Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 28 October 2008

Tip to Phishers: First Build Site, THEN Spam

Posted on 04:04 by Unknown
As a transplant to the South, I was not at first familiar with the expression "Bless his little heart". Its often used to express amusement at something silly a young child or animal may do, because they don't know any better. When used with regards to adults, it replaces Yankee expressions because Southerners are generally too polite to say someone is too stupid to live. I've lived in the South for more than twenty years now, so when I saw the phishing campaign that started up around 1:20 this morning, all I could say about the Phisher was "awwww....bless his little heart!"

Here's what the spam emails look like:









When I say we started getting spam from this campaign, I mean SEVERAL messages every minute. The spammer had registered himself some nice domain names using the Chinese Registrar: HICHINA ZHICHENG TECHNOLOGY LTD.

1securebanking.com
connect-secure.com
ibanking-net.com
ibanking-secure.com
securebanking-net.com
secureconnect-us.com
secure-ebank.com
secure-ebanking.com
secure-ibank.com
secure-ibanking.com
secure-netbanker.com
securesolutions-net.com
us-bankconnect.com
us-securebanking.com



He had chosen some innocent American's identities to use when he did his domain name registrations, so they would seem "American", I guess . . .

He was Darleen Murray from Buffalo, NY
and Ray Brooks from Swanquarter, NY
and David Minor from New York, NY
and Eric Mattson from Sherman Oaks, CA
and Joshua Zadow from Mitchell, SD
and Thomas Brooks from Atlanta, GA
and Alice Hatch from Murray, UT
and Leonard Johnson from Socaldwell, OK
and Stephanie Jordan from Seattle, WA
and Ruth Sims from Morro Bay, CA
and Sam McNeal from Baltimore, MD
and Barbara White from Bangor, ME
and Robert Russwurm from Kingston, NY
and Megan Alfonso from Lake Wales, FL

He even used their real phone numbers and email addresses for the contact information on the registrations!

Each of these folks curiously decided to use the same Technical ID on their registrations -- gTec Limited in Moscow, Russia.

Seven of the domains were registered on October 13th, and seven more on October 23rd, but none were used for spamming before this morning.

Early this morning, Our Pathetic Phisher launched his spam campaign, using machines from all around the world to send his spam. We received messages sent from Japan and Germany, from Korea and Lithuania, from Canada and Kansas City, from Russia and Bulgaria, from the Ukraine and from Turkey.

But there is nothing on ANY of the websites! Even as we sit here watching the spam continue to flow in, we can't get ANY of the websites to show content!

Was it a bad path in the spam? (Regardless of brand they all used the same path.)

Was it quick action by those staunch anti-phishing crusaders in China? (The IP addresses are all the same . . . 123.134.66.8 . . . which is hosted on CNCGroup in Shangdong China.

Or it possible, that the Phisher is just that stupid. That he forgot to put the content on his webservers before he began to send his spam. I'm inclined to believe this is the situation here.

Say it with me . . .

"Bless his little heart..."



Here are the URLs that we saw . . . many times each:

http://associatedbank.1securebanking.com/251005/account-update/
http://associatedbank.1-securebanking.com/251005/account-update/
http://associatedbank.connect-usbanks.com/251005/account-update/
http://associatedbank.ibanking-net.com/251005/account-update/
http://associatedbank.ibanking-secure.com/251005/account-update/
http://associatedbank.securebanking-net.com/251005/account-update/
http://associatedbank.secureconnect-us.com/251005/account-update/
http://associatedbank.secure-ebank.com/251005/account-update/
http://associatedbank.secure-ebanking.com/251005/account-update/
http://associatedbank.secure-ibank.com/251005/account-update/
http://associatedbank.secure-ibanking.com/251005/account-update/
http://associatedbank.secure-netbanker.com/251005/account-update/
http://associatedbank.us-bankconnect.com/251005/account-update/
http://associatedbank.us-securebanking.com/251005/account-update/
http://commercebank.1securebanking.com/251005/account-update/
http://commercebank.1-securebanking.com/251005/account-update/
http://commercebank.connect-secure.com/251005/account-update/
http://commercebank.ibanking-net.com/251005/account-update/
http://commercebank.ibanking-secure.com/251005/account-update/
http://commercebank.securebanking-net.com/251005/account-update/
http://commercebank.secureconnect-us.com/251005/account-update/
http://commercebank.secure-ebanking.com/251005/account-update/
http://commercebank.secure-ibank.com/251005/account-update/
http://commercebank.secure-ibanking.com/251005/account-update/
http://commercebank.secure-netbanker.com/251005/account-update/
http://commercebank.securesolutions-net.com/251005/account-update/
http://commercebank.us-bankconnect.com/251005/account-update/
http://commercebank.us-securebanking.com/251005/account-update/
http://bank.countrywide.1-securebanking.com/251005/account-update/
http://bank.countrywide.connect-secure.com/251005/account-update/
http://bank.countrywide.connect-usbanks.com/251005/account-update/
http://bank.countrywide.ibanking-net.com/251005/account-update/
http://bank.countrywide.ibanking-secure.com/251005/account-update/
http://bank.countrywide.securebanking-net.com/251005/account-update/
http://bank.countrywide.secureconnect-us.com/251005/account-update/
http://bank.countrywide.secure-ebank.com/251005/account-update/
http://bank.countrywide.secure-ebanking.com/251005/account-update/
http://bank.countrywide.secure-ibank.com/251005/account-update/
http://bank.countrywide.secure-ibanking.com/251005/account-update/
http://bank.countrywide.secure-netbanker.com/251005/account-update/
http://bank.countrywide.securesolutions-net.com/251005/account-update/
http://bank.countrywide.us-bankconnect.com/251005/account-update/
http://bank.countrywide.us-securebanking.com/251005/account-update/
http://countrywide.1securebanking.com/251005/account-update/
http://countrywide.connect-secure.com/251005/account-update/
http://countrywide.ibanking-net.com/251005/account-update/
http://countrywide.ibanking-secure.com/251005/account-update/
http://countrywide.securebanking-net.com/251005/account-update/
http://countrywide.secureconnect-us.com/251005/account-update/
http://countrywide.secure-ebanking.com/251005/account-update/
http://countrywide.secure-ibank.com/251005/account-update/
http://countrywide.secure-ibanking.com/251005/account-update/
http://countrywide.secure-netbanker.com/251005/account-update/
http://countrywide.securesolutions-net.com/251005/account-update/
http://wachovia.1securebanking.com/251005/account-update/
http://wachovia.1-securebanking.com/251005/account-update/
http://wachovia.connect-secure.com/251005/account-update/
http://wachovia.ibanking-net.com/251005/account-update/
http://wachovia.ibanking-secure.com/251005/account-update/
http://wachovia.securebanking-net.com/251005/account-update/
http://wachovia.secureconnect-us.com/251005/account-update/
http://wachovia.secure-ebank.com/251005/account-update/
http://wachovia.secure-ebanking.com/251005/account-update/
http://wachovia.secure-ibank.com/251005/account-update/
http://wachovia.secure-ibanking.com/251005/account-update/
http://wachovia.secure-netbanker.com/251005/account-update/
http://wachovia.securesolutions-net.com/251005/account-update/
http://wachovia.us-bankconnect.com/251005/account-update/
http://wachovia.us-securebanking.com/251005/account-update/
Email ThisBlogThis!Share to XShare to Facebook
Posted in phishing | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • What about the Social Security Numbers? (The Utah Data Breach and your SSN)
    The Utah Data Breach This week the continuing saga of the Utah Medicaid Data Breach continued to unfold. If you haven't been following...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Carder Christopher Schroebel gets Seven Years
    21 years old and thinking about Cybercrime as a career choice?  Think again.  Seattle-based U.S. Attorney Jenny Durkan told a press conferen...
  • Stop the Rumors: Quit SMSing about WalMart Gang Initiations
    My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here...
  • New BBC spam mocks Georgia's President, Spreads New Virus
    This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads ...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Digital Certificates Update
    A quick update from the previous post. The Digital Certificates spam campaign against Merrill Lynch continues, but the good guys seem to be ...
  • ATM Cashers in 26 Countries steal $40M
    CBS News in New York has a video on their website this morning title Cyber-attacks behind possibly record-breaking bank heist . Former FBI ...
  • A New Year and Anti-Virus Products Are Still Losing
    One of our most popular blog posts in 2008 was back in August - Anti-Virus Products Still Fail on Fresh Viruses . I'm sad to report tha...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ▼  October (11)
      • LaSalle acquisition by Bank of America spreads mal...
      • First Enom Phish, now Network Solutions Phish
      • Caution: Enom Phishing continues
      • Ding Dong The Witch Is Dead! ( ICANN Pulls the Pl...
      • Tip to Phishers: First Build Site, THEN Spam
      • Operación Carrusel sets an example for fighting Ch...
      • The demise of index1.php PornTube Video Malware
      • Ryan Goldstein: Digerati Faces ?Justice?
      • FTC stops AffKing and SanCash, so is Pill Spam Gone?
      • SanCash (Affking) taken down in New Zealand
      • Need help with your debt? Ask the Panamanian Russ...
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile