Tuesday, August 12, 2008

Anti-Virus Products Still Fail on Fresh Viruses

Today was our monthly meeting of the Birmingham InfraGard. At the meeting we talked about our new InfraGard-wide initiative to investigate malware together. If you're an InfraGard member and want more details, please let me know.

Why is it worth focusing on new malware again? Because the truth is the criminals are innovating faster than the Anti-Virus vendors can keep up with. Its true that some of the AV companies have really fast signature cycles, but its also true that their methodology is to write new signatures for viruses that are encountered in the wild.

The problem with that, of course, is that once the virus is in the wild, their customers may encounter it before they do. Face it. Someone has to report that the thing exists!

Here's a few examples from today's spam at the UAB Spam Data Mine.

Example One: Colonial Bank Certificate Spam



The spam message comes in saying:


Colonial Bank Tech Support issued important security update for business accounts. Updated certificate packages that fix various security problems are now available in our Update Center>>

All Colonial Bank users should upgrade to this updated package, which contains ssl multi-protection.

Sincerely,
Colonial Bank Customer Service Department


The website, eg3x.com, hosted in the Ukraine, on IP address 83.170.242.174, which looks like this:



drops an .exe file to visitors, named "certificate_230943772836234.exe"

The malware has an MD5 value of 99c074f671f8e8af5c85ca908d106605 and is 30,208 bytes in size.

As of this timestamp, only FIVE OF THIRTY-SIX Anti-virus products provide protection from this virus. So, a user with current AV protection will be told "no virus found" if they check to see whether this malware is a virus before deciding if they should run it.



VirusTotal detection (5/36)

AVG = Win32/Heur
CAT-QuickHeal - DNAScan
eSafe = Suspicious File
Microsoft = VirTool:Win32/Obfuscator.BO
Webwasher-Gateway = Virus.Win32.FileInfector.gen (suspicious)

All others = No Virus Found

Example Two: UPS Tracking Malware



We've received several copies of this malware today, and several queries from fellow InfraGard members, who reported that their Anti-Virus product had not detected it. This malware arrives as an email attachment. It claims to be From: United Parcel Service, and it has a subject line intended to be a Tracking Number, such as "Tracking N_8513200376" or "Tracking N_ 0294544032".

The body of the email is:


Unfortunately we were not able to deliver postal package you sent on July the 21st in time because the recipient’s address is not correct.

Please print out the invoice copy attached and collect the package at our office

Your UPS


We've seen two attachment names so far:

WW_671282.zip ==> contains WW_671282.exe
and
WW2_ASH182.zip ==> contains WW2_ASH182.exe

While the former file was already detected by 22 of the 36 anti-virus engines at VirusTotal, the latter file was only detected by 7 of 36 when we first uploaded it, although at this timestamp the detection is now 8 of 36:



Example Three: CNN Alerts: Breaking News





Despite the fact that these spam messages have been going on for several days now, each day the malware which is being CURRENTLY SPAMMED is largely undetectable by most anti-virus products. And we're still seeing A LOT OF THIS SPAM. Look at the timestamps here:



In this case, we take as an example, the spammed URL:

http://us-spine.com/update.html

and let it give us a malware executable: adobe_flash.exe

The currently spammed version of this malware is undetectable by 22 anti-virus products including F-Prot, F-Secure, McAfee, Panda, Symantec, and Trend.



Bottom line: If you are in charge of anti-virus for your corporate environment, it is time to learn the Study of Malware and stop trusting anti-virus products. They are important. You should have them. You should update them regularly (at LEAST daily!) But you should not rely on them to tell you if an executable is "safe".

Monday, August 11, 2008

iTunes Store Phish

In the middle of my 5,000 copies of the newest CNN Alert spam, I had an email from iTunes. I have to tell you, it made me mad. I assumed it meant that my children had been shopping on my iTunes account, and had done something wrong with my account. (love you, K-Dub! love you, Zach!)

And that's why I thought it worth writing about. We hear so much about Phishing, and its almost always described as "a counterfeit bank website", and then usually the definition is extended to say "mumblemumble Paypal mumblemumble eBay", since they don't really fit in to the "banking" concept of Phishing.

The subject of the email was "Important: Billing Problem" and the From: address was "iTunes Store".

The punchline of the email was:


We were unable to process your most recent payment. Did you recently change your bank, phone number or credit card?

To ensure that your service is not interrupted, please update your billing information today by clicking here , After a few clicks, just verify the information you entered is correct.




The "click here" part pointed to this website:

http://www.rofilme.net/m_subtitrari/store.apple.com/us/

which does a pretty good job of looking like an Apple Store, doesn't it?



Clearly this particular criminal is relying on the fact that we aren't going to suspect a non-banking site of being phishing. More evidence? The same site where this phishing site is hosted, "rofilme.net", was used last week as an AOL Billing phish, with the address:

http://www.rofilme.net/m_subtitrari/my.screename.aol.com/_cqr/login/sitedomain/bill.aol.com/sslsecure/update/

Its a rather complex phish . . . the Apple Store phish actually runs a "verify.php" file on another server, http://www.satc.net/gallery/washington_d.c./verify.php, which stores the stolen data in a .txt file. The first set of credentials was given up right at six hours ago, and so far there are 44 plausible sets of identities in the file. Not a huge harvest, but enough to cause a headache for at least 44 people.

The format of the harvested identities text file looks like this:

-----------------------------------
FirstName : Txxxx
Last name : Bxxxx
Address : 9xxxxxx
City : Sxxxxx
State : Tx
Zipcode : 79549
Country : US
PhoneNumber Ext : 3xx
Phone : 5xx.xxxx
Card number : 40034xxxxxxxxxx
Expiry month : January
Expiry year : 11
CVV2 : xxx
Mother's maiden name : bxxxxx
SSN : 462xxxxxx
Birth day : 24
Birth year : 1951
Birth month : 09
Email : txxxxx@yahoo.com
Password : xxxxx
Mon Aug 11, 2008 2:22 pm
6x.1xx.2xx.6x
------------------------------

As you can see, I gave some "xxxx" to protect this person's identity.

So, just a reminder, gentle reader . . . when someone wants your identity, it doesn't have to be a BANK site to be a PHISH.

Saturday, August 09, 2008

The UAB Spam Data Mine: Looking at Malware Sites

(update: report link URL at end has been corrected...)

In the UAB Computer Forensics program, we have students who are studying the basics of cybercrime, but we also have students who are Malware Researchers, Phishing Researchers, and of course Spam Researchers. Much of our research is enabled by our main research project, the UAB Spam Data Mine.

For some of you, the first glimpse you had of the power of the UAB Spam Data Mine was in last Friday's entry, Linking All the News Spam Together. In that example, we made a recursive SQL query, where we asked "what other spam was sent by the computers that sent this spam?" That's one of the most basic queries we can do. Give us a spam "subject", and we can find all the IPs that sent that subject, and then all of the other emails that those same IPs sent. We can do much cooler things than that. I'll try to tell you about one each week.

In today's post we'll demonstrate one of the ways the Malware team can benefit from queries from the UAB Spam Data Mine.

On a mailing list (Gar waves to Paul), someone mentioned some new malware that was advertised by a spam message with the subject "Shocking porno dvd Carmen Electra". The URL in that spam message pointed to a website ending in "index1.php".

When you visit the website, it downloaded a virus with the name: video312f3sxxx.exe

We knew that we had seen lots of spam with "index1.php", but wondered how many different versions of the virus we could still find "live" on the Internet.

This wasn't intended to be an exhaustive search, so we didn't worry about trying to prove we had every single email in this cluster -- although the spam clustering algorithms are advancing to the point that that is very possible. For today we just did another very simple query.

"Let's find all of the spam where the subject had the word "Shocking" and that contained a URL ending in "index1.php"

-------------
select a.message_id, a.subject, a.sender_ip, b.machine, b.path
from spam a, spam_link b
where (a.message_id = b.message_id)
and subject like '%hocking%' and path like '%/index1.php%';
-------------

This resulted in more than 1600 emails. Changing the query up, we added "group by machine" to make a list of the 261 unique websites which had been advertised as hosting an "index1.php" file.

That list got passed off to a simple "wget" script, which fetched the content of index1.php, following any links that it sent us to, as long as they were on the same site.

Of the 261 websites which had been advertised by this spam, 71 of them were still "live", and gave us 578 different files. In most cases, here's how the fetch worked:

Pulling "index1.php" would send us to a webpage, often named either "index6.html" or "index12.html". That web page would have an Animated GIF file, which, if clicked on, would download the actual virus, as an ".exe" file.

Here are the five animated .gifs which were found on the different versions of the websites:











In most cases, while that visible activity was going on, more stealthy attempts to infect the machine were also underway. In most cases this took the form of an "iframe" which stored the same .exe file on the visitors machine through an encoded javascript program. Visitors who came to the website using Internet Explorer, and who allow JavaScript to run by default on all websites, were infected regardless of whether they clicked on the image.

The next step was to find out how many virus "versions" we were dealing with, and whether they were well known or not. We ended up with 40 different MD5 values, and 40 different filenames:

archive.exe
free_vid.exe
hot_video.exe
hot_video5672.exe
news_usama_video.exe
secret_archive.exe
secret_shok_video.exe
usama_video.exe
video.exe
video_porn.exe
video_shok765.exe
video_shoking.exe
video_usama.exe
video_xxx7546.exe
video135443.exe
video23574fr41.exe
video25653.exe
video2575fr78.exe
video345895gt54.exe
video3468ht34.exe
video354rporn.exe
video37752hq35.exe
video43242xxx.exe
video4324g32.exe
video432654xd.exe
video4326xx.exe
video435_porn.exe
video49825m6.exe
video623porn.exe
video654_ew.exe
video78475fd6.exe
video8658er87.exe
videofilm.exe
videokl_ds4.exe
videonjk568.exe
videoou_8777.exe
videoporn2325.exe
videoPorn3951.exe
videoXXX4579.exe
videoXXX76s3545.exe
videoxxx787.exe

In this PDF table of the websites we reviewed, 08aug08.report.pdf, we list all 74 live websites from which we received malware in today's check of the 261 sites. The filename, MD5, size, and the date of the exe files is given.

The malware sites are everywhere . . . Aregntina, Brazil, Canada, the Czech Republic, Denmark, France, Germany, Hong Kong, Italy, Mexico, Poland, Portugal, Romania, Spain, Switzerland, Turkey, Venezuela. (See IP WHOIS spreadsheet, or Domain WHOIS list.)

The malware from these sites will now be "unpacked" and analyzed by the malware researchers. They've already looked at many of these pieces of malware. For example, the "news_usama_video.exe" that they looked at last week had several nice clues in it, such as the IP address of the Command & Control site for the malware, the format of the communications to and from that C&C, and an internal version number. The malware we were looking at two weeks ago in this family labeled itself "1.0.4" internally. The version last week called itself "1.0.5". Several of the earlier versions were all proven to be related by the fact that they all pointed to the same Command & Control even though their MD5 value was different.

Spam => Data Mine => Reports => WGets => Unpacking => Analysis

Friday, August 08, 2008

TJX Update: The San Diego Indictments

As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust".

There were actually four separate indictments filed, and now that we have the indictments, we'll hopefully be able to learn more about some of these more mysterious criminals.

In the first indictment, the UNITED STATES OF AMERICA v. MAKSYM YASTREMSKIY

the charges are:

18 USC Section 1029(a)(2), and (c)(1)(A)(i) - Trafficking in Unauthorized Access Devices
18 USC Sections 1028(a)(7) and (b)(1)(D) - Identity Theft
18 USC Section 1028A(a)(1) - Aggravated Identity Theft
18 USC Section 1956(h) - Conspiracy to Launder Monetary Instruments
18 USC Section 982 - Criminal Forfeiture

As we saw in the first part of today's post, TJX Update: The Boston Indictments, when Albert Gonzalez and friends didn't know how to turn their stolen credit cards into money, they reached out to Eastern Europe for advice. When they didn't know how to crack their PINs, they reached out to Eastern Europe for advice. When they didn't know how to make sure their sniffer programs would remain undetected, they reached out to Eastern Europe for advice.

Much of that time, they were reaching out to Maksym Yastremskiy.

From May 31, 2005 until May 30, 2006, Yastremskiy, operating in the Southern District of California and elsewhere, sold approximately 155,000 credit card numbers "with intent to defraud", for $98,000 in cash.

Maskym ran a website which was his primary mechanism for selling cards. Prices varied by the bulk, and quantities of cards were advertised on the website (presumably by himself and others) in batches from ten or a dozen, up to several hundred thousand cards or even several million.

The general practice was that Maksym would be contacted by email or chat and the subject of how to make the purchase would be discussed. Unknown buyers would wire a cash payment, usually with Western Union, to Yastremskiy or an accomlpice. Trusted purchasers were allowed to wire directly into Yastremskiy's various bank accounts.
Once the funds transfer was complete, the purchaser would be granted the requested number and type of cards through the website. The indictment gives examples such as "10 Citibank Visa (Gold)" or "20 Royal Bank of Hong Kong Master Card (Platinum)" or "12 Chase Visa (Classic)".

Maksym's charges do not specifically reference Gonzalez from Miami, nor do they name the source of the cards.

Forfeiture claim is made to property derived from many payments, including but not limited to:

$846,762.18 in E-Gold accounts
$ 87,517.36 in Parex Bank account
$3,781,436.36 in an Asia Universal Bank account
$4,862,884.96 in Western Union money transfers
$1,931,047 in US currency




The second indictment is the UNITED STATES OF AMERICA v. ALEKSANDR SUVOROV, aka Lifestyle, aka JohnnyHell, aka Dantist.

The charges brought against Suvorov are:

18 USC Section 1029(b)(2) - Conspiracy to Possess Unauthorized Access Devices and to Traffic Unauthorized Access Devices
18 USC Section 1029(a)(3) and (c)(1)(A)(i) - Possession of Unauthorized Access Devices
18 USC Section 1029(a)(2) and (c)(1)(A)(i) - Trafficking in Unauthorized Access Devices
18 USC Section 1028(a)(7) and (b)(1)(D) - Identity Theft
18 USC Section 1028A(a)(1) - Aggravated Identity Theft
18 USC Sec 2 - Aiding and Abetting

Suvorov's Conspiracy charges name Maksym as his co-conspirator (however Maksym was not charged with Conspiracy in his indictment).

The Overt Acts in the conspiracy are:

On February 10, 2006, Maksym Yastremskiy agreed to sell 160,000 unauthorized credit card account numbers to a purchaser located in San Diego, California.

On February 20, 2006, Sukorov provided Maksym (AKA Maksik) with 160,000 unauthorized credit card account numbers for purpose of re-sale.

On March 17, 2006, in exchange for $10,000 in US Currency, Maksik transferred the first 6,798 of the negotiated 160,000 unauthorized credit cards.

Suvorov received occasional payments from Maksik from May 2, 2005 until May 1, 2006 as the cards were slowly bought and the funds were received back. Over the course of this time, Suvorov received from Maksik approximately $75,000.




In the third indictment, The UNITED STATES OF AMERICA has three Defendants:

SERGEY ALEXANDROVICH PAVLOVICH, aka Panther, aka Diplomaticos, aka PoL1Ce Dog, aka Fallen Angel, aka Panther757

DZMITRY VALERYEVICH BURAK, aka Leon, aka Graph, aka Wolf

SERGEY VALERYEVICH STORCHAK, aka Fidel

The only charge against these three is:

18 USC Section 1029(b)(2) Conspiracy to Traffic Unauthorized Access Devices

This is such a disappointment after the charges against the Boston crowd and the first two here! What are they charged with?

On May 11, 2007 - Sergey Pavlovich negotiated the sale of 90 stolen credit cards to a purchaser in the Southern District of California.

On September 11, 2006 - Dzmitry Valeryevich Burak negotiated the sale of 30 stolen credit cards to a purchaser in the Southern District of California.

On October 10, 2007 - Sergey Valeryevich Storchak agreed to sell 64 stolen credit cards to a purchaser in the Southern District of California.

Ummmm... Big whoop.




In the fourth indictment, the UNITED STATES OF AMERICA also charges three defendants:

HUNG-MING CHIU, aka Slimbady, aka Tomaliki, aka B&Q, aka Betrmb

ZHI ZHI WANG, aka Akihikotobe, aka Attorney

FNU LNU (for those of you who don't speak Chinese OR Indictmentese, that's First Name Unknown Last Name Unknown), aka Delpiero

The charges brought are:

18 USC Section 1029(b)(2) - Conspiracy to Possess Unauthorized Access Devices, to Traffic Counterfeit Access Devices, and to Traffic Unauthorized Access Devices
18 USC Section 1029(a)(2) and (c)(1)(A)(i) - Trafficking in Unauthorized Access Devices
18 USC Section 1029(a)(1) and (c)(1)(A)(i) - Trafficking in Counterfeit Access Devices
18 USC Section 1028A(a)(1) - Aggravated Identity Theft
18 USC Section 2 - Aiding and Abetting

The three defendants are charged with entering into conspiracy with Maksik (Maksym Yastremskiy) and JonnyHell (that's the third way I've seen that spelled in official documents this week!) (Aleksandr Suvorov).

The Overt Acts in their conspiracy include:

On July 30, 2005 - Zhi Zhi Wang sold 100 counterfeit credit card blanks to a purchaser located in the Southern District of California. The order was later filled by Hung-Ming Chiu.

On July 30, 2005 - Zhi Zhi Wang sold 100 counterfeit credit card blanks to a purchaser located in the Southern District of California. The order was subsequently filled by Hung-Ming Chiu.

On September 17, 2005 - Hung-Ming Chiu discussed with Maksym "Maksik" Yastremskiy the creation of a website that could be used to distribute stolen credit card accounts. Maksik agreed that he would be the website's provider of stolen credit card account information.

On September 28, 2007 - FNU LNU, aka Delpiero, sold 100 unauthorized access devices to a purchaser in the Southern District of California.

From September 17, 2004 until September 16, 2005, Hung-Ming sold approximately 162 credit card account numbers that had been stolen or obtained with intent to defraud, for approximately $4,500 in cash.

From September 17, 2005 until September 16, 2006, he did it again, with 172 cards for which he received $5,000.

From April 18, 2007 until April 17, 2008, Delpiero sold about 350 credit card account numbers for about $4,500.

They also sold "real looking" (or counterfeit) blank plastic.



OK, we'll pause here for a moment to reflect on how ludicrous it sounds to have a single press release naming people with $20 Million in forfeiture in the same case with people who only made $4,500. This is the part where we interject that these are real bad guys doing world-wide crime! The problem is that we have to have jurisdiction, in this case in the Southern District of California, for whatever we charge them with. Before you get terribly disillusioned about the nature of these "small fish" based on the indictments, let's investigate the Affidavit of Special Agent Ryan Knisley of the United State Secret Service.



SA Knisley has been a Secret Service Agent since August 7, 2006. What we don't see in the indictments themselves is that "Pavlovich" runs a HUGE Credit card trading service known as "Dumps Market" (www.dumpsmarket.net, at the time of the indictment.)

Burak had screwed up and found himself with a Yahoo! address which was searched by the US Secret Service. As a result of that search, he was found to be trading "BIN lists" (Bank Identification Numbers) and stolen credit card numbers with Storchak.

Storchak's accounts were also searched, and it was found that the credit card numbers traded between these two actually had been used for real dollar losses of $7,000,000!

Other evidence pointed to email accounts at a site called "safe-mail". Commonly held by the criminals to be beyond the stretch of US Law Enforcement. Through the Mutual Legal Assistance Treaty, email accounts at "SAFe-mail", which resides in Israel, were also searched, and the results shared with the USSS. In those mails
more details were revealed indicating that Pavlovich was the source of many of the stolen credit cards.

Pavlovich was running DumpsMarket in Belarus. Who also cooperates with US Law Enforcement. The Belarus law enforcment folks seized Pavlovich's hard drive, made a copy, and sent it to the US Secret Service. Pavlovich's hard drive contained more than 10,000 stolen credit cards, and photographs of himself spending time with Burak and Storchak in various social settings.

So, while the actual charges brought here seem small, we MUST make them stick. This is a $7 Million Bad Guy of the variety who needs to go to jail.

Three Cheers to Southern California for taking what data they could own and deciding to press forward with it!

While it is not specifically laid out in the documents to which I have access, it is my strong belief that the Chinese defendants are in a similar situation. The small numbers in Southern California should not be seen as a measure of their insignificance as criminals, but rather as a sign that when you spread multi-million dollar crime around the entire globe, its hard to find one small set of contiguous ZIP Codes that had many losses.

Again, Three Cheers to the US Secret Service, and the US Attorney of the Southern District of California!

(All Four Indictments, and the Affadavit are included in a single 34 page PDF)

TJX Update: The Boston Indictments

The Boston indictments are now public and have quite a few more facts for us, and I'm so excited that I've just received the first of the San Diego indictments from their most helpful press officer!

I'm going to run this in two parts. Boston first, and then San Diego.

An incomplete story was painted by the earliest press releases, which lead the media to quickly jump on the fact that Gonzalez was a wardriver, and TJX and the other victim companies had sloppy wireless security. True, but not a complete picture.

We'll start by looking at what else we can learn from the indictments that are now available in Boston.

What's in a name? We'll start with Albert Gonzalez's A/K/A's:

cumbajohny
cj
UIN 201679996
UIN 476747
k1ngchilli
stanozololz

Unfortunately, that genius of blackhat journalism, Kevin Poulson, has beat us to the punch with this one in his Wired Blog, but what a great story it is. You'll recall in our previous blog post on this subject, TJX Reminder: We Will Arrest You, and We Will Send You To Jail, we mentioned that Albert Gonzalez was a US Secret Service Informant. Now that we know his alias, CumbaJohny, we see that Albert was the snitch for Operation Firewall, the Secret Service case that lead to the arrests of 28 members of the ShadowCrew back in October of 2004. CumbaJohny, now re-handled as Segvec, now gets to feel what its like to be on the receiving end of one of these seizures.

The Violations that Segvec faces are:

18 USC section 371 Conspiracy
18 USC section 1030(a)(5)(A)(i)Damage to Computer Systems
18 USC section 1343 Wire Fraud
18 USC section 1029(a)(3) Access Device Fraud
18 USC section 1029(c)(1)(C), 982(a)(2)(B),981(a)(1)(C) Criminal Forfeiture
28 USC section 2461(c) Criminal Forfeiture

Here's the way the Conspiracy charges stack up. First we have to establish what they conspired to do. The indictments lists "the objects of the conspiracy" this way:


a. Exploit vulnerabilities in wireless computer networks used at retail store locations

b. Exploit vulnerabilities used to manage large business databases

c. Gain unauthorized access to computer networks processing and storing debit and credit card transactions and other valuable data for major corporate retailers.

d. Download and steal from computer networks operated by major corporate retailers over 40 million pieces of card holders' track 2 data - the information found on the magnetic stripes of credit and debit cards, which is read by ATMs and credit card readers - as well as internal accounts and proprietary files

e. Sell stolen track 2 data in Eastern Europe, the United States and elsewhere to others for fraudulent use

f. "Cash out" stolen track 2 data by encoding the data on the magnetic stripes of blank payment cards and using these cards to obtain tens of thousands of dollars at a time from banks' ATMs

g. Conceal and launder the illegal proceeds through anonymous web currencies in the United States and Russia, and offshore bank accounts in Latvia

h. Repatriate portions of the illegal proceeds through web currency converters and ATM cards linked to Eastern European banks.


The Gonzalez indictment tells quite a bit more about how they moved from WarDriving to much greater exploits.

First, Gonzalez, Toey, and Scott went wardriving around Miami, in commercial areas such as the area around U.S. 1, identifying vulnerable wireless networks. They targeted large retailers, "including, but not limited to" BJ's Wholesale Club, DSW, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, and TJX.

After infiltrating their networks, they began locating and stealing sensitive files and data, including credit card numbers.

At this point, they are just punks. This type of break-in is a dime a dozen. But then they took it further. It says they went on to install sniffer programs, monitoring and stealing password and account information as well as track 2 data.

The conspiracy broadened as they had to bring in new associates to help with decrypting the encrypted PIN numbers on their tens of millions of Track 2 reads.

The stolen data was stored on servers in Latvia, the Ukraine, and the United States, and encrypted to prevent access by others. From there, the data was sold in "dumps", cashed out, and the money was redistributed, using webmoney, ATMs, and in some cases even mailing express packages full of cash to drop boxes!

Regarding their technical skills, custom SQL injection attacks were developed to take on particularly desirable web sites. The attacks were mounted against a variety of database-driven web sites to find additional track 2 data, internal accounts, and files of large businesses.

Regarding the level of Gonzalez' conspiracy -- he used sensitive law enforcement information, which he obtained by his "cooperation" with the US Secret Service, to alert his conspirators and make sure they would not be identified and arrested.


Some particular examples illustrate the dates and players:

In 2003, Gonzalez and Scott use wireless access to steal track 2 data at BJ's Wholesale Club.

In 2004, Scott and "J.J." gain unauthorized access to the wireless network of the OfficeMax on 109th Street and US 1 in Miami, locating and downloading encrypted PINs.

Scott and J.J., unable to decrypt the PINs, passed the data to Gonzalez, who located and engaged another co-conspirator who had the necessary decryption abilities.

On July 12 and 18th, 2005, Scott accessed TJX's Marshalls department stores in Miami, using the wireless network there to compromise servers at TJX's server farm in Framingham, Massachusetts.

On September 15-16, Scott accessed the Framingham servers and retrieved the data which their sniffers had been collecting.

Beginning on May 14-15, 2006, Scott installed and configured a VPN connection between one of the TJX card transaction servers and a server obtained by Gonzalez.

On May 15, 2006, Gonzalez used ICQ to ask Yastremskiy for help in obtaining an undetectable sniffer program. Beginning on May 15 and lasting through May 20th, they established their new undetectable sniffer.

The new sniffer's data was retrieved on many dates, including October 27 and December 18, 2006.

Beginning in August of 2007, Gonzalez invited Toey to move to Miami. In exchange for cash payments and free rent, Toey began to develop an Internet-based attack on the servers at "Forever 21", with the goal of obtaining financial data.

Prior to moving to Miami, Toey worked as a broker for Gonzalez, finding customers, who would be given login credentials to retrieve the credit cards from one of the many encrypted dump sites around the Internet.

From February to May of 2006, Gonzalez collaborated with Yastremskiy to distribute OfficeMax track 2 data.

On March 13, 2008, Gonzalez used his VPN connection to TJX from a computer in Latvia to store 16 million unique credit and debit card numbers. That same day he stored more than 25 million credit and debit cards on a Ukranian server as well.

Gonzalez faces forfeiture of $1,650,000 cash, a condo in Miami, a 2006 BMW 330I, some computers, a Glock 27, a "350C Currency Counter" (wow!),

As for the further act of Gonzalez, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?




Christopher Scott's Indictment is much less sexy from the beginning, mostly because he has no cool hacker aliases at the beginning.

He is charged with most of the same charges, with the exception of Wire Fraud.

His forfeiture included, $400,000 in cash, eleven computers, some nice iPods, some nice monitors, and they even took his XBOX and PSPs!

Let this be a warning to you, children. If you hack into TJX, you will lose your XBOX privileges! (Oh, and go to jail for a long time, hopefully!)

As for the further acts of Scott, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?



Damon Patrick Toey faced the same charges as Chris Scott. He also does not get Cool Points for having many AKAs, but let's face it, Damon Toey is a cooler name than Chris Scott.

Toey's "Overt Acts" section focuses on his selling of "dumps" of cards on behalf of Gonzalez and splitting the proceeds, and his leading role in the SQL injection and other Internet-based attacks used to access corporate databases and systems, including the Forever 21 attack, where he had the leading role.

I love the actual wording of Count Two, the Access Device Fraud:


In or about October, 2004, in the Eastern District of Virginia and elsewhere, Damon Patrick Toey, knowingly and with intent to defraud, possessed at least 15 unauthorized access devices, to wit: stolen credit and debit card numbers.


Yes, 40,000,000 is "at least" 15.

Based on the forfeiture, it looks like Damon was the Talented but Unimaginative member of the team. He forfeited only $9,500 and a few computers. But they got his XBOX too!

As for the further acts of Toey, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?

Linking all the News Spam together (CNN.com Daily Top 10)

One of my students has been studying the relationship between the various "news spam" malware pieces, and has found some interesting patterns linking the spam campaigns together by the proven relationship between the spam messages.

Tonight I decided to look at the relationships using the "open SQL query" interface to our UAB Spam Data Mine. The advanced data clustering algorithms do some incredible things, but tonight I just wanted to see what IP addresses had sent us spam email for the "CNN.com Daily Top 10" campaign, and then ask, "So what other spam do we have in the Data Mine that comes from those IP addresses?"

The query is actually very simple for this type of question:

=============================================================

select a.message_id, a.subject, a.sender_ip, b.machine, b.path
from spam a, spam_link b
where (a.message_id = b.message_id)
and a.sender_ip in
(select sender_ip from spam where
subject like '%CNN.com Daily Top 10%')
order by a.sender_ip, a.subject;

==============================================================

Which says, find all the IP addresses that sent us spam where the subject includes the string "CNN.com Daily Top 10". Then make us a list of all the messages sent by those same IP addresses, and show the subject, and URLs (machine + path) from those messages, ordered by IP address and then subject.

------

Observations:

We had emails in the CNN group from 4,875 unique IP addresses. Those IP addresses sent us a total of 11,809 emails.

10 emails in November
102 emails in December
51 emails in January
191 emails in February
162 emails in March
213 emails in April
363 emails in May
403 emails in June
2,892 emails in July
7,421 emails in August

Browsing the subjects, it was clear that most of the emails before very late June were an assortment of pills, watches, and enlargement promises. A clear "news trend" started at the very end of June.

Looking at only paths spammed by this group in July and August, these IP addresses spammed the following paths:

/1.html
/about.html
/begin.html
/checkit.html
/cnnlive.html
/cnnnews.html
/cnnonline.html
/cnntop.html
/cnnvideo.html
/default.html
/first.html
/fresh.html
/gowatch.html
/hotnews.html
/Images/.../video-nude-anjelia.avi.exe
(several variations of previous)
/index1.html
/index1.php
/index2.html
/livestreaming.html
/lol.html
/main.html
/msvideoc.exe
/news.html
/news/
/r.html
/redir.html
/showvideo.html
/start.html
/stream.html
/top.html
/tophot.html
/topnews.html
/video
/video.exe
/view.exe
/viewmovie.html
/watchit.html
/watchmovie.mpg.exe
/whatsup.html
(many crazy long paths all on "livefilestore.com")

So, EVERY MAJOR "news spam" campaign we received in July can also be found by looking at emails which came from the same IP addresses as the CNN.com Daily Top 10 emails. We wrote about several of these back in July, for example:

r.html ==> Nuwar Looks for News Readers - July 7

viewmovie.html == News Headlines Still Out of Control - July 22

topnews.html == Top News in Spam = Old News - July 26

I've placed the list of IP addresses used in this spam in a text file on my UAB website:

http://www.cis.uab.edu/forensics/CNN.iplist.txt

The list of all 2,255 URLs which were spammed in those emails is also available on my UAB website:

http://www.cis.uab.edu/forensics/CNN.urls.txt

If you have a similar list, I'd love to compare notes!

--------------

Gary Warner
Director of Research in Computer Forensics
The University of Alabama at Birmingham
gar@cis.uab.edu gar@askgar.com

Thursday, August 07, 2008

CNN Spam Diversifies . . .

We continue to see an alarming number of spam messages pretending to be from CNN, with the subject "CNN.com Daily Top 10". Approximately 6% of our spam messages are currently part of this campaign.

The spam messages contain graphics which are actually being loaded from the real CNN website. We'll load them here from the same site so you can see them. These are the graphics present in each of the spam emails, fetched directly from the CNN website, just like the current spam campaign, lending to the credibility of the spam.







Top 10 stories









There are now more than 190 URLs being used to spread the malware. While the earliest versions of the malware URL all used the path "index2.html", the malware now also is hosted on the paths "cnnlive.html", "cnnnews.html", "cnntop.html", and "cnnvideo.html".

There are now 162 servers hosting 192 paths which have been involved in this attack. Each of these servers had the malicious content uploaded to it by a hacker. Most of these are legitimate websites which were hosting real webpages before they were compromised for this purpose. Because the malicious contents are not interfering with the primary use of the server, in many cases the webmasters were not even aware of the compromise.

*WE DESIRE TO SPEAK TO ANY ADMINISTRATOR WHO CAN PROVIDE LOG FILES FROM ONE OR MORE OF THESE COMPROMISED SERVERS*

Here is a list of malicious URLs, grouped by "path":

http://adcockonline.com/cnnlive.html
http://ademirpestana.com.br/cnnlive.html
http://beta.wwf.it/cnnlive.html
http://caminhodocristo.com.br/cnnlive.html
http://cdlaestrella.com/cnnlive.html
http://fondeur.com/cnnlive.html
http://fotosdc.com/cnnlive.html
http://gracesmarketplace.com/cnnlive.html
http://hangarmobiliario.startlogic.com/cnnlive.html
http://jumpking.fr/cnnlive.html
http://layber.com.br/cnnlive.html
http://piedrarustica.com/cnnlive.html
http://pyromagie.com/cnnlive.html
http://rosh-hanikra.com/cnnlive.html
http://sarlcreapub.fr/cnnlive.html
http://www.consulting-ev.com/cnnlive.html
http://www.familiavelazquez.com/cnnlive.html
http://www.ferienpark-berum.de/cnnlive.html
http://www.martinkahl.com/cnnlive.html
http://www.nlg.com.br/cnnlive.html
http://www.smackxx.de/cnnlive.html


http://art-cie.fr/cnnnews.html
http://cityofdetroit-beta.com/cnnnews.html
http://energydrinkshop.com/cnnnews.html
http://imeriberica.com/cnnnews.html
http://leggiillustrate.it/cnnnews.html
http://lorenziniassociati.it/cnnnews.html
http://nodostudio.com/cnnnews.html
http://ophtha.com.co/cnnnews.html
http://pastry-art.de/cnnnews.html
http://pcenmarcha.com/cnnnews.html
http://reservadeoporto.com/cnnnews.html
http://scotsact.com/cnnnews.html
http://sethory.de/cnnnews.html
http://studiogabia.com/cnnnews.html
http://style-r.de/cnnnews.html
http://uggi.com.br/cnnnews.html
http://videogamesheaven.dot5hosting.com/cnnnews.html
http://wp1054775.wp086.webpack.hosteurope.de/cnnnews.html
http://www.bellomeparrucchieri.it/cnnnews.html
http://www.ck-automobile.de/cnnnews.html
http://www.datgame.com/cnnnews.html
http://www.konaya.com.tw/cnnnews.html
http://www.marmibuono.com/cnnnews.html
http://www.ssurmant.es/cnnnews.html
http://www.uwg-groebenzell.de/cnnnews.html
http://www.vonalpenhirsch.be/cnnnews.html


http://adcockonline.com/cnntop.html
http://ademirpestana.com.br/cnntop.html
http://beta.wwf.it/cnntop.html
http://carports-rhein-neckar-dreieck.de/cnntop.html
http://cdlaestrella.com/cnntop.html
http://congresoaracenaegc.es/cnntop.html
http://fondeur.com/cnntop.html
http://fotosdc.com/cnntop.html
http://gracesmarketplace.com/cnntop.html
http://hangarmobiliario.startlogic.com/cnntop.html
http://ipp-dresden.de/cnntop.html
http://jumpking.fr/cnntop.html
http://karokuhle.de/cnntop.html
http://koblenzer-schaengelbrot.de/cnntop.html
http://layber.com.br/cnntop.html
http://missglobe-albania.com/cnntop.html
http://morenogonzalo.com/cnntop.html
http://piedrarustica.com/cnntop.html
http://primeracolina.cl/cnntop.html
http://pyromagie.com/cnntop.html
http://rosh-hanikra.com/cnntop.html
http://sarlcreapub.fr/cnntop.html
http://scsroofing.com/cnntop.html
http://steinsein.gmxhome.de/cnntop.html
http://terrano2.be/cnntop.html
http://www.affiliateincome4free.com/cnntop.html
http://www.alfa-nt.com/cnntop.html
http://www.blackhawkk9.com/cnntop.html
http://www.consulting-ev.com/cnntop.html
http://www.ferienpark-berum.de/cnntop.html
http://www.jills-homepage.de/cnntop.html
http://www.martinkahl.com/cnntop.html
http://www.microbyte.ch/cnntop.html
http://www.nlg.com.br/cnntop.html
http://www.smackxx.de/cnntop.html


http://ademirpestana.com.br/cnnvideo.html
http://apamys.es/cnnvideo.html
http://aramusicaiespectacles.com/cnnvideo.html
http://barrierelectric.com/cnnvideo.html
http://beta.wwf.it/cnnvideo.html
http://caminhodocristo.com.br/cnnvideo.html
http://cave-live.info/cnnvideo.html
http://cdlaestrella.com/cnnvideo.html
http://colleflambo.com/cnnvideo.html
http://dcfwarriors.org/cnnvideo.html
http://directorioelejido.com/cnnvideo.html
http://erbilproje.com/cnnvideo.html
http://eventosgs.com.ar/cnnvideo.html
http://familylaw-nj.com/cnnvideo.html
http://hangarmobiliario.startlogic.com/cnnvideo.html
http://maviinci.org/cnnvideo.html
http://meusarquivos.net/cnnvideo.html
http://mikkokaaria.com/cnnvideo.html
http://naltech.co.il/cnnvideo.html
http://piedrarustica.com/cnnvideo.html
http://praxisfilms.co.il/cnnvideo.html
http://rosh-hanikra.com/cnnvideo.html
http://sarlcreapub.fr/cnnvideo.html
http://showtech.myzen.co.uk/cnnvideo.html
http://starbistro.de/cnnvideo.html
http://synerweb.info/cnnvideo.html
http://thediver.co.il/cnnvideo.html
http://twistedrose.com.mx/cnnvideo.html
http://www.drtimcic.org/cnnvideo.html
http://www.familiavelazquez.com/cnnvideo.html
http://www.ferienpark-berum.de/cnnvideo.html
http://www.instrumelec.be/cnnvideo.html
http://www.iteco.cz/cnnvideo.html
http://www.malicioso.net/cnnvideo.html
http://www.martinkahl.com/cnnvideo.html
http://www.massouristudios.gr/cnnvideo.html
http://www.nlg.com.br/cnnvideo.html
http://www.ruf-an-alle.de/cnnvideo.html
http://www.smackxx.de/cnnvideo.html
http://www.transam99.de/cnnvideo.html


http://1stbs.com/index2.html
http://208.112.108.239/index2.html
http://3dtoy.com.br/index2.html
http://attomega.com/index2.html
http://autourdufeu.net/index2.html
http://borinsrl-store.com/index2.html
http://climatel.dot5hosting.com/index2.html
http://dztransporte.de/index2.html
http://hieber-ed.de/index2.html
http://hometrimwork.com/index2.html
http://isctrim.com/index2.html
http://lombardi.ws/index2.html
http://megadent.pl/index2.html
http://realdecor.com.br/index2.html
http://renderize.net/index2.html
http://sol.innopulse.es/index2.html
http://tomar-a-andar.com/index2.html
http://turegalodesanvalentin-julieta.idoo.com/index2.html
http://vehne-cafe.de/index2.html
http://voxinterna.de/index2.html
http://www.bardaue.com.br/index2.html
http://www.dj-ralfi.de/index2.html
http://www.sibercar-card.com/index2.html
http://www.weddingsinsardinia.com/index2.html
http://www.wellnessantamaria.com/index2.html


http://496dots.com/news/
http://620dreams.com/news/
http://90lights.org/news/
http://90muses.org/news/
http://97folders.org/news/
http://99spots.org/news/
http://9feeds.org/news/
http://arkaki.org/news/
http://asvoo.org/news/
http://awaybuddies.org/news/
http://back82.org/news/
http://behind97.org/news/
http://bibdit.org/news/
http://blogcube.org/news/
http://cafemarker52.com/news/
http://cafepaths077.com/news/
http://clipcabin.org/news/
http://facecurve.com/news/
http://front7589.com/news/
http://frontsend09.com/news/
http://joogle2.com/news/
http://my3598.com/news/
http://open6098.com/news/
http://ourmark75.com/news/
http://squinento96.com/news/
http://stikimixer.com/news/
http://styledesk86.com/news/
http://tao767.com/news/
http://true479.com/news/
http://upgle12.com/news/
http://www.18columns.org/news/
http://www.26cubes.org/news/
http://www.28buddies.org/news/
http://www.36dreams.org/news/
http://www.36people.org/news/
http://www.41cells.org/news/
http://www.58friends.org/news/
http://www.60balloons.org/news/
http://www.60circles.org/news/
http://www.6feeds.org/news/
http://www.71piles.org/news/
http://www.75cubes.org/news/
http://www.79circles.org/news/
http://www.7lights.org/news/
http://www.83friends.org/news/
http://www.83groups.org/news/
http://www.86places.org/news/
http://www.87clouds.org/news/
http://yooia97.com/news/

An astounding number of fake headlines have been used as lures. Each spam email message contains ten of these headlines listed as "Top Stories" and ten more of these headlines listed as "Top Videos".

`Dark Knight' - download it instantly fo free
125,000 gorillas found in New York
12-year-old with HIV applauded at AIDS conference
16 Police Die in Pre-Olympic Attack
5 more arrested from west Texas polygamist sect
6 NFL greats inducted into the pro football hall of fame
8-Foot Python Becomes Laundry
95-year-old Paul Batman calls Texas -- not Gotham City -- home.
A college student has vowed to make it through the summer on one tank of gas.
A drunken driver slams into car as officer wrote a ticket.
A first-birthday coming of age ritual that foretells the future.
A look at the future computing technologies which will go beyond Moore's Law.
A major study by Microsoft supports "small world" theory.
A prostitute waits for customers
A young human rights attorney makes unprecented move against religious police.
Acrobatic troupe's colourful London debut of Swan Lake
Activists kill 3 in Ohio
Afghan, NATO troops kill 17 militants in southern Afghanistan
Aged Tires: A Driving Hazard?
Ageing Japanese men worry about body odour
Air force one crashes in Iraq
Al QaedaÆs Leader Arrested
Alleged pickup thief loses truck to carjacker
Amy Winehouse hospitalized following drug overdose
An American pilot's mission won the heart of a city in its darkest hour.
Ancestor of T-Rex dinosaur unearthed in Poland
Ancient shark had colossal bite. See pics now!
Andre Agassi admits drug abuse
Angels Grow on Trees says Hillary Clinton
Angry, late, tired passengers make computers crash
Anthrax researcher had been under psychiatric care before his death.
Arctic park faces melting crisis
A-Rod to wed Madonna in September
AS SEEN ON TV: Elder Care Resources
Athletes bare all. See now!
Atlanta's Airport Named World's Busiest
Attackers kill 16 police at Chinese border post
Bank accounts 'not working for customers
Bank breaks rules on charges court case Derbyshire
Bank charges claims left in limbo
Bank Pampers Thousands
Bankers are laughing all the way to the bank
Banks to rake in extra $1.3bn in next six months after delaying OFT overdraft crackdown
Beckham wins a surfboard in LA
Become Sperm Donor and Get Rich
Beijing unblocks BBC Chinese site
Beijing under threat as Olympics looms
Bikers down to bare basics for eco demonstration
Bill Clinton and Monika seen again
Bill Clinton finds Hillary affair pics
Bill Clinton Regrets, 'I Am Not a Racist'
Bill Thompson asks if the web changes how we think
Bill Thompson on Apple's software security stance
Blake Lively admits crush on Britney
Blake Lively admits teenage lesbianism
Boy Loses Arm in Gator Attack
Boy thrown outside window in school
Boys bounce for 24 hours in world record attempt
Brangelina babies finally unveiled on Web
Brazil launches rainforest fund
Breaking Dawn' Book Excerpt Exclusive!
'Breaking Dawn' Book Excerpt Exclusive!
Bridge collapses in New York
Buses are a 'consumer's paradise' as airfares rise and air stresses grow.
Bush plans to kill prisoner
Bush urgently flies to Asia
Buy gasoline before prices shoot off
Buy the original Olympic Torch from Beijing
Can a party game reveal flaws in U.S. wiretapping and war plans?
Car bomb in Washington kills hundreds
Car buyers sue Ford over limited edition vehicle
Celebrity was seen naked on the beach
Changing the way we think
Cheesus! Jesus Spotted in a Cheeto
Chef: sorry for suggesting poison plant in salad
China clamping down on journalists' Web access to control image during Games.
China has more internet users than US
China Jails Another Dissident Before Games
China Rising: Will It Overtake the U.S.?
China tightens security following attack in west
China's 'rapid renewables surgery' is available now!
Christian Bale admits affair with Angelina Jolie
Christian Bale hits on Lindsay Lohan
Christina Applegate treated for breast cancer
Church-goers shot for having different views
Clark Rockefeller continues to stymie investigators' questions about his past.
Cleaning up in 'fab world'
Clinton Denies Racism Claims
Closing the Gates after Bill
Comedian Mac in Chicago hospital
Commercial dog clones are available now
Computer mouse faces extinction
Condo investors in Florida are struggling to hold their lives together.
Cops May Close Anthrax Probe Today
Coroner ID's teenager who was asphyxiated, dumped in shallow desert grave.
Corrupt China official betrayed by leaky toilet
Cuil - new google-ish search engine
Customers not paid back overdraft charges
Death or a crippling injury could leave your loved ones out in the cold.
Definition of a womanÆs G-spot
Dinosaurs Come to Life at Exhibit
Dinosaurs interact with humans on 'Primeval'
Disputed Korean rocks bring banking, ring tones
Divorced, beheaded or died? Joss Stone to play one of Henry VIII's wives in The Tudors
Doctor Who writer Russell T Davies is among the stars
Dog Plays Mom for Tiger Cubs
Dog Rides a 'Hog'
Don't streak, get drunk or sleep outside at Olympics
Doping scandal rush out before the opening
Drug, alcohol mix blamed for "Joker's" death
Drunken Man Can't Erase Arrest
Dumped computers cause toxic concerns in Ghana
Early stereo recordings restored
Edouard hits Texas, many dies
Edouard Triggers 'Cane Watch for Texas
Energy giants are told to pay back billions
Engine test for Falcon 9 rocket
Ernest Hemingway look-alikes hit Key West's streets to honor the author.
Ex-Google engineers debut 'Cuil' way to search
Facebook Grows, but Where's the Profit?
Facebook under attack by clones
Family Dinner in China's Countryside
Family Lives Paycheck-to-Paycheck
Farmer sends message to neighbors with car fence
Fatal medication errors at home causes 1 million deaths
FBI arrest Gotti Jr in New York
FBI investigates new attacks on Calif. scientists
FBI reveal sealed docs describing anthrax attack details
FDA warns against eating lobster
FIC Says Overdraft Charges Unfair On Consumers
Fight back against unfair credit card practices
Find you friend online for free
Five Secrets to Get a Bargain on a House
Fla. man dials 911, complains his sub had no sauce
Floods in Minnesota kill hundreds
Food Prices Too High? Buy a Farm
Four Girls and You. Reveal Your Fantasies
France accused in Rwanda genocide
Free banking is a myth: charges on current accounts reach $8bn a year
Freeman still in serious condition after car crash
Funnies: Celebrity Candidates?
Furnished Nazi bunkers surface in Denmark
Future directions in computing
Gay bishops banned and castigated
Gay declares himself fit for 100m
GE declares 100 million deficit
German police women get "bullet-proof bras"
Get a current account that beats the credit crunch
Get new sport car. If youÆre smart enough
Get your up-to-date fix of blog posts about all things digital
Good Housekeeping Institute tested backpacks, snacks and lunch boxes.
Google accused on privacy views
Google Knol threatens wikipedia
Gossip Girl wins six Choice gongs
GPS-equipped turtle stumbles upon field of marijuana in a D.C. park.
Grabbing for Destiny: A Chinese Baby's Coming of Age
Guinea Pigs Get Dressed ... and Eaten
Half-scale replica of German tank built for paintball competition.
Harried family forgets 3-year-old daughter at airport.
Have Your Hours Been Cut?
Hedge-Fund Soldier Leads Double Life
High cost of little cash
Hillary admits she was wrong
Hillary falls from horse, hurts arm
Hillary finds ladies' stuff in house, storms off in a huff
Hi-tech criminals target Twitter
Hopkins, Epstein, Bolger Join Cast of 'Dirty Dancing''s U.S. Tour
How One Family Fought Foreclosure
Human malaria jab tests nearing
IBM to file for bankruptcy
Iggy Pop truck stolen after show
Illusionist Chris Angel races against time in a building set to detonate.
In the era of pills, fewer psychiatrists do talk therapy.
In the first surgery of its kind, a German farmer gets a new pair of arms.
Inflation rises to 35-year high of 8.2%
Intel unveils graphics chip line. See it now!
Internet exposes Obama affair
Is this photo fake? Meet the people who say it is...
It's a buyer's market if you know what 'code words' to look for.
Jacksons to receive Icon honour
Japanese rookie tosses perfect game for Dodgers
JFK heir found
Joe Corre was born to rail against
Kaiser Chiefs boast a 'weird, fresh, radical' new sound
Kelsey Grammer in hospital after heart attack
Kevin Costner appreciates politics and making movies.
Kevn Spacey forced to admit to affair
Key to Biz Success: The Conference Table?
Kidnap Dad In Custody, Girl Found Safe
Last Survivor of K-2 Tragedy Still Climbing
Laura Bush naked
Learn how to be a guru in finding G-spots
Leona Lewis up for US MTV award
Light goes out on pioneer machine
Lost Your Home to Foreclosure?
Madonna admits to 12 different affairs
Madonna seduced Timberlake on set
Maggie Q seen with Brad Pitt
Magma in the Atlantic ocean cooks up ultra-hot water.
Maine island loses trash can mail delivery service
Making a career in Hollywood. You can do it!
Making punishment fit the crime
Man Offers $1 Billion Reward for Breast Cancer Cure
Man presumed dead in 1976 Colo. flood found alive
Man shoots churchgoers over liberal views
Man tells 911 slot machine stole his money
Man wins appeal in bizarre gasoline suicide case
Mars May Not Be Garden Spot
Mass suicide of prisoners in US cell
Massive earthquake in Japan kills thousands
McDonald's feed wastes
Meet the Real Batman
Men survivied month eating dog food
Merrill Lynch files for bankruptcy
MGM Mirage gets CityCenter financing
Michael Jackson is sued by his own dog
Michael Jordan admits affairs with dozens of girls
Michael Jordan attacks Clinton
Michelle Obama latest fashion disaster
Microsoft sees end of Windows era
Miley Cyrus describes her dream man
Mitch Winehouse will host a phone-in show on BBC Radio London in September.
Moon can inhabited at 2010
More UCLA staff saw celebs' health records
Morgage Loan You Can Pay Off
Mortgage rates rise to heavens
MTA Screwing You
Murderer on the loose after cop bungle in Iowa
Mysterious 'Monster of Montauk'
Naked Madonna blows the press conference
Naked Teen Meets You at Your Home
NASA engineer-DJ Mark Branch thinks spinning beats is a science.
Neighborhood quarrel threatened to bring war, but it ends in handshakes.
New Breed of Dolphin
New cure for Alzheimers' discovered
New quake hits Chinese province
New study suggests that athletic performance can affect visual perception.
No answers as McCarthy, Favre meet late into night
No More $1 Double Cheeseburgers?
No wonder we don't trust the banks
Nokia morphs itself from within
Northern Rock cash boost attacked
Not All Men Need Prostate Cancer Screening
NY girl falls 14 stories, saved by sooty landing
Oasis to play secret gig for fans
Obama beats McCain
Obama sacks 4 top staff
Obama spotted in secret China meeting
Obama urges opening oil reserves
Obama-Clinton ticket is most likely
Oil price falls further to $118
Oil prices drop to 45-year low
Olsen seeks Ledger immunity
Olympic Sport: Blocking the Internet
Olympics-Wear ox pendant to avoid rat clashes, leaders
One couple juggles two kids and four jobs; a rebate check is their only relief.
One family struggles to maintain company, as personal savings dry up.
One million dollars to be win by Friday. Try you luck
One woman risks her own financial future to care for her grandparents.
Owner's delight as scientists produce five clones of pet pooch
Oxygen bottle damages Qantas aircraft
Packet pioneer
Pain at the Pump Roils Presidential Campaigns
Palin show criticised on accuracy
Paris Hilton's mom takes offense at McCain's humor
Phoenix diary. The team is under pressure to get results on Mars
Police hunt stolen rare shark
Police killed in west China ahead of Games
Pool Parasite Infections on the Rise
Primate warning. Beware of gorillas!
Primates 'face extinction crisis'
Private plane travel to be banned
Punk progeny launches "Terrorist" clothing line
Research shows a mother's brain reacts positively to infant's smile.
Rig dumps tons of dirt when nature calls driver
Riposte to "Eat, Pray, Love" hooks studio deal
Roosevelt revisited - 100 months to halt dangerous climate change
Russian stocks take hit as govt. looks to nationalize steel, oil companies.
Ryan Seacrest survives California shark attack
S. America: To the Brink of War and Back
S. Koreans fire water cannons at Bush
Secret deal kept British troops out of Basra
See how this family of six keeps their grocery bill at $350 a month.
Sex and the city forbidden,
Sex link' to French oyster rout
'Sex link' to French oyster rout
Sexual strength youÆd never dreamt of. Get it now
Sheen 'highest paid US TV actor'
Shia LaBeouf recovering after hand surgery
Should a baby be risked to save her sister?
Six month delay over refund of bank charges $800 bank charges for 8p overdraft
Small Businesses Feeling the Squeeze
Social networking sites have lots of users, but no one seems to be buying.
Sony goes solo in music venture
SpaceX launch fails a third time
Staff urged to dress down, stay cool as U.N. heats up
Star Wars' George Lucas on thrill of making Clone Wars
Star Wars model raises $350,000
Statins reduce memory loss
Student charged ?800 for going 8p into the red
Study shows: Golf Holes Bigger to Athletes
Superheroes Get Sandy
Take look inside the surreal and ultra-clean world of the silicon manufacturing plant.
Take you chance, win new car!
Taking Viagra daily exceeds menÆs strength, new research says
Teenage Mutant Ninja NARC
Tehran says it launched nuke missile
Ten to watch
Terminator Salvation, fourth Terminator film previews
Thailand bans Grand Theft Auto IV
The bloody murderer is arrested at last
The decline of primates shows time is running out
The hits and misses of his leadership of Microsoft
The humble mobile phone become a multimedia, multi-function monster
The importance of being there
The mortgage mess has plunged some American families into crisis
The sea creature giving Britain's olympic sailing squad a boost
The three New Jersey brothers delight teens with fun, wholesome music.
Three children jailed for armed holdup
Tips and resources so you can make better decisions about elder care.
Tips by 'America's Cheapest Family'
Torture widespread in Palestinian jails
Tropical Storm Edouard moving toward Texas coast
Turkey investigates deaths of 27 babies in 2-week period at Ankara hospital.
Two planes in airport collision
Typhoon in Taiwan devastates city
Urgent! Strong quake hits China
US beef unsafe for consumption
US hearing for 'al-Qaeda' woman
US Potatoes unsafe for consumption
US surgical errors cost $1.5 billion a year: report
Vet Aids Endangered Shark
Victoria Beckham is descendant of comrade of Marx
Video websites 'must vet content'
Virgin Galactic shows off mothership space craft
Virgin territory for ISPs
Vitamin C 'slows cancer growth'
Wall-climbing robots have been developed by scientists in America.
War, Spying and Party Game Delusions
Was there a deal to keep the British out of the Basra battle?
Watchdog gives banks more time over complaints
West Nile virus cases reported in California
Western wealth poses dilemma for Muslim islanders
What has melon liqueur got to do with Microsoft?
What Is Microsoft So Afraid Of?
Whoopi Kissed a Girl and She Liked It
Why mass hysteria is the exception -- not the rule.
Why Microsoft's next-gen software is called Midori
Why the future is in your hands
WiFi will work everywhere. Find out
Wildlife: A luxury we can live without?
Will nearly all Americans be obese by 2030? Diet experts have their say.
Woman Attacked by Beau's Pitbull
Woman gives birth to 18th child
Woman Survives Bear Attack
World's Hottest Water Found
World's oldest joke traced back to 1900 BC
World's smallest snake discovered
X Files fails to make UK impact
Yahoo board wins investor vote
Yankees plane crashes over Minnesota
Yard Work and Leather is just one of many new candle scents for men.
You New Credit, No
Your Mortgages Questions Answered
You're under a vest! German policewomen get 'bullet-proof bra'

Tuesday, August 05, 2008

TJX Reminder: "We Will Arrest You, and We Will Send You To Jail"

As we've been watching the news since the TJX bust, there have been several times where I thought we would hear that charges for that break-in would finally come. Well, it seems today is the day! Albert Gonzalez of Miami, who is known by his hacker handle "Segvec", was charged along with two other Miami residents in Boston today, while eight others were charged in Los Angeles.

With several hundred million dollars in theft, Attorney General Michael Mukasey did a press release about the indictments. According to Mukasey's speech:

hey targeted at least nine major retail corporations, including the TJX Corporation, whose stores include Marshalls and TJ Maxx; BJ's Wholesale Club; Barnes and Noble; Sports Authority; Boston Market; Office Max; Dave and Busters restaurants; DSW shoe stores; and Forever 21.


Mukasey continued, describing today's actions as a key part in the strategy of the Identity Theft Task Force, co-chaired by Mukasey and the chairman of the Federal Trade Commission, William Kovacic:


And the cooperation among investigators and prosecutors throughout the United States and around the world that led to these indictments shows the promise of close coordination in tackling these problems. Cases like this send a clear message to those who might be tempted to abuse our computer networks to steal information and harm law-abiding people and businesses: If you do, we will track you down wherever you are in the world, we will arrest you, and we will send you to jail.


The Department of Justice Press Release goes into som emore details, naming the additional co-conspirators:

Three From Miami were charged in Boston today:

Albert Gonzalez, AKA Segvec
Christopher Scott
Damon Patrick Toey

In San Diego charges were unsealed against:

From the Ukraine:
Maksym Yastremskiy, AKA Maksik
Dzmitry Burak
Sergey Storchak (no, I don't believe this is the Deputy Minister of Finance in Russia, of the same name, who is already in prison for embezzlement...)

From the Ukraine:
Aleksander Suvorov, AKA Jonny Hell

From China:
Hung-Ming Chiu (邱黄明)
Zhi Zhi Wang (王治治)

From ????:
the unknown hacker named Delpiero (isn't that an Italian soccer player's name?)

From Belarus:
Sergey Pavolvich

The indictments in San Diego are the result of an on-going three year undercover operation run by the Secret Service.


We last discussed Albert Gonzalez in this blog posting from May 12th, under the title TJX and Dave & Busters. Gonzalez was actually working as a "Confidential Informant" for the US Secret Service when they became aware of his involvement in this case. He had come to the attention of the Service when they arrested him in 2003 for Access Device Fraud. He was re-arrested for Wire Fraud on May 8th, according to documents from the US District Court in Miami, Floriday.

Maksym Yastremskiy has been jailed longer than any of the others, having been arrested at a nightclub in Kemer, Turkey with his girlfriend, and found to be in possession of "at least 1 million" credit card credentials, many of which have been found to be TJX data. That story broke (if you speak Turkish), all the way back in August of 2007 with these two articles:

Milliyet.com.tr - August 2nd

and

Sabah.com.tr - August 3rd

We first talked about that in this blog with the story TJX: From Florida to the Ukraine?, where we discussed the Miami crew who were turning TJX cards into WalMart Gift Cards before laundering them via eBay sales of luxury items bought in Sam's Clubs.

The next to get arrested was probably Jonny Hell, whose arrest back on March 3, 2008 was recently depicted in this Der Spiegel story from June 30th.



Jonny Hell, in Der Spiegel . . .

If you'll forgive my bad translation, the story says something like:


The two American agents, dark suits and service-brands of the Secret service, stood motionless beside the snake of the flight-traveler at the Frankfurt airport. They waited until Aleksandr Suvorov and his friend Vika were next, arriving at terminal 1 Singapore Airlines for three weeks of recuperation in Bali for the love-pair. As Suvorov pushed his Estonian passport over the counter-bar, eyewitnesses remember, there the Special Agents Paul B. and Timothy G. stepped forward, pulled out their ID cards, and revealed it to him. "You are arrested". It was March 3rd, shortly before 22 o'clock . . .

Since then, he has waited for his delivery to the USA. He is regarded as a top international hacker, that steals sensitive data in a big style by means of Trojan horses, and then resells it. The young Estonian, who supposedly hides behind the hacker-pseudonym "Jonny Hell", belongs to "one of the biggest world-wide circles dealing in stolen credit card numbers".




If anyone has more information on these hackers and their other exploits, please send them in!

Gary Warner
gar@askgar.com

CNN Lends Authenticity to News Spam

UPDATED!

At the UAB Spam Data Mine we've been tracking the recent malware attacks which use news headlines as their spam bait. You've seen a few previous stories on the subject in this blog, NuWar Looks for News Readers, News Headlines Still Out of Control, and Top News in Spam Old News.

The thing that makes last night's new spam campaign newsworthy is the inclusion of a very authentic looking CNN wrapper on the spam.



We received more than 1,400 copies of this spam email so far in the UAB Spam Data Mine. While the subject of the email has always been "CNN.com Daily Top 10", the listed stories are composed of a random mix from the following 84 topics:

`Dark Knight' - download it instantly fo free
12-year-old with HIV applauded at AIDS conference
16 Police Die in Pre-Olympic Attack
6 NFL greats inducted into the pro football hall of fame
8-Foot Python Becomes Laundry
95-year-old Paul Batman calls Texas -- not Gotham City -- home.
A drunken driver slams into car as officer wrote a ticket.
A prostitute waits for customers
Afghan, NATO troops kill1 7 militants in southern Afghanistan
Aged Tires: A Driving Hazard?
Ancestor of T-Rex dinosaur unearthed in Poland
Angry, late, tired passengers make computers crash
Attackers kill 16 police at Chinese border post
Bikers down to bare basics for eco demonstration
Bill Clinton and Monika seen again
Bill Clinton Regrets, 'I Am Not a Racist'
Boy Loses Arm in Gator Attack
Boys bounce for 24 hours in world record attempt
Breaking Dawn' Book Excerpt Exclusive!
Bush urgently flies to Asia
Can a party game reveal flaws in U.S. wiretapping and war plans?
Celebrity was seen naked on the beach
Cheesus! Jesus Spotted in a Cheeto
Chef: sorry for suggesting poison plant in salad
China Rising: Will It Overtake the U.S.?
Christina Applegate treated for breast cancer
Cops May Close Anthrax Probe Today
Corrupt China official betrayed by leaky toilet
Dinosaurs Come to Life at Exhibit
Dog Plays Mom for Tiger Cubs
Dog Rides a 'Hog'
Don't streak, get drunk or sleep outside at Olympics
Doping scandal rush out before the opening
Drunken Man Can't Erase Arrest
Edouard Triggers 'Cane Watch for Texas
Ernest Hemingway look-alikes hit Key West's streets to honor the author.
Facebook Grows, but Where's the Profit?
FBI reveal sealed docs describing anthrax attack details
Find you friend online for free
Five Secrets to Get a Bargain on a House
Funnies: Celebrity Candidates?
Furnished Nazi bunkers surface in Denmark
GPS-equipped turtle stumbles upon field of marijuana in a D.C. park.
Guinea Pigs Get Dressed ... and Eaten
Half-scale replica of German tank built for paintball competition.
Harried family forgets 3-year-old daughter at airport.
Illusionist Chris Angel races against time in a building set to detonate.
In the first surgery of its kind, a German farmer gets a new pair of arms
It's a buyer's market if you know what 'code words' to look for.
Kevin Costner appreciates politics and making movies.
Key to Biz Success: The Conference Table?
Kidnap Dad In Custody, Girl Found Safe
Maine island loses trash can mail delivery service
Man presumed dead in 1976 Colo. flood found alive
Man wins appeal in bizarre gasoline suicide case
Meet the Real Batman
Michael Jackson is sued by his own dog
Mortgage rates rise to heavens
Mysterious 'Monster of Montauk'
Naked Madonna blows the press conference
NY girl falls 14 stories, saved by sooty landing
Obama beats McCain
Olympic Sport: Blocking the Internet
Olympics-Wear ox pendant to avoid rat clashes, leaders
Paris Hilton's mom takes offense at McCain's humor
Police killed in west China ahead of Games
Pool Parasite Infections on the Rise
Rig dumps tons of dirt when nature calls driver
Russian stocks take hit as govt. looks to nationalize steel, oil companies.
Sex and the city forbidden,
Social networking sites have lots of users, but no one seems to be buying
Superheroes Get Sandy
Teenage Mutant Ninja NARC
Tehran says it launched nuke missile
The three New Jersey brothers delight teens with fun, wholesome music.
Tropical Storm Edouard moving toward Texas coast
Vet Aids Endangered Shark
War, Spying and Party Game Delusions
What Is Microsoft So Afraid Of?
Whoopi Kissed a Girl and She Liked It
Will nearly all Americans be obese by 2030? Diet experts have their say.
Woman Attacked by Beau's Pitbull
Woman Survives Bear Attack


What happens if you click the link? In our first wave of the attack, we've identified 45+ different websites, which, like the previous waves of news headline malware, seem to be hosted on sites which have been compromised for this purpose.

CAUTION! DO NOT VISIT THESE LINKS! LIVE MALWARE PRESENT!


http://1stbs.com/index2.html
http://realdecor.com.br/index2.html
http://turegalodesanvalentin-julieta.idoo.com/index2.html
http://www.sibercar-card.com/index2.html
http://autourdufeu.net/index2.html
http://208.112.108.239/index2.html
http://attomega.com/index2.html
http://tomar-a-andar.com/index2.html
http://renderize.net/index2.html
http://lombardi.ws/index2.html
http://3dtoy.com.br/index2.html
http://sol.innopulse.es/index2.html
http://vehne-cafe.de/index2.html
http://climatel.dot5hosting.com/index2.html
http://www.dj-ralfi.de/index2.html
http://dztransporte.de/index2.html
http://www.bardaue.com.br/index2.html
http://voxinterna.de/index2.html
http://hieber-ed.de/index2.html
http://www.wellnessantamaria.com/index2.html
http://hometrimwork.com/index2.html
http://isctrim.com/index2.html
http://borinsrl-store.com/index2.html
http://megadent.pl/index2.html
http://www.weddingsinsardinia.com/index2.html

UPDATE: Now we're seeing "/news/" as a valid path, instead of the earlier "/index2.html". We'll keep an eye out on this trend . . . so far there is not actually any content on these "/news/" pages, however they are all currently resolving to the same IP. Perhaps the spammer just got ahead of himself?

http://cafepaths077.com/news/
http://496dots.com/news/
http://ourmark75.com/news/
http://joogle2.com/news/
http://cafemarker52.com/news/
http://tao767.com/news/
http://open6098.com/news/
http://yooia97.com/news/
http://facecurve.com/news/
http://front7589.com/news/
http://620dreams.com/news/
http://stikimixer.com/news/
http://squinento96.com/news/
http://my3598.com/news/
http://styledesk86.com/news/
http://upgle12.com/news/
http://frontsend09.com/news/
http://true479.com/news/

Sites are hosted around the world, including the United States, Brasil, France, Italy, and Poland. Analysis of the malware and the websites by UAB students shows that it is clearly related to previous "news" campaigns, though you'll forgive me if we don't share all of those details here.

As before, malware detection is far from complete in the anti-virus community. A scan of this malware on VirusTotal still shows only 16 of 36 different detect the virus, although I'm happy to report that Symantec is now among those who do. (McAfee, Trend, and Microsoft are still among those who do not.)

The challenge to those wishing to block the virus is the same as we've been dealing with. The current malware name is "get_flash_update.exe", but even blocking by name may not be adequate. One of the website tricks is to cause machines to download the malware via a javascript program. In the javascript program, the name of the file is interspersed with "garbage characters", which are then removed by the program when it comes time to save the file.

For example:

g(e(t_f&l*a^s#h_$u!p*(date)#.!%e^x&#e!'

is followed by a command to remove:

replace(/\!|@|#|\$|%|\^|&|\*|\(|\)

which leads to the name to be stored being:

get_flash_update.exe

The actual filename then, would never occur in the web filters.

These viruses are on legitimate websites which have been compromised. Blocking the websites will protect your business, but may block a real company as penalty for their compromise. We are still working with webmasters and providers to learn how the sites are being compromised, but the leading theory at the moment is via an FTP password compromise.

Sunday, August 03, 2008

Another Insider Busted: Countrywide Financial Analyst

(updated with new information)

Rene Rebollo, a 36 year old former Countrywide employee from Pasadena, has been charged by the FBI and taken into custody with a co-conspirator Wahid Siddiqi, a 25 year old from Thousand Oaks. Its alleged that Rebollo would come into the office every Sunday and download data from Countrywide's subprime mortgage system, Full Spectrum Lending. He apparently logged in each weekend for two years, downloading information on 20,000 each weekend and carrying it home on a flash drive. For this he was paid $500 per week. In all he is accused of selling identity information on 2 million Countrywide applicants, and pocketing $70,000 for his efforts, which exceeded his annual salary at Countrywide. (The Ventura County Star put that figure at $63,000.)

The LA Times reported yesterday that this means Rebollo was selling identities for about 2.5 cents each. They quote Beth Givens from the Privacy Rights Clearinghouse as saying "This guy obviously didn't do his homework. He doesn't know the value of these on the black market", noting that often social security numbers are sold for dollars each, not pennies.


According to Thom Mrozek, of the US Attorney's Office in Los Angeles, the buyers of the stolen data were using it as lead generators to offer the same subprime loan customers other financial offers.

Its not clear yet how the data was normally transferred from Rebollo to Wahid Siddiqi, but what we do know is that Siddiqi was a reseller of the data Rebollo accessed by logging in with his credentials as a Senior Financial Analyst. According to his LinkedIn Profile, Rebollo worked at Countrywide since September of 1999.

The FBI came into the case when one of their confidential witnesses made a buy from Siddiqi of the stolen customer profiles for several thousand countrywide customers for $4,000. According to the Ventura County Star, the witness met both Siddiqi, who he called "Nico", and Rebolla, who he called "Rob Bello", in a night club and exchanged cash for CDs containing the stolen data.

The charges against Rebollo, who stole the data, could include up to five years in federal prison. Siddiqi, the reseller, could face up to fifteen years.

This isn't the first major mortgage broker to face insider jobs. Online mortgage broker Lending Tree Inc accused two former employees of illegally accessing information on "potentially millions of clients".

Update: We've received a copy of two affadavits sworn by FBI Special Agent Richard Ryan that were presented to the courts. One is a 13-page document, in support of the charges being brought against Rebollo and Siddiqi.

The charge against Rebollo is a violation of Title 18 USC Section 1030(a)(2)(A), "Exceeding Authorized Access to the Computer of a Financial Institution". The charge against Siddiqi is Title 18 USC Section 1028(a)(7), "Fraud and Related Activity in Connection with Identification Documents".


On July 7th, second Confidential Witness made consensually recorded telephone calls to "Nico" (Siddiqi) and ordered several thousand leads, negotiating a price of $4,000 for the data. He met with Nico on July 9th while wearing a wire, and received the data on CDs, which he loaded into an FBI undercover laptop, and got Nico to confirm that they were "fresh Countrywide" leads, and that they contained "full socials" (full social security numbers). He paid Nico the $4,000 in cash, provided by the FBI. Armed with this information, Ryan was ready to go interview Rebollo.

Rebollo was interviewed at his place of employment on July 15th by SA Ryan and SA Medrano. During the interview he confirmed the previous information about his weekly practice of stealing data by exporting it to a personal thumb drive. Rebollo actually opened a bank account at Washington Mutual "Doing Business As" RR Consulting. This account was specifically for receiving and holding the profits from his stolen data.

In the beginning, Rebollo would email the contents of his thumb drive to his buyers from a public computer at Kinko's. Frequently he would export data requested by his buyer, such as "new declines", or people who had a loan offered, but chose not to take the loan. Rebollo confirmed that he knew there was a company policy against sharing Lead Sources outside the company. He also confirmed that he knew that most CountryWide computers had a security feature which prevented the use of a thumb drive. He had found that he had access to one computer which did not have this feature.

According to the affadavit, on July 15th, Rebollo voluntarily turned over the flash drive he used to transport the data and the personal computer he used to broker the data. The flash drive had about "thirty to fifty" spreadsheets on it, each containing thousands of records with names, telephone numbers, addresses, and social security numbers of Countrywide applicants.

Rebollo agreed to sign a "CONSENT TO SEARCH" and to allow the FBI to follow him to his home and allowed them to take his thumb drive and his computer. He also printed many of the email messages showing that he had sent the stolen data from his home computer to various buyers.

Two days after SA Ryan returned to his office with Rebollo's computer and thumb drive, he was contacted by Rebollo's attorney who said their "Consent to Search" had been revoked.

Thanks for reading along . . . here comes the best part!

FIVE DAYS AFTER THAT, a Confidential Witness provided a recording from Rebollo, informing him that he was "camping at Mammoth" and implying he had data to sell. After consulting with the FBI, the CW called Rebollo back, in the presence of the FBI, and asked for 7,000 to 8,000 leads for customers in the states of California, Oregon, Florida, and New York. Rebollo agreed to provide the leads for $400. This a full week AFTER Rebollo had confessed everything to the FBI, lead them to his home, and offered them his thumb drive and computer!!!

Shortly after the call, an email, containing 8,000 leads, was received by the CW.

This second Affidavit, dated July 31st, was for permission to go back and do a court-ordered search (as opposed to the friendly "consent" search previously performed.)

Permission was granted.

Tuesday, July 29, 2008

FBI & Facebook: Storm Worm gets it all wrong!

The newest version of Storm is out again . . . this time making claims about the FBI and Facebook.

The virus-laden website looks like this:



The subjects of the spam email messages, according to UAB's Spam Data mine, include:

F.B.I. agents patrol Facebook
F.B.I. busts alleged Facebook
F.B.I. Facebook Records
F.B.I. Looks Into Facebook
F.B.I. may strike Facebook
F.B.I. on the Hunt for Facebook users
F.B.I. tries to fight Facebook
F.B.I. wants instant access to Facebook
F.B.I. Watching Hezbollah in Facebook
F.B.I. Watching Possible Terrorists on Facebook
F.B.I. watching us
F.B.I. watching you
Facebook Coming Under F.B.I. Scrutiny
Facebook Coming Under FBI Scrutiny
Facebook's F.B.I. ties
Facebook's FBI ties
FBI bypasses Facebook to nail you
FBI can watch our conversation through Facebook
FBI Facebook Crime Survey
FBI Facebook Records
FBI Looks Into Facebook
FBI may strike Facebook
FBI on the Hunt for Facebook users
FBI tries to fight Facebook
FBI wants instant access to Facebook
FBI Watching Hezbollah in Facebook
FBI Watching Possible Terrorists on Facebook
Get Facebook's F.B.I. Files
Get Facebook's FBI Files
The F.B.I. has a new way of tracking Facebook

Although the earliest versions of the spam pointed to websites by their domain name, including:

CAUTION! VIRUS SITES BELOW!



http://BestValueNews.com/
http://CompanyNewsNetwork.com/
http://FedNewsWorld.com/
http://GoodNewsGames.com/
http://SmartNewsRadio.com/
http://StockLowNews.com/
http://ToplessDailyNews.com/
http://ToplessNewsRadio.com/
http://WapDailyNews.com/

The most recent versions used an IP address instead, such as:

http://24.12.169.217/ Comcast (Chicago)
http://24.152.149.120/ Earthlink
http://24.207.187.180/ Charter Cable
http://64.53.204.29/ WideOpenWest (Naperville, Illinois)
http://67.33.128.195/ AT&T (Atlanta)
http://67.36.183.52/ AT&T (Chicago)
http://68.191.113.190/ Charter Cable
http://68.23.168.178/ AT&T (Chicago)
http://68.51.193.78/ Comcast (Savannah, GA)
http://69.154.54.244/ AT&T (Texas)
http://69.246.107.179/ Comcast (Michigan)
http://70.121.49.136/ Road Runner
http://75.48.238.18/ AT&T (Kalamazoo, Michigan)
http://75.72.106.94/ Comcast (Minnesota)
http://166.82.171.132/ Windstream (Little Rock, Arkansas)
http://208.104.248.17/ Rock Hill Telephone Company (Rock Hill, SC)
http://208.126.51.68/ Butler-Bremer Mutual Telephone (netINS, Inc)

As with most emerging viruses, coverage for this malware in the anti-virus community is quite pathetic at the moment. They will certainly catch up soon, but the current scan at VirusTotal revealed only SIX of Thirty-Three AV products could detect this virus. Detection was not present for any of the leading AV products, including McAfee, Symantec, and Trend Micro. Microsoft also fails to detect at this time.

To Understand the War on Terror: Read This

The handful of you who follow my annual book list know that in addition to my science fiction and haiku poetry diet, I read books on world politics, terrorism, and the intelligence community. I don't normally talk about them here, but this week I read a book that I believe would be a Must Read.





Ronald Kessler's book, The Terrorist Watch: Inside the Desperate Race To Stop the Next Attack could not have been written by anyone other than the columnist of The Washington Insider. As a long-time member of the FBI Fan Club, I was surprised by the things Kessler revealed that I simply didn't know about the Bureau and the War on Terror. Especially after his crucifixion of former FBI Director Louis Freeh (1993-2001) in his book "The Bureau: The Secret History of the FBI", I really hadn't imagined what a good friend of the Bureau Kessler could be.

Kessler takes a few current FBI Myths and jumps straight to the source, asking for, and getting, unprecedented access, including interviews in their environment, with Willie Hulon, then the Executive Assistant Director of the FBI's National Security Branch, Art Cummins, then the Deputy Director of the National Counterterrorism Center (he since took Willie's old job), FBI Director Robert Mueller, CIA Director Michael Hayden, and White House advisor on counterterrorism Fran Townsend, are just some of the highlights of his Who's Who in Counter Terrorism tour.

Myth: The CIA and FBI don't share information

Response: Kessler gives us a guided tour of the National CounterTerrorism Center (NCTC), spending a great deal of time on the layout of the 10,000 square-foot operations center which has the FBI's Counterterrorism Division watch center on one end, and the CIA's Counterterrorism Center's watch center on the other end. No walls separate the entire workspace, and Kessler explains in detail how the analysts from sixteen different intelligence agencies interact in the space, and share information to keep the "mother of all databases", the Terrorist Information Datamart Environment, up to date and synchronized with what is known by each of the intelligence agencies. In a chapter called "Dr. Strangelove", Kessler walks us through what happens in the daily "SVTCs" - the all agency briefings that are run from the NCTC at 8 AM, 3 PM, and 1 AM, seven days a week.

One of the biggest challenges to understand, and one that still receives a great deal of criticism, is how the FBI can go about being both an Intelligence Agency and a Law Enforcement Agency.

Kessler illustrates "the old thinking" vs. "the new thinking" this way . . . (quoting Art Cummings):


The director [Mueller] said, 'We've got this new mission. Its a prevention mission.'

Pre-9/11, the first consideration was, I got an indictment in my pocket . . . slap it down on the table, pick the guy up, throw him on an airplane...put him in jail and you go, 'Okay, I've done a great job today.'"


Through interviews with Philip Mudd, Art Cummings, Pat D'Amuro, and others, Kessler makes it clear that that is no longer the situation. Now the first concern, when the suspect has a possible terrorism connection, is intelligence gathering. The Bureau's unique approach to extracting intelligence, whether it be in months long "friendly interrogations", through human surveillance teams, or through "technical collection", were explained to a level rarely seen in a public work.

While its clear Kessler is in the Fan Club with me, he doesn't skirt around the challenges. He addresses FISA, National Security Letters, the Computer Incompetency of the Bureau (Sentinel and Virtual Case File), whether we'd be better off with an MI5 style agency, Gitmo, and the various media feeding frenzies.

Most books about the Intelligence Community and the War on Terror focus on government screw-ups, incompetencies, and secret agendas and have as their mission the undermining of the public's confidence in our government. It was refreshing to read Kessler's "insider look" offering an alternative view into these issues, and I hope others will join me in checking out this book.

Saturday, July 26, 2008

Top News in Spam = Old News

First, I wanted to say that I am appalled and saddened by the news that Eddie Davidson, the escaped convict who was serving time for spam has killed his wife and three year old child before committing suicide. Many of these spammers and cyber criminals are sick sociopaths who believe they are beyond the law, but its still sad news whenever innocent lives are taken. My prayers are with the family as they grieve.

For yet another day, the Top News in spam is Old News. The "News Headline" or "Video.exe" spammers continue to dominate our in boxes.

More than 90 compromised webservers have been used in this newest attack, which uses more than 90 new email subjects to trick the public into infecting themselves.

Each website contains the files:

topnews.html
00.html
dnd.js
master.js
master2.css

The file 00.html contains an encoded block of Javascript code, which, when uncoded reveals the hostile code downloader.

First the subjects:

"I Won't Raise Taxes," Says Schwarzenegger, "except For The Indians."
50 Cent sues Taco Bell
Apple nosedives on Jobs' death
Arnold Says im Gay Too!
Arnold Schwarzenegger to make movie
Astronauts Pose With The U.S. Snoopy
B52 bomber crashed in Hawaii
Batman is gay. Watch the proof.
Battle Of The Butts, J Lo V Britney Spears
Beijing Olympics cancelled
Bin Laden driver denies al Qaeda links
Black Panthers Sue White Guys For Stealing Copyrighted Gesture
Blair: Im Not Gay, Thats Just My Accent
Brave Suicide Bomber Survives Blast!
Britney and Justin are together again
Britney Clothed Photo Fury
Bush Accidentally Starts The War On Iran
Bush To Reporters: Fuck The Constitution
Bush 'Troubled' by Gay Marriages. Declares San Francisco Part of 'Axis of Evil'
Buy stocks now to make money
Cambodia declares war on foreigners
Cell phone use increases cancer
Clubs refuse to release players for Olympics
Courtney Love Vows To Wear Clothes
Earthquake in Japan kills millions
Ebay Lists Another Cheese Sandwich
Fat Chinese Man Kills And Eats Brother Because He Was Hungry
Ferguson fears Chelsea
Four Horsemen Of The Apocalypse Unveil New Alert System
French Have More Sex In Surveys Than Any Other Country
Gay Marriage Could Be Profitable
Gay Men Perceive Each Other As Homophobic
How to avoid paying credit cards
How To Break Up With Your Girl, Then Get Some Bootie Time!
Hurricane Dolly damages infrastructure
I Liked The Part When The French Got Their Asses Busted - G.W. Bush
Insider tips to these stocks
IT departments lauded for selling data
Join our weekly poker tournaments
Kidney stealing ring busted
Man gets pole stuck in handcuffs
McCain diagnosed with pancreatic cancer
McCain's health suspect
My Scrotum Is Getting Really Huge These Days
New betting tips for new season
New National Anthem Proposed By Bush
Obama bribes voters
Obama diagnosed with brain tumor
Obama engages rappers in election aid
Obama Is Anorexic Over-Exerciser
Obama withdraws support for Israel
Obama's mistress speaks up
Oil prices fall sharply
Osama caught sodomizing lieutenants
Osama Seen Dining At The Paris Ritz
Osama trains goats for tactical bombing
Pamela and Britney are lesbian lovers
Pamela Anderson To Sell Her Clothes; Announcement Causes Nationwide Frenzy
Please Baby, Give Me Another Chance
Possible Spam : Shocking Video Shows Spongebob And Gay Sex!
Prada gives fake bags to charity
Release Of The Nancy Pelosi Sex Dvd Causes Mass Erectile Dysfunction In Us
Richard Nixon Speaks From The Grave!
Right To Own Guns Upheld
Sarah Jessica Parker Arrested For Gross Negligee
School Board Adopts Gay-Ass Uniform Policy
Schwarzenegger reduces minimum wages
Scientists Create Prosthetic Brain
Shocking Video Shows Spongebob And Gay Sex!
South Korea goes to war over dead tourist
Spongebob Denies Reports That Hes Gay
Steve Jobs down with cancer
Steve Jobs to resign from Apple
Stock Markets Close As Global Earth World Planet International Buys All Shares
Studies show Americans love complaining
Studies show Europeans hate Asians
Studies show female bosses love flirting
Stupid millionaire gives huge tips
Stupid woman buys iPhone for 5000
Switzerland To Be Devoured By Black Hole
Terrorist bombs Philippines killing 30
Texans Do The Unthinkable
Theodore Roosevelt Was A Gay Man
Tiger Woods Will Call Next Son Monkey
Tupac Shakur Speaks Out From Beyond The Grave: "Stop Releasing My Stanky Old Songs"
WalMart declares bankruptcy
Woman chokes after swallowing Tiffany diamond
Woman found with bottle in vagina
Your tickets have been confirmed

If you are in control of any of hacked webservers, we would like very much to speak with you regarding the method of compromise. We are hearing that the servers are being compromised through FTP sessions, with a real FTP Password being used. Are these brute forces? have they "sniffed" the FTP password (which we should remember, should never be used, as it is sent across the internet in an unencrypted method!), or have they "keylogged" the FTP passwords from the users machines? We need to know!

We have looked up the "WHOIS" information on all of these domains and sent an email to each webmaster, asking for more details about their attack, and informing them of the bad content on their servers so they can get it cleaned up.

Sadly, many of these domains either do not have WHOIS information, or have expired email addresses, so even when we TRY to contact the webmaster, we are unable to do so without poring over their websites looking for contact information. If the WHOIS data were properly implemented, a simple program could inform all of these webmasters.

My favorite WHOIS data was for the domains beatmung-sachsen.eu, cmeedilizia.eu, and deliriuslaspalmas.com, which gave as the Administrative Contact:


This domain exists, but because the European Registry of Internet Domain Names (EURid) is, in our view, run by incompetent administrators who failed to properly manage the server, you cannot view the domain registration data unless you visit their Web site, www.whois.eu


Like the authors of that WHOIS data, I am not spending my time visiting the page.


http://afg.es/topnews.html
http://albertruiz.net/topnews.html
http://alim.co.il/topnews.html
http://allevatoritrotto.it/topnews.html
http://amafe.org/topnews.html
http://ambulatoriovirtuale.it/topnews.html
http://atelier-de-loulou.fr/topnews.html
http://automoviliaria.es/topnews.html
http://autoreserve.fr/topnews.html
http://bielizna.tgory.pl/topnews.html
http://blueseven.com.br/topnews.html
http://bollettinogiuridicosanitario.it/topnews.html
http://caprilchamonix.com.br/topnews.html
http://carlolongarini.it/topnews.html
http://champimousse.com/topnews.html
http://cheviot.org.nz/topnews.html
http://contrapie.com/topnews.html
http://corradiproject.info/topnews.html
http://dantealighieriasturias.es/topnews.html
http://deliriuslaspalmas.com/topnews.html
http://ecchoppers.co.za/topnews.html
http://elianacaminada.net/topnews.html
http://fonavistas.com/topnews.html
http://fraemma.com/topnews.html
http://fundmyira.com/topnews.html
http://galvatoledo.com/topnews.html
http://grafisch-ontwerpburo.nl/topnews.html
http://gruppouni.com/topnews.html
http://hausfeld-solar.de/topnews.html
http://herbatele.com/topnews.html
http://houseincostaricaforsale.com/topnews.html
http://izliyorum.org/topnews.html
http://jureplaninc-sp.com/topnews.html
http://kwhgs.ca/topnews.html
http://lapiramidecoslada.es/topnews.html
http://last-minute-reisen-4u.de/topnews.html
http://marcadina.fr/topnews.html
http://maremax.it/topnews.html
http://markmaverick.com/topnews.html
http://micela.info/topnews.html
http://motoclubnosvamos.com/topnews.html
http://nebottorrella.com/topnews.html
http://negozistore.it/topnews.html
http://neticon.pl/topnews.html
http://norbert-leifheit.gmxhome.de/topnews.html
http://ocoartefatos.com.br/topnews.html
http://omdconsulting.es/topnews.html
http://parapendiolestreghe.it/topnews.html
http://positive-begegnungen.de/topnews.html
http://projetsoft.net/topnews.html
http://rbc.gmxhome.de/topnews.html
http://segelclub-honau.de/topnews.html
http://snmobilya.com/topnews.html
http://splashcor.com.br/topnews.html
http://stephanmager.gmxhome.de/topnews.html
http://svcanvas.com/topnews.html
http://tautau.web.simplesnet.pt/topnews.html
http://textilhogarnovadecor.com/topnews.html
http://theflorist4u.com/topnews.html
http://thewindsorhotel.it/topnews.html
http://vuelosultimahora.com/topnews.html
http://www.aliarzani.de/topnews.html
http://www.ambermarketing.com/topnews.html
http://www.arnold82.gmxhome.de/topnews.html
http://www.beatmung-sachsen.eu/topnews.html
http://www.campodifiori.it/topnews.html
http://www.clickjava.net/topnews.html
http://www.cmeedilizia.eu/topnews.html
http://www.dammer.info/topnews.html
http://www.embedded-silicon.de/topnews.html
http://www.ferrariclubpesaro.it/topnews.html
http://www.fgwiese.de/topnews.html
http://www.fswash.site.br.com/topnews.html
http://www.fytema.es/topnews.html
http://www.gildas-saliou.com/topnews.html
http://www.go-art-morelli.de/topnews.html
http://www.go-siegmund.de/topnews.html
http://www.guerrero-tuning.com/topnews.html
http://www.gut-barbarastein.de/topnews.html
http://www.japansec.com/topnews.html
http://www.komma10-thueringen.de/topnews.html
http://www.koon-design.de/topnews.html
http://www.lanz-volldiesel.de/topnews.html
http://www.lauscher-staat.de/topnews.html
http://www.losnaranjos.com.es/topnews.html
http://www.medical-service-krause.de/topnews.html
http://www.nakedinbed.co.uk/topnews.html
http://www.nepi.si/topnews.html
http://www.radieschenhein.de/topnews.html
http://www.residenceflora.it/topnews.html
http://www.sabuha.de/topnews.html
http://www.ser-all.com/topnews.html
http://www.siemieniewicz.de/topnews.html
http://www.viajesk.es/topnews.html