CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

storm worm spam
Goto page Previous  1, 2, 3, 4, 5  Next
 
Post new topic   Reply to topic       All -> FavForums -> Spam [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2856

Premium

PostPosted: Thu Dec 27, 2007 4:55 pm    Post subject:
Reply with quote

Regardless of the laws in Russia, they can create their own acceptable use policies and anyone who registers a domain with them must agree to them. If distributing malware doesn't violate their corporate AUP, they are purposefully siding with the criminals. They've got enough pages of documents specifying how they are going to get paid, and it seems the only penalty even for false whois information is that they won't let you renew or transfer the domain.

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1813
Location: Japan
Premium

PostPosted: Fri Dec 28, 2007 1:18 am    Post subject:
Reply with quote

And while we are fighting yesterday's domain name, "they" are already a step ahead: 'newyearcards2008.com' offering download file 'happynewyear2008.exe'.

Registrar: ANO REGIONAL NETWORK INFORMATION CENTER DBA RU-CENTER
Registered: 2007-12-26
Hosted again on countless hijacked machines all over the world.
Reported to MIRT.
Complaint sent to nic.ru by email & fax.

Back to top
View users profile Send private message Visit posters website
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2930

Blue Security Premium

PostPosted: Fri Dec 28, 2007 6:03 am    Post subject:
Reply with quote

Botnet Scanner report

Scanned the fast-flux network of infected IPs used for the Storm New Years cards infection for 2 days.

IPs detected: 3715
IPs reported: 3715
Reports sent to ISPs: 600

ISPs with largest number of infections:

1. SBC Global (US) (Pacbell, Ameritech, SWBell etc)
2. Comcast (US)
3. RoadRunner (US)

Back to top
View users profile Send private message Visit posters website AIM Address
maques

Trooper
Trooper


Joined: Dec 27, 2007
Posts: 10
Location: Hungary

PostPosted: Fri Dec 28, 2007 3:55 pm    Post subject:
Reply with quote

New domain: newyearwithlove.com

Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Fri Dec 28, 2007 4:19 pm    Post subject:
Reply with quote

maques wrote:
New domain: newyearwithlove.com
http://www.securityzone.org/?p=33
http://blogs.pcmag.com/securitywatch/2007/12/a_stormy_new_year.php

Back to top
View users profile Send private message
maques

Trooper
Trooper


Joined: Dec 27, 2007
Posts: 10
Location: Hungary

PostPosted: Fri Dec 28, 2007 9:35 pm    Post subject:
Reply with quote

Open letter to RU-CENTER [tld-ncc /@/ nic.ru]
( CastleCops Link/postx211215-0-30.html)

According to your policy described at:
http://www.nic.ru/about/en/servpol.html#2.2

In reference to:
"2.1.1. User shall not perform any actions that may result in:
d) damage or the possibility of damage to any other User or any third party;"

I would like to ask you, in the name of the Internet Community to apply the following:
"2.3.1. RU-CENTER may apply the following sanctions to Users that violate the provisions of Subsection 2.1:
a) suspend or refuse the provision of any or all Services;
b) take steps to stop User from violating the Terms of Use."

to the following domains:

uhavepostcard.com
merrychristmasdude.com
happycards2008.com
newyearcards2008.com
newyearwithlove.com

and any other that you might be aware of, registered in the last days with the same method, characteristics [name/relation to new year] and/or data like the above ones.

Thank you for your cooperation.

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2930

Blue Security Premium

PostPosted: Sat Dec 29, 2007 7:34 am    Post subject:
Reply with quote

The Russian CERT Center is also notified of the requirement to remove those domain names.

Whack a few more moles

Back to top
View users profile Send private message Visit posters website AIM Address
Randy67

Corporal
Corporal


Joined: May 18, 2006
Posts: 61
Location: USA

PostPosted: Sat Dec 29, 2007 5:33 pm    Post subject: new domain
Reply with quote

To the tune of celebration. A very happy New Year
hxxp://familypostcards2008.com/


If it's of any use, here's the SpamCop.net URL for the spam.

h$$p://www.spamcop.net/sc?id=z1590044173z1933822cb8dbec0d9901468b4e3972aez

Back to top
View users profile Send private message
maques

Trooper
Trooper


Joined: Dec 27, 2007
Posts: 10
Location: Hungary

PostPosted: Sun Dec 30, 2007 2:55 pm    Post subject:
Reply with quote

New one: freshcards2008[.com]

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2856

Premium

PostPosted: Sun Dec 30, 2007 3:46 pm    Post subject:
Reply with quote

(oops -- duplicate)

I had been checking these daily variants with Virustotal and Jotti and posting the poorly detected one (all of them) on the unknown files forum, but their new sites won't let you do it without turning off noscripts. Since I know zilch about java, I haven't wanted to try that.

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2930

Blue Security Premium

PostPosted: Sun Dec 30, 2007 11:54 pm    Post subject:
Reply with quote

12 new domain names registered Dec 29 for Storm distribution are listed in the EU Spam Wiki
http://www.spamtrackers.eu/wiki/index.php?title=Storm#December_29

Back to top
View users profile Send private message Visit posters website AIM Address
roberto78
Warnings : 1

Sergeant
Sergeant


Joined: Feb 20, 2007
Posts: 114


PostPosted: Mon Dec 31, 2007 6:09 pm    Post subject: News from spamhaus.org on the Storm Worm Botnet:
Reply with quote

From spamhaus.org:

Quote:
"While many registrars are very cooperative, others have not yet addressed the problem. In this case the Storm worm people have registered their domains through Nic.ru. This does not look like a coincidence, because thus far Spamhaus has been unable to establish contact with Nic.ru to have the domains involved shut down. Of course it is the holiday season, but we assume that even Nic.ru has a 24/7 staff to keep things running and to react to serious issues."


Quote:
"This is a very serious issue, involving a massive flood of spam designed to infect many thousands of end-user machines. Due to the fast-flux nature of the hosting only Nic.ru can effectively put a halt to this malware disguised as a fake greeting card, stop thousands of internet users from becoming infected with the Storm worm and becoming senders of spam right after that. Unfortunately, Nic.ru has failed to react to all of our efforts at contacting them. Given the huge impact of the Storm worm, the impact Nic.ru can have by suspending the domains involved and their failure to react promptly, Spamhaus has no other option than to list critical parts of their infrastructure in SBL to get their attention. Holiday season or not, organizations like Nic.ru need to react when alerted to serious problems like these."


News from spamhaus.org on the Storm Worm Botnet:
http://www.spamhaus.org/news.lasso?article=624

Back to top
View users profile Send private message
roberto78
Warnings : 1

Sergeant
Sergeant


Joined: Feb 20, 2007
Posts: 114


PostPosted: Thu Jan 03, 2008 1:56 pm    Post subject:
Reply with quote

From Spamhaus.org:-> http://www.spamhaus.org/news.lasso?article=624

Quote:

The only fast and effective way of shutting down a fast-flux hosted website is to shut down the domains involved. If the domains are removed from the TLD rootservers they cannot be resolved anymore, this makes the fast-flux hosted websites unreachable. The only party that can shut down a domain is the registrar where the domain was registered. With the advent of fast-flux hosting, registrars now have a critical role in enforcing a policy against spam. That is why Spamhaus sees it as an absolute must that registrars keep in touch with--and react to--today's spam & virus issues.

News from spamhaus.org on the Storm Worm Botnet:
http://www.spamhaus.org/news.lasso?article=624

See there: CastleCops Link/f287-Complainterator.html

and more on Complainterator here http://weblog.complainterator.com/ and http://spamtrackers.eu/wiki/index.php?title=Complainterator
and http://www.complainterator.com/

For more informations on complainterator.com, see there:
http://www.aboutus.org/ComplaintErator.com
http://www.google.com/search?q=complainterator
http://www.siteadvisor.com/sites/complainterator.com

Back to top
View users profile Send private message
chao284

Guest
IP: 24.16.*.*






PostPosted: Sat Jan 05, 2008 12:27 am    Post subject:
Reply with quote

roberto78

One problem, as since last night I have been unable to connect to spamhaus, it keeps timing out and my tracert says the domain is still active, could this mean my ISP might harboring a DDoS bot the Storm Worm is using that is causing spamhaus to timeout my connection?

Back to top
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2856

Premium

PostPosted: Sat Jan 05, 2008 2:02 am    Post subject:
Reply with quote

I can get Spamhaus fine right now, and it was okay last night for me, too. Comcast certainly has plenty of storm-infested computers on their network, and spamhaus is under pretty much perpetual DDoS from what I understand. But because Comcast has so many users on dynamic IP addresses, it's harder for DDoS targets to just block entire IP ranges as they are also blocking a lot of legitimate users. It's possible that the last time you logged on, you were assigned an IP address recently used by a bot. You could find out by trying a proxy, or disconnecting from the internet long enough to get a new IP address assigned. Also, I don't know the details of cable internet -- do other people in your neighborhood share the same IP address?

Or, you could be infected yourself.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Spam All times are GMT
Goto page Previous  1, 2, 3, 4, 5  Next
Page 3 of 5

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer