<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Dark Visitor &#187; money</title>
	<atom:link href="http://www.thedarkvisitor.com/tag/money/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Jun 2011 03:15:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Chinese hackers&#8230;DDoS attack services</title>
		<link>http://www.thedarkvisitor.com/2008/05/chinese-hackersddos-attack-services/</link>
		<comments>http://www.thedarkvisitor.com/2008/05/chinese-hackersddos-attack-services/#comments</comments>
		<pubDate>Wed, 21 May 2008 17:23:03 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacker Hunting]]></category>
		<category><![CDATA[Hacker Organization]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[money]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=565</guid>
		<description><![CDATA[Meet Demon Group, an organization that specializes in providing much needed hacking services&#8230;their fellow citizens would like to see them dead or jailed&#8230;in no particular order or combination. The screen capture above had to be taken from a Google cache because Demon Group&#8217;s website (www.ddosx.cn) seems to have vanished from the interwebs. I have some [...]]]></description>
			<content:encoded><![CDATA[<p>Meet Demon Group, an organization that specializes in providing much needed hacking services&#8230;their fellow citizens would like to see them dead or jailed&#8230;in no particular order or combination.</p>
<p><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon1.jpg"><img class="alignnone size-medium wp-image-566 aligncenter" title="demon1" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon1-300x277.jpg" alt="" width="300" height="277" /></a><br />
The <a href="http://72.14.205.104/search?q=cache:genNCjLmbx4J:www.ddosx.cn/+ddosx+qq:81991&amp;hl=en&amp;ct=clnk&amp;cd=3&amp;gl=us">screen capture</a> above had to be taken from a Google cache because Demon Group&#8217;s website (www.ddosx.cn) seems to have vanished from the interwebs.  I have some theories on why it disappeared, which I will share later.</p>
<p>First noticed the group when I found one of <a href="http://tieba.baidu.com/f?kw=%D6%D0%B9%FA%BA%DA%BF%CD">their advertisements</a> on Baidu Postings (Large Chinese BBS):</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon2.jpg"><img class="alignnone size-medium wp-image-567 aligncenter" title="demon2" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon2-300x118.jpg" alt="" width="300" height="118" /></a></p>
<p>The group claims to provide various types of <a href="http://tieba.baidu.com/f?kz=383575417">DDoS attack services</a> on internet cafes, websites, private servers, servers&#8230;etc.  They sell attack software packages and rent out specialized tools to gather up infected computers (Guaranteed to gather up no fewer than 600-900 in a single day).  The contact number provided is QQ:81991.</p>
<p style="text-align: center;"><strong>Demon Group Spams</strong></p>
<p>Demon group, you spam your services&#8230;you spam them a lot!  <a href="http://www.google.com/search?hl=en&amp;q=%E6%8F%90%E4%BE%9B%E5%90%84%E7%A7%8DDDOS%E6%94%BB%E5%87%BB%E4%B8%9A%E5%8A%A1QQ81991&amp;btnG=Search">You spam them too much</a>!  Now you have ticked off a guy named Good Good, he would like to see you go to jail, he has reported you to the <strong>INTERNET POLICE</strong>!</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon3.jpg"><img class="alignnone size-medium wp-image-568 aligncenter" title="demon3" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon3-300x208.jpg" alt="" width="300" height="208" /></a></p>
<p><span id="more-285"></span><br />
Internet Police Officer Cha Cha has responded to the <a href="http://jmjl.tjwj.gov.cn/redirect.php?tid=165&amp;goto=lastpost">complaint</a> and says she will be paying close attention -cough- :</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon4.jpg"><img class="alignnone size-full wp-image-569 aligncenter" title="demon4" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon4.jpg" alt="" width="401" height="231" /></a></p>
<p style="text-align: center;">
<p style="text-align: center;"><strong>Demon Group Spams and Lacks Common Sense</strong></p>
<p style="text-align: left;">In another ill-fated attempt to <a href="http://72.14.205.104/search?q=cache:jLHri62_eM0J:tieba.baidu.com/f%3Fkz%3D376521415+ddosx.cn/anrls/article.asp%3Fid%3D136&amp;hl=en&amp;ct=clnk&amp;cd=2&amp;gl=us">promote their website</a>, they appear to have decided to get a viral story started that someone had predicted the Sichuan earthquake two months earlier.  Of course, they linked the story back to a webpage on their own site and continued to repeat the story for over 300 posts.</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon5.jpg"><img class="alignnone size-full wp-image-570 aligncenter" title="demon5" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon5.jpg" alt="" width="369" height="760" /></a></p>
<p style="text-align: left;">These postings were of course interspersed with predictable <strong>DEATH THREATS </strong>and <strong>WARNINGS</strong> if they didn&#8217;t stop!</p>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon6.jpg"><img class="alignnone size-full wp-image-571 aligncenter" title="demon6" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon6.jpg" alt="" width="357" height="95" /></a></p>
<blockquote>
<p style="text-align: left;">Die, once again you are deceiving people, how is it you weren&#8217;t buried under a collapsed building in Wenchuan!!!!</p>
</blockquote>
<p style="text-align: center;"><a href="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon7.jpg"><img class="alignnone size-full wp-image-572 aligncenter" title="demon7" src="http://www.thedarkvisitor.com/wp-content/uploads/2008/05/demon7.jpg" alt="" width="357" height="97" /></a></p>
<blockquote><p>Careful in this time of crisis, it is against the law to fabricate a rumor.</p></blockquote>
<p>Yeah, by this point in the story, my theory on why their website has now disappeared from the face of the Earth is pretty much unnecessary.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/05/chinese-hackersddos-attack-services/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Horton hears a (Chinese hacker) Hu</title>
		<link>http://www.thedarkvisitor.com/2008/03/horton-hears-a-chinese-hacker-hu/</link>
		<comments>http://www.thedarkvisitor.com/2008/03/horton-hears-a-chinese-hacker-hu/#comments</comments>
		<pubDate>Wed, 05 Mar 2008 05:25:02 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hackers Talking]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[economy]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[money]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=386</guid>
		<description><![CDATA[Yeah, sorry about the title&#8230; This story comes via the news.china.com and is an inteview with a Chinese hacker named Hu.  The good news is that it is one of the most candid interviews I have ever read. The bad news is that it is very long and has a lot of technical language that I constantly struggle with.  So, it will be at least a three-part [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center"><img src="http://www.thedarkvisitor.com/wp-content/uploads/2008/03/hortonhu.JPG" alt="hortonhu.JPG" /></p>
<p>Yeah, sorry about the title&#8230;</p>
<p>This story comes via the news.china.com and is an <a href="http://news.china.com/zh_cn/social/1007/20080215/14672115.html">inteview with a Chinese hacker named Hu</a>.  The good news is that it is one of the most candid interviews I have ever read.  The bad news is that it is very long and has a lot of technical language that I constantly struggle with.  So, it will be at least a three-part post (if not more) and will be heavily edited in some places. I also may call on one or two of you to lend a hand in coming up with the exact technical jargon.  Our hacker Hu gives a very detailed look inside the economy of the underground world of Chinese hackers.</p>
<p>The article begins with a story about a Miss Liu, who returns home, turns on her computer and as she is skimming through webpages, a Word document suddenly opens.  At the top of the document, it begins to automatically write, &#8220;I have seen your picture, you are certainly very pretty!&#8221;</p>
<p>Due to her job at a large website portal, she immediately realizes this as a Trojan sequence and shuts off the power to the computer.  (Miss Liu) &#8220;I didn&#8217;t expect that my computer could be hit by the Gray Pigeon (Trojan) and turned into a meat chicken (肉鸡).  If I hadn&#8217;t turned off the computer, the hacker would still be controlling my computer and would also be able to send out data packets giving away all my computers secrets.</p>
<p>The term Rouji (肉鸡), Meat Chicken, I believe is slang for a compromised/infected computer. (a little help!)</p>
<p>It is reported that Gray Pigeon is one of the most virulent viruses in the last several years.  The <em>2007 China Computer Virus Epidemic Network Security Report</em> classified it as the 3rd largest virus.   After infection, the computer can be completely controlled through long-distance attack.  The hacker can easily copy, delete or download documents on the computer.  Through long-distance attack (the hacker) can also record every keystroke, the users QQ number and online game user information.  Furthermore, after infection, the computer that the hacker has invaded is called meat chicken.</p>
<p>In fact, in China, there are several million users just like Miss Liu who are unaware that they are contributing to the strength of this network underground industrial chain.   According to statistics from the Kingsoft Global Anti-Virus Monitoring Center, in 2007, the nation (China) had over 50 million infected computers; an 18.15 percent increase over the same time last year with 90.56 percent of internet users suffering a virus attack.  Among those, over 5 million of the infected computers were in Guangdong.</p>
<p>End Part I&#8230;tomorrow we will actually get into the interview with hacker Hu.<br />
<a href="http://www.thedarkvisitor.com/2008/03/hortonhearshackerparttwo/"></a></p>
<p><a href="http://www.thedarkvisitor.com/2008/03/hortonhearshackerparttwo/">Horton hears a (Chinese hacker) Hu…Part II</a><br />
<a href="http://www.thedarkvisitor.com/2008/03/horton-hears-a-chinese-hacker-hupart-iii/">Horton hears a (Chinese hacker) Hu&#8230;Part III</a><a href="http://www.thedarkvisitor.com/2008/03/horton-hears-a-chinese-hacker-hupart-iii/"></a><br />
<a href="http://www.thedarkvisitor.com/2008/03/hortonfour/">Horton hears a (Chinese hacker) Hu&#8230;Part IV</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/03/horton-hears-a-chinese-hacker-hu/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Next Winner of the Pennsylvania Lottery&#8230;Chinese Hacker</title>
		<link>http://www.thedarkvisitor.com/2008/01/next-winner-of-the-pennsylvania-lotterychinese-hacker/</link>
		<comments>http://www.thedarkvisitor.com/2008/01/next-winner-of-the-pennsylvania-lotterychinese-hacker/#comments</comments>
		<pubDate>Sun, 06 Jan 2008 16:03:26 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Nationalism]]></category>
		<category><![CDATA[US attacks]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[money]]></category>
		<category><![CDATA[political]]></category>
		<category><![CDATA[US attack]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=240</guid>
		<description><![CDATA[WTOPnews.com is reporting that Chinese hackers have forced the Pennsylvania government&#8217;s website to shut down. Hackers broke into the pages of the departments of Labor and Industry, Education, and Military and Veterans Affairs, as well as the Pennsylvania Lottery, said Mia DeVane said, a spokeswoman for the Office of Administration. Political or monetary motivation?  Or, [...]]]></description>
			<content:encoded><![CDATA[<p>WTOPnews.com is reporting that Chinese hackers have forced the Pennsylvania government&#8217;s website to shut down.</p>
<blockquote><p>Hackers broke into the pages of the departments of Labor and Industry, Education, and Military and Veterans Affairs, as well as the Pennsylvania Lottery, said Mia DeVane said, a spokeswoman for the Office of Administration.</p></blockquote>
<p>Political or monetary motivation?  Or, just a wonderful combination? <a HREF="http://www.wtop.com/?nid=104&amp;sid=1320993">Penssylvania&#8217;s government is going off the air, read their parting words</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2008/01/next-winner-of-the-pennsylvania-lotterychinese-hacker/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Underground Economy of the Chinese Web</title>
		<link>http://www.thedarkvisitor.com/2007/12/the-underground-economy-of-the-chinese-web/</link>
		<comments>http://www.thedarkvisitor.com/2007/12/the-underground-economy-of-the-chinese-web/#comments</comments>
		<pubDate>Wed, 05 Dec 2007 23:07:11 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Chinese Malware]]></category>
		<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[economy]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[money]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=172</guid>
		<description><![CDATA[Over at Honeyblog.org, Thorsten Holz has a great post detailing the underground economy of the Chinese web. It explains the different &#8220;professions&#8221; and how they interact with each other to produce income. I feel this is an extremely important part of the Chinese hacker network (even though the article isn&#8217;t confined to that) and is [...]]]></description>
			<content:encoded><![CDATA[<p>Over at Honeyblog.org, Thorsten Holz has a great post detailing the underground economy of the Chinese web.  It explains the different &#8220;professions&#8221; and how they interact with each other to produce income.  I feel this is an extremely important part of the Chinese hacker network (even though the article isn&#8217;t confined to that) and is at least a partial explanation of how it fuels itself.  <a href="http://honeyblog.org/junkyard/reports/www-china-TR.pdf" title="Chinese Web Underground Economy">The Underground Economy of the Chinese Web</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2007/12/the-underground-economy-of-the-chinese-web/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Feel Really Good About Your CAPTCHA Security&#8230;Don&#8217;t!</title>
		<link>http://www.thedarkvisitor.com/2007/11/feel-really-good-about-your-captcha-securitydont/</link>
		<comments>http://www.thedarkvisitor.com/2007/11/feel-really-good-about-your-captcha-securitydont/#comments</comments>
		<pubDate>Sat, 24 Nov 2007 00:05:32 +0000</pubDate>
		<dc:creator>Heike</dc:creator>
				<category><![CDATA[Hacking for money]]></category>
		<category><![CDATA[Captcha]]></category>
		<category><![CDATA[Chinese hackers]]></category>
		<category><![CDATA[money]]></category>

		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=123</guid>
		<description><![CDATA[Hat-tip again to Jumper! Jeff Atwood, at Coding Horror, has an excellent post on CAPTCHA tech and how it is implemented. He includes a section on a Chinese hacker who has posted a price list based on the probability of breaking different encoding. Well worth the read here.]]></description>
			<content:encoded><![CDATA[<p>Hat-tip again to Jumper!</p>
<p>Jeff Atwood, at Coding Horror, has an excellent post on CAPTCHA tech and how it is implemented.  He includes a section on a Chinese hacker who has posted a price list based on the probability of breaking different encoding.   Well worth the read <a href="http://www.codinghorror.com/blog/archives/001001.html">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thedarkvisitor.com/2007/11/feel-really-good-about-your-captcha-securitydont/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

