Date: 26 December 2007
Click here for printable version
Hi everyone,
I hope everyone had a great Christmas and Boxing day.
You may have noticed a huge influx of spam emails. In particular, I'd like to mention the Storm group. They went very quiet for a long while. They have now come back with vengeance. On Christmas Eve, we saw a varying number of email subject lines but all had very simple body content.
Example Email Subjects
- Merry Christmas To All
- Mrs. Clause Is Out Tonight!
- Seasons Greetings
- Time for a little Christmas Cheers.
- The Twelve Girls Of Christmas
- Santa Said, HO HO HO
- Warm Up this Christmas
- Your Secret Santa
- Merry Christmas From your Secret Santa
- Looking for something hot this Christmas
Example email bodies include:
-----------------------------------------------------------------------
Yo,
Here are some real holiday treats, the kind you can't wait to get your
hands on. LOL This will be the best 2 min you spend this holiday. hehe
h**p :// merrychristmasdude,com/
-----------------------------------------------------------------------
Wha sup,
I know your busy right now but you don't want to miss this, I know its
right up your alley. Hey what can 1 min from your day hurt. You wont
regret it for sure. ;-)
h**p :// merrychristmasdude,com/
-----------------------------------------------------------------------
got a few minutes?
Winter can be cold. I bet you could use a little something to warm you
up. This might not be fun for the whole family, but I bet you'll like it
come one take 2 min and check it out.
h**p :// merrychristmasdude,com/
-----------------------------------------------------------------------
All the links are the same but hosted on a fast-flux network.
> merrychristmasdude.com.
------------
Got answer:
HEADER:
opcode = QUERY, id = 12, rcode = NOERROR
header flags: response, want recursion, recursion avail.
questions = 1, answers = 1, authority records = 0, additional = 0
QUESTIONS:
merrychristmasdude.com, type = A, class = IN
ANSWERS:
-> merrychristmasdude.com
internet address = 24.166.157.45
ttl = 0 (0 secs)
> merrychristmasdude.com.
------------
Got answer:
HEADER:
opcode = QUERY, id = 13, rcode = NOERROR
header flags: response, want recursion, recursion avail.
questions = 1, answers = 1, authority records = 0, additional = 0
QUESTIONS:
merrychristmasdude.com, type = A, class = IN
ANSWERS:
-> merrychristmasdude.com
internet address = 75.20.226.10
ttl = 0 (0 secs)
As you can see the TTL (Time-To-Live) is set to zero seconds. This means that every time you do a DNS query of the domain that it will resolve to a different IP. Now let us look at the nameservers:
> set query=ns
> merrychristmasdude.com.
------------
Got answer:
HEADER:
opcode = QUERY, id = 14, rcode = NOERROR
header flags: response, want recursion, recursion avail.
questions = 1, answers = 13, authority records = 0, additional = 0
QUESTIONS:
merrychristmasdude.com, type = NS, class = IN
ANSWERS:
-> merrychristmasdude.com
nameserver = ns.merrychristmasdude.com
ttl = 172573 (1 day 23 hours 56 mins 13 secs)
-> merrychristmasdude.com
nameserver = ns10.merrychristmasdude.com
ttl = 172573 (1 day 23 hours 56 mins 13 secs)
[REMOVED FOR CLARITY]
The setup includes thirteen unique nameservers which aren't fast-flux. They have designed this with a fair bit of redundancy.
Also I'll mention that they have sat on this domain for about a month
Creation Date: 2007.11.27
Updated Date: 2007.12.17
Expiration Date: 2008.11.27
It is also registered through a domain Registrar in Russia, RU-CENTER.
Then on boxing day they have gone mental with New Years postcards, well wishes, greetings and whatever other catch phrases they can mutter.
- New Year Postcard
- Wishes for the new year
- Happy 2008 To You!
- Happy 2008!
- Happy New Year To You!
- Happy New Year To auscert@auscert.org.au!
- Lots of greetings on new year
- Message for new year
- New Hope and New Beginnings...
- New Year Ecard
- New Year Postcard
- New Year wishes for you
- Opportunities for the new year
Domains include:
- h**p :// uhavepostcard,com/ (Creation Date: 2007.12.23)
- h**p :// happycards2008,com/ (Creation Date: 2007.12.26)
These domains are setup the same way as the Christmas domain.
Anyway, I leave it there for you all. I hope you all have a safe and fun New Years eve and New Years day.
Cheers
Zane.
|