Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 18 April 2013

Boston Explosion Spammer shifts to Texas Fertilizer Plant Explosion

Posted on 08:44 by Unknown
Yesterday recipients of the Malcovery Today's Top Threat report were among the first to get a detailed analysis of the new spam campaign offering videos of the Boston Explosion. Our normal practice is to report on any email campaign that sends us at least 1,000 malware attachments or at least 1,000 malicious links that would lead to a malware infection if the link was to be followed. By mid-afternoon, we had already seen 80,000 copies of this spam!

Because of the prevalence of the campaign, we decided to share a copy of the T3 Report with anyone who wanted it, rather than reserving it for our paying customers. You can still get a copy by following this link:

Free Malcovery T3 Report: Boston Marathon Explosion Spam.
Click Logo for your Free T3 Report

Today, our analysts have uncovered the newest update to the threat ... more than 18,000 emails already received this morning with subjects related to the Texas Fertilizer Plant explosion.


count | subject
-------+-----------------------------------------------------
3263 | Fertilizer Plant Explosion Near Waco, Texas
2110 | Raw: Texas Explosion Injures Dozens
2074 | CAUGHT ON CAMERA: Fertilizer Plant Explosion
2045 | Texas Plant Explosion
2014 | Texas Explosion Injures Dozens
1943 | CAUGHT ON CAMERA: Fertilizer Plant Explosion Near Waco, Texas
1609 | Texas plant explosion
1572 | Video footage of Texas explosion
1542 | Plant Explosion Near Waco, Texas
The Boston Explosion spam subjects are still an active part of the campaign as well, with nearly 10,000 additional messages coming from that group!

count | subject
-------+-----------------------------------------------------
1315 | 2 Explosions at Boston Marathon
1197 | Explosions at the Boston Marathon
1104 | Boston Explosion Caught on Video
1100 | Video of Explosion at the Boston Marathon 2013
1034 | Explosions at Boston Marathon
1032 | Aftermath to explosion at Boston Marathon
1027 | BREAKING - Boston Marathon Explosion
999 | Explosion at the Boston Marathon
958 | Explosion at Boston Marathon
The "count" tells how many samples we have received in the UAB Spam Data Mine, which powers the Malcovery T3 offering. The UAB Spam Data Mine was created as part of UAB's initiatives to create new tools, techniques, and training to fight cyber crime! In December of 2012, UAB launched Malcovery Security to enable our Spam and Phishing efforts to protect more businesses.

To prove that yesterday's campaign and today's campaign are actually one and the same, we traced the URLs being advertised, and found many of the emails that linked to certain IP addresses yesterday with a URL ending in "/boston.html" or "/news.html" are now being advertised in spam with a "/texas.html" link that is being used in the new messages today.

Despite the fact that there are DOZENS of malicious URLs that can be seen in the emails above, we have so far only identified seven "exploit addresses" that are hidden in those malicious websites.


hxxp://auris.comlu.com/ozsr.html
hxxp://bestdoghouseplans.com/azsq.html
hxxp://emucoupons.com/amiq.html
hxxp://nlln.org/aeir.html
hxxp://sambocombat.us/hwsr.html
hxxp://your360solutions.com/emsr.html
hxxp://zendeux.com/wzsq.html
Today's Top Threat subscribers are notified of this type of information each day in their daily T3 reports. By knowing the danger points in top spam campaigns, they are able to use this information either PROACTIVELY, by putting rules into their network security devices and software to block these destination addresses, or REACTIVELY, by scanning their log files to determine if any computer on their network visited one of those sites.

Just like yesterday, any Windows computer that visits one of the links in their email will be shown several YouTube videos, while one of the exploit sites listed above is used to interrogate their computer, infect it with appropriate malware, and add it to their spamming botnet.

Yesterday we clocked individual infected computers as sending approximately 400 emails per minute. 400 * 60 minutes per hour * 24 hours per day == 576,000 emails per day per infected computer! Each computer that clicks this link adds the ability for the spammer to grow their spamming rate by a half million emails per day!

We call this the "Growth Stage" of a botnet. When the objective of a spam message is to cause more computers to also send spam, the botmaster (the criminal who runs the botnet) is trying to enlarge his infrastructure. At some point, the botmaster can issue a command to cause any portion or all of his new collection of "bots" to perform new actions.

These actions could include:

  • sending spam that earns money for the criminal, such as Pharmaceutical spam.
  • infection with a new malware that steals personal financial information, such as the Zeus or Cridex malware.
  • infection with a new malware that causes your computer to attack company websites as part of a "Distributed Denial of Service" (DDOS) Attack, such as the attacks that have been going on against large banks and other companies.
  • infection with a new malware that can steal documents, or allow remote control of your company computer to use as a base of infiltration into your organization, such as what happened to the South Carolina Tax Office
  • infection with a new malware that can delete data or cause your machine to be unbootable such as the Dark Seoul Attacks in South Korea last month.
Read More
Posted in | No comments

Wednesday, 17 April 2013

Boston Marathon explosion spam leads to Malware

Posted on 11:24 by Unknown
A new malware spam campaign, claiming to provide videos regarding the Boston Marathon explosion tragedy, is infecting computers and sending spam at a rate that is unprecedented in more than a year. The UAB Spam Data Mine, which has partnered with Malcovery Security to offer the "Today's Top Threat Report" received more than 80,000 copies of the malicious email, with more than 50,000 arriving before noon today.

The top spam subjects for this campaign so far have been:


(count listed as of noon)
5952 | Boston Explosion Caught on Video
5885 | Explosions at the Boston Marathon
5873 | Aftermath to explosion at Boston Marathon
5855 | 2 Explosions at Boston Marathon
5729 | Explosions at Boston Marathon
5725 | Explosion at Boston Marathon
5690 | Video of Explosion at the Boston Marathon 2013
5530 | Explosion at the Boston Marathon
4891 | BREAKING - Boston Marathon Explosion
A second spam campaign is also active, using "CNN-related" spam subjects:


88 | Opinion: North Korean Official's child was the CIA target - Boston Marathon Explosions Worse Sensations. - CNN.com
84 | Opinion: Osama bin Laden's legacy - Boston Marathon Explosions - CNN.com
82 | Opinion: FBI knew about bombs 3 days before Boston Marathon - Why and Who Benefits? - CNN.com
79 | Opinion: Boston Marathon Explosions - Who benefits? - CNN.com
77 | Opinion: China Official's child was the CIA target - Boston Marathon Explosions Worse Sensations. - CNN.com
75 | Opinion: Osama Bin Laden video about Boston Marathon Explosions - bad news for all the world. - CNN.com
70 | Opinion: Boston Marathon Explosions - CIA Benefits? - CNN.com
70 | Undeliverable: Explosion at the Boston Marathon
69 | Opinion: Osama bin Laden still alive - Boston Marathon Worse Sensation!? - CNN.com
67 | Undeliverable: Explosions at Boston Marathon
67 | Opinion: Boston Marathon Explosions made by radical Gays? Really? - CNN.com
65 | Opinion: Boston Marathon Explosions - Obama Benefits? - CNN.com
64 | Undeliverable: Boston Explosion Caught on Video
62 | Opinion: Boston Marathon Explosions - Osama bin Laden still alive? - CNN.com
61 | Undeliverable: Video of Explosion at the Boston Marathon 2013
60 | Opinion: Osama death was Faked by CIA - Boston Marathon Explosions Worse News. - CNN.com
The first group of spam messages have the subject line followed by a single URL, consisting of an IP address followed by either "boston.html" or "news.html".


count | machine | path
-------+---------------------------+-------------------
1667 | 118.141.37.122 | /boston.html
1564 | 190.245.177.248 | /boston.html
1533 | 178.137.120.224 | /boston.html
1507 | 110.92.80.47 | /boston.html
1484 | 37.229.92.116 | /news.html
1466 | 188.2.164.112 | /boston.html
1448 | 178.137.100.12 | /news.html
1422 | 78.90.133.133 | /boston.html
1376 | 118.141.37.122 | /news.html
1363 | 212.75.18.190 | /boston.html
1356 | 178.137.120.224 | /news.html
1344 | 110.92.80.47 | /news.html
1331 | 83.170.192.154 | /boston.html
1330 | 37.229.92.116 | /boston.html
1317 | 219.198.196.116 | /news.html
1314 | 37.229.215.183 | /boston.html
1312 | 61.63.123.44 | /news.html
1309 | 61.63.123.44 | /boston.html
1280 | 219.198.196.116 | /boston.html
1271 | 85.198.81.26 | /news.html
1247 | 190.245.177.248 | /news.html
1214 | 94.28.49.130 | /boston.html
1171 | 94.28.49.130 | /news.html
1157 | 94.153.15.249 | /news.html
1150 | 83.170.192.154 | /news.html
1137 | 78.90.133.133 | /news.html
1100 | 95.87.6.156 | /news.html
1069 | 85.198.81.26 | /boston.html
1061 | 94.153.15.249 | /boston.html
1056 | 212.75.18.190 | /news.html
1055 | 37.229.215.183 | /news.html
1038 | 95.87.6.156 | /boston.html
1028 | 188.2.164.112 | /news.html
1011 | 178.137.100.12 | /boston.html
960 | 46.233.4.113 | /news.html
791 | 176.241.148.169 | /news.html
766 | 176.241.148.169 | /boston.html
758 | 91.241.177.162 | /news.html
739 | 46.233.4.113 | /boston.html
735 | 213.34.205.27 | /boston.html
651 | 213.34.205.27 | /news.html
642 | 91.241.177.162 | /boston.html
626 | 62.45.148.76 | /news.html
553 | 85.217.234.98 | /boston.html
511 | 62.45.148.76 | /boston.html
484 | 85.217.234.98 | /news.html
205 | 31.133.84.65 | /news.html
152 | 31.133.84.65 | /boston.html
47 | 109.87.205.222 | /boston.html
44 | 109.87.205.222 | /news.html
19 | 50.136.163.28 | /news.html
17 | 50.136.163.28 | /boston.html
The second group uses a website address rather than an IP address followed by either "cnn_boston.html" or "bostoncnn.html"

count | machine | path
-------+------------------------------+------------------------------------------------------
191 | www.domcomfort.ru | /bostoncnn.html
176 | www.whchivast.com | /cnn_boston.html
142 | relax-perm.ru | /bostoncnn.html
80 | www.peaceofchristparish.org | /cnn_boston.html
71 | imdh.knu.ac.kr | /cnn_boston.html
63 | create-serv.ru | /popeabuse.html
59 | skinnee.net | /cnn_boston.html
56 | numeralarmowy-112.pl | /cnn_boston.html
56 | imdh.kyungpook.ac.kr | /cnn_boston.h
41 | higherthanab.com | /cnn_boston.html
40 | ufferichter.dk | /cnn_boston.html
37 | business-link.net | /cnn_boston.html
25 | ochronaprawkonsumenta.pl | /cnn_boston.html
24 | mannesmann.cz | /cnn_boston.html
20 | kuzenergo.ru | /cnn_boston.html
20 | siemsrl.com | /bostoncnn.html
18 | alex-spil.dk | /cnn_boston.html
17 | host321.ru | /cnn_boston.html
13 | www.vdnh.kiev.ua | /cnn_boston.html
10 | www.theophany.co.nz | /cnn_boston.html
8 | yanjingedu.org | /cnn_boston.html
6 | china-ptjc.com | /cnn_boston.html
5 | econ-group.com | /cnn_boston.html
3 | mezdustrok.com.ua | /cnn_boston.html
2 | alltomforsakringar.nu | /cnn_boston.html
2 | ufferichter.com | /cnn_boston.html
We self-infected by visiting one of the IP address links in a web browser. The page had a series of YouTube videos, including this one:

However, if we look at the source code of the page, we notice something that certainly seems out of place!

The last IFRAME there calls a site called "spareroomwebdesign.com" and a file "waiq.html"

One of the changes to our machine was the addition of a registry key:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SonyAgent: "C:\WINDOWS\Temp\temp86.exe"

When we checked, we found a hidden file, 815,616 bytes in size in that location.

The MD5 of the file is: fdbc94958b8f0ec2b24302c6d4685c46

As of this writing, only 8 of the 46 Anti-virus programs at VirusTotal are aware of this malware and able to detect it. https://www.virustotal.com/en/file/560766fc73edf8eff02674a220e2794c008caeefc476c8fef04c21a16eb23a0f/analysis/

Once infected, your machine BECOMES THE SPAMMER, and begins to distribute emails. In a 48 second run our infected machine attempted to send 348 spam messages, all with a subject from the list above.

The SECOND, CNN-themed spam campaign is a Financial Crimes malware infector, known as Cridex.

Both campaigns have been thoroughly documented in the Malcovery Security Top Threats Today report, normally reserved for our paying subscribers. Due to the extremely prolific nature of the Boston Marathon Explosion spam campaign, we are offering that T3 report as a free sample for any interested parties.

Free Malcovery T3 Report: Boston Marathon Explosion Spam.
Click Logo for your Free T3 Report
Read More
Posted in | No comments

Wednesday, 10 April 2013

New Spam Attack accounts for 62% of our spam!

Posted on 07:10 by Unknown
A new spamming botnet seems to be on the scenes, distinguishing itself with an extremely high spam volume, a great diversity of email subjects, and an amazingly diverse collection of URLs, mostly hosted on compromised websites.

Four of the top six spam subjects in the past 36 hours came from this new botnet:
• Obama’s policies affecting unemployed
• Change your life in 60 seconds.
• Recently got a job offer?
• Have you ever considered working on the internet?

When we used the Malcovery Spam Data Mine to review the sending IP addresses, we found that these messages had come from more than 23,000 different IP addresses. Just for the “Obama’s policies” subject, we saw 296 unique URLs advertised just this morning before 8:00 AM! Here are some of the Top URLs for that spam message.


count machine path
38 www.ghostsquad.altervista.org /cellchickengrahamwilliams/
36 rundeecke.bplaced.net /connectiondevicejamesbailey/
35 sungoldcoast.com /assistantelegantjasonedwards/
35 www.coloniasunidas.com /conflictarticlephilipwood/
35 www.cocheenminiatura.altervista.org /arrestautumndanielhill/
34 protetyk.ovh.org /engineercorealanspencer/
33 www.ghostsquad.altervista.org /cellchickencraigdavies/
32 guildrampage.com /besickendwaynemiller/
32 cuorebravo.com /armyeastkevinspencer/
31 www.curiosando.altervista.org /clockconflictjohnking/
31 www.divorcecamp.com /equalatmospheregeoffreycooper/
31 6sejc.com /associatealliedadrianthomas/

When we check for other websites advertised in spam, JUST FOR SPAMMING IP ADDRESSES THAT SENT THE FOUR SUBJECTS ABOVE, and ONLY FOR THE PAST 36 hours, we find that 3,849 distinct URLs were spamvertised a total of 1,217,196 times – only counting the spam in our Spam Data Mine!

A great variety of subject lines were used in addition to the four top ones above. By “theme” there were:

Oprah and Celebrity subjects:

  • Oprah Winfrey Reveals That She Has A Sister Named Patricia
  • Kourtney & Kim Take NY
  • Oprah’s big secret: she has a sister
  • Oscar 2011: What To Expect
  • Ivanka Trump Has A Baby Bump
  • Ellen DeGeneres secret
  • Rapid-Fire Fitness: Katy Perry
  • Release Your Soul with Pamela Anderson
  • Your morning fashion and beauty report: Reese Witherspoon
  • Anne Hathaway find out how
Fitness subjects:
  • Fitness: Love the 30s!
  • Body and Soul women’s weight loss
  • Healthy Hollywood
  • Miracle Diet or Scam
  • Sorry, guys, these fitness classes aren’t for you
  • No workout, lose weight
  • Miracle or science?
  • Get fit
  • Women try to balance fitness, safety
  • No diet just weight loss
  • Workouts for Women
Silly “fwd” and “re” subjects:
  • Fwd: private
  • Fwd: hey
  • Fwd: question
  • Fwd: hello
  • Re: important
  • Re: hey
  • Fwd: deal
  • Fwd: ?
  • Fwd: information
  • Fwd: …
  • Fwd: business
  • Fwd: answer
  • Fwd: help
News Subjects:
  • Fox investigates claim
  • Fox News investigates: “Change your life in 60 seconds!”
  • Need some money? Fox News wants to help
  • BBC: Online giant Google, worth over 100 billion dollars..
  • Unemployed? Fox! Investigates.
  • TBS breaking news
Random number weight loss subjects:
  • She lost 54 lb in 3 weeks.
  • She lost 46 pounds in 3 weeks.
  • She lost 53 lbs in 3 weeks.
  • (etc.)
And there are still “Work at Home” scam versions, even though the URLs now take you to weight loss websites instead:


Home Maker Dad claims investigated by Fox
Work from home Dad claims investigated by TBS
Work from home Mom claims investigated by CNN USA
Home-Maker Mom claims investigated by Fox!
Work from home Mom claims investigated by Fox News
Work from home Mother claims investigated by BBC
Work at home Mom claims investigated by TBS
Work-from-home Dad claims investigated by CNN
Stay-at-home Mom claims investigated by Yahoo!
Stay home Mother claims investigated by TBS
Home-Maker Dad claims investigated by CNN USA
Homemaker Mom claims investigated by BBC
Stay home Father claims investigated by Fox
Stay home Mom claims investigated by CNN
Stay at home Mother claims investigated by Fox!
Stay home Dad claims investigated by CNN!
Work-at-home Dad claims investigated by CNN
Stay home Mom claims investigated by BBC
Work-at-home Mom claims investigated by Fox!
Work-at-home Mom claims investigated by CNN!
Work-from-home Mom claims investigated by BBC
Work at home Mother claims investigated by BBC USA
Work-at-home Mom claims investigated by BBC USA
Stay at home Mom claims investigated by Fox!
Homemaker Mother claims investigated by CNN
Work at home Mother claims investigated by ITV
Homemaker Father claims investigated by CNN!
Stay at home Mother claims investigated by TBS
Work-at-home Dad claims investigated by Fox
Home Maker Mom claims investigated by ITV
Home Maker Father claims investigated by Fox
Work-at-home Dad claims investigated by BBC USA
Homemaker Mother claims investigated by CNN USA
Work at home Dad claims investigated by Fox News
Work from home Dad claims investigated by BBC USA
Home-Maker Father claims investigated by Fox News
Home-Maker Mother claims investigated by Fox News
What do those pages do when you visit them?

On Monday morning, they sent you to a website with information about a new “Work at Home” program that you could learn about for the low low low price of $100.

But today, they are sending you to a page that proclaims:

Breakthrough Diet Exposed: Celebrity Doctor Uncovers The “Holy Grail of Weight Loss”

This is an on-going campaign that has recently advertised various miracle weight loss products including Raspberry Drops, Green Coffee Bean Extract, and now, “Garcinia Cambogia Featured on TV”

The method for doing this is the use a tiny javascript to set the “parent location href” equal to com-independentvoice.net (or one of many other redirector pages) and passing an “indexer.php?a=225783&c=job” parameter along with the new address. This causes the browser to go to that page and look up the job offer, which displays the weight loss miracle of the day by forwarding the visitor to the path “/diet/GarciniaCambogiaDiet/”

Trying to leave the website generates pop-up messages like these:

Several great clues that these guys are not legitimate including:

The domain is registered by UKRNames.com (Ukrainian Domain Name Registrar of Ill Repute)

The IP address, 201.182.92.166, is hosted at AS52284, Panamaserver.com, claiming to be in Panama.

That IP is also “naturaldietforyou1.com” as well as:

Burnfatandgetflatstomach1.com
Rapidfatlossnatural1.com
Getbestdietsecret1.com
Howtoloseweightquicklyexercises.com
Howtoloseweightfastwithexerciseanddiet.com
Easistnaturalwaytoloseweight.com
Com-work24.net
Finance-reports.com-work24.net
Com-newslocal6.net
Finance-reports.com-newslocal6.net
Com-cbc.net
Finance-reports.com-cbc.net
Finance-reports.com-thestar.net
Com-world-jobnews.net
Com-globejobnews.net
Com-dailylocalnews.net
Finance-reports.com-cnnnewsnet
Com-independentnews.net
Alternativenewsdaily.net

Just picking one of those addresses, com-cnnnews.net was also hosted at:
31.184.192.35
31.184.192.36
81.17.23.40
142.0.72.101
142.0.72.103
176.9.208.121
176.9.208.122
176.9.218.182
185.12.45.102
185.12.45.107
199.91.174.71
199.91.174.72
199.182.168.139
201.182.92.166

More subjects:


Need some money? CNN! wants to help
Fox investigates claim
Fox News investigates: "Change your life in 60 seconds!"
Need some money? Fox News wants to help
BBC: Online giant Google, worth over 100 billion dollars..
Unemployed? Fox! investigates.
TBS breaking news
Lost your job? Fox News wants to help.
CNN! investigates "impossible" claims.
Lost your job? BBC USA wants to help.
CNN! investigates: "Change your life in 60 seconds!"
CNN investigates: "Change your life in 60 seconds!"
Fox!: Online giant Google, worth over 100 billion dollars..
BBC investigates latest claim.
BBC investigates claim
Fox! breaking news
CNN investigates latest claim.
ITV investigates claim
ITV investigates: "Change your life in 60 seconds!"
CNN!: Breaking news!
CNN USA investigates: "Change your life in 60 seconds!"
Unemployed? CNN USA investigates.
Lost your job? BBC wants to know.
Need some money? TBS wants to help
Unemployed? Yahoo! investigates.
Lost your job? CNN USA wants to know.
ITV investigates latest claim.
Yahoo! investigates: "Change your life in 60 seconds!"
TBS: Online giant Google, worth over 100 billion dollars..
Lost your job? CNN wants to know.
Lost your job? TBS wants to help.
CNN!: Online giant Google, worth over 100 billion dollars..
Lost your job? TBS wants to know.
Lost your job? CNN! wants to help.
Lost your job? CNN! wants to know.
Fox!: Breaking news!
Unemployed? Fox News investigates.
Lost your job? ITV wants to know.
Unemployed? TBS investigates.
Need some money? CNN USA wants to help
Lost your job? CNN USA wants to help.
Lost your job? Fox! wants to help.
CNN USA investigates claim
Yahoo! investigates latest claim.
Fox! investigates claim
CNN: Breaking news!
Lost your job? Yahoo! wants to know.
BBC USA investigates "impossible" claims.
Yahoo!: Online giant Google, worth over 100 billion dollars..
Lost your job? Fox! wants to know.
Fox investigates: "Change your life in 60 seconds!"
TBS: Breaking news!
Unemployed? CNN investigates.
Yahoo! breaking news
Need some money? CNN wants to help
Fox! investigates "impossible" claims.
ITV breaking news
Lost your job? Fox News wants to know.
Unemployed? ITV investigates.
BBC USA investigates claim
CNN USA investigates latest claim.
CNN investigates "impossible" claims.
Fox breaking news
Fox: Online giant Google, worth over 100 billion dollars..
Lost your job? Fox wants to know.
ITV: Online giant Google, worth over 100 billion dollars..
Yahoo!: Breaking news!
Need some money? Yahoo! wants to help
BBC USA: Online giant Google, worth over 100 billion dollars..
Lost your job? ITV wants to help.
Need some money? Fox! wants to help
Fox News: Breaking news!
Fox News breaking news
Fox News investigates latest claim.
Yahoo! investigates claim
Fox News: Online giant Google, worth over 100 billion dollars..
Yahoo! investigates "impossible" claims.
CNN USA: Breaking news!
ITV: Breaking news!
ITV investigates "impossible" claims.
BBC USA investigates latest claim.
CNN USA investigates "impossible" claims.
CNN USA breaking news
TBS investigates: "Change your life in 60 seconds!"
BBC USA investigates: "Change your life in 60 seconds!"
Fox investigates latest claim.
BBC USA: Breaking news!
BBC breaking news
Unemployed? BBC investigates.
TBS investigates claim
TBS investigates latest claim.
Need some money? BBC wants to help
BBC: Breaking news!
Need some money? ITV wants to help
BBC USA breaking news
Unemployed? CNN! investigates.
CNN: Online giant Google, worth over 100 billion dollars..
CNN breaking news
Lost your job? CNN wants to help.
Lost your job? BBC USA wants to know.
Lost your job? Fox wants to help.
Need some money? BBC USA wants to help
CNN investigates claim
Fox News investigates claim
Lost your job? BBC wants to help.
Fox! investigates: "Change your life in 60 seconds!"
BBC investigates: "Change your life in 60 seconds!"
Fox: Breaking news!
TBS investigates "impossible" claims.
CNN USA: Online giant Google, worth over 100 billion dollars..
BBC investigates "impossible" claims.
Fox! investigates latest claim.
CNN! investigates latest claim.
Unemployed? Fox investigates.
Fox investigates "impossible" claims.
Lost your job? Yahoo! wants to help.
Need some money? Fox wants to help
CNN! breaking news
Unemployed? BBC USA investigates.
Fox News investigates "impossible" claims.
CNN! investigates claim


Work at home Dad claims investigated
Rapid fire weight loss Salma Hayek
Work-at-home Mom claims investigated
Breaking news for Home Maker Father.
Breaking news for Stay at home Dad.
Breaking news for Home-Maker Father.
Oprah Whinfrey Heads To Paris In Search Of The Perfect Wedding Gown!
Breaking news for Home-Maker Mother.
Breaking news for Work-at-home Mom.
Ellen DeGeneres diet or scam?
Salma Hayek diet or scam?
weight loss Katy Perry
Breaking news for Stay home Dad.
Stay at home Mother claims investigated
Breaking news for Stay home Father.
Stay at home Father claims investigated
Release Your Soul with Anne Hathaway
weight loss Madonna
Breaking news for Work-at-home Dad.
Ellen DeGeneres secret
Rapid-Fire Fitness: Katy Perry
Release Your Soul with Pamela Anderson
Your morning fashion and beauty report: Reese Witherspoon
Anne Hathaway find out how
Work from home Mom claims investigated
Breaking news for Work at home Mom.
Rachel Ray says
Britney Spears Going Harder, More Urgent
Pamela Anderson try to balance fitness, safety
Check out how Natalie Portman did it
Oprah Whinfrey try to balance fitness, safety
Breaking news for Work from home Father.
Ellen DeGeneres weight loss
Breaking news for Homemaker Father.
Homemaker Dad claims investigated
Read More
Posted in | No comments

Monday, 18 March 2013

Tax Season is Malware Season

Posted on 23:47 by Unknown
This summary is not available. Please click here to view the post.
Read More
Posted in | No comments

Sunday, 12 August 2012

Carder Christopher Schroebel gets Seven Years

Posted on 06:44 by Unknown
21 years old and thinking about Cybercrime as a career choice?  Think again.  Seattle-based U.S. Attorney Jenny Durkan told a press conference back on June 11, 2012 "People think that cybercriminals cannot be found or apprehended.  Today we know that's not true.  You cannot hide in cyberspace.  We will find you.  We will charge you.  We will extradite you and we will prosecute you." (see: MSNBC: Feds Arrest Alleged Credit Card Fraud Kingpin.) 

Christopher A. Schroebel


Durkan seems to be standing true to her word.  Friday her office successfully sentenced Christopher A. Schroebel, a 21 year old man from Maryland, to seven years in prison. 

The "Official" complaint against Schroebel says that on a date before July 20, 2011 and continuing until August 3, 2011 Schroebel was stealing information from Mondello's Italian Restaurant,  specifically the data from credit cards belonging to K.H., K.W., J.H., V.D., S.J., and M.H..  That gives us the first charge - Obtaining Information From a Protected Computer.

An interview in the Seattle Times explains what Schroebel did, from the perspective of Corino Bonjrada, the owner of Modello Risorante Italiano.  Schroebel had planted spyware in the Point of Sale terminals of dozens of businesses.  Bonjrada told the Times "Some of my customers were saying they didn't know if they wanted to come back.  They were afraid."  Some of the customers were hit with fraudulent charges "within 10 minutes"of swiping out at his restaurant.  (See: Dutch man charged with stealing Washington credit cards.)
  
Schroebel was arrested last November possessing over 84,000 stolen or purchased credit card data stripes and made his first court appearance November 21, 2011.  At that time, he was sentenced to an inpatient substance abuse program, and was released from that program on December 26, 2011.   He was picked up and arrested again on a local warrant, and ordered detained as a flight risk January 24, 2012.  So, he has already been in prison nearly more than eight months at this point.  (Detention order is available at archive.org.

Schroebel entered a plea agreement on May 15, 2012,  and was held pending his August 10, 2012 sentencing.  (See: PACER case number; 180519, Docket 2:2011-cr-00391-RSM.)


The Seattle Police Department describes it a bit better:

The SPD has been actively investigating unauthorized computer intrusions ("hacks") into the computer systems of small businesses located in the Western District of Washington (including Mondello's Italian Restaurant in Magnolia and Seattle Restaurant Store in Shoreline).


The person/s responsible for the hacks installed malicious software ("malware") on the computer systems of the victim businesses.  The malware was designed to, and has collected credit card account numbers belonging to customers/clients of the victim businesses.  The stolen credit card account numbers were then transmitted over the Internet to a computer server under the control of the hacker/s and/or their associations.

USSS ECTF/NCFI Success Story


That's from the affidavit of a SPD Computer Forensics Detective, David Dunn.  He is a member of the USSS Electronic Crimes Task Force, Seattle Field Office.  The Secret Service partners with local police departments all across the country to share their Computer Forensics capability in the form of free training and expertise to help work these cases.  Part of that training is right here in Hoover, Alabama at the National Computer Forensics Institute.  (David actually responded to this post, giving permission to share his name, and confirming that he took AFT (Advanced Forensics Training) and NITRO (Network Intrusion Response) courses at the National Computer Forensics Institute in Hoover.)

Listen to the training and experience this guy got by being a local law enforcement part of the USSS Electronic Crimes Task Force.

In April of 2005, I was transferred to the Seattle Police Department Fraud unit as a Computer Forensic Detective.  I am currently, and since October of 2006 have been assigned as a full time member of the USSS Electronic Crimes Task Force, Seattle Field Office.  I hold a Special Deputation appointment through the United States Marshals Service that permits me to seek and execute arrest and search warrants supporting a federal task force.  As a member of the Seattle USSS E-Crimes Task Force, I investigate violations of federal law in the state of Washington that fall under the responsibility of the USSS, with an emphasis on crimes involving computers, the Internet, and electronic communications.

(...Many local training courses listed, and then... )
My training and experience also specifically includes training and experience regarding computer and network intrusions, commonly known as "hacking."  This includes completion of the 40 hour "Incident Handling and Response" course on network intrusions and incident response through the Department of Homeland Security.  I have experience with packet analysis, malware, and viruses.  I am a Certified Ethical Hacker.  I have attended 104 hours of training in Network Intrusion Response at the National Computer Forensic Institute.  I hold the following certifications: EnCase Certified Examiner, Access Data Certified Examiner, IACIS Computer Forensic Certified Examiner.  I have received advanced training in both network intrusion forensics as well as Point of Sale forensic investigations.

As a member of the USSS ECrimes Task Force, I have worked on numerous computer and network intrusion cases.  These cases have involved a range of hacker techniques and modus operandi, including social engineering, SQL injection attacks, botnet attacks, malware infections and various other menas of computer infection and attack.  I have examined myriad server logs and volumes of  IP address information as part of my investigation of various hacking cases.  I have also created and examined forensic images of dozens of infected and hacked computers and servers.  I have investigated cyber cases involving both national and international victims and suspects.  As a result, I am familiar with schemes involving large scale Internet crimes and network atacks.



(Here's a picture with my summer students from the National Science Foundation Research Experience for Undergraduates at the NCFI - sorry - shameless plug - I think this place is great!)





Back to the Hacking Charges



The Complaint then says that "knowingly and with the intent to defraud, trafficked in and used credit card track data from credit card accounts belonging to (the above) without their knowledge or consent, and by such conduct obtained profits aggregating $1,000 or more, said trafficking affecting interstate and foreign commerce, in that the credit card account numbers that were so trafficked and used by Schroebel and others to make fraudulent purchases in states outside the State of Washington."  That's the second charge - Access Device Fraud.

When Schroebel was arrested, he was in possession of 84,000 credit card numbers that he had stolen or bought from other hackers.

When the SPD investigated the charges made on the cards used by the customers at Mondello's they led them to California. One of the cards, belonging to K.H. was used at Home Depot, Wal-Mart, Jack-n-the-Box, and several other locations.  V.D. and S.J. dined together at Mondello's on July 30, 2011, and BOTH had their cards being used for fraudulent purchases in Southern California on July 31, 2011.

That's where we get to the next interesting member of our trio, GUERILLA BLACK.

GUERILLA BLACK, MRBUSINESSMAN62, BLACKDOLLA, Charles Tony Williamson



(click for press release)

The Indictment of Guerilla Black fills in the California end of the story.



Guerilla Black is described as a "B.I.G. look-alike" (or some would say imitator).  Apparently the record sales needed a bit of supplement to help him live the private jets and limos image he attempted to maintain in his youTube videos.  (Shown above is the track "Compton".)

From at least January 2011 credit cards stolen by Schroebel were showing up in California, being used by Guerilla Black and his crew.  Black's indictment shows many entries such as:

19. On or about February 9, 2011, the coconspirator who hacked the point of sale computer system at the Shoreline, WA business sent an e-mail to CHARLES TONY WILLIAMSON, that contained multiple customer credit card numbers that were stolen through the hack of that business, including at least one credit card number that had been issued by Boeing Employees' Credit Union.

or

32. On or about July 31, 2011, the coconspirator who hacked the point of sale computer system at the Seattle, WA restaurant sent an e-mail to CHARLES TONY WILLIAMSON, that contained multiple customer credit card numbers that were stolen through the hack of that business, including at least two credit card numbers that had been issued by Boeing Employees' Credit Union.


 (Gee, which two would those be?)

The indictment lays out that Williamson "expressed his preference and desire to coconspirators to buy 'dumps' of stolen credit card numbers 'in bulk,' that is, in lots of at least 100, or 500, or more."  and that he "expressed his preference and desire...to obtain credit card numbers that were 'freshly' stolen through 'point of sale system' computer network intrusions rather than card numbers that were skimmed or stolen from credit card databases compiled by others, because the 'fresh' card numbers stolen from point of sale system hacks could be used more successfully for fraudulent transactions."

Williamson "redistributed the stolen card numbers to a network of criminal associates, with the intente and the expectation that these associates would then use the stolen credit card numbers for fraudulent transactions."

But Williamson wasn't the only one Schroebel was selling to . . .


Schrooten / Fortezza


As it turns out, Schroebel would sell the cards he acquired from these POS terminals to another 21 year old, Dutch national David Benjamin Schrooten, who ran a website that sold credit cards to others for their use.

Schrooten will be well-known under his hacker name "Fortezza" to anyone who follows the excellent blog KrebsOnSecurity.com.  Krebs story Feds Arrest Kurupt Carding Kingpin tells us more about the English language carding site run by Fortezza called Kurupt.su.  According to Krebs, Fortezza gained many of his cards by breaking in to a competing carding site.  In retaliation, THOSE carders posted a message announcing that Fortezza "needs to learn not to fuck with Russians !!!" and providing his information, including real name, city, home address, shipping address, telephone number, and fax number.

Krebs has a screen shot of the post on his blog:



Schrooten was arrested as he got off a plane in Romania, and later extradicted to the United States.  He will be tried in September in Seattle.


(click for press release)


According to the Schrooten indictment (also from KrebsOnSecurity) Schrooten is charged with Conspiracy to Commit Access Device Fraud and Bank Fraud, 2 counts of Access Device Fraud, 5 counts of Bank Fraud, 1 count of Intentional Damage to a Protected Computer, and 5 counts of Aggravated Identity Theft.

As we've discussed before, one of the ways our judicial system is not geared up for handling international cybercrime is that wherever these cases are tried, they address only the charges LOCAL TO THAT JURISDICTION.  So, in this case, the trial is in Seattle, which means the only victims who can be named are those with a connection to the Western District of Washington.  Particularly this trio of cases focuses on the charge that the Boeing Employees' Credit Union, and members of the credit union who reside in the Western District of Washington, had money stolen by these criminals.  So, the counts of Bank Fraud against Schrooten specifically refer to transactions on April 25, 2011, August 20, 2011, December 21, 2011, and two on February 1, 2012, where the account holder was a BECU customer who lived within the jurisdiction of this court.



There will likely be more arrests, and more sentences, in this case in the near future.  I wanted to share it now though because it is a great example of what happens when a smart local detective partners with the USSS Electronic Crimes Task Force, and runs down a local crime, along with its international implications.

Read More
Posted in | No comments

Wednesday, 20 June 2012

Soldier Auto Escrow Scam

Posted on 06:18 by Unknown
Last night I got an email from a student ...
My brother is wanting to buy a car that is in the UK. The seller is claiming she will get free shipping from military affiliation. She wants to conduct the deal through eBay's buyer protection program. She's selling a fairly nice car for 1700 dollars. No money changes hands until the car is in my brother's possession and he has approved of the car (10 days to approve). What do you think?

Sounds pretty good, with the little caveat that the seller doesn't own the car, but he DOES own the escrow service where you are expected to put your money! THIS IS A SCAM, usually tied back to Romania.

A recent headline in Boston was Romanian Mobster Arrested in Lexington May Be Tied To Car Scam (April 4, 2012, CBS Boston). In that story, Catalin Buzea of Romania was opening bank accounts with a fake passport when he was arrested. He was said to be "duping people nationwide who are buying cars online ... a well trained thief working with counterparts in Romania ... they successfully direct online car buyers to bogus yet very real looking online payment systems." Buzea wired more than $100,000 back to Romania in three weeks, all the result of online auto scams.

It is rather amazing that Buzea and his crew are still in operation after last year's news. In July 2011, US and Romanian police arrested more than 100 people who had stolen more than $100 million from online scams similar to this. Romanian police arrested 90 people after doing 117 raids in 9 cities. In the US, "money mules" (called "arrows" by the Romanians) would retrieve money from US bank accounts using fake identities, such as Buzea did. In the July 2011 action the case was developed by arresting "arrows" in Florida, Kentucky, Missouri, Pennsylvania, and Texas, who were all used to provide clues to the Romanian police. The DOJ Press Release listed many criminals involved in these schemes including Vadim Gherghelejiu, Anatolie Bisericanu, Jairo Osorno, Jason Eibinder, Ciprian Jdera, Pedro Pulido, Ivan Boris Barkovic, Beand Dorsainville, Sergiu Petrov, Oleg Virlan, Marian Cristea, Andrian Olarita, Adrian Culda, Tiberiu Zachiteanu, Marion Potcovaru, Augustin Prundurelu, Georgina Andrei, Sorin Mihai Madaian, Victor Angelescu, Klara Mirabela Rusu, and Eduard Sorin Neacsu. But based on this morning's report from the UAB student, a few more still need to go to jail.

This scam comes up often enough that I thought I might make a post about it here. The language used in the initial contact is "fill in the blank" so I hope that someone will read this and find themselves warned.

Here's a sample message.

Hello and sorry for my delay,

I'm SGT Paul Hayes. This Corolla LE is in perfect working condition. This vehicle engine runs very, very smooth. No electrical problems on this beauty. This detailed vehicle makes the exterior looks like it just came off the assembly line. The car has 35k miles. VIN Number: 2T1BR32E76C639533

CD Player Transmission: Automatic Air Conditioning Anti-Lock Brakes Driver Airbag Passenger Airbag Side Airbags Cruise Control Power Locks Power Windows Power Seats Click this link for more pics: http://s284.photobucket.com/albums/ll7/rr6toy/

As I know that my current situation is pretty special I want the deal closed only through eBay's Buyer Protection Program in order for you to be 100% protected. You will make the payment to eBay and they will hold the money until you receive the car. ONLY AFTER you receive the car and you inspect it(for 10 days) eBay will release the payment to me; in this way we are both protected. Anyway i am sure that if you won`t be satisfied about the car i will surely find another buyer in your area and there will be no need for you to ship the car back. I am located in London, UK and I was sent here with my department of peace maintenance. Two months ago, my wife moved here with me and brought the car with her, but now we have to sell it back in the United States because we can't register it here; it has US specs and everything, and registering it here in Europe will take for ever. My final price on it is 2,950 USD. If you will take it for this price, I am willing to handle the shipping. It will be shipped from here by plane with US Air Military Cargo so it will not cost me anything. You will get it to the nearest airport in your area and then it will be trucked forward to your place. You will receive the car in about 3 days. Please get back to me asap if you decide to buy, and include in your e-mail your full name and address where you want it shipped so I can start the deal with eBay. You will receive all the transaction payment and shipping details from them.

Best Regards,

Paul and Stephanie Hayes

That message is from November 2008, and is ALMOST identical to the message the student's brother received.

So what do you do about Soldier Auto Escrow Scams?

The best investigative team I know that works these issues is actually the eBay Motors security team. They have some great advice available on eBay Motors Security Center website. They recommend that you forward any suspicious emails you receive to "car@ebay.com" -- and they actually don't mind whether the email started at eBay, Craigslist, or anywhere else. If there is a scammer who is selling cars on the Internet, ESPECIALLY if it mentions an escrow service or eBay, please send a copy to "car@ebay.com"!!

If you actually lost money on one of these, please be sure to report it also to the FBI through the ic3.gov Internet Crime Complaint Center. The form makes it difficult to just share clues if you were not actually stolen from, but if you actually lost money, it would be well worth reporting there!

Related scams

Sometimes the best "proof" you can share with a skeptic-friend who is considering falling for the scam despite your warning is to show them ALMOST IDENTICAL emails from other victims. Here are a few to get you started:

In November 2009 - Fraudwatchers saw SGT John Edwards selling an Altima SL with VIN Number: 1N4BL11D65C376012.

June 15, 2012 - Jules was almost scammed buying a Honda Accord EX from SSgt Monica Dixon with VIN Number: 1HGCM56744A118864.

January 13, 2008 - Katy Lee was offered a Honda Accord EX by Sgt. Robert Parra with VIN Number: 1hgcg1655ya068349.

January 23, 2010 - FightTheScams posted about SGT Jacob Gulledge selling his Accord EXL with VIN Number: 1HGCM66825A031982

They don't have to be in London . . . Sgt. William Thompson is selling his car from Afghanistan using a very similar scam.

Hello,

I am emailing you regarding the 2003 Mazda 6 that I have for sale. The general condition of this car is excellent, very well maintained, no damages and no mechanical problems, the engine runs and sounds awesome, automatic transmission, 4 Cylinder 2.3 Liter, tan leather interior and white exterior with no cosmetic complaints really worth comment. The alloys are all presentable and originals the fronts having a few marks, all tyres in good condition with plenty life remaining. Clean carpets, seats, roof, boot and plastics. Both remote keys are present and they are working, no electrical issues. I do have the title, clear, under my name. The car has 90,136 miles, year 2003 and VIN#1YVFP80C635M26324. I’m not interested in any trades only to sell it!

Price was reduced to $1,995 (URGENT SALE) as I need to sell this car before June 25 when I will leave with my platoon back to Afghanistan and don’t want it get old in my backyard.

I though you might want to see more pics, click on this link:
http://s1148.photobucket.com/albums/o565/WhiteMazda/?albumview=slideshow

Hope to hear from you as soon as possible!

Thank you,
William Thompson

Lt. Steve Hoinski is selling his 2005 Audi A4 from Madrid Spain, but the description sure sounds like he's in London!
As I know that my current situation is pretty special I want the deal closed only through eBay's Buyer Protection Program in order for you to be 100% protected. You will make the payment to eBay and they will hold the money until you receive the car. ONLY AFTER you receive the car and inspect it (for 10 days) eBay will release the payment to me; in this way we are both protected. Anyway i am sure that if you won`t be satisfied with the car i will surely find another buyer in your area and there will be no need for you to ship the car back.

I am located in Madrid,Spain and I was sent here to improve the military relationships between our country and Spain. One month ago, my wife moved here with me and brought the car with her, but now we have to sell it back in the United States because In order to be able to register this car here, I would have to pay very high import/custom taxes. My final price on it is $ 2950. If you will take it for this price, I am willing to handle the shipping. It will be shipped from here by plane with US Air Military Cargo so it will not cost me anything. You will get it to the nearest airport in your area and then it will be trucked forward to your place. You will receive the car in about 4 days. Please get back to me asap if you decide to buy, and include in your e-mail your full name and address where you want it shipped so I can start the deal with eBay. You will receive all the transaction payment and shipping details from them.

Thank you and have a nice day,
Lt. Steve Hoinski

Looks Too Good To Be True

There's dozens and dozens of these, but some good advice can be had from the "LooksTooGoodToBeTrue.com" website that has a page that explains Escrow Fraud. Use the "Looks Too Good To Be True" test on your sale . . . There's a reason they are selling it at "looks too good to be true" prices:

"One month ago my wife moved here with me and brought the car with her but now we have to sell it back in the United States because we can’t register it here; it has US specs and everything and registering it here in Europe will take for ever."

They are going to ship you a car internationally in a very short period of time:

"You will get it to the nearest airport in your area and then it will be trucked forward to your place. You will receive the car in about 4 days." (In reality you would be lucky to get a car from KANSAS in four days!)

They claim the deal is with eBay, even though they aren't selling the vehicle on eBay:

"Please get back to me ASAP if you decide to buy and include in your e-mail your full name and address where you want it shipped so I can start the deal with eBay."

(eBay will only stand behind eBay deals where the whole transaction happens ON eBAY! Don't fall for these scam deals ... when someone tries to steer you OUTSIDE of eBay they are normally planning to rip you off.)

For American buyers, the only Escrow service that eBay supports is "Escrow.com". They have tips for how to do an escrow purchase on the website Using escrow services for eBay Motors vehicles purchases.

Read More
Posted in | No comments

Saturday, 19 May 2012

What about the Social Security Numbers? (The Utah Data Breach and your SSN)

Posted on 15:17 by Unknown

The Utah Data Breach

This week the continuing saga of the Utah Medicaid Data Breach continued to unfold.

If you haven't been following the story, here's the play-by-play:

  • April 4 - State Agencies Investigate Data Breach - the Utah Department of Technology Services notified the Utah Department of Health that a breach on March 30, 2012 accessed 24,000 Medicaid claims. Michael Hales, the Health Department's Medicaid Director tells the Salt Lake City Tribune that "it's likely that few Social Security numbers were on the records as Medicaid clients have different identification numbers on their files."

  • April 6 - Impact of Medicaid data breach on DTS server widens - oops. Did we say 24,000? It was actually 181,604 people, of which 25,096 had their Social Security numbers compromised.

  • April 9 - Data Breach Expands to Include More Victims - oops. Did we say 181,604? It was actually 780,000 people, of which 280,000 had their Social Security numbers compromised.

  • May 15 - Governor Gary Herbert Details Comprehensive State Response to Data Breach - Utah's Governor announces:

    • A state-wide audit of every server on the state network, conducted by Deloitte & Touche

    • Sheila Walsh-McDonald appointed Health Data Security Ombudsman (a new position)

    • Director of the Department of Technology Services, Stephen Fletcher, resigns.

    • The Salt Lake Trib reports that the server was likely hacked from Romania, and was hacked because a default password had not been changed.

That is an amazing story. Remember that Utah only has 2.8 million people according to the US Census. So in this single data breach 28% of the residents of Utah had their personal information stolen from them, and 10% of them had their Social Security Number stolen.

The good news, if there is any, is that Utah is now Very Serious about Identity Theft, launching its new IRIS: Identity Theft Reporting Information System in response. What will it take for the other states to get serious about identity theft?

What About Social Security Numbers?

The Utah story was only intended to be a vehicle for asking this question. What are we doing about Social Security Number theft? If hackers get your password, you can have your password reset. If hackers steal your credit card number, the bank will issue you a new one. If your bank account is breached, it is not uncommon to have the bank CLOSE your account and open a new account for you. But what if you the hackers steal your Social Security Number?

The first place that seemed reasonable to check was the Social Security website. They have a page about Identity Theft called Identity Theft and Your Social Security Number (SSA Publication No. 05-10064, ICN 463270, August 2009).

That form asks "What if an identity thief is creating credit problems for you?" and answers the question:

If someone has misused your Social Security number or other personal information to create credit or other problems for you, Social Security cannot resolve these problems.

They have several recommendations:

  • Contact the Federal Trade Commission (FTC) or call 1-877-IDTHEFT (1-877-438-4338).
  • Contact the IRS Identity Protection Unit (1-800-908-4490) if you think there may be tax issues, such as the identity thief filing a tax return using your number, or taking employment using your number.
  • File a complaint with the FBI's Internet Crime Complaint Center (IC3.gov) which is the best course to engage law enforcement in your response.
  • Apply for free credit reports. The federal government provides a free Annual Credit Report at AnnualCreditReport.com.

But read on . . . IT IS POSSIBLE to get a new Social Security Number, and Social Security will work with you to do that IF YOUR NUMBER IS BEING ACTIVELY ABUSED, but they warn that getting a new number may actually be worse than the abuse. For example, in the United States, the key to your credit history is your Social Security Number. If you get a new number, congratulations, you now have Zero Credit History. You won't be able to get a credit card or a loan without a lengthy ordeal or a co-signer.

So what is the answer? Despite all the controversy, it may be time to go back to the discussion of a National Identity Card. I visited Spain last summer and my banking security friends marveled at how the US clung to our antiquated system. They have a National Identity Card (DNI - Documento nacional de identidad) that is carried at all times. The chip in the card contains a digitized version of a photo of the bearer, plus a digital version of their signature and finger prints! There is no value to having only the Number -- my friend who was explaining it to me said you can write your number on your business cards, because there is NOTHING ANYONE CAN DO by simply having the number. It is the CARD that has value. If you have my number, but not the chip in my card, it is worthless to you.

I'd like to see this discussion move forward. If criminals don't already have your Social Security Number, it is certainly only a matter of time. Even if it is only a theoretical question right now, it is extremely likely that this question will be a personal matter to you or someone you love in the near future.

Especially if you live in Utah.

Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Help stop the Osama bin Laden Videos on Facebook
    If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with in...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • A Dark and STORMy Night
    Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor. On the evening of Octobe...
  • TJX Update: The San Diego Indictments
    As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust". There wer...
  • Facebook Safety & Million Member Facebook Groups
    Two of my friends today invited me to join "Million User" facebook groups. Not that it matters really, but the two groups were: P...
  • Microsoft Security Intelligence Report 2H08
    The Microsoft Security Intelligence Report for the second half of 2008 has been released (the 184 PDF version, available from http://microso...
  • Operation Open Market: The Vendors
    When we wrote last week about Operation Open Market the court documents had not yet been released in a major multi-agency Identity Theft ca...
  • First 2008 Presidential Spam Campaign?
    Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it poss...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile