CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Current scam directory?

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Robin

Site Admin
Phishing Squad Team Lead

Joined: Oct 15, 2003
Posts: 8946

1st Responder Mentors a-squared Anti-Malware Administrators Forums Admin MIRT Moderators MVP Phishing Squad Security Experts Team CC Committee Team F@H

PostPosted: Wed Jan 19, 2005 2:55 pm    Post subject: Current scam directory?
Reply with quote

Hi everyone,

I was thinking about this over the last few days. The more I think about it the more I think it might be a beneficial thing. I'm posting in here to get some feedback from the masses so to speak.

What if we create a database of sorts here on CastleCops with known phishing scams? It would work like an encyclopedia, so items would be listed alphabetically, and in some cases would include actual examples of the emails being sent out to folks.

Does anyone have any thoughts on the idea?

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Wed Jan 19, 2005 4:02 pm    Post subject:
Reply with quote

It is a good idea, Robin, especially if the database is searchable rather than simply retrievable.

I have documented a few in the past and have a backlog of others waiting to be added. The problems that I have encountered so far are trying to establish criteria for what constitutes a unique threat as opposed to a variation of an existing threat and what data to collect and publish for each threat.

I have done this in a forum/topic format and I am continually amazed at the referrals that I draw from Google. Some of the search strings are very surprising.

Anyway, I'll be happy to contribute in any way possible.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
Robin

Site Admin
Phishing Squad Team Lead

Joined: Oct 15, 2003
Posts: 8946

1st Responder Mentors a-squared Anti-Malware Administrators Forums Admin MIRT Moderators MVP Phishing Squad Security Experts Team CC Committee Team F@H

PostPosted: Wed Jan 19, 2005 4:09 pm    Post subject:
Reply with quote

It occured to me because we got a feedback recently about someone getting nailed by a scam, I'd done an article on previously. I thought maybe if the database was there and searchable like you suggest it would help people, because they can google just the names or associated companies and get results back for it.

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Wed Jan 19, 2005 4:48 pm    Post subject:
Reply with quote

People are definitely out there searching for the info. Given CC's already respectable search engine ranking this would be a great place for it.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
stan_qaz

Premium Member


Joined: Mar 31, 2003
Posts: 10635

Premium

PostPosted: Wed Jan 19, 2005 4:56 pm    Post subject:
Reply with quote

Search by subject or search by first 10 words would make it easy to match your spam to the database.


_________________
Questions? Try the wiki
http://wiki.castlecops.com/MailWasher_Pro
Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Wed Jan 19, 2005 5:10 pm    Post subject:
Reply with quote

After muddling about with several ideas, formats, and approaches I am considering settling on one that includes the following:

1) Screenshot of e-mail unless sent as plain text
2) Complete source of email including headers
3) Whois information on the originating IP
4) Whois on the target URL (and reverse DNS, if appropriate)
5) Comments as appropriate.

After receiving multiple different attempts from the same originating IP I have thought about adding entries for these cross referenced to the corresponding emails.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
stan_qaz

Premium Member


Joined: Mar 31, 2003
Posts: 10635

Premium

PostPosted: Wed Jan 19, 2005 7:12 pm    Post subject:
Reply with quote

As long as none of the links in the mail are live and addreses are munged to protect the innocent that would be good.


_________________
Questions? Try the wiki
http://wiki.castlecops.com/MailWasher_Pro
Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Wed Jan 19, 2005 7:31 pm    Post subject:
Reply with quote

Yeah, I always delete the actual recipient's address. The message source goes into quotes so the links aren't live.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
stan_qaz

Premium Member


Joined: Mar 31, 2003
Posts: 10635

Premium

PostPosted: Wed Jan 19, 2005 10:31 pm    Post subject:
Reply with quote

I was also concerned about forged senders but you seem to have the plan well together.


_________________
Questions? Try the wiki
http://wiki.castlecops.com/MailWasher_Pro
Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Wed Jan 19, 2005 10:38 pm    Post subject:
Reply with quote

I hadn't actually thought about the forged senders aspect. Thanks for pointing that out. Most of the ones that I have dealt with have been fake institutional emails so no individual privacy issues were involved.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16536

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Thu Jan 20, 2005 3:28 am    Post subject:
Reply with quote

Oldfrog wrote:
After receiving multiple different attempts from the same originating IP I have thought about adding entries for these cross referenced to the corresponding emails.

An interesting discussion. This last point is particularly intriguing. This might offer the opportunity to look for links to known SPAM sources -- i.e. is this stuff spawned by the same individuals or do they operate in different circles. Of course all of this is complicated by the use of hijacked PCs.

Back to top
View users profile Send private message
stan_qaz

Premium Member


Joined: Mar 31, 2003
Posts: 10635

Premium

PostPosted: Thu Jan 20, 2005 3:38 am    Post subject:
Reply with quote

Oldfrog, If you haven't used spamcop.net recently they have added a pretty good forgery detection tool to the submission process, called mailhosts there, that you could use to track your personal message headers for forgeries but its not much good for stuff forwarded to you even with full headers.

Most of what I get seems to be forged anymore with only the links inside going anywhere. I'll look at a few of the scammy messages and see if I can see anything. With MailWasher running well now I usually only look at about 1% of my incoming spam and delete the rest of it without looking.


_________________
Questions? Try the wiki
http://wiki.castlecops.com/MailWasher_Pro
Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Thu Jan 20, 2005 4:01 am    Post subject:
Reply with quote

I will check out the spamcop tool and see how it works. SamSpade also has a built in email header parsing tool that is fairly decent. I normally follow the from/to chains until I find a break either by address inconsistency or reverse DNS failure.

Here is a sample of the format that I am using at the moment.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer