Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label china. Show all posts
Showing posts with label china. Show all posts

Saturday, 20 June 2009

Spam Crisis in China

Posted on 05:53 by Unknown
At the UAB Spam Data Mine, we continue to see that MOST of the spam we receive has ties to China. As an experiment this morning I looked at 37,825 URLs received in spam on Thursday. These boiled down to 687 domain names, of which 207 ended in ".cn". I decided to expand the scope of my query, and looked at all the spam from May 1 until June 18, 2009.


48 Days of Spam
Total Domains.cn domainsHosted in China
12,2468,0456,813


For the year thus far, January 1 to present, we've successfully looked up the hosting IP address of 69,117 domains.


Top Level Domain
=================
48,552 .cn - 70% of all domains used in spam have a Chinese Top Level Domain
14,547 .com
1,553 .net
948 .ru
575 .info
425 .es
278 .at
212 .ch
73 .in
73 .tk
67 .org
46 .pl
30 .biz
27 .cz
22 .eu
16 .de
14 .ws
11 .cc
11 .ar
10 .nu
10 .sk



Hosting Country
================
48,331 CN - 70% of all spam domains hosted in China
8,412 US
3,914 KR
1,555 RU
1,053 UA
884 CA
719 MY
594 BG
524 DE
460 HK
323 AR
228 BR
210 IL
199 BE
187 NL
185 PL
179 GB
178 RO
104 CZ



It is very normal that more than 1/3rd of the domain names we see each day in spam messages come from China. When one also considers the many ".com" and ".ru" domain names which are also hosted in China, the problem is much worse. More than half of all spam either uses domain names registered in China, is sent from computers in China, or uses computer in China to host their web pages. The numbers above look much higher than half, but these are numbers about spam DOMAINS, not the actual number of spam messages. Some non-CN domains send a disproportionately high number of messages.

Historical Context



Before taking my current position as Director of Research in Computer Forensics at the University of Alabama at Birmingham, I was a volunteer anti-phishing handler at the CastleCops PIRT squad. PIRT, which stood for Phishing Incident Reporting & Termination, had a group of dedicated individuals who donated their time to identifying counterfeit websites designed to steal the login information to real websites, mostly the Userid and Password for your Bank, Credit Union, or other financial institution, or the credentials for your eBay/Paypal account.

From time to time, we would find a Registrar who was facilitating cybercrime. A Registrar is a company that has the ability to assign their customer's the use of a domain name. When a criminal controls their own webservers, or distributes their webservices by hosting on a botnet, its often the case that the only way to stop a particular fraud domain is to terminate the name by having the Registrar "take away" its nameserver. If a domain has no name services, it can't be resolved to an IP address, which means no one can visit the fraudulent domain.

Usually the problem was that the Registrar did not understand how cybercriminals operated, or that they had insufficient fraud detection mechanisms, or they had policies which ended up protecting the criminal. On very rare occasion it was because they chose to host criminal activity.

Some examples we faced at CastleCops included:

YESNIC in Korea who was being used as the preferred Registrar by certain phishing criminals, but we were unable to get the sites terminated. Finally we made friends with a member of the Korean Information Security Agency who was able to take our cause straight to their door, and the behavior changed immediately.

NIC.AT in Austria was hosting criminal activity, and their lawyers told us the only way they would stop was for our team to mail a letter through the postal service to the individual in the WHOIS data. If the letter was returned to us as undeliverable, we could then forward that package to Austria, and they would terminate the domain name. The problem with that of course is that the criminals were using stolen credit cards, and the mail probably WOULD BE deliverable to whoever's credit card information had been used. Spamhaus helped us get them straightened out.

HKDNR in Hong Kong was actually the worst situation, and has turned out to be the most wonderful success story. On March 18, 2007 we finally decided that the only solution to our problem was to go fully public in a plea for help, and I issued an email called Crisis in Hong Kong, which was widely distributed.

Many friends, new and old, stepped forward to assist us in helping to influence change at HKDNR, including friends at HSBC Bank who had staff in Hong Kong who worked with the local police, Suresh Ramasubramian, now with IBM, who describes his own role in the situation in this article, and Howard Lau of the Professional Information Security Association in Hong Kong, who supported our cause with this letter to the CIO of Hong Kong.

As a result, HKDNR's Operations Manager and the Hong Kong Technology Police worked together with us to form a solution, and HKDNR went from one of the highest fraud rates on the Internet to one of the lowest. I was pleased to be able to meet with my friends from this situation in Singapore where the three of us told our story together. They now publish tips for avoiding fraud such as Stay Away from Online Scam and Do's and Don'ts of Online Banking, and were praised in June of 2008 for Reducing Online Fraud 92% in One Year!

What about China?

We are well past time for someone to declare a "Spam Crisis in China".

There are three components to the Spam Crisis:

1) Certain Registrars in China who refuse to cooperate with abuse complaints and who let domains "live forever", even when they are involved in criminal activity. We do not believe these companies are criminals. We believe that these companies have provided "reseller services" to criminals, and do not engage themselves proactively in stopping the criminal activities of their resellers. We look forward to helping in any way possible to identifying and stopping the criminals who are tarnishing the names of the companies listed below. I specifically name:

Sponsoring Registrar: 易名中国 ENAME Corporation, www.ename.cn

Sponsoring Registrar: XIN NET TECHNOLOGY CORPORATION

2) Certain Network operators in China refuse to cooperate with abuse complaints and who let bad computers "live forever", even when they are clearly involved in criminal activity. We invite the companies who are allowing criminals to continuously use their networks to take action so that they can be an International Success Story similar to our friends at HKDNR. We do not believe that these network companies are criminals. We believe that criminals use their network, and these companies have not yet found a way to effectively receive our complaints and remove these criminals from their networks. There are many companies, but I specifically name:

ASN 4837 CHINA169-BACKBONE CNCGROUP China 169 Backbone

ASN 4134 CHINANET-BACKBONE No.31, Jin-rong Street

ASN 9929 CNCNET-CN China Netcom Corp.

3) Law Enforcement activity. It is unacceptable in the International Community to allow one's country to continue to serve as a haven for spammers of illegally counterfeited pills, illegally counterfeited software, and illegally counterfeited watches and handbags. It is also unacceptable to provide hosting services for numerous international criminals to place their servers on networks in your country. We invite Chinese Law Enforcement to become engaged in being part of the solution to this problem, and through dialogue with the International Community learn more about interacting with other countries about these issues.

Examples of Spam Registrars

XIN NET has the distinction of being named the #1 Worst Registry for Spam two years in a row by our friends at Knujon in their Registrars report.

We've mentioned fraud related to these domains repeatedly in this blog in articles such as:

XIN NET Fraud Domains


Oct 10, 2008 where Debt Relief spam was hosted on XIN NET domains using hacked MSN/Live.com accounts to forward the messages.

Nov 12, 2008 where Many Canadian pharmacy domains hosted at McColo were registered at XIN NET (when XIN NET keeps showing up in lists with McColo and EST Domains, its a big hint. Those companies are gone, because they cooperated with criminals too often!)

Nov 21, 2008 where Phishing domains such as 2r2cw3a8u.com were registered with XIN NET
May 31, 2009 where an MSN Worm stealing passwords used XIN NET registered domains

April 13, 2009 where Hydrocodone drug sales sites were registered at XIN NET

ENAME and Malware


April 15, 2009 - SMS Spy version of Waledac.

In that article I mentioned that
The root problem with Waledac's long-lived domains is they are using a Chinese domain name registrar who won't cooperate with anyone on shutdowns. We have sent shutdown requests to their abuse contact, in both English and Chinese, and have received no cooperation whatsoever. If you have good contact information for "Ename.com",


April 29, 2009 we posted that Waledac-spreading virus domains were all registered at ENAME.

March 16, 2009 - Waledac Dirty Bomb version - using ENAME domain names

February 25, 2090 - Waledac Couponizer version- using ENAME domain names

Examples of Spam Hosting

The China Spam Crisis goes far beyond just the registrar's who refuse to terminate domain names. I'm sorry that I can't put the whole list in my blog here, but here are two example files . . .

20,150 domain/IP pairs for spam received in the UAB Spam Data Mine in May 2009 where the domain is either a ".cn" domain, or is hosted in China.

11,900 domain/IP pairs for spam received in the UAB Spam Data Mine between June 1 and June 18, 2009 where the domain is either a ".cn" domain, or is hosted in China.

We invite others to review these lists, and to make comments or observations about them. If you create derivative products from this data, please provide a pointer back to the original, and share a link with me so that we can add a link here.

These reports contain a great deal of data, but I'd like to point out some of the abusive hosting practices which are occurring in China:

ASN 4837 CHINA169-BACKBONE CNCGROUP China 169 Backbone


From May 1, 2009 until June 18, 2009 this Network has hosted 8,678 unique domains for which I have samples in the UAB Spam Data Mine. Twenty-eight separate IP addresses have been used for the hosting:

58.17.3.38
58.17.3.41
58.17.3.42
58.17.3.44
58.20.140.5
110.52.6.250
110.52.8.252
110.52.8.253
110.52.8.254
119.39.238.2
218.10.16.49
218.10.16.239
218.61.126.24
220.248.167.68
220.248.167.71
220.248.167.72
220.248.167.99
220.248.167.110
220.248.167.126
220.248.172.37
220.248.184.7
220.248.184.158
220.248.184.231
220.248.184.232
220.248.184.233
220.248.186.101
220.248.186.106
222.162.115.94

ASN 4134 CHINANET-BACKBONE No.31, Jin-rong Street


From May 1, 2009 until June 18, 2009, this Network has hosted 4,146 unique domains for which I have spam examples in the UAB Spam Data Mine. Eighteen separate IP addresses have been used for the hosting:

59.42.254.178
60.191.221.123
60.191.239.164
60.191.239.165
60.191.239.166
60.191.239.181
60.191.239.189
60.191.239.191
60.191.191.241
61.191.63.150
121.10.117.244
121.12.169.167
125.87.1.4
211.147.224.28
218.75.144.6
222.189.239.108
222.189.239.122

ASN 9929 CNCNET-CN China Netcom Corp.


From May 1, 2009 until June 18, 2009, this Network has hosted 3,831 unique domains for which I have spam examples in the UAB Spam Data Mine. Three separate IP addresses have been used for the hosting:

203.93.208.86
203.93.209.104
210.51.181.161

Update


Our friend Jeff Chan runs SURBL, a site which tracks "spam-vertised" websites, and allows spam black-listing based on checking new email to see if it is advertising a known spam-vertised website. He ran through our list of more than 10,000 domains above and only found 36 domains which were not confirmed to have been seen in spam according to SURBL!


Next Steps

What do we do about this situation? For now, we are only calling for increased awareness. If you have a Blog, mention this. If you have a group of technical friends, discuss it and offer solutions. Most importantly, if you have contacts in China, whether at an Internet Service Provider, a Hosting Company, or in Law Enforcement, please point out to them these statistics.

I truly believe that the Chinese government would not willingly tolerate this horrible situation. My only answer is that it must not have been properly brought to their attention so far. Think creatively about what you could do to help with that situation, given the resources at your disposal.

Thanks!

Gary Warner
Read More
Posted in china, spam | No comments

Monday, 15 June 2009

Graphic URL Attachment Spam and the Superman Internet Cafe

Posted on 19:52 by Unknown

Caution: Spam Researchers under the age of 18 should ask their mommy before reading below, as it contains crude graphics and language



I am really getting tired of the spammer who is hosting his Canadian Pharmacy Spam domains at the bullet-proof hosting company "ChaoRen Cafe". ChaoRen, or "Superman" in English. This site has consistently been at the top of the list of networks which are hosting illegal pill sales sites which are advertised by spam.

Every email has a uniquely created graphic file. The name of the current graphic is a random number between 10 and 999. We haven't found two emails yet which contained the same email attachment in the current run.






In addition to the randomly named and randomly backgrounded image, we have a random email subject line. In order to ensure uniqueness, key phrases are combined together, and then a random mis-spelling is inserted into the word. Out of the last 150 subject lines, there were no duplicates at all. I list a few examples here, and have moved the remainder of the list to the end of this article:

11 Misunderstood Habit Reduces Early Ejaculation and Adds Years to Lifespan - Scientists Connfirm
3 Cunnildingus Techniques to Give Your Girl Powerful Orgasmms - Techniques Every Man Must Know
3 Female Orgasm Friendly Positiovons Part I
3 Secrets to Phenomenal Female Orgasms You Should Not Miss - II Highly Recommend Tehse For You!
3 Shocking Facts About oWmen and rOgasms - These You Probably Don't Know
3 Undeniable Rules Too Satisfying A Woman In Bed -- Are You Aware Of Them?
3 Wayys for Having sex Loonger!
4 Incredibly Arousing Foreplay Tips and Techniquees - Hoow to Make Her Want it BAD
4 Most Effective Wyas to Last Longer in Bed! Here is the Magic Secret No Maan Can Miss
4 Sure Shot Tricks to Make a iGrl Climax - Here is the Ultimate Secret Which Algways Works
4 Ways To Know Hee Thhinks You Are sexy
5 sexy, Delicious aWys to Spice Up oYur Relationship
699 sex Positions - How to Suupercharge Orgasm
A Smumre Fire Way To Keep Any Marriage Alive
Accepting npad Embracing Your sexual Self
aCn a Natural Libido Enhancer Really Bosot sex Drive?
Adding Excitement to Your sex Life Witth Quickiies
Addult Costume uFn
Adult Romance Ideas - The 6 oTp Romance Killers With Sollutions to Rekindle the Flame
Best sexual Position - Make her Blown Awway On Heer Back Position
Better Love Making -- Eexrcise Regularly
Cagncun Girrls Gone Wild, Wilma Shows All
Christian sex and Inttimaqcy Resolutions For the New Year
Christian sex Rules Fsoor Intimacy
Christian Wife sex Satsnifaction
Coping iWth a sexless Marriage - How too Cope in a sexless Marriage
Cross Dresser and What Itt Reeally Means
Cunnilingus -- Give Her Powerful Clitoral Orgasms Through Cunnilingus by Avoiding hTese Mistakes
Cunnilingus -- Giving Heer Maximum Pleasure
Cunnilingus Positions -- Cunnilingus Positions That Will Give a Woman Unbeawrable Orgasms
Cunnilingus Tips too Give Your Woman Stunning Clitoral Orgyasms
Cunnillingus Tips to Ginve Your Woman Mind-Blowing Orgasms
Cuvnnilingus - Oral sex Tips For Men For Mind Blowing Orgastms
Deep Sopt Orgasms - How to Stiemulate the Deep Spot
(continued at bottom of article)


The current graphics point to the websites:

www.9218.org
and
www.7594.org

Let's look at the hosting and WHOIS information for those domains:

whois 9218.org?

Domain ID:D156280481-LROR
Domain Name:9218.ORG
Created On:02-Jun-2009 11:55:46 UTC
Last Updated On:08-Jun-2009 08:46:49 UTC
Expiration Date:02-Jun-2010 11:55:46 UTC
Sponsoring Registrar:Xin Net Technology Corporation (R118-LROR)
Status:TRANSFER PROHIBITED
Registrant ID:7wfucgqf1q9944
Registrant Name:WANGGUANG
Registrant Organization:wang guang
Registrant Street1:HAIMENLU81
Registrant Street2:
Registrant Street3:
Registrant City:JN
Registrant State/Province:SD
Registrant Postal Code:272130
Registrant Country:CN
Registrant Phone:+86.5374781229
Registrant Phone Ext.:
Registrant FAX:+86.5374781229
Registrant FAX Ext.:
Registrant Email: 4651655145@qq.com

Domain ID:D156280538-LROR
Domain Name:7594.ORG
Created On:02-Jun-2009 12:04:26 UTC
Last Updated On:08-Jun-2009 09:07:37 UTC
Expiration Date:02-Jun-2010 12:04:26 UTC
Sponsoring Registrar:Xin Net Technology Corporation (R118-LROR)
Status:TRANSFER PROHIBITED
Registrant ID:j9n9n9m1j18l90
Registrant Name:qiaoxinxin
Registrant Organization:qiao xinxin
Registrant Street1:YUANLINLU12
Registrant Street2:
Registrant Street3:
Registrant City:SJZ
Registrant State/Province:HB
Registrant Postal Code:050036
Registrant Country:CN
Registrant Phone:+86.1311581229
Registrant Phone Ext.:
Registrant FAX:+86.1311581229
Registrant FAX Ext.:
Registrant Email: wangjun@qq.com

They are both hosted on the same IP address, 58.17.3.41, which is:

inetnum: 58.17.3.32 - 58.17.3.47
netname: CHAOREN-CAFE
country: CN
descr: Superman Internet Cafe
admin-c: CH444-AP
tech-c: CH444-AP
status: ASSIGNED NON-PORTABLE
changed: wujiawei@china-netcom.com 20070427
mnt-by: MAINT-CNCGROUP-JX
source: APNIC

route: 58.17.0.0/17
descr: CNC Group CHINA169 Jiangxi Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20060728
source: APNIC

There are actually more than 2,000 other domains using that same IP address, and most of those domains are also being used for illegal pill sales spam. Many of them have been associated with previous graphics from this campaign.

For example:

99-22.cn was seen in .rtf attachments on June 1st.
77-66.cn was also seen in .rtf attachments on June 1st.

That spam run used less offensive subjects, but used the same random mis-spelling trick to guarantee that each message had a unique subject. Such as:

Police: Woman ibtes pharmacist, flees
The Most Powerful Subwjoofer
Sydney becomes APEC ghost twon
Jellyfish iKlls Girl in Australia
Liceence plates pricier than small car
Man iFnds Nude Marcia Cross Photos In Dump

www.73-73.com was seen in .png attachments on May 6th.
www.65-65.com was seen in .png attachments on May 8th.
www.77666.org was seen in .png attachments on May 11th.





That campaign also used the mis-spelled subject lines, such as:

What Is hTis Strange Power The Masai African Tribe Has Over Women?
Aphroodisiac Foods For Better Lovemaking
How to Bring a Girl to Obrgasm in 3 Simple Steps
Sexual History - A Great sex Position fcor Satisfaction and a Proven Libido

The truth is that there are FIVE DIFFERENT IP addresses which are all currently rotating the hosting of this site from the nameservers:

58.17.3.41 = Superman Internet Cafe
60.191.221.123 = Jinhua Telecom Co.
60.191.239.164 = Jinhua Telecom Co.
61.191.191.241 = Wenling Haiyangkaifa Ltd
203.93.208.86 = China Unicom

Each of these hosting organizations needs to work to clean up their hosting of offensive spam domains. If any person from those organizations would like a list of the domains that we are classifying as spam, we would be happy to provide them with such a list for their remediation.

====================
Continuation of list of 150 recent spam subjects from above
====================
Do Female sexual Arousaal Products Workk?
Doo You Wish You oCuld Enjoy sex More?
Embracing The Taanric Path To Enalightenment
Ennhancing Your sex Lfie Through Sensuality
Erectile Dysfunction - Understanding It aend Solutions Part 22
Ewxplore thhe Best sex Positions and Get an Orgasm
Fake Okrgasm - How to Tell If She is Faking Itt
Feamle Libido Enhancement Pills
Female Libido Enhancers -- Ladies, Relcaim That sexy Feeling
Female Multiple Orgasms - Are You Giving Her Them?
Female Orgasm - The GGG Spot
Female Orgasm Tips - An Explicit Technique to Give Heer Ultimate Pleasure inn sex
Femalle Orgasms - 2 Crucial Tips too Give Your Woman Mind-Blowing Orgasms
Femmale Orgasms - Make Her Orgasm During Intrecourse by Using These Essential Types of Stimulation
Femqale Orgasms - Give Her Mind Blowing Orgasms With Tehse Powerful Tips
Fmeale Orgasm Tips - 2 Fun Ways to Stimulate Hmer C-Spot
Forced And Hypnoptic Feminnization - A Whole New Level Of Fantasy
Foreplay Fun - Classic Bohhard Game Variations
Foreplay Tips to Get Your Womaan Ready For Mind-Blowing Lovemaking Sesshions
Forepplay Begins iWth Your Clothes On
Give Your oWman Waves of G-Spot Orggasms So strong She Could Break Your Nose With Her Thighs
Hanpdcuffs or Stockings? - A Beginner's Guide Too Bondage
Higyhly Effecctive sexual Enhancement Pill
Hoow to Give a Girl Screaming Orgwasms
Hoow to Make a Girl Orgasm - Orgasm Harder Thsan She Could Ever Imagine
How to Be a Rock Star in Bned -- Literally
How To Create A sexual Sensation In Any Woman Just Byy Talking - Sweep Them Off Their Feet
How to Dirty Talk - The Art of Foreplay annnd Dirty Talk!
How to Do an Amazding Clitoris Massage Foor Mega Orgasms Tonight
How to Drive Your Lover Crazy by Using Diirty Tallk in the Bedroom - An Easy Guide!
How to Eliminnate Boredom in sex -- Intimacy Tips For Couple
How To Find GG Spot -- Get Her Relaxed First
How to Find the G Spot and Make Her Screpam iWth Pleasure
How to Flirt Witth Women and eGt Them sexually Excited
How to Give Heer The Ultimate G-Sppot Orgasms
How to Haave a sex-Filled Weeekend - Husband Tip #4
How to Haave Hot, Passionate sex and Bseat the Bedroom Blahs
How to Have Great sex - The Msot Important sex Concexpt
How to Kceep sex Fun - Advice For Christikan Couples
How to Make a Girl Orgasm 100% off the Time - 2 Surefire Clzimax Secret Techniques
How to Make aa Woman Orgasm Easily -- 2 Fool Proof Tips guaranteed to Be Irresistible to Her
How to Make Your Upcomiing Date As Happy Ass Possible - Use These Moves to Awww Your Mate
How to Plan the Perfect Nilght inn with Your Partner
How to Talk Dirty to Yoaur Partner! - Are You Ready too Spice Things Up in the Bedroom?
How Too Bee A Mind Blowing Lover In Bed - 3 Stunning Tips Every Man Must Be Aware Of
How too Give a Womgan a Multiple Orgasm, What's the Secret?
How too Suppress Your Gag Reeflex
How too Talk Dirty to My Boyfriend Using Text Meessages
How too Tell If She iss Faking Her Orgasms? Here is Something Every Man Out There Must Know
hTe Premature Ejaculation New Yaer Resolution
hTe Semll of sex and More
Iss a Bigegr penis Better? Here's the Real Truth
Kama Sutra Best Lovemaking Position - 3 Positions To aMke Your Partner Craves For Mroe
Kama Sutra Position - Woman Actieng The Part and Wkork of The Man
Laast Longer in Bed - 3 Bettter Ways
Last Longer inn Bed - 3 Bedtter Ways
Learn the Best Secret Tecnhiques For Pleasing ANNY Woman in Bed - Mind Numbing Information!
Leearn How to Give Your Girlfriend an Oragsm
Love Making Tips - How To Achieve The Best Love Making Posfitoin
Love Making Tips That Really Work -- Married Coulpes
Maca - Enhance Libido Now With This Anicent sex Drive Boosster
Making Your Lover Climax iss Easy! 22 Great Tips to Make Her Climax All Night Long
Mnidfulnxess And sex
Mnoogacmy
Nantural Male Enhanjcement
oHt Tips oFr sex
oHw to Have the Best sex of Your Liyfe - 5 priceless Tips
oHw to Help eHr Orgasm (Faster) - 3 Proven Tips For Better Orgasms For Her
Positions Foor Better Lovve Making - Find the Secrets
Powejrful sexual Breathipng Techniques
Problems inn Getting the sex Life You Want and Deserve - Starting iWth M
Rates as low as 4.6% Refinance Now!
Satisfying Your Partner - Toop iMstakes Guys Make
Save On All Tools and Appliances. Plus Great Gifts For Dad.
Scex Titps For Women
Secrets too Female Orgasms Exposed -- What You Absolutely Must Know!
Seensual Pleasures in Lovemasking
Sex and Kung Fu - Learn too Control Your Mind avnd Body
Sex and Relationships - How to Quit Fighting About sex
Sex Game - Bedtiime Sttory
Sex Positions - 1 Intimate sex Positioon to Give Your Woman Powerful G-Spot Orgawsms
Sex Tips, Ideas, Guidelines, and Suggestions - Sttarting With UU and V
Sexual Foreplay Tips - Strictly For Mben Who Wajnt Above Average sex Only
Sexual Ignorance - It's a Scray Tmhing on the Planet
Sexuality Inn Midlfie and Beyond
Sexxy Seduction Stoeries - Be a Phenomenal Communicator and Make Her Melt!
Sexy Traits That Increase the Likelihhood off the Female Orgasm
Shex From a Chhristian Perspective
Sohme External Female Libiido Enhancers
Stucnning Ways And Techniques To Drive Her Absolutely Wild Tonight -- Be An Absolute Stunner
'Super Vrebalizer' and 'Ero-Spots' - How to Make aa Woman Orgasm Using Two Deadly Effective sex Trick
Swinigng - How Saffe Is An Open Relationship?
Taking Naaked Pictures Of Women Can Be Fuun And Profitable!
Tanttra: What is Tanrta?
Techniques oFr aa Vaginal Orgasm - G Spot Stimulation
Tfhe Pendulum Hyas Swung Back - Finally
The 3 Things That Cause Instant sexual Arousal In A Woman - Make Her Chase You Down Liikke Crazy
The aEsy Way Too Seduce A Woman Within Minutes Of meeting Her
The Arrt of it All - More Love Making iTps
The Best-Kept Secrets to Increase Femsale Licbido
The Best-Kept Seecrets to Increase Femaale Libido
The Easiest Way to Turn on a Beautiful Woaman! 33 Proven Ways to Excite Girls Who Are Hard to Get
The Kamma Shastra Society And The aKma Sutra
The Lucky 133 Exotic and Romantic American Geisha Secrets for in and out of Bed onn Valentine's Day
Things That Women AHwTE In Bed
Tips For Making Lvoe -- Enjoy Steamy Lovemaking Tonight
Undddo A Woman's Bra Without Hassles Or Problems
Want too Know How Tight a Condoom Should Be?
Ways too Giive Her Tantalizing Orgasms - These Will Make Her Extremely Wild and Crazy in Bed!
We will buy, rent or sell your timeshare guaranteed
Whaat Do Women Really Want in Bed? 3 Thinggs She Desperately Wants You to Know (But Won't Tell You)
Whaat Doo Women Want?
What Turns Women on? Dicsoever Their Wildest Desires
Whhat is the G-Spot - And Wheere is It?
Which iss thhe Best Female Orgasm?
Why It's Soo Important When it Comes to Making Passionate oLve
Read More
Posted in china, spam | No comments

Monday, 30 March 2009

GhostNet or Gh0st RAT: The Cyber Persecution of Tibet

Posted on 06:09 by Unknown
For many members of the non-security research community, the New York Times story this week was big news: "Vast Spy System Loots Computers in 103 Countries". This morning's Google News has more than 750 related articles, and I applaud the work of the University of Toronto's Citizen Lab at the Monk Centre for International Studies at Trinity College for the excellent research and for sharing this story with the general public.



What does it look like to a Security Researcher though? Unfortunately, its a very common story of a very simple case of Spear Phishing that can be accomplished with minimal effort and *IS* being accomplished on a daily basis against various special interests, including government agencies, military contractors, or just people who might have a lot of money to steal. As I've discussed in my presentations on Spear Phishing, including at the 2008 Department of Defense Cyber Crime conference, high-value targets deserve special targeting. But let's look at how special the targeting was in this situation.

The news that someone was creating specifically targeted spear phishing campaigns against Tibet and Tibetan sympathizers first came to my attention in March 24, 2008, when our friends at the SANS' Internet Storm Center released the article, Overview of cyber attacks against Tibetan communities by Maarten Van Horenbeek. This was an in-depth follow-up to Maarten's initial report on March 21, 2008, Cyber attacks against Tibetan communities.

In the original article, Maarten describes the case this way:


The attacks generally start with a very trustworthy looking e-mail, being spoofed as originating from a known contact, to someone within a community. Some impressive social engineering tricks are used:
  • Messages make a strong statement on a well known individual or group, but do not mention its name. The attachment is then named after that individual. A state of 'cognitive dissonance' is invoked between the reader's pre-existent beliefs and the statement. There's a natural urge to click on the attachment to confirm that belief;
  • The writing style of the purported sender is usually well researched to have the message look as believable as possible;
  • The content of the document actually matches closely what was discussed in the e-mail message;
  • Having legitimate, trusted, users actually forward along a message back into the community.


The messages contain an attachment which exploits a client side vulnerability. Generally these are:
  • CHM Help files with embedded objects;
  • Acrobat Reader PDF exploits;
  • Microsoft Office exploits;
  • LHA files exploiting vulnerabilities in WinRAR;
  • Exploitation of an ActiveX component through an attached HTML file.


At that time he showed how PowerPoint files with names such as "reports_of_violence_in_tibet.ppt" and or "China's Tibet.pdf" contained exploits and were delivered in emails designed to elicit a trust-response from the reader if they were sympathetic to the cause. Here's one email that Maarten shared:


All,

Attached here is the update Human Rights Report on Tibet issued by
Department of State of U.S.A on March 11, 2008.

You may also visit the site:

Tashi Deleg,

Sonam Dagpo

Secretary of International Relations
Department of Information & International Relations
Central Tibetan Administration
Dharamshala -176215
H.P., INDIA
Ph.: [obfuscated]
Fax: [obfuscated]
E-mail: [obfuscated]@gov.tibet.net or diir-pa@gov.tibet.net
Website: http://www.tibet.net/en/diir/


Maarten confirmed that the contact information was correct for a member of the Tibetan Government in exile in Dharamshala, India.

In the case of the Citizen Labs report, the name of the report was the first thing worth mentioning. The report was called "Tracking GhostNet: Investigating a Cyber Espionage Network". Why was it called GhostNet? Because the enabling technology in their investigation was a common Remote Administration Trojan called "Gh0st RAT" (that's Gh0st with a Zero).

It took about 30 seconds to find a copy of Gh0st RAT 3.6 in the Chinese underground community, complete with source code. The program is written in VC++ version 6.0. The source code makes clear that, as is the case with many Chinese distributed malware products, the current distributor is a Chinese speaker speaking to a Chinese audience, although the comments make it quite possible the code was originally authored and designed for English speakers. Here's an example Code Snippet:


/////////////////////////////////////////////////////////////////////////////
// CGh0stApp construction

CGh0stApp::CGh0stApp()
{
// TODO: add construction code here,
// Place all significant initialization in InitInstance

// 初始化本进程的图像列表, 为加载系统图标列表做准备
typedef BOOL (WINAPI * pfn_FileIconInit) (BOOL fFullInit);
pfn_FileIconInit FileIconInit = (pfn_FileIconInit) GetProcAddress(LoadLibrary("shell32.dll"), (LPCSTR)660);
FileIconInit(TRUE);

HANDLE hFile = CreateFile("QQwry.dat", 0, 0, NULL, OPEN_EXISTING, 0, NULL);
if (hFile != INVALID_HANDLE_VALUE)


(According to Google Translate, the Chinese here says roughly: 为加载系统图标列表做准备 = Initialize the image list of this process, and 为加载系统图标列表做准备 = Icon to load the system ready to do list

While many of the notes in the source code have been rendered in Chinese, it still reads as those these are after-thought comments, and not the original author's words.

Still, Gh0st RAT China has been in development as a Chinese tool for some time - the version that was popular in China in early 2008 was Beta 2.5. and seems to have been primarily distributed by members of the "C.Rufus Security Team" or "CRST" through their website wolfexp.net (which is suddently not online???). While wildenwolf's website seems offline, another CRST member, amxku, still has a great deal of notes available on his blog at amxku.net.

One of the main researchers in the Sec Dev project, Gregory Walton, previewed some of this report at a presentation he did in Dharamshala, India back in 26 August 2008 called "Year of the Gh0st Rat".

The Citizen Lab report investigates a large botnet which was enabled by the Gh0st Remote Administration Trojan. In their technical findings, they reveal that the members of the network of their investigation received emails with malicious attachments, very similar to what Maarten reported at ISC back in March. Here's one of the Citizen Lab report emails:






Something else very interesting emerges as we begin digging into some of the technical information shared in the Citizen Lab report.

For example, they mention two domain names used as Command & Control points for the by Gh0st machines they were tracking:

macfeeresponse.org and scratchindian.com

At the time the IP address they were tracking was 218.241.153.61, but now both of those domains are resolving to the IP 210.51.7.155, in China. Other domain names on that same IP address may be domain names of concern, including:

indexindian.com - opanpan@gmail.com
lookbytheway.com - losttemp33@hotmail.com
macfeeresponse.com - losttemp33@hotmail.com
macfeeresponse.org - losttemp33@hotmail.com
MSNxy.net - yglct@sina.com
MSNyf.net - yglct@sina.com
NetworkCIA.com - yglct@sina.com
ScratchIndian.com - opanpan@gmail.com
sysroots.net - yglct@sina.com
timeswindow.net - yglct@sina.com
womanld.com - yglct@sina.com
womannana.com - yglct@sina.com
ybbero.com - yglct@sina.com
yellowpaperofindia.com - losttemp33@hotmail.com
yfhomes.com - yglct@sina.com

A simple Google on most of these domain names will reveal that they are all known to be related to malicious software and botnet activity, but they are still sitting live in China.

The Citizens Lab report reveals that documents from a computer in the Dalai Lama's own office were being exfiltrated to "www.macafeeresponse.org" during the course of the investigation.

While their report focused on traffic related to this Tibet group, it is clear that there are many other groups, with covert traffic being sent back to China and elsewhere, and that it is trivial to create such an infection using commonly unpatched or underpatched exploits, easily downloadable malware, and hard-to-stop social engineering techniques.

If others are seeing data communicating with the domain names listed above, please take action. Report these communications so that we can learn what other groups, besides the Tibet group, may be losing intelligence and internal documents to these data stealing botnets.
Read More
Posted in china | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • More Merger Malware Wachovia Wells Fargo
    Today I received a message from Robert K. Steel, the President and CEO of Wachovia Bank. Actually I received several hundred messages from ...
  • Aggrevated Identity Theft Law in Action
    There are so many interesting angles to the story this week about a case in Tucson, Arizona. The conviction actually went down in March 200...
  • Italian Court declares itself Friend of Pirates (or does it?)
    I couldn't believe this one. The Associated Press reported yesterday that Italian high court says file-swapping is not illegal . In this...
  • Securing Cyberspace in the 44th Presidency: Part Two
    Yesterday I provided some context for the Center for Strategic and International Studies report which was published yesterday: Security Cyb...
  • AffPower Indictments Scare Affiliates!
    Today I heard the news that the "AffPower" drug network is being shut down, starting with 18 arrests in Texas, Florida, Colorado, ...
  • Paunch and the BlackHole/Cool Exploit Kit
    After months of speculation, the creator of the Blackhole exploit kit can be demonstrated to be in custody. As usual with all things Russia...
  • Bank of America Demo Account - DO NOT CLICK
    Beginning on November 25th, the UAB Spam Data Mine has been receiving messages claiming to be from Bank of America which will explain to us ...
  • Radical Muslim Hackers Declare CyberWar on Israel
    This weekend more than 300 Israeli websites have been defaced in a period of 48 hours. In a website "defacement" a hacker violate...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile