Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, 31 August 2008

Hurricane Gustav: Fraud Watch

Posted on 05:47 by Unknown
For several years I've worked as an "industry partner" sharing information with the coolest Law Enforcement / Industry / Academia partnership on the planet - the National Cyber Forensics Training Alliance. One of the very first things we did together was compiling potential fraud domains for Hurricane Katrina.

Since that time, anytime we've seen a natural disaster, we've been on the lookup for domains which might be abused for fraud. It was only natural then that I retuned my settings at DomainTools yesterday to alert on Gustav domains.

Here's what we've seen so far about new domains, registered with the word "Gustav" in them:

Parked Domains



- parked at GoDaddy

contributegustav.org
contributiongustav.org
donategustav.org
donationgustav.org
gustav-relief.org
gustavassistance.org
gustavattorney.com
gustavclaims.net
gustavcontribution.org
gustavhelpers.org
gustavlawsuit.com
gustavlawyer.com
gustavlouisiana.org
gustavneworleans.org
gustavotimponi.com
gustavrecovery.org
hurricanegustavrepair.com
hurricanegustavvictims.info
hurricanegustavvictims.org
hurricanegustav08.com

Parked at IPTV Domains:

gustavcharities.com
gustavcharity.com
gustavdonation.com
gustavrelieffund.com

Parked at Mad Dog Domains & Cattle Company:

hurricanegustavresponse.info
officialhurricanegustav2008.info

Parked at Network Solutions:

gustavresponse.com


Parked on a Sedo search click ads site:

gustavhurricanerelief.com
gustavhurricanerelief.info
gustavhurricanerelief.net
gustavhurricanerelief.org
gustavlegalrelief.com
gustavlegalrelief.info

Parked at Sedoparking.com:

gustav-hurricane.info
gustav-hurricane.net
gustav-hurricane.org
gustav-hurricane.us

Points to a Sedo IP, but no content there:


hurricanegustavrelief.info
hurricanegustavrelief.net
hurricanegustavrelief.org


Parked at WebSites2You:

gustavfound.com
gustavmissing.com
survivedgustav.com
survivedgustav.net

For sale by auction on ebay and sedo by "harfordadvantage.com":

helpgustavvictims.com
helpgustavvictims.net
helpgustavvictims.org



Real Domains



There are several newly registered Gustav domains that actually contain real content!


gustavneworleans.com <== SHOCK! A real page of Gustav Information! (registered by Lawrence Muller of Virtual Corp in New York, who owns more than 400 other domains)

gustavpictures.com <== SHOCK! A real page of Gustav-related photos! (registered via Domains By Proxy by someone who seems to be "on the ground" watching the National Guard come into town)

hurricanegustavphotos.com <== SHOCK! A real page for Gustav-related photos! (registered by Cyril Payne of Theodore, Alabama. A nice frame, but no pictures yet.)

hurricanegustave.info <== SHOCK! Real information about the storm! (registered by Mark Cummings of Madisonville, Louisiana. Useful and current storm data, with Weather Channel graphics.)

Two Offering Good Deeds



Two other domains seem to be owned by Good Citizen who have reserved the domains and will give them for free to a worthy charity who would like to have the domain:


gustavrelief.info <== SHOCK! A good deed doer has reserved this domain, which he will give for free to a real charity . . .

gustavrelieffund.org <== See image



So far no signs of fraud, only Domain Speculation, but as always, we'll be keeping an eye on the situation as we move forward.

Gary Warner
Director of Research
UAB Computer Forensics
http://www.cis.uab.edu/forensics/
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • What about the Social Security Numbers? (The Utah Data Breach and your SSN)
    The Utah Data Breach This week the continuing saga of the Utah Medicaid Data Breach continued to unfold. If you haven't been following...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Carder Christopher Schroebel gets Seven Years
    21 years old and thinking about Cybercrime as a career choice?  Think again.  Seattle-based U.S. Attorney Jenny Durkan told a press conferen...
  • Stop the Rumors: Quit SMSing about WalMart Gang Initiations
    My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here...
  • New BBC spam mocks Georgia's President, Spreads New Virus
    This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads ...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Digital Certificates Update
    A quick update from the previous post. The Digital Certificates spam campaign against Merrill Lynch continues, but the good guys seem to be ...
  • ATM Cashers in 26 Countries steal $40M
    CBS News in New York has a video on their website this morning title Cyber-attacks behind possibly record-breaking bank heist . Former FBI ...
  • A New Year and Anti-Virus Products Are Still Losing
    One of our most popular blog posts in 2008 was back in August - Anti-Virus Products Still Fail on Fresh Viruses . I'm sad to report tha...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ▼  August (22)
      • Hurricane Gustav: Fraud Watch
      • Banking Digital Certificate Malware in Spam
      • E-cards Run Wild. Where are the Anti-Virus Compan...
      • Leave Those Viruses at SCHOOL!
      • Celebrity Spam-Off: Will Paris Hilton Overtake An...
      • Shadow Botnet case may yield spammer Leni Neto
      • More Online Pharmacy Affiliates Indicted
      • Evidence that Georgia DDOS attacks are "populist" ...
      • One third of current spam points to malware sites
      • New BBC spam mocks Georgia's President, Spreads Ne...
      • Can You Pick the Real MSNBC.Com Breaking News?
      • MSNBC Breaking News replaces CNN Spam Wave
      • Anti-Virus Products Still Fail on Fresh Viruses
      • iTunes Store Phish
      • The UAB Spam Data Mine: Looking at Malware Sites
      • TJX Update: The San Diego Indictments
      • TJX Update: The Boston Indictments
      • Linking all the News Spam together (CNN.com Daily ...
      • CNN Spam Diversifies . . .
      • TJX Reminder: "We Will Arrest You, and We Will Sen...
      • CNN Lends Authenticity to News Spam
      • Another Insider Busted: Countrywide Financial Analyst
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile