Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 18 May 2012

Social Engineering: Facebook Photo

Posted on 13:58 by Unknown
Please welcome a guest-blogger, Sarah Turner, who authored today's report. Sarah is a malware analyst in the UAB Computer Forensics Research Laboratory and is the editor of our daily "Emerging Threats By Email" report. I asked her to put together an article about a prevalent spam campaign that has been running wild for about a month now. While the HISTORICAL malware described below is fairly well detected, each morning when a new version has come out the detection has been low, with improvement over the next 24-48 hours. If you see a message like this, RESIST TEMPTATION! DO NOT CLICK!

_-_
gar

Social Engineering: Facebook Photo

Guest blogger: Sarah Turner

This campaign utilizes social engineering containing subject lines that insinuate a photo is enclosed that was obtained from a social media site or public domain depicting the recipient or the ex girlfriend of the recipient in a scandalous or otherwise embarrassing predicament.

The campaign only uses 8 subjects, shown below.

  • FW:Check the attachment you have to react somehow to this picture
  • FW:They killed your privacy man your photo is all over facebook! NAKED!
  • FW:Why did you put this photo online?
  • FW:You HAVE to check this photo in attachment man
  • RE:Check the attachment you have to react somehow to this picture
  • RE:They killed your privacy man your photo is all over facebook! NAKED!
  • RE:Why did you put this photo online?
  • RE:You HAVE to check this photo in attachment man

The email body can vary between the 3 samples shown below:


Hey,
I have a question-have you seen this picture of yours in attachment?? Three facebook friends sent it to me today...why did you put it online? wouldn't it harm your job? what if parents see it? you must be way cooler than I thought about you man :))))

Hate to bother you,
But I really need to ask you - is it you at this picture in attachment? I can't tell you where I got this picture it doesn't actually matter...The question is is it really you???.

I'm sorry,
I got to show you this picture in attachment. I can't tell who gave it to me sorry but this chick looks a lot like your ex-gf. But who's that due??.

all of which encourage the recipient to open the attachment and see the image to which they’re referring. Typically the attachment is in the form of a .ZIP containing an executable, however the attachments received on May 16, 17, and 18, the attachment extension was not as a .ZIP but as “.jpg.exe”.

The first few times this malware was received (April 20 – 23), once it was downloaded and prompted to run, it acted as an AntiVirus Software.

After that, the received malware was identified as Cutwail delivering Zeus. The executable would be prompted to run and there would be no recordable network traffic but multiple changes would be made to your Registry and a new file, named svchost.exe would be added to your computer. The executable received today had a detection of XXXX on Virus Total.

UAB has 11 prominent MD5’s associated with this campaign (and a couple mis-formed files)

count md5_hex
24998 b42cf3d2cc829aba1e771f9517b2b97d (38 of 41 detects at VirusTotal)
21754 57f40166fd7cafe84ef51fe5f7776c51 (21 of 41 detects at VirusTotal)
21011 77e7fc1b2addc8ee5ea74e3592d4ab89 (14 of 41 detects at VirusTotal)
14918 76e144a572b4c52e3ddb8bd860dfbdd9 (36 of 41 detects at VirusTotal)
9562 5dea03a160543724d7cf4adda93a28ae (36 of 41 detects at VirusTotal)
9138 061f96cf8f7713d17e580900ba20c6b4 (31 of 42 detects at VirusTotal)
8286 9badf88e346bd0530d4e5248d2bb2f35 (37 of 42 detects at VirusTotal)
6362 d60bfa876dc382908fbcde1c96d5b95f (36 of 42 detects at VirusTotal)
5604 bf7b30a96dc8be8bbfb826158afb2379 (34 of 42 detects at VirusTotal)
4742 8cc36756d15560335ed53c47bd7cbc5e (36 of 42 detects at VirusTotal)
2538 d6f05da06a26d9d731273a0fa26dd7e1 (12 of 42 detects at VirusTotal)
This campaign was seen for the first time on 4/20/12 and was the top campaign seen today. Below is the full list of days and receipt counts from prior to this week.
receiving_date count
---------------- ------
2012-04-20 6372
2012-04-21 20819
2012-04-22 3182
2012-04-23 5739
2012-04-29 14918
2012-05-03 9252
2012-05-04 308
2012-05-06 2
2012-05-07 9138
2012-05-08 8286
2012-05-08 13
2012-05-11 1279
2012-05-12 4325
2012-05-16 7260
2012-05-17 17053
2012-05-17 13751
2012-05-18 4701
2012-05-18 2538
We have seen at least 6,757 unique IP addresses used to send us copies of this email with one of these malware attachments. When the malware is fresh, as it is each morning in the Emerging Threats By Email report, the detection rates are much lower. For example, here is the status from the May 17th Emerging Threats By Email report: So, yesterday morning when the report was written, that version of the malware had 7 detects, although as of this writing it has 14.
Read More
Posted in | No comments

Nichole Michelle Merzi of Operation Phish Phry gets 5 years

Posted on 05:14 by Unknown
Back in 2009, this blog ran the story FBI's Biggest Domestic Phishing Bust documenting Operation Phish Phry and explaining what was then known of the structure of an international phishing operation with more than 100 members. Yesterday Nichole Michelle Merzi, one of the ring-leaders, was finally sentenced to five years:
Defendant is committed on Counts 1, 34, 35, 38, 39, 48, and 51 of the Indictment to the Bureau of Prisons for 36 months. This term consists of 36 months on each of Counts 1, 34, 35, 38, 39, and 51; 36 months on Count 48, to be served concurrently; and 24 months on Count 46, to be served consecutively; for a total of 60 months. Defendant shall receive credit for any time served. Supervised release for three years.
The case began all the way back on September 30, 2009 with the filing of an indictment that charged:
  • Kenneth Joseph Lucas (1) count(s) 1-9,
  • Nichole Michelle Merzi (2) count(s) 1,
  • Jonathan Preston Clark (3) count(s) 1,
  • Jarrod Michael Akers (4) count(s) 1,
  • Kyle Wendell Akers (5) count(s) 1,
  • Wayne Edwards Arbaugh (6) count(s) 1-2,
  • Demorris Brooks (7) count(s) 1,
  • Antonio Late Colson (8) count(s) 1,
  • Kenneth Crews (9) count(s) 1,
  • Manu T Fifita (10) count(s) 1,
  • Jennifer Anabelle Lopez Gonzalez (11) count(s) 1, 7-9,
  • Tinika Sabrina Gunn (12) count(s) 1,
  • Jason Marcellus Jenkins (13) count(s) 1,
  • Sylvia Johnson (14) count(s) 1,
  • Remar Ahmir Lawton (15) count(s) 1,
  • Kyle Brandon Martin (16) count(s) 1,
  • Franklin Anthony Ragsdale (17) count(s) 1, 4-6,
  • Steven Aaron Saunders (18) count(s) 1,
  • Rynn Spencer (19) count(s) 1,
  • Raquel Raffi Varjabedian (20) count(s) 1,
  • Candace Marie Zie (21) count(s) 1,
  • Ashley A Ager (22) count(s) 1,
  • Latina Shaneka Black (23) count(s) 1,
  • Michael Dominick Gunn Dacosta, Jr (24) count(s) 1,
  • Virgil Phillip Daniels (25) count(s) 1,
  • Tramond S Davis (26) count(s) 1,
  • Shontovia D Debose (27) count(s) 1,
  • Joshua Vincent Fauncher (28) count(s) 1,
  • Krystal Fontenot (29) count(s) 1,
  • Anthony Donnel Fuller (30) count(s) 1, 5-6,
  • Michael Christopher Grier (31) count(s) 1,
  • Bryanna Harrington (32) count(s) 1,
  • Shawn K Jordan (33) count(s) 1-3,
  • Billy Littlejohn Kelly (34) count(s) 1,
  • Reggie B Logan, Jr (35) count(s) 1,
  • Ikinasio Lousiale, Jr (36) count(s) 1,
  • Raymond V Mancillas (37) count(s) 1,
  • David P Mullin (38) count(s) 1,
  • Vincent Nguyen (39) count(s) 1,
  • Ario Plogovii (40) count(s) 1,
  • Brandon R Ross (41) count(s) 1,
  • Alan Elvis St. Pierre (42) count(s) 1,
  • Courtney Monet Sears (43) count(s) 1,
  • Me Arlene Settle (44) count(s) 1,
  • Paula W Sims (45) count(s) 1,
  • Jamie Smith (46) count(s) 1,
  • Brandon Kyle Thomas (47) count(s) 1,
  • Christopher Uhamaka (48) count(s) 1,
  • James Michael Viorato (49) count(s) 1,
  • Jovon Darnell Weems (50) count(s) 1,
  • David D Westbrooks (51) count(s) 1,
  • Bridget Deque Wilkins (52) count(s) 1,
  • Marcus Deshaun Williams (53) count(s) 1.

In a conspiracy, we have to show "Overt Acts" committed by each member of the conspiracy in support of the conspiracy, which is how we end up with an 86 page Operation Phish Phry Indictment.

The indictment charges:

18 USC § 134: Wire and Bank Fraud Conspiracy
18 USC § 1344(1): Bank Fraud
18 USC § 1028A: Aggravated Identity Theft
18 USC § 371: Computer Fraud Conspiracy
18 USC § 1030(a)(4): Computer Fraud
18 USC § 1956(h): Money Laundering Conspiracy
§ 2: Aiding and Abetting and Causing an Act to Be Done

There are 335 Overt Acts charged in the Indictment, such as:

Overt Act No. 14: On July 31, 2008, defendant ZIE sent an SMS message to defendant LUCAS, in Los Angeles County, to transmit the account number and account holder name for the one checking account and one savings account that unindicted coconspirator K.M. opened that day at BOA, which transmission was for the purpose of causing defendant LUCAS, to make and to cause an unauthorized transfer of funds to those accounts and for the purpose of allowing unindicted coconspirator K.M. to withdraw the transferred funds.

Overt Act No. 16: On July 31, 2008, in Los Angeles County, defendant LUCAS caused a computer transfer of funds from a victim bank account at BOA, which neither BOA nor the victim had authorized, into defendant LOGAN's checking and savings accounts.

(In Overt Acts 17 and 18 Logan then withdraws $900 of that money from checking and $400 from savings.)

Overt Act No 70: On August 20, 2008, in Los Angeles County, defendant LUCAS caused computer transfers of $350 from a victim bank account at BOA, which neither BOA nor the victim had authorized, into defendant NGUYEN's checking account and $1,200 from a victim bank account at BOA, which neither BOA nor the victim had authorized, into defendant NGUYEN's savings account.

Overt Act No. 181: On December 11, 2008, in Los Angeles County, defendant JENKINS drove unindicted coconspirator A. J. to a Wells Fargo bank branch located in Los Angeles County to withdraw the $1,000 that defendant LUCAS caused to be deposited into unindicted coconspirator A.J.'s savings account.

Overt Act No. 186: On December 16, 2008, during a telephone conversation with defendant LUCAS< defendant MERZI advised defendant LUCAS that she had caused an unindicited coconspirator to conduct a transfer of funds from a victim bank account at Wells Fargo, which neither Wells Fargo nor the victim had authorized, and next would cause an unauthorized transfer of funds from a victim BOA account.

Overt Act No. 237: On June 14, 2007, in Los Angeles Cou8nty, defendant K. AKERS transmitted $1,900 by Western Union to unindicted coconspirator E. A.


It goes on like that for some 60 pages. From January 2007 to September 2009, the Ringleaders get victim credentials, the second tier transfer the funds around to accounts opened and controlled by the third tier, who then get driven around and sent into banks to take out the money, which gets passed up through management and wired via Western Union to Egypt, with everyone taking a piece of the pie.

For those who are interested in how you argue such a case in court, I've also posted the Operation Phish Phry Closing Arguments Power Point. Hundreds of pages of courtroom transcripts are also available from PACER.

Read More
Posted in | No comments

Thursday, 10 May 2012

IRS Identity Theft leads to 25 year Sentence for Alabama Fraudsters

Posted on 04:14 by Unknown
The news in Alabama today is that IDENTITY THEFT DOES NOT PAY. Veronica Dale of Montgomery, Alabama was sentenced to 334 months in prison and Alchico Grant of Lowndes County, Alabama was sentenced to 310 months in prison after the two participated in a scheme to file more than 500 fraudulent tax returns and steal from the IRS $3,741,908! The two will also have to pay $2.8 Million in restitution.

The sentences were announced on the main Department of Justice website with the title Leaders of Multi-million Dollar Fraud Ring That Used Stolen Information of Medicaid Recipients Each Sentenced to Over 25 Years in Prison

The charges brought against Veronica Dale include:

CR. NO: 2:10-CR-242-MEF (see see Indictment

18 USC § 286: Conspiracy to Defraud the Government
18 USC § 287: False, Fictitious or Fraudulent Claims
18 USC § 641: Theft of Government Public Money, Property or Records
18 USC § 1028A: Aggravated Identity Theft

CR. NO: 2:11-CR-69-MEF (see see Indictment

18 USC § 1343: Wire Fraud
18 USC § 1028A: Aggravated Identity Theft

In the first case, the defendants were:

Veronica Denise Dale
Alchico Dewayne Grant
Laquanta Grant
Isaac C. Dailey
Leroy Howard

In a superseding indictment filed for crimes that occurred after the first case was already underway, the defendants were:

Melinda Renae Clayton
Alchico Dewayne Grant
Veronica Denise Dale
Stephanie Adams
Valerie Byrd

Veronica owned and operated Dale's Tax Service, a tax preparation business located in Montgomery, Alabama. Looking back, it is likely that opening the Tax Service was just part of the plan to commit these crimes.

Veronica obtained Social Security numbers and names and used them to prepare and file false income tax returns and directed tax refunds to be deposited into accounts controlled by her and her co-defendants.

The bank accounts received at least $2.3 million in tax refunds.

1/21/2009 $4,990
2/14/2009 $5,124
3/6/2009 $7,352
3/15/2009 $10,688
3/15/2009 $10,031
3/15/2009 $10,332>
3/24/2009 $10,636
etc. etc. (the indictment lists 26 filings, but this happened well over 500 times!) Money was deposited into accounts opened in 2008, 2009, and 2010 at Regions Bank in Montgomery, Alabama and Woodforest Bank in Montgomery, Alabama, as well as Alabama State Employees Credit Union, MAX Credit Union. In 2011 additional accounts were opened at Bank of America where several more tax returns were received.

Veronica turned herself in to US Marshall Service on December 17, 2010. Here is the amazing part. AFTER TURNING HERSELF IN, and being released on bail pending trial, SHE KEPT STEALING MONEY FROM THE IRS!!!

The second case (2:11-CR-69-MEF) explains that between approximately January 2011 and April 2011, Dale conspired with Melinda Clayton and others to file an ADDITIONAL 155 fraudulent tax returns, to gather another $494,424 in tax refunds. THIS WAS AFTER DALE HAD ALREADY TURNED HERSELF IN because of the charges in the other case! She "caused to be stored at Clayton's residence thousands of names and social security numbers unlawfully obtained from EDS."

She pleaded guilty October 14, 2011.

The guilty plea (see see the Plea Agreementincludes the fact that "on counts 1,9,10,27 and 28, a 6-level enhancement is warranted because the Defendant's direct participation in the offense involved 250 or more victims.

The guilty plea explains that "Between June 2007 and February 2008, the Defendant worked as a temporary employee at EDS in Montgomery, Alabama. She "was able to and did wrongfully and illegally acquire Medicaid records which included the names, social security numbers, and dates of births of thousands of inviduals who received Medicaid benefits.

Between January 2009 and December 2010, she used these records stolen from EDS to file over 500 false tax returns.

308 of those tax retunrs deposited money into accounts of the Alabama State Employees Credit Union controlled by Betty Washington. The accounts received approximately $1,440,632.40 in false tax refunds.

Read More
Posted in | No comments

Friday, 4 May 2012

Waya Nwaki pleads guilty in globe-spanning phishing ring

Posted on 05:59 by Unknown
We often hear complaints from our Banking friends about criminals in Nigeria. Today's story is another example of the truth that in 2012, there is no place left to hide. Back in April 2011, FBI New Jersey presented their case to the Grand Jury in the form of a sealed indictment accusing several criminals of phishing:

Karlis Karklins
Charles Umeh Chidi
Waya Nwaki (AKA Prince Abuja, AKA USAPrince12k)
Osarhieme Uyi Obaygbona (AKA bside)
Marvin Dion HIll (AKA Nyhiar Da Boss, AKA Nihiar Springs)
Alphonsus Osuala
Olaniyi Jones

The case was officially unsealed on January 20, 2012, as the suspects were rounded up, chiefly Olaniyi Jones Makinde, who was arrested that week in Lagos, Nigeria:


(click for original in AfricanSpotlight.com)

Romance: Nigeria Style

Although this is what would normally be thought of as a "Nigerian Scam Ring" many of the players were already in the United States and had been for some time. Olaniyi, pictured above, is better known to Americans as his romantic alter ego, Brenda Stuart (brendastuart@rocketmail.com, age 35, London, b.Feb 21, 1977)

"Brenda" would "fall in love" with various men that "she" met online, and then have various financial hardships which required the men to send money to her overseas accounts. Several "Money Mules" (called "Maga" in the Nigerian lingo) would assist with getting the money back to Jones via Western Union or Moneygram.

According to BekkyBlog Olaniyi Victor Makinde, also known as Andrea Bradley and Olaniyi Jones was originally arrested on September 6, 2011 by FBI agents working with Nigerian authorities on charges brought by the San Francisco division of the FBI related to two marriage scams where he harvested $620,225.04 from two American victims, Marilou Sibbaluca and John Massoni. While waiting in the Olokuta medium prison, he was charged again in the current New Jersey case. According to the blogger, Olanyiy was a recent graduate of the University of Ado Ekiti.

Criminal History in US

Waya Nwaki and Alphonsis Osuala should have been fairly easy to find. Rather than being in Nigeria, they were already in prison in Georgia. They had been arrested in Belvedere, South Carolina all the way back in April 20, 2005. They recruited a "white guy", Douglas Hudson, to go into a bank and cash a check for $2950 in a Bank of America branch while they waited outside in their silver Lincoln Navigator. Later that day they did the same scam, using a copy of the same check, in Aiken, South Carolina. Aiken, who was carrying a counterfeit resident alien card in the name of Steven Ratzlaff, was arrested in the bank by Lieutenant Farmer of the Aiken Department of Public Safety, while his colleague Officer Wilson pulled over the suspicious Lincoln Navigator and searched it, finding $17,000 in cash under the driver's seat, and a fake soda can containing six more copies of the same check. Nwaki was paying Hudosn $500 for each check they succesfully cashed, and theat they had done five successful scams in the previous two days. After being released, they were apparently back on the street for a while before being rearrested in Georgia.

Phishing

The more recent scams were pure phishing. The six US-based codefendants worked with Jones to steal money from Payroll Processors ADP and Intuit as well as several banks. Karklins and Chidi would email phishing and spear-phishing attacks to the banking customers to lure them to phishing sites - fake bank websites that would be used to gather login credentials. As has been a growing trend, some of the credentials were used to do telephone transactions with the banks, instead of trying to use their online systems, which often have more fraud protection in place. Once the money was available, the criminals sent wire transfers to bank accounts in the United States, Mexico, the United Kingdom, Latvia, France, Bulgaria, Russia, and Nigeria. $3.5 million in wire transfers were attempted and $1.3 million were successfully withdrawn. This activity spanned a couple years, beginning at least as early as November 2009, when Karklins was setting up Chase Bank phishing sites. In January 2010 they added an ADP scam, and successfully harvested credentials for at least 27 sets of userids and passwords. These Payroll accounts allowed them to establish imaginary employees in various companies who received payments along with the real employees each payday until they were discovered. Karklins and Chidi would email Nwaki credentials for high value phishing accounts that they came across so that Nwaki could gather the money. It seems they ignored low value balances and focused only on taking the money from the high value accounts. Notices would go to Nwaki such as "28k chase, male, login yourself for check copy." or "CHASE 13.8k = male, age 32" or "BOA Business 25k + mail access". In February 2010, an Regions Bank account operated by defendant Hill was used to wire money to Bulgaria and Latvia. Nwaki also provided login credentials for a "50k drop" that was sent to the Regions account. Of the more than $1.3 million stolen, more than $300,000 of the funds were sent to a J.M. Sovereign Account operated by Jones in Nigeria.
Read More
Posted in | No comments

Tuesday, 1 May 2012

Paypal "You Just Sent a Payment" spam leads to malware

Posted on 05:26 by Unknown
A new malicious spam campaign has just launched this morning targeting Paypal users. This malware campaign attempts to "social engineer" users into clicking a link that they know they shouldn't click on! Here's the email:

The criminals believe (and from what we've seen, correctly) that when presented with the news that you just sent $100 to someone from your Paypal account, you will have a panic reaction and click on the link in the email. This is what they are counting on!

As you can see we got quite a few of these this morning:

The destination is NOT going to be Paypal. Don't click on the link, and tell your friends not to click on the link either! If they do, a bad set of malicious actions are set into motion.

This particular version of the campaign just started about 2.5 hours ago. Here are the number of messages we have seen so far:

 count |        mbox         
-------+---------------------
22 | 2012-05-01 04:00:00
22 | 2012-05-01 04:15:00
312 | 2012-05-01 04:30:00
41 | 2012-05-01 04:45:00
15 | 2012-05-01 05:00:00
78 | 2012-05-01 05:15:00
241 | 2012-05-01 05:30:00
1 | 2012-05-01 05:45:00
210 | 2012-05-01 06:00:00
91 | 2012-05-01 06:15:00
(10 rows)
There are many hundreds of links that may have been advertised in your copy of this email, but don't click on ANY of them!

In the example case that we checked, we followed a link to "globalsecurityservices.com" (yes, we like irony).

When the web page was visited, it immediately executed two remote javascript files (I've added spaces to "break" them):

script type="text/javascript" src="http:// laxana .org /1VxMC4Dy /js .js"
script type="text/javascript" src="http:// womaametw3 .com /CWTKosSw /js .js"
which redirected to an Exploit server that displayed this "Please Wait" sign while something more malicious was happening in the background.

The exploit kit dropped a Java "JAR" file that was launched in Java, taking advantage of a security hole, which then caused another executable file to download and install on the computer.

What was that executable? We're not sure yet, but your anti-virus product probably doesn't know either. At the time we submitted the malware to VirusTotal there were only 5 of 43 anti-virus products could label the malware as malicious. Although McAfee called it "Zbot" (PWS-Zbot.gen.ya, the anti-virus name for the Zeus Bot) Avast and one other vendor called it "Karagany" (Win32:Karagany-FS [Trj]).

The malware's MD5 was 4f58895af2b8f89bd90092f08fcbd54f and it was 33280 bytes in size.

Here's a link to the original VirusTotal report.

Previous Threats

This link is very closely linked to a "LinkedIn" spam campaign from yesterday. That campaign functioned in exactly the same manner, with the difference only in the spam campaign.

All of the domains listed below have been compromised by an attacker. Most likely the criminals have stolen the FTP userid and password of the criminal, allowing them to change the webmaster's content without the webmaster's knowledge. If you control or know the owner of one of these websites, let them know they have been hacked. They need to remove the content, scan any computers they use to access their website for malware, and change their password AFTER they get the malware cleaned up.


machine | path
-------------------------------+----------------------
cpaindia.net | /rHFbxKTn/index.html
dealaddict.ch | /bp9ksV54/index.html
dealaddict.ch | /N2rhmW5i/index.html
dealaddict.ch | /r1kVYAfU/index.html
dealaddict.ch | /vpW8hoZ6/index.html
depilee.com | /BzJoVeo0/index.html
depilee.com | /Lskx0Bew/index.html
depilee.com | /NdHgm0gT/index.html
depilee.com | /oZFZ0qJK/index.html
depilee.com | /pD2zHbBB/index.html
depilee.com | /vpW8hoZ6/index.html
depilee.com | /wcE0aK0J/index.html
depilee.com | /wjivLtgo/index.html
dpsdurgapur.com | /4RcYf6gB/index.html
dpsdurgapur.com | /7QLZuMme/index.html
dpsdurgapur.com | /bp9ksV54/index.html
dpsdurgapur.com | /BzJoVeo0/index.html
dpsdurgapur.com | /ErmgUouT/index.html
dpsdurgapur.com | /gj1W42Ee/index.html
dpsdurgapur.com | /i8ztSS5H/index.html
dpsdurgapur.com | /iaJ7FSBi/index.html
dpsdurgapur.com | /mKvc8Mh7/index.html
dpsdurgapur.com | /N2rhmW5i/index.html
dpsdurgapur.com | /NdHgm0gT/index.html
dpsdurgapur.com | /oZFZ0qJK/index.html
dpsdurgapur.com | /pD2zHbBB/index.html
dpsdurgapur.com | /rHFbxKTn/index.html
dpsdurgapur.com | /rzDZAsw7/index.html
dpsdurgapur.com | /t7xYVUJE/index.html
dpsdurgapur.com | /tLnW6jJT/index.html
dpsdurgapur.com | /UAtkgmot/index.html
dpsdurgapur.com | /UcL29wrU/index.html
dpsdurgapur.com | /vpW8hoZ6/index.html
dpsdurgapur.com | /wtQ8G0Ku/index.html
dpsdurgapur.com | /YhwvXGhk/index.html
dpsdurgapur.com | /zvo8ioak/index.html
enfoquescreativos.com | /4RcYf6gB/index.html
enfoquescreativos.com | /7NEM56yQ/index.html
enfoquescreativos.com | /7QLZuMme/index.html
enfoquescreativos.com | /bp9ksV54/index.html
enfoquescreativos.com | /BzJoVeo0/index.html
enfoquescreativos.com | /ddLvpeMu/index.html
enfoquescreativos.com | /DkM4v1PP/index.html
enfoquescreativos.com | /gj1W42Ee/index.html
enfoquescreativos.com | /N2rhmW5i/index.html
enfoquescreativos.com | /oZFZ0qJK/index.html
enfoquescreativos.com | /r1kVYAfU/index.html
enfoquescreativos.com | /Re3BMGVG/index.html
enfoquescreativos.com | /rHFbxKTn/index.html
enfoquescreativos.com | /RoScD8aq/index.html
enfoquescreativos.com | /rzDZAsw7/index.html
enfoquescreativos.com | /UAtkgmot/index.html
enfoquescreativos.com | /vpW8hoZ6/index.html
enfoquescreativos.com | /wjivLtgo/index.html
enfoquescreativos.com | /wtQ8G0Ku/index.html
enfoquescreativos.com | /YhwvXGhk/index.html
enfoquescreativos.com | /zvo8ioak/index.html
ftp.neez.com.br | /4RcYf6gB/index.html
ftp.neez.com.br | /7NEM56yQ/index.html
ftp.neez.com.br | /7QLZuMme/index.html
ftp.neez.com.br | /ErmgUouT/index.html
ftp.neez.com.br | /gj1W42Ee/index.html
ftp.neez.com.br | /mKvc8Mh7/index.html
ftp.neez.com.br | /NdHgm0gT/index.html
ftp.neez.com.br | /oZFZ0qJK/index.html
ftp.neez.com.br | /pSG1s2xs/index.html
ftp.neez.com.br | /Re3BMGVG/index.html
ftp.neez.com.br | /rzDZAsw7/index.html
ftp.neez.com.br | /t7xYVUJE/index.html
ftp.neez.com.br | /tLnW6jJT/index.html
ftp.neez.com.br | /UAtkgmot/index.html
ftp.neez.com.br | /UcL29wrU/index.html
ftp.neez.com.br | /wcE0aK0J/index.html
ftp.neez.com.br | /xXr3khjG/index.html
ftp.pousadaesmeralda.com.br | /4RcYf6gB/index.html
ftp.pousadaesmeralda.com.br | /bp9ksV54/index.html
ftp.pousadaesmeralda.com.br | /ddLvpeMu/index.html
ftp.pousadaesmeralda.com.br | /DkM4v1PP/index.html
ftp.pousadaesmeralda.com.br | /gj1W42Ee/index.html
ftp.pousadaesmeralda.com.br | /i8ztSS5H/index.html
ftp.pousadaesmeralda.com.br | /iaJ7FSBi/index.html
ftp.pousadaesmeralda.com.br | /Lskx0Bew/index.html
ftp.pousadaesmeralda.com.br | /mKvc8Mh7/index.html
ftp.pousadaesmeralda.com.br | /N2rhmW5i/index.html
ftp.pousadaesmeralda.com.br | /NdHgm0gT/index.html
ftp.pousadaesmeralda.com.br | /oZFZ0qJK/index.html
ftp.pousadaesmeralda.com.br | /pD2zHbBB/index.html
ftp.pousadaesmeralda.com.br | /pSG1s2xs/index.html
ftp.pousadaesmeralda.com.br | /r1kVYAfU/index.html
ftp.pousadaesmeralda.com.br | /Re3BMGVG/index.html
ftp.pousadaesmeralda.com.br | /rHFbxKTn/index.html
ftp.pousadaesmeralda.com.br | /rzDZAsw7/index.html
ftp.pousadaesmeralda.com.br | /UcL29wrU/index.html
ftp.pousadaesmeralda.com.br | /wcE0aK0J/index.html
ftp.pousadaesmeralda.com.br | /wjivLtgo/index.html
ftp.pousadaesmeralda.com.br | /wtQ8G0Ku/index.html
ftppousadaesmeralda.com.br | /ddLvpeMu/index.html
ftppousadaesmeralda.com.br | /Lskx0Bew/index.html
ftppousadaesmeralda.com.br | /oZFZ0qJK/index.html
ftppousadaesmeralda.com.br | /pSG1s2xs/index.html
ftppousadaesmeralda.com.br | /wjivLtgo/index.html
globesecurityservices.com | /4RcYf6gB/index.html
globesecurityservices.com | /6BrzkppT/index.html
globesecurityservices.com | /7NEM56yQ/index.html
globesecurityservices.com | /7QLZuMme/index.html
globesecurityservices.com | /bp9ksV54/index.html
globesecurityservices.com | /BzJoVeo0/index.html
globesecurityservices.com | /ddLvpeMu/index.html
globesecurityservices.com | /DkM4v1PP/index.html
globesecurityservices.com | /ErmgUouT/index.html
globesecurityservices.com | /gj1W42Ee/index.html
globesecurityservices.com | /i8ztSS5H/index.html
globesecurityservices.com | /iaJ7FSBi/index.html
globesecurityservices.com | /Lskx0Bew/index.html
globesecurityservices.com | /mKvc8Mh7/index.html
globesecurityservices.com | /NdHgm0gT/index.html
globesecurityservices.com | /oZFZ0qJK/index.html
globesecurityservices.com | /pD2zHbBB/index.html
globesecurityservices.com | /pSG1s2xs/index.html
globesecurityservices.com | /rHFbxKTn/index.html
globesecurityservices.com | /RoScD8aq/index.html
globesecurityservices.com | /rzDZAsw7/index.html
globesecurityservices.com | /t7xYVUJE/index.html
globesecurityservices.com | /tLnW6jJT/index.html
globesecurityservices.com | /UAtkgmot/index.html
globesecurityservices.com | /UcL29wrU/index.html
globesecurityservices.com | /vpW8hoZ6/index.html
globesecurityservices.com | /wcE0aK0J/index.html
globesecurityservices.com | /wjivLtgo/index.html
globesecurityservices.com | /wtQ8G0Ku/index.html
gpureappliances.com | /4RcYf6gB/index.html
gpureappliances.com | /6BrzkppT/index.html
gpureappliances.com | /7NEM56yQ/index.html
gpureappliances.com | /7QLZuMme/index.html
gpureappliances.com | /bp9ksV54/index.html
gpureappliances.com | /ddLvpeMu/index.html
gpureappliances.com | /DkM4v1PP/index.html
gpureappliances.com | /ErmgUouT/index.html
gpureappliances.com | /gj1W42Ee/index.html
gpureappliances.com | /Lskx0Bew/index.html
gpureappliances.com | /N2rhmW5i/index.html
gpureappliances.com | /NdHgm0gT/index.html
gpureappliances.com | /oZFZ0qJK/index.html
gpureappliances.com | /pD2zHbBB/index.html
gpureappliances.com | /r1kVYAfU/index.html
gpureappliances.com | /rHFbxKTn/index.html
gpureappliances.com | /RoScD8aq/index.html
gpureappliances.com | /rzDZAsw7/index.html
gpureappliances.com | /t7xYVUJE/index.html
gpureappliances.com | /UAtkgmot/index.html
gpureappliances.com | /vpW8hoZ6/index.html
gpureappliances.com | /wcE0aK0J/index.html
gpureappliances.com | /wtQ8G0Ku/index.html
gpureappliances.com | /xXr3khjG/index.html
gpureappliances.com | /YhwvXGhk/index.html
gpureappliances.com | /zvo8ioak/index.html
hitechsystems.org.in | /4RcYf6gB/index.html
hitechsystems.org.in | /7NEM56yQ/index.html
hitechsystems.org.in | /7QLZuMme/index.html
hitechsystems.org.in | /ddLvpeMu/index.html
hitechsystems.org.in | /DkM4v1PP/index.html
hitechsystems.org.in | /gj1W42Ee/index.html
hitechsystems.org.in | /Lskx0Bew/index.html
hitechsystems.org.in | /mKvc8Mh7/index.html
hitechsystems.org.in | /N2rhmW5i/index.html
hitechsystems.org.in | /NdHgm0gT/index.html
hitechsystems.org.in | /oZFZ0qJK/index.html
hitechsystems.org.in | /pD2zHbBB/index.html
hitechsystems.org.in | /pSG1s2xs/index.html
hitechsystems.org.in | /r1kVYAfU/index.html
hitechsystems.org.in | /Re3BMGVG/index.html
hitechsystems.org.in | /rHFbxKTn/index.html
hitechsystems.org.in | /RoScD8aq/index.html
hitechsystems.org.in | /rzDZAsw7/index.html
hitechsystems.org.in | /t7xYVUJE/index.html
hitechsystems.org.in | /UAtkgmot/index.html
hitechsystems.org.in | /UcL29wrU/index.html
hitechsystems.org.in | /vpW8hoZ6/index.html
hitechsystems.org.in | /wcE0aK0J/index.html
hitechsystems.org.in | /wjivLtgo/index.html
hitechsystems.org.in | /wtQ8G0Ku/index.html
hitechsystems.org.in | /xXr3khjG/index.html
hypernovamedia.com | /4RcYf6gB/index.html
hypernovamedia.com | /6BrzkppT/index.html
hypernovamedia.com | /7NEM56yQ/index.html
hypernovamedia.com | /7QLZuMme/index.html
hypernovamedia.com | /bp9ksV54/index.html
hypernovamedia.com | /BzJoVeo0/index.html
hypernovamedia.com | /DkM4v1PP/index.html
hypernovamedia.com | /ErmgUouT/index.html
hypernovamedia.com | /gj1W42Ee/index.html
hypernovamedia.com | /i8ztSS5H/index.html
hypernovamedia.com | /iaJ7FSBi/index.html
hypernovamedia.com | /Lskx0Bew/index.html
hypernovamedia.com | /mKvc8Mh7/index.html
hypernovamedia.com | /N2rhmW5i/index.html
hypernovamedia.com | /pD2zHbBB/index.html
hypernovamedia.com | /pSG1s2xs/index.html
hypernovamedia.com | /r1kVYAfU/index.html
hypernovamedia.com | /Re3BMGVG/index.html
hypernovamedia.com | /RoScD8aq/index.html
hypernovamedia.com | /t7xYVUJE/index.html
hypernovamedia.com | /tLnW6jJT/index.html
hypernovamedia.com | /UAtkgmot/index.html
hypernovamedia.com | /UcL29wrU/index.htm
hypernovamedia.com | /UcL29wrU/index.html
hypernovamedia.com | /vpW8hoZ6/index.html
hypernovamedia.com | /wcE0aK0J/index.html
hypernovamedia.com | /wjivLtgo/index.html
hypernovamedia.com | /xXr3khjG/index.html
hypernovamedia.com | /YhwvXGhk/index.html
hypernovamedia.com | /zvo8ioak/index.html
ilabph.com | /6BrzkppT/index.html
ilabph.com | /7NEM56yQ/index.html
ilabph.com | /BzJoVeo0/index.html
ilabph.com | /ddLvpeMu/index.html
ilabph.com | /ErmgUouT/index.html
ilabph.com | /gj1W42Ee/index.html
ilabph.com | /i8ztSS5H/index.html
ilabph.com | /iaJ7FSBi/index.html
ilabph.com | /Lskx0Bew/index.html
ilabph.com | /mKvc8Mh7/index.html
ilabph.com | /N2rhmW5i/index.html
ilabph.com | /NdHgm0gT/index.html
ilabph.com | /oZFZ0qJK/index.html
ilabph.com | /pD2zHbBB/index.html
ilabph.com | /pSG1s2xs/index.html
ilabph.com | /r1kVYAfU/index.html
ilabph.com | /Re3BMGVG/index.html
ilabph.com | /rHFbxKTn/index.html
ilabph.com | /RoScD8aq/index.html
ilabph.com | /rzDZAsw7/index.html
ilabph.com | /t7xYVUJE/index.html
ilabph.com | /tLnW6jJT/index.html
ilabph.com | /UAtkgmot/index.html
ilabph.com | /UcL29wrU/index.html
ilabph.com | /vpW8hoZ6/index.html
ilabph.com | /wcE0aK0J/index.html
ilabph.com | /wjivLtgo/index.html
ilabph.com | /wtQ8G0Ku/index.html
ilabph.com | /xXr3khjG/index.html
ilabph.com | /YhwvXGhk/index.html
jmexy.com | /4RcYf6gB/index.html
jmexy.com | /7QLZuMme/index.html
jmexy.com | /BzJoVeo0/index.html
jmexy.com | /ddLvpeMu/index.html
jmexy.com | /DkM4v1PP/index.html
jmexy.com | /ErmgUouT/index.html
jmexy.com | /gj1W42Ee/index.html
jmexy.com | /Lskx0Bew/index.html
jmexy.com | /mKvc8Mh7/index.html
jmexy.com | /N2rhmW5i/index.html
jmexy.com | /NdHgm0gT/index.html
jmexy.com | /r1kVYAfU/index.html
jmexy.com | /Re3BMGVG/index.html
jmexy.com | /rHFbxKTn/index.html
jmexy.com | /RoScD8aq/index.html
jmexy.com | /rzDZAsw7/index.html
jmexy.com | /tLnW6jJT/index.html
jmexy.com | /UAtkgmot/index.html
jmexy.com | /UcL29wrU/index.html
jmexy.com | /vpW8hoZ6/index.html
jmexy.com | /wcE0aK0J/index.html
jmexy.com | /wjivLtgo/index.html
jmexy.com | /wtQ8G0Ku/index.html
jmexy.com | /xXr3khjG/index.html
jmexy.com | /YhwvXGhk/index.html
jmexy.com | /zvo8ioak/index.html
justinbieber-fans.nixiweb.com | /6BrzkppT/index.html
justinbieber-fans.nixiweb.com | /7NEM56yQ/index.html
justinbieber-fans.nixiweb.com | /ddLvpeMu/index.html
justinbieber-fans.nixiweb.com | /DkM4v1PP/index.html
justinbieber-fans.nixiweb.com | /ErmgUouT/index.html
justinbieber-fans.nixiweb.com | /gj1W42Ee/index.html
justinbieber-fans.nixiweb.com | /iaJ7FSBi/index.html
justinbieber-fans.nixiweb.com | /Lskx0Bew/index.html
justinbieber-fans.nixiweb.com | /mKvc8Mh7/index.html
justinbieber-fans.nixiweb.com | /oZFZ0qJK/index.html
justinbieber-fans.nixiweb.com | /pD2zHbBB/index.html
justinbieber-fans.nixiweb.com | /pSG1s2xs/index.html
justinbieber-fans.nixiweb.com | /Re3BMGVG/index.html
justinbieber-fans.nixiweb.com | /rHFbxKTn/index.html
justinbieber-fans.nixiweb.com | /RoScD8aq/index.html
justinbieber-fans.nixiweb.com | /rzDZAsw7/index.html
justinbieber-fans.nixiweb.com | /t7xYVUJE/index.html
justinbieber-fans.nixiweb.com | /UcL29wrU/index.html
justinbieber-fans.nixiweb.com | /xXr3khjG/index.html
justinbieber-fans.nixiweb.com | /YhwvXGhk/index.html
justinbieber-fans.nixiweb.com | /zvo8ioak/index.html
mangalamcorporation.in | /4RcYf6gB/index.html
mangalamcorporation.in | /6BrzkppT/index.html
mangalamcorporation.in | /bp9ksV54/index.html
mangalamcorporation.in | /BzJoVeo0/index.html
mangalamcorporation.in | /ddLvpeMu/index.html
mangalamcorporation.in | /DkM4v1PP/index.html
mangalamcorporation.in | /gj1W42Ee/index.html
mangalamcorporation.in | /i8ztSS5H/index.html
mangalamcorporation.in | /iaJ7FSBi/index.html
mangalamcorporation.in | /mKvc8Mh7/index.html
mangalamcorporation.in | /N2rhmW5i/index.html
mangalamcorporation.in | /NdHgm0gT/index.html
mangalamcorporation.in | /oZFZ0qJK/indexhtml
mangalamcorporation.in | /oZFZ0qJK/index.html
mangalamcorporation.in | /pD2zHbBB/index.html
mangalamcorporation.in | /pSG1s2xs/index.html
mangalamcorporation.in | /r1kVYAfU/index.html
mangalamcorporation.in | /rHFbxKTn/index.html
mangalamcorporation.in | /RoScD8aq/index.html
mangalamcorporation.in | /rzDZAsw7/index.html
mangalamcorporation.in | /UAtkgmot/index.html
mangalamcorporation.in | /UcL29wrU/index.html
mangalamcorporation.in | /vpW8hoZ6/index.html
mangalamcorporation.in | /wcE0aK0J/index.html
mangalamcorporation.in | /xXr3khjG/index.html
mangalamcorporation.in | /YhwvXGhk/index.html
mksteslaenergy.com | /4RcYf6gB/index.html
mksteslaenergy.com | /6BrzkppT/index.html
mksteslaenergy.com | /7NEM56yQ/index.html
mksteslaenergy.com | /BzJoVeo0/index.html
mksteslaenergy.com | /ddLvpeMu/index.html
mksteslaenergy.com | /DkM4v1PP/index.html
mksteslaenergy.com | /ErmgUouT/index.html
mksteslaenergy.com | /gj1W42Ee/index.html
mksteslaenergy.com | /i8ztSS5H/index.html
mksteslaenergy.com | /iaJ7FSBi/index.html
mksteslaenergy.com | /mKvc8Mh7/index.html
mksteslaenergy.com | /N2rhmW5i/index.html
mksteslaenergy.com | /NdHgm0gT/index.html
mksteslaenergy.com | /oZFZ0qJK/index.html
mksteslaenergy.com | /pD2zHbBB/index.html
mksteslaenergy.com | /pSG1s2xs/index.html
mksteslaenergy.com | /r1kVYAfU/index.html
mksteslaenergy.com | /rzDZAsw7/indexhtml
mksteslaenergy.com | /rzDZAsw7/index.html
mksteslaenergy.com | /tLnW6jJT/index.html
mksteslaenergy.com | /UAtkgmot/index.html
mksteslaenergy.com | /UcL29wrU/index.html
mksteslaenergy.com | /wcE0aK0J/index.html
mksteslaenergy.com | /wjivLtgo/index.html
mksteslaenergy.com | /xXr3khjG/index.html
mksteslaenergy.com | /YhwvXGhk/index.html
mpralos.gr | /6BrzkppT/index.html
mpralos.gr | /7NEM56yQ/index.html
mpralos.gr | /7QLZuMme/index.html
mpralos.gr | /bp9ksV54/index.html
mpralos.gr | /BzJoVeo0/index.html
mpralos.gr | /ErmgUouT/index.html
mpralos.gr | /gj1W42Ee/index.html
mpralos.gr | /i8ztSS5H/index.html
mpralos.gr | /iaJ7FSBi/index.html
mpralos.gr | /Lskx0Bew/index.html
mpralos.gr | /mKvc8Mh7/index.html
mpralos.gr | /N2rhmW5i/index.html
mpralos.gr | /NdHgm0gT/index.html
mpralos.gr | /oZFZ0qJK/index.html
mpralos.gr | /pD2zHbBB/index.html
mpralos.gr | /pSG1s2xs/index.html
mpralos.gr | /r1kVYAfU/index.html
mpralos.gr | /rHFbxKTn/index.html
mpralos.gr | /rzDZAsw7/index.html
mpralos.gr | /t7xYVUJE/index.html
mpralos.gr | /tLnW6jJT/index.html
mpralos.gr | /UAtkgmot/index.html
mpralos.gr | /UcL29wrU/index.html
mpralos.gr | /wcE0aK0J/index.html
mpralos.gr | /wjivLtgo/index.html
mpralos.gr | /wtQ8G0Ku/index.html
mpralos.gr | /zvo8ioak/index.html
njsksansthan.com | /6BrzkppT/index.html
njsksansthan.com | /7NEM56yQ/index.html
njsksansthan.com | /7QLZuMme/index.html
njsksansthan.com | /bp9ksV54/index.html
njsksansthan.com | /ddLvpeMu/index.html
njsksansthan.com | /DkM4v1PP/index.html
njsksansthan.com | /ErmgUouT/index.html
njsksansthan.com | /iaJ7FSBi/index.html
njsksansthan.com | /Lskx0Bew/index.html
njsksansthan.com | /N2rhmW5i/index.html
njsksansthan.com | /pD2zHbBB/index.html
njsksansthan.com | /Re3BMGVG/index.html
njsksansthan.com | /RoScD8aq/index.html
njsksansthan.com | /rzDZAsw7/index.html
njsksansthan.com | /UcL29wrU/index.html
njsksansthan.com | /wtQ8G0Ku/index.html
njsksansthan.com | /xXr3khjG/index.html
njsksansthan.com | /YhwvXGhk/index.html
njsksansthan.com | /zvo8ioak/index.html
pakwestind.com | /6BrzkppT/index.html
pakwestind.com | /ErmgUouT/index.html
pakwestind.com | /i8ztSS5H/index.html
pakwestind.com | /NdHgm0gT/index.html
pakwestind.com | /oZFZ0qJK/index.html
pakwestind.com | /pD2zHbBB/index.html
pakwestind.com | /rHFbxKTn/index.html
pakwestind.com | /t7xYVUJE/index.html
pakwestind.com | /tLnW6jJT/index.html
pakwestind.com | /UAtkgmot/index.html
pakwestind.com | /UcL29wrU/index.html
pakwestind.com | /wcE0aK0J/index.html
pakwestind.com | /wtQ8G0Ku/index.html
punial.com | /4RcYf6gB/index.html
punial.com | /7NEM56yQ/index.html
punial.com | /7QLZuMme/index.html
punial.com | /bp9ksV54/index.html
punial.com | /BzJoVeo0/index.html
punial.com | /ErmgUouT/index.html
punial.com | /i8ztSS5H/index.html
punial.com | /NdHgm0gT/index.html
punial.com | /r1kVYAfU/index.html
punial.com | /rHFbxKTn/index.html
punial.com | /RoScD8aq/index.html
punial.com | /t7xYVUJE/index.html
punial.com | /UcL29wrU/index.html
punial.com | /vpW8hoZ6/index.html
punial.com | /xXr3khjG/index.html
punial.com | /zvo8ioak/index.html
rsons.in | /6BrzkppT/index.html
rsons.in | /bp9ksV54/index.html
rsons.in | /DkM4v1PP/index.html
rsons.in | /gj1W42Ee/index.html
rsons.in | /i8ztSS5H/index.html
rsons.in | /mKvc8Mh7/index.html
rsons.in | /r1kVYAfU/index.html
rsons.in | /Re3BMGVG/index.html
rsons.in | /tLnW6jJT/index.html
rsons.in | /UAtkgmot/index.html
rsons.in | /vpW8hoZ6/index.html
rsons.in | /wcE0aK0J/index.html
rsons.in | /wtQ8G0Ku/index.html
rsons.in | /xXr3khjG/index.html
siniflar.net | /4RcYf6gB/index.html
siniflar.net | /ddLvpeMu/index.html
siniflar.net | /ErmgUouT/index.html
siniflar.net | /wjivLtgo/index.html
Read More
Posted in | No comments

Thursday, 26 April 2012

SOCA & FBI seize 36 Criminal Credit Card Stores

Posted on 05:40 by Unknown
Today the Serious & Organised Crime Agency (SOCA) in the UK announced the completion of a joint operation targeting 36 criminal websites dealing with stolen credit card and online bank account information. The April 26th Press Release indicates that the operation targeted a particular type of e-commerce platform known as an Automated Vending Cart, or AVC. Here's an advertisement from one of the sites, CVVPlaza.com:

The seized domains are now redirected to a website controlled by the FBI which reads:

The United States Government has seized this domain name pursuant to a seizure warrant issued by the United States District Court for the Eastern District of Virginia under the authority of 18 U.S.C. §§ 981(a)(1)(A) & (b)(2). A United States Magistrate Judge issued that seizure warrant after finding that a sworn affidavit established probable cause that this domain name was personal property involved in a transaction or attempted transaction in violation of section 18 U.S.C. § 1956(a)(2)(A) & (h)
If you registered this domain name, or otherwise claim an ownership interest in this domain name, you should consult an attorney about your rights.


(click for full size)

SOCA has requested that we not provide a full list of the domain names at this time, but two which they have revealed in their own products are "cvvplaza.com" and "ccstore.biz". The others will be added once permission is received.

Some of the screenshots provided by SOCA include:

a site offering an inventory of more than 37,000 confirmed credit cards:

and a fairly nice "search screen:

SOCA has recovered more than 2.5 million card numbers or credentials that they say would have granted the criminals access to more than £500 million (about $809 million US Dollars!) These were NOT the value of the cards currently available for sale in these card shops, but rather the value of the cards that have been recovered from criminals who purchased the cards from these card shops. The total inventory is expected to be much higher. SOCA is leading the way in international cooperation. In this case they worked with the BKA in Germany, the KLPD in the Netherlands, the Ukraine Ministry of Internal Affairs, the Australian Federal Police, the Romanian National Police and of course the FBI in the United States. These recoveries took place over the course of the past two years. The operator of at least one of these AVC stores was arrested in Macedonia by the Macedonian Ministry of the Interior's Cyber Crime Unit. Some online card shops have very simplistic interfaces, such as this: while others have extremely beautiful websites. Check out the login page for this site: Our friend Dancho Danchev has written extensively about the online carding markets, for example in his article: Exposing Market for Stolen Credit Cards. Brian Krebs has also written extensively on the topic with articles such as How much is your identity worth?

Read More
Posted in | No comments

Tuesday, 3 April 2012

UK Zeus user G-Zero Sentenced

Posted on 04:25 by Unknown
According to today's Daily Mail, court details have now emerged regarding Edward Pearson, a 23 year old hacker from York, England known online as "G-Zero", and his activities involving the Zeus and SpyEye trojans.

Pearson was ultimately arrested after his girlfriend, Cassandra Mennim, tried to pay for hotel rooms at the Cedar Court Grand Hotel and the Lady Anne Middleton Hotel, both in York, using stolen credit cards. (Pictures of the hotels were in the Daily Mail's original story on this case on February 20 - Computer whizz faces jail for writing programme to steal personal details of 8 MILLION people, including 400 PayPal accounts.

G-Zero Gets Doxed (June 2011)


Although these details are not shared in court, the Hacker world has known who Pearson was for some time ... on June 3, 2011, on the hacker forum "OpenSC.ws" - a site where Trojan authors and botnet herders meet and greet and buy and sell from one another, a user named "cr333k" posted these details. His post read:

"I dedicate this post to ED aka G-Zero because he is the reason I obtained this material" (referring to the leaked version of SpyEye v.1.2.8.0 and v.1.2.99.39).

"So in his honor, I will chase him off the internet."

Cr333k then proceeds to document G-Zero's use of Spyeye, claiming that G-Zero was in charge of the Spyeye servers at 89.149.202.104 [Leaseweb in Germany] and 91.211.11.192 [a serverbox.de account hosted in the UK], and claiming that his main IP address was 178.86.2.40 [a Ukrainian IP], but that he also used the IPs 94.12.53.50 [a SkyNet broadband account in the UK] and 77.103.230.142 [a VirginMedia/Telewest residential cable modem in the UK].

He provides userids and passwords to several of his sites, including the details of his "webnames.ru" account in the name of "GZero" and his hosting.ua account in the name of "rogue2" (with the same password.)

He claimed at that time that his name was Edward Pearson, and that he was in control of the email accounts gzero@9.cn, eddypearson@gmail.com, solipsis@w.cn, cellar@9.cn.

He gave his address as: Edward Pearson, 11 Regatta Court, Oyster Row, Cambridge, Cambridgeshire, cb58ns, UK, and shared his userid and password for his Liberty Reserve online money account

Cr333k claims to have stolen $5500 from Pearson's account...no idea if that is true.

(Eddy also had his superstrong password hash dumped by the guys at Zero For Owned. When they dumped Eddy's details out of the RootCult website after SQL-injection of their database, Eddy's GroundZero password was shown to have an MD5 hash of c8837b23ff8aaa8a2dde915473ce0991. Bad news. That would mean his password was "123321". Not a good password choice for a bad ass hacker. Of course that dump was from 2006, so Eddy would have been ... 17??)

Loose Lips


Probably not a good idea to tie your bad-ass hacker name to your real name in such things as your SoundCloud account (Userid: GZero Name: Edward Pearson, Cambridge, Britain (UK) soundcloud.com/eddypearson

He did the same thing back in 2009 when he was trying to share his online video ripping system on the forum DigitalSpy. His ripper service was distributed from "ripple.net" which he registered with his true personal details, but advertised in the DigitalSpy forum with his hacker handle "GZero".

Domain name: RIZZLE.NET

Administrative Contact:
Pearson, Edward eddypearson@gmail.com
93 Brampton Road
Cambridge, Cambridgeshire CB1 3HJ
GB
+44.7912558447

GZero's post on July 13, 2010 to "HackForums.net" was also pretty interesting:

Alright guys,
Basically I've not been part of the "scene" for many years, long before botnets, around the "how do i hack hotmail?" era. I got very bored of the bunch of rude little pricks that seemed to engulf the place.

Who remembers Zebulun hey? :p

Anyway, I a freelance programmer (C,C++,PHP,Python+many more) and pentester, the legit kind!

I was playing with one of the public copies of the the Zeus botnet, and I have simply fallen in love!

Basically, I'm have all the skills to really do some cool stuff here, coding is my day job, and have until now been working with a private group to make a bit of cash on the side, just not with bots.

Basically, I can do Programming, Custom Hacking, Bulletproof hosting, Setups of anything, FUDding things, Some very sneaky stuff to do with botnet takeovers, CC stuff, Been stealing the latest drive by sploits (NOT the packs), reversing em and then hopefully I'll make a real nice exploit pack if I have the time.

Basically I only just got onto botnets, and I LOVE WHAT I SEE. That said, I have been working with malware, hacking, financial stuff and the darker side of things for many years, just with a group I trust, not involved in the "scene"

Long story short, I want to to talk to people, learn more about the way things are done, and ideally work with somebody, or do some work for them in exchange for a decent copy of Zeus.

Basically, I'm trying to get on this and I have everything else pretty much setup, but I'm just not happy with using a public Zeus. REALLY want to get everything JUUUST right before really get stuck in ;)

MSN me guys, even if you don't have what I want, a interesting discussion is always nice and I'm always nice and helpful. I do have some vaguely private softs to share, but really this is my problem, for this to be GOOD, I need a good bot, and I LOVE Zeus...

MSN:
gzero@9.cn
solipsis@w.cn




8 Million Identities?


According to the police, on one of Pearson's computers they recovered 8,110,474 names with birthdates and postcodes for adults living in the United Kingdom. He also had details of 2,701 credit or debit cards stolen between January 1, 2010 and August 30, 2011.

At one point Pearson used a program he had written in Python to test potential PayPal accounts, and successfully confirmed more than 200,000 PayPal account details.

David Hughes, the prosecutor in the case, says that Pearson also hacked into systems belonging to Nokia and AOL, which caused Nokia to disable certain of its systems for two weeks while it reviewed the intrusion.

(The Nokia intrusion is believed to be the August 2011 SQL Injection of the "developers.nokia.com" website)

Intellectual Challenge?


Although the crown paints Pearson as a criminal mastermind, his defense attorney, Andrew Bodnar, claims that he was not interested in large-scale theft, but considered this merely an intellectual challenge. To support his point, he claims that the total documented theft, despite possession of thousands of cards, was only £2,351 or about $3700 US Dollars, mostly in the form of fastfood orders, pizza, and to pay his cell phone bills.

This is quite a difference between the original charge, that Pearson "plotted a £350,000 fraud" ($560,000 USD).

Mennim's lawyer called her a "vulnerable young woman who found comfort in Pearson following a difficult previous relationship." He describes her as a straight A student who is ashamed of her actions and will pay back the money she owes the hotel.

Pearson was sentenced to two years and two months, and Mennim to 12 months of supervised release. Although Pearson did not SELL the details he had gathered, it was demonstrated that he shared them with other hackers online, and the judge took this into consideration in the sentencing, as she said "Your computers and software were a devastating tool kit. I accept you didn't sell this information, but you shared it with other computer programmers, and you had no way of knowing how THEY might use this information."

The ultimate charges, to which the pair plead guilty:

Pearson - "Making an article for used in fraud and two counts of possession of an article for use in fraud."

Mennim - "Two counts of obtaining services dishonestly."

According to the original charges, the couple were also dealing the drug MDVP, also called "super cocaine". Apparently those charges were dropped. They seem consistent with his lifestyle - for instance, see this post on Cannabis.com from October 2007 where Eddy announces he has just moved to Cambridge and is looking for "connections" via his MSN chat account, eddypearson@gmail.com. This is consistent with some of his HackForums.net posts where he describes himself as "High and Pissed Off".
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • Vista Security Features
    BitLocker Drive Encryption A Real-world Windows Vista BitLocker Tip BitLocker Drive Encryption BitLocker Drive Encryption Frequently Asked Q...
  • A Prominent American Express Phish
    Every once in a while we see a spam campaign where we dig in to the complexity, expecting to find malware, and find that the criminal has ju...
  • Money Laundering $1 at a time - a win for the UK's PCeU
    In London a little-known police unit called the Police Central E-Crime Unit (PCeU) has scored another big win. For several years people hav...
  • 2008: Looking back on a Year of Spam and Malware
    Happy New Year! As we get ready for the New Year, there are quite a few security folks making predictions for 2009. I think my friend Dan...
  • Most Dangerous Cities for Cyber Crime?
    Symantec Riskiest Cybercrime Cities Symantec released a study today in conjunction with Sperling's Best Places today. According to thei...
  • ACH Spammer switches to Shortened URLs
    For many weeks now the spammers behind one particular malware family have been fighting a running battle to keep their malware-hosting domai...
  • Lin Mun Poo: Hacker of the Federal Reserve and ...?
    ** UPDATE: Poo arraigned and in custody ** On October 21, 2010, Malaysian citizen Lin Mun Poo landed at the JFK airport in New York and and ...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ▼  2013 (17)
    • ▼  November (1)
      • Tempting Photo Attachments Lead to Fake AV
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ►  August (23)
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile