Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 12 August 2008

Anti-Virus Products Still Fail on Fresh Viruses

Posted on 13:43 by Unknown
Today was our monthly meeting of the Birmingham InfraGard. At the meeting we talked about our new InfraGard-wide initiative to investigate malware together. If you're an InfraGard member and want more details, please let me know.

Why is it worth focusing on new malware again? Because the truth is the criminals are innovating faster than the Anti-Virus vendors can keep up with. Its true that some of the AV companies have really fast signature cycles, but its also true that their methodology is to write new signatures for viruses that are encountered in the wild.

The problem with that, of course, is that once the virus is in the wild, their customers may encounter it before they do. Face it. Someone has to report that the thing exists!

Here's a few examples from today's spam at the UAB Spam Data Mine.

Example One: Colonial Bank Certificate Spam



The spam message comes in saying:


Colonial Bank Tech Support issued important security update for business accounts. Updated certificate packages that fix various security problems are now available in our Update Center>>

All Colonial Bank users should upgrade to this updated package, which contains ssl multi-protection.

Sincerely,
Colonial Bank Customer Service Department


The website, eg3x.com, hosted in the Ukraine, on IP address 83.170.242.174, which looks like this:



drops an .exe file to visitors, named "certificate_230943772836234.exe"

The malware has an MD5 value of 99c074f671f8e8af5c85ca908d106605 and is 30,208 bytes in size.

As of this timestamp, only FIVE OF THIRTY-SIX Anti-virus products provide protection from this virus. So, a user with current AV protection will be told "no virus found" if they check to see whether this malware is a virus before deciding if they should run it.



VirusTotal detection (5/36)

AVG = Win32/Heur
CAT-QuickHeal - DNAScan
eSafe = Suspicious File
Microsoft = VirTool:Win32/Obfuscator.BO
Webwasher-Gateway = Virus.Win32.FileInfector.gen (suspicious)

All others = No Virus Found

Example Two: UPS Tracking Malware



We've received several copies of this malware today, and several queries from fellow InfraGard members, who reported that their Anti-Virus product had not detected it. This malware arrives as an email attachment. It claims to be From: United Parcel Service, and it has a subject line intended to be a Tracking Number, such as "Tracking N_8513200376" or "Tracking N_ 0294544032".

The body of the email is:


Unfortunately we were not able to deliver postal package you sent on July the 21st in time because the recipient’s address is not correct.

Please print out the invoice copy attached and collect the package at our office

Your UPS


We've seen two attachment names so far:

WW_671282.zip ==> contains WW_671282.exe
and
WW2_ASH182.zip ==> contains WW2_ASH182.exe

While the former file was already detected by 22 of the 36 anti-virus engines at VirusTotal, the latter file was only detected by 7 of 36 when we first uploaded it, although at this timestamp the detection is now 8 of 36:



Example Three: CNN Alerts: Breaking News





Despite the fact that these spam messages have been going on for several days now, each day the malware which is being CURRENTLY SPAMMED is largely undetectable by most anti-virus products. And we're still seeing A LOT OF THIS SPAM. Look at the timestamps here:



In this case, we take as an example, the spammed URL:

http://us-spine.com/update.html

and let it give us a malware executable: adobe_flash.exe

The currently spammed version of this malware is undetectable by 22 anti-virus products including F-Prot, F-Secure, McAfee, Panda, Symantec, and Trend.



Bottom line: If you are in charge of anti-virus for your corporate environment, it is time to learn the Study of Malware and stop trusting anti-virus products. They are important. You should have them. You should update them regularly (at LEAST daily!) But you should not rely on them to tell you if an executable is "safe".
Read More
Posted in | No comments

Monday, 11 August 2008

iTunes Store Phish

Posted on 14:51 by Unknown
In the middle of my 5,000 copies of the newest CNN Alert spam, I had an email from iTunes. I have to tell you, it made me mad. I assumed it meant that my children had been shopping on my iTunes account, and had done something wrong with my account. (love you, K-Dub! love you, Zach!)

And that's why I thought it worth writing about. We hear so much about Phishing, and its almost always described as "a counterfeit bank website", and then usually the definition is extended to say "mumblemumble Paypal mumblemumble eBay", since they don't really fit in to the "banking" concept of Phishing.

The subject of the email was "Important: Billing Problem" and the From: address was "iTunes Store".

The punchline of the email was:


We were unable to process your most recent payment. Did you recently change your bank, phone number or credit card?

To ensure that your service is not interrupted, please update your billing information today by clicking here , After a few clicks, just verify the information you entered is correct.




The "click here" part pointed to this website:

http://www.rofilme.net/m_subtitrari/store.apple.com/us/

which does a pretty good job of looking like an Apple Store, doesn't it?



Clearly this particular criminal is relying on the fact that we aren't going to suspect a non-banking site of being phishing. More evidence? The same site where this phishing site is hosted, "rofilme.net", was used last week as an AOL Billing phish, with the address:

http://www.rofilme.net/m_subtitrari/my.screename.aol.com/_cqr/login/sitedomain/bill.aol.com/sslsecure/update/

Its a rather complex phish . . . the Apple Store phish actually runs a "verify.php" file on another server, http://www.satc.net/gallery/washington_d.c./verify.php, which stores the stolen data in a .txt file. The first set of credentials was given up right at six hours ago, and so far there are 44 plausible sets of identities in the file. Not a huge harvest, but enough to cause a headache for at least 44 people.

The format of the harvested identities text file looks like this:

-----------------------------------
FirstName : Txxxx
Last name : Bxxxx
Address : 9xxxxxx
City : Sxxxxx
State : Tx
Zipcode : 79549
Country : US
PhoneNumber Ext : 3xx
Phone : 5xx.xxxx
Card number : 40034xxxxxxxxxx
Expiry month : January
Expiry year : 11
CVV2 : xxx
Mother's maiden name : bxxxxx
SSN : 462xxxxxx
Birth day : 24
Birth year : 1951
Birth month : 09
Email : txxxxx@yahoo.com
Password : xxxxx
Mon Aug 11, 2008 2:22 pm
6x.1xx.2xx.6x
------------------------------

As you can see, I gave some "xxxx" to protect this person's identity.

So, just a reminder, gentle reader . . . when someone wants your identity, it doesn't have to be a BANK site to be a PHISH.
Read More
Posted in phishing | No comments

Saturday, 9 August 2008

The UAB Spam Data Mine: Looking at Malware Sites

Posted on 16:44 by Unknown
(update: report link URL at end has been corrected...)

In the UAB Computer Forensics program, we have students who are studying the basics of cybercrime, but we also have students who are Malware Researchers, Phishing Researchers, and of course Spam Researchers. Much of our research is enabled by our main research project, the UAB Spam Data Mine.

For some of you, the first glimpse you had of the power of the UAB Spam Data Mine was in last Friday's entry, Linking All the News Spam Together. In that example, we made a recursive SQL query, where we asked "what other spam was sent by the computers that sent this spam?" That's one of the most basic queries we can do. Give us a spam "subject", and we can find all the IPs that sent that subject, and then all of the other emails that those same IPs sent. We can do much cooler things than that. I'll try to tell you about one each week.

In today's post we'll demonstrate one of the ways the Malware team can benefit from queries from the UAB Spam Data Mine.

On a mailing list (Gar waves to Paul), someone mentioned some new malware that was advertised by a spam message with the subject "Shocking porno dvd Carmen Electra". The URL in that spam message pointed to a website ending in "index1.php".

When you visit the website, it downloaded a virus with the name: video312f3sxxx.exe

We knew that we had seen lots of spam with "index1.php", but wondered how many different versions of the virus we could still find "live" on the Internet.

This wasn't intended to be an exhaustive search, so we didn't worry about trying to prove we had every single email in this cluster -- although the spam clustering algorithms are advancing to the point that that is very possible. For today we just did another very simple query.

"Let's find all of the spam where the subject had the word "Shocking" and that contained a URL ending in "index1.php"

-------------
select a.message_id, a.subject, a.sender_ip, b.machine, b.path
from spam a, spam_link b
where (a.message_id = b.message_id)
and subject like '%hocking%' and path like '%/index1.php%';
-------------

This resulted in more than 1600 emails. Changing the query up, we added "group by machine" to make a list of the 261 unique websites which had been advertised as hosting an "index1.php" file.

That list got passed off to a simple "wget" script, which fetched the content of index1.php, following any links that it sent us to, as long as they were on the same site.

Of the 261 websites which had been advertised by this spam, 71 of them were still "live", and gave us 578 different files. In most cases, here's how the fetch worked:

Pulling "index1.php" would send us to a webpage, often named either "index6.html" or "index12.html". That web page would have an Animated GIF file, which, if clicked on, would download the actual virus, as an ".exe" file.

Here are the five animated .gifs which were found on the different versions of the websites:











In most cases, while that visible activity was going on, more stealthy attempts to infect the machine were also underway. In most cases this took the form of an "iframe" which stored the same .exe file on the visitors machine through an encoded javascript program. Visitors who came to the website using Internet Explorer, and who allow JavaScript to run by default on all websites, were infected regardless of whether they clicked on the image.

The next step was to find out how many virus "versions" we were dealing with, and whether they were well known or not. We ended up with 40 different MD5 values, and 40 different filenames:

archive.exe
free_vid.exe
hot_video.exe
hot_video5672.exe
news_usama_video.exe
secret_archive.exe
secret_shok_video.exe
usama_video.exe
video.exe
video_porn.exe
video_shok765.exe
video_shoking.exe
video_usama.exe
video_xxx7546.exe
video135443.exe
video23574fr41.exe
video25653.exe
video2575fr78.exe
video345895gt54.exe
video3468ht34.exe
video354rporn.exe
video37752hq35.exe
video43242xxx.exe
video4324g32.exe
video432654xd.exe
video4326xx.exe
video435_porn.exe
video49825m6.exe
video623porn.exe
video654_ew.exe
video78475fd6.exe
video8658er87.exe
videofilm.exe
videokl_ds4.exe
videonjk568.exe
videoou_8777.exe
videoporn2325.exe
videoPorn3951.exe
videoXXX4579.exe
videoXXX76s3545.exe
videoxxx787.exe

In this PDF table of the websites we reviewed, 08aug08.report.pdf, we list all 74 live websites from which we received malware in today's check of the 261 sites. The filename, MD5, size, and the date of the exe files is given.

The malware sites are everywhere . . . Aregntina, Brazil, Canada, the Czech Republic, Denmark, France, Germany, Hong Kong, Italy, Mexico, Poland, Portugal, Romania, Spain, Switzerland, Turkey, Venezuela. (See IP WHOIS spreadsheet, or Domain WHOIS list.)

The malware from these sites will now be "unpacked" and analyzed by the malware researchers. They've already looked at many of these pieces of malware. For example, the "news_usama_video.exe" that they looked at last week had several nice clues in it, such as the IP address of the Command & Control site for the malware, the format of the communications to and from that C&C, and an internal version number. The malware we were looking at two weeks ago in this family labeled itself "1.0.4" internally. The version last week called itself "1.0.5". Several of the earlier versions were all proven to be related by the fact that they all pointed to the same Command & Control even though their MD5 value was different.

Spam => Data Mine => Reports => WGets => Unpacking => Analysis
Read More
Posted in | No comments

Friday, 8 August 2008

TJX Update: The San Diego Indictments

Posted on 14:08 by Unknown
As promised, here is the update regarding the eight individuals charged in San Diego in connection with "the TJX bust".

There were actually four separate indictments filed, and now that we have the indictments, we'll hopefully be able to learn more about some of these more mysterious criminals.

In the first indictment, the UNITED STATES OF AMERICA v. MAKSYM YASTREMSKIY

the charges are:

18 USC Section 1029(a)(2), and (c)(1)(A)(i) - Trafficking in Unauthorized Access Devices
18 USC Sections 1028(a)(7) and (b)(1)(D) - Identity Theft
18 USC Section 1028A(a)(1) - Aggravated Identity Theft
18 USC Section 1956(h) - Conspiracy to Launder Monetary Instruments
18 USC Section 982 - Criminal Forfeiture

As we saw in the first part of today's post, TJX Update: The Boston Indictments, when Albert Gonzalez and friends didn't know how to turn their stolen credit cards into money, they reached out to Eastern Europe for advice. When they didn't know how to crack their PINs, they reached out to Eastern Europe for advice. When they didn't know how to make sure their sniffer programs would remain undetected, they reached out to Eastern Europe for advice.

Much of that time, they were reaching out to Maksym Yastremskiy.

From May 31, 2005 until May 30, 2006, Yastremskiy, operating in the Southern District of California and elsewhere, sold approximately 155,000 credit card numbers "with intent to defraud", for $98,000 in cash.

Maskym ran a website which was his primary mechanism for selling cards. Prices varied by the bulk, and quantities of cards were advertised on the website (presumably by himself and others) in batches from ten or a dozen, up to several hundred thousand cards or even several million.

The general practice was that Maksym would be contacted by email or chat and the subject of how to make the purchase would be discussed. Unknown buyers would wire a cash payment, usually with Western Union, to Yastremskiy or an accomlpice. Trusted purchasers were allowed to wire directly into Yastremskiy's various bank accounts.
Once the funds transfer was complete, the purchaser would be granted the requested number and type of cards through the website. The indictment gives examples such as "10 Citibank Visa (Gold)" or "20 Royal Bank of Hong Kong Master Card (Platinum)" or "12 Chase Visa (Classic)".

Maksym's charges do not specifically reference Gonzalez from Miami, nor do they name the source of the cards.

Forfeiture claim is made to property derived from many payments, including but not limited to:

$846,762.18 in E-Gold accounts
$ 87,517.36 in Parex Bank account
$3,781,436.36 in an Asia Universal Bank account
$4,862,884.96 in Western Union money transfers
$1,931,047 in US currency




The second indictment is the UNITED STATES OF AMERICA v. ALEKSANDR SUVOROV, aka Lifestyle, aka JohnnyHell, aka Dantist.

The charges brought against Suvorov are:

18 USC Section 1029(b)(2) - Conspiracy to Possess Unauthorized Access Devices and to Traffic Unauthorized Access Devices
18 USC Section 1029(a)(3) and (c)(1)(A)(i) - Possession of Unauthorized Access Devices
18 USC Section 1029(a)(2) and (c)(1)(A)(i) - Trafficking in Unauthorized Access Devices
18 USC Section 1028(a)(7) and (b)(1)(D) - Identity Theft
18 USC Section 1028A(a)(1) - Aggravated Identity Theft
18 USC Sec 2 - Aiding and Abetting

Suvorov's Conspiracy charges name Maksym as his co-conspirator (however Maksym was not charged with Conspiracy in his indictment).

The Overt Acts in the conspiracy are:

On February 10, 2006, Maksym Yastremskiy agreed to sell 160,000 unauthorized credit card account numbers to a purchaser located in San Diego, California.

On February 20, 2006, Sukorov provided Maksym (AKA Maksik) with 160,000 unauthorized credit card account numbers for purpose of re-sale.

On March 17, 2006, in exchange for $10,000 in US Currency, Maksik transferred the first 6,798 of the negotiated 160,000 unauthorized credit cards.

Suvorov received occasional payments from Maksik from May 2, 2005 until May 1, 2006 as the cards were slowly bought and the funds were received back. Over the course of this time, Suvorov received from Maksik approximately $75,000.




In the third indictment, The UNITED STATES OF AMERICA has three Defendants:

SERGEY ALEXANDROVICH PAVLOVICH, aka Panther, aka Diplomaticos, aka PoL1Ce Dog, aka Fallen Angel, aka Panther757

DZMITRY VALERYEVICH BURAK, aka Leon, aka Graph, aka Wolf

SERGEY VALERYEVICH STORCHAK, aka Fidel

The only charge against these three is:

18 USC Section 1029(b)(2) Conspiracy to Traffic Unauthorized Access Devices

This is such a disappointment after the charges against the Boston crowd and the first two here! What are they charged with?

On May 11, 2007 - Sergey Pavlovich negotiated the sale of 90 stolen credit cards to a purchaser in the Southern District of California.

On September 11, 2006 - Dzmitry Valeryevich Burak negotiated the sale of 30 stolen credit cards to a purchaser in the Southern District of California.

On October 10, 2007 - Sergey Valeryevich Storchak agreed to sell 64 stolen credit cards to a purchaser in the Southern District of California.

Ummmm... Big whoop.




In the fourth indictment, the UNITED STATES OF AMERICA also charges three defendants:

HUNG-MING CHIU, aka Slimbady, aka Tomaliki, aka B&Q, aka Betrmb

ZHI ZHI WANG, aka Akihikotobe, aka Attorney

FNU LNU (for those of you who don't speak Chinese OR Indictmentese, that's First Name Unknown Last Name Unknown), aka Delpiero

The charges brought are:

18 USC Section 1029(b)(2) - Conspiracy to Possess Unauthorized Access Devices, to Traffic Counterfeit Access Devices, and to Traffic Unauthorized Access Devices
18 USC Section 1029(a)(2) and (c)(1)(A)(i) - Trafficking in Unauthorized Access Devices
18 USC Section 1029(a)(1) and (c)(1)(A)(i) - Trafficking in Counterfeit Access Devices
18 USC Section 1028A(a)(1) - Aggravated Identity Theft
18 USC Section 2 - Aiding and Abetting

The three defendants are charged with entering into conspiracy with Maksik (Maksym Yastremskiy) and JonnyHell (that's the third way I've seen that spelled in official documents this week!) (Aleksandr Suvorov).

The Overt Acts in their conspiracy include:

On July 30, 2005 - Zhi Zhi Wang sold 100 counterfeit credit card blanks to a purchaser located in the Southern District of California. The order was later filled by Hung-Ming Chiu.

On July 30, 2005 - Zhi Zhi Wang sold 100 counterfeit credit card blanks to a purchaser located in the Southern District of California. The order was subsequently filled by Hung-Ming Chiu.

On September 17, 2005 - Hung-Ming Chiu discussed with Maksym "Maksik" Yastremskiy the creation of a website that could be used to distribute stolen credit card accounts. Maksik agreed that he would be the website's provider of stolen credit card account information.

On September 28, 2007 - FNU LNU, aka Delpiero, sold 100 unauthorized access devices to a purchaser in the Southern District of California.

From September 17, 2004 until September 16, 2005, Hung-Ming sold approximately 162 credit card account numbers that had been stolen or obtained with intent to defraud, for approximately $4,500 in cash.

From September 17, 2005 until September 16, 2006, he did it again, with 172 cards for which he received $5,000.

From April 18, 2007 until April 17, 2008, Delpiero sold about 350 credit card account numbers for about $4,500.

They also sold "real looking" (or counterfeit) blank plastic.



OK, we'll pause here for a moment to reflect on how ludicrous it sounds to have a single press release naming people with $20 Million in forfeiture in the same case with people who only made $4,500. This is the part where we interject that these are real bad guys doing world-wide crime! The problem is that we have to have jurisdiction, in this case in the Southern District of California, for whatever we charge them with. Before you get terribly disillusioned about the nature of these "small fish" based on the indictments, let's investigate the Affidavit of Special Agent Ryan Knisley of the United State Secret Service.



SA Knisley has been a Secret Service Agent since August 7, 2006. What we don't see in the indictments themselves is that "Pavlovich" runs a HUGE Credit card trading service known as "Dumps Market" (www.dumpsmarket.net, at the time of the indictment.)

Burak had screwed up and found himself with a Yahoo! address which was searched by the US Secret Service. As a result of that search, he was found to be trading "BIN lists" (Bank Identification Numbers) and stolen credit card numbers with Storchak.

Storchak's accounts were also searched, and it was found that the credit card numbers traded between these two actually had been used for real dollar losses of $7,000,000!

Other evidence pointed to email accounts at a site called "safe-mail". Commonly held by the criminals to be beyond the stretch of US Law Enforcement. Through the Mutual Legal Assistance Treaty, email accounts at "SAFe-mail", which resides in Israel, were also searched, and the results shared with the USSS. In those mails
more details were revealed indicating that Pavlovich was the source of many of the stolen credit cards.

Pavlovich was running DumpsMarket in Belarus. Who also cooperates with US Law Enforcement. The Belarus law enforcment folks seized Pavlovich's hard drive, made a copy, and sent it to the US Secret Service. Pavlovich's hard drive contained more than 10,000 stolen credit cards, and photographs of himself spending time with Burak and Storchak in various social settings.

So, while the actual charges brought here seem small, we MUST make them stick. This is a $7 Million Bad Guy of the variety who needs to go to jail.

Three Cheers to Southern California for taking what data they could own and deciding to press forward with it!

While it is not specifically laid out in the documents to which I have access, it is my strong belief that the Chinese defendants are in a similar situation. The small numbers in Southern California should not be seen as a measure of their insignificance as criminals, but rather as a sign that when you spread multi-million dollar crime around the entire globe, its hard to find one small set of contiguous ZIP Codes that had many losses.

Again, Three Cheers to the US Secret Service, and the US Attorney of the Southern District of California!

(All Four Indictments, and the Affadavit are included in a single 34 page PDF)
Read More
Posted in | No comments

TJX Update: The Boston Indictments

Posted on 12:37 by Unknown
The Boston indictments are now public and have quite a few more facts for us, and I'm so excited that I've just received the first of the San Diego indictments from their most helpful press officer!

I'm going to run this in two parts. Boston first, and then San Diego.

An incomplete story was painted by the earliest press releases, which lead the media to quickly jump on the fact that Gonzalez was a wardriver, and TJX and the other victim companies had sloppy wireless security. True, but not a complete picture.

We'll start by looking at what else we can learn from the indictments that are now available in Boston.

What's in a name? We'll start with Albert Gonzalez's A/K/A's:

cumbajohny
cj
UIN 201679996
UIN 476747
k1ngchilli
stanozololz

Unfortunately, that genius of blackhat journalism, Kevin Poulson, has beat us to the punch with this one in his Wired Blog, but what a great story it is. You'll recall in our previous blog post on this subject, TJX Reminder: We Will Arrest You, and We Will Send You To Jail, we mentioned that Albert Gonzalez was a US Secret Service Informant. Now that we know his alias, CumbaJohny, we see that Albert was the snitch for Operation Firewall, the Secret Service case that lead to the arrests of 28 members of the ShadowCrew back in October of 2004. CumbaJohny, now re-handled as Segvec, now gets to feel what its like to be on the receiving end of one of these seizures.

The Violations that Segvec faces are:

18 USC section 371 Conspiracy
18 USC section 1030(a)(5)(A)(i)Damage to Computer Systems
18 USC section 1343 Wire Fraud
18 USC section 1029(a)(3) Access Device Fraud
18 USC section 1029(c)(1)(C), 982(a)(2)(B),981(a)(1)(C) Criminal Forfeiture
28 USC section 2461(c) Criminal Forfeiture

Here's the way the Conspiracy charges stack up. First we have to establish what they conspired to do. The indictments lists "the objects of the conspiracy" this way:


a. Exploit vulnerabilities in wireless computer networks used at retail store locations

b. Exploit vulnerabilities used to manage large business databases

c. Gain unauthorized access to computer networks processing and storing debit and credit card transactions and other valuable data for major corporate retailers.

d. Download and steal from computer networks operated by major corporate retailers over 40 million pieces of card holders' track 2 data - the information found on the magnetic stripes of credit and debit cards, which is read by ATMs and credit card readers - as well as internal accounts and proprietary files

e. Sell stolen track 2 data in Eastern Europe, the United States and elsewhere to others for fraudulent use

f. "Cash out" stolen track 2 data by encoding the data on the magnetic stripes of blank payment cards and using these cards to obtain tens of thousands of dollars at a time from banks' ATMs

g. Conceal and launder the illegal proceeds through anonymous web currencies in the United States and Russia, and offshore bank accounts in Latvia

h. Repatriate portions of the illegal proceeds through web currency converters and ATM cards linked to Eastern European banks.


The Gonzalez indictment tells quite a bit more about how they moved from WarDriving to much greater exploits.

First, Gonzalez, Toey, and Scott went wardriving around Miami, in commercial areas such as the area around U.S. 1, identifying vulnerable wireless networks. They targeted large retailers, "including, but not limited to" BJ's Wholesale Club, DSW, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, and TJX.

After infiltrating their networks, they began locating and stealing sensitive files and data, including credit card numbers.

At this point, they are just punks. This type of break-in is a dime a dozen. But then they took it further. It says they went on to install sniffer programs, monitoring and stealing password and account information as well as track 2 data.

The conspiracy broadened as they had to bring in new associates to help with decrypting the encrypted PIN numbers on their tens of millions of Track 2 reads.

The stolen data was stored on servers in Latvia, the Ukraine, and the United States, and encrypted to prevent access by others. From there, the data was sold in "dumps", cashed out, and the money was redistributed, using webmoney, ATMs, and in some cases even mailing express packages full of cash to drop boxes!

Regarding their technical skills, custom SQL injection attacks were developed to take on particularly desirable web sites. The attacks were mounted against a variety of database-driven web sites to find additional track 2 data, internal accounts, and files of large businesses.

Regarding the level of Gonzalez' conspiracy -- he used sensitive law enforcement information, which he obtained by his "cooperation" with the US Secret Service, to alert his conspirators and make sure they would not be identified and arrested.


Some particular examples illustrate the dates and players:

In 2003, Gonzalez and Scott use wireless access to steal track 2 data at BJ's Wholesale Club.

In 2004, Scott and "J.J." gain unauthorized access to the wireless network of the OfficeMax on 109th Street and US 1 in Miami, locating and downloading encrypted PINs.

Scott and J.J., unable to decrypt the PINs, passed the data to Gonzalez, who located and engaged another co-conspirator who had the necessary decryption abilities.

On July 12 and 18th, 2005, Scott accessed TJX's Marshalls department stores in Miami, using the wireless network there to compromise servers at TJX's server farm in Framingham, Massachusetts.

On September 15-16, Scott accessed the Framingham servers and retrieved the data which their sniffers had been collecting.

Beginning on May 14-15, 2006, Scott installed and configured a VPN connection between one of the TJX card transaction servers and a server obtained by Gonzalez.

On May 15, 2006, Gonzalez used ICQ to ask Yastremskiy for help in obtaining an undetectable sniffer program. Beginning on May 15 and lasting through May 20th, they established their new undetectable sniffer.

The new sniffer's data was retrieved on many dates, including October 27 and December 18, 2006.

Beginning in August of 2007, Gonzalez invited Toey to move to Miami. In exchange for cash payments and free rent, Toey began to develop an Internet-based attack on the servers at "Forever 21", with the goal of obtaining financial data.

Prior to moving to Miami, Toey worked as a broker for Gonzalez, finding customers, who would be given login credentials to retrieve the credit cards from one of the many encrypted dump sites around the Internet.

From February to May of 2006, Gonzalez collaborated with Yastremskiy to distribute OfficeMax track 2 data.

On March 13, 2008, Gonzalez used his VPN connection to TJX from a computer in Latvia to store 16 million unique credit and debit card numbers. That same day he stored more than 25 million credit and debit cards on a Ukranian server as well.

Gonzalez faces forfeiture of $1,650,000 cash, a condo in Miami, a 2006 BMW 330I, some computers, a Glock 27, a "350C Currency Counter" (wow!),

As for the further act of Gonzalez, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?




Christopher Scott's Indictment is much less sexy from the beginning, mostly because he has no cool hacker aliases at the beginning.

He is charged with most of the same charges, with the exception of Wire Fraud.

His forfeiture included, $400,000 in cash, eleven computers, some nice iPods, some nice monitors, and they even took his XBOX and PSPs!

Let this be a warning to you, children. If you hack into TJX, you will lose your XBOX privileges! (Oh, and go to jail for a long time, hopefully!)

As for the further acts of Scott, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?



Damon Patrick Toey faced the same charges as Chris Scott. He also does not get Cool Points for having many AKAs, but let's face it, Damon Toey is a cooler name than Chris Scott.

Toey's "Overt Acts" section focuses on his selling of "dumps" of cards on behalf of Gonzalez and splitting the proceeds, and his leading role in the SQL injection and other Internet-based attacks used to access corporate databases and systems, including the Forever 21 attack, where he had the leading role.

I love the actual wording of Count Two, the Access Device Fraud:


In or about October, 2004, in the Eastern District of Virginia and elsewhere, Damon Patrick Toey, knowingly and with intent to defraud, possessed at least 15 unauthorized access devices, to wit: stolen credit and debit card numbers.


Yes, 40,000,000 is "at least" 15.

Based on the forfeiture, it looks like Damon was the Talented but Unimaginative member of the team. He forfeited only $9,500 and a few computers. But they got his XBOX too!

As for the further acts of Toey, and all that he did, are they not written in the Book of the Chronicles of the Criminals of Massachusetts?
Read More
Posted in | No comments

Linking all the News Spam together (CNN.com Daily Top 10)

Posted on 02:00 by Unknown
One of my students has been studying the relationship between the various "news spam" malware pieces, and has found some interesting patterns linking the spam campaigns together by the proven relationship between the spam messages.

Tonight I decided to look at the relationships using the "open SQL query" interface to our UAB Spam Data Mine. The advanced data clustering algorithms do some incredible things, but tonight I just wanted to see what IP addresses had sent us spam email for the "CNN.com Daily Top 10" campaign, and then ask, "So what other spam do we have in the Data Mine that comes from those IP addresses?"

The query is actually very simple for this type of question:

=============================================================

select a.message_id, a.subject, a.sender_ip, b.machine, b.path
from spam a, spam_link b
where (a.message_id = b.message_id)
and a.sender_ip in
(select sender_ip from spam where
subject like '%CNN.com Daily Top 10%')
order by a.sender_ip, a.subject;

==============================================================

Which says, find all the IP addresses that sent us spam where the subject includes the string "CNN.com Daily Top 10". Then make us a list of all the messages sent by those same IP addresses, and show the subject, and URLs (machine + path) from those messages, ordered by IP address and then subject.

------

Observations:

We had emails in the CNN group from 4,875 unique IP addresses. Those IP addresses sent us a total of 11,809 emails.

10 emails in November
102 emails in December
51 emails in January
191 emails in February
162 emails in March
213 emails in April
363 emails in May
403 emails in June
2,892 emails in July
7,421 emails in August

Browsing the subjects, it was clear that most of the emails before very late June were an assortment of pills, watches, and enlargement promises. A clear "news trend" started at the very end of June.

Looking at only paths spammed by this group in July and August, these IP addresses spammed the following paths:

/1.html
/about.html
/begin.html
/checkit.html
/cnnlive.html
/cnnnews.html
/cnnonline.html
/cnntop.html
/cnnvideo.html
/default.html
/first.html
/fresh.html
/gowatch.html
/hotnews.html
/Images/.../video-nude-anjelia.avi.exe
(several variations of previous)
/index1.html
/index1.php
/index2.html
/livestreaming.html
/lol.html
/main.html
/msvideoc.exe
/news.html
/news/
/r.html
/redir.html
/showvideo.html
/start.html
/stream.html
/top.html
/tophot.html
/topnews.html
/video
/video.exe
/view.exe
/viewmovie.html
/watchit.html
/watchmovie.mpg.exe
/whatsup.html
(many crazy long paths all on "livefilestore.com")

So, EVERY MAJOR "news spam" campaign we received in July can also be found by looking at emails which came from the same IP addresses as the CNN.com Daily Top 10 emails. We wrote about several of these back in July, for example:

r.html ==> Nuwar Looks for News Readers - July 7

viewmovie.html == News Headlines Still Out of Control - July 22

topnews.html == Top News in Spam = Old News - July 26

I've placed the list of IP addresses used in this spam in a text file on my UAB website:

http://www.cis.uab.edu/forensics/CNN.iplist.txt

The list of all 2,255 URLs which were spammed in those emails is also available on my UAB website:

http://www.cis.uab.edu/forensics/CNN.urls.txt

If you have a similar list, I'd love to compare notes!

--------------

Gary Warner
Director of Research in Computer Forensics
The University of Alabama at Birmingham
gar@cis.uab.edu gar@askgar.com
Read More
Posted in | No comments

Thursday, 7 August 2008

CNN Spam Diversifies . . .

Posted on 08:32 by Unknown
We continue to see an alarming number of spam messages pretending to be from CNN, with the subject "CNN.com Daily Top 10". Approximately 6% of our spam messages are currently part of this campaign.

The spam messages contain graphics which are actually being loaded from the real CNN website. We'll load them here from the same site so you can see them. These are the graphics present in each of the spam emails, fetched directly from the CNN website, just like the current spam campaign, lending to the credibility of the spam.







Top 10 stories









There are now more than 190 URLs being used to spread the malware. While the earliest versions of the malware URL all used the path "index2.html", the malware now also is hosted on the paths "cnnlive.html", "cnnnews.html", "cnntop.html", and "cnnvideo.html".

There are now 162 servers hosting 192 paths which have been involved in this attack. Each of these servers had the malicious content uploaded to it by a hacker. Most of these are legitimate websites which were hosting real webpages before they were compromised for this purpose. Because the malicious contents are not interfering with the primary use of the server, in many cases the webmasters were not even aware of the compromise.

*WE DESIRE TO SPEAK TO ANY ADMINISTRATOR WHO CAN PROVIDE LOG FILES FROM ONE OR MORE OF THESE COMPROMISED SERVERS*

Here is a list of malicious URLs, grouped by "path":

http://adcockonline.com/cnnlive.html
http://ademirpestana.com.br/cnnlive.html
http://beta.wwf.it/cnnlive.html
http://caminhodocristo.com.br/cnnlive.html
http://cdlaestrella.com/cnnlive.html
http://fondeur.com/cnnlive.html
http://fotosdc.com/cnnlive.html
http://gracesmarketplace.com/cnnlive.html
http://hangarmobiliario.startlogic.com/cnnlive.html
http://jumpking.fr/cnnlive.html
http://layber.com.br/cnnlive.html
http://piedrarustica.com/cnnlive.html
http://pyromagie.com/cnnlive.html
http://rosh-hanikra.com/cnnlive.html
http://sarlcreapub.fr/cnnlive.html
http://www.consulting-ev.com/cnnlive.html
http://www.familiavelazquez.com/cnnlive.html
http://www.ferienpark-berum.de/cnnlive.html
http://www.martinkahl.com/cnnlive.html
http://www.nlg.com.br/cnnlive.html
http://www.smackxx.de/cnnlive.html


http://art-cie.fr/cnnnews.html
http://cityofdetroit-beta.com/cnnnews.html
http://energydrinkshop.com/cnnnews.html
http://imeriberica.com/cnnnews.html
http://leggiillustrate.it/cnnnews.html
http://lorenziniassociati.it/cnnnews.html
http://nodostudio.com/cnnnews.html
http://ophtha.com.co/cnnnews.html
http://pastry-art.de/cnnnews.html
http://pcenmarcha.com/cnnnews.html
http://reservadeoporto.com/cnnnews.html
http://scotsact.com/cnnnews.html
http://sethory.de/cnnnews.html
http://studiogabia.com/cnnnews.html
http://style-r.de/cnnnews.html
http://uggi.com.br/cnnnews.html
http://videogamesheaven.dot5hosting.com/cnnnews.html
http://wp1054775.wp086.webpack.hosteurope.de/cnnnews.html
http://www.bellomeparrucchieri.it/cnnnews.html
http://www.ck-automobile.de/cnnnews.html
http://www.datgame.com/cnnnews.html
http://www.konaya.com.tw/cnnnews.html
http://www.marmibuono.com/cnnnews.html
http://www.ssurmant.es/cnnnews.html
http://www.uwg-groebenzell.de/cnnnews.html
http://www.vonalpenhirsch.be/cnnnews.html


http://adcockonline.com/cnntop.html
http://ademirpestana.com.br/cnntop.html
http://beta.wwf.it/cnntop.html
http://carports-rhein-neckar-dreieck.de/cnntop.html
http://cdlaestrella.com/cnntop.html
http://congresoaracenaegc.es/cnntop.html
http://fondeur.com/cnntop.html
http://fotosdc.com/cnntop.html
http://gracesmarketplace.com/cnntop.html
http://hangarmobiliario.startlogic.com/cnntop.html
http://ipp-dresden.de/cnntop.html
http://jumpking.fr/cnntop.html
http://karokuhle.de/cnntop.html
http://koblenzer-schaengelbrot.de/cnntop.html
http://layber.com.br/cnntop.html
http://missglobe-albania.com/cnntop.html
http://morenogonzalo.com/cnntop.html
http://piedrarustica.com/cnntop.html
http://primeracolina.cl/cnntop.html
http://pyromagie.com/cnntop.html
http://rosh-hanikra.com/cnntop.html
http://sarlcreapub.fr/cnntop.html
http://scsroofing.com/cnntop.html
http://steinsein.gmxhome.de/cnntop.html
http://terrano2.be/cnntop.html
http://www.affiliateincome4free.com/cnntop.html
http://www.alfa-nt.com/cnntop.html
http://www.blackhawkk9.com/cnntop.html
http://www.consulting-ev.com/cnntop.html
http://www.ferienpark-berum.de/cnntop.html
http://www.jills-homepage.de/cnntop.html
http://www.martinkahl.com/cnntop.html
http://www.microbyte.ch/cnntop.html
http://www.nlg.com.br/cnntop.html
http://www.smackxx.de/cnntop.html


http://ademirpestana.com.br/cnnvideo.html
http://apamys.es/cnnvideo.html
http://aramusicaiespectacles.com/cnnvideo.html
http://barrierelectric.com/cnnvideo.html
http://beta.wwf.it/cnnvideo.html
http://caminhodocristo.com.br/cnnvideo.html
http://cave-live.info/cnnvideo.html
http://cdlaestrella.com/cnnvideo.html
http://colleflambo.com/cnnvideo.html
http://dcfwarriors.org/cnnvideo.html
http://directorioelejido.com/cnnvideo.html
http://erbilproje.com/cnnvideo.html
http://eventosgs.com.ar/cnnvideo.html
http://familylaw-nj.com/cnnvideo.html
http://hangarmobiliario.startlogic.com/cnnvideo.html
http://maviinci.org/cnnvideo.html
http://meusarquivos.net/cnnvideo.html
http://mikkokaaria.com/cnnvideo.html
http://naltech.co.il/cnnvideo.html
http://piedrarustica.com/cnnvideo.html
http://praxisfilms.co.il/cnnvideo.html
http://rosh-hanikra.com/cnnvideo.html
http://sarlcreapub.fr/cnnvideo.html
http://showtech.myzen.co.uk/cnnvideo.html
http://starbistro.de/cnnvideo.html
http://synerweb.info/cnnvideo.html
http://thediver.co.il/cnnvideo.html
http://twistedrose.com.mx/cnnvideo.html
http://www.drtimcic.org/cnnvideo.html
http://www.familiavelazquez.com/cnnvideo.html
http://www.ferienpark-berum.de/cnnvideo.html
http://www.instrumelec.be/cnnvideo.html
http://www.iteco.cz/cnnvideo.html
http://www.malicioso.net/cnnvideo.html
http://www.martinkahl.com/cnnvideo.html
http://www.massouristudios.gr/cnnvideo.html
http://www.nlg.com.br/cnnvideo.html
http://www.ruf-an-alle.de/cnnvideo.html
http://www.smackxx.de/cnnvideo.html
http://www.transam99.de/cnnvideo.html


http://1stbs.com/index2.html
http://208.112.108.239/index2.html
http://3dtoy.com.br/index2.html
http://attomega.com/index2.html
http://autourdufeu.net/index2.html
http://borinsrl-store.com/index2.html
http://climatel.dot5hosting.com/index2.html
http://dztransporte.de/index2.html
http://hieber-ed.de/index2.html
http://hometrimwork.com/index2.html
http://isctrim.com/index2.html
http://lombardi.ws/index2.html
http://megadent.pl/index2.html
http://realdecor.com.br/index2.html
http://renderize.net/index2.html
http://sol.innopulse.es/index2.html
http://tomar-a-andar.com/index2.html
http://turegalodesanvalentin-julieta.idoo.com/index2.html
http://vehne-cafe.de/index2.html
http://voxinterna.de/index2.html
http://www.bardaue.com.br/index2.html
http://www.dj-ralfi.de/index2.html
http://www.sibercar-card.com/index2.html
http://www.weddingsinsardinia.com/index2.html
http://www.wellnessantamaria.com/index2.html


http://496dots.com/news/
http://620dreams.com/news/
http://90lights.org/news/
http://90muses.org/news/
http://97folders.org/news/
http://99spots.org/news/
http://9feeds.org/news/
http://arkaki.org/news/
http://asvoo.org/news/
http://awaybuddies.org/news/
http://back82.org/news/
http://behind97.org/news/
http://bibdit.org/news/
http://blogcube.org/news/
http://cafemarker52.com/news/
http://cafepaths077.com/news/
http://clipcabin.org/news/
http://facecurve.com/news/
http://front7589.com/news/
http://frontsend09.com/news/
http://joogle2.com/news/
http://my3598.com/news/
http://open6098.com/news/
http://ourmark75.com/news/
http://squinento96.com/news/
http://stikimixer.com/news/
http://styledesk86.com/news/
http://tao767.com/news/
http://true479.com/news/
http://upgle12.com/news/
http://www.18columns.org/news/
http://www.26cubes.org/news/
http://www.28buddies.org/news/
http://www.36dreams.org/news/
http://www.36people.org/news/
http://www.41cells.org/news/
http://www.58friends.org/news/
http://www.60balloons.org/news/
http://www.60circles.org/news/
http://www.6feeds.org/news/
http://www.71piles.org/news/
http://www.75cubes.org/news/
http://www.79circles.org/news/
http://www.7lights.org/news/
http://www.83friends.org/news/
http://www.83groups.org/news/
http://www.86places.org/news/
http://www.87clouds.org/news/
http://yooia97.com/news/

An astounding number of fake headlines have been used as lures. Each spam email message contains ten of these headlines listed as "Top Stories" and ten more of these headlines listed as "Top Videos".

`Dark Knight' - download it instantly fo free
125,000 gorillas found in New York
12-year-old with HIV applauded at AIDS conference
16 Police Die in Pre-Olympic Attack
5 more arrested from west Texas polygamist sect
6 NFL greats inducted into the pro football hall of fame
8-Foot Python Becomes Laundry
95-year-old Paul Batman calls Texas -- not Gotham City -- home.
A college student has vowed to make it through the summer on one tank of gas.
A drunken driver slams into car as officer wrote a ticket.
A first-birthday coming of age ritual that foretells the future.
A look at the future computing technologies which will go beyond Moore's Law.
A major study by Microsoft supports "small world" theory.
A prostitute waits for customers
A young human rights attorney makes unprecented move against religious police.
Acrobatic troupe's colourful London debut of Swan Lake
Activists kill 3 in Ohio
Afghan, NATO troops kill 17 militants in southern Afghanistan
Aged Tires: A Driving Hazard?
Ageing Japanese men worry about body odour
Air force one crashes in Iraq
Al QaedaÆs Leader Arrested
Alleged pickup thief loses truck to carjacker
Amy Winehouse hospitalized following drug overdose
An American pilot's mission won the heart of a city in its darkest hour.
Ancestor of T-Rex dinosaur unearthed in Poland
Ancient shark had colossal bite. See pics now!
Andre Agassi admits drug abuse
Angels Grow on Trees says Hillary Clinton
Angry, late, tired passengers make computers crash
Anthrax researcher had been under psychiatric care before his death.
Arctic park faces melting crisis
A-Rod to wed Madonna in September
AS SEEN ON TV: Elder Care Resources
Athletes bare all. See now!
Atlanta's Airport Named World's Busiest
Attackers kill 16 police at Chinese border post
Bank accounts 'not working for customers
Bank breaks rules on charges court case Derbyshire
Bank charges claims left in limbo
Bank Pampers Thousands
Bankers are laughing all the way to the bank
Banks to rake in extra $1.3bn in next six months after delaying OFT overdraft crackdown
Beckham wins a surfboard in LA
Become Sperm Donor and Get Rich
Beijing unblocks BBC Chinese site
Beijing under threat as Olympics looms
Bikers down to bare basics for eco demonstration
Bill Clinton and Monika seen again
Bill Clinton finds Hillary affair pics
Bill Clinton Regrets, 'I Am Not a Racist'
Bill Thompson asks if the web changes how we think
Bill Thompson on Apple's software security stance
Blake Lively admits crush on Britney
Blake Lively admits teenage lesbianism
Boy Loses Arm in Gator Attack
Boy thrown outside window in school
Boys bounce for 24 hours in world record attempt
Brangelina babies finally unveiled on Web
Brazil launches rainforest fund
Breaking Dawn' Book Excerpt Exclusive!
'Breaking Dawn' Book Excerpt Exclusive!
Bridge collapses in New York
Buses are a 'consumer's paradise' as airfares rise and air stresses grow.
Bush plans to kill prisoner
Bush urgently flies to Asia
Buy gasoline before prices shoot off
Buy the original Olympic Torch from Beijing
Can a party game reveal flaws in U.S. wiretapping and war plans?
Car bomb in Washington kills hundreds
Car buyers sue Ford over limited edition vehicle
Celebrity was seen naked on the beach
Changing the way we think
Cheesus! Jesus Spotted in a Cheeto
Chef: sorry for suggesting poison plant in salad
China clamping down on journalists' Web access to control image during Games.
China has more internet users than US
China Jails Another Dissident Before Games
China Rising: Will It Overtake the U.S.?
China tightens security following attack in west
China's 'rapid renewables surgery' is available now!
Christian Bale admits affair with Angelina Jolie
Christian Bale hits on Lindsay Lohan
Christina Applegate treated for breast cancer
Church-goers shot for having different views
Clark Rockefeller continues to stymie investigators' questions about his past.
Cleaning up in 'fab world'
Clinton Denies Racism Claims
Closing the Gates after Bill
Comedian Mac in Chicago hospital
Commercial dog clones are available now
Computer mouse faces extinction
Condo investors in Florida are struggling to hold their lives together.
Cops May Close Anthrax Probe Today
Coroner ID's teenager who was asphyxiated, dumped in shallow desert grave.
Corrupt China official betrayed by leaky toilet
Cuil - new google-ish search engine
Customers not paid back overdraft charges
Death or a crippling injury could leave your loved ones out in the cold.
Definition of a womanÆs G-spot
Dinosaurs Come to Life at Exhibit
Dinosaurs interact with humans on 'Primeval'
Disputed Korean rocks bring banking, ring tones
Divorced, beheaded or died? Joss Stone to play one of Henry VIII's wives in The Tudors
Doctor Who writer Russell T Davies is among the stars
Dog Plays Mom for Tiger Cubs
Dog Rides a 'Hog'
Don't streak, get drunk or sleep outside at Olympics
Doping scandal rush out before the opening
Drug, alcohol mix blamed for "Joker's" death
Drunken Man Can't Erase Arrest
Dumped computers cause toxic concerns in Ghana
Early stereo recordings restored
Edouard hits Texas, many dies
Edouard Triggers 'Cane Watch for Texas
Energy giants are told to pay back billions
Engine test for Falcon 9 rocket
Ernest Hemingway look-alikes hit Key West's streets to honor the author.
Ex-Google engineers debut 'Cuil' way to search
Facebook Grows, but Where's the Profit?
Facebook under attack by clones
Family Dinner in China's Countryside
Family Lives Paycheck-to-Paycheck
Farmer sends message to neighbors with car fence
Fatal medication errors at home causes 1 million deaths
FBI arrest Gotti Jr in New York
FBI investigates new attacks on Calif. scientists
FBI reveal sealed docs describing anthrax attack details
FDA warns against eating lobster
FIC Says Overdraft Charges Unfair On Consumers
Fight back against unfair credit card practices
Find you friend online for free
Five Secrets to Get a Bargain on a House
Fla. man dials 911, complains his sub had no sauce
Floods in Minnesota kill hundreds
Food Prices Too High? Buy a Farm
Four Girls and You. Reveal Your Fantasies
France accused in Rwanda genocide
Free banking is a myth: charges on current accounts reach $8bn a year
Freeman still in serious condition after car crash
Funnies: Celebrity Candidates?
Furnished Nazi bunkers surface in Denmark
Future directions in computing
Gay bishops banned and castigated
Gay declares himself fit for 100m
GE declares 100 million deficit
German police women get "bullet-proof bras"
Get a current account that beats the credit crunch
Get new sport car. If youÆre smart enough
Get your up-to-date fix of blog posts about all things digital
Good Housekeeping Institute tested backpacks, snacks and lunch boxes.
Google accused on privacy views
Google Knol threatens wikipedia
Gossip Girl wins six Choice gongs
GPS-equipped turtle stumbles upon field of marijuana in a D.C. park.
Grabbing for Destiny: A Chinese Baby's Coming of Age
Guinea Pigs Get Dressed ... and Eaten
Half-scale replica of German tank built for paintball competition.
Harried family forgets 3-year-old daughter at airport.
Have Your Hours Been Cut?
Hedge-Fund Soldier Leads Double Life
High cost of little cash
Hillary admits she was wrong
Hillary falls from horse, hurts arm
Hillary finds ladies' stuff in house, storms off in a huff
Hi-tech criminals target Twitter
Hopkins, Epstein, Bolger Join Cast of 'Dirty Dancing''s U.S. Tour
How One Family Fought Foreclosure
Human malaria jab tests nearing
IBM to file for bankruptcy
Iggy Pop truck stolen after show
Illusionist Chris Angel races against time in a building set to detonate.
In the era of pills, fewer psychiatrists do talk therapy.
In the first surgery of its kind, a German farmer gets a new pair of arms.
Inflation rises to 35-year high of 8.2%
Intel unveils graphics chip line. See it now!
Internet exposes Obama affair
Is this photo fake? Meet the people who say it is...
It's a buyer's market if you know what 'code words' to look for.
Jacksons to receive Icon honour
Japanese rookie tosses perfect game for Dodgers
JFK heir found
Joe Corre was born to rail against
Kaiser Chiefs boast a 'weird, fresh, radical' new sound
Kelsey Grammer in hospital after heart attack
Kevin Costner appreciates politics and making movies.
Kevn Spacey forced to admit to affair
Key to Biz Success: The Conference Table?
Kidnap Dad In Custody, Girl Found Safe
Last Survivor of K-2 Tragedy Still Climbing
Laura Bush naked
Learn how to be a guru in finding G-spots
Leona Lewis up for US MTV award
Light goes out on pioneer machine
Lost Your Home to Foreclosure?
Madonna admits to 12 different affairs
Madonna seduced Timberlake on set
Maggie Q seen with Brad Pitt
Magma in the Atlantic ocean cooks up ultra-hot water.
Maine island loses trash can mail delivery service
Making a career in Hollywood. You can do it!
Making punishment fit the crime
Man Offers $1 Billion Reward for Breast Cancer Cure
Man presumed dead in 1976 Colo. flood found alive
Man shoots churchgoers over liberal views
Man tells 911 slot machine stole his money
Man wins appeal in bizarre gasoline suicide case
Mars May Not Be Garden Spot
Mass suicide of prisoners in US cell
Massive earthquake in Japan kills thousands
McDonald's feed wastes
Meet the Real Batman
Men survivied month eating dog food
Merrill Lynch files for bankruptcy
MGM Mirage gets CityCenter financing
Michael Jackson is sued by his own dog
Michael Jordan admits affairs with dozens of girls
Michael Jordan attacks Clinton
Michelle Obama latest fashion disaster
Microsoft sees end of Windows era
Miley Cyrus describes her dream man
Mitch Winehouse will host a phone-in show on BBC Radio London in September.
Moon can inhabited at 2010
More UCLA staff saw celebs' health records
Morgage Loan You Can Pay Off
Mortgage rates rise to heavens
MTA Screwing You
Murderer on the loose after cop bungle in Iowa
Mysterious 'Monster of Montauk'
Naked Madonna blows the press conference
Naked Teen Meets You at Your Home
NASA engineer-DJ Mark Branch thinks spinning beats is a science.
Neighborhood quarrel threatened to bring war, but it ends in handshakes.
New Breed of Dolphin
New cure for Alzheimers' discovered
New quake hits Chinese province
New study suggests that athletic performance can affect visual perception.
No answers as McCarthy, Favre meet late into night
No More $1 Double Cheeseburgers?
No wonder we don't trust the banks
Nokia morphs itself from within
Northern Rock cash boost attacked
Not All Men Need Prostate Cancer Screening
NY girl falls 14 stories, saved by sooty landing
Oasis to play secret gig for fans
Obama beats McCain
Obama sacks 4 top staff
Obama spotted in secret China meeting
Obama urges opening oil reserves
Obama-Clinton ticket is most likely
Oil price falls further to $118
Oil prices drop to 45-year low
Olsen seeks Ledger immunity
Olympic Sport: Blocking the Internet
Olympics-Wear ox pendant to avoid rat clashes, leaders
One couple juggles two kids and four jobs; a rebate check is their only relief.
One family struggles to maintain company, as personal savings dry up.
One million dollars to be win by Friday. Try you luck
One woman risks her own financial future to care for her grandparents.
Owner's delight as scientists produce five clones of pet pooch
Oxygen bottle damages Qantas aircraft
Packet pioneer
Pain at the Pump Roils Presidential Campaigns
Palin show criticised on accuracy
Paris Hilton's mom takes offense at McCain's humor
Phoenix diary. The team is under pressure to get results on Mars
Police hunt stolen rare shark
Police killed in west China ahead of Games
Pool Parasite Infections on the Rise
Primate warning. Beware of gorillas!
Primates 'face extinction crisis'
Private plane travel to be banned
Punk progeny launches "Terrorist" clothing line
Research shows a mother's brain reacts positively to infant's smile.
Rig dumps tons of dirt when nature calls driver
Riposte to "Eat, Pray, Love" hooks studio deal
Roosevelt revisited - 100 months to halt dangerous climate change
Russian stocks take hit as govt. looks to nationalize steel, oil companies.
Ryan Seacrest survives California shark attack
S. America: To the Brink of War and Back
S. Koreans fire water cannons at Bush
Secret deal kept British troops out of Basra
See how this family of six keeps their grocery bill at $350 a month.
Sex and the city forbidden,
Sex link' to French oyster rout
'Sex link' to French oyster rout
Sexual strength youÆd never dreamt of. Get it now
Sheen 'highest paid US TV actor'
Shia LaBeouf recovering after hand surgery
Should a baby be risked to save her sister?
Six month delay over refund of bank charges $800 bank charges for 8p overdraft
Small Businesses Feeling the Squeeze
Social networking sites have lots of users, but no one seems to be buying.
Sony goes solo in music venture
SpaceX launch fails a third time
Staff urged to dress down, stay cool as U.N. heats up
Star Wars' George Lucas on thrill of making Clone Wars
Star Wars model raises $350,000
Statins reduce memory loss
Student charged ?800 for going 8p into the red
Study shows: Golf Holes Bigger to Athletes
Superheroes Get Sandy
Take look inside the surreal and ultra-clean world of the silicon manufacturing plant.
Take you chance, win new car!
Taking Viagra daily exceeds menÆs strength, new research says
Teenage Mutant Ninja NARC
Tehran says it launched nuke missile
Ten to watch
Terminator Salvation, fourth Terminator film previews
Thailand bans Grand Theft Auto IV
The bloody murderer is arrested at last
The decline of primates shows time is running out
The hits and misses of his leadership of Microsoft
The humble mobile phone become a multimedia, multi-function monster
The importance of being there
The mortgage mess has plunged some American families into crisis
The sea creature giving Britain's olympic sailing squad a boost
The three New Jersey brothers delight teens with fun, wholesome music.
Three children jailed for armed holdup
Tips and resources so you can make better decisions about elder care.
Tips by 'America's Cheapest Family'
Torture widespread in Palestinian jails
Tropical Storm Edouard moving toward Texas coast
Turkey investigates deaths of 27 babies in 2-week period at Ankara hospital.
Two planes in airport collision
Typhoon in Taiwan devastates city
Urgent! Strong quake hits China
US beef unsafe for consumption
US hearing for 'al-Qaeda' woman
US Potatoes unsafe for consumption
US surgical errors cost $1.5 billion a year: report
Vet Aids Endangered Shark
Victoria Beckham is descendant of comrade of Marx
Video websites 'must vet content'
Virgin Galactic shows off mothership space craft
Virgin territory for ISPs
Vitamin C 'slows cancer growth'
Wall-climbing robots have been developed by scientists in America.
War, Spying and Party Game Delusions
Was there a deal to keep the British out of the Basra battle?
Watchdog gives banks more time over complaints
West Nile virus cases reported in California
Western wealth poses dilemma for Muslim islanders
What has melon liqueur got to do with Microsoft?
What Is Microsoft So Afraid Of?
Whoopi Kissed a Girl and She Liked It
Why mass hysteria is the exception -- not the rule.
Why Microsoft's next-gen software is called Midori
Why the future is in your hands
WiFi will work everywhere. Find out
Wildlife: A luxury we can live without?
Will nearly all Americans be obese by 2030? Diet experts have their say.
Woman Attacked by Beau's Pitbull
Woman gives birth to 18th child
Woman Survives Bear Attack
World's Hottest Water Found
World's oldest joke traced back to 1900 BC
World's smallest snake discovered
X Files fails to make UK impact
Yahoo board wins investor vote
Yankees plane crashes over Minnesota
Yard Work and Leather is just one of many new candle scents for men.
You New Credit, No
Your Mortgages Questions Answered
You're under a vest! German policewomen get 'bullet-proof bra'
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Aggrevated Identity Theft Law in Action
    There are so many interesting angles to the story this week about a case in Tucson, Arizona. The conviction actually went down in March 200...
  • More Merger Malware Wachovia Wells Fargo
    Today I received a message from Robert K. Steel, the President and CEO of Wachovia Bank. Actually I received several hundred messages from ...
  • Italian Court declares itself Friend of Pirates (or does it?)
    I couldn't believe this one. The Associated Press reported yesterday that Italian high court says file-swapping is not illegal . In this...
  • Securing Cyberspace in the 44th Presidency: Part Two
    Yesterday I provided some context for the Center for Strategic and International Studies report which was published yesterday: Security Cyb...
  • Radical Muslim Hackers Declare CyberWar on Israel
    This weekend more than 300 Israeli websites have been defaced in a period of 48 hours. In a website "defacement" a hacker violate...
  • AffPower Indictments Scare Affiliates!
    Today I heard the news that the "AffPower" drug network is being shut down, starting with 18 arrests in Texas, Florida, Colorado, ...
  • Paunch and the BlackHole/Cool Exploit Kit
    After months of speculation, the creator of the Blackhole exploit kit can be demonstrated to be in custody. As usual with all things Russia...
  • Bank of America Demo Account - DO NOT CLICK
    Beginning on November 25th, the UAB Spam Data Mine has been receiving messages claiming to be from Bank of America which will explain to us ...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile