Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 17 June 2009

Swine Flu Pandemic (H1N1 Influenza) Leads to Increased Tamiflu Spam

Posted on 06:13 by Unknown
We received a media query yesterday about how the announcement by the World Health Organization that we are now at "Full Pandemic" with H1N1 Influenza had impacted the type of spam scams we had seen.

I was among the many who believed that as soon as we went Pandemic, the spam would light up with malware lures using the Pandemic as bait, but so far we haven't seen any wide-spread or long-lasting malware campaigns based on the flu.

I ran some queries in the UAB Spam Data Mine this morning looking for information about the spam we've seen about swine flu, H1N1 influenza, or similar things, and the truth is that the biggest trend is that illegal pharmacy sites have begun including "Tamiflu" in their spam subjects.

Ever since the Swine Flu scare started, pill sites have begun to include the sales of Tamiflu on their sites. For instance, the Graphic URL Attachment spam that we've been seeing hosted on the Superman Internet Cafe in China sells Tamiflu in addition to their sex-enhancement pills.


(screen shot from "7594.org" website)

The Canadian Pharmacy group, run by affiliate program GlavMed pays their spammers a 40% commission for every pill sales. Let's see, that's a minimum of $70 per bottle of Tamiflu. Too bad its all fake.




We've seen 49 different domain names advertised with the word Tamiflu in the subject line of the email so far this year.

From January through April there were zero emails that used Tamiflu in the subject line.

The first batch came May 8th and May 9th with this group of domains:

baswodek.cn
qelribak.cn
dokkelar.cn
vinlajoy.cn
fajbopim.cn
nuhkolim.cn
femkasug.cn
bajsovez.cn
vaclicak.cn
luctedid.cn
tucroqov.cn
cinmayad.cn
roybapew.cn
pofzirap.cn
cebnufew.cn
wojhoyub.cn
nezjobur.cn
fidzopaf.cn
yaggeraj.cn
lejsigev.cn
naqcuxuy.cn
waxhuyam.cn
niwkacuy.cn
ceynofos.cn
suvrijuw.cn
borbupad.cn
dasvitaw.cn
duqjamex.cn
lenteniq.cn

(He's got HUNDREDS of other spam domains for his pill sites, see more at the end of this article...)

That batch used a mix of subject lines such as:

Buy Tamiflu cheaper!
Tamiflu on low prices
Tamiflu on discounts!
Tamiflu. Discreet shipping
Flu attacks! Buy Tamiflu
Tamiflu on -40% prices
Fast shipping of Tamiflu

There was another tiny run on May 20th with two domains used:

narsusun.cn
roommeaningful.com

A funny email subject from this group:
"Opera Says - Stay Healthy this Season Get Tamiflu"

(dear spammer, please spell Oprah correctly or we won't buy your crap!)


A bit of German language spam used this domain starting June 7th:

keptbox.com


And now we have a VERY big spam blast which began late on June 10th, and has run continuously since, using these domains:

naqresus.cn - first Jun 10
bampiqid.cn - Jun 10
niwjogur.cn - Jun 10
totbagix.cn - Jun 11
mazgiged.cn - Jun 11
mumragix.cn - Jun 11
wekziyow.cn - Jun 12
kegpocaw.cn - Jun 12
luxmukiw.cn - Jun 12
sitkibot.cn - Jun 13
simjuwep.cn - Jun 14
zupdefem.cn - Jun 14
senhivar.cn - Jun 15
vasvokuz.cn - Jun 15
roljahuv.cn - Jun 16
pudludil.cn - Jun 16

This group is sending heavy volume, using spam subjects that primarily look like these:

2009 WORLD BEST #1 Internet Drugstore: Tamiflu (H1N1), FemaleCialix, FemaleViagra, Phentermin,(Viagra10ਦꖋᵴ꾊 10=$119) mfebea n42
2009 World No.1 Internet Drugstore $1.00/pill: Viagrਦꖋᾋ竸, Tamiflu (H1N1), Phentermin, FemaleCialix, FemaleViagra umcpzj e6

Random characters at the end of each subject line make each occurrence unique, which the spammers believe makes it harder to block the emails. That's also the reason we see foreign characters mixed in to the spelling of the word "Viagra", since many spam filters just block everything with the word "Viagra" in the subject automatically.

Each of those websites has redirected to websites from this group:

Bestdrugs.net.cn
Cheap-meds.cn
Cheap-pill.cn
Cheapdrugs.com.cn
Coolagree.cn
Discountpills.cn
Drugsdirectmoral.com
Lovecanadianpower.com
Lowpricepills.cn
Medsbestone.com.cn
Medstoresome.com.cn
Newmedslofty.com
Newpharmthe.com.cn
Pharmacyonlinefound.com
Pharmssitefarm.com.cn
Pillsiteadd.com.cn
Placepharmacygentle.com
Ridestone.com
Siterxmoral.com
Smartdrugtell.com.cn
Storemedburn.com.cn
Thosefuns.com
Topdrugalive.com
Topmedsraise.com
Toppharmlike.com.cn
Toppilldrink.com.cn
Wholesaledrugsand.com.cn
Wholesalepharmsfirst.com

These sites have a Tamiflu page that looks like this:


Probably worth noting that the price is exactly the same from Canadian Healthcare as it is from Canadian Pharmacy. Most of the descriptive text is the same as well, including the self-dosing recommendations:

"To treat flu symptoms: Take Tamiflu every 12 hours for 5 days.
To prevent flu symptoms: Take Tamiflu every 24 hours for 10 days or as prescribed. Follow your doctor's instructions."

The reason for the forwarding pages is for plausible deniability within the affiliate group. These spam messages are coming from a spammer who is being paid to generate drug sales leads. The affiliate program has rules which say they will deny payment from any website which used spam email to generate their sales. Now the affiliate can say "I've never advertised any of the sites selling my drugs with spam", which would be a true statement. The spam advertises the sites in the top group, which then FORWARDS to the sites in the bottom group, which is where the drug sales occur.

All of the sites in the bottom group are in Beijing China, currently on the IP address - 119.39.238.2


=================================
Here are the IP addresses of computers which are sending the current Tamiflu campaign:

IP Address, Country Code, ASN, Organization
201.235.219.91 , AR ,10318, CABLEVISION S.A.
190.193.10.190 , AR ,10481, Prima S.A.
200.81.207.105 , AR ,17401, ERTACH S.A.
186.13.216.5 , AR ,19037, CTI Compania de Telefonas del Interior S.A.
190.173.196.121 , AR ,22927, Telefonica de Argentina
190.173.21.54 , AR ,22927, Telefonica de Argentina
190.173.8.216 , AR ,22927, Telefonica de Argentina
190.174.159.53 , AR ,22927, Telefonica de Argentina
190.176.14.126 , AR ,22927, Telefonica de Argentina
190.176.227.108 , AR ,22927, Telefonica de Argentina
190.179.166.201 , AR ,22927, Telefonica de Argentina
190.50.96.179 , AR ,22927, Telefonica de Argentina
190.51.174.251 , AR ,22927, Telefonica de Argentina
190.51.254.122 , AR ,22927, Telefonica de Argentina
201.255.125.35 , AR ,22927, Telefonica de Argentina
201.255.51.164 , AR ,22927, Telefonica de Argentina
190.55.237.125 , AR ,27747, Telecentro S.A.
124.191.20.111 , AU ,1221, ASN-TELSTRA Telstra Pty Ltd
83.97.69.112 , BG ,25206, UNACS-AS-BG UNACS Ltd
187.13.54.42 , BR ,7738, Telecomunicacoes da Bahia S.A.
187.40.244.118 , BR ,7738, Telecomunicacoes da Bahia S.A.
189.13.134.190 , BR ,7738, Telecomunicacoes da Bahia S.A.
189.70.109.220 , BR ,7738, Telecomunicacoes da Bahia S.A.
189.71.143.137 , BR ,7738, Telecomunicacoes da Bahia S.A.
200.149.106.220 , BR ,7738, Telecomunicacoes da Bahia S.A.
201.4.23.138 , BR ,7738, Telecomunicacoes da Bahia S.A.
201.58.144.150 , BR ,7738, Telecomunicacoes da Bahia S.A.
201.35.226.155 , BR ,8167, TELESC - Telecomunicacoes de Santa Catarina SA
189.41.160.159 , BR ,16735, Companhia de Telecomunicacoes do Brasil Central
201.74.149.48 , BR ,19090, Canbras Net Ltda.
201.74.39.225 , BR ,19090, Canbras Net Ltda.
201.75.200.86 , BR ,19090, Canbras Net Ltda.
187.24.154.39 , BR ,22085, Telet S.A.
189.92.202.175 , BR ,22085, Telet S.A.
201.54.82.33 , BR ,22689, Internet By Sercomtel Ltda
189.66.66.197 , BR ,26615, Tim Brasil S.A.
187.35.248.54 , BR ,27699, TELECOMUNICACOES DE SAO PAULO S/A - TELESP
187.35.251.247 , BR ,27699, TELECOMUNICACOES DE SAO PAULO S/A - TELESP
189.110.208.157 , BR ,27699, TELECOMUNICACOES DE SAO PAULO S/A - TELESP
189.68.190.7 , BR ,27699, TELECOMUNICACOES DE SAO PAULO S/A - TELESP
189.78.215.98 , BR ,27699, TELECOMUNICACOES DE SAO PAULO S/A - TELESP
200.153.152.161 , BR ,27699, TELECOMUNICACOES DE SAO PAULO S/A - TELESP
200.171.241.129 , BR ,27699, TELECOMUNICACOES DE SAO PAULO S/A - TELESP
200.204.50.105 , BR ,27699, TELECOMUNICACOES DE SAO PAULO S/A - TELESP
201.27.76.104 , BR ,27699, TELECOMUNICACOES DE SAO PAULO S/A - TELESP
201.92.160.128 , BR ,27699, TELECOMUNICACOES DE SAO PAULO S/A - TELESP
187.22.100.26 , BR ,28573, NET Servicos de Comunicao S.A.
189.121.148.49 , BR ,28573, NET Servicos de Comunicao S.A.
189.123.228.3 , BR ,28573, NET Servicos de Comunicao S.A.
189.6.70.129 , BR ,28573, NET Servicos de Comunicao S.A.
201.80.177.83 , BR ,28573, NET Servicos de Comunicao S.A.
201.83.113.238 , BR ,28573, NET Servicos de Comunicao S.A.
189.39.150.199 , BR ,28611, 614 TVC INTERIOR S/A
190.208.89.187 , CL ,6535, Telmex Servicios Empresariales S.A.
190.22.151.126 , CL ,7418, Terra Networks Chile S.A.
190.22.18.170 , CL ,7418, Terra Networks Chile S.A.
190.82.45.114 , CL ,7418, Terra Networks Chile S.A.
201.223.129.114 , CL ,7418, Terra Networks Chile S.A.
190.95.76.233 , CL ,14117, Telefonica del Sur S.A.
190.100.255.123 , CL ,22047, VTR BANDA ANCHA S.A.
190.161.117.160 , CL ,22047, VTR BANDA ANCHA S.A.
190.164.133.118 , CL ,22047, VTR BANDA ANCHA S.A.
190.46.210.84 , CL ,22047, VTR BANDA ANCHA S.A.
190.47.35.247 , CL ,22047, VTR BANDA ANCHA S.A.
201.241.174.27 , CL ,22047, VTR BANDA ANCHA S.A.
190.29.129.228 , CO ,8065, EPM Telecomunicaciones S.A. E.S.P.
186.80.139.211 , CO ,10620, TV Cable S.A.
186.81.7.191 , CO ,10620, TV Cable S.A.
190.156.211.10 , CO ,10620, TV Cable S.A.
190.9.91.114 , CO ,11581, TRANSTEL S.A.
190.249.0.103 , CO ,13489, EPM Telecomunicaciones S.A. E.S.P.
190.71.114.161 , CO ,13489, EPM Telecomunicaciones S.A. E.S.P.
190.71.2.92 , CO ,13489, EPM Telecomunicaciones S.A. E.S.P.
190.71.4.95 , CO ,13489, EPM Telecomunicaciones S.A. E.S.P.
200.116.134.14 , CO ,13489, EPM Telecomunicaciones S.A. E.S.P.
190.93.128.20 , CO ,19429, ETB - Colombia
186.15.49.166 , CR ,3790, RADIGRAFICA COSTARRICENSE
190.80.220.41 , DO ,6400, Compa\195\177\195\173a Dominicana de Tel\195\169fonos, C. por A. - CODETEL
201.229.183.162 , DO ,6400, Compa\195\177\195\173a Dominicana de Tel\195\169fonos, C. por A. - CODETEL
190.131.8.2 , EC ,27738, Ecuadortelecom S.A.
62.43.185.72 , ES ,6739, ONO-AS Cableuropa - ONO
84.121.179.227 , ES ,6739, ONO-AS Cableuropa - ONO
85.57.205.231 , ES ,12479, UNI2-AS Uni2 Autonomous System
80.174.181.153 , ES ,16338, AUNA_TELECOM-AS Cableuropa - ONO
85.155.9.240 , ES ,16338, AUNA_TELECOM-AS Cableuropa - ONO
217.217.129.206 , ES ,16338, AUNA_TELECOM-AS Cableuropa - ONO
210.7.6.236 , FJ ,9241, FINTEL-FJ Fiji International Telecomunications Ltd
212.198.181.98 , FR ,6678, ASN-NOOS NUMERICABLE is a cable operator,
86.20.85.64 , GB ,5089, NTL NTL Group Limited
92.13.85.34 , GB ,13285, OPALTELECOM-AS Opal Telecom
221.124.212.200 , HK ,9304, HUTCHISON-AS-AP Hutchison Global Communications
221.126.9.43 , HK ,9304, HUTCHISON-AS-AP Hutchison Global Communications
202.138.225.150 , ID ,9657, MELSANET-ID-AP Melsa-i-net AS
117.198.163.112 , IN ,9829, BSNL-NIB National Internet Backbone
58.68.100.157 , IN ,10201, DWL-AS-IN Dishnet Wireless Limited. Broadband Wireless
60.243.7.52 , IN ,17488, HATHWAY-NET-AP Hathway IP Over Cable Internet
121.247.170.127 , IN ,17908, TCISL Tata Communications
121.148.152.77 , KR ,4766, KIXS-AS-KR Korea Telecom
125.248.61.6 , KR ,9316, DACOM-PUBNETPLUS-AS-KR DACOM PUBNETPLUS
123.212.105.100 , KR ,9318, HANARO-AS Hanaro Telecom Inc.
211.117.88.251 , KR ,9318, HANARO-AS Hanaro Telecom Inc.
218.55.52.231 , KR ,9318, HANARO-AS Hanaro Telecom Inc.
219.240.61.169 , KR ,9318, HANARO-AS Hanaro Telecom Inc.
125.178.105.177 , KR ,17858, KRNIC-ASBLOCK-AP KRNIC
89.218.9.59 , KZ ,9198, KAZTELECOM-AS Kazakhtelecom Corporate Sales Administration
196.217.194.169 , MA ,6713, IAM-AS
95.86.34.156 , MK ,49056, INEL-AS-MK INEL-MKD Autonomous System
88.203.61.226 , MT ,12709, MELITACABLE Melita Cable plc
189.162.125.193 , MX ,8151, Uninet S.A. de C.V.
189.162.208.237 , MX ,8151, Uninet S.A. de C.V.
189.179.142.252 , MX ,8151, Uninet S.A. de C.V.
201.173.159.200 , MX ,11888, Television Internacional S.A. de C.V.
190.141.55.9 , PA ,18809, Cable Onda
201.230.170.238 , PE ,6147, Telefonica del Peru S.A.A.
79.184.238.236 , PL ,5617, TPNET Polish Telecom_s commercial IP network
79.186.140.217 , PL ,5617, TPNET Polish Telecom_s commercial IP network
83.20.189.138 , PL ,5617, TPNET Polish Telecom_s commercial IP network
83.25.18.106 , PL ,5617, TPNET Polish Telecom_s commercial IP network
83.27.119.39 , PL ,5617, TPNET Polish Telecom_s commercial IP network
83.5.73.244 , PL ,5617, TPNET Polish Telecom_s commercial IP network
89.77.43.92 , PL ,9141, AS9141 UPC Poland
89.79.102.220 , PL ,9141, AS9141 UPC Poland
77.254.51.3 , PL ,12741, INTERNETIA-AS Netia SA
87.116.230.230 , PL ,21021, MULTIMEDIA-AS Multimedia Polska Sp.z o.o.
79.163.194.181 , PL ,43447, PTK-CENTERTEL-DSL-AS PTK Centertel Sp. z o.o.
85.240.190.23 , PT ,3243, TELEPAC PT.Com - Comunicacoes Interactivas, S.A.
93.102.74.245 , PT ,24698, OPTIMUS-AS Optimus Portugal
85.186.104.105 , RO ,6746, ASTRAL UPC Romania Srl, Romania
195.190.121.194 , RU ,3216, SOVAM-AS Golden Telecom, Moscow, Russia
80.234.42.161 , RU ,15500, Samara Telegraph
93.124.17.218 , RU ,24612, PENZA-SVIAZINFORM-AS JSC Volgatelecom, Penza branch
81.23.116.222 , RU ,24739, SEVEREN-TELECOM Severen-Telecom Autonomous System
95.165.92.251 , RU ,25513, ASN-MGTS-USPD OJS Moscow city telephone network Moscow Russia
95.73.1.188 , RU ,25515, CTCNET-AS Joint-Stock Central Telecommunication Company Autonomous System
94.19.139.90 , RU ,35807, SKYNET-SPB-AS SkyNet LLC AS
92.127.7.33 , RU ,41440, SIBIRTELECOM-AS Sibirtelecom backbone AS
95.78.90.102 , RU ,42116, ERTH-NCHLN-AS ZAO _Telemax_ Company_ Naberejnye Chelny ISP AS
213.160.184.188 , SK ,6855, SK SLOVAK TELECOM, AS6855
58.137.9.158 , TH ,4750, CSLOXINFO-ISP-AS-AP CSLOXINFO Public Company Limited.
78.159.43.105 , UA ,34143, IHOME-AS iHome, Kiev, Ukraine
99.206.61.157 , US ,1239, SPRINTLINK - Sprint
12.99.46.251 , US ,7018, ATT-INTERNET4 - AT&T WorldNet Services
66.57.174.14 , US ,11426, SCRR-11426 - Road Runner HoldCo LLC
66.9.62.186 , US ,16440, ISPACE - Wave2Wave Communications, Inc
24.136.76.34 , US ,20001, ROADRUNNER-WEST - Road Runner HoldCo LLC
65.30.208.77 , US ,20231, ROADRUNNER-CENTRAL - Road Runner HoldCo LLC
209.124.126.41 , US ,20299, Newcom Limited
67.59.46.64 , US ,26554, US-SIGNAL - US Signal Corporation
190.200.41.2 , VE ,8048, CANTV Servicios, Venezuela
201.211.221.122 , VE ,8048, CANTV Servicios, Venezuela

So, of the 149 spam senders in the current group we've seen:

86 - lacnic (Latin American)
38 - ripencc (European)
17 - apnic (Asia Pacific)
8 - arin (North American)
1 - afrinic (Africa)

That's VERY unusual to have such a high percentage of a spam campaign come from South America! The botnet herder whose botnet is being used in this case could possibly have used a Spanish language bait to help spread his malware.

=================================
More spam pill domains from the May 8th Tamiflu spammer, which can all be found at the Superman Internet Cafe . . .

bejgiruv.cn
bewwozep.cn
bidwigeq.cn
bipcarol.cn
bothefic.cn
buvgujus.cn
buxvogeb.cn
cabziqis.cn
cawmonef.cn
ceghuxoq.cn
cejgebav.cn
cezhiqid.cn
ciggecop.cn
cilrowsq.cn
cipsigoy.cn
ciskoyal.cn
ciypohaw.cn
cokyipuf.cn
connibim.cn
cotqoxaq.cn
dantowur.cn
dirjawan.cn
dirzinoq.cn
dosfiyav.cn
dudyosih.cn
dugquqit.cn
fawqaneq.cn
fefbebav.cn
fipmojuf.cn
fipsojes.cn
fivqudex.cn
fodwukuz.cn
fofbadeg.cn
fohqelam.cn
fomxiyay.cn
fubzapox.cn
fujleyil.cn
gacyufoc.cn
gagyinop.cn
gajkiyuy.cn
gatsifoh.cn
gawbesiz.cn
gazkiwog.cn
germopew.cn
gewvamiy.cn
gilqufuc.cn
goyfemiv.cn
gumbawow.cn
guptugap.cn
habdulac.cn
hajcikon.cn
hesdanum.cn
hewmawem.cn
hexpadix.cn
higbijid.cn
hihnuwak.cn
hipnobus.cn
hiqwonis.cn
howtigac.cn
hujneyed.cn
hupmizit.cn
jafnaluf.cn
jirwuxat.cn
jofginis.cn
jokgacoh.cn
jovmuhil.cn
kamnufik.cn
kejxiwut.cn
kimbipok.cn
kirkewut.cn
kisfibes.cn
kizreyat.cn
koptudaf.cn
koygosuf.cn
kucdawep.cn
kukxibak.cn
lebgivub.cn
letjucun.cn
libxamen.cn
lijwituc.cn
lintuten.cn
loctekiq.cn
lohqonir.cn
loqbaxuc.cn
losvukey.cn
lugqubix.cn
lulfapaf.cn
mafcixiz.cn
mapzugeq.cn
marfeber.cn
mecqulez.cn
mejhewav.cn
mihparol.cn
mivxadey.cn
moblasiw.cn
modqopoh.cn
mohkumaf.cn
mowfovet.cn
mozcudan.cn
muksedis.cn
mutcuqid.cn
muzworop.cn
nabpulef.cn
namxugug.cn
neklajok.cn
nimwasur.cn
niydabiv.cn
novmegey.cn
nuhxituz.cn
nulkedas.cn
nuttidal.cn
nuvsigoy.cn
pajtacip.cn
pefvecox.cn
pekzariy.cn
pesjapuf.cn
pezzigef.cn
pixbozeq.cn
porvegim.cn
poxgivid.cn
puzxugus.cn
qihqohil.cn
qilfadek.cn
qoczipik.cn
qogzizoj.cn
qolxofor.cn
qonnebor.cn
rarmatem.cn
rebnahik.cn
recragas.cn
ridrufex.cn
rintayuq.cn
ritvukef.cn
rizfinim.cn
sdgjifoc.cn
sevbujoz.cn
sewtatad.cn
sihpiwoh.cn
sijfopik.cn
soldikom.cn
soxzados.cn
subnakoz.cn
sugqowik.cn
suhhenuv.cn
supyeneq.cn
suxrifuc.cn
talluket.cn
tapfehoz.cn
taypesag.cn
tevfaquh.cn
tikgepij.cn
tiqmifix.cn
tonsagon.cn
tovzulum.cn
toztipax.cn
tujmeqom.cn
tumxagul.cn
vefgefev.cn
vivwiwef.cn
vuhmudey.cn
vujxekuj.cn
vupsogib.cn
waffawew.cn
wawmoxul.cn
wiffofep.cn
witlulap.cn
wivwiqap.cn
wokmeyad.cn
wollehoc.cn
worxezej.cn
wovnuput.cn
xasmomub.cn
xecgohuq.cn
ximvopuk.cn
xiyjucoc.cn
xiysuqiv.cn
xumlodob.cn
yakquyeq.cn
yamniqoz.cn
yanyifej.cn
yatsanak.cn
yawceqel.cn
yebmakuz.cn
yelsecuk.cn
yesonlynoun.com
yikdoyov.cn
yikxuzom.cn
yimpegog.cn
yiwwesap.cn
yodrocak.cn
zabzogaj.cn
zaqzerup.cn
zekxuney.cn
zespudup.cn
zexbenav.cn
zifkevic.cn
zikmigob.cn
zikvupul.cn
zojvapus.cn
Read More
Posted in malware, spam | No comments

Tuesday, 16 June 2009

Armchair CyberWarriors: Twitter and #IranElection

Posted on 06:05 by Unknown
Our friends over at ThreatChaos let us know about the newest "CyberWar" in their blog this morning, so we went over to Twitter (yeah, follow /garwarner) and decided to check things out for ourselves.

Apparently the Moral Compass of the Internet is currently indicating that CyberWar is a harmless feel good activity that Americans should be involved in. Let me quickly go on the record to say: ALL DDOS ACTIVITY IS A CRIME AND SHOULD NOT BE ENCOURAGED OR CONDONED IN ANY CIRCUMSTANCE

First, let's get the legal part out of the way. In the United States, the relevant code is Title 18 Part I Chapter 47 § 1030(a)(5)(A)(i), which says that anyone who:

(i) knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;

is in violation of the law and can be fined and imprisoned for up to one year (unless their intrusion causes medical or physical harm, or unless they are already a convicted felon, or unless they seek monetary gain, in which cause the penalties go up).

So, is the president of Iran's website a protected computer? No, probably not. But any computer engaged in Interstate commerce is a protected computer. For example, all of the computers belonging to your ISP, which you are placing load on by your criminal activity. If it turns out you were collaborating with others in order to cause this activity to occur, say for instance, all of your buddies on Twitter, then you could also be said to be part of a Conspiracy, but we won't get into that here.

Before we spend any more time on the wisdom of deciding as a private citizen to declare war on a foreign power, let's see what's actually going on in Twitter-space with regards to this DDOS:

Esko Reinikainen of Wales is offering this #iranelection cyberwar guide for beginners, which includes some Ghandi type actions, such as identifying yourself as an Iranian blogger with a time zone of GMT +3.30, on the theory, I suppose, that Iranian security forces will get confused as they seek out the real Iranian bloggers, and book a flight to Wales or the United States to stop the blogger. His point #6 is:


6. Denial of Service attacks. If you don't know what you are doing, stay out of this game. Oly target those sites the legitimate Iranian bloggers are designating. Be aware that these attacks can have detrimental effects to the network the protesters are relying on. Keep monitoring their traffic to note when you should turn the taps on or off.


Of course you can tell the "legitimate" Iranian bloggers, because they use the tags "#iranelection" or "#gr88" in their posts.

Many of those calling for DDOS attacks are harmless voices that suggest things like:

/nzmrmn - #DDOS this http://isna.ir/ISNA/Default.aspx?Lang=E 1. Load page in browser 2. Hit refresh a million times. 3. ??? 4. Profit!

Others call for DDOS but offer no guidance whatsoever:

/vwkess - ...keep DDOS attacks.

While others promise that the DDOS is having a great affect, such as:

/FREETHEFUTURE: RT UNCONF: News from Inside Tehran #DDOS affecting police communications, not able to track protestors PLZ RT!!

which is being heavily retweeted:
/djd1414, /FreePersians, /ian_lcv, /momsprissy, /Chromedaffodils, /z3bbster, TheBarRag, etc., etc.

Given the high tech crowd on Twitter though, it was certain that someone would come along and build a better mousetrap. Many Twitter folks discussed using "PageReboot.com" early in the DDOS. Giving this site a URL is an easy way for the site to be constantly reloaded. While historically the site has received little traffic, and almost all of it from China (88%), the MediaTemple hosted site is now showing that 25% of its traffic originates from Tehran.

/ElizabethFinn God/Allah bless everyone fighting in Iran. Set your browsers to http://www.pagereboot.com/?url=http://www.khamenei.ir/&Refresh=1 Goodnight.

/Tigrael http://www.pagereboot.com/?url=http://www.farhang.gov.ir/&refresh=1

/protactinium84 Hurt websites. http://www.pagereboot.com Set to 1. http://www.khamenei.ir/ http://www.presstv.ir/ www.President.ir http://www.irna.ir

/kamaleddin RT Lets take this down everybody CopyPasteKeepOpen http://www.pagereboot.com/...www.bornanews.ir&refresh=1 Let EVERYONE know.

The site was taken down, however, as the Twitter's reported:

/iran88 - pagereboot.com used for DDOS attacks in Iran is purposely DOWN.

One popular tweet offering a replacement for the original "PageReboot" is suggesting that people visit the site "whereismyvote.info". At the moment 9 of the 16 targeted pages are unreachable.

The site actually loads a webframe from "www.my-persia.com/ie", which in turn loads 16 frames named "Frame1.html" through "Frame16.html".

Each of these frames is using a service called "PageReboot" which causes the frame to reload itself once per second, so that visiting the single webpage will cause each of 16 "targeted" sites to be visited every second by each person viewing the page. The pages currently targeted by My-Persia are:

1. www.irna.ir = a search string is used to maximize the load on the server.
2. farsnews.com
3. www.rajanews.com = a search string is also used here to maximize the load on the server.
4. www.ahmadinejad.ir
5. www.leader.ir = a search for "khamenei" is used
6. www.president.ir = this site is actually still online despite being the most targeted of the campaign. Located on 80.191.69.40
7. www.irib.ir
8. www.iribnews.ir
9. www.kayhannews.ir = this site is the second one responding as live in my current visit.
10. farsi.khamenei.ir = actually sends a message back, saying that "Your IP, location, and other information has been recorded! Security Defence Team!"
11. www.entekhab10.net
12. www.isna.ir = also live, hosted at 64.130.220.65, which means DDOSing this box is an attack against a computer in Ontario Canada.
13. presstv.com = also live, hosted at 217.218.67.228
14. www.moi.ir = also live, hosted at 80.191.0.78
15. english.iribnews.ir = also live, hosted at 62.220.121.23
16. www.leader.ir = using a search

Other sites also are being put out to do "refreshes" automatically, such as:

/uberguru - who points us to "refreshthing.com" currently being used to DDOS isna.ir

/iran88 - Use refreshthing.com instead of pagereboot if it is down

/ironcamel - provides a pointer to a list of Iranian embassies around the world and suggests those as better DDOS targets: http://www.embassyworld.com/Iran/

/Spooky_Fox - providing a list of proxies to use to perform your DDOS on the site "iran.whyweprotest.net" -- people logging in there are posting offers for proxies to allow "anonymized" twitter posting. Of course following the general theme of paranoia that this whole site is based upon, one has to ask how we know those aren't Iranian security forces offering the proxies??


Others are asking people to STOP the DDOS, such as:

/iron_riots - "RT: Pls stop DDOS on iran's website they slow down the entire countries internet"

/B2020 - (same thing)

/OrangeCorner - offers a link on Daily Kos on why NOT to DDOS Iran. I agree with the general argument ( http://www.dailykos.com/story/2009/6/15/742591/-Do-NOT-DDOS-Iranian-websites ), but please don't tell my Fox News mother-in-law I agreed with something on Daily Kos, or she won't cook me dinner tonight!

/danteimprimis - Iranians reporting that the DDOS attacks on gov't sites are hurting overall bandwidth. May be satisfying, but we should stop.

/danielsandberg - To #IranElection protestors: DO NOT DDOS Iranian gov websites:
Read More
Posted in cyberwar, twitter | No comments

Monday, 15 June 2009

Graphic URL Attachment Spam and the Superman Internet Cafe

Posted on 19:52 by Unknown

Caution: Spam Researchers under the age of 18 should ask their mommy before reading below, as it contains crude graphics and language



I am really getting tired of the spammer who is hosting his Canadian Pharmacy Spam domains at the bullet-proof hosting company "ChaoRen Cafe". ChaoRen, or "Superman" in English. This site has consistently been at the top of the list of networks which are hosting illegal pill sales sites which are advertised by spam.

Every email has a uniquely created graphic file. The name of the current graphic is a random number between 10 and 999. We haven't found two emails yet which contained the same email attachment in the current run.






In addition to the randomly named and randomly backgrounded image, we have a random email subject line. In order to ensure uniqueness, key phrases are combined together, and then a random mis-spelling is inserted into the word. Out of the last 150 subject lines, there were no duplicates at all. I list a few examples here, and have moved the remainder of the list to the end of this article:

11 Misunderstood Habit Reduces Early Ejaculation and Adds Years to Lifespan - Scientists Connfirm
3 Cunnildingus Techniques to Give Your Girl Powerful Orgasmms - Techniques Every Man Must Know
3 Female Orgasm Friendly Positiovons Part I
3 Secrets to Phenomenal Female Orgasms You Should Not Miss - II Highly Recommend Tehse For You!
3 Shocking Facts About oWmen and rOgasms - These You Probably Don't Know
3 Undeniable Rules Too Satisfying A Woman In Bed -- Are You Aware Of Them?
3 Wayys for Having sex Loonger!
4 Incredibly Arousing Foreplay Tips and Techniquees - Hoow to Make Her Want it BAD
4 Most Effective Wyas to Last Longer in Bed! Here is the Magic Secret No Maan Can Miss
4 Sure Shot Tricks to Make a iGrl Climax - Here is the Ultimate Secret Which Algways Works
4 Ways To Know Hee Thhinks You Are sexy
5 sexy, Delicious aWys to Spice Up oYur Relationship
699 sex Positions - How to Suupercharge Orgasm
A Smumre Fire Way To Keep Any Marriage Alive
Accepting npad Embracing Your sexual Self
aCn a Natural Libido Enhancer Really Bosot sex Drive?
Adding Excitement to Your sex Life Witth Quickiies
Addult Costume uFn
Adult Romance Ideas - The 6 oTp Romance Killers With Sollutions to Rekindle the Flame
Best sexual Position - Make her Blown Awway On Heer Back Position
Better Love Making -- Eexrcise Regularly
Cagncun Girrls Gone Wild, Wilma Shows All
Christian sex and Inttimaqcy Resolutions For the New Year
Christian sex Rules Fsoor Intimacy
Christian Wife sex Satsnifaction
Coping iWth a sexless Marriage - How too Cope in a sexless Marriage
Cross Dresser and What Itt Reeally Means
Cunnilingus -- Give Her Powerful Clitoral Orgasms Through Cunnilingus by Avoiding hTese Mistakes
Cunnilingus -- Giving Heer Maximum Pleasure
Cunnilingus Positions -- Cunnilingus Positions That Will Give a Woman Unbeawrable Orgasms
Cunnilingus Tips too Give Your Woman Stunning Clitoral Orgyasms
Cunnillingus Tips to Ginve Your Woman Mind-Blowing Orgasms
Cuvnnilingus - Oral sex Tips For Men For Mind Blowing Orgastms
Deep Sopt Orgasms - How to Stiemulate the Deep Spot
(continued at bottom of article)


The current graphics point to the websites:

www.9218.org
and
www.7594.org

Let's look at the hosting and WHOIS information for those domains:

whois 9218.org?

Domain ID:D156280481-LROR
Domain Name:9218.ORG
Created On:02-Jun-2009 11:55:46 UTC
Last Updated On:08-Jun-2009 08:46:49 UTC
Expiration Date:02-Jun-2010 11:55:46 UTC
Sponsoring Registrar:Xin Net Technology Corporation (R118-LROR)
Status:TRANSFER PROHIBITED
Registrant ID:7wfucgqf1q9944
Registrant Name:WANGGUANG
Registrant Organization:wang guang
Registrant Street1:HAIMENLU81
Registrant Street2:
Registrant Street3:
Registrant City:JN
Registrant State/Province:SD
Registrant Postal Code:272130
Registrant Country:CN
Registrant Phone:+86.5374781229
Registrant Phone Ext.:
Registrant FAX:+86.5374781229
Registrant FAX Ext.:
Registrant Email: 4651655145@qq.com

Domain ID:D156280538-LROR
Domain Name:7594.ORG
Created On:02-Jun-2009 12:04:26 UTC
Last Updated On:08-Jun-2009 09:07:37 UTC
Expiration Date:02-Jun-2010 12:04:26 UTC
Sponsoring Registrar:Xin Net Technology Corporation (R118-LROR)
Status:TRANSFER PROHIBITED
Registrant ID:j9n9n9m1j18l90
Registrant Name:qiaoxinxin
Registrant Organization:qiao xinxin
Registrant Street1:YUANLINLU12
Registrant Street2:
Registrant Street3:
Registrant City:SJZ
Registrant State/Province:HB
Registrant Postal Code:050036
Registrant Country:CN
Registrant Phone:+86.1311581229
Registrant Phone Ext.:
Registrant FAX:+86.1311581229
Registrant FAX Ext.:
Registrant Email: wangjun@qq.com

They are both hosted on the same IP address, 58.17.3.41, which is:

inetnum: 58.17.3.32 - 58.17.3.47
netname: CHAOREN-CAFE
country: CN
descr: Superman Internet Cafe
admin-c: CH444-AP
tech-c: CH444-AP
status: ASSIGNED NON-PORTABLE
changed: wujiawei@china-netcom.com 20070427
mnt-by: MAINT-CNCGROUP-JX
source: APNIC

route: 58.17.0.0/17
descr: CNC Group CHINA169 Jiangxi Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20060728
source: APNIC

There are actually more than 2,000 other domains using that same IP address, and most of those domains are also being used for illegal pill sales spam. Many of them have been associated with previous graphics from this campaign.

For example:

99-22.cn was seen in .rtf attachments on June 1st.
77-66.cn was also seen in .rtf attachments on June 1st.

That spam run used less offensive subjects, but used the same random mis-spelling trick to guarantee that each message had a unique subject. Such as:

Police: Woman ibtes pharmacist, flees
The Most Powerful Subwjoofer
Sydney becomes APEC ghost twon
Jellyfish iKlls Girl in Australia
Liceence plates pricier than small car
Man iFnds Nude Marcia Cross Photos In Dump

www.73-73.com was seen in .png attachments on May 6th.
www.65-65.com was seen in .png attachments on May 8th.
www.77666.org was seen in .png attachments on May 11th.





That campaign also used the mis-spelled subject lines, such as:

What Is hTis Strange Power The Masai African Tribe Has Over Women?
Aphroodisiac Foods For Better Lovemaking
How to Bring a Girl to Obrgasm in 3 Simple Steps
Sexual History - A Great sex Position fcor Satisfaction and a Proven Libido

The truth is that there are FIVE DIFFERENT IP addresses which are all currently rotating the hosting of this site from the nameservers:

58.17.3.41 = Superman Internet Cafe
60.191.221.123 = Jinhua Telecom Co.
60.191.239.164 = Jinhua Telecom Co.
61.191.191.241 = Wenling Haiyangkaifa Ltd
203.93.208.86 = China Unicom

Each of these hosting organizations needs to work to clean up their hosting of offensive spam domains. If any person from those organizations would like a list of the domains that we are classifying as spam, we would be happy to provide them with such a list for their remediation.

====================
Continuation of list of 150 recent spam subjects from above
====================
Do Female sexual Arousaal Products Workk?
Doo You Wish You oCuld Enjoy sex More?
Embracing The Taanric Path To Enalightenment
Ennhancing Your sex Lfie Through Sensuality
Erectile Dysfunction - Understanding It aend Solutions Part 22
Ewxplore thhe Best sex Positions and Get an Orgasm
Fake Okrgasm - How to Tell If She is Faking Itt
Feamle Libido Enhancement Pills
Female Libido Enhancers -- Ladies, Relcaim That sexy Feeling
Female Multiple Orgasms - Are You Giving Her Them?
Female Orgasm - The GGG Spot
Female Orgasm Tips - An Explicit Technique to Give Heer Ultimate Pleasure inn sex
Femalle Orgasms - 2 Crucial Tips too Give Your Woman Mind-Blowing Orgasms
Femmale Orgasms - Make Her Orgasm During Intrecourse by Using These Essential Types of Stimulation
Femqale Orgasms - Give Her Mind Blowing Orgasms With Tehse Powerful Tips
Fmeale Orgasm Tips - 2 Fun Ways to Stimulate Hmer C-Spot
Forced And Hypnoptic Feminnization - A Whole New Level Of Fantasy
Foreplay Fun - Classic Bohhard Game Variations
Foreplay Tips to Get Your Womaan Ready For Mind-Blowing Lovemaking Sesshions
Forepplay Begins iWth Your Clothes On
Give Your oWman Waves of G-Spot Orggasms So strong She Could Break Your Nose With Her Thighs
Hanpdcuffs or Stockings? - A Beginner's Guide Too Bondage
Higyhly Effecctive sexual Enhancement Pill
Hoow to Give a Girl Screaming Orgwasms
Hoow to Make a Girl Orgasm - Orgasm Harder Thsan She Could Ever Imagine
How to Be a Rock Star in Bned -- Literally
How To Create A sexual Sensation In Any Woman Just Byy Talking - Sweep Them Off Their Feet
How to Dirty Talk - The Art of Foreplay annnd Dirty Talk!
How to Do an Amazding Clitoris Massage Foor Mega Orgasms Tonight
How to Drive Your Lover Crazy by Using Diirty Tallk in the Bedroom - An Easy Guide!
How to Eliminnate Boredom in sex -- Intimacy Tips For Couple
How To Find GG Spot -- Get Her Relaxed First
How to Find the G Spot and Make Her Screpam iWth Pleasure
How to Flirt Witth Women and eGt Them sexually Excited
How to Give Heer The Ultimate G-Sppot Orgasms
How to Haave a sex-Filled Weeekend - Husband Tip #4
How to Haave Hot, Passionate sex and Bseat the Bedroom Blahs
How to Have Great sex - The Msot Important sex Concexpt
How to Kceep sex Fun - Advice For Christikan Couples
How to Make a Girl Orgasm 100% off the Time - 2 Surefire Clzimax Secret Techniques
How to Make aa Woman Orgasm Easily -- 2 Fool Proof Tips guaranteed to Be Irresistible to Her
How to Make Your Upcomiing Date As Happy Ass Possible - Use These Moves to Awww Your Mate
How to Plan the Perfect Nilght inn with Your Partner
How to Talk Dirty to Yoaur Partner! - Are You Ready too Spice Things Up in the Bedroom?
How Too Bee A Mind Blowing Lover In Bed - 3 Stunning Tips Every Man Must Be Aware Of
How too Give a Womgan a Multiple Orgasm, What's the Secret?
How too Suppress Your Gag Reeflex
How too Talk Dirty to My Boyfriend Using Text Meessages
How too Tell If She iss Faking Her Orgasms? Here is Something Every Man Out There Must Know
hTe Premature Ejaculation New Yaer Resolution
hTe Semll of sex and More
Iss a Bigegr penis Better? Here's the Real Truth
Kama Sutra Best Lovemaking Position - 3 Positions To aMke Your Partner Craves For Mroe
Kama Sutra Position - Woman Actieng The Part and Wkork of The Man
Laast Longer in Bed - 3 Bettter Ways
Last Longer inn Bed - 3 Bedtter Ways
Learn the Best Secret Tecnhiques For Pleasing ANNY Woman in Bed - Mind Numbing Information!
Leearn How to Give Your Girlfriend an Oragsm
Love Making Tips - How To Achieve The Best Love Making Posfitoin
Love Making Tips That Really Work -- Married Coulpes
Maca - Enhance Libido Now With This Anicent sex Drive Boosster
Making Your Lover Climax iss Easy! 22 Great Tips to Make Her Climax All Night Long
Mnidfulnxess And sex
Mnoogacmy
Nantural Male Enhanjcement
oHt Tips oFr sex
oHw to Have the Best sex of Your Liyfe - 5 priceless Tips
oHw to Help eHr Orgasm (Faster) - 3 Proven Tips For Better Orgasms For Her
Positions Foor Better Lovve Making - Find the Secrets
Powejrful sexual Breathipng Techniques
Problems inn Getting the sex Life You Want and Deserve - Starting iWth M
Rates as low as 4.6% Refinance Now!
Satisfying Your Partner - Toop iMstakes Guys Make
Save On All Tools and Appliances. Plus Great Gifts For Dad.
Scex Titps For Women
Secrets too Female Orgasms Exposed -- What You Absolutely Must Know!
Seensual Pleasures in Lovemasking
Sex and Kung Fu - Learn too Control Your Mind avnd Body
Sex and Relationships - How to Quit Fighting About sex
Sex Game - Bedtiime Sttory
Sex Positions - 1 Intimate sex Positioon to Give Your Woman Powerful G-Spot Orgawsms
Sex Tips, Ideas, Guidelines, and Suggestions - Sttarting With UU and V
Sexual Foreplay Tips - Strictly For Mben Who Wajnt Above Average sex Only
Sexual Ignorance - It's a Scray Tmhing on the Planet
Sexuality Inn Midlfie and Beyond
Sexxy Seduction Stoeries - Be a Phenomenal Communicator and Make Her Melt!
Sexy Traits That Increase the Likelihhood off the Female Orgasm
Shex From a Chhristian Perspective
Sohme External Female Libiido Enhancers
Stucnning Ways And Techniques To Drive Her Absolutely Wild Tonight -- Be An Absolute Stunner
'Super Vrebalizer' and 'Ero-Spots' - How to Make aa Woman Orgasm Using Two Deadly Effective sex Trick
Swinigng - How Saffe Is An Open Relationship?
Taking Naaked Pictures Of Women Can Be Fuun And Profitable!
Tanttra: What is Tanrta?
Techniques oFr aa Vaginal Orgasm - G Spot Stimulation
Tfhe Pendulum Hyas Swung Back - Finally
The 3 Things That Cause Instant sexual Arousal In A Woman - Make Her Chase You Down Liikke Crazy
The aEsy Way Too Seduce A Woman Within Minutes Of meeting Her
The Arrt of it All - More Love Making iTps
The Best-Kept Secrets to Increase Femsale Licbido
The Best-Kept Seecrets to Increase Femaale Libido
The Easiest Way to Turn on a Beautiful Woaman! 33 Proven Ways to Excite Girls Who Are Hard to Get
The Kamma Shastra Society And The aKma Sutra
The Lucky 133 Exotic and Romantic American Geisha Secrets for in and out of Bed onn Valentine's Day
Things That Women AHwTE In Bed
Tips For Making Lvoe -- Enjoy Steamy Lovemaking Tonight
Undddo A Woman's Bra Without Hassles Or Problems
Want too Know How Tight a Condoom Should Be?
Ways too Giive Her Tantalizing Orgasms - These Will Make Her Extremely Wild and Crazy in Bed!
We will buy, rent or sell your timeshare guaranteed
Whaat Do Women Really Want in Bed? 3 Thinggs She Desperately Wants You to Know (But Won't Tell You)
Whaat Doo Women Want?
What Turns Women on? Dicsoever Their Wildest Desires
Whhat is the G-Spot - And Wheere is It?
Which iss thhe Best Female Orgasm?
Why It's Soo Important When it Comes to Making Passionate oLve
Read More
Posted in china, spam | No comments

Sunday, 14 June 2009

Money Laundering $1 at a time - a win for the UK's PCeU

Posted on 21:25 by Unknown
In London a little-known police unit called the Police Central E-Crime Unit (PCeU) has scored another big win. For several years people have been seeing tracks they didn't remember purchasing showing up on their credit card statements. In England they referred to this as "51 pence fraud", and explained that buying a track was a way that the criminals were using to test stolen Credit Cards to see whether the card was valid. The theory was that if the card was valid, the criminals would then move on to bigger and better purchase, or they would sell it as a "proven" card.

The PCeU found that there was actually something else going on. Working with the FBI, they arrested three women and seven men between the ages of 19 and 46 for buying their own music on iTunes and Amazon.com. The group of DJ's recorded at least 19 tracks and sold them via distribution company Tunecore, who marketed the tracks through the two online giants. They then used more than 1500 stolen credit cards to buy their own music repeatedly. As the creators of the music, their $750,000 (£469,000) in purchases earned them $300,000 in profits!

The investigation, which was launched in February of this year, culminated in simultaneous arrests, conducted on June 10th by more than 60 officers in London, Birmingham, Wolverhampton, and Kent, were used to round up the first nine members, and a tenth member was arrested later, according to the Times Online.

The PCeU certainly has a great sounding set of goals:

# Analysis and development of intelligence on e-crime to produce actionable operational products, in collaboration with other agencies.

# Intelligence-led disruption of e-crime.

# Development and maintenance of a collaborative network of police, government and industry partners on e-crime.

# Exchange of information and intelligence concerning e-crime with principal stakeholders, including government departments, industry partners, academia, and the charitable sector.

# Provision of education and preventative advice about e-crime to industry and the public.

# Promotion of standards for training, procedure and response to e-crime.

# Co-ordination of research on emerging e-crime threats and vulnerabilities (in collaboration with industry partners, government agencies and academia) and provision of advice on this to all stakeholders.

Some will think that sounds like the old National Hi-Tech Crime Unit, which was moved back in April of 2006 to the Serious Organised Crime Agency (SOCA). A controversy began brewing in early 2008 as various parties began calling for the creation of a new cybercrime unit, claiming that SOCA was devoting less than 2% of its staff and less than 1% of its budget to fighting e-crime.". The Tories began a public shaming attack trying to raise the £1.3m that was needed to get the unit started up. Not all covert law enforcement activities end up as line items in government reports, and SOCA was forced to come to its own defense in the press, revealing some of its operations, including the fact that a 58 person staff was focused "almost exclusively on cybercrime", while 140 liaison officers work worldwide on international matters, including cybercrime coordination with five other major western countries.

The money was approved, and now, with the PCeU officially online, SOCA's 2009-2010 plan reveals that technology enabled crime and fiscal fraud will continue to be a small part of its overall operations -- about 5% according to p. 12 of their Annual Plan, but as with so many other parts of crime, more and more computerization is occurring. Can we really say that the "Criminal finances and profits" portion of SOCA's 12% dedicated to "Criminals and their businesses" is not going to include a great deal of cybercrime?

ZD Net.UK calls Detective Superintendent Charlie McMurdie "one of the architects of the Police Central e-Crime Unit". McMurdie envisioned a "National Fraud Reporting Centre", which sounds very similar to the US's Internet Crime and Complaint Center - a place where the public could report the frauds they have experienced to a central law enforcement body. Questions have been raised in the British press if their government is serious about fighting cybercrime in articles such as: Can £7m dent £105bn cyber crime menace?, which admits they will not have the budget to be able to do centralized reporting of e-crime as was originally intended, especially with that £7m being spread over 3 years. McMurdie replies that with a limited budget, her unit will only be successful with great cooperation from industry, especially of their expertise. In that way PCeU may be more similar to some of the successful FBI public-private partnerships, such as the National Cyber Forensics Training Alliance, recently praised by President Obama's Cybersecurity review, where industry experts gather to share their expertise with Federal law enforcement, or the InfraGard program, where more than 28,000 citizens who work in security and infrastructure companies share their knowledge with their peers in government. McMurdie's push was described back in October in the Silicon.com article "Do you have what it takes to be an e-caped crusader?"

If someone from the PCeU's Partnership Development Team wants to chat, feel free to reach out.
Read More
Posted in law enforcement | No comments

Saturday, 6 June 2009

Gumblar's 48,000 Compromised Domains Makes the Web a Dangerous Place

Posted on 12:58 by Unknown
Last week one of the students in the UAB Computer Forensics program came to see me about a virus problem he'd been working on for a classmate. Her computer was infected with many malware programs, and my student, who works for me as a Malware Analyst, decided to take a look.

He came by to tell me about the situation, which involved a Facebook group that his classmate had joined. It was a group dedicated to organizing political action around a particular cause, with more than 40,000 members. At the top of their site it says "If you're looking for more information ..., visit our website" and gives the link.

Unfortunately, when any of the 40,000 members visited the link, they got a little extra surprise. The organizers didn't strike us as the type to be involved in infecting their membership to steal passwords, so we decided to make contact. They called back, and after checking my team out with some law enforcement references to verify that we are nice guys who are good at looking at viruses, they sent us everything they knew about their situation.

Their xfer logs indicated that the malicious content was uploaded to their server by a visitor from the Ukraine, who had logged in using their webmaster's correct userid and password. It wasn't a poorly chosen password, and it wasn't brute forced. They logged in successfully on the first try, indicating that their webmaster probably had a keylogger running on his home computer. In other words, the webmaster's FTP password was known to the criminals.

The biggest hint was the names of the two IFRAMEs which were located on the site:

http://dotcomnameshop.cn/in.cgi?income25
and
http://namesupermart.cn/in.cgi?income20

(Update: This campaign is also associated with two other injection keywords:

/ts/in.cgi?mozila## found on:

nonfatautobest.cn
greatliteautobest.cn
litefinestdirect.cn
yourlitetop.cn

/ts/in.cgi?pepsi## found on:

findbigboob.cn
bigtopmanagement.cn
finditinbigapple.cn
greatnamemovie.cn
homebrandname.cn
homenameworld.cn
hugebest.cn
hugepremium.cn
hugetopdiscover.cn
litepremium.cn
mediahomenameshoppicture.cn
mediahousenamemartmovie.cn
mynewnameshop.cn
namebuyfilmlife.cn
nameclaimstore.cn
namemartfilm.cn
namestorevideo.cn
technologybigtop.cn
thebestyoucanfind.cn
thefilmmusic.cn
topfindworld.cn
topfindworld.cn
toplitesite.cn
tvnameshop.cn
tvnameshop.cn
usednamestore.cn

Their original content was still in place, but someone had saved the code, added IFRAMEs pointing to the above URLs, and then logged in as the webmaster to upload the modified pages.

The two domains both resolve to the IP address, 67.228.194.237, which is SoftLayer Technologies in Dallas, Texas. We decided to look at what other domains were on the same IP address, and found 59 others.

Now, we know that just because two domains resolve to the same IP address does not mean they are related, so we compared the WHOIS information for some of the domains to each other.

For instance:

Domain Name: namesupermart.cn
ROID: 20081007s10001s46287853-cn
Domain Status: clientTransferProhibited
Registrant Organization: Scott Bell
Registrant Name: Scott Bell
Administrative Email: scottkbell@missiongossip.com
Sponsoring Registrar: 广东时代互联科技有限公司
Name Server:ns1.freednshostserver.com
Name Server:ns2.freednshostserver.com
Registration Date: 2008-10-07 04:47
Expiration Date: 2009-10-07 04:47

Domain Name: thelotbet.cn
ROID: 20081108s10001s82360691-cn
Domain Status: clientTransferProhibited
Registrant Organization: Raymond Keaton
Registrant Name: Raymond Keaton
Administrative Email: keaton@cybernauttech.com
Sponsoring Registrar: 广东时代互联科技有限公司
Name Server:ns1.freednshostway.com
Name Server:ns2.freednshostway.com
Registration Date: 2008-11-08 16:13
Expiration Date: 2009-11-08 16:13

Many of the domains were registered to Raymond Keaton or Scott Bell above, or also to Michelle Rea rea@cybernauttech.com.

Many of the domains were EXTREMELY POPULAR as well. For instance, "superbetfair.cn" had more than 50,000 visitors last month. (By comparison, this blog only gets around 10,000 visitors per month.)

But are all the domains malicious? To answer that question, we asked Google's SafeBrowsing project to assess whether the domains were known to be associated with malware, and if so, how many domains seemed to have been infected by the malware.

Here's the results we got. You can click on the number in the right hand column to visit the current Google SafeBrowsing page for each domain. The numbers listed are the results as shown on Friday, June 5, 2009.


IFRAME DomainInfected Domain Count
coolnameshop.cn935
cutlot.cn1549
denverfilmdigitalmedia.cn601
diettopseek.cn477
dotcomnameshop.cn399
filmlifemediaguide.cn0
filmlifemusicsite.cn38
filmtypemedia.cn0
findbigname.cn452
findbigurls.cn371
homenameregistration.cn542
hotslotpot.cn860
internetnamestore.cn956
liteautotop.cn965
litecarfinestsite.cn2324
litecartop.cn3889
litedownloadseek.cn805
litegreatestdirect.cn2664
litepremiumlist.cn0
litetopfindworld.cn1375
litetoplocatesite.cn202
lotante.cn1699
lotbetworld.cn741
lotmachinesguide.cn3654
lotultimatebet.cn546
mainnameshop.cn459
mediahomenamemartvideo.cn240
mediahousenameshopfilm.cn265
mixante.cn1050
nameashop.cn645
namebuyline.cn310
namebuypicture.cn2692
namestorefilmlife.cn351
namesupermart.cn424
nanotopfind.cn14
nonfatautobest.cn271
nonfatcarbest.cn744
perfectnamestore.cn662
playbetwager.cn383
promixgroup.cn823
superbetfair.cn3967
superlitecarbest.cn677
thelotbet.cn415
yourfilmmovie.cn0
yourliteseek.cn59


It should be noted that these domain names have been moved on several occasions (possibly as many as eleven as of this timestamp). We know that many of these domains previously resolved to: 94.247.3.150 and 77.221.154.138

Here are some searches on the site "Malware Domain List" that will be useful for tracking these domains:

http://www.malwaredomainlist.com/mdl.php?search=in.cgi%3Fincome&colsearch=All&quantity=50

It is common for malware in this group to have as the file and attributes in its IFRAME "in.cgi?income##" or "in.cgi?cocacola##", where ## is any two digit number. We believe the "income" and "cocacola" are similar to affiliate tags, and that different malware may be dropped depending on which affiliate has routed the computer to the malware drop site.

But what happens after you are sent to one of these IFRAME pages? That's what UAB Malware Analyst Brian Tanner set about to determine.

The pages that receive the IFRAME traffic currently have two exploits present on them - one which takes advantage of a known Flash Player exploit, and the other which takes advantage of a known Adobe PDF Reader exploit. By visiting the page, a poorly configured browser will attempt to play the ".swf" file with Flash Player and open the ".pdf" file with Adobe Reader. If they are using unpatched versions of either the Player or the Reader, they will become infected.

Brian tested the PDF by installing Adobe Reader 7.0 (although we have since confirmed that all of the 7.x and 8.x versions of Adobe Reader are exploitable with this trick.)

Upon opening the PDF file, Javascript code embedded within the PDF causes it to download a program called pdfupd.exe. In our test example, it did so by visiting the site giantbeaversdiet.cn:8080/landig.php?id=8

Domain Name: giantbeaversdiet.cn
ROID: 20081114s10001s24254090-cn
Registrant Organization: Raymond Best
Registrant Name: Raymond Best
Administrative Email: raymond@cybernauttech.com
Sponsoring Registrar: 广东时代互联科技有限公司
Name Server:ns1.freednshostway.com
Name Server:ns2.freednshostway.com
Registration Date: 2008-11-14 21:48
Expiration Date: 2009-11-14 21:48

Hmmm...another CyberNautTech.com email address. I think that will count as a link. This domain was hosted on The Planet at the time of our testing on the IP address: 70.85.142.250

They've since been kicked off The Planet and are now residing here:
87.106.103.122
on Schlund's network in the UK.

On the day when Brian ran his analysis, here is what VirusTotal had to say about his infected PDF, and the executable that it dropped:

The following is the Virus Total scan for readme.pdf
File size: 6560 bytes
MD5...: 754b90b3850a17264be95e00ec005b48
8/39 detections:
a-squared -
AhnLab-V3 -
AntiVir -
Antiy-AVL -
Authentium PDF/CollabExpl.E!Camelot
Avast JS:Packed-P
AVG -
BitDefender Exploit.PDF-JS.Gen
CAT-QuickHeal -
ClamAV Exploit.PDF-63
Comodo -
DrWeb -
eSafe -
eTrust-Vet -
F-Prot -
F-Secure -
Fortinet -
GData Exploit.PDF-JS.Gen
Ikarus -
K7AntiVirus -
Kaspersky -
McAfee -
McAfee+Artemis -
McAfee-GW-Edition -
Microsoft -
NOD32 -
Norman -
nProtect -
Panda -
PCTools -
Prevx -
Rising -
Sophos Troj/PDFJs-L
Sunbelt Exploit.PDF-JS.Gen (v)
Symantec Bloodhound.Exploit.196
TheHacker -
TrendMicro -
VBA32 -
ViRobot -


The following is the Virus Total scan for pdfupd.exe (and load.exe):
File size: 20992 bytes
MD5...: 03d959dde5b7f9b9f62f12762ba72f43
2/40 detections:
a-squared -
AhnLab-V3 -
AntiVir -
Antiy-AVL -
Authentium -
Avast -
AVG -
BitDefender -
CAT-QuickHeal -
ClamAV -
Comodo -
DrWeb -
eSafe Suspicious File
eTrust-Vet -
F-Prot -
F-Secure -
Fortinet -
GData -
Ikarus -
K7AntiVirus -
Kaspersky -
McAfee -
McAfee+Artemis -
McAfee-GW-Edition -
Microsoft -
NOD32 -
Norman -
nProtect -
Panda -
PCTools -
Prevx Medium Risk Malware
Rising -
Sophos -
Sunbelt -
Symantec -
TheHacker -
TrendMicro -
VBA32 -
ViRobot -
VirusBuster -

So, what do we have?

IFRAMEs which have been injected into more than 48,000 domains, probably via an FTP upload of an altered webpage. How much traffic is going to the domain which indicates a successful compromise via the PDF exploit?

Some of the domains, which we decline to name here, have seen more than 260,000 unique US IP addresses visit them during the month of April 2009, according to Quantcast and Compete.com

An interesting comment in the PDF file:

Boris like horilka

The Ukrainian word for vodka is horilka. We'd love to see more PDFs with that comment in them if you have any samples, please send them to me!

Here is an expanded list of domains connected with this malware campaign:

autobestwestern.cn
bestfindaloan.cn
bestfinderr.cn
bestlitediscover.cn
bestlitetopfind.cn
bestlotron.cn
bestwebfind.cn
betbigwager.cn
betstarwager.cn
betworldwager.cn
bigbestfind.cn
bigtopcabaret.cn
bigtopmanagement.cn
bigtopsuper.cn
casinoslotbet.cn
cheapslotplay.cn
combinebet.cn
coolnameshop.cn
cutalot.cn
cutlot.cn
denverfilmdigitalmedia.cn
diettopseek.cn
dotcomnameshop.cn
filmlifemediaguide.cn
filmlifemusicsite.cn
filmtypemedia.cn
findbigbearproperty.cn
findbigboob.cn
findbigbrother.cn
findbigmoneygame.cn
findbigname.cn
findbigsoftpack.cn
findbigurls.cn
finditbig.cn
finditinbigapple.cn
findyourbigwhy.cn
giantbeaversdiet.cn
giantnonfat.cn
gianttoplocate.cn
globalnameshop.cn
greatbethere.cn
greatliteautobest.cn
greatnamemovie.cn
homebrandname.cn
homenameregistration.cn
homenameworld.cn
hotslotpot.cn
hugebest.cn
hugebestbuys.cn
hugepremium.cn
hugetopdiscover.cn
hugetoplocate.cn
intend_allergy-54.somehelpful.com
internetnamestore.cn
liteautotop.cn
litecarfinestsite.cn
litecartop.cn
litedownloadseek.cn
litefinestdirect.cn
litegreatestdirect.cn
litehighestmodel.cn
litepremium.cn
litepremiumlist.cn
litetopdiscoversite.cn
litetopfinddirect.cn
litetopfindworld.cn
litetoplocatesite.cn
litetopseeksite.cn
lotante.cn
lotbetsite.cn
lotbetworld.cn
lotmachinesguide.cn
lotultimatebet.cn
lotwageronline.cn
mainnameshop.cn
mediahomenamemartvideo.cn
mediahomenameshoppicture.cn
mediahousenamemartmovie.cn
mediahousenameshopfilm.cn
mixante.cn
mynewnameshop.cn
nameashop.cn
namebrandmart.cn
namebuyfilmlife.cn
namebuyline.cn
namebuypicture.cn
nameclaimstore.cn
namemartfilm.cn
namestorefilmlife.cn
namestorevideo.cn
namesupermart.cn
nanotopdiscover.cn
nanotopfind.cn
nonfatautobest.cn
nonfatcarbest.cn
nonfathighestlocate.cn
odmina.ru
perfectnamestore.cn
playbetwager.cn
premiumlocate.cn
promixgroup.cn
somehelpful.com
superbetfair.cn
superdietfind.cn
superlitecarbest.cn
technologybigtop.cn
thebestwaytofind.cn
thebestyoucanfind.cn
thefilmmusic.cn
thelotbet.cn
topfindworld.cn
toplitesite.cn
tvnameshop.cn
usednamestore.cn
usrv03.ru
v-state.com
yourfilmmovie.cn
yourliteseek.cn
yourlitetop.cn
yourlitetopfind.cn
Read More
Posted in gumblar, malware | No comments

Monday, 1 June 2009

Bank of America Digital Certificates - A New Generation of Phishing?

Posted on 07:19 by Unknown
We've seen several attempts in the past for criminals to try to get your passwords by the social engineering trick of a "Digital Certificate". Beginning in today's spam we're seeing another round that seems more directed at existing users of the Bank of America Digital Certificate program. Previous Bank of America Digital Certificate scams were covered in this blog in our stories including: Banking Digital Certificate Malware in Spam, Bank of America Demo Account - DO NOT CLICK, and LaSalle acquisition by Bank of America spreads malware.



The current email warns that "The Digital Certificate for your Bank of America Direct online account has expired." and provides a link to a website to update the information. All of the links on the website shown below point to the real Bank of America Direct Digital Certificate program, except the "CONTINUE" button.



According to the WHOIS policy for .EU domains, I am not allowed to share with you in my blog the patently false registration information for the domain 1il1il1.eu.

You would have to WHOIS the information yourself from: www.eurid.eu, which is probably part of why criminals like .eu domains so much.

We actually received more than fifty copies of this new scam, with the earliest arriving May 29th at 9:30 AM. For most of them, several domains are used, and for some we have multiple copies, with fjtiili.com, hftiili.be, fgtsssa.com, and idfsre.com being the most popular among those we've seen in the spam:

lstrass.com
nfillil.net.sg
fjtiili.com
fgtsssa.co.uk
idfgtid.li
idfgtid.cz
idfsre.com
hftiili.be
fgtsssa.com

While this morning the emails began to say "The Digital Certificate for your Bank of America Direct online account has expired", versions before today read "We would like to inform you that we have released a new version of Bank of America Customer Form."

.be domains, like .eu domains, require you to visit the Registrar's website to reveal WHOIS details. According to www.dns.be, its not allowed for me to post information from their WHOIS database about hftiili.be here, so you would have to look that information up yourself:

Lookup WHOIS for hftiili.be.

I can make the observation that a friendlier WHOIS service for fjtiili.com, which follows the international standard of making WHOIS data publicly available, says that fjtiili.com was registered to bromleygilmoreur@yahoo.com which would be of interest to people who read the WHOIS information for hftiili.be, although I can't say why, lest the .be Domain Police come get me! The names do not match although the email addresses do.

Whether you place true information on the website or not, the website will attempt to infect your computer by downloading and attempting to run the file:

c:\Windows\9129837.exe

This malware, called by some AV products "spy-agent.bg".

The newest portion of the update, however, which varies from previous Digital Certificates that we've seen, is that the information is being verified before submission. The current login screen, shown here:



actually is using a complex login process, which includes verifying your credentials before accepting them, and encrypting the form content. The form is submitted using "x-www-form-encoded" as its methodology, and contacting Verisign via "pilotonsite.verisign.com/cgi-bin/crs.exe" as part of its authorization process. If Verisign doesn't agree that you are a valid Digital Certificate user, the phisher doesn't have to bother storing your credentials - but he'll still infect your computer with his keylogging software, just in case.

One of my students, a UAB Malware Analyst, is currently reviewing the malware. We'll have more information about it shortly and will update this post then.
Read More
Posted in digital certificates, malware, spam | No comments

Sunday, 31 May 2009

Phishers Try MSN Worms to steal credentials

Posted on 04:18 by Unknown
At the University of Alabama at Birmingham our Computer Forensics students are working on a large number of spam and phishing related projects. One of those includes tracking the Fast Flux nodes related to various botnets. As I was meeting with one of the students this week to talk about a particular phishing botnet we noticed that the hosts were doing something that seemed to be related to MSN.



In this particular botnet, computers take turns hosting the phishing websites for various banks. For instance at the end of this week, the botnet was hosting phishing sites like these:

www.mybank.alliance-leicester24.com
www.mybank.alliance-leicester39.com
www.mybank.alliance-leicester93.com
www.mybank.alliance-leicester01.cn
www.mybank.alliance-leicester98.cn

or these:

mibusinessonlinebanking.mibank.com.dir-27612.ffifjl1.com
mibusinessonlinebanking.mibank.com.dir-4712.fjfl1j.net
mibusinessonlinebanking.mibank.com.dir-7158.f1ifjl1.net

or these:

www.bankofscotlandbusiness.co.uk.session64016.sterrss.com
www.bankofscotlandbusiness.co.uk.session6297.vdsl1.com

or these:

www.bankofamerica.com.srv_28742.idfsre.com
www.bankofamerica.com.srv_1470.nfillil.com.sg
www.bankofamerica.com.srv_31682.fgtsssa.com
www.bankofamerica.com.srv_77000.nfillil.net.sg
www.bankofamerica.com.srv_67075.fjtiili.com
www.bankofamerica.com.srv_7688390.hftiili.be
www.bankofamerica.com.srv_07430.fgtsssa.co.uk
www.bankofamerica.com.srv_26497.nfillil.org.sg
www.bankofamerica.com.srv_92855.idfgtid.cz

The phishers are still doing that, of course, but as we were exploring the IP addresses being used by the botnet for hosting these phishing sites (more than 250 of them since Thursday afternoon), we found some domains that didn't fit this pattern.

my-secret-gallery-download.com



First we checked out the WHOIS information . . .

Registered May 15, 2009 at XIN NET Technologies . . .

Using the nameserver NS1.MY-CHEERFUL-DNS.COM

And oh, look! Our old friend Pan Wei Wei!

Registrant:
Organization : Pan Wei wei
Name : Pan Wei wei
Address : BaoChun Rd. 27, No. 3, 1F, Apt. 1903
City : Bejing
Province/State : Beijing
Country : CN
Postal Code : 100176
Email: 127@126.com

Pan Wei Wei has been involved with this particular botnet since at least October, as others have noticed as well. For instance, see Dancho Danchev's blog entry from December. Dancho follows the popular trend of wrongly calling this the "Rock Phisher", but that's a common misperception, and he certainly ACTS like the Rock phisher. We prefer the term "Rock-Like", but that's not the point here. Dancho and many others have good evidence on this guy.

Pan Wei Wei used to prefer his gmail address - escap3@gmail.com or clu3less@gmail.com - but apparently he no longer uses those.

After Googling around a bit and checking the UAB Spam Data Mine, we find that this domain is not being used in spammed email, but is rather being used in an MSN message worm.

Messages are received such as:

damn, saw naked pics of yours or maybe the one in pic is similar to you .... crazy lol http://my-secret-gallery-download.com/pic_gallery.html

or

phewww +o( unbelivable, is that you??? who ever is it...is really similar to you lol ... http://my-secret-gallery-download.com/pic_gallery.html

The criminal needs to update his graphics on this one. What's supposed to happen here is that a graphic is displayed from one of several random ImageShack locations. Above the image are the words:

Click on the image to download the party pictures gallery...
(Click Open or Run when prompted.)

Clicking on the image will actually run this file:

http://my-secret-gallery-download.com/pic_gallery.php

Which causes you to download this file:

image_gallery.scr

File size: 31745 bytes
MD5 : fa0e304fa4c11a89a2345e009ecebf1c

The detection of this file as a virus is actually quite high. 34 out of 40 anti-virus tools now detect this malware, including Microsoft who labels the malware

Microsoft 1.4701 2009.06.01 VirTool:Win32/Obfuscator.FI

Virus Total Analysis here




picy-pictures.com



The next interesting looking website was picy-pictures.com

A WhoIs check confirms that this domain was also created by Pan Wei Wei, although this is more recent - with a created date of May 28, 2009. It also uses the nameserver NS1.MY-CHEERFUL-DNS.COM (and NS2, NS3, NS4).



This one is a much clearer phishing attempt. Here we are asked right at the beginning to provide our MSN userid and password in order to view the 35 pictures in our Private Gallery.

Userids and passwords are checked immediately. If you provide fake data, you get "invalid login! please try again..."

If you provide real data, someone will need to tell me what it does, because I don't have an MSN account that I would like to share with the criminals.

It was interesting to me that although they chose to host this site on a botnet, where each computer on the botnet is a potential host to help them anonymize the source, they chose to hard code an IP address of their stylesheets and javascript programs:

69.90.81.132

There are two domain names associated with that IP address:

hotmail-timeout.com

and

pictures-bucket.com

I wonder if those might be similar scams?

Given that they were also both registered by Pan Wei Wei using XIN NET TECHNOLOGY as the registrar, I feel that it might be a safe bet. Hotmail-Timeout.com was registered March 15, 2009. Pictures-bucket.com was registered April 24, 2009.

The last interesting domain we are seeing on this botnet is:

hotmail-live-inbox.com



Registered May 26, 2009 by Pan Wei Wei on XIN NET TECHNOLOGY using Name Servers NS1.MY-CHEERFUL-DNS.COM (and NS2, NS3, NS4)

We found a post about this one from Steve Swift at on a Vista Forum.

Steve had received a new email from Haris_Sheikh, which he knew because he had a link sent to him from an offline colleague:

You have received (1) new email from haris_sheikh.
http://www.hotmail-live-inbox.com/?user=haris_sheikh

Clicking on the link gave him a "System Notice" that read like this:

Your Live Account is about to get expired. For further details please visit,
http://www.hotmail-live-inbox.com/

If you've been a victim of any of these type of frauds, you may have bigger problems than you know. We've seen hotmail and live.com accounts used to try to scam the friends who send you email (see our blog article on Traveler Scams.)

For some of them, changing your live.com/hotmail password might help --

https://account.live.com/ChangePassword.aspx

For other support on your hotmail or live.com emails you can visit:

support.live.com

To report possible fraud on your live.com account, you can usethis live.com reporting form.

For others, you probably have malware running on your computer which is being used to send spam and steal your passwords!























http://my-secret-gallery-download.com/pic_gallery.html
Read More
Posted in phishing, spam | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Aggrevated Identity Theft Law in Action
    There are so many interesting angles to the story this week about a case in Tucson, Arizona. The conviction actually went down in March 200...
  • More Merger Malware Wachovia Wells Fargo
    Today I received a message from Robert K. Steel, the President and CEO of Wachovia Bank. Actually I received several hundred messages from ...
  • Italian Court declares itself Friend of Pirates (or does it?)
    I couldn't believe this one. The Associated Press reported yesterday that Italian high court says file-swapping is not illegal . In this...
  • Securing Cyberspace in the 44th Presidency: Part Two
    Yesterday I provided some context for the Center for Strategic and International Studies report which was published yesterday: Security Cyb...
  • Radical Muslim Hackers Declare CyberWar on Israel
    This weekend more than 300 Israeli websites have been defaced in a period of 48 hours. In a website "defacement" a hacker violate...
  • AffPower Indictments Scare Affiliates!
    Today I heard the news that the "AffPower" drug network is being shut down, starting with 18 arrests in Texas, Florida, Colorado, ...
  • Paunch and the BlackHole/Cool Exploit Kit
    After months of speculation, the creator of the Blackhole exploit kit can be demonstrated to be in custody. As usual with all things Russia...
  • Bank of America Demo Account - DO NOT CLICK
    Beginning on November 25th, the UAB Spam Data Mine has been receiving messages claiming to be from Bank of America which will explain to us ...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile