Australia's Leading Computer Emergency Response Team

Its raining Storm
Date: 26 December 2007
Original URL: http://www.auscert.org.au/render.html?cid=7066&it=8557


Hi everyone,

I hope everyone had a great Christmas and Boxing day.

You may have noticed a huge influx of spam emails. In particular, I'd like to mention the Storm group. They went very quiet for a long while. They have now come back with vengeance. On Christmas Eve, we saw a varying number of email subject lines but all had very simple body content.


Example Email Subjects

  • Merry Christmas To All
  • Mrs. Clause Is Out Tonight!
  • Seasons Greetings
  • Time for a little Christmas Cheers.
  • The Twelve Girls Of Christmas
  • Santa Said, HO HO HO
  • Warm Up this Christmas
  • Your Secret Santa
  • Merry Christmas From your Secret Santa
  • Looking for something hot this Christmas


Example email bodies include:

-----------------------------------------------------------------------
Yo,

Here are some real holiday treats, the kind you can't wait to get your hands on. LOL This will be the best 2 min you spend this holiday. hehe h**p :// merrychristmasdude,com/

-----------------------------------------------------------------------

Wha sup,

I know your busy right now but you don't want to miss this, I know its right up your alley. Hey what can 1 min from your day hurt. You wont regret it for sure. ;-)
h**p :// merrychristmasdude,com/

-----------------------------------------------------------------------

got a few minutes?

Winter can be cold. I bet you could use a little something to warm you up. This might not be fun for the whole family, but I bet you'll like it come one take 2 min and check it out.
h**p :// merrychristmasdude,com/
-----------------------------------------------------------------------


All the links are the same but hosted on a fast-flux network.

> merrychristmasdude.com.
------------
Got answer:
    HEADER:
        opcode = QUERY, id = 12, rcode = NOERROR
        header flags:  response, want recursion, recursion avail.
        questions = 1,  answers = 1,  authority records = 0,  additional = 0

    QUESTIONS:
        merrychristmasdude.com, type = A, class = IN
    ANSWERS:
    ->  merrychristmasdude.com
        internet address = 24.166.157.45
        ttl = 0 (0 secs)

> merrychristmasdude.com.

------------
Got answer:
    HEADER:
        opcode = QUERY, id = 13, rcode = NOERROR
        header flags:  response, want recursion, recursion avail.
        questions = 1,  answers = 1,  authority records = 0,  additional = 0

    QUESTIONS:
        merrychristmasdude.com, type = A, class = IN
    ANSWERS:
    ->  merrychristmasdude.com
        internet address = 75.20.226.10
        ttl = 0 (0 secs)
As you can see the TTL (Time-To-Live) is set to zero seconds. This means that every time you do a DNS query of the domain that it will resolve to a different IP. Now let us look at the nameservers:
> set query=ns
> merrychristmasdude.com.

------------
Got answer:
    HEADER:
        opcode = QUERY, id = 14, rcode = NOERROR
        header flags:  response, want recursion, recursion avail.
        questions = 1,  answers = 13,  authority records = 0,  additional = 0

    QUESTIONS:
        merrychristmasdude.com, type = NS, class = IN
    ANSWERS:
    ->  merrychristmasdude.com
        nameserver = ns.merrychristmasdude.com
        ttl = 172573 (1 day 23 hours 56 mins 13 secs)
    ->  merrychristmasdude.com
        nameserver = ns10.merrychristmasdude.com
        ttl = 172573 (1 day 23 hours 56 mins 13 secs)

   [REMOVED FOR CLARITY] 

The setup includes thirteen unique nameservers which aren't fast-flux. They have designed this with a fair bit of redundancy.


Also I'll mention that they have sat on this domain for about a month

Creation Date:         2007.11.27
Updated Date:          2007.12.17
Expiration Date:       2008.11.27

It is also registered through a domain Registrar in Russia, RU-CENTER.

Then on boxing day they have gone mental with New Years postcards, well wishes, greetings and whatever other catch phrases they can mutter.

  • New Year Postcard
  • Wishes for the new year
  • Happy 2008 To You!
  • Happy 2008!
  • Happy New Year To You!
  • Happy New Year To auscert@auscert.org.au!
  • Lots of greetings on new year
  • Message for new year
  • New Hope and New Beginnings...
  • New Year Ecard
  • New Year Postcard
  • New Year wishes for you
  • Opportunities for the new year

Domains include:
  • h**p :// uhavepostcard,com/ (Creation Date: 2007.12.23)
  • h**p :// happycards2008,com/ (Creation Date: 2007.12.26)

These domains are setup the same way as the Christmas domain.

Anyway, I leave it there for you all. I hope you all have a safe and fun New Years eve and New Years day.

Cheers

Zane.