Wednesday, 21 October 2009

Scareware Serving Conficker.B Infection Alerts Spam Campaign

A fake "conficker.b infection alert" spam campaign first observed in April, 2009 (using the following scareware domains antivirus-av-ms-check .com; antivirus-av-ms-checker .com; ms-anti-vir-scan .com; mega-antiviral-ms .com back then) is once again circulating in an attempt to trick users into installing "antispyware application", in this case the Antivirus Pro 2010 scareware.

This campaign is directly related to last week's Microsoft Outlook update campaign, with both of these using identical download locations for the scareware.

The following is an extensive list of the domains involved in the campaigns:
abumaso3tkamid .com - Email: drawn@ml3.ru
afedodevascevo .com - Email: sixty@8081.ru
alertonabert .com - Email: flop@infotorrent.ru
alertonbgabert .com - Email: vale@e2mail.ru
alioneferkilo .com - Email: va@blogbuddy.ru
anobalukager .com - Email: chalkov@co5.ru
anobhalukager .com - Email: humps@infotorrent.ru
bufertongamoda .com - Email: kurt@8081.ru
buhafertadosag .com - Email: bias@co5.ru
buhervadonuska .com - Email: vale@e2mail.ru
bulakeskatorad .com - Email: bias@co5.ru
bulerkoseddasko .com - Email: bias@co5.ru
buleropihertan .com - Email: def@co5.ru
celiminerkariota .com - Email: morse@corporatemail.ru
certovalionas .com - Email: kurt@8081.ru
dabertugaburav .com - Email: def@co5.ru
elxolisdonave .com - Email: curb@cheapmail.ru
enkafuleskohuj .com - Email: kerry@freemailbox.ru
ertanueskayert .com - Email: xmas@co5.ru
ertonaferdogalo .com - Email: kerry@freemailbox.ru
ertu6nagertos .com - Email: recipe@isprovider.ru
ertubedewse .com - Email: weak@infotorrent.ru
ertugasedumil .com - Email: chalkov@co5.ru
ertugaskedumil .com - Email: humps@infotorrent.ru
ertunagertos .com - Email: def@co5.ru
erubamerkadolo .com - Email: kerry@freemailbox.ru

fedostalonkah .com - Email: bias@co5.ru
ftahulabedaso .com - Email: raced@corporatemail.ru
gumertagionader .com - Email: seize@e2mail.ru
huladopkaert .com - Email: chute@infotorrent.ru
iobacebauiler .com - Email: roy@corporatemail.ru
itorkalione .com - Email: pygmy@8081.ru
julionejurmon .com - Email: jacob@freemailbox.ru
julionermon .com - Email: pygmy@8081.ru
konitorsabure .com - Email: chalkov@co5.ru
konitorswabure .com - Email: humps@infotorrent.ru
lersolamaderg .com - Email: chalkov@co5.ru
lersolamgaderg .com - Email: humps@infotorrent.ru
linkertagubert .com - Email: kerry@freemailbox.ru
lionglenhrvoa .com - Email: sixty@8081.ru
liposdakoferda .com - Email: leaf@corporatemail.ru
lopastionertu .com - Email: cues@e2mail.ru
nebrafsofertu .com - Email: humps@infotorrent.ru
nuherfodaverta .com - Email: morse@corporatemail.ru
nulerotkabelast .com - Email: dealt@8081.ru
nulkersonatior .com - Email: dealt@8081.ru
obuleskinrodab .com - Email: xmas@co5.ru
ofaderhabewuit .com - Email: kerry@freemailbox.ru
okavanubares .com - Email: chalkov@co5.ru
okaveanubares .com - Email: humps@infotorrent.ru

onagerfadusak .com - Email: cues@e2mail.ru
orav4abustorabe .com - Email: drawn@ml3.ru
oscaviolaner .com - Email: larks@freemailbox.ru
ovuiobvipolak .com - Email: sixty@8081.ru
ovuioipolak .com - Email: bias@co5.ru
paferbasedos .com - Email: chalkov@co5.ru
pafersbasedos .com - Email: humps@infotorrent.ru
polanermogalios .com - Email: dealt@8081.ru
rdafergfvacex .com - Email: jacob@freemailbox.ru
rtugamer5tobes .com - Email: drawn@ml3.ru
rtugamertobes .com - Email: kw@co5.ru
scukonherproger .com - Email: kazoo@isprovider.ru
shuretrobaniso .com - Email: frail@infotorrent.ru
tarhujelafert .com - Email: raced@corporatemail.ru
tavakulio5nkab .com - Email: recipe@isprovider.ru
tavakulionkab .com - Email: def@co5.ru
tertunavogav .com - Email: la@freemailbox.ru
tertunwavogav .com - Email: drawn@ml3.ru
tsabunerkadosa .com - Email: humps@infotorrent.ru

tsarbunerkadosa .com - Email: humps@infotorrent.ru
tubanerdavaf .com - Email: chalkov@co5.ru
tubanerdavjaf .com - Email: halkov@co5.ru
uhajokalesko .com - Email: flop@infotorrent.ru
uhajokvfalesko .com - Email: flop@infotorrent.ru
ulioperdanogad .com - Email: vale@e2mail.ru
uliopewrdanogad .com - Email: kerry@freemailbox.ru
uplaserdunavats .com - Email: dealt@8081.ru
utka3merdosubor .com - Email: drawn@ml3.ru
utkamerdosubor .com - Email: kw@co5.ru
utorganedoskaw .com - Email: kerry@freemailbox.ru
utorgtanedoskaw .com - Email: xmas@co5.ru
uvgaderbotario .com - Email: def@co5.ru
vudermaguliermot .com - Email: leaf@corporatemail.ru
vuilerdomegase .com - Email: leaf@corporatemail.ru
vuilleskomandar .com - Email: seize@e2mail.ru
vulertagulermos .com - Email: dealt@8081.ru
vuretronulevka .com - Email: dealt@8081.ru
weragumasekasuke .com - Email: kazoo@isprovider.ru
werynaherdobas .com - Email: dealt@8081.ru

Despite the comprehensive portfolio of domains used, relying on spam to increase revenue from scareware sales is prone to fail, in this specific case due to the lack of event-based social engineering theme, something that was present in the first campaign.

ChoicePoint to pay $275,000 in latest data breach

By Elinor Mills
InSecurity Complex
CNet News
October 20, 2009

ChoicePoint, one of the nation's largest data brokers, has been fined $275,000 by the U.S. Federal Trade Commission for a data breach that exposed personal information of 13,750 people last year.

In April 2008, ChoicePoint turned off a key electronic security tool that it used to monitor access to one of its databases and failed to notice the problem for four months, according to an FTC statement.

During that period, unauthorized searches were conducted for 30 days on a ChoicePoint database that contained Social Security numbers and other sensitive information, the FTC said.

The FTC alleged that ChoicePoint's conduct violated a 2006 court order requiring the company to institute a comprehensive information security program following a 2005 breach that compromised the personal information of more than 163,000 people and resulted in at least 800 cases of identity fraud. The company was ordered to pay $10 million in civil penalties and $5 million to consumers in that case.

Tuesday, 20 October 2009

Classified Info on Dangerous Chemicals Hacked

The Korea Times
10-17-2009

Hackers stole classified information on dangerous chemicals in their raid on the South Korean army computer network in what was believed to be an attack by North Korea, Yonhap News Agency reported Saturday, quoting government officials.

The Chemicals Accident Response Information System, used by 589 South Korean government agencies including fire and police stations, was accessed by hackers on March 5. Hackers appear to have broken into the system using the ID of a South Korean army officer whose personal computer was infected by a virus, according to officials.

"We believe the hacker tapped into the system using the ID, withdrawing classified information of 1,350 dangerous chemicals," an army official was quoted as saying by Yonhap. "The government believes North Korea could be behind the hacking. We are continuing our investigation."

The revelation comes less than three months after cyber attacks severely slowed or disrupted dozens of South Korean government and business Web sites, including those of the presidential office and ministries of defense and foreign affairs. Rumors were rampant then that North Korean hackers orchestrated the attacks, although they have yet to be substantiated.

"We are trying to find out exactly how much information has been withdrawn," another unnamed official at Seoul's Environment Ministry was quoted as saying, adding the government has asked organizations dealing with the chemicals to tighten security.

Unnamed intelligence sources in Seoul said in May that North Korea operates a cyber warfare unit that seeks to disrupt South Korean and U.S. military networks and visits U.S. military sites more frequently than any other country.

South Korea and the U.S. signed a memorandum of understanding on April 30 to bolster cooperation in fighting cyber terrorism against their defense networks.

VoIP hack suspect fugitive extradited back to US

By John Leyden
The Register
19th October 2009

A Venezuelan hacking suspect arrested in Mexico last February on computer hacking and fraud charges faces a court appearance in New Jersey on Tuesday, following his extradition to the US last week.

Edwin Pena, 26, a former Miami resident, fled from US justice in August
2006 two months after he was bailed on charges of hacking into phone systems and stealing VoIP call credits. Pena allegedly resold these services in collusion with an accomplice, Robert Moore of Washington.
Pena and Moore raked in an estimated $1.4m through the alleged sale of 10 million voice call minutes stolen from telecoms suppliers.

Moore pleaded guilty multiple computer hacking and fraud offences in late 2007, resulting in a two year jail sentence. His admitted involvement in the scam involved scanning telecom supplier networks for vulnerabilities between June 2005 and October 2005. Pena, the alleged brains of the operation and major beneficiary, use Moore's reconnaissance to draw up a list of targets for attack.

The Venezuelan used brute force techniques to extract activation codes from vulnerable telecom supplier systems. Among those victimised was a Newark, New Jersey supplier of telecoms services.

Medical Records: Stored in the Cloud, Sold on the Open Market


By Kim Zetter
Threat Level
Wired.com
October 19, 2009

When patients visit a physician or hospital, they know that anyone involved in providing their health care can lawfully see their medical records.

But unknown to patients, an increasing number of outside vendors that manage electronic health records also have access to that data, and are reselling the information as a commodity.

The revelation comes in a recent New York Times article about how so-called "scrubbed" patient data isn't as anonymous as people think.
The piece focuses primarily on how anonymized data can be cross-bred with other publicly available databases, such as voting records, which subverts the anonymity. Buried near the end of the article is the news that medical data is collected, anonymized and sold, not by insurance agencies and health care providers, but by third-party vendors who provide medical-record storage in the cloud.

Electronic health record (EHR) services have been a growing industry in the last few years, according to Sue Reber, marketing director of the Certification Commission for Health Information Technology. Reber says most vendors used to simply sell software packages; once the product was sold, the vendor had no connection to the data stored in it. But an increasing number of companies have begun to offer web-based software-management applications that include database storage controlled and managed by the vendor.

Botnet Unleashes Variety Of New Phishing Attacks


By Kelly Jackson Higgins
DarkReading
Oct 19, 2009

The massive Zbot botnet that spreads the treacherous Zeus banking Trojan has been launching a wave of relatively convincing phishing attacks during the past few days -- the most recent of which is a phony warning of a mass Conficker infection from Microsoft that comes with a free "cleanup tool."

The wave of attacks began early last week targeting corporations in the form of email messages that alerted victims of a "system upgrade." Email is accompanied by poisoned attachments and links; in some cases it poses as a message from victims' IT departments, including their actual email domains, and alerts them about a "security upgrade" to their email accounts. The message then refers victims to a link to reset their mailbox accounts, and the link takes them to a site that looks a lot like an Outlook Web Access (OWA) page (PDF), but instead infects them with the Zeus Trojan.

Today, researchers at F-Secure spotted the botnet spamming out malware-laden email that tries to trick recipients with a convincing lure messages that says, "On October 22, 2009 server upgrade will take place."

"What we're seeing is an evolving campaign of different lures to see which one works," says Richard Wang, manager of Sophos Labs in the U.S.

The Zbot botnet, which is made up of 3.6 million PCs in the U.S., or 1 percent of all PCs in the country, according to data from Damballa, spreads the deadly Zeus Trojan. Zeus, which steals users' online financial credentials, represents 44 percent of all financial malware infections today, according to Trusteer.

Monday, 19 October 2009

Terrible DailyMail journalist, linking artice. Jan Moir What Have u Written

Artice ltake from Dailymail. Not sure how long Mrs Moir is going to have ajob for..

A strange, lonely and troubling death . . .



Stephen Gately

Dead at 33: Stephen Gately

The news of Stephen Gately's death was deeply shocking. It was not just that another young star had died pointlessly.

Through the recent travails and sad ends of Michael Jackson, Heath Ledger and many others, fans know to expect the unexpected of their heroes - particularly if those idols live a life that is shadowed by dark appetites or fractured by private vice.

There are dozens of household names out there with secret and not-so-secret troubles, or damaging habits both past and present.

Robbie, Amy, Kate, Whitney, Britney; we all know who they are. And we are not being ghoulish to anticipate, or to be mentally braced for, their bad end: a long night, a mysterious stranger, an odd set of circumstances that herald a sudden death.

In the morning, a body has already turned cold before the first concerned hand reaches out to touch an icy celebrity shoulder. It is not exactly a new storyline, is it?

In fact, it is rather depressingly familiar. But somehow we never expected it of him. Never him. Not Stephen Gately.

In the cheerful environs of Boyzone, Gately was always charming, cute, polite and funny.

A founder member of Ireland's first boy band, he was the group's co-lead singer, even though he could barely carry a tune in a Louis Vuitton trunk.

He was the Posh Spice of Boyzone, a popular but largely decorous addition.

Gately came out as gay in 1999 after discovering that someone was planning to sell a story revealing his sexuality to a newspaper.

Although he was effectively smoked out of the closet, he has been hailed as a champion of gay rights, albeit a reluctant one.

At the time, Gately worried that the revelations might end his ultra-mainstream career as a pin-up, but he received an overwhelmingly positive response from fans. In fact, it only made them love him more.

In 2006, Gately entered into a civil union with internet businessman Andrew Cowles, who had been introduced to him by mutual friends Elton John and David Furnish.

Last week, the couple were enjoying a holiday together in their apartment in Mallorca before their world was capsized.
Boyzone

Boyzone: Gately and his bandmates had a hugely successful career and had recently reformed

All the official reports point to a natural death, with no suspicious circumstances. The Gately family are - perhaps understandably - keen to register their boy's demise on the national consciousness as nothing more than a tragic accident.

Even before the post-mortem and toxicology reports were released by the Spanish authorities, the Gatelys' lawyer reiterated that they believed his sudden death was due to natural causes.

But, hang on a minute. Something is terribly wrong with the way this incident has been shaped and spun into nothing more than an unfortunate mishap on a holiday weekend, like a broken teacup in the rented cottage.

Consider the way it has been largely reported, as if Gately had gently keeled over at the age of 90 in the grounds of the Bide-a-Wee rest home while hoeing the sweet pea patch.

The sugar coating on this fatality is so saccharine-thick that it obscures whatever bitter truth lies beneath. Healthy and fit 33-year-old men do not just climb into their pyjamas and go to sleep on the sofa, never to wake up again.


More...

* Boyzone to play gig of their lives at Stephen Gately's funeral as police reveal his final few hours
* Stephen Gately smoked cannabis on night he died, civil partner tells Spanish police
* Louis Walsh pulls out of X Factor show to attend 'best friend' Stephen Gately's funeral

Whatever the cause of death is, it is not, by any yardstick, a natural one. Let us be absolutely clear about this. All that has been established so far is that Stephen Gately was not murdered.

And I think if we are going to be honest, we would have to admit that the circumstances surrounding his death are more than a little sleazy.

After a night of clubbing, Cowles and Gately took a young Bulgarian man back to their apartment. It is not disrespectful to assume that a game of canasta with 25-year-old Georgi Dochev was not what was on the cards.

Cowles and Dochev went to the bedroom together while Stephen remained alone in the living room.
Andy Cowles
Georgi Dochev

Gately's civil partner, Andrew Cowles, left, and Bulgarian student Georgi Dochev, right, were at the apartment on the night of the singer's death

What happened before they parted is known only to the two men still alive. What happened afterwards is anyone's guess.

A post-mortem revealed Stephen died from acute pulmonary oedema, a build-up of fluid on his lungs.

Gately's family have always maintained that drugs were not involved in the singer's death, but it has just been revealed that he at least smoked cannabis on the night he died.

Nevertheless, his mother is still insisting that her son died from a previously undetected heart condition that has plagued the family.

Another real sadness about Gately's death is that it strikes another blow to the happy-ever-after myth of civil partnerships.

Gay activists are always calling for tolerance and understanding about same-sex relationships, arguing that they are just the same as heterosexual marriages. Not everyone, they say, is like George Michael.

Of course, in many cases this may be true. Yet the recent death of Kevin McGee, the former husband of Little Britain star Matt Lucas, and now the dubious events of Gately's last night raise troubling questions about what happened.

It is important that the truth comes out about the exact circumstances of his strange and lonely death.

As a gay rights champion, I am sure he would want to set an example to any impressionable young men who may want to emulate what they might see as his glamorous routine.

For once again, under the carapace of glittering, hedonistic celebrity, the ooze of a very different and more dangerous lifestyle has seeped out for all to see.
Tara Palmer-Tomkinson: Too old for this look




Read more: http://www.dailymail.co.uk/femail/article-1220756/A-strange-lonely-troubling-death--.html#ixzz0UOGo8pwf

emails

a

The Register - Security

IQ test

The Register - Security: Anti-Virus

HackWire - Hacker News