Blog for hpHosts, and whatever else I feel like writing about ....

Tuesday, 3 November 2009

Are you helping the Facebook botnet?

We've had various phishing botnets over the years, and this one is no different, well, almost. I received several e-mails claiming to be from Facebook, with the following content;

facebook

Dear Facebook user,
In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security.
Before you are able to use the new login system, you will be required to update your account.

Click here to update your account online now.
If you have any questions, reference our New User Guide.
Thanks,

The Facebook Team Update your Facebook account

Update

This message was intended for a1aaa1azzzz1zaaaaa@it-mate.co.uk.
Facebook's offices are located at 1601 S. California Ave., Palo Alto, CA 94304.


Plain text is a little messy, so here's a screenshot;



Once you load this, and pop in your password etc, you're taken to the following screen;



http://www.facebook.com.vvvaszxx.eu/globaldirectory/MyAccount.php
http://www.facebook.com.pppiod.eu/globaldirectory/MyAccount.php
http://www.facebook.com.pppioz.eu/globaldirectory/MyAccount.php

This tells you;

In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security. Before you are able to use the new login system, you will be required to update your account.
A new Facebook Update Tool has been released for your account. Please download and install the tool using the link below:


The file offered, updatetool.exe (MD5: b245eb505f49f88e124c0ae2988d2fe9), is of course malware.

Payload:
http://www.facebook.com.vvvaszxx.eu/globaldirectory/updatetool.exe
http://www.facebook.com.pppiod.eu/globaldirectory/updatetool.exe
http://www.facebook.com.pppioz.eu/globaldirectory/updatetool.exe

hpHosts entry:

http://hosts-file.net/?s=www.facebook.com.vvvaszxx.eu
http://hosts-file.net/?s=www.facebook.com.pppiod.eu
http://hosts-file.net/?s=www.facebook.com.pppioz.eu

Someone's already beaten me to VT with this one (not surprisingly, it's a Zbot variant), and it shows a measly 7 vendors detecting it;

VirusTotal result:
http://www.virustotal.com/analisis/12f028e654dd35182905a3413082cee0e92df22099739f6516143986c9628e6a-1257207933

Anubis result:
http://anubis.iseclab.org/?action=result&task_id=1e18837e806b75744e57310de488fba61

Incase you're wondering by the way, the folks responsible for this are the same folks responsible for both the previous phishing and malware campaigns, and for the current IRS phishing and malware campaign;

http://hosts-file.net/?s=www.irs.gov.pppiod.eu/fraud_application/directory/statement.php

Payload (VT #1 VT #2):
http://www.irs.gov.pppiod.eu/fraud_application/directory/tax-statement.exe
http://www.irs.gov.vvvaszxx.eu/globaldirectory/tax-statement.exe
http://www.irs.gov.pppioz.eu/globaldirectory/tax-statement.exe



IP's seen thus far:

IP Address AS# Hostname
112.152.65.97 (0) 17858 Resolution failed
114.37.100.39 (2) 3462 114-37-100-39.dynamic.hinet.net
115.22.11.185 (1) 4766 Resolution failed
117.195.238.67 (0) 9829 Resolution failed
119.201.184.155 (0) 4766 Resolution failed
122.124.130.158 (2) 3462 122-124-130-158.dynamic.hinet.net
122.254.241.9 (0) 17871 Resolution failed
123.195.226.68 (2) 9924 123-195-226-68.dynamic.kbronet.com.tw
124.120.17.143 (0) 17552 ppp-124-120-17-143.revip2.asianet.co.th
125.208.81.28 (1) 17849 Resolution failed
190.174.24.185 (0) 22927 190-174-24-185.speedy.com.ar
201.239.155.181 (1) 22047 pc-181-155-239-201.cm.vtr.net
211.172.68.226 (0) 18310 Resolution failed
211.203.144.69 (0) 9318 Resolution failed
211.58.98.242 (2) 9318 Resolution failed
218.158.65.44 (0) 4766 Resolution failed
220.91.81.239 (2) 4766 Resolution failed
222.157.114.2 (1) 7482 Resolution failed
71.11.234.135 (3) 20115 71-11-234-135.dhcp.ftwo.tx.charter.com
77.239.70.153 (1) 42571 153-70.telrad.net
77.52.52.167 (0) 21497 77-52-52-167.dialup.umc.net.ua
85.202.49.44 (0) 43939 cb44.osiedle.net.pl
88.216.136.50 (1) 33922 c-136-50.marinet.lt
89.208.248.251 (1) 12695 Resolution failed
91.89.60.107 (2) 29562 HSI-KBW-091-089-060-107.hsi2.kabelbw.de
92.115.218.172 (7) 8926 host-static-92-115-218-172.moldtelecom.md
93.89.214.131 (3) 45025 as45025-93-89-214-131.mol.net.ua
94.189.154.183 (0) 31042 cable-94-189-154-183.dynamic.sbb.rs
95.111.215.187 (0) 31343 Resolution failed
95.68.71.163 (1) 12578 Resolution failed

You're going to be seeing alot of these if the past campaigns are anything to go by, and it's pretty much a guarantee that there's going to be more than just the afformentioned domains involved. If you receive any of these, please do forward them to me (with the original headers if possible);

phishing @ it-mate.co.uk

Monday, 2 November 2009

virscan.org ripoff

"Serious" over the Malwarebytes forums alerted me to a site that was suspected of ripping off the VirScan.org site (provides a service along the lines of VirusTotal), www.hrppw.com.cn.

I fired off an e-mail to the virscan.org guys to see if they knew anything about it and appears they weren't aware of it. I thought I'd upload a file to see how exactly they were doing this, whether they were actually running this on their site, or simply submitted to the real virscan.org site and lifting the results, but alas, all I got when trying to check this was;



I've not yet gone through the sites source code and Javascript files to check this yet.

The site is hosted not surprisingly, in China at;

AS: 4134 222.75.128.0/18 CHINANET-BACKBONE
IP: 222.75.167.61

Domain Name: hrppw.com.cn
ROID: 20070409s10011s43854380-cn
Domain Status: ok
Registrant Organization: zhoukaidong
Registrant Name: 周开东
Administrative Email: 6809830@qq.com
Sponsoring Registrar: 北京众鑫乾坤网络科技有限公司
Name Server:ns1.namerich.com
Name Server:ns2.namerich.com
Registration Date: 2007-04-09 17:45
Expiration Date: 2010-04-09 17:45

inetnum: 222.75.167.0 - 222.75.167.127
netname: CHINANET-NX
descr: XBEMY-SCHOOL
country: CN
admin-c: CH93-AP
tech-c: ZL127-AP
mnt-by: MAINT-CHINANET-NINGXIA
changed: security110@163.com 20071210
status: ASSIGNED NON-PORTABLE
source: APNIC

person: Chinanet Hostmaster
nic-hdl: CH93-AP
e-mail: anti-spam@ns.chinanet.cn.net
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: dingsy@cndata.com 20070416
mnt-by: MAINT-CHINANET
source: APNIC

person: zhaolong li
address: 44 jiefangdong street,ningxia,750001,
address: china
country: CN
phone: +86-951-6018000
fax-no: +86-951-6019000
e-mail: lzl@public.yc.nx.cn
nic-hdl: ZL127-AP
mnt-by: MAINT-NEW
changed: lzl@public.yc.nx.cn 20010220
source: APNIC


Google shows this site previously existed on the same IP, as deepwow.com, and with identical content;

http://209.85.229.132/search?q=cache:CEvmmB-JV3YJ:deepwow.com/report/d9b2db5851315e997645e3a035eb1904.html+%22deepwow.com%22&cd=1&hl=en&ct=clnk&gl=uk

Domain Name : deepwow.com
PunnyCode : deepwow.com
Creation Date : 2008-10-13 13:25:49
Updated Date : 2008-10-13 13:25:47
Expiration Date : 2009-10-13 13:25:41

Registrant:
Organization : zhang lei
Name : zhang lei
Address : zheng zhou
City : zheng zhou
Province/State : Henan
Country : cn
Postal Code : 450003

Administrative Contact:
Name : zhang lei
Organization : zhang lei
Address : zheng zhou
City : zheng zhou
Province/State : Henan
Country : cn
Postal Code : 450003
Phone Number : 86-0371-60132888
Fax : 86-0371-60132888
Email : tissot28244428@sina.com

Technical Contact:
Name : zhang lei
Organization : zhang lei
Address : zheng zhou
City : zheng zhou
Province/State : Henan
Country : cn
Postal Code : 450003
Phone Number : 86-0371-60132888
Fax : 86-0371-60132888
Email : tissot28244428@sina.com

Billing Contact:
Name : zhang lei
Organization : zhang lei
Address : zheng zhou
City : zheng zhou
Province/State : Henan
Country : cn
Postal Code : 450003
Phone Number : 86-0371-60132888
Fax : 86-0371-60132888
Email : tissot28244428@sina.com

WhoIs server: whois.paycenter.com.cn

IOBit Steals Malwarebytes’ Intellectual Property

Malwarebytes Corporation have recently published information on their blog, concerning the stealing of the Malwarebytes Anti-Malware database by China based, IObit.

Malwarebytes has recently uncovered evidence that a company called IOBit based in China is stealing and incorporating our proprietary database and intellectual property into their software. We know this will sound hard to believe, because it was hard for us to believe at first too. But after an indepth investigation, we became convinced it was true. Here is how we know.

We came across a post on the IOBit forums that showed IOBit Security 360 flagging a specific key generator for our Malwarebytes’ Anti-Malware software using the exact naming scheme we use to flag such keygens: Don’t.Steal.Our.Software.A.

Dont.Steal.Our.Software.A, File, G:\Nothing Much\Anti-Spyware\Malwarebytes’ Anti-Malware v1.39\Key_Generator.exe, 9-30501

Why would IOBit detect a keygen for our software and refer to it using our database name? We quickly became suspicious. Either the forum post was fraudulent or IOBit was stealing our database.

So we dug further. We accumulated more similar evidence for other detections, and we soon became convinced that this was not a mistake, it was not a coincidence, it was not an isolated event, and it persisted presently in their current database. They are using both our database and our database format exactly.


Read more
http://malwarebytes.besttechie.net/2009/11/02/iobit-steals-malwarebytes-intellectual-property/

Because of this, IOBit have been re-added to hpHosts with the FSA classification.

Sunday, 1 November 2009

New Honeypot Mimics The Web Vulnerabilities Attackers Want To Exploit

A next-generation Web server honeypot project is under way that poses as Web servers with thousands of vulnerabilities in order to gather firsthand data from real attacks targeting Websites.

Unlike other Web honeypots, the new open-source Glastopf tool dynamically emulates vulnerabilities attackers are looking for, so it's more realistic and can gather more detailed attack information, according to its developers. "Many attackers are checking the vulnerability of the application before they inject malicious code. My project is the first Web application honeypot with a working vulnerability emulator able to respond properly to attacker requests," says Lukas Rist, who created Glastopf.

Rist, a student, built Glastopf through the Google Summer of Code (Gsoc) 2009 program, where student developers write code for open-source projects. His Web honeypot was one of the Honeynet Project's Gsoc projects.

Unlike other Web honeypots that use templates posing as real Web apps, Glastopf basically adapts to the attack and can automatically detect and allow an unknown attack. Glastopf uses a combination of known signatures of vulnerabilities and also records the keywords an attacker uses when visiting the honeypot to ensure it gets indexed in search engines, which attackers often use to find new targets. The project uses a central database to gather the Web attack data from the Glastopf honeypot sensors installed by participants who want to share their data with the database.


Read more
http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=221300001&cid=RSSfeed

PayPal phish: Dear Mr Scammer .....

There seems to be a trend over the past 6 months, of switching from links directly in the phishing e-mails, to having the entire phishing page in the e-mail itself (as an attachment). Others in the security arena have already publicised this for the most part, so I'll skip over the details.

I wonder however, why our dear scammer has done this. I know it's to try and bypass phishing and junk filters, but given they still need to process the details they're stealing, they're not making it any harder to stop them. It takes two seconds for me to open up the attachment in an editor and identify the URL the details will be submitted to, or the user will be taken to, and pop that into any number of the available blaclists (or if I can, simply have the site/server shut down). All they're doing, is making it far easier for us, to say "hey victim, notice the attachment? your e-mail client will (if using Outlook for example) already block known malicious extensions, so just err, don't open the rest of them and you'll be fine for the most part".

In addition, whilst average Joe is already taken in quite frequently, by phishing scams, I'd hope (yep, I know) they'd see it and think "hang on a second, my bank/PayPal whatever, is an actual site not an attachment" (I know what you're going to say here, so I'll save you the trouble - the problem is, as much as we'd like it not to, this does actually sometimes work, users are far too gullible). Point is, most gullible users (I hate that word too) run whatever security was pre-installed, so Norton, McAfee, etc etc, which whilst mostly useless, does actually stop *some* phishing scams, and IE with it's SmartScreen filters, will still block those identified as phishing scams, so this isn't going to make the scammers life any easier.

The URL in this case anyway, is;

http://218.6.15.141/soft/fun/complete.php

Which simply redirects to PayPal if accessed directly (and will do the same for the victim, once it's saved the details they entered into the form that's contained in the attachment they're sent).

The IP, 218.6.15.141, belongs to AS4134 CHINANET-BACKBONE, a range well known for everything from exploits to phishing, to pretty much everything else. My personal recommendation is to block the entire /16 (218.6.0.0-218.6.255.255), but that's just me (I've seen far too much malicious activity across all of the CHINANET-BACKBONE ranges, with only a handful of legit sites being seen).

As an aside, I have noticed the hpHosts server having sporadic timeout issues when displaying query results (e.g. Netblock information when querying an IP), and am looking into this.