I just wanted to break the silence to make a brief post about a skid I found who goes by the name of Daily, aka Nick Moses.
Skidforums profile: http://www.hackforums.net/member.php?action=profile&uid=99678
He's apparently been one of the biggest 4chan malware spreaders, constantly spamming up all the boards with links to shitty Java drivebys and such. He's been doing this for years now, but he's ramped up his skid efforts in the past two months.
A few examples:
He's even been getting into the hearts of weeaboos and redirecting them to Java drivebys (with some code he copied and pasted from 1 of 2,000 security blogs).
He also is apparently somewhat of a 4channer himself. Here's him attentionwhoring in an old moot sticky:
Just Google any of his domains, which I'm going to list towards the bottom, and you'll see tons and tons of 4chan hits. This is only a tiny sampling.
Seems he's mostly been spreading Blackshades lately, developed and sold by the fine gentlemen in the below blog post. After a few "issues" he's started only spreading DarkComet instead. But anyway, onto the fun stuff.
First, I found his Blackshades panel install, and graciously liberated him of his bots and logs to save him some money on bandwidth and hard drive space.
|About 250 bots were uninstalled by the time it finished|
I also found some kind of stolen password storage panel on his website mosesmusic.net. It's tied to some shitty VB password stealer.
I continued to be of assistance, and helped him free up a few megs (or however much it takes to store 16,000 passwords).
|Password stealer panel|
I went one step further and performed a "citizen's revokal" of all his domains, by order of acclaimed domain authority Meatspin Inc.
|utilities.3utilities.com (used for RAT connections)|
|Logged into his Namecheap account|
|An order he made|
|Giving 220.127.116.11 some much needed traffic|
I've got some more shit but I won't bore you with the details. I currently have all his domains, though he's trying to recover them and probably trying to register some new ones. When that happens I will be in talks with Namecheap.
Go hog wild.
Daily - Nick Moses http://www.hackforums.net/member.php?action=profile&uid=99678 Nicholas (Nick) Moses Age: 21 16 Water St Orleans, VT 05860-1306 United States (802) 754-1050 Parents' address (possibly old; above address may be their current one): Jay Moses (Father) & Wanda Moses (Mother) 3258 Glen Rd Newport, VT 05855-9043 United States (802) 334-4522 Went to Champlain College in Vermont: http://www.champlain.edu College dorm/apartment address as of 2010: Nick Moses Mailbox #663 Champlain College P.O Box 670 Burlington, VT 05402 Associated IP Addresses: 18.104.22.168 - Used for malware hosting and bitcoins, appears residential, probably current home IP. Being used right now as DarkComet C&C. (ISP: Charter) 22.214.171.124 - Home IP, probably old (ISP: Charter) 126.96.36.199 - Previously hosted nickmoses.net 188.8.131.52 - Previously hosted mosesmusic.net 184.108.40.206 [utilities.3utilities.com] - VPS of some sort, used as a proxy (Provider: GigeNET) 220.127.116.11 [artemishost.no-ip.biz] - Another VPS, some malware he spreads connects back here; also has some recorded bitcoin transactions (Provider: GigeNET) 18.104.22.168 [apocalypsefree.in] - DarkComet hosting 22.214.171.124 [apocalypsefree.in] - DarkComet hosting 126.96.36.199 - no-ip.org DarkComet 188.8.131.52 - no-ip.org DarkComet 184.108.40.206 - no-ip.org DarkComet Emails: firstname.lastname@example.org email@example.com firstname.lastname@example.org email@example.com firstname.lastname@example.org MSN: email@example.com AIM: dailydaily500 Skype: itsnickmoses XBL: Daily500 Facebook: https://www.facebook.com/nickmoses Archived Facebook info: http://profileengine.com/people/nickmoses/nick.moses Google+: https://plus.google.com/104296121370055224470/ Myspace: http://www.myspace.com/coolmoses Photobucket: http://s576.photobucket.com/profile/daily500 Formspring: http://www.formspring.me/itsnickmoses Steam: http://steamcommunity.com/id/itsmemoses Xfire: http://beta.xfire.com/profile/dailydaily500/ DeviantArt (lol): http://daily500.deviantart.com Ebay: http://myworld.ebay.com/dailydaily500/ Chess.com: http://www.chess.com/members/view/daily500 Runescape Username: dailymage Profiles owned by him presumably used for stalking or deception, possibly hacked accounts: https://www.facebook.com/beth.davis.7712 http://www.myspace.com/242729140 http://www.myspace.com/330598988 http://www.bebo.com/PleaseSignIn.jsp?Page=c/profile&MemberId=1863201824 All usernames: nickmoses itsnickmoses itsmemoses Daily daily500 dailydaily500 dailymage Domains: apocalypsefree.in doomzco.com slackforum.com nickmoses.net mosesmusic.net dudeitscool.net dudeitshosting.net pagemake.org (Java drivebys) teengirlslive.us (used for spreading Java drivebys, Google it and you'll see tons of 4chan threads) teencamlive.net (spreading) teencamzlive.us (spreading) photos-at-90.org (expired)
|Nick Moses, hacker extraordinnaire|
|what I don't even|