Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 2 September 2009

Bell Canada phish - still about the Cards

Posted on 04:11 by Unknown
As I was reviewing new spam categories from yesterday's mail to the UAB Spam Data Mine, I noticed a new phishing campaign against Bell Canada. It is important that consumers, who have been trained to believe that "phishing emails pretend to be banks" understand that ANY sort of company can send you a phishing email.

Apparently someone really wanted us to visit this phishing site, since we received more than 200 copies of the spam message. The site, which was still live this morning, more than 24 hours after the campaign had begun, looks like this:



I know what you're thinking. Why would anyone go to the trouble to steal the userid and password to my home telephone service? Perhaps the second page of questions will help answer that question:



After the phisher gets your Visa or Mastercard number, complete with Expiry date and Security Code, then we try for the Identity Theft Trifecta: Mother's Maiden Name, Date of Birth, and Social Insurance Number (the Canadian version of our Social Security Number). Of course they get a complete home address with home phone and employer just for good measure.

Phishing builds trust, by imitating a trusting relationship, and then asks more personal details. As consumers become more aware of "bank phishing", we will likely see more "non-bank phishing", hoping that the cautious behavior learned by banking customers doesn't generalize to the relationship with their phone company.

Truthfully, this was the second time that we have seen a Bell Canada phish, but the professionalism of this site is a huge improvement over the phish of July 28th. In the July 28th email, we were addressed as "Dear costumer" with a website that pointed to "ns2.e-karnet.net/home/Home_L-Login.pagelanguage=en®ion=ON.htm". That previous email came from "privacy@bell.ca" while the current email comes from "notification@bell-biling.ca". There were quite a few similarities however.

The target domain advertised in the new phishing campaign is:

upgrade-accounts.com

which was registered on August 30th with that most untrustworthy registrar, China Springboard. The computer on which this domain resides is 203.213.76.12, in Australia. According to DomainTools, that same computer is also the host of:

alliance-leicester056.com
alliance-leicester259.com
alliance-leicester304.com
alliance-leicester423.com
alliance-leicester603.com
alliance-leicester620.com
alliance-leicester628.com
alliance-leicester860.com
alliance-leicester907.com
my-pictures-downloads.com
and upgrade-accounts.com

DomainTools says that Upgrade-accounts.com has also been recently associated with the IP address 65.202.231.12, which has also served as the host of:

account-verifications.com
alliance-leicester076.com
alliance-leicester508.com
alliance-leicester528.com
alliance-leicester551.com

The account-verifications.com domain is the big news though! It has been mostly associated with a recent paypal phish using the host name paypal.account-verifications.com. Once that little piece of evidence slips in, we now see that this is actually a Fast Flux hosting botnet that specializes in phishing. Knowing that the bell.ca.upgrade-accounts.com may be a Fast Flux address, we switch modes to check for that, and come up with a HUGE list of computers - more than 120 computers, all of which have acted as the "webserver" for this phishing campaign.

Running quickly through the 128 IP addresses looking for additional hosts, we find a few big nameserver groups that tie the Bell Canada phishing campaign to other phishing campaigns hosted on the same Fast Flux network. Very significantly, however, this is NOT the same Fast Flux network currently being used to abuse Bank of America and KeyBank.

Some nameserver groups on this network:

ns3.the-breakfast-dreams.com used by:

alliance-leicester830.com
alliance-leicester860.com
alliance-leicester890.com
alliance-leicester551.com
alliance-leicester851.com
alliance-leicester312.com
alliance-leicester304.com
alliance-leicester174.com
alliance-leicester076.com
alliance-leicester727.com
alliance-leicester547.com
alliance-leicester508.com
alliance-leicester028.com
alliance-leicester528.com
alliance-leicester038.com
alliance-leicester068.com
alliance-leicester259.com

ns2.my-toshi-dns.com used by:

alliance-leicester620.com
alliance-leicester830.com
alliance-leicester850.com
alliance-leicester860.com
alliance-leicester890.com
alliance-leicester851.com
alliance-leicester312.com
alliance-leicester882.com
alliance-leicester603.com
alliance-leicester423.com
alliance-leicester963.com
alliance-leicester174.com
alliance-leicester065.com
alliance-leicester446.com
alliance-leicester056.com
alliance-leicester076.com
alliance-leicester547.com
alliance-leicester508.com
alliance-leicester718.com
alliance-leicester528.com
alliance-leicester628.com
alliance-leicester038.com
alliance-leicester259.com
verification-processing.com

ns2.the-tzone-strip.com used by:

my-pictures-downloads.com (such as doc_v1.my-pictures-downloads.com)

Other than the correction of the mis-spelled "Costumer" to "Customer", both emails have the same wording:




This e-mail was sent by Bell Canada to notify you that we have temporarily prevented access to your account.

We have reasons to believe that your account may have been accessed by someone else.

Please verify your details by following the link below :

http://www.bell.ca/account-activation?id=539933

© Bell Canada
( Please do not reply to this e-mail , this account is not monitored. Follow the instructions in the e-mail )





We only received one copy of the first email, sent from a single computer in Peoria, Illinois attached to the OmniLec network: 207.152.69.115

The new email came from botnet computers all over the world, including computers in Argentina, Belgium, Brazil, Chile, Germany, Hong Kong, India, Israel, Italy, Portugal, Russia, Singapore, Spain, Taiwan, Uruguay, Vietnam, as well as US based networks large and small.

The spamming program seems to be doing "false received lines" in the mail. So for instance, a computer in Spain has mail header lines that seem quite troubling at face value. "mail.royalbank-usa.com" or "mxe.jpmchase.com"? On further review these "trusted" mail senders have been falsely injected into the mail headers.


Received: from home (cm-85-152-241-195.telecable.es [85.152.241.195])
by [Gary's Server] (8.11.6/8.11.0) with ESMTP id n81JLV015681;
Tue, 1 Sep 2009 19:21:33 GMT
(envelope-from busybodiesoc8@home.com)
Received: from 85.152.241.195 by mxe.jpmchase.com; Tue, 1 Sep 2009 13:21:45 -0600
Date: Tue, 1 Sep 2009 13:21:45 -0600
From: Bell
X-Mailer: The Bat! (v2.00.2) Business
Reply-To: busybodiesoc8@home.com
X-Priority: 3 (Normal)
Message-ID: <236508618.53500285241073@home>
To: [Gary's spam trap]
Subject: Bell Online Notification
MIME-Version: 1.0
Content-Type: text/html;
charset=Windows-1252
Content-Transfer-Encoding: 7bit




Some computers associated with hosting this campaign:

bell.ca.upgrade-accounts.com 121.221.140.248
bell.ca.upgrade-accounts.com 121.221.214.232
bell.ca.upgrade-accounts.com 121.221.238.162
bell.ca.upgrade-accounts.com 124.13.162.53
bell.ca.upgrade-accounts.com 129.93.154.62
bell.ca.upgrade-accounts.com 129.93.176.255
bell.ca.upgrade-accounts.com 138.210.154.36
bell.ca.upgrade-accounts.com 149.84.93.20
bell.ca.upgrade-accounts.com 174.103.124.144
bell.ca.upgrade-accounts.com 200.87.22.27
bell.ca.upgrade-accounts.com 202.181.203.146
bell.ca.upgrade-accounts.com 202.77.97.227
bell.ca.upgrade-accounts.com 203.213.76.12
bell.ca.upgrade-accounts.com 204.118.0.2
bell.ca.upgrade-accounts.com 207.112.105.241
bell.ca.upgrade-accounts.com 207.255.141.194
bell.ca.upgrade-accounts.com 209.204.65.148
bell.ca.upgrade-accounts.com 209.204.65.155
bell.ca.upgrade-accounts.com 209.204.65.225
bell.ca.upgrade-accounts.com 209.204.73.181
bell.ca.upgrade-accounts.com 209.204.76.245
bell.ca.upgrade-accounts.com 212.183.199.25
bell.ca.upgrade-accounts.com 213.77.79.30
bell.ca.upgrade-accounts.com 213.94.231.25
bell.ca.upgrade-accounts.com 216.16.111.15
bell.ca.upgrade-accounts.com 216.209.249.145
bell.ca.upgrade-accounts.com 216.63.106.83
bell.ca.upgrade-accounts.com 217.166.213.26
bell.ca.upgrade-accounts.com 219.83.125.242
bell.ca.upgrade-accounts.com 220.253.17.133
bell.ca.upgrade-accounts.com 220.253.52.194
bell.ca.upgrade-accounts.com 220.253.7.121
bell.ca.upgrade-accounts.com 24.164.252.40
bell.ca.upgrade-accounts.com 24.176.238.10
bell.ca.upgrade-accounts.com 24.2.218.189
bell.ca.upgrade-accounts.com 24.224.130.181
bell.ca.upgrade-accounts.com 24.231.38.216
bell.ca.upgrade-accounts.com 24.24.222.220
bell.ca.upgrade-accounts.com 58.179.58.93
bell.ca.upgrade-accounts.com 60.51.55.131
bell.ca.upgrade-accounts.com 60.53.164.146
bell.ca.upgrade-accounts.com 60.53.50.130
bell.ca.upgrade-accounts.com 62.219.139.9
bell.ca.upgrade-accounts.com 64.150.244.50
bell.ca.upgrade-accounts.com 64.77.247.214
bell.ca.upgrade-accounts.com 65.202.231.12
bell.ca.upgrade-accounts.com 65.64.101.64
bell.ca.upgrade-accounts.com 65.75.110.66
bell.ca.upgrade-accounts.com 66.140.75.206
bell.ca.upgrade-accounts.com 66.169.38.6
bell.ca.upgrade-accounts.com 66.41.35.61
bell.ca.upgrade-accounts.com 66.56.48.61
bell.ca.upgrade-accounts.com 67.110.218.85
bell.ca.upgrade-accounts.com 67.176.38.186
bell.ca.upgrade-accounts.com 67.189.218.254
bell.ca.upgrade-accounts.com 67.244.94.2
bell.ca.upgrade-accounts.com 67.55.133.223
bell.ca.upgrade-accounts.com 67.77.32.172
bell.ca.upgrade-accounts.com 68.112.23.119
bell.ca.upgrade-accounts.com 68.127.17.153
bell.ca.upgrade-accounts.com 68.89.235.44
bell.ca.upgrade-accounts.com 69.228.83.3
bell.ca.upgrade-accounts.com 69.65.178.183
bell.ca.upgrade-accounts.com 69.88.210.46
bell.ca.upgrade-accounts.com 70.211.102.143
bell.ca.upgrade-accounts.com 70.220.79.109
bell.ca.upgrade-accounts.com 71.198.190.25
bell.ca.upgrade-accounts.com 71.205.3.107
bell.ca.upgrade-accounts.com 71.235.236.26
bell.ca.upgrade-accounts.com 71.236.171.101
bell.ca.upgrade-accounts.com 71.9.74.21
bell.ca.upgrade-accounts.com 72.188.10.131
bell.ca.upgrade-accounts.com 74.210.179.153
bell.ca.upgrade-accounts.com 75.198.56.175
bell.ca.upgrade-accounts.com 75.254.58.29
bell.ca.upgrade-accounts.com 75.26.163.159
bell.ca.upgrade-accounts.com 75.53.216.199
bell.ca.upgrade-accounts.com 75.64.12.251
bell.ca.upgrade-accounts.com 75.71.206.166
bell.ca.upgrade-accounts.com 76.106.45.169
bell.ca.upgrade-accounts.com 76.121.95.161
bell.ca.upgrade-accounts.com 76.211.231.228
bell.ca.upgrade-accounts.com 76.226.3.189
bell.ca.upgrade-accounts.com 77.126.129.61
bell.ca.upgrade-accounts.com 78.106.15.143
bell.ca.upgrade-accounts.com 79.179.121.187
bell.ca.upgrade-accounts.com 79.182.107.157
bell.ca.upgrade-accounts.com 79.78.247.155
bell.ca.upgrade-accounts.com 79.78.250.33
bell.ca.upgrade-accounts.com 80.186.4.160
bell.ca.upgrade-accounts.com 80.243.252.246
bell.ca.upgrade-accounts.com 81.56.250.159
bell.ca.upgrade-accounts.com 81.56.67.245
bell.ca.upgrade-accounts.com 81.57.3.231
bell.ca.upgrade-accounts.com 82.192.130.213
bell.ca.upgrade-accounts.com 82.224.8.132
bell.ca.upgrade-accounts.com 82.54.130.181
bell.ca.upgrade-accounts.com 83.217.136.210
bell.ca.upgrade-accounts.com 84.215.65.58
bell.ca.upgrade-accounts.com 84.224.17.130
bell.ca.upgrade-accounts.com 84.224.21.84
bell.ca.upgrade-accounts.com 84.224.59.118
bell.ca.upgrade-accounts.com 84.224.74.194
bell.ca.upgrade-accounts.com 84.224.82.197
bell.ca.upgrade-accounts.com 84.99.95.231
bell.ca.upgrade-accounts.com 86.20.198.55
bell.ca.upgrade-accounts.com 86.52.55.254
bell.ca.upgrade-accounts.com 88.169.2.156
bell.ca.upgrade-accounts.com 88.185.146.240
bell.ca.upgrade-accounts.com 88.61.120.136
bell.ca.upgrade-accounts.com 89.195.11.101
bell.ca.upgrade-accounts.com 89.195.203.163
bell.ca.upgrade-accounts.com 89.195.69.140
bell.ca.upgrade-accounts.com 91.67.60.242
bell.ca.upgrade-accounts.com 92.11.210.200
bell.ca.upgrade-accounts.com 92.15.0.90
bell.ca.upgrade-accounts.com 92.41.10.236
bell.ca.upgrade-accounts.com 92.49.112.66
bell.ca.upgrade-accounts.com 93.80.43.196
bell.ca.upgrade-accounts.com 93.81.219.84
bell.ca.upgrade-accounts.com 95.221.8.233
bell.ca.upgrade-accounts.com 98.154.121.106
bell.ca.upgrade-accounts.com 98.193.136.121
bell.ca.upgrade-accounts.com 98.208.170.143
bell.ca.upgrade-accounts.com 98.239.34.67
bell.ca.upgrade-accounts.com 99.144.178.98
ns2.my-toshi-dns.com 216.16.111.15
ns2.my-toshi-dns.com 24.164.252.40
ns2.my-toshi-dns.com 64.150.244.50
ns2.my-toshi-dns.com 66.41.35.61
ns2.my-toshi-dns.com 67.60.51.148
ns2.my-toshi-dns.com 68.61.133.232
ns2.my-toshi-dns.com 69.88.210.46
ns2.my-toshi-dns.com 72.188.10.131
ns2.my-toshi-dns.com 74.137.209.179
ns2.my-toshi-dns.com 76.106.45.169
ns2.my-toshi-dns.com 76.226.3.189
ns2.my-toshi-dns.com 79.182.107.157
ns2.my-toshi-dns.com 82.81.59.108
ns2.my-toshi-dns.com 98.231.216.148
ns2.my-toshi-dns.com 99.144.178.98
ns2.my-toshi-dns.com 99.145.1.33
ns3.the-breakfast-dreams.com 138.210.154.36
ns3.the-breakfast-dreams.com 204.118.0.2
ns3.the-breakfast-dreams.com 216.16.111.15
ns3.the-breakfast-dreams.com 24.224.130.181
ns3.the-breakfast-dreams.com 24.24.222.220
ns3.the-breakfast-dreams.com 64.150.244.50
ns3.the-breakfast-dreams.com 66.56.48.61
ns3.the-breakfast-dreams.com 67.176.38.186
ns3.the-breakfast-dreams.com 67.189.218.254
ns3.the-breakfast-dreams.com 69.88.210.46
ns3.the-breakfast-dreams.com 71.9.74.21
ns3.the-breakfast-dreams.com 75.53.216.199
ns3.the-breakfast-dreams.com 76.106.45.169
ns3.the-breakfast-dreams.com 76.226.3.189
ns3.the-breakfast-dreams.com 79.182.107.157
ns3.the-breakfast-dreams.com 99.144.178.98

Here is a sample of the Paypal version of this phishing campaign . . . the samples received on 02SEP09 actually give the red-letter due date of September 4, 2009.



And this is what the destination website looks like:



paypal.account-verifications.com 121.221.178.220
paypal.account-verifications.com 121.221.27.162
paypal.account-verifications.com 121.221.38.55
paypal.account-verifications.com 124.13.161.90
paypal.account-verifications.com 124.178.143.91
paypal.account-verifications.com 124.178.61.167
paypal.account-verifications.com 138.210.154.36
paypal.account-verifications.com 143.238.217.216
paypal.account-verifications.com 149.84.93.20
paypal.account-verifications.com 173.24.196.107
paypal.account-verifications.com 174.103.124.144
paypal.account-verifications.com 174.112.140.242
paypal.account-verifications.com 189.100.238.142
paypal.account-verifications.com 189.102.0.4
paypal.account-verifications.com 200.181.232.149
paypal.account-verifications.com 200.87.22.27
paypal.account-verifications.com 202.131.190.199
paypal.account-verifications.com 202.181.203.146
paypal.account-verifications.com 202.77.97.227
paypal.account-verifications.com 203.213.76.12
paypal.account-verifications.com 204.118.0.2
paypal.account-verifications.com 207.112.105.241
paypal.account-verifications.com 207.255.141.194
paypal.account-verifications.com 209.226.103.11
paypal.account-verifications.com 212.183.199.25
paypal.account-verifications.com 213.213.224.71
paypal.account-verifications.com 213.77.79.30
paypal.account-verifications.com 213.94.231.25
paypal.account-verifications.com 216.16.111.15
paypal.account-verifications.com 216.209.249.45
paypal.account-verifications.com 216.209.249.62
paypal.account-verifications.com 217.166.213.26
paypal.account-verifications.com 219.83.125.242
paypal.account-verifications.com 220.253.150.163
paypal.account-verifications.com 220.253.17.133
paypal.account-verifications.com 220.253.34.101
paypal.account-verifications.com 220.253.5.151
paypal.account-verifications.com 24.11.189.120
paypal.account-verifications.com 24.161.9.69
paypal.account-verifications.com 24.164.252.40
paypal.account-verifications.com 24.167.235.62
paypal.account-verifications.com 24.176.238.10
paypal.account-verifications.com 24.2.218.189
paypal.account-verifications.com 24.205.113.172
paypal.account-verifications.com 24.215.216.188
paypal.account-verifications.com 24.224.130.181
paypal.account-verifications.com 24.244.131.150
paypal.account-verifications.com 24.95.71.28
paypal.account-verifications.com 58.175.18.110
paypal.account-verifications.com 58.179.58.219
paypal.account-verifications.com 60.53.167.111
paypal.account-verifications.com 64.150.244.50
paypal.account-verifications.com 64.212.203.42
paypal.account-verifications.com 65.202.231.12
paypal.account-verifications.com 65.64.101.64
paypal.account-verifications.com 65.75.110.66
paypal.account-verifications.com 66.169.38.6
paypal.account-verifications.com 66.38.128.32
paypal.account-verifications.com 66.56.48.61
paypal.account-verifications.com 66.68.181.143
paypal.account-verifications.com 67.110.218.85
paypal.account-verifications.com 67.176.38.186
paypal.account-verifications.com 67.189.218.254
paypal.account-verifications.com 67.203.215.110
paypal.account-verifications.com 67.206.200.69
paypal.account-verifications.com 67.206.217.237
paypal.account-verifications.com 67.206.253.9
paypal.account-verifications.com 67.244.94.2
paypal.account-verifications.com 67.55.133.223
paypal.account-verifications.com 67.60.51.148
paypal.account-verifications.com 67.77.32.172
paypal.account-verifications.com 68.127.17.153
paypal.account-verifications.com 68.61.133.232
paypal.account-verifications.com 69.228.200.191
paypal.account-verifications.com 69.228.93.155
paypal.account-verifications.com 69.249.191.186
paypal.account-verifications.com 69.65.178.183
paypal.account-verifications.com 69.88.210.46
paypal.account-verifications.com 70.208.53.169
paypal.account-verifications.com 70.220.128.146
paypal.account-verifications.com 71.198.190.25
paypal.account-verifications.com 71.205.3.107
paypal.account-verifications.com 71.59.170.64
paypal.account-verifications.com 72.188.10.131
paypal.account-verifications.com 72.191.126.193
paypal.account-verifications.com 72.228.110.6
paypal.account-verifications.com 74.137.209.179
paypal.account-verifications.com 74.138.241.23
paypal.account-verifications.com 74.138.245.15
paypal.account-verifications.com 74.210.179.153
paypal.account-verifications.com 74.76.198.115
paypal.account-verifications.com 74.76.201.187
paypal.account-verifications.com 75.198.244.63
paypal.account-verifications.com 75.199.44.68
paypal.account-verifications.com 75.53.213.231
paypal.account-verifications.com 75.64.12.251
paypal.account-verifications.com 75.71.206.166
paypal.account-verifications.com 76.106.45.169
paypal.account-verifications.com 76.121.95.161
paypal.account-verifications.com 76.211.231.228
paypal.account-verifications.com 76.226.3.189
paypal.account-verifications.com 76.251.30.161
paypal.account-verifications.com 76.251.30.217
paypal.account-verifications.com 77.126.129.61
paypal.account-verifications.com 77.126.224.30
paypal.account-verifications.com 77.98.104.107
paypal.account-verifications.com 78.106.150.21
paypal.account-verifications.com 78.106.36.178
paypal.account-verifications.com 79.182.107.157
paypal.account-verifications.com 79.78.132.207
paypal.account-verifications.com 79.78.174.115
paypal.account-verifications.com 79.78.194.155
paypal.account-verifications.com 80.2.198.148
paypal.account-verifications.com 80.243.252.246
paypal.account-verifications.com 80.243.255.209
paypal.account-verifications.com 81.56.250.159
paypal.account-verifications.com 81.56.67.245
paypal.account-verifications.com 81.57.3.231
paypal.account-verifications.com 82.192.130.213
paypal.account-verifications.com 82.224.8.132
paypal.account-verifications.com 82.54.130.181
paypal.account-verifications.com 82.81.59.108
paypal.account-verifications.com 83.217.136.210
paypal.account-verifications.com 84.215.65.58
paypal.account-verifications.com 84.224.110.22
paypal.account-verifications.com 84.224.123.17
paypal.account-verifications.com 84.224.41.3
paypal.account-verifications.com 84.224.79.166
paypal.account-verifications.com 84.224.86.75
paypal.account-verifications.com 84.99.63.200
paypal.account-verifications.com 85.156.144.24
paypal.account-verifications.com 85.156.191.12
paypal.account-verifications.com 85.218.15.247
paypal.account-verifications.com 86.20.198.55
paypal.account-verifications.com 88.169.2.156
paypal.account-verifications.com 88.185.146.240
paypal.account-verifications.com 89.178.117.148
paypal.account-verifications.com 89.195.143.55
paypal.account-verifications.com 89.195.70.163
paypal.account-verifications.com 89.242.111.217
paypal.account-verifications.com 91.107.224.186
paypal.account-verifications.com 91.67.60.242
paypal.account-verifications.com 93.80.41.163
paypal.account-verifications.com 94.197.114.111
paypal.account-verifications.com 98.151.171.171
paypal.account-verifications.com 98.154.122.245
paypal.account-verifications.com 98.193.136.121
paypal.account-verifications.com 98.208.170.143
paypal.account-verifications.com 98.231.216.148
paypal.account-verifications.com 98.239.34.67
paypal.account-verifications.com 98.249.93.67
paypal.account-verifications.com 99.139.126.44
paypal.account-verifications.com 99.141.212.29
paypal.account-verifications.com 99.144.178.98
paypal.account-verifications.com 99.145.1.33
paypal.account-verifications.com 99.154.247.41
Read More
Posted in phishing, spam | No comments

Tuesday, 1 September 2009

Koobface wrecks Search results

Posted on 04:21 by Unknown
One question that people often ask when we describe how millions of computers are infected with malware is "Why would anyone do that?" The answer of course is: MONEY.

Some of these money making schemes are so convolluted that it seems unlikely that anyone could make any money at them, but even if they only make a couple pennies per day on each machine, when you have millions of compromised machines, that adds up over time.

Ellen Mesmer of Network World documented America's Ten Most Wanted Botnets last month, and placed Zeus at #1, followed by Koobface at #2. That's a pretty good prioritization system, and one we are following at UAB in our Malware Analysis lab. Zeus is straight-forward. It steals money by compromising their banking credentials, and stealing the money out of their bank accounts. Koobface is far more subtle. With more than 2.9 million compromised American computers, its well worth looking at closer.

UAB Computer Forensics now has three Malware Analysts looking at malware. Brian Tanner, the most senior of the crew, has been looking at Koobface on a regular basis since January, and has a good understanding of how it works. He walked me through the paces yesterday, explaining the most recent version, starting by clicking on a link posted by a "friend" we maintain on Facebook because we can always count on him to provide a link to the current malware.

In this case, the link appeared to be a "video" that our friend wanted us to play. In reality, it caused our goat machine to fetch a URL from the site:

rect08242009.com/youtube.com/w/?video/

That fetch actually pulled another file called "ups.php", which caused us to run code from:

masa31082009.com/go/fb_w.php

That program maintains a list of compromised Facebook user computers, and sends us to one of them to retrieve a page. On our first fetch, I got a page that looked like this:



Reloading the page repeatedly took us on a world tour of Koobface infected computers:

87.68.44.27 - Israel
77.209.151.61 - Spain
82.230.156.57 - France
81.218.240.227 - Israel
75.67.228.96 - United States
99.231.223.214 - Canada
62.219.75.124 - Israel
58.106.194.24 - Australia
196.217.41.210 - Morocco
92.236.36.252 - United Kingdom
190.160.116.8 - Chile
67.160.142.66 - United States
85.224.115.120 - Sweden
41.201.58.21 - Algeria
79.181.30.45 - Israel
71.225.221.135 - United States

Network Administrators, each of these pages (today) was loading the malware from a path called /0x3e8/. If you see anyone hitting that path on any of your IP addresses, you may have a Koobface infection on your network.

Each page was 100% identical to each other page.

After seeing the page, a program runs so that when you next click a mouse button or type a key, you receive a popup message telling you that you need to upgrade your Flash Player in order to see the video your friend is trying to share with you.

Of course, THAT is what infects your computer. You are prompted to download and execute a file called 'setup.exe' which is the actual Koobface malware. Once downloaded, the bad guys can cause your computer to do many new things.

A VirusTotal report on this malware indicates that it is currently detected by 23 of 41 anti-virus products, up by five from the 18 of 41 that detected it last night.

Network Administrators can recognize infected machines because they will communicate with some of the following Command & Control domains for this version of Koobface:

suz11082009.com
xtd2s0090815.com
rect08242009.com
zadnik270809.com
pari270809.com
mymegadomain03072009.com

and of course as we already mentioned, masa31082009.com.

Tanner unpacked the setup.exe binary and was able to find strings indicating that the malware knows how to interact with several social networking sites, including:

hi5.com
tagged.com
twitter.com
bebo.com
facebook.com
myspace.com
netlog.com

But how does the site make money? Koobface is the "infect and spread" function, but other malware dropped to our computer performed the "monetize" function. In our case, Koobface's command & control (C&C) server at suz11082009.com (61.235.117.83) gave us several .exe files, including ff2ie.exe, fb.61.exe, and v2prx.exe. These were copied to other file names after being downloaded, including "pp11.exe" and "mset.exe".

In our case, a fake anti-virus product, also known as a "scareware" installation, was downloaded and began pestering us relentlessly that our machine was infected with viruses and that we needed to purchase a copy of their fake anti-virus product in order to stop these messages from popping up. In our case the fake product was "PC AntiSpyWare 2010".

That is the more obvious money-maker. Its amazing how many people fall for this scam! Previous busts of scareware vendors indicate that they have dozens of employees in their companies and have sold millions of dollars worth of the fake products! The scam is described on the FTC's website as Free Security Scan Could Cost Time and Money, and took action against companies in December 2008, and June 2009 against one company who successfully sold their fake product to more than 1 million consumers!
That's $40 Million Dollars!

The other way that these companies make money is through "affiliate advertising programs". Brian Tanner demonstrated for me in the lab. On an uninfected computer, when one does a Google search, Google returns results, and then you can visit the pages by clicking on the link in the results tab. On a computer that had been infected with Koobface, a secondary infection had been downloaded which caused search results to be redirected through an elaborate network of affiliate advertising programs. In order to prevent too much suspicion, it seems that a random chance is performed before deciding whether to give you your real page, or take you to an advertising page instead.

Some examples that Brian showed me included:

Search for "dog" or "cat" -- took us to the 3M Scotch Fur Remover page, no matter what Google result we clicked on.

Search for "cheap games" -- took us to the Geek Life page (gklife.com), no matter what Google result we clicked on.

Search for "Symantec" or "McAfee" -- took us to "stopsign.com", no matter what Google result we clicked on.

By looking at a network packet capture, we could see that we were being routed through many hops, that usually began with a computer called "findy31.com".

So, findy31.com (85.13.236.155) would send us to "kc.mv.bidsystem.com" which would send us to "kc.xmlseasrch.miva.com" (204.137.28.195), which sent us to "www.toseeka.com".

Or, findy31.com would send us to xmlsearch.miva.com, which sent us to "www.shopica.com".

Of, findy31.com would send us to "atl.mv.bidsystem.com", which sent us to "atl.xmlsearch.miva.com" (66.150.51.151), which sent us to "www.stopsign.com".

Several of the pages we were redirected through are legitimate advertisement affiliate programs, which pay webmasters for referring traffic to their sites. The problem here is that some "bad affiliates" have joined their program, and are redirecting traffic by use of search engine result manipulation, instead of legitimately interested customers choosing to click on advertisements.

Brian's other discovery was in his analysis of the malware which performs the redirection. That malware had several hardcoded addresses to control its function, including some IP addresses, such as 69.162.121.82, 69.162.90.138, 69.162.84.186, 216.245,196.234, and also some domain names, including fire***eye.com, and f***briankrebs.com, and antisgetout.cn.

We shared the Brian Krebs domain with our friend at the Washington Post, who authors the excellent column "Security Fix". He responded with today's column From Koobface with Love, where he and Alex Lanstein from FireEye, another great security researcher, reflect on what it means to have a malware domain named after themselves. Alex calls it "a feather in his cap." Well done, gentlemen! Keep up the good fight!
Read More
Posted in koobface, malware | No comments

Friday, 24 July 2009

From Russia, With Love . . . new Postcard spam spies on your PC

Posted on 04:47 by Unknown
Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evening of July 22nd we began to receive Postcards from thousands of our friends, that we didn't even know we had!



The emails all looked pretty much the same . . .



But they actually pointed to many different websites:

www.postcards.org.deaseza.gs
www.postcards.org.deashza.cn
www.postcards.org.deashza.gs
www.postcards.org.deaswza.gs
www.postcards.org.gewasq.cn
www.postcards.org.gewasq.hn
www.postcards.org.hcpill.com
www.postcards.org.hcpill.net
www.postcards.org.hertfe.com.mx
www.postcards.org.hyrewa.com.mx
www.postcards.org.jukhyt.com.mx
www.postcards.org.kijerw.in
www.postcards.org.kiytre.eu
www.postcards.org.lensaq.com
www.postcards.org.lensaq.net
www.postcards.org.lenshe.com
www.postcards.org.lenshe.net
www.postcards.org.liwefz.cn
www.postcards.org.liwesz.gs
www.postcards.org.liwesz.hn
www.postcards.org.liwofz.in
www.postcards.org.qemuide.cn
www.postcards.org.qemuide.gs
www.postcards.org.qemuide.hn
www.postcards.org.qemuide.in

Each of these websites offers you the opportunity to download your postcard:




The "postcard" link actually downloads a program which infects your computer with "Zeus Bot" software, which allows the criminal to steal all of your passwords for your bank, email, FTP sites, social networking sites, etc.

Even if you are "smart" and don't download and run the "postcard.exe" program, the cyber criminal has placed other traps on his website. In this case, there is a hidden "iframe" on the page, which causes your computer to open a "hidden window" and run whatever commands are located on the website:

evgard.ru/img/in.php


These websites are part of a group of "fast flux hosted" domains, which the anti-phishing community has been calling "Avalanche" because of their similarity to the old Rock Phish criminal campaign. "Fast Flux" domains actually resolve to the IP addresses of innocent victim computers who have a "web proxy" secretly running on their computer. Our cybercrime researchers at UAB have identified more than 3,700 computers that have served as the "web proxy" for these campaigns so far, including several hundred computers in the United States. Each of those proxies looks up the real criminal website, and forwards the information back to their visitors, so that the victim never actually touches the criminal's true computer, only the web proxy of another victim.

Most recently this group has been used for a few different campaigns including:

Ally Bank

secure.ally.com.deaswq.com
secure.ally.com.deaswq.net
secure.ally.com.deasws.com
secure.ally.com.deasws.net
secure.ally.com.hcpill.com
secure.ally.com.hcpill.info
secure.ally.com.hcpill.net
secure.ally.com.picdll.com
secure.ally.com.picdll.net

Comerica

businessconnect.comerica.com.session-id-379.sandigocc.com.mx
businessconnect.comerica.com.session-id-4367610.sdcac.com.mx
businessconnect.comerica.com.session-id-5539.sandigocc.com.mx
businessconnect.comerica.com.session-id-562.dirmode.org.mx
businessconnect.comerica.com.session-id-6290003.dirmode.com.mx
businessconnect.comerica.com.session-id-6815.fikhi.com.mx

eBay

cgi.ebay.com.bvgfty.com
cgi.ebay.com.bvgfty.net
cgi.ebay.com.hukkil.com.mx
cgi.ebay.com.hyfers.com
cgi.ebay.com.hyfers.net
cgi.ebay.com.hyrrte.com
cgi.ebay.com.hyrrte.net
cgi.ebay.com.ikhy1.com
cgi.ebay.com.ikhy1.net
cgi.ebay.com.ikhya.com
cgi.ebay.com.ikhyi.com
cgi.ebay.com.ikhyi.net
cgi.ebay.com.ikhyk.com
cgi.ebay.com.ikhyk.net
cgi.ebay.com.ikhyl.com
cgi.ebay.com.ikhyl.net
cgi.ebay.com.ikhyt.com
cgi.ebay.com.ikhyt.net

They are able to sustain such a high throughput of phishing - those counterfeit bank websites which trick you into giving up your password - because they have an elaborate back end for laundering their money. An army of Americans have chosen to sign up for them to work as "money mules". Rather than taking the risk of performing the financial transactions themselves, the criminals have recruited people with different spam for "work at home" jobs to do the deed for them.

Here's an advertisement being offered currently by these same criminals:



In this case, they promise that you can be a "work at home" Customer Service Specialist, earning $27 per hour "+ a bonus per processed transaction".

Those "processed transactions" work like this.

1) They send someone a spam message with a link to a fake bank website

2) The victim gives up their userid and password on the fake website

3) The criminal logs in to the real bank's website using that information, and transfers money to the "Customer Service Specialist" AKA Money Mule.

4) The Mule then receives instructions on how to wire the money internationally, keeping a generation commission (money stolen from someone else's bank account!) for themselves.

In the new "ZBot" version of this scam, only step 1 changes. You no longer have to visit a fake bank website. Once you have the ZBot malware installed on your computer, the criminal gets your password when you visit your bank's real website. If you have multiple banks and multiple credit cards, the criminal will eventually have passwords to them all as you log in to multiple accounts. This is also true for business accounts. Brian Krebs recently reported how Bullitt County Kentucky lost $415,000 by having it transferred out of their own bank accounts and sent to dozens of Money Mules. The mules each received between $7,000 and $9,900 per transaction, and then wired most of that money overseas.

How prevalent is ZBot? IDG's Ellen Messmer reported this week in her article America's Ten Most Wanted Botnets that Zeus Bot now has 3.6 Million infected victims in the United States, slightly ahead of the 2.9 Million infected with Koobface.

That's 3.6 Million Americans whose computers and financial transactions are being spied upon by Russian criminals.

Do we know its Russian? ZeusBot is actually a system for stealing website data from victims. It comes complete with a nice Graphical User Interface for keeping track of your infected machines, and tools to allow you to prioritize certain banks that are of highest interest to you. At any given moment there are more than 400 distinct command & control sites active for Zeus, so its possible there are many criminals involved. However, the ZeusBot system is written in Russian, as are the users manuals. Some of those controllers are in the United States, and we encourage US Law Enforcement to do everything they can to get to the bottom of this situation.

Your friends in Computer Forensics Research and the security industry can help. Just ask.

SAFETY UPDATE

ATTENTION NETWORK ADMINISTRATORS!!!
If you are observing traffic to the following netblock please contact me at gar@cis.uab.edu. Thank you!

91.213.72.0/24

This netblock is where the Zeus controller for the postcards malware is sitting. Its already shifted several times this week, but included:

91.213.72.10
91.213.72.11 - munaagami.net
91.213.72.12 - conscop.com
91.213.72.13 - pinesk.com

The version I visited this morning was using the "conscop.com" domain as its command and control.
Read More
Posted in malware, spam, zbot | No comments

Wednesday, 22 July 2009

Cyber IN-Security: Ten Times More Computer Security Graduates needed for .gov jobs

Posted on 08:40 by Unknown
One hour ago at the National Press Club, the Partnership for Public Service presented its report "Cyber IN-Security: Strengthening the Federal Cybersecurity Workforce". Participating in the presentation were:

- Ron Sanders, chief human capital officer, Director of National Intelligence
- Vance Hitch, chief information officer, Department of Justice
- Max Stier, president and CEO, Partnership for Public Service

A copy of the 36 page report, co-authored with Booz Allen Hamilton, is available from OurPublicService.org.

The first, and most important, of the four challenges described in the report is ...

1) The pipeline of potential new talent is inadequate.

The report says that only 40% of various hiring decision makers in federal agencies are "satisfied or very satisfied" with the quality of applicants applying for federal cybersecurity jobs and only 30 percent are satisfied or very satisfied with the number of qualified candidates who are applying. The need is for "closer to 1,000 graduates a year" to fill these jobs, as opposed to the current 120 graduates provided through the Scholarships for Service program.

A couple quotes from the report:
Defense Secretary Robert Gates has stated that the Pentagon is "desperately short of people who have capabilities (defensive and offensive cybersecurity war skills) in all the services and we have to address it." ... Three-fourths of CIOs, CISOs, IT hiring managers, and HR professionals surveyed for this report said attracting skilled cybersecurity talent would be a "high" or "top" priority for the next two fiscal years.


Much like our government did during the space race, the White House should lead a nationwide effort to encourage more Americans to develop technology, math and science skills. In conjunction with this effort, Congress should fund expansion of the successful programs that provide graduate and undergraduate scholarships in computer science and cybersecurity fields, such as the Scholarship for Service program, in return for a commitment to government service.


Victor Piotrowski, who heads the Scholarship for Service program, says there are currently 870 students who have graduated from the program over its lifetime, and that there are 225 students currently enrolled in the program nationally. The pipeline currently produces 120 students per year, but Victor says the need is for "between 500 and 1,000 such graduates" every year. His program is currently funded at $12 Million per year, although the Cyber Security Act of 2009, proposed by Senator Jay Rockefeller from West Virginia, would raise that to $300 million over five years.

The report also quotes Alan Paller from SANS Institute, who says "There is a radical shortage of people who can fight in cyber space -- penetration testers, aggressors, and vulnerability analysts. My sense is it is an order of magnitude short, a factor of 10 short."

Other agencies quoted in the report describe that they are being "outbid by other agencies", and that the existing pool gets snapped up by the "FBI, NSA, and DHS", leaving other federal agencies without the talent they need.

The Pentagon has estimated that their military, civilian, and contractor workforce dedicated to cybersecurity positions is 90,000 personnel, while the non-DOD cybersecurity workforce is estimated at between 35,000 to 45,000. The Intelligence community, who we have seen takes "the majority" of new hires, has a classified number of workers in this space as well.

Other critical concerns raised by the report are that . . .

- The Hiring Process is Broken
- Government Lacks Clear Definitions for Cybersecurity Jobs
- No Career Path for Cybersecurity Workers
- Pay Limitations Make It Harder for Government to Compete for Top Talent

From my position as the Director of Research in Computer Forensics at the University of Alabama at Birmingham I'm focusing on trying to do our part to help. Students who come through our program will have a solid foundation in the basics of information assurance that are taught in the core of our program, such as Internetworking, Computer Security, Network Security, etc., but we then specialize in addressing the needs of future cybercrime investigators.

In "Law, Evidence and Procedure", students get a broad look at our Justice system and how cases move through it.

In "Introduction to Computer Forensics" we then explain how a computer security "incident" fits into that framework and how the rules they heard about in LEP apply to the specifics of cybercrime cases and cases involving digital evidence.

In "Cybercrime & Forensics" students explore the side of Computer Forensics which we call "Media Forensics", learning about how files are stored on disks, and getting practical experience using the same tools they will encounter in the field, duplicating hard drives to create a forensic working copy, understanding the structure of FAT and NTFS file systems, learning to recover deleted files, crack passwords, decrypt files, and thoroughly document a piece of digital media using tools such as EnCase.

In "Investigating Online Crime" students explore the other side of Computer Forensics which we call "Network Forensics", meaning how the various computers involved in a case interact with one another. From a legal process perspective, this course introduces the students to various tools to retrieve data from providers, including subpoenas, search warrants, etc, as well as what burden of proof is required for each, and for the indictment. Guest speakers include both local and federal law enforcement, and both local and federal prosecutors who share details of actual cases with the students, stressing WHY certain information was required to move their case forward, and any legal or technical barriers that had to be overcome. Students create original applications for analysing cybercrime and digital evidence, and work with Analyst tools, including I2 Analysts Notebook and Maltego to prepare mock presentations for investigators, prosecutors, judges, and juries to document a wide variety of cases.

Top students in our program are also invited to join our research team, where we have active projects working on real cases related to Spam, Phishing, Malware, and website attacks.

I'm excited to see the focus being brought on the great need for graduates who can take on these Cyber Security positions, and hope that many potential graduates will come join us at UAB to prepare themselves for those jobs. Our Certificate in Computer Forensics is available with the Masters or PhD in Computer & Information Science, or with the Masters in Criminal Justice.
Read More
Posted in computer security careers, public policy | No comments

Tuesday, 21 July 2009

Twitter search leads to Naked Newscaster malware (Erin Andrews)

Posted on 04:13 by Unknown
Some folks saw this ABC News story yesterday, and sent me surprised questions that I hadn't blogged about it, so, here is the after-the-fact blog about a situation that is still continuing.



(click for ABC News story)

The story actually goes much bigger than that. Sure there are lots of people who have "erin andrews peephole photos" links on Twitter, and almost all of them are pointing to a virus, as we mentioned in the ABC News story.

As we've discussed several times in the past, this is another case of shortened URLs taking you to unknown pages, and Twitter training us all to blindly follow the link. Many of the links we've checked out all go to the same place. So, for example:

http://bit.ly/uUplf
http://bit.ly/zgkG1
http://bit.ly/31YLP9
http://bit.ly/105NfM
http://bit.ly/Wjtxe

all point to the same place . . .



Attempting to play the video there actually redirects you to a malware page where you will grab a link to the website lyy-exe.com and download a piece of malware called onlinemovies.40014.exe.

When we first scanned the malware yesterday morning, VirusTotal indicated that it was detected by four of 41 anti-virus products. By last night that was up to 10 of 41, and this morning when we rescanned (July 21st) the detection rate was XXXXXXXXXX

The rest of the story comes out as we look at the other posts made by some of the people who were posting links to the malware. We decided to grab a few that have posted in the past two hours, and see what else they were posting. Here's our sample group:

estefanikime, corinnenamlo, kaylahjofa, haydenluyan, sandynifa, stacilaqu, margaritloomm, beverlykineo, jazminekayam, stasianika, patsykasex, giselleheni, nadinebeeca, sidneydame, margaretfaxe, marniexuqu, unanilu, shanicebibee, trudypoohm.

It looks like the malware may actually be creating its own Twitter accounts, as these accounts for the most part have no followers, and are following no one. They seem to be depending on the fact that people actually "search" twitter, and their results will be found among the other results. This really points out the fact that Twitter needs to do something more than just their current LIFO (Last In First Out) search. If you search for a term, and I am the last person to post something with that term, you will see MY post, even if nobody follows me at all, even if I am an account that was created thirty minutes ago. Wouldn't it make more sense to see what the people are saying who are at least being followed by SOMEONE?

estefanikime has 0 followers and follows no one. Her recent news stories point to the sites:
legalmusic4all.com (an illegal music site hosted on NetDirekt in Germany)
fusionstories.com (an entertainment blog hosted on NetDirekt in Germany)

and several shortened URLs which use the subject lines:
watch erin andrews video => thecooltube.com
spinnerette => thecooltube.com
2009 espy award winners => thecooltube.com
tour de france stage 16 => thecooltube.com
t.o. show => thecooltube.com
blue spark => thecooltube.com
bachelorette men tell all => thecooltube.com

corinnenamlo has 4 followers but is following no one.
Her shortened URLs use the subject lines:
andrea mcnulty
tokyo rose => thecooltube.com
charleston high school mississippi => thecooltube.com
chuck yeager => thecooltube.com
throw it in the bag remix lyrics => thecooltube.com
jesse holley => thecooltube.com
inhaling duster => thecooltube.com
neil armstrong death => thecooltube.com
chris brown apology => thecooltube.com

Wait! I believe I'm detecting a pattern!

Other links being used included:
arturo gatti funeral
mullah krekar
aaron brink wife vanessa
tna victory road 2009 results
nomura s jellyfish
verizon wireless amphitheater irvine
lee westwood golfer
hgsi stock
labor pains lindsay lohan

All point to the malware site, "thecooltube.com".

When ABC News called yesterday, I was on my way to teach a class for the University of Alabama at Birmingham (UAB)'s Computer Forensics program. The course is called "Investigating Online Crime", and is a mix of Computer & Information Science and Criminal Justice students who are interested in careers in cybercrime investigations. I had been looking for an example for them to work on digging into a case using a variety of online tools, and Maltego from Paterva. I did a quick change-out on the case we would look at, and asked them to follow their leads on this one instead. They certainly found some interesting things!

With ten minutes to go before class, I also asked one of my graduate students, Malware Analyst Brian Tanner, to run a quick dynamic analysis of the malware in the lab. He pulled out some IP addresses of interest for the malware and some of the students included those IP addresses and domain names in their Maltego charts as well. Here are some of the sites that the malware connects to immediately after launching:

myart-gallery.com - 64.27.5.202
isyouimageshere.com - 66.197.155.150
imgesinstudioonline.com - 69.10.35.251
yourimagesstudio.com - 200.35.151.36
imagesrepository.com - 216.240.157.91
delphiner.com - 94.75.207.219
searchzoeken.com - 216.240.149.156

After this basic setup, the malware infected box goes nuts doing advertisement clickfraud, jumping back and forth between a variety of search sites, and following the resulting links, such as "homesearchnova.com" and "top100search.com" and "www-news-today.com" and "ad.reduxmedia.com" and "ad.yieldmanager.com" and "abcsearch.com" and "lucky5forme.com"

In our particular case, we were for some reason doing a lot of "Bollywood" related traffic, doing searches such as "hindi film actor photo" and ending up following links to places like "bollywoodhungama.com"

Someone interested in Advertising Click-Fraud may want to dig into this particular malware much more deeply.

Some of the other interesting clusters the students found were based on nameserver - for instance the nameserver "ns1.alvobs.com" is used by many domains which seem to be involved in tricking people into infecting themselves. Here are some of the domain names that they found were being actively visited:

agro-files-archive.com
allshemes.com
all-tube-world.com
analiticstat.com
best-light-search.com
besttubetech.com
chamitron.com
circuitsradio.com
datasheetcatalog.biz
dipexe.com
dirtydogaudio.com
downloadnativeexe.com
exedownloadfull.com
exe-paste.com
exe-soft-development.com
exe-xxx-file.com
eyeexe.com
getdatasheet.com
go-exe-go.com
greattubeamp.com
green-tube-site.com
holidayhomesearch.com
hotexedownload.com
humorbestimages.com
imagescopybetween.com
isyouimageshere.com
kazus.info
labsmedcom.com
last-exe-portal.com
lost-exe-site.com
luxartpics.com
lyy-exe.com
main-exe-home.com
my-exe-load.com
protectionimage.com
robo-exe.com
sk1project.org
softportal-extrafiles.com
softportal-files.com
sphericalart.com
storeyourimagehere.com
super0tube.com
super-exe-home.com
supertubetop.com
sysreport1.com
sysreport2.com
techdatasheets.com
testtubefilms.com
texasimages2009.com
the-blue-tube.com
thecooltube.com
thetubeamps.com
thetubesmovie.com
tiaexe.com
tube-best-4free.com
tube-collection.com
tubefaster.com
tvtesttube.com
yourtubetop.com

Many of these sites have already been shut down due to malware complaints. Hopefully Directi will look into the others as well.

One of the students ran the WHOIS on many of these domains and noticed that in addition to having invalid phone numbers (such as Tasha Chambers in Kearns Utah, who has the telephone: Tel. +001.98985647689) the pattern was to make either a gmail or a yahoo address using the first portion of the first and last names, so we had whois name/email pairs such as:

Chuck Jackson / chucjack@gmail.com
Colette Milton / colemilto@yahoo.com
Dion Choiniere / noelwollenberg@ymail.com (ok, breaks that pattern!)
Jamie Sires / jamisires@gmail.com
Leota Allison / leotallison@gmail.com
Malcolm Cromer / malccrome@gmail.com
Michael Barnes / michabarn@gmail.com
Norman Troup / normtroup@yahoo.com
Queenie Ziegler / queeziegl@gmail.com
Robyn Hamilton / robrhamil@gmail.com
Tasha Chambers / tashcham@gmail.com

Almost all of the domains that were owned by the people above had been terminated. Almost all of the domains registered to "PrivacyProtect.org" had NOT been terminated - which is probably because PrivacyProtect makes it hard to lodge a complaint based on the fact that the domain has false WHOIS information.

Domains that are still live are:

holidayhomesearch.com
protectionimage.com
imagescopybetween.com
greattubeamp.com
luxartpics.com
analiticstat.com
lyy-exe.com
chamitron.com
exe-soft-development.com
sk1project.org
dirtydogaudio.com
texasimages2009.com
allshemes.com
circuitsradio.com
datasheetcatalog.biz
kazus.info
techdatasheets.com
tubefaster.com
humorbestimages.com
labsmedcom.com
storeyourimagehere.com

After class, Brian got back into the lab to prove to me why he was better than the "automatic unpacker" I had used in class. As usual, he was amazing. He stepped through the malware with a debugger until it had unpacked itself fully into memory, and then dropped the image from memory to reveal even more hard-coded website names, including:

superarthome.com
and
robert-art.com

which seem to be "backup" command & controls. When we launched we sent a string "/senm.php?data=" to "myart-gallery.com", but apparently if that domain is unavailable, the code will try "robert-art.com" or "superarthome.com" instead.
Read More
Posted in twitter malware | No comments

Wednesday, 15 July 2009

Spammers Abusing URL Shortening Services

Posted on 07:57 by Unknown
We've previously warned about the dangers of following "Tiny URLs" on Twitter. With only 140 characters to use in your message, many Twitterers use URL shortening services to save their precious characters. Unfortunately, for most people you have no idea where that click is going to take you until you click on it and get forwarded by the URL shortening service. Its a bit like playing Russian roulette. Click the shortened URLs, and you may get informative news stories, insightful blog articles, pornography, or a new virus!

At the UAB Spam Data Mine we've seen a few of these Tiny URLs used in spam, but now we have our first major campaign that is exploiting them in a highly organized way.



Bingo Palms has a current spam campaign underway which involves a large number of these URL shorteners, including:

aafter.us
bit.ly
is.gd
jh.to
jtty.com
myurl.in
o.ly
phaze.me
sturly.com
tcbp.net
tlink.me
urltwitter.com


So far we've seen almost a thousand of these spam messages, and have encountered 453 unique URLs at this point. Here are the subjects that are being used in this spam campaign:

Subject: $10 free deposit
Subject: $5000 Jackpot waiting for you!
Subject: 200% bonus on every deposit
Subject: 75 and 90 Ball Bingo
Subject: Become A Bingo Hustler
Subject: Become A Winner Today
Subject: Become A Winner With Bingo
Subject: b-i-n-g-o for you!
Subject: Bingo has never been easier.
Subject: Bing-o Was Her Name-o
Subject: Do you like to play bingo online?
Subject: Enjoy Bingo Online
Subject: Ever wanted to play Bingo for Cash ?
Subject: Gamble online? Read me!
Subject: Gamble With Bingo
Subject: Gamble? Like to play online?
Subject: Hot 9-Real SLot Machines! $25,000 Jackpot
Subject: Hustle Online. Play Bingo.
Subject: Like Bingo? Win $
Subject: Nickel, Dime, Quarter, & High Roller Games!
Subject: Nightly Events for CASH Prizes
Subject: Online diplomas here.
Subject: Play Bing0 Online
Subject: Play Bingo Now
Subject: Play Bingo Today
Subject: play online
Subject: Play Online Now
Subject: Play Online, Win Today
Subject: Someone has invited you to a game of Bingo
Subject: Something For You. Play Online.
Subject: Vehicle Warranty - 60% off
Subject: Want to play bingo online and win CASH ?
Subject: Win With Bingo
Subject: You have been invited to a Bingo game!

We see this campaign as a dangerous precedence which could be followed by other spammers to make our efforts to block their spam more difficult. As one would expect, the spammer, in addition to cheating the affiliate program, and offering "probably illegal" gambling to his email recipients, is delivering his spam message through a world-wide botnet of compromised computers. Just in our spam samples, we have spam for this campaign sent from 698 different computers in 43 different countries around the world.

Afrinic countries of CI, MA, SD, ZA
APNIC countries of BD, HK, ID, IN, JP, KR, PK, TH, TW, VN
ARIN countries of US (only 6 machines)
LACNIC countries of AR, BR, CL, CO, MX, SV, VE
RIPENCC countries of AM, AZ, BY, DE, EU, GR, HR, HU, IL, IQ, IR, IT, KZ, MD, PL, PT, RO, RS, RU, UA, UZ

Despite a broad smattering of countries, 43% of our spam came from Brazil, 20% from Russia, 13% from the Ukraine, 7% from India, and 2% from Italy. No other country represented more than 1% of the spam we received in this campaign.


Here are the URLs that we have seen so far in this campaign:

http://aafter.us/0oysiA
http://aafter.us/15Exas
http://aafter.us/3d3V9e
http://aafter.us/459UeB
http://aafter.us/4fOecg
http://aafter.us/4R2udg
http://aafter.us/4YzvqA
http://aafter.us/6DvEsN
http://aafter.us/78Lj60
http://aafter.us/9GQEkZ
http://aafter.us/9TOYVb
http://aafter.us/A4Oc0S
http://aafter.us/AxwsYK
http://aafter.us/b9rkEe
http://aafter.us/bezEO3
http://aafter.us/BIyffd
http://aafter.us/ckqW55
http://aafter.us/cyHq06
http://aafter.us/D8kzvt
http://aafter.us/DBYJNk
http://aafter.us/dpJxBc
http://aafter.us/ew7332
http://aafter.us/FIDLQs
http://aafter.us/FJLPyM
http://aafter.us/fTJDW4
http://aafter.us/jptgOx
http://aafter.us/JwmKyP
http://aafter.us/jYg3j6
http://aafter.us/kdOH1o
http://aafter.us/knACii
http://aafter.us/motFQJ
http://aafter.us/n8quI5
http://aafter.us/N8U0Bq
http://aafter.us/P8o6Kn
http://aafter.us/PI3BvT
http://aafter.us/qDDkB6
http://aafter.us/QfSfkf
http://aafter.us/RH3z2F
http://aafter.us/rNqm6H
http://aafter.us/sEwQMU
http://aafter.us/siykT5
http://aafter.us/sY6RN1
http://aafter.us/TXgsXd
http://aafter.us/UxbBYV
http://aafter.us/vcmHnv
http://aafter.us/XwUWd3
http://aafter.us/YP4zHn
http://aafter.us/YUXbB4
http://aafter.us/ZjUAOw
http://bit.ly/10VJRX
http://bit.ly/11oYQ8
http://bit.ly/14egZi
http://bit.ly/15piKn
http://bit.ly/16aOsd
http://bit.ly/16iqi3
http://bit.ly/16temb
http://bit.ly/19AQlF
http://bit.ly/37LQeX
http://bit.ly/4mrqW9
http://bit.ly/8Tbvz
http://bit.ly/9K5r5
http://bit.ly/B0S1U
http://bit.ly/b3JyJ
http://bit.ly/E7hiD
http://bit.ly/eBlww
http://bit.ly/Ex5GL
http://bit.ly/EzZV4
http://bit.ly/FIolK
http://bit.ly/gj9Py
http://bit.ly/gQxNZ
http://bit.ly/ih7Di
http://bit.ly/iwdpY
http://bit.ly/joj8y
http://bit.ly/lhPp7
http://bit.ly/MOXP7
http://bit.ly/N3iVs
http://bit.ly/Q4XY0
http://bit.ly/q7EwA
http://bit.ly/RWnFc
http://bit.ly/tdLyV
http://bit.ly/TEXC4
http://bit.ly/tSW62
http://bit.ly/ttrZ5
http://bit.ly/tvZ0h
http://bit.ly/V2q7R
http://bit.ly/Ve1jJ
http://bit.ly/VI7n6
http://bit.ly/Vs7Tb
http://bit.ly/xiUSr
http://bit.ly/xJEcE
http://bit.ly/xjIii
http://bit.ly/YdVa5
http://is.gd/1xL2e
http://is.gd/1xL2f
http://is.gd/1xL2g
http://is.gd/1xL2h
http://is.gd/1xL2i
http://is.gd/1xL2k
http://is.gd/1xL4B
http://is.gd/1xL4E
http://is.gd/1xL4F
http://is.gd/1xL4G
http://is.gd/1xL4L
http://is.gd/1xL6e
http://is.gd/1xL6m
http://is.gd/1xL6o
http://is.gd/1xL6r
http://is.gd/1xL6u
http://is.gd/1xL6z
http://is.gd/1xL8H
http://is.gd/1xL8t
http://is.gd/1xLaB
http://is.gd/1xLaE
http://is.gd/1xLaK
http://is.gd/1xLaO
http://is.gd/1xLaP
http://is.gd/1xLaW
http://is.gd/1xLcS
http://is.gd/1xLdc
http://is.gd/1xLdg
http://is.gd/1xLdh
http://is.gd/1xLdi
http://is.gd/1xLeX
http://is.gd/1xLff
http://is.gd/1xLfG
http://is.gd/1xLfx
http://jh.to/1obuti
http://jh.to/3ulofu
http://jh.to/4alo9u
http://jh.to/4u0axo
http://jh.to/4u9o8u
http://jh.to/5ayoja
http://jh.to/9eyisi
http://jh.to/9i8ika
http://jh.to/do0eba
http://jh.to/do9ihu
http://jh.to/ha6e0u
http://jh.to/je2a9e
http://jh.to/le8iha
http://jh.to/li3iju
http://jh.to/lozi1i
http://jh.to/rokoye
http://jh.to/vetagi
http://jh.to/xu5onu
http://jh.to/yekife
http://jh.to/yilizo
http://jh.to/zeximo
http://jtty.com/05i
http://jtty.com/0g8k
http://jtty.com/640z
http://jtty.com/6g0
http://jtty.com/90jm
http://jtty.com/aeuw
http://jtty.com/afn2
http://jtty.com/alr9
http://jtty.com/bhsv
http://jtty.com/cgt2
http://jtty.com/clx8
http://jtty.com/cn69
http://jtty.com/dhs9
http://jtty.com/dqr6
http://jtty.com/e2b0
http://jtty.com/e589
http://jtty.com/ehlm
http://jtty.com/ejn3
http://jtty.com/ely7
http://jtty.com/eu27
http://jtty.com/fruy
http://jtty.com/gkot
http://jtty.com/hklq
http://jtty.com/htx3
http://jtty.com/ilq3
http://jtty.com/ilw4
http://jtty.com/ix12
http://jtty.com/ixz6
http://jtty.com/jk17
http://jtty.com/knwz
http://jtty.com/lw56
http://jtty.com/lwz2
http://jtty.com/nrz1
http://jtty.com/ouxz
http://jtty.com/rsv9
http://jtty.com/tyz6
http://jtty.com/tz68
http://jtty.com/vyz2
http://jtty.com/wpz0
http://jtty.com/wt0h
http://jtty.com/y0q3
http://myurl.in/2SA9A
http://myurl.in/3Kgq3
http://myurl.in/3txkM
http://myurl.in/50WTX
http://myurl.in/6MUXd
http://myurl.in/6rP1t
http://myurl.in/8m00V
http://myurl.in/8QnMd
http://myurl.in/9ml8L
http://myurl.in/AhDeA
http://myurl.in/AKF1g
http://myurl.in/AMJBY
http://myurl.in/BCD7U
http://myurl.in/BM1RA
http://myurl.in/CcSAD
http://myurl.in/cooWR
http://myurl.in/drm2U
http://myurl.in/e0LIu
http://myurl.in/EcZlr
http://myurl.in/Ezbrh
http://myurl.in/Fk2Qs
http://myurl.in/H6xsv
http://myurl.in/HbY51
http://myurl.in/HiUfB
http://myurl.in/ivqVE
http://myurl.in/kr0Xn
http://myurl.in/L62hH
http://myurl.in/LUk5g
http://myurl.in/NWsMe
http://myurl.in/oa5Zo
http://myurl.in/Oq8Jj
http://myurl.in/pWVr8
http://myurl.in/q6qsq
http://myurl.in/rhChK
http://myurl.in/th2Gr
http://myurl.in/TSR8k
http://myurl.in/u8jyb
http://myurl.in/UzmYY
http://myurl.in/vppYC
http://myurl.in/wZoeF
http://myurl.in/XAj2y
http://myurl.in/xIIll
http://myurl.in/Y2Dc7
http://myurl.in/YbCtF
http://myurl.in/YG2Ny
http://myurl.in/yl4s2
http://myurl.in/yxj2l
http://o.ly/qT1
http://o.ly/qT3
http://o.ly/qT4
http://o.ly/qT5
http://o.ly/qT6
http://o.ly/qT7
http://o.ly/qT8
http://o.ly/qT9
http://o.ly/qTA
http://o.ly/qTb
http://o.ly/qTC
http://o.ly/qTH
http://o.ly/qTJ
http://o.ly/qTK
http://o.ly/qTm
http://o.ly/qTn
http://o.ly/qTO
http://o.ly/qTR
http://o.ly/qTS
http://o.ly/qTU
http://o.ly/qTV
http://o.ly/qTW
http://o.ly/qTX
http://o.ly/qYF
http://o.ly/qYh
http://o.ly/qYi
http://o.ly/qYm
http://o.ly/qYn
http://o.ly/qYo
http://o.ly/qYp
http://o.ly/qYq
http://o.ly/qYS
http://o.ly/qYt
http://o.ly/qYv
http://o.ly/qYw
http://o.ly/qYx
http://o.ly/qYy
http://phaze.me/0994
http://phaze.me/0cjw
http://phaze.me/0r08
http://phaze.me/11c7
http://phaze.me/1j84
http://phaze.me/1jy4
http://phaze.me/2dsc
http://phaze.me/2s08
http://phaze.me/2tq6
http://phaze.me/2xzx
http://phaze.me/3k5z
http://phaze.me/3r3k
http://phaze.me/3trj
http://phaze.me/3v4x
http://phaze.me/4kdb
http://phaze.me/4q59
http://phaze.me/5314
http://phaze.me/5jb1
http://phaze.me/6gjq
http://phaze.me/6n6p
http://phaze.me/836x
http://phaze.me/ckyd
http://phaze.me/d4nf
http://phaze.me/dj19
http://phaze.me/ffrn
http://phaze.me/fn86
http://phaze.me/g30w
http://phaze.me/g68v
http://phaze.me/gm36
http://phaze.me/hwjf
http://phaze.me/jh88
http://phaze.me/jrny
http://phaze.me/k12t
http://phaze.me/m9b6
http://phaze.me/nq7c
http://phaze.me/nt1x
http://phaze.me/nz1b
http://phaze.me/p0q0
http://phaze.me/pkkt
http://phaze.me/rm2y
http://phaze.me/t4wq
http://phaze.me/tqn0
http://phaze.me/v1b0
http://phaze.me/vm98
http://phaze.me/vmtm
http://phaze.me/vqqw
http://phaze.me/w736
http://phaze.me/xptc
http://phaze.me/yqnd
http://phaze.me/zh2v
http://sturly.com/aal0
http://sturly.com/aal1
http://sturly.com/aal2
http://sturly.com/aal5
http://sturly.com/aal6
http://sturly.com/aalm
http://sturly.com/aalq
http://sturly.com/aalr
http://sturly.com/aals
http://sturly.com/aalv
http://sturly.com/aalw
http://sturly.com/aalx
http://sturly.com/aaly
http://sturly.com/aalz
http://sturly.com/aama
http://sturly.com/aamb
http://sturly.com/aamc
http://sturly.com/aame
http://sturly.com/aamf
http://sturly.com/aamg
http://sturly.com/aamh
http://sturly.com/aami
http://sturly.com/aamk
http://sturly.com/aaml
http://sturly.com/aams
http://sturly.com/aamu
http://tcbp.net/s9
http://tcbp.net/sa
http://tcbp.net/sB
http://tcbp.net/sc
http://tcbp.net/sd
http://tcbp.net/sE
http://tcbp.net/sF
http://tcbp.net/sg
http://tcbp.net/sh
http://tcbp.net/sI
http://tcbp.net/sj
http://tcbp.net/sk
http://tcbp.net/sl
http://tcbp.net/sN
http://tcbp.net/sQ
http://tcbp.net/sS
http://tcbp.net/st
http://tcbp.net/sW
http://tcbp.net/sX
http://tcbp.net/sY
http://tcbp.net/t0
http://tcbp.net/t2
http://tcbp.net/t3
http://tcbp.net/t5
http://tcbp.net/t7
http://tcbp.net/t8
http://tcbp.net/t9
http://tcbp.net/ta
http://tcbp.net/tb
http://tcbp.net/tc
http://tcbp.net/te
http://tcbp.net/ti
http://tcbp.net/tj
http://tcbp.net/tk
http://tlink.me/1499
http://tlink.me/1500
http://tlink.me/1501
http://tlink.me/1502
http://tlink.me/1503
http://tlink.me/1504
http://tlink.me/1505
http://tlink.me/1507
http://tlink.me/1508
http://tlink.me/1510
http://tlink.me/1514
http://tlink.me/1515
http://tlink.me/1516
http://tlink.me/1517
http://tlink.me/1518
http://tlink.me/1519
http://tlink.me/1520
http://tlink.me/1525
http://tlink.me/1526
http://tlink.me/1527
http://tlink.me/1529
http://tlink.me/1530
http://tlink.me/1532
http://tlink.me/1533
http://tlink.me/1534
http://tlink.me/1537
http://tlink.me/1538
http://tlink.me/1540
http://tlink.me/1542
http://tlink.me/1543
http://tlink.me/1545
http://tlink.me/1549
http://tlink.me/1550
http://tlink.me/1554
http://tlink.me/1555
http://tlink.me/1557
http://tlink.me/1560
http://tlink.me/1563
http://tlink.me/1564
http://tlink.me/1565
http://tlink.me/1566
http://tlink.me/1567
http://tlink.me/1569
http://tlink.me/1570
http://tlink.me/1571
http://tlink.me/1572
http://tlink.me/1573
http://tlink.me/1574
http://tlink.me/1575
http://tlink.me/1576
http://urltwitter.com/1ipevu
http://urltwitter.com/2i7isa
http://urltwitter.com/4aza2o
http://urltwitter.com/4otifu
http://urltwitter.com/5ireri
http://urltwitter.com/6eyoco
http://urltwitter.com/6i3eko
http://urltwitter.com/bi3e7o
http://urltwitter.com/bixaso
http://urltwitter.com/fale2e
http://urltwitter.com/gu3eto
http://urltwitter.com/jafabu
http://urltwitter.com/jarewa
http://urltwitter.com/kedopu
http://urltwitter.com/kuno6o
http://urltwitter.com/me3ajo
http://urltwitter.com/nasozi
http://urltwitter.com/so3afi
http://urltwitter.com/vido6a
http://urltwitter.com/wulule
http://urltwitter.com/yucazo
Read More
Posted in malware, twitter | No comments

Friday, 3 July 2009

Are You Ready for Independence Day Fireworks? Waledac is!

Posted on 07:38 by Unknown
Loyal Blog readers will know that the UAB Spam Data Mine has been tracking the Waledac spam campaigns since their onset. We've followed this worm through the Obama inauguration, Valentine's Day, A Fake Grocery Coupon scam, a Fake Reuters story about a terrorist bomb, and an SMS Spy program. Of course ALL of the domains associated with Waledac infection have been registered on ENAME.cn, the horribly managed Chinese registrar who seems to register more domains used in spam and malware than any other registrar on earth! Even though many of the SMS Spy version of the domains are still live, they have been forwarding to Canadian Pharmacy websites recently.

Until today.



Here is a sneak preview of the newest version of Waledac. Although the spam campaign has not yet started, the websites are already displaying this new YouTube page promising "Colorful Independence Day events took place throughout the country". The past tense indicates to us that this campaign probably won't take off until late on the day of July 4th. The video claims to be the "South Shore's Fourth of July fireworks show" which has been named by "The American Pyrotechnics Association" as the best display in the nation.

As with previous versions though, the problem is that when you click "play" on the fake YouTube page, you are invited to run "install.exe". What is that?

Unfortunately, its a demonstration of how Anti-Virus products work. Anti-virus products start to detect a virus when enough people complain about the virus to warrant the addition of the virus to their library of anti-virus signatures. In this case, because the virus hasn't been spammed yet, almost no one has complained, and as a result, almost no one knows that it is a virus. By the time the virus begins to spread on Saturday evening of a holiday weekend, how many anti-virus engineers will be in the shop to write a definition?

4 of 40 anti-virus products know to block this program!


Last year of course it was the Storm Worm that was spreading via Fourth of July fireworks, as we covered in our story Storm Worm Salutes Our Nation on 4th.

Hopefully with a little advance warning, we'll do a better job protecting ourselves this year!

We infected one machine with this version of Waledac to see what happened. The most immediate impact is that we started sending spam. The "install.exe" which we downloaded actually had the SMTP engine built in, so we would say this is the primary purpose. The Waledac executable is also doing huge volumes of peer to peer traffic, as before, talking to many things which seem to be nginx servers (but which are actually nginx Proxy servers.)

In addition to the spam-sending, we made connection to the website "securitytoolspro.com", which downloaded an executable "12690784.exe", which is actually a fake anti-virus product.

The first action of this download is to change our windows wallpaper to look like this:



Then the install begins:



After "scanning" our computer, it asks us to "Remove All Threats", which involves buying the product from a website:



An unpacked version of the Waledac malware can be retrieved from Eureka, which I used to do a lazy man's unpack:

Eureka Report. Clicking the "Strings" tab of that report will provide many hard-coded IP addresses which are part of the "start up" process for the peer to peer network.

UPDATE


We had set our spam traps up to let me know when we got our first Waledac Fireworks spam, and it JUST came in while I was at dinner! (Roughly twelve hours after my initial post of this article PREDICTING this spam campaign.)

The first spam message we received on this campaign was received from a Russian IP address, 94.255.18.91, and used the email subject: "Light up the sky". The body of the message was only one line, as with previous Waledac campaigns, and read: "American Independence Day" and contained a link the virus.

The hostile website in this email was "moviesfireworks.com".

Other email subjects we've seen include:

America the Beautiful
Celebrate the spirit of America
Celebrating the spirit of our Country
Celebrations have already begun
Happy Birthday America!
Long Live America
Super 4th!

The single line of text in the bodies of the emails have included:

America the Beautiful
Bright and joyful Fourth of July
Celebrate the spirit of America
Happy Birthday, America!
Long Live America
Super 4th!
The best of 4th of July Salute

So, we believe that the same spam template variable is probably being used for the subject line and the email body line.

The domain names we have actually seen in received emails so far are:

fireholiday.com
fireworksholiday.com
holidayfirework.com
holidaysfirework.com


As with all previous Waledac spam, these are "Fast Flux hosted" on a multitude of IP addresses.

Other Domain Names (DO NOT CLICK!!!!!)

fireworkspoint.com
moviesfireworks.com
moviefireworks.com

Jeremy from SudoSecure responded to one of my posts with information from his excellent Waledac tracker. I have to point out that his domain list is VERY complete, and that his blog post was one hour earlier than mine. 8-) But we aren't competing . . . 8-)

4thfirework.com
fireholiday.com
fireworksholiday.com
fireworksnetwork.com
fireworkspoint.com
handyphoneworld.com
happyindependence.com
holidayfirework.com
holidaysfirework.com
holifireworks.com
interactiveindependence.com
miosmschat.com
movie4thjuly.com
moviefireworks.com
movieindependence.com
movies4thjuly.com
moviesfireworks.com
moviesindependence.com
outdoorindependence.com
superhandycap.com
thehandygal.com
video4thjuly.com
videoindependence.com
yourhandyhome.com


Waledac Tracker at SudoSecure

Jeremy's Waledac Blog post



Domains should be updated here as people see them in their spam . . .

http://rss.uribl.com/nic/CHINA_SPRINGBOARD_INC_.html

These are being registered on China Springboard, which is a change of Registrar for Waledac, who has always used ENAME before. Of course the ENAME registrar is still loaded with horrible volumes of spam:

http://rss.uribl.com/nic/XIAMEN_ENAME_NETWORK_TECHNOLOGY_D_B_A_ENAME_CN_ENAME_COM.html


Thanks to our friends at URI Black List for providing those real time feeds of bad domains from Chinese registrars for us. They also have a feed for XIN NET:

http://rss.uribl.com/nic/XIN_NET_TECHNOLOGY_CORPORATION.html
Read More
Posted in malware, spam, waledac | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Vista Security Features
    BitLocker Drive Encryption A Real-world Windows Vista BitLocker Tip BitLocker Drive Encryption BitLocker Drive Encryption Frequently Asked Q...
  • A Prominent American Express Phish
    Every once in a while we see a spam campaign where we dig in to the complexity, expecting to find malware, and find that the criminal has ju...
  • Money Laundering $1 at a time - a win for the UK's PCeU
    In London a little-known police unit called the Police Central E-Crime Unit (PCeU) has scored another big win. For several years people hav...
  • 2008: Looking back on a Year of Spam and Malware
    Happy New Year! As we get ready for the New Year, there are quite a few security folks making predictions for 2009. I think my friend Dan...
  • Most Dangerous Cities for Cyber Crime?
    Symantec Riskiest Cybercrime Cities Symantec released a study today in conjunction with Sperling's Best Places today. According to thei...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Lin Mun Poo: Hacker of the Federal Reserve and ...?
    ** UPDATE: Poo arraigned and in custody ** On October 21, 2010, Malaysian citizen Lin Mun Poo landed at the JFK airport in New York and and ...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ▼  2013 (17)
    • ▼  November (1)
      • Tempting Photo Attachments Lead to Fake AV
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ►  August (23)
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile