Thursday, 1 November 2007

Ron Paul spam and Online Support

Do you ever write something that you think is going to be ignored, like most of the things your write, and suddenly it takes on a life of its own?

At The University of Alabama at Birmingham (UAB), I am the Director of Research in Computer Forensics. What does that mean? It means that I work on three things:

Three Things



I train students who will have CyberCrime related jobs in the future, including Computer Forensics techs, CyberCrime Investigators, Special Agents, and Computer Scientists. Some of my current students are interning with the FBI, the US Secret Service, and the Jefferson County Sheriff just to name a few places.

I do research on CyberCrime related issues, including Phishing, Spam, and Malware. Besides writing about Ron Paul Spam, I've also written about many aspects of the Storm Worm, and have had my research presented at many law enforcement and computer security meetings. My students and I meet with people working in law enforcement and struggling with CyberCrime issues and work on better solutions to these problems. Several students have seen their research projects turned in to active law enforcement investigations.

I do public awareness and training for the public and current professionals. With October being Cyber Security Awareness Month, that was a pretty busy time for me, doing presentations on Spam, Phishing, Botnets, and participating in a Threat Assessment panel for the Congressional Internet Caucus".

Phishing



With regards to phishing, I'm a member of the CastleCops PIRT Squad where our all volunteer staff works to notify webmasters, banks, and law enforcement when someone has placed a phishing site on the Internet, and to provide them data to help them shut it down, and determine who did the attack. I'm also an active member of the Digital PhishNet where I serve on the Technology Committee, and the AntiPhishing Working Group where I co-chair the Working With Law Enforcement committee.

Spam



With regards to spam, I've presented twice at the FBI's "Slam Spam" conference, and have met with more than a hundred law enforcement professionals, security researchers, and lawyers regarding spam and related issues, including the folks who run the Federal Trade Commissions anti-spam lab, which is a fine place to report spam messages -- http://www.ftc.gov/spam/. As soon as UAB is prepared to receive your spam submissions, I'll certainly let you know here!

One of the main research projects we are working on in the Computer Forensics area is our Spam Data Mine for Law Enforcement Applications. We've had a paper accepted for presentation at the Association for Computational Machinery's Symposium on Applied Computing Conference in Brazil, and continue to develop our techniques. My co-authors and co-researchers have developed algorithms that "parse" the interesting parts of incoming spam email messages, and then attempt to "cluster" the messages into groups based on similarities between the parsed attributes. We have really big really fast computers to work on this project, and as our inbound spam volume increases, we have a great team of researchers in the department who specialize in "Grid Computing" who are looking forward to helping us shape our algorithms so they can take advantage of hundreds of processors to allow even more messages to be considered in our clustering and calculations.

In future phases of this research we look forward to having new spam campaigns automatically identified and browsable on a website dedicated to this project.

All of that to make clear to the many dozens of Ron Paul Supporters who have taken their valuable time to send me their thoughts, including a few profane ones, that I am not making this crap up.

How many people do I think were behind the Ron Paul spam? One. And not one that is officially recognized in any capacity by the Ron Paul campaign.

Let me make something very clear. I never said anything that was intended to imply Ron Paul does not have a lot of online support. Is it interesting that others have seen online regularities? Yes. But that doesn't mean that there not truly a large number of online supporters. In fact, I'll go a bit beyond that and give the Paul-ites some ammunition they can use.

One online research site measures vast amounts of Internet traffic, and then makes estimates of how many UNIQUE AMERICAN COMPUTERS visit a given website. Let's look at how some of the candidate websites stack up:











Fred08.com287,000
HillaryClinton.com209,000
BarackObama.com192,000
RonPaul2008.com155,000 UNIQUE IPs
JohnEdwards.com115,000
MittRomney.com103,000
JohnMcCain.com73,000
JoinRudy2008.com68,000



Want my source? I'll bet you do. Tell the mad dogs in your midst to stop the obscene phone calls and I'll post it later. haha!

There. Gary Warner of UAB says that Ron Paul's online following is dramatically larger than the offline polls would lead one to believe.

Can we go back to talking about Viagra now?

A Dark and STORMy Night

Just in time for the spookiest night of the year, the Storm botnet recruitment spam switched to a Halloween flavor.

On the evening of October 29th, the Storm worm continued to send spam messages about funny cats or krazy kats, but the websites began to change.



By October 30, many of the spam messages we received had also been modified to match the new theme. Subjects included:

Halloween Fun
To much fun
Watch him dance
You have received an ecard

With bodies such as:

I know you will like this. Heck you might even pass it on. LOL

Just a little Halloween fun.

This thing is to fun. I sent it to everyone. I hope you don.t mind.

Someone has sent you a card to make you laugh. Come see it online!

The volume of Storm recruitment email we are receiving has dramatically reduced this month, though the botnet is still sending quite a bit of Pump and Dump spam. It seems that the Storm Botnet masters still keep track of the holidays. Fourth of July, Labor Day, First Day of NFL Season, and now Halloween.

Monday, 29 October 2007

First 2008 Presidential Spam Campaign?

Does Ron Paul suddenly have a strong support base among foreign computer owners with strange names and multiple personalities? or is it possible we have the First 2008 Presidential Spam Campaign?

I thought it odd when I logged in to my computer this morning and found an email in which someone declared Ron Paul to be the winner of the Republican Debate yesterday, but then, I have all sorts of odd friends. By the time I had received my fifteenth copy of the email, I knew this was something more than a deluded pseudo-Republican. I thought at first this was a virus, but now it seems to be a plain ole Spam Campaign.

The question, I suppose, is what should be done about it? Will we see fans of other campaigns hiring out spam campaigns devoted to extolling the views and records of their candidates? Will there be an evolving message body on the Ron Paul spam to keep pace with the upcoming events on the campaign trail? Its too early to tell, but we will continue to document the trend from the Spam Lab at UAB.

Here's the body of the email . . .





Hello Scott,

Ron Paul is for the people, unless you want your children to
have human implant RFID chips, a National ID card and create
a North American Union and see an economic collapse far worse
than the great depression. Vote for Ron Paul he speaks the
truth and the media and government is afraid of him. This is
the last honest politican left to bring this country out of
this rut from the War Profiteers and bush Administration has
created. Get motivated America, don't believe the lies of the
media he has also WON the GOP Debate On Sunday! Value Freedom
and Liberty instead of corporate lies and corruption. Bypass
this media blackout they are doing to Ron Paul, tell your family
and friends and get involved in a local group at meetup.com make
your voice heard! He will end the War In Iraq immediately,
He will eliminate the IRS and wasteful government spending, and
eliminate the Federal Reserve and restore power to the people
and the only person not a member on the CFR. Can any other runner
make these claims or give Americans the true freedom we were all
raised to believe? We are all economic slaves to the banks and the
illegal federal Reserve. This is why our currency is worth nothing
because of Hidden Inflation Tax and the IRS taking everything
you make!

** RON PAUL WILL STOP THE IRAQ WAR IMMEDIATELY! **

He has NEVER voted:
* to raise taxes
* for an unbalanced budget
* to raise congressional pay
* for a federal restriction on gun ownership
* to increase the power of the executive branch

He HAS voted:
* against the Iraq war
* against the inappropriately named USA PATRIOT act
* against regulating the internet
* against the Military Commissions Act

He will eliminate the IRS, Wasteful Government Spending &
Stop The Iraq War Immediately!

Most importantly, he voted NO on anything in Congress that
is not allowed by the Constitution. And he Despises any
politican that does not do their job for the people and lives
up to the constitution!

Google.com & Youtube.com Search: "Ron Paul"
Join The Revolution!

***************************************
We Need A Real President That Will Restore And Protect
Americans! Stop The War! Protect Our Borders!
*********VOTE RON PAUL 2008************
ubPOJg






The subject line seems to be selected from a small number of subject lines, and then appended with a random character cluster (perhaps to break spam filters?):

Subject lines:

Vote Ron Paul 2008! ZyhYKbw

Iraq Scam Exposed, Ron Paul TLshVzn

Ron Paul Exposes Federal Reserve bpIHP

Ron Paul Stops Iraq War! gPsLhM

Iraq Scam Exposed, Ron Paul wjtsLBp

Ron Paul Stops Iraq War! LcskHxT

Government Wasteful Spending Eliminated by Ron Paul vpntZRr

Vote Ron Paul 2008! pboLKjr

Who Is Ron Paul? ZTobxay

Ron Paul Exposes Federal Reserve JrZXihF

Ron Paul Stops Iraq War! LyNdrha

Ron Paul Eliminates The IRS! fiqfRZZ

Government Wasteful Spending Eliminated by Ron Paul BtkmlDF

Ron Paul Wins GOP Debate! HMzjoqO

Ron Paul Exposes Federal Reserve SBHBcSO

Government Wasteful Spending Eliminated By Ron Paul mEoHUiR

Government Wasteful Spending Eliminated By Ron Paul HRAyaaI


The spam seems to invent a random first and last name, and combine that with a true email address from the infected machine. Here are sample senders from my inbox:


curtice andrzej - sph@research-int.com - [77.181.200.157] (Germany)

byrann shan - phyllis@faxsav.com - [86.9.35.98] (the UK)

humbert jerrimy - alessand@tvldyn.com - [87.210.63.248] (the Netherlands)

jamey jamal - fataneh@i-qts.com - [124.84.175.218] (Japan)

algernon heung-do - melville@surecom.com - [124.84.175.218] (Japan)

christoforo sharad - fang@ohiohills.com - [124.84.175.218] (Japan)

fabe rosemary - hywel@msn.com - [124.84.175.218] (Japan)

hamil orlando - osulliva@surecom.com - [58.140.151.170] (Korea)

cristobal dai - irma@seagate.com - [58.140.151.170] (Korea)

frants cresswell - aziz@3com.com - [190.86.81.131] (El Salvador)

claudius quinn - avi@shoyher.com - [200.166.91.2] (Brazil)

chaim billie - mukund@atomis.com - [200.166.91.2] (Brazil)

chris field - hal@connecthouston.com - [79.3.4.33] (Italy)

alonso sidharta - cindy@e-business-associates.com - [58.141.39.110](Korea)

linn ming-hor - jikun@four-soft.com - [196.207.13.18] (Nigeria)

jerad anant - gorog@franceloisirs.com - [218.209.109.27] (Korea)

Friday, 26 October 2007

How Many Websites Can a Hacker Hack without Being Prosecuted?

Apparently the answer to that is TENS OF THOUSANDS, or more.

IskorpitX, the tutor of an entire generation of Turkish hackers, will shortly be able to claim that he has broken into 200,000 websites. (He's currently at 191,000 according to one popular hacker watching website).

Brasilian hacker, Fatal Error, runs a distant second, having broken in to "only" 32,000 websites according to the same source.

Wouldn't you say that would make them "targets of interest" for law enforcement activity? Sadly, that is not the case. Perhaps, you think to yourself, they have only attacked "low value" websites. Perhaps they are brand new to the scene? If only that were the case! Fatal Error, who lists many US Government websites, and even my home state of Alabama government websites, among his victims, has been actively attacking websites since 2002.

IskorpitX has been defacing websites since at least 2003, and has the governments of Argentina, Australia, Brazil, China, Columbia, France, India, Italy, Korea, Malaysia, Peru, the Philippines, Thailand, Venezuela and South Africa among his many victims. Of course the US government is on the list as well (such as the National Endowment for the Humanities), as well as Harvard University and Bank of America.

IskorpitX even has his own YouTube videos!

http://www.youtube.com/watch?v=ahqSeJvM2XU

http://www.youtube.com/watch?v=jTah9ckvV3Y

Other Turkish "Cyber Warriors" have even done television news interviews about why they hack websites!

http://www.youtube.com/watch?v=w4QgEsuTZrM


Here's one interesting hacker this week and the victims which are still laying around in Google's Cache:

I found it interesting because this hacker is doing SQL Exploits such as we've seen on several high profile attacks in the past including the National Institutes of Health and the United Nations. In this case, a content management system is being SQL injected to replace "titles" of things with the name of the hacker.

Google for the string "OwneD by RootDamages by FasT", and you'll find some interesting victims among the 26,100 pages being returned.

How about The Department of Veterans Affairs and their Cooperative Studies program?

www.vacsp.gov/news.cfm
www.csp.gov/news.cfm

(Although the Malaysian government also got a visit:

www.mygeoportal.gov.my/faq.cfm

Or the Michigan Bar Association?

www.michbar.org/news.cfm

Systems Integrator "Regan Technologies"?

www.rtcorp.com/news.cfm

The Esalen Center for Theory & Research still has pages with the title "OwneD by RootDamages by FasT", such as:

http://www.esalenctr.org/display/confpage.cfm?confid=10&pageid=105&pgtype=1

As does Applied Robotics:

http://www.arobotics.com/about/company_news/news_details.cfm?ID=17

But they weren't just limited to News articles. I think I'd feel very safe using a shopping cart where every product in the online store had been renamed to "OwneD by RootDamages by FasT", such as those at MetroPole360:

http://www.metropole360.com/productcat.cfm?productCatID=3

But you don't have to be a business to have an insecure webserver. Just ask the National Limousine Association, or the NorWest Dog Training Club:

http://209.85.165.104/search?q=cache:d_YOcnX94A4J:norwestdogtraining.co.nz/Newsletter.cfm

http://209.85.165.104/search?q=cache:aN6AmMtGh0kJ:www.limo.org/scriptContent/t_inside.cfm

One subject "that comes up over and over again on Ducati Online" is "OwneD by RootDamages by FasT" according to this news article:

http://www.ducati.net/faq.cfm?id=4

They're even having a conference on the topic in Brasil at the Psychology Congress. September 7th was their conference on "OwneD by RootDamages by FasT". They expected 6 thousand people to attend.

So how many websites will these hackers be allowed to deface before someone decides to arrest them?

Monday, 15 October 2007

Is Your Fifth Grader Smarter Than a Laughing Cat?

Have you seen the television show "Are You Smarter Than a Fifth Grader?" I've been thinking about a variation of that question as I consider the newest version of The Storm Worm.

This morning on the "Good Morning, Alabama" show as I discussed the Storm Worm, the weatherman laughed and said "Fortunately, I pretty much stay awy from laughing cats". So do most adults with bank accounts. Ask the question another way though. "Is there anyone who uses your computer who is into laughing cats?"

Laughing Cat Storm Worm


Twenty of the Twenty-nine anti-virus products I scanned this particular virus with (using Virus Total), did not report an infection. As of this writing, ClamAV, F-Prot, F-Secure, Microsoft, Panda, and Symantec were among the anti-virus programs who said "No Virus Found" to this current malware. ( Click for Results of this scan.)

Previous versions of the Storm Worm have used things such as Greeting Cards, an NFL Game Tracker, Labor Day greetings, Fourth of July greetings, and even Virus Alerts as means to trick people into visiting the malware site.

UAB's Computer Forensics research area will continue to study and document the storm worm until we can find a way to identify the criminals and bring them to justice.

I'll be giving a Public Lecture on Botnets this Friday (October 19th) at the Hull University Center Auditorium.

Saturday, 22 September 2007

Is the Internet a Prosecution-Free Zone?

Jörg Ziercke, the chief of the Bundeskriminalamt (BKA) in Germany, was quoted in a
press release on the BFK website, following a simultaneous phishing raid in Bad Homburg, Düsseldorf, Köln, Frankfurt and Elmshorn. His words lay down an interesting challenge:

"This case shows once more: Criminal organizations are increasingly using the Internet in order to make enormous profits with an allegedly low risk of discovery." He said that prosecutors are constantly facing new challenges regarding Cyber Crime, but that "the Internet cannot develop into a prosecution-free zone."

That's exactly what's at risk. We have to decide whether the Internet is going to be patrolled and prosecuted just like the streets and alleys of our cities, or whether we are going to allow crime to occur unabated there.

In the BKA case, two women, aged 22 and 23, and six men, aged from 20 to 36 years old, have been imprisoned pending their court appearance. Two others are also charged but were not taken into custody.

Sounds good, and congratulations to the BKA! But what about all the other phishers? So far in September, we've made positive confirmation on more than THREE THOUSAND phishing sites in UAB's Computer Forensics Research lab. We can't continue to allow it to take 18 months before a phishing investigation leads to charges.

The more evidence we gather, and the more relationships we find between phishing campaigns, the greater the chance that we can get some law enforcement action.

Remember, if you hear of someone who has been a victim of Identity Theft, Phishing, or any other Cyber Crime, please make sure they fill out a complaint at the Internet Crime and Complaint Center, http://www.ic3.gov/.

Also, if there has not been a financial loss, phishing sites still need to be reported! When you receive a phishing email, please help by sending it to:

pirt@castlecops.com

or by using the webform at:

http://www.castlecops.com/pirt

Let's make sure the Internet doesn't become a "Prosecution-Free Zone".

Tuesday, 4 September 2007

TJX: From Florida to the Ukraine?

Last week the media lit up with speculations that 24 year old Ukrainian hacker, Maksym Yastremskiy, who had been arrested in Turkey on August 2nd, may be behind the TJX Credit Card hack. The Boston Globe's Ross Kerber may have had the best coverage with his story "Suspect
named in TJX credit card probe"
on August 21. The story quoted Greg Crabb of the US Postal Inspection Service's global investigations division. Crabb said Maksym was "likely the largest seller of stolen TJX numbers". TJX, the financial company in the TJ Maxx conglomerate, believes that as many as 45.7 million credit cards were stolen during a breach during 2005 and 2006, which captured credit card transactions all the way back to 2003.

How's your Turkish? This August 2nd article , "Antalya'da yakalanan Ukraynalı hacker 80 bin kişiyi dolandırmış", interviews Turkish police officer, Feyzullah Arslan, who arrested Maksym after a sting in a luxury night club in Kerem, Turkey.



Using a "follow-the-money" investigative technique, the investigation began with 10 guilty pleas in Florida back in March from a crew of careless cyber criminals who had racked up millions of dollars of purchases from Wal-Mart and other Florida retailers using stolen credit cards that tracked back to TJX. The Florida investigation actually started when Gainesville police were contacted regarding two local Wal-Mart stores who had made individual gift-card sales in the amounts of $18,000 and $24,000. HINT: IF SOMEONE WANTS $24,000 IN WAL-MART GIFT CARD, THERE MAY BE A CRIME LYING ABOUT.

Those cards were used at a Sam's Club in Miami, along with many other cards, to buy large quantities of electronics and jewelry. At that time, the cards were all tracked back to TJX, and an estimate of the loss from the database hack was released in the news -- Gainesville police Sergeant Ray Barber revealed "They estimate the loss from that hack job to be around $8 million", although this particular crew had only rung up $1 million in charges so far. (See, for example: "Florida police make arrests in TJX, Winners credit card theft".

The first six, arrested March 19, were:

Irving Jose Escobar, 18
Reinier Camaraza Alvarez, 27
Julio Oscar Alberti, 33
Dianelly Hernandez, 19
Nair Zuleima Alvarez, 40
Zenia Mercedes Llorente

All ten, including the additional:

Erick Fernandez Rodriguez
Hector Alfaro Rodriguez
Alexis Arcia
Armando Ochoa

have Mugshots posted on eweek.com.




In a USA Today story a map of Irving Escobar's shopping spree, where he bought as many as 60 $400 gift cards in a single location, and then spent the money from November 1st to January 18th, is mapped out.



The big break in this first case came when an alert Wal-Mart employee followed the gift card purchases out of the store and recorded their license plate number. (For more, see the March 24, 2007 Boston Globe story by Ross Kerber, quoted here: Scam May Be Tied to Stolen TJX Data

A second Florida-based TJX gang plead guilty in late June. This group was charged with possessing 172,000 sets of credit card data, which had been used to make at least $75 Million in bogus credit card charges. Arrested in this scam were:

Miguel Alegria, 46, of Hialeah, FL
Raynier Pupo, 22, of Miami, FL
Ariel Montero, 32, of Aventura, FL
Javier Padron-Bravo, 35, of Aventura, FL
Julio Lopez, 30, of Hialeah, FL
and Anett VIllar, 26, of Hialeah, FL



Alegria, Pupo, Montero, and Padron-Bravo plead guilty to conspiracy in exchange for a plea agreement that included cooperation.

The Nashville Secret Service ran the investigation as "Operation Blinky" named for the first suspect's online name, which they co-opted as an undercover identity. For more see: TJX, Polo Data Surfaces In Another Credit Card Bust.