Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 17 July 2008

Russian Cybercrooks, CoreFlood, and the Amazing Joe Stewart

Posted on 02:39 by Unknown
If the Anti-Virus world was run like the Chess world, we would all know Joe Stewart from SecureWorks as an International GrandMaster of Malware Analysis. One of the advantages of being an International GrandMaster of Malware Analysis is that you get to shine spotlights on really bad stuff -- and people listen! I'm talking about Stewart's excellent article in yesterday's USA Today on the Coreflood Gang. Before I returned home to find a copy of the article clipped and laying by my recliner by my dutiful paper-reading mother-in-law, I had several queries about "the Coreflood Gang", and I didn't know they even existed. Coreflood was a word from distant memory, dealing with pre-Windows XP machines for me. In fact the first searches I did took me to articles such as this 2003 Redmondmag article where Chris Belthoff from Sophos explains how the virus works. With a little digging we are able to see that the Coreflood Gang is Stewart's name for the group who is applying this virus from "ancient history" in Internet years to
a new purpose and with a much higher payback. Other common names for the virus were Corefloo and AFCore.

The article, which seems a rehash of the Robert McMillan IDG article, (here from InfoWOrld): Trojan lurks, waiting to steal admin passwords, from July 2nd, is a much-needed escalation from the technical press to the general public. Unfortunately it rings an alarm bell without giving any of the necessary details to know what to do about the possibility of your own machines being infected.

It lays out a situation where Stewart was able to come into possession of a cache of data which was harvested by the trojan he has dubbed Coreflood. The server contained MORE THAN 500 GIGABYTES of stolen data in compressed form, showing evidence of 378,758 unique Coreflood infections inside thousands of organizations.

The chart that accompanies the article discusses single organizations, including hospitals, hotel chains, universities, and school districts, which had many hundreds of infections located at a single organization. The worst example was a school district where more than 31,000 computers had been infected with this trojan.

As the PC World article made clear, the reason this type of infection is possible is because of a program called "PsExec", which is a SysInternals program currently distributed by Microsoft. The purpose of PsExec is to allow a Windows Domain Administrator to perform remote administrative tasks on machines throughout their network. The thing which has made the CoreFlood trojan, first disclosed in 2001, suddenly newsworthy is its use of this tool. As Stewart explains in his Technical Analysis of Coreflood/AFCore, infected hosts lie in wait on their networks, waiting for a Domain Level Administrator to log in to the box. When the trojan detects that it has Domain Administrator privileges, it then uses its copy of PsExec to perform a remote installation on all of the other hosts where that Domain Administrator account has control. A single infected computer can then become an entire network of infected computers in a matter of minutes!

Once infected, the computer becomes part of a very professional and elaborate botnet control system, which uses an SQL Database to sift, sort, and manage all of the data which it has stolen from keyloggers and files on its infected machines. In this way the controllers of Coreflood can make simple queries to their central database of stolen data such as, "Show me a bank account on Bank XYZ, where the balance is greater than $100,000!"

As I'm sure interest will be high in this virus after the story, I thought I would give some more hints on finding the AV program articles about it. (Since googling on CoreFlood will give you 2,000 blog articles on Joe's article!)

McAfee has been following malware called CoreFlood since at least October of 2001. As recently as July 3, 2008 they mention Coreflood and the fact that a tool called JailBreak is often installed on the same computer, which is used to export items from the Windows Certificate Store. The file "sstore2K.exe" should be searched for if you are looking for recent CoreFlood infections. Their main article, which they call "CoreFlood.dr" was "recently updated to Low-Profile due to media attention", they say, referring to a PCWorld article from July 2nd on the trojan.


Symantec, like McAfee until last week, has considered Coreflood to be a "Risk Level 1: Very Low" according to their Main Coreflood article. They rate its number of infections as being "More than 1000" at a number of sites "More than 10", in the article which was posted in 2002, with updates as recently as June 20, 2008. They describe the trojan as being "primarily designed to conduct Denial of Service (DoS) attacks", which was certainly what everyone believed until Stewart's revelation.

Symantec also has a detection for webpages that try to infect visitors with Coreflood, which has been the main path of infection since at least 2003, when the exploit described in Microsoft Security Bulleting MS03-032 were used to do "drive-by" attacks on webpage visitors.

A search at Sophos finds A 2003 article on CoreFloo-C, where it describes the earlier IRC-controlled trojan, as well as a 2004 article on CoreFloo-D. They make it all the way through the alphabet several times with this one, with Afcore AJ being in August 2004. The current version seems to be named "CoreFlo", such as Troj/CoreFlo-P in January 2007, which they alias as "Backdoor.Win32.Afcore.cm", and CoreFlood.dll, and Backdoor.Coreflood.

Speaking of through the alphabet, F-Secure has enough version of "Backdoor.Win32.Afcore" that they were on version "di", according to their July 13th version of their anti-virus signatures. Here's a description from Version Q, in 2003, which seems to be the last time this virus deserved its own article.

Good luck, Virus Hunters! I hope this article will help you move from "concerned" to "informed"!


_-_
gar
Read More
Posted in | No comments

Wednesday, 16 July 2008

22 More Romanians meet The Long Arm of the Law

Posted on 08:51 by Unknown
How Long is the Long Arm of the Law? Its at least long enough to reach from eBay headquarters to Romania. In another example of the successful international cooperation between the FBI and Romanian Cyber officials, 22 more Romanians have been arrested for Internet Fraud Crimes.

The first English language story that I've seen was on Romanian Authorities Arrest 24 Suspects in Internet Frauds.

A Romanian story with today's date has more details, for those who speak Romanian:

Romanian story here: În afacerea Malware, 21 de persoane arestate
. The Romanian story mentions that some of the electronic commerce sites targeted by the group included e-Bay, Equine.com, and Craigslist.com. Along with computer equipment and equipment to make false identities, the police seized mobile phones, SIM cards, and funds in Lei (romanian money), Euros, British Pounds, and US Dollars.

The arrests were made in the Romanian cities of Bucharest, Ramnicu Valcea, Sibiu, Alexandria, Dragasani, and Hundeoara. The leader of the group, Romeo Chiţă, was arrested in an apartment home belonging to a Romanian elected official, Dumitru Puzdrea. Puzdrea denied knowing anything about Chiţă's illegal activities.

One news crew was on site to see some of the hackers arrested. Here's a video taken in Râmnicu Vâlcea from yesterday afternoon. Watch to the end to see hackers in handcuffs. The accompanying Romanian News Story is getting commented on heavily - 57 comments already by this posting. Very educational. It seems the "F" word is the same in English as it is in Romanian.

Three un-named Romanian Hackers from Ramnicu Valcea:









I'll post more information as it becomes available, but congratulations to the FBI, and to the Brigada Specială de Intervenţie a Jandarmeriei, and DIICOT (Romanian organized crime and anti-terrorism squad)
Read More
Posted in | No comments

Monday, 7 July 2008

Nuwar Looks for News Readers?

Posted on 14:56 by Unknown
What news headlines would make you click an email link, even though you KNOW you aren't supposed to do that? The authors of the newest round of Nuwar, which may or may not be the same "storm" worm that we've seen two rounds of already this month, think they know.

Based on a review of this afternoon's "infect you through news headlines", the virus authors believe you want to know about Obama, McCain, Angelina Jolie, and the new Batman movie.

The spam for malware-infection "PornTube" sites is really out of control lately.

The current trend is to hack into someone's site, leave an "r.html" file there, and then send spam with totally unrelated subjects which, when clicked on, will open very offensive porn images and also try to infect the visitor by sending them to a secret website through an "iFrame". (The iFrame redirection site, digitaltreath.info, is now down and will hopefully stay down, after nearly a month of hosting badness.)

The malware which is present on each site is a file called "video.exe", which at least several AV products (AVG, McAfee, Microsoft, Trend) are calling "Nuwar", aka Storm.

Symantec calls it "Trojan.Erotpics", while several others call it "Exchanger" (AhnLab, BitDefender, ClamAV, Fortinet, VBA).

eSafe, F-Prot, Panda haven't weighed in yet -- VirusTotal shows 22 of 33 detections right now.

The template seems to be, pick a random subject, pick a random body line, pick a random website, with the choices I've seen today including:

Subjects
===========

  • Actors required Sign up now
  • Angelina jolie shock pregnancy discovery
  • Angelina Jolie suffers miscarriage
  • Apple files for bankruptcy
  • Are you getting enough
  • Beyonce breaks up with Jay Z
  • Blast in Pakistan
  • Brad Pitt confesses to betrayal
  • China fires missle in Taiwan's direction
  • Christopher Nolan's Knight vision
  • Clinton withdraws support for Obama
  • Eminem found dead in disco toilet
  • Fantastic year for spanish athletes
  • Federer crashes out
  • Fight for your benefits and rights
  • Heath Ledger never saw the Dark Knight
  • Hurricane hits Caribbean islands
  • India plans attack on terrorists
  • Join our talent hunt contest
  • Latest gossips on celebrities
  • Madonna admits to extra marital affair
  • McCain suffers heart attack
  • McCain withdraws from presidential race
  • McCaine vows to remain celibate
  • Memorabilia for heroes only
  • Miley cyrus naked photos expose
  • Obtain your degree in six months
  • Oil falls below $100 a barrel
  • Party scenes with American idols
  • Retire a millionaire
  • Search for singing talents
  • Spielberg found dead in freak accident
  • Take a look only if you are worth it
  • The Mummy 3 movie bankrupt, release delayed


Bodies
===========

  • A-rod admits to previous secret gay fetish
  • Asian girls mass Org partying
  • Barack Obama has been exposed to lack patriotism and shows loss of support from the masses
  • Can you take on two hot girls
  • Check out your popularity polls among colleagues
  • Elton John’s new lover
  • European girls group Org scenes
  • FBI surveillance team reveals trade secrets
  • French hospital in the south of France has admitted Hollywood actress Angelina Jolie
  • Fully online Master's degrees available at accessible prices
  • Gays in U.S military
  • Gun ban threatens to destroy obama's campaign
  • J Lo secret marriage threatens to destroy current marriage
  • John McCain gathers support from lackeys in Iraq and Afghanistan towards his election campaign
  • Kobe Bryant traded to Toronto in latest blockbuster trade
  • Late and great Ledger in running for posthumous Oscar award
  • Lindsay lohan drugged out at own birthday party
  • Madonna split finalized, Guy Ritchie in tears
  • ndia vows to find the masterminds behind the suicide attack that have killed entire embassy staff in Afghanistan
  • Obama belittles McCain's ability to be a presidential candidate contender at his age
  • Obama openly supports abortion and gay rights in bid to win more support from the masses
  • Oprah Winfrey announces wedding plans
  • Paris Hilton in new naked pictures romp at 4th of july party
  • Places to go for secret rendezvous
  • Pregnant Angelina Jolie asked the media to leave her alone while she waits to give birth to twins
  • President Bush latest political guffaw
  • Rating of stolen car for 2007
  • Republican John McCain admits he has no ideas how to jump start the economy and that the Democrat's stimulus plan is the way to go
  • Senator McCain found unconscious in toilet
  • Start your own business and make more money
  • The sky is the limit for Christian Bale as he returns for a second attempt at taming Gotham City
  • This week top travel destination
  • Videos of your neighbors making things
  • Videos on sports celebs and their flings
  • Wesley Clark snubs McCain's service as forgettable in July 4 tribute to the nation
  • Your colleagues are earning more than you



Websites
===========
PLEASE DO NOT VISIT THESE LINKS! THEY *WILL* ATTEMPT TO INFECT YOUR COMPUTER!!!!
Note, all of these sites may contain legitimate business on other pages, but these "r.html" pages have been placed on these domains by a hacker. We aren't saying these sites are guilty of anything other than having bad security.

http://209.222.133.85/r.html
http://50percentoff.nl/r.html
http://adlerautomobile.bg/r.html
http://avellanas.org/r.html
http://balcondelrio.com/r.html
http://boeckinggmbh.de/r.html
http://bursabil-net.com/r.html
http://www.cochesdeimportacion.formulacoches.com/r.html
http://chromet.com/r.html
http://www.dicon.eu/r.html
http://dysank.pl/r.html
http://ethereal-hell.telefragged.com/r.html
http://fabricadsonhos.com/r.html
http://fazemos.com.br/r.html
http://www.govdeli.com/r.html
http://houtkoning.nl/r.html
http://i-manager.it/r.html
http://iconn.pl/r.html
http://livresedotabaco.com/r.html
http://lpplegnica.pl/r.html
http://mediahits.de/r.html
http://phoenixadministration.com/r.html
http://pikous.fr/r.html
http://point1.angies-cafe.de/r.html
http://www.rundegg.com/r.html
http://s229782982.mialojamiento.es/r.html
http://savons-de-provence.com/r.html
http://superhostsite.com/r.html
http://testing.vuenosairez.com/r.html
http://www.trivium.hu/r.html
http://www.rundegg.com/r.html
http://zonamediabus.net/r.html


There seem to be at least two "active" sets of templates (so, you would never see "Angelina Jolie" subjects with the "Kobe Bryant" body, because they are in different template sets, as an example.)

So, news readers, beware . . .
Read More
Posted in | No comments

Thursday, 3 July 2008

Storm Worm Salutes Our Nation on the 4th!

Posted on 15:29 by Unknown
I had just left for my holiday weekend when one of our UAB Computer & Information Sciences students
called to let me know he thought he had a new Storm version on his hands.

He had received an email wishing him a happy Fourth of July, followed by an IP address, which he recognized as a traditional Storm-style email.

I ran a quick check in the UAB Spam Data Mine, and here is what we had so far (the oldest of these is around 90 minutes ago, so we'll have a fuller picture tomorrow I'm sure.)

Subjects
=================
Amazing firework 2008
America the Beautiful
American Independence Day
Bright and joyful Fourth of July
Celebrate Independence
Celebrating Fourth of July
Celebrating the Glory of our Nation
Celebrating the spirit of our Country
Celebrations have already begun
Fabulous Independence Day firework
God bless America
Happy Birthday, America!
Happy Independence Day
Happy Independence Day!!
Independence Day firework broke all records *
Spectacular fireworks show
Stars and Strips forever
The best of 4th of July Salute
Time for Fireworks
Wish your friends a happy Independence Day


Bodies
=================
Amazing Independence Day show
America the Beautiful
Celebrating the Glory of our Nation
God bless America
Sparkling Celebration of Independence Day
Stars and Strips forever
Super 4th!
The best firework you've ever seen

IP Addresses
=================
4.248.91.239
12.173.3.17
24.13.166.252
24.130.139.182
24.249.135.214
24.33.244.139
24.99.230.65
64.252.164.229
65.185.105.8
65.185.32.14
67.176.18.50
67.185.246.151
67.191.111.202
67.36.178.103
67.38.31.104
68.179.134.99
68.62.190.121
69.0.75.77
69.141.230.19
69.225.5.209
216.137.135.74
216.255.59.26




The website, which seems to invite visitors to play a fireworks video,
actually downloads the Storm malware in the form
of an executable called "fireworks.exe".



Detection is fairly good already, with 16 of 28 AV engines detecting at
VirusTotal.com, with each calling it the various well known names for Storm:

Dorf:
Sophos = "Troj/Dorf-BP"

Nuwar:
AVG = I-Worm/Nuwar.U
McAfee = W32/Nuwar@MM
Microsoft = Backdoor:Win32/Nuwar.gen!D
NOD32v2 = Win32/Nuwar.DC

Peacomm:
Symantec = Trojan.Peacomm.D

Peed:
BitDefender = Trojan.Peed.JLV

Tibs:
VirusBuster = Trojan.Tibs.AMZ

Zhelatin:
AntiVir = WORM/Zhelatin.Gen
GData = Email-Worm.Win32.Zhelatin.add
Kaspersky = Email-Worm.Win32.Zhelatin.add
Webwasher = Worm.Zhelatin.Gen


Because this is a holiday weekend, there may be quite a few people who don't get blocking in place right away.

Best of luck to you all, and to those who are fortunate enough to live in the United States of America, Happy Independence Day!
Read More
Posted in | No comments

Wednesday, 2 July 2008

7-11 ATM Hackers (?) - More details

Posted on 04:42 by Unknown
More details are now available about a trio of hackers who were indicted back in March on charges of stealing more than $5M from customers of ATMs. In a July 1st USA Today story few facts were revealed, but it was enough to spin the story back up in the media. I'm getting enough questions about it, I thought I would try to summarize what we know.

Kevin Poulsen had many details, including an affidavit by FBI cyber-crime agent Albert Murray and an affidavit by Ari Baranoff, a US Secret Service Electronic Crimes Task Force agent working in the Eastern District of New York, in his June 28th WIRED Blog.


Baranoff deposed Olena Rakushchynets, the wife of the primary suspect, Yuriy Rakushchynets, who was arrested February 28, 2008 in their Brooklyn residence.

The search warrant against their residence had revealed that Yuriy participated in several Internet carding forums, and had purchased information used to encode blank ATM cards, which he then used to withdraw cash from ATMs. In February 2008 alone, he withdrew approximately $750,000, and on September 30, 2007 and October 1, 2007, he took out $100,000 in the 48 hour period. They also found $800,000 in cash ($690,000 in bags in their bedroom closet), a $34,000 Mercedes, and, from the pocketbook of Olena, 51 $20 bills in sequential order. Olena also had $99,000 in three separate safe deposit boxes, and had made more than $50,000 in deposits to the Ukranian National Federal Credit Union. (See WIRED's copy of the affadavit.

Yuriy, elsewhere called "Ryabinin", a 32-year-old Ukranian immigrant, Ivan Biltse, elsewhere called "Belyayev", 30, and Angelina Kitaeva, were all named in the indictment which covered activities from October 2007 to March 4, 2008. They were charged with "Conspiracy to Commit Access Device Fraud", and that they

unlawfully, willfully, and knowingly, and with intent to defraud, in an offense affecting interstate commerce, did effect and attempt to effect transactions, with one and more access devices issued to another person and persons, to receive payment and other things of value during a one-year period the aggregate value of which is equal to or greater than $1,000.


The indictment states Forfeiture claims on $2,000,000 in property, including the $800,000 seized from Yuriy on February 29, 2008 and an additional $800,000 seized from Ivan on March 4, 2008. (See WIRED's copy of the indictment.

Ivan Biltse, of Bensonhurst, New York, was originally arraigned on March 6, 2008 after being picked up for stealing $9,624 in 12 withdrawals from a Washington Mutal Bank ATM in Bay Ridge back on October 1. According to the New York Daily News, Ivan and Yuriy (who lived in Kensington) were cousins. (See Two Brooklyn Men ripped off $5M from ATMs around globe.)

The case actually started much earlier than that, when back on October 3, 2007, according to the FBI affadavit, First Bank notified the St. Louis Secret Service office that four "iWire" Prepaid Card accounts had been compromised. On just the dates September 30 and October 1, 2007, these four accounts were used to attempt more than 9,000 withdrawals from ATMs around the world, resulting in a loss of approximately $5 Million.

First Bank provided a list of withdrawal attempts, and several hundred of them came from banks in Brooklyn, including the Washington Mutual location that we already mentioned. Transaction and surveillance video pulled from several ATMs and nearby cameras showed:

a Caucasian male making withdrawals at the times and ATM terminals indicated in the First Bank Withdrawal Information for the Compromised Accounts. In the ATM video, this male is wearing a dark blue or black baseball cap emblazoned with the words "Top Gun" and a star and wings symbol, as well as a tan-colored sweatshirt or jacket with a dark blue or black front panel and dark blue or black trim at the zipper and collar.


Separately, on February 1, 2008, Citibank informed the FBI that a Citibank server(*) that processes ATM withdrawals at 7-11 convenience stores had been breached. A fraud alert system was established to flag all uses of these accounts, and the Citibank Withdrawal Information was used in a similar method. Surveillance video was pulled for many of these transactions, and some of them, including some on February 20, 2008 at the Citibank branch at 502 86th Street in Brooklyn, were made by the same individual, wearing the same "Top Gun" hat and sweatshirt as in the October withdrawals.

(Poulsen mentions that Citibank denies a breach. The USA Today article points out that the ATMs in question were not operated by Citibank, but by two other companies, Houston-based Cardtronics, and Brookfield, Wisconsin-based Fiserv. At this point, I don't think anyone has revealed what server was actually breached.)

This individual was quickly identified as Yuriy Ryabinin / Rakushchynets, and was found to have made $750,000 in fraudulent ATM withdrawals just in the month of February. How? Investigators searched Carding forums for individuals who were trading in First Bank or Citibank ATM information. One of these individuals was listing an ICQ number for contact. The ICQ had been registered earlier by "Yuri" a "29 years old male from brooklyn, USA".

A search for the same ICQ number showed that it belonged to a ham radio operator who signed his posts in Ham Radio websites with the same ICQ number. Some of those posts included photographs of Yuri in Dayton at a convention, wearing the same sweatshirt as the individual in the Washington Mutual and Citibank ATM surveillance videos.

A further search on the Ham Radio call sign that he used in these forums found that the FCC had sent him a letter, mentioning his call sign, regarding some minor administrative violations. The letter was addressed to "Mr. Yuriy Ryabinin, 679 Coney Island Avenue 2, Brooklyn, NY 11218".

A public records search found a Florida driver's license in that name, with a matching photograph. Ryabinin also had a Michigan driver's license under the name "Yuriy Rakushchynets".


Very Nice Work, Special Agent Albert Murray.

It will be interesting to see how much of the rest of the initial $5M in First Bank transactions can be identified.

You know I had to Google around a bit and find his call sign, right?

Yuriy Rakushchynets also had a hotmail account -- n2tta@hotmail.com, which he used to post a query looking for a job "within 2 hours drive of Brooklyn, NY". I have no idea what a "CQ-Contest" is, but Yuri was very active in them apparently, listed as a "fulltime operator" for events like the "CQWW SSB Soapbox", and other places giving his name and his call sign in things like:

Yuri, N2TTA, will be active as NP2/N2TTA between February 12-19th. His activity will include the ARRL DX CW Contest (February 16-17th) as NP2S and as a Single-Op/All-Band entry. Yuri informs OPDX that he will be active on CW and SSB on all bands including 30/17/12 meters.
(link.

Yeah, I guess with a couple mill of other people's money, you can buy some nice radios, eh, Yuri?
Read More
Posted in | No comments

Tuesday, 1 July 2008

July Storm Worm gives us some Love

Posted on 14:35 by Unknown
The authors of the Storm Worm must have had some good success with their "love theme" for last month's Storm Propagation Spam, because they have decided to repeat the theme today.

Right about midnight the UAB Spam Data Mine began to receive spam messages for the new Storm Worm.

After being directed to a website that looks like this:



we followed the links on the site to receive some fresh malware. How fresh was it? The executables, which were named "winner.exe" and "mylove.exe" depending on whether you follow the banner ad or the text link, were uploaded to VirusTotal where we found these results:



At our initial scan, of 33 different AV engines, only FOUR of them knew this was a virus, and only two could label it correctly. (Currently we are up to EIGHT AV products properly identifying this as storm. My university machine, which runs McAfee Anti-Virus, does not detect it with a fresh signature update.)

We have seen a wide variety of subject lines in the spam so far . . .

All I need is You
Always on my mind
Can't forget You
Can't stay away from you
Crazy in love
Crazy in love with you
Deep in my heart
Deeply in love with you
Fallen for you
For you...Sweetheart!
Hate that I love you
Here in my heart
Hold you close
I give my heart to you
I knew I Loved You
I'll never stope loving you
I'll Never Find Someone Like You
I'll Still Love You More
I Love Being In Love With You
I love you so much!
In your arms
Just you and me
Lost In Love
Lost In Your Eyes
Love me tender, love me true
Lovin' You
Lucky to have you
Madly in love
Miss you with all my heart
Missing you
My heart belongs to you
My heart to yours
My heart was stolen
Not the same without you
Only Wanna Be With You
Somebody loves you
Stand by my side
Together forever
We belong together
With all my love
With you by mi side
You are always on my mind
You are in my heart
You are my world
You are the ONE
You feel up my senses
You have touched my heart
You make my world beautiful
You make my world special

The domain names which have been used so far are:

bestlovelyric.com
gonelovelife.com
greatadore.com
knowholove.com
loveisknowlege.com
lovekingonline.com
lovemarkonline.com
loveoursite.com
makeloveforever.com
makingadore.com
makingloveworld.com
musiconelove.com
shelovehimtoo.com
superlovelyric.com
theplaylove.com
wantcherish.com
whoisknowlove.com
wholovedirect.com
wholoveguide.com

(Yes, we actually have spam samples for every one of these domains. For most we have MANY samples. That's what the Spam Data Mine does!)

All of these domains seem to be registered with Chinese Registrar "www.bizcn.com".

They use the nameservers (ns# as the prefix on each of these, ns, ns1, ns2, etc.):

likethisone1.com
lollypopycandy.com
verynicebank.com

and their own domain (ns1.wholoveguide.com, etc.)

The latter nameserver, verynicebank.com, was also used during the Beijing Earthquake version of the storm worm, described by f-secure. It served as the nameserver for "grupogaleria.cn", which was used in the attack described by F-Secure in their blog on June 19th. It also served as the nameserver for "nationwide2u.cn", although we are not yet sure of the purpose of that domain name.


We are actively seeking termination of the last few domains now (most are already down).
Read More
Posted in | No comments

Monday, 30 June 2008

19 years old and headed to prison

Posted on 13:03 by Unknown
Jason Michael Milmont, of Cheyenne, Wyoming, may be only 19 years old, but he's already a very successful cybercriminal. In this Los Angeles FBI Press Release, Milmont confessed to controlling between 5,000 and 15,000 remote victims' computers, which he infected through modified versions of Limewire, and through Instant Message spam messages which lead users to infected websites. Links he placed on MySpace and PhotoBucket were also used to spread his malware.

In January, sources such as ComputerWorld were calling Nugache a challenger to the Storm Worm for its virility, and implied that hackers "tied to the Russian Business Network" may be responible for an upgraded version. Nugache was one of the first botnets to be controlled via a Peer to Peer or distributed interface. Lacking a central Command & Control made it more difficult to identify the real controller of the network.

Milmont confessed to being the programmer -- so, it was a 19 year old in Wyoming, rather than a Russian boogie man in this case. Using a graphical user interface Milmont created, he could easily harvest the stolen credentials which the Nugache worm was gathering from his victims as they logged in to their banking and credit card sites. Infected machines could be remotely upgraded to receive new versions of the malware. The third version added the key-logging software to the malware kit.

Although Milmont harvested many credentials, he is only being asked to pay $73,866.36 in restitution, for purchases made using the stolen credit cards. Milmont shipped packages to vacant addresses where he then picked the packages up himself.

Jason studied computers at Laramie County Community College in Cheyenne. One of his instructors there, Roger Findley, described him as extremely intelligent but socially awkward.

By pleading guilty, Milmont will only be charged with a single count of a violation of 1030 (a)(4), accessing a computer without authorization with intention to defraud and obtain a thing of value. The maximum sentence to that plea would be 5 years and a $250,000 fine.

View the 22 page plea agreement here.


Links:

http://www.theregister.co.uk/2008/06/28/nugache_creator_plea_agreement/
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • Microsoft Security Intelligence Report 2H08
    The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microso...
  • Operation Open Market: The Vendors
    When we wrote last week about Operation Open Market the court documents had not yet been released in a major multi-agency Identity Theft ca...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile