CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

Evidence Required

 
Post new topic   Reply to topic       All -> FavForums -> Knujon General Discussion [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2884

Blue Security Premium

PostPosted: Fri May 02, 2008 9:53 pm    Post subject: Evidence Required
Reply with quote

A request for evidence from law enforcement. Perhaps Knujon may have some examples in their archives


Herbal King Spam from your archives?

Do you have any samples of spam sent to Hong Kong
(with a ".hk address). I only need approx 10 samples in total of
Herbal King Spam sent from 12 October 2007 to 16 December 2007.


Full headers please, unobfuscated. They will not be published electronically, just produced in court evidence.

Back to top
View users profile Send private message Visit posters website AIM Address
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1033
Location: USA

PostPosted: Sat May 03, 2008 5:07 am    Post subject:
Reply with quote

May want to try the contact at knujon address, Knujon doesn't appear too active on the forums as of late....but I'm sure they could come up with some samples. Smile

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2705

Premium

PostPosted: Wed May 07, 2008 8:58 pm    Post subject:
Reply with quote

ahoier wrote:
May want to try the contact at knujon address, Knujon doesn't appear too active on the forums as of late....but I'm sure they could come up with some samples. Smile


...only if Knujon has participants with "@domain.hk" email addresses. There are lots of spamtraps, but the .hk address is the element that may not be so easy to come up with after the fact.

Back to top
View users profile Send private message
Knujon

Captain
Captain
Premium Member

Joined: May 25, 2006
Posts: 585
Location: USA
Premium

PostPosted: Wed May 21, 2008 2:04 pm    Post subject:
Reply with quote

Here's the problem with the herbal king. We've got lots of data on them but my guess is that they are distributed and deployed by kits. What we have may not match the specific incident in question. This situation requires some higher level planning and coordination since the whole picture is going to stretch across jurisdictions.

Back to top
View users profile Send private message Visit posters website
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1033
Location: USA

PostPosted: Wed May 21, 2008 3:33 pm    Post subject:
Reply with quote

As AC rephrased, samples of Herbal King spam sent to .hk (hong kong) addresses is what's requested Smile

Now.....I can understand, with all the data you guys are processing, pin-pointing ALL spam that contains a .hk address in the To: or Delivered-To area of the headers, could take a long time, depending on how advanced your search/data queries can be.

And even then, how would that affect evidence if a .hk address was forged/munged into the To:

If your system isn't this advanced, to create a query, and display the results of something like this, perhaps it might be something to look into expanding on, as I feel it could greatly help.

Overall, I don't think the problem here is anything with jurisdictions. But perhaps could lead to a greater investigation if evidence that matches this criteria has been submitted Smile

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Knujon

Captain
Captain
Premium Member

Joined: May 25, 2006
Posts: 585
Location: USA
Premium

PostPosted: Wed May 21, 2008 3:40 pm    Post subject:
Reply with quote

We looked, we can find things pretty quickly. The issue is that herbal king is a moving target with lots of affiliates. The whole things needs to be taken out at the same time.

Back to top
View users profile Send private message Visit posters website
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2705

Premium

PostPosted: Wed May 21, 2008 3:47 pm    Post subject:
Reply with quote

Red's not looking for things mailed from Hong Kong, just things with a recipient who is a resident of Hong Kong (or uses a HK mail service). It doesn't matter which affiliates, as we aren't being told whose head is in the noose yet.

All you need to filter is the "To" line, which isn't going to be forged like a "From" line. It all depends whether you have any submitters in Hong Kong -- if so, you'll have a lot of Elite Herbal spam, if you don't have a submitter in HK, you won't have any of their spam mailed to HK.

Back to top
View users profile Send private message
Knujon

Captain
Captain
Premium Member

Joined: May 25, 2006
Posts: 585
Location: USA
Premium

PostPosted: Wed May 21, 2008 3:57 pm    Post subject:
Reply with quote

Understood, I believe that is the case since we don't have any .hk clients.

Back to top
View users profile Send private message Visit posters website
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1033
Location: USA

PostPosted: Thu May 22, 2008 5:00 am    Post subject:
Reply with quote

darn Sad


I was about to edit my post, but it got too late and had to leave to work Razz But AC summed it up quite nicely.

hmmm...where do .hk users hang out on the web? lol....orkut? myspace? Razz Knujon advertising might be good lol.


hmm. wonder if Paul could grab/sort the CC members database by e-mail address, to see if we have any .hk users here....? - and nudge them, to see whether or not they have any specimens? lol.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Knujon General Discussion All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer