Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Wednesday, 4 August 2010

PhacePhish: New Facebook Attack gives a One-Two Punch

Posted on 00:42 by Unknown
Tonight I had a message from one of my Facebook friends who was concerned that someone may have hacked her Facebook account. She was worried that she might get a virus by looking at the links they had posted on her behalf. I assured her not to worry -- if her Facebook account was sending links to other people's walls, she probably already had a virus. After digging a bit deeper, I'm not so sure.

The "One-Two" punch of this current Facebook attack is similar to some of the spamming malware. Some of the messages it sends are to generate profit for the cybercriminal, and some of the messages are to infect more users to build the criminal's delivery network.

Here is the first type of message -- the "profit" message:



This reminds me of a current "work at home mom" trend that some of my other friends are engaging in. There really is a weight loss multi-level marketing scheme right now where the participants are encouraged to make a website telling about "the plan" and then are told that making money is as easy as following the plan yourself, and posting your weight loss reports to all your Facebook friends. (Hope your happy and skinny, DG, I wouldn't know, I blocked you on facebook as soon as you started that crap!)

What happens if you follow the link? The link doesn't go to my friend's weight loss page. It goes to an Acai Berry affiliate sales "news" page that is supposed to look like a real "news" site that just happens to be featuring a story about the miracle of the Acai Berry.



Clicking anywhere on the "news" page takes you first to an affiliate tracker page:

tracker.cpaprosperity.net/affe?offer_id=500&aff_id=1161

and then to the sales page for their diet plan:

acaioptimum.com/?afil=az1007

The diet scam page is hosted by Black Rock Hosting on the IP address 64.38.201.205.

That was the "One" . . . here comes the "Two" of our One-Two Punch:



What's the other important purpose for Facebook besides getting your friends to join your Multi-Level Marketing Weightloss plan? Sending stupid videos to one another, right? Everyone knows that when one of your friends posts a link, you are required to immediately click on it, and the click the "Like" button. This is how people know that we are their friends. We "Like" all their stupid videos.

(Actually, I'm a big Facebook fan. My family communicates like crazy with it, and I enjoy sharing pictures with my friends and playing Bejeweled Blitz. But this is the part where I'm supposed to be all sarcastic...)

So, when my friend BG posted this message to all of her friends' walls, what would happen if they clicked on it?

The first thing is that it sends you to a website called "securitymeassures3.co.tv". That page is going to call some Javascript to find out what country you are in:



If you are in the US, you then load the webpage "explororjones.com/deel/deeus/"

If you are anywhere else in the world, you then load the webpage "explororjones.com/deel/deeint/"

Either way, the page that loads looks like this:



WAIT! How did I get logged out of Facebook? (you are supposed to say to yourself...) then you quickly type in your userid and password for Facebook on this other page, which is actually at "explororjones.com"

ExplororJones is hosted on that excellent Netherlands hosting company Worldstream. I don't recall Facebook moving their operations there. When a webpage that isn't really the company you are trying to log in to tries to convince you to login on the fake web page we call that phishing.

That's why I'm calling this particular attack "PhacePhish" - most phishing attacks start with a spam message that sends you a scary reason that you really need to log in to your bank RIGHT NOW. This one starts with a spammy Facebook message instead.

Sooo...does my friend have a virus?

No, its very very probable that my friend clicked on a "funny baby" or some other leading video on one of her friends' Facebook posts, believed she was logged out of Facebook, and logged back in, giving her password to the criminals. The criminals then can login as my friend and repost the message on all of their facebook pages. If they fall for it, then they'll tell their friends, and they'll tell their friends, and they'll tell their friends, and pretty soon we'll all be skinny and rich! Happy ending!

I'd call my friend and tell her all of this, but its 3:00 AM. I'll let her sleep a bit more while the criminals spread their message through her Facebook account. Wonder if the Facebook guys are awake . . . hmmmmmmmm....
Read More
Posted in facebook, phishing | No comments

Wednesday, 10 March 2010

HM Revenue & Customs Refund Portal - Ten Phish in One

Posted on 10:42 by Unknown
This morning I was reading a report from Kenneth Paschal, a member of the UAB Phishing Operations research team, that contained an interesting group of new phishing sites. The campaign advertises an "HM Revenue & Customs" page using an email with this message body:

After the last annual calculations of your fiscal activity, we have determined that you are eligible to receive a tax refund of 988.50 GBP. Please submit the tax refund request and allow us 2-3 days in order to process it.

Click Here to submit your tax refund request

Note : A refund can be delayed a variety of reasons, for example submitting invalid records or applying after deadline.

Best Regards

HM Revenue & Customs


The so-called "Tax Refund Portal" looks like this:



Each of the icons takes the visitor to a very professional looking phishing site to have the credentials for that bank stolen. The banks currently making up the pool including:

Barclays
Lloyds TSB
Halifax
Abbey
HSBC
Cahoot
Royal Bank of Scotland
Egg Bank
NatWest
Alliance & Leicester

In most cases the URL advertised in the phishing email actually is a forwarder to another location. For instance, the most recent phish from today forwarded to this site to show the actual content:

hxxp://daegups.com/bbs/data/bbs2/folder/folder/New Folder/United2/Folder/Folder/Folder/Folder/Folder/Folder/Folder/empty/empty/empty/United2/United/United/United/index.htm


We had previously seen seventeen such phishing sites, in July and August of 2009, but the front has been quiet until March 1st. A quick peek into the UAB PhishURLs database shows that we're seeing an escalated number of these sites being created.

2010-03-01 | http://www.tvlinko.com/refundportal.htm
2010-03-02 | http://www.tvlinko.com/hmrc/refundportal.htm
2010-03-03 | http://romeningh.dz/img/glyph/hmrc/refundportal.htm
2010-03-03 | http://www.michaelmucklow.com/wp-content/hmrc/refundportal.htm
2010-03-04 | http://www.urbanecology.org/szjtd/hmrc/hmrc/refundportal.htm
2010-03-04 | http://kaptan-electricite.dz/images/me/hmrc/hmrc/refundportal.htm
2010-03-04 | http://kaptan-electricite.dz/images/ms/hmrc/hmrc/refundportal.htm
2010-03-04 | http://www.ardeola.org/lib/hmrc/refundportal.htm
2010-03-04 | http://kaptan-electricite.dz/images/hmrc/hmrc/refundportal.htm
2010-03-04 | http://kaptan-electricite.dz/images/all/hmrc/hmrc/refundportal.htm
2010-03-05 | http://www.bloomingdaledc.org/joomla/cache/hmrc/refundportal.htm
2010-03-05 | http://www.demo.wecandesign.com.tw/gojahn/images/file/hmrc/hmrc/refundportal.htm
2010-03-05 | http://www.demo.wecandesign.com.tw/gojahn/images/image/hmrc/hmrc/refundportal.htm
2010-03-05 | http://www.demo.wecandesign.com.tw/gojahn/upimg/pro/hmrc/hmrc/refundportal.htm
2010-03-05 | http://www.demo.wecandesign.com.tw/gojahn/upimg/hmrc/hmrc/refundportal.htm
2010-03-06 | http://www.planet-promo.de/roxx/cache/hmrc/hmrc/refundportal.htm
2010-03-06 | http://mojwlasnydom.com/gallery/hmrc/hmrc/refundportal.htm
2010-03-06 | http://www.peterkinitsolutions.com/demos/lingerie/images/hmrc/hmrc/refundportal.htm
2010-03-06 | http://www.peterkinitsolutions.com/demos/Jewellery/images/hmrc/hmrc/refundportal.htm
2010-03-06 | http://planet-promo.de/cache/hmrc/hmrc/refundportal.htm
2010-03-06 | http://planet-promo.de/roxx/logs/hmrc/hmrc/refundportal.htm
2010-03-06 | http://www.examsheets.net/images/hmrc/hmrc/refundportal.htm
2010-03-07 | http://bogatypolak.com/hmrc/hmrc/refundportal.htm
2010-03-07 | http://www.cz.etechsol.pk/cp/hmrc/hmrc/refundportal.htm
2010-03-07 | http://mojwlasnydom.com/uk/hmrc/hmrc/refundportal.htm
2010-03-07 | http://artemoda.uol.com.br/fotos/hmrc/hmrc/refundportal.htm
2010-03-07 | http://bogatypolak.com/uk/hmrc/hmrc/refundportal.htm
2010-03-07 | http://www.ingatlanok.erdelyitelkek.ro/re_images/UK/hmrc/hmrc/refundportal.htm
2010-03-07 | http://mojwlasnydom.com/images/hmrc/hmrc/refundportal.htm
2010-03-07 | http://artemoda.uol.com.br/downloads/hmrc/hmrc/refundportal.htm
2010-03-07 | http://mojwlasnydom.com/libs/hmrc/hmrc/refundportal.htm
2010-03-08 | http://www.ingatlanok.erdelyitelkek.ro/re_images/UK/hmrc/refundportal.htm
2010-03-08 | http://www.cotogarden.com/templates/hmrc/refundportal.htm
2010-03-08 | http://www.cotogarden.com/myimages/hmrc/refundportal.htm
2010-03-08 | http://www.cotogarden.com/hmrc/refundportal.htm
2010-03-09 | http://www.cotogarden.com/_private/hmrc/refundportal.htm
2010-03-09 | http://www.cotogarden.com/images/hmrc/refundportal.htm
2010-03-09 | http://www.cotogarden.com/_vti_bin/hmrc/refundportal.htm
2010-03-09 | http://www.cotogarden.com/banners/hmrc/refundportal.htm
2010-03-10 | http://www.restoretherepublic.com/images/hmrc/refundportal.htm
2010-03-10 | http://www.eab-gmbh.de/images/hmrc/refundportal.htm
2010-03-10 | http://www.eab-gmbh.de/cgi-bin/hmrc/refundportal.htm

The UAB Spam Data Mine had samples in our March 6th spam at 12:30 AM, 1:30 AM, 4:30 AM and 5:45 AM spam collections for "planet-promo.de/roxx/logs/hmrc/hmrc/refundportal.htm". After that site was terminated, the bad guys relaunched in our 12:15 PM spam collection with "www.examsheets.net/images/hmrc/hmrc/refundportal.htm". As you can see, many others have followed.



We'll continue to watch for emerging patterns like this one, and share with you what we find. For now, be wary of this "Tax Refund Portal"!
Read More
Posted in phishing | No comments

Sunday, 21 February 2010

Phishers target Blogger.com accounts

Posted on 13:59 by Unknown
A new phishing campaign came out about two hours ago, this time targeting bloggers who use Google's "blogger.com" and "blogspot" services.

The emails are pretty straightforward:

Subject: Your Blogger Account

Dear Blogger account owner,
To update your Blogger account please click the following link:

http://www.blogger.com/update/VE.php?service=blogger&c=111111111111111111&email=youremail@yourdomain.com.

Thank you for using Blogger.

This is a post-only mailing. Replies to this message are not monitored or answered.


The webpages are of course not actually Blogger, but are phishing sites on ".kr" domains, which have been favored lately by the Avalanche/Zeus group.

http://www.blogger.com.esub.co.kr/update/VE.php?service=blogger
http://www.blogger.com.esub.kr/update/VE.php?service=blogger
http://www.blogger.com.esub.ne.kr/update/VE.php?service=blogger
http://www.blogger.com.esug.co.kr/update/VE.php?service=blogger
http://www.blogger.com.esug.kr/update/VE.php?service=blogger
http://www.blogger.com.esug.ne.kr/update/VE.php?service=blogger
http://www.blogger.com.esuk.kr/update/VE.php?service=blogger
http://www.blogger.com.esuk.ne.kr/update/VE.php?service=blogger
http://www.blogger.com.esuk.or.kr/update/VE.php?service=blogger
http://www.blogger.com.esus.co.kr/update/VE.php?service=blogger
http://www.blogger.com.esus.kr/update/VE.php?service=blogger
http://www.blogger.com.esus.ne.kr/update/VE.php?service=blogger
http://www.blogger.com.esut.co.kr/update/VE.php?service=blogger
http://www.blogger.com.esut.kr/update/VE.php?service=blogger
http://www.blogger.com.esut.ne.kr/update/VE.php?service=blogger


Updated: 22FEB2010 @ 9AM Central time

These are the sites we've seen spammed so far this morning . . .

www.blogger.com.dese.ne.kr
www.blogger.com.desr.co.kr
www.blogger.com.desr.kr
www.blogger.com.desr.or.kr
www.blogger.com.desv.co.kr
www.blogger.com.desv.or.kr
www.blogger.com.erdca.ne.kr
www.blogger.com.erdce.kr
www.blogger.com.erdcq.kr
www.blogger.com.erdcu.kr
www.blogger.com.erdcu.ne.kr
www.blogger.com.esuk.kr
www.blogger.com.zoba.co.kr
www.blogger.com.zoba.kr
www.blogger.com.zoba.or.kr
www.blogger.com.zobv.co.kr
www.blogger.com.zohy.kr
www.blogger.com.zohy.or.kr


The phishing site itself looks like this:



We've seen about 350 copies of this phishing campaign so far, but again, its just started up. Look for more URLs to follow.
Read More
Posted in phishing | No comments

Saturday, 12 December 2009

Ongoing VISA scam drop Zeus Zbot

Posted on 12:03 by Unknown
I guess the UAB Spam Data Mine is having a bad day! Our VISA card is being used in Kuwait!

Dear VISA card holder,

A recent review of your transaction history determined that your card was used at an ATM located in Kuwait, but for security reasons the requested transaction was refused.Please carefully review electronic report for your VISA card


Its also being used at an ATM located in:

Albania, Angola, Argentina, Australia, Bahamas, Cambodia, Central African Republic, China, Cuba, Cyprus, Egypt, Ethiopia, France, Greenland, Guam, Honduras, Italy, Jamaica, Japan, Jordan, Korea, Liberia, Lithuania, Luxembourg, Mauritania, Monaco, Mozambique, Nepal, New Zealand, Niger, Oman, Palau, Panama, Paraguay, Peru, Philippines, Romania, Russian Federation, Rwanda, Seychelles, Somalia, Sri Lanka, Switzerland, Taiwan, Tajikistan, Thailand, Turkmenistan, United Arab Emirates, United Kingdom, Uruguay, Zambia, and probably others.



We know that its real, because for security purposes they X'ed out part of our number, as you can see on this destination website below.



Of course, EVERY VISA card starts with a "4", so that isn't actually a very useful hint.

The subject lines in our emails were:

possible fraudulent transaction
possible fraudulent transaction and/or collusion
possible fraudulent transaction and/or collusion with your VISA card
possible fraudulent transaction has been executed
possible fraudulent transaction has been executed with your VISA card
possible fraudulent transaction is identified
possible fraudulent transaction is identified with your VISA card
possible fraudulent transaction occurred
possible fraudulent transaction occurred with your VISA card
possible fraudulent transaction with your VISA card


The "STATEMENT" link on the website is for an executable named "cardstatement.exe".

The copy we sent to VirusTotal was detected by 16 of 41 AV products according to this VirusTotal Report.

Its a big file. File size: 131072 bytes
MD5 : 1560a00d7e83a085ac76b5d514761baa

Several majors are already detecting it as "zbot".

We've seen the malware spammed on 118 different domain names since the start of the campaign, with more than 17,000 copies of the spam received in the UAB Spam Data Mine. In front of the domain name are several possible prefixes:

alerts.visa.com.(domain)
reports.visa.com.(domain)
statements.visa.com.(domain)
transactions.visa.com.(domain)
sessionid_(random).visa.com.(domain)
sessionid(random).visa.com.(domain)
sessionid-(random).visa.com.(domain)

Here are the 118 domain names we've seen so far:

lotet0.co.uk
lotet1.co.uk
lotet2.co.uk
loteti0.co.uk
luuuuud.co.uk
luuuuuk.co.uk
luuuuul.co.uk
luuuuuo.co.uk
miinu001.co.uk
miinui01.co.uk
miinuo01.co.uk
miinuoo1.co.uk
minutu11.co.uk
minutul1.co.uk
minuty11.co.uk
minutyi1.co.uk
mrreggh.co.uk
mrreggi.co.uk
mrreggj.co.uk
mrreggk.co.uk
nteeeera1.co.uk
ntueeepi1.co.uk
ntueeera1.co.uk
ntueeeri1.co.uk
thhfyb.co.uk
thhfym.co.uk
thhfys.co.uk
thhfyv.co.uk
umr1eep1.co.uk
umr1iep0.co.uk
umr1iep1.co.uk
umrteep1.co.uk
lotet0.me.uk
lotet1.me.uk
lotet2.me.uk
loteti0.me.uk
luuuuud.me.uk
luuuuuk.me.uk
luuuuul.me.uk
luuuuuo.me.uk
miinu001.me.uk
miinui01.me.uk
miinuo01.me.uk
miinuoo1.me.uk
minutu11.me.uk
minutul1.me.uk
minuty11.me.uk
minutyi1.me.uk
mrreggh.me.uk
mrreggi.me.uk
mrreggj.me.uk
mrreggk.me.uk
nteeeera1.me.uk
ntueeepi1.me.uk
ntueeera1.me.uk
ntueeeri1.me.uk
thhfyb.me.uk
thhfym.me.uk
thhfys.me.uk
thhfyv.me.uk
umr1eep1.me.uk
umr1iep0.me.uk
umr1iep1.me.uk
umrteep1.me.uk
lotet0.org.uk
lotet1.org.uk
lotet2.org.uk
loteti0.org.uk
luuuuud.org.uk
luuuuuk.org.uk
luuuuul.org.uk
luuuuuo.org.uk
miinu001.org.uk
miinui01.org.uk
miinuo01.org.uk
miinuoo1.org.uk
minutu11.org.uk
minutul1.org.uk
minuty11.org.uk
minutyi1.org.uk
mrreggh.org.uk
mrreggi.org.uk
mrreggj.org.uk
mrreggk.org.uk
nteeeera1.org.uk
ntueeepi1.org.uk
ntueeera1.org.uk
ntueeeri1.org.uk
thhfyb.org.uk
thhfym.org.uk
thhfys.org.uk
thhfyv.org.uk
umr1eep1.org.uk
umr1iep0.org.uk
umr1iep1.org.uk
umrteep1.org.uk
teh10ll1.be
teh11ll1.be
tehh1ll1.be
tehhtll1.be
tehhtpl1.be
tehhttl1.be
tih11ll1.be
luuuuuk.eu
luuuuul.eu
luuuuuo.eu
mrreggh.eu
mrreggi.eu
mrreggj.eu
nteeeera1.eu
ntueeera1.eu
ntueeeri1.eu
thhfyb.eu
thhfym.eu
thhfyv.eu
umr1eep1.eu
umr1iep1.eu
umrteep1.eu

Only a small handful of these are live. We're seeing mostly the ".be" domains right now, such as:

sessionidP2Q8MFCEG7EU5.visa.com.teh10ll1.be
sessionidLWIV86A.visa.com.teh11ll1.be
reports.visa.com.tehh1ll1.be
reports.visa.com.tehhtll1.be
sessionidOI26B5OXFSCBTV.visa.com.tehhtpl1.be
alerts.visa.com.tehhttl1.be
sessionid_5HR4GA8G3.visa.com.tih11ll1.be

but, those are the URLs seen in the freshest spam. The criminal seems pretty reliable about shifting to new domains when the old ones go offline.

Be very careful about visiting these pages . . . the new Zbot distribution websites also contain driveby infectors. The current one is being dropped via an IFRAME which points here:

"bersdf.com/grsfx/in.php"

That drops a malicious PDF called "pdf.pdf" and a malicious flash file called "swf.swf". It also looks like it calls a file called "sNode.php".

Here is a VirusTotal report for pdf.pdf (12 of 41 detects)

File size: 21784 bytes
MD5 : 254f1479f6546ad62651ae572a16b4e8

and a VirusTotal report for swf.swf (0 of 41 detects)

File size: 10735 bytes
MD5...: 48a36eaf2ca13802f539c9bf065781af

Seems rather strange that they would be pushing a "safe" Flash file. Could it really be a totally undetectable .SWF file exploit? Professional researchers, please help yourselves. Opinions wanted.

The additional droppers are currently fetching two files:

1file.exe (Virus report here - is a Zbot infector with 17 of 41 detects.
File size: 131072 bytes
MD5 : 1560a00d7e83a085ac76b5d514761baa

file.exe (Virus Report here) - is also a Zbot infector with 14 of 41 detects.
File size: 130048 bytes
MD5 : ded54d739fa2e4c66d4a488d3b855861

I guess the nice thing about that directory is that its an open browsable directory, complete with "ReadMe_!!!.txt" file.

Here's the source code for a nice little file called "install.sql". Perhaps we can learn a bit about how the Avalanche spammer works from this file.



======================================================
http://bersdf.com/grsfx/install.sql
======================================================

-- phpMyAdmin SQL Dump
-- version 2.6.1
-- http://www.phpmyadmin.net
--
-- Хост: localhost
-- Время создания: Июл 17 2009 г., 22:57
-- Версия сервера: 5.0.45
-- Версия PHP: 5.2.4
--
-- БД: `123321`
--

-- --------------------------------------------------------

--
-- Структура таблицы `browsers`
--

CREATE TABLE IF NOT EXISTS `browsers` (
`id` tinyint(4) NOT NULL auto_increment,
`name` varchar(16) default NULL,
PRIMARY KEY (`id`)
) ENGINE=MyISAM AUTO_INCREMENT=12 DEFAULT CHARSET=cp1251 AUTO_INCREMENT=12 ;

--
-- Дамп данных таблицы `browsers`
--

INSERT INTO `browsers` VALUES (1, 'Opera');
INSERT INTO `browsers` VALUES (2, 'Konqueror');
INSERT INTO `browsers` VALUES (3, 'Lynx');
INSERT INTO `browsers` VALUES (4, 'Links');
INSERT INTO `browsers` VALUES (5, 'MSIE etc');
INSERT INTO `browsers` VALUES (6, 'Netscape');
INSERT INTO `browsers` VALUES (7, 'Mozilla');
INSERT INTO `browsers` VALUES (8, 'Firefox');
INSERT INTO `browsers` VALUES (9, 'Unknown');
INSERT INTO `browsers` VALUES (10, 'MSIE 7');
INSERT INTO `browsers` VALUES (11, 'MSIE 8');

-- --------------------------------------------------------

--
-- Структура таблицы `countries`
--

CREATE TABLE IF NOT EXISTS `countries` (
`abrev` char(2) NOT NULL default '',
`name` varchar(44) character set cp1251 collate cp1251_general_cs default NULL,
KEY `abrev` (`abrev`)
) ENGINE=MyISAM DEFAULT CHARSET=cp1251;

--
-- Дамп данных таблицы `countries`
--

INSERT INTO `countries` VALUES ('AP', 'Asia/Pacific Region');
INSERT INTO `countries` VALUES ('EU', 'Europe');
INSERT INTO `countries` VALUES ('AD', 'Andorra');
INSERT INTO `countries` VALUES ('AE', 'United Arab Emirates');
INSERT INTO `countries` VALUES ('AF', 'Afghanistan');
INSERT INTO `countries` VALUES ('AG', 'Antigua and Barbuda');

(Gar-Note: Skipping Big Long Country List here)
--
-- Дамп данных таблицы `hit2plug`
--


-- --------------------------------------------------------

--
-- Структура таблицы `loads`
--

CREATE TABLE IF NOT EXISTS `loads` (
`id` int(11) NOT NULL auto_increment,
`sploit_id` int(11) NOT NULL default '0',
`time` varchar(16) NOT NULL default '',
`hash` varchar(32) NOT NULL default '',
PRIMARY KEY (`id`),
KEY `hash` (`hash`)
) ENGINE=MyISAM AUTO_INCREMENT=4231 DEFAULT CHARSET=latin1 AUTO_INCREMENT=4231 ;

--
-- Дамп данных таблицы `loads`
--


-- --------------------------------------------------------

--
-- Структура таблицы `os`
--

CREATE TABLE IF NOT EXISTS `os` (
`id` tinyint(4) NOT NULL auto_increment,
`name` varchar(32) NOT NULL default '',
PRIMARY KEY (`id`)
) ENGINE=MyISAM AUTO_INCREMENT=16 DEFAULT CHARSET=cp1251 AUTO_INCREMENT=16 ;

--
-- Дамп данных таблицы `os`
--

INSERT INTO `os` VALUES (1, 'Linux');
INSERT INTO `os` VALUES (2, 'Windows 95');
INSERT INTO `os` VALUES (3, 'Windows 98');
INSERT INTO `os` VALUES (4, 'Windows XP SP2');
INSERT INTO `os` VALUES (5, 'Windows 2000');
INSERT INTO `os` VALUES (6, 'Windows XP');
INSERT INTO `os` VALUES (7, 'Windows 2003');
INSERT INTO `os` VALUES (8, 'Windows Vista');
INSERT INTO `os` VALUES (9, 'Windows Mobile');
INSERT INTO `os` VALUES (10, 'Macintosh');
INSERT INTO `os` VALUES (11, 'FreeBSD');
INSERT INTO `os` VALUES (12, 'Unknown');

-- --------------------------------------------------------

-- --------------------------------------------------------

--
-- Структура таблицы `sploits`
--

CREATE TABLE IF NOT EXISTS `sploits` (
`id` int(11) NOT NULL auto_increment,
`name` varchar(32) NOT NULL default '',
`loads` int(11) NOT NULL default '0',
PRIMARY KEY (`id`)
) ENGINE=MyISAM AUTO_INCREMENT=667 DEFAULT CHARSET=latin1 AUTO_INCREMENT=667 ;

--
-- Дамп данных таблицы `sploits`
--

INSERT INTO `sploits` VALUES (1, 'RDS.DataSpace', 0);
INSERT INTO `sploits` VALUES (2, 'PDF.Collab', 0);
INSERT INTO `sploits` VALUES (3, 'PDF.Printf', 0);
INSERT INTO `sploits` VALUES (4, 'PDF.Icon', 0);
INSERT INTO `sploits` VALUES (5, 'Other', 0);

-- --------------------------------------------------------
============================
The guys at MaxMind will be excited to know that these criminals are customers of theirs for Geocoding the locations of their infected bots.

The creators of the "FSPACK" malware engine will also be proud to count these guys as customers.

It looks like we've got four exploits that are going to try to run when we visit, if you can trust the loader. RDS.DataSpace is OLD, like MS06-014. A note on SecurityFocus in 2007 says that the MPack Hacker Tool uses it. Apparently the FSPack hacker tool does too!
Read More
Posted in phishing, zbot | No comments

Saturday, 5 December 2009

Webmasters Targeted by CPANEL phish

Posted on 05:17 by Unknown
Webmasters from at least 90 online hosting providers are specifically targeted in the newest round of Avalanche phish.

The spam emails that are going out look like these:







Due to the system maintenance, we kindly ask you to take a few minutes to confirm your FTP details.
Please confirm your FTP details by using the link below:


Subject lines use the name of the targeted hosting company in the email subject, such as:

(targeted hosting company) webhosting update
(targeted hosting company) web hosting update
(targeted hosting company) webhosting user
(targeted hosting company) web hosting update
for (targeted hosting company) webhosting user
for (targeted hosting company) web hosting user

Given all the variations, we've seen more than 900 unique subject lines.

When the link is followed, the websites are of course the criminal's phishing page instead of the web hosting company's CPanel page. (CPanel is a popular website
administration tool.)

The goal seems to really be capturing the FTP userids and passwords of webmasters. You can imagine what sorts of badness this campaign may lead to!

The website looks like this:



Here are some websites currently live . . .

cpanel.netbenefit.co.uk.tygkhggi.co.uk
cpanel.123-reg.co.uk.tygkrggi.co.uk
cpanel.1and1.co.uk.tygsrggi.co.uk
cpanel.locaweb.com.br.tygkhggi.me.uk
cpanel.1and1.co.uk.tygkrggi.org.uk
cpanel.locaweb.com.br.tygrhggi.org.uk
cpanel.1and1.co.uk.tygrtggi.org.uk
cpanel.fasthosts.co.uk.tygsrggi.org.uk
cpanel.4shared.com.tygrhggi.co.uk
cpanel.4shared.com.tygkrggi.me.uk
cpanel.4shared.com.tygsrggi.me.uk

The pattern of the URL is:

cpanel.(targeted hosting company).topleveldomain

where (targeted hosting company) can be:
locaweb.com.br
now.cn
4shared.com
50webs.com
bluehost.com
earthlink.com
github.com
godaddy.com
homestead.com
hostalia.com
hostgator.com
hostmonster.com
ixwebhosting.com
jeeran.com
lunarpages.com
mediafire.com
mozy.com
namecheap.com
netfirms.com
networksolutions.com
pair.com
powweb.com
qwest.com
register.com
resellerclub.com
siteground.com
sitesell.com
softlayer.com
squarespace.com
startlogic.com
t35.com
theplanet.com
ucoz.com
vendio.com
volusion.com
web.com
webhost4life.com
webhostingpad.com
west263.com
x10hosting.com
yahoo.com
35.com
bravehost.com
dreamhost.com
enom.com
fatcow.com
krypt.com
midphase.com
one.com
xlhost.com
000webhost.com
all-inkl.com
angelfire.com
bravenet.com
freeservers.com
freewebs.com
ipower.com
justhost.com
leaseweb.com
pingdom.com
rackspace.com
zerolag.com
arabstart.com
awardspace.com
fortunecity.com
freehostia.com
dynadot.com
pueblo.cz
arcor.de
funpic.de
hosteurope.de
ohost.de
1und1.de
server4you.de
strato.de
usenext.de
aruba.it
isimtescil.net
masterweb.net
ovh.net
speakeasy.net
aplus.net
mediatemple.net
home.pl
nazwa.pl
masterhost.ru
123-reg.co.uk
1and1.co.uk
oneandone.co.uk
fasthosts.co.uk
netbenefit.co.uk
website.ws

The URL contains your email address and the provider link. When you visit the page, this information is stored as part of the URL for "command_003.php". You can see what I mean in the layout below:

(html)(head)
(title)WebHost Manager(/title)
(meta http-equiv="Content-Type" content="text/html; charset=UTF-8")
(link rel="shortcut icon" href="http://whm.demo.cpanel.net/favicon.ico" type="image/x-icon">)
(/head)
(frameset cols="217,566*" frameborder="NO" border="0" framespacing="0" rows="*")
(frame src="command.htm" name="commander" frameborder="no" id="commander" scrolling="yes")
(frameset rows="70,*" cols="*" framespacing="0" frameborder="no" border="0")
(frame src="command_002.htm" name="topFrame" frameborder="no" noresize="noresize" id="topFrame" scrolling="no")
(frame src="command_003.php?email=phishthis@phishme.com&service=mediafire.com" name="mainFrame" id="mainFrame" frameborder="no")(/frameset)
(/frameset)
(/html)


After providing the userid and password, your information is saved, and then you are forwarded to whatever hosting provider was specified in the "service=" tag. If you clicked on a web.com version of the email, you go to web.com. If you clicked on a yahoo.com version of the email, you go to yahoo.

If you are a webmaster and have received one of these emails, please be sure to contact your hosting provider to reset your passwords immediately, and review your pages to see what changes may have been made. If you learn what the bad guys are doing with your site, please drop me a note about it as well. (gar at uab dot edu)

Thanks!
Read More
Posted in phishing | No comments

Wednesday, 28 October 2009

FACEBOOK PHISH! Users Beware!

Posted on 07:30 by Unknown
The FDIC spam campaign that we reported on yesterday in our story Fake FDIC Spam Campaign Spreads Zeus has already moved on to its next attack. Now its trying to steal your Facebook passwords in what appears at first glance to be a "traditional" phishing attack. (Please see the end of this article for an update on how this "phish" actually is another Zeus malware infection vector.)



The UAB Spam Data Mine has already received more than 250 copies of the new phishing email this morning, which claims:

In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security.

Before you are able to use the new login system, you will be required to update your account.

Click (here) to update your account online now.

If you have any questions, reference our New User Guide

Thanks,
The Facebook Team


The email is fake, of course, and so are the websites they point to. So far we've identified 31 unique domain names registered by the criminal for use in this Facebook account.

The website looks like this:



UAB Malware Analyst Brian Tanner took the new Facebook Phish for a drive through the lab, and confirmed that this is NOT JUST A PHISH - in fact it might not be a traditional phish at all. Its actually a Zeus Bot installer, pointing at the same command & control site as yesterday's FDIC version of Zeus:



Clicking on the prompted "UpdateTool.exe" is the infection vector for Zeus. According to the VirusTotal Report for this malware, only 8 of 41 AV products are currently labelling this executable as malware.

File size: 105472 bytes
MD5 : 1198d2ddf09061fbfb70de423cde059f

Update 29OCT09 AM


Spam for this campaign is still coming fast and furious to the UAB Spam Data Mine. More than 200 fresh copies were received already this morning.

File size: 105984 bytes
MD5...: 6aad88ba4805b2daa4fc6106a5376065

A
VirusTotal report
for the current version is showing 9 of 41 detections.

Update - 01NOV2009


From October 27th until November 1st, we've seen 242 different domain names used by this campaign. Here are the ones that are currently live at this point in time (5:25 PM) --

www.facebook.com.heratsb.eu
www.facebook.com.heratsd.eu
www.facebook.com.heratsf.eu
www.facebook.com.heratsg.eu
www.facebook.com.heratsh.eu
www.facebook.com.heratsk.eu
www.facebook.com.heratsl.eu
www.facebook.com.heratsm.eu
www.facebook.com.heratsn.eu
www.facebook.com.heratso.eu
www.facebook.com.heratsq.eu
www.facebook.com.heratsr.eu
www.facebook.com.heratss.eu
www.facebook.com.heratst.eu
www.facebook.com.heratsy.eu
www.facebook.com.lllujiob.eu
www.facebook.com.lllujioc.eu
www.facebook.com.lllujiod.eu
www.facebook.com.lllujiof.eu
www.facebook.com.lllujiog.eu
www.facebook.com.lllujioh.eu
www.facebook.com.lllujioi.eu
www.facebook.com.lllujioj.eu
www.facebook.com.lllujion.eu
www.facebook.com.lllujiot.eu
www.facebook.com.lllujiov.eu
www.facebook.com.lllujiox.eu
www.facebook.com.lllujioy.eu
www.facebook.com.lllujioz.eu
www.facebook.com.ttteraa.eu
www.facebook.com.ttterab.eu
www.facebook.com.ttterac.eu
www.facebook.com.ttterad.eu
www.facebook.com.ttterae.eu
www.facebook.com.ttteraf.eu
www.facebook.com.ttterag.eu
www.facebook.com.ttteran.eu
www.facebook.com.ttteraq.eu
www.facebook.com.ttterav.eu
www.facebook.com.ttterax.eu
www.facebook.com.ttteraz.eu

Here is the full list . . .

www.facebook.com.edilokqf.eu
www.facebook.com.edilokqi.eu
www.facebook.com.edilokqm.eu
www.facebook.com.edilokqn.eu
www.facebook.com.edilokqr.eu
www.facebook.com.edilokqs.eu
www.facebook.com.edilokqu.eu
www.facebook.com.edilokqv.eu
www.facebook.com.edilokqw.eu
www.facebook.com.edilokqx.eu
www.facebook.com.eiye1ua.eu
www.facebook.com.eiye1uc.eu
www.facebook.com.eiye1ue.eu
www.facebook.com.eiye1uf.eu
www.facebook.com.eiye1ug.eu
www.facebook.com.eiye1ur.eu
www.facebook.com.eiye1us.eu
www.facebook.com.eiye1ut.eu
www.facebook.com.eiye1uv.eu
www.facebook.com.fasazab.eu
www.facebook.com.fasazad.eu
www.facebook.com.fasazae.eu
www.facebook.com.fasazaf.eu
www.facebook.com.fasazag.eu
www.facebook.com.fasazam.eu
www.facebook.com.fasazan.eu
www.facebook.com.fasazav.eu
www.facebook.com.heratsb.eu
www.facebook.com.heratsd.eu
www.facebook.com.heratsf.eu
www.facebook.com.heratsg.eu
www.facebook.com.heratsh.eu
www.facebook.com.heratsk.eu
www.facebook.com.heratsl.eu
www.facebook.com.heratsm.eu
www.facebook.com.heratsn.eu
www.facebook.com.heratso.eu
www.facebook.com.heratsq.eu
www.facebook.com.heratsr.eu
www.facebook.com.heratss.eu
www.facebook.com.heratst.eu
www.facebook.com.heratsy.eu
www.facebook.com.herrazzb.eu
www.facebook.com.herrazzd.eu
www.facebook.com.herrazzf.eu
www.facebook.com.herrazzg.eu
www.facebook.com.herrazzh.eu
www.facebook.com.herrazzj.eu
www.facebook.com.herrazzk.eu
www.facebook.com.herrazzo.eu
www.facebook.com.herrazzr.eu
www.facebook.com.herrazzt.eu
www.facebook.com.herrazzu.eu
www.facebook.com.herrazzv.eu
www.facebook.com.herrazzy.eu
www.facebook.com.ibbaswza.eu
www.facebook.com.ibbaswzd.eu
www.facebook.com.ibbaswze.eu
www.facebook.com.ibbaswzf.eu
www.facebook.com.ibbaswzr.eu
www.facebook.com.iokasqzc.eu
www.facebook.com.iokasqze.eu
www.facebook.com.iokasqzh.eu
www.facebook.com.iokasqzr.eu
www.facebook.com.iokasqzt.eu
www.facebook.com.iokasqzy.eu
www.facebook.com.ioooliob.eu
www.facebook.com.iooolioc.eu
www.facebook.com.iooolioe.eu
www.facebook.com.ioooliog.eu
www.facebook.com.iooolioq.eu
www.facebook.com.iooolior.eu
www.facebook.com.iooolios.eu
www.facebook.com.ioooliot.eu
www.facebook.com.ioooliov.eu
www.facebook.com.ioooliow.eu
www.facebook.com.ioooliox.eu
www.facebook.com.iooolioy.eu
www.facebook.com.lef1asza.eu
www.facebook.com.lefassza.eu
www.facebook.com.lefaszab.eu
www.facebook.com.lefaszac.eu
www.facebook.com.lefaszad.eu
www.facebook.com.lefaszak.eu
www.facebook.com.lefaszam.eu
www.facebook.com.lefaszan.eu
www.facebook.com.lefaszav.eu
www.facebook.com.lefaszax.eu
www.facebook.com.lefaszxa.eu
www.facebook.com.lefawsza.eu
www.facebook.com.lllujiob.eu
www.facebook.com.lllujioc.eu
www.facebook.com.lllujiod.eu
www.facebook.com.lllujiof.eu
www.facebook.com.lllujiog.eu
www.facebook.com.lllujioh.eu
www.facebook.com.lllujioi.eu
www.facebook.com.lllujioj.eu
www.facebook.com.lllujion.eu
www.facebook.com.lllujiot.eu
www.facebook.com.lllujiov.eu
www.facebook.com.lllujiox.eu
www.facebook.com.lllujioy.eu
www.facebook.com.lllujioz.eu
www.facebook.com.mibbbad.co.uk
www.facebook.com.mibbbad.me.uk
www.facebook.com.mibbbad.org.uk
www.facebook.com.mibbbah.co.uk
www.facebook.com.mibbbah.me.uk
www.facebook.com.mibbbah.org.uk
www.facebook.com.mibbbal.co.uk
www.facebook.com.mibbbal.me.uk
www.facebook.com.oooeasec.eu
www.facebook.com.oooeasef.eu
www.facebook.com.oooeaseg.eu
www.facebook.com.poresawa.eu
www.facebook.com.poresawd.eu
www.facebook.com.poresawe.eu
www.facebook.com.poresawg.eu
www.facebook.com.poresawj.eu
www.facebook.com.poresawo.eu
www.facebook.com.poresawq.eu
www.facebook.com.poresaws.eu
www.facebook.com.poresawt.eu
www.facebook.com.poresawu.eu
www.facebook.com.poresawv.eu
www.facebook.com.poresawx.eu
www.facebook.com.qqqqasc.eu
www.facebook.com.qqqqasd.eu
www.facebook.com.qqqqasf.eu
www.facebook.com.qqqqasg.eu
www.facebook.com.qqqqash.eu
www.facebook.com.qqqqasj.eu
www.facebook.com.qqqqask.eu
www.facebook.com.qqqqasl.eu
www.facebook.com.qqqqaso.eu
www.facebook.com.qqqqasr.eu
www.facebook.com.qqqqasy.eu
www.facebook.com.saaasaj.eu
www.facebook.com.saaasak.eu
www.facebook.com.saaasam.eu
www.facebook.com.saaasav.eu
www.facebook.com.saaasay.eu
www.facebook.com.saxzask.co.uk
www.facebook.com.saxzask.me.uk
www.facebook.com.saxzask.org.uk
www.facebook.com.saxzasl.co.uk
www.facebook.com.saxzasl.me.uk
www.facebook.com.saxzasl.org.uk
www.facebook.com.saxzasv.co.uk
www.facebook.com.saxzasv.me.uk
www.facebook.com.saxzasv.org.uk
www.facebook.com.saxzasy.co.uk
www.facebook.com.sazzawe.co.uk
www.facebook.com.sazzawe.eu
www.facebook.com.sazzawe.me.uk
www.facebook.com.sazzawf.co.uk
www.facebook.com.sazzawf.eu
www.facebook.com.sazzawf.me.uk
www.facebook.com.sazzawk.co.uk
www.facebook.com.sazzawk.eu
www.facebook.com.sazzawk.me.uk
www.facebook.com.sazzawl.co.uk
www.facebook.com.sazzawl.eu
www.facebook.com.sazzawl.me.uk
www.facebook.com.sazzawy.co.uk
www.facebook.com.sazzawy.eu
www.facebook.com.sazzawy.me.uk
www.facebook.com.ttteraa.eu
www.facebook.com.ttterab.eu
www.facebook.com.ttterac.eu
www.facebook.com.ttterad.eu
www.facebook.com.ttterae.eu
www.facebook.com.ttteraf.eu
www.facebook.com.ttterag.eu
www.facebook.com.ttteran.eu
www.facebook.com.ttteraq.eu
www.facebook.com.ttterav.eu
www.facebook.com.ttterax.eu
www.facebook.com.ttteraz.eu
www.facebook.com.ujtqwaq1.co.uk
www.facebook.com.ujtqwaq1.eu
www.facebook.com.ujtqwaq1.me.uk
www.facebook.com.ujtqwaq1.org.uk
www.facebook.com.ujtqwaqb.co.uk
www.facebook.com.ujtqwaqb.eu
www.facebook.com.ujtqwaqb.me.uk
www.facebook.com.ujtqwaqb.org.uk
www.facebook.com.ujtqwaqk.co.uk
www.facebook.com.ujtqwaqk.eu
www.facebook.com.ujtqwaqk.me.uk
www.facebook.com.ujtqwaqk.org.uk
www.facebook.com.ujtqwaqm.co.uk
www.facebook.com.ujtqwaqm.eu
www.facebook.com.ujtqwaqm.org.uk
www.facebook.com.ujtqwaqo.co.uk
www.facebook.com.ujtqwaqo.eu
www.facebook.com.ujtqwaqo.me.uk
www.facebook.com.ujtqwaqo.org.uk
www.facebook.com.xxxasqwa.eu
www.facebook.com.xxxasqwe.eu
www.facebook.com.xxxasqwi.eu
www.facebook.com.xxxasqwk.eu
www.facebook.com.xxxasqwl.eu
www.facebook.com.xxxasqwo.eu
www.facebook.com.xxxasqwp.eu
www.facebook.com.xxxasqwr.eu
www.facebook.com.xxxasqwt.eu
www.facebook.com.xxxasqwu.eu
www.facebook.com.xxxasqwy.eu
www.facebook.com.xxxasqwz.eu
www.facebook.com.yhheaszb.eu
www.facebook.com.yhheaszc.eu
www.facebook.com.yhheasze.eu
www.facebook.com.yhheaszf.eu
www.facebook.com.yhheaszh.eu
www.facebook.com.yhheaszi.eu
www.facebook.com.yhheaszq.eu
www.facebook.com.yhheaszu.eu
www.facebook.com.yhheaszv.eu
www.facebook.com.yhheaszy.eu
www.facebook.com.yy1azsva.eu
www.facebook.com.yy1azsvc.eu
www.facebook.com.yy1azsvq.eu
www.facebook.com.yy1azsvz.eu
www.facebook.com.yyy1asvf.eu
www.facebook.com.yyy1azsy.eu
www.facebook.com.yyy1azvg.eu
www.facebook.com.yyy1zsve.eu
www.facebook.com.yyyaszai.eu
www.facebook.com.yyyaszal.eu
www.facebook.com.yyyaszao.eu
www.facebook.com.yyyaszap.eu
www.facebook.com.yyyaszaq.eu
www.facebook.com.yyyaszar.eu
www.facebook.com.yyyaszau.eu
www.facebook.com.yyyaszay.eu
www.facebook.com.yyyazsvd.eu
www.facebook.com.zaaaasaa.eu
www.facebook.com.zaaaasag.eu
www.facebook.com.zaaaasaq.eu
www.facebook.com.zaaaasaz.eu
Read More
Posted in phishing, spam, zbot | No comments

Wednesday, 21 October 2009

Phishing For Love: Banking Insiders

Posted on 11:39 by Unknown
This week in the Eastern District of Pennsylvania, an indictment was unsealed against Miguel Bell, Christopher Russell, Michael Merin, Kareem Russell, and Tamika Brown for their actions in stealing more than $1 Million from Citizens Bank, PNC Bank, Wachovia Bank, M&T Bank, Provident Bank, and SunTrust Bank. Michael Levy, US Attorney in that district, brought the charges.

This entire article is a summation of the charges from the extremely detailed sixty-one page indictment.

The five were charged with the following violations:

18 U.S.C. § 371 - conspiracy to commit bank fraud and aggravated identity theft
18 U.S.C. § 1344 - bank fraud -8 counts
18 U.S.C. § 1028A - aggravated identity theft - 34 counts
18 U.S.C. § 2 - aiding and abetting

The charges resulted from activities between September 1, 2005 and November 30, 2008.

Miguel Bell



Miguel Bell is accused of being the ringleader in the scheme, which consisted of stealing identifying information and account numbers, and then having "check runners" pose as the bank customers and cash fraudulent checks from the accounts belonging to those whose identities they were using.

Bell developed his information feed by pursuing romantic relationships with bank employees and one insurance company employee, and after gaining their trust, compelling them to provide bank information, customer account numbers, and personal identifying information including names, addresses, dates of birth, social security numbers, and driver's license numbers. Bell's love interests also rented cars which he provided to the check runners in order to cash out the accounts.

Bell also required Michael Merin, Rashin Owens, and David Tunnell to recruit bank employees to provide the same information he was getting from his love interests.

Bell verified high account balances by calling the banks' automated banking telephone services.

Bell provided his check runners with fraudulent driver's licenses and to have them photographed, and also provided them with fake checks and "cheat sheets" to help them memorize their new identity. On many occasions he provided transportation and maintained cell phone contact with the check runners while they went into the banks.

Bell took the largest share of all the proceeds, and was in charge of distributing funds to others. Check runners were recruited, used for a day, and paid at the end of the day.

Christopher Russell


The indictment describes Christopher Russell as "the right hand man". Among his roles in the scheme he verified bank balances and recruited check runners, often in exchange for illegal drugs or money for illegal drugs. He accompanied check runners to be photographed for their fraudulent driver's licenses. He provided the identity cheat sheets and fraudulent checks to the check runners, and instructed them on their tasks to perform. He often provided transportation and maintained cell phone contact with the check runners. He would often receive the payout from the check runner, and then pass most of the funds to Miguel Bell for further distribution, and paid the check runners.

Kareem Russell


Kareem is described as a "middle man" in the scheme. He primarily recruited runners, and provided all the same activites as Christopher Russell, including recruiting check runners, providing them with drugs or money for drugs, escorted runners to be photographed for fraudulent drivers licenses, and provided transporation, passed funds to Miguel, and paid his check runners from the proceedings.

Michael Merin


Merin was also called a "middle man", but concentrated on recruiting bank employees in addition to some check runners. Among those recruited:

- Jon Steffon of Citizens Bank (charged elsewhere)
- Kern Haynes of Citizens Bank (charged elsewhere)
- Marcus Nabried of Citizens Bank (charged elsewhere)

Tamika Brown


Tamika Brown was partnered with Christopher Russell and accompanied him in transporting his runners for photography and for fraudulent transactions. She also was in charge of providing the runners with clothes to wear for their photographs and fraud, and for arranging the rental of cars to be used in transporting the check runners.

Recruiting


PNC Bank Employee Tiffany Brodie was in contact with Miguel Bell from at least September 1, 2005 until June 30, 2006, and provided at least four bank accounts and associated personal information to Bell from her customers at PNC Bank.

Tiffany's information allowed check runner James Kennedy to steal $13,050 by pretending to be one of these customers. She also rented cars for Miguel.

Citizens Bank Employee Trena Smith was in contact with Miguel Bell from at least November 1, 2005 until December 20, 2005. She provided information on thirty-seven Citizens Bank account holders, which resulted in $390,039 being stolen by check runners Ralph Guy, Jennie Hill, Priscilla Torres and others, who presented fake ids claiming to be these customers.

Citizens Bank Employee Jon Steffon was recruited by Michael Merin and provided at least fourteen sets of identity data for his customers to Michael, which were used between May 1, 2006 and July 30, 2006 to steal $100,687 from Citizens Bank via check runners. "On or about" June 10, 2006, Miguel Bell possessed hand-written person information on five Citizens Bank account holders, written by Jon STeffon and given to Merin by Steffon. He also held three false Pennsylvanie driver's licenses and two false Delaware driver's licenses in those names, as well as Citibank MasterCards and fraudulent checks in those names.

Citizens Bank Employees Jamila Hamler, Marcus Nabried, and Tamea Hill provided personal information of twenty-seven account holders to Merin between July 1, 2006 and July 30, 2006. Tamea Hill provided at least four additional identities to Elton Harris and Rashin Owens, who passed the information to Miguel Bell. These identities were passed to James Kennedy and other check runners to accomplish $213,145 in theft.

Citizens Bank Employee Kern Haynes provided sixteen accounts to Michael Merin, who then passed the information to Bell and Christopher Russell. These identities were used by check runner Eileen Comire and others to accomplish at least $98,375 in theft.

Citizens Bank Employee Regina Tolliver provided information on seven Citizens Bank account holders which was used between March 1 and November 30, 2007 by check runners Richard Maden and Eileen Comire to withdraw $181,577 using their false identities.

Citizens Bank Employee Deonda Barnett provided twelve identities used to steal $24,172 using check runner Eileen Comire and another $18,312 using check runner James Howard.

Citizens Bank Employee Clarissa Gavin provided six account holder identities, which were used by check runner Tommy Antone Murray, Eileen Comire, David TUnnell and others to cash out $70,811.

Car Dealership Recruitment



Rashin Owens and David Tunnell recruited Damoon Hosseinzadeh, an employee at the car dealership "New Concepts, Inc." to provide identity information regarding customers of the dealership. These were used to take $37,900 from Commerce Bank with David Tunnell acting as the check runner.

Insurance Company Recruitment


Colonial Penn Insurance Company employee Lisa Bryant Nelso was used to provide bank account information for persons banking at Citizens Bank, Wachovia Bank, M&T Bank, Provident Bank, and SunTrust Bank.

Ten Citizens Bank identities provided by Nelson were used by check runners to cash out $33,833.

Twenty-five Wachovia identities provided by Nelson were used by check runners to cash out $134,935.

Twelve M&T Bank account identities provided by Nelson were used by check runners to cash out $53,085.

One Provident Bank identity provided by Nelson was used to cash out $7,000.

One SunTrust identity provided by Nelson was used to cash out $2,250.

The Check Runners


There were SO MANY Check Runners, including:
Ralph Guy, Jennie Hill, Priscilla Torres, Gregory Grayson, David Tunnell, Richard Maden, Eileen Comire, and James Kennedy. The indictment actually details their involvement, claiming . . .

Ralph Guy did 37 checks on identities from Pennsylvania, Vermont, Ohio, and Michigan stealing or attempting to steal $174,046.

Jennie Hill did 24 checks on identities from Indiana, New Hampshire, Vermont, Ohio, and Michigan stealing or attempting to steadl $104,422.

Priscilla Torres did 2 checks for $9,243 on identities from Pennsylvanie and Delaware. She also was the driver for other check runners on some occasions.

Gregory Grayson did one check for $2,500 on a New Jersey identity.

James Kennedy did four checks vs. PNC Bank and twenty checks vs. Citizens Bank using at least eleven identities to steal $61,600.

Eileen Comire did at least thirty-seven checks imitating at least twenty-seven account holders to steal at least $240,599 from Wachovia Bank, and an additional $186,913 from Citizens Bank using eighty-eight fraudulent checks and twenty-one account holder identities. She also uses twenty-two checks belonging to twelve M&T account holders to steal an additional $58,135 from M & T Bank.

David Tunnell did seven transactions totalling $41,900 from Commerce Bank using two different identities, and six transactions totalling $45,100 from Citizens Bank using three identities.

Richard Maden used five Citizens Bank identities to present twenty-nine fraudulent checks totalling $97,374.

Notice of Forfeiture


These criminals stand to lose all property, real or personal, that constitutes or is derived from proceeds traceable to the commission of such offenses - up to a value of $1,300,000.
Read More
Posted in law enforcement, phishing | No comments

Tuesday, 20 October 2009

TowerNet CapitalOne: Avalanche returns after 15 monthsOne

Posted on 12:34 by Unknown
The Avalanche Botnet, which has been spamming phishing pages, and most recently the IRS Zeus campaign, has returned to traditional phishing. The UAB Spam Data Mine has received hundreds of samples today with subjects like this:

Download and install digital certificate
Enhancements: New Release
How to install digital certificate
Install Digital certificate
Install Digital Certificate software
Obtain Digital Certificate
Pick Up and Install Digital Certificate
Please install digital certificate software
Please read this important information concerning your privacy
Please Read: This Document Contains Important Information
This Document Contains Important Information



Advertised websites in this target group include:

towernet.capitalonebank.com.racder1c.net
towernet.capitalonebank.com.racder1x.com
towernet.capitalonebank.com.raeder1f.net
towernet.capitalonebank.com.rarder1g.com
towernet.capitalonebank.com.raxsder1.net
towernet.capitalonebank.com.rzasder1.com
towernet.capitalonebank.com.t1fliil.com
towernet.capitalonebank.com.t1fliil.net
towernet.capitalonebank.com.t1fliil.tc
towernet.capitalonebank.com.yyy1yyrd.co.uk
towernet.capitalonebank.com.yyy1yyre.co.uk
towernet.capitalonebank.com.yyy1yyrf.co.uk
towernet.capitalonebank.com.yyy1yyrg.co.uk
towernet.capitalonebank.com.yyy1yyrj.co.uk
towernet.capitalonebank.com.yyy1yyrk.co.uk
towernet.capitalonebank.com.yyy1yyrl.co.uk
towernet.capitalonebank.com.yyy1yyrm.co.uk
towernet.capitalonebank.com.yyy1yyro.co.uk
towernet.capitalonebank.com.yyy1yyrq.co.uk
towernet.capitalonebank.com.yyy1yyrr.co.uk
towernet.capitalonebank.com.yyy1yyrs.co.uk
towernet.capitalonebank.com.yyy1yyru.co.uk
towernet.capitalonebank.com.yyy1yyrv.co.uk
towernet.capitalonebank.com.yyy1yyrx.co.uk


The October 2009 Email



Dear Capital One TowerNetSM or Treasury Optimizer user,

As part of the new terms and conditions of the Data Access Agreement between your organization and the Capital One, your organization will be given a Digital Certificate.

Because of the private nature of the client data, worldwide access via Web to that data, and the potential for fraud, the system must be certain of user identity and authorization. Capital One online banking services use two security mechanisms:
1. Customer & User Codes and passwords to identify users; and
2. Digital certificates to ensure that the user is access the business services through a valid computer, in a trusted organization.

Each registered user must have the Capital One's digital certificate installed on his or her machine in order to access online banking services.

To pickup and install your Digital Certificate, please visit:

http://towernet.capitalonebank.com/capitaloneid/usersdir/formpage.aspx/index.php?em=mymail@mydomain.com&id=703121513513613724734835496595606706767090

Please do not respond to this message as it is generated automatically.


Thank you for choosing Capital One!

DO NOT REPLY TO THIS MESSAGE
To protect your privacy, this e-mail box is not equipped to handle replies. If you have any questions, please use the secure messaging options available through Online Banking or contact Customer Service at 1-877-442-3764.

This e-mail is intended solely for the use of the individual(s) to whom it is addressed. If you believe you received this e-mail in error, please contact Customer Service at 1-877-442-3764 immediately, delete the e-mail from your computer and do not copy or disclose it to anyone else.

NOTICE ABOUT SERVICING E-MAILS
This e-mail contains information directly related to your account with us, other services to which you have subscribed, and/or any application you may have submitted.

You may receive customer service e-mails even if you have requested not to receive e-mail marketing offers from Capital One.

Capital One and its service providers are committed to protecting your privacy and ask you not to send sensitive account information through e-mail. You can view our privacy policy and contact information at www.capitalone.com. This e-mail relates to financial services offered by the Capital One family of companies, including Capital One Bank (USA), N.A. and Capital One, N.A., members FDIC. ©2009 Capital One.
Capital One is a federally registered service mark. All rights reserved.



The information contained in this e-mail is confidential and/or proprietary
to Capital One and/or its affiliates. The information transmitted herewith
is intended only for use by the individual or entity to which it is
addressed. If the reader of this message is not the intended recipient,
you are hereby notified that any review, retransmission, dissemination,
distribution, copying or other use of, or taking of any action in reliance
upon this information is strictly prohibited. If you have received this
communication in error, please contact the sender and delete the material
from your computer.


A quick check in our spam data mine showed that we had many messages from July 9th to July 23rd, 2008 that looked very similar:

towernet.capitalonebank.com.mj.org.kg
towernet.capitalonebank.com.srv1.com.es
towernet.capitalonebank.com.mem.org.kg
towernet.capitalonebank.com.srv1.com.es
towernet.capitalonebank.com.srv2.com.es
towernet.capitalonebank.com.whymangame.org.es
towernet.capitalonebank.com.simongrog.com.es
towernet.capitalonebank.com.serversid.co.uk




The July 2008 Email



In July of 2008, the spam messages didn't actually take customers to a phishing page, but rather to a "Digital Certificate page". Now we have spam that is claiming to be a Digital Certificate, but actually just seems to be a phish. Some of the Summer of 2008 Digital Certificate domains targeting Capital One included:

dexoim.com
jimmedy.com
jioece.com
jioeres.com
klainey.com
maginele.com
mkeiop.com
niytec.com
nnerdix.com
poemils.com


Note: This is a service message regarding TowerNET Form.

Dear customer:

As part of the new security measures, all Capital One Bank business customers (including all former customers of North Fork bank) are required to complete TowerNET Form (or Treasury Optimizer Form). Please complete the form as soon as possible.

To select your form please click on the following link:

http://towernet.capitalonebank.com/onlineform/IDslcertificatedlls/userdirectory/stack/comdir/userform.aspx?ID=2987123067912365091827359023&refer=23987529

Thank you for being a valued customer.

Sincerely,

Online Banking Team

0x4685 create tmp QH3M X1Z end F1W6 XJKV exe XVRO. start: 0x6, 0x5609, 0x4 97925705631835442299918536989 0x67430426, 0x206, 0x3, 0x392 0x67, 0x988 0x2, 0x23, 0x01703069, 0x1, 0x4856 YTU: 0x0763, 0x43816681, 0x5182, 0x831, 0x99970266 IW8D: 0x6947, 0x4267, 0x07, 0x01751563, 0x9651, 0x373, 0x44043375, 0x5, 0x342, 0x5, 0x6101, 0x99, 0x0223, 0x58, 0x199 GJY: 0x1992, 0x78, 0x5, 0x348, 0x56, 0x409, 0x4538, 0x9683, 0x89015643, 0x44, 0x746, 0x03185899, 0x9, 0x3

end: 0x8, 0x2234, 0x8, 0x436, 0x07, 0x53322197, 0x2873, 0x41, 0x114, 0x6, 0x87, 0x7065, 0x74627088 media: 0x5 api: 0x264, 0x871, 0x9589 OT5 2IUL 0x7916, 0x2898, 0x320, 0x67922853, 0x0113, 0x4701, 0x7559, 0x8186, 0x5, 0x5639, 0x74679667, 0x4 920911942973 0x595 BDLA WH2. 0x4673, 0x16778534, 0x0, 0x9845, 0x423 QV1: 0x20765394, 0x9, 0x22851093, 0x0, 0x3, 0x53759855, 0x726, 0x8, 0x66030524 0x96413662, 0x7, 0x5

serv: 0x139, 0x5, 0x710, 0x871, 0x054, 0x6709, 0x037, 0x2, 0x6621, 0x02753076, 0x18651692, 0x5760, 0x881, 0x6691 0x43852370, 0x7292, 0x7, 0x0, 0x9 6U4: 0x25193089, 0x84976848, 0x6, 0x944, 0x350, 0x94990755, 0x3528, 0x51 YXO: 0x36, 0x50, 0x774, 0x64, 0x40539047, 0x89 578, file. 0x96291281, 0x24, 0x907, 0x0123, 0x3, 0x50, 0x0007, 0x1, 0x38693923, 0x5745, 0x39770877 4XFD: 0x50, 0x5, 0x76148701, 0x500, 0x77686479, 0x7463, 0x73962606, 0x51 0x24, 0x01601735, 0x3, 0x82, 0x54, 0x03, 0x2175, 0x57, 0x61 hex X5I9 exe 9AI api start. dec: 0x97, 0x0, 0x615, 0x3, 0x80455440, 0x25, 0x1, 0x61, 0x6, 0x69, 0x14, 0x61152270, 0x18, 0x33 9629819832066915873

45514408333619487641751706301863961 cvs: 0x85, 0x896, 0x95342281, 0x04 stack: 0x53, 0x71382978, 0x708, 0x0, 0x1, 0x9, 0x338, 0x265 D4HL: 0x61307749, 0x865, 0x647, 0x2002, 0x2, 0x1, 0x87, 0x22, 0x0561, 0x4, 0x31, 0x08


We actually ALSO saw this as "Rock Phish" back in April 2006 -

http://session421087.towernet.capitalonebank.com.kigrt.jp/customerservice/formpage
http://session6152365674.towernet.capitalonebank.com.kigrt.jp/customerservice/
Read More
Posted in phishing | No comments

Thursday, 8 October 2009

The FBI's Biggest Domestic Phishing Bust Ever

Posted on 01:55 by Unknown
Yesterday the FBI began performing arrests of more than 100 individuals involved in a phishing investigation announced in the Central District of California courts. The case, known as Operation Phish Phry was the top story on the FBI website yesterday. Robert Mueller announced the case during a speech to the Commonwealth Club of California, where he praised the cooperation with the Secret Service and their Los Angeles Electronic Crimes Task Force, as well as state and local law enforcement. He said this was the first joint cyber investigation with Egypt and that this cooperative effort illustrates "the power of our global partnerships." Mueller also used the speech to praise the 32,000 members of the FBI's InfraGard program, "experts on our critical infrastructure" who help the FBI prevent risks to that infrastructure from becoming a reality.

The official press release from the Los Angeles FBI office says the announcement of the case came from:
Keith B. Bolcar, Acting Assistant Director in Charge, FBI Los Angeles
George S. Cardona, Acting United States Attorney, Los Angeles
and
Kieran Ramsey, FBI Legal Attache in Cairo Egypt
along with Egyptian Law Enforcement Authorities.


The 85 page indictment, which was presented to a Grand Jury back in February was unsealed once the arrests began, and contains a wealth of information. WIRED Magazine's Threat Level blog was the first to have a copy of the indictment.

The basic charges are:
18 USC S 1349: Wire and Bank Fraud Conspiracy
18 USC $ 1344(1): Bank Fraud
18 USC $ 1028A: Aggravated Identity Theft
18 USC $ 371: Computer Fraud Conspiracy
18 USC $ 1030(a)(4): Computer Fraud
18 USC $ 1956(h): Money Laundering Conspiracy

I'm especially happy to see the Aggravated Identity Theft charge, as it provides an automatic and non-negotiable +2 years to each sentence, which guarantees none of these people will get a "slap on the wrist", unless the prosecution fails to show they used the identities of at least ten individuals.

Although the investigation is labelled "Operation Phish Phry" by the FBI, the US-based charges deal with the money-laundering aspects more than the actual phishing. The phishing portions of the scheme seem to have been run by a group of nearly fifty individuals primarily in Egypt, who would transfer bank account credentials to the US-based ring leaders, who would use their network to move the money through mule accounts, out to cash, and eventually to be wired back to Egypt (minus a commission for the US-based players). Mueller mentions that the funds came from "approximately 5,000 American citizens" who were presumably the victims of these phishing attacks.

This was a tiered operation involving three ring leaders, who used sixteen associates to enlist thirty-eight money mules to receive stolen funds and wire them primarily to Egypt. In order to establish that each of the defendants was definitely involved, the indictment lists 335 "Overt Acts", mostly taking the form of giving a date, place, defendant, and an amount of money transmitted from a stated account to another defendant or unindicted co-conspirator.




(click for larger image, created with i2 Analyst's Notebook by Gary Warner)

The three ring-leaders identified in the indictment were:

Kenneth Joseph Lucas of Los Angeles, California
Nichole Michelle Merzi of Oceanside, California
Jonathan Preston Clark

These three operated a ring of middlemen who recruited the actual money mules. The middlemen were:

Jarrod Michael Akers
Kyle Wendell Akers
Wayne Edwards Arbaugh
Demorris Brooks
Antonio Late Colson
Kenneth Crews
Manu T. Fifita
Jennifer Anabelle Lopez Gonzalez
Tinika Sabrina Gunn
Jason Marcellus Jenkins
Sylvia Johnson
Remar Ahmir Lawton
Kyle Brandon Martin
Frankline Anthony Ragsdale
Steven Aaron Saunders
Rynn Spencer
Raquel Raffi Varjabedian
Candace Marie Zie

Lastly, the actual money mules that were indicted:

Ashley A. Ager
Latina Shaneka Black
Michael Dominick Gunn Dacosta Jr.
Virgil Phillip Daniels
Tramond S. Davis
Shontovia D. Debose
Joshua Vincent Fauncher
Krystal Fontenot
Anthony Donnel Fuller
Michael Christopher Grier
Bryanna Harrington
Shawn K. Jordan
Billy Littlejohn Kelly
Reggie B. Logan, Jr.
Ikinasio Lousiale, Jr.
Raymond V. Mancillas
David P. Mullin
Vincent Nguyen
Ario Plogovii
Brandon R. Ross
Alan Elvis St. Pierre
Courtney Monet Sears
Me Arlene Settle
Paula W. Sims
Jamie Smith
Brandon Kyle Thomas
Christopher Uhamaka
James Michael Viorato
Jovon Darnell Weems
David D. Westbrooks
Bridget Deque Wilkins
Marcus Deshaun Williams

The ages of the defendants range from 19 to 44, with only two being older than 31. Kenneth Crews and Demorris Brooks recruited seven money mules from North Carolina, and one or more unindicted recruiters gathered seven additional mules from Nevada, including at least four from Las Vegas.

Overt Acts are broken into sections:

A. Defendants Lucas and Zie:
Zie opens a bank BOA account, communicates with Lucas by telephone five times, withdraws stolen funds that were tranferred to his bank account. He opens two more account, talks to Lucas 54 times by telephone, and withdraws more stolen funds. Opens more accounts, communicates with Lucas 24 times in a single day, withdraws more stolen funds. The first 14 acts are about these two.

F. Defendants Lucas, Crews, and Logan:
Crews text-messages account numbers opened by Logan to Lucas, who causes funds to move from a victim account to Logan's accounts. Logan withdraws the money.

G. Defendants Lucas and Mancillas:
(Unindicted coconspirator) text-messages Lucas with account numbers opened by Mancillas at BOA. Lucas transfers funds from a victim to the Mancillas account, and Mancillas withdraws the funds.

H. Defendants Lucas and Mullin:
(Unindicted coconspirator) text-messages Lucas the account numbers opened by Mullin at Bank of America. Lucas moves funds from a victim account to the Mullin account, and Mullin withdraws the funds.

They do that over and over and over. The first 200 "Overt Acts" listed all involve Lucas as the one who moves the money from the victim's account.

The credentials for the victim accounts were acquired by phishing, but at this time, we don't have enough details to really know WHICH phishing attacks we're dealing with. It should certainly be pointed out that the phishing attacks were NOT NECESSARILY against Bank of America and Wells Fargo. Funds from any bank can be sent to Mule accounts at any bank, as long as they are both part of the ACH network. Hopefully more details will come out as this case progresses.

The later activities in the indictment make it seem that at least one or more of the defendants had their phone tapped or was cooperating with investigators, such as:

On February 17, 2009, defendants Colson, Weems, and Lucas agreed via telephone that defendant Colson would deliver $1,200 to defendant Lucas

Beginning with Overt Act #201 in the indictment (page 54) the activities turn to Wire Transfers, such as:

On January 12, 2007 in Los Angeles County, defendant J. Akers transmitted $1,300 by Western Union to unindicted coconspirator E.A.

The next forty acts involve Jarrod Michael Akers wiring nearly $100,000 to various parties, mostly unnamed in this indictment. Rehmar Amir Lawton also does more than $30,000 in wire transfers in "Overt Acts". Jonathon Preston Clark, Nichole Michelle Merzi, Candace Marie Zie, Demorris Brooks, Jennifer Lopez Gonzalez and others are also involved in the Wires.

One of the key telephone conversations that was part of the indictment is "Overt Act No. 241":

On December 22, 2008, in Los Angeles County, defendants LUCAS and K. AKERS, in a telephone conversation, discussed the scheme to cause unauthorized transfers of funds into bank accounts for the purpose of allowing coconspirators to withdraw the transferred funds, and defendant LUCAS advised defendant K. AKERS to solicit individuals who need money to assist in the scheme.
Read More
Posted in law enforcement, phishing | No comments

Thursday, 10 September 2009

Tien Truong Nguyen pleads Guilty

Posted on 04:26 by Unknown
In April of 2007, the Eastern District of California sent out a Press Release titled "SACRAMENTO MAN CHARGED WITH COMPUTER FRAUD AND AGGRAVATED IDENTITY THEFT" with the description, "Internet Phishing Scheme Used to Steal Thousands of Credit and Debit Card Numbers, Social Security Numbers."

At the University of Alabama at Birmingham, our UAB Computer Forensics program has a mix of Computer & Information Science and Criminal Justice students who are working together to research how phishing investigations are performed. When I saw this story back in the news today, I thought we might have another agent who could help us understand how the US Secret Service investigates phishing. While I'm very glad that Nguyen was picked up, and it looks like ECSAP-trained Senior Special Agent Brian Korbs did an excellent job on the Computer Forensics aspects of this case, unfortunately this wasn't a "phishing investigation."

Several of my students learned about the US Secret Service Electronic Crimes Special Agent Program (ECSAP) while visiting the National Computer Forensics Institute in Hoover, Alabama, about ten miles from our campus, earlier this month. Housed at the NCFI, the Electronic Crimes Task Force for the Birmingham field office of the Secret Service maintains a computer forensics lab where computer forensics examiners from the US Secret Service and the Alabama Bureau of Investigation work side-by-side with examiners from the Alabama District Attorneys Association and the Hoover Police Department to perform examinations and provide training and forensic services to all manner of law enforcement cases. The NCFI provides the equivalent of the Secret Service ECSAP training for state and local law enforcement officers across the country. ECSAP-based courses available in Hoover include "Basic Investigation of Computer and Electronic Crimes Program (BICEP)", "Network Intrusion Responder Program (NITRO)", "Basic Computer Evidence Recovery Training (BCERT)", and "Advanced Computer Evidence Recovery Training (ACERT)", which is ten full weeks of very hands-on training! The NCFI also offers two "Computer Forensics in Court" classes, CFC-J for Judges, and CFC-P for Prosecutors.

Back to the story . . . According to the Affidavit of SSA Brian Korbs, Nguyen was clearly involved in phishing. He was able to establish that from at least October 15, 2005 through January 26, 2007, Nguyen was involved in multiple identity theft, phishing, and credit card fraud activities.

The forensics examination covered:

A Dell Laptop Computer "Latitude" Serial Number 8P530B1
A Toshiba Laptop Computer "M-45" with black thumb drive Serial Number 26234221Q
A Hewlett Packard Laptop Computer "Pavilion D1000" with Serial Number CNF5382K5T
two black USB thumb drives and
A Dell Computer Model 470 Serial Number 37NQC61

These showed that Nguyen was regularly communicating with Eastern Europeans to acquire credit card and debit card numbers, social security numbers, and other personal identification information. Files on the computer were used to create phishing websites, including sites against eBay, Fairwinds Credit Union (Florida), Heritage Bank (Olympia, Washington), Honolulu City and County Employees Credit Union, and others. A program for encoding credit cards, lists of account information, a magnetic card writer, and a laminator were found. Thousands of email addresses, sorted by the state in which they were located, were found to be used for sending out phishing emails state-by-state. (For example, it would make sense to only send "Honolulu City and County Employees Credit Union" phishing emails to people who live in Hawaii.)

The fruit of the phishing was "thousands of pages of customer information" from companies "such as eBay, Western Union, and others." Korbs reported finding
"Hundreds of files of credit card numbers, many with PINs, as well as the true cardholders name, address, email address, password, bank account information, social security number, driver's license number, telephone number, etc." Korbs estimates that "tens of thousands" of identities were on the computer, which is certainly "more than 15" as described in the Federal statute (see below).

Yahoo! chat logs were also found on the computer, which, if printed, would be 16,000 pages of logs. Many of the chats related to buying and selling credit cards, and exchanging email addresses for phish targeting.

In Nguyen's case, the whole story seems to be that he worked with several Romanians to build phishing sites and steal personally identifiable information. Then he provided that information to local accomplices who cashed out in an interesting manner. Apparently GE Capital runs a system of kiosks in California Wal-Mart stores where you can enter your information and be approved for an instant line of credit, which is provided as Wal-Mart coupons that can be used to shop in the store. According to Special Agent Korbs, they did this for more than $200,000 worth of merchandise. In the full indictment, it lists many of the items purchased with these cards, including laptops, monitors, satellite radio systems, 8 ipods, infrared night light, a "Nightowl" night vision scope, CB radios, GPS units, watches, televisions, a radar detector, etc.

When Detective Jim Hudson, from the Placer County Sheriff, and Special Agent Korbs talked to Tien Nguyen after he was arrested on January 26, 2007, he waived his Miranda rights and told them pretty much everything. He admitted to using his computer to trade identities and credit card information, and he explained the GE Capital / Wal Mart scheme.

Enter the 9th Circuit


So, why after all this time is Nguyen just now pleading guilty? Apparently the defense's plan all along has been to say that all of the evidence that was obtained from Nguyen, INCLUDING HIS CONFESSION, was based on a warrantless search of the premises, which meant all of the evidence should be suppressed. After the recent 9th Circuit ruling, Nguyen's lawyer, Micheal K. Cernyar of Long Beach, California, thought he had fresh evidence, and on September 8, 2009 a hearing was held before the Honorable Morrison C. England, Jr, to hear this a plea to establish a new hearing for a new motion to suppress. Here are the basics outlined in the Motion to Suppress:

* Mr. Nguyen was arrested on or about January 26, 2007 on a Ramey Warrant at his residence located at 8225 & 8229 Gerber Road, Sacramento, California. "A warrantless search of the residence" uncovered all of the information, while Nguyen and his companion were detained in the living room of the home.

* On March 27, 2007, Special Agent Korbs applied for a federal search warrant seeking the items seized on January 26, 2007. After receiving this search warrant, Nguyen was indicted April 26, 2007.

* Nguyen moved "to suppress all evidence and any statements obtained" claiming his Fourth Amendment rights were violated, and his motion was denied October 15, 2008.

Here's the new part . . .

7. Last week, in United States v. Gonzalez -- F.3d --, (9th Cir. 2009) (D.C. No. 07-30098), the Ninth Circuit reversed a matter regarding suppression of evidence based upon a warrentless search when applying the recent ruling in Arizona v. Gant. The Ninth Circuit held that Mr. Gonzalez was entitled to benefit from the Supreme Court's ruling in Gant.

8. Counsel believes that the facts in Mr. Nguyen's warrentless search incident to arrest are at the very list similarly situated to those in the Gant and Gonzalez matter.


Rodney Joseph Gant v. Arizona was a case where a man was arrested, and after his arrest police went and searched his vehicle, which he was not in at the time of the arrest. In the car, they found cocaine, not related to the charges for which he had just been arrested, and expanded the charges to include drug possession. Because they did not have a warrant for the vehicular search, and because the perp was not in the vehicle, the Supreme Court ruled that they should not have searched the vehicle without a warrant. (This has been standard practice, called "The Bright Line rule" since 1981 . . .)

How does this relate to the 9th Circuit decision in US. v. Gonzales? It is well-established practice that police can perform a warrantless search "incident to arrest", meaning that after I've arrested you, it is "not unreasonable" to search for evidence related to the crime for which you have been arrested, both on your person, as well as in the immediate vicinity. The question of what is meant by the immediate vicinity is one that has had the legal scholars appealing searches on Fourth Amendment grounds over and over. In this case, it all starts with Chimel v. California. The Supreme Court held that when someone is arrested in their home, officers would be reasonable to search not only the room of the arrest, but other "sufficiently large spaces" where someone might be hiding that could be a risk to officer safety. So, the idea was, if I arrest you in your living room, but I feel that someone might be hiding in the closet, I can look in the closet, without a warrant, to see if your brother is hiding in their with a shotgun planning to jump out and shoot me. I couldn't search the drawer in the end-table, because it is unlikely a potential attacker is hiding in that drawer. Several arguments since then have argued whether you should only be able to do such a search if there was a suspicion that such a risk to officer safety was probable, and then, only in certain "reasonable areas", with three cases helping define those boundaries and expectations -- Maryland v. Buie, Belton v. New York, and Thornton v. United States. Arizona v. Gant reset those expectations by overruling some of those prior standards of when it was reasonable to do an "suspicionless search", which lead to the 9th Circuit Decision.

The judge rightly denied the motion to suppress, since this WAS a search "INCIDENT TO ARREST", and there was EVERY REASON to believe that the computers held relevant evidence of the crime for which Nguyen was being arrested, based on his own statements, and his own permission to search, meaning that NONE of those prior cases really had anything to do with this case.

With his last hope extinguished, Nguyen pleaded guilty, but even then went all the way to the wire. I really thought he was going to go to trial! His lawyer had submitted Questions for the Jury (Voire Dire) as recently as September 2, 2009! I had to chuckle as I read through them . . . he asks if they Bank Online, if they use their Debit Card online, if they have purchased online items in the past year . . . I thought the next question might be "Please state your debit card number slowly, and tell us your PIN." When it came down to the start of the Jury Trial, at 9:00 am on September 8th, the Courtroom minutes tell us that Nguyen asked for a five minute recess, and came back in and pleaded guilty to counts 1-4. He then asked for another recess, and came back and pleaded guilty to count 5.

The Penalty Slip with the indictment includes the charges. Especially sweet that the Aggravated Identity Theft adds an automatic +2 years. Nguyen was found to have a shotgun in his bedroom as well, a Remington 870 Express Magnum.

18 USC § 371 - Conspiracy to Commit Computer Fraud and Access Device Fraud:
- Not more than $250,000 or notmore than gross gain or loss;
- Not more than 5 years imprisonment, or both
- Not more than 3 years of supervised release

18 USC § 1029(a)(2) - Access Device Fraud
- Not more than $250,000 or not more than gross gain or gross loss;
- Not more than 5 years imprisonment, or both
- Not more than 3 years of supervised release

18 USC § 1029(a)(3) - Possession of More than 15 Unauthorized Access Devices
- Not more than $250,000 or not more than gross gain or gross loss;
- Not more than 10 years imprisonment, or both
- Not more than 3 years of supervised release

18 USC § 1028A(a)(1) - Aggravated Identity Theft
- Not more than $250,000 or not more than gross gain or gross loss;
- Not more than 2 years imprisonment, or both
- Not more than 3 years of supervised release

18 USC § 922(g)(1) - Felon in Possession of a Firearm or Ammunition
- Not more than $250,000 or not more than gross gain or gross loss;
- Not more than 10 years imprisonment, or both
- Not more than 3 years of supervised release

(Nguyen had already spent "more than a year" in jail back in 1999 for "Receipt of Stolen Property" and "Making and Passing Fictitious Checks", but these were state of California crimes rather than Federal crimes.)

The sentencing for Nguyen will be on November 19th, at 9:00 am.

The question for my student's research project is - "Was this a phishing investigation?" We haven't talked to Special Agent Korbs yet, but from a reading of the court documents, I believe the answer will be "No." This was a credit card fraud investigation, which uncovered a phishing case after the Computer Forensics evidence was evaluated.

The on-going and unsolved question for our research is, "Could this case have been worked the other way around?" If we had started with the Honolulu City and County Employees Credit Union phishing site, would we have still ended up at Tien Truong Nguyen's front door? If you are a law enforcement officer with first-hand experience in phishing investigations, we'd love to talk with you and get your opinion.

References: Stranger than Dictum: Why Arizona v. Gant Compels the Conclusion that Suspicionless Buie Searches Incident to Lawful Arrests are Unconstitutional by Colin Miller, Assistant Professor of the John Marshall Law School.
Read More
Posted in law enforcement, phishing | No comments

Wednesday, 2 September 2009

Bell Canada phish - still about the Cards

Posted on 04:11 by Unknown
As I was reviewing new spam categories from yesterday's mail to the UAB Spam Data Mine, I noticed a new phishing campaign against Bell Canada. It is important that consumers, who have been trained to believe that "phishing emails pretend to be banks" understand that ANY sort of company can send you a phishing email.

Apparently someone really wanted us to visit this phishing site, since we received more than 200 copies of the spam message. The site, which was still live this morning, more than 24 hours after the campaign had begun, looks like this:



I know what you're thinking. Why would anyone go to the trouble to steal the userid and password to my home telephone service? Perhaps the second page of questions will help answer that question:



After the phisher gets your Visa or Mastercard number, complete with Expiry date and Security Code, then we try for the Identity Theft Trifecta: Mother's Maiden Name, Date of Birth, and Social Insurance Number (the Canadian version of our Social Security Number). Of course they get a complete home address with home phone and employer just for good measure.

Phishing builds trust, by imitating a trusting relationship, and then asks more personal details. As consumers become more aware of "bank phishing", we will likely see more "non-bank phishing", hoping that the cautious behavior learned by banking customers doesn't generalize to the relationship with their phone company.

Truthfully, this was the second time that we have seen a Bell Canada phish, but the professionalism of this site is a huge improvement over the phish of July 28th. In the July 28th email, we were addressed as "Dear costumer" with a website that pointed to "ns2.e-karnet.net/home/Home_L-Login.pagelanguage=en®ion=ON.htm". That previous email came from "privacy@bell.ca" while the current email comes from "notification@bell-biling.ca". There were quite a few similarities however.

The target domain advertised in the new phishing campaign is:

upgrade-accounts.com

which was registered on August 30th with that most untrustworthy registrar, China Springboard. The computer on which this domain resides is 203.213.76.12, in Australia. According to DomainTools, that same computer is also the host of:

alliance-leicester056.com
alliance-leicester259.com
alliance-leicester304.com
alliance-leicester423.com
alliance-leicester603.com
alliance-leicester620.com
alliance-leicester628.com
alliance-leicester860.com
alliance-leicester907.com
my-pictures-downloads.com
and upgrade-accounts.com

DomainTools says that Upgrade-accounts.com has also been recently associated with the IP address 65.202.231.12, which has also served as the host of:

account-verifications.com
alliance-leicester076.com
alliance-leicester508.com
alliance-leicester528.com
alliance-leicester551.com

The account-verifications.com domain is the big news though! It has been mostly associated with a recent paypal phish using the host name paypal.account-verifications.com. Once that little piece of evidence slips in, we now see that this is actually a Fast Flux hosting botnet that specializes in phishing. Knowing that the bell.ca.upgrade-accounts.com may be a Fast Flux address, we switch modes to check for that, and come up with a HUGE list of computers - more than 120 computers, all of which have acted as the "webserver" for this phishing campaign.

Running quickly through the 128 IP addresses looking for additional hosts, we find a few big nameserver groups that tie the Bell Canada phishing campaign to other phishing campaigns hosted on the same Fast Flux network. Very significantly, however, this is NOT the same Fast Flux network currently being used to abuse Bank of America and KeyBank.

Some nameserver groups on this network:

ns3.the-breakfast-dreams.com used by:

alliance-leicester830.com
alliance-leicester860.com
alliance-leicester890.com
alliance-leicester551.com
alliance-leicester851.com
alliance-leicester312.com
alliance-leicester304.com
alliance-leicester174.com
alliance-leicester076.com
alliance-leicester727.com
alliance-leicester547.com
alliance-leicester508.com
alliance-leicester028.com
alliance-leicester528.com
alliance-leicester038.com
alliance-leicester068.com
alliance-leicester259.com

ns2.my-toshi-dns.com used by:

alliance-leicester620.com
alliance-leicester830.com
alliance-leicester850.com
alliance-leicester860.com
alliance-leicester890.com
alliance-leicester851.com
alliance-leicester312.com
alliance-leicester882.com
alliance-leicester603.com
alliance-leicester423.com
alliance-leicester963.com
alliance-leicester174.com
alliance-leicester065.com
alliance-leicester446.com
alliance-leicester056.com
alliance-leicester076.com
alliance-leicester547.com
alliance-leicester508.com
alliance-leicester718.com
alliance-leicester528.com
alliance-leicester628.com
alliance-leicester038.com
alliance-leicester259.com
verification-processing.com

ns2.the-tzone-strip.com used by:

my-pictures-downloads.com (such as doc_v1.my-pictures-downloads.com)

Other than the correction of the mis-spelled "Costumer" to "Customer", both emails have the same wording:




This e-mail was sent by Bell Canada to notify you that we have temporarily prevented access to your account.

We have reasons to believe that your account may have been accessed by someone else.

Please verify your details by following the link below :

http://www.bell.ca/account-activation?id=539933

© Bell Canada
( Please do not reply to this e-mail , this account is not monitored. Follow the instructions in the e-mail )





We only received one copy of the first email, sent from a single computer in Peoria, Illinois attached to the OmniLec network: 207.152.69.115

The new email came from botnet computers all over the world, including computers in Argentina, Belgium, Brazil, Chile, Germany, Hong Kong, India, Israel, Italy, Portugal, Russia, Singapore, Spain, Taiwan, Uruguay, Vietnam, as well as US based networks large and small.

The spamming program seems to be doing "false received lines" in the mail. So for instance, a computer in Spain has mail header lines that seem quite troubling at face value. "mail.royalbank-usa.com" or "mxe.jpmchase.com"? On further review these "trusted" mail senders have been falsely injected into the mail headers.


Received: from home (cm-85-152-241-195.telecable.es [85.152.241.195])
by [Gary's Server] (8.11.6/8.11.0) with ESMTP id n81JLV015681;
Tue, 1 Sep 2009 19:21:33 GMT
(envelope-from busybodiesoc8@home.com)
Received: from 85.152.241.195 by mxe.jpmchase.com; Tue, 1 Sep 2009 13:21:45 -0600
Date: Tue, 1 Sep 2009 13:21:45 -0600
From: Bell
X-Mailer: The Bat! (v2.00.2) Business
Reply-To: busybodiesoc8@home.com
X-Priority: 3 (Normal)
Message-ID: <236508618.53500285241073@home>
To: [Gary's spam trap]
Subject: Bell Online Notification
MIME-Version: 1.0
Content-Type: text/html;
charset=Windows-1252
Content-Transfer-Encoding: 7bit




Some computers associated with hosting this campaign:

bell.ca.upgrade-accounts.com 121.221.140.248
bell.ca.upgrade-accounts.com 121.221.214.232
bell.ca.upgrade-accounts.com 121.221.238.162
bell.ca.upgrade-accounts.com 124.13.162.53
bell.ca.upgrade-accounts.com 129.93.154.62
bell.ca.upgrade-accounts.com 129.93.176.255
bell.ca.upgrade-accounts.com 138.210.154.36
bell.ca.upgrade-accounts.com 149.84.93.20
bell.ca.upgrade-accounts.com 174.103.124.144
bell.ca.upgrade-accounts.com 200.87.22.27
bell.ca.upgrade-accounts.com 202.181.203.146
bell.ca.upgrade-accounts.com 202.77.97.227
bell.ca.upgrade-accounts.com 203.213.76.12
bell.ca.upgrade-accounts.com 204.118.0.2
bell.ca.upgrade-accounts.com 207.112.105.241
bell.ca.upgrade-accounts.com 207.255.141.194
bell.ca.upgrade-accounts.com 209.204.65.148
bell.ca.upgrade-accounts.com 209.204.65.155
bell.ca.upgrade-accounts.com 209.204.65.225
bell.ca.upgrade-accounts.com 209.204.73.181
bell.ca.upgrade-accounts.com 209.204.76.245
bell.ca.upgrade-accounts.com 212.183.199.25
bell.ca.upgrade-accounts.com 213.77.79.30
bell.ca.upgrade-accounts.com 213.94.231.25
bell.ca.upgrade-accounts.com 216.16.111.15
bell.ca.upgrade-accounts.com 216.209.249.145
bell.ca.upgrade-accounts.com 216.63.106.83
bell.ca.upgrade-accounts.com 217.166.213.26
bell.ca.upgrade-accounts.com 219.83.125.242
bell.ca.upgrade-accounts.com 220.253.17.133
bell.ca.upgrade-accounts.com 220.253.52.194
bell.ca.upgrade-accounts.com 220.253.7.121
bell.ca.upgrade-accounts.com 24.164.252.40
bell.ca.upgrade-accounts.com 24.176.238.10
bell.ca.upgrade-accounts.com 24.2.218.189
bell.ca.upgrade-accounts.com 24.224.130.181
bell.ca.upgrade-accounts.com 24.231.38.216
bell.ca.upgrade-accounts.com 24.24.222.220
bell.ca.upgrade-accounts.com 58.179.58.93
bell.ca.upgrade-accounts.com 60.51.55.131
bell.ca.upgrade-accounts.com 60.53.164.146
bell.ca.upgrade-accounts.com 60.53.50.130
bell.ca.upgrade-accounts.com 62.219.139.9
bell.ca.upgrade-accounts.com 64.150.244.50
bell.ca.upgrade-accounts.com 64.77.247.214
bell.ca.upgrade-accounts.com 65.202.231.12
bell.ca.upgrade-accounts.com 65.64.101.64
bell.ca.upgrade-accounts.com 65.75.110.66
bell.ca.upgrade-accounts.com 66.140.75.206
bell.ca.upgrade-accounts.com 66.169.38.6
bell.ca.upgrade-accounts.com 66.41.35.61
bell.ca.upgrade-accounts.com 66.56.48.61
bell.ca.upgrade-accounts.com 67.110.218.85
bell.ca.upgrade-accounts.com 67.176.38.186
bell.ca.upgrade-accounts.com 67.189.218.254
bell.ca.upgrade-accounts.com 67.244.94.2
bell.ca.upgrade-accounts.com 67.55.133.223
bell.ca.upgrade-accounts.com 67.77.32.172
bell.ca.upgrade-accounts.com 68.112.23.119
bell.ca.upgrade-accounts.com 68.127.17.153
bell.ca.upgrade-accounts.com 68.89.235.44
bell.ca.upgrade-accounts.com 69.228.83.3
bell.ca.upgrade-accounts.com 69.65.178.183
bell.ca.upgrade-accounts.com 69.88.210.46
bell.ca.upgrade-accounts.com 70.211.102.143
bell.ca.upgrade-accounts.com 70.220.79.109
bell.ca.upgrade-accounts.com 71.198.190.25
bell.ca.upgrade-accounts.com 71.205.3.107
bell.ca.upgrade-accounts.com 71.235.236.26
bell.ca.upgrade-accounts.com 71.236.171.101
bell.ca.upgrade-accounts.com 71.9.74.21
bell.ca.upgrade-accounts.com 72.188.10.131
bell.ca.upgrade-accounts.com 74.210.179.153
bell.ca.upgrade-accounts.com 75.198.56.175
bell.ca.upgrade-accounts.com 75.254.58.29
bell.ca.upgrade-accounts.com 75.26.163.159
bell.ca.upgrade-accounts.com 75.53.216.199
bell.ca.upgrade-accounts.com 75.64.12.251
bell.ca.upgrade-accounts.com 75.71.206.166
bell.ca.upgrade-accounts.com 76.106.45.169
bell.ca.upgrade-accounts.com 76.121.95.161
bell.ca.upgrade-accounts.com 76.211.231.228
bell.ca.upgrade-accounts.com 76.226.3.189
bell.ca.upgrade-accounts.com 77.126.129.61
bell.ca.upgrade-accounts.com 78.106.15.143
bell.ca.upgrade-accounts.com 79.179.121.187
bell.ca.upgrade-accounts.com 79.182.107.157
bell.ca.upgrade-accounts.com 79.78.247.155
bell.ca.upgrade-accounts.com 79.78.250.33
bell.ca.upgrade-accounts.com 80.186.4.160
bell.ca.upgrade-accounts.com 80.243.252.246
bell.ca.upgrade-accounts.com 81.56.250.159
bell.ca.upgrade-accounts.com 81.56.67.245
bell.ca.upgrade-accounts.com 81.57.3.231
bell.ca.upgrade-accounts.com 82.192.130.213
bell.ca.upgrade-accounts.com 82.224.8.132
bell.ca.upgrade-accounts.com 82.54.130.181
bell.ca.upgrade-accounts.com 83.217.136.210
bell.ca.upgrade-accounts.com 84.215.65.58
bell.ca.upgrade-accounts.com 84.224.17.130
bell.ca.upgrade-accounts.com 84.224.21.84
bell.ca.upgrade-accounts.com 84.224.59.118
bell.ca.upgrade-accounts.com 84.224.74.194
bell.ca.upgrade-accounts.com 84.224.82.197
bell.ca.upgrade-accounts.com 84.99.95.231
bell.ca.upgrade-accounts.com 86.20.198.55
bell.ca.upgrade-accounts.com 86.52.55.254
bell.ca.upgrade-accounts.com 88.169.2.156
bell.ca.upgrade-accounts.com 88.185.146.240
bell.ca.upgrade-accounts.com 88.61.120.136
bell.ca.upgrade-accounts.com 89.195.11.101
bell.ca.upgrade-accounts.com 89.195.203.163
bell.ca.upgrade-accounts.com 89.195.69.140
bell.ca.upgrade-accounts.com 91.67.60.242
bell.ca.upgrade-accounts.com 92.11.210.200
bell.ca.upgrade-accounts.com 92.15.0.90
bell.ca.upgrade-accounts.com 92.41.10.236
bell.ca.upgrade-accounts.com 92.49.112.66
bell.ca.upgrade-accounts.com 93.80.43.196
bell.ca.upgrade-accounts.com 93.81.219.84
bell.ca.upgrade-accounts.com 95.221.8.233
bell.ca.upgrade-accounts.com 98.154.121.106
bell.ca.upgrade-accounts.com 98.193.136.121
bell.ca.upgrade-accounts.com 98.208.170.143
bell.ca.upgrade-accounts.com 98.239.34.67
bell.ca.upgrade-accounts.com 99.144.178.98
ns2.my-toshi-dns.com 216.16.111.15
ns2.my-toshi-dns.com 24.164.252.40
ns2.my-toshi-dns.com 64.150.244.50
ns2.my-toshi-dns.com 66.41.35.61
ns2.my-toshi-dns.com 67.60.51.148
ns2.my-toshi-dns.com 68.61.133.232
ns2.my-toshi-dns.com 69.88.210.46
ns2.my-toshi-dns.com 72.188.10.131
ns2.my-toshi-dns.com 74.137.209.179
ns2.my-toshi-dns.com 76.106.45.169
ns2.my-toshi-dns.com 76.226.3.189
ns2.my-toshi-dns.com 79.182.107.157
ns2.my-toshi-dns.com 82.81.59.108
ns2.my-toshi-dns.com 98.231.216.148
ns2.my-toshi-dns.com 99.144.178.98
ns2.my-toshi-dns.com 99.145.1.33
ns3.the-breakfast-dreams.com 138.210.154.36
ns3.the-breakfast-dreams.com 204.118.0.2
ns3.the-breakfast-dreams.com 216.16.111.15
ns3.the-breakfast-dreams.com 24.224.130.181
ns3.the-breakfast-dreams.com 24.24.222.220
ns3.the-breakfast-dreams.com 64.150.244.50
ns3.the-breakfast-dreams.com 66.56.48.61
ns3.the-breakfast-dreams.com 67.176.38.186
ns3.the-breakfast-dreams.com 67.189.218.254
ns3.the-breakfast-dreams.com 69.88.210.46
ns3.the-breakfast-dreams.com 71.9.74.21
ns3.the-breakfast-dreams.com 75.53.216.199
ns3.the-breakfast-dreams.com 76.106.45.169
ns3.the-breakfast-dreams.com 76.226.3.189
ns3.the-breakfast-dreams.com 79.182.107.157
ns3.the-breakfast-dreams.com 99.144.178.98

Here is a sample of the Paypal version of this phishing campaign . . . the samples received on 02SEP09 actually give the red-letter due date of September 4, 2009.



And this is what the destination website looks like:



paypal.account-verifications.com 121.221.178.220
paypal.account-verifications.com 121.221.27.162
paypal.account-verifications.com 121.221.38.55
paypal.account-verifications.com 124.13.161.90
paypal.account-verifications.com 124.178.143.91
paypal.account-verifications.com 124.178.61.167
paypal.account-verifications.com 138.210.154.36
paypal.account-verifications.com 143.238.217.216
paypal.account-verifications.com 149.84.93.20
paypal.account-verifications.com 173.24.196.107
paypal.account-verifications.com 174.103.124.144
paypal.account-verifications.com 174.112.140.242
paypal.account-verifications.com 189.100.238.142
paypal.account-verifications.com 189.102.0.4
paypal.account-verifications.com 200.181.232.149
paypal.account-verifications.com 200.87.22.27
paypal.account-verifications.com 202.131.190.199
paypal.account-verifications.com 202.181.203.146
paypal.account-verifications.com 202.77.97.227
paypal.account-verifications.com 203.213.76.12
paypal.account-verifications.com 204.118.0.2
paypal.account-verifications.com 207.112.105.241
paypal.account-verifications.com 207.255.141.194
paypal.account-verifications.com 209.226.103.11
paypal.account-verifications.com 212.183.199.25
paypal.account-verifications.com 213.213.224.71
paypal.account-verifications.com 213.77.79.30
paypal.account-verifications.com 213.94.231.25
paypal.account-verifications.com 216.16.111.15
paypal.account-verifications.com 216.209.249.45
paypal.account-verifications.com 216.209.249.62
paypal.account-verifications.com 217.166.213.26
paypal.account-verifications.com 219.83.125.242
paypal.account-verifications.com 220.253.150.163
paypal.account-verifications.com 220.253.17.133
paypal.account-verifications.com 220.253.34.101
paypal.account-verifications.com 220.253.5.151
paypal.account-verifications.com 24.11.189.120
paypal.account-verifications.com 24.161.9.69
paypal.account-verifications.com 24.164.252.40
paypal.account-verifications.com 24.167.235.62
paypal.account-verifications.com 24.176.238.10
paypal.account-verifications.com 24.2.218.189
paypal.account-verifications.com 24.205.113.172
paypal.account-verifications.com 24.215.216.188
paypal.account-verifications.com 24.224.130.181
paypal.account-verifications.com 24.244.131.150
paypal.account-verifications.com 24.95.71.28
paypal.account-verifications.com 58.175.18.110
paypal.account-verifications.com 58.179.58.219
paypal.account-verifications.com 60.53.167.111
paypal.account-verifications.com 64.150.244.50
paypal.account-verifications.com 64.212.203.42
paypal.account-verifications.com 65.202.231.12
paypal.account-verifications.com 65.64.101.64
paypal.account-verifications.com 65.75.110.66
paypal.account-verifications.com 66.169.38.6
paypal.account-verifications.com 66.38.128.32
paypal.account-verifications.com 66.56.48.61
paypal.account-verifications.com 66.68.181.143
paypal.account-verifications.com 67.110.218.85
paypal.account-verifications.com 67.176.38.186
paypal.account-verifications.com 67.189.218.254
paypal.account-verifications.com 67.203.215.110
paypal.account-verifications.com 67.206.200.69
paypal.account-verifications.com 67.206.217.237
paypal.account-verifications.com 67.206.253.9
paypal.account-verifications.com 67.244.94.2
paypal.account-verifications.com 67.55.133.223
paypal.account-verifications.com 67.60.51.148
paypal.account-verifications.com 67.77.32.172
paypal.account-verifications.com 68.127.17.153
paypal.account-verifications.com 68.61.133.232
paypal.account-verifications.com 69.228.200.191
paypal.account-verifications.com 69.228.93.155
paypal.account-verifications.com 69.249.191.186
paypal.account-verifications.com 69.65.178.183
paypal.account-verifications.com 69.88.210.46
paypal.account-verifications.com 70.208.53.169
paypal.account-verifications.com 70.220.128.146
paypal.account-verifications.com 71.198.190.25
paypal.account-verifications.com 71.205.3.107
paypal.account-verifications.com 71.59.170.64
paypal.account-verifications.com 72.188.10.131
paypal.account-verifications.com 72.191.126.193
paypal.account-verifications.com 72.228.110.6
paypal.account-verifications.com 74.137.209.179
paypal.account-verifications.com 74.138.241.23
paypal.account-verifications.com 74.138.245.15
paypal.account-verifications.com 74.210.179.153
paypal.account-verifications.com 74.76.198.115
paypal.account-verifications.com 74.76.201.187
paypal.account-verifications.com 75.198.244.63
paypal.account-verifications.com 75.199.44.68
paypal.account-verifications.com 75.53.213.231
paypal.account-verifications.com 75.64.12.251
paypal.account-verifications.com 75.71.206.166
paypal.account-verifications.com 76.106.45.169
paypal.account-verifications.com 76.121.95.161
paypal.account-verifications.com 76.211.231.228
paypal.account-verifications.com 76.226.3.189
paypal.account-verifications.com 76.251.30.161
paypal.account-verifications.com 76.251.30.217
paypal.account-verifications.com 77.126.129.61
paypal.account-verifications.com 77.126.224.30
paypal.account-verifications.com 77.98.104.107
paypal.account-verifications.com 78.106.150.21
paypal.account-verifications.com 78.106.36.178
paypal.account-verifications.com 79.182.107.157
paypal.account-verifications.com 79.78.132.207
paypal.account-verifications.com 79.78.174.115
paypal.account-verifications.com 79.78.194.155
paypal.account-verifications.com 80.2.198.148
paypal.account-verifications.com 80.243.252.246
paypal.account-verifications.com 80.243.255.209
paypal.account-verifications.com 81.56.250.159
paypal.account-verifications.com 81.56.67.245
paypal.account-verifications.com 81.57.3.231
paypal.account-verifications.com 82.192.130.213
paypal.account-verifications.com 82.224.8.132
paypal.account-verifications.com 82.54.130.181
paypal.account-verifications.com 82.81.59.108
paypal.account-verifications.com 83.217.136.210
paypal.account-verifications.com 84.215.65.58
paypal.account-verifications.com 84.224.110.22
paypal.account-verifications.com 84.224.123.17
paypal.account-verifications.com 84.224.41.3
paypal.account-verifications.com 84.224.79.166
paypal.account-verifications.com 84.224.86.75
paypal.account-verifications.com 84.99.63.200
paypal.account-verifications.com 85.156.144.24
paypal.account-verifications.com 85.156.191.12
paypal.account-verifications.com 85.218.15.247
paypal.account-verifications.com 86.20.198.55
paypal.account-verifications.com 88.169.2.156
paypal.account-verifications.com 88.185.146.240
paypal.account-verifications.com 89.178.117.148
paypal.account-verifications.com 89.195.143.55
paypal.account-verifications.com 89.195.70.163
paypal.account-verifications.com 89.242.111.217
paypal.account-verifications.com 91.107.224.186
paypal.account-verifications.com 91.67.60.242
paypal.account-verifications.com 93.80.41.163
paypal.account-verifications.com 94.197.114.111
paypal.account-verifications.com 98.151.171.171
paypal.account-verifications.com 98.154.122.245
paypal.account-verifications.com 98.193.136.121
paypal.account-verifications.com 98.208.170.143
paypal.account-verifications.com 98.231.216.148
paypal.account-verifications.com 98.239.34.67
paypal.account-verifications.com 98.249.93.67
paypal.account-verifications.com 99.139.126.44
paypal.account-verifications.com 99.141.212.29
paypal.account-verifications.com 99.144.178.98
paypal.account-verifications.com 99.145.1.33
paypal.account-verifications.com 99.154.247.41
Read More
Posted in phishing, spam | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Vista Security Features
    BitLocker Drive Encryption A Real-world Windows Vista BitLocker Tip BitLocker Drive Encryption BitLocker Drive Encryption Frequently Asked Q...
  • A Prominent American Express Phish
    Every once in a while we see a spam campaign where we dig in to the complexity, expecting to find malware, and find that the criminal has ju...
  • Money Laundering $1 at a time - a win for the UK's PCeU
    In London a little-known police unit called the Police Central E-Crime Unit (PCeU) has scored another big win. For several years people hav...
  • 2008: Looking back on a Year of Spam and Malware
    Happy New Year! As we get ready for the New Year, there are quite a few security folks making predictions for 2009. I think my friend Dan...
  • Most Dangerous Cities for Cyber Crime?
    Symantec Riskiest Cybercrime Cities Symantec released a study today in conjunction with Sperling's Best Places today. According to thei...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Lin Mun Poo: Hacker of the Federal Reserve and ...?
    ** UPDATE: Poo arraigned and in custody ** On October 21, 2010, Malaysian citizen Lin Mun Poo landed at the JFK airport in New York and and ...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ▼  2013 (17)
    • ▼  November (1)
      • Tempting Photo Attachments Lead to Fake AV
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ►  August (23)
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile