After monitoring the Waledac "infection domains" for more than a month, our last "interesting" event was the change in Look & Feel to the SMS Spy Program which we wrote about back on April 15th. In that blog article we mentioned that basically ALL of the domains used by Waledac, through the Valentine's Day campaign, the Couponizer campaign, the Terror Alert campaign, and the SMS Spy campaign, were all still alive!
Here's the newest change. ALL of the Waledac infection domains have now morphed into pill sites, and MANY of the older Waledac domains have finally been terminated.
Here's where stand with live FORMER Waledac domains. Many domains from the "Terror Alert" and "SMS Spy" alert are now forwarding on a random basis to domains which are either hosting Canadian Pharmacy or Canadian Health & Care Mall.
Of the Waledac domains that we were tracking, the following are now live forwarding domains:
antiterroralliance.com
blogginhell.com
blogsitedirect.com
boarddiary.com
discountfreesms.com
downloadfreesms.com
eccellentesms
fearalert.com
freecolorsms.com
freesmsorange.com
ipersmstext.com
nuovosmsclub.com
primosmsfree.com
smsclubnet.com
smsinlinea.com
smsluogo.com
superioresms.com
terroralertstatus.com
virtualesms.com
"Canadian Health & Care mall" at arzuhuxupi.com
"Canadian Health & Care Mall" at rahtydryo.com
"Canadian Health & Care mall" at vennocvajgo.com
"Canadian Pharmacy" at earpassionate.com
"Canadian Pharmacy" at transformationforgiving.com
"Canadian Pharmacy" at giftedaglow.com
"Canadian Pharmacy" at strivingalive.com
The following Waledac domains now appear to be terminated:
adorepoem.com
adoresong.com
adoresongs.com
againstfear.com
bestadore.com
bestbreakingfree.com
bestcouponfree.com
bestgoodnews.com
bestlovehelp.com
bestlovelong.com
bluevalentineonline.com
breakingfreemichigan.com
breakinggoodnews.com
breakingkingnews.com
breakingnewsfm.com
breakingnewsltd.com
chatloveonline.com
cherishletter.com
cherishpoems.com
codecouponsite.com
funloveonline.com
funnyvalentinessite.com
goodnewsdigital.com
goodnewsreview.com
greatcouponclub.com
greatsalesgroup.com
greatsalestax.com
greatsvalentine.com
greatvalentinepoems.com
linkworldnews.com
lovecentralonline.com
lovelifeportal.com
reportradio.com
romanticsloving.com
smartsalesgroup.com
spacemynews.com
supersalesonline.com
thecoupondiscount.com
thevalentinelovers.com
tntbreakingnews.com
wapcitynews.com
whocherish.com
wirelessvalentineday.com
worldlovelife.com
worldnewsdot.com
worshiplove.com
worldtracknews.com
youradore.com
yourbreakingnews.com
yourcountycoupon.com
yourgreatlove.com
yourvalentinepoems.com
Wednesday, April 29, 2009
Tuesday, April 21, 2009
President Obama's CTO: Aneesh Chopra
Like so many others who were playing the guessing game regarding President Obama's new CTO, I was wrong. I take comfort in failing along with BusinessWeek, ZDNet, Forbes, TheStreet, The Wall Street Journal and others to guess who would fill the office.
We might have taken a hint from one of President Obama's recent speeches to Congress, where he said:
"Our recovery plan will invest in electronic health records and new technology that will reduce errors, bring down costs, ensure privacy, and save lives."
-- (Transcript 24FEB09
Aneesh Chopra's bio on his Virginia website points out that he chairs the "Solutions Committee of the IT Investment Board, the Effectiveness and Efficiency Committee on the Council on Virginia's Future, and co-chairs the Healthcare IT Council". He was awarded the Healthcare Information and Management Systems Society's 2007 State Leadership Advocacy Award, and was named one of the top 25 by Government Technology magazine's Doers, Dreamers, and Drivers magazine.
In 2006, ExecutiveBiz.com interviewed Mr. Chopra on his new position as Secretary of Technology for the Commonwealth of Virginia. His answer to the question "What is your background?" lines up well with President Obama's vision for secure electronic healthcare records:
ExecutiveBiz: What is your background?
Aneesh Chopra: Professionally, I am a managing director at a think tank with a focus for the health care industry, but a big portion of my professional background has been studying ways that technology can fundamentally transform the healthcare industry in particular. Also, I internally helped launched the Advisory Board's first software-based membership business. So not only have I been researching technology and how I can benefit the healthcare industry, I have been business development wise active in the use of technology to grow our own business.
It was clear from his work in the job though that Health Care was not his only focus. Here were some answers regarding educational technology, another area on which the Secretary turned his attention while in office in Virginia, from one of the 46 Podcasts his office put out during his time there: (03/25/09 - Secretary Chopra discusses technology in the classroom --
We have an innovation imperative in the Commonwealth, and frankly for the country, and it requires us to think anew about how we produce students who are globally competitive. There are three basic questions we have to ask:
What are we actually teaching our kids?
How are we teaching our kids?
What are the tools with which we can allow the sharing ideas and the process of learning how to teach our kids?
In each of these areas there is a place for technology to play a role, in some cases a direct role, and in other cases more of an indirect role.
In his 2007 Accomplishments podcast (January 9, 2008) he stressed three Public/Private Partnerships, including:
a Google partnership to produce Google SiteMaps of 55 government websites, mapping more than 200,000 state webpages to increase their ability
Microsoft Virtual Earth helped create Campus Safety maps to help identify resources and plans for various emergencies on campus as a reaction to school shootings.
Cox and Comcast Cable began offering "GED On Demand" for free to more than 1 million broadband subscribers in Virginia.
1 of 3 new jobs created in Virginia came from high-tech jobs, and 30% of all wage-earners in Virginia received their pay from a technology related job.
5 innovators in HealthCare IT, 3 of which provided an 8-fold return on the investment. The Virginia HealthCare Exchange Network was created as part of the initiative.
Many other initiatives were described, making this podcast well worth listening to in order to learn more about how our nation's new CTO thinks about Technology. Many of these initiatives were grant-generated, by placing challenges into the community and asking for innovators who have solutions to step forward to address government productivity, broadband, and government IT.
To summarize what I see about Aneesh Chopra - he's proven that he knows how to solicit ideas from innovators, shape them into actual solutions, and roll them out as successful products. He did it in the business world, he did it in his HealthCare IT think tank, and he did it for the State of Virginia. I look forward to seeing what he can do for our nation.
I'm especially interested to see what types of reforms a technology thinker can bring to our Criminal Justice systems! At UAB Computer Forensics our partnership between Computer Science and Justice Science is based on the concept that when Computer Scientists are presented with Criminal Justice problems, good technology things can happen. Hopefully this will be one of our new CTO's priority areas as well.
Wednesday, April 15, 2009
Waledac shifts to SMS Spy program
We've known that Waledac spreads itself via Social Engineering - convincing users that they WANT to download a program. Recently we've seen Waledac acting as a Valentine's Day E-Card, a Couponizer program, and a Fake News Story about a Dirty Bomb.
Today the UAB Spam Data Mine began to get spam messages for a new Social Engineering trick. Here are some of the email subjects we're seeing:
Subjects
-----------
Read his SMS
The world's most advanced sms reading program
Now, It's possible to read other people's SMS
Read other people's SMS online
You can read anyone's SMS
The email bodies point to the websites with lines like these:
Do you trust her? http://smsclubnet.com/
You can read anyone's SMS http://virtualesms.com
Do you really trust her? http://www.freecolorsms.com
Do you really trust him? http://downloadfreesms.com/
Are you ready to know the truth? http://smsclubnet.com
Are you sure you want to know? http://smsclubnet.com
The webpage you visit looks like this:

The malware which you can download from the page is recognized by 13 of the 39 Anti-Virus products tested according to this VirusTotal Report.
File size: 419840 bytes
MD5...: 8623f18666be9d480710b29eab3b796a
The root problem with Waledac's long-lived domains is they are using a Chinese domain name registrar who won't cooperate with anyone on shutdowns. We have sent shutdown requests to their abuse contact, in both English and Chinese, and have received no cooperation whatsoever. If you have good contact information for "Ename.com", we really could use an introduction, thank you! No one answers their "1000@ename.com" email address, but perhaps a Chinese speaker might call them at +86.5922669769 ? ? ?
The complete list of NEW domain names created for this round of Waledac are:
smspianeta.com
miosmsclub.com
downloadfreesms.com
virtualesms.com
chinamobilesms.com
freeservesms.com
freecolorsms.com
smsclubnet.com
But a great number of the previous domains are also still live, and still serving Waledac, including:
adoresongs.com
antiterroris.com
bestadore.com
bestcouponfree.com
bestjournalguide.com
bestlifeblog.com
bestlovehelp.com
bestlovelong.com
bestusablog.com
bluevalentineonline.com
breakingnewsltd.com
chatloveonline.com
cherishletter.com
codecouponsite.com
easyworldnews.com
funloveonline.com
funnyvalentinessite.com
goodnewsdigital.com
goodnewsreview.com
greatcouponclub.com
greatsalesgroup.com
greatsvalentine.com
lovecentralonline.com
lovelifeportal.com
mobilephotoblog.com
photoblogsite.com
romanticsloving.com
spacemynews.com
thecoupondiscount.com
thevalentinelovers.com
tntbreakingnews.com
urbanfear.com
usabreakingnews.com
wirelessvalentineday.com
worldlovelife.com
worshiplove.com
youradore.com
yourgreatlove.com
yourvalentineday.com
yourvalnetinepoems.com
If you have contact at Ename.com, these ALL need killed, thank you! They are all now distributing the new "SMS Spy" version of Waledac.
Today the UAB Spam Data Mine began to get spam messages for a new Social Engineering trick. Here are some of the email subjects we're seeing:
Subjects
-----------
Read his SMS
The world's most advanced sms reading program
Now, It's possible to read other people's SMS
Read other people's SMS online
You can read anyone's SMS
The email bodies point to the websites with lines like these:
Do you trust her? http://smsclubnet.com/
You can read anyone's SMS http://virtualesms.com
Do you really trust her? http://www.freecolorsms.com
Do you really trust him? http://downloadfreesms.com/
Are you ready to know the truth? http://smsclubnet.com
Are you sure you want to know? http://smsclubnet.com
The webpage you visit looks like this:

The malware which you can download from the page is recognized by 13 of the 39 Anti-Virus products tested according to this VirusTotal Report.
File size: 419840 bytes
MD5...: 8623f18666be9d480710b29eab3b796a
The root problem with Waledac's long-lived domains is they are using a Chinese domain name registrar who won't cooperate with anyone on shutdowns. We have sent shutdown requests to their abuse contact, in both English and Chinese, and have received no cooperation whatsoever. If you have good contact information for "Ename.com", we really could use an introduction, thank you! No one answers their "1000@ename.com" email address, but perhaps a Chinese speaker might call them at +86.5922669769 ? ? ?
The complete list of NEW domain names created for this round of Waledac are:
smspianeta.com
miosmsclub.com
downloadfreesms.com
virtualesms.com
chinamobilesms.com
freeservesms.com
freecolorsms.com
smsclubnet.com
But a great number of the previous domains are also still live, and still serving Waledac, including:
adoresongs.com
antiterroris.com
bestadore.com
bestcouponfree.com
bestjournalguide.com
bestlifeblog.com
bestlovehelp.com
bestlovelong.com
bestusablog.com
bluevalentineonline.com
breakingnewsltd.com
chatloveonline.com
cherishletter.com
codecouponsite.com
easyworldnews.com
funloveonline.com
funnyvalentinessite.com
goodnewsdigital.com
goodnewsreview.com
greatcouponclub.com
greatsalesgroup.com
greatsvalentine.com
lovecentralonline.com
lovelifeportal.com
mobilephotoblog.com
photoblogsite.com
romanticsloving.com
spacemynews.com
thecoupondiscount.com
thevalentinelovers.com
tntbreakingnews.com
urbanfear.com
usabreakingnews.com
wirelessvalentineday.com
worldlovelife.com
worshiplove.com
youradore.com
yourgreatlove.com
yourvalentineday.com
yourvalnetinepoems.com
If you have contact at Ename.com, these ALL need killed, thank you! They are all now distributing the new "SMS Spy" version of Waledac.
Monday, April 13, 2009
New Drug sites avoid Visa and MasterCard, Sell Hydrocodone
Those who research Pharmaceutical spam have learned that there are basically two major classes of drugs. Those which the Feds care about stopping (Controlled substances monitored by the DEA) and those the Feds are happy to ignore, and which they call dismissingly "Lifestyle Drugs".
Its quite frustrating in light of the fact that, as Microsoft pointed out recently in their semi-annual report on Internet safety, 97% of the email on the Internet is spam, and HALF of that email is pharmaceutical spam. For someone to decide that its not worth investigating lifestyle drugs (by which they mean Viagra, Cialis, and other sexual-experience related drugs) as vigorously as we investigate "Controlled Substances" has lead to our current status on the Internet as a world flooded with absolutely uncontrolled drug spam.
Nevertheless, knowing that there is a two-tiered system of investigation related to pharmaceutical spam, we've all learned that the way to get action is to point out sites that are selling things that are on the Class I, Class II, Class III, or Class IV Controlled Substance List.
Side Note - if you are looking for a Computer Forensics Research program interested in making an impact on pharmaceutical spam, that has as partners in its "Computer Science/Justice Science Working Group" forensic criminologists with their own Gas Chromotography Mass Spectrometer (GS/MS), and faculty and grad students trained in its use, please look no further than the University of Alabama at Birmingham.
That's one of the two reasons why this new spam cluster is especially interesting to me. We have more than 1450 spam emails in the UAB Spam Data Mine during March and another 1,069 so far during April that contain the word "Hydrocodone" in either the body or the subject. The subject line in today's case actually says "Hydrocodone For You", and pointed to a pharmacy site here:
http://show-advanced-individual.com/

which leads with Hydrocodone, Vicodin, Phentermine, Ambien, Valium, and Levitra. They have quite a few alternate payment methods, but most notably they do NOT accept Visa or Mastercard:




By accepting electronic checks, direct bank transfers, and Western Union payments, these dealers in fake drugs can move their money even faster than they move their drugs. The world of money laundering possibilities opens wide once you get Visa and MasterCard off the option list. That should also make it pretty clear to the potential buyers. This vendor wants to move your money Quickly, Untraceably, and most importantly Irreversibly. They want to make sure they get your money NOW, even though you may (or may not) get your drugs later, and that even if you do NOT got your drugs, there is no way your going to get your money back, or even figure out where your money went.
This particular domain was registered on March 20th via XIN NET Technology.
The IP is at 116.125.56.218 - Hanaro telecom, Korea
This is not a new IP address to us at the UAB Spam Data Mine.
March 23 - 116.125.56.218 (1 spammed domain)
March 24 - 116.125.56.218 (13 spammed domains)
March 25 - 116.125.56.218 (16 spammed domains)
March 26 - 116.125.56.218 (50 spammed domains)
March 27 - 116.125.56.218 (42 spammed domains)
March 28 - 116.125.56.218 (42 spammed domains)
March 29 - 116.125.56.218 (42 spammed domains)
March 30 - 116.125.56.218 (64 spammed domains)
March 31 - 116.125.56.218 (75 spammed domains)
(I'll update those stats with April data once its been caught up...)
The Hotmail address in the whois data is = na506@hotmail.com
Two hundred other hyphenated domain names are on the same Hanaro IP address, according to DomainTools:
Approach-amazing-day.com
Approach-amazing-year.com
Approach-coming-human.com
Approach-delightful-2009.com
Approach-delightful-memory.com
Approach-delightful-species.com
Approach-emotive-creature.com
Approach-emotive-kind.com
Approach-fresh-month.com
Approach-hopeful-second.com
Approach-hot-blooded-2009.com
Approach-hot-blooded-year.com
Approach-new-2009.com
Approach-nice-2009.com
Approach-pretty-hour.com
Approach-touched-second.com
Approachamazinghour.com
Approachdelightfulhour.com
Approachhopeful2009.com
Approachmysteriousspecies.com
Approachprettyyear.com
Approachsucessfulcreature.com
Cherish-coming-creature.com
Cherish-eminent-species.com
Cherish-emotive-species.com
Cherish-fresh-day.com
Cherish-hot-blooded-minute.com
Cherish-hot-blooded-year.com
Cherish-mysterious-month.com
Cherish-nice-creature.com
Cherish-pretty-second.com
Cherish-sucessful-kind.com
Cherishamazingminute.com
Cherishcomingmemory.com
Cherisheminenthuman.com
Cherishemotive2009.com
Cherishemotivebeing.com
Cherishfreshbeing.com
Cherishhopefulhuman.com
Cherishmysteriouskind.com
Cherishprettysecond.com
Cherishsurprisingkind.com
Enjoy-beautiful-second.com
Enjoy-coming-month.com
Enjoy-delightful-species.com
Enjoy-eminent-human.com
Enjoy-exciting-month.com
Enjoy-hot-blooded-human.com
Enjoy-pretty-memory.com
Enjoyaffectingsecond.com
Enjoybeautifulsecond.com
Enjoydelightfulsecond.com
Enjoyfreshyear.com
Enjoyhot-bloodedmonth.com
Enjoyniceyear.com
Enjoysucessful2009.com
Feel-sucessful-day.com
Feel-sucessful-hour.com
Feel-surprising-second.com
Feelhopefulmemory.com
Feelhopefulminute.com
Feelsucessfulsecond.com
Feelsurprisingmemory.com
Greet-amazing-human.com
Greet-amazing-kind.com
Greet-delightful-species.com
Greet-delightful-year.com
Greet-fresh-creature.com
Greet-nice-creature.com
Greet-nice-memory.com
Greet-sucessful-being.com
Greetamazingmemory.com
Greeteminentsecond.com
Greethot-bloodedcreature.com
Greethot-bloodedkind.com
Greethot-bloodedmemory.com
Greetnewspecies.com
Guide-developping-block.com
Guide-developping-corporation.com
Guide-developping-urban-area.com
Guide-incorruptible-institution.com
Guide-upright-individual.com
Guide-well-behaved-street.com
Guidedeveloppingblock.com
Guidedeveloppingcompany.com
Guidedeveloppinglane.com
Guideincorruptiblesquare.com
Guideopenstreet.com
Guidereliableinstitution.com
Guidewell-behavedcountry.com
Guidewell-behavedurban-area.com
Meet-amazing-minute.com
Meet-exciting-kind.com
Meet-fresh-being.com
Meet-hot-blooded-minute.com
Meet-pretty-being.com
Meetamazingmonth.com
Meetamazingsecond.com
Meetcomingbeing.com
Meetcomingcreature.com
Meetdelightfulhour.com
Meetemotivecreature.com
Meetexciting2009.com
Meethot-bloodedbeing.com
Meetsucessfulcreature.com
Meetsucessfulday.com
Meetsurprisingcreature.com
Meetsurprisingsecond.com
Reveal-advanced-corporation.com
Reveal-advanced-lane.com
Reveal-advanced-street.com
Reveal-civilized-country.com
Reveal-civilized-urban-area.com
Reveal-clean-institution.com
Reveal-developping-lane.com
Reveal-educational-unit.com
Reveal-frugal-alley.com
Reveal-neat-entreprise.com
Reveal-neat-institution.com
Reveal-peaceful-country.com
Reveal-spiritual-lane.com
Reveal-spiritual-street.com
Reveal-upright-organization.com
Reveal-upright-street.com
Reveal-well-behaved-corporation.com
Reveal-well-behaved-urban-area.com
Revealadvancedcompany.com
Revealadvancedindividual.com
Revealadvancedunit.com
Revealcivilizedentreprise.com
Revealcivilizedindividual.com
Revealculturalcity.com
Revealculturalstreet.com
Revealculturalunit.com
Revealdeveloppingcity.com
Revealincorruptibleindividual.com
Revealpeacefulunit.com
Revealreliableinstitution.com
Revealspiritualblock.com
Revealspiritualdistrict.com
Revealspiritualentreprise.com
Revealspiritualurban-area.com
Share-affecting-year.com
Share-amazing-species.com
Share-amazing-year.com
Share-beautiful-species.com
Share-beautiful-year.com
Share-coming-year.com
Share-delightful-kind.com
Share-eminent-being.com
Share-eminent-hour.com
Share-emotive-being.com
Share-emotive-minute.com
Share-fresh-2009.com
Share-pretty-creature.com
Share-sucessful-human.com
Share-surprising-2009.com
Share-surprising-year.com
Share-touched-year.com
Shareaffectingcreature.com
Shareaffectingmemory.com
Sharehopefulmonth.com
Sharemysterious2009.com
Shareprettycreature.com
Sharesucessfulday.com
Sharesurprisingminute.com
Show-advanced-individual.com
Show-civilized-entreprise.com
Show-civilized-organization.com
Show-civilized-square.com
Show-clean-block.com
Show-educational-citizen.com
Show-educational-corporation.com
Show-harmonious-mechanism.com
Show-harmonious-organization.com
Show-neat-urban-area.com
Show-spiritual-block.com
Show-tidy-lane.com
Show-upright-urban-area.com
Showadvancedurban-area.com
Showcleanentreprise.com
Showincorruptiblecountry.com
Showpeacefulorganization.com
Showtidyorganization.com
Showwell-behavedsquare.com
Treat-affecting-being.com
Treat-amazing-2009.com
Treat-beautiful-creature.com
Treat-exciting-year.com
Treat-fresh-memory.com
Treat-hot-blooded-second.com
Treat-mysterious-minute.com
Treat-surprising-memory.com
Treat-touched-kind.com
Treat-touched-month.com
Treathopefulday.com
Treathot-bloodedhour.com
Treatsucessful2009.com
Uideharmoniousalley.com
Welove-supersale.com
Over the weekend, a new Hydrocodone cluster emerged, distinct from the one above.
The new cluster used the following domain names in more than 1500 emails just over the last weekend:
aoisiis.com
aposoos.com
apsppew.com
blotbump.com
blotcare.com
blotcool.com
bumpflow.com
bumpfold.com
candark.com
canword.com
celitrre.com
dealrise.com
debaiteo.com
domefast.com
domerests.com
dometake.com
esperros.com
fecioos.com
felippie.com
fullmage.com
fullmeed.com
fullmend.com
fullruse.com
kaiffelt.com
lungsse.com
macrsoku.com
maghiarr.com
mailldeo.com
maingive.com
maltfame.com
maltfire.com
maltflip.com
maltlike.com
maltmain.com
maltmalts.com
maltplay.com
malttall.com
malttilts.com
marnarq.com
masciake.com
naryneat.com
nowdark.com
nowwall.com
pionname.com
pionnary.com
pionpick.com
pionrise.com
pollsies.com
ppoleiw.com
qalsibbe.com
qaselict.com
realpin.com
riennsi.com
ropeww.com
rpeusw.com
spoeii.com
tehsui.com
wallmay.com
wallrise.com
wallsdeals.com
wesleos.com
wposlles.com
yehsuue.com
The new cluster looks like another Viagra site at first:

but scrolling down, we see it really is selling Hydrocodone and other Class II and Class III Controlled Substances:

As with the first cluster we mention, Visa and MasterCard are conspicuously missing from this site. It now accepts ONLY American Express:

Fortunately, they are concerned about the High Incidence of Fraud. 8-) Haha!
Its quite frustrating in light of the fact that, as Microsoft pointed out recently in their semi-annual report on Internet safety, 97% of the email on the Internet is spam, and HALF of that email is pharmaceutical spam. For someone to decide that its not worth investigating lifestyle drugs (by which they mean Viagra, Cialis, and other sexual-experience related drugs) as vigorously as we investigate "Controlled Substances" has lead to our current status on the Internet as a world flooded with absolutely uncontrolled drug spam.
Nevertheless, knowing that there is a two-tiered system of investigation related to pharmaceutical spam, we've all learned that the way to get action is to point out sites that are selling things that are on the Class I, Class II, Class III, or Class IV Controlled Substance List.
Side Note - if you are looking for a Computer Forensics Research program interested in making an impact on pharmaceutical spam, that has as partners in its "Computer Science/Justice Science Working Group" forensic criminologists with their own Gas Chromotography Mass Spectrometer (GS/MS), and faculty and grad students trained in its use, please look no further than the University of Alabama at Birmingham.
That's one of the two reasons why this new spam cluster is especially interesting to me. We have more than 1450 spam emails in the UAB Spam Data Mine during March and another 1,069 so far during April that contain the word "Hydrocodone" in either the body or the subject. The subject line in today's case actually says "Hydrocodone For You", and pointed to a pharmacy site here:
http://show-advanced-individual.com/

which leads with Hydrocodone, Vicodin, Phentermine, Ambien, Valium, and Levitra. They have quite a few alternate payment methods, but most notably they do NOT accept Visa or Mastercard:




By accepting electronic checks, direct bank transfers, and Western Union payments, these dealers in fake drugs can move their money even faster than they move their drugs. The world of money laundering possibilities opens wide once you get Visa and MasterCard off the option list. That should also make it pretty clear to the potential buyers. This vendor wants to move your money Quickly, Untraceably, and most importantly Irreversibly. They want to make sure they get your money NOW, even though you may (or may not) get your drugs later, and that even if you do NOT got your drugs, there is no way your going to get your money back, or even figure out where your money went.
This particular domain was registered on March 20th via XIN NET Technology.
The IP is at 116.125.56.218 - Hanaro telecom, Korea
This is not a new IP address to us at the UAB Spam Data Mine.
March 23 - 116.125.56.218 (1 spammed domain)
March 24 - 116.125.56.218 (13 spammed domains)
March 25 - 116.125.56.218 (16 spammed domains)
March 26 - 116.125.56.218 (50 spammed domains)
March 27 - 116.125.56.218 (42 spammed domains)
March 28 - 116.125.56.218 (42 spammed domains)
March 29 - 116.125.56.218 (42 spammed domains)
March 30 - 116.125.56.218 (64 spammed domains)
March 31 - 116.125.56.218 (75 spammed domains)
(I'll update those stats with April data once its been caught up...)
The Hotmail address in the whois data is = na506@hotmail.com
Two hundred other hyphenated domain names are on the same Hanaro IP address, according to DomainTools:
Approach-amazing-day.com
Approach-amazing-year.com
Approach-coming-human.com
Approach-delightful-2009.com
Approach-delightful-memory.com
Approach-delightful-species.com
Approach-emotive-creature.com
Approach-emotive-kind.com
Approach-fresh-month.com
Approach-hopeful-second.com
Approach-hot-blooded-2009.com
Approach-hot-blooded-year.com
Approach-new-2009.com
Approach-nice-2009.com
Approach-pretty-hour.com
Approach-touched-second.com
Approachamazinghour.com
Approachdelightfulhour.com
Approachhopeful2009.com
Approachmysteriousspecies.com
Approachprettyyear.com
Approachsucessfulcreature.com
Cherish-coming-creature.com
Cherish-eminent-species.com
Cherish-emotive-species.com
Cherish-fresh-day.com
Cherish-hot-blooded-minute.com
Cherish-hot-blooded-year.com
Cherish-mysterious-month.com
Cherish-nice-creature.com
Cherish-pretty-second.com
Cherish-sucessful-kind.com
Cherishamazingminute.com
Cherishcomingmemory.com
Cherisheminenthuman.com
Cherishemotive2009.com
Cherishemotivebeing.com
Cherishfreshbeing.com
Cherishhopefulhuman.com
Cherishmysteriouskind.com
Cherishprettysecond.com
Cherishsurprisingkind.com
Enjoy-beautiful-second.com
Enjoy-coming-month.com
Enjoy-delightful-species.com
Enjoy-eminent-human.com
Enjoy-exciting-month.com
Enjoy-hot-blooded-human.com
Enjoy-pretty-memory.com
Enjoyaffectingsecond.com
Enjoybeautifulsecond.com
Enjoydelightfulsecond.com
Enjoyfreshyear.com
Enjoyhot-bloodedmonth.com
Enjoyniceyear.com
Enjoysucessful2009.com
Feel-sucessful-day.com
Feel-sucessful-hour.com
Feel-surprising-second.com
Feelhopefulmemory.com
Feelhopefulminute.com
Feelsucessfulsecond.com
Feelsurprisingmemory.com
Greet-amazing-human.com
Greet-amazing-kind.com
Greet-delightful-species.com
Greet-delightful-year.com
Greet-fresh-creature.com
Greet-nice-creature.com
Greet-nice-memory.com
Greet-sucessful-being.com
Greetamazingmemory.com
Greeteminentsecond.com
Greethot-bloodedcreature.com
Greethot-bloodedkind.com
Greethot-bloodedmemory.com
Greetnewspecies.com
Guide-developping-block.com
Guide-developping-corporation.com
Guide-developping-urban-area.com
Guide-incorruptible-institution.com
Guide-upright-individual.com
Guide-well-behaved-street.com
Guidedeveloppingblock.com
Guidedeveloppingcompany.com
Guidedeveloppinglane.com
Guideincorruptiblesquare.com
Guideopenstreet.com
Guidereliableinstitution.com
Guidewell-behavedcountry.com
Guidewell-behavedurban-area.com
Meet-amazing-minute.com
Meet-exciting-kind.com
Meet-fresh-being.com
Meet-hot-blooded-minute.com
Meet-pretty-being.com
Meetamazingmonth.com
Meetamazingsecond.com
Meetcomingbeing.com
Meetcomingcreature.com
Meetdelightfulhour.com
Meetemotivecreature.com
Meetexciting2009.com
Meethot-bloodedbeing.com
Meetsucessfulcreature.com
Meetsucessfulday.com
Meetsurprisingcreature.com
Meetsurprisingsecond.com
Reveal-advanced-corporation.com
Reveal-advanced-lane.com
Reveal-advanced-street.com
Reveal-civilized-country.com
Reveal-civilized-urban-area.com
Reveal-clean-institution.com
Reveal-developping-lane.com
Reveal-educational-unit.com
Reveal-frugal-alley.com
Reveal-neat-entreprise.com
Reveal-neat-institution.com
Reveal-peaceful-country.com
Reveal-spiritual-lane.com
Reveal-spiritual-street.com
Reveal-upright-organization.com
Reveal-upright-street.com
Reveal-well-behaved-corporation.com
Reveal-well-behaved-urban-area.com
Revealadvancedcompany.com
Revealadvancedindividual.com
Revealadvancedunit.com
Revealcivilizedentreprise.com
Revealcivilizedindividual.com
Revealculturalcity.com
Revealculturalstreet.com
Revealculturalunit.com
Revealdeveloppingcity.com
Revealincorruptibleindividual.com
Revealpeacefulunit.com
Revealreliableinstitution.com
Revealspiritualblock.com
Revealspiritualdistrict.com
Revealspiritualentreprise.com
Revealspiritualurban-area.com
Share-affecting-year.com
Share-amazing-species.com
Share-amazing-year.com
Share-beautiful-species.com
Share-beautiful-year.com
Share-coming-year.com
Share-delightful-kind.com
Share-eminent-being.com
Share-eminent-hour.com
Share-emotive-being.com
Share-emotive-minute.com
Share-fresh-2009.com
Share-pretty-creature.com
Share-sucessful-human.com
Share-surprising-2009.com
Share-surprising-year.com
Share-touched-year.com
Shareaffectingcreature.com
Shareaffectingmemory.com
Sharehopefulmonth.com
Sharemysterious2009.com
Shareprettycreature.com
Sharesucessfulday.com
Sharesurprisingminute.com
Show-advanced-individual.com
Show-civilized-entreprise.com
Show-civilized-organization.com
Show-civilized-square.com
Show-clean-block.com
Show-educational-citizen.com
Show-educational-corporation.com
Show-harmonious-mechanism.com
Show-harmonious-organization.com
Show-neat-urban-area.com
Show-spiritual-block.com
Show-tidy-lane.com
Show-upright-urban-area.com
Showadvancedurban-area.com
Showcleanentreprise.com
Showincorruptiblecountry.com
Showpeacefulorganization.com
Showtidyorganization.com
Showwell-behavedsquare.com
Treat-affecting-being.com
Treat-amazing-2009.com
Treat-beautiful-creature.com
Treat-exciting-year.com
Treat-fresh-memory.com
Treat-hot-blooded-second.com
Treat-mysterious-minute.com
Treat-surprising-memory.com
Treat-touched-kind.com
Treat-touched-month.com
Treathopefulday.com
Treathot-bloodedhour.com
Treatsucessful2009.com
Uideharmoniousalley.com
Welove-supersale.com
Over the weekend, a new Hydrocodone cluster emerged, distinct from the one above.
The new cluster used the following domain names in more than 1500 emails just over the last weekend:
aoisiis.com
aposoos.com
apsppew.com
blotbump.com
blotcare.com
blotcool.com
bumpflow.com
bumpfold.com
candark.com
canword.com
celitrre.com
dealrise.com
debaiteo.com
domefast.com
domerests.com
dometake.com
esperros.com
fecioos.com
felippie.com
fullmage.com
fullmeed.com
fullmend.com
fullruse.com
kaiffelt.com
lungsse.com
macrsoku.com
maghiarr.com
mailldeo.com
maingive.com
maltfame.com
maltfire.com
maltflip.com
maltlike.com
maltmain.com
maltmalts.com
maltplay.com
malttall.com
malttilts.com
marnarq.com
masciake.com
naryneat.com
nowdark.com
nowwall.com
pionname.com
pionnary.com
pionpick.com
pionrise.com
pollsies.com
ppoleiw.com
qalsibbe.com
qaselict.com
realpin.com
riennsi.com
ropeww.com
rpeusw.com
spoeii.com
tehsui.com
wallmay.com
wallrise.com
wallsdeals.com
wesleos.com
wposlles.com
yehsuue.com
The new cluster looks like another Viagra site at first:

but scrolling down, we see it really is selling Hydrocodone and other Class II and Class III Controlled Substances:

As with the first cluster we mention, Visa and MasterCard are conspicuously missing from this site. It now accepts ONLY American Express:

Fortunately, they are concerned about the High Incidence of Fraud. 8-) Haha!
Thursday, April 09, 2009
Is There a Conficker E? Waledac makes a move...
At UAB Computer Forensics, we have been tracking the spam bot, Waledac, since March 19th, by checking every so often (like 4 times a minute) all of the domain names that we now are being used to distribute Waledac. We've been making a list of the infected nodes, with the timestamp that we see them distributing Waledac, and offering that list to various network providers. (If you are a network provider/ISP, send me an email to get a pointer to the list, there are around 4,000 US-based IPs on it so far.)
This morning, Packet Ninja Dan Clemens gave me a call asking if I had seen Trend Micro's claim that Conficker was updating. I hadn't seen that, but I had seen emails on one of my secret squirrel mailing lists that Conficker was updating from "goodnewsdigital.com". That didn't make any sense at all to me! We've seen 2,821 IP addresses serving up "plain ole' Waledac" from GND, so far. (See https://info.cis.uab.edu/forensics/blog/gnd.list.txt)
Just to make sure, I went ahead and fetched the current Waledac binary from one of the GoodNewsDigital.com websites, and sure enough, it was Plain Ole Waledac.
MD5: 20ac8daf84c022ef10bc042128ccace6
Currently detected by only 9 of 40 products at VirusTotal
Here's the VirusTotal Link, but the details are here:
AntiVir - TR/Crypt.ZPACK.Gen
CAT-QuickHeal - DNAScan
F-Secure - Packed:W32/Waledac.gen!I
Fortinet - W32/PackWaledac.C
McAfee-GW-Edition - Trojan.Crypt.ZPACK.Gen
Microsoft - Trojan:Win32/Waledac.gen!A
NOD32 - Variant of Win32/Kryptic.LP
Panda - Suspicious file
Sophos - Mal/WaledPak-A
A sad statement of the current state of anti-virus, that a KNOWN MALWARE DISTRIBUTION POINT that has been serving up viruses since mid-March for a large spam botnet is still entirely undetected by 3/4ths of the AV products!
But it gets worse.
I went and read Trend Micro's assertions on their blog . . .
According to Trend Micro they saw new malware arrive on one of their conficker boxes, being dropped not via a website update, as we've all been expecting, but via a Peer 2 Peer connection from other Conficker machines. The new malware arrived via P2P on their box and began attempting to propagate in worm-like fashion looking for MS08-067 vulnerabilities (the same as previous versions of Conficker), as well as opening a webserver on port 5114, and making connections to Myspace, MSN, eBay, CNN, and AOL. After this, the machine downloaded a file from GoodNewsDigital.com, which is, as I mentioned above, a Waledac distribution point.
The file that it downloads though IS NOT THE PRIMARY WALEDAC MALWARE. We retrieved the same file in our labs at UAB (forgive me, but the file is named "fuck4.exe"), and scanned it with VirusTotal as well. This is NOT the file you receive if you visit the Waledac host, as we decribed above, via a normal spam-referred website visit.
Here's what we got from "fuck4.exe" at VirusTotal:
ZERO products detect this as malware. NONE of the 40 sites thought the 418kb executable file was a virus.
VirusTotal Report
Trend is calling the new variant WORM_DOWNAD.E (DownAdUp is an alias for Conficker).
The Trend article certainly has caused some deep thinking here this morning! Thanks to Ivan Macalintal at Trend, and because he thanks Joseph Cepe and Paul Ferguson, we thank them as well!
Wait, why are we thanking Paul Ferguson? I had to go find out. Its because of his excellent documentation on the Peer2Peer nature of Conficker in the Trend Blog on April 4th. While the entire world began watching on April 1st for Conficker to be updated via new malware that was placed on one of the 50,500 domain names that began to be searched on April 1, the bad guys have snuck in the back door and updated Conficker via P2P instead.
Paul got a head start on his Peer to Peer research from the excellent malware researchers at CERT-LEXI in their Blog at CERT-LEXSI.
We'll be contacting more Conficker researchers as the day goes on and trying to determine if ALL the Conficker nodes have just merged with Waledac, or if something else is occurring here.
This morning, Packet Ninja Dan Clemens gave me a call asking if I had seen Trend Micro's claim that Conficker was updating. I hadn't seen that, but I had seen emails on one of my secret squirrel mailing lists that Conficker was updating from "goodnewsdigital.com". That didn't make any sense at all to me! We've seen 2,821 IP addresses serving up "plain ole' Waledac" from GND, so far. (See https://info.cis.uab.edu/forensics/blog/gnd.list.txt)
Just to make sure, I went ahead and fetched the current Waledac binary from one of the GoodNewsDigital.com websites, and sure enough, it was Plain Ole Waledac.
MD5: 20ac8daf84c022ef10bc042128ccace6
Currently detected by only 9 of 40 products at VirusTotal
Here's the VirusTotal Link, but the details are here:
AntiVir - TR/Crypt.ZPACK.Gen
CAT-QuickHeal - DNAScan
F-Secure - Packed:W32/Waledac.gen!I
Fortinet - W32/PackWaledac.C
McAfee-GW-Edition - Trojan.Crypt.ZPACK.Gen
Microsoft - Trojan:Win32/Waledac.gen!A
NOD32 - Variant of Win32/Kryptic.LP
Panda - Suspicious file
Sophos - Mal/WaledPak-A
A sad statement of the current state of anti-virus, that a KNOWN MALWARE DISTRIBUTION POINT that has been serving up viruses since mid-March for a large spam botnet is still entirely undetected by 3/4ths of the AV products!
But it gets worse.
I went and read Trend Micro's assertions on their blog . . .
According to Trend Micro they saw new malware arrive on one of their conficker boxes, being dropped not via a website update, as we've all been expecting, but via a Peer 2 Peer connection from other Conficker machines. The new malware arrived via P2P on their box and began attempting to propagate in worm-like fashion looking for MS08-067 vulnerabilities (the same as previous versions of Conficker), as well as opening a webserver on port 5114, and making connections to Myspace, MSN, eBay, CNN, and AOL. After this, the machine downloaded a file from GoodNewsDigital.com, which is, as I mentioned above, a Waledac distribution point.
The file that it downloads though IS NOT THE PRIMARY WALEDAC MALWARE. We retrieved the same file in our labs at UAB (forgive me, but the file is named "fuck4.exe"), and scanned it with VirusTotal as well. This is NOT the file you receive if you visit the Waledac host, as we decribed above, via a normal spam-referred website visit.
Here's what we got from "fuck4.exe" at VirusTotal:
ZERO products detect this as malware. NONE of the 40 sites thought the 418kb executable file was a virus.
VirusTotal Report
Trend is calling the new variant WORM_DOWNAD.E (DownAdUp is an alias for Conficker).
The Trend article certainly has caused some deep thinking here this morning! Thanks to Ivan Macalintal at Trend, and because he thanks Joseph Cepe and Paul Ferguson, we thank them as well!
Wait, why are we thanking Paul Ferguson? I had to go find out. Its because of his excellent documentation on the Peer2Peer nature of Conficker in the Trend Blog on April 4th. While the entire world began watching on April 1st for Conficker to be updated via new malware that was placed on one of the 50,500 domain names that began to be searched on April 1, the bad guys have snuck in the back door and updated Conficker via P2P instead.
Paul got a head start on his Peer to Peer research from the excellent malware researchers at CERT-LEXI in their Blog at CERT-LEXSI.
We'll be contacting more Conficker researchers as the day goes on and trying to determine if ALL the Conficker nodes have just merged with Waledac, or if something else is occurring here.
Wednesday, April 08, 2009
Microsoft Security Intelligence Report 2H08
The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microsoft.com/sir/ is timestamped the evening of April 6th). We reported on the last SIR report back on November 11, 2008 - please see Microsoft Reveals Malware and Spam Trends for our coverage of that report.
52% of the Security Vulnerability announced throughout the industry, via the Common Vulnerability Scoring System were of "High" criticality, while 56% of them were "Easy to exploit". 90% of the industry vulnerability announcements related to applications or browsers. Only 10% dealt with Operating Systems.
Microsoft released 42 Security patches during the 2H08 period.
More than 97% of the email sent across the Internet during 2H08 was unwanted! They have malicious attachments, they are phishing emails, or they are just plain spam. As all of us already suspected 48.6% of all the spam observed during 2H08 was for pharmaceutical products. Another 23% were for non-pharmacy product advertisements.

Notice that the Stock Pump & Dump spam almost disappeared. What would they sell if we could do the same thing to pharmacy spam?
The report also calls attention to the demise of McColo as being the big enforcement action of the year. This section of their report is called "Spam Volume Drops 46 Percent When Hosting Provider Goes Offline". The spam level at the end of December was still lower than the pre-McColo action on November 11th.
About 1 in 1500 websites (more than 1 million) indexed by Live Search (Microsoft's answer to the Google search engine, available at live.com) contained a drive-by-download page. More than 1% of websites with a ".cn" country code hosted drive-by-download exploits. When they looked at the products that were being exploited in these driver exploits, #1 and #2 were Adobe Flash and RealPlayer.

(from p.48 of the Microsoft SIR report for 2H08)
On Windows XP machines, browser exploits targeted a Microsoft product 40.9% of the time. On Windows Vista machines, successful browser exploits targeted a Microsoft product only 5.5% of the time. This is one of many places throughout the document that Microsoft reminds us that Vista is a more secure operating system than XP.
In the first half of 2008, most compromised browsers were running Chinese language set (zh-CN = 25.6%). In the second half of 2008, American English language browsers easily passed them (en-US = 32.4%).
The SIR report makes a point that the criminals today are having great success with social engineering targeting Fear, Trust, and Desire. Rogue Security Software did so well, because people are afraid of viruses.
Of the Social Engineering attacks that were based on an infected Microsoft Office File program, 91.3% of the attacks used the more than two year old exploit, CVE-2006-2492 MS06-027 to infect users via a Microsoft Word document. Curiously only 32.5% of these infected Word documents targeted en-US machines. 15.7% targeted Taiwanese machines, 12% Russian, 11.1% other Chinese machines, and 2.6% Iraqi machines.
Two Adobe PDF reader exploits also became popular in 2H08, spreading strongly and increasingly from October until the end of the year. 57% of the Adobe attacks targeted en-US machines. China didn't make the top ten on that list.
One important note regarding corrupt Office documents. Microsoft's SIR report recommends that users *NOT* run "Windows Update", but rather run "Microsoft Update". Applying Windows Update will never prompt you to install Microsoft Office patches, which may be why so many machines are still vulnerable to two year old malware. The report recommends that users read this entry:
How Is Windows Update Different Than Microsoft Update?, and make the appropriate changes on their machines.
The report also makes clear that the trend has continued - most security breaches are accomplished not through "hacking" (though more than 15% are), but through stolen or lost equipment, usually laptops.
In 2H08, 13.2Million US computers were cleaned by Microsoft's anti-malware desktop products.

(source: SIR report p. 69)
For more details, please see the full SIR report.
Number of Security Vulnerabilities
52% of the Security Vulnerability announced throughout the industry, via the Common Vulnerability Scoring System were of "High" criticality, while 56% of them were "Easy to exploit". 90% of the industry vulnerability announcements related to applications or browsers. Only 10% dealt with Operating Systems.
Microsoft released 42 Security patches during the 2H08 period.
Spam
More than 97% of the email sent across the Internet during 2H08 was unwanted! They have malicious attachments, they are phishing emails, or they are just plain spam. As all of us already suspected 48.6% of all the spam observed during 2H08 was for pharmaceutical products. Another 23% were for non-pharmacy product advertisements.
Notice that the Stock Pump & Dump spam almost disappeared. What would they sell if we could do the same thing to pharmacy spam?
The report also calls attention to the demise of McColo as being the big enforcement action of the year. This section of their report is called "Spam Volume Drops 46 Percent When Hosting Provider Goes Offline". The spam level at the end of December was still lower than the pre-McColo action on November 11th.
Browser Drive-By-Infections
About 1 in 1500 websites (more than 1 million) indexed by Live Search (Microsoft's answer to the Google search engine, available at live.com) contained a drive-by-download page. More than 1% of websites with a ".cn" country code hosted drive-by-download exploits. When they looked at the products that were being exploited in these driver exploits, #1 and #2 were Adobe Flash and RealPlayer.
(from p.48 of the Microsoft SIR report for 2H08)
On Windows XP machines, browser exploits targeted a Microsoft product 40.9% of the time. On Windows Vista machines, successful browser exploits targeted a Microsoft product only 5.5% of the time. This is one of many places throughout the document that Microsoft reminds us that Vista is a more secure operating system than XP.
In the first half of 2008, most compromised browsers were running Chinese language set (zh-CN = 25.6%). In the second half of 2008, American English language browsers easily passed them (en-US = 32.4%).
Social Engineering
The SIR report makes a point that the criminals today are having great success with social engineering targeting Fear, Trust, and Desire. Rogue Security Software did so well, because people are afraid of viruses.
Of the Social Engineering attacks that were based on an infected Microsoft Office File program, 91.3% of the attacks used the more than two year old exploit, CVE-2006-2492 MS06-027 to infect users via a Microsoft Word document. Curiously only 32.5% of these infected Word documents targeted en-US machines. 15.7% targeted Taiwanese machines, 12% Russian, 11.1% other Chinese machines, and 2.6% Iraqi machines.
Two Adobe PDF reader exploits also became popular in 2H08, spreading strongly and increasingly from October until the end of the year. 57% of the Adobe attacks targeted en-US machines. China didn't make the top ten on that list.
One important note regarding corrupt Office documents. Microsoft's SIR report recommends that users *NOT* run "Windows Update", but rather run "Microsoft Update". Applying Windows Update will never prompt you to install Microsoft Office patches, which may be why so many machines are still vulnerable to two year old malware. The report recommends that users read this entry:
How Is Windows Update Different Than Microsoft Update?, and make the appropriate changes on their machines.
Security Breaches
The report also makes clear that the trend has continued - most security breaches are accomplished not through "hacking" (though more than 15% are), but through stolen or lost equipment, usually laptops.
Geographic Trends
In 2H08, 13.2Million US computers were cleaned by Microsoft's anti-malware desktop products.
(source: SIR report p. 69)
For more details, please see the full SIR report.
Monday, March 30, 2009
GhostNet or Gh0st RAT: The Cyber Persecution of Tibet
For many members of the non-security research community, the New York Times story this week was big news: "Vast Spy System Loots Computers in 103 Countries". This morning's Google News has more than 750 related articles, and I applaud the work of the University of Toronto's Citizen Lab at the Monk Centre for International Studies at Trinity College for the excellent research and for sharing this story with the general public.

What does it look like to a Security Researcher though? Unfortunately, its a very common story of a very simple case of Spear Phishing that can be accomplished with minimal effort and *IS* being accomplished on a daily basis against various special interests, including government agencies, military contractors, or just people who might have a lot of money to steal. As I've discussed in my presentations on Spear Phishing, including at the 2008 Department of Defense Cyber Crime conference, high-value targets deserve special targeting. But let's look at how special the targeting was in this situation.
The news that someone was creating specifically targeted spear phishing campaigns against Tibet and Tibetan sympathizers first came to my attention in March 24, 2008, when our friends at the SANS' Internet Storm Center released the article, Overview of cyber attacks against Tibetan communities by Maarten Van Horenbeek. This was an in-depth follow-up to Maarten's initial report on March 21, 2008, Cyber attacks against Tibetan communities.
In the original article, Maarten describes the case this way:
At that time he showed how PowerPoint files with names such as "reports_of_violence_in_tibet.ppt" and or "China's Tibet.pdf" contained exploits and were delivered in emails designed to elicit a trust-response from the reader if they were sympathetic to the cause. Here's one email that Maarten shared:
Maarten confirmed that the contact information was correct for a member of the Tibetan Government in exile in Dharamshala, India.
In the case of the Citizen Labs report, the name of the report was the first thing worth mentioning. The report was called "Tracking GhostNet: Investigating a Cyber Espionage Network". Why was it called GhostNet? Because the enabling technology in their investigation was a common Remote Administration Trojan called "Gh0st RAT" (that's Gh0st with a Zero).
It took about 30 seconds to find a copy of Gh0st RAT 3.6 in the Chinese underground community, complete with source code. The program is written in VC++ version 6.0. The source code makes clear that, as is the case with many Chinese distributed malware products, the current distributor is a Chinese speaker speaking to a Chinese audience, although the comments make it quite possible the code was originally authored and designed for English speakers. Here's an example Code Snippet:
(According to Google Translate, the Chinese here says roughly: 为加载系统图标列表做准备 = Initialize the image list of this process, and 为加载系统图标列表做准备 = Icon to load the system ready to do list
While many of the notes in the source code have been rendered in Chinese, it still reads as those these are after-thought comments, and not the original author's words.
Still, Gh0st RAT China has been in development as a Chinese tool for some time - the version that was popular in China in early 2008 was Beta 2.5. and seems to have been primarily distributed by members of the "C.Rufus Security Team" or "CRST" through their website wolfexp.net (which is suddently not online???). While wildenwolf's website seems offline, another CRST member, amxku, still has a great deal of notes available on his blog at amxku.net.
One of the main researchers in the Sec Dev project, Gregory Walton, previewed some of this report at a presentation he did in Dharamshala, India back in 26 August 2008 called "Year of the Gh0st Rat".
The Citizen Lab report investigates a large botnet which was enabled by the Gh0st Remote Administration Trojan. In their technical findings, they reveal that the members of the network of their investigation received emails with malicious attachments, very similar to what Maarten reported at ISC back in March. Here's one of the Citizen Lab report emails:

Something else very interesting emerges as we begin digging into some of the technical information shared in the Citizen Lab report.
For example, they mention two domain names used as Command & Control points for the by Gh0st machines they were tracking:
macfeeresponse.org and scratchindian.com
At the time the IP address they were tracking was 218.241.153.61, but now both of those domains are resolving to the IP 210.51.7.155, in China. Other domain names on that same IP address may be domain names of concern, including:
indexindian.com - opanpan@gmail.com
lookbytheway.com - losttemp33@hotmail.com
macfeeresponse.com - losttemp33@hotmail.com
macfeeresponse.org - losttemp33@hotmail.com
MSNxy.net - yglct@sina.com
MSNyf.net - yglct@sina.com
NetworkCIA.com - yglct@sina.com
ScratchIndian.com - opanpan@gmail.com
sysroots.net - yglct@sina.com
timeswindow.net - yglct@sina.com
womanld.com - yglct@sina.com
womannana.com - yglct@sina.com
ybbero.com - yglct@sina.com
yellowpaperofindia.com - losttemp33@hotmail.com
yfhomes.com - yglct@sina.com
A simple Google on most of these domain names will reveal that they are all known to be related to malicious software and botnet activity, but they are still sitting live in China.
The Citizens Lab report reveals that documents from a computer in the Dalai Lama's own office were being exfiltrated to "www.macafeeresponse.org" during the course of the investigation.
While their report focused on traffic related to this Tibet group, it is clear that there are many other groups, with covert traffic being sent back to China and elsewhere, and that it is trivial to create such an infection using commonly unpatched or underpatched exploits, easily downloadable malware, and hard-to-stop social engineering techniques.
If others are seeing data communicating with the domain names listed above, please take action. Report these communications so that we can learn what other groups, besides the Tibet group, may be losing intelligence and internal documents to these data stealing botnets.
What does it look like to a Security Researcher though? Unfortunately, its a very common story of a very simple case of Spear Phishing that can be accomplished with minimal effort and *IS* being accomplished on a daily basis against various special interests, including government agencies, military contractors, or just people who might have a lot of money to steal. As I've discussed in my presentations on Spear Phishing, including at the 2008 Department of Defense Cyber Crime conference, high-value targets deserve special targeting. But let's look at how special the targeting was in this situation.
The news that someone was creating specifically targeted spear phishing campaigns against Tibet and Tibetan sympathizers first came to my attention in March 24, 2008, when our friends at the SANS' Internet Storm Center released the article, Overview of cyber attacks against Tibetan communities by Maarten Van Horenbeek. This was an in-depth follow-up to Maarten's initial report on March 21, 2008, Cyber attacks against Tibetan communities.
In the original article, Maarten describes the case this way:
The attacks generally start with a very trustworthy looking e-mail, being spoofed as originating from a known contact, to someone within a community. Some impressive social engineering tricks are used:
- Messages make a strong statement on a well known individual or group, but do not mention its name. The attachment is then named after that individual. A state of 'cognitive dissonance' is invoked between the reader's pre-existent beliefs and the statement. There's a natural urge to click on the attachment to confirm that belief;
- The writing style of the purported sender is usually well researched to have the message look as believable as possible;
- The content of the document actually matches closely what was discussed in the e-mail message;
- Having legitimate, trusted, users actually forward along a message back into the community.
The messages contain an attachment which exploits a client side vulnerability. Generally these are:
- CHM Help files with embedded objects;
- Acrobat Reader PDF exploits;
- Microsoft Office exploits;
- LHA files exploiting vulnerabilities in WinRAR;
- Exploitation of an ActiveX component through an attached HTML file.
At that time he showed how PowerPoint files with names such as "reports_of_violence_in_tibet.ppt" and or "China's Tibet.pdf" contained exploits and were delivered in emails designed to elicit a trust-response from the reader if they were sympathetic to the cause. Here's one email that Maarten shared:
All,
Attached here is the update Human Rights Report on Tibet issued by
Department of State of U.S.A on March 11, 2008.
You may also visit the site:
Tashi Deleg,
Sonam Dagpo
Secretary of International Relations
Department of Information & International Relations
Central Tibetan Administration
Dharamshala -176215
H.P., INDIA
Ph.: [obfuscated]
Fax: [obfuscated]
E-mail: [obfuscated]@gov.tibet.net or diir-pa@gov.tibet.net
Website: http://www.tibet.net/en/diir/
Maarten confirmed that the contact information was correct for a member of the Tibetan Government in exile in Dharamshala, India.
In the case of the Citizen Labs report, the name of the report was the first thing worth mentioning. The report was called "Tracking GhostNet: Investigating a Cyber Espionage Network". Why was it called GhostNet? Because the enabling technology in their investigation was a common Remote Administration Trojan called "Gh0st RAT" (that's Gh0st with a Zero).
It took about 30 seconds to find a copy of Gh0st RAT 3.6 in the Chinese underground community, complete with source code. The program is written in VC++ version 6.0. The source code makes clear that, as is the case with many Chinese distributed malware products, the current distributor is a Chinese speaker speaking to a Chinese audience, although the comments make it quite possible the code was originally authored and designed for English speakers. Here's an example Code Snippet:
/////////////////////////////////////////////////////////////////////////////
// CGh0stApp construction
CGh0stApp::CGh0stApp()
{
// TODO: add construction code here,
// Place all significant initialization in InitInstance
// 初始化本进程的图像列表, 为加载系统图标列表做准备
typedef BOOL (WINAPI * pfn_FileIconInit) (BOOL fFullInit);
pfn_FileIconInit FileIconInit = (pfn_FileIconInit) GetProcAddress(LoadLibrary("shell32.dll"), (LPCSTR)660);
FileIconInit(TRUE);
HANDLE hFile = CreateFile("QQwry.dat", 0, 0, NULL, OPEN_EXISTING, 0, NULL);
if (hFile != INVALID_HANDLE_VALUE)
(According to Google Translate, the Chinese here says roughly: 为加载系统图标列表做准备 = Initialize the image list of this process, and 为加载系统图标列表做准备 = Icon to load the system ready to do list
While many of the notes in the source code have been rendered in Chinese, it still reads as those these are after-thought comments, and not the original author's words.
Still, Gh0st RAT China has been in development as a Chinese tool for some time - the version that was popular in China in early 2008 was Beta 2.5. and seems to have been primarily distributed by members of the "C.Rufus Security Team" or "CRST" through their website wolfexp.net (which is suddently not online???). While wildenwolf's website seems offline, another CRST member, amxku, still has a great deal of notes available on his blog at amxku.net.
One of the main researchers in the Sec Dev project, Gregory Walton, previewed some of this report at a presentation he did in Dharamshala, India back in 26 August 2008 called "Year of the Gh0st Rat".
The Citizen Lab report investigates a large botnet which was enabled by the Gh0st Remote Administration Trojan. In their technical findings, they reveal that the members of the network of their investigation received emails with malicious attachments, very similar to what Maarten reported at ISC back in March. Here's one of the Citizen Lab report emails:
Something else very interesting emerges as we begin digging into some of the technical information shared in the Citizen Lab report.
For example, they mention two domain names used as Command & Control points for the by Gh0st machines they were tracking:
macfeeresponse.org and scratchindian.com
At the time the IP address they were tracking was 218.241.153.61, but now both of those domains are resolving to the IP 210.51.7.155, in China. Other domain names on that same IP address may be domain names of concern, including:
indexindian.com - opanpan@gmail.com
lookbytheway.com - losttemp33@hotmail.com
macfeeresponse.com - losttemp33@hotmail.com
macfeeresponse.org - losttemp33@hotmail.com
MSNxy.net - yglct@sina.com
MSNyf.net - yglct@sina.com
NetworkCIA.com - yglct@sina.com
ScratchIndian.com - opanpan@gmail.com
sysroots.net - yglct@sina.com
timeswindow.net - yglct@sina.com
womanld.com - yglct@sina.com
womannana.com - yglct@sina.com
ybbero.com - yglct@sina.com
yellowpaperofindia.com - losttemp33@hotmail.com
yfhomes.com - yglct@sina.com
A simple Google on most of these domain names will reveal that they are all known to be related to malicious software and botnet activity, but they are still sitting live in China.
The Citizens Lab report reveals that documents from a computer in the Dalai Lama's own office were being exfiltrated to "www.macafeeresponse.org" during the course of the investigation.
While their report focused on traffic related to this Tibet group, it is clear that there are many other groups, with covert traffic being sent back to China and elsewhere, and that it is trivial to create such an infection using commonly unpatched or underpatched exploits, easily downloadable malware, and hard-to-stop social engineering techniques.
If others are seeing data communicating with the domain names listed above, please take action. Report these communications so that we can learn what other groups, besides the Tibet group, may be losing intelligence and internal documents to these data stealing botnets.
Wednesday, March 25, 2009
Bank Hacking Exposed: The Analyzer Affadavit
One of my favorite twitter friends, InfraGard member and PCI expert Michael Dahn (@sfoak), sent his tweets a link today to the Affidavit of Darren Hafnet, a Calgary Police officer working on the Commercial Crime unit, with regards to the arrest of Ehud Tenenbaum (via this excellent WIRED ThreatLevel story). As we wrote back in September (see: Is The Analyzer Really Back?), Tenenbaum became a world-famous hacker for breaching more than 400 systems at the Pentagon, but was most recently picked up in Canada for master-minding a major bank heist via ATM cards.
An indictment, issued by Assistant US Attorney Melissa Marrus from the Eastern District of New York back in October, was extremely short on details, charging Tenenbaum, AKA Analyzer22@hotmail.com, with two counts - "Conspiracy to Commit Access Device Fraud" and "Access Device Fraud" "the aggregate value of which was equal to or greater than $1,000. (Title 18 Section 1029(a)(5), (b)(2), (c)(1)(A)(ii) and 3551) - although my PACER account shows there is a second "*Restricted*" document associated with case 1:2008cr00747.
The Canadian affidavit makes it clear how much greater than $1,000 we are talking about, and reveals quite a bit about the methods used by Tenenbaum and his gang.
The scam is referred to as a "PIN Cashout Conspiracy", and it works like this:
First, Tenenbaum uses SQL Injection techniques to break into a database-driven website which resides on a financial institution's network.
Then, he uses his access to the bank's systems to locate their ATM database.
If necessary, he alters the PIN for the cards he is planning to cash out.
Then he sells these card data to other criminals.
Those criminals create ATM cards using Tenenbaum's information, and drain the accounts. Tenenbaum receives a percentage of the proceeds - in this case "10-20%".
During January and February 2008, the US Secret Service has revealed that they were investigating two such breaches involving Tenenbaum - one against OmniAmerican Credit Union of Fort Worth, Texas, and the other against Global Cash Card in Irvine, California. In April and May of 2008, it is also known that there were breaches of this nature against Symmetrex, a transaction processor in Florida, and 1st Source Bank in Indiana. Symmetrex cards were used by MetaBank - with branches in Iowa and South Dakota. Actual losses of more than $4 Million were experienced just by those brands.
Those who follow computer crime will not be shocked at the location of the servers the criminals used to carry out their attacks. The affidavit says some of the servers were located at HopOne Internet Corp in McLean, Virginia while "much of the traffic going through the HopOne servers was originating from from the Dutch company LeaseWeb."
Through cooperative monitoring in the Netherlands and in the United States, Tenenbaum's MSN conversations have become part of the official court documents, including his confession to hacking the servers, and transactions where he sold many of the cards obtained. The cards were used by "cashiers" in Russia, Turkey, the United States, Canada, Sweden, Bulgaria, and Germany to drain the accounts. Tenenbaum charged between 10-20% of the total proceeds for his role, stating in one chat that he stood to earn between "350 - 400" - that's 400,000! (Unsure whether this was dollars or Euros).
On April 28, 2008 Tenenbaum chatted with another criminal boasting that he had made himself a Windows administrator on the 1st Source Bank network, and had granted himself the ability to modify PINs on debit cards used by the bank's customers. This solves an on-going problem for the criminals - as banks have locked down their Track 2 data on Debit cards, the criminals have had to find ways to break the encryption algorithms of the banks in order to modify the cards. With The Analyzer's method this is no longer necessary. While logged in to the Bank's system, Tenenbaum just set the PINs to whatever he desired and instructed his cohorts to burn cards that would use those PIN numbers.
In another chat, Tenenbaum boasts that he hacked the largest bank Greece (alpha.gr) and "has friends" working in their network.
Tenenbaum was located, according to the Affidavit, by using the IP address from his chats to locate his office in Montreal, where he was set up as the director of "Internet Labs Secure, Inc". The Montreal police confirmed that this was Tenenbaum's residence on July 25, 2008. The same IP address, 69.70.122.98, was also confirmed to have accessed Global Cash Card's network.
Based on this information, Tenenbaum was arrested on August 28, 2008 in Montreal, and charged with fraud by the Calgary Police Service. Tenenbaum had entered Canada legally on an Israeli passport on March 11, 2008, which granted him permission to visit for up to six months.
One of the challenges that I am frequently given by investigators is "surely the criminals would not hack from their own IP address!" In this case, we have evidence that one of the "super hackers" both chats and logs in to banks from an IP address originating at his residence.
Interesting . . .
I wonder how many other banks have criminals running their networks for them without their knowledge?
(The Affidavit, courtesy of WIRED)
An indictment, issued by Assistant US Attorney Melissa Marrus from the Eastern District of New York back in October, was extremely short on details, charging Tenenbaum, AKA Analyzer22@hotmail.com, with two counts - "Conspiracy to Commit Access Device Fraud" and "Access Device Fraud" "the aggregate value of which was equal to or greater than $1,000. (Title 18 Section 1029(a)(5), (b)(2), (c)(1)(A)(ii) and 3551) - although my PACER account shows there is a second "*Restricted*" document associated with case 1:2008cr00747.
The Canadian affidavit makes it clear how much greater than $1,000 we are talking about, and reveals quite a bit about the methods used by Tenenbaum and his gang.
The scam is referred to as a "PIN Cashout Conspiracy", and it works like this:
First, Tenenbaum uses SQL Injection techniques to break into a database-driven website which resides on a financial institution's network.
Then, he uses his access to the bank's systems to locate their ATM database.
If necessary, he alters the PIN for the cards he is planning to cash out.
Then he sells these card data to other criminals.
Those criminals create ATM cards using Tenenbaum's information, and drain the accounts. Tenenbaum receives a percentage of the proceeds - in this case "10-20%".
During January and February 2008, the US Secret Service has revealed that they were investigating two such breaches involving Tenenbaum - one against OmniAmerican Credit Union of Fort Worth, Texas, and the other against Global Cash Card in Irvine, California. In April and May of 2008, it is also known that there were breaches of this nature against Symmetrex, a transaction processor in Florida, and 1st Source Bank in Indiana. Symmetrex cards were used by MetaBank - with branches in Iowa and South Dakota. Actual losses of more than $4 Million were experienced just by those brands.
Those who follow computer crime will not be shocked at the location of the servers the criminals used to carry out their attacks. The affidavit says some of the servers were located at HopOne Internet Corp in McLean, Virginia while "much of the traffic going through the HopOne servers was originating from from the Dutch company LeaseWeb."
Through cooperative monitoring in the Netherlands and in the United States, Tenenbaum's MSN conversations have become part of the official court documents, including his confession to hacking the servers, and transactions where he sold many of the cards obtained. The cards were used by "cashiers" in Russia, Turkey, the United States, Canada, Sweden, Bulgaria, and Germany to drain the accounts. Tenenbaum charged between 10-20% of the total proceeds for his role, stating in one chat that he stood to earn between "350 - 400" - that's 400,000! (Unsure whether this was dollars or Euros).
On April 28, 2008 Tenenbaum chatted with another criminal boasting that he had made himself a Windows administrator on the 1st Source Bank network, and had granted himself the ability to modify PINs on debit cards used by the bank's customers. This solves an on-going problem for the criminals - as banks have locked down their Track 2 data on Debit cards, the criminals have had to find ways to break the encryption algorithms of the banks in order to modify the cards. With The Analyzer's method this is no longer necessary. While logged in to the Bank's system, Tenenbaum just set the PINs to whatever he desired and instructed his cohorts to burn cards that would use those PIN numbers.
In another chat, Tenenbaum boasts that he hacked the largest bank Greece (alpha.gr) and "has friends" working in their network.
Tenenbaum was located, according to the Affidavit, by using the IP address from his chats to locate his office in Montreal, where he was set up as the director of "Internet Labs Secure, Inc". The Montreal police confirmed that this was Tenenbaum's residence on July 25, 2008. The same IP address, 69.70.122.98, was also confirmed to have accessed Global Cash Card's network.
Based on this information, Tenenbaum was arrested on August 28, 2008 in Montreal, and charged with fraud by the Calgary Police Service. Tenenbaum had entered Canada legally on an Israeli passport on March 11, 2008, which granted him permission to visit for up to six months.
One of the challenges that I am frequently given by investigators is "surely the criminals would not hack from their own IP address!" In this case, we have evidence that one of the "super hackers" both chats and logs in to banks from an IP address originating at his residence.
Interesting . . .
I wonder how many other banks have criminals running their networks for them without their knowledge?
(The Affidavit, courtesy of WIRED)
Thursday, March 19, 2009
Stop the Rumors: Quit SMSing about WalMart Gang Initiations
My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here's one of them:
At least three different friends sent the message in the space of thirty minutes. I reassured them that it was just a hoax, and pointed them to the Urban Legends sites to see that this rumor has been going around for at least four years:
July 2005 email version:
http://urbanlegends.about.com/library/bl_memphis_gang_initiations.htm
December 2007 email version:
http://urbanlegends.about.com/library/bl_memphis_gang_initiation.htm
March 2009 SMS version:
http://urbanlegends.about.com/b/2009/03/18/police-walmart-gang-initation-rumors-are-false.htm
What was interesting to me though was how widespread the event is, and how each area seems to be treating it as a stand-alone event. Googling up the news has chiefs of police saying there is nothing to worry about, while others are promising a "state-wide investigation".
Apparently the best way to send a rumor is to text it to a teenager and tell her to send it to all her girlfriends.
In Delaware, the State Police are being inundated with calls, and have shared a copy of their message:
The Greenwood, South Carolina sheriff's office Major Lonnie Smith is promising that there will be extra patrols at their WalMart's Thursday night "as a precaution".
In Portage, Indiana police were on hand at local WalMarts after they "received information from high school students that there was going to be a shooting at a Wal-Mart as a gang initiation."
In Georgia police put out extra patrols, earning the outrage of at least one blogger who says tax payer money was wasted because the police couldn't use Google.
The Jefferson Parish, New Orleans sheriff says these are nothing but rumors, but "As a precaution, Normand is assigning additional personnel to the area as needed", Col. John Fortunato said.
Officers in Murfreesboro Tennessee showed more restraint when the rumors were making their rounds in January -- “An e-mail being distributed in Nashville and Rutherford County about gang intitations is fabricated,” said Chief Deputy Virgil Gammon of the Rutherford County Sheriff’s Department in a Jan. 18, 2008 article.
In Chattanooga Tennessee a version is circulating which names a specific store - the Gunbarrel Road Wal-Mart near Hamilton Place. Chattanooga Police spokesperson Jeri Weary said, "This is not a situation that has occurred in Chattanooga and there have been no reported incidents at any of the Chattanooga area Walmarts."
Police in Findlay Ohio told the local ABC 13 News that they've been told the rumors originated in South Carolina.
Police in Birmingham, Alabama were also calm about the situation -- "They circulate that kind of stuff every year," said Sgt. S. White of the Birmingham Police Department's East Precinct, interviewed by the Birmingham News. "Usually there is nothing to it."
The rumors are being reported in almost every city with a newspaper! Yuma, Arizona, Moline, Illinois, Palm Beach, Florida, Greeley, Colorado . . .
You get the idea . . . all around the country a text message rumor storm has police and concerned parents buzzing about something that everyone is quite sure is a hoax.
Fwd: Do not go to any walmart tonight. Gang initiation to shoot 3 women tonight. Not sure which walmart. And confirmd on tv. Forward 2 all girls on ur phone
At least three different friends sent the message in the space of thirty minutes. I reassured them that it was just a hoax, and pointed them to the Urban Legends sites to see that this rumor has been going around for at least four years:
July 2005 email version:
http://urbanlegends.about.com/library/bl_memphis_gang_initiations.htm
December 2007 email version:
http://urbanlegends.about.com/library/bl_memphis_gang_initiation.htm
March 2009 SMS version:
http://urbanlegends.about.com/b/2009/03/18/police-walmart-gang-initation-rumors-are-false.htm
What was interesting to me though was how widespread the event is, and how each area seems to be treating it as a stand-alone event. Googling up the news has chiefs of police saying there is nothing to worry about, while others are promising a "state-wide investigation".
Apparently the best way to send a rumor is to text it to a teenager and tell her to send it to all her girlfriends.
In Delaware, the State Police are being inundated with calls, and have shared a copy of their message:
i don't noe how tru dis is but here it is. Dont go 2 any walmarts 2nite ther will be a gang initiation n dey have 2 kill 3 women at each store. Tell ur love 1s.
The Greenwood, South Carolina sheriff's office Major Lonnie Smith is promising that there will be extra patrols at their WalMart's Thursday night "as a precaution".
In Portage, Indiana police were on hand at local WalMarts after they "received information from high school students that there was going to be a shooting at a Wal-Mart as a gang initiation."
In Georgia police put out extra patrols, earning the outrage of at least one blogger who says tax payer money was wasted because the police couldn't use Google.
The Jefferson Parish, New Orleans sheriff says these are nothing but rumors, but "As a precaution, Normand is assigning additional personnel to the area as needed", Col. John Fortunato said.
Officers in Murfreesboro Tennessee showed more restraint when the rumors were making their rounds in January -- “An e-mail being distributed in Nashville and Rutherford County about gang intitations is fabricated,” said Chief Deputy Virgil Gammon of the Rutherford County Sheriff’s Department in a Jan. 18, 2008 article.
In Chattanooga Tennessee a version is circulating which names a specific store - the Gunbarrel Road Wal-Mart near Hamilton Place. Chattanooga Police spokesperson Jeri Weary said, "This is not a situation that has occurred in Chattanooga and there have been no reported incidents at any of the Chattanooga area Walmarts."
Police in Findlay Ohio told the local ABC 13 News that they've been told the rumors originated in South Carolina.
Police in Birmingham, Alabama were also calm about the situation -- "They circulate that kind of stuff every year," said Sgt. S. White of the Birmingham Police Department's East Precinct, interviewed by the Birmingham News. "Usually there is nothing to it."
The rumors are being reported in almost every city with a newspaper! Yuma, Arizona, Moline, Illinois, Palm Beach, Florida, Greeley, Colorado . . .
You get the idea . . . all around the country a text message rumor storm has police and concerned parents buzzing about something that everyone is quite sure is a hoax.
Wednesday, March 18, 2009
Carders do battle through spam - carder.su
We've seen several cases in the past where Law Enforcement action is triggered by one criminal actively and publicly spreading information (or mis-information) about another criminal's activities.
That seems to be the case in what is happening now, as a spammer is using an existing spam botnet to send messages about the Russian credit card trading site "carder.su".
Beginning on the afternoon of March 16th, the UAB Spam Data Mine began to receive copies of this email message:

So far we have 142 copies of this email, which came from 138 different email addresses, and were sent to 122 of our unique trap accounts. The emails had 13 different subject lines, but were otherwise the same:
Carders attack
Carders here
Carders online
Carders threat
Hazardous site
How is it possible?
Sale Data
Stolen bank accounts
Stolen credit cards
Stolen data
Terrible site
The threat of credit card
Where is the police?
There were also 132 unique IP addresses in the email headers, corresponding to the 132 bot machines which were used to send us this spam. It would be interesting to know what other spam is coming from these same bot machines. Fortunately, when you have a Spam Data Mine sitting around, that's a pretty simple query to make.
(Full list of IPs at the end of this article . . . if you recognize the botnet please let me know.)
Unfortunately, some IP addresses are less helpful than others . . . is it valid to say that these emails came from the same botnet, for example, when we haven't seen other email from them since October?
Emails from 213.25.157.1 (in Poland):
Or these from 212.26.246.161 (in Russia)
The next one is far more useful, because although it shows a long history of spam from the computer at 203.197.115.82 (in India), it also has spam from two weeks ago, which we know by the subject is a sign of a Waledac infected computer.
Unfortunately, that was the only machine in our pool which seemed to be a Waledac box. Another coincidence only.
While many of the 132 computers were to be found sending other spam in the UAB Spam Data Mine, there were not enough which sent recent spam to draw any definite conclusions on the botnet.
Limiting our interest only to the most recent spam from the pool of IP addresses, we find that recently spammed sites from the same criminal include:
http://2009-film.ru/ - an illegal movie download site listing this contact information:
Tel: +7 (495) 504-14-43
ICQ: 431409065
As well as the Viagra-selling site, US HealthCare Inc, hosted in Korea and using the domain names:
bumpfold.com
blotcare.com
dunknew.com
dealrise.com
wallsdeals.com
A second set of recent Viagra sites, Canadian Healthcare, used Chinese auto-forwarding URLs in their spam, such as:
aqeakteny.giwhohov.cn
yzmjnq.giwhohov.cn
which forwarded to the Israeli hosted website:
maxitiny.com
A third set of pills was available from this Canadian Pharmacy website:
caringflattering.com
What do we actually know about Carder.su? Not a whole lot truthfully. We know its a popular site - at its max there were more than 14,000 members logged in at the same time.
The WHOIS information for the domain says it is registered to "Private Person", but does give a phone number and an email address:
phone: +79164541122
e-mail: cardersu@ya.ru
A peek back at the WHOIS history shows it was originally registered by:
Maria A Ageeva
886824@mail.ru
+79124427798
From at least November 20, 2009 until March 10, 2009, "Private Person" used a gmail account of: cardersu@gmail.com
Their servers are hosted in Moscow on the 2x4.ru network, owned by Pavel Ivanov.
Ivanov has many interesting customers on his network 92.241.168.0/23. Fine folks like:
cyberterrorist.biz
bl4ckc4rd.ws (black card?)
unlimitedhack.cn
drugspurchase.com
seobiz.org
heihachi.net
coderz.ws
abuse-crew.cc
nukeuploads.com
glavforum.ru
I have to say, the 2x4.ru folks have suspended some of the porn sites that drop malware, so maybe they only cater to certain types of criminals. "gigatube.net" and "eroticzzz.info" were suspended for dropping malware, as was "swiss-warez.biz"
Do you recognize this botnet?
41.248.155.122
58.8.172.135
58.9.203.10
59.182.251.171
61.14.3.165
62.140.238.1
62.57.137.76
67.204.146.123
77.236.6.91
77.30.51.182
77.31.4.53
77.31.64.86
78.106.36.221
78.160.216.232
78.162.210.118
78.162.73.40
78.163.200.222
78.165.108.153
78.166.191.79
78.167.164.42
78.167.58.60
78.169.14.70
78.93.197.72
78.93.82.106
78.96.182.134
79.189.49.202
81.214.156.70
83.29.230.20
84.10.79.200
84.139.136.5
84.47.93.42
85.101.110.99
85.103.13.223
85.103.251.189
85.104.58.189
85.105.209.23
85.108.245.33
85.108.253.26
85.110.153.77
85.110.157.133
85.110.171.230
85.198.177.13
85.99.185.187
86.122.165.34
87.0.54.121
87.109.14.12
87.109.14.174
87.109.159.178
87.120.109.249
87.205.244.153
88.224.151.137
88.224.251.96
88.224.44.225
88.224.75.134
88.226.69.100
88.227.248.11
88.228.97.232
88.230.74.81
88.232.153.116
88.234.163.254
88.237.221.48
88.238.89.111
88.242.123.170
88.243.107.145
88.243.217.210
88.245.107.7
88.245.228.14
88.246.96.61
88.252.78.129
88.254.234.140
89.136.79.96
89.228.156.6
89.252.9.126
89.46.136.175
89.76.97.16
90.148.146.140
91.124.23.200
91.201.112.2
92.112.23.168
92.37.151.127
92.44.194.243
92.47.222.107
92.61.238.120
92.82.172.41
93.94.178.187
93.98.37.210
94.44.29.200
94.96.11.241
94.99.184.93
94.99.74.20
95.134.200.103
95.58.142.176
95.78.138.40
113.53.170.179
116.71.2.192
117.197.96.124
118.43.204.82
121.159.184.91
121.242.55.42
124.121.38.204
124.121.85.111
125.136.199.83
188.48.200.177
189.112.85.88
189.114.152.233
189.12.187.224
189.24.135.57
189.27.243.210
189.46.152.128
189.78.253.59
189.82.74.79
189.93.0.162
190.120.140.118
190.135.146.135
190.19.69.90
196.218.55.234
200.121.245.19
200.163.33.130
201.19.24.84
201.24.126.235
201.67.135.232
201.67.186.108
201.76.71.9
203.197.115.82
211.107.153.132
211.247.31.154
212.26.246.161
213.181.170.167
213.25.157.1
217.147.25.250
218.152.226.159
220.253.192.12
That seems to be the case in what is happening now, as a spammer is using an existing spam botnet to send messages about the Russian credit card trading site "carder.su".
Beginning on the afternoon of March 16th, the UAB Spam Data Mine began to receive copies of this email message:
So far we have 142 copies of this email, which came from 138 different email addresses, and were sent to 122 of our unique trap accounts. The emails had 13 different subject lines, but were otherwise the same:
Carders attack
Carders here
Carders online
Carders threat
Hazardous site
How is it possible?
Sale Data
Stolen bank accounts
Stolen credit cards
Stolen data
Terrible site
The threat of credit card
Where is the police?
There were also 132 unique IP addresses in the email headers, corresponding to the 132 bot machines which were used to send us this spam. It would be interesting to know what other spam is coming from these same bot machines. Fortunately, when you have a Spam Data Mine sitting around, that's a pretty simple query to make.
(Full list of IPs at the end of this article . . . if you recognize the botnet please let me know.)
Unfortunately, some IP addresses are less helpful than others . . . is it valid to say that these emails came from the same botnet, for example, when we haven't seen other email from them since October?
Emails from 213.25.157.1 (in Poland):
Date Email Subject
-----------+---------------------------------
2008AUG10 | debt consolidation calculator
2008AUG13 | loans for debt consolidation
2008AUG15 | debt consolidation loans
2008AUG21 | unsecured debt consolidation loans
2008AUG31 | credit check
2008SEP06 | a debt consolidation loan
2008SEP06 | debt busters
2008SEP06 | debt consolidation advice
2008SEP09 | profit debt consolidation
2008SEP25 | clear debt
2008SEP29 | help me get out of debt
2008OCT01 | credit cards debt
2008OCT15 | help to get out of debt
2008OCT26 | horses for loan
2008OCT29 | student loan debt
Or these from 212.26.246.161 (in Russia)
Date | Email Subject
-----------+----------------------------------------------------
2008APR30 | Greetings, I have learned an interesting thing
2008MAY06 | Merrill Lynch Business Centre - Changing a website
The next one is far more useful, because although it shows a long history of spam from the computer at 203.197.115.82 (in India), it also has spam from two weeks ago, which we know by the subject is a sign of a Waledac infected computer.
message_id | subject
------------+-------------------------------------------
2008OCT04 | Hi! I wanna chat with you!
2008DEC08 | Watches
2008DEC13 | Hi sweety
2008DEC26 | Swiss Branded Watches
2009JAN01 | Swiss Branded Watches
2009JAN04 | Don't settle for less
2009JAN03 | Swiss Branded Watches
2009JAN04 | Swiss Branded Watches
2009JAN05 | Swiss Branded Watches
2009JAN06 | Attention: Important Information!
2009JAN08 | Re: Miley loves it huge
2009JAN16 | Swiss Branded Watches
2009JAN24 | Pharmacy Discount for (email)
2009JAN21 | Russian queens are waiting.
2009JAN30 | Turn your bedroom life into a volcano of pleasure.
2009FEB05 | Add floors to your skyscraper special offer for (email)
2009FEB14 | Facing a love-making problem? We will solve all yout problems in few minutes.
2009FEB17 | Have you heard about Viagra for women?
2009FEB27 | Pharma Discount for
2009MAR02 | Regards The day of Love
2009MAR06 | Regards The day of Love
Unfortunately, that was the only machine in our pool which seemed to be a Waledac box. Another coincidence only.
While many of the 132 computers were to be found sending other spam in the UAB Spam Data Mine, there were not enough which sent recent spam to draw any definite conclusions on the botnet.
Limiting our interest only to the most recent spam from the pool of IP addresses, we find that recently spammed sites from the same criminal include:
http://2009-film.ru/ - an illegal movie download site listing this contact information:
Tel: +7 (495) 504-14-43
ICQ: 431409065
As well as the Viagra-selling site, US HealthCare Inc, hosted in Korea and using the domain names:
bumpfold.com
blotcare.com
dunknew.com
dealrise.com
wallsdeals.com
A second set of recent Viagra sites, Canadian Healthcare, used Chinese auto-forwarding URLs in their spam, such as:
aqeakteny.giwhohov.cn
yzmjnq.giwhohov.cn
which forwarded to the Israeli hosted website:
maxitiny.com
A third set of pills was available from this Canadian Pharmacy website:
caringflattering.com
What about Carder.su?
What do we actually know about Carder.su? Not a whole lot truthfully. We know its a popular site - at its max there were more than 14,000 members logged in at the same time.
The WHOIS information for the domain says it is registered to "Private Person", but does give a phone number and an email address:
phone: +79164541122
e-mail: cardersu@ya.ru
A peek back at the WHOIS history shows it was originally registered by:
Maria A Ageeva
886824@mail.ru
+79124427798
From at least November 20, 2009 until March 10, 2009, "Private Person" used a gmail account of: cardersu@gmail.com
Their servers are hosted in Moscow on the 2x4.ru network, owned by Pavel Ivanov.
Ivanov has many interesting customers on his network 92.241.168.0/23. Fine folks like:
cyberterrorist.biz
bl4ckc4rd.ws (black card?)
unlimitedhack.cn
drugspurchase.com
seobiz.org
heihachi.net
coderz.ws
abuse-crew.cc
nukeuploads.com
glavforum.ru
I have to say, the 2x4.ru folks have suspended some of the porn sites that drop malware, so maybe they only cater to certain types of criminals. "gigatube.net" and "eroticzzz.info" were suspended for dropping malware, as was "swiss-warez.biz"
Do you recognize this botnet?
41.248.155.122
58.8.172.135
58.9.203.10
59.182.251.171
61.14.3.165
62.140.238.1
62.57.137.76
67.204.146.123
77.236.6.91
77.30.51.182
77.31.4.53
77.31.64.86
78.106.36.221
78.160.216.232
78.162.210.118
78.162.73.40
78.163.200.222
78.165.108.153
78.166.191.79
78.167.164.42
78.167.58.60
78.169.14.70
78.93.197.72
78.93.82.106
78.96.182.134
79.189.49.202
81.214.156.70
83.29.230.20
84.10.79.200
84.139.136.5
84.47.93.42
85.101.110.99
85.103.13.223
85.103.251.189
85.104.58.189
85.105.209.23
85.108.245.33
85.108.253.26
85.110.153.77
85.110.157.133
85.110.171.230
85.198.177.13
85.99.185.187
86.122.165.34
87.0.54.121
87.109.14.12
87.109.14.174
87.109.159.178
87.120.109.249
87.205.244.153
88.224.151.137
88.224.251.96
88.224.44.225
88.224.75.134
88.226.69.100
88.227.248.11
88.228.97.232
88.230.74.81
88.232.153.116
88.234.163.254
88.237.221.48
88.238.89.111
88.242.123.170
88.243.107.145
88.243.217.210
88.245.107.7
88.245.228.14
88.246.96.61
88.252.78.129
88.254.234.140
89.136.79.96
89.228.156.6
89.252.9.126
89.46.136.175
89.76.97.16
90.148.146.140
91.124.23.200
91.201.112.2
92.112.23.168
92.37.151.127
92.44.194.243
92.47.222.107
92.61.238.120
92.82.172.41
93.94.178.187
93.98.37.210
94.44.29.200
94.96.11.241
94.99.184.93
94.99.74.20
95.134.200.103
95.58.142.176
95.78.138.40
113.53.170.179
116.71.2.192
117.197.96.124
118.43.204.82
121.159.184.91
121.242.55.42
124.121.38.204
124.121.85.111
125.136.199.83
188.48.200.177
189.112.85.88
189.114.152.233
189.12.187.224
189.24.135.57
189.27.243.210
189.46.152.128
189.78.253.59
189.82.74.79
189.93.0.162
190.120.140.118
190.135.146.135
190.19.69.90
196.218.55.234
200.121.245.19
200.163.33.130
201.19.24.84
201.24.126.235
201.67.135.232
201.67.186.108
201.76.71.9
203.197.115.82
211.107.153.132
211.247.31.154
212.26.246.161
213.181.170.167
213.25.157.1
217.147.25.250
218.152.226.159
220.253.192.12
Monday, March 16, 2009
Waledac: Fake Dirty Bomb in Your City
In the February 25th edition of this Blog, Watch Out For Coupon Offers, we described how the Waledac malware family was being distributed in spam pretending to be from "The Couponizer". One of the unique additions to that campaign was that the criminal was using a GeoLocation service on his website to customize the website to reflect the location of your computer.

So, in my location, the headline reads "Powerful explosion burst in Birmingham this morning.", but that is because the criminal has resolved my originating IP and determined I was in Birmingham, Alabama.
In today's version of the Waledac spam, we see the same brief emails which were used in the Valentine's Day and Couponizer Waledac campaigns. A small phrase as the subject line, such as:
Haven't you been there?
I hope you are in good health
What a tragedy!
Take care about yourself!
and another small phrase in the body, such as:
Are you and your friends ok?
How do you feel?
I worry about you
We worry about you
followed by a link to a website, ending in "main.php" or "run.php" or "contact.php", or with no filename at all - just the path.
Clicking on the video controls will prompt for the download of an executable - "news.exe" in my case, which would join your computer to the spamming botnet.
VirusTotal gave a 7 of 39 detection rate for this malware.
click here for VirusTotal Report.
For whatever reason it seems that NOBODY is shutting down the Waledac domains. We reviewed 57 recent and current Waledac domains, and found that only six of them were not currently resolving.
Here is the list of domains associated with Waledac:
adorepoem.com
adoresong.com
adoresongs.com
bestadore.com
bestbreakingfree.com
bestcouponfree.com
bestgoodnews.com
bestlovehelp.com
bestlovelong.com
bluevalentineonline.com
breakingfreemichigan.com
breakinggoodnews.com
breakingkingnews.com
breakingnewsfm.com
breakingnewsltd.com
chatloveonline.com
cherishletter.com
cherishpoems.com
codecouponsite.com
extendedman.com
farboards.com
funloveonline.com
funnyvalentinessite.com
goodnewsdigital.com
goodnewsreview.com
greatcouponclub.com
greatsalesgroup.com
greatsalestax.com
greatsvalentine.com
greatvalentinepoems.com
linkworldnews.com
longballonline.com
lovecentralonline.com
lovelifeportal.com
reportradio.com
romanticsloving.com
smartsalesgroup.com
spacemynews.com
supersalesonline.com
thecoupondiscount.com
thevalentinelovers.com
thevalentineparty.com
tntbreakingnews.com
wapcitynews.com
whocherish.com
wirelessvalentineday.com
worldlovelife.com
worldnewsdot.com
worldnewseye.com
worldtracknews.com
worshiplove.com
youradore.com
yourbreakingnew.com
yourcountycoupon.com
yourgreatlove.com
yourlength.com
yourvalentinepoems.com
You can clearly see that some are "News", some "Coupon", and some "Valentine" related, but they are almost all still active and still infecting people's computers in an attempt to regrow the Waledac spamming botnet.
The domain names use only four different identities in their WHOIS data:
yanshi_ying@yeah.net (Yan Shi Ying)
ed30673637@126.com (Zhao Jun Hua)
meishengchang@163.com (LiPaul Kunshan Yunshu Gongsi)
wusong_ccc@126.com (Zhang Min)
We don't know the size of the Waledac spamming botnet right now, but we were able to quickly make a list of more than 1,200 machines which are currently "hosting" the webservers used by the malware. I've made a file available of 1,235 IP addresses currently hosting Waledac web proxy servers, but that is only a tiny sample of the overall population. Domain owners will find the IP addresses sorted by Country Code, then ASN/Organization, and then IP. Country codes of the bots include:
AR, AU, BA, BE, BG, BR, BS, BY, CA, CH, CI, CL, CN, CO, CS, CZ, DE, DK,
EE, ES, EU, FI, FR, GB, GE, HK, HU, IE, IL, IN, IR, IT, JP, KR, KZ, LT,
LV, MA, MD, MK, MY, NL, NO, PH, PL, PT, RO, RS, RU, SE, SI, SK, TH, TN,
TR, UA, US, UY, VN, and ZA.
(Quiz yourself - How many of those country codes do you know?
Need to cheat? - list of country codes)
The distribution of infected machines in my little snapshot is quite diverse. More than 300 networks from 60 different countries, with no network having more than 60 of the 1,235 machines on my list.
The top networks in my unscientific snapshot were:
59 machines - ComCast ASN 7922 (USA)
58 machines - Proxad ASN 12322 (France)
54 machines - Rogers Cable ASN 812 (Canada)
52 machines - AT&T ASN 7132 (USA)
51 machines - NTL Group ASN 5089 (Great Britain)
44 machines - Shaw Communications ASN 6327 (Canada)
34 machines - Charter Communications ASN 20115 (USA)
27 machines - ComCast ASN 33491 (USA)
26 machines - Road Runner ASN 11427 (USA)
20 machines - ComCast ASN 33278 (USA)
The full list is available as an Excel spreadsheet or as a CSV file.

So, in my location, the headline reads "Powerful explosion burst in Birmingham this morning.", but that is because the criminal has resolved my originating IP and determined I was in Birmingham, Alabama.
In today's version of the Waledac spam, we see the same brief emails which were used in the Valentine's Day and Couponizer Waledac campaigns. A small phrase as the subject line, such as:
Haven't you been there?
I hope you are in good health
What a tragedy!
Take care about yourself!
and another small phrase in the body, such as:
Are you and your friends ok?
How do you feel?
I worry about you
We worry about you
followed by a link to a website, ending in "main.php" or "run.php" or "contact.php", or with no filename at all - just the path.
Clicking on the video controls will prompt for the download of an executable - "news.exe" in my case, which would join your computer to the spamming botnet.
VirusTotal gave a 7 of 39 detection rate for this malware.
click here for VirusTotal Report.
For whatever reason it seems that NOBODY is shutting down the Waledac domains. We reviewed 57 recent and current Waledac domains, and found that only six of them were not currently resolving.
Here is the list of domains associated with Waledac:
adorepoem.com
adoresong.com
adoresongs.com
bestadore.com
bestbreakingfree.com
bestcouponfree.com
bestgoodnews.com
bestlovehelp.com
bestlovelong.com
bluevalentineonline.com
breakingfreemichigan.com
breakinggoodnews.com
breakingkingnews.com
breakingnewsfm.com
breakingnewsltd.com
chatloveonline.com
cherishletter.com
cherishpoems.com
codecouponsite.com
extendedman.com
farboards.com
funloveonline.com
funnyvalentinessite.com
goodnewsdigital.com
goodnewsreview.com
greatcouponclub.com
greatsalesgroup.com
greatsalestax.com
greatsvalentine.com
greatvalentinepoems.com
linkworldnews.com
longballonline.com
lovecentralonline.com
lovelifeportal.com
reportradio.com
romanticsloving.com
smartsalesgroup.com
spacemynews.com
supersalesonline.com
thecoupondiscount.com
thevalentinelovers.com
thevalentineparty.com
tntbreakingnews.com
wapcitynews.com
whocherish.com
wirelessvalentineday.com
worldlovelife.com
worldnewsdot.com
worldnewseye.com
worldtracknews.com
worshiplove.com
youradore.com
yourbreakingnew.com
yourcountycoupon.com
yourgreatlove.com
yourlength.com
yourvalentinepoems.com
You can clearly see that some are "News", some "Coupon", and some "Valentine" related, but they are almost all still active and still infecting people's computers in an attempt to regrow the Waledac spamming botnet.
The domain names use only four different identities in their WHOIS data:
yanshi_ying@yeah.net (Yan Shi Ying)
ed30673637@126.com (Zhao Jun Hua)
meishengchang@163.com (LiPaul Kunshan Yunshu Gongsi)
wusong_ccc@126.com (Zhang Min)
We don't know the size of the Waledac spamming botnet right now, but we were able to quickly make a list of more than 1,200 machines which are currently "hosting" the webservers used by the malware. I've made a file available of 1,235 IP addresses currently hosting Waledac web proxy servers, but that is only a tiny sample of the overall population. Domain owners will find the IP addresses sorted by Country Code, then ASN/Organization, and then IP. Country codes of the bots include:
AR, AU, BA, BE, BG, BR, BS, BY, CA, CH, CI, CL, CN, CO, CS, CZ, DE, DK,
EE, ES, EU, FI, FR, GB, GE, HK, HU, IE, IL, IN, IR, IT, JP, KR, KZ, LT,
LV, MA, MD, MK, MY, NL, NO, PH, PL, PT, RO, RS, RU, SE, SI, SK, TH, TN,
TR, UA, US, UY, VN, and ZA.
(Quiz yourself - How many of those country codes do you know?
Need to cheat? - list of country codes)
The distribution of infected machines in my little snapshot is quite diverse. More than 300 networks from 60 different countries, with no network having more than 60 of the 1,235 machines on my list.
The top networks in my unscientific snapshot were:
59 machines - ComCast ASN 7922 (USA)
58 machines - Proxad ASN 12322 (France)
54 machines - Rogers Cable ASN 812 (Canada)
52 machines - AT&T ASN 7132 (USA)
51 machines - NTL Group ASN 5089 (Great Britain)
44 machines - Shaw Communications ASN 6327 (Canada)
34 machines - Charter Communications ASN 20115 (USA)
27 machines - ComCast ASN 33491 (USA)
26 machines - Road Runner ASN 11427 (USA)
20 machines - ComCast ASN 33278 (USA)
The full list is available as an Excel spreadsheet or as a CSV file.
Finding the Spam Before Its Spammed . . .
This morning I met with Brian Tanner, one of the UAB Malware Analysts, to determine what malware he should unpack for us this morning. I told him that I was interested in doing a quick check on the "Facebook" malware that we saw over the weekend. The only problem is that Ryan and the guys at Facebook had already had all those domains shut down. No problem. We'll just find the domains they are ABOUT to spam instead.
The UAB Spam Data Mine had received more than 500 emails yesterday in what we are calling the "Facebook Stripper" spam campaign.

The subject lines are each unique, having a suffix of "(Last rated by Random Name)", where Random Name has a first and last name randomly chosen. There are 32 base subjects though:
FaceBook message: Dancing Girl Drunk In The Pub- facebook Video
FaceBook message: Amateur Video - Perfect Girls striptease
FaceBook message: Art Of Exotic Dancing Striptease Series - video...
FaceBook message: Beautiful Girl Dancing Extrahard Striptease!
FaceBook message: Beautiful Girl Dancing Striptease! Cute!
FaceBook message: Beautiful girl hot dancing alone - video
FaceBook message: Beautiful Girls Dancing in the Club
FaceBook message: Dancing Girl loves herself - Amazing Clips
FaceBook message: Dancing girl oriental dance ...
FaceBook message: Dancing girls ... Funny and Hot Videos
FaceBook message: Erotic Dance Striptease
FaceBook message: Exotic Dance Video From facebook member.
FaceBook message: Extreme striptease dance video
FaceBook message: Facebook girl Striptease Beautiful dance
FaceBook message: facebook members Dancing In Striptease
FaceBook message: Girls Dancing on facebook Video
FaceBook message: Hot Girl Dancing At Striptease Dance Party
FaceBook message: Magnificent Exotic Dancing - video ...
FaceBook message: Magnificent girl dancing video clip
FaceBook message: Magnificent Girls dancing in front of camera
FaceBook message: Magnificent Girls dancing on stage
FaceBook message: Magnificent Girls extremely dancing
FaceBook message: Magnificent Striptease Dance
FaceBook message: Numerous of Magnificent Girls Dancing video
FaceBook message: Perfect Girl Dancing Video
FaceBook message: Perfect Girls Dancing - Video
FaceBook message: Smokin' and dancing girl
FaceBook message: These two girls are so... watch the video
FaceBook message: Two Magnificent Girls Dancing, More Info ...
FaceBook message: Two Magnificent Girls Dancing...
FaceBook message: Very Beautiful facebook girl Dance Video!
FaceBook message: Watch the Oooh! Super Beautiful Girl Dancing
Yesterday the domains used in the spam were:
53445player.com
5436player.com
7636player.com
4346player.com
867player.com
While these domains were hosted on a large number of botnet hosted machines, their nameserver actually had a static location. They all used the nameserver "ns1.pvthstonline.com" (8.12.160.183) and "ns2.pvthstonline.com" (205.1.190.113).
Using a Passive DNS Replication service (*wave* to Florian), we checked to see what other nameservers were hosted on 205.1.190.113.
ns2.insdcertificate.com and ns2.shortcuttingv.com were both hosted on that IP.
We knew that the domains served by insdcertificate.com were old - we saw those mostly on the 13th -- 342certificate.com, 234certificate.com, 656certificate.com, 767certificate.com and 867certificate.com -- so we decided to look for domains that were served by ns2.shortcuttingv.com.
Sure enough, we found five domains - all registered THIS MORNING (its only 10:40 AM here):
423adobe.com
545adobe.com
675adobe.com
685adobe.com
987adobe.com
We confirmed that 423adobe.com is being fast flux hosted -- its currently using the IP addresses:
71.195.128.169 (ComCast in Brandon, MA)
75.138.113.226 (Charter Cable in Ashville, NC)
96.32.130.151 (Charter Cable in Alpharetta, GA)
98.209.65.175 (ComCast in East Lansing, MI)
208.120.237.132 (Mindspring in Brooklyn, NY)
Looking at some history on these IPs, we can confirm that they have previously hosted Bank of America "video demo malware", on domains such as 867certificate.com and aheadfixpatch.com, as well as previous days of the Facebook stripper malware, on domains such as 5436player.com, and facebooketus.com.
When we put the "path" of "/home.htm" on one of the domains that we are predicting for today's host, we get the Facebook look-alike page, along with a popup telling us we have to download a new video player (which is actually the virus), now using the name "Flash_Adobe11.exe"

Uploading the malware to VirusTotal, we see that it is only detected by 4 of the 39 anti-virus products with which it is scanned. If you are relying on AVG, McAfee, Microsoft, Symantec, Trend, or pretty much anyone else to protect you from this virus, so far, they don't know about it. (Our report to VirusTotal causes a copy to be sent to them for analysis though - which is one of the reasons we love VirusTotal!)
Click for VirusTotal report
File size: 36352 bytes
MD5...: d17008513f2c93933b92a392260c5cda
Brian finished unpacking the malware and confirms that this copy still sends its stolen credentials to Hong Kong's HostFresh network to the IP address 58.65.232.17.
We've now seen more than 300 copies of the "predicted" facebook spam, and the criminals have now shifted again to another group of domain names:
2433module.com
3445module.com
3499module.com
5464module.com
9873module.com
We've seen less than 4 copies of each of these latest, which have a new malware piece as well, which you can find a VirusTotal report for here:
http://www.virustotal.com/analisis/aadd5db3b69580412041681ea3bb65e7
The UAB Spam Data Mine had received more than 500 emails yesterday in what we are calling the "Facebook Stripper" spam campaign.
The subject lines are each unique, having a suffix of "(Last rated by Random Name)", where Random Name has a first and last name randomly chosen. There are 32 base subjects though:
FaceBook message: Dancing Girl Drunk In The Pub- facebook Video
FaceBook message: Amateur Video - Perfect Girls striptease
FaceBook message: Art Of Exotic Dancing Striptease Series - video...
FaceBook message: Beautiful Girl Dancing Extrahard Striptease!
FaceBook message: Beautiful Girl Dancing Striptease! Cute!
FaceBook message: Beautiful girl hot dancing alone - video
FaceBook message: Beautiful Girls Dancing in the Club
FaceBook message: Dancing Girl loves herself - Amazing Clips
FaceBook message: Dancing girl oriental dance ...
FaceBook message: Dancing girls ... Funny and Hot Videos
FaceBook message: Erotic Dance Striptease
FaceBook message: Exotic Dance Video From facebook member.
FaceBook message: Extreme striptease dance video
FaceBook message: Facebook girl Striptease Beautiful dance
FaceBook message: facebook members Dancing In Striptease
FaceBook message: Girls Dancing on facebook Video
FaceBook message: Hot Girl Dancing At Striptease Dance Party
FaceBook message: Magnificent Exotic Dancing - video ...
FaceBook message: Magnificent girl dancing video clip
FaceBook message: Magnificent Girls dancing in front of camera
FaceBook message: Magnificent Girls dancing on stage
FaceBook message: Magnificent Girls extremely dancing
FaceBook message: Magnificent Striptease Dance
FaceBook message: Numerous of Magnificent Girls Dancing video
FaceBook message: Perfect Girl Dancing Video
FaceBook message: Perfect Girls Dancing - Video
FaceBook message: Smokin' and dancing girl
FaceBook message: These two girls are so... watch the video
FaceBook message: Two Magnificent Girls Dancing, More Info ...
FaceBook message: Two Magnificent Girls Dancing...
FaceBook message: Very Beautiful facebook girl Dance Video!
FaceBook message: Watch the Oooh! Super Beautiful Girl Dancing
Yesterday the domains used in the spam were:
53445player.com
5436player.com
7636player.com
4346player.com
867player.com
While these domains were hosted on a large number of botnet hosted machines, their nameserver actually had a static location. They all used the nameserver "ns1.pvthstonline.com" (8.12.160.183) and "ns2.pvthstonline.com" (205.1.190.113).
Using a Passive DNS Replication service (*wave* to Florian), we checked to see what other nameservers were hosted on 205.1.190.113.
ns2.insdcertificate.com and ns2.shortcuttingv.com were both hosted on that IP.
We knew that the domains served by insdcertificate.com were old - we saw those mostly on the 13th -- 342certificate.com, 234certificate.com, 656certificate.com, 767certificate.com and 867certificate.com -- so we decided to look for domains that were served by ns2.shortcuttingv.com.
Sure enough, we found five domains - all registered THIS MORNING (its only 10:40 AM here):
423adobe.com
545adobe.com
675adobe.com
685adobe.com
987adobe.com
We confirmed that 423adobe.com is being fast flux hosted -- its currently using the IP addresses:
71.195.128.169 (ComCast in Brandon, MA)
75.138.113.226 (Charter Cable in Ashville, NC)
96.32.130.151 (Charter Cable in Alpharetta, GA)
98.209.65.175 (ComCast in East Lansing, MI)
208.120.237.132 (Mindspring in Brooklyn, NY)
Looking at some history on these IPs, we can confirm that they have previously hosted Bank of America "video demo malware", on domains such as 867certificate.com and aheadfixpatch.com, as well as previous days of the Facebook stripper malware, on domains such as 5436player.com, and facebooketus.com.
When we put the "path" of "/home.htm" on one of the domains that we are predicting for today's host, we get the Facebook look-alike page, along with a popup telling us we have to download a new video player (which is actually the virus), now using the name "Flash_Adobe11.exe"
Uploading the malware to VirusTotal, we see that it is only detected by 4 of the 39 anti-virus products with which it is scanned. If you are relying on AVG, McAfee, Microsoft, Symantec, Trend, or pretty much anyone else to protect you from this virus, so far, they don't know about it. (Our report to VirusTotal causes a copy to be sent to them for analysis though - which is one of the reasons we love VirusTotal!)
Click for VirusTotal report
File size: 36352 bytes
MD5...: d17008513f2c93933b92a392260c5cda
Brian finished unpacking the malware and confirms that this copy still sends its stolen credentials to Hong Kong's HostFresh network to the IP address 58.65.232.17.
Afternoon Update
We've now seen more than 300 copies of the "predicted" facebook spam, and the criminals have now shifted again to another group of domain names:
2433module.com
3445module.com
3499module.com
5464module.com
9873module.com
We've seen less than 4 copies of each of these latest, which have a new malware piece as well, which you can find a VirusTotal report for here:
http://www.virustotal.com/analisis/aadd5db3b69580412041681ea3bb65e7
Wednesday, March 11, 2009
ClassMates.com spam keeps sucking passwords
Yesterday we received more than 800 copies of spam email messages using a ClassMates.com subject to trick people into infecting themselves with a password stealing program.

There were two separate groups of websites. The first group of five domains all used the nameserver ns1.boxingmital.com. The domain names were:
brloadvideo.com (34 emails)
coreadminclass.com (42 emails)
meetingclassmatesserver.com (37 emails)
servesonline.com (44 emails)
updateunionplayer.com (54 emails)
This one had 29 different subject lines:
Classmates personal message: - Help me decide please....
Classmates personal message: "Help me to decide which way to choose?"
Classmates personal message: Can you help me to choose my final woman?
Classmates personal message: Girls Help me to Decide? I want as many answers as Possible please ...
Classmates personal message: Help me decide please - Wife Guys!
Classmates personal message: HELP ME TO CHOOSE A GOOD WOMAN PLEASE!
Classmates personal message: Help me to choose....Wife Guys!
Classmates personal message: Help me to decide a good and with best woman
Classmates personal message: Help me to decide my wife! - family
Classmates personal message: Help me to decide on a woman and wife?
Classmates personal message: Help me to decide on a woman.
Classmates personal message: Help me to decide on my family.
Classmates personal message: Help me to decide please!
Classmates personal message: Help me to decide what kind of woman better!
Classmates personal message: Help me to decide whether or not to tell my friend that ...
Classmates personal message: Help me to decide which woman better
Classmates personal message: Help me to decide which woman to choose?
Classmates personal message: Help me to decide. Making decisions about my family can be confusing.
Classmates personal message: Hi all, i need your opinion and help for choosing woman
Classmates personal message: Hi Guys Please help me to choose between the two womans.
Classmates personal message: Please help me to decide which way to choose
Classmates personal message: Please, help me to choose right woman!
Classmates personal message: plz help me to choose what to do, Wife is a beast!
Classmates personal message: Re:can you help me to choose a wife
Classmates personal message: Who can help me to decide where is right way.
Classmates personal message: Wife Guys! Help Me To Decide WIfe!!!
Classmates personal message: Wife Guys! information to help me choose the right way
Classmates personal message: Wife Guys! Need to decide Quickly what to do, PLEASE HELP ME.
Classmates personal message: Wife is a beast! can any one help me to choose
The bodies of the emails in this group looked like this:
The second group of emails also came from five different domains, which all used the nameserver "ns1.clickforghost.com". The domains in this group were:
clieckfordownload.com (120 emails)
installserverversion10.com (125 emails)
unionmeetflash.com (131 emails)
updtadeyouwinplayer.com (121 emails)
videoplayer11version.com (128 emails)
And the subject lines from this group were:
2009 Classmates - 2009 Meeting
2009 Classmates - Annual Meeting
2009 Classmates - Getting Video
2009 Classmates - Ill have more to say about the specifics of the meeting soon
2009 Classmates - Meetings
2009 Classmates - Save video fragments from movies with the simplicity of pressing ...
2009 Classmates Annual Meeting
2009 Classmates Annual Meeting -- Coming Soon! - Modern ...
2009 Classmates Annual Meeting & Exposition
2009 Classmates ANNUAL MEETING March 11, 2009
2009 Classmates Annual Meeting.
2009 Classmates FREE VIDEO CONFERENCING,
2009 Classmates Meeting Registration, Registration information, coming soon. ...
2009 Classmates Online Meeting - Fast. Easy. Secure
2009 Classmates start searching for friends, classmates, family
2009 Classmates TOLL FREE AUDIO, ONLINE ...
2009 Classmates Video Conferencing and Online Meeting Services
2009 Classmates Videos
2009 Classmates WEB CONFERENCING,
Annual 2009 Classmates Meeting has become the premier meeting
Annual Meeting - 2009 Classmates
Classmates 2009 Annual Meeting March
Classmates annual meeting as soon as possible - invitation
Get to Know Your Classmates - What Works
Greetings fellow members of the 2009 Classmates
Helping Classmates Understand invitations 2009 Classmates
Invite Your Friends and Get invited! 2009 Classmates
Meet your classmates -- join our social network
News - 2009 Classmates Annual Meeting.
One of your classmates have 4 kids...
One of your classmates have airplan...
One of your classmates have limo...
One of your classmates invitation...
One of your classmates lost...
One of your classmates new photos...
One of your classmates sent invitation to you...
One of your classmates wedding...
Save The Date! 2009 Classmates Annual Meeting soon.
Video Clips- 2009 Classmates!
What are your ol' classmates up to? > General Family & Friends ...
What is an Annual Return? 2009 Classmates
In both examples, the name after the "Sincerely" was randomly selected from a huge list of possible first and last names.
Once infected, the malware steals passwords from FTP sessions, POP3 and IMAP email sessions, ICQ sessions, and any webpages that seem to be prompting for a login. The stolen data used to be sent to UKR Telecom in these cases, but we've had another update. The data is now sent to HostFresh in Hong Kong at the IP address 58.65.232.17
inetnum: 58.65.232.0 - 58.65.239.255
netname: HOSTFRESH
descr: HostFresh
descr: Internet Service Provider
country: HK
admin-c: PL466-AP
tech-c: PL466-AP
remarks: Please send Spam & Abuse report to
remarks: abuse@hostfresh.com
person: Piu Lo
nic-hdl: PL466-AP
e-mail: ipadmin@hostfresh.com
address: No. 500, Post Office, Tuen Mun, N.T., Hong Kong
phone: +852-35979788
fax-no: +852-24522539
country: HK
changed: 20071025
A virusTotal report on the malware, which was named "AdobeMedia10.exe" can be found at the following URL (9 of 39 anti-virus products now know this is a virus. Yesterday it was 6 of 39.)
http://www.virustotal.com/analisis/eec39a519bd12b2c654bc541fd3a2907

For malware analyst fans, I was out of the office so I used "Eureka" to unpack the malware. You can find strings from the unpacked executable here:
http://eureka.cyber-ta.org/OUTPUT/c26213f4a96b0c5b9b2f4c98813ca264/
There were two separate groups of websites. The first group of five domains all used the nameserver ns1.boxingmital.com. The domain names were:
brloadvideo.com (34 emails)
coreadminclass.com (42 emails)
meetingclassmatesserver.com (37 emails)
servesonline.com (44 emails)
updateunionplayer.com (54 emails)
This one had 29 different subject lines:
Classmates personal message: - Help me decide please....
Classmates personal message: "Help me to decide which way to choose?"
Classmates personal message: Can you help me to choose my final woman?
Classmates personal message: Girls Help me to Decide? I want as many answers as Possible please ...
Classmates personal message: Help me decide please - Wife Guys!
Classmates personal message: HELP ME TO CHOOSE A GOOD WOMAN PLEASE!
Classmates personal message: Help me to choose....Wife Guys!
Classmates personal message: Help me to decide a good and with best woman
Classmates personal message: Help me to decide my wife! - family
Classmates personal message: Help me to decide on a woman and wife?
Classmates personal message: Help me to decide on a woman.
Classmates personal message: Help me to decide on my family.
Classmates personal message: Help me to decide please!
Classmates personal message: Help me to decide what kind of woman better!
Classmates personal message: Help me to decide whether or not to tell my friend that ...
Classmates personal message: Help me to decide which woman better
Classmates personal message: Help me to decide which woman to choose?
Classmates personal message: Help me to decide. Making decisions about my family can be confusing.
Classmates personal message: Hi all, i need your opinion and help for choosing woman
Classmates personal message: Hi Guys Please help me to choose between the two womans.
Classmates personal message: Please help me to decide which way to choose
Classmates personal message: Please, help me to choose right woman!
Classmates personal message: plz help me to choose what to do, Wife is a beast!
Classmates personal message: Re:can you help me to choose a wife
Classmates personal message: Who can help me to decide where is right way.
Classmates personal message: Wife Guys! Help Me To Decide WIfe!!!
Classmates personal message: Wife Guys! information to help me choose the right way
Classmates personal message: Wife Guys! Need to decide Quickly what to do, PLEASE HELP ME.
Classmates personal message: Wife is a beast! can any one help me to choose
The bodies of the emails in this group looked like this:
Special video report March 10, 2009
Message from your group member:
"Should I leave my Crazy Fat Wife for a younger woman? Please look video and Help me to decide, please ........I need your help, if possible - Write your opinion on the page wall"
Proceed to open full message text:
http://classmates.messagecenter.filetime.videomessageid-toa3dk6b1.coreadminclass.com/msg4829.htm?/boundary/LOGIN=bf96xidehi5oqtc
Sincerely, Velma Lacy.
2009 Classmates Message Center.
The second group of emails also came from five different domains, which all used the nameserver "ns1.clickforghost.com". The domains in this group were:
clieckfordownload.com (120 emails)
installserverversion10.com (125 emails)
unionmeetflash.com (131 emails)
updtadeyouwinplayer.com (121 emails)
videoplayer11version.com (128 emails)
And the subject lines from this group were:
2009 Classmates - 2009 Meeting
2009 Classmates - Annual Meeting
2009 Classmates - Getting Video
2009 Classmates - Ill have more to say about the specifics of the meeting soon
2009 Classmates - Meetings
2009 Classmates - Save video fragments from movies with the simplicity of pressing ...
2009 Classmates Annual Meeting
2009 Classmates Annual Meeting -- Coming Soon! - Modern ...
2009 Classmates Annual Meeting & Exposition
2009 Classmates ANNUAL MEETING March 11, 2009
2009 Classmates Annual Meeting.
2009 Classmates FREE VIDEO CONFERENCING,
2009 Classmates Meeting Registration, Registration information, coming soon. ...
2009 Classmates Online Meeting - Fast. Easy. Secure
2009 Classmates start searching for friends, classmates, family
2009 Classmates TOLL FREE AUDIO, ONLINE ...
2009 Classmates Video Conferencing and Online Meeting Services
2009 Classmates Videos
2009 Classmates WEB CONFERENCING,
Annual 2009 Classmates Meeting has become the premier meeting
Annual Meeting - 2009 Classmates
Classmates 2009 Annual Meeting March
Classmates annual meeting as soon as possible - invitation
Get to Know Your Classmates - What Works
Greetings fellow members of the 2009 Classmates
Helping Classmates Understand invitations 2009 Classmates
Invite Your Friends and Get invited! 2009 Classmates
Meet your classmates -- join our social network
News - 2009 Classmates Annual Meeting.
One of your classmates have 4 kids...
One of your classmates have airplan...
One of your classmates have limo...
One of your classmates invitation...
One of your classmates lost...
One of your classmates new photos...
One of your classmates sent invitation to you...
One of your classmates wedding...
Save The Date! 2009 Classmates Annual Meeting soon.
Video Clips- 2009 Classmates!
What are your ol' classmates up to? > General Family & Friends ...
What is an Annual Return? 2009 Classmates
Special video report March 10, 2009
One of your classmates has sent you a video invitation:
"Read the story and see photos of my wedding and our tour,Please discover our video invitation to your family. I hope to get back from you soon..."
Proceed to view full message:
http://classmates.messagecenter.asp.videomessageid-x0ajpo2vz1.updtadeyouwinplayer.com/msg4829.htm?/InterstitialControl/LOGIN=t8k6pqzb5azfjpw
Sincerely, Marion Lyon.
2009 Classmates Message Center.
In both examples, the name after the "Sincerely" was randomly selected from a huge list of possible first and last names.
Once infected, the malware steals passwords from FTP sessions, POP3 and IMAP email sessions, ICQ sessions, and any webpages that seem to be prompting for a login. The stolen data used to be sent to UKR Telecom in these cases, but we've had another update. The data is now sent to HostFresh in Hong Kong at the IP address 58.65.232.17
inetnum: 58.65.232.0 - 58.65.239.255
netname: HOSTFRESH
descr: HostFresh
descr: Internet Service Provider
country: HK
admin-c: PL466-AP
tech-c: PL466-AP
remarks: Please send Spam & Abuse report to
remarks: abuse@hostfresh.com
person: Piu Lo
nic-hdl: PL466-AP
e-mail: ipadmin@hostfresh.com
address: No. 500, Post Office, Tuen Mun, N.T., Hong Kong
phone: +852-35979788
fax-no: +852-24522539
country: HK
changed: 20071025
A virusTotal report on the malware, which was named "AdobeMedia10.exe" can be found at the following URL (9 of 39 anti-virus products now know this is a virus. Yesterday it was 6 of 39.)
http://www.virustotal.com/analisis/eec39a519bd12b2c654bc541fd3a2907
For malware analyst fans, I was out of the office so I used "Eureka" to unpack the malware. You can find strings from the unpacked executable here:
http://eureka.cyber-ta.org/OUTPUT/c26213f4a96b0c5b9b2f4c98813ca264/
Thursday, February 26, 2009
Another Password Stealer hides as Bank of America video malware
One of our top spam campaigns today at the UAB Spam Data Mine is the newest Snifula/Gozi password stealing trojan, this time disguised as a Bank of America malware.

I'll go ahead and give you the text of their warning, because this is just hilarious on a website THAT INTENDS TO PLANT A KEYLOGGER ON YOUR COMPUTER!
The email, which we've seen several hundred times so far, will contain a link to one of the following websites:
videopatchdownload.com
viewvideopatch.com
screensecuritypatch.com
serverupdtatevideo.com
patchdownloader.com
Faithful readers will already know that these will have all been created today, using the Chinese registrar BizCN.com. Its almost not worth looking up, the pattern is so predictable. But, lest we be accused of not being thorough, we did. Yeah, its BizCN.com. There are always five domains, all sharing the same nameserver, in this case, ns1.localterms.com.
The spam message itself has used FIFTY different subject lines:
Adopt Best Practices Online - Bank of America
Always "Log-off" Internet Banking first then close your browser - Bank of America
Always remember to Log-Off Internet Banking - Bank of America
Avoid accessing your online banking information at Internet or Cyber cafes - Bank of America
Bank of America, and/or Banc of America security # apply updates
Bank of America, and/or Banc of America security # Ensure that your operating system has all latest patches and updates installed.
Bank of America, and/or Banc of America security # Ensure that your operating system updated.
Bank of America, and/or Banc of America security # latest patches and updates installation.
Bank of America, and/or Banc of America Security alert
Bank of America, and/or Banc of America security measures
Bank of America, and/or Banc of America security measures 2008
Bank of America, and/or Banc of America security measures 2008 you can take to protect your company
Bank of America, and/or Banc of America security measures you can take to protect your company
Bank of America, N.A. (BANA) and/or Banc of America also provides extensive information regarding identity theft prevention
Bank of America, N.A. (BANA) and/or Banc of America has developed a Fraud Prevention Checklist
Bank of America, N.A. (BANA) and/or Banc of America has developed a new 128 bit sofware
Bank of America, N.A. (BANA) and/or Banc of America has developed an update for log in page
Bank of America, N.A. (BANA) and/or Banc of America has developed new anti-Fraud feature
Bank of America, N.A. (BANA) and/or Banc of America has developed new free protection tool
Bank of America, N.A. (BANA) and/or Banc of America has developed serious protection
Bank of America, N.A. (BANA) and/or Banc of America has developed special file protection
Bank of America, N.A. (BANA) and/or Banc of America is committed to providing you with a convenient, safe and secure online banking
Bank of America, N.A. (BANA) and/or Banc of America News - security development
Bank of America, N.A. (BANA) and/or Banc of America recommend that you use 128 bit file
Bank of America, N.A. (BANA) and/or Banc of America recommend that you use fraud prevention procedures
Bank of America, N.A. (BANA) and/or Banc of America recommend that you use security update
Bank of America, N.A. (BANA) and/or Banc of America recommend that you use updated browser
Bank of America, N.A. (BANA) and/or Banc of America recommend to review your account security
Bank of America, N.A. (BANA) and/or Banc of America would like to announce latest update
Bank of America, N.A. (BANA) and/or Banc of America would like to inform you lates development
Bank of America, N.A. (BANA) and/or Banc of America would like to inform you news
Bank of America, N.A. (BANA) and/or Banc of America would like to inform you security updates
Bank of America, N.A. (BANA) and/or Banc of America would like to open new security features
Bank of America, N.A. (BANA) and/or Banc of America would like to stop fraud practice
Check your computer manufacturer's (hardware/operating system) Web site for "patches"
Do not share your Internet Banking User name and Password with anyone - Bank of America
Don't share access to your computer with strangers - Bank of America
Financial data confidential at all times - Bank of America
Install Firewall software on your home and networked computers - Bank of America
Learn about computer infections and be aware of the latest computer viruses - Bank of America
Memorize your Password and Bill Pay Security Key and never write it down or reveal it to anyone - Bank of America
Only provide information that you initiate through an application - Bank of America
Our systems and security procedures- Bank of America
Protect them and change your Passwords on a regular basis - every 60 days - Bank of America
Protect Your Computer - Bank of America
Protected from unauthorized use - Bank of America
The security of your information is paramount- Bank of America
This will help prevent others from being able to view your online banking information - Bank of America
Use a combination of both letters and numbers - Bank of America.
Your Log-In Information - Bank of America
Your Password to your online account information - Bank of America
The faithful readers will also already know that these websites are all "Fast Flux hosted", and that they use the same Fast Flux network as the ASProx phishing spam.
So, for example, the IP address 24.87.189.139, Shaw Communications in Calgary, is hosting our current video malware, but has also been seen hosting Classmates.com malware (which is Snifula/Gozi), such as domains such as customeridclass.com, , as well as the current "Net Teller" phishing campaign on domains like ijili.be, proftd.name, id-refts.mobi, proftd.eu, uttjii.eu, and utltii.eu -- the "Comerica" phishing on domains such as r003.eu, idir04.eu, dll-5.eu, v005.eu, dll-8.eu, dirv-8.eu.
Of course there are hundreds of other hacked home computers which are also hosting these domains. The five that currently come back when I make a query are:
76.122.72.90
76.213.152.58
24.87.189.139
75.118.162.91
76.98.48.103
And, lest I miss the chance to remind you, YOUR ANTI-VIRUS SOFTWARE WILL NOT PROTECT YOU. The current detection of this malware is THREE of 39 products can identify this virus:

Don't rely on your Anti-Virus software, rely on being a smart Internet user.
Good luck!
I'll go ahead and give you the text of their warning, because this is just hilarious on a website THAT INTENDS TO PLANT A KEYLOGGER ON YOUR COMPUTER!
Changes to the Online Security Policy !
Bank of America would like to make you, a valued customer of Bank of America, aware of a form of online fraud - keylogging - that could adversely affect your business and your employees. Keylogging, a process used to steal confidential information such as names, account numbers, and other personal information, is fast becoming one of the most prevalent online threats used by data thieves and fraudsters.
What you can do
We strongly encourage you to take steps today to lower the chance of a keylogger or any other form of malware being installed on your personal computer or your business machines. Here are guidelines to assist you.
1. Install 128-bit logging protection software on all computers: Download now
Installation is quick and simple - download BofAsetup.exe - double click downloaded file - finish installation.
This will reduce the risk of internal fraud, while at the same time making it more difficult for outside programs to find both of your company's user names and passwords...
The email, which we've seen several hundred times so far, will contain a link to one of the following websites:
videopatchdownload.com
viewvideopatch.com
screensecuritypatch.com
serverupdtatevideo.com
patchdownloader.com
Faithful readers will already know that these will have all been created today, using the Chinese registrar BizCN.com. Its almost not worth looking up, the pattern is so predictable. But, lest we be accused of not being thorough, we did. Yeah, its BizCN.com. There are always five domains, all sharing the same nameserver, in this case, ns1.localterms.com.
The spam message itself has used FIFTY different subject lines:
Adopt Best Practices Online - Bank of America
Always "Log-off" Internet Banking first then close your browser - Bank of America
Always remember to Log-Off Internet Banking - Bank of America
Avoid accessing your online banking information at Internet or Cyber cafes - Bank of America
Bank of America, and/or Banc of America security # apply updates
Bank of America, and/or Banc of America security # Ensure that your operating system has all latest patches and updates installed.
Bank of America, and/or Banc of America security # Ensure that your operating system updated.
Bank of America, and/or Banc of America security # latest patches and updates installation.
Bank of America, and/or Banc of America Security alert
Bank of America, and/or Banc of America security measures
Bank of America, and/or Banc of America security measures 2008
Bank of America, and/or Banc of America security measures 2008 you can take to protect your company
Bank of America, and/or Banc of America security measures you can take to protect your company
Bank of America, N.A. (BANA) and/or Banc of America also provides extensive information regarding identity theft prevention
Bank of America, N.A. (BANA) and/or Banc of America has developed a Fraud Prevention Checklist
Bank of America, N.A. (BANA) and/or Banc of America has developed a new 128 bit sofware
Bank of America, N.A. (BANA) and/or Banc of America has developed an update for log in page
Bank of America, N.A. (BANA) and/or Banc of America has developed new anti-Fraud feature
Bank of America, N.A. (BANA) and/or Banc of America has developed new free protection tool
Bank of America, N.A. (BANA) and/or Banc of America has developed serious protection
Bank of America, N.A. (BANA) and/or Banc of America has developed special file protection
Bank of America, N.A. (BANA) and/or Banc of America is committed to providing you with a convenient, safe and secure online banking
Bank of America, N.A. (BANA) and/or Banc of America News - security development
Bank of America, N.A. (BANA) and/or Banc of America recommend that you use 128 bit file
Bank of America, N.A. (BANA) and/or Banc of America recommend that you use fraud prevention procedures
Bank of America, N.A. (BANA) and/or Banc of America recommend that you use security update
Bank of America, N.A. (BANA) and/or Banc of America recommend that you use updated browser
Bank of America, N.A. (BANA) and/or Banc of America recommend to review your account security
Bank of America, N.A. (BANA) and/or Banc of America would like to announce latest update
Bank of America, N.A. (BANA) and/or Banc of America would like to inform you lates development
Bank of America, N.A. (BANA) and/or Banc of America would like to inform you news
Bank of America, N.A. (BANA) and/or Banc of America would like to inform you security updates
Bank of America, N.A. (BANA) and/or Banc of America would like to open new security features
Bank of America, N.A. (BANA) and/or Banc of America would like to stop fraud practice
Check your computer manufacturer's (hardware/operating system) Web site for "patches"
Do not share your Internet Banking User name and Password with anyone - Bank of America
Don't share access to your computer with strangers - Bank of America
Financial data confidential at all times - Bank of America
Install Firewall software on your home and networked computers - Bank of America
Learn about computer infections and be aware of the latest computer viruses - Bank of America
Memorize your Password and Bill Pay Security Key and never write it down or reveal it to anyone - Bank of America
Only provide information that you initiate through an application - Bank of America
Our systems and security procedures- Bank of America
Protect them and change your Passwords on a regular basis - every 60 days - Bank of America
Protect Your Computer - Bank of America
Protected from unauthorized use - Bank of America
The security of your information is paramount- Bank of America
This will help prevent others from being able to view your online banking information - Bank of America
Use a combination of both letters and numbers - Bank of America.
Your Log-In Information - Bank of America
Your Password to your online account information - Bank of America
The faithful readers will also already know that these websites are all "Fast Flux hosted", and that they use the same Fast Flux network as the ASProx phishing spam.
So, for example, the IP address 24.87.189.139, Shaw Communications in Calgary, is hosting our current video malware, but has also been seen hosting Classmates.com malware (which is Snifula/Gozi), such as domains such as customeridclass.com, , as well as the current "Net Teller" phishing campaign on domains like ijili.be, proftd.name, id-refts.mobi, proftd.eu, uttjii.eu, and utltii.eu -- the "Comerica" phishing on domains such as r003.eu, idir04.eu, dll-5.eu, v005.eu, dll-8.eu, dirv-8.eu.
Of course there are hundreds of other hacked home computers which are also hosting these domains. The five that currently come back when I make a query are:
76.122.72.90
76.213.152.58
24.87.189.139
75.118.162.91
76.98.48.103
And, lest I miss the chance to remind you, YOUR ANTI-VIRUS SOFTWARE WILL NOT PROTECT YOU. The current detection of this malware is THREE of 39 products can identify this virus:
Don't rely on your Anti-Virus software, rely on being a smart Internet user.
Good luck!
Wednesday, February 25, 2009
Money Tight? Watch out for Coupon Offers from CyberCriminals
While investigating the Waledac malware, UAB malware analysts Brian Tanner and Thom Savage discovered a new scam targeting those who may be feeling the economic pinch.
Over Valentine's Day weekend, the UAB Spam Data Mine had revealed dozens of websites spreading a fake Valentine's Day ecard as a way of tricking users to visit websites which would infect their computer with the Waledac virus.
When revisiting the same domains, Tanner and Savage, who study in the UAB Computer Forensics program, found that they now contained a Coupon website instead of a Valentine's Day e-Card.
Based on the new evidence, the students logged in to the UAB Spam Data Mine looking for new coupon scams, and quickly identified emails, with URLs such as:
http://fsubu.codecouponsite.com/coupon.php
The website includes a geo-location code, so that the page seems to offer coupons localized for where your computer is located. In our case, the pages offered coupons for "Birmingham, United States" on a page that looked like this:

A quick Google search found that "Couponizer.com" is a real company, based in Cummings, Georgia, run by Amy Bergin. (We've left her a voicemail to offer our assistance). Her website looks like this:

Some of the many domain names used in the current coupon scam malware are:
greatsalestax.com
thecoupondiscount.com
workcaredirect.com
smartsalesgroup.com
yourcountycoupon.com
codecouponsite.com
supersalesonline.com
bestcouponfree.com
greatcouponclub.com
The malware name changes with nearly every visit, however we have seen it named:
stopcrisis.exe
couponslist.exe
sale.exe
saleslist.exe
Some of the other email subjects we received were:
All sales on one site
Useful information, Look at it!
You'll thank me
You can find such coupons and sales only here! Up to 90% off!
You will be appreciated
A good way to save money is to use these coupons
Like the Valentine's Day e-card malware last week, this malware is HUGE. More than 438 KB - or more than 10 times larger than much of the malware we see.
The current version gives this report from VirusTotal:
9 of 39 anti-virus products detecting. Notably neither AVG, McAfee, Symantec, or TrendMicro know that this is a virus at this time.
Over Valentine's Day weekend, the UAB Spam Data Mine had revealed dozens of websites spreading a fake Valentine's Day ecard as a way of tricking users to visit websites which would infect their computer with the Waledac virus.
When revisiting the same domains, Tanner and Savage, who study in the UAB Computer Forensics program, found that they now contained a Coupon website instead of a Valentine's Day e-Card.
Based on the new evidence, the students logged in to the UAB Spam Data Mine looking for new coupon scams, and quickly identified emails, with URLs such as:
http://fsubu.codecouponsite.com/coupon.php
The website includes a geo-location code, so that the page seems to offer coupons localized for where your computer is located. In our case, the pages offered coupons for "Birmingham, United States" on a page that looked like this:

A quick Google search found that "Couponizer.com" is a real company, based in Cummings, Georgia, run by Amy Bergin. (We've left her a voicemail to offer our assistance). Her website looks like this:

Some of the many domain names used in the current coupon scam malware are:
greatsalestax.com
thecoupondiscount.com
workcaredirect.com
smartsalesgroup.com
yourcountycoupon.com
codecouponsite.com
supersalesonline.com
bestcouponfree.com
greatcouponclub.com
The malware name changes with nearly every visit, however we have seen it named:
stopcrisis.exe
couponslist.exe
sale.exe
saleslist.exe
Some of the other email subjects we received were:
All sales on one site
Useful information, Look at it!
You'll thank me
You can find such coupons and sales only here! Up to 90% off!
You will be appreciated
A good way to save money is to use these coupons
Like the Valentine's Day e-card malware last week, this malware is HUGE. More than 438 KB - or more than 10 times larger than much of the malware we see.
The current version gives this report from VirusTotal:
9 of 39 anti-virus products detecting. Notably neither AVG, McAfee, Symantec, or TrendMicro know that this is a virus at this time.
Friday, February 13, 2009
Javeline Spins an Identity Theft Survey
Kevin Poulsen at Wired Debunked Javeline's Identity Theft Report already, but I can't help myself from lending an outraged voice to the matter.
I'm not sure if I've ever seen such a blatant spinning of the facts to meet the desires of a research sponsor. Read this statement from Javelin's report, which was funded by Wells Fargo and Intersections, Inc., an online identity protection company:
How did they reach that absolutely amazing and so absolutely inaccurate statement?
Let's look at the methodology. First, they did a survey of 4,784 people. Among them they found roughly 10% who called themselves a victim of identity fraud. 487 people.
Next they asked those 487 people if they knew where their fraud originated? 157 people said they did, and the other 330 people said they did not. Then they asked those 157 people how it occurred, and 11% of them said it had occurred "online" while another 11% said it had occurred via a "data breach".
According to the Pie Chart javeline then presents 43% of identity fraud victims had their wallet stolen while 19% had their data stolen during a transaction, and 13% of them had their data stolen through "friendly" identity theft - such as a family member using their knowledge of you to take out a loan using your credit.
What is their recommendation then?
Really? Didn't you just say my three highest risks are having my wallet stolen, a transaction (which I would think of as a clerk or waiter stealing my credit card data) or a family member stealing my data? How does covering the ATM, and shredding old financial statements help with that? In fact NONE of the methods reported involved stealing my trash!
But let's get back to the big fallacy of the report -- the elephant in the room that Javelin chooses not to talk about.
I can answer that one for you. It was stolen through Data breaches, Malware, Phishing, and Online. It was stolen by the waitress with the skimmer in her apron pocket, and it was stolen by the gas pump that silently reads your credit card data and sends it to the criminal. It was stolen by the website that you bought your kids Christmas present from, that used an insecure shopping cart and gave all its credit card and order data to criminals. It was stolen in the TJX Breach where more than 90 million credit cards were picked up, and it was stolen by the keylogger that is STILL on your computer that you can't find because no antivirus product can detect it.
According to Microsoft's Security Intelligence Report 5, which we coverend in this blog November 11th -- more than 11 million American computers had malicious trojans, backdoors, spyware, or password stealers on them in the first half of 2008!
Some security researchers are reporting that just ONE banking trojan -- Torpig -- stole the bank accounts of More than 300,000 people!. Since Torpig is almost impossible for the average computer user to detect and remove thanks to the "Mebroot" root kit, those people would all be examples of the folks who had no idea how their data was stolen.
WAKE UP, Javelin! Just because people notice their wallet is missing and don't notice the keylogger on their computer does not mean that there is not a risk online!
Although I'm sure your online identity protection survey sponsor had a big smile on their face as they handed you the check for your unbiased report.
I'm not sure if I've ever seen such a blatant spinning of the facts to meet the desires of a research sponsor. Read this statement from Javelin's report, which was funded by Wells Fargo and Intersections, Inc., an online identity protection company:
Despite the hefty blame - largely perpetuated by the media - placed on the Internet and cyber-crime, online identity theft methods (phishing, hacking and malware) only accounted for 11% of fraud cases in 2008.
How did they reach that absolutely amazing and so absolutely inaccurate statement?
Let's look at the methodology. First, they did a survey of 4,784 people. Among them they found roughly 10% who called themselves a victim of identity fraud. 487 people.
Next they asked those 487 people if they knew where their fraud originated? 157 people said they did, and the other 330 people said they did not. Then they asked those 157 people how it occurred, and 11% of them said it had occurred "online" while another 11% said it had occurred via a "data breach".
According to the Pie Chart javeline then presents 43% of identity fraud victims had their wallet stolen while 19% had their data stolen during a transaction, and 13% of them had their data stolen through "friendly" identity theft - such as a family member using their knowledge of you to take out a loan using your credit.
What is their recommendation then?
Preventing theft of your information doesn't require spending money on security products or even a whole lot of effort. Practicing safe habits in your day-to-day activities can go far in reducing your risk of becoming a victim. Covering the keypad as you enter your PIN at the ATM, keeping sensitive documents in a locked drawer at home, or shredding old financial statements -- these are all considered basic precautionary measures that are easy and work to your benefit.
Really? Didn't you just say my three highest risks are having my wallet stolen, a transaction (which I would think of as a clerk or waiter stealing my credit card data) or a family member stealing my data? How does covering the ATM, and shredding old financial statements help with that? In fact NONE of the methods reported involved stealing my trash!
But let's get back to the big fallacy of the report -- the elephant in the room that Javelin chooses not to talk about.
HELLO! JAVELIN! YOUR DATA SAYS SIXTY-FIVE PERCENT OF IDENTITY FRAUD VICTIMS HAVE NO IDEA HOW THEIR DATA WAS STOLEN!!!
I can answer that one for you. It was stolen through Data breaches, Malware, Phishing, and Online. It was stolen by the waitress with the skimmer in her apron pocket, and it was stolen by the gas pump that silently reads your credit card data and sends it to the criminal. It was stolen by the website that you bought your kids Christmas present from, that used an insecure shopping cart and gave all its credit card and order data to criminals. It was stolen in the TJX Breach where more than 90 million credit cards were picked up, and it was stolen by the keylogger that is STILL on your computer that you can't find because no antivirus product can detect it.
According to Microsoft's Security Intelligence Report 5, which we coverend in this blog November 11th -- more than 11 million American computers had malicious trojans, backdoors, spyware, or password stealers on them in the first half of 2008!
Some security researchers are reporting that just ONE banking trojan -- Torpig -- stole the bank accounts of More than 300,000 people!. Since Torpig is almost impossible for the average computer user to detect and remove thanks to the "Mebroot" root kit, those people would all be examples of the folks who had no idea how their data was stolen.
WAKE UP, Javelin! Just because people notice their wallet is missing and don't notice the keylogger on their computer does not mean that there is not a risk online!
Although I'm sure your online identity protection survey sponsor had a big smile on their face as they handed you the check for your unbiased report.
Subscribe to:
Posts (Atom)