Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 15 October 2008

SanCash (Affking) taken down in New Zealand

Posted on 21:03 by Unknown
It was great of the Federal Trade Commission to up an arrest that can be announced at this years eCrime Researchers Summit that I'm attending this week in Atlanta. Right after the afternoon break, a spam researcher from McAfee shared the good news with me: the New Zealand government and the Federal Trade Commission had both taken action againt AffKing / SanCash.

SiL from I Kill SPammers did a column in his blog back on March 3, 2008 called On The Trail of SanCash and Infinity Secure. At the end, he mentions his evidence linking SanCash to GenBucks, Tulip Labs, and Elite Herbal. He mentions that besides SanCash in India, there were representatives located in Christchurch, New Zealand, and issues a warning:


SanCash: your days as a sponsor of illegal spammers are numbered. Spammers in the SanCash Program: we will find you and you will lose everything.


Apparently SiL was right. According the FTC and New Zealand documents, the ring was actually run from Australia and the United States, but had links to ChristChurch. Here's the FTC's intro to the topic from their "Memorandum Supporting Plaintiff's ex parte Motion for a Temporary Restraining Order with Asset Freeze, Other Equitable Relief, and Order to Show Cause Why a Preliminary Injunction Should not Issue":


The FTC asks the Court to take immediate action to shut down an international "spam" enterprise that deceptively markets and sells bogus "male enhancement" pills and "generic" prescription drugs that are falsely claimed to be FDA-approved. Defendants' ongoing deceptive product sales are defrauding consumers out of millions of dollars, and the network of "spammers" that they pay to promote their product is causing considerable harm. Despite taking great efforts to avoid detection, the evidence shows that Australia-based Lance Atkinson and U.S.-based Jody Smith control, and profit from, this operation.

This enterprise -- which operates on the Internet under the name "AffKing" -- is responsible for likely billions of illegal commercial e-mail messages and is one of the largest spam organizations in the world. The FTC has received over three million complaints regarding spam messages connected to this operation. The spam messages sent on behalf of the operation falsify information that would identify the true sender in violation of the federal CAN-SPAM law regulating e-mail marketing. The messages also illegally fail to offer a mechanism by which consumers can opt-out from receiving further email messages.


The FTC had previously placed a permanent injunction ordering Lance Atkinson to cease making false claims about "herbal" products and utilizing illegal spam messages. If the name Lance Thomas Atkinson was familiar, it should! He and his colleague Michael John Anthony Van Essen were charged in the Global Web Promotions Pty Ltd case in 2004, which was called, on April 29, 2004, in this FTC Press Release, "the first criminal action under CAN-SPAM". The FTC had, at that time, received 399,000 email messages that they linked back to Global Web Promotions. Global Web was at that time selling a diet patch and a "Natural Human Growth Hormone" product, which sold at $80 and $74.95 each. Files related to that case may be found Under FTC File No 042-3086, which ended on September 20, 2005 with an order for the pair to pay $2.2 Million dollars. ($490,280 for selling bogus products, and $1,709,982.74 for sending illegal spam).

The current FTC case, FTC File No 072 3085, is against Lance Thomas Atkinson, Inet Ventures Pty Ltd, an Australian proprietary company, Jody Michael Smith, Tango Pay Inc., a Delaware corporation, Click Fusion Inc., a Delaware corporation, and TwoBucks Trading Limited, a Cyprus limited liability company.

The players in the case and their roles, seem to break down like this:

Lance Atkinson, aka "SanCash", sold herbal products and hired spammers to promote them from October 2006 through December 2007. He controlled the website "sancash.com", where his "affiliates" could log in to check their earnings.

The New Zealand Police have many chat logs of Lance talking with his co-conspirators, including one where he recruits Roland Smits to help him run Global Web Promotions. In the chat, Atkinson says "well hopefully it doesn't end in the FTC again."

Other excerpts from the log include Shane telling Lance things like "I have a dude in India who employs 50 people to manually spam people from gmail / hotmail" and "The Russians want to do some serious spamming this weekend".

Just in his ePassporte account, Atkinson received over $1.7 million from the Genbucks account, and transferred over $1.8 Million to others to cover their commissions.

Despite living in Australia, Lance logged in regularly to his "sancash@gmail.com" email address from his home IP.

Things started heating up in December 2007, when an intercepted chat message reveals Shane telling Lance "I had bbc world call my home. i think you need to stop spamming asap."

The Archive.org Wayback machine has archives of sancash from June 29, 2007 to December 11, 2007.

After that time period, Lance partnered with his new US buddy, Jody Smith, to form "affking.com", which replaced the sancash site. Affiliates were paid for their spam services on behalf of "King Replica" and "VPXL" male enhancement pills, as well as "Target Pharmacy" and "Canadian Healthcare".

Revenues for the new operation exceeded $500,000 per month only in payments from Visa. MasterCard charges would presumably make the payment even higher.

Tango Pay received $3.3 Million between September 2007 and May 2008.

Jody Smith ran Tango Pay and Click Fusion operations, using the fake names "Gerald Causey" and "Nicholas Santos"

In addition to the FTC charges, Lance and Shane Atkinson and Roland Smits, are being fined $200,000 by the New Zealanders. More details from New Zealand can be found in this Scoop Politics article.

Chat logs obtained by the New Zealand police reveal that Lance's brother Shane contorlled the company Genbucks.

This weekend, we'll examine our UAB Spam Data Mine to see what types of volumes we may have been dealing with, and some of the domains that were used in the scam.
Read More
Posted in | No comments

Saturday, 4 October 2008

Need help with your debt? Ask the Panamanian Russians for help!

Posted on 09:36 by Unknown
Has the current economic crisis caused you personal debt problems? As a cybercrime researcher I'd like to make one recommendation. If you need help with your debt, please DO NOT turn to Russian spammers who use Chinese domain name registrars to create domains they claim to host in Panama.

Today I decided to choose one of the more prevalent spam campaigns and see what was behind it. For some time now we've been seeing a spam campaign that has random words forming the Subject line, one of which will be "debt" or "credit", such as:

reducing debt
science of debt elimination
secured debt consolidation
south carolina debt consolidation
student debt consolidation
student loan debt
student loan debt consolidation
tax debt
tenant debt consolidation
the best way to get out of debt
third world debt
tips on how to get out of debt
tips to get out of debt
to get out of debt

There are three main variations of this spam currently. The first has messages that look like this, and point to a real domain name:


Its time to completely eradicate your debts!

ELIMINATE your carddebts and ALL other unsecured debts

Visit www.kneeddawpresent.com

* NO more payments to creditors
* YOUR long term credit will NOT be affected.
* NO confrontation's

Visit www.kneeddawpresent.com


* 10K minimum combined debts required for eligibility.
* US residents only.



This family, which I call the "Visit group", is currently spamming these websites, some of which have to be typed, because the criminal has placed [DOT] in the website name, such as www.bdstfirstcredit[DOT]com.

www.bastfirstcredit.com - 220.248.185.10 - ONLINENIC
www.bbstfirstcredit.com - 220.248.185.10 - ONLINENIC
www.bcstfirstcredit.com - 220.248.185.10 - ONLINENIC
www.bdstfirstcredit.com - 220.248.185.10 - ONLINENIC
www.bfstfirstcredit.com - 220.248.185.10 - ONLINENIC
www.expatpenpresent.com - 200.63.43.3 - XIN NET
www.gustyekeliving.com - 200.63.43.3 - 35 Technology Co., Ltd
www.kneeddawpresent.com - 200.63.43.3 - HICHINA ZHICHENG TECHNOLOGY
www.scotsoffserious.com - 200.63.43.3 - HICHINA ZHICHENG TECHNOLOGY
www.smokyoleclean.com - 200.63.43.3 - XIN NET
www.stonezitequal.com - 200.63.43.3 - XIN NET
www.tonesprogreat.com - 200.63.43.3 - HICHINA ZHICHENG TECHNOLOGY
www.vineswarloose.com - 220.248.185.10 - XIN NET
www.wipedeonearly.com - 200.63.43.3 - XIN NET
www.zestfirstcredit.com - 220.248.185.10 - ONLINENIC

So, this group of domains, all linked by common spam bodies, uses four different ICANN Registrars, but only one DNS server pair (NS1.WELDNS.COM / NS2.WELDNS.COM) and only two hosting IP addresses. 200.63.43.3 is hosted on Panamaserver.com and 220.248.185.10 is hosted in China on a network that is listed as "Changde-cdcnczxjdia".

Those registered on ONLINENIC and hosting in Changde, Hunan province of China, are registered to the name Shestakov Yuriy, who uses the email address alexvasiliev1987@cocainmail.com and the phone number +7.9218839910

Those registered on XIN NET and hosting on Panamaserver.com were registered by FANJIE in fujiansheng, china with an email of li_xiang253@tom.com.

Those registered on HICHINA and hosting on Panamaserver were registered by HANXIAOWEN with the email 2514862@qq.com - but they still use the DNS "NS1.WELDNS.COM" which is also used by the XIN NET and the ONLINENIC domain names!

That's the "Visit Group".

The second group is the "LiveFileStore.com" group. These emails all contain a spam body that looks like this:


Clear all your Debt. Save $1000s.Free Debt Analysis. No obligation.

http://tfe7ta.bay.livefilestore.com/y1pFg8blopfnoudOpHPXbKKZztaQP5QODFIxxBDAuUB0xO_hdJoJ33CGzn6hEFg8itiAyBpm7oDoSs



With many different "line one" texts, such as:

Prompt Debt Collection Services We are professional, Contract Now!
Get debt relief & start fresh!Helped thousands of clients
Get rid of credit card debtStop garnishments and calls
We sell debt portfolios and workwith new buyers daily
Eliminate Your Debt!Credit Cards, Medical Bills, Loans.

etc. etc.

The URLs point to a page on LiveFileStore.com which does an "autoforward" to another domain. All of them I reviewed today forwarded to this location:

http://platydeyember.com/

So, let's see what that domain is all about:

Registered on XIN NET TECHNOLOGY, this domain was registered to WANGQIHOW using the email "limian_changshi@sina.cn". Its hosted on the IP address 200.63.43.3, Panamaserver.com.

We're actually receiving many "non-debt" spams that use the LiveFileStore.com auto-forwarding trick. Some other examples would be,

Online Casinos, such as pages forwarding to:
http://zombileimound.com/
which was registered on XIN NET TECHNOLOGY and is hosted on PanamaServer.com on the IP address 200.63.43.3, and was registered by limian_changshi@sina.cn.

King Replica watch spam, such as pages forwarding to:
http://lookmyal.com/
which is unrelated to the others, and uses javascript obfuscation to hide its redirection point.


The third group of "debt spam" are the ones using advertisements on "live.com". This group uses spam that points to a "spaces.live.com" url, which contains an advertisement such as this one:



Clicking on these visual ads takes us to domains such as "windstensafe.com", which was registered on XIN NET TECHNOLOGY, is hosted on 200.63.43.3 on PanamaServer.com, and is regsitered to "li_xiang253@tom.com", using the DNS servers NS1.WELDNS.COM and NS2.WELDNS.COM.

Research into PanamaServer.com shows that they are hosting a wide assortment of criminal domains. Qualified researchers are welcome to request a list of more than 2700 domain names hosted there, including many domains registered by Russian named individuals, and using Nameservers ending in ".ru".

I'll let you know if PanamaServer gives me any answer to my queries about these domains:


abuse@panamaserver.com
El cangrejo, 49
Panama
+507 263.3723
Read More
Posted in | No comments

Tuesday, 23 September 2008

Digital Certificate Spammer Goes for Google Adwords

Posted on 04:13 by Unknown
From late May until last week, the Digital Certificate Malware spammer has been targeting banking brands. That has changed with last week's attack on CareerBuilder, and now a new attack against Google AdWords which began Monday afternoon. Starting at 2:17 PM (US Central Time) the UAB Spam Data Mine began receiving copies of a new Digital Certificate spam for Google AdWords.

The fraudulent webpage encourages users to "download 128-bit Digital Certificate software and enjoy all Google Adwords services security", and features a large "Download now" button:



Thirty different email subject lines have been used so far:

Account Protection! Google Adwords Alert
Account Protection! Google Adwords is dedicated to protecting your privacy
Account Protection! Google Adwords pad lock and encryption features help to ensure you
Account Protection! Google Adwords Security and Identity Protection Newsletter
Account Protection! Google Adwords Security Update
Account Protection! Google Adwords Services
Account Protection! Google Adwords Services Contacts
Account Protection! How does Google Adwords protect my information?
Account Protection! How does Google Adwords protect my privacy and personal information?
Account Protection! Visit a Google Adwords Center
Account Protection! What is Google Adwords Security SSL?
Google Adwords - protect your account
Google Adwords Alert
Google Adwords Customer Service
Google Adwords fraud
Google Adwords Guards and Protects Your Information
Google Adwords is dedicated to protecting your privacy
Google Adwords pad lock and encryption features help to ensure you
Google Adwords Security
Google Adwords Security and Identity Protection Newsletter
Google Adwords Security News
Google Adwords Security Update
Google Adwords Services
Google Adwords Services Contacts
Google Adwords uses a wide variety of fraud
How does Google Adwords protect my information?
How does Google Adwords protect my privacy and personal information?
What is Google Adwords Security SSL?

Regardless of the subject, each email stresses the importance of having a 128-bit SSL security, and says that browsers which do not have it will not be able to login to Google Adwords after September 24th.

Here's one example:


Attention GOOGLE ADWORDS Customers!

For certain services, such as our advertising programs, we request 128-bit SSL security information which we maintain in encrypted form on secure servers.
We take appropriate security measures to protect against unauthorized access to our unauthorized alteration, disclosure or destruction of data.
Please download latest SSL protection certificate

Read more>>

Unprotected browsers will not be able to Log in after September 24, 2008
Sincerely, Jenna Hooper.

2008 Google Adwords, Developing new services



The name at the end has no meaning within Google, and in fact we have seen 299 unique names listed so far, so there is a very high likelihood they are being randomly generated.

So far there are five domain names associated with this attack (we've requested that Register.com shutdown the domains already):

adwrss.com
ggoocom.com
meyolev.com
mitroces.com
spaentri.com

The domains, which were all created on September 22nd, hide behind the "Domain Discrete" service which seems designed to protect criminals:

Example Registrant (adwrss.com):
Domain Discreet
ATTN: adwrss.com
Avenida do Infante 50
Funchal, Madeira 9004-521
PT
Email: 8b09659a0a141150016552e5e91485b1@domaindiscreet.com

The initial file which is downloaded is 6,144 bytes in size. This tiny file, which is only a "dropper" for the real malware proves the relationship between this and other recent digital certificate spam.

GoogleADwordscertSEtup.exe = MD5 54fc18040782d53c9dc7f8365fe26367
SPlusWachoviadigicert.exe = MD5 54fc18040782d53c9dc7f8365fe26367

This is NOT an exact match with last week's CareerBuilder malware, which was also 6,144 bytes, but had a different MD5 hash value, but which matched the recent RBC and SunTrust Bank certificates.

CertEmployersectorSSL.exe = MD5 1dee8e8c891727c0868aa9486165824d
RBCCer_509.exe = MD5 1dee8e8c891727c0868aa9486165824d
SSLSunTrustsetupclient6783492.exe = MD5 1dee8e8c891727c0868aa9486165824d

The Google Adwords malware will download an additional file, called "file.exe" which is the actual keylogger. This keylogger sends its stolen data to the Piradius Network in Malaysia. Admins are encouraged to report any traffic they see leaving their network headed to IP addresses on this block:

124.217.248/24

The current IP address is 124.217.248.174, but several IP addresses on this network receive stolen data for other keyloggers as well.

The Keylogger is "context sensitive". An analysis performed on the malware by UAB Student Brian Tanner indicates that it detects particular login events and sends the data using these patterns:

http://%s%s?user_id=%.4u&version_id=%s&passphrase=%s&socks=%lu&version=%lu&crc=%.8x
URL: sniffer_ftp_%s
ftp_server=%s&ftp_login=%s&ftp_pass=%s&version=%lu
URL: sniffer_pop3_%s
pop3_server=%s&pop3_login=%s&pop3_pass=%s
URL: sniffer_imap_%s
imap_server=%s&imap_login=%s&imap_pass=%s
URL: sniffer_icq_%s
icq_user=%s&icq_pass=%s

It is also known to steal "generic" login events for various webpage logins. A machine infected with this keylogger will basically send every type of login data to the criminals who are behind the scheme.

The malware is dropped with "rootkit" capabilities. This means that traditional Windows methods of detecting whether a file is present will fail. The malware uses some of the following filenames:

ntoskrnl.exe
trust.exe
9129837.exe
new_drv.sys <=== a key part of the Root Kit

As with previous versions of Digital Certificate malware, the web pages for these domain names are hosted via the Botnet which the malware creates. For example, at this moment, the IP addresses resolving for adwrss.com are:

116.127.169.178, <= Hanaro Telecom, Korea
121.125.52.212, <= Hanaro Telecom, Korea
121.137.245.201, <= KorNet, Korea
121.175.13.103 <= KorNet, Korea
220.88.91.61, <= KorNet, Korea
75.51.103.215, <= AT&T, Saginaw, Michigan
79.117.195.143, <= RDSNet, Romania
93.1.15.7, <= Groupe N9uf Cegetel, Paris France
99.140.183.32 <= AT&T, Chicago, Illinois
99.227.84.87 <= Rogers Cable, Canada

But this pool shifts every few minutes. Hundreds of machines are part of this "hosting botnet".
Read More
Posted in | No comments

Monday, 22 September 2008

Governor Palin's Email: Security Questions in the Facebook Age

Posted on 04:25 by Unknown
Think about how much information the average FaceBooker or blogger shares about himself online. Now consider this, Governor Sarah Palin's Yahoo! email address allowed a password reset by knowing the answer to three Security Questions:

What is your birthdate?
What is your ZIP code?
Where did you meet your spouse?

The answer took a few Google searches. Every celebrity birthdate can be easily found online. Wasila, Alaska only has one ZIP code, and Palin is known to have met her husband in high school. The last took three guesses, with the correct answer being "Wasilla High", according to the post on 4chan.org's /b/ board by someone calling himself Rubico --(rubico10@yahoo.com)-- and now confirmed to be 20-year-old David Kernell who, Republicans are pointing out, is the son of a Democratic State Representative in Tennessee.



Kernell used a publicly available anonymizing server called "Ctunnel" operated by Gabriel Ramuglia in Athens, Georgia to try to protect his identity while hitting the Yahoo! website. Ramuglia is cooperating voluntarily with the FBI, who gained the CTunnel IP address from Yahoo's logs.

Let's consider for a moment some of the other security questions that have been offered as "Security" to some of our accounts. I've complained about these for years, because many of them are trivial to find for even a moderately "online" person. But again, let's consider these in the Facebook Age, and take a moment to reflect on how absolutely broken they are.

Here's a set of Challenge Questions from a very large American bank:

In what city were your born?
What is your favorite hobby?
What high school did you attend?
What was your high school mascot?
What is your father's middle name?
What is your mother's maiden name?
What is the name of your first employer?
What is the first name of your first child?
In what city was your father born?
When is your wedding anniversary? (Enter the full name of month)
In what city was your high school?

What High School? Gee - Look at my Classmates.com account.
First Employer? Not hard to find on my LinkedIn page.
Mother's maiden name? Hello? I run a genealogy mailing list for that surname!
Pet's name? My daughter has created a "DogBook" account for our pet!

So, what do you do when they ask you for a security question? Lie. Be dishonest. DO NOT TELL THE TRUTH. Be imaginative! And then write down your security questions and put them wherever you keep your birth certificate and passport.

Pet's name? Sir Gallahad the Cat-Snuffer
Favorite movie? Pippi Longstockings
Month of your wedding? Octuary
Mother's maiden name? Mugillicutty

In other words - they force you to HAVE a security question, but PLEASE don't make it something the rest of the world can find out with a Google search.

Of course, its worse if you are a celebrity. Governor Palin, after all, has a biography written that will answer most of these questions. The more famous you are, or in some cases the wealthier you are, the more likely it is you will be targeted.

As an illustration, we have the story from back in 2001 of Abraham Abdallah. A 32 year old New York City bus boy. A high school drop out. Who happened to be working his way through the Forbes magazine "400 Richest People" list. At the time of his arrest he had impersonated many of these famous people simply by knowing enough about them to be able to pass a telephone version of the Security Questions above.

See: Forbes rich list falls prey to high-tech fraudster
Read More
Posted in | No comments

Friday, 19 September 2008

CareerBuilder Latest Digital Certificate Malware Target

Posted on 06:05 by Unknown
CareerBuilder.com has joined the list of brands targeted by a criminal who spams the news of a new "Digital Certificate" said to protect customers. The spam emails claim that by running a Setup Wizard for the "Microsoft Windows Live ID Certification service", customers will protect themselves better. In reality, its a piece of malware called a "keylogger" that will infect customer machines, and share what they type with criminals seeking login credentials for this online job-hunters site.

The UAB Spam Data Mine received more than 400 copies of the spam yesterday, which used twenty different subject lines to advertise eleven webservers which would carry out the compromise when visited.

The dangerous websites look like this:



These are the subjects used in the nefarious emails:

CareerBuilder Commercial Customer Service
CareerBuilder Employer Security PlusSM
CareerBuilder Employer Services
CareerBuilder Employer Services Contacts
CareerBuilder is dedicated to protecting your privacy
CareerBuilder Job posting Services
CareerBuilder offers a full array of job posting
CareerBuilder Security and Identity Protection
CareerBuilder Security PlusSM Guards and Protects Your Information
CareerBuilder Security PlusSM uses a wide variety of fraud
CareerBuilder's pad lock and encryption features help to ensure you
Employer- CareerBuilder
Employer Services (CareerBuilder at Work)
Employer: With CareerBuilder Security Plus keeping your financial information
Employer: With CareerBuilder Security Plus we regularly monitor accounts through
How does CareerBuilder protect your information
How does CareerBuilderm protect your privacy and personal information
Visit a CareerBuilder Employer Center
What is CareerBuilder Employer Security PlusSM

The websites which are being used by these campaign are currently these:

bniyime.com
btyonro.com
chortom.com
ggolrrle.com
nbviox.com
njieme.com
vcveebnu.com
veeimor.com
vertumru.com

Update!


We reported the bad guys domains, and they were all shut down. Did that stop our bad guys? No. They went and made another batch! We've received 444 more copies of this campaign, now using THESE domain names, created today...

adwornee.com
beriupe.com
carertre.com
mieppeeei.com
pystshdoll.com
uscarer.com




UAB Computer Forensics personnel shared information of the new attack with CareerBuilders fraud prevention staff last night, and are working to terminate these domains immediately.

This is the latest in a family of "Digital Certificate" malware which we've been following since at least May. Some of the other columns we've done on this topic are listed here for your convenience:

Digital Certificate Alert! - May 6th article about the Colonial Bank, Comerica, and Merrill Lynch Digital Certificate Malware

Anti-Virus Products Still Fail on Fresh Viruses - August 12th article using the largely undetectable "Colonial Bank" Digital Certificate Malware as an example

Banking Digital Certificate Malware in Spam - August 30th article about the Bank of America and SunTrust Digital Certificate Malware

The domains above are hosted using "Fast Flux" technology, where the nameservers for the domains are constantly updated so that at any given moment there are at least ten "bot" computers (home users who are already compromised) who act as "Proxy web servers" to complicate the task of finding the actual server. We've already identified more than 200 IP addresses which will resolve these domains.

The same Fast Flux network is also hosting the "Walker & Sons" work-at-home scam to recruit "Money Mules". We warned about this type of scam last week in our column, "Work at Home . . . for a Criminal?". In the current Walker & Sons scam, which has used more than a dozen domain names all registered at "123-reg.co.uk", the Money Mule position is described like this:


Financial Coordinator

Job summary :

As a regional Financial Coordinator for our company you will be responsible to administer customer payments. You will help to fasten customer settlements and payments delivery. You will participate in internal and external company funds flow to speed up maturity of bills and other transactions. We need you to support our international team to be able to raise capital, attract more and more customers and expand into new economical markets and assist in the development of the company in general.

Responsibilities:

Deal with order and bill payment projects
* Receive and manage customer payments and any other business payments ( your existing accounts is to be used for the trial period of first three customer payments and a business account to be opened especially for the company needs in the future)
* Implement calculations regarding each new coming payment project to be dealt with
* Ensure the high-speed delivery of the funds to the final destination through Western Union or Money Gram quick collect services
* Be in a tight collaboration with the Head Office and report directly to the Finance Manager

Required skills and experience:
* Excellent project management skills
* Written and verbal communication skills
* High School diploma or equivalent preferred
* Excellent time management skills
* Excellent organizational and communication skills
* Capable of managing multiple projects and prioritizing deadlines

This position offers part employment (1-2 hours a day) and net 10% commission
If you are interested in this opportunity, click the Apply Now! button.


See the key phrases I've highlighted? You'll be receiving stolen funds into your personal checking account, and then using Western Union and Money Gram to withdraw these funds and ship them overseas. The proper title for this job is "Money Launderer", and holding this job is a crime. If you've been duped into this job, you need to contact law enforcement and explain your situation.

Some of the many domain names being used for this scam include:

salker.co.uk
salker.me.uk
salker.org.uk
swalkeer.me.uk
walkeer.co.uk
walkeer.me.uk
walkeer.org.uk
wallker.co.uk
walsoon.org.uk

CareerBuilder.com is a fine, safe place to find a job. But LOGIN TO THEIR WEBSITE by typing its URL in the browser. Don't follow links in email messages that take you there.
Read More
Posted in | No comments

Saturday, 13 September 2008

Internet Landfills: Praise for Brian Krebs

Posted on 04:32 by Unknown
Have you ever played Sim City? One of the problems a City Manager has to deal with is the disposal of waste. One of the possible solutions to that problem, is that you can create a landfill. The next problem is always where to put it, because your Sims will all complain and move away if you put it in their neighborhood. The same thing happens in real life. Google ("public meeting" and landfill) and you'll find tens of thousands of pages about meetings where Citizens get together to complain about the landfill that either is, or has been proposed to be, near their homes.

At the Birmingham InfraGard meeting on September 9th, I shared a presentation called "The Beautification of Internet Landfills". It started out with a couple definitions:

Internet Landfill
A network, hosting site, or registrar which attracts an entirely unlikely percentage of criminal activity
Beautification
Causing such landfills to reform their evil ways, or find themselves in legal trouble, or bandwidth impaired due to “public shunning


The meeting dropped a challenge to the Birmingham InfraGard members to become part of the "Neighborhood Watch" for the Internet.

When you see Badness, as a Corporate Security Professional, what do you do:

  • (A) Protect your own systems from the Badness?
  • (B) Share what you've learned with others, so they can be protected too?
  • (C) Trace the Badness to its origins and attempt to shut it down?
  • (D) Report the Badness to an appropriate Law Enforcement Agency?

The answer should be (E) - All of the above.

If you don't know HOW, I told the InfraGard members, then lets share information together to LEARN how.

One of the best ways to see an example of this in action is to follow the SecurityFix column by Brian Krebs of the Washington Post, and to examine and emulate the work of the fine researchers and security companies that he mentions frequently there.

We've all read the stories about the Russian Business Network, and how they were hosting criminal content all the way back to 2004, primarily under the guise of "Too Coin Software". RBN has been documented as the host of hundreds of child pornography websites, the notorious "iFrameMoney.biz" advertising network, and other badness such as the UrSnif Trojan and the SetSlice exploit. As recently as April 2007, they were infecting visitors with spam-based exploits being pushed by our friends Naked Britney and Paris. After making a ridiculous claim to have relocated to Panama (despite still being fed by upstream provider SBT Telecom in St. Petersburg), RBN continued to host its badness until they were outed by a journalistic campaign of exposure.

While there were some great publications shining a light on RBN, the one that seemed to me to have the greatest impact was the October 13, 2007 piece in Brian Krebs' must read column, SecurityFix.
"Shadowy Russian Firm Seen as Conduit for Cybercrime"
An Internet business based in St. Petersburg has become a world hub for Web sites devoted to child pornography, spamming, and identity theft, according to computer security experts...


Last week, Krebs declared that he was going on a campaign to unmask some other criminal organizations working openly and unafraid on the Internet.

Many people miss perhaps the best part of the first report, which was:

Report Slams US Host as Major Source of Badware

Following this report, the comments lit up like crazy, including, as we were shocked to see, Emil K., the owner of Intercage/Atrivo, who proclaimed his innocence, but also promised quick action on any criminal activity, and posted his ICQ number in case anyone had anything they wanted to report:

It was also interesting to see Konstantin Poltev rise to his defense in the comments, also proclaiming his own innocence, and providing his personal email address (kokach@estdomains.com) and promising to take quick action against any abuse on their site saying "We are going to perform a total clean-up, really total."

Another Intercage employee invited anyone who has problems for a tour of his data center, and reminded that you can email "abuse@intercage.com" with abuse complaints, or "russ@intercage.com" or "emil@intercage.com" if you have suggestions to improve their business.


Some of his columns since then have included:
Scammer-Heavy U.S. ISP Grows More Isolated which reminded us that Atrivo is Bad, and showed how Atrivo's various Internet Connectivity sources have been pulling the plug to avoid being associated with their evil.

A Superlative Scam and Spam Site Registrar which introduced the public to what security researchers have long known: Criminals like to register domains with EstDomain, because they ignore abuse complaints and let the crime continue.


EstDomains: A Sordid History and a Storied CEO which called attention to the well-known criminal career of Vladimir Tsastsin, the CEO of EstDomains, and asked the question if we should have a domain registrar who has done time for credit card fraud, document forgery, and money laundering.

Fake Antispyware Purveyor Doubles as Domain Registrar which focused on the practices of Klikdomains, aka Vivids Media GMBH, which has been behind many of the fake anti-virus and anti-spyware products. Because of Krebs work, Directi Internet Solutions, in India, has changed their business practices, and will no longer allow Klik to use its anonymizing service "PrivacyProtect" when registering domains. Directi's president, Bhavin Turakhia, shared with Krebs that nearly half of the 100,000 domains registered by Klik have eventually been suspended for abuse. After Krebs targeted their domains, Directi terminated another 21,000 sites in 48 hours!

The current series by Krebs resulted from some of the replies he received from another Must Read series, called Web Fraud 2.0, the week of August 17-23. The components of that series were:

Web Fraud 2.0: Cloaking Connections

Web Fraud 2.0: Validating Your Stolen Goods

Web Fraud 2.0: Digital Forgeries

Web Fraud 2.0: Distributing Your Malware



Interesting Sidebar found in WIRED along these same lines:
Online Posse Assembles, to Unmask Russia's Hackers
Read More
Posted in | No comments

Friday, 12 September 2008

Protecting Anonymized Religious Speech Overturns Nine Year Spam Sentence

Posted on 13:15 by Unknown
Last night I invited some friends to "Justice Science Movie Night". As my readers know my appointment at the University of Alabama at Birmingham (UAB) is in both the Computer & Information Sciences and the Justice Sciences departments. I arranged a viewing of a movie that takes a look at our corrections system in the United States and poses the question, "Are we trying to reform criminals? or appease society?" In the evenings movie, the demands of a near future society to feel that criminals had been adequately punished greatly outweighed the desire to rehabilitate the wrong-doers. The movie was called "Death Race".

When I hear about court rulings like the one today in the Virginia Supreme Court, I reach the levels of frustration that temporarily make me lack admiration for the fairness of our courts.

The case was the AOL Spamming conviction against Jeremy Jaynes. Jaynes was convicted in 2004, the first case brought using the new Virginia Anti-Spam Law. He was sentenced to nine years in prison as a result of sending tens of thousands of spam messages to AOL subscribers. Listed by Spamhaus as the #8 Worst Spammer on their Register of Known Spam Operations, Jaynes, who was also known as Gaven Stubberfield has been free pending appeal this entire time.

The case focused on 55,472 spam messages sent to AOL email subscribers on three days in July of 2003. According to a December 12, 2003 New York Times story, from July 11th to August 9th of that year more than 100,000 AOL subscribers clicked the "Report as Spam" button on emails sent by Jaynes.

(Image from CNN)

Although Jaynes lawyer in the original case was later convicted of obstructing justice and laundering money for a spammer and disbarred, it seems his client will walk. Currin helped his client hide $689,000 from the IRS, according to the charges of which he was found guilty.

In September of 2006, Jaynes appeal was heard by the Court of Appeals of Virginia, where it was pleaded before Judges Haley, Bumgardner, and Fitzpatrick that his conviction should be overturned on four grounds:
(1) Virginia lacked jurisdiction over the case, as he resided and performed his actions in North Carolina.
(2) the statute violates the First Amendment
(3) the statute violates the Dormant Commerce Clause
(4) the statute is unconstitutionally vague.

The judges found that the arguments had no merit.

The appeal did not question the facts that:
On July 16 he sent 12,197 pieces of unsolicited bulk email with falsified routing and transmission information onto AOL's proprietary network.
On July 19 he sent 24,172 similar emails, and on July 26 he sent 19,104 more.

The messages advertised either a FedEx claims product, a stock picker, or a history eraser.

Jayne's home contained CDs with 176 million email addresses and 1.3 billion user names, as well as zip disks containing 107 million AOL email addresses.

In the Court of Appeals, the claims of the First Amendment were thrown out, because "Each e-mail advertised a commercial product; none contained any content that was personal, political, religious, or otherwise non-commercial." Because the nature of his complaint was "in the nature of a trespass statute", the Court of Appeals declared that Jaynes lacked the standing to raise a First Amendment challenge.

Now, the Supreme Court has found that because the law prohibits anonymous internet emails, without making exception for Freedom of Speech issues, the law is unconstitutional. While the Commonwealth argued that that portion of the law was not in play here, the Supreme Court replied "A successful facial overbreadth challenge precludes the application of the affected statute in all circumstances."

In otherwords, because the Virginia law COULD be used to make it illegal to use an anonymous identity to send political or religious speech, the law is unconstitutional, and because it is unconstitutional, all charges brought under the law are also unconstitutional.

The Court did do us the favor of citing several other State laws which do properly restrict their application to commercial settings. Laws they held out as examples include:

Arizona Revised Statutes Article 16 Commercial Electronic Mail §44-1372.01

Arkansas Code Ann. Unsolicited Commercial and Sexually Explicit Electronic Mail Prevention Act § 4-88-603
California Bus. & Prof. Code § 17538.45

Florida Statutes, Electronic Commerce, Electronic Communications § 668.603

Idaho Code, Unfair Bulk Electronic Mail Advertisement Practices, § 48-603E

Illinois Comp. Stat. tit. 815 § 511/10, Electronic Mail Act

Indiana Code § 24-5-22-7, Deceptive Commercial Electronic Mail

Kansas Stat. Ann § 50-6, 107, Commercial Electronic Mail Act

Maryland Code Ann., Commercial Law § 14-3002
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Aggrevated Identity Theft Law in Action
    There are so many interesting angles to the story this week about a case in Tucson, Arizona. The conviction actually went down in March 200...
  • More Merger Malware Wachovia Wells Fargo
    Today I received a message from Robert K. Steel, the President and CEO of Wachovia Bank. Actually I received several hundred messages from ...
  • Italian Court declares itself Friend of Pirates (or does it?)
    I couldn't believe this one. The Associated Press reported yesterday that Italian high court says file-swapping is not illegal . In this...
  • Securing Cyberspace in the 44th Presidency: Part Two
    Yesterday I provided some context for the Center for Strategic and International Studies report which was published yesterday: Security Cyb...
  • Radical Muslim Hackers Declare CyberWar on Israel
    This weekend more than 300 Israeli websites have been defaced in a period of 48 hours. In a website "defacement" a hacker violate...
  • AffPower Indictments Scare Affiliates!
    Today I heard the news that the "AffPower" drug network is being shut down, starting with 18 arrests in Texas, Florida, Colorado, ...
  • Paunch and the BlackHole/Cool Exploit Kit
    After months of speculation, the creator of the Blackhole exploit kit can be demonstrated to be in custody. As usual with all things Russia...
  • Bank of America Demo Account - DO NOT CLICK
    Beginning on November 25th, the UAB Spam Data Mine has been receiving messages claiming to be from Bank of America which will explain to us ...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile