Monday, June 01, 2009

Bank of America Digital Certificates - A New Generation of Phishing?

We've seen several attempts in the past for criminals to try to get your passwords by the social engineering trick of a "Digital Certificate". Beginning in today's spam we're seeing another round that seems more directed at existing users of the Bank of America Digital Certificate program. Previous Bank of America Digital Certificate scams were covered in this blog in our stories including: Banking Digital Certificate Malware in Spam, Bank of America Demo Account - DO NOT CLICK, and LaSalle acquisition by Bank of America spreads malware.



The current email warns that "The Digital Certificate for your Bank of America Direct online account has expired." and provides a link to a website to update the information. All of the links on the website shown below point to the real Bank of America Direct Digital Certificate program, except the "CONTINUE" button.



According to the WHOIS policy for .EU domains, I am not allowed to share with you in my blog the patently false registration information for the domain 1il1il1.eu.

You would have to WHOIS the information yourself from: www.eurid.eu, which is probably part of why criminals like .eu domains so much.

We actually received more than fifty copies of this new scam, with the earliest arriving May 29th at 9:30 AM. For most of them, several domains are used, and for some we have multiple copies, with fjtiili.com, hftiili.be, fgtsssa.com, and idfsre.com being the most popular among those we've seen in the spam:

lstrass.com
nfillil.net.sg
fjtiili.com
fgtsssa.co.uk
idfgtid.li
idfgtid.cz
idfsre.com
hftiili.be
fgtsssa.com

While this morning the emails began to say "The Digital Certificate for your Bank of America Direct online account has expired", versions before today read "We would like to inform you that we have released a new version of Bank of America Customer Form."

.be domains, like .eu domains, require you to visit the Registrar's website to reveal WHOIS details. According to www.dns.be, its not allowed for me to post information from their WHOIS database about hftiili.be here, so you would have to look that information up yourself:

Lookup WHOIS for hftiili.be.

I can make the observation that a friendlier WHOIS service for fjtiili.com, which follows the international standard of making WHOIS data publicly available, says that fjtiili.com was registered to bromleygilmoreur@yahoo.com which would be of interest to people who read the WHOIS information for hftiili.be, although I can't say why, lest the .be Domain Police come get me! The names do not match although the email addresses do.

Whether you place true information on the website or not, the website will attempt to infect your computer by downloading and attempting to run the file:

c:\Windows\9129837.exe

This malware, called by some AV products "spy-agent.bg".

The newest portion of the update, however, which varies from previous Digital Certificates that we've seen, is that the information is being verified before submission. The current login screen, shown here:



actually is using a complex login process, which includes verifying your credentials before accepting them, and encrypting the form content. The form is submitted using "x-www-form-encoded" as its methodology, and contacting Verisign via "pilotonsite.verisign.com/cgi-bin/crs.exe" as part of its authorization process. If Verisign doesn't agree that you are a valid Digital Certificate user, the phisher doesn't have to bother storing your credentials - but he'll still infect your computer with his keylogging software, just in case.

One of my students, a UAB Malware Analyst, is currently reviewing the malware. We'll have more information about it shortly and will update this post then.

Sunday, May 31, 2009

Phishers Try MSN Worms to steal credentials

At the University of Alabama at Birmingham our Computer Forensics students are working on a large number of spam and phishing related projects. One of those includes tracking the Fast Flux nodes related to various botnets. As I was meeting with one of the students this week to talk about a particular phishing botnet we noticed that the hosts were doing something that seemed to be related to MSN.



In this particular botnet, computers take turns hosting the phishing websites for various banks. For instance at the end of this week, the botnet was hosting phishing sites like these:

www.mybank.alliance-leicester24.com
www.mybank.alliance-leicester39.com
www.mybank.alliance-leicester93.com
www.mybank.alliance-leicester01.cn
www.mybank.alliance-leicester98.cn

or these:

mibusinessonlinebanking.mibank.com.dir-27612.ffifjl1.com
mibusinessonlinebanking.mibank.com.dir-4712.fjfl1j.net
mibusinessonlinebanking.mibank.com.dir-7158.f1ifjl1.net

or these:

www.bankofscotlandbusiness.co.uk.session64016.sterrss.com
www.bankofscotlandbusiness.co.uk.session6297.vdsl1.com

or these:

www.bankofamerica.com.srv_28742.idfsre.com
www.bankofamerica.com.srv_1470.nfillil.com.sg
www.bankofamerica.com.srv_31682.fgtsssa.com
www.bankofamerica.com.srv_77000.nfillil.net.sg
www.bankofamerica.com.srv_67075.fjtiili.com
www.bankofamerica.com.srv_7688390.hftiili.be
www.bankofamerica.com.srv_07430.fgtsssa.co.uk
www.bankofamerica.com.srv_26497.nfillil.org.sg
www.bankofamerica.com.srv_92855.idfgtid.cz

The phishers are still doing that, of course, but as we were exploring the IP addresses being used by the botnet for hosting these phishing sites (more than 250 of them since Thursday afternoon), we found some domains that didn't fit this pattern.

my-secret-gallery-download.com



First we checked out the WHOIS information . . .

Registered May 15, 2009 at XIN NET Technologies . . .

Using the nameserver NS1.MY-CHEERFUL-DNS.COM

And oh, look! Our old friend Pan Wei Wei!

Registrant:
Organization : Pan Wei wei
Name : Pan Wei wei
Address : BaoChun Rd. 27, No. 3, 1F, Apt. 1903
City : Bejing
Province/State : Beijing
Country : CN
Postal Code : 100176
Email: 127@126.com

Pan Wei Wei has been involved with this particular botnet since at least October, as others have noticed as well. For instance, see Dancho Danchev's blog entry from December. Dancho follows the popular trend of wrongly calling this the "Rock Phisher", but that's a common misperception, and he certainly ACTS like the Rock phisher. We prefer the term "Rock-Like", but that's not the point here. Dancho and many others have good evidence on this guy.

Pan Wei Wei used to prefer his gmail address - escap3@gmail.com or clu3less@gmail.com - but apparently he no longer uses those.

After Googling around a bit and checking the UAB Spam Data Mine, we find that this domain is not being used in spammed email, but is rather being used in an MSN message worm.

Messages are received such as:

damn, saw naked pics of yours or maybe the one in pic is similar to you .... crazy lol http://my-secret-gallery-download.com/pic_gallery.html

or

phewww +o( unbelivable, is that you??? who ever is it...is really similar to you lol ... http://my-secret-gallery-download.com/pic_gallery.html

The criminal needs to update his graphics on this one. What's supposed to happen here is that a graphic is displayed from one of several random ImageShack locations. Above the image are the words:

Click on the image to download the party pictures gallery...
(Click Open or Run when prompted.)

Clicking on the image will actually run this file:

http://my-secret-gallery-download.com/pic_gallery.php

Which causes you to download this file:

image_gallery.scr

File size: 31745 bytes
MD5 : fa0e304fa4c11a89a2345e009ecebf1c

The detection of this file as a virus is actually quite high. 34 out of 40 anti-virus tools now detect this malware, including Microsoft who labels the malware

Microsoft 1.4701 2009.06.01 VirTool:Win32/Obfuscator.FI

Virus Total Analysis here




picy-pictures.com



The next interesting looking website was picy-pictures.com

A WhoIs check confirms that this domain was also created by Pan Wei Wei, although this is more recent - with a created date of May 28, 2009. It also uses the nameserver NS1.MY-CHEERFUL-DNS.COM (and NS2, NS3, NS4).



This one is a much clearer phishing attempt. Here we are asked right at the beginning to provide our MSN userid and password in order to view the 35 pictures in our Private Gallery.

Userids and passwords are checked immediately. If you provide fake data, you get "invalid login! please try again..."

If you provide real data, someone will need to tell me what it does, because I don't have an MSN account that I would like to share with the criminals.

It was interesting to me that although they chose to host this site on a botnet, where each computer on the botnet is a potential host to help them anonymize the source, they chose to hard code an IP address of their stylesheets and javascript programs:

69.90.81.132

There are two domain names associated with that IP address:

hotmail-timeout.com

and

pictures-bucket.com

I wonder if those might be similar scams?

Given that they were also both registered by Pan Wei Wei using XIN NET TECHNOLOGY as the registrar, I feel that it might be a safe bet. Hotmail-Timeout.com was registered March 15, 2009. Pictures-bucket.com was registered April 24, 2009.

The last interesting domain we are seeing on this botnet is:

hotmail-live-inbox.com



Registered May 26, 2009 by Pan Wei Wei on XIN NET TECHNOLOGY using Name Servers NS1.MY-CHEERFUL-DNS.COM (and NS2, NS3, NS4)

We found a post about this one from Steve Swift at on a Vista Forum.

Steve had received a new email from Haris_Sheikh, which he knew because he had a link sent to him from an offline colleague:

You have received (1) new email from haris_sheikh.
http://www.hotmail-live-inbox.com/?user=haris_sheikh

Clicking on the link gave him a "System Notice" that read like this:

Your Live Account is about to get expired. For further details please visit,
http://www.hotmail-live-inbox.com/

If you've been a victim of any of these type of frauds, you may have bigger problems than you know. We've seen hotmail and live.com accounts used to try to scam the friends who send you email (see our blog article on Traveler Scams.)

For some of them, changing your live.com/hotmail password might help --

https://account.live.com/ChangePassword.aspx

For other support on your hotmail or live.com emails you can visit:

support.live.com

To report possible fraud on your live.com account, you can usethis live.com reporting form.

For others, you probably have malware running on your computer which is being used to send spam and steal your passwords!























http://my-secret-gallery-download.com/pic_gallery.html

Saturday, May 02, 2009

University Spammers, the Shah brothers, arrested

Congratulations to the Assistant US Attorney for Western Missouri, Matthew Wolesky, and the FBI investigators who have arrested and indicted the Shah brothers! The news was released in a Kansas City FBI Press Release on April 29th.

Amir Ahmad Shah, 28, and his brother, Osmaan Ahmad Shah along with their business, I2O, Inc, and their co-collaborators Liu Guang Ming of China, and Paul Zucker, 55, of New Jersey were named in the 51-count indictment.

Both Amir Shah and Osmaan Shah are listed on the Entrepreneur site, "The Rise To The Top", where they are listed as "Experts" on the site, which provides "Entrepreneurship Education for Young Entrepreneurs". (Any guesses on whether they will be there by Monday? haha! Just in case, I've taken screen shots for you here:



original URL: http://www.therisetothetop.com/guest-expert-profile.php?id=22



original URL: http://www.therisetothetop.com/guest-expert-profile.php?id=24

According to "CrunchBase", Osmaan Shah received his BS in Finance & Banking in 2006, and his MBA in 2009, both from the University of Missouri. His profile says:

Osmaan Shah is the co-founder and lead software developer of Noog. In his 7+ years of development experience, he exhibits a passion for dynamic front-end web design (javascript, AJAX/Comet). He specializes in the incubation of creative new products and online portals targeted towards students and young retail consumers. Mr. Shah is also the a Director and co-founder of VistaClick where he serves as the online marketing campaign manager.


Amir Shah's company is VistaClick.


(Original URL: http://www.vistaclick.com)

VistaClick's website describes an Affiliate Program where you could become one of their 17,000 "registered campus affiliates".

I wasn't able to pull the indictment from Pacer myself, as the "CM/ECF System for the Western District of Missouri is currently down for maintenance" (sigh), but someone else had already posted it online. (See indictment for case mowdce 4:2009cr00141, courtesy of Columbia Daily Tribune).

Here's what we can glean from the 59 page indictment:

First, the charges, which are all applied to the Shah brothers and to I2O, Inc. Liu Guang Ming and Paul Zucker are included in charges 1, 7-16, and 43-51.

Count One: 18 USC § 371 (Conspiracy), a Class D Felony, with possible sentence not more than 5 years with not more than $250,000 fine.

Counts Two through Six: 18 USC § 1030(a)(2) (Fraud in Connection with Computers), a Class C Felony, with possible sentence not more than 5 years with not more than $250,000 fine.

Count Seven: 18 USC § 1030(a)(5) (Fraud in Connection with Computers), a Class C Felony, with possible sentence not more than 10 years with not more than $250,000 fine.

Counts Eight through Sixteen: 18 USC § 1037(a)(1) (Fraud in Connection with Email), a Class E Felony, not more than 3 years, with not more than $250,000 fine.

Counts Seventeen through Forty-Two: 18 USC § 1037(a)(2) (Fraud in Connection with Email), not more than 3 years, with not more than $250,000 fine.

Counts Forty-Three through Fifty-One: 18 USC § 1037(a)(3) (Fraud in Connection with Email)

In the indictment, the defendants are said to have developed an email-harvesting program and used the program to harvest email addresses from the University of Missouri and over two thousand other United States universities and colleges. The defendants then used this database, which included more than 8 million email addresses, to send email messages advertising products that were specifically targeted to college students. The indictment covers thirty-one separate spam campaigns sent using this database.

The emails would claim to be sent from their local "campus representatives", and would often refer to the company as being "alumni-owned" in an attempt to make recipients believe their use of the advertised service would somehow benefit their alma mater or its graduates.

Many of the emails were sent from an "Offshore Bullet Proof Hosting" company located in China. Their emailing software falsified email header information and rotated the subject lines, reply-to addresses, message contents, and advertised URLs in an attempt to bypass spam filters. They also used false information when registering domain names.

After being investigated, and having search warrants served against their homes and business in an investigation into spam messages targeted at University of Missouri students, the spammers merely stopped sending email to any of the addresses harvested from the University of Missouri.

The defendants would register as many as sixty unique domain names for a single spam campaign, all pointing at identical content. They also started a social networking site called "noog.com" which also was advertised by spam. More than $4.1 million in product sales came from the defendants' spam campaigns. They attempted to conceal their earnings both through real estate purchases and sending large sums of money out of country.

In a useful part of the indictment that might be copied by others, definitions for the following terms are provided:
Addresses
Botnet
Domain
Domain name
Domain name service
Email harvesting
Email header
Instant messaging
Internet
Internet Protocol address (IP address)
Internet service provider (ISP)
Mail server
Name server
Proxy server
Realtime Blackhole List (RBL)
Server
Spam filter
Viruses
Website
Web Host

Here's how the roles of the defendants are described:

Amir Ahmad Shah - the co-owner and president of I2O, Inc. - the overall leader of the spam operations and the "idea guy".

Osmaan Ahmad Shah - the co-owner of I2O, Inc - the Chief Operating Officer and the "computer guy" in the partnership. He created the email extgractors, administered the websites, designed the websites, and dealt with other programming and implementation matters.

Liu Guang Ming - rented forty servers under his control in China to host websites, send spam, and search for proxies that could be used for sending spam.

Paul Fredric Zucker - a spammer who purchased proxies from the Shahs, and at other times sold proxies to the Shahs. He also leased space from Ming.

Several other unindicted and unnamed co-conspirators are mentioned, included a family member who ran "VistaClick Pakistan" for the Shahs.

Other companies in the conspiracy were DirectPO, VistaClick, Funding Junction, Veridio, OIBA, Textbook Registry, and Your City Development.

The Shahs began their operation "in or before 2001" by harvesting student email addresses. They began working with Ming in or before 2002, conducting conversations via AOL Instant Messenger. The ad they responded to read:


Servers are located in China and run by some of their largest ISPs. Our tech support team manages servers around the clock with constant contact from China to US. We have several sites sending millions of emails per day. Unlike other hosts, you will NOT need to switch domain names or experience periods of downtime. Our uptime guarantee is 90%. If you are serious about bulk mailing, you have come to the right place.


I was able to find a copy of a post by "AMIR SHAH" back on October 11, 2002, advertising "BULLET PROOF CHINA HOSTING" on this URL on sidetrak.com as an example.

In that ad, Amir offers to send messages for $30 per million emails sent. He used the AOL instant messager id "rulubos@aol.com".

Amir Shah also had a twitter account with that same identity, rulubos. He hasn't posted anything there since January 5th, 2009, when his last post was "looking at twitter and wondering if I should just incorporate this feature into Noog."

Amir follows Jianxiong Song. Hmmm...let's look at some more twitter links . . . Jianxiong is following WaqasShah, whose last twitter post is "WaqasShah is relieved" posted on APril 24th. WaqasShah follows noog_com, who was testing bloog mobile, according to their last twitter on April 17th. Noog has an interesting group of Venture Capitalists that he follows, but I won't list them here.

OK, back to the indictment.

In chat logs found on the computers, Zucker trains O. Shah in the art of spamming, and they communicate about how many proxies they would need to send 2 million emails, being disappointed with a rate of only 110,000 per hour. O. Shah later tells Zucker (July 14, 2003) that he can now send 1 million emails per hour with a 65% delivery rate (unblocked/unfiltered). Later, O. Shah tells his brother A. Shah that by plugging directly into the University of Missouri Columbia network "with a cable not using the wireless" he can send 2 million spam messages per hour from the school.

Search warrants were served against the Shah residence in Columbia, Missouri and their business address also in Columbia on February 23, 2005. They found more than 3 million student email addresses harvested from 2002, 5 million harvested from 2003, and 37.5 million AOL email addresses, 33.7 million MSN addresses, 10.8 Hotmail addresses, 5.2 million Yahoo addresses, and more than 4 million United Kingdom email addresses.

The indictment shows that the crew was identifying a ridiculous number of proxy servers which they could use to "bounce mail" from. For a price of $75 per week, Zucker was able to provide them "1500-2500 proxies twice a day". Originally, the transaction had gone the other way, with Shah providing a list of 45,000 proxies to Zucker earlier, receiving payment for his services via Paypal.

Zucker communicated with O. Shah about how to obtain and use the software program "Dark Mailer", and sent Shah a copy of the program on February 3, 2005. They also used the programs Supermailer and "Group Mail".

Bank records showed that the Shahs transferred more than $30,000 to Ming for hosting services.

Other chats showed the brothers discussing ways to make money. For example, they sent spam for a "teeth whitening" service, where they received a commission for successful sales. The brother said "if we need to mail a million or two to get 10,000 kids...then so be it...who cares."

Here's an example of their teeth-whitening emails, from April 1, 2004, which will illustrate how the SHAH brothers took advantage of students trust in their university relationships:

"Each year, several alumni-owned companies offer various specials to our students and faculty. This month, the university has been offered a special discount on custom fitted teeth whitening systems. Alumni-owned, Custom Bright, Inc., is offering its products to students and faculty at significant discounts all this month. We encourage you to visit their website and take advantage of this alumni offer."

This continued all the way through 2009, with messages like this one, sent March 1, 2009:

"As many of you may be aware, our campus has been offered a special discount on professional custom-fitted teeth whitening systems from a company run by our very own alumni. There will be several campus representatives (like myself) giving out more information over the next 2 weeks."

The brothers discussed having "a more forceful message" to encourage registration in a particular textbook system they were spamming:

"With higher tuition and course material costs, we are working to find new ways of saving students money. This semester, we have implemented a new textbook buyback program that will get students better payouts at the semester ending buyback and may also increase used textbook availability. You MUST complete your registration before the end of this week if you wish to be eligible for this semester's buyback."

Other campaigns that used similar spam sold Digital Cameras, iPods, NCAA Basketball merchandise, and Magazine subscriptions.

Some of the many domain names they used:

surveyproject.org
surveydirect.org
campuschange.org
whiteningtoday.com
whiteningnow.com
discoverwhitening.com
myschoolipods.com
studentipods.com
campusipods.com
semestersavings.com
semesterdiscounts.com
saveatcollege.com
collegedecember.com
estudentoffers.com
mycollegedeals.com
collegefuture.com
campusfuture.com
campusinput.com
whiteningservices.com
whiteningovernight.com
whiteninglabs.com
mycampusnanos.com
campusnanos.com
schoolipods.com

The full indictment gives date ranges for these and many other domain names.

Some of the purchases the Shah brothers made include:

a home in Columbia - $191,123.

a luxury lost in St. Louis - $251,861.

paying off a house in St. Louis - $33,698.

a downpayment on a Lexus sedan - $8,800.

The forfeiture of any assets, up to a total of $4,191,966.57 is also requested, which will come from several bank accounts, and the sale of properties at:

1301 Fieldcrest, Columbia, MO
1520 Washington Avenue, Unit #301, St. Louis, MO
a parking space (?)
5417 Idaho Avenue, St. Louis, MO

a 2002 Lexus (Missouri plate: CA9R6B)
a 2001 BMW (Missouri plate: 391ZEP)

Update



Apparently the Shah brothers indictment has shared with other spammers some good tips on this type of spam. Here's a message that one of my students at UAB received on April 30, 2009:

_____________________________________
From: Jenna T. [jenna@OverstockApple.com]
Sent: Thursday, April 30, 2009 2:20 AM
To: (name of my student)
Subject: Student/Faculty Discount

Dear Students/Faculty,

As you may have heard, several alumni-owned companies have teamed up to sponsor a campus-wide gift for our students and faculty. Working with Apple, they have acquired a small quantity of the new iPod Nano Chrome. This limited supply has now been made available to students and faculty at a significant discount. If you were at all interested in getting one of these iPods with this educational discount, please be sure to place your order online before this offer expires NEXT WEEK.

http://www.OverstockApple.com/h/3189094

Have a great summer!

Jenna T.
OverstockApple.com Student Representative



Have you seen a recent spam (after April 24th) from this group, pretending to be offering a discount for products from an "alumni-owned company"? If you can send it to me WITH HEADERS, I'd very much like to see it. Send it to: alumnispam@askgar.com

Wednesday, April 29, 2009

Waledac Moving on to . . . Canadian Pharmacy?

After monitoring the Waledac "infection domains" for more than a month, our last "interesting" event was the change in Look & Feel to the SMS Spy Program which we wrote about back on April 15th. In that blog article we mentioned that basically ALL of the domains used by Waledac, through the Valentine's Day campaign, the Couponizer campaign, the Terror Alert campaign, and the SMS Spy campaign, were all still alive!

Here's the newest change. ALL of the Waledac infection domains have now morphed into pill sites, and MANY of the older Waledac domains have finally been terminated.

Here's where stand with live FORMER Waledac domains. Many domains from the "Terror Alert" and "SMS Spy" alert are now forwarding on a random basis to domains which are either hosting Canadian Pharmacy or Canadian Health & Care Mall.

Of the Waledac domains that we were tracking, the following are now live forwarding domains:

antiterroralliance.com
blogginhell.com
blogsitedirect.com
boarddiary.com
discountfreesms.com
downloadfreesms.com
eccellentesms
fearalert.com
freecolorsms.com
freesmsorange.com
ipersmstext.com
nuovosmsclub.com
primosmsfree.com
smsclubnet.com
smsinlinea.com
smsluogo.com
superioresms.com
terroralertstatus.com
virtualesms.com


"Canadian Health & Care mall" at arzuhuxupi.com
"Canadian Health & Care Mall" at rahtydryo.com
"Canadian Health & Care mall" at vennocvajgo.com

"Canadian Pharmacy" at earpassionate.com
"Canadian Pharmacy" at transformationforgiving.com
"Canadian Pharmacy" at giftedaglow.com
"Canadian Pharmacy" at strivingalive.com


The following Waledac domains now appear to be terminated:

adorepoem.com
adoresong.com
adoresongs.com
againstfear.com
bestadore.com
bestbreakingfree.com
bestcouponfree.com
bestgoodnews.com
bestlovehelp.com
bestlovelong.com
bluevalentineonline.com
breakingfreemichigan.com
breakinggoodnews.com
breakingkingnews.com
breakingnewsfm.com
breakingnewsltd.com
chatloveonline.com
cherishletter.com
cherishpoems.com
codecouponsite.com
funloveonline.com
funnyvalentinessite.com
goodnewsdigital.com
goodnewsreview.com
greatcouponclub.com
greatsalesgroup.com
greatsalestax.com
greatsvalentine.com
greatvalentinepoems.com
linkworldnews.com
lovecentralonline.com
lovelifeportal.com
reportradio.com
romanticsloving.com
smartsalesgroup.com
spacemynews.com
supersalesonline.com
thecoupondiscount.com
thevalentinelovers.com
tntbreakingnews.com
wapcitynews.com
whocherish.com
wirelessvalentineday.com
worldlovelife.com
worldnewsdot.com
worshiplove.com
worldtracknews.com
youradore.com
yourbreakingnews.com
yourcountycoupon.com
yourgreatlove.com
yourvalentinepoems.com

Tuesday, April 21, 2009

President Obama's CTO: Aneesh Chopra

Photo From Virginia.gov
Like so many others who were playing the guessing game regarding President Obama's new CTO, I was wrong. I take comfort in failing along with BusinessWeek, ZDNet, Forbes, TheStreet, The Wall Street Journal and others to guess who would fill the office.

We might have taken a hint from one of President Obama's recent speeches to Congress, where he said:

"Our recovery plan will invest in electronic health records and new technology that will reduce errors, bring down costs, ensure privacy, and save lives."
-- (Transcript 24FEB09

Aneesh Chopra's bio on his Virginia website points out that he chairs the "Solutions Committee of the IT Investment Board, the Effectiveness and Efficiency Committee on the Council on Virginia's Future, and co-chairs the Healthcare IT Council". He was awarded the Healthcare Information and Management Systems Society's 2007 State Leadership Advocacy Award, and was named one of the top 25 by Government Technology magazine's Doers, Dreamers, and Drivers magazine.

In 2006, ExecutiveBiz.com interviewed Mr. Chopra on his new position as Secretary of Technology for the Commonwealth of Virginia. His answer to the question "What is your background?" lines up well with President Obama's vision for secure electronic healthcare records:

ExecutiveBiz: What is your background?

Aneesh Chopra: Professionally, I am a managing director at a think tank with a focus for the health care industry, but a big portion of my professional background has been studying ways that technology can fundamentally transform the healthcare industry in particular. Also, I internally helped launched the Advisory Board's first software-based membership business. So not only have I been researching technology and how I can benefit the healthcare industry, I have been business development wise active in the use of technology to grow our own business.


It was clear from his work in the job though that Health Care was not his only focus. Here were some answers regarding educational technology, another area on which the Secretary turned his attention while in office in Virginia, from one of the 46 Podcasts his office put out during his time there: (03/25/09 - Secretary Chopra discusses technology in the classroom --


We have an innovation imperative in the Commonwealth, and frankly for the country, and it requires us to think anew about how we produce students who are globally competitive. There are three basic questions we have to ask:
What are we actually teaching our kids?
How are we teaching our kids?
What are the tools with which we can allow the sharing ideas and the process of learning how to teach our kids?
In each of these areas there is a place for technology to play a role, in some cases a direct role, and in other cases more of an indirect role.


In his 2007 Accomplishments podcast (January 9, 2008) he stressed three Public/Private Partnerships, including:

a Google partnership to produce Google SiteMaps of 55 government websites, mapping more than 200,000 state webpages to increase their ability

Microsoft Virtual Earth helped create Campus Safety maps to help identify resources and plans for various emergencies on campus as a reaction to school shootings.

Cox and Comcast Cable began offering "GED On Demand" for free to more than 1 million broadband subscribers in Virginia.

1 of 3 new jobs created in Virginia came from high-tech jobs, and 30% of all wage-earners in Virginia received their pay from a technology related job.

5 innovators in HealthCare IT, 3 of which provided an 8-fold return on the investment. The Virginia HealthCare Exchange Network was created as part of the initiative.

Many other initiatives were described, making this podcast well worth listening to in order to learn more about how our nation's new CTO thinks about Technology. Many of these initiatives were grant-generated, by placing challenges into the community and asking for innovators who have solutions to step forward to address government productivity, broadband, and government IT.

To summarize what I see about Aneesh Chopra - he's proven that he knows how to solicit ideas from innovators, shape them into actual solutions, and roll them out as successful products. He did it in the business world, he did it in his HealthCare IT think tank, and he did it for the State of Virginia. I look forward to seeing what he can do for our nation.

I'm especially interested to see what types of reforms a technology thinker can bring to our Criminal Justice systems! At UAB Computer Forensics our partnership between Computer Science and Justice Science is based on the concept that when Computer Scientists are presented with Criminal Justice problems, good technology things can happen. Hopefully this will be one of our new CTO's priority areas as well.

Wednesday, April 15, 2009

Waledac shifts to SMS Spy program

We've known that Waledac spreads itself via Social Engineering - convincing users that they WANT to download a program. Recently we've seen Waledac acting as a Valentine's Day E-Card, a Couponizer program, and a Fake News Story about a Dirty Bomb.

Today the UAB Spam Data Mine began to get spam messages for a new Social Engineering trick. Here are some of the email subjects we're seeing:

Subjects
-----------
Read his SMS
The world's most advanced sms reading program
Now, It's possible to read other people's SMS
Read other people's SMS online
You can read anyone's SMS

The email bodies point to the websites with lines like these:

Do you trust her? http://smsclubnet.com/
You can read anyone's SMS http://virtualesms.com
Do you really trust her? http://www.freecolorsms.com
Do you really trust him? http://downloadfreesms.com/
Are you ready to know the truth? http://smsclubnet.com
Are you sure you want to know? http://smsclubnet.com

The webpage you visit looks like this:



The malware which you can download from the page is recognized by 13 of the 39 Anti-Virus products tested according to this VirusTotal Report.


File size: 419840 bytes
MD5...: 8623f18666be9d480710b29eab3b796a

The root problem with Waledac's long-lived domains is they are using a Chinese domain name registrar who won't cooperate with anyone on shutdowns. We have sent shutdown requests to their abuse contact, in both English and Chinese, and have received no cooperation whatsoever. If you have good contact information for "Ename.com", we really could use an introduction, thank you! No one answers their "1000@ename.com" email address, but perhaps a Chinese speaker might call them at +86.5922669769 ? ? ?

The complete list of NEW domain names created for this round of Waledac are:

smspianeta.com
miosmsclub.com
downloadfreesms.com
virtualesms.com
chinamobilesms.com
freeservesms.com
freecolorsms.com
smsclubnet.com

But a great number of the previous domains are also still live, and still serving Waledac, including:

adoresongs.com
antiterroris.com
bestadore.com
bestcouponfree.com
bestjournalguide.com
bestlifeblog.com
bestlovehelp.com
bestlovelong.com
bestusablog.com
bluevalentineonline.com
breakingnewsltd.com
chatloveonline.com
cherishletter.com
codecouponsite.com
easyworldnews.com
funloveonline.com
funnyvalentinessite.com
goodnewsdigital.com
goodnewsreview.com
greatcouponclub.com
greatsalesgroup.com
greatsvalentine.com
lovecentralonline.com
lovelifeportal.com
mobilephotoblog.com
photoblogsite.com
romanticsloving.com
spacemynews.com
thecoupondiscount.com
thevalentinelovers.com
tntbreakingnews.com
urbanfear.com
usabreakingnews.com
wirelessvalentineday.com
worldlovelife.com
worshiplove.com
youradore.com
yourgreatlove.com
yourvalentineday.com
yourvalnetinepoems.com

If you have contact at Ename.com, these ALL need killed, thank you! They are all now distributing the new "SMS Spy" version of Waledac.

Monday, April 13, 2009

New Drug sites avoid Visa and MasterCard, Sell Hydrocodone

Those who research Pharmaceutical spam have learned that there are basically two major classes of drugs. Those which the Feds care about stopping (Controlled substances monitored by the DEA) and those the Feds are happy to ignore, and which they call dismissingly "Lifestyle Drugs".

Its quite frustrating in light of the fact that, as Microsoft pointed out recently in their semi-annual report on Internet safety, 97% of the email on the Internet is spam, and HALF of that email is pharmaceutical spam. For someone to decide that its not worth investigating lifestyle drugs (by which they mean Viagra, Cialis, and other sexual-experience related drugs) as vigorously as we investigate "Controlled Substances" has lead to our current status on the Internet as a world flooded with absolutely uncontrolled drug spam.

Nevertheless, knowing that there is a two-tiered system of investigation related to pharmaceutical spam, we've all learned that the way to get action is to point out sites that are selling things that are on the Class I, Class II, Class III, or Class IV Controlled Substance List.

Side Note - if you are looking for a Computer Forensics Research program interested in making an impact on pharmaceutical spam, that has as partners in its "Computer Science/Justice Science Working Group" forensic criminologists with their own Gas Chromotography Mass Spectrometer (GS/MS), and faculty and grad students trained in its use, please look no further than the University of Alabama at Birmingham.

That's one of the two reasons why this new spam cluster is especially interesting to me. We have more than 1450 spam emails in the UAB Spam Data Mine during March and another 1,069 so far during April that contain the word "Hydrocodone" in either the body or the subject. The subject line in today's case actually says "Hydrocodone For You", and pointed to a pharmacy site here:

http://show-advanced-individual.com/



which leads with Hydrocodone, Vicodin, Phentermine, Ambien, Valium, and Levitra. They have quite a few alternate payment methods, but most notably they do NOT accept Visa or Mastercard:






By accepting electronic checks, direct bank transfers, and Western Union payments, these dealers in fake drugs can move their money even faster than they move their drugs. The world of money laundering possibilities opens wide once you get Visa and MasterCard off the option list. That should also make it pretty clear to the potential buyers. This vendor wants to move your money Quickly, Untraceably, and most importantly Irreversibly. They want to make sure they get your money NOW, even though you may (or may not) get your drugs later, and that even if you do NOT got your drugs, there is no way your going to get your money back, or even figure out where your money went.


This particular domain was registered on March 20th via XIN NET Technology.

The IP is at 116.125.56.218 - Hanaro telecom, Korea

This is not a new IP address to us at the UAB Spam Data Mine.

March 23 - 116.125.56.218 (1 spammed domain)
March 24 - 116.125.56.218 (13 spammed domains)
March 25 - 116.125.56.218 (16 spammed domains)
March 26 - 116.125.56.218 (50 spammed domains)
March 27 - 116.125.56.218 (42 spammed domains)
March 28 - 116.125.56.218 (42 spammed domains)
March 29 - 116.125.56.218 (42 spammed domains)
March 30 - 116.125.56.218 (64 spammed domains)
March 31 - 116.125.56.218 (75 spammed domains)

(I'll update those stats with April data once its been caught up...)

The Hotmail address in the whois data is = na506@hotmail.com

Two hundred other hyphenated domain names are on the same Hanaro IP address, according to DomainTools:

Approach-amazing-day.com
Approach-amazing-year.com
Approach-coming-human.com
Approach-delightful-2009.com
Approach-delightful-memory.com
Approach-delightful-species.com
Approach-emotive-creature.com
Approach-emotive-kind.com
Approach-fresh-month.com
Approach-hopeful-second.com
Approach-hot-blooded-2009.com
Approach-hot-blooded-year.com
Approach-new-2009.com
Approach-nice-2009.com
Approach-pretty-hour.com
Approach-touched-second.com
Approachamazinghour.com
Approachdelightfulhour.com
Approachhopeful2009.com
Approachmysteriousspecies.com
Approachprettyyear.com
Approachsucessfulcreature.com
Cherish-coming-creature.com
Cherish-eminent-species.com
Cherish-emotive-species.com
Cherish-fresh-day.com
Cherish-hot-blooded-minute.com
Cherish-hot-blooded-year.com
Cherish-mysterious-month.com
Cherish-nice-creature.com
Cherish-pretty-second.com
Cherish-sucessful-kind.com
Cherishamazingminute.com
Cherishcomingmemory.com
Cherisheminenthuman.com
Cherishemotive2009.com
Cherishemotivebeing.com
Cherishfreshbeing.com
Cherishhopefulhuman.com
Cherishmysteriouskind.com
Cherishprettysecond.com
Cherishsurprisingkind.com
Enjoy-beautiful-second.com
Enjoy-coming-month.com
Enjoy-delightful-species.com
Enjoy-eminent-human.com
Enjoy-exciting-month.com
Enjoy-hot-blooded-human.com
Enjoy-pretty-memory.com
Enjoyaffectingsecond.com
Enjoybeautifulsecond.com
Enjoydelightfulsecond.com
Enjoyfreshyear.com
Enjoyhot-bloodedmonth.com
Enjoyniceyear.com
Enjoysucessful2009.com
Feel-sucessful-day.com
Feel-sucessful-hour.com
Feel-surprising-second.com
Feelhopefulmemory.com
Feelhopefulminute.com
Feelsucessfulsecond.com
Feelsurprisingmemory.com
Greet-amazing-human.com
Greet-amazing-kind.com
Greet-delightful-species.com
Greet-delightful-year.com
Greet-fresh-creature.com
Greet-nice-creature.com
Greet-nice-memory.com
Greet-sucessful-being.com
Greetamazingmemory.com
Greeteminentsecond.com
Greethot-bloodedcreature.com
Greethot-bloodedkind.com
Greethot-bloodedmemory.com
Greetnewspecies.com
Guide-developping-block.com
Guide-developping-corporation.com
Guide-developping-urban-area.com
Guide-incorruptible-institution.com
Guide-upright-individual.com
Guide-well-behaved-street.com
Guidedeveloppingblock.com
Guidedeveloppingcompany.com
Guidedeveloppinglane.com
Guideincorruptiblesquare.com
Guideopenstreet.com
Guidereliableinstitution.com
Guidewell-behavedcountry.com
Guidewell-behavedurban-area.com
Meet-amazing-minute.com
Meet-exciting-kind.com
Meet-fresh-being.com
Meet-hot-blooded-minute.com
Meet-pretty-being.com
Meetamazingmonth.com
Meetamazingsecond.com
Meetcomingbeing.com
Meetcomingcreature.com
Meetdelightfulhour.com
Meetemotivecreature.com
Meetexciting2009.com
Meethot-bloodedbeing.com
Meetsucessfulcreature.com
Meetsucessfulday.com
Meetsurprisingcreature.com
Meetsurprisingsecond.com
Reveal-advanced-corporation.com
Reveal-advanced-lane.com
Reveal-advanced-street.com
Reveal-civilized-country.com
Reveal-civilized-urban-area.com
Reveal-clean-institution.com
Reveal-developping-lane.com
Reveal-educational-unit.com
Reveal-frugal-alley.com
Reveal-neat-entreprise.com
Reveal-neat-institution.com
Reveal-peaceful-country.com
Reveal-spiritual-lane.com
Reveal-spiritual-street.com
Reveal-upright-organization.com
Reveal-upright-street.com
Reveal-well-behaved-corporation.com
Reveal-well-behaved-urban-area.com
Revealadvancedcompany.com
Revealadvancedindividual.com
Revealadvancedunit.com
Revealcivilizedentreprise.com
Revealcivilizedindividual.com
Revealculturalcity.com
Revealculturalstreet.com
Revealculturalunit.com
Revealdeveloppingcity.com
Revealincorruptibleindividual.com
Revealpeacefulunit.com
Revealreliableinstitution.com
Revealspiritualblock.com
Revealspiritualdistrict.com
Revealspiritualentreprise.com
Revealspiritualurban-area.com
Share-affecting-year.com
Share-amazing-species.com
Share-amazing-year.com
Share-beautiful-species.com
Share-beautiful-year.com
Share-coming-year.com
Share-delightful-kind.com
Share-eminent-being.com
Share-eminent-hour.com
Share-emotive-being.com
Share-emotive-minute.com
Share-fresh-2009.com
Share-pretty-creature.com
Share-sucessful-human.com
Share-surprising-2009.com
Share-surprising-year.com
Share-touched-year.com
Shareaffectingcreature.com
Shareaffectingmemory.com
Sharehopefulmonth.com
Sharemysterious2009.com
Shareprettycreature.com
Sharesucessfulday.com
Sharesurprisingminute.com
Show-advanced-individual.com
Show-civilized-entreprise.com
Show-civilized-organization.com
Show-civilized-square.com
Show-clean-block.com
Show-educational-citizen.com
Show-educational-corporation.com
Show-harmonious-mechanism.com
Show-harmonious-organization.com
Show-neat-urban-area.com
Show-spiritual-block.com
Show-tidy-lane.com
Show-upright-urban-area.com
Showadvancedurban-area.com
Showcleanentreprise.com
Showincorruptiblecountry.com
Showpeacefulorganization.com
Showtidyorganization.com
Showwell-behavedsquare.com
Treat-affecting-being.com
Treat-amazing-2009.com
Treat-beautiful-creature.com
Treat-exciting-year.com
Treat-fresh-memory.com
Treat-hot-blooded-second.com
Treat-mysterious-minute.com
Treat-surprising-memory.com
Treat-touched-kind.com
Treat-touched-month.com
Treathopefulday.com
Treathot-bloodedhour.com
Treatsucessful2009.com
Uideharmoniousalley.com
Welove-supersale.com

Over the weekend, a new Hydrocodone cluster emerged, distinct from the one above.

The new cluster used the following domain names in more than 1500 emails just over the last weekend:

aoisiis.com
aposoos.com
apsppew.com
blotbump.com
blotcare.com
blotcool.com
bumpflow.com
bumpfold.com
candark.com
canword.com
celitrre.com
dealrise.com
debaiteo.com
domefast.com
domerests.com
dometake.com
esperros.com
fecioos.com
felippie.com
fullmage.com
fullmeed.com
fullmend.com
fullruse.com
kaiffelt.com
lungsse.com
macrsoku.com
maghiarr.com
mailldeo.com
maingive.com
maltfame.com
maltfire.com
maltflip.com
maltlike.com
maltmain.com
maltmalts.com
maltplay.com
malttall.com
malttilts.com
marnarq.com
masciake.com
naryneat.com
nowdark.com
nowwall.com
pionname.com
pionnary.com
pionpick.com
pionrise.com
pollsies.com
ppoleiw.com
qalsibbe.com
qaselict.com
realpin.com
riennsi.com
ropeww.com
rpeusw.com
spoeii.com
tehsui.com
wallmay.com
wallrise.com
wallsdeals.com
wesleos.com
wposlles.com
yehsuue.com

The new cluster looks like another Viagra site at first:



but scrolling down, we see it really is selling Hydrocodone and other Class II and Class III Controlled Substances:



As with the first cluster we mention, Visa and MasterCard are conspicuously missing from this site. It now accepts ONLY American Express:



Fortunately, they are concerned about the High Incidence of Fraud. 8-) Haha!

Thursday, April 09, 2009

Is There a Conficker E? Waledac makes a move...

At UAB Computer Forensics, we have been tracking the spam bot, Waledac, since March 19th, by checking every so often (like 4 times a minute) all of the domain names that we now are being used to distribute Waledac. We've been making a list of the infected nodes, with the timestamp that we see them distributing Waledac, and offering that list to various network providers. (If you are a network provider/ISP, send me an email to get a pointer to the list, there are around 4,000 US-based IPs on it so far.)

This morning, Packet Ninja Dan Clemens gave me a call asking if I had seen Trend Micro's claim that Conficker was updating. I hadn't seen that, but I had seen emails on one of my secret squirrel mailing lists that Conficker was updating from "goodnewsdigital.com". That didn't make any sense at all to me! We've seen 2,821 IP addresses serving up "plain ole' Waledac" from GND, so far. (See https://info.cis.uab.edu/forensics/blog/gnd.list.txt)

Just to make sure, I went ahead and fetched the current Waledac binary from one of the GoodNewsDigital.com websites, and sure enough, it was Plain Ole Waledac.

MD5: 20ac8daf84c022ef10bc042128ccace6

Currently detected by only 9 of 40 products at VirusTotal

Here's the VirusTotal Link, but the details are here:

AntiVir - TR/Crypt.ZPACK.Gen
CAT-QuickHeal - DNAScan
F-Secure - Packed:W32/Waledac.gen!I
Fortinet - W32/PackWaledac.C
McAfee-GW-Edition - Trojan.Crypt.ZPACK.Gen
Microsoft - Trojan:Win32/Waledac.gen!A
NOD32 - Variant of Win32/Kryptic.LP
Panda - Suspicious file
Sophos - Mal/WaledPak-A

A sad statement of the current state of anti-virus, that a KNOWN MALWARE DISTRIBUTION POINT that has been serving up viruses since mid-March for a large spam botnet is still entirely undetected by 3/4ths of the AV products!

But it gets worse.

I went and read Trend Micro's assertions on their blog . . .

According to Trend Micro they saw new malware arrive on one of their conficker boxes, being dropped not via a website update, as we've all been expecting, but via a Peer 2 Peer connection from other Conficker machines. The new malware arrived via P2P on their box and began attempting to propagate in worm-like fashion looking for MS08-067 vulnerabilities (the same as previous versions of Conficker), as well as opening a webserver on port 5114, and making connections to Myspace, MSN, eBay, CNN, and AOL. After this, the machine downloaded a file from GoodNewsDigital.com, which is, as I mentioned above, a Waledac distribution point.

The file that it downloads though IS NOT THE PRIMARY WALEDAC MALWARE. We retrieved the same file in our labs at UAB (forgive me, but the file is named "fuck4.exe"), and scanned it with VirusTotal as well. This is NOT the file you receive if you visit the Waledac host, as we decribed above, via a normal spam-referred website visit.

Here's what we got from "fuck4.exe" at VirusTotal:

ZERO products detect this as malware. NONE of the 40 sites thought the 418kb executable file was a virus.

VirusTotal Report

Trend is calling the new variant WORM_DOWNAD.E (DownAdUp is an alias for Conficker).

The Trend article certainly has caused some deep thinking here this morning! Thanks to Ivan Macalintal at Trend, and because he thanks Joseph Cepe and Paul Ferguson, we thank them as well!

Wait, why are we thanking Paul Ferguson? I had to go find out. Its because of his excellent documentation on the Peer2Peer nature of Conficker in the Trend Blog on April 4th. While the entire world began watching on April 1st for Conficker to be updated via new malware that was placed on one of the 50,500 domain names that began to be searched on April 1, the bad guys have snuck in the back door and updated Conficker via P2P instead.

Paul got a head start on his Peer to Peer research from the excellent malware researchers at CERT-LEXI in their Blog at CERT-LEXSI.


We'll be contacting more Conficker researchers as the day goes on and trying to determine if ALL the Conficker nodes have just merged with Waledac, or if something else is occurring here.

Wednesday, April 08, 2009

Microsoft Security Intelligence Report 2H08

The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microsoft.com/sir/ is timestamped the evening of April 6th). We reported on the last SIR report back on November 11, 2008 - please see Microsoft Reveals Malware and Spam Trends for our coverage of that report.

Number of Security Vulnerabilities



52% of the Security Vulnerability announced throughout the industry, via the Common Vulnerability Scoring System were of "High" criticality, while 56% of them were "Easy to exploit". 90% of the industry vulnerability announcements related to applications or browsers. Only 10% dealt with Operating Systems.

Microsoft released 42 Security patches during the 2H08 period.

Spam



More than 97% of the email sent across the Internet during 2H08 was unwanted! They have malicious attachments, they are phishing emails, or they are just plain spam. As all of us already suspected 48.6% of all the spam observed during 2H08 was for pharmaceutical products. Another 23% were for non-pharmacy product advertisements.



Notice that the Stock Pump & Dump spam almost disappeared. What would they sell if we could do the same thing to pharmacy spam?

The report also calls attention to the demise of McColo as being the big enforcement action of the year. This section of their report is called "Spam Volume Drops 46 Percent When Hosting Provider Goes Offline". The spam level at the end of December was still lower than the pre-McColo action on November 11th.

Browser Drive-By-Infections


About 1 in 1500 websites (more than 1 million) indexed by Live Search (Microsoft's answer to the Google search engine, available at live.com) contained a drive-by-download page. More than 1% of websites with a ".cn" country code hosted drive-by-download exploits. When they looked at the products that were being exploited in these driver exploits, #1 and #2 were Adobe Flash and RealPlayer.



(from p.48 of the Microsoft SIR report for 2H08)

On Windows XP machines, browser exploits targeted a Microsoft product 40.9% of the time. On Windows Vista machines, successful browser exploits targeted a Microsoft product only 5.5% of the time. This is one of many places throughout the document that Microsoft reminds us that Vista is a more secure operating system than XP.

In the first half of 2008, most compromised browsers were running Chinese language set (zh-CN = 25.6%). In the second half of 2008, American English language browsers easily passed them (en-US = 32.4%).

Social Engineering



The SIR report makes a point that the criminals today are having great success with social engineering targeting Fear, Trust, and Desire. Rogue Security Software did so well, because people are afraid of viruses.

Of the Social Engineering attacks that were based on an infected Microsoft Office File program, 91.3% of the attacks used the more than two year old exploit, CVE-2006-2492 MS06-027 to infect users via a Microsoft Word document. Curiously only 32.5% of these infected Word documents targeted en-US machines. 15.7% targeted Taiwanese machines, 12% Russian, 11.1% other Chinese machines, and 2.6% Iraqi machines.

Two Adobe PDF reader exploits also became popular in 2H08, spreading strongly and increasingly from October until the end of the year. 57% of the Adobe attacks targeted en-US machines. China didn't make the top ten on that list.

One important note regarding corrupt Office documents. Microsoft's SIR report recommends that users *NOT* run "Windows Update", but rather run "Microsoft Update". Applying Windows Update will never prompt you to install Microsoft Office patches, which may be why so many machines are still vulnerable to two year old malware. The report recommends that users read this entry:

How Is Windows Update Different Than Microsoft Update?, and make the appropriate changes on their machines.

Security Breaches



The report also makes clear that the trend has continued - most security breaches are accomplished not through "hacking" (though more than 15% are), but through stolen or lost equipment, usually laptops.

Geographic Trends



In 2H08, 13.2Million US computers were cleaned by Microsoft's anti-malware desktop products.


(source: SIR report p. 69)

For more details, please see the full SIR report.

Monday, March 30, 2009

GhostNet or Gh0st RAT: The Cyber Persecution of Tibet

For many members of the non-security research community, the New York Times story this week was big news: "Vast Spy System Loots Computers in 103 Countries". This morning's Google News has more than 750 related articles, and I applaud the work of the University of Toronto's Citizen Lab at the Monk Centre for International Studies at Trinity College for the excellent research and for sharing this story with the general public.



What does it look like to a Security Researcher though? Unfortunately, its a very common story of a very simple case of Spear Phishing that can be accomplished with minimal effort and *IS* being accomplished on a daily basis against various special interests, including government agencies, military contractors, or just people who might have a lot of money to steal. As I've discussed in my presentations on Spear Phishing, including at the 2008 Department of Defense Cyber Crime conference, high-value targets deserve special targeting. But let's look at how special the targeting was in this situation.

The news that someone was creating specifically targeted spear phishing campaigns against Tibet and Tibetan sympathizers first came to my attention in March 24, 2008, when our friends at the SANS' Internet Storm Center released the article, Overview of cyber attacks against Tibetan communities by Maarten Van Horenbeek. This was an in-depth follow-up to Maarten's initial report on March 21, 2008, Cyber attacks against Tibetan communities.

In the original article, Maarten describes the case this way:


The attacks generally start with a very trustworthy looking e-mail, being spoofed as originating from a known contact, to someone within a community. Some impressive social engineering tricks are used:
  • Messages make a strong statement on a well known individual or group, but do not mention its name. The attachment is then named after that individual. A state of 'cognitive dissonance' is invoked between the reader's pre-existent beliefs and the statement. There's a natural urge to click on the attachment to confirm that belief;
  • The writing style of the purported sender is usually well researched to have the message look as believable as possible;
  • The content of the document actually matches closely what was discussed in the e-mail message;
  • Having legitimate, trusted, users actually forward along a message back into the community.


The messages contain an attachment which exploits a client side vulnerability. Generally these are:
  • CHM Help files with embedded objects;
  • Acrobat Reader PDF exploits;
  • Microsoft Office exploits;
  • LHA files exploiting vulnerabilities in WinRAR;
  • Exploitation of an ActiveX component through an attached HTML file.


At that time he showed how PowerPoint files with names such as "reports_of_violence_in_tibet.ppt" and or "China's Tibet.pdf" contained exploits and were delivered in emails designed to elicit a trust-response from the reader if they were sympathetic to the cause. Here's one email that Maarten shared:


All,

Attached here is the update Human Rights Report on Tibet issued by
Department of State of U.S.A on March 11, 2008.

You may also visit the site:

Tashi Deleg,

Sonam Dagpo

Secretary of International Relations
Department of Information & International Relations
Central Tibetan Administration
Dharamshala -176215
H.P., INDIA
Ph.: [obfuscated]
Fax: [obfuscated]
E-mail: [obfuscated]@gov.tibet.net or diir-pa@gov.tibet.net
Website: http://www.tibet.net/en/diir/


Maarten confirmed that the contact information was correct for a member of the Tibetan Government in exile in Dharamshala, India.

In the case of the Citizen Labs report, the name of the report was the first thing worth mentioning. The report was called "Tracking GhostNet: Investigating a Cyber Espionage Network". Why was it called GhostNet? Because the enabling technology in their investigation was a common Remote Administration Trojan called "Gh0st RAT" (that's Gh0st with a Zero).

It took about 30 seconds to find a copy of Gh0st RAT 3.6 in the Chinese underground community, complete with source code. The program is written in VC++ version 6.0. The source code makes clear that, as is the case with many Chinese distributed malware products, the current distributor is a Chinese speaker speaking to a Chinese audience, although the comments make it quite possible the code was originally authored and designed for English speakers. Here's an example Code Snippet:


/////////////////////////////////////////////////////////////////////////////
// CGh0stApp construction

CGh0stApp::CGh0stApp()
{
// TODO: add construction code here,
// Place all significant initialization in InitInstance

// 初始化本进程的图像列表, 为加载系统图标列表做准备
typedef BOOL (WINAPI * pfn_FileIconInit) (BOOL fFullInit);
pfn_FileIconInit FileIconInit = (pfn_FileIconInit) GetProcAddress(LoadLibrary("shell32.dll"), (LPCSTR)660);
FileIconInit(TRUE);

HANDLE hFile = CreateFile("QQwry.dat", 0, 0, NULL, OPEN_EXISTING, 0, NULL);
if (hFile != INVALID_HANDLE_VALUE)


(According to Google Translate, the Chinese here says roughly: 为加载系统图标列表做准备 = Initialize the image list of this process, and 为加载系统图标列表做准备 = Icon to load the system ready to do list

While many of the notes in the source code have been rendered in Chinese, it still reads as those these are after-thought comments, and not the original author's words.

Still, Gh0st RAT China has been in development as a Chinese tool for some time - the version that was popular in China in early 2008 was Beta 2.5. and seems to have been primarily distributed by members of the "C.Rufus Security Team" or "CRST" through their website wolfexp.net (which is suddently not online???). While wildenwolf's website seems offline, another CRST member, amxku, still has a great deal of notes available on his blog at amxku.net.

One of the main researchers in the Sec Dev project, Gregory Walton, previewed some of this report at a presentation he did in Dharamshala, India back in 26 August 2008 called "Year of the Gh0st Rat".

The Citizen Lab report investigates a large botnet which was enabled by the Gh0st Remote Administration Trojan. In their technical findings, they reveal that the members of the network of their investigation received emails with malicious attachments, very similar to what Maarten reported at ISC back in March. Here's one of the Citizen Lab report emails:






Something else very interesting emerges as we begin digging into some of the technical information shared in the Citizen Lab report.

For example, they mention two domain names used as Command & Control points for the by Gh0st machines they were tracking:

macfeeresponse.org and scratchindian.com

At the time the IP address they were tracking was 218.241.153.61, but now both of those domains are resolving to the IP 210.51.7.155, in China. Other domain names on that same IP address may be domain names of concern, including:

indexindian.com - opanpan@gmail.com
lookbytheway.com - losttemp33@hotmail.com
macfeeresponse.com - losttemp33@hotmail.com
macfeeresponse.org - losttemp33@hotmail.com
MSNxy.net - yglct@sina.com
MSNyf.net - yglct@sina.com
NetworkCIA.com - yglct@sina.com
ScratchIndian.com - opanpan@gmail.com
sysroots.net - yglct@sina.com
timeswindow.net - yglct@sina.com
womanld.com - yglct@sina.com
womannana.com - yglct@sina.com
ybbero.com - yglct@sina.com
yellowpaperofindia.com - losttemp33@hotmail.com
yfhomes.com - yglct@sina.com

A simple Google on most of these domain names will reveal that they are all known to be related to malicious software and botnet activity, but they are still sitting live in China.

The Citizens Lab report reveals that documents from a computer in the Dalai Lama's own office were being exfiltrated to "www.macafeeresponse.org" during the course of the investigation.

While their report focused on traffic related to this Tibet group, it is clear that there are many other groups, with covert traffic being sent back to China and elsewhere, and that it is trivial to create such an infection using commonly unpatched or underpatched exploits, easily downloadable malware, and hard-to-stop social engineering techniques.

If others are seeing data communicating with the domain names listed above, please take action. Report these communications so that we can learn what other groups, besides the Tibet group, may be losing intelligence and internal documents to these data stealing botnets.

Wednesday, March 25, 2009

Bank Hacking Exposed: The Analyzer Affadavit

One of my favorite twitter friends, InfraGard member and PCI expert Michael Dahn (@sfoak), sent his tweets a link today to the Affidavit of Darren Hafnet, a Calgary Police officer working on the Commercial Crime unit, with regards to the arrest of Ehud Tenenbaum (via this excellent WIRED ThreatLevel story). As we wrote back in September (see: Is The Analyzer Really Back?), Tenenbaum became a world-famous hacker for breaching more than 400 systems at the Pentagon, but was most recently picked up in Canada for master-minding a major bank heist via ATM cards.

An indictment, issued by Assistant US Attorney Melissa Marrus from the Eastern District of New York back in October, was extremely short on details, charging Tenenbaum, AKA Analyzer22@hotmail.com, with two counts - "Conspiracy to Commit Access Device Fraud" and "Access Device Fraud" "the aggregate value of which was equal to or greater than $1,000. (Title 18 Section 1029(a)(5), (b)(2), (c)(1)(A)(ii) and 3551) - although my PACER account shows there is a second "*Restricted*" document associated with case 1:2008cr00747.

The Canadian affidavit makes it clear how much greater than $1,000 we are talking about, and reveals quite a bit about the methods used by Tenenbaum and his gang.

The scam is referred to as a "PIN Cashout Conspiracy", and it works like this:

First, Tenenbaum uses SQL Injection techniques to break into a database-driven website which resides on a financial institution's network.

Then, he uses his access to the bank's systems to locate their ATM database.

If necessary, he alters the PIN for the cards he is planning to cash out.

Then he sells these card data to other criminals.

Those criminals create ATM cards using Tenenbaum's information, and drain the accounts. Tenenbaum receives a percentage of the proceeds - in this case "10-20%".

During January and February 2008, the US Secret Service has revealed that they were investigating two such breaches involving Tenenbaum - one against OmniAmerican Credit Union of Fort Worth, Texas, and the other against Global Cash Card in Irvine, California. In April and May of 2008, it is also known that there were breaches of this nature against Symmetrex, a transaction processor in Florida, and 1st Source Bank in Indiana. Symmetrex cards were used by MetaBank - with branches in Iowa and South Dakota. Actual losses of more than $4 Million were experienced just by those brands.

Those who follow computer crime will not be shocked at the location of the servers the criminals used to carry out their attacks. The affidavit says some of the servers were located at HopOne Internet Corp in McLean, Virginia while "much of the traffic going through the HopOne servers was originating from from the Dutch company LeaseWeb."

Through cooperative monitoring in the Netherlands and in the United States, Tenenbaum's MSN conversations have become part of the official court documents, including his confession to hacking the servers, and transactions where he sold many of the cards obtained. The cards were used by "cashiers" in Russia, Turkey, the United States, Canada, Sweden, Bulgaria, and Germany to drain the accounts. Tenenbaum charged between 10-20% of the total proceeds for his role, stating in one chat that he stood to earn between "350 - 400" - that's 400,000! (Unsure whether this was dollars or Euros).

On April 28, 2008 Tenenbaum chatted with another criminal boasting that he had made himself a Windows administrator on the 1st Source Bank network, and had granted himself the ability to modify PINs on debit cards used by the bank's customers. This solves an on-going problem for the criminals - as banks have locked down their Track 2 data on Debit cards, the criminals have had to find ways to break the encryption algorithms of the banks in order to modify the cards. With The Analyzer's method this is no longer necessary. While logged in to the Bank's system, Tenenbaum just set the PINs to whatever he desired and instructed his cohorts to burn cards that would use those PIN numbers.

In another chat, Tenenbaum boasts that he hacked the largest bank Greece (alpha.gr) and "has friends" working in their network.

Tenenbaum was located, according to the Affidavit, by using the IP address from his chats to locate his office in Montreal, where he was set up as the director of "Internet Labs Secure, Inc". The Montreal police confirmed that this was Tenenbaum's residence on July 25, 2008. The same IP address, 69.70.122.98, was also confirmed to have accessed Global Cash Card's network.

Based on this information, Tenenbaum was arrested on August 28, 2008 in Montreal, and charged with fraud by the Calgary Police Service. Tenenbaum had entered Canada legally on an Israeli passport on March 11, 2008, which granted him permission to visit for up to six months.

One of the challenges that I am frequently given by investigators is "surely the criminals would not hack from their own IP address!" In this case, we have evidence that one of the "super hackers" both chats and logs in to banks from an IP address originating at his residence.

Interesting . . .

I wonder how many other banks have criminals running their networks for them without their knowledge?

(The Affidavit, courtesy of WIRED)

Thursday, March 19, 2009

Stop the Rumors: Quit SMSing about WalMart Gang Initiations

My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here's one of them:


Fwd: Do not go to any walmart tonight. Gang initiation to shoot 3 women tonight. Not sure which walmart. And confirmd on tv. Forward 2 all girls on ur phone


At least three different friends sent the message in the space of thirty minutes. I reassured them that it was just a hoax, and pointed them to the Urban Legends sites to see that this rumor has been going around for at least four years:


July 2005 email version:
http://urbanlegends.about.com/library/bl_memphis_gang_initiations.htm

December 2007 email version:
http://urbanlegends.about.com/library/bl_memphis_gang_initiation.htm

March 2009 SMS version:
http://urbanlegends.about.com/b/2009/03/18/police-walmart-gang-initation-rumors-are-false.htm

What was interesting to me though was how widespread the event is, and how each area seems to be treating it as a stand-alone event. Googling up the news has chiefs of police saying there is nothing to worry about, while others are promising a "state-wide investigation".

Apparently the best way to send a rumor is to text it to a teenager and tell her to send it to all her girlfriends.

In Delaware, the State Police are being inundated with calls, and have shared a copy of their message:


i don't noe how tru dis is but here it is. Dont go 2 any walmarts 2nite ther will be a gang initiation n dey have 2 kill 3 women at each store. Tell ur love 1s.


The Greenwood, South Carolina sheriff's office Major Lonnie Smith is promising that there will be extra patrols at their WalMart's Thursday night "as a precaution".

In Portage, Indiana police were on hand at local WalMarts after they "received information from high school students that there was going to be a shooting at a Wal-Mart as a gang initiation."

In Georgia police put out extra patrols, earning the outrage of at least one blogger who says tax payer money was wasted because the police couldn't use Google.

The Jefferson Parish, New Orleans sheriff says these are nothing but rumors, but "As a precaution, Normand is assigning additional personnel to the area as needed", Col. John Fortunato said.

Officers in Murfreesboro Tennessee showed more restraint when the rumors were making their rounds in January -- “An e-mail being distributed in Nashville and Rutherford County about gang intitations is fabricated,” said Chief Deputy Virgil Gammon of the Rutherford County Sheriff’s Department in a Jan. 18, 2008 article.

In Chattanooga Tennessee a version is circulating which names a specific store - the Gunbarrel Road Wal-Mart near Hamilton Place. Chattanooga Police spokesperson Jeri Weary said, "This is not a situation that has occurred in Chattanooga and there have been no reported incidents at any of the Chattanooga area Walmarts."

Police in Findlay Ohio told the local ABC 13 News that they've been told the rumors originated in South Carolina.

Police in Birmingham, Alabama were also calm about the situation -- "They circulate that kind of stuff every year," said Sgt. S. White of the Birmingham Police Department's East Precinct, interviewed by the Birmingham News. "Usually there is nothing to it."

The rumors are being reported in almost every city with a newspaper! Yuma, Arizona, Moline, Illinois, Palm Beach, Florida, Greeley, Colorado . . .

You get the idea . . . all around the country a text message rumor storm has police and concerned parents buzzing about something that everyone is quite sure is a hoax.

Wednesday, March 18, 2009

Carders do battle through spam - carder.su

We've seen several cases in the past where Law Enforcement action is triggered by one criminal actively and publicly spreading information (or mis-information) about another criminal's activities.

That seems to be the case in what is happening now, as a spammer is using an existing spam botnet to send messages about the Russian credit card trading site "carder.su".

Beginning on the afternoon of March 16th, the UAB Spam Data Mine began to receive copies of this email message:



So far we have 142 copies of this email, which came from 138 different email addresses, and were sent to 122 of our unique trap accounts. The emails had 13 different subject lines, but were otherwise the same:

Carders attack
Carders here
Carders online
Carders threat
Hazardous site
How is it possible?
Sale Data
Stolen bank accounts
Stolen credit cards
Stolen data
Terrible site
The threat of credit card
Where is the police?

There were also 132 unique IP addresses in the email headers, corresponding to the 132 bot machines which were used to send us this spam. It would be interesting to know what other spam is coming from these same bot machines. Fortunately, when you have a Spam Data Mine sitting around, that's a pretty simple query to make.

(Full list of IPs at the end of this article . . . if you recognize the botnet please let me know.)

Unfortunately, some IP addresses are less helpful than others . . . is it valid to say that these emails came from the same botnet, for example, when we haven't seen other email from them since October?

Emails from 213.25.157.1 (in Poland):

Date Email Subject
-----------+---------------------------------
2008AUG10 | debt consolidation calculator
2008AUG13 | loans for debt consolidation
2008AUG15 | debt consolidation loans
2008AUG21 | unsecured debt consolidation loans
2008AUG31 | credit check
2008SEP06 | a debt consolidation loan
2008SEP06 | debt busters
2008SEP06 | debt consolidation advice
2008SEP09 | profit debt consolidation
2008SEP25 | clear debt
2008SEP29 | help me get out of debt
2008OCT01 | credit cards debt
2008OCT15 | help to get out of debt
2008OCT26 | horses for loan
2008OCT29 | student loan debt

Or these from 212.26.246.161 (in Russia)

Date | Email Subject
-----------+----------------------------------------------------
2008APR30 | Greetings, I have learned an interesting thing
2008MAY06 | Merrill Lynch Business Centre - Changing a website


The next one is far more useful, because although it shows a long history of spam from the computer at 203.197.115.82 (in India), it also has spam from two weeks ago, which we know by the subject is a sign of a Waledac infected computer.


message_id | subject
------------+-------------------------------------------
2008OCT04 | Hi! I wanna chat with you!
2008DEC08 | Watches
2008DEC13 | Hi sweety
2008DEC26 | Swiss Branded Watches
2009JAN01 | Swiss Branded Watches
2009JAN04 | Don't settle for less
2009JAN03 | Swiss Branded Watches
2009JAN04 | Swiss Branded Watches
2009JAN05 | Swiss Branded Watches
2009JAN06 | Attention: Important Information!
2009JAN08 | Re: Miley loves it huge
2009JAN16 | Swiss Branded Watches
2009JAN24 | Pharmacy Discount for (email)
2009JAN21 | Russian queens are waiting.
2009JAN30 | Turn your bedroom life into a volcano of pleasure.
2009FEB05 | Add floors to your skyscraper special offer for (email)
2009FEB14 | Facing a love-making problem? We will solve all yout problems in few minutes.
2009FEB17 | Have you heard about Viagra for women?
2009FEB27 | Pharma Discount for
2009MAR02 | Regards The day of Love
2009MAR06 | Regards The day of Love


Unfortunately, that was the only machine in our pool which seemed to be a Waledac box. Another coincidence only.

While many of the 132 computers were to be found sending other spam in the UAB Spam Data Mine, there were not enough which sent recent spam to draw any definite conclusions on the botnet.


Limiting our interest only to the most recent spam from the pool of IP addresses, we find that recently spammed sites from the same criminal include:

http://2009-film.ru/ - an illegal movie download site listing this contact information:

Tel: +7 (495) 504-14-43
ICQ: 431409065

As well as the Viagra-selling site, US HealthCare Inc, hosted in Korea and using the domain names:
bumpfold.com
blotcare.com
dunknew.com
dealrise.com
wallsdeals.com

A second set of recent Viagra sites, Canadian Healthcare, used Chinese auto-forwarding URLs in their spam, such as:

aqeakteny.giwhohov.cn
yzmjnq.giwhohov.cn

which forwarded to the Israeli hosted website:

maxitiny.com

A third set of pills was available from this Canadian Pharmacy website:

caringflattering.com

What about Carder.su?



What do we actually know about Carder.su? Not a whole lot truthfully. We know its a popular site - at its max there were more than 14,000 members logged in at the same time.

The WHOIS information for the domain says it is registered to "Private Person", but does give a phone number and an email address:

phone: +79164541122
e-mail: cardersu@ya.ru

A peek back at the WHOIS history shows it was originally registered by:

Maria A Ageeva
886824@mail.ru
+79124427798

From at least November 20, 2009 until March 10, 2009, "Private Person" used a gmail account of: cardersu@gmail.com

Their servers are hosted in Moscow on the 2x4.ru network, owned by Pavel Ivanov.
Ivanov has many interesting customers on his network 92.241.168.0/23. Fine folks like:

cyberterrorist.biz
bl4ckc4rd.ws (black card?)
unlimitedhack.cn
drugspurchase.com
seobiz.org
heihachi.net
coderz.ws
abuse-crew.cc
nukeuploads.com
glavforum.ru

I have to say, the 2x4.ru folks have suspended some of the porn sites that drop malware, so maybe they only cater to certain types of criminals. "gigatube.net" and "eroticzzz.info" were suspended for dropping malware, as was "swiss-warez.biz"



Do you recognize this botnet?



41.248.155.122
58.8.172.135
58.9.203.10
59.182.251.171
61.14.3.165
62.140.238.1
62.57.137.76
67.204.146.123
77.236.6.91
77.30.51.182
77.31.4.53
77.31.64.86
78.106.36.221
78.160.216.232
78.162.210.118
78.162.73.40
78.163.200.222
78.165.108.153
78.166.191.79
78.167.164.42
78.167.58.60
78.169.14.70
78.93.197.72
78.93.82.106
78.96.182.134
79.189.49.202
81.214.156.70
83.29.230.20
84.10.79.200
84.139.136.5
84.47.93.42
85.101.110.99
85.103.13.223
85.103.251.189
85.104.58.189
85.105.209.23
85.108.245.33
85.108.253.26
85.110.153.77
85.110.157.133
85.110.171.230
85.198.177.13
85.99.185.187
86.122.165.34
87.0.54.121
87.109.14.12
87.109.14.174
87.109.159.178
87.120.109.249
87.205.244.153
88.224.151.137
88.224.251.96
88.224.44.225
88.224.75.134
88.226.69.100
88.227.248.11
88.228.97.232
88.230.74.81
88.232.153.116
88.234.163.254
88.237.221.48
88.238.89.111
88.242.123.170
88.243.107.145
88.243.217.210
88.245.107.7
88.245.228.14
88.246.96.61
88.252.78.129
88.254.234.140
89.136.79.96
89.228.156.6
89.252.9.126
89.46.136.175
89.76.97.16
90.148.146.140
91.124.23.200
91.201.112.2
92.112.23.168
92.37.151.127
92.44.194.243
92.47.222.107
92.61.238.120
92.82.172.41
93.94.178.187
93.98.37.210
94.44.29.200
94.96.11.241
94.99.184.93
94.99.74.20
95.134.200.103
95.58.142.176
95.78.138.40
113.53.170.179
116.71.2.192
117.197.96.124
118.43.204.82
121.159.184.91
121.242.55.42
124.121.38.204
124.121.85.111
125.136.199.83
188.48.200.177
189.112.85.88
189.114.152.233
189.12.187.224
189.24.135.57
189.27.243.210
189.46.152.128
189.78.253.59
189.82.74.79
189.93.0.162
190.120.140.118
190.135.146.135
190.19.69.90
196.218.55.234
200.121.245.19
200.163.33.130
201.19.24.84
201.24.126.235
201.67.135.232
201.67.186.108
201.76.71.9
203.197.115.82
211.107.153.132
211.247.31.154
212.26.246.161
213.181.170.167
213.25.157.1
217.147.25.250
218.152.226.159
220.253.192.12

Monday, March 16, 2009

Waledac: Fake Dirty Bomb in Your City

In the February 25th edition of this Blog, Watch Out For Coupon Offers, we described how the Waledac malware family was being distributed in spam pretending to be from "The Couponizer". One of the unique additions to that campaign was that the criminal was using a GeoLocation service on his website to customize the website to reflect the location of your computer.



So, in my location, the headline reads "Powerful explosion burst in Birmingham this morning.", but that is because the criminal has resolved my originating IP and determined I was in Birmingham, Alabama.

In today's version of the Waledac spam, we see the same brief emails which were used in the Valentine's Day and Couponizer Waledac campaigns. A small phrase as the subject line, such as:

Haven't you been there?
I hope you are in good health
What a tragedy!
Take care about yourself!

and another small phrase in the body, such as:

Are you and your friends ok?
How do you feel?
I worry about you
We worry about you

followed by a link to a website, ending in "main.php" or "run.php" or "contact.php", or with no filename at all - just the path.

Clicking on the video controls will prompt for the download of an executable - "news.exe" in my case, which would join your computer to the spamming botnet.

VirusTotal gave a 7 of 39 detection rate for this malware.

click here for VirusTotal Report.

For whatever reason it seems that NOBODY is shutting down the Waledac domains. We reviewed 57 recent and current Waledac domains, and found that only six of them were not currently resolving.

Here is the list of domains associated with Waledac:

adorepoem.com
adoresong.com
adoresongs.com
bestadore.com
bestbreakingfree.com
bestcouponfree.com
bestgoodnews.com
bestlovehelp.com
bestlovelong.com
bluevalentineonline.com
breakingfreemichigan.com
breakinggoodnews.com
breakingkingnews.com
breakingnewsfm.com
breakingnewsltd.com
chatloveonline.com
cherishletter.com
cherishpoems.com
codecouponsite.com
extendedman.com
farboards.com
funloveonline.com
funnyvalentinessite.com
goodnewsdigital.com
goodnewsreview.com
greatcouponclub.com
greatsalesgroup.com
greatsalestax.com
greatsvalentine.com
greatvalentinepoems.com
linkworldnews.com
longballonline.com
lovecentralonline.com
lovelifeportal.com
reportradio.com
romanticsloving.com
smartsalesgroup.com
spacemynews.com
supersalesonline.com
thecoupondiscount.com
thevalentinelovers.com
thevalentineparty.com
tntbreakingnews.com
wapcitynews.com
whocherish.com
wirelessvalentineday.com
worldlovelife.com
worldnewsdot.com
worldnewseye.com
worldtracknews.com
worshiplove.com
youradore.com
yourbreakingnew.com
yourcountycoupon.com
yourgreatlove.com
yourlength.com
yourvalentinepoems.com

You can clearly see that some are "News", some "Coupon", and some "Valentine" related, but they are almost all still active and still infecting people's computers in an attempt to regrow the Waledac spamming botnet.

The domain names use only four different identities in their WHOIS data:

yanshi_ying@yeah.net (Yan Shi Ying)
ed30673637@126.com (Zhao Jun Hua)
meishengchang@163.com (LiPaul Kunshan Yunshu Gongsi)
wusong_ccc@126.com (Zhang Min)

We don't know the size of the Waledac spamming botnet right now, but we were able to quickly make a list of more than 1,200 machines which are currently "hosting" the webservers used by the malware. I've made a file available of 1,235 IP addresses currently hosting Waledac web proxy servers, but that is only a tiny sample of the overall population. Domain owners will find the IP addresses sorted by Country Code, then ASN/Organization, and then IP. Country codes of the bots include:

AR, AU, BA, BE, BG, BR, BS, BY, CA, CH, CI, CL, CN, CO, CS, CZ, DE, DK,
EE, ES, EU, FI, FR, GB, GE, HK, HU, IE, IL, IN, IR, IT, JP, KR, KZ, LT,
LV, MA, MD, MK, MY, NL, NO, PH, PL, PT, RO, RS, RU, SE, SI, SK, TH, TN,
TR, UA, US, UY, VN, and ZA.

(Quiz yourself - How many of those country codes do you know?
Need to cheat? - list of country codes)

The distribution of infected machines in my little snapshot is quite diverse. More than 300 networks from 60 different countries, with no network having more than 60 of the 1,235 machines on my list.

The top networks in my unscientific snapshot were:
59 machines - ComCast ASN 7922 (USA)
58 machines - Proxad ASN 12322 (France)
54 machines - Rogers Cable ASN 812 (Canada)
52 machines - AT&T ASN 7132 (USA)
51 machines - NTL Group ASN 5089 (Great Britain)
44 machines - Shaw Communications ASN 6327 (Canada)
34 machines - Charter Communications ASN 20115 (USA)
27 machines - ComCast ASN 33491 (USA)
26 machines - Road Runner ASN 11427 (USA)
20 machines - ComCast ASN 33278 (USA)

The full list is available as an Excel spreadsheet or as a CSV file.