<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: disrupt]]></title>
    <link>http://securityratty.com/tag/disrupt</link>
    <description></description>
    <pubDate>Tue, 01 Jul 2008 03:05:01 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Will Code Malware for Financial Incentives]]></title>
      <link>http://securityratty.com/article/30eebfa1383ce3a671879e2f1f0af37d</link>
      <guid>http://securityratty.com/article/30eebfa1383ce3a671879e2f1f0af37d</guid>
      <description><![CDATA[A couple of hundred dollars can indeed get you state of the art undetectable piece of malware with post-purchase service in the form of automatic lower detection rate for sure, but what happens when...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SSLQOaWm71I/AAAAAAAACdM/nHHgxqAJn-4/s1600-h/malware_hire_sample_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SSLQOaWm71I/AAAAAAAACdM/nHHgxqAJn-4/s200/malware_hire_sample_1.JPG" /></a>A couple of hundred dollars can indeed get you state of the art <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">undetectable piece of malware with post-purchase service</a> in the form of automatic lower detection rate for sure, but what happens when the vendors of such releases start vertically integrating just like everyone else, and start offering OS-independent spamming, flooding, modifications and tweaking of popular crimeware kits in the very same fashion? The quality assurance process gets centralized into the hands of experienced programmers that have been developing cybercrime facilitating tools for years.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SSLcUHXGAoI/AAAAAAAACdU/wnzsUHFHSrg/s1600-h/malware_hire_sample_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SSLcUHXGAoI/AAAAAAAACdU/wnzsUHFHSrg/s200/malware_hire_sample_2.JPG" /></a>It's interesting to monitor the pricing schemes that they implement. For instance, the modularity of a particular malware, that is the additional functions that a buyer may want or not want, increase or decrease the price respectively. Others, tend to leave the price open topic by only mentioning the starting price for their services and they increasing it again in open topic fashion.<br />
<br />
Let's take look at some recently advertised (translated) "malware coding for hire" propositions, highlighting some of the latest developments in their pricing strategies :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SSMEwnRgU6I/AAAAAAAACdc/bFEBpsTalQQ/s1600-h/malware_hire_sample_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SSMEwnRgU6I/AAAAAAAACdc/bFEBpsTalQQ/s200/malware_hire_sample_3.JPG" /></a><b>Proposition 1</b> : <br />
"<i>Programs and scripts under the following categories are accepted : </i><br />
<i>grabbers; spamming tools for forums, spamming tools for social networking sites, modifications of admin panels for (popular crimeware kits), phishing pages</i><br />
<br />
<i>Platform: software running on MAC OS to Windows  </i><br />
<i>Multitasking: have the capacity to work on multiple projects</i><br />
<i>Speed and responsibility: at the highest level  </i><br />
<i>Pre-payment for new customers: 50% of the whole price, 30% pre-pay of the whole price for repreated customers  </i><br />
<i>Support: Paid  </i><br />
<i>Rates: starting from 100 euros</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SSMGg5E49_I/AAAAAAAACds/lWtlV3eYu4s/s1600-h/malware_hire_sample_4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SSMGg5E49_I/AAAAAAAACds/lWtlV3eYu4s/s200/malware_hire_sample_4.JPG" /></a><i>If, after speaking ultimate price, you decide to add to your order something else - the price change. Prepare the job immediately, which will understand what to do and how much it will cost you, if you have any suggestions for a price, then lays them immediately and not after the work is completed. If you order something that requires parsing your logs, and their continued use, you agree to provide "a significant portion of the logs, so that after putting the project did not raise misunderstandings due to the fact that some logs are no longer "fresh", because of their "uniqueness". In this case, for the finalization of the project will be charged an additional fee.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SSMKeg8y5SI/AAAAAAAACd0/ekeV4Us8PwY/s1600-h/malware_hire_sample_5.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SSMKeg8y5SI/AAAAAAAACd0/ekeV4Us8PwY/s200/malware_hire_sample_5.JPG" /></a>This is an example of an "open topic pricing scheme" with the vendor offering the possibility to code the malware or the tool for any price above 100 euro based on what he perceives as features included within worth the price.<br />
<br />
<b>Proposition 2</b>:<br />
"<i>Starting price for my malware is 250 EUR. Additional modules like P2P features, source code for a particular module go for an additional 50 EUR. If you're paying in another currency the price is 200 GBP or 395 dollars. I sell only ten copies of the builder so hurry up. The trading process is simple - a password protected file with the malware is sent to you so you can see the files inside. You then sent the money and I mail you back the password. If you don't like this way you lose.&nbsp;</i><br />
<br />
<i>I can also offer you another deal, I will share the complete source code in exchange to access to a botnet with at least 4000 infected hosts because I don't have time to play around with me bot right now.</i> <br />
<br />
This proposition is particularly interesting because the seller is introducing basic understanding of exchange rates, but most of all because he's in fact offering a direct bargain in the form of access to a botnet in exchange for a complete source code of his malware bot. Both propositions are also great examples that vendors engage by keeping their current and potential customers up-to-date with <a href="http://ddanchev.blogspot.com/2008/04/botnet-masters-to-do-list.html">TODO lists of features to come</a> next to the usual CHANGELOGS, and, of course,&nbsp; establish trust by allowing potential customers to take a peek at the source code of the malware they're about to purchase.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire </a><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/russias-fsb-vs-cybercrime.html">Russia's FSB vs Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">Localizing Open Source Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/quality-and-assurance-in-malware.html">Quality and Assurance in Malware Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2006/09/benchmarking-and-optimising-malware.html">Benchmarking and Optimising Malware</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=a8huN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=a8huN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sEoBN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sEoBN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rj24n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rj24n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W4aen"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W4aen" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7YAqN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7YAqN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rEDhN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rEDhN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rpNUn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rpNUn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/457569401" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 10:57:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/source malware">source malware</category>
      <category domain="http://securityratty.com/tag/malware attacks">malware attacks</category>
      <category domain="http://securityratty.com/tag/malware bot">malware bot</category>
      <category domain="http://securityratty.com/tag/proprietary malware tools">proprietary malware tools</category>
      <category domain="http://securityratty.com/tag/source code">source code</category>
      <category domain="http://securityratty.com/tag/complete source code">complete source code</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/457569401/will-code-malware-for-financial.html">Will Code Malware for Financial Incentives</source>
    </item>
    <item>
      <title><![CDATA[AF083-022: Visualization for Command and Control of Cyberspace Operations]]></title>
      <link>http://securityratty.com/article/04478e019cd46327427f88b45cf76a53</link>
      <guid>http://securityratty.com/article/04478e019cd46327427f88b45cf76a53</guid>
      <description><![CDATA[AF083-022 TITLE: Visualization for Command and Control of Cyberspace Operations
TECHNOLOGY AREAS: Air Platform, Information Systems, Space Platforms, Human Systems
The technology within this topic is...]]></description>
      <content:encoded><![CDATA[<p>AF083-022  TITLE: Visualization for Command and Control of Cyberspace Operations</p>
<p>TECHNOLOGY AREAS: Air Platform, Information Systems, Space Platforms, Human Systems</p>
<p>The technology within this topic is restricted under the International Traffic in Arms Regulation (ITAR), which controls the export and import of defense-related material and services. Offerors must disclose any proposed use of foreign nationals, their country of origin, and what tasks each would accomplish in the statement of work in accordance with section 3.5.b.(7) of the solicitation.</p>
<p>OBJECTIVE: Develop visualization techniques for planning and execution of Cyberspace operations.</p>
<p>DESCRIPTION: Fulfilling the Air Force mission “… to fly and fight in Air, Space, and Cyberspace” requires effective C2 tools for the observation, planning and execution of cyberspace operations. Conventional battlespace visualization tools were developed for the physical world (i.e., geospatially oriented), where the battlespace, weapons and effects are concrete, often observable entities. Cyberspace and its critical electronic infrastructures are an artificial world that must be created, modified and sustained by the warfighter. This artificial world of cyberspace has concrete links back to the physical world that shape the information landscape, affect the decision-making process, and control the communication channels crucial to C2.</p>
<p>Standard, geospatially oriented C2 tools are not suitable for providing cyber combatants with comparable situation awareness to understand events, evaluate options, and make decisions in the electromagnetic domain. The combatants in the cyber domain needs to be able to quickly see and understand not just the physical relationships of the traditional battlespace, but also the logical relationships and information dependencies in the abstract landscape of cyberspace. Cyber C2 visualizations need to provide information for strategy, tactics and execution of effects that may, or may not, have physical correlates. Examples of these cyber events include network attack detection, attack identification, damage assessment, denial of service (DOS) warnings, and information warfare or cyber-attack operations.</p>
<p>For example, a commander may be planning to intentionally disrupt a portion of his network to investigate a cyber-attack. He will need to understand what ripple effects will occur across the functionally diverse and geographically distributed network. These ripple effects will have both a cyber component (e.g., locations that will lose connectivity or suffer degraded performance characteristics) and a real-world component (e.g., information about enemy forces may be unavailable or delayed, reducing blue force effectiveness) that must be visualized, explored and tasked from within his C2 tools.</p>
<p>Decision makers will greatly benefit from innovative visualization tools that can improve their understanding of all aspects of the Cyber domain. These aspects include 1) the current state of the information environment, the physical and virtual battlespace and enemy and friendly capabilities and vulnerabilities; 2) the scope and scale of courses of action that affect information or information networks; 3) the primary effects and ripple effects of an operation in both the physical and cyber battlespaces, and 4) the risks for collateral damage associated with cyber warfare activities.</p>
<p>PHASE I: Identify cyberspace characteristics relevant to C2 visualization. Identify correlation methods and visualization techniques to understand battlespace, operations, and effects. Define metrics to evaluate efficacy. Document results in a written report, including mockups of proposed visualizations.</p>
<p>PHASE II: Construct a working prototype to demonstrate integrated visualization of cyber data showing 1) the status of information environment, 2) its effect on the conventional battlespace, and 3) the status of information operations. Evaluate effectiveness using metrics defined in Phase I.</p>
<p>PHASE III / DUAL USE: Military application: Additional military applications include command and control environments, like the Air Operations Centers (AOCs). Commercial application: Monitoring and defending infrastructures (e.g., financial and energy) against cyber-attacks. Visualization cyberspace is beneficial for security of commercial communication and information networks.</p>
<p>REFERENCES:</p>
<p>1. ‘<a href="www.af.mil/news/story.asp?id=123028524" target="_blank">Air Force leaders to discuss new ‘Cyber Command’</a></p>
<p>2. Laura S. Tinnel, O. Sami Saydjari, and Joshua W. Haines, An Integrated Cyber Panel System, IEEE Computer Society,</p>
<p>3. Anita D’Amico and Stephen Salas, Visualization as an Aid for Assessing the Mission Impact of Information Security Breaches, IEEE 2003.</p>
<p>4. Tim Bass, “<a href="http://www.silkroad-asia.com/d/node/34" target="_blank">Cyberspace Situational Awareness Demands Mimic Traditional Command Requirements</a>,” AFCEA Signal Magazine, February 2000.</p>
<p>KEYWORDS: visualization, cyber, human factors, planning, situation awareness, command and control, HCI</p>
<p>Reference. <a href="http://www.dodsbir.net/sitis/display_topic.asp?Bookmark=34486">SITIS Topic Details, Visualization for Command and Control of Cyberspace Operations</a></p>
<p>See also:  <a href="http://www.dodsbir.net/solicitation/sbir083/af083.doc">http://www.dodsbir.net/solicitation/sbir083/af083.doc</a></p>
]]></content:encoded>
      <pubDate>Fri, 17 Oct 2008 20:01:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/visualization">visualization</category>
      <category domain="http://securityratty.com/tag/information landscape">information landscape</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information operations">information operations</category>
      <category domain="http://securityratty.com/tag/operations">operations</category>
      <category domain="http://securityratty.com/tag/visualization techniques">visualization techniques</category>
      <category domain="http://securityratty.com/tag/develop visualization techniques">develop visualization techniques</category>
      <category domain="http://securityratty.com/tag/cyber-attack">cyber-attack</category>
      <category domain="http://securityratty.com/tag/cyber-attack operations">cyber-attack operations</category>
      <source url="http://www.thecepblog.com/2008/10/18/af083-022-visualization-for-command-and-control-of-cyberspace-operations/">AF083-022: Visualization for Command and Control of Cyberspace Operations</source>
    </item>
    <item>
      <title><![CDATA[Flaw in internet protocol core could disrupt almost any broadband connection device]]></title>
      <link>http://securityratty.com/article/1492ec3fdfb1fea641e9b9b53474b92a</link>
      <guid>http://securityratty.com/article/1492ec3fdfb1fea641e9b9b53474b92a</guid>
      <description><![CDATA[Security experts have discovered a flaw in a core internet protocol that can be exploited to disrupt just about any device with a broadband connection. The finding could have profound consequences for...]]></description>
      <content:encoded><![CDATA[Security experts have discovered a flaw in a core internet protocol that can be exploited to disrupt just about any device with a broadband connection. The finding could have profound consequences for millions of people who depend on websites, mail servers, and network infrastructure.
The bug in the transmission control protocol (TCP) affords attackers a wealth [...]]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 18:22:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/broadband connection">broadband connection</category>
      <category domain="http://securityratty.com/tag/transmission control protocol">transmission control protocol</category>
      <category domain="http://securityratty.com/tag/core internet protocol">core internet protocol</category>
      <category domain="http://securityratty.com/tag/network infrastructure">network infrastructure</category>
      <category domain="http://securityratty.com/tag/profound consequences">profound consequences</category>
      <category domain="http://securityratty.com/tag/security experts">security experts</category>
      <category domain="http://securityratty.com/tag/affords attackers">affords attackers</category>
      <category domain="http://securityratty.com/tag/mail servers">mail servers</category>
      <category domain="http://securityratty.com/tag/flaw">flaw</category>
      <source url="http://cyberinsecure.com/flaw-in-internet-protocol-core-could-disrupt-almost-any-broadband-connection-device/">Flaw in internet protocol core could disrupt almost any broadband connection device</source>
    </item>
    <item>
      <title><![CDATA[In-Flight VoIP Ban: Against FCC Rules? Highly Desirable?]]></title>
      <link>http://securityratty.com/article/04edfe3e5a28bd63c48bc3f4ded28db4</link>
      <guid>http://securityratty.com/article/04edfe3e5a28bd63c48bc3f4ded28db4</guid>
      <description><![CDATA[Think-tank wonders whether banning in-flight VoIP constitutes a violation of FCC rules about blocking services: The Progress and Freedom Foundation's Barbara Espin uses the ban on in-flight VoIP by...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://blog.pff.org/archives/2008/09/does_disclosure.html"><strong>Think-tank wonders whether banning in-flight VoIP constitutes a violation of FCC rules about blocking services:</strong></a> The Progress and Freedom Foundation's Barbara Espin uses the ban on in-flight VoIP by American Airlines (facilitated by provider Aircell) to make a broader argument about what she calls the FCC's "ad hoc approach to broadband network management issues." It's clever. American discloses that calling isn't allowed, and VoIP isn't even technically within the FAA or FCC's purview, as far as I can determine. The FAA could choose to regulate it as a safety issue. PFF generally tilts anti-regulation, and has as what it calls its "supporters" a broad area of multiple system cable operators and telecom firms, including Comcast, which was singled out and fined by the FCC for its undisclosed network disruption of P2P connections.</p>

<p><a href="http://www.nytimes.com/2008/09/14/business/14essay.html?_r=2&ei=5070&emc=eta1&oref=slogin&oref=slogin"><strong>Espin references Joe Sharkey's excellent column on in-flight calling in Sunday's New York Times:</strong></a> Sharkey, a veteran travel writer, who survived a mid-air collision over the Brazilian Amazon a few years ago, looks at varying attitudes about calls made during flights. He quotes Aircell's Jack Blumenstein saying what I've telling folks for months: Aircell has a lot of techniques to block VoIP calls already, and "as we identify new ways that people are trying to do voice calls on the airplane, we just kind of zero in and knock those off." Many geeks have assumed Aircell is a bunch of unsavvy folks who wouldn't be able to figure out how to disrupt their clever workarounds for making VoIP. (I keep noting that introducing jitter for suspicious data connections wouldn't disrupt legitimate applications, but would destroy VoIP call quality.)</p>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 05:50:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/in-flight voip constitutes">in-flight voip constitutes</category>
      <category domain="http://securityratty.com/tag/in-flight">in-flight</category>
      <category domain="http://securityratty.com/tag/in-flight voip">in-flight voip</category>
      <category domain="http://securityratty.com/tag/block voip calls">block voip calls</category>
      <category domain="http://securityratty.com/tag/fcc rules">fcc rules</category>
      <category domain="http://securityratty.com/tag/fcc">fcc</category>
      <category domain="http://securityratty.com/tag/voice calls">voice calls</category>
      <category domain="http://securityratty.com/tag/calls">calls</category>
      <source url="http://wifinetnews.com/archives/008444.html">In-Flight VoIP Ban: Against FCC Rules? Highly Desirable?</source>
    </item>
    <item>
      <title><![CDATA[Cost/Benefit of Terrorism Security]]></title>
      <link>http://securityratty.com/article/3ef2fe47ba64d2a4788b864a136d04e7</link>
      <guid>http://securityratty.com/article/3ef2fe47ba64d2a4788b864a136d04e7</guid>
      <description><![CDATA[The terrifying cost of feeling safer ,&quot; from the Sydney Morning Herald : Sandler and his colleagues conducted an analysis of the costs and benefits of five different approaches to combating terrorism....]]></description>
      <content:encoded><![CDATA[<p>"<a href="http://business.smh.com.au/business/the-terrifying-cost-of-feeling-safer-20080826-435l.html">The terrifying cost of feeling safer</a>," from the <i>Sydney Morning Herald</i>:</p>

<blockquote>Sandler and his colleagues conducted an analysis of the costs and benefits of five different approaches to combating terrorism. I must warn you that, because of the dearth of information, this study is even more reliant on assumptions than usual. Even so, in three cases the cost of the action so far exceeds the benefits that doubts about the reliability of the estimates recede.

<p>Because the loss of life is so low, they measure the benefits of successful counter-terrorism measures in terms of loss of gross domestic product avoided. Trouble is, terrorism does little to disrupt economic growth, as even September 11 demonstrated.</p>

<p>Using the case of the US, Sandler estimates that simply continuing the present measures involves costs exceeding benefits by a factor of at least 10. Adopting additional defensive measures (such as stepping up security at valuable targets) would, at best, entail costs 3.5 times the benefits. Taking more pro-active measures (such as invading Afghanistan) would have costs at least eight times the benefits.</p>

<p>According to Sandler, only greater international co-operation, or adopting more sensitive foreign policies to project a more positive image abroad, could produce benefits greater than their (minimal) costs.</p>

<p>What's that? You don't care what it costs because no one can put a value on saving a human life? Heard of opportunity cost? Taxpayers' money we waste on excessive counter-terrorism measures is money we can't spend reducing the gap between white and indigenous health -- or, if that doesn't appeal, on buying Olympic medals.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=HIz7L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=HIz7L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=8TfcL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=8TfcL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 12 Sep 2008 02:32:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/measures involves costs">measures involves costs</category>
      <category domain="http://securityratty.com/tag/costs">costs</category>
      <category domain="http://securityratty.com/tag/measures">measures</category>
      <category domain="http://securityratty.com/tag/cost">cost</category>
      <category domain="http://securityratty.com/tag/benefits">benefits</category>
      <category domain="http://securityratty.com/tag/produce benefits">produce benefits</category>
      <category domain="http://securityratty.com/tag/pro-active measures">pro-active measures</category>
      <category domain="http://securityratty.com/tag/entail costs">entail costs</category>
      <category domain="http://securityratty.com/tag/additional defensive measures">additional defensive measures</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/costbenefit_of.html">Cost/Benefit of Terrorism Security</source>
    </item>
    <item>
      <title><![CDATA[Web Based Botnet Command and Control Kit 2.0]]></title>
      <link>http://securityratty.com/article/4f945955ba8a424fe6b9352583602062</link>
      <guid>http://securityratty.com/article/4f945955ba8a424fe6b9352583602062</guid>
      <description><![CDATA[The average web based command and control kit for a botnet consisting of single user, single campaign functions only, has just lost its charm, with a recent discovery of a proprietary botnet kit whose...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SK7vNKA_3xI/AAAAAAAACFk/bFba_0dWvI4/s1600-h/web_botnet_cc_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SK7vNKA_3xI/AAAAAAAACFk/TqKIw6bxpjw/s200-R/web_botnet_cc_1.JPG" /></a>The average web based command and control kit for a botnet consisting of single user, single campaign functions only, has just lost its charm, with a recent discovery of a proprietary botnet kit whose features clearly indicate that the kit's coder know exactly which niches to fill - presumably based on his personal experience or market research into competing products.<br />
<br />
What are some its key differentiation factors? <b>Multitasking</b> at its best, for instance, the kits provides the botnet master with the opportunity to manage numerous different task such as several malware campaigns and DDoS attacks simultaneously, where each of these gets a separate metrics page.  <b>&nbsp;</b><br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8Bf1BEKoI/AAAAAAAACFs/Yicbw9alvSs/s1600-h/web_botnet_cc_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8Bf1BEKoI/AAAAAAAACFs/rzG7g1DxhQs/s200-R/web_botnet_cc_2.JPG" /></a><b>Automation</b> of malicious tasks, by setting up tasks, and issuing notices on the status of the task, when it was run and when it was ended. Just consider the possibilities for a scheduling malware and DDoS attacks for different quarters. <b>&nbsp;</b><br />
<br />
<b>Segmentation</b> in every aspect of the tasks, for instance, a DDoS attacks against a particular site can be scheduled to launched on a specific date from infected hosts based in chosen countries only. <b>&nbsp;</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8BqO4a_VI/AAAAAAAACF0/UMGxAh9uGF0/s1600-h/web_botnet_cc_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8BqO4a_VI/AAAAAAAACF0/ZlxV-mc44fM/s200-R/web_botnet_cc_3.JPG" /></a><b>Customized DDoS</b> in the sense of empowering the botnet master with point'n'click ability to dedicate a precise number of the bots to participate, which countries they should be based in, and for how long the attack should remain active. <b>Quality and assurance in DDoS attacks</b> based on the measurement of the bot's bandwidth against a particular country, in this case the object of the attack, so theoretically bots from neighboring countries would DDoS the country in question far more efficiently. <b>&nbsp;</b><br />
<br />
<a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8B0rE_rgI/AAAAAAAACF8/NKwLnKmmH44/s1600-h/web_botnet_cc_4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8B0rE_rgI/AAAAAAAACF8/pVosEgAltxk/s200-R/web_botnet_cc_4.JPG" /></a><b>Historical malware campaign performance</b>, is perhaps the most quality assurance feature in the entire kit, presumably created in order to allow the person behind it to measure which were the most effective malware and DDoS campaigns that he executed in the past. From an OSINT perspective, sacrificing his operational security by maintaing detailed logs from previous attacks is a gold mine directly establishing his relationships with previous malware campaigns.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8B8T36-3I/AAAAAAAACGE/BhFmeDoa8Lk/s1600-h/web_botnet_cc_5.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8B8T36-3I/AAAAAAAACGE/vij9THb60ow/s200-R/web_botnet_cc_5.JPG" /></a><b>Bot Description</b>:  &nbsp; <br />
<div dir="ltr" id="result_box">1. Completely invisible Bot work in the system.  <br />
2. Not loads system.  <br />
3. Invisible in the process.  <br />
4. Workaround all firewall.  <br />
5. Bot implemented as a driver.  </div><div dir="ltr" id="result_box"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CIQJHsKI/AAAAAAAACGM/SzpE6NqryP8/s1600-h/web_botnet_cc_6.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CIQJHsKI/AAAAAAAACGM/CptzW9_ji-k/s200-R/web_botnet_cc_6.JPG" /></a><b>Functions Bot</b> (constantly updated):&nbsp;</div><div dir="ltr" id="result_box">1. Downloading a file (many options). <br />
2. HTTP DDoS (many options, including http authentication).  </div><div dir="ltr" id="result_box"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CQZXzF1I/AAAAAAAACGU/LI52hSDJhpA/s1600-h/web_botnet_cc_7.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8CQZXzF1I/AAAAAAAACGU/AIaGhGUL0Fk/s200-R/web_botnet_cc_7.JPG" /></a><b>The web interface</b>&nbsp;</div><div dir="ltr" id="result_box">-- Convenient manager tasks. <br />
-- Every task can be stopped, put on pause, etc. ... <br />
-- Interest and visual scale of the task.&nbsp;&nbsp;</div><div dir="ltr" id="result_box">-- A task manager for DDoS and Loader <br />
&nbsp;&nbsp;&nbsp;&nbsp;</div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8Cvw3fTbI/AAAAAAAACGc/Zqcrn6XWYEw/s1600-h/web_botnet_cc_8.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SK8Cvw3fTbI/AAAAAAAACGc/0PQgE_timh4/s200-R/web_botnet_cc_8.JPG" /></a>-- <b>For DDoS tasks</b> </div><div dir="ltr" id="result_box">Bots involved in DDoS 'f. <br />
Condition of the victim (works, fell).  <br />
</div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8C5JVrIeI/AAAAAAAACGk/HNHO_ar0MgA/s1600-h/web_botnet_cc_9.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8C5JVrIeI/AAAAAAAACGk/Y1z0VIR3B9k/s200-R/web_botnet_cc_9.JPG" /></a>2. <b>Bots manager  </b><br />
-- Displays a list of bots (postranichno). <br />
-- Obratseniya date of the first and last. <br />
-- ID Bot. <br />
-- Country Bot. <br />
-- Type Bot. <br />
-- The status Bot (online / offline). <br />
-- Bot bandwidth to different parts of the world (europe, asia). <br />
-- The possibility of removing bots</div><div dir="ltr" id="result_box">-- When you click on ID Bot loadable still a wealth of information about it</div><div dir="ltr" id="result_box"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8D0Vm4XxI/AAAAAAAACGs/BM5pm1_Rtag/s1600-h/web_botnet_cc_11.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SK8D0Vm4XxI/AAAAAAAACGs/mQEa7wVxDNc/s200-R/web_botnet_cc_11.JPG" /></a>3. <b>Statistics botneta  </b><br />
-- Statistics both common and build Bot. <br />
-- Information on the growth and decline botneta dates (and build). <br />
-- Bots online <br />
-- All bots</div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div dir="ltr" id="result_box"><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8D6Gv_qnI/AAAAAAAACG0/JTOJS-ZHQek/s1600-h/web_botnet_cc_12.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SK8D6Gv_qnI/AAAAAAAACG0/ujbOfFEX9TA/s200-R/web_botnet_cc_12.JPG" /></a>-- Dead bots. <br />
<br />
4. <b>Statistics botneta country</b></div><div dir="ltr" id="result_box">-- All countries to work on&nbsp;</div><div dir="ltr" id="result_box">-- New work by country&nbsp;</div><div dir="ltr" id="result_box">-- Online work from country to country</div><div dir="ltr" id="result_box">-- Dead bots by country</div><div dir="ltr" id="result_box"></div><div dir="ltr" id="result_box">5. <b>Detailed history botneta</b>&nbsp;</div><div dir="ltr" id="result_box">6. <b>Convenient user-friendly interface adding teams</b> <br />
8. <b>Admin minimal server loads</b>  <br />
-- Use php5/mysql  <br />
</div><div dir="ltr" id="result_box"><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8EKSfrczI/AAAAAAAACG8/3oulo2cgTtM/s1600-h/web_botnet_cc_13.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SK8EKSfrczI/AAAAAAAACG8/xEI9xAwNGNM/s200-R/web_botnet_cc_13.JPG" /></a><b>Upcoming features : </b><br />
1. Form grabber (price increase substantially), for old customers will be charged as an upgrade <br />
2. Public key cryptography<br />
3. Clustering campaigns and DDoS attacks<br />
<br />
Despite it's proprietary nature, it's quality and innovative features will sooner or later leak out for everyone to take advantage of, a rather common lifecycle for the majority of proprietary malware kits in general.</div><div dir="ltr" id="result_box"><br />
<b>Related posts:</b></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/02/blackenergy-ddos-bot-web-based-c.html">BlackEnergy DDoS Bot Web Based<br />
</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html">A New DDoS Malware Kit in the Wild</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_20.html">The Cyber Bot - Web Based Malware</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_7672.html">The Black Sun Bot - Web Based Malware</a> </div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/09/custom-ddos-capabilities-within-malware.html">Custom DDoS Capabilities Within a Malware</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">Botnet on Demand Service</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/03/loadsccs-ddos-for-hire-service.html">Loads.cc - DDoS for Hire Service</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a>&nbsp;</div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/03/botnet-communication-platforms.html">Botnet Communication Platforms</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2008/04/botnet-masters-to-do-list.html">A Botnet Master's To-Do List</a></div><div dir="ltr" id="result_box"><a href="http://ddanchev.blogspot.com/2007/05/ddos-on-demand-vs-ddos-extortion.html">DDoS on Demand VS DDoS Extortion</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/how-does-botnet-with-100k-infected-pcs.html">How Does a Botnet with 100k Infected PCs Look Like?</a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Y5dBtK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Y5dBtK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WsNccK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WsNccK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ToV4Pk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ToV4Pk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=I6a7ak"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=I6a7ak" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2S7WNK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2S7WNK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Qk66sK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Qk66sK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8S5ask"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8S5ask" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/372102101" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 10:02:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ddos attacks based">ddos attacks based</category>
      <category domain="http://securityratty.com/tag/ddos attacks">ddos attacks</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/previous malware campaigns">previous malware campaigns</category>
      <category domain="http://securityratty.com/tag/ddos attacks simultaneously">ddos attacks simultaneously</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/country bot">country bot</category>
      <category domain="http://securityratty.com/tag/ddos">ddos</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/372102101/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</source>
    </item>
    <item>
      <title><![CDATA[Banker Malware Targeting Brazilian Banks in the Wild]]></title>
      <link>http://securityratty.com/article/4c146364a5e5366271bb42a4f795af8d</link>
      <guid>http://securityratty.com/article/4c146364a5e5366271bb42a4f795af8d</guid>
      <description><![CDATA[Despite the ongoing customerization of malware, and the malware coding for hire customer tailored services, certain malware authors still believe in the product concept, namely, they build it and wait...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKldLvANUBI/AAAAAAAACC8/4JM_2PVEVY4/s1600-h/banker_malware_brazil_banks.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKldLvANUBI/AAAAAAAACC8/zzcjUAMw61E/s200-R/banker_malware_brazil_banks.jpg" /></a>Despite the ongoing customerization of malware, and the malware coding for hire customer tailored services, certain malware authors still believe in the product concept, namely, they build it and wait for someone to come. In this underground proposition for a proprietary banker malware targeting primarily Brazillian bank, the author is relying on the localized value added to his malware forgetting a simply fact - that the most popular banker malware is generalizing E-banking transactions in such a way that it's successfully able to hijack the sessions of banks it hasn't originally be coded to target in general.<br />
<br />
<b>Banks targetted in this banker malware :</b><br />
<i>Bank Equifax<br />
Bank Itau<br />
Bank Check<br />
Bank Vivo<br />
Bank Banrisul<br />
Tim Bank Brazil<br />
Bank Nossa Caixa<br />
Bank Santander Banespa<br />
Bank Infoseg<br />
Bank Paypal <br />
Bank Caixa Economica Federal<br />
Bank Bradesco<br />
Bank Northeast<br />
Royal Bank<br />
Bank Itau Personnalite<br />
Bank PagSeguro<br />
Australia Bank<br />
Credicard Citi Bank<br />
Credicard Bank Itau<br />
Rural Bank</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKlgsZBqOLI/AAAAAAAACDE/kN2MQLJqjls/s1600-h/banker_malware_brazil_banks1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKlgsZBqOLI/AAAAAAAACDE/niBpSaKVaTE/s200-R/banker_malware_brazil_banks1.jpg" /></a>Taking into consideration the fact that not everyone would be willing to pay a couple of thousand dollars for a <a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">banker malware kit targeting banks the customer isn't interested in at the first place</a>, malware authors have long been tailoring their propositions on the basis of modules. Adding an additional module for stealtness increases the prices, as well as an additional module forwarding the process of updating the malware binary to the "customer support desk". Moreover, stripping the banker kit from modules in which the customer doesn't have interest, like for instance exclude all Asian banks the kit has already built-in capabilities to hijack and log transactions from, decreases its price.<br />
<br />
In a truly globalized IT underground, Brazillian cybercriminals tend to prefer using the <a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">market leading tools courtesy of Russian malware authors</a>, so this localized banker malware with its basic session screenshot taking capabilities and accounting data logging has a very long way to go before it starts getting embraced by the local underground.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/twitter-malware-campaign-wants-to-bank.html">The Twitter Malware Campaign Wants to Bank With You</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/targeted-spamming-of-bankers-malware.html">Targeted Spamming of Bankers Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/localized-bankers-malware-campaign.html">A Localized Bankers Malware Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/76service-cybercrime-as-service-going.html">76Service - Cybercrime as a Service Going Mainstream</a><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed "Spamming Appliances" - The Future of Spam</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UycytK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UycytK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=aWvyIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=aWvyIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KGP6hk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KGP6hk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1wZEOk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1wZEOk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PycnBK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PycnBK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KVzVsK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KVzVsK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XGelDk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XGelDk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/368038328" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 03:01:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/banker malware">banker malware</category>
      <category domain="http://securityratty.com/tag/banker malware kit">banker malware kit</category>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/popular banker malware">popular banker malware</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/bank itau personnalite">bank itau personnalite</category>
      <category domain="http://securityratty.com/tag/bank itau">bank itau</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/russian malware authors">russian malware authors</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/368038328/banker-malware-targetting-brazilian.html">Banker Malware Targeting Brazilian Banks in the Wild</source>
    </item>
    <item>
      <title><![CDATA[76Service - Cybercrime as a Service Going Mainstream]]></title>
      <link>http://securityratty.com/article/35bdaf104e9aecf7703834d959f39050</link>
      <guid>http://securityratty.com/article/35bdaf104e9aecf7703834d959f39050</guid>
      <description><![CDATA[Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKKs5L3ihpI/AAAAAAAACBs/vEaSMC2S8nI/s1600-h/76service.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKKs5L3ihpI/AAAAAAAACBs/qhgjQh39ej8/s200-R/76service.JPG" style="border: 0pt none ;" /></a>Disintermediating the intermediaries in the cybercrime ecosystem, ultimately results in more profitable operations. Controversial to the concept of outsourcing, some cybercriminals are in fact so self-sufficient, that the stereotype of a mysterious 76service server offered for rent could in fact easily cease to exist in an ecosystem so vibrant that literally everyone can partion their botnet and start offering access to it on a multi-user basis. Evil? Obviously. Extending the lifecycle of a proprietary malware tool? Definitely.<br />
<br />
<a href="http://www.youtube.com/watch?v=lw9IeuKkNbc">The infamous 76service</a>, a cybercrime as a service web interface where customers basically collect the final output out of the banking malware botnet during the specific period of time for which they've purchases access to the service, is going mainstream, with 76Service's Spring Edition apparently leaking out, and cybercriminals enjoying its interoperability potential by introducing different banking trojans in their campaigns. <br />
<br />
In this post, I'll discuss the 76service's spring.edition that has been combined with a <a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher banking malware</a>, an a popular <a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">web malware exploitation kit</a>, with two campaigns currently hosting 5.51GB of stolen banking data based on over 1 million compromised hosts 59% of which are based in Russia. Screenshots courtesy of an egocentric underground show-off.<br />
<br />
<a href="http://www.cio.com/article/print/135500">Some general info on the 76service</a> :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKyWAXgYGI/AAAAAAAACB0/JXHZFuBb6Rs/s1600-h/76service1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKyWAXgYGI/AAAAAAAACB0/2qZfVy6YfU8/s200-R/76service1.JPG" style="border: 0pt none ;" /></a>"<i>Subscribers could log in with their assigned user name and     password any time during the 30-day project. They’d be     met with a screen that told them which of their bots was     currently active, and a side bar of management options. For     example, they could pull down the latest drops—data     deposits that the Gozi-infected machines they subscribed to     sent to the servers, like the 3.3 GB one Jackson had     found. A project was like an investment portfolio. Individual     Gozi-infected machines were like stocks and subscribers bought     a group of them, betting they could gain enough personal     information from their portfolio of infected machines to make a     profit, mostly by turning around and selling credentials on the     black market. (In some cases, subscribers would use a few of     the credentials themselves). Some machines, like some stocks, would under perform and     provide little private information. But others would land the     subscriber a windfall of private data. The point was to     subscribe to several infected machines to balance that risk,     the way Wall Street fund managers invest in many stocks to     offset losses in one company with gains in another.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKy5q1ebVI/AAAAAAAACB8/uGe8GuhDvRg/s1600-h/76service2.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKKy5q1ebVI/AAAAAAAACB8/88IxypeBf74/s200-R/76service2.JPG" style="border: 0pt none ;" /></a>The 76service empowers everyone who is either not willing to spend time and resources for building and maintaining a botnet, launching campaigns, and SQL injecting hundreds of thousands of sites in order to take advantage of the long tail of malware infected sites that theoretically can outpace the traffic that could come from a SQL injected high-profile site.<br />
<br />
Next to the spring.edition, <a href="http://secureworks.com/research/threats/gozi/">the winter edition's price starts from $1000 and goes to $2000</a>, which is all a matter of who you're buying it from, unless of course you haven't come across leaked copies :<br />
<br />
"<i>Assuming that the dealer offering what he claimed was the 76service kit was correct, the profit is not only in the kit, but in selling value added services like exploitation, compromised servers/accounts, database configuration, and customization of the interface. Prices start between $1000 to $2000 and go up based on added services. The underground payment methods generally involve hard-to-track virtual currencies, whose central authority is in a jurisdiction where regulation is liberal to non-existent, and feature non-reversible transactions. The individual or group called "76service" was easy to track down on the Web, but not in person.</i>" <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKLUyA7g9LI/AAAAAAAACCE/nl-OA3FHPs0/s1600-h/76service3.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKLUyA7g9LI/AAAAAAAACCE/8zS6gcoEdvk/s200-R/76service3.JPG" style="border: 0pt none ;" /></a>It's interesting to monitor how services aiming to provide specific malicious services are vertically integrating by expanding their portfolio of related services -- taka a spamming vendor that will offer the segmented email databases, the advanced metrics, and the localization of the spam messages to different languages -- or letting the buyer have full control of anything that comes out of a particular botnet for a specific period of time in which he has bought access to it. For instance, DDoS for hire matured into botnet for hire, which evolved into today's "What type of stolen data do you want?" for hire mentality I'm starting to see emerging, next to the usual interest in improving the metrics and thereby the probability for a more succesful campaign. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKLa2TO4yAI/AAAAAAAACCM/4s3Mkgb-NOY/s1600-h/metafisher1_ukstories.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKLa2TO4yAI/AAAAAAAACCM/Bt7wKW7IPcE/s200-R/metafisher1_ukstories.jpg" style="border: 0pt none ;" /></a>Ironically, this cybercrime model is so efficient that the people behind it cannot seem to be able to process all of the stolen data, which like a great deal of underground assets loses its value if not sold as fast as possible. The result of this oversupply of stolen data are the increasing number of services selling raw logs segmented based on a particular country for a specific period of time.<br />
<br />
Time for a remotely exploitable vulnerability in yet another malware kit about to go mainstream? Definitely, unless of course backdooring it and releasing it doesn't achieve the obvious results of controlling someone else's cybercrime ecosystem.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed "Spamming Appliances" - The Future of Spam</a><br />
<br />
<b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NWhwdK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NWhwdK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7zGnyK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7zGnyK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rqgfok"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rqgfok" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zA7GDk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zA7GDk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4r7WMK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4r7WMK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=880FjK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=880FjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3wtOmk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3wtOmk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/363878623" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 04:08:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/76service">76service</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/malware botnet">malware botnet</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/mysterious 76service server">mysterious 76service server</category>
      <category domain="http://securityratty.com/tag/web service">web service</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/363878623/76service-cybercrime-as-service-going.html">76Service - Cybercrime as a Service Going Mainstream</source>
    </item>
    <item>
      <title><![CDATA[Coding Spyware and Malware for Hire]]></title>
      <link>http://securityratty.com/article/1dbd4bddd9e4248009d0273ad7cae5dd</link>
      <guid>http://securityratty.com/article/1dbd4bddd9e4248009d0273ad7cae5dd</guid>
      <description><![CDATA[What type of antivirus evasion do you want today? For the past several years, we have been witnessing the emerging customerization applied in malware and spyware for hire services. What used to be a...]]></description>
      <content:encoded><![CDATA[<div class="separator" style="text-align: left; clear: both;"><a href="http://bp2.blogger.com/_wICHhTiQmrA/SIWJkocpGwI/AAAAAAAAB8U/_v3hJOM2k_s/s1600-h/preview_random.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SIWJkocpGwI/AAAAAAAAB8U/15Yc8N_lG74/s200-R/preview_random.jpg" style="border: 0pt none ;" /></a></div>What type of antivirus evasion do you want today? For the past several years, we have been witnessing the emerging customerization applied in malware and spyware for hire services. What used to be a situation where the malware authors would code and then start promoting a piece of malware including features that he thinks his potential customers would want by generalizing a cybercriminal's needs, is today's "listening to the customer" win-win situation that they've reached already. <br />
<br />
The whole maturity from a product concept to customerization is in fact so prevalent these days, that malware authors wanting to preserve their intellectual property are forbidding their customers from reverse engineering their malware modules, presumably fearing that <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">remotely exploitable flaws like this one in one of the most popular Ebanker malwares for the last two yers Zeus</a>, could be discovered due to the malware author's insecure coding practices. Moreover, limiting the distribution of a single license they are given to more than three people will result in the malware author ignoring any future business relationships with the party that ruined the exclusiveness of the malware, thereby leaking it to the public, something that's been happening and will continue happening with web malware exploitation kits.<br />
<br />
What would be the price of a custom malware module coded on demand? How much does it cost to have a built in email harvester that would sniff all the incoming and outgoing email addresses from the infected host to later on include them in upcoming spam and malware campaigns? Would the malware author also provide a managed hosting service for the command and control and the actual binaries on a revenue sharing <br />
<br />
Here's an automatically translated, and fairly easy to understand random proposition for coding spyware and malware for hire, aiming to answer many of these questions, clearly demonstrating that today's malware is coded in exactly the same way the customer wants it to : <br />
<br />
"<i>As you can see in the history of its development turned directly into the combine, while almost no raspuh in weight, full-size pack аж 18 kb and minialno 5 kb, for all nampomnyu again, all descriptions below can be done as otdelnym bot, and any combination of cross except for a few restrictions. This product is targeted at mass-user and will not be all prodavatsya row. So, you can choose from:</i><br />
<br />
<i>Actually loader - is able to load a file from adminki, by country and other characteristics, such as the number of animals on board with a specific bot, a country group of countries, the availability of certain authors or Fire, sredenemu time online, etc. etc.. You can adjust the speed of shipping limits for each file, can load 1 as well as how files simultaneously<br />
300 €</i><br />
<br />
<i><b>FTP and not only Graber</b><br />
Analyzes user traffic and collects from the ftp acclamation, that is ftp acclamation would you regardless of how the customer uses ftp user, thus can be obtained most valuable ftp aka (even those to which the password is not saved), you can also grab other in a way not only acclamation acclamation and other tasty things more)<br />
150 €<b>&nbsp;</b></i><br />
<br />
<i><b>Assembler spam bases</b><br />
Analyzes user traffic and collects from all email, snifit http pop3 smtp protocols, keeps records unikallnosti locally on each boat to reduce the burden on the server as well as globally on a server has 2 mode of operation - ie passive with only collects user to please and active - the very beginning to download the entire inet) in search of soap<br />
220 €<br />
<br />
<b>Socks 4 / 5</b><br />
Normal soks with competently implemented multithreading, is activated only if the user real Ip, otherwise not. And also optional, depending on the connection type and speed ineta.<br />
70 €<br />
<br />
<b>Indicates</b><br />
The primitive method, contamination fleshek avtoranom gives 2-3% increase in the first week and up to 7% in the next, a pleasant trifle)<br />
35 €<br />
<br />
<b>Scripts</b><br />
Loader supports internal scripting language - jscript, to carry out arbitrary actions on the victim machine, whether recording data in the register, setting authentic hon-Pago, opening URL in your browser (it was done so to please with 90% punching)), apload arbitrary files on a server, even theoretically possible to form and grabing inzhekty in IE) has only to write the script zaebetes, vobschem lyuboye actions soul who wish)<br />
70 € basic functionality<br />
<br />
<b>Assembler passwords</b><br />
Collects data such as passwords pstorage IE, MSN, etc., will be added at the request of other sources of passwords<br />
70 €<br />
<br />
<b>Mini-AV</b><br />
When installing loadera wheelbarrows to remove BHO shaped three, zevso-shaped, the majority of shit from all avtoranov, render most keylogerov until all) forward proposals to improve<br />
70 €<br />
<br />
<b>File-default</b><br />
In exe loadera program URL (in adminke) to the file which once progruzit 1 and run at first start loadera on wheelbarrows, while simultaneously helping progruzke Trojan for example, in its entire botnet that does not paired with challenges in adminke, the module operates in 20 seconds after the mini - av which excludes the removal of your Trojan bot, after progruza this exe bot continues to normal activities.<br />
35 €<br />
<br />
<b>Form Graber</b><br />
While in beta version, robbed IE. Sends logs in adminku, folding country. Logs are like logs agent. It consists of:<br />
<br />
<b>Graber certificats</b><br />
On the idea is part formgrabera but could work and of itself, actually there is nothing to describe)<br />
<br />
<b>Injections</b><br />
Literacy sold inzhekty, did not begin work after full progruza pages (as in bolshistve three) and immediately supported injection yavaskript code, which allows avtozalivy and DC inzhekty for data collection. For example not to yuzat acclamation at all is not yet introduce the necessary number of Britain, after which inzhekt ceases to operate. Вобщем mdelat can be anything and in any form) rather than the meager request field pin) And also inzhektov subspecies - a substitute for the issuance of search enginee.<br />
<br />
<b>Graber balances</b><br />
Makes loot aka balances at the entrance to the user acclamation, detail added to the logs.<br />
<br />
<b>Screen</b><br />
Universal method to grab information from absolutely any species and varieties klaiviatur screens, in particular html, flash, in one picture, with a drop-down fields after choosing your encrypted, as well as information such as "enter 3 yu secret letter word" etc. as well as any information which is visible a user but not seen in the logs. Screen settings of adminki, set URL where do screen as well as the type of screen: for virtual keyboard (done several small images of areas around the clique) or to "enter 3 yu secret letter words" (makes 1 full shot). With the withdrawal screen recorded in the log entry with the name of the file to the screen this position.<br />
<br />
<b>Antiabuznost for botneta</b><br />
Feachem adminki, keep botnet enables fast, normal, bezglyuchnyh NEabuzoustoychivyh hosting, with features that you forget what abuzy, nohistory week saporta "abuzoustoychivogo" hosting inaccessibility host to half ineta etc., etc., also with the help of the supplement will be able to keep huge botnety (over SL) at 1 dedike with 512 Lake) and well on the price of hosting a savings, not $ 500 a month and 150. It may use this feature to stroronnim development, Trojans, bots, etc., actually is a separate product. And incidentally, if you do not understand the theory that nenado ask "and how does it work?" imagine that it works and point and neubivaemo in pritsnipe.<br />
600 € +<br />
&nbsp;</i><br />
<i>All prices are in euros, the calculation is made at the rate of CB on the day of purchase. ps I will not disappear as most authors after months of sales, I DONT how to please you get to the assembly ftp, I DONT how many soap collects soap-graber, I DONT what otstuk from loadera, I DONT soksov how many will be from 1 to downloads, and how best To work load a file is not dead quickly, if you are confused my ignorance - that my loader so you do not need more tries)<br />
<br />
Rules / Licence<br />
-- Customer has no right to transfer any of his three 3 persons except options for harmonizing with me<br />
-- Customer does not have the right to make any decompile, research, malicious modification of any three parts<br />
-- Customer has no right where either rasprostanyat information about three and a public discussion with the exception of three entries.<br />
-- For violating the rules - without any license denial manibekov and further conversations</i>" <br />
<br />
This malware coder seems to be participating in an affiliate program with a malicious ISP that is offering hosting services for the entire campaign, not just the malware binaries, so you have a rather good example that incentives and revenue-sharing models result in value-added services, a all-in-one shop for a customer to take advantage of without bothering to approach a third-party.<br />
<br />
Cybercrime is getting even more easier to outsource these days, and with the malicious parties improving their communication and incentives model, the resulting transparency in the underground market<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/russias-fsb-vs-cybercrime.html">Russia's FSB vs Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">Localizing Open Source Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/quality-and-assurance-in-malware.html">Quality and Assurance in Malware Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2006/09/benchmarking-and-optimising-malware.html">Benchmarking and Optimising Malware</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CfEGOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CfEGOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZmZP2J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZmZP2J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3RDQbj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3RDQbj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uN1LUj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uN1LUj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oSzTOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oSzTOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KOIqZJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KOIqZJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8gh7xj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8gh7xj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/342366718" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 23:52:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware author">malware author</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware binaries">malware binaries</category>
      <category domain="http://securityratty.com/tag/malware attacks">malware attacks</category>
      <category domain="http://securityratty.com/tag/ftp">ftp</category>
      <category domain="http://securityratty.com/tag/ftp user">ftp user</category>
      <category domain="http://securityratty.com/tag/collects">collects</category>
      <category domain="http://securityratty.com/tag/malware industry">malware industry</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/342366718/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</source>
    </item>
    <item>
      <title><![CDATA[Summarizing June's Threatscape]]></title>
      <link>http://securityratty.com/article/520325188c71fdacd3f86834feb1cdc5</link>
      <guid>http://securityratty.com/article/520325188c71fdacd3f86834feb1cdc5</guid>
      <description><![CDATA[June's threatscape that I'll summarize in this post based on all the research conducted during the month, was a very vibrant one. With the return of GPcode, a remotely exploitable flaw in the Zeus...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"><a href="http://bp3.blogger.com/_wICHhTiQmrA/SGoHvxfg0WI/AAAAAAAAB3M/6CMFS1Q1zGQ/s1600-h/ddanchev.jpg" imageanchor="1" style="clear: left; border-right: 0pt; border-top: 0pt; float: left; margin-bottom: 1em; border-left: 0pt; margin-right: 1em; border-bottom: 0pt; background-color: transparent;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SGoHvxfg0WI/AAAAAAAAB3M/WskmE9LDFvE/s200-R/ddanchev.jpg" style="border-right: 0pt; border-top: 0pt; border-left: 0pt; border-bottom: 0pt;" /></a>June's threatscape that I'll summarize in this post based on all the research conducted during the month, was a very vibrant one. With the return of GPcode, a remotely exploitable flaw in the Zeus crimeware kit allowing both, researchers and malicious parties to assess the severity of a particular banker malware campaign, the increasing use of malicious doorways next to ICANN and IANA's DNS hijacking, all speak for themselves and how diverse the threats and, of course, the abilities to maintain a decent situatiational awareness about what's going on have become.</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>01.</b>&nbsp; <a href="http://ddanchev.blogspot.com/2008/06/uks-crime-reduction-portal-hosting.html">U.K's Crime Reduction Portal Hosting Phishing Pages</a> - nothing new here since vulnerable sites are to be "remotely file included" and SQL injected to locally host anything on behalf of a malicious party. Risk and responsibility forwarding is one thing, but having a crime reduction portal hosting phishing pages is entirely another. The phishing pages was shut down in less than 12 hours upon notification</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>02.</b> <a href="http://ddanchev.blogspot.com/2008/06/price-discrimination-in-market-for.html">Price Discrimination in the Market for Stolen Credit Cards</a> - Tracking down "yet another stolen credit cards for sale" service in the wild, the price discremination that they applied greatly reflects the current lack of transpararency for a potential buyer of stolen credit cards, and how higher profit margins are driving the entire business model. With script kiddies running their own botnets and undermining the sophisticated botnet master's high profit margin business model by undercutting their prices, stolen credit cards are not what they used to be - an exclussive good. Nowadays, they are a commodity good and often a bargain</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>03.</b> <a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a> - Sampling an active blackhat SEO campaign out of the hundreds of thousands currently active online, releaved a large portfolio of domains serving Zlob variants by pitching them as fake codecs that the end user should download if they are to view the non existent adult content at the sites. Where's the OSINT mean? It's in the fact that the codecs and the fake security software phone back to UkrTeleGroup Ltd's network</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>04.</b> <a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a> - With the current oversupply of malware infected hosts, and botnet masters embracing the services model for anything malicious, in this post I discussed the radical security approach of puchasing already infected malware hosts on a per country basis, disinfecting them and forcing them to update all the software on the infected PCs. Of course, on an opt-in basis. The possibility to directly provide incentives for botnet hunters to shut down whatever they come across to on a daily basis, and that's a lot of botnets, is also there</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>05.</b> <a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html">Who's Behind the GPcode Ransomware?</a> - The title speaks for itself, the research with enough actionable intelligence gathered in the shortest timeframe possible is already proving accurate and highly valuable. How come? Stay tuned for more developments</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>06.</b> <a href="http://ddanchev.blogspot.com/2008/06/imageshack-typosquatted-to-serve.html">ImageShack Typosquatted to Serve Malware</a> - In a rare instance of a creative attack combining typosquatting in order to impersonate ImageShack and serve malware by redirecting users to an image file that is actually forwarding to the binary, I was recently tipped by the folks at TrendMicro who are also following this that the site is up and running again. Not for long</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>07.</b> <a href="http://ddanchev.blogspot.com/2008/06/fake-youtube-site-serving-flash.html">Fake YouTube Site Serving Flash Exploits</a> - Next to using the usual set of exploits courtesy of a commodity web malware exploitation kit, this campaign was also using flash exploits. Even more interesting is the fact that the password stealer obtained was attempting to phone back to a misconfigured malware command and control interface, basically allowing you to assess the campaign from the eyes of the "campaigner"</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>08.</b> <a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</a> - Web site defacements are getting monetized just like SQL injections are in order to locally host a blackhat search engine optimization campaign on a vulnerable site with a high page rank. In this post I've assessed such monetization courtesy of a web site defacer at The Africa Middle Market Fund</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>09.</b> <a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a> - Yet another large domains portfolio exposed though a malicious doorway redirecting to fake porn and video sites serving Zlob variants, tracking down the initial spamming of the malicious doorways across multiple vulnerable forums and guestbooks </div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>10.</b> <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a> - When cyber criminals get advised to patch their vulnerable versons of the Zeus Crimeware Kit, you know there's a monoculture in the crimeware market. This flaw released publicly in May, 2008, not just allows others to hijack someone's ebanking botnet, but also, vendors and researchers to better assess a vulnerable Zeus command and control location</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>11.</b> <a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a> - When templates for fake video and adult sites are just as available as they are now, anyone can take advantage of this cheap social engineering track that seems to work just fine. Compared to relying on blackhat search optimization to acquire traffic, some of the campaigns were SQL injected at vulnerable sites in order to drive traffic to them, next to several other tactics which when combined can result in a lot of people unknowingly visiting the sites </div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>12.</b> <a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">Phishing Campaign Spreading Across Facebook</a> - An internal phishing campaign was circulating across Facebook, which got taken care of thanks to coordinated efforts with Facebook's security folks. There's also an indicating tha they are currently typosquatting other social networking sites like Hi5 for instance</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>13.</b> <a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a> - As a firm believed in taking a random sample for a particular threat segment, this was once of these cases confirming the confidence I've built into anticipating upcoming tactics and strategies to be used </div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>14.</b> <a href="http://ddanchev.blogspot.com/2008/06/update-to-photobuckets-dns-hijacking.html">An Update to Photobucket's DNS Hijacking</a> - Despite that Photobucket didn't oficially acknowledge the DNS hijacking, the hosting provider the NetDevilz hacking team used issued a statement. Ironically, the Turkish hacking group used the same provider weeks later to redirect ICANN and IANA's domains to Atspace.com</div>
<div style="text-align: left;"><b>15.</b> <a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a> - Among the largest domains portfolio of malware serving porn sites I've exposed in a while, all of them naturally remain active since they are hosted on a partition of RBN's diverse network. Visualizing a malicious doorway or the entire ecosystem provides a better understanding at how structured the ecosystems are</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<b>16.</b> <a href="http://ddanchev.blogspot.com/2008/06/backdoording-cyber-jihadist-ebooks-for.html">Backdoording Cyber Jihadist Ebooks for Surveillance Purposes</a> - Despite that in this case we have a cyber jihadist backdoording his own released books, the international intelligence community next to law enforcement are known to have expressed interest in backdooring suspect's PCs, so why not SQL inject the cyber jihadist forums themselves?<br />
<b>17.</b> <a href="http://ddanchev.blogspot.com/2008/06/right-wing-israeli-hackers-deface.html">Right Wing Israeli Hackers Deface Hamas's Site</a> - When you read that Hamas's site is hacked, you ask yourself the following, do they even have a web site that's up the running? The answer to which would be the fact that even Hezbollah has been maintaining an Internet infrastructure since 1998 <br />
<b>18.</b> <a href="http://ddanchev.blogspot.com/2008/06/icann-and-ianas-domain-names-hijacked.html">ICANN and IANA's Domain Names Hijacked by the NetDevilz Hacking Group</a> - A fact is a fact, no comment here, go through all the technical details of the hijacking, including some actionable intelligence on who's behind the hijacking<br />
<b>19.</b> <a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The Malicious ISPs You Rarely See in Any Report</a> - Who's tolerating malicious activities on their network, and how is the RBN related to all this? Well, when combined, the tiny parts of these ISPs represent a tiny part of the Russian Business Network itself<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Arx0SJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Arx0SJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5olcEJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5olcEJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=a2BAsj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=a2BAsj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=H5lz4j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=H5lz4j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MYqzVJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MYqzVJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1PoM3J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1PoM3J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=d9Ilyj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=d9Ilyj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/323996877" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 03:05:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/fake youtube site">fake youtube site</category>
      <category domain="http://securityratty.com/tag/web site defacements">web site defacements</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware hosts">malware hosts</category>
      <category domain="http://securityratty.com/tag/web site defacer">web site defacer</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/vulnerable sites">vulnerable sites</category>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/323996877/summarizing-junes-threatscape.html">Summarizing June's Threatscape</source>
    </item>
  </channel>
</rss>
