Brian Krebs has provided people who use online banking services with excellent advice: do your online banking only from a read-only, bootable operating system, such as Knoppix, or Ubuntu.
Brian's articles on this subject have been featured by both Slashdot and Google. He provides a tutorial on how to burn a live CD using Ashampoo Burning Studio Free. If you use Nero, my tutorial on burning ISO images may also be useful.
For those who do not wish to burn their own ISO image, the large bookstores now have Linux magazines available which include bootable Linux Live CDs.
James McQuaid
Friday, October 16, 2009
Sunday, October 11, 2009
Blocking the ASProx Fast Flux Botnet
With the IP addresses of the ASProx fast flux botnet changing between infected residential computers nearly daily, the only effective methods of blocking it are through the use of a DNS black hole or with Snort Inline.
Gary Warner provides an excellent write up on the botnet at his blog at: http://garwarner.blogspot.com/2009/10/cyber-security-awareness-month-day-one.html
Today, I updated the DNS Super Blackhole at emergingthreats.net. You can download the DNS Super Black Hole files for Smoothwall at Emerging Threats from: http://doc.emergingthreats.net/bin/view/Main/HoneywallSamples)
* config-hosts (http://doc.emergingthreats.net/pub/Main/HoneywallSamples/config-hosts): 275,937 organized crime, RBN affiliates, malware hosts and bad actors blacklisted for Smoothwall 3. Leave last line blank. Place in /var/smoothwall/hosts/, then rename config-hosts to config. Updated 10-11-2009: added 9,116 cybercrime and malware domains identified since 6-20-2009.
* hosts (http://doc.emergingthreats.net/pub/Main/HoneywallSamples/hosts): Protect your home from 275,937 bad domains for Smoothwall 3; placed in /var/smoothwall/hosts/. Note: with this many objects in BlackHole, you must use local loopback (blacklisted domains must resolve to 127.0.0.1). Updated 10-11-2009. If you believe that your domain should not be listed, please let us know and we will review it for delisting.
- James McQuaid
Gary Warner provides an excellent write up on the botnet at his blog at: http://garwarner.blogspot.com/2009/10/cyber-security-awareness-month-day-one.html
Today, I updated the DNS Super Blackhole at emergingthreats.net. You can download the DNS Super Black Hole files for Smoothwall at Emerging Threats from: http://doc.emergingthreats.net/bin/view/Main/HoneywallSamples)
* config-hosts (http://doc.emergingthreats.net/pub/Main/HoneywallSamples/config-hosts): 275,937 organized crime, RBN affiliates, malware hosts and bad actors blacklisted for Smoothwall 3. Leave last line blank. Place in /var/smoothwall/hosts/, then rename config-hosts to config. Updated 10-11-2009: added 9,116 cybercrime and malware domains identified since 6-20-2009.
* hosts (http://doc.emergingthreats.net/pub/Main/HoneywallSamples/hosts): Protect your home from 275,937 bad domains for Smoothwall 3; placed in /var/smoothwall/hosts/. Note: with this many objects in BlackHole, you must use local loopback (blacklisted domains must resolve to 127.0.0.1). Updated 10-11-2009. If you believe that your domain should not be listed, please let us know and we will review it for delisting.
- James McQuaid
Thursday, September 24, 2009
Protected By Emerging Again
In "'Money Mule' Recruitment Network Exposed" (http://voices.washingtonpost.com/securityfix/2009/09/money_mule_recruitment_101.html?wprss=securityfix),
Brian Krebs discusses fraudelent money mule recruiters the Scope Group Inc.
scope-group.cn and its associated web sites operate on the following IP addresses:
222.35.137.234
222.35.137.235
222.35.137.236
222.35.137.237
Those who have implemented the emerging-rbn.rules had protected the users of their networks from these ruthless criminals, who stole more than $117,000.00 from the small Sanford School District last month.
James McQuaid
Brian Krebs discusses fraudelent money mule recruiters the Scope Group Inc.
scope-group.cn and its associated web sites operate on the following IP addresses:
222.35.137.234
222.35.137.235
222.35.137.236
222.35.137.237
Those who have implemented the emerging-rbn.rules had protected the users of their networks from these ruthless criminals, who stole more than $117,000.00 from the small Sanford School District last month.
James McQuaid
Wednesday, September 23, 2009
Protected By Emerging
Those who have implemented the emerging-rbn.rules had protected their
networks from the September 11th and 12th attacks on the visitors to The New York Times web site.
The attacks utilized the following IP addresses:
212.117.166.69
64.86.16.170
88.198.107.25
88.198.120.177
91.212.107.5
91.212.127.200
94.102.48.29
94.102.51.26
Dancho Danchev and Gary Warner's blogs provide good explanations of
these attacks:
http://ddanchev.blogspot.com/2009/09/ukrainian-fan-club-features.html
http://garwarner.blogspot.com/2009/09/in-brief-new-york-times-fake-anti-virus.html
Visit Emerging Threats at emergingthreats.net
James McQuaid
networks from the September 11th and 12th attacks on the visitors to The New York Times web site.
The attacks utilized the following IP addresses:
212.117.166.69
64.86.16.170
88.198.107.25
88.198.120.177
91.212.107.5
91.212.127.200
94.102.48.29
94.102.51.26
Dancho Danchev and Gary Warner's blogs provide good explanations of
these attacks:
http://ddanchev.blogspot.com/2009/09/ukrainian-fan-club-features.html
http://garwarner.blogspot.com/2009/09/in-brief-new-york-times-fake-anti-virus.html
Visit Emerging Threats at emergingthreats.net
James McQuaid
Labels:
Emerging Threats,
malware,
The New York Times,
web attacks
Friday, September 11, 2009
RBN Attacking White House Anti-Drug Web Sites
In another example of the RBN revealing the true measure of their malice, White House Anti-Drug Sites have been attacked over the past week.
Malware Domain List reported on September 5th that whitehousedrugpolicy.gov, the website of Office of National Drug Control Policy had been compromised. In that instance, the site was directing visitors to a trojan:
adgallery.whitehousedrugpolicy.gov/members/Miley-Cyrus-Nude/default.aspx 198.77.71.192 adgallery.whitehousedrugpolicy.gov directs to trojan abuse@noc.privatedns.com 2009/09/05.
whitehousedrugpolicy.gov features White House Drug Policy initiatives, programs, and resources as well as, testimony and press releases. The site outlines National Drug Control Strategy goals and objectives.
Today, I found that drugs4sale.loderunner.in, which is a data receptor for the notorious Clampi banking Trojan (Trojan.Clampi) had an A record pointing to 130.94.30.137. This is the same IP address reserved for use by theantidrug.com, the "Parents: The Anti-Drug" site created by Fleishman-Hillard (a leader in international marketing and communications).
AS2914 NTTC-GIN-AS NTT Communications Global IP Network
DNS Records
base record name ip reverse route as
drugs4sale.loderunner.in a 130.94.30.137
United States
mail.theantidrug.com a 130.94.30.137
United States
the-anti-drug.com a 130.94.30.137
United States
theantidrug.com a 130.94.30.137
United States
Alexei Vasiliev, a familiar RBN criminal involved in the propagation of the Clampi banking Trojan, used his email address (alexvasiliev1987@cocainmail.com) to register one of the known Clampi domains.
Malware Domain List reported on September 5th that whitehousedrugpolicy.gov, the website of Office of National Drug Control Policy had been compromised. In that instance, the site was directing visitors to a trojan:
adgallery.whitehousedrugpolicy.gov/members/Miley-Cyrus-Nude/default.aspx 198.77.71.192 adgallery.whitehousedrugpolicy.gov directs to trojan abuse@noc.privatedns.com 2009/09/05.
whitehousedrugpolicy.gov features White House Drug Policy initiatives, programs, and resources as well as, testimony and press releases. The site outlines National Drug Control Strategy goals and objectives.
Today, I found that drugs4sale.loderunner.in, which is a data receptor for the notorious Clampi banking Trojan (Trojan.Clampi) had an A record pointing to 130.94.30.137. This is the same IP address reserved for use by theantidrug.com, the "Parents: The Anti-Drug" site created by Fleishman-Hillard (a leader in international marketing and communications).
AS2914 NTTC-GIN-AS NTT Communications Global IP Network
DNS Records
base record name ip reverse route as
drugs4sale.loderunner.in a 130.94.30.137
United States
mail.theantidrug.com a 130.94.30.137
United States
the-anti-drug.com a 130.94.30.137
United States
theantidrug.com a 130.94.30.137
United States
Alexei Vasiliev, a familiar RBN criminal involved in the propagation of the Clampi banking Trojan, used his email address (alexvasiliev1987@cocainmail.com) to register one of the known Clampi domains.
Thursday, July 30, 2009
RBN Attacks Labour Organization
Russian Business Network hackers have targeted the computers of visitors to WomensLabour.org, a website devoted to women and the labour market in Central and Eastern Europe.
The website is designed to provide Non Governmental Organizations (NGOs) and particularly gender focused NGOs with up to date information about the economic position of women from the Central and Eastern Europe (CEE). It places particular emphasis on the link between the EU enlargement process and the position of CEE women in the labour market.
The RBN is well known for its direct involvement in the sexual exploitation of women and children. The Russian Business Network's efforts to spy on Eastern European labour organizations should be noted by law enforcement.
MalwareDomainList.com first listed WomensLabour.org as compromised on June 30th. Google's Safe Browsing application reports that visitors to the site were targeted by malicious software ("resulted in malicious software being downloaded and installed without user consent") originating at martuz.cn, betbigwager.cn, and cutlot.cn. Cutlot.cn and betbigwager.cn are operated by well known cyber criminal Raymond Keaton (keaton@cybernauttech.com). Chen Poon, who also acts in tandem with Russian cyber criminals, owns martuz.cn. The RBN's malicious software included, but was not limited to, "7 scripting exploits".
- James McQuaid
The website is designed to provide Non Governmental Organizations (NGOs) and particularly gender focused NGOs with up to date information about the economic position of women from the Central and Eastern Europe (CEE). It places particular emphasis on the link between the EU enlargement process and the position of CEE women in the labour market.
The RBN is well known for its direct involvement in the sexual exploitation of women and children. The Russian Business Network's efforts to spy on Eastern European labour organizations should be noted by law enforcement.
MalwareDomainList.com first listed WomensLabour.org as compromised on June 30th. Google's Safe Browsing application reports that visitors to the site were targeted by malicious software ("resulted in malicious software being downloaded and installed without user consent") originating at martuz.cn, betbigwager.cn, and cutlot.cn. Cutlot.cn and betbigwager.cn are operated by well known cyber criminal Raymond Keaton (keaton@cybernauttech.com). Chen Poon, who also acts in tandem with Russian cyber criminals, owns martuz.cn. The RBN's malicious software included, but was not limited to, "7 scripting exploits".
- James McQuaid
Labels:
NGO,
RBN,
Russian Business Network,
spying on labour,
WomensLabour.org
Monday, April 20, 2009
DNS Super Black Hole
DNS Black Hole technology has been used in various settings for some years. "The first DNSBL was the Real-time Blackhole List (RBL), created in 1997 by Paul Vixie as part of his Mail Abuse Prevention System (MAPS)" (note: http://en.wikipedia.org/wiki/DNSBL).
Some years later, David Glosser's open source security project at EmergingThreats.net formalized the use of the technique as a means of blocking malware (note http://www.malwaredomains.com/bhdns.html). His site includes a nice hyperlink list of the various hosts blocking web sites at http://www.malwaredomains.com/bhdns.html#Resources.
Over the past two years, having faced an onslaught of hundreds of new malware domains per week created by the RBN and their affiliates, those of us engaged in mitigation and recovery operations began creating Super Black Holes in Linux DNS servers as a matter of necessity. Initially, there was some skepticism as to whether the concept was practicable, but it has proven sound when used with internal DNS servers.
The great advantage for home users is that a DNS Super Black Hole provides the opportunity to effectively block a *very* large number of malicious web sites with minimum resources. For example, to filter by IP address the 247,268 evil sites (provided in the DNS Super Black Hole files that I am posting) requires 6 GB of RAM deployed across two inline firewall servers. Such hardware is unavailable to most home users. In contrast, using one older PC bearing only 512 MB of RAM, the home user can block the same 247,268 bad actor web sites using a DNS Super Black Hole (deployed on a free, open source software platform such as Smoothwall). Windows users can edit the files by using free, open source software such as Notepad++ (http://sourceforge.net/projects/notepad-plus/) and WinSCP (http://sourceforge.net/projects/winscp/). This provides parents with a means to filter racist, criminal and pornographic web sites.
In the struggle against cyber criminals, I have often observed instances where viruses are used to drive up the traffic statistics of a web site owned by the criminal. This enables cyber criminals to auction the domain at a greater price. In order to discourage this practice, my DNS Super Black Hole files include many of these domains.
Few individuals visit malicious web sites on purpose. In most cases, the user visits a legitimate site which has been hacked or which includes a malicious banner ad (a fairly common occurence at Yahoo and Google). The end result is that a hidden window or I-Frame is invoked by JavaScript which installs malware on the PC. DNS Super Black Hole prevents this by diverting the DNS (domain name server) query to the Black Hole. The files include Internet bad actors as well as, most of the known malware domains as of May 27, 2009.
Smoothwall is a stable platform which provides excellent installation instructions and documentation (http://www.smoothwall.org/) and user community support (http://community.smoothwall.org/forum/). As such, it is ideal for home users.
You can download the DNS Super Black Hole files for Smoothwall at Emerging Threats from: http://doc.emergingthreats.net/bin/view/Main/HoneywallSamples):
* config-hosts (http://doc.emergingthreats.net/pub/Main/HoneywallSamples/config-hosts): 247,268 organized crime, RBN affiliates, malware hosts and bad actors blacklisted for Smoothwall 3. Leave last line blank. Place in /var/smoothwall/hosts/, then rename config-hosts to config. Update 5-27-2009: 3,526 cybercrime and malware domains discovered since May 3rd.
* hosts (http://doc.emergingthreats.net/pub/Main/HoneywallSamples/hosts): Protect your home from 247,268 bad domains for Smoothwall 3; placed in /var/smoothwall/hosts/. Note: with this many objects in BlackHole, you must use local loopback. Updated 5-27-2009.
Many of the web sites listed in these files are extraordinarily dangerous, so do not visit them!
Labels:
content filtering,
dns black hole,
home defense,
Smoothwall
Subscribe to:
Posts (Atom)