Tuesday, January 28, 2020

How does a government censor the Internet? A rare peek from Jammu and Kashmir

From time to time we hear that a totalitarian government has locked down Internet access for a part or all of their country.  Normally, that is about all we hear about the situation.  In the case of India, not normally thought of as a Totalitarian government, we have a unique opportunity to look at what they are censoring as they began to relax the total lockout of Internet services that was put into place in Jammu and Kashmir.

The "lift" of total censorship began on January 14th, when Internet Service Providers were ordered to install firewalls that would only allow access to 153 government-approved websites.  As was pointed out by "The Wire", "No Mainstream News in List of 153 Whitelisted Websites Under Kashmir's First Govt Firewall."  TheWire.in noted that "Conspicuously absent from the list that includes Gmail, Netflix, Zomato, Oyo Rooms and Paytm are news and social media websites."

The order from the "Principal Secretary to the Government, Home Department" to the ISPs stated that the Internet shutdown was because "there have been number of reports of the use of internet in cross border terrorism/terror activities, incitement, rumour-mongering, etc. as also misuse of pre-paid mobile connections by anti-national elements."

Internet Order

The total ban of Internet services remained in effect for "the districts of Srinagar, Budgam, Ganderbal, Baramulla, Anantnag, Kulgan, Shopian, and Pulwama.  But for "all the 10 districts of Jammu division and to begin with the revenue districts of Kupwara & Bandipora of the Kashmir Valley" were allowed to have access to the list of 158 websites beginning on January 18th, 2020.  (That list is available via Scribd here:  "Temporary Suspension of Telecom Services"

A week later, the list was amended to include not only many News sites, as TheWire had pointed out, but also a large list of "Utilities" which included movie theaters, car dealerships, shoe sales websites, and pizza delivery services.

The new expanded list is provided below in a searchable form (the original is an image-based scan.)

I would invite others to make relevant observations in the comments sections, or in your own publications linking back to this page.  The list is intended to be a faithful representation of the new order, which can be found on the JK Home Office website as Home-05(TSTS) of 2020.

While the order has been commonly described as containing "300 URLs", there are a handful of duplicates, where a URL was included both with a trailing slash and without the slash.  It should also be noted that there are a very large number of websites included by Top Level Domain, due to the inclusion of the TLDs:  Ac.in (most academic institutions in India will be included here), Gov.in (most government offices and services in India will be included here), and Nic.in (most network infrastructure services from the Ministry of Electronics and Information Technology is included here.)

It is curious how it was decided which websites to include and not to include.  For example, why include Adidas and Reebok, but not Nike?  I'm sure the programmers are thrilled to see that Github and StackOverflow are included!  What other observations strike you as interesting?  Please comment or Tweet about them!


Site NumberWebsite URL Category
1www.google.comSearch Engines
2www.apple.comSearch Engines
3www.office.comSearch Engines
4www.google.com > chromeSearch Engines
5www.google.caSearch Engines
6ca.search.yahoo.comSearch Engines
7search.yahoo.comSearch Engines
8www.live.comSearch Engines
9www.ask.comSearch Engines
10search.msn.comSearch Engines
11www.google.co.ukSearch Engines
12qc.search.yahoo.comSearch Engines
13www.hyundai.comAutomobiles
14www.suzukimotorcycle.co.inAutomobiles
15www.tata.comAutomobiles
16www.marutisuzuki.com/MarutiSuzuki/CarAutomobiles
17www.axisbank.comBanking
18www.hdfc.comBanking
19www.hdfcsec.comBanking
20www.icicibank.comBanking
21www.icicidirect.comBanking
22www.jkbankonline.comBanking
23www.onlinesbi.comBanking
24www.pnbindia.inBanking
25www.bankbazaar.comBanking
26www.moneycontrol.comBanking
27www.paisabazaar.comBanking
28www.paypal.comBanking
29www.policybazaar.comBanking
30www.rbi.org.inBanking
31www.westernunion.comBanking
32jammuuniversity.inEducation
33jkpsc.nic.inEducation
34jkssb.nic.inEducation
35kashmiruniversity.netEducation
36skuastkashmir.ac.inEducation
37www.cukashmir.ac.inEducation
38www.freejobalert.comEducation
39mahendras.orgEducation
40mrunal.orgEducation
41www.bankersadda.comEducation
42www.indianetzone.comEducation
43www.insightsonindia.comEducation
44www.iustlive.comEducation
45www.tcyonline.comEducation
46www.vedantu.comEducation
47www.aakash.ac.inEducation
48www.britannica.comEducation
49www.burnhallschool.ac.inEducation
50www.byjus.comEducation
51www.damsdelhi.comEducation
52www.dpssrinagar.comEducation
53www.elsevier.comEducation
54www.foundationworldschool.comEducation
55www.gdgoenkasrinagar.comEducation
56www.github.comEducation
57www.gktoday.inEducation
58www.ignou.ac.inEducation
59www.indiankanoon.orgEducation
60www.indiaresults.comEducation
61www.islamicuniversity.edu.inEducation
62www.lpu.inEducation
63www.madeeasy.inEducation
64www.mciindia.orgEducation
65www.nature.comEducation
66www.nitsri.ac.inEducation
67www.pathfinderacademy.inEducation
68www.pchssrinagar.comEducation
69www.resonance.ac.inEducation
70www.sciencedirect.comEducation
71www.siu.edu.inEducation
72www.springer.comEducation
73www.ssmengg.edu.inEducation
74www.stackoverflow.comEducation
75www.udemy.comEducation
76www.unacademy.comEducation
77www.wikipedia.orgEducation
78www.naukri.comEmployment
79www.jagranjosh.comEmployment
80www.sail.co.inEmployment
81Airtel TVEntertainment
82Amazon PrimeEntertainment
83HotstarEntertainment
84gaana.comEntertainment
85tatasky.comEntertainment
86tvfplay.comEntertainment
87www.altbalaji.comEntertainment
88www.dishtv.inEntertainment
89www.imdb.comEntertainment
90www.jiosaavn.comEntertainment
91www.spotify.comEntertainment
92wynk.inEntertainment
93NetflixEntertainment
94Sony LivEntertainment
95VootEntertainment
96www.crickbuzz.comEntertainment
97www.espn.inEntertainment
98Zee5Entertainment
99www.google.com > gmailMail
100in.mail.yahoo.comMail
101mail.rediff.comMail
102outlook.live.comMail
103news.statetimes.inMail
104prsindia.orgMail
105www.earlytimes.inEntertainment
106www.kashmirtimes.comNews
107www.kashmiruzma.netNews
108www.risingkashmir.comNews
109www.thenorthlines.comNews
110aajtak.intoday.inNews
111economictimes.indiatimes.comNews
112edition.cnn.comNews
113kashmirage.netNews
114kashmirobserver.netNews
115news.google.comNews
116scroll.inNews
117thekashmirimages.comNews
118theprint.inNews
119theprint.inNewsDUPLICATE
120thewire.inNews
121timesofindia.indiatimes.comNews
122www.aljazeera.comNews
123www.amarujala.comNews
124www.bbc.comNews
125www.business-standard.comNews
126www.channelnewsasia.comNews
127www.dailyexcelsior.comNews
128www.dailypioneer.comNews
129www.deccanchronicle.comNews
130www.epw.inNews
131www.financialexpress.comNews
132www.financialexpress.com NewsDUPLICATE
133www.forbes.comNews
134www.greaterkashmir.comNews
135www.hindustantimes.comNews
136www.jagran.comNews
137www.livemint.comNews
138www.mid-day.comNews
139www.moneycontrol.comNews
140www.moneycontrol.comNewsDUPLICATE
141www.ndtv.comNews
142www.newindianexpress.comNews
143www.news18.comNews
144www.nytimes.comNews
145www.outlookindia.comNews
146www.outlookindia.comNewsDUPLICATE
147www.presstv.comNews
148www.presstv.comNewsDUPLICATE
149www.republicworld.comNews
150www.scoopwhoop.comNews
151www.telegraphindia.comNews
152www.theguardian.comNews
153www.thehindu.comNews
154www.thehindubusinessline.comNews
155www.thekashmirmonitor.netNews
156www.thelallantop.comNews
157www.thequint.comNews
158www.timesnownews.comNews
159www.tribuneindia.comNews
160www.washingtonpost.comNews
161www.wionews.comNews
162www.wsj.comNews
163www.amnesty.orgNGOs
164www.fordfoundation.orgNGOs
165www.helpageindia.orgNGOs
166www.savethechildren.inNGOs
167www.smilefoundationindia.orgNGOs
168Ac.inServices
169Gov.inServices
170www.incometaxindiaefiling.gov.inServices
171www.jkpolice.gov.inServices
172www.passportindia.gov.inServices
173www.services.gst.gov.inServices
174enps.nsdl.comServices
175uidai.gov.inServices
176nic.inServices
177www.gmcs.edu.inServices
178www.lalpathlabs.comServices
179www.shifamedcenter.comServices
180www.skims.ac.inServices
181geekyranjit.comTechnology Updates
182overdrive.inTechnology Updates
183beebom.comTechnology Updates
184www.androidauthority.comTechnology Updates
185www.autocarindia.comTechnology Updates
186www.carwale.comTechnology Updates
187www.cnet.comTechnology Updates
188www.digit.inTechnology Updates
189www.engadget.comTechnology Updates
190www.gsmarena.comTechnology Updates
191www.pcmag.comTechnology Updates
192www.techradar.comTechnology Updates
193www.theverge.comTechnology Updates
194www.zigwheels.comTechnology Updates
195www.cleartrip.comTravel
196www.goibibo.comTravel
197www.irctc.co.inTravel
198www.makemytrip.comTravel
199www.yatra.comTravel
200www.airindia.comTravel
201www.cleartrip.comTravel
202www.easemytrip.comTravel
203www.flightstats.comTravel
204www.hajcommitee.gov.inTravelTYPO
205www.iismgulmarg.inTravel
206www.incredibleindia.orgTravel
207www.ixigo.comTravel
208www.jktourism.orgTravel
209www.oyorooms.comTravel
210www.pawanhans.co.inTravel
211www.redbus.inTravel
212www.shriamarnathjishrine.comTravel
213www.trivago.comTravel
214www.trivago.in Travel
215jakemp.nic.inUtilities
216www.jabong.comUtilities
217billsahuliyat.jkpdd.netUtilities
218earth.google.comUtilities
219www.airtel.inUtilities
220www.amazon.inUtilities
221www.bhimupi.org.inUtilities
222www.flipkart.comUtilities
223www.healthkart.comUtilities
224www.myntra.comUtilities
225www.netmeds.comUtilities
226www.paytmbank.comUtilities
227JIO chatUtilities
228www.99acres.comUtilities
229www.airtel.inUtilitiesDUPLICATE
230www.bharatpetroleum.comUtilities
231www.bluedart.comUtilities
232www.bsnl.co.inUtilities
233www.cardekho.comUtilities
234www.dtdc.inUtilities
235www.ebharatgas.comUtilities
236www.fedex.comUtilities
237www.firstflight.netUtilities
238www.freecharge.inUtilities
239www.gaadiwaadi.comUtilities
240www.gati.comUtilities
241www.indane.co.inUtilities
242www.indiamart.comUtilities
243www.jio.com Utilities
244www.jkhandicrafts.comUtilities
245www.jkpdd.gov.inUtilities
246www.jkpwdrb.nic.inUtilities
247www.justdial.comUtilities
248www.magicbricks.comUtilities
249www.myhpgas.inUtilities
250www.olx.inUtilities
251www.pharmeasy.inUtilities
252www.quikr.comUtilities
253www.sulekha.comUtilities
254www.tbmes.orgUtilities
255www.vodafone.inUtilities
256www.zomato.comUtilities
257cleartax.inUtilities
258in.bookmyshow.comUtilities
259keep.google.comUtilities
260lens.google.comUtilities
261oppo-inUtilities
262support.google.comUtilities
263support.microsoft.comUtilities
264translate.google.co.inUtilities
265vimeo.comUtilities
266wikimapia.orgUtilities
267www.adidas.co.inUtilities
268www.ajio.comUtilities
269www.aliexpress.comUtilities
270www.bajaauto.comUtilities
271www.bing.comUtilities
272www.decathlon.inUtilities
273www.dell.comUtilities
274www.dominos.co.inUtilities
275www.fabindia.comUtilities
276www.gingerlabs.comUtilities
277www.heromotocorpo.com/en-in/Utilities
278www.houzz.inUtilities
279www.indeed.co.inUtilities
280www.india.ford.comUtilities
281www.indiamart.comUtilities
282www.jeep-india.comUtilities
283www.kia.comUtilities
284www.kinemaster.comUtilities
285www.lenovo.comUtilities
286www.lenskart.comUtilities
287www.office.comUtilitiesDUPLICATE
288www.pizzahut.co.inUtilities
289www.pvrcinemas.comUtilities
290www.quora.comUtilities
291www.reebok.comUtilities
292www.shopclues.comUtilities
293www.swiggy.comUtilities
294www.tatamotors.comUtilities
295www.toyotabharat.comUtilities
296www.upwork.comUtilities
297www.wavecinemas.comUtilities
298www.upwork.comUtilitiesDUPLICATE
299www.zomato.comUtilities
300www8.hp.comUtilities
301www.accuweather.comUtilities

Thursday, January 09, 2020

Iranian APT Group Overview

Today the Birmingham InfraGard Chapter and the Alabama ISSA held a joint meeting featuring a presentation from the Cybersecurity & Infrastructure Security Agency, part of DHS that was formerly known as the NPPD.  I learned of a ton of offerings from CISA.gov at the meeting, so I want to start by sharing a link to their CISA Insights Page, where they released earlier this week some guidelines for updating your company's Risk Assessment regarding potential cyber or physical threats from Iranian actors in light of our current political situation, and the tendency of the Iranian regime to lash out with Cyber attacks when they can't accomplish what they want with the limited reach of their military.  That Insight was called Increased Geopolitical Tensions and Threats and features ten readiness steps for making sure your org is not a soft target for cyber attacks from Iran. Most of these are things you should be doing anyway, but hey, an Iran threat is possibly a good time to go check those out!  One way of thinking about covering your cyber bases that I really like is actually from the Australian Government, who recommends their "Essential 8" Strategies to Mitigate Cyber Security Incidents.  Start with making sure you have your Essentials covered, but then move on to "Very Good" and "Excellent" steps as your org matures your security practices.

However, we all know that Iran has many Advanced Persistent Threat (APT) Groups, and that there is much more to watching for such activity then patching your systems and telling your users to be aware.  A large org will want to know more about the behaviors of documented Iranian APT Groups. Often these insights include known malware families used by the actor, or what sectors or countries this threat group historically has attacked.

I've seen several documents that share a woefully incomplete list of APT groups from Iran, so I've tried to pull together some helpful links to the main groups below.  In each case, if their is a "MITRE Group #" after the main title, you will find a very robust list of TTPs (Tactics, Techniques, and Procedures) about the group and links to many more reports and resources about the group than I have provided below.  However, I DO like the reports I've listed and think you might want to read them as part of "basic understanding" before following a dozen reports about the same group.  One slight complaint about the MITRE data, and APT Group Naming in general, is there is a great deal of disagreement about which group names are aliases for the same groups, and which may be entirely different groups that just share some tools with one another.  Hey, I'm doing the best I can here, and so is MITRE.  It's tricky!  If you feel I've really got something screwed up, leave a comment!  Let's chat!

Most every vendor it seems likes to put their own personal spin on APT Groups.  I have to confess to being a sucker for the CrowdStrike naming conventions (Hi Adam! Hi Dmitri! Hi Shawn!).  They use a different Animal to label each APT Group based on the name of the country where the group is hosted.  Their name for Iran is "Kitten" (as in "Persian Kitten", get it?)

While there are several excellent APT Disambiguation efforts, my favorite for ease of use is the one run by Florian Roth (Twitter @Cyb3rops ) - APT Groups and Operations.  Go to the Iran tab. There are columns for malware sets and links related to each group as well.

If you prefer a much more detailed read of APT Groups, the ThaiCERT has an amazing Threat Actor Encyclopedia! A 275 page omnibus of APT!  However, it is really tricky to pull out, for example, JUST the Iran stuff from it.

For now, I'll organize this by the CrowdStrike Kitten Names. Their set includes at least:

but there are many other companies naming other Iranian APT Groups that may or may not link up with the Kittens.  FireEye is the main user of the numbered APT Groups.  Many of these now have a "Kitten" name as you see above ... APT33, 34, 35, and 39 are all Iranian.  There are several "less well labeled" actors who either don't really behave like traditional APT, or haven't been as widely linked as those above, but are still serious.  A few of those below:
  • Cyber Fighters of Izz Ad-Din Al Qassam - the bank DDOS guys.  
  • DarkHydrus (AKA Lazy Meerkat) - some say is actually also Slayer Kitten, others disagree
  • Gold Iowell (AKA Boss Spider) - these are the SamSam Ransomware guys 

If it would be helpful to just have the MITRE links all in one place, here you go!

Thursday, January 02, 2020

Backdoored Phishing Kits are still popular

What did you do for the holidays?  If you're a cybercrime geek you probably took advantage of some of the extra time on your hands to investigate some new phishing sites, right?



Jone Fredrick is the type of Facebook user who is quite open about his criminal activity.  He boasts about his phishing skills by having a Facebook profile picture of someone taking a selfie showing their government issued ID and their credit card!  He claims to live in Blida, Algeria, and probably does.  Over the holidays Jone update his YouTube channel, "mr azert" with a new Chase Bank phishing kit.  (Phishers don't call this phishing.  They call it "bank scams" or "scam pages."

In the past two weeks, Jone, who uses the alias "Mr Azert", has uploaded several videos about his new scam pages to his YouTube channel.  Chase, Spotify, Dropbox, Alibaba, and Paypal all have new scam pages courtesy of Mr Azert.  How generous that he just gives them away for free!


After listening to so much bad gangster/scammer rap music, it was nice to hear some Algerian rap while I did my investigation.  Mr Azert confirms this is him by replying to "Tutor Arena421" giving him his email address (foley.victoria998@gmail.com) and Facebook address ( jone.fredrick.79).


Of course, we report the offending content to YouTube.  If you ever encounter the same, please use the "Report" function.  The correct flow is to click the "Three Dots" ... then "Report".  Then choose  "Spam or misleading" and then the subcategory "Scams / fraud"



In this case, the reason Mr Azert is giving away these phishing kits is that he has backdoored all of the kits.  We'll look at the Chase one first.   There are five separate PHP files that send the various stolen information back to the person using the kit.  



When we look at the actual "Send" command, we notice that the email command says "for each $send" ... but the instructions for the kit have told the kit downloader that they should include their own email address in a certain place, which is "import"ed into this code.  What other address is being used here?


If we scroll up about we see that $send is receiving a variable called "token" from the form post that called this PHP code, and then converting it into ASCII with "hex2bin".


The calling code in this case is "myaccount.php" which seems to do some "input validation" but in reality, is also loading the "token" value:


That hex string at the bottom starting with "6665" is decoded in the "hex2bin" call into a pair of email addresses:  

  fenction@gmail.com  and fenction@yahoo.com

So, anyone who downloads Mr Azert's kit is going to either create or hack a website, upload and unpack the kit, spam out links to that URL, and then have all of their stolen data go back to Mr Azert in Algeria, who is likely to be better at cashing out the information than someone too lame to make their own phishing kit.

We're of course reporting all of this to YouTube, Gmail, Yahoo, and Facebook ... 

So how did you spend YOUR holiday?  

Happy New Year everyone!




Wednesday, December 04, 2019

Air Peace CEO charged with millions in money laundering re-buying planes he already owns

The Department of Justice announced last week that they were indicting the CEO of Air Peace for bank fraud and money laundering.



I had some difficulty finding the indictments for this case on PACER.  It turns out I couldn't find it in PACER because the court system decided that "Allen Ifechukwu Athan Onyema" should be listed in PACER with the last name "Athan Onyema", not "Onyema."

A friend shared a copy of the indictment from Guardian.ng, which has had some interesting articles, such as this one:

Why we ain’t castigating Allen Onyema, by militant group

which says in part "We expect Allen Onyema to put up a good defence for himself. So far, no American bank has accused him of defrauding or absconding with its money. He is innocent until proven guilty." ... which just shows that the Joint Revolutionary Council's spokesperson also didn't read the court documents, because that is EXACTLY what he is accused of!

Onyema is well-loved by many, earning wide admiration and praise for recently using his planes to repatriate many Nigerians who found themselves being shunned by xenophobia in South Africa, as was described in this BBC Pidgin article:
https://www.bbc.com/pidgin/tori-49692424
(from @flyairpeace's Instagram account)
Reading the indictment was VERY interesting.  I had previously suggested on Twitter that Onyema was buying imaginary airplanes, but that was NOT the case!  The airplanes are REAL and various plane spotter types have the planes with those Manufacturer numbers listed as now being property of Air Peace, which boasts a growing fleet of planes, which are listed here:

https://www.planespotters.net/airline/Air-Peace

The problem was that fake Lines of Credit, fake Appraisals, and fake Purchase documents all claimed Onyema was buying these planes from Springfield Aviation, when in fact, he had ALREADY BOUGHT THEM FROM OTHER OWNERS!  He basically bought all the planes TWICE and then bonused the money back to himself from Springfield.  He paid Springfield over $20M for the planes he already owned, and then over the course of many months, Springfield sent him back $15M of the same money.

It seems that Onyema lived for a while in Atlanta, Georgia.  In January 2016, he closed a Bank of America account and moved $4,000,396.43 via cashier's check to a pair of Wells Fargo accounts, opened in person in Atlanta, Georgia.

A LOT of money was then moved into that account, mostly from charities in Nigeria that Onyema controlled, including "All-Time Peace Media Communications" and "Foundation for Ethnic Harmony."

Onyema used the money to go shopping.  Prada, Neiman Marcus, Macy's, Louis Vuitton, the Apple store, a $180,000 Rolls Royce, a $88,500 Mercedes.  Over the course of eight years, $44.9 million was transferred from foreign accounts into Onyema's personal accounts at Bank of America, Wells fargo, and JP Morgan Chase.  Mostly from the "charities" that he was running back in Africa, including Foundation for Ethnic Harmony, International Center for Non-Violence and Peace Development, All-Time Peace Media Communications Limited, and Every Child Limited.

In July 2016, Onyema opened a Wells Fargo checking account in Atlanta (WF 8621) in the name Springfield Aviation Company, LLC.  He regularly spent money from that account for personal expenses, including grocery shopping at Publix, shopping at Macy's, DSW, staying at the Ritz Carlton, and eating at various restaurants.

In November 2017, Onyema opened new bank accounts in the name of "Springfield Aviation Company, LLC" but he was the sole authorized signatory.

The stories of his double-purchased planes are told in six "Letters of Credit" scenarios in the indictment.

Letter of Credit One: FB16TLL000 for Boeing MSN: 28721

On or about February 10, 2017, Wells Fargo transferred $1,982,228.46 into Springfield Aviation’s Wells Fargo account, WF 8621.  According to the court documents, however, the plane he was purchasing was already owned by Air Peace! Planespotters shows that it was registered to Air Peace  (new registration: 5N-BUJ ... and that the previous owner was Aurora, a Russian airline, who used the Registration number RA-73013, but notes they stored the plane at an airport in Tallin until 09JUN2016.)

https://www.planespotters.net/airframe/Boeing/737/5N-BUJ-Air-Peace/aDYGTYbg


The plane, as painted by the previous owner ... 
https://www.planespotters.net/photo/970748/ra-73013-sat-airlines-boeing-737-5l9

The plane, while being repainted as Air Peace (note the tail is not yet reattached) 
https://www.planespotters.net/photo/943421/5n-buj-air-peace-boeing-737-5l9

Both of those photos were taken in Tallin, Estonia, where the previous owner stored the plane before selling it to Air Peace.

Letter of Credit Two - LCITF-17-00414 for Boeing MSN: 27910

The court documents say the second plane was purchased by Air Peace from AerSale Inc on April 25, 2017 for $3,751,460 USD.  This is consistent with the history of that plane, which was previously sold by AerSale to Air Nigeria, and afterwards leased several times before being sold to Air Peace:

https://www.planespotters.net/airframe/Boeing/737/5N-BUQ-Air-Peace/WKYqcQ8Q

Wells Fargo received a credit request from Fidelity Bank of Nigeria saying that Air Peace was going to buy the plane for $4,750,000 from Springfield Aviation.  BUT SPRINGFIELD NEVER OWNED THE PLANE!  A company with no history of aviation, JMI LLC, provided a "full aircraft appraisal" saying the plane was worth $5,500,000 and Wells Fargo transferred $4,750,000 from Onyema's accounts into Springfield Aviation's Wells Fargo account, WF 8621, on April 25, 2017.

https://www.planespotters.net/photo/search?manufacturer=Boeing&type=737&cn=27910

Letter of Credit Three - ILCCOCBG1702932 - Boeing MSN: 28561 and Boeing MSN: 28562

These two planes were bought from Texas based Jetran, LLC on May 18, 2017.  $3,600,000 was the purchase price for the pair of planes. The wire transfer was sent from WF 8020 on May 15, 2017.

On October 2017, Wells received another letter of credit request, asking for $3,480,000 to be paid to Springfield Aviation's WF 8621 bank account.  JMI again provided an appraisal, claiming that just the 28561 plane was being sold and that it appraised by itself for $5,400,000.

On November 29, 2017, Well Fargo transferred $4,899,690 to Springfield Aviation's Wells Fargo account WF 8621 FOR A PLANE THAT HAD ALREADY BEEN PURCHASED FROM JETRAN nine months earlier!

https://www.planespotters.net/photo/search?manufacturer=Boeing&type=737&cn=28561

Letter of Credit Four - LCITF-17-00555 - Boeing MSN: 28660

In January 2017, Onyema bought another Boeing 737-300, MSN: 28660, from Oklahoma-based Aero Acquisition.  He paid $2,315,000 for the plane on January 9, 2017, wiring the money from his Wells 8020 account.

In April 2017, Wells received ANOTHER letter of credit request FOR THE SAME PLANE, but this time, claiming it would be purchased for $4,500,000 from Springfield Aviation.  On June 19, 2017, Wells Fargo transferred $4,499,900 to Springfield Aviation's Wells Fargo 8621 account, FOR A PLANE THAT SPRINGFIELD NEVER OWNED and that Onyema had already purchased from Aero Acquisition SIX MONTHS EARLIER!

None of the plane spotter photos of this plane are the Air Peace version...but its also a very real plane.

https://www.planespotters.net/photo/search?manufacturer=Boeing&type=737&cn=28660

Letter of Credit Five - FB17ILC00561C - Boeing MSN: 28562

This is the second plane previously mentioned having been purchased in May 2017 from Jetran, LLC.  Again, a new letter of credit arrives, this time to JPMorgan Chase Bank.

On Feb 20, 2018, JPMorgan Chase transferred $4,087,028 to Springfield Aviation's JPMC 5512 bank account, FOR A PLANE THAT Onyema had already bought 9 months earlier from Jetran!

https://www.airfleets.net/ficheapp/plane-b737-28562.htm

The plane was photographed with its Air Peace paint job and registration 5N-BUL in February 2018:

https://www.planespotters.net/photo/822183/5n-bul-air-peace-boeing-737-36nwl

Many previous photos as the Meridiana plane and as the Air Italy plane have been taken of the same airframe


https://www.planespotters.net/photo/search?manufacturer=Boeing&type=737&cn=28562



After being paid $20,218,846 for planes it never owned, what happened next?
Springfield began sending the money back to Onyema.  All of the transfers listed below were sent from the Springfield Aviation bank accounts back to Onyema's personal accounts.
  • 3/22/2017 - $1M
  • 3/23/2017 - $1M
  • 5/7/2017 - $500,000
  • 5/7/2017 - $500,000
  • 5/15/2017 - $500,000
  • 5/15/2017 - $500,000
  • 5/15/2017 - $500,000
  • 5/15/2017 - $500,000
  • 5/15/2017 - $100,000
  • 5/15/2017 - $500,000
  • 5/15/2017 - $150,000
  • 6/19/2017 - $500,000
  • 6/19/2017 - $500,000
  • 6/19/2017 - $500,000
  • 6/19/2017 - $500,000
  • 6/19/2017 - $500,000
  • 6/19/2017 - $500,000
  • 6/19/2017 - $500,000
  • 6/19/2017 - $500,000
  • 6/19/2017 - $500,000
  • 11/29/2017 - $1M
  • 11/29/2017 - $1M
  • 11/29/2017 - $1M
  • 11/29/2017 - $1M
  • 11/29/2017 - $890,000

After sending back to Onyema $15,140,000, Onyema then tries to get the money out of the United States.  In August 2018, Onyema created Bluestream Aero Services and Springfield Aviation Company in Ontario, Canada.  He opened accounts for the companies at Bank of Montreal and sent $10 Million (in November 2018) from his personal Wells Fargo account to those bank accounts in Canada.

Based on the timing of the court documents, moving $10 Million out of the country is likely to be what triggered the investigation.  While the original Criminal Complaint is still "sealed", it was filed one month after the wire transfers to Canada.  So, while the indictments and arrest warrants were only issued on November 19, 2019, the court case began in December of 2018 with the "magistrate complaint."


As my many Nigerian Twitter followers are reminding me, everyone is Innocent until proven Guilty, but what I have learned through many years of watching the American Justice system, they don't unseal federal indictments until their evidence is rock solid!  When you cause charities you control to send you $44 Million dollars, and then you create fraudulent documents to pay a company you control $20 Million US Dollars for airplanes that you already own, and then send most of that money back to your private banking accounts, and then try to get that money out of the United States into Canada, I think it is plain to see crimes have been committed.

Of course this doesn't stop the Nigerian media from running stories stating that "the allegations of financial misdeeds against [Onyema] as a deliberate attempt to kill Air Peace and deepen the unemployement crisis in the country."

https://guardian.ng/news/diaspora-nigerians-urge-buhari-to-wade-into-onyemas-ordeal/

I'm sure the facts won't matter to the Concerned Diaspora Citizens, but I hope reasonable people will understand that the US Government is not persecuting businessmen.  They are charging criminals with crimes.

Monday, November 18, 2019

Facebook's Transparency Report: (Expert) Supervised Machine Learning Works!

Last summer the BBC technology program "Click" came to visit the lab for a special called "Can Technology Solve the Opioid Crisis?"  One of the points we stressed with @NickKwek was that when we report opiods and fentanyl-related posts to Facebook the objective is not to take down THAT POST, but rather to help Facebook's automated tools update their models of what offensive drug sales content looks like.

Last week we had an opportunity to see what that looks like in action as Facebook released their transparency report for Q3 2019.  Facebook's Transparency report is divided into two major sections which each have two subsections. "Enforcement of our Standards" covers "Community Standards Enforcement" and "Intellectual Property Infringement."  The other major section, "Legal Requests" is divided into "Government Requests for User Data" and "Content Restrictions Based on Local Law."

The November 2019 transparency report for Community Standards looks at ten categories of content on Facebook and four categories of content on Instagram.

In this post, we'll look primarily at the statistics for "Regulated Goods: Drugs and Firearms" but the other categories on Facebook are:

  • Adult Nudity and Sexual Activity
  • Bullying and Harassment
  • Child Nudity and Sexual Exploitation of Children
  • Fake Accounts
  • Hate Speech
  • Spam
  • Terrorist Propaganda
  • Violent and Graphic Content
  • Suicide and Self-injury
On Instagram, the other categories are:
  • Child Nudity and Sexual Exploitation of Children
  • Suicide and Self-injury
  • Terrorist Propaganda
Facebook has shared previously about our work to reduce terrorist content on their platform.  See their "Hard Questions" blog post -- "Are We Winning the War on Terrorism Online."  In this most recent report, they share that "Our proactive rate for detecting content related to al-Qaeda, ISIS and their affiliates remained above 99% in Q2 and Q3 2019, while our proactive rate for all terrorist organizations in Q2 and Q3 2019 is above 98%."

What does that mean?  It means that through the power of machine learning, when someone posts content trying to "express support or praise for groups, leaders, or individuals involved in terrorist activities" the content is removed automagically without the need for anyone to report it 98-99% of the time!

They've also previously discussed our relationship regarding the Opioid Crisis.  See their post "Supporting Our Community in the Face of the Opioid Epidemic." 

As Facebook has focused on identifying drug-related content, the number of detections has risen.  That's likely from two reasons -- one, they are now discovering content that previously would have remained unreported in the past; but also two, frustrated users are attempting to post their drug sales information in more ways trying to get past the blocks -- and largely failing to do so.

Drug related posts actioned:
  • 572,400 posts in Q4 2018
  • 841,200 posts in Q1 2019 
  • 2,600,000 posts in Q2 2019 
  • 4,400,000 posts in Q3 2019
When I attended Facebook's Faculty Summit all the way back in 2016  they had me hooked from the very beginning of the day when Facebook's Engineering Director Joaquin Quinonero Candela gave his opening keynote.  All of this amazing machine learning technology that people like Dr. Candela had created to help improve online ad delivery were ALSO being used to make the platform as safe as possible against a wide variety of threats. I was especially excited to learn about the work of Wendy Mu. At the time Wendy's bio said "Wendy is an engineering manager on Care Machine Learning, which leverages machine learning to remove abusive content from the site.  Over the last three years at Facebook, she has also worked on Site Integrity, Product Infrastructure, and Privacy."  Wendy and her team are inventing and patenting new ways of applying machine learning to this problem space.  Nektarios Leontiadis "a research scientist on the Threats Infrastructure Team" with a PhD in online crime modeling and prevention from Carnegie Mellon and Jen Weedon, previously at FireEye, were some of the other folks I met there that made such a profound impression on me!  Since then, the UAB Computer Forensics Research Lab has partnered with Facebook on many projects, but quite a few have taken the form of "what would a human expert label as offending content in this threat space?"

This is where "supervised machine learning" comes into play.  

The simplest version of Supervised Machine Learning is the "I am not a Robot" testing that Google uses to label the world.  You may be old enough to remember when Google perfected their Google Books project by asking us to human label all of the unreadable words that their scanner lifted from old books, but which were not properly recognized by their OCR algorithm.  Then we were asked to label the address numbers found on buildings and mailboxes and then later to choose cars, bicycles, traffic lights, and more recently cross walks as it seems we are not teaching future self-driving cars how to not drive over pedestrians.

This works well for "general knowledge" types of supervised learning.  Anyone over the age of three can fairly reliably tell the difference between a Cat and a Dog.  When people talk about supervised machine learning, that is the most common example, which comes from the concept of "Convolutional Neural Networks".  Do a search on "machine learning cat dog" and you'll find ten thousand example articles, such as this image from Booz Allen Hamilton.

Booz Allen Hamilton infographic 


We're working on something slightly different, in that the labeling requires more specialized knowledge than "Cat vs. not Cat".   Is this chemical formula a Fentanyl variant?  Is the person in this picture the leader of a terrorist organization?  What hashtags are opioid sellers using to communicate with one another once their 100 favorite search terms are being blocked by Facebook and Instagram?

Facebook Research has a nice set of videos that explain some of the basics of Machine Learning that are shared as part of the "Machine Learning Academy" series:

from: https://research.fb.com/videos/field-guide-to-machine-learning-lesson-1-problem-definition/
In this chart, the data provided by UAB is primarily part of that "Data Gathering" section ... by bringing forensic drug chemists into the lab, we're able to provide a more sophisticated set of "labelers" than the general public.  Part of our "Accuracy testing" then comes in on the other end.  After the model built from our data (and the data from other reporters) is put into play, does it become more difficult for our experts to find such content online?

Looking at the Transparency Report's Community Standards section, the results are looking really great!  


In the fourth quarter of 2018, only 78.6% of the offending drug content at Facebook was being removed by automation.  22% of it didn't get deleted until a user reported it, by clicking through the content reporting buttons.  By the 3rd Quarter of 2019, 97.6% of offending drug content was removed at Facebook by applying automation!

In Q4 2018, 122,493 pieces of drug content were "manually reported" while 449,906 pieces were "machine identified."

In Q3 2019, 105,600 pieces of drug content were "manually reported", but now about 4.3 million pieces were "machine identified."  

Terror Data

Twitter also produces a Transparency report and also shares information about content violations, but in most categories lags far behind Facebook on automation.  Twitter's latest transparency report says that "more than 50% of Tweets we take action on for abuse are now being surfaced using technology. This compares to just 20% a year ago."  The one category where they seem to be doing much better than that is terrorism.  Their last report covered the period January to June 2019.  Twitter does not share statistics about drug sales content, but does have Terrorism information.  During this period, 115,861 accounts were suspended for violations related to the promotion of terrorism.  87% of those accounts were identified through internal tools.  

Facebook doesn't share these numbers by unique accounts, but rather by the POSTS that have been actioned.  In the Q3 2019 data, Twitter actioned 5.2 million pieces of terror content.  98.5% of those posts were machine identified.





Tuesday, November 12, 2019

'Tis the Season for SCAMS!

A recent project that DarkTower worked on was related to fraudulent marketplaces offering too-good-to-be-true deals on electronics.  DarkTower's CEO Robin Pugh took those lessons and applied them to a recent online shopping experience ... I asked her to write it up for our blog:

As I was browsing some of my favorite Instagrammers this morning, one of them posted about a great coffee system that was on price rollback at Walmart.com for $99 – nearly half off the list price of $179.99.  As a coffee lover AND a bargain lover, I was immediately interested and began searching for more information.  Since I wasn’t familiar with how this particular coffee system worked, I typed the model name in my google search bar, intending to find some YouTube videos on how it worked, but since I left my search term fairly broad, some interesting sites popped up in my search results. 

https://julishopgame.com/index.php/ninja-coffee-bar-system-cf097.html
RED FLAG #1: Prices that are TOO good

WOW!  An even BIGGER BARGAIN… more than $10 less than the Walmart.com price?!  But on a site I’ve never heard of “Juli Shop,” so I began to take a closer look at the site, since we all know a) it’s hard to beat a Walmart price and b) if it’s too good to be true….  Well, you can finish that sentence.  (Other kitchen appliances on the site also had crazy discounts.  The "DeLonghi Dedica EC680 15 Bar Stainless Steel Slim Espresso" machine is only $160.99 at Juli Shop, but $299.99 at Bed Bath & Beyond and BestBuy, and $241 at WalMart.com.)


RED FLAG  #2:  Same Day delivery

Among the things I notice about Juli Shop, in the list of things they promote about their site is “Same Day Delivery.”  Really?  Same Day? So where are they located that they can promise same day delivery?

https://julishopgame.com/index.php/contacts/
They purport to be in Citronelle, Alabama, with a local phone number; so I looked up the address on Google Maps and found that it’s a lovely 2 BR/2 BA brick ranch home that’s not currently for sale. The phone number – brace yourself – is disconnected. But they’ll definitely get me my Ninja Coffee Bar System today.

RED FLAG #3: Spelling Errors
I also notice in the menu bar that they want to tell me “Abouts Us”. Other sections of the menu are labeled "INFOMATION" and "CUSTORMER." Well, spelling errors are often a hallmark of scam sites and phishing emails, so I click to learn more “Abouts” them.

https://julishopgame.com/index.php/about-us/
RED FLAG #4:  Information clearly copied from another site
Oddly, their About Us page has no mention of Juli Shop.  It is 100% about a fashion apparel company called Madison Island, and Juli Shop has no apparel merchandise at all.  Let’s check out Madison Island to see if it’s an affiliate, or maybe a parent company.

A quick search for Madison Island reveals that it is a fictitious demo store used to test Magento, a popular shopping cart processing plug-in, which Juli Shop uses to process its credit card transactions. By the way, Magento is targeted by one of the most prevalent malware families called Magecart.  Magecart is specifically to steal credit card credentials.  So let’s think of the possibilities here:  a scam site that takes your money and never delivers the promised item AND steals your credit card information at the same time.  That’s quite a criminal enterprise!

RED FLAG #5:  Sanity check
At this point, all signs point toward a scam site, and I’m pretty sure I’m going to be paying $10 more for my Ninja Coffee Bar; but before I move on, I check out scamadviser.com.
https://www.scamadviser.com/check-website/julishopgame.com/index.php/about-us
They give Juli Shop a 66% “TrustScore”, which puts it squarely in the “green” zone; but after reading the negative/positive comments, I’m not sure I agree.  First, the website was established 21 days ago.  The server is used by multiple websites, which isn’t uncommon for a small site, but they are offering items and services that are not typical of a small site.  Additionally, and quite concerning, the set up involves both the US and Vietnam.  A multi-country set-up is not common for a small site, and somehow Vietnam doesn’t jive with Citronelle, Alabama.

Further review of the scamadviser.com data shows conflicting information around the site’s infrastructure, but also shows that there are no comments or reviews on typical review sites like Sitejabber and Trustpilot. The absence of this information is quite telling.

Scamadviser may give this site a 66% trust rating.  I’m giving it a 100% SCAM rating.

As the Christmas cyber shopping season is upon us, before you shop at a new online store, take the time to thoroughly review the site.  As demonstrated above, a few key checks and paying attention to red flags can quickly reveal whether you should be entering your credit card information there, and whether it may leave Santa with an empty sack on Christmas eve.

Saturday, November 09, 2019

Business Email Compromise (#BEC) Email Forwarding In Action


DarkTower President Robin Pugh was chatting with a friend who is the VP of Operations for her family business.  She mentioned as an aside that their email had been hacked, and of course, Robin’s cybercrime-fighter ears perked up.  The friend went on to explain that one of her clients, a global, Fortune 500 company, had called her to confirm email instructions from the company to start making payments into a different bank account.  But, of course, those were not legitimate instructions.

The screenshot below shows part of an email thread between her customer and the criminal using the compromised account.  What you cannot tell due to the redactions is that a cybercriminal had control of an account at the company; he messaged all customers to change the remittance instructions.  Even when the customer responded by email to confirm that these were legitimate instructions, the criminal assured the customer that the instructions were correct. 




However, the customer noticed some spelling and grammar discrepancies in the response and finally called the vendor to confirm.  Once alerted to the email compromise, the VP immediately changed the password to secure the email account.  This is certainly a "Best Practice" when responding to a phishing incident.  

But having spent time listening to Gary and Heather talk so much about Business Email Compromise, Robin knew to advise her friend to check one more thing…forwarding rules in the email client.  

After navigating in the email client to the Rules section, the VP found that a rule had been created to forward any messages mentioning the words “wire instructions,” “wire transfer,” “fund transfer,” “payment,” or “invoice” to the address blessingsalways823 at gmail dot com.



"If the message includes specific words in the subject or body 'wire instructions' or 'wire transfer' or 'funds transfer' or 'payment' or 'invoice'; forward the message to blessingalways823 at gmail.com."


Even though Robin’s friend had already changed the email account password, the criminals were able to continue viewing and intercepting the email messages that were important to them.

The next steps were then to disable the rule, have I.T. check other users in the email domain for malicious forwarding rules, and then begin the process of notifying clients. 

A DarkTower investigation revealed that the Gmail account was used to register the domain name alpan.us on 9/13/18, for which the registration details reveal the name and address Anthony L. Ania, 34501 Southside Park Dr, Solon, OH, 44139, phone 813-856-5005, and fax 650-253-0000.  The domain has never had a website and was probably used to impersonate an executive of Alpan Lighting Products, a company in California that uses the domain name alpan.com.  The address in Ohio may belong to a Cleveland attorney who has suffered identity theft, but there are at least three Nigerian profiles on Facebook using the same name, and the Google account password recovery process reveals that a phone number ending in 05 is tied to the Gmail account.



The criminal’s Gmail account was also seen on two boat sales websites, sailboatlistings dot com and powerboatlistings dot com, in lists of suspicious email addresses.

Lessons Learned:
1) Simply changing the password did not secure the account. 
2) Never confirm suspicious emails by replying to the suspicious email.
3) Regularly check rules in email accounts of your domain.