Wednesday, June 05, 2013

Vietnamese Carders arrested in MattFeuter.ru case

Eleven Cyber criminals Arrested

I'm always pleased to see international cooperation in cybercrime investigations! This afternoon we received the news from the UK's SOCA, (the Serious Organised Crime Agency) that there were eleven arrests globally in a case involving cooperation from the Vietnamese High-Tech Crime Unit (HTCU), the Criminal Investigative Division of the the Ministry of Public Security of Vietnam (MPSVN CID), SOCA, the Metropolitan Police Central e-Crime Unit (PCeU), and the FBI. Eight criminals were arrested in Vietnam and three additional arrests were made in the UK.

All of these criminals were associated with the "mattfeuter" family of websites (mattfeuter.ru, mattfeuter.cc, mattfeuter.su, mattfeuter.com, etc.) where approximately 16,000 members bought and sold stolen credit card data in bulk. It is believed that purchases from the website had facilitated more than $200M worth of credit card fraud worldwide through the sale of more than 1.1 million credit cards.

SOCA and the PCeU are joining forces to create the new National Crime Agency later this year, but are already performing joint operations such as this investigation in anticipation of the UK's new National Cyber Crime Unit. Andy Archibald, who is the interim Deputy Director of the National Cyber Crime Unit, where the "Dedicated Cheque and Plastic Crime Unit" is housed, had this to say:

“One of the world’s major facilitation networks for online card fraud has been dismantled by this operation, and those engaged in this type of crime should know that that they are neither anonymous, nor beyond the reach of law enforcement agencies. We and our partners, in the UK and abroad, continue to protect the public and legitimate businesses by targeting websites trading in stolen card data, and relentlessly pursuing those who operate and frequent them."

Operations of this nature would not be possible without the support of private sector partners, in this case primarily Visa and MasterCard.

In keeping with UK law, the names of the three arrested there are not given, only their names and locations:

  • 37 year old man from West Ham
  • 34 year old man from Thornton Heath
  • 44 year old man from Manor Park
In the US, the New Jersey US Attorney's office has filed charges on 23 year old Duy Hai Truong, of Ho Chi Minh City, in Vietnam.

Vietnamese media has identified those arrested in Vietnam, and have named as their ringleader Van Tien Tu. The full list of those arrested include:

  • Ngo Thi Quynh Anh
  • Tran Thi Dieu Hien
  • Van Tien Tu
  • Truong Hai Duy
  • Le Van Kieu, those five all from Ho Chi Min City
  • Trinh Khac Duong
  • Dao Ba Bang
  • Doan Van Chuc, those three from Hanoi
The HCM City five are charged with illegally posting and using information from the Internet.

The Hanoi three are charged with using the credit card data for online gambling.

The ringleader, Van Tien Tu, is charged with having created the Mattfeuter websites, where credit cards are sold for between $2 and $20 per card. As the operator of the site, Van Tien Tu and his group earned approximately $1.5 million in commissions on their sales.

Although we haven't yet heard of many cases with Vietnamese cyber crime yet, the improvements in Vietnamese law passed in 2009 made it a criminal offense to fraudulently obtain card dat from overseas targets, as well as from victims in Vietnam.

The New Jersey case focuses on Duy Hai Truong, pictured below:

In a statement from the New Jersey US Attorney's Office, Paul Fishman announced that Truong was charged with "conspiracy to commit bank fraud. From 2007 until his recent arrest, Truong allegedly defrauded financial institutions as part of the massive scheme, in which personal identifying information relating to more than 1.1 million credit cards was stolen and resold to criminal customers worldwide." The New Jersey statement alludes to "arrests made over the past week in the United Kingdom, Vietnam, Italy, Germany, and elsewhere" so I am sure there will be additional news in the near future as the details of the case unfold.

The Official Complaint against Duy Hai Truong reveals that fees on the mattfeuter.biz and mattfeuter.com websites varied from $1 to $300 per "dump" (a dump referring to a magnetic card stripe read from a Credit or Debit Card), and that the fees were usually paid through Western Union or Liberty Reserve.

Truong is being held in Vietnam pending the settlement of charges in the UK, but if convicted in the US, Truong could face up to 30 years in prison and a fine of either $1 million or twice the gain from the offense, or twice the losses caused by the offense, whichever is greater.

New Jersey has also released the Sworn Complaint by FBI Special Agent Russell Ficara, who testifies that he reviewed over 1100 bank accounts and many searches of email accounts, residences, offices, and drop addresses related to this case. His testimony includes many of the email accounts used, including mattfeuter123@gmail.com, augustino267@gmail.com, ho.robbie@gmail.com, and included more than 150,000 email messages with more than 1.1 million credit card numbers being traded, including cards and personally identifiable information (PII) related to many victims residing in New Jersey.

As with so many criminals, Truong also had a Facebook account that referred to his real name, made references to the conspiracy, and contained photos of messages to and from Dump Purchasers and making reference to stolen credit cards!

A single Western Union location "in or around Ho Chi Minh City, Vietnam" was documented to have received more than $1.9 million in payments just related to MTCNs (Money Transfer Control Numbers) documented in the emails from the three referenced accounts, all controlled by Truong.

Monday, May 13, 2013

The Kelihos Botnet: Spam Data Mine + i2 Analyst Notebook

On April 17th & 18th, 2013, we blogged about spammers who were using the Boston Marathon Explosion and the Texas Fertilizer Plant Explosion to dramatically increase the size of their botnet. The botnet in question was the Kelihos botnet, and the primary purpose of the malware being delivered in that two day campaign was to cause newly infected computers to also join the botnet as additional spam-sending computers. Malcovery Security, where I serve as Chief Technologist, put out a free copy of their daily malware "Top Threats Today" report because the prevalence of that spam was nearly 80 times the level that we normally consider to be an "outbreak" of malicious activity.

So, what have the criminals behind Kelihos been doing with all of their new spam-sending power? Primarily they are sending Pump and Dump spam.

Pump & Dump

A Pump and Dump spam campaign is an email that claims a particular stock symbol is going to have a large increase in value in the near future and encourages investors to jump in while the price is still low. These are usually sub-penny stocks where the criminals have arranged to own millions of shares of an existent publicly traded "pink sheets" company. They then do false press releases about new business developments, accompanied with a spam campaign. We've seen stocks rise from 1/5th of a cent to 30 or 40 cents or on rare occasion $1 per share before the criminal dumps his millions of shares for a 10,000% profit. These attacks often coincide with brokerage phishing attacks where a stolen Fidelity account (or something like it) is used to buy the initial shares, or to buy many shares to give the appearance of high market activity in the junk stock to encourage wary investors.

Over the weekend, the Kelihos Pump & Dump target is "GT RL" which they claim is a small movie studio that is primed for an acquisition. In the spam emails they tell the story of an investor who owned 39% of Lions Gate and earned $1 Billion USD when the studio was acquired by a larger organization. GTRL is "Get Real USA, Inc." which claims last summer to have had "Academy Award Nominee Dean Wright" join their board of advisors, according to their website, which is denying any involvement in the current spam run.

On March 4, 2013, GTRL opened the market day trading at $0.0052. Friday it closed at $0.01 on a volume of 1.9 million shares traded. So someone is certainly buying shares!

Why do we care? Primarily because it has been one of the top spam-sending botnets ever since the Boston explosion spam. Yesterday, May 11, we saw a RIDICULOUS number of spam subject lines, all touting this penny stock.

Spam Data Mine

Long time readers will be familiar with the UAB Spam Data Mine. In December, we licensed the Spam Data Mine technology to Malcovery who use the Malcovery Spam Data Mine to identify Today's Top Threats for their customers, based on techniques and methodologies developed at UAB over the past six years. The Spam Data Mine receives in the neighborhood of a million messages per day, which we "parse" to extract key features which are stored in a PostgreSQL database. As we look at the top subjects recently, they have been dominated by Pump & Dump spam. For example, here are some of yesterday's Top Subject lines related to Stock:

  1267 | It is Our New Alert! This Low Float Monster is a Must See
  1203 | You won't beleive your eyes!
  1123 | This Stock is Starting to Heat Up
  1109 | Perfect Time To Add!
  1103 | Our Featured Gem
   804 | It`s official, this stock is a 100% perfect buy!
   621 | There should be outrage against bailouts!
   617 | Things to Know Before Your Next Trade
   574 | Closing out the week with Mega Gains!
   534 | This Stock is moving up as it should
   526 | Exciting Trade Idea Details Inside!
   503 | New Pick Coming Tomorrow, This is a Must Read!
   496 | This Stock is well positioned for another monster run!
   494 | Spectacular bouquets, only $19.99!
   478 | Stocks on watch for mega gains this week!
   460 | This Company IS RED HOT!!!
   458 | This Company is on Immediate Alert! This Bull is Positioning for a Major Run

If we just limit our search to spam that contained the word "Stock" or "Company" in the spam, we had more than 175,000 emails yesterday, using 1,976 subject lines! But how would we know the other subject lines in the campaign? "Perfect Time To Add!" doesn't have the word "Stock" or "Company" in the subject. There is also no guarantee that all of the messages containing these words are part of this spam campaign.

To get a better handle on this, we are going to do a series of queries to build a candidate pool, and then use IBM's i2 Analyst's Notebook to perform what we call "Visual Pre-Clustering" to help us determine some ground truth and to help us screen out some possible outliers. If there are several unrelated botnets all sending Pump and Dump spam, the clusters should be easily identifiable using this technique, while if there are other spam messages unrelated to Pump and Dump being sent by Kelihos, those should also be easily identifiable.

First, let's pile up our data:

Spam Queries to Build a Candidate Data Set

To begin, I'm going to collect a list of IP addresses of computers that sent me spam on May 11, 2013 that used the word "stock" or "company" in their spam message. This query creates a temp table called "may11stockip" that contains the list of IP addresses that sent me those messages and a count of how many times each was used.

spam=> select count(*), sender_ip into may11stockip from spam where (subject ilike '%stock%' or subject ilike '%company%') and receiving_date = '2013-05-11' group by sender_ip order by count desc;
This gave me 27,425 unique addresses. Our next step is to ask the Spam Data Mine for other subjects that were sent by that group of IP addresses. While it is true that I could build one massive query to do all of this work, we've found over time that the temporary tables can be useful to have preserved, and using the temporary tables actual speeds up the final result.

spam=> select count(*), subject into may11stocksub from spam a, may11stockip b where a.sender_ip = b.sender_ip and receiving_date = '2013-05-11' group by subject order by count desc;

This generated 6,420 spam subject lines! Far more than the 1976 that contained the words "stock" or "company"! In fact, given the size of the botnet, it is actually likely that I may have received some spam from computers that DID NOT use the word "stock" or "company", so we'll run one more iteration. Dropping the "may11stockip" table, we rebuild it from any computer that sent a subject found in the new temptable, may11stocksub.

spam=> select count(*), sender_ip into may11stockip from spam a, may11stocksub b where a.subject = b.subject and receiving_date = '2013-05-11' group by sender_ip;

Now we have 93,538 candidate IP addresses to consider as possible Kelihos nodes!

Our last iteration in building our "Pile of Data" to hand to i2 is to create relationships between those 93,538 candidate IP addresses and all of the subjects they used. Our goal is to have a nice table that can be imported into i2 Analyst's Notebook.

spam=> select count(*), a.sender_ip, subject into may11stockpairs from spam a, may11stock b where receiving_date = '2013-05-11' and a.sender_ip = b.sender_ip group by a.sender_ip, subject order by count desc;
This generates 282,763 pairs of "sender_ip x subject".

Visual Pre-Clustering with i2 Analyst's Notebook

From these 282,763 pairs, we're going to let i2 do all the hard work. Here's the basic idea. Let's say we have 4 computers, A, B, C, and D and each of these computers sent an email from the set M1, M2, M3, M4, M5, M6, M7. For the sake of argument, we are going to say that because there is NO CHANCE that the computers would have sent the same email, unless they were CONTROLLED by the same criminal spammer. If we can demonstrate which computers sent the same messages, we could then determine which computers were controlled by the same criminal.

A - M1
A - M2
A - M3
B - M4
B - M5
C - M1
C - M6
C - M7
D - M1
D - M6 
D - M7
If we were to draw a picture of that, just as you see it on the list, it might look like this:

But if we allow i2 to give a more intuitive layout, it would look like this, which makes it very plain that Computers A, C, and D are sending "the same" emails, while Computer B is sending "different" emails.

One Day of Kelihos in i2 Analyst's Notebook

You might say to yourself, "That didn't seem to add much value?" But now imagine that there are 282,763 rows on your list instead of eleven, and that instead of having four computers you have 93,538 and instead of having seven email subjects you have 7,226.

Here's the chart you get when you do that!

or with some labels on it:

Cluster A
The cluster labeled as "A" is our main "Stock Pump & Dump" cluster. All of our "main" Stock and Company subjects are in the heart of that cluster, with many related computers coming from them.

Cluster B
This cluster is primarily formed of spam for "Work at Home" scams. Some sample subjects from this group include:

Ready to be your own boss?
Business Startup
Your second chance in life just arrived
Sick of paying bills?
Wanna pay off your debts?
Stop just barely making ends meet every month
Make Money Online
Wanna Learn how to make money online?
Success Kit
Ill show you the road to early retirement
Successful Business
New Income
Wanna make up to $6500/month?
Job openings in your area!
At Home Income
A living online is easier than you think
Work From Home Jobs Available!

One slight "False join" is linking "A" and "B" and has to be manually eliminated. "Empty Subject" is the only subject in Cluster H hidden in the midst of the Corpus Callosum that joins A and B. After discovering this, we manually deleted that subject from the chart, and re-ordered the chart, after also first removing "disjointed" clusters that had not tie to the core, such as Cluster F and the others at the top, and many of the "Fan-subclusters" such as Cluster I that surrounded Cluster A.

The "Cleaned Up" version of the chart still makes it abundantly clear that THOUSANDS of IP addresses that are part of the "Stock Pump and Dump" cluster on the left are ALSO part of the "Work at Home" (B) and "Pharmacy Express" (C,D,E) clusters on the right. The Cleaned Up chart, shown below, still has 91,833 IP Addresses and 6,242 Email Subjects, with 277,747 unique "pairs" between them.

IP addresses closer to the right have primarily "Work at Home" spam subjects, such as 95.57.242.156:

 count |                 subject                  
-------+------------------------------------------
     2 | TODAY`S TRADING IDEA IS `Advanced`
     1 | Work for Moms
     1 | It moves up nicely on heavy accumulation
     1 | Job Hiring is at an all time low...
     1 | Sick of paying bills?
     1 | Business Startup
(6 rows)

or 31.7.57.214:

 count |               subject               
-------+-------------------------------------
    13 | Successful Business
     1 | Sick of not making ends meet?
     1 | Wanna make up to $6500/month?
     1 | Job Hiring is at an all time low...
     1 | What kind of investor are you?
(5 rows)

IP addresses closer to the left have primarily "Stock Pump and Dump" spam subjects, such as 178.90.148.44:

 count |                                subject                                 
-------+------------------------------------------------------------------------
     5 | This Company is Ready to Run
     5 | It is one to watch this week!
     4 | Analysts gives this stock a "STRONG SPECULATIVE BUY" rating
     4 | New Play Coming
     3 | This Company has a history of Huge Rallies, on verge of another Rally?
     3 | New Wild Breakout Pick Coming TONIGHT!
     3 | The NEW TRADE ALERT
     3 | A Potential Mover from Penny Stock
     3 | It Is Wasting Little Time Making Waves
     2 | This Company Ends Last Week Strong
     2 | Get Ready For The Hottest Gold Pick On The Planet!
     2 | Our New Blazin Sub-Penny Alert!
     1 | Be Ready
     1 | Success Kit
     1 | This Company exploded in volume today
     1 | Second chance for traders who have `calmed down`...
     1 | Sick of a dead end job?
     1 | We`ve Got A Bouncer On Our Hands!
     1 | This Stock Signs Agreement With Reputable PR Agency
     1 | Back to work week will get this play really going!
(20 rows)

The "Bumps" that circle cluster B are groups of IP addresses that share "some but not all" of the subjects found in Cluster B. There are many IP addresses that we saw only once or twice -- because of their low volume, they do not appear as "fully meshed" as the IP addresses in the "core" of Cluster B. A couple examples will demonstrate this.

In the core of Cluster B we see thousands of IP addresses that were used for at least 2 or 3 Work at Home messages:

'59.94.88.82/32'           
-------+-------------------------------
     2 | Successful Business
     1 | Wanna make up to $6500/month?
     1 | Income At Home
'120.60.69.113/32'
 -------+-----------------------------------------------
     1 | Success Kit
     1 | Stop just barely making ends meet every month
'212.62.37.89/32'
-------+-------------------------------
     2 | Success Kit
     1 | Wanna make up to $6500/month?
     1 | Income At Home
'87.241.142.252/32'
-------+------------------------------
     2 | Work for Moms
     1 | Replace your nine to five...
'37.99.26.121/32'
 -------+------------------
     1 | Business Startup
     1 | Success Kit
'2.146.92.235/32'
-------+-----------------------------------------
     1 | Make Money Online
     1 | Your second chance in life just arrived
Small "micro clusters" of IP addresses used for both the "C" or "D" Pharma spam and one or more of the Work at Home subjects fill the ridge between Clusters "B" and "C, D, E":

'176.33.176.120/32'
-------+-----------------------------------------
     1 | ð°ð°ð°Cialis (30 pills 20mg) USD 91.50 & Viagra (30 pills 100mg)  USD 81.90ð°ð°ð°
     1 | ð°ð°ð°Viagra (30 pills 100mg)  USD 81.90 & Cialis (30 pills 20mg) USD 91.50 ð°ð°ð°
     1 | Your second chance in life just arrived
'113.22.157.247/32'
-------+------------------------------
     1 | ð°ð°ð°Cialis (30 pills 20mg) USD 91.50 & Viagra (30 pills 100mg)  USD 81.90ð°ð°ð°
     1 | Replace your nine to five...
     1 | ð°ð°ð°Viagra (30 pills 100mg)  USD 81.90 & Cialis (30 pills 20mg) USD 91.50 ð°ð°ð°

Here are two example IP addresses from a single "Bump" on the left edge of Cluster B.

'190.236.188.41/32'
-------+-----------------------------------------------
     1 | Stop just barely making ends meet every month
'118.68.119.212/32'
-------+-----------------------------------------------
     1 | Stop just barely making ends meet every month

Cluster C, D, and E
These are Viagra Spam clusters. C & D are two very popular subjects, both resolving to "Pharmacy Express" websites. The small cluster "E" is formed of IP addresses that sent spam for both Cluster C and Cluster D.

Cluster F & Friends
Cluster F and the neighboring small clusters at the top of the chart have been included primarily through a coincidental usage of the word "Company" in their subject lines. F, for example, is a well-known spammer of the type the industry calls a "Snowshoe spammer." They rotate through hosted data centers, paying their bills for nice hardware to be used for spamming with stolen credit cards. When they get thrown out of one data center for spamming, they move to the next.

Cluster G & J
These clusters are also primarily joined through the coincidental use of the word "Company" in the subcluster subjects.

Cluster I
There are many "Fan-shapes" around the edges of Cluster A. Looking at Cluster I as an example, there are 36 subjects in that "fan cluster" all related to "Replica goods":

A Rolex replica watch
ALL MAJOR DESIGNER REPLICA WATCHES
Bags
Beautiful quartz, water-resistant Replica watches
Box Sets
Bracelets
Cufflinks
Gold Watches
Gucci Bags
...

Only a single (subject x sender_ip) pair links this fan-cluster to the main Cluster A. The subject "replica watches! rolex, patek philippe, vacheron constantin and others!" which was attached to dozens of IP addresses in the fan-cluster, is also attached to the IP address "201.9.120.242" That IP address also sent us two messages with the email subjects "This Stock Move Starting!".

154 IP addresses in Cluster A also used the subject "This Stock Move Starting!"

To focus on the core activity, disconnected subclusters, such as F, and "fan-clusters" such as I are removed from the chart, and the layout is performed again.

Thursday, May 09, 2013

ATM Cashers in 26 Countries steal $40M

CBS News in New York has a video on their website this morning title Cyber-attacks behind possibly record-breaking bank heist. Former FBI Assistant Director John Miller shares the story and says "We've learned how they carried out this cyber-attack, and it's unlike anything ever seen before."

Except it isn't. In fact, on Tuesday morning this week I was sharing a presentation about financial cyber crimes with Iberia Bank in New Orleans, LA. I mentioned that one of the things that banks still need to be on the lookout for is true "intrusions" into their system. By planting malware on internal bank systems, criminals can gain deep penetrating access to the internal workings of the bank and take their time, recruiting specialists to help them learn the inner workings of the bank to coordinate very elaborate schemes.

The attack described by Miller involves a group who had partnered together around the world calling themselves the "Unlimited Operation". In the scheme he describes, hackers gain internal access to a bank, or in the most recent case "a Visa/MasterCard processing Center," and gain the ability to manipulate the withdrawal limit on certain ATM Debit cards. These card numbers are then distributed around the world to "Cashing Gangs" that make local copies of the ATM cards and build a network of cashers who "work the machines."

One of the most notorious hacking operations in U.S. History was "Solar Sunrise" - a deep penetration into the Pentagon's computer operations that served as a wake up call for the U.S. Government and lead to the production of a video (now available on YouTube) called

(YouTube video: Solar Sunrise: Dawn of a New Threat
.

The hacker mastermind behind Solar Sunrise was an Israeli hacker, Ehud Tenenbaum, who called himself The Analyzer. In September of 2008 we wrote about him on this blog in the story Is The Analyzer Really Back? (The return of Ehud Tenenbaum) because Tenenbaum was the mastermind behind an attack against a Calgary-based financial services company. In that case, Tenenbaum penetrated the company's internal systems and gained the ability to alter or remove the ATM withdrawal limits. Then, teams of cashers, armed with counterfeit ATM cards bearing the magnetic stripe information corresponding to those accounts, hit the streets withdrawing $2 Million dollars in a blitz of ATM-withdrawals.

But that's not the only time it happened. This blog also ran the story in November 2009 called The $9 Million World-Wide Bank Robbery that shared the details of exactly the same type of raid being performed against RBS WorldPay, headquartered in Atlanta, Georgia. In that case, Estonian hackers penetrated the financial services company, that specializes in "Payroll Debit Cards". After doing so, they contracted with fellow-criminals in Russia, Yevgeny Anikin and Viktor Pleschcuk, who have both confessed their crimes, and received suspended sentences in the Russian bribery-based version of Justice. (See article: Hacker3 escapes jail time in RBS WorldPay ATM heist.) Anikin and Pleschuk worked with the famous Credit Card trading criminal BadB (Vladislav Horohorin) to build a network of cashers operating in 280 cities. Over the course of 12 hours, 2100 ATM machines in 280 cities allowed more than $9 Million in withdrawals from those 44 accounts.

That doesn't mean Cyber Criminals can't go to jail though! Vladislav Horohorin was arrested in Nice, France as he prepared to return to Moscow. (See the Daily Mail story, One of world's most wanted cyber criminals caught on French Riviera.) Horohorin, or "BadB" was the founder of Carder Planet, and was actually returned to the US, where he was tried and in April 2013 Sentenced to 88 Months in Prison.

For a look at one of the US-based casher rings in the RBS WorldPay case, we could also consider the case of Sonya Martin, a Nigerian woman, who ran the Chicago casher gang used in that case. Sonya's ring only withdrew $89,120 in Chicago, but she still got a 30 month sentence back in August 2012. See: Cell leader in RBS WorldPay fraud scheme sentenced.

One other case that used this methodology, and also had New York City ties, was the case that charged Ukrainians Yuriy Ryabinin and Ivan Biltse with performing $750,000 in ATM withdrawals. BankInfoSecurity.com reported the story in 2008, which documented that $5 million was withdrawn in more than 9,000 withdrawals "all around the world" on September 30th and October 1st of that year. According to an affidavit shared by Wired Magazine, this case was tied to a breach of a Citibank server that processed ATM withdrawals at 7-Eleven convenience stores.

In the current case described this morning by CBS, it was described that later today New York U.S. Attorney's office prosecutor Loretta Lynch would announce the arrest of seven members of a New York casher gang that hit ATM's up and down Broadway for almost $2 million during the most recent "Unlimited Operation" case. "Unlimited" was involved in a similar $5 Million raid against a financial institution in India. CBS shared a graphic of the location of ATM machines that were used in the arrests that will be announced later today.

In the New York case, the arrested cashers were:

  • ALBERTO YUSI LAJUD-PEÑA, 23 (deceased)
  • JAEL MEJIA COLLADO, 23
  • JOAN LUIS MINIER LARA, 22
  • EVAN JOSE PEÑA, 35
  • JOSE FAMILIA REYES, 24
  • ELVIS RAFAEL RODRIGUEZ, 24
  • EMIR YASSER YEJE, 24
  • CHUNG YU-HOLGUIN, 22

The Eastern District of New York's Press Release, Eight Members of New York Cell of Cybercrime Organization Indicted in $45 Million Cybercrime Campaign, released today, May 09, 2013, explains the details of how the cashers above, who withdrew $2.8 Million in New York, fit in to the larger "Unlimited Operations." In the first operation, the New York crew withdrew $400,000 from 140 ATMs in New York City in two hours and 25 minutes. In the second operation, February 19-20, 2013, the crew performed 3,000 ATM withdrawals, scoring $2.4 Million in cash between 3 PM on the 19th and 1:26 AM on the 20th, stealing about $240,000 per hour!

The worldwide take on the Feb 19-20 raid included 36,000 transactions and $40 million!

Alberto Yusi Lajud-Peña, the leader of the New York casher ring, laundered the cash, in one case depositing 7,491 $20 bills in a single transaction in Miami, Florida. The crew bought and sold "portable luxury goods" with the cash, including luxury watches and cars, including a Mercedes SUV and a Porsche Panamera valued at $250,000 between the two. Alberto, also known as "Prime" online, was murdered in the Dominican Republic sometime after these robberies occurred.

U.S. Attorney Lynch says that law enforcement authorities in Japan, Canada, Germany, and Romania made great contributions in the case, but that they also received cooperation from the authorities in the UAE, Dominican Republic, Mexico, Italy, Spain, Belgium, France, United Kingdom, Latvia, Estonia, Thailand, and Malaysia.

What these cases are intended to demonstrate is the importance of closely monitoring the internal corporate network for signs of a breach. In a presentation at ITWeb Security Summit this week, "Formulating an attack-focused security plan", Mandiant CSO Richard Bejtlich shares that 75% of break-ins happen through someone clicking on or responding to a malicious email, and that in 2/3rds of incidents, the breach isn't discovered by the company but is reported by a third party organization. Bejlitch says that by the time the attacker is discovered "they will have been inside your company for around eight months."

That's what Malcovery's Today's Top Threats report is intended to address. What is that Top Threat email that is going to lead to criminals having control of one or more of your internal employees? It takes time for the criminal to learn enough about your organization's internal workings to be able to take over and reset ATM balances. Quick detection of the breach is key to preventing problems like those described above.

Wednesday, May 08, 2013

Alabama Identity Theft in FTC Annual Consumer Sentinel Report

Each year the Federal Trade Commission puts out a report called the Consumer Sentinel Report that is not a statistical projection about Identity theft and fraud, but a listing of actual complaints received.

(102 page report here: Consumer Sentinel 2012)

Metropolitan Statistical AreaComplaints per 100,000
Miami / Fort Lauderdale / Pompano Beach, FL 645.4
Naples / Marco Island, FL 397.8
Tampa / St. Petersburg / Clearwater, FL 352.3
Cape Coral / Fort Myers, FL 292.5
Tallahassee, FL 288.5
Lakeland / Winter Haven, FL 281
Port St. Lucie / Fort Pierce, FL 272.6
Atlanta / Sandy Springs / Marietta, GA 246.6
North Port / Bradenton / Sarasota, FL 244.9
Orlando / Kissimmee / Sanford, FL 233.8
Punta Gorda, FL 220.7
Valdosta, GA 218.5
Ocala, FL 213.4
Albany, GA 209.1
Columbus, GA/AL 205.9
Montgomery, AL 203.7
Jacksonville, FL 190.4
Detroit / Warren / Livonia, MI 188.2
Sebastian / Vero Beach, FL 184.7
Savannah, GA 183.3
Palm Bay / Melbourne / Titusville, FL182.6
Gainesville, FL182.4
Deltona / Daytona Beach / Ormond Beach, FL177.9
Beaumont / Port Arthur, TX176
Macon, GA170.5

16 of top 25 in Florida
6 of top 25 in Georgia
1 in Alabama
1 in Michigan
1 in Texas

Alabama, my home state, seems to have some seriously bad scores in the area of Identity Theft. The report lists "per capita" complaints, ordered by the "Metropolitan areas" as defined by the US Census Bureau.

Alabama Cities:

#15 - Columbus, GA/AL (205.9 per 100,000)
#16 - Montgomery, AL (203.7 per 100,000)
#42 - Auburn-Opelika, AL (124.1 per 100,000)
#62 - Birmingham-Hoover, AL (111 per 100,000)
#91 - Enterprise-Ozark, AL (97.8 per 100,000)
#118 - Anniston-Oxford, AL (90.2 per 100,000)
#125 - Tuscaloosa, AL (88.4 per 100,000)
#132 - Dothan, AL (87.2 per 100,000)
#145 - Gadsden, AL (84.3 per 100,000)
#195 - Decatur, AL (72.8 per 100,000)
#198 - Daphne-Fairhope-Foley, AL (72.4 per 100,000)
#303 - Florence-Muscle Shoals, AL (56.4 per 100,000)

SpyEye Botherder BX1 - welcome to Georgia!

Timeline:

The BX1 Indictment

(Click to download the Bx1 Indictment) North District of Georgia (Atlanta)

Criminal Docket for Case#: 1:11-cr-00557-UNA-1 (filed 12/20/2011)

Counts:

(1) 18:1349 Attempt and Conspiracy to Commit Mail Fraud
(2-11) 18:1343 & 2 – Fraud by Wire, Radio, or Television
(13) 18:1030(a)(5)(A), 1030(c)(4)(B) – Fraud Activity Connected with Computers
(14-23) 18:1030(a)(2)(C), 1030(c)(2)(B)(i) – Fraud Activity Connected with Computers

From December 2009 to September 2011 [Redacted] and Hamza Bendelladj, AKA Bx1 conspired to … defraud financial institutions and individuals and obtain money and property from them by means of materially false and fraudulent pretenses, representations and promises, as well as omission of material facts, including moneys, funds, credits, assets, and other properties.

Botnets were defined and described, and SpyEye was described as having the capabilities to “facilitate the theft of confidential personal and financial information by numerous examples including a data grabber or keystroke logger, and at times by presenting a fake bank web page or portions of a bank web page to trick a user into entering personal information.

(The principal author of SpyEye is redacted in the published Indictment). Bx1 is listed as a co-conspirator who helped develop SpyEye components. The behavior of SpyEye is described in great detail, including the creation and deployment of particular Web Injects and how they behave.

Bx1 communicated through email, instant messaging programs, and web forums to discuss purchasing, updating, customizing, developing components for, and pricing SpyEye, as well as aspects of operating SpyEye components.

From at least February 21, 2011 through February 24, 2011 at least one of Bx1’s C&C servers were located in Atlanta, Georgia, distributing configs that targeted 253 unique financial institutions.

Counts 2 through 11 of the indictment trace particular infections that could be documented through the logs of the Atlanta-based server and which lead to confirmed financial losses of particular victims in California, North Carolina, New York, and Virginia.

Count 12 names particular websites used by Bx1 for his advertising, including the website www.darkode.com where particular messages in January, June, July, and September 2010 are cited. The June issue discussed “Form Grabbing” while an update in September introduced the ability to scan all controlled bots for Credit Card credentials. In April 2011, the YouTube user “danielhb1988” called himself Bx1 and claimed to be selling SpyEye in a video advertised on that site. In July 2011, an undercover law enforcement officer purchased SpyEye from Bx1 for $8,500, receiving his purchased code from www.sendspace.com.

Counts 14 through 23 document particular examples of the SpyEye server at 75.127.109.16, communicating with protected computers

The Atlanta Server

During the time period stated in the indictment, the IP address indicated was known to be distributing malware from the hostile URL (spaces added for safety):

www . 100myr . com / cp / bin / exe . exe

www . 100myr . com / cp / gate . php ? guid = (infected machine configuration report stuff here)

That server was hosted at Global Network Access (gnax.net) in Atlanta.

The domain was registered January 20, 2011 on Joker.com by random68@live.com

That same email address was used to register the domain "bx1.biz"

Tuesday, May 07, 2013

Cyber Aspects of the Pentagon's new China report (A2/AD, CNE)

This week the Pentagon released their Annual Report to Congress, Military and Security Developments Involving the People's Republic of China 2013. While the 83-page report details all aspects of military and security, our readership will of course be most interested in the Cyber aspects. For their convenience I've just copied the portions most relevant to that target audience.

Starting at the beginning, "China's leaders in 2012 sustained investment in [missiles and counter-space weapons] and military cyberspace capabilities that appear designed to enable anti-access/area-denial (A2/AD) misisons (what PLA strategists refer to as "counter-intervention operations").

(For more on A2/AD, please see this excellent Q&A on the topic from the Center for Strategic and International Studies (CSIS), The Emerging Anti-Access Area-Denial Challenge.) Chapter 3 of the report, "Force Modernization Goals and Trends," mentions that "Beijing is investing in military programs and weapons designed to improve extended-range power projection and operations in emerging domains such as cyber, space, and electronic warfare.

Anti-Access/Area Denial (A2/AD)

(Begin Quote) As part of its planning for military contingencies, China continues to develop measures to deter or counter third-party intervention, particularly by the United States. China's approach to dealing with this challenge is manifested in a sustained effort to develop the capability to attack, at long ranges, military forces that might deploy or operate within the western Pacific, which the DoD characterizes as "anti-access" and "area denial" (A2/AD) capabilities. China is pursuing a variety of air, sea, undersea, space and counter-space, information warfare systems and operational concepts to achieve this capability, moving toward an array of overlapping, multilayered offensive capabilities extending from China's coast into the western Pacific. China's 2008 Defense White Paper asserts, for example, that one of the priorities for the development of China's armed forces is to "increase the country's capabilities to maintain maritime, space, and electromagnetic space security."

An essential element, if not a fundamental prerequisite, of China's emerging A2/AD regime is the ability to control and dominate the information spectrum in all dimensions of the modern battlespace. PLA authors often cite the need in modern warfare to control information, sometimes termed "information blockade" or "informaiton dominance," and to seize the initiative and gain an information advantage in the early phases of a campaign to achieve air and sea superiority. China is improving information and operational security to protect its own information structures, and is also developing electronic and information warfare capabilities, including denial and deception, to defeat those of its adversaries. China's "information blockade" likely envisions employment of military and non-military instruments of state power across the battlespace, including in cyberspace and outer space. China's investments in advanced electronic warfare systems, counter-space weapons, and computer network operations (CNO) -- combined with more traditional forms of control historically associated with the PLA and CCP systems, such as propaganda and denial through opacity, reflect the emphasis and priority China's leaders place on building capacity for information advantage.

(...)

Information Operations

New technologies allow the PLA to share intelligence, battlefield information, logistics information, weather reports, etc., instantaneously (over robust and redundant communications networks), resulting in improved situational awareness for commanders. In particular, by enabling the sharing of near-real-time ISR data with commanders in the field, decision-making processes are facilitated, shortening command timelines and making operations more efficient.

(...)

Cyber Activities Directed Against the Department of Defense

In 2012, numerous computer systems around the world, including those owned by the U.S. government, continued to be targeted for intrusions, some of which appear to be attributable directly to the Chinese government and military. These intrusions were focused on exfiltrating information. China is using its computer network exploitation (CNE) capability to support intelligence collection against the U.S. diplomatic, economic, and defense industrial base sectors that support U.S. national defense programs. The information targeted could potentially be used to benefit China’s defense industry, high technology industries, policymaker interest in US leadership thinking on key China issues, and military planners building a picture of U.S. network defense networks, logistics, and related military capabilities that could be exploited during a crisis. Although this alone is a serious concern, the accesses and skills required for these intrusions are similar to those necessary to conduct computer network attacks. China’s 2010 Defense White Paper notes China’s own concern over foreign cyberwarfare efforts and highlighted the importance of cyber-security in China’s national defense.

Cyberwarfare in China’s Military

. Cyberwarfare capabilities could serve Chinese military operations in three key areas. First and foremost, they allow data collection for intelligence and computer network attack purposes. Second, they can be employed to constrain an adversary’s actions or slow response time by targeting network-based logistics, communications, and commercial activities. Third, they can serve as a force multiplier when coupled with kinetic attacks during times of crisis or conflict.

Developing cyber capabilities for warfare is consistent with authoritative PLA military writings. Two military doctrinal writings, Science of Strategy, and Science of Campaigns identify information warfare (IW) as integral to achieving information superiority and an effective means for countering a stronger foe. Although neither document identifies the specific criteria for employing computer network attack against an adversary, both advocate developing capabilities to compete in this medium.

The Science of Strategy and Science of Campaigns detail the effectiveness of IW and CNO in conflicts and advocate targeting adversary C2 and logistics networks to affect their ability to operate during the early stages of conflict. As Science of Strategy explains, “In the information war, the command and control system is the heart of information collection, control, and application on the battlefield. It is also the nerve center of the entire battlefield.”

In parallel with its military preparations, China has increased diplomatic engagement and advocacy in multilateral and international forums where cyber issues are discussed and debated. Beijing’s agenda is frequently in line with Russia’s efforts to promote more international control over cyber activities. China and Russia continue to promote an Information Security Code of Conduct that would have governments exercise sovereign authority over the flow of information and control of content in cyberspace. Both governments also continue to play a disruptive role in multilateral efforts to establish transparency and confidence-building measures in international fora such as the Organization for Security and Cooperation in Europe (OSCE), ASEAN Regional Forum, and the UN Group of Governmental Experts. Although China has not yet agreed with the U.S. position that existing mechanisms, such as international humanitarian law, apply in cyberspace, Beijing’s thinking continues to evolve. (End Quote)

Thursday, April 18, 2013

Boston Explosion Spammer shifts to Texas Fertilizer Plant Explosion

Yesterday recipients of the Malcovery Today's Top Threat report were among the first to get a detailed analysis of the new spam campaign offering videos of the Boston Explosion. Our normal practice is to report on any email campaign that sends us at least 1,000 malware attachments or at least 1,000 malicious links that would lead to a malware infection if the link was to be followed. By mid-afternoon, we had already seen 80,000 copies of this spam!

Because of the prevalence of the campaign, we decided to share a copy of the T3 Report with anyone who wanted it, rather than reserving it for our paying customers. You can still get a copy by following this link:

Free Malcovery T3 Report: Boston Marathon Explosion Spam.
Click Logo for your Free T3 Report

Today, our analysts have uncovered the newest update to the threat ... more than 18,000 emails already received this morning with subjects related to the Texas Fertilizer Plant explosion.

 count |                subject                                             
-------+-----------------------------------------------------
  3263 | Fertilizer Plant Explosion Near Waco, Texas
  2110 | Raw: Texas Explosion Injures Dozens
  2074 | CAUGHT ON CAMERA: Fertilizer Plant Explosion
  2045 | Texas Plant Explosion
  2014 | Texas Explosion Injures Dozens
  1943 | CAUGHT ON CAMERA: Fertilizer Plant Explosion Near Waco, Texas
  1609 | Texas plant explosion
  1572 | Video footage of Texas explosion
  1542 | Plant Explosion Near Waco, Texas
The Boston Explosion spam subjects are still an active part of the campaign as well, with nearly 10,000 additional messages coming from that group!
 count |                subject                                             
-------+-----------------------------------------------------
  1315 | 2 Explosions at Boston Marathon
  1197 | Explosions at the Boston Marathon
  1104 | Boston Explosion Caught on Video
  1100 | Video of Explosion at the Boston Marathon 2013
  1034 | Explosions at Boston Marathon
  1032 | Aftermath to explosion at Boston Marathon
  1027 | BREAKING - Boston Marathon Explosion
   999 | Explosion at the Boston Marathon
   958 | Explosion at Boston Marathon
The "count" tells how many samples we have received in the UAB Spam Data Mine, which powers the Malcovery T3 offering. The UAB Spam Data Mine was created as part of UAB's initiatives to create new tools, techniques, and training to fight cyber crime! In December of 2012, UAB launched Malcovery Security to enable our Spam and Phishing efforts to protect more businesses.

To prove that yesterday's campaign and today's campaign are actually one and the same, we traced the URLs being advertised, and found many of the emails that linked to certain IP addresses yesterday with a URL ending in "/boston.html" or "/news.html" are now being advertised in spam with a "/texas.html" link that is being used in the new messages today.

Despite the fact that there are DOZENS of malicious URLs that can be seen in the emails above, we have so far only identified seven "exploit addresses" that are hidden in those malicious websites.

hxxp://auris.comlu.com/ozsr.html
hxxp://bestdoghouseplans.com/azsq.html
hxxp://emucoupons.com/amiq.html
hxxp://nlln.org/aeir.html
hxxp://sambocombat.us/hwsr.html
hxxp://your360solutions.com/emsr.html
hxxp://zendeux.com/wzsq.html
Today's Top Threat subscribers are notified of this type of information each day in their daily T3 reports. By knowing the danger points in top spam campaigns, they are able to use this information either PROACTIVELY, by putting rules into their network security devices and software to block these destination addresses, or REACTIVELY, by scanning their log files to determine if any computer on their network visited one of those sites.

Just like yesterday, any Windows computer that visits one of the links in their email will be shown several YouTube videos, while one of the exploit sites listed above is used to interrogate their computer, infect it with appropriate malware, and add it to their spamming botnet.

Yesterday we clocked individual infected computers as sending approximately 400 emails per minute. 400 * 60 minutes per hour * 24 hours per day == 576,000 emails per day per infected computer! Each computer that clicks this link adds the ability for the spammer to grow their spamming rate by a half million emails per day!

We call this the "Growth Stage" of a botnet. When the objective of a spam message is to cause more computers to also send spam, the botmaster (the criminal who runs the botnet) is trying to enlarge his infrastructure. At some point, the botmaster can issue a command to cause any portion or all of his new collection of "bots" to perform new actions.

These actions could include:

  • sending spam that earns money for the criminal, such as Pharmaceutical spam.
  • infection with a new malware that steals personal financial information, such as the Zeus or Cridex malware.
  • infection with a new malware that causes your computer to attack company websites as part of a "Distributed Denial of Service" (DDOS) Attack, such as the attacks that have been going on against large banks and other companies.
  • infection with a new malware that can steal documents, or allow remote control of your company computer to use as a base of infiltration into your organization, such as what happened to the South Carolina Tax Office
  • infection with a new malware that can delete data or cause your machine to be unbootable such as the Dark Seoul Attacks in South Korea last month.

Wednesday, April 17, 2013

Boston Marathon explosion spam leads to Malware

A new malware spam campaign, claiming to provide videos regarding the Boston Marathon explosion tragedy, is infecting computers and sending spam at a rate that is unprecedented in more than a year. The UAB Spam Data Mine, which has partnered with Malcovery Security to offer the "Today's Top Threat Report" received more than 80,000 copies of the malicious email, with more than 50,000 arriving before noon today.
The top spam subjects for this campaign so far have been:

(count listed as of noon)
  5952 | Boston Explosion Caught on Video
  5885 | Explosions at the Boston Marathon
  5873 | Aftermath to explosion at Boston Marathon
  5855 | 2 Explosions at Boston Marathon
  5729 | Explosions at Boston Marathon
  5725 | Explosion at Boston Marathon
  5690 | Video of Explosion at the Boston Marathon 2013
  5530 | Explosion at the Boston Marathon
  4891 | BREAKING - Boston Marathon Explosion
A second spam campaign is also active, using "CNN-related" spam subjects:
    88 | Opinion: North Korean Official's child was the CIA target - Boston Marathon Explosions Worse Sensations. - CNN.com
    84 | Opinion: Osama bin Laden's legacy - Boston Marathon Explosions - CNN.com
    82 | Opinion: FBI knew about bombs 3 days before Boston Marathon - Why and Who Benefits? - CNN.com
    79 | Opinion: Boston Marathon Explosions - Who benefits? - CNN.com
    77 | Opinion: China Official's  child was the CIA target - Boston Marathon Explosions Worse Sensations. - CNN.com
    75 | Opinion: Osama Bin Laden video about Boston Marathon Explosions - bad news for all the world. - CNN.com
    70 | Opinion: Boston Marathon Explosions - CIA Benefits? - CNN.com
    70 | Undeliverable: Explosion at the Boston Marathon
    69 | Opinion: Osama bin Laden still alive - Boston Marathon Worse Sensation!? - CNN.com
    67 | Undeliverable: Explosions at Boston Marathon
    67 | Opinion: Boston Marathon Explosions made by radical Gays? Really? - CNN.com
    65 | Opinion: Boston Marathon Explosions - Obama Benefits? - CNN.com
    64 | Undeliverable: Boston Explosion Caught on Video
    62 | Opinion: Boston Marathon Explosions - Osama bin Laden still alive? - CNN.com
    61 | Undeliverable: Video of Explosion at the Boston Marathon 2013
    60 | Opinion: Osama death was Faked by CIA - Boston Marathon Explosions Worse News. - CNN.com
The first group of spam messages have the subject line followed by a single URL, consisting of an IP address followed by either "boston.html" or "news.html".
 count |          machine          |  path                                                                       
-------+---------------------------+-------------------
  1667 | 118.141.37.122            | /boston.html
  1564 | 190.245.177.248           | /boston.html
  1533 | 178.137.120.224           | /boston.html
  1507 | 110.92.80.47              | /boston.html
  1484 | 37.229.92.116             | /news.html
  1466 | 188.2.164.112             | /boston.html
  1448 | 178.137.100.12            | /news.html
  1422 | 78.90.133.133             | /boston.html
  1376 | 118.141.37.122            | /news.html
  1363 | 212.75.18.190             | /boston.html
  1356 | 178.137.120.224           | /news.html
  1344 | 110.92.80.47              | /news.html
  1331 | 83.170.192.154            | /boston.html
  1330 | 37.229.92.116             | /boston.html
  1317 | 219.198.196.116           | /news.html
  1314 | 37.229.215.183            | /boston.html
  1312 | 61.63.123.44              | /news.html
  1309 | 61.63.123.44              | /boston.html
  1280 | 219.198.196.116           | /boston.html
  1271 | 85.198.81.26              | /news.html
  1247 | 190.245.177.248           | /news.html
  1214 | 94.28.49.130              | /boston.html
  1171 | 94.28.49.130              | /news.html
  1157 | 94.153.15.249             | /news.html
  1150 | 83.170.192.154            | /news.html
  1137 | 78.90.133.133             | /news.html
  1100 | 95.87.6.156               | /news.html
  1069 | 85.198.81.26              | /boston.html
  1061 | 94.153.15.249             | /boston.html
  1056 | 212.75.18.190             | /news.html
  1055 | 37.229.215.183            | /news.html
  1038 | 95.87.6.156               | /boston.html
  1028 | 188.2.164.112             | /news.html
  1011 | 178.137.100.12            | /boston.html
   960 | 46.233.4.113              | /news.html
   791 | 176.241.148.169           | /news.html
   766 | 176.241.148.169           | /boston.html
   758 | 91.241.177.162            | /news.html
   739 | 46.233.4.113              | /boston.html
   735 | 213.34.205.27             | /boston.html
   651 | 213.34.205.27             | /news.html
   642 | 91.241.177.162            | /boston.html
   626 | 62.45.148.76              | /news.html
   553 | 85.217.234.98             | /boston.html
   511 | 62.45.148.76              | /boston.html
   484 | 85.217.234.98             | /news.html
   205 | 31.133.84.65              | /news.html
   152 | 31.133.84.65              | /boston.html
    47 | 109.87.205.222            | /boston.html
    44 | 109.87.205.222            | /news.html
    19 | 50.136.163.28             | /news.html
    17 | 50.136.163.28             | /boston.html
The second group uses a website address rather than an IP address followed by either "cnn_boston.html" or "bostoncnn.html"
 count |           machine            |                         path                         
-------+------------------------------+------------------------------------------------------
   191 | www.domcomfort.ru            | /bostoncnn.html
   176 | www.whchivast.com            | /cnn_boston.html
   142 | relax-perm.ru                | /bostoncnn.html
    80 | www.peaceofchristparish.org  | /cnn_boston.html
    71 | imdh.knu.ac.kr               | /cnn_boston.html
    63 | create-serv.ru               | /popeabuse.html
    59 | skinnee.net                  | /cnn_boston.html
    56 | numeralarmowy-112.pl         | /cnn_boston.html
    56 | imdh.kyungpook.ac.kr         | /cnn_boston.h
    41 | higherthanab.com             | /cnn_boston.html
    40 | ufferichter.dk               | /cnn_boston.html
    37 | business-link.net            | /cnn_boston.html
    25 | ochronaprawkonsumenta.pl     | /cnn_boston.html
    24 | mannesmann.cz                | /cnn_boston.html
    20 | kuzenergo.ru                 | /cnn_boston.html
    20 | siemsrl.com                  | /bostoncnn.html
    18 | alex-spil.dk                 | /cnn_boston.html
    17 | host321.ru                   | /cnn_boston.html
    13 | www.vdnh.kiev.ua             | /cnn_boston.html
    10 | www.theophany.co.nz          | /cnn_boston.html
     8 | yanjingedu.org               | /cnn_boston.html
     6 | china-ptjc.com               | /cnn_boston.html
     5 | econ-group.com               | /cnn_boston.html
     3 | mezdustrok.com.ua            | /cnn_boston.html
     2 | alltomforsakringar.nu        | /cnn_boston.html
     2 | ufferichter.com              | /cnn_boston.html
We self-infected by visiting one of the IP address links in a web browser. The page had a series of YouTube videos, including this one:
However, if we look at the source code of the page, we notice something that certainly seems out of place!

The last IFRAME there calls a site called "spareroomwebdesign.com" and a file "waiq.html"
One of the changes to our machine was the addition of a registry key:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SonyAgent: "C:\WINDOWS\Temp\temp86.exe"
When we checked, we found a hidden file, 815,616 bytes in size in that location.
The MD5 of the file is: fdbc94958b8f0ec2b24302c6d4685c46
As of this writing, only 8 of the 46 Anti-virus programs at VirusTotal are aware of this malware and able to detect it. https://www.virustotal.com/en/file/560766fc73edf8eff02674a220e2794c008caeefc476c8fef04c21a16eb23a0f/analysis/
Once infected, your machine BECOMES THE SPAMMER, and begins to distribute emails. In a 48 second run our infected machine attempted to send 348 spam messages, all with a subject from the list above.
The SECOND, CNN-themed spam campaign is a Financial Crimes malware infector, known as Cridex.
Both campaigns have been thoroughly documented in the Malcovery Security Top Threats Today report, normally reserved for our paying subscribers. Due to the extremely prolific nature of the Boston Marathon Explosion spam campaign, we are offering that T3 report as a free sample for any interested parties.

Free Malcovery T3 Report: Boston Marathon Explosion Spam.
Click Logo for your Free T3 Report
















Wednesday, April 10, 2013

New Spam Attack accounts for 62% of our spam!

A new spamming botnet seems to be on the scenes, distinguishing itself with an extremely high spam volume, a great diversity of email subjects, and an amazingly diverse collection of URLs, mostly hosted on compromised websites.

Four of the top six spam subjects in the past 36 hours came from this new botnet:
• Obama’s policies affecting unemployed
• Change your life in 60 seconds.
• Recently got a job offer?
• Have you ever considered working on the internet?

When we used the Malcovery Spam Data Mine to review the sending IP addresses, we found that these messages had come from more than 23,000 different IP addresses. Just for the “Obama’s policies” subject, we saw 296 unique URLs advertised just this morning before 8:00 AM! Here are some of the Top URLs for that spam message.

count                 machine                     path                      
38  www.ghostsquad.altervista.org          /cellchickengrahamwilliams/
36  rundeecke.bplaced.net                  /connectiondevicejamesbailey/
35  sungoldcoast.com                       /assistantelegantjasonedwards/
35  www.coloniasunidas.com                 /conflictarticlephilipwood/
35  www.cocheenminiatura.altervista.org    /arrestautumndanielhill/
34  protetyk.ovh.org                       /engineercorealanspencer/
33  www.ghostsquad.altervista.org          /cellchickencraigdavies/
32  guildrampage.com                       /besickendwaynemiller/
32  cuorebravo.com                         /armyeastkevinspencer/
31  www.curiosando.altervista.org          /clockconflictjohnking/
31  www.divorcecamp.com                   /equalatmospheregeoffreycooper/
31  6sejc.com                              /associatealliedadrianthomas/

When we check for other websites advertised in spam, JUST FOR SPAMMING IP ADDRESSES THAT SENT THE FOUR SUBJECTS ABOVE, and ONLY FOR THE PAST 36 hours, we find that 3,849 distinct URLs were spamvertised a total of 1,217,196 times – only counting the spam in our Spam Data Mine!

A great variety of subject lines were used in addition to the four top ones above. By “theme” there were:

Oprah and Celebrity subjects:

  • Oprah Winfrey Reveals That She Has A Sister Named Patricia
  • Kourtney & Kim Take NY
  • Oprah’s big secret: she has a sister
  • Oscar 2011: What To Expect
  • Ivanka Trump Has A Baby Bump
  • Ellen DeGeneres secret
  • Rapid-Fire Fitness: Katy Perry
  • Release Your Soul with Pamela Anderson
  • Your morning fashion and beauty report: Reese Witherspoon
  • Anne Hathaway find out how
Fitness subjects:
  • Fitness: Love the 30s!
  • Body and Soul women’s weight loss
  • Healthy Hollywood
  • Miracle Diet or Scam
  • Sorry, guys, these fitness classes aren’t for you
  • No workout, lose weight
  • Miracle or science?
  • Get fit
  • Women try to balance fitness, safety
  • No diet just weight loss
  • Workouts for Women
Silly “fwd” and “re” subjects:
  • Fwd: private
  • Fwd: hey
  • Fwd: question
  • Fwd: hello
  • Re: important
  • Re: hey
  • Fwd: deal
  • Fwd: ?
  • Fwd: information
  • Fwd: …
  • Fwd: business
  • Fwd: answer
  • Fwd: help
News Subjects:
  • Fox investigates claim
  • Fox News investigates: “Change your life in 60 seconds!”
  • Need some money? Fox News wants to help
  • BBC: Online giant Google, worth over 100 billion dollars..
  • Unemployed? Fox! Investigates.
  • TBS breaking news
Random number weight loss subjects:
  • She lost 54 lb in 3 weeks.
  • She lost 46 pounds in 3 weeks.
  • She lost 53 lbs in 3 weeks.
  • (etc.)
And there are still “Work at Home” scam versions, even though the URLs now take you to weight loss websites instead:

Home Maker Dad claims investigated by Fox
 Work from home Dad claims investigated by TBS
 Work from home Mom claims investigated by CNN USA
 Home-Maker Mom claims investigated by Fox!
 Work from home Mom claims investigated by Fox News
 Work from home Mother claims investigated by BBC
 Work at home Mom claims investigated by TBS
 Work-from-home Dad claims investigated by CNN
 Stay-at-home Mom claims investigated by Yahoo!
 Stay home Mother claims investigated by TBS
 Home-Maker Dad claims investigated by CNN USA
 Homemaker Mom claims investigated by BBC
 Stay home Father claims investigated by Fox
 Stay home Mom claims investigated by CNN
 Stay at home Mother claims investigated by Fox!
 Stay home Dad claims investigated by CNN!
 Work-at-home Dad claims investigated by CNN
 Stay home Mom claims investigated by BBC
 Work-at-home Mom claims investigated by Fox!
 Work-at-home Mom claims investigated by CNN!
 Work-from-home Mom claims investigated by BBC
 Work at home Mother claims investigated by BBC USA
 Work-at-home Mom claims investigated by BBC USA
 Stay at home Mom claims investigated by Fox!
 Homemaker Mother claims investigated by CNN
 Work at home Mother claims investigated by ITV
 Homemaker Father claims investigated by CNN!
 Stay at home Mother claims investigated by TBS
 Work-at-home Dad claims investigated by Fox
 Home Maker Mom claims investigated by ITV
 Home Maker Father claims investigated by Fox
 Work-at-home Dad claims investigated by BBC USA
 Homemaker Mother claims investigated by CNN USA
 Work at home Dad claims investigated by Fox News
 Work from home Dad claims investigated by BBC USA
 Home-Maker Father claims investigated by Fox News
 Home-Maker Mother claims investigated by Fox News
What do those pages do when you visit them?

On Monday morning, they sent you to a website with information about a new “Work at Home” program that you could learn about for the low low low price of $100.

But today, they are sending you to a page that proclaims:

Breakthrough Diet Exposed: Celebrity Doctor Uncovers The “Holy Grail of Weight Loss”

This is an on-going campaign that has recently advertised various miracle weight loss products including Raspberry Drops, Green Coffee Bean Extract, and now, “Garcinia Cambogia Featured on TV”

The method for doing this is the use a tiny javascript to set the “parent location href” equal to com-independentvoice.net (or one of many other redirector pages) and passing an “indexer.php?a=225783&c=job” parameter along with the new address. This causes the browser to go to that page and look up the job offer, which displays the weight loss miracle of the day by forwarding the visitor to the path “/diet/GarciniaCambogiaDiet/”

Trying to leave the website generates pop-up messages like these:

Several great clues that these guys are not legitimate including:

The domain is registered by UKRNames.com (Ukrainian Domain Name Registrar of Ill Repute)

The IP address, 201.182.92.166, is hosted at AS52284, Panamaserver.com, claiming to be in Panama.

That IP is also “naturaldietforyou1.com” as well as:

Burnfatandgetflatstomach1.com
Rapidfatlossnatural1.com
Getbestdietsecret1.com
Howtoloseweightquicklyexercises.com
Howtoloseweightfastwithexerciseanddiet.com
Easistnaturalwaytoloseweight.com
Com-work24.net
Finance-reports.com-work24.net
Com-newslocal6.net
Finance-reports.com-newslocal6.net
Com-cbc.net
Finance-reports.com-cbc.net
Finance-reports.com-thestar.net
Com-world-jobnews.net
Com-globejobnews.net
Com-dailylocalnews.net
Finance-reports.com-cnnnewsnet
Com-independentnews.net
Alternativenewsdaily.net

Just picking one of those addresses, com-cnnnews.net was also hosted at:
31.184.192.35
31.184.192.36
81.17.23.40
142.0.72.101
142.0.72.103
176.9.208.121
176.9.208.122
176.9.218.182
185.12.45.102
185.12.45.107
199.91.174.71
199.91.174.72
199.182.168.139
201.182.92.166

More subjects:

 Need some money? CNN! wants to help
 Fox investigates claim
 Fox News investigates: "Change your life in 60 seconds!"
 Need some money? Fox News wants to help
 BBC: Online giant Google, worth over 100 billion dollars..
 Unemployed? Fox! investigates.
 TBS breaking news
 Lost your job? Fox News wants to help.
 CNN! investigates "impossible" claims.
 Lost your job? BBC USA wants to help.
 CNN! investigates: "Change your life in 60 seconds!"
 CNN investigates: "Change your life in 60 seconds!"
 Fox!: Online giant Google, worth over 100 billion dollars..
 BBC investigates latest claim.
 BBC investigates claim
 Fox! breaking news
 CNN investigates latest claim.
 ITV investigates claim
 ITV investigates: "Change your life in 60 seconds!"
 CNN!: Breaking news!
 CNN USA investigates: "Change your life in 60 seconds!"
 Unemployed? CNN USA investigates.
 Lost your job? BBC wants to know.
 Need some money? TBS wants to help
 Unemployed? Yahoo! investigates.
 Lost your job? CNN USA wants to know.
 ITV investigates latest claim.
 Yahoo! investigates: "Change your life in 60 seconds!"
 TBS: Online giant Google, worth over 100 billion dollars..
 Lost your job? CNN wants to know.
 Lost your job? TBS wants to help.
 CNN!: Online giant Google, worth over 100 billion dollars..
 Lost your job? TBS wants to know.
 Lost your job? CNN! wants to help.
 Lost your job? CNN! wants to know.
 Fox!: Breaking news!
 Unemployed? Fox News investigates.
 Lost your job? ITV wants to know.
 Unemployed? TBS investigates.
 Need some money? CNN USA wants to help
 Lost your job? CNN USA wants to help.
 Lost your job? Fox! wants to help.
 CNN USA investigates claim
 Yahoo! investigates latest claim.
 Fox! investigates claim
 CNN: Breaking news!
 Lost your job? Yahoo! wants to know.
 BBC USA investigates "impossible" claims.
 Yahoo!: Online giant Google, worth over 100 billion dollars..
 Lost your job? Fox! wants to know.
 Fox investigates: "Change your life in 60 seconds!"
 TBS: Breaking news!
 Unemployed? CNN investigates.
 Yahoo! breaking news
 Need some money? CNN wants to help
 Fox! investigates "impossible" claims.
 ITV breaking news
 Lost your job? Fox News wants to know.
 Unemployed? ITV investigates.
 BBC USA investigates claim
 CNN USA investigates latest claim.
 CNN investigates "impossible" claims.
 Fox breaking news
 Fox: Online giant Google, worth over 100 billion dollars..
 Lost your job? Fox wants to know.
 ITV: Online giant Google, worth over 100 billion dollars..
 Yahoo!: Breaking news!
 Need some money? Yahoo! wants to help
 BBC USA: Online giant Google, worth over 100 billion dollars..
 Lost your job? ITV wants to help.
 Need some money? Fox! wants to help
 Fox News: Breaking news!
 Fox News breaking news
 Fox News investigates latest claim.
 Yahoo! investigates claim
 Fox News: Online giant Google, worth over 100 billion dollars..
 Yahoo! investigates "impossible" claims.
 CNN USA: Breaking news!
 ITV: Breaking news!
 ITV investigates "impossible" claims.
 BBC USA investigates latest claim.
 CNN USA investigates "impossible" claims.
 CNN USA breaking news
 TBS investigates: "Change your life in 60 seconds!"
 BBC USA investigates: "Change your life in 60 seconds!"
 Fox investigates latest claim.
 BBC USA: Breaking news!
 BBC breaking news
 Unemployed? BBC investigates.
 TBS investigates claim
 TBS investigates latest claim.
 Need some money? BBC wants to help
 BBC: Breaking news!
 Need some money? ITV wants to help
 BBC USA breaking news
 Unemployed? CNN! investigates.
 CNN: Online giant Google, worth over 100 billion dollars..
 CNN breaking news
 Lost your job? CNN wants to help.
 Lost your job? BBC USA wants to know.
 Lost your job? Fox wants to help.
 Need some money? BBC USA wants to help
 CNN investigates claim
 Fox News investigates claim
 Lost your job? BBC wants to help.
 Fox! investigates: "Change your life in 60 seconds!"
 BBC investigates: "Change your life in 60 seconds!"
 Fox: Breaking news!
 TBS investigates "impossible" claims.
 CNN USA: Online giant Google, worth over 100 billion dollars..
 BBC investigates "impossible" claims.
 Fox! investigates latest claim.
 CNN! investigates latest claim.
 Unemployed? Fox investigates.
 Fox investigates "impossible" claims.
 Lost your job? Yahoo! wants to help.
 Need some money? Fox wants to help
 CNN! breaking news
 Unemployed? BBC USA investigates.
 Fox News investigates "impossible" claims.
 CNN! investigates claim


Work at home Dad claims investigated
 Rapid fire weight loss Salma Hayek
 Work-at-home Mom claims investigated
 Breaking news for Home Maker Father.
 Breaking news for Stay at home Dad.
 Breaking news for Home-Maker Father.
 Oprah Whinfrey Heads To Paris In Search Of The Perfect Wedding Gown!
 Breaking news for Home-Maker Mother.
 Breaking news for Work-at-home Mom.
 Ellen DeGeneres diet or scam?
 Salma Hayek diet or scam?
 weight loss Katy Perry
 Breaking news for Stay home Dad.
 Stay at home Mother claims investigated
 Breaking news for Stay home Father.
 Stay at home Father claims investigated
 Release Your Soul with Anne Hathaway
 weight loss Madonna
 Breaking news for Work-at-home Dad.
 Ellen DeGeneres secret
 Rapid-Fire Fitness: Katy Perry
 Release Your Soul with Pamela Anderson
 Your morning fashion and beauty report: Reese Witherspoon
 Anne Hathaway find out how
 Work from home Mom claims investigated
 Breaking news for Work at home Mom.
 Rachel Ray says
 Britney Spears Going Harder, More Urgent
 Pamela Anderson try to balance fitness, safety
 Check out how Natalie Portman did it
 Oprah Whinfrey try to balance fitness, safety
 Breaking news for Work from home Father.
 Ellen DeGeneres weight loss
 Breaking news for Homemaker Father.
 Homemaker Dad claims investigated

Monday, March 18, 2013

Tax Season is Malware Season

In the United States, personal income taxes are due for every worker on April 15th.  The period of time from about January 31st until April 15th is when most of us file our taxes, which means Cyber Criminals love to imitate tax related services during this time.

Each day we review Today's Top Threats for the Malcovery "T3" report.  Quite a few of them have imitated tax related issues, from the Internal Revenue Service (IRS) themselves, to Intuit, the makers of the popular TurboTax software, to assorted warnings that problems have occurred with your filing.

Here are a few of my recent favorites:

Feb 12, 2013:  IRS

Our email subjects for this campaign sounded serious:

 count |                                         subject                                         
-------+------------------------------------------------------------------------------------------
   446 | surcharge for delay of tax return filling
   381 | forfeiture for delay of tax return filling
   363 | forfeit for delay of tax return filling
   361 | pecuniary penalty for delay of tax return filling
   350 | fine for delay of tax return filling
   315 | penalty for delay of tax return filling
   124 | Income Tax Refund TURNED DOWN
   108 | Income Tax Refund NOT ACCEPTED
    94 | Income Tax Refund NOT APPROVED
    90 | Income Tax Refund RETURNED
    87 | Income Tax Refund CANCELED
    74 | Income Tax Refund REJECTED



In this case there were at least 59 hacked websites that were advertised in the spam messages.  Here are some of the top ones:


count machinepath
519www.buyonlineclothing.com//wp-content/themes/mantra/uploads/rjtd_irs.html
361www.stuterisb.se/wp-content/uploads/fgallery/irs_rjtr.html
313www.michaeldauphinais.com//wp-content/themes/mantra/uploads/rjtd_irs.html
200trademarksprotected.com//wp-content/themes/mantra/uploads/irs_rjtr.html
100www.cowcomco.com//wp-content/themes/mantra/uploads/rjtd_irs.html
88www.hugoflores.net//wp-content/themes/mantra/uploads/rjtd_irs.html
79www.dvla-plates.com//wp-content/themes/mantra/uploads/rjtra_irs.html
77energeticfitness.com/wp-content/plugins/mm-forms-community/upload/temp/irs_rjtra.html
66www.electronicsreviewers.com//wp-content/themes/mantra/uploads/rjtra_irs.html
64www.newhavenfreestore.com/wp-content/plugins/mm-forms-community/upload/temp/irs_rjtr.html
63www.ordinarycoder.com//wp-content/themes/trulyminimal/includes/framework/plugins/rjtra_irs.html
62www.100daystochangemylife.com//wp-content/themes/mantra/uploads/rjtd_irs.html
56cliptogive.com/wp//wp-content/themes/mantra/uploads/rjtd_irs.html
53www.jimhyland.com//wp-content/themes/mantra/uploads/rjtra_irs.html
51www.nicejordans23.com/Jordanblog//wp-content/themes/mantra/uploads/rjtd_irs.html
41futurizekorea.com//wp-content/themes/mantra/uploads/irs_rjtr.html
38www.misslulublogs.com//wp-content/themes/trulyminimal/includes/framework/plugins/irs_rjtr.html
37notfatnow.com/irs_rjtr.html
35swanirubber.com/Blog//wp-content/themes/mantra/uploads/rjtra_irs.html
34troutkinglures.com/store-front//wp-content/themes/mantra/uploads/rjtra_irs.html
34www.amir-jafari.com//wp-content/themes/mantra/uploads/rjtd_irs.html
32www.hungergamesreporter.com//wp-content/themes/mantra/uploads/irs_rjtra.html
28www.nolahelper.com//wp-content/themes/mantra/uploads/irs_rjtr.html
28jyaproductora.com//wp-content/themes/mantra/uploads/irs_rjtr.html
22www.shuckabuck.com//wp-content/themes/mantra/uploads/irs_rjtr.html
22www.mamanbandante.com//wp-content/themes/mantra/uploads/irs_rjtr.html
21stjudeintercession.com/prayer/wp-content/plugins/mm-forms-community/upload/temp/rjtra_irs.html

Feb 14, 2013: TurboTax

In this campaign, the spammers hope we will believe that TurboTax is informing us that our "State Tax Return" has been rejected. In reality the "please find information attached" is a zip file with a randomly named file name (tax_RANDNUMBERS.zip). The zip file (MD5 = '44e31cab12de506e9b7e9df3c4414cef') is quite widely detected now, but that was not the case on the day of the campaign.

Mar 13, 2013: Intuit

The poor English in the subject on this spam message: "Payroll Account Holded by Intuit" may have helped prevent victimization.

But there were still 146 hacked websites that were each being used to redirect traffic to the Black Hole Exploit server. Despite the fact that this spam campaign is now six days old, many of these links are still active. A link followed this morning (March 19, 2013) redirects to the website "heelicotper.ru" on the path "forum/links/column.php". This domain resolves to 89.110.131.10, 132.230.75.95, 188.165.202.204, and 50.22.0.2. Even six days after the attack, several of the links sent in the original spam message are still functional, and will stop drop malware from the exploit server. (This morning we got a file that renamed itself to KB01148523.exe, which disguises itself as an "Advanced display adapter" driver update, claiming to be by "Microsoft Corporation". The file has the MD5 8fe6968cab2b12ae486628c1a07cb86. How do you detect which machines in your network might be infected, since the detection rate (currently 9 of 46 at VirusTotal) means that AVG, Avast, F-Prot, Microsoft, Symantec, Sophos, and Trend Micro would not detect this malware. We recommend looking for the BEHAVIOR of this malware in your network or web proxy logs. If someone visited one of the sites below, or more importantly, visited the site they redirect to - heelicotper.ru - then that machine needs to be examined and remediated.


    19 | www.mysteam.ru                             | /report.htm
    19 | z-la.ru                                    | /report.htm
    12 | www.sellpei.com                            | /report.htm
    11 | cs.4id.lv                                  | /report.htm
    11 | elyospride.snl.su                          | /report.htm
    11 | pokemons.ru                                | /report.htm
    10 | forum.parkourfamilygomel.com               | /report.htm
     9 | www.talkgolf.org                           | /report.htm
     9 | cs.ittf.com.ua                             | /report.htm
     9 | renaults.net                               | /report.htm
     9 | www.netmfdevices.com                       | /report.htm
     9 | bin-cs.ru                                  | /report.htm
     8 | forum.diavolo-rp.ru                        | /report.htm
     8 | deltanineairsoft.com                       | /report.htm
     8 | forum.s1mpluworld.ru                       | /report.htm
     8 | onlyfan.ru                                 | /report.htm
     8 | www.j-hero.com                             | /report.htm
     8 | fr.underworld.alwaysdata.net               | /report.htm
     8 | forum.muapocalypse.ru                      | /report.htm
     8 | mv-forum.free-h.net                        | /report.htm
     7 | forum.gornofwar.ru                         | /report.htm
     7 | skibukovel.ru                              | /report.htm
     7 | stargate-radio.com                         | /report.htm
     7 | forumgg.xost.me                            | /report.htm
     7 | gartepiopv2.altervista.org                 | /report.htm
     7 | evostrike.ro                               | /report.htm
     7 | reprobatessouthwest.co.uk                  | /report.htm
     7 | halo117.com                                | /report.htm
     7 | www.vfpr.ru                                | /report.htm
     7 | www.uobview.com                            | /report.htm
     7 | orioncraft.ru                              | /report.htm
     7 | www.firearmschat.com                       | /report.htm
     7 | konsolowisko.pl                            | /report.htm
     6 | scorpions-wot.tk                           | /report.htm
     6 | www.ultravioletphotography.com             | /report.htm
     6 | la2nebesa.ru                               | /report.htm
     6 | shieldandsword.ru                          | /report.htm
     6 | accademiaminer.altervista.org              | /report.htm
     6 | xn--l1adgmc.xn--80ahx8f.xn--e1apq.xn--p1ai | /report.htm
     6 | isage.nes.org.sg                           | /report.htm
     6 | veni_vidi_vici.byethost14.com              | /report.htm
     6 | h2hproject.in                              | /report.htm
     6 | chronic.bplaced.net                        | /report.htm
     6 | forum.xboxarea.com                         | /report.htm
     6 | zabijamy.pl                                | /report.htm
     6 | forum.patriots-cs.ru                       | /report.htm
     6 | forum.myaion.su                            | /report.htm
     6 | kpoxi.ru                                   | /report.htm
     6 | www.maxhimitalo.com                        | /report.htm
     6 | elitegamer.ru                              | /report.htm
     6 | turbotamil.org                             | /report.htm
     6 | forum.classicgunz.com                      | /report.htm
     6 | forum.mineclub.org                         | /report.htm
     5 | sinto-online.ru                            | /report.htm
     5 | forum.mccxcix.com                          | /report.htm
     5 | fast-break.org                             | /report.htm
     5 | ps-elumination.com                         | /report.htm
     5 | www.survival-soundz.com                    | /report.htm
     5 | forum.gtr-site.info                        | /report.htm
     5 | poker-hunter.ru                            | /report.htm
     5 | forum.vtex.com.br                          | /report.htm
     5 | forumkulturystyka.com                      | /report.htm
     5 | cs.justbe.pro                              | /report.htm
     5 | 20h27.com                                  | /report.htm
     5 | wowfatalityforum.byethost16.com            | /report.htm
     5 | ptw.lv                                     | /report.htm
     5 | l2javelline.ru                             | /report.htm
     5 | darkube.net                                | /report.htm
     5 | wdhe.ru                                    | /report.htm
     5 | chatpat.org                                | /report.htm
     5 | www.medics-corpsmen.com                    | /report.htm
     5 | kompstart40.ru                             | /report.htm
     5 | allstudents.net.ru                         | /report.htm
     5 | forum.darkube.net                          | /report.htm
     5 | cs-gold.net                                | /report.htm
     5 | snails-city.ru                             | /report.htm
     5 | azcsforums.com                             | /report.htm
     5 | nightcore.pl                               | /report.htm
     5 | necroz-team.ru                             | /report.htm
     4 | s13club.ru                                 | /report.htm
     4 | code-projects.com                          | /report.htm
     4 | lamanserlo.com                             | /report.htm
     4 | zym-server.ru                              | /report.htm
     4 | forum.g-o-d.ru                             | /report.htm
     4 | tagyl.web-planet.cz                        | /report.htm
     4 | gpro.ro                                    | /report.htm
     4 | dev.diypedia.ro                            | /report.htm
     4 | playsense.ru                               | /report.htm
     4 | plastidipforum.ru                          | /report.htm
     4 | forum.gzone.info                           | /report.htm
     4 | ots.hmhost.pl                              | /report.htm
     4 | wsat.kz                                    | /report.htm
     4 | www.medforum.md                            | /report.htm
     4 | forum.anivisions.ru                        | /report.htm
     4 | forum.mafiacrafting.ru                     | /report.htm
     4 | www.cso-original.ru                        | /report.htm
     4 | xn--80adfeab9argno2mtb.xn--p1ai            | /report.htm
     4 | www.adminwebmaster.com                     | /report.htm
     4 | corp.spinco.info                           | /report.htm
     4 | fot-cs.p.ht                                | /report.htm
     4 | forums.deimoscorp.eu                       | /report.htm
     4 | homou.org                                  | /report.htm
     4 | www.foxiran.com                            | /report.htm
     4 | starkmuebles.com                           | /report.htm
     4 | myforester.ru                              | /report.htm
     4 | kolosov89.tmweb.ru                         | /report.htm
     4 | forum.nephridie.com                        | /report.htm
     4 | forums.agueraton.net                       | /report.htm
     4 | yachtdream.ru                              | /report.htm
     3 | www.e-treedental.com                       | /report.htm
     3 | www.team-increment.com                     | /report.htm
     3 | forum.hansen-ro.com                        | /report.htm
     3 | www.modernmetal.pl                         | /report.htm
     3 | s382436236.websitehome.co.uk               | /report.htm
     3 | forum.pandaro.ru                           | /report.htm
     3 | spokupki.org                               | /report.htm
     3 | forum.myevoque.ru                          | /report.htm
     3 | sochaczew24h.pl                            | /report.htm
     3 | iiibforever.altervista.org                 | /report.htm
     3 | soft-droid.ru                              | /report.htm
     3 | extradrive.ru                              | /report.htm
     3 | www.lendagames.com                         | /report.htm
     3 | forum.waytotruth.in.ua                     | /report.htm
     3 | www.sosaria.com.br                         | /report.htm
     3 | forum.aion-lightning.su                    | /report.htm
     3 | forum.samp-ml.ru                           | /report.htm
     3 | vipshara.net                               | /report.htm
     3 | art-tm.net                                 | /report.htm
     3 | wst-team.ru                                | /report.htm
     3 | driftnsk.ru                                | /report.htm
     2 | ingameclan.myarena.ru                      | /report.htm
     2 | www.fifa-online.pl                         | /report.htm
     2 | angel-css.ru                               | /report.htm
     2 | www.club2108.com                           | /report.htm
     2 | ostrza.arieth.com                          | /report.htm
     2 | www.coachownersclub.com                    | /report.htm
     2 | abt.id.lv                                  | /report.htm
     2 | foro.ateneahost.com                        | /report.htm
     2 | hohyunworld.com                            | /report.htm
     2 | www.piratas4x4.com                         | /report.htm
     2 | evgamer.com                                | /report.htm
     1 | e-war.ws                                   | /report.htm
     1 | resist.kiev.ua                             | /report.htm
     1 | reamhosting.com                            | /report.htm
     1 | www.sandsofdestiny.net                     | /report.htm

Mar 13, 2013: EFTPS

Last for now, the spam claiming to be from "The Electronic Federal Tax Payment System" (EFTPS) had a different subject for every email, based on a random number stuck in the subject line. "Tax Payment N (RANDOM NUMBER HERE) is failed."

Seventy-eight hacked websites were used by this one to redirect visitors to a Black Hole Exploit Server . . . Just like above, the "loading.htm" pages will redirect to a Black Hole Exploit server, that will drop malware onto your computer.

 count |                   machine                   |     path     
-------+---------------------------------------------+--------------
    32 | forum.myfaberlic.com.ua                     | /loading.htm
    26 | forum.garudaflyff.web.id                    | /loading.htm
    25 | talk.altrock.us                             | /loading.htm
    24 | l2-fallenlords.16mb.com                     | /loading.htm
    23 | forum.rus-hw.ru                             | /loading.htm
    23 | forum.gorod4217.ru                          | /loading.htm
    23 | forums.farahfa.com                          | /loading.htm
    22 | www.forum.deutschland1.ru                   | /loading.htm
    21 | forum.mumonster.com.br                      | /loading.htm
    20 | forum.xorezm.com                            | /loading.htm
    20 | forum.esthus.ru                             | /loading.htm
    20 | la2reckless.16mb.com                        | /loading.htm
    20 | xn----7sbbhei2a7a0ag3e5ehq.xn--p1ai         | /loading.htm
    19 | forum.vp-css.ru                             | /loading.htm
    19 | forum.sg-wars.com                           | /loading.htm
    19 | la2.under.net.ua                            | /loading.htm
    19 | ambition-bs.bplaced.net                     | /loading.htm
    19 | forum.tiki-online.com                       | /loading.htm
    18 | forum.lin2hero.ru                           | /loading.htm
    18 | forum.bfkc.ru                               | /loading.htm
    18 | cs.franyk.net                               | /loading.htm
    18 | xn--90aefd3alei2i.xn--p1ai                  | /loading.htm
    18 | forum.gr-trophy.ru                          | /loading.htm
    18 | www.rteam.vinfo.fr.nf                       | /loading.htm
    17 | forum.universe-life.ru                      | /loading.htm
    17 | forum.oxuyun.com                            | /loading.htm
    17 | forum.gaming-pro.net.ua                     | /loading.htm
    16 | forum.fnatic.w2c.ru                         | /loading.htm
    16 | forum.mineiros.pt                           | /loading.htm
    16 | xn--l1adgmc.xn--90aicihxbb.xn--p1ai         | /loading.htm
    16 | forum.autoelectric33.ru                     | /loading.htm
    16 | xbox.pp.ua                                  | /loading.htm
    15 | forum.pvp-extreme.ru                        | /loading.htm
    15 | t4-11.mo3gov.net                            | /loading.htm
    15 | forum.100portal.pl                          | /loading.htm
    15 | foro.soranime.net                           | /loading.htm
    15 | info-games.16mb.com                         | /loading.htm
    15 | forum.arva-online.ru                        | /loading.htm
    15 | piton.webuda.com                            | /loading.htm
    15 | forums.egkrinkel.com                        | /loading.htm
    15 | habboinfo.free-h.net                        | /loading.htm
    15 | time-is-now.w2c.ru                          | /loading.htm
    14 | theconfederatestates.net                    | /loading.htm
    14 | forums.bluwavevirtual.org                   | /loading.htm
    14 | forum.thehosthouse.co.uk                    | /loading.htm
    14 | notched.16mb.com                            | /loading.htm
    14 | talk.yumyumpers.ru                          | /loading.htm
    14 | old.zagloba.me                              | /loading.htm
    14 | forum.muzolandia.pl                         | /loading.htm
    14 | ff.xokkeist.ru                              | /loading.htm
    14 | nightcor.cluster015.ovh.net                 | /loading.htm
    14 | rich-rpg.tw1.ru                             | /loading.htm
    13 | forum.prb-fight.dp.ua                       | /loading.htm
    13 | forum.cs-play.org                           | /loading.htm
    13 | letsfiestar.com                             | /loading.htm
    13 | 6.hamming.z8.ru                             | /loading.htm
    13 | forum.l2-virus.net                          | /loading.htm
    13 | elixrr.org                                  | /loading.htm
    13 | easy-host.tw1.ru                            | /loading.htm
    13 | forum.mostpeople.ru                         | /loading.htm
    13 | forum.skygsm.com                            | /loading.htm
    13 | forum.wildspirit.su                         | /loading.htm
    12 | forum.gamer-p.ru                            | /loading.htm
    12 | www.forum.redknife-tm.ru                    | /loading.htm
    12 | www.yozzteam.ru                             | /loading.htm
    12 | 90218.d33a.web.hosting-test.net             | /loading.htm
    12 | forum.illusionsplay.com                     | /loading.htm
    12 | rrp.ct8.pl                                  | /loading.htm
    12 | just-craft.vv.si                            | /loading.htm
    12 | minecraft.fatalforces.com                   | /loading.htm
    11 | forum.filix.ru                              | /loading.htm
    11 | www.forum-csc.pp.ua                         | /loading.htm
    11 | forums.consortiumguild.com                  | /loading.htm
    10 | forum.aresus.ru                             | /loading.htm
    10 | data-direction.hu                           | /loading.htm
     9 | forum.dota-info.ru.yellow.intobservatory.ru | /loading.htm
     8 | forum.lordsofeurope.ru                      | /loading.htm
     7 | volyn.bplaced.net                           | /loading.htm
(78 rows)