Left Accent
UAB CIS Header

UAB Open Source Intelligence Project against Cybercrime (OSIPACC)

Updated on Wed, 06/02/2010 - 3:09pm

When someone places hostile computer code on a computer and causes it to perform actions unauthorized by the owner of that computer, they are violating the federal laws of the United States.  In general, this activity is referred to as a Computer Intrusion.  Some of the Federal Laws that might apply in the case of a Computer Intrusion would include:

The sentencing on several of these laws specific to botnet activity was increased by the "Identity Theft Enforcement and Restitution Act of 2007" sponsored by the Cyber Senator from Vermont, Patrick Leahy.  Gary Warner wrote about some of these enhancements in his "CyberCrime & Doing Time" blog back when the bill was being considered.  (See: the Identity Theft Enforcement and Restitution Act of 2007.   Some of the key improvements are that:

    - there is no financial threshold to be crossed when planting "spyware" or malicious software used for identity theft.  Any occurence makes it a Federal crime.

     - if at least ten computers are controlled by one criminal for the purpose of stealing identity, the crime is classified as a FELONY.

     - prison terms under Section 1030 (a)(5) would be increased to up to five years for a first offense of such a felony.

Given all of the above, why are bad guys not being sent to jail more regularly for these types of crimes?

1. There is an enormous deficit in the resources applied to Cybercrime investigation and enforcement.

2. There is a lack of capability to understand and investigate complex cyber crimes.

3. The public is not helping in a useful and practical way.

The focus of the "UAB Open Source Intelligence Project against Cybercrime" is to address all three of these points.  In order to be successful, we need partners who are willing to change their business practices with regards to malware and phishing.  Overwhelmingly, the corrective action applied when malware is discovered in a business environment is to isolate and clean the infected computer, often by formatting the hard drive and reinstalling all software.  When a phishing email is discovered, the recipient is often advised to "just hit delete."  In the Criminal Justice world, this would be referred to as "Destruction of Evidence".

Malware

As we have illustrated through many presentations, including Gary's recent presentations at IT-360 in Canada and GovSec in Washington DC, many malware infections are being used to steal not only passwords and personal banking information, but deep intelligence about the victim, and the company in which the victim's computer is located.  By destroying the malware without a proper investigation, corporate networks have in many cases allowed a deep intrusion into their network to go undetected for months or in some cases years.

Although it is true that a crime has been committed, it is also unlikely that you will get an appreciable law enforcement response by calling your local FBI office and saying "one of my computers has a virus."  Deeper analysis is required, which is often not possible in small businesses or businesses with limited security staff.

To support the Malware portion of this project, UAB researchers are asking for help from the owners of malware-infected computers.  Our current focus is to help identify the 'hosting infrastructure' of some current botnets.  One of the largest of these botnets is known as Koobface.  This malware, infects more than 3 million American computers, and causes several types of mischief, including causing your Google Search results to be altered to point you to affiliate advertisement sites controlled by the computer, allowing other malware families (especially fake anti-virus) to be placed on the infected computer, and causing you to send messages to other Facebook, Twitter, Bebo, and Hi-5 and other users trying to get them to infect themselves as well.

When a webmaster becomes infected with Koobface, his userid and password for his website may be sent to the criminals, who then log in and add a new subdirectory on their webserver which can be used as a Command & Control point.  If you receive an email from UAB asking for your help in documenting this type of attack, please consider responding.

When the victims can share information and produce a quality intelligence report, it does three things:
 
   -   It establishes the validity of the case.

   -   It reduces the manpower required by law enforcement to understand and successfully investigate the case.

   -   It helps make the case understandable to grand juries, prosecutors, attorneys, or judges who may need to help with the investigative process.

We hope that you will respond affirmatively to our research team if you are asked to share log files with us.

Thanks for your cooperation!

Gary Warner
Director of Research in Computer Forensics
The University of Alabama at Birmingham

 


Koobface Distribution domains:

The following domains were compromised by the Koobface malware and used to spread the malware in a secret subdirectory named "/.sys/":

 

 

3mates.com
500instantniches.com
6omdagen.dk
aaskereia-online.de
acaivf.com.au
admin.volleyliga.be
alankaye.info
allstateprocess.com
alvin.dk
amazingpets.org
andyt.co.uk
anlaegkp.dk
aricosenza.it
awatch4u2.com
bc-wny.com
beautydesk.be
bebaurora.com
becker.webd.pl
bodyforgesystem.com
borderssportinggoods.com
branderideklub.dk
brandtransfer.com
brevard-fl.com
brugdesign.it
brusselslivestock.ca
buddydrums.fridh.se
Bullmastiffsbywatchman.com
bushdecor.com
car-transport.com.au
cccforum.be
cedelevator.com
celebrem.com
cfdataservices.net
christicolvin.net
christophebaetens.be
citroen2cv.se
commerce-enville.fr
condenast.tempwebpage.com
corteostoricoterrasanctibenedicti.org
crossroads-wfd.org
cshservice.com
cucciolidiagnese.it
dance-alarm.de
darelorenzo.it
dbtravelworld.com
decolff.be
deltasatuk.com
dentistschoice-fl.com
depannage-selection.com
derryrailtrail.org
devonhols.co.uk
dinovincenzopatroni.com
djcarmelospinella.com
dusinklubben.dk
dynasales.net
e-autosystem.gr
edensensuel.fr
efficientenergysystems.ca
elenailyina.com
epbh.org
ertrafikskola.se
espositofotografi.it
eurobizlink.com
familiespil.dk
ferme-saveurs.com
fininve.it
fintel.tv
fintelservizi.com
fintelservizi.it
firmafrugtforeningen.dk
flaminiaspeziale.com
formacio.eio.es
fos.be
fredericia-stavgang.dk
fridh.se
frigologistics.nl
galacticcenter.org
gamlabodens.se
ginun-oz.co.il
goldenliontech.com
goldmaniac.com
gospel-force.com
graficamaratea.com
grdcb.com
greenhealthyliving4u.netfirms.com
grinde.dk
haque-law.com
healthmann.pk
idrottsevenemang.se
illuminators.com.au
impromptucatering.com
inartdesigns.com
informatique86.fr
InternetcityHosting.com
internethosting.sg
investrade.sk
ipera.it
javanas.nl
jcshop.netfirms.com
josecure.com
jotya.com
journalsexyplus.com
juanfurlan.com.ar
jugendfeuerwehr-zermatt.ch
juridikitiden.se
jv-s.com
kantinetakeaway.dk
karpatykrosno.net
kcresale.com
keeplan.com
kennethom.net
kingdom.dreamhosters.com
kingdomchristianity.com
laudunlardoiseavenir.fr
lavalledellupo.it
likkewaan.co.za
lilianverhaegen.be
linkpilots.com
littlepalmbeach.com
liveinczech.com
loca-plus.fr
lotuscovecampground.com
lr-online.dk
mad-i-bevaegelse.dk
mag5.kiev.ua
magnumopus.dk
mahjongmuseum.com
mashburnsales.com
mdcoc.net
mediast.eu
micaelmarkstrom.se
mitchellelectricinc.com
mkmohanty.com
mm2dc.com
modefrugt.dk
musicol.co.il
mvccpa.org
nancy-woodward.com
norrbotten.adventkyrka.se
norsk-kasjmirgeit.no
northernbiscuit.ca
nvranch-alpacas.com
onderwijsnet.be
online-doors.co.uk
onlinesigns.co.za
optimumorg.com
paolosimi.com
paolosimi.it
paseoshoes.it
petfish.net
piessegioielli.it
pixels-prod.com
plincx.com
portalecomuni.com
portalecomuni.it
portugalresa.se
preventthebite.com
privacyweb.tv
projectlightafrica.com
prostruction.net
qatar-business-guide.net
rainmakertech.com
rallynews.servhome.org
ralphcotton.net
reishus.de
rentsatoday.com
restaurant-premier.com
richardspizza.com
ristorante-amici.it
ristorantecaminetto.it
ritmotours.com.tr
roomservicedesign.com.au
sambawafarms.com
santechshara.com
saratogasteakhouse.com
scooterist.se
scouting.volleyliga.be
sheenalarsen.com
shirleymancino.com
silverbirdgroup.com
sinonilimited.com
sp3.emikolow.pl
sphusa.com
sportbar-pfeffersberg.net
spritdrycker.se
stevenslargetreesales.com
stevesplaceusaparts.com
stopreporter.com
stuartthomasmanor.com
telephone-selection.com
testing.onlinesigns.co.za
thecanadians.net
thecenterinsider.com
themeadowsfamily.com
thenutritiongroup.biz
theocseries.com
tissuespritz.com
tompkinssolutions.netfirms.com
tradersquants.com.mx
trailride.gr
trattoriabilly.com
trattoriabilly.eu
travelsek.com
treasurevalleyrevival.org
tributionline.com
trip4x4.co.il
trucksor.no
tskfc.com
uaetoon.net
unacorn.net
ussales.it
veggiemama.com.hk
vespia.se
veterinariancare.us
viale.be
vinvan.be
vitogabriele.com
vlmbrabant.be
voiture-selection.com
voyages-selection.com
waypoint-center.org
welovetweet.com
whyviral.com
winemylips.be
workmantech.net
wsearch.fr
www.9-mois-tout-rond.com
www.aapgroup.com.kh
www.activcomfrance.com
www.aegypten-mit-stefan.de
www.alem.at
www.ancgrimaldi.info
www.animalsitting.be
www.australianslongevity.net
www.bastakigroup.com
www.bogangallery.com
www.bradrichmond.com
www.brusselslivestock.ca
www.bunnyclub.tv
www.caminfoservices.com
www.ceipdoctorseres.org
www.cemmacreation.com
www.challengevolley02.fr
www.chateaudecoisse.com
www.choisisunenouvelleapproche.ca
www.civfweb.netfirms.com
www.comunicat-de-presa.ro
www.deadlyserious.co.uk
www.deaf-world-gehoerlos-friend.de
www.deinzahnarzt.com
www.demeuleneire.be
www.drive4faf.com
www.drive4marten.com
www.egpi-btp.com
www.ekenasbowling.fi
www.eom.it
www.ferienhaus-muehlner.de
www.firststategymnastics.com
www.flohr.tuknet.dk
www.footroast.ca
www.gdservices91.com
www.gecahe.com
www.gloggnitzer-werbeatelier.de
www.herangi.com
www.hitechsolutioncenter.com
www.hoganjobs.com
www.hotelkreuzwirt.at
www.hotelthier.at
www.idif.it
www.intelsourcepvt.com
www.its-email.co.uk
www.j80-trinitains.com
www.jadvent.ca
www.jallabyah.com
www.jh-shop.com
www.jwdtrees.com
www.kochausleidenschaft.de
www.laspheredesservices.fr
www.leitner-fenster.com
www.lesprofessionnelsdelafermeture.com
www.liguevolley.be
www.lionkitchen.com.sg
www.lottoladiescycling.be
www.macom.co.at
www.maison-materiaux-ecologiques.fr
www.maltesekitchen.com.mt
www.martin-acke.be
www.massage-tom.com
www.mushinenterprises.com
www.mx2.jellingnet.dk
www.nbcf.co.uk
www.nichildrenservices.org
www.northernterritorydidgecircle.nl
www.ntas.com
www.oneofakindsxm.com
www.paginebusiness.it
www.palmaleinehof.be
www.partenaires-particuliers.fr
www.patrickcadona.com
www.person.doae.go.th
www.photo-reviews.com
www.powertreecorp.com
www.proelec-dpt.fr
www.queerasfolk-community.de
www.rc-speedracing.at
www.rc-speedracing.com
www.re-active.net
www.richwebhosts.com
www.ricksmusicstore.com
www.schatzbichl.at
www.shg-fibromyalgie.com
www.shogunlevallois.com
www.signyourweb.com
www.skylergreene.com
www.soluybesttour.com
www.sportmeeuwengruitrode.be
www.stevenslargetreesales.com
www.tabdesign.com.sg
www.tcsweb.nl
www.thalasso-selection.com
www.tmunvictoria.com
www.today-production.com
www.tommycooperphotography.com
www.tomsmassagepraxis.at
www.usadance-royalpalm.org
www.vallesina.tv
www.viewkhmer.com
www.vivatap-usa.com
www.volleyliga.be
www.waypoint-center.org
www.wttcmi.com
www.youandibusinessclub.co.uk
x-paint.se
yarentextil.com
yayasoft.co.il
yourprofit.brevard-fl.com
zaferburo.com.tr
zanzibarnelpallone.com
ziasgelato.com
zu.ktk.ru

 

The following domains were compromised by Koobface and used to spread malware in directories with random names, all beginning with a "."

 

02f32e3.netsolhost.com
130.94.217.10
142exoticworkout.com
1836ink.com
195.28.180.40
196.27.0.5
198.65.28.86
208.56.96.242
209.227.239.155
212.199.48.66
216.198.197.89
216.92.214.178
65.175.67.205
67.199.32.51
67.228.184.3
6omdagen.dk
76.12.110.242
81.25.120.53
97.74.57.12
abskupina.si
admin.volleyliga.be
aduniversal.com
aguasdomondego.com
alabasta.homeip.net
alankaye.info
allbudo.com
allstateprocess.com
almafoodsrl.it
alpenhaus.com.ar
alvillaggiodelsole.netsons.org
alvin.dk
alvsbackastrand.se
amandaimagen.com
amazingpets.org
amicitia.info
andreplazzotta.com
animationstjo.fr
anlaegkp.dk
aramiyun.com
aricosenza.it
arrownw.com
ato5marche.it
awatch4u2.com
aziendavitivinicolacollefavignano.it
baronessan.se
bastianellozambelli.it
baticlick.com
bcdsupport.com
beachfishingwa.org.au
bebaurora.com
becker.webd.pl
benquerenciadelaserena.com
bestchamber.com
bigbandintica.com
bildtuben.se
blackice.up.md
bmthungary.hu
bollylady.com
book4pro.com
boutred.se
branderideklub.dk
brandtransfer.com
brusselslivestock.ca
bushdecor.com
bwbudo.com
bwtrading.se
calendar.bwbudo.com
careyadkinsdesign.com
carothersconstruction.com
cartujo.org
castingspells.co.za
cedbetchannel.com
cedelevator.com
celebrem.com
charlepoeng.be
chinchinbar.com
chunkbait.com
cissiandthegoat.yonas.se
climaxabia.com
clr.dsfm.mb.ca
clubsanisidro.com.mx
cnkerleven.com
coldwellbanker.net
condenast.tempwebpage.com
copyandpaste.co.cc
cortedibacco.it
corteostoricoterrasanctibenedicti.org
cpvs.org
credibleartstherapies.org
croonco.se
cseajudiciary.org
cucciolidiagnese.it
danc.se
daolasabike.it
darelorenzo.it
darmika.be
davidcollinsmasterofceremonies.co.uk
dbtravelworld.com
decolff.be
degrit.com
deltasatuk.com
dev.bwbudo.com
dev.bwtrading.se
devonhols.co.uk
dewskin.com
dinovincenzopatroni.com
directcolors.com
djcarmelospinella.com
dmsa.it
doctorsorchestra.com
dreamworksroma.it
dudesrsly.com
dulys.com
dusinklubben.dk
earacupuncture.biz
edensensuel.fr
efficientenergysystems.ca
electring.hu
elenailyina.com
emmedici.net
epbh.org
erleliivak.com
ertrafikskola.se
espositofotografi.it
euskorock.es
evelori.ch
eventosvergara.cl
f9phx.net
fatucci.it
favoritofswissmountain.hu
fh.bamlu.at
fininve.it
fintel.tv
fintelservizi.com
fintelservizi.it
firmafrugtforeningen.dk
fiwe.se
flaminiaspeziale.com
fmcurling.org
formacio.eio.es
forum.kingdomchristianity.com
forwardmarchministries.org
fos.be
fotoplanet.it
franknelsonbuilding.com
frenchbean.co.uk
gamlabodens.se
gemmadivita.it
gilvision.com
glabs.it
goldenliontech.com
goldmaniac.com
gosin.be
graficamaratea.com
grdcb.com
greenlightsrecycling.com
grinde.dk
grossmanco.com
guest.worldviewproduction.com
guptacorporation.com
habitart.eu
healthmann.pk
hellgrens.com
helpdroid.omicronrecords.com
highway77truckservice.com
hillsdemocrat.com
hireorderthinking.com
holustravel.cz
hottesttomato.com
ifaro.altervista.org
iglesiabetania1.com
ihostu.co.uk
illuminators.com.au
imagequest360.com
impresaambiente.com
inartdesigns.com
IndustrialWholesale.com
ineedwheyprotein.co.uk
innovengine.info
integratek.omicronrecords.com
InternetcityHosting.com
internethosting.sg
intranet.bwtrading.se
ipera.it
irisjard.o2switch.net
isehaug.no
islamwelt.ch
islandmusicexport.com
israimplant.com
jameser.com
jcshop.netfirms.com
jesannproperties.co.uk
johnphelan.com
josecure.com
journalsexyplus.com
jsacm.com
kantinetakeaway.dk
karpatykrosno.net
kcresale.com
keekerknives.com
keeplan.com
kennethom.net
kertenkelereklam.com
klimentglass.cz
kriminologi.nu
kvarteretekorren.se
lamsmotorsports.com
lanavabadajoz.com
langstoncorp.com
lanonna.co.uk
lavalledellupo.it
leonardandself.com
libermann.phpnet.org
libertybellmp.com
lineapapel.com
linneaochlouise.yonas.se
littlepalmbeach.com
liveinczech.com
lotuscovecampground.com
lsante.com
lunaairforlife.com
madnessmarketing.com
mahjongmuseum.com
malarcupen.com
marcopolo.uk.net
mariosanzone.it
mbmproducciones.com
mdcoc.net
micaelmarkstrom.se
microstart.fr
migdal.org.il
mii.yonas.se
mindbodyandsolemt.com
mitchellelectricinc.com
moarhof.net
modefrugt.dk
montecristo.com.au
mudohareid.no
mukdahan.doae.go.th
mypage.bwbudo.com
nassnig.org
naturalherbalsinc.com
neon21.it
netservicesrl.com
neuesdach.ch
nhugiotle.com
nightprodder.yonas.se
nonsuchtherapy.co.uk
nosneezes.com
notretracesurterre.org
omicronsystems.inc.md
on3la.be
onderwijsnet.be
onlineadmin.net
onlinesigns.co.za
optimumorg.com
orangery.nezhin.com
ornskoldskatten.se
ottaviocasalini.com
ourpetpix.com
palestraenergia.com
paolosimi.com
paolosimi.it
paperlessflightbag.com
paseoshoes.it
pbcers.org
peakndale.com
perugialibri.it
peteasyhotel.com
petfish.net
pheromoneforum.org
piessegioielli.it
pilatescenter.se
platinumrushmusic.net
plincx.com
pokretmojasrbija.rs
polistena.net
pondclean.netfirms.com
portalecomuni.com
portalecomuni.it
privacyweb.tv
programs.ppbsa.org
projectlightafrica.com
projects.bwtrading.se
prousaudio.com
puertohurraco.org
quailvalleyfund.org
quellidelpianodisopra.com
rauret.fr
rbws.duebiinformatica.it
recruitsavvy.com
redactie.parochiesedegem.be
reddevilsmcturkey.com
reishus.de
renografica.net
rentor.it
rentsatoday.com
reporsenna.netsons.org
retrobutiken.se
rhigar.nu
richmondpowerboat.com
riskzone.ppbsa.org
ristorantecaminetto.it
ritmotours.com.tr
riverstoneimmobiliare.it
robertodecarlo.com
romastasera.it
roomservicedesign.com.au
rvl.it
s1021009.crystone.net
saratogasteakhouse.com
sarrasinphotography.netfirms.ca
sarumstud.com
scheduler.omicronrecords.com
scheron.com
scouting.volleyliga.be
secure.tourinrome.org
seed527.obtrix.net
SERROUVILLE.FR
servicehandlaren.com
servicehandlaren.se
servicehandlarn.com
sessions.Justsmilephotography.com
sgottnerivers.com
shannondreamlabradors.de
sheenalarsen.com
shirleymancino.com
silverbirdgroup.com
slatten.se
slcsc.co.uk
smartdog.yonas.se
smartvwater.com
soccermanagement.it
sphusa.com
sporthal.msolutions.be
stevenslargetreesales.com
stopreporter.com
store.retrobutiken.se
stuartthomasmanor.com
stubbieholderking.com
studio2tv.it
svenfotopagina.be
svenskservicehandel.se
symposium.israimplant.com
tamiltrades.com
taneysworld.com
tappinskis.se
teaterm.com
testing.onlinesigns.co.za
themasterofceremoniesclub.co.uk
themeadowsfamily.com
theroamingjew.com
therobinson.net
toobusiness.tv
toskanaferien.net
trailride.gr
Training.ppbsa.org
trattoriabilly.com
trattoriabilly.eu
trendynailsunlimited.com
tributionline.com
trucksor.no
tufateer.net
twitterhispano.net
uaetoon.net
ultimoharem.com
undomeda.com
unna.nu
upload.boad.org.uk
upload.bwbudo.com
uspalletsupply.com
vangecars.it
veggiemama.com.hk
verdiverdi.net
veterinariancare.us
vgto.be
viale.be
vininorden.se
vitogabriele.com
waffotis.se
welovetweet.com
welplandeast.com
werme.nu
WESTCOASTPERFORMANCECOATINGS.COM
westerntaneyfire.com
westparksports.org
whygre.com
williamarias.us
winemylips.be
wl21www995.webland.ch
wl24www154.webland.ch
woodworksbyjamie.com
wowparis2000.com
www.activcomfrance.com
www.aicis.it
www.antoinemeriaux.com
www.australianslongevity.net
www.bastakigroup.com
www.benquerenciadelaserena.com
www.betteroffgeek.com
www.bizneed.com
www.blowmeupbig.com
www.bracaleart.com
www.bracalemusic.com
www.bradrichmond.com
www.bruleursdeloups.com
www.ce5now.com
www.ceipdoctorseres.org
www.cemmacreation.com
www.cerclewalloncouillet.be
www.chateaudecoisse.com
www.christchurchgastonia.org
www.chuckstevensoldies.com
www.clubpittsburgh.com
www.coloridellavita.com
www.cpvs.org
www.deadlyserious.co.uk
www.deinzahnarzt.com
www.demeuleneire.be
www.drive4faf.com
www.drive4marten.com
www.dueciliguria.it
www.ediltermo.com
www.ekenasbowling.fi
www.emimedical.info
www.eom.it
www.firststategymnastics.com
www.flohr.tuknet.dk
www.footroast.ca
www.gdservices91.com
www.gecahe.com
www.geve.be
www.graceimpact.org
www.hemix.co.za
www.herangi.com
www.hitechsolutioncenter.com
www.hoganjobs.com
www.hotelthier.at
www.idif.it
www.ilfrutteto.net
www.ilterrazzoallaveneziana.it
www.ineedit.es
www.inkdhero.com
www.intelsourcepvt.com
www.jallabyah.com
www.jwdtrees.com
www.kaleto.com.ar
www.kochausleidenschaft.de
www.kylieonline.com
www.lanavabadajoz.com
www.laspheredesservices.fr
www.learningomaha.com
www.liguevolley.be
www.limenspot.com
www.lionkitchen.com.sg
www.listofindia.com
www.lottoladiescycling.be
www.macom.co.at
www.maltesekitchen.com.mt
www.menicia.org
www.musicomm.ca
www.mx2.jellingnet.dk
www.nbcf.co.uk
www.neweed.org
www.nichildrenservices.org
www.nottinghamdowns.com
www.oneofakindsxm.com
www.oneononeprop.co.za
www.paginebusiness.it
www.passionjardin58.com
www.patrickcadona.com
www.pegasolavoro.it
www.politicalnobody.com
www.powertreecorp.com
www.radiovisioncristianahn.com
www.richmondpowerboat.com
www.richwebhosts.com
www.rrmaps.com
www.serendipities.net
www.sevenpinesstables.com
www.shogunlevallois.com
www.signyourweb.com
www.skylergreene.com
www.soluybesttour.com
www.sportmeeuwengruitrode.be
www.steelstoneind.com
www.tabdesign.com.sg
www.taekwondovelden.nl
www.teatraveler.com
www.themitchellmethod.com
www.tizianozanella.it
www.tmunvictoria.com
www.tomsmassagepraxis.at
www.trustonecorp.com
www.usenet4all.ch
www.vallesina.tv
www.vasanthkumar.com
www.vaxjoff.com
www.volleyliga.be
www.wallitdemo.co.za
www.weberschristmasforest.com
www.wnyvfa.org
www.wttcmi.com
www.zarionline.com
yarentextil.com
yonas.se
youvalues.com
zaferburo.com.tr
zanzibarnelpallone.com
zapjuice.tv
ziasgelato.com
zionhills.net
zipro.net


 



Accent Right