Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 8 August 2008

Linking all the News Spam together (CNN.com Daily Top 10)

Posted on 02:00 by Unknown
One of my students has been studying the relationship between the various "news spam" malware pieces, and has found some interesting patterns linking the spam campaigns together by the proven relationship between the spam messages.

Tonight I decided to look at the relationships using the "open SQL query" interface to our UAB Spam Data Mine. The advanced data clustering algorithms do some incredible things, but tonight I just wanted to see what IP addresses had sent us spam email for the "CNN.com Daily Top 10" campaign, and then ask, "So what other spam do we have in the Data Mine that comes from those IP addresses?"

The query is actually very simple for this type of question:

=============================================================

select a.message_id, a.subject, a.sender_ip, b.machine, b.path
from spam a, spam_link b
where (a.message_id = b.message_id)
and a.sender_ip in
(select sender_ip from spam where
subject like '%CNN.com Daily Top 10%')
order by a.sender_ip, a.subject;

==============================================================

Which says, find all the IP addresses that sent us spam where the subject includes the string "CNN.com Daily Top 10". Then make us a list of all the messages sent by those same IP addresses, and show the subject, and URLs (machine + path) from those messages, ordered by IP address and then subject.

------

Observations:

We had emails in the CNN group from 4,875 unique IP addresses. Those IP addresses sent us a total of 11,809 emails.

10 emails in November
102 emails in December
51 emails in January
191 emails in February
162 emails in March
213 emails in April
363 emails in May
403 emails in June
2,892 emails in July
7,421 emails in August

Browsing the subjects, it was clear that most of the emails before very late June were an assortment of pills, watches, and enlargement promises. A clear "news trend" started at the very end of June.

Looking at only paths spammed by this group in July and August, these IP addresses spammed the following paths:

/1.html
/about.html
/begin.html
/checkit.html
/cnnlive.html
/cnnnews.html
/cnnonline.html
/cnntop.html
/cnnvideo.html
/default.html
/first.html
/fresh.html
/gowatch.html
/hotnews.html
/Images/.../video-nude-anjelia.avi.exe
(several variations of previous)
/index1.html
/index1.php
/index2.html
/livestreaming.html
/lol.html
/main.html
/msvideoc.exe
/news.html
/news/
/r.html
/redir.html
/showvideo.html
/start.html
/stream.html
/top.html
/tophot.html
/topnews.html
/video
/video.exe
/view.exe
/viewmovie.html
/watchit.html
/watchmovie.mpg.exe
/whatsup.html
(many crazy long paths all on "livefilestore.com")

So, EVERY MAJOR "news spam" campaign we received in July can also be found by looking at emails which came from the same IP addresses as the CNN.com Daily Top 10 emails. We wrote about several of these back in July, for example:

r.html ==> Nuwar Looks for News Readers - July 7

viewmovie.html == News Headlines Still Out of Control - July 22

topnews.html == Top News in Spam = Old News - July 26

I've placed the list of IP addresses used in this spam in a text file on my UAB website:

http://www.cis.uab.edu/forensics/CNN.iplist.txt

The list of all 2,255 URLs which were spammed in those emails is also available on my UAB website:

http://www.cis.uab.edu/forensics/CNN.urls.txt

If you have a similar list, I'd love to compare notes!

--------------

Gary Warner
Director of Research in Computer Forensics
The University of Alabama at Birmingham
gar@cis.uab.edu gar@askgar.com
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...
  • 70 Romanian Phishers & Fraudsters Arrested
    On March 4th, FBI Director Robert Mueller was given a speech on Cybercrime to the RSA conference where he mentioned that: And we have worke...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ▼  August (22)
      • Hurricane Gustav: Fraud Watch
      • Banking Digital Certificate Malware in Spam
      • E-cards Run Wild. Where are the Anti-Virus Compan...
      • Leave Those Viruses at SCHOOL!
      • Celebrity Spam-Off: Will Paris Hilton Overtake An...
      • Shadow Botnet case may yield spammer Leni Neto
      • More Online Pharmacy Affiliates Indicted
      • Evidence that Georgia DDOS attacks are "populist" ...
      • One third of current spam points to malware sites
      • New BBC spam mocks Georgia's President, Spreads Ne...
      • Can You Pick the Real MSNBC.Com Breaking News?
      • MSNBC Breaking News replaces CNN Spam Wave
      • Anti-Virus Products Still Fail on Fresh Viruses
      • iTunes Store Phish
      • The UAB Spam Data Mine: Looking at Malware Sites
      • TJX Update: The San Diego Indictments
      • TJX Update: The Boston Indictments
      • Linking all the News Spam together (CNN.com Daily ...
      • CNN Spam Diversifies . . .
      • TJX Reminder: "We Will Arrest You, and We Will Sen...
      • CNN Lends Authenticity to News Spam
      • Another Insider Busted: Countrywide Financial Analyst
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile