Saturday, May 19, 2012

What about the Social Security Numbers? (The Utah Data Breach and your SSN)

The Utah Data Breach

This week the continuing saga of the Utah Medicaid Data Breach continued to unfold.

If you haven't been following the story, here's the play-by-play:

That is an amazing story. Remember that Utah only has 2.8 million people according to the US Census. So in this single data breach 28% of the residents of Utah had their personal information stolen from them, and 10% of them had their Social Security Number stolen.

The good news, if there is any, is that Utah is now Very Serious about Identity Theft, launching its new IRIS: Identity Theft Reporting Information System in response. What will it take for the other states to get serious about identity theft?

What About Social Security Numbers?

The Utah story was only intended to be a vehicle for asking this question. What are we doing about Social Security Number theft? If hackers get your password, you can have your password reset. If hackers steal your credit card number, the bank will issue you a new one. If your bank account is breached, it is not uncommon to have the bank CLOSE your account and open a new account for you. But what if you the hackers steal your Social Security Number?

The first place that seemed reasonable to check was the Social Security website. They have a page about Identity Theft called Identity Theft and Your Social Security Number (SSA Publication No. 05-10064, ICN 463270, August 2009).

That form asks "What if an identity thief is creating credit problems for you?" and answers the question:

If someone has misused your Social Security number or other personal information to create credit or other problems for you, Social Security cannot resolve these problems.

They have several recommendations:

But read on . . . IT IS POSSIBLE to get a new Social Security Number, and Social Security will work with you to do that IF YOUR NUMBER IS BEING ACTIVELY ABUSED, but they warn that getting a new number may actually be worse than the abuse. For example, in the United States, the key to your credit history is your Social Security Number. If you get a new number, congratulations, you now have Zero Credit History. You won't be able to get a credit card or a loan without a lengthy ordeal or a co-signer.

So what is the answer? Despite all the controversy, it may be time to go back to the discussion of a National Identity Card. I visited Spain last summer and my banking security friends marveled at how the US clung to our antiquated system. They have a National Identity Card (DNI - Documento nacional de identidad) that is carried at all times. The chip in the card contains a digitized version of a photo of the bearer, plus a digital version of their signature and finger prints! There is no value to having only the Number -- my friend who was explaining it to me said you can write your number on your business cards, because there is NOTHING ANYONE CAN DO by simply having the number. It is the CARD that has value. If you have my number, but not the chip in my card, it is worthless to you.

I'd like to see this discussion move forward. If criminals don't already have your Social Security Number, it is certainly only a matter of time. Even if it is only a theoretical question right now, it is extremely likely that this question will be a personal matter to you or someone you love in the near future.

Especially if you live in Utah.

Lessons from the First Cyber Cops

I was so excited to see Bob Gourley's blog post "A Lesson From the First Cyber Cops" which is how I learned about an event on May 16th hosted by the Atlantic Council. As part of a program called the Cyber Statecraft Initiative, Jason Healey moderated a discussion called: ”Lessons from Our Cyber Past: The First Cyber Cops”.

The panelists were all people that I have met and been very impressed with over the years: Steven Chabinsky was the lawyer who served as Senior Counsel to FBI's Cyber Division and advised our InfraGard national board when I served in 2002-2003. He was the first lawyer I met who actually understood what cyber was all about. He's currently the Assistant Deputy Director of National Intelligence for Cyber.

Shawn Henry, former FBI Executive Assistant Director of Criminal, Cyber, Response, and Services Branch, and now a principal at CrowdStrike. I saw him last sharing his passion for the InfraGard program up in DC last November.

Christopher Painter, the Coordinator for Cyber Issues at State and former U.S. Attorney, Computer Crime and Intellectual Property Section of the Department of Justice, who I first met as I was learning about the "24/7 network" of international information sharing that he helped to build.

What I've done here is listened to the audio recording of this panel session, and done my best to accurately transcribe what I heard. I think you'll find it as fascinating as I did, but encourage you to Listen to the MP3 if you have time. There were about forty minutes of Q&A from the audience at the end that I have not transcribed. Any errors in transcription are mine, please take this as "gary's notes" and use the MP3 as your authoritative source.

Getting Started in CyberCrime Investigations

Q: What got you started in Cybercrime?

A: (Chris Painter) Always interested in technology, while I was in college and law school. In 1991 went to the US Attorney's office in California. This was before the web, but many companies, and the government, and the military and others were certainly relying on computers.

I was working with Scott Charney who had started the first Computer Crime unit. There were several companies experiencing theft of source code, including cellular phone companies, and the University of Southern California, where they had data losses, but also someone storing stolen data there. That turned out to be Kevin Mitnick. We had great FBI agents here, Trent Teyema, Ken McGuire and others. In the course of investigating Kevin, I had to learn Linux, and how to review log files. Worked with the first Stock manipulation cases, the first eBay case, which was the Mafia Boy DDOS case, which was the first case I worked with Shawn on. Back in that day a plane was circling the court house with a banner reading "FREE KEVIN!"

A: (Steven Chabinsky) The way I got into computers was with games. In 1979 or 1980 I had a cousin that had a TRS-80. He was signing in to a service called "The Source" and he allowed me to play "Adventure". One of those games where you typed "Turn Right" and it says "You see a nasty elf, what do you do?" and you type "Fight Elf" and it says "The nasty elf killed you!" I was fascinated. I was the kid that worked every day after school, not to save money to buy a car, but to buy an Apple computer. The one I wanted was 1200 bucks and it didn't come with a floppy drive. A floppy drive was another 400 bucks. It came with 48k. I had to buy another 16k just to be able to program, in Fortran at the time. I end up joining the FBI. Fast forward. In 1998 President Clinton had PDD-63, and the FBI was put in the lead of the National Infrastructure Protection Center. The concept was that multi-agency and private sector had to work together. They needed another lawyer, and I raised my hand immediately. It had to do with Cyber. In 1996, Cleveland, Columbus, and Toledo had started InfraGard. I really need your help. How would we nationalize this program? We took this group of a couple hundred people and today it has 50,000 members. The FBI only has 30,000 members. After September 11th, it grew to be beyond Cyber and to include Critical Infrastructure. And in that time I began to give legal advice, and began to give legal advice on all sorts of intrusion cases, which is how I met Shawn Henry.

A: (Shawn Henry) I'm honored to be with two of my closest friends. Our relationships developed because we were on the front line in this space in 1999 and 2000. There were not a lot of things known at this time. I latched on to these two attorneys who were working in this space and who were most importantly innovative. My start was very similar to Steve's only instead of playing with an elf, mine was Star Trek. You see a Klingon ship. Turn right. That was my interest as a freshman in high school. When I joined the Bureau there were some linux courses and cyber courses available and I took them. There was a vacancy as Chief of the Cyber Investigations Unit and this was a natural route for me to take.. I had spent a couple years at headquarters as a supervisor. I wanted to take the things we did in the physical world, the things we learned fighting organized crime and terrorist groups, white collar crime, and apply them in the Cyber realm. I had a lot of experience using authorized intercepts, wiretaps, informants, that sort of thing. This was 1998. I remember sitting there with Steve in the command post at 11:59 PM on New Year's Eve watching the countdown, 9, 8, 7, ... when it hit zero, the lights went off. Because someone had flipped the switch off as a prank. But Steve and I started working the very first undercover case in the Computer Intrusion environment. We had hundreds of cases at the time but we had never used this technique. It was the first time Steve and I had met to chat about the legal consequences. We had an undercover agent who joined a hacking group, who actually did some hacking - all segmented and legally authorized - it gave us great insight into the group and is now common practice for us. That would have been February or March of 2000. We did get a prosecution, but I can't say what group.

What were the Wake Up Call events?

Q: The DOD has been through several "wake up call" events, the latest being Buckshot Yankee. Has DOJ been through that as well?

A: (Steve) Yes, with Solar Sunrise we see military computers, .mil computers, being intruded upon coming from abroad. It was happening during the conflict with Iraq. The traffic is coming in from a middle eastern country, and it really looks like this is an attack coming from a nation state. There was the obvious real possibility that we were under attack. If we are, how do we handle attribution, how do we respond. Of course the FBI does their investigations constitutionally, by the rules, regulations, statutes, and constitutional requirements of the US, not traveling easily in ways that would impact the sovereignty of other nations. Dealing with probable cause and beyond a reasonable doubt. Is there enough to justify a military response. We were at the table saying that we don't think there is enough attribution at this time. Of course we know the end of the story. A couple kids in Cloverdale, California, working with a young adult in Israel, purposely routing their traffic to make it appear to be coming from another country. (Gar-note: we blogged about The Analyzer, the Israeli in Solar Sunrise.) What was the moral of the story? Our .mil had been intruded upon. It could have been used to launch attacks on other countries. Will our adversaries show the same restraint if they were to see our computers attacking them? Another incident involved the White House, getting all the named players on a teleconference, this was before DHS. A large botnet, a very large botnet was being assembled - is it possible that it is being grown to attack the United States? Well, no, in the end it was being used for click fraud. (Laughter) Yes, your reaction, it becomes comical. But at the time, you can't anticipate the end of the story while you are in the middle of it. Early on we were thinking an attacks was coming from your country, but now its gone to the other extreme, there is such poor attribution that the problem has resolved itself. We're better at understanding the motives of events. We don't have White House calls about these incidents any more.

A: (Chris) You asked about wake up calls, we've had several, but they are like wake up calls with a snooze button. It gets attention briefly and then we go back to sleep. Back in 2000 when we saw these big botnets being built, we thought this was going to be how the criminals took down everything. But then we started seeing the large DDOS events against media companies like CNN. They got a lot of media attention, it took a few months, but we found him and it turned out to be a 13 year old boy, MafiaBoy, living in Canada. At the time we were saying "This must be a nation state! It's too sophisticated, it couldn't be an individual." RCMP monitored his communications back to his house. The father was ordering a hit on one of his colleagues, so it was Mafia Dad and Mafia Boy, great family.

That was one wake up call. Later on you had the commercialization of this with botnets, botherders, and then the lone wolf, lone gunman hackers, who kept a low profile who didn't want to be seen who wanted to steal money or trade secrets from companies and others or having an impact on infrastructure. The early Infrastructure impacts were inadvertent. Some kids playing in a telephone switch who impacted a local airport ... (24:40) ... these all built on each other to create the atmosphere now compared to even five years ago is dramatically different, because of these cases, successful cases that we've talked about and other things that have happened.

A: (Shawn) We haven't had the wake up moment yet globally, and we won't until there are physical implications ramifications of an actual attack. When the lights go off for a period of time, or when people die. Its the equivalent of planes crashing into buildings. People take terrorism seriously when they see blood in the streets. For me the wake up uwas the I Love You virus. Around Valentine's Day, I love you, everyone wants to know who, so they all click on it and have a virus. It had a cascading effect around the world in 24 hours. This is not a United States problem, this is a global problem. In the past it was relatively clear where venue was. We had victims in all 50 states and 56 field offices who all claimed they had venue. I had to decide where, as chief of the unit, where venue was going to be and which field office was going to work that case, and I did it without conferring with the US Attorney's Offices. I gave it to Newark, and their US Attorney's Office jumped on board. When ultimately at the end of the day we identified that this was a young man in the Philippines, he was identified and someone put their arms on him, but in the end the Philippines had no law against what he did. Even though he was identified, even though he caused great economic damage, nothing happened. They arrested him, but then they let him go. The global element here. How do we look at this as an International level. Its an international problems. We need to have consistent laws, consistent strategy. We have to have a consistent understanding. The FBI has now centralized rather than 56 field offices operating independently there is a central command. Headquarters will decide how things get done. We, and not just the FBI, but the community as a whole have become much more strategic in our operations and much more strategic in the execution of our mission.

A: (Steve) Cybercrime has lead in terms of our understanding and Cybersecurity followed on. People were working on cyber crime policy before they were thinking at a policy level about cyber security, partly because of the I love you virus. There was a lot of efforts through the G8 to focus on cybercrime. There was a ministerial meeting back in 1999 where this was pushed as a major initiative. Three legs of a stool, you had to have good capacity to fight these crimes, good laws in place, and the capability to cooperate internationally. The G8 and then the Budapest Convention on Cybercrime, the Council of Europe convention that is still the single item that really deals with these issues. The 24/7 program which started with 8 countries and now has 60 countries. There was a lot of work enhancing the Legat program around the world. It was really good expert work among the cognicenti that has now reached the leadership of these governments.

A: (Shawn) I think you are being modest Chris, because the world looked to you and your colleagues at DOJ. The Philippines ended up updating their laws in just a couple months and the world followed. The Department of Justice put us in a leadership role here. The United States, through the Department of Justice, really put us in place. I haven't seen any cases in the last eight years where we haven't been able to prosecute because the laws were not in place.

A: (Steve) I'll go back to what Shawn said -- Its not about all following the cyber trail. There is the money trail. You have to combine all these things. There are a lot of countries where it is still illegal to do undercover operations. You can react all day long, but if you can't get inside these organizations and bust them down from the inside.

Are We Winning?

Q: It sounds like overall on the cybercrime and law enforcement side in the US, we've made great progress. Are we winning?

A: (Shawn) We are not winning

A: (Steve) But I don't think we are losing. This is why I always hate this question! (Shawn: The State Department!) What are the metrics for winning? How do you measure winning or not winning? Clearly there is much more awareness, there is much more law enforcement resource, there are things like Infragard on the private sector, there is more international awareness of this, but the threat has gotten bigger. Criminal groups, nation states, potentially terrorist actors though we aren't seeing this yet. We clearly are more reactive than we should be and we need to have more capability to fight it. Yes or no.

A: (Shawn) When I say we aren't winning, we are not getting ahead, we are falling behind. We are having impact. We are having success. Through the efforts of the FBI, the Department of Justice, the Intelligence community, and the private sector, we have had impact. We have made arrests, we have identified groups, we have attribution, but we are not getting ahead, we are falling behind. there is more and more data getting pushed, more and more people coming online more subjects getting into this who are realizing opportunities to exploit and to line their pockets, and there are countries getting involved in cyber espionage. We are having successes but we are falling behind.

A: (Chris) We are having successes. I came to this in August of 1998. The private sector is working together, the government and the private sector are working better together. I'm seeing more arrests. Tactically, you can show a chart showing how we've improved. We're doing better, but the threat is outpacing our capabilities. When we look at our strategy - what does success look like? The reason we are getting further behind - early on we saw this as an Internet problem a net-centric threat. Over time we've come to see this is a technology threat. Every aspect of our lives are chip-enabled. The threat is controlled by technology. The vulnerabilities to automobiles there are chips controlling your accelaration chips control your brakes. Can we get in through bluetooth? Biomedical devices - there is software in the insulin pump that allows for remote diagnostic capability. There are chips controlling the flow of insulin into your body. Can we cause that to happen remotely? The researchers say yes. You see the problems with Wireless, purposeful interference and jamming. We are becoming more reliant on inherently vulnerable products and services. So the combination of those two make us as a strategic point, falling further behind. We are getting to a point where we have to reflect on what risk mitigation looks like in this area. Whether our policies that focus predominently on vulnerability mitigation and whether that is a successful long term security model. If you think of most security models they rely on on threat deterrence - the notion that the actor won't act because there will be some deterrant effect. you'll be captured, have some penalty. Here we have a model relying on hardening our targets. That's not how we live in the real world, that's called a fortress. Technologies are not meant to be bunkered down. It's not surprising as we accept technologies that are not fortressed and bunkered down, when we have a risk model that doesn't rely on threat deterrence, we'll fall further behind.

A: (Steve) We have to have both of them. You need to lock your doors which we haven't done a good job of, AND have consequences for the people who break in also. There is a lot more to do on hardening the targets and locking the doors, but you have to do threat reduction and threat deterrence. The question is, If you are a cyber criminal, let's take the criminal element for now, it used to be really costless to you, could route your attacks through other countries, you really wouldn't think there was any chance of getting caught. Most cyber criminals ... There have been some great deterrent cases, Getting deterrence cases out there, undercover cases taken down that make the criminals not trust each other. But there is no perception of risk. The positive side if there is a benefit to the criminal, but there is a neglible chance of getting caught, you aren't going to have an impact.

Lessons Learned?

Q: When I look at DOD, I see them caught up on the same questions they had in the late 90s on organizations, and authorities, and definitions, but when I look at Cybercrime it seems you have made progress beyond all that. What are the most important lessons, and are those lessons being inculcated on the new agents, new attorneys?

A: Understanding the scope of this problem and how it will impact your life. There is an age-old problem that the three of us have dealt with for years, which is that victims won't come forward. There is a sense there is nothing government will do for them. That they would be further victimized, that law enforcement would come in and cart off their computers, that they would suffer public reputational damage if it was found out. We need to move this from the area of cyber intrusions being some special sexy kind of thing, but more like bank robberies in Los Angeles. There were many bank robberies in Los Angeles, but people kept using the banks.

A: There has been dramatic progress in how law enforcement addresses these issues. We are doing much better on not victimizing victims. There were big cases before I got there, a Citibank case ???? (42:15) ??? there were stories early on when the FBI came in and in order to preserve the data we seized the computers. We fixed that right away. We didn't keep repeating that, although the stories continue. We also stopped naming the victims so often. Working with the private sector better. The other issue, a Cuckoo's Egg issue back to Clifford Stoll, where someone says there has been a victimization and you ask how much the damage is and its neglible, 75 cents, you hang up and laugh. (Gar-note: Clifford really did report that someone had used 75 cents of computer time, and then had changed the logs to hide it.) The damage is not obvious, but the threat to infrastructure represented by these intrusions are real. You don't have to wait for a big dollar loss to take an attack seriously. The third area of change is taking information IN THE COURSE Of the investigation, and using that information to help protect victims while the case is still active. Back in the NIPC days, we would literally get on a stage and tell private sector what we knew while proceeding with the investigation. I hear all the time that the FBI wants to keep the problem happening so they can monitor the crime and don't care about the victim. We've done a better job helping law enforcement provide value to the Net Defender while we are proceding against the adversaries.

Q: When we first started, every FBI dude would stand up and say "I don't really understand these computers, I have to ask my granddaughter to help me ..." and every FBI dude would get up and start the pitch that way - but I remember the first time I heard Steve with Kim Perretti talk and realize they really get this stuff.

A: We started really hiring towards this hiring pool. In the 90s we hired attorneys and CPAs for the agent role, but then over time began hiring very brilliant people, who work for major companies patriotic people who sometimes take a cut of 2/3rds of their salaries. We created a career path oriented towards cyber, with 30 unique courses that are evaluated constantly to make sure they are timely.

A: In dealing the victims, we only identified in the Mitnick case the victims by their initials. Bloomberg had a hacker try to extort them, and he came to the FBI and said "screw them, I want to send the message that you can't come threaten me like this." Bloomberg met the guy in London with $250,000 with two of his colleagues who were actually a Metropolitan Police officer and an FBI agent who proceeded to lock up these two Kazikstanis and bring them back to New York. (See: Zezov case for details)


Q&A Session

Friday, May 18, 2012

Social Engineering: Facebook Photo

Please welcome a guest-blogger, Sarah Turner, who authored today's report. Sarah is a malware analyst in the UAB Computer Forensics Research Laboratory and is the editor of our daily "Emerging Threats By Email" report. I asked her to put together an article about a prevalent spam campaign that has been running wild for about a month now. While the HISTORICAL malware described below is fairly well detected, each morning when a new version has come out the detection has been low, with improvement over the next 24-48 hours. If you see a message like this, RESIST TEMPTATION! DO NOT CLICK!

_-_
gar

Social Engineering: Facebook Photo

Guest blogger: Sarah Turner

This campaign utilizes social engineering containing subject lines that insinuate a photo is enclosed that was obtained from a social media site or public domain depicting the recipient or the ex girlfriend of the recipient in a scandalous or otherwise embarrassing predicament.

The campaign only uses 8 subjects, shown below.

  • FW:Check the attachment you have to react somehow to this picture
  • FW:They killed your privacy man your photo is all over facebook! NAKED!
  • FW:Why did you put this photo online?
  • FW:You HAVE to check this photo in attachment man
  • RE:Check the attachment you have to react somehow to this picture
  • RE:They killed your privacy man your photo is all over facebook! NAKED!
  • RE:Why did you put this photo online?
  • RE:You HAVE to check this photo in attachment man

The email body can vary between the 3 samples shown below:


Hey,
I have a question-have you seen this picture of yours in attachment?? Three facebook friends sent it to me today...why did you put it online? wouldn't it harm your job? what if parents see it? you must be way cooler than I thought about you man :))))

Hate to bother you,
But I really need to ask you - is it you at this picture in attachment? I can't tell you where I got this picture it doesn't actually matter...The question is is it really you???.

I'm sorry,
I got to show you this picture in attachment. I can't tell who gave it to me sorry but this chick looks a lot like your ex-gf. But who's that due??.

all of which encourage the recipient to open the attachment and see the image to which they’re referring. Typically the attachment is in the form of a .ZIP containing an executable, however the attachments received on May 16, 17, and 18, the attachment extension was not as a .ZIP but as “.jpg.exe”.

The first few times this malware was received (April 20 – 23), once it was downloaded and prompted to run, it acted as an AntiVirus Software.

After that, the received malware was identified as Cutwail delivering Zeus. The executable would be prompted to run and there would be no recordable network traffic but multiple changes would be made to your Registry and a new file, named svchost.exe would be added to your computer. The executable received today had a detection of XXXX on Virus Total.

UAB has 11 prominent MD5’s associated with this campaign (and a couple mis-formed files)

count md5_hex
24998  b42cf3d2cc829aba1e771f9517b2b97d (38 of 41 detects at VirusTotal)
21754  57f40166fd7cafe84ef51fe5f7776c51 (21 of 41 detects at VirusTotal)
21011  77e7fc1b2addc8ee5ea74e3592d4ab89 (14 of 41 detects at VirusTotal)
14918  76e144a572b4c52e3ddb8bd860dfbdd9 (36 of 41 detects at VirusTotal)
9562  5dea03a160543724d7cf4adda93a28ae (36 of 41 detects at VirusTotal)
9138  061f96cf8f7713d17e580900ba20c6b4 (31 of 42 detects at VirusTotal)
8286  9badf88e346bd0530d4e5248d2bb2f35 (37 of 42 detects at VirusTotal)
6362  d60bfa876dc382908fbcde1c96d5b95f (36 of 42 detects at VirusTotal)
5604  bf7b30a96dc8be8bbfb826158afb2379 (34 of 42 detects at VirusTotal)
4742  8cc36756d15560335ed53c47bd7cbc5e (36 of 42 detects at VirusTotal)
2538  d6f05da06a26d9d731273a0fa26dd7e1 (12 of 42 detects at VirusTotal)
This campaign was seen for the first time on 4/20/12 and was the top campaign seen today. Below is the full list of days and receipt counts from prior to this week.
receiving_date count
----------------        ------
 2012-04-20      6372
 2012-04-21      20819
 2012-04-22      3182
 2012-04-23      5739
 2012-04-29      14918
 2012-05-03      9252
 2012-05-04      308
 2012-05-06      2
 2012-05-07      9138
 2012-05-08      8286
 2012-05-08      13
 2012-05-11      1279
 2012-05-12      4325
 2012-05-16      7260
 2012-05-17      17053
 2012-05-17      13751
 2012-05-18      4701
 2012-05-18      2538
We have seen at least 6,757 unique IP addresses used to send us copies of this email with one of these malware attachments. When the malware is fresh, as it is each morning in the Emerging Threats By Email report, the detection rates are much lower. For example, here is the status from the May 17th Emerging Threats By Email report: So, yesterday morning when the report was written, that version of the malware had 7 detects, although as of this writing it has 14.

Nichole Michelle Merzi of Operation Phish Phry gets 5 years

Back in 2009, this blog ran the story FBI's Biggest Domestic Phishing Bust documenting Operation Phish Phry and explaining what was then known of the structure of an international phishing operation with more than 100 members. Yesterday Nichole Michelle Merzi, one of the ring-leaders, was finally sentenced to five years:
Defendant is committed on Counts 1, 34, 35, 38, 39, 48, and 51 of the Indictment to the Bureau of Prisons for 36 months. This term consists of 36 months on each of Counts 1, 34, 35, 38, 39, and 51; 36 months on Count 48, to be served concurrently; and 24 months on Count 46, to be served consecutively; for a total of 60 months. Defendant shall receive credit for any time served. Supervised release for three years.
The case began all the way back on September 30, 2009 with the filing of an indictment that charged:
  • Kenneth Joseph Lucas (1) count(s) 1-9,
  • Nichole Michelle Merzi (2) count(s) 1,
  • Jonathan Preston Clark (3) count(s) 1,
  • Jarrod Michael Akers (4) count(s) 1,
  • Kyle Wendell Akers (5) count(s) 1,
  • Wayne Edwards Arbaugh (6) count(s) 1-2,
  • Demorris Brooks (7) count(s) 1,
  • Antonio Late Colson (8) count(s) 1,
  • Kenneth Crews (9) count(s) 1,
  • Manu T Fifita (10) count(s) 1,
  • Jennifer Anabelle Lopez Gonzalez (11) count(s) 1, 7-9,
  • Tinika Sabrina Gunn (12) count(s) 1,
  • Jason Marcellus Jenkins (13) count(s) 1,
  • Sylvia Johnson (14) count(s) 1,
  • Remar Ahmir Lawton (15) count(s) 1,
  • Kyle Brandon Martin (16) count(s) 1,
  • Franklin Anthony Ragsdale (17) count(s) 1, 4-6,
  • Steven Aaron Saunders (18) count(s) 1,
  • Rynn Spencer (19) count(s) 1,
  • Raquel Raffi Varjabedian (20) count(s) 1,
  • Candace Marie Zie (21) count(s) 1,
  • Ashley A Ager (22) count(s) 1,
  • Latina Shaneka Black (23) count(s) 1,
  • Michael Dominick Gunn Dacosta, Jr (24) count(s) 1,
  • Virgil Phillip Daniels (25) count(s) 1,
  • Tramond S Davis (26) count(s) 1,
  • Shontovia D Debose (27) count(s) 1,
  • Joshua Vincent Fauncher (28) count(s) 1,
  • Krystal Fontenot (29) count(s) 1,
  • Anthony Donnel Fuller (30) count(s) 1, 5-6,
  • Michael Christopher Grier (31) count(s) 1,
  • Bryanna Harrington (32) count(s) 1,
  • Shawn K Jordan (33) count(s) 1-3,
  • Billy Littlejohn Kelly (34) count(s) 1,
  • Reggie B Logan, Jr (35) count(s) 1,
  • Ikinasio Lousiale, Jr (36) count(s) 1,
  • Raymond V Mancillas (37) count(s) 1,
  • David P Mullin (38) count(s) 1,
  • Vincent Nguyen (39) count(s) 1,
  • Ario Plogovii (40) count(s) 1,
  • Brandon R Ross (41) count(s) 1,
  • Alan Elvis St. Pierre (42) count(s) 1,
  • Courtney Monet Sears (43) count(s) 1,
  • Me Arlene Settle (44) count(s) 1,
  • Paula W Sims (45) count(s) 1,
  • Jamie Smith (46) count(s) 1,
  • Brandon Kyle Thomas (47) count(s) 1,
  • Christopher Uhamaka (48) count(s) 1,
  • James Michael Viorato (49) count(s) 1,
  • Jovon Darnell Weems (50) count(s) 1,
  • David D Westbrooks (51) count(s) 1,
  • Bridget Deque Wilkins (52) count(s) 1,
  • Marcus Deshaun Williams (53) count(s) 1.

In a conspiracy, we have to show "Overt Acts" committed by each member of the conspiracy in support of the conspiracy, which is how we end up with an 86 page Operation Phish Phry Indictment.

The indictment charges:

18 USC § 134: Wire and Bank Fraud Conspiracy
18 USC § 1344(1): Bank Fraud
18 USC § 1028A: Aggravated Identity Theft
18 USC § 371: Computer Fraud Conspiracy
18 USC § 1030(a)(4): Computer Fraud
18 USC § 1956(h): Money Laundering Conspiracy
§ 2: Aiding and Abetting and Causing an Act to Be Done

There are 335 Overt Acts charged in the Indictment, such as:

Overt Act No. 14: On July 31, 2008, defendant ZIE sent an SMS message to defendant LUCAS, in Los Angeles County, to transmit the account number and account holder name for the one checking account and one savings account that unindicted coconspirator K.M. opened that day at BOA, which transmission was for the purpose of causing defendant LUCAS, to make and to cause an unauthorized transfer of funds to those accounts and for the purpose of allowing unindicted coconspirator K.M. to withdraw the transferred funds.

Overt Act No. 16: On July 31, 2008, in Los Angeles County, defendant LUCAS caused a computer transfer of funds from a victim bank account at BOA, which neither BOA nor the victim had authorized, into defendant LOGAN's checking and savings accounts.

(In Overt Acts 17 and 18 Logan then withdraws $900 of that money from checking and $400 from savings.)

Overt Act No 70: On August 20, 2008, in Los Angeles County, defendant LUCAS caused computer transfers of $350 from a victim bank account at BOA, which neither BOA nor the victim had authorized, into defendant NGUYEN's checking account and $1,200 from a victim bank account at BOA, which neither BOA nor the victim had authorized, into defendant NGUYEN's savings account.

Overt Act No. 181: On December 11, 2008, in Los Angeles County, defendant JENKINS drove unindicted coconspirator A. J. to a Wells Fargo bank branch located in Los Angeles County to withdraw the $1,000 that defendant LUCAS caused to be deposited into unindicted coconspirator A.J.'s savings account.

Overt Act No. 186: On December 16, 2008, during a telephone conversation with defendant LUCAS< defendant MERZI advised defendant LUCAS that she had caused an unindicited coconspirator to conduct a transfer of funds from a victim bank account at Wells Fargo, which neither Wells Fargo nor the victim had authorized, and next would cause an unauthorized transfer of funds from a victim BOA account.

Overt Act No. 237: On June 14, 2007, in Los Angeles Cou8nty, defendant K. AKERS transmitted $1,900 by Western Union to unindicted coconspirator E. A.


It goes on like that for some 60 pages. From January 2007 to September 2009, the Ringleaders get victim credentials, the second tier transfer the funds around to accounts opened and controlled by the third tier, who then get driven around and sent into banks to take out the money, which gets passed up through management and wired via Western Union to Egypt, with everyone taking a piece of the pie.

For those who are interested in how you argue such a case in court, I've also posted the Operation Phish Phry Closing Arguments Power Point. Hundreds of pages of courtroom transcripts are also available from PACER.

Thursday, May 10, 2012

IRS Identity Theft leads to 25 year Sentence for Alabama Fraudsters

The news in Alabama today is that IDENTITY THEFT DOES NOT PAY. Veronica Dale of Montgomery, Alabama was sentenced to 334 months in prison and Alchico Grant of Lowndes County, Alabama was sentenced to 310 months in prison after the two participated in a scheme to file more than 500 fraudulent tax returns and steal from the IRS $3,741,908! The two will also have to pay $2.8 Million in restitution.

The sentences were announced on the main Department of Justice website with the title Leaders of Multi-million Dollar Fraud Ring That Used Stolen Information of Medicaid Recipients Each Sentenced to Over 25 Years in Prison

The charges brought against Veronica Dale include:

CR. NO: 2:10-CR-242-MEF (see see Indictment

18 USC § 286: Conspiracy to Defraud the Government
18 USC § 287: False, Fictitious or Fraudulent Claims
18 USC § 641: Theft of Government Public Money, Property or Records
18 USC § 1028A: Aggravated Identity Theft

CR. NO: 2:11-CR-69-MEF (see see Indictment

18 USC § 1343: Wire Fraud
18 USC § 1028A: Aggravated Identity Theft

In the first case, the defendants were:

Veronica Denise Dale
Alchico Dewayne Grant
Laquanta Grant
Isaac C. Dailey
Leroy Howard

In a superseding indictment filed for crimes that occurred after the first case was already underway, the defendants were:

Melinda Renae Clayton
Alchico Dewayne Grant
Veronica Denise Dale
Stephanie Adams
Valerie Byrd

Veronica owned and operated Dale's Tax Service, a tax preparation business located in Montgomery, Alabama. Looking back, it is likely that opening the Tax Service was just part of the plan to commit these crimes.

Veronica obtained Social Security numbers and names and used them to prepare and file false income tax returns and directed tax refunds to be deposited into accounts controlled by her and her co-defendants.

The bank accounts received at least $2.3 million in tax refunds.

1/21/2009 $4,990
2/14/2009 $5,124
3/6/2009 $7,352
3/15/2009 $10,688
3/15/2009 $10,031
3/15/2009 $10,332>
3/24/2009 $10,636
etc. etc. (the indictment lists 26 filings, but this happened well over 500 times!) Money was deposited into accounts opened in 2008, 2009, and 2010 at Regions Bank in Montgomery, Alabama and Woodforest Bank in Montgomery, Alabama, as well as Alabama State Employees Credit Union, MAX Credit Union. In 2011 additional accounts were opened at Bank of America where several more tax returns were received.

Veronica turned herself in to US Marshall Service on December 17, 2010. Here is the amazing part. AFTER TURNING HERSELF IN, and being released on bail pending trial, SHE KEPT STEALING MONEY FROM THE IRS!!!

The second case (2:11-CR-69-MEF) explains that between approximately January 2011 and April 2011, Dale conspired with Melinda Clayton and others to file an ADDITIONAL 155 fraudulent tax returns, to gather another $494,424 in tax refunds. THIS WAS AFTER DALE HAD ALREADY TURNED HERSELF IN because of the charges in the other case! She "caused to be stored at Clayton's residence thousands of names and social security numbers unlawfully obtained from EDS."

She pleaded guilty October 14, 2011.

The guilty plea (see see the Plea Agreementincludes the fact that "on counts 1,9,10,27 and 28, a 6-level enhancement is warranted because the Defendant's direct participation in the offense involved 250 or more victims.

The guilty plea explains that "Between June 2007 and February 2008, the Defendant worked as a temporary employee at EDS in Montgomery, Alabama. She "was able to and did wrongfully and illegally acquire Medicaid records which included the names, social security numbers, and dates of births of thousands of inviduals who received Medicaid benefits.

Between January 2009 and December 2010, she used these records stolen from EDS to file over 500 false tax returns.

308 of those tax retunrs deposited money into accounts of the Alabama State Employees Credit Union controlled by Betty Washington. The accounts received approximately $1,440,632.40 in false tax refunds.

Friday, May 04, 2012

Waya Nwaki pleads guilty in globe-spanning phishing ring

We often hear complaints from our Banking friends about criminals in Nigeria. Today's story is another example of the truth that in 2012, there is no place left to hide. Back in April 2011, FBI New Jersey presented their case to the Grand Jury in the form of a sealed indictment accusing several criminals of phishing:

Karlis Karklins
Charles Umeh Chidi
Waya Nwaki (AKA Prince Abuja, AKA USAPrince12k)
Osarhieme Uyi Obaygbona (AKA bside)
Marvin Dion HIll (AKA Nyhiar Da Boss, AKA Nihiar Springs)
Alphonsus Osuala
Olaniyi Jones

The case was officially unsealed on January 20, 2012, as the suspects were rounded up, chiefly Olaniyi Jones Makinde, who was arrested that week in Lagos, Nigeria:


(click for original in AfricanSpotlight.com)

Romance: Nigeria Style

Although this is what would normally be thought of as a "Nigerian Scam Ring" many of the players were already in the United States and had been for some time. Olaniyi, pictured above, is better known to Americans as his romantic alter ego, Brenda Stuart (brendastuart@rocketmail.com, age 35, London, b.Feb 21, 1977)

"Brenda" would "fall in love" with various men that "she" met online, and then have various financial hardships which required the men to send money to her overseas accounts. Several "Money Mules" (called "Maga" in the Nigerian lingo) would assist with getting the money back to Jones via Western Union or Moneygram.

According to BekkyBlog Olaniyi Victor Makinde, also known as Andrea Bradley and Olaniyi Jones was originally arrested on September 6, 2011 by FBI agents working with Nigerian authorities on charges brought by the San Francisco division of the FBI related to two marriage scams where he harvested $620,225.04 from two American victims, Marilou Sibbaluca and John Massoni. While waiting in the Olokuta medium prison, he was charged again in the current New Jersey case. According to the blogger, Olanyiy was a recent graduate of the University of Ado Ekiti.

Criminal History in US

Waya Nwaki and Alphonsis Osuala should have been fairly easy to find. Rather than being in Nigeria, they were already in prison in Georgia. They had been arrested in Belvedere, South Carolina all the way back in April 20, 2005. They recruited a "white guy", Douglas Hudson, to go into a bank and cash a check for $2950 in a Bank of America branch while they waited outside in their silver Lincoln Navigator. Later that day they did the same scam, using a copy of the same check, in Aiken, South Carolina. Aiken, who was carrying a counterfeit resident alien card in the name of Steven Ratzlaff, was arrested in the bank by Lieutenant Farmer of the Aiken Department of Public Safety, while his colleague Officer Wilson pulled over the suspicious Lincoln Navigator and searched it, finding $17,000 in cash under the driver's seat, and a fake soda can containing six more copies of the same check. Nwaki was paying Hudosn $500 for each check they succesfully cashed, and theat they had done five successful scams in the previous two days. After being released, they were apparently back on the street for a while before being rearrested in Georgia.

Phishing

The more recent scams were pure phishing. The six US-based codefendants worked with Jones to steal money from Payroll Processors ADP and Intuit as well as several banks. Karklins and Chidi would email phishing and spear-phishing attacks to the banking customers to lure them to phishing sites - fake bank websites that would be used to gather login credentials. As has been a growing trend, some of the credentials were used to do telephone transactions with the banks, instead of trying to use their online systems, which often have more fraud protection in place. Once the money was available, the criminals sent wire transfers to bank accounts in the United States, Mexico, the United Kingdom, Latvia, France, Bulgaria, Russia, and Nigeria. $3.5 million in wire transfers were attempted and $1.3 million were successfully withdrawn. This activity spanned a couple years, beginning at least as early as November 2009, when Karklins was setting up Chase Bank phishing sites. In January 2010 they added an ADP scam, and successfully harvested credentials for at least 27 sets of userids and passwords. These Payroll accounts allowed them to establish imaginary employees in various companies who received payments along with the real employees each payday until they were discovered. Karklins and Chidi would email Nwaki credentials for high value phishing accounts that they came across so that Nwaki could gather the money. It seems they ignored low value balances and focused only on taking the money from the high value accounts. Notices would go to Nwaki such as "28k chase, male, login yourself for check copy." or "CHASE 13.8k = male, age 32" or "BOA Business 25k + mail access". In February 2010, an Regions Bank account operated by defendant Hill was used to wire money to Bulgaria and Latvia. Nwaki also provided login credentials for a "50k drop" that was sent to the Regions account. Of the more than $1.3 million stolen, more than $300,000 of the funds were sent to a J.M. Sovereign Account operated by Jones in Nigeria.

Tuesday, May 01, 2012

Paypal "You Just Sent a Payment" spam leads to malware

A new malicious spam campaign has just launched this morning targeting Paypal users. This malware campaign attempts to "social engineer" users into clicking a link that they know they shouldn't click on! Here's the email:

The criminals believe (and from what we've seen, correctly) that when presented with the news that you just sent $100 to someone from your Paypal account, you will have a panic reaction and click on the link in the email. This is what they are counting on!

As you can see we got quite a few of these this morning:

The destination is NOT going to be Paypal. Don't click on the link, and tell your friends not to click on the link either! If they do, a bad set of malicious actions are set into motion.

This particular version of the campaign just started about 2.5 hours ago. Here are the number of messages we have seen so far:

 count |        mbox         
-------+---------------------
    22 | 2012-05-01 04:00:00
    22 | 2012-05-01 04:15:00
   312 | 2012-05-01 04:30:00
    41 | 2012-05-01 04:45:00
    15 | 2012-05-01 05:00:00
    78 | 2012-05-01 05:15:00
   241 | 2012-05-01 05:30:00
     1 | 2012-05-01 05:45:00
   210 | 2012-05-01 06:00:00
    91 | 2012-05-01 06:15:00
(10 rows)
There are many hundreds of links that may have been advertised in your copy of this email, but don't click on ANY of them!

In the example case that we checked, we followed a link to "globalsecurityservices.com" (yes, we like irony).

When the web page was visited, it immediately executed two remote javascript files (I've added spaces to "break" them):

script type="text/javascript" src="http:// laxana .org /1VxMC4Dy /js .js"
script type="text/javascript" src="http:// womaametw3 .com /CWTKosSw /js .js"
which redirected to an Exploit server that displayed this "Please Wait" sign while something more malicious was happening in the background.

The exploit kit dropped a Java "JAR" file that was launched in Java, taking advantage of a security hole, which then caused another executable file to download and install on the computer.

What was that executable? We're not sure yet, but your anti-virus product probably doesn't know either. At the time we submitted the malware to VirusTotal there were only 5 of 43 anti-virus products could label the malware as malicious. Although McAfee called it "Zbot" (PWS-Zbot.gen.ya, the anti-virus name for the Zeus Bot) Avast and one other vendor called it "Karagany" (Win32:Karagany-FS [Trj]).

The malware's MD5 was 4f58895af2b8f89bd90092f08fcbd54f and it was 33280 bytes in size.

Here's a link to the original VirusTotal report.

Previous Threats

This link is very closely linked to a "LinkedIn" spam campaign from yesterday. That campaign functioned in exactly the same manner, with the difference only in the spam campaign.

All of the domains listed below have been compromised by an attacker. Most likely the criminals have stolen the FTP userid and password of the criminal, allowing them to change the webmaster's content without the webmaster's knowledge. If you control or know the owner of one of these websites, let them know they have been hacked. They need to remove the content, scan any computers they use to access their website for malware, and change their password AFTER they get the malware cleaned up.

            machine            |         path         
-------------------------------+----------------------
 cpaindia.net                  | /rHFbxKTn/index.html
 dealaddict.ch                 | /bp9ksV54/index.html
 dealaddict.ch                 | /N2rhmW5i/index.html
 dealaddict.ch                 | /r1kVYAfU/index.html
 dealaddict.ch                 | /vpW8hoZ6/index.html
 depilee.com                   | /BzJoVeo0/index.html
 depilee.com                   | /Lskx0Bew/index.html
 depilee.com                   | /NdHgm0gT/index.html
 depilee.com                   | /oZFZ0qJK/index.html
 depilee.com                   | /pD2zHbBB/index.html
 depilee.com                   | /vpW8hoZ6/index.html
 depilee.com                   | /wcE0aK0J/index.html
 depilee.com                   | /wjivLtgo/index.html
 dpsdurgapur.com               | /4RcYf6gB/index.html
 dpsdurgapur.com               | /7QLZuMme/index.html
 dpsdurgapur.com               | /bp9ksV54/index.html
 dpsdurgapur.com               | /BzJoVeo0/index.html
 dpsdurgapur.com               | /ErmgUouT/index.html
 dpsdurgapur.com               | /gj1W42Ee/index.html
 dpsdurgapur.com               | /i8ztSS5H/index.html
 dpsdurgapur.com               | /iaJ7FSBi/index.html
 dpsdurgapur.com               | /mKvc8Mh7/index.html
 dpsdurgapur.com               | /N2rhmW5i/index.html
 dpsdurgapur.com               | /NdHgm0gT/index.html
 dpsdurgapur.com               | /oZFZ0qJK/index.html
 dpsdurgapur.com               | /pD2zHbBB/index.html
 dpsdurgapur.com               | /rHFbxKTn/index.html
 dpsdurgapur.com               | /rzDZAsw7/index.html
 dpsdurgapur.com               | /t7xYVUJE/index.html
 dpsdurgapur.com               | /tLnW6jJT/index.html
 dpsdurgapur.com               | /UAtkgmot/index.html
 dpsdurgapur.com               | /UcL29wrU/index.html
 dpsdurgapur.com               | /vpW8hoZ6/index.html
 dpsdurgapur.com               | /wtQ8G0Ku/index.html
 dpsdurgapur.com               | /YhwvXGhk/index.html
 dpsdurgapur.com               | /zvo8ioak/index.html
 enfoquescreativos.com         | /4RcYf6gB/index.html
 enfoquescreativos.com         | /7NEM56yQ/index.html
 enfoquescreativos.com         | /7QLZuMme/index.html
 enfoquescreativos.com         | /bp9ksV54/index.html
 enfoquescreativos.com         | /BzJoVeo0/index.html
 enfoquescreativos.com         | /ddLvpeMu/index.html
 enfoquescreativos.com         | /DkM4v1PP/index.html
 enfoquescreativos.com         | /gj1W42Ee/index.html
 enfoquescreativos.com         | /N2rhmW5i/index.html
 enfoquescreativos.com         | /oZFZ0qJK/index.html
 enfoquescreativos.com         | /r1kVYAfU/index.html
 enfoquescreativos.com         | /Re3BMGVG/index.html
 enfoquescreativos.com         | /rHFbxKTn/index.html
 enfoquescreativos.com         | /RoScD8aq/index.html
 enfoquescreativos.com         | /rzDZAsw7/index.html
 enfoquescreativos.com         | /UAtkgmot/index.html
 enfoquescreativos.com         | /vpW8hoZ6/index.html
 enfoquescreativos.com         | /wjivLtgo/index.html
 enfoquescreativos.com         | /wtQ8G0Ku/index.html
 enfoquescreativos.com         | /YhwvXGhk/index.html
 enfoquescreativos.com         | /zvo8ioak/index.html
 ftp.neez.com.br               | /4RcYf6gB/index.html
 ftp.neez.com.br               | /7NEM56yQ/index.html
 ftp.neez.com.br               | /7QLZuMme/index.html
 ftp.neez.com.br               | /ErmgUouT/index.html
 ftp.neez.com.br               | /gj1W42Ee/index.html
 ftp.neez.com.br               | /mKvc8Mh7/index.html
 ftp.neez.com.br               | /NdHgm0gT/index.html
 ftp.neez.com.br               | /oZFZ0qJK/index.html
 ftp.neez.com.br               | /pSG1s2xs/index.html
 ftp.neez.com.br               | /Re3BMGVG/index.html
 ftp.neez.com.br               | /rzDZAsw7/index.html
 ftp.neez.com.br               | /t7xYVUJE/index.html
 ftp.neez.com.br               | /tLnW6jJT/index.html
 ftp.neez.com.br               | /UAtkgmot/index.html
 ftp.neez.com.br               | /UcL29wrU/index.html
 ftp.neez.com.br               | /wcE0aK0J/index.html
 ftp.neez.com.br               | /xXr3khjG/index.html
 ftp.pousadaesmeralda.com.br   | /4RcYf6gB/index.html
 ftp.pousadaesmeralda.com.br   | /bp9ksV54/index.html
 ftp.pousadaesmeralda.com.br   | /ddLvpeMu/index.html
 ftp.pousadaesmeralda.com.br   | /DkM4v1PP/index.html
 ftp.pousadaesmeralda.com.br   | /gj1W42Ee/index.html
 ftp.pousadaesmeralda.com.br   | /i8ztSS5H/index.html
 ftp.pousadaesmeralda.com.br   | /iaJ7FSBi/index.html
 ftp.pousadaesmeralda.com.br   | /Lskx0Bew/index.html
 ftp.pousadaesmeralda.com.br   | /mKvc8Mh7/index.html
 ftp.pousadaesmeralda.com.br   | /N2rhmW5i/index.html
 ftp.pousadaesmeralda.com.br   | /NdHgm0gT/index.html
 ftp.pousadaesmeralda.com.br   | /oZFZ0qJK/index.html
 ftp.pousadaesmeralda.com.br   | /pD2zHbBB/index.html
 ftp.pousadaesmeralda.com.br   | /pSG1s2xs/index.html
 ftp.pousadaesmeralda.com.br   | /r1kVYAfU/index.html
 ftp.pousadaesmeralda.com.br   | /Re3BMGVG/index.html
 ftp.pousadaesmeralda.com.br   | /rHFbxKTn/index.html
 ftp.pousadaesmeralda.com.br   | /rzDZAsw7/index.html
 ftp.pousadaesmeralda.com.br   | /UcL29wrU/index.html
 ftp.pousadaesmeralda.com.br   | /wcE0aK0J/index.html
 ftp.pousadaesmeralda.com.br   | /wjivLtgo/index.html
 ftp.pousadaesmeralda.com.br   | /wtQ8G0Ku/index.html
 ftppousadaesmeralda.com.br    | /ddLvpeMu/index.html
 ftppousadaesmeralda.com.br    | /Lskx0Bew/index.html
 ftppousadaesmeralda.com.br    | /oZFZ0qJK/index.html
 ftppousadaesmeralda.com.br    | /pSG1s2xs/index.html
 ftppousadaesmeralda.com.br    | /wjivLtgo/index.html
 globesecurityservices.com     | /4RcYf6gB/index.html
 globesecurityservices.com     | /6BrzkppT/index.html
 globesecurityservices.com     | /7NEM56yQ/index.html
 globesecurityservices.com     | /7QLZuMme/index.html
 globesecurityservices.com     | /bp9ksV54/index.html
 globesecurityservices.com     | /BzJoVeo0/index.html
 globesecurityservices.com     | /ddLvpeMu/index.html
 globesecurityservices.com     | /DkM4v1PP/index.html
 globesecurityservices.com     | /ErmgUouT/index.html
 globesecurityservices.com     | /gj1W42Ee/index.html
 globesecurityservices.com     | /i8ztSS5H/index.html
 globesecurityservices.com     | /iaJ7FSBi/index.html
 globesecurityservices.com     | /Lskx0Bew/index.html
 globesecurityservices.com     | /mKvc8Mh7/index.html
 globesecurityservices.com     | /NdHgm0gT/index.html
 globesecurityservices.com     | /oZFZ0qJK/index.html
 globesecurityservices.com     | /pD2zHbBB/index.html
 globesecurityservices.com     | /pSG1s2xs/index.html
 globesecurityservices.com     | /rHFbxKTn/index.html
 globesecurityservices.com     | /RoScD8aq/index.html
 globesecurityservices.com     | /rzDZAsw7/index.html
 globesecurityservices.com     | /t7xYVUJE/index.html
 globesecurityservices.com     | /tLnW6jJT/index.html
 globesecurityservices.com     | /UAtkgmot/index.html
 globesecurityservices.com     | /UcL29wrU/index.html
 globesecurityservices.com     | /vpW8hoZ6/index.html
 globesecurityservices.com     | /wcE0aK0J/index.html
 globesecurityservices.com     | /wjivLtgo/index.html
 globesecurityservices.com     | /wtQ8G0Ku/index.html
 gpureappliances.com           | /4RcYf6gB/index.html
 gpureappliances.com           | /6BrzkppT/index.html
 gpureappliances.com           | /7NEM56yQ/index.html
 gpureappliances.com           | /7QLZuMme/index.html
 gpureappliances.com           | /bp9ksV54/index.html
 gpureappliances.com           | /ddLvpeMu/index.html
 gpureappliances.com           | /DkM4v1PP/index.html
 gpureappliances.com           | /ErmgUouT/index.html
 gpureappliances.com           | /gj1W42Ee/index.html
 gpureappliances.com           | /Lskx0Bew/index.html
 gpureappliances.com           | /N2rhmW5i/index.html
 gpureappliances.com           | /NdHgm0gT/index.html
 gpureappliances.com           | /oZFZ0qJK/index.html
 gpureappliances.com           | /pD2zHbBB/index.html
 gpureappliances.com           | /r1kVYAfU/index.html
 gpureappliances.com           | /rHFbxKTn/index.html
 gpureappliances.com           | /RoScD8aq/index.html
 gpureappliances.com           | /rzDZAsw7/index.html
 gpureappliances.com           | /t7xYVUJE/index.html
 gpureappliances.com           | /UAtkgmot/index.html
 gpureappliances.com           | /vpW8hoZ6/index.html
 gpureappliances.com           | /wcE0aK0J/index.html
 gpureappliances.com           | /wtQ8G0Ku/index.html
 gpureappliances.com           | /xXr3khjG/index.html
 gpureappliances.com           | /YhwvXGhk/index.html
 gpureappliances.com           | /zvo8ioak/index.html
 hitechsystems.org.in          | /4RcYf6gB/index.html
 hitechsystems.org.in          | /7NEM56yQ/index.html
 hitechsystems.org.in          | /7QLZuMme/index.html
 hitechsystems.org.in          | /ddLvpeMu/index.html
 hitechsystems.org.in          | /DkM4v1PP/index.html
 hitechsystems.org.in          | /gj1W42Ee/index.html
 hitechsystems.org.in          | /Lskx0Bew/index.html
 hitechsystems.org.in          | /mKvc8Mh7/index.html
 hitechsystems.org.in          | /N2rhmW5i/index.html
 hitechsystems.org.in          | /NdHgm0gT/index.html
 hitechsystems.org.in          | /oZFZ0qJK/index.html
 hitechsystems.org.in          | /pD2zHbBB/index.html
 hitechsystems.org.in          | /pSG1s2xs/index.html
 hitechsystems.org.in          | /r1kVYAfU/index.html
 hitechsystems.org.in          | /Re3BMGVG/index.html
 hitechsystems.org.in          | /rHFbxKTn/index.html
 hitechsystems.org.in          | /RoScD8aq/index.html
 hitechsystems.org.in          | /rzDZAsw7/index.html
 hitechsystems.org.in          | /t7xYVUJE/index.html
 hitechsystems.org.in          | /UAtkgmot/index.html
 hitechsystems.org.in          | /UcL29wrU/index.html
 hitechsystems.org.in          | /vpW8hoZ6/index.html
 hitechsystems.org.in          | /wcE0aK0J/index.html
 hitechsystems.org.in          | /wjivLtgo/index.html
 hitechsystems.org.in          | /wtQ8G0Ku/index.html
 hitechsystems.org.in          | /xXr3khjG/index.html
 hypernovamedia.com            | /4RcYf6gB/index.html
 hypernovamedia.com            | /6BrzkppT/index.html
 hypernovamedia.com            | /7NEM56yQ/index.html
 hypernovamedia.com            | /7QLZuMme/index.html
 hypernovamedia.com            | /bp9ksV54/index.html
 hypernovamedia.com            | /BzJoVeo0/index.html
 hypernovamedia.com            | /DkM4v1PP/index.html
 hypernovamedia.com            | /ErmgUouT/index.html
 hypernovamedia.com            | /gj1W42Ee/index.html
 hypernovamedia.com            | /i8ztSS5H/index.html
 hypernovamedia.com            | /iaJ7FSBi/index.html
 hypernovamedia.com            | /Lskx0Bew/index.html
 hypernovamedia.com            | /mKvc8Mh7/index.html
 hypernovamedia.com            | /N2rhmW5i/index.html
 hypernovamedia.com            | /pD2zHbBB/index.html
 hypernovamedia.com            | /pSG1s2xs/index.html
 hypernovamedia.com            | /r1kVYAfU/index.html
 hypernovamedia.com            | /Re3BMGVG/index.html
 hypernovamedia.com            | /RoScD8aq/index.html
 hypernovamedia.com            | /t7xYVUJE/index.html
 hypernovamedia.com            | /tLnW6jJT/index.html
 hypernovamedia.com            | /UAtkgmot/index.html
 hypernovamedia.com            | /UcL29wrU/index.htm
 hypernovamedia.com            | /UcL29wrU/index.html
 hypernovamedia.com            | /vpW8hoZ6/index.html
 hypernovamedia.com            | /wcE0aK0J/index.html
 hypernovamedia.com            | /wjivLtgo/index.html
 hypernovamedia.com            | /xXr3khjG/index.html
 hypernovamedia.com            | /YhwvXGhk/index.html
 hypernovamedia.com            | /zvo8ioak/index.html
 ilabph.com                    | /6BrzkppT/index.html
 ilabph.com                    | /7NEM56yQ/index.html
 ilabph.com                    | /BzJoVeo0/index.html
 ilabph.com                    | /ddLvpeMu/index.html
 ilabph.com                    | /ErmgUouT/index.html
 ilabph.com                    | /gj1W42Ee/index.html
 ilabph.com                    | /i8ztSS5H/index.html
 ilabph.com                    | /iaJ7FSBi/index.html
 ilabph.com                    | /Lskx0Bew/index.html
 ilabph.com                    | /mKvc8Mh7/index.html
 ilabph.com                    | /N2rhmW5i/index.html
 ilabph.com                    | /NdHgm0gT/index.html
 ilabph.com                    | /oZFZ0qJK/index.html
 ilabph.com                    | /pD2zHbBB/index.html
 ilabph.com                    | /pSG1s2xs/index.html
 ilabph.com                    | /r1kVYAfU/index.html
 ilabph.com                    | /Re3BMGVG/index.html
 ilabph.com                    | /rHFbxKTn/index.html
 ilabph.com                    | /RoScD8aq/index.html
 ilabph.com                    | /rzDZAsw7/index.html
 ilabph.com                    | /t7xYVUJE/index.html
 ilabph.com                    | /tLnW6jJT/index.html
 ilabph.com                    | /UAtkgmot/index.html
 ilabph.com                    | /UcL29wrU/index.html
 ilabph.com                    | /vpW8hoZ6/index.html
 ilabph.com                    | /wcE0aK0J/index.html
 ilabph.com                    | /wjivLtgo/index.html
 ilabph.com                    | /wtQ8G0Ku/index.html
 ilabph.com                    | /xXr3khjG/index.html
 ilabph.com                    | /YhwvXGhk/index.html
 jmexy.com                     | /4RcYf6gB/index.html
 jmexy.com                     | /7QLZuMme/index.html
 jmexy.com                     | /BzJoVeo0/index.html
 jmexy.com                     | /ddLvpeMu/index.html
 jmexy.com                     | /DkM4v1PP/index.html
 jmexy.com                     | /ErmgUouT/index.html
 jmexy.com                     | /gj1W42Ee/index.html
 jmexy.com                     | /Lskx0Bew/index.html
 jmexy.com                     | /mKvc8Mh7/index.html
 jmexy.com                     | /N2rhmW5i/index.html
 jmexy.com                     | /NdHgm0gT/index.html
 jmexy.com                     | /r1kVYAfU/index.html
 jmexy.com                     | /Re3BMGVG/index.html
 jmexy.com                     | /rHFbxKTn/index.html
 jmexy.com                     | /RoScD8aq/index.html
 jmexy.com                     | /rzDZAsw7/index.html
 jmexy.com                     | /tLnW6jJT/index.html
 jmexy.com                     | /UAtkgmot/index.html
 jmexy.com                     | /UcL29wrU/index.html
 jmexy.com                     | /vpW8hoZ6/index.html
 jmexy.com                     | /wcE0aK0J/index.html
 jmexy.com                     | /wjivLtgo/index.html
 jmexy.com                     | /wtQ8G0Ku/index.html
 jmexy.com                     | /xXr3khjG/index.html
 jmexy.com                     | /YhwvXGhk/index.html
 jmexy.com                     | /zvo8ioak/index.html
 justinbieber-fans.nixiweb.com | /6BrzkppT/index.html
 justinbieber-fans.nixiweb.com | /7NEM56yQ/index.html
 justinbieber-fans.nixiweb.com | /ddLvpeMu/index.html
 justinbieber-fans.nixiweb.com | /DkM4v1PP/index.html
 justinbieber-fans.nixiweb.com | /ErmgUouT/index.html
 justinbieber-fans.nixiweb.com | /gj1W42Ee/index.html
 justinbieber-fans.nixiweb.com | /iaJ7FSBi/index.html
 justinbieber-fans.nixiweb.com | /Lskx0Bew/index.html
 justinbieber-fans.nixiweb.com | /mKvc8Mh7/index.html
 justinbieber-fans.nixiweb.com | /oZFZ0qJK/index.html
 justinbieber-fans.nixiweb.com | /pD2zHbBB/index.html
 justinbieber-fans.nixiweb.com | /pSG1s2xs/index.html
 justinbieber-fans.nixiweb.com | /Re3BMGVG/index.html
 justinbieber-fans.nixiweb.com | /rHFbxKTn/index.html
 justinbieber-fans.nixiweb.com | /RoScD8aq/index.html
 justinbieber-fans.nixiweb.com | /rzDZAsw7/index.html
 justinbieber-fans.nixiweb.com | /t7xYVUJE/index.html
 justinbieber-fans.nixiweb.com | /UcL29wrU/index.html
 justinbieber-fans.nixiweb.com | /xXr3khjG/index.html
 justinbieber-fans.nixiweb.com | /YhwvXGhk/index.html
 justinbieber-fans.nixiweb.com | /zvo8ioak/index.html
 mangalamcorporation.in        | /4RcYf6gB/index.html
 mangalamcorporation.in        | /6BrzkppT/index.html
 mangalamcorporation.in        | /bp9ksV54/index.html
 mangalamcorporation.in        | /BzJoVeo0/index.html
 mangalamcorporation.in        | /ddLvpeMu/index.html
 mangalamcorporation.in        | /DkM4v1PP/index.html
 mangalamcorporation.in        | /gj1W42Ee/index.html
 mangalamcorporation.in        | /i8ztSS5H/index.html
 mangalamcorporation.in        | /iaJ7FSBi/index.html
 mangalamcorporation.in        | /mKvc8Mh7/index.html
 mangalamcorporation.in        | /N2rhmW5i/index.html
 mangalamcorporation.in        | /NdHgm0gT/index.html
 mangalamcorporation.in        | /oZFZ0qJK/indexhtml
 mangalamcorporation.in        | /oZFZ0qJK/index.html
 mangalamcorporation.in        | /pD2zHbBB/index.html
 mangalamcorporation.in        | /pSG1s2xs/index.html
 mangalamcorporation.in        | /r1kVYAfU/index.html
 mangalamcorporation.in        | /rHFbxKTn/index.html
 mangalamcorporation.in        | /RoScD8aq/index.html
 mangalamcorporation.in        | /rzDZAsw7/index.html
 mangalamcorporation.in        | /UAtkgmot/index.html
 mangalamcorporation.in        | /UcL29wrU/index.html
 mangalamcorporation.in        | /vpW8hoZ6/index.html
 mangalamcorporation.in        | /wcE0aK0J/index.html
 mangalamcorporation.in        | /xXr3khjG/index.html
 mangalamcorporation.in        | /YhwvXGhk/index.html
 mksteslaenergy.com            | /4RcYf6gB/index.html
 mksteslaenergy.com            | /6BrzkppT/index.html
 mksteslaenergy.com            | /7NEM56yQ/index.html
 mksteslaenergy.com            | /BzJoVeo0/index.html
 mksteslaenergy.com            | /ddLvpeMu/index.html
 mksteslaenergy.com            | /DkM4v1PP/index.html
 mksteslaenergy.com            | /ErmgUouT/index.html
 mksteslaenergy.com            | /gj1W42Ee/index.html
 mksteslaenergy.com            | /i8ztSS5H/index.html
 mksteslaenergy.com            | /iaJ7FSBi/index.html
 mksteslaenergy.com            | /mKvc8Mh7/index.html
 mksteslaenergy.com            | /N2rhmW5i/index.html
 mksteslaenergy.com            | /NdHgm0gT/index.html
 mksteslaenergy.com            | /oZFZ0qJK/index.html
 mksteslaenergy.com            | /pD2zHbBB/index.html
 mksteslaenergy.com            | /pSG1s2xs/index.html
 mksteslaenergy.com            | /r1kVYAfU/index.html
 mksteslaenergy.com            | /rzDZAsw7/indexhtml
 mksteslaenergy.com            | /rzDZAsw7/index.html
 mksteslaenergy.com            | /tLnW6jJT/index.html
 mksteslaenergy.com            | /UAtkgmot/index.html
 mksteslaenergy.com            | /UcL29wrU/index.html
 mksteslaenergy.com            | /wcE0aK0J/index.html
 mksteslaenergy.com            | /wjivLtgo/index.html
 mksteslaenergy.com            | /xXr3khjG/index.html
 mksteslaenergy.com            | /YhwvXGhk/index.html
 mpralos.gr                    | /6BrzkppT/index.html
 mpralos.gr                    | /7NEM56yQ/index.html
 mpralos.gr                    | /7QLZuMme/index.html
 mpralos.gr                    | /bp9ksV54/index.html
 mpralos.gr                    | /BzJoVeo0/index.html
 mpralos.gr                    | /ErmgUouT/index.html
 mpralos.gr                    | /gj1W42Ee/index.html
 mpralos.gr                    | /i8ztSS5H/index.html
 mpralos.gr                    | /iaJ7FSBi/index.html
 mpralos.gr                    | /Lskx0Bew/index.html
 mpralos.gr                    | /mKvc8Mh7/index.html
 mpralos.gr                    | /N2rhmW5i/index.html
 mpralos.gr                    | /NdHgm0gT/index.html
 mpralos.gr                    | /oZFZ0qJK/index.html
 mpralos.gr                    | /pD2zHbBB/index.html
 mpralos.gr                    | /pSG1s2xs/index.html
 mpralos.gr                    | /r1kVYAfU/index.html
 mpralos.gr                    | /rHFbxKTn/index.html
 mpralos.gr                    | /rzDZAsw7/index.html
 mpralos.gr                    | /t7xYVUJE/index.html
 mpralos.gr                    | /tLnW6jJT/index.html
 mpralos.gr                    | /UAtkgmot/index.html
 mpralos.gr                    | /UcL29wrU/index.html
 mpralos.gr                    | /wcE0aK0J/index.html
 mpralos.gr                    | /wjivLtgo/index.html
 mpralos.gr                    | /wtQ8G0Ku/index.html
 mpralos.gr                    | /zvo8ioak/index.html
 njsksansthan.com              | /6BrzkppT/index.html
 njsksansthan.com              | /7NEM56yQ/index.html
 njsksansthan.com              | /7QLZuMme/index.html
 njsksansthan.com              | /bp9ksV54/index.html
 njsksansthan.com              | /ddLvpeMu/index.html
 njsksansthan.com              | /DkM4v1PP/index.html
 njsksansthan.com              | /ErmgUouT/index.html
 njsksansthan.com              | /iaJ7FSBi/index.html
 njsksansthan.com              | /Lskx0Bew/index.html
 njsksansthan.com              | /N2rhmW5i/index.html
 njsksansthan.com              | /pD2zHbBB/index.html
 njsksansthan.com              | /Re3BMGVG/index.html
 njsksansthan.com              | /RoScD8aq/index.html
 njsksansthan.com              | /rzDZAsw7/index.html
 njsksansthan.com              | /UcL29wrU/index.html
 njsksansthan.com              | /wtQ8G0Ku/index.html
 njsksansthan.com              | /xXr3khjG/index.html
 njsksansthan.com              | /YhwvXGhk/index.html
 njsksansthan.com              | /zvo8ioak/index.html
 pakwestind.com                | /6BrzkppT/index.html
 pakwestind.com                | /ErmgUouT/index.html
 pakwestind.com                | /i8ztSS5H/index.html
 pakwestind.com                | /NdHgm0gT/index.html
 pakwestind.com                | /oZFZ0qJK/index.html
 pakwestind.com                | /pD2zHbBB/index.html
 pakwestind.com                | /rHFbxKTn/index.html
 pakwestind.com                | /t7xYVUJE/index.html
 pakwestind.com                | /tLnW6jJT/index.html
 pakwestind.com                | /UAtkgmot/index.html
 pakwestind.com                | /UcL29wrU/index.html
 pakwestind.com                | /wcE0aK0J/index.html
 pakwestind.com                | /wtQ8G0Ku/index.html
 punial.com                    | /4RcYf6gB/index.html
 punial.com                    | /7NEM56yQ/index.html
 punial.com                    | /7QLZuMme/index.html
 punial.com                    | /bp9ksV54/index.html
 punial.com                    | /BzJoVeo0/index.html
 punial.com                    | /ErmgUouT/index.html
 punial.com                    | /i8ztSS5H/index.html
 punial.com                    | /NdHgm0gT/index.html
 punial.com                    | /r1kVYAfU/index.html
 punial.com                    | /rHFbxKTn/index.html
 punial.com                    | /RoScD8aq/index.html
 punial.com                    | /t7xYVUJE/index.html
 punial.com                    | /UcL29wrU/index.html
 punial.com                    | /vpW8hoZ6/index.html
 punial.com                    | /xXr3khjG/index.html
 punial.com                    | /zvo8ioak/index.html
 rsons.in                      | /6BrzkppT/index.html
 rsons.in                      | /bp9ksV54/index.html
 rsons.in                      | /DkM4v1PP/index.html
 rsons.in                      | /gj1W42Ee/index.html
 rsons.in                      | /i8ztSS5H/index.html
 rsons.in                      | /mKvc8Mh7/index.html
 rsons.in                      | /r1kVYAfU/index.html
 rsons.in                      | /Re3BMGVG/index.html
 rsons.in                      | /tLnW6jJT/index.html
 rsons.in                      | /UAtkgmot/index.html
 rsons.in                      | /vpW8hoZ6/index.html
 rsons.in                      | /wcE0aK0J/index.html
 rsons.in                      | /wtQ8G0Ku/index.html
 rsons.in                      | /xXr3khjG/index.html
 siniflar.net                  | /4RcYf6gB/index.html
 siniflar.net                  | /ddLvpeMu/index.html
 siniflar.net                  | /ErmgUouT/index.html
 siniflar.net                  | /wjivLtgo/index.html

Thursday, April 26, 2012

SOCA & FBI seize 36 Criminal Credit Card Stores

Today the Serious & Organised Crime Agency (SOCA) in the UK announced the completion of a joint operation targeting 36 criminal websites dealing with stolen credit card and online bank account information. The April 26th Press Release indicates that the operation targeted a particular type of e-commerce platform known as an Automated Vending Cart, or AVC. Here's an advertisement from one of the sites, CVVPlaza.com:

The seized domains are now redirected to a website controlled by the FBI which reads:

The United States Government has seized this domain name pursuant to a seizure warrant issued by the United States District Court for the Eastern District of Virginia under the authority of 18 U.S.C. §§ 981(a)(1)(A) & (b)(2). A United States Magistrate Judge issued that seizure warrant after finding that a sworn affidavit established probable cause that this domain name was personal property involved in a transaction or attempted transaction in violation of section 18 U.S.C. § 1956(a)(2)(A) & (h)
If you registered this domain name, or otherwise claim an ownership interest in this domain name, you should consult an attorney about your rights.


(click for full size)

SOCA has requested that we not provide a full list of the domain names at this time, but two which they have revealed in their own products are "cvvplaza.com" and "ccstore.biz". The others will be added once permission is received.

Some of the screenshots provided by SOCA include:

a site offering an inventory of more than 37,000 confirmed credit cards:

and a fairly nice "search screen:

SOCA has recovered more than 2.5 million card numbers or credentials that they say would have granted the criminals access to more than £500 million (about $809 million US Dollars!) These were NOT the value of the cards currently available for sale in these card shops, but rather the value of the cards that have been recovered from criminals who purchased the cards from these card shops. The total inventory is expected to be much higher. SOCA is leading the way in international cooperation. In this case they worked with the BKA in Germany, the KLPD in the Netherlands, the Ukraine Ministry of Internal Affairs, the Australian Federal Police, the Romanian National Police and of course the FBI in the United States. These recoveries took place over the course of the past two years. The operator of at least one of these AVC stores was arrested in Macedonia by the Macedonian Ministry of the Interior's Cyber Crime Unit. Some online card shops have very simplistic interfaces, such as this: while others have extremely beautiful websites. Check out the login page for this site: Our friend Dancho Danchev has written extensively about the online carding markets, for example in his article: Exposing Market for Stolen Credit Cards. Brian Krebs has also written extensively on the topic with articles such as How much is your identity worth?

Tuesday, April 03, 2012

UK Zeus user G-Zero Sentenced

According to today's Daily Mail, court details have now emerged regarding Edward Pearson, a 23 year old hacker from York, England known online as "G-Zero", and his activities involving the Zeus and SpyEye trojans.

Pearson was ultimately arrested after his girlfriend, Cassandra Mennim, tried to pay for hotel rooms at the Cedar Court Grand Hotel and the Lady Anne Middleton Hotel, both in York, using stolen credit cards. (Pictures of the hotels were in the Daily Mail's original story on this case on February 20 - Computer whizz faces jail for writing programme to steal personal details of 8 MILLION people, including 400 PayPal accounts.

G-Zero Gets Doxed (June 2011)


Although these details are not shared in court, the Hacker world has known who Pearson was for some time ... on June 3, 2011, on the hacker forum "OpenSC.ws" - a site where Trojan authors and botnet herders meet and greet and buy and sell from one another, a user named "cr333k" posted these details. His post read:

"I dedicate this post to ED aka G-Zero because he is the reason I obtained this material" (referring to the leaked version of SpyEye v.1.2.8.0 and v.1.2.99.39).

"So in his honor, I will chase him off the internet."

Cr333k then proceeds to document G-Zero's use of Spyeye, claiming that G-Zero was in charge of the Spyeye servers at 89.149.202.104 [Leaseweb in Germany] and 91.211.11.192 [a serverbox.de account hosted in the UK], and claiming that his main IP address was 178.86.2.40 [a Ukrainian IP], but that he also used the IPs 94.12.53.50 [a SkyNet broadband account in the UK] and 77.103.230.142 [a VirginMedia/Telewest residential cable modem in the UK].

He provides userids and passwords to several of his sites, including the details of his "webnames.ru" account in the name of "GZero" and his hosting.ua account in the name of "rogue2" (with the same password.)

He claimed at that time that his name was Edward Pearson, and that he was in control of the email accounts gzero@9.cn, eddypearson@gmail.com, solipsis@w.cn, cellar@9.cn.

He gave his address as: Edward Pearson, 11 Regatta Court, Oyster Row, Cambridge, Cambridgeshire, cb58ns, UK, and shared his userid and password for his Liberty Reserve online money account

Cr333k claims to have stolen $5500 from Pearson's account...no idea if that is true.

(Eddy also had his superstrong password hash dumped by the guys at Zero For Owned. When they dumped Eddy's details out of the RootCult website after SQL-injection of their database, Eddy's GroundZero password was shown to have an MD5 hash of c8837b23ff8aaa8a2dde915473ce0991. Bad news. That would mean his password was "123321". Not a good password choice for a bad ass hacker. Of course that dump was from 2006, so Eddy would have been ... 17??)

Loose Lips


Probably not a good idea to tie your bad-ass hacker name to your real name in such things as your SoundCloud account (Userid: GZero Name: Edward Pearson, Cambridge, Britain (UK) soundcloud.com/eddypearson

He did the same thing back in 2009 when he was trying to share his online video ripping system on the forum DigitalSpy. His ripper service was distributed from "ripple.net" which he registered with his true personal details, but advertised in the DigitalSpy forum with his hacker handle "GZero".

Domain name: RIZZLE.NET

Administrative Contact:
Pearson, Edward eddypearson@gmail.com
93 Brampton Road
Cambridge, Cambridgeshire CB1 3HJ
GB
+44.7912558447

GZero's post on July 13, 2010 to "HackForums.net" was also pretty interesting:

Alright guys,
Basically I've not been part of the "scene" for many years, long before botnets, around the "how do i hack hotmail?" era. I got very bored of the bunch of rude little pricks that seemed to engulf the place.

Who remembers Zebulun hey? :p

Anyway, I a freelance programmer (C,C++,PHP,Python+many more) and pentester, the legit kind!

I was playing with one of the public copies of the the Zeus botnet, and I have simply fallen in love!

Basically, I'm have all the skills to really do some cool stuff here, coding is my day job, and have until now been working with a private group to make a bit of cash on the side, just not with bots.

Basically, I can do Programming, Custom Hacking, Bulletproof hosting, Setups of anything, FUDding things, Some very sneaky stuff to do with botnet takeovers, CC stuff, Been stealing the latest drive by sploits (NOT the packs), reversing em and then hopefully I'll make a real nice exploit pack if I have the time.

Basically I only just got onto botnets, and I LOVE WHAT I SEE. That said, I have been working with malware, hacking, financial stuff and the darker side of things for many years, just with a group I trust, not involved in the "scene"

Long story short, I want to to talk to people, learn more about the way things are done, and ideally work with somebody, or do some work for them in exchange for a decent copy of Zeus.

Basically, I'm trying to get on this and I have everything else pretty much setup, but I'm just not happy with using a public Zeus. REALLY want to get everything JUUUST right before really get stuck in ;)

MSN me guys, even if you don't have what I want, a interesting discussion is always nice and I'm always nice and helpful. I do have some vaguely private softs to share, but really this is my problem, for this to be GOOD, I need a good bot, and I LOVE Zeus...

MSN:
gzero@9.cn
solipsis@w.cn




8 Million Identities?


According to the police, on one of Pearson's computers they recovered 8,110,474 names with birthdates and postcodes for adults living in the United Kingdom. He also had details of 2,701 credit or debit cards stolen between January 1, 2010 and August 30, 2011.

At one point Pearson used a program he had written in Python to test potential PayPal accounts, and successfully confirmed more than 200,000 PayPal account details.

David Hughes, the prosecutor in the case, says that Pearson also hacked into systems belonging to Nokia and AOL, which caused Nokia to disable certain of its systems for two weeks while it reviewed the intrusion.

(The Nokia intrusion is believed to be the August 2011 SQL Injection of the "developers.nokia.com" website)

Intellectual Challenge?


Although the crown paints Pearson as a criminal mastermind, his defense attorney, Andrew Bodnar, claims that he was not interested in large-scale theft, but considered this merely an intellectual challenge. To support his point, he claims that the total documented theft, despite possession of thousands of cards, was only £2,351 or about $3700 US Dollars, mostly in the form of fastfood orders, pizza, and to pay his cell phone bills.

This is quite a difference between the original charge, that Pearson "plotted a £350,000 fraud" ($560,000 USD).

Mennim's lawyer called her a "vulnerable young woman who found comfort in Pearson following a difficult previous relationship." He describes her as a straight A student who is ashamed of her actions and will pay back the money she owes the hotel.

Pearson was sentenced to two years and two months, and Mennim to 12 months of supervised release. Although Pearson did not SELL the details he had gathered, it was demonstrated that he shared them with other hackers online, and the judge took this into consideration in the sentencing, as she said "Your computers and software were a devastating tool kit. I accept you didn't sell this information, but you shared it with other computer programmers, and you had no way of knowing how THEY might use this information."

The ultimate charges, to which the pair plead guilty:

Pearson - "Making an article for used in fraud and two counts of possession of an article for use in fraud."

Mennim - "Two counts of obtaining services dishonestly."

According to the original charges, the couple were also dealing the drug MDVP, also called "super cocaine". Apparently those charges were dropped. They seem consistent with his lifestyle - for instance, see this post on Cannabis.com from October 2007 where Eddy announces he has just moved to Cambridge and is looking for "connections" via his MSN chat account, eddypearson@gmail.com. This is consistent with some of his HackForums.net posts where he describes himself as "High and Pissed Off".

Saturday, March 31, 2012

USPS Click-N-Ship abused in malware spam

This campaign begins with an email that looks like this:



The email indicates that you have been charged a random amount of money to have a shipping label created. In this case, we were charged $47.44. Because we haven't really ordered a shipping label, we might be upset to be charged, and click the "USPS Click-N-Ship" link that APPEARS to take you to "www.usps.com/clicknship".

In reality, there are more than eight hundred destination webpages on more than one hundred sixty (160) websites were advertised in emails that we saw in the UAB Spam Data Mine that use this template, but none of them go to the United States Postal Service.

A single destination would have many subdirectories, all created by the hacker, that contained the link. For example, this Czech website:

1 | lenkajonasova.chytrak.cz | /1xmg2qrr/index.html
11 | lenkajonasova.chytrak.cz | /9hEetc63/index.html
5 | lenkajonasova.chytrak.cz | /CgeknEwU/index.html
14 | lenkajonasova.chytrak.cz | /FP817PwV/index.html
9 | lenkajonasova.chytrak.cz | /hQLv8GxT/index.html
1 | lenkajonasova.chytrak.cz | /LRt1KuAY/index.html
13 | lenkajonasova.chytrak.cz | /qedwZQiv/index.html
1 | lenkajonasova.chytrak.cz | /rSqvJdhP/index.html

The spam messages use a variety of subjects. The ones we saw yesterday were:

count | subject | sender_domain
-------+--------------------------------------------+---------------
479 | USPS postage labels order confirmation. | usps.com
433 | Your USPS postage charge. | usps.com
428 | USPS postage labels receipt. | usps.com
403 | Your USPS postage labels charge. | usps.com
384 | Your USPS shipment postage labels receipt. | usps.com
346 | USPS postage labels invoice. | usps.com
322 | Your USPS delivery. | usps.com
319 | USPS postage invoice. | usps.com
(8 rows)


This was a very light campaign, compared to many that we have seen recently. We received more than half of these emails in a single 15 minute span ending at 7:15 AM our time - which would be 8:15 AM on the US East Coast. We have the theory that the new spam campaign, with a never-before-seen malware sample, is sent at the beginning of the East Coast day as a way to get maximum infections in places like New York City and Washington DC.


The most common websites, all with their own "random-looking" subdirectories were:
count | machine
-------+----------------------------------
598 | h7xb37qx.utawebhost.at
208 | jadore-events.ro
150 | kissmyname.fr
143 | renkliproje.com
139 | kegelmale.com
138 | layarstudio.com
127 | firemediastd.com
126 | hillside.99k.org
126 | ks306518.kimsufi.com
118 | k-linkinternational.com
113 | graphicdesignamerica.com
112 | hascrafts.com
112 | iaatiaus.org
102 | immodefisc.net

(The rest of the list is at the end of this article...)

A Sample Run


Each day in the UAB Computer Forensics Research Laboratory, students in the MS/CFSM program produce a report shared with the government called the "Emerging Threats By Email" report. They take a prevalent "new threat" in the email from that day and document it's action, in part by infecting themselves with the malware! Here's a sample run through I did this morning using the techniques followed in our daily report.

We begin by visiting a website advertised in the spam. In this case, I chose:

allahverdi.eu (109.235.251.244) /BSg1hNCZ/index.html (400 bytes)

These "email-advertised links" each call javascript files from a variety of other sites. In this example run, visiting the site caused us to load Javascript from the URL below.

uglyd.com/xTnfi7mG (210.193.7.161) / xTnfi7mG/js.js (81 bytes)

This javascript file sets the "document location" for the current browser
window to be "http://178.32.160.255:8080" with a path of showthreat.php
?t = 73a07bcb51f4be71. This is a Black Hole Exploit kit server, which causes the rest of the infection to be continued.)

This is the location my run gave this morning . . . yesterday morning's run used a different Black Hole Exploit Kit location:



178.32.160.255:8080/showthread.php?t=blahblahblah (20,110 bytes)

178.32.160.255:8080/data/Pol.jar (14,740 bytes)

178.32.160.255:8080/q.php?f=4203d&e=0 (dropped calc.exe 151,593 bytes)
MD5 = 44226029540cd2ad401c4051f8dac610
VirusTotal (16/42)

The next two files are dropped because of the Java execution of "Pol.jar".

At the time of the UAB Emerging Threats by Email report on Friday morning March 29th, the Virus Total detections for this malware were "2 of 42". More than 20 hours later the detection is still only "19 of 42".

santacasaitajuba.com.br (200.26.137.121) /WBoTANuY/hBhT7.exe (323,624 bytes)
MD5 = 276dbbb4ae33e9e202249b462eaeb01e
VirusTotal (19/42)

elespacio.telmexla.net.co (200.98.197.103) /sNxQTzEK/bHk6KE.exe (323,624 bytes)
MD5 = 276dbbb4ae33e9e202249b462eaeb01e
VirusTotal (19/42)



The "Zeus file" (the 323,624 byte one) copies itself into a newly created randomly named directory within the current user's "Application Data" directory. In the current run, it disguised itself with a "Notepad" icon, claiming to be "Notepad / Microsoft Corporation" in it's properties. The file was named peix.exe (but that's random also.) The file does an "in place update" so that my MD5 modified without changing the filename. My new MD5 of this morning was:

98202808dea55042a3a1aa2d28ab640a

Which gives a current VirusTotal detection of (14/42):

AntiVir = TR/Crypt.XPACK.Gen
Avast = Win32:Spyware-gen [Spy]
AVG = Zbot.CO
BitDefender = Gen:Variant.Kazy.64187
DrWeb = Trojan.PWS.Panda.1947
F-Secure = Gen:Variant.Kazy.64187
GData = Gen:Variant.Kazy.64174
Kaspersky = Trojan-Dropper.Win32.Injector.dxrh
McAfee = PWS-FADB!98202808DEA5
Microsoft = PWS:WIn32/Zbot.gen!AF
NOD32 = Win32/Spy.Zbot.AAN
Norman = W32/Kryptik.BKR
Rising = Trojan.Win32.Generic.12BDDB90
VIPRE = Trojan.Win32.Generic.pak!cobra

Most of those definitions just mean "Hey! This is Bad! Don't Run It!"

Antivirus companies don't use the same names for most of this stuff as cybercrime investigators. So, for instance, in the Microsoft Lawsuit last week, they described criminals involved with three malware families = Zeus, SpyEye, and IceIX. All of these would show a "Zbot" or "Kazy" detection in the group above. PWS means "Pass Word Stealer." "pak", "XPACK", and "kryptic" just mean that the malware is compressed in a way that implies it is probably malicious.

The bottom line is that this very successful malware distribution campaign has tricked people into installing something from the broader Zeus family (whether Zeus, SpyEye, or IceIX doesn't really matter to the consumer). Once compromised, that computer is going to begin sharing personal financial information with criminals, and allowing remote control access to the computer from anywhere in the world to allow further malicious activity to occur.

This is the kind of malware that was featured on NBC's Rock Center with Brian Williams recently, and that was at the heart of the civil action taken by Microsoft, FS-ISAC, and NACHA that lead to the seizure of many domain names and some servers controlled by Zeus Criminals.



Click to learn more about UAB's Center for Information Assurance and Joint Forensics Research or to learn about UAB's Masters Degree in Computer Forensics & Security Management.




other destinations



98 | made.lu
96 | maceraoyunlari.host.org
88 | kazahana.hanabie.com
85 | kthtu.or.kr
84 | ftp.peratur.com.br
82 | agroturystyka-szczawnica.pl
78 | lenkajonasova.chytrak.cz
77 | ftp.lucpinheiro.com.br
74 | imo213.com
70 | indonesiatravelnow.com
67 | gulfcoastlocalsearch.com
67 | laptopschematic.org
65 | 4realpeople.info
62 | incaltamintepeg.ro
58 | davidanber.com
52 | malibojevnik.si
52 | 188.121.58.196
45 | lcvtv.com
44 | lastrender.com
44 | laserreproducciones.com
44 | lukasz-slaby.pl
41 | 032b67b.netsolhost.com
41 | larryharrison.com
40 | 182.18.152.247
39 | genxlogistics.com
38 | 0317159.netsolhost.com
37 | getprofitsfast.com
37 | kbizzsolutions.com
34 | icon-construction.ca
33 | mariekebrouwers.nl
33 | kgncomputers.com
30 | meinungsmacher.at
21 | heroesandheritage.net
20 | interfinbrok.ro
16 | ecrane.vn
16 | erolkara.net
12 | euro2012bettingtips.com
11 | ftp.tack.sk
11 | stcw95.org
10 | 6111homewood.com
10 | meritmobile.com
10 | ozerresidence.com
10 | ftp.infoesporte.com.br
10 | grossturismo.com.br