Friday, August 5, 2011

Infamous SPAMRAT 'Spamford' Indicted,
Facing A Possible 16 Years In Jail :-D


I'm a veteran SPAMRAT hunter / destroyer. I've killed off so many SPAMRATS, I'm convinced I'm on their 'Do Not Spam' list for fear that I'll hunt them down and eliminate them. I very rarely receive SPAM in my email these days. Instead, I get verification and thank you notes from ISPs when they shut down SPAMRATS I've reported.


Therefore, it is with great glee that I read over the past couple days that the single most infamous SPAMMER of all time is facing a possible 16 years in jail for his nefarious damage to the Internet. Who's the SPAMRAT? It's Sanford 'Spamford' Wallace. He represents the ultimate Marketing Moron, an idiot who literally hates his customers and bombs them with marketing manure at every opportunity with no conscience, no respect for the consequences. I'd go so far as to label him and his ilk psychopathic, but don't consider me any expert on psychology.

Spamford's trial is scheduled to start August 22nd. Below are a few articles about the story so far.

Spam King Sanford Wallace Indicted for Facebook Spam

Infamous spam king could get prison time for Facebook spamming, phishing

Sanford Wallace @ Wikipedia

If you'd like to become a SPAMRAT hunter as well, here's a great place to start. I've been a paying contributor since 1998:

SpamCop.net

Every chunk of SPAM you turn in to SpamCop.net is verified, reported to affected ISPs, the offender listed on a SPAM blacklist provided free to the public. I've heard SPAMRATS rant in public about how much they hate SpamCop.net. Relish that thought. Contribute to the cause.

;-Derek

Wednesday, August 3, 2011

McAfee Figures Out That Red China
Has Been Hacking The USA
For Five Years



Red China has been hacking the USA government since 1998, the year China was given 'Most Favored Nation' status. 1998 was the year the roots of China's government hacking gathered together and formed 'The Red Hacker Alliance'. It used to be that the Red Chinese government denied paying The Red Hacker Alliance for its services. These days TRHA has simply been integrated directly into the Chinese government. They no longer operate as in independent entity.


The USA government was forced to admit China's activity in 2007 after the public was informed that government Windows OS computers connected to the Internet had been infected with bot malware that was feeding ALL available USA government documents directly to China. An internal Chinese memo was also uncovered around that time which declared a cyber war against the USA.


And now we get to read that McAfee figured out, here in 2011, that Red China has been hacking the USA for the last five years. Incredible DUH Factor:


Travel back to some of my earliest posts in this blog for more about the history of Red China's declared Cyber War against the USA. Here's a relevant article from 2006, five years ago:


Here's a link to a post I made over at Soft32.com's Mac forum on May 31, 2007:


As I quoted from the SANS Institute's NewsBites newsletter, Volume 9, Number 43:
--DoD Report: China Bolstering Cyber Warfare Capabilities  (May 28 & 29, 2007) 
China "has established information warfare units to develop viruses to  attack enemy computer systems and networks, and tactics and measures to  protect friendly computer systems and networks," according to a recent  report from the US Defense Department (DoD). In previous years, the  Pentagon's annual report to Congress on China's military power has  indicated that China was focusing on defensive measures, so the shift  to offensive tactics merits attention. 
So where have you been for five years McAfee? And why does the tech press think McAfee's late revelation is news?

Here are a further few China cyber war articles from way back when:

May 30, 2007

Cyber Warfare: Beyond Estonia-Russia, Rise of China's 5th Dimension Cyber Army for the 21st Century


September 14, 2007


October 9, 2009


CONCLUSION: Think about Red China screwing over the USA as well as the rest of the world the next time you buy cheap stuff 'Made In China'. Wonder why the USA still provides Red China with 'Most Favored Nation' status considering the fact that China has declared war against us. Think about the motives of the traitorous Corporate Oligarchy that really rules the USA government.
--

Friday, July 8, 2011

Current Mac Malware, 2011-07:
Introduction

In order to help Mac users understand the current state of malware on the platform, I am providing a review  of each current form. This will not be an exhaustive review, but should help relieve much misunderstanding and concern about the ongoing, many years old, anti-Apple security FUD Fest.

I will be going through the malware in reverse chronological order, featuring the most current concerns first and the oldies but gnarlies last.

The first thing to know is that technically, ALL currently active Mac malware are Trojan horses. That means that they are entirely inert until such time as a user (or 'LUSER', in cynical terminology) inadvertently installs them.

I am NOT including any hacker tools or 'legal' spyware in my details articles. These require a third party to be able to physically access your computer and directly install them for their nefarious purposes. You won't personally be in any danger of installing them unless a hacker or IT administrator directs you to do so. They require hackers or administrators to access your computer in order for them to do any harm. I may address these forms of software at another time. I am more concerned about what YOU might mistakenly install.

THE LIST:

1) Trojan.OSX.MACDefender.A - O [15 strains]

2) Trojan.OSX.BlackHoleRAT.A - C [3 strains]

3) Trojan.OSX.Boonana.A

4) Trojan.OSX.OpinionSpy.A - B [2 strains]

5) Trojan.OSX.iServices.A - C [3 strains]

6) Trojan.OSX.PokerStealer.A

7) Trojan.OSX.RSPlug.A - Q [17 strains]

The total number of Mac malware species are 7.
The total number of Mac malware strains are 42.


The 'Malware' Hacker Tools I Am Leaving Out:

'Trojan'.OSX.Lamzev.A

'Trojan'.OSX.Hellraiser.A - D [4 strains]

There are a number of inert malware as well as 'Proof of Concept' malware of no concern which I have also left out of my list. You may find them on other lists but you won't find them infecting anyone with up-to-date computers, apart for test computers in a lab. (A famous example of 'Proof of Concept' malware is Trojan.OSX.Oomp.A, aka Trojan.OSX.Leap.A. It is of no consequence or importance).

If you'd like a list of current 'legal' spyware, I suggest the list kindly provided at the MacScan/SecureMac site.

Note that, due to the lack of adherence to standards within the anti-malware community, there are a lot of name variations for the exact same malware. In the case of the MAC Defender Trojan I discovered 15 different names. I am not including them here in my list as these alternative names are irrelevant and needlessly confusing. What I have listed here are the 'official' names from my point of view as well as those whom I consider to be professional experts and original malware discoverers in the field. However, I will be listing a number of the alternative names in my subsequent articles that provide details about each of the current malware species.

As ever, I request corrections to my information. If I have missed a malware species or strain, please let me know asap. Much appreciated!

Friday, July 1, 2011

World Laughs At China's Blundered Trickery


There are few things as carthartic as a good laugh in the face of deceitful intent.

Just in time to counter 'China Chip-gate', officials of the totalitarian 'communist' nation are caught using blundered Photoshop trickery for a publicity photo. The press is all abuzz about the magical picture where three Huili country officials are miraculously floating inches above the road they are inspecting.

Such is the level of attention to facts and honesty in the current Chinese culture. (0_o)

Joyfully, the ongoing response around the world has been to copy and paste the Huili officials into various other scenarios. Do a search on the terms 'Huili officials' and you'll get a boatload.  Check back often for new configurations. ;-)

Google: Huili officials

Here is an article about the hilarity that includes an incredible number of creative examples:

Floating Chinese Government Officials Inspect New Road

For your own photo trickery pleasure, I have provided rough .PNG images of the three Huili officials, with invisible backgrounds. Just drag them out of the article into your favorite scenario! It's fun. Post your images to the internet and be sure to put 'Huili officials' in the title.

Share and Enjoy,

;-Derek

Wednesday, June 29, 2011

China Laughs At US Federal Security

Way back in 2007, when I started this blog, I had a run in with the members of China's 'Red Hacker Alliance'. I reposted their history and reiterated hacker crimes they'd been pulling against the USA since 1998, the year China was given 'Most Favored Nation' status. 2007 was the year the US feds finally admitted the reality of the situation, after the Chinese government memo declaring 'Technology War' on the USA became public knowledge, after the US feds discovered that every one of their computers connected to the Internet had been botted by Chinese malware, sending to China ever piece of accessible data.
•••
Now here we are 4 (FOUR) years later and THIS happens:

If left undiscovered the result could have rendered useless U.S. missiles and killed the signal from aircraft that tells everyone whether it's friend or foe.
Who can blame China for laughing?
•••
How about the Obama administration offers me the CIO cabinet position? I couldn't possibly do any worse.
--

Friday, June 10, 2011

More Critical Adobe Security Updates
blahblahblah

--
If you haven't gotten the hang of it yet, despite Adobe's scheduled quarterly updates to their software, they've been pushing out security updates at the rate of about once a month. March was no exception. April was no exception. May was no exception. I didn't bother to announce them all here because it has become all so predictable that I figure everyone knows to watch for them coming.

And now it's June. Here comes the quarterly update, like we care that it's quarterly. Why Adobe bother with his BS is beyond my comprehension. I personally think they're nuts over there.

So here we go, the quarterly update announcement is HERE. The quarterly update comes out Tuesday, June 14th. As per usual, it is a CRITICAL security update. It will be for both Adobe Reader and Adobe Acrobat.

If you'd like to keep track of when future 'out of band' (non-quarterly, once a month) security updates from Adobe are released, the two best web locations are:

Adobe Security Bulletins and Advisories

Adobe Product Security Incident Response Team (PSIRT) Blog

Predictable as these 'out-of-band' critical security updates have become over the last full year, keep in mind that if you use Adobe's stuff, it is important to keep up-to-date with their security patches if you want to keep your Mac as safe as possible.

Over and out.
--

Saturday, June 4, 2011

The CARO Malware Naming Scheme

--


In 2009, amidst my trying to sort out why malware naming is chaotic within the anti-malware community, I came across an elegant malware naming system from CARO (The Computer AntiVirus Researcher's Organization) that is considered the standard. It has no competing proposed system apart from the 'whatever' mess practiced by the various anti-malware researchers/companies.


Recently I have been volunteering time with a group of other Mac security geeks as we try to keep track of what is going on with the Trojan.OSX.MAC Defender scamware series and provide malware signatures to the ClamAV Open Source project. One of our members was musing about applying the biological taxonomy system to malware naming. I wrote back that malware naming doesn't successfully fit within that system. Instead I described the CARO Scheme while tossing in a few of my usual rants about chaos in the anti-malware community. For those interested, here is my description of the CARO Scheme:


~~~~~~~~~~



There is an standard malware naming system called the 'CARO Malware Naming Scheme'. Despite its existence and age, it is generally ignored in favor of chaos. As the description article itself states:
No matter how good a naming standard, it is mostly worthless if nobody is using it. And, as experience has demonstrated, some anti–virus producers would fol- low their own malware naming scheme in royal disregard of any proposed standards.
You can read about the CAROS scheme here:


To quote:
The general format of a Full CARO Malware Name is
[(type)://][(platform)/](family)[.(group)][.(length)].(variant)[(modifiers)][!(comment)]
where the items in square brackets are optional. According to this format, only the family name and the variant name of a piece of malware are mandatory and, as we shall see later, even the variant name can be omitted when reporting it. The Full Name is white space–delimited. That is, it cannot contain white space (i.e., space, tab, car- riage return, line feed), and there is a white space before and after it.


Here is the general CARO approach:

1) The name starts with the type of malware. For Macs, all the malware are Trojan horses. Therefore, they all begin with 'Trojan' followed by a period. 

Due to the mixed types of malware being created these days, this can get messy. Some malware these days are Trojans that infect the target with a bot, which itself is a worm by way of spewing SPAM or DDOS attackes. This is the case with the iServices Trojan. But I believe the best approach here is to name the malware type as that which is initially presented to the target computer. Therefore, Trojan works in all the current Mac cases.

However, I still argue that hacker tools are NOT Trojans. They're just hacker tools. They are only infected onto computers by way of 'LUSER' behavior whereby a hacker inadvertently has physical access to the target computer.

2) The malware type is followed by the target OS name. In our case it is 'OSX'. Previous to Mac OS X, the term 'MacOS' was used. But since Mac OS X is certified UNIX, the term 'Mac' is being dropped and only 'OSX remains. The OS name is followed by another period.

3) The third part of the name is supposed to be left to whomever first discovers the malware in the wild and chooses a name for it. 

For example, Andrew Welch (of Ambrosia Software) was the first person to fully describe and name the proof-of-concept Trojan which he named "Oompa-Loompa" or simply "Oomp". Using his variation on the Caro scheme, the resulting name was:

Trojan/OSX/Oomp-A

But Symantec has more clout than Andrew and after his work pushed out the name 'leap' instead, resulting in their name of it:

Trojan.OSX.Leap.A

4) The fourth part of the name specifies the variant, starting with A through Z, proceeding to AA through ZZ, etc. Therefore, at this point we have (I think):

Trojan.OSX.MAC Defender.A
Trojan.OSX.MAC Defender.B
Trojan.OSX.MAC Defender.C
Trojan.OSX.MAC Defender.D

Unfortunately, it is left up to interpretation as to what constitutes a new variant. As I noted over the weekend, I've seen MAC Defender.E listed, for reasons I cannot explain. With the two new proven varients, apparently that naming source would be up to MAC Defender.G at least, at this point.

I like Shawn's idea about digging into the actual Trojan app's Contents directory to check out the guts of each potentially new 'variant'. The web page GUI variations are clearly of little importance compared to the actual Trojan app variations.

5) If there are further details about a specific malware, they are typically put in parentheses after the variant identifying letter. For the MAC Defender variants this would include all the names for the installer files and the various names the Trojan application gives itself. Therefore, we could have:

Trojan.OSX.MAC Defender.B (aka Apple Security Center, aka Apple Web Security...)

~~~~~~

I have never seen the Caro scheme used exactly in the original proposed format. But the general approach of focusing from abstract to specific has remained in most of the offshoots of the scheme. Typically, the separators between the naming items are simply periods, as in: 

Trojan.OSX.MAC Defender.A

Intego stick to this specific pattern.

Microsoft use a colon instead of the first period, resulting in:

Trojan:OSX.MAC Defender.A

See:

Some companies choose to use forward slashes and dashes in their malware naming, resulting for example in:

Trojan/OSX/MAC Defender-A

Overall, because this is what I call 'The Wild West Era' of the anti-malware community, malware naming chaos reigns. There are commonly three publicly published names from various anti-malware researchers/companies for exactly the same malware. In the case of MAC Defender I've counted over 15 names at VirusTotal for what may only be MAC Defender.A.


I hope my lecture was helpful. ;-)


:-Derek
--