Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, 2 May 2009

University Spammers, the Shah brothers, arrested

Posted on 09:04 by Unknown
Congratulations to the Assistant US Attorney for Western Missouri, Matthew Wolesky, and the FBI investigators who have arrested and indicted the Shah brothers! The news was released in a Kansas City FBI Press Release on April 29th.

Amir Ahmad Shah, 28, and his brother, Osmaan Ahmad Shah along with their business, I2O, Inc, and their co-collaborators Liu Guang Ming of China, and Paul Zucker, 55, of New Jersey were named in the 51-count indictment.

Both Amir Shah and Osmaan Shah are listed on the Entrepreneur site, "The Rise To The Top", where they are listed as "Experts" on the site, which provides "Entrepreneurship Education for Young Entrepreneurs". (Any guesses on whether they will be there by Monday? haha! Just in case, I've taken screen shots for you here:



original URL: http://www.therisetothetop.com/guest-expert-profile.php?id=22



original URL: http://www.therisetothetop.com/guest-expert-profile.php?id=24

According to "CrunchBase", Osmaan Shah received his BS in Finance & Banking in 2006, and his MBA in 2009, both from the University of Missouri. His profile says:

Osmaan Shah is the co-founder and lead software developer of Noog. In his 7+ years of development experience, he exhibits a passion for dynamic front-end web design (javascript, AJAX/Comet). He specializes in the incubation of creative new products and online portals targeted towards students and young retail consumers. Mr. Shah is also the a Director and co-founder of VistaClick where he serves as the online marketing campaign manager.


Amir Shah's company is VistaClick.


(Original URL: http://www.vistaclick.com)

VistaClick's website describes an Affiliate Program where you could become one of their 17,000 "registered campus affiliates".

I wasn't able to pull the indictment from Pacer myself, as the "CM/ECF System for the Western District of Missouri is currently down for maintenance" (sigh), but someone else had already posted it online. (See indictment for case mowdce 4:2009cr00141, courtesy of Columbia Daily Tribune).

Here's what we can glean from the 59 page indictment:

First, the charges, which are all applied to the Shah brothers and to I2O, Inc. Liu Guang Ming and Paul Zucker are included in charges 1, 7-16, and 43-51.

Count One: 18 USC § 371 (Conspiracy), a Class D Felony, with possible sentence not more than 5 years with not more than $250,000 fine.

Counts Two through Six: 18 USC § 1030(a)(2) (Fraud in Connection with Computers), a Class C Felony, with possible sentence not more than 5 years with not more than $250,000 fine.

Count Seven: 18 USC § 1030(a)(5) (Fraud in Connection with Computers), a Class C Felony, with possible sentence not more than 10 years with not more than $250,000 fine.

Counts Eight through Sixteen: 18 USC § 1037(a)(1) (Fraud in Connection with Email), a Class E Felony, not more than 3 years, with not more than $250,000 fine.

Counts Seventeen through Forty-Two: 18 USC § 1037(a)(2) (Fraud in Connection with Email), not more than 3 years, with not more than $250,000 fine.

Counts Forty-Three through Fifty-One: 18 USC § 1037(a)(3) (Fraud in Connection with Email)

In the indictment, the defendants are said to have developed an email-harvesting program and used the program to harvest email addresses from the University of Missouri and over two thousand other United States universities and colleges. The defendants then used this database, which included more than 8 million email addresses, to send email messages advertising products that were specifically targeted to college students. The indictment covers thirty-one separate spam campaigns sent using this database.

The emails would claim to be sent from their local "campus representatives", and would often refer to the company as being "alumni-owned" in an attempt to make recipients believe their use of the advertised service would somehow benefit their alma mater or its graduates.

Many of the emails were sent from an "Offshore Bullet Proof Hosting" company located in China. Their emailing software falsified email header information and rotated the subject lines, reply-to addresses, message contents, and advertised URLs in an attempt to bypass spam filters. They also used false information when registering domain names.

After being investigated, and having search warrants served against their homes and business in an investigation into spam messages targeted at University of Missouri students, the spammers merely stopped sending email to any of the addresses harvested from the University of Missouri.

The defendants would register as many as sixty unique domain names for a single spam campaign, all pointing at identical content. They also started a social networking site called "noog.com" which also was advertised by spam. More than $4.1 million in product sales came from the defendants' spam campaigns. They attempted to conceal their earnings both through real estate purchases and sending large sums of money out of country.

In a useful part of the indictment that might be copied by others, definitions for the following terms are provided:
Addresses
Botnet
Domain
Domain name
Domain name service
Email harvesting
Email header
Instant messaging
Internet
Internet Protocol address (IP address)
Internet service provider (ISP)
Mail server
Name server
Proxy server
Realtime Blackhole List (RBL)
Server
Spam filter
Viruses
Website
Web Host

Here's how the roles of the defendants are described:

Amir Ahmad Shah - the co-owner and president of I2O, Inc. - the overall leader of the spam operations and the "idea guy".

Osmaan Ahmad Shah - the co-owner of I2O, Inc - the Chief Operating Officer and the "computer guy" in the partnership. He created the email extgractors, administered the websites, designed the websites, and dealt with other programming and implementation matters.

Liu Guang Ming - rented forty servers under his control in China to host websites, send spam, and search for proxies that could be used for sending spam.

Paul Fredric Zucker - a spammer who purchased proxies from the Shahs, and at other times sold proxies to the Shahs. He also leased space from Ming.

Several other unindicted and unnamed co-conspirators are mentioned, included a family member who ran "VistaClick Pakistan" for the Shahs.

Other companies in the conspiracy were DirectPO, VistaClick, Funding Junction, Veridio, OIBA, Textbook Registry, and Your City Development.

The Shahs began their operation "in or before 2001" by harvesting student email addresses. They began working with Ming in or before 2002, conducting conversations via AOL Instant Messenger. The ad they responded to read:


Servers are located in China and run by some of their largest ISPs. Our tech support team manages servers around the clock with constant contact from China to US. We have several sites sending millions of emails per day. Unlike other hosts, you will NOT need to switch domain names or experience periods of downtime. Our uptime guarantee is 90%. If you are serious about bulk mailing, you have come to the right place.


I was able to find a copy of a post by "AMIR SHAH" back on October 11, 2002, advertising "BULLET PROOF CHINA HOSTING" on this URL on sidetrak.com as an example.

In that ad, Amir offers to send messages for $30 per million emails sent. He used the AOL instant messager id "rulubos@aol.com".

Amir Shah also had a twitter account with that same identity, rulubos. He hasn't posted anything there since January 5th, 2009, when his last post was "looking at twitter and wondering if I should just incorporate this feature into Noog."

Amir follows Jianxiong Song. Hmmm...let's look at some more twitter links . . . Jianxiong is following WaqasShah, whose last twitter post is "WaqasShah is relieved" posted on APril 24th. WaqasShah follows noog_com, who was testing bloog mobile, according to their last twitter on April 17th. Noog has an interesting group of Venture Capitalists that he follows, but I won't list them here.

OK, back to the indictment.

In chat logs found on the computers, Zucker trains O. Shah in the art of spamming, and they communicate about how many proxies they would need to send 2 million emails, being disappointed with a rate of only 110,000 per hour. O. Shah later tells Zucker (July 14, 2003) that he can now send 1 million emails per hour with a 65% delivery rate (unblocked/unfiltered). Later, O. Shah tells his brother A. Shah that by plugging directly into the University of Missouri Columbia network "with a cable not using the wireless" he can send 2 million spam messages per hour from the school.

Search warrants were served against the Shah residence in Columbia, Missouri and their business address also in Columbia on February 23, 2005. They found more than 3 million student email addresses harvested from 2002, 5 million harvested from 2003, and 37.5 million AOL email addresses, 33.7 million MSN addresses, 10.8 Hotmail addresses, 5.2 million Yahoo addresses, and more than 4 million United Kingdom email addresses.

The indictment shows that the crew was identifying a ridiculous number of proxy servers which they could use to "bounce mail" from. For a price of $75 per week, Zucker was able to provide them "1500-2500 proxies twice a day". Originally, the transaction had gone the other way, with Shah providing a list of 45,000 proxies to Zucker earlier, receiving payment for his services via Paypal.

Zucker communicated with O. Shah about how to obtain and use the software program "Dark Mailer", and sent Shah a copy of the program on February 3, 2005. They also used the programs Supermailer and "Group Mail".

Bank records showed that the Shahs transferred more than $30,000 to Ming for hosting services.

Other chats showed the brothers discussing ways to make money. For example, they sent spam for a "teeth whitening" service, where they received a commission for successful sales. The brother said "if we need to mail a million or two to get 10,000 kids...then so be it...who cares."

Here's an example of their teeth-whitening emails, from April 1, 2004, which will illustrate how the SHAH brothers took advantage of students trust in their university relationships:

"Each year, several alumni-owned companies offer various specials to our students and faculty. This month, the university has been offered a special discount on custom fitted teeth whitening systems. Alumni-owned, Custom Bright, Inc., is offering its products to students and faculty at significant discounts all this month. We encourage you to visit their website and take advantage of this alumni offer."

This continued all the way through 2009, with messages like this one, sent March 1, 2009:

"As many of you may be aware, our campus has been offered a special discount on professional custom-fitted teeth whitening systems from a company run by our very own alumni. There will be several campus representatives (like myself) giving out more information over the next 2 weeks."

The brothers discussed having "a more forceful message" to encourage registration in a particular textbook system they were spamming:

"With higher tuition and course material costs, we are working to find new ways of saving students money. This semester, we have implemented a new textbook buyback program that will get students better payouts at the semester ending buyback and may also increase used textbook availability. You MUST complete your registration before the end of this week if you wish to be eligible for this semester's buyback."

Other campaigns that used similar spam sold Digital Cameras, iPods, NCAA Basketball merchandise, and Magazine subscriptions.

Some of the many domain names they used:

surveyproject.org
surveydirect.org
campuschange.org
whiteningtoday.com
whiteningnow.com
discoverwhitening.com
myschoolipods.com
studentipods.com
campusipods.com
semestersavings.com
semesterdiscounts.com
saveatcollege.com
collegedecember.com
estudentoffers.com
mycollegedeals.com
collegefuture.com
campusfuture.com
campusinput.com
whiteningservices.com
whiteningovernight.com
whiteninglabs.com
mycampusnanos.com
campusnanos.com
schoolipods.com

The full indictment gives date ranges for these and many other domain names.

Some of the purchases the Shah brothers made include:

a home in Columbia - $191,123.

a luxury lost in St. Louis - $251,861.

paying off a house in St. Louis - $33,698.

a downpayment on a Lexus sedan - $8,800.

The forfeiture of any assets, up to a total of $4,191,966.57 is also requested, which will come from several bank accounts, and the sale of properties at:

1301 Fieldcrest, Columbia, MO
1520 Washington Avenue, Unit #301, St. Louis, MO
a parking space (?)
5417 Idaho Avenue, St. Louis, MO

a 2002 Lexus (Missouri plate: CA9R6B)
a 2001 BMW (Missouri plate: 391ZEP)

Update



Apparently the Shah brothers indictment has shared with other spammers some good tips on this type of spam. Here's a message that one of my students at UAB received on April 30, 2009:

_____________________________________
From: Jenna T. [jenna@OverstockApple.com]
Sent: Thursday, April 30, 2009 2:20 AM
To: (name of my student)
Subject: Student/Faculty Discount

Dear Students/Faculty,

As you may have heard, several alumni-owned companies have teamed up to sponsor a campus-wide gift for our students and faculty. Working with Apple, they have acquired a small quantity of the new iPod Nano Chrome. This limited supply has now been made available to students and faculty at a significant discount. If you were at all interested in getting one of these iPods with this educational discount, please be sure to place your order online before this offer expires NEXT WEEK.

http://www.OverstockApple.com/h/3189094

Have a great summer!

Jenna T.
OverstockApple.com Student Representative



Have you seen a recent spam (after April 24th) from this group, pretending to be offering a discount for products from an "alumni-owned company"? If you can send it to me WITH HEADERS, I'd very much like to see it. Send it to: alumnispam@askgar.com
Read More
Posted in law enforcement, spam | No comments

Wednesday, 29 April 2009

Waledac Moving on to . . . Canadian Pharmacy?

Posted on 05:04 by Unknown
After monitoring the Waledac "infection domains" for more than a month, our last "interesting" event was the change in Look & Feel to the SMS Spy Program which we wrote about back on April 15th. In that blog article we mentioned that basically ALL of the domains used by Waledac, through the Valentine's Day campaign, the Couponizer campaign, the Terror Alert campaign, and the SMS Spy campaign, were all still alive!

Here's the newest change. ALL of the Waledac infection domains have now morphed into pill sites, and MANY of the older Waledac domains have finally been terminated.

Here's where stand with live FORMER Waledac domains. Many domains from the "Terror Alert" and "SMS Spy" alert are now forwarding on a random basis to domains which are either hosting Canadian Pharmacy or Canadian Health & Care Mall.

Of the Waledac domains that we were tracking, the following are now live forwarding domains:

antiterroralliance.com
blogginhell.com
blogsitedirect.com
boarddiary.com
discountfreesms.com
downloadfreesms.com
eccellentesms
fearalert.com
freecolorsms.com
freesmsorange.com
ipersmstext.com
nuovosmsclub.com
primosmsfree.com
smsclubnet.com
smsinlinea.com
smsluogo.com
superioresms.com
terroralertstatus.com
virtualesms.com


"Canadian Health & Care mall" at arzuhuxupi.com
"Canadian Health & Care Mall" at rahtydryo.com
"Canadian Health & Care mall" at vennocvajgo.com

"Canadian Pharmacy" at earpassionate.com
"Canadian Pharmacy" at transformationforgiving.com
"Canadian Pharmacy" at giftedaglow.com
"Canadian Pharmacy" at strivingalive.com


The following Waledac domains now appear to be terminated:

adorepoem.com
adoresong.com
adoresongs.com
againstfear.com
bestadore.com
bestbreakingfree.com
bestcouponfree.com
bestgoodnews.com
bestlovehelp.com
bestlovelong.com
bluevalentineonline.com
breakingfreemichigan.com
breakinggoodnews.com
breakingkingnews.com
breakingnewsfm.com
breakingnewsltd.com
chatloveonline.com
cherishletter.com
cherishpoems.com
codecouponsite.com
funloveonline.com
funnyvalentinessite.com
goodnewsdigital.com
goodnewsreview.com
greatcouponclub.com
greatsalesgroup.com
greatsalestax.com
greatsvalentine.com
greatvalentinepoems.com
linkworldnews.com
lovecentralonline.com
lovelifeportal.com
reportradio.com
romanticsloving.com
smartsalesgroup.com
spacemynews.com
supersalesonline.com
thecoupondiscount.com
thevalentinelovers.com
tntbreakingnews.com
wapcitynews.com
whocherish.com
wirelessvalentineday.com
worldlovelife.com
worldnewsdot.com
worshiplove.com
worldtracknews.com
youradore.com
yourbreakingnews.com
yourcountycoupon.com
yourgreatlove.com
yourvalentinepoems.com
Read More
Posted in malware, waledac | No comments

Tuesday, 21 April 2009

President Obama's CTO: Aneesh Chopra

Posted on 06:48 by Unknown
Photo From Virginia.gov
Like so many others who were playing the guessing game regarding President Obama's new CTO, I was wrong. I take comfort in failing along with BusinessWeek, ZDNet, Forbes, TheStreet, The Wall Street Journal and others to guess who would fill the office.

We might have taken a hint from one of President Obama's recent speeches to Congress, where he said:

"Our recovery plan will invest in electronic health records and new technology that will reduce errors, bring down costs, ensure privacy, and save lives."
-- (Transcript 24FEB09

Aneesh Chopra's bio on his Virginia website points out that he chairs the "Solutions Committee of the IT Investment Board, the Effectiveness and Efficiency Committee on the Council on Virginia's Future, and co-chairs the Healthcare IT Council". He was awarded the Healthcare Information and Management Systems Society's 2007 State Leadership Advocacy Award, and was named one of the top 25 by Government Technology magazine's Doers, Dreamers, and Drivers magazine.

In 2006, ExecutiveBiz.com interviewed Mr. Chopra on his new position as Secretary of Technology for the Commonwealth of Virginia. His answer to the question "What is your background?" lines up well with President Obama's vision for secure electronic healthcare records:

ExecutiveBiz: What is your background?

Aneesh Chopra: Professionally, I am a managing director at a think tank with a focus for the health care industry, but a big portion of my professional background has been studying ways that technology can fundamentally transform the healthcare industry in particular. Also, I internally helped launched the Advisory Board's first software-based membership business. So not only have I been researching technology and how I can benefit the healthcare industry, I have been business development wise active in the use of technology to grow our own business.


It was clear from his work in the job though that Health Care was not his only focus. Here were some answers regarding educational technology, another area on which the Secretary turned his attention while in office in Virginia, from one of the 46 Podcasts his office put out during his time there: (03/25/09 - Secretary Chopra discusses technology in the classroom --


We have an innovation imperative in the Commonwealth, and frankly for the country, and it requires us to think anew about how we produce students who are globally competitive. There are three basic questions we have to ask:
What are we actually teaching our kids?
How are we teaching our kids?
What are the tools with which we can allow the sharing ideas and the process of learning how to teach our kids?
In each of these areas there is a place for technology to play a role, in some cases a direct role, and in other cases more of an indirect role.


In his 2007 Accomplishments podcast (January 9, 2008) he stressed three Public/Private Partnerships, including:

a Google partnership to produce Google SiteMaps of 55 government websites, mapping more than 200,000 state webpages to increase their ability

Microsoft Virtual Earth helped create Campus Safety maps to help identify resources and plans for various emergencies on campus as a reaction to school shootings.

Cox and Comcast Cable began offering "GED On Demand" for free to more than 1 million broadband subscribers in Virginia.

1 of 3 new jobs created in Virginia came from high-tech jobs, and 30% of all wage-earners in Virginia received their pay from a technology related job.

5 innovators in HealthCare IT, 3 of which provided an 8-fold return on the investment. The Virginia HealthCare Exchange Network was created as part of the initiative.

Many other initiatives were described, making this podcast well worth listening to in order to learn more about how our nation's new CTO thinks about Technology. Many of these initiatives were grant-generated, by placing challenges into the community and asking for innovators who have solutions to step forward to address government productivity, broadband, and government IT.

To summarize what I see about Aneesh Chopra - he's proven that he knows how to solicit ideas from innovators, shape them into actual solutions, and roll them out as successful products. He did it in the business world, he did it in his HealthCare IT think tank, and he did it for the State of Virginia. I look forward to seeing what he can do for our nation.

I'm especially interested to see what types of reforms a technology thinker can bring to our Criminal Justice systems! At UAB Computer Forensics our partnership between Computer Science and Justice Science is based on the concept that when Computer Scientists are presented with Criminal Justice problems, good technology things can happen. Hopefully this will be one of our new CTO's priority areas as well.
Read More
Posted in public policy | No comments

Wednesday, 15 April 2009

Waledac shifts to SMS Spy program

Posted on 14:24 by Unknown
We've known that Waledac spreads itself via Social Engineering - convincing users that they WANT to download a program. Recently we've seen Waledac acting as a Valentine's Day E-Card, a Couponizer program, and a Fake News Story about a Dirty Bomb.

Today the UAB Spam Data Mine began to get spam messages for a new Social Engineering trick. Here are some of the email subjects we're seeing:

Subjects
-----------
Read his SMS
The world's most advanced sms reading program
Now, It's possible to read other people's SMS
Read other people's SMS online
You can read anyone's SMS

The email bodies point to the websites with lines like these:

Do you trust her? http://smsclubnet.com/
You can read anyone's SMS http://virtualesms.com
Do you really trust her? http://www.freecolorsms.com
Do you really trust him? http://downloadfreesms.com/
Are you ready to know the truth? http://smsclubnet.com
Are you sure you want to know? http://smsclubnet.com

The webpage you visit looks like this:



The malware which you can download from the page is recognized by 13 of the 39 Anti-Virus products tested according to this VirusTotal Report.


File size: 419840 bytes
MD5...: 8623f18666be9d480710b29eab3b796a

The root problem with Waledac's long-lived domains is they are using a Chinese domain name registrar who won't cooperate with anyone on shutdowns. We have sent shutdown requests to their abuse contact, in both English and Chinese, and have received no cooperation whatsoever. If you have good contact information for "Ename.com", we really could use an introduction, thank you! No one answers their "1000@ename.com" email address, but perhaps a Chinese speaker might call them at +86.5922669769 ? ? ?

The complete list of NEW domain names created for this round of Waledac are:

smspianeta.com
miosmsclub.com
downloadfreesms.com
virtualesms.com
chinamobilesms.com
freeservesms.com
freecolorsms.com
smsclubnet.com

But a great number of the previous domains are also still live, and still serving Waledac, including:

adoresongs.com
antiterroris.com
bestadore.com
bestcouponfree.com
bestjournalguide.com
bestlifeblog.com
bestlovehelp.com
bestlovelong.com
bestusablog.com
bluevalentineonline.com
breakingnewsltd.com
chatloveonline.com
cherishletter.com
codecouponsite.com
easyworldnews.com
funloveonline.com
funnyvalentinessite.com
goodnewsdigital.com
goodnewsreview.com
greatcouponclub.com
greatsalesgroup.com
greatsvalentine.com
lovecentralonline.com
lovelifeportal.com
mobilephotoblog.com
photoblogsite.com
romanticsloving.com
spacemynews.com
thecoupondiscount.com
thevalentinelovers.com
tntbreakingnews.com
urbanfear.com
usabreakingnews.com
wirelessvalentineday.com
worldlovelife.com
worshiplove.com
youradore.com
yourgreatlove.com
yourvalentineday.com
yourvalnetinepoems.com

If you have contact at Ename.com, these ALL need killed, thank you! They are all now distributing the new "SMS Spy" version of Waledac.
Read More
Posted in malware, spam, waledac | No comments

Monday, 13 April 2009

New Drug sites avoid Visa and MasterCard, Sell Hydrocodone

Posted on 07:16 by Unknown
Those who research Pharmaceutical spam have learned that there are basically two major classes of drugs. Those which the Feds care about stopping (Controlled substances monitored by the DEA) and those the Feds are happy to ignore, and which they call dismissingly "Lifestyle Drugs".

Its quite frustrating in light of the fact that, as Microsoft pointed out recently in their semi-annual report on Internet safety, 97% of the email on the Internet is spam, and HALF of that email is pharmaceutical spam. For someone to decide that its not worth investigating lifestyle drugs (by which they mean Viagra, Cialis, and other sexual-experience related drugs) as vigorously as we investigate "Controlled Substances" has lead to our current status on the Internet as a world flooded with absolutely uncontrolled drug spam.

Nevertheless, knowing that there is a two-tiered system of investigation related to pharmaceutical spam, we've all learned that the way to get action is to point out sites that are selling things that are on the Class I, Class II, Class III, or Class IV Controlled Substance List.

Side Note - if you are looking for a Computer Forensics Research program interested in making an impact on pharmaceutical spam, that has as partners in its "Computer Science/Justice Science Working Group" forensic criminologists with their own Gas Chromotography Mass Spectrometer (GS/MS), and faculty and grad students trained in its use, please look no further than the University of Alabama at Birmingham.

That's one of the two reasons why this new spam cluster is especially interesting to me. We have more than 1450 spam emails in the UAB Spam Data Mine during March and another 1,069 so far during April that contain the word "Hydrocodone" in either the body or the subject. The subject line in today's case actually says "Hydrocodone For You", and pointed to a pharmacy site here:

http://show-advanced-individual.com/



which leads with Hydrocodone, Vicodin, Phentermine, Ambien, Valium, and Levitra. They have quite a few alternate payment methods, but most notably they do NOT accept Visa or Mastercard:






By accepting electronic checks, direct bank transfers, and Western Union payments, these dealers in fake drugs can move their money even faster than they move their drugs. The world of money laundering possibilities opens wide once you get Visa and MasterCard off the option list. That should also make it pretty clear to the potential buyers. This vendor wants to move your money Quickly, Untraceably, and most importantly Irreversibly. They want to make sure they get your money NOW, even though you may (or may not) get your drugs later, and that even if you do NOT got your drugs, there is no way your going to get your money back, or even figure out where your money went.


This particular domain was registered on March 20th via XIN NET Technology.

The IP is at 116.125.56.218 - Hanaro telecom, Korea

This is not a new IP address to us at the UAB Spam Data Mine.

March 23 - 116.125.56.218 (1 spammed domain)
March 24 - 116.125.56.218 (13 spammed domains)
March 25 - 116.125.56.218 (16 spammed domains)
March 26 - 116.125.56.218 (50 spammed domains)
March 27 - 116.125.56.218 (42 spammed domains)
March 28 - 116.125.56.218 (42 spammed domains)
March 29 - 116.125.56.218 (42 spammed domains)
March 30 - 116.125.56.218 (64 spammed domains)
March 31 - 116.125.56.218 (75 spammed domains)

(I'll update those stats with April data once its been caught up...)

The Hotmail address in the whois data is = na506@hotmail.com

Two hundred other hyphenated domain names are on the same Hanaro IP address, according to DomainTools:

Approach-amazing-day.com
Approach-amazing-year.com
Approach-coming-human.com
Approach-delightful-2009.com
Approach-delightful-memory.com
Approach-delightful-species.com
Approach-emotive-creature.com
Approach-emotive-kind.com
Approach-fresh-month.com
Approach-hopeful-second.com
Approach-hot-blooded-2009.com
Approach-hot-blooded-year.com
Approach-new-2009.com
Approach-nice-2009.com
Approach-pretty-hour.com
Approach-touched-second.com
Approachamazinghour.com
Approachdelightfulhour.com
Approachhopeful2009.com
Approachmysteriousspecies.com
Approachprettyyear.com
Approachsucessfulcreature.com
Cherish-coming-creature.com
Cherish-eminent-species.com
Cherish-emotive-species.com
Cherish-fresh-day.com
Cherish-hot-blooded-minute.com
Cherish-hot-blooded-year.com
Cherish-mysterious-month.com
Cherish-nice-creature.com
Cherish-pretty-second.com
Cherish-sucessful-kind.com
Cherishamazingminute.com
Cherishcomingmemory.com
Cherisheminenthuman.com
Cherishemotive2009.com
Cherishemotivebeing.com
Cherishfreshbeing.com
Cherishhopefulhuman.com
Cherishmysteriouskind.com
Cherishprettysecond.com
Cherishsurprisingkind.com
Enjoy-beautiful-second.com
Enjoy-coming-month.com
Enjoy-delightful-species.com
Enjoy-eminent-human.com
Enjoy-exciting-month.com
Enjoy-hot-blooded-human.com
Enjoy-pretty-memory.com
Enjoyaffectingsecond.com
Enjoybeautifulsecond.com
Enjoydelightfulsecond.com
Enjoyfreshyear.com
Enjoyhot-bloodedmonth.com
Enjoyniceyear.com
Enjoysucessful2009.com
Feel-sucessful-day.com
Feel-sucessful-hour.com
Feel-surprising-second.com
Feelhopefulmemory.com
Feelhopefulminute.com
Feelsucessfulsecond.com
Feelsurprisingmemory.com
Greet-amazing-human.com
Greet-amazing-kind.com
Greet-delightful-species.com
Greet-delightful-year.com
Greet-fresh-creature.com
Greet-nice-creature.com
Greet-nice-memory.com
Greet-sucessful-being.com
Greetamazingmemory.com
Greeteminentsecond.com
Greethot-bloodedcreature.com
Greethot-bloodedkind.com
Greethot-bloodedmemory.com
Greetnewspecies.com
Guide-developping-block.com
Guide-developping-corporation.com
Guide-developping-urban-area.com
Guide-incorruptible-institution.com
Guide-upright-individual.com
Guide-well-behaved-street.com
Guidedeveloppingblock.com
Guidedeveloppingcompany.com
Guidedeveloppinglane.com
Guideincorruptiblesquare.com
Guideopenstreet.com
Guidereliableinstitution.com
Guidewell-behavedcountry.com
Guidewell-behavedurban-area.com
Meet-amazing-minute.com
Meet-exciting-kind.com
Meet-fresh-being.com
Meet-hot-blooded-minute.com
Meet-pretty-being.com
Meetamazingmonth.com
Meetamazingsecond.com
Meetcomingbeing.com
Meetcomingcreature.com
Meetdelightfulhour.com
Meetemotivecreature.com
Meetexciting2009.com
Meethot-bloodedbeing.com
Meetsucessfulcreature.com
Meetsucessfulday.com
Meetsurprisingcreature.com
Meetsurprisingsecond.com
Reveal-advanced-corporation.com
Reveal-advanced-lane.com
Reveal-advanced-street.com
Reveal-civilized-country.com
Reveal-civilized-urban-area.com
Reveal-clean-institution.com
Reveal-developping-lane.com
Reveal-educational-unit.com
Reveal-frugal-alley.com
Reveal-neat-entreprise.com
Reveal-neat-institution.com
Reveal-peaceful-country.com
Reveal-spiritual-lane.com
Reveal-spiritual-street.com
Reveal-upright-organization.com
Reveal-upright-street.com
Reveal-well-behaved-corporation.com
Reveal-well-behaved-urban-area.com
Revealadvancedcompany.com
Revealadvancedindividual.com
Revealadvancedunit.com
Revealcivilizedentreprise.com
Revealcivilizedindividual.com
Revealculturalcity.com
Revealculturalstreet.com
Revealculturalunit.com
Revealdeveloppingcity.com
Revealincorruptibleindividual.com
Revealpeacefulunit.com
Revealreliableinstitution.com
Revealspiritualblock.com
Revealspiritualdistrict.com
Revealspiritualentreprise.com
Revealspiritualurban-area.com
Share-affecting-year.com
Share-amazing-species.com
Share-amazing-year.com
Share-beautiful-species.com
Share-beautiful-year.com
Share-coming-year.com
Share-delightful-kind.com
Share-eminent-being.com
Share-eminent-hour.com
Share-emotive-being.com
Share-emotive-minute.com
Share-fresh-2009.com
Share-pretty-creature.com
Share-sucessful-human.com
Share-surprising-2009.com
Share-surprising-year.com
Share-touched-year.com
Shareaffectingcreature.com
Shareaffectingmemory.com
Sharehopefulmonth.com
Sharemysterious2009.com
Shareprettycreature.com
Sharesucessfulday.com
Sharesurprisingminute.com
Show-advanced-individual.com
Show-civilized-entreprise.com
Show-civilized-organization.com
Show-civilized-square.com
Show-clean-block.com
Show-educational-citizen.com
Show-educational-corporation.com
Show-harmonious-mechanism.com
Show-harmonious-organization.com
Show-neat-urban-area.com
Show-spiritual-block.com
Show-tidy-lane.com
Show-upright-urban-area.com
Showadvancedurban-area.com
Showcleanentreprise.com
Showincorruptiblecountry.com
Showpeacefulorganization.com
Showtidyorganization.com
Showwell-behavedsquare.com
Treat-affecting-being.com
Treat-amazing-2009.com
Treat-beautiful-creature.com
Treat-exciting-year.com
Treat-fresh-memory.com
Treat-hot-blooded-second.com
Treat-mysterious-minute.com
Treat-surprising-memory.com
Treat-touched-kind.com
Treat-touched-month.com
Treathopefulday.com
Treathot-bloodedhour.com
Treatsucessful2009.com
Uideharmoniousalley.com
Welove-supersale.com

Over the weekend, a new Hydrocodone cluster emerged, distinct from the one above.

The new cluster used the following domain names in more than 1500 emails just over the last weekend:

aoisiis.com
aposoos.com
apsppew.com
blotbump.com
blotcare.com
blotcool.com
bumpflow.com
bumpfold.com
candark.com
canword.com
celitrre.com
dealrise.com
debaiteo.com
domefast.com
domerests.com
dometake.com
esperros.com
fecioos.com
felippie.com
fullmage.com
fullmeed.com
fullmend.com
fullruse.com
kaiffelt.com
lungsse.com
macrsoku.com
maghiarr.com
mailldeo.com
maingive.com
maltfame.com
maltfire.com
maltflip.com
maltlike.com
maltmain.com
maltmalts.com
maltplay.com
malttall.com
malttilts.com
marnarq.com
masciake.com
naryneat.com
nowdark.com
nowwall.com
pionname.com
pionnary.com
pionpick.com
pionrise.com
pollsies.com
ppoleiw.com
qalsibbe.com
qaselict.com
realpin.com
riennsi.com
ropeww.com
rpeusw.com
spoeii.com
tehsui.com
wallmay.com
wallrise.com
wallsdeals.com
wesleos.com
wposlles.com
yehsuue.com

The new cluster looks like another Viagra site at first:



but scrolling down, we see it really is selling Hydrocodone and other Class II and Class III Controlled Substances:



As with the first cluster we mention, Visa and MasterCard are conspicuously missing from this site. It now accepts ONLY American Express:



Fortunately, they are concerned about the High Incidence of Fraud. 8-) Haha!
Read More
Posted in pharmaceuticals, spam | No comments

Thursday, 9 April 2009

Is There a Conficker E? Waledac makes a move...

Posted on 06:22 by Unknown
At UAB Computer Forensics, we have been tracking the spam bot, Waledac, since March 19th, by checking every so often (like 4 times a minute) all of the domain names that we now are being used to distribute Waledac. We've been making a list of the infected nodes, with the timestamp that we see them distributing Waledac, and offering that list to various network providers. (If you are a network provider/ISP, send me an email to get a pointer to the list, there are around 4,000 US-based IPs on it so far.)

This morning, Packet Ninja Dan Clemens gave me a call asking if I had seen Trend Micro's claim that Conficker was updating. I hadn't seen that, but I had seen emails on one of my secret squirrel mailing lists that Conficker was updating from "goodnewsdigital.com". That didn't make any sense at all to me! We've seen 2,821 IP addresses serving up "plain ole' Waledac" from GND, so far. (See http://www.cis.uab.edu/forensics/blog/gnd.list.txt)

Just to make sure, I went ahead and fetched the current Waledac binary from one of the GoodNewsDigital.com websites, and sure enough, it was Plain Ole Waledac.

MD5: 20ac8daf84c022ef10bc042128ccace6

Currently detected by only 9 of 40 products at VirusTotal

Here's the VirusTotal Link, but the details are here:

AntiVir - TR/Crypt.ZPACK.Gen
CAT-QuickHeal - DNAScan
F-Secure - Packed:W32/Waledac.gen!I
Fortinet - W32/PackWaledac.C
McAfee-GW-Edition - Trojan.Crypt.ZPACK.Gen
Microsoft - Trojan:Win32/Waledac.gen!A
NOD32 - Variant of Win32/Kryptic.LP
Panda - Suspicious file
Sophos - Mal/WaledPak-A

A sad statement of the current state of anti-virus, that a KNOWN MALWARE DISTRIBUTION POINT that has been serving up viruses since mid-March for a large spam botnet is still entirely undetected by 3/4ths of the AV products!

But it gets worse.

I went and read Trend Micro's assertions on their blog . . .

According to Trend Micro they saw new malware arrive on one of their conficker boxes, being dropped not via a website update, as we've all been expecting, but via a Peer 2 Peer connection from other Conficker machines. The new malware arrived via P2P on their box and began attempting to propagate in worm-like fashion looking for MS08-067 vulnerabilities (the same as previous versions of Conficker), as well as opening a webserver on port 5114, and making connections to Myspace, MSN, eBay, CNN, and AOL. After this, the machine downloaded a file from GoodNewsDigital.com, which is, as I mentioned above, a Waledac distribution point.

The file that it downloads though IS NOT THE PRIMARY WALEDAC MALWARE. We retrieved the same file in our labs at UAB (forgive me, but the file is named "fuck4.exe"), and scanned it with VirusTotal as well. This is NOT the file you receive if you visit the Waledac host, as we decribed above, via a normal spam-referred website visit.

Here's what we got from "fuck4.exe" at VirusTotal:

ZERO products detect this as malware. NONE of the 40 sites thought the 418kb executable file was a virus.

VirusTotal Report

Trend is calling the new variant WORM_DOWNAD.E (DownAdUp is an alias for Conficker).

The Trend article certainly has caused some deep thinking here this morning! Thanks to Ivan Macalintal at Trend, and because he thanks Joseph Cepe and Paul Ferguson, we thank them as well!

Wait, why are we thanking Paul Ferguson? I had to go find out. Its because of his excellent documentation on the Peer2Peer nature of Conficker in the Trend Blog on April 4th. While the entire world began watching on April 1st for Conficker to be updated via new malware that was placed on one of the 50,500 domain names that began to be searched on April 1, the bad guys have snuck in the back door and updated Conficker via P2P instead.

Paul got a head start on his Peer to Peer research from the excellent malware researchers at CERT-LEXI in their Blog at CERT-LEXSI.


We'll be contacting more Conficker researchers as the day goes on and trying to determine if ALL the Conficker nodes have just merged with Waledac, or if something else is occurring here.
Read More
Posted in conficker, spam, waledac | No comments

Wednesday, 8 April 2009

Microsoft Security Intelligence Report 2H08

Posted on 12:27 by Unknown
The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microsoft.com/sir/ is timestamped the evening of April 6th). We reported on the last SIR report back on November 11, 2008 - please see Microsoft Reveals Malware and Spam Trends for our coverage of that report.

Number of Security Vulnerabilities



52% of the Security Vulnerability announced throughout the industry, via the Common Vulnerability Scoring System were of "High" criticality, while 56% of them were "Easy to exploit". 90% of the industry vulnerability announcements related to applications or browsers. Only 10% dealt with Operating Systems.

Microsoft released 42 Security patches during the 2H08 period.

Spam



More than 97% of the email sent across the Internet during 2H08 was unwanted! They have malicious attachments, they are phishing emails, or they are just plain spam. As all of us already suspected 48.6% of all the spam observed during 2H08 was for pharmaceutical products. Another 23% were for non-pharmacy product advertisements.



Notice that the Stock Pump & Dump spam almost disappeared. What would they sell if we could do the same thing to pharmacy spam?

The report also calls attention to the demise of McColo as being the big enforcement action of the year. This section of their report is called "Spam Volume Drops 46 Percent When Hosting Provider Goes Offline". The spam level at the end of December was still lower than the pre-McColo action on November 11th.

Browser Drive-By-Infections


About 1 in 1500 websites (more than 1 million) indexed by Live Search (Microsoft's answer to the Google search engine, available at live.com) contained a drive-by-download page. More than 1% of websites with a ".cn" country code hosted drive-by-download exploits. When they looked at the products that were being exploited in these driver exploits, #1 and #2 were Adobe Flash and RealPlayer.



(from p.48 of the Microsoft SIR report for 2H08)

On Windows XP machines, browser exploits targeted a Microsoft product 40.9% of the time. On Windows Vista machines, successful browser exploits targeted a Microsoft product only 5.5% of the time. This is one of many places throughout the document that Microsoft reminds us that Vista is a more secure operating system than XP.

In the first half of 2008, most compromised browsers were running Chinese language set (zh-CN = 25.6%). In the second half of 2008, American English language browsers easily passed them (en-US = 32.4%).

Social Engineering



The SIR report makes a point that the criminals today are having great success with social engineering targeting Fear, Trust, and Desire. Rogue Security Software did so well, because people are afraid of viruses.

Of the Social Engineering attacks that were based on an infected Microsoft Office File program, 91.3% of the attacks used the more than two year old exploit, CVE-2006-2492 MS06-027 to infect users via a Microsoft Word document. Curiously only 32.5% of these infected Word documents targeted en-US machines. 15.7% targeted Taiwanese machines, 12% Russian, 11.1% other Chinese machines, and 2.6% Iraqi machines.

Two Adobe PDF reader exploits also became popular in 2H08, spreading strongly and increasingly from October until the end of the year. 57% of the Adobe attacks targeted en-US machines. China didn't make the top ten on that list.

One important note regarding corrupt Office documents. Microsoft's SIR report recommends that users *NOT* run "Windows Update", but rather run "Microsoft Update". Applying Windows Update will never prompt you to install Microsoft Office patches, which may be why so many machines are still vulnerable to two year old malware. The report recommends that users read this entry:

How Is Windows Update Different Than Microsoft Update?, and make the appropriate changes on their machines.

Security Breaches



The report also makes clear that the trend has continued - most security breaches are accomplished not through "hacking" (though more than 15% are), but through stolen or lost equipment, usually laptops.

Geographic Trends



In 2H08, 13.2Million US computers were cleaned by Microsoft's anti-malware desktop products.


(source: SIR report p. 69)

For more details, please see the full SIR report.
Read More
Posted in malware, spam | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • Microsoft Security Intelligence Report 2H08
    The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microso...
  • Operation Open Market: The Vendors
    When we wrote last week about Operation Open Market the court documents had not yet been released in a major multi-agency Identity Theft ca...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile