Showing posts with label china. Show all posts
Showing posts with label china. Show all posts

Saturday, 25 January 2014

Unprecedented International Cybercrime Cooperation Nabs Email Hackers

Email Hacking in China, India, Romania

Yesterday we tweeted asking for more information on a statement we found in India's press regarding an email hacker charged in Pune. The article I sited, Pune techie held after FBI alert on hacking racket, reported:
The CBI on Friday arrested a 32-year-old techie from Pune after a tip-off from the Federal Bureau of Investigation (FBI) about a racket involving hacking of 900 e-mail accounts belonging to people from across the world, including Americans and Indians. [...] Following the FBI tip-off, the CBI carried out raids in Ghaziabad, Mumbai and Pune during which several professional hackers were rounded up. Tiwari was arrested and taken on transit remand to Delhi by the CBI team. His computers and other gadgets were seized. According to the CBI, the e-mail accounts of 171 Indians and more than 700 foreign nationals, including Americans, had been hacked. [...] The agency said the raids were part of a coordinated action involving the agencies of China, Romania, the US and India. This was the first time the CBI had tied up with international investigation agencies to launch an operation against cyber crime in India.
We were so pleased to learn of the CBI's Cooperation with the FBI on it's first Cybercrime coordinated effort, but were left puzzling over the statement about coordinated raids in India, Romania, China, and the US.

The confusion was over the fact that the FBI had decided to not unseal the cases in the US related to these crimes until they received confirmation from their peers in India, Romania, and China that the others involved in the case had been successfully arrested. Once that was concluded, we were able to find the original announcement, January 24, 2014, from the US Attorney's Office in the Central District of California, International Law Enforcement Efforts Result in Charges Around the World Against Operators and Customers of E-Mail Hacking Websites.

  • Mark Anthony Townsend, 45, of Cedarville Arkansas and
  • Joshua Alan Tabor, 29, of Prairie Grove Arkansas were charged with a felony violation for running "needpassword.com". Customers of their service would provide an email account and make payment via PayPal once the email password was obtained. More than 6,000 email accounts were hacked during this scheme.
    Three additional US persons were charged, but these were charged with the lesser misdemeanor charges related to hiring a hacker (as opposed to the two above, who did the hacking themselves):
  • John Ross Jesensky, 30, of Northridge, California, paid $21,675 to a Chinese website to obtain email account passwords.
  • Laith Nona, 31, of Troy, Michigan, paid $1,081 to obtain email account passwords.
  • Arthur Drake, 55, of Bronx, New York, paid $1,011 to get email account passwords.

The Romanian DCCO (Direcţiei de Combatere a Criminalităţii Organizate or Directorate for Combating Organized Crime) part of the DIICOT, searched the residences and arrested four individuals associated with the hacker for hire websites:

  • zhackgroup.com
  • spyhackgroup.com
  • rajahackers.com
  • clickhack.com
  • ghostgroup.org (since at least September 2006!)
  • e-mail-hackers.com






Romanian Email hacker, Guccifer

The Romanians report that these individuals broke into at least 1600 email accounts between February 2011 and October 2012.

Based so far only on the coincidence of timing, this blogger believes that this was the notorious "Guccifer" or Marcel Lazar Lehel, who was previously charged with a suspended sentence of three years (February 8, 2012) for hacking into email accounts belonging to SRI director George Maior, former US state secretary Colin Powell, members of Bush and Rockefeller families and officials of the Obama administration. See for example the January 22, 2014 story in Romania's Nine O'Clock news, "Hacker 'Gucifer' caught in Arad" -- www.nineoclock.ro/hacker-“guccifer”-caught-in-arad/. In another story from digi24.ro (via Google Translation) it says:

[In addition to] SRI boss George Major, George Bush, and Colin Powell, Other victims of 'Guccifer' were actor Steve Martin, John Dean, former advisor to President Richard Nixon, actress Mariel Hemingway, three members of the House of Lords in the UK, Laura Manning Johnson, a former CIA analyst, George Roche was Secretary of the Air Force, and President MetLife (insurance company).
. In the earlier charges that resulted in the suspended sentence, Guccifer was charged with accessing and making public photos from the Facebook pages and email accounts of many public officials in Romania as well.


Indian Email hacker, Amit Tiwari

The Central Bureau of Investigation in India arrested Amit Tiwari (who had previously been arrested for Credit Card Fraud) for operating the websites www.hirehacker.net and www.anonymiti.com, who hacked at least 935 e-mail accounts between February 2011 and February 2013.

HireHacker's homepage
HireHacker.net was a prolific advertiser of their services since 2007, creating many "blogs" (such as freelancehackers.wordpress.com) and posting questions on places like Yahoo Answers like "Can the Famous Internet Detectives at HireHacker.net really recover my cheating spouses email password?"


Chinese Email hacker, Ying Liu

The Ministry of Public Safety in China arrested Ying Liu (劉颖), AKA Brent Liu, for operating the website HireToHack.net. Liu was shown to have broken into at least 300 email accounts between January 2012 and March 2013.

Liu's website had it's fifteen minutes of fame when it was featured in NYMag's story Hiring Hackers is Super Cheap. In that story from January 2012, two Kuwaiti brothers, Bassam Alghanim being the billionaire of the two, hired some Chinese hackers "for the price of a really good dinner" to break into his brother's email account. That story indicated that the hackers earned $200,000 in thirteen months by breaking into accounts. The story was also covered in the Wall Street Journal (which also has a video from Cassell Bryan-Low about the case), where the actual hacking may have been via Invisible Hacking Group instead.

Ying Liu hosted his website, hiretohack.net, on the notorious Malaysian hosting platform, Piradius.net. Here are some screen shots of HireToHack.net that show how their system worked:

Homepage
Menu of Services
Order Placement
This is such an amazing demonstration of international cooperation! I know I already said so, but for India's CBI, China's MPS, Romania's DCCO, and the FBI to cooperate together on a single case is without precedence! A great sign towards a bad future for cyber criminals!

Saturday, 14 December 2013

20 Million Chinese Hotel Guests have data leaked

This morning Secure Computing shared a brief article about Data on 20 Million Chinese Hotel Guests being shared by hackers. Unfortunately the only link in the article was a search for the word Breach on SCMagazine's own website.

The source was South China Morning Post, which has actually been writing about this for some time. On October 11, Amy Li reported that "Home Inn Hotels" a popular discount chain, and Hanting Hotel Group, were using "faulty hotel management software" developed by CNWISDOM. This was reported by "independent internet security watchdog Wuyun.org". The NASDAQ traded hotel chain eventually acknowledged the vulnerability, which they described as a weakness in their Wireless Portal Security System, and announced on their home page that the issue had been resolved, thanking WooYun for helping them with the vulnerability.

CNWisdom Data Leaks

Shortly after the initial exchange, a seller on Taobao (think Chinese eBay) announced that he was selling 8 Gigabytes of hotel guest data for 2,000 Yuan. South China Morning Post reported that the chain had 450,000 hotel rooms in 4,500 hotels, and that when guests register, they are required to provide their home address, phone number, ID card, date of birth, and workplace if they want to use the WiFi service. This is apparently the data that was received.

As reported in Patrick Boehler December 9th story in the South China Morning Post, Chinese Hackers Leak Hotel Guest Data on WeChat, multiple websites were distributing the hotel data for 20 million guests, and some enterprising hackers had even built a chat interface allowing you to TXT someone's ID card number to the service and having it reply with the details of any hotel stays by that guest.

WooYun

WooYun regularly shares vulnerability data, so we thought we would start at the beginning and find that. There were several "cnwisdom" breach reports there, including:

WooYun-2013-41171 (submitted October 28, 2013) - which referred to an SQL injection vulnerability

WooYun-2013-41171 (submitted October 27, 2013) - which referred to a STRUCTS problem

WooYun-2013-034935 (submitted August 21, 2013) - the WiFi Data Leak

Unfortunately, I have to rely on some Google Translate here ...

The way WooYun explains it is (Gary's paraphrase of the Google Translate of what they said:)

"Users connect to their hotel's open WiFi, which requires them to use a webpage to authenticate. That webpage is using http protocol, which means the username and password are transmitted in the clear. But the next phase of the authentication is to update a central database of WiFi information. IN THE CLEAR, the authentication connects to a database using the username "cnwisdomapi" and the password "3b823[马赛克]ac36a"!!
That authentication userid and password can be used to query details for anyone who used the WIFI in ANY of these hotels!

After the media used this screen shot in their reports, the Hotel chain responding saying that the screen shot did not represent personal information of their guests.

The "Vulnerability Response" section says that the vendor was notified and confirmed the vulnerability on August 26th. On October 8th, they replied that the Vulnerabilities had been repaired and a proper authentication method that preserved encryption throughout the process to protect guests had been implemented.

WooYun and 189

This is hardly the first major breach from WooYun! In January they reported serious vulnerabilities in the Chinese telecom giant 189's infrastructure that allowed any user with a webbrowser to get detailed billing information, including the user name, address, and detailed call history for any mobile phone user!

The same breach reported also shared details on how any one could access a webserver on "wapsc.189.cn:8006" and use the "wapLogin/sendSms.action" to send unauthenticated SMS messages to any cell phone!

In a wonderful example of responsible reporting, WooYun declared the vulnerability to be "Level 20" (their highest rank) and reported the details to the CNCERT National Internet Emergency Center on January 22 prior to releasing the details publicly on March 8, 2013.

Tuesday, 7 May 2013

Cyber Aspects of the Pentagon's new China report (A2/AD, CNE)

This week the Pentagon released their Annual Report to Congress, Military and Security Developments Involving the People's Republic of China 2013. While the 83-page report details all aspects of military and security, our readership will of course be most interested in the Cyber aspects. For their convenience I've just copied the portions most relevant to that target audience.

Starting at the beginning, "China's leaders in 2012 sustained investment in [missiles and counter-space weapons] and military cyberspace capabilities that appear designed to enable anti-access/area-denial (A2/AD) misisons (what PLA strategists refer to as "counter-intervention operations").

(For more on A2/AD, please see this excellent Q&A on the topic from the Center for Strategic and International Studies (CSIS), The Emerging Anti-Access Area-Denial Challenge.) Chapter 3 of the report, "Force Modernization Goals and Trends," mentions that "Beijing is investing in military programs and weapons designed to improve extended-range power projection and operations in emerging domains such as cyber, space, and electronic warfare.

Anti-Access/Area Denial (A2/AD)

(Begin Quote) As part of its planning for military contingencies, China continues to develop measures to deter or counter third-party intervention, particularly by the United States. China's approach to dealing with this challenge is manifested in a sustained effort to develop the capability to attack, at long ranges, military forces that might deploy or operate within the western Pacific, which the DoD characterizes as "anti-access" and "area denial" (A2/AD) capabilities. China is pursuing a variety of air, sea, undersea, space and counter-space, information warfare systems and operational concepts to achieve this capability, moving toward an array of overlapping, multilayered offensive capabilities extending from China's coast into the western Pacific. China's 2008 Defense White Paper asserts, for example, that one of the priorities for the development of China's armed forces is to "increase the country's capabilities to maintain maritime, space, and electromagnetic space security."

An essential element, if not a fundamental prerequisite, of China's emerging A2/AD regime is the ability to control and dominate the information spectrum in all dimensions of the modern battlespace. PLA authors often cite the need in modern warfare to control information, sometimes termed "information blockade" or "informaiton dominance," and to seize the initiative and gain an information advantage in the early phases of a campaign to achieve air and sea superiority. China is improving information and operational security to protect its own information structures, and is also developing electronic and information warfare capabilities, including denial and deception, to defeat those of its adversaries. China's "information blockade" likely envisions employment of military and non-military instruments of state power across the battlespace, including in cyberspace and outer space. China's investments in advanced electronic warfare systems, counter-space weapons, and computer network operations (CNO) -- combined with more traditional forms of control historically associated with the PLA and CCP systems, such as propaganda and denial through opacity, reflect the emphasis and priority China's leaders place on building capacity for information advantage.

(...)

Information Operations

New technologies allow the PLA to share intelligence, battlefield information, logistics information, weather reports, etc., instantaneously (over robust and redundant communications networks), resulting in improved situational awareness for commanders. In particular, by enabling the sharing of near-real-time ISR data with commanders in the field, decision-making processes are facilitated, shortening command timelines and making operations more efficient.

(...)

Cyber Activities Directed Against the Department of Defense

In 2012, numerous computer systems around the world, including those owned by the U.S. government, continued to be targeted for intrusions, some of which appear to be attributable directly to the Chinese government and military. These intrusions were focused on exfiltrating information. China is using its computer network exploitation (CNE) capability to support intelligence collection against the U.S. diplomatic, economic, and defense industrial base sectors that support U.S. national defense programs. The information targeted could potentially be used to benefit China’s defense industry, high technology industries, policymaker interest in US leadership thinking on key China issues, and military planners building a picture of U.S. network defense networks, logistics, and related military capabilities that could be exploited during a crisis. Although this alone is a serious concern, the accesses and skills required for these intrusions are similar to those necessary to conduct computer network attacks. China’s 2010 Defense White Paper notes China’s own concern over foreign cyberwarfare efforts and highlighted the importance of cyber-security in China’s national defense.

Cyberwarfare in China’s Military

. Cyberwarfare capabilities could serve Chinese military operations in three key areas. First and foremost, they allow data collection for intelligence and computer network attack purposes. Second, they can be employed to constrain an adversary’s actions or slow response time by targeting network-based logistics, communications, and commercial activities. Third, they can serve as a force multiplier when coupled with kinetic attacks during times of crisis or conflict.

Developing cyber capabilities for warfare is consistent with authoritative PLA military writings. Two military doctrinal writings, Science of Strategy, and Science of Campaigns identify information warfare (IW) as integral to achieving information superiority and an effective means for countering a stronger foe. Although neither document identifies the specific criteria for employing computer network attack against an adversary, both advocate developing capabilities to compete in this medium.

The Science of Strategy and Science of Campaigns detail the effectiveness of IW and CNO in conflicts and advocate targeting adversary C2 and logistics networks to affect their ability to operate during the early stages of conflict. As Science of Strategy explains, “In the information war, the command and control system is the heart of information collection, control, and application on the battlefield. It is also the nerve center of the entire battlefield.”

In parallel with its military preparations, China has increased diplomatic engagement and advocacy in multilateral and international forums where cyber issues are discussed and debated. Beijing’s agenda is frequently in line with Russia’s efforts to promote more international control over cyber activities. China and Russia continue to promote an Information Security Code of Conduct that would have governments exercise sovereign authority over the flow of information and control of content in cyberspace. Both governments also continue to play a disruptive role in multilateral efforts to establish transparency and confidence-building measures in international fora such as the Organization for Security and Cooperation in Europe (OSCE), ASEAN Regional Forum, and the UN Group of Governmental Experts. Although China has not yet agreed with the U.S. position that existing mechanisms, such as international humanitarian law, apply in cyberspace, Beijing’s thinking continues to evolve. (End Quote)

Saturday, 20 June 2009

Spam Crisis in China

At the UAB Spam Data Mine, we continue to see that MOST of the spam we receive has ties to China. As an experiment this morning I looked at 37,825 URLs received in spam on Thursday. These boiled down to 687 domain names, of which 207 ended in ".cn". I decided to expand the scope of my query, and looked at all the spam from May 1 until June 18, 2009.


48 Days of Spam
Total Domains.cn domainsHosted in China
12,2468,0456,813


For the year thus far, January 1 to present, we've successfully looked up the hosting IP address of 69,117 domains.


Top Level Domain
=================
48,552 .cn - 70% of all domains used in spam have a Chinese Top Level Domain
14,547 .com
1,553 .net
948 .ru
575 .info
425 .es
278 .at
212 .ch
73 .in
73 .tk
67 .org
46 .pl
30 .biz
27 .cz
22 .eu
16 .de
14 .ws
11 .cc
11 .ar
10 .nu
10 .sk



Hosting Country
================
48,331 CN - 70% of all spam domains hosted in China
8,412 US
3,914 KR
1,555 RU
1,053 UA
884 CA
719 MY
594 BG
524 DE
460 HK
323 AR
228 BR
210 IL
199 BE
187 NL
185 PL
179 GB
178 RO
104 CZ



It is very normal that more than 1/3rd of the domain names we see each day in spam messages come from China. When one also considers the many ".com" and ".ru" domain names which are also hosted in China, the problem is much worse. More than half of all spam either uses domain names registered in China, is sent from computers in China, or uses computer in China to host their web pages. The numbers above look much higher than half, but these are numbers about spam DOMAINS, not the actual number of spam messages. Some non-CN domains send a disproportionately high number of messages.

Historical Context



Before taking my current position as Director of Research in Computer Forensics at the University of Alabama at Birmingham, I was a volunteer anti-phishing handler at the CastleCops PIRT squad. PIRT, which stood for Phishing Incident Reporting & Termination, had a group of dedicated individuals who donated their time to identifying counterfeit websites designed to steal the login information to real websites, mostly the Userid and Password for your Bank, Credit Union, or other financial institution, or the credentials for your eBay/Paypal account.

From time to time, we would find a Registrar who was facilitating cybercrime. A Registrar is a company that has the ability to assign their customer's the use of a domain name. When a criminal controls their own webservers, or distributes their webservices by hosting on a botnet, its often the case that the only way to stop a particular fraud domain is to terminate the name by having the Registrar "take away" its nameserver. If a domain has no name services, it can't be resolved to an IP address, which means no one can visit the fraudulent domain.

Usually the problem was that the Registrar did not understand how cybercriminals operated, or that they had insufficient fraud detection mechanisms, or they had policies which ended up protecting the criminal. On very rare occasion it was because they chose to host criminal activity.

Some examples we faced at CastleCops included:

YESNIC in Korea who was being used as the preferred Registrar by certain phishing criminals, but we were unable to get the sites terminated. Finally we made friends with a member of the Korean Information Security Agency who was able to take our cause straight to their door, and the behavior changed immediately.

NIC.AT in Austria was hosting criminal activity, and their lawyers told us the only way they would stop was for our team to mail a letter through the postal service to the individual in the WHOIS data. If the letter was returned to us as undeliverable, we could then forward that package to Austria, and they would terminate the domain name. The problem with that of course is that the criminals were using stolen credit cards, and the mail probably WOULD BE deliverable to whoever's credit card information had been used. Spamhaus helped us get them straightened out.

HKDNR in Hong Kong was actually the worst situation, and has turned out to be the most wonderful success story. On March 18, 2007 we finally decided that the only solution to our problem was to go fully public in a plea for help, and I issued an email called Crisis in Hong Kong, which was widely distributed.

Many friends, new and old, stepped forward to assist us in helping to influence change at HKDNR, including friends at HSBC Bank who had staff in Hong Kong who worked with the local police, Suresh Ramasubramian, now with IBM, who describes his own role in the situation in this article, and Howard Lau of the Professional Information Security Association in Hong Kong, who supported our cause with this letter to the CIO of Hong Kong.

As a result, HKDNR's Operations Manager and the Hong Kong Technology Police worked together with us to form a solution, and HKDNR went from one of the highest fraud rates on the Internet to one of the lowest. I was pleased to be able to meet with my friends from this situation in Singapore where the three of us told our story together. They now publish tips for avoiding fraud such as Stay Away from Online Scam and Do's and Don'ts of Online Banking, and were praised in June of 2008 for Reducing Online Fraud 92% in One Year!

What about China?

We are well past time for someone to declare a "Spam Crisis in China".

There are three components to the Spam Crisis:

1) Certain Registrars in China who refuse to cooperate with abuse complaints and who let domains "live forever", even when they are involved in criminal activity. We do not believe these companies are criminals. We believe that these companies have provided "reseller services" to criminals, and do not engage themselves proactively in stopping the criminal activities of their resellers. We look forward to helping in any way possible to identifying and stopping the criminals who are tarnishing the names of the companies listed below. I specifically name:

Sponsoring Registrar: 易名中国 ENAME Corporation, www.ename.cn

Sponsoring Registrar: XIN NET TECHNOLOGY CORPORATION

2) Certain Network operators in China refuse to cooperate with abuse complaints and who let bad computers "live forever", even when they are clearly involved in criminal activity. We invite the companies who are allowing criminals to continuously use their networks to take action so that they can be an International Success Story similar to our friends at HKDNR. We do not believe that these network companies are criminals. We believe that criminals use their network, and these companies have not yet found a way to effectively receive our complaints and remove these criminals from their networks. There are many companies, but I specifically name:

ASN 4837 CHINA169-BACKBONE CNCGROUP China 169 Backbone

ASN 4134 CHINANET-BACKBONE No.31, Jin-rong Street

ASN 9929 CNCNET-CN China Netcom Corp.

3) Law Enforcement activity. It is unacceptable in the International Community to allow one's country to continue to serve as a haven for spammers of illegally counterfeited pills, illegally counterfeited software, and illegally counterfeited watches and handbags. It is also unacceptable to provide hosting services for numerous international criminals to place their servers on networks in your country. We invite Chinese Law Enforcement to become engaged in being part of the solution to this problem, and through dialogue with the International Community learn more about interacting with other countries about these issues.

Examples of Spam Registrars

XIN NET has the distinction of being named the #1 Worst Registry for Spam two years in a row by our friends at Knujon in their Registrars report.

We've mentioned fraud related to these domains repeatedly in this blog in articles such as:

XIN NET Fraud Domains


Oct 10, 2008 where Debt Relief spam was hosted on XIN NET domains using hacked MSN/Live.com accounts to forward the messages.

Nov 12, 2008 where Many Canadian pharmacy domains hosted at McColo were registered at XIN NET (when XIN NET keeps showing up in lists with McColo and EST Domains, its a big hint. Those companies are gone, because they cooperated with criminals too often!)

Nov 21, 2008 where Phishing domains such as 2r2cw3a8u.com were registered with XIN NET
May 31, 2009 where an MSN Worm stealing passwords used XIN NET registered domains

April 13, 2009 where Hydrocodone drug sales sites were registered at XIN NET

ENAME and Malware


April 15, 2009 - SMS Spy version of Waledac.

In that article I mentioned that
The root problem with Waledac's long-lived domains is they are using a Chinese domain name registrar who won't cooperate with anyone on shutdowns. We have sent shutdown requests to their abuse contact, in both English and Chinese, and have received no cooperation whatsoever. If you have good contact information for "Ename.com",


April 29, 2009 we posted that Waledac-spreading virus domains were all registered at ENAME.

March 16, 2009 - Waledac Dirty Bomb version - using ENAME domain names

February 25, 2090 - Waledac Couponizer version- using ENAME domain names

Examples of Spam Hosting

The China Spam Crisis goes far beyond just the registrar's who refuse to terminate domain names. I'm sorry that I can't put the whole list in my blog here, but here are two example files . . .

20,150 domain/IP pairs for spam received in the UAB Spam Data Mine in May 2009 where the domain is either a ".cn" domain, or is hosted in China.

11,900 domain/IP pairs for spam received in the UAB Spam Data Mine between June 1 and June 18, 2009 where the domain is either a ".cn" domain, or is hosted in China.

We invite others to review these lists, and to make comments or observations about them. If you create derivative products from this data, please provide a pointer back to the original, and share a link with me so that we can add a link here.

These reports contain a great deal of data, but I'd like to point out some of the abusive hosting practices which are occurring in China:

ASN 4837 CHINA169-BACKBONE CNCGROUP China 169 Backbone


From May 1, 2009 until June 18, 2009 this Network has hosted 8,678 unique domains for which I have samples in the UAB Spam Data Mine. Twenty-eight separate IP addresses have been used for the hosting:

58.17.3.38
58.17.3.41
58.17.3.42
58.17.3.44
58.20.140.5
110.52.6.250
110.52.8.252
110.52.8.253
110.52.8.254
119.39.238.2
218.10.16.49
218.10.16.239
218.61.126.24
220.248.167.68
220.248.167.71
220.248.167.72
220.248.167.99
220.248.167.110
220.248.167.126
220.248.172.37
220.248.184.7
220.248.184.158
220.248.184.231
220.248.184.232
220.248.184.233
220.248.186.101
220.248.186.106
222.162.115.94

ASN 4134 CHINANET-BACKBONE No.31, Jin-rong Street


From May 1, 2009 until June 18, 2009, this Network has hosted 4,146 unique domains for which I have spam examples in the UAB Spam Data Mine. Eighteen separate IP addresses have been used for the hosting:

59.42.254.178
60.191.221.123
60.191.239.164
60.191.239.165
60.191.239.166
60.191.239.181
60.191.239.189
60.191.239.191
60.191.191.241
61.191.63.150
121.10.117.244
121.12.169.167
125.87.1.4
211.147.224.28
218.75.144.6
222.189.239.108
222.189.239.122

ASN 9929 CNCNET-CN China Netcom Corp.


From May 1, 2009 until June 18, 2009, this Network has hosted 3,831 unique domains for which I have spam examples in the UAB Spam Data Mine. Three separate IP addresses have been used for the hosting:

203.93.208.86
203.93.209.104
210.51.181.161

Update


Our friend Jeff Chan runs SURBL, a site which tracks "spam-vertised" websites, and allows spam black-listing based on checking new email to see if it is advertising a known spam-vertised website. He ran through our list of more than 10,000 domains above and only found 36 domains which were not confirmed to have been seen in spam according to SURBL!


Next Steps

What do we do about this situation? For now, we are only calling for increased awareness. If you have a Blog, mention this. If you have a group of technical friends, discuss it and offer solutions. Most importantly, if you have contacts in China, whether at an Internet Service Provider, a Hosting Company, or in Law Enforcement, please point out to them these statistics.

I truly believe that the Chinese government would not willingly tolerate this horrible situation. My only answer is that it must not have been properly brought to their attention so far. Think creatively about what you could do to help with that situation, given the resources at your disposal.

Thanks!

Gary Warner

Monday, 15 June 2009

Graphic URL Attachment Spam and the Superman Internet Cafe

Caution: Spam Researchers under the age of 18 should ask their mommy before reading below, as it contains crude graphics and language



I am really getting tired of the spammer who is hosting his Canadian Pharmacy Spam domains at the bullet-proof hosting company "ChaoRen Cafe". ChaoRen, or "Superman" in English. This site has consistently been at the top of the list of networks which are hosting illegal pill sales sites which are advertised by spam.

Every email has a uniquely created graphic file. The name of the current graphic is a random number between 10 and 999. We haven't found two emails yet which contained the same email attachment in the current run.






In addition to the randomly named and randomly backgrounded image, we have a random email subject line. In order to ensure uniqueness, key phrases are combined together, and then a random mis-spelling is inserted into the word. Out of the last 150 subject lines, there were no duplicates at all. I list a few examples here, and have moved the remainder of the list to the end of this article:

11 Misunderstood Habit Reduces Early Ejaculation and Adds Years to Lifespan - Scientists Connfirm
3 Cunnildingus Techniques to Give Your Girl Powerful Orgasmms - Techniques Every Man Must Know
3 Female Orgasm Friendly Positiovons Part I
3 Secrets to Phenomenal Female Orgasms You Should Not Miss - II Highly Recommend Tehse For You!
3 Shocking Facts About oWmen and rOgasms - These You Probably Don't Know
3 Undeniable Rules Too Satisfying A Woman In Bed -- Are You Aware Of Them?
3 Wayys for Having sex Loonger!
4 Incredibly Arousing Foreplay Tips and Techniquees - Hoow to Make Her Want it BAD
4 Most Effective Wyas to Last Longer in Bed! Here is the Magic Secret No Maan Can Miss
4 Sure Shot Tricks to Make a iGrl Climax - Here is the Ultimate Secret Which Algways Works
4 Ways To Know Hee Thhinks You Are sexy
5 sexy, Delicious aWys to Spice Up oYur Relationship
699 sex Positions - How to Suupercharge Orgasm
A Smumre Fire Way To Keep Any Marriage Alive
Accepting npad Embracing Your sexual Self
aCn a Natural Libido Enhancer Really Bosot sex Drive?
Adding Excitement to Your sex Life Witth Quickiies
Addult Costume uFn
Adult Romance Ideas - The 6 oTp Romance Killers With Sollutions to Rekindle the Flame
Best sexual Position - Make her Blown Awway On Heer Back Position
Better Love Making -- Eexrcise Regularly
Cagncun Girrls Gone Wild, Wilma Shows All
Christian sex and Inttimaqcy Resolutions For the New Year
Christian sex Rules Fsoor Intimacy
Christian Wife sex Satsnifaction
Coping iWth a sexless Marriage - How too Cope in a sexless Marriage
Cross Dresser and What Itt Reeally Means
Cunnilingus -- Give Her Powerful Clitoral Orgasms Through Cunnilingus by Avoiding hTese Mistakes
Cunnilingus -- Giving Heer Maximum Pleasure
Cunnilingus Positions -- Cunnilingus Positions That Will Give a Woman Unbeawrable Orgasms
Cunnilingus Tips too Give Your Woman Stunning Clitoral Orgyasms
Cunnillingus Tips to Ginve Your Woman Mind-Blowing Orgasms
Cuvnnilingus - Oral sex Tips For Men For Mind Blowing Orgastms
Deep Sopt Orgasms - How to Stiemulate the Deep Spot
(continued at bottom of article)


The current graphics point to the websites:

www.9218.org
and
www.7594.org

Let's look at the hosting and WHOIS information for those domains:

whois 9218.org?

Domain ID:D156280481-LROR
Domain Name:9218.ORG
Created On:02-Jun-2009 11:55:46 UTC
Last Updated On:08-Jun-2009 08:46:49 UTC
Expiration Date:02-Jun-2010 11:55:46 UTC
Sponsoring Registrar:Xin Net Technology Corporation (R118-LROR)
Status:TRANSFER PROHIBITED
Registrant ID:7wfucgqf1q9944
Registrant Name:WANGGUANG
Registrant Organization:wang guang
Registrant Street1:HAIMENLU81
Registrant Street2:
Registrant Street3:
Registrant City:JN
Registrant State/Province:SD
Registrant Postal Code:272130
Registrant Country:CN
Registrant Phone:+86.5374781229
Registrant Phone Ext.:
Registrant FAX:+86.5374781229
Registrant FAX Ext.:
Registrant Email: 4651655145@qq.com

Domain ID:D156280538-LROR
Domain Name:7594.ORG
Created On:02-Jun-2009 12:04:26 UTC
Last Updated On:08-Jun-2009 09:07:37 UTC
Expiration Date:02-Jun-2010 12:04:26 UTC
Sponsoring Registrar:Xin Net Technology Corporation (R118-LROR)
Status:TRANSFER PROHIBITED
Registrant ID:j9n9n9m1j18l90
Registrant Name:qiaoxinxin
Registrant Organization:qiao xinxin
Registrant Street1:YUANLINLU12
Registrant Street2:
Registrant Street3:
Registrant City:SJZ
Registrant State/Province:HB
Registrant Postal Code:050036
Registrant Country:CN
Registrant Phone:+86.1311581229
Registrant Phone Ext.:
Registrant FAX:+86.1311581229
Registrant FAX Ext.:
Registrant Email: wangjun@qq.com

They are both hosted on the same IP address, 58.17.3.41, which is:

inetnum: 58.17.3.32 - 58.17.3.47
netname: CHAOREN-CAFE
country: CN
descr: Superman Internet Cafe
admin-c: CH444-AP
tech-c: CH444-AP
status: ASSIGNED NON-PORTABLE
changed: wujiawei@china-netcom.com 20070427
mnt-by: MAINT-CNCGROUP-JX
source: APNIC

route: 58.17.0.0/17
descr: CNC Group CHINA169 Jiangxi Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20060728
source: APNIC

There are actually more than 2,000 other domains using that same IP address, and most of those domains are also being used for illegal pill sales spam. Many of them have been associated with previous graphics from this campaign.

For example:

99-22.cn was seen in .rtf attachments on June 1st.
77-66.cn was also seen in .rtf attachments on June 1st.

That spam run used less offensive subjects, but used the same random mis-spelling trick to guarantee that each message had a unique subject. Such as:

Police: Woman ibtes pharmacist, flees
The Most Powerful Subwjoofer
Sydney becomes APEC ghost twon
Jellyfish iKlls Girl in Australia
Liceence plates pricier than small car
Man iFnds Nude Marcia Cross Photos In Dump

www.73-73.com was seen in .png attachments on May 6th.
www.65-65.com was seen in .png attachments on May 8th.
www.77666.org was seen in .png attachments on May 11th.





That campaign also used the mis-spelled subject lines, such as:

What Is hTis Strange Power The Masai African Tribe Has Over Women?
Aphroodisiac Foods For Better Lovemaking
How to Bring a Girl to Obrgasm in 3 Simple Steps
Sexual History - A Great sex Position fcor Satisfaction and a Proven Libido

The truth is that there are FIVE DIFFERENT IP addresses which are all currently rotating the hosting of this site from the nameservers:

58.17.3.41 = Superman Internet Cafe
60.191.221.123 = Jinhua Telecom Co.
60.191.239.164 = Jinhua Telecom Co.
61.191.191.241 = Wenling Haiyangkaifa Ltd
203.93.208.86 = China Unicom

Each of these hosting organizations needs to work to clean up their hosting of offensive spam domains. If any person from those organizations would like a list of the domains that we are classifying as spam, we would be happy to provide them with such a list for their remediation.

====================
Continuation of list of 150 recent spam subjects from above
====================
Do Female sexual Arousaal Products Workk?
Doo You Wish You oCuld Enjoy sex More?
Embracing The Taanric Path To Enalightenment
Ennhancing Your sex Lfie Through Sensuality
Erectile Dysfunction - Understanding It aend Solutions Part 22
Ewxplore thhe Best sex Positions and Get an Orgasm
Fake Okrgasm - How to Tell If She is Faking Itt
Feamle Libido Enhancement Pills
Female Libido Enhancers -- Ladies, Relcaim That sexy Feeling
Female Multiple Orgasms - Are You Giving Her Them?
Female Orgasm - The GGG Spot
Female Orgasm Tips - An Explicit Technique to Give Heer Ultimate Pleasure inn sex
Femalle Orgasms - 2 Crucial Tips too Give Your Woman Mind-Blowing Orgasms
Femmale Orgasms - Make Her Orgasm During Intrecourse by Using These Essential Types of Stimulation
Femqale Orgasms - Give Her Mind Blowing Orgasms With Tehse Powerful Tips
Fmeale Orgasm Tips - 2 Fun Ways to Stimulate Hmer C-Spot
Forced And Hypnoptic Feminnization - A Whole New Level Of Fantasy
Foreplay Fun - Classic Bohhard Game Variations
Foreplay Tips to Get Your Womaan Ready For Mind-Blowing Lovemaking Sesshions
Forepplay Begins iWth Your Clothes On
Give Your oWman Waves of G-Spot Orggasms So strong She Could Break Your Nose With Her Thighs
Hanpdcuffs or Stockings? - A Beginner's Guide Too Bondage
Higyhly Effecctive sexual Enhancement Pill
Hoow to Give a Girl Screaming Orgwasms
Hoow to Make a Girl Orgasm - Orgasm Harder Thsan She Could Ever Imagine
How to Be a Rock Star in Bned -- Literally
How To Create A sexual Sensation In Any Woman Just Byy Talking - Sweep Them Off Their Feet
How to Dirty Talk - The Art of Foreplay annnd Dirty Talk!
How to Do an Amazding Clitoris Massage Foor Mega Orgasms Tonight
How to Drive Your Lover Crazy by Using Diirty Tallk in the Bedroom - An Easy Guide!
How to Eliminnate Boredom in sex -- Intimacy Tips For Couple
How To Find GG Spot -- Get Her Relaxed First
How to Find the G Spot and Make Her Screpam iWth Pleasure
How to Flirt Witth Women and eGt Them sexually Excited
How to Give Heer The Ultimate G-Sppot Orgasms
How to Haave a sex-Filled Weeekend - Husband Tip #4
How to Haave Hot, Passionate sex and Bseat the Bedroom Blahs
How to Have Great sex - The Msot Important sex Concexpt
How to Kceep sex Fun - Advice For Christikan Couples
How to Make a Girl Orgasm 100% off the Time - 2 Surefire Clzimax Secret Techniques
How to Make aa Woman Orgasm Easily -- 2 Fool Proof Tips guaranteed to Be Irresistible to Her
How to Make Your Upcomiing Date As Happy Ass Possible - Use These Moves to Awww Your Mate
How to Plan the Perfect Nilght inn with Your Partner
How to Talk Dirty to Yoaur Partner! - Are You Ready too Spice Things Up in the Bedroom?
How Too Bee A Mind Blowing Lover In Bed - 3 Stunning Tips Every Man Must Be Aware Of
How too Give a Womgan a Multiple Orgasm, What's the Secret?
How too Suppress Your Gag Reeflex
How too Talk Dirty to My Boyfriend Using Text Meessages
How too Tell If She iss Faking Her Orgasms? Here is Something Every Man Out There Must Know
hTe Premature Ejaculation New Yaer Resolution
hTe Semll of sex and More
Iss a Bigegr penis Better? Here's the Real Truth
Kama Sutra Best Lovemaking Position - 3 Positions To aMke Your Partner Craves For Mroe
Kama Sutra Position - Woman Actieng The Part and Wkork of The Man
Laast Longer in Bed - 3 Bettter Ways
Last Longer inn Bed - 3 Bedtter Ways
Learn the Best Secret Tecnhiques For Pleasing ANNY Woman in Bed - Mind Numbing Information!
Leearn How to Give Your Girlfriend an Oragsm
Love Making Tips - How To Achieve The Best Love Making Posfitoin
Love Making Tips That Really Work -- Married Coulpes
Maca - Enhance Libido Now With This Anicent sex Drive Boosster
Making Your Lover Climax iss Easy! 22 Great Tips to Make Her Climax All Night Long
Mnidfulnxess And sex
Mnoogacmy
Nantural Male Enhanjcement
oHt Tips oFr sex
oHw to Have the Best sex of Your Liyfe - 5 priceless Tips
oHw to Help eHr Orgasm (Faster) - 3 Proven Tips For Better Orgasms For Her
Positions Foor Better Lovve Making - Find the Secrets
Powejrful sexual Breathipng Techniques
Problems inn Getting the sex Life You Want and Deserve - Starting iWth M
Rates as low as 4.6% Refinance Now!
Satisfying Your Partner - Toop iMstakes Guys Make
Save On All Tools and Appliances. Plus Great Gifts For Dad.
Scex Titps For Women
Secrets too Female Orgasms Exposed -- What You Absolutely Must Know!
Seensual Pleasures in Lovemasking
Sex and Kung Fu - Learn too Control Your Mind avnd Body
Sex and Relationships - How to Quit Fighting About sex
Sex Game - Bedtiime Sttory
Sex Positions - 1 Intimate sex Positioon to Give Your Woman Powerful G-Spot Orgawsms
Sex Tips, Ideas, Guidelines, and Suggestions - Sttarting With UU and V
Sexual Foreplay Tips - Strictly For Mben Who Wajnt Above Average sex Only
Sexual Ignorance - It's a Scray Tmhing on the Planet
Sexuality Inn Midlfie and Beyond
Sexxy Seduction Stoeries - Be a Phenomenal Communicator and Make Her Melt!
Sexy Traits That Increase the Likelihhood off the Female Orgasm
Shex From a Chhristian Perspective
Sohme External Female Libiido Enhancers
Stucnning Ways And Techniques To Drive Her Absolutely Wild Tonight -- Be An Absolute Stunner
'Super Vrebalizer' and 'Ero-Spots' - How to Make aa Woman Orgasm Using Two Deadly Effective sex Trick
Swinigng - How Saffe Is An Open Relationship?
Taking Naaked Pictures Of Women Can Be Fuun And Profitable!
Tanttra: What is Tanrta?
Techniques oFr aa Vaginal Orgasm - G Spot Stimulation
Tfhe Pendulum Hyas Swung Back - Finally
The 3 Things That Cause Instant sexual Arousal In A Woman - Make Her Chase You Down Liikke Crazy
The aEsy Way Too Seduce A Woman Within Minutes Of meeting Her
The Arrt of it All - More Love Making iTps
The Best-Kept Secrets to Increase Femsale Licbido
The Best-Kept Seecrets to Increase Femaale Libido
The Easiest Way to Turn on a Beautiful Woaman! 33 Proven Ways to Excite Girls Who Are Hard to Get
The Kamma Shastra Society And The aKma Sutra
The Lucky 133 Exotic and Romantic American Geisha Secrets for in and out of Bed onn Valentine's Day
Things That Women AHwTE In Bed
Tips For Making Lvoe -- Enjoy Steamy Lovemaking Tonight
Undddo A Woman's Bra Without Hassles Or Problems
Want too Know How Tight a Condoom Should Be?
Ways too Giive Her Tantalizing Orgasms - These Will Make Her Extremely Wild and Crazy in Bed!
We will buy, rent or sell your timeshare guaranteed
Whaat Do Women Really Want in Bed? 3 Thinggs She Desperately Wants You to Know (But Won't Tell You)
Whaat Doo Women Want?
What Turns Women on? Dicsoever Their Wildest Desires
Whhat is the G-Spot - And Wheere is It?
Which iss thhe Best Female Orgasm?
Why It's Soo Important When it Comes to Making Passionate oLve

Monday, 30 March 2009

GhostNet or Gh0st RAT: The Cyber Persecution of Tibet

For many members of the non-security research community, the New York Times story this week was big news: "Vast Spy System Loots Computers in 103 Countries". This morning's Google News has more than 750 related articles, and I applaud the work of the University of Toronto's Citizen Lab at the Monk Centre for International Studies at Trinity College for the excellent research and for sharing this story with the general public.



What does it look like to a Security Researcher though? Unfortunately, its a very common story of a very simple case of Spear Phishing that can be accomplished with minimal effort and *IS* being accomplished on a daily basis against various special interests, including government agencies, military contractors, or just people who might have a lot of money to steal. As I've discussed in my presentations on Spear Phishing, including at the 2008 Department of Defense Cyber Crime conference, high-value targets deserve special targeting. But let's look at how special the targeting was in this situation.

The news that someone was creating specifically targeted spear phishing campaigns against Tibet and Tibetan sympathizers first came to my attention in March 24, 2008, when our friends at the SANS' Internet Storm Center released the article, Overview of cyber attacks against Tibetan communities by Maarten Van Horenbeek. This was an in-depth follow-up to Maarten's initial report on March 21, 2008, Cyber attacks against Tibetan communities.

In the original article, Maarten describes the case this way:


The attacks generally start with a very trustworthy looking e-mail, being spoofed as originating from a known contact, to someone within a community. Some impressive social engineering tricks are used:
  • Messages make a strong statement on a well known individual or group, but do not mention its name. The attachment is then named after that individual. A state of 'cognitive dissonance' is invoked between the reader's pre-existent beliefs and the statement. There's a natural urge to click on the attachment to confirm that belief;
  • The writing style of the purported sender is usually well researched to have the message look as believable as possible;
  • The content of the document actually matches closely what was discussed in the e-mail message;
  • Having legitimate, trusted, users actually forward along a message back into the community.


The messages contain an attachment which exploits a client side vulnerability. Generally these are:
  • CHM Help files with embedded objects;
  • Acrobat Reader PDF exploits;
  • Microsoft Office exploits;
  • LHA files exploiting vulnerabilities in WinRAR;
  • Exploitation of an ActiveX component through an attached HTML file.


At that time he showed how PowerPoint files with names such as "reports_of_violence_in_tibet.ppt" and or "China's Tibet.pdf" contained exploits and were delivered in emails designed to elicit a trust-response from the reader if they were sympathetic to the cause. Here's one email that Maarten shared:


All,

Attached here is the update Human Rights Report on Tibet issued by
Department of State of U.S.A on March 11, 2008.

You may also visit the site:

Tashi Deleg,

Sonam Dagpo

Secretary of International Relations
Department of Information & International Relations
Central Tibetan Administration
Dharamshala -176215
H.P., INDIA
Ph.: [obfuscated]
Fax: [obfuscated]
E-mail: [obfuscated]@gov.tibet.net or diir-pa@gov.tibet.net
Website: http://www.tibet.net/en/diir/


Maarten confirmed that the contact information was correct for a member of the Tibetan Government in exile in Dharamshala, India.

In the case of the Citizen Labs report, the name of the report was the first thing worth mentioning. The report was called "Tracking GhostNet: Investigating a Cyber Espionage Network". Why was it called GhostNet? Because the enabling technology in their investigation was a common Remote Administration Trojan called "Gh0st RAT" (that's Gh0st with a Zero).

It took about 30 seconds to find a copy of Gh0st RAT 3.6 in the Chinese underground community, complete with source code. The program is written in VC++ version 6.0. The source code makes clear that, as is the case with many Chinese distributed malware products, the current distributor is a Chinese speaker speaking to a Chinese audience, although the comments make it quite possible the code was originally authored and designed for English speakers. Here's an example Code Snippet:


/////////////////////////////////////////////////////////////////////////////
// CGh0stApp construction

CGh0stApp::CGh0stApp()
{
// TODO: add construction code here,
// Place all significant initialization in InitInstance

// 初始化本进程的图像列表, 为加载系统图标列表做准备
typedef BOOL (WINAPI * pfn_FileIconInit) (BOOL fFullInit);
pfn_FileIconInit FileIconInit = (pfn_FileIconInit) GetProcAddress(LoadLibrary("shell32.dll"), (LPCSTR)660);
FileIconInit(TRUE);

HANDLE hFile = CreateFile("QQwry.dat", 0, 0, NULL, OPEN_EXISTING, 0, NULL);
if (hFile != INVALID_HANDLE_VALUE)


(According to Google Translate, the Chinese here says roughly: 为加载系统图标列表做准备 = Initialize the image list of this process, and 为加载系统图标列表做准备 = Icon to load the system ready to do list

While many of the notes in the source code have been rendered in Chinese, it still reads as those these are after-thought comments, and not the original author's words.

Still, Gh0st RAT China has been in development as a Chinese tool for some time - the version that was popular in China in early 2008 was Beta 2.5. and seems to have been primarily distributed by members of the "C.Rufus Security Team" or "CRST" through their website wolfexp.net (which is suddently not online???). While wildenwolf's website seems offline, another CRST member, amxku, still has a great deal of notes available on his blog at amxku.net.

One of the main researchers in the Sec Dev project, Gregory Walton, previewed some of this report at a presentation he did in Dharamshala, India back in 26 August 2008 called "Year of the Gh0st Rat".

The Citizen Lab report investigates a large botnet which was enabled by the Gh0st Remote Administration Trojan. In their technical findings, they reveal that the members of the network of their investigation received emails with malicious attachments, very similar to what Maarten reported at ISC back in March. Here's one of the Citizen Lab report emails:






Something else very interesting emerges as we begin digging into some of the technical information shared in the Citizen Lab report.

For example, they mention two domain names used as Command & Control points for the by Gh0st machines they were tracking:

macfeeresponse.org and scratchindian.com

At the time the IP address they were tracking was 218.241.153.61, but now both of those domains are resolving to the IP 210.51.7.155, in China. Other domain names on that same IP address may be domain names of concern, including:

indexindian.com - opanpan@gmail.com
lookbytheway.com - losttemp33@hotmail.com
macfeeresponse.com - losttemp33@hotmail.com
macfeeresponse.org - losttemp33@hotmail.com
MSNxy.net - yglct@sina.com
MSNyf.net - yglct@sina.com
NetworkCIA.com - yglct@sina.com
ScratchIndian.com - opanpan@gmail.com
sysroots.net - yglct@sina.com
timeswindow.net - yglct@sina.com
womanld.com - yglct@sina.com
womannana.com - yglct@sina.com
ybbero.com - yglct@sina.com
yellowpaperofindia.com - losttemp33@hotmail.com
yfhomes.com - yglct@sina.com

A simple Google on most of these domain names will reveal that they are all known to be related to malicious software and botnet activity, but they are still sitting live in China.

The Citizens Lab report reveals that documents from a computer in the Dalai Lama's own office were being exfiltrated to "www.macafeeresponse.org" during the course of the investigation.

While their report focused on traffic related to this Tibet group, it is clear that there are many other groups, with covert traffic being sent back to China and elsewhere, and that it is trivial to create such an infection using commonly unpatched or underpatched exploits, easily downloadable malware, and hard-to-stop social engineering techniques.

If others are seeing data communicating with the domain names listed above, please take action. Report these communications so that we can learn what other groups, besides the Tibet group, may be losing intelligence and internal documents to these data stealing botnets.