Tuesday, September 14, 2010

"Here You Have" Hype & Electronic Jihad

Hype


On September 9th, my blog post on the "Here You Have" worm mentioned that the spread mechanisms of the worm were narrowly focused on a few targets that it hit very hard. Because of this, I've been quite surprised to see claims such as this USA Today article, which claims:

Viral messages carrying an innocuous-looking "Here you have" or "Just for you" subject line at one point Thursday accounted for an astounding 14.2% of spam messages moving across the Internet, says Nilesh Bhandari, Cisco product manager.


and then goes on to do the math for us. The article says there are 300 billion emails per day, so "Here You Have" must have sent 42 billion emails. They then show a chart, for which they provide no source attribution, that demonstrates that there was only one thirty minute period where whoever their source for the chart (presumably Cisco?) claimed the spam had reached 14.2%.



If we assume briefly that there really are 300 billion emails per day, a back of the envelope calculation of this chart would indicate that there were actually closer to 8 billion, rather than 42 billion, emails sent by "Here You Have". (You can clearly see by the USA Today's own chart that in most time periods for the day the percentage was closer to "0%" than to "14%"). 14.2% occurred in only one 30 minute sampling, which, if we assume an equal distribution of the 300 billion across the day, would mean 887 million emails in that thirty minute window.

BUT WAIT! Is it accurate to project the sampling from Cisco's Ironport on "the global spam" picture? Absolutely not! Take for a moment my personal anecdotal evidence. I stand by my earlier statement that the UAB Spam Data Mine on September 9th received 17 copies of the "Here You Have" emails, 13 of which came from senders in a single large financial institution. Our calculation of 0.00002% is perhaps closer to the average "global spam" recipients reality.

In my personal spam collection, including many "live" personal email addresses, I received 10,134 spam email messages on September 9th, of which ZERO were from the "Here You Have" worm. (And yes, I use NO FORM of spam filtering on those email addresses.) I also received zero copies in my university email accounts.

Our reality, and yours, unless your primary email account is in a very large corporation running Outlook, is probably closer to what was described by Microsoft. (Thanks to Robert McMillan of IDG News for pointing this out in his article Here You Have Worm Caused Brief Havoc.)



In this Technet Blog post: "Update on the Here You Have Worm: Visal-B" the Microsoft lab says that in normal spam monitoring, 90% of their reports come from "consumer" email users (protected and reported through Microsoft Security Essentials), while very few reports come from their "corporate" email users (protected and reported through Forefront Client Security).

Microsoft bloggers Jimmy Kuo & Holly Stewart go on to say that while they have sensors deployed worldwide, 98% of their reports for this worm came from US-based reporters. Cisco's 2010 MidYear Security Report (36 page PDF) says that 8.98% of global spam originates in the United States.

When Cisco Ironport reports their numbers, we have to remember that their appliance is overwhelmingly present in corporate email accounts. I know the Ironport guys, believe they have a great product, and believe they reported accurately what they saw on the corporate networks, but also believe that a few media sources have misinterpreted these numbers to turn Here You Have into the Global Armageddon of Spam, which it clearly was not. Except for some US-based corporate mail servers.

But was that the whole point? In order to learn more we need to identify some "patient zero" spam recipients. Who was THE FIRST PERSON at ABC, NASA, Google, JP Morgan Chase, etc, to receive the spam. When we learn more about who is behind the attack, it looks like targeting "big corporations" may have been the whole point of the worm!

Electronic Jihad



The more interesting angle to me is the revelations from Joe Stewart, the International Grandmaster of Malware Analysis at SecureWorks in his blog post Here You Have Worm and e-Jihad Connection. I asked Heather McCalley, the Criminal Intelligence Supervisor in the UAB Computer Forensics Research Laboratory to summarize the details for us:

Joe Stewart had previously identified that the malware contained a string "iraq_resistance" and that a previous version of the same malware use an email address "iraq_resistance@yahoo.com".

A fellow researcher at Internet Identity provided us a link to a YouTube video that claimed to be from the author of the worm. When we first saw the video early yesterday morning it had been viewed 128 times. Heather took a screen shot showing 302 views yesterday morning. This morning there have been 3,803 views of the video.



My nickname is Iraq Resistance. Listen to me about the reasons behind the 9 september virus that affected NASA, Coca-Cola, Google, and most American ?gains?. What I wanted to say is that United States does not have the right to invade our people and steal our oil under the name of nuclear weapons. Have you seen any there? No evidence, even about any project. How easy you kill and destroy. Second, about the Christian Terry Jones what he tried to do on the same day this worm spread is not even fair. I know that not all Christians are similar and some newspapers wrote that I am a terrorist hacker because of the computer virus and Mr. Terry Jones is not and he is not terrorist because he infected all muslims' behavior. I think America, come on! Be fair. Where is your freedom which must end when it reaches another person's freedom. And you say you modern educated people. I don't know there is another one and really I don't like smashing and as you know there were no computers smashed as you know by the analysis report. I could have smashed all those I infected but I wouldn't and don't use the word terrorist please. I hope that all people understand I am not a negative person. Thanks for publishing.


(click for video)

So, shall we take Mr. IqZiad at his word? Context is everything, and in this case, we have ample evidence that iraq_resistance, the self-proclaimed "Commander of the Brigades of Tariq bin Ziad", desires to harm America.

Here's a post that he made on the website "vbhacker.net" where he has been active since 2006 using the username "iraq_resistance":

فيروس طارق بن زياد يعصف بأمريكا
السلام عليكم
قام قائد كتائب طارق بن زياد بشن هجوم فيروس على شركات امريكية وذلك يوم الخميس واصاب عدد هائل من الكمبيوترات ما ادى الى ان الشركات توقف خادمات البريد حتى تسيطر على المشكلة.
وقد اوقفت شركة كومكاست بعض خادماتها وشركة قوقل وشركة كوكاكولا ووكالة ناسا وذلك في ضرف ساعتين مساء الخميس الموافق 9-9-2010
هذا تقرير من شركة مايكروسوفت
http://www.msnbc.msn.com/id/39087497/ns/technology_and_science-security/
وهذا تقرير الدايلي ميل البريطانية

http://www.dailymail.co.uk/sciencetech/article-1310890/Here-virus-causes-havoc-spreads-world.html

وقد اقسم قائد كتائب طارق بن زياد على مواصلة الهجوم في وقت لاحق انتقاما لحملتهم على الاسلام
الرجاء نشر هذا الانجاز والدعاء لكتائب طارق بن زياد بالتوفيق والحفظ


The post takes credit for the attack, links to two news stories about the attack, and then closes in the last two lines by saying:

As the Commander of the Brigades of the Tarik bin Ziad, I swear the attacks will continue in retaliation for their attacks against Islam.

Please publish this achievement and pray for the success and protection of al-Tarik bin Ziad.


Well, Mr. IQZiad, I've published your achievement, but I am certainly praying for a different outcome than the one you request.

The user iraq_resistance has been a member of vbhack.net since 2006. When we looked into the board this morning there were 619 active registered users logged in to the site, as well as 17,032 "guests" reading public messages on the board. The board, which is hosted on LiquidWeb in Chicago, is one of the 22,000 most popular on the Internet according to NetCraft, and has many non-offensive topics, including large popular forums about the World Cup and Islam.

Despite his long membership, Iraq_resistance has only created three discussion threads. The most popular, which was read 4,765 times and has 163 replies, was this message from May of 2008, entitled: مطلوب شباب للمشاركة في حملة الجهاد الالكتروني
which translates as: "Wanted: Young people to participate in Electronic Jihad".

السلام عليكم اخواني
تم تأسيس مجموعة بإسم كتائب طارق بن زياد وهدف هذه المجموعة اختراق اجهزة امريكية تابعة للجيش الامريكي
وقد تطلب زيادة العدد حتى نكون اكثر فعالية .. لذلك نطرح شروط الانتساب الى هذه المجموعة الجهادية الالكترونية:

1 - أن يكون هدف المشترك الجهاد الالكتروني وأن يقسم أنه لن يستخدم ما يتعلمه مع المجموعة ضد هدف آخر.

2 - الإخلاص في العمل واحترام أعضاء المجموعة وبعد توسعها يكون للاقدمية والاكثر فعالية مرتبة القيادة على مجموعات تابعة للمجموعة الرئيسية .

3 - يكون اللقاء والمحادثة على الياهو مسنجر والامسن .

4 - اي مشاكل مع الاعضاء او القيادات باب الشكوى مفتوح للقائد العام للكتائب .

5 - مستوى المجاهد غير مهم لانه سيتعلم مع المجموعة كما ان الطريقة ليست صعبة وهي مؤثرة فعلا.

6 - اتباع نصائح القائد العام والاخلاص الكامل بالعمل لوجه الله .

7 - تناسي الاحقاد بين اعضاء المجموعة وروح المنافسة تكون ضد العدو وليس ضد الاخوة .


8 - القسم في عدم استخدام ما يتعلمه في هدف اخر خارج المجموعة سيكون على المايك ويسمعه القائد العام .

نسأل الله ان يوفقنا ويسدد خطانا واياكم .. ونتمنى من الاخوة الاستجابة للانضمام لهذه الفرصة المباركة
كما نشكر ادارة المنتدى لاتاحة الفرصة لاعلان الحملة وطلب والانتساب وسيتم موافاتكم اولا باول بالنتائج باذن الله.
للانضمام الرجاء اضافة معرف ياهو

tarek_bin_ziad_army

بانتظار المجاهدين لقبول اضافتكم
اخوكم القائد العام لكتائب طارق بن زياد


Which, according to Google translate, reads:

Peace be upon you my brothers

Group was established in the name of al-Tariq bin Ziyad and goal of this group infiltrate a U.S. subsidiary of the U.S. Army

The increasing number of requests so we'll be more effective .. Therefore, we present the conditions for affiliation to these jihadist group E:

1 - to be the common goal of electronic jihad and to apportion that it will use what it learns with the group against the other goal.

2 - dedication to work and respect for members of the group and after the expansion is the most seniority and rank the effectiveness of the leadership groups of the main group.

3 - be meeting and chatting on Yahoo Messenger, Alamson.

4 - any problems with members or leaders open the door of the complaint to the General Commander of the Brigade.

5 - the level of fighting is not important because he will learn with the group and that the way in which it is not really impressive.

6 - follow the advice of the Commander in Chief and dedication to working for God's sake.

7 - forget the grudges between the members of the group and the spirit of competition which is against the enemy and not against the brothers.

8 - Section in the non-use of learning the target outside the group will be on the mic and hear the commander in chief.

We ask God to help us and guide our steps and you .. And good response from the brothers to join this blessed opportunity

We also thank the management of the Forum for the opportunity to announce the campaign and asked the association and will provide you with first hand the results, God willing.

Please add to join the Yahoo ID

tarek_bin_ziad_army

Waiting for the Mujahideen to accept Adavckm
Brother Commander General of the Brigades, Tariq ibn Ziyad


Tariq ibn Ziyad was the name of the Muslim servant who was appointed a General and given troops to conquer the Iberian peninsula in the year 711. You can read more about him in his Wikipedia article, or for a more Islam-friendly version of events, see HaqIslam. Tariq is the invader who famously burned his ships after landing, convinced of his victory by a vision of the Prophet promising him success and that he would personally kill King Roderick.

The same "call for recruits" was posted in many other places, including:

http://www.amman-dj.com/vb/a-t68089/ (by user "iraq_resistance", active since December 2006, hosted on SoftLayer in the USA.)

http://www.m0dy.net/vb/t104142.html (by user "iraq_resistance", active since November 2005, hosted on SoftLayer in the USA.)

http://vbnaajm.naajm.com/showthread.php?t=44269 (by user "iraq_resistance", active since July 2004, hosted on BlueHost in the USA.)

http://www.arabteam2000-forum.com/index.php?showuser=74343 (user "iraq_resistance", active since March 2006, hosted on XLHost in the USA.)

In addition there are malware author recruiting ads, such as this one:

http://lovesingle.jeeran.com/no2.html

The call is for assistance from those who can create computer viruses to strike the enemy. Malware coders who want to help in the cause were instructed (in Arabic):

To subscribe send a message to

tarek_bin_ziad_army@yahoo.com

And please send a message to email the following to configure a lethal army of God Almighty in the future

thabet3000@gmail.com


Impact?



So despite the "I'm not a terrorist", YouTube video, we have a mass-mailing worm that disproportionately impacted US-based businesses, successfully planting backdoor code on many of the infected machines, planted by a person who has been calling himself "Iraq_resistance" since 2006, and who has been recruiting for "electronic Jihad" participants since 2008. This person boasted about his attacks, and has promised there will be others, and as far back as March 6, 2009, was specifically inviting malware authors to help him create "a lethal army of God".

Was there a lot of Hype in the coverage of this malware? Yes. But perhaps the hype is deserving a deeper response than a shrug.

Update


Our friend Bob McMillan has shared an interesting Series of Emails with the worm author.

Thursday, September 09, 2010

"Here you have" spam spreads email worm

This evening while I was driving to an open house at my daughter's school (very cool! proud of you, Kyriae!) a journalist called to ask me about "the major new email worm that everyone is talking about".

Insert sound of crickets.

I asked him for more details and he said all he knew so far was that it used the subject line "Here you have", which made me laugh -- that was the main subject line of the Anna Kournikova virus way back in 2001!

In my lab at the University of Alabama at Birmingham we have a project called the UAB Spam Data Mine, so I'm usually a pretty good person to ask if something involves the words "major" and "email", but not this time. As the evening progressed I got more and more queries and emails about it, so I decided to look into it.

In the entire Spam Data Mine, we had 17 copies of the email, or roughly one out of every 100,000 email messages for the day. Certainly not "major", but then when we looked at the actual emails, we noticed that thirteen of the seventeen came from the same Very Large Financial Institution.

That did pique my interest! ABC seems to be the only news station covering the story, which is because the worm behind this malware managed to get lose in some ABC properties. Here's a sample news story, from ABC 13 in Houston:

A massive and dangerous email virus has spread like wildfire, flooding inboxes and disrupting operations across the globe. The email is landing in the inboxes of companies around the world.

The email has the subject line 'Here you have.' In the body of the email, it reads, "Hello: This is The Document I told you about, you can find it here," and contains a reference to a document and a link to what appears to be a PDF. IT departments are advising users not to open the email or click on the link, but to delete the message.

If you click on the link, the virus replicates and sends itself out using your name and contact list.

The attack appears to be global, so far affecting companies such as Disney, P&G, Dow, Coca-Cola and others. The Florida Department of Transportation's email system has been shut down, and other Florida government agencies have been affected, but so far no Texas government agencies are reporting any impact. The virus may have originated in Russia.

(story from ABC's KTRK in Houston)

ABC National news had a similarly glamorous lead in, mentioning that as of 4 PM on Thursday "Here you have" was the second hottest news trend on Google. "Organizations including NASA, Comcast, AIG, Disney, Proctor & Gamble, Florida Department of Transportation and Wells Fargo are just a few of the organizations apparently affected by the worm, which appears to have sent out hundreds of thousands, if not millions of e-mails"

If we scroll back in the Twitter space about twelve hours (1:00 PM on Thursday) we can confirm that at least for some folks, the email did feel pretty overwhelming. See posts such as:

tony1971 who else is getting tons of e-mails with the subject, #hereyouhave?

jmyoung82 328 emails and counting from #hereyouhave email worm

wiltap I turned off my desktop email--machine was non-responsive. RT @perfectcr Yup, its global! #hereyouhave

padevries Seems like #hereyouhave #virus is under control at my company. After 724 emails in 10 min it has stopped.

The malware preferred to spread via the Outlook mail program, and spammed itself primarily by sending to every member of the local Outlook address book. In companies where a domain administrator logged in to an infected machine the effect was that every machine reachable from that machine that used the same administrator password became infected, and then each of those users sent an email to every other user in the company directory. I can see where that would pile up quickly.

Apparently very few companies have the addresses in the UAB Spam Data Mine in their address books, which would explain me receiving so little spam. (A fortuitous typographical error seems to be how I got most of our copies.)

BarracudaLabs claims in their useful and informative blog entry, “Here You Have” Spam Teaches an Old Worm a New Trick that they saw the spam first at 9:44 AM Pacific time and quickly saw 200,000 copies, but that its likely that infected organizations had many more. The spam dried up once the website hosting the malware shut down the offending account.

Although the malware is being recognized for its spam, the reason it is being labeled as a worm has to do with its spread within corporate networks. The malware, which was previously seen on August 20th, has been given the name W32.Imsolk.A by Symantec and others at that time. They call the new version "W32.Imsolk.B". TrendMicro calls the new version "Worm_Meylme.B".

Here's a VirusTotal report showing detections and who is calling it what. Currently 23 of 42 anti-virus products are reporting a detection. (Up from 17 of 42 when I checked about 4 hours ago).

Its interesting to follow Symantec's ticket on the malware through the day . . . Symantec Tech Support ticket - which concluded:

""Enterprise customers are protected by a Rapid Release signature set dated Sep 9th 2010 rev 023, or later. The next regular definition set to be published at 16:00 PST Sep 9th 2010 will contain the detection."

McAfee's AvertLabs also had a Special Report on Here you Have, including links to their advice on identifying and removing the malware, with a special Knowledge Base link that provided information on an emergency signature file and a special version of their stand-alone "stinger" product.

Microsoft has a quite good Threat Encyclopedia entry for the previous version, which they called "Visal.A", and has updated it with a great entry on Visal.B. Some of the cooler features of this malware described by Microsoft include:

- the malware copies itself as " CV 2010.exe" to drives C: through H:.

- The worm adds an autostart key by making the following registry modification:

In subkey: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Adds value: "Sets Shell"
With data: “%windir%\csrss.exe”


which is how it guarantees that it will re-invoke after boot -- note that by linking to "Winlogon", even a 'safe mode' boot will be "infected".

- the worm will attempt to mount network shares for all computers on the local network and copy itself as a fake graphic file - "N73.Image12.03.2009.JPG.scr" and placing itself in a "New Folder", as well as folders named "Music" and "Print" on every drive it can mount. It will add an entry into an autorun.inf file on each of those drives to ensure that mounting the drive will invoke their fake JPG file.

- The malware also attaches itself via the registry to 391 various .exe file names, primarily the names of security tools and programs, so that if any of them are executed, the malware stored in "%windir%\csrss.exe" will be re-invoked.

Although the malware theoretically can send three different emails from templates in the malware, all of the samples we received today were of the first variety:

Subject: Here you have
Hello:

This is The Document I told you about,you can find it Here.
http://www.sharedocuments.com/library/PDF_Document21.025542010.pdf

Please check it and reply as soon as possible.

Cheers,


The first actual copy of the email we saw was actually from an employee of a local utility company. In all the copies I saw, the actual link was downloading the content from:

members.multimania.co.uk/yahoophoto/PDF_Document21_025542010_pdf.scr

Although SCR files are traditionally thought of as "screen saver" files, if the file is an executable, '.scr' files can be directly executed in Windows, as indeed this one is. Because file extensions are suppressed by default in Windows, and because the executable uses an icon that makes it appear to be a PDF file, this one fooled quite a number of people.

Multimania quickly shutdown the account "yahoophoto" once it was understood what was
happening. After that the attack more or less ran itself out. While it continued to spread via network shares inside of large corporate networks, the email based component was a dud after that point.

Random Pseudo-URLs Try to Confuse Anti-Spam Solutions

This summary is not available. Please click here to view the post.

Thursday, September 02, 2010

Discovery Channel Terrorist background

Today I asked our UAB Cyber Intelligence team to give me some background on the Discover Channel eco-terrorist, James J. Lee. Heather McCalley, who supervises the team, provides the following "guest" blog entry. We'll be seeing more guest bloggers from my research team at UAB's Computer Forensics Research Lab in the future . . .






Discovery Channel shooter James Jay Lee not only ran the website www.savetheplanetprotest.com, he was also a frequent poster in the saveThePlanetProtest topic on a message board at Yuku.com: savetheplanetprotest.yuku.com

There he chatted as “misterfifteen” with other misguided people in January 2008 about the weeklong protest he was planning--although it sounds like it was more of a vigil--for Discovery Channel headquarters beginning the following February 15th. On this forum he wrote threateningly about his anger toward the educational TV channel: “They have to get on board with saving the planet and I'd better start seeing some REAL improvement in the news that things are changing.” (or, WHAT will happen, you ask?) He also wrote, “Discovery is the enemy.” But his protest fizzled out when nobody showed up, and he decided to quit paying people to hang around, like the homeless man below:



In order to create a "protest crowd", Lee began throwing thousands of dollars of cash into the air, as documented in this YouTube video Mad Money Dash in Silver Springs.

The police arrested him, and Lee notes in the forum that he was held for two weeks, including four days in the loony bin. I like the way one forum poster commented on Lee’s alias name on Yuku: “an obvious reference to the Fifteen Minutes of Fame he hopes to garnish from this fruitless exertion of time and energy.”

Shortly after his release he launched his new effort, an essay contest with a $200,000 first prize:



Well, Lee never quite went so far in his posts as to make outright threats of physical harm. But what if he had? Who monitors such incendiary internet sites? Don’t count on Yuku to take this down anytime soon; they describe themselves as “a social universe of communities united by people and their passions.”And, I suppose the 11-step rant on his website will stay up until he misses a few payments to IN2NET NETWORK, INC. Pete4Peace details his concerns, however, in a post about several encounters with Lee. He was concerned because Lee “talked about using violence” :

http://beltwaybeast.blogspot.com/

That blog post from today contains email exchanges from the past between the blogger and "misterfifteen@hotmail.com".

Inquiring 21st Century minds have already identified Lee’s old videos, photos, and MySpace page(already down)…heck, he even has a fan page now on Facebook! Although he had clearly been thinking about the Discovery Channel for a long time, he actually updated his manifesto on his website yesterday morning before heading over to the headquarters building. The time stamp for the HTML page is Wednesday, September 01, 2010 8:46:30 AM. Chilling. (His manifesto is at savetheplanetprotest.com, at least for now...(archived here just in case...)


Don't check that CV! Major Zeus Spam Campaign

In a bold new spam campaign, the criminals behind the Zeus Botnet have been distributing a spam email with a link to an executable file.

We first noticed this campaign in the UAB Spam Data Mine with a spam email message with the subject "you vacancy".

The body of that email read:


Thank you for the chat yesterday, it really helped me get a clearer idea
of recruitment as well as exploring any potential opportunity.

I have just spotted a mistake on the CV I sent in which my email was incorrect.

Apologies for any inconvenience caused if you have already sent me any information on anything we discussed.

My CV is an updated!
CV with the correct email on this link: http://good-resume.info/mycv.docx


The exact same email has also been seen in the UAB Spam Data Mine with several other subjects today:
908you vacancy
869Re: CV
864for CV
370Welcoming speech
115Greetings
112Hello
111Compliments
110Salutation
108Speech of welcome
100Civilities
99Hello message


The final link there that LOOKS like its going to download a Microsoft Word document, actually retrieves a file with the name:

mycv.doc.exe

The properties on that document claim to be:

BitDefender Management Console
SOFTWIN S.R.L.

The current detection rate on the malware at VirusTotal is 16/43, meaning that only 16 of 43 anti-virus products identify this as malware, although only one is calling it "zbot". Here's the VirusTotal Report for md5 = 10fd124206b15f878240f22a30eaf9fe

Our copy of the malware came from a computer with the IP address 58.222.143.148, which has been in bad company for some time. The IP is located on China Beijing Chinanet Jiangsu Province Network. Another example of Russian-speaking crooks hosting their malicious servers in China.

According to those great guys at ZeusTracker, that IP has been used for some really bad stuff.

caseoffinance.cc
dowsonstoke.cc
leadingcase.cc (Confirmed Zeus)
goldfieldforu.cc (Confirmed Zeus 8/24)
youmoneyway.cc (Confirmed Zeus 8/24)
a8228djjnedu7e8hd83ndd43d3d3.com
mikkymouse.com
first-wave-aug.com
iwfybfywi.com (Confirmed Zeus 8/19)
whiteagngo.com (Confirmed Zeus 9/2)
ekuns.com
fasterbuyers.com
hotsku.com (COnfirmed Zeus 9/1)
askuv.com (Confirmed Zeus 9/2)
good-resume.info
roundhome.net (Confirmed Zeus 8/24)
caramelloinze.net (Confirmed Zeus 9/2)
plitkinski.net
olandik.net (Confirmed Zeus 8/20)
instamfan.net (Confirmed Zeus 7/28)
tjkleen.net (Confirmed Zeus 8/9)
incornew.net (Confirmed Zeus 7/30)
autasienga.ru
jocudaidie.ru (Confirmed Zeus 7/15)
dahzunaeye.ru (Confirmed Zeus 6/23)
vohphozeeg.ru
eexiziedai.ru
railuhocal.ru (Confirmed Zeus 6/11)
blackfuril.ru
purplepron.ru (Confirmed Zeus 8/15)
cahgofoneu.ru (Confirmed Zeus 8/31)
iveeteepew.ru (Confirmed Zeus 6/23)
hazelpay.ru (Confirmed Zeus = 5/27)

We've got quite a few more details that we've already shared with law enforcement, but we wanted the public to be advised as well.

If you are a spam researcher and can tell me what botnet this is, please shoot me a note at 'gar at cis dot uab dot edu'. Here are some of the top sending IPs for this group:

72.16.178.42
81.180.66.34
187.36.133.238
186.82.57.113
186.112.107.35
77.127.135.151
195.135.239.5
76.97.210.124
195.228.164.14
24.36.173.168
93.32.50.228
211.17.116.17
24.80.8.180
190.48.237.121
212.29.192.202

Thursday, August 26, 2010

Major Fraud Ring Busted in Largest Chinese Cybercrime Operation

Yesterday Taiwanese Criminal Investigation Bureau Commissioner Lin Teh-hua announced the largest cybercrime operation in the history of his organization. (The Criminal Investigation Bureau's report, in Chinese, is here). 548 Taiwanese police officers and 2,720 Chinese police officers took part in the operation which resulted in 450 fraudsters being arrested throughout Taiwan and in the Chinese provinces of Fujian, Huanan, Hubei, Anhui, Guangdong and Guangxi. After a joint operations agreement was signed between Chinese and Taiwanese authorities, more than 16 joint raids have been conducted leading to more than 1,000 arrests.

In this case, the activity particularly focused on telephone fraud and internet auction fraud. The arrests come close on the heels of the break up of a similar fraud ring in Ho Chi Minh City where 99 fraudsters from Taiwan and China were arrested. In the Vietnamese fraud, where 76 Taiwanese and 23 Chinese citizens were arrested, fraudsters would take over entire hotels, booking as many as 30 to 40 hotel rooms for their fraud. They would place randome phone calls, posing as telecom officials, police officers, or prosecutors, and urge people to wire money to specified accounts. Some individuals lost millions of dollars in that fraud. The Ho Chi Minh case made note that on July 1st there had been a related raid where 32 Taiwanese and 14 Chinese were arrested. Major General Huynh Huu Chien of the Ministry of Public Security called it the largest foreign hacker ring ever in Vietnam, saying that they also had been doing ATM fraud, hacking into foreign banks and using ATM card readers to steal from more than 200 foreign bank accounts and financial institutions.

The Vietnam case continued on August 13th, when police arrested eleven Taiwanese men and two women in Can Tho. In that case, the police seized laptops, phones, walkie-talkies, and most intriguingly more than 50 "fraud scripts" that guided the fraudsters through the "play" of imitating a police officer or state agency official in order to further their fraud.

The Taiwanese-Chinese arrests this week seem to be more of the same, as police explain that the groups formed temporary "Telephone Fraud Centers" where the scammers placed calls following elaborate scripts that helped them to perpetrate their frauds. In Taiwan, in addition to the seizure of laptops, cell phones, and fraud manuals, fake courier uniforms were found.

This raid began to be built after a large meeting in China's Fujian Province where police from across China came together in Ningde to address illegal telecom operations, money laundering, impersonation of public agencies for fraud, and online shopping scams, but the case actually originated with the arrest of "Rong Yu" who was arrested back in April when police discovered he had been operating a fraud from the Taizhong Emperor Hotel, pretending to be a Shen Fuwen law clerk. By tracing the criminal contacts of this phony law clerk, more than seven other similar groups were identified, including the identification of the group's headquarters in Hunan Province.

The group was also found to be related to a fake online auction group - the Wuhan Pride network (www.dey100.com). This group, which claimed to be an online trading company, was involved in both the sale of goods that were never actually delivered, but also ATM fraud conducted after stealing banking information from the buyers of those fake goods! Some of the victims report getting very strange deliveries, such as ordering goods online and receiving an empty CD box or a package of soap instead of what they ordered. When they called to complain, this allowed the fraudsters to gather additional personal information about them that allowed further fraud to occur.

I hope more details of this fraud will be revealed in the next few days, but for now, I want to offer congratulations to the investigators who are helping to clean up online crime throughout China and Taiwan!

Saturday, August 21, 2010

"(Famous person) died" spam

According to my spam inbox, today was a horrible day to be a celebrity:

Alicia Keys died
Angelina Jolie died
Beyonce Knowles died
Bon Jovi died
Brad Pitt died
Cameron Diaz died
David Beckham died
Gwen Stefani died
J.K. Rowling died
Jay-Z died
Jennifer Aniston died
Jennifer Lopez died
Johnny Depp died
Justin Timberlake died
Kanye West died
Madonna died
Miley Cyrus died
Nicole Kidman died
Oprah Winfrey died
Ronaldinho died
Tiger Woods died
Tom Cruise died

In the UAB Spam Data Mine we received between 450 and 539 copies of each of these spam messages.

The body of the email has the same text for each, with only the name varying. The name used in the body of the email doesn't necessarily match the name in the subject line. Here's an example:


Cameron Diaz died along with 34 other people when the Air Force CT-43 "Bobcat" passenger plane carrying the group on a trip crashed into a mountainside while approaching the Dubrovnik airport in Croatia during heavy rain and poor visibility.

Please see attachment


The attachment is called "News.html" is "base64" encoded, but if you click on it, it will launch in a web browser.

The HTML is composed of javascript functions which takes substrings of pieces of code and composes them together to make a URL:


new String("hre3y9b".substr(0,3)+"hv5f5hv".substr(3,1))]=
new String("http:P5v".substr(0,5)+ "//panHSOY".substr(0,5)+
"3aPiplusP3a".substr(3,5) + ".com.V4Hq".substr(0,5)+
"mx/1.0Xq".substr(0,5) + "HFkhtmlFHk".substr(3,4))


So, the "hre3y9b" becomes "hre" the "hv5f5hv" becomes an "f" for "href" etc . . .

It eventually turns into:

hxxp://paniplus.com.mx/1.html

(the "xx" instead of "tt" is to prevent this from being live)

That page has two URLs on it, one pointing to the free domain website 'cz.cc':

cetogilco.cz.cc / scanner10 / ?afid=24

This page goes to a fake anti-virus site . . .

The second URL points to:

analyticspool.in / wiki / index.php ?sid=151 &search=ecard &refresh=on


From cetogilco.cz.cc the file "antivirus.exe" is downloaded.

A VirusTotal Report for this malware, showing 18 of 41 detects, is available. The MD5 is cb38da67e9a96afb0b3674eddee26472.

Monday, August 09, 2010

Viagra Spammers as Hackers?

This summary is not available. Please click here to view the post.

Friday, August 06, 2010

Spam Campaign: Zeus's Greatest Hits spreads malware

Yesterday I had the pleasure of speaking on the subject of phishing to the Association of Certified Fraud Examiners Alabama chapter conference, hosted at the UAB School of Business, where my friend Tommie Singleton teaches Forensic Accounting.

After talking about the traditional phishing, and the statistics that we have about phishing through our UAB Phishing Operations and UAB Phishing Intelligence teams, I shared with the group that while phishing is continuing to be on the rise, compromise of banking credentials through malware is an ever growing threat.

To demonstrate the problem with malware, I opened one of my spam receiving email accounts as a user and clicked on several email messages.

I clicked on an email from July 30th that warned me that "FDIC has officially named your bank failed bank", clicked the attachment, and demonstrated my anti-virus product (on this machine I was using Microsoft Forefront) successfully protected me from the malware.

Then I clicked on an email from July 31st that claimed to have details on "Your order from Amazon.com". Again, my AV popped on the attachment.

Then I clicked on an email from August 2nd with the subject "DHL Tracking number 080231". Pop! Virus!

Then I clicked on an email from August 3rd with the subject "Notice of Underreported Incomeir" - "yeah, Incomeir" not Income. Those guys at IRS apparently don't have a spell-checker. Pop! Virus!

Then I clicked on an email that was about four hours old - "You have received a file from (email) via YouSendIt." No warning. So we unpacked the zip file and sent it to VirusTotal. 11 of 42 detections. Note that at VirusTotal, Microsoft was described as being a product that detected the malware, but VirusTotal was running a slightly newer (by a few hours) version of the AV than my laptop. Symantec and Trend and several other "big players" weren't detecting yet, but I told my audience that really didn't mean one was better than another - it was more or less a shooting of the dice who would be the "first detector."

So, what's going on with all of these new malware attachments? I would describe it as a "Zeus's Greatest Hits" campaign. Some of the most successful "Zbot spreading" spam campaigns are all being re-issued, only as attached-malware spam instead of "sending to website" spam. I've linked previous blog posts about Zeus campaigns to some of the top spam subjects in the list below. If we just look at spam for this week in the UAB Spam Data Mine, we see things like:

515 copies - "An unauthorized transaction billed to your bank account"
16,606 copies - DHL Tracking number #######
353 copies - FDIC has officially named your bank failed bank
17,143 copies - Hello
553 copies - Notice of Underreported Incomeir
10,829 copies - report
2,089 copies - Review your annual Social Security statement
166 copies - SALE OF BUSINESS Document
6,256 copies - Scan from a Xerox WorkCentre Pro N #######
412 copies - Unauthorized ACH transaction
387 copies - Welcome to Friendster
10,852 copies - You have received a file from (email) via YouSendIt.
2,479 copies - You have received an Greeting eCard
1,224 copies - Your Flight Ticket #####
301 copies - Your internet access is going to get suspended
7,513 copies - Your Order with Amazon.com
4736 - YOUR SALE TO CAN PTY LIMITED

How do we know that these emails might be related to one another? The primary reason is how I selected the list that you see above. In the UAB Spam Data Mine, I picked one of the common subjects that are being used to spread this malware, and said "Show me all the email subjects sent from the same IP address as emails which sent me the subject 'You have received an Greeting eCard' and limit myself to only consider emails from August 2010."

All of the subjects in the list above were part of the response. Now, there were also hundreds of thousands of other emails - mostly selling Viagra and watches, but ALL of the subjects above were sent from computers that also sent at least one email with the "You have received an Greeting eCard" email.

What is the malware? If you are "into" MD5s, you can check them out yourself. In the emails above, the technique is to send an executable file within a ZIP file attached to the email. Here are the most popular '.zip' attachments so far in August:

11075 | 21c4690e291dfa09cc2eef89501fd9b9 | dhl_viewer (35)
10415 | 3e11b5374aaf019fc091d51be43bfdfc | yousendit_reader (23)
7403 | a170953b22815478083d4853f7ebfe57 | report (33)
6018 | 3a88a7fdeac36395bd6b1f6185b13b2c | report.document.doc (33)
5332 | 57eaeb400b49774533c45099877911f8 | dhl_viewer (33)
4738 | bae1fff9774a4366ef73247fcf6cb394 | 08-05-2010(10).pdf (30)
3234 | d0c9552a39d20576f50bbcdc692a187c | amazon_invoice_viewer (30)
3212 | 8f025c1c63e1d11d3a5444eaba978ce7 | xerox workcentrereader (31)
2509 | ccf81bcb37af7cc0835904ec2a49c6ce | report (33)
1617 | 347d3c44ba6c3f6501406e697170192c | statement (32)
1099 | d8fbbf60aafaf400f008b3b8f2b32a41 | transaction report (28)
736 | 02154aba2c9ad2e2bcbe80b7a31246f3 | ecard (34)
576 | 4fa198977d4d3a10a7282a71cb315955 | invoice_viewer (30)
563 | 5cbcc4e1a1f1c2c37149e8db953213b0 | statement (29)
421 | 58d62a8c7fc5a690d4ff18c752a20eb6 | doc (27)
409 | 1c4031ae6c0e327f86dc4201a3532468 | facebook_passw_31.07.2010 (21)
393 | 7ce7bdbc4ce52261ba2f8773d2c196e7 | statement (27)
371 | 02857e7260d3e73811093c8826efe37e | tax report (28)
367 | 802871fdc77c47ff398de9bae8548635 | invoice_viewer (32)
362 | d410ba8345407ab17f2f3b0c98b225d0 | invoice_viewer (26)
361 | 8f0e7810523e1f9d715f951150e9c845 | tax statement (29)
341 | 5eab651ded4b0f9f949beac0dda62146 | report (28)
275 | 0acdecd08273284ce26cd99a0beed1fe | tax statement (33)
202 | 83234d04953e4b8e3f5688ec62567fe1 | changelog_30.07.2010 (35)
198 | 9a02b55cb88acf80b840504d672c21da | resume (23)
179 | d747c2928f1205c69e459b308a35fe1e | transaction report (14)
177 | 8b357aca247a729e07f0ee935c578c81 | transaction report (33)
175 | d5083f3dfefe3d6a9dc3ccd9c2fd622f | changelog_30.07.2010 (26)
138 | 3100bc960f80e8b078c3f8dd6d53de7b | dhl_tracking_ (24)
76 | 5e5b596bdf2f39b1fdfeb23821c75f41 | dhl_viewer (2)
73 | 68b13b6ecbb24322c9fe183b064eef9d | financial summary.xls (27)
51 | 5667dba64be7749c23148b564303fd11 | invoice (11)
37 | 5f2515a06e45acf9e3429ed78447e6a7 | core business advice notice ccc[1].doc (12)
33 | bbc7b06a0f0e6b09b8b7b07f3dab3b6b | statement (7)
31 | 489e4d09253414a8884fcf70326c81b9 | 090508 ccc equipment inventory v4.xls (11)
30 | 477a292406bfbbc474c35efdc92462a6 | business report.doc (12)
30 | 5bd1fb667558da6945518c28d485a37d | tax report (31)
28 | aaead684fe45133c628d3388451b7b6e | invoice_viewer (29)

The ones with low counts are mostly going to be the very newest versions (or ones that were sent in July and ended early on August 1st).

Some detects are pretty good ... for instance, that final "invoice_viewer" was first seen on August 5th (yesterday) and currently as 29 of 42 detects at VirusTotal. However, the number of malware detections on VirusTotal - RIGHT NOW - is the number in Parentheses after the malware attachment name. See the 7? and the 11? Remember that these are WORST when the email is FRESH. Some of these are from August 1st.

What about RIGHT NOW?

I'm going to scan the next two email atttached zips that arrive and show you the detections of FRESH email-delivered malware.

Oh - since the three most recent ".zip" attached emails were in this category, I'll mention this here. Another current email-delivered .zip campaign is "Your private photo attached" and contains a zip named with a random word (My last one was "accosting.zip"). It had a zero of 42 detect as a zip file.

That's because it's not malware. Its the "randomly created image" showing that I should buy pills from "yes82.ru".



Here are some of the emails from the campaign above:








Wednesday, August 04, 2010

PhacePhish: New Facebook Attack gives a One-Two Punch

Tonight I had a message from one of my Facebook friends who was concerned that someone may have hacked her Facebook account. She was worried that she might get a virus by looking at the links they had posted on her behalf. I assured her not to worry -- if her Facebook account was sending links to other people's walls, she probably already had a virus. After digging a bit deeper, I'm not so sure.

The "One-Two" punch of this current Facebook attack is similar to some of the spamming malware. Some of the messages it sends are to generate profit for the cybercriminal, and some of the messages are to infect more users to build the criminal's delivery network.

Here is the first type of message -- the "profit" message:



This reminds me of a current "work at home mom" trend that some of my other friends are engaging in. There really is a weight loss multi-level marketing scheme right now where the participants are encouraged to make a website telling about "the plan" and then are told that making money is as easy as following the plan yourself, and posting your weight loss reports to all your Facebook friends. (Hope your happy and skinny, DG, I wouldn't know, I blocked you on facebook as soon as you started that crap!)

What happens if you follow the link? The link doesn't go to my friend's weight loss page. It goes to an Acai Berry affiliate sales "news" page that is supposed to look like a real "news" site that just happens to be featuring a story about the miracle of the Acai Berry.



Clicking anywhere on the "news" page takes you first to an affiliate tracker page:

tracker.cpaprosperity.net/affe?offer_id=500&aff_id=1161

and then to the sales page for their diet plan:

acaioptimum.com/?afil=az1007

The diet scam page is hosted by Black Rock Hosting on the IP address 64.38.201.205.

That was the "One" . . . here comes the "Two" of our One-Two Punch:



What's the other important purpose for Facebook besides getting your friends to join your Multi-Level Marketing Weightloss plan? Sending stupid videos to one another, right? Everyone knows that when one of your friends posts a link, you are required to immediately click on it, and the click the "Like" button. This is how people know that we are their friends. We "Like" all their stupid videos.

(Actually, I'm a big Facebook fan. My family communicates like crazy with it, and I enjoy sharing pictures with my friends and playing Bejeweled Blitz. But this is the part where I'm supposed to be all sarcastic...)

So, when my friend BG posted this message to all of her friends' walls, what would happen if they clicked on it?

The first thing is that it sends you to a website called "securitymeassures3.co.tv". That page is going to call some Javascript to find out what country you are in:



If you are in the US, you then load the webpage "explororjones.com/deel/deeus/"

If you are anywhere else in the world, you then load the webpage "explororjones.com/deel/deeint/"

Either way, the page that loads looks like this:



WAIT! How did I get logged out of Facebook? (you are supposed to say to yourself...) then you quickly type in your userid and password for Facebook on this other page, which is actually at "explororjones.com"

ExplororJones is hosted on that excellent Netherlands hosting company Worldstream. I don't recall Facebook moving their operations there. When a webpage that isn't really the company you are trying to log in to tries to convince you to login on the fake web page we call that phishing.

That's why I'm calling this particular attack "PhacePhish" - most phishing attacks start with a spam message that sends you a scary reason that you really need to log in to your bank RIGHT NOW. This one starts with a spammy Facebook message instead.

Sooo...does my friend have a virus?

No, its very very probable that my friend clicked on a "funny baby" or some other leading video on one of her friends' Facebook posts, believed she was logged out of Facebook, and logged back in, giving her password to the criminals. The criminals then can login as my friend and repost the message on all of their facebook pages. If they fall for it, then they'll tell their friends, and they'll tell their friends, and they'll tell their friends, and pretty soon we'll all be skinny and rich! Happy ending!

I'd call my friend and tell her all of this, but its 3:00 AM. I'll let her sleep a bit more while the criminals spread their message through her Facebook account. Wonder if the Facebook guys are awake . . . hmmmmmmmm....