Over the past week and a half, cybercriminals have been aggressively spamvertising a growing portfolio of domains, relying on deceptive advertising for nonexistent and fraudulent online gambling web sites, serving the well known Win32.GAMECasino.
- Go through related posts: Don't Play Poker on an Infected Table; Malware(Client-Side Exploits) Serving Online Casinos
Detecting rate for SmartDownload.exe - Win32.GAMECasino - Result: 10/42 (23.81%). Sample phones back the following domain - download.realtimegaming.com /cdn/goldvipclub/package_list.ini.zip?fakeParam=1 - 212.201.100.144 - Email: admin@REALTIMEGAMING.COM; RealTime Gaming Holding Company, LLC, registered under the following address according to the information published on their web site:
- For Licensing opportunities or Company Information,please submit request to Hasting B.V. Click Here.Hastings International B.V.New Haven Office CenterEmancipatie Boulevard 31 – P.O. Box 6052Curacao Netherlands Antilles
Spamvertised domains parked on 116.123.221.17; 112.159.237.58:
aerojackpot.net - Email: dfgdfgvcsx12@foxmail.com
compujackpot.net - Email: dfgdfgvcsx12@foxmail.com
jackpotadvance.net - Email: dfgdfgvcsx12@foxmail.com
jackpotalist.net - Email: dfgdfgvcsx12@foxmail.com
jackpotbee.net - Email: dfgdfgvcsx12@foxmail.com
jackpotbuzz.net - Email: dfgdfgvcsx12@foxmail.com
jackpotcanyon.net - Email: dfgdfgvcsx12@foxmail.com
jackpotclubs.net - Email: dfgdfgvcsx12@foxmail.com
jackpotfairy.net - Email: dfgdfgvcsx12@foxmail.com
jackpotfan.net - Email: dfgdfgvcsx12@foxmail.com
jackpotflag.net - Email: dfgdfgvcsx12@foxmail.com
jackpoticity.net - Email: dfgdfgvcsx12@foxmail.com
jackpotjets.net - Email: dfgdfgvcsx12@foxmail.com
jackpotlodge.net - Email: dfgdfgvcsx12@foxmail.com
jackpotlodge.net - Email: dfgdfgvcsx12@foxmail.com
jackpotmoment.net - Email: dfgdfgvcsx12@foxmail.com
jackpotpair.net - Email: dfgdfgvcsx12@foxmail.com
jackpotrocket.net - Email: dfgdfgvcsx12@foxmail.com
jackpotthink.net - Email: dfgdfgvcsx12@foxmail.com
jackpottodoor.net - Email: dfgdfgvcsx12@foxmail.com
jackpotwire.net - Email: dfgdfgvcsx12@foxmail.com
jacpotcongress.net - Email: dfgdfgvcsx12@foxmail.com
linejackpot.net - Email: dfgdfgvcsx12@foxmail.com
lux777cazino.net - Email: efghfgbvghfgh@qq.com
majicjackpot.net - Email: dfgdfgvcsx12@foxmail.com
midjackpot.net - Email: dfgdfgvcsx12@foxmail.com
mixerjackpot.net - Email: dfgdfgvcsx12@foxmail.com
needjackpot.net - Email: dfgdfgvcsx12@foxmail.com
nestjackpot.net - Email: dfgdfgvcsx12@foxmail.com
shopjackpot.net - Email: dfgdfgvcsx12@foxmail.com
smart-nest.net - Email: dfgdsfvcb@163.com
structjackpot.net - Email: dfgdfgvcsx12@foxmail.com
the-cash.net - Email: dfgdsfvcb@163.com
thejackpots.net - Email: dfgdfgvcsx12@foxmail.com
windowjackpots.net - Email: dfgdfgvcsx12@foxmail.com
win-vox.net - Email: dfgdsfvcb@163.com
aerowin.net - Email: dfgdsfvcb@163.com
beach-jackpot.net - Email: dfgdsfvcb@163.com
beautyselite.net - Email: dfgdsfvcb@163.com
binwin.net - Email: dfgdsfvcb@163.com
clashflash.net - Email: dfgdsfvcb@163.com
couldwin.net - Email: dfgdsfvcb@163.com
dinwin.net - Email: dfgdsfvcb@163.com
eliteclasss.net - Email: dfgdsfvcb@163.com
eliteorder.net - Email: dfgdsfvcb@163.com
eliteplaza.net - Email: dfgdsfvcb@163.com
elitescoop.net - Email: dfgdsfvcb@163.com
eliteweird.net - Email: dfgdsfvcb@163.com
ezelite.net - Email: dfgdsfvcb@163.com
flashapex.net - Email: dfgdsfvcb@163.com
flashbrook.net - Email: dfgdsfvcb@163.com
flashbuzzs.net - Email: dfgdsfvcb@163.com
flashcensus.net - Email: dfgdsfvcb@163.com
flashclashs.net - Email: dfgdsfvcb@163.com
flashlasch.net - Email: dfgdsfvcb@163.com
flashlash.net - Email: dfgdsfvcb@163.com
flashmoment.net - Email: dfgdsfvcb@163.com
flashnest.net - Email: dfgdsfvcb@163.com
flashpixie.net - Email: dfgdsfvcb@163.com
flashslash.net - Email: dfgdsfvcb@163.com
flashspark.net - Email: dfgdsfvcb@163.com
flashspell.net - Email: dfgdsfvcb@163.com
flashzap.net - Email: dfgdsfvcb@163.com
free-smart.net - Email: dfgdsfvcb@163.com
ginwin.net - Email: dfgdsfvcb@163.com
goingtowins.net - Email: dfgdsfvcb@163.com
hitecwinner.net - Email: dfgdsfvcb@163.com
innerwinner.net - Email: dfgdsfvcb@163.com
interelite.net - Email: dfgdsfvcb@163.com
jackpot-direct.net - Email: dfgdsfvcb@163.com
jackpot-fire.net - Email: dfgdsfvcb@163.com
jackpot-help.net - Email: dfgdsfvcb@163.com
jackpot-infinity.net - Email: dfgdsfvcb@163.com
jackpot-mind.net - Email: dfgdsfvcb@163.com
jackpot-minute.net - Email: dfgdsfvcb@163.com
jackpot-phone.net - Email: dfgdsfvcb@163.com
jackpot-reunion.net - Email: dfgdsfvcb@163.com
jackpot-senate.net - Email: dfgdsfvcb@163.com
jackpot-talk.net - Email: dfgdsfvcb@163.com
jackpot-taven.net - Email: dfgdsfvcb@163.com
jackpot-topia.net - Email: dfgdsfvcb@163.com
jackpot-wire.net - Email: dfgdsfvcb@163.com
laschflash.net - Email: dfgdsfvcb@163.com
learn-jackpot.net - Email: dfgdsfvcb@163.com
magicwinner.net - Email: dfgdsfvcb@163.com
mapwinner.net - Email: dfgdsfvcb@163.com
mediaselite.net - Email: dfgdsfvcb@163.com
mindelite.net - Email: dfgdsfvcb@163.com
mrelite.net - Email: dfgdsfvcb@163.com
needwin.net - Email: dfgdsfvcb@163.com
pixiewinner.net - Email: dfgdsfvcb@163.com
powerwinners.net - Email: dfgdsfvcb@163.com
predict-jackpot.net - Email: dfgdsfvcb@163.com
pushelite.net - Email: dfgdsfvcb@163.com
reseachelite.net - Email: dfgdsfvcb@163.com
sellelite.net - Email: dfgdsfvcb@163.com
sgameelite.net - Email: dfgdsfvcb@163.com
sharpwinner.net - Email: dfgdsfvcb@163.com
smart-enough.net - Email: dfgdsfvcb@163.com
smart-fire.net - Email: dfgdsfvcb@163.com
smart-log.net - Email: dfgdsfvcb@163.com
smart-nest.net - Email: dfgdsfvcb@163.com
smart-spree.net - Email: dfgdsfvcb@163.com
steelites.net - Email: dfgdsfvcb@163.com
surveylite.net - Email: dfgdsfvcb@163.com
targetelite.net - Email: dfgdsfvcb@163.com
theelites.net - Email: dfgdsfvcb@163.com
theflashers.net - Email: dfgdsfvcb@163.com
theywin.net - Email: dfgdsfvcb@163.com
velowinner.net - Email: dfgdsfvcb@163.com
vote-smart.net - Email: dfgdsfvcb@163.com
wanttowin.net - Email: dfgdsfvcb@163.com
winbot.net - Email: dfgdsfvcb@163.com
winnercrest.net - Email: dfgdsfvcb@163.com
winnerfast.net - Email: dfgdsfvcb@163.com
winnerhut.net - Email: dfgdsfvcb@163.com
winnerincumbent.net - Email: dfgdsfvcb@163.com
winnermass.net - Email: dfgdsfvcb@163.com
winnerpub.net - Email: dfgdsfvcb@163.com
winnerrocket.net - Email: dfgdsfvcb@163.com
winnersalon.net - Email: dfgdsfvcb@163.com
winnerscan.net - Email: dfgdsfvcb@163.com
winnertake.net - Email: dfgdsfvcb@163.com
winnertal.net - Email: dfgdsfvcb@163.com
winnertoyou.net - Email: dfgdsfvcb@163.com
zap-smart.net - Email: dfgdsfvcb@163.com
Name servers of notice:
ns1.bb6ns.com - 58.83.8.45 - Email: li-zhenshu@163.com
ns1.bedws.com - 218.61.126.28 - Email: guoxiufenghy@163.com
ns1.catdogns.com - 218.61.126.28 - Email: li-zhenshu@163.com
ns1.cebht.com - 218.61.126.28 - Email: li-zhenshu@163.com
ns1.dd5ns.com - 61.191.191.61 - Email: li-zhenshu@163.com
ns1.dogmens.com - 208.78.242.185 - Email: hmr@data99.com
ns1.euromarketorder.com - 218.61.126.28
ns1.fesws.com - 218.61.126.28 - Email: info2@data99.com
ns1.goatdns.com - 218.61.126.28 - Email: li-zhenshu@163.com
ns1.hh7ns.com - 218.61.126.28 - Email: li-zhenshu@163.com
ns1.kindball.com - 218.61.126.28 - Email: zhaokaijunlp@163.com
ns1.mm8ns.com - 218.61.126.28 - Email: li-zhenshu@163.com
ns1.nn4ns.com - 218.61.126.28 - Email: li-zhenshu@163.com
ns1.ss6ns.com - 61.191.191.61 - Email: shirley9127@hotmail.com
ns1.wildnn.com - 208.78.242.185 - Email: hmr@data99.com
ns2.gg9ns.com - 218.61.126.28 - Email: li-zhenshu@163.com
ns2.sruisorehoes.com - 218.61.126.28 - Email: li-zhenshu@163.com
ns2.zz8ns.com - 218.61.126.28 - Email: li-zhenshu@163.com
ns3.bavns.com - 218.61.126.28 - Email: shirley9127@hotmail.com
ns3.bawns.com - 218.61.126.28 - Email: li-zhenshu@163.com
ns3.becns.com - 218.61.126.28 - Email: li-zhenshu@163.com
ns3.bojns.com - 218.61.126.28 - Email: li-zhenshu@163.com
The campaign is a great example of cybercrime-friendly affiliate networks, with the cybercriminals in this case investing a modest amount of money for the actual spamming process, and then earning 30% flat rate, which can also be scaling between 20% to 45% depending on their choice.
The practice has been around for years. Here are three monetizations strategies seeing within the last two years, all of which remain an active tactic for fraudsters to take advantage of:
- Brandjacking and monetizing through pseudo-value added crapware applications- this practice has been profiled in a previous analysis "Cybersquatting Security Vendors for Fraudulent Purposes". PandaSecurity's reaction back then? Immediate notification of their legal department.
- SMS micro-payment scams through typosquatting and brandjacking - this tactic has already been profiled in "Legitimate Software Typosquatted in SMS Micro-Payment Scam" analysis. Compared to the typosquatting in the previous scheme, this campaign was monetizing freely available software.
- Abuse of legitimate affiliate networks - In January, 2009, I profiled and took down a campaign that has typosquatted domains for popular applications and was advertising them through Google's AdSense in an attempt to earn money from a legitimate affiliate network - Conduit's Rewards Program. The abuse of these networks can be easily taken care of, since the cybercriminal that's violating their Terms of Service is exposing himself as a legitimate user, with his very own CampaignID.
Amazon's Web Services are aware of this campaign. Action against it should be taken shortly.
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
No comments:
Post a Comment