Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 7 July 2008

Nuwar Looks for News Readers?

Posted on 14:56 by Unknown
What news headlines would make you click an email link, even though you KNOW you aren't supposed to do that? The authors of the newest round of Nuwar, which may or may not be the same "storm" worm that we've seen two rounds of already this month, think they know.

Based on a review of this afternoon's "infect you through news headlines", the virus authors believe you want to know about Obama, McCain, Angelina Jolie, and the new Batman movie.

The spam for malware-infection "PornTube" sites is really out of control lately.

The current trend is to hack into someone's site, leave an "r.html" file there, and then send spam with totally unrelated subjects which, when clicked on, will open very offensive porn images and also try to infect the visitor by sending them to a secret website through an "iFrame". (The iFrame redirection site, digitaltreath.info, is now down and will hopefully stay down, after nearly a month of hosting badness.)

The malware which is present on each site is a file called "video.exe", which at least several AV products (AVG, McAfee, Microsoft, Trend) are calling "Nuwar", aka Storm.

Symantec calls it "Trojan.Erotpics", while several others call it "Exchanger" (AhnLab, BitDefender, ClamAV, Fortinet, VBA).

eSafe, F-Prot, Panda haven't weighed in yet -- VirusTotal shows 22 of 33 detections right now.

The template seems to be, pick a random subject, pick a random body line, pick a random website, with the choices I've seen today including:

Subjects
===========

  • Actors required Sign up now
  • Angelina jolie shock pregnancy discovery
  • Angelina Jolie suffers miscarriage
  • Apple files for bankruptcy
  • Are you getting enough
  • Beyonce breaks up with Jay Z
  • Blast in Pakistan
  • Brad Pitt confesses to betrayal
  • China fires missle in Taiwan's direction
  • Christopher Nolan's Knight vision
  • Clinton withdraws support for Obama
  • Eminem found dead in disco toilet
  • Fantastic year for spanish athletes
  • Federer crashes out
  • Fight for your benefits and rights
  • Heath Ledger never saw the Dark Knight
  • Hurricane hits Caribbean islands
  • India plans attack on terrorists
  • Join our talent hunt contest
  • Latest gossips on celebrities
  • Madonna admits to extra marital affair
  • McCain suffers heart attack
  • McCain withdraws from presidential race
  • McCaine vows to remain celibate
  • Memorabilia for heroes only
  • Miley cyrus naked photos expose
  • Obtain your degree in six months
  • Oil falls below $100 a barrel
  • Party scenes with American idols
  • Retire a millionaire
  • Search for singing talents
  • Spielberg found dead in freak accident
  • Take a look only if you are worth it
  • The Mummy 3 movie bankrupt, release delayed


Bodies
===========

  • A-rod admits to previous secret gay fetish
  • Asian girls mass Org partying
  • Barack Obama has been exposed to lack patriotism and shows loss of support from the masses
  • Can you take on two hot girls
  • Check out your popularity polls among colleagues
  • Elton John’s new lover
  • European girls group Org scenes
  • FBI surveillance team reveals trade secrets
  • French hospital in the south of France has admitted Hollywood actress Angelina Jolie
  • Fully online Master's degrees available at accessible prices
  • Gays in U.S military
  • Gun ban threatens to destroy obama's campaign
  • J Lo secret marriage threatens to destroy current marriage
  • John McCain gathers support from lackeys in Iraq and Afghanistan towards his election campaign
  • Kobe Bryant traded to Toronto in latest blockbuster trade
  • Late and great Ledger in running for posthumous Oscar award
  • Lindsay lohan drugged out at own birthday party
  • Madonna split finalized, Guy Ritchie in tears
  • ndia vows to find the masterminds behind the suicide attack that have killed entire embassy staff in Afghanistan
  • Obama belittles McCain's ability to be a presidential candidate contender at his age
  • Obama openly supports abortion and gay rights in bid to win more support from the masses
  • Oprah Winfrey announces wedding plans
  • Paris Hilton in new naked pictures romp at 4th of july party
  • Places to go for secret rendezvous
  • Pregnant Angelina Jolie asked the media to leave her alone while she waits to give birth to twins
  • President Bush latest political guffaw
  • Rating of stolen car for 2007
  • Republican John McCain admits he has no ideas how to jump start the economy and that the Democrat's stimulus plan is the way to go
  • Senator McCain found unconscious in toilet
  • Start your own business and make more money
  • The sky is the limit for Christian Bale as he returns for a second attempt at taming Gotham City
  • This week top travel destination
  • Videos of your neighbors making things
  • Videos on sports celebs and their flings
  • Wesley Clark snubs McCain's service as forgettable in July 4 tribute to the nation
  • Your colleagues are earning more than you



Websites
===========
PLEASE DO NOT VISIT THESE LINKS! THEY *WILL* ATTEMPT TO INFECT YOUR COMPUTER!!!!
Note, all of these sites may contain legitimate business on other pages, but these "r.html" pages have been placed on these domains by a hacker. We aren't saying these sites are guilty of anything other than having bad security.

http://209.222.133.85/r.html
http://50percentoff.nl/r.html
http://adlerautomobile.bg/r.html
http://avellanas.org/r.html
http://balcondelrio.com/r.html
http://boeckinggmbh.de/r.html
http://bursabil-net.com/r.html
http://www.cochesdeimportacion.formulacoches.com/r.html
http://chromet.com/r.html
http://www.dicon.eu/r.html
http://dysank.pl/r.html
http://ethereal-hell.telefragged.com/r.html
http://fabricadsonhos.com/r.html
http://fazemos.com.br/r.html
http://www.govdeli.com/r.html
http://houtkoning.nl/r.html
http://i-manager.it/r.html
http://iconn.pl/r.html
http://livresedotabaco.com/r.html
http://lpplegnica.pl/r.html
http://mediahits.de/r.html
http://phoenixadministration.com/r.html
http://pikous.fr/r.html
http://point1.angies-cafe.de/r.html
http://www.rundegg.com/r.html
http://s229782982.mialojamiento.es/r.html
http://savons-de-provence.com/r.html
http://superhostsite.com/r.html
http://testing.vuenosairez.com/r.html
http://www.trivium.hu/r.html
http://www.rundegg.com/r.html
http://zonamediabus.net/r.html


There seem to be at least two "active" sets of templates (so, you would never see "Angelina Jolie" subjects with the "Kobe Bryant" body, because they are in different template sets, as an example.)

So, news readers, beware . . .
Read More
Posted in | No comments

Thursday, 3 July 2008

Storm Worm Salutes Our Nation on the 4th!

Posted on 15:29 by Unknown
I had just left for my holiday weekend when one of our UAB Computer & Information Sciences students
called to let me know he thought he had a new Storm version on his hands.

He had received an email wishing him a happy Fourth of July, followed by an IP address, which he recognized as a traditional Storm-style email.

I ran a quick check in the UAB Spam Data Mine, and here is what we had so far (the oldest of these is around 90 minutes ago, so we'll have a fuller picture tomorrow I'm sure.)

Subjects
=================
Amazing firework 2008
America the Beautiful
American Independence Day
Bright and joyful Fourth of July
Celebrate Independence
Celebrating Fourth of July
Celebrating the Glory of our Nation
Celebrating the spirit of our Country
Celebrations have already begun
Fabulous Independence Day firework
God bless America
Happy Birthday, America!
Happy Independence Day
Happy Independence Day!!
Independence Day firework broke all records *
Spectacular fireworks show
Stars and Strips forever
The best of 4th of July Salute
Time for Fireworks
Wish your friends a happy Independence Day


Bodies
=================
Amazing Independence Day show
America the Beautiful
Celebrating the Glory of our Nation
God bless America
Sparkling Celebration of Independence Day
Stars and Strips forever
Super 4th!
The best firework you've ever seen

IP Addresses
=================
4.248.91.239
12.173.3.17
24.13.166.252
24.130.139.182
24.249.135.214
24.33.244.139
24.99.230.65
64.252.164.229
65.185.105.8
65.185.32.14
67.176.18.50
67.185.246.151
67.191.111.202
67.36.178.103
67.38.31.104
68.179.134.99
68.62.190.121
69.0.75.77
69.141.230.19
69.225.5.209
216.137.135.74
216.255.59.26




The website, which seems to invite visitors to play a fireworks video,
actually downloads the Storm malware in the form
of an executable called "fireworks.exe".



Detection is fairly good already, with 16 of 28 AV engines detecting at
VirusTotal.com, with each calling it the various well known names for Storm:

Dorf:
Sophos = "Troj/Dorf-BP"

Nuwar:
AVG = I-Worm/Nuwar.U
McAfee = W32/Nuwar@MM
Microsoft = Backdoor:Win32/Nuwar.gen!D
NOD32v2 = Win32/Nuwar.DC

Peacomm:
Symantec = Trojan.Peacomm.D

Peed:
BitDefender = Trojan.Peed.JLV

Tibs:
VirusBuster = Trojan.Tibs.AMZ

Zhelatin:
AntiVir = WORM/Zhelatin.Gen
GData = Email-Worm.Win32.Zhelatin.add
Kaspersky = Email-Worm.Win32.Zhelatin.add
Webwasher = Worm.Zhelatin.Gen


Because this is a holiday weekend, there may be quite a few people who don't get blocking in place right away.

Best of luck to you all, and to those who are fortunate enough to live in the United States of America, Happy Independence Day!
Read More
Posted in | No comments

Wednesday, 2 July 2008

7-11 ATM Hackers (?) - More details

Posted on 04:42 by Unknown
More details are now available about a trio of hackers who were indicted back in March on charges of stealing more than $5M from customers of ATMs. In a July 1st USA Today story few facts were revealed, but it was enough to spin the story back up in the media. I'm getting enough questions about it, I thought I would try to summarize what we know.

Kevin Poulsen had many details, including an affidavit by FBI cyber-crime agent Albert Murray and an affidavit by Ari Baranoff, a US Secret Service Electronic Crimes Task Force agent working in the Eastern District of New York, in his June 28th WIRED Blog.


Baranoff deposed Olena Rakushchynets, the wife of the primary suspect, Yuriy Rakushchynets, who was arrested February 28, 2008 in their Brooklyn residence.

The search warrant against their residence had revealed that Yuriy participated in several Internet carding forums, and had purchased information used to encode blank ATM cards, which he then used to withdraw cash from ATMs. In February 2008 alone, he withdrew approximately $750,000, and on September 30, 2007 and October 1, 2007, he took out $100,000 in the 48 hour period. They also found $800,000 in cash ($690,000 in bags in their bedroom closet), a $34,000 Mercedes, and, from the pocketbook of Olena, 51 $20 bills in sequential order. Olena also had $99,000 in three separate safe deposit boxes, and had made more than $50,000 in deposits to the Ukranian National Federal Credit Union. (See WIRED's copy of the affadavit.

Yuriy, elsewhere called "Ryabinin", a 32-year-old Ukranian immigrant, Ivan Biltse, elsewhere called "Belyayev", 30, and Angelina Kitaeva, were all named in the indictment which covered activities from October 2007 to March 4, 2008. They were charged with "Conspiracy to Commit Access Device Fraud", and that they

unlawfully, willfully, and knowingly, and with intent to defraud, in an offense affecting interstate commerce, did effect and attempt to effect transactions, with one and more access devices issued to another person and persons, to receive payment and other things of value during a one-year period the aggregate value of which is equal to or greater than $1,000.


The indictment states Forfeiture claims on $2,000,000 in property, including the $800,000 seized from Yuriy on February 29, 2008 and an additional $800,000 seized from Ivan on March 4, 2008. (See WIRED's copy of the indictment.

Ivan Biltse, of Bensonhurst, New York, was originally arraigned on March 6, 2008 after being picked up for stealing $9,624 in 12 withdrawals from a Washington Mutal Bank ATM in Bay Ridge back on October 1. According to the New York Daily News, Ivan and Yuriy (who lived in Kensington) were cousins. (See Two Brooklyn Men ripped off $5M from ATMs around globe.)

The case actually started much earlier than that, when back on October 3, 2007, according to the FBI affadavit, First Bank notified the St. Louis Secret Service office that four "iWire" Prepaid Card accounts had been compromised. On just the dates September 30 and October 1, 2007, these four accounts were used to attempt more than 9,000 withdrawals from ATMs around the world, resulting in a loss of approximately $5 Million.

First Bank provided a list of withdrawal attempts, and several hundred of them came from banks in Brooklyn, including the Washington Mutual location that we already mentioned. Transaction and surveillance video pulled from several ATMs and nearby cameras showed:

a Caucasian male making withdrawals at the times and ATM terminals indicated in the First Bank Withdrawal Information for the Compromised Accounts. In the ATM video, this male is wearing a dark blue or black baseball cap emblazoned with the words "Top Gun" and a star and wings symbol, as well as a tan-colored sweatshirt or jacket with a dark blue or black front panel and dark blue or black trim at the zipper and collar.


Separately, on February 1, 2008, Citibank informed the FBI that a Citibank server(*) that processes ATM withdrawals at 7-11 convenience stores had been breached. A fraud alert system was established to flag all uses of these accounts, and the Citibank Withdrawal Information was used in a similar method. Surveillance video was pulled for many of these transactions, and some of them, including some on February 20, 2008 at the Citibank branch at 502 86th Street in Brooklyn, were made by the same individual, wearing the same "Top Gun" hat and sweatshirt as in the October withdrawals.

(Poulsen mentions that Citibank denies a breach. The USA Today article points out that the ATMs in question were not operated by Citibank, but by two other companies, Houston-based Cardtronics, and Brookfield, Wisconsin-based Fiserv. At this point, I don't think anyone has revealed what server was actually breached.)

This individual was quickly identified as Yuriy Ryabinin / Rakushchynets, and was found to have made $750,000 in fraudulent ATM withdrawals just in the month of February. How? Investigators searched Carding forums for individuals who were trading in First Bank or Citibank ATM information. One of these individuals was listing an ICQ number for contact. The ICQ had been registered earlier by "Yuri" a "29 years old male from brooklyn, USA".

A search for the same ICQ number showed that it belonged to a ham radio operator who signed his posts in Ham Radio websites with the same ICQ number. Some of those posts included photographs of Yuri in Dayton at a convention, wearing the same sweatshirt as the individual in the Washington Mutual and Citibank ATM surveillance videos.

A further search on the Ham Radio call sign that he used in these forums found that the FCC had sent him a letter, mentioning his call sign, regarding some minor administrative violations. The letter was addressed to "Mr. Yuriy Ryabinin, 679 Coney Island Avenue 2, Brooklyn, NY 11218".

A public records search found a Florida driver's license in that name, with a matching photograph. Ryabinin also had a Michigan driver's license under the name "Yuriy Rakushchynets".


Very Nice Work, Special Agent Albert Murray.

It will be interesting to see how much of the rest of the initial $5M in First Bank transactions can be identified.

You know I had to Google around a bit and find his call sign, right?

Yuriy Rakushchynets also had a hotmail account -- n2tta@hotmail.com, which he used to post a query looking for a job "within 2 hours drive of Brooklyn, NY". I have no idea what a "CQ-Contest" is, but Yuri was very active in them apparently, listed as a "fulltime operator" for events like the "CQWW SSB Soapbox", and other places giving his name and his call sign in things like:

Yuri, N2TTA, will be active as NP2/N2TTA between February 12-19th. His activity will include the ARRL DX CW Contest (February 16-17th) as NP2S and as a Single-Op/All-Band entry. Yuri informs OPDX that he will be active on CW and SSB on all bands including 30/17/12 meters.
(link.

Yeah, I guess with a couple mill of other people's money, you can buy some nice radios, eh, Yuri?
Read More
Posted in | No comments

Tuesday, 1 July 2008

July Storm Worm gives us some Love

Posted on 14:35 by Unknown
The authors of the Storm Worm must have had some good success with their "love theme" for last month's Storm Propagation Spam, because they have decided to repeat the theme today.

Right about midnight the UAB Spam Data Mine began to receive spam messages for the new Storm Worm.

After being directed to a website that looks like this:



we followed the links on the site to receive some fresh malware. How fresh was it? The executables, which were named "winner.exe" and "mylove.exe" depending on whether you follow the banner ad or the text link, were uploaded to VirusTotal where we found these results:



At our initial scan, of 33 different AV engines, only FOUR of them knew this was a virus, and only two could label it correctly. (Currently we are up to EIGHT AV products properly identifying this as storm. My university machine, which runs McAfee Anti-Virus, does not detect it with a fresh signature update.)

We have seen a wide variety of subject lines in the spam so far . . .

All I need is You
Always on my mind
Can't forget You
Can't stay away from you
Crazy in love
Crazy in love with you
Deep in my heart
Deeply in love with you
Fallen for you
For you...Sweetheart!
Hate that I love you
Here in my heart
Hold you close
I give my heart to you
I knew I Loved You
I'll never stope loving you
I'll Never Find Someone Like You
I'll Still Love You More
I Love Being In Love With You
I love you so much!
In your arms
Just you and me
Lost In Love
Lost In Your Eyes
Love me tender, love me true
Lovin' You
Lucky to have you
Madly in love
Miss you with all my heart
Missing you
My heart belongs to you
My heart to yours
My heart was stolen
Not the same without you
Only Wanna Be With You
Somebody loves you
Stand by my side
Together forever
We belong together
With all my love
With you by mi side
You are always on my mind
You are in my heart
You are my world
You are the ONE
You feel up my senses
You have touched my heart
You make my world beautiful
You make my world special

The domain names which have been used so far are:

bestlovelyric.com
gonelovelife.com
greatadore.com
knowholove.com
loveisknowlege.com
lovekingonline.com
lovemarkonline.com
loveoursite.com
makeloveforever.com
makingadore.com
makingloveworld.com
musiconelove.com
shelovehimtoo.com
superlovelyric.com
theplaylove.com
wantcherish.com
whoisknowlove.com
wholovedirect.com
wholoveguide.com

(Yes, we actually have spam samples for every one of these domains. For most we have MANY samples. That's what the Spam Data Mine does!)

All of these domains seem to be registered with Chinese Registrar "www.bizcn.com".

They use the nameservers (ns# as the prefix on each of these, ns, ns1, ns2, etc.):

likethisone1.com
lollypopycandy.com
verynicebank.com

and their own domain (ns1.wholoveguide.com, etc.)

The latter nameserver, verynicebank.com, was also used during the Beijing Earthquake version of the storm worm, described by f-secure. It served as the nameserver for "grupogaleria.cn", which was used in the attack described by F-Secure in their blog on June 19th. It also served as the nameserver for "nationwide2u.cn", although we are not yet sure of the purpose of that domain name.


We are actively seeking termination of the last few domains now (most are already down).
Read More
Posted in | No comments

Monday, 30 June 2008

19 years old and headed to prison

Posted on 13:03 by Unknown
Jason Michael Milmont, of Cheyenne, Wyoming, may be only 19 years old, but he's already a very successful cybercriminal. In this Los Angeles FBI Press Release, Milmont confessed to controlling between 5,000 and 15,000 remote victims' computers, which he infected through modified versions of Limewire, and through Instant Message spam messages which lead users to infected websites. Links he placed on MySpace and PhotoBucket were also used to spread his malware.

In January, sources such as ComputerWorld were calling Nugache a challenger to the Storm Worm for its virility, and implied that hackers "tied to the Russian Business Network" may be responible for an upgraded version. Nugache was one of the first botnets to be controlled via a Peer to Peer or distributed interface. Lacking a central Command & Control made it more difficult to identify the real controller of the network.

Milmont confessed to being the programmer -- so, it was a 19 year old in Wyoming, rather than a Russian boogie man in this case. Using a graphical user interface Milmont created, he could easily harvest the stolen credentials which the Nugache worm was gathering from his victims as they logged in to their banking and credit card sites. Infected machines could be remotely upgraded to receive new versions of the malware. The third version added the key-logging software to the malware kit.

Although Milmont harvested many credentials, he is only being asked to pay $73,866.36 in restitution, for purchases made using the stolen credit cards. Milmont shipped packages to vacant addresses where he then picked the packages up himself.

Jason studied computers at Laramie County Community College in Cheyenne. One of his instructors there, Roger Findley, described him as extremely intelligent but socially awkward.

By pleading guilty, Milmont will only be charged with a single count of a violation of 1030 (a)(4), accessing a computer without authorization with intention to defraud and obtain a thing of value. The maximum sentence to that plea would be 5 years and a $250,000 fine.

View the 22 page plea agreement here.


Links:

http://www.theregister.co.uk/2008/06/28/nugache_creator_plea_agreement/
Read More
Posted in | No comments

Saturday, 14 June 2008

Chinese Hackers hit Congress?

Posted on 07:16 by Unknown
The early news from US Representative Frank Wolf (R-VA) came out on June 11th, when Wolf submitted House Resolution 1263, calling for the Sergeant at Arms of the House of Representatives to "ensure that all Members, committees, and offices of the House are alerted to the dangers of electronic attacks on the computers and information systems used in carrying out their official duties and are fully briefed on how to protect themselves, their official records, and their communications from electronic security breaches". This is what the news story should have been -- that Representative Wolf calls for tighter security. A news-worthy and noble action, which is long overdue and would receive wide support from the Security Community.

The single line from his Resolution which has captured all of the attention came from this "Whereas" . . .


Whereas in subsequent meetings with HIR [The House Information Resources office] and officials from the Federal Bureau of Investigation, the outside source responsible for these incides was revealed to be located in the People's Republic of China;


More than 1100 news stories on Google mention the story, with some of the international mud-slinging using headlines like "US Accuses Chinese of Hacking Government Computers" which gained replies of "China says it's incapable of hacking Reps' computers".

Wolf didn't use such headlines -- the news story on his own website is headlined with Wolf Reveals House Computers Compromised by Outside Source. His office works with human rights activists and political dissidents around the world, and his emails and correspondence with some of these individuals was apparently compromised. He does say "My suspicion is that I was targeted by Chinese sources because of my long history of speaking out about China's abysmal human rights record." He also says that the Foreign Affairs Committee computers and that of other members who work "to help people who are suffering around the world" were similarly targeted.

That record is perhaps put most plainly in this impassioned speech by Representative Wolf from July 2007 -- Made in China, accuses China of poisoning toothpaste and toys, dumping products at below the cost of production on the international markets, arresting hundreds for religious beliefs and interring them in "slave labor camps", and compares their bid for the Olympics to that of the Nazis.

Wolf's words of warning on the Hill quote from several other sources as he issued his call for arms -- including a Congressional Research Service report indicating that 140 different foreign intelligence organizations regularly attempt to hack into the computer systems of US government agencies and US companies.

Joel Brenner, National Counterintelligence Executive of the Officer of the Director of National Intelligence used that figure in his speech here, and told CNN in October, it isn't just China, "there are about 140 foreign intelligence organizations trying to hack into the US government and US companies".

(Brenner also discussed the threat by the Chinese in this speech before the American Bar Association, where he says "From a purely fiscal point of view, it also means
the Chinese are leveraging the American R&D budget — your tax dollars and mine — in support of their own war-fighting capability.")

Wolf also made reference to the April 10, 2008 BusinessWeek story: The New E-Espionage Threat, which is a must read for anyone dealing with these threats both in corporate America and the government.

His reference to Shane Harris' alarming cover story of the National Journal magazine, China's Cyber Militia brings up other issues though. Is this fact? or fiction? I've had a copy of the "Northeast Blackout Report" on my hard drive for years, and am very familiar with the incident from both open and classified conversations. This is the first time that I've seen the blackout blamed on the People's Liberation Army, and frankly, I'm skeptical. Harris says:


One prominent expert told National Journal he believes that China’s People’s Liberation Army played a role in the power outages. Tim Bennett, the former president of the Cyber Security Industry Alliance, a leading trade group, said that U.S. intelligence officials have told him that the PLA in 2003 gained access to a network that controlled electric power systems serving the northeastern United States. The intelligence officials said that forensic analysis had confirmed the source, Bennett said. “They said that, with confidence, it had been traced back to the PLA.” These officials believe that the intrusion may have precipitated the largest blackout in North American history, which occurred in August of that year. A 9,300-square-mile area, touching Michigan, Ohio, New York, and parts of Canada, lost power; an estimated 50 million people were affected.


Rising to speak after Mr. Wolf, in support of his resolution, was US Representative Chris Smith (R-NJ), who used the opportunity to smear Google and Cisco, and call for support for his "Global Online Freedom" bill:


Google, for its part, has become the de facto center for China's ubiquitous anti-American, anti-Tibetan, anti-religious propaganda machine, while Cisco has made the dreaded Chinese secret police among the most effective in the world.


Like Wolf, Smith has reason to believe the attacks are sponsored by Beijing. He says:


The attackers hacked into files related to China. These contained legislative proposals directly related to Beijing, including the Global Online Freedom Act, e-mails with human rights groups regarding strategy, information on hearings on China--I chaired more than 25 hearings on human rights abuses in China--and the names of Chinese dissidents. While this absolutely doesn't prove that Beijing was behind the attack, it raises very serious concern that it was.


My conclusion is that it is clear that China is developing Cyber espionage capabilities, and it is clear that there are many attacks using Chinese IP addresses, but I have not yet seen any hard evidence that Wolf's computer was definitely attacked by "the Chinese". Even Mr. Smith's accusation indicates that the HIR staff told him "it came through or from a Chinese IP address".

That's why I refused to jump on the Evil China Bandwagon when I was interviewed by IDG News's Robert McMillan for the story he called: Weak Evidence Links Congressmen's Cyber Attacks to China. The truth is that there are many active criminal enterprises hosting "bullet proof servers" in China, which are used by a wide range of cyber criminals for all sorts of attacks. It would simplify things if we could return to a Reaganesque view of the world where all evil comes from a single location, but it takes more evidence than I have seen so far to jump on this particular bandwagon. Certainly there is a great deal of state-sponsored hacking from China, but until the details of each particular investigation are known, we can't make statements with the degree of certainty that Congressman Smith would like.
Read More
Posted in | No comments

Friday, 6 June 2008

A Romantic June Storm

Posted on 20:58 by Unknown
On June 2nd, starting at 5:53 PM, the UAB Spam Data Mine started receiving spam messages for the new version of the storm worm. The messages lead to a website titled "Who is loving you?" The "Love Riddles" web page invites you to "Just click here" to find out.



Its been four days since the new round of storm started up. How is the detection rate?

According to VirusTotal, only 6 of 32 AV engines are currently detecting this version of Storm:



What should you be looking for?

So far we've seen these email subjects:

I belong to you
I Wanna Be With You
Just you and me
Missing you
Missing you with every breath
My heart beats just for you
My heart was stolen
Nothing's Gonna Change My Love For You
Stand by my side
Together forever
We belong together
You are my world
You are the ONE
You make my world beautiful
You make my world special


Which contained a single phrase of text, followed by an IP address. Here are the Text lines in the body of the message:

Always on my mind
Can't stay away from you
Crazy in love with you
Dreaming 'bout you
Here in my heart
I want to be with you
I'll Still Love You More
In your arms
Just you and me
Lonely without you
Lost In Your Eyes
Lucky to have you
Missing you
Not the same without you
Somebody loves you
Stand by my side
Together forever
Wanna kiss you
We belong together
You are always on my mind
You are my world
You feel up my senses
You have touched my heart
You make my world special

And here are a list of some of the IP addresses we've seen advertised in the messages:

24.232.184.4
59.54.57.99
60.43.108.150
61.93.161.182
62.117.121.10
67.149.110.236 (*)
68.74.124.34
69.137.21.212 (*)
77.87.88.101
78.185.150.204
83.4.43.26
85.121.85.185
86.126.123.109
86.126.169.39
116.111.209.201
116.72.162.240
121.152.86.118
123.201.37.59
124.107.138.98
151.49.127.7
190.172.212.240
190.18.188.183
190.53.11.211
190.55.159.93
200.115.109.46
200.125.111.190
200.74.9.216
200.8.248.229
201.209.64.220
201.250.43.228
203.223.246.131 (*)
222.105.121.8

At this time, only 3 of these IPs, marked with an (*) actually delivered the malware.
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Aggrevated Identity Theft Law in Action
    There are so many interesting angles to the story this week about a case in Tucson, Arizona. The conviction actually went down in March 200...
  • More Merger Malware Wachovia Wells Fargo
    Today I received a message from Robert K. Steel, the President and CEO of Wachovia Bank. Actually I received several hundred messages from ...
  • Italian Court declares itself Friend of Pirates (or does it?)
    I couldn't believe this one. The Associated Press reported yesterday that Italian high court says file-swapping is not illegal . In this...
  • Securing Cyberspace in the 44th Presidency: Part Two
    Yesterday I provided some context for the Center for Strategic and International Studies report which was published yesterday: Security Cyb...
  • Radical Muslim Hackers Declare CyberWar on Israel
    This weekend more than 300 Israeli websites have been defaced in a period of 48 hours. In a website "defacement" a hacker violate...
  • AffPower Indictments Scare Affiliates!
    Today I heard the news that the "AffPower" drug network is being shut down, starting with 18 arrests in Texas, Florida, Colorado, ...
  • Paunch and the BlackHole/Cool Exploit Kit
    After months of speculation, the creator of the Blackhole exploit kit can be demonstrated to be in custody. As usual with all things Russia...
  • Bank of America Demo Account - DO NOT CLICK
    Beginning on November 25th, the UAB Spam Data Mine has been receiving messages claiming to be from Bank of America which will explain to us ...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile