Sunday, April 25, 2010

Iranian "Sun-Army" attacks NASA and JDA

What does NASA, the US space agency, have in common with the Jerusalem Development Authority of the Israeli government? They've both been attacked this week by the new Iranian hacking group, "Sun-Army".

The Defacement authority, Zone-H.org reports that this group did their first reported hacks on February 17th, one more on February 27th, and then on February 23rd defaced:

maorm.larc.nasa.gov
pic.larc.nasa.gov
fabrication.larc.nasa.gov
ohcm.larc.nasa.gov
sw-eng.larc.nasa.gov
cmar.larc.nasa.gov
careertalk.larc.nasa.gov
oea.larc.nasa.gov
technologygateway.nasa.gov

www.zhemgang.gov.bt
www.jda.gov.il



Their earlier defacements accuse "traitors to the Islamic Republic of Iran" and quotes from the Quran - "Sura Araf verse 179"

That verse says, "And in the law of retaliation there is saving of life for you, O' people of understanding, so that you may guard yourselves against evil."

(These verse were teachings to prevent "tribal feuds" - prior to the Quran, when someone was killed, his family would seek vengeance by killing all of the murderers tribe that they could. This passage of the Quran teaches that retaliation should be one for one. The accused can seek limited vengeance, but once retaliation has been achieved, there should be no on-going feud. Lives are saved by limiting the retaliation.)

Here is their defacement of the Jerusalem Development Authority:



The current NASA defacement contained this English language text:

In The Name Of God

The Nasa organization which is funded by Usa and plays an important role not only in the most of scientific fields but also in many other projects like "Star Wars" which was aimed to weeken the former soviet union , now has come down to its knees toward
the scientific level of young iranians and iran , the birth place of Cyrus the great, who formed the biggest empire the world has ever seen.

the scientific apartaide which is imposed by Usa and it alies can never prevent us from progressing in international scene , special peaceful nuclear energy.

We Congratulate You On The Occasion Of Worlds Astronomical Day


The same message is repeated in Persian, with the following line added at the end:

که ایران و ایران زمین زنده باد /// سر افراز و جاوید و پاینده باد

I can't seem to translate that well with Google Translate it is rendered as:

Iran and the Iranian Live Earth / / / partition and the eternal and lasting head wind

(If you can provide a better translation, please let me know! gar at uab dot edu)



The more recent defacement points to the Sun-Army.com website, shown here:



The Sun-Army says on their website that they were created by inviting the leaders of many influential hacking groups to join forces under the new name to support Iran's security and the Quran. They claim the group was created on February 26, 2010.

Mehdy007 is a fairly regular visitor to the Iranian hacking site, Ashiyane Digital Security. One of his posts, from August 2009, shows him uploading links to a set of 55 hacking videos on a wide-range of hacking topics. On February 24th of this year he was sharing SQL Injection attack techniques with the group, one of which he demonstrated by hacking "sciencescotland.org"

Nitrojen26 also is a member at Ashiyane, and has in the past used the Yahoo email address "Nitrojen26@yahoo.com"

The.Mo3tafA, Nitrojen26, and BodyGuard all regularly show up on pages defaced under the name "Ashiyane Digital Security Team" along with Behrooz_Ice and Q7x, with this trademark logo:



MagicCoder is the relative newcomer to the group, though he has done some solo-hacking according to his Zone-H stats, and has his own logo as well:



He's a gmail user = magicc0d3r@gmail.com

PLUS is an unknown for me. Great hacker name, since its basically impossible to Google-search. He's been involved as a named party on a number of "team defacements" for Ashiyane, including ones that left this fairly recent tag:



On defacements that use that image, the message in Persian and English is:

Our belligerence is religious and does not own any borders, thus we are here as long as atheism and blasphemy exist. We do know that effrontery of blasphemy to Imam Khomeini is what that only you can do. This is just a warning to your governmental sites!


The list of members on those hacks is:
Behrooz_Ice -Q7x -Sha2ow -Virangar -Nitrojen26 -BodyGuard -tHe.Mo3tafA MagicCoder -0261 -Ali_Eagle -PLUS -Jok3r -System.Fehler
We Love Iran
Ashiyane Digital Security Team




The WHOIS registration information for Sun-Army.com lists the same email address as their defacements -- sun.army@asia.com -- as well as this address:

Sun Army
Sun Army (sun.army@asia.com)
Iranian Apartment. Azadi Sq. Tehran
Tehran
Zanjan,12365
IR
Tel. +009.2122532689

Domain servers in listed order:
ns4.mihanblog.com
ns3.mihanblog.com


The domain was registered by PublicDomainRegistry.com (DirectI Internet Solutions)

Those nameservers serve more than 700 other domains . . . mostly Iranian TLDs, ".ir"

Many of those domains are listed as attack pages, sucvh as "karrar.ir," which is described by Google SafeBrowsing as:

What happened when Google visited this site?

Of the 871 pages we tested on the site over the past 90 days, 37 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-04-25, and the last time suspicious content was found on this site was on 2010-04-22.

Malicious software includes 987 scripting exploit(s).

Malicious software is hosted on 4 domain(s), including link313m.persiangig.com/, link313m.blogfa.com/, bidel.ir.googlepages.com/.

2 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including link313m.blogfa.com/, boxeshia-sonni.mihanblog.com/.

This site was hosted on 1 network(s) including AS30176 (PRIORITYCOLO).


Following the links from that SafeBrowsing page find warning of malware, including malware being distributed via "sarzaminnews.mihanblog.com", "karrar.mihanblog.com", and "karrar.ir".

Saturday, April 24, 2010

Carders and Video Pirates?

This summary is not available. Please click here to view the post.

Tuesday, April 20, 2010

Dmitry Naskovets of CallService.biz, Meet the FBI

CallService.biz Gets a New Website


On April 19th a friend sent me a Facebook link announcing that CallService.biz had been closed. The news was officially announced by the New York FBI on Monday, although the arrests happened on April 15th.

The website, even as of this writing, displays a new homepage that looks something like this:



When the FBI designed to take over the management of the CallService.biz website, they did a little relocation first. For some reason they didn't want to host it in Moscow, I guess. The old location, 212.158.162.5, is the home of such great websites as:

1001russian-bride.com, a fine site for buying your new Russian wife (you can talk to her first for only $5.99 per minute...)

and

AdmiralSlots.com, a Casino that I'm assured by all of my spam is a great place to play. They have a wonderful affiliate program which will pay you 20% of the deposits your customers sign up. Errr... "Привлекая новых клиентов в наше казино, вы будете получать 20% от всех их депозитов, независимо от выигрыша." Thankfully, they NEVER send spam. "Запрещена реклама с помощью спама и методами, противоречащими действующему законодательству и нормам морали." See?

Tracking the various organizations that have hosted this criminal website sends us through such dark corners of the Internet as Net Access Corporation (NAC) in New Jersey (66.246.206.121), Garant Park Telecom (89.111.176.54) at Moscow State University, and Caravan.ru (212.158.162.5) also in Moscow.

CardingWorld.cc, also mentioned in the Indictment, is hosted at RusTelecom.biz and was registered using a clever gmail account - cardingw@gmail.com, although originally the owner used the more discrete email - cardingworld_cw@yahoo.com or cwivanov@googlemail.com.

The Indictment



The Indictment (thanks to ThreatLevel@Wired for providing a copy...saves me a couple bucks on my PACER account), says that Dmitry M. Naskovets (Дмитрий Насковец) resided in the Czech Republic and the Republic of Belarus and that he operated the online business CallService.biz with his co-conspirator, Sergey A. Semashko (Сергей Семашко), and that such business was "an online enterprise designed to help identity thieves profit from stolen financial data."

(Dmitry was arrested in the Czech Republic on April 15th. Sergey was arrested in Belarus the same day, while Lithuanian police seized the cardingworld.cc website related to the case, which was housed at 193.219.5.196, IP space belonging to Elneta, elnet.lt.)

From at least June 2007 up to and including April 2010, Naskovets and Semashko operated CallService.biz. Part of their service was to recruit English and German speakers to pose as authorized account holders in order to conduct or confirm fraudulent transactions on behalf of CallService.biz customers. The website allowed Russian speaking customers to place orders for these services. From the indictment:

Orders consisted of, for example, the name of the bank the user wanted to contact, the stolen account information that the user had illegally obtained, and instructions from the user as to what to say, or the fraudulent transaction that was to be conducted, during a phone call to the bank. NASKOVETS and his co-conspirators would assign an appropriate individual, including one who was the same gender and spoke the same language as the authorized account holder. After the requested call was made, NASKOVETS and his co-conspirators would report the results to the CallService.biz user, who could issue instructions for further telephone calls, if necessary.


The indictment quotes from an advertisement that Semashko placed on another website to advertise their service. That website, CardingWorld.cc, was owned and operated by Semashko. The advertisement claimed that CallService.biz had 'over 2090 people working with it' and had done 'over 5400 confirmation calls' to banks, meaning calls to confirm or conduct fraudulent transactions, as described above."

Charges placed against Naskovets and Semashko include:

Title 18 Section 1343, accusing them of "unlawfully, willfully, and knowingly, having devised and intending to devise a scheme and artifice to defraud, and for obtaining money and property by means of false and fraudulent pretenses, representations, and promises, [that] would and did transmit and cause to be transmitted by means of wire, radio, and television communication in interstate and foreign commerce, writings, signs, signals, pictures, and sounds for the purpose of executing such scheme and artifice."

The charges are supported by Instant Message logs which talk about registering the domain name, and wiring fees as much as $35,000 between the two. Other messages contained details of online purchases, including the victim's name, address, email address, Social Security number, answers to security questions related to their banking account, and other information.

Other charges included violations of:

Title 18 USC Sections 1029(a)(2) (obtaining a thing of value greater than $1000 through use of one or more unauthorized access devices during a one-year period)

Title 18 USC 1029(a)(3) (possessing fifteen or more counterfeit or unauthorized access devices)

Title 18 USC 1029(a)(5) (receiving payment exceeding $1000 in interstate and foreign commerce via access devices issued to another person)

Title 18 USC 1028A(c), 1028A(a)(1) and (2) - possession of credit card numbers and bank account numbers (access devices) belonging to other people and transferring them to co-conspirators who used them to facilitate fraudulent transactions.


The Reaction in the Russian Underground



The reaction to this news has been pretty swift. In the carding forum, http://forum.xakepok.org/, one of the moderators, "Maestro", posted a Russian translation of the FBI press release and warned people that the logs from the Callservice.biz site were in the possession of the FBI and that people should immediately discontinue use of any emails or ICQ programs that they had used on that server.

Over on Web-Hack.ru the criminals are warning one another to be careful ("Будьте осторожны - берегите себя!") , and to keep an eye on this situation - especially if the US manages to extradite the criminal! One of the posters mentions that the press release says the criminal could face 39 1/2 years in prison, but then jokes, "of course he'll get off in 3 years."

The moderators at CarderNews.ru start off their very lengthy column by saying "this is not a news story to read quickly and shake your head and forget...this is an information bomb!" The moderator goes on to say, "first, don't panic. Nobody is going to use the information on these servers to start busing petty thieves", but then he goes on and reminds people that even petty thieves should be using SSL and VPN for their internet traffic. He concludes with "do not panic, and do not forget about your safety" (не поддавайтесь панике и не забывайте о своей безопасности.)

CarderNews then does an interview with "Cesar" a moderator who says he worked on the "technical administration" side of the CardingWorld server. Nothing too informative in the interview. It was clear Cesar was limiting what he was going to say.

Thursday, April 15, 2010

Fake AV In the News

Last week I had the opportunity to speak to the IT-360 conference in Toronto, Canada. One of the points that I made in my talk was that we need to respond differently to malware. Rather than just deleting the malware, those who are able should spend a bit of additional time to gather intelligence and share that intelligence with the public and law enforcement. Brian Jackson from ITBusiness Canada took that message to heart, and contacted our lab this week to ask what we could tell him about a curious Google search that he performed.

Brian was looking for more information on the plane involved in the recent death of the President of Poland, a plane known as a "TU-154" called a "Careless" by NATO. When he did his Google search:

TU-154 Careless

nine of the top ten hits he got back were links to pages containing malware. He tells his own version of the story in his article Hackers exploit Polish President's death with scareware attack. Now, even three days later, several of the top Google results still are pointing to malware sites, including:

haroldmedia.com.au
insidekbm.com
innerproductsgroup.com

We passed Brian's request for research to our Malware Analysis group, led by UAB Computer & Information Sciences Masters student, Brian Tanner, who was able to give a quick response to the request - having a strong understanding of what was going on in the first thirty minutes, including identifying a high school website in North Alabama that had been compromised to help distribute the malware! Others joined Brian in the analysis to provide more details.

These sites are running extreme SEO malware - Search Engine Optimization pages which function by building "news headline" sites designed to achieve top Google ranks. For instance, Google is currently indexing 741 unique news headlines pointing off the InnerProductsGroup website, most are current news headlines or "hot searches" such as:

mine rescue teams
mine rescue chambers
frank lucas wife
new york times crossword answers
mega piranha trailer
nbc news brian williams
kristen stewart budapest
tupolev 154 cockpit
the katyn massacre movie
national katyn massacre movie
smolensk airport
jack johnson tour dates usa 2010
spartacus episode 12
Remax.com Homes For Sale Houston

Here's an example from that list - a search for "Kristen Stewart Budapest" shows three malware pages in the top ten results on Google, in positions #4, #7, and #9 for me, but only one of the three is currently properly labeled as "This Site May Harm Your Computer"



What happens if you visit one of these sites? It launches a malware installation of a part that we call "Fake AV" malware. Let me start by showing you what one of these LOOKS like:



Clicking OK results in a web page that appears to be doing a Virus Scan.



The AV, which was really a web page, then says it needs to be updated, and offers an update for you to install.


Running that one actually does install the Fake AV product.




After installing the Fake AV, many imaginary viruses on your computer are "detected", and you are asked if you would like to "Remove All".



Choosing "Remove All" prompts you for credit card information, offering several purchase plans ranging from $49.95 to $89.95 for a "lifetime" Fake AV product.




If you decide not to complete the transaction, you will be bugged relentlessly with pop-ups like these.




Reporting ScareWare



Sounds scary, doesn't it? The industry calls this type of malware "Scareware". Its going to keep trying to make you believe that the only way to keep your machine safe is to give the criminal your credit card information.

Last June, the US Government's Federal Trade Commission fined one of these Scareware vendors $1.9 Million for selling more than 1 million copies of his fake anti-virus software! That's proof that people really do get victimized by this software! I experienced some of James Reno and Innovative Marketing's software first hand when I visited a hotel in San Diego last year. The Business Office computers were all "protected" with one of their fake anti-virus software packages.

There's big money in Fake AV, which is why the current gang continues so diligently even after seeing one of their fellows fined $1.9 Million!

If you've been scammed by these criminals, be sure to file a complaint! I recommend complaining to the FBI's Internet Crime & Complaint Center (ic3.gov). Because of the FTC's previous involvement with Fake AV, you might also want to file your complaint there using their FTC Complaint Assistant.

While neither of these complaint forms is ideally suited for dealing with a Fake AV product, both do offer the opportunity to enter a free-form complaint towards the end of the process. Put as much descriptive detail as you can there.

(Watch FTC Video ScamWatch: How To File A Complaint.)

How does it work?



The sites that have been SEO optimized to show up in news headline and other popular searches act as redirectors. If you type the URL in directly, it forwards you to CNN.com. If you are REFERRED to the URL from Google, Yahoo, or Bing, you are redirected instead to the fake "scanner" page. That page will vary widely, but it started in our case above with a redirect to:

www.bestsafety9.xorg.pl

That first copy of the malware it installed, "packupdate_build8_195_2.exe" was only lightly detected. In a VirusTotal Report on this malware, only 8 out of 40 anti-virus products detected this software as malicious. Major products including ClamAV, F-Prot, Kaspersky, McAfee, Sophos, and Symantec did not report this software as malware.

We let the software run in the lab for a bit to see what computers it would connect to. Here's a partial list:

myfairland.com (91.207.192.24) - Sam Tam, UK
paymentsafety.net (94.102.63.61) - Ecatel, NL (nameserver = 64.86.16.19)
report.land-protection.com (91.207.192.24) - Sam Tam, UK
update1.winsystemupdates.com (188.124.7.156) - Vital Teknoloji, TR
report1.stat-mx.xorg.pl (109.196.132.41) - Vline, Ltd, Moscow
update2.winsystemupdates.com (93.186.124.92) Vital Teknoloji, TR
secure1.safepayzone.xorg.pl (188.124.7.158) Vital Teknoloji, TR
virtest.com (95.169.186.3) - Keyweb, RU - ICQ: 570352881 / virtest@gmail.com
invoiceerica.com (213.229.83.84) - ?? Bluesquare House, Berkshire, UK?
webpaybill.net (66.197.156.53) - NOC, Inc, Scranton, Pennsylvania
system-defender2010.com (91.212.226.199) - Artem Zhirkov, Russia
update1.savecompnow.com (188.124.7.158) Vital Teknoloji, TR

"virtest.com" is a service similar to Virus Total, only this one is clearly run to help criminals determine if there malware is detected or not. VirusTotal, run by white hat security researchers in Spain, shares details of submitted viruses with all participating anti-virus companies. VirTest is almost the opposite. As our friends at Damballa pointed out recently, VirTest charges money to scan your submitted malware and pledges anonymity and that your submissions will NEVER be shared with anti-virus vendors. Our infected computer constantly checked VirTest to see whether it was detected or not. After a while, the malware replaced itself with some new code that we found running from the location:

C:\Documents and Settings\All Users\Application Data\ea73a34\CUea73.exe /s /i /uid=195 /ls=6

That copy of the malware was only detected by 5 of 39 anti-virus products, according to this VirusTotal Report.

After this software ran, we noticed changes in our HOSTS file. All Google sites, for many different country codes, as well as Bing and Yahoo! search pages were being redirected via the HOSTS file to point to 209.212.147.138. That's on the Coloquest network in Arlington Heights, Illinois.

Many of the domains we linked to were hosted on common IP addresses with other domains, such as:

softdialogonline.com
windowspc-defender.com
online-systemscanner.com
system-updates.net

Several of those domains are registered to "Garritt Kooken" with Netherlands email address gkook@checkjemail.nl, who strangely uses the Chinese telephone number +86.592257788 despite having a street address in India.

Mr. Kooken really likes to make fake AV product websites, and hosts many of them on Ecatel in the Netherlands, such as:

best-pc-defender.net
cleanupantivirus.com (94.102.63.64)
cleanviron-mypc.net
dopc-checkprotect.in
exodus130.com
fast-guardcleaneronpc.net
fastscanandcleansoft.com
fastzone-guard.com
holduponyourpc.com
hotcleanof-yourpc.net
lastcheckonmy-zone.net
new-system-defender.net
on-guardzone.com
paymentsafety.net (94.102.63.61)
pcliveguard.com (94.102.63.65)
pcregrtuy.com
safeantivirus.net
safetypcprotection.net
save-secure.com
search4vir.net
securityantivirus.net (94.102.63.67)
seekviron-mypc.net
systemmdefender.com  (94.102.63.61)
systemmguard.com
systemonlinepayment.com
thebestcleanofpc.net
windowsadditionalguard.net
winguard-pro.com
xmopolit67re.com
your-securepayment.com   (94.102.63.61)
your-staffdefender.com
yourzone-best-defender.com

Looking at some IP Neighbors for computers our infected lab machine connected to, we find:

Looking at some "IP Neighbors":

Ecatel of the Netherlands (AS29073)
-----------------------------------
safety-payment.net - 94.102.63.62
safetypayment.net - 94.102.63.62
secures-guard.com - 94.102.63.64
systemmguard.com - 94.102.63.64
cleanupantivirus.com - 94.102.63.64
windowspc-defender.com 94.102.63.65
windowsguard-pro.com - 94.102.63.68
safeantivirus.net = 94.102.63.69
paymentsecurity.net = 94.102.63.69
secure.greywall.net = 94.102.63.69

on Vital Teknoloji in Turkey (AS44565)
------------------------------
update1.winsystemupdate.xorg.pl - 188.124.7.155
securemyfield.com - 188.124.7.156
newsystem-guard.com - 188.124.7.156
update1.winsystemupdates.com - 188.124.7.156
savecompnow.com - 188.124.7.156
newsystem-guard.net - 188.124.7.156
secure1.safetypayment.xorg.pl - 188.124.7.158
newsystemshield.net - 188.124.7.158

on Vline Ltd in Moscow (AS39150)
-----------------------------
www3.tr-leech-kl.xorg.pl - 109.196.132.41
update2.sysupdate-n2.xorg.pl - 109.196.132.41
update2.sysupdt-n2.xorg.pl - 109.196.132.41
report1.stat-mx.xorgl.pl - 109.196.132.41
www1.free-scan-offer-nl.xorg.pl - 109.196.132.40
update1.sysupdate-n3.xorg.pl - 109.196.132.40
www1.best-free-scan-deal-k24.xorg.pl - 109.196.132.40
www1.best-free-scan-deal-nihob.xorg.pl - 109.196.132.40

Unfortunately this is just a drop in the bucket. This bad guy has 1800 domain names to his registration.

Our friend Dancho Danchev mentioned gkook in his series A Diverse Portfolio of Fake Security Software back in December.

A search at the excellent MalwareURL.com shows that this email address has been associated with this type of malware since at least October 9th, when "windows-pcdefender.com" was being reported.

Kimberly at Stop Malvertising did an excellent write-up showing this criminal poisoning searches for St Patrick's Day Celebrations.

She also reported back on December 1, 2009, that Tiger Woods SEO poisoning was leading to Fake AV products in this same group.

Monday, April 12, 2010

Nicolae Popescu, Romanian hacker, at large!

Last week we congratulated DIICOT and their FBI partners on the successful arrest of 70 Romanian Internet fraudsters from three large cybercrime rings. This story continues to develop with more facts being shared as the legal proceedings move forward - but the most significant development is that one of the ring leaders is missing!

While 34 fraudsters are being held in Râmnicu Vâlcea for 29 days while the prosecution builds their cases against them, the most signficant news is one of the individuals NOT being held!


(source: Stirile Pro TV)

One of the ringleaders of the group captured last week, Nicolae Popescu, 'released himself' from custody and is now at large. Apparently when the initial arrests were made, the legal documents under which they were being held were set to expire at 1830 on the day of their arrest. The DIICOT prosecutors were working madly to make their claims to hold each of those arrested for 29 days further investigative period, as is typical in Romanian law, but when 6:30 PM came and went and no papers had been served against Nicolae, he asked to be released, and legally, there was nothing that could be done to stop him! Apparently he quietly walked out the front door without anyone notifying the DIICOT staff what was going on.

I read about this in Impact Real, but many other Romanian news sources are covering the story. No one knows where he is at this time. If you've got more info, please send it this way!

If you live in Romania, you are being asked to report any contact or sighting of Nicolae to the emergency police number. People are also being asked to look out for his vehicles. 30-year-old Nicolae is from Alexandria, Alexandria, Teleorman, Romania. He owns a white Mercedes Benz ML with the license plate "B-63-JOC" (B63"Play" in Romanian), a Black Mercedes Benz CLS 350 with the license plate "B-42-JOC", and a black Audi A6 with the license plate "B-80-BJI".

The Internet Scammers Blog has quoted Romanian Masura Media who is covering the case. Masura says that thirty-four hackers arrested in Valcea will be held for 29 days while further investigation is underway. Their names:

Florin Dan Mişcoci, Alexandru Răduţ, Marius Adrian Ologu, Marian Sorin Grigorie, Laurenţiu Dumitru Anghel, Vasile Petronel Avram, Florin Buceag, Iulian Stere, David Gabriel Cârstea, Narcis Nicolae Petrache, Sebastian Lungu, Bogdan Mehedinţu, Daniel Alexandru Ciomag, Aurel Cătălin Dincă, Gheorghe Tiberiu Budărescu, Ionuţ Sorin Dumitru, Gabriel Drăghici, Nicolae Cristian Ciucă, Nicolae Popescu, Dumitru Daniel Busogioiu, Ovidiu Vlad Cristea, Ştefan Iordachi, Florin Nicula, Nicolae Andrei Paraschiva, Cătălin Sârbu, Marian Lovită Priboi, Mihaela Florina Ungureanu, Vlad Nicolae Vrapciu, Flore Valentin Boje, Alin Constantin Cotă, Florin Dorin Răducu, Călin Cornel Fălcuşan, Alexandru Nicolăescu, Claudiu Marian Turica.

Googling almost any of those names will find many more stories in Romanian. . .

Impact Real also lists the items seized during the raids on this group:

77,350 euros, 49,000 U.S. dollars, 64,860 pounds, 60,645 lei, a luxury watch, a rifle, three pistols and 150 grams of gold. 70 laptops, 165 mobile phones, 35 desktop computers, 15 modems, new servers, 10 blank cards, 2425 SIM cards, 40 cards, 325 memory sticks , 1040 CD-DVD, 20 hard disks, 30 disks and six video cameras. As well as seven cars, worth over 300,000 euros.

Hmmm... what would bad guys be doing with 2,425 SIM cards? Very interesting!

Tuesday, April 06, 2010

70 Romanian Phishers & Fraudsters Arrested

On March 4th, FBI Director Robert Mueller was given a speech on Cybercrime to the RSA conference where he mentioned that:
And we have worked with the Romanian National Police to arrest more than 100 Romanian nationals in the past 18 months. Four years ago, several American companies threatened to cut cyber ties with Romania because of the rampant hacking originating from that country. And yet today, Romania is one of our strongest partners.


Hotnews.ro followed this up with a 7 minute interview from March 9, 2010 with FBI Legal Attache Gary Dickson who is the liaison between the FBI and Romanian cyber police. He states in the interview that Romanian cyber criminals steal "hundreds of millions of dollars" from Americans each year.


(click to play interview in YouTube)

When asked what the main type of crime was that Romanians committed against Americans, Dickson said it was primarily Auction fraud - where they sold imaginary goods to Americans.

There is good news on that front today from Romania!

On Tuesday, April 6, 2010, the Romanian Police released the news of a police raid organized by the prosecutors at D.I.I.C.O.T. - the Directorate for Investigating Organized Crime and Terrorism - had arrested 70 members of three separate organized cyber crime groups.

DIICOT Press Release

Since 2006 these groups have stolen funds from citizens of Spain, Italy, France, New Zealand, Denmark, Sweden, Germany, Austria, the United States, Canada, and Switzerland - primarily through online auction fraud. International authorities have identified more than 800 victims with more than 800,000 Euros worth of losses.

300 gendarmes and 400 policemen, including 260 members of the Special Investigations Brigade of the Gendarme participated in the arrests, which included 101 search warrants being served. 31 in Bucharest, 41 in Valcea, 12 in Teleorman, 4 in River, and one each in Arges, Prahova, Brasov, Constanta, Doj Giurgiu, Suceava, Botosani, Bacau.

DIICOT says that the raids were conducted in collaboration with the FBI and US Secret Service officers from the US Embassy in Bucharest.

A video of one of their raids was posted as an MP4 file -- here's a few stills from that video:





The story is starting to hit the wires with April 7th bylines - follow along in Romanian if you wish:

The story FBI Descends on Prahova indicates searches were also conducted related to this case in Prague and in the USA.

According to the Gazeta de Sud the raid was codenamed "Operation: Valley of the Kings" (Valea Regilor).

Gandul News has a photograph I haven't seen elsewhere, and reports that the criminals were selling fictional electronic and luxury cars and even airplanes. Recent sales included a BMW X5, Lexus and Infiniti vehicles, and even a recreational aircraft that sold for 67,000 Euros to a rich American. The group also sold motorcycles, laptops, and gold and platinum Rolex watches -- all fakes. Officers monitored the three groups for a year before pulling the trigger on the raid.

Realitatea got a statement from DIICOT executive, Nicolae Blaga - "Computer fraud and the sale of information stolen by phishing are well-known practices" or something like that -- (Modul de fraudă informatică este arhicunoscut cu procurarea datelor prin fishing, inducerea în eroare a părţilor vătămate prin licitaţii frauduloase.)

Nicolae's statement to the Adevarul.ro included the statement that "the support he received from the FBI was of great importance." (Am beneficiat de spijinul FBI care a fost de mare importanţă")

Agentia is the only story so far that specifically mentions fake eBay sites being involved. It is likely that the account take-overs that allowed the convincing sale of vehicles began with an eBay phishing campaign to steal credentials.

According to this story in Brasov one particular student, pays his way through college by selling imaginary yachts and villas on the Internet. He received his wake-up call from the Organized Crime Brigade in his dorm room at the University of Transylvania.

Thursday, April 01, 2010

PWN2OWN & Fuzzing

Charlie Miller got quite a bit of buzz for his fuzz when at CanSecWest he owned a fully patched Mac with fully patched Safari "in 10 seconds". He got more attention when he announced that he wasn't going to release his discovered vulnerabilities, but rather provide a detailed methodology that would allow the vendors to find all the bugs that he had found, plus more. Forbes Magazine shares that much of Charlie's skills was acquired while working for five years at the NSA as a "global network exploitation analyst". What a cool title!

While I have some head knowledge about fuzzing - having read and played with the book Fuzzing: Brute Force Vulnerability Discovery, what really made me understand its value was working a Penetration Testing engagement with Packet Ninja Daniel Clemens. Dan does most of his work at a hand-crafted "ninja intuition" level, but when he has discovered a potentially vulnerable app, he's absolutely willing to throw a fuzzer at it and let it churn. In this case, I got to watch him in action with Burp Intruder.

I knew that Dragos, another famous fuzzer, listed Burp Intruder as one of his Ten Favorite Web Application Fuzzing Tools. But watching this tool in the hands of a master Pen-Tester like Dan really made the lights come on for me!

Still, its one thing to fuzz forms on a website, and quite another to fuzz applications (although Dan does that quite successfully, too). When I heard about Charlie's "three-peat", winning PWN2OWN for the third consecutive year, I started hitting all the blogs looking for first hand accounts from people who were there. One of the most amazing things to me was that Charlie claimed to have found all of these vulnerabilities using "a dumb 5-lines of python fuzzer". I got some hints that things were more complicated than that by looking at some slide-shots from CanSecWest 2010 In Pictures, including scary ones like this:


and

(pics from "infosecevents.net")

Charlie's talk demonstrated his results using his fuzzing technique on PDF files using Adobe Acrobat Reader and Mac PDF Preview and on PowerPoint files, using Open Office PPT, Microsoft Office PPT. From his previously discussed work in Safari and IE we know that his techniques have much broader implications.

Today I finally got a much deeper understanding when I saw from the Thoughts from a Technocrat blog that Charlie had posted his CanSecWest slides from his presentation -- Babysitting an army of monkeys: an analysis of fuzzing 4 products with 5 lines of Python (PPT file).

His presentation contains this hint at the Five Lines of Python you've been breathlessly waiting for:

numwrites=random.randrange(math.ceil((float(len(buf)) / FuzzFactor)))+1for j in range(numwrites):rbyte = random.randrange(256)rn = random.randrange(len(buf))buf[rn] = "%c"%(rbyte);


Charlie actually recommends three other presentations on fuzzing within his slidedeck:

Fuzz by Number - Charlie Miller, 2008

!exploitable and Effective Fuzzing Strategies as a Regular Part of Testing - Jason Shirk, 2009

Effective Fuzzing Strategies - David Molnar and Lars Opstad, 2010

If you are responsible for ANY application security, you really need to evaluate Charlie's methods. His setup involved fuzzing for three weeks on five Mac OS boxes. Surely the authors of major web browsers can afford a setup of at least that complexity? Hmmmm....(dear students, what do you think *WE* could set up???)

Charlie's Fuzzing book is available at Amazon.com:

Fuzzing for Software Security Testing and Quality Assurance

Be sure to follow Charlie on Twitter if this is a topic of interest to you:

http://twitter.com/0xcharlie


(Full Disclosure: For the observant, yes, the Amazon links in this presentation are affiliate-tagged. If enough of you buy the books, my copy is free. When I buy security books they go in my library for students in the UAB Computer Forensics Research lab to use. If you want to send us free books some other way, that's cool, too. 8-)

Tuesday, March 30, 2010

Microsoft Releases "Out of Band" IE Update

Microsoft has released a new patch for Internet Explorer, and no, your calendar isn't off, this is NOT the Second Tuesday of the month. According to the Microsoft Security Advisory, updated today, the reason for the out-of-band release was that the vulnerability described in CVE-2010-0806, "Uninitilized Memory Corruption Vulnerability", was being widely seen in the wild.

Interestingly, Microsoft thanks Chinese security company "VenusTech" for providing them notice of that exploit.

Absolutely. On March 10th the exploit was added to the MetaSploit framework, and instructions on how to use the exploit immediately hopped on many hacker boards. We saw it first on the replacement for Milw0rm, XpltDB: Exploit-DB.com.

Here is just a sampling of some of the places its being openly discussed:

hackua.com - the Ukrainian hacking forum, had a post on March 14, 2010 by "Dementor" explaining the use of the exploit, which quoted the HD Moore version, including the comments about the exploit being observed in the wild by Red-Sec, who observed the exploit on the website www.topix21century.com

0day.net in Guizhou province, China, had the Chinese language version of the discussion beginning on March 12th, posted by the owner of the forum, asphack. He provided a .rar file of the exploit from his website, asphack.com.

exploit.in, which despite the India country code is a Russian language website carrying banner ads for various Russian-language cybercrime sites, such as "InstallsMarket", "SecretsLine VPN", and "EvaPharmacy". As an example of those, InstallsMarket will install your malware on 1,000 US-based bots for $100. Interesting place to be discussing IE vulnerabilities, no?

Korea's SecurityPlus also was sharing details, and the exploit.

Several Chinese hacker sites linked back to: BBS.pediy.com. Their very active "Software Debugging Forum" had several members contributing suggested improvements to the shell code. 45 replies to the thread so far, but the thread has been read almost 5,000 times!

The Microsoft Bulletin is here:

ms10-018.

Some of the issues addressed include:

CVE-2010-0267 - Uninitialized Memory Corruption Vulnerability
CVE-2010-0488 - Post Encoding Information Disclosure Vulnerability
CVE-2010-0489 - Race Condition Memory Corruption Vulnerability
CVE-2010-0490 - Uninitialized Memory Corruption Vulnerability
CVE-2010-0491 - HTML Object Memory Corruption Vulnerability
CVE-2010-0492 - HTML Object Memory Corruption Vulnerability
CVE-2010-0494 - HTML Element Cross-Domain Vulnerability
CVE-2010-0805 - Memory Corruption Vulnerability
CVE-2010-0806 - Uninitialized Memory Corruption Vulnerability
CVE-2010-0807 - HTML Rendering Memory Corruption Vulnerability

Yeah, I think we ought to install that patch!

Sunday, March 28, 2010

Arrests on the Rise

Lots of little newsworthy updates recently . . . they've been well-covered elsewhere, but we wanted to make sure our readers saw them as well.

Russia: Safe Haven no more?


One of the constant complaints that we hear is "the criminal is probably in Russia", as an excuse for why a case is not worth investigating. Back on November 11, 2009, we posted a story The $9 Million World-wide Bank Robbery, where VIKTOR PLESHCHUK, 28, of St. Petersburg, Russia; SERGEI TŠURIKOV, 25, of Tallinn, Estonia; and OLEG COVELIN, 28, of Chişinău, Moldova were charged with leading the robbery, which actually occurred in 2008. This week the Financial Times has revealed that Viktor Pleshchuk was arrested by the FSB. Their story leads with:

Russia has quietly arrested several suspects in one of the world's biggest cyberbank thefts, raising hopes of a previously unseen level of official co-operation in a country that has been a haven for criminals.


Other sources, for instance Bank Info Security News have confirmed that Sergei and Oleg were also arrested by the FSB at the same time.

Your Federal Friends on Facebook?


Pasquale Manfredi isn't exactly a nice guy. The authorities have wanted to arrest him for some time because of his naughty habits such as assassinating his enemies by shooting a bazooka at their car. The Daily Mail says that he also maintained a Facebook account under the name "Georgie", with Al Pacino's "ScarFace" as his Profile picture. According to The Register, authorities used intelligence gathered from his Facebook page to identify his location and successfully make the arrest.
(Image from Daily Mail)

The Associated Press's Richard Lardner followed up with a story about the way MySpace and Facebook are both being used as investigative goldmines. See his story Break the law and your new 'friend' may be the FBI.

Twitter Hacker in France


"Hacker Croll" an unemployed 25-year-old hacker who lived with his parents had his moment of fame after breaking into the Twitter accounts of President Obama and Britney Spears. The AP story says he was arrested by French police, who have released him to reappear on June 24th for his trial. The hacker calls himself "more of a pirate than a hacker", and has explained his method to the police. French prosecutor, Jean-Yves Coquillat, says the young man was acting on a bet, and that he is "the sort who likes to claim responsibility for what he's done." According to an AFP Story TechCrunch had received more than 300 documents belonging to Twitter employees that were provided by Hacker Croll. Twitter has acknowledged that they seem legitimate.

Monday, March 22, 2010

Most Dangerous Cities for Cyber Crime?

Symantec Riskiest Cybercrime Cities


Symantec released a study today in conjunction with Sperling's Best Places today. According to their Executive Summary to make their list they considered a number of factors, including:

- Number of malicious attacks
- Number of potential malware infections
- Number of spam zombies
- Number of bot infected computers
- Level of Internet Access
- Expenditures on computer hardware and software
- Wireless hotspots
- Broadband connectivity
- Internet usage
- Online purchase

The report lists the Ten Riskiest Cities, and then gives a list of recommendations, the first of which is of course to buy Security software. (#2 - keep your computer patched, and #3 - Stay Educated about current threats. They recommend www.everyclickmatters.com for that. I actually would add to that recommendation that geeks should read this blog and non-geeks should visit StaySafeOnline.org, a great site by the NCSA that has advice for Home users, K-12, Higher Ed, and Small Business users.

Here's the Top Ten "Riskiest Cities for Cyber Crime":

1. Seattle
2. Boston
3. Washington DC
4. San Francisco
5. Raleigh
6. Atlanta
7. Minneapolis
8. Denver
9. Austin
10. Portland

PC World's JR Raphael reported today on The 50 Riskiest Cities for Cybercrime in America, from the same Symantec report. Disappointed that your city is not on the list? I was too. No Birmingham, Alabama, which points out a flaw in the methodology. The Symantec report assumes that the greatest dangers are in the most wired cities (rate goes up for broadband acceptance, wifi hotspots, etc.)

I honestly believe that a different look at the numbers would show that rates of cybercrime are higher in places with higher populations of retired computer users, a lower education (or at least CYBER education) level, and places where computers have only recently been added to the home and are new to concepts of email and online banking. These are likely to be the exact opposite places as found in the Symantec report.

Just to look at a couple examples . . .

Symantec says Seattle is #1 for Cybercrime.
The FTC Consumer Sentinel put them at #78 for complaints about Fraud.
The FTC Consumer Sentinel put them at #148 for complaints about Identity Theft.

Symantec says Boston is #2 for Cybercrime.
The FTC Consumer Sentinel put them at #254 for complaints about Fraud.
The FTC Consumer Sentinel put them at #252 for complaints about Identity Theft.

Symantec says Washington DC is #3 for Cybercrime.
The FTC Consumer Sentinel put them at #36 for complaints about Fraud.
The FTC Consumer Sentinel put them at #82 for complaints about Identity Theft.

Symantec definitely considers other factors that WOULD increase with higher rates of acceptance - bots like high speed broadband, and if you have more computer users, you'll have more spammers, etc. They are in a unique position to model that, and I give them their due for studying their numbers and sharing them with the public. But . . . I think when most people think about Cyber Crime Risk, they want to know if they are going to have their money or their identities stolen. The Symantec model just doesn't answer that question very well.


What is the FTC's Consumer Sentinel? Funny you should ask!

FTC's Consumer Sentinel Report


One way of spot-checking the data would be to review what the likely threats are in each city based on actual criminal complaints. Its called the "Consumer Sentinel" report from the Federal Trade Commission. Each year about this time, the FTC puts out their annual report gathered from a variety of sources, including the FBI's Internet Crime & Complaint Center (IC3.gov), one of the best places a consumer can report cyber crime victimization.

This year's Consumer Sentinel Network Data Book for January - December 2009 was released on February 22nd. 1.3 Million complaints were received, including 721,418 complaints of online Fraud were made to the network, with 630,604 victims reporting average losses of $2,721 for a total of $1.7 Billion in fraud losses last year.

48% of those frauds were originated by email - part of the reason that the UAB Spam Data Mine is such an important part of our research at UAB. With $850 Million worth of fraud being linked to email last year, we think email-based crimes are well worth studying.

The Consumer Sentinel report breaks down complaints per capita on a state-by-state in the categories of "Identity Theft" and "Fraud & Other Complaints".

The Top Ten states for Identity Theft:
(# = Complaints per 100,000 residents)
1. Florida122.3
2. Arizona119.4
3. Texas116.4
4. California114.2
5. Nevada106
6. New Mexico98
7. Georgia97.2
8. New York95
9. Colorado93.8
10. Illinois91.8
(17. Alabama)76.2


Top Ten States for Fraud & Other Complaints
1. Nevada412.9
2. Arizona412.4
3. Texas397.2
4. California393.6
5. Nevada391.7
6. New Mexico377.7
7. Georgia376.1
8. New York369.3
9. Colorado366.8
10. Illinois361.9
(20. Alabama)296.1


Top Ten Large Metropolitan Areas for Fraud and Other Consumer Complaints
# per 100,000 residents
1. Mount Vernon-Anacortes, WA 684.7
2. Dunn, NC 684.3
3. Greeley, CO 656.8
4. Boulder, CO 640.5
5. Allegan, MI 631.4
6. Gainesville, GA 625.5
7. Roseburg, OR 618.5
8. Thomasville-Lexington, NC 617.8
9. Eugene-Springfield, OR564.9
10. Montgomery, AL 549.8
171. Birmingham-Hoover, AL351.5


Top Ten Large Metropolitan Areas for Identity Theft Complaints
# per 100,000 residents
1. Brownsville-Harlingen, TX 262.4
2. McAllen-Edinburg-Mission, TX 247.4
3. Laredo, TX196
4. Miami-Fort Lauderdale-Pompano Beach, FL193.2
5. Madera, CA180.9
6. Dunn, NC173.8
7. Merced, CA 172.7
8. Corpus Christi, TX 171.3
9. Greeley, CO 169.4
10. Bakersfield, CA 168.2
11. Visalia-Porterville, CA 168.2
12. Thomasville-Lexington, NC 160.4
13. Montgomery, AL 155.8



Consumer Reports "State of the Net"


I first heard about the Consumer Reports "State of the Net" survey when I attended the National Press Club kick-off for "October is Cyber Security Awareness Month" in 2008 and met Jeffrey Fox, the Consumer Reports Technology Editor. I was amazed by the quality of the data! Finally we could make some reasonable statements about the level of phishing losses to consumers! We'll hopefully see the 2010 edition soon, but in the meantime, let me recommend their work from June 2009, Boom Time For Cybercrime, where they estimate the cost of cybercrime to $8 Billion per year.

Why is their number so much larger than the number from the Federal Trade Commission Report? The FTC report is ACTUAL VICTIMS who have taken the time to report their victimization to one of the agencies represented in the Consumer Sentinel. The Consumer Reports model builds a statistically supported model and surveys enough folks to project across the entire US population. For instance, Consumer Reports says that 1 in 13 online households in the US knows that they gave their personal information to a phisher during the previous two years, and that 1 in 7 of these lost money (so 1 in 90 households lost money to phishing - or roughly $483 Million). Their costs also include other damages however, such as the fact that 1 in 12 households replaced a computer in the past six months due to "serious problems" with viruses or spyware ($1.7 Billion), and that 1 in 7 households had experienced a "serious" virus problem ($5.8 Billion in clean-up costs).

Alabama's Top Cities for Fraud and Identity Theft


Here's a little special section for friends in Alabama (where UAB is based)

Alabama had 8,546 Fraud Complaints, for $13,739,250 in losses last year.
Alabama also had 3,586 Identity Theft Complaints.

For Fraud, our "Metropolitan Areas" on the list were:

#10. Montgomery 2,012 complaints / 549.8 per 100,000
#101. Huntsville 1,539 complaints / 398.1 per 100,000
#139. Gadsden 387 complaints / 374.9 per 100,000
#171. Birmingham-Hoover 3,895 complaints / 351.5 per 100,000
#206. Anniston-Oxford 378 complaints / 334.2 per 100,000
#212. Decatur 496 complaints / 332.3 per 100,000
#217. Auburn-Opelika 430 complaints / 329.5 per 100,000
#247. Tuscaloosa 650 complaints / 316.7 per 100,000
#256. Daphne-Fairhope-Foley 535 complaints / 311.5 per 100,000
#258. Dothan 431 complaints / 309 per 100,000
#272. Mobile 1,235 complaints / 305.4 per 100,000
#336. Florence-Muscle Shoals 391 complaints / 273.1 per 100,000

For Identity Theft in Alabama

#13. Montgomery 570 complaints / 155.8 per 100,000
#77. Tuscaloosa 221 complaints / 107.7 per 100,000
#130. Birmingham-Hoover 1,023 complaints / 92.3 per 100,000
#136. Gadsden 94 complaints / 91.1 per 100,000
#141. Dothan 125 complaints / 89.6 per 100,000
#160. Anniston-Oxford 98 complaints / 86.6 per 100,000
#176. Mobile 339 complaints / 83.8 per 100,000
#188. Auburn-Opelika 107 complaints / 82 per 100,000
#210. Decatur 116 complaints / 77.7 per 100,000
#219. Daphne-Fairhope-Foley 130 complaints / 75.7 per 100,000
#312. Florence-Muscle Shoals 83 complaints / 58 per 100,000
#315. Huntsville 218 complaints / 56.4 per 100,000

Thursday, March 11, 2010

PKK Hackers Arrested in Turkey


Hacker sites and foreign press are picking up the story today of the arrest of at least 23 hackers in 13 different provinces in Turkey. The news was first seen in Russian on 09MAR2010, but is now spreading into the English speaking press, with more details available.

News.AZ ran the story 23 Kurdish hackers arrested in Turkey, which provides some basic facts that the hackers are associated with the Kurdistan Workers' Party, or PKK, and were taken to Diyarbakır for further questioning. This article calls the hacker team the "Cold Attack Team", and says that it took orders from leaders in Kandil in Iraq and in Europe regarding what websites to hack and what messages to place there. It also mentions that the hackers distributed a PowerPoint attachment via email which would trojan the readers computer.

It is unknown if this story is related to news first released in February about another PKK hacker. A story in Today's Zaman provides a bit more depth, PKK hacker faces up to 10 years in prison, identifying the leader of a PKK hacker group as having been apprehended on November 14th, and charged with "acquiring state secrets and confidential documents on behalf of the PKK terrorist organization". The indictment unveiled by a Diyarbakır prosecutor reveals that the hacker, who they call by his initials, R.Ç., had classified documents on his computer belonging to Turkey's National Intelligence Organization, the Milli Istihbarat Teskilati (MİT), and evidence that the hacker had an "online friendship" with Murat Karayılan, who leads the PKK in northern Iraq. R.Ç. claims he was introduced to Murat by a friend in France, and that they gained the classified documents through "computer virus programs he placed on pornographic Web sites visited by army members."

Mr. WaGrAnT is probably a member of the group - a YouTube tribute to his hacks, posted by "KurdishKANGAL58" back in August shows many examples of his works, under the title: Cold Hackers Kυrdish Hαcкєяѕ Gяσυρ 2σσ9, but there are actually many other Kurdish hacker tributes, including this one that gives you a nice exposure to Kurdish rap music: Kurdish Hacker " Mr.WaGRaNt " Dünyaya Karsi.

COLDHACKERS VE THT YANI TOLHILDAN HACK TEAM UNLU KURD HACK GRUBU TURKLERIN SANAL KABUSU is one of many other sites, which actually shows the group name "ColdHackers" where they call themselves "Cyber Median's Guerillas".

Zone-H statistics for the ColdHackers gives them credit for 2,661 website defacements on 1,230 unique computers, including 3 hacks in the past 48 hours.


(click image to visit Zone-H)

The team's website, ColdHackers.team-forum.net is still live as of this writing. Members share their PKK pride with avatars such as this one:



Someone on the team also maintains their "cold-hackers.spaces.live.com" website at Microsoft -- which has this example of their photoshop abilities. Famous hackers need a good PhotoShop team!



This image is from their defacement in December of a Turkish government website:

Wednesday, March 10, 2010

HM Revenue & Customs Refund Portal - Ten Phish in One

This morning I was reading a report from Kenneth Paschal, a member of the UAB Phishing Operations research team, that contained an interesting group of new phishing sites. The campaign advertises an "HM Revenue & Customs" page using an email with this message body:

After the last annual calculations of your fiscal activity, we have determined that you are eligible to receive a tax refund of 988.50 GBP. Please submit the tax refund request and allow us 2-3 days in order to process it.

Click Here to submit your tax refund request

Note : A refund can be delayed a variety of reasons, for example submitting invalid records or applying after deadline.

Best Regards

HM Revenue & Customs


The so-called "Tax Refund Portal" looks like this:



Each of the icons takes the visitor to a very professional looking phishing site to have the credentials for that bank stolen. The banks currently making up the pool including:

Barclays
Lloyds TSB
Halifax
Abbey
HSBC
Cahoot
Royal Bank of Scotland
Egg Bank
NatWest
Alliance & Leicester

In most cases the URL advertised in the phishing email actually is a forwarder to another location. For instance, the most recent phish from today forwarded to this site to show the actual content:

hxxp://daegups.com/bbs/data/bbs2/folder/folder/New Folder/United2/Folder/Folder/Folder/Folder/Folder/Folder/Folder/empty/empty/empty/United2/United/United/United/index.htm


We had previously seen seventeen such phishing sites, in July and August of 2009, but the front has been quiet until March 1st. A quick peek into the UAB PhishURLs database shows that we're seeing an escalated number of these sites being created.

2010-03-01 | http://www.tvlinko.com/refundportal.htm
2010-03-02 | http://www.tvlinko.com/hmrc/refundportal.htm
2010-03-03 | http://romeningh.dz/img/glyph/hmrc/refundportal.htm
2010-03-03 | http://www.michaelmucklow.com/wp-content/hmrc/refundportal.htm
2010-03-04 | http://www.urbanecology.org/szjtd/hmrc/hmrc/refundportal.htm
2010-03-04 | http://kaptan-electricite.dz/images/me/hmrc/hmrc/refundportal.htm
2010-03-04 | http://kaptan-electricite.dz/images/ms/hmrc/hmrc/refundportal.htm
2010-03-04 | http://www.ardeola.org/lib/hmrc/refundportal.htm
2010-03-04 | http://kaptan-electricite.dz/images/hmrc/hmrc/refundportal.htm
2010-03-04 | http://kaptan-electricite.dz/images/all/hmrc/hmrc/refundportal.htm
2010-03-05 | http://www.bloomingdaledc.org/joomla/cache/hmrc/refundportal.htm
2010-03-05 | http://www.demo.wecandesign.com.tw/gojahn/images/file/hmrc/hmrc/refundportal.htm
2010-03-05 | http://www.demo.wecandesign.com.tw/gojahn/images/image/hmrc/hmrc/refundportal.htm
2010-03-05 | http://www.demo.wecandesign.com.tw/gojahn/upimg/pro/hmrc/hmrc/refundportal.htm
2010-03-05 | http://www.demo.wecandesign.com.tw/gojahn/upimg/hmrc/hmrc/refundportal.htm
2010-03-06 | http://www.planet-promo.de/roxx/cache/hmrc/hmrc/refundportal.htm
2010-03-06 | http://mojwlasnydom.com/gallery/hmrc/hmrc/refundportal.htm
2010-03-06 | http://www.peterkinitsolutions.com/demos/lingerie/images/hmrc/hmrc/refundportal.htm
2010-03-06 | http://www.peterkinitsolutions.com/demos/Jewellery/images/hmrc/hmrc/refundportal.htm
2010-03-06 | http://planet-promo.de/cache/hmrc/hmrc/refundportal.htm
2010-03-06 | http://planet-promo.de/roxx/logs/hmrc/hmrc/refundportal.htm
2010-03-06 | http://www.examsheets.net/images/hmrc/hmrc/refundportal.htm
2010-03-07 | http://bogatypolak.com/hmrc/hmrc/refundportal.htm
2010-03-07 | http://www.cz.etechsol.pk/cp/hmrc/hmrc/refundportal.htm
2010-03-07 | http://mojwlasnydom.com/uk/hmrc/hmrc/refundportal.htm
2010-03-07 | http://artemoda.uol.com.br/fotos/hmrc/hmrc/refundportal.htm
2010-03-07 | http://bogatypolak.com/uk/hmrc/hmrc/refundportal.htm
2010-03-07 | http://www.ingatlanok.erdelyitelkek.ro/re_images/UK/hmrc/hmrc/refundportal.htm
2010-03-07 | http://mojwlasnydom.com/images/hmrc/hmrc/refundportal.htm
2010-03-07 | http://artemoda.uol.com.br/downloads/hmrc/hmrc/refundportal.htm
2010-03-07 | http://mojwlasnydom.com/libs/hmrc/hmrc/refundportal.htm
2010-03-08 | http://www.ingatlanok.erdelyitelkek.ro/re_images/UK/hmrc/refundportal.htm
2010-03-08 | http://www.cotogarden.com/templates/hmrc/refundportal.htm
2010-03-08 | http://www.cotogarden.com/myimages/hmrc/refundportal.htm
2010-03-08 | http://www.cotogarden.com/hmrc/refundportal.htm
2010-03-09 | http://www.cotogarden.com/_private/hmrc/refundportal.htm
2010-03-09 | http://www.cotogarden.com/images/hmrc/refundportal.htm
2010-03-09 | http://www.cotogarden.com/_vti_bin/hmrc/refundportal.htm
2010-03-09 | http://www.cotogarden.com/banners/hmrc/refundportal.htm
2010-03-10 | http://www.restoretherepublic.com/images/hmrc/refundportal.htm
2010-03-10 | http://www.eab-gmbh.de/images/hmrc/refundportal.htm
2010-03-10 | http://www.eab-gmbh.de/cgi-bin/hmrc/refundportal.htm

The UAB Spam Data Mine had samples in our March 6th spam at 12:30 AM, 1:30 AM, 4:30 AM and 5:45 AM spam collections for "planet-promo.de/roxx/logs/hmrc/hmrc/refundportal.htm". After that site was terminated, the bad guys relaunched in our 12:15 PM spam collection with "www.examsheets.net/images/hmrc/hmrc/refundportal.htm". As you can see, many others have followed.



We'll continue to watch for emerging patterns like this one, and share with you what we find. For now, be wary of this "Tax Refund Portal"!

Monday, March 08, 2010

Energizer DUO: Trojan yourself for only $19.99


(image from EnergizerRecharge.eu)

The Energizer DUO, a USB-powered battery recharger, was confirmed on Friday by Energizer Holdings to contain malicious code. According to this Energizer Press Release, they were notified by the CERT Coordination Center that the Windows software that ships with their DUO Charger "contains a vulnerability".

Energizer has discontinued sale of this product and has removed the site to download the software. In addition, the company is directing consumers that downloaded the Windows version of the software to uninstall or otherwise remove the software from your computer. This will eliminate the vulnerability. In addition CERT and Energizer recommend that users remove a file that may remain after the software has been removed. The file name is Arucer.dll, which can be found in the Window system32 directory.

Energizer is currently working with both CERT and U.S. government officials to understand how the code was inserted in the software. Additional technical information can be found at http://www.kb.cert.org/vuls/id/154421.


Apparently Unix tutorial author Ed Schaller was the one who reported the malware to US-CERT. US-CERT then asked Symantec to evaluate the malware, which was written up by Liam Murchu in the Symantec Security Response Blog.

According to the US-CERT article, Arucer.dll is launched in the traditional way, with a "rundll32" call from the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run key.

The hashes for the malware file, Arucer.dll, which is 28,672 bytes in size, are:

MD5: 1070be3e60a1868d2cd62fc90d76c861
SHA1: d102b1d2538d8771be85403272e5a22a4b3f81ad

US-CERT indicates that the file properties indicate the file was written on a Chinese computer. (Language set = 0x0804)

The detection on that malware as of last night is still pretty sketchy according to VirusTotal. In this VirusTotal Report for Arucer.dll it showed that only 9 of 42 anti-virus products would have triggered on this malware. Microsoft, Sunbelt, and Symantec are now detecting it as "Arugizer" (or Arurizer in Microsoft's case). F-secure, Fortinet, McAfee, and Sophos are also detecting.

Although Symantec's Liam indicates they were able to download the software from the Energizer website on Friday, all links we could find for the downloadable package, formerly at:
hxxp://www.energizer.com/usbcharger/download/UsbCharger_setup_V1_1_1.exe
now redirect to an Energizer homepage.

If you REALLY want to trojan yourself, perhaps your best bet is to buy one of these systems from a third party, such as Amazon.com who still offers Energizer Charger USB Duo for $16.99.

Symantec reports that after infection, the machine begins to listen on port 7777. Valid commands which can be sent to that port are in the form of XOR'ed CLSIDs, with the list being:

• {E2AC5089-3820-43fe-8A4D-A7028FAD8C28}
• {F6C43E1A-1551-4000-A483-C361969AEC41}
• {EA7A2EB7-1E49-4d5f-B4D8-D6645B7440E3}
• {783EACBF-EF8B-498e-A059-F0B5BD12641E}
• {0174D2FC-7CB6-4a22-87C7-7BB72A32F19F}
• {98D958FC-D0A2-4f1c-B841-232AB357E7C8}
• {4F4F0D88-E715-4b1f-B311-61E530C2C8FC}
• {384EBE2C-F9EA-4f6b-94EF-C9D2DA58FD13}
• {8AF1C164-EBD6-4b2b-BC1F-64674E98A710}

US-CERT has released Snort rules for these various detects, which it has named:
Arucer Command Execution
Arucer DIR Listing
Arucer WRITE FILE command
Arucer READ FILE command
Arucer NOP command
Arucer FIND FILE command
Arucer YES command
Arucer ADD RUN ONCE command
Arucer DEL FILE command

which seems to indicate a wide-range of possibilities from this trojan.

Gregg Keizer wrote a nice piece for ComputerWorld on this topic: Energizer Bunny's software infects PCs, which reminds us that in 2007 Seagate shipped trojaned drives, and Apple shipped some trojaned iPods, and that in 2008 Best Buy sold Digital Picture frames with attack code in them.

Thanks to @EdNadrotowicz for the Twitter tip-off on this story...

Friday, March 05, 2010

RSA Keynotes: Howard Schmidt

I've always regretted not attending the RSA conference with more than 500 speakers in 15 different tracks, and perhaps never so much as this year. A special disappointment was not attending the Secure Computing Awards dinner where this year they gave out their first Blogger Awards, including "Most Popular Security Blogger", which was awarded to Gary Warner, author of Cybercrime & Doing Time! Thanks to my friends and readers who voted.

The "Best Corporate Security Blog", went to Proofpoint for their Email Security Blog. The other contenders in my category included two of my favorite security bloggers -- Brian Krebs for his blog Krebs on Security, and fellow spam-researcher Graham Cluley for his Blog at Sophos. Bruce Schneier's Schneier on Security and Securosis rounded out the ballot for Most Popular Security Blogger.

This week I'll be summarizing some of the RSA Keynotes, starting with Howard Schmidt's RSA keynote

Howard Schmidt - U.S. Cybersecurity Coordinator



I was excited when the announcement was made that Howard Schmidt was the new Cybersecurity Coordinator for President Obama, primarily because I've had the chance to see this man's passion for cybersecurity. Howard and I are both InfraGard members, and one of the most impressive times I saw him was in Knoxville, Tennessee where we were back-to-back speakers for the their "October is Cybersecurity Awareness Month" conference. Not only was Howard speaking there, he actually had 40 speaking engagements during the 31 days of the month to address audiences about the importance of Cybersecurity Awareness! I can't think of a more energetic or appropriate person to be in this new position!

Howard began his talk with a discussion of the evolution of cyber security, comparing it to the evolution of fire fighting. He described how after people got tired of watching buildings burn down, we started building them near rivers so we could have a ready source of water to try to put out the fire. Then we had a volunteer fire department that could help prevent things from burning to the ground. We trained them how to put out fires. Later we started looking at how to keep fire's from being so devastating. We came up with "building codes" to make less flammable buildings. Why do we still have anything that can catch on fire in a building? Because we have to. Since we couldn't stop every fire, we put sprinkler systems in buildings. Will things still catch on fire? Sure. But hopefully we'll put them out quickly.

Then he made all the similar cybersecurity comparisons, leading up to his new role in the administration, representing President Obama, and working with Intelligence, Law Enforcement, Defense, and civil agencies to try to build a Secure, Trustworthy, and Resilient computing infrastructure.

In many ways his new job is to respond to the Near Term action items on the Cyber Policy Review completed by Melissa Hathaway. He used most of his talk to provide an update on the ten items:

1. Appoint somebody - (Howard)
2. Update the strategy -
3. Bring private industry into the discussion
- new FISMA performance metrics
- acknowledges that you can be FISMA compliant and not secure
- new guidelines work toward real-time security awareness
4. Appoint privacy & civil liberties person
5. Review legal issues regarding their work
6. Create a national and international security awareness policy
- national awareness (DHS)
- formal cybersecurity education (DOE)
- federal workforce structure (OPM/DOD)
- national workforce training (DHS/DOD/DNI)
7. International cybersecurity policy
8. Cybersecurity Incident Response Plan
9. Develop a framework for Research & Development (NIST, DHS S&T)
10. Cybersecurity based identity management strategy

(the fully described 10 action item "Near Term Action Plan" is given in the 76-page Cyberspace Policy Review final report

He also discussed the "open information" approach of President Obama's administration. I recall attending a briefing by Cornelius Tate in 2008 where he talked about EINSTEIN and the Trusted Internet Connections program for one of the first times publicly. Even then, all he could say about the other ten initiatives of the CNCI was that they were classified.

The Comprehensive National Cybersecurity Initiative (CNCI) has been reclassified so that we at least know what the twelve areas of the CNCI are. (These are now available on WhiteHouse.gov/cybersecurity/ => CNCI (html) or CNCI (pdf))

Wednesday, March 03, 2010

Spamming Botnets - Strategies welcome

Several mailing lists have been buzzing in the aftermath of the recent shutdown attempts against the Waledac network. The results of this shutdown can best be seen by visiting the Waledac tracker run by our friend Jeremy at SudoSecure.

Prior to the action of Microsoft's Digital Crimes Unit in their Operation b49, Waledac was propagating itself with more than 200 Chinese-registered domain names, and was found just in December to have sent more than 651 million emails just to hotmail.com recipients! In response to their action in court, "Microsoft Corporation v. John Does 1-27", the unusual motion was granted to have Verisign terminate the domains in light of the refusal of China Springboard to cooperate. In the days immediately following this action, the final few domain names were terminated, most recently "frostep.com" and "walkali.com".

Waledac was a peer-to-peer / P2P botnet that uses fast-flux hosting of Chinese registered domain names in order to guarantee long-life to itself. Waledac was often called the successor to the Storm botnet because the bots do not communicate directly with the "true" Command & Control, but rather have a "peer list" which they are in constant contact with. Bots make queries either to their hard-coded peers, or by asking one of the bot-controlled domain names for a file, usually a .gif, .jpg, or .png file. Instead of receiving back a graphics file however, they receive back a custom-coded reply which either gives them an instruction, or causes them to update their spam template or receiving email list.

Some excellent research has been performed on Waledac in recent months, including the "Walowdac" research project lead by Thorsten Holz and researchers at the University of Mannheim and the University of Vienna (Ben Stock, Jan Gobel, Markus Engelberth, Felix Freiling). Their custom-crafted Waledac clone was able to fully communicate with the botnet, but did not send spam. They found that Waledac had an average size of 55,000 active bots on any given day (August 6, 2009 - September 1, 2009).

At UAB we had mostly focused on alerting the public of various attempts by the Waledac network to spread itself via email, including:

- 2009 New Years greetings
- Fake coupon offers
- Fake Reuters story about a Terrorist bomb
- an SMS Spy program
- Independence Day Fireworks
- 2009 Christmas / 2010 New Year's cards

What Next?



Unfortunately, while Waledac was at various times in the past year a "Top Ten Spam Botnet", the biggest botnets are orders of magnitude larger and still spamming like crazy.

Michael Kassner and Terry Zink have both been blogging on the current situation. Kassner gave a list of the Top 10 spam botnets: New and Improved over at TechRepublic, largely based on Terry's series Which botnet sends the most spam? over on MSDN in his Anti-malware Blog.

The Top Ten list, from their perspective, includes:

Bot Names# of BotsSpam Per Day
Grum600,00040 billion
Bobax (aka Kraken)100,00027 billion
Pushdo/Cutwail/Pandex?19 billion
Rustock2,000,00017 billion
Bagle/Beagle/Mitglieder500,00014 billion
Mega-D/Ozdok50,00011 billion
Maazben300,0002.5 billion
Xarvester60,0002.5 billion
Donbot100,000800 million
Gheg60,000400 million


Are those numbers "true"? Every security company has a different opinion on the size and strength and spam volume of the various botnets. What I can say is "their estimates are based on sound logic".

One of my personal favorites for sizing spamming botnets is the guys over at M86 Security with their weekly chart called Tracking Spam Botnets. Here's their most recent graphic:



Looking at the historical data over at their website, although we can talk about the Top Ten, Rustock has been the top spamming botnet since at least July, and currently is responsible for 50.7% of all the spam on the planet! I've challenged this over-emphasis on Rustock with their researchers, actually while they were still "Marshal", and as I said above, "their estimates are based on sound logic".

Another of my favorite spam trackers is MessageLabs. These guys produce fantastic intelligence that is quite accessible in their monthly Messagelabs Intelligence Reports. I'll call special attention to their 2009 Annual Security Report which had as a major theme "Botnets Bounce Back with Sharpened Survival Skills".

Strategy?


Those of you have heard me speak in person know that I believe the answer to these botnets and their continued survival must be the Criminal Justice process. When McColo was shut down (see Analyzing the Aftermath of the McColo Shutdown or Brian Krebs' Major Source of Online Scams and Spams Knocked Offline) spam had a significant world-wide drop in volume, but it rebounded. Why? Because no bad guys went to jail.

Our friends at FireEye are doing amazing botnet work (see their blog @ FireEye Malware Intelligence Lab, but without convictions, even the successful botnet takedowns, like their work on Smashing the Mega-D/Ozdok Botnet eventually rebound.

(by the way - FireEye has the best low-down on the Pushdo/Cutwail botnet and its current Command & Control structure.)

Cautions are already being expressed as a result of the Waledac take-down, that by using TECHNOLOGY to do the takedowns instead of CRIMINAL JUSTICE APPROACHES that we are just helping to rapidly evolve the capabilities of the various cyber criminals who make their living through spam.

We have to move from DISABLING the C&C networks, to MONITORING the C&C networks. Bad guys need to stop worrying about having to lease new servers, and start worrying about the long arm of the law knocking at their door. Its why we do what we do the way we do at UAB. Our Computer Forensics Research program partners the Computer & Information Sciences department with the Justice Sciences department, and draws heavily on graduate students and faculty members from both departments to help make a better informed and better equipped cybercrime investigator with the goal of changing the way we fight cybercrime.



Update:

Today Panda Labs released details of the takedown of the Mariposa Botnet. This botnet, run by the DDP Team (Días de Pesadilla Team), had a shocking discovery at the end - TWELVE MILLION IP addresses were making regular contact with the C&C servers! From the article:
On February 3, 2010, the Spanish Civil Guard arrested Netkairo. After the arrest of this 31-year-old Spaniard, police seized computer material that led to the capture of another two Spanish members of the gang: J.P.R., 30, a.k.a. “jonyloleante”, and J.B.R., 25, a.k.a. “ostiator”. Both of them were arrested on February 24, 2010."


The AP also issued a story about the arrests: Authorities bust 3 in infection of 13M computers. Fox News also ran a story, Malicious Botnet Found in 50 of Fortune 100.

Congratulations to the Spanish Civil Guard, Panda Labs, and the other members of the Mariposa Working Group (Defence Intelligence, and the Georgia Tech Information Security Center)

A technical analysis of the Mariposa botnet is available from Defence Intelligence.