Technologies that
Bring Peace of Mind
Online
technical Help
and Support
Status live support chat
Live support
Have a question?
Call us Toll-Free at:
1-877-ANTISPY
1-877-2684779
+44-207-099-2078
More contacts


Subscribe to our
RSS feed
Subscribe to our RSS feed
In focus
Money Mule Recruiters use ASProx's Fast Fluxing Services
July 18, 2008 11:23

    Just consider this scheme for a second. A well known money mule recruitment site Cash Transfers is maintaining a fast-flux infrastructure on behalf of the Asprox botnet, that is also providing hosting services for several hundred domains used on the last wave of SQL injection attacks. Ironically, the money mule recruitment site is sharing IPs with many of them. Who are these money launderers (cashtransfers.tk; cashtransfers.eu; type53.eu; sid57.tk; catdbw.mobi; cdrpoex.com etc.  ) anyway?

"Cash-Transfers Inc. is an online-to-offline international money transfer service. We offer a secure, fast, and inexpensive means of sending money from the UK to offline recipients worldwide. Recipients do not require a bank account or Internet connection to receive funds. We have teamed with select local disbursement partners to provide a convenient, secure, and cost-effective means of sending money to family, friends and business partners abroad. The basic requirements to send money/transfer money are:

1) Senders must have Internet access and a bank account or credit/debit card to transfer money. However, recipients do not require either a bank account or Internet connection.

2) Money sent through Cash-Transfers Inc. is available for pick up at the distribution partner instantly, or, in most countries, money can be delivered to the recipient in a matter of hours.

3) Our local agents will call your recipient (during local business hours) to provide additional details, including: forms of identification required, hours of operation, and other locations. The sender will also receive an email confirmation with transaction details and tracking information."

The fast-flux infrastructure they're currently using is also providing services to domains that are currently used, or have been used in previous SQL injection attacks. Some info on the current DNS servers used in the fast-flux :

ns10.cashtransfers.tk
ns11.cashtransfers.tk
ns1.cashtransfers.tk
ns12.cashtransfers.tk
ns2.cashtransfers.tk
ns13.cashtransfers.tk
ns3.cashtransfers.tk
ns14.cashtransfers.tk
ns4.cashtransfers.tk
ns15.cashtransfers.tk
ns5.cashtransfers.tk
ns16.cashtransfers.tk
ns6.cashtransfers.tk
ns17.cashtransfers.tk
ns7.cashtransfers.tk
ns8.cashtransfers.tk

With the distributed and dynamic hosting infrastructure courtesy of the malware infected user, scammers, spammers, phishers and malware authors are only starting to experiment with the potential abuses of such an underground ecosystem build on the foundations of compromises hosts.

Related posts:
Storm Worm's Fast Flux Networks
Managed Fast Flux Provider
Fast Flux Spam and Scams Increasing
Fast Fluxing Yet Another Pharmacy Spam
Obfuscating Fast Fluxed SQL Injected Domains
Storm Worm Hosting Pharmaceutical Scams
Fast-Fluxing SQL injection attacks executed from the Asprox botnet

All news for October 10, 2008
  22:58  Schneier on Security: Friday Squid Blogging: Natural Squid Steganography
  22:45  Martin McKeay: Recording Notice: Security Roundtable - Blogger Ethics
  18:30  Schneier on Security: The More Things Change, the More They Stay the Same
  14:39  Martin McKeay: Brute force attacks against WPA/WPA2 using Nvidia cards
  12:35  Schneier on Security: Data Mining for Terrorists Doesn't Work
  00:02  Martin McKeay: Sequoia´s helping decide the election? God help us!

All news for October 9, 2008
  23:00  MSRC: Update 1: Microsoft Security Advisory 951306
  19:07  Schneier on Security: Nonviolent Activists Are Now Terrorists
  17:51  Martin McKeay: Cisco Ooops: drug runner music on VPN CD
  16:40  MSRC: October 2008 Advanced Notification
  12:44  Schneier on Security: "New Attack" Against Encrypted Images
  12:22  Martin McKeay: Step by step guide to the DNS vulnerability
  09:28  Dancho Danchev: Cybercriminals Abusing Lycos Spain To Serve Malware
  09:00  Dancho Danchev: Commoditization of Anti Debugging Features in RATs - Part Two

All news for October 8, 2008
  14:46  Martin McKeay: NoScript protects from ClickJacking
  14:14  Martin McKeay: Big Surprise: Data mining doesn´t catch terrorists
  12:55  Schneier on Security: Chinese Monitoring Skype Messages
  02:23  Martin McKeay: Network Security Podcast, Episode 123

All news for October 7, 2008
  21:51  Schneier on Security: Do-Not-Call Lists
  18:27  Martin McKeay: Recording notice: NSP 123
  15:54  Dancho Danchev: Summarizing Zero Day's Posts for September
  14:49  Martin McKeay: Now he´s done it! Security Mike sells out
  12:21  Dancho Danchev: A Diverse Portfolio of Fake Security Software - Part Eight
  11:48  Schneier on Security: The Seven Habits of Highly Ineffective Terrorists
  07:42  Dancho Danchev: Web Based Malware Emphasizes on Anti-Debugging Features
  00:01  Dancho Danchev: Fake Windows XP Activation Trojan Wants Your CVV2 Code
Keywords: money, mule, recruiters, use, asproxs, fast, fluxing, services

All news for October, 2008


All news for 2008