Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 16 June 2009

Armchair CyberWarriors: Twitter and #IranElection

Posted on 06:05 by Unknown
Our friends over at ThreatChaos let us know about the newest "CyberWar" in their blog this morning, so we went over to Twitter (yeah, follow /garwarner) and decided to check things out for ourselves.

Apparently the Moral Compass of the Internet is currently indicating that CyberWar is a harmless feel good activity that Americans should be involved in. Let me quickly go on the record to say: ALL DDOS ACTIVITY IS A CRIME AND SHOULD NOT BE ENCOURAGED OR CONDONED IN ANY CIRCUMSTANCE

First, let's get the legal part out of the way. In the United States, the relevant code is Title 18 Part I Chapter 47 § 1030(a)(5)(A)(i), which says that anyone who:

(i) knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;

is in violation of the law and can be fined and imprisoned for up to one year (unless their intrusion causes medical or physical harm, or unless they are already a convicted felon, or unless they seek monetary gain, in which cause the penalties go up).

So, is the president of Iran's website a protected computer? No, probably not. But any computer engaged in Interstate commerce is a protected computer. For example, all of the computers belonging to your ISP, which you are placing load on by your criminal activity. If it turns out you were collaborating with others in order to cause this activity to occur, say for instance, all of your buddies on Twitter, then you could also be said to be part of a Conspiracy, but we won't get into that here.

Before we spend any more time on the wisdom of deciding as a private citizen to declare war on a foreign power, let's see what's actually going on in Twitter-space with regards to this DDOS:

Esko Reinikainen of Wales is offering this #iranelection cyberwar guide for beginners, which includes some Ghandi type actions, such as identifying yourself as an Iranian blogger with a time zone of GMT +3.30, on the theory, I suppose, that Iranian security forces will get confused as they seek out the real Iranian bloggers, and book a flight to Wales or the United States to stop the blogger. His point #6 is:


6. Denial of Service attacks. If you don't know what you are doing, stay out of this game. Oly target those sites the legitimate Iranian bloggers are designating. Be aware that these attacks can have detrimental effects to the network the protesters are relying on. Keep monitoring their traffic to note when you should turn the taps on or off.


Of course you can tell the "legitimate" Iranian bloggers, because they use the tags "#iranelection" or "#gr88" in their posts.

Many of those calling for DDOS attacks are harmless voices that suggest things like:

/nzmrmn - #DDOS this http://isna.ir/ISNA/Default.aspx?Lang=E 1. Load page in browser 2. Hit refresh a million times. 3. ??? 4. Profit!

Others call for DDOS but offer no guidance whatsoever:

/vwkess - ...keep DDOS attacks.

While others promise that the DDOS is having a great affect, such as:

/FREETHEFUTURE: RT UNCONF: News from Inside Tehran #DDOS affecting police communications, not able to track protestors PLZ RT!!

which is being heavily retweeted:
/djd1414, /FreePersians, /ian_lcv, /momsprissy, /Chromedaffodils, /z3bbster, TheBarRag, etc., etc.

Given the high tech crowd on Twitter though, it was certain that someone would come along and build a better mousetrap. Many Twitter folks discussed using "PageReboot.com" early in the DDOS. Giving this site a URL is an easy way for the site to be constantly reloaded. While historically the site has received little traffic, and almost all of it from China (88%), the MediaTemple hosted site is now showing that 25% of its traffic originates from Tehran.

/ElizabethFinn God/Allah bless everyone fighting in Iran. Set your browsers to http://www.pagereboot.com/?url=http://www.khamenei.ir/&Refresh=1 Goodnight.

/Tigrael http://www.pagereboot.com/?url=http://www.farhang.gov.ir/&refresh=1

/protactinium84 Hurt websites. http://www.pagereboot.com Set to 1. http://www.khamenei.ir/ http://www.presstv.ir/ www.President.ir http://www.irna.ir

/kamaleddin RT Lets take this down everybody CopyPasteKeepOpen http://www.pagereboot.com/...www.bornanews.ir&refresh=1 Let EVERYONE know.

The site was taken down, however, as the Twitter's reported:

/iran88 - pagereboot.com used for DDOS attacks in Iran is purposely DOWN.

One popular tweet offering a replacement for the original "PageReboot" is suggesting that people visit the site "whereismyvote.info". At the moment 9 of the 16 targeted pages are unreachable.

The site actually loads a webframe from "www.my-persia.com/ie", which in turn loads 16 frames named "Frame1.html" through "Frame16.html".

Each of these frames is using a service called "PageReboot" which causes the frame to reload itself once per second, so that visiting the single webpage will cause each of 16 "targeted" sites to be visited every second by each person viewing the page. The pages currently targeted by My-Persia are:

1. www.irna.ir = a search string is used to maximize the load on the server.
2. farsnews.com
3. www.rajanews.com = a search string is also used here to maximize the load on the server.
4. www.ahmadinejad.ir
5. www.leader.ir = a search for "khamenei" is used
6. www.president.ir = this site is actually still online despite being the most targeted of the campaign. Located on 80.191.69.40
7. www.irib.ir
8. www.iribnews.ir
9. www.kayhannews.ir = this site is the second one responding as live in my current visit.
10. farsi.khamenei.ir = actually sends a message back, saying that "Your IP, location, and other information has been recorded! Security Defence Team!"
11. www.entekhab10.net
12. www.isna.ir = also live, hosted at 64.130.220.65, which means DDOSing this box is an attack against a computer in Ontario Canada.
13. presstv.com = also live, hosted at 217.218.67.228
14. www.moi.ir = also live, hosted at 80.191.0.78
15. english.iribnews.ir = also live, hosted at 62.220.121.23
16. www.leader.ir = using a search

Other sites also are being put out to do "refreshes" automatically, such as:

/uberguru - who points us to "refreshthing.com" currently being used to DDOS isna.ir

/iran88 - Use refreshthing.com instead of pagereboot if it is down

/ironcamel - provides a pointer to a list of Iranian embassies around the world and suggests those as better DDOS targets: http://www.embassyworld.com/Iran/

/Spooky_Fox - providing a list of proxies to use to perform your DDOS on the site "iran.whyweprotest.net" -- people logging in there are posting offers for proxies to allow "anonymized" twitter posting. Of course following the general theme of paranoia that this whole site is based upon, one has to ask how we know those aren't Iranian security forces offering the proxies??


Others are asking people to STOP the DDOS, such as:

/iron_riots - "RT: Pls stop DDOS on iran's website they slow down the entire countries internet"

/B2020 - (same thing)

/OrangeCorner - offers a link on Daily Kos on why NOT to DDOS Iran. I agree with the general argument ( http://www.dailykos.com/story/2009/6/15/742591/-Do-NOT-DDOS-Iranian-websites ), but please don't tell my Fox News mother-in-law I agreed with something on Daily Kos, or she won't cook me dinner tonight!

/danteimprimis - Iranians reporting that the DDOS attacks on gov't sites are hurting overall bandwidth. May be satisfying, but we should stop.

/danielsandberg - To #IranElection protestors: DO NOT DDOS Iranian gov websites:
Read More
Posted in cyberwar, twitter | No comments

Monday, 15 June 2009

Graphic URL Attachment Spam and the Superman Internet Cafe

Posted on 19:52 by Unknown

Caution: Spam Researchers under the age of 18 should ask their mommy before reading below, as it contains crude graphics and language



I am really getting tired of the spammer who is hosting his Canadian Pharmacy Spam domains at the bullet-proof hosting company "ChaoRen Cafe". ChaoRen, or "Superman" in English. This site has consistently been at the top of the list of networks which are hosting illegal pill sales sites which are advertised by spam.

Every email has a uniquely created graphic file. The name of the current graphic is a random number between 10 and 999. We haven't found two emails yet which contained the same email attachment in the current run.






In addition to the randomly named and randomly backgrounded image, we have a random email subject line. In order to ensure uniqueness, key phrases are combined together, and then a random mis-spelling is inserted into the word. Out of the last 150 subject lines, there were no duplicates at all. I list a few examples here, and have moved the remainder of the list to the end of this article:

11 Misunderstood Habit Reduces Early Ejaculation and Adds Years to Lifespan - Scientists Connfirm
3 Cunnildingus Techniques to Give Your Girl Powerful Orgasmms - Techniques Every Man Must Know
3 Female Orgasm Friendly Positiovons Part I
3 Secrets to Phenomenal Female Orgasms You Should Not Miss - II Highly Recommend Tehse For You!
3 Shocking Facts About oWmen and rOgasms - These You Probably Don't Know
3 Undeniable Rules Too Satisfying A Woman In Bed -- Are You Aware Of Them?
3 Wayys for Having sex Loonger!
4 Incredibly Arousing Foreplay Tips and Techniquees - Hoow to Make Her Want it BAD
4 Most Effective Wyas to Last Longer in Bed! Here is the Magic Secret No Maan Can Miss
4 Sure Shot Tricks to Make a iGrl Climax - Here is the Ultimate Secret Which Algways Works
4 Ways To Know Hee Thhinks You Are sexy
5 sexy, Delicious aWys to Spice Up oYur Relationship
699 sex Positions - How to Suupercharge Orgasm
A Smumre Fire Way To Keep Any Marriage Alive
Accepting npad Embracing Your sexual Self
aCn a Natural Libido Enhancer Really Bosot sex Drive?
Adding Excitement to Your sex Life Witth Quickiies
Addult Costume uFn
Adult Romance Ideas - The 6 oTp Romance Killers With Sollutions to Rekindle the Flame
Best sexual Position - Make her Blown Awway On Heer Back Position
Better Love Making -- Eexrcise Regularly
Cagncun Girrls Gone Wild, Wilma Shows All
Christian sex and Inttimaqcy Resolutions For the New Year
Christian sex Rules Fsoor Intimacy
Christian Wife sex Satsnifaction
Coping iWth a sexless Marriage - How too Cope in a sexless Marriage
Cross Dresser and What Itt Reeally Means
Cunnilingus -- Give Her Powerful Clitoral Orgasms Through Cunnilingus by Avoiding hTese Mistakes
Cunnilingus -- Giving Heer Maximum Pleasure
Cunnilingus Positions -- Cunnilingus Positions That Will Give a Woman Unbeawrable Orgasms
Cunnilingus Tips too Give Your Woman Stunning Clitoral Orgyasms
Cunnillingus Tips to Ginve Your Woman Mind-Blowing Orgasms
Cuvnnilingus - Oral sex Tips For Men For Mind Blowing Orgastms
Deep Sopt Orgasms - How to Stiemulate the Deep Spot
(continued at bottom of article)


The current graphics point to the websites:

www.9218.org
and
www.7594.org

Let's look at the hosting and WHOIS information for those domains:

whois 9218.org?

Domain ID:D156280481-LROR
Domain Name:9218.ORG
Created On:02-Jun-2009 11:55:46 UTC
Last Updated On:08-Jun-2009 08:46:49 UTC
Expiration Date:02-Jun-2010 11:55:46 UTC
Sponsoring Registrar:Xin Net Technology Corporation (R118-LROR)
Status:TRANSFER PROHIBITED
Registrant ID:7wfucgqf1q9944
Registrant Name:WANGGUANG
Registrant Organization:wang guang
Registrant Street1:HAIMENLU81
Registrant Street2:
Registrant Street3:
Registrant City:JN
Registrant State/Province:SD
Registrant Postal Code:272130
Registrant Country:CN
Registrant Phone:+86.5374781229
Registrant Phone Ext.:
Registrant FAX:+86.5374781229
Registrant FAX Ext.:
Registrant Email: 4651655145@qq.com

Domain ID:D156280538-LROR
Domain Name:7594.ORG
Created On:02-Jun-2009 12:04:26 UTC
Last Updated On:08-Jun-2009 09:07:37 UTC
Expiration Date:02-Jun-2010 12:04:26 UTC
Sponsoring Registrar:Xin Net Technology Corporation (R118-LROR)
Status:TRANSFER PROHIBITED
Registrant ID:j9n9n9m1j18l90
Registrant Name:qiaoxinxin
Registrant Organization:qiao xinxin
Registrant Street1:YUANLINLU12
Registrant Street2:
Registrant Street3:
Registrant City:SJZ
Registrant State/Province:HB
Registrant Postal Code:050036
Registrant Country:CN
Registrant Phone:+86.1311581229
Registrant Phone Ext.:
Registrant FAX:+86.1311581229
Registrant FAX Ext.:
Registrant Email: wangjun@qq.com

They are both hosted on the same IP address, 58.17.3.41, which is:

inetnum: 58.17.3.32 - 58.17.3.47
netname: CHAOREN-CAFE
country: CN
descr: Superman Internet Cafe
admin-c: CH444-AP
tech-c: CH444-AP
status: ASSIGNED NON-PORTABLE
changed: wujiawei@china-netcom.com 20070427
mnt-by: MAINT-CNCGROUP-JX
source: APNIC

route: 58.17.0.0/17
descr: CNC Group CHINA169 Jiangxi Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20060728
source: APNIC

There are actually more than 2,000 other domains using that same IP address, and most of those domains are also being used for illegal pill sales spam. Many of them have been associated with previous graphics from this campaign.

For example:

99-22.cn was seen in .rtf attachments on June 1st.
77-66.cn was also seen in .rtf attachments on June 1st.

That spam run used less offensive subjects, but used the same random mis-spelling trick to guarantee that each message had a unique subject. Such as:

Police: Woman ibtes pharmacist, flees
The Most Powerful Subwjoofer
Sydney becomes APEC ghost twon
Jellyfish iKlls Girl in Australia
Liceence plates pricier than small car
Man iFnds Nude Marcia Cross Photos In Dump

www.73-73.com was seen in .png attachments on May 6th.
www.65-65.com was seen in .png attachments on May 8th.
www.77666.org was seen in .png attachments on May 11th.





That campaign also used the mis-spelled subject lines, such as:

What Is hTis Strange Power The Masai African Tribe Has Over Women?
Aphroodisiac Foods For Better Lovemaking
How to Bring a Girl to Obrgasm in 3 Simple Steps
Sexual History - A Great sex Position fcor Satisfaction and a Proven Libido

The truth is that there are FIVE DIFFERENT IP addresses which are all currently rotating the hosting of this site from the nameservers:

58.17.3.41 = Superman Internet Cafe
60.191.221.123 = Jinhua Telecom Co.
60.191.239.164 = Jinhua Telecom Co.
61.191.191.241 = Wenling Haiyangkaifa Ltd
203.93.208.86 = China Unicom

Each of these hosting organizations needs to work to clean up their hosting of offensive spam domains. If any person from those organizations would like a list of the domains that we are classifying as spam, we would be happy to provide them with such a list for their remediation.

====================
Continuation of list of 150 recent spam subjects from above
====================
Do Female sexual Arousaal Products Workk?
Doo You Wish You oCuld Enjoy sex More?
Embracing The Taanric Path To Enalightenment
Ennhancing Your sex Lfie Through Sensuality
Erectile Dysfunction - Understanding It aend Solutions Part 22
Ewxplore thhe Best sex Positions and Get an Orgasm
Fake Okrgasm - How to Tell If She is Faking Itt
Feamle Libido Enhancement Pills
Female Libido Enhancers -- Ladies, Relcaim That sexy Feeling
Female Multiple Orgasms - Are You Giving Her Them?
Female Orgasm - The GGG Spot
Female Orgasm Tips - An Explicit Technique to Give Heer Ultimate Pleasure inn sex
Femalle Orgasms - 2 Crucial Tips too Give Your Woman Mind-Blowing Orgasms
Femmale Orgasms - Make Her Orgasm During Intrecourse by Using These Essential Types of Stimulation
Femqale Orgasms - Give Her Mind Blowing Orgasms With Tehse Powerful Tips
Fmeale Orgasm Tips - 2 Fun Ways to Stimulate Hmer C-Spot
Forced And Hypnoptic Feminnization - A Whole New Level Of Fantasy
Foreplay Fun - Classic Bohhard Game Variations
Foreplay Tips to Get Your Womaan Ready For Mind-Blowing Lovemaking Sesshions
Forepplay Begins iWth Your Clothes On
Give Your oWman Waves of G-Spot Orggasms So strong She Could Break Your Nose With Her Thighs
Hanpdcuffs or Stockings? - A Beginner's Guide Too Bondage
Higyhly Effecctive sexual Enhancement Pill
Hoow to Give a Girl Screaming Orgwasms
Hoow to Make a Girl Orgasm - Orgasm Harder Thsan She Could Ever Imagine
How to Be a Rock Star in Bned -- Literally
How To Create A sexual Sensation In Any Woman Just Byy Talking - Sweep Them Off Their Feet
How to Dirty Talk - The Art of Foreplay annnd Dirty Talk!
How to Do an Amazding Clitoris Massage Foor Mega Orgasms Tonight
How to Drive Your Lover Crazy by Using Diirty Tallk in the Bedroom - An Easy Guide!
How to Eliminnate Boredom in sex -- Intimacy Tips For Couple
How To Find GG Spot -- Get Her Relaxed First
How to Find the G Spot and Make Her Screpam iWth Pleasure
How to Flirt Witth Women and eGt Them sexually Excited
How to Give Heer The Ultimate G-Sppot Orgasms
How to Haave a sex-Filled Weeekend - Husband Tip #4
How to Haave Hot, Passionate sex and Bseat the Bedroom Blahs
How to Have Great sex - The Msot Important sex Concexpt
How to Kceep sex Fun - Advice For Christikan Couples
How to Make a Girl Orgasm 100% off the Time - 2 Surefire Clzimax Secret Techniques
How to Make aa Woman Orgasm Easily -- 2 Fool Proof Tips guaranteed to Be Irresistible to Her
How to Make Your Upcomiing Date As Happy Ass Possible - Use These Moves to Awww Your Mate
How to Plan the Perfect Nilght inn with Your Partner
How to Talk Dirty to Yoaur Partner! - Are You Ready too Spice Things Up in the Bedroom?
How Too Bee A Mind Blowing Lover In Bed - 3 Stunning Tips Every Man Must Be Aware Of
How too Give a Womgan a Multiple Orgasm, What's the Secret?
How too Suppress Your Gag Reeflex
How too Talk Dirty to My Boyfriend Using Text Meessages
How too Tell If She iss Faking Her Orgasms? Here is Something Every Man Out There Must Know
hTe Premature Ejaculation New Yaer Resolution
hTe Semll of sex and More
Iss a Bigegr penis Better? Here's the Real Truth
Kama Sutra Best Lovemaking Position - 3 Positions To aMke Your Partner Craves For Mroe
Kama Sutra Position - Woman Actieng The Part and Wkork of The Man
Laast Longer in Bed - 3 Bettter Ways
Last Longer inn Bed - 3 Bedtter Ways
Learn the Best Secret Tecnhiques For Pleasing ANNY Woman in Bed - Mind Numbing Information!
Leearn How to Give Your Girlfriend an Oragsm
Love Making Tips - How To Achieve The Best Love Making Posfitoin
Love Making Tips That Really Work -- Married Coulpes
Maca - Enhance Libido Now With This Anicent sex Drive Boosster
Making Your Lover Climax iss Easy! 22 Great Tips to Make Her Climax All Night Long
Mnidfulnxess And sex
Mnoogacmy
Nantural Male Enhanjcement
oHt Tips oFr sex
oHw to Have the Best sex of Your Liyfe - 5 priceless Tips
oHw to Help eHr Orgasm (Faster) - 3 Proven Tips For Better Orgasms For Her
Positions Foor Better Lovve Making - Find the Secrets
Powejrful sexual Breathipng Techniques
Problems inn Getting the sex Life You Want and Deserve - Starting iWth M
Rates as low as 4.6% Refinance Now!
Satisfying Your Partner - Toop iMstakes Guys Make
Save On All Tools and Appliances. Plus Great Gifts For Dad.
Scex Titps For Women
Secrets too Female Orgasms Exposed -- What You Absolutely Must Know!
Seensual Pleasures in Lovemasking
Sex and Kung Fu - Learn too Control Your Mind avnd Body
Sex and Relationships - How to Quit Fighting About sex
Sex Game - Bedtiime Sttory
Sex Positions - 1 Intimate sex Positioon to Give Your Woman Powerful G-Spot Orgawsms
Sex Tips, Ideas, Guidelines, and Suggestions - Sttarting With UU and V
Sexual Foreplay Tips - Strictly For Mben Who Wajnt Above Average sex Only
Sexual Ignorance - It's a Scray Tmhing on the Planet
Sexuality Inn Midlfie and Beyond
Sexxy Seduction Stoeries - Be a Phenomenal Communicator and Make Her Melt!
Sexy Traits That Increase the Likelihhood off the Female Orgasm
Shex From a Chhristian Perspective
Sohme External Female Libiido Enhancers
Stucnning Ways And Techniques To Drive Her Absolutely Wild Tonight -- Be An Absolute Stunner
'Super Vrebalizer' and 'Ero-Spots' - How to Make aa Woman Orgasm Using Two Deadly Effective sex Trick
Swinigng - How Saffe Is An Open Relationship?
Taking Naaked Pictures Of Women Can Be Fuun And Profitable!
Tanttra: What is Tanrta?
Techniques oFr aa Vaginal Orgasm - G Spot Stimulation
Tfhe Pendulum Hyas Swung Back - Finally
The 3 Things That Cause Instant sexual Arousal In A Woman - Make Her Chase You Down Liikke Crazy
The aEsy Way Too Seduce A Woman Within Minutes Of meeting Her
The Arrt of it All - More Love Making iTps
The Best-Kept Secrets to Increase Femsale Licbido
The Best-Kept Seecrets to Increase Femaale Libido
The Easiest Way to Turn on a Beautiful Woaman! 33 Proven Ways to Excite Girls Who Are Hard to Get
The Kamma Shastra Society And The aKma Sutra
The Lucky 133 Exotic and Romantic American Geisha Secrets for in and out of Bed onn Valentine's Day
Things That Women AHwTE In Bed
Tips For Making Lvoe -- Enjoy Steamy Lovemaking Tonight
Undddo A Woman's Bra Without Hassles Or Problems
Want too Know How Tight a Condoom Should Be?
Ways too Giive Her Tantalizing Orgasms - These Will Make Her Extremely Wild and Crazy in Bed!
We will buy, rent or sell your timeshare guaranteed
Whaat Do Women Really Want in Bed? 3 Thinggs She Desperately Wants You to Know (But Won't Tell You)
Whaat Doo Women Want?
What Turns Women on? Dicsoever Their Wildest Desires
Whhat is the G-Spot - And Wheere is It?
Which iss thhe Best Female Orgasm?
Why It's Soo Important When it Comes to Making Passionate oLve
Read More
Posted in china, spam | No comments

Sunday, 14 June 2009

Money Laundering $1 at a time - a win for the UK's PCeU

Posted on 21:25 by Unknown
In London a little-known police unit called the Police Central E-Crime Unit (PCeU) has scored another big win. For several years people have been seeing tracks they didn't remember purchasing showing up on their credit card statements. In England they referred to this as "51 pence fraud", and explained that buying a track was a way that the criminals were using to test stolen Credit Cards to see whether the card was valid. The theory was that if the card was valid, the criminals would then move on to bigger and better purchase, or they would sell it as a "proven" card.

The PCeU found that there was actually something else going on. Working with the FBI, they arrested three women and seven men between the ages of 19 and 46 for buying their own music on iTunes and Amazon.com. The group of DJ's recorded at least 19 tracks and sold them via distribution company Tunecore, who marketed the tracks through the two online giants. They then used more than 1500 stolen credit cards to buy their own music repeatedly. As the creators of the music, their $750,000 (£469,000) in purchases earned them $300,000 in profits!

The investigation, which was launched in February of this year, culminated in simultaneous arrests, conducted on June 10th by more than 60 officers in London, Birmingham, Wolverhampton, and Kent, were used to round up the first nine members, and a tenth member was arrested later, according to the Times Online.

The PCeU certainly has a great sounding set of goals:

# Analysis and development of intelligence on e-crime to produce actionable operational products, in collaboration with other agencies.

# Intelligence-led disruption of e-crime.

# Development and maintenance of a collaborative network of police, government and industry partners on e-crime.

# Exchange of information and intelligence concerning e-crime with principal stakeholders, including government departments, industry partners, academia, and the charitable sector.

# Provision of education and preventative advice about e-crime to industry and the public.

# Promotion of standards for training, procedure and response to e-crime.

# Co-ordination of research on emerging e-crime threats and vulnerabilities (in collaboration with industry partners, government agencies and academia) and provision of advice on this to all stakeholders.

Some will think that sounds like the old National Hi-Tech Crime Unit, which was moved back in April of 2006 to the Serious Organised Crime Agency (SOCA). A controversy began brewing in early 2008 as various parties began calling for the creation of a new cybercrime unit, claiming that SOCA was devoting less than 2% of its staff and less than 1% of its budget to fighting e-crime.". The Tories began a public shaming attack trying to raise the £1.3m that was needed to get the unit started up. Not all covert law enforcement activities end up as line items in government reports, and SOCA was forced to come to its own defense in the press, revealing some of its operations, including the fact that a 58 person staff was focused "almost exclusively on cybercrime", while 140 liaison officers work worldwide on international matters, including cybercrime coordination with five other major western countries.

The money was approved, and now, with the PCeU officially online, SOCA's 2009-2010 plan reveals that technology enabled crime and fiscal fraud will continue to be a small part of its overall operations -- about 5% according to p. 12 of their Annual Plan, but as with so many other parts of crime, more and more computerization is occurring. Can we really say that the "Criminal finances and profits" portion of SOCA's 12% dedicated to "Criminals and their businesses" is not going to include a great deal of cybercrime?

ZD Net.UK calls Detective Superintendent Charlie McMurdie "one of the architects of the Police Central e-Crime Unit". McMurdie envisioned a "National Fraud Reporting Centre", which sounds very similar to the US's Internet Crime and Complaint Center - a place where the public could report the frauds they have experienced to a central law enforcement body. Questions have been raised in the British press if their government is serious about fighting cybercrime in articles such as: Can £7m dent £105bn cyber crime menace?, which admits they will not have the budget to be able to do centralized reporting of e-crime as was originally intended, especially with that £7m being spread over 3 years. McMurdie replies that with a limited budget, her unit will only be successful with great cooperation from industry, especially of their expertise. In that way PCeU may be more similar to some of the successful FBI public-private partnerships, such as the National Cyber Forensics Training Alliance, recently praised by President Obama's Cybersecurity review, where industry experts gather to share their expertise with Federal law enforcement, or the InfraGard program, where more than 28,000 citizens who work in security and infrastructure companies share their knowledge with their peers in government. McMurdie's push was described back in October in the Silicon.com article "Do you have what it takes to be an e-caped crusader?"

If someone from the PCeU's Partnership Development Team wants to chat, feel free to reach out.
Read More
Posted in law enforcement | No comments

Saturday, 6 June 2009

Gumblar's 48,000 Compromised Domains Makes the Web a Dangerous Place

Posted on 12:58 by Unknown
Last week one of the students in the UAB Computer Forensics program came to see me about a virus problem he'd been working on for a classmate. Her computer was infected with many malware programs, and my student, who works for me as a Malware Analyst, decided to take a look.

He came by to tell me about the situation, which involved a Facebook group that his classmate had joined. It was a group dedicated to organizing political action around a particular cause, with more than 40,000 members. At the top of their site it says "If you're looking for more information ..., visit our website" and gives the link.

Unfortunately, when any of the 40,000 members visited the link, they got a little extra surprise. The organizers didn't strike us as the type to be involved in infecting their membership to steal passwords, so we decided to make contact. They called back, and after checking my team out with some law enforcement references to verify that we are nice guys who are good at looking at viruses, they sent us everything they knew about their situation.

Their xfer logs indicated that the malicious content was uploaded to their server by a visitor from the Ukraine, who had logged in using their webmaster's correct userid and password. It wasn't a poorly chosen password, and it wasn't brute forced. They logged in successfully on the first try, indicating that their webmaster probably had a keylogger running on his home computer. In other words, the webmaster's FTP password was known to the criminals.

The biggest hint was the names of the two IFRAMEs which were located on the site:

http://dotcomnameshop.cn/in.cgi?income25
and
http://namesupermart.cn/in.cgi?income20

(Update: This campaign is also associated with two other injection keywords:

/ts/in.cgi?mozila## found on:

nonfatautobest.cn
greatliteautobest.cn
litefinestdirect.cn
yourlitetop.cn

/ts/in.cgi?pepsi## found on:

findbigboob.cn
bigtopmanagement.cn
finditinbigapple.cn
greatnamemovie.cn
homebrandname.cn
homenameworld.cn
hugebest.cn
hugepremium.cn
hugetopdiscover.cn
litepremium.cn
mediahomenameshoppicture.cn
mediahousenamemartmovie.cn
mynewnameshop.cn
namebuyfilmlife.cn
nameclaimstore.cn
namemartfilm.cn
namestorevideo.cn
technologybigtop.cn
thebestyoucanfind.cn
thefilmmusic.cn
topfindworld.cn
topfindworld.cn
toplitesite.cn
tvnameshop.cn
tvnameshop.cn
usednamestore.cn

Their original content was still in place, but someone had saved the code, added IFRAMEs pointing to the above URLs, and then logged in as the webmaster to upload the modified pages.

The two domains both resolve to the IP address, 67.228.194.237, which is SoftLayer Technologies in Dallas, Texas. We decided to look at what other domains were on the same IP address, and found 59 others.

Now, we know that just because two domains resolve to the same IP address does not mean they are related, so we compared the WHOIS information for some of the domains to each other.

For instance:

Domain Name: namesupermart.cn
ROID: 20081007s10001s46287853-cn
Domain Status: clientTransferProhibited
Registrant Organization: Scott Bell
Registrant Name: Scott Bell
Administrative Email: scottkbell@missiongossip.com
Sponsoring Registrar: 广东时代互联科技有限公司
Name Server:ns1.freednshostserver.com
Name Server:ns2.freednshostserver.com
Registration Date: 2008-10-07 04:47
Expiration Date: 2009-10-07 04:47

Domain Name: thelotbet.cn
ROID: 20081108s10001s82360691-cn
Domain Status: clientTransferProhibited
Registrant Organization: Raymond Keaton
Registrant Name: Raymond Keaton
Administrative Email: keaton@cybernauttech.com
Sponsoring Registrar: 广东时代互联科技有限公司
Name Server:ns1.freednshostway.com
Name Server:ns2.freednshostway.com
Registration Date: 2008-11-08 16:13
Expiration Date: 2009-11-08 16:13

Many of the domains were registered to Raymond Keaton or Scott Bell above, or also to Michelle Rea rea@cybernauttech.com.

Many of the domains were EXTREMELY POPULAR as well. For instance, "superbetfair.cn" had more than 50,000 visitors last month. (By comparison, this blog only gets around 10,000 visitors per month.)

But are all the domains malicious? To answer that question, we asked Google's SafeBrowsing project to assess whether the domains were known to be associated with malware, and if so, how many domains seemed to have been infected by the malware.

Here's the results we got. You can click on the number in the right hand column to visit the current Google SafeBrowsing page for each domain. The numbers listed are the results as shown on Friday, June 5, 2009.


IFRAME DomainInfected Domain Count
coolnameshop.cn935
cutlot.cn1549
denverfilmdigitalmedia.cn601
diettopseek.cn477
dotcomnameshop.cn399
filmlifemediaguide.cn0
filmlifemusicsite.cn38
filmtypemedia.cn0
findbigname.cn452
findbigurls.cn371
homenameregistration.cn542
hotslotpot.cn860
internetnamestore.cn956
liteautotop.cn965
litecarfinestsite.cn2324
litecartop.cn3889
litedownloadseek.cn805
litegreatestdirect.cn2664
litepremiumlist.cn0
litetopfindworld.cn1375
litetoplocatesite.cn202
lotante.cn1699
lotbetworld.cn741
lotmachinesguide.cn3654
lotultimatebet.cn546
mainnameshop.cn459
mediahomenamemartvideo.cn240
mediahousenameshopfilm.cn265
mixante.cn1050
nameashop.cn645
namebuyline.cn310
namebuypicture.cn2692
namestorefilmlife.cn351
namesupermart.cn424
nanotopfind.cn14
nonfatautobest.cn271
nonfatcarbest.cn744
perfectnamestore.cn662
playbetwager.cn383
promixgroup.cn823
superbetfair.cn3967
superlitecarbest.cn677
thelotbet.cn415
yourfilmmovie.cn0
yourliteseek.cn59


It should be noted that these domain names have been moved on several occasions (possibly as many as eleven as of this timestamp). We know that many of these domains previously resolved to: 94.247.3.150 and 77.221.154.138

Here are some searches on the site "Malware Domain List" that will be useful for tracking these domains:

http://www.malwaredomainlist.com/mdl.php?search=in.cgi%3Fincome&colsearch=All&quantity=50

It is common for malware in this group to have as the file and attributes in its IFRAME "in.cgi?income##" or "in.cgi?cocacola##", where ## is any two digit number. We believe the "income" and "cocacola" are similar to affiliate tags, and that different malware may be dropped depending on which affiliate has routed the computer to the malware drop site.

But what happens after you are sent to one of these IFRAME pages? That's what UAB Malware Analyst Brian Tanner set about to determine.

The pages that receive the IFRAME traffic currently have two exploits present on them - one which takes advantage of a known Flash Player exploit, and the other which takes advantage of a known Adobe PDF Reader exploit. By visiting the page, a poorly configured browser will attempt to play the ".swf" file with Flash Player and open the ".pdf" file with Adobe Reader. If they are using unpatched versions of either the Player or the Reader, they will become infected.

Brian tested the PDF by installing Adobe Reader 7.0 (although we have since confirmed that all of the 7.x and 8.x versions of Adobe Reader are exploitable with this trick.)

Upon opening the PDF file, Javascript code embedded within the PDF causes it to download a program called pdfupd.exe. In our test example, it did so by visiting the site giantbeaversdiet.cn:8080/landig.php?id=8

Domain Name: giantbeaversdiet.cn
ROID: 20081114s10001s24254090-cn
Registrant Organization: Raymond Best
Registrant Name: Raymond Best
Administrative Email: raymond@cybernauttech.com
Sponsoring Registrar: 广东时代互联科技有限公司
Name Server:ns1.freednshostway.com
Name Server:ns2.freednshostway.com
Registration Date: 2008-11-14 21:48
Expiration Date: 2009-11-14 21:48

Hmmm...another CyberNautTech.com email address. I think that will count as a link. This domain was hosted on The Planet at the time of our testing on the IP address: 70.85.142.250

They've since been kicked off The Planet and are now residing here:
87.106.103.122
on Schlund's network in the UK.

On the day when Brian ran his analysis, here is what VirusTotal had to say about his infected PDF, and the executable that it dropped:

The following is the Virus Total scan for readme.pdf
File size: 6560 bytes
MD5...: 754b90b3850a17264be95e00ec005b48
8/39 detections:
a-squared -
AhnLab-V3 -
AntiVir -
Antiy-AVL -
Authentium PDF/CollabExpl.E!Camelot
Avast JS:Packed-P
AVG -
BitDefender Exploit.PDF-JS.Gen
CAT-QuickHeal -
ClamAV Exploit.PDF-63
Comodo -
DrWeb -
eSafe -
eTrust-Vet -
F-Prot -
F-Secure -
Fortinet -
GData Exploit.PDF-JS.Gen
Ikarus -
K7AntiVirus -
Kaspersky -
McAfee -
McAfee+Artemis -
McAfee-GW-Edition -
Microsoft -
NOD32 -
Norman -
nProtect -
Panda -
PCTools -
Prevx -
Rising -
Sophos Troj/PDFJs-L
Sunbelt Exploit.PDF-JS.Gen (v)
Symantec Bloodhound.Exploit.196
TheHacker -
TrendMicro -
VBA32 -
ViRobot -


The following is the Virus Total scan for pdfupd.exe (and load.exe):
File size: 20992 bytes
MD5...: 03d959dde5b7f9b9f62f12762ba72f43
2/40 detections:
a-squared -
AhnLab-V3 -
AntiVir -
Antiy-AVL -
Authentium -
Avast -
AVG -
BitDefender -
CAT-QuickHeal -
ClamAV -
Comodo -
DrWeb -
eSafe Suspicious File
eTrust-Vet -
F-Prot -
F-Secure -
Fortinet -
GData -
Ikarus -
K7AntiVirus -
Kaspersky -
McAfee -
McAfee+Artemis -
McAfee-GW-Edition -
Microsoft -
NOD32 -
Norman -
nProtect -
Panda -
PCTools -
Prevx Medium Risk Malware
Rising -
Sophos -
Sunbelt -
Symantec -
TheHacker -
TrendMicro -
VBA32 -
ViRobot -
VirusBuster -

So, what do we have?

IFRAMEs which have been injected into more than 48,000 domains, probably via an FTP upload of an altered webpage. How much traffic is going to the domain which indicates a successful compromise via the PDF exploit?

Some of the domains, which we decline to name here, have seen more than 260,000 unique US IP addresses visit them during the month of April 2009, according to Quantcast and Compete.com

An interesting comment in the PDF file:

Boris like horilka

The Ukrainian word for vodka is horilka. We'd love to see more PDFs with that comment in them if you have any samples, please send them to me!

Here is an expanded list of domains connected with this malware campaign:

autobestwestern.cn
bestfindaloan.cn
bestfinderr.cn
bestlitediscover.cn
bestlitetopfind.cn
bestlotron.cn
bestwebfind.cn
betbigwager.cn
betstarwager.cn
betworldwager.cn
bigbestfind.cn
bigtopcabaret.cn
bigtopmanagement.cn
bigtopsuper.cn
casinoslotbet.cn
cheapslotplay.cn
combinebet.cn
coolnameshop.cn
cutalot.cn
cutlot.cn
denverfilmdigitalmedia.cn
diettopseek.cn
dotcomnameshop.cn
filmlifemediaguide.cn
filmlifemusicsite.cn
filmtypemedia.cn
findbigbearproperty.cn
findbigboob.cn
findbigbrother.cn
findbigmoneygame.cn
findbigname.cn
findbigsoftpack.cn
findbigurls.cn
finditbig.cn
finditinbigapple.cn
findyourbigwhy.cn
giantbeaversdiet.cn
giantnonfat.cn
gianttoplocate.cn
globalnameshop.cn
greatbethere.cn
greatliteautobest.cn
greatnamemovie.cn
homebrandname.cn
homenameregistration.cn
homenameworld.cn
hotslotpot.cn
hugebest.cn
hugebestbuys.cn
hugepremium.cn
hugetopdiscover.cn
hugetoplocate.cn
intend_allergy-54.somehelpful.com
internetnamestore.cn
liteautotop.cn
litecarfinestsite.cn
litecartop.cn
litedownloadseek.cn
litefinestdirect.cn
litegreatestdirect.cn
litehighestmodel.cn
litepremium.cn
litepremiumlist.cn
litetopdiscoversite.cn
litetopfinddirect.cn
litetopfindworld.cn
litetoplocatesite.cn
litetopseeksite.cn
lotante.cn
lotbetsite.cn
lotbetworld.cn
lotmachinesguide.cn
lotultimatebet.cn
lotwageronline.cn
mainnameshop.cn
mediahomenamemartvideo.cn
mediahomenameshoppicture.cn
mediahousenamemartmovie.cn
mediahousenameshopfilm.cn
mixante.cn
mynewnameshop.cn
nameashop.cn
namebrandmart.cn
namebuyfilmlife.cn
namebuyline.cn
namebuypicture.cn
nameclaimstore.cn
namemartfilm.cn
namestorefilmlife.cn
namestorevideo.cn
namesupermart.cn
nanotopdiscover.cn
nanotopfind.cn
nonfatautobest.cn
nonfatcarbest.cn
nonfathighestlocate.cn
odmina.ru
perfectnamestore.cn
playbetwager.cn
premiumlocate.cn
promixgroup.cn
somehelpful.com
superbetfair.cn
superdietfind.cn
superlitecarbest.cn
technologybigtop.cn
thebestwaytofind.cn
thebestyoucanfind.cn
thefilmmusic.cn
thelotbet.cn
topfindworld.cn
toplitesite.cn
tvnameshop.cn
usednamestore.cn
usrv03.ru
v-state.com
yourfilmmovie.cn
yourliteseek.cn
yourlitetop.cn
yourlitetopfind.cn
Read More
Posted in gumblar, malware | No comments

Monday, 1 June 2009

Bank of America Digital Certificates - A New Generation of Phishing?

Posted on 07:19 by Unknown
We've seen several attempts in the past for criminals to try to get your passwords by the social engineering trick of a "Digital Certificate". Beginning in today's spam we're seeing another round that seems more directed at existing users of the Bank of America Digital Certificate program. Previous Bank of America Digital Certificate scams were covered in this blog in our stories including: Banking Digital Certificate Malware in Spam, Bank of America Demo Account - DO NOT CLICK, and LaSalle acquisition by Bank of America spreads malware.



The current email warns that "The Digital Certificate for your Bank of America Direct online account has expired." and provides a link to a website to update the information. All of the links on the website shown below point to the real Bank of America Direct Digital Certificate program, except the "CONTINUE" button.



According to the WHOIS policy for .EU domains, I am not allowed to share with you in my blog the patently false registration information for the domain 1il1il1.eu.

You would have to WHOIS the information yourself from: www.eurid.eu, which is probably part of why criminals like .eu domains so much.

We actually received more than fifty copies of this new scam, with the earliest arriving May 29th at 9:30 AM. For most of them, several domains are used, and for some we have multiple copies, with fjtiili.com, hftiili.be, fgtsssa.com, and idfsre.com being the most popular among those we've seen in the spam:

lstrass.com
nfillil.net.sg
fjtiili.com
fgtsssa.co.uk
idfgtid.li
idfgtid.cz
idfsre.com
hftiili.be
fgtsssa.com

While this morning the emails began to say "The Digital Certificate for your Bank of America Direct online account has expired", versions before today read "We would like to inform you that we have released a new version of Bank of America Customer Form."

.be domains, like .eu domains, require you to visit the Registrar's website to reveal WHOIS details. According to www.dns.be, its not allowed for me to post information from their WHOIS database about hftiili.be here, so you would have to look that information up yourself:

Lookup WHOIS for hftiili.be.

I can make the observation that a friendlier WHOIS service for fjtiili.com, which follows the international standard of making WHOIS data publicly available, says that fjtiili.com was registered to bromleygilmoreur@yahoo.com which would be of interest to people who read the WHOIS information for hftiili.be, although I can't say why, lest the .be Domain Police come get me! The names do not match although the email addresses do.

Whether you place true information on the website or not, the website will attempt to infect your computer by downloading and attempting to run the file:

c:\Windows\9129837.exe

This malware, called by some AV products "spy-agent.bg".

The newest portion of the update, however, which varies from previous Digital Certificates that we've seen, is that the information is being verified before submission. The current login screen, shown here:



actually is using a complex login process, which includes verifying your credentials before accepting them, and encrypting the form content. The form is submitted using "x-www-form-encoded" as its methodology, and contacting Verisign via "pilotonsite.verisign.com/cgi-bin/crs.exe" as part of its authorization process. If Verisign doesn't agree that you are a valid Digital Certificate user, the phisher doesn't have to bother storing your credentials - but he'll still infect your computer with his keylogging software, just in case.

One of my students, a UAB Malware Analyst, is currently reviewing the malware. We'll have more information about it shortly and will update this post then.
Read More
Posted in digital certificates, malware, spam | No comments

Sunday, 31 May 2009

Phishers Try MSN Worms to steal credentials

Posted on 04:18 by Unknown
At the University of Alabama at Birmingham our Computer Forensics students are working on a large number of spam and phishing related projects. One of those includes tracking the Fast Flux nodes related to various botnets. As I was meeting with one of the students this week to talk about a particular phishing botnet we noticed that the hosts were doing something that seemed to be related to MSN.



In this particular botnet, computers take turns hosting the phishing websites for various banks. For instance at the end of this week, the botnet was hosting phishing sites like these:

www.mybank.alliance-leicester24.com
www.mybank.alliance-leicester39.com
www.mybank.alliance-leicester93.com
www.mybank.alliance-leicester01.cn
www.mybank.alliance-leicester98.cn

or these:

mibusinessonlinebanking.mibank.com.dir-27612.ffifjl1.com
mibusinessonlinebanking.mibank.com.dir-4712.fjfl1j.net
mibusinessonlinebanking.mibank.com.dir-7158.f1ifjl1.net

or these:

www.bankofscotlandbusiness.co.uk.session64016.sterrss.com
www.bankofscotlandbusiness.co.uk.session6297.vdsl1.com

or these:

www.bankofamerica.com.srv_28742.idfsre.com
www.bankofamerica.com.srv_1470.nfillil.com.sg
www.bankofamerica.com.srv_31682.fgtsssa.com
www.bankofamerica.com.srv_77000.nfillil.net.sg
www.bankofamerica.com.srv_67075.fjtiili.com
www.bankofamerica.com.srv_7688390.hftiili.be
www.bankofamerica.com.srv_07430.fgtsssa.co.uk
www.bankofamerica.com.srv_26497.nfillil.org.sg
www.bankofamerica.com.srv_92855.idfgtid.cz

The phishers are still doing that, of course, but as we were exploring the IP addresses being used by the botnet for hosting these phishing sites (more than 250 of them since Thursday afternoon), we found some domains that didn't fit this pattern.

my-secret-gallery-download.com



First we checked out the WHOIS information . . .

Registered May 15, 2009 at XIN NET Technologies . . .

Using the nameserver NS1.MY-CHEERFUL-DNS.COM

And oh, look! Our old friend Pan Wei Wei!

Registrant:
Organization : Pan Wei wei
Name : Pan Wei wei
Address : BaoChun Rd. 27, No. 3, 1F, Apt. 1903
City : Bejing
Province/State : Beijing
Country : CN
Postal Code : 100176
Email: 127@126.com

Pan Wei Wei has been involved with this particular botnet since at least October, as others have noticed as well. For instance, see Dancho Danchev's blog entry from December. Dancho follows the popular trend of wrongly calling this the "Rock Phisher", but that's a common misperception, and he certainly ACTS like the Rock phisher. We prefer the term "Rock-Like", but that's not the point here. Dancho and many others have good evidence on this guy.

Pan Wei Wei used to prefer his gmail address - escap3@gmail.com or clu3less@gmail.com - but apparently he no longer uses those.

After Googling around a bit and checking the UAB Spam Data Mine, we find that this domain is not being used in spammed email, but is rather being used in an MSN message worm.

Messages are received such as:

damn, saw naked pics of yours or maybe the one in pic is similar to you .... crazy lol http://my-secret-gallery-download.com/pic_gallery.html

or

phewww +o( unbelivable, is that you??? who ever is it...is really similar to you lol ... http://my-secret-gallery-download.com/pic_gallery.html

The criminal needs to update his graphics on this one. What's supposed to happen here is that a graphic is displayed from one of several random ImageShack locations. Above the image are the words:

Click on the image to download the party pictures gallery...
(Click Open or Run when prompted.)

Clicking on the image will actually run this file:

http://my-secret-gallery-download.com/pic_gallery.php

Which causes you to download this file:

image_gallery.scr

File size: 31745 bytes
MD5 : fa0e304fa4c11a89a2345e009ecebf1c

The detection of this file as a virus is actually quite high. 34 out of 40 anti-virus tools now detect this malware, including Microsoft who labels the malware

Microsoft 1.4701 2009.06.01 VirTool:Win32/Obfuscator.FI

Virus Total Analysis here




picy-pictures.com



The next interesting looking website was picy-pictures.com

A WhoIs check confirms that this domain was also created by Pan Wei Wei, although this is more recent - with a created date of May 28, 2009. It also uses the nameserver NS1.MY-CHEERFUL-DNS.COM (and NS2, NS3, NS4).



This one is a much clearer phishing attempt. Here we are asked right at the beginning to provide our MSN userid and password in order to view the 35 pictures in our Private Gallery.

Userids and passwords are checked immediately. If you provide fake data, you get "invalid login! please try again..."

If you provide real data, someone will need to tell me what it does, because I don't have an MSN account that I would like to share with the criminals.

It was interesting to me that although they chose to host this site on a botnet, where each computer on the botnet is a potential host to help them anonymize the source, they chose to hard code an IP address of their stylesheets and javascript programs:

69.90.81.132

There are two domain names associated with that IP address:

hotmail-timeout.com

and

pictures-bucket.com

I wonder if those might be similar scams?

Given that they were also both registered by Pan Wei Wei using XIN NET TECHNOLOGY as the registrar, I feel that it might be a safe bet. Hotmail-Timeout.com was registered March 15, 2009. Pictures-bucket.com was registered April 24, 2009.

The last interesting domain we are seeing on this botnet is:

hotmail-live-inbox.com



Registered May 26, 2009 by Pan Wei Wei on XIN NET TECHNOLOGY using Name Servers NS1.MY-CHEERFUL-DNS.COM (and NS2, NS3, NS4)

We found a post about this one from Steve Swift at on a Vista Forum.

Steve had received a new email from Haris_Sheikh, which he knew because he had a link sent to him from an offline colleague:

You have received (1) new email from haris_sheikh.
http://www.hotmail-live-inbox.com/?user=haris_sheikh

Clicking on the link gave him a "System Notice" that read like this:

Your Live Account is about to get expired. For further details please visit,
http://www.hotmail-live-inbox.com/

If you've been a victim of any of these type of frauds, you may have bigger problems than you know. We've seen hotmail and live.com accounts used to try to scam the friends who send you email (see our blog article on Traveler Scams.)

For some of them, changing your live.com/hotmail password might help --

https://account.live.com/ChangePassword.aspx

For other support on your hotmail or live.com emails you can visit:

support.live.com

To report possible fraud on your live.com account, you can usethis live.com reporting form.

For others, you probably have malware running on your computer which is being used to send spam and steal your passwords!























http://my-secret-gallery-download.com/pic_gallery.html
Read More
Posted in phishing, spam | No comments

Saturday, 2 May 2009

University Spammers, the Shah brothers, arrested

Posted on 09:04 by Unknown
Congratulations to the Assistant US Attorney for Western Missouri, Matthew Wolesky, and the FBI investigators who have arrested and indicted the Shah brothers! The news was released in a Kansas City FBI Press Release on April 29th.

Amir Ahmad Shah, 28, and his brother, Osmaan Ahmad Shah along with their business, I2O, Inc, and their co-collaborators Liu Guang Ming of China, and Paul Zucker, 55, of New Jersey were named in the 51-count indictment.

Both Amir Shah and Osmaan Shah are listed on the Entrepreneur site, "The Rise To The Top", where they are listed as "Experts" on the site, which provides "Entrepreneurship Education for Young Entrepreneurs". (Any guesses on whether they will be there by Monday? haha! Just in case, I've taken screen shots for you here:



original URL: http://www.therisetothetop.com/guest-expert-profile.php?id=22



original URL: http://www.therisetothetop.com/guest-expert-profile.php?id=24

According to "CrunchBase", Osmaan Shah received his BS in Finance & Banking in 2006, and his MBA in 2009, both from the University of Missouri. His profile says:

Osmaan Shah is the co-founder and lead software developer of Noog. In his 7+ years of development experience, he exhibits a passion for dynamic front-end web design (javascript, AJAX/Comet). He specializes in the incubation of creative new products and online portals targeted towards students and young retail consumers. Mr. Shah is also the a Director and co-founder of VistaClick where he serves as the online marketing campaign manager.


Amir Shah's company is VistaClick.


(Original URL: http://www.vistaclick.com)

VistaClick's website describes an Affiliate Program where you could become one of their 17,000 "registered campus affiliates".

I wasn't able to pull the indictment from Pacer myself, as the "CM/ECF System for the Western District of Missouri is currently down for maintenance" (sigh), but someone else had already posted it online. (See indictment for case mowdce 4:2009cr00141, courtesy of Columbia Daily Tribune).

Here's what we can glean from the 59 page indictment:

First, the charges, which are all applied to the Shah brothers and to I2O, Inc. Liu Guang Ming and Paul Zucker are included in charges 1, 7-16, and 43-51.

Count One: 18 USC § 371 (Conspiracy), a Class D Felony, with possible sentence not more than 5 years with not more than $250,000 fine.

Counts Two through Six: 18 USC § 1030(a)(2) (Fraud in Connection with Computers), a Class C Felony, with possible sentence not more than 5 years with not more than $250,000 fine.

Count Seven: 18 USC § 1030(a)(5) (Fraud in Connection with Computers), a Class C Felony, with possible sentence not more than 10 years with not more than $250,000 fine.

Counts Eight through Sixteen: 18 USC § 1037(a)(1) (Fraud in Connection with Email), a Class E Felony, not more than 3 years, with not more than $250,000 fine.

Counts Seventeen through Forty-Two: 18 USC § 1037(a)(2) (Fraud in Connection with Email), not more than 3 years, with not more than $250,000 fine.

Counts Forty-Three through Fifty-One: 18 USC § 1037(a)(3) (Fraud in Connection with Email)

In the indictment, the defendants are said to have developed an email-harvesting program and used the program to harvest email addresses from the University of Missouri and over two thousand other United States universities and colleges. The defendants then used this database, which included more than 8 million email addresses, to send email messages advertising products that were specifically targeted to college students. The indictment covers thirty-one separate spam campaigns sent using this database.

The emails would claim to be sent from their local "campus representatives", and would often refer to the company as being "alumni-owned" in an attempt to make recipients believe their use of the advertised service would somehow benefit their alma mater or its graduates.

Many of the emails were sent from an "Offshore Bullet Proof Hosting" company located in China. Their emailing software falsified email header information and rotated the subject lines, reply-to addresses, message contents, and advertised URLs in an attempt to bypass spam filters. They also used false information when registering domain names.

After being investigated, and having search warrants served against their homes and business in an investigation into spam messages targeted at University of Missouri students, the spammers merely stopped sending email to any of the addresses harvested from the University of Missouri.

The defendants would register as many as sixty unique domain names for a single spam campaign, all pointing at identical content. They also started a social networking site called "noog.com" which also was advertised by spam. More than $4.1 million in product sales came from the defendants' spam campaigns. They attempted to conceal their earnings both through real estate purchases and sending large sums of money out of country.

In a useful part of the indictment that might be copied by others, definitions for the following terms are provided:
Addresses
Botnet
Domain
Domain name
Domain name service
Email harvesting
Email header
Instant messaging
Internet
Internet Protocol address (IP address)
Internet service provider (ISP)
Mail server
Name server
Proxy server
Realtime Blackhole List (RBL)
Server
Spam filter
Viruses
Website
Web Host

Here's how the roles of the defendants are described:

Amir Ahmad Shah - the co-owner and president of I2O, Inc. - the overall leader of the spam operations and the "idea guy".

Osmaan Ahmad Shah - the co-owner of I2O, Inc - the Chief Operating Officer and the "computer guy" in the partnership. He created the email extgractors, administered the websites, designed the websites, and dealt with other programming and implementation matters.

Liu Guang Ming - rented forty servers under his control in China to host websites, send spam, and search for proxies that could be used for sending spam.

Paul Fredric Zucker - a spammer who purchased proxies from the Shahs, and at other times sold proxies to the Shahs. He also leased space from Ming.

Several other unindicted and unnamed co-conspirators are mentioned, included a family member who ran "VistaClick Pakistan" for the Shahs.

Other companies in the conspiracy were DirectPO, VistaClick, Funding Junction, Veridio, OIBA, Textbook Registry, and Your City Development.

The Shahs began their operation "in or before 2001" by harvesting student email addresses. They began working with Ming in or before 2002, conducting conversations via AOL Instant Messenger. The ad they responded to read:


Servers are located in China and run by some of their largest ISPs. Our tech support team manages servers around the clock with constant contact from China to US. We have several sites sending millions of emails per day. Unlike other hosts, you will NOT need to switch domain names or experience periods of downtime. Our uptime guarantee is 90%. If you are serious about bulk mailing, you have come to the right place.


I was able to find a copy of a post by "AMIR SHAH" back on October 11, 2002, advertising "BULLET PROOF CHINA HOSTING" on this URL on sidetrak.com as an example.

In that ad, Amir offers to send messages for $30 per million emails sent. He used the AOL instant messager id "rulubos@aol.com".

Amir Shah also had a twitter account with that same identity, rulubos. He hasn't posted anything there since January 5th, 2009, when his last post was "looking at twitter and wondering if I should just incorporate this feature into Noog."

Amir follows Jianxiong Song. Hmmm...let's look at some more twitter links . . . Jianxiong is following WaqasShah, whose last twitter post is "WaqasShah is relieved" posted on APril 24th. WaqasShah follows noog_com, who was testing bloog mobile, according to their last twitter on April 17th. Noog has an interesting group of Venture Capitalists that he follows, but I won't list them here.

OK, back to the indictment.

In chat logs found on the computers, Zucker trains O. Shah in the art of spamming, and they communicate about how many proxies they would need to send 2 million emails, being disappointed with a rate of only 110,000 per hour. O. Shah later tells Zucker (July 14, 2003) that he can now send 1 million emails per hour with a 65% delivery rate (unblocked/unfiltered). Later, O. Shah tells his brother A. Shah that by plugging directly into the University of Missouri Columbia network "with a cable not using the wireless" he can send 2 million spam messages per hour from the school.

Search warrants were served against the Shah residence in Columbia, Missouri and their business address also in Columbia on February 23, 2005. They found more than 3 million student email addresses harvested from 2002, 5 million harvested from 2003, and 37.5 million AOL email addresses, 33.7 million MSN addresses, 10.8 Hotmail addresses, 5.2 million Yahoo addresses, and more than 4 million United Kingdom email addresses.

The indictment shows that the crew was identifying a ridiculous number of proxy servers which they could use to "bounce mail" from. For a price of $75 per week, Zucker was able to provide them "1500-2500 proxies twice a day". Originally, the transaction had gone the other way, with Shah providing a list of 45,000 proxies to Zucker earlier, receiving payment for his services via Paypal.

Zucker communicated with O. Shah about how to obtain and use the software program "Dark Mailer", and sent Shah a copy of the program on February 3, 2005. They also used the programs Supermailer and "Group Mail".

Bank records showed that the Shahs transferred more than $30,000 to Ming for hosting services.

Other chats showed the brothers discussing ways to make money. For example, they sent spam for a "teeth whitening" service, where they received a commission for successful sales. The brother said "if we need to mail a million or two to get 10,000 kids...then so be it...who cares."

Here's an example of their teeth-whitening emails, from April 1, 2004, which will illustrate how the SHAH brothers took advantage of students trust in their university relationships:

"Each year, several alumni-owned companies offer various specials to our students and faculty. This month, the university has been offered a special discount on custom fitted teeth whitening systems. Alumni-owned, Custom Bright, Inc., is offering its products to students and faculty at significant discounts all this month. We encourage you to visit their website and take advantage of this alumni offer."

This continued all the way through 2009, with messages like this one, sent March 1, 2009:

"As many of you may be aware, our campus has been offered a special discount on professional custom-fitted teeth whitening systems from a company run by our very own alumni. There will be several campus representatives (like myself) giving out more information over the next 2 weeks."

The brothers discussed having "a more forceful message" to encourage registration in a particular textbook system they were spamming:

"With higher tuition and course material costs, we are working to find new ways of saving students money. This semester, we have implemented a new textbook buyback program that will get students better payouts at the semester ending buyback and may also increase used textbook availability. You MUST complete your registration before the end of this week if you wish to be eligible for this semester's buyback."

Other campaigns that used similar spam sold Digital Cameras, iPods, NCAA Basketball merchandise, and Magazine subscriptions.

Some of the many domain names they used:

surveyproject.org
surveydirect.org
campuschange.org
whiteningtoday.com
whiteningnow.com
discoverwhitening.com
myschoolipods.com
studentipods.com
campusipods.com
semestersavings.com
semesterdiscounts.com
saveatcollege.com
collegedecember.com
estudentoffers.com
mycollegedeals.com
collegefuture.com
campusfuture.com
campusinput.com
whiteningservices.com
whiteningovernight.com
whiteninglabs.com
mycampusnanos.com
campusnanos.com
schoolipods.com

The full indictment gives date ranges for these and many other domain names.

Some of the purchases the Shah brothers made include:

a home in Columbia - $191,123.

a luxury lost in St. Louis - $251,861.

paying off a house in St. Louis - $33,698.

a downpayment on a Lexus sedan - $8,800.

The forfeiture of any assets, up to a total of $4,191,966.57 is also requested, which will come from several bank accounts, and the sale of properties at:

1301 Fieldcrest, Columbia, MO
1520 Washington Avenue, Unit #301, St. Louis, MO
a parking space (?)
5417 Idaho Avenue, St. Louis, MO

a 2002 Lexus (Missouri plate: CA9R6B)
a 2001 BMW (Missouri plate: 391ZEP)

Update



Apparently the Shah brothers indictment has shared with other spammers some good tips on this type of spam. Here's a message that one of my students at UAB received on April 30, 2009:

_____________________________________
From: Jenna T. [jenna@OverstockApple.com]
Sent: Thursday, April 30, 2009 2:20 AM
To: (name of my student)
Subject: Student/Faculty Discount

Dear Students/Faculty,

As you may have heard, several alumni-owned companies have teamed up to sponsor a campus-wide gift for our students and faculty. Working with Apple, they have acquired a small quantity of the new iPod Nano Chrome. This limited supply has now been made available to students and faculty at a significant discount. If you were at all interested in getting one of these iPods with this educational discount, please be sure to place your order online before this offer expires NEXT WEEK.

http://www.OverstockApple.com/h/3189094

Have a great summer!

Jenna T.
OverstockApple.com Student Representative



Have you seen a recent spam (after April 24th) from this group, pretending to be offering a discount for products from an "alumni-owned company"? If you can send it to me WITH HEADERS, I'd very much like to see it. Send it to: alumnispam@askgar.com
Read More
Posted in law enforcement, spam | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • Microsoft Security Intelligence Report 2H08
    The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microso...
  • Operation Open Market: The Vendors
    When we wrote last week about Operation Open Market the court documents had not yet been released in a major multi-agency Identity Theft ca...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile