Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 13 January 2010

Minipost: #CNIRcyberwar ? ? ?

Posted on 03:41 by Unknown
Several Chinese hacker groups have decided to retaliate for the "Iranian Cyber Army" attack against the Chinese search engine, Baidu.com, which we reported yesterday in our story Iranian Cyber Army Returns - Target: Baidu.

A few sources (thanks especially @packetninjas), have sent me links to Chinese webpages where their hacker community is expressing outrage by hacking back. One twitter hashtag seen with regards to this effort has been #CNIRcyberwar .

Despite the hashtag, there is no evidence whatsoever that there are GOVERNMENTS involved in this so-called CyberWar. On the Chinese side, this is the action of some patriotic but mis-guided youth who believe they can change world opinion by trashing a few insignificant websites. On the Iranian side, there is no evidence that any malice was intended towards the nation of China - it seemed their objective was to just place their message before a large audience - a goal they seem to have accomplished. I consider it highly unlikely that additional Iranian attacks on Chinese servers will result from this "CyberWar".

A hacker who claims membership in the "Honker Union for China" has posted many defacements of Iranian sites, along with lists of "official Iranian government sites" that he believes should be targeted, on the site:

http://bbs.360.cn/4261899/34063883.html

There is certainly debate going on, even within his own hacker community. One post this morning on "forums.chinesehonker.org" argued that the Iranians may not be behind the attack, but that it might really be the "dark Yankees" trying to stir up trouble. The rationale of that poster was that the attack came the day before a Chinese government missile interception test. ??? really ???

在没有确切证据的情况下,我倒是认为很能是美国佬干的,原因就是在百度背黑前一天我们进行了导弹拦截实验,进而引起了百度的被黑,这事从一件政治事件引起的网络攻击。
(from 自强不息 on forums.chinesehonker.org)

There is also an attempt to improve the image of Chinese hackers in the world with a little grammatical help from their friends. Another "honker" in the room suggests some help with one defacer's wording, suggesting that they replace:

The big national power spurs strong corps!

with

Our nation has internet experts who aren't afraid to fight back.

and

we are Oppose the special prganization of IR

with

We oppose this special organization of IR.


The Iranian attacks are being discussed in a thread on Baidu as well:


http://tieba.baidu.com/f?kz=695043079

This "soldier" is listing stored images of defaced Iranian websites, which he's actually pulling from the posts of "soping" on the site "bbs.360.cn":

room98.ir - Defaced image, including the text:



chinese honker team[H.U.C.]

I'm very sorry for this Testing!
Because of this morning your Iranian Cyber Army
Maybe you haven't konw this thing!
This morning your Iranian Cyber Army intrusion our baidu.com
So i'm very unfortunate for you
Please tell your so-called Iranian Cyber Army
Don't intrusion chinese website about The United States authoritires to intervene
This is a warning!
Khack by toutian from Honker Union For China


Other sites on his list include:

www.iribu.ir - Defacement image

Text:
CHINA Honker
China do not hear any foreign hacker!
The big national power spurs strong corps!
we are Oppose the special prganization of
IR

Another version of the text read:

Anysize
We are Red_hacker
Let the world hear the voice of China
The state is higher than the dignity of all!

f*** ir !
china up !
honker_Anysize@qq.com
(archived image)

That same text, with a different background image, also appeared on www2.mousavian.ir - (archived image)

An earlier version of the text (another hacker probably using the same vulnerability) read:

High-profile work being
Viruses, anti-virus, invasion, the invasion
The darkness of night, slowly permeates the wing?
The third area information security group By: h4ck3ber

The People's Republic of China Long Live
The great Chinese people long live
Domestic safety inspection
Oppose splkitting Safeguarding unity
http://hi.baidu.com/no_hackTime

pankration.gov.ir - Defacement image

www.diabetes.ir/home - Defacement image

Each of these sites is being tagged repeatedly by various hackers, as you can see documented in this thread:

http://bbs.360.cn/4261899/34063883.html?page=3
Read More
Posted in | No comments

Tuesday, 12 January 2010

Iranian Cyber Army returns - target: Baidu.com

Posted on 06:33 by Unknown
Many Americans are not familiar with Baidu, but in China its the word people say when we would say Google. Baidu is a Chinese search engine that commands a powerful 60% of the marketplace. And this morning, their website looked liked this:



The white line of Persian text on the website is a statement that reads:

« ارتش سایبری ایران در اعتراض به دخالت های سايتهاي بيگانه و صهیونیستی در امور داخلی کشورمان و پخش اخبار دروغ و تفرقه برانگیز راه اندازي شده است


Google Translate tells us that that says:

Army of cyber-sites has been established to protest intervention in the internal affairs of our country and broadcast of false and divisive news by Foreigners and Israel.


(with a little word-re-ordering to preserve meaning)


We first heard of the Iranian Cyber Army on December 18th when they attacked Twitter with an almost identical attack. We documented the attack here in our story Who Is the Iranian Cyber Army?.

In today's attack, the nameservers for Baidu were redirected to a small network that caters to "warez" and various piracy and pornography servers. The computer 188.95.49.6 became the address for ns1.baidu.com, ns2.baidu.com, and ns3.baidu.com, and these new "unofficial" nameservers did a wild-card resolution for everything at baidu, pointing it to the same IP address 188.95.49.6.

Later in the morning, that IP address shifted to 188.95.49.19, which is the address which is currently live as of this writing.

Click the image below to see the full unedited version of the original graphic that was posted on the server:


(the original file was named "-1-2.jpg")
(The EXIF data indicates that the file was saved using Adobe Photoshop CS4 Windows on December 27, 2009 at 1:41:44 PM.)

There were also two VERY interesting email addresses on the page:

Soldier@CyberArmyOfIran.com
and
Soldier@IRCArmy.com

The website "cyberarmyofiran.com" is hosted on the Canadian IP address 70.35.29.162, which belongs to "Netfirms Inc".

Registrant:
Domain Privacy Group, Inc.
c/o cyberarmyofiran.com,
7030 Woodbine Ave. Suite 800
Markham, ON L3R 6G2
CA

Domain name: cyberarmyofiran.com

Administrative Contact:
Domain Privacy Group, Inc. privacy635948@domainprivacygroup.com
c/o cyberarmyofiran.com,
7030 Woodbine Ave. Suite 800
Markham, ON L3R 6G2
CA
Fax:

Technical Contact:
Domain Privacy Group, Inc. privacy635948@domainprivacygroup.com
c/o cyberarmyofiran.com,
7030 Woodbine Ave. Suite 800
Markham, ON L3R 6G2
CA
Fax:

Registrar of Record: Netfirms Inc.
Record expires on 2010-12-31.
Record created on 2009-12-31.
Database last updated on 2010-01-12 06:51:32.

The website "ircarmy.com" is hosted on US IP address 98.136.50.138, which belongs to Yahoo! (and is currently using a Yahoo! Nameserver)

Domain Name.......... ircarmy.com
Creation Date........ 2009-12-31
Registration Date.... 2009-12-31
Expiry Date.......... 2010-12-31
Organisation Name.... Iranian Army
Organisation Address. PO Box 61359
Organisation Address.
Organisation Address. Sunnyvale
Organisation Address. 94088
Organisation Address. CA
Organisation Address. US

Admin Name........... Admin PrivateRegContact
Admin Address........ PO Box 61359
Admin Address........
Admin Address........ Sunnyvale
Admin Address........ 94088
Admin Address........ CA
Admin Address........ US
Admin Email.......... contact@myprivateregistration.com
Admin Phone.......... +1.5105952002
Admin Fax............

That first IP address for today's redirect, 188.95.49.6, resolved such names as:

www.baidu.com
proxy.baidu.com
news.baidu.com
passport.baidu.com
post.baidu.com
utility.baidu.com
video.baidu.com
cpro.baidu.com
map.baidu.com
spaces.baidu.com
zhidao.baidu.com

well, actually, EVERYTHING.baidu.com resolved temporarily to this IP address.

What is that IP address normally used for? When I try a reverse resolution on that IP it tells me the server's name is "pink2.warez-host.com"

The site normally hosts such webservers as:

wamboload.org
greateamwarez.pl
xtrem-360.com
shugalclub.com
xtreme-load.com
thewarezlife.com
ddlhentai.com
ewddl.com
warezdream.com
dxdforum.com
warez-host.com
blue.warez-host.com
linkpex.com
housebeats.in
scriptzsector.ws
pirate-club.net
wawa-mania.eu
demon-board.eu
iklotz.ru
0daymusic.biz

So what do we know about WarezHost? Here's what their website says about themselves:



Warez-Host is a privately-owned organization located in Dubai, UAE. At Warez-Host, we understand that our customers' web sites are important and they require reliable services to ensure that service is not interrupted. We have established a solid foundation to offer a reliable, easy to use and low cost web hosting solution for small-to-large sized businesses and helping thousands of customers get their web sites online.

Our goal is to provide a low-cost web hosting solution that is easy-to-use, and is customer service oriented. At Warez-Host, we value our customers and recognize their need for quality service and outstanding customer service.

Warez-Host web hosting is the perfect choice for all of your web hosting needs, our datacenters located in Netherlands, IRAN and Germany.




The Dedicated Server pages for each data center explain what types of content you can host on their servers. For example, its ok to host stolen software and movies ("warez") in all three locations, but the Iranian Data Center list (shown below) makes it clear you can't host pornography in Iran - although you can in their German and Netherlands based data centers.



So, if someone wants to get to the bottom of who hacked Baidu, all they have to do is slap a subpoena on the UAE-based company's Iranian data center manager to see who owns this dedicated server and get logs from it.

Yeah. Good luck with that.

More badness from "warez-host.com" servers:

0daymusic.biz
3rabwarez.com
70sshowonline.com
A1source.us
Alibablog.com
Allokamas.com
Allo-kamas.net
Alternatedown.com
Appfuzion.com
Aspecialtimetoremember.com
Bdwarez.info
Bestindo.us
Blogfigo.com
Bloodordie.com
Brif.net
Cumsafaci.com
Darkantiviruses.org
Ddlfree.com
Ddlhentai.com
Demon-board.eu
Devilstreaming.com
Diplomworld.com
Diplomworld.ru
Dll-404.com
D-moviez.com
Downloaderz.net
Dragon91.com
Dreadfulappz.com
Dxdforum.com
Dzson.com
Endees.com
Enjoywarez.org
Enz.ir
Ewddl.com
Extreme-load.com
Fbghana.com
Figyelo.net
Firstwarez.pl
Freefile.ir
Freemoviewizard.com
Ftaonline.org
Futurewarez.com
Gamehaxerz.com
Geejee.us
Geewee.eu
Get-connection.info
Gormiz.com
Gp-studios.info
Gstonerz.com
Hdppv.net
Hotfilmvn.net
Hot-uploads.com
Housebeats.in
Iklotz.com
Iklotz.ru
Indianddl.info
Insidernet.com
Italywarez.net
Linkbucks.in
Linkpex.com
Linkxpic.com
Live-desi.com
Magazinesbay.com
Marvisatechnology.com
Mastworld.net
Mediaanime.info
Megauploadparadise.com
Mexicowarez.com
Minitech.ws
Mobile1.ir
Montamela.net
Morehtamilsangam.com
Movie-at-home.com
Neopetstuff.com
Neopetstuff.net
Netspond.com
New-connection.info
No2pc.com
Nop-licite.us
Now-connection.info
Operationwolf.net
Parsikade.ir
Pejaforum.net
Persianmember.com
Persianmember.ir
Pirate-club.net
Piratemonster.com
Porn-down.com
Projectannihilation.org
Qpv8.ir
Rapid4all.org
Resell-host.biz
Rivea.org
Sataplu.com
Scriptzsector.ws
Search-ddl.com
Secured-webhosting.com
Seekwarez.com
Seheri-bb.com
Seo-shop.info
Sharing-rapidshare.com
Sharing-rapidshares.com
Shugalclub.com
Simoali.com
Sonicviewbrasil.net
Sportzkrieg.com
Streamdvd.net
Superpartage.com
Tagmite.com
Tamilsangammoreh.com
Tehwarez.com
Tensaibux.com
Tensaidownloader.com
Theentertainmentcore.com
Theforcestrikes.com
Thewarezlife.com
Tsontakias.org
Ultimate-porn.us
Ultrafull.com
Untiempopararecordar.com
Upload4u.ir
Uptaze.com
Wamboload.org
Warez.ir
Warez-design.com
Warezdream.com
Warezground.org
Warez-help.org
Warez-host.com
Warez-host.net
Warezisland.com
Warezlegacy.com
Warez-life.com
Warezmarket.net
Warezs.net
Warez-share.net
Warez-zz.com
Warwealth.com
Watch-free-episodes-online.org
Wawa-mania.eu
Whatsupearl.com
Woodbumgfx.com
Xfresh.us
Xtreme-load.com
You-down.com
Zojesalem.com
Read More
Posted in | No comments

Thursday, 31 December 2009

New Year's Waledac Card

Posted on 12:52 by Unknown
We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back!

I'm on vacation today, so I was actually alerted to the story by a friend twittering this SC Magazine story. Vacation or not, that was worth checking into. I took a dip into the UAB Spam Data Mine looking for domain names associated with this version of the malware.

We've seen more than sixty different Subject lines used by the spam:

2010 New Year Wishes!
A Great 2010!
A Happy New Year!
A New Year e-card is waiting for you
A special card just for you
Greeting Card from Santa
Greeting for you!
Greeting you with heartiest New Year wishes.
Greetings from Santa
Happy 2010 To U!
Happy 2010!
Happy New Year 2010!
Happy New Year greetings e-card is waiting for you
Happy New Year greetings for you
Happy New Year greetings from your friend
Happy New Year To U!
Happy New Year Wish!
Happy New Year wishes just for you
Happy New Year Wishes!
Happy New Year!
Happy, Happy New Year!
Have a funfilled and blasting NewYear!
Have a Great New Year!
Have a happy and colorful New Year!
Have a Happy New Year!
Have a very Happy New Year!
I made an Ecard for U!
I sent you the ecard
l want to share Greeting with you
New Year 2010 Ecard Special Delivery
New Year 2010 greetings for you
New Year 2010!
New Year Cheers!
New Year E-card for you
New Year Ecard Notification
New Year Wishes!
Regards from Santa
Santa has sent you a digital postcard!
Santa has sent you a greeting card!
Santa has sent you a Happy New Year E-Card!
Santa has sent you a New Year E-Card!
Santa has sent you a New Year greeting card!
Santa has sent you an E-Card!
Santa has sent you an ecard!
Santa has something to show you!
Santa sent you New Year Greetings
Santa sent you a Greeting!
Santa sent you New Year Wishes!
Santa wishes you a Happy New Year
Sparkling wishes on the New Year!
Special New Year Wish for you.
Warmest Wishes For New Year!
Welcome 2010!
Wishing you a Happy New Year!
Wishing you the Best New Year!
You have a greeting card
You have a New Year Greeting!
You Have An E-card Waiting For You!
You have received a greetings card
You Received an Ecard.
You've got a Happy New Year Greeting Card!
You've got a New Year card!
You've got an E-card

Each domain can be used with any subject, and with any of the following paths:

/2010.html
/card.html
/ecard.html
/postcard.html


Domain names are pre-pended with random host names, such as:

aohqi.aweleon.com
bpn.bedioger.com
cjk.bicodehl.com
amb.birdab.com
coki.cismosis.com
amg.crucism.com
csxyg.cycloro.com
aqlec.encybest.com
asthu.framtr.com
boiij.frostep.com
dxuo.gumentha.com
bba.hindger.com
bt.hornalfa.com
delhy.noloid.com
aju.nonprobs.com
cvr.oughwa.com
buqdv.pantali.com
djre.pathoph.com
balr.prerre.com
cuh.purgand.com
dope.rascop.com
baamo.specipa.com

These domains are of course registered at China Springboard Inc. On each domain name, you can click the name to see the Waledac Tracker report by our friend Jeremy at SudoSecure in Huntsville. Some of these domain names have as many 12,000 entries in his Waledac Tracker!

aweleon.com - registered Oct 27, 2009 - NS1.FAVOLU.COM - hjuahge@yeah.net
bedioger.com - registered Aug 7, 2009 - NS1.FAVOLU.COM - pljlkeg@126.com
bicodehl.com - registered Nov 26, 2009 - NS1.FAVOLU.COM - xihyakern@163.com
birdab.com - registered Sep 30, 2009 - NS1.FAVOLU.COM - hjuahge@yeah.net
cismosis.com - registered Aug 7, 2009 - NS1.FAVOLU.COM - pljlkeg@126.com
crucism.com - registered Sep 30, 2009 - NS1.FAVOLU.COM - hjuahge@yeah.net
cycloro.com - registered Oct 27, 2009 - NS1.FAVOLU.COM - hjuahge@yeah.net
encybest.com - registered Nov 26, 2009 - NS1.FAVOLU.COM - xihyakern@163.com
framtr.com - registered Nov 26, 2009 - NS1.FAVOLU.COM - xihyakern@163.com
frostep.com - registered Nov 26, 2009 - NS1.FAVOLU.COM - xihyakern@163.com
gumentha.com - registered Nov 26, 2009 - NS1.FAVOLU.COM - xihyakern@163.com
hindger.com - registered Nov 26, 2009 - NS1.FAVOLU.COM - xihyakern@163.com
hornalfa.com - registered Nov 26, 2009 - NS1.FAVOLU.COM - xihyakern@163.com
noloid.com - registered Nov 26, 2009 - NS1.FAVOLU.COM - xihyakern@163.com
nonprobs.com - registered Aug 7, 2009 - NS1.FAVOLU.COM - pljlkeg@126.com
oughwa.com - registered Nov 26, 2009 - NS1.FAVOLU.COM - xihyakern@163.com
pantali.com - registered Oct 27, 2009 - NS1.FAVOLU.COM - hjuahge@yeah.net
pathoph.com - registered Oct 27, 2009 - NS1.FAVOLU.COM - hjuahge@yeah.net
prerre.com - registered Oct 27, 2009 - NS1.FAVOLU.COM - hjuahge@yeah.net
purgand.com - registered Nov 26, 2009 - NS1.FAVOLU.COM - xihyakern@163.com
rascop.com - registered Sep 30, 2009 - NS1.FAVOLU.COM - hjuahge@yeah.net
specipa.com - registered Sep 30, 2009 - NS1.FAVOLU.COM - hjuahge@yeah.net


DomainName : FRAMTR.COM

RSP: China Springboard Inc.
URL: http://www.namerich.cn

Name Server: NS6.FAVOLU.COM
Name Server: NS3.FAVOLU.COM
Name Server: NS1.FAVOLU.COM
Name Server: NS2.FAVOLU.COM
Name Server: NS5.FAVOLU.COM
Name Server: NS4.FAVOLU.COM
Status: clientTransferProhibited
Status: clientDeleteProhibited
Creation Date: 2009-11-26
Expiration Date: 2010-11-26
Last Update Date: 2009-12-31

Registrant ID: V-X-57482-12887
Registrant Name: HUA XINGJUN
Registrant Organization: HUA XINGJUN
Registrant Address: CHANGZHOUDADAO214
Registrant City: CZ
Registrant Province/State: JS
Registrant Country Code: CN
Registrant Postal Code: 213072
Registrant Phone Number: +86.051956612412
Registrant Fax: +86.051956612412
Registrant Email: xihyakern@163.com

Some of these domains are already published in MalwareDomainList.com, such as:

noloid.com/wcap.exe - this one is a Fake AV dropper. Here's the VirusTotal report showing 19 of 40 detects:

File size: 230994 bytes
MD5 : ab585c87652c933f82bbaddfd52ea15d
SHA1 : a142cb266ad6cd764501981f6bb194025b7c8cc8

gumentha.com/ecard.html

gumentha.com/counter.php
- this actually causes a download from biozcgicfziy.com/nte/TREST1.php

gumentha.com/in2.php
- this one causes a download from domoktov.com/bu1/
- (you'll be shocked to learn that domain is registered to someone in St. Petersburg, Russia . . .one Denis Sergunkin already known to be hosting Fragus Exploit kits on other domains of his, such as 1tomohappy.com and funky-soft2.com)

purgand.com/in5.php
- this one also hits domoktov.com/bu1/

aweleon.com/ghost.php
- that one ALSO hits domoktov.com. So, Denis? are you paying the Waledac gang? or ARE you the Waledac gang?


This time around the Waledac domains are hosted using Fast Flux, and they are also using Fast Flux for the Nameservers. As we've discussed before, this means that the addresses of the compromised computers are entered into the nameserver records as the host addresses for the malware domains. In other words, getting infected makes your computer spread the infection. So far we've seen more than 1500 computers being used by the malware in this way.



I'll load up a Virtual Machine in a bit to evaluate the actual malware.


Facebook Zbot Still Spreading



We're also seeing an on-going fake Facebook update, which is the Zeus bot. Here are the 45 domains we've seen in the UAB Spam Data Mine so far this morning:

www.facebook.com.hyjjjh1a.com
www.facebook.com.hyjjjh1a.net
www.facebook.com.hyjjjh1d.com
www.facebook.com.hyjjjh1d.net
www.facebook.com.hyjjjh1f.com
www.facebook.com.hyjjjh1f.net
www.facebook.com.hyjjjh1h.com
www.facebook.com.hyjjjh1h.net
www.facebook.com.hyjjjh1j.com
www.facebook.com.hyjjjh1j.net
www.facebook.com.hyjjjh1m.com
www.facebook.com.hyjjjh1q.com
www.facebook.com.hyjjjh1q.net
www.facebook.com.hyjjjh1s.com
www.facebook.com.hyjjjh1s.net
www.facebook.com.ter3awqlaq.com.pl
www.facebook.com.ter3awqlbb.com.pl
www.facebook.com.ter3awqlcd.com.pl
www.facebook.com.ter3awqlds.com.pl
www.facebook.com.ter3awqlee.com.pl
www.facebook.com.ter3awqleg.com.pl
www.facebook.com.ter3awqler.com.pl
www.facebook.com.ter3awqlhg.com.pl
www.facebook.com.ter3awqlju.com.pl
www.facebook.com.ter3awqlre.com.pl
www.facebook.com.ter3awqlsz.com.pl
www.facebook.com.ter3awqlvb.com.pl
www.facebook.com.ter3awqlvr.com.pl
www.facebook.com.ter3awqlwt.com.pl
www.facebook.com.ter3awqlyy.com.pl
www.facebook.com.y7y66yc.com.pl
www.facebook.com.y7y66yd.com.pl
www.facebook.com.y7y66yf.com.pl
www.facebook.com.y7y66yg.com.pl
www.facebook.com.y7y66yh.com.pl
www.facebook.com.y7y66yi.com.pl
www.facebook.com.y7y66yj.com.pl
www.facebook.com.y7y66yk.com.pl
www.facebook.com.y7y66yl.com.pl
www.facebook.com.y7y66ym.com.pl
www.facebook.com.y7y66yo.com.pl
www.facebook.com.y7y66yr.com.pl
www.facebook.com.y7y66yt.com.pl
www.facebook.com.y7y66yu.com.pl
www.facebook.com.y7y66yy.com.pl
Read More
Posted in | No comments

Saturday, 26 December 2009

2009 Year in Review

Posted on 09:47 by Unknown
As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share back with our readers what stories were most interesting to them, based on the traffic that was created to the blog. We'll do two more "Year in Review" stories, one focused on social computing threats, and one focused on the year's "Cyberwar" stories.

First I wanted to mention that in 2009, pageviews to the blog went up by about 74% over 2008. Although I had hoped for 200,000 pageviews this year, we fell a bit shy of the mark. As of December 26th, we've had 125,983 unique visitors bring us 192,409 pageviews in 150,722 visits.

Google was the primary way that people found our stories, and I am grateful to the folks at Google for hosting the blog again this year. After Google, the #2 referrer to the site was Facebook. Its nice to see people on Facebook warning each other about security risks and sharing links to the blog with each other. #3 was Twitter. Although I have a bit more than 550 followers on Twitter, its also been nice to see a large number of retweets with links back to the blog. Thanks to all the Facebookers and Twitterers who have been sharing our stories with their friends and followers.

2009 Top Stories by Readership



1. Webmasters Targeted by CPanel Phish - many hosting companies and webmaster organizations helped spread the word about this unique phishing attack that wasn't trying to steal banking passwords, but rather webmaster passwords. The goal of the attack was to compromise the login credentials that allow webmasters to change their webpages, which is exactly what we've been seeing this week. Thousands of accounts being taken over so that their webpages could be injected with malicious iframes to compromise visitors to existing websites with a "clean" history.

2. Fake FDIC spam campaign spreads Zeus malware - one of the most prevalent ways to steal identities this year was to begin with a broadly targeted social engineering scare which enticed visitors to click links that would lead to malware. In this case, the spam warned "Your bank has failed!" and provided a link to your "personalized FDIC report" to determine if your deposits were covered by insurance.

3. Computer Virus Masquerades as Obama - despite being a November 2008 story, websurfers continued to follow links to our story about malware being distributed in links that claimed to be messages from our President.

4. DownAdUp, Conflicker, Conficker whatever you want to call it, this worm drew tons of attention from January until March. Then, after what most consider an April 1st "flop", the worm got very little media attention. This is largely because of the successful efforts of the Conficker Working Group which has worked behind the scenes to keep the malware at bay and to warn network operators. Most don't realize that there are still more than 6 million Conficker-infected computers in the world.

5. Outlook Web Access and Fake Microsoft Outlook Update both drew large amounts of attention as spammers took advantage of the popularity of Microsoft's mail software to trick users into downloading malware.

6. Gumblar's 48,000 compromised domains make the web a dangerous place was also a popular story. Sharing details about the IFRAMES injected into the compromised webpages helped webmasters to know that they were part of the attack.

7. The IRS version of Zeus was one of several stories where the distributors of the Zeus password-stealing software used government based spam campaigns to fool email recipients. They also imitated the Centers for Disease Control, the Social Security Administration.

8. One on-going trend that we've seen was covered in our story Carders Do Battle Through Spam. These battles, which I call "pigeon fights", involve a spammer sending out false and very criminal accusations against another online criminal group. In this case, there was a bit of truth, as the spam claimed that carder.su sells illegal credit cards, while in other cases they may be accused of terrorism, child pornography, or human traficking. The goal seems to be to get enough law-abiding citizens to report the horrible spam they got to focus law enforcement attention on a competitor.

9. Its nice to be able to share good news in our blog, and the best kind of news is when cyber criminals get arrested. Our story The FBI's Biggest Domestic Phishing Bust Ever covered Operation: Phish Phry, where more than 50 Americans and a number of Egyptians were arrested as part of an international phishing conspiracy that had stolen funds from more than 5,000 American bank accounts.

10. Our next largest story was the coverage we offered to a Spam Crisis in China. That one is not over yet, but a major step forward was accomplished this month when CN-NIC announced new rules on domain registrations. We'll be reviewing the results of these rules, which limit the fraudulent use of ".cn" domains, to determine what impact the changes are having on spam so far.

Other stories that received high volumes of traffic included:

* - Koobface Wrecks Search Results. Koobface remains one of the greatest cyber threats we're currently facing.

* - Several stories about the Waledac malware, including a Couponizer version of Waledac, an SMS Spy Waledac, a Dirty Bomb in Your City Waledac, and an Independence Day Waledac.

* - I continue to be contacted daily by people who have been hit by a Traveler Scam claiming a stranded friend needs money. Most of these are Nigerian account takeovers of Hotmail, Live.com, and Yahoo email addresses which are then used to email all the friends found in the address book.

* - and of course the Erin Andrews / Twitter / Naked Newscaster story, which will continue to get traffic forever because it has the word "naked" in the title.

Thanks to Those who Link to our Stories . . .


We've had some faithful friends who have been kind enough to mention the blog. I probably should have run this as a separate story at Thanksgiving time, but for all of you listed below, Thank You! Whether you are security experts, journalists, or fellow bloggers, I am happy to count us all on the same team.

the Internet Storm Center at SANS has linked stories several times from their Handlers Diary. These selfless individuals donate their time to track emerging threats and from time to time share stories from this blog with their readers. They have an enormous readership based on the impact to this blog when one of our stories is mentioned there. Traffic-wise, it is better to show up in the SANS ISC Diary than to be Slash-Dotted!

Brian Krebs of the Washington Post continues to be the most influential journalist in the Internet Security space and has been kind enough to mention our stories on several occasions in 2009. His legendary leadership in the McColo campaign has changed the way the world looks at evil web hosting, but his constant awareness of what's happening in cybercrime has also kept him at the forefront of investigative journalism in our space. I can't wait to see what Brian does in 2010!

UAB's Computer & Information Sciences department has also driven considerable traffic to the blog - and not just from my students! Our unique offering of a certificate in Computer Forensics that combines the disciplines from Criminal Justice, Forensic Science, and Computer Science is gaining popularity as the correct approach to preparing cybercrime investigators for their career.

The Composite Blocking List sent us traffic all year long, but mostly from a single story, which was their definitive coverage of the effects of the McColo shutdown on spam. Using a blocklist like the CBL, SpamHaus SBL, or SURBL is highly recommended anti-spam practice.

Ryan Naraine and Dancho Danchev should be on every security person's Google Reader list. With a nice mix of straight security and cybercrime, the consistency and quality of this blog drives a lot of traffic when we get a nod from them.

Security.NL is one of the most consistent referrers to the blog and drives a lot of traffic our way. Last year they linked to our blog thirty separate times! Since I don't speak Dutch, I can only hope that a "beveiligingsexpert" is a good thing, because they say I am one! Thanks for making sure our friends in the Netherlands are on top of cybercrime and security issues!

IDG's Robert McMillan also is a journalist who is breaking an enormous number of cybercrime stories, although its harder to quantify the number of referrals from his blogs because they show up as links from PC World, ComputerWorld, Network World, Linuxworld, CIO, CSO, InfoWorld, and the foreign language versions of so many of those as well. Bob is another hard-working cyber security journalist who often exposes me to new stories that end up being covered in this blog. Thanks, Bob!

The Register also continues to break stories regularly on cybercrime issues, and has frequently sent traffic our way - especially in stories from Dan Goodin and John Leyden.

SC Magazine continues to grow in popularity and influence as well, and we've been favored by mention several times this year from Dan Kaplan. He's a journalist well worth following! It was also great to work with their editor, Illena Armstrong, on the SC 24/7 Virtual Symposium on botnets.

Thanks also to some others who regularly send traffic to this blog:

Security Focus: Headlines

SiL at InBoxRevenge and all the great anti-spammers there . . . (and also SiL's blog, I Kill Spammers.)

the Malware Domains List and their forums.

ThreatChaos blogger Richard Stiennon

and our friends at HK CERT, Simple Machines, Dark Reading, Le Monde, New York Times, ComputerForensicsBlog, PGP Blog, Naver Blog, and all the rest . . .
Read More
Posted in | No comments

Tuesday, 22 December 2009

A donde se va Avalanche? BBVA! y United Bankers Association

Posted on 05:37 by Unknown
The Avalanche botnet continues to send out spam for spreading malware and phishing. Its newest target is Spanish banking giant BBVA.

We don't get a lot of Spanish spam to the UAB Spam Data Mine, but we have received several copies with subjects like:

Establecidas nuevas medidas de seguridad
Aviso Urgente
nuevas medidas de seguridad
Nuevas Medidas De Seguridad
Haga El Favor De Confirmar Sus Datos
Aviso Importante Para Los Clientes Del Banco

The message looks like this:
Estimado cliente,
Servicio técnico del banco BBVA renovó el software para mejorar el servicio de los clientes del banco.
Para asegurar la integridad de sus datos Usted tiene que rellenar el Formulario de cliente.
Para empezar a rellenar el formulario pulse en el vínculo:
http://formulario.bbva.es/DFAUTH/DFServlet/LogonServlet.php?id=9450983366442462436235235236689910980197561325891724661774&email=userid@domain.tld
Esto es un mensaje automático, no hace falta que respondas.
Reciba un cordial saludo,
Grupo BBVA.


The samples that we have so far use these domain names:

formulario.bbva.es.kfjoitiil.co.uk
formulario.bbva.es.kfjtimiil.co.uk
formulario.bbva.es.kfjtitiil.co.uk
formulario.bbva.es.kfotitiil.co.uk
formulario.bbva.es.mfjtitiil.co.uk
formulario.bbva.es.ofjtitiil.co.uk

The list is already growing . . . up to 14 now . . .

formulario.bbva.es.kfjmitiil.co.uk
formulario.bbva.es.kfjoitiil.co.uk
formulario.bbva.es.kfjtimiil.co.uk
formulario.bbva.es.kfjtitiil.co.uk
formulario.bbva.es.kfjtitiim.co.uk
formulario.bbva.es.kfjtitiml.co.uk
formulario.bbva.es.kfjtmtiil.co.uk
formulario.bbva.es.kfjtotiil.co.uk
formulario.bbva.es.kfmtitiil.co.uk
formulario.bbva.es.kfotitiil.co.uk
formulario.bbva.es.kmjtitiil.co.uk
formulario.bbva.es.kojtitiil.co.uk
formulario.bbva.es.mfjtitiil.co.uk
formulario.bbva.es.ofjtitiil.co.uk



The first page of the websites just asks for a Userid and Password:



The second page asks visitors to provide 100 three-digit numbers which are used as a fraud prevention mechanism by the bank. In normal usage, visitors to the bank are prompted with an X and Y coordinate, like "A7", and will add to their password the three digit number that is found on that position on their card. Each banking customer has their own unique card. The phisher here can't use their userid and password unless they also have the card information, so they are asking for THE ENTIRE CARD!



But what else can we learn by looking at Passive DNS?

As with all of the "Avalanche family" of phishing and malware sites, the site is hosted via Fast Flux. That is, infected personal computers around the world have malware on them which allows the criminal to point his Nameserver settings to these compromised home computers. When someone clicks on the spam message, they are directed not to the criminal's webserver, but to one of these compromised home computers.

The Fast Flux phrase refers to the fact that the criminal constantly updates his nameservers to rotate the hosting of the spammed hostname across many hundreds of bots.

As an example, here are some of the IP addresses for the hostname:

formulario.bbva.es.kfjtitiil.co.uk:

61.0.70.16
85.98.91.104
87.69.46.150
89.139.168.132
95.56.43.92
121.128.247.163
121.131.237.21
183.87.51.109
187.7.94.21
189.105.197.134
189.110.217.186
189.163.144.141
189.179.6.48
189.192.13.43
189.193.59.146
189.194.168.45
189.220.219.70
190.141.201.180
190.162.176.58
190.190.237.103
196.217.220.42
196.217.228.33
196.217.53.158
200.66.40.188
200.83.102.20
201.132.106.254
201.160.230.120
201.164.184.87
201.166.100.22
201.166.44.190
201.218.67.203
217.132.22.172
220.67.225.229
222.107.109.74

When we investigate one of those IP addresses, we find that the same Fast Flux hosts were found to also be hosting the Visa.com Zeus malware distribution sites that we've discussed earlier, and also a "United Bankers Association" site.

We can still see the UBA version, and find many samples of it in the UAB Spam Data Mine, such as these:

The bank you have an account in, is declared bankrupt. Learn How to Save your Money: >link<

Subjects for this spam include:

A message for the owner of ******** bank account.
A new back is declared bankrupt.
Bankrputcy declaration.

Yeah, it really says "back" instead of "bank" and really uses "********" in the subject line.

The sites we found sharing Fast Flux hosting with the BBVA campaign include:

u-b-a.org.dirpote1.be
bankruptcy.u-b-a.org.dirpote1.be
unitedba.org.dirpote1.be
ub-assoc.org.dirpote1.be
bankruptcy.unbassoc.org.dirpote1.be
ubassoc.org.dirpote1.be
bankruptcy.ubassoc.org.dirpote1.be
ub-association.org.dirpote1.be
bankruptcy.ub-association.org.dirpote1.be
unitedbankersassociation.org.dirpote1.be
bankruptcy.unitedbankersassociation.org.dirpote1.be
unitedbankers.org.dirpote1.be
bankruptcy.unitedbankers.org.dirpote1.be
u-b-a.com.dirpote1.be
bankruptcy.u-b-a.com.dirpote1.be
bankruptcy.unitedba.com.dirpote1.be

We saw tons of this spam yesterday for a variety of domains and hostnames, such as:

bankruptcy.ub-assoc.org.uk.dirtotp1.co.uk
bankruptcy.ub-association.org.uk.dirtotp2.co.uk
bankruptcy.ubassoc.co.uk.dirtotp3.co.uk
bankruptcy.u-b-a.co.uk.vdfproo.co.uk
bankruptcy.unitedbankersassociation.co.uk.dirdlpr3.be
bankruptcy.unitedbankers.co.uk.dirdlpro.be
bankruptcy.u-b-a.co.uk.dirdlpro1.be
bankruptcy.ubassoc.co.uk.dirdlpro2.be
bankruptcy.ubassoc.co.uk.progh1.be
bankruptcy.u-b-a.co.uk.progh2.be
bankruptcy.unitedba.co.uk.tpotpdd.be
bankruptcy.unitedbankers.co.uk.tpotpdd1.be
bankruptcy.unitedbankers.co.uk.vdfproo.be
bankruptcy.ub-assoc.co.uk.vstdrerr.be
bankruptcy.unitedbankersassociation.com.111ttillil.co.uk
bankruptcy.ubassoc.com.11fttillil.co.uk
bankruptcy.u-b-a.com.11tttillil.co.uk
bankruptcy.unitedba.com.1jfttillil.co.uk
bankruptcy.ub-assoc.com.yjfttillil.co.uk
bankruptcy.u-b-a.com.dirpote1.be
bankruptcy.unitedba.com.dirpote3.be
bankruptcy.unitedba.com.dirpote4.be
bankruptcy.ubassoc.com.dirpote5.be
bankruptcy.ub-association.com.dirpote6.be
bankruptcy.unbassoc.org.dirpote7.be
bankruptcy.ub-assoc.com.dirpote8.be
bankruptcy.u-b-a.com.dttflji.be
bankruptcy.ub-association.com.itdflji.be
bankruptcy.ubassoc.com.ittdlji.be
bankruptcy.u-b-a.com.ittfdji.be
bankruptcy.ub-assoc.com.ittfldi.be
bankruptcy.ubassoc.com.ittfljd.be
bankruptcy.ubassoc.org.ittflji.be
bankruptcy.ubassoc.com.ittfljx.be
bankruptcy.u-b-a.org.ittflxi.be
bankruptcy.ubassoc.com.ittfxji.be
bankruptcy.ubassoc.com.itxflji.be
bankruptcy.unbassoc.com.ityxlji.be
bankruptcy.ub-assoc.org.ixtflji.be
unitedbankers.co.uk.promoderp.be
bankruptcy.u-b-a.org.xttflji.be
bankruptcy.ubassoc.com.ydtflji.be
bankruptcy.u-b-a.com.11t1jtiil.com
bankruptcy.u-b-a.org.11t1kt1pl.com
bankruptcy.ubassoc.com.11t1ktiil.com
bankruptcy.ubassoc.com.11tfjtiil.com
bankruptcy.u-b-a.com.i1tfjtiil.com
bankruptcy.ub-association.com.ictfjtiil.com
bankruptcy.ub-association.com.ivtfjtiil.com
bankruptcy.unitedba.com.11t1kt1il.net
bankruptcy.u-b-a.com.11t1ktiil.net
bankruptcy.ub-association.com.11tfjtiil.net
bankruptcy.ubassoc.com.i1tfjtiil.net
bankruptcy.u-b-a.com.ictfjtiil.net
bankruptcy.unitedbankersassociation.com.ivtfjtiil.net


This site doesn't provide ANY information about the so-called bankruptcy of "your bank", but it does tell you you have to upgrade your Adobe Macromedia Flash Player:



The malware distributed there, called "flashinstaller.exe" is binary identical to the current fake Visa malware, "cardstatement.exe". A VirusTotal Report shows 13 of 41 anti-virus products currently detecting the malware.

Additional information
File size: 188928 bytes
MD5 : d61c6195eda54b1009208ba823ccdac4

There are also tons of "visa.com" links, such as:

sessionid2ypkfd1y0wa0.visa.com.dirpote1.be
sessionid-0n8owwc0.visa.com.dirpote1.be
sessionid3yfwwyc0.visa.com.dirpote1.be
sessionidsubv3f0.visa.com.dirpote1.be
sessionid_3s76mvuowvpjkg0.visa.com.dirpote1.be
sessionidqsz66rkt0hdji0.visa.com.dirpote1.be
sessioniddmw8pukq74ck0.visa.com.dirpote1.be
sessionid8r1efl0.visa.com.dirpote1.be
sessionid_v9k2ybsrl0.visa.com.dirpote1.be
sessionid36x1p4ya4sl0.visa.com.dirpote1.be
sessionid08ypfdtr1z4o0.visa.com.dirpote1.be
sessionid_9yagx6ub4w37q0.visa.com.dirpote1.be
sessionid_ff17zq0.visa.com.dirpote1.be
sessionidl5292sut0.visa.com.dirpote1.be
sessionid-e3wkqkg0min23u0.visa.com.dirpote1.be
sessionid_yvotp5t613z9u0.visa.com.dirpote1.be
Read More
Posted in | No comments

Monday, 21 December 2009

Some updates . . . Visa/Zeus and Google Jobs

Posted on 11:48 by Unknown
On December 12th we covered a new "Visa.com" version of the Zeus distribution spam.
(See story: Ongoing Visa Scam Drops Zeus Zbot.

There are at least forty domains seen in today's spam. Please see the story above for more on the URL pattern, (the machine name may begin with "alerts", "reports", "statements", "transactions", or a "sessionid" with random characters after the "sessionid" version, but here is one sample URL for each domain:

alerts.visa.com.111ttillil.co.uk
alerts.visa.com.11fttillil.co.uk
alerts.visa.com.11tttillil.co.uk
alerts.visa.com.1jfttillil.co.uk
alerts.visa.com.yjfttillil.co.uk
reports.visa.com.dirpote1.be
alerts.visa.com.dirpote2.be
alerts.visa.com.dirpote3.be
alerts.visa.com.dirpote4.be
alerts.visa.com.dirpote5.be
alerts.visa.com.dirpote6.be
alerts.visa.com.dirpote8.be
alerts.visa.com.dttflji.be
alerts.visa.com.itdflji.be
alerts.visa.com.ittdlji.be
alerts.visa.com.ittfdji.be
alerts.visa.com.ittfldi.be
alerts.visa.com.ittfljd.be
alerts.visa.com.ittflji.be
alerts.visa.com.ittfljx.be
alerts.visa.com.ittflxi.be
alerts.visa.com.ittfxji.be
alerts.visa.com.itxflji.be
alerts.visa.com.ityxlji.be
alerts.visa.com.ixtflji.be
alerts.visa.com.xttflji.be
alerts.visa.com.ydtflji.be
alerts.visa.com.11t1jtiil.com
alerts.visa.com.11t1kt1il.com
alerts.visa.com.11t1kt1pl.com
alerts.visa.com.11t1ktiil.com
alerts.visa.com.11tfjtiil.com
alerts.visa.com.i1tfjtiil.com
alerts.visa.com.ictfjtiil.com
alerts.visa.com.ivtfjtiil.com
alerts.visa.com.11t1jtiil.net
alerts.visa.com.11t1ktiil.net
alerts.visa.com.11tfjtiil.net
alerts.visa.com.i1tfjtiil.net
alerts.visa.com.ivtfjtiil.net

Its too early to know for sure what malware this is, because currently only 4 of the 41 anti-virus products at VirusTotal detect it as anything at all. Sunbelt calls it Bredolab, the three others all say only that it is "suspicious". I'll try to run it through our malware VM later today and make a more definite judgement.

VirusTotal Report here

cardstatement.exe
File size: 188928 bytes
MD5 : d61c6195eda54b1009208ba823ccdac4

Google Jobs Update


We warned about a Google Jobs scam back on December 1st (see article: Google Jobs Scam -- Read the Fine Print!!). Google actually sued the scammers who were running that scheme on December 9th (see article: Google v. Pacific WebWorks. Unfortunately the spam, and the scamming, continues unabated.

One example would be the spam messages for this "spaces.live.com" blog:

http://cid-3d8eb92dd2d67dba.spaces.live.com/

which leads to the website "biznews7.org", which forwards to the website "news2010letter.com", which recruits people to join the scam by sharing their credit card number on the site "http://www.safetrialoffers.com/searchsecretsystems/le5/".

On that site, the same scam is still being run by this organization:

Search 4 Profit, LLC.
7614 Arvilla Avenue.
Sun Valley, CA 91352

The Fine Print still reads:

Terms and Disclosures. Billing authorization obtained pursuant to the Uniform Electronic Transaction Act and the Electronic Signatures in Global and National Transactions Act. By submitting this form, I am ordering Search Secret Systems for a 7-day bonus period for $1.97 billed to my credit Card; If you enjoy Search Secret Systems, simply do nothing. On the 7th day my credit card will automatically be charged an easy payment of $89.26 once a month for three months. After the three months you will not be billed again. You will then maintain unlimited access to our member site. During your three month program you may cancel anytime by calling 1-877-361-8622 M - F, 8am-8pm MST.




Amazingly, the phone number was answered and a person actually asked how they could help me! When we wrote the first article, the phone rang and rang, but no one ever answered.

Of course, there are still quite a few ways this is illegal, even if they do now answer the phone, including the CAN SPAM violations. The email "from" address is forged and there is no "unsubscribe" link of any sort, nor is there a physical mailing address, despite this being a commercial offer. Here's an example spam message:

Never work in an office again! I've been working for someone else my entire life. A few weeks ago I found out about working for Google online so I decided to check it out. I signed up and read a few articles and tried a few different things and within 6 weeks I was making enough to quit my full time job to work at home! If this sounds like something that interests your, check out URL
http://profiles.yahoo.com/blog/MVO2GFP4W7AEJ42YOXCPAVOTU4
A song, a song, high above the trees




Work for the world's largest employer today lori has Earned $2,069 This December Alone! Check it out here:
http://cid-5ccbbcb19ba7028f.spaces.live.com
O tidings of comfort and joy.


Read More
Posted in zbot | No comments

Friday, 18 December 2009

Who is the "Iranian Cyber Army"? Twitter DNS Redirect

Posted on 06:16 by Unknown
(Update: 12JAN10 - Iranian Cyber Army Returns -- Target: Baidu.com )

#1 Search on Google in the past hour: "Iranian Cyber Army"
#2 Search on Google in the past hour: "Twitter hacked"

What do these things have to do with each other?

A formerly unknown group, the Iranian Cyber Army, was able to redirect the DNS for Twitter, causing all visitors to be temporarily redirected to another IP address, not belonging to Twitter, and sharing the message from the Iranian Cyber Army that they are cooler hackers than you.

Since we do actually track website defacers at UAB, and since we've never heard of the Iranian Cyber Army, we thought we would take a quick peek in our favorite Iranian hacker rooms to see who was boasting of their conquest.

First we found "vhdmsm" sharing details of the attack in the Iranian Hacker Forum, Ashiyane Digital Security.

They quote the defacement:

========================

Iranian Cyber Army

THIS SITE HAS BEEN HACKED BY IRANIAN CYBER ARMY

iRANiAN.CYBER.ARMY@GMAIL.COM

U.S.A. Think They Controlling And Managing Internet By Their Access, But THey Don't, We Control And Manage Internet By Our Power, So Do Not Try To Stimulation Iranian Peoples To....

NOW WHICH COUNTRY IN EMBARGO LIST? IRAN? USA?

WE PUSH THEM IN EMBARGO LIST

Take Care

=====================
and post links to the Twitter Blog entry about the attack, and a CNET news story.

But there is no indication they were themselves involved.

We're going to need some more evidence. Perhaps someone should be talking to the folks at BlueHost this morning.

See for yourself?


A little twiddling with various DNS Caching systems, and we were able to find the IP address to which traffic had been redirected:

66.147.244.182

There are some interesting domains there, including:

http://mowjcamp.net/

That site is interesting, because its on Bluehost, in the United States.

which currently shows content made from these graphic files (I've moved them to a more permanent location...just in case):










In my opinion, it looks like that server was compromised via WordPress vulnerabilities, but that is just an educated guess based on content at this time. So, it looks like the hacker first hacked one of the sites on the Bluehost box, other mowjcamp.org, wpcrowd.com, or coventryri.com, then redirected all the twitter traffic to that IP by changing the Nameserver entries for Twitter to point away from their normal Google-provided IP addresses to 66.147.242.88 instead.

Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • Microsoft Security Intelligence Report 2H08
    The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microso...
  • Operation Open Market: The Vendors
    When we wrote last week about Operation Open Market the court documents had not yet been released in a major multi-agency Identity Theft ca...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile