<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Krebs on Security &#187; Brett Stone-Gross</title>
	<atom:link href="http://krebsonsecurity.com/tag/brett-stone-gross/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 23 May 2012 14:03:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Spam &amp; Fake AV: Like Ham &amp; Eggs</title>
		<link>http://krebsonsecurity.com/2011/07/spam-fake-av-like-ham-eggs/</link>
		<comments>http://krebsonsecurity.com/2011/07/spam-fake-av-like-ham-eggs/#comments</comments>
		<pubDate>Tue, 26 Jul 2011 23:17:10 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[Web Fraud 2.0]]></category>
		<category><![CDATA[Brett Stone-Gross]]></category>
		<category><![CDATA[Canadian Pharmacy]]></category>
		<category><![CDATA[fake AV]]></category>
		<category><![CDATA[Glavmed]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Peter Severa]]></category>
		<category><![CDATA[ROKSO]]></category>
		<category><![CDATA[Sevantivir]]></category>
		<category><![CDATA[spamhaus]]></category>
		<category><![CDATA[Spamit]]></category>
		<category><![CDATA[Steven Belfort]]></category>
		<category><![CDATA[UCSB]]></category>
		<category><![CDATA[waledac]]></category>
		<category><![CDATA[Win32.Kelihos.b]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=10831</guid>
		<description><![CDATA[An explosion of online fraud tools and services online makes it easier than ever for novices to get started in computer crime. At the same time, a growing body of evidence suggests that much of the world's cybercrime activity may be the work of a core group of miscreants who've been at it for many years.

I recently highlighted the financial links among the organizations responsible for promoting fake antivirus products and spam-advertised pharmacies; all were relying on a few banks in Azerbaijan to process credit card payments. ]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2011%252F07%252Fspam-fake-av-like-ham-eggs%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Spam%20%26%20Fake%20AV%3A%20Like%20Ham%20%26%20Eggs%22%20%7D);"></div>
<p>An explosion of online fraud tools and services online makes it easier than ever for novices to get started in computer crime. At the same time, a growing body of evidence suggests that much of the world&#8217;s cybercrime activity may be the work of a core group of miscreants who&#8217;ve been at it for many years.</p>
<p>I recently highlighted the <a title="Azeri Banks Corner Fake AV, Pharma Market" href="http://krebsonsecurity.com/2011/07/azeri-banks-corner-fake-av-pharma-market/" target="_blank">financial links</a> among the organizations responsible for promoting fake antivirus products and spam-advertised pharmacies; all were relying on a few banks in Azerbaijan to process credit card payments.</p>
<p>In this segment, I&#8217;ll look at the personnel overlap between the fake AV and pharma industries. The data is drawn from two places: a study done by researchers at the <strong>University of California, Santa Barbara</strong> (UCSB) that examined three of the most popular fake AV affiliate services which pay hackers to foist worthless software on clueless Internet users; and <a title="Spamit, Glavmed Pharmacy Networks Exposed" href="http://krebsonsecurity.com/2011/02/spamit-glavmed-pharmacy-networks-exposed/" target="_blank">the leaked Glavmed/Spamit affiliate database</a>, which includes the financial and contact information for many of the world&#8217;s top spammers and hackers.</p>
<p>UCSB researcher <strong>Brett Stone-Gross</strong> and I compared the ICQ instant message numbers belonging to affiliates from Glavmed/Spamit with the ICQ numbers used by affiliates of the largest of the fake AV programs measured by his research team. The result? 417 out of 998 affiliates who were registered with the fake AV distribution service &#8212; <strong><em>a whopping 42.2 percent</em></strong> &#8212; also were registered pharma spammers with Glavmed/Spamit.</p>
<p><span id="more-10831"></span>Unfortunately, the other two fake AV affiliate programs had not stored affiliate ICQ numbers in their databases, so we needed to find another basis for examining users of these programs. Instead, we looked for common email addresses among affiliates of the three fake AV programs and for affiliates of Glavmed/Spamit. This is almost certainly a conservative measure of overlap, because miscreants tend to change email addresses more frequently than they adopt new ICQ numbers. Even so, we found that the rate of email address overlap was high, between 19 and 27 percent across all programs:</p>
<p><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2011/07/avoverlap.png"><img class="aligncenter size-full wp-image-10851" title="avoverlap" src="http://krebsonsecurity.com/wp-content/uploads/2011/07/avoverlap.png" alt="" width="493" height="105" /></a></p>
<p>STRADDLING BOTH WORLDS</p>
<p>A textbook example of this overlap was a key Spamit member, a hacker named &#8220;Severa.&#8221; Prior to <a title="Spam Affiliate Program Spamit.com to Close" href="http://krebsonsecurity.com/2010/09/spam-affialite-program-spamit-com-to-close/" target="_blank">Spamit&#8217;s shutdown in September 2010</a>, Severa was a moderator of the &#8220;spam&#8221; section on the site (like most cybercrime forums, Spamit had sections dedicated to a range of criminal enterprises).</p>
<p><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2011/07/spamdothome.png"><img class="alignright size-medium wp-image-10859" title="spamdothome" src="http://krebsonsecurity.com/wp-content/uploads/2011/07/spamdothome-300x152.png" alt="" width="300" height="152" /></a>Severa is short for <strong>&#8220;Peter Severa</strong>,&#8221; a Russian who is listed at #5 on <strong>Spamhaus</strong>&#8216;s <a title="Spamhaus's ROKSO" href="http://www.spamhaus.org/statistics/spammers.lasso" target="_blank">Register of Known Spam Operations</a> (ROKSO). According to Spamhaus, Severa is one of the longest operating criminal spam-lords on the Internet. Severa advertises his spamming services on several invite-only cyber crime forums.</p>
<p>Until last month, Severa ran a fake antivirus distribution affiliate program called<strong> Sevantivir</strong>, which seems to have counted among its ranks a large number of Glavmed/Spamit members (Sevantivir is <strong>not</strong> one of the three fake AV services included in the UCSB study).</p>
<p>It appears that Severa has been using his fake AV affiliate program to generate new infections for the botnet that powers his spamming service. Last month, I reached out to French security blogger <strong>Steven K.</strong>, after reading one of his posts about a different fake AV affiliate program. I showed Steven an easy way to obtain a malware download from the Sevantivir affiliate Web site, and he spent the next couple of days <a title="Tracking Cyber Crime: Severa and Black Software AV" href="http://xylibox.blogspot.com/2011/06/tracking-cyber-crime-severa.html" target="_blank">studying the malware</a>.</p>
<p><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2011/07/sevdownload.png"><img class="alignleft size-medium wp-image-10861" title="sevdownload" src="http://krebsonsecurity.com/wp-content/uploads/2011/07/sevdownload-300x296.png" alt="" width="300" height="296" /></a>Steven discovered that the malicious installer that Sevantivir affiliates were asked to distribute was designed to download two files. One was a fake AV program called Security Shield. The other was a spambot that blasts junk email pimping Canadian Pharmacy/Glavmed pill sites. The spambot is detected by Microsoft&#8217;s antivirus software as <a title="Win32.Kelihos" href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Backdoor%3aWin32%2fKelihos.A" target="_blank">Win32.Kelihos.b</a>. According to Microsoft, Kelihos.b <a title="Kelihos and Waledac Separated at Birth" href="http://blogs.technet.com/b/mmpc/archive/2011/01/11/kelihos-and-waledac-separated-at-birth.aspx" target="_blank">shares large portions of its code</a> with the <strong>Waledac worm</strong>, an infamous worm that for several years was <a href="http://www.sunbeltsecurity.com/ThreatDisplay.aspx?tid=4068504&amp;cs=BE6DB614B76D1A38C28164ECDD5D8162" target="_blank">synonymous with Canadian Pharmacy spam</a>.</p>
<p>Microsoft targeted the Waledac botnet last year in <a href="http://blogs.technet.com/b/mmpc/archive/2010/03/02/waledac-botnets-and-rsa.aspx" target="_blank">a sneak attack on its control infrastructure</a>. Microsoft does not consider this Kelihos.b worm to be in the same family as Waledac, <a href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230" target="_blank">as claimed by some researchers</a>.  Microsoft states: &#8220;Based on our analysis, we have classified this as a new family and not a variant of Waledac. It is important to note that this new family is not communicating with nor is it reactivating the original Waledac which had its command and control infrastructure neutralized last year.&#8221;</p>
<p>Stay tuned for the final story in this series, which will look at how recent events have impacted the fake AV industry.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/07/spam-fake-av-like-ham-eggs/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Naming and Shaming &#8216;Bad&#8217; ISPs</title>
		<link>http://krebsonsecurity.com/2010/03/naming-and-shaming-bad-isps/</link>
		<comments>http://krebsonsecurity.com/2010/03/naming-and-shaming-bad-isps/#comments</comments>
		<pubDate>Fri, 19 Mar 2010 04:47:47 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[A Little Sunshine]]></category>
		<category><![CDATA[The Coming Storm]]></category>
		<category><![CDATA[Web Fraud 2.0]]></category>
		<category><![CDATA[Brett Stone-Gross]]></category>
		<category><![CDATA[FIRE]]></category>
		<category><![CDATA[GigeNET]]></category>
		<category><![CDATA[MAAWG]]></category>
		<category><![CDATA[sam fleitman]]></category>
		<category><![CDATA[Softlayer]]></category>
		<category><![CDATA[ThePlanet.com]]></category>
		<category><![CDATA[university of california santa barbara]]></category>
		<category><![CDATA[yvonne donaldson]]></category>

		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1382</guid>
		<description><![CDATA[I asked or simply polled some of the most vigilant sources of this information for their recent data, and put together a rough chart indicating the Top Ten most prevalent ISPs from each of their vantage points. ISPs or hosts that show up more than others on these various lists are color-coded to illustrate consistency of findings (click the image to enlarge it). The trouble is, all of these individual efforts map badness from just one or a handful of perspectives, each of which may be limited in some way by particular biases, such as the type of threats that they monitor. For example, some measure only phishing attacks, while others concentrate on charting networks that play host to malicious software and botnet controllers.]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2010%252F03%252Fnaming-and-shaming-bad-isps%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Naming%20and%20Shaming%20%27Bad%27%20ISPs%22%20%7D);"></div>
<p>Roughly two years ago, I began an investigation that sought to chart the baddest places on the Internet, the red light districts of the Web, if you will. What I found in the process was that many security experts, companies and private researchers also were gathering this intelligence, but that few were publishing it. Working with several other researchers, I collected and correlated mounds of data, and published what I could verify in<em> The Washington Post</em>. The subsequent unplugging of malware and spammer-friendly ISPs <a href="http://voices.washingtonpost.com/cgi-bin/mt/mt-search.cgi?search=atrivo&amp;blog_id=66&amp;MaxResults=100" target="_blank">Atrivo</a> and then <a href="http://voices.washingtonpost.com/cgi-bin/mt/mt-search.cgi?search=mccolo&amp;blog_id=66&amp;MaxResults=100" target="_blank">McColo</a> in late 2008 showed what can happen when the Internet community collectively highlights centers of badness online.</p>
<p>Fast-forward to today, and we can see that there are a large number of organizations publishing data on the Internet&#8217;s top trouble spots. I polled some of the most vigilant sources of this information for their recent data, and put together a rough chart indicating the Top Ten most prevalent ISPs from each of their vantage points.  [A few notes about the graphic below: The ISPs or hosts that show up more frequently than others on these lists are color-coded to illustrate consistency of findings. The ISPs at the top of each list are the "worst," or have the most number of outstanding abuse issues.  "AS" stands for "autonomous system" and is mainly a numerical way of keeping track of ISPs and hosting providers. Click the image to enlarge it.]</p>
<p><a href="http://www.krebsonsecurity.com/wp-content/uploads/2010/03/WebRep.jpg"><img class="aligncenter size-full wp-image-1825" title="WebRep" src="http://www.krebsonsecurity.com/wp-content/uploads/2010/03/WebRep.jpg" alt="" width="583" height="250" /></a>What you find when you start digging through these various community watch efforts is not that the networks named are entirely or even mostly bad, but that they do tend to have more than their share of  neighborhoods that have been overrun by the online equivalent of street gangs.  The trouble is, all of these individual efforts tend to map ISP reputation from just one or a handful of perspectives, each of which may be limited in some way by particular biases, such as the type of threats that they monitor. For example, some measure only phishing attacks, while others concentrate on charting networks that play host to malicious software and botnet controllers. Some only take snapshots of badness, as opposed to measuring badness that persists at a given host for a sizable period of time.</p>
<p>Also, some organizations that measure badness are limited by their relative level of visibility or by simple geography. That is to say, while the Internet is truly a global network, any one watcher&#8217;s view of things may be colored by where they are situated in the world geographically, or where they most often encounter threats, as well as their level of visibility beyond their immediate horizon.</p>
<p>In February 2009, I gave the keynote address at a <a href="http://www.maawg.org/" target="_blank">Messaging Anti-Abuse Working Group</a> (MAAWG) conference in San Francisco, where I was invited to talk about research that preceded the Atrivo and McColo takedowns. The biggest point I tried to hammer home in my talk was that there was a clear need for an entity whose organizing principle was to collate <em>and publish</em> near real-time information on the Web&#8217;s most hazardous networks. Instead of having 15 or 20 different organizations independently mapping ISP reputation, I said, why not create one entity that does this full-time?</p>
<p>Unfortunately, some of the most clear-cut nests of badness online &#8212; the <a href="http://www.krebsonsecurity.com/2010/03/researchers-map-multi-network-cybercrime-infrastructure/" target="_blank">Troyaks of the world</a> and other networks that appear to designed from the ground up for cyber criminals &#8212; are obscured for the most part from surface data collation efforts such as my simplistic attempt above. For a variety of reasons, unearthing and confirming that level of badness requires a far deeper dive. But even at its most basic, an ongoing, public project that cross-correlates ISP reputation data from a multiplicity of vantage points could persuade legitimate ISPs &#8212; particularly major carriers here in the United States &#8212; to do a better job of cleaning up their networks.</p>
<p>What follows is the first in what I hope will be a series of stories on different, ongoing efforts to measure ISP reputation, and to hold Internet providers and Web hosts more accountable for the badness on their networks.</p>
<p><span id="more-1382"></span></p>
<p><strong>PLAYING WITH FIRE</strong></p>
<p>I first encountered the Web reputation approach created by the researchers from the <strong>University of California Santa Barbara</strong> after reading a paper they wrote last year about the results of their having hijacked a  network of drive-by download sites that is typically rented out to cyber criminals. <strong>Rob Lemos</strong> <a href="http://www.technologyreview.com/computing/23566/?a=f" target="_blank">wrote about their work</a> for <em>MIT Technology Review</em> last fall.</p>
<p><a href="http://www.krebsonsecurity.com/wp-content/uploads/2010/03/FIRE.jpg"><img class="alignright size-medium wp-image-1829" title="FIRE" src="http://www.krebsonsecurity.com/wp-content/uploads/2010/03/FIRE-300x233.jpg" alt="" width="300" height="233" /></a>Shortly after the Atrivo and McColo disconnections, the UCSB guys started their own Web reputation mapping project called <a href="http://maliciousnetworks.org/index.php" target="_blank">FInding RoguE Networks</a>, or FIRE.</p>
<p>Brett Stone-Gross, a PhD candidate in UCSB&#8217;s <a href="http://www.cs.ucsb.edu/">Department of Computer Science</a>, said he and two fellow researchers there sought to locate ISPs that exhibited a consistently bad reputation.</p>
<p>&#8220;The networks you find in the FIRE rankings are those that show persistent and long-lived malicious behavior,&#8221; Stone-Gross said.</p>
<p>The data that informs FIRE&#8217;s Top 20 comes from several anti-spam feeds, such as <a href="http://www.spamcop.net/" target="_blank">Spamcop</a>, <a href="http://www.phishtank.com">Phishtank</a>, and includes data on malware-laden sites from <a href="http://anubis.iseclab.org/" target="_blank">Anubis</a> and <a href="http://wepawet.iseclab.org/" target="_blank">Wepawet</a>, open-source tools that let users scan suspicious files and Web sites. Stone-Gross said the scoring is computed based on how many botnet command and control centers, phishing and malware exploit servers for drive-by downloads are at those ISPs, but only when those have been hosted at a given ISP over a certain number of days.</p>
<p>&#8220;The threshold is about a week. Basically you get points for each bad server you have, and then it&#8217;s scaled according to size,&#8221; he said. &#8220;We take the inverse of the network size (the approximate number of hosts) and multiple it by the aggregate sum of the network&#8217;s malicious activities.&#8221;</p>
<p>Stone-Gross said about half of the Top 20 are fairly static. &#8220;<a href="http://www.gigenet.com/index.html" target="_blank">GigeNET</a>, for example, seem to be leaders in hosting <a href="http://maliciousnetworks.org/top20.php?order=bot" target="_blank">IRC botnets</a>, and this has roughly been the case as long as we&#8217;ve been keeping track.&#8221; GigeNET did not return calls seeking comment.</p>
<p>Even compensating for size, FIRE lists some of the world&#8217;s largest ISPs and hosts conspicuously at the top (worst) of its badness index. However, FIRE&#8217;s findings are consistent with those that measure badness from other perspectives, and two major US-based networks show up time and again on most of these lists: Houston-based <a href="http://www.theplanet.com">ThePlanet.com</a>, and Plano, Texas based <a href="http://www.softlayer.com">Softlayer Technologies</a>.</p>
<p>Stone-Gross said a major contributor to the badness problem at many big hosts is the fact that most of their tenants are absentee landlords, some of whom have rented and sub-let their places out to itinerant riff-raff.</p>
<p>&#8220;What happens is they&#8217;ll have maybe a few hundred or even thousand resellers, and those resellers often sell to other resellers, and so on,&#8221; he said. &#8220;The upstream providers don’t like to shut them off right away, because that reseller might have one bad client out of 50, and they&#8217;re not law enforcement, and they don&#8217;t feel it&#8217;s their job to enforce these kinds of things.&#8221;</p>
<p><strong>Sam Fleitman</strong>, chief operating officer at Softlayer, said the company has been trying to become more proactive in dealing with abuse issues on its network. Fleitman said his abuse team has been reaching out to a number of groups that measure Web reputation to see about getting direct feeds of their data.</p>
<p>“Most hosting companies are reactive…finding and getting rid of problems that are reported to them,” Fleitman said. “We want to be proactive, our goals are aligned, and so we’ve been trying to get that information in an automated way so we can take care of these things quicker.”</p>
<p>Indeed, not long after the UCSB team posted their FIRE statistics online, Softlayer approached the group to hear suggestions for reducing their ranking, Stone-Gross said.</p>
<p>&#8220;They came to us and said, &#8216;We’d like to improve that,&#8217; so we had a talk with them and gave them a whole bunch of suggestions,&#8221; Stone-Gross said. &#8220;That was about three weeks ago, and they&#8217;ve since gone from being consistently in the Top 3 worst to usually much lower on the list.&#8221;</p>
<p><a href="http://www.krebsonsecurity.com/wp-content/uploads/2010/03/theplanethistory.jpg"><img class="alignleft size-medium wp-image-1832" title="theplanethistory" src="http://www.krebsonsecurity.com/wp-content/uploads/2010/03/theplanethistory-300x279.jpg" alt="" width="300" height="279" /></a>What&#8217;s probably most unique about FIRE&#8217;s approach is it allows users to view not just the volume of reported abuse issues at a given network, but also to drill down into specific examples and even chart the life of said abuse examples over time.</p>
<p>For instance, if you click <a href="http://maliciousnetworks.org/chart.php?as=AS21844" target="_blank">this link</a> you will see the reputation history for ThePlanet.com. The graphic in the upper right indicates that, aside from a brief period in the middle of 2009, ThePlanet has been at or near the top of the FIRE list for most of the last 18 months. Stone-Gross said that one gap corresponds to a time last April when the university&#8217;s servers crashed and stopped recording data for a few days.</p>
<p>Click on any historic points in the multicolored line graphs in the bottom left and you can view the IP addresses of phishing Web sites, malware and botnet servers on ThePlanet.com over that same time period, as recorded by UCSB.</p>
<p>ThePlanet&#8217;s <strong>Yvonne Donaldson</strong> declined to discuss FIRE numbers, the abuse longevity claims, or the company&#8217;s prevalence on eight out of ten of the reputation lists that flagged it as problematic. In a statement e-mailed to Krebs on Security, she said only that the company takes security very seriously, and that it takes action against customers that violate its acceptable use policies.</p>
<p>&#8220;When we find issues of a credible threat, we notify the appropriate authorities,&#8221; Donaldson wrote.  &#8220;We may also take action by disabling or removing the site, and also notify customers if a specific site they are hosting is in violation.&#8221;</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2010/03/naming-and-shaming-bad-isps/feed/</wfw:commentRss>
		<slash:comments>64</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 3/11 queries in 0.002 seconds using memcached
Object Caching 426/444 objects using memcached

Served from: krebsonsecurity.com @ 2012-05-24 09:28:43 -->
