Wednesday, April 13, 2011

Bold FBI Move Shutters COREFLOOD Bot

In February 2005, John Leyden told the story of Joe Lopez a 42 year old businessman in Miami Florida who sued his bank after having $90,348 wired out of his account to Parex Bank in Riga, Latvia. The US Secret Service examined his computer and found that his system was infected with the Coreflood trojan.

Where did the money go? According to USA Today's Byron Acohido, someone named Yanson Arnold withdrew $20,000 of the money three days later.

The story was featured on NBC Nightly News on December 14, 2004, in a story called The Fleecing Of America which indicated the money had been stolen via the CoreFlood Virus.

In June of 2008, Joe Stewart, International Grandmaster of Malware Reverse Engineering, released a report called Coreflood/AFcore Trojan Analysis. He started his report by calling attention to five highlights:

1. One of the oldest botnets in continuous operation (+6 years)
2. Motive turned from DDoS to selling anonymity services to full-fledged bank fraud
3. Entire Windows domains infected at once (thousands of computers at some organizations)
4. Over 378,000 computers infected during 16-month time frame
5. Infected businesses, hospitals, government organizations, and even a state police agency

When Joe worked with Spamhaus back then to investigate an active C&C they found FIFTY GIGABYTES of compressed data, stolen over the course of two years, with a MySQL database that the criminal was using to track which information it had stolen from 378,758 unique bots over a period of 16 months. At one point, Joe's report shows "a major hotel chain" with over 7,000 infected computers, and a State Police agency with over 110 infected computers! Among the data stolen were 8,485 bank passwords, 3,233 credit card passwords, 151,000 email passwords, and 58,391 social networking site passwords. At that time, in 2008, the controller domains were: mcupdate.net, joy4host.com, and antrexhost.com.

Here we are in April 2011 -- almost three years later, and "antrexhost.com" is still an active C&C for the domain, which is still stealing money, despite being featured on NBC Nightly News, USA Today, and discussed by name by the White House's Howard Schmidt.

All of that may have come to an end today, as announced by today's FBI Press Release headline was Department of Justice Takes Action to Disable International Botnet. The botnet in question is known as Coreflood, and according to court papers released by the FBI's New Haven Field Office, a pair of Command & Control servers, located at 207.210.74.74 and 74.63.232.233 were controlling 2,336,542 infected computers as of February 2010. Of those, 1,853,005 were located in the United States.

207.210.74.74 is a server on the Global Net Access system, that hosted a domain called jane.unreadmsg.net. vaccina.medinnovation.org was the C&C name on 74.63.232.233


From the request for a Temporary Restraining Order filed by Assistant US Attorney Edward Chang:

12. The Coreflood Botnet was used, among other things,
to commit financial fraud. Infected computers in the Coreflood
Botnet automatically recorded the keystrokes and Internet
communications of unsuspecting users, including online banking
credentials and passwords. The stolen data was then sent to one
or more Coreflood C&C servers, where it was stored for review by
the Defendants and their co-conspirators. The Coreflood C&C
servers also stored the network and operating system
characteristics of the infected computers. The Defendants and
their co-conspirators used the stolen data, including online
banking credentials and passwords, to direct fraudulent wire
transfers from the bank accounts of their victims.

13. The victims of the fraud scheme described above
included, inter alia:

a. A real estate company in Michigan, from whose bank
account there were fraudulent wire transfers made in a
total amount of approximately $115,771;

b. A law firm in South Carolina, from whose bank account
there were fraudulent wire transfers made in a total
amount of approximately $78,421;

c. An investment company in North Carolina, from whose
bank account there were fraudulent wire transfers made
in a total amount of approximately $151,201; and

d. A defense contractor in Tennessee, from whose bank
account there were fraudulent wire transfers attempted
in a total amount of approximately $934,528, resulting
in an actual loss of approximately $241,866.

The full extent of the financial loss caused by the Coreflood
Botnet is not known, due in part to the large number of infected
computers and the quantity of stolen data.



Here are some of the hostnames that were used by Coreflood -- some dates are in the future, indicating that the bot had the ability to change to new names over time, to prevent just the sort of shutdown that occurred today:


C&C SERVER ASSIGNED 207.210.74.74
MonthPrimary Domain Alternate Domain
1/2011 a-gps.vip-studions.net old.antrexhost.com
2/2011 dru.realgoday.net marker.antrexhost.com
3/2011 brew.fishbonetree.biz spamblocker.antrexhost.com
4/2011 jane.unreadmsg.net ads.antrexhost.com
5/2011 exchange.stafilocox.net cafe.antrexhost.com
6/2011 ns1.diplodoger.com coffeeshop.antrexhost.com
7/2011 a-gps.vip-studions.net old.antrexhost.com
8/2011 dru.realgoday.net marker.antrexhost.com
9/2011 brew.fishbonetree.biz spamblocker.antrexhost.com
10/2011 jane.unreadmsg.net ads.antrexhost.com
11/2011 exchange.stafilocox.net cafe.antrexhost.com
12/2011 ns1.diplodoger.com coffeeshop.antrexhost.com

C&C SERVER ASSIGNED 74.63.232.233

Month Primary Domain Alternate Domain
1/2011 taxadvice.ehostville.com taxfree.nethostplus.net
2/2011 ticket.hostnetline.com accounts.nethostplus.net
3/2011 flu.medicalcarenews.org logon.nethostplus.net
4/2011 vaccina.medinnovation.org imap.nethostplus.net
5/2011 ipadnews.netwebplus.net onlinebooking.nethostplus.net
6/2011 acdsee.licensevalidate.net imap.nethostplus.net
7/2011 wellness.hostfields.net pop3.nethostplus.net
8/2011 savupdate.licensevalidate.netschedules.nethostplus.net
9/2011 wiki.hostfields.netmediastream.nethostplus.net
10/2011taxadvice.ehostville.com taxfree.nethostplus.net
11/2011 ticket.hostnetline.com accounts.nethostplus.net
12/2011 flu.medicalcarenews.org logon.nethostplus.net


In addition to the affidavit for the TRO, FBI Special Agent Kenneth Keller got a most unusual Seizure Warrant. With the warrant, they requested that the court compel the Registrars of the 24 domain names posted above to change the DNS settings for the servers, so that they would resolve to SINKHOLE-00.SHADOWSERVER.ORG and SINKHOLE-01.SHADOWSERVER.ORG.

To maximize the difficult of taking down this bot, the criminal spread his domain registrations all over the world. He used Wild West Domains (US-AZ), Above.com (of Australia), Big Rock Solutions (of Mumbai), LiquidNet (UK), Network Solutions (US-Virginia), Active Registrar (SIngapore), 1&1 Internet (Germany), TuCows (Toronto), Dotster (US-Washington), MyDomain, Inc (US-Washington), DomainRegistry.com (US-New Jersey), and Melbourne IT (which is Yahoo!'s registrar of choice), Mesh Digital (UK), Misk.com (US-NY), Moniker (US-Florida), and Directi (India).

Obviously a US court order has little impact in Mumbai or Singapore, so it was important to get this done when the "active" domains were US-based.

A "SinkHole" in the cyber security world is a trick that is invoked to cause botnets who are trying to talk to a criminal server to instead talk to a computer owned by a researcher or investigator. Its a great way for both measuring levels of infection and also for preventing the bad guy from being able to talk to his bots.

In this case, the sinkhole went beyond this though. Here comes the cool part from this Temporary Restraining Order issued by the Honorable (and very smart!) Vanessa L. Bryant.

WHEREAS the Government has shown good cause to believe: (a) that hundreds of thousands of computers are infected by Coreflood, known collectively as the "Coreflood Botnet"; (b) that the computers infected by Coreflood can be remotely controlled by the
Defendants, using certain computer servers known as the "Coreflood C&C Servers" and certain Domains"; (c) that, on or about April 12, 2011, the Government will execute seizure warrants for the Coreflood C&C Servers and the Coreflood Domains; (d) that the Government's seizuer of the Coreflood C&C Servers and the Coreflood Domains will leave the infected computers still running Coreflood; (e) that allowing Coreflood to continue running on the infected computers will cause a continuing and substantial injury to the owners and users of the infected computers, exposing them to a loss of privacy and an increased risk of further computer intrusions; and (f) that it is feasible to stop Coreflood from running on infected computers by establishing a substitute command and control server;

WHEREAS the Coreflood Domains are listed in Schedule A, together with the corresponding registry, registar, and domain name service ("DNS") provider (collectively, the "Domain Service Providers") used by the Defendants with respect to each of the Coreflood Domains;

WHEREAS the Government has shown good cause to believe that: (a) it is reasonably likely that the Government can show that the Defendants are committing wire fraud and bank fraud and are engaging in unauthorized interception of electronic communications, as alleged; (b) it is reasonably likely that the Government can show a continuing and substantial injury to a class of persons, viz., the owners and users of computers infected by Coreflood; and (c) it is reasonably likely that the Government can show that the requested restraining order will prevent or ameliorate injury to that class of persons;

(etc...)

Pursuant to the authority granted by 28 U.S.C. $ 566, the United States Marshal for the District of Connecticut ("USMS") shall execute and enforce this Order, with the assistance of the Federal Bureau of Investigation ("FBI") if needed, by establishing a substitute server at the Internet Systems Consortium...that will respond to requests addressed to the Coreflood DOmains by issuing instructions that will cause the Coreflood software on infected computers to stop running, subject to the limitation that such instructions shall be issued only to computers reasonably determined to be in the United States.


The Restraining Order gave blanket permission for anything that was using the DNS servers "NS1.CYBERWATCHFLOOR.COM" (204.74.66.143) or "NS1.CYBERWATCHFLOOR.COM" (204.74.67.143) to instead point to Special Agent Kenneth Keller's server 149.20.51.124.




Of course, some people may not want the Department of Justice telling their computer what to do. Because of that possibility, the FBI Press Release offers the option:

The Department of Justice and FBI, working with Internet service providers around the country, are committed to identifying and notifying as many innocent victims as possible who have been infected with Coreflood, in order to avoid or minimize future fraud losses and identity theft resulting from Coreflood. Identified owners of infected computers will also be told how to "opt out" from the TRO, if for some reason they want to keep Coreflood running on their computers.

Friday, April 08, 2011

The Epsilon Phishing Model

There is a saying "if you give a man a fish, he'll eat for a day, but if you teach a man to fish, he can feed himself for a lifetime."

In the case of the Epsilon email breach the saying might be "if you teach a man to be phished, he'll be a victim for a lifetime."

In order to illustrate my point, let's look at a few of the security flaws in the business model of email-based marketing, using Epsilon Interactive and their communications as some examples.

NOTE: Epsilon has released another Press Release to assure the public that no Personally Identifiable Information was released. The point of this article is not to argue that point, but rather to say there is something flawed in training users to click on links in emails.

Targeted Mailing Lists Help Avoid Detection



One of the advantages to phishers in using destination email addresses from the Epsilon Breach is that it helps keep their emails out of the hands of the security research and anti-phishing communities. Phishers, especially the less-skilled ones, tend to buy or steal large email address lists. Many researchers and anti-phishers (including us!) have managed to get their "spam-trap" email addresses onto those lists, which gives us visibility to spam campaigns. At UAB, as an example, we receive more than a million spam email messages each day. Some of these emails are phishing emails, which we then share with law enforcement and our strategic partners. Using a combination of automated and manual tools, we review tens of thousands of URLs each day to learn the addresses of the criminals new phishing sites. But what if a phisher only sends his phishing email to "confirmed" customer email addresses? This greatly reduces the ability of the anti-phishing community to respond to these phishing sites.


Guaranteed Delivery "From:" Addresses



Another thing a phisher would like to accomplish is to make sure that his message arrives without being blocked. Perhaps his victim is running spam filtering software. What is the first things that would be desirable? He would like his email to be sent from an address that will guarantee delivery. The easiest way to make sure that spam is delivered is to make sure that the "From:" address is in the potential victim's address book. This is why so many email messages arrive with the "from" and "to" addresses being the same. The spammers assume that you will have your own address in your address book, and therefore spam-filtering rules will not be applied to that address.

How else could they do that? Epsilon helpfully instructs their customers to add their email addresses to their address book. If a phisher now imitates those addresses, their email will bypass many phishing filters:



This email was sent to you by Ethan Allen.
Please add ethanallenstyle@email.ethanallen.com to your address book. This will ensure delivery to your inbox.


You are receiving this e-mail because you have requested information about CRESTOR(R) (rosuvastatin calcium) Tablets. Add CRESTOR@email.CRESTOR.com to your address book so future e-mails from us will not be marked as spam.


Add citicards@info.citibank.com to your address book to ensure delivery.


To ensure delivery to your inbox, please add Walgreens@email.walgreens.com to your address book.


This e-mail was sent to you by Eddie Bauer Friends. To ensure delivery to your inbox (not junk or bulk), please add info@eddiebauerfriends.com to your address book.


To ensure receipt of your Red Roof RediCard emails, please add redicard@redroofinn.bfi0.com to your address book.


To ensure receipt of our emails, please add targetdailydeals@targetnewsletter.bfio.com to your Contacts or Address Book.


etc . . .

So if the phisher makes his "from" address one of these "trusted" addresses, what happens?

Teach a man (or woman) to Click



One of the main pieces of advice that security professionals give to audiences and readers when they are speaking or writing about the topic of phishing is DO NOT CLICK ON LINKS IN YOUR EMAIL!

This is exactly the opposite advice that customers in the Epsilon databases receive. Epsilon and other email senders work on the theory of full-visibility communications. They know which email messages they send to which users, and they prove their value to the companies they represent by providing deep intelligence on the "click behavior" of the customers they email on behalf of those companies. Each link in an Epsilon email is customized with a URL that tells Epsilon who clicked on the link.

The whole point of emails from Epsilon is to get customers to click on links! I've truncated the URLs to protect privacy, but here's an example of one from Target. Clicking on this one takes me to their "Daily Deals. One Day Only. Always Free Shipping."

http://target.bfi0.com/145d56598layfousibljoi2iaaaaaaq5mirqsi2bcpuyaaaaa/C?V=bF9pbmRleAEBcHJvZmlsZV9pZAExMTM1MzYzMTY5AXppcF9jb2RlAQFfV0FWRV9JRF8BNjEwODA0MzQ5AV9QTElTVF9JRF8BMjE1NDI2MjUBZ19pbmRleAEBZW1haWxfYWRkcgFnYXJAYXNrZ2FyLmNvbQFfU0NIRF9UTV8BMjAxMTA0MDMxMjAwMDABcHJvZmlsZV9rZXkBMjU4NTkyMDM%3D&k2hXe6YFbcPUoDxGzFz1FA

which means I can get "juniors" denim skinny jeans for $12.49 today only! (which also means my daughter probably gave my email account to Target....hmmmm.....)

Here's a few examples:



Greetings from the National Geographic Online Store!

You are invited to join an exclusive community of individuals interested in National Geographic. As a member, you will...
* Help us choose catalog covers.
* Get sneak peeks at new products we=92re considering.
* Give valuable advice to people at National Geographic who decide what products we should offer.
* Get an insider=92s view of how our catalog and online store help fund the Society's Mission programs in the areas of research,

conservation, exploration, and education.

Click here to join the NG Store Insider panel. http://newsletters.nationalgeographic.com/1####....



Now through April 10, 2011

$50 OFF YOUR PURCHASE OF $250 OR MORE*
ENTER CODE > =

Txx3-4xxxxx-xx3xx2

HAUTE SALE
HURRY, ENDS TODAY!
40% OFF select styles. In-store & online.

http://bebeonline.bebe.com/#####...


Introducing the NY DEAL of the DAY! Extra savings on a must have style! In stores & online. Today only! The Hudson wide leg pant,
only $14.99 today only! Check our homepage every day of this sale for our new DEAL!

Shop now >
http://email.nyandcompany.com/1####...



Today Only! Save 30% at Gap Outlet

To get this coupon, copy and paste this url:
http://mail.goAAA.com/1#####...


------------------------
DAILY DEALS. ALWAYS FREE SHIPPING.
------------------------

Fun, cool stuff at amazing prices, available for one day only.


Shop Now:
http://targetenewsletter.bfi0.com/####...


BBC AMERICA NEWSLETTER
Doctor Who in America for the Very First Time
April 6, 2011
Doctor Who: Brand New Season
The Tardis is hopping the pond and the stakes have never been higher. =

WATCH THE EXTENDED TRAILER
http://bbcamerica.bfi0.com/1####...


The statement for your account ending in 4616 is now available online.
Log in to Online Banking to view your statement and pay your bill.
Please visit
http://email.capitalone.com/1####...



The point of every one of those emails is HEY YOU! CLICK ON THIS LINK!!!


The Warnings & The Future



If you live in the United States and you have ever used a credit card, your inbox is already flooded with Epsilon notices, so I hesitate to show you very many. We've heard of warnings from more than fifty companies, and personally seen the warnings from at least:

1-800-Flowers begin_of_the_skype_highlighting              1-800-Flowers      end_of_the_skype_highlighting
Abe Books
AIR MILES Reward Program
Ameriprise Financial
Barclays Bank of Delaware (US Airways Dividend Miles MasterCard, DIRECTV Rewards, iTunes Rewards, LLBean etc... )
Beachbody
Brookstone
Capital One
Citibank (AT&T Universal Card, Exxon Mobile, Home Depot, Shell)
Disney Destinations
Eddie Bauer
Ethan Allen
Hilton Honors
Krogers
Lacoste USA
Marriott
McKinsey Quarterly
M&T Bank
New York & Company
Red Roof Inn
Soccer.com
Target
Tastefully Simple
TD Ameritrade
TIAA-CREF
Tivo
Verizon
World Financial Network National Bank (WFNNB) (Ann Taylor, Catherine's, Chadwick's, Eddie Bauer, Gander Mountain, HSN, Maurice's, Newport News, Peeble's, The RoomPlace, United Retail Group, Victoria's Secret, Woman Within)
Walgreens

The warnings are missing the point of MY warning. All of them assure you that they aren't going to ask you for your personal information, and that your personal information hasn't been lost, "only your email address."

They tell you though NOT TO OPEN EMAILS FROM PEOPLE YOU DON'T KNOW. I don't know anyone named "shellcreditcard@info.accountonline.com" and I certainly don't know anyone named "TargetNews@target.bfio.com"



Of course that also misses entirely the fact that ANYONE can make their "From:" email anything they would like it to be! Email is not a form of trusted communication! So, how does the end-user know that the email really came from a real sender? Its a growing problem. Certain vendors have had luck with certain large mail providers -- for example eBay and Gmail. Because eBay signs all of their outbound email with a "digital signature" and Gmail knows what digital signature eBay uses, Gmail will reject any email that claims to be from eBay but really isn't.

There is a whole association, The Online Trust Alliance, filled with great companies dedicated to trying to fix this problem, but where they stand right now is that acceptance has been limited, and "traditional" email solutions don't come out of the box with the ability to interact richly with these forms of signatures and authentications.

Imagine for example that you are a global brand with more than 500,000 employees. In order to "turn on" digital authentication, you have to make sure that every single email sent by any of your 500,000 employees has a valid "digital signature" that proves the email really came from you! On the other end of the spectrum, if everyone locks down their email clients to only allow emails that are signed and certified, emails from individuals like you and me are likely to be thrown away!

In the meantime, we're stuck with imperfect solutions -- the need of the corporation to get their messages delivered and clicked on -- and the need of the consumer to NOT CLICK on messages that may lead to malware infections.

One-Click Malware - Drive-By Infections



Kaspersky Labs had a recent headline on this topic: Malware in February: Cybercriminals Perfect Drive-By Tactics.

In most of the top reported malware for February, the infection method was to convince a user to click on a link which took them to a "poisoned" webpage -- one on which some hostile code was present that could take advantage of security flaws in the webpage visitor's browser, PDF reader, flash player, or other code to place malware on the visitor's computer. Kasperky's February Report showed more than 70 million times where a Kaspersky customer had tried to visit a website that would have infected their computer if they had not been blocked!

The Warnings in the Epsilon Breaches can't warn you of that though. If they gave you the advice I would give you, they would be saying "Please don't click on the things our marketing department sends you!" which would result in them losing their jobs.

I have to say that the Citibank group of warnings do have a form that I appreciate.



As a means of proving email is REALLY from them, they provide the final four digits of your account number, your name, and the year you joined their card program on all of their official emails. I have to say that I find this very effective.

Unfortunately, yet another problem at Bigfoot/Epsilon ruined my joy on this one for today:



The error tells me "Secure Connection Failed" "images.bigfootinteractive.com:443 uses an invalid security certificate ... This could be a problem with the server's configuration or it could be someone trying to impersonate the server."




It's probably just something wrong as they try to re-issue security certificates related to tightening up their shop, but still it sends the wrong message at a critical time for their company!

Saturday, March 26, 2011

Kingpin by Kevin Poulson of WIRED

I love to read, but it's been quite a long time since I had one of those "books I can't put down" evenings. Tonight was one of those nights. I had been delaying the start of reading "KINGPIN: How one hacker took over the billion-dollar cybercrime underground" not because I thought it would be a book I couldn't put down, but because honestly, I thought I knew the story already.

If you were interested in the hacking scene around the turn of the millenium, you would definitely know the name Max Butler. Max made a name for himself in the IDS world, helping with the earliest days of Snort, and running a database for IDS signatures called arachnIDS. I remember when Max went to jail the first time, chatting with my friend Dan Clemens of PacketNinjas, LLC, who was also into IDS systems and snort in a heavy way, about the arrest. It was troubling to see someone running a website called "WhiteHats.com" and ending up in jail. The version of the story I thought I knew was that Max had been asked by the Feds to help them patch their systems from the BIND bug that was so popular in 1998-1999, but that Max couldn't resist the urge to
put a back door into the patch.

White Hat Hacker in Court - April 13, 2000 - "Open source hacker "Max Vision" aided the FBI while allegedly cracking the Pentagon."

Max Vision: FBI Pawn? - May 8, 2001 - "FBI agents called him 'the Equalizer': a security expert and confessed hacker who infiltrated the electronic underground to help the Bureau. When he drew the line at bugging a friend, they threw the book at him."

Max Vision Begins 18-Month Term - July 5, 2001 - "Intrusion detection guru joins a growing hacker population in federal stir."

All of those stories are by Kevin Poulsen, who has "owned" this story from the very beginning.

The popular theory at the time was that Max had been sent to DefCon and was only charged with his crimes after refusing to be a snitch for the Feds at DefCon. See for instance this conversation thread from 2001, Max Butler AKA Max Vision-Iceman-Aphex Now Retired.

I've spoken to investigators at extremely large companies who actually used Max Butler to test the security of their systems as a Penetration Tester, only learning later that he was actually stealing from them at the same time!

In addition to remembering the story very well from the "old days," I also know the story as a friend of the NCFTA who has had the chance to meet and work with FBI Special Agent Keith Mularski. Keith's work, announced by the FBI in their October 20, 2008 press release, 'Dark Market' Takedown -- Exclusive Cyber Club for Crooks Exposed lead to the arrest of more than 50 cyber criminals who were in the credit card stealing and trading business. (More details on DarkMarket arrests are available from WIRED: Dark Market ring leader pleads guilty in London.

Like the more recent arrest of Albert Gonzales AKA Segvec Max has a long story of helping the Feds and working against them at the same time. Gonzales was a US Secret Service informant against the ShadowCrew, while simultaneously breaching the Heartland Payments systems, TJX, and many other places.

The difference though, was that while Gonzales was a two-timing crook who was playing the system, Max started off as a troubled soul who wanted desperately to be the hero, but couldn't resist the thrill of the hack.

Like I said, I thought I already knew the story. Reading Kevin's book brought out so many details I couldn't possibly have known though. Kevin did a great job getting into the early life of the characters, and exploring the formation of their personalities and motivations. As Kevin reels out the lives of the characters, its clear to see that there were several types of criminals in the stories. His ability to create a sympathetic protagonist out of a criminal who caused $80 Million in credit card fraud is a feat in itself.

This book belongs on the shelf next to Steven Levy's Hackers. If you haven't read it yet, pick a rainy Saturday and start early in the day, you aren't going to be able to stop until you get to the last page.


Order Kingpin from Amazon


Be sure to read more stories by Kevin at WIRED by following his Author Page at Threat Level and elsewhere.

Monday, March 14, 2011

Federal Reserve Spam

Last week the big malware-spreading spam claimed to be from NACHA and warned about problems with an ACH money transfer. The same bad guys are at it again, this week pretending to be the Federal Reserve bank.

The UAB Spam Data Mine has received more than 3500 copies of the spam email messages, primarily using the subject lines:

Wire Transfer #12976271232523 (a random number on each email)
Wire transfer 0430972006146 was canceled (a random number on each email)
Wire transfer was canceled
Wire transfer was rejected
Your Wire fund transfer
Your Wire Transfer
Your Wire Transfer #2491786220489 (a random number on each email)
Your Wire Transfer, ID544349843700 (a random number on each email)

The senders of the email message varied between one of five choices:

alert@federalreserve.gov
alerts@federalreserve.gov
fedwire@federalreserve.gov
info@federalreserve.gov
information@federalreserve.gov

As before, someone with a Yahoo email address had their account used on GoDaddy to register ".info" domains to be used in this campaign. This time, we have spam samples for 487 of them.

Both GoDaddy and Afilias have excellent abuse staffs, and the domains in question were quickly terminated.

count | machine
-------+----------------------------------
8 | A-WIREBLOG.INFO
8 | AWIRE.INFO
5 | A-WIRENOW.INFO
6 | A-WIREONLINE.INFO
11 | A-WIRESHOP.INFO
4 | A-WIRESITE.INFO
7 | A-WIRESTORE.INFO
8 | A-WIRETODAY.INFO
4 | BESTA-WIRE.INFO
10 | BESTD-WIRE.INFO
9 | BESTFEDERALWIRE.INFO
6 | BESTFEDWIRE-B.INFO
2 | BESTFEDWIRE-E.INFO
8 | BESTFEDWIRE-M.INFO
8 | BESTFEDWIRE-N.INFO
9 | BESTFEDWIRE-O.INFO
5 | BESTFEDWIRE-Q.INFO
10 | BESTFEDWIRE-R.INFO
4 | BESTFEDWIRE-T.INFO
14 | BESTFEDWIRE-U.INFO
7 | BESTFEDWIRE-Y.INFO
9 | BESTI-WIRE.INFO
5 | BESTP-WIRE.INFO
6 | BESTU-WIRE.INFO
8 | BESTWIREORGANISATION.INFO
4 | BESTWIREREPORTTRANSFER.INFO
5 | BESTWIRETRANSFERMONEY.INFO
6 | BESTX-WIRE.INFO
4 | BESTZ-ACH.INFO
7 | BESTZ-WIRE.INFO
11 | COPPER-WIRE-ORGANISATION.INFO
6 | COPPERWIREORGANISATION.INFO
8 | COPPER-WIRE-REPORT-TRANSFER.INFO
8 | COPPERWIREREPORTTRANSFER.INFO
5 | COPPERWIRETRANSFERMONEY.INFO
3 | CUSTOMWIREORGANISATION.INFO
13 | D-WIREBLOG.INFO
7 | DWIRECABLE.INFO
10 | DWIRECLOTH.INFO
10 | DWIREDIAMETER.INFO
8 | D-WIRE-FENCE.INFO
5 | DWIREFENCE.INFO
8 | DWIREFORMING.INFO
5 | D-WIRE.INFO
7 | DWIREMANUFACTURER.INFO
12 | D-WIRENOW.INFO
7 | D-WIREONLINE.INFO
3 | DWIRESHELF.INFO
9 | D-WIRESHOP.INFO
11 | D-WIRES.INFO
9 | D-WIRESITE.INFO
10 | D-WIRESTORE.INFO
9 | DWIRESUPPLIERS.INFO
6 | DWIRETECH.INFO
8 | D-WIRETODAY.INFO
7 | ELECTRICALWIRETRANSFERMONEY.INFO
9 | FEDERALWIREBLOG.INFO
8 | FEDERALWIRECABLE.INFO
7 | FEDERALWIRECLOTH.INFO
8 | FEDERALWIREDIAMETER.INFO
8 | FEDERAL-WIRE-FENCE.INFO
6 | FEDERALWIREFENCE.INFO
9 | FEDERALWIREFORMING.INFO
9 | FEDERAL-WIRE.INFO
6 | FEDERALWIRE.INFO
7 | FEDERALWIRENOW.INFO
5 | FEDERALWIREONLINE.INFO
6 | FEDERALWIRESHELF.INFO
6 | FEDERALWIRESHOP.INFO
6 | FEDERALWIRES.INFO
5 | FEDERALWIRESITE.INFO
8 | FEDERALWIRESIZES.INFO
8 | FEDERALWIRESTORE.INFO
9 | FEDERALWIRETECH.INFO
9 | FEDERALWIRETODAY.INFO
8 | FEDWIREANDBLUE.INFO
8 | FEDWIREANDSAVE.INFO
8 | FEDWIREANDSILVER.INFO
4 | FEDWIREANDSONS.INFO
12 | FEDWIREANDSOUL.INFO
2 | FEDWIREANDSTYLE.INFO
7 | FEDWIREANDTRAVEL.INFO
10 | FEDWIRE-BBLOG.INFO
8 | FEDWIRE-BE-CONNECTED.INFO
6 | FEDWIREBECONNECTED.INFO
10 | FEDWIRE-BE-COOL.INFO
7 | FEDWIREBECOOL.INFO
11 | FEDWIRE-BE.INFO
10 | FEDWIREBE.INFO
7 | FEDWIRE-B.INFO
8 | FEDWIREB.INFO
6 | FEDWIRE-BNOW.INFO
7 | FEDWIRE-BONLINE.INFO
8 | FEDWIRE-B-RICH.INFO
7 | FEDWIREBRICH.INFO
7 | FEDWIRE-BSHOP.INFO
3 | FEDWIRE-BS.INFO
7 | FEDWIRE-BSITE.INFO
6 | FEDWIRE-BSTORE.INFO
8 | FEDWIRE-BTODAY.INFO
5 | FEDWIRE-EBLOG.INFO
6 | FEDWIRE-E.INFO
8 | FEDWIREE.INFO
5 | FEDWIRE-E-MINOR.INFO
7 | FEDWIREEMINOR.INFO
6 | FEDWIRE-ENOW.INFO
9 | FEDWIRE-EONLINE.INFO
4 | FEDWIRE-ESHOP.INFO
9 | FEDWIRE-ES.INFO
10 | FEDWIRE-ESITE.INFO
5 | FEDWIRE-ESTORE.INFO
4 | FEDWIRE-ETODAY.INFO
11 | FEDWIRE-M-BASKETBALL.INFO
6 | FEDWIREMBASKETBALL.INFO
10 | FEDWIRE-MBLOG.INFO
4 | FEDWIRE-M.INFO
12 | FEDWIREM.INFO
13 | FEDWIRE-MNOW.INFO
4 | FEDWIRE-MONLINE.INFO
7 | FEDWIRE-MSHOP.INFO
3 | FEDWIRE-MS.INFO
3 | FEDWIRE-MSITE.INFO
3 | FEDWIRE-MSTORE.INFO
12 | FEDWIRE-MTODAY.INFO
6 | FEDWIRE-M-WARD.INFO
7 | FEDWIREMWARD.INFO
12 | FEDWIRE-NBLOG.INFO
9 | FEDWIRE-N.INFO
3 | FEDWIREN.INFO
5 | FEDWIRE-NNOW.INFO
4 | FEDWIRE-NONLINE.INFO
4 | FEDWIRE-N-SCALE.INFO
16 | FEDWIRENSCALE.INFO
6 | FEDWIRE-NSHOP.INFO
3 | FEDWIRE-NS.INFO
5 | FEDWIRE-NSITE.INFO
4 | FEDWIRE-NSTORE.INFO
11 | FEDWIRE-NTODAY.INFO
6 | FEDWIRE-OBLOG.INFO
5 | FEDWIRE-O-HENRY.INFO
7 | FEDWIREOHENRY.INFO
8 | FEDWIRE-O.INFO
5 | FEDWIREO.INFO
6 | FEDWIRE-ONOW.INFO
13 | FEDWIRE-OONLINE.INFO
11 | FEDWIRE-OSHOP.INFO
9 | FEDWIRE-OS.INFO
11 | FEDWIRE-OSITE.INFO
4 | FEDWIRE-OSTORE.INFO
8 | FEDWIRE-O-TICKET.INFO
5 | FEDWIREOTICKET.INFO
7 | FEDWIRE-OTODAY.INFO
9 | FEDWIRE-Q-AUDIO.INFO
5 | FEDWIREQAUDIO.INFO
9 | FEDWIRE-Q-AWARDS.INFO
10 | FEDWIREQAWARDS.INFO
7 | FEDWIRE-QBLOG.INFO
9 | FEDWIRE-Q-CELL.INFO
5 | FEDWIREQCELL.INFO
9 | FEDWIRE-Q-FEVER.INFO
9 | FEDWIREQFEVER.INFO
6 | FEDWIRE-Q.INFO
5 | FEDWIRE-Q-MAGAZINE.INFO
6 | FEDWIREQMAGAZINE.INFO
8 | FEDWIRE-QNOW.INFO
5 | FEDWIRE-QONLINE.INFO
8 | FEDWIRE-QSHOP.INFO
9 | FEDWIRE-QS.INFO
5 | FEDWIRE-QSITE.INFO
6 | FEDWIRE-QSTORE.INFO
12 | FEDWIRE-QTODAY.INFO
5 | FEDWIRE-RBLOG.INFO
5 | FEDWIRE-R.INFO
5 | FEDWIRER.INFO
8 | FEDWIRE-R-KELLY.INFO
3 | FEDWIRERKELLY.INFO
13 | FEDWIRE-RNOW.INFO
7 | FEDWIRE-RONLINE.INFO
3 | FEDWIRE-RSHOP.INFO
11 | FEDWIRE-RS.INFO
7 | FEDWIRE-RSITE.INFO
8 | FEDWIRE-RSTORE.INFO
5 | FEDWIRE-RTODAY.INFO
7 | FEDWIRE-TBLOG.INFO
6 | FEDWIRE-T-CELLS.INFO
12 | FEDWIRETCELLS.INFO
7 | FEDWIRE-T.INFO
9 | FEDWIRET.INFO
8 | FEDWIRE-T-MAGAZINE.INFO
6 | FEDWIRETMAGAZINE.INFO
4 | FEDWIRE-TNOW.INFO
9 | FEDWIRE-TONLINE.INFO
6 | FEDWIRE-T-PAIN.INFO
8 | FEDWIRETPAIN.INFO
8 | FEDWIRE-TSHOP.INFO
6 | FEDWIRE-TS.INFO
5 | FEDWIRE-TSITE.INFO
5 | FEDWIRE-TSTORE.INFO
14 | FEDWIRE-TTODAY.INFO
4 | FEDWIRE-UBLOG.INFO
11 | FEDWIRE-U.INFO
9 | FEDWIREU.INFO
12 | FEDWIRE-UNOW.INFO
12 | FEDWIRE-UONLINE.INFO
10 | FEDWIRE-USHOP.INFO
10 | FEDWIRE-US.INFO
5 | FEDWIRE-USITE.INFO
10 | FEDWIRE-USTORE.INFO
3 | FEDWIRE-UTODAY.INFO
7 | FEDWIRE-YBLOG.INFO
6 | FEDWIRE-Y-CAMP.INFO
7 | FEDWIREYCAMP.INFO
10 | FEDWIRE-Y.INFO
9 | FEDWIREY.INFO
6 | FEDWIRE-YNOW.INFO
7 | FEDWIRE-YONLINE.INFO
7 | FEDWIRE-YOU-CANT.INFO
8 | FEDWIREYOUCANT.INFO
6 | FEDWIRE-YOU.INFO
9 | FEDWIREYOU.INFO
9 | FEDWIRE-YOU-ROCK.INFO
10 | FEDWIREYOUROCK.INFO
2 | FEDWIRE-YOU-SAVE.INFO
4 | FEDWIREYOUSAVE.INFO
12 | FEDWIREYOUTUBE.INFO
5 | FEDWIRE-YSHOP.INFO
5 | FEDWIRE-YS.INFO
7 | FEDWIRE-YSITE.INFO
7 | FEDWIRE-YSTORE.INFO
8 | FEDWIRE-YTODAY.INFO
4 | FREEA-WIRE.INFO
7 | FREED-WIRE.INFO
9 | FREEFEDERALWIRE.INFO
8 | FREEFEDWIRE-B.INFO
7 | FREEFEDWIRE-E.INFO
9 | FREEFEDWIRE-M.INFO
5 | FREEFEDWIRE-N.INFO
7 | FREEFEDWIRE-O.INFO
2 | FREEFEDWIRE-Q.INFO
5 | FREEFEDWIRE-R.INFO
8 | FREEFEDWIRE-T.INFO
13 | FREEFEDWIRE-U.INFO
14 | FREEFEDWIRE-Y.INFO
7 | FREEI-WIRE.INFO
5 | FREEP-WIRE.INFO
8 | FREEU-WIRE.INFO
5 | FREEWIREORGANISATION.INFO
9 | FREEWIREREPORTTRANSFER.INFO
4 | FREEWIRETRANSFERMONEY.INFO
8 | FREEX-WIRE.INFO
7 | FREEZ-ACH.INFO
6 | FREEZ-WIRE.INFO
5 | GAUGEWIREORGANISATION.INFO
5 | GAUGEWIRETRANSFERMONEY.INFO
7 | I-MOBILE-WIRE.INFO
8 | IMOBILEWIRE.INFO
5 | IRONWIREORGANISATION.INFO
5 | IRONWIREREPORTTRANSFER.INFO
7 | IRONWIRETRANSFERMONEY.INFO
6 | I-WIREBLOG.INFO
10 | IWIREHOMES.INFO
8 | I-WIRE.INFO
7 | I-WIRE-INTERACTIVE.INFO
5 | IWIREINTERACTIVE.INFO
10 | IWIRENETWORKS.INFO
10 | I-WIRENOW.INFO
11 | I-WIREONLINE.INFO
7 | I-WIRESHOP.INFO
2 | I-WIRES.INFO
7 | I-WIRESITE.INFO
8 | I-WIRESTORE.INFO
14 | I-WIRE-TECH.INFO
5 | IWIRETECH.INFO
11 | I-WIRETODAY.INFO
7 | METALWIREORGANISATION.INFO
6 | METALWIREREPORTTRANSFER.INFO
6 | METALWIRETRANSFERMONEY.INFO
6 | MYA-WIRE.INFO
3 | MYD-WIRE.INFO
8 | MYFEDERALWIRE.INFO
12 | MYFEDWIRE-B.INFO
5 | MYFEDWIRE-E.INFO
13 | MYFEDWIRE-M.INFO
8 | MYFEDWIRE-N.INFO
10 | MYFEDWIRE-O.INFO
4 | MYFEDWIRE-Q.INFO
11 | MYFEDWIRE-R.INFO
11 | MYFEDWIRE-T.INFO
10 | MYFEDWIRE-U.INFO
11 | MYFEDWIRE-Y.INFO
7 | MYI-WIRE.INFO
6 | MYP-WIRE.INFO
5 | MYU-WIRE.INFO
12 | MYWIREORGANISATION.INFO
7 | MYWIREREPORTTRANSFER.INFO
9 | MYWIRETRANSFERMONEY.INFO
5 | MYX-WIRE.INFO
9 | MYZ-ACH.INFO
7 | MYZ-WIRE.INFO
4 | NEWA-WIRE.INFO
6 | NEWD-WIRE.INFO
5 | NEWFEDERALWIRE.INFO
12 | NEWFEDWIRE-B.INFO
5 | NEWFEDWIRE-E.INFO
12 | NEWFEDWIRE-M.INFO
7 | NEWFEDWIRE-N.INFO
7 | NEWFEDWIRE-O.INFO
8 | NEWFEDWIRE-Q.INFO
10 | NEWFEDWIRE-R.INFO
5 | NEWFEDWIRE-T.INFO
11 | NEWFEDWIRE-U.INFO
5 | NEWFEDWIRE-Y.INFO
6 | NEWI-WIRE.INFO
7 | NEWP-WIRE.INFO
18 | NEWU-WIRE.INFO
12 | NEWWIREORGANISATION.INFO
9 | NEWWIREREPORTTRANSFER.INFO
8 | NEWWIRETRANSFERMONEY.INFO
3 | NEWX-WIRE.INFO
6 | NEWZ-ACH.INFO
10 | NEWZ-WIRE.INFO
11 | PRECISIONWIREORGANISATION.INFO
3 | P-WIREBLOG.INFO
10 | PWIRECABLE.INFO
8 | PWIRECLOTH.INFO
4 | PWIREDIAMETER.INFO
8 | P-WIRE-FENCE.INFO
3 | PWIREFENCE.INFO
7 | PWIREFORMING.INFO
2 | P-WIRE.INFO
11 | PWIRE.INFO
9 | PWIREMANUFACTURER.INFO
8 | P-WIRENOW.INFO
9 | P-WIREONLINE.INFO
7 | PWIRESHELF.INFO
6 | P-WIRESHOP.INFO
7 | P-WIRES.INFO
12 | P-WIRESITE.INFO
7 | P-WIRESTORE.INFO
6 | PWIRESUPPLIERS.INFO
4 | P-WIRETODAY.INFO
6 | RESISTANCEWIRETRANSFERMONEY.INFO
7 | RIDINGTHEWIRE.INFO
12 | ROME-X-WIRE.INFO
9 | SILVERWIRETRANSFERMONEY.INFO
10 | SPOT-I-WIRE.INFO
11 | SPOTIWIRE.INFO
4 | STEEL-WIRE-ORGANISATION.INFO
9 | STEELWIREORGANISATION.INFO
3 | STEEL-WIRE-REPORT-TRANSFER.INFO
9 | STEELWIREREPORTTRANSFER.INFO
5 | STEELWIRETRANSFERMONEY.INFO
7 | THEA-WIRE.INFO
7 | THEDETROITWIRE.INFO
7 | THED-WIRE.INFO
3 | THEFEDERALWIRE.INFO
11 | THEFEDWIRE-B.INFO
5 | THEFEDWIRE-E.INFO
8 | THEFEDWIRE-M.INFO
7 | THEFEDWIRE-N.INFO
5 | THEFEDWIRE-O.INFO
7 | THEFEDWIRE-Q.INFO
6 | THEFEDWIRE-R.INFO
9 | THEFEDWIRE-T.INFO
3 | THEFEDWIRE-U.INFO
12 | THEFEDWIRE-Y.INFO
9 | THEI-WIRE.INFO
7 | THEP-WIRE.INFO
4 | THERIDEWIRE.INFO
2 | THEU-WIRE.INFO
11 | THEWIREDOGS.INFO
6 | THEWIREGUYS.INFO
6 | THE-WIRE.INFO
5 | THEWIREORGANISATION.INFO
14 | THEWIREREPORTTRANSFER.INFO
1 | THEWIRETRANSFERMONEY.INFO
10 | THEX-WIRE.INFO
10 | THEZ-ACH.INFO
6 | THEZ-WIRE.INFO
6 | TRAVEL-A-WIRE.INFO
10 | TRAVELAWIRE.INFO
12 | U-WIREBLOG.INFO
7 | UWIRECABLE.INFO
11 | UWIRECLOTH.INFO
9 | UWIREDIAMETER.INFO
7 | U-WIRE-FENCE.INFO
9 | UWIREFENCE.INFO
9 | UWIREFORMING.INFO
9 | U-WIRE.INFO
9 | UWIREMANUFACTURER.INFO
4 | U-WIRENOW.INFO
8 | U-WIREONLINE.INFO
9 | UWIRESHELF.INFO
7 | U-WIRESHOP.INFO
8 | U-WIRES.INFO
8 | U-WIRESITE.INFO
8 | U-WIRESTORE.INFO
5 | UWIRESUPPLIERS.INFO
6 | UWIRETECH.INFO
3 | U-WIRETODAY.INFO
6 | WALKINGTHEWIRE.INFO
12 | WIREORGANISATIONBLOG.INFO
10 | WIRE-ORGANISATION.INFO
5 | WIREORGANISATION.INFO
5 | WIREORGANISATIONNOW.INFO
9 | WIREORGANISATIONONLINE.INFO
6 | WIREORGANISATIONSHOP.INFO
5 | WIREORGANISATIONS.INFO
3 | WIREORGANISATIONSITE.INFO
9 | WIREORGANISATIONSTORE.INFO
6 | WIREORGANISATIONTODAY.INFO
7 | WIREREPORTCARDSTRANSFER.INFO
6 | WIRE-REPORT-CARD-TRANSFER.INFO
7 | WIREREPORTCARDTRANSFER.INFO
4 | WIREREPORTTRANSFERBLOG.INFO
11 | WIRE-REPORT-TRANSFER.INFO
6 | WIREREPORTTRANSFER.INFO
4 | WIREREPORTTRANSFERNOW.INFO
6 | WIREREPORTTRANSFERONLINE.INFO
4 | WIREREPORTTRANSFERSHOP.INFO
10 | WIREREPORTTRANSFERS.INFO
6 | WIREREPORTTRANSFERSITE.INFO
2 | WIREREPORTTRANSFERSTORE.INFO
7 | WIREREPORTTRANSFERTODAY.INFO
5 | WIRETRANSFERMONEYBLOG.INFO
13 | WIRE-TRANSFER-MONEY.INFO
7 | WIRETRANSFERMONEY.INFO
7 | WIRETRANSFERMONEYNOW.INFO
7 | WIRETRANSFERMONEYONLINE.INFO
7 | WIRETRANSFERMONEYSHOP.INFO
9 | WIRETRANSFERMONEYS.INFO
6 | WIRETRANSFERMONEYSITE.INFO
10 | WIRETRANSFERMONEYSTORE.INFO
1 | WIRETRANSFERMONEYTODAY.INFO
7 | WIRETRANSFERSTATIONMONEY.INFO
3 | X-CABLE.INFO
4 | XCIRCUITBOARDS.INFO
6 | X-CIRCUIT.INFO
7 | XCIRCUIT.INFO
5 | X-CONNECTION.INFO
6 | XELECTRICALCONDUCTOR.INFO
6 | X-FILAMENT.INFO
7 | XFILAMENT.INFO
8 | X-WIREBLOG.INFO
6 | XWIRE.INFO
10 | X-WIRENOW.INFO
11 | X-WIREONLINE.INFO
8 | X-WIRESHOP.INFO
3 | X-WIRES.INFO
2 | X-WIRESITE.INFO
6 | X-WIRESTORE.INFO
2 | X-WIRETODAY.INFO
13 | Z-ACH-ACCOUNTS.INFO
5 | ZACHACCOUNTS.INFO
10 | Z-ACHBLOG.INFO
8 | Z-ACH.INFO
9 | Z-ACHNOW.INFO
16 | Z-ACHONLINE.INFO
6 | Z-ACH-PAYMENT.INFO
10 | ZACHPAYMENT.INFO
5 | Z-ACH-PAYMENTS.INFO
6 | ZACHPAYMENTS.INFO
5 | Z-ACHSHOP.INFO
4 | Z-ACHS.INFO
8 | Z-ACHSITE.INFO
6 | Z-ACHSTORE.INFO
4 | Z-ACHTODAY.INFO
4 | Z-ACH-TRANSACTIONS.INFO
10 | ZACHTRANSACTIONS.INFO
5 | ZCABLE.INFO
9 | ZCIRCUITBOARDS.INFO
9 | ZCIRCUIT.INFO
6 | ZCONNECTION.INFO
5 | ZFILAMENT.INFO
10 | ZLINESEGMENT.INFO
3 | ZLINETRAINS.INFO
3 | ZLINK.INFO
4 | Z-WIREBLOG.INFO
7 | Z-WIRE-INTERACTIVE.INFO
9 | ZWIREINTERACTIVE.INFO
6 | Z-WIRENOW.INFO
8 | Z-WIREONLINE.INFO
11 | Z-WIRESHOP.INFO
7 | Z-WIRES.INFO
13 | Z-WIRESITE.INFO
15 | Z-WIRESTORE.INFO
7 | Z-WIRETODAY.INFO
(487 rows)

Saturday, March 12, 2011

UK Government counts the Cost of Cybercrime

The British government has released a report on the annual cost of cybercrime to the United Kingdom. The study mechanism seems greatly flawed, in that it relies almost exclusively on published reports and expert opinions, rather than on any structured gathering of information from victims.

The news was announced in the press this week, for example in the Independent.

They came up with a 2010 annual cost of cyber crime of £27 billion (or $43 billion US Dollars). If the costs were projected evenly from the $2.2 trillion UK economy to the $14.1 trillion US economy, that would estimate our own costs of cybercrime at $275 billion (roughly 6.4 times larger economy.) There is no basis to believe that projection is accurate, but the scale is probably similar.

The study was paid for by the OCSIA, the Office of Cyber Security and Information Assurance. It was conducted by Detica, a BAE Systems company.

The full 32 page report is available from the Cabinet Office

They place costs at:

£3.1 billion to citizens with
£1.7 billion in Identity Theft
£1.4 billion to online scams.

£2.2 billion to the government

£21 billion businesses of which:

£9.2 billion in Intellectual Property theft
£7.6 billion in industrial espionage
£2.2 billion in extortion
£1.3 billion from direct theft
£1 billion in costs related to lost customer data

The Intellectual Property theft was certainly not evenly distributed. They put the most likely industries as:

£1.8 billion = pharmaceuticals & biotech
£1.7 billion = electronic & electrical material
£1.6 billion = software & computer services
£1.3 billion = chemicals
£800 million = automobiles & parts
£800 million = non-profits
£400 million = aerospace & defence

The greatest risk in Intellectual Property theft was believed to be untrustworthy insiders who fell to the pressure of bribery.

The Espionage Impact was largely in three areas:

£2.1 billion = financial services
£1.6 billion = mining
£1.3 billion = aerospace and defence
£900 million = software & computer services

Friday, March 11, 2011

More ACH Spam from NACHA

While we wait for the Japanese Earthquake scams to begin, we noticed another on-going spam campaign. We wrote about the ACH Transaction Rejected spam back in February, but another round is active, with another 350+ freshly registered domains.

The body of the email this time around reads:

The ACH transfer (ID: 65388185980), recently sent from your checking account (by you or any other person), was cancelled by the other financial institution.

Please click here (link) to view details

If you have any questions or comments, contact us at info@nacha.org. Thank you for using http://www.nacha.org.

/This messages is intended for use by addressee only and may contain privileged and confidential information. If you are not the intended recipient, dissemination of this communication is prohibited. If you have received this communication in error, please delete all copies of the message and attachments and notify the sender immediately. /



The spam has one of the following ten subject lines:

ACH payment canceled
ACH payment rejected
ACH transaction canceled
ACH Transfer canceled
ACH transfer rejected
Rejected ACH payment
Rejected ACH transaction
Rejected ACH transfer
Your ACH transaction
Your ACH transfer

Each claims to be from "nacha.org" - the National Automated Clearing House Association - the people who handle electronic payments between banks.

The from addresses are:

ach@nacha.org
admin@nacha.org
alert@nacha.org
alerts@nacha.org
info@nacha.org
payment@nacha.org
payments@nacha.org
risk@nacha.org
risk_manager@nacha.org
transactions@nacha.org
transfers@nacha.org


Here are the domain names we are seeing this time around. I haven't checked all of them, but the ones I checked were GoDaddy. (GoDaddy and Affilias have been notified, and many of the domains are already disabled.)


machine
-----------------------------------
ACHDESCRIBES.INFO
ACH-DETAILS-EMERGE.INFO
ACHDETAILSEMERGE.INFO
ACH-DETAILS.INFO
ACHDETAILS.INFO
ACH-DETAILS-MAGAZINE.INFO
ACHDETAILSMAGAZINE.INFO
ACHDETAILSNOW.INFO
ACHDETAILSONLINE.INFO
ACHDETAILSSHOP.INFO
ACHDETAILSSITE.INFO
ACHDETAILSSTORE.INFO
ACHDETAILSTODAY.INFO
ACHELEMENTS.INFO
ACH-INFORMATION-ARCHITECTURE.INFO
ACHINFORMATIONASSURANCE.INFO
ACHINFORMATIONBLOG.INFO
ACH-INFORMATION.INFO
ACHINFORMATION.INFO
ACHINFORMATIONLITERACY.INFO
ACHINFORMATIONNOW.INFO
ACHINFORMATIONONLINE.INFO
ACH-INFORMATION-SCIENCES.INFO
ACHINFORMATIONSCIENCES.INFO
ACH-INFORMATION-SHARING.INFO
ACHINFORMATIONSHARING.INFO
ACHINFORMATIONSHOP.INFO
ACHINFORMATIONS.INFO
ACHINFORMATIONSITE.INFO
ACHINFORMATIONSTORE.INFO
ACHINFORMATIONTODAY.INFO
ACHINFORMATIONWARFARE.INFO
ACHINFORMS.INFO
ACHREPORTBLOG.INFO
ACH-REPORT-CARD.INFO
ACHREPORTCARD.INFO
ACH-REPORT-CARDS.INFO
ACHREPORTCARDS.INFO
ACH-REPORT-COVERS.INFO
ACHREPORTCOVERS.INFO
ACH-REPORT.INFO
ACHREPORT.INFO
ACHREPORTNOW.INFO
ACHREPORTONLINE.INFO
ACHREPORTSHOP.INFO
ACHREPORTS.INFO
ACHREPORTSITE.INFO
ACHREPORTSTORE.INFO
ACHREPORTTODAY.INFO
ACHREVIEW.INFO
ATRANSFERADMISSION.INFO
ATRANSFERAGENT.INFO
ATRANSFERAPPLICANTS.INFO
A-TRANSFERBLOG.INFO
ATRANSFERFILES.INFO
ATRANSFERGUIDES.INFO
ATRANSFER.INFO
A-TRANSFERNOW.INFO
A-TRANSFERONLINE.INFO
ATRANSFERPRICING.INFO
ATRANSFERREQUEST.INFO
A-TRANSFERSHOP.INFO
A-TRANSFERS.INFO
A-TRANSFERSITE.INFO
A-TRANSFER-STATION.INFO
ATRANSFERSTATION.INFO
A-TRANSFERSTORE.INFO
A-TRANSFERTODAY.INFO
B-ACH-ACCOUNTS.INFO
BACHACCOUNTS.INFO
B-ACHBLOG.INFO
B-ACH.INFO
B-ACHNOW.INFO
B-ACHONLINE.INFO
B-ACH-PAYMENT.INFO
BACHPAYMENT.INFO
B-ACH-PAYMENTS.INFO
BACHPAYMENTS.INFO
B-ACHSHOP.INFO
B-ACHS.INFO
B-ACHSITE.INFO
B-ACHSTORE.INFO
B-ACHTODAY.INFO
B-ACH-TRANSACTIONS.INFO
BACHTRANSACTIONS.INFO
BESTACHDETAILS.INFO
BESTACHINFORMATION.INFO
BESTACHREPORT.INFO
BESTA-TRANSFER.INFO
BESTB-ACH.INFO
BESTD-PAYMENT.INFO
BESTG-PAYMENT.INFO
BESTP-ACH.INFO
BESTQ-ACH.INFO
BESTQ-PAYMENT.INFO
BESTQ-TRANSFER.INFO
BESTR-TRANSFER.INFO
BESTT-TRANSFER.INFO
BESTV-ACH.INFO
BESTW-ACH.INFO
BESTZ-PAYMENT.INFO
D-PAYMENTBLOG.INFO
D-PAYMENT.INFO
DPAYMENT.INFO
DPAYMENTMETHOD.INFO
DPAYMENTMETHODS.INFO
D-PAYMENTNOW.INFO
D-PAYMENTONLINE.INFO
DPAYMENTOPTION.INFO
DPAYMENTPROCESSING.INFO
DPAYMENTPROCESSOR.INFO
D-PAYMENTSHOP.INFO
D-PAYMENTS.INFO
D-PAYMENTSITE.INFO
DPAYMENTSOLUTION.INFO
DPAYMENTSOLUTIONS.INFO
D-PAYMENTSTORE.INFO
DPAYMENTTERMINAL.INFO
D-PAYMENTTODAY.INFO
DPAYMENTTRANSACTION.INFO
ELECTRONIC-ACH-DETAILS.INFO
ELECTRONICACHDETAILS.INFO
ELECTRONIC-ACH-REPORT.INFO
ELECTRONICACHREPORT.INFO
FREEACHDETAILS.INFO
FREEACHINFORMATION.INFO
FREEACHREPORT.INFO
FREEA-TRANSFER.INFO
FREEB-ACH.INFO
FREED-PAYMENT.INFO
FREEG-PAYMENT.INFO
FREEQ-ACH.INFO
FREEQ-PAYMENT.INFO
FREEQ-TRANSFER.INFO
FREER-TRANSFER.INFO
FREET-TRANSFER.INFO
FREEV-ACH.INFO
FREEW-ACH.INFO
FREEZ-PAYMENT.INFO
G-PAYMENTBLOG.INFO
G-PAYMENT.INFO
GPAYMENT.INFO
GPAYMENTMETHOD.INFO
GPAYMENTMETHODS.INFO
G-PAYMENTNOW.INFO
G-PAYMENTONLINE.INFO
GPAYMENTPROCESSING.INFO
GPAYMENTPROCESSOR.INFO
G-PAYMENTSHOP.INFO
G-PAYMENTS.INFO
G-PAYMENTSITE.INFO
GPAYMENTSOLUTIONS.INFO
G-PAYMENTSTORE.INFO
GPAYMENTTERMINAL.INFO
G-PAYMENTTODAY.INFO
GPAYMENTTRANSACTION.INFO
MASTER-P-ACH.INFO
MASTERPACH.INFO
MYACHDETAILS.INFO
MYACHINFORMATION.INFO
MYACHREPORT.INFO
MYA-TRANSFER.INFO
MYB-ACH.INFO
MYD-PAYMENT.INFO
MYG-PAYMENT.INFO
MYP-ACH.INFO
MYQ-ACH.INFO
MYQ-PAYMENT.INFO
MYQ-TRANSFER.INFO
MYR-TRANSFER.INFO
MYT-TRANSFER.INFO
MYV-ACH.INFO
MYW-ACH.INFO
MYZ-PAYMENT.INFO
NEWACHDETAILS.INFO
NEWACHINFORMATION.INFO
NEWACHREPORT.INFO
NEWA-TRANSFER.INFO
NEWB-ACH.INFO
NEWD-PAYMENT.INFO
NEWG-PAYMENT.INFO
NEWP-ACH.INFO
NEWQ-ACH.INFO
NEWQ-PAYMENT.INFO
NEWQ-TRANSFER.INFO
NEWR-TRANSFER.INFO
NEWT-TRANSFER.INFO
NEWV-ACH.INFO
NEWW-ACH.INFO
NEWZ-PAYMENT.INFO
P-ACH-ACCOUNTS.INFO
PACHACCOUNTS.INFO
P-ACHBLOG.INFO
P-ACH.INFO
P-ACHNOW.INFO
P-ACHONLINE.INFO
P-ACH-PAYMENT.INFO
PACHPAYMENT.INFO
P-ACH-PAYMENTS.INFO
PACHPAYMENTS.INFO
P-ACHSHOP.INFO
P-ACHS.INFO
P-ACHSITE.INFO
P-ACHSTORE.INFO
P-ACHTODAY.INFO
P-ACH-TRANSACTIONS.INFO
PACHTRANSACTIONS.INFO
Q-ACH-ACCOUNTS.INFO
QACHACCOUNTS.INFO
Q-ACHBLOG.INFO
Q-ACH.INFO
QACH.INFO
Q-ACHNOW.INFO
Q-ACHONLINE.INFO
Q-ACH-PAYMENT.INFO
QACHPAYMENT.INFO
Q-ACH-PAYMENTS.INFO
QACHPAYMENTS.INFO
Q-ACHSHOP.INFO
Q-ACHS.INFO
Q-ACHSITE.INFO
Q-ACHSTORE.INFO
Q-ACHTODAY.INFO
Q-ACH-TRANSACTIONS.INFO
QACHTRANSACTIONS.INFO
Q-PAYMENTBLOG.INFO
Q-PAYMENT.INFO
QPAYMENTMETHOD.INFO
QPAYMENTMETHODS.INFO
Q-PAYMENTNOW.INFO
Q-PAYMENTONLINE.INFO
QPAYMENTOPTION.INFO
QPAYMENTPROCESSING.INFO
QPAYMENTPROCESSOR.INFO
QPAYMENTSCHEDULE.INFO
Q-PAYMENTSHOP.INFO
Q-PAYMENTS.INFO
Q-PAYMENTSITE.INFO
QPAYMENTSOLUTION.INFO
QPAYMENTSOLUTIONS.INFO
Q-PAYMENTSTORE.INFO
QPAYMENTTERMINAL.INFO
Q-PAYMENTTODAY.INFO
QPAYMENTTRANSACTION.INFO
QTRANSFERADMISSION.INFO
QTRANSFERAGENT.INFO
QTRANSFERAPPLICANTS.INFO
Q-TRANSFERBLOG.INFO
QTRANSFERFILES.INFO
QTRANSFERGUIDES.INFO
Q-TRANSFER.INFO
QTRANSFER.INFO
Q-TRANSFERNOW.INFO
Q-TRANSFERONLINE.INFO
QTRANSFERPRICING.INFO
QTRANSFERREQUEST.INFO
Q-TRANSFERSHOP.INFO
Q-TRANSFERS.INFO
Q-TRANSFERSITE.INFO
Q-TRANSFER-STATION.INFO
QTRANSFERSTATION.INFO
Q-TRANSFERSTORE.INFO
Q-TRANSFERTODAY.INFO
RTRANSFERADMISSION.INFO
RTRANSFERAGENT.INFO
RTRANSFERAPPLICANTS.INFO
R-TRANSFERBLOG.INFO
RTRANSFERFILES.INFO
RTRANSFERGUIDES.INFO
R-TRANSFER.INFO
RTRANSFER.INFO
R-TRANSFERNOW.INFO
R-TRANSFERONLINE.INFO
RTRANSFERPRICING.INFO
RTRANSFERREQUEST.INFO
R-TRANSFERSHOP.INFO
R-TRANSFERS.INFO
R-TRANSFERSITE.INFO
R-TRANSFER-STATION.INFO
RTRANSFERSTATION.INFO
R-TRANSFERSTORE.INFO
R-TRANSFERTODAY.INFO
TERMINAL-B-ACH.INFO
TERMINALBACH.INFO
THEACHDETAILS.INFO
THEACHINFORMATION.INFO
THEACHREPORT.INFO
THEA-TRANSFER.INFO
THEB-ACH.INFO
THED-PAYMENT.INFO
THEG-PAYMENT.INFO
THEP-ACH.INFO
THEQ-ACH.INFO
THEQ-PAYMENT.INFO
THEQ-TRANSFER.INFO
THER-TRANSFER.INFO
THET-TRANSFER.INFO
THEV-ACH.INFO
THEW-ACH.INFO
THEZ-PAYMENT.INFO
TTRANSFERADMISSION.INFO
TTRANSFERAGENT.INFO
TTRANSFERAPPLICANTS.INFO
T-TRANSFERBLOG.INFO
TTRANSFERFILES.INFO
TTRANSFERGUIDES.INFO
TTRANSFER.INFO
T-TRANSFERNOW.INFO
T-TRANSFERONLINE.INFO
TTRANSFERPRICING.INFO
TTRANSFERREQUEST.INFO
T-TRANSFERSHOP.INFO
T-TRANSFERS.INFO
T-TRANSFERSITE.INFO
T-TRANSFER-STATION.INFO
TTRANSFERSTATION.INFO
T-TRANSFERSTORE.INFO
T-TRANSFERTODAY.INFO
V-ACH-ACCOUNTS.INFO
VACHACCOUNTS.INFO
V-ACHBLOG.INFO
V-ACH.INFO
V-ACHNOW.INFO
V-ACHONLINE.INFO
V-ACH-PAYMENT.INFO
VACHPAYMENT.INFO
V-ACH-PAYMENTS.INFO
VACHPAYMENTS.INFO
V-ACHSHOP.INFO
V-ACHS.INFO
V-ACHSITE.INFO
V-ACHSTORE.INFO
V-ACHTODAY.INFO
V-ACH-TRANSACTIONS.INFO
VACHTRANSACTIONS.INFO
W-ACH-ACCOUNTS.INFO
WACHACCOUNTS.INFO
W-ACHBLOG.INFO
W-ACH.INFO
W-ACHNOW.INFO
W-ACHONLINE.INFO
W-ACH-PAYMENT.INFO
WACHPAYMENT.INFO
W-ACH-PAYMENTS.INFO
WACHPAYMENTS.INFO
W-ACHSHOP.INFO
W-ACHS.INFO
W-ACHSITE.INFO
W-ACHSTORE.INFO
W-ACHTODAY.INFO
WACHTRANSACTIONS.INFO
WARRENGPAYMENT.INFO
ZPAYMENTARRANGEMENT.INFO
Z-PAYMENTBLOG.INFO
ZPAYMENTCARD.INFO
ZPAYMENTCARDS.INFO
ZPAYMENTDATES.INFO
ZPAYMENTDEADLINE.INFO
ZPAYMENTDEFINITION.INFO
ZPAYMENTINSTRUMENTS.INFO
ZPAYMENTLOCATIONS.INFO
Z-PAYMENTONLINE.INFO
ZPAYMENTPLATFORM.INFO
ZPAYMENTPROTECTION.INFO
Z-PAYMENTSHOP.INFO
Z-PAYMENTS.INFO
Z-PAYMENTSITE.INFO
Z-PAYMENTSTORE.INFO
Z-PAYMENTTODAY.INFO

Thursday, March 10, 2011

ENISA on Botnets - Ten Tough Questions

Yesterday was the beginning of the "Workshop on Botnet Detection, Measurement, Disinfection & Defence" in Cologne, Germany. ( agenda here )

The tracks for Wednesday were "Anti-Botnet Policy Initiatives" and "Legal and Regulatory Issues" both featuring panelists from the Council of Europe and NATO.

Today's tracks included "Anti-Botnet Policy Initiatives Part 2," "State of the Art on Measurements, Countermeasures, and Botnets," "Industry View on Fighting Botnets," "Research and Academia on Fighting Botnets." Some great speakers are on the agenda, including Peter Kruse and Dennis Rand from CSIS Security Group, Mikko Hypponen from F-Secure, and Vitaly Kamluk from Kaspersky.

Two significant documents were released at the conference this morning that pretty much need to go on the Must Read list for anyone interested in Botnets:

Botnets: Detection, Measurement, Disinfection & Defence



After a keynote address by Professor Dr. Udo Helmbrecht, the executive director of ENISA (European Network and Information Security Agency), Daniel Plohmann and Dr. Giles Hogben shared a presentation of ENISA's 154 page document called "Botnets: Detection, Measurement, Disinfection & Defence", editor Dr. Giles Hogben, which you may find on their website here:

http://www.enisa.europa.eu/act/res/botnets/botnets-measurement-detection-disinfection-and-defence

The document calls attention to the highest priorities that we should collectively address:
- Mitigation of existing botnets
- Prevention of new infections
- Minimizing the profitability of botnets and cybercrime

In the first of these, there is a call for a new model of engaging, encouraging, and incentivizing Internet Service Providers to be an asset in the botnet fight. Current business models and in some cases current laws both reduce the effectiveness of ISPs in helping to fight botnets. Other MITIGATION issues encourage improved botnet identification and monitoring, increased information sharing, and bringing cybercrime laws into harmony internationally. Other advice had to do with making sure the entire botnet can be killed before attempting a "partial shutdown."

Under the PREVENTION category, public awareness, and improvements to software defenses are encouraged.

Under the PROFITABILITY category, it is necessary to improve anti-fraud mechanisms, and to address the social level of the crimes rather than only the technological level, by increasing deterrence through tougher prosecution and sentencing of offenders.

Specific guidance is provided for Regulators, End-users, Research Institutions, and
any information holders.

With regards to the Research Institutions, the recommendation was that they should be "more strongly integrated, and where appropriate, empowered in the fight against botnets. Research should focus on techniques which can be implemented in large-scale operations environments subject to typical cost constraints. They should be supported in studying methods for the detection of botnets and the analysis of malware, in order to provide efficient tools to reduce the reaction time when dealing with complex and sophisticated malware threats. As the results of research may be of interest for ongoing investigations, the process of publishing these results should reflect the responsibility associated with them." (extracted from the Executive Summary, p. 7)

Towards that end, I want to mention that the Anti-Phishing Working Group is trying to encourage this level of interaction between Researchers, Law Enforcement, and Industry through events such as next week's "eCrime Researchers Sync-Up." My colleague, Kent Kerley, and I will be attending from the University of Alabama at Birmingham to work on building these international relationships, not just among EU nations, but around the world. APWG sponsors the eCrime Researchers Summit, the eCrime Operations Summit, and now the eCrime Researchers Sync-up to try to encourage exactly the types of interactions described in this report. To learn more about APWG events, visit the APWG eCrime Research page.

Botnets: Ten Tough Questions


Second, ENISA's document called "Botnets: 10 Tough Questions" which is an 18 page summary of some of the major issues facing us regarding Botnets.

Botnets: Ten Tough Questions.

The Ten Tough Questions document is described as a document that "distills the major issues which need to be understood and addressed by decision-makers in all groups of stakeholders."

Here's a list of the Questions to whet your appetite. I highly recommend consuming both documents!

Q1. How much trust to put in published figures?

Q2. What are the main challenges associated with jurisdiction?

Q3. What should be the main role of the EU/National Governments?

Q4. Which parties should take which responsibilities?

Q5. Where to invest money most efficiently?

(HINT! EDUCATION AND RESEARCH!!)

Q6. What are key incentives for cooperative information sharing?

Q7. What are key challegnes for cooperative information sharing?

Q8. Are there unseen/undetected botnets?

Q9. Which aspects are still missing in the fight against botnets?

Q10. What are future trends?

Wednesday, March 09, 2011

Ghostmarket Carders Sentenced in UK

Back in November we ran a story Schoolboy Hackers steal $18 Million regarding the case against the operators of the online credit card trading forum known as Ghostmarket. Today's post is just a quick follow-up to share details of their sentences from New Scotland Yard.



The defendants had harvested more than 130,000 compromised credit card numbers, and had successfully installed Zeus on more than 15,000 computers in 150 countries, gathering more than 4 million lines of data from the compromised computers.

The Metropolitan Police of London sentenced the Ghostmarket criminals on March 2, 2011, as they share in this Press Release.

An audio clip by Detective Inspector Colin Wetherill explains the accomplishment.


[A] Gary Paul Kelly, 21 (14.04.89) unemployed of Clively Avenue, Clifton, Swinton, Manchester -- sentenced to Five Years

Kelly was arrested on November 3, 2009 as a result of a search warrant of his home. Detectives were able to build a working copy of the GhostMarket forum from the database files recovered from Kelly's PC.



[B] Nicholas Webber, 19 (10.10.91) a student of Cavendish Road, Southsea; -- sentenced to Five Years


[C] Ryan Thomas, 18 (8.7.92) a web designer of Howard Road, Seer Green, Beaconsfield, Herts; -- sentenced to Four Years

Webber and Thomas were arrested on October 12, 2009 while partying in a five star London hotel, paid for with stolen credit cards. A big hint that they may be associated with the crime of carding and the GhostMarket website was that both were in possession of GhostMarket business cards in their name, calling the site "A new era in virtual marketing" and stating "I'm a carder, ask about me..."

After being released on bail, the pair were rearrested at the Gatwick airport on January 29, 2010 as they returned from a trip to Palma, Majorca.


[D] Shakira Ricardo, 21 (14.11.89) unemployed of Flat 13, J Shed, Kings Road, Swansea SA1; -- sentenced to 18 Months.

A fifth defendant, Samantha Worley, pleaded guilty earlier and received a sentence of 200 hours community service.

Full details of the charges against the five are available from The Metropolitan Police of London

Friday, February 25, 2011

"ACH Transaction Rejected" payments lead to Zeus

On February 23rd, our friends at Trend Micro reported that ACH Leads to Fake Java Update. Looking into this campaign in the UAB Spam Data Mine we found some interesting characteristics about the spam campaign.

We've seen NACHA, the National Automated Clearing House Association, used as bait for a Zeus trap before. See our article from November 2009, Newest Zeus = NACHA The Electronic Payments Association.

The spam body, containing a random signator name and random domain reads:

===========================================================================

The ACH transaction , recently initiated from your bank account (by you or any
other person), was rejected by the Electronic Payments Association.

Please click here to view details

------------------------------------------------------------------

Benjamin Grant,
Fraud Department

==========================================================================

Here are our counts by Subject so far for this campaign:

count | subject
-------+---------------------------
1656 | ACH Transfer cancelled
1620 | Your ACH Transfer
1558 | ACH Transfer rejected
1598 | Your ACH transaction
1610 | ACH transaction cancelled
1622 | ACH transaction rejected
(6 rows)

That's out of a volume of slightly more than 1 million emails per day. Here it is with date added:

count | subject | receiving_date
-------+---------------------------+----------------
10 | ACH transaction cancelled | 2011-02-22
13 | ACH transaction rejected | 2011-02-22
23 | ACH Transfer cancelled | 2011-02-22
18 | ACH Transfer rejected | 2011-02-22
15 | Your ACH transaction | 2011-02-22
11 | Your ACH Transfer | 2011-02-22
1600 | ACH transaction cancelled | 2011-02-23
1609 | ACH transaction rejected | 2011-02-23
1633 | ACH Transfer cancelled | 2011-02-23
1540 | ACH Transfer rejected | 2011-02-23
1583 | Your ACH transaction | 2011-02-23
1609 | Your ACH Transfer | 2011-02-23
(12 rows)

What was extremely interesting about this campaign was the large number of domains it registered to be used in this abuse. Fortunately, these were all "GoDaddy.com" domains and were quickly brought under control to prevent the spread of the malware.

Here are our volume by spammed domain:

count | machine
-------+---------------------------------
26 | AC-CURE-HS.INFO
30 | ACCUREHS.INFO
33 | ACH-ACCOUNTS.INFO
26 | ACHACCOUNTS.INFO
29 | ACHDAUDIO.INFO
29 | ACHDBLOG.INFO
28 | ACHDCAMERA.INFO
25 | ACHDCOMPATIBLE.INFO
26 | ACHDFORMAT.INFO
30 | AC-HD.INFO
30 | ACHDNOW.INFO
26 | ACHDONLINE.INFO
24 | ACHDPHOTO.INFO
36 | ACHDPROGRAMMING.INFO
31 | ACHDRECEIVER.INFO
28 | ACHDRECORDING.INFO
34 | ACHDSHOP.INFO
34 | ACHDSIGNALS.INFO
39 | ACHDS.INFO
26 | ACHDSITE.INFO
27 | ACHDSTORE.INFO
25 | ACHDTODAY.INFO
31 | ACHFACID.INFO
36 | ACHFBANDS.INFO
34 | ACHFBLOG.INFO
45 | ACHFBROADCASTING.INFO
37 | ACHFCONTEST.INFO
27 | ACHFEXPOSURE.INFO
37 | AC-HF.INFO
27 | ACHFMOBILE.INFO
24 | ACHFNOW.INFO
26 | ACHFONLINE.INFO
34 | ACHFRADAR.INFO
25 | ACHFRECEIVER.INFO
22 | ACHFSHOP.INFO
37 | ACHFS.INFO
38 | ACHFSITE.INFO
31 | ACHFSPECTRUM.INFO
30 | ACHFSTORE.INFO
28 | ACHFTODAY.INFO
28 | ACHGBLOG.INFO
47 | ACHGENTERTAINMENT.INFO
35 | AC-HG-EXPOSURE.INFO
40 | ACHGEXPOSURE.INFO
44 | AC-HG.INFO
26 | ACHGMETAL.INFO
33 | ACHGNOW.INFO
27 | ACHGONLINE.INFO
17 | ACHGSHOP.INFO
26 | ACHGS.INFO
29 | ACHGSITE.INFO
27 | ACHGSPOT.INFO
29 | ACHGSTORE.INFO
26 | ACHGTODAY.INFO
26 | AC-HG-VACUUM.INFO
30 | ACHGVACUUM.INFO
27 | AC-HG-WELLS.INFO
31 | ACHGWELLS.INFO
28 | AC-HIGHSCHOOL.INFO
33 | ACHIGHSCHOOL.INFO
25 | ACH-PAYMENT.INFO
28 | ACH-PAYMENTS.INFO
30 | ACHPBLOG.INFO
41 | ACHPCERTIFICATION.INFO
39 | ACHPENTERPRISE.INFO
34 | ACHPHARDWARE.INFO
36 | ACHPIBLOG.INFO
27 | AC-HPI-CARS.INFO
33 | ACHPICARS.INFO
27 | AC-HPI-CHECKS.INFO
30 | ACHPICHECKS.INFO
32 | AC-HPI.INFO
33 | ACHPI.INFO
28 | AC-HP.INFO
26 | ACHPINOW.INFO
33 | ACHPINTEGRITY.INFO
27 | ACHPIONLINE.INFO
21 | AC-HPI-RACING.INFO
30 | ACHPIRACING.INFO
38 | ACHPISHOP.INFO
23 | ACHPIS.INFO
32 | ACHPISITE.INFO
20 | ACHPISTORE.INFO
26 | ACHPITODAY.INFO
30 | ACHPLINUX.INFO
25 | ACHPNOW.INFO
28 | ACHPONLINE.INFO
24 | ACHPPHOTO.INFO
23 | ACHPPRINTER.INFO
35 | ACHPSERVER.INFO
40 | ACHPSERVERS.INFO
40 | ACHPSHOP.INFO
31 | ACHPS.INFO
28 | ACHPSITE.INFO
32 | ACHPSTORE.INFO
34 | ACHPTODAY.INFO
21 | ACHSBLOG.INFO
32 | AC-HS.INFO
33 | ACHSNOW.INFO
35 | ACHSONLINE.INFO
36 | ACHSSHOP.INFO
38 | ACHSSITE.INFO
33 | ACHSSTORE.INFO
33 | ACHSTODAY.INFO
35 | ACHTBLOG.INFO
31 | AC-HT-CONSULTING.INFO
38 | ACHTCONSULTING.INFO
19 | AC-HT-EDITOR.INFO
31 | ACHTEDITOR.INFO
30 | AC-HT-ENTERPRISES.INFO
37 | ACHTENTERPRISES.INFO
31 | AC-HT.INFO
35 | AC-HT-MOBILE.INFO
32 | ACHTMOBILE.INFO
33 | ACHTNOW.INFO
26 | ACHTRANSACTIONBLOG.INFO
35 | ACHTRANSACTIONCODE.INFO
38 | ACH-TRANSACTION.INFO
29 | ACHTRANSACTION.INFO
29 | ACHTRANSACTIONISOLATION.INFO
23 | ACHTRANSACTIONLAYER.INFO
28 | ACHTRANSACTIONLOGIC.INFO
26 | ACHTRANSACTIONMONITORING.INFO
18 | ACHTRANSACTIONNOW.INFO
29 | ACHTRANSACTIONONLINE.INFO
27 | ACH-TRANSACTION-PROCESSING.INFO
32 | ACHTRANSACTIONPROCESSING.INFO
34 | ACH-TRANSACTION-PUBLISHERS.INFO
29 | ACHTRANSACTIONPUBLISHERS.INFO
17 | ACHTRANSACTIONSHOP.INFO
31 | ACH-TRANSACTIONS.INFO
28 | ACHTRANSACTIONS.INFO
29 | ACHTRANSACTIONSITE.INFO
31 | ACHTRANSACTIONSTORE.INFO
29 | ACHTRANSACTIONTODAY.INFO
28 | ACHTRANSFERAGENT.INFO
28 | ACHTRANSFERBLOG.INFO
33 | ACHTRANSFERCREDITS.INFO
26 | ACHTRANSFERFILES.INFO
37 | ACHTRANSFERGUIDE.INFO
31 | ACHTRANSFERGUIDES.INFO
34 | ACH-TRANSFER.INFO
30 | ACHTRANSFER.INFO
30 | ACHTRANSFERNOW.INFO
32 | ACHTRANSFERONLINE.INFO
35 | ACHTRANSFERPRICING.INFO
16 | ACHTRANSFERREQUEST.INFO
33 | ACHTRANSFERSHOP.INFO
32 | ACHTRANSFERS.INFO
35 | ACHTRANSFERSITE.INFO
34 | ACH-TRANSFER-STATION.INFO
31 | ACHTRANSFERSTATION.INFO
30 | ACHTRANSFERSTORE.INFO
29 | ACHTRANSFERTODAY.INFO
25 | ACHTRUSTASSETS.INFO
25 | ACHTRUSTBLOG.INFO
31 | ACHTRUSTCORPORATION.INFO
37 | ACHTRUSTDOCUMENT.INFO
32 | ACH-TRUST.INFO
31 | ACHTRUST.INFO
32 | ACHTRUSTINSTRUMENT.INFO
20 | ACHTRUSTINVESTMENTS.INFO
21 | ACHTRUSTLANDS.INFO
33 | ACHTRUSTNOW.INFO
30 | ACHTRUSTONLINE.INFO
27 | ACHTRUSTSHOP.INFO
23 | ACHTRUSTS.INFO
26 | ACHTRUSTSITE.INFO
26 | ACHTRUSTSTORE.INFO
35 | ACHTRUSTTODAY.INFO
22 | ACH-TRUST-WEBSITE.INFO
34 | ACHTRUSTWEBSITE.INFO
28 | ACHTSHOP.INFO
28 | ACHTS.INFO
38 | ACHTSITE.INFO
34 | ACHTSTORE.INFO
33 | ACHTTODAY.INFO
32 | ACHUBLOG.INFO
30 | AC-HU.INFO
27 | ACHUNOW.INFO
21 | ACHUONLINE.INFO
32 | ACHUSHOP.INFO
40 | ACHUSITE.INFO
32 | ACHUSTORE.INFO
24 | ACHUTODAY.INFO
35 | ACHYBLOG.INFO
28 | ACH-Y-CAMP.INFO
35 | ACHYCAMP.INFO
31 | ACH-Y.INFO
30 | ACHYNOW.INFO
28 | ACHYONLINE.INFO
25 | ACHYSHOP.INFO
31 | ACHYS.INFO
18 | ACHYSITE.INFO
27 | ACHYSTORE.INFO
39 | ACHYTODAY.INFO
29 | ACHZBLOG.INFO
30 | AC-HZ.INFO
26 | ACHZNOW.INFO
35 | ACHZONLINE.INFO
28 | ACHZSHOP.INFO
34 | ACHZS.INFO
33 | ACHZSITE.INFO
22 | ACHZSTORE.INFO
32 | ACHZTODAY.INFO
2 | ACTORTUO.INFO
27 | BASEBALLTRANSACTIONS.INFO
40 | BESTACHD.INFO
22 | BESTACHF.INFO
36 | BESTACHG.INFO
39 | BESTACHPI.INFO
34 | BESTACHP.INFO
29 | BESTACHS.INFO
32 | BESTACHT.INFO
26 | BESTACHTRANSACTION.INFO
37 | BESTACHTRANSFER.INFO
30 | BESTACHTRUST.INFO
29 | BESTACHU.INFO
31 | BESTACHY.INFO
28 | BESTACHZ.INFO
2 | BESTKRUST.INFO
33 | BESTTRANSFERACH.INFO
1 | BETAINFO.INFO
2 | BRENT-TOR.INFO
2 | CALMWEATHER.INFO
2 | CLOTHES-PEG-I.INFO
42 | COLLEGETRANSFERACH.INFO
3 | dfc4.co.cc
4 | dfc5.co.cc
22 | DISTRIBUTEDTRANSACTIONS.INFO
40 | DOMAINTRANSFERACH.INFO
2 | EDUCATIONALTOPIC.INFO
40 | ELECTRONIC-ACH.INFO
31 | ELECTRONICACH.INFO
21 | ELECTRONICACHTRUST.INFO
39 | ELECTRONIC-ACH-Y.INFO
28 | ELECTRONICACHY.INFO
27 | ELECTRONICTRANSACTIONS.INFO
2 | FLOORSURFACE.INFO
35 | FREEACHD.INFO
31 | FREEACHF.INFO
33 | FREEACHG.INFO
29 | FREEACHPI.INFO
37 | FREEACHP.INFO
24 | FREEACHS.INFO
33 | FREEACHT.INFO
27 | FREEACHTRANSACTION.INFO
26 | FREEACHTRANSFER.INFO
28 | FREEACHTRUST.INFO
31 | FREEACHU.INFO
33 | FREEACHY.INFO
31 | FREEACHZ.INFO
33 | FREETRANSFERACH.INFO
2 | FREEULX.INFO
39 | HEAT-TRANSFER-ACH.INFO
45 | HEATTRANSFERACH.INFO
2 | IGLOMINERALS.INFO
1 | INCORRECT-RESULT.INFO
2 | INTERACTIVEROUTE.INFO
1 | JOURNALISSUE.INFO
25 | LEAGUETRANSACTIONS.INFO
3 | LOVES-YOU-LX.INFO
2 | LYNXPOPULATIONS.INFO
2 | MAMBARANKING.INFO
2 | MAMBASCHOLARSHIP.INFO
2 | MB-CARD.INFO
32 | MEMORYTRANSACTIONS.INFO
2 | MERCURYLYNX.INFO
34 | MYACHD.INFO
36 | MYACHF.INFO
28 | MYACHG.INFO
31 | MYACHPI.INFO
22 | MYACHP.INFO
32 | MYACHT.INFO
40 | MYACHTRANSACTION.INFO
41 | MYACHTRANSFER.INFO
37 | MYACHTRUST.INFO
28 | MYACHU.INFO
34 | MYACHY.INFO
30 | MYACHZ.INFO
2 | MYPEGI.INFO
26 | MYTRANSFERACH.INFO
30 | NEWACHD.INFO
37 | NEWACHF.INFO
26 | NEWACHG.INFO
44 | NEWACHPI.INFO
28 | NEWACHP.INFO
31 | NEWACHS.INFO
29 | NEWACHT.INFO
32 | NEWACHTRANSACTION.INFO
27 | NEWACHTRANSFER.INFO
23 | NEWACHTRUST.INFO
26 | NEWACHU.INFO
19 | NEWACHY.INFO
30 | NEWACHZ.INFO
45 | NEWTRANSFERACH.INFO
1 | NEWULX.INFO
2 | NOVA-TU-O.INFO
2 | OTTAWALYNX.INFO
2 | PEGISHOP.INFO
34 | PLAYERTRANSACTIONS.INFO
24 | REPRESENTATIVETRANSACTIONS.INFO
3 | RESPOND-E-PT.INFO
2 | REWARDMILES.INFO
2 | RIMINFO.INFO
2 | ROUGHTOR.INFO
38 | SECUREDTRANSACTIONS.INFO
2 | SLOTESITE.INFO
23 | SPORTS-TRANSACTIONS.INFO
21 | SPORTSTRANSACTIONS.INFO
2 | STAR-TU-O.INFO
2 | STARTUOTICKET.INFO
2 | STEELRIM.INFO
29 | TECHTRANSFERACH.INFO
27 | THEACHD.INFO
37 | THEACHF.INFO
28 | THEACHG.INFO
20 | THEACHPI.INFO
31 | THEACHP.INFO
34 | THEACHS.INFO
30 | THEACHT.INFO
26 | THEACHTRANSACTION.INFO
30 | THEACHTRANSFER.INFO
22 | THEACHTRUST.INFO
27 | THEACHU.INFO
29 | THEACHY.INFO
33 | THEACHZ.INFO
34 | THETRANSFERACH.INFO
2 | TOR-MINERALS.INFO
26 | TRANSACTIONSSHOP.INFO
30 | TRANSACTIONSTODAY.INFO
22 | TRANSFERACHACCOUNTS.INFO
25 | TRANSFERACHBLOG.INFO
32 | TRANSFER-ACH.INFO
36 | TRANSFERACH.INFO
34 | TRANSFERACHNOW.INFO
24 | TRANSFERACHONLINE.INFO
33 | TRANSFERACHPAYMENT.INFO
34 | TRANSFERACHPAYMENTS.INFO
33 | TRANSFERACHSHOP.INFO
27 | TRANSFERACHS.INFO
39 | TRANSFERACHSITE.INFO
34 | TRANSFERACHSTORE.INFO
32 | TRANSFERACHTODAY.INFO
41 | TRANSFERADMISSION.INFO
34 | TRANSFERAPPLICANTS.INFO
35 | TRANSFERGUIDE.INFO
36 | TRANSFERGUIDES.INFO
2 | ULXS.INFO
23 | WEALTHTRANSFERACH.INFO
2 | WIRELESS-COMMUNICATIONS.INFO
2 | YMYSTICK.INFO
2 | YOU-LX.INFO
2 | YUM-RESTAURANTS.INFO
2 | YUMTHAI.INFO
(355 rows)

The last domains we saw spammed were slightly after 7 PM (Central time) on Feb 23rd:

NEWACHTRANSFER.INFO
FREEACHY.INFO
ACHUSTORE.INFO
NEWTRANSFERACH.INFO
ACHGNOW.INFO
TRANSFERADMISSION.INFO
ACHPBLOG.INFO
MYACHTRUST.INFO
ACHYS.INFO
THEACHPI.INFO
ACHPSTORE.INFO

all came in between 7 PM and 7:15 PM into the UAB Spam Data Mine.

If you've read some of our Technical Reports then you know that UAB has a unique capability to build "Spam Clusters" of messages related on many different factors. One of our fairly standard checks is to ask "what other spam is coming from the machines that sent us this spam?"

In this case, the answer was NOTHING.

It was as if every single machine that sent this spam message had been uniquely compromised for the sole purpose of sending us this email. Out of 9,610 sending IP addresses, only TWO of them had been seen previously sending spam to the UAB Spam Data Mine. Two Viagra ad from 196.22.14.4 on February 18th and 19th and a set of seven Viagra ads from 112.135.85.114 on February 8th and 9th. The other 9,608 sending IP addresses had not sent us any spam, at least in the past month. That's so unusual that it is actually impossible. There are so many bot-infected computers that randomly selecting any 9,000 internet-connected computers, there is NO CHANCE that none of them sent me spam.

It turns out the spam messages had "dubious header records" inserted.

To explore this deeper, I looked at the headers of 92 email messages I had personally received in this campaign (as opposed to the UAB Spam Data Mine receiving them -- the smaller data set is easier to manipulate for manual or quick scripting review.)

It turned out that the 92 emails, which at first seemed to come from 92 different IPs, actually came from 14 machines, with the most popular ones being:

Received: from static.vdc.vn [113.160.224.168]
Received: from triband-mum-59.184.120.21.mtnl.net.in [59.184.120.21]
Received: from 95.subnet125-164-81.speedy.telkom.net.id [125.164.81.95]

All well known spammer IPs (click links to see their "Project Honeypot" reputations).

While digging deeper, it seems that each of the spam messages was sent while authenticated into gmail. As a quick spot check, I examined the 92 email messages that I received in my personal accounts. Out of the 92, 92 of them had an "envelope-from" and a matching "Return-Path:" statement showing a gmail account that had been used to send the spam message:

(envelope-from abominatingr@gmail.com)
(envelope-from adjournt5@gmail.com)
(envelope-from alwaysw7@gmail.com)
(envelope-from anaestheticsnz556@gmail.com)
(envelope-from analog@gmail.com)
(envelope-from anthropologyi9@gmail.com)
(envelope-from bagateller67@gmail.com)
(envelope-from bawlct1@gmail.com)
(envelope-from beachcombersbdu88@gmail.com)
(envelope-from becomingly001@gmail.com)
(envelope-from belligerency028@gmail.com)
(envelope-from biweekliesqa38@gmail.com)
(envelope-from butteriesldn@gmail.com)
(envelope-from costs@gmail.com)
(envelope-from dependenceq@gmail.com)
(envelope-from dhakatx223@gmail.com)
(envelope-from dismounts05@gmail.com)
(envelope-from distinguishedxe4@gmail.com)
(envelope-from dogwoodui449@gmail.com)
(envelope-from dryadd@gmail.com)
(envelope-from earthworkssmu44@gmail.com)
(envelope-from episodesmf3@gmail.com)
(envelope-from epistolarieskud474@gmail.com)
(envelope-from excusingo6049@gmail.com)
(envelope-from foxtrotteds@gmail.com)
(envelope-from guyinghr6@gmail.com)
(envelope-from hairiestrwv95@gmail.com)
(envelope-from heartbreako0@gmail.com)
(envelope-from helpedcf201@gmail.com)
(envelope-from hotelierpv186@gmail.com)
(envelope-from importunitymn2@gmail.com)
(envelope-from indefinites@gmail.com)
(envelope-from indispensably950@gmail.com)
(envelope-from irishwoman0463@gmail.com)
(envelope-from islander18@gmail.com)
(envelope-from kinkedhby9@gmail.com)
(envelope-from knottiestn@gmail.com)
(envelope-from kropotkinci@gmail.com)
(envelope-from litanies0@gmail.com)
(envelope-from locomotivezq84@gmail.com)
(envelope-from lugsfo@gmail.com)
(envelope-from manfullym7@gmail.com)
(envelope-from matzoshl229@gmail.com)
(envelope-from memorizingxf7@gmail.com)
(envelope-from micronsv1@gmail.com)
(envelope-from mines2@gmail.com)
(envelope-from morerkc896@gmail.com)
(envelope-from murkierp9@gmail.com)
(envelope-from northwesterlyl4@gmail.com)
(envelope-from orbiting4@gmail.com)
(envelope-from organsgqz3@gmail.com)
(envelope-from painfullerujt3@gmail.com)
(envelope-from paltryr63@gmail.com)
(envelope-from phwpa1@gmail.com)
(envelope-from pincushionsl206@gmail.com)
(envelope-from polyglotsxn51@gmail.com)
(envelope-from prohibitorys49@gmail.com)
(envelope-from queenslandpu9@gmail.com)
(envelope-from refracting05@gmail.com)
(envelope-from repaymentsrdr@gmail.com)
(envelope-from rerouteso6@gmail.com)
(envelope-from reselljucd@gmail.com)
(envelope-from rhinestoneo@gmail.com)
(envelope-from ricksjn@gmail.com)
(envelope-from ridgepolem843@gmail.com)
(envelope-from sandieruj@gmail.com)
(envelope-from scabbedl6@gmail.com)
(envelope-from septuagenarians8917@gmail.com)
(envelope-from siberiat1@gmail.com)
(envelope-from slumberad148@gmail.com)
(envelope-from soldieringr7065@gmail.com)
(envelope-from solemnizedo36@gmail.com)
(envelope-from soliloquizese3@gmail.com)
(envelope-from southernersh477@gmail.com)
(envelope-from speedilyby98@gmail.com)
(envelope-from spokes356@gmail.com)
(envelope-from subsidiaryuzxs5@gmail.com)
(envelope-from surmountableoa062@gmail.com)
(envelope-from ternsz27@gmail.com)
(envelope-from thingslq@gmail.com)
(envelope-from totalitiest2@gmail.com)
(envelope-from tuberous37@gmail.com)
(envelope-from ufab3@gmail.com)
(envelope-from undergo@gmail.com)
(envelope-from undertakenf5@gmail.com)
(envelope-from undyingp8344@gmail.com)
(envelope-from unquestionablyww4@gmail.com)
(envelope-from untestedslq4201@gmail.com)
(envelope-from vegemitebe042@gmail.com)
(envelope-from victoriouswyt3@gmail.com)
(envelope-from warmheartedw4@gmail.com)
(envelope-from writhe78@gmail.com)

Sunday, January 30, 2011

Anonymous DDOSers Arrested and Searched

Back in December we shared a couple blog stories about a cyber attack being called Operation Payback. In the first, Internet Anarchy: Anonymous Crowds Flex Their Muscles I discussed with UAB Justice Sciences Chair, John Sloan, some of the sociology behind these actions, especially the ideas of Diffuse Crowds and Convergence Theory. In the second article, Operation Payback Origins we dug deeper into the activities of the group behind Operation Payback, a group tied back to the internet forums at 4Chan who call themselves Anonymous. On Friday, the FBI and other law enforcement agencies around the world began to show their hand.

In a January 27th FBI press release, the FBI announced that they had conducted forty search warrants around the country to gain evidence to identify some of the key US-based actors behind the DDOS attacks. They also revealed that IDS signatures had been shared with many of the key Internet Service Providers in the country to help them identify which of their subscribers were using a DDOS attack tool called LOIC. The press release contained a warning as well:

The FBI also is reminding the public that facilitating or conducting a DDoS attack is illegal, punishable by up to 10 years in prison, as well as exposing participants to significant civil liability.


The LOIC, or Low Orbit Ion Cannon, is a tool reminiscent of the tools distributed during the controversy surrounding the Iranian Elections. We wrote about those in an article called Armchair CyberWarriors, Twitter, and the Iran Election. In the DDOS tools of ancient days (five to ten years ago -- "ancient" in Internet years), DDOS attacks were performed primarily by hacking many home computers to form a botnet, and then instructing those computers to overwhelm a target by generating massive amounts of traffic towards that target. These attacks are called a "Distributed Denial of Service" attack, or DDOS. What changed with Iran was that many individuals were being invited to join the attack by intentionally installing DDOS software on their machines.

So, who are the forty FBI search warrants served against? We won't know for a while. In the United States, a search warrant is an investigative tool, used upon demonstration of "probable cause" to gather further information that will be used to create an indictment. While law enforcement agencies typically do not identify who search warrants have been served upon, it is quite often the case, especially in protests such as this, that those served may choose to share that information to begin rallying public support for their upcoming case. If the search warrant and other information gathered provides sufficient evidence to conclusively identify a criminal and document the crimes they have performed, the law enforcement agency will ask the prosecutor's office for an indictment. (In Federal cases, this would be a prosecutor at a United States Attorney's Office, usually chosen because a significant victim or a significant number of victims are located in their jurisdiction.) Even once the indictment has been issued, it is not unusual for the indictment to be "sealed" until the accused are arrested and have had a chance to appoint an attorney and to be "arraigned" when their charges are formally presented to them in a court setting. In some other countries, such as England, the law enforcement agencies are not allowed to name the accused so early in the case.

Speaking of England, they executed their own action against the Anonymous DDOSers of Operation Payback this week. The UK's Metropolitan Police released a statement about the arrests that shared the following details:

Detectives from the Metropolitan Police Service's Police Central e-Crime Unit (PCeU) have arrested five people in connection with offences under the Computer Misuse Act 1990. The five males aged, 15, 16, 19, 20 and 26, are being held after a series of coordinated arrests at residential addresses in the West Midlands, Northants, Herts, Surrey and London at 07:00hrs today (27 January).


Anonymous responded in an Open Letter to the UK Police saying

Not only does it reveal the fact that you do not seem to understand the present-day political and technological reality, we also take this as a serious declaration of war from yourself, the UK government, to us, Anonymous, the people.


and continuing:
So our advice to you, the UK government, is to take this statement as a serious warning from the citizens of the world. We will not rest until our fellow anon protesters have been released.


These were not the first DDOSers arrested in this case. The Dutch were the first to make an arrest. First, one of the AnonOps spokespersons screwed up and left their name embedded in a PDF that they used for a press release. Alex Tapanaris and his website both disappeared the same day, as reported by Open Topic which shares a PDF showing the properties and the text of that press release. The website "TorrentFreak" posted speculations about the online monicker of the next Dutch hacker, also arrested back on December 10th. These arrests lead the AnonOps attackers (Anonymous Operations = AnonOps) to then attack the Dutch Ministry of Justice.

How This Will Go Down


Obviously no one can say exactly how these cases will go down, but a brief look at history should help the current miscreants understand what they are likely to face.

AnonOps conveniently forgets to tell people about others in their little cyber protest army who have been arrested for DDOS attacks in the past. Dmitry Guzner, age 19, was the first. New Jersey-based Dmitry Guzner received a 366 day sentence for his involvement in DDOS attacks sponsored by 4Chan's Anonymous against the Church of Scientology. Right on his heels was Brian Thomas Mettenbrink of Grand Island, Nebraska. Brian pleaded guilty to also being involved in the DDOS, and as part of his guilty plea "only" received a one year sentence. (Thanks to @lconstantin of Softpedia for reminding us of those prior examples.)

To put this in perspective, that's two hackers getting a year in jail each for attacking the Church of Scientology and causing "approximately $5,000 in damages." How much do you suppose the damage was for taking Mastercard and Visa offline?

Those who are choosing to involve themselves in this criminal behavior should take a look at the record of those who have gone before them before choosing to pick up their own criminal records.

Here's some more reading for those interested in becoming criminals, spending a year in prison, and paying between $20,000 and $37,000 of their own money by participating in an AnonOps DDOS:

Dmitriy Guzner's Guilty Plea

Dmitriy Guzner's Sentencing Documents

Brian Mettenbrink's Indictment

Brian Mettenbrink's Guilty Plea

Brian Mettenbrink's Sentencing Memo

Brian Mettenbrink's Sentencing documents, Attachments A-E including Brett having to pay the $20,000 fee that Scientology paid to Prolexic for DDOS protection.


Got Updates?


As we learn more about the forty search warrants from public sources, we'll add them here.

The Atlanta Progressive News shares that one of the Search warrants was executed at a Georgia Tech Dorm room belonging to Zhiwei "Jack" Chen.

Drifters Bar in Dixon Illinois was also searched during this investigation. The bar's computer was disassembled and the hard drive imaged, but it is believed the computer sought probably belonged to a patron who was taking advantage of the free WiFi to participate in Operation Payback.

The Guardian reveals that the UK 20 year old mentioned above is Chris Wood, who uses the AnonOps alias ColdBlood.