Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, 31 August 2008

Hurricane Gustav: Fraud Watch

Posted on 05:47 by Unknown
For several years I've worked as an "industry partner" sharing information with the coolest Law Enforcement / Industry / Academia partnership on the planet - the National Cyber Forensics Training Alliance. One of the very first things we did together was compiling potential fraud domains for Hurricane Katrina.

Since that time, anytime we've seen a natural disaster, we've been on the lookup for domains which might be abused for fraud. It was only natural then that I retuned my settings at DomainTools yesterday to alert on Gustav domains.

Here's what we've seen so far about new domains, registered with the word "Gustav" in them:

Parked Domains



- parked at GoDaddy

contributegustav.org
contributiongustav.org
donategustav.org
donationgustav.org
gustav-relief.org
gustavassistance.org
gustavattorney.com
gustavclaims.net
gustavcontribution.org
gustavhelpers.org
gustavlawsuit.com
gustavlawyer.com
gustavlouisiana.org
gustavneworleans.org
gustavotimponi.com
gustavrecovery.org
hurricanegustavrepair.com
hurricanegustavvictims.info
hurricanegustavvictims.org
hurricanegustav08.com

Parked at IPTV Domains:

gustavcharities.com
gustavcharity.com
gustavdonation.com
gustavrelieffund.com

Parked at Mad Dog Domains & Cattle Company:

hurricanegustavresponse.info
officialhurricanegustav2008.info

Parked at Network Solutions:

gustavresponse.com


Parked on a Sedo search click ads site:

gustavhurricanerelief.com
gustavhurricanerelief.info
gustavhurricanerelief.net
gustavhurricanerelief.org
gustavlegalrelief.com
gustavlegalrelief.info

Parked at Sedoparking.com:

gustav-hurricane.info
gustav-hurricane.net
gustav-hurricane.org
gustav-hurricane.us

Points to a Sedo IP, but no content there:


hurricanegustavrelief.info
hurricanegustavrelief.net
hurricanegustavrelief.org


Parked at WebSites2You:

gustavfound.com
gustavmissing.com
survivedgustav.com
survivedgustav.net

For sale by auction on ebay and sedo by "harfordadvantage.com":

helpgustavvictims.com
helpgustavvictims.net
helpgustavvictims.org



Real Domains



There are several newly registered Gustav domains that actually contain real content!


gustavneworleans.com <== SHOCK! A real page of Gustav Information! (registered by Lawrence Muller of Virtual Corp in New York, who owns more than 400 other domains)

gustavpictures.com <== SHOCK! A real page of Gustav-related photos! (registered via Domains By Proxy by someone who seems to be "on the ground" watching the National Guard come into town)

hurricanegustavphotos.com <== SHOCK! A real page for Gustav-related photos! (registered by Cyril Payne of Theodore, Alabama. A nice frame, but no pictures yet.)

hurricanegustave.info <== SHOCK! Real information about the storm! (registered by Mark Cummings of Madisonville, Louisiana. Useful and current storm data, with Weather Channel graphics.)

Two Offering Good Deeds



Two other domains seem to be owned by Good Citizen who have reserved the domains and will give them for free to a worthy charity who would like to have the domain:


gustavrelief.info <== SHOCK! A good deed doer has reserved this domain, which he will give for free to a real charity . . .

gustavrelieffund.org <== See image



So far no signs of fraud, only Domain Speculation, but as always, we'll be keeping an eye on the situation as we move forward.

Gary Warner
Director of Research
UAB Computer Forensics
http://www.cis.uab.edu/forensics/
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Digital Certificate Spammer Goes for Google Adwords
    From late May until last week, the Digital Certificate Malware spammer has been targeting banking brands. That has changed with last week...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Most Dangerous Cities for Cyber Crime?
    Symantec Riskiest Cybercrime Cities Symantec released a study today in conjunction with Sperling's Best Places today. According to thei...
  • Beware Weekend Facebook Scam!
    The cybercriminals seem to have completed their Black Friday shopping and returned to work this morning with a new Facebook scam. Its proba...
  • What does a National Cyber Range do?
    This week Aviation Week ran a story called DARPA Unveils Cyber Warfare Range . The article quotes Rance Walleston, the director of BAE Syst...
  • 2008: Looking back on a Year of Spam and Malware
    Happy New Year! As we get ready for the New Year, there are quite a few security folks making predictions for 2009. I think my friend Dan...
  • WIRED: November Jargon Watch & Forensics?
    One of my NASA buddies (hi, Lisa!) dropped by last week for coffee and to catch up on the world of information management. When I introduce...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ►  2013 (17)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ▼  August (23)
      • Hurricane Gustav: Fraud Watch
      • Banking Digital Certificate Malware in Spam
      • E-cards Run Wild. Where are the Anti-Virus Compan...
      • Leave Those Viruses at SCHOOL!
      • Celebrity Spam-Off: Will Paris Hilton Overtake An...
      • Shadow Botnet case may yield spammer Leni Neto
      • More Online Pharmacy Affiliates Indicted
      • Evidence that Georgia DDOS attacks are "populist" ...
      • One third of current spam points to malware sites
      • New BBC spam mocks Georgia's President, Spreads Ne...
      • Can You Pick the Real MSNBC.Com Breaking News?
      • MSNBC Breaking News replaces CNN Spam Wave
      • Anti-Virus Products Still Fail on Fresh Viruses
      • iTunes Store Phish
      • Features and Tutorials
      • The UAB Spam Data Mine: Looking at Malware Sites
      • TJX Update: The San Diego Indictments
      • TJX Update: The Boston Indictments
      • Linking all the News Spam together (CNN.com Daily ...
      • CNN Spam Diversifies . . .
      • TJX Reminder: "We Will Arrest You, and We Will Sen...
      • CNN Lends Authenticity to News Spam
      • Another Insider Busted: Countrywide Financial Analyst
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile