[ Team Cymru Community Services ] [ Team Cymru Commercial Services ] [ Dragon Research Group ]
Pentagon Confused by Its Own 'Subs vs. Terrorists' Plan "The Pentagon has a dream that it wont give up: blasting any target on the planet with a submarines missile...." (more) | Twitter Censorship Move Sparks Backlash: Is It Justified? "Internet scorn for Twitters announcement Thursday that it would censor tweets was swift and unforgiving...." (more) | Students busted for hacking computers, changing grades "Three high school juniors have been arrested after they devised a sophisticated hacking scheme to up their grades and make money selling quiz answers to their classmates...." (more) | SEC Goes After Online Trading Firms That Unwittingly Helped Latvian Hacker "In an effort to crack down on hacker/stock traders who hijack brokerage accounts and exploit the stock market for gain, the Securities and Exchange Commission has, in a novel move, gone after four online trading companies and eight executives who they say helped a Latvian hacker make more than $850,000 from fraudulent trades...." (more) | Microsoft's Kelihos botnet suspect says he's innocent "The man pegged by Microsoft as the mastermind behind the Kelihos botnet, says he's not guilty, according to a report...." (more) | Anonymous takes aim over Europe's SOPA "Online activists Anonymous are targeting the European Parliament and supporters of the Anti-Counterfeiting Trade Agreement (ACTA), which critics say would curtail freedom of expression and encourage surveillance by service providers...." (more) | Cyber crime: Beware of ID theft "MUMBAI: Identity theft is one of the growing concerns in cyber crime in India today...." (more) | Hot Issue At The Hawaii Legislature: Cybercrime "Spurred by a dramatic rise in computer-related crimes including possibly affecting one of their own colleagues lawmakers have introduced more than 30 measures in the Hawaii Legislature concerning cybercrime...." (more) | CNP Integrations Presents Tight Cyber Crime Security Integration for Joomla & Drupal "The announcement by CNP Integrations to present a new hosting platform is set to be a complete and one of its kind cyber monitoring solutions...." (more) | Aberdeen Police Department: Fighting cyber criminals "An Airmen stationed at Ellsworth Air Force Base near Rapid City is facing a number of charges Friday after police say he drove more than 300 miles to have sex with a 13-year-old girl he met on the Internet...." (more) | European Parliament rapporteur quits in Acta protest "Negotiations over a controversial anti-piracy agreement have been described as a "masquerade" by a key Euro MP...." (more) | Now You Can Buy Guns on the Online Underground Marketplace "It's been eight months since we exposed Silk Road, the underground online marketplace where you can anonymously buy any drug imaginable...." (more) | Beware of malicious QR codes: Report "Cyber criminals have taken advantage of the proliferation of quick response (QR) codes on posters and marketing material by putting their own malicious stickers over the top of legitimate ones, warns security vendor, AVG Australia and New Zealand...." (more) | Why global action on cybercrime needed "International action to snuff out cybercrime is desperately needed, officials and business leaders say, warning that criminals move at internet speed while countries drag their feet...." (more) | Telstra provides assistance package for Tweed Shire flood victims "Telstra has today released an assistance package for residents and small businesses in and surrounding the flood-affected Tweed Shire region...." (more) | Twitter to censor tweets in specific countries "Twitter now has the ability to censor tweets in specific countries, the social networking service announced on Thursday...." (more) | IN: IU Information Security responds to hacking of President's Challenge website "Last semester the Presidents Challenge website tracked IU [Indiana University] employees nutrition and exercise progress throughout their participation in the Healthy IU fitness competition...." (more) | Nigerian Man Sentenced For Large Credit Card Fraud Scheme "U.S. Attorney Timothy Q. Purdon announced that on January 23, 2012, Adekunle Olufemi Adetiloye, a citizen of Nigeria and resident of Canada, was sentenced by U.S. District Chief Judge Ralph R. Erickson to 17 years and 10 months in federal prison for one of the largest and most complex credit card schemes in North Dakota banking history...." (more) | Update: More than 4,000 vets potentially affected by VA data breach "A Veterans Affairs Department data breach may have put at risk the personal information of more than 4,000 veterans, VA Chief Information Officer Roger Baker said Wednesday...." (more) | CA: SF city worker charged with data theft "A former San Francisco city employee is facing charges that she stole Social Security and other confidential information from more than 3,000 people who applied for Medi-Cal benefits...." (more) | Tide fans ordering from Bamastuff.com may have had credit card information stolen "University of Alabama fans who bought items from Bamastuff...." (more) | NC: Deputies: Windstream employee stole 'numerous' customer accounts in fraud "A Mt. Pleasant man turned himself in this morning after authorities issued warrants for his arrest...." (more) | Univ. of Hawaii settles data breach class action "The University of Hawaii will provide two years of credit protection services to settle a class-action lawsuit involving data breaches involving nearly 100,000 students, faculty, alumni and staff between 2009 and 2011, officials and attorneys announced Thursday...." (more) | NY ID theft scam has victims in 30 states "Two New York women are facing grand larceny and other charges after a prosecutor said they posted phony Craigslist ads for nonexistent jobs and apartments and then used respondents personal information to obtain state income tax refunds, bank loans and credit cards in the victims names...." (more) | CA: Sequoia Hospital vendor posted hospital employee's personal information online "A contractor working for Sequoia Hospital inadvertently posted the personal information of 391 current and former hospital employees on a public website, where it stayed for four years, the hospital said Thursday...." (more) |
hash-identifier: ID different types of hashes used to encrypt data and especially passwords http://t.co/xwV0tS5R | Trend's top 11 bits of APT research last year that didn't make headlines? http://t.co/FdCZ6Yq5 | Dragon Research Group's Weekend Reads:responsible and forced disclosure http://t.co/HavKGqHB | European Parliament's website DDoS'd in retaliation for Megaupload + anti-counterfeiting trade agreement http://t.co/zQAdMc0r | 15 essential open source tools for Windows admins http://t.co/D3c5hTZU | looking at 11.5M African tweets --> nice pic, 68% of African twitters users get their news this way http://t.co/ekJgrxsv | Sophos: Security Threat Report 2012, nothing groundbreaking but solid observations anyway http://t.co/77uRSWQa | #Android Reverse Engineering (A.R.E.) Virtual Machine, install virtualbox + d/l their image #malware http://t.co/ls0ovD0H | Symantec: stop using pcAnywhere, source code WAS stolen in 2006, brought to light by YamaTough's releases http://t.co/XQoM4p8x | Fingerprinting your TV power consumption + MITM attack on your SmartMeter = what you're watching http://t.co/C6zAxDF0 | coming to NANOG54 in San Diego? See our own John Kristoff (twice!) on Sunday Feb 5th http://t.co/QQjaOBdk | "Suspicious Package" free plug-in for OS X: look inside PKG files before it's too late http://t.co/sGifQzHZ | BAH: UK is a bigger 'cyber-power' than anyone else, including USA http://t.co/macKs7kL | TSA: Hackers disrupted railway signals @ Northwest rail company for 2 days in December http://t.co/FiosMGLt | WSJ: hiretohack DOT net will "crack" p/wds in 48 hrs for $150+ http://t.co/82FIdZ8J |
Episode 106: Security Scripting, DDoS Tuning & Animations YouTube RSS Feed Twitter

Recent Data

[ Data Page 1 ] [ Data Page 2 ] [ Data Page 3 ] [ Data Page 4 ] [ Data Page 5 ]

Top 10 UDP Ports (logarithmic scale)

This chart shows the top 10 UDP ports seen in sampled global Internet traffic in our most recent hourly data sample. This chart is on a logarithmic scale, so the difference between the top port (usually UDP/53) and the bottom port may be more significant than it appears to the naked eye.

View all available monitoring graphs

Sampled DNS Request Rate (daily)

Our insight into Internet traffic around the globe allows us to sample and estimate trends in Domain Name System (DNS) requests, one of the key pieces of Internet infrastructure. This chart provides a glimpse into that sampled rate over the past 30 days, aggregated daily, for both TCP and UDP DNS requests (though the TCP request rate is so low it is difficult to discern).

View all available monitoring graphs

Average Daily Botnet Traffic

This chart shows the average amount of traffic we see to each botnet command and control (C&C) server we are monitoring daily. This is the actual bandwidth consumed by the bots as they check in with the controller and receive commands. This data is based on a sampled view of traffic, and shouldn't be treated as hard numbers, but can give you an idea of the rates of usage involved in running a botnet.

View all available monitoring graphs

Underground Economy Activity

This chart shows a very general sampled indicator of the average number of messages per hour seen each day in various underground economy forums for the past 30 days. The numbers should not be taken as absolutes, and have considerable sampling error, but are believed to be a reasonable indicator of overall trends.

View all available monitoring graphs

Internet Malicious Activity Maps

Internet Malicious Activity Hilbert Map The map to the left shows network locations of malicious activity on the Internet within the past 30 days, plotted using a Hilbert curve. Check out our Internet Malicious Activity Maps page for full details and a larger view of this and other maps.

Recent Releases

Our contribution to Operation Ghost Click

[17 NOV 2011] On 09 November 2011, US law enforcement released details of a major series of arrests as part of Operation Ghost Click. Team Cymru is proud to have been able to add details of victim computers that were part of this criminal infrastructure into one of our daily feeds of data that is provided at no cost to providers around the world. These lists of affected IP addresses enable network managers to identify and remediate computers infected by malware that are taking part in criminal activities.

This has a direct impact on people: it disrupts criminals and improves the lives of legitimate Internet users everywhere; we're honored to have been able to contribute to this effort. Our great thanks to all who contributed to this team effort.

Details of the case and our commentary can be found in this darkreading.com article. Images of the data we provided to our partners can be found via Twitter here and here.


Unexpected and unsubstantiated blog post

[25 OCT 2011] A recent blog post appeared to draw the unsubstantiated conclusion that more than 760 organizations were compromised with some of the same resources used to hit RSA earlier this year. Team Cymru was one of the organizations named in the posting.

We have no evidence of compromise related to incidents at RSA or anywhere else. The source of the report, and those who revealed and posted it, didn't take the time to contact us, or to share incident details with us. Thus we are unable to investigate further. We hope that those who gathered this data will responsibly disclose it to the potential victims.

Please note that without more details on the methodology used to determine the list of organizations, and a scientific review of the same, it's not safe to assume that an entry on the list means either "victim" or "false positive". We've seen no data or methodology description that would support either case.


New Underground Insight: A Criminal Perspective on Exploit Packs

[05 MAY 2011] The Team Cymru Business Intelligence Team is pleased to announce the release of their latest paper, entitled "A Criminal Perspective on Exploit Packs". This paper chronicles the genesis and historical eveolution of the Browser Exploit Pack (BEP). We discuss our research into the installation and usage of 40 different packs. Most notably, the paper discusses dishonor among coding thieves and the entrenched practice of "statistics shaving". Finally, we examine the monetization, code protection, and overall effectiveness of the various packs. For full details, check out the whitepaper, and don't forget to look at the rest of our whitepapers as well!


Team Cymru moving to Florida

[04 MAY 2011] Team Cymru today announced that they are relocating their headquarters staff from Chicago, Illinois, to Central Florida over the summer. The majority of our Chicago staff will move and are excited at the prospect of continuing to use our insight to improve lives, but from a significantly warmer location.

We do not forsee any disruption to our community or commercial feeds and services during this transition and we will continue to update our partners with news as appropriate. If you have any questions or concerns in the meantime, please e-mail outreach@cymru.com and we will be happy to discuss them with you!


View older news items in our news archives.

Friends of Team Cymru  
  CSIRT-MU Dyn, Inc. F-Secure FIRST  
  GoDaddy.com Interoute Communications REN-ISAC Savvis Communications  
  Support Intelligence Tata Communications Verizon Business  
 

Team Cymru Community Services