Friday, September 19, 2008

BulkEnt

Yeah, I am breathing.
BulkEnt/Gary Garrett is next.

About a year ago the following was posted on bulkerforum.biz:

Hey guys

We are looking for one or two responsible/can-spam compliant mailers to do a few mailings for us. We need to do a little more testing to tweak our system before launching 100%. I am willing to pay upfront if you have good references. The product is mobile phone text-message(SMS) based. I am looking for someone that can hit all the major ISPs and can send atleast a few million per day. Contact me ASAP for more details as we are looking to get started right away.

AIM: BulkEnterprise
ICQ: 221-281-113
Yahoo: BulkEnt1
If this ebizpro ever got his bluetooth and SMS-spamming up and going is an open question.

If someone else is more eager than me, go ahead.

Wednesday, April 16, 2008

spam-court.com taken offline

For an unspecified time. Forever is definately a possibility.
Watch ducksintworows.blogspot.com or this one instead.
If you feel it is worth the time.

Saturday, March 1, 2008

Nathan ("n")

Briefly mentioned by Ducks in his "snippets":

  • Note to self: The nick "n" is probably also known as elitet0kr, EvilAnarchistGuy, nathanownzu, t0k3d, EliteRAHA. Remember the guy from a couple of years back: Nathan?

I don't know what he mean by the last sentence, I should have a chat with him about that. But the info about his other nicks are correct with one exeption, I doubt that he is "EvilAnarchistGuy". I also add another of his nicks which is very interesting: t0k3d. More about that one later.

Anyway, on bulkerforum.biz he was offering proxies for sale.
A post from Tue Feb 05, 2008, not so long ago:
Hello,

I am selling high quality IP restricted proxys that are HP scanned and have anti-honeypot code working at the bot-level to get rid of those tricky HPs. As of now there are 1.5-2.5k working, unlisted (spamcop, spamhaus) proxys online at any given time. The list is reset every 1.5 to 2 hours, depending on what the customer wants. The proxy supports socks4 and socks5, no HTTP as of yet, sorry.

The cost is $150/week for every IP authorized on the proxys. This includes scanning/proxy checker servers as well. Many people ask me why they have to pay for the scanning/proxy checker server. It is simply because every IP takes up space in the IP authorization bracket, and that is what I base the price on.

If you are interested, my Skype is savethedogs. PM me for AIM and MSN.


Legal proxies? Hardly.
He had another posting back in September 2007 with some nice screenshots.
There are also some other screenshots floating around which can be tied to his highly illegal activity. And a domain name legi0n.net (now expired) is highly interesting. That domain has been involved in some criminal activitity a few years back (nicked from http://www.f-secure.com/v-descs/ircbot_es.shtml):

The backdoor's file is a PE executable file about 8 kilobytes long, packed with MEW file compressor and patched with PE_Patch.

When the backdoor's file is activated on a computer, it copies its file to Windows System folder as MOUSEBM.EXE and then starts the copied file as a service named 'Mouse Button Monitor', described as follows:

Enables a computer to maintain synchronization with a PS/2 pointing device.
Stopping or disabling this service will result in system instability.

If the backdoor fails to start its service, it tries to inject its code into Explorer.exe process. When active, the backdoor connects to one of the following servers on port 18067:

esxt.is-a-fag.net
esxt.legi0n.net

Then backdoor joins an IRC channel called '#p2' using the hardcoded password and creates a bot there. A remote hacker can control a backdoor via a bot that it creates in the '#p2' channel. A hacker can do any of the following:
  • scan for vulnerable computers and spread to them using PnP exploit
  • download and run files on an infected computer
  • find files on local hard disks
  • perform DDoS (Distributed Denial of Service) attack
  • perform SYN and UDP flood
The backdoor has the ability to spread to remote computers using the PnP exploit on port 445. Please see the following page for detailed information on the vulnerability:

http://www.microsoft.com/technet/security/Bulletin/MS05-039.mspx

Detection

Detection for this malware was published on August 15th, 2005 in the following F-Secure Anti-Virus updates:

[FSAV_Database_Version]

Version=2005-08-15_05


You asked for screenshots?
Here is a couple, note his nicks and his website. I split this one in two:



More screenshots will be added if needed.

Someone should kick his Butt.

Friday, December 7, 2007

Ron Paul spam tied to bulkerforum.biz

This story on slashdot made a couple of bells start ringing.

... someone calling themselves nenastnyj was behind it and their botnet control server has been shut down


nenastnyj is a member of bulkerforum.biz. You will probably know him as "nena" over there.
Drug spammer apparently in charge of PharmaBucks. Here is his first posting on bulkerforum in January 2007:

Posted: Tue Jan 09, 2007 7:36 am
Post subject: New big money with PharmaBucks
Dear colleagues (we hope that we will be able to call you partners of our partnership program in future),

The partnership program "PharmaBucks" is more than happy to encourage you to cooperate with us.

For the time being, there is one shop and four medical preparations, that are the most needed, available in our partnership program.

We offer you sales with commissions from 30 to 50%. According to the promotion of our program everybody who registers before February 1st, 2007 will be registered in partnership plan " Silver " that offers you 40%.

Our conditions and benefits:

- Detailed and very honest statistics! You will feel it from the very first minute of our cooperation;
- Commissions up to 55%;
- Referral system of 5%
- Our own steady bulk-servers;
- Support is always ready to answer your questions comprehensively and correctly;
- Daily change of domains, personal domains for the big adverts;
- Regular professional text refreshments;
- Salaries webmoney, fethard, wire;
- Hold – 14 days;
- % commissions according to the following tariff description:

0-10 sales per day - 30% commission
11-20 sales per day - 40% commission
20-50 sales per day - 45% commission
50+ sales per day - 55% commission


Our cooperation and your time is of a great value for us, that’s why we made all the conditions of successful and lucrative cooperation with you so much easier.

Everybody, from the beginners to the professionals, is more than welcome to join our partnership program. Respectful and sophisticated Support is always ready to help you with any kind of problem.

Our working team consists of exceptional professionals that have invested all their experience acquired throughout many years into this program.
We are always looking with a perspective concentrating our attention and experience only on reaching the highest peaks, comprehensively analyzing and improving our accomplishments.

We hope that you will value our advantages starting from today.

To register and start working you can by connecting to this ICQ number: 303-435-751.
Back to top
View user's profile Send private message
ICQ Number <------- 304927900 304-927-900

A bit later he answers neuman's question:
what are the products?

now only 4, and 1 shop, soon ill be 4more products
now only Viagra Soft tabs Cialis soft tabs, cialis, and viagra pro


A small image from pharmabucks.biz when the page was still up:

We have not been following nena/PharmaBucks around, so we don't know the story after January.


Back to the Ron Paul spam:
More details in a report from Secureworks.
A bit shorter version on ars technica

And there is something else that is a bit interesting in that report.
The Ron Paul spam has been tied to "Reactor botnet". "spamit" on bulkerforum is being mentioned, but SecureWorks doubt he is the author. It is more likely that he is a customer of the author of the bot controlling software.
Interesting points anyway.

Now, I highly doubt that the Russians are especially interested in US politics.
Which leaves the question: Which american spammers (and probably with connections to bulkerforum.biz) are behind the spam for Ron Paul?

We know that the Digital Gangstas Matt Leppala, Pete Snoufax and ytcracker are close to an orgasm if Ron Paul is being mentioned. But we have no idea if they were behind the spam. n0fx on bulkerforum is an old buddy of them.

Thursday, December 6, 2007

DucksInTwoRows blog is back

Has been up back again for a few days now.
Not any new content now.
Writing a small draft on kref/spamit.
And another small one on toxicdog and his alias.