Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 10 November 2009

Zeus / Zbot Malware moves Back to IRS

Posted on 08:44 by Unknown
After a vigorous day of spamming a Fake Myspace Update Tool, the criminals behind this campaign have refocused their efforts back to the Internal Revenue Service.

This time around the spam is almost identical to that which we saw from the September 11th until October 17th. We wrote about this a couple times in articles such as IRS Version of Zeus Continues and A Weekend of Old News, both of which listed many websites previously used by the criminal.

The websites seen so far this morning by the UAB Spam Data Mine have included:

www.irs.gov.ooolnz.co.uk
www.irs.gov.ooolnz.me.uk
www.irs.gov.ooolnz.org.uk
www.irs.gov.ooolnzq.co.uk
www.irs.gov.ooolnzq.me.uk
www.irs.gov.ooolnzq.org.uk
www.irs.gov.ooolnzs.co.uk
www.irs.gov.ooolnzs.me.uk
www.irs.gov.ooolnzs.org.uk
www.irs.gov.oouask.co.uk
www.irs.gov.oouask.me.uk
www.irs.gov.oouask.org.uk
www.irs.gov.oouaso.co.uk
www.irs.gov.oouaso.me.uk
www.irs.gov.oouaso.org.uk
www.irs.gov.oouasr.co.uk
www.irs.gov.oouasr.me.uk
www.irs.gov.oouasr.org.uk
www.irs.gov.oouasv.co.uk
www.irs.gov.oouasv.me.uk
www.irs.gov.oouasv.org.uk
www.irs.gov.oouasz.co.uk
www.irs.gov.oouasz.me.uk
www.irs.gov.oouasz.org.uk
www.irs.gov.ssveef.co.uk
www.irs.gov.ssveef.me.uk
www.irs.gov.ssveef.org.uk
www.irs.gov.ssveeh.co.uk
www.irs.gov.ssveeh.me.uk
www.irs.gov.ssveeh.org.uk
www.irs.gov.ssveem.co.uk
www.irs.gov.ssveem.me.uk


A fresh website image from this morning.

The current version of the malware is:

File size: 83160 bytes
MD5...: 7b4d6fc7369501229b4d7ca6734c228c

VirusTotal is pretty back-logged at the moment. I'll check back for a detection report later in the day and share the results here.
Read More
Posted in zbot | No comments

Monday, 9 November 2009

Zeus Malware Moves to Myspace

Posted on 06:18 by Unknown
Beginning about 90 minutes ago, the Zeus malware, also known as Zbot, began a new spam distribution campaign to infect more victims. The newest campaign follows the model of last week's Facebook UpdateTool, only now targeting MySpace users.

This update is pretty much in "Breaking News" mode at the moment, we haven't yet run the malware through the lab for a full analysis, but here's what we can tell you so far:

1. There are 30 recently created domains being used as targets in the spam messages. Here are the host names we've seen so far in spam messages:

accounts.myspace.com.deaaaf.co.uk
accounts.myspace.com.deaaaf.me.uk
accounts.myspace.com.deaaaf.org.uk
accounts.myspace.com.deaaag.me.uk
accounts.myspace.com.deaaag.org.uk
accounts.myspace.com.deaaas.me.uk
accounts.myspace.com.deaaas.org.uk
accounts.myspace.com.iiolii.co.uk
accounts.myspace.com.iiolii.me.uk
accounts.myspace.com.iiolii.org.uk
accounts.myspace.com.iiolik.co.uk
accounts.myspace.com.iiolik.me.uk
accounts.myspace.com.iiolik.org.uk
accounts.myspace.com.iiolio.co.uk
accounts.myspace.com.iiolio.me.uk
accounts.myspace.com.iiolio.org.uk
accounts.myspace.com.iioliu.co.uk
accounts.myspace.com.iioliu.me.uk
accounts.myspace.com.iioliu.org.uk
accounts.myspace.com.ttesza.co.uk
accounts.myspace.com.ttesza.org.uk
accounts.myspace.com.tteszf.co.uk
accounts.myspace.com.tteszf.me.uk
accounts.myspace.com.tteszf.org.uk
accounts.myspace.com.tteszg.co.uk
accounts.myspace.com.tteszg.me.uk
accounts.myspace.com.tteszg.org.uk
accounts.myspace.com.tteszk.co.uk
accounts.myspace.com.tteszk.me.uk
accounts.myspace.com.tteszk.org.uk

2. Spam messages are using a variety of subject lines, including:

message id #5332015152732 (note: each message has a random id #)
MySpace Account update
Please update your MySpace account
Update your MySpace account
You are required to update your MySpace account
Your MySpace account

3. The text of the email messages contains:

Dear MySpace user!

Please be informed that you are required to update your MySpace account.

Please update your MySpace account by clicking here:

http://accounts.myspace.com.iiolii.me.uk/msp/index.php?fuseaction=update&code=(random)&email=(email address)

If you're unable to click on the link above, copy and paste it into your browser's address bar.

-------------------------

At MySpace we care about your privacy. This email is never sent unsolicited.

If you think you've received this email in error, or if you have any questions or concerns regarding your privacy, please contact us at:

privacy@myspace.com

MySpace, Inc.
8391 Beverly Blvd. #349
Los Angeles, CA 90048
USA

©2003-2009 MySpace.com. All Rights Reserved.


4. The websites look like this:



5. Logging in takes you to a page that looks like this:



6. The malware is NOT being distributed from these sites. The malware link actually points to a domain created this morning called:

myspace-files.com

which was registered through "Answerable.com", using PrivacyProtection.

We tried to give Answerable a call, but the crappy VOIP forwarding service they are using to connect to their technical support left me with an agent crackling and saying "I'm sorry, I can't understand you." On the third try, I got a very helpful woman in India who referred me to "support.publicdomainregistry.com" to fill out an abuse desk. We've requested that the domain be terminated.

A VirusTotal report shows that while most of the AV products do not yet detect this malware (14 of 41 can detect it), those which do label it either as Zbot or Bifrost.

File size: 108544 bytes
MD5 : 9014141626efee1175ebee3135f3accf

First Update: 10:20 AM


The malware is now back on the same server as advertised by the spam. Seems something happened to their old malware domain. (evil grin). The new path is:

/msp/updatetool.exe

A Fresh VirusTotal Report shows that the malware has changed in both size and signature. Detection is still 14 of 41, but its a different 14.

File size: 105472 bytes
MD5 : 4c7693219eaa304e38f5f989a8346e51

Second Update: 4:20 PM



There have been sixty-nine unique domains seen in this campaign so far today. The currently live domains at this timestamp are:

accounts.myspace.com.iuuuujef.co.uk
accounts.myspace.com.iuuuujef.me.uk
accounts.myspace.com.iuuuujef.org.uk
accounts.myspace.com.iuuuujeg.co.uk
accounts.myspace.com.iuuuujeg.me.uk
accounts.myspace.com.iuuuujeg.org.uk
accounts.myspace.com.iuuuujek.co.uk
accounts.myspace.com.iuuuujek.me.uk
accounts.myspace.com.iuuuujek.org.uk
accounts.myspace.com.iuuuujer.co.uk
accounts.myspace.com.iuuuujer.me.uk
accounts.myspace.com.yyyyiuj.co.uk
accounts.myspace.com.yyyyiuj.me.uk
accounts.myspace.com.yyyyiuj.org.uk
accounts.myspace.com.yyyyiuk.co.uk
accounts.myspace.com.yyyyiuk.me.uk
accounts.myspace.com.yyyyiuk.org.uk
accounts.myspace.com.yyyyiuo.co.uk
accounts.myspace.com.yyyyiuo.me.uk
accounts.myspace.com.yyyyiuo.org.uk
accounts.myspace.com.yyyyiur.co.uk
accounts.myspace.com.yyyyiur.me.uk
accounts.myspace.com.yyyyiur.org.uk


These have been reported to the Fox Interactive Media and MySpace abuse teams for termination.
Read More
Posted in zbot | No comments

Saturday, 31 October 2009

Facebook Safety & Million Member Facebook Groups

Posted on 16:09 by Unknown
Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were:

PETITION FOR FACEBOOK TO INSTALL A DISLIKE BUTTON...NEED 1,000,000 MEMBERS ASAP..INVITE EVERYONE YOU KNOW TO JOIN

and

If 1,000,001 people join, Facebook will re-install the old News Feed!


The first group, IN SIX DAYS, has grown from 1 user to 401,200 users! Some of you are cheering saying, YES! Now Facebook will be FORCED to have a "Dislike" button!

The second group now has 719,000 users! HINT: Despite the topic, Facebook is not going to re-install the old News Feed.

Would you like to see the secret truth about why people create "million user groups"?

Enter the seedy world of the online advertiser. Not the Madison Avenue advertising companies, but the punks who sit at home and devise ways to advertise their wares through spam, SEO (search engine optimization), and social network spam. They are making more money than you, and filling our lives with virtual junkmail, and in many cases, malware.

Note that what they are doing below is probably NOT illegal. Slimy, yes. Illegal? No. Although it may violate Facebook rules, that's an issue for Facebook, not the police.

Here's an example post from a forum on a "Black Hat" website. The forum is in a group called:

Black Hat Forum > Black Hat SEO > Social Networking Sites > FaceBook

The user "almir" is a typical user there. After each of his messages to his shady advertising friends, he signs with his own advertisement -- claiming that he controls a Facebook Group with 550,000 members, and he'll post your message to his group for $800. Almir says that between his groups, he has about 2 million people he can post to on Facebook. At his peak he was making about $250 per day from his ads, and he says on a good day, he could make $600. Lets see. 365 * 250 = $91,250 per year. Not bad money for making up reasons that a million people should join your group.

Another user there, "LeDave", claims he controls more than 100 Facebook groups, and the ads that he posts there generate between 6,000 and 7,000 clicks per day to "ClickBank". (ClickBank is an affiliate advertising site where you get paid every time someone follows your link. Following the links makes money for the guy controlling the Facebook group. If the users BUY things, you get a commission.) LeDave claims he was the creator of the "1,000,000 members against the new facebook layout" group. He claims he grew that group to more than 3 million users! Why? So he could make money selling links to his members!

One of the other members has a group with 1.5 million users. He offers to help newbie advertisers "get launched" by recommending their group to his users for the low low price of $100 per recommendation.

(this information from the thread . . .

http://www.blackhatworld.com/blackhat-seo/facebook/130560-facebook-groups-finally-getting-makeover-hard-make-viral-group-again.html

)

So, remember that the next time you join a "million member group", what you are really doing is helping these advertisers make it easier to spam you with their ads. While it may seem a great "social cause", its not. Nobody cares if 1 million people join the group. Except the guy getting paid for it.

Here are a few other "of course, we should join that!" million member groups:

I bet I can find 1,000,000 people who hate cancer
Members: 1,609,864 members

I bet I can still find 1,000,000 people who dislike George Bush!
Members: 968,146 members

1,000,000 Hamish and Andy Fans by 01/01/10
Members: 731,824 members

1,000,000 AGAINST THE NEW FACEBOOK LOOK!!!
Members: 713,565 members

"WE HAVE TO SAVE FACEBOOK" PETITION - 1,000,000 PEOPLE NEEDED!!!!!
Members: 466,648 members

I Bet I Can Find 1,000,000 People Who Just Want Peace
Members: 379,282 members

Not saying that all those groups are advertising driven. Just suggesting that its a serious possibility.

Yes, I like Facebook! (But not all the Apps)



Are you surprised? Yes, I'm a Cybercrime Investigations guy who likes Facebook. I give a "Privacy & Security" lecture to our CIS 105 class each term at the University where I warn of the dangers of Social Network Sites, but when used properly, I love Facebook (for play) and LinkedIn (for work).

In my lectures I warn of things like having your privacy settings set too broadly - sharing your information with the whole world - and things like installing Applications without understanding who wrote them or what their Terms of Service are.

Facebook has been getting better with setting rules for their developers, but its still important to know what access and rights developers have to your personal information when you use their apps. My general rule is that if I don't know the developer, I don't install the app. For instance, I play PopCap games in Facebook. I've used their apps for years, I've worked with their tech support, and I trust them to do the right thing. I have no idea who wrote the Facebook Application "How Long Will You Survive When Zombies Rule the World", but 1,461,000 Facebook users have trusted them to do the right thing with their personal data. To install the app in Facebook (as with every app) I am cautioned:

By proceeding, you are allowing How long will you survive when zombies over run the world? to access your information and you are agreeing to the Facebook Terms of Use in your use of How long will you survive when zombies over run the world?


I'm not so trusting with strangers. (No offense, Zombie dudes. Random example from things I was invited to install today.)

Those "Terms of Use" link you to the "About Platform" page, which reminds you that when you install an application, you are giving the developer of that application permission to access such things as:

your name, your profile picture, your gender, your birthday, your hometown location (city/state/country), your current location (city/state/country), your political view, your activities, your interests, your musical preferences, television shows in which you are interested, movies in which you are interested, books in which you are interested, your favorite quotes, your relationship status, your dating interests, your relationship interests, your network affiliations, your education history, your work history, your course information, copies of photos in your photo albums, metadata associated with your photo albums (e.g., time of upload, album name, comments on your photos, etc.), the total number of messages sent and/or received by you, the total number of unread messages in your in-box, the total number of "pokes" you have sent and/or received, the total number of wall posts on your Wall, a list of user IDs mapped to your friends, your social timeline, notifications that you have received from other applications, and events associated with your profile.



If you want to know more about Applications on Facebook, here are the new policies that Application Developers have to agree to follow -- Facebook: Developer Principles and Policies.

Tips for Facebook Users, From Facebook


I know the guys at Facebook and have been very pleased with how pro-active they are with responding to security issues, and with warning their users. If you haven't seen these steps, you should definitely check them out.

Facebook: Protecting Account Security

Facebook: Privacy Settings and Fundamentals

There are lots of other great tips from Facebook. I would encourage users (and parents of children who use Facebook) to visit their Help Center to learn more.
Read More
Posted in | No comments

Wednesday, 28 October 2009

FACEBOOK PHISH! Users Beware!

Posted on 07:30 by Unknown
The FDIC spam campaign that we reported on yesterday in our story Fake FDIC Spam Campaign Spreads Zeus has already moved on to its next attack. Now its trying to steal your Facebook passwords in what appears at first glance to be a "traditional" phishing attack. (Please see the end of this article for an update on how this "phish" actually is another Zeus malware infection vector.)



The UAB Spam Data Mine has already received more than 250 copies of the new phishing email this morning, which claims:

In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security.

Before you are able to use the new login system, you will be required to update your account.

Click (here) to update your account online now.

If you have any questions, reference our New User Guide

Thanks,
The Facebook Team


The email is fake, of course, and so are the websites they point to. So far we've identified 31 unique domain names registered by the criminal for use in this Facebook account.

The website looks like this:



UAB Malware Analyst Brian Tanner took the new Facebook Phish for a drive through the lab, and confirmed that this is NOT JUST A PHISH - in fact it might not be a traditional phish at all. Its actually a Zeus Bot installer, pointing at the same command & control site as yesterday's FDIC version of Zeus:



Clicking on the prompted "UpdateTool.exe" is the infection vector for Zeus. According to the VirusTotal Report for this malware, only 8 of 41 AV products are currently labelling this executable as malware.

File size: 105472 bytes
MD5 : 1198d2ddf09061fbfb70de423cde059f

Update 29OCT09 AM


Spam for this campaign is still coming fast and furious to the UAB Spam Data Mine. More than 200 fresh copies were received already this morning.

File size: 105984 bytes
MD5...: 6aad88ba4805b2daa4fc6106a5376065

A
VirusTotal report
for the current version is showing 9 of 41 detections.

Update - 01NOV2009


From October 27th until November 1st, we've seen 242 different domain names used by this campaign. Here are the ones that are currently live at this point in time (5:25 PM) --

www.facebook.com.heratsb.eu
www.facebook.com.heratsd.eu
www.facebook.com.heratsf.eu
www.facebook.com.heratsg.eu
www.facebook.com.heratsh.eu
www.facebook.com.heratsk.eu
www.facebook.com.heratsl.eu
www.facebook.com.heratsm.eu
www.facebook.com.heratsn.eu
www.facebook.com.heratso.eu
www.facebook.com.heratsq.eu
www.facebook.com.heratsr.eu
www.facebook.com.heratss.eu
www.facebook.com.heratst.eu
www.facebook.com.heratsy.eu
www.facebook.com.lllujiob.eu
www.facebook.com.lllujioc.eu
www.facebook.com.lllujiod.eu
www.facebook.com.lllujiof.eu
www.facebook.com.lllujiog.eu
www.facebook.com.lllujioh.eu
www.facebook.com.lllujioi.eu
www.facebook.com.lllujioj.eu
www.facebook.com.lllujion.eu
www.facebook.com.lllujiot.eu
www.facebook.com.lllujiov.eu
www.facebook.com.lllujiox.eu
www.facebook.com.lllujioy.eu
www.facebook.com.lllujioz.eu
www.facebook.com.ttteraa.eu
www.facebook.com.ttterab.eu
www.facebook.com.ttterac.eu
www.facebook.com.ttterad.eu
www.facebook.com.ttterae.eu
www.facebook.com.ttteraf.eu
www.facebook.com.ttterag.eu
www.facebook.com.ttteran.eu
www.facebook.com.ttteraq.eu
www.facebook.com.ttterav.eu
www.facebook.com.ttterax.eu
www.facebook.com.ttteraz.eu

Here is the full list . . .

www.facebook.com.edilokqf.eu
www.facebook.com.edilokqi.eu
www.facebook.com.edilokqm.eu
www.facebook.com.edilokqn.eu
www.facebook.com.edilokqr.eu
www.facebook.com.edilokqs.eu
www.facebook.com.edilokqu.eu
www.facebook.com.edilokqv.eu
www.facebook.com.edilokqw.eu
www.facebook.com.edilokqx.eu
www.facebook.com.eiye1ua.eu
www.facebook.com.eiye1uc.eu
www.facebook.com.eiye1ue.eu
www.facebook.com.eiye1uf.eu
www.facebook.com.eiye1ug.eu
www.facebook.com.eiye1ur.eu
www.facebook.com.eiye1us.eu
www.facebook.com.eiye1ut.eu
www.facebook.com.eiye1uv.eu
www.facebook.com.fasazab.eu
www.facebook.com.fasazad.eu
www.facebook.com.fasazae.eu
www.facebook.com.fasazaf.eu
www.facebook.com.fasazag.eu
www.facebook.com.fasazam.eu
www.facebook.com.fasazan.eu
www.facebook.com.fasazav.eu
www.facebook.com.heratsb.eu
www.facebook.com.heratsd.eu
www.facebook.com.heratsf.eu
www.facebook.com.heratsg.eu
www.facebook.com.heratsh.eu
www.facebook.com.heratsk.eu
www.facebook.com.heratsl.eu
www.facebook.com.heratsm.eu
www.facebook.com.heratsn.eu
www.facebook.com.heratso.eu
www.facebook.com.heratsq.eu
www.facebook.com.heratsr.eu
www.facebook.com.heratss.eu
www.facebook.com.heratst.eu
www.facebook.com.heratsy.eu
www.facebook.com.herrazzb.eu
www.facebook.com.herrazzd.eu
www.facebook.com.herrazzf.eu
www.facebook.com.herrazzg.eu
www.facebook.com.herrazzh.eu
www.facebook.com.herrazzj.eu
www.facebook.com.herrazzk.eu
www.facebook.com.herrazzo.eu
www.facebook.com.herrazzr.eu
www.facebook.com.herrazzt.eu
www.facebook.com.herrazzu.eu
www.facebook.com.herrazzv.eu
www.facebook.com.herrazzy.eu
www.facebook.com.ibbaswza.eu
www.facebook.com.ibbaswzd.eu
www.facebook.com.ibbaswze.eu
www.facebook.com.ibbaswzf.eu
www.facebook.com.ibbaswzr.eu
www.facebook.com.iokasqzc.eu
www.facebook.com.iokasqze.eu
www.facebook.com.iokasqzh.eu
www.facebook.com.iokasqzr.eu
www.facebook.com.iokasqzt.eu
www.facebook.com.iokasqzy.eu
www.facebook.com.ioooliob.eu
www.facebook.com.iooolioc.eu
www.facebook.com.iooolioe.eu
www.facebook.com.ioooliog.eu
www.facebook.com.iooolioq.eu
www.facebook.com.iooolior.eu
www.facebook.com.iooolios.eu
www.facebook.com.ioooliot.eu
www.facebook.com.ioooliov.eu
www.facebook.com.ioooliow.eu
www.facebook.com.ioooliox.eu
www.facebook.com.iooolioy.eu
www.facebook.com.lef1asza.eu
www.facebook.com.lefassza.eu
www.facebook.com.lefaszab.eu
www.facebook.com.lefaszac.eu
www.facebook.com.lefaszad.eu
www.facebook.com.lefaszak.eu
www.facebook.com.lefaszam.eu
www.facebook.com.lefaszan.eu
www.facebook.com.lefaszav.eu
www.facebook.com.lefaszax.eu
www.facebook.com.lefaszxa.eu
www.facebook.com.lefawsza.eu
www.facebook.com.lllujiob.eu
www.facebook.com.lllujioc.eu
www.facebook.com.lllujiod.eu
www.facebook.com.lllujiof.eu
www.facebook.com.lllujiog.eu
www.facebook.com.lllujioh.eu
www.facebook.com.lllujioi.eu
www.facebook.com.lllujioj.eu
www.facebook.com.lllujion.eu
www.facebook.com.lllujiot.eu
www.facebook.com.lllujiov.eu
www.facebook.com.lllujiox.eu
www.facebook.com.lllujioy.eu
www.facebook.com.lllujioz.eu
www.facebook.com.mibbbad.co.uk
www.facebook.com.mibbbad.me.uk
www.facebook.com.mibbbad.org.uk
www.facebook.com.mibbbah.co.uk
www.facebook.com.mibbbah.me.uk
www.facebook.com.mibbbah.org.uk
www.facebook.com.mibbbal.co.uk
www.facebook.com.mibbbal.me.uk
www.facebook.com.oooeasec.eu
www.facebook.com.oooeasef.eu
www.facebook.com.oooeaseg.eu
www.facebook.com.poresawa.eu
www.facebook.com.poresawd.eu
www.facebook.com.poresawe.eu
www.facebook.com.poresawg.eu
www.facebook.com.poresawj.eu
www.facebook.com.poresawo.eu
www.facebook.com.poresawq.eu
www.facebook.com.poresaws.eu
www.facebook.com.poresawt.eu
www.facebook.com.poresawu.eu
www.facebook.com.poresawv.eu
www.facebook.com.poresawx.eu
www.facebook.com.qqqqasc.eu
www.facebook.com.qqqqasd.eu
www.facebook.com.qqqqasf.eu
www.facebook.com.qqqqasg.eu
www.facebook.com.qqqqash.eu
www.facebook.com.qqqqasj.eu
www.facebook.com.qqqqask.eu
www.facebook.com.qqqqasl.eu
www.facebook.com.qqqqaso.eu
www.facebook.com.qqqqasr.eu
www.facebook.com.qqqqasy.eu
www.facebook.com.saaasaj.eu
www.facebook.com.saaasak.eu
www.facebook.com.saaasam.eu
www.facebook.com.saaasav.eu
www.facebook.com.saaasay.eu
www.facebook.com.saxzask.co.uk
www.facebook.com.saxzask.me.uk
www.facebook.com.saxzask.org.uk
www.facebook.com.saxzasl.co.uk
www.facebook.com.saxzasl.me.uk
www.facebook.com.saxzasl.org.uk
www.facebook.com.saxzasv.co.uk
www.facebook.com.saxzasv.me.uk
www.facebook.com.saxzasv.org.uk
www.facebook.com.saxzasy.co.uk
www.facebook.com.sazzawe.co.uk
www.facebook.com.sazzawe.eu
www.facebook.com.sazzawe.me.uk
www.facebook.com.sazzawf.co.uk
www.facebook.com.sazzawf.eu
www.facebook.com.sazzawf.me.uk
www.facebook.com.sazzawk.co.uk
www.facebook.com.sazzawk.eu
www.facebook.com.sazzawk.me.uk
www.facebook.com.sazzawl.co.uk
www.facebook.com.sazzawl.eu
www.facebook.com.sazzawl.me.uk
www.facebook.com.sazzawy.co.uk
www.facebook.com.sazzawy.eu
www.facebook.com.sazzawy.me.uk
www.facebook.com.ttteraa.eu
www.facebook.com.ttterab.eu
www.facebook.com.ttterac.eu
www.facebook.com.ttterad.eu
www.facebook.com.ttterae.eu
www.facebook.com.ttteraf.eu
www.facebook.com.ttterag.eu
www.facebook.com.ttteran.eu
www.facebook.com.ttteraq.eu
www.facebook.com.ttterav.eu
www.facebook.com.ttterax.eu
www.facebook.com.ttteraz.eu
www.facebook.com.ujtqwaq1.co.uk
www.facebook.com.ujtqwaq1.eu
www.facebook.com.ujtqwaq1.me.uk
www.facebook.com.ujtqwaq1.org.uk
www.facebook.com.ujtqwaqb.co.uk
www.facebook.com.ujtqwaqb.eu
www.facebook.com.ujtqwaqb.me.uk
www.facebook.com.ujtqwaqb.org.uk
www.facebook.com.ujtqwaqk.co.uk
www.facebook.com.ujtqwaqk.eu
www.facebook.com.ujtqwaqk.me.uk
www.facebook.com.ujtqwaqk.org.uk
www.facebook.com.ujtqwaqm.co.uk
www.facebook.com.ujtqwaqm.eu
www.facebook.com.ujtqwaqm.org.uk
www.facebook.com.ujtqwaqo.co.uk
www.facebook.com.ujtqwaqo.eu
www.facebook.com.ujtqwaqo.me.uk
www.facebook.com.ujtqwaqo.org.uk
www.facebook.com.xxxasqwa.eu
www.facebook.com.xxxasqwe.eu
www.facebook.com.xxxasqwi.eu
www.facebook.com.xxxasqwk.eu
www.facebook.com.xxxasqwl.eu
www.facebook.com.xxxasqwo.eu
www.facebook.com.xxxasqwp.eu
www.facebook.com.xxxasqwr.eu
www.facebook.com.xxxasqwt.eu
www.facebook.com.xxxasqwu.eu
www.facebook.com.xxxasqwy.eu
www.facebook.com.xxxasqwz.eu
www.facebook.com.yhheaszb.eu
www.facebook.com.yhheaszc.eu
www.facebook.com.yhheasze.eu
www.facebook.com.yhheaszf.eu
www.facebook.com.yhheaszh.eu
www.facebook.com.yhheaszi.eu
www.facebook.com.yhheaszq.eu
www.facebook.com.yhheaszu.eu
www.facebook.com.yhheaszv.eu
www.facebook.com.yhheaszy.eu
www.facebook.com.yy1azsva.eu
www.facebook.com.yy1azsvc.eu
www.facebook.com.yy1azsvq.eu
www.facebook.com.yy1azsvz.eu
www.facebook.com.yyy1asvf.eu
www.facebook.com.yyy1azsy.eu
www.facebook.com.yyy1azvg.eu
www.facebook.com.yyy1zsve.eu
www.facebook.com.yyyaszai.eu
www.facebook.com.yyyaszal.eu
www.facebook.com.yyyaszao.eu
www.facebook.com.yyyaszap.eu
www.facebook.com.yyyaszaq.eu
www.facebook.com.yyyaszar.eu
www.facebook.com.yyyaszau.eu
www.facebook.com.yyyaszay.eu
www.facebook.com.yyyazsvd.eu
www.facebook.com.zaaaasaa.eu
www.facebook.com.zaaaasag.eu
www.facebook.com.zaaaasaq.eu
www.facebook.com.zaaaasaz.eu
Read More
Posted in phishing, spam, zbot | No comments

Tuesday, 27 October 2009

Fake FDIC spam campaign spreads Zeus malware

Posted on 08:47 by Unknown
The UAB Spam Data Mine is continuing to experience high volumes of spam claiming to be from the Federal Deposit Insurance Corporation. FDIC.gov spam is using two email subjects:

FDIC has officially named your bank a failed bank
you need to check your Bank Deposit Insurance Coverage

The email messages claim to be from the email address consumeralerts@fdic.gov, which is a real email address used by the FDIC, but obviously being forged by the malware distributors in this situation.

Here's an example email:



You have received this message because you are a holder of a FDIC-insured bank account. Recently FDIC has officially named the bank you have opened your account with as a failed bank, thus, taking control of its assets.

You need to visit the official FDIC website and perform the following steps to check your Deposit Insurance Coverage:

* Visit FDIC website: http://www.fdic.gov/bankinsured/failed/personalfile/holder.php?email=youremail@yourdomain.com&id=233388521333599678361293755617839671

* Download and open your personal FDIC Insurance File to check your Deposit Insurance Coverage

Federal Deposit Insurance Corporation


The website to which you are directed looks like this:



The website offers a copy of "your personal FDIC Insuranace file" to see whether your coverage has been impacted. The website seems to offer this file as either an Adobe PDF file or a Microsoft Word file. In reality, the first is named "pdf.exe" and the second is named "word.exe", which are both the same file - a 105,472 byte executable file.

A VirusTotal report indicates that currently 9 anti-virus products are able to label this version of the malware, which we expect will be changed regularly by the criminals:

File size: 105472 bytes
MD5 : f4007a6af6dc841cd2961a8b3d2fbb8e

The detections declare it to be Zeus Bot, and UAB Malware Analyst Brian Tanner examined the malware in the lab and confirmed the same, identifying the location of the command & control server and sharing that information with appropriate law enforcement officials.


So far UAB researchers have identified 93 unique domains registered and used by the criminals for this campaign:

www.fdic.gov.h1erfae.eu
www.fdic.gov.h1erfai.eu
www.fdic.gov.h1erfaj.eu
www.fdic.gov.h1erfaq.eu
www.fdic.gov.h1erfar.eu
www.fdic.gov.h1erfat.eu
www.fdic.gov.h1erfau.eu
www.fdic.gov.h1erfaw.eu
www.fdic.gov.h1erfay.eu
www.fdic.gov.milki1a.co.uk
www.fdic.gov.milki1a.me.uk
www.fdic.gov.milki1e.me.uk
www.fdic.gov.milki1i.co.uk
www.fdic.gov.milki1l.co.uk
www.fdic.gov.milki1l.me.uk
www.fdic.gov.milki1y.me.uk
www.fdic.gov.nyuh1awa.eu
www.fdic.gov.nyuh1awb.eu
www.fdic.gov.nyuh1awc.eu
www.fdic.gov.nyuh1awd.eu
www.fdic.gov.nyuh1awe.eu
www.fdic.gov.nyuh1awf.eu
www.fdic.gov.nyuh1awg.eu
www.fdic.gov.nyuh1awh.eu
www.fdic.gov.nyuh1awm.eu
www.fdic.gov.nyuh1awn.eu
www.fdic.gov.nyuh1aws.eu
www.fdic.gov.nyuh1awt.eu
www.fdic.gov.nyuh1awv.eu
www.fdic.gov.nyuh1awx.eu
www.fdic.gov.nyuh1awz.eu
www.fdic.gov.ookilfd.eu
www.fdic.gov.ookilfe.eu
www.fdic.gov.ookilff.eu
www.fdic.gov.ookilfg.eu
www.fdic.gov.ookilfh.eu
www.fdic.gov.ookilfj.eu
www.fdic.gov.ookilfk.eu
www.fdic.gov.ookilfs.eu
www.fdic.gov.ookilfv.eu
www.fdic.gov.ookilfx.eu
www.fdic.gov.pouikib.eu
www.fdic.gov.pouikic.eu
www.fdic.gov.pouikie.eu
www.fdic.gov.pouikig.eu
www.fdic.gov.pouikiq.eu
www.fdic.gov.pouikir.eu
www.fdic.gov.pouikis.eu
www.fdic.gov.pouikit.eu
www.fdic.gov.pouikiv.eu
www.fdic.gov.pouikiw.eu
www.fdic.gov.pouikix.eu
www.fdic.gov.pouikiy.eu
www.fdic.gov.tt1qwa1.co.uk
www.fdic.gov.tt1qwa1.eu
www.fdic.gov.tt1qwa1.me.uk
www.fdic.gov.tt1qwae.eu
www.fdic.gov.tt1qwae.me.uk
www.fdic.gov.tt1qwaq.co.uk
www.fdic.gov.tt1qwaq.eu
www.fdic.gov.tt1qwaq.me.uk
www.fdic.gov.tt1qwar.co.uk
www.fdic.gov.tt1qwar.eu
www.fdic.gov.tt1qwar.me.uk
www.fdic.gov.tt1qwat.co.uk
www.fdic.gov.tt1qwat.eu
www.fdic.gov.tt1qwat.me.uk
www.fdic.gov.tygerah.co.uk
www.fdic.gov.tygerah.eu
www.fdic.gov.tygerah.me.uk
www.fdic.gov.tygerak.co.uk
www.fdic.gov.tygerak.eu
www.fdic.gov.tygerak.me.uk
www.fdic.gov.tygerat.co.uk
www.fdic.gov.tygerat.eu
www.fdic.gov.tygerat.me.uk
www.fdic.gov.tygeraw.co.uk
www.fdic.gov.tygeraw.eu
www.fdic.gov.tygeraw.me.uk
www.fdic.gov.tygeraz.co.uk
www.fdic.gov.tygeraz.eu
www.fdic.gov.tygeraz.me.uk
www.fdic.gov.yh1qab.co.uk
www.fdic.gov.yh1qab.eu
www.fdic.gov.yh1qab.me.uk
www.fdic.gov.yh1qak.co.uk
www.fdic.gov.yh1qak.eu
www.fdic.gov.yh1qal.co.uk
www.fdic.gov.yh1qal.eu
www.fdic.gov.yh1qal.me.uk
www.fdic.gov.yh1qao.co.uk
www.fdic.gov.yh1qaz.co.uk
www.fdic.gov.yh1qaz.eu

Of these, 38 domains are currently live:

www.fdic.gov.h1erfau.eu
www.fdic.gov.ookilfd.eu
www.fdic.gov.ookilfe.eu
www.fdic.gov.ookilff.eu
www.fdic.gov.ookilfg.eu
www.fdic.gov.ookilfh.eu
www.fdic.gov.ookilfj.eu
www.fdic.gov.ookilfk.eu
www.fdic.gov.ookilfs.eu
www.fdic.gov.ookilfv.eu
www.fdic.gov.ookilfx.eu
www.fdic.gov.pouikib.eu
www.fdic.gov.pouikic.eu
www.fdic.gov.pouikie.eu
www.fdic.gov.pouikig.eu
www.fdic.gov.pouikiq.eu
www.fdic.gov.pouikir.eu
www.fdic.gov.pouikis.eu
www.fdic.gov.pouikit.eu
www.fdic.gov.pouikiv.eu
www.fdic.gov.pouikiw.eu
www.fdic.gov.pouikix.eu
www.fdic.gov.pouikiy.eu
www.fdic.gov.tygerah.co.uk
www.fdic.gov.tygerah.eu
www.fdic.gov.tygerah.me.uk
www.fdic.gov.tygerak.co.uk
www.fdic.gov.tygerak.eu
www.fdic.gov.tygerak.me.uk
www.fdic.gov.tygerat.co.uk
www.fdic.gov.tygerat.eu
www.fdic.gov.tygerat.me.uk
www.fdic.gov.tygeraw.co.uk
www.fdic.gov.tygeraw.eu
www.fdic.gov.tygeraw.me.uk
www.fdic.gov.tygeraz.co.uk
www.fdic.gov.tygeraz.eu
www.fdic.gov.tygeraz.me.uk



UPDATE!

- 27OCT09 4PM in Alabama:

The FDIC's Sandra L. Thompson, Director of the Division of Supervision and Consumer Protection has provided an update to this emerging threat on their website:

http://www.fdic.gov/news/news/SpecialAlert/2009/sa09183.html

We're currently down to 16 "live" sites that we've seen in this afternoon's FDIC spam:

www.fdic.gov.ookilfh.eu
www.fdic.gov.ookilfj.eu
www.fdic.gov.ookilfs.eu
www.fdic.gov.pouikib.eu
www.fdic.gov.pouikic.eu
www.fdic.gov.pouikie.eu
www.fdic.gov.pouikig.eu
www.fdic.gov.pouikiq.eu
www.fdic.gov.pouikir.eu
www.fdic.gov.pouikis.eu
www.fdic.gov.pouikit.eu
www.fdic.gov.pouikiv.eu
www.fdic.gov.pouikiw.eu
www.fdic.gov.pouikix.eu
www.fdic.gov.pouikiy.eu
www.fdic.gov.pouikif.eu
Read More
Posted in spam, zbot | No comments

Thursday, 22 October 2009

FBI and SOCA make a media splash at RSA Europe

Posted on 18:00 by Unknown
I'm returned, sleep-deprived and jet-lagged, from back-to-back conferences in the Seattle area. First there was the Microsoft-hosted Digital Crimes Consortium, which combined three prior conferences - Law Enforcement Tech, Digital PhishNet, and the Botnet conference, into one. With some 400 attendees from more forty different countries, many great international law enforcement collaborations will come from that event. Microsoft was a fantastic host, as always, and the law enforcement folks got a special "badges only" day at the beginning of the conference to learn about new tools from Microsoft to help in the fight against cybercrime.

Next was the Anti-Phishing Working Group / IEEE eCrime Researchers Summit, where UAB students Brad Wardman and Gaurang Shukla and I presented a paper on analyzing phishing URLs to reveal underlying website vulnerabilities being exploited by cyber criminals. Many great papers were presented by academics from around the world, and encouraged by some great corporate and law enforcement participants to continue this growing area of research. The APWG staff, and Randal Vaughn from Baylor, and the whole gang from Internet Identity put together a great conference! Friends from Citibank, Google, PhishLabs, SilverTail, eBay, Affilias, SupportIntelligence, Cyveillance and others shared great industry perspectives to help inform the academics of their pain points that could benefit from research, as well as sharing research of their own. I was especially excited to learn of some fellow dataminers at University of Ballarat, Australia, and to see what they are doing with phishing email detection, but there was a great crowd of researchers presenting from Mississippi State, Texas State, Carnegie Mellon, University College Dublin, University of Konstanz, and University of Buffalo. You'll be able to read all the papers in the near future through the IEEE Proceedings.

But I have to say, despite the jet-lag, I really wish I was at RSA Europe right now. The big news today was a presentation by FBI Supervisory Special Agent Keith Mularski and Andy Auld from the Serious and Organised Crime Agency (SOCA).

I'm tired, so I'm going to let the media tell the story . . . please read the articles below and accept my apologies for not writing my own.

Some of the articles had to take the mud-slinging side of the story:

"Russian Police and Internet Registry Accused of Aiding Cybercrime" (eweek Europe)

"SOCA: Russian Cyber Gang Bribed Police" (ZD Net)

Still, the important points did make it through the hype machine:

"FBI and SOCA need help" (Computer Weekly)

where Keith Mularski says "A partnership with the IT Security industry is important" and Andy Auld, head of intelligence and e-crime at SOCA says "The US, UK, Germany, Netherlands, and Australia have all joined forces to form a taskforce to tackling this international problem."

"FBI and SOCA Seek Help From Security Teams" (V3)

Some saw it as painting a gloomy future:

"Experts See Forecast Worsen for Cybercrime" (PC World)


While others painted it in a more sensational positive light:

"FBI and SOCA plot cybercrime smackdown: White hats get proactive on e-crime" (The Register)

I've worked with both guys in the past, and I know how I'm interpreting the presentation: We've got a big problem we are facing, and only through global cooperation by law enforcement AND industry can we solve it. That's the same messages we heard at Digital Crimes and the same message we heard at APWG eCrimes, but unlike the past, the current round of conferences wasn't just talk. It was presentation after presentation of how the cooperation is actually working!

I have to give one shout-out while I'm blogging. It was great to make a new Russian friend, Pavel, who came all the way to Tacoma to share the message that there are plenty of "good guys" in Russia. Thanks for making the trip, Pavel!
Read More
Posted in | No comments

Wednesday, 21 October 2009

Phishing For Love: Banking Insiders

Posted on 11:39 by Unknown
This week in the Eastern District of Pennsylvania, an indictment was unsealed against Miguel Bell, Christopher Russell, Michael Merin, Kareem Russell, and Tamika Brown for their actions in stealing more than $1 Million from Citizens Bank, PNC Bank, Wachovia Bank, M&T Bank, Provident Bank, and SunTrust Bank. Michael Levy, US Attorney in that district, brought the charges.

This entire article is a summation of the charges from the extremely detailed sixty-one page indictment.

The five were charged with the following violations:

18 U.S.C. § 371 - conspiracy to commit bank fraud and aggravated identity theft
18 U.S.C. § 1344 - bank fraud -8 counts
18 U.S.C. § 1028A - aggravated identity theft - 34 counts
18 U.S.C. § 2 - aiding and abetting

The charges resulted from activities between September 1, 2005 and November 30, 2008.

Miguel Bell



Miguel Bell is accused of being the ringleader in the scheme, which consisted of stealing identifying information and account numbers, and then having "check runners" pose as the bank customers and cash fraudulent checks from the accounts belonging to those whose identities they were using.

Bell developed his information feed by pursuing romantic relationships with bank employees and one insurance company employee, and after gaining their trust, compelling them to provide bank information, customer account numbers, and personal identifying information including names, addresses, dates of birth, social security numbers, and driver's license numbers. Bell's love interests also rented cars which he provided to the check runners in order to cash out the accounts.

Bell also required Michael Merin, Rashin Owens, and David Tunnell to recruit bank employees to provide the same information he was getting from his love interests.

Bell verified high account balances by calling the banks' automated banking telephone services.

Bell provided his check runners with fraudulent driver's licenses and to have them photographed, and also provided them with fake checks and "cheat sheets" to help them memorize their new identity. On many occasions he provided transportation and maintained cell phone contact with the check runners while they went into the banks.

Bell took the largest share of all the proceeds, and was in charge of distributing funds to others. Check runners were recruited, used for a day, and paid at the end of the day.

Christopher Russell


The indictment describes Christopher Russell as "the right hand man". Among his roles in the scheme he verified bank balances and recruited check runners, often in exchange for illegal drugs or money for illegal drugs. He accompanied check runners to be photographed for their fraudulent driver's licenses. He provided the identity cheat sheets and fraudulent checks to the check runners, and instructed them on their tasks to perform. He often provided transportation and maintained cell phone contact with the check runners. He would often receive the payout from the check runner, and then pass most of the funds to Miguel Bell for further distribution, and paid the check runners.

Kareem Russell


Kareem is described as a "middle man" in the scheme. He primarily recruited runners, and provided all the same activites as Christopher Russell, including recruiting check runners, providing them with drugs or money for drugs, escorted runners to be photographed for fraudulent drivers licenses, and provided transporation, passed funds to Miguel, and paid his check runners from the proceedings.

Michael Merin


Merin was also called a "middle man", but concentrated on recruiting bank employees in addition to some check runners. Among those recruited:

- Jon Steffon of Citizens Bank (charged elsewhere)
- Kern Haynes of Citizens Bank (charged elsewhere)
- Marcus Nabried of Citizens Bank (charged elsewhere)

Tamika Brown


Tamika Brown was partnered with Christopher Russell and accompanied him in transporting his runners for photography and for fraudulent transactions. She also was in charge of providing the runners with clothes to wear for their photographs and fraud, and for arranging the rental of cars to be used in transporting the check runners.

Recruiting


PNC Bank Employee Tiffany Brodie was in contact with Miguel Bell from at least September 1, 2005 until June 30, 2006, and provided at least four bank accounts and associated personal information to Bell from her customers at PNC Bank.

Tiffany's information allowed check runner James Kennedy to steal $13,050 by pretending to be one of these customers. She also rented cars for Miguel.

Citizens Bank Employee Trena Smith was in contact with Miguel Bell from at least November 1, 2005 until December 20, 2005. She provided information on thirty-seven Citizens Bank account holders, which resulted in $390,039 being stolen by check runners Ralph Guy, Jennie Hill, Priscilla Torres and others, who presented fake ids claiming to be these customers.

Citizens Bank Employee Jon Steffon was recruited by Michael Merin and provided at least fourteen sets of identity data for his customers to Michael, which were used between May 1, 2006 and July 30, 2006 to steal $100,687 from Citizens Bank via check runners. "On or about" June 10, 2006, Miguel Bell possessed hand-written person information on five Citizens Bank account holders, written by Jon STeffon and given to Merin by Steffon. He also held three false Pennsylvanie driver's licenses and two false Delaware driver's licenses in those names, as well as Citibank MasterCards and fraudulent checks in those names.

Citizens Bank Employees Jamila Hamler, Marcus Nabried, and Tamea Hill provided personal information of twenty-seven account holders to Merin between July 1, 2006 and July 30, 2006. Tamea Hill provided at least four additional identities to Elton Harris and Rashin Owens, who passed the information to Miguel Bell. These identities were passed to James Kennedy and other check runners to accomplish $213,145 in theft.

Citizens Bank Employee Kern Haynes provided sixteen accounts to Michael Merin, who then passed the information to Bell and Christopher Russell. These identities were used by check runner Eileen Comire and others to accomplish at least $98,375 in theft.

Citizens Bank Employee Regina Tolliver provided information on seven Citizens Bank account holders which was used between March 1 and November 30, 2007 by check runners Richard Maden and Eileen Comire to withdraw $181,577 using their false identities.

Citizens Bank Employee Deonda Barnett provided twelve identities used to steal $24,172 using check runner Eileen Comire and another $18,312 using check runner James Howard.

Citizens Bank Employee Clarissa Gavin provided six account holder identities, which were used by check runner Tommy Antone Murray, Eileen Comire, David TUnnell and others to cash out $70,811.

Car Dealership Recruitment



Rashin Owens and David Tunnell recruited Damoon Hosseinzadeh, an employee at the car dealership "New Concepts, Inc." to provide identity information regarding customers of the dealership. These were used to take $37,900 from Commerce Bank with David Tunnell acting as the check runner.

Insurance Company Recruitment


Colonial Penn Insurance Company employee Lisa Bryant Nelso was used to provide bank account information for persons banking at Citizens Bank, Wachovia Bank, M&T Bank, Provident Bank, and SunTrust Bank.

Ten Citizens Bank identities provided by Nelson were used by check runners to cash out $33,833.

Twenty-five Wachovia identities provided by Nelson were used by check runners to cash out $134,935.

Twelve M&T Bank account identities provided by Nelson were used by check runners to cash out $53,085.

One Provident Bank identity provided by Nelson was used to cash out $7,000.

One SunTrust identity provided by Nelson was used to cash out $2,250.

The Check Runners


There were SO MANY Check Runners, including:
Ralph Guy, Jennie Hill, Priscilla Torres, Gregory Grayson, David Tunnell, Richard Maden, Eileen Comire, and James Kennedy. The indictment actually details their involvement, claiming . . .

Ralph Guy did 37 checks on identities from Pennsylvania, Vermont, Ohio, and Michigan stealing or attempting to steal $174,046.

Jennie Hill did 24 checks on identities from Indiana, New Hampshire, Vermont, Ohio, and Michigan stealing or attempting to steadl $104,422.

Priscilla Torres did 2 checks for $9,243 on identities from Pennsylvanie and Delaware. She also was the driver for other check runners on some occasions.

Gregory Grayson did one check for $2,500 on a New Jersey identity.

James Kennedy did four checks vs. PNC Bank and twenty checks vs. Citizens Bank using at least eleven identities to steal $61,600.

Eileen Comire did at least thirty-seven checks imitating at least twenty-seven account holders to steal at least $240,599 from Wachovia Bank, and an additional $186,913 from Citizens Bank using eighty-eight fraudulent checks and twenty-one account holder identities. She also uses twenty-two checks belonging to twelve M&T account holders to steal an additional $58,135 from M & T Bank.

David Tunnell did seven transactions totalling $41,900 from Commerce Bank using two different identities, and six transactions totalling $45,100 from Citizens Bank using three identities.

Richard Maden used five Citizens Bank identities to present twenty-nine fraudulent checks totalling $97,374.

Notice of Forfeiture


These criminals stand to lose all property, real or personal, that constitutes or is derived from proceeds traceable to the commission of such offenses - up to a value of $1,300,000.
Read More
Posted in law enforcement, phishing | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • Microsoft Security Intelligence Report 2H08
    The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microso...
  • Operation Open Market: The Vendors
    When we wrote last week about Operation Open Market the court documents had not yet been released in a major multi-agency Identity Theft ca...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile