Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 14 October 2009

Targeted URLs in spam . . .OWA Settings update

Posted on 16:40 by Unknown
All of our trap domains are seeing a new spam campaign today where the website being spammed actually SEEMS to be the email recipient's own domain.

The webpage claims to be a new Microsoft Outlook Web Access update.

Sample email:


Dear user of the mydomain.com mailing service!

We are informing you that because of the security upgrade of the mailing service your mailbox (mymail@mydomain.com) settings were changed. In order to apply the new set of settings click on the following link:

http://mydomains.com/owa/service_directory/settings.php?email=mymail@mydomain.com&from=mydomain.com&fromname=mymail

Best regards, mydomain.com Technical Support


The email subjects which have been used have been:

A new settings for for the mymail@mydomain.com mailbox has just been released
For the owner of the mymail@mydomain.com mailbox
The settings for the mymail@mydomain.com mailbox were changed

In this entire post, remember that where "mymail@mydomain.com" will be replaced by the actual email recipient's userid and domain name.

The websites look like this:



Of course the link is a new version of the Zeus / Zbot trojan.

http://mydomain.com.bertdffe.co.uk/owa/service_directory/settings.php
http://mydomain.com.bertdffe.eu/owa/service_directory/settings.php
http://mydomain.com.bertdffm.co.uk/owa/service_directory/settings.php
http://mydomain.com.bertdffm.eu/owa/service_directory/settings.php
http://mydomain.com.bertdffo.eu/owa/service_directory/settings.php
http://mydomain.com.bertdffw.co.uk/owa/service_directory/settings.php
http://mydomain.com.bertdffw.eu/owa/service_directory/settings.php
http://mydomain.com.nerrasssb.eu/owa/service_directory/settings.php
http://mydomain.com.nerrassso.eu/owa/service_directory/settings.php
http://mydomain.com.nerrasssp.co.uk/owa/service_directory/settings.php
http://mydomain.com.nerrasssp.eu/owa/service_directory/settings.php
http://mydomain.com.nerrassst.co.uk/owa/service_directory/settings.php
http://mydomain.com.nerrassst.eu/owa/service_directory/settings.php
http://mydomain.com.nerrasssu.co.uk/owa/service_directory/settings.php
http://mydomain.com.nerrasssu.eu/owa/service_directory/settings.php
http://mydomain.com.nerrasssw.co.uk/owa/service_directory/settings.php
http://mydomain.com.nerrasssw.eu/owa/service_directory/settings.php
http://mydomain.com.nerrasssx.co.uk/owa/service_directory/settings.php
http://mydomain.com.nerrasssx.eu/owa/service_directory/settings.php
http://mydomain.com.nerrasssy.co.uk/owa/service_directory/settings.php
http://mydomain.com.nerrasssy.eu/owa/service_directory/settings.php
http://mydomain.com.oikkkkua.co.uk/owa/service_directory/settings.php
http://mydomain.com.oikkkkua.eu/owa/service_directory/settings.php
http://mydomain.com.oikkkkuf.co.uk/owa/service_directory/settings.php
http://mydomain.com.oikkkkuf.eu/owa/service_directory/settings.php
http://mydomain.com.oikkkkuh.co.uk/owa/service_directory/settings.php
http://mydomain.com.oikkkkuh.eu/owa/service_directory/settings.php
http://mydomain.com.oikkkkuy.co.uk/owa/service_directory/settings.php
http://mydomain.com.oikkkkuy.eu/owa/service_directory/settings.php
http://mydomain.com.polikka.eu/owa/service_directory/settings.php
http://mydomain.com.polikki.co.uk/owa/service_directory/settings.php
http://mydomain.com.polikki.eu/owa/service_directory/settings.php
http://mydomain.com.polikko.co.uk/owa/service_directory/settings.php
http://mydomain.com.polikko.eu/owa/service_directory/settings.php
http://mydomain.com.polikkp.co.uk/owa/service_directory/settings.php
http://mydomain.com.polikkp.eu/owa/service_directory/settings.php
http://mydomain.com.wsasdec.eu/owa/service_directory/settings.php
http://mydomain.com.wsasdep.co.uk/owa/service_directory/settings.php
http://mydomain.com.wsasdep.eu/owa/service_directory/settings.php
http://mydomain.com.wsasder.co.uk/owa/service_directory/settings.php
http://mydomain.com.wsasder.eu/owa/service_directory/settings.php
http://mydomain.com.wsasdev.co.uk/owa/service_directory/settings.php
http://mydomain.com.wsasdev.eu/owa/service_directory/settings.php
http://mydomain.com.wsasdez.co.uk/owa/service_directory/settings.php
Read More
Posted in | No comments

IRS Zeus via Geocities

Posted on 13:41 by Unknown
After a couple days with no "IRS Zeus" spam, the flow of spam messages has restarted. The new spam messages are exactly like the ones we've been seeing since September 9th, with one very significant difference:


Subject: Notice of Underreported Income


Taxpayer ID: e0cdd8db-00000684284766US
Tax Type: INCOME TAX
Issue: Unreported/Underreported Income (Fraud Application)

Please review your tax statement on Internal Revenue Service (IRS) website (click on the link below):

review tax statement for taxpayer id: e0cdd8db-00000684284766US

Internal Revenue Service


Two changes are that my email address is no longer part of the "taxpayer id", nor is it part of the URL to which the spam directs me.

When I followed the link in the most recent spam message, I "eventually" end up on the website:

http://www.irs.gov.nerrasssb.co.uk/fraud_application/directory/statement.php?tid=target-00000169290787US

however, that URL is *NOT* what is present in the email message!

http://geocities.com/AnnabelleRichardson78/yredaxubu.htm
http://geocities.com/AshleyWyatt42/ohulociqam.htm
http://geocities.com/AustinHobbs20/nulaxubumul.htm
http://geocities.com/AveryGoodwin43/ihociqamy.htm
http://geocities.com/bcwowpuyne/yredaxubu.htm
http://geocities.com/BillSantos33/nulaxubumu.htm
http://geocities.com/BriannaHensley06/yredax.htm
http://geocities.com/DamienMorris57/apegapyzap.htm
http://geocities.com/ddfsteyxbext/alynahej.htm
http://geocities.com/DevinSnyder65/ikahejov.htm
http://geocities.com/EdwinRandall53/nulaxubumul.htm
http://geocities.com/EltonLawson02/uwalajahe.htm
http://geocities.com/foayoqetpxe/nulaxu.htm
http://geocities.com/FreddyCampbell36/ohuloc.htm
http://geocities.com/hshybmbcg/alynah.htm
http://geocities.com/KirbyRaymond27/ociqam.htm
http://geocities.com/kktpxdqnhb/ulociqamy.htm
http://geocities.com/kmbxpkrkpe/byhegap.htm
http://geocities.com/ktywgegrcudf/byhegapy.htm
http://geocities.com/LiliaMathews67/yredaxubu.htm
http://geocities.com/MarionHudson45/nulaxu.htm
http://geocities.com/MasonSalinas48/rociqamynah.htm
http://geocities.com/MiguelPatterson69/ohuloci.htm
http://geocities.com/MilesFlowers05/alynah.htm
http://geocities.com/msxpytqms/apegapyz.htm
http://geocities.com/MurrayWaters50/byhegapy.htm
http://geocities.com/nmxtumdrfrff/alynah.htm
http://geocities.com/npxqrwxww/apegapyz.htm
http://geocities.com/ocaxbasohmgo36/hiqamyna.htm
http://geocities.com/rhauwqyee/nulaxubumul.htm
http://geocities.com/RobinWhitley59/byhegapy.htm
http://geocities.com/RussChandler61/yredax.htm
http://geocities.com/sfgesqfhrtrx/yredaxubu.htm
http://geocities.com/ShirleyTrevino49/bumulociqa.htm
http://geocities.com/TanyaWeber50/nulaxubumu.htm
http://geocities.com/TiffanyKirby11/yredaxubumu.htm
http://geocities.com/TyreeOsborne93/byhegapyz.htm
http://geocities.com/ufxesabsq/apegap.htm
http://geocities.com/WadeJoyce45/mulociqam.htm
http://geocities.com/yoqrawycf/yredaxubumu.htm
http://geocities.com/zgdgesbnw/ynahejoveke.htm
http://geocities.comgeoffreyPowell47/yredaxubum.htm

Of course none of these URLs actually is the final destination.

The current malware is

File size: 89600 bytes
MD5...: d62e9d994d587e94e04ad3f75ff14f69

you can see a VirusTotal report which shows a 6 of 41 detection rate. Only six anti-virus products out of 41 currently know that this is malware.
Read More
Posted in zbot | No comments

Sunday, 11 October 2009

A weekend of Old News

Posted on 06:47 by Unknown

Adobe



I'm not sure whose idea it was that we should be able to execute Javascript inside a PDF or Flash file, but we continue to see this exploited. Let's review:

In February 2009, Kevin Haley from Symantec warned that the Adobe PDF reader had an unpatched bug that was being exploited in the wild.
Adobe acknowledged this in a February 19th security advisory.

In April 2009, Computerworld shared a warning from David Lenoe of Adobe urging people to disable Javascript, saying "All currently supported shipping versions of Adobe Reader and Acrobat, 9.1, 8.1.4, and 7.1.1 and earlier, are vulnerable to this issue.

In May 2009, SANS Internet Storm Center warned that the current version of Adobe Flash Player (9.0.124.0) was vulnerable to a similar exploit.

In July 2009, SANS advised of "YA0D" or "Yet Another 0-Day" in Adobe Flash Player.

And finally we get to this week . . . on October 8th, Adobe again released a security advisory, which could be paraphrased as: "hey! if you run our program, you may get owned. We'll patch it next week," advising that a patch would be released on October 13th.

You know, rather than warning us every sixty days that its dangerous to run Javascript in their programs, perhaps Adobe would consider turning it off by default?

IRS Zeus / Zbot continues


Another day, another million dollars stolen by the Russians. This weekend the fake IRS websites are continuing to be a top spam category with more than 56 new websites pretending to be the Internal Revenue Service.

The current malware is still undetected by most anti-virus products, and as always, it changes on an almost daily basis. The current version was first seen Saturday morning, and only 4 of 41 anti-virus products detected that version. Its now up to 12 of 41 according to this current VirusTotal Report for MD5 fb9580be8bcdca37cc377e365365d4de which is 90,112 bytes in size.

Here are the websites we've seen spammed over the past few days according to the UAB Spam Data Mine:

Those spammed on October 9th . . .

www.irs.gov.beffaxsde.eu
www.irs.gov.bezfalsdo.eu
www.irs.gov.bezfazsda.eu
www.irs.gov.brtferho.eu
www.irs.gov.brtferhx.eu
www.irs.gov.brtferhy.eu
www.irs.gov.byugggb.com
www.irs.gov.byugggb.net
www.irs.gov.byugggk.com
www.irs.gov.byugggk.net
www.irs.gov.byugggl.com
www.irs.gov.byugggl.net
www.irs.gov.byugggm.com
www.irs.gov.byugggm.net
www.irs.gov.byugggr.com
www.irs.gov.byugggr.net
www.irs.gov.byugggu.com
www.irs.gov.byugggu.net
www.irs.gov.feraaaz.eu
www.irs.gov.feraaze.eu
www.irs.gov.gerfas1k.com
www.irs.gov.gerz1der.cn
www.irs.gov.gerz1der.com
www.irs.gov.gerz1der.net
www.irs.gov.gerzfdek.cn
www.irs.gov.gerzfdek.com
www.irs.gov.gerzfdek.net
www.irs.gov.linners.cz
www.irs.gov.oiiiterqa.cn
www.irs.gov.oiiiterqa.com
www.irs.gov.oiiiterqa.eu
www.irs.gov.oiiiterqq.cn
www.irs.gov.oiiiterqq.com
www.irs.gov.oiiiterqr.cn
www.irs.gov.oiiiterqr.com
www.irs.gov.oiiiterqw.eu
www.irs.gov.oiiiterqz.cn
www.irs.gov.oiiiterqz.com
www.irs.gov.oiiiterqz.eu
www.irs.gov.oyicoemqu.eu
www.irs.gov.oyicoerqz.eu
www.irs.gov.oyiioerql.eu
www.irs.gov.qazseek.eu
www.irs.gov.qazseep.eu
www.irs.gov.qazsewe.eu
www.irs.gov.qazsewl.eu
www.irs.gov.qazsewm.cn
www.irs.gov.qazsewx.eu
www.irs.gov.qazskem.eu
www.irs.gov.qazsxek.eu
www.irs.gov.refdree.eu
www.irs.gov.refdref.eu
www.irs.gov.refdrek.eu
www.irs.gov.refdrem.eu
www.irs.gov.yxeeddlrp.eu


Those spammed on October 10th . . .

www.irs.gov.brtferho.eu
www.irs.gov.brtferhv.eu
www.irs.gov.brtferhx.eu
www.irs.gov.brtferhy.eu
www.irs.gov.byugggb.com
www.irs.gov.byugggb.net
www.irs.gov.byugggk.com
www.irs.gov.byugggk.net
www.irs.gov.byugggl.com
www.irs.gov.byugggl.net
www.irs.gov.byugggm.com
www.irs.gov.byugggm.net
www.irs.gov.byugggr.com
www.irs.gov.byugggr.net
www.irs.gov.byugggu.com
www.irs.gov.byugggu.net
www.irs.gov.feraaaz.eu
www.irs.gov.feraaze.eu
www.irs.gov.gerfas1k.com
www.irs.gov.gerz1der.cn
www.irs.gov.gerz1der.com
www.irs.gov.gerz1der.net
www.irs.gov.gerzfdek.cn
www.irs.gov.gerzfdek.com
www.irs.gov.gerzfdek.net
www.irs.gov.linners.cz
www.irs.gov.refdree.eu
www.irs.gov.refdref.eu
www.irs.gov.refdrek.eu
www.irs.gov.refdrem.eu

Those spammed on October 11th . . .

www.irs.gov.brtferho.eu
www.irs.gov.brtferhv.eu
www.irs.gov.brtferhx.eu
www.irs.gov.brtferhy.eu
www.irs.gov.byugggb.com
www.irs.gov.byugggb.net
www.irs.gov.byugggk.com
www.irs.gov.byugggk.net
www.irs.gov.byugggl.com
www.irs.gov.byugggl.net
www.irs.gov.byugggm.com
www.irs.gov.byugggm.net
www.irs.gov.byugggr.com
www.irs.gov.byugggr.net
www.irs.gov.byugggu.com
www.irs.gov.byugggu.net
www.irs.gov.feraaaz.eu
www.irs.gov.feraaze.eu
www.irs.gov.gerz1der.cn
www.irs.gov.gerz1der.com
www.irs.gov.gerz1der.net
www.irs.gov.gerzfdek.cn
www.irs.gov.gerzfdek.com
www.irs.gov.gerzfdek.net
www.irs.gov.linners.cz
www.irs.gov.refdree.eu
www.irs.gov.refdref.eu
www.irs.gov.refdrek.eu
www.irs.gov.refdrem.eu


Comcast raises the bar for ISP Behavior


There is one new news item I wanted to call attention to this weekend. According to Brian Krebs "Security Fix" column in the Washington Post Comcast, the largest residential Internet Service Provider, is beginning a new program to alert home PC users who might be infected with malicious bot software.

Good job, Comcast! If we can get more Internet Service Providers monitoring for malicious software, we could dramatically reduce the number of infected computers. We look forward to hearing how this initiative impacts your customers!
Read More
Posted in | No comments

Thursday, 8 October 2009

The FBI's Biggest Domestic Phishing Bust Ever

Posted on 01:55 by Unknown
Yesterday the FBI began performing arrests of more than 100 individuals involved in a phishing investigation announced in the Central District of California courts. The case, known as Operation Phish Phry was the top story on the FBI website yesterday. Robert Mueller announced the case during a speech to the Commonwealth Club of California, where he praised the cooperation with the Secret Service and their Los Angeles Electronic Crimes Task Force, as well as state and local law enforcement. He said this was the first joint cyber investigation with Egypt and that this cooperative effort illustrates "the power of our global partnerships." Mueller also used the speech to praise the 32,000 members of the FBI's InfraGard program, "experts on our critical infrastructure" who help the FBI prevent risks to that infrastructure from becoming a reality.

The official press release from the Los Angeles FBI office says the announcement of the case came from:
Keith B. Bolcar, Acting Assistant Director in Charge, FBI Los Angeles
George S. Cardona, Acting United States Attorney, Los Angeles
and
Kieran Ramsey, FBI Legal Attache in Cairo Egypt
along with Egyptian Law Enforcement Authorities.


The 85 page indictment, which was presented to a Grand Jury back in February was unsealed once the arrests began, and contains a wealth of information. WIRED Magazine's Threat Level blog was the first to have a copy of the indictment.

The basic charges are:
18 USC S 1349: Wire and Bank Fraud Conspiracy
18 USC $ 1344(1): Bank Fraud
18 USC $ 1028A: Aggravated Identity Theft
18 USC $ 371: Computer Fraud Conspiracy
18 USC $ 1030(a)(4): Computer Fraud
18 USC $ 1956(h): Money Laundering Conspiracy

I'm especially happy to see the Aggravated Identity Theft charge, as it provides an automatic and non-negotiable +2 years to each sentence, which guarantees none of these people will get a "slap on the wrist", unless the prosecution fails to show they used the identities of at least ten individuals.

Although the investigation is labelled "Operation Phish Phry" by the FBI, the US-based charges deal with the money-laundering aspects more than the actual phishing. The phishing portions of the scheme seem to have been run by a group of nearly fifty individuals primarily in Egypt, who would transfer bank account credentials to the US-based ring leaders, who would use their network to move the money through mule accounts, out to cash, and eventually to be wired back to Egypt (minus a commission for the US-based players). Mueller mentions that the funds came from "approximately 5,000 American citizens" who were presumably the victims of these phishing attacks.

This was a tiered operation involving three ring leaders, who used sixteen associates to enlist thirty-eight money mules to receive stolen funds and wire them primarily to Egypt. In order to establish that each of the defendants was definitely involved, the indictment lists 335 "Overt Acts", mostly taking the form of giving a date, place, defendant, and an amount of money transmitted from a stated account to another defendant or unindicted co-conspirator.




(click for larger image, created with i2 Analyst's Notebook by Gary Warner)

The three ring-leaders identified in the indictment were:

Kenneth Joseph Lucas of Los Angeles, California
Nichole Michelle Merzi of Oceanside, California
Jonathan Preston Clark

These three operated a ring of middlemen who recruited the actual money mules. The middlemen were:

Jarrod Michael Akers
Kyle Wendell Akers
Wayne Edwards Arbaugh
Demorris Brooks
Antonio Late Colson
Kenneth Crews
Manu T. Fifita
Jennifer Anabelle Lopez Gonzalez
Tinika Sabrina Gunn
Jason Marcellus Jenkins
Sylvia Johnson
Remar Ahmir Lawton
Kyle Brandon Martin
Frankline Anthony Ragsdale
Steven Aaron Saunders
Rynn Spencer
Raquel Raffi Varjabedian
Candace Marie Zie

Lastly, the actual money mules that were indicted:

Ashley A. Ager
Latina Shaneka Black
Michael Dominick Gunn Dacosta Jr.
Virgil Phillip Daniels
Tramond S. Davis
Shontovia D. Debose
Joshua Vincent Fauncher
Krystal Fontenot
Anthony Donnel Fuller
Michael Christopher Grier
Bryanna Harrington
Shawn K. Jordan
Billy Littlejohn Kelly
Reggie B. Logan, Jr.
Ikinasio Lousiale, Jr.
Raymond V. Mancillas
David P. Mullin
Vincent Nguyen
Ario Plogovii
Brandon R. Ross
Alan Elvis St. Pierre
Courtney Monet Sears
Me Arlene Settle
Paula W. Sims
Jamie Smith
Brandon Kyle Thomas
Christopher Uhamaka
James Michael Viorato
Jovon Darnell Weems
David D. Westbrooks
Bridget Deque Wilkins
Marcus Deshaun Williams

The ages of the defendants range from 19 to 44, with only two being older than 31. Kenneth Crews and Demorris Brooks recruited seven money mules from North Carolina, and one or more unindicted recruiters gathered seven additional mules from Nevada, including at least four from Las Vegas.

Overt Acts are broken into sections:

A. Defendants Lucas and Zie:
Zie opens a bank BOA account, communicates with Lucas by telephone five times, withdraws stolen funds that were tranferred to his bank account. He opens two more account, talks to Lucas 54 times by telephone, and withdraws more stolen funds. Opens more accounts, communicates with Lucas 24 times in a single day, withdraws more stolen funds. The first 14 acts are about these two.

F. Defendants Lucas, Crews, and Logan:
Crews text-messages account numbers opened by Logan to Lucas, who causes funds to move from a victim account to Logan's accounts. Logan withdraws the money.

G. Defendants Lucas and Mancillas:
(Unindicted coconspirator) text-messages Lucas with account numbers opened by Mancillas at BOA. Lucas transfers funds from a victim to the Mancillas account, and Mancillas withdraws the funds.

H. Defendants Lucas and Mullin:
(Unindicted coconspirator) text-messages Lucas the account numbers opened by Mullin at Bank of America. Lucas moves funds from a victim account to the Mullin account, and Mullin withdraws the funds.

They do that over and over and over. The first 200 "Overt Acts" listed all involve Lucas as the one who moves the money from the victim's account.

The credentials for the victim accounts were acquired by phishing, but at this time, we don't have enough details to really know WHICH phishing attacks we're dealing with. It should certainly be pointed out that the phishing attacks were NOT NECESSARILY against Bank of America and Wells Fargo. Funds from any bank can be sent to Mule accounts at any bank, as long as they are both part of the ACH network. Hopefully more details will come out as this case progresses.

The later activities in the indictment make it seem that at least one or more of the defendants had their phone tapped or was cooperating with investigators, such as:

On February 17, 2009, defendants Colson, Weems, and Lucas agreed via telephone that defendant Colson would deliver $1,200 to defendant Lucas

Beginning with Overt Act #201 in the indictment (page 54) the activities turn to Wire Transfers, such as:

On January 12, 2007 in Los Angeles County, defendant J. Akers transmitted $1,300 by Western Union to unindicted coconspirator E.A.

The next forty acts involve Jarrod Michael Akers wiring nearly $100,000 to various parties, mostly unnamed in this indictment. Rehmar Amir Lawton also does more than $30,000 in wire transfers in "Overt Acts". Jonathon Preston Clark, Nichole Michelle Merzi, Candace Marie Zie, Demorris Brooks, Jennifer Lopez Gonzalez and others are also involved in the Wires.

One of the key telephone conversations that was part of the indictment is "Overt Act No. 241":

On December 22, 2008, in Los Angeles County, defendants LUCAS and K. AKERS, in a telephone conversation, discussed the scheme to cause unauthorized transfers of funds into bank accounts for the purpose of allowing coconspirators to withdraw the transferred funds, and defendant LUCAS advised defendant K. AKERS to solicit individuals who need money to assist in the scheme.
Read More
Posted in law enforcement, phishing | No comments

Wednesday, 7 October 2009

Microsoft "Your e-mail will be blocked" phish

Posted on 04:04 by Unknown
An interesting phishing campaign has resulted in several news stories about stolen passwords. That got me digging in the UAB Spam Data Mine looking for related emails. I didn't find THAT phish, but we did receive a large number of email messages claiming to be sent by Microsoft.com with this seemingly important warning:


Your e-mail will be blocked within 48 hours for spam, if this is mistake please cintact us.
Please click here for detailes.

Thank You.
Spam security Customer Service


The "Click Here" portion of the email was a link to a website containing the domain name:

58342875324752.com

with a randomized "host name" portion of the machine, such as:

http://jicjhfchcf63990210626.58342875324752.com/1.html
http://bcaifegghi22625742876.58342875324752.com/1.html
http://ahgdjifchf33143196196.58342875324752.com/1.html
http://dacjfiefdf06964096947.58342875324752.com/1.html
http://aggjbdbejf52476850184.58342875324752.com/1.html
http://gichjabdga24449952037.58342875324752.com/1.html
http://cdbbeibcce54169406995.58342875324752.com/1.html
http://cgahdjahih39067688421.58342875324752.com/1.html
http://dibgdfdbjc50687902460.58342875324752.com/1.html
http://geghdgfbbd77652789593.58342875324752.com/1.html
http://hbahfdbfhb41867793765.58342875324752.com/1.html
http://ecfafijdic45542087833.58342875324752.com/1.html
http://jfjhbgidfj46950802509.58342875324752.com/1.html
http://chcdgeecgh27341962790.58342875324752.com/1.html

Email subject lines observed during this phishing campaign included:

Alert: Account Deactivation Notice
Important message about your account information
NOTIFICATION OF LIMITED ACCOUNT ACCESS
Online Access Supended
Online Account Locked
Online Security Measures
Re-Confirm Your Online Access.
Your account has been flagged!
Your account has been placed on restricted status
Your Account Suspension
Your Online Account Needs Update

The spam had a unique forgery in the email headers to make them appear to be from Microsoft. In an email header, there is a "Received" line which shows the address from which an email was sent, such as:

Return-Path:
Received: from dsl-189-139-6-108-dyn.prod-infinitum.com.mx (dsl-189-139-6-108-dyn.prod-infinitum.com.mx [189.139.6.108] (may be forged))
by GarsServer.com (8.11.6/8.11.0) with ESMTP id n96Lew069365
for <85qrhskymaucw@GarsDomain.com>; Tue, 6 Oct 2009 21:40:59 GMT
(envelope-from bec713-security@microsoft.com)
Received: from dns749.microsoft.com(dns697.microsoft.com [189.139.6.108]) by 189.139.6.108 with SMTP id 69811070;

In this case, the "Return-Path" line is fake, and has been added by the sender. The second "Received" line is also fake, trying to convince you that the sending IP "189.139.6.108" is actually a Microsoft computer, which it's not!


The End?


Unfortunately, that's as far as this part of the investigation can go. The website had already been terminated, by asking the Registrar to remove the nameserver from active duty, meaning that no computers can reach the website in question.

But is that really the end?

The nameserver for this domain, which has already been terminated, was ns1.bloktrest.net. By setting that as our nameserver, we can see that the site was "fast flux" hosted on many different IP addresses. For instance, resolving the domain currently, according to bloktrest.net, points us to:

211.220.122.249
59.28.65.79
61.82.161.51
84.126.133.91
85.136.101.254
86.101.82.52
89.74.19.174
94.189.175.182
116.65.199.187
118.34.214.178
118.38.110.10
119.196.189.101
121.141.44.120
121.181.5.75

By hard-coding one of these IP addresses to the domain name, we can see that what WOULD have happened if we had visited the site was that we would have loaded an IFRAME from the site:

(DO NOT VISIT!) us-business-shop-2019.com/shop/?0a8f23e34c3fccbdbc459ef0d52b3910

THAT website has been listed since September 3rd at MalwareDomainList as a LuckySploit exploiter.

So, the question is at large - was this a phishing site at all? or merely a way to get people to have LuckySploit take over their computers?

Whois points to Badness



Here is the WHOIS data for 58342875324752.com which was registered October 5, 2009 at TodayNIC.com, an infamous Chinese registrar.

Administrative Contact:
Name: Ferd Derfo
Organization: Ferd Derfo
Address: Moskow
City: Moskow
Province/state: MSK
Country: RU
Postal Code: 133331
Phone: +7.9357738849
Fax: +7.9357738849
Email: molda3333vimo@safe-mail.net

Here is the WHOIS data for us-business-shop-2019.com which was registered at another infamous Chinese registrar, ONLINENIC.com, on July 21, 2009:

Serpino Berbeto ad6@safe-mail.net +1.2128848801
Serpino Berbeto
403 po box
New York NY US 10037

ns1.dns-diy.net
ns2.dns-diy.net

Do a search on "Serpino Berbeto" and you'll find more than 1,000 ways in which this identity is involved in the creation of domains used for the distribution of malware, and with online fraud domains, including fake Escrow sites, spam, pirated software (easy-software-store.com), Canadian Pharmacy (shop29.net).

The Serpino identity is one of the many "resellers" that cause OnlineNIC and other Chinese registrars to be such widely used havens for cybercriminals.

Serpino is hosting this site, and several other recent malware infection sites he's been behind, on a webblock belonging to "The Bigness Group" in St. Petersburg, Russia.

Serpino's sites on that netblock include:

yournewvideo.info - 195.88.190.29
brberfsdfsdafs.com - 195.88.190.31
lovisiribkabolishajaimalenkaja - 195.88.190.235
us-business-shop-2019.com - 195.88.190.202
fgddfgdgdfg.com - 195.88.190.235

of course other aliases are also hosting malware on this netblock, which seems to be filling the role of the old Russian Business Network, also of St. Petersburg:

Tourino Markes / moldavimo00@safe-mail.net has registered:
vertigoinvasion.com = 195.88.190.240 - associated with both Zeus and the Fragus exploit kit

Kelly Watsen / potenciallio@safe-mail.net has registered:
landingerfor.org = 195.88.190.235 - associated with LuckySploit exploit kit

Fego Fegochev / moldavimo@safe-mail.net has registered:
ppoqass.info = 195.88.190.246 - associated with the LuckySploit exploit kit
bbortixx.info = 195.88.190.246 - also associated with LuckySploit

Passive DNS reveals all sorts of badness. Recommendation? Everyone should block "The Bigness" and their entire network block!

IRS Zeus Again???



I ran the fast flux IP addresses given above through some checks at a Passive DNS Logging system to see if they were "known" IP addresses. Yes. Several of the IP addresses above are part of the same Fast Flux network which is being used for the "Avalanche" botnet, which is currently behind the IRS Zeus net!

So what happens if we hard-code a host entry for the above IP addresses, and tell it that it is one of the recent IRS domains?

That's right. I added this line to my "hosts" file:

211.53.54.227 www.irs.gov.hyu111a.com

and visited:

www.irs.gov.hyu111a.com/fraud_application/directory/statement.php

an IRS domain which has no active nameserver and has not been live for more than a week. It resolved on the IP address used above for the domain 58342875324752.com, and displayed the IRS Zeus infection website, complete with an active link for downloading the current malware.

File size: 95744 bytes
MD5...: fe80e38049ebb5f082adfb3dd9110d51
Click for Virus Total Report, showing that only 7 of 41 anti-virus products currently detect this Zbot / Zeus Bot infector.
Read More
Posted in malware, zbot | No comments

Monday, 5 October 2009

A Day in the Life of Spam

Posted on 15:07 by Unknown
Its been quite a while since I did a "Day in the Life of Spam", but with some recent ups and downs in the trends, I thought it would be worth taking a look again.

For this study, I chose one group of trap addresses for the UAB Spam Data Mine, and decided to try to categorize every email received on October 4, 2009. These particular trap accounts received 10,583 spam emails that day. So how did they break out?

5854 emails or 55.3% = Pharmaceutical products
2303 emails or 21.7% = Watches and other counterfeit goods
1044 emails or 9.8% = Malware distribution
512 emails or 4.8% = Illegal software "OEM" software downloads
397 emails or 3.8% = Fake diplomas or instant degrees
69 emails or 0.6% = Work at home scams
66 emails or 0.6% = Russian language emails
30 emails or 0.3% = Casino spam
28 emails or 0.26% = "Giveaways gotchas" (gift cards, plane tickets,
cell phones, laptops that are called "free" but aren't)
28 emails or 0.26% = Chinese/Japanese emails

200 emails or 1.9% = miscellaneous things other than categories above
insurance, credit reports, DISH Network, ink & toner,
language learning, government grants, dating services,
GI bill info, teeth whitening, government auctions,
ab circle, timeshares, florida rental properties,
colo detox, etc.

Digging in deeper, Canadian Pharmacy dominated the pharmacy category, with what
seems to be at least 19 different spam campaigns, all pushing Canadian Pharmacy
affiliated websites. Compared to other affiliate pill programs, they win hands down:

5358 emails = Canadian Pharmacy
260 emails = Maximum Gentleman penis enlargement
107 emails = Canadian Health Care
61 emails = Online Pharmacy
32 emails = My Canadian Pharmacy
16 emails = Canadian Health & Care Mall
12 emails = Canadian Family Pharmacy
8 emails = Acai Berry

The big changes that stand out especially are that the famous "Russian Brides" spam has almost vanished entirely. Gone also is the Acai Berry spam, which was at one point nearly 15% of all of our spam email messages. 419 scams are disappearing as well, with only 7 emails out of the 10,500+ examined for this "Day in the Life" peek.

When we look at the URLs advertised just in those 5,358 Canadian Pharmacy emails, we find 7,056 unique URLs hosted on 348 domains, of which 234 are ".cn" domains:

aobypwto.cn
aohumwto.cn
bavulov.cn
biyahaj.cn
bjelunep.cn
bobobuk.cn
bohetoj.cn
botazux.cn
bsobidar.cn
bsozefew.cn
busegis.cn
buwaneg.cn
cabavov.cn
cedwoyep.cn
cixivic.cn
cmeqoher.cn
cnahehas.cn
cpiliguk.cn
cqolodar.cn
csimigek.cn
cucodag.cn
cujozas.cn
cuyilec.cn
czavoyig.cn
dadodeg.cn
dahonif.cn
darohus.cn
dbixumaq.cn
ddayatot.cn
dejoviw.cn
dhajeqiy.cn
dijajiv.cn
dilonef.cn
disaniv.cn
dnojisud.cn
doboget.cn
docuyiv.cn
dojiqur.cn
dtusukir.cn
dzayowis.cn
dzolufay.cn
fasosup.cn
fceqinaf.cn
fducilox.cn
fehavux.cn
fejunab.cn
fibujes.cn
ficimap.cn
finahoz.cn
fohiyub.cn
fovihag.cn
fpupewat.cn
fsoresok.cn
fxocefew.cn
gakarid.cn
gbukagef.cn
gebosor.cn
ggefalom.cn
girucav.cn
glimesaf.cn
gmogacof.cn
gmonigec.cn
gobahod.cn
gpevehig.cn
gzevohaq.cn
hakobiz.cn
havarul.cn
hbejivix.cn
hgodakej.cn
hkawutet.cn
hocacap.cn
holoyin.cn
huvayov.cn
hxeqotet.cn
hyunohep.cn
jagegop.cn
jimigok.cn
jiquwac.cn
jirohup.cn
jjunopov.cn
jjunopov.cn
jpatoxih.cn
jranoxug.cn
jvafohit.cn
jvoqidev.cn
jxubocot.cn
kepomat.cn
kkamugag.cn
kovupaj.cn
krecahol.cn
kufanuv.cn
kyejixey.cn
lamadul.cn
lbihakag.cn
lbogupey.cn
lemecij.cn
loganuw.cn
lqihedax.cn
ltexujis.cn
lufogay.cn
luladuz.cn
lwofepib.cn
lwofexiv.cn
lxolemaj.cn
lyarazok.cn
lyuvuced.cn
mahalam.cn
mbajihiz.cn
mivutim.cn
mobivis.cn
moqeqez.cn
mtejuxad.cn
muhazec.cn
myibaqum.cn
nagozuc.cn
nahojut.cn
napojox.cn
nhofewih.cn
niduqab.cn
njihivax.cn
nnifikaj.cn
nocigoj.cn
nosadoc.cn
nqewonih.cn
nropemij.cn
pajikub.cn
pawucit.cn
pazoxif.cn
pevular.cn
pirebav.cn
pkipuyom.cn
pqezosem.cn
puhoquj.cn
puwuwug.cn
qahomeh.cn
qdiwoxaq.cn
qelaquk.cn
qfudocik.cn
qivokex.cn
qiyejas.cn
qoconug.cn
qokutuq.cn
qonanih.cn
qoxifuw.cn
qqisuluw.cn
qtufetag.cn
qudehiv.cn
qzonumeg.cn
rasafas.cn
rewelay.cn
rfozinud.cn
rgekepum.cn
rgekepum.cn
rizexez.cn
rjuyunex.cn
rmenisul.cn
rqasesoy.cn
rwobucem.cn
scelamoq.cn
shetepoc.cn
sirepil.cn
sjowemor.cn
socowuv.cn
sodajud.cn
somorez.cn
soqunup.cn
sorufar.cn
sovuzoq.cn
spojoxiq.cn
tatapum.cn
tawamof.cn
tdiceruk.cn
tfenuhah.cn
thidafak.cn
thodurux.cn
tnawulod.cn
tnikixep.cn
tvufisux.cn
vapabog.cn
vibariq.cn
vivuxab.cn
viyezis.cn
vludihum.cn
vobenog.cn
vohuren.cn
vopaguz.cn
voxaziq.cn
vqamiwur.cn
vriyigip.cn
vvobipad.cn
wabifoy.cn
wbakilit.cn
wbohovuh.cn
wgesirok.cn
wicigeh.cn
wiyisuh.cn
wnexejip.cn
wonefaq.cn
worldvld.cn
wovewab.cn
wuqumud.cn
xehevug.cn
xexugan.cn
xifepuj.cn
xipames.cn
xozowoj.cn
xquwavuk.cn
xuyokir.cn
ycaqoped.cn
ycetuvow.cn
yfolobow.cn
ygemuhop.cn
yinicuv.cn
yipenov.cn
ylafarum.cn
yororom.cn
yujacub.cn
yvukudey.cn
yzigawim.cn
zajeqav.cn
zapoyuf.cn
zcixefat.cn
zecemiz.cn
zfumulik.cn
zicorem.cn
zkodibay.cn
zlesanus.cn
zovoliz.cn
zowimij.cn
zrugaviv.cn
zsomiyon.cn
ztokusut.cn
zuguvov.cn
zupabuv.cn

Another 84 are ".com" domains:

12n3.com
150m.com
adabisnis.com
adorewow.com
adsnote.com
aftermelody.com
angerpeople.com
awaredear.com
barracudacentral.com
betterspoke.com
boldcover.com
cefjedhoha.com
chordspend.com
clickboothlnk.com
cncd-tex.com
coatfew.com
codetwo.com
comfyrace.com
confluencehr.com
connectionends.com
couldfloor.com
creamyglass.com
createsend2.com
entervanish.com
expertreason.com
fallsautumn.com
frankoferosscom.com
gate2service.com
giftedstood.com
gisdany.com
google.com
gotmoral.com
groupfinger.com
havebasic.com
hecreamy.com
helpleave.com
hesheet.com
hoawukfue.com
ihrodinpe.com
images-amazon.com
iomega.com
kezlink.com
livejournal.com
magicrange.com
metalartmaster.com
microsoft.com
mightysing.com
miturl.com
nbcmediacenter.com
onbisnis.com
passport.com
periodtwo.com
pharmacyonlineoffernow.com
posesea.com
proudnoble.com
quietcotton.com
qupdumvov.com
razoncollins.com
renownchief.com
restcalm.com
restthere.com
shegentle.com
shrtn.com
sidecatch.com
smooththan.com
soilbear.com
sonbottom.com
spreadtwenty.com
stoodstudy.com
stringmunchy.com
suchpull.com
t35.com
talkjoyful.com
thebraintree.com
tinytwitt.com
trucktingle.com
waitname.com
webmd.com
weightboxtime.com
whiledesire.com
winsportbike.com
yahoo.com (abused in the form of newly created "yahoo groups")
zestquart.com
Read More
Posted in spam | No comments

Friday, 2 October 2009

Cyber Security Awareness Month: Day Two

Posted on 10:24 by Unknown

Fake IRS Email Continues


I know this is becoming the Spam Campaign that Just Won't Die, but today we are still seeing extreme volumes of spam claiming to be from the Internal Revenue Service, with the subject line "Notice of Underreported Income". Here are the host names being used in the spam for October 1st and so far on October 2nd:

October 2, 2009 Domains seen in spam by the UAB Spam Data Mine:

www.irs.gov.ccviilli.com
www.irs.gov.ccviilli.net
www.irs.gov.ccviilll.com
www.irs.gov.ccviilll.net
www.irs.gov.ccvillli.com
www.irs.gov.gerradsz1.be
www.irs.gov.gerradsz1.co.ee
www.irs.gov.gerradsz1.com
www.irs.gov.gerradsz1.eu
www.irs.gov.haqwaz1.co.im
www.irs.gov.haqwaz1.com.im
www.irs.gov.haqwaz1.im
www.irs.gov.haqwaz1.net.im
www.irs.gov.hyyyyf1.cn
www.irs.gov.hyyyyf1.eu
www.irs.gov.hyyyyf2.eu
www.irs.gov.hyyyyf3.cn
www.irs.gov.hyyyyf4.cn
www.irs.gov.hyyyyf5.cn
www.irs.gov.hyyyyf6.cn
www.irs.gov.hyyyyf6.eu
www.irs.gov.hyyyyf7.cn
www.irs.gov.hyyyyf7.eu
www.irs.gov.hyyyyf8.cn
www.irs.gov.hyyyyf8.eu
www.irs.gov.nyuz1a.com
www.irs.gov.nyuz1a.net
www.irs.gov.nyuz2a.com
www.irs.gov.nyuz2a.net
www.irs.gov.nyuz3a.com
www.irs.gov.nyuz3a.net
www.irs.gov.nyuz4a.com
www.irs.gov.nyuz4a.net
www.irs.gov.nyuz5a.com
www.irs.gov.nyuz5a.net
www.irs.gov.vsdftpp.net

October 1, 2009 Domains seen in spam by the UAB Spam Data Mine:

www.irs.gov.ercc1zw.com
www.irs.gov.hyu111a.com
www.irs.gov.msrvtpp101.be
www.irs.gov.msrvtpp101.com
www.irs.gov.msrvtpp101.eu
www.irs.gov.msrvtpp102.be
www.irs.gov.msrvtpp102.com
www.irs.gov.msrvtpp102.eu
www.irs.gov.msrvtpp103.be
www.irs.gov.msrvtpp103.com
www.irs.gov.msrvtpp103.eu
www.irs.gov.vsdftpp.biz
www.irs.gov.vsdftpp.com
www.irs.gov.vsdftpp.in
www.irs.gov.vsdftpp.info
www.irs.gov.vsdftpp.mobi
www.irs.gov.vsdftpp.net
www.irs.gov.vsdftpp.org

Attempting to retrieve the malware from these sites, we were successful only with those on the ".im" country code. Like many cybercriminals, the criminals behind Zeus rely on inexperienced or uncooperative domain name registrars in order to keep their malicious websites live longer. In this case the domains:

haqwaz1.co.im
haqwaz1.com.im
haqwaz1.im
haqwaz1.net.im

as you're no doubt aware (ok, I had to look it up too!) .IM = Isle of Man. These domains would have been registered from "nic.im", who holds the keys to taking those domains off-line. I'm using the "nic.im" "contact us" page to report these fraud domains now.

The current version of the malware, which is still a Zeus Bot or "Zbot" infector, has these characteristics:

File size: 95232 bytes
MD5...: 869dba8c4bd9bb5a9030a24096883c6b

and is currently detected by only 9 of 41 anti-virus products at VirusTotal as you can see in this VirusTotal Report.

Other Malware in the Mail


Another long-running spam campaign claims that there has been a "delivery problem" with either DHL or Western Union.

The spam message says something like:


Hello!

We were not able to deliver the package you have sent on the (date here) in time
because the recipient's address is inexact.
Please print out the invoice copy attached and collect the package at our department.

DHL Customer Service


In this case the "attached package" is a piece of malware:

File size: 62464 bytes
MD5 : a4c926feeb6f906344f583091a02598f

which is well-detected as "BredoLab" as you can see in this VirusTotal Report by 16 of 41 anti-virus products.

Another version of the same spam says the same thing, only uses "UPS Delivery Problem" as the subject line and claims to be sent from "United Parcel Service".

A third version of the spam claims to be from Western Union, using the subject line "Wester Union transfer is available for withdrawl".


Dear customer.

The amount of money transfer: 8566 USD.
Money is available to withdrawl.

You may find the Money Transfer Control Number and receiver's details in document attached to this email.

Western Union.
Customer Service Center.


Whichever of these BredoLab malwares you run, you end up with Fake AV products being installed on your computer.


In the last prominent malware campaign we'll look at today a spam message is sent with the subject line "Thank you for setting the order No.475456". The text of the email reads:


Dear Customer!

Thank you for ordering at our online store.
Your order: Sony VAIO A1133651A, was sent at your address.
The tracking number of your postal parcel is indicated in the document attached to this letter.
Please, print out the postal label for receiving this parcel.

Internet Store.


Several slight variations of the attachment, sometimes called "install" and other times called "open" detect as different malware, with the two main versions being:

File size: 13312 bytes
MD5 : 595dc19dab1fa441304d77971c507d65

which detects as "Bravix" or "FakeAlert" or many other names, as you can see in this VirusTotal Report, which shows that 20 of 41 Anti-virus products detect this as malware.

and

File size: 13824 bytes
MD5 : 19daf4ef68dd4d830d4159e3d0dc7eb0

which also has many different detection names, including "Bravix", as you can see in this VirusTotal Report, which shows 23 of 41 anti-virus products detect this as malware.
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Vista Security Features
    BitLocker Drive Encryption A Real-world Windows Vista BitLocker Tip BitLocker Drive Encryption BitLocker Drive Encryption Frequently Asked Q...
  • A Prominent American Express Phish
    Every once in a while we see a spam campaign where we dig in to the complexity, expecting to find malware, and find that the criminal has ju...
  • Money Laundering $1 at a time - a win for the UK's PCeU
    In London a little-known police unit called the Police Central E-Crime Unit (PCeU) has scored another big win. For several years people hav...
  • 2008: Looking back on a Year of Spam and Malware
    Happy New Year! As we get ready for the New Year, there are quite a few security folks making predictions for 2009. I think my friend Dan...
  • Most Dangerous Cities for Cyber Crime?
    Symantec Riskiest Cybercrime Cities Symantec released a study today in conjunction with Sperling's Best Places today. According to thei...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Lin Mun Poo: Hacker of the Federal Reserve and ...?
    ** UPDATE: Poo arraigned and in custody ** On October 21, 2010, Malaysian citizen Lin Mun Poo landed at the JFK airport in New York and and ...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ▼  2013 (17)
    • ▼  November (1)
      • Tempting Photo Attachments Lead to Fake AV
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ►  August (23)
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile