Thursday, March 29, 2007

Beware fake IE 7 downloads

There is spam out there that tries to get you to download IE 7.  It’s fake, of course.  When you click on the image, you are then offered to download a trojan (Sunbelt Sandbox analysis here, VirusTotal results here).  Antivirus coverage is mediocre.


Fakeie123123123123


And just for fun, check out the source code of this spam.


Alex Eckelberry

Brilliant!

I’m going to give you a sneak peek of a very cool skunkworks project going on over at Mayhemic Labs

One thing that a lot of people have commented on (and particularly the good folks over at F-Secure) is that phishers register domains using words like “Chase”, “ebay”, etc.  This makes it easier to foil their victims (such as having a URL like “chase-banking-center.com). 

Of course, a great idea is to have the domain registrars simply refuse to register domains with these names (or at least trigger a review of a suspicious domain before allowing it to register).  However, that’s not always easy to get done. 

But what if new suspicious domain registrations were automatically tracked in a format that allows everyone to see what’s going on?


That’s just what Ben Jackson did over at Mayhemic Labs: He developed a “Domain Tracker System” to track domain registrations by using DomainTools' Domain Mark reports


Called the Crow's Nest,  it aggregates submissions of domain mark reports containing keywords that would be likely used in a phishing domain. The system processes these reports and adds them into a database. The submitter (or other volunteers) can then flag domains that look suspicious. These domains are then monitored for activity. Every 6 hours registration and DNS records are checked to see if the domain is hosted and or still registered. If the site is hosted, the user can then check the site and see if something phishy is going on, and if so, notify the parties affected.


Phishtrack_2131231231


Phishtrack_2131231232


For now, this site is only being used by security researchers. There’s also lots of people who helped him in this, and when it goes public, I’m sure he’ll thank those that don’t mind being publlicly acknowledged.  

Expect this site to be public in a few weeks.  And then those Phishers will feel a whole lot of hurt.  


Alex Eckelberry 

Tuesday, March 27, 2007

Best. Spam. Ever.

Bestspamever00099123


 


Alex Eckelberry

Fun with HDR

Over the holidays, I bought myself a Canon Rebel XTi as a Christmas present.  It’s my first digital SLR (I have an analog 35 mm SLR and plenty of digital point and shoots, but never made the leap to digital SLR) and I’ve been learning slowly but surely, with a bit of help from Robert LaFollette, Sunbelt’s creative director (and an uber-guru on photography). 

One area I’ve been playing with is HDR (High Dynamic Range), using PhotoMatix.  I love the effect but there are tricks to learn to do it well.  Of course Robert’s done plenty of HDR and he sent me this incredible HDR photo he took in Miami a few weeks ago.

Hdr0000123

You can see more of Robert’s pics here.  And if you want to see lots of HDR flicks, there’s also a HDR section on Flickr.


Alex Eckelberry

Castro's new side gig

Normally from a group associated with running haxdoor monstrosities, we see this opportunity to be a mule.



Your task as a Smart Transfer manager will consist in transferring payments from one of our clients to another.

Due to the fact that our company works in securities market, we constantly buy and sell payments, so you will work with this money. Also there will be tasks to receive charity money from our donators worldwide and resend them to our HQ for future resending.

 Your profit depends on how fast money circulates in the world transaction system. You have nothing to loose while doing this one-click job. Just check your email for a message from us with information about wire transfer to your checking account and instructions what to do with it. The faster you send the money further, the higher numbers of transfers to process you get. No office work, no need in special financial skills, flexible timetable. You choose work time yourself. 1-2 hours of occupation a day. For each transaction you will get 140$.

  For the first month you should receive about 15 transactions, later, depending on your speed and accuracy you can get more. You will get paid on the 10th day from your first transfer, and after that monthly. We guarantee that you receive at least 15 transfers a month, what makes minimal payment of 2100$.


Omegai1003888


Registered to Fidel Castro in Havana. Cuba libre!


Alex Eckelberry
(Thanks Patrick)

What's wrong with this picture?

BankFinancia1112l

Alex Eckelberry
(Thanks Eaglewolf and the PIRT team)

Supporting spyware

The practice of advertising in spyware directly supports spyware itself.  It’s something that’s garnered some attention, with the New York AG’s office coming to a settlement in January with three major online advertisers over the matter.

However, Ben Edelman shows how this practice is continuing. 



“…despite their duties to the NYAG, both Cingular and Travelocity have failed to sever their ties with spyware vendors. As shown in the six examples below, Cingular and Travelocity continue to receive spyware-originating traffic, including traffic from some of the web's most notorious and most widespread spyware, in direct violation of their respective Assurances of Discontinuance. That said, Priceline seems to have succeeded in substantially reducing these relationships -- suggesting that Cingular and Travelocity could do better if they put forth appropriate effort.”


It’s worth noting that advertisements are typically placed through third party advertising networks (to see how this works, read my earlier blog entry here).  Because they are using an intermediary, some advertisers may claim that they can’t control where their ads are placed, which is a crock. Just because you buy ads through a third-party ad network does not mean you can’t control it. For example, when one major security software company found its products being advertised inadvertently in spyware, they found the source and clamped down — and this is a company that advertisers a lot online.  The same goes for a number of other companies. 

To avoid getting ads placed in spyware, an advertiser can, at the least, a) choose third party ad networks that have a demonstrated track record of not placing ads in spyware and b) make the third party ad network attest in writing that they will not place your ads in spyware. 

Things have gotten better in the third party ad network side.  When AOL bought Advertising.com, they immediately dumped $100 million in business that was being done through spyware.  And a number of other third party ad networks are clamping down, refusing to advertise through spyware programs.

But as Ben writes, it’s still happening.  And that money spent by advertisers directly supports the makers of spyware.


Alex Eckelberry