Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of...

38

Transcript of Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of...

Page 1: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 2: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 3: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 4: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 5: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 6: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 7: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 8: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 9: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 10: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 11: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 12: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 13: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.

Marketplace Ads for Goods

Page 14: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.

Marketplace Ads for Services

Page 15: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 16: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 17: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 18: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.

The Storm botnet

Overnet (UDP)‏Reachability check

Page 19: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.

Infe

cted

mac

hine

sH

oste

d in

frast

ruct

ure

TCP

HTTP

HTTPproxies

Workers

Proxybots

Botmaster

The Storm botnet

Page 20: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.

If we controlthese …

… we can monitor &influence these

Page 21: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 22: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 23: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 24: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 25: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.

Types of Storm C&C Messages

• Activation (report from bot to botmaster)• Email address harvests• Spamming instructions• Delivery reports• DDoS instructions• FastFlux instructions• HTTP proxy instructions• Sniffed passwords report• IFRAME injection/report

Page 26: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.

Spam campaign mechanics

TCP

HTTP

HTTPproxies

Workers

Proxybots

Botmaster

Page 27: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.

Campaign mechanics: harvest

TCP

HTTP

HTTPproxies

Workers

Proxybots

Botmaster

@@@@

@

@@ @

Page 28: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 29: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.

Campaign mechanics: spamming

TCP

HTTP

HTTPproxies

Workers

Proxybots

Botmaster

Page 30: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 31: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 32: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.

Campaign mechanics: spamming

TCP

HTTP

HTTPproxies

Workers

Proxybots

Botmaster

Page 33: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 34: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.

Spamalytics

Who is targeted?Who is targeted?

34

• Top 20 domains• Many Web mail & broadband

providers, but very long tail• Campaigns have nearly identical

distributions• Same scammers, or target

lists sold to multiplescammers

• Also see spam campaigns sentsolely to test accounts

Page 35: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.

Campaign mechanics: reporting

TCP

HTTP

HTTPproxies

Workers

Proxybots

Botmaster

Page 36: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 37: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.
Page 38: Scams - ICIR · Spam target email address. FQDN of sending bot, as reported to the bot as part of the preceding C&C exchange. Creates content-boundary strings for multi-part messages.