<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: codec]]></title>
    <link>http://securityratty.com/tag/codec</link>
    <description></description>
    <pubDate>Thu, 10 Jul 2008 12:59:13 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Eight]]></title>
      <link>http://securityratty.com/article/8679b7cba84c40cf05ac706ffff136e1</link>
      <guid>http://securityratty.com/article/8679b7cba84c40cf05ac706ffff136e1</guid>
      <description><![CDATA[In the spirit of &quot; taking a bite out of cybercrime &quot;, here are the latest fake security software domains, typosquatted and already acquiring traffic through a dozen of malware campaigns redirecting to...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrE3tf04BI/AAAAAAAACQQ/kcG-puPQ2zs/s1600-h/fake_security_software_october.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrE3tf04BI/AAAAAAAACQQ/uqK0Of48ME4/s200-R/fake_security_software_october.PNG" /></a>In the spirit of "<a href="http://bp3.blogger.com/_wICHhTiQmrA/R3WKqj8-MnI/AAAAAAAABSw/9FrQmDwhpb4/s1600-h/mcgruff_cybercrime.jpg">taking a bite out of cybercrime</a>", here are the latest fake security software domains, typosquatted and already acquiring traffic through a dozen of malware campaigns redirecting to most of them :<br />
<br />
<b>antivirus-scanner-online.com</b> (67.205.75.14)<br />
<br />
<b>archivepacker.com</b> (78.157.142.111)<br />
<b>winpacker.com<br />
xh-codec.net</b><br />
<br />
<b>securedownloadcenter.com</b> (89.18.189.44)<br />
<b>winupdates-server.com<br />
browserssecuritypage.com<br />
megatradetds0.com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: left;"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrFf0onJVI/AAAAAAAACQY/L3D_vlP23hU/s1600-h/fake_security_software_october1.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrFf0onJVI/AAAAAAAACQY/omtYi_kxTos/s200-R/fake_security_software_october1.PNG" /></a></div><b>quickscanpc.com</b> (78.159.118.144)<br />
<b>clickchecker6.com<br />
</b><br />
<b>gensoftdownload.com</b> (91.203.93.25) <br />
<br />
<b>online-av-scan2008.com</b> (66.232.105.232)<br />
<b>anothersoftportal09.com</b><br />
<b>bigfreesoftarchive.com</b><br />
<b>celebs-on-video-08.com</b><br />
<b>celebs-on-video-2008.com</b><br />
<b>cleansoftportal2009.com</b><br />
<b>hot-p0rntube.com</b><br />
<b>hot-porn-tube-2008.com</b><br />
<b>hot-porn-tube2008.com</b><br />
<b>hot-porn-tube2009.com</b><br />
<b>justdomain08.com</b><br />
<b>new-porntube-2008.com</b><br />
<b>online-av-scan2008.com</b><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOrGSntRZ4I/AAAAAAAACQg/iIu0w9kigNc/s1600-h/fake_security_software_october2.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOrGSntRZ4I/AAAAAAAACQg/AIs6ZzzeXmI/s200-R/fake_security_software_october2.PNG" /></a><b>s0ftvvarep0rtal.com<br />
s0ftvvareportal.com<br />
s0ftvvareportal08.com<br />
s0ftwarep0rtal08.com<br />
softportalforfun.com<br />
softportalforfun08.com<br />
softportalforfun2008.com<br />
softvvareportal.com<br />
softvvareportal08.com<br />
softvvareportal2008.com<br />
trustedsoftportal06.com<br />
trustedsoftportal2008.com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOrG2J5DAiI/AAAAAAAACQo/PHQM9BSuc6A/s1600-h/fake_security_software_october3.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOrG2J5DAiI/AAAAAAAACQo/emqLynBbpqo/s200-R/fake_security_software_october3.PNG" /></a><b>antivirus-online-08.com</b> (89.187.48.155; 218.106.90.227)<br />
<b>anti-virus-xp.com<br />
anti-virus-xp.net<br />
anti-virusxp2008.net<br />
antimalware09.com<br />
antivirxp.net<br />
av-xp08.net<br />
av-xp2008.com<br />
av-xp2008.net<br />
avx08.net<br />
axp2008.com<br />
e-antiviruspro.com<br />
eantivirus-payment.com<br />
ekerberos.com<br />
online-security-systems.com<br />
xpprotector.com<br />
youpornzztube.com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrHASFNdfI/AAAAAAAACQw/qIj8zB5yVAY/s1600-h/fake_software_october.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOrHASFNdfI/AAAAAAAACQw/ARL4Yobkx74/s200-R/fake_software_october.png" /></a><b>sp-preventer.com</b> (92.241.163.32)<br />
<b>spypreventers.com</b><br />
<br />
<b>u-a-v-2008.com</b> (92.241.163.31)<br />
<b>uav2008.com</b><br />
<br />
<b>power-avcc.com</b> (92.62.101.57)<br />
<b>power-avc.com<br />
pvrantivirus.com</b><br />
<br />
<b>m-s-a-v-c.com</b> (92.62.101.55)<br />
<b>ms-avcc.com<br />
ms-avc.com</b><br />
<br />
<b>wav2008.com</b> (92.241.163.30)<br />
<b>wiav2009.com</b><br />
<b>win-av.com<br />
windows-av.com<br />
windowsav.com&nbsp;</b><br />
<br />
You know the drill.<b>&nbsp;</b><br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a> <b></b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1QWvM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1QWvM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=r6QfM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=r6QfM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Q76lm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Q76lm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JZP6m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JZP6m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YNGWM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YNGWM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MxVcM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MxVcM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=h2Vfm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=h2Vfm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413758015" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 03:21:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/malware campaigns">malware campaigns</category>
      <category domain="http://securityratty.com/tag/av-xp2008">av-xp2008</category>
      <category domain="http://securityratty.com/tag/anti-virus-xp">anti-virus-xp</category>
      <category domain="http://securityratty.com/tag/antimalware09">antimalware09</category>
      <category domain="http://securityratty.com/tag/uav2008">uav2008</category>
      <category domain="http://securityratty.com/tag/axp2008">axp2008</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413758015/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Eight</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Six]]></title>
      <link>http://securityratty.com/article/c31e0991fc6f93e70c9a40cf1ca74ce2</link>
      <guid>http://securityratty.com/article/c31e0991fc6f93e70c9a40cf1ca74ce2</guid>
      <description><![CDATA[Thanks to misconfigured traffic management kits, not taking advantage of all the built-in features that could have made a research a little bit more time consuming, here are the latest fake security...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SNqkjX8i0oI/AAAAAAAACLY/oW2_WhlJhfg/s1600-h/fake_security_software_september.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="189" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SNqkjX8i0oI/AAAAAAAACLY/zHIGkRoi5jM/s200-R/fake_security_software_september.JPG" width="200" /></a>Thanks to misconfigured traffic management kits, not taking advantage of all the built-in features that could have made a research a little bit more time consuming, here are the latest fake security software domains popping up at the end of fake adult content sites :<br />
<br />
<b>anti-spyware8 .com<br />
anti-spyware4 .com<br />
anti-spyware11 .com<br />
anti-spyware10 .com</b><br />
<b>antivirus-cs1 .com<br />
antivirus-cs14 .com<br />
antivirus-cs4 .com<br />
antivirus-cs15 .com<br />
antivirus-cs5 .com<br />
antivirus-cs7 .com<br />
antivirus-cs8 .com<br />
antivirus-cs9 .com<br />
trustedpaymenssite .com<br />
altawebgl-500 .com<br />
masterspitetds09 .com<br />
protectionaudit .com<br />
prt3ctionactiv3scan .com<br />
prtectionactivescan .com<br />
smartantivirusv2 .com<br />
smartantivirus2009v2 .com<br />
smartantivirus2009v2-buy .com<br />
smartantivirus-2009v2buy .com<br />
smart-antivirus2009v2buy .com<br />
anti-virus-xp .com<br />
anti-virus-xp .net<br />
e-antiviruspro .com<br />
ultimate-anti-virus .com <br />
antimalwarewarrior2009 .com</b><br />
<b>spyware-buy .com<br />
superantivirus2009 .com<br />
total-secure2009 .com<br />
pcprivacycleanerpro .com<br />
bestguardownload .com<br />
trustedantivirus .com<br />
antivirus-buy1 .com<br />
spyware-quickscan-2008 .com<br />
securealertbar .com<br />
secureclick1 .com<br />
megantivirus2009 .com <br />
micro-antivirus2008 .com<br />
superantivirus2009 .com <br />
advanced-anti-virus .com&nbsp; <br />
antivirusmaster2009 .com&nbsp; <br />
scanner-online1 .com<br />
internet-scanner2009 .com<br />
filescheck-list303 .com<br />
virus-webscanner .com<br />
virus9-webscanner .com<br />
spamnuker .com<br />
detect-file101 .com<br />
googlescanners-360 .com<br />
onlinescannersite9 .com<br />
bestantivirusscan .com<br />
hottystars .com<br />
internet-defenses .com<br />
globals-advers .com<br />
quickupdates29 .com<br />
myscanners101 .com<br />
myfreescan500 .com<br />
scanthnet .com<br />
scanners-pro .com<br />
megatradetds0 .com<br />
xp-licensingpages .com<br />
bestantivirusscan .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SNrGyIp8TvI/AAAAAAAACLg/6ZPTklX3YhA/s1600-h/fake_security_software_september_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="110" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SNrGyIp8TvI/AAAAAAAACLg/23VCO4Xvlv8/s200-R/fake_security_software_september_2.JPG" width="200" /></a><b>power-avc .com<br />
pvrantivirus .com<br />
online-xp-antivirus-checker .com<br />
antivir-online-scan .com<br />
online-win-xpantivirus .com<br />
tube-911 .com<br />
favoredmovie .com<br />
getqtysoftware .com<br />
softwareportal2008 .com<br />
megazcodec .com<br />
soft-upgrade-network .com<br />
download-base .com<br />
fastsoftdownloads .com<br />
software-downloadz .com<br />
download-soft-basez .com<br />
plupdate .com<br />
0scan .com<br />
virus-online-scan .com<br />
0scanner .com<br />
porno-tds .com<br />
jirolu .com<br />
virus-online-scanz .com<br />
red-tubbe .info<br />
win-xp-antivir-hqscanne .com<br />
xp-protections .com<br />
xp-registration .com<br />
xp2008-protect .com<br />
getdefender2009 .com<br />
gettotalsec2008 .com<br />
msantivirus-xp .com<br />
xp-licensingpages .com<br />
protectionpurchase .com<br />
winxp-antivir-on-line-scan .com <br />
antispychecker .com<br />
errorofbrowser .com<br />
fresh-video-news .com<br />
newschannel2008 .com<br />
internet--daily-news .com<br />
secure.signupsecurity .com<br />
xpacodec .com<br />
xpbcodec .com<br />
gmkvideo .com<br />
hqsextube08 .com<br />
antivirusworld9 .com<br />
viacodecright1 .com<br />
viacodecright2 .com<br />
quickupdates29 .com<br />
antivirusworld9 .com<br />
scanthnet .com<br />
city-codec .com<br />
citycodec .net<br />
codecdownload.anothersoftportal09 .com<br />
viacodecright2 .com<br />
sextubecodec023dfs41 .com<br />
hot-sextubedriver2 .com<br />
viacodecright2 .com</b><br />
<br />
The Diverse Portfolio of Fake Security Software series are prone to continue taking a bite out of cybercrime, and the people who distribute them on a affiliation based revenue sharing model. <br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Three</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html">EstDomains  and Intercage VS Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-security-software-domains-serving.html">Fake  Security Software Domains Serving Exploits</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized  Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got  Your XPShield Up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake  PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's  Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy  Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">Geolocating  Malicious ISPs</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The  Malicious ISPs You Rarely See in Any Report</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fl5WL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fl5WL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=limgL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=limgL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DSqtl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DSqtl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rGI5l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rGI5l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BE6sL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BE6sL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9HuVL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9HuVL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=44Tvl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=44Tvl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/402243350" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 14:29:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/malicious isps">malicious isps</category>
      <category domain="http://securityratty.com/tag/affiliation based revenue">affiliation based revenue</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/viacodecright2">viacodecright2</category>
      <category domain="http://securityratty.com/tag/lazy summer days">lazy summer days</category>
      <category domain="http://securityratty.com/tag/traffic management kits">traffic management kits</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/402243350/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</source>
    </item>
    <item>
      <title><![CDATA[Louisville ISSA Nmap presentation slides and media posted]]></title>
      <link>http://securityratty.com/article/bbd469872f1364ae4fd2a7434ef471c1</link>
      <guid>http://securityratty.com/article/bbd469872f1364ae4fd2a7434ef471c1</guid>
      <description><![CDATA[I've posted the slides and related media for the Nmap presentation I'm giving Friday (Sept 5) for the Kentuckiana ISSA . You should be able to find the codec for the videos in the zip file. If you...]]></description>
      <content:encoded><![CDATA[I've posted the slides and related media for the Nmap presentation I'm 
giving Friday (Sept 5) for the <a href="http://www.issa-kentuckiana.org/">	Kentuckiana ISSA</a>. You should be able to find the codec for the videos in the zip file.&nbsp; If you plan to come to the free class at Ivy Tech 	(Sellersburg Indiana) on the 20th please <a href="http://www.irongeek.com/i.php?page=contact">contact me</a>.
<p><a href="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?a=ZRsQMm"><img src="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?i=ZRsQMm" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/383739632" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 17:07:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nmap presentation">nmap presentation</category>
      <category domain="http://securityratty.com/tag/ivy tech">ivy tech</category>
      <category domain="http://securityratty.com/tag/slides">slides</category>
      <category domain="http://securityratty.com/tag/zip file">zip file</category>
      <category domain="http://securityratty.com/tag/media">media</category>
      <category domain="http://securityratty.com/tag/sellersburg indiana">sellersburg indiana</category>
      <category domain="http://securityratty.com/tag/free class">free class</category>
      <category domain="http://securityratty.com/tag/kentuckiana issa">kentuckiana issa</category>
      <category domain="http://securityratty.com/tag/codec">codec</category>
      <source url="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~3/383739632/issa-nmap.zip">Louisville ISSA Nmap presentation slides and media posted</source>
    </item>
    <item>
      <title><![CDATA[Louisville ISSA Nmap presentation slides and media posted]]></title>
      <link>http://securityratty.com/article/f387eebef71a2cc826a73e5f487aa218</link>
      <guid>http://securityratty.com/article/f387eebef71a2cc826a73e5f487aa218</guid>
      <description><![CDATA[I've posted the slides and related media for the Nmap presentation I'm giving Friday (Sept 5) for the Kentuckiana ISSA . You should be able to find the codec for the videos in the zip file. If you...]]></description>
      <content:encoded><![CDATA[I've posted the slides and related media for the Nmap presentation I'm 
giving Friday (Sept 5) for the <a href="http://www.issa-kentuckiana.org/">	Kentuckiana ISSA</a>. You should be able to find the codec for the videos in the zip file.&nbsp; If you plan to come to the free class at Ivy Tech 	(Sellersburg Indiana) on the 20th please <a href="http://www.irongeek.com/i.php?page=contact">contact me</a>.<img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/LRahduBv5Oo" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 17:07:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nmap presentation">nmap presentation</category>
      <category domain="http://securityratty.com/tag/ivy tech">ivy tech</category>
      <category domain="http://securityratty.com/tag/slides">slides</category>
      <category domain="http://securityratty.com/tag/zip file">zip file</category>
      <category domain="http://securityratty.com/tag/media">media</category>
      <category domain="http://securityratty.com/tag/sellersburg indiana">sellersburg indiana</category>
      <category domain="http://securityratty.com/tag/free class">free class</category>
      <category domain="http://securityratty.com/tag/kentuckiana issa">kentuckiana issa</category>
      <category domain="http://securityratty.com/tag/codec">codec</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/LRahduBv5Oo/issa-nmap.zip">Louisville ISSA Nmap presentation slides and media posted</source>
    </item>
    <item>
      <title><![CDATA[Louisville ISSA Nmap presentation slides and media posted]]></title>
      <link>http://securityratty.com/article/8f73d5ea405b630ead98be97a1463a58</link>
      <guid>http://securityratty.com/article/8f73d5ea405b630ead98be97a1463a58</guid>
      <description><![CDATA[I've posted the slides and related media for the Nmap presentation I'm giving Friday (Sept 5) for the Kentuckiana ISSA . You should be able to find the codec for the videos in the zip file. If you...]]></description>
      <content:encoded><![CDATA[I've posted the slides and related media for the Nmap presentation I'm 
giving Friday (Sept 5) for the <a href="http://www.issa-kentuckiana.org/">	Kentuckiana ISSA</a>. You should be able to find the codec for the videos in the zip file.&nbsp; If you plan to come to the free class at Ivy Tech 	(Sellersburg Indiana) on the 20th please <a href="http://www.irongeek.com/i.php?page=contact">contact me</a>.]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 17:07:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nmap presentation">nmap presentation</category>
      <category domain="http://securityratty.com/tag/ivy tech">ivy tech</category>
      <category domain="http://securityratty.com/tag/slides">slides</category>
      <category domain="http://securityratty.com/tag/zip file">zip file</category>
      <category domain="http://securityratty.com/tag/media">media</category>
      <category domain="http://securityratty.com/tag/sellersburg indiana">sellersburg indiana</category>
      <category domain="http://securityratty.com/tag/free class">free class</category>
      <category domain="http://securityratty.com/tag/kentuckiana issa">kentuckiana issa</category>
      <category domain="http://securityratty.com/tag/codec">codec</category>
      <source url="http://www.irongeek.com/downloads/issa-nmap.zip">Louisville ISSA Nmap presentation slides and media posted</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Five]]></title>
      <link>http://securityratty.com/article/38118a4a2d1022021197659857d63ff3</link>
      <guid>http://securityratty.com/article/38118a4a2d1022021197659857d63ff3</guid>
      <description><![CDATA[The &quot;campaign managers&quot; behind these fake security software propositions are not just starting to take park them at up to three different locations, localize the sites to different languages and...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SL0JgRiDYeI/AAAAAAAACI8/6WOV1GjHRlY/s1600-h/fake_software_september1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SL0JgRiDYeI/AAAAAAAACI8/JMBr1bMh8no/s200-R/fake_software_september1.JPG" /></a>The "campaign managers" behind these <a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">fake security software propositions</a> are not just starting to take park them at up to three different locations, <a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">localize the sites</a> to different languages and introduce <a href="http://ddanchev.blogspot.com/2008/08/fake-security-software-domains-serving.html">client-side exploits</a>, just in case the end user gets suspicious and doesn't install it, but also, the natural evasive practices. For instance, once some of their domains get detected and blocked, they put them in a stand by mode and relaunch them online in a week or so, or ensure that only those coming to the domains from where they are supposed to come - yet another blackhat SEO or SQL injection attack - are the only ones getting to see the download screen.<br />
<br />
Some of the new additions parked at the same IPs offered by the "known suspects" include :<br />
<br />
<b>main-scanner .com</b> - (77.244.220.138; 78.159.97.247; 89.149.209.251; 212.95.37.154)<br />
<b>scanner-mainpro .com<br />
scanner-online1 .com<br />
alldiskscheck300 .com<br />
myscanners101 .com<br />
download-a1 .com<br />
scanner-online1 .com<br />
multilang1 .com<br />
ratemyblog1 .com<br />
multisearch1 .com<br />
filescheck-list303 .com<br />
woodst-sale .com<br />
scanner-mainpro .com<br />
main-scanner .com<br />
directrevisions .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SL0MwkX0VNI/AAAAAAAACJE/QObbQi3_9Ng/s1600-h/doctor_antivirus1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="141" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SL0MwkX0VNI/AAAAAAAACJE/vDM5gk_K5fc/s200-R/doctor_antivirus1.png" width="200" /></a><b>supersolution-freeantivirus .com</b> - (213.155.2.69)<br />
<b>antivirus-bestsolution .net<br />
antivirus4protection .net<br />
antivirusproxp .com<br />
freebest-antivirus .net<br />
goodantivirus-free .net<br />
noadwareantivirus .com<br />
pwrantivirus2009 .com<br />
solution-freeantivirus .com<br />
supersolution-antivirus .com<br />
supersolution-freeantivirus .com<br />
antivirusdwl .com<br />
securesoftdl .com<br />
viva-codec .com<br />
win-antivirus-protect .com<br />
avxp-2008 .net<br />
antivirusq .net<br />
antivirus2008b .net<br />
antivirus2008m .net<br />
antivirus2008n .net<br />
antivirus2008v .net<br />
antivirus777 .com<br />
antivirusq .net<br />
antivirusr .net<br />
antivirust .net<br />
antivirusw .net<br />
antivirusu .net<br />
expressantivirus2009 .com<br />
spywarezscan .net<br />
antispywareq .net<br />
free-anti-spywaree .net<br />
avcheckyourpc .net<br />
</b><br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SL0NgVvxo5I/AAAAAAAACJM/zna4-YKQE_o/s1600-h/doctor_antivirus2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SL0NgVvxo5I/AAAAAAAACJM/4mda8Pv35yY/s200-R/doctor_antivirus2.png" /></a><b>software-for-me08 .com</b> - (78.157.143.250)<br />
<b>software-for-me-08 .com<br />
softwarefor-me2008 .com<br />
softwarefor-me-2008 .com<br />
software-forme08 .com</b><br />
<br />
<b>doctor2antivirus .com</b> - (217.112.94.226; 87.248.163.56)<br />
<b>doctor5antivirus .com<br />
doctor6antivirus .com<br />
doctor7antivirus .com<br />
doctor8antivirus .com<br />
doctorantivirus2008a .com<br />
doctor-antivirus .com<br />
bcodecnow .net</b><br />
<br />
<b>mysoftwarefreezone .com</b> - (91.203.92.97)<br />
<b>hotvid44 .com<br />
totsec2009 .com<br />
getdefender2009 .com<br />
totalsecure2009 .com<br />
myveryprivatevid .com<br />
mustseethatvid .com<br />
onlythebestvid .com<br />
ie-antivirus-order .com<br />
ie-anti-virus .com<br />
secure-order-box .com</b><br />
<br />
<b>secureexpertcleaner .com</b> - (89.149.227.50)<br />
<b>bestxpclean2008 .com<br />
virusremover2008 .com<br />
registrydoctor2008 .com<br />
securefileshredder .com<br />
hypersecurefileshredder .com<br />
bestsecureexpertcleaner .com</b><br />
<br />
<b>getdefender2009 .com</b> - (58.65.238.34)<br />
<b>malwarebell .com<br />
free-viruscan .com<br />
tmptmpservvv .com<br />
cometoseemyshow .com</b><br />
<br />
<b>getneededsoftware .com</b> - (91.203.93.25)<br />
<b>gettotalsec2008 .com<br />
thedownloadvid .com<br />
scan.pc-antispyware-scanner .com<br />
totalsecure2009 .com</b><br />
<br />
<b>wista-antivirus2009 .com</b> - (216.255.179.203)<br />
<b>usawindowsupdates .com</b> - (85.17.143.213)<br />
<b>mswindowsupdates .com</b><br />
<br />
The campaigns and the hosting providers are continuously monitored, especially taking into consideration the fact that the domains are already appearing in Alexa's web rankings with sudden peaks of traffic.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-security-software-domains-serving.html">Fake Security Software Domains Serving Exploits</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A Diverse Portfolio of Fake Security Software - Part Four</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse Portfolio of Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got Your XPShield Up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">Geolocating Malicious ISPs</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The Malicious ISPs You Rarely See in Any Report</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9RKAnL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9RKAnL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=S4YvYL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=S4YvYL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=J1kcWl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=J1kcWl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=q4Iwql"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=q4Iwql" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Cbh1CL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Cbh1CL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=b89bjL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=b89bjL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=t2D6Bl"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=t2D6Bl" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/381234025" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 01:04:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/introduce client-side exploits">introduce client-side exploits</category>
      <category domain="http://securityratty.com/tag/malicious isps">malicious isps</category>
      <category domain="http://securityratty.com/tag/exploits">exploits</category>
      <category domain="http://securityratty.com/tag/sql injection attack">sql injection attack</category>
      <category domain="http://securityratty.com/tag/lazy summer days">lazy summer days</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/381234025/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software - Part Five</source>
    </item>
    <item>
      <title><![CDATA[Holy Media Codecs, Batman!]]></title>
      <link>http://securityratty.com/article/3d984264f929456ea8e4f274d55394ef</link>
      <guid>http://securityratty.com/article/3d984264f929456ea8e4f274d55394ef</guid>
      <description><![CDATA[Batman is still in full swing at the box office - I'm sure me seeing it seven times probably didn't hurt - so with that in mind (and thoughts of the Zango / Dark Knight issue still rattling around my...]]></description>
      <content:encoded><![CDATA[
        Batman is still in full swing at the box office - I'm sure me seeing it seven times probably didn't hurt - so with that in mind (and thoughts of the <a href="http://www.theregister.co.uk/2008/08/18/dark_knight_zango_affiliate_gateway/">Zango / Dark Knight issue</a> still rattling around my brain) I thought it would be fun to see exactly how quickly it can all go wrong when looking for Dark Knight material online.<br /><br />The answer is: extremely quickly.<br /><br />There's a lot of sites out there claiming to carry "full versions" of The Dark Knight, and although they don't offer Zango, they <i>do</i> offer fake media codecs (which usually do all sorts of horrible things to a computer). Let's pull one of these sites apart as an example of how the scam fits together.<br /><br />Here's a typical site pushing what they claim to be The Dark Knight:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman000.html" onclick="window.open('http://blog.spywareguide.com/images/dbman000.html','popup','width=717,height=564,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman000-thumb-317x249.jpg" alt="dbman000.jpg" class="mt-image-none" style="" height="249" width="317" /></a></span><br />Click to Enlarge<br /></div><br />Dijgg(dot)com, an obvious Digg.com knockoff apparently hosting a large streaming window - the movie quality will be awesome, won't it? Well, actually, no it won't.<br /><br />In the middle of the video window is a popup:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman0.jpg" src="http://blog.spywareguide.com/images/dbman0.jpg" class="mt-image-none" style="" height="145" width="399" /></span></div><br /><br /> <div>Install the "codec", and this won't end well. The EXE comes from a site called Favoritetube(dot)com:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman1.jpg" src="http://blog.spywareguide.com/images/dbman1.jpg" class="mt-image-none" style="" height="203" width="348" /></span></div><br /><br />A quick check for the <a href="http://www.siteadvisor.com/sites/favoritetube.net/postid?p=1063293">safety</a> <a href="http://safeweb.norton.com/report/show?name=favoritetube.net">ratings</a> of that website should be enough to tell you this is a scam. Indeed, there isn't even a movie being streamed here (despite it saying "Connecting" at the bottom of the movie player) - because if you right click on the player itself:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman0000.jpg" src="http://blog.spywareguide.com/images/dbman0000.jpg" class="mt-image-none" style="" height="370" width="418" /></span></div><br /></div><div><br />You can see the "player" is actually just a static image (because I'm given the option to "Copy Image Location"). The image is hosted at Favoritetube, just like the "codecs":<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman2.html" onclick="window.open('http://blog.spywareguide.com/images/dbman2.html','popup','width=655,height=570,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman2-thumb-355x308.jpg" alt="dbman2.jpg" class="mt-image-none" style="" height="308" width="355" /></a></span><br /><br />Click to Enlarge<br /></div><br />There are quite a lot of these sites floating around out there at present:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman3.html" onclick="window.open('http://blog.spywareguide.com/images/dbman3.html','popup','width=738,height=532,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman3-thumb-338x243.jpg" alt="dbman3.jpg" class="mt-image-none" style="" height="243" width="338" /></a></span><br /><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman4.html" onclick="window.open('http://blog.spywareguide.com/images/dbman4.html','popup','width=599,height=533,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman4-thumb-399x355.jpg" alt="dbman4.jpg" class="mt-image-none" style="" height="355" width="399" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman100.html" onclick="window.open('http://blog.spywareguide.com/images/dbman100.html','popup','width=625,height=516,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman100-thumb-325x268.jpg" alt="dbman100.jpg" class="mt-image-none" style="" height="268" width="325" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />At this point, it's a given that I'm going to show you what happens if you install one of the files typically pushed from the above sites, right? Well, wait no longer - this....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman7.jpg" src="http://blog.spywareguide.com/images/dbman7.jpg" class="mt-image-none" style="" height="81" width="84" /></span></div><br /></div><div><br />...will deposit a rogue antispyware tool on your desktop (one of more more obnoxious ones that refuses to leave you alone):<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/antispycheck1.html" onclick="window.open('http://blog.spywareguide.com/images/antispycheck1.html','popup','width=877,height=668,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/antispycheck1-thumb-377x287.jpg" alt="antispycheck1.jpg" class="mt-image-none" style="" height="287" width="377" /></a></span><br /><br />Click to Enlarge<br /></div><br />Strange and annoying icons will start to creep across your desktop:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman8.jpg" src="http://blog.spywareguide.com/images/dbman8.jpg" class="mt-image-none" style="" height="82" width="245" /></span></div><br /></div><div><br />....and you'll have more fake system alerts than you can shake a very large stick at:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="antispycheck22.jpg" src="http://blog.spywareguide.com/images/antispycheck22.jpg" class="mt-image-none" style="" height="304" width="273" /></span></div><br /><br />This concludes my public safety announcement. I'm off to see Dark Knight again...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 06:10:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dark knight issue">dark knight issue</category>
      <category domain="http://securityratty.com/tag/dark knight">dark knight</category>
      <category domain="http://securityratty.com/tag/movie player">movie player</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/enlarge">enlarge</category>
      <category domain="http://securityratty.com/tag/image">image</category>
      <category domain="http://securityratty.com/tag/copy image location">copy image location</category>
      <category domain="http://securityratty.com/tag/movie">movie</category>
      <source url="http://blog.spywareguide.com/2008/08/holy-media-codecs-batman.html">Holy Media Codecs, Batman!</source>
    </item>
    <item>
      <title><![CDATA[Fake Porn Sites Serving Malware - Part Three]]></title>
      <link>http://securityratty.com/article/df6f06139a5c1a6029631a2d5221d428</link>
      <guid>http://securityratty.com/article/df6f06139a5c1a6029631a2d5221d428</guid>
      <description><![CDATA[Continue the Fake Porn Sites Serving Malware and Fake Porn Sites Serving Malware - Part Two series, in part three we'll take a peek at the emerging trend of parking a single domain at up to three...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQENtZvVWI/AAAAAAAACHU/3Th9wGTcre4/s1600-h/fake_porn_zlob_codec_localized.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQENtZvVWI/AAAAAAAACHU/1aZSLqClTi4/s200-R/fake_porn_zlob_codec_localized.JPG" /></a>Continue the <a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a> and <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a> series, in part three we'll take a peek at the emerging trend of parking a single domain at up to three different hosting locations, re-establishing connections between malicious ISPs for yet another time in between exposing the domains and the download locations sharing the same IPs.<br />
<br />
<b>downlfreesexgirlbeach .com</b> first redirects to <b>infodist1 .com/in.cgi?2 </b>then to <b>watchnenjoy.com/index.php?id=1314&amp;style=black</b>, and finally to the front end to the codec's download location <b>handmadeclips .com</b>, where the codec is downloaded from <b>fwlprocedure .com</b>.  Behind these domains, we can easily expose many other fake porn sites and pharmaceutical scams, next to a small portfolio of domains specifically used for hosting the binaries. Due to the obvious rotation I've encountered several times so far, a fake porn site today, is tomorrow's blackhat SEO content farm :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQHSj0XVWI/AAAAAAAACHc/DX-IaOAduVs/s1600-h/fake_porn_august.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQHSj0XVWI/AAAAAAAACHc/k9h1_E21wag/s200-R/fake_porn_august.JPG" /></a><b>downlfreesexgirlbeach .com</b> - (88.214.198.25)<br />
<b>vids365 .com<br />
downlfreesexgirlbeach .com<br />
top.only-bi .com<br />
wikiei .com<br />
paysuperporn .com<br />
aboutsexporn .com<br />
freactor .com<br />
cheapofficialpills .com<br />
finance-leaders.comnudenakedboys .com<br />
photosgayboys&nbsp; .com<br />
uniqueincest.com<br />
shyincest .com<br />
banrnd.central-xxx .com<br />
tvisklick .info<br />
thebg .net<br />
termion .net<br />
xoxvids .net<br />
bestpricepills .net<br />
bcodecnow .net</b><br />
<br />
<b>infodist1 .com</b> - (88.214.204.40)<br />
<b>farmasearch2008 .com<br />
flaxxvid .com<br />
xanax777pills .com<br />
18virgingirls .com<br />
girlnudegallaryvideox .com<br />
allxxxpornogerlsx .com<br />
jproshin .info<br />
familytaboo .info<br />
fullsitehost .info<br />
20searchonlinesite .net<br />
add-your-video .net<br />
blogs4y .net</b><br />
<br />
<div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SLQIspjO3tI/AAAAAAAACHs/MaMXiAw02F8/s1600-h/downlfreesexgirlbeach_viz.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SLQIspjO3tI/AAAAAAAACHs/znHGKTmbcHE/s200-R/downlfreesexgirlbeach_viz.JPG" /></a><b>adult-shemale .com</b> - (88.214.198.25)<br />
<b>adult-tranny .com<br />
all-shemale&nbsp; .com&nbsp;&nbsp;&nbsp; <br />
bcodecnow .net<br />
best-tranny .com&nbsp;&nbsp;&nbsp; <br />
bestguyportal .com<br />
bestmoviez .com&nbsp;&nbsp;&nbsp; <br />
central-xxx .com<br />
downlfreesexgirlbeach .com&nbsp;&nbsp;&nbsp; <br />
gallery-boy .com<br />
hiosexywomensxxxgirlsx .com&nbsp;&nbsp;&nbsp; <br />
lady-dick .com<br />
bcodecnow .net<br />
mytoppharmacy .com<br />
nakednudeboys .com&nbsp;&nbsp;&nbsp; <br />
nakednudemen .com<br />
nudenakedboys .com<br />
only-bi .com<br />
only-shemale .com<br />
page-reviews .com<br />
paulaslosingit .com<br />
photosgayboys .com<br />
stud-boys .com&nbsp;&nbsp;&nbsp; <br />
the0download .com<br />
wikiei .com&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; <br />
moviez .com<br />
hiosexywomensxxxgirlsx .com<br />
sexygirlsisuniformh0t .com&nbsp;&nbsp;&nbsp; <br />
the0download .com</b><br />
<br />
<b>flwprocedure .com </b>- (77.91.231.201)<b><br />
movupdate .com<br />
flwupdate .com<br />
formatmpeg .com<br />
movieexternal .com<br />
flwtool .com <br />
aviexecution .com<br />
releasedvideo .com<br />
wmvcompressor .com<br />
movieopens .com<br />
mpegapparatus .com<br />
flwassistant .com<br />
flwinstrument .com<br />
piterserv .com<br />
wovview .com</b><br />
<br />
<b>Some info on a sample codec :</b><br />
Scanners Result: 11/36 (30.56%)<br />
Trojan-Downloader.Win32.Zlob.cos<br />
Trojan.Popuper.7315<br />
File size: 10240 bytes <br />
MD5...: 467e4e78974dc8b2ee5d7da024daf31a <br />
SHA1..: 311e0c710bb15761ef3dace54b55489830cf5803<br />
<br />
Phones back to <b>69.50.164.50</b>/this/is/stereo/music.php?param=0;1314;1550; <b>69.50.164.50</b>/this/is/stereo/jazz.php?param=49325611;2:191:5|7:271:0|6:130:0|9:0:5|34:65536:0 and to <b>85.255.119.244</b>/this/is/stereo/music.php?param=0;4135;1548.<br />
<br />
When <b>Emil Kaperski's</b> owned <a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">InterCage, Inc.</a> (69.50.164.50) meets <a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">UkrTeleGroup Ltd.</a> (85.255.119.244) previously known as <b>Andrei Kislizin's</b> owned InHoster, you know you're on the right track.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kUs27K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kUs27K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sRXTAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sRXTAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sOsoWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sOsoWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fnooek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fnooek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R3T9kK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R3T9kK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WaKp6K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WaKp6K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R12pRk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R12pRk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/375241515" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 05:02:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <category domain="http://securityratty.com/tag/codec">codec</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/sample codec">sample codec</category>
      <category domain="http://securityratty.com/tag/locations">locations</category>
      <category domain="http://securityratty.com/tag/fake porn site">fake porn site</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/375241515/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Three</source>
    </item>
    <item>
      <title><![CDATA[Facebook Worm Still Going Strong]]></title>
      <link>http://securityratty.com/article/3d63cb5f4654a97b393266f752d1c56a</link>
      <guid>http://securityratty.com/article/3d63cb5f4654a97b393266f752d1c56a</guid>
      <description><![CDATA[A colleague of mine had a private message sent to them on Facebook yesterday from the account of a friend. The message is related (of course) to the recent Facebook worm





Click the link, and...]]></description>
      <content:encoded><![CDATA[
        A colleague of mine had a private message sent to them on Facebook yesterday from the account of a friend. The message is related (of course) to the recent <a href="http://blogs.pcmag.com/securitywatch/2008/08/facebook_worm_spreads_rapidly.php">Facebook worm</a>:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fbspam1.jpg" src="http://blog.spywareguide.com/images/fbspam1.jpg" class="mt-image-none" style="" height="304" width="413" /></span></div><br /> <div><br />Click the link, and you'll see something like this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/fbspam2.html" onclick="window.open('http://blog.spywareguide.com/images/fbspam2.html','popup','width=700,height=510,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/fbspam2-thumb-300x218.jpg" alt="fbspam2.jpg" class="mt-image-none" style="" height="218" width="300" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />Yes, it's Ye Olde Fake Codec installer, hosted on what appears to be a hacked website. As always, pay close attention to what you're being sent from your friends. If it doesn't <i>seem</i> like something they'd send you, that's probably because they didn't...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 05:57:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/recent facebook worm">recent facebook worm</category>
      <category domain="http://securityratty.com/tag/close attention">close attention</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/facebook yesterday">facebook yesterday</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/friend">friend</category>
      <category domain="http://securityratty.com/tag/website">website</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <source url="http://blog.spywareguide.com/2008/08/facebook-worm-still-going-stro.html">Facebook Worm Still Going Strong</source>
    </item>
    <item>
      <title><![CDATA[The Template-ization of Malware Serving Sites]]></title>
      <link>http://securityratty.com/article/ae9fa7925137e6a71a690ef3b705294d</link>
      <guid>http://securityratty.com/article/ae9fa7925137e6a71a690ef3b705294d</guid>
      <description><![CDATA[Just like web malware exploitation kits and phishing pages turned into a commodity underground good , allowing easy localization to different languages , and of course, the natural lowering of entry...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHZZ6zTOnOI/AAAAAAAAB5c/3Sqe37mACns/s1600-h/fake_video_codec_template.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHZZ6zTOnOI/AAAAAAAAB5c/Rsu1-EiUFlY/s200-R/fake_video_codec_template.JPG" style="border: 0pt none ;" /></a>Just like web <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">malware</a> <a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">exploitation</a> <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">kits</a> and <a href="http://ddanchev.blogspot.com/2008/03/phishing-pages-for-every-bank-are.html">phishing pages turned into a commodity underground good</a>, allowing easy <a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">localization to different languages</a>, and of course, the natural lowering of entry barriers into web malware and phishing in general, the very same thing is happening with fake ActiveX templates like the ones used on <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">the majority of fake porn and celebrity sites I've been assessing recently</a>.<br />
<br />
The increase of these bogus ActiveX templates is due to the fact that despite they are currently available for sale, buyers appear to be leaking them for everyone to use so that they can continue maintaining their current business models, namely, the services they offer with the ActiveX templates. Unethical competitive practices among cybercriminals and scammers are only to starting to take place with one another trying to ruin or extend the lifecycle of their services.<br />
<br />
Talking about prevalence, the <b>TonsOfPorn ActiveX</b> remains the most widely used rogue ActiveX in the majority of fake codec campaigns for the last couple of months. The ActiveX is largely abused by using another <b>fake porn site template for PornTube</b>, which in combination result in nothing more than huge domain portfolios with no content at all if we exclude the Zlob variants.<br />
<br />
And while template-tization means more efficient malware campaigns, it also results in a common pattern for generic detection of such sites. For instance, the folks at <a href="http://www.finjan.com/MCRCblog.aspx?EntryId=1993">Finjan did an experiment by verifying the signature based detection of the common javascript file</a> that was used in the ongoing waves of SQL injection attacks. Their conclusion :<br />
<br />
"<i>Can it be that Anti-virus products are now holding more signatures for domains and URLs rather than trying to identify a malicious code they never inspected before? As my research found, just by changing the domain names, some AVs did not find this code as malicious...... surprisingly enough.</i>"<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHaFBlIm7bI/AAAAAAAAB5k/lXlcCbD2H78/s1600-h/inthecloud3.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHaFBlIm7bI/AAAAAAAAB5k/wABNqH2-Sz0/s200-R/inthecloud3.jpg" style="border: 0pt none ;" /></a>When assessing malware campaigns in general, I usually do the same for the record. Storm Worm's use of <b>ind.php</b> for executing its set of exploits has the same detection rate - <b>scanners result: 10/33 (30.30%)</b> and is detected as JS.Zhelatin.zb.<br />
<br />
Getting back to the <b>TonsOfPorn ActiveX</b>, it's structure is more static than a Red Army statue in Estonia, making it easy to proactively protect against, no matter the domain, no matter the exploits served. It's detection rate is close to the javascript from the SQL injection attacks - <b>Scanners Result: 9/33 (27.28%) </b>and is detected as <b>Trojan.HTML.Zlob.L</b>.<br />
<br />
From my personal experience, blocking an IP address where a couple of hundred malicious domains remain parked, is just as useful as blocking a single domain acting as the main redirector behind a huge domains portfolio of malicious domains. However, the most beneficial approach on a large scale remains the practice of taking care of the most obvious patterns that still remain faily easy to detect, at least for the time being, due to the efficiency the people behind them aim to achieve, making them easily susceptible to generic detection approaches.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=60LvHJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=60LvHJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TvxsiJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TvxsiJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UeK86j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UeK86j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AHP63j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AHP63j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ci9jvJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ci9jvJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mQuV1J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mQuV1J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FGm2Yj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FGm2Yj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/332106839" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 12:59:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious domains remain">malicious domains remain</category>
      <category domain="http://securityratty.com/tag/malicious domains">malicious domains</category>
      <category domain="http://securityratty.com/tag/tonsofporn activex remains">tonsofporn activex remains</category>
      <category domain="http://securityratty.com/tag/tonsofporn activex">tonsofporn activex</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/generic detection approaches">generic detection approaches</category>
      <category domain="http://securityratty.com/tag/generic detection">generic detection</category>
      <category domain="http://securityratty.com/tag/activex">activex</category>
      <category domain="http://securityratty.com/tag/fake activex">fake activex</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/332106839/template-ization-of-malware-serving.html">The Template-ization of Malware Serving Sites</source>
    </item>
  </channel>
</rss>
