Thursday, January 09, 2014
Dissecting the Ongoing Febipos/Carfekab Rogue Chrome/Firefox Extensions Dropping, Facebook Circulating Malicious Campaign
This summary is not available. Please
click here to view the post.
Tuesday, January 07, 2014
Fake Adobe Flash Player Serving Campaign Utilizes Google Hosting/Redirection Infrastructure, Spreads Across Facebook
What "better" time to spread malicious "joy", then during the Holidays? Cybercriminals are still busy maintaining a fake Adobe Flash Player serving, Facebook spreading campaign, which I originally intercepted during the Holidays, utilizing Google redirectors/hosting services. Despite the modest -- naturally conservative estimate -- click-through rate (45,000 clicks) compared to that of the most recently profiled similar Febipos spreading campaign, which resulted in over 1 million clicks, the campaign remains active, and continues tricking users into installing the rogue Adobe Flash Player, resulting in the continued spread of the campaign, on the Facebook Walls of socially engineered users.
Let's dissect the campaign, expose its infrastructure/command and control servers, and provide MD5s of the served malware.
Spamvertised Facebook URL+redirection chain: hxxp://goo.gl/QeshtO; hxxp://goo.gl/vVbrHp; hxxp://goo.gl/0oSJ7z; hxxp://goo.gl/38qIq8; hxxp://goo.gl/QNQhc5 -> hxxps://9dvme0lk2r0osqg3qb3rlk95z.storage.googleapis.com/q1fwum32gld35iab9d2u4o35bjsvhjhu309.html?ref=12 -> hxxp://goo.gl/wKXme1 -> hxxp://www.i-justice.org/g-o-27312-gooenn.html
(94.23.166.27) -> hxxp://f3c47a0d01f3ec343f57-2ba5bba9317af81ae21c42000295a455.r9.cf4.rackcdn.com/24471bmbqv07595?ref=27312&aff_sub=27312&sub_id=27312 -> hxxp://www.eklentidunyasi.com/dl.php (176.31.2.155) or hxxp://www.agentofex.com/dl.php (176.227.218.99; www.puee.in) ->
hxxp://docs.google.com/uc?export=download&id=0B6DFdqpSFDAlSmpsTkZkT2hvN28 or hxxps://doc-0g-4o-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/7fbm9gn67t8t18r8etd00juf0rvmrrmh/1387836000000/16300082901287672546/*/0BzU3dARQGry0TlMxN3F2STN0Z3M
GA Account ID: UA-36486228-1
Detection rate for the served malware: MD5: 30118bec581f80de46445aef79e6cf10 - detected by 33 out of 48 antivirus scanners as Trojan-Ransom.Win32.Blocker.dbud.
Once executed, the sample phones back to:
hxxp://176.31.2.155/extFiles/control8.txt
hxxp://176.31.2.155/extFiles/NewFile0008.exe
hxxp://176.31.2.155/extFiles/version.txt
hxxp://176.31.2.155/extFiles/list.txt
hxxp://176.31.2.155/extFiles/list.txt
hxxp://176.31.2.155/extFiles/buflash.xpi
hxxp://176.31.2.155/extFiles/bune10.zip
hxxp://176.31.2.155/extFiles/private/sandbox_status.php
hxxp://176.31.2.155/extFiles/extFiles/yok.txt
The files were offline in time of processing of the sample.
Related MD5s for the same served fake Adobe Flash Player:
MD5: 61f5af5d0067ea8d10f0764ff3c82066
MD5: 80b9ef43183abdd5b22482bc1cea7b36
MD5: 2da7cb838234eebbca3115fcafd6f513
MD5: 40ae8d901102ee3951c241b394eb94e9
MD5: 30118bec581f80de46445aef79e6cf10
MD5: 2de9865032e997d59c03bfd8435f1ada
MD5: fce013bec7b3651c100b6887c0a12eee
Once executed, MD5: fce013bec7b3651c100b6887c0a12eee phones back to:
hxxp://176.227.218.99/extFiles/control17.txt
hxxp://176.227.218.99/extFiles/NewFile00017.exe
hxxp://46.163.100.240/NewFile00017.exe
hxxp://176.227.218.99/NewFile00017.exe
hxxp://176.227.218.99/extFiles/extFiles/version.txt
hxxp://176.227.218.99/extFiles/extFiles/list.txt
hxxp://176.227.218.99/extFiles/extFiles/buflash.xpi
hxxp://176.227.218.99/extFiles/extFiles/bune10.zip
Files remain offline in the time of processing of the sample.
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
Let's dissect the campaign, expose its infrastructure/command and control servers, and provide MD5s of the served malware.
Spamvertised Facebook URL+redirection chain: hxxp://goo.gl/QeshtO; hxxp://goo.gl/vVbrHp; hxxp://goo.gl/0oSJ7z; hxxp://goo.gl/38qIq8; hxxp://goo.gl/QNQhc5 -> hxxps://9dvme0lk2r0osqg3qb3rlk95z.storage.googleapis.com/q1fwum32gld35iab9d2u4o35bjsvhjhu309.html?ref=12 -> hxxp://goo.gl/wKXme1 -> hxxp://www.i-justice.org/g-o-27312-gooenn.html
(94.23.166.27) -> hxxp://f3c47a0d01f3ec343f57-2ba5bba9317af81ae21c42000295a455.r9.cf4.rackcdn.com/24471bmbqv07595?ref=27312&aff_sub=27312&sub_id=27312 -> hxxp://www.eklentidunyasi.com/dl.php (176.31.2.155) or hxxp://www.agentofex.com/dl.php (176.227.218.99; www.puee.in) ->
hxxp://docs.google.com/uc?export=download&id=0B6DFdqpSFDAlSmpsTkZkT2hvN28 or hxxps://doc-0g-4o-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/7fbm9gn67t8t18r8etd00juf0rvmrrmh/1387836000000/16300082901287672546/*/0BzU3dARQGry0TlMxN3F2STN0Z3M
GA Account ID: UA-36486228-1
Detection rate for the served malware: MD5: 30118bec581f80de46445aef79e6cf10 - detected by 33 out of 48 antivirus scanners as Trojan-Ransom.Win32.Blocker.dbud.
Once executed, the sample phones back to:
hxxp://176.31.2.155/extFiles/control8.txt
hxxp://176.31.2.155/extFiles/NewFile0008.exe
hxxp://176.31.2.155/extFiles/version.txt
hxxp://176.31.2.155/extFiles/list.txt
hxxp://176.31.2.155/extFiles/list.txt
hxxp://176.31.2.155/extFiles/buflash.xpi
hxxp://176.31.2.155/extFiles/bune10.zip
hxxp://176.31.2.155/extFiles/private/sandbox_status.php
hxxp://176.31.2.155/extFiles/extFiles/yok.txt
The files were offline in time of processing of the sample.
Related MD5s for the same served fake Adobe Flash Player:
MD5: 61f5af5d0067ea8d10f0764ff3c82066
MD5: 80b9ef43183abdd5b22482bc1cea7b36
MD5: 2da7cb838234eebbca3115fcafd6f513
MD5: 40ae8d901102ee3951c241b394eb94e9
MD5: 30118bec581f80de46445aef79e6cf10
MD5: 2de9865032e997d59c03bfd8435f1ada
MD5: fce013bec7b3651c100b6887c0a12eee
Once executed, MD5: fce013bec7b3651c100b6887c0a12eee phones back to:
hxxp://176.227.218.99/extFiles/control17.txt
hxxp://176.227.218.99/extFiles/NewFile00017.exe
hxxp://46.163.100.240/NewFile00017.exe
hxxp://176.227.218.99/NewFile00017.exe
hxxp://176.227.218.99/extFiles/extFiles/version.txt
hxxp://176.227.218.99/extFiles/extFiles/list.txt
hxxp://176.227.218.99/extFiles/extFiles/buflash.xpi
hxxp://176.227.218.99/extFiles/extFiles/bune10.zip
Files remain offline in the time of processing of the sample.
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
Fake Adobe Flash Player Serving Campaign Utilizes Google Hosting/Redirection Infrastructure, Spreads Across Facebook
What "better" time to spread malicious "joy", then during the Holidays? Cybercriminals are still busy maintaining a fake Adobe Flash Player serving, Facebook spreading campaign, which I originally intercepted during the Holidays, utilizing Google redirectors/hosting services. Despite the modest -- naturally conservative estimate -- click-through rate (45,000 clicks) compared to that of the most recently profiled similar Febipos spreading campaign, which resulted in over 1 million clicks, the campaign remains active, and continues tricking users into installing the rogue Adobe Flash Player, resulting in the continued spread of the campaign, on the Facebook Walls of socially engineered users.
Let's dissect the campaign, expose its infrastructure/command and control servers, and provide MD5s of the served malware.
Spamvertised Facebook URL+redirection chain: hxxp://goo.gl/QeshtO; hxxp://goo.gl/vVbrHp; hxxp://goo.gl/0oSJ7z; hxxp://goo.gl/38qIq8; hxxp://goo.gl/QNQhc5 -> hxxps://9dvme0lk2r0osqg3qb3rlk95z.storage.googleapis.com/q1fwum32gld35iab9d2u4o35bjsvhjhu309.html?ref=12 -> hxxp://goo.gl/wKXme1 -> hxxp://www.i-justice.org/g-o-27312-gooenn.html
(94.23.166.27) -> hxxp://f3c47a0d01f3ec343f57-2ba5bba9317af81ae21c42000295a455.r9.cf4.rackcdn.com/24471bmbqv07595?ref=27312&aff_sub=27312&sub_id=27312 -> hxxp://www.eklentidunyasi.com/dl.php (176.31.2.155) or hxxp://www.agentofex.com/dl.php (176.227.218.99; www.puee.in) ->
hxxp://docs.google.com/uc?export=download&id=0B6DFdqpSFDAlSmpsTkZkT2hvN28 or hxxps://doc-0g-4o-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/7fbm9gn67t8t18r8etd00juf0rvmrrmh/1387836000000/16300082901287672546/*/0BzU3dARQGry0TlMxN3F2STN0Z3M
GA Account ID: UA-36486228-1
Detection rate for the served malware: MD5: 30118bec581f80de46445aef79e6cf10 - detected by 33 out of 48 antivirus scanners as Trojan-Ransom.Win32.Blocker.dbud.
Once executed, the sample phones back to:
hxxp://176.31.2.155/extFiles/control8.txt
hxxp://176.31.2.155/extFiles/NewFile0008.exe
hxxp://176.31.2.155/extFiles/version.txt
hxxp://176.31.2.155/extFiles/list.txt
hxxp://176.31.2.155/extFiles/list.txt
hxxp://176.31.2.155/extFiles/buflash.xpi
hxxp://176.31.2.155/extFiles/bune10.zip
hxxp://176.31.2.155/extFiles/private/sandbox_status.php
hxxp://176.31.2.155/extFiles/extFiles/yok.txt
The files were offline in time of processing of the sample.
Related MD5s for the same served fake Adobe Flash Player:
MD5: 61f5af5d0067ea8d10f0764ff3c82066
MD5: 80b9ef43183abdd5b22482bc1cea7b36
MD5: 2da7cb838234eebbca3115fcafd6f513
MD5: 40ae8d901102ee3951c241b394eb94e9
MD5: 30118bec581f80de46445aef79e6cf10
MD5: 2de9865032e997d59c03bfd8435f1ada
MD5: fce013bec7b3651c100b6887c0a12eee
Once executed, MD5: fce013bec7b3651c100b6887c0a12eee phones back to:
hxxp://176.227.218.99/extFiles/control17.txt
hxxp://176.227.218.99/extFiles/NewFile00017.exe
hxxp://46.163.100.240/NewFile00017.exe
hxxp://176.227.218.99/NewFile00017.exe
hxxp://176.227.218.99/extFiles/extFiles/version.txt
hxxp://176.227.218.99/extFiles/extFiles/list.txt
hxxp://176.227.218.99/extFiles/extFiles/buflash.xpi
hxxp://176.227.218.99/extFiles/extFiles/bune10.zip
Files remain offline in the time of processing of the sample.
Let's dissect the campaign, expose its infrastructure/command and control servers, and provide MD5s of the served malware.
Spamvertised Facebook URL+redirection chain: hxxp://goo.gl/QeshtO; hxxp://goo.gl/vVbrHp; hxxp://goo.gl/0oSJ7z; hxxp://goo.gl/38qIq8; hxxp://goo.gl/QNQhc5 -> hxxps://9dvme0lk2r0osqg3qb3rlk95z.storage.googleapis.com/q1fwum32gld35iab9d2u4o35bjsvhjhu309.html?ref=12 -> hxxp://goo.gl/wKXme1 -> hxxp://www.i-justice.org/g-o-27312-gooenn.html
(94.23.166.27) -> hxxp://f3c47a0d01f3ec343f57-2ba5bba9317af81ae21c42000295a455.r9.cf4.rackcdn.com/24471bmbqv07595?ref=27312&aff_sub=27312&sub_id=27312 -> hxxp://www.eklentidunyasi.com/dl.php (176.31.2.155) or hxxp://www.agentofex.com/dl.php (176.227.218.99; www.puee.in) ->
hxxp://docs.google.com/uc?export=download&id=0B6DFdqpSFDAlSmpsTkZkT2hvN28 or hxxps://doc-0g-4o-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/7fbm9gn67t8t18r8etd00juf0rvmrrmh/1387836000000/16300082901287672546/*/0BzU3dARQGry0TlMxN3F2STN0Z3M
GA Account ID: UA-36486228-1
Detection rate for the served malware: MD5: 30118bec581f80de46445aef79e6cf10 - detected by 33 out of 48 antivirus scanners as Trojan-Ransom.Win32.Blocker.dbud.
Once executed, the sample phones back to:
hxxp://176.31.2.155/extFiles/control8.txt
hxxp://176.31.2.155/extFiles/NewFile0008.exe
hxxp://176.31.2.155/extFiles/version.txt
hxxp://176.31.2.155/extFiles/list.txt
hxxp://176.31.2.155/extFiles/list.txt
hxxp://176.31.2.155/extFiles/buflash.xpi
hxxp://176.31.2.155/extFiles/bune10.zip
hxxp://176.31.2.155/extFiles/private/sandbox_status.php
hxxp://176.31.2.155/extFiles/extFiles/yok.txt
The files were offline in time of processing of the sample.
Related MD5s for the same served fake Adobe Flash Player:
MD5: 61f5af5d0067ea8d10f0764ff3c82066
MD5: 80b9ef43183abdd5b22482bc1cea7b36
MD5: 2da7cb838234eebbca3115fcafd6f513
MD5: 40ae8d901102ee3951c241b394eb94e9
MD5: 30118bec581f80de46445aef79e6cf10
MD5: 2de9865032e997d59c03bfd8435f1ada
MD5: fce013bec7b3651c100b6887c0a12eee
Once executed, MD5: fce013bec7b3651c100b6887c0a12eee phones back to:
hxxp://176.227.218.99/extFiles/control17.txt
hxxp://176.227.218.99/extFiles/NewFile00017.exe
hxxp://46.163.100.240/NewFile00017.exe
hxxp://176.227.218.99/NewFile00017.exe
hxxp://176.227.218.99/extFiles/extFiles/version.txt
hxxp://176.227.218.99/extFiles/extFiles/list.txt
hxxp://176.227.218.99/extFiles/extFiles/buflash.xpi
hxxp://176.227.218.99/extFiles/extFiles/bune10.zip
Files remain offline in the time of processing of the sample.
Monday, January 06, 2014
Summarizing Webroot's Threat Blog Posts for December
The following is a brief summary of all of my posts at Webroot's Threat Blog for December, 2013. You can subscribe to Webroot's Threat Blog RSS Feed, or follow me on Twitter:
01. Cybercrime-friendly VPN service provider pitches itself as being ‘recommended by Edward Snowden’
02. Commercial Windows-based compromised Web shells management application spotted in the wild
03. Compromised legitimate Web sites expose users to malicious Java/Symbian/Android “Browser Updates”
04. Malicious multi-hop iframe campaign affects thousands of Web sites, leads to a cocktail of client-side exploits – part two
05. How cybercriminals efficiently violate YouTube, Facebook, Twitter, Instagram, SoundCloud and Google+’s ToS
06. Tumblr under fire from DIY CAPTCHA-solving, proxies-supporting automatic account registration tools
07. Newly launched ‘HTTP-based botnet setup as a service’ empowers novice cybercriminals with bulletproof hosting capabilities – part three
08. Cybercriminals offer fellow cybercriminals training in Operational Security (OPSEC)
09. Fake ‘WhatsApp Missed Voicemail’ themed emails lead to pharmaceutical scams
10. A peek inside the booming underground market for stealth Bitcoin/Litecoin mining tools
11. Cybercrime Trends 2013 – Year in Review
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
Wednesday, December 11, 2013
Continuing Facebook "Who's Viewed Your Profile" Campaign Affects Another 190k+ Users, Exposes Malicious Cybercrime Ecosystem
Last week, immediately after I published the initial analysis detailing a massive privacy-violating "Who's Viewed Your Profile" campaign, that was circulating across Facebook, the cybercriminals behind it, supposedly took it offline, with one of the main redirectors now pointing to 127.0.0.1.
Not surprisingly, the primary campaign has multiple sub-campaigns still in circulation, which based on the latest statistics -- embedded within the campaign on the same day they supposedly shut it down -- has already exposed another 190,000+ of the social network's users -- the original campaign appears to have been launched in 2011 having already exposed 800,000+ users -- to more rogue, privacy violating apps -- JS.Febipos, Mindspark Interactive Network's MyImageConverter and Trojan-Ransomer.CLE, in this particular case.
Let's dissect the still circulating campaign, expose the entire infrastructure supporting it, establish direct connections with it to related malicious campaigns, indicating that someone's either multi-tasking, or that their malicious/fraudulent activities share the same infrastructure, provide MD5s for the currently served privacy-violating apps, as well as list the actual -- currently live -- hosting locations.
Sample redirection chain:
hxxp://NXJXBMQ.tk/?12358289 - 93.170.52.21; 93.170.52.33 -> hxxp://p2r0f3rviewer9890.co.nf/?sdk222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
222222222222222222222222222222222222222222222222222222222222222222222222222ajsklfjasl
fkjasfklja -> hxxp://prostats.vf1.us - 192.157.201.42 -> hxxp://whoviewsfb.uni.me/ch/profile.html - 82.208.40.11
Redirection chain domain name reconnaissance:
NXJXBMQ.tk - 93.170.52.21; 93.170.52.33
p2r0f3rviewer9890.co.nf - 83.125.22.192
whoviewsfb.uni.me - 82.208.40.11
prostats.vf1.us - 192.157.201.42
wh0stalks.uni.me - 192.157.201.42
cracks4free.info - 192.157.201.42
Known to have responded to 93.170.52.21 are also the following fraudulent domains:
0.facebook.com.fpama.tk
001200133184123129811.tk
00wwebhost.tk
01203313441.tk
01prof86841.tk
029m821t9fs.4ieiii.tk
031601.tk
0333.tk
0571baidu.tk
05pr0f1le21200.tk
05pr0file214741.tk
060uty80w.tk
06emu.tk
0886.tk
0akleycityn.tk
0ao0grecu.tk
0fcf7.chantaljltaste.tk
0lod1lmt1.tk
0love.tk
The following malicious MD5s are also known to have phoned back to 93.170.52.21 in the past:
MD5: ee78fe57ad8dbac96b31f41f77eb5877
MD5: bed006372fc76ec261dc9b223b178438
MD5: 58f9cbec80d1dc3a5afbb7339d200e66
MD5: fd0c6b284f7700d59199c55fdcd5bd8a
MD5: 4bfeb3c882d816d37c3e6cbb749e44af
MD5: 97ec866ac26e961976e050591f49fec3
MD5: aba1720b1a6747de5d5345b5893ba2f5
MD5: de5e1f6f137ecb903a018976fc04e110
MD5: a9669b65cabd6b25a32352ccf6c6c09a
MD5: 003f4d9dafba9ee6e358b97b8026e354
MD5: bab313e031b0c54d50fd82d221f7defc
MD5: e6b766f627b91fd420bd93fab4bc323f
MD5: d63656d9b051bf762203b0c4ac728231
MD5: 935440d970ee5a6640418574f4569dab
MD5: 2524e3b4ed3663f5650563c1e431b05c
MD5: f726646a41f95b12ec26cf01f1c89cf9
MD5: a5af6c04d28fcea476827437caf4c681
MD5: c7346327f86298fa5dad160366a0cf26
MD5: 912ed9ef063ae5b6b860fd34f3e8b83a
MD5: b33aaa98ad706ced23d7c64aed0fcad6
Known to have responded to 93.170.52.33 are also the following fraudulent domains:
0lwwa.tk
0msms.tk
122.72.0.7sierra-web-www.szjlc-pcb.tk
1z8dz.tk
4f1wz8.ga
777898.ga
888234.ml
8eld7.tk
abmomre.tk
accountupdateinformation.tk
ahram-org-eg.tk
alex-fotos.tk
allycam.tk
amerdz.ml
angelsmov.tk
apis-drives-google.tk
apis-googledrive.tk
apple-idss.tk
appleid.apple.com.cgi-bin.myappleid.woa.apple-idss.tk
avtoshina.tk
The following malicious MD5s are also known to have phoned back to 93.170.52.33 in the past:
MD5: 2d951e649a8bbcbfa468f7916e188f9f
MD5: dbe2c0788e74916eba251194ef783452
MD5: 4bfeb3c882d816d37c3e6cbb749e44af
MD5: dc01c1db51e26b585678701a64c94437
MD5: 61cc3de4e9a9865e0d239759ed3c7d5a
MD5: 64505b7ca1ce3c1c0c4892abe8d86321
MD5: 0b98356395b2463ea0f339572b9c95ef
MD5: 9e87c189d3cbf2fc2414934bef6e661b
MD5: 48964a66bdc81b48f2fe7a31088c041b
MD5: f81c85bea0e2251655b7112b352f302e
The following MD5s are also known to have phoned back to 83.125.22.192 in the past:
MD5: 3935b6efa7e5ee995f410f4ef1e613ab
MD5: 64c1496e1ba2b7cb5c54a33c20be3e95
MD5: 08f76a1ed5996d7dfdcf8226fe3f66b9
MD5: f508d8034223c4ce233f1bdbed265a3a
Known to have responded to 82.208.40.11 are the following fraudulent domains:
000e0062fb44cd5b277591349e070277.cz.cc
003bc1b16c548efbc4f30790e0bc17be.cz.cc
0057ab88a8febe310f94107137731424.cz.cc
008447a58c242b52cb69fe7dceea9a0b.cz.cc
00a47e5e57323f23c66f2c2d5bc1debc.cz.cc
00a9a591d1e7aaf65639781bc73199d4.cz.cc
00ad3353e0ba865a521da380ba4e0cc4.cz.cc
00d55beb792962f7a04c66b85f2c6082.cz.cc
00e3b9ece447187da3f43f98ab619a28.cz.cc
00eb52dbc4331a64e4fd96fdca890d9c.cz.cc
00f59cfa33cd097e943a38a8f2e343ee.cz.cc
00fbdb49398f0e5fd9d5572044d8934e.cz.cc
010ab81241856dfca44dd9ade4489fbc.cz.cc
011622fb7752328ebb60bd2c075f1fe6.cz.cc
011fbf88cff1c18e05c2afb53d6e5ffd.cz.cc
0133147433aeef23bbe60df0cbc4eac9.cz.cc
013f98b7157ae3754d463e9d2346a549.cz.cc
013fa3e9db6e476282b8e9f1bac6d68e.cz.cc
017c2bd33744c2d423a2a7598a0c0a4e.cz.cc
019368b1f3b364c0d3ec412680638f04.cz.cc
The following malicious MD5s are also known to have phoned back to 82.208.40.11 in the past:
MD5: 2c89dfc1706b31ba7de1c14e229279e5
MD5: 6719d3e8606d91734cde25b8dfc4156f
MD5: 61dcea6fbf15b68be831bff8c5eb0c1d
MD5: 3875fa91f060d02bddd43ff8e0046588
MD5: 929b72813bae47f78125ec30c58f3165
MD5: 96fa2ea6db2e4e9f00605032723e1777
MD5: c46968386138739c81e219da6fb3ead5
MD5: 3d627e0dbc5ac51761fa7cc7b202ec49
MD5: d9714a0f7f881d3643125aa0461a30be
MD5: 81171015a95073748994e463142ddcc7
Known to have responded to 192.157.201.42 are also the following fraudulent domains:
cracks4free.info
pr0lotra.p9.org
prostats.vf1.us
wh0prof.uni.me
cracks4free.info
Time to provide the actual, currently live, hosting locations for the served privacy-violating content.
Mindspark Interactive Network's MyImageConverter served URL:
hxxp://download.myimageconverter.com/index.jhtml?partner=^AZ0^xdm081
Google Store served URLs:
hxxps://chrome.google.com/webstore/detail/miapmjacmjonmofofflhnbafpbmfapac - currently active
hxxps://chrome.google.com/webstore/detail/dllaajjfgpigkeblmlbamflggfjkgbej
Dropbox Accounts serving the Android app (offline due to heavy usage), and the Firefox extension:
hxxps://dl.dropboxusercontent.com/s/rueyn3owrrpsbw4/whoviews5.xpi - currently online
hxxps://dl.dropboxusercontent.com/s/so3vm50w298qkto/WhoViewsYourProfile.apk
Facebook App URL:
hxxp://apps.facebook.com/dislike___button/
Google Docs served privacy-violating apps:
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqVFljUDBnTjFHdVE&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqRXBMLWZ4cVZJV2s&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqOXlyNko0VFBOdnM&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqZm5yeUFudFhqclU&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqbWpfNW5FalJmRGM&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqS3V1ZkZBQjJGbjQ&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqX2xXbEJLbEY0Q3M&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqMU5RVkJSWURxME0&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqVFljUDBnTjFHdVE&export=download
GA Account IDs: UA-23441223-3; UA-12798017-1
MyImageConverter Affiliate Network ID: ^AZ0^xdm081
Detection rate for the served apps/extensions:
MD5: 30cf98d7dc97cae57f8d72487966d20b - detected by 19 out of 49 antivirus scanners as Trojan-Ransomer.CLE; Troj/Mdrop-FNZ
MD5: 88dd376527c18639d3f8bf23f77b480e - detected by 8 out of 49 antivirus scanners as JS:Febipos-N [Trj]; JS/Febipos
Once executed, MD5: 30cf98d7dc97cae57f8d72487966d20b also drops MD5: 106320fc1282421f8f6cf5eb0206abee and MD5: 43b20dc1b437e0e3af5ae7b9965e0392 on the affected hosts. It then phones back to 195.167.11.4:
Two more MD5s from different malware campaigns, are known to have phoned back to 195.167.11.4:
MD5: 8192c574b8e96605438753c49510cd97
MD5: d55de5e9ec25a80ddfecfb34d417b098
The Privacy Policy (hxxp://prostats.vf1.us/firefox/pp.html) and the EULA (hxxp://prostats.vf1.us/firefox/eula.html) point to hxxp://dislikeIt.com - 176.74.176.179. Not surprisingly, multiple malicious MD5s are also known to have previously interacted with the same IP:
MD5: d366088e4823829798bd59a4d456a3df
MD5: 3c73db8202d084f33ab32069f40f58c8
MD5: d7fce1ec777c917f72530f79363fc6d3
MD5: 83568d744ab226a0642233b93bfc7de6
MD5: c84b1bd7c2063f34900bbc9712d66e0f
MD5: 58baa919900656dacaf39927bb614cf1
MD5: a86e97246a98206869be78fd451029a0
MD5: 70a0894397ac6f65c64693f1606f1231
MD5: f9166237199133b24cd866b61d0f6cca
MD5: 0f24ad046790ee863fd03d19dbba7ea5
Based on the latest performance metrics for the campaign, over 190,000 users have already interacted with this sub-campaign, since 4th of December, when I initially analyzed the primary campaign.
Monitoring of the campaign is naturally in progress. Updates will be posted as soon as new developments take place.
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
Continuing Facebook "Who's Viewed Your Profile" Campaign Affects Another 190k+ Users, Exposes Malicious Cybercrime Ecosystem
Last week, immediately after I published the initial analysis detailing a massive privacy-violating "Who's Viewed Your Profile" campaign, that was circulating across Facebook, the cybercriminals behind it, supposedly took it offline, with one of the main redirectors now pointing to 127.0.0.1.
Not surprisingly, the primary campaign has multiple sub-campaigns still in circulation, which based on the latest statistics -- embedded within the campaign on the same day they supposedly shut it down -- has already exposed another 190,000+ of the social network's users -- the original campaign appears to have been launched in 2011 having already exposed 800,000+ users -- to more rogue, privacy violating apps -- JS.Febipos, Mindspark Interactive Network's MyImageConverter and Trojan-Ransomer.CLE, in this particular case.
Let's dissect the still circulating campaign, expose the entire infrastructure supporting it, establish direct connections with it to related malicious campaigns, indicating that someone's either multi-tasking, or that their malicious/fraudulent activities share the same infrastructure, provide MD5s for the currently served privacy-violating apps, as well as list the actual -- currently live -- hosting locations.
hxxp://NXJXBMQ.tk/?12358289 - 93.170.52.21; 93.170.52.33 -> hxxp://p2r0f3rviewer9890.co.nf/?sdk222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
2222222222222222222222222222222222222222222222222222222222222222222222222222222222
222222222222222222222222222222222222222222222222222222222222222222222222222ajsklfjasl
fkjasfklja -> hxxp://prostats.vf1.us - 192.157.201.42 -> hxxp://whoviewsfb.uni.me/ch/profile.html - 82.208.40.11
Redirection chain domain name reconnaissance:
NXJXBMQ.tk - 93.170.52.21; 93.170.52.33
p2r0f3rviewer9890.co.nf - 83.125.22.192
whoviewsfb.uni.me - 82.208.40.11
prostats.vf1.us - 192.157.201.42
wh0stalks.uni.me - 192.157.201.42
cracks4free.info - 192.157.201.42
Known to have responded to 93.170.52.21 are also the following fraudulent domains:
0.facebook.com.fpama.tk
001200133184123129811.tk
00wwebhost.tk
01203313441.tk
01prof86841.tk
029m821t9fs.4ieiii.tk
031601.tk
0333.tk
0571baidu.tk
05pr0f1le21200.tk
05pr0file214741.tk
060uty80w.tk
06emu.tk
0886.tk
0akleycityn.tk
0ao0grecu.tk
0fcf7.chantaljltaste.tk
0lod1lmt1.tk
0love.tk
The following malicious MD5s are also known to have phoned back to 93.170.52.21 in the past:
MD5: ee78fe57ad8dbac96b31f41f77eb5877
MD5: bed006372fc76ec261dc9b223b178438
MD5: 58f9cbec80d1dc3a5afbb7339d200e66
MD5: fd0c6b284f7700d59199c55fdcd5bd8a
MD5: 4bfeb3c882d816d37c3e6cbb749e44af
MD5: 97ec866ac26e961976e050591f49fec3
MD5: aba1720b1a6747de5d5345b5893ba2f5
MD5: de5e1f6f137ecb903a018976fc04e110
MD5: a9669b65cabd6b25a32352ccf6c6c09a
MD5: 003f4d9dafba9ee6e358b97b8026e354
MD5: bab313e031b0c54d50fd82d221f7defc
MD5: e6b766f627b91fd420bd93fab4bc323f
MD5: d63656d9b051bf762203b0c4ac728231
MD5: 935440d970ee5a6640418574f4569dab
MD5: 2524e3b4ed3663f5650563c1e431b05c
MD5: f726646a41f95b12ec26cf01f1c89cf9
MD5: a5af6c04d28fcea476827437caf4c681
MD5: c7346327f86298fa5dad160366a0cf26
MD5: 912ed9ef063ae5b6b860fd34f3e8b83a
MD5: b33aaa98ad706ced23d7c64aed0fcad6
Known to have responded to 93.170.52.33 are also the following fraudulent domains:
0lwwa.tk
0msms.tk
122.72.0.7sierra-web-www.szjlc-pcb.tk
1z8dz.tk
4f1wz8.ga
777898.ga
888234.ml
8eld7.tk
abmomre.tk
accountupdateinformation.tk
ahram-org-eg.tk
alex-fotos.tk
allycam.tk
amerdz.ml
angelsmov.tk
apis-drives-google.tk
apis-googledrive.tk
apple-idss.tk
appleid.apple.com.cgi-bin.myappleid.woa.apple-idss.tk
avtoshina.tk
The following malicious MD5s are also known to have phoned back to 93.170.52.33 in the past:
MD5: 2d951e649a8bbcbfa468f7916e188f9f
MD5: dbe2c0788e74916eba251194ef783452
MD5: 4bfeb3c882d816d37c3e6cbb749e44af
MD5: dc01c1db51e26b585678701a64c94437
MD5: 61cc3de4e9a9865e0d239759ed3c7d5a
MD5: 64505b7ca1ce3c1c0c4892abe8d86321
MD5: 0b98356395b2463ea0f339572b9c95ef
MD5: 9e87c189d3cbf2fc2414934bef6e661b
MD5: 48964a66bdc81b48f2fe7a31088c041b
MD5: f81c85bea0e2251655b7112b352f302e
The following MD5s are also known to have phoned back to 83.125.22.192 in the past:
MD5: 3935b6efa7e5ee995f410f4ef1e613ab
MD5: 64c1496e1ba2b7cb5c54a33c20be3e95
MD5: 08f76a1ed5996d7dfdcf8226fe3f66b9
MD5: f508d8034223c4ce233f1bdbed265a3a
Known to have responded to 82.208.40.11 are the following fraudulent domains:
000e0062fb44cd5b277591349e070277.cz.cc
003bc1b16c548efbc4f30790e0bc17be.cz.cc
0057ab88a8febe310f94107137731424.cz.cc
008447a58c242b52cb69fe7dceea9a0b.cz.cc
00a47e5e57323f23c66f2c2d5bc1debc.cz.cc
00a9a591d1e7aaf65639781bc73199d4.cz.cc
00ad3353e0ba865a521da380ba4e0cc4.cz.cc
00d55beb792962f7a04c66b85f2c6082.cz.cc
00e3b9ece447187da3f43f98ab619a28.cz.cc
00eb52dbc4331a64e4fd96fdca890d9c.cz.cc
00f59cfa33cd097e943a38a8f2e343ee.cz.cc
00fbdb49398f0e5fd9d5572044d8934e.cz.cc
010ab81241856dfca44dd9ade4489fbc.cz.cc
011622fb7752328ebb60bd2c075f1fe6.cz.cc
011fbf88cff1c18e05c2afb53d6e5ffd.cz.cc
0133147433aeef23bbe60df0cbc4eac9.cz.cc
013f98b7157ae3754d463e9d2346a549.cz.cc
013fa3e9db6e476282b8e9f1bac6d68e.cz.cc
017c2bd33744c2d423a2a7598a0c0a4e.cz.cc
019368b1f3b364c0d3ec412680638f04.cz.cc
The following malicious MD5s are also known to have phoned back to 82.208.40.11 in the past:
MD5: 2c89dfc1706b31ba7de1c14e229279e5
MD5: 6719d3e8606d91734cde25b8dfc4156f
MD5: 61dcea6fbf15b68be831bff8c5eb0c1d
MD5: 3875fa91f060d02bddd43ff8e0046588
MD5: 929b72813bae47f78125ec30c58f3165
MD5: 96fa2ea6db2e4e9f00605032723e1777
MD5: c46968386138739c81e219da6fb3ead5
MD5: 3d627e0dbc5ac51761fa7cc7b202ec49
MD5: d9714a0f7f881d3643125aa0461a30be
MD5: 81171015a95073748994e463142ddcc7
Known to have responded to 192.157.201.42 are also the following fraudulent domains:
cracks4free.info
pr0lotra.p9.org
prostats.vf1.us
wh0prof.uni.me
cracks4free.info
Time to provide the actual, currently live, hosting locations for the served privacy-violating content.
Mindspark Interactive Network's MyImageConverter served URL:
hxxp://download.myimageconverter.com/index.jhtml?partner=^AZ0^xdm081
Google Store served URLs:
hxxps://chrome.google.com/webstore/detail/miapmjacmjonmofofflhnbafpbmfapac - currently active
hxxps://chrome.google.com/webstore/detail/dllaajjfgpigkeblmlbamflggfjkgbej
Dropbox Accounts serving the Android app (offline due to heavy usage), and the Firefox extension:
hxxps://dl.dropboxusercontent.com/s/rueyn3owrrpsbw4/whoviews5.xpi - currently online
hxxps://dl.dropboxusercontent.com/s/so3vm50w298qkto/WhoViewsYourProfile.apk
Facebook App URL:
hxxp://apps.facebook.com/dislike___button/
Google Docs served privacy-violating apps:
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqVFljUDBnTjFHdVE&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqRXBMLWZ4cVZJV2s&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqOXlyNko0VFBOdnM&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqZm5yeUFudFhqclU&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqbWpfNW5FalJmRGM&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqS3V1ZkZBQjJGbjQ&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqX2xXbEJLbEY0Q3M&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqMU5RVkJSWURxME0&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqVFljUDBnTjFHdVE&export=download
GA Account IDs: UA-23441223-3; UA-12798017-1
MyImageConverter Affiliate Network ID: ^AZ0^xdm081
Detection rate for the served apps/extensions:
MD5: 30cf98d7dc97cae57f8d72487966d20b - detected by 19 out of 49 antivirus scanners as Trojan-Ransomer.CLE; Troj/Mdrop-FNZ
MD5: 88dd376527c18639d3f8bf23f77b480e - detected by 8 out of 49 antivirus scanners as JS:Febipos-N [Trj]; JS/Febipos
Once executed, MD5: 30cf98d7dc97cae57f8d72487966d20b also drops MD5: 106320fc1282421f8f6cf5eb0206abee and MD5: 43b20dc1b437e0e3af5ae7b9965e0392 on the affected hosts. It then phones back to 195.167.11.4:
Two more MD5s from different malware campaigns, are known to have phoned back to 195.167.11.4:
MD5: 8192c574b8e96605438753c49510cd97
MD5: d55de5e9ec25a80ddfecfb34d417b098
The Privacy Policy (hxxp://prostats.vf1.us/firefox/pp.html) and the EULA (hxxp://prostats.vf1.us/firefox/eula.html) point to hxxp://dislikeIt.com - 176.74.176.179. Not surprisingly, multiple malicious MD5s are also known to have previously interacted with the same IP:
MD5: d366088e4823829798bd59a4d456a3df
MD5: 3c73db8202d084f33ab32069f40f58c8
MD5: d7fce1ec777c917f72530f79363fc6d3
MD5: 83568d744ab226a0642233b93bfc7de6
MD5: c84b1bd7c2063f34900bbc9712d66e0f
MD5: 58baa919900656dacaf39927bb614cf1
MD5: a86e97246a98206869be78fd451029a0
MD5: 70a0894397ac6f65c64693f1606f1231
MD5: f9166237199133b24cd866b61d0f6cca
MD5: 0f24ad046790ee863fd03d19dbba7ea5
Based on the latest performance metrics for the campaign, over 190,000 users have already interacted with this sub-campaign, since 4th of December, when I initially analyzed the primary campaign.
Monitoring of the campaign is naturally in progress. Updates will be posted as soon as new developments take place.
Wednesday, December 04, 2013
Facebook Circulating 'Who's Viewed Your Profile' Campaign Exposes 800k+ Users to CrossRider PUA/Rogue Firefox Add-ons/Android Adware AirPush
A massive privacy-violating, Facebook circulating "Who's Viewed Your Profile" campaign, has been operating beneath the radar, exposing over 800,000 users internationally, to a cocktail of PUAs (Potentially Unwanted Applications), rogue Firefox Add-ons impersonating Adobe's Flash Player, as well as the Android based adware AirPush.
Relying on a proven social engineering tactic of "offering what's not being offered in general", next to hosting the rogue files on legitimate service providers -- Google Docs and Dropbox in this particular case -- the campaign is a great example that the ubiquitous for the social network social engineering scheme, continues to trick gullible and uninformed users into installing privacy-violating applications on their hosts/mobile devices.
Let's dissect the campaign, expose its infrastructure, (conservatively) assess the damage, and provide fresh MD5s for the currently served privacy-violating PUAs, Firefox add-ons, and Android adware.
Primary spamvertised Facebook URL: FCOSYUC.tk/?15796422
Redirection chain: p2r0f3rviewer9890.co.nf -> bit.ly/1bZCeNv?vsdvc -> wh0prof.uni.me/?sdvsjka -> wh0prof.uni.me/ch/
Rogue Google Store Extension URL (currently offline): hxxps://chrome.google.com/webstore/detail/dllaajjfgpigkeblmlbamflggfjkgbej
Campaign's GA Account ID: UA-12798017-1
Domain name reconnaissance:
wh0prof.uni.me - 192.157.201.42
Known to have responded to the same IP are also the following domains:
cracks4free.info
pr0lotra.p9.org
Google Docs Hosted PUA URLs:
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqVFljUDBnTjFHdVE&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqRXBMLWZ4cVZJV2s&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqUjllLWc4MVFRQUk&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqOXlyNko0VFBOdnM&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqZm5yeUFudFhqclU&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqbWpfNW5FalJmRGM&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqS3V1ZkZBQjJGbjQ&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqX2xXbEJLbEY0Q3M&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqMU5RVkJSWURxME0&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqVFljUDBnTjFHdVE&export=download
Dropbox Firefox Add-on/Android APK Hosted URLs:
hxxps://dl.dropboxusercontent.com/s/so3vm50w298qkto/WhoViewsYourProfile.apk
hxxps://dl.dropboxusercontent.com/s/kor9c2mqv49esva/kkadobe-ff.xpi
Detection rate for the served PUAs, the Android adware and the rogue Firefox Add-on:
MD5: c7fcf7078597ea752b8d54e406c266a7 - detected by 5 out of 48 antivirus scanners as PUP.Optional.CrossRider
MD5: 30cf98d7dc97cae57f8d72487966d20b - detected by 6 out of 48 antivirus scanners as Trojan.Dropper.FB
MD5: f2459b6bde1d662399a3df725bf8891b - detected by 13 out of 48 antivirus scanners as Adware/AirPush!Android; Android Airpush; Adware/ANDR.Airpush.G.Gen
MD5: 3fb95e1ed77d1b545cf7385b4521b9ae - detected by 18 out of 48 antivirus scanners as JS/TrojanClicker.Agent.NDL
Once executed MD5: 30cf98d7dc97cae57f8d72487966d20b phones back to 195.167.11.4.
Time to (conservatively) assess the campaign's damage over the year(s):
The click-through rate should be considered conservative, and it remains unknown whether the URL shortening service was used by the cybercriminal(s) since day one of the campaign.
The campaign remains active, and is just the tip of the iceberg in terms of similar campaigns tricking Facebook's users into thinking that they can eventually see who's viewed their profile. Facebook users who stumble across such campaigns on their own, or their friends' Walls, are advised to consider reporting the campaign back to Facebook, immediately.
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
Relying on a proven social engineering tactic of "offering what's not being offered in general", next to hosting the rogue files on legitimate service providers -- Google Docs and Dropbox in this particular case -- the campaign is a great example that the ubiquitous for the social network social engineering scheme, continues to trick gullible and uninformed users into installing privacy-violating applications on their hosts/mobile devices.
Let's dissect the campaign, expose its infrastructure, (conservatively) assess the damage, and provide fresh MD5s for the currently served privacy-violating PUAs, Firefox add-ons, and Android adware.
Primary spamvertised Facebook URL: FCOSYUC.tk/?15796422
Redirection chain: p2r0f3rviewer9890.co.nf -> bit.ly/1bZCeNv?vsdvc -> wh0prof.uni.me/?sdvsjka -> wh0prof.uni.me/ch/
Rogue Google Store Extension URL (currently offline): hxxps://chrome.google.com/webstore/detail/dllaajjfgpigkeblmlbamflggfjkgbej
Campaign's GA Account ID: UA-12798017-1
Domain name reconnaissance:
wh0prof.uni.me - 192.157.201.42
Known to have responded to the same IP are also the following domains:
cracks4free.info
pr0lotra.p9.org
Google Docs Hosted PUA URLs:
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqVFljUDBnTjFHdVE&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqRXBMLWZ4cVZJV2s&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqUjllLWc4MVFRQUk&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqOXlyNko0VFBOdnM&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqZm5yeUFudFhqclU&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqbWpfNW5FalJmRGM&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqS3V1ZkZBQjJGbjQ&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqX2xXbEJLbEY0Q3M&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqMU5RVkJSWURxME0&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqVFljUDBnTjFHdVE&export=download
Dropbox Firefox Add-on/Android APK Hosted URLs:
hxxps://dl.dropboxusercontent.com/s/so3vm50w298qkto/WhoViewsYourProfile.apk
hxxps://dl.dropboxusercontent.com/s/kor9c2mqv49esva/kkadobe-ff.xpi
Detection rate for the served PUAs, the Android adware and the rogue Firefox Add-on:
MD5: c7fcf7078597ea752b8d54e406c266a7 - detected by 5 out of 48 antivirus scanners as PUP.Optional.CrossRider
MD5: 30cf98d7dc97cae57f8d72487966d20b - detected by 6 out of 48 antivirus scanners as Trojan.Dropper.FB
MD5: f2459b6bde1d662399a3df725bf8891b - detected by 13 out of 48 antivirus scanners as Adware/AirPush!Android; Android Airpush; Adware/ANDR.Airpush.G.Gen
MD5: 3fb95e1ed77d1b545cf7385b4521b9ae - detected by 18 out of 48 antivirus scanners as JS/TrojanClicker.Agent.NDL
Once executed MD5: 30cf98d7dc97cae57f8d72487966d20b phones back to 195.167.11.4.
Time to (conservatively) assess the campaign's damage over the year(s):
The click-through rate should be considered conservative, and it remains unknown whether the URL shortening service was used by the cybercriminal(s) since day one of the campaign.
The campaign remains active, and is just the tip of the iceberg in terms of similar campaigns tricking Facebook's users into thinking that they can eventually see who's viewed their profile. Facebook users who stumble across such campaigns on their own, or their friends' Walls, are advised to consider reporting the campaign back to Facebook, immediately.
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
Facebook Circulating 'Who's Viewed Your Profile' Campaign Exposes 800k+ Users to CrossRider PUA/Rogue Firefox Add-ons/Android Adware AirPush
A massive privacy-violating, Facebook circulating "Who's Viewed Your Profile" campaign, has been operating beneath the radar, exposing over 800,000 users internationally, to a cocktail of PUAs (Potentially Unwanted Applications), rogue Firefox Add-ons impersonating Adobe's Flash Player, as well as the Android based adware AirPush.
Relying on a proven social engineering tactic of "offering what's not being offered in general", next to hosting the rogue files on legitimate service providers -- Google Docs and Dropbox in this particular case -- the campaign is a great example that the ubiquitous for the social network social engineering scheme, continues to trick gullible and uninformed users into installing privacy-violating applications on their hosts/mobile devices.
Let's dissect the campaign, expose its infrastructure, (conservatively) assess the damage, and provide fresh MD5s for the currently served privacy-violating PUAs, Firefox add-ons, and Android adware.
Primary spamvertised Facebook URL: FCOSYUC.tk/?15796422
Redirection chain: p2r0f3rviewer9890.co.nf -> bit.ly/1bZCeNv?vsdvc -> wh0prof.uni.me/?sdvsjka -> wh0prof.uni.me/ch/
Rogue Google Store Extension URL (currently offline): hxxps://chrome.google.com/webstore/detail/dllaajjfgpigkeblmlbamflggfjkgbej
Campaign's GA Account ID: UA-12798017-1
wh0prof.uni.me - 192.157.201.42
Known to have responded to the same IP are also the following domains:
cracks4free.info
pr0lotra.p9.org
Google Docs Hosted PUA URLs:
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqVFljUDBnTjFHdVE&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqRXBMLWZ4cVZJV2s&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqUjllLWc4MVFRQUk&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqOXlyNko0VFBOdnM&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqZm5yeUFudFhqclU&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqbWpfNW5FalJmRGM&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqS3V1ZkZBQjJGbjQ&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqX2xXbEJLbEY0Q3M&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqMU5RVkJSWURxME0&export=download
hxxps://docs.google.com/uc?authuser=0&id=0BziH-mKCuQwqVFljUDBnTjFHdVE&export=download
Dropbox Firefox Add-on/Android APK Hosted URLs:
hxxps://dl.dropboxusercontent.com/s/so3vm50w298qkto/WhoViewsYourProfile.apk
hxxps://dl.dropboxusercontent.com/s/kor9c2mqv49esva/kkadobe-ff.xpi
Detection rate for the served PUAs, the Android adware and the rogue Firefox Add-on:
MD5: c7fcf7078597ea752b8d54e406c266a7 - detected by 5 out of 48 antivirus scanners as PUP.Optional.CrossRider
MD5: 30cf98d7dc97cae57f8d72487966d20b - detected by 6 out of 48 antivirus scanners as Trojan.Dropper.FB
MD5: f2459b6bde1d662399a3df725bf8891b - detected by 13 out of 48 antivirus scanners as Adware/AirPush!Android; Android Airpush; Adware/ANDR.Airpush.G.Gen
MD5: 3fb95e1ed77d1b545cf7385b4521b9ae - detected by 18 out of 48 antivirus scanners as JS/TrojanClicker.Agent.NDL
Once executed MD5: 30cf98d7dc97cae57f8d72487966d20b phones back to 195.167.11.4.
Time to (conservatively) assess the campaign's damage over the year(s):
The click-through rate should be considered conservative, and it remains unknown whether the URL shortening service was used by the cybercriminal(s) since day one of the campaign.
The campaign remains active, and is just the tip of the iceberg in terms of similar campaigns tricking Facebook's users into thinking that they can eventually see who's viewed their profile. Facebook users who stumble across such campaigns on their own, or their friends' Walls, are advised to consider reporting the campaign back to Facebook, immediately.
Tuesday, December 03, 2013
Summarizing Webroot's Threat Blog Posts for November
The following is a brief summary of all of my posts at Webroot's Threat Blog for November, 2013. You can subscribe to Webroot's Threat Blog RSS Feed, or follow me on Twitter:
01. Google-dorks based mass Web site hacking/SQL injecting tool helps facilitate malicious online activity
02. Deceptive ads lead to the SpyAlertApp PUA (Potentially Unwanted Application)
03. Cybercriminals differentiate their ‘access to compromised PCs’ service proposition, emphasize on the prevalence of ‘female bot slaves’
04. New vendor of ‘professional DDoS for hire service’ spotted in the wild
05. Source code for proprietary spam bot offered for sale, acts as force multiplier for cybercrime-friendly activity
06. Low Quality Assurance (QA) iframe campaign linked to May’s Indian government Web site compromise spotted in the wild
07. Popular French torrent portal tricks users into installing the BubbleDock/Downware/DownloadWare PUA (Potentially Unwanted Application)
08. Web site of Brazilian ‘Prefeitura Municipal de Jaqueira’ compromised, leads to fake Adobe Flash player
09. Malicious multi-hop iframe campaign affects thousands of Web sites, leads to a cocktail of client-side exploits
10. Vendor of TDoS products/services releases new multi-threaded SIP-based TDoS tool
11. Cybercriminals spamvertise tens of thousands of fake ‘Sent from my iPhone’ themed emails, expose users to malware
12. Fake ‘Annual Form (STD-261) – Authorization to Use Privately Owned Vehicle on State Business’ themed emails lead to malware
13. ‘Newly released proxy-supporting Origin brute-forcing tools targets users with weak passwords’
14. Fake WhatsApp ‘Voice Message Notification’ themed emails expose users to malware
15. Cybercriminals impersonate HSBC through fake ‘payment e-Advice’ themed emails, expose users to malware
16. Fake ‘MMS Gallery’ notifications impersonate T-Mobile U.K, expose users to malware
17. Fake ‘October’s Billing Address Code’ (BAC) form themed spam campaign leads to malware
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
Thursday, November 14, 2013
Fake Chrome/Firefox/Internet Explorer/Safari Updates Expose Users to Android Malware
A currently ongoing malicious campaign using compromised sites as the primary traffic acquisition tactic, is attempting to socially engineer users (English and Russian speaking) into thinking that they're using an outdated version of their browser, and need to apply a bogus (security/antivirus) update. In reality though, the update is a variant of Trojan:Android/Fakeinst.EQ/Android.SmsSend.
Sample screenshots of the fake browser update landing pages:
Social engineering redirection chain: hxxp://france-leasebacks.com/includes/domit/1.php -> hxxp://advertcliks.net/ir/28/1405/56e9ca1335c2773445a79d5ddf75a755/ (93.115.82.239; Email: maxaxaha@gmail.com) -> hxxp://newupdateronline.org (109.163.230.182; Email: vbistrih@yandex.com).
Known to have responded to 109.163.230.182 are also the following domains:
1mc8.asia
anglecultivatep.in
appallinglyndiscoveries.in
bilious-6biros.in
boathire.pw
cvwv87.pro
dlsdcncnew1.pw
efuv77.pro
familye-perspex.in
farting-meagre.in
flvupdate.in
fringeclamberedk.in
hopefully-great8.in
investment-growsa.asia
money-tree.pw
moon-media.pw
moontree.pw
mountainlake.pw
movingv-relation.in
new-updateronline.org
Sample Android samples pushed by the campaign:
MD5: da7fffa08bdeb945ca8237c2894aedd0 - detected by 11 out of 46 antivirus scanners as Android.SmsSend.809.origin; Android.Trojan.FakeInst.HE
MD5: 1e1f57f6c8c9fb39da8965275548174f - detected by 17 out of 46 antivirus scanners as HEUR:Trojan-SMS.AndroidOS.FakeInst.fe; Andr/RuSms-AL
MD5: b0f597636859b7f5b2c1574d7a8bbbbb - detected by 13 out of 47 antivirus scanners as HEUR:Trojan-SMS.AndroidOS.FakeInst.fe; Andr/RuSms-AL
MD5: b40aebc327e1bc6aabe5ccb4f18e8ea4 - detected by 16 out of 48 antivirus scanners as Android:FakeIns-AF; Trojan:Android/Fakeinst.EQ
All samples phone back to dlsdcncnew.net (109.163.230.182; Email: constantin.zawyalov@yandex.ru). Responding to the same IP is also newapk-flv.org.
The same email is also known to have been previously used to register the following domains:
downloader8days.in
open-filedownload4.in (known to have responded to 188.95.159.30)
upweight.in
bestnewbrowsers.in
bestowedcomedyb.org (known to have responded to 109.163.230.180)
expandload.in
2012internet-load.in
4interfilefolder.in
99030.in
admitted-6crept.org
rufileserver.in
It appears that the traffic is not segmented -- to affect mobile device users only -- at any point of the redirection chain, an indication of what I believe is a boutique cybercrime-friendly operation. In comparison, the relatively more sophisticated ones would segment the traffic, usually acquired through the active exploitation of tens of thousands of legitimate Web sites, or the direct purchase of segmented mobile traffic.
Interestingly, both novice players in this market segment, and the experienced ones, are implementing basic evasive tactics, such as, for instance, the need to provide a valid mobile number, where a potential victim will receive a confirmation code for accessing the inventory of rogue games and applications, thereby preventing automatic acquisition of the apps for further analysis. Moreover, providing a valid mobile number to the cybercriminals behind the campaign, is naturally prone to be abused in ways largely based on the preferences of those who obtained them through such a way, therefore users are advised not to treat their mobile number in a privacy conscious way.
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
Sample screenshots of the fake browser update landing pages:
Social engineering redirection chain: hxxp://france-leasebacks.com/includes/domit/1.php -> hxxp://advertcliks.net/ir/28/1405/56e9ca1335c2773445a79d5ddf75a755/ (93.115.82.239; Email: maxaxaha@gmail.com) -> hxxp://newupdateronline.org (109.163.230.182; Email: vbistrih@yandex.com).
Known to have responded to 109.163.230.182 are also the following domains:
1mc8.asia
anglecultivatep.in
appallinglyndiscoveries.in
bilious-6biros.in
boathire.pw
cvwv87.pro
dlsdcncnew1.pw
efuv77.pro
familye-perspex.in
farting-meagre.in
flvupdate.in
fringeclamberedk.in
hopefully-great8.in
investment-growsa.asia
money-tree.pw
moon-media.pw
moontree.pw
mountainlake.pw
movingv-relation.in
new-updateronline.org
Sample Android samples pushed by the campaign:
MD5: da7fffa08bdeb945ca8237c2894aedd0 - detected by 11 out of 46 antivirus scanners as Android.SmsSend.809.origin; Android.Trojan.FakeInst.HE
MD5: 1e1f57f6c8c9fb39da8965275548174f - detected by 17 out of 46 antivirus scanners as HEUR:Trojan-SMS.AndroidOS.FakeInst.fe; Andr/RuSms-AL
MD5: b0f597636859b7f5b2c1574d7a8bbbbb - detected by 13 out of 47 antivirus scanners as HEUR:Trojan-SMS.AndroidOS.FakeInst.fe; Andr/RuSms-AL
MD5: b40aebc327e1bc6aabe5ccb4f18e8ea4 - detected by 16 out of 48 antivirus scanners as Android:FakeIns-AF; Trojan:Android/Fakeinst.EQ
All samples phone back to dlsdcncnew.net (109.163.230.182; Email: constantin.zawyalov@yandex.ru). Responding to the same IP is also newapk-flv.org.
The same email is also known to have been previously used to register the following domains:
downloader8days.in
open-filedownload4.in (known to have responded to 188.95.159.30)
upweight.in
bestnewbrowsers.in
bestowedcomedyb.org (known to have responded to 109.163.230.180)
expandload.in
2012internet-load.in
4interfilefolder.in
99030.in
admitted-6crept.org
rufileserver.in
It appears that the traffic is not segmented -- to affect mobile device users only -- at any point of the redirection chain, an indication of what I believe is a boutique cybercrime-friendly operation. In comparison, the relatively more sophisticated ones would segment the traffic, usually acquired through the active exploitation of tens of thousands of legitimate Web sites, or the direct purchase of segmented mobile traffic.
Interestingly, both novice players in this market segment, and the experienced ones, are implementing basic evasive tactics, such as, for instance, the need to provide a valid mobile number, where a potential victim will receive a confirmation code for accessing the inventory of rogue games and applications, thereby preventing automatic acquisition of the apps for further analysis. Moreover, providing a valid mobile number to the cybercriminals behind the campaign, is naturally prone to be abused in ways largely based on the preferences of those who obtained them through such a way, therefore users are advised not to treat their mobile number in a privacy conscious way.
This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.
Subscribe to:
Posts (Atom)
Blog Archive
About Me
- Dancho Danchev
- Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com
Total Pageviews
Labels
- 29A (1)
- 29A Virus Coding Group (1)
- 419 Scam (4)
- AbdAllah (1)
- Abdallah Internet Hizmetleri (1)
- Able Danger (1)
- Abuse Department (1)
- Active Security Monitor (1)
- Advance Fee Scam (2)
- Advanced Persistent Threat (2)
- Advertising (3)
- Adware (3)
- Affiliate Network (7)
- Ahmad Al Agha (1)
- Al Qaeda (3)
- Aleksandr Zhukov (1)
- Allied Group Inc (1)
- Amazon AWS (1)
- ANA Spoofer Project (1)
- Android (2)
- Anonymity (31)
- Anonymizer (1)
- Anonymous (1)
- Anonymous Hacking Collective (1)
- Anti-Phishing Group (1)
- Antivirus (6)
- Antivirus Signatures (3)
- Anton Nikolaevich Korotchenko (1)
- AOL (2)
- API (1)
- Apple (1)
- APT (1)
- Aqua ZeuS Gang (1)
- Armadillo Phone (2)
- Ashiyane Digital Security Team (5)
- ASProx (2)
- Astalavista (7)
- Astalavista Security Group (1)
- Astalavista.box.sk (4)
- ATM Skimmer (1)
- ATS (1)
- Australia (1)
- Authentication (2)
- Avalance Botnet (2)
- Avast (1)
- Background Check (1)
- BadB (1)
- Bahama Botnet (1)
- BakaSoftware (1)
- Bantu (1)
- BBC (1)
- Bebo (1)
- Bed Time Reading (1)
- Behrooz Kamalian (2)
- Best Practices (2)
- BGP (1)
- Big Brother (3)
- Bill Gates Botnet (1)
- Biography (1)
- Biometrics (1)
- Bitcoin (1)
- Bjorn Andreasson (1)
- Black Energy (1)
- Blackhat SEO (27)
- Blood and Honor (1)
- Blood and Honor Bulgaria (1)
- Boeing (1)
- Bogus Account (1)
- bother (1)
- Botners (1)
- Botnet (160)
- Botnets (21)
- Box.sk (1)
- Brian Krebs (1)
- Brute-Forcing (1)
- Bulgaria (18)
- Bulgaria Law Enforcement (14)
- Bulgarian Cyber Army (1)
- Bulgarian Cyber Army Hacking Group (1)
- Bullet Proof Hosting (1)
- Bust (1)
- C4I (2)
- CALEA (1)
- Caller ID (1)
- Caller ID Spoofer (1)
- Candid Wuest (1)
- CAPTCHA (2)
- Career Enrichment (1)
- Cash Transfers (1)
- CCTV (1)
- CDT (1)
- Cell Phone Monitoring (1)
- Cell Phone Surveillance (1)
- CellDEK (1)
- Censorship (28)
- Center for Democracy and Technology (1)
- CERT (1)
- Cheyenne Mountain Operations Center (1)
- China (9)
- China Eagle Union (1)
- CIA (15)
- CipherTrust (1)
- Classified Information (1)
- Client-Side Exploits (30)
- Client-Side Vulnerabilities (30)
- CNO (1)
- COCOM (1)
- Cold War (1)
- COMINT (1)
- Competitive Intelligence (3)
- Compliance (3)
- Computer Crime Survey (1)
- Computer Network Operation (1)
- Conficker (1)
- Confidential Connections (1)
- Conspiracy (1)
- Conspiracy Theory (1)
- Conti (8)
- Conti Ransomware (7)
- Conti Gang (8)
- Conti Ransomware (7)
- Conti Ransomware Gang (8)
- Cookies (1)
- CoolWebSearch (4)
- Corporate Risk Management (4)
- Counter Espionage (2)
- Counter Intelligence (1)
- Credit Cards (7)
- Crimeware (3)
- Critical Infrastructure (2)
- Crusade Affiliates (1)
- Crypters (1)
- Cryptography (6)
- Cryptome (2)
- Cryptoviral Extortion (2)
- CSIA (2)
- CVE (1)
- Cyber Attack (61)
- Cyber Espionage (73)
- Cyber Insurance (1)
- Cyber Jihad (34)
- Cyber Militia (7)
- Cyber Security Industry Alliance (1)
- Cyber Security Investment (9)
- Cyber Terrorism (40)
- Cyber Threat Actor Attribution Maltego Graphs (2)
- Cyber Warfare (68)
- Cyber Weapon (1)
- Cyber Weapons (1)
- CyberCamp 2016 (1)
- Cybercrime (334)
- Cybercrime Ecosystem (21)
- Cybercrime Forum (36)
- Cybercrime Forum Data Set (13)
- Cybercrime Incident Response (1)
- Cybercrime Incident Response Maltego Graphs (1)
- Cybercrime Search Engine (1)
- Cybercriminal (1)
- Cyberpunk (4)
- Cyberspace (22)
- Cybertronics (3)
- Daniel Brandt (1)
- Dark Vader (1)
- Dark Forum (1)
- Dark Web (10)
- Dark Web Onion (5)
- Dark Web Search Engine (2)
- DarkComet RAT (1)
- Darkode (1)
- Darkode Forum Community (1)
- Data Acquisition (1)
- Data Breach (10)
- Data Center (1)
- Data Leak (2)
- Data Mining (6)
- David Endler (2)
- DCLeaks (1)
- DDoS (10)
- DDoS For Hire (1)
- Defense Complex (1)
- Delicious Information Warfare (1)
- Denmark (1)
- Department of Defense (2)
- DHS (1)
- DIA (1)
- Digital Armaments (1)
- Digital Forensics (2)
- Digital Rights (8)
- Dilbert (1)
- Distributed Computing (4)
- Distributed Computing Project (4)
- Distributed Project (4)
- DNS (2)
- DNS Changer (1)
- DoD (3)
- DoJ (1)
- DotCom (1)
- DreamHost (1)
- Dropbox (1)
- Durzhavna Sigurnost (3)
- DVD of the Weekend (5)
- E-Banking (2)
- E-Business (3)
- E-Commerce (2)
- E-Shop (2)
- Eavesdropping (24)
- Ebay (1)
- ECHELON (2)
- ECOFIN Projects (1)
- Economics (3)
- eID (1)
- Electric Universe (1)
- Electromagnetic Pulse Weapons (3)
- Electronic Banking (1)
- ELINT (1)
- Emotet (2)
- Emotet Botnet (1)
- EMP (3)
- Encrochat (1)
- Encrochat Database Leak (1)
- Encrypted Communication (6)
- Encrypted Phone (1)
- Encryption (8)
- Enigma (2)
- ENISA (1)
- Enki Bilal (1)
- Enron (1)
- Erasmus Bridge (1)
- Eric Goldman (2)
- Espionage (6)
- Espionage Movie (2)
- Evgeniy Mikhaylovich Bogachev (1)
- Exmanoize (1)
- Exploit Broker (10)
- Exploit Kit (2)
- Exploits (39)
- Eyeball Series (1)
- F-Secure (1)
- Facebook (15)
- Fake Account (1)
- Fake Adobe Flash Player (4)
- Fake Certificate (1)
- Fake Chrome Extension (1)
- Fake Chrome Update (1)
- Fake Code Signing Certificate (1)
- Fake Confirmed Facebook Friend Request Email (1)
- Fake Documents (7)
- Fake Facebook Appeal (1)
- Fake Facebook Notification (1)
- Fake Facebook Profile Spy Application (1)
- Fake Firefox Update (1)
- Fake Hosting Provider (1)
- Fake ID (7)
- Fake Internet Explorer Update (1)
- Fake Passport (8)
- Fake Personal ID (1)
- Fake Safari Update (1)
- Fake Security Software (48)
- Fake Tech Support Scam (1)
- Fake Utility Bill (4)
- Fake Video Codec (2)
- Fake Visa (1)
- Fake Visa Application (1)
- Fake Web Site (1)
- Fake Who's Viewed Your Facebook Profile Extension (4)
- Fake YouTube Player (1)
- Fast-Flux (3)
- FBI (4)
- FBI Most Wanted (5)
- FCC (1)
- FDIC (1)
- Financial Management (1)
- Firas Nur Al Din Dardar (1)
- FireEye (1)
- Flashpoint Intel (1)
- Foreign Influence Operations (2)
- Forensics (2)
- Forwarderz (2)
- FoxNews (1)
- Fraud (17)
- Free Speech (17)
- FSB (2)
- FTLog (1)
- FTLog Worm (1)
- Gartner (1)
- Gavril Danilkin (1)
- GazTranzitStroyInfo (1)
- GCHQ (8)
- GDBOP (1)
- Generation I (1)
- George Bush (1)
- Georgi Markov (1)
- Georgia (4)
- Germany (1)
- Gift Cards (1)
- GiveMeDB (1)
- Global Security Challenge (1)
- Goa Trance (1)
- GoDaddy (1)
- Google (11)
- Google Firebase (1)
- Google Ads (1)
- Google Docs (6)
- Google Earth (4)
- Google Groups (1)
- Google Hacking (2)
- Google Maps (3)
- Google Play (1)
- Google Store (1)
- Greece (1)
- Growth Hacker (2)
- GRU (1)
- Guccifer 2.0 (1)
- GUI (1)
- Gumblar (1)
- Hacked Database (5)
- Hacked Web Site (5)
- Hacker (2)
- Hackers (2)
- Hacking (233)
- Hacking Book (1)
- Hacking Forum (1)
- Hacking Group (5)
- Hacking Groups (1)
- Hacking Tools (1)
- HackPhreak (1)
- HackPhreak Hacking Group (1)
- Hacktivism (5)
- Haiti (1)
- Hamas (1)
- Hezbollah (1)
- High Tech Brazil Hack Team (1)
- Hilary Kneber (4)
- HKLeaks (1)
- Home Molestation (8)
- Homebrew (1)
- Honeynet Project (1)
- Honker Union of China (1)
- HUMINT (2)
- ICBM (1)
- ID Theft (4)
- iDefense (3)
- Identity Theft (4)
- Illegal Arrest (13)
- Illegal Hosting (1)
- Illegal Restraint (3)
- IMINT (2)
- IMLogic (3)
- India (1)
- India Company (1)
- Indicator of Compromise (1)
- Information Operations (2)
- Information Security (598)
- Information Security Forum (1)
- Information Security Market (5)
- Information Warfare (67)
- Infrastructure Security (1)
- InFraud (1)
- InFraud Cybercrime Gang (1)
- InFraud Cybercrime Syndicate (1)
- InFraud Organization (1)
- InqTana Mac OS X Malware (1)
- Insider (8)
- Insider Monitoring (2)
- Insider Threat (9)
- Instant Messaging (6)
- Intellectual Property (1)
- Intelligence (19)
- Intelligence Agency (17)
- Intelligence Community (35)
- Internal Revenue Service (1)
- International Exploit Shop (2)
- Internet (15)
- Internet Censorship (23)
- Internet Economy (4)
- Internet Relay Chat (1)
- Investment Banking (6)
- IoC (1)
- IP Cloaking (2)
- IP Hiding (1)
- IP Spoofing (1)
- iPowerWeb (1)
- IPSec (1)
- IPv4 (1)
- IPv6 (2)
- Iran (19)
- Iran Election (1)
- Iran Election 2009 (1)
- Iran Hacker Groups (7)
- Iran Hacking Groups (7)
- Iran Mabna Hackers (1)
- IRC (1)
- IRS (1)
- ISIS (1)
- Israel (1)
- Jabber (5)
- JabberZeuS (2)
- Javor Kolev (1)
- Jeffrey Carr (1)
- Joanna Rutkowska (1)
- Johannes Ullrich (2)
- John Young (1)
- K Rudolph (1)
- Kaseya (1)
- Kaseya Ransomware Attack (1)
- Katrina (1)
- Keylogger (1)
- KGB (7)
- Kidnapping (14)
- Koobface (29)
- Koobface Botnet (3)
- Korean Demilitarized Zone (1)
- KrotReal (1)
- Latest News Articles (2)
- Latvia (1)
- Law Enforcement (29)
- Lawful Interception (5)
- Leaks (1)
- Lenovo (3)
- Liberty Front Press Network (1)
- Lizamoon (2)
- Loads.cc (1)
- Localization (1)
- Location Tracking (2)
- Lockheed Martin (1)
- Logicube (1)
- Lone Gunmen (3)
- Lovely Horse (2)
- Lubyanka Square Headquarters (1)
- M4 Project (1)
- Mac OS X (3)
- Malicious Software (190)
- Maltego (6)
- Maltego Graphs (1)
- Malvertising (4)
- Malware (49)
- Malware Information Sharing Platform (1)
- Marketing (2)
- Mass Web Site Defacement (10)
- Mastercard (1)
- McAfee (3)
- MD5 (1)
- Media Methane (1)
- Memoir (2)
- Metrics (1)
- Microsoft (3)
- Microsoft Live (1)
- Military Communications (2)
- Ministry of Interior (1)
- MISP (1)
- Missile Base (1)
- Mobile (5)
- Mobile Application (2)
- Mobile Communication Censorship (1)
- Mobile Internet (3)
- Mobile Location Tracking (5)
- Mobile Malware (10)
- Mobile Security (2)
- Mohammad Sagegh Ahmadzadegan (1)
- Money Laundering (24)
- Money Mule (26)
- Money Mule Recruitment (26)
- Monoculture (1)
- Morgan Stanley (1)
- Moses Staff (1)
- Most Wanted Cybercriminals (1)
- MSN (3)
- MSRC (1)
- MSRC Researcher Recognition Program (1)
- Muhammad Cartoons (1)
- MVR (1)
- MyWebFace (1)
- NASA (1)
- National Cyber Security Centre (1)
- National Security (2)
- Native Intelligence (1)
- NBC (2)
- NCSC (1)
- NetAssist LLC (1)
- NetCraft (1)
- Network Centric Warfare (1)
- Network Solutions (3)
- New Media (9)
- Nikolay Nedyalkov (1)
- Nikopol Trilogy (1)
- Nintendo (1)
- Nintendo DS (1)
- NordVPN (1)
- Norman Sandbox (1)
- North Korea (3)
- North Korea Missile Launch Pad (1)
- NSA (16)
- NSO Group (1)
- NSO Group Spyware (1)
- Nuclear Weapons (3)
- Nyxem (1)
- OEM (1)
- Offensive Cyber Warfare (1)
- OMEMO (1)
- Omerta (1)
- One-Time Password (1)
- One-Time Passwords In Everything (2)
- OneCare (1)
- Online Advertising (5)
- Online Fraud (12)
- Online Marketing (3)
- Online Propaganda Campaign (1)
- Online Scam (3)
- Open Source Malware (3)
- Operation EQUALIZER (1)
- Operation Uncle George (8)
- OPIE (1)
- OPSEC (1)
- Osama Bin Laden (1)
- OSINT (118)
- OSINT Training (1)
- OTC (1)
- OTP (1)
- Over-The-Counter (1)
- Packers (1)
- Parked Domains (1)
- Passwords (2)
- Pavlin Georgiev (1)
- Pay Per Install (3)
- PayPal (1)
- Perplex City (1)
- Persistent Cookies (1)
- Personal Career (1)
- Personal Data (4)
- Pharmaceutical Scams (1)
- Phileas Crawler (1)
- Phishing (12)
- Phishing Campaign (8)
- Phishing Domain Farm (1)
- Phishing Toolbar (2)
- PhishTube (1)
- Phreedom (1)
- Physical Security (1)
- Pinterest (1)
- Piracy (1)
- PlushForums (1)
- Podcast (2)
- Point of Sale Terrminal (1)
- Politics (1)
- PornTube (1)
- POS (1)
- Potentially Unwanted Application (2)
- PR (1)
- Press Coverage (1)
- Privacy (34)
- Project RAHAB (1)
- Prolexic (1)
- Protonmail (4)
- Proxy Service (1)
- Psychedelic Trance (2)
- PSYOPS (2)
- Psytrance (2)
- Psytrance Song of the Day (2)
- Qassam Cyber Fighters (2)
- Radicati Group (1)
- Ransomware (20)
- RAT (1)
- Ray Kurzweil (1)
- RBN (1)
- Reconnaissance Satellite (2)
- Red Joan (1)
- Regulation (1)
- Remote Access Tool (4)
- Reporters Without Borders (1)
- Return On Investment (9)
- Return On Security Investment (10)
- REvil Ransomware Group (1)
- Revolution in Militvry Affairs (1)
- RIPA (1)
- Risk Management (2)
- Rogue Account (1)
- Rogue Chrome Extension (1)
- Rogue Facebook Appeal (1)
- Rogue Security Software (2)
- Rogue Video Codec (1)
- Rogue YouTube Player (1)
- Rogueware (3)
- ROI (3)
- Roman Polesek (1)
- Root Server (2)
- Rootkit (1)
- ROSI (7)
- RSA (1)
- RSA Conference (1)
- Russia (12)
- Russia Small Group (1)
- Russian (1)
- Russian Bomber (1)
- Russian Business Network (4)
- Russian Submarine (1)
- Safe Harbor (1)
- Satellite Imagery (3)
- Satellite Jamming (1)
- Satellite SIGINT (1)
- Scam (4)
- Scams (9)
- Scandoo (1)
- ScanSafe (1)
- Scareware (50)
- Scientific Intelligence (1)
- Scribd (1)
- Search Engine (16)
- Search Engine Optimization (26)
- SEC (1)
- SecondEye Solutions (2)
- Secret Service (1)
- Secure Communication (1)
- SecureDrop (1)
- Securities and Exchange Commission (1)
- Security (645)
- Security Awareness (2)
- Security Book (1)
- Security Breach (4)
- Security Conference (2)
- Security Directory (1)
- Security Education (1)
- Security Event (2)
- Security Forum (1)
- Security Game (1)
- Security Industry (6)
- Security Interviews (3)
- Security Investment (5)
- Security Metrics (3)
- Security Podcast (2)
- Security Project (1)
- Security Research (1)
- Security Statistics (3)
- Security Training (1)
- Security Trends (8)
- Sensitive Information (2)
- SEO (2)
- Shadow Server (1)
- ShadowCrew (5)
- SIGINT (2)
- Silent Circle (1)
- Sipco Systems (1)
- SIPRNET (2)
- SITE Institute (1)
- SiteAdvisor (4)
- Skype (2)
- Sniffing (1)
- Social Engineering (4)
- Social Network Analysis (5)
- SocialMediaSystem (1)
- Software Piracy (1)
- Solarwinds (1)
- Song of the Day (2)
- Sophos (1)
- Soviet Union (1)
- Space Warfare (3)
- Space Weapons (1)
- Spam (10)
- Spam Campaign (7)
- Spam Operations (7)
- Spear Phishing (2)
- Spoofing (1)
- Sprott Asset Management (1)
- Spyware (3)
- SQL Injection (3)
- SSL (2)
- SSN (1)
- Stalkware (1)
- Starlight (1)
- Stealth Ideas Inc (1)
- Steganography (1)
- STIX (3)
- STIX2 (3)
- Stolen Credit Card (9)
- Stolen Credit Cards (5)
- Stolen Gift Cards (1)
- Strider Crawler (1)
- Sub7 (1)
- Suri Pluma (1)
- Surveillance (24)
- Swine Flu (1)
- Symantec (5)
- Symbian (1)
- Syria (2)
- Syrian Electronic Army (1)
- Syrian Embassy (1)
- Taia Global (1)
- TAN (1)
- TAXII (3)
- TDoS (1)
- Team Code Zero (1)
- Team Code Zero Hacking Group (1)
- Tech Support Scam (1)
- Technical Collection (73)
- Technical Mujahid (1)
- Telephony Denial of Service Attack (1)
- Terrorism (8)
- th3j35t3r (1)
- THAAD (1)
- The Bunker (1)
- The Immortals (1)
- The Lawnmower Man (2)
- The Outer Limits (4)
- Thought Leadership (1)
- Thousand Talents Program (1)
- Threat Intelligence (18)
- Threat Intelligence Feed (2)
- Threat Intelligence Report (1)
- TIA (4)
- Tipping Point (1)
- Top Secret Program (1)
- Tor (1)
- Tor Project (1)
- Torrent (1)
- TorrentReactor (1)
- Total Information Awareness (4)
- Travel Without Moving (9)
- TrendMicro (2)
- Trickbot (1)
- Trickbot Gang (1)
- Trickbot Malware (1)
- Trickbot Malware Gang (1)
- Trifinite Group (1)
- Trojan Horse (2)
- TROYAK-AS (2)
- Tutanota (2)
- Twitter (4)
- Two Factor Authentication (1)
- Two-Factor Authentication (3)
- Typosquatting (3)
- U.K National Cyber Security Centre (1)
- U.S Bureau of Engraving and Printing (2)
- U.S Cyber Command (1)
- U.S Driving License (1)
- U.S Elections (3)
- U.S Sanctions (1)
- U.S Secret Service (1)
- Underground Search Engine (1)
- United Kingdom (4)
- University ID Card (1)
- Vasil Moev Gachevski (1)
- Vault 7 (1)
- VeriSign (1)
- Vertex Net Loader (1)
- Virtual Private Network (2)
- Virtual Reality (5)
- Virtual Reality Social Network (4)
- Virtual World (4)
- Virus (1)
- Virus for You (1)
- Virus Map (1)
- Virus Recovery Button (1)
- Viruses (2)
- VirusTotal (1)
- Visa (1)
- Visual Information System (2)
- Visualization (3)
- Void Balaur Malware Gang (1)
- VoIP (2)
- VPN (3)
- Vulnerabilities (39)
- Vulnerability Broker (10)
- War Driving (1)
- War Games (1)
- Weapon Systems (1)
- Web 2.0 (3)
- Web Application Worm (1)
- Web Crawler (2)
- Web Inject (1)
- Web Proxy Service (1)
- Web Shells (1)
- Web Site Defacement (10)
- Web Site Defacement Groups (4)
- Webroot (2)
- WHGDG (1)
- WhoisXML API (10)
- WhoisXML API Jabber ZeuS Gang (1)
- Wireless (2)
- Wireless Hacking (1)
- Wireless Internet (2)
- Wiretapping (10)
- WMF Vulnerability (2)
- World Hacker Global Domination Group (1)
- X-Files (2)
- X-Tunnel (1)
- XMPP (4)
- XSS (1)
- Yahoo (2)
- Yaroslav Vasinskyi (1)
- Yavor Kolev (1)
- YouTube (1)
- ZDNet (1)
- ZDNet Zero Day Blog (1)
- Zero Day Exploit (6)
- Zero Day Initiative (2)
- Zerodium (1)
- ZeuS (4)
- Zombie Alert (2)
- Zone-H (2)
- Zotob (1)
Dancho Danchev's Blog - Mind Streams of Information Security Knowledge is wearing HalfBaked. Free WP-Theme by GuyFisher. Converted to Blogger by Template-Godown.




























