Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 16 May 2011

ACH Spammer switches to Shortened URLs

Posted on 06:41 by Unknown
For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domains in place for a campaign that we have been calling "NACHA Spam".

In this campaign, which we first wrote about in November 2009 (see: Newest Zeus: NACHA Electronic Payments, the criminals send emails suggesting that an Automated Clearing House (ACH) payment has failed. It is thought that this may be a method of screening recipients as only people who deal with money transfer on a regular basis would be familiar with NACHA as having authority over ACH payments.

In more recent versions of the campaign, including the one we wrote about in March 2011 (see: More ACH Spam from NACHA) we have seen dozens or even hundreds of newly created domain names used to host the malicious content.

Here's a sample of the email body:




The ACH transfer (ID: 1514969569958), recently initiated from your checking account (by you or any other person), was canceled by the Electronic Payments Association.

Rejected transaction
Transaction ID: 1514969569958
Reason for rejection See details in the report below
Transaction Report report_1514969569958.pdf.exe (self-extracting archive, Adobe PDF)

13450 Sunrise Valley Drive, Suite 100 Herndon, VA 20171 (703) 561-1100

2011 NACHA - The Electronic Payments Association




This morning's most popular subjects:

count | subject
-------+--------------------------
159 | ACH payment canceled
144 | ACH transfer rejected
143 | ACH payment rejected
143 | Rejected ACH payment
137 | Rejected ACH transaction
137 | ACH Transfer canceled
135 | Rejected ACH transfer
131 | Your ACH transfer
131 | ACH transaction canceled
130 | Your ACH transaction
(10 rows)

count | sender_email
-------+-------------
135 | risk@nacha.org
134 | alerts@nacha.org
134 | risk_manager@nacha.org
133 | alert@nacha.org
133 | admin@nacha.org
129 | transactions@nacha.org
124 | ach@nacha.org
122 | payment@nacha.org
120 | transfers@nacha.org
117 | payments@nacha.org
109 | info@nacha.org
(11 rows)

The "new" feature of today's spam campaign is that the criminals have begun using URL shortening services to do their redirection. Although this is new for the current campaign, we've seen it before. We wrote a technical report on the subject last fall called URL Shorteners Used by Online Drug Dealers.

So far this morning, we've observed 34 different URL shortening services in play on this campaign:

count | machine
-------+-----------------
116 | 2mb.eu
93 | p1nk.me
92 | 80p.eu
92 | mzan.si
90 | linkr.fr
88 | redir.ec
84 | 2.gp
80 | udanax.org
79 | ks.gs
71 | whir.li
71 | qr.net
70 | TinyBP.com
68 | spedr.com
68 | urlzip.fr
66 | tiny.ly
60 | shortn.me
48 | mx.vc
16 | urli.nl
11 | snipurl.com
6 | shrt.st
3 | gd.is
3 | virg10.com
2 | rurls.ru
2 | zipurl.fr
2 | lu2su.net
1 | nutshellurl.com
1 | surl.hu
1 | icy.tsd.to
1 | squeerl.net
1 | 3cm.kz
1 | tuit.in
1 | tqb.qlnk.net
1 | mi13.tk
1 | minu.me
(34 rows)

Some of these are

A full list of the more than 1,000 shortened URLs we've seen follows. Remember, these are MALICIOUS URLs. Don't go there if you aren't trained to deal with this kind of stuff.

count | machine | path
-------+-----------------+--------------
5 | spedr.com | /4y7SQSmS
5 | redir.ec | /tYvk
4 | snipurl.com | /27vmxz
4 | redir.ec | /EcPZ
4 | TinyBP.com | /15kcx
4 | 2mb.eu | /TUQBY8
4 | udanax.org | /ZPLf
3 | 2mb.eu | /W8Li1F
3 | mzan.si | /GwQm
3 | qr.net | /b4e0
3 | linkr.fr | /rLao
3 | tiny.ly | /dPnJ
3 | TinyBP.com | /53wi
3 | whir.li | /3z7g
3 | spedr.com | /G9mJzD3W
3 | 2mb.eu | /T2mMP3
3 | linkr.fr | /Jw7M
3 | udanax.org | /ZP0F
3 | urlzip.fr | /W0T
3 | 80p.eu | /ip
3 | virg10.com | /6t6
3 | qr.net | /b4ev
3 | 2mb.eu | /fKVGJX
3 | mzan.si | /N56x
3 | shortn.me | /igWl
...
(1080 rows)

(List truncated in interest of space -- for the full list of shortened URLs, click here: ACH.shortened.urls.txt.)

While we haven't followed every link, all that we have followed so far redirected to a fake forum page on mnuyspe.co.be (193.105.121.158) where "drive-by" exploits are attempted.
Read More
Posted in | No comments

Wednesday, 4 May 2011

Help stop the Osama bin Laden Videos on Facebook

Posted on 18:15 by Unknown
If you have teenage friends, or friends with poor security practices, you will probably notice that your wall has recently filled up with invitations to watch a video of Osama bin Laden being killed.



The behavior of this particular scam is too cause a link to be posted BY YOU on all of your friends' walls. (There is another popular one going around -- "See Who Viewed Your Profile" -- that behaves in the same way. Facebook confirms that there is no app that can do that, and encourages us to use the "REPORT" feature when we see that.

If you click the link, many geeky "redirections" (described at end of article) happen before you end up on a page that looks like this:



The danger starts if you click "Watch Video". DON'T DO IT!

While it would be interesting to explore the Cross Site Scripting vulnerability that allows this to happen, the more important thing to share is "what should a FaceBook user who sees this activity do about this offending post on their wall?"

Whenever you see something objectionable on your wall, the thing to do is REPORT IT!

Hover your mouse over a message on your wall, and a grey "X" will appear at the top right of the message.



When you click the "X" by the top right corner of the wall post, you are presented with a drop down menu. We're going to choose the bottom item -- "Report As Abuse"



Since the post is not "about me", we go to the lower section and choose "Spam or scam"




When we click "OK" we get an option to block the user. Since this is an innocent mistake by our friend, we don't want to "block" the friend, so just check the bottom box that says "Report to Facebook." If our friend is the sort of helpless, clueless individual that clicks on everything they see, eventually we would want to block this friend.



We get a nice "Thank you" from our friends at Facebook Security! These really help the team! They get the messages and use them to prioritize what things need to be addressed. If many reports are received for the same link, or about the same user, those things get addressed more quickly. Different types of reports go to different sub-groups so just because they are busy helping fight something like today's report doesn't mean that they ignore cyber-bullying.

Facebook WANTS YOU to report things that bother you. That's how they keep a clean neighborhood.

Help them help you. REPORT SCAMS!

Then take a moment more and send your friend a friendly message letting them know what's going on. They might want to let the rest of their friends know.

Facebook security has several recommendations, including a couple that I honestly wouldn't have thought of. (I'll put those first)


  1. Unlike the page which tricked you into showing fake video and report them immediately to Facebook. -- in addition to posting the message to your friends' walls, this tricky Facebook worm causes you to "Like" its page. The more "Likes" a page has, the more people are convinced it's real, so it is helpful to go "UNLIKE" the page. (if you've liked it, it will be a choice on the left side menu.)

  2. If a friend is posting suspicious messages to your wall, they may have malicious software on their computer, or may have clicked something bad themselves. Facebook Help says the best thing to do is tell your friend to contact Facebook Help.

  3. If YOU are the one posting the message, this Facebook Help post is for you: Wall posts were sent from my account, and I didn’t send them. It has helpful hints about anti-virus, not clicking on spam, and how to reset your password.

  4. Have up-to-date anti-virus software

  5. Keep an eye for messages that often feature misspellings, poor grammar and nonstandard English. If it doesn't look like a message your friend would type, REPORT IT! It may be related to malware or a malicious app that is using your friend's account!

  6. Do not open spam mails, including clicking links contained within those messages.

  7. Don’t copy and paste any scripts in your Facebook profile. Several scams have worked by encouraging you to paste something odd in your profile. Some of those scripts install apps, grant permissions, or make you do things you wouldn't want to do!

  8. If you’re using Chrome, make sure you don’t paste any scripts in your browser bar, as the browser tries to preload anything you type in the ‘awesome’ bar.




Geek Alert!

Here's an example stream of what happens if you click one of these links ...
In this case, the link is going to pass through several rounds of redirection, which we can see by doing a "wget" of the destination URL. A "301" command makes your browser move on to another web address without really adding any new content.

In the top example, the destination URL is tinyurl.com/3b8uayr

wget http://tinyurl.com/3b8uayr
Resolving tinyurl.com... 64.62.243.89, 64.62.243.90
Connecting to tinyurl.com|64.62.243.89|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: http://zamakoko.mo.tl/ [following]
--19:51:27-- http://zamakoko.mo.tl/
=> `index.html'
Resolving zamakoko.mo.tl... 174.122.44.67
Connecting to zamakoko.mo.tl|174.122.44.67|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: http://on.fb.me/jM9tNF [following]
--19:51:47-- http://on.fb.me/jM9tNF
=> `jM9tNF'
Resolving on.fb.me... 168.143.174.97
Connecting to on.fb.me|168.143.174.97|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: http://www.facebook.com/pages/0sama-tape/121566207922629 [following]
--19:51:59-- http://www.facebook.com/pages/0sama-tape/121566207922629
=> `121566207922629'
Resolving www.facebook.com... 69.63.189.16
Connecting to www.facebook.com|69.63.189.16|:80... connected.
HTTP request sent, awaiting response... 302 Moved Temporarily
Location: http://www.facebook.com/common/browser.php [following]
--19:52:05-- http://www.facebook.com/common/browser.php
=> `browser.php'
Connecting to www.facebook.com|69.63.189.16|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: unspecified [text/html]

[ <=> ] 11,771 --.--K/s
19:52:24 (1.40 MB/s) - `browser.php' saved [11771]

Which leaves us sitting here:

Read More
Posted in | No comments

Wednesday, 13 April 2011

Bold FBI Move Shutters COREFLOOD Bot

Posted on 21:25 by Unknown
In February 2005, John Leyden told the story of Joe Lopez a 42 year old businessman in Miami Florida who sued his bank after having $90,348 wired out of his account to Parex Bank in Riga, Latvia. The US Secret Service examined his computer and found that his system was infected with the Coreflood trojan.

Where did the money go? According to USA Today's Byron Acohido, someone named Yanson Arnold withdrew $20,000 of the money three days later.

The story was featured on NBC Nightly News on December 14, 2004, in a story called The Fleecing Of America which indicated the money had been stolen via the CoreFlood Virus.

In June of 2008, Joe Stewart, International Grandmaster of Malware Reverse Engineering, released a report called Coreflood/AFcore Trojan Analysis. He started his report by calling attention to five highlights:

1. One of the oldest botnets in continuous operation (+6 years)
2. Motive turned from DDoS to selling anonymity services to full-fledged bank fraud
3. Entire Windows domains infected at once (thousands of computers at some organizations)
4. Over 378,000 computers infected during 16-month time frame
5. Infected businesses, hospitals, government organizations, and even a state police agency

When Joe worked with Spamhaus back then to investigate an active C&C they found FIFTY GIGABYTES of compressed data, stolen over the course of two years, with a MySQL database that the criminal was using to track which information it had stolen from 378,758 unique bots over a period of 16 months. At one point, Joe's report shows "a major hotel chain" with over 7,000 infected computers, and a State Police agency with over 110 infected computers! Among the data stolen were 8,485 bank passwords, 3,233 credit card passwords, 151,000 email passwords, and 58,391 social networking site passwords. At that time, in 2008, the controller domains were: mcupdate.net, joy4host.com, and antrexhost.com.

Here we are in April 2011 -- almost three years later, and "antrexhost.com" is still an active C&C for the domain, which is still stealing money, despite being featured on NBC Nightly News, USA Today, and discussed by name by the White House's Howard Schmidt.

All of that may have come to an end today, as announced by today's FBI Press Release headline was Department of Justice Takes Action to Disable International Botnet. The botnet in question is known as Coreflood, and according to court papers released by the FBI's New Haven Field Office, a pair of Command & Control servers, located at 207.210.74.74 and 74.63.232.233 were controlling 2,336,542 infected computers as of February 2010. Of those, 1,853,005 were located in the United States.

207.210.74.74 is a server on the Global Net Access system, that hosted a domain called jane.unreadmsg.net. vaccina.medinnovation.org was the C&C name on 74.63.232.233


From the request for a Temporary Restraining Order filed by Assistant US Attorney Edward Chang:

12. The Coreflood Botnet was used, among other things,
to commit financial fraud. Infected computers in the Coreflood
Botnet automatically recorded the keystrokes and Internet
communications of unsuspecting users, including online banking
credentials and passwords. The stolen data was then sent to one
or more Coreflood C&C servers, where it was stored for review by
the Defendants and their co-conspirators. The Coreflood C&C
servers also stored the network and operating system
characteristics of the infected computers. The Defendants and
their co-conspirators used the stolen data, including online
banking credentials and passwords, to direct fraudulent wire
transfers from the bank accounts of their victims.

13. The victims of the fraud scheme described above
included, inter alia:

a. A real estate company in Michigan, from whose bank
account there were fraudulent wire transfers made in a
total amount of approximately $115,771;

b. A law firm in South Carolina, from whose bank account
there were fraudulent wire transfers made in a total
amount of approximately $78,421;

c. An investment company in North Carolina, from whose
bank account there were fraudulent wire transfers made
in a total amount of approximately $151,201; and

d. A defense contractor in Tennessee, from whose bank
account there were fraudulent wire transfers attempted
in a total amount of approximately $934,528, resulting
in an actual loss of approximately $241,866.

The full extent of the financial loss caused by the Coreflood
Botnet is not known, due in part to the large number of infected
computers and the quantity of stolen data.



Here are some of the hostnames that were used by Coreflood -- some dates are in the future, indicating that the bot had the ability to change to new names over time, to prevent just the sort of shutdown that occurred today:


C&C SERVER ASSIGNED 207.210.74.74
MonthPrimary Domain Alternate Domain
1/2011 a-gps.vip-studions.net old.antrexhost.com
2/2011 dru.realgoday.net marker.antrexhost.com
3/2011 brew.fishbonetree.biz spamblocker.antrexhost.com
4/2011 jane.unreadmsg.net ads.antrexhost.com
5/2011 exchange.stafilocox.net cafe.antrexhost.com
6/2011 ns1.diplodoger.com coffeeshop.antrexhost.com
7/2011 a-gps.vip-studions.net old.antrexhost.com
8/2011 dru.realgoday.net marker.antrexhost.com
9/2011 brew.fishbonetree.biz spamblocker.antrexhost.com
10/2011 jane.unreadmsg.net ads.antrexhost.com
11/2011 exchange.stafilocox.net cafe.antrexhost.com
12/2011 ns1.diplodoger.com coffeeshop.antrexhost.com

C&C SERVER ASSIGNED 74.63.232.233

Month Primary Domain Alternate Domain
1/2011 taxadvice.ehostville.com taxfree.nethostplus.net
2/2011 ticket.hostnetline.com accounts.nethostplus.net
3/2011 flu.medicalcarenews.org logon.nethostplus.net
4/2011 vaccina.medinnovation.org imap.nethostplus.net
5/2011 ipadnews.netwebplus.net onlinebooking.nethostplus.net
6/2011 acdsee.licensevalidate.net imap.nethostplus.net
7/2011 wellness.hostfields.net pop3.nethostplus.net
8/2011 savupdate.licensevalidate.netschedules.nethostplus.net
9/2011 wiki.hostfields.netmediastream.nethostplus.net
10/2011taxadvice.ehostville.com taxfree.nethostplus.net
11/2011 ticket.hostnetline.com accounts.nethostplus.net
12/2011 flu.medicalcarenews.org logon.nethostplus.net


In addition to the affidavit for the TRO, FBI Special Agent Kenneth Keller got a most unusual Seizure Warrant. With the warrant, they requested that the court compel the Registrars of the 24 domain names posted above to change the DNS settings for the servers, so that they would resolve to SINKHOLE-00.SHADOWSERVER.ORG and SINKHOLE-01.SHADOWSERVER.ORG.

To maximize the difficult of taking down this bot, the criminal spread his domain registrations all over the world. He used Wild West Domains (US-AZ), Above.com (of Australia), Big Rock Solutions (of Mumbai), LiquidNet (UK), Network Solutions (US-Virginia), Active Registrar (SIngapore), 1&1 Internet (Germany), TuCows (Toronto), Dotster (US-Washington), MyDomain, Inc (US-Washington), DomainRegistry.com (US-New Jersey), and Melbourne IT (which is Yahoo!'s registrar of choice), Mesh Digital (UK), Misk.com (US-NY), Moniker (US-Florida), and Directi (India).

Obviously a US court order has little impact in Mumbai or Singapore, so it was important to get this done when the "active" domains were US-based.

A "SinkHole" in the cyber security world is a trick that is invoked to cause botnets who are trying to talk to a criminal server to instead talk to a computer owned by a researcher or investigator. Its a great way for both measuring levels of infection and also for preventing the bad guy from being able to talk to his bots.

In this case, the sinkhole went beyond this though. Here comes the cool part from this Temporary Restraining Order issued by the Honorable (and very smart!) Vanessa L. Bryant.

WHEREAS the Government has shown good cause to believe: (a) that hundreds of thousands of computers are infected by Coreflood, known collectively as the "Coreflood Botnet"; (b) that the computers infected by Coreflood can be remotely controlled by the
Defendants, using certain computer servers known as the "Coreflood C&C Servers" and certain Domains"; (c) that, on or about April 12, 2011, the Government will execute seizure warrants for the Coreflood C&C Servers and the Coreflood Domains; (d) that the Government's seizuer of the Coreflood C&C Servers and the Coreflood Domains will leave the infected computers still running Coreflood; (e) that allowing Coreflood to continue running on the infected computers will cause a continuing and substantial injury to the owners and users of the infected computers, exposing them to a loss of privacy and an increased risk of further computer intrusions; and (f) that it is feasible to stop Coreflood from running on infected computers by establishing a substitute command and control server;

WHEREAS the Coreflood Domains are listed in Schedule A, together with the corresponding registry, registar, and domain name service ("DNS") provider (collectively, the "Domain Service Providers") used by the Defendants with respect to each of the Coreflood Domains;

WHEREAS the Government has shown good cause to believe that: (a) it is reasonably likely that the Government can show that the Defendants are committing wire fraud and bank fraud and are engaging in unauthorized interception of electronic communications, as alleged; (b) it is reasonably likely that the Government can show a continuing and substantial injury to a class of persons, viz., the owners and users of computers infected by Coreflood; and (c) it is reasonably likely that the Government can show that the requested restraining order will prevent or ameliorate injury to that class of persons;

(etc...)

Pursuant to the authority granted by 28 U.S.C. $ 566, the United States Marshal for the District of Connecticut ("USMS") shall execute and enforce this Order, with the assistance of the Federal Bureau of Investigation ("FBI") if needed, by establishing a substitute server at the Internet Systems Consortium...that will respond to requests addressed to the Coreflood DOmains by issuing instructions that will cause the Coreflood software on infected computers to stop running, subject to the limitation that such instructions shall be issued only to computers reasonably determined to be in the United States.


The Restraining Order gave blanket permission for anything that was using the DNS servers "NS1.CYBERWATCHFLOOR.COM" (204.74.66.143) or "NS1.CYBERWATCHFLOOR.COM" (204.74.67.143) to instead point to Special Agent Kenneth Keller's server 149.20.51.124.




Of course, some people may not want the Department of Justice telling their computer what to do. Because of that possibility, the FBI Press Release offers the option:

The Department of Justice and FBI, working with Internet service providers around the country, are committed to identifying and notifying as many innocent victims as possible who have been infected with Coreflood, in order to avoid or minimize future fraud losses and identity theft resulting from Coreflood. Identified owners of infected computers will also be told how to "opt out" from the TRO, if for some reason they want to keep Coreflood running on their computers.
Read More
Posted in | No comments

Friday, 8 April 2011

The Epsilon Phishing Model

Posted on 08:17 by Unknown
There is a saying "if you give a man a fish, he'll eat for a day, but if you teach a man to fish, he can feed himself for a lifetime."

In the case of the Epsilon email breach the saying might be "if you teach a man to be phished, he'll be a victim for a lifetime."

In order to illustrate my point, let's look at a few of the security flaws in the business model of email-based marketing, using Epsilon Interactive and their communications as some examples.

NOTE: Epsilon has released another Press Release to assure the public that no Personally Identifiable Information was released. The point of this article is not to argue that point, but rather to say there is something flawed in training users to click on links in emails.

Targeted Mailing Lists Help Avoid Detection



One of the advantages to phishers in using destination email addresses from the Epsilon Breach is that it helps keep their emails out of the hands of the security research and anti-phishing communities. Phishers, especially the less-skilled ones, tend to buy or steal large email address lists. Many researchers and anti-phishers (including us!) have managed to get their "spam-trap" email addresses onto those lists, which gives us visibility to spam campaigns. At UAB, as an example, we receive more than a million spam email messages each day. Some of these emails are phishing emails, which we then share with law enforcement and our strategic partners. Using a combination of automated and manual tools, we review tens of thousands of URLs each day to learn the addresses of the criminals new phishing sites. But what if a phisher only sends his phishing email to "confirmed" customer email addresses? This greatly reduces the ability of the anti-phishing community to respond to these phishing sites.


Guaranteed Delivery "From:" Addresses



Another thing a phisher would like to accomplish is to make sure that his message arrives without being blocked. Perhaps his victim is running spam filtering software. What is the first things that would be desirable? He would like his email to be sent from an address that will guarantee delivery. The easiest way to make sure that spam is delivered is to make sure that the "From:" address is in the potential victim's address book. This is why so many email messages arrive with the "from" and "to" addresses being the same. The spammers assume that you will have your own address in your address book, and therefore spam-filtering rules will not be applied to that address.

How else could they do that? Epsilon helpfully instructs their customers to add their email addresses to their address book. If a phisher now imitates those addresses, their email will bypass many phishing filters:



This email was sent to you by Ethan Allen.
Please add ethanallenstyle@email.ethanallen.com to your address book. This will ensure delivery to your inbox.


You are receiving this e-mail because you have requested information about CRESTOR(R) (rosuvastatin calcium) Tablets. Add CRESTOR@email.CRESTOR.com to your address book so future e-mails from us will not be marked as spam.


Add citicards@info.citibank.com to your address book to ensure delivery.


To ensure delivery to your inbox, please add Walgreens@email.walgreens.com to your address book.


This e-mail was sent to you by Eddie Bauer Friends. To ensure delivery to your inbox (not junk or bulk), please add info@eddiebauerfriends.com to your address book.


To ensure receipt of your Red Roof RediCard emails, please add redicard@redroofinn.bfi0.com to your address book.


To ensure receipt of our emails, please add targetdailydeals@targetnewsletter.bfio.com to your Contacts or Address Book.


etc . . .

So if the phisher makes his "from" address one of these "trusted" addresses, what happens?

Teach a man (or woman) to Click



One of the main pieces of advice that security professionals give to audiences and readers when they are speaking or writing about the topic of phishing is DO NOT CLICK ON LINKS IN YOUR EMAIL!

This is exactly the opposite advice that customers in the Epsilon databases receive. Epsilon and other email senders work on the theory of full-visibility communications. They know which email messages they send to which users, and they prove their value to the companies they represent by providing deep intelligence on the "click behavior" of the customers they email on behalf of those companies. Each link in an Epsilon email is customized with a URL that tells Epsilon who clicked on the link.

The whole point of emails from Epsilon is to get customers to click on links! I've truncated the URLs to protect privacy, but here's an example of one from Target. Clicking on this one takes me to their "Daily Deals. One Day Only. Always Free Shipping."

http://target.bfi0.com/145d56598layfousibljoi2iaaaaaaq5mirqsi2bcpuyaaaaa/C?V=bF9pbmRleAEBcHJvZmlsZV9pZAExMTM1MzYzMTY5AXppcF9jb2RlAQFfV0FWRV9JRF8BNjEwODA0MzQ5AV9QTElTVF9JRF8BMjE1NDI2MjUBZ19pbmRleAEBZW1haWxfYWRkcgFnYXJAYXNrZ2FyLmNvbQFfU0NIRF9UTV8BMjAxMTA0MDMxMjAwMDABcHJvZmlsZV9rZXkBMjU4NTkyMDM%3D&k2hXe6YFbcPUoDxGzFz1FA

which means I can get "juniors" denim skinny jeans for $12.49 today only! (which also means my daughter probably gave my email account to Target....hmmmm.....)

Here's a few examples:



Greetings from the National Geographic Online Store!

You are invited to join an exclusive community of individuals interested in National Geographic. As a member, you will...
* Help us choose catalog covers.
* Get sneak peeks at new products we=92re considering.
* Give valuable advice to people at National Geographic who decide what products we should offer.
* Get an insider=92s view of how our catalog and online store help fund the Society's Mission programs in the areas of research,

conservation, exploration, and education.

Click here to join the NG Store Insider panel. http://newsletters.nationalgeographic.com/1####....



Now through April 10, 2011

$50 OFF YOUR PURCHASE OF $250 OR MORE*
ENTER CODE > =

Txx3-4xxxxx-xx3xx2

HAUTE SALE
HURRY, ENDS TODAY!
40% OFF select styles. In-store & online.

http://bebeonline.bebe.com/#####...


Introducing the NY DEAL of the DAY! Extra savings on a must have style! In stores & online. Today only! The Hudson wide leg pant,
only $14.99 today only! Check our homepage every day of this sale for our new DEAL!

Shop now >
http://email.nyandcompany.com/1####...



Today Only! Save 30% at Gap Outlet

To get this coupon, copy and paste this url:
http://mail.goAAA.com/1#####...


------------------------
DAILY DEALS. ALWAYS FREE SHIPPING.
------------------------

Fun, cool stuff at amazing prices, available for one day only.


Shop Now:
http://targetenewsletter.bfi0.com/####...


BBC AMERICA NEWSLETTER
Doctor Who in America for the Very First Time
April 6, 2011
Doctor Who: Brand New Season
The Tardis is hopping the pond and the stakes have never been higher. =

WATCH THE EXTENDED TRAILER
http://bbcamerica.bfi0.com/1####...


The statement for your account ending in 4616 is now available online.
Log in to Online Banking to view your statement and pay your bill.
Please visit
http://email.capitalone.com/1####...



The point of every one of those emails is HEY YOU! CLICK ON THIS LINK!!!


The Warnings & The Future



If you live in the United States and you have ever used a credit card, your inbox is already flooded with Epsilon notices, so I hesitate to show you very many. We've heard of warnings from more than fifty companies, and personally seen the warnings from at least:

1-800-Flowers begin_of_the_skype_highlighting              1-800-Flowers      end_of_the_skype_highlighting
Abe Books
AIR MILES Reward Program
Ameriprise Financial
Barclays Bank of Delaware (US Airways Dividend Miles MasterCard, DIRECTV Rewards, iTunes Rewards, LLBean etc... )
Beachbody
Brookstone
Capital One
Citibank (AT&T Universal Card, Exxon Mobile, Home Depot, Shell)
Disney Destinations
Eddie Bauer
Ethan Allen
Hilton Honors
Krogers
Lacoste USA
Marriott
McKinsey Quarterly
M&T Bank
New York & Company
Red Roof Inn
Soccer.com
Target
Tastefully Simple
TD Ameritrade
TIAA-CREF
Tivo
Verizon
World Financial Network National Bank (WFNNB) (Ann Taylor, Catherine's, Chadwick's, Eddie Bauer, Gander Mountain, HSN, Maurice's, Newport News, Peeble's, The RoomPlace, United Retail Group, Victoria's Secret, Woman Within)
Walgreens

The warnings are missing the point of MY warning. All of them assure you that they aren't going to ask you for your personal information, and that your personal information hasn't been lost, "only your email address."

They tell you though NOT TO OPEN EMAILS FROM PEOPLE YOU DON'T KNOW. I don't know anyone named "shellcreditcard@info.accountonline.com" and I certainly don't know anyone named "TargetNews@target.bfio.com"



Of course that also misses entirely the fact that ANYONE can make their "From:" email anything they would like it to be! Email is not a form of trusted communication! So, how does the end-user know that the email really came from a real sender? Its a growing problem. Certain vendors have had luck with certain large mail providers -- for example eBay and Gmail. Because eBay signs all of their outbound email with a "digital signature" and Gmail knows what digital signature eBay uses, Gmail will reject any email that claims to be from eBay but really isn't.

There is a whole association, The Online Trust Alliance, filled with great companies dedicated to trying to fix this problem, but where they stand right now is that acceptance has been limited, and "traditional" email solutions don't come out of the box with the ability to interact richly with these forms of signatures and authentications.

Imagine for example that you are a global brand with more than 500,000 employees. In order to "turn on" digital authentication, you have to make sure that every single email sent by any of your 500,000 employees has a valid "digital signature" that proves the email really came from you! On the other end of the spectrum, if everyone locks down their email clients to only allow emails that are signed and certified, emails from individuals like you and me are likely to be thrown away!

In the meantime, we're stuck with imperfect solutions -- the need of the corporation to get their messages delivered and clicked on -- and the need of the consumer to NOT CLICK on messages that may lead to malware infections.

One-Click Malware - Drive-By Infections



Kaspersky Labs had a recent headline on this topic: Malware in February: Cybercriminals Perfect Drive-By Tactics.

In most of the top reported malware for February, the infection method was to convince a user to click on a link which took them to a "poisoned" webpage -- one on which some hostile code was present that could take advantage of security flaws in the webpage visitor's browser, PDF reader, flash player, or other code to place malware on the visitor's computer. Kasperky's February Report showed more than 70 million times where a Kaspersky customer had tried to visit a website that would have infected their computer if they had not been blocked!

The Warnings in the Epsilon Breaches can't warn you of that though. If they gave you the advice I would give you, they would be saying "Please don't click on the things our marketing department sends you!" which would result in them losing their jobs.

I have to say that the Citibank group of warnings do have a form that I appreciate.



As a means of proving email is REALLY from them, they provide the final four digits of your account number, your name, and the year you joined their card program on all of their official emails. I have to say that I find this very effective.

Unfortunately, yet another problem at Bigfoot/Epsilon ruined my joy on this one for today:



The error tells me "Secure Connection Failed" "images.bigfootinteractive.com:443 uses an invalid security certificate ... This could be a problem with the server's configuration or it could be someone trying to impersonate the server."




It's probably just something wrong as they try to re-issue security certificates related to tightening up their shop, but still it sends the wrong message at a critical time for their company!
Read More
Posted in | No comments

Saturday, 26 March 2011

Kingpin by Kevin Poulson of WIRED

Posted on 23:55 by Unknown
I love to read, but it's been quite a long time since I had one of those "books I can't put down" evenings. Tonight was one of those nights. I had been delaying the start of reading "KINGPIN: How one hacker took over the billion-dollar cybercrime underground" not because I thought it would be a book I couldn't put down, but because honestly, I thought I knew the story already.

If you were interested in the hacking scene around the turn of the millenium, you would definitely know the name Max Butler. Max made a name for himself in the IDS world, helping with the earliest days of Snort, and running a database for IDS signatures called arachnIDS. I remember when Max went to jail the first time, chatting with my friend Dan Clemens of PacketNinjas, LLC, who was also into IDS systems and snort in a heavy way, about the arrest. It was troubling to see someone running a website called "WhiteHats.com" and ending up in jail. The version of the story I thought I knew was that Max had been asked by the Feds to help them patch their systems from the BIND bug that was so popular in 1998-1999, but that Max couldn't resist the urge to
put a back door into the patch.

White Hat Hacker in Court - April 13, 2000 - "Open source hacker "Max Vision" aided the FBI while allegedly cracking the Pentagon."

Max Vision: FBI Pawn? - May 8, 2001 - "FBI agents called him 'the Equalizer': a security expert and confessed hacker who infiltrated the electronic underground to help the Bureau. When he drew the line at bugging a friend, they threw the book at him."

Max Vision Begins 18-Month Term - July 5, 2001 - "Intrusion detection guru joins a growing hacker population in federal stir."

All of those stories are by Kevin Poulsen, who has "owned" this story from the very beginning.

The popular theory at the time was that Max had been sent to DefCon and was only charged with his crimes after refusing to be a snitch for the Feds at DefCon. See for instance this conversation thread from 2001, Max Butler AKA Max Vision-Iceman-Aphex Now Retired.

I've spoken to investigators at extremely large companies who actually used Max Butler to test the security of their systems as a Penetration Tester, only learning later that he was actually stealing from them at the same time!

In addition to remembering the story very well from the "old days," I also know the story as a friend of the NCFTA who has had the chance to meet and work with FBI Special Agent Keith Mularski. Keith's work, announced by the FBI in their October 20, 2008 press release, 'Dark Market' Takedown -- Exclusive Cyber Club for Crooks Exposed lead to the arrest of more than 50 cyber criminals who were in the credit card stealing and trading business. (More details on DarkMarket arrests are available from WIRED: Dark Market ring leader pleads guilty in London.

Like the more recent arrest of Albert Gonzales AKA Segvec Max has a long story of helping the Feds and working against them at the same time. Gonzales was a US Secret Service informant against the ShadowCrew, while simultaneously breaching the Heartland Payments systems, TJX, and many other places.

The difference though, was that while Gonzales was a two-timing crook who was playing the system, Max started off as a troubled soul who wanted desperately to be the hero, but couldn't resist the thrill of the hack.

Like I said, I thought I already knew the story. Reading Kevin's book brought out so many details I couldn't possibly have known though. Kevin did a great job getting into the early life of the characters, and exploring the formation of their personalities and motivations. As Kevin reels out the lives of the characters, its clear to see that there were several types of criminals in the stories. His ability to create a sympathetic protagonist out of a criminal who caused $80 Million in credit card fraud is a feat in itself.

This book belongs on the shelf next to Steven Levy's Hackers. If you haven't read it yet, pick a rainy Saturday and start early in the day, you aren't going to be able to stop until you get to the last page.


Order Kingpin from Amazon


Be sure to read more stories by Kevin at WIRED by following his Author Page at Threat Level and elsewhere.
Read More
Posted in | No comments

Monday, 14 March 2011

Federal Reserve Spam

Posted on 14:43 by Unknown
Last week the big malware-spreading spam claimed to be from NACHA and warned about problems with an ACH money transfer. The same bad guys are at it again, this week pretending to be the Federal Reserve bank.

The UAB Spam Data Mine has received more than 3500 copies of the spam email messages, primarily using the subject lines:

Wire Transfer #12976271232523 (a random number on each email)
Wire transfer 0430972006146 was canceled (a random number on each email)
Wire transfer was canceled
Wire transfer was rejected
Your Wire fund transfer
Your Wire Transfer
Your Wire Transfer #2491786220489 (a random number on each email)
Your Wire Transfer, ID544349843700 (a random number on each email)

The senders of the email message varied between one of five choices:

alert@federalreserve.gov
alerts@federalreserve.gov
fedwire@federalreserve.gov
info@federalreserve.gov
information@federalreserve.gov

As before, someone with a Yahoo email address had their account used on GoDaddy to register ".info" domains to be used in this campaign. This time, we have spam samples for 487 of them.

Both GoDaddy and Afilias have excellent abuse staffs, and the domains in question were quickly terminated.

count | machine
-------+----------------------------------
8 | A-WIREBLOG.INFO
8 | AWIRE.INFO
5 | A-WIRENOW.INFO
6 | A-WIREONLINE.INFO
11 | A-WIRESHOP.INFO
4 | A-WIRESITE.INFO
7 | A-WIRESTORE.INFO
8 | A-WIRETODAY.INFO
4 | BESTA-WIRE.INFO
10 | BESTD-WIRE.INFO
9 | BESTFEDERALWIRE.INFO
6 | BESTFEDWIRE-B.INFO
2 | BESTFEDWIRE-E.INFO
8 | BESTFEDWIRE-M.INFO
8 | BESTFEDWIRE-N.INFO
9 | BESTFEDWIRE-O.INFO
5 | BESTFEDWIRE-Q.INFO
10 | BESTFEDWIRE-R.INFO
4 | BESTFEDWIRE-T.INFO
14 | BESTFEDWIRE-U.INFO
7 | BESTFEDWIRE-Y.INFO
9 | BESTI-WIRE.INFO
5 | BESTP-WIRE.INFO
6 | BESTU-WIRE.INFO
8 | BESTWIREORGANISATION.INFO
4 | BESTWIREREPORTTRANSFER.INFO
5 | BESTWIRETRANSFERMONEY.INFO
6 | BESTX-WIRE.INFO
4 | BESTZ-ACH.INFO
7 | BESTZ-WIRE.INFO
11 | COPPER-WIRE-ORGANISATION.INFO
6 | COPPERWIREORGANISATION.INFO
8 | COPPER-WIRE-REPORT-TRANSFER.INFO
8 | COPPERWIREREPORTTRANSFER.INFO
5 | COPPERWIRETRANSFERMONEY.INFO
3 | CUSTOMWIREORGANISATION.INFO
13 | D-WIREBLOG.INFO
7 | DWIRECABLE.INFO
10 | DWIRECLOTH.INFO
10 | DWIREDIAMETER.INFO
8 | D-WIRE-FENCE.INFO
5 | DWIREFENCE.INFO
8 | DWIREFORMING.INFO
5 | D-WIRE.INFO
7 | DWIREMANUFACTURER.INFO
12 | D-WIRENOW.INFO
7 | D-WIREONLINE.INFO
3 | DWIRESHELF.INFO
9 | D-WIRESHOP.INFO
11 | D-WIRES.INFO
9 | D-WIRESITE.INFO
10 | D-WIRESTORE.INFO
9 | DWIRESUPPLIERS.INFO
6 | DWIRETECH.INFO
8 | D-WIRETODAY.INFO
7 | ELECTRICALWIRETRANSFERMONEY.INFO
9 | FEDERALWIREBLOG.INFO
8 | FEDERALWIRECABLE.INFO
7 | FEDERALWIRECLOTH.INFO
8 | FEDERALWIREDIAMETER.INFO
8 | FEDERAL-WIRE-FENCE.INFO
6 | FEDERALWIREFENCE.INFO
9 | FEDERALWIREFORMING.INFO
9 | FEDERAL-WIRE.INFO
6 | FEDERALWIRE.INFO
7 | FEDERALWIRENOW.INFO
5 | FEDERALWIREONLINE.INFO
6 | FEDERALWIRESHELF.INFO
6 | FEDERALWIRESHOP.INFO
6 | FEDERALWIRES.INFO
5 | FEDERALWIRESITE.INFO
8 | FEDERALWIRESIZES.INFO
8 | FEDERALWIRESTORE.INFO
9 | FEDERALWIRETECH.INFO
9 | FEDERALWIRETODAY.INFO
8 | FEDWIREANDBLUE.INFO
8 | FEDWIREANDSAVE.INFO
8 | FEDWIREANDSILVER.INFO
4 | FEDWIREANDSONS.INFO
12 | FEDWIREANDSOUL.INFO
2 | FEDWIREANDSTYLE.INFO
7 | FEDWIREANDTRAVEL.INFO
10 | FEDWIRE-BBLOG.INFO
8 | FEDWIRE-BE-CONNECTED.INFO
6 | FEDWIREBECONNECTED.INFO
10 | FEDWIRE-BE-COOL.INFO
7 | FEDWIREBECOOL.INFO
11 | FEDWIRE-BE.INFO
10 | FEDWIREBE.INFO
7 | FEDWIRE-B.INFO
8 | FEDWIREB.INFO
6 | FEDWIRE-BNOW.INFO
7 | FEDWIRE-BONLINE.INFO
8 | FEDWIRE-B-RICH.INFO
7 | FEDWIREBRICH.INFO
7 | FEDWIRE-BSHOP.INFO
3 | FEDWIRE-BS.INFO
7 | FEDWIRE-BSITE.INFO
6 | FEDWIRE-BSTORE.INFO
8 | FEDWIRE-BTODAY.INFO
5 | FEDWIRE-EBLOG.INFO
6 | FEDWIRE-E.INFO
8 | FEDWIREE.INFO
5 | FEDWIRE-E-MINOR.INFO
7 | FEDWIREEMINOR.INFO
6 | FEDWIRE-ENOW.INFO
9 | FEDWIRE-EONLINE.INFO
4 | FEDWIRE-ESHOP.INFO
9 | FEDWIRE-ES.INFO
10 | FEDWIRE-ESITE.INFO
5 | FEDWIRE-ESTORE.INFO
4 | FEDWIRE-ETODAY.INFO
11 | FEDWIRE-M-BASKETBALL.INFO
6 | FEDWIREMBASKETBALL.INFO
10 | FEDWIRE-MBLOG.INFO
4 | FEDWIRE-M.INFO
12 | FEDWIREM.INFO
13 | FEDWIRE-MNOW.INFO
4 | FEDWIRE-MONLINE.INFO
7 | FEDWIRE-MSHOP.INFO
3 | FEDWIRE-MS.INFO
3 | FEDWIRE-MSITE.INFO
3 | FEDWIRE-MSTORE.INFO
12 | FEDWIRE-MTODAY.INFO
6 | FEDWIRE-M-WARD.INFO
7 | FEDWIREMWARD.INFO
12 | FEDWIRE-NBLOG.INFO
9 | FEDWIRE-N.INFO
3 | FEDWIREN.INFO
5 | FEDWIRE-NNOW.INFO
4 | FEDWIRE-NONLINE.INFO
4 | FEDWIRE-N-SCALE.INFO
16 | FEDWIRENSCALE.INFO
6 | FEDWIRE-NSHOP.INFO
3 | FEDWIRE-NS.INFO
5 | FEDWIRE-NSITE.INFO
4 | FEDWIRE-NSTORE.INFO
11 | FEDWIRE-NTODAY.INFO
6 | FEDWIRE-OBLOG.INFO
5 | FEDWIRE-O-HENRY.INFO
7 | FEDWIREOHENRY.INFO
8 | FEDWIRE-O.INFO
5 | FEDWIREO.INFO
6 | FEDWIRE-ONOW.INFO
13 | FEDWIRE-OONLINE.INFO
11 | FEDWIRE-OSHOP.INFO
9 | FEDWIRE-OS.INFO
11 | FEDWIRE-OSITE.INFO
4 | FEDWIRE-OSTORE.INFO
8 | FEDWIRE-O-TICKET.INFO
5 | FEDWIREOTICKET.INFO
7 | FEDWIRE-OTODAY.INFO
9 | FEDWIRE-Q-AUDIO.INFO
5 | FEDWIREQAUDIO.INFO
9 | FEDWIRE-Q-AWARDS.INFO
10 | FEDWIREQAWARDS.INFO
7 | FEDWIRE-QBLOG.INFO
9 | FEDWIRE-Q-CELL.INFO
5 | FEDWIREQCELL.INFO
9 | FEDWIRE-Q-FEVER.INFO
9 | FEDWIREQFEVER.INFO
6 | FEDWIRE-Q.INFO
5 | FEDWIRE-Q-MAGAZINE.INFO
6 | FEDWIREQMAGAZINE.INFO
8 | FEDWIRE-QNOW.INFO
5 | FEDWIRE-QONLINE.INFO
8 | FEDWIRE-QSHOP.INFO
9 | FEDWIRE-QS.INFO
5 | FEDWIRE-QSITE.INFO
6 | FEDWIRE-QSTORE.INFO
12 | FEDWIRE-QTODAY.INFO
5 | FEDWIRE-RBLOG.INFO
5 | FEDWIRE-R.INFO
5 | FEDWIRER.INFO
8 | FEDWIRE-R-KELLY.INFO
3 | FEDWIRERKELLY.INFO
13 | FEDWIRE-RNOW.INFO
7 | FEDWIRE-RONLINE.INFO
3 | FEDWIRE-RSHOP.INFO
11 | FEDWIRE-RS.INFO
7 | FEDWIRE-RSITE.INFO
8 | FEDWIRE-RSTORE.INFO
5 | FEDWIRE-RTODAY.INFO
7 | FEDWIRE-TBLOG.INFO
6 | FEDWIRE-T-CELLS.INFO
12 | FEDWIRETCELLS.INFO
7 | FEDWIRE-T.INFO
9 | FEDWIRET.INFO
8 | FEDWIRE-T-MAGAZINE.INFO
6 | FEDWIRETMAGAZINE.INFO
4 | FEDWIRE-TNOW.INFO
9 | FEDWIRE-TONLINE.INFO
6 | FEDWIRE-T-PAIN.INFO
8 | FEDWIRETPAIN.INFO
8 | FEDWIRE-TSHOP.INFO
6 | FEDWIRE-TS.INFO
5 | FEDWIRE-TSITE.INFO
5 | FEDWIRE-TSTORE.INFO
14 | FEDWIRE-TTODAY.INFO
4 | FEDWIRE-UBLOG.INFO
11 | FEDWIRE-U.INFO
9 | FEDWIREU.INFO
12 | FEDWIRE-UNOW.INFO
12 | FEDWIRE-UONLINE.INFO
10 | FEDWIRE-USHOP.INFO
10 | FEDWIRE-US.INFO
5 | FEDWIRE-USITE.INFO
10 | FEDWIRE-USTORE.INFO
3 | FEDWIRE-UTODAY.INFO
7 | FEDWIRE-YBLOG.INFO
6 | FEDWIRE-Y-CAMP.INFO
7 | FEDWIREYCAMP.INFO
10 | FEDWIRE-Y.INFO
9 | FEDWIREY.INFO
6 | FEDWIRE-YNOW.INFO
7 | FEDWIRE-YONLINE.INFO
7 | FEDWIRE-YOU-CANT.INFO
8 | FEDWIREYOUCANT.INFO
6 | FEDWIRE-YOU.INFO
9 | FEDWIREYOU.INFO
9 | FEDWIRE-YOU-ROCK.INFO
10 | FEDWIREYOUROCK.INFO
2 | FEDWIRE-YOU-SAVE.INFO
4 | FEDWIREYOUSAVE.INFO
12 | FEDWIREYOUTUBE.INFO
5 | FEDWIRE-YSHOP.INFO
5 | FEDWIRE-YS.INFO
7 | FEDWIRE-YSITE.INFO
7 | FEDWIRE-YSTORE.INFO
8 | FEDWIRE-YTODAY.INFO
4 | FREEA-WIRE.INFO
7 | FREED-WIRE.INFO
9 | FREEFEDERALWIRE.INFO
8 | FREEFEDWIRE-B.INFO
7 | FREEFEDWIRE-E.INFO
9 | FREEFEDWIRE-M.INFO
5 | FREEFEDWIRE-N.INFO
7 | FREEFEDWIRE-O.INFO
2 | FREEFEDWIRE-Q.INFO
5 | FREEFEDWIRE-R.INFO
8 | FREEFEDWIRE-T.INFO
13 | FREEFEDWIRE-U.INFO
14 | FREEFEDWIRE-Y.INFO
7 | FREEI-WIRE.INFO
5 | FREEP-WIRE.INFO
8 | FREEU-WIRE.INFO
5 | FREEWIREORGANISATION.INFO
9 | FREEWIREREPORTTRANSFER.INFO
4 | FREEWIRETRANSFERMONEY.INFO
8 | FREEX-WIRE.INFO
7 | FREEZ-ACH.INFO
6 | FREEZ-WIRE.INFO
5 | GAUGEWIREORGANISATION.INFO
5 | GAUGEWIRETRANSFERMONEY.INFO
7 | I-MOBILE-WIRE.INFO
8 | IMOBILEWIRE.INFO
5 | IRONWIREORGANISATION.INFO
5 | IRONWIREREPORTTRANSFER.INFO
7 | IRONWIRETRANSFERMONEY.INFO
6 | I-WIREBLOG.INFO
10 | IWIREHOMES.INFO
8 | I-WIRE.INFO
7 | I-WIRE-INTERACTIVE.INFO
5 | IWIREINTERACTIVE.INFO
10 | IWIRENETWORKS.INFO
10 | I-WIRENOW.INFO
11 | I-WIREONLINE.INFO
7 | I-WIRESHOP.INFO
2 | I-WIRES.INFO
7 | I-WIRESITE.INFO
8 | I-WIRESTORE.INFO
14 | I-WIRE-TECH.INFO
5 | IWIRETECH.INFO
11 | I-WIRETODAY.INFO
7 | METALWIREORGANISATION.INFO
6 | METALWIREREPORTTRANSFER.INFO
6 | METALWIRETRANSFERMONEY.INFO
6 | MYA-WIRE.INFO
3 | MYD-WIRE.INFO
8 | MYFEDERALWIRE.INFO
12 | MYFEDWIRE-B.INFO
5 | MYFEDWIRE-E.INFO
13 | MYFEDWIRE-M.INFO
8 | MYFEDWIRE-N.INFO
10 | MYFEDWIRE-O.INFO
4 | MYFEDWIRE-Q.INFO
11 | MYFEDWIRE-R.INFO
11 | MYFEDWIRE-T.INFO
10 | MYFEDWIRE-U.INFO
11 | MYFEDWIRE-Y.INFO
7 | MYI-WIRE.INFO
6 | MYP-WIRE.INFO
5 | MYU-WIRE.INFO
12 | MYWIREORGANISATION.INFO
7 | MYWIREREPORTTRANSFER.INFO
9 | MYWIRETRANSFERMONEY.INFO
5 | MYX-WIRE.INFO
9 | MYZ-ACH.INFO
7 | MYZ-WIRE.INFO
4 | NEWA-WIRE.INFO
6 | NEWD-WIRE.INFO
5 | NEWFEDERALWIRE.INFO
12 | NEWFEDWIRE-B.INFO
5 | NEWFEDWIRE-E.INFO
12 | NEWFEDWIRE-M.INFO
7 | NEWFEDWIRE-N.INFO
7 | NEWFEDWIRE-O.INFO
8 | NEWFEDWIRE-Q.INFO
10 | NEWFEDWIRE-R.INFO
5 | NEWFEDWIRE-T.INFO
11 | NEWFEDWIRE-U.INFO
5 | NEWFEDWIRE-Y.INFO
6 | NEWI-WIRE.INFO
7 | NEWP-WIRE.INFO
18 | NEWU-WIRE.INFO
12 | NEWWIREORGANISATION.INFO
9 | NEWWIREREPORTTRANSFER.INFO
8 | NEWWIRETRANSFERMONEY.INFO
3 | NEWX-WIRE.INFO
6 | NEWZ-ACH.INFO
10 | NEWZ-WIRE.INFO
11 | PRECISIONWIREORGANISATION.INFO
3 | P-WIREBLOG.INFO
10 | PWIRECABLE.INFO
8 | PWIRECLOTH.INFO
4 | PWIREDIAMETER.INFO
8 | P-WIRE-FENCE.INFO
3 | PWIREFENCE.INFO
7 | PWIREFORMING.INFO
2 | P-WIRE.INFO
11 | PWIRE.INFO
9 | PWIREMANUFACTURER.INFO
8 | P-WIRENOW.INFO
9 | P-WIREONLINE.INFO
7 | PWIRESHELF.INFO
6 | P-WIRESHOP.INFO
7 | P-WIRES.INFO
12 | P-WIRESITE.INFO
7 | P-WIRESTORE.INFO
6 | PWIRESUPPLIERS.INFO
4 | P-WIRETODAY.INFO
6 | RESISTANCEWIRETRANSFERMONEY.INFO
7 | RIDINGTHEWIRE.INFO
12 | ROME-X-WIRE.INFO
9 | SILVERWIRETRANSFERMONEY.INFO
10 | SPOT-I-WIRE.INFO
11 | SPOTIWIRE.INFO
4 | STEEL-WIRE-ORGANISATION.INFO
9 | STEELWIREORGANISATION.INFO
3 | STEEL-WIRE-REPORT-TRANSFER.INFO
9 | STEELWIREREPORTTRANSFER.INFO
5 | STEELWIRETRANSFERMONEY.INFO
7 | THEA-WIRE.INFO
7 | THEDETROITWIRE.INFO
7 | THED-WIRE.INFO
3 | THEFEDERALWIRE.INFO
11 | THEFEDWIRE-B.INFO
5 | THEFEDWIRE-E.INFO
8 | THEFEDWIRE-M.INFO
7 | THEFEDWIRE-N.INFO
5 | THEFEDWIRE-O.INFO
7 | THEFEDWIRE-Q.INFO
6 | THEFEDWIRE-R.INFO
9 | THEFEDWIRE-T.INFO
3 | THEFEDWIRE-U.INFO
12 | THEFEDWIRE-Y.INFO
9 | THEI-WIRE.INFO
7 | THEP-WIRE.INFO
4 | THERIDEWIRE.INFO
2 | THEU-WIRE.INFO
11 | THEWIREDOGS.INFO
6 | THEWIREGUYS.INFO
6 | THE-WIRE.INFO
5 | THEWIREORGANISATION.INFO
14 | THEWIREREPORTTRANSFER.INFO
1 | THEWIRETRANSFERMONEY.INFO
10 | THEX-WIRE.INFO
10 | THEZ-ACH.INFO
6 | THEZ-WIRE.INFO
6 | TRAVEL-A-WIRE.INFO
10 | TRAVELAWIRE.INFO
12 | U-WIREBLOG.INFO
7 | UWIRECABLE.INFO
11 | UWIRECLOTH.INFO
9 | UWIREDIAMETER.INFO
7 | U-WIRE-FENCE.INFO
9 | UWIREFENCE.INFO
9 | UWIREFORMING.INFO
9 | U-WIRE.INFO
9 | UWIREMANUFACTURER.INFO
4 | U-WIRENOW.INFO
8 | U-WIREONLINE.INFO
9 | UWIRESHELF.INFO
7 | U-WIRESHOP.INFO
8 | U-WIRES.INFO
8 | U-WIRESITE.INFO
8 | U-WIRESTORE.INFO
5 | UWIRESUPPLIERS.INFO
6 | UWIRETECH.INFO
3 | U-WIRETODAY.INFO
6 | WALKINGTHEWIRE.INFO
12 | WIREORGANISATIONBLOG.INFO
10 | WIRE-ORGANISATION.INFO
5 | WIREORGANISATION.INFO
5 | WIREORGANISATIONNOW.INFO
9 | WIREORGANISATIONONLINE.INFO
6 | WIREORGANISATIONSHOP.INFO
5 | WIREORGANISATIONS.INFO
3 | WIREORGANISATIONSITE.INFO
9 | WIREORGANISATIONSTORE.INFO
6 | WIREORGANISATIONTODAY.INFO
7 | WIREREPORTCARDSTRANSFER.INFO
6 | WIRE-REPORT-CARD-TRANSFER.INFO
7 | WIREREPORTCARDTRANSFER.INFO
4 | WIREREPORTTRANSFERBLOG.INFO
11 | WIRE-REPORT-TRANSFER.INFO
6 | WIREREPORTTRANSFER.INFO
4 | WIREREPORTTRANSFERNOW.INFO
6 | WIREREPORTTRANSFERONLINE.INFO
4 | WIREREPORTTRANSFERSHOP.INFO
10 | WIREREPORTTRANSFERS.INFO
6 | WIREREPORTTRANSFERSITE.INFO
2 | WIREREPORTTRANSFERSTORE.INFO
7 | WIREREPORTTRANSFERTODAY.INFO
5 | WIRETRANSFERMONEYBLOG.INFO
13 | WIRE-TRANSFER-MONEY.INFO
7 | WIRETRANSFERMONEY.INFO
7 | WIRETRANSFERMONEYNOW.INFO
7 | WIRETRANSFERMONEYONLINE.INFO
7 | WIRETRANSFERMONEYSHOP.INFO
9 | WIRETRANSFERMONEYS.INFO
6 | WIRETRANSFERMONEYSITE.INFO
10 | WIRETRANSFERMONEYSTORE.INFO
1 | WIRETRANSFERMONEYTODAY.INFO
7 | WIRETRANSFERSTATIONMONEY.INFO
3 | X-CABLE.INFO
4 | XCIRCUITBOARDS.INFO
6 | X-CIRCUIT.INFO
7 | XCIRCUIT.INFO
5 | X-CONNECTION.INFO
6 | XELECTRICALCONDUCTOR.INFO
6 | X-FILAMENT.INFO
7 | XFILAMENT.INFO
8 | X-WIREBLOG.INFO
6 | XWIRE.INFO
10 | X-WIRENOW.INFO
11 | X-WIREONLINE.INFO
8 | X-WIRESHOP.INFO
3 | X-WIRES.INFO
2 | X-WIRESITE.INFO
6 | X-WIRESTORE.INFO
2 | X-WIRETODAY.INFO
13 | Z-ACH-ACCOUNTS.INFO
5 | ZACHACCOUNTS.INFO
10 | Z-ACHBLOG.INFO
8 | Z-ACH.INFO
9 | Z-ACHNOW.INFO
16 | Z-ACHONLINE.INFO
6 | Z-ACH-PAYMENT.INFO
10 | ZACHPAYMENT.INFO
5 | Z-ACH-PAYMENTS.INFO
6 | ZACHPAYMENTS.INFO
5 | Z-ACHSHOP.INFO
4 | Z-ACHS.INFO
8 | Z-ACHSITE.INFO
6 | Z-ACHSTORE.INFO
4 | Z-ACHTODAY.INFO
4 | Z-ACH-TRANSACTIONS.INFO
10 | ZACHTRANSACTIONS.INFO
5 | ZCABLE.INFO
9 | ZCIRCUITBOARDS.INFO
9 | ZCIRCUIT.INFO
6 | ZCONNECTION.INFO
5 | ZFILAMENT.INFO
10 | ZLINESEGMENT.INFO
3 | ZLINETRAINS.INFO
3 | ZLINK.INFO
4 | Z-WIREBLOG.INFO
7 | Z-WIRE-INTERACTIVE.INFO
9 | ZWIREINTERACTIVE.INFO
6 | Z-WIRENOW.INFO
8 | Z-WIREONLINE.INFO
11 | Z-WIRESHOP.INFO
7 | Z-WIRES.INFO
13 | Z-WIRESITE.INFO
15 | Z-WIRESTORE.INFO
7 | Z-WIRETODAY.INFO
(487 rows)
Read More
Posted in | No comments

Saturday, 12 March 2011

UK Government counts the Cost of Cybercrime

Posted on 08:25 by Unknown
The British government has released a report on the annual cost of cybercrime to the United Kingdom. The study mechanism seems greatly flawed, in that it relies almost exclusively on published reports and expert opinions, rather than on any structured gathering of information from victims.

The news was announced in the press this week, for example in the Independent.

They came up with a 2010 annual cost of cyber crime of £27 billion (or $43 billion US Dollars). If the costs were projected evenly from the $2.2 trillion UK economy to the $14.1 trillion US economy, that would estimate our own costs of cybercrime at $275 billion (roughly 6.4 times larger economy.) There is no basis to believe that projection is accurate, but the scale is probably similar.

The study was paid for by the OCSIA, the Office of Cyber Security and Information Assurance. It was conducted by Detica, a BAE Systems company.

The full 32 page report is available from the Cabinet Office

They place costs at:

£3.1 billion to citizens with
£1.7 billion in Identity Theft
£1.4 billion to online scams.

£2.2 billion to the government

£21 billion businesses of which:

£9.2 billion in Intellectual Property theft
£7.6 billion in industrial espionage
£2.2 billion in extortion
£1.3 billion from direct theft
£1 billion in costs related to lost customer data

The Intellectual Property theft was certainly not evenly distributed. They put the most likely industries as:

£1.8 billion = pharmaceuticals & biotech
£1.7 billion = electronic & electrical material
£1.6 billion = software & computer services
£1.3 billion = chemicals
£800 million = automobiles & parts
£800 million = non-profits
£400 million = aerospace & defence

The greatest risk in Intellectual Property theft was believed to be untrustworthy insiders who fell to the pressure of bribery.

The Espionage Impact was largely in three areas:

£2.1 billion = financial services
£1.6 billion = mining
£1.3 billion = aerospace and defence
£900 million = software & computer services
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Aggrevated Identity Theft Law in Action
    There are so many interesting angles to the story this week about a case in Tucson, Arizona. The conviction actually went down in March 200...
  • More Merger Malware Wachovia Wells Fargo
    Today I received a message from Robert K. Steel, the President and CEO of Wachovia Bank. Actually I received several hundred messages from ...
  • Italian Court declares itself Friend of Pirates (or does it?)
    I couldn't believe this one. The Associated Press reported yesterday that Italian high court says file-swapping is not illegal . In this...
  • Securing Cyberspace in the 44th Presidency: Part Two
    Yesterday I provided some context for the Center for Strategic and International Studies report which was published yesterday: Security Cyb...
  • Radical Muslim Hackers Declare CyberWar on Israel
    This weekend more than 300 Israeli websites have been defaced in a period of 48 hours. In a website "defacement" a hacker violate...
  • AffPower Indictments Scare Affiliates!
    Today I heard the news that the "AffPower" drug network is being shut down, starting with 18 arrests in Texas, Florida, Colorado, ...
  • Paunch and the BlackHole/Cool Exploit Kit
    After months of speculation, the creator of the Blackhole exploit kit can be demonstrated to be in custody. As usual with all things Russia...
  • Bank of America Demo Account - DO NOT CLICK
    Beginning on November 25th, the UAB Spam Data Mine has been receiving messages claiming to be from Bank of America which will explain to us ...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ▼  2013 (21)
    • ▼  December (4)
      • Top Brands Imitated by Malicious Spam
      • 20 Million Chinese Hotel Guests have data leaked
      • Indian Banks targeted in multi-brand Phishing Attack
      • Paunch and the BlackHole/Cool Exploit Kit
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile