Authority

Issued On: 1/11/1008
Expires On: 2/10/2010



Unfortunately, someone put a Meadows Credit Union phish in a subdirectory of the catalog.




Visitors to that phishing site will see the same "warm fuzzy" yellow bar, and the same "Authenticated by Equifax" message.

Which brings me to the point of this article. We are all talking about Extended Validation Certificates, which will turn your address bar green, "proving" that the site is legitimate. What proof do we have that someone hasn't hacked the legitimate site and used it for an illegitimate purpose. That's what we see here with a "pre-" EV Certificate. German Import House is a legitimate site, and paid for an Equifax Certificate to prove so. However, the visitor to the Meadows Credit Union phishing site is ALSO going to see the Certificate behavior. But what does that prove?

How much danger are we in when we train our users that a colored address bar means they are safe - and then phishers hack those sites to host phishing content? The user sees a colored bar and a padlock -- one that really has a corresponding certificate on file -- and decides that its a safe site. Are EV Certs the answer? or just another way to train users that they don't have to think?


--

Wednesday, May 14, 2008

Indictments reveal $77 Million in Illegal Pill Sales

Congratulations to the Daytona Beach FBI, US Attorney Robert O'Neill, and their colleagues at IRS and FDA.

The Daytona Beach News reported the arrest of three Volusia county ringleaders with the headline Locals accused in $77 million Internet drug ring.

According to the indictment, Jive Network distributed approximately 4.8 million dosage units of Schedule III controlled substances and approximately 39.2 million dosage units of Schedule IV controlled substnaces to Internet customers who had no valid prescriptions. They serviced over 500,000 customer orders and generated more than $77 Million in revenues over a three year period.

Charged in the indictment were:

Jude LaCour, 35, Daytona Beach, Florida (Jive Network Owner)
Jeffrey LaCour, 60, South Daytona, Florida (Jive Network Director of Operations)

whose charges included money laundering and drug trafficking offenses involving the sale of controlled substances over the Internet. (The elder LaCour was profiled May 11th in this story: Rx Suspect has Mixed Local History

Hudsen Smith, 36, Deland, Florida (Jive Network Director of Pharmacy/Physician Operations)

and the following physicians, who were paid to do the "medical reviews" for patients who had no prescriptions.

Christopher Tobin, 41, Wilmington, North Carolina (Physician)
Akhil Baranwal*, 34, Pennsylvania (Physician)
Alexis Roman Torres, 54, Puerto Rico (Physician)
Andrew DeSonia, 47, Indiana (Physician)
Marget Fulmore (McIntosh), 52, Charlotte, North Carolina (Physician)
Abel Lau, 36, Tulsa, Oklahoma (Physician)
James Pickens, 72, Midvale, Utah (Physician)

The prescriptions were filled by several pharmacists, but the only one charged in this indictment is:

Geunnet Chebssi, 56, Spencerville, Maryland (Pharmacist)

Customers, who had no prescriptions, accessed the websites and purchased the controlled substances after completing a short health history questionnaire. Identities were not verified and medical records were not submitted.

The announcement of this indictment has been a long time coming. Online drug stores have known that The Jive Network, also known as "Celestial Group Inc", has been in trouble since at least April of 2005. A note from one such online drugstore dated April 24, 2005, read:


The Jive Network, also trading as Celestial Group Inc, were closed on the morning of April 19, 2005 as part of an investigation by DEA and FBI. To date no charges have been laid and the owner of the online pharmacy group, Jude LaCour is not in custody and has not been charged with any offences. (...) The pharmacy sites that are affected are: ePharmacist, Pillvalue, Pillstore, InstantPills, and Cyberpills.


An update on May 12, 2005 added this:


We believe Jive Network are trying to get back online and are clearing ePharmacist, PillStore, PillValue, and CyberPill orders that were held up around April 19th. Over the past 2 weeks, they seem to be either refunding customers or sending product.


At that time, Jive sent a letter to their affiliates explaining the situation. (Quoted from the "rx-affiliate" forum at "ABestWeb.com", posted April 29, 2005):


Dear Affiliate,

You may have heard the news that our offices were served with a search warrant last Tuesday, April 19th, 2005.

However, NO ARRESTS were made. No Charges were filed.

This is an obvious attempt by the DEA and FBI to try and lump us in with a group of 20 other companies/individuals that had been under
investigation, and who WERE arrested around the same time.

We want to share with you that we are NOT related to nor connected with these 20 in any way.

Jive Network has ALWAYS done everything by the book and beyond.

We have broken no laws.

We know that some of your checks have bounced. This is because the search warrant also allowed them to seize all bank accounts. When we say all,
we do mean ALL! We realize that apologizing for the difficulty this has caused you does very little, but we want to assure you of this: As soon as we are able to correct it, we will.

As to the current status, late last week, we put the websites back online. We have our internet connections and the equipment we need to start
processing orders again. However, until our accounts and other matters are operational, we are not taking orders at this time.

Additionally, something is going on with our phone lines. This is likely part of this defamatory attempt on us, so we are working to uncover and
resolve that problem as well.

When we are fully operational, we will immediately begin processing orders.

Lastly, to those of you that have emailed us telling us that you are with us, we want to express how sincerely all of us appreciate that support.
We have read comments such as, "You guys are the best ever in the industry, just let me know when I can switch my links back".

This kind of response is more than encouraging to us, and the truth is that we want to be here for as much as you are here for us. We do understand
what you are experiencing.

Please understand that the delay in sending you some kind of direct communication has been due to the circumstances of this situation, NOT
BECAUSE WE DIDN'T WANT TO TALK TO YOU.

You can be sure that this situation will not stop us. We might "look" much different in the future, we will still be us, the same "Jive Network
Team" working hard for you.

While we are uncertain as to when we will come back online, you can be certain that when we do, our entire business will be stronger and even better
than before. A team that has been through an event like this and stands firm, is a team that can accomplish anything.

Stand firm with us. We will accomplish great things, together.

Sincerely,

Jive Network



(The same letter can also be found here)

In February 2006 the note was updated again that "XL Pharmacy" had acquired the chain of online drugstores, and was standing by to fill your needs. "XLPharmacy prescriptions drugs are made by world renowned International pharmaceutical companies such as Novartis, Cipla Abbot, Aventis, Bayer, Cipla, Dr. Reddy's, Merck, Eli Lily, GlaxoSmithKline, and Ranbaxy. All prescription drugs are shipped in the manufacturers' original package and have the manufacturers' original seal for your safety.

The link provided is still live:http://www.xlpharmacy.com/index.php?img=4&kbid=1325. The helpful FAQ on that site, which claims to have been online since 2004, says:


In all cases orders require a prescription prior to shipment. If you do not have a prior prescription you will be asked to complete a online medical consultation and it will them be reviewed by a licensed physician who may or may not issue a medical prescription based upon your medical consultation. If your online medical consultation was not approved by the physician you will then need to provide a medical prescription from your local physician by fax to us prior to the shipment of your order.


And yes, this replacement pharmacy is still recruiting . . .according to their website:


Experience the highest payout commission and the best Affiliate Support by telephone, live chat and email. XLPharmacy.com pays the highest direct commission and the highest second tier commissions in the industry. Payments are made by bank transfer or epassporte weekly. Please contact the program manager to arrange for your preferred payment options and commissions structure. Commissions are paid up to 45%.


I can't swear that to be accurate. There were several competing affiliate programs who apparently were believed to have purchased Jive Networks customer list. LaCour and Jive Network were also the feature of an issue of The Ripoff Report claiming they had gone back into business operating "rxwebdrugstore.com, realprescriptions.com, rxwebmeds.com" and others. The owner of "Secure Medical" posted a rebuttal to this though claiming they were not related, and that their database had been compromised.

In a letter written by Haden Smith back on Aug 20, 2004, he claims there are more than 100 online prescription websites using their fulfillment services, and that their pharmacies earn between $3,000 and $10,000 per day profit.

The chat boards used by the online pharmacies and their customers are lighting up with news stories about the arrests:

Rx Affiliate Forum posters want to know "are affiliates next"? In reply, the poster was reminded "What about the 8 affpower affiliates" who were arrested? Several posters say that advertising is not illegal as long as the affiliates don't take the payments or touch or ship the drugs they are "just like Google or Yahoo" - only advertisers.

epharmacywatch.com, which provides this list of online pharmacies and their associated "Consultation Fees" and user ratings. Their conversation forum for talking about US-based online pharmacies has over 100,000 posts! The site has 117,791 registered users as of this morning. It will be interesting to see if their reaction to the news goes beyond mere reporting of the indictments.

* - curious coincidence in names here . . . this name, and city, came from court documents, but there is an Akhil Baranwai in Georgia accused of the same sort of behavior (i vs L at the end of the last name)

Monday, May 12, 2008

TJX and Dave & Busters

If you've visited a Dave & Busters, you know these are a great place for grown-ups to go out and play. I've been to several events at the Atlanta location, and enjoy the Virtual Reality games there. I never thought I would see a Dave & Busters story come up on the news-ticker that I have watching for new TJX stories, but that is what happened this morning.

You will probably recall the story of Maksym Yastremskiy (Maksik), a Ukrainian citizen arrested in Turkey for his role in trading enormous volumes of credit cards which could all be traced back to the TJX debacle. He was back in the news today with two other hackers, Aleksandr Suvorov (JonnyHell) from Estonia, and Albert Gonzales (Segvec). The charges are that the first two ran a scam involving the installation of packet sniffers into thte cash register systems at 11 Dave & Buster's restaurants. Just the Islandia, New York location was credited with 5,000 customer's credit card data leading to more than $600,000 in fraudulent purchases. Segvec is charged only with "wire fraud conspiracy", in that he purchased some of this data from Maksik.

The indictment was posted on the ABC News website.

The 27 counts against the first two are:

Count One: Conspiracy to Commit Wire Fraud
(knowingly and intentionally conspiring to devise a scheme and artifice to defraud D&B, its customers, and the financial institutions that issued the customers' credit and debit cards, and to obtain money and property...by means of materially false and fraudulent pretenses, representations and promises, and attempting to do so by means of wire communication in interstate and foreign commerce . . . )

Counts 2-5: Wire Fraud
(installing a packet sniffer, and reactivating it at D&B Store #2 in Islandia, New York, on 5/18/07, 6/9/07, 7/23/07, 8/14/07.)


Count 6: Conspiracy to Possess Unauthorized Access Devices

Count 7-9: Possession of Unauthorized Access Devices
(the "access device" in question being log files containing "15 or more credit and debit card account numbers".)
(Title 18, Section 1029(a)(3))
(Title 18, Section 1029(c)(1)(A)(i))


Count 10-12: Aggravated Identity Theft
(Title 18 Section 1028A(a)(1), (b), (c)(5))

Count 13: Conspiracy to Commit Computer Fraud
(Title 18 Section 371 and 3551)

Count 14-16: Unauthorized Computer Access Involving an Interstate Communication
(Title 18 Section 1030(a)(2)(C))
(Title 18 Section 1030(c)(2)(B)(i))

Count 17-19: Unauthorized Computer Access to Obtain Things of Value
(Title 18 Section 1030(a)(4))
(Title 18 Section 1030(c)(3)(A))

Count 20-23: Unlawful Transmission of Computer Codes
(Title 18 Section 1030(a)(5)(A)(i))
(Title 18 Section 1030(a)(5)(B)(i))
(Title 18 Section 1030(c)(4)(A))

Count 24-27: Interception of Electronic Communications
(Title 18 Section 2511(1)(a))
(Title 18 Section 2511(4)(a))

Oh yeah, and they are going to go for Criminal Forfeiture of all losses.

All the way back in June 2007, Maksik and Segvec are on the way towards losing their e-gold accounts, according to this testimony from US Secret Service agent Roy Dotson, who names e-gold account number 1751848 as belonging to Maksik, and 3584940 as belonging to Segvec.

From that affadavit:


“Segvec”: “Segvec” is a vendor of stolen financial information on the carding
website Makafaka and accepts payment for his contraband in e-gold. A search and review of the e-gold database revealed number 2464856 – which has as its contact name “segvec.” According to information related to me from agents of New Scotland Yard’s National Terrorist Financial Investigation Unit regarding email communications they had with Douglas Jackson in April 2007, Douglas Jackson was aware that “segvec” was a Ukrainian carder.

An analysis of “segvec”’s account number 2464856 yielded the following results:
The account was created in October 2005. There were 93 transfers into the account with a value of 1524.80951 grams ($845,545.60).

20 of the 90 transactions, which total 726.623113 grams ($410,750.00) and occur between February and May 2006, are transfer of funds from account 1751848, “Maksik’s Job”



“Maksik”: “Maksik” is a known vendor of stolen credit card information, stolen
financial accounts, and fraudulent Ukranian passports on the Shadowcrew, Mazafaka, and Carderplanet carding websites and accepts payment for this contraband in e-gold. A search and review of the e-gold database revealed account number 1751848, with the account name “Maksik’s Job,” and contact email addresses of info@maksikjob.com and maksik@maksik.biz. Several memo fields in the transaction record for e-gold account number 1751848 indicate carding activity, including, for example, “1-27 order amex” (i.e., an order for a stolen American Express credit card number), “Happy H4xOr Dumps” (i.e., stolen credit card information), “For 20 classics” (i.e., a type of credit card). A search and review of the e-gold database also revealed e-gold account number 3399565, with the account name “Maksik’s account,” and containing a contact email address of Maksik@maksik.cc. A review of this account also shows many transactions with other e-gold accounts controlled by known carders, including e-gold account number 2567183 (controlled by “Lord kaisersose” – a known vendor of stolen credit card information), and e-gold account number 2874688 (controlled by “u26" – a provider of credit card pre-authorization services to vendors)


Yastremskiy was arrested in Turkey in July 2007, where he remains in jail.

Suvorov was arrested in Germany in March 2008.

Gonzalez was arrested in Miami in May 2008 by the US Secret Service.

Friday, May 09, 2008

Digital Certificates Update

A quick update from the previous post.

The Digital Certificates spam campaign against Merrill Lynch continues, but the good guys seem to be recovering their lead. Of the 9 domain names used in the spam campaign last night:

876536784k.com
2376540m.com
1291logon.org
10000993m.com
374286434d.com
8447652a.com
1291logon.biz
1291logon.net
1291logon.com

only one was live when my morning report was run this morning.

2376540m.com

did load the web page shown in the previous blog entry, and attempted to download the file:

MLBusinessCentreCERTv6704.exe

but this time the download was detected by McAfee anti-virus and blocked as "Spy-Agent.bg"

Much better. We'll see if we can make 2376540m.com go away shortly.

Tuesday, May 06, 2008

Digital Certificate Alert!

UAB Computer Forensics is investigating yet another "Digital Certificate" phishing attack -- this time with Merrill Lynch as the target.

The traditional definition of phishing requires the website that the customer visits to request personal information, such as the userid and password to an online account, or credit card or bank account information. In this case, no personally identifiable information is requested. Instead, the emails and the destination website tell the potential victim that Digital Certificates will make their online financial experiences safer. This rings true with consumers, who are certain to have heard about the advantages of certificates, especially as the "Extended Validation Certificates" (the ones that turn your browser address bar green if you are on a real site?) are increasingly proclaimed by companies like DigiCert,
Verisign,
and Thawte to be the Next Big Thing in security.

It is this increased consumer awareness that is leading to the current rounds of victimization. In this scheme, the consumer receives an email, informing him that his financial accounts will be more secure if they upgrade to digital certificates, or that their current digital certificate has expired and needs to be upgraded. If they follow the link, they are taken to a website where they receive more information about the importance of the upgrade, and are given instructions to "install" their digital certificate, with a link to download the installation program.

The installation program is of course a virus. The first Digital Certificate malware we investigated, against Bank of America, ended in early April, but the new round, which includes Comerica Bank, Colonial Bank, and now Merrill Lynch, is still going strong, with Comerica being a nearly daily target with more than 250 domain names used in the fraud. Colonial Bank has only been targeted on two days, with 22 domain names used, and now Merrill Lynch, which launched yesterday with the domain names

1291logon.info and 1291logon.com

(I confirmed that both websites were taken offline before publishing this article.)

The Merrill Lynch version of the Malware is called "Papras.dk" by most of the anti-virus programs that detect it. The first version of the Colonial Bank trojan was called "Papras.dh", and the first version of the Comerica Bank trojan that we looked at was called "Papras.dc". More evidence that these are originating from a common source.

As with most emerging threats, common anti-virus products are not immediately blocking the threat. For instance, F-Prot, McAfee, and Symantec, do not show on VirusTotal as having detection for this threat. McAfee engineers have previously complained to me that VirusTotal is not an accurate way of knowing whether they have detection. I run McAfee on my own work desktop though, (for balance, I run Symantec at home), and when I do an AV update (to DAT version 5289.0000, dated May 6 2008), and then scan the file, it does not detect.

The sad part about the failure of common AV engines to detect this virus is that this file is a BINARY IDENTICAL MATCH for the Colonial Bank version of the trojan that we analyzed and reported on April 30. One week later, and the two largest AV companies still have no detection.


The current email looks like this:




MERRILL LYNCH BUSINESS CENTER IS CHANGING

Merrill Lynch develops new solutions that deliver instant,
comprehensive online banking and protection against evolving
computer security threats.

Dear Merrill Lynch Business Center Customer:

In an effort to better serve you, the following changes to the
daily processing procedures will go into effect on Tuesday, May 6th:
We’ll be launching new ml.com Business Centre homepage

In addition to a fresh look, the new Merrill Lynch website will provide:
-VIP CLUB
-Easier access to login
-Easier ways to contact and locate us
-Access to more information on what we offer and what we do Online
Please discover new Business Centre homepage now:
Continue>>

Copyright 2008 Merrill Lynch & Co., Inc.




And the website that it pointed us to looked like this:



Now, put on your Sherlocke Holmes hat and try this one yourselves. Can you detect any similarities with this email?




Comerica TM Connect Web Bank Renewal

Certificate Renewal
Personal (Smartcard) e-Cert & Personal e-Cert
Certificate owner must renew the certificate before expiry date.
Your certificate expiration date - 1may 2008.
The system will send email (Certificate Renewal Notice) to the certificate owner ten
days and 3 hours before the certificate is due to expire, if it has not been renewed.
Upon receiving the renewal notice, certificate owner is required to connect to
Comerica Bank Certificate Management System and present the client certificate.
Secure Server e-Cert & Developer e-Cert
Certificate owner has the responsibility to renew the certificate before expiry date.
Successful renewed application will receive an email notification from Comerica Bank.
Applicant can just browse to the URL stated in the email and then download the certificate.

Download now>>

2008 Comerica Treasury Management Connect Web (SM) Version 4.2




How about this email?




Connection-Colonial Bank Renewal

Certificate Renewal
Personal (Smartcard) e-Cert & Personal e-Cert
Certificate owner must renew the certificate before expiry date.
Your certificate expiration date - 1may 2008.
The system will send email (Certificate Renewal Notice) to the certificate owner ten
days and 3 hours before the certificate is due to expire, if it has not been renewed.
Upon receiving the renewal notice, certificate owner is required to connect to
Colonial Bank Certificate Management System and present the client certificate.
Secure Server e-Cert & Developer e-Cert
Certificate owner has the responsibility to renew the certificate before expiry date.
Successful renewed application will receive an email notification from Colonial Bank.
Applicant can just browse to the URL stated in the email and then download the certificate.

Download now>>

2003 Colonial Bank, N.A.


Thursday, April 17, 2008

Dear CEO . . . You are Commanded to Go Phishing!

This week has been busy with yet another Spear Phishing campaign being launched against the Execs of US-based companies. This is not a new trend by any means. In my presentation at the DOD CyberCrime Conference this year, "Spear Phishing: Hackers Target High Value Targets", I shared information about the October "Better Business Bureau" spear phishing attack and the January "US Department of Justice" spear phishing attack. Its clear that this round is a continuation of these.

In the current round, the email contains the real name of the executive (we have confirmed it is not only CEOs, so that is also consistent with the previous attacks), and their real telephone number in the body of the email. Here are some excerpts from one such email . . .


SUBPOENA IN A CIVIL CASE

Case Number:

(numbers here)
United States District Court

YOU ARE HEREBY COMMANDED to appear and testify before the Grand Jury of
the United States District Court at the place, date, and time specified
below.

...

Please download the entire document on this matter (follow this link)
and print it for your records.

...

Failure to appear at the time and place indicated may result in a
contempt of court citation. Bring this subpoena with you to the
courtroom and present it to the bailiff.


The initial domain used in the attack, "cacd-uscourts.com" was registered through the Registrar "Web4Africa" on April 12th. On Monday, we had the good fortune that someone reported this phish to the CastleCops PIRT Team, where it was assigned PIRT #792683. Monday evening, PIRT received an email back from Web4Africa informing us that the site had been disabled, which they did by changing their NameServers to "suspended1.web4africa.net" and "suspended2.web4africa.net", as you can see in their Current WHOIS record.

I wasn't able to fetch the malware the first round, as I was away from my lab at the incredible Usenix LEET 08 Workshop, where I was able to meet some security heroes of mine, Thorsten Holz and Neils Provos, the authors of Virtual Honeypots: From Botnet Tracking to Intrusion Detection. (Subliminal mode on -- Buy this Book! -- Subliminal Mode Off).

I got home Wednesday afternoon and went straight to the lab, only to learn that the Phisher was stupid enough to immediately try again. When I arrived in the lab, I checked for other sites hosted by the original nameservers and saw that a new domain name had been registered early Tuesday morning. They chose a different name, "casd-uscourts.com", which they hosted on the exact same IP as the other box, (which incidentally hosts several other malware sites which infect their visitors by installing software via "IFRAME" and Encrypted Javascript techniques).

We used CastleCops to get the site shut down again last night, but not until we first made some screen shots and infected a goat machine with the malware to see what it would do. (Thanks to two of my UAB CIS graduate students for staying late and working on this last night!)

The site is using ActiveX to deliver its malware, and requires an Internet Explorer browser, as you can see from the two screen shots below:






Several people have said "No CEO would click on a subpoena in email!" That's probably true. The CEO would probably send it to the corporate counsel, who would click on the subpoena in email.

Regardless WHO clicks on it, here is what happens if someone does:

The browser goes to "Acrobat.php", which causes the creation of a hidden file called \Windows\system32\Acrobat.dll.

The registry is modified by placing the value: "rundll3d acrobat.dll Anit" in the registry key: \HKLM\Software\Microsoft\Windows\CurrentVersion\Run

A listening port is opened (in our case it was on port 1900).

Every 60 seconds, the machine notifies this computer in China of its infected status by visiting a URL like this:

http://124.94.101.48/MMM/parse.php?mod=cmd&user=MachineName

where MachineName is the system name of the machine in question.

That is probably all the details I'll share for now.

If anyone has observed network traffic going to this IP, there is a very good chance someone in your network is infected. I'd love to know what other communications your infected machine is exhibiting. Please do send me an email!

Wednesday, April 09, 2008

"Grey Pigeon" banking trojan leads to jail time in China




On April 3, computing.co.uk reported the arrest of four Chinese men for breaking into the online bank accounts of their fellow citizens. The report was high on theory and low on details. For the moment we will ignore the "spin" being placed in this story elsewhere in the media -- does this mean the Chinese government wants to stop hackers, but only if they are hacking other Chinese? -- let's just examine the facts.

The four men, who have the surnames of Duan, Wei, Li, and Ruan, according to an April 1 report from Shanghai Daily News received sentences ranging from 8 years to 2.5 years. They were also fined 155,000 yuan, or about $20,000 USD. The sentencing occurred in the Luwan District People's Court.

According the Shanghai Daily News report, the hackers did their work by using a hacker tool called "Grey pigeon 2006vip". After planting this software on various websites, visitors to those websites became infected with a trojan which stole their userids and passwords when they logged on to their bank. We call this type of infection a "Drive By Infector". All that is necessary to be infected is to visit a website hosting the malware.

Li's role was to hack the website and install "Grey Pigeon". Duan received the accounts and transferred the money out of the victim accounts to an account controlled by the hackers. Wei and Ruan had the hands-on job of withdrawing the cash from ATM machines.

The withdraws mentioned in the trial occurred on April 11, 2007 and May 12, 2007.

Luwan district, which is part of Shanghai, has seen similar cases of this type recently, including the the conviction of Bai Yongchun last September, who was also convicted of stealing money by using the Grey Pigeon software.

Grey Pigeon can be found being discussed at "hacker120.com", which also goes by the name of "www.hkop.cn", in a forum called: 黑客攻防技术专区

The current version of Grey Pigeon (Grey Pigeon 2008, or 微尘灰鸽子2008免杀版), has been available at hacker120.com since January 31, 2008. The virus tries to edit your registry to make itself a Windows Service, by adding the tag:

HKLM\SYSTEM\CurrentControlSet\Services\Windows XP Vista

to your registry, with a pointer to itself. The originally downloaded file is named "hacker.com.cn.ini", but this file is renamed to an ".exe" with the same name as it is copied to create the Windows Service named "Windows XP Vista".

Sophos detects the current version of Grey Pigeon as "Troj/Mdrop-BQA", and has protected against it since Feb 2008, according to this Sophos information page.

In China, the Grey Pigeon family is prevalent enough that Chinese anti-virus company "Rising" has a special detection program for it, which can be downloaded from their website (GPDetect.exe), where they have a link to Grey Pigeon information from their main website homepage. (The information page about Grey Pigeon has been being updated since originally published by Rising in 2005!)

Thursday, April 03, 2008

Welcome Cornelius Tate, our new NCSD!



Today Brian Krebs broke the story in his Washington Post "Security Fix" blog, that Cornelius Tate had been named to head the Department of Homeland Security's National Cyber Security Division.

Cornelius Tate is a perfect example of a Computer Science major making a difference in the world of Cyber Crime. Tate received his bachelor of science in Computer Science from the University of Mississippi in 1985, but when a friend of his joined the Secret Service during Tate's junior year, he realized that he would rather be investigating computer crimes than writing code. (Source: DiversityCareers.com)


Like former NCSD Director, Jerry Dixon, Tate worked at the IRS after graduating from college. US-CERT will not be something new to him -- in 2002, Tate served as the Carnegie Mellon University's Software Engineering Institute as the "resident liaiason" from the USSS to the CERT Coordination Center (CERT/CC). Tate initiated the use of CERT/CC staff in high profile protection planning as part of the "Critical Systems Protection Initiative" (CSPI) which included having CERT members travel with the Secret Service to prepare cyber systems for events such as the 2002 Olympic Games and Super Bowl XXXVI.

Tate also recognizes the value of R&D. In this feature from SEI's CERT/CC Tate says of the Service, "We bring hands-on experience, and the CERT/CC provides a research and development capability that extends beyond the scope of our traditional protective mission."

While at CERT/CC, Tate was part of the "Insider Threat Study" research staff that lead to the development of the "MERIT" system, which we actually had presented in Birmingham at the joint "FBI InfraGard/USSS Computer Crimes Working Group" meeting in 2006. MERIT stands for "Management and Education of the Risk of Insider Threats", and we learned a great deal from the presentation.

When Tate was assigned to the Presidential Protective Detail, he served as the Supervisory Administrator for Technology Systems, and was actively involved in tracing email and Internet-based threats to the White House and its residents.

InfraGard members will know of Mr. Tate's work, not only from his participation in the famous InfraGard Houston conferences, but also in the form of their DHS-appointed Protective Security Advisors. Mr. Tate oversaw all of our nation's PSA's in his position as the Director of Field Operations for the Protective Security Division. In Birmingham we are very grateful for the active participation of our PSA in the Birmingham Chapter of InfraGard.

Congratulations on the new position, Mr. Tate. As an InfraGard President, and a Cyber Crime Researcher, I wish you well, and look forward to working with you and your staff in your new endeavors.

In Nigeria, Yahoo Boys picked up by EFCC Raids

Cyber Cafes in Akure in the state of Ondo, and Onitsha, in the state of Anambra were raided today. The locals have a term for the type of cyber criminal who lurks in these cafes. They call them "yahoo boys".


(image from "Hey CyberCafe" in Onitsha, not included in the raid, just a sample picture of an Onitsha-based cybercafe)

In Akure, agents of the EFCC (Econonmic and Financial Crimes Commission), acting as customers, mingled about the crowd, bought airtime, and began using computers themselves while observing the activities of those around them. Once their suspicions were confirmed, they rose and identified themselves, requiring each of the users of the cafe to remain on site until they had confirmed what email addresses they had been using, and what activities those email addresses had been performing. "This Day" in Lagos reports that at least one Yahoo Man jumped out the window when the raid began. This Day reports that the following day the cyber cafes were nearly empty, "leaving only those with serious business".

In Onitsha, things went a bit differently, according to The Nigerian Tribune, with officers arriving in an unmarked Toyota van and blocking off the road leading to Main Market to prevent the flight of cyber cafe operators.

Sixteen arrests were made, primarily of Yahoo Boys, who spend their days reading and sending scam emails hoping to encourage rich Americans to part with their money. At least one cyber cafe operator was also arrested, and several computers were confiscated as evidence.

The most fascinating part of this story, however, is not in the current day's news. For the story behind the story we have to go back to March 17th, when the President of Nigeria, Umaru Yar'Adua, announced that he was planning to establish a separate body known as the National Cyber Crimes Commission. The bill, which was described in Nigeria's Business Day Online, was called necessary precisely because the EFCC cannot effectively "handle the cyber crimes in addition to its other responsibilities". Business Day Online's source said the activities of the Yahoo Boys are having a negative impact on the government and on investment and a separate agency was required to handle the situation.

The bill to establish the National Cyber Crimes Commission is still in the National Assembly. With the president leaning on both chambers for quick passage, is the EFCC trying to prove the bill is unnecessary?

Public opinion has turned against the EFCC, as represented in a recent column in the IndependentNGOnline, called "Heroes, Yahoo Boys, and the Rest of Us". (Sorry, the article is no longer online, the author "angrymichael2004@yahoo.com" has a regular column called "Conversations of an Angry Man"). The column calls the Yahoo Boys "Criminal Eaglets", and warns the EFCC that if they continue to "deliberately overlook" the Yahoo Boys, they are going to use their relative wealth to graduate to the true houses of power.

The columnist continues "I had the impression that the EFCC may rather wait for these fraudsters to cut their teeth in politics or public administration before going after them", but he then goes on to say those who chase down and catch these crooks are the true heroes. While the President is welcoming as national heroes Nigerian boxer, Samuel Peter, and the Under 17 World Championship Nigerian soccer team, the Golden Eaglets, the columnist recommends the President proclaim those who catch cyber criminals National Heroes instead.

Whether the NCCC is formed, or whether the EFCC decides to take their cyber crime responsibilities more seriously, the benefit on the American public should be positive. For today, the EFCC are Crime Fighting Heroes. I hope it continues!

Tuesday, April 01, 2008

AKILL Convicted - Are we safer now?

Last night the BBC World Service called to ask me what I thought of the AKILL conviction. We primarily discussed that the news here should not be that AKILL is the criminal mastermind of the Internet, but that its Good News that we've managed to catch someone and get a conviction.




AKILL, Owen Thor Walker, AKA "Snow Whyte" (Whyte was his mother's maiden name), AKA "Snow Walker" (note to hackers, don't use your own name as your alias), is a troubled young man living in New Zealand. Up until his conviction he was a quiet, gifted programmer, who worked for Trio Software Development. The media is painting him to be the ring leader of a worldwide criminal enterprise which controls 1.3 Million computers and has caused $20 Million USD in damages.

There is no question Walker was brilliant. He is diagnosed with Asperger's Syndrome, a disorder in the same family as autism, characterized by very poor social interaction, and a fixation on a narrow range of intellectually challenging pursuits that often involve a high degree of repetition. His mother says he left school at age 14, largely because of problems with bullies, and completed his education via correspondence courses.

But what were the actual charges? ComputerWorld New Zealand is reporting this morning that the only damages they have charged him with are $13,000 in costs which the University of Pennsylvania incurred in recovering from a Botnet attack he launched against the TAUNET service housed at UPenn. (See ComputerWorld.nz

The Sydney Morning Herald, which ran a picture of Walker and his mother in this article of Feb 29, 2008, said:

Walker was arrested in November last year in the northern city of Hamilton as part of an international investigation into a cyber crime network accused of infiltrating 1.3 million computers and skimming millions of dollars from victims' bank accounts.


But the original story which brought AKILL into the International eye was the charges brought by the FBI under Operation Bot Roast II, which Forbes magazine mentioned like this as recently as yesterday:

The FBI's deputy assistant director of its Cyber Division, Shawn Henry, points to the November arrest of the hacker known as AKILL, an 18-year-old in New Zealand running a botnet of 50,000 computers.


The other charge that we know about AKILL is that he has been accused "by Dutch authorities" of being part of a scheme where hackers installed advertising software on computers they compromised. One of the other targets of Operation Bot Roast II was Robert Matthew Bentley, of Panama City, Florida. Bentley was convicted of his charges on March 6, 2008, according to this FBI Jacksonville Press Release.

I am saying that it is very likely that this is actually the same scheme that AKILL was tied up in, (but haven't found the proof of that yet). Bentley was accused of installing software for a scheme called "Dollar Revenue". Dollar Revenue was fined $1.54 Million USD by Dutch authorities in a scheme where hackers were paid 15/100 of a Euro for installing the adware on European computers, or 25 cents for installing the adware on American computers. (See this PC World article)

These types of revenues fall more in line with what was said during AKILL's trial, where the judge was considering whether to force Walker to pay restitution of "$8,000". New Zealand media are reporting that Walker plead guilty to infecting "at least 20,000" computers, and his bank accounts show that he had received payments of "$40,000 NZD". (See for example this New Zealand TV station's report.

What actually was the "criminal mastermind" activity that AKILL performed? He took source code for a previous botnet program and made some slight modifications to it. Detective Inspector Peter Devoy of the New Zealand police confirmed in interviews that AKILL is responsible for the "AkBot" malware. (See Security IT World's story for more.) (Devoy was also the one quoted in the original New Zealand Police press release: Waikato Police investigate cyber-crime

How was Walker caught? It looks like a good job of International Cooperation, but one lynchpin in the investigation goes back to making poor choices in friends online. Ryan Goldstein, AKA Digerati, has been a troublemaker for years. Ryan, a 21-year old student at UPenn, was a member of a hacking group called "TeamLoosh", and couldn't decide what color his hat should be.

TeamLoosh leader, rofles, basically went on a character-assassination rampage against Ryan, posting defaming photographs and emails intended to show that Ryan was a pedophile anywhere that he saw Ryan making posts. Some of these appeared in places like "governmentsecurity.org", posting links to a file named: http://www.teamloosh.com/txt/Digerati-Exposed.zip (now offline).

Ryan was angry, but having been banned from several places because of these accusations, he behaved in his typical fashion. He promised AKILL access to several "elite" hacker websites where he still had influence, if he would help him get revenge. The DDOS, intended to punish the TAUNET Internet Relay Chat servers which had banned "Digerati", was said to include 50,000 attacking computers, which were launched against TAUNET by AKILL.

The Digerati Indictment is available from the Pennsylvania US Attorney's Office. It reveals the exact nature of the payment offered to AKILL. (Quoting from page 5 of the indictment:


"I can get you some good private stuff, i can also pay you, to take taunet down...i have access to a lot of stuff you might want...www.findnot.com/servers.html - i have a legit login/pass for that, guaranteed to work through 2007 at least...undetected, unreleased bifrost (trojan) beta with 100% av (antivirus) and fw (firewall) bypass."


I'm very pleased that Ryan/Digerati and Owen/AKILL/Snow Whyte have been apprehended, but the point of what I tried to say on BBC World Service this morning was let's not make this a fishing story. We haven't landed Moby Dick here. We haven't stopped a "Criminal Mastermind". We caught a few juveniles with anger management and social problems, who made $40,000 selling hacked computers to a Dutch advertising company and attacked a University chat room because the boys there told another boy he was not their friend any more.

Its a message that International Law Enforcement Cooperation is working, at least between the Dutch, the FBI, and the New Zealanders, but we still have a long way to go before the Internet is going to be a safe place to play.

-----

Corrections Made:
Ryan Lee, ryan1918, has pointed out an error in the original version of this posting. Ryan Lee (ryan1918) is *NOT* Digerati, and should not be confused with Ryan Goldstein.

To Priest, stm, rofles, Gammarays, Zerofool2005 - thanks for the comments - send me an email. Happy to learn more and have a more accurate article.

Monday, March 31, 2008

Don't Be A Fool! Don't Click on New Storm Email!

The Storm Worm is at it again, spamming Holiday related spam to infect our machines.

Beginning around noon on March 31st, UAB's Spam Data Mine began receiving email containing a familiar pattern - a holiday related subject line, with an IP number as the URL to a website the spammer wished us to visit.

Subject lines we've seen so far include:


  • All Fools' Day
  • Gotcha! April Fool!
  • Happy April Fool's Day.
  • I am a Fool for your Love
  • Surprise! The joke's on you.
  • Today's Joke!
  • Wise Men Have Learned More from Fools...

The email bodies are just a single phrase followed by a link to a malware website:


  • All Fools' Day (link)
  • Doh! All's Fool. (link)
  • Happy April Fool's Day. (link)
  • Happy April Fools! (link)
  • I am a Fool for your Love (link)
  • Join the Laugh-A-Lot! (link)
  • Surprise! The joke's on you. (link)
  • Gotcha! April Fool!
  • Happy April Fool's Day.


Some of the spammed servers are actually still hosting a previous version of the malware, called "e-card.exe", which has been detected since March 11th. (Although there are still 13 AV companies, according to "VirusTotal.com", including Symantec, which do not detect this old version as a virus.

While some of the servers are offering an old "e-card.exe" version, most have changed to look like this:



The new executable names are "foolsday.exe" and "kickme.exe". Both are the same file, which as of this writing is 139,776 bytes in size, and has an MD5 value of:

7bc0344370ce5e6dd6e1a99e8ce347e0

I was the first to upload the new version of the virus to VirusTotal (or at least it did not say "this file has previously been analyzed", as it does when you are not the first.) At this time, coverage is very spotty. For instance, AVG, ClamAV, F-Prot, McAfee, Microsoft, NOD32, Panda, Symantec, and Sophos all say "No virus found". In fact, of the 32 antivirus products checked by VirusTotal, only 5 named this as a virus, and three of those based this on the fact that it was a "Packed Executable".

UAB researchers have found the same "FoolsDay" version of the malware on more than a dozen servers so far, and, as is usual for storm, most of these are cable modem attached PCs belonging to Americans. Sites in cities like Los Angeles, Miami were prevalent, while we did see one site in Russia (79.164.169.26), and one in Turkey (78.166.30.169) so far.

What happened to Easter?

Several people in the AV community have been wondering, "What happened to Easter?" One theory is that our criminals are Christian on some level and decided not to use the resurrection of Christ to spread viruses. The other theory (which I prefer) is that Russian Orthodox Easter isn't until April 14th, and the virus writers got caught sleeping, not remembering that we in the West don't celebrate Easter when they do.

Tuesday, March 25, 2008

Phishers Seek Google Adword Accounts

In recent months we have seen occasions where Advertisements placed with Google have actually pointed consumers to sites which would attempt to infect their computers with various forms of malware. A new Phishing Campaign discovered in the UAB Spam Data Mine may indicate this form of attack is about to get a lot worse.

Google has been very quick to identify and terminate the accounts of these malware advertisers, but what will their response be when long-time "known good" advertisers suddenly start having malware pop up in their ads?

This seems to be the focus of a new phishing campaign.

The email which comes from:

adwords-noreply@google.com

Looks like this:




Dear Google AdWords Customer!


In order to update your billing information, please sign in
to your AdWords account at https://adwords.google.com, and submit your
billing information. Your account will be reactivated as soon as you have
entered your payment details. Your ads will show immediately if you
decide to pay for clicks via credit or debit card. If you decide to pay
by direct debit, we may need to receive your signed debit authorization
before your ads start running, depending on your location. If you
choose bank transfer, your ads will show as soon as we receive your
first payment. (Payment options vary by location.)

Thank you for choosing AdWords. We look forward to providing you with
the most effective advertising available.

Sincerely,

The Google AdWords Team




The problem is that the Adwords link doesn't go to Google. In a review of fifty samples of the email collected from the UAB Spam Data Mine, fifteen counterfeit "Google AdWords" websites were identified:

http://adwords.google.com.049jfm.cn/select/Login/

http://adwords.google.com.0k8ujd.cn/select/Login/

http://adwords.google.com.adwordsgl.cn/select/Login/

http://adwords.google.com.fgreo3.cn/select/Login/

http://adwords.google.com.fnjdk.cn/select/Login/

http://adwords.google.com.fr4ck.cn/select/Login/

http://adwords.google.com.fri23.cn/select/Login/

http://adwords.google.com.fruwa0b.cn/select/Login/

http://adwords.google.com.googadw.cn/select/Login/

http://adwords.google.com.irf12.cn/select/Login/

http://adwords.google.com.kdje332.cn/select/Login/

http://adwords.google.com.ork0r.cn/select/Login/

http://adwords.google.com.r4oik.cn/select/Login/

http://adwords.google.com.session932.cn/select/Login/

http://adwords.google.com.treoo.cn/select/Login/


In what is now becoming a familiar pattern, criminals are using previous crimes to enable future crimes. In the current example of the Google Adwords phishing spam, although the "From" addresses say the email came from Google, the rest of the header makes it clear that these emails were sent from logged in Yahoo and Hotmail accounts.

Whether these accounts were created as throw away accounts for this spam campaign, or are actually accounts which were broken into and used without their owners' permission is still being investigated. The lists of yahoo and hotmail accounts have been shared with investigators, and those, as well as the counterfeit website lists, have been sent to the FBI's Digital PhishNet for further investigation.




(screen shot of http://adwords.google.com.adwordsgl.cn/select/Login/ - 24MAR08 0630AM CST)

Emails were received from Brazil, Germany, India, the Netherlands, Russia, Spain, Switzerland, Turkey, Uruguay, but also from California, Florida, Georgia, Indiana, and Massachusetts.



The UAB Spam Data Mine is operated by UAB Computer Forensics Research, a Joint Operation of the Department of Computer & Information Sciences and the Department of Justice Sciences at The University of Alabama at Birmingham.

Thursday, February 28, 2008

Smiling Bob Forfeits $33 Million

Back in 2002, USA Today had a story about Smiling Bob, the first penis enlargement program to have television advertisements. A snip from that article:


The folks who market Enzyte offer up their "Independent Customer Study," which involved mailing a questionnaire with the product to 70 men.

According to a company brochure, the most-improved volunteers reported that the length and circumference of their erect penis increased a total of four inches.

"It makes no sense medically," counters Dallas urologist Kenneth Goldberg. There's no way that increasing blood flow to the penis, as Enzyte claims to do, will actually increase its size, he says.


Well, Dr. Goldberg was proved right this week in a Cincinnati court room.

Steven Warshak is the president and owner of Berkeley Premium Nutraceuticals, the makers of "Enzyte" which you might have seen advertised by "Smiling Bob" if you watch Spike TV. It turns out that the product was sold through advertising that included fake "size increase" testimonials, fake customer satisfaction ratings, and fictitious doctors.

The jury also found that it was a common business practice to bill customers who asked for a free-trial, and to refuse to honor money-back guarantees.

The US Postal Inspection Service, the FBI's Cincinnati Field Office, the IRS, and the FDA all provided evidence in the jury trial today in the Southern District of Ohio.

Warshak was convicted of 5 counts of conspiracy to commit money laundering and various types of fraud, conspiracy to obstruct proceedings before the US Federal Trade Commission, 12 counts of mail fraud, three counts of bank fraud, and 73 counts of money laundering.

His mother, Harriet Warshak, aged 75, got 8 counts of conspiracy, bank fraud and money laundering.

His lawyer, Paul Kellogg, aged 41, was convicted of 6 counts of conspiracy including conspiracy to obstruct proceedings before the FDA and FTC, and money laundering.

Steven Pugh, a warehouse manager for Warshak, got 1 count of conspiracy to obstruct proceedings before the FDA.

TCI Media and Berkeley Premium Nutraceuticals were also charged.

The most exciting news is that the jury also found for forfeiture of $33,190,000 worth of assets, including real estate, bank accounts, cars, and insurance policies.

Although Warshak was indicted back on September 21, 2006, the trial just concluded today.

I know I saw Smiling Bob ads as recently as two weeks ago. I'll have to watch Spike TV tonight and see if they are still airing.

The FBI Press Release on the jury's verdict was released on February 26th.

Wednesday, January 16, 2008

Storm Loves You!

The Storm Worm (yes, I know its not a worm, but that's what its called!) has mutated once again and is back in the full swing of "SP" mode, or "Storm Propagation" mode.

Beginning around 3 AM on January 15th, we started seeing new spam messages attempting to infect people with the Storm malware by tricking them into viewing a dangerous website.

Not sure if this is a COMPLETE list of subjects and bodies, but I'm seeing quite a few of them. I'm guessing you can mix and match some of the nouns and adjectives in the subjects below. I'm also guessing that the subjects and bodies may be interchangable.

The big news is that the URLs are no longer using Fast Flux domain names, which means that the Storm folks have to go back to using IP addresses as URLs.

Here are some of the Subjects used by the current storm campaign.

A Is For Attitude
A Kiss So Gentle
A Rose for My Love
A Toast My Love
A Token of My Love
Come Dance with Me
Come Relax with Me
Destiny
Eternity of Your Love
Hugging My Pillow
I am Complete
I Love Thee
I Love You Soo Much
In Your Arms
Inside My Heart
Last Night
Love Remains
Magic Power of Love
Miracle of Love
Our Journey
Our Love is Free
Pages from My Heart
Sending You All My Love
Sent with Love
The Mood for Love
When Love Comes Knocking
When You Fall in Love
You... In My Dreams
You're my Dream
You're the One
Your Love has Opened


Bodies:

A Is For Attitude (URL)
A Dream is a Wish (URL)
A Toast My Love (URL)
Come Dance with Me (URL)
Eternity of Your Love (URL)
Hugging My Pillow (URL)
If Loving You (URL)
I Love Thee (URL)
I Love You Soo Much (URL)
Inside My Heart (URL)
Last Night (URL)
Our Journey (URL)
Our Love is Strong (URL)
Our Love Nest (URL)
Sending You All My Love (URL)
Sent with Love (URL)
Miracle of Love (URL)
Path We Share (URL)
The Miracle of Love (URL)
The Mood for Love (URL)
The Moon & Stars (URL)
Words in my Heart (URL)
You're In My Thoughts (URL)
Wrapped in Your Arms (URL)
You're In My Thoughts (URL)

A few IPs I've got spam for:

24.13.25.195
24.29.57.5
24.98.163.49
24.147.84.166
24.158.201.51
24.182.164.166
58.8.154.229
59.93.124.61
61.254.150.135
62.30.214.249
64.130.186.121
64.131.210.85
65.127.69.227
65.189.144.143
66.56.162.236
66.65.246.186
67.170.38.85
68.52.93.226
68.91.149.33
69.153.229.224
69.236.21.121
70.119.36.227
70.237.140.25
70.237.219.11
70.251.159.54
71.224.194.223
71.228.87.148
75.18.129.8
75.46.65.147
75.74.12.93
75.132.167.64
75.176.123.128
75.181.155.252
76.86.247.98
76.87.138.125
76.108.103.196
76.211.9.128
76.223.80.123
76.117.96.98
76.255.55.200
77.244.67.25
79.120.46.50
79.176.169.98
116.126.30.18
125.184.241.30
190.47.48.223
190.50.109.86
190.172.254.93
200.8.248.51
200.126.102.5
201.223.179.88
208.38.67.197
218.238.54.74
218.190.195.185
220.77.192.117
220.79.184.205

--

--------------

Gary Warner
Director of Research in Computer Forensics
The University of Alabama at Birmingham

Friday, January 11, 2008

New IRS Virus page taxes users

A phishing site hosts fraudulent bank pages, and an IRS look-alike virus

A new round of spam, first noticed on January 8th, has been observed by anti-phishing researchers at the University of Alabama at Birmingham. In many ways the spam is typical phishing emails, trying to trick users into visiting a fraudulent website. This family of emails uses the domains listed below to host several different phishing campaigns, each in a different subdirectory. For example:

/_mem_bin/formslogin.asp = Intelligent Finance
/default.aspx = NatWest Bank
/confirm.asp = Royal Bank of Scotland

But in addition to the traditional phishing, or bank fraud websites, which try to steal userids and passwords for online banking accounts, this spam campaign also includes a fake Internal Revenue Service website - and it isn't asking for your password!

/importantpubs/index.htm = Internal Revenue Service

After giving a warning to "Business/Corporate Treasury Managers and Accountants", the fraudulent IRS website claims to have "important recent changes to business and corporate tax laws".




Each of the links which claim to be a new document with important tax information actually is a link to a virus! With file names like:

ALL_TAXPAYERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
ESTATE_AND_TRUST_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
EXCISE_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
EXEMPT_ORG_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
FOREIGN_ISSUES_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
INDIVIDUALS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
IRA_TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE
TREASURY-MANAGERS_IRS_IMPORTANT_NOTICE_SELF-PDF.EXE

the virus attempts to trick users into opening the file. If successful, the user will think he is getting information to share his taxes with the IRS, but actually the user will begin to share their information with criminals instead!

Some of the domains hosting this virus so far:

New Sites
jan77.net
aut33.com
pid28.com
com61.net
inf32.net
sid24.net
chcpi.com
chk08.net
dll57.com
idp56.us
user94.net
Older sites
ssl--jan08.com
ssl--site.com
ssl-jan08site.com
url-sslsite.com
update-ssl.com
url-ssl.com
confirm--07jan.com
6jan-update.in
securesafesite.net
myupdatesite.net
comssl.net
secure--confirm.net
06jan--confirm.net
7jan--verify.net

REMEMBER! The IRS is not going to send you an email to warn you about new documents or ask you to login. Several major anti-virus products do not yet detect this virus! Be safe! Do not click on links sent to you in email. If you need new tax documents, visit the real website at: http://www.irs.gov/.



As we have seen in so much recent malware, the websites are being rotated to include hosting on many servers. Here are the sites which are serving the malware according to our most recent query, but there may be many many more.


83.9.136.40 - Warsaw, Poland
77.253.113.235 - Warsaw, Poland
24.93.127.106 - Columbus, Ohio
69.201.136.16 - New York, New York
128.118.145.125 - Penn State University
87.209.100.8 - Amsterdam, the Netherlands
144.162.93.16 - Dallas County Community College
80.85.229.201 - Tarnow, Poland

_-_
gary warner
https://info.cis.uab.edu/forensics/

Thursday, January 03, 2008

Ralsky: Going Down

***IMPORTANT UPDATE*** January 11, 2008!
Today Alan Ralsky was taken into custody - arrested after arriving from Germany and taken into custody.
**********************

Congratulations to First Assistant US Attorney Terrence Berg and his colleagues in Detroit for being willing to prosecute one of the top spammers, as revealed in a 41-count indictment unveiled today in Detroit!

According to the January 3, 2008 announcement by the US Department of Justice today, Scott Bradley and Judy Devenow were in court after being arrested today to hear the charges. John Hui was arrested in New York on January 2nd. The other defendants are at large and being sought. (Hint: You might check the Dominican Republic? Oh wait. Wrong spammer. That was Rizler.)

The full list of defendents is given below:

Alan M. Ralsky, 52, of West Bloomfield, Michigan

Scott K. Bradley, 46, of West Bloomfield, Michigan

Judy M. Devenow, 55, of Lansing, Michigan

John S. Bown, 47, of Poway, California

William C. Neil, 45, of Fresno, California

Anki K. Neil, 36, of Fresno, California

James E. Bragg, 39, of Queen Creek, Arizona

James E. Fite, 34, of Whittier, California

Peter Severa, age unknown, of Russia

How Wai John Hui, 49, of Vancouver, Canada and Hong Kong

Francis A. Tribble, of Los Angeles, California

Ralsky, who has his own Wikipedia page became one of the most famous spammers after an interview with the Detroit News in 2002. Pictures of his ill-gotten mansion are available at Archive.org.

The FBI raided Ralsky's home in 2005, and apparently today's indictments are the conclusion of that investigation, which DOJ says is now three years old!

While a total pricetag may never be placed on all of Ralsky's illegal profits, DOJ says he earned $3 Million just in the summer of 2005!

Ralsky has long been on the excellent Spamhaus Registry of Known Spam Offenders and was featured in the book "Spam Kings". Brian McWilliams, the author of Spam Kings, called Ralsky "the most successful spammer" in this Tech Soup Interview in 2004. Partly because he was still in business after the successful 2001 Verizon lawsuit against him. Three years later and he's still spamming!

Joel Kurth did an excellent profile on Ralsky in August of 2002 for the Detroit News, where Ralsky admits to maintaining a 150 million email address mailing list (though he points out there were 87 million email addresses that he does NOT send spam to because they unsubscribed.)

I wonder how many millions more people he's offended since 2002?

Congratulations again, Detroit, CCIPS, and thanks to the FBI, Postal Inspectors, and IRS Agents who assisted in bringing this to indictment.

Now if they can just get the other 8 co-defendants into custody . . .

Wednesday, January 02, 2008

And on January 1st EVERYBODY SPAM!

Its been a while since I've looked at a virus with a date-triggered behavior change, but that seems to be the case with the one I'm currently looking into.

I spent most of the day yesterday playing with a new spamming virus which "triggered" on January 1st to begin spamming "VPXL" male organ enlargement pills, after being dormant on a machine for almost two weeks.

I would very much appreciate any reports (which will be kept anonymous) regarding how wide-spread this virus may be, or whether anyone can identify the original point of infection.

This is currently the most widely spread spam campaign being observed by our Spam Data Mine at UAB. Its the same group that has been previously using the brands "King Replica" for counterfeit watches and "EliteHerbal" for pills.

The machine I was studying became infected on December 17th, after a "drive-by infection" sent it to the website "www.injectpanel.com" where it hit a file called "/us/ret.php", which caused it to download "index[1].exe". (We are working to get this site shutdown already).

Infected machines will be easily identified (now that Jan 1 has passed), by an enormous number of outbound SMTP connections.

Infected machines will probably have a large number of files in their root directory ending in ".tmp". Some of these files may be 42,496 bytes in size, which are copies of the .exe, while others will be 0 bytes in size.

Infected machines ARE rootkitted, with a couple files of true interest:
c:\windows\system32\wsnpoem\audio.dll
c:\windows\system32\wsnpoem\video.dll

(I found these with "RootKit Revealer", a Most Useful Tool!)

Infected machines will contact on each boot "www.injectpanel.com", and may also connect on each boot "www.botsys.net".

AV vendor PREVX had received 11 copies of this virus since December 18th, most commonly called "index[1].exe".

VirusTotal received its first copy on December 30th, and had a 43% detection. It was NOT detected by ClamAV, F-Prot, McAfee, NOD, Sunbelt, or Symantec. As of Jan 1, it showed 53% detection. (17 of 32 AV products could detect the virus.)

The copy I was dealing with had the MD5:

b7f085411871026218cc30b4a6c0363e

Other secondary infections have been seen being "dropped" from injectpanel.com. Including "Nurech" (AKA "Chepvil"), which also showed only a 13 of 32 detection rate on Jan 1.

Nurech places a large number of files in the Windows\System32 directory.
Some example names were:
imapi.exe
mnmsrvc.exe
msdtc.exe
netdde.exe
alg.exe.tmp
cisvc.exe.tmp

These will be copied to a "numbered" temp file, such as:

124671.exe
147359.exe

which can be found in memory and in the C:\Windows\Temp\ directory.

The file size of these files is "8,704".

MD5 for Nurech = 337915d40c893b64ef57fe3866dadb8f

If anyone else is experiencing these viruses, I'd love to learn any more details you might be able to share, but most importantly I'm trying to gage how widespread the infection is.

Windows XP Machines infected with Nurech may demonstrate the characteristic of "falling off" networks, getting stuck in an "acquiring network device" state. (Which may be an overwhelmed TCP stack from the many many copies of "svchost" that are trying to drive TCP connections.)

Thanks for any help!

Gary Warner
Director of Research in Computer Forensics
http://www.cis.uab.edu/forensics/

Wednesday, December 26, 2007

A Stormy Christmas and a Botnet New Year

The newest round of Storm Worm Propagation emails has come out, and its
again, largely undetected malware.

The main URLs we are seeing at this point are:

uhavepostcard.com <== (majority use this one)

happycards2008.com <== (all of these dated today)

There are more than 100 samples using these two URLs so far. The first
was received December 24th at 12:10 PM. The most recent was received
just moments ago.

- -------
Subjects include:

A fresh new year
A fresh new year...
As you embrace another new year
Blasting new year
Happy 2008 To You!
Happy 2008!
Happy New Year To (emailhere)
Happy New Year To You!
Happy New Year!
It's the new Year
Joyous new year
Lots of greetings on new year
Message for new year
New Hope and New Beginnings...
New Year Ecard
New Year Postcard
New Year wishes for you
Opportunities for the new year
Wishes for the new year

---------

A scan of the current malware on VirusTotal just now showed a 37.5%
detection rate. The version scanned was 142,337 bytes and had the MD5
checksum of:

44dc7307c81eb9fe0a0cf9147a9932ef

Notable non-detections include F-Prot, Kaspersky, McAfee, and Sophos

Those detecting named the malware as follows:

AntiVir = TR/Rootkit.Gen
Avast = Win32:Zhelatin-ASX
BitDefender = DeepScan:Generic.Malware.FMH@mmign.55A134E9
ClamAV = Trojan.Zhelatin
DrWeb = Trojan.Spambot.2386
Fortinet = W32/Tibs.G@mm
Microsoft = Backdoor:WinNT/Nuwar.B!sys
NOD32v2 = probably a variant of Win32/Fuclip
Panda = suspicious file
Prevx1 = Stormy:Worm-All Variants
Symantec = Trojan.Peacomm
Webwasher = Trojan.Rootkit.Gen

PREVX.com says this version was first seen on December 26th and has been
reported by one user in Spain. (That's where VirusTotal is, so I guess
that's me and others using VirusTotal.)

A Christmas version of the Storm Worm Propagation email may still be lurking in in-boxes as employees return from their holiday vacations. The Christmas version primarily used the malware domain:

merrychristmasdude.com

and used these subject lines. Visiting those sites now actually downloads the same "happy-2008.exe" malware as the New Year propagation uses, since these are in reality the same infected computers acting as the web hosts.

The Christmas subject lines were:

Christmas Email
Cold Winter Nights
Feel the Holiday Spirit
Find Some Christmas Tail
Ho Ho Ho.s
How.s It Goin
I love this Carol!
Jingle Bells, Jingle Bells
Looking for something hot this Christmas
Merry Christmas From your Secret Santa
Merry Christmas To All
Mrs. Clause
Mrs. Clause Is Out Tonight!
Santa Said, HO HO HO
Seasons Greetings
The Perfect Christmas
The Twelve Girls of Christmas
Time for a little Christmas Cheer.
Warm Up this Christmas
Your Secret Santa

The domain names for all of these are set up in a "round robin". For instance, I use "nslookup" to query "merrychristmasdude.com" ten times in a row and get the following list of IP replies:

66.78.160.196
24.126.208.180
86.125.107.157
70.249.186.39
79.172.83.168
91.142.197.135
62.43.161.233
78.60.109.65
91.122.89.214
75.58.60.145

A much longer list of IP addresses which answer queries for all three of these domain names:

12.207.192.66
12.215.209.21
12.219.197.139
12.227.173.1
24.165.167.150
24.181.224.249
24.181.42.5
24.182.40.236
24.2.46.250
24.210.99.223
24.3.160.88
24.95.77.206
58.226.226.6
58.8.20.129
59.112.81.137
59.113.187.86
59.12.125.252
59.15.71.112
59.3.40.145
59.86.244.147
59.92.78.2
59.93.39.233
59.95.191.39
60.249.4.119
60.50.100.42
60.53.25.73
60.56.115.109
60.9.222.137
61.15.254.115
61.32.177.59
61.72.147.153
61.80.150.87
62.65.232.246
64.85.228.164
65.189.233.73
65.31.39.88
66.142.52.23
66.31.113.211
67.164.126.186
67.173.35.121
67.177.191.148
67.181.90.28
67.186.43.176
67.187.30.81
68.127.51.120
68.167.71.243
68.187.46.125
68.204.186.99
68.248.237.55
68.54.157.173
68.54.234.64
68.63.133.158
68.79.7.249
68.80.244.129
68.81.122.156
68.81.195.121
69.154.137.176
69.183.216.161
69.215.175.83
69.225.12.176
69.226.25.20
69.247.40.180
69.248.212.75
69.254.83.191
70.115.222.172
70.126.163.174
70.243.43.6
70.245.14.188
70.249.186.39
71.200.198.181
71.205.208.104
71.224.88.232
71.227.249.98
71.230.219.209
71.230.66.163
71.237.134.222
71.86.54.0
71.96.13.37
72.40.18.255
72.48.192.221
72.8.101.213
74.128.121.44
74.138.172.43
74.164.251.210
74.75.193.213
75.131.212.194
75.132.160.97
75.21.75.238
75.35.110.9
75.35.252.137
75.37.39.88
75.50.232.119
75.61.64.23
75.68.231.167
75.73.216.43
75.85.190.206
76.107.42.125
76.111.115.55
76.119.119.58
76.15.46.122
76.171.99.77
76.173.57.101
76.212.92.117
76.22.76.57
76.229.114.65
76.243.202.32
76.25.147.99
76.254.139.102
76.65.181.160
76.68.144.93
77.41.47.214
77.48.16.49
77.57.127.78
77.99.143.61
78.107.182.172
78.107.190.69
78.92.91.186
79.112.4.123
79.120.35.238
79.120.56.38
79.126.167.63
79.139.178.64
79.165.162.240
79.182.0.73
80.73.89.69
81.190.78.83
81.210.133.54
82.1.108.104
82.181.41.160
82.233.232.162
82.79.129.214
83.5.77.234
83.54.12.240
84.10.43.106
84.126.102.227
84.31.89.195
85.180.66.14
86.102.1.205
86.125.170.161
86.61.66.60
86.63.107.2
87.207.117.102
87.8.161.149
88.156.9.155
88.164.68.15
89.110.51.47
89.137.201.205
89.161.22.219
89.178.170.110
89.20.119.182
89.215.180.33
89.228.40.58
89.36.102.75
89.38.163.176
90.150.126.235
90.150.215.50
90.157.92.141
91.106.18.142
91.122.147.67
91.122.19.127
91.18.246.67
98.194.162.228
98.196.29.67
99.145.19.221
99.241.144.189
117.199.240.218
121.1.85.140
121.124.15.53
121.146.205.123
121.150.127.150
121.158.220.126
121.162.87.237
121.165.21.31
121.172.10.95
121.173.45.111
121.179.107.71
121.246.163.37
121.246.86.244
121.247.143.131
121.247.165.149
121.247.66.110
121.96.253.35
122.164.35.171
122.202.44.89
122.32.53.35
122.36.84.38
122.50.173.172
122.99.16.4
123.201.0.167
123.202.81.199
123.203.20.137
123.215.177.241
123.236.114.63
124.120.35.98
124.120.36.238
124.125.116.171
124.199.33.113
124.244.198.114
124.82.112.191
125.137.205.157
125.208.107.18
125.233.65.153
125.235.36.97
125.24.82.14
168.243.219.228
190.17.101.223
190.21.9.139
195.189.153.21
196.217.102.238
200.84.241.161
200.94.163.191
201.172.192.141
201.222.110.245
201.231.140.173
201.241.57.55
201.255.181.193
201.27.179.128
203.223.220.24
203.255.10.96
206.45.91.55
209.102.185.215
210.105.165.204
210.109.244.10
211.109.96.223
211.195.3.79
211.201.18.155
211.204.48.194
211.54.167.69
213.169.180.110
217.123.175.129
218.156.143.96
218.174.73.42
220.118.185.247
220.121.81.72
220.19.166.13
220.225.184.83
220.76.90.93
220.78.225.208
221.147.22.23
222.114.18.22
222.238.245.88
222.98.228.236

Good luck, and thanks for any help terminating the three domain names in question:


Merry Christmas and Happy New Year, CyberCrime Fighters . . .

_-_
gary warner
http://www.cis.uab.edu/forensics/