Blog for hpHosts, and whatever else I feel like writing about ....

Wednesday, 16 June 2010

Botnets: The good, the bad and the confusing

Both Jart at HostExploit, and Pedro Bueno at McAfee, recently reported on botnets being used by the good guys, aswell as the bad. See;

http://www.internetevolution.com/author.asp?section_id=717&doc_id=193286&f_src=internetevolution_section_717

http://www.trustedsource.org/blog/422

The problem here, is that we've known for years that the bad guys were using them, and likely knew but didn't want to admit, that the good guys invariably used the same sort of tactics, to root out the bad guys. The problem is, as Jart asked, how are you supposed to tell the good from the bad?

Do you just look at the source systems, and target systems? Well no, that's not going to help you, as I found out recently, when sending a take down notice to 1 & 1 during an investigation into this, and was informed, that actually, the IP addresses had been hijacked by the good guys, for analysis purposes, or as he put it;

1&1 does not host the evil scripts or any infecting Root-Server. The [removed] rooted the Domain to their 1&1 Servers from China to our range to investigate the attacks and furhter access. So it looked like 1&1 did it. This was reported in the german media, too.


For a good guys bot to be successful, it needs to look and act, exactly the same as the bad guys bot. But this poses a huge problem, both from an ethical perspective, and a legal one.

There's several problems with the good guys using this method, and at least one of them is from a legal stand point. Thankfully I'm not a lawyer, so will leave the discussion on that one, to those more familiar with the laws regarding that than myself (as far as I'm concerned, good guys or bad, they have no right to access a system without authorization, which is what these are doing). One of the other problems is, there's no flag from the good guys bot, to enable us to identify them as good, and to be fair, we'd not believe such a flag even if there were one.

Tuesday, 15 June 2010

ALERT: metsupport.com - yet another telephone based fraud (aka SupportOnClick revisited - again)

We've got yet another domain involved in telephony based fraud folks. This time it's metsupport.com, which is housed at 74.208.232.54 (PTR: perfora.net, AS8560 74.208.0.0/16 ONEANDONE-AS 1&1 Internet AG) and registered to an entity in India (sound familiar? it should do, SupportOnClick, TechMyHelp, Comantra et al, are all based there and all involved in the same activity) called "MET", who according to DomainTools, also own a few thousand other domains (still digging to identify them).

The story sadly, is the same as the domains previously reported on. The caller phones the victim claiming to be from company x, y or z (in this case, the victim reports the tech claimed to be from "Microsoft"), and has been told by their computer that the victims machine is infected, then instructs them to view the Event Viewer to see the "evidence" of infection (as you'll already know, there's no such evidence, the Event Viewer simply reports information, warnings and errors regarding programs and Windows services).

Once conned, the victim is then asked to download remote desktop software (usually TeamViewer), to allow the tech to connect to the victims computer, and this finally ends in the victim being scammed out of hundreds of pounds.

metsupport.com was created on June 3rd 2010, and the WhoIs details show;

domain: metsupport.com
created: 03-Jun-2010
last-changed: 03-Jun-2010
registration-expiration: 03-Jun-2011

nserver: ns51.1and1.com 74.208.2.8
nserver: ns52.1and1.com 74.208.3.7

status: CLIENT-TRANSFER-PROHIBITED

registrant-firstname: Kunal
registrant-lastname: Gupta
registrant-organization: MET
registrant-street1: Surya Apt.
registrant-street2: #10,Bangur Avenue,B-Block
registrant-pcode: 700055
registrant-state: WB
registrant-city: Kolkata
registrant-ccode: IN
registrant-phone: +91.3332609070
registrant-email: ceo_met@ymail.com


The UK phone number on the website, 020 3026 3983, was purchased through a company called "Simwood eSMS Limited" (simwood.com), who are a virtual telephony service provider. Whether they're aware of their customers scamming people is unknown.

E-mail addresses known to be used by "MET" are ceo_met@ymail.com and methinkers@gmail.com. One of the other domains they own is metrusty.com, which is living on a GoDaddy IP (97.74.215.127 that's also housing such maliciousness as 24x7livefootball.info (fraud) and 24x7livecricket.info (fraud), both of which are running the all too familiar SMS fraud with the help of rdmedia.com/glomobi.com, who want to take at least £15 out of your wallet (how nice).

Update 16062010 17:37

I am happy to report, Joerg over at 1 & 1, has disabled this domain.

References

techonsupport.com, click4rescue.com, pcrescueworld.com: SupportOnClick revisited
http://hphosts.blogspot.com/2009/12/techonsupportcom-click4rescuecom.html

SupportOnClick: Phoned by Malwarebytes? BigPond? Anyone else?

http://hphosts.blogspot.com/2009/07/supportonclick-phoned-by-malwarebytes.html

SupportOnClick Update
http://hphosts.blogspot.com/2009/04/supportonclick-update.html

supportonclick.com scamming you by telephone!
http://hphosts.blogspot.com/2009/03/supportonclickcom-scamming-you-by.html

Fake tech support call scam - prefetch virus logmein123.com
http://www.digitaltoast.co.uk/fake-tech-support-call-scam-prefetch-virus-logmein123com

New scam - They call you by phone!
http://www.malwarebytes.org/forums/index.php?showtopic=11156

Staffordshire Council - Telephone computer support warning (PDF)
http://www.staffordshire.gov.uk/NR/rdonlyres/6997DBB0-E31E-4AFB-A886-C9DDEE114204/90090/TelephoneComputerSupportWarning.pdf

Cold call scam warns of virus infection
http://www.h-online.com/security/Cold-call-scam-warns-of-virus-infection--/news/112893

Scareware scammers adopt cold call tactics
http://www.theregister.co.uk/2009/04/10/supportonclick_scareware_scam

Amazon: Watch what you're paying

Browsing for prices on Amazon, I came across something that simply stopped me right in my tracks - almost £2000 for half a gig of PC133 for a desktop! (wasn't after it for a desktop, was looking for prices for PC133 SODIMMs);



Don't want to pay that for half a gig? Then you're definately not going to like this one;



There is of course, a serious point to this. There's been quite a few cases of online shops mistakenly selling things for less than they meant to, and that's obviously a good thing for the shopper. However, unless you're actually looking at the price before you click through to purchase, you could be in for one hell of a shock.

Monday, 14 June 2010

Scam Alert: news9online.org

When is an online rag, not an online rag? When it's a scam of course.

Investigating a site on Bizland IP space, that was previously carrying malicious content, I noticed an ad that immediately got my attention, and not in a good way either. There were 2 primary things wrong with it;

1. It was delivered via AdBrite - a company known for allowing very questionable adverts on their network

2. The adverts picture;



What's wrong with this picture, I hear you ask. You know what's wrong with it already of course, so you're not asking me, I'm just hearing things. Getting back, as my jokes are rubbish (can I blame too much caffeine?), the adverts clickthrough URL is;

click.adbrite.com/mb/click.php?sid=1556445&banner_id=13472994&variation_id=1759057&uts=1276543863&keyword_id=1474020&ab=171966555&sscup=0a61d052d9b1aae48b824e121046c583&sscra=67aa5e257fbea61876e86596d1111d3d&ub=3560464381&guid=933829ee-d106-4fe5-b1af-e676bbb8b4d0&odc=grx&rs=&tgt=http%3A%2F%2Fwww.news9online.org%2Fbusiness-news%2Fuk%3Ftid%3Dabuk1&sc=&adt=1&bg=12665422&rhash=8b993b0fe0d57a497eb39c573ab019df&zeid=deterministic&nsscup=8b2da98819f3852147e4c2af0a977eae&bkw=&r=

Once clicked, we're taken to a site that is claiming to be an online rag. However, there's something desperately wrong here. Besides the obvious, the story' writer is outlining steps, and the site has allowed pictures in the space usually reserved for user comment (El Reg would never allow pictures in their comment fields).

It gets even more obvious that it's a scam however, when we try clicking through to the other categories. For example, try clicking Politics, and you're taken to;

maspromo.quickckit.hop.clickbank.net/?tid=abuk1

And where does this go? Why to the scam itself of course;

quickcashkit.net

To save you some time, both news9online.org and quickcashkit.net, are on the same IP;

IP: 65.60.57.194
IP PTR: downloadgifts.com
ASN: 32475 65.60.0.0/18 SINGLEHOP-INC - SingleHop

downloadgifts.com is also on the same IP, and has some interesting name servers;

ns1.myhomewealthsystem.com (65.60.57.194)
ns2.myhomewealthsystem.com (65.60.57.195)

Both are also on SingleHop IP space, and I'll be highly surprised if the range is not on lease to JustHost (SingleHop customer that generates alot of abuse reports).

Thursday, 10 June 2010

Virgin Media + The Money Club: I wanna be a telepest!

I've just had an interesting conversation with Virgin Media. My mother has been receiving calls from 0116 225 3841 for the last 3 days, each time the phone was answered, the caller would instantly hang up without saying a word, giving the impression it's actually an automated dialer.

I traced this number back to Virgin Media, and duly called them, having tried to call the number itself (constantly said it was busy). Virgin Media' sales team informed me that it was actually their "national" team that is responsible for these nuisance calls, and put me through to them.

Speaking to the rep at the national team, I asked to speak to a manager, and was finally told a manager was on the line - but interestingly, the manager never actually spoke, instead the rep asked for the address of the property, my mothers name, my name, how I knew VM were responsible and how I traced it back to them. Finally, she told me she'd have to fill in a form to have the calls stopped, and we'll wait and see as far as whether or not that happens.

The problems here of course, is that we spoke with them last year about their doing the same thing, and were told they'd remove her number from the list - evidently they didn't. The biggest problem however, is that my mothers obviously not the only one they're doing this to, and not everyone has someone on hand that can trace the number and get the calls stopped - and we shouldn't actually have to get them to stop calling to begin with, especially when they're just instantly hanging up.

I've got a theory as far as why it's hanging up, and the theory is that it's to find out when people are likely to be in, for a future sales call, or a door step visit (VM have already done the door step visit a number of times, along with the likes of Talk Talk etc - both were told there's not a hope in hell).

However, here's the interesting twist. I wasn't satisfied with the explanation from Virgin Media, so did some more digging, and discovered the number actually belongs to a website called "The Money Club";

themoneyclub.co.uk
5k
Langley Business Centre; S
Langley
Slough
SL3 8DS
United Kingdom

Quite why Virgin Media took the blame, instead of correctly identifying it was actually *their customer* that is to blame, is beyond me. The woman I spoke to at The Money Club was rather brazen about it, and was absolutely fine with the problems they're creating for people, saying it's the easiest method for *them* (apparently not giving a damn about the people the dialer is calling). If you'd like to call 5k to get yourself removed from their list of people to annoy, you can reach them at 01753 733733.

It's worth noting the woman I spoke to, when asked why this number didn't appear on their website, advised me they've actually got over 500 numbers they're using for dialers. It's also worth noting that Companies House has no record of either "5k" or "The Money Club" (there are records for "The Money Club Ltd" and "The Money Club Direct Ltd", but neither of these are in Slough).

If you've been receiving these calls, first and foremost, report them to your service provider (Sky, BT etc), and to both OfCom and BBC Watchdog. Hopefully these people will finally get the message that these sort of tactics aren't welcome.

Finally, register with the TPS (Telephone Preference Service), a free service designed to stop nuisance marketing calls;

http://www.tpsonline.org.uk/tps/what/