Internet Anthropologist Think Tank

  • Search our BLOG


  • HOME
    Terrorist Names SEARCH:
    Loading

    Sunday, June 01, 2008

    Chinese caught red handed HACKING


    Take an example of this PDF file we got a sample of via VirusTotal. The only information we have on this 130kB sample is that it was named f1be1cdea0bcc5a1574a10771cd4e8e8.pdf (after it's MD5 hash) and that it was submitted on the 23rd of May.

    When you open this document, this is what you'll see:

    Department of Homeland Security G-325A

    Looks like a Department of Homeland Security form G-325A.

    Look again.

    What's the filename?

    It's not f1be1cdea0bcc5a1574a10771cd4e8e8.pdf. It's 0521.pdf.

    This is not the document we opened.

    So what happens here?

    Apparently this PDF has been used in a targeted attack against an unknown target.

    When this PDF is opened in Acrobat Reader, it uses a known exploit to to drop files.

    Specifically, it creates two files in the TEMP folder: D50E.tmp.exe and 0521.pdf.

    Then it executes the EXE and launches the clean 0521.pdf file to Adobe Reader in order to fool the user that everything is all right.

    D50E.tmp.exe is a backdoor that creates lots of new files with innocent-sounding filenames, including:

    \windows\system32\avifil16.dll
    \windows\system32\avifil64.dll
    \windows\system32\drivers\pcictrl.sys
    \windows\system32\drivers\Nullbak.dat
    \windows\system32\drivers\Beepbak.dat

    The SYS component is a rootkit that tries to hide all this activity on the infected machine.

    nbsstt.3322.orgThe backdoor tries to connect to port 80 of a host called nbsstt.3322.org. Anybody operating this machine would have full access to the infected machine.

    Well, 3322.org is one of the well-known Chinese DNS-bouncers that we see a lot in targeted attaks. Does nbsstt mean something? Beats me, but Google will find a user with this nickname posting to several Chinese military-related web forums, such as bbs.cjdby.net.

    Where does nbsstt.3322.org point to?

    nbsstt.3322.org

    IP address 125.116.97.19 is in Zhejiang, China.

    And it's live right now, answering requests at port 80.

    SOURCE:
    ....
    sHEESH I'm turning my computer off, cutting the cable and locking it in the attic..
    Lets see them attack it now.

    Call ahh umm somebody...yes somebody should take that PC down and the server.
    Burn them up.

    G

    .

    Labels: , , , , , , , ,

    Terrorist Names SEARCH:
    Loading

    Wednesday, January 09, 2008

    Hacker Arrested for "Internet Terror"


    Hacker Arrested for "Internet Terror"

    Text of report in English by Israeli newspaper The Jerusalem Post website on 1 January

    [Unattributed report: Seventeen-Year-Old Arab Suspected of 'Internet Terror']

    A 17-year-old from the Arab village of Kfar Karah, in Wadi Ara, was arrested overnight Monday on suspicion of hacking into and sabotaging thousands of Web sites, police said. The suspect allegedly wrecked sites belonging to the Likud Party, Maccabi Tel Aviv, shopping sites and sites used as servers by various other companies.

    The Northern District Police Fraud Squad is set to request a five- day remand extension for the suspected hacker.

    Police described the alleged offences as "Internet terror", accusing the teen of working with several associates from Turkey and Saudi Arabia to specifically ruin Israeli websites. As yet, it is unclear if government sites were affected.

    [A related report on Voice of Israel radio (in Hebrew 1000 gmt 1 Jan 08) said: "The hackers used to leave the following message: You are killing Palestinians, and we will kill your servers."]
    SOURCE:


    g


    .

    Labels: ,

    Terrorist Names SEARCH:
    Loading

    Tuesday, September 04, 2007

    China hackers penetrate Pentagon computers


    BEIJING (Reuters) - China on Tuesday rejected a report that hackers controlled by its military had successfully entered a Pentagon network, calling the claim a product of "Cold War" thinking.

    The Financial Times, citing former and serving U.S. officials, said Chinese People's Liberation Army hackers broke into a U.S. Defence Department network in June, taking data and prompting the shutdown of a system serving department secretary Robert Gates.

    The report came a week after German Chancellor Angela Merkel raised similar claims that Chinese hackers had infected German government ministries with spying programs.

    China deflected the German reports, and now it has flatly rejected the U.S. claims, as well as denying reports that Chinese-made weapons have been used by Taliban fighters in Afghanistan.

    "The Chinese government has consistently opposed and vigorously attacked according to the law all Internet-wrecking crimes, including hacking," Foreign Ministry spokeswoman Jiang Yu said.

    "Some people are making wild accusations against China ... They are totally groundless and also reflect a Cold War mentality."

    Beijing has devoted a large part of its rising defence budget to developing more advanced technology, including computer capabilities. But Jiang said her government was also the victim of computer attacks.

    CHINESE MILITARY

    The Financial Times cited one source familiar with the event as saying there was a "very high level of confidence ... trending towards total certainty" that the army was behind it. Continued...

    xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

    Defense Department Responds to Cyber Threats, Official Says
    By Sgt. Sara Wood, USA
    American Forces Press Service

    WASHINGTON, Sept. 4, 2007 – The Defense Department receives many attempted cyber attacks each day and has measures in place to aggressively respond to and deter these attacks, a department spokesman said today.

    Pentagon spokesman Bryan Whitman addressed media reports that a computer system in the Office of the Secretary of Defense was hacked into by the Chinese military earlier this year. Whitman confirmed that an attack did occur in June but declined to identify the origin of the threat. It is often difficult to pinpoint the true origin of an intrusion into computer systems and even more difficult to tie the intrusion to a specific nation or government, he noted.

    "Cyber or non-kinetic type threats to military computer networks are viewed as just as real and just as significant as physical or kinetic threats," Whitman said. "The department aggressively responds to deter all intrusions to defend what is known as the GIG, the global information grid."

    When the intrusion occurred in June, elements of an unclassified e-mail system in the Office of the Secretary of Defense were taken off-line briefly, Whitman said. However, the department has redundant systems in place, so ongoing operations were not disrupted, he said. The system was restored to full service within two or three weeks.

    There are hundreds of attempted intrusions into the Defense Department computer network each day, the majority of which are detected and stopped, Whitman said. The nature of the threat is large and diverse and includes recreational hackers, self-styled cyber vigilantes, various groups with nationalistic or ideological agendas, transnational actors, and nation states. When appropriate, the department turns cases over to law enforcement officials for investigation, he said.

    "We continue to aggressively monitor our networks for intrusions," Whitman said. "We have appropriate procedures to address events of this nature."

    Since the incident in June, Whitman said, he knows of no successful intrusions into the Defense Department computer system.

    Labels: ,