Translate

Posts mit dem Label Virginia werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Virginia werden angezeigt. Alle Posts anzeigen

5/08/2014

U.S. NAVY MILITARY HACK 2012:

Nicholas Paul Knight & Daniel Trenton Krueger

charged with Hacking US Navy Computer Systems & Sites


Daniel Trenton Krueger, 20, of Salem, Illinois and Nicholas Paul Knight, 27, of Chantilly, Virginia, were accused of conspiring "to hack computers and computer systems as part of a plan to steal identities, obstruct justice, and damage a protected computer" from April 2012 to June 2013, court documents and prosecutors said.

USS Harry S. Truman

Knight, a former systems administrator in the nuclear reactor department of the USS Harry S. Truman, was the self-proclaimed leader and publicist of "Team Digi7al," prosecutors said. He used the names Inertia, Iner7ia, Logic and Solo and has been a hacker since the age of 16, charging documents say. He was discharged from the Navy after he was caught trying to hack a Navy database while at sea.

In an interview with a reporter for the website Softpedia, parts of which are quoted in charging documents, "Iner7ia" said that he was originally a White hat hacker, who found and reported security vulnerabilities. But he became bored and said "the people I did work for were ungrateful and sometimes they wouldn't take me seriously."

He admitted being a member of the United States Navy, and said that he worked for the people of the U.S. hacking primarily government sites, not the government. "I believe that if we can't protect ourselves against a cyber attack, then how can we trust the government to protect against anything else?"


He said that he uses a separate computer to avoid being caught, and at one point said, "I just hope that I can retire knowing I was never caught and arrested. Haha"

Krueger, who was studying network administration at an undisclosed college, did the hacking "out of boredom," prosecutors said. He went by the names Thor, Orunu, Gambit and Chronus.

Charging documents say that in June of 2012, the Naval Criminal Investigative Service (NCIS) detected a breach of a Naval database located in Oklahoma that contains the Social Security numbers, names, and birth dates of roughly approximately 220.000 members of the military.


"The Navy quickly identified the breach and tracked down the alleged culprits through their online activity, revealing an extensive computer hacking scheme committed across the country and even abroad," said U.S. Attorney Danny C. Williams of the Northern District of Oklahoma.

U.S. Attorney Danny C. Williams
The NCIS and Defense Criminal Investigative Service identified Knight and Krueger as the hackers of the Navy database as well as systems belonging to the U.S. National Geospatial-Intelligence Agency, the Department of Homeland Security, AT&T U-verse, Universities, Police Departments in Toronto and Alabama and the entire email account of the Peruvian ambassador to Bolivia.

They posted links to the data via Team Digi7al's Twitter account, and one co-conspirator said they released the data because they were "somewhat politically inclined to" but also because it was "fun, and we can," prosecutors said.

The U-verse hack compromised the personal information of 3.500 customers. The June 2012 Navy hack left 700 overseas military members unable to access the system and get "logistical support" for their transfers for more than 10 weeks and cost the Navy more than 500.000 US-Dollars documents say.

The U.S. National Geospatial-Intelligence Agency

After the NCIS searched Knight's Virginia home in February of 2013, he admitted "many" of his Team Digi7al activities and agreed to cooperate, but told a juvenile co-conspirator to delete data, documents say.

That juvenile and two others who hacked for Team Digi7al were not charged.

4/10/2014

Potentially MALICIOUS ADs:
bellroy.com (IP: 54.236.92.225)
risking with
HIDDEN Iframes (W32.HfsIframe)
and Microsoft Internet Explorer remote code execution via option element


FOR WEBMASTERS & BLOGGERS
If you own a Website or a Blog and are affiliated with Google AdSense, in order to your own Reputation, should block the Domain bellroy.com in your AdSense Dashboard. See the following Report why:


MALICIOUS ADVERTISER: 
HIDDEN IFRAME(s) & 
Microsoft Internet Explorer remote code execution via option element

DOMAIN:
http://bellroy.com/
  • https://www.virustotal.com/de/url/c98b0274361f078ffe11c672882a44deea265179edb5c6fa0602d63080855968/analysis/
W32.HfsIframe
  • https://www.virustotal.com/de/file/67b5a8555f0660f5cea968abbbe32c48a92b6c0cb1782c682a0bb7d35f2439cd/analysis/1397146549/
<--- iframe src="//www.googletagmanager.com/ns.html?id=GTM-MF9C"height="0" width="0" style="display:none;visibility:hidden" --->

AD-LINK:
http://www.googleadservices.com/pagead/aclk?sa=L&ai=CGfswyL9GU6j-NIuoiga4sYDQCouup8sGi_S0sYgBo5WpvzgQASCOwJQjUJeJzE5guwOgAd3f68sDyAECqQI_TRhS36CvPqgDAcgDwQSqBIsBT9BrjS7o2Hx01Y0JFiIuwvJ1xe9IjZ3AaQviQnug8Np1m1Lub00UCac2hzu_KqEdA3aCF6v0DESTEaRR-1SjYlNxE2mKIljXjfcmAgj4IJnE_mEbmdov7A_Top1ov2PE0Cm3JltzAOkli0GYOFPDLlmdDDZfXT2fFSIbEi-AgySr64NOLCIbYqODF4gGAaAGAoAHi6CUNA&num=1&cid=5GjrqWA5Hr9KASVQwZCWupTr&sig=AOD64_1_pgpU0nS6Jm4kbl0tCan3rcz2HA&client=ca-pub-5585202032329389&adurl=http://bellroy.com/wallets/note-sleeve-wallet&nm=2&mb=2&bg=!A0RJckn2eYHUnAIAAABGUgAAACcqAPHBZ1R_GZZ-qskVhAC1RCaSH8E7P1WWZC0O5x_RfOeSlUkxeJvIMszsmy3sXPqRsDlNy8wF68FONASqnu6VRxJ-s-NpHWsQ1GS7blV93HhI3unMwwLWf3jO_ggQ1uDpL5_XK5lofwEA5P2icYwOYX-diVH7uhcjdcVDH0WnnUDwsfalxoHuio6rkHLlVZEw0K_n8FBECRILAC_D7YNm3YixQnPoAup1vg7QEcYLoGraugw_6A2qJro2Z8bmpX0mbatP_HXSBMdhAiO9S4pffic21NrkmjGVx-d_c9TBhi1Tj4BMHIOEuAFJr7PX2F7yuuWu
  • https://www.virustotal.com/de/url/95f54e683c7aa90bcff2516c4203b1eab34ab0773398e57f1df39494d6bfa9da/analysis/1397146003/
W32.HfsIframe
  • https://www.virustotal.com/de/file/5a84faf5f6aca07d4390a9b5cfccc29512b29edb295113d7a6f81dd8c85e0028/analysis/1397146289/
<--- iframe src="//www.googletagmanager.com/ns.html?id=GTM-MF9C"height="0" width="0" style="display:none;visibility:hidden" --->
Microsoft Internet Explorer remote code execution via option element
  • https://urlquery.net/report.php?id=1397146071040
  • https://urlquery.net/report.php?id=1397146084651
--->
http://bellroy.com/wallets/note-sleeve-wallet?gclid=CJGghbqm1r0CFbFFMgodI1QA3w
  • https://www.virustotal.com/de/url/415b1b40a688e6db53001d576b04991a469967e8b17f5327f591942b0ec5b423/analysis/
W32.HfsIframe
  • https://www.virustotal.com/de/file/fbf1f3b0f36895ff64f2ed8270a6058d912395b6fe94a596b7f0e04381422a90/analysis/1397147003/
<--- iframe src="//www.googletagmanager.com/ns.html?id=GTM-MF9C"height="0" width="0" style="display:none;visibility:hidden" --->
Microsoft Internet Explorer remote code execution via option element
  • https://urlquery.net/report.php?id=1397146245634
  • https://urlquery.net/report.php?id=1397146261020
  • https://urlquery.net/report.php?id=1397146282006

IP:
http://54.236.92.225/
  • https://www.virustotal.com/de/url/17c875d298cbb4a685465b5dfbd5f3ae5097b78a8fa58184f224a872eec7d4f3/analysis/1397147591/
  • https://www.virustotal.com/de/ip-address/54.236.92.225/information/

HIDDEN LINK TO:
http://carryology.com/
  • https://www.virustotal.com/de/url/85e70248597bc714f3eac0644ff669c2680af8b6a50b23d34420e54e0f9bd902/analysis/1397147301/

3/08/2014

Potentially Malicious Visitor (to this Blog):
www.tomato.ph (MaxMind)
(TRACKING, SPYING) IPs: 54.236.190.114 & 108.168.255.244
United States (Ashburn, VIRGINIA & Dallas, TEXAS)


POTENTIALLY MALICIOUS DOMAIN: 
(POLICY) MAXMIND (TRACKING, SPYING)

DOMAIN:
http://www.tomato.ph/
  • https://www.virustotal.com/de/url/8f1306cf60d80de18b06697d12890e89943b23ab44960d750d9b9ba3ec5121db/analysis/1394306901/
--->
http://j.maxmind.com/app/geoip.js
  • https://www.virustotal.com/de/url/bdffdcdd50418770193d866a68d097ffbbd72158caa110f2b7540bee5f2aab9b/analysis/1394307559/
  • https://urlquery.net/report.php?id=9831174
IPs =
http://54.236.190.114/
  • https://www.virustotal.com/de/url/d6c397de2fdc35201adfd6f4bc67fe61be7c58a193bccf78224707c9f05f59ad/analysis/1394308470/
  • https://www.virustotal.com/de/ip-address/54.236.190.114/information/
http://108.168.255.244/
  • https://www.virustotal.com/de/url/11d9dd4b53825e5f4371d6010274fd0d1caf942de082ad4f337333ed4697b0bb/analysis/1394308621/
  • https://www.virustotal.com/de/ip-address/108.168.255.244/information/
WEB REPUTATION: POOR
  • http://www.senderbase.org/lookup/?search_string=108.168.255.244
ALSO INVOLVED:
http://s3.amazonaws.com/
  • https://www.virustotal.com/de/url/fb0222f7e7664026a7b4947403538912107334fcb96e6dd7aae7cc63a7046fef/analysis/1394307761/
IP =
http://176.32.102.66/
  • https://www.virustotal.com/de/url/2b46d508f8e2d72d0d42a638111f39f7eedf221718f6b08efd1f313d31b2a3c7/analysis/1394308270/
  • https://www.virustotal.com/de/ip-address/176.32.102.66/information/
Fwd/Rev DNS Match: No
  • http://www.senderbase.org/lookup/?search_string=176.32.102.66

1/01/2014

Underground Drug Website “Silk Road”: Manhattan U.S. Attorney Announces Charges Against Three Individuals for Their Roles in Running Silk Road Website

On December 20th, 2013, Preet Bharara, the United States Attorney for the Southern District of New York, George Venizelos, the Assistant Director-in-Charge of the New York Office of the Federal Bureau of Investigation, Brian R. Crowell, the Special-Agent-in-Charge of the New York Field Division of the Drug Enforcement Administration, and Toni Weirauch, the Special Agent-in-Charge of the New York Field Office of the Internal Revenue Service, Criminal Investigation (“IRS-CI”), announced the unsealing of an indictment against Andrew Michael Jones, a/k/a “Inigo,” Gary Davis, a/k/a “Libertas,” and Peter Philipp Nash, a/k/a “Samesamebutdifferent,” a/k/a “Batman73,” a/k/a “Symmetry,” a/k/a “Anonymousasshit,” in connection with their alleged roles in operating
“Silk Road,”, a hidden website designed to enable its users to buy and sell illegal drugs and other unlawful goods and services anonymously and beyond the reach of law enforcement.

Jones was arrested in Charles City, Virginia, on December 19th, 2013, and was presented in Richmond, Virginia in the United States District Court for the Eastern District of Virginia a day later.

Davis is believed to be in Ireland.

Nash was arrested in Australia on December 20th, 2013, by the Australian Federal Police in Brisbane, Australia.

All three individuals are alleged to have conspired to run the Silk Road website with Ross William Ulbricht, a/k/a “Dread Pirate Roberts,” a/k/a “DPR,” a/k/a “Silk Road,” the alleged owner and operator of Silk Road, who was previously arrested in San Francisco, California, on October 1st, 2013, pursuant to a Complaint filed in a Manhattan federal court.



According to the allegations in the Indictment unsealed in Manhattan federal court, and the Complaint previously filed against Ulbricht:

From about January 2011 until October 2nd, 2013, the “Silk Road” website hosted a sprawling black-market bazaar on the internet, where illegal drugs and other illicit goods and services were regularly bought and sold by the site’s users. 
During its more than two-and-a-half years in operation, Silk Road was used by several thousand drug dealers and other unlawful vendors to distribute hundreds of kilograms of illegal drugs and other illicit goods and services to well over a hundred thousand buyers, and to launder hundreds of millions of dollars deriving from these unlawful transactions.

Ulbricht, the owner and operator of Silk Road, ran the website with the assistance of a small support staff, including both site administrators and forum moderators. The site administrators were responsible for, among other things, monitoring user activity on Silk Road for problems, responding to customer service inquiries, and resolving disputes between buyers and vendors. 
The forum moderators were responsible for, among other things, monitoring user activity on discussion forums associated with the site, providing guidance to forum users concerning how to conduct business on Silk Road, and reporting any significant problems discussed on the forums to the site administrators and to Ulbricht. Ulbricht paid the site administrators and forum moderators salaries ranging from approximately $50,000 to approximately $75,000 per year for their services.

Jones and Davis worked as site administrators on Silk Road. 
Nash worked as the primary moderator on the Silk Road discussion forums. JONES, DAVIS, and NASH were each paid salaries by Ulbricht for their roles in connection with Silk Road.

JONES, 24, of Charles City, Virginia, DAVIS, 25, of Wicklow, Ireland, and NASH, 40, of Brisbane, Australia, are each charged with one count of narcotics conspiracy, which carries a maximum sentence of life in prison and a mandatory minimum sentence of 10 years in prison; one count of conspiracy to commit computer hacking, which carries a maximum sentence of five years in prison; and one count of money laundering conspiracy, which carries a maximum sentence of 20 years in prison.

The official Indictment PDF can be found here: http://www.wired.com/images_blogs/threatlevel/2013/12/Jones-Andrew-et-al-Silk-Road-Indictment.pdf