Home / Blogs

Moving Target: Spammer Using Over 1000 Home Computers as DNS

Richard M. Smith

Some individual appears to have hijacked more than a 1,000 home computers starting in late June or early July and has been installing a new Trojan Horse program on them. The Trojan allows this person to run a number of small websites on the hijacked home computers. These websites consists of only a few web pages and apparently produce income by directing sign-ups to for-pay porn websites through affiliate programs. Spam emails messages get visitors to come to the small websites.

To make it more difficult for these websites to be shut down, a single home computer is used for only 10 minutes to host a site. After 10 minutes, the IP address of the website is changed to a different home computer. The hacker is able to do this quick switching because he has installed DNS name servers for his domains on other home computers under his control. The DNS name servers specify that a hostname-to-IP-address mapping should only live for 10 minutes. Over the July 4th long weekend, some of these same web servers were used in an apparent phishing scam to collect stolen PayPal passwords and credit card numbers. Silicon.com has an article about this scam.

Joe Stewart of LURHQ has obtained a copy of the Trojan, which he has named Migmaf. His analysis of the Trojan was just released on LURHQ website.

The initial theory was that the Trojan was installing a mini-web server on hacked computer to host the porn websites. However, Joe's analysis shows that the Trojan is actually a reverse HTTP proxy that makes a home computer act as a front for a home base Web server.

Some of the domain names used by the websites of the Trojan are:

- onlycoredomains.com
- pizdatohosting.com
- bigvolumesites.com
- wolrdofpisem.com
- arizonasiteslist.com
- nomorebullshitsite.com
- linkxxxsites.com

I've been monitoring these domains since July 5th and found over 2,000 unique IP address used by hosts in these domains. Almost all of these IP addresses are for commercial ISPs used by home computer users. AOL.com was the most used ISP.

One interesting feature of the Trojan is that it times the connection speed of a home computer that it is running on and reports the connection speed back to home base. The home base computer seems to only select a computer to run a reverse proxy server or the DNS name server if the computer has a high-speed cable or DSL Internet connection!

It is not known at the present time how the Trojan gets installed on people's computers. My theory is that the Sobig.e virus might be involved, but the evidence is not strong at the moment. 

By Richard M. Smith, Computer & Internet Security Expert

Related topics: Cybersecurity, DNS, Domain Names, Email, IP Addressing, Spam

 
   

Don't miss a thing – get the Weekly Wrap delivered to your inbox.

Comments

Re: Moving Target: Spammer Using Over 1000 Home Computers as DNS fnord  –  Jul 18, 2003 1:55 PM PDT

This is but one of many examples of why using the DNS to fight spam as suggested in this: http://www.circleid.com/article/151_0_1_0_C/ CircleID article is doomed to failure. -g

To post comments, please login or create an account.

Related Blogs

Related News

Explore Topics

Dig Deeper

Cybersecurity

Sponsored by Verisign

Mobile Internet

Sponsored by Afilias Mobile & Web Services

DNS Security

Sponsored by Afilias

IP Addressing

Sponsored by Avenue4 LLC

Promoted Posts

Buying or Selling IPv4 Addresses?

Watch this video to discover how ACCELR/8, a transformative trading platform developed by industry veterans Marc Lindsey and Janine Goodman, enables organizations to buy or sell IPv4 blocks as small as /20s. more»

Industry Updates – Sponsored Posts

Radix's .TECH, .STORE, .ONLINE and .FUN Get Approval from the Chinese Government

Join Neustar's Town Hall Meeting and Help Shape the Future Of .US

Domain Registrations Reach 331.9 Million, 6.7 Million Growth Year over Year

Avenue4 Helps IPv4 Sellers and Buyers Gain Market Access, Overcome Complexities

Introduction to ACCELR/8 - Fast Lane to the IPv4 Market

Avenue4 Launches ACCELR/8, Transforming the IPv4 Market with Automated Order-Driven Trading

.brands Spotlight: Banking and Finance Industries

Google Buys Business.Site Domain for 'Google My Business'

Radix Announces Global Web Design Contest, F3.space

Global Domain Name Registrations Reach 330.6 Million, 1.3 Million Growth in First Quarter of 2017

.TECH Gets Its Big Hollywood Break

Verisign Named to the Online Trust Alliance's 2017 Audit and Honor Roll

Why the Record Number of Reverse Domain Name Hijacking UDRP Filings in 2016?

Attacks Decrease by 23 Precent in 1st Quarter While Peak Attack Sizes Increase: DDoS Trends Report

UDRP: Better Late than Never - ICA Applauds WIPO for Removing Misguided 'Retroactive Bad Faith'

The Rise and Fall of the UDRP Theory of 'Retroactive Bad Faith'

.PRESS Supports Press Freedom Day for 3rd Consecutive Year

Leading Internet Associations Strengthen Cooperation

5 Afilias Top Level Domains Now Licensed for Sale in China

Radix Announces Largest New gTLD Sale with Casino.Online