|
|
Last week, I read some interesting news on an Australian website The Age. A journalist explained that a Russian malware distribution site offered a haul of 1000 spyware-infected Australian machines for 100USD, double the price offered for US machines and 30 times more than those from Asia.
Searching this site, I discovered the InstallsCash partnership program:

It was a well known dishonest offer: after registration, the affiliate had to put a short one line iframe code on his website pages. Next, and as explained in the FAQ, this hidden iframe would be used to silently redirect any visitor to another website to install (via an MPack like process) the affiliation program. Each successful installation made from the affiliate site would involve a payment.
To cover the tracks, the InstallsCash registrar is from China (bizcn.com). The fake registrant address is in the US (Iowa City) and the e-mail contact in Russia (ydwrtyxamz_at_mail.ru). It is easy to understand that this last name was randomly chosen. We will surely encounter some others in our investigations!
Being curious and to clearly demonstrate the dishonesty of the offer, I decided to subscribe myself by using some fake data to fill in the proposed form:

This screenshot is interesting; it lists the allowed system of payments. Here we recognize all the regular ones the cybercriminals are using. Having done that, I had to wait for 24 hours:

This Saturday at wake up, I tried my luck and attempted a connection. They activated my registration and my personal iframe code waited for me:

As I discussed first, the iframe I had to hide on my website pointed at another website using a strange name randomly chosen and created using a more or less automated method I discussed in a previous blog entry. It seems the affiliator creates or uses a different one for each affiliate. Thanks to these unique names, the software recognizes each of them. Data can be feed into their stats page and then they can calculate the payments.
On my personal page, the top white window contained my iframe. In the middle the affiliator gave me the same one, but in an encrypted form. It was not explained but it was clear I had to use this one on my pages to mislead or avoid some security technologies. The distributer goes so far as to say, and I quote, “they will be updating every 3 days and they will be invisible for every antivirus!”
The whois gave me the result I expected, which was something similar to InstallsCash.com:
Registrar was bizcn.com and registrant contact came with another improbable e-mail address:
Jan Dendinger ycsmmiqtyo_at_mail.ru
Phone +1 3196433xxx Fax: +13.196433xxx
309 East Main Street
West Branch IA 523581
us
Some quick searches with Google allowed me to find many other similar sites.
I looked at my stats page. Of course it was blank:

When the Age announced 100$ per 1000 unique loads, my rate table quoted the half and only 3$ for Asia:

But the journalist was right, in my private windows message as well as on the main page I could read InstallsCash made some special offer since February 16th: they increased their rates “for USA by 2 and any mix of country was about 30$”:

However, I note the price is still low compared with the payments these guys proposed in September 2006. But at that time, Australia and UK PC were the most wanted:

Yes, it seems that behind InstallCash, IframeCash (September 2006) and IframeDollars (November 2007) are hidden the same people. To understand this you can, for example compare the FAQs:

In November 2007, the RBNExploit blog discussed then that iFrameCash and iFrameDollars were possibly linked to the Russian Business Network. This confirms that RBN trading partners are still in business. And if they propose, since thay have been doing it for several years, commissions for deliberately planting malicious iframes, believe me, it is because it is a lucrative business.
Finally please note that via its ScriptScan module, McAfee VirusScan blocks and detects the PHP script as JS/Exploit-BO.gen. Moreover, the invisible files
are detected as Downloader-BDH.
|
|
Submit your own comments / message for this post