Monday, November 18, 2019

Facebook's Transparency Report: (Expert) Supervised Machine Learning Works!

Last summer the BBC technology program "Click" came to visit the lab for a special called "Can Technology Solve the Opioid Crisis?"  One of the points we stressed with @NickKwek was that when we report opiods and fentanyl-related posts to Facebook the objective is not to take down THAT POST, but rather to help Facebook's automated tools update their models of what offensive drug sales content looks like.

Last week we had an opportunity to see what that looks like in action as Facebook released their transparency report for Q3 2019.  Facebook's Transparency report is divided into two major sections which each have two subsections. "Enforcement of our Standards" covers "Community Standards Enforcement" and "Intellectual Property Infringement."  The other major section, "Legal Requests" is divided into "Government Requests for User Data" and "Content Restrictions Based on Local Law."

The November 2019 transparency report for Community Standards looks at ten categories of content on Facebook and four categories of content on Instagram.

In this post, we'll look primarily at the statistics for "Regulated Goods: Drugs and Firearms" but the other categories on Facebook are:

  • Adult Nudity and Sexual Activity
  • Bullying and Harassment
  • Child Nudity and Sexual Exploitation of Children
  • Fake Accounts
  • Hate Speech
  • Spam
  • Terrorist Propaganda
  • Violent and Graphic Content
  • Suicide and Self-injury
On Instagram, the other categories are:
  • Child Nudity and Sexual Exploitation of Children
  • Suicide and Self-injury
  • Terrorist Propaganda
Facebook has shared previously about our work to reduce terrorist content on their platform.  See their "Hard Questions" blog post -- "Are We Winning the War on Terrorism Online."  In this most recent report, they share that "Our proactive rate for detecting content related to al-Qaeda, ISIS and their affiliates remained above 99% in Q2 and Q3 2019, while our proactive rate for all terrorist organizations in Q2 and Q3 2019 is above 98%."

What does that mean?  It means that through the power of machine learning, when someone posts content trying to "express support or praise for groups, leaders, or individuals involved in terrorist activities" the content is removed automagically without the need for anyone to report it 98-99% of the time!

They've also previously discussed our relationship regarding the Opioid Crisis.  See their post "Supporting Our Community in the Face of the Opioid Epidemic." 

As Facebook has focused on identifying drug-related content, the number of detections has risen.  That's likely from two reasons -- one, they are now discovering content that previously would have remained unreported in the past; but also two, frustrated users are attempting to post their drug sales information in more ways trying to get past the blocks -- and largely failing to do so.

Drug related posts actioned:
  • 572,400 posts in Q4 2018
  • 841,200 posts in Q1 2019 
  • 2,600,000 posts in Q2 2019 
  • 4,400,000 posts in Q3 2019
When I attended Facebook's Faculty Summit all the way back in 2016  they had me hooked from the very beginning of the day when Facebook's Engineering Director Joaquin Quinonero Candela gave his opening keynote.  All of this amazing machine learning technology that people like Dr. Candela had created to help improve online ad delivery were ALSO being used to make the platform as safe as possible against a wide variety of threats. I was especially excited to learn about the work of Wendy Mu. At the time Wendy's bio said "Wendy is an engineering manager on Care Machine Learning, which leverages machine learning to remove abusive content from the site.  Over the last three years at Facebook, she has also worked on Site Integrity, Product Infrastructure, and Privacy."  Wendy and her team are inventing and patenting new ways of applying machine learning to this problem space.  Nektarios Leontiadis "a research scientist on the Threats Infrastructure Team" with a PhD in online crime modeling and prevention from Carnegie Mellon and Jen Weedon, previously at FireEye, were some of the other folks I met there that made such a profound impression on me!  Since then, the UAB Computer Forensics Research Lab has partnered with Facebook on many projects, but quite a few have taken the form of "what would a human expert label as offending content in this threat space?"

This is where "supervised machine learning" comes into play.  

The simplest version of Supervised Machine Learning is the "I am not a Robot" testing that Google uses to label the world.  You may be old enough to remember when Google perfected their Google Books project by asking us to human label all of the unreadable words that their scanner lifted from old books, but which were not properly recognized by their OCR algorithm.  Then we were asked to label the address numbers found on buildings and mailboxes and then later to choose cars, bicycles, traffic lights, and more recently cross walks as it seems we are not teaching future self-driving cars how to not drive over pedestrians.

This works well for "general knowledge" types of supervised learning.  Anyone over the age of three can fairly reliably tell the difference between a Cat and a Dog.  When people talk about supervised machine learning, that is the most common example, which comes from the concept of "Convolutional Neural Networks".  Do a search on "machine learning cat dog" and you'll find ten thousand example articles, such as this image from Booz Allen Hamilton.

Booz Allen Hamilton infographic 


We're working on something slightly different, in that the labeling requires more specialized knowledge than "Cat vs. not Cat".   Is this chemical formula a Fentanyl variant?  Is the person in this picture the leader of a terrorist organization?  What hashtags are opioid sellers using to communicate with one another once their 100 favorite search terms are being blocked by Facebook and Instagram?

Facebook Research has a nice set of videos that explain some of the basics of Machine Learning that are shared as part of the "Machine Learning Academy" series:

from: https://research.fb.com/videos/field-guide-to-machine-learning-lesson-1-problem-definition/
In this chart, the data provided by UAB is primarily part of that "Data Gathering" section ... by bringing forensic drug chemists into the lab, we're able to provide a more sophisticated set of "labelers" than the general public.  Part of our "Accuracy testing" then comes in on the other end.  After the model built from our data (and the data from other reporters) is put into play, does it become more difficult for our experts to find such content online?

Looking at the Transparency Report's Community Standards section, the results are looking really great!  


In the fourth quarter of 2018, only 78.6% of the offending drug content at Facebook was being removed by automation.  22% of it didn't get deleted until a user reported it, by clicking through the content reporting buttons.  By the 3rd Quarter of 2019, 97.6% of offending drug content was removed at Facebook by applying automation!

In Q4 2018, 122,493 pieces of drug content were "manually reported" while 449,906 pieces were "machine identified."

In Q3 2019, 105,600 pieces of drug content were "manually reported", but now about 4.3 million pieces were "machine identified."  

Terror Data

Twitter also produces a Transparency report and also shares information about content violations, but in most categories lags far behind Facebook on automation.  Twitter's latest transparency report says that "more than 50% of Tweets we take action on for abuse are now being surfaced using technology. This compares to just 20% a year ago."  The one category where they seem to be doing much better than that is terrorism.  Their last report covered the period January to June 2019.  Twitter does not share statistics about drug sales content, but does have Terrorism information.  During this period, 115,861 accounts were suspended for violations related to the promotion of terrorism.  87% of those accounts were identified through internal tools.  

Facebook doesn't share these numbers by unique accounts, but rather by the POSTS that have been actioned.  In the Q3 2019 data, Twitter actioned 5.2 million pieces of terror content.  98.5% of those posts were machine identified.





Tuesday, November 12, 2019

'Tis the Season for SCAMS!

A recent project that DarkTower worked on was related to fraudulent marketplaces offering too-good-to-be-true deals on electronics.  DarkTower's CEO Robin Pugh took those lessons and applied them to a recent online shopping experience ... I asked her to write it up for our blog:

As I was browsing some of my favorite Instagrammers this morning, one of them posted about a great coffee system that was on price rollback at Walmart.com for $99 – nearly half off the list price of $179.99.  As a coffee lover AND a bargain lover, I was immediately interested and began searching for more information.  Since I wasn’t familiar with how this particular coffee system worked, I typed the model name in my google search bar, intending to find some YouTube videos on how it worked, but since I left my search term fairly broad, some interesting sites popped up in my search results. 

https://julishopgame.com/index.php/ninja-coffee-bar-system-cf097.html
RED FLAG #1: Prices that are TOO good

WOW!  An even BIGGER BARGAIN… more than $10 less than the Walmart.com price?!  But on a site I’ve never heard of “Juli Shop,” so I began to take a closer look at the site, since we all know a) it’s hard to beat a Walmart price and b) if it’s too good to be true….  Well, you can finish that sentence.  (Other kitchen appliances on the site also had crazy discounts.  The "DeLonghi Dedica EC680 15 Bar Stainless Steel Slim Espresso" machine is only $160.99 at Juli Shop, but $299.99 at Bed Bath & Beyond and BestBuy, and $241 at WalMart.com.)


RED FLAG  #2:  Same Day delivery

Among the things I notice about Juli Shop, in the list of things they promote about their site is “Same Day Delivery.”  Really?  Same Day? So where are they located that they can promise same day delivery?

https://julishopgame.com/index.php/contacts/
They purport to be in Citronelle, Alabama, with a local phone number; so I looked up the address on Google Maps and found that it’s a lovely 2 BR/2 BA brick ranch home that’s not currently for sale. The phone number – brace yourself – is disconnected. But they’ll definitely get me my Ninja Coffee Bar System today.

RED FLAG #3: Spelling Errors
I also notice in the menu bar that they want to tell me “Abouts Us”. Other sections of the menu are labeled "INFOMATION" and "CUSTORMER." Well, spelling errors are often a hallmark of scam sites and phishing emails, so I click to learn more “Abouts” them.

https://julishopgame.com/index.php/about-us/
RED FLAG #4:  Information clearly copied from another site
Oddly, their About Us page has no mention of Juli Shop.  It is 100% about a fashion apparel company called Madison Island, and Juli Shop has no apparel merchandise at all.  Let’s check out Madison Island to see if it’s an affiliate, or maybe a parent company.

A quick search for Madison Island reveals that it is a fictitious demo store used to test Magento, a popular shopping cart processing plug-in, which Juli Shop uses to process its credit card transactions. By the way, Magento is targeted by one of the most prevalent malware families called Magecart.  Magecart is specifically to steal credit card credentials.  So let’s think of the possibilities here:  a scam site that takes your money and never delivers the promised item AND steals your credit card information at the same time.  That’s quite a criminal enterprise!

RED FLAG #5:  Sanity check
At this point, all signs point toward a scam site, and I’m pretty sure I’m going to be paying $10 more for my Ninja Coffee Bar; but before I move on, I check out scamadviser.com.
https://www.scamadviser.com/check-website/julishopgame.com/index.php/about-us
They give Juli Shop a 66% “TrustScore”, which puts it squarely in the “green” zone; but after reading the negative/positive comments, I’m not sure I agree.  First, the website was established 21 days ago.  The server is used by multiple websites, which isn’t uncommon for a small site, but they are offering items and services that are not typical of a small site.  Additionally, and quite concerning, the set up involves both the US and Vietnam.  A multi-country set-up is not common for a small site, and somehow Vietnam doesn’t jive with Citronelle, Alabama.

Further review of the scamadviser.com data shows conflicting information around the site’s infrastructure, but also shows that there are no comments or reviews on typical review sites like Sitejabber and Trustpilot. The absence of this information is quite telling.

Scamadviser may give this site a 66% trust rating.  I’m giving it a 100% SCAM rating.

As the Christmas cyber shopping season is upon us, before you shop at a new online store, take the time to thoroughly review the site.  As demonstrated above, a few key checks and paying attention to red flags can quickly reveal whether you should be entering your credit card information there, and whether it may leave Santa with an empty sack on Christmas eve.

Saturday, November 09, 2019

Business Email Compromise (#BEC) Email Forwarding In Action


DarkTower President Robin Pugh was chatting with a friend who is the VP of Operations for her family business.  She mentioned as an aside that their email had been hacked, and of course, Robin’s cybercrime-fighter ears perked up.  The friend went on to explain that one of her clients, a global, Fortune 500 company, had called her to confirm email instructions from the company to start making payments into a different bank account.  But, of course, those were not legitimate instructions.

The screenshot below shows part of an email thread between her customer and the criminal using the compromised account.  What you cannot tell due to the redactions is that a cybercriminal had control of an account at the company; he messaged all customers to change the remittance instructions.  Even when the customer responded by email to confirm that these were legitimate instructions, the criminal assured the customer that the instructions were correct. 




However, the customer noticed some spelling and grammar discrepancies in the response and finally called the vendor to confirm.  Once alerted to the email compromise, the VP immediately changed the password to secure the email account.  This is certainly a "Best Practice" when responding to a phishing incident.  

But having spent time listening to Gary and Heather talk so much about Business Email Compromise, Robin knew to advise her friend to check one more thing…forwarding rules in the email client.  

After navigating in the email client to the Rules section, the VP found that a rule had been created to forward any messages mentioning the words “wire instructions,” “wire transfer,” “fund transfer,” “payment,” or “invoice” to the address blessingsalways823 at gmail dot com.



"If the message includes specific words in the subject or body 'wire instructions' or 'wire transfer' or 'funds transfer' or 'payment' or 'invoice'; forward the message to blessingalways823 at gmail.com."


Even though Robin’s friend had already changed the email account password, the criminals were able to continue viewing and intercepting the email messages that were important to them.

The next steps were then to disable the rule, have I.T. check other users in the email domain for malicious forwarding rules, and then begin the process of notifying clients. 

A DarkTower investigation revealed that the Gmail account was used to register the domain name alpan.us on 9/13/18, for which the registration details reveal the name and address Anthony L. Ania, 34501 Southside Park Dr, Solon, OH, 44139, phone 813-856-5005, and fax 650-253-0000.  The domain has never had a website and was probably used to impersonate an executive of Alpan Lighting Products, a company in California that uses the domain name alpan.com.  The address in Ohio may belong to a Cleveland attorney who has suffered identity theft, but there are at least three Nigerian profiles on Facebook using the same name, and the Google account password recovery process reveals that a phone number ending in 05 is tied to the Gmail account.



The criminal’s Gmail account was also seen on two boat sales websites, sailboatlistings dot com and powerboatlistings dot com, in lists of suspicious email addresses.

Lessons Learned:
1) Simply changing the password did not secure the account. 
2) Never confirm suspicious emails by replying to the suspicious email.
3) Regularly check rules in email accounts of your domain.


Tuesday, November 05, 2019

A Phish That Scans For Viruses

While I was on the train today I was checking email and found that I had received an interesting phish.  It was sent to an email i haven't used in years that apparently still fowards:

I certainly didn't want to miss my "incomming" fax, so I of course needed to click the link to "Preview Fax Message." 

The phish started off going to "outlake-q.hopto[.]com" and passing my email address as a parameter in the URL.  I changed that up a bit as you'll see below.  The HopTo address claims it is "Connecting to OneDrive" but it's really forwarding to the rest of the phish.

"Leak-weave[.]gq" says "Please wait ..." while it continues connecting to OneDrive I guess. . . ?
Once it connects to OneDrive (which apparently is now hosted at leak-weave) it asks me to "Please hold a while" as "OneDrive Security is scanning your file for virus!" 


Great news!  No Virus detected on file!

"Scan Complete!  Your file is secure and safe for download. Office365 OneDrive."  So I guess I can Download the file, right?

Not so fast!  First we have to confirm the password for "ohno@pleasedonhackme.org" 

It takes the time to actually connect to the PleaseDonHackMe.org mail server and concludes that I have entered an "Invalid password"


No file for you!

Now, if a visitor actually believed there was a file, they may have been tempted to provide their REAL password at this time.  I don't know if that would result in a Download or not, but I've decided not to find out!

Hope you enjoyed today's Adventure in Phishing!  Tune in next time to see .  .  . well, we don't know what yet.





Friday, November 01, 2019

A Targeted (?) Phish from a LinkedIn Connection

This morning while I was on the Exercise Bike at the UAB Rec Center I got a LinkedIn message from a colleague I haven't spoken to in a couple years.


That was actually the SECOND funny thing about my LinkedIn profile this morning.  The first one was that, since I'm a Premium Member, I get notified when people check out my Profile there.  I had one unusual visitor:

å½­å®¶’s Profile
Peng Jia has a TOTALLY BLANK LinkedIn profile.   linkedin.com/in/å®¶-å½­-334485167

I sent John a text message on his phone, but followed up, knowing I was likely talking to a scammer, with a LinkedIn Reply:

Well, since it was "really" from John, I finished my 10 miles on the bike, showered, ran back to my office and fired up a VM to visit his link:



Gee, what was I worried about?  It's totally from John!  It says right there!

Of course, some might find it odd that the "View Message Folder" link takes me to the URL 
" eone [.] ga /mm/business/proposal/afzz "

Now this is where "Targeting" comes in ... Take a look at this Phishing website and try to think what industry might be targeted by this LinkedIn-propagated phishing campaign?  



Hmmmm... AstraZeneca,  Proctor & Gamble, Boston Scientific (who makes Medical Devices)  and GE (who has a GE HealthCare line that makes many medical devices), Nationwide Insurance (who offers Health insurance plans)?  Looks like they are targeting the HealthCare sector.  But Pandora? (Update: I'm told that Pandora is the name of a system from Omnicell.com that is used for doing data analytics to detect diverted pharmaceutical products.  I don't think this is their logo, but it is likely that the Pandora reference is to that.)

At first I was confused why a phish possibly targeting HealthCare would be coming after me, but then I realized ... I'M EMPLOYED BY UAB -- The University of Alabama at Birmingham -- one of the largest and best funded research hospitals in America!  Any chance that I'm getting LinkedIn spam because - to a casual observer - I'm a HOSPITAL employee?  And then having this tagged up with at least three health care logos?  Ok, so what happens next?

Well, then they steal your email and password ... 


Gmail was the only one that had a second page ... if you entered Gmail it then wanted your phone number too.


We grabbed the phishing kit, because that's what we do, and took a browse around.


All of the individual files have the same "Action" -- which is to call Finish . php


Finish is where the entered information gets mixed with environmental variables from your machine and all of the details get emailed to the criminal.

The last piece is that the email address is referred to by a variable name that isn't in this PHP file:

If you scroll back to the top of "Finish . PHP" you'll find what you need there:


The top line shows which additional files should be loaded by the phish.  "CONTROLS" is the one we want, which is where we find the criminal's email address:  madiba23101@gmail.com 


It would make a great example for my students if anyone in Law Enforcement cared about this ... but sadly, the only people who care are the LinkedIn Security Team, who had this account down so fast that by the time I responded with "So shall I call you Madiba?" my friend John's account had already been secured and gave me an error message.

A couple last funny notes ... the kit contains a file called "Netcraft_check.php" that checks to see if the user agent is "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)") and refuses to load the page if it is.  Might want to update that user agent, Netcraft hunters.

There is also a file "visitor_log.php" that gives away the fact that all of the visitors to this phish have their IP address, timestamp, and browser agent shared.   because of this, we can tell that a bunch of people visited the phish from LinkedIn, becasue it adds "Mobile/15E148 [LinkedInApp]" to the end of the browser agent string.  As of this writing, only 127 unique visitors have been to the phish.  41 of them were browsing the phish from within the LinkedIn application on a Mobile Device.



Unfortunately for the Phisher, the poor fool put his phishing site behind CloudFlare, so the referring IP addresses are NOT the victim's IP address, they are all CloudFlare IPs.  Oh well.  Nice Try, Mister Phisher.  (we'll shoot this to CloudFlare to terminate your hosting as well.)

Tuesday, October 29, 2019

Stories of Romance Scam Victims: Ronayerin Ogolor

Ronayerin Ogolor has pled guilty to causing $900,000 in losses to at least 13 Romance Scam victims.  Ogolor, a 50 year old naturalized citizen from Nigeria, lived in Kansas City, Missouri when he committed the various fraud schemes.  After "falling in love" via ChristianMingle, Facebook, or Hangout.com, Ogolor would begin to string his victims on to being lured out of their finances, whether or not they were wealthy.

Ogolor maintained multiple bank accounts.  Two US Bank accounts in his own name (ending in 8969 and 1885), a Wells Fargo account ending in 6281 in the name "Ronayerin Ogolor Merchandise", and a Wells Fargo account ending in 2141 in the name Ovrichona - a business involved in "overseas auto sales." A Bank of America account ending in 6776 in the name "American Quarter Horse Association eBanking", as well as BofA accounts ending in 4957 and 1988 in the name "Ogolor Merchandise." A Bank Midwest acount in the name "Rons Solutions" which he claimed was a Beauty Salon originally, but told a Bank Midwest employee bought American goods from cars to diapers and resold them in Nigeria.

He paid for his online dating sites via "AlcudaBill"

We thought it would be illustrative to share some of his schemes found in the Criminal Complaint.

Victim 1 - Alabama
Met "Charles Zolt" on ChristianMingle.com.  He was an "oil rig worker".  Zolt convinced Victim 1 to sell her car and wire him $9,500.

Victim 2 - Ohio
Met "Bradley Majestic" on ChristianMingle.com.  He was also an "oil rig worker" who claimed to be from Belgium. Victim 2 sent him over $30,000 in paymets starting with $3,500 in March 2015.

Victim 3 - Indiana
Met "Lawrence Garrison" after receiving a Facebook friend request.  Garrison also was an oil rig worker.  He claimed to have been born in Denmark. He sent a photo of a $4 million check, claiming he would pay her back when he got home by cashing that check.  He needed help getting funding to tow a $500,000 drill head to Ohio.  Victim 3 "invested" $450,000 overall in the scam.

Victim 4 - Washington
Met Ogolor in a variety of aliases.  Repeatedly tricked into wiring money to help meet fees associated with money transfers of up to $1 million USD.

Victim 5 - Minnesota
Met "David Stasiak" on Facebook.  Stasiak claimed to be a general contractor for Baytex Energy who worked on an oil rig.  She sent money to pay taxes on a large amount of gold that Stasiak was bringing into the country.  She "paid taxes" moving the gold through Qatar and Turkey, eventually being told that a final $32,000 had to be paid to a customs officer at Hartfield Airport in Atlanta to get the gold delivered.  She did not send the final payment, but was out several thousand dollars by this time.

Victim 6 - Arizona
Met "Samantha Brown" from Australia.  Claimed she had received a $250,000 inheritance.  She deposited the money into Victim 6's account and sent $60,000 to Haxzades Auto, LLC; $80,000 to Ronnie Leon Hammers; and $70,000 to Wells Fargo account 2141 (Ronayerin Ogolor dba Ovrichona Company.)  The $250,000 was the proceeds of a BEC scam.

Victim 7 - Texas
Met "James Philip" a US Army General in Afghanistan and agreed to help him smuggle two cases with $5 million in cash back to the USA.  Victim 7 sent three wires totaling $68,000 to pay various fees to help get these cases through customs.

Victim 8 - Florida
Met "Gary Ross Rodney" on Facebook.  Communicated via Skype and Email.  Claimed he had a UK bank account worth $500,000 to pay taxes to get the funds to the United States.  Victim 8 SOLD HER HOUSE to get Rodney the needed money, wiring $56,000 and $65,000 to Ogolor Merchandise's Bank of America account (4957).

Victim 9 - Illinois
Met "Manuel Rigby" on Facebook.  Rigby worked on an oil rig.  Claimed he had been detained in Atlanta, Georgia for traveling with too much cash.    Sent a total of $60,000 to get her boyfriend out of prison.

Victim 10 - Texas
met "Jonathan Lester" on either ChristianMingle or EHarmony.  Lester worked on an oil rig!  (Are  you surprised?)  Lester claimed to be from France.  He was importing a box with $2.75 million in cash, but needed to pay some fees to get it through Customs.  Via Hangouts, Victim 10 was instructed to send a $24,500 cashier's check to Ogolor Merchandise's BofA account 4957.  Altogether, she sent "Lester" $126,400.

Victim 11 - Florida
Met "Linda Stout" on Hangout.com.  Ogolor Sent him a $6,500 check and asked him to keep $1500 and send the other $5,000 to the Ogolor Merchandise BofA account.  (The check was fraudulent.)

Victim 12 - Italy
Met "Alexander McFelix" on Facebook.  McFelix was a U.S. Soldier serving in Afghanistan.  Wired money to help McFelix pay fees to retire early.  Over $13,600 in three payments to three different bank accounts controlled by Ogolor.

Victim 13 - California
Met "Robert Williams" on Facebook.  Williams worked for an oil company in Saudi Arabia, 'so his salary was paid in cash.'  Now needed help paying fees to bring his box of $2.6 million in cash through U.S. Customs.  Victim 13 sent more than $345,000 to pay various fees to import the money -- all to accounts controlled by Ogolor and associates, including a Citibank account in the name of Owurachanel LLC, an account in the name BJs Global Sales, and an account in the name Vinpep Services, LLC, and an account in the name TLA Technology & Consulting LLC.

For the dramatic conclusion ...

On October 19, 2018, the FBI learned that Ogolor had purchased a plane ticket to Frankfurt, Germany. He was arrested in the Kansas City International airport as he waited to board his plane.

Ogolor pled guilty on October 23, 2019, and signed a statement agreeing that he understood he may get 20 years in prison, a $250,000 fine, three years supervised release, an order to pay restitution to his victims, and possible deportation from the country after release.






Wednesday, October 16, 2019

"Welcome to Video" raid leads to 337 arrests due to Bitcoin Exchanges that use strong KYC

The darkweb child sexual exploitation video site, "Welcome to Video", first came onto Law Enforcement's attention as a result of a case in the UK, where a geophysicist Matthew Falder was arrested.  When the National Crime Agency was looking into his hard drive, they found he had been a member of "Welcome to Video" which at the time used the dark web address mt3plrzdiyqf6jim .onion.  Anyone visiting that website recently would have seen this banner instead:


Law enforcement actually got the website through a silly webmaster error.  One of the webpages on the website linked some of its component files by the server's IP address instead of its onion URL address.  The IP address, 121.185.153.45, was a Korea Telecom address.  They got the owner's address details and were able to confirm his identity.

After establishing undercover addresses, searches on the website for some common child sexual exploitation searches, and received indications that there were THOUSANDS of matching videos.  I don't know that we should share the terms with our readers, but some search terms resulted in more than 7,000 or even 10,000 matching videos.  Searches for videos involving children as young as four years old or even two years old yielded 4,000 matching videos each.

 Anyone could view "thumbnails" on the site, but to download or view the related videos, you had to have Points.  You could buy points for bitcoin, or you could "earn" points by uploading a unique video, or having a friend sign up and use your referral code.

 On multiple occasions, including September 28, 2017 and February 23, 2018, federal agents made payments on the website, and within 48 hours, the money had been moved to another Bitcoin wallet.  That wallet turned out to be a Coinbase wallet.  When they asked Coinbase who paid for that Bitcoin account, it was Jong Woo Son. To be able to buy Coinbase from a bank account, Jong was required to provide KYC (Know Your Customer) information, so he provided and confirmed an email address and telephone number, both of which were found to belong to Jong.

That gave law enforcement enough to raid Jong's residence, where they found the server in his bedroom, containing 8 TB of child sexual exploitation images, and log files indicating that MORE THAN A MILLION videos had been downloaded from the site.  The raid was conducted by US IRS-CI, US HSI, UK NCA, and the South Korean National Police.  By comparing the hashes of these videos to the collection at NCMEC (The National Center for Missing and Exploited Children), they found that 45% of these videos had never been seen before.

MANY of the users of the site were "creating" videos by abusing children they had access to. The United States has indicted Jong Woo Son, but he is already serving time for charges brought in South Korea.  The indictment does provide a great deal of information about the case that helps us understand what happened:


(from the Jong Woo Son indictment)
We know from other sources that the "exchanger in the United States" is Coinbase (see below).  Every time Welcome To Video presented an opportunity for payment to a visitor, it generated a new potential Bitcoin wallet address.  Until someone makes a payment, however, it is more like a "potential" wallet.  If the visitor wasn't sure how to get Bitcoin, Jong's website recommended that an easy way was to set up a Coinbase account!
By tracing other addresses that also moved small payments to the same wallet that the undercover payments were moved to, they were able to identify a "cluster" of 221 frequently used bitcoin addresses that had been used to receive payments that were then sent to the website owner, Jong Woo Son.  Later, they asked Coinbase, and two other major Bitcoin Exchanges, to identify accounts that had sent payments to any of that pool of 221 bitcoin addresses.  Why so many?  To make sure which payment belongs to which user, when a user indicates they are about to make a payment, they are assigned a bitcoin address to use for their transaction.  This is fairly common practice on darkweb markets. To avoid conflicts, Jong had many such addresses that would receive the payment from a specific user, probably created at transaction time. Jong would consolidate these bitcoin "wallets" by moving the funds to his primary account, from which he sometimes withdrew funds directly to his bank account. Because transacting against a bitcoin address creates new addresses, those at least 7,300 small payments were paid to different addresses controlled by Jong over time.
This was really spelled out in detail as the prosecutor, and then the FBI agent, tried to explain bitcoin to the judge in the Gratowski case.   That was the Texas case involving former HSI Agent Richard Nikolai Gratowski.  Same thing.  He used his own USAA Credit card to pay Coinbase to buy his bitcoin.  I have the 100 page transcript of his court hearing, which was fascinating to read.  He was sentenced to 70 months (and has already appealed to the 5th circuit.)  Most of the court documents referred to "Bitcoin Exchange 1" -- but the transcript names Coinbase 84 times!  I think they deserve a lot of the credit for making this case possible through their strict KYC implementation!


Subpoenas asking for "who has been sending money to these 221 bitcoin wallets?" is where they got their hitlist of 337 site users who were arrested.  They including pedophiles residing in Alabama, Arkansas, California, Connecticut, Florida, Georgia, Kansas, Louisiana, Maryland, Massachusetts, Nebraska, New Jersey, New York, North Carolina, Ohio, Oregon, Pennsylvania, Rhode Island, South Carolina, Texas, Utah, Virginia, Washington State and Washington, D.C. as well as the United Kingdom, South Korea, Germany, Saudi Arabia, the United Arab Emirates, the Czech Republic, Canada, Ireland, Spain, Brazil and Australia.  MOST of those users were identified because of the strict "Know Your Customer" rules that reputable bitcoin exchanges are now requiring of their customers. 

As a result of all of the investigations so far, at least 23 underage children were rescued in the US, UK, and Spain!

In ALL of the US cases I pulled court records for, that was the process.  Find a username on the seized server, prove that they had transacted bitcoin from a KYC-friendly exchange, such as Coinbase, then subpoena the bitcoin exchange to see who owned the account.  Coinbase and other reputable Bitcoin Exchanges, requires "strong Know Your Customer" as a means of reducing fraudulent or criminal behavior.  For Coinbase, that includes a drivers license scan, and a response to both an email and an SMS message to confirm that they know your real email and real telephone number.  For the accounts found, they could then check the Korean server to see which user had made a payment at that time and date, and how much activity they had on the server.  Then law enforcement would either confront the pedophile or conduct a search warrant to get confirmation of the evidence from the customer.  Priority was placed on anyone who seemed to be CREATING the content, or who had previous related charges.

Michael Ezeagbor was found to have used the identity "mikeexp1" on the site.  He had earned points by uploading 10 videos, and had downloaded 42 videos.  He paid 0.1 BTC on Jan 29, 2016 (which at the time was only $38.)  The Bitcoin exchange he used provided his DOB, SSN, address, and a Yahoo email account.  He had bought the bitcoin on the exchange using his A+ FCU account.

Eric Wagner paid 0.06 BTC on November 5, 2016 (about $43 at the time).  He had downloaded 40 videos and uploaded 84 videos.  His bitcoin exchange revealed his email was "wagnered@comcast.net" and he was using a DFCU debit card which matched the name, address, and SSN on file with the bitcoin exchange.

Brian James LaPrath was identified in the same way.  Because he had NOT uploaded, choosing just to pay, and had downloaded very little, he was allowed to plea to money laundering, although he is doing probation with sex offender style limitations in place.


The most troubling case I reviewed was that of Nicholas Stengel who had PREVIOUSLY been arrested for possession of child pornography and had served 41 months, followed by 36 months supervised release.  His supervised release included all of the above, and more.  He relapsed during that time, refusing to take his court ordered polygraph, and was charged with using a computer in violation of his parole to seek child pornography and with public masturbation.  In his first case he was charged with possessing 79,335 images and 230 videos.  When an HSI Cybercrime Special Agent hit his door with a warrant, Stengel's wife stalled the agents at the door while Stengel got into his bathtub with a knife and slit his own wrists and throat!  He was given emergency medical care, but now found to possess 805,457 images and 6,884 videos!
Stengel attempts suicide during his search warrant

Several others who were charged with PRODUCING child sexual exploitation imagery to upload to the site were listed in The Daily Mail's story on the case:

Paul Casey Whipple, 35, of Hondo, Texas, a U.S. Border Patrol Agent, was arrested in the Western District of Texas, on charges of sexual exploitation of children/minors, production, distribution, and possession of child pornography. Whipple remains in custody awaiting trial in San Antonio

Michael Lawson, 36, of Midland, Georgia, was arrested in the Middle District of Georgia on charges of attempted sexual exploitation of children and possession of child pornography. He was sentenced to serve 121 months in prison followed by 10 years of supervised release following his plea to a superseding information charging him with one count of receipt of child pornography

Nader Hamdi Ahmed, 29 of Jersey City, New Jersey, was arrested in the District of New Jersey, for sexual exploitation or other abuse of children. Ahmed pleaded guilty to an information charging him with one count of distribution of child pornography. He is scheduled to be sentenced Oct. 1, 2019

Jeffrey Lee Harris, 32, of Pickens, South Carolina, pleaded guilty in the District of South Carolina for producing, distributing, and possessing child pornography

Nikolas Bennion Bradshaw, 24, of Bountiful, Utah, was arrested in the State of Utah, and charged with five counts of sexual exploitation of a minor, and was sentenced to time served with 91 days in jail followed by probation;