<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; Hacker Hunting</title>
	<atom:link href="http://www.thedarkvisitor.com/category/hacker-hunting/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 24 Feb 2010 10:27:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Leader of Chinese hacker group that planned DDoS attack on CNN identified</title>
		<link>http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/</link>
		<comments>http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/#comments</comments>
		<pubDate>Sun, 19 Jul 2009 13:03:53 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker History]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Tibet]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1805</guid>
		<description><![CDATA[In April of 2008, we reported Revenge of the Flame&#8217;s plan to carry out a DDoS attack on the CNN website.  A series of events during that time period enraged the Chinese online community: European nations harshly criticized China&#8217;s response to the Tibetan uprising; pro-Tibetan independence protesters in Paris tried to snatch the Olympic torch [...]]]></description>
			<content:encoded><![CDATA[<p>In April of 2008, we reported <a href="http://www.thedarkvisitor.com/2008/04/breaking-anti-cnns-call-for-european-protests-spreading-onlinebreaking-cnn-possible-target-of-chinese-hacker-attack-on-19-april-what-beijing-police-supplied-eggs-to-protesters-during-anti-japan/"><em>Revenge of the Flame</em>&#8217;s plan to carry out a DDoS attack</a> on the <em>CNN</em> website.  A series of events during that time period enraged the Chinese online community: European nations harshly criticized China&#8217;s response to the Tibetan uprising; pro-Tibetan independence protesters in Paris tried to snatch the Olympic torch from the hands of a wheelchair-bound Chinese female athlete; and Jack Cafferty, a CNN commentator, referred to Chinese products as &#8220;junk&#8221; and called the Chinese government &#8220;goons and thugs.&#8221;   In response to these insults, <em>Anti-CNN</em> called for overseas Chinese in Europe to wave the Chinese flag and raise their voice to the sky.</p>
<p>In response to these same events, a hacker, using the online name cn_magistrate, formed a group called Revenge of the Flame and announced his plan to carry out a DDoS attack on<em> the  CNN</em> website.  We <a href="http://www.thedarkvisitor.com/2008/04/breaking-upcoming-chinese-hacker-attack-on-cnn-building-steam/">followed the events</a> as calls went out for Chinese netizens to join the action.  We were there when cn_magistrate <a href="http://www.thedarkvisitor.com/2008/04/chinese-hacker-group-identified-as-revenge-of-the-flame-calls-off-attack-on-cnntoo-many-people-know/">called off the attack</a> and <a href="http://www.thedarkvisitor.com/2008/04/revenge-of-the-flame-disbands-denies-all-responsibility-for-attack-on-cnnand-kills-website/">disbaned the organization</a>.  Then he vanished&#8230;</p>
<p style="text-align: center;"><a rel="attachment wp-att-1806" href="http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/cnmagistrate/"><img class="aligncenter size-thumbnail wp-image-1806" title="cnmagistrate" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/cnmagistrate-150x150.jpg" alt="cnmagistrate" width="150" height="150" /></a></p>
<p style="text-align: center;">cn_magistrate</p>
<p style="text-align: left;"><strong>Cold Case</strong>:  Yeah, we keep looking.  Finally <a href="http://hi.baidu.com/hack666/profile">located him</a> through a combination of e-mail address, website and online name.   Below are the results of a Whois search we conducted on the associated website during the time of the attack (Notice the website name and e-mail address):</p>
<p style="text-align: left;">Domain Name: <span style="color: #ff0000;">hacksa.cn<strong style="color: #333333;"> </strong></span><br />
ROID: 20070811s10001s50288265-cn<br />
Domain Status: ok<br />
Registrant Organization: 判官<br />
Registrant Name: 判官<br />
Administrative Email: <span style="color: #ff0000;">Kenan2677@126.com</span><br />
Sponsoring Registrar: 北京万网志成科技有限公司<br />
Name Server:ns1.okidc.com Name Server:ns2.okidc.com<br />
Registration Date: 2007-08-11 11:59<br />
Expiration Date: 2008-08-11 11:59</p>
<p style="text-align: left;">
<p style="text-align: center;"><a rel="attachment wp-att-1807" href="http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/cnmagistrate2/"><img class="size-thumbnail wp-image-1807 aligncenter" title="cnmagistrate2" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/cnmagistrate2-150x150.jpg" alt="cnmagistrate2" width="150" height="150" /></a></p>
<p style="text-align: center;">Hacksa.cn website letter</p>
<p style="text-align: left;">The image seen above was taken from cn_magistrate&#8217;s <a href="http://hi.baidu.com/hack666/album/item/76ab0f2ed5d95a584ec22600.html#IMG=7afdc950c42ede511038c2e8">current blog</a> showing the old URL  hacksa.cn,  which was <a href="http://www.thedarkvisitor.com/2008/04/495/">associated with the <em>CNN</em> attack</a>.</p>
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;"><a rel="attachment wp-att-1809" href="http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/cnmagistrate4-2/"><img class="aligncenter size-medium wp-image-1809" title="cnmagistrate4" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/cnmagistrate41-300x30.jpg" alt="cnmagistrate4" width="300" height="30" /></a></p>
<p style="text-align: left;">This <a href="http://hi.baidu.com/hack666/blog/item/ed31f11360dd07015aaf53ce.html">reply from cn_magistrate</a> in the comments section of his blog shows the e-mail address  Kenan2677@126.com, used to register <em>hacksa.cn</em>.</p>
<p style="text-align: left;">SURPRISE&#8230;</p>
<p style="text-align: left;"><a rel="attachment wp-att-1812" href="http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/cnmagistrate3/"><img class="aligncenter size-full wp-image-1812" title="cnmagistrate3" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/cnmagistrate3.JPG" alt="cnmagistrate3" width="284" height="289" /></a></p>
<p style="text-align: left;">He claims to be a Taiwanese citizen&#8230;</p>
<p style="text-align: left;">I&#8217;ve written to cn_magistrate and asked if he will talk to us about the incident.  Off topic, did anyone hear the news about Taiwan and the US coming closer to an <a href="http://www.chinapost.com.tw/taiwan/foreign-affairs/2009/05/28/209871/Ma-pitches.htm">extradition agreement</a>?  That would be cool.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.thedarkvisitor.com%2F2009%2F07%2Fleader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified%2F&amp;linkname=Leader%20of%20Chinese%20hacker%20group%20that%20planned%20DDoS%20attack%20on%20CNN%20identified"><img src="http://www.thedarkvisitor.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/07/leader-of-chinese-hacker-group-that-planned-ddos-attack-on-cnn-identified/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Hacker hunting: Finding the Mafia Baron</title>
		<link>http://www.thedarkvisitor.com/2009/07/hacker-hunting-finding-the-mafia-baron/</link>
		<comments>http://www.thedarkvisitor.com/2009/07/hacker-hunting-finding-the-mafia-baron/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 22:58:01 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[Other attacks]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1765</guid>
		<description><![CDATA[
Chinese hackers are annoying, it&#8217;s a fact.  You ask a simple question trying to establish if they were the person responsible for  hacking the Turkish Embassy website and you get the run around.  Our hacker in question responds with the standard, &#8220;I&#8217;ve got no idea what you&#8217;re talking about.&#8221; ANNOYING
Then in our comments section, a [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a rel="attachment wp-att-1768" href="http://www.thedarkvisitor.com/2009/07/hacker-hunting-finding-the-mafia-baron/baron/"><img class="aligncenter size-full wp-image-1768" title="baron" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/baron.JPG" alt="baron" width="456" height="263" /></a></p>
<p>Chinese hackers are annoying, it&#8217;s a fact.  You ask a simple question trying to establish if they were the person responsible for  <a href="http://www.thedarkvisitor.com/2009/07/chinese-hacker-warning-left-on-turkish-embassy-website/">hacking the Turkish Embassy website</a> and you get the run around.  Our hacker in question responds with the standard, &#8220;I&#8217;ve got no idea what you&#8217;re talking about.&#8221; ANNOYING</p>
<p>Then in our comments section, a Chinese hacker leaves a message saying that it was all <a href="http://www.thedarkvisitor.com/2009/07/chinese-hacker-warning-left-on-turkish-embassy-website/#comment-3294">just a crazy coincidence</a> and this is the wrong guy.  Next, someone using a different name <a href="http://www.thedarkvisitor.com/2009/07/chinese-hacker-warning-left-on-turkish-embassy-website/#comment-3295">leaves the comment</a> &#8220;Mafia Baron MSN:lfort@lvte.cn&#8221; without any further explanation.  ANNOYING</p>
<p><span id="more-1765"></span></p>
<p>Time to revisit the hacker&#8217;s website and see what I missed.  One of the first things I looked for was the name Mafia Baron in the blogroll section to make sure I hadn&#8217;t made a mistake&#8230;and it wasn&#8217;t there.  Bless Google cache for keeping a copy from the 12th, clearly showing the link to Mafia Baron (on left) even though it was removed today (on right). ANNOYING</p>
<p><a rel="attachment wp-att-1766" href="http://www.thedarkvisitor.com/2009/07/hacker-hunting-finding-the-mafia-baron/baron2/"><img class="aligncenter size-full wp-image-1766" title="baron2" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/baron2.JPG" alt="baron2" width="471" height="421" /></a> When you rolled over the link for Mafia Baron,  it pointed back to the same website, http://hi.baidu.com/forhack.  It just might be that the owner of the  site accidentally  linked to his own website and not that of the Baron.   ANNOYING</p>
<p>Why do I think the site owner accidentally linked to his own site?  Baidu blogs have a special feature that shows the last couple of visitors to your site if they are also using Baidu blogs and one of the guests had lfort08 underneath his icon.  It was too similar to the address left in our comments section to be unrelated:</p>
<p><a rel="attachment wp-att-1767" href="http://www.thedarkvisitor.com/2009/07/hacker-hunting-finding-the-mafia-baron/baron3/"><img class="aligncenter size-full wp-image-1767" title="baron3" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/baron3.JPG" alt="baron3" width="383" height="386" /></a>Clicking on the icon takes you to the <a href="http://hi.baidu.com/lfort08">Mafia Baron&#8217;s website</a> and in <a href="http://hi.baidu.com/lfort08/album/item/37359891f4dadeaaa877a453.html">his photo album</a> is a screen shot of the embassy defacement, time stamped only 46 minutes after the reported time of the attack:  ANNOYING</p>
<p style="text-align: center;"><a rel="attachment wp-att-1769" href="http://www.thedarkvisitor.com/2009/07/hacker-hunting-finding-the-mafia-baron/baronfinal/"><img class="aligncenter size-thumbnail wp-image-1769" title="baronfinal" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/07/baronfinal-150x150.jpg" alt="baronfinal" width="150" height="150" /></a></p>
<p style="text-align: left;">You know, if all of the stuff on the Baron&#8217;s website just disappears, it will really be&#8230;</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.thedarkvisitor.com%2F2009%2F07%2Fhacker-hunting-finding-the-mafia-baron%2F&amp;linkname=Hacker%20hunting%3A%20Finding%20the%20Mafia%20Baron"><img src="http://www.thedarkvisitor.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/07/hacker-hunting-finding-the-mafia-baron/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Hackers: the China Syndrome by Mara Hvistendahl</title>
		<link>http://www.thedarkvisitor.com/2009/04/hackers-the-china-syndrome-by-mara-hvistendahl/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/hackers-the-china-syndrome-by-mara-hvistendahl/#comments</comments>
		<pubDate>Fri, 24 Apr 2009 11:12:48 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker History]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Leaders]]></category>
		<category><![CDATA[Nationalism]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1549</guid>
		<description><![CDATA[Best hobby in the world.
It was absolutely my privilege to  spend a few days talking with Mara Hvistendahl on the subject of Chinese hackers.  She is such a fantastic lady and I couldn&#8217;t have enjoyed our time more. 
While linking to our interview may seem a bit of shameless self-promotion, I mainly wanted it on [...]]]></description>
			<content:encoded><![CDATA[<p>Best hobby in the world.</p>
<p><span class="author">It was absolutely my privilege to  spend a few days talking with <a href="http://www.marahvistendahl.com/bio.cfm">Mara Hvistendahl</a> on the subject of Chinese hackers.  She is such a fantastic lady and I couldn&#8217;t have enjoyed our time more. </span></p>
<p><span class="author">While linking to our interview may seem a bit of shameless self-promotion, I mainly wanted it on record that Mara called me, &#8220;</span>a <strong>trim</strong> 46-year-old.&#8221;  I pushed for other words like swashbuckling, ruggedly handsome and athletic until Mara started mentioning other adjectives such as weird, strange and goofy.</p>
<p><strong>&#8230;TRIM!</strong></p>
<p><a href="http://www.popsci.com/scitech/article/2009-04/hackers-china-syndrome"><em>Hackers: the China Syndrome</em></a> by Mara Hvistendahl</p>
<p><span class="author"><br />
</span></p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.thedarkvisitor.com%2F2009%2F04%2Fhackers-the-china-syndrome-by-mara-hvistendahl%2F&amp;linkname=Hackers%3A%20the%20China%20Syndrome%20by%20Mara%20Hvistendahl"><img src="http://www.thedarkvisitor.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/hackers-the-china-syndrome-by-mara-hvistendahl/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>CasperNet gets punked</title>
		<link>http://www.thedarkvisitor.com/2009/04/caspernet-gets-punked/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/caspernet-gets-punked/#comments</comments>
		<pubDate>Sat, 04 Apr 2009 13:37:33 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[India Attacks]]></category>
		<category><![CDATA[CasperNet]]></category>
		<category><![CDATA[lost33]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1497</guid>
		<description><![CDATA[Remember the fable about the Scorpion and the Frog?  Well, we got stung&#8230;
Lost33 did not make contact with Jumper last night.  In fact, it seems he spent the night changing his QQ number and deleting all info from his blog. The website is now completely empty, except for a change to his personal data.  Lost33 [...]]]></description>
			<content:encoded><![CDATA[<p>Remember the fable about the <a href="http://en.wikipedia.org/wiki/The_Scorpion_and_the_Frog">Scorpion and the Frog</a>?  Well, we got stung&#8230;</p>
<p>Lost33 did not make contact with Jumper last night.  In fact, it seems he spent the night changing his QQ number and deleting all info from <a href="http://hi.baidu.com/damnfootman">his blog</a>. The website is now completely empty, except for a change to his personal data.  Lost33 changed his current residence from Sichuan to Beijing:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1638" href="http://www.thedarkvisitor.com/2009/04/caspernet-gets-punked/capsernetpunk1-2/"><img class="aligncenter size-medium wp-image-1638" title="CapserNetPunk1" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/CapserNetPunk1-300x205.jpg" alt="CapserNetPunk1" width="300" height="205" /></a></p>
<p>We retained a full copy of the previous night&#8217;s conversation with Lost33 but have decided to only release two sections.  The first section is being reprinted to prove the connection between Lost33 and the losttemp33 hotmail account:</p>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #008242; text-align: center;">jumper_tdv 2009-04-02 23:57:28</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">Do you have the email address <a href="mailto:losttemp33@hotmail.com">losttemp33@hotmail.com</a>?</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #0000ff; text-align: center;"><span style="font-family: STHeiti Light; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal;">周小屁</span> 2009-04-02 23:57:30</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: 'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">Sorry for my english too</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #0000ff; text-align: center;"><span style="font-family: STHeiti Light; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal;">周小屁</span> 2009-04-02 23:58:11</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: 'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">yes ,but i never use it.</div>
<p>The second section is being released&#8230;well, to be honest, just because I think it is funny. I can practically see Jumper&#8217;s expression as he types, &#8220;Yes, really.&#8221;</p>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #008242; text-align: center;">jumper_tdv 2009-04-03 00:05:29</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">The problem is that your lost33 email is used to register DNS names for hackers</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #0000ff; text-align: center;"><span style="font-family: STHeiti Light; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal;">周小屁</span> 2009-04-03 00:05:43</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: 'Lucida Grande'; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;"><span style="font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 12px; line-height: normal; font-size-adjust: none; font-stretch: normal;"> </span> really?</div>
<p style="text-align: center;">
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; color: #008242; text-align: center;">jumper_tdv 2009-04-03 00:05:51</div>
<div style="margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; font-size: 13px; line-height: normal; font-size-adjust: none; font-stretch: normal; text-align: center;">Yes, really</div>
<p>Are we surprised, shocked, or angry over Lost33 punking us&#8230;</p>
<p>-Hey, it&#8217;s just his nature.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.thedarkvisitor.com%2F2009%2F04%2Fcaspernet-gets-punked%2F&amp;linkname=CasperNet%20gets%20punked"><img src="http://www.thedarkvisitor.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/caspernet-gets-punked/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Children of a lesser malware</title>
		<link>http://www.thedarkvisitor.com/2009/04/children-of-a-lesser-malware/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/children-of-a-lesser-malware/#comments</comments>
		<pubDate>Fri, 03 Apr 2009 20:51:20 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[India Attacks]]></category>
		<category><![CDATA[CasperNet]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1494</guid>
		<description><![CDATA[UPDATE: Added further comment by Nart Villeneuve at the bottom (Great guy!)
Yep, that would be us&#8230;
According to researchers at IWM, Lost33&#8217;s information was only included in the GhostNet report because his malware was found on two computers associated with the Dalai Lama&#8217;s network.  However, it was different from the remote control access tool gh0stRAT that [...]]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE:</strong> Added further comment by Nart Villeneuve at the bottom (Great guy!)</p>
<p>Yep, that would be us&#8230;</p>
<p>According to researchers at IWM, Lost33&#8217;s information was only included in the GhostNet report because his malware was found on two computers associated with the Dalai Lama&#8217;s network.  However, it was different from the remote control access tool<span class="body"> gh0stRAT that made up the backbone of GhostNet.</span></p>
<p><span class="body">From the <a href="http://www.securityfocus.com/brief/940">report</a> by Robert Lemos at <em>Security Focus</em>:</span></p>
<blockquote><p>However, the e-mail address was found only on two of the computers analyzed for the investigation, said Nart Villeneuve, a researcher at the CitizenLab and one of the authors of the GhostNet report. Both computers had been infected with a second piece of malware, separate from the gh0st remote access tool (gh0stRAT) that formed the backbone of the surveillance network, he said.</p>
<p>&#8220;That is a valid piece of malware but it is not the one related to the malware that connected to the admin interface for the gh0stRAT,&#8221; Villeneuve said.</p></blockquote>
<p>So it looks like we are now investigating a massive network intrusion of two computers.  One, two.  We will call our project CasperNet.</p>
<p style="text-align: center;"><a href="http://doopy1956.com/graphics/casper.jpg"><img class="aligncenter" src="http://doopy1956.com/graphics/casper.jpg" alt="" width="350" height="271" /></a></p>
<p>Spoke with Jumper earlier today and he still feels it is worthwhile to pursue.  So, he will continue his conversation with Lost33 tonight.</p>
<p><strong>UPDATE:</strong> Wanted to add this comment left by <a href="http://www.nartv.org/">Nart Villeneuve</a> because I thought it was super nice of him.  I botched up his report but he was still kind enough to stop by and offer these words of encouragement:</p>
<p>&#8220;I wouldn’t say lesser at all — just different. The CasperNet (www.lookbytheway.net/www.macfeeresponse.org) which sounds way better than what I’ve been calling it (CGI after their use of CGI scripts) was the one that was found to be retrieving a sensitive document related to the Dalai Lama’s negotiating position. In addition to being found at the OHHDL it was also found at the Tibetan NGO Drewla.&#8221;</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.thedarkvisitor.com%2F2009%2F04%2Fchildren-of-a-lesser-malware%2F&amp;linkname=Children%20of%20a%20lesser%20malware"><img src="http://www.thedarkvisitor.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/children-of-a-lesser-malware/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Hunting the GhostNet Hacker</title>
		<link>http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/#comments</comments>
		<pubDate>Thu, 02 Apr 2009 17:16:55 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Ghostnet]]></category>
		<category><![CDATA[IWM]]></category>
		<category><![CDATA[lost33]]></category>
		<category><![CDATA[opanpan]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1441</guid>
		<description><![CDATA[UPDATE: James Tay from Citizen Lab left us a comment.  That&#8217;s right, part of the support team for the Ghostnet Report.  God, we really should have cleaned up the place.  Thanks for taking the time to stop by James! (originally I stated he was a contributing author, James has clarified).
UPDATE2: Lost33 is now in contact [...]]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE:</strong> James Tay from <a href="http://www.citizenlab.org/"><em>Citizen Lab</em></a> left us a comment.  That&#8217;s right, part of the support team for the <em>Ghostnet Report</em>.  God, we really should have cleaned up the place.  Thanks for taking the time to stop by James! (originally I stated he was a contributing author, James has clarified).</p>
<p><span style="color: #ff0000;">UPDATE2: </span><span style="color: #ff0000;">Lost33 is now in contact with us and we are trying to get his side of the story.  He has requested we mask his QQ number now that he is in contact and we have complied.  (Never do late night updates.  A commenter pointed out that the original wording for this update sounded like we were holding his QQ hostage unless he spoke with us.  That certainly wasn&#8217;t my meaning but that is definitely what it sounded like.  Just wanted to explain the reason for the sudden masking of his contact number.)<br />
</span></p>
<p>First, hats off to the researchers at <a href="http://www.infowar-monitor.net/">IWM</a>.  They did great work on the GhostNet project and we owe them a debt of gratitude for sharing it with us.</p>
<p style="text-align: center;"><strong>The Hunt</strong></p>
<p>One aspect skipped over in the GhostNet report were the e-mails associated with the websites, losttemp33@hotmail.com and opanpan@gmail.com.  For the last two days, Jumper and I have been tracking them down to see where they would take us.</p>
<p>Comparing the Whois returns for two of the websites involved, macfeeresponse.com and scratchindian.com, yields startlingly similar results:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1643" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetwhoiscompare-2/"><img class="aligncenter size-thumbnail wp-image-1643" title="ghostnetwhoiscompare" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetwhoiscompare-150x150.jpg" alt="ghostnetwhoiscompare" width="150" height="150" /></a></p>
<p style="text-align: center;">Double-click to fully englarge</p>
<p style="text-align: left;">We conclude that this is the same person using different e-mail addresses or associates working together.  The domains are registered on the same server and are too close in content to be considered a random coincidence.</p>
<p style="text-align: left;">The Opanpan e-mail went nowhere, so we concentrated on losttemp33.  A simple Google search for the e-mail address, led us to the website for <em><a href="http://search.pudn.com/friend_i.asp?e=litonghui*263.net" target="_blank">Programmers United Development Net:</a></em></p>
<p style="text-align: center;"><a rel="attachment wp-att-1644" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetpudn-2/"><img class="aligncenter size-full wp-image-1644" title="ghostnetPUDN" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetPUDN.JPG" alt="ghostnetPUDN" width="489" height="262" /></a></p>
<p style="text-align: left;">Clicking on the link leads to <a href="http://www.pudn.com/upload_log.asp?e=losttemp33*hotmail.com">three programs losttemp33</a> provided for download.</p>
<p>Next we were able to locate a post from <a href="http://www.whitecell.org/forums/viewthread.php?tid=101&amp;page=1&amp;sid=gtGR1QRz#pid497">2005 on Windows hacking</a>:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1645" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetfirstemail-2/"><img class="aligncenter size-full wp-image-1645" title="ghostnetfirstemail" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetfirstemail.JPG" alt="ghostnetfirstemail" width="489" height="274" /></a></p>
<p style="text-align: left;">Notice that the author of this post uses the signature <strong>Lost33</strong> in the upper left-hand corner.  Using the signature <a href="http://www.google.com/search?q=lost33+%E9%BB%91%E5%AE%A2&amp;hl=en&amp;client=firefox-a&amp;rls=org.mozilla:en-US:official&amp;start=0&amp;sa=N">Lost33 and the Chinese characters for hacker</a> (黑客), we were able to find an individual who was associated with Xfocus, Isbase and even seems to have <a href="http://209.85.173.132/search?q=cache:6O3meawl2sgJ:https://www.xfocus.org/bbs/index.php?act%3DST%26f%3D12%26t%3D27219%26page%3D6+%22lost33%22+%E9%BB%91%E5%AE%A2&amp;cd=2&amp;hl=en&amp;ct=clnk&amp;gl=us">studied under Glacier</a>.  More importantly, we found a <a href="http://i.mop.com/lost33">blog</a> under the same name.</p>
<p style="text-align: center;"><a rel="attachment wp-att-1646" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetmopprofile-2/"><img class="aligncenter size-full wp-image-1646" title="ghostnetmopprofile" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetmopprofile.JPG" alt="ghostnetmopprofile" width="485" height="399" /></a></p>
<p style="text-align: left;">This blog stopped getting updates in 2006 but provided us with a couple of more clues to keep searching.  The first red box shows the date of birth as 24 July 1982 and place of current residence as Chengdu City, Sichuan.  It is important to recall that all of the Whois results for GhostNet associated websites showed Chengdu, Sichuan as the city and province for the organization. The second red box at the bottom is Lost33&#8217;s personal motto, &#8220;The bored soldier swaying on an empty battlefield.&#8221;</p>
<p style="text-align: left;">We kept searching but it seemed like we had hit a brick wall, Lost33 vanished from the internet in 2006.  That was when we decided that a person might change their user id but never their motto.  Can&#8217;t abandon your motto.</p>
<p style="text-align: left;">Plugged in the &#8220;The bored soldier,&#8221; and bingo&#8230;<a href="http://hi.baidu.com/damnfootman">The Bored Soldier&#8217;s blog space</a>:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1647" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetbannerheader-2/"><img class="aligncenter size-medium wp-image-1647" title="ghostnetbannerheader" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetbannerheader-300x131.jpg" alt="ghostnetbannerheader" width="300" height="131" /></a></p>
<p style="text-align: left;">Lost33 now blogs under the name Damnfootman:</p>
<p style="text-align: left;"><a rel="attachment wp-att-1451" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetdamnfootman/"></a></p>
<p style="text-align: center;"><a rel="attachment wp-att-1702" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetdamnfootman-2/"><img class="aligncenter size-full wp-image-1702" title="ghostnetdamnfootman" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetdamnfootman.JPG" alt="ghostnetdamnfootman" width="430" height="578" /></a></p>
<p style="text-align: left;">
<p style="text-align: left;">Why are we sure this is the same person as Lost33?  Well, they not only share the same motto but <a href="http://hi.baidu.com/damnfootman/profile">birth date and place of residence as well</a>:</p>
<p style="text-align: left;"><a rel="attachment wp-att-1452" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetprofile/"></a></p>
<p style="text-align: center;"><strong><a rel="attachment wp-att-1703" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetprofile-2/"><img class="aligncenter size-full wp-image-1703" title="ghostnetprofile" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetprofile.JPG" alt="ghostnetprofile" width="481" height="192" /></a></strong></p>
<p style="text-align: left;">
<p style="text-align: center;"><strong>Blog bits of interest</strong></p>
<ul>
<li>Lost33 attended the <a href="http://www.uestc.edu.cn/web3/">University of Electronic Science and Technology</a> in China.</li>
</ul>
<ul>
<li>He has a <a href="http://forum.eviloctal.com/thread-29717-1-1.html">link</a> on the website to the Chinese hacker<em> </em>forum for<em> Eviloctal</em> and our dear friend <a href="http://www.thedarkvisitor.com/2007/11/peoples-armed-police-officer-hacking/">Sunwear</a>.</li>
</ul>
<ul>
<li>Lost33 is also keeping up with friends at <a href="http://hi.baidu.com/damnfootman/blog/item/b6f0d71959d5350034fa41b8.html">Xfocus and NSfocus</a><a href="http://cache.baidu.com/c?m=9d78d513d9d430ae4f9d90697d61c010124381132ba7a6020bde843892732a30506692e761615753938e3d2c40e91e03b1ac622f775c73f1c095d45dddcad06872d97075311d8615499358e9df01659f2fca1cafed0ee6c9ed2fd9ff8f8fc854248007582bc7b19c5a77489d29ed7e40befa994a17590de9ad613fa41d2068824911eb1bf9e230681086829b055bc35d923745&amp;p=9e718d1486cc41dd0be295644f&amp;user=baidu"> </a>on garden variety hacker tools.</li>
</ul>
<p>We have left a couple of posts on Lost33&#8217;s blog and are waiting to see if he will respond:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1648" href="http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/ghostnetpost-2/"><img class="aligncenter size-medium wp-image-1648" title="ghostnetpost" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetpost-285x300.jpg" alt="ghostnetpost" width="285" height="300" /></a></p>
<p>The note asks Lost33 if he would be willing to discuss the GhostNet matter with us.</p>
<p>There were two QQ numbers associated with the opanpan and lost33 email addresses.  We attempted to contact both of them but were rejected.</p>
<p style="text-align: center;"><strong>Summary</strong></p>
<p>While we are aware that there are other lost33 websites out there, such as myspace/lost33, these do not meet the profile of our hacker. It would be a very unusual set of circumstances that would lead to such a bizarre set of coincidences coming together as we have here:</p>
<ul>
<li>The Ghostnet websites list Chengdu, Sichuan under organization and the pseudonym losttemp33 as the contact e-mail address.</li>
</ul>
<ul>
<li>The e-mail address losttemp33@hotmail.com has been posted on at least two websites dealing with computer programming. The post on hacking Windows shows that the person also uses the alias lost33 as an alternative to the full e-mail address.</li>
</ul>
<ul>
<li>An individual using the lost33 signature has posted on several Chinese hacker forums including Xfocus and Isbase (the Green Army). He may even have been a student under Glacier.</li>
</ul>
<ul>
<li>The first lost33 website shows a birth date of 24 July 1982 and current address as Chengdu, Sichuan. The website motto is, “The bored solider sways on the empty battlefield.”</li>
</ul>
<ul>
<li>The second “bored soldier” website is clearly owned by the same person as the first lost33 website. The owners were born on the same date; both live in Chengdu, Sichuan and use the same motto. The new website has links with known hacker websites (Xfocus, NSfocus and Eviloctal), links to hacker programs and demonstrates and education in technology (University of Electronic Science and Technology of China).</li>
</ul>
<p>Obviously the weakest link in the analysis is the jump between losttemp33 and lost33 but we feel the weight of the evidence shows a connection. We do not conclusively claim this person is involved but we think further inquiry is needed.</p>
<p>&lt;edit&gt; &#8211; A few readers have asked for the QQ number that was redacted.  Since lost33 doesn&#8217;t seem to be using that QQ number anymore &#8211; here is the original screenshot:</p>
<p><img class="alignleft size-full wp-image-1516" title="picture-11" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/picture-11.png" alt="lost33's QQ" /></p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.thedarkvisitor.com%2F2009%2F04%2Fhunting-the-ghostnet-hacker%2F&amp;linkname=Hunting%20the%20GhostNet%20Hacker"><img src="http://www.thedarkvisitor.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/hunting-the-ghostnet-hacker/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>A simple post</title>
		<link>http://www.thedarkvisitor.com/2009/04/a-simple-post/</link>
		<comments>http://www.thedarkvisitor.com/2009/04/a-simple-post/#comments</comments>
		<pubDate>Thu, 02 Apr 2009 10:01:19 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Ghostnet]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1460</guid>
		<description><![CDATA[I posted this yesterday on a Chinese blog and Jumper has been trying to reach him via QQ:


The note asks the owner of the website if he would be willing to discuss the GhostNet matter with us.
He logged on for several hours after the question had been posted but has not responded as of this [...]]]></description>
			<content:encoded><![CDATA[<p>I posted this yesterday on a Chinese blog and Jumper has been trying to reach him via QQ:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1461" href="http://www.thedarkvisitor.com/2009/04/a-simple-post/ghostnetmask/"><a rel="attachment wp-att-1655" href="http://www.thedarkvisitor.com/2009/04/a-simple-post/ghostnetmask-3/"><img class="aligncenter size-full wp-image-1655" title="ghostnetmask" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/04/ghostnetmask1.JPG" alt="ghostnetmask" width="481" height="506" /></a><br />
</a></p>
<p>The note asks the owner of the website if he would be willing to discuss the GhostNet matter with us.</p>
<p>He logged on for several hours after the question had been posted but has not responded as of this time.</p>
<p>This story will run later today, with or without communication from the individual.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.thedarkvisitor.com%2F2009%2F04%2Fa-simple-post%2F&amp;linkname=A%20simple%20post"><img src="http://www.thedarkvisitor.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/04/a-simple-post/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Charging Bull and Chinese Vampire</title>
		<link>http://www.thedarkvisitor.com/2009/02/charging-bull-and-chinese-vampire/</link>
		<comments>http://www.thedarkvisitor.com/2009/02/charging-bull-and-chinese-vampire/#comments</comments>
		<pubDate>Sun, 15 Feb 2009 17:04:51 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacker History]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Charging Bull]]></category>
		<category><![CDATA[Chinese Vampire]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1356</guid>
		<description><![CDATA[
What does the Charging Bull have in common with the Chinese Vampire? According to Dr. Shi Xiaohong, who performed extensive analysis on the two viruses, they were written by the same author.
Sina Tech News has been reporting on the rapid spread of a relatively new virus called &#8220;Charging Bull.&#8221; Probably got the name from appearing [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-1676" href="http://www.thedarkvisitor.com/2009/02/charging-bull-and-chinese-vampire/bullvampire-2/"><img class="aligncenter size-full wp-image-1676" title="bullvampire" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/02/bullvampire.JPG" alt="bullvampire" width="400" height="406" /></a></p>
<p>What does the Charging Bull have in common with the Chinese Vampire? According to Dr. Shi Xiaohong, who performed extensive analysis on the two viruses, they were written by the same author.</p>
<p><em>Sina Tech News</em> has been reporting on the rapid <a href="http://www.cnwnews.com/html/tech/cn_hlw/gnhlw/20090215/78451.html">spread of a relatively new virus called &#8220;Charging Bull.&#8221;</a> Probably got the name from appearing around the same time as the Chinese New Year, Year of the Ox.  Let&#8217;s face it, &#8220;Charging Ox&#8221; does not sound cool.</p>
<p>In June of 08, we told you about <a href="http://www.thedarkvisitor.com/2008/06/vampires-chinese-hackers-treachery-and-smoking-hacker-babelets-face-it-this-post-has-it-all/">Chinese Vampire</a> and later the next month about the <a href="http://www.thedarkvisitor.com/2008/07/chinese-hacker-soap-opera/">big controvery</a> surrounding the original author.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.thedarkvisitor.com%2F2009%2F02%2Fcharging-bull-and-chinese-vampire%2F&amp;linkname=Charging%20Bull%20and%20Chinese%20Vampire"><img src="http://www.thedarkvisitor.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/02/charging-bull-and-chinese-vampire/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Chinese body art 人体艺术</title>
		<link>http://www.thedarkvisitor.com/2009/01/chinese-body-art-%e4%ba%ba%e4%bd%93%e8%89%ba%e6%9c%af/</link>
		<comments>http://www.thedarkvisitor.com/2009/01/chinese-body-art-%e4%ba%ba%e4%bd%93%e8%89%ba%e6%9c%af/#comments</comments>
		<pubDate>Tue, 27 Jan 2009 11:14:49 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Censorship]]></category>
		<category><![CDATA[China internet]]></category>
		<category><![CDATA[Hacker Hunting]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=1169</guid>
		<description><![CDATA[On 18 January, we gave you a look at how to spot hot trends in China and the possibility that Chinese hackers were using similar tools to find targets for malware.  Getting the most bang for your buck.  Today, I&#8217;ve decided to see if my knowledge is worth anything.
Prediction: &#8220;Chinese body art&#8221; sites and body [...]]]></description>
			<content:encoded><![CDATA[<p>On 18 January, we gave you a look at how to spot <a href="http://www.thedarkvisitor.com/2009/01/chinese-hackers-and-hot-trends/">hot trends in China</a> and the possibility that Chinese hackers were using similar tools to find targets for malware.  Getting the most bang for your buck.  Today, I&#8217;ve decided to see if my knowledge is worth anything.</p>
<p>Prediction: &#8220;Chinese body art&#8221; sites and body art pictures (人体艺术照片) will be high on the list for hackers.  Why?</p>
<p style="text-align: center;"><a rel="attachment wp-att-1170" href="http://www.thedarkvisitor.com/2009/01/chinese-body-art-%e4%ba%ba%e4%bd%93%e8%89%ba%e6%9c%af/insight/"></a></p>
<p style="text-align: center;"><a rel="attachment wp-att-1996" href="http://www.thedarkvisitor.com/2009/01/chinese-body-art-%e4%ba%ba%e4%bd%93%e8%89%ba%e6%9c%af/insight-2/"><img class="aligncenter size-full wp-image-1996" title="insight" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/01/insight.JPG" alt="insight" width="357" height="349" /></a></p>
<p>According to Google Insight, there has been a 2400% increase in the number of searches for this term over the last seven days.</p>
<p><a rel="attachment wp-att-1171" href="http://www.thedarkvisitor.com/2009/01/chinese-body-art-%e4%ba%ba%e4%bd%93%e8%89%ba%e6%9c%af/baidurenben/"></a></p>
<p style="text-align: center;"><a rel="attachment wp-att-1997" href="http://www.thedarkvisitor.com/2009/01/chinese-body-art-%e4%ba%ba%e4%bd%93%e8%89%ba%e6%9c%af/baidurenben-2/"><img class="aligncenter size-full wp-image-1997" title="baidurenben" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/01/baidurenben.JPG" alt="baidurenben" width="438" height="163" /></a></p>
<p>It is also showing up in the #19 spot as hot searches on Top Baidu.  What is Chinese body art?  Shhh, it&#8217;s pron.  Artsy pron.  Let&#8217;s see, China announces crackdown on pron&#8230;now this &#8220;art&#8221; makes the top searches on Google and Baidu.  Hmmm?</p>
<p>Going back to <a href="http://www.google.com/insights/search/#q=%E4%BA%BA%E4%BD%93%E8%89%BA%E6%9C%AF%E7%85%A7%E7%89%87&amp;geo=CN&amp;date=today%201-m&amp;cmpt=q">Google Insight</a>, you can get your tags for search engine optimization over the past 30 days:</p>
<p>1. 艺术照片</p>
<p>2. 人体艺术</p>
<p>3. 人体</p>
<p>4. 人体艺术图片</p>
<p>5.  人体写真</p>
<p>Really want to get fancy and you could add cities:</p>
<p style="text-align: center;"><a rel="attachment wp-att-1999" href="http://www.thedarkvisitor.com/2009/01/chinese-body-art-%e4%ba%ba%e4%bd%93%e8%89%ba%e6%9c%af/insight2-2/"><img class="aligncenter size-thumbnail wp-image-1999" title="insight2" src="http://www.thedarkvisitor.com/wp-content/uploads/2009/01/insight2-150x150.jpg" alt="insight2" width="150" height="150" /></a><a href="http://www.thedarkvisitor.com/wp-content/uploads/2009/01/insight2.jpg"></a></p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.thedarkvisitor.com%2F2009%2F01%2Fchinese-body-art-%25e4%25ba%25ba%25e4%25bd%2593%25e8%2589%25ba%25e6%259c%25af%2F&amp;linkname=Chinese%20body%20art%20%E4%BA%BA%E4%BD%93%E8%89%BA%E6%9C%AF"><img src="http://www.thedarkvisitor.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2009/01/chinese-body-art-%e4%ba%ba%e4%bd%93%e8%89%ba%e6%9c%af/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Chinese hackers will do anything for your WoW password (updated)</title>
		<link>http://www.thedarkvisitor.com/2008/11/chinese-hackers-will-do-anything-for-your-wow-password/</link>
		<comments>http://www.thedarkvisitor.com/2008/11/chinese-hackers-will-do-anything-for-your-wow-password/#comments</comments>
		<pubDate>Mon, 10 Nov 2008 16:19:38 +0000</pubDate>
		<dc:creator>jumper</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[all your wow-gold are belong to us]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[World of Warcraft]]></category>
		<category><![CDATA[wow]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=709</guid>
		<description><![CDATA[So the Analyt&#8217;s Diary blog at viruslist.com has an article on some new mass SQL injection attack that jacks up .asp pages with redirects to browser exploits.  The exploits drop one of two trojans that steal passwords and whatnot.  Here is h.js:
document.write(&#8220;&#8221;);
document.write(&#8220;&#8221;);
Wordpress won&#8217;t display the script.  Basically, it loads an iframe that [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 260px"><img title="Trojan Horse" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/02/250px-trojanhorsemythimage.jpg" alt="Trojan Horse" width="250" height="166" /><p class="wp-caption-text">Trojan Horse</p></div>
<p>So the Analyt&#8217;s Diary blog at viruslist.com has an <a href="http://www.viruslist.com/en/weblog?weblogid=208187604">article</a> on some new mass SQL injection attack that jacks up .asp pages with redirects to browser exploits.  The exploits drop one of two trojans that steal passwords and whatnot.  Here is h.js:</p>
<p><del datetime="2008-11-10T18:10:20+00:00"><em>document.write(&#8220;&#8221;);<br />
document.write(&#8220;&#8221;);</em></del></p>
<p>Wordpress won&#8217;t display the script.  Basically, it loads an iframe that points to two separate URLS (these URLs contain browser exploits so don&#8217;t follow them):</p>
<p>hxxp://vvexe.com/haha/index.html and<br />
hxxp://www.kenya.com/faq.htm<br />
<del datetime="2008-11-11T02:44:42+00:00"><br />
I can&#8217;t seem to get to either of these sites at the moment.  I&#8217;ll try again later.</del></p>
<p><strong>Update:  </strong>I spent some time looking at this malware.  The two pages listed earlier in this post contain iframes to browser plug-in exploits for real player and other typical vulnerabilities.  The exploits attempt to load and run down.exe (e160f590d894a98474697ac0db987746 not packed/delphi code) which in turn downloads hxxp://www.vvexe.com/haha/down.txt to get the additional files 1.exe (a7fc8c966fdeb550fe19aba3169569be not packed/VC++), do.exe (5af5edaa2cebf1fed56ad36799b2c850 ) and cool.exe (18867d6de1a3a9241c14c22c19b51351 not packed/delphi).</p>
<p>1.exe is a WoW trojan and waits for passwords sent to:</p>
<p>grunt.wowchina.com and [kr|us|tw|eu].[version|logon].worldofwarcraft.com.  It also looks for and attempts to disable many types of security software.  It attempts to send the stolen credentials to an asp on www.yilu777.com.</p>
<p>do.exe is a little more interesting.  It appears to be a generic remote access trojan that sends a beacon to qq number 58836533.  A quick search for that qq number revealed that this person&#8217;s paipai account has been frozen:</p>
<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/11/paipai.png"><img src="http://www.thedarkvisitor.com/wp-content/uploads/2008/11/paipai.png" alt="http://shop.paipai.com/58836533" title="paipai" class="alignleft size-medium wp-image-724" /></a></p>
<p>So I do some more digging and find the QQ profile with a name and nick:</p>
<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/11/picture-3.png"><img src="http://www.thedarkvisitor.com/wp-content/uploads/2008/11/picture-3.png" alt="" title="QQ_Profile" class="alignnone size-thumbnail wp-image-726" /></a></p>
<p>Searching for the nickname got me to a few blogs and profiles that had some young girl who is really into anime.  Maybe her QQ account got pwn3d or maybe, just maybe she is a member of <a href="http://www.thedarkvisitor.com/2008/05/chinese-female-hacker-group/">&#8220;China Girl Security&#8221;</a>.  I tried to get an add on that QQ account so I could talk to the hacker but didn&#8217;t have any luck.</p>
<p>Note to Chinese hackers:  <a href="http://www.casualgaming.biz/news/27887/China-to-tax-virtual-property">Please pay the tax</a> on your WoW gold profits.</p>
<a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.thedarkvisitor.com%2F2008%2F11%2Fchinese-hackers-will-do-anything-for-your-wow-password%2F&amp;linkname=Chinese%20hackers%20will%20do%20anything%20for%20your%20WoW%20password%20%28updated%29"><img src="http://www.thedarkvisitor.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Bookmark"/></a>]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/11/chinese-hackers-will-do-anything-for-your-wow-password/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
