Friday, September 20, 2013

Fake AV Malware Hits the Android

Mobile Defender - the last line of protection

Having studied malware delivered by spam for the past seven years, it is a fairly rare event for me to be amazed by something new, but that is exactly what happened today thanks to a new finding by Brendan Griffin, the lead author of Malcovery's Today's Top Threats report.

In yesterday's report, Malcovery customers were informed of a prevalent spam email that used the subject lines:

  • Voice Message Notification
  • 1 New Voicemail(s)
  • 2 New Voicemail(s)
  • 3 New Voicemail(s)
  • 4 New Voicemail(s)
  • 5 New Voicemail(s)
  • 6 New Voicemail(s)
When the spam messages from this campaign are rendered in an HTML mail viewer, the received message looks like this:

For a Windows user who clicks on the link, the malware calculates a location and drops a .zip file to the visitor with a name appropriate for thier location. For example, in yesterday's T3 Report, Brendan documented the behavior of a file he received from "bhaktapurtravel.com.np" that was named "VoiceMail_Birmingham_(205)4581400.zip".

At the time of Brendan's review, only 6 of 48 Antivirus vendors detected the .zip file as malicious according to this VirusTotal Report for zip.

The unpacked file, which used an icon displaying a musical note on a sheet of paper, fared little better, with only 7 of 48 detections as shown in this Virus Total Report for exe.

Twenty-four hours later, that detection is up to 21 of 48 detections, with several vendors (AntiVir, DrWeb, Microsoft) calling the malware "Kuluoz" while BitDefender, EmSoft, and F-Secure prefer the name "Symmi".

Android Version?

Given that the email message was claiming to be from an Android application called "WhatsApp", Brendan revisited the link, using a User-Agent string that would be commonly associated with an Android-based browser.

Instead of receiving an .exe file, when using the Android emulation mode, Malcovery received *AND INSTALLED* a file called "WhatsApp.apk". Examining the code, Brendan found bilingual messages in Russian and English that seemed to be indicating that various malware packages had been found on his phone. Here's one example, that seems to claim the presence of Downad/Conficker:

The Android malware, which had the MD5: 5290df867914473426b82233567c03af, was much better detected by AV engines ...

At first glance, that seems quite encouraging! But think about it more. What possible good does it do you to have AVG, ESET, F-Secure, Kaspersky, and Trend Micro telling you that this APK file is hostile? You certainly aren't running any of their Anti-virus products on your Android phone, are you?

Brendan decided it was time to put this malware into a true Android phone, and received some shocking results, shown below!

First, the Android App pretends to scan your phone for malware . . .

And then, it asks you for your credit card information in order to buy the "Mobile Defender" application to protect your phone!

We were amused by the "Lifetime Software License" which offers a 60% discount. I wonder how many years they expect us to live to calculate that discount! Hopefully they are referring to the lifetime of their malware, rather than us or our phone!

Historical FakeAV Scams

We certainly have been talking about Fake AV for a long time! Here are some of our previous articles on the subject, dating all the way back to 2008 -- but this Fake AV on Android Phones was a first for us, especially in such a prominent spam campaign!

FTC Moves against Fake AntiVirus ScareWare Companies - Dec 2008
Conficker Fears Spread Fake AV - April 2009
Fake Twitter, Linked In, and ScribD pages lead to Fake AV - June 2009
Fake AV in the News - April 2010
MasterCard Spam leads to Fake AV - July 2011

Sites seen in spam with either "info.php" or "app.php" malware links

Each of the sites below was found in spam in the Malcovery Spam Data Mine, either with an "app.php" path, such as "/app.php?message=7nof02WSsCV044njNqRS+F1mNBPcaaHD7u7VE/2vY7c=" or an "info.php" path such as "/app.php?message=NaZNY1tYTjYL5u0C/rimmNLlnDKRleqTEBJme/hthH4="

We believe that each of the sites below was compromised to allow the criminals to insert the "app.php" or "info.php" file on their system.

At this time, we are unsure whether the "localization" seen on the Windows version of this malware is based on geolocation of the infected computer's IP address, or whether the parameter passed in the URL contains an encoding of the user's location. Every URL observed had a unique string in the "message=" portion.

countmachine
countmachinecountmachine
24 babytoysbaby.com4 coffsdentalcentre.com.au
22 bhaktapurtravel.com.np4 admingo.ru
22 tsypa.ru4 5100429.ru
19 manchesterbuddhistcentre.org.uk4 skupina-lira.si
18 koshergiftsuk.com4 planeta-avtomat.ru
17 casperscomputers.com4 personalcarephysio.ca
17 mywebby.ru4 iperidrosi.org
16 ifuneral.it4 dxixisport.com
16 tk-galaktika.ru4 guru27.ru
15 mdou321.ru4 holenefesh.com
14 thaiecom.net4 zag.com.ua
14 thenewdabbs.com4 yildizotel.com.tr
14 locweld.com4 shinyvsem.ru
14 gourmetschlitten.com4 dr-nonna.ru
14 sadafmirza.com4 niessing-gladbeck.de
14 serov1.com4 uwes-futterkiste.de
14 growlerscraftbeerandales.com4 boat-plastic.ru
13 globalpeat.com4 morterablanca.com
13 dj220w.ru4 co-co-mail.net
12 improvisera.net4 vizazh.zp.ua
12 www.raspinawin.com4 verfassungsschutz-bw.de
12 srivivekananda.com4 darkmatta.com
12 amicidelcuore.info4 www.kip26.ru
12 shop-rakushki.ru3 veerbootkobus.nl
11 rkbtservice.ru3 fehoozy.com
11 djvakcina.com3 juhatanninen.com
11 muzikosfabrikas.lt3 artedangi.com
10 ikarplus.com3 truesouthmanagement.com
10 katrinfil.ru3 paternocalabro.it
10 ladwig-gmbh.de3 tennissimo.be
10 profnastil-sm.ru3 westsaitama.com
10 cateringjaipur.com3 venoras.com
10 clockcards.ie3 netbook.com.ua
10 lichtenauer-fv.de3 einstalacje.pl
10 mrsergio.com3 kovka1.ru
10 gseo.it3 piotrkozak.com
10 mirvshkatulke.ru3 momks.org
10 albecoperu.com3 tcpredatorsbaseball.com
9 dimater.com3 autovaza.net
9 dezibelmusik.de3 surya.org
9 goldnart.ru3 fiskr.ru
9 rickhelpt.nl3 piediplomacy.com
9 designmakers.kz3 dis-travel.ru
9 crazyparty.com.pl3 sportsbettingonlineusa.net
9 tc.CastineLLC.com3 dmitriy-vasilchuk.com
9 gustavblome.de3 craftyfolks.net
9 autopialighting.com3 cityglobal.ru
9 eckkaluga.ru3 isuzu.loader.com.ua
9 redmangoindo.com3 isa-scouts.de
9 olimpodelbenessere.it3 www.michael-roos.net
9 mazdaparts.su3 www.ninja-ninja.com
9 lexbox.am3 net2day.tk
8 pennerimperium.de3 maov.info
8 yakitoriya-mo.ru3 elmetsystem.pl
8 dush80-svao.ru3 tischlerei-klemm.de
8 mastersonpr.com3 such-spinne.de
8 slocis.com3 pts.kovrov.ru
8 art52.ru3 thundermistpowerboats.com
8 tva.ru3 sungatov.ru
8 frescomeble.pl3 harald-rupp.com
8 darkstudio.net3 shermes.biz
8 orbitmotion.com3 auronzo.it
8 cam.shaksha.ru3 yakrus.com
8 www.chelyabreduktor.com3 gogreenbravo.com
8 everyday24h.de3 tengritel.kz
8 www.auxtribusindiennes.com3 sewretro.com
7 dialoguetrust.net3 oilhelp.info
7 magavilla.com3 bdlmachines.com
7 structuredsettlementsannuities.com3 cypresshomecareinc.com
7 brainseal.com3 yalublutebyazhizn.ru
7 bareli.co.il3 specialistdental.com.au
7 colorpaco.com3 trivenidigital.com
7 kasutin.ru3 englishteam.ru
7 www.myinnerpc.com2 e-nt.de
7 fasthotel.ru2 cargor.net
7 whiteys.co.uk2 ingredientspring.com
7 smsa.pt2 cthmail.de
7 granitderi.com.tr2 corpstroy.ru
7 ntsysteme.de2 heartwood.com
7 artisan-co.ru2 na-derevnu-dedu.ru
7 mosobladvokatura.ru2 swanseacity.co.uk
7 gamez.com.ua2 mdou104.ru
7 sentabilisim.com2 assistantinukraine.com
7 tufts.biz2 wowbestservers.com
6 angelomasotti.it2 arsenalyar.ru
6 tripdogs.com2 velvet-sound.ru
6 ciarko.by2 intimdosug38.ru
6 big-cock.biz2 supertouch.co.in
6 softrace.no2 chemycards.com
6 haugesund-toppidrettsgymnas.no2 cebuhomesville.com
6 samedaystationery.co.uk2 leaderscenter.com
6 tadaphotography.com2 rolandward.co.uk
6 dyffryn.org2 ignologics.com
6 hochseilgarten-springe.de2 zarco-sic.com
6 bagnaradiromagna.net2 etarlo.ru
6 sitallsmolensk.ru2 bigpk.ru
6 humtata.de2 ofis-v-nikolaeve.com
6 tiarahlds.com2 ravolna.ru
6 allpress.biz2 pyora68.net
6 zdrowieonly.ovh.org2 poster.ua
6 webasto-ufa.ru2 scottishtaxifinance.co.uk
6 custers.ru2 formularmaker.com
6 hansobermeier.de2 ais-stroi.ru
6 ziehdichauskunft.com2 bluereefwatersports.com
6 venetamalaysia.com2 fundigital.org
6 cathedralcityestates.co.uk2 avminho.pt
6 paminklaizidiniai.lt2 pechatiboom.ru
6 mbuhgalter.ru2 filtrum-safari.ru
6 shilvi.com2 aquatechperu.com
6 orderschering.com2 butik-koles.ru
5 mouvsoch185.ru2 visumconsulting.com
5 zenxual.com2 warehouseboxing.com
5 michael-roos.net2 elviras-tischdeko.de
5 easywebmexico.com2 homemoney.ru
5 agapy.com2 mar-kant.nl
5 marsperformance.ru2 eeesolution.com
5 muzacikunovice.cz2 microfi.co.uk
5 andyxator.ru1 neps.ru
5 bahfuture.org1 christel-gekeler.de
5 cfgb.fr1 open-63.ru
5 golazvezda.ru1 hardmetalunderground.com
5 mapradio.org1 nickparton.com
5 therabrands.com1 dieschrauba.at
5 goetzke-krottelbach.de1 gardi.eu
5 paleorecip.es1 vivasan-forum.ru
5 rus-futbolka.ru1 aki-kowalstwo.pl
5 lcc.org.au1 dotmatt.com
5 stolk.de1 wesselinkgmbh.de
5 mikemetcalfe.ca1 turfirma-yaroslavl.ru
5 nbvf.nl1 positivelynaked.com
5 juszczyn.eu1 barkersofwindsor.co.uk
5 izumrudny.org1 assignmentwriting.co.uk
5 myinnerpc.com1 manfred-konrad.de
5 burtonbrothers.net1 frenken-adviesburo.nl
5 asesoriacontableperu.com1 alumdeco.ru
5 dustycatwriter.com1 pawsathome.ca
5 coolpcgames.co.uk1 demonic3d.com
5 wallmountainweb.com1 computing4schools.co.uk
5 airspill.com1 visibus.ru
5 schweitzers.com1 nazike.com
5 cond.ru1 vitapool.ru
5 trimeducation.com1 eventlocation-kiel.de
5 bfphotography.eu1 radio-kabyle.com
5 meter-online.info1 stkiliansnsmullagh.ie
5 organocontinuo.com1 spentec.ca
5 damsit.com1 gsp35.ru
5 ahkrc.org1 shkolaimperatritsy.ru
5 tc.castinellc.com1 cdrv.ru
5 muralzbyjean.com1 altaicompass.com
5 gubo.com1 pototype.com
4 paulhughestransport.com1 line-message.net
4 koo-doo.ru1 sad-natali.ru
4 louisedenson.com1 gie-expo.com
4 mcmillandefense.com1 lkmining.com
4 avionstudio.com1 sonyfoto.com.pt
4 permanentmakeup-soest.de1 schulezorneding.de
4 rogerclarkejohnson.com1 angelkeeper.ru
4 solovy.ru1 enlightenpro.com
4 simoneliebst.de1 burim.by
4 georgysphoto.ru1 pp73.ru
4 initsiativa.com1 avitrade.ru
4 mephics.co.tz1 centik.de
4 pax-sancta.de1 nevertoolatebook.com
4 physiotherapie-kies.de1 alyes.nl
4 idollighting.com1 romchik.com
4 semeylib.kz1 towi69.de
4 foundationforhealthaction.org1 eplater.co.uk
4 ekimenko.net1 intal.net.ua
4 mikroeta.lt1 radio-germanija.de
4 contact.com.vn1 manjitubhi.com
4 yu7.ru1 carrahar.co.uk
4 srmarketers.com1 arenda-t.ru
4 supercarsofmoscow.ru1 torbeta.com
4 greaterbaycomputer.com1 ventoz.ru
1 babysun-volga.ru

Monday, August 19, 2013

Cross Brand Intelligence and Phishing

While there is certainly a reason to shut down any site imitating your company as fast as possible, we have to always consider what the implications are of understanding the Cross-Brand Intelligence aspects of any site being abused to imitate an organization. A rare open directory shared by our friend, security researcher Tom Shaw, gives a perfect example of this.

The website on the IP address 38.64.138.118 has an open directory on it's root, showing the dates of creation of a number of phishing campaigns:

July 23, 2013 @ 23:47 == "v3/"
August 8, 2013 @ 11:58 == "picture.png/"
August 9, 2013 @ 01:56 == "apple.png/"
August 14, 2013 @ 17:42 == "paypal.png/"
August 15, 2013 @ 06:49 == "contar.png/"
Attempting to visit the "/apple.png/" page on that server results in a 302 redirection to the address "http://venenolabs.activo.in/h5-apple"

Similarly, attempting to visit the "/picture.png/" page on that server results in a 302 redirection to the address "http://venenolabs.activo.in/h6-vbv/" The Apple page redirects to pearstech.com where an Apple phishing page is displayed: The Visa page redirects to rajeshwasave.com where a Visa Argentina phishing page is displayed: venenolabs.activo.in is on the IP address 174.36.29.21.

Both Pearstech.com and Rajeshwasave.com are on the IP address 174.37.147.184.

The "paypal.png" site no longer resolves to a Paypal server, although it did. It has now been repurposed to also redirect to: The "contar.png" page is an interesting one, after showing what appears to be an AdFly link for a pay-per-click affiliate program run by "theunifiedwealthteam.com" we are forwarded to the Facebook page of "Veneno Labs" who seem to primarily boast in Spanish about the various websites they have hacked and defaced. No idea if V3NEN0 LABS, whose facebook posts are mostly from the area of Lima Peru, has anything to do with the phishing sites or not until we review some logs. Veneno uses the email address "venenolabs@yahoo.com", according to his Facebook page.

MAD666 and #d3xt3rH4ck seem to be members of the T34M. (SO elite! Did you see how they spelled Team?)

As with most defacers, it's often interesting to look at their very first actions. In this case, as soon as Veneno had a facebook page, "Jesusedus" Jesus Edu Soto Meza, was clicking Like on his images. A Computer Science student from Lima, Peru attending IDAT Computacion?

(Perhaps Dexter Hack? ==> https://www.facebook.com/dexterhackperu.defaced.3 )

The Veneno Labs group has more than 500 members, and a gmail account ==> venenolabs@Gmail.com ( https://www.facebook.com/groups/419870534733048/ )

Perhaps the most interesting is the "lol.exe" which is a Zeus malware installer.

It seems that our Peruvian website defacers have moved across the line from Hacktivism to Phishing and Malware distribution!

Monday, August 12, 2013

Anonymous, #OpBankster, and the Too Many Nancy's Problem

The current Anonymous "#OpBanksters" seems to have very little in common with the original operation by the Anonymous Portuguese group that was originally posted on YouTube back on April 14, 2013. However, the beginning of the current round started with an August 8th post by @AnonLegionPT (Anonymous Legion PT) inviting people to view the original video and then log on to AnonNet and join the "#opbanksters" chat room on Friday the 9th at 10 PM to discuss.

www.youtube.com/watch?v=9ZdMlgnvaqQ&feature=youtu.be

While we don't know what happened in the chat room, the result was that we began to see posts on PasteBin listing the email addresses and internet-facing IP addresses and hostnames of Portuguese banks.

An English translation of the Portuguese video reads:


Published on Apr 14, 2013

Greetings. We are Anonymous Portugal and this is the # banksters operation, a protest action against banks around the world, who have created a corrupt financial system based on debt-interest, speculation large sums with large multinationals and made the money a lucrative business that benefits a minority, but enslaves the rest of the population.

Banks extend credit to slashing with money created out of thin air, causing a snowball effect on the shortcomings of the banking system relative to the overall debt. With this system, banks enrich immeasurably, pay low interest on that deposit and charge high interest loans they make.

With this system of interest, speculation of the value of money and inflated product, it is easy to see where they come from debt, not only of companies and governments, but also emerge as the personal debt of each family. For years, banks eased lending by attracting people with the illusion of being able to have great purchasing power by easy access to money, and creating a debt trap from which many now can not get out. The social stratification, poverty, hunger and unemployment are therefore a consequence of the existing financial system, fatalities that may not disappear while this persists.

Banks in Portugal receive 8 billion state budget since 1999, are recapitalized with $ 12 billion in 2012 and are still saying that the people are having to endure? Portuguese people must know the true and the real gangsters responsible for the crisis, beyond the state. # OpBanksters: Portuguese and international banks, your time has come!

We are Anonymous!
We are Legion!
We do not forgive!
We do not forget!
Expect us!


While the original Twitter posts this week WERE from Anonymous Portugal, and the original PasteBin posts were also about Portuguese bank Credito Agricola, the Op quickly grew beyond its original intention of punishing Portuguese banks for being poor custodians of public funds.

The first three banks posted to the Operation's PasteBin page were:
Banco dos Espiritos Santos (BES) Portugal (110 emails / 62 hosts)
CreditoAgricola Portugal (136 emails)
and BBVA Portugal/Spain

On August 10th, with the exception of the European banking Authority (europa.eu) only Portuguese banks had their employee email addresses and hosts listed, including:

Cetelem PT
Credibom PT
Cofidis PT
Montepio PT
Banif PT
Bancobic PT
Banco BPI PT
Millennium BCP PT
Banco Popular PT/ES

On August 11th the information disclosure activity spread beyond the borders of Portugal.

Bank of America
Barclays
Lincoln State Bank
Deutsche Bank AG US
Dun & Bradstreet
FDIC
Federal Mortage Association
Federal Reserve Banks of Atlanta, New York, Richmond, and San Francisco
Fitch Rating
Goldman Sachs
Hartford Financial
Huntington Bank
Imperial Bank of Canada
London Stock Exchange

On August 12th (so far) we have seen added:

Moody's
Nasdaq
National Australian Bank
PNC
Royal Bank of Canada
Standard & Poors
SunTrust
M&T Bank
Royal Bank of Scotland
TD (Toronto Dominion)
Union Bank
Wall Street Insurance
Wall Street Journal
Citibank
JP Morgan Chase
Zurich Financial
were all added to the list. In the case of Bank of America, as one extreme example, more than 3700 named employees, with titles and emails, were listed.

At that point, we thought there may be a major problem with email-based security about to be unleashed!

As I discussed on Hacker HotShots this week, the Verizon Data Breach Investigations Report quotes "ThreatSim.com" as saying that when a hostile email is sent to three employees of an organization, there is a 50% chance that someone will click on it, but when an email is sent to TEN employees, there is nearly a "Guarantee" that someone will click on it! I couldn't imagine how bad things could go if 3700 employees were being targeted by hand-crafted malicious emails!

That seemed to be the what was happening already in Portugal, as we began to see defacements appear, such as this one hosted on the website "www.cie.com.pt" which is the "Centro de Intervenção Empresarial" showing "#opBankster" branded defacements:

The Anonymous Portugal Blog is here:

anonymouspt.blogspot.com/2013/08/op-banksters-part-ii.html

Their Facebook page is here:

https://www.facebook.com/AnonymousLegionPt

They claim to have successfullly DDOSed:

www.complemento-vintage.pt
www.lusonegocio.com
www.credibom.pt
www.flexibom.pt
www.cofidis.pt
www.cetelem.pt
and have confirmed that they are behind the PasteBin handle "#opBanksters"

The Too Many Nancy's Problem

As I started looking through the list of so many leaked addresses for all of these North American banks, I realized there might be a problem. The naming convention for each of the banks was "First Name, Last Initial" @ domain.com, so if I were on the lists, Gary Warner, my email would be given as "garyw@zurichna.com" or "garyw@frbatlanta.org" or "garyw@tdbank.ca". Obviously there would be collisions if that were the case, but I didn't see any attempt to avoid them. I also correspond regularly with many of the brands attacked, and realized that in many cases the domain listed is NOT the domain name where individuals who work for that organization receive their emails.

I decided to do a frequency distribution on the first names and look for "over-represented" names that seemed unlikely to me. I won't go into all the details here, but I looked at female first names from the 1990 US Census and compared them to distributions here. (A 1990 census person would be at least 23, so may be well represented in the work force. Anyone older than 23 would also be listed in the 1990 census, so it seemed as good a source as any.

MARY           2.629  2.629      1
PATRICIA       1.073  3.702      2
LINDA          1.035  4.736      3
BARBARA        0.980  5.716      4
ELIZABETH      0.937  6.653      5
JENNIFER       0.932  7.586      6
MARIA          0.828  8.414      7
SUSAN          0.794  9.209      8
MARGARET       0.768  9.976      9
DOROTHY        0.727 10.703     10
LISA           0.704 11.407     11
NANCY          0.669 12.075     12
On the first file I reviewed, I had, instead of the distribution above:
6 Mary's
1 Patricia
10 Linda's
7 Barbara's
9 Elizabeth's
14 Jennifer's
5 Maria's
7 Susan's
3 Margaret's
2 Dorothy's
6 Lisa's 
14 Nancy's
Now that may not be the most scientific of comparisons, but as a genealogist, I was confident I was dealing with TOO MANY NANCY'S!

Focusing in on the Nancy's the problem really started showing up. In each of the bank email lists I reviewed, the distribution of names was wildly out of line, and for popular names included many duplicate email addresses that would further confirm these were fakes. For example, just at Toronto Dominion, we had people with the email address "nancym@tdbank.ca" in the following positions and locations:

nancym@tdbank.ca == A Financial Planner in Richmand Hill, Ontario
nancym@tdbank.ca == A Merchant Risk Analyst II in Lewiston, Maine
nancym@tdbank.ca == A Recruitment manager in Toronto, Ontario
nancym@tdbank.ca == A Senior Compliance Officer in Hagersville, Ontario

Malcovery Security specializes in dealing with Email-based threat intelligence. We've got some great ideas for dealing with this current situation. Please reach out to us if you'd like to discuss.

Saturday, August 10, 2013

When Parked Domains Still Infect - Internet.bs and ZeroPark

This summary is not available. Please click here to view the post.

Wednesday, July 24, 2013

"Royal Baby" & Other CNN spam leads to malware

As many sources reported earlier today, an email claiming to be from CNN's "Scribbler" provided a link to "Watch Live Hospital Updates" of the Royal Baby:

But what do Harrison Ford, President Obama, and Snowden have in common with The Royal Baby?

They were all subjects of fake "CNN Breaking News" stories delivered by spam email today that contained links to a dangerous collection of malware! In the Malcovery Spam Data Mine we had hundreds of copies of emails with subjects including:

"Snowden able to leave Moscow airport" - BreakingNews CNN
"Harrison Ford on 'Ender's Game' controversy: 'Not an issue for me'"
"Obama speech to urge refocus "
"Perfect gift for royal baby ... a tree?" - BreakingNews CNN


(click each image for full-size email)

To demonstrate the relatedness of the spam, a list of the URLs that were used by each of the four campaigns is listed at the end of this article, labeled either "snowden", "ender", "obama", or "tree" for which campaign advertised that URL. We threw all of the advertised URLs into a fetcher and found that there were two files found in the destinations. The first (from earlier in the day) pointed to two Javascript files that were used to redirect the visitor to an Exploit Kit that would cause malware dropped to their computer. The second (later in the day, and still live as of this writing) pointed to three Javascript files that redirected to a different Exploit Kit site.

I've added spaces to the URLs for your protection, but DO NOT VISIT ANY OF THESE URLS!!!

(early morning version <== redirects to nphscards.com / topic / accidentally-results-stay.php )

index.html with MD5 = 958a887fcfcad89b3fdeea4b58e55905
  - which loads two Javascript files:
               ftp.thermovite.de   / kurile  / teeniest.js     
               traditionalagoonresort.com  / prodded  / televised.js  
(afternoon version <== redirects to deltaboatraces.net / topic / accidentally-results-stay.php )
index.html with MD5 = bc73afe28fc6b536e675cea4ac468b7d 
   - which loads three Javascript files:
                  thealphatechnologies.com   / advantageously   / autopilots.js 
                  atlas247.com   / mussiest   /syndicating.js  
                  www.mshc.in   /drubbing   / mouthful.js 
Since it was late in the day by the time I was able to review these myself, I infected myself with the afternoon version.

deltaboatraces.net == 173.246.104.136 and is still an active infector as of this timestamp.

I got a randomly named 297,472 byte file, detected by 11 of 46 Anti-Virus vendors at VirusTotal.com, which was Zeus.

See VirusTotal Report

Adobe Flash Player Update?

After infecting, the website tries to trick the user into "upgrading his Adobe Flash Player", but please notice in the graphic below, I'm not on the Adobe website!

After "installing" my Adobe update, my sandbox went crazy and also fetched malware from each of these locations:

After infection with the second my sandbox went to "deltarivehouse.net / forum / viewtopic.php" (173.246.104.136) which caused a string of additional infections to occur. While the initial infection was Zeus, the well-known Financial Crime malware that steals banking information, but also provides criminals full remote-control capabilities to your computer, the purpose of the additional malware was for another form of money making.

"sainitravels.in" (204.11.58.185) to fetch "f7Qsfao.exe"
(VirusTotal: 8 of 46)) - "Tepfor" or "Medfos" malware

"server1.extra-web.cz" (212.80.69.55) to fetch "dbm.exe"
(VirusTotal: 8 of 46)

"www.MATTEPLANET.com" (208.86.184.10) to fetch "q7ojEH7.exe"
(VirusTotal: 4 of 46)

"ictsolutions.net.au" (27.124.120.1) to fetch "SAQjaWu.exe"
(VirusTotal: 8 of 46)

Medfos, one of the malware names given to several of the above, is an "Advertisement redirection" malware campaign. Microsoft did a great job explaining how Medfos works in their blog post, Medfos - Hijacking Your Daily Search on the Microsoft Malware Protection Center blog back in September. Some of the sites that seem to be related to this Medfos install include "bidpenniesforgold.net" (IP: 50.63.25.37) and "webpayppcclick.com" (IP: 85.17.147.34).

According to our friends at Domain Tools, that last IP address is associated with a whole world of "Pay Per Click" fraud domains, including:

advertisingclickfeed.com
allfeedppcadvertising.com
clickppcadvertisingone.com
clickwebppcpay.com
csuperclick.com
feedppcadvertisingdirect.com
feedppcadvertisinginfo.com
feedyourppcdirect.com
firstfeedppcadvertising.com
newpaywebclick.com
onlineppcclick.com
paymittelsclick.com
payonlineppc.com
payppcclickonline.com
paywebclick.com
paywebclicksite.com
perclickguide.com
perclicksite.com
perclickworld.com
ppcadvertisingfeed.com
ppcadvertisingworld.com
ppcclickonlineppc.com
ppcnewfeed.com
ppcperclickadvertising.com
ppcperpayadvertising.com
ppcwebclickpay.com
streamppcadvertising.com
webpayppcclick.com
Hopefully tying these malware samples to that activity can help someone clean up that mess! (Attention: Leaseweb!)

Spammed URLs for the Snowden, Ender, Obama, and Tree Campaigns

obama198.251.67.11/incumbency/index.html
obama198.251.67.11 /philippine/index.html
obama198.251.67.11 /stifles/index.html
snowden198.251.67.11/campaigners/index.html
snowden198.251.67.11/foxhole/index.html
snowden198.251.67.11/fracturing/index.html
snowden198.251.67.11/incumbency/index.html
tree198.251.67.11/nomadic/index.html
tree198.251.67.11/philippine/index.html
tree198.251.67.11/reprehended/index.html
tree198.251.67.11/sauciness/index.html
tree198.251.67.11/sonya/index.html
snowden198.251.67.11  /voodooing/index.html
ender198.61.134.93 /decompressed/index.html
ender198.61.134.93 /dinosaur/index.html
ender198.61.134.93 /microeconomics/index.html
ender198.61.134.93 /packard/index.html
ender198.61.134.93 /reprimanding/index.html
ender198.61.134.93 /sash/index.html
ender51956147.de.strato-hosting.eu   /radicalism/index.html
ender51956147.de.strato-hosting.eu   /remote/index.html
ender51956147.de.strato-hosting.eu   /soyinka/index.html
obama96.9.7.80                /draftier/index.html
tree96.9.7.80      /coif/index.html
tree96.9.7.80      /contentious/index.html
snowden96.9.7.80      /imperiling/index.html
snowden96.9.7.80      /implausibilities/index.html
tree96.9.7.80      /slaloming/index.html
snowden96.9.780       /imperiling/index.html
enderadeseye.me.pn /clunkier/index.html
enderadeseye.me.pn /incest/index.html
enderadeseye.me.pn /mischancing/index.html
enderadeseye.me.pn /rarest/index.html
enderadeseye.me.pn /uglies/index.html
enderandywinnie.com/albert/index.html
enderandywinnie.com/anywheres/index.html
enderandywinnie.com/chairing/index.html
enderandywinnie.com/fits/index.html
enderandywinnie.com/network/index.html
enderandywinnie.com/preservation/index.html
enderaptword.com.my/dromedaries/index.html
enderaptword.com.my/incurred/index.html
enderaptword.com.my/interpol/index.html
enderaptword.com.my/translations/index.html
enderaptword.com.my/vietminh/index.html
obamaassuredpropertycare.net  /overlying/index.html
obamaassuredpropertycare.net  /sneezes/index.html
treeassuredpropertycare.net /arrhenius/index.html
snowdenassuredpropertycare.net  /changed/index.html
snowdenassuredpropertycare.net/debaucheries/index.html
snowdenassuredpropertycare.net  /dulls/index.html
treeassuredpropertycare.net  /dulls/index.html
snowdenassuredpropertycare.net /overlying/index.html
treeassuredpropertycare.net /premeditation/index.html
treeassuredpropertycare.net /shekels/index.html
snowdenassuredpropertycare.net  /sneezes/index.html
obamabbsmfg.biz  /belaying/index.html
obamabbsmfg.biz               /lather/index.html
treebbsmfg.biz     /activists/index.html
snowdenbbsmfg.biz     /intellectualize/index.html
snowdenbbsmfg.biz     /lather/index.html
treebbsmfg.biz     /servo/index.html
treebbsmfg.biz     /skiing/index.html
treebbsmfg.biz     /tourist/index.html
snowdenbbsmfgbiz      /intellectualize/index.html
snowdenbbsmfgbiz      /lather/index.html
enderbestpaintinginc.org             /candidacy/index.html
enderbestpaintinginc.org             /enmeshes/index.html
enderbestpaintinginc.org             /genitives/index.html
enderbestpaintinginc.org             /hardly/index.html
enderbestpaintinginc.org             /parser/index.html
obamabordihn.net              /rubik/index.html
snowdenbordihn.net    /gnarl/index.html
treebordihn.net    /gnarl/index.html
treebordihn.net    /gushing/index.html
treebordihn.net    /reformulates/index.html
snowdenbordihn.net    /squirreling/index.html
treebordihn.net    /squirreling/index.html
enderchad.westhostsite.com           /addle/index.html
enderchad.westhostsite.com           /augmenting/index.html
enderchad.westhostsite.com           /buttonholes/index.html
enderchad.westhostsite.com           /expend/index.html
enderchad.westhostsite.com           /shillings/index.html
enderchad.westhostsite.com           /unfailing/index.html
enderCHALONE.COM.SG/ebbed/index.html
enderCHALONE.COM.SG/homy/index.html
enderCHALONE.COM.SG/saddling/index.html
obamadeerstalkersbop.org.nz   /evelyn/index.html
snowdendeerstalkersbop.org.nz               /absconding/index.html
treedeerstalkersbop.org.nz               /actioning/index.html
treedeerstalkersbop.org.nz               /bathroom/index.html
snowdendeerstalkersbop.org.nz               /dissatisfied/index.html
treedeerstalkersbop.org.nz               /dissatisfied/index.html
snowdendeerstalkersbop.org.nz               /tran/index.html
obamadtgcommunity.com         /imprimatur/index.html
snowdendtgcommunity.com   /electroencephalographs/index.html
treedtgcommunity.com   /electroencephalographs/index.html
snowdendtgcommunity.com   /gentlefolk/index.html
treedtgcommunity.com   /gunpoint/index.html
treedtgcommunity.com   /ingresses/index.html
snowdendtgcommunity.com   /parachutists/index.html
treedtgcommunity.com   /seesawing/index.html
snowdendtgcommunity.com   /thwacked/index.html
snowdendtgcommunity.com   /tzar/index.html
treeedition.cnn.com/
obamaekaterini.mainsys.gr     /bloodier/index.html
obamaekaterini.mainsys.gr     /habitual/index.html
treeekaterini.mainsys.gr                 /habitual/index.html
snowdenekaterini.mainsys.gr                 /livelongs/index.html
treeekaterini.mainsys.gr                 /oxymora/index.html
snowdenekaterini.mainsys.gr                 /peddle/index.html
snowdenekaterini.mainsys.gr                 /prithee/index.html
treeekaterini.mainsys.gr                 /suggested/index.html
snowdenekaterini.mainsys.gr                 /voled/index.html
treeekaterini.mainsys.gr                 /voled/index.html
enderfermatabow.com/clinicians/index.html
enderfermatabow.com/depicting/index.html
enderfermatabow.com/fairyland/index.html
obamaftp.suavva.com           /initiators/index.html
obamaftp.suavva.com           /riverbed/index.html
obamaftp.suavva.com           /sousa/index.html
snowdenftp.suavva.com /overstatements/index.html
treeftp.suavva.com /sousa/index.html
treeftp.suavva.com /surges/index.html
obamafuhr-haustechnik.de      /resubmit/index.html
treefuhr-haustechnik.de/attempted/index.html
treefuhr-haustechnik.de/continua/index.html
treefuhr-haustechnik.de/impartially/index.html
snowdenfuhr-haustechnik.de/recollecting/index.html
treefuhr-haustechnik.de/recollecting/index.html
treefuhr-haustechnik.de/taboo/index.html
snowdenfuhr-haustechnik.de/unswerving/index.html
endergbihongkong.org                 /boer/index.html
endergbihongkong.org                 /economist/index.html
endergbihongkong.org                 /inconsiderately/index.html
endergbihongkong.org                 /unenlightened/index.html
endergrape.wurster.ws                /filtration/index.html
endergrape.wurster.ws                /geisha/index.html
endergrape.wurster.ws                /pagans/index.html
endergrape.wurster.ws                /rationalized/index.html
endergrape.wurster.ws                /spica/index.html
endergrape.wurster.ws                /suntans/index.html
snowdenhackspitz.com  /adidas/index.html
snowdenhackspitz.com  /candied/index.html
snowdenhackspitz.com  /impropriety/index.html
treehackspitz.com  /kook/index.html
treehackspitz.com  /penetrable/index.html
obamahotelnewyorkbd.com       /twill/index.html
treehotelnewyorkbd.com /bayou/index.html
snowdenhotelnewyorkbd.com /doyens/index.html
treehotelnewyorkbd.com /doyens/index.html
snowdenhotelnewyorkbd.com /fiftieths/index.html
snowdenhotelnewyorkbd.com /hill/index.html
snowdenhotelnewyorkbd.com /preyer/index.html
treehotelnewyorkbdcom  /bayou/index.html
enderic44.com  /bulgarian/index.html
enderic44.com  /byword/index.html
enderic44.com  /flourishes/index.html
enderic44.com  /ganglier/index.html
enderic44.com  /sundry/index.html
enderisgett.org/ambling/index.html
enderisgett.org/besmirched/index.html
enderisgett.org/daybed/index.html
enderisgett.org/discriminatory/index.html
enderisgett.org/flux/index.html
enderisgett.org/tanzania/index.html
obamajobarium.com             /sham/index.html
snowdenjobarium.com   /benefactresses/index.html
snowdenjobarium.com   /hobos/index.html
treejobarium.com   /melissa/index.html
obamajoerg.gmxhome.de         /ease/index.html
obamajoerg.gmxhome.de         /freezes/index.html
snowdenjoerg.gmxhome.de   /ease/index.html
snowdenjoerg.gmxhome.de   /enumerated/index.html
treejoerg.gmxhome.de   /enumerated/index.html
snowdenjoerg.gmxhome.de   /harvester/index.html
treejoerg.gmxhome.de   /skeptically/index.html
treekassos.gr      /bode/index.html
treekassos.gr      /chosen/index.html
snowdenkassos.gr      /dragooning/index.html
snowdenkassos.gr      /futility/index.html
snowdenkassos.gr      /golf/index.html
snowdenkassos.gr      /walkways/index.html
treekassos.gr      /walkways/index.html
snowdenkassosgr       /futility/index.html
snowdenkassosgr       /golf/index.html
obamakryokontur.fr            /biopsy/index.html
obamakryokontur.fr            /brows/index.html
obamakryokontur.fr            /kern/index.html
obamakryokontur.fr            /nosh/index.html
treekryokontur.fr  /alternator/index.html
snowdenkryokontur.fr  /brows/index.html
treekryokontur.fr  /brows/index.html
treekryokontur.fr  /curs/index.html
treekryokontur.fr  /heating/index.html
snowdenkryokontur.fr  /housebreaking/index.html
snowdenkryokontur.fr  /preheats/index.html
snowdenkryokontur.fr  /tint/index.html
snowdenkryokontur.fr  /windmills/index.html
enderlees-landscaping.com            /angiosperm/index.html
enderlees-landscaping.com            /barrettes/index.html
enderlees-landscaping.com            /illegitimacy/index.html
snowdenlimelight.arinet.com                 /cloy/index.html
snowdenlimelight.arinet.com                 /hamlet/index.html
treelimelight.arinet.com                 /hamlet/index.html
snowdenlimelight.arinet.com                 /universities/index.html
obamalostfounddevices.com     /mama/index.html
obamalostfounddevices.com     /mullet/index.html
obamalostfounddevices.com     /unavoidable/index.html
obamalostfounddevices.com     /unavoidable/indexhtml
snowdenlostfounddevices.com                 /blaspheme/index.html
snowdenlostfounddevices.com                 /espinoza/index.html
treelostfounddevices.com                 /espinoza/index.html
snowdenlostfounddevices.com                 /friskily/index.html
snowdenlostfounddevices.com                 /hunchbacked/index.html
snowdenlostfounddevices.com                 /mama/index.html
treelostfounddevices.com                 /mama/index.html
snowdenlostfounddevices.com                 /manageable/index.html
snowdenlostfounddevices.com                 /undresses/index.html
treelostfounddevices.com                 /undresses/index.html
snowdenmydataplus.com /parenthesized/index.html
snowdenmydataplus.com /powhatan/index.html
treemydataplus.com /spotlessness/index.html
obamanendt.com                /degree/index.html
treenendt.com      /famous/index.html
snowdennendt.com      /horded/index.html
snowdennendt.com      /phoneyed/index.html
snowdennendt.com      /psalmists/index.html
treenendt.com      /shown/index.html
snowdennendt.com      /spreaders/index.html
enderphotos4earth.com                /strobe/index.html
enders273524369.onlinehome.us        /disarray/index.html
enders273524369.onlinehome.us        /opposite/index.html
enders273524369.onlinehome.us        /sheepishly/index.html
enders273524369.onlinehome.us        /wakes/index.html
enders273524369.onlinehome.us        /yeasty/index.html
trees3.hostingkartinok.com               /uploads/images/2013/07/98de33a494997c23b11e1c1259955ebd.jpg
trees3.hostingkartinok.com               /uploads/images/2013/07/98de33a494997c23b11e1c1259955ebdjpg
trees3hostingkartinok.com                /uploads/images/2013/07/98de33a494997c23b11e1c1259955ebd.jpg
obamas5.hostingkartinok.com   /uploads/images/2013/07/4a36da5ef96e4d41aa3a6ba91f1c7a9a.jpg
obamas5.hostingkartinok.com   /uploads/images/2013/07/4a36da5ef96e4d41aa3a6ba91f1c7a9ajpg
obamas5hostingkartinok.com    /uploads/images/2013/07/4a36da5ef96e4d41aa3a6ba91f1c7a9a.jpg
enderstolichband.com                 /betook/index.html
enderstolichband.com                 /daddy/index.html
enderstolichband.com                 /laudatory/index.html
enderstolichband.com                 /mediated/index.html
enderstolichband.com                 /modulation/index.html
enderstolichband.com                 /slander/index.html
enderstolichband.com                 /slovakian/index.html
obamat.co   /068wfdEwvI
obamat.co   /0B3uJXHZHq
obamat.co   /2RKkCjMhDY
obamat.co   /3Bi5WUDuzQ
obamat.co   /6oxioBYqIN
obamat.co   /7qev03NGnJ
obamat.co   /a4ERRbQQl4
obamat.co   /acBBL0xTCV
obamat.co   /bkkUHH67hJ
obamat.co   /bXH47NZNqO
obamat.co   /C6DXVWqaBc
obamat.co   /c6pMmdDPpO
obamat.co   /dcLDDl0aty
obamat.co   /DKgUzhWMr9
obamat.co   /dpM6GQ5NZ5
obamat.co   /dW8S1lHWkf
obamat.co   /e9AsQbSPBW
obamat.co   /eGRRrXsqQP
obamat.co   /EUKNmKfV7q
obamat.co   /f3bUOwEME8
obamat.co   /fOPdMNQOsM
obamat.co   /g29I6C8vZy
obamat.co   /GfduFeg1yd
obamat.co   /gGGSrs26ZU
obamat.co   /gKwkpduJ5v
obamat.co   /Gs7xupxY4e
obamat.co   /hP66qiEvov
obamat.co   /htgnJQgBls
obamat.co   /ims3mUbQAJ
obamat.co   /j7WCQHF8ZR
obamat.co   /JNaITTgZF4
obamat.co   /JyXdiTk9zz
obamat.co   /k99DjSMgDX
obamat.co   /KroVjGhTzS
obamat.co   /lwcWsTSwc9
obamat.co   /m69otwSQB6
obamat.co   /M8wADK71ii
obamat.co   /MMJJZm6BgK
obamat.co   /MrjneT1p2F
obamat.co   /nD7PWsTS2Z
obamat.co   /nGGBXHTZiR
obamat.co   /NT9VneQG7G
obamat.co   /o5dSTNSEWg
obamat.co   /OR7w6EeD2s
obamat.co   /PMuNvHMrPz
obamat.co   /Q4diDo0JMR
obamat.co   /QEdUNFwVSe
obamat.co   /qEQMOBXrQu
obamat.co   /rfiCBnJbng
obamat.co   /RGFxIi96oy
obamat.co   /Rlu9pAZfbd
obamat.co   /SbzAPP8Vdh
obamat.co   /TtGPbv2jkt
obamat.co   /twZBBrhZF6
obamat.co   /utoI54aE3a
obamat.co   /vj38vKkeNZ
obamat.co   /vp6XZXxaev
obamat.co   /VPxdX8abZV
obamat.co   /xDlelOjWBn
obamat.co   /XFiGKFtVKp
obamat.co   /XOWz23aYDY
obamat.co   /y5jSjRvpnk
obamat.co   /yCZT3kJ259
obamat.co   /yfpfhlOVyB
obamat.co   /yJqGYQPmwe
obamat.co   /ytpUhryXaB
obamat.co   /YVTow2XnJ8
endertpafbicaaorg.web.siteprotect.net/expansionist/index.html
endertpafbicaaorg.web.siteprotect.net/tocqueville/index.html
endertransstorlogistics.eu           /cowered/index.html
endertransstorlogistics.eu           /dapples/index.html
endertransstorlogistics.eu           /dentist/index.html
endertransstorlogistics.eu           /footpaths/index.html
endertransstorlogistics.eu           /have/index.html
endertransstorlogistics.eu           /miraculous/index.html
obamavillaflorida.biz         /backslappers/index.html
obamavillaflorida.biz         /chin/index.html
obamavillaflorida.biz         /encapsulates/index.html
treevillaflorida.biz   /caste/index.html
treevillaflorida.biz   /chin/index.html
snowdenvillaflorida.biz   /cliquish/index.html
treevillaflorida.biz   /cliquish/index.html
snowdenvillaflorida.biz   /huitzilopitchli/index.html
snowdenvillaflorida.biz   /rotogravure/index.html
treevillaflorida.biz   /unloosing/index.html
obamawhittakerwatertech.com   /beveling/index.html
obamawhittakerwatertech.com   /butlers/index.html
snowdenwhittakerwatertech.com               /careering/index.html
snowdenwhittakerwatertech.com               /guardroom/index.html
treewhittakerwatertech.com               /guardroom/index.html
snowdenwhittakerwatertech.com               /hundredweights/index.html
treewhittakerwatertech.com               /plover/index.html
snowdenwhittakerwatertech.com               /snorts/index.html
enderwww.arrow2000.ca                /gradient/index.html
enderwww.arrow2000.ca                /homemaker/index.html
enderwww.arrow2000.ca                /mulling/index.html
enderwww.arrow2000.ca                /nettie/index.html
enderwww.arrow2000.ca                /offed/index.html
obamawww.bernderl.de          /paradigmatic/index.html
snowdenwww.bernderl.de/coward/index.html
snowdenwww.bernderl.de/munoz/index.html
treewww.bernderl.de/oleaginous/index.html
snowdenwww.bernderl.de/polygon/index.html
snowdenwww.bernderl.de/selvedge/index.html
treewww.bernderl.de/undue/index.html
enderwww.bst-kanzlei.de              /attenuation/index.html
enderwww.bst-kanzlei.de              /cutback/index.html
enderwww.bst-kanzlei.de              /divorce/index.html
treewww.compare-treadmills.co.uk         /bassinet/index.html
snowdenwww.compare-treadmills.co.uk         /deciding/index.html
treewww.compare-treadmills.co.uk         /faster/index.html
snowdenwww.compare-treadmills.co.uk         /implosion/index.html
treewww.compare-treadmills.co.uk         /implosion/index.html
snowdenwww.compare-treadmills.co.uk         /leon/index.html
snowdenwww.compare-treadmills.co.uk         /leonor/index.html
treewww.compare-treadmills.co.uk         /march/index.html
treewww.compare-treadmills.co.uk         /tamarinds/index.html
enderwww.ishootyou.gr                /auguring/index.html
enderwww.ishootyou.gr                /insinuating/index.html
enderwww.ishootyou.gr                /sultanates/index.html
enderwww.ishootyou.gr                /towelling/index.html
obamawww.kauai2u.com          /connect/index.html
treewww.kauai2u.com/connect/index.html
snowdenwww.kauai2u.com/cynically/index.html
treewww.kauai2u.com/department/index.html
snowdenwww.kauai2u.com/descent/index.html
snowdenwww.kauai2u.com/finked/index.html
snowdenwww.kauai2u.com/strapping/index.html
treewww.kauai2u.com/strapping/index.html
treewww.masago-bkt.co.jp                 /axes/index.html
snowdenwww.masago-bkt.co.jp                 /beirut/index.html
obamawww.Miami-Beach-Reisen.de/eminently/index.html
obamawww.Miami-Beach-Reisen.de/tangoing/index.html
snowdenwww.Miami-Beach-Reisen.de            /eduardo/index.html
treewww.Miami-Beach-Reisen.de            /exceeding/index.html
snowdenwww.Miami-Beach-Reisen.de            /frail/index.html
snowdenwww.Miami-Beach-Reisen.de            /incrusts/index.html
treewww.Miami-Beach-Reisen.de            /invalided/index.html
treewww.Miami-Beach-Reisen.de            /requirements/index.html
snowdenwww.Miami-Beach-Reisen.de            /tangoing/index.html
obamawww.readingfluency.net   /juvenile/index.html
snowdenwww.readingfluency.net               /imperishables/index.html
treewww.readingfluency.net               /imperishables/index.html
snowdenwww.readingfluency.net               /poachers/index.html
snowdenwww.readingfluency.net               /tarantula/index.html
treewww.saito-office.biz                 /hooker/index.html
snowdenwww.saito-office.biz                 /rechargeable/index.html
snowdenwww.saito-office.biz                 /suggestively/index.html
treewww.saito-office.biz                 /suggestively/index.html
snowdenwww.saito-office.biz                 /vandyke/index.html
snowdenwww.schmaeing-reken.de               /banjos/index.html
treewww.schmaeing-reken.de               /baxter/index.html
snowdenwww.schmaeing-reken.de               /blocking/index.html
treewww.schmaeing-reken.de               /blocking/index.html
treewww.schmaeing-reken.de               /droller/index.html
treewww.schmaeing-reken.de               /iambs/index.html
treewww.schmaeing-reken.de               /metamorphosing/index.html
snowdenwww.schmaeing-reken.de               /mucks/index.html
treewww.schmaeing-reken.de               /regurgitating/index.html
obamawww.socivi.com           /estonians/index.html
treewww.socivi.com /flippancy/index.html
snowdenwww.socivi.com /incapable/index.html
snowdenwww.socivi.com /infuses/index.html
treewww.socivi.com /lepke/index.html
snowdenwww.socivi.com /moonlights/index.html
treewww.socivi.com /tugs/index.html
treewww.spurtwinslotshelvingsystems.co.uk/chirruping/index.html
treewww.spurtwinslotshelvingsystems.co.uk/dumped/index.html
snowdenwww.spurtwinslotshelvingsystems.co.uk/helot/index.html
treewww.spurtwinslotshelvingsystems.co.uk/reprinted/index.html
snowdenwww.spurtwinslotshelvingsystems.co.uk/terminological/index.html
treewww.spurtwinslotshelvingsystems.co.uk/terminological/index.html
treewww.spurtwinslotshelvingsystems.co.uk/tushes/index.html
treewww.tennisclub-iburg.de              /barking/index.html
snowdenwww.tennisclub-iburg.de              /bruckner/index.html
snowdenwww.tennisclub-iburg.de              /distemper/index.html
treewww.tennisclub-iburg.de              /excreta/index.html
snowdenwww.tennisclub-iburg.de              /geneses/index.html
snowdenwww.tennisclub-iburg.de              /hepper/index.html
treewww.tennisclub-iburg.de              /retributions/index.html
obamawww.wurster.ws           /dope/index.html
treewww.wurster.ws /cheaply/index.html
snowdenwww.wurster.ws /dearness/index.html
snowdenwww.wurster.ws /fixity/index.html
treewww.wurster.ws /loathing/index.html
treewww.wurster.ws /rump/index.html

Wednesday, June 05, 2013

Vietnamese Carders arrested in MattFeuter.ru case

Eleven Cyber criminals Arrested

I'm always pleased to see international cooperation in cybercrime investigations! This afternoon we received the news from the UK's SOCA, (the Serious Organised Crime Agency) that there were eleven arrests globally in a case involving cooperation from the Vietnamese High-Tech Crime Unit (HTCU), the Criminal Investigative Division of the the Ministry of Public Security of Vietnam (MPSVN CID), SOCA, the Metropolitan Police Central e-Crime Unit (PCeU), and the FBI. Eight criminals were arrested in Vietnam and three additional arrests were made in the UK.

All of these criminals were associated with the "mattfeuter" family of websites (mattfeuter.ru, mattfeuter.cc, mattfeuter.su, mattfeuter.com, etc.) where approximately 16,000 members bought and sold stolen credit card data in bulk. It is believed that purchases from the website had facilitated more than $200M worth of credit card fraud worldwide through the sale of more than 1.1 million credit cards.

SOCA and the PCeU are joining forces to create the new National Crime Agency later this year, but are already performing joint operations such as this investigation in anticipation of the UK's new National Cyber Crime Unit. Andy Archibald, who is the interim Deputy Director of the National Cyber Crime Unit, where the "Dedicated Cheque and Plastic Crime Unit" is housed, had this to say:

“One of the world’s major facilitation networks for online card fraud has been dismantled by this operation, and those engaged in this type of crime should know that that they are neither anonymous, nor beyond the reach of law enforcement agencies. We and our partners, in the UK and abroad, continue to protect the public and legitimate businesses by targeting websites trading in stolen card data, and relentlessly pursuing those who operate and frequent them."

Operations of this nature would not be possible without the support of private sector partners, in this case primarily Visa and MasterCard.

In keeping with UK law, the names of the three arrested there are not given, only their names and locations:

  • 37 year old man from West Ham
  • 34 year old man from Thornton Heath
  • 44 year old man from Manor Park
In the US, the New Jersey US Attorney's office has filed charges on 23 year old Duy Hai Truong, of Ho Chi Minh City, in Vietnam.

Vietnamese media has identified those arrested in Vietnam, and have named as their ringleader Van Tien Tu. The full list of those arrested include:

  • Ngo Thi Quynh Anh
  • Tran Thi Dieu Hien
  • Van Tien Tu
  • Truong Hai Duy
  • Le Van Kieu, those five all from Ho Chi Min City
  • Trinh Khac Duong
  • Dao Ba Bang
  • Doan Van Chuc, those three from Hanoi
The HCM City five are charged with illegally posting and using information from the Internet.

The Hanoi three are charged with using the credit card data for online gambling.

The ringleader, Van Tien Tu, is charged with having created the Mattfeuter websites, where credit cards are sold for between $2 and $20 per card. As the operator of the site, Van Tien Tu and his group earned approximately $1.5 million in commissions on their sales.

Although we haven't yet heard of many cases with Vietnamese cyber crime yet, the improvements in Vietnamese law passed in 2009 made it a criminal offense to fraudulently obtain card dat from overseas targets, as well as from victims in Vietnam.

The New Jersey case focuses on Duy Hai Truong, pictured below:

In a statement from the New Jersey US Attorney's Office, Paul Fishman announced that Truong was charged with "conspiracy to commit bank fraud. From 2007 until his recent arrest, Truong allegedly defrauded financial institutions as part of the massive scheme, in which personal identifying information relating to more than 1.1 million credit cards was stolen and resold to criminal customers worldwide." The New Jersey statement alludes to "arrests made over the past week in the United Kingdom, Vietnam, Italy, Germany, and elsewhere" so I am sure there will be additional news in the near future as the details of the case unfold.

The Official Complaint against Duy Hai Truong reveals that fees on the mattfeuter.biz and mattfeuter.com websites varied from $1 to $300 per "dump" (a dump referring to a magnetic card stripe read from a Credit or Debit Card), and that the fees were usually paid through Western Union or Liberty Reserve.

Truong is being held in Vietnam pending the settlement of charges in the UK, but if convicted in the US, Truong could face up to 30 years in prison and a fine of either $1 million or twice the gain from the offense, or twice the losses caused by the offense, whichever is greater.

New Jersey has also released the Sworn Complaint by FBI Special Agent Russell Ficara, who testifies that he reviewed over 1100 bank accounts and many searches of email accounts, residences, offices, and drop addresses related to this case. His testimony includes many of the email accounts used, including mattfeuter123@gmail.com, augustino267@gmail.com, ho.robbie@gmail.com, and included more than 150,000 email messages with more than 1.1 million credit card numbers being traded, including cards and personally identifiable information (PII) related to many victims residing in New Jersey.

As with so many criminals, Truong also had a Facebook account that referred to his real name, made references to the conspiracy, and contained photos of messages to and from Dump Purchasers and making reference to stolen credit cards!

A single Western Union location "in or around Ho Chi Minh City, Vietnam" was documented to have received more than $1.9 million in payments just related to MTCNs (Money Transfer Control Numbers) documented in the emails from the three referenced accounts, all controlled by Truong.

Monday, May 13, 2013

The Kelihos Botnet: Spam Data Mine + i2 Analyst Notebook

On April 17th & 18th, 2013, we blogged about spammers who were using the Boston Marathon Explosion and the Texas Fertilizer Plant Explosion to dramatically increase the size of their botnet. The botnet in question was the Kelihos botnet, and the primary purpose of the malware being delivered in that two day campaign was to cause newly infected computers to also join the botnet as additional spam-sending computers. Malcovery Security, where I serve as Chief Technologist, put out a free copy of their daily malware "Top Threats Today" report because the prevalence of that spam was nearly 80 times the level that we normally consider to be an "outbreak" of malicious activity.

So, what have the criminals behind Kelihos been doing with all of their new spam-sending power? Primarily they are sending Pump and Dump spam.

Pump & Dump

A Pump and Dump spam campaign is an email that claims a particular stock symbol is going to have a large increase in value in the near future and encourages investors to jump in while the price is still low. These are usually sub-penny stocks where the criminals have arranged to own millions of shares of an existent publicly traded "pink sheets" company. They then do false press releases about new business developments, accompanied with a spam campaign. We've seen stocks rise from 1/5th of a cent to 30 or 40 cents or on rare occasion $1 per share before the criminal dumps his millions of shares for a 10,000% profit. These attacks often coincide with brokerage phishing attacks where a stolen Fidelity account (or something like it) is used to buy the initial shares, or to buy many shares to give the appearance of high market activity in the junk stock to encourage wary investors.

Over the weekend, the Kelihos Pump & Dump target is "GT RL" which they claim is a small movie studio that is primed for an acquisition. In the spam emails they tell the story of an investor who owned 39% of Lions Gate and earned $1 Billion USD when the studio was acquired by a larger organization. GTRL is "Get Real USA, Inc." which claims last summer to have had "Academy Award Nominee Dean Wright" join their board of advisors, according to their website, which is denying any involvement in the current spam run.

On March 4, 2013, GTRL opened the market day trading at $0.0052. Friday it closed at $0.01 on a volume of 1.9 million shares traded. So someone is certainly buying shares!

Why do we care? Primarily because it has been one of the top spam-sending botnets ever since the Boston explosion spam. Yesterday, May 11, we saw a RIDICULOUS number of spam subject lines, all touting this penny stock.

Spam Data Mine

Long time readers will be familiar with the UAB Spam Data Mine. In December, we licensed the Spam Data Mine technology to Malcovery who use the Malcovery Spam Data Mine to identify Today's Top Threats for their customers, based on techniques and methodologies developed at UAB over the past six years. The Spam Data Mine receives in the neighborhood of a million messages per day, which we "parse" to extract key features which are stored in a PostgreSQL database. As we look at the top subjects recently, they have been dominated by Pump & Dump spam. For example, here are some of yesterday's Top Subject lines related to Stock:

  1267 | It is Our New Alert! This Low Float Monster is a Must See
  1203 | You won't beleive your eyes!
  1123 | This Stock is Starting to Heat Up
  1109 | Perfect Time To Add!
  1103 | Our Featured Gem
   804 | It`s official, this stock is a 100% perfect buy!
   621 | There should be outrage against bailouts!
   617 | Things to Know Before Your Next Trade
   574 | Closing out the week with Mega Gains!
   534 | This Stock is moving up as it should
   526 | Exciting Trade Idea Details Inside!
   503 | New Pick Coming Tomorrow, This is a Must Read!
   496 | This Stock is well positioned for another monster run!
   494 | Spectacular bouquets, only $19.99!
   478 | Stocks on watch for mega gains this week!
   460 | This Company IS RED HOT!!!
   458 | This Company is on Immediate Alert! This Bull is Positioning for a Major Run

If we just limit our search to spam that contained the word "Stock" or "Company" in the spam, we had more than 175,000 emails yesterday, using 1,976 subject lines! But how would we know the other subject lines in the campaign? "Perfect Time To Add!" doesn't have the word "Stock" or "Company" in the subject. There is also no guarantee that all of the messages containing these words are part of this spam campaign.

To get a better handle on this, we are going to do a series of queries to build a candidate pool, and then use IBM's i2 Analyst's Notebook to perform what we call "Visual Pre-Clustering" to help us determine some ground truth and to help us screen out some possible outliers. If there are several unrelated botnets all sending Pump and Dump spam, the clusters should be easily identifiable using this technique, while if there are other spam messages unrelated to Pump and Dump being sent by Kelihos, those should also be easily identifiable.

First, let's pile up our data:

Spam Queries to Build a Candidate Data Set

To begin, I'm going to collect a list of IP addresses of computers that sent me spam on May 11, 2013 that used the word "stock" or "company" in their spam message. This query creates a temp table called "may11stockip" that contains the list of IP addresses that sent me those messages and a count of how many times each was used.

spam=> select count(*), sender_ip into may11stockip from spam where (subject ilike '%stock%' or subject ilike '%company%') and receiving_date = '2013-05-11' group by sender_ip order by count desc;
This gave me 27,425 unique addresses. Our next step is to ask the Spam Data Mine for other subjects that were sent by that group of IP addresses. While it is true that I could build one massive query to do all of this work, we've found over time that the temporary tables can be useful to have preserved, and using the temporary tables actual speeds up the final result.

spam=> select count(*), subject into may11stocksub from spam a, may11stockip b where a.sender_ip = b.sender_ip and receiving_date = '2013-05-11' group by subject order by count desc;

This generated 6,420 spam subject lines! Far more than the 1976 that contained the words "stock" or "company"! In fact, given the size of the botnet, it is actually likely that I may have received some spam from computers that DID NOT use the word "stock" or "company", so we'll run one more iteration. Dropping the "may11stockip" table, we rebuild it from any computer that sent a subject found in the new temptable, may11stocksub.

spam=> select count(*), sender_ip into may11stockip from spam a, may11stocksub b where a.subject = b.subject and receiving_date = '2013-05-11' group by sender_ip;

Now we have 93,538 candidate IP addresses to consider as possible Kelihos nodes!

Our last iteration in building our "Pile of Data" to hand to i2 is to create relationships between those 93,538 candidate IP addresses and all of the subjects they used. Our goal is to have a nice table that can be imported into i2 Analyst's Notebook.

spam=> select count(*), a.sender_ip, subject into may11stockpairs from spam a, may11stock b where receiving_date = '2013-05-11' and a.sender_ip = b.sender_ip group by a.sender_ip, subject order by count desc;
This generates 282,763 pairs of "sender_ip x subject".

Visual Pre-Clustering with i2 Analyst's Notebook

From these 282,763 pairs, we're going to let i2 do all the hard work. Here's the basic idea. Let's say we have 4 computers, A, B, C, and D and each of these computers sent an email from the set M1, M2, M3, M4, M5, M6, M7. For the sake of argument, we are going to say that because there is NO CHANCE that the computers would have sent the same email, unless they were CONTROLLED by the same criminal spammer. If we can demonstrate which computers sent the same messages, we could then determine which computers were controlled by the same criminal.

A - M1
A - M2
A - M3
B - M4
B - M5
C - M1
C - M6
C - M7
D - M1
D - M6 
D - M7
If we were to draw a picture of that, just as you see it on the list, it might look like this:

But if we allow i2 to give a more intuitive layout, it would look like this, which makes it very plain that Computers A, C, and D are sending "the same" emails, while Computer B is sending "different" emails.

One Day of Kelihos in i2 Analyst's Notebook

You might say to yourself, "That didn't seem to add much value?" But now imagine that there are 282,763 rows on your list instead of eleven, and that instead of having four computers you have 93,538 and instead of having seven email subjects you have 7,226.

Here's the chart you get when you do that!

or with some labels on it:

Cluster A
The cluster labeled as "A" is our main "Stock Pump & Dump" cluster. All of our "main" Stock and Company subjects are in the heart of that cluster, with many related computers coming from them.

Cluster B
This cluster is primarily formed of spam for "Work at Home" scams. Some sample subjects from this group include:

Ready to be your own boss?
Business Startup
Your second chance in life just arrived
Sick of paying bills?
Wanna pay off your debts?
Stop just barely making ends meet every month
Make Money Online
Wanna Learn how to make money online?
Success Kit
Ill show you the road to early retirement
Successful Business
New Income
Wanna make up to $6500/month?
Job openings in your area!
At Home Income
A living online is easier than you think
Work From Home Jobs Available!

One slight "False join" is linking "A" and "B" and has to be manually eliminated. "Empty Subject" is the only subject in Cluster H hidden in the midst of the Corpus Callosum that joins A and B. After discovering this, we manually deleted that subject from the chart, and re-ordered the chart, after also first removing "disjointed" clusters that had not tie to the core, such as Cluster F and the others at the top, and many of the "Fan-subclusters" such as Cluster I that surrounded Cluster A.

The "Cleaned Up" version of the chart still makes it abundantly clear that THOUSANDS of IP addresses that are part of the "Stock Pump and Dump" cluster on the left are ALSO part of the "Work at Home" (B) and "Pharmacy Express" (C,D,E) clusters on the right. The Cleaned Up chart, shown below, still has 91,833 IP Addresses and 6,242 Email Subjects, with 277,747 unique "pairs" between them.

IP addresses closer to the right have primarily "Work at Home" spam subjects, such as 95.57.242.156:

 count |                 subject                  
-------+------------------------------------------
     2 | TODAY`S TRADING IDEA IS `Advanced`
     1 | Work for Moms
     1 | It moves up nicely on heavy accumulation
     1 | Job Hiring is at an all time low...
     1 | Sick of paying bills?
     1 | Business Startup
(6 rows)

or 31.7.57.214:

 count |               subject               
-------+-------------------------------------
    13 | Successful Business
     1 | Sick of not making ends meet?
     1 | Wanna make up to $6500/month?
     1 | Job Hiring is at an all time low...
     1 | What kind of investor are you?
(5 rows)

IP addresses closer to the left have primarily "Stock Pump and Dump" spam subjects, such as 178.90.148.44:

 count |                                subject                                 
-------+------------------------------------------------------------------------
     5 | This Company is Ready to Run
     5 | It is one to watch this week!
     4 | Analysts gives this stock a "STRONG SPECULATIVE BUY" rating
     4 | New Play Coming
     3 | This Company has a history of Huge Rallies, on verge of another Rally?
     3 | New Wild Breakout Pick Coming TONIGHT!
     3 | The NEW TRADE ALERT
     3 | A Potential Mover from Penny Stock
     3 | It Is Wasting Little Time Making Waves
     2 | This Company Ends Last Week Strong
     2 | Get Ready For The Hottest Gold Pick On The Planet!
     2 | Our New Blazin Sub-Penny Alert!
     1 | Be Ready
     1 | Success Kit
     1 | This Company exploded in volume today
     1 | Second chance for traders who have `calmed down`...
     1 | Sick of a dead end job?
     1 | We`ve Got A Bouncer On Our Hands!
     1 | This Stock Signs Agreement With Reputable PR Agency
     1 | Back to work week will get this play really going!
(20 rows)

The "Bumps" that circle cluster B are groups of IP addresses that share "some but not all" of the subjects found in Cluster B. There are many IP addresses that we saw only once or twice -- because of their low volume, they do not appear as "fully meshed" as the IP addresses in the "core" of Cluster B. A couple examples will demonstrate this.

In the core of Cluster B we see thousands of IP addresses that were used for at least 2 or 3 Work at Home messages:

'59.94.88.82/32'           
-------+-------------------------------
     2 | Successful Business
     1 | Wanna make up to $6500/month?
     1 | Income At Home
'120.60.69.113/32'
 -------+-----------------------------------------------
     1 | Success Kit
     1 | Stop just barely making ends meet every month
'212.62.37.89/32'
-------+-------------------------------
     2 | Success Kit
     1 | Wanna make up to $6500/month?
     1 | Income At Home
'87.241.142.252/32'
-------+------------------------------
     2 | Work for Moms
     1 | Replace your nine to five...
'37.99.26.121/32'
 -------+------------------
     1 | Business Startup
     1 | Success Kit
'2.146.92.235/32'
-------+-----------------------------------------
     1 | Make Money Online
     1 | Your second chance in life just arrived
Small "micro clusters" of IP addresses used for both the "C" or "D" Pharma spam and one or more of the Work at Home subjects fill the ridge between Clusters "B" and "C, D, E":

'176.33.176.120/32'
-------+-----------------------------------------
     1 | ð°ð°ð°Cialis (30 pills 20mg) USD 91.50 & Viagra (30 pills 100mg)  USD 81.90ð°ð°ð°
     1 | ð°ð°ð°Viagra (30 pills 100mg)  USD 81.90 & Cialis (30 pills 20mg) USD 91.50 ð°ð°ð°
     1 | Your second chance in life just arrived
'113.22.157.247/32'
-------+------------------------------
     1 | ð°ð°ð°Cialis (30 pills 20mg) USD 91.50 & Viagra (30 pills 100mg)  USD 81.90ð°ð°ð°
     1 | Replace your nine to five...
     1 | ð°ð°ð°Viagra (30 pills 100mg)  USD 81.90 & Cialis (30 pills 20mg) USD 91.50 ð°ð°ð°

Here are two example IP addresses from a single "Bump" on the left edge of Cluster B.

'190.236.188.41/32'
-------+-----------------------------------------------
     1 | Stop just barely making ends meet every month
'118.68.119.212/32'
-------+-----------------------------------------------
     1 | Stop just barely making ends meet every month

Cluster C, D, and E
These are Viagra Spam clusters. C & D are two very popular subjects, both resolving to "Pharmacy Express" websites. The small cluster "E" is formed of IP addresses that sent spam for both Cluster C and Cluster D.

Cluster F & Friends
Cluster F and the neighboring small clusters at the top of the chart have been included primarily through a coincidental usage of the word "Company" in their subject lines. F, for example, is a well-known spammer of the type the industry calls a "Snowshoe spammer." They rotate through hosted data centers, paying their bills for nice hardware to be used for spamming with stolen credit cards. When they get thrown out of one data center for spamming, they move to the next.

Cluster G & J
These clusters are also primarily joined through the coincidental use of the word "Company" in the subcluster subjects.

Cluster I
There are many "Fan-shapes" around the edges of Cluster A. Looking at Cluster I as an example, there are 36 subjects in that "fan cluster" all related to "Replica goods":

A Rolex replica watch
ALL MAJOR DESIGNER REPLICA WATCHES
Bags
Beautiful quartz, water-resistant Replica watches
Box Sets
Bracelets
Cufflinks
Gold Watches
Gucci Bags
...

Only a single (subject x sender_ip) pair links this fan-cluster to the main Cluster A. The subject "replica watches! rolex, patek philippe, vacheron constantin and others!" which was attached to dozens of IP addresses in the fan-cluster, is also attached to the IP address "201.9.120.242" That IP address also sent us two messages with the email subjects "This Stock Move Starting!".

154 IP addresses in Cluster A also used the subject "This Stock Move Starting!"

To focus on the core activity, disconnected subclusters, such as F, and "fan-clusters" such as I are removed from the chart, and the layout is performed again.