Showing posts with label Chinese Hacker. Show all posts
Showing posts with label Chinese Hacker. Show all posts

Chinese hackers…DDoS attack services

Meet Demon Group, an organization that specializes in providing much needed hacking services…their fellow citizens would like to see them dead or jailed…in no particular order or combination.


The screen capture above had to be taken from a Google cache because Demon Group’s website (www.ddosx.cn) seems to have vanished from the interwebs. I have some theories on why it disappeared, which I will share later.

First noticed the group when I found one of their advertisements on Baidu Postings (Large Chinese BBS):

The group claims to provide various types of DDoS attack services on internet cafes, websites, private servers, servers…etc. They sell attack software packages and rent out specialized tools to gather up infected computers (Guaranteed to gather up no fewer than 600-900 in a single day). The contact number provided is QQ:81991.

Demon Group Spams

Demon group, you spam your services…you spam them a lot! You spam them too much! Now you have ticked off a guy named Good Good, he would like to see you go to jail, he has reported you to the INTERNET POLICE!


Internet Police Officer Cha Cha has responded to the complaint and says

[Source: Thedarkvisitor]

Chinese hacker soap opera

On the 21st of June, we told you about SKSgod selling a trojan downloader called “Chinese Hacker Vampire” and the online controversy that ensued when another hacker took credit for it. The end? No, fresh drama has been introduced into this saga.

Author of Chinese Hacker Vampire Program JAILED!

On 4 July, News.cn reported that an 18-year-old hacker surnamed Zhou had been arrested in connection with selling the trojan downloader program. Police from Chongqing City launched an investigation into the case after receiving a phone call from an anonymous source who reported that there was a website selling the Chinese Hacker Vampire downloader. According to the report, Zhou’s website even threatened to shutdown the anti-virus software industry.

On July 1st, Chongqing police captured Zhou while still asleep in his apartment and he later made a full confession to the crime. The end? No.

Silly police, you can’t arrest a vampire

Decided to visit SKSgod’s website and see when he last posted and surprise…it was 5 July. Wait, wasn’t he jailed on July 1st? Nope. SKSgod is just having a real run of bad luck with people stealing his program and identity.

On 5 July, he posts an apology to all the people who lost money purchasing the Chinese Vampire downloader and promised to use his energy to create a better program. One person in the comments section suggested that his time and energy could be put to better use. So, that was funny.

On 4 July, when the story was breaking about the arrest, he posted three separate articles dealing with the rumor. All three postings had the same theme, complaining about how all this news was hurting his reputation.

Is he at all concerned about the poor schmuck shown getting arrested? Nope, this is all about him and his online creds. The end? Who knows.

[Source: Thedarkvisitor]


Chinese hacker instructional video of the Gray Pigeon trojan



One of the clearest instructional videos I have seen on how to use the Gray Pigeon trojan horse. I haven’t tried to translate the video but thought it might be of interest to some of our more technically inclinded audience. The first part describes how to use the program and the second part shows how the information is collected from an infected computer.

[Source:
Thedarkvisitor]

Chinese hacker Withered Rose returns




UPDATE: Dominic reminds me that some people might not be as Chinese hacker obsessed as myself and suggests I give some links as to why Withered Rose is important. Whoops on my part! For some background on rose, read here and here.

As mentioned yesterday and updated today, Withered Rose (Tan Dailin) is back to his old haunts; both mghacker.com and ncph.net websites are up and running again. Just a couple of observations:

1) Rose has done some scrubbing of his personal blog mghacker.com. Had to go to the wayback machine to make sure but you can tell a number of posts have been deleted for some reason by comparing the wayback machine to what is listed on the current blog’s archive. Rose has wiped out everything prior to March of 2007 and selectively edited the months still showing.

2) Not sure why but at least four of the new post on ncph.net are old posts from the mghacker.com blog:

a.

Mghacker 再现社会工程学 (29 Mar 2007)
Ncph 再现社会工程学 (31 May 2008)

[Source: Thedarkvisitor]

b.

Mghacker 3389密码的嗅探 (29 Mar 2007)

Ncph 3389密码的嗅探 (11 May 2008)

c.

Mghacker Rainbow Table 分析 (10 Apr 2007)

Ncph Rainbow Table 分析 (11 May 2008)

d.

Mghacker 获取cuteftp中的ssh密码 (16 May 2007)

Ncph 获取cuteftp中的ssh密码 (11 May 2008)

3) Whois data shows that NCPH.net administrative contact as:

Administrative Contact:
ncph studio
ncph studio ()
si chuan li gong xue yuan
zigong, Sichuan, cn 643000
P: +86.13154663992 F: +86.13154663992

Sichuan Ligong Xueyuan is the Sichuan University of Science and Engineering. Rose founded NCPH while a student at the university. A Chinese hacker going by the name of Rodag, who was also a member of NCPH lists the university as a contact on his blog.

The contact number 86.13154663992, was noted by Jumper in an IRC log:

# jumperon 08 Dec 2007 at 11:04 pm edit this

In the second picture of Rose, he is using a tool called Metasploit on his computer. http://www.metasploit.com.

IDefense has a lot of stuff on NCPH and Rose. There are a couple of archived webcast videos about them on idefense’ website. I did a bunch of searching and found this funny tidbit:

21:41 gila poyo
21:41 you computer is hack by chinese’s hack infall, shit!
21:41 from http://www.chinahonker.com my name is tan dailin
21:41 contact us with QQ 5372453 or
21:41 tel:86+0+13154663992
21:41 my blog :www.mghacker.com or http://www.ncph.net
21:41 ~~~~~~~~~~~~~~~~~~~~~~~~~shit! you are a pig !
21:41 i found this in some machine
21:41 haha
21:41 YOUR COMPUTER IS HACK

It is from an archived IRC log. There isn’t any more context to go off of so I’m not sure who is who in this. Gila poyo is malay but I don’t know what it means.

My guess is the at the two of them are old college buddies.

4) What does this random sampling of information mean? Not much. Just wanted people to be aware that Mr. Rose is back in business and on the internet.

Chinese hackers target Sharon Stone

The first calls are starting to make the rounds on Chinese hacker sites to attack the Sharon Stone website. The actress recently started a firestorm in China after she gave an interview suggesting that the earthquake in Sichuan was the result of bad karma. I guessed it would be just a matter of time before Chinese hackers targeted her online and have been monitoring the boards.

One site has posted a bit of initial reconnaissance of the website:

There was also a post asking to have the unofficial website of Sharon Stone hacked:

Tried going to the website for a contact address but found the, “This site may harm your computer” posting. Maybe Jumper will have the time to check it out later.


[Source: Thedarkvisitor]

Chinese International E-Sports Festival website hacked out of existence

From what I can gather, this is the second year of the International E-Sports Festival, co-sponsored by China and South Korea. This year’s competition will be held in Wuhan, China on 10 Oct 2008. The screen shot above was posted at ief.com.cn/, which is billed as the official Chinese website of the 2008 International E-Sports Festival. The site now looks like this:

A little background on the games:

Planning for IEF was started in 2003 at the express request of China’s central government with the aim of providing positive, culturally appropriate Internet alternatives for Chinese youth. The government decided to pursue these objectives through the China Youth League, one of the most influential organizations in China. Many of China’s leaders, including President Hu, come from its ranks.

In November 2003, ‘e-sports’ was added as China’s ninety-ninth official sport by the Sports Bureau of the PRC’s Central Committee in order to add further importance to the objectives of the IEF. The organizing committee was formed to develop and implement initiatives to respond to the CPC’s constructive vision. Since then, the Committee has successfully developed and staged numerous very popular events under the banner of the IEF.

In January 2007 President Hu Jintao noted the success of IEF and issued policies designed to ensure the continuing development of culturally appropriate content and inculcating within China’s Internet community a culture of positive and innovative attitudes. In April 2007, the Central People’s Committee Political Bureau reinforced this policy by emphasizing the importance of developing a social-network model of Internet use by China’s youth.

Cont…

Several reports coming out of China are suggesting the attack was carried out because South Korean committee organizers cancelled a promise to open a Japanese area.  Furthermore, the hacker appeared to be…wait for it… Japanese.  Yeah, the “Turkish hacker Firtina Bozo was here..!!” seems to have been lost on them.  That one Hotmail address with a .jp tag must have blinded them to all other things contained in the message.

Just for fun I decided to see if there were other hacks by Firtina Bozo and let me tell you that is one busy individual.

[Source: Thedarkvisitor]

China detains web site defacer spreading earthquake rumors

June 19th, 2008

The Xinhua news agency is reporting that the web site defacer which I mentioned in a previous post regarding the use ofChina hacker detained web site defacements as tools for psychological operations, has been located and detained in less than a week after he defaced the Seismic Emergency and Public Center of the Guangxi province where he left a fake message on an upcoming earthquake that’s going to hit China.

Tracking him down and releasing detention clips to the Chinese media is one of these emblematic cyber crime cases the Chinese Cyber Police would do anything to solve. Would they also be allocating the same resources to another incident if it wasn’t the momentum and the boldness of this hacker to do what he did in times when China’s shaken by earthquakes?

Xinhua has more details :

“Chen, 19, worked in a technology company after graduating from junior middle school. He said he hacked the site to show off his computer skills and have “fun,” according to the police.

The administration website was found to have been hacked on May 31. A notice mourning the victims of the 8.0-magnitude quake had been revised to read: “Please prepare for an earthquake with a magnitude of more than 9.0 in Guangxi,” Tang said

The news scroll, meanwhile, had been replaced with a single phrase: “Experts warn of earthquake in Guangxi in the near future,” he said. “

There are three types of web site defacers, the average ones basically greeting their team members without deleting anything, the commercial ones, that would monetize their defacement by selling the access to the web server to spammers and malware authors, and the stupid ones, who would deface the Seismic Emergency and Public Center  of the Guangxi province in times when China’s shaken by earthquakes and leave a note on yet another one coming.

What is this case demonstrating us anyway? That when there’s a will, there’s always a way. Most importantly, that when you cannot stop being the number one hosting provider of malware, and malware command and control interfaces in the world, you pick up a single bee out of the beehive and slap it with a newspaper in front of everyone.

[Source: Zdnet]