Thursday, September 30, 2010

New York FBI: 17 Wanted Zeus Criminals

The New York FBI needs your help. Today they announced indictments against thirty-seven cybercriminals involved with Zeus. Ten of these were arrested previously in the recent past. Ten more were arrested today. The other seventeen are "At Large".

I'll let you read for yourself the charges against the many criminals by visiting the FBI's New York Field Office announcement:

FBI New York Press Release

A wanted poster, showing the seventeen "At Large" criminals is available here:

Seventeen Zeus Criminals Wanted by FBI

If you find clues about any of these people make sure to get them to your local FBI office! (Send us a copy too! gar at cis dot uab dot edu)

Wanted: Ilya Karasev



Known aliases: Goran Dobric, Alexis Herris, Fransoise Lewenstadd, Fortune Binot, Diman Karasev

Status: J-1 Visa issued May 2008. Converted to F-1 Visa in December 2008. Terminated January 11, 2010

Actions:

April 13, 2010 - presented a Belgium passport in the name of Fransoise Lewenstadd to a TD Bank branch to open an account.

April 19, 2010 - presented a Greek passport in the name of "Alexis Herris" to open a TD Bank account.

June 2, 2010 - received $4200 stolen funds into the TD Bank Herris Account. Withdrew $4,000 from a TD Bank branch in Ocean Township, NJ.

July 1, 2010 - presented a foreign passport in the name "Fortune Binot" to open a TD Bank account in Brooklyn, New York

May 3, 2010 - "Herris" opened a Bank of America account. Received $12,300 in unauthorized wire transfer to that account.

May 20, 2010 - "Herris" withdrew $9,000 from Neptune, NJ branch. Made two debit card purchases totaling $3581.40 at a convenience store in Jersey City, NJ. (That's a lot of Doritos!!!)

Several more items are known with BOA withdraws from Little Silver, Little Eatontown, and Red Bank, New Jersey from a Bank of America "Fortune Binot" account.

There was also JP Morgan Chase activity.

Open Source Intelligence:

Facebook Profile

An Ilya Karasev, with many friends in New Jersey, has a Facebook account. In this picture from the account, he looks to be the same person as pictured above.



Other photos on his site include Ilya riding a bus, standing in front of Applebee's Time Square in New York. Ilya attended Volgograd State Technical University, class of 2005, where he majored in "Motor Transport."



Wanted: Dmitry Saprunov




Known Aliases: Lean Marc Garrot, Bazil Kozloff, Milorad Petrovic

Status: Entered the United States on May 19, 2009 on a visa.

A cooperating subject says that Saprunov lives as roommates with fellow co-conspirator Nikolai "Robert" Garifulin in an apartment in Brooklyn, New York. Subject says they recently accessed a safety deposit box, probably at Wachovia Bank. Gariflun recently traveled to Russia to "pay the hackers" carrying $150,000 cash concealed in his luggage.

Actions:

June 4, 2010 - Saprunov opens a TD Bank account in Manhattan using a foreign passport in the name of "Bazil Kozloff".

June 7, 2010 - Saprunov uses the Kozloff identity to open a Bank of America account in Bronx, New York.

June 11, 2010 - Saprunov opens a TD Bank account in Brooklyn using a passport from Belgium in the name of "Lean Marc Garrot".

June 12, 2010 - Saprunov opens a BOA account in Long Island, New York using the Garrot identity.

June 29, 2010 - $14,000 is wired to the Kozloff BOA account.

July 6, 2010 - just under $14000 is wired to the Garrot BOA Account.

July 6, 2010 - "Garrot" withdraws $13,9450 in four transactions from a teller and three ATM machines in Bradley Beach, New Jersey

Open Source Intelligence:

Facebook Profile:


(from the Facebook album "AVE" (Possibly Avenue New York Club?) by Sergey Palychev.
Also pictured: Alejandro Martinez, Elizaveta Osadchikh, Anastasia Yudintseva, Natalya Vassilyeva



(Interesting note: Ildar Mukhamedov is a friend of both Saprunov and Karasev on facebook, and they are friends of each others.)

Watcha Got?



More will be added as time allows. If you have something you'd like to share, send it in!

Go Go, Maltego!!


Wanted: Lilian Adam



Known Aliases:

Wanted: Marina Oprea



Known Aliases:

Wanted: Kristina Izvekova



Known Aliases:

Wanted: Sofya Dikova



Known Aliases:


Wanted: Artem Tsygankov



Known Aliases:

Wanted: Catalina Cortac



Known Aliases:

Wanted: Ion Volosciuc



Known Aliases:




Testimony from State Department DSS Agent



Wanted: Artem Semenov



Known Aliases: Valentin Kulakov, Alexey Michinnik, Arvind Shah, Fred Teschemacher, Tokin Waaran, David Warren

Entered the country June 1, 2009 on a J1 Visa, stating that he was a full-time student at Kazan State University of Technology.

Arrested December 17, 2009 by NYPD at a Manhattan branch of Bank of America, trying to open an account in the name of Nicholas Congleton. Arraigned on December 18th. Failed to appear in court on February 22, 2010.

On January 15, 2010, Customs agents intercepted a package from the Republic of Moldova destined for Artem shipping new passports to him. The passports were from the Federal Republic of Yugoslavia and were issued in the names of Petar Stojanovic and Victor Rajkov.

A collaborating witness testified that Artem recruited Almira and Julia (below) to work for him. The CW says that the two were provided with tickets to fly from New York City to Las Vegas on August 25, 2010.


Wanted: Almira Rakhmatulina



Known Aliases: Natalia Davidova, Irina Sergeeva

On June 6, 2010 Almira entered the country traveling on a J1 Student Visa stating that she was a full-time student at Omsk State University.

On July 16, 2010, Almira opened a TD Bank account in the name of Natalia Davidova using a Greek passport in that name. On July 17th, the same passport was used to open a Wachovia Bank account in New York City.

On July 20, 2010, Almira opened a TD Bank account in the name of Irina Sergeeva, using the same Brooklyn street address that she used with the Natalia Davidova account. A Greek passport for the Sergeeva alias was used as proof of identity.

A balance check of that account was made using an ATM in Las Vegas, Nevada on September 17, 2010.


Wanted: Julia Shpirko



Known Aliases: Ekaterina Kaloeva, Ekaterina Smirnova


On June 6, 2010, Shpirko entered the country traveling on a J1 Student Visa stating that she was a full-time student at Omsk State University.

On or about July 20, 2010, Shpirko opened a TD Bank account was opened in Manhattan in the name of Ekaterina Smirnova.




Wanted: Yulia Klepikova



Known Aliases:

Wanted: Maxim Panferov



Known Aliases:

Wanted: Nikolai Garafulin



Known Aliases:

Wanted: Dorin Codreanu



Known Aliases: Savvas Paian

On April 21, 2010, Dorin opened a Chase account using a Greek passport in the name Savvas Paian.

On May 11, 2010, the Chase-Paian account received $10,246 from a victim in Illionois.

On May 18, 2010, Dorin opened a TD Bank account using the same identity, but making it a business account in the name "Savvas Import Group LLC".

Open Source Intelligence:

Savvas Import Group, LLC is a "fruit and vegetable" importer, using the address "1612 Kings Highway Apartment 48, Brooklyn, NY 11229-1210", according to Manta.com.
Manta puts their phone number as 347.530.9785 begin_of_the_skype_highlighting              347.530.9785      end_of_the_skype_highlighting

That phone number also belongs to "Brooklyn Fruit Vegetable Growers Shippers" and "Neptune Fruit Vegetable Growers Shippers" which both have the same street address as well.



On June 3, 2010, the

Wanted: Stanislav Rastorguev



Known Aliases:

A Room Within A Room





Una habitación dentro de otra, diseñada por Davidson Rafailidis con sede en Berlín. Es una idea simple que parte de lo que necesitas y así poder ahorrar en el espacio que requiere calefacción o refrigeración mediante el control de la temperatura. Se crea un efecto invernadero gracias al material plástico de burbujas utilizado para cubrir la habitación, sujetado por una estructura de madera que conecta los nodos principales de la puerta y ventana, ocupando el espacio central de calentamiento o enfriamiento. Ver más dentro del post;

English info after the jump;

A room within a room designed by Berlin-based Davidson Rafailidis. The idea is simple: only partition what you need and thus save on space that requires heating or cooling by controlling the temperature only within the occupied portions of the room. A wooden framework supports greenhouse-grade insulating bubble-wrap and connects key nodes such as doors and windows to a core heated or cooled space.








How Ink Is Made





Peter Welfare presidente y jefe de The Printing Ink Company muestra cómo el color y la tinta es creado a partir de las materias primas con polvo, barniz, y pasión. Todo lo que los diseñadores e impresores necesitan saber sobre el proceso, los desafíos y las ganas de hacer la tinta. Ver vídeo dentro del post;

Video and english info after the jump;

Peter Welfare, president and head inkmaker, The Printing Ink Company shows how colour and ink is created from the raw ingredients--powder, varnish, and passion. Everything designers and printers need to know about the process, the challenges and joy of ink making.



Written and produced by Ian Daffern
Directed and Edited by Tate Young

Balancing Barn





"Balancing Barn" está situada en Suffolk, Inglaterra. Es un proyecto llevado acabo por MVDRV de Rotterdam y por la firma británica Mole Architects. La casa tiene 35m de largo se equilibra en el borde de una pendiente, con la mitad del edificio en voladizo, 5 metros es la altura que hay entre el suelo de la casa y el prado de abajo. En el punto más lejano se encuentra una sala de estar con grandes ventanales, una superficie de cristal y una gran claraboya. Tiene un total de 4 dormitorios y está revestida en acero inoxidable reflectante, y el interior forrado con madera contrachapada.
Me encanta la idea y el contraste que hace el acero inoxidable reflectante rodeado de tanta naturaleza. Ver más dentro del post;

English info after the jump;

"Balancing Barn" is situated in Suffolk, England. Is a project realized by MVDRV of Rotterdam and British firm Mole Architects. The 35m long house is balanced on the edge of a slope, with half of the building cantilevered out over a meadow 5m below. At the furthest most point is a living room with large windows and a glazed floor and large rooflight. The 4 bedroom house is clad in reflective stainless steel, and internally lined with plywood.









Warp by Florent di Bartolo



Warp is the last flash animation designed by Florent di Bartolo, I really like the perfect and soft color degradation. Florent is a french artist who lives currently in Annecy. During the last years he has worked on several projects curated by the CiTu a federation of laboratories directed by Maurice Benayoun. He is also writting a thesis about the usages of databases in new media. See also others conceptual animations in his website. See animation below;



Full animation here

Wednesday, September 29, 2010

MiniPost: UK Zeus Criminals Identified

Eleven of those arrested for committing financial cybercrimes using Zeus malware in the UK have now been formally charged and named, according to a story in this morning's Guardian from which I quote:

Eight people have been charged with conspiracy to defraud and money laundering. They are Ukrainian Yuriy Korovalenko, 28, from Chingford, Essex; Ukrainian Yevhen Kulibaba, 32, from Chingford; Latvian Karina Kostromina, 33, from Chingford; Estonian Aleksander Kusner, 27, from Romford, Essex; Ukrainian Roman Zenyk, 29, of Romford; Belorussian Eduard Babaryka, 26, from Romford; Latvian Ivars Poikans, 29, from Harlow, Essex; and Latvian Kaspars Cliematnieks, 24, from Harlow.

Two have been charged with conspiracy to defraud: Ukrainians Milka Valerij, 29, and Iryna Prakochyk, 23, from Chingford.

Georgian Zurab Revazishvili, 34, from Romford, is charged with offences under the Identity Cards Act 2005.

ShapeShift





ShapeShift es un experimento que investiga futuras posibilidades de materialización arquitectónica. Este proyecto explora la posible aplicación de polímeros electro-activo (EPA) en una escala arquitectónica. EAP ofrece una nueva relación con el espacio construido a través de su combinación única de cualidades. Es un material ultra-ligero y flexible, con la capacidad de cambiar de forma sin la necesidad de actuadores mecánicos. ShapeShift une las técnicas avanzadas en el diseño y fabricación arquitectónica y la ciencia de materiales, así como el impulso de la investigación académica sobre aplicaciones en el mundo real. Este proyecto está siendo desarrollado por Computer Aided Architectural Design (ETHZ) y Swiss Federal Laboratories for Materials Science and Technology (EMPA). Ver video y más imágenes dentro del post;

Video and english info after the jump;

ShapeShift is an experiment in future possibilities of architectural materialization. This project explores the potential application of electro-active polymer (EAP) at an architectural scale. EAP offers a new relationship to built space through its unique combination of qualities. It is an ultra-lightweight, flexible material with the ability to change shape without the need for mechanical actuators. ShapeShift bridges gaps between advanced techniques in architectural design/fabrication and material science as well as pushing academic research towards real world applications. The project is being developed by Computer Aided Architectural Design (ETHZ) and the Swiss Federal Laboratories for Materials Science and Technology (EMPA). More info here.









Major Zeus Bust in the UK: Nineteen Zbot Thieves Arrested

The Metropolitan Police are to be congratulated this morning on the largest Zeus arrest to date. News broke on September 28th that the Met's PCeU Police Central e-crime Unit had arrested nineteen criminals in relation to a large Zeus or Zbot trojan network.

The Daily Mail has a set of great pictures of the criminals being taken into custody from their homes in their story, Hi-tech crime police quiz 19 people over internet bank scam that netted hackers up to £20m from British accounts. Police raided the homes simultaneously in the pre-dawn hours on Tuesday. These two pictures are part of five you can find there:





In case you don't travel much, £20 million pounds is a lot of money. That's roughly $31 Million USD. The criminals were stealing "about two million pounds per month". For comparison, the FBI released second quarter bank theft numbers last week. From April 1 to June 31 there were 1135 bank robberies and eleven bank burglaries in the United States, which earned criminals only $8 million USD or £5 million pounds.

In otherwords, this one Zeus gang stole more money in three months than ALL TRADITIONAL BANK ROBBERIES in the United States during the same length of time.

Although many folks haven't heard of the PCeU, their Mission Statement is
To improve the police response to victims of e-crime by developing the capability of the Police Service across England, Wales and Northern Ireland, co-ordinating the law enforcement approach to all types of e-crime, and by providing a national investigative capability for the most serious e-crime incidents.


15 men and 4 women were arrested, ranging in age from 23 to 47 years old. Detective Chief Inspector Terry Wilson of the Metropolitan Police credits the arrest to a Virtual Task Force composed of law enforcement, computer experts, and bank security personnel who worked together to track the movements of the criminals. Sounds a lot like the InfraGard model to me -- a private public partnership anchored on the FBI where computer security experts and personnel working in Critical Infrastructures, such as the Financial Industry, share information to stop criminals and terrorists.

Despite their financial success, the Daily Mail reports that the ringleader, "in his 20s, and his wife, an accomplice in the scam, were arrested in an unremarkable third-floor flat in Chingford, Essex.

Despite this raid, there are still at least 162 "online" Zeus servers that continue to gather stolen credentials from compromised computers, according to the invaluable ZeusTracker service.

We've documented dozens of stories in this blog about Zeus over the past year, and are excited to see this most significant law enforcement action to date.

The clock is ticking . . . who is going to have the best arrest before we all meet up in three weeks?

Tuesday, September 28, 2010

"Ants in my pants" by Edhv





El equipo de diseño con sede en Eindhoven ‘Edhv‘ ha diseñado estas sillas formadas por hormigas. La silla se ha construido mediante el tracking producido al movimiento de las hormigas sobre un modelo a escala. Este equipo que venia haciendo proyectos en 2D con insectos (recomendable ver este proyecto) se aventura en el mundo tridimensional con "Ants in my pants". Esta colección de sillas se presentó en la exhibición Dutch Invertuals en el Salone Del Mobile di Milano. Ver más dentro del post;

English info after the jump;

The Eindhoven-based design team ‘Edhv‘ made these chairs constructed by ants. The chair is actually build up from tracking the movement of ants walking on a scale model.
As a follow-up to our Debug 2D project they ventured into the world of three dimensions. Edhv presented these series of chairs at the Dutch Invertuals exhibition in Milan during Salone Del Mobile. (See more experiments in 2D with ants, here)