Just received an email for Wordpress blog of a comment to our Botnet Analytics Blog post, that looks so real:
<for security reasons, the header info has been truncated>
To: contact.fingers@gmail.com
Subject: [Botnet Analytics Blog] Please moderate: “Commercializing Botnets”
X-PHP-Script: botnet.kaffenews.com/wp-comments-post.php for xxxxxxx
Date: Wed, 17 Mar 2010 10:01:00 -0400
From: xxxxxx<xxxxxxx@botnet.kaffenews.com>
Message-ID: <62e98c7537ee322c81e19df5ca2d12bd@botnet.kaffenews.com>
X-Priority: 3
X-Mailer: xxxxxx (xxxxxxxxxxxxxxxxx) [version xxxxx]
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=”UTF-8″
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname – xxxxxxx.hostgator.com
X-AntiAbuse: Original Domain – gmail.com
X-AntiAbuse: Originator/Caller UID/GID – [597 597] / [47 12]
X-AntiAbuse: Sender Address Domain – xxxxxx.hostgator.com
A new comment on the post #218 “Commercializing Botnets” is waiting for your approval
http://botnet.kaffenews.com/?p=218
Author : herbal ecstacy (IP: 173.234.19.194 , 173.234.19.194.rdns.ubiquityservers.com)
E-mail : Raulnab@gmail.com
URL : http://bit.ly/herbalecstacy
Whois : http://ws.arin.net/cgi-bin/whois.pl?queryinput=173.234.19.194
Comment:
Hi all, i just found this here after an good google search. Neat blog you got here! Keep it up!
Approve it: http://botnet.kaffenews.com/wp-admin/comment.php?action=approve&c=57
Trash it: http://botnet.kaffenews.com/wp-admin/comment.php?action=trash&c=57
Spam it: http://botnet.kaffenews.com/wp-admin/comment.php?action=spam&c=57
Currently 1 comment is waiting for approval. Please visit the moderation panel:
http://botnet.kaffenews.com/wp-admin/edit-comments.php?comment_status=moderated
In here, the thing that looks real according to us is the comment: “Hi all, i just found this here after an good google search. Neat blog you got here! Keep it up!”.
The other details in the comment indicated that this is a SPAM comment:
Author : herbal ecstacy (IP: 173.234.19.194 , 173.234.19.194.rdns.ubiquityservers.com) —> Ubiquity Servers[Dedicated hosts] are damn cheap compared to other dedicated server accounts [am not comparing with Cloud services], and hence we have been seeing the increase in Botnets & SPAM accounts from there more often. It is not completely true, as in we cannot determine something like that based on hosting provider, although your antennas would turn on[sense of suspicion] and you would start looking for more info.
IP queries on the above IP[173.234.19.194]:
Block Lists …
asiaspam.spamblocked.com: Listed!
bl.deadbeef.com: Not Listed!
bl.emailbasura.org: Not Listed!
bl.spamcop.net: Not Listed!
blackholes.five-ten-sg.com: Not Listed!
blacklist.woody.ch: Not Listed!
bogons.cymru.com: Not Listed!
cbl.abuseat.org: Not Listed!
cdl.anti-spam.org.cn: Not Listed!
combined.abuse.ch: Not Listed!
combined.rbl.msrbl.net: Not Listed!
db.wpbl.info: Not Listed!
dnsbl-1.uceprotect.net: Not Listed!
dnsbl-2.uceprotect.net: Not Listed!
dnsbl-3.uceprotect.net: Not Listed!
dnsbl.abuse.ch: Not Listed!
dnsbl.ahbl.org: Not Listed!
dnsbl.cyberlogic.net: Not Listed!
dnsbl.inps.de: Not Listed!
dnsbl.njabl.org: Not Listed!
dnsbl.sorbs.net: Not Listed!
drone.abuse.ch: Not Listed!
duinv.aupads.org: Not Listed!
dul.dnsbl.sorbs.net: Not Listed!
dul.ru: Not Listed!
dyna.spamrats.com: Not Listed!
dynip.rothen.com: Not Listed!
eurospam.spamblocked.com: Listed!
fl.chickenboner.biz: Not Listed!
http.dnsbl.sorbs.net: Not Listed!
images.rbl.msrbl.net: Not Listed!
ips.backscatterer.org: Not Listed!
isps.spamblocked.com: Listed!
ix.dnsbl.manitu.net: Not Listed!
korea.services.net: Not Listed!
lacnic.spamblocked.com: Listed!
misc.dnsbl.sorbs.net: Not Listed!
noptr.spamrats.com: Not Listed!
ohps.dnsbl.net.au: Not Listed!
omrs.dnsbl.net.au: Not Listed!
orvedb.aupads.org: Not Listed!
osps.dnsbl.net.au: Not Listed!
osrs.dnsbl.net.au: Not Listed!
owfs.dnsbl.net.au: Not Listed!
owps.dnsbl.net.au: Not Listed!
pbl.spamhaus.org: Not Listed!
phishing.rbl.msrbl.net: Not Listed!
probes.dnsbl.net.au: Not Listed!
proxy.bl.gweep.ca: Not Listed!
proxy.block.transip.nl: Not Listed!
psbl.surriel.com: Not Listed!
rbl.interserver.net: Not Listed!
rdts.dnsbl.net.au: Not Listed!
relays.bl.gweep.ca: Not Listed!
relays.bl.kundenserver.de: Not Listed!
relays.nether.net: Not Listed!
residential.block.transip.nl: Not Listed!
ricn.dnsbl.net.au: Not Listed!
rmst.dnsbl.net.au: Not Listed!
sbl.spamhaus.org: Not Listed!
short.rbl.jp: Not Listed!
smtp.dnsbl.sorbs.net: Not Listed!
socks.dnsbl.sorbs.net: Not Listed!
spam.dnsbl.sorbs.net: Not Listed!
spam.rbl.msrbl.net: Not Listed!
spam.spamrats.com: Not Listed!
spamlist.or.kr: Not Listed!
spamrbl.imp.ch: Not Listed!
t3direct.dnsbl.net.au: Not Listed!
tor.ahbl.org: Not Listed!
tor.dnsbl.sectoor.de: Not Listed!
torserver.tor.dnsbl.sectoor.de: Not Listed!
ubl.lashback.com: Not Listed!
ubl.unsubscore.com: Not Listed!
virbl.bit.nl: Not Listed!
virus.rbl.jp: Not Listed!
virus.rbl.msrbl.net: Not Listed!
web.dnsbl.sorbs.net: Not Listed!
wormrbl.imp.ch: Not Listed!
xbl.spamhaus.org: Not Listed!
zen.spamhaus.org: Not Listed!
Reverse DNS/Canonical name Info …
Host IP : 173.234.19.194
Canonical Name : 173.234.19.194.rdns.ubiquityservers.com
Whois Info ...
GeekTools Whois Proxy v5.0.4 Ready.
Checking access for 74.220.215.117... ok.
Final results obtained from whois.arin.net.
Results:
Nobis Technology Group, LLC NETBLK-NOBIS-TECHNOLOGY-GROUP-08 (NET-173-234-0-0-1)
173.234.0.0 - 173.234.255.255
Ubiquity Server Solutions Dallas NETBLK-UBIQUITY-DALLAS-173-234-16-0 (NET-173-234-16-0-1)
173.234.16.0 - 173.234.19.255
# ARIN WHOIS database, last updated 2010-03-16 20:00
# Enter ? for additional hints on searching ARIN's WHOIS database.
#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at https://www.arin.net/whois_tou.html
Results brought to you by the GeekTools WHOIS Proxy
Server results may be copyrighted and are used with permission.
Your host (74.220.215.117) has visited 1 times today.
Though few of the above listed RBL’s listed that it was LISTED in them, Senderbase.org did not have any records of it since the following block lists that are used by many websites because of their true positive nature has not LISTED the SPAMMING IP/site “yet”:
AbuseAT CBL........................: Not Listed!
AHBL DNSBL.........................: Not Listed!
China Anti-Spam Alliance CBL.......: Not Listed!
China Anti-Spam Alliance CBLLESS...: Not Listed!
China Anti-Spam Alliance CBLPLUS...: Not Listed!
EFNet RBL..........................: Not Listed!
Manitu DNSBL.......................: Not Listed!
NJABL DNSBL........................: Not Listed!
Sorbs web..........................: Not Listed!
Sorbs DNSBL........................: Not Listed!
Spamcop BL.........................: Not Listed!
SURBL Multi........................: Not Listed!
Surriel PSBL.......................: Not Listed!
UCEPROTECT DNSBL Level 1...........: Not Listed!
UCEPROTECT DNSBL Level 2...........: Not Listed!
UCEPROTECT DNSBL Level 3...........: Not Listed!
UCEPROTECT DNSBL BackScatterer.....: Not Listed!
URIBL Multi........................: Not Listed!
WPBL DNSBL.........................: Not Listed!
E-mail : Raulnab@gmail.com —> Did not find any records for this email.
URL : http://bit.ly/herbalecstacy —> This takes you to http://www.herbal-ecstacy.com/. Watch out for such TINY URL’s. Bit.ly & TinyURL does a great job of shrinking URL’s although this remains a threat to home users who click on URL’s without knowing where they are really taken to. JSunpack results can be viewed at:
http://jsunpack.jeek.org/dec/go?report=413fe49475b141fba1ed79768a64bd3b375385bf
In the above report, the following are listed suspicious:
suspicious: MSIEUseAfterFree CVE-2010-0249 detected
www.herbal-ecstacy.com/js/prototype.js suspicious
[suspicious:5] (script) www.herbal-ecstacy.com/js/prototype.js
suspicious: MSIEUseAfterFree CVE-2010-0249 detected
info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
info: ObfuscationPattern detected location eval String.fromCharCode
info: [script http] :
info: [decodingLevel=0] found JavaScript
info: [decodingLevel=0] decoded 542 bytes (decoding_467bcc4d36c9ddf09f15dac1e9e767806b4e4d66)
info: [decodingLevel=1] found JavaScript
info: [file] saved www.herbal-ecstacy.com/js/prototype.js to (original_1703adc185bd3af6e8dec62e343907805fdf342f)
www.herbal-ecstacy.com/ suspicious
[nothing detected] www.herbal-ecstacy.com/
info: [script .] www.herbal-ecstacy.com/products.js
info: [script .] www.herbal-ecstacy.com/js/prototype.js
info: [script .] www.herbal-ecstacy.com/js/scriptaculous.js?load=effects,builder
info: [script .] www.herbal-ecstacy.com/js/lightbox.js
info: [img http] www.herbal-ecstacy.com/images/help.jpg
info: [img .] www.herbal-ecstacy.com/images/hyperdrive-herbal-ecstacy.jpg
info: [img .] www.herbal-ecstacy.com/images/neuro-herbal-ecstacy.jpg
info: [img .] www.herbal-ecstacy.com/images/slowdown-herbal-ecstacy.jpg
info: [img .] www.herbal-ecstacy.com/images/sextreme-herbal-extacy.jpg
info: [img http] www.herbal-ecstacy.com/images/creditcard.jpg
info: [img http] cashburners.com/click.php?id=secureserver&group=3&referer=http://www.google.com/trends/hottrends
info: [decodingLevel=0] found JavaScript
Whois : http://ws.arin.net/cgi-bin/whois.pl?queryinput=173.234.19.194 —> If you would like to view the Whois info.
This shows that SPAMMERs are taking steps to ensure that they look legit and hide among the “NORMAL” category of responses, although the Security Analysts out there aren’t going to give up either. Hope this helps. Thank you for choosing EvilFingers!