Keeping Money Mule Recruiters on a Short Leash - Part Five

0
January 31, 2011

With money mule recruitment continuing to represent the most actively used risk-forwarding tactic within the cybercrime ecosystem for the purpose of securely distribution fraudulently obtained funds, part five of the "Keeping Money Mule Recruiters on a Short Leash" series are here to stay.

What's particularly interesting about the money mule recruitment domain portfolio that I'll expose, is the logical progression from bogus companies offering financial services, to a diverse set of companies occupying multiple markets/covering different market segments.

-Current trends - Localization and standardization/template-tization
A great example of this trend -- largely driven by the standardization and template-zation of money mule recruitment sites as a service- is Schwartz & Brothers LLC (schwartz-brothers.cc).

"Schwartz & Brothers LLC is the first choice for artists and buyers alike! Schwartz & Brothers LLC is an effective tool for the artist and emerging artist to market and promote their art in a professional and inexpensive manner. We will market your art to the international community of art buyers. Whether you are looking to buy or sell original art, Schwartz & Brothers LLC is the premier art site for those seeking to buy or sell original art online."


From financial services to an entirely new market segment, whereas the entire recruitment process remains pretty static, excluding several time quality assurance oriented details. For instance, every potential mule is required to download a entry level job psychological test, which surprisingly asks directly whether the mule is from Australia, next to automatically choosing Australia as a country of origin at a later stage throughout the registration process.

Moreover, in the context of quality assurance, the recruiters also ask the applicant "Are you/were you convicted?" in an attempt to combine the survey results with other details such the opening date of the bank account, as well as the average daily/weekly/monthly amount transferred.

- The Terms of Service
"DUTIES:
The Contractor undertakes the responsibility to receive payments from the Clients of the Company to his personal bank account, withdraw cash and to process payments to the Company's partners by Western Union or MoneyGram money transfer system within one (1) day. He/she will report directly to the senior manager and to any other party designated by the senior manager in connection with the performance of the duties under this Agreement and shall fulfill any other duties reasonably requested by the Company and agreed to by the Contractor.

CONFIDENTIALITY:
The Contractor acknowledges that during the engagement he will have access to and become acquainted with various trade secrets, inventions, innovations, processes, information, records and specifications owned or licensed by the Company and/or used by the Company in connection with the operation of its business including, without limitation, the Company's business and product processes, methods, customer lists, accounts and procedures.

The Contractor agrees that he will not disclose any of the aforesaid, directly or indirectly, or use any of them in any manner, either during the term of this Agreement or at any time thereafter. All files, records, documents, blueprints, specifications, information, letters, notes, media lists, original artwork/creative, notebooks, and similar items relating to the business of the Company, whether prepared by the Contractor or otherwise coming into his possession, shall remain the exclusive property of the Company.

The Contractor shall not retain any copies of the foregoing without the Company's prior written permission. The Contractor further agrees that he will not disclose his retention as an independent contractor or the terms of this Agreement to any person without the prior written consent of the Company and shall at all times preserve the confidential nature of his relationship to the Company and of the services hereunder.

If the Contractor releases any of the above information to any parties outside of this company, such as personal friend, close relatives or other Financial Institutions such as a Bank or other Financial Firms, such could be considered grounds for immediate termination. If the Contractor is ever in doubt of what information can be released and when, the Contractor will contact their superior right away.

TERMS OF ENGAGEMENT:
The Contractor is engaged by the Company on terms of thirty-days (30) probationary period. During the probationary period the Company undertakes to pay to the Contractor the base salary amounting to AUD 2300 per month plus 8% commission from each payment processing operation. After the probationary period the Company agrees to revise and raise the base salary to 3000 USD. The Company has the right to cancel this Agreement at any time within the probationary period or refuse to extend it after that, should the Contractor refuse to fulfill his/her obligations under this Agreement or fulfills them not in good faith.The Contractor has the right to terminate the Agreement at any time on condition that he/she has processed all previous payments and has no new instructions.

COMPENSATION:
The Company undertakes to pay taxes accrued in connection with money transfer.The Company shall also reimburse part of expenses which are incurred in connection with money transfer by Western Union or MoneyGram systems (should money transfer charges exceed 3%, i.e. commission for payment processing operation).The above difference will be automatically added to the base salary of the Contractor and paid once per month together with the base salary.

The Company shall have the right to decrease the Contractor's commission in case the payment processing terms were violated by the Contractor. Should the Contractor delays re-sending money accepted to his bank account for the period exceeding one (1) day without any explicit reason, the Company shall have the right to impose sanctions on the Contractor if only the delay has not been caused by the Force Majeur circumstances and to apply to the arbitration and claim for the reimburse of the amount transferred to his account or for compensation for other damage if any, evicted due to the delay.

The Contractor may take days off at any time and at his/her option upon giving five (5) working days advance notice in writing or three (3) working days advance notice via e-mail or fax to the Company in order that the latter may abstain from charging the Contractor with new instructions. However, salary for each day-off is deducted from the Contractor's base salary.
"

- OSINT data for money mule recruitment sites
The following portfolio of money mule recruitment domains appears to have been registered using automated email registration tools, with the potential for CAPTCHA outsourcing clearly considered by the malicious parties, taking into consideration the even decreasing price for solving CAPTCHA challenges.

4STAR-SOLUTIONS.CC - Email: urge@bz3.ru
ACOON-GROUPLLC.CC - Email: bombay@yourisp.ru
ACOONGROUP-LLC.CO - Email: jx@ppmail.ru
AIMIC-GROUPLLC.CC - 98.141.220.118 - Email: aryan@ppmail.ru
AMINA-GROUPCO.CO - Email: beige@ca4.ru
AMINA-GROUPINC.CC - Email: zowie@yourisp.ru
AMINAORG.CC - Email: range@ppmail.ru
ARPHIS-GOLDGROUP.CC - Email: rook@ca4.ru
ARPHIS-GOLDGROUP.CC - Email: rook@ca4.ru
ARPHISGOLDGROUP-INC.CO - Email: ira@bz3.ru
AUS-FINANCE.CC - Email: ours@ca4.ru
BREDGAR-GROUPLLC.CC - Email: zoe@ca4.ru
BREDGARGROUP-LLC.CO - Email: judo@free-id.ru
CESIS-GROUPLLC.CC - Email: el@cheapbox.ru
CESISGROUP-LLC.CC - Email: flip@free-id.ru
CESIS-GROUPLLC.CO - Email: our@ca4.ru
COCOONGROUP-LLC.HK - Email: most@cheapbox.ru
CORES-GROUP.CC - Email: jaunt@cheapbox.ru
CORESGROUP-INC.CO - Email: yule@cheapbox.ru
CORES-GROUPLTD.CO - Email: liszt@bz3.ru
CRAFT-GROUPNET.CC - Email: room@yourisp.ru
DILIGENCE-GROUP.CO - Email: twig@ppmail.ru
DILIGENCE-GROUPINC.CC - Email: till@cheapbox.ru
DUNCROFT-GROUP-INC.CC - Email: swiss@ca4.ru
DUNCROFTGROUP-INC.CO - Email: shoot@ppmail.ru
ELSDEN-GROUPINC.HK - Email: lost@ppmail.ru
FARLINE-FIN.CO - Email: pecks@free-id.ru
FARLINE-FININC.CC - Email: cynic@free-id.ru
FILEGROUP-LLC.CO - Email: knelt@ca4.ru
FINTEC-LTD.CC - Email: w@yourisp.ru
FINTEC-UK.CO - Email: sons@bz3.ru


GLEICHFALLS-GROUPINC.CO - Email: tents@ppmail.ru
I-COMPASS-GROUP.CO - Email: wolf@ca4.ru
IM-SYSGROUP.CO - Email: truce@free-id.ru
IMSYSTEMS-GROUP.CC - Email: agate@bz3.ru
INCOGROUP-USA.CO - Email: beams@free-id.ru
JOURNEY-FINANCIAL.CC - Email: lulu@ca4.ru
LBMGROUPCO.CC - Email: dreamy@ppmail.ru
LBM-GROUPINC.CO - Email: coma@ca4.ru
LCD-FIN.CO - Email: salt@free-id.ru
LCD-FINANCE.CC - Email: fritz@bz3.ru
MACROTECHINC.CC - Email: cv@yourisp.ru
MACROTECH-UK.CO - Email: curl@cheapbox.ru
MALLOW-GROUP.CC - Email: cues@ppmail.ru
MALLOW-GROUPINC.CO - Email: hn@bz3.ru
MONEY-VISUALUK.CC - Email: hn@bz3.ru
MONEYVISUAL-LLC.CO - Email: yam@free-id.ru
MARFYGROUP.CC - Email: thorny@cheapbox.ru
MICHAELESGROUP-USA.CO - Email: knelt@ca4.ru
OLIVER-SONSINC.CC - Email: drub@cheapbox.ru
ONLINE-SOLUTIONSLLC.CC - Email: coma@ca4.ru
PEGASLTDUNION.cc - Email: prim@bz3.ru
PHYSIS-GROUPLLC.CC - Email: tt@ca4.ru
PHYSISGROUP-LLC.CO - Email: opals@free-id.ru
PINFOLD-GROUPINC.CO - Email: beams@free-id.ru
RADIUM-GROUP.CC - Email: spy@yourisp.ru
RADIUMUK-LTD.CC - Email: socks@cheapbox.ru
REDISCO-GROUPINC.HK - Email: wimp@ca4.ru
SANTORINI-FIN.CC - Email: gill@cheapbox.ru
SANTORINI-FINANCE.CO - Email: foul@yourisp.ru
SCHNELLER-GROUPINC.CO - Email: foul@yourisp.ru
SCHWARTZ-BROTHERS.cc - Email: oozed@bz3.ru
SILVERSUNGROUP-INC.CC - Email: cp@ca4.ru
SILVERSUN-GROUPUK.CO - Email: cheer@ca4.ru
SOLUTIONSLTD.CC - Email: h2o@ca4.ru
STILE-GROUPLLC.CC - Email: ma@free-id.ru
SUNRISEPR-GROUPLTD.CC - Email: cough@ppmail.ru
TECHADVINC.CC - Email: chance@cheapbox.ru
TECHADV-INC.CC - Email: chance@cheapbox.ru
TECHOUSE-GROUP.CC - Email: scale@yourisp.ru
UKTECH-GROUPLLC.CC - Email: cap@ca4.ru
USGROUP-AMINA.CO - Email: cap@ca4.ru
USGROUP-REIGN.CO - Email: w@ppmail.ru
YESGROUP-LLC.CO - Email: twig@ppmail.ru

Name servers of notice:
NS1.LIBUNITAU.CC - 178.162.152.76 (AS28753) - Email: ached@yourisp.ru
NS1.NNSQUE.CC - Email: amok@cheapbox.ru
NS1.OLIVAU.CC - Email: bop@cheapbox.ru
NS1.PAGEREDNS.CC - 178.162.152.77 (AS28753) - Email: freer@free-id.ru
NS1.SURPLUSUSA.CC - 209.159.156.162 (AS19318) - Email: skulk@ppmail.ru
NS1.TVSILVAU.CC - Email: fact@ppmail.ru
NS1.UKNSSPACE.CC - 69.10.44.190 (AS19318) - Email: gravy@ca4.ru
ns1.uksource.cc - 69.10.44.189 (AS19318) - Email: liver@cheapbox.ru
NS1.USABONDS.CC - Email: bart@cheapbox.ru
NS2.AUSTDEC.CC - 66.199.236.114 (AS15149) - Email: bold@yourisp.ru
NS2.COUKSNS.CC - 122.70.148.179 (AS55462) - Email: preen@ppmail.ru
ns2.gbtrade.cc - 66.199.236.114 (AS15149) - Email: ct@yourisp.ru
NS2.OLIVAU.CC - Email: bop@cheapbox.ru
NS2.RINGTONS.CC - 66.199.236.115 (AS15149) - Email: aaron@cheapbox.ru
NS2.TVSILVAU.CC - Email: fact@ppmail.ru
NS2.USAFUNDS.CC - 76.73.47.28 (AS30058) - Email: tile@yourisp.ru
NS2.ZONENSUK.CC - 178.162.181.11 (AS28753) - Email: rooms@ppmail.ru
NS3.AUSTDEC.CC - 178.162.181.11 (AS28753) - Email: bold@yourisp.ru
NS3.FOLOWDNS.CC - 178.162.181.11 (AS28753) - Email: dyed@bz3.ru
NS3.SDNSAU.CC - Email: level@cheapbox.ru
NS3.SURPLUSUSA.CC - 69.50.192.97 (AS18866) - Email: skulk@ppmail.ru
NS3.TVSILVAU.CC - Email: fact@ppmail.ru
NS3.UKCCONS.CC - 178.162.181.11 (AS28753) - Email: ted@cheapbox.ru
NS3.UKDNS.CC - 66.199.236.116 (AS15149) - Email: append@free-id.ru
ns3.ukearnings.cc - 178.162.181.11 (AS28753) - Email: bf@free-id.ru

ASs of notice using standart ns1;ns2; ns3 structure:
AS28753 - NETDIRECT AS NETDIRECT Frankfurt, DE
AS19318 - NJIIX-1 NJIIX.net 110B Meadowlands Pkwy Secaucus, NJ 07094 +1.201.605.1425
AS28753 - NETDIRECT AS NETDIRECT Frankfurt, DE
AS15149 - EZZI-101-BGP EZZI

- Long term trends - "from mule inventory to transactions inventory"
With the localization and standardization/template-tization of the entire money mule recruitment process an every day's reality, quality assurance and diversification of the markets/market segments in order to increase the probability of successful social engineering attack, will start taking place. Moreover, the current template driven recruitment ecosystem will inevitably start taking advantage of basic concepts such as geolocation and content cloaking, in order to once again increase the probability for converting a web site visitor into a mule.

At an invite-only conference that I attended in September, 2010, someone from the audience asked me a rather interesting question. Does it really matter how many mules are recruited by a particular syndicate, and most importantly, can we talk about average number of days/weeks/hours by the time the mule gets busted, and can no longer offer his/her services?

In the long term, we're inevitably going to witness the migration from building inventories of mules to transaction-driven mule recruitment model where the capability-driven mentality surpasses the mule inventory building one. The number of possible transactions with success rates based on historical performance, combined with an infinite loop of recruitment is what will drive the entire mule recruitment ecosystem.

Related posts:
The DNS Infrastructure of the Money Mule Recruitment Ecosystem
Keeping Money Mule Recruiters on a Short Leash - Part Four
Money Mule Recruitment Campaign Serving Client-Side Exploits
Keeping Money Mule Recruiters on a Short Leash - Part Three
Money Mule Recruiters on Yahoo!'s Web Hosting
Dissecting an Ongoing Money Mule Recruitment Campaign
Keeping Money Mule Recruiters on a Short Leash - Part Two
Keeping Reshipping Mule Recruiters on a Short Leash
Keeping Money Mule Recruiters on a Short Leash
Standardizing the Money Mule Recruitment Process
Inside a Money Laundering Group's Spamming Operations
Money Mule Recruiters use ASProx's Fast Fluxing Services
Money Mules Syndicate Actively Recruiting Since 2002

This post has been reproduced from Dancho Danchev's blog. Continue reading →

Keeping Money Mule Recruiters on a Short Leash - Part Five

January 31, 2011

With money mule recruitment continuing to represent the most actively used risk-forwarding tactic within the cybercrime ecosystem for the purpose of securely distribution fraudulently obtained funds, part five of the "Keeping Money Mule Recruiters on a Short Leash" series are here to stay.

What's particularly interesting about the money mule recruitment domain portfolio that I'll expose, is the logical progression from bogus companies offering financial services, to a diverse set of companies occupying multiple markets/covering different market segments.

-Current trends - Localization and standardization/template-tization
A great example of this trend -- largely driven by the standardization and template-zation of money mule recruitment sites as a service- is Schwartz & Brothers LLC (schwartz-brothers.cc).

"Schwartz & Brothers LLC is the first choice for artists and buyers alike! Schwartz & Brothers LLC is an effective tool for the artist and emerging artist to market and promote their art in a professional and inexpensive manner. We will market your art to the international community of art buyers. Whether you are looking to buy or sell original art, Schwartz & Brothers LLC is the premier art site for those seeking to buy or sell original art online."


From financial services to an entirely new market segment, whereas the entire recruitment process remains pretty static, excluding several time quality assurance oriented details. For instance, every potential mule is required to download a entry level job psychological test, which surprisingly asks directly whether the mule is from Australia, next to automatically choosing Australia as a country of origin at a later stage throughout the registration process.

Moreover, in the context of quality assurance, the recruiters also ask the applicant "Are you/were you convicted?" in an attempt to combine the survey results with other details such the opening date of the bank account, as well as the average daily/weekly/monthly amount transferred.

- The Terms of Service
"DUTIES:
The Contractor undertakes the responsibility to receive payments from the Clients of the Company to his personal bank account, withdraw cash and to process payments to the Company's partners by Western Union or MoneyGram money transfer system within one (1) day. He/she will report directly to the senior manager and to any other party designated by the senior manager in connection with the performance of the duties under this Agreement and shall fulfill any other duties reasonably requested by the Company and agreed to by the Contractor.

CONFIDENTIALITY:
The Contractor acknowledges that during the engagement he will have access to and become acquainted with various trade secrets, inventions, innovations, processes, information, records and specifications owned or licensed by the Company and/or used by the Company in connection with the operation of its business including, without limitation, the Company's business and product processes, methods, customer lists, accounts and procedures.

The Contractor agrees that he will not disclose any of the aforesaid, directly or indirectly, or use any of them in any manner, either during the term of this Agreement or at any time thereafter. All files, records, documents, blueprints, specifications, information, letters, notes, media lists, original artwork/creative, notebooks, and similar items relating to the business of the Company, whether prepared by the Contractor or otherwise coming into his possession, shall remain the exclusive property of the Company.

The Contractor shall not retain any copies of the foregoing without the Company's prior written permission. The Contractor further agrees that he will not disclose his retention as an independent contractor or the terms of this Agreement to any person without the prior written consent of the Company and shall at all times preserve the confidential nature of his relationship to the Company and of the services hereunder.

If the Contractor releases any of the above information to any parties outside of this company, such as personal friend, close relatives or other Financial Institutions such as a Bank or other Financial Firms, such could be considered grounds for immediate termination. If the Contractor is ever in doubt of what information can be released and when, the Contractor will contact their superior right away.

TERMS OF ENGAGEMENT:
The Contractor is engaged by the Company on terms of thirty-days (30) probationary period. During the probationary period the Company undertakes to pay to the Contractor the base salary amounting to AUD 2300 per month plus 8% commission from each payment processing operation. After the probationary period the Company agrees to revise and raise the base salary to 3000 USD. The Company has the right to cancel this Agreement at any time within the probationary period or refuse to extend it after that, should the Contractor refuse to fulfill his/her obligations under this Agreement or fulfills them not in good faith.The Contractor has the right to terminate the Agreement at any time on condition that he/she has processed all previous payments and has no new instructions.

COMPENSATION:
The Company undertakes to pay taxes accrued in connection with money transfer.The Company shall also reimburse part of expenses which are incurred in connection with money transfer by Western Union or MoneyGram systems (should money transfer charges exceed 3%, i.e. commission for payment processing operation).The above difference will be automatically added to the base salary of the Contractor and paid once per month together with the base salary.

The Company shall have the right to decrease the Contractor's commission in case the payment processing terms were violated by the Contractor. Should the Contractor delays re-sending money accepted to his bank account for the period exceeding one (1) day without any explicit reason, the Company shall have the right to impose sanctions on the Contractor if only the delay has not been caused by the Force Majeur circumstances and to apply to the arbitration and claim for the reimburse of the amount transferred to his account or for compensation for other damage if any, evicted due to the delay.

The Contractor may take days off at any time and at his/her option upon giving five (5) working days advance notice in writing or three (3) working days advance notice via e-mail or fax to the Company in order that the latter may abstain from charging the Contractor with new instructions. However, salary for each day-off is deducted from the Contractor's base salary.
"

- OSINT data for money mule recruitment sites
The following portfolio of money mule recruitment domains appears to have been registered using automated email registration tools, with the potential for CAPTCHA outsourcing clearly considered by the malicious parties, taking into consideration the even decreasing price for solving CAPTCHA challenges.

4STAR-SOLUTIONS.CC - Email: urge@bz3.ru
ACOON-GROUPLLC.CC - Email: bombay@yourisp.ru
ACOONGROUP-LLC.CO - Email: jx@ppmail.ru
AIMIC-GROUPLLC.CC - 98.141.220.118 - Email: aryan@ppmail.ru
AMINA-GROUPCO.CO - Email: beige@ca4.ru
AMINA-GROUPINC.CC - Email: zowie@yourisp.ru
AMINAORG.CC - Email: range@ppmail.ru
ARPHIS-GOLDGROUP.CC - Email: rook@ca4.ru
ARPHIS-GOLDGROUP.CC - Email: rook@ca4.ru
ARPHISGOLDGROUP-INC.CO - Email: ira@bz3.ru
AUS-FINANCE.CC - Email: ours@ca4.ru
BREDGAR-GROUPLLC.CC - Email: zoe@ca4.ru
BREDGARGROUP-LLC.CO - Email: judo@free-id.ru
CESIS-GROUPLLC.CC - Email: el@cheapbox.ru
CESISGROUP-LLC.CC - Email: flip@free-id.ru
CESIS-GROUPLLC.CO - Email: our@ca4.ru
COCOONGROUP-LLC.HK - Email: most@cheapbox.ru
CORES-GROUP.CC - Email: jaunt@cheapbox.ru
CORESGROUP-INC.CO - Email: yule@cheapbox.ru
CORES-GROUPLTD.CO - Email: liszt@bz3.ru
CRAFT-GROUPNET.CC - Email: room@yourisp.ru
DILIGENCE-GROUP.CO - Email: twig@ppmail.ru
DILIGENCE-GROUPINC.CC - Email: till@cheapbox.ru
DUNCROFT-GROUP-INC.CC - Email: swiss@ca4.ru
DUNCROFTGROUP-INC.CO - Email: shoot@ppmail.ru
ELSDEN-GROUPINC.HK - Email: lost@ppmail.ru
FARLINE-FIN.CO - Email: pecks@free-id.ru
FARLINE-FININC.CC - Email: cynic@free-id.ru
FILEGROUP-LLC.CO - Email: knelt@ca4.ru
FINTEC-LTD.CC - Email: w@yourisp.ru
FINTEC-UK.CO - Email: sons@bz3.ru


GLEICHFALLS-GROUPINC.CO - Email: tents@ppmail.ru
I-COMPASS-GROUP.CO - Email: wolf@ca4.ru
IM-SYSGROUP.CO - Email: truce@free-id.ru
IMSYSTEMS-GROUP.CC - Email: agate@bz3.ru
INCOGROUP-USA.CO - Email: beams@free-id.ru
JOURNEY-FINANCIAL.CC - Email: lulu@ca4.ru
LBMGROUPCO.CC - Email: dreamy@ppmail.ru
LBM-GROUPINC.CO - Email: coma@ca4.ru
LCD-FIN.CO - Email: salt@free-id.ru
LCD-FINANCE.CC - Email: fritz@bz3.ru
MACROTECHINC.CC - Email: cv@yourisp.ru
MACROTECH-UK.CO - Email: curl@cheapbox.ru
MALLOW-GROUP.CC - Email: cues@ppmail.ru
MALLOW-GROUPINC.CO - Email: hn@bz3.ru
MONEY-VISUALUK.CC - Email: hn@bz3.ru
MONEYVISUAL-LLC.CO - Email: yam@free-id.ru
MARFYGROUP.CC - Email: thorny@cheapbox.ru
MICHAELESGROUP-USA.CO - Email: knelt@ca4.ru
OLIVER-SONSINC.CC - Email: drub@cheapbox.ru
ONLINE-SOLUTIONSLLC.CC - Email: coma@ca4.ru
PEGASLTDUNION.cc - Email: prim@bz3.ru
PHYSIS-GROUPLLC.CC - Email: tt@ca4.ru
PHYSISGROUP-LLC.CO - Email: opals@free-id.ru
PINFOLD-GROUPINC.CO - Email: beams@free-id.ru
RADIUM-GROUP.CC - Email: spy@yourisp.ru
RADIUMUK-LTD.CC - Email: socks@cheapbox.ru
REDISCO-GROUPINC.HK - Email: wimp@ca4.ru
SANTORINI-FIN.CC - Email: gill@cheapbox.ru
SANTORINI-FINANCE.CO - Email: foul@yourisp.ru
SCHNELLER-GROUPINC.CO - Email: foul@yourisp.ru
SCHWARTZ-BROTHERS.cc - Email: oozed@bz3.ru
SILVERSUNGROUP-INC.CC - Email: cp@ca4.ru
SILVERSUN-GROUPUK.CO - Email: cheer@ca4.ru
SOLUTIONSLTD.CC - Email: h2o@ca4.ru
STILE-GROUPLLC.CC - Email: ma@free-id.ru
SUNRISEPR-GROUPLTD.CC - Email: cough@ppmail.ru
TECHADVINC.CC - Email: chance@cheapbox.ru
TECHADV-INC.CC - Email: chance@cheapbox.ru
TECHOUSE-GROUP.CC - Email: scale@yourisp.ru
UKTECH-GROUPLLC.CC - Email: cap@ca4.ru
USGROUP-AMINA.CO - Email: cap@ca4.ru
USGROUP-REIGN.CO - Email: w@ppmail.ru
YESGROUP-LLC.CO - Email: twig@ppmail.ru

Name servers of notice:
NS1.LIBUNITAU.CC - 178.162.152.76 (AS28753) - Email: ached@yourisp.ru
NS1.NNSQUE.CC - Email: amok@cheapbox.ru
NS1.OLIVAU.CC - Email: bop@cheapbox.ru
NS1.PAGEREDNS.CC - 178.162.152.77 (AS28753) - Email: freer@free-id.ru
NS1.SURPLUSUSA.CC - 209.159.156.162 (AS19318) - Email: skulk@ppmail.ru
NS1.TVSILVAU.CC - Email: fact@ppmail.ru
NS1.UKNSSPACE.CC - 69.10.44.190 (AS19318) - Email: gravy@ca4.ru
ns1.uksource.cc - 69.10.44.189 (AS19318) - Email: liver@cheapbox.ru
NS1.USABONDS.CC - Email: bart@cheapbox.ru
NS2.AUSTDEC.CC - 66.199.236.114 (AS15149) - Email: bold@yourisp.ru
NS2.COUKSNS.CC - 122.70.148.179 (AS55462) - Email: preen@ppmail.ru
ns2.gbtrade.cc - 66.199.236.114 (AS15149) - Email: ct@yourisp.ru
NS2.OLIVAU.CC - Email: bop@cheapbox.ru
NS2.RINGTONS.CC - 66.199.236.115 (AS15149) - Email: aaron@cheapbox.ru
NS2.TVSILVAU.CC - Email: fact@ppmail.ru
NS2.USAFUNDS.CC - 76.73.47.28 (AS30058) - Email: tile@yourisp.ru
NS2.ZONENSUK.CC - 178.162.181.11 (AS28753) - Email: rooms@ppmail.ru
NS3.AUSTDEC.CC - 178.162.181.11 (AS28753) - Email: bold@yourisp.ru
NS3.FOLOWDNS.CC - 178.162.181.11 (AS28753) - Email: dyed@bz3.ru
NS3.SDNSAU.CC - Email: level@cheapbox.ru
NS3.SURPLUSUSA.CC - 69.50.192.97 (AS18866) - Email: skulk@ppmail.ru
NS3.TVSILVAU.CC - Email: fact@ppmail.ru
NS3.UKCCONS.CC - 178.162.181.11 (AS28753) - Email: ted@cheapbox.ru
NS3.UKDNS.CC - 66.199.236.116 (AS15149) - Email: append@free-id.ru
ns3.ukearnings.cc - 178.162.181.11 (AS28753) - Email: bf@free-id.ru

ASs of notice using standart ns1;ns2; ns3 structure:
AS28753 - NETDIRECT AS NETDIRECT Frankfurt, DE
AS19318 - NJIIX-1 NJIIX.net 110B Meadowlands Pkwy Secaucus, NJ 07094 +1.201.605.1425
AS28753 - NETDIRECT AS NETDIRECT Frankfurt, DE
AS15149 - EZZI-101-BGP EZZI

- Long term trends - "from mule inventory to transactions inventory"
With the localization and standardization/template-tization of the entire money mule recruitment process an every day's reality, quality assurance and diversification of the markets/market segments in order to increase the probability of successful social engineering attack, will start taking place. Moreover, the current template driven recruitment ecosystem will inevitably start taking advantage of basic concepts such as geolocation and content cloaking, in order to once again increase the probability for converting a web site visitor into a mule.

At an invite-only conference that I attended in September, 2010, someone from the audience asked me a rather interesting question. Does it really matter how many mules are recruited by a particular syndicate, and most importantly, can we talk about average number of days/weeks/hours by the time the mule gets busted, and can no longer offer his/her services?

In the long term, we're inevitably going to witness the migration from building inventories of mules to transaction-driven mule recruitment model where the capability-driven mentality surpasses the mule inventory building one. The number of possible transactions with success rates based on historical performance, combined with an infinite loop of recruitment is what will drive the entire mule recruitment ecosystem.

Related posts:
The DNS Infrastructure of the Money Mule Recruitment Ecosystem
Keeping Money Mule Recruiters on a Short Leash - Part Four
Money Mule Recruitment Campaign Serving Client-Side Exploits
Keeping Money Mule Recruiters on a Short Leash - Part Three
Money Mule Recruiters on Yahoo!'s Web Hosting
Dissecting an Ongoing Money Mule Recruitment Campaign
Keeping Money Mule Recruiters on a Short Leash - Part Two
Keeping Reshipping Mule Recruiters on a Short Leash
Keeping Money Mule Recruiters on a Short Leash
Standardizing the Money Mule Recruitment Process
Inside a Money Laundering Group's Spamming Operations
Money Mule Recruiters use ASProx's Fast Fluxing Services
Money Mules Syndicate Actively Recruiting Since 2002

This post has been reproduced from Dancho Danchev's blog. Continue reading →

Spamvertised "Your password has been stolen!" Malware Campaign Circulating

0
January 26, 2011
A currently ongoing spamvertised campaign, attempts to impersonate the most popular social networking site, Facebook.

Using a well proven "Your password has been stolen!" theme, the campaign entices the end user into downloading and executing the malware. Social engineering-driven campaigns targeting Facebook, remain among the popular malware campaign spreading techniques due to the ease of execution.

Subject: Facebook Support. Your password has been stolen! ID50888
Message: Good afternoon.

A Spam is sent from your FaceBook account.

Your password has been changed for safety. Information regarding your account and a new password is attached to the letter.Read this information thoroughly and change the password to complicated one. Please do not reply to this email, it's automatic mail notification! Thank you for your attention. Your Facebook!


Spamvertised filedname: Facebook_details_ID76803.zip (32,458 bytes)

Detecrion rate:
Facebook_details.exe - Trojan-Downloader:W32/Koobface.HV - 12/ 43 (27.9%)
MD5   : f0e7a8c264fe14562ca8ac98abb35840
SHA1  : f68d15e66590c69ac75c46a09ae495be8bbf231f
SHA256: 3ca757bfdecbee20ec10d5af770700041f4bc1b17ee3123f4d85acfd19e1bb74

Upon execution, the sample phones back to:
Phones back to:
interviewbuy.ru /forum/document.doc
interviewbuy.ru /forum/load.php?file=0
interviewbuy.ru /forum/load.php?file=1
interviewbuy.ru /forum/load.php?file=2
interviewbuy.ru /forum/load.php?file=3
interviewbuy.ru /forum/load.php?file=4
interviewbuy.ru /forum/load.php?file=5
interviewbuy.ru /forum/load.php?file=6
interviewbuy.ru /forum/load.php?file=7
interviewbuy.ru /forum/load.php?file=8
interviewbuy.ru /forum/load.php?file=9
interviewbuy.ru /forum/load.php?file=ftpgrabber
interviewbuy.ru /forum/load.php?file=pokergrabber


interviewbuy.ru - 91.204.48.96 (AS24965); 124.217.248.229 (AS45839) Email: servman1976@yandex.ru

ZeuS crimeware activity at AS24965 (SPOINT-AS S.Point LTD) as well as SpyEye malicious activity is also observed.

This post has been reproduced from Dancho Danchev's blog. Continue reading →

Summarizing 3 Years of Research Into Cyber Jihad

0
September 11, 2010

From the "been there, actively researched that" department.
  1. Tracking Down Internet Terrorist Propaganda
  2. Arabic Extremist Group Forum Messages' Characteristics
  3. Cyber Terrorism Communications and Propaganda
  4. A Cost-Benefit Analysis of Cyber Terrorism
  5. Current State of Internet Jihad
  6. Analysis of the Technical Mujahid - Issue One
  7. Full List of Hezbollah's Internet Sites
  8. Steganography and Cyber Terrorism Communications
  9. Hezbollah's DNS Service Providers from 1998 to 2006
  10. Mujahideen Secrets Encryption Tool
  11. Analyses of Cyber Jihadist Forums and Blogs
  12. Cyber Traps for Wannabe Jihadists
  13. Inshallahshaheed - Come Out, Come Out Wherever You Are
  14. GIMF Switching Blogs
  15. GIMF Now Permanently Shut Down
  16. GIMF - "We Will Remain"
  17. Wisdom of the Anti Cyber Jihadist Crowd
  18. Cyber Jihadist Blogs Switching Locations Again
  19. Electronic Jihad v3.0 - What Cyber Jihad Isn't
  20. Electronic Jihad's Targets List
  21. Teaching Cyber Jihadists How to Hack
  22. A Botnet of Infected Terrorists?
  23. Infecting Terrorist Suspects with Malware
  24. The Dark Web and Cyber Jihad
  25. Cyber Jihadist Hacking Teams
  26. Two Cyber Jihadist Blogs Now Offline
  27. Characteristics of Islamist Websites
  28. Cyber Traps for Wannabe Jihadists
  29. Mujahideen Secrets Encryption Tool
  30. An Analysis of the Technical Mujahid - Issue Two
  31. Terrorist Groups' Brand Identities
  32. A List of Terrorists' Blogs
  33. Jihadists' Anonymous Internet Surfing Preferences
  34. Sampling Jihadists' IPs
  35. Cyber Jihadists' and TOR
  36. A Cyber Jihadist DoS Tool
  37. GIMF Now Permanently Shut Down
  38. Mujahideen Secrets 2 Encryption Tool Released
  39. Terror on the Internet - Conflict of Interest
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter. Continue reading →

Historical OSINT: Celebrities Death, Fedex Invoices, Office-Themed Malware Campaigns

0
September 08, 2010
As promised, this would be a pretty short historical OSINT post -- catching up is in progress -- detailing the structure of several campaigns that took place throughout July-August, 2010, and (as always) try to emphasize on the connection with historical malware campaigns profiled on my personal blog.

Campaigns of notice include: spamvertised "Celebrities death-themed emails", "Fedex shipment status themed invoices", and "Office-themed documents".

Sample subjects:
Angelina Jolie died; Gwen Stefani died; Oprah Winfrey died; Tom Cruise died; Application; Thursday Journal Club; End Of Rotation; Abstracts; Project Declaration; Residency Happy Hour: SOP_POLICIES; Fwd: Updated Journal Club Handout

Sample attachments:
journal club articles.zip; Rotation Input Sheet.zip; ppi and c dif.zip; MSpeck.zip; ResidencyPrep.zip; speck Case presentation draft.zip; journal club template.zip

Detection rates, phone back URLs, and connections with previously profiled campaigns:
- news.exe - Trojan.Bredolab-993 - 40/ 43 (93.0%)
MD5: 44522def7cf2a42aa26f59c2ac4ced58
SHA1: 2f60531b6e33d842eba505f3c3cb81a3ff6e3e6a

- journal club articles.exe - Backdoor/Bredolab.edb - 41/ 43 (95.3%)
MD5: 72e90fd1264e731109d1b6b977b2c744
SHA1: 0a36b882d1b4d8b42cc466ec286e95bbb2e77d49

Upon execution, the samples phone back to:
188.65.74.161 /mrmun_sgjlgdsjrthrtwg.exe - AS42473 - DOWN
194.28.112.3 /outlook.exe - AS48691 - ACTIVE

- outlook.exe - TrojanSpy:Win32/Fitmu.A - 17/ 43 (39.5%)
MD5: 8f4eca49b87e36daae14b8549071dece
SHA1: 1d390e9f8d6e744ead58dd6c424581419f732498

Upon execution, the dropped sample phones back to:
cuscuss.com - 188.65.74.164 - Email: info@blackry.com


Responding to 188.65.74.164 at AS42473 are also:
wiggete.com - Email: info@blackry.com
depenam.com - Email: info@blackry.com
fishum.com - Email: info@blackry.com
blackry.com - Email: info@blackry.com

Two of the domains are know to have been serving client-side exploits, but the redirection is currently returning an error "Connect to 188.40.232.254 on port 80 ... failed".

- depenam .com/count22.php
- blackry .com/count21.php
    - vseohuenno .com/trans/b3/ - 188.40.232.254 - Email: latertrans@gmail.com

Responding to 188.40.232.254, AS24940 are also the following command and control, client-side exploit serving domains:
gurgamer.com - (New IP: 86.155.172.30) Email: latertrans@gmail.com
moneybeerers.com - Email: latertrans@gmail.com
daeshnew.com - (New IP: 86.145.158.90) Email: latertrans@gmail.com
volosatyhren.com - Email: latertrans@gmail.com
vyebyvglaz.com - Email: latertrans@gmail.com
---------------------------------------------------------------------------------

- FedexInvoice_EE776129.exe - Win32/Oficla.LK - 41/ 43 (95.3%)
MD5: d4e2875127f5cbdf797de7f1417f96a7
SHA1: c2df8d8c178142ba7bee48dbf9a9f68c32a14f5e

Upon execution, the sample phones back to:
ilovelasvegas .ru/web/St/bb.php?v=200&id=636608811&b=24augNEW&tm= - 109.196.134.44, AS39150 - Email: vadim.rinatovich@yandex.ru with x5vsm5.ru - Email: vadim.rinatovich@yandex.ru also parked there.

Where do we know the vadim.rinatovich@yandex.ru email from? From two previously profiled campaigns "Spamvertised iTunes Gift Certificates and CV Themed Malware Campaigns"; and "Dissecting the Xerox WorkCentre Pro Scanned Document Themed Campaign" having a direct relationship with the Asprox botnet.

This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter. Continue reading →

Spamvertised Best Buy, Macy's, Evite and Target Themed Scareware/Exploits Serving Campaign

0
August 09, 2010

They are back again (Spamvertised Amazon "Verify Your Email", "Your Amazon Order" Malicious Emails; Dissecting the Xerox WorkCentre Pro Scanned Document Themed Campaign) for a fresh start of the week, with a currently ongoing spam campaign, serving scareware and client-side exploits, using a "Thank you for your payment"/"Thank you for your EXPRESS payment" themed subjects impersonating popular brands such as Best Buy, Macy's, Target and Evite.

Let's dissect the campaign, its structure, emphasize on the monetization strategy, and expose the complete portfolio of the domains involved in the campaign.

Sample email:
"Subject :Thank you for your payment Don’t miss a thing – Add support@e.macys.com to your email address book! Click here if you are unable to see images in this email.

1. Sign in on macys.com at https://www.macys.com/myinfo/index.ognc
2. Click on “My Account” – “My Profile” at https://www.macys.com/myinfo/profile/index.ognc
3. Uncheck the box Receive email notification when statements are available to view online and when payments are due.
4. Click on “Update Profile”
5. Expect the change to take place in 3 days
©2009 macys.com Inc., 685 Market Street, Suite 800, San Francisco, CA 94105. All rights reserved.
"

Compared to previous campaigns, the directory structure (fast fluxed :8080/index.php?pid=10; maliciousurl.ru /QWERTY.js; maliciousurl.ru /ODBC.js; LAN.js; Access.js; End_User.js etc.) of this one remains virtually the same, depending, of course, on the angle you choose for dissecting it.


Sample campaign structure:
- musicsgeneva.com /x.html - "PLEASE WAITING 4 SECOND..."
- opus22.org /x.html - "PLEASE WAITING 4 SECOND..."
- shamelessfreegift.com /x.html - "PLEASE WAITING 4 SECOND..."
- physicianschoiceonline.com /x.htm - "PLEASE WAITING 4 SECOND..."
    - baymediagroup .com:8080/index.php?pid=10 - client-side exploits - 188.165.95.133; 188.165.192.106; 91.121.108.61; 94.23.60.106; 178.32.5.233 - Email: fb@bigmailbox.ru
        - hoopdotami.cz .cc/scanner5/?afid=24 - 188.72.192.229 - scareware monetization

- Detection rate:
antivirus_24.exe - Trojan.Win32.FraudPack.berq - Result: 16/42 (38.1%)
File size: 166912 bytes
MD5...: b3cd297c654d3be52ffeb5f6a5ff13b4
SHA1..: bae889dd8ac7b22ec5f5649d6e0c073c8e2119d5

Upon execution, the sample phones back to:
httpsstarss.in /httpss/v=40&step=2&hostid= - 188.72.226.154 - Email: stevieksbaiz@hotmail.com
httpstatsconfig.com /getfile.php?r= - 204.12.226.173 - Email: httpstatsconfig.com@evoprivacy.com


Responding to 204.12.226.173 are also:
ns1.desktopsecurity2010ltd.com - Email: sixtakidlt2@hotmail.com
ns2.desktopsecurity2010ltd.com
www.desktopsecurity2010ltd.com
httpstatsconfig.com
ns1.httpstatsconfig.com
ns2.httpstatsconfig.com
desktopsecuritycorp.com
ns1.desktopsecuritycorp.com
ns2.desktopsecuritycorp.com


Domains using the same name server, ns1.freedomen.info - 209.85.99.32 - Email: mail@vetaxa.com
adsonlineinc.com - 66.96.239.86
picmonde.com - 94.228.220.93
bonblogger.com - 94.228.220.93
h2fastpornpics.com - 94.228.220.93
celebsfinectpics.com - 94.228.209.133 - Email: temp.for.loan@gmail.com
celebsfreeimages.com - 94.228.209.134 - Email: hannigey233@hotmail.com
picindividuals.com - 94.228.220.93
picbloggerprojet.com - 94.228.220.93
httpsstarss.in
hippocounter.info - 96.9.177.21
genesisbeta.net - 94.228.220.94


Name servers of notice:
ns1.getyourdns.com - 194.79.88.121
ns2.getyourdns.com - 77.68.52.52
ns3.getyourdns.com - 87.98.149.171
ns4.getyourdns.com - 66.185.162.248
ns1.instantdnsserver.com - 194.79.88.121 - Email: depot@infotorrent.ru
ns2.instantdnsserver.com - 77.68.52.52
ns3.instantdnsserver.com - 87.98.149.171
ns4.instantdnsserver.com - 66.185.162.248

Client-side exploits serving domains part of the campaign:
aquaticwrap.ru - Email: vibes@freenetbox.ru
aroundpiano.ru - Email: vibes@freenetbox.ru
baybear.ru - Email: vibes@freenetbox.ru
baymediagroup.com - Email: fb@bigmailbox.ru
bayjail.ru - Email: bushy@bigmailbox.ru
betaguy.ru - Email: vibes@freenetbox.ru
blockoctopus.ru - Email: semi@freenetbox.ru
budgetdude.ru - Email: totem@freenetbox.ru
chaoticice.ru - Email: vibes@freenetbox.ru
clannut.ru - Email: totem@freenetbox.ru
clockledge.ru - Email: totem@freenetbox.ru
coldboy.ru - Email: totem@freenetbox.ru
countryme.ru - Email: totem@freenetbox.ru
dayemail.ru - Email: totem@freenetbox.ru
diseasednoodle.ru - Email: vibes@freenetbox.ru
discountprowatch.com - Email: bike@fastermail.ru
dyehill.ru - Email: angles@fastermail.ru
easychurch.ru - Email: vibes@freenetbox.ru
economypoet.ru - Email: semi@freenetbox.ru
envirodollars.ru - Email: vibes@freenetbox.ru
forhomessale.ru - Email: dull@freemailbox.ru
galacticstall.ru - Email: vibes@freenetbox.ru
getyourdns.com - Email: fb@bigmailbox.ru
hairyartist.ru - Email: vibes@freenetbox.ru
lonelyzero.ru - Email: vibes@freenetbox.ru
lovingmug.ru - Email: vibes@freenetbox.ru
lowermatch.ru - Email: vibes@freenetbox.ru
luckyfan.ru - Email: vibes@freenetbox.ru
malepad.ru - Email: semi@freenetbox.ru
matchsearch.ru - Email: semi@freenetbox.ru
microlightning.ru - Email: vibes@freenetbox.ru
mindbat.ru - Email: semi@freenetbox.ru
mealpoets.ru - Email: totem@freenetbox.ru
nutcountry.ru - Email: dying@qx8.ru
obscurewax.ru - Email: vibes@freenetbox.ru
oceanobject.ru - Email: semi@freenetbox.ru
parkperson.ru - Email: semi@freenetbox.ru
penarea.ru - Email: dying@qx8.ru
ponybug.ru - Email: dying@qx8.ru
pocketbloke.ru - Email: angles@fastermail.ru
programability.ru - Email: dying@qx8.ru
rancideye.ru - Email: vibes@freenetbox.ru
rawscent.ru - Email: vibes@freenetbox.ru
recordsquare.ru - Email: totem@freenetbox.ru
rescuedtoilet.ru - Email: vibes@freenetbox.ru
riotassistance.ru - Email: angles@fastermail.ru
scarletpole.ru - Email: vibes@freenetbox.ru
secondgain.ru - Email: vibes@freenetbox.ru
shortrib.ru - Email: vibes@freenetbox.ru
slaveperfume.ru - Email: totem@freenetbox.ru
sodacells.ru - Email: dying@qx8.ru
smelldrip.ru - Email: totem@freenetbox.ru
starvingarctic.ru - Email: vibes@freenetbox.ru
stagepause.ru - Email: totem@freenetbox.ru
sweatymilk.ru - Email: vibes@freenetbox.ru
tartonion.ru - Email: vibes@freenetbox.ru
tunemug.ru - Email: tips@freenetbox.ru
wearyratio.ru - Email: vibes@freenetbox.ru
yummyeyes.ru - Email: vibes@freenetbox.ru

UPDATED: Thursday, August 12, 2010: Historical OSINT for client-side exploit serving domains part of Gumblar's campaigns for April/May 2010 using hostdnssite.com (Email: cop@qx8.ru) name server:
bestdarkman.info - Email: wwww@qx8.ru
bestwebclub.info - Email: asleep@5mx.ru
buyfootjoy.info - Email: mellow@5mx.ru
carswebnet.info - Email: mynah@freenetbox.ru
cityrealtimes.info - Email: asleep@5mx.ru
clandarkguide.info - Email: mellow@5mx.ru
clandarksky.info - Email: wwww@qx8.ru
darkangelcam.info - Email: mellow@5mx.ru
darkbluecoast.info - Email: wwww@qx8.ru
darksidenetwork.info - Email: mellow@5mx.ru
digitaljoyworld.info - Email: mellow@5mx.ru
eroomsite.info - Email: feint@qx8.ru
esunsite.info - Email: wwww@qx8.ru
extrafreeweb.info - Email: mynah@freenetbox.ru
feedandstream.info - Email: mynah@freenetbox.ru
gloomyblack.info - Email: wwww@qx8.ru
homesweetrv.info - Email: mynah@freenetbox.ru
indiawebnet.info - Email: mynah@freenetbox.ru
joylifein.info - Email: mellow@5mx.ru
joysportsworld.info - Email: mellow@5mx.ru
justroomate.info - Email: feint@qx8.ru
kenjoyworld.info - Email: mellow@5mx.ru
learnwebguide.info - Email: mynah@freenetbox.ru
luxurygenuine.info - Email: asleep@5mx.ru
myfeedsite.info - Email: feint@qx8.ru
newsuntour.info - Email: wwww@qx8.ru
oneroomhome.info - Email: feint@qx8.ru
realshoponline.info - Email: asleep@5mx.ru
redsunpark.info - Email: feint@qx8.ru
roomstoretexas.info - Email: feint@qx8.ru
suncoastatlas.info - Email: feint@qx8.ru
sunstarvideo.info - Email: feint@qx8.ru
supersunbeds.info - Email: feint@qx8.ru
superwebworld.info - Email: asleep@5mx.ru
sweetpeapots.info - Email: mynah@freenetbox.ru
sweetteenzone.info - Email: mynah@freenetbox.ru
thedarkwaters.info - Email: wwww@qx8.ru
thejoydiet.info - Email: mellow@5mx.ru
therealclamp.info - Email: drum@maillife.ru
thesunchaser.info - Email: wwww@qx8.ru
thesweetchild.info - Email: mynah@freenetbox.ru
theultimateweb.info - Email: asleep@5mx.ru
theyellowsun.info - Email: feint@qx8.ru
webguidetv.info - Email: asleep@5mx.ru
webnetenglish.info - Email: mynah@freenetbox.ru
yourprintroom.info - Email: feint@qx8.ru
yoursweetteen.info - Email: mynah@freenetbox.ru 
 

UPDATED: Friday, August 13, 2010:
The use of Yahoo Groups is still ongoing. Sample URL: groups.yahoo .com/group/nfldcsyi/message which includes a link to perfectpillcool .com:8080.

The campaign is ongoing, updates will be posted as soon as new developments emerge.

This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter. Continue reading →