Search for notes by fellow students, in your own course and all over the country.

Browse our notes for titles which look like what you need, you can preview any of the notes via a sample of the contents. After you're happy these are the notes you're after simply pop them into your shopping cart.

My Basket

You have nothing in your shopping cart yet.

Title: this is class report
Description: this is very good for understanding

Document Preview

Extracts from the notes are below, to see the PDF you'll receive please use the links above


All Your Cards Are Belong To Us:
Understanding Online Carding Forums

arXiv:1607
...
CR] 24 Jan 2017

Andreas Haslebacher, Jeremiah Onaolapo, and Gianluca Stringhini
University College London
andreas
...
14@ucl
...
uk
{j
...
stringhini}@cs
...
ac
...
Carding forums,
in particular, are known for being focused on trading nancial
information
...
Existing literature
mainly focuses on the organisation and structure of the forums
...
This paper provides rst-of-its-kind
empirical evidence on active forums where stolen nancial data is
traded
...
We focused our analyses on
products, prices, seller prolicacy, seller specialisation, and seller
reputation, and present a detailed discussion on our ndings
...


I NTRODUCTION

£479 million of fraud losses on UK issued credit and
debit cards were recorded in 2014 [1]
...
” This category
of fraud denotes that card details obtained through illicit
methods such as phishing, skimming or hacking are used for
fraudulent online transactions
...

Theft of card information is usually the rst step in the
chain of credit card fraud
...
These deals and activities
take place in a massive underground economy, usually aided
by underground online forums
...
On these forums, fraudsters typically open a thread and write an advertisement for their
products as a rst posting
...

The sales volumes thus generated appear to be substantial
...
It is therefore important to understand
the characteristics of these online forums and the activity of
cybercriminals using them
...
In particular, there are only a few studies
available about credit card related forums
...
In addition, existing studies are usually based on either
expert interviews or examinations of forums that have been
shut down by law enforcement agents
...
The examination of closed forums may be
problematic since they may differ from those still existing,
especially when this difference is the reason why they are
closed
...

In this paper, we collected data directly from the discussions on the underground forums that we studied, with
emphasis on product offers and advertisements posted by
potential sellers on the forums
...
As a result, we excluded buyers and money mules
from this study (we will study them in future work)
...
In order to overcome the literature gaps
and methodological concerns we highlighted earlier, this paper
aims to shed light on the current situation of underground
online forums by analysing real data collected from active
forums
...
After studying existing research literature, we
dened the following hypotheses to guide our analyses:


Hypothesis 1 (H1 )
...




Hypothesis 2 (H2 )
...




Hypothesis 3 (H3 )
...




Hypothesis 4 (H4 )
...




Hypothesis 5 (H5 )
...




Hypothesis 6 (H6 )
...


Our analyses conrmed H1 , H2 and H6
...
Details
of the analyses are in Section IV
...
In this paper, we established an outline of
active forums and their dening features
...
This investigation thus provides insights into current underground online forums, unlike previous
work that studied forums that were shut down
...
Overall, we present a comprehensive
overview of carding forums
...
Our ndings suggest that a small
number of traders are responsible for the majority of the trafc
observed on the underground forums
...

II
...
In addition, we
develop some hypotheses from the general ndings presented
in existing literature
...

A
...
In 2011,
Motoyama et al
...

Stone-Gross et al
...
Onaolapo et al
...

Credit card information is generally divided into three
groups: credit card numbers, dumps, and fullz [10]
...
Dumps
denote information from the tracks on the magnetic stripe of
a card
...

Fullz provide further information on the cardholder including,
for example, date of birth or social security number [10]
...
Only two years later, credit card

numbers were available for $0
...
Shulman [11] mentions
three reasons that account for this decline: CVVs are becoming
a commodity, monetizing information is more difcult and
credit cards are beset by stolen online credentials
...
50-$20 for CVVs
...

Sood and Enbody [13] provide a more detailed estimation
of rates charged per credit card number
...
Classied according to credit card types, a classic
or standard credit card number from the USA or Canada costs
$8-$10, a gold card $15-$20 and an Amex $6-$10
...
Nevertheless, they are still more expensive than
the lower limits of their quoted price range ($4/$5)
...

Reasons for price differences include the types of cards
and countries of origin, as already mentioned, in addition to
the rarity and the quantity of the products to be purchased [14]
...
Furthermore, cards with more personal information
available, with high balances and extended expiration dates
and freshly acquired cards tend to be more expensive [6]
...
Existing literature does not
state reliable prices for dumps or fullz
...

For dumps, no hypothesis can be formulated derived from existing research literature
...
However, once
copied and successfully used to conduct a transaction, such a
clone might be a lucrative means of payment
...
g
...

B
...
These roles are not mutually exclusive; sellers
may simultaneously be buyers
...
[6] argue that,
based on expert interviews and literature review, the total
number of participants on the forums is likely to rise
...
At least from a historic
perspective, Christin [15] conrmed this growth of participants
on underground platforms as he observed a linear increase
of sellers during his half-year analysis of Silk Road, a large
underground marketplace
...

In terms of geographic location, forum users come from
all over the world
...
These geographic
patterns, however, vary depending on the types of forums and
the services provided
...

Examinations in relation to sales quantity reveal substantial
differences in seller prolicacy
...
[18] identied
an “insider ring” composed of several top sellers
...
One common characteristic is
that they joined the community very early and are frequent
visitors to the pages
...
It is unclear, however, whether they leave
the community after having made sales or due to unsuccessful
attempts
...
[7] analysed
the records of 6 closed forums and concluded that 10% of
the sellers are responsible for 40%-50% of the goods traded
...
Their
conclusion is based on counting of advertisements of sellers on
one underground forum
...
Moreover, the
analysis of several forums instead of one might have produced
more reliable results
...
That implies a
small group accounts for more offenses than its expected share
would be
...
We hypothesise
(H2 ) that on active carding forums, a small number of traders
are responsible for a large proportion of trafc
...
Seller specialisation
Looking at the products sold per seller, several studies
found evidence of specialisation amongst sellers
...
[21], for example, promote an ecosystem perspective to
understand the actions of underground traders
...
They try to reach this advantage by
specialising in a particular type of product [21]
...
While one
third of sellers offered various products, two thirds focused
on only one product category
...
In recent years, Symantec has observed an increasing
professionalisation in all aspects in the underground economy
...
Sood and
Enbody [13] also identied specialisation as a trend in underground markets
...
Hence,
there is a division of labour due to differing skills
...

These ndings indicate that specialisation is present in the
underground ecosystem as in the legitimate business world
...

What does that mean in terms of product prices? We did not
nd any association between specialisation and product prices
in existing literature
...
This efciency enables an
increase in production compared to unspecialised suppliers
...

Applying this to traders on carding forums, we expect costand price-reducing effects when sellers specialise in trading
of a single product category (due to the economies of scale)
...

D
...
A reputable seller is more likely to be trusted
and thus more likely to engage in trades and to complete
transactions
...
Buyers may rate their sellers
by giving positive ratings if the ordered products have been
successfully delivered, and negative ratings if the seller has
not delivered and was rather a ripper
...

However, the effort to establish baseline reputation appears
to be laborious
...
In this case, the reputation process is intrinsically
peer-driven
...
Sometimes, forum administrators provide a vetting
process, often in addition to the peer-driven process and often
with intransparent criteria
...

The emphasis on reputation and trust means that it is indispensable for competitive forums to have a well-functioning
reputation system
...
Since trades on carding forums
depend on relationships between mutually distrustful parties,
we argue that trust is even more important than in legitimate
trades
...
We thus hypothesise (H5 ) that
the carding forums to be analysed have working reputation
systems that are at least as sophisticated as those of legal
marketplaces, for instance eBay
...

As discussed, the efforts needed for gaining trust are
extensive
...
It is therefore not expected that sellers are present on
multiple forums
...
[7] expectation of non-existing multiple accounts
...
[6] who argue without
providing any reasons that sellers would advertise on multiple
marketplaces
...

III
...

We collected names of underground forums from various
sources, and selected 5 forums that matched our selection
criteria for examination
...

A
...

We took the following steps to nd carding forums: First,
we collected names of forums that were mentioned by
research literature
...
Third, we used other search engines and information pages, namely Onion
...
org and “The Hidden Wiki
...
In the latter case, we adopted the method of
snowball sampling [24]
...

By this means, we found 25 forums, 15 of them via
Google
...
The forum names
mentioned in existing literature research were of little use
since all the mentioned forums had already been shut down
...
Although numerous forums
were listed, most of them did not exist anymore
...

Notwithstanding, the carding underworld seems to be dynamic
...

Besides forums, we discovered more than two dozen stores
(e
...
Globalcards and Dexter, offering mainly credit card
numbers)
...

They do not gather multiple sellers, they have no reputation
systems, and users normally do not communicate with each
other
...


Forum name
Agoraforum
Altenen
Crdpro
Crimenetwork
Cardingforum
Hackingforum
Unixorder
Crdclub
Carderscave
Infraud
Lampeduza
Blackstuff
Bus1Nezz
Cardingmaa
Bpcsquad
Procarder
Cardersforum
Crimes
Carderbase
Carder
Darkstuff
Coinodeal
Tuxedocrew
Privatemarket
Omerta

Forum address (http://
...
onion/
www
...
com
crdpro
...
onion
www
...
org
hackingforum
...
unixorder
...
ws
www
...
ru
infraud
...
so
www
...
net/forum
...
biz
www
...
ws
www
...
com
www
...
ru
www
...
se/
crimes
...
su
carder
...
darkstuff
...
com
www
...
biz
privatemarket
...
cm

TABLE I: Names and web addresses of discovered forums
...


To narrow down the analyses, we chose ve out of the
25 forums (see Table II) for detailed examination: Altenen,
Crdpro, Crimenetwork, Bpcsquad, and Tuxedocrew
...
We
excluded Agoraforum despite possessing the greatest number
of posts, because 99% of its posts are requests for referral
links for registration on Agora Marketplace
...
Thus, it is not entirely new and it might
provide interesting insights when its content is compared to
that of larger forums
...
It is remarkable to note that it
is the largest one of the very new forums
...
These criteria should ensure a good mix
...

B
...
This means that
a snapshot was made by the end of June and data of the
previous three months was collected
...

This limitation to three months meant that no full activityrecord could be recorded
...
However, we argue that the current situation is of
interest and not the past, and that three months are still more
advantageous than shorter periods
...
Admittedly,

a longer period would be benecial for the smaller forums
...

C
...
For the selected forums, threads where potential sellers
advertise their products were collected
...
No activity
records, copies of databases or web crawler services were
available
...
For instance, we did not analyse private messages used
to arrange and complete trades
...

Where necessary and possible, we set up login credentials to
gain wider access to the forums
...
Ads that were created before the
three-month observation period were not collected
...
Therefore, we captured older
threads in cases where an activity in the form of answer
postings or vouchings during the three months was registered
...
Indeed, it was
crucial to consider such older threads since it was expected that
long-established insider rings existed on the forums, as pointed
out by Farooqi et al
...

The threads usually describe the advertised products and
their prices
...

Calculating the mean value may distort the picture presuming
that, for example, if only one high-priced gold card is offered
in addition to many low-priced standard cards
...

To keep the focus on carding, we limited the spectrum
of investigation to typical nancial cybercrime related data:
credit card numbers (CVVs), dumps, fullz, PayPal-credentials
and Western Union (WU) payment transfers
...

In order to operationalise “trafc” on the forums, as necessary for hypothesis H2 , D´ecary-H´etu and Lepp¨anen [19]
counted advertisements as indicators
...
” Vouchings
are evident signs that successful transactions have been made
...
Conversely, there might be rippers vouching for each
other without having made any transaction
...
[18] and Christin [15] also relied on vouchings and
member feedbacks, using them to calculate revenues, counting
vouchings seems to be an appropriate method
...
These pages display complete lists of all threads and posts written by the corresponding users
...
The denition of specialisation is
relatively strict
...
Only very narrowly related categories, for instance
credit card numbers and fullz, were treated as identical product
categories in this respect
...
We carried out searches
for users throughout the selected forums, and compared their
identity details
...
These details were collected from the postings and the users’ prole pages
...
Depending on the forum,
these are the FAQs, specially installed forum threads, terms and
conditions or customer information sites
...

In total, we collected 388 threads
...
5 individual products (e
...
CVV USA Classic)
...

Forum
Altenen
Crdpro
Crimenetwork
Bpcsquad
Tuxedocrew

Threads
206
57
96
25
4

Individual products
431
270
136
130
20

TABLE II: Threads and individual products per forum

D
...
We analysed the content we collected both qualitatively and quantitatively
...

To prepare the data for analysis, a categorisation of thread
content was necessary
...
We stuck to clear coding
rules in order to avoid subjective and inconsistent categorisations
...
g
...
However,
these categories were somewhat too coarse and further subcategories had to be created (e
...
“CVV” or “dumps”)
...
Yet,
it is important to ensure that the categories do not become
too small and thus render subsequent quantitative calculations
impossible
...
Since the aim of
the categorisation is to obtain meaningful product categories,
we avoided such ne distinctions
...
g
...
Visa and Mastercard details were
not explicitly differentiated since they are usually treated
interchangeably by the traders
...
At rst, we ran general frequency calculations
...
For H3 , the frequencies of the
specialised users were compared to the unspecialised ones
...

Since their price distributions resembled Poisson rather than
a normal distribution, we performed Mann-Whitney-U tests
to test whether there were signicant differences between
the values
...
To assess the degree
of sophistication in relation to legitimate marketplaces, we
compared them to eBay’s system
...
However, we
found no suitable legitimate large-scale forum set up to enable
trading
...
Finally,
in order to examine whether sellers operated on more than one
forum (H6 ), we reproduced and interpreted the proportions of
multiple representations across all forums
...
Therefore, the
results (Section IV) are reported in aggregated form, and
where applicable, and if enough cases are available, for every
individual forum
...


DATA A NALYSIS

In this section, we describe our analyses of the ve selected
forums, and our ndings
...
Overview
We discovered 25 forums, out of which we selected ve
forums for analyses
...
The attributes are name,
members, total posts, accessibility, languages, and founding
date
...
The names and full website addresses of the discovered
forums are listed in Table I
...
com,
...
so
(Somalia)
...

Members
...
A comparison between the rst search in February 2015 and the
second in June 2015 revealed some substantial increases in
members
...
4% increment), and Cardingmaa grew
from 98,700 to 121,500 members (23
...
Altenen,
already a large forum in February, was more than twice as large
four months later (from 60,700 to 148,800 members, 145
...


It is not clear how many of the members on each forum
were actually contributing
...
On Altenen, these were 38,300 of its 148,800 members
(25
...
7%)
...

Total posts
...
Besides advertisements, the posts comprised
mainly answers to advertisements or contributions to discussions
...
” In line with the
increase in number of members, the number of posts also
increased between the two searches (e
...
Cardingmaa from
31,900 to 37,600 posts, 17
...
On Altenen, the
number of posts doubled (from 607,100 to 1,265,500 posts,
108
...

Accessibility
...
This means
that everybody could access them for free or even without
registration
...
Access to these
areas usually required a recommendation or an invitation by
other members
...

Languages
...
Some forums contained international
sections in various languages
...

Founding date
...
These are not necessarily the
founding dates as older posts might have been deleted in the
meantime
...
g
...
We estimated founding dates between 2008 and
2014
...

In terms of size, the median number of members was
28,850, while the median number of posts was 58,150
...
1 (Privatemarket) and 18
...
There are thus forums where only a fraction
of the members post messages and there are some where
members post numerous messages on average
...

B
...

Products and prices
...

CVVs are further divided by product type
...
PayPal
credentials are advertised for $3
...
As hypothesised (H1 ), prices for fullz
are higher than those for credit card numbers (CVV: mean =
10
...
00; fullz: mean = 31
...
00)
...
86, p < 0
...

Products
CVVs
Classic
Gold
Amex
others
unspecied
Dumps
Fullz
PayPal
WU ($100)
Total

Number
465
98
14
66
16
271
234
140
133
15
987

Proportion (%)
47
...
9
1
...
7
1
...
5
23
...
2
13
...
5
100
...
08
9
...
86
12
...
00
9
...
52
31
...
01
15
...

Examined per individual forum, prices of CVVs do not
vary substantially, those for the other products show considerable variation
...
On Altenen, for example, dumps
have a share of 8% of the products analysed
...
Yet the absolute numbers are partly very
low and the values may thus lack reliability
...
Since
the absolute numbers are too low to display these values
for each forum, Table IV shows them summarised across all
forums
...
There is indeed substantial variation between
different product types and countries
...
US products are the cheapest, while European products
tend to be more expensive
...
The products are not sold evenly throughout
all sellers on the forums
...
This user
joined Altenen in summer 2014 and sells CVVs of various
countries
...
Altenen has the
most unequal distribution
...
Bpcsquad and

CVV

Australia
Canada
UK
USA

Dumps

Canada
EU
USA

Classic
Amex
Classic
Amex
Classic
Amex
Classic
Classic
Gold
Classic
Gold
Classic
Gold

Number
12
10
14
10
17
25
31
14
12
20
20
29
27

Price ($)
12
...
20
10
...
10
11
...
02
5
...
43
45
...
75
58
...
17
30
...


Tuxedocrew have too few vouchings to calculate a Lorenz
curve
...
Crdpro
does not diverge from these distributions
...
Although Crdpro has 17 times as
many users as Bpcsquad, for example, it produced only twice
as many advertising threads during the time of observation
...
Furthermore, there have been
no new entries in the two VIP areas since 2013 and the forum
appeared to have been disconnected during some summer
months in 2013
...
As far as reputation is concerned,
the high-prole sellers have usually high reputation ratings
...
However, we could not conrm the presence of an
insider ring, as proposed by Farooqi et al
...
Overall, only
ve out of the twenty most prolic users registered in the
founding year of the according forum
...

However, it is possible that some sellers have more than one
account and have thus several “joining-dates
...

Seller specialisation
...

Regarding Crdpro, Bpcsquad and Tuxedocrew, the hypothesis would be true
...
This pattern is exactly the opposite of
Crimenetwork’s
...

The results for H3 raise the question about differences between specialised and unspecialised sellers
...
Regarding Altenen, for example, seven out of the twenty users with the
most vouchings are specialised
...

In terms of prices per product, there are some differences
...
However, only the
price difference for dumps is statistically signicant at the
95% condence level (Mann-Whitney-U = 1643, z = -4
...
01)
...

That said, it is delicate to summarise product types because every type and country has its own price
...
Hence,
we made such a price comparison for US Classic CVVs, the

(a) All forums
...


Fig
...


(a) Crdpro forum
...


Fig
...


most prevalent product type
...
63, n
...


delivery [27]
...


A striking aspect that Table VI reveals is the distribution
of advertised product categories among specialised and unspecialised users
...
5% of all products)
...
4%) that specialised users advertise
...
A user’s “reputation power” consists of
the number of positive minus the number of negative feedback
points
...
In
addition, users are allowed to rate threads
...
In case of
non-delivery, buyers receive their money back out of this fund
...
In using that
service, a buyer pays the money plus a transaction fee of $5$30 to Altenen
...


Seller reputation
...
The reputation systems are as
follows:
eBay: Buyers on eBay can leave feedback for a seller after
a purchase and transaction ends
...
” Positive feedback gives one point, neutral
feedback does not change the score, and negative feedback
subtracts one point [26]
...
However, the system was disabled during our
observation
...
1
41
73
...
0
15
60
...
0
147
38
...
9
15
26
...
0
10
40
...
0
239
61
...


CVV
Dumps
Fullz
Paypal
Total

Number
166
193
45
21
425

Specialised users
Proportion (%)
39
...
4
10
...
9
100
...
28
32
...
86
1
...
7
10
...
5
42
...
4
30
...
5
3
...
0

TABLE VI: Number, proportion, and price of product categories per specialised and unspecialised users
...
An
escrow service was not provided
...
Members may “like”
other members
...
Crimenetwork’s escrow service is
comparable to Altenen’s
...

Bpcsquad: As seen with Altenen and Crdpro, members
may rate other members on Bpcsquad by giving positive,
neutral or negative feedback
...
Furthermore, there is a thread rating
possibility
...

Tuxedocrew: Tuxedocrew’s reputation system differed from
those seen so far
...
Instead, the forum
administrator could award users with special titles
...
Tuxedocrew also offered an escrow service and
charged a 15% fee
...
However, it had an amateurish touch,
especially the $50 buyer protection reserve which is not able to
cover substantial amounts
...
H5 is thus
rejected
...
Finally, we examined
whether users were present on several forums
...

In total, only six sellers were found trading on more than one
forum, namely two on Altenen and Crdpro, two on Altenen
and Bpcsquad, and two on Bpcsquad and Crdpro
...
Hypothesis 6 is thus conrmed;
concentration on a single forum was expected
...


D ISCUSSION

In this section, we summarise our ndings on the carding
forums that we studied
...
Finally, we highlight limitations
of the study
...
The prices sought for the products
offered on the forums lie within the range given by the
reviewed literature
...
This may be due to the effort needed to gain
or monetise the data, the amount of information available, the
higher rewarding potential, and differing demand and supply
...
In contrast, CVVs are wellrepresented on the forums and thus seem to be available in
abundance, which might push prices downwards
...
Taking into account the large proportion of
CVVs on the investigated forums, trading credit card numbers
is presumably still a lucrative business
...
Western Union money transfer services play only a
marginal role on most of the forums
...

Even though some users complete hundreds of transactions,
most users do not sell anything at all
...
This domination by a few traders
implies that the forums are not typical forums characterised
by mutual exchanging and participating users
...

Referring back to the methodology part, counting of vouchings instead of ads, the latter [19] was probably more suitable
to determine criminal performance
...
Counting of
ads would have overlooked that
...
Specialisation was observed mostly on

Crdpro
...
Dumps constitute almost half of the products
sold by specialised users on Crdpro
...
Unlike CVVs or
credentials, the acquisition of dumps requires a connection to
the physical world
...
As a result, it might be costlier
for unspecialised users to acquire dumps, thus forcing them
to sell dumps at higher prices, which would conrm Smith’s
economic theory [23]
...
It could be
argued that if they are apt or have valuable data sources, they
know and distribute other types of illicit products and services
...
These users, though,
might as well be rippers
...

Overall, it is possible that the scope of analysis regarding
specialisation was too narrow
...
Another reason might be that carding
is not as complicated as other cybercrimes like DDoS-attacks
or large-scale spam campaigns
...
Therefore, it makes more sense to
be specialised in those domains
...
It might
thus be true that the effort needed to reach a certain reputation
level deters users from establishing themselves on multiple
forums, as Motoyama et al
...
This effort could
also be the reason why most users do not have any ratings at
all, as the analysis showed
...
Regarding users with high
reputation and many vouchings, it is highly unlikely to nd
any rippers among them
...

It is interesting to note that an expert interviewed by Ablon et
al
...

In general, and if not stated otherwise, all our ndings
apply to all ve examined forums
...
Sales on Crimenetwork are not distributed as
extremely unevenly as on other forums, neither are there
numerous specialised users present
...
Crimenetwork is thus more forum-like in terms of
mutual exchange and participation than the other forums
...

In addition, the forum gives the impression of being wellmaintained
...
g
...

Crdpro is the obvious opposite
...
It appears to be in decline
...
It might be a question of time until the entire
forum will be closed
...
However, the number
of vouchings are low and it is thus questionable how fruitful
the business really is
...
A
reason for the small size of this forum might be the high
charges for the escrow service or, even more likely, the lack
of a user-based reputation system
...
This
might be too little to build trust among the users and to boost
trade
...
Bpcsquad is relatively small and the low
number of ratings may denote unsuccessful deals
...

In contrast, the enormous increase in members on Altenen
is impressive
...
Forums with numerous users usually have
diverse products, and a multitude of potential buyers, that
is, high supply and demand
...
Altenen provides an
additional, arguably pseudo-protection measure
...
We encountered a number of limitations during
the study, and they are mentioned in this section
...

After all, due to the technique of considering the vouchings
of this time period, older and often very protable ads were
included in the analysis
...
That is, no private messages
could be studied
...
Thus, the ndings of this study do not give
a complete picture of the forums
...
The third limitation concerns the internal validity
of the data
...
This might
bias the data
...

Another threat to internal validity is the recorded product
prices
...
No post was found where the
possibility of price negotiations was mentioned
...

Finally, given that the examined forums trade different
goods or attract certain types of users, the ndings are an
artefact of the forums in question and do not represent the
entire carding underworld
...
The selection of the forums is
thus a threat to external validity
...
In principle, this limitation was
overcome by selecting ve different forums based on various
selection criteria
...
Sellers were focus of this study
...
The
reviewed literature did not cover buyers and they were also
neglected in this paper
...

Regarding research design and methodology, a long-term or
a follow-up study might be able to identify trends or conrm
the patterns found in this study, respectively
...
This method would
allow researchers to collect more information on traders and
gain better understanding of their roles within the fraud chain
...


[11]
[12]
[13]

[14]
[15]

[16]

[17]

VI
...
What
differentiates this study from others is, rst, we investigated
real data instead of drawing conclusions based solely on existing literature or expert opinion, second, we examined active
forums instead of closed forums, and third, we applied a lowlevel focus on products, prices and sellers
...
However, it
is not clear how promising the future of carding forums is,
especially with the emergence of single-vendor stores which
could imply that high-prole sellers would leave existing
carding forums to open their own single-vendor stores
...
F
...
UK, “Fraud The Facts 2015,” http://www
...

org
...
asp, 2015, [Online: Accessed 23February-2016]
...
Gold, “Identity crisis?” Engineering Technology, vol
...
10, pp
...

L
...
Corradin, and F
...

S
...
Garg, D
...
Greenstadt, “Honor among thieves:
A common’s analysis of cybercrime economies,” in eCrime Researchers
Summit (eCRS), 2013
...
1–11
...
Yip, N
...
Webber, “Why forums?: an empirical
analysis into the facilitating factors of carding forums,” in Proceedings
of the 5th Annual ACM Web Science Conference
...

453–462
...
Ablon, M
...
Libicki, and A
...
Golay, Markets for Cybercrime
Tools and Stolen Data: Hackers’ Bazaar
...

M
...
McCoy, K
...
Savage, and G
...
Voelker,
“An analysis of underground forums,” in Proceedings of the 2011 ACM
SIGCOMM conference on Internet measurement conference
...
71–80
...
Stone-Gross, T
...
Stringhini, and G
...

J
...
Mariconti, and G
...

T
...
Holt and E
...
23, no
...
33–50, 2010
...
Shulman, “The underground credentials market,” Computer Fraud
& Security, vol
...
3, pp
...

S
...
20,” technical
report, Symantec Corporation, Tech
...
, 2015
...
K
...
J
...
6, no
...
28–38,
2013
...
Hutchings and T
...
Holt, “A crime script analysis of the online
stolen data market,” British Journal of Criminology, p
...

N
...
International World
Wide Web Conferences Steering Committee, 2013, pp
...

K
...
Christin, “Measuring the longitudinal evolution of the
online anonymous marketplace ecosystem,” in 24th USENIX Security
Symposium (USENIX Security 15), 2015, pp
...

A
...
nbcnews
...

S
...
Ikram, G
...
De Cristofaro, A
...
Jourjon, M
...
Kaafar, M
...
Shaq, and F
...
01637, 2015
...
D´ecary-H´etu and A
...

M
...
L
...
Sage, 2010
...
Kraemer-Mbula, P
...
Rush, “The cybercrime ecosystem:
Online innovation in the shadows?” Technological Forecasting and
Social Change, vol
...
3, pp
...

T
...
Holt, “Exploring the social organisation and structure of stolen
data markets,” Global Crime, vol
...
2-3, pp
...

A
...
Random House, 1937
...
Biernacki and D
...
10, no
...
141–163, 1981
...
Kluge, “Empirisch begr¨undete typenbildung: Zur konstruktion von
typen und typologien in der qualitativen forschung,” Opladen: Leske+
Budrich, 1999
...
ebay
...
uk/help/feedback/
howitworks
...

http://pages
...
co
...

“eBay Seller Protection,” http://portal
...
co
...

B
...
com/2015/02/08/
fullz-dumps-and-cvvs-heres-what-hackers-are-selling-on-the-black-market/,
2015, [Online: Accessed 23-February-2016]
Title: this is class report
Description: this is very good for understanding