Last visit was: Sat Jul 05, 2014 7:17 am
It is currently Sat Jul 05, 2014 7:17 am

Krebs On Security: Pharma Wars


All times are UTC - 5 hours [ DST ]


 [ 20 posts ]  Go to page 1, 2  Next
Author Message
 PostPosted: Tue Aug 30, 2011 9:18 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
This story is the gift that keeps on giving:

http://krebsonsecurity.com/2011/08/phar ... rotection/

I won't quote a piece because the entire report is worth reading. He appears to be meticulously going through the entire cache of chat logs involving Gusev, Dmitry Stupin and our old pal Andrey Smirnov.

Fantastic. I'm glad that Gusev, Stupin and Pavel V. are all in jail (still.)

SiL


Top
 Profile  
 PostPosted: Tue Aug 30, 2011 10:39 pm   
Spammer Exterminator
User avatar

Joined: Mon Feb 26, 2007 11:13 pm
Posts: 1132
Maybe related? I received a few notices today of honeypot/spamtrapped delivery-attempts of pharma spam with unassigned .ru domains. There's nothing to spam, and yet there is spam, via rustock I believe, but definitely a botnet. Maybe that's unclear. There are links, with paths including the word /test/ but the hosts do not resolve.

I'm thinking that these are attempts at chest-beating from a major affiliate - who perhaps has read the Krebs post - and who has nothing better to do than prove that he's still around.

_________________
Only on our site you will find a SPICE under the comprehensible prices!


Top
 Profile  
 PostPosted: Thu Nov 17, 2011 1:45 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
Another entry in the Pharma Wars series from Krebs:

http://krebsonsecurity.com/2011/11/phar ... injustice/

Just excellent again.

SiL


Top
 Profile  
 PostPosted: Thu Nov 17, 2011 4:42 pm   
Spammers' Nightmare
User avatar

Joined: Thu Apr 12, 2007 6:55 pm
Posts: 2549
http://krebsonsecurity.com appears to be down at the moment.
Checked with http://www.downforeveryoneorjustme.com/ ... curity.com and
they report it down for everyone.


Top
 Profile  
 PostPosted: Thu Nov 17, 2011 8:26 pm   
You are kiillllling-a my bizinisss!
User avatar

Joined: Tue Jun 27, 2006 2:01 am
Posts: 9227
It is still having problems. Sometimes it loads for me.

nginx is giving a 502 gateway error, and there are other errors depending on when you try.

This is convenient for Igor, Dmitry and Pavel


Top
 Profile WWW  
 PostPosted: Thu Nov 17, 2011 10:09 pm   
Spammer Killing Machine
User avatar

Joined: Sun Jun 13, 2010 5:22 pm
Posts: 528
Red Dwarf wrote:
It is still having problems. Sometimes it loads for me.

ditto
I can get to the actual site from the Google cache of its webpages.


Top
 Profile  
 PostPosted: Thu Nov 17, 2011 10:24 pm   
You are kiillllling-a my bizinisss!
User avatar

Joined: Tue Jun 27, 2006 2:01 am
Posts: 9227
The site is serving only 10% of global access requests and the rest of the time is suffering time-outs.

This is similar to a what you would see in a KrebsOnSecurity DDOS attack, but could be a localized congestion problem.

Time will tell. It would not be surprising. This is an earlier article, which highlights how these people are prepared to use DDOS to their advantage
Brian Krebs wrote:
Financial Mogul Linked to DDoS Attacks — Krebs on Security
http://krebsonsecurity.com/2011/06/financial-mogul-linked-to-ddos-attacks/

Pavel Vrublevsky, the embattled co-founder of ChronoPay — Russia’s largest online payments processor — has reportedly fled the country after the arrest of a suspect who confessed that he was hired ..


Here is a message from Brian today
Brian Krebs wrote:
yeah, stupid bots are loving my site today. krebsonsecurity.com is intermittently available
Site has been under 1 gigabit ddos for much of the day. Still ongoing

As an interim measure, for those unable to read it, here is a capture of Brian's latest article, referenced at the start of this thread.
I will remove it when access to his web site is stabilized. Republished with permission.


Top
 Profile WWW  
 PostPosted: Thu Nov 17, 2011 11:30 pm   
You are kiillllling-a my bizinisss!
User avatar

Joined: Tue Jun 27, 2006 2:01 am
Posts: 9227
This post was syndicated from: Krebs on Security and was written by: Brian Krebs. Original post: at Krebs on Security

    Pharma Wars - The Price of (in)Justice

Quote:
I spoke this week at Govcert 2011, a security conference in Rotterdam. The talk drew heavily on material from my Pharma Wars series, about the alleged proprietors of two competing rogue Internet pharmacies who sought to destroy the others’ reputation and business and ended up succeeding on both counts. Here is the latest installment.

For those who haven’t been following along, I’ve put together a cheat sheet on the main players, the back story and the conflict. Scroll down to skip this section.

Actors

Pavel Vrublevsky: Co-founder and Former chief executive officer of ChronoPay, until recently a major processor of electronic payments in Russia. Vrublevsky has been accused of running an illegal business, a rogue Internet pharmacy affiliate program called Rx-Promotion, and is currently in prison awaiting trial on unrelated cybercrime charges. Known to business partners as “Red” or “RedEye.”

Igor Gusev: Co-founded ChronoPay with Vrublevsky in 2003. Had a falling out with Vrublevsky in 2005, left ChronoPay and started the Internet pharmacy affiliate programs GlavMed and SpamIt. The latter was closed in Sept. 2010, and Gusev has been charged with running an illegal business. He is still at large.

Dmitry Stupin: Gusev’s right-hand man. Helped to build SpamIt and GlavMed. The logs below are from a set of logs leaked to several download sites that contain thousands of conversations between Stupin and Gusev. The logs were obtained shortly after the police detained Stupin as part of the criminal investigation into Gusev.

Conflict: Two former business partners-turned-competitors try to sabotage each others’ business and to get the other arrested.

The Conversation

The conversation below takes place between Feb. 21 and 23, 2010, and is a chat log between Gusev and Stupin. Gusev already knows there are plans to file criminal charges against him, which indeed come just seven months after this conversation was recorded. The two are discussing plans to pay more than $1.5 million to politicians and law enforcement to obtain a criminal prosecution of Vrublevsky.

Several attendees at Govcert 2011 asked about the likelihood of Vrublevsky serving time, if convicted. This chat may provide a clue. In the middle of the following conversation, Gusev says he has secured promises that if arrested, Vrublevsky “would remain in prison and would not be able to pay his way out,” Gusev wrote. “He is going to lose a large portion of his business and will be left with no money to fight the war.”

Gusev: Latest news – all the materials to start a criminal case were given to prosecutors on Friday. After holidays I am going to get some information regarding “what” and “who”. Are we meeting on 24th?

Stupin: Yes we are meeting on 24th.

Stupin: Shaman’s stuff got broken, everything is declined. I cannot come to Moscow, as usual. I broke my leg in Turkey.

Gusev: Really??? Is it really broken?

Stupin: Yes.

Stupin: Here. hip-notics.com. I was learning how to do somersault doing Aerial skiing (freestyle).

Gusev: In reality, I think it’s for the better. There is no need for you to go to Moscow. After the holidays I am going to get the information which was received by the prosecutors’ office, however I am planning to leave from here for a couple of months. This is extremely serious, this is not just articles in newspapers.

Gusev: Write down my new number. It used to be 325667.9. 20к (5k are going to the middleman and 15k are going to a person from prosecutors’ office). 5к (for the search of materials regarding Pasha’s case); $2к (to lawyer for compromising materials and Newsweek); summed up to: 298667.9

Stupin: Okay.

    TWO DAYS LATER:
Gusev: I need a piece of advice: I found a person who is willing to help me in situation with Red. He has a proven scheme, because he is a very strong lawyer. A real fixer-upper. For his service, along with very large sum of money, he is asking for something in return — he is asking to help his friend – a very famous webmaster, who faced similar problem as the one we are facing, and who was saved by that person. This “friend” is not doing anything right now. This lawyer is asking us to help him with establishing on-line pharmacy affiliation (partnerka). I am not glad with this proposition to create our own competition, however, out of all people I talked to, only this person offered a structured solution to the problem, giving us hopes. People from Volleyball Association can and will cover us, using their FSB connections, but they can do very little with Prosecutors’ Office, they can only prolong the legal proceedings. They will also not be able to prosecute Red. The person who we are asked to help is my old acquaintance – Pet – the owner of лолного – billing of billcards (sunbill). [For more information on the role of the Russian Volleyball association in this story, see Pharma Wars: Purchasing Protection].

Stupin: Let’s offer him to create “us” under his own brand.

Gusev: We have already tried doing this. He is going to leave on his own. IMHO the ideal way is to offer him our clone as 50-50 partnership. I have not offered anything to anyone yet before knowing your opinion. I cannot say no, otherwise, the “fixer-upper” is not going to take our case (even if we give him as much money as he asks for) :( In that case I will have to do everything by myself (I know how to do it and even have several people, who can split the whole scheme step by step and execute them). However, this way, there is very high chance that they will take the money, but will do nothing. Or will milk me and Red at the same time, making double the money, and, again, do nothing.

Stupin: It’s not a problem at all, they have tried so many times to do something with us – and have not followed through on their own. Our sites are publicly available, there is no risk to process orders from trusted sites.

Gusev: Hosting is ours, tech support is only ours. We will not give the software. Maintenance is also ours.

Stupin; Yes, we are giving them the sites, they will redo them, giving them API for the affiliation (partnerka).

Gusev: ок, I will try to bound them by these conditions. Do you want to know how much the service regarding Red cost?

Stupin: Sure. I have just arrived, with my leg, I can’t really think straight.

Gusev: 1.5 million.

Stupin: Oh, God!!! What does he promise for that?

Gusev: He promises that Red would remain in prison and would not be able to pay for his way out + he is going to lose a large portion of his business and will be left with no money to fight the war.

Gusev: I do not want to write all the details here on Jabber, that is why I wanted to meet. I am gathering the money for him, and for your for the office, and I am leaving for 2-3 months.

Stupin: ok, are you going to bring money for the office? Let’s meet at that time? Because I am going to get stuck for approximately a month with my leg.

Gusev: Yes, I am trying to gather enough money. Pasha is helping me, but with very small sums and when he has available money, not when I need it.

Gusev: Can we borrow from your brother? At most 150-200к?

Stupin: Yes, I will do it. Some time ago I rented a house in Moscow suburbs, and the owner offered to rent with his help, I have his e-mail and the phone number, he is mature, calm, we can try.

Gusev: Could you find out his requirements?

Stupin: Okay, I will call.


"Pet" referenced above is the Belarusian child porn purveyor Yevgeny Petrovsky whose history is listed in this article

лолного means "Lolitas" which is a reference to child pornography, where Petrovsky made his money


Top
 Profile WWW  
 PostPosted: Fri Nov 18, 2011 12:47 am   
You are kiillllling-a my bizinisss!
User avatar

Joined: Thu Mar 01, 2007 3:01 am
Posts: 5915
This can't look too good for the Russian law enforcement authorities, either -- not with the US government raising a new fuss to mark the second anniversary of Sergei Magnitsky's death:
http://www.bbc.co.uk/news/world-europe-14323398


Top
 Profile  
 PostPosted: Fri Nov 18, 2011 12:33 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
Krebsonsecurity was indeed under a sustained DDOS attack.

He logged the ip's. Is there anyone here who could assist in identifying the botnet based on a set of IP addresses?

Either post back here or PM me.

Thanks

SiL


Top
 Profile  
 PostPosted: Fri Nov 18, 2011 1:58 pm   
You are kiillllling-a my bizinisss!
User avatar

Joined: Tue Jun 27, 2006 2:01 am
Posts: 9227
Shadowserver


Top
 Profile WWW  
 PostPosted: Sat Nov 19, 2011 8:09 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
Good call, Red. I'll also recommend FireEye. (Never know.)

Thanks.

SiL


Top
 Profile  
 PostPosted: Sun Jan 01, 2012 3:14 am   
You are kiillllling-a my bizinisss!
User avatar

Joined: Thu Mar 01, 2007 3:01 am
Posts: 5915
There's a new installment today with an elegant triangulation implicating a couple Russian programmers as botmasters:
http://krebsonsecurity.com/2012/01/phar ... botmaster/


Top
 Profile  
 PostPosted: Sun Jan 01, 2012 12:35 pm   
Spammer Killing Machine
User avatar

Joined: Sun Jun 13, 2010 5:22 pm
Posts: 528
Krebs On Security: "Pharma Wars: ‘Google,’ the Cutwail Botmaster" states
Quote:
Russian software firm Digital Infinity Developers Group (the search engine Google currently flags diginfo.ru as malicious)

Please excuse my ineptness, but Google SafeBrowsing reports that diginfo.ru is clean and it states
Quote:
Google has not visited this site within the past 90 days.

How can I reconcile the difference?


Top
 Profile  
 PostPosted: Sun Jan 01, 2012 2:56 pm   
You are kiillllling-a my bizinisss!
User avatar

Joined: Thu Mar 01, 2007 3:01 am
Posts: 5915
Contact form for Brian is here:
http://krebsonsecurity.com/about/

He does respond quickly.


Top
 Profile  
 [ 20 posts ]  Go to page 1, 2  Next

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Ahrefs, Google [Bot], Wayback machine and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  


Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
Style originally created by Volize © 2003 • Redesigned SkyLine by MartectX © 2008