Monday, February 23, 2009

Fake Celebrity Video Sites Serving Malware - Part Three

In the overwhelming sea of template-ization of malware serving sites, (naked )celebrities would always remain the default choice offered in the majority of bogus content generating tools taking advantage of the high-page rank of legitimate Web 2.0 services.

Following the 2008's Fake Celebrity Video Sites Serving Malware series (Part Two) the very latest addition to the series demonstrates the automatic abuse of legitimate infrastructure - in this case Blogspot for the purpose of traffic acquisition.

The following are currently active and part of the same campaign:
lisa-bonet-angel-heart.blogspot.com
milla-jovovich-gallery.blogspot.com
pamela-anderson-hot-sex-tape.blogspot.com
rihanna-nude-gallery.blogspot.com
kate-hudson-nude-gallery.blogspot.com
milla-jovovich-gallery.blogspot.com
teacher-slept-with-boy.blogspot.com
meg-white-new-sex-tape.blogspot.com
anna-faris-hot-video.blogspot.com
so-hard-movies.blogspot.com
 

vanessa-hot.blogspot.com
paris-hilton-sexass.blogspot.com
sex-tape-lindsay-lohan.blogspot.com
chloesevigny-privategallery.blogspot.com
kate-winslet-nude-gallery.blogspot.com
keeley-hazell-sex-hot-video .blogspot.com
miley-cyrus-sex-tape .blogspot.com
britney-spears-hottest-video .blogspot.com
miley-cyrus-naked-video .blogspot.com
alyssa-milano-naked-video .blogspot.com
kardashian-hot-video .blogspot.com
naked-jennifer-lopez .blogspot.com
vanessa-hudgens-hot-video .blogspot.com
hottest-lindsay-lohan-video .blogspot.com
cameron-diaz-porn .blogspot.com
underworld-rise-lycans .blogspot.com


Compared to the single-post only Blogspots, the following domains top100videoz.com; cinemacafe.tv; xvids-top.com have a lot more bogus content to offer.

Wednesday, February 18, 2009

Pharmaceutical Spammers Targeting LinkedIn

Following January's malware campaign relying on bogus LinkedIn profiles, this time it's pharmaceutical spammers' turn to target the business-oriented social networking site.

From a spammers/blackhat SEO-er's perspective, this is done for the purpose of increasing the page rank of their pharmaceutical domains based on the number of links coming from LinkedIn. The campaigns are monetized through the usual affiliate based pharmaceutical networks.

The following is a complete list of the currently active bogus domains, all part of identical campaigns:
linkedin .com/in/buyviagra45
linkedin .com/in/phenterminetrueway
linkedin .com/in/OnlineBuyProzac
linkedin .com/in/CheapBuyGabapentin
linkedin .com/in/BuyCheapTramadol
linkedin .com/in/cheaptramadol
linkedin .com/in/buybactrimonline
linkedin .com/in/OnlineBuyAugmentin
linkedin .com/in/OnlineBuyMetformin
linkedin .com/in/OnlineBuyBiaxin
linkedin .com/in/CheapBuyNorvasc
linkedin .com/in/OrderBuyCelebrex
linkedin .com/in/OnlineBuyLipitor
linkedin .com/in/BuyCheapOxycontin
linkedin .com/in/OnlineBuyHydrocodone
linkedin .com/in/OrderBuyPercocet
linkedin .com/in/OnlineBuyFioricet
linkedin .com/in/OrderBuyKlonopin
linkedin .com/in/OnlineBuyDiazepam
linkedin .com/in/OnlineBuyXanax
linkedin .com/in/CheapBuyOxycodone
linkedin .com/in/OnlineBuyClonazepam
linkedin .com/in/OnlineBuyEffexor
linkedin .com/in/OnlineBuyAmbien
linkedin .com/in/OnlineBuyAtivan
linkedin .com/in/OnlineBuyVicodin
linkedin .com/in/OnlineBuyNexium
linkedin .com/in/OrderBuyCipro
linkedin .com/in/OnlineBuyLorazepam
linkedin .com/in/propecia
linkedin .com/in/OnlineBuyAllegra
linkedin .com/in/CheapBuyMeridia
linkedin .com/in/OnlineBuyZithromax
linkedin .com/in/OnlineBuyCelexa
linkedin .com/in/clomid
linkedin .com/in/clonazepam
linkedin .com/in/BuyCheapNeurontin
linkedin .com/in/cheapfioricet
linkedin .com/in/OnlineBuyClomid
linkedin .com/in/OnlineBuyIbuprofen
linkedin .com/in/OnlineBuyZoloft
linkedin .com/in/OnlineBuyToprol
linkedin .com/in/OnlineBuyAleve
linkedin .com/in/OnlineBuyAleve
linkedin .com/in/OnlineBuyVioxx
linkedin .com/in/OnlineBuyWellbutrin
linkedin .com/in/OnlineBuyAmoxicillin
linkedin .com/in/OnlineBuySuboxone
linkedin .com/in/OnlineBuyOxycodone
linkedin .com/in/OnlineBuyLisinopril
linkedin .com/in/OrderBuyPrevacid
linkedin .com/in/OnlineBuyLevaquin
linkedin .com/in/OnlineBuyUltram
linkedin .com/in/OnlineBuyAlprazolam
linkedin .com/in/OnlineBuyLamictal
linkedin .com/in/OnlineBuyNaproxen
linkedin .com/in/OnlineBuyZyprexa
linkedin .com/in/OnlineBuyCoumadin
linkedin .com/in/OnlineBuyValium
linkedin .com/in/OnlineBuyLithium
linkedin .com/in/OnlineBuySynthroid
linkedin .com/in/OnlineBuyHerceptin
linkedin .com/in/OnlineBuyAvandia

linkedin .com/in/OnlineBuyTramadol
linkedin .com/in/OnlineBuyCymbalta
linkedin .com/in/OnlineBuyDoxycycline
linkedin .com/in/OnlineBuyProtonix
linkedin .com/in/OnlineBuyTestosterone
linkedin .com/in/OnlineBuyTopamax
linkedin .com/in/OnlineBuyBenadryl
linkedin .com/in/OnlineBuyBactrim
linkedin .com/in/OnlineBuyMethadone
linkedin .com/in/OnlineBuyAtenolol
linkedin .com/in/OnlineBuyConcerta
linkedin .com/in/OnlineBuyCrestor
linkedin .com/in/OnlineBuyTrazodone
linkedin .com/in/OnlineBuyVytorin
linkedin .com/in/OnlineBuyMelatonin
linkedin .com/in/OnlineBuyCephalexin
linkedin .com/in/OnlineBuyThyroid
linkedin .com/in/OnlineBuyChantix
linkedin .com/in/OnlineBuyInsulin
linkedin .com/in/OnlineBuyGenace
linkedin .com/in/OnlineBuyByetta
linkedin .com/in/OnlineBuyPropecia
linkedin .com/in/OnlineBuyPlavix
linkedin .com/in/OnlineBuyYaz
linkedin .com/in/OnlineBuyYasmin
linkedin .com/in/OnlineBuyPotassium
linkedin .com/in/OnlineBuyValtrex
linkedin .com/in/OnlineBuyVoltaren
linkedin .com/in/OnlineBuyPenicillin
linkedin .com/in/OnlineBuyZyrtec
linkedin .com/in/OnlineBuyMagnesium
linkedin .com/in/OnlineBuyPrednisone
linkedin .com/in/OnlineBuySeroquel
linkedin .com/in/OnlineBuySoma
linkedin .com/in/OnlineBuyGabapentin
linkedin .com/in/OnlineBuyAspirin
linkedin .com/in/OnlineBuyPseudovent
linkedin .com/in/OnlineBuyLortab
linkedin .com/in/OnlineBuyPaxil
linkedin .com/in/OnlineBuyAlli
linkedin .com/in/BuyCheapXenical
linkedin .com/in/CheapBuyUltracet
linkedin .com/in/buyhydrocodone
linkedin .com/in/OrderBuyAlli
linkedin .com/in/buypaxilonline
linkedin .com/in/OnlineBuyMobic
linkedin .com/in/OnlineBuyNaprosyn
linkedin .com/in/OnlineBuyCipro
linkedin .com/in/OnlineBuyMorphine
linkedin .com/in/vimax
linkedin .com/in/OnlineBuyAccutane
linkedin .com/in/vigrx
linkedin .com/in/OnlineBuyNorvasc
linkedin .com/in/OnlineBuyOxycontin
linkedin .com/in/OnlineBuyProvigil
linkedin .com/in/OnlineBuyPercocet
linkedin .com/in/OnlineBuyCelebrex
linkedin .com/in/OnlineBuyAdipex
linkedin .com/in/OnlineBuyRitalin
linkedin .com/pub/dir/purchase/viagra
linkedin .com/pub/dir/cialis/online
linkedin .com/pub/dir/methocarbamol/online
linkedin .com/pub/dir/acyclovir/online
linkedin .com/pub/dir/klonopin/online
linkedin .com/pub/dir/zyprexa/online
linkedin .com/pub/dir/amitriptyline/online
linkedin .com/pub/dir/buymodalertonline/buymodalertonline
linkedin .com/pub/dir/zocor/online
linkedin .com/pub/dir/levitra/online
linkedin .com/pub/dir/citalopram/online
linkedin .com/pub/dir/arimidex/online
linkedin .com/pub/dir/niacin/online
linkedin .com/pub/dir/phentermine/online
linkedin .com/pub/dir/provigil/online
linkedin .com/pub/dir/ritalin/online

Pharmaceutical domains used in the campaigns:
buy-pharmacy .info
viagra-pills .info
nenene .og
rxoffers .net
allrxs .org
onlinepharmacy4u .org
cheap-tramadol .us
buy-tramadol.blogdrive .com
buymodalert .com
rx-prime .com
suche-project .eu


Acquiring new users in a highly competitive Web 2.0 world is crucial, no doubt about it. But in 2009, if you're not at least requiring a valid email address, a confirmation of the registration combined with a CAPTCHA to at least slow down the bogus account registration process and ruin their efficiency model - systematic abuse of the service is inevitable (Commercial Twitter spamming tool hits the market).

LinkedIn's abuse team has already been notified of these accounts.

Tuesday, February 17, 2009

Community-driven Revenue Sharing Scheme for CAPTCHA Breaking

What follows when a system that was originally created to be recognizable by humans only, gets undermined by low-waged humans or grassroots movements? Irony, with no chance of reincarnation. CAPTCHA is dead, humans killed it, not bots.

A new market entrant into the CAPTCHA-breaking economy, is proposing a novel approach that is not only going to result in a more efficient human-based CAPTCHA solving on a large scale, but is also going to generate additional revenues for webmasters and their site's community members. The concept is fairly simple, since it's mimicking reCAPTCHA's core idea.

However, instead of digitizing books, the CAPTCHA entry field that any webmaster of an underground community, or a general site in particular that would like to syndicate CAPTCHAs from Web 2.0 web properties is free to do so on a revenue-sharing, or plain simple voluntary basis.

Consider for a moment the implications if such a project of they manage to execute it successfully. Starting from community-driven CAPTCHA breaking of Web 2.0 sites on basic forum registration fields using MySpace.com's CAPTCHA for authenticating new/old users, the plain simple automatic rotation for idle community users, to the enforcement of CAPTCHA authentication for each and every new forum post/reply.

What happens with the successfully recognized CAPTCHAs? As usual, hundreds of thousands of bogus profiles will get automatically registered for the purpose of spam and malware spreading, or reselling purposes. The development of this service -- if any -- will be monitored and updates posted if it goes mainstream.

Related posts:
The Unbreakable CAPTCHA
Spammers attacking Microsoft's CAPTCHA -- again
Spam coming from free email providers increasing
Gmail, Yahoo and Hotmail’s CAPTCHA broken by spammers
Microsoft’s CAPTCHA successfully broken
Vladuz's Ebay CAPTCHA Populator
Spammers and Phishers Breaking CAPTCHAs
DIY CAPTCHA Breaking Service
Which CAPTCHA Do You Want to Decode Today?

Wednesday, February 11, 2009

Quality Assurance in a Managed Spamming Service

Following previous coverage of the managed spam services offered by the Set-X mail system and a copycat variant of it, a newly introduced managed spam service is emphasizing on quality assurance through the use of a Google Search Appliance for storing of the harvested email databases and the spam templates.

Here's an automatic translation of some of the key features offered by the system, currently having a price tag of $1,200 per month:

"A summary of the main possibilities of the system
- Innovative technology deliver a unique e-mail system designed specifically for ******** to maximize serve up e-mails with a low rate of rejection-Kernel Multi-organization system provides extremely high speed while the low-platform-Provide complete sender's anonymity at the maximum system performance in terms multi-technology operating system bypass content filters using the built-in special tags:

+ Configurable generation of random strings
+ Change the case of letters randomly in a block 
+ random permutation of symbols in the block 
+ Inserting a random character in an arbitrary place in the block 
+ Replacing the same style of letters Latin alphabet for the Russian block 
+ Duplicating a random character in the block 
+ Paste into the body of a random letter strings from a file 
+ Managed morfirovanie image files in the format GIF-Correct emulation header sent letters Simultaneous connection of several bases e-mail addresses of those letter-substitution is performed from file-substitution e-mail addresses for the fields From and Reply-To is performed from a file-format of outgoing messages TEXT and HTML
+Ability to send emails from attachments
+Correct work with images in HTML messages possible as a direct method and with copies of CC , BCC-record-keeping system, results of the system is stored in files good, bad and unlucky for each connection of e-mail addresses, respectively
+The system is convenient and intuitive graphical user interface

System management
The system is operated under the interface to "Control Panel". The first is of them is multifunctional and serves to start the process of sending (the state of the "Run"), pause (the state of "pause") and confirm the end of the (state "Report") . The second button ( "Stop") serves to interrupt the process otpravki. Data section also contains the following information fields: 
- executes an action in this field is carried out to date, the system-progress indicator graphic indication of progress the task, Completed Display task progress percentage 
- Successful delivery of letters to the number of addresses that had been carried out successfully, failure of the number of addresses that failed to deliver a letter-number bad non-existent addresses, duration of the actual time of the task-status displays the status of the kernel system kernel kernel memory Displays memory core systems"

The ongoing arms race between the security industry and cybercriminals, is inevitably driving innovation at both sides of the front. However, based on the scalability of these managed spam services, it's only a matter of time for the vendors to embrace simple penetration pricing strategies that would allow even the most price-conscious cybercriminals, or novice cybercriminals in general to take advantage of this standardized spamming approach. The disturbing part is that the innovation introduced on behalf of the spam vendors in terms of bypassing spam filters, seems to be introduced not on the basis of lower delivery rates, but due to the internal competition in the cybercrime ecosystem.

For instance, new market entrants in the face of botnet masters attempting to monetize their botnets by offering the usual portfolio of cybercrime services, often undercut the offerings of the sophisticated managed spam vendors. And so the vendors innovate with capabilities that the new market entrants cannot match, in order to not only preserve their current customers, but also, acquire new ones. Managed spam services as a business model is entirely driven by long term "bulk orders", compared to earning revenues on a volume basis by empowering low profile spammers with sophisticated delivery mechanisms.

In the long term, just like every other segment within the cybercrime ecosystem, vertical integration and consolidation will continue taking place, and thankfully we'll have a situation where the spam vendors would be sacrificing OPSEC (operational security) on their way to scale their business model and acquire more customers.

Thursday, February 05, 2009

Summarizing Zero Day's Posts for January

The following is a brief summary of all of my posts at ZDNet's Zero Day for January. You can also go through previous summaries for December, November, October, September, August and July, as well as subscribe to my personal RSS feed or Zero Day's main feed.

Notable articles for January include Microsoft study debunks phishing profitability; Legal concerns stop researchers from disrupting the Storm Worm botnet and Google Video search results poisoned to serve malware.

01. Thousands of Israeli web sites under attack
02. Bogus LinkedIn profiles serving malware
03. Microsoft study debunks phishing profitability
04. Paris Hilton's official web site serving malware
05. Malware author greets Microsoft's Windows Defender team
06. 3.5m hosts affected by the Conficker worm globally
07. GoDaddy hit by a DDoS attack
08. Legal concerns stop researchers from disrupting the Storm Worm botnet
09. Malware-infected WinRAR distributed through Google AdWords
10. New mobile malware silently transfers account credit
11. GPU-Accelerated Wi-Fi password cracking goes mainstream
12. Google Video search results poisoned to serve malware

Tuesday, February 03, 2009

A Diverse Portfolio of Fake Security Software - Part Fifteen

Descriptive fake security software domains speak for themselves, and what follows are the very latest ones currently active in the wild :

spywareguard2009m .com (78.26.179.253; 94.247.2.39)
systemguard2009m .com
spywareguard2009 .com
systemguard2009 .com
getsysgd09 .com


Registrant : Damir Sbil; Email: damirsbils791@googlemail.com

antispyscanner13 .com (94.247.2.39; 78.26.179.253)
sgproductm .com
sgviralscan .com
sg10scanner .com
sg11scanner .com
sg12scanner .com
sg9scanner .com
sgproduct .com


Registrant: Ahmo Stolica; Email: ahmostoln73@yahoo.com

buysysantivirus2009 .com (94.247.2.75)
sysav-download .com
sysav-storage .com
sysantivirus-check .com
antispyware-pro-dl .com
sysantivirus2009 .com
sysav-download .com
sysav-storage .com
sysantivirus-check .com
antispywarefastcheck .com
antispyware-scanner-2009 .com
antispyware-pro-dl .com


Registrant: Dion Choiniere; Email: noelwollenberg@ymail.com

premium-antivirus-defence.com (195.24.78.186)
lite-antispyware-scan.com
computeronlinescan.com
lite-antispyware-scan.com
liteantispywarescan.com
liteantispywarescanner.com
liteantispywareproscan.com
onlineproantispywarescan.com
bestantispywarescan.com
bestantispywarelivescan.com
antispywareliveproscan.com
antispywareinternetproscan.com
bestanti-virusscan.com
antimalware-scanner.com
computerantivirusproscanner.com
antimalwareproscanner.com
antimalware-pro-scanner.com
antimalware-scanner.com
antimalware-scan.com
computeronlineproscanner.com


Registrant: Maksim Hirivskiy Email: alt165@freebbmail.com

DNS servers to keep an eye on, courtesy of UralComp-as Ural Industrial Company LTD (AS48511) :
ns1.europegigabyte .com
fastuploadserver .com
ns1.managehostdns .com
dns3.systempromns .com
ns1.freehostns .com
ns1.singatours .com
ns1.airflysupport .com
ns1.eguassembly .com
ns1.fastfreetest .cn


Proactively blocking these undermines a great deal of traffic acquisition campaigns whose aim is to hijack legitimate traffic to these domains.

Related posts:
A Diverse Portfolio of Fake Security Software - Part Fourteen
A Diverse Portfolio of Fake Security Software - Part Thirteen
A Diverse Portfolio of Fake Security Software - Part Twelve
A Diverse Portfolio of Fake Security Software - Part Eleven
A Diverse Portfolio of Fake Security Software - Part Ten
A Diverse Portfolio of Fake Security Software - Part Nine
A Diverse Portfolio of Fake Security Software - Part Eight
A Diverse Portfolio of Fake Security Software - Part Seven
A Diverse Portfolio of Fake Security Software - Part Six
A Diverse Portfolio of Fake Security Software - Part Five
A Diverse Portfolio of Fake Security Software - Part Four
A Diverse Portfolio of Fake Security Software - Part Three
A Diverse Portfolio of Fake Security Software - Part Two
Diverse Portfolio of Fake Security Software