<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: downloader]]></title>
    <link>http://securityratty.com/tag/downloader</link>
    <description></description>
    <pubDate>Thu, 06 Mar 2008 07:50:57 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Fake Porn Sites Serving Malware - Part Three]]></title>
      <link>http://securityratty.com/article/df6f06139a5c1a6029631a2d5221d428</link>
      <guid>http://securityratty.com/article/df6f06139a5c1a6029631a2d5221d428</guid>
      <description><![CDATA[Continue the Fake Porn Sites Serving Malware and Fake Porn Sites Serving Malware - Part Two series, in part three we'll take a peek at the emerging trend of parking a single domain at up to three...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQENtZvVWI/AAAAAAAACHU/3Th9wGTcre4/s1600-h/fake_porn_zlob_codec_localized.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQENtZvVWI/AAAAAAAACHU/1aZSLqClTi4/s200-R/fake_porn_zlob_codec_localized.JPG" /></a>Continue the <a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a> and <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a> series, in part three we'll take a peek at the emerging trend of parking a single domain at up to three different hosting locations, re-establishing connections between malicious ISPs for yet another time in between exposing the domains and the download locations sharing the same IPs.<br />
<br />
<b>downlfreesexgirlbeach .com</b> first redirects to <b>infodist1 .com/in.cgi?2 </b>then to <b>watchnenjoy.com/index.php?id=1314&amp;style=black</b>, and finally to the front end to the codec's download location <b>handmadeclips .com</b>, where the codec is downloaded from <b>fwlprocedure .com</b>.  Behind these domains, we can easily expose many other fake porn sites and pharmaceutical scams, next to a small portfolio of domains specifically used for hosting the binaries. Due to the obvious rotation I've encountered several times so far, a fake porn site today, is tomorrow's blackhat SEO content farm :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQHSj0XVWI/AAAAAAAACHc/DX-IaOAduVs/s1600-h/fake_porn_august.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQHSj0XVWI/AAAAAAAACHc/k9h1_E21wag/s200-R/fake_porn_august.JPG" /></a><b>downlfreesexgirlbeach .com</b> - (88.214.198.25)<br />
<b>vids365 .com<br />
downlfreesexgirlbeach .com<br />
top.only-bi .com<br />
wikiei .com<br />
paysuperporn .com<br />
aboutsexporn .com<br />
freactor .com<br />
cheapofficialpills .com<br />
finance-leaders.comnudenakedboys .com<br />
photosgayboys&nbsp; .com<br />
uniqueincest.com<br />
shyincest .com<br />
banrnd.central-xxx .com<br />
tvisklick .info<br />
thebg .net<br />
termion .net<br />
xoxvids .net<br />
bestpricepills .net<br />
bcodecnow .net</b><br />
<br />
<b>infodist1 .com</b> - (88.214.204.40)<br />
<b>farmasearch2008 .com<br />
flaxxvid .com<br />
xanax777pills .com<br />
18virgingirls .com<br />
girlnudegallaryvideox .com<br />
allxxxpornogerlsx .com<br />
jproshin .info<br />
familytaboo .info<br />
fullsitehost .info<br />
20searchonlinesite .net<br />
add-your-video .net<br />
blogs4y .net</b><br />
<br />
<div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SLQIspjO3tI/AAAAAAAACHs/MaMXiAw02F8/s1600-h/downlfreesexgirlbeach_viz.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SLQIspjO3tI/AAAAAAAACHs/znHGKTmbcHE/s200-R/downlfreesexgirlbeach_viz.JPG" /></a><b>adult-shemale .com</b> - (88.214.198.25)<br />
<b>adult-tranny .com<br />
all-shemale&nbsp; .com&nbsp;&nbsp;&nbsp; <br />
bcodecnow .net<br />
best-tranny .com&nbsp;&nbsp;&nbsp; <br />
bestguyportal .com<br />
bestmoviez .com&nbsp;&nbsp;&nbsp; <br />
central-xxx .com<br />
downlfreesexgirlbeach .com&nbsp;&nbsp;&nbsp; <br />
gallery-boy .com<br />
hiosexywomensxxxgirlsx .com&nbsp;&nbsp;&nbsp; <br />
lady-dick .com<br />
bcodecnow .net<br />
mytoppharmacy .com<br />
nakednudeboys .com&nbsp;&nbsp;&nbsp; <br />
nakednudemen .com<br />
nudenakedboys .com<br />
only-bi .com<br />
only-shemale .com<br />
page-reviews .com<br />
paulaslosingit .com<br />
photosgayboys .com<br />
stud-boys .com&nbsp;&nbsp;&nbsp; <br />
the0download .com<br />
wikiei .com&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; <br />
moviez .com<br />
hiosexywomensxxxgirlsx .com<br />
sexygirlsisuniformh0t .com&nbsp;&nbsp;&nbsp; <br />
the0download .com</b><br />
<br />
<b>flwprocedure .com </b>- (77.91.231.201)<b><br />
movupdate .com<br />
flwupdate .com<br />
formatmpeg .com<br />
movieexternal .com<br />
flwtool .com <br />
aviexecution .com<br />
releasedvideo .com<br />
wmvcompressor .com<br />
movieopens .com<br />
mpegapparatus .com<br />
flwassistant .com<br />
flwinstrument .com<br />
piterserv .com<br />
wovview .com</b><br />
<br />
<b>Some info on a sample codec :</b><br />
Scanners Result: 11/36 (30.56%)<br />
Trojan-Downloader.Win32.Zlob.cos<br />
Trojan.Popuper.7315<br />
File size: 10240 bytes <br />
MD5...: 467e4e78974dc8b2ee5d7da024daf31a <br />
SHA1..: 311e0c710bb15761ef3dace54b55489830cf5803<br />
<br />
Phones back to <b>69.50.164.50</b>/this/is/stereo/music.php?param=0;1314;1550; <b>69.50.164.50</b>/this/is/stereo/jazz.php?param=49325611;2:191:5|7:271:0|6:130:0|9:0:5|34:65536:0 and to <b>85.255.119.244</b>/this/is/stereo/music.php?param=0;4135;1548.<br />
<br />
When <b>Emil Kaperski's</b> owned <a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">InterCage, Inc.</a> (69.50.164.50) meets <a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">UkrTeleGroup Ltd.</a> (85.255.119.244) previously known as <b>Andrei Kislizin's</b> owned InHoster, you know you're on the right track.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kUs27K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kUs27K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sRXTAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sRXTAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sOsoWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sOsoWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fnooek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fnooek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R3T9kK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R3T9kK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WaKp6K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WaKp6K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R12pRk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R12pRk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/375241515" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 05:02:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <category domain="http://securityratty.com/tag/codec">codec</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/sample codec">sample codec</category>
      <category domain="http://securityratty.com/tag/locations">locations</category>
      <category domain="http://securityratty.com/tag/fake porn site">fake porn site</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/375241515/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Three</source>
    </item>
    <item>
      <title><![CDATA[Compromised Web Servers Serving Fake Flash Players]]></title>
      <link>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</link>
      <guid>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</guid>
      <description><![CDATA[The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/SSFpGnP3wvA/s1600-h/fake_flash1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/qKqvrWeAN3s/s200-R/fake_flash1.png" style="border: 0pt none ;" /></a>The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so much confidence in this risk-forwarding process of hosting their campaigns, that they would start actively spamming the links residing within low-profile legitimate sites across the web.<br />
<br />
This campaign serving fake flash players is getting so prevalent these days due to the multiple spamming approaches used, that it's hard not to notice it - and expose it. From a strategic perspective, having a legitimate low-profile site -- of course with the obvious exceptions being on purposely registered for malicious purposes within the participating sites -- hosting your malicious campaign is pretty creative in terms of forwarding the responsibility, and the eventual blocking of a legitimate site to the its owner. As far as the owner's are concerned, it appears that some of them are already seeing the malware page popping-up on the top of their daily traffic stats, and have taken measures to remove it.<br />
<br />
Moreover, <a href="http://blogs.adobe.com/psirt/2008/08/verifying_installers.html">Adobe's Product Security Incident Response Team (PSIRT) issued a warning notice about the attack yesterday</a>, which could come handy if the <a href="http://www.infoworld.com/article/08/08/05/Adobe_warns_of_bogus_Flash_Player_installers_1.html">attackers weren't taking advantage of client-side vulnerabilities</a>, putting the unware end user is a situation where he <a href="http://blogs.stopbadware.org/articles/2008/08/05/same-dogs-new-tricks">wouldn't even receive a download dialog</a> :<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/LuFjz3rFLAc/s1600-h/fake_flash3_exploit.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/GXwA3Ai1LLY/s200-R/fake_flash3_exploit.jpg" style="border: 0pt none ;" /></a>"<i>We have seen coverage from the security community of a worm on popular social networking sites that is using social engineering lures to get users to install a piece of malware. According to the reports, the worm posts comments on these sites that include links to a fake site. If the link is followed, users are told they need to update their Flash Player. The installer, posted on a malicious site, of course installs malware instead of Flash Player.We’d like to take this opportunity to reiterate the importance of validating installers and updates before installing them. First off, do not download Flash Player from a site other than adobe.com – you can find the link for downloading Flash Player here. This goes for any piece of software (Reader, Windows Media Player, Quicktime, etc.) – if you get a notice to update, it’s not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious.</i>"<br />
<br />
<a href="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/6PfKZxTNQao/s1600-h/fake_flash2.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/ADBheDs2hkk/s200-R/fake_flash2.png" style="border: 0pt none ;" /></a>The structure of the malware campaign is pretty static, with several exceptions where they also take advange of client-side vulnerabilities (Real player exploit) attempting to automatically deliver the fake flash update or player depending on the campaign. On each and every site, there are <b>dnd.js</b> and <b>master.js</b> scripts shich serve the rogue download window, and another .html file, where an IFRAME attempts to access the traffic management command and control, in a random URL it was <b>207.10.234.217/cgi-bin/index.cgi?user200</b>. A sample list of participating URLs, most of which are still active and running :<br />
<br />
<div style="text-align: left;"><b>joseantoniobaltanas .com</b></div><b>automoviliaria .es/hotnews.html<br />
risasnc .it/fresh.html<br />
carpe-diem .com.mx/fresh.html<br />
kotilogullari .com.tr/hotnews.html<br />
ferrariclubpesaro .it/hotnews.html<br />
imobiliariacom .com.br/default.html<br />
misoares .com<br />
osniehus .de/fresh.html<br />
mydirecttube .com/1/5098/<br />
madosma .com/default.html<br />
tutotic .com/checkit.html<br />
veit-team .si/default.html<br />
antigewaltkurse .de/stream.html<br />
kwhgs .ca/topnews.html<br />
vorgo .com/stream.html<br />
ankaraspor .com.tr/default.html<br />
xxxdnn0314 .locaweb.com.br/watchit.html<br />
ossuzio .com/watchit.html<br />
cit-inc .net/default.html<br />
negocioindependiente .biz/default.html<br />
ambermarketing .com/topnews.html<br />
web27 .login-7.loginserver.ch/stream.html<br />
moretewebdesign .br-web.com/stream.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/hotnews.html<br />
campodifiori .it/topnews.html<br />
212.50.55.81 /stream.html<br />
logisigns .net/fresh.html<br />
intimaescorts .com/default.html<br />
ghioautotre .it/live.html<br />
geckert .de/stream.html<br />
yuricardinali .com/watchit.html<br />
retder .com/fresh.html<br />
valdaran .es/default.html<br />
getadultaccess .com/movie/?aff=5274<br />
bauelemente-giering .de/stream.html<br />
newyork-hebergement .com/watchit.html<br />
allevatoritrotto .it/live.html<br />
exoss2 .com/hotnews.html<br />
soundandlightkaraoke .com/stream.html<br />
land-kan .com/stream.html<br />
grimaldi.nexenservices .com/watchit.html<br />
inconstancia .com.br/watchit.html <br />
gretelstudio .com/stream.html<br />
sumacyl .com/watchit.html<br />
mysna .net/fresh.html<br />
gimnasioyx .com.ar/watchit.html<br />
lagalbana .com/watchit.html<br />
bielizna.tgory .pl/topnews.html<br />
bcs92.imingo .net/stream.html<br />
lapiramidecoslada .es/topnews.html<br />
raulortega .com/stream.html<br />
go-art-morelli .de/hotnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
dianagraf .es/default.html<br />
komma10-thueringen .de/hotnews.html<br />
miavassilev .com/stream.html<br />
swampgiants .com/watchit.html<br />
compagniedephalsbourg .com/fresh.html<br />
arla-rc .net/hotnews.html<br />
salacopernico .es/watchit.html<br />
drfinster .de/checkit.html<br />
healthylifehypnotherapy .com/stream.html<br />
ecotrike-bg .com/fresh.html<br />
paoepalavra .org/watchit.html<br />
jureplaninc-sp .com/topnews.html<br />
fichte-lintfort .de/default.html<br />
hergert-band .de/checkit.html<br />
izliyorum .org/topnews.html<br />
lideka .com/stream.html<br />
athena-digitaldesign .com.tw/hotnews.html<br />
e-paso .pl/stream.html<br />
colombeblanche .org/stream.html<br />
teatromalasa .es/watchit.html<br />
mesporte.digiweb.com .br/stream.html<br />
bistrodavila.com .br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
jbhumet .com/default.html<br />
gruppouni .com/hotnews.html<br />
francex .net/fresh.html<br />
galvatoledo .com/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
kroenert .name/default.html<br />
textilhogarnovadecor .com/topnews.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
neticon .pl/hotnews.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
easterstreet .de/fresh.html<br />
piogiovannini .com.ar/watchit.html<br />
ser-all .com/topnews.html<br />
petzold-dieter .de/checkit.html<br />
beatmung-brandenburg .de/checkit.html<br />
ossuzio .com/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
zelenaratolest .cz/pornotube/index1.htm<br />
ambulatoriovirtuale .it/topnews.html<br />
10a3 .ru/index1.php<br />
izliyorum .org/topnews.html<br />
collectedthoughts .co.uk/index12.html<br />
afg .es/topnews.html<br />
albertruiz .net/topnews.html<br />
bielizna.tgory .pl/topnews.html<br />
blueseven.com .br/topnews.html<br />
bollettinogiuridicosanitario .it/topnews.html<br />
caprilchamonix.com .br/topnews.html<br />
carlolongarini .it/topnews.html<br />
champimousse .com/topnews.html<br />
cheviot.org .nz/topnews.html<br />
contrapie .com/topnews.html<br />
gruppouni .com/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
herbatele .com/topnews.html<br />
houseincostaricaforsale .com/topnews.html<br />
alim.co .il/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
amafe .org/topnews.html<br />
ambulatoriovirtuale .it/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
automoviliaria .es/topnews.html<br />
autoreserve .fr/topnews.html<br />
izliyorum .org/topnews.html<br />
jureplaninc-sp .com/topnews.html<br />
kwhgs .ca/topnews.html<br />
lapiramidecoslada .es/topnews.html<br />
last-minute-reisen-4u .de/topnews.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
corradiproject .info/topnews.html<br />
dantealighieriasturias .es/topnews.html<br />
deliriuslaspalmas .com/topnews.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/topnews.html<br />
fonavistas .com/topnews.html<br />
fraemma .com/topnews.html<br />
fundmyira .com/topnews.html<br />
galvatoledo .com/topnews.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
markmaverick .com/topnews.html<br />
micela .info/topnews.html<br />
motoclubnosvamos .com/topnews.html<br />
nebottorrella .com/topnews.html<br />
negozistore .it/topnews.html<br />
neticon .pl/topnews.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
segelclub-honau .de/topnews.html<br />
snmobilya .com/topnews.html<br />
splashcor .com.br/topnews.html<br />
stephanmager .gmxhome.de/topnews.html<br />
svcanvas .com/topnews.html<br />
tautau.web .simplesnet.pt/topnews.html<br />
textilhogarnovadecor .com/topnews.html<br />
theflorist4u .com/topnews.html<br />
thewindsorhotel .it/topnews.html<br />
vuelosultimahora .com/topnews.html<br />
aliarzani .de/topnews.html<br />
ambermarketing .com/topnews.html<br />
arnold82.gmxhome .de/topnews.html<br />
ocoartefatos.com .br/topnews.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
projetsoft .net/topnews.html<br />
rbc.gmxhome .de/topnews.html<br />
beatmung-sachsen .eu/topnews.html<br />
campodifiori .it/topnews.html<br />
clickjava .net/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
dammer .info/topnews.html<br />
embedded-silicon .de/topnews.html<br />
ferrariclubpesaro .it/topnews.html<br />
fgwiese .de/topnews.html<br />
fswash.site .br.com/topnews.html<br />
fytema .es/topnews.html<br />
gildas-saliou. com/topnews.html<br />
go-art-morelli .de/topnews.html<br />
go-siegmund .de/topnews.html<br />
guerrero-tuning .com/topnews.html<br />
gut-barbarastein .de/topnews.html<br />
japansec .com/topnews.html<br />
komma10-thueringen .de/topnews.html<br />
koon-design .de/topnews.html<br />
lanz-volldiesel .de/topnews.html<br />
lauscher-staat .de/topnews.html<br />
losnaranjos.com .es/topnews.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
nepi.si/topnews .html<br />
radieschenhein. de/topnews.html<br />
residenceflora .it/topnews.html<br />
sabuha .de/topnews.html<br />
ser-all .com/topnews.html<br />
siemieniewicz .de/topnews.html<br />
viajesk .es/topnews.html<br />
allevatoritrotto .it/live.html<br />
bollettinogiuridicosanitario .it/live.html<br />
carlolongarini .it/topnews.html<br />
maremax .it/topnews.html<br />
negozistore .it/topnews.html<br />
parapendiolestreghe .it/live.html<br />
www.donlisander .it/stream.html<br />
aerogenesis .net/watchit.html<br />
allevatoritrotto .it/live.html<br />
atelier-de-loulou .fr/topnews.html<br />
bistrodavila.com .br/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
caprilchamonix.com .br/topnews.html<br />
cheviot.org .nz/live.html<br />
condorautocenter .com.br/watchit.html<br />
dantealighieriasturias .es/live.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/live.html<br />
fonavistas .com/topnews.html<br />
fundmyira .com/topnews.html<br />
g6esporte .com.br/stream.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
gretelstudio .com/stream.html<br />
gutierrezymoralo .com/watchit.html<br />
healthylifehypnotherapy .com/stream.html<br />
herbatele .com/live.html<br />
jureplaninc-sp .com/topnews.html<br />
lacomercialsrl .com.ar/stream.html<br />
lagalbana .com/watchit.html<br />
lapuertaestrecha .com.es/watchit.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
myadultcube .com/flash//aff=5176<br />
myadultcube .com/flash//aff=5810<br />
myadultcube .com/movie//aff=5155<br />
newyork-hebergement .com/watchit.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
omdconsulting .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
parapendiolestreghe .it/live.html<br />
regesh. co.il/watchit.html<br />
rikkeroenneberg .dk/watchit.html<br />
s215847279 .onlinehome.fr/stream.html<br />
salacopernico .es/watchit.html<br />
seekzones .com/watchit.html<br />
seicomsl .es/watchit.html<br />
sigma-lux .ro/watchit.html<br />
soundandlightkaraoke .com/stream.html<br />
stephanmager.gmxhome .de/topnews.html<br />
tartuinstituut .ca/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
aliarzani .de/topnews.html<br />
ambermarketing. com/live.html<br />
bilbondo .com/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
colombeblanche .org/stream.html<br />
donlisander .it/stream.html<br />
fgwiese .de/topnews.html<br />
geckert .de/stream.html<br />
helene-taucher .de/watchit.html<br />
lanz-volldiesel .de/topnews.html<br />
mairie-margnylescompiegne .fr/watchit.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
ossuzio .com/watchit.html<br />
piogiovannini .com.ar/watchit.html<br />
sabuha .de/topnews.html<br />
sumacyl .com/watchit.html<br />
swampgiants .com/watchit.html<br />
xn--glland-3ya .de/stream.html<br />
yuricardinali .com/watchit.html</b><br />
<b>nepi .si/topnews.html<br />
dammer .info/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
galvatoledo .com/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
micela .info/topnews.html<br />
bistrodavila .com.br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
gruppouni .com/hotnews.html<br />
galvatoledo .com/topnews.html<br />
kroenert .name/default.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
dantealighieriasturias .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
89.19.29 .13/stream.html<br />
slobodandjakovic .com/fresh.html<br />
cqcs.com .br/stream.html<br />
seekzones .com/watchit.html<br />
pascosa .it/stream.html<br />
caprilchamonix .com.br/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
ferien-urlaub-lastminute .de/default.html<br />
mueggelpark .info/watchit.html<br />
hillner-online .de/fresh.html<br />
guiasaojose .net/default.html<br />
deliriuslaspalmas .com/topnews.html<br />
fraemma .com/topnews.html<br />
morsbaby .net/default.html<br />
vickywhite .com/fresh.html<br />
micela .info/topnews.html<br />
corradiproject .info/topnews.html<br />
liguehavraise .com/live.html<br />
capacitacaoemlideranca .com.br/fresh.html<br />
materialesyacabados .com.mx/stream.html<br />
208.112.7.68 /checkit.html<br />
152.10.1.37 /1.html<br />
carlolongarini .it/topnews.html<br />
splashcor.com .br/topnews.html<br />
lobpreisstrasse .org/1.html<br />
motoclubnosvamos .com/hotnews.html<br />
hk-rc.com /1.html<br />
taaf.re /stream.html<br />
dulceysalao .com/default.html<br />
amafe .org/topnews.html <br />
</b><br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/MTxnF1XLDCw/s1600-h/fake_flash3_rogue_software.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/3Dgh4x23dRs/s200-R/fake_flash3_rogue_software.png" style="border: 0pt none ;" /></a>Sample detection rate : <span id="status_nombre">flashupdate.exe</span><br />
<span id="status_nombre"><b>Scanners Result</b>: 35/36 (97.23%)</span><br />
<span id="status_nombre">Trojan-Downloader.Win32.Exchanger.hk; Troj/Cbeplay-A</span><br />
<b>File size</b>: 78848 bytes<br />
<b>MD5</b>...: c81b29a3662b6083e3590939b6793bb8<br />
<b>SHA1</b>..: d513275c276840cb528ce11dd228eae46a74b4b4<br />
<br />
The downloader then "phones back home" at <b>72.9.98.234 port 443 </b>which is responding to the rogue security software AntiSpy Spider (<b>antispyspider.net</b>) :<br />
<br />
"<i>AntiSpy Spider is a cutting-edge anti-spyware solution.This revolutionary anti-spyware program was created by the industry's top spyware experts in order to protect your computer and your privacy.html, while ensuring optimal system performance.With the ability to locate, eliminate and prevent the widest range of spyware threats, AntispyStorm is able to offer its users a safe, spyware-free computing experience; and with it's convenient automatic update feature, AntispyStorm ensures continuous up-to-date protection.</i>" <br />
<br />
Sample detection rate : antispyspider.msi<br />
<b>Scanners Result</b>: 11/35 (31.43%)<br />
FraudTool.Win32.AntiSpySpider.b;&nbsp; <br />
<b>File size</b>: 1851904 bytes<br />
<b>MD5</b>...: 2f1389e445f65e8a9c1a648b42a23827<br />
<b>SHA1</b>..: e32aa6aa791e98fe6fdef451bd3b8a45bad0acd8<br />
<br />
The bottom line - over a thousand domains are participating, with many other apparently joining the party proportionally with the web site owner's actions to get rid of the malware campaign hosted on their servers.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BvcTqK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BvcTqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=onawHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=onawHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fa1ek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fa1ek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5nQAgk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5nQAgk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sqdHIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sqdHIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mq3LKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mq3LKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8zplkk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8zplkk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/356677080" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 10:50:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/html file">html file</category>
      <category domain="http://securityratty.com/tag/html">html</category>
      <category domain="http://securityratty.com/tag/comtopnews">comtopnews</category>
      <category domain="http://securityratty.com/tag/detopnews">detopnews</category>
      <category domain="http://securityratty.com/tag/windows media player">windows media player</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/real player exploit">real player exploit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/356677080/compromised-web-servers-serving-fake.html">Compromised Web Servers Serving Fake Flash Players</source>
    </item>
    <item>
      <title><![CDATA[Blackhat SEO Redirects to Malware and Rogue Software]]></title>
      <link>http://securityratty.com/article/2199017f7c1af4461b71026dc303b308</link>
      <guid>http://securityratty.com/article/2199017f7c1af4461b71026dc303b308</guid>
      <description><![CDATA[A black SEO farm with built-in redirection to a multitude of sites serving rogue codecs (Zlob malware variants) and fake security software phoning back to UkrTeleGroup Ltd's network - could it get...]]></description>
      <content:encoded><![CDATA[<div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SEe1DIDe2DI/AAAAAAAABxI/dNKrE60D00g/s1600-h/pornotubedirect1.JPG"><img id="BLOGGER_PHOTO_ID_5208330559383590962" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SEe1DIDe2DI/AAAAAAAABxI/dNKrE60D00g/s200/pornotubedirect1.JPG" border="0" /></a>A black SEO farm with built-in redirection to a multitude of sites serving rogue codecs (Zlob malware variants) and <a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">fake security software</a> phoning back to <a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">UkrTeleGroup Ltd's</a> network - could it get even more interesting? Of course, as the current state of Zlob malware serving tactics can be seperated in two distinct groups, those abusing the <a href="http://ddanchev.blogspot.com/2008/05/malware-attack-exploiting-flash-zero.html">"sort of" zero day Flash exploit</a>, as the currently <a href="http://ddanchev.blogspot.com/2008/05/yet-another-massive-sql-injection.html">active SQL injection attacks</a> are all taking advantage of it, and those still relying on plain simple redirect to multimedia sites requiring you to install the fake codec.<br /><br /><br /><div><div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SEe3eSO6t8I/AAAAAAAABxQ/GtMaVRNVy4E/s1600-h/blackhat_SEO_visualized.JPG"><img id="BLOGGER_PHOTO_ID_5208333224995633090" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/SEe3eSO6t8I/AAAAAAAABxQ/GtMaVRNVy4E/s200/blackhat_SEO_visualized.JPG" border="0" /></a>While tracking down the <a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">massive blackhat SEO poisoning campaigns</a> that took place in March, 2008, as well as the countless number of embedded/injected malware campaigns targeting high profile sites that we've been seeing recently, it's becoming increasingly common to come across a repeating malicious pattern. Basically, a <a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">domain portfolio of typosquatted domains</a> looking like legitimate codec sites is created, several bogus video, mostly p0rn related sites with no content start acting as a frontend to the codecs, where traffic is driven through blackhat SEO doorways. Moreover, rogue codec sites are increasing because the templates for the p0rn and codec sites are turning into a commodity, just like phishing pages and DIY phishing page generators lowering down the entry barriers into these practices.</div><br /><div><br /></div><div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SEfKn96fT7I/AAAAAAAABxY/kbygMpNzS54/s1600-h/blackhat_seo_codecs3.png"><img id="BLOGGER_PHOTO_ID_5208354282060861362" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SEfKn96fT7I/AAAAAAAABxY/kbygMpNzS54/s200/blackhat_seo_codecs3.png" border="0" /></a>Let's assess a sample redirection doorway, a visualization and sample traffic of which you can see in the attached screenshots. At <strong>porntubedirect.info </strong>we have a fake counter <strong>porntubedirect.info/stat/count.php</strong> loading the redirection script from <strong>216.240.139.234/sutra/in.cgi?3</strong> which is a javascript serving a different site on-the-fly, courtesy of a well known blackhat SEO campaign tool. The output of this redirection is a new domain serving Zlob variants in the form of fake codecs hosted under the following domains :</div><br /><div><strong>antivirus-scanonline.com</strong><br /></div><div><strong>indafuckfuck.com</strong></div><strong>newcontents2008.com</strong><br /><div><strong>avwav.com</strong></div><strong>anykindclips.com</strong><br /><div><strong>dirtyxxxvids.com</strong></div><strong>clipsmachines.com</strong><br /><div><strong>thesoft-portal-08.com</strong></div><br /><div>Sample detecton rates for the codecs obtained :<br /></div><div><br /></div><div>Scanners Result: 8/32 (25%)</div><span style="font-weight: bold;">W32/PolyZlob!tr.dldr; Trojan:Win32/Tibs.gen!lds</span><br /><div>File size: 119296 bytes </div>MD5...: dc5538af557cb4c311cb86d6574400ba<br /><div>SHA1..: 5cf1602db8c4fdd3c5ac5101e5a6c5daa77f5ff1</div><br /><div>Scanners Result: 6/32 (18.75%)<br /></div><div style="font-weight: bold;">Trojan-Downloader.Win32.FraudLoad.axa; Trojan.Dldr.FraudLoad.axa</div>File size: 60416 bytes<br /><div>MD5...: 14938bfe35128687e05f7f8ccbd29c7d </div>SHA1..: cf651e959fff945c9659321e79ba2788062b721d<br /><div><br /></div><div>Scanners Result: 14/32 (43.75%)</div><span style="font-weight: bold;">Trojan-Downloader.Win32.Zlob.lps; TrojanDownloader:Win32/Zlob.IB</span><br /><div>File size: 18432 bytes</div>MD5...: 9b3bbcd4549970a92eb1b11c46a451bb<br /><div>SHA1..: 679508aba4e547935d5e4104a735c754b40de49e</div><br /><div>Scanners Result: 18/32 (56.25%)<br /></div><div style="font-weight: bold;">Trojan-Downloader.Win32.Delf.ilx; TrojanDownloader:Win32/Chengtot.A</div>File size: 91683 bytes<br /><div>MD5...: 727e3f353281229128fdb1728d6ef345</div>SHA1..: 3f9c9000b273e8bf75db322382fbaabf333faf26<br /><div><br />Once we've managed to obtain several of the fake codec domains, passive DNS monitoring and using third-party tools helps us expose a huge portfolio of rogue domains such as :</div><br /><div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SEfM81C3WTI/AAAAAAAABxo/whvBq4dE_sE/s1600-h/blackhat_seo_codecs1.png"><img id="BLOGGER_PHOTO_ID_5208356839480580402" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SEfM81C3WTI/AAAAAAAABxo/whvBq4dE_sE/s200/blackhat_seo_codecs1.png" border="0" /></a><span style="font-weight: bold;">funfuckporn.com</span> <span style="font-weight: bold;"><br />musicpo</span><span style="font-weight: bold;">rtalfree.com</span> <span style="font-weight: bold;"><br />online-dvdrip.com</span> <span style="font-weight: bold;"><br />widget-porn.com</span> <span style="font-weight: bold;"><br />gt-funny.com</span> <span style="font-weight: bold;"><br />gt-movies.com</span><br /><span style="font-weight: bold;">gt-stars.com</span> <span style="font-weight: bold;"><br />hot-sextube.com</span> <span style="font-weight: bold;"><br />hot-pornotube-2008.com</span> <span style="font-weight: bold;"><br />hot-pornotube08.com</span> <span style="font-weight: bold;"><br />hotpornotube08.com</span> <span style="font-weight: bold;"><br />porn-youtube-08.org</span> <span style="font-weight: bold;"><br />uriy.org</span> <span style="font-weight: bold;"><br />sextube20008.com</span> <span style="font-weight: bold;"><br /></span><span style="font-weight: bold;">streamxxxvideo.com</span><br /><span style="font-weight: bold;">xxxgirlsgirls.com</span> <span style="font-weight: bold;"><br />porno-tube20008.com</span> <span style="font-weight: bold;"><br />2008adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />2008adults2008.com</span> <span style="font-weight: bold;"><br />adult18tube2008.com</span> <span style="font-weight: bold;"><br />sextube18adult.com</span> <span style="font-weight: bold;"><br />all-videos-home.com</span><br /><span style="font-weight: bold;">adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />onlinestreamvide.com</span> <span style="font-weight: bold;"><br />adultvideos4all.com</span> <span style="font-weight: bold;"><br />sex18tube2008.com</span> <span style="font-weight: bold;"><br />adultxx-18.com</span> <span style="font-weight: bold;"><br />mymediasex.com</span><br /><span style="font-weight: bold;">ladyxxxworld.com</span><br /><span style="font-weight: bold;">adultstreamportal.com</span> <span style="font-weight: bold;"><br />young-girls-board.com</span> <span style="font-weight: bold;"><br />porn-youtube08.net</span><br /><span style="font-weight: bold;">adultfreemarket.info</span> <span style="font-weight: bold;"><br />adult-codec08.com  </span> <span style="font-weight: bold;"><br />adult-tubecodec08.com   </span> <span style="font-weight: bold;"><br />adult-tubecodec2008.com   </span> <span style="font-weight: bold;"><br />adulthot-codec08.com   </span> <span style="font-weight: bold;"><br />adulttubecodec2008.com </span> <span style="font-weight: bold;"><br />hot-tubecodec20.com </span> <a href="http://bp2.blogger.com/_wICHhTiQmrA/SEfMyTsY63I/AAAAAAAABxg/ZtiCEo6OWi8/s1600-h/blackhat_seo_codecs2.png"><img id="BLOGGER_PHOTO_ID_5208356658729249650" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/SEfMyTsY63I/AAAAAAAABxg/ZtiCEo6OWi8/s200/blackhat_seo_codecs2.png" border="0" /></a><span style="font-weight: bold;"><br />media-tubecodec2008.com </span> <span style="font-weight: bold;"><br />porn-tubecodec20.com</span> <span style="font-weight: bold;"><br />hot-sextubecodec.com</span> <span style="font-weight: bold;"><br />sexporntubecodec14.com </span> <span style="font-weight: bold;"><br />sexporntubecodec32.com</span> <span style="font-weight: bold;"><br />sexporntubecodec77.com </span> <span style="font-weight: bold;"><br />sexporntubecodec98.com </span> <span style="font-weight: bold;"><br />adult-codec08.com</span><br /><span style="font-weight: bold;">adult-codec2008.com</span> <span style="font-weight: bold;"><br />adult-tubecodec08.com</span> <span style="font-weight: bold;"><br />adult-tubecodec2008.com</span> <span style="font-weight: bold;"><br />adulthot-codec08.com</span> <span style="font-weight: bold;"><br />adulthot-codec20008.com</span> <span style="font-weight: bold;"><br />adulthot-codec2008.com</span> <span style="font-weight: bold;"><br />adulthotcodec032008.com</span> <span style="font-weight: bold;"><br />adulthotcodec072008.com</span> <span style="font-weight: bold;"><br />adulthotcodec092008.com</span> <span style="font-weight: bold;"><br />adulthotcodec29018.com</span> <span style="font-weight: bold;"><br />adulthotcodec29098.com</span> <span style="font-weight: bold;"><br />adulttubecodec2008.com</span> <span style="font-weight: bold;"><br />media-tubecodec2008.com</span> <span style="font-weight: bold;"><br />sexhotcodec09.com</span> <span style="font-weight: bold;"><br />sexhotcodec1.com</span> <span style="font-weight: bold;"><br />sexhotcodec11.com</span> <span style="font-weight: bold;"><br />sexhotcodec12.com</span> <span style="font-weight: bold;"><br />sexhotcodec90.com</span> <span style="font-weight: bold;"><br />thehotcodec21.com</span> <span style="font-weight: bold;"><br />thehotcodecgt.com</span> <span style="font-weight: bold;"><br />thehotcodechq.com</span><br /><span style="font-weight: bold;">thehotcodeclk.com</span> <span style="font-weight: bold;"><br />thehotcodecrt.com</span><br /><span style="font-weight: bold;">thehotcodecxx.com</span><br /><span style="font-weight: bold;">thehotcodeczz.com</span><br /><br />What you see is not always what you get online, however, the infrastructure providers in the majority of malware campaigns tend to remain the same.<br /></div><div> </div></div></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NNJ0dI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NNJ0dI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fngtI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fngtI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sC7SZi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sC7SZi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GqEr0i"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GqEr0i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZhU6uI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZhU6uI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uOADsI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uOADsI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=337i4i"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=337i4i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/305310836" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 03:59:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/profile sites">profile sites</category>
      <category domain="http://securityratty.com/tag/multimedia sites">multimedia sites</category>
      <category domain="http://securityratty.com/tag/codec sites">codec sites</category>
      <category domain="http://securityratty.com/tag/zlob variants">zlob variants</category>
      <category domain="http://securityratty.com/tag/zlob">zlob</category>
      <category domain="http://securityratty.com/tag/zlob malware variants">zlob malware variants</category>
      <category domain="http://securityratty.com/tag/rogue codec sites">rogue codec sites</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/305310836/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</source>
    </item>
    <item>
      <title><![CDATA[These are real nasties folks, be afraid, be very afraid]]></title>
      <link>http://securityratty.com/article/850189ee08a6871ef4916db1e7cc852b</link>
      <guid>http://securityratty.com/article/850189ee08a6871ef4916db1e7cc852b</guid>
      <description><![CDATA[Read the article to see what came in 3rd. Its actually the one Ive seen most talked about in Forums and Blogs


clipped from www.marketwire.com

BitDefender Lab Reveals Top Three E-Threats in May


...]]></description>
      <content:encoded><![CDATA[<div > Read the article to see what came in 3rd. Its actually the one Ive seen most talked about in Forums and Blogs. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/9F44C613-DA45-46CF-93BC-40F3556A0EB9/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/9743831d-fe8d-4238-884b-88d6290f60db/9F44C613-DA45-46CF-93BC-40F3556A0EB9/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.marketwire.com/mw/release.do?id=864498" href="http://www.marketwire.com/mw/release.do?id=864498" style="font-size: 11px;">www.marketwire.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.marketwire.com/mw/release.do?id=864498 -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">BitDefender Lab Reveals Top Three E-Threats in May</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.marketwire.com/mw/release.do?id=864498 --><P><br />
The top menace of the month is Trojan.Clicker.CM, a<br />
pop-up-ad-serving trojan distributed via infected websites. In order to<br />
successfully display the pop-ups containing advertisements, the trojan has<br />
the ability to bypass the Norton Internet Security Pop-up Blocker.<br />
</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.marketwire.com/mw/release.do?id=864498 --><P><br />
In second place is Trojan.Downloader.WMA.Wimad.N. Despite the<br />
complicated-sounding name, this trojan serves a very simple function: to<br />
load another piece of malware. It does so by pretending to be a helper<br />
application that downloads a &#8220;codec&#8221; playing a &#8220;special type&#8221; of WMA file.<br />
Once the user is tricked, it downloads and runs Adware.PlayMp3z.A, an<br />
application meant to take personal information from the computer and use it<br />
for marketing or suspicious practices. When executed, the adware displays a<br />
pop-up with an EULA, in an attempt to convince users of its legitimacy.<br />
</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/9F44C613-DA45-46CF-93BC-40F3556A0EB9/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Wed, 04 Jun 2008 19:42:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trojan serves">trojan serves</category>
      <category domain="http://securityratty.com/tag/trojan">trojan</category>
      <category domain="http://securityratty.com/tag/wma">wma</category>
      <category domain="http://securityratty.com/tag/wma file">wma file</category>
      <category domain="http://securityratty.com/tag/runs adware">runs adware</category>
      <category domain="http://securityratty.com/tag/convince users">convince users</category>
      <category domain="http://securityratty.com/tag/downloads">downloads</category>
      <category domain="http://securityratty.com/tag/top menace">top menace</category>
      <category domain="http://securityratty.com/tag/suspicious practices">suspicious practices</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=468">These are real nasties folks, be afraid, be very afraid</source>
    </item>
    <item>
      <title><![CDATA[Malware Attack Exploiting Flash Zero Day Vulnerability]]></title>
      <link>http://securityratty.com/article/90a9f39245301cfd0e3b9867b6a9b0be</link>
      <guid>http://securityratty.com/article/90a9f39245301cfd0e3b9867b6a9b0be</guid>
      <description><![CDATA[It's been a while since we've last witnessed malware attacks using zero day vulnerabilities, and the latest one exploiting a zero day in Adobe's flash player is definitely worth assessing. The current...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SDx0V-zK7ZI/AAAAAAAABvw/1OVWctHnjZ8/s1600-h/adobe_zeroday_2008.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SDx0V-zK7ZI/AAAAAAAABvw/1OVWctHnjZ8/s200/adobe_zeroday_2008.JPG" alt="" id="BLOGGER_PHOTO_ID_5205163190317149586" border="0" /></a>It's been a while <a href="http://ddanchev.blogspot.com/2008/02/malicious-advertising-malvertising.html">since we've last witnessed</a> malware attacks using zero day vulnerabilities, and the latest one exploiting a zero day in Adobe's flash player is definitely worth assessing. The current malware attack has been traced back to Chinese blackhats, who are using a zero day to infect users with password stealers, moreover, one of the domains serving the Adobe zero day has been sharing the same IP with four of the malware domains in the recent waves of <a href="http://ddanchev.blogspot.com/2008/05/malware-domains-used-in-sql-injection.html">massive SQL injection attacks</a>, indicating this incident and the previous ones are connected. <a href="http://www.symantec.com/security_response/threatcon/index.jsp">According to Symantec</a> :<br /><br />"<span style="font-style: italic;">Preliminary investigation suggests that the DeepSight honeynet may also have captured this attack. We are looking into this further. Currently two Chinese sites are known to be hosting ex</span><span style="font-style: italic;">ploits for this flaw: <span style="font-weight: bold;">wuqing17173.cn</span> and <span style="font-weight: bold;">woai117.cn</span>. The sites appear to be exploiting the same flaw, but are using different payloads. At the moment these domains do not appear </span><span style="font-style: italic;">to be resolving, but they may come back in the future. Network administrators are advised to blacklist these domains to prevent clients from inadvertently being redirected to them. Avoid browsing to untrustworthy sites. Also, consider disabling Flash or use some sort of script-blocking mechanism, such as NoScript for Firefox, to explicitly allow SWFs to run only on trusted sites. </span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SDx7-uzK7aI/AAAAAAAABv4/eaYrPHOlwjk/s1600-h/adobe_zeroday_1_2008.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SDx7-uzK7aI/AAAAAAAABv4/eaYrPHOlwjk/s200/adobe_zeroday_1_2008.JPG" alt="" id="BLOGGER_PHOTO_ID_5205171586978213282" border="0" /></a>The Internet Storm Center also <a href="http://isc.sans.org/diary.html?storyid=4465">made an announcement</a> and assessed a <a href="http://isc.sans.org/diary.html?storyid=4468">malware domain that was using the exploits</a> in this case<span style="font-weight: bold;"> play0nlnie.com</span> (125.46.104.172), next to <a href="http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html">Adobe's Product Security Inci</a><a href="http://blogs.adobe.com/psirt/2008/05/potential_flash_player_issue.html">dent Response Team (PSIRT)</a> original announcement of the vulnerability. What about the original hosting sites for this exploits? Are they still active and serving it, what are the detection rates of the exploits and the malware served, and are there any other domains that should be blocked, also responding to the same IPs.<br /><br />Let's assess the campaign using the <a href="http://www.securityfocus.com/bid/29386">Adobe Flash Player SWF File Unspecified Remote Code Execution Vulnerability</a>. At <span style="font-weight: bold;">count18.wuqing17173.cn/click.aspx.php</span> (58.215.87.11) the end user is receiving a look looks like a 404 error message, however, within the 404 message there's a great deal of information exposing the exploits location and participation domains, which you can see attached in the screenshot above. In between several obfuscations we are finally able to locate the exploits serving host, as there are multiple exploits this particular campaign is taking advatange of, in between the Adobe Flash Player one :<br /><br /><span style="font-weight: bold;">0novel.com /real.js</span> <span style="font-weight: bold;"><br />0novel.com /rl.htm</span> <span style="font-weight: bold;"><br />0novel.com /lz.htm</span> <span style="font-weight: bold;"><br />0novel.com /bf.htm</span> <span style="font-weight: bold;"><br />0novel.com /xl.htm</span> <span style="font-weight: bold;"><br />0novel.com /flash.swf</span> <span style="font-weight: bold;"><br />0novel.com /flash1.swf</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SDx_bezK7bI/AAAAAAAABwA/DJQvH46M_aU/s1600-h/fake_404_error_message.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SDx_bezK7bI/AAAAAAAABwA/DJQvH46M_aU/s200/fake_404_error_message.jpg" alt="" id="BLOGGER_PHOTO_ID_5205175379434335666" border="0" /></a>Let's get back to the second domain which is not returning a valid 403 error forbidden message, <span style="font-weight: bold;">woai117.cn</span> (221.206.20.145) which has also been sharing the same IP with <span style="font-weight: bold;">kisswow.com.cn</span>; <span style="font-weight: bold;">qiqi111.cn</span>; <span style="font-weight: bold;">ririwow.cn</span>; <span style="font-weight: bold;">wowgm1.cn</span>, among the domains used in <a href="http://ddanchev.blogspot.com/2008/05/malware-domains-used-in-sql-injection.html">the ongoing SQL injection attacks</a>. Once the binary located at <span style="font-weight: bold;">woai117.cn /bak.exe</span> was obtained and sandboxed, it tried to download more malware by accessing <span style="font-weight: bold;">woai117.cn /kiss.txt</span> with the following binaries already obtained, analyzed and distributed among AV vendors :<br /><br /><span style="font-weight: bold;">117276.cn /1.exe</span> <span style="font-weight: bold;"><br />117276.cn /2.exe</span> <span style="font-weight: bold;"><br />117276.cn /3.exe</span> <span style="font-weight: bold;"><br />woai117.cn /bing.exe</span><br /><br />Detection rates for the exploit, the obfuscations and the malware binaries obtained :<br /><br /><span style="font-weight: bold;">Sample obfuscation</span><br />Scanners result : 3/32 (9.38%)<br />F-Secure - Exploit.JS.Agent.oa<br />GData - Exploit.JS.Agent.oa<br />Kaspersky - Exploit.JS.Agent.oa<br />File size: 35767 bytes<br />MD5...: 11d2b82a35cd37560673680f25571bac<br />SHA1..: 687066c90bb44fee574f2763041ee80dfee4d5bf<br /><br /><span style="font-weight: bold;">A sample flash file with the exploit</span><br />Scanners result : 2/32 (6.25%)<br />eSafe - SWF.Exploit<br />Symantec - Downloader.Swif.C<br />File size: 846 bytes<br />MD5...: 1222bf4627894cb88142236481680d03<br />SHA1..: bbf59d9e6610e6f982a7ce7fc9e9878ffd3bfe70<br /><br /><span style="font-weight: bold;">The malware served</span><br />Scanners result : 18/32 (56.25%)<br />MemScan:Win32.Worm.Otwycal.T; a variant of Win32/AutoRun.NAD<br />File size: 25229 bytes<br />MD5...: 6be5a7b11601f8cb06ebba08c063aa09<br />SHA1..: 95d266e2e04e27a923467f483c23818c38ebe19e<br /><br /><span style="font-weight: bold;">The password stealers</span><br />Scanners result : 19/32 (59.38%)<br />Trojan.PWS.OnLineGames.WOM; Win32/TrojanDropper.Agent.NKK<br />File size: 42268 bytes<br />SHA1..: 7dfd51e96269f8d53354dd4c028d0c9481ebf4c8<br /><br />Scanners result : 13/32 (40.63%)<br />W32/Heuristic-159!Eldorado; Suspicious:W32/Malware!Gemini<br />File size: 108172 bytes<br />MD5...: a0383dd1571af5e2f104e1f7d6df7a67<br />SHA1..: be5b9b00ce9e378e545fa4f1e67160f20ba82ad2<br /><br />Consider <a href="http://flashblock.mozdev.org/">blocking flash by using Flashblock</a> for instance, until the issue is taken care of :<br /><br />"<span style="font-style: italic;">Flashblock is an extension for the Mozilla, Firefox, and Netscape   browsers that takes a pessimistic approach to dealing with Macromedia Flash   content on a webpage and blocks ALL Flash content from loading.   It then leaves placeholders on the webpage that allow you to click to   download and then view the Flash content.</span> "<br /><br />It could have been worse, as "wasting a zero day exploit" affecting such ubiquitous player such as Adobe's flash player for infecting the end users with a rather average password stealer is better, than having had the exploit leaked to others who would have have introduced their latest rootkits and banker malware.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MOTq5H"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MOTq5H" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PViwtH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PViwtH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BYW3jh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BYW3jh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mVV03h"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mVV03h" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=O64pnH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=O64pnH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HM5wcH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HM5wcH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NJ3wDh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NJ3wDh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/299370875" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 27 May 2008 13:33:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flash">flash</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/macromedia flash content">macromedia flash content</category>
      <category domain="http://securityratty.com/tag/flash content">flash content</category>
      <category domain="http://securityratty.com/tag/sample flash file">sample flash file</category>
      <category domain="http://securityratty.com/tag/adobe flash player">adobe flash player</category>
      <category domain="http://securityratty.com/tag/adobe">adobe</category>
      <category domain="http://securityratty.com/tag/participation domains">participation domains</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/299370875/malware-attack-exploiting-flash-zero.html">Malware Attack Exploiting Flash Zero Day Vulnerability</source>
    </item>
    <item>
      <title><![CDATA[Chinese Hacktivists Waging People's Information Warfare Against CNN]]></title>
      <link>http://securityratty.com/article/05c9fa38479affa4d154230adf02a08e</link>
      <guid>http://securityratty.com/article/05c9fa38479affa4d154230adf02a08e</guid>
      <description><![CDATA[Empowering and coordinating script kiddies by releasing DIY DDoS tools (backdoored as well) during the DDoS attacks against Estonia for instance, is exactly what is happening in the time of blogging...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SA0mJdDpixI/AAAAAAAABmQ/Urb3lYBmDhU/s1600-h/hackcnn.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SA0mJdDpixI/AAAAAAAABmQ/Urb3lYBmDhU/s200/hackcnn.jpg" alt="" id="BLOGGER_PHOTO_ID_5191847889288661778" border="0" /></a>Empowering and coordinating script kiddies by <a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html">releasing DIY DDoS tools (backdoored as well)</a> during the <a href="http://ddanchev.blogspot.com/2007/08/your-point-of-view-requested.html">DDoS attacks against Estonia</a> for instance, is exactly what is happening in the time of blogging with a massive forum and IM coordination between Chinese netizens enticed to install a pre-configured to flood CNN.com piece of malware. Both of these coordinated incidents greatly illustrate what <a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">people's information warfare, and the malicious culture of participation</a> is all about. The PSYOPS <span style="font-weight: bold;">anti-cnn.com</span> initiative is maturing into a central coordination point for recruiting DDoS participants on a nationalism level. Some info on <span style="font-weight: bold;">hackcnn.com</span>, the malware, internal commentary on behalf of the hacktivists, and who's behind it :<br /><br /><span style="font-weight: bold;">hackcnn.com</span> (58.49.59.253)<br />58.48.0.0-58.55.255.255 CHINANET-HB CHINANET Hubei province network China Telecom A12<br />Xin-Jie-Kou-Wai Street Beijing 100088,<br />China, Beijing 100000<br />tel:  101 1010000<br />fax:  101 1010000<br />china@hackcnn.com<br /><br />Upon execution of the tool, 18 TCP Connection Attempts to cnn.com (<span style="font-weight: bold;">64.236.91.24:80</span>) start, trying to access the following file at CNN.com :<br /><br />- Request: <span style="font-weight: bold;">GET /aux/con/com1/../../[LAG]../.%./../../../../fakecnn/redflag-stay-here.php.aspx.asp.cfm.jsp</span><br />Response: 400 "Bad Request"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SA0pB9DpiyI/AAAAAAAABmY/2oFEElHWyFs/s1600-h/hackcnn_tool.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SA0pB9DpiyI/AAAAAAAABmY/2oFEElHWyFs/s200/hackcnn_tool.jpg" alt="" id="BLOGGER_PHOTO_ID_5191851058974526242" border="0" /></a>antiCnn.exe<br />Scanner results : 3% Scanner(1/36) found malware!<br />TROJAN.DOWNLOADER.GEN<br />File size: 174592 bytes<br />MD5...: c03abd4d871cd83fe00df38536f26422<br />SHA1..: 0502c74ee90e110ceed3cbb81b2ee53d26068691<br />Released by : Red Flag Cyber Operations nixrumor@gmail.com<br /><br />From a network reconnaissance perspective, the Chinese hacktivists didn't even bother to take care of Apache's /server status, and therefore we're easily able<br />to obtain such juicy inside information about hackcnn.com such as :<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SA0p_tDpizI/AAAAAAAABmg/8oIPp-wM404/s1600-h/sports_cnn_ddosed.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SA0p_tDpizI/AAAAAAAABmg/8oIPp-wM404/s200/sports_cnn_ddosed.jpg" alt="" id="BLOGGER_PHOTO_ID_5191852119831448370" border="0" /></a>Current Time: Tuesday, 22-Apr-2008 07:00:56<br />Restart Time: Monday, 21-Apr-2008 15:25:39<br />Parent Server Generation: 0<br />Server uptime: 15 hours 35 minutes 17 seconds<br />Total accesses: 291670 - Total Traffic: 533.8 MB<br />5.2 requests/sec - 9.7 kB/second - 1918 B/request<br />4 requests currently being processed, 246 idle workers<br /><br />Internal commentary excerpts regarding the motivation and their updates on the first DDoS round :<br /><br />"<span style="font-style: italic;">Our team of non-governmental organisations, We only private network enthusiasts. However, we have a patriotic heart, We will absolutely not permit any person to discredit our motherland under any name, We are committed to attack some spreading false information, and malicious slander, libel, support Tibet independence site.</span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SA0t6dDpi0I/AAAAAAAABmo/oNfnCtMt6ns/s1600-h/sports_cnn_defaced_1.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SA0t6dDpi0I/AAAAAAAABmo/oNfnCtMt6ns/s200/sports_cnn_defaced_1.jpg" alt="" id="BLOGGER_PHOTO_ID_5191856427683646274" border="0" /></a>"<span style="font-style: italic;">User to a black CNN website suffer the same name. Yesterday, some Internet users attacked the domain name contains a "cnn" sports Web site, leaving protest speech, but reporters did not check the site found a relationship with CNN.</span>  <span style="font-style: italic;">Yesterday's attack was th</span><span style="font-style: italic;">e website with the domain name sports.si.cnn.com engaged in the work of the network of residents in Urumqi Mr. Chen, at about 2 pm, the attackers up a website hackcnn.com know, the "CNN sub-station" invasion and modify their pages. "Tug-of-war administrator and hackers," Mr. Chen said, after sports.si.cnn.com pages sometimes normal, and sometimes been modified. 16:50, the reporter saw on the pages left in bilingual text and flash animation, stressed that Tibet is a part of China, cnn protest against prejudice and false reports, the title page column was changed to "F * * kCNN!. "</span>  <span style="font-style: italic;">A few minutes later, the web site to enter a user ID and password before connecting, "evidently administrator of the authority." Chen analysis. Yesterday, the reporter tried to contact the attack, but received no response. Reporter verify that the contact address sports.si.cnn.com Pennsylvania in the United States, and the sports channel CNN web site is not the same, did not disclose information with the CNN.</span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SA0uEtDpi1I/AAAAAAAABmw/eBx0cveCP5A/s1600-h/sports_cnn_defaced_2.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SA0uEtDpi1I/AAAAAAAABmw/eBx0cveCP5A/s200/sports_cnn_defaced_2.jpg" alt="" id="BLOGGER_PHOTO_ID_5191856603777305426" border="0" /></a>DDoS-ing is one thing, defacing is entirely another, try <a href="http://209.85.135.104/search?q=cache:bP4fl_vKGtwJ:sports.si.cnn.com/test.htm+%22fuck+cnn%22&amp;hl=en&amp;ct=clnk&amp;cd=8"><span style="color:black;"><span style="color:blue;">sports.si.cnn.com/test.htm</span></span></a> which was last defaced yesterday spreading "<span style="font-style: italic;">We are not against the western media, but against the lies and fabricated stories in the media</span>", "<span style="font-style: italic;">We are not against the western people, but against the prejudice from the western society.!</span>" messages.<br /><br />According to forum postings however, now that they've sent a signal, the attitude is shifting from attacking CNN to Western media in general. Thankfully, just like the case with <a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html">the  Electronic Jihad program</a>, they did not put a lot of efforts into ensuring the lifecycle of the tool will remain as long as possible, by introducing a way to automatically update the tool with new targets. In fact, in <a href="http://ddanchev.blogspot.com/2007/08/cyber-jihadist-dos-tool.html">the Electronic Jihad case</a>, the hardcoded update locations were all down priot to releasing the tool, making a bit more efforts cunsuming to finally manage to <a href="http://ddanchev.blogspot.com/2007/11/electronic-jihads-targets-list.html">obtain the targets list</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Y8er0oG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Y8er0oG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=U8qwQ1G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=U8qwQ1G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6x6u2fg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6x6u2fg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=z5wKCqg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=z5wKCqg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=lglljMG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=lglljMG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4Hn9S4G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4Hn9S4G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UBIyLWg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UBIyLWg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/275221877" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Apr 2008 22:25:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cnn">cnn</category>
      <category domain="http://securityratty.com/tag/cnn sub-station">cnn sub-station</category>
      <category domain="http://securityratty.com/tag/flood cnn">flood cnn</category>
      <category domain="http://securityratty.com/tag/sports web site">sports web site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/psyops anti-cnn">psyops anti-cnn</category>
      <category domain="http://securityratty.com/tag/contact address sports">contact address sports</category>
      <category domain="http://securityratty.com/tag/contact">contact</category>
      <category domain="http://securityratty.com/tag/sports">sports</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/275221877/chinese-hacktivists-waging-peoples.html">Chinese Hacktivists Waging People's Information Warfare Against CNN</source>
    </item>
    <item>
      <title><![CDATA[A Portfolio of Fake Video Codecs]]></title>
      <link>http://securityratty.com/article/da5a9cbd10567ad678797555887c3267</link>
      <guid>http://securityratty.com/article/da5a9cbd10567ad678797555887c3267</guid>
      <description><![CDATA[Shall we expose a huge domains portfolio of fake/rogue video codecs hosting the same Zlob variant on each and every of the domains, thereby acting as a great example of what malicious economies of...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/R-GFkl280xI/AAAAAAAABeY/2elbkYQIiXE/s1600-h/zlob_variant_codec_IFRAME.jpg"><img id="BLOGGER_PHOTO_ID_5179567910137156370" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/R-GFkl280xI/AAAAAAAABeY/2elbkYQIiXE/s200/zlob_variant_codec_IFRAME.jpg" border="0" /></a>Shall we expose a huge domains portfolio of fake/rogue video codecs hosting the same Zlob variant on each and every of the domains, thereby acting as a great example of what malicious economies of scale means? But of course. As I've pointed out in a previous post, on the tactical warfare front the output of a malicious IFRAME campaign is often neglected from the perspective of lacking the two/three layered IFRAME-ing and redirection that the malicious parties usually implement at the beginning of the campaign. Basically, the over twenty fake video codecs domains are hosting the same binary in the form of a Zlob malware downloader, <a href="http://ddanchev.blogspot.com/2008/03/rogue-rbn-software-pushed-through.html">infrastructure courtesy of the RBN's used ATRIVO</a> (64.28.176.0/20). Currently active domains hosting the" DVDAccess codec", namely a Zlob malware variant :<br /><div></div><strong><br />pornqaz.com</strong><div><strong>uinsex.com</strong></div><div><strong>qazsex.com</strong></div><div><strong>sexwhite.net</strong></div><div><strong>lightporn.net</strong></div><div><strong>xeroporn.com</strong></div><div><strong>brakeporn.net</strong></div><div><strong>sexclean.net</strong></div><div><strong>delfiporn.net</strong></div><div><strong>pornfire.net</strong></div><div><strong>redcodec.net</strong></div><div><strong>democodec.com</strong></div><div><strong><a href="http://bp1.blogger.com/_wICHhTiQmrA/R-GMil280yI/AAAAAAAABeg/BNuHgUi6Tng/s1600-h/fake_videocodecs_zlob.jpg"><img id="BLOGGER_PHOTO_ID_5179575572358812450" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/R-GMil280yI/AAAAAAAABeg/BNuHgUi6Tng/s200/fake_videocodecs_zlob.jpg" border="0" /></a>delficodec.com</strong></div><div><strong>turbocodec.net</strong></div><div><strong>gamecodec.com</strong></div><div><strong>blackcodec.net</strong></div><div><strong>xerocodec.com</strong></div><div><strong>ixcodec.net</strong></div><div><strong>codecdemo.com</strong></div><div><strong>ixcodec.com</strong></div><div><strong>citycodec.com</strong></div><div><strong>codecthe.com</strong></div><div><strong>codecnitro.com</strong></div><div><strong>codecbest.com</strong></div><div><strong>codecspace.com</strong></div><div><strong>popcodec.net</strong></div><div><strong>uincodec.com</strong></div><div><strong>xhcodec.com</strong></div><div><strong>stormcodec.net</strong></div><div><strong>codecmega.com</strong></div><div><strong>whitecodec.com</strong></div><div><strong>jetcodec.com</strong></div><div><strong>endcodec.com<br />abccodec.com</strong></div><div><strong>codecred.net</strong></div><div><strong>cleancodec.com</strong></div><div><strong>herocodec.com</strong></div><div><strong>nicecodec.com</strong></div><div> </div><div><br />DVDaccess's pitch : "<em>DVDaccess is a multimedia software that allowa access to Windows collection of multimedia drivers and integrates with any application using DirectShow and Microsoft Video for Windows. DVDaccess will highly increase quality of video files you play. DVDaccess enhances your music listening experience by improving the sound quality of video files sound, MP3, internet radio, Windows Media and other music files. Renew stereo depth, add 3D surround sound, restore sound clarity, boost your audio levels, and produce deep, rich bass sounds.</em>"</div><div> </div><div><strong><br />Scanner results</strong> : 39% Scanner (14/36) found malware!</div><div><a href="http://ddanchev.blogspot.com/2008/03/more-high-profile-sites-iframe-injected.html">Trojan-Downloader.Win32.Zlob.eie</a></div><div><strong>File Size</strong> : 74823 byte</div><div><strong>MD5</strong> : 30965fdbd893990dd24abda2285d9edc</div><div><strong>SHA1</strong> : 53eacbb9cdf42394bd455d9bd2275f05730332f7</div><div> </div><div><br />Why are the malicious parties so KISS oriented at the end of every campaign, compared to the complexity and tactical warfare tricking automated malware harvesting approaches within the beginning of the campaign? Because they're not even considering the possibility of proactively detecting the output of the many other malware campaigns to come, which will inevitable be ending up to these very same domains serving a single Zlob variant. Just like the recent massive IFRAME attacks, where in between the live exploit URLs and rogue security software, the end users were redirected to DVDaccess as well. In fact, the <a href="http://ddanchev.blogspot.com/2008/03/more-high-profile-sites-iframe-injected.html">massive IFRAME attack campaign</a> was, and continues to redirect to one of the domains in the portfolio I've just provided you with.<br /></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=N5nRWnF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=N5nRWnF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WyFJnOF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WyFJnOF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uoN5Tzf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uoN5Tzf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Dpxg3Zf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Dpxg3Zf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=lHyCclF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=lHyCclF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pu6sSYF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pu6sSYF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vBNz9Af"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vBNz9Af" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/254547002" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 19 Mar 2008 14:27:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/single zlob variant">single zlob variant</category>
      <category domain="http://securityratty.com/tag/zlob variant">zlob variant</category>
      <category domain="http://securityratty.com/tag/zlob">zlob</category>
      <category domain="http://securityratty.com/tag/zlob malware variant">zlob malware variant</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/huge domains portfolio">huge domains portfolio</category>
      <category domain="http://securityratty.com/tag/dvdaccess">dvdaccess</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/254547002/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</source>
    </item>
    <item>
      <title><![CDATA[Embedded Malware at Bloggies Awards Site]]></title>
      <link>http://securityratty.com/article/2d70cdf7c3222d6baa33fd53c95733f6</link>
      <guid>http://securityratty.com/article/2d70cdf7c3222d6baa33fd53c95733f6</guid>
      <description><![CDATA[The &quot;window of opportunity&quot; for traffic acquisition by taking advantage of a huge anticipated traffic is something malicious parties always find adaptive ways to take advantage of. Back in December,...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/R9hnJ0-0GJI/AAAAAAAABeI/-8N1oPmt4co/s1600-h/bloggie_awards_malware_iframe.jpg"><img id="BLOGGER_PHOTO_ID_5177001190200973458" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/R9hnJ0-0GJI/AAAAAAAABeI/-8N1oPmt4co/s200/bloggie_awards_malware_iframe.jpg" border="0" /></a>The "window of opportunity" for traffic acquisition by taking advantage of a huge anticipated traffic is something malicious parties always find adaptive ways to take advantage of. Back in December, 2007, the same event based <a href="http://ddanchev.blogspot.com/2007/12/have-your-malware-in-timely-fashion.html">malware embedded attack appeared at a French government's site covering France/Libya relations</a> right in the middle of Libya's leader visit in the country. My detailed analysis back then revealed details of the usual RBN connection, with IFRAME hosts switchng between <a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">HostFresh, Ukrtelegroup Ltd, and Turkey Abdallah Internet Hizmetleri</a>, to surprisingly end up to <a href="http://ddanchev.blogspot.com/2008/03/new-media-malware-gang-part-four.html">the New Media Malware Gang</a> original IP, futher confirming the existence of what's now a diverse ecosystem.<br /><br />The same <a href="http://www.news.com.au/technology/story/0,25642,23345956-5014239,00.html">timely malware embedded attack</a> happened at the top of the Annual Weblog Awards site - The Bloggies as <a href="http://blog.trendmicro.com/bloggies-gives-out-malware-before-awards/">TrendMicro assessed on Monday</a> :<br /><br />"<em>The Web site of the Annual Weblogs Awards — more informally known as the Bloggies — was hacked recently, serving up a malicious Javascript to its visitors. This happened on the eve of the award ceremony, as reported in NEWS.com.au.</em>"<br /><br />An embedded malware screenshot is worth a thousand words, so here it goes attached, and IcePack's now easily detectable module :<br /><br /><strong>Scanner results</strong> : 47% Scanner(17/36) found malware!<br /><strong>File Size</strong> : 10666 byte<br /><strong>MD5</strong> : 0860a1f5f1b27db14fedbfc979399fa4<br /><strong>SHA1</strong> : 81c4ca763850fd3d675a0955ee6885ce83db53a5<br />HTML/Psyme.Gen; Trojan-Downloader.JS.Agent.et<br /><br />Moreover, <strong>wilicenwww.biz/1/1/ice-pack/index.php </strong>is currently responding to <strong>202.75.38.150</strong>, and besides the descriptive IcePack host, the IP also responds to the following domains :<br /><br /><strong>bigsavingpharmacy.com</strong><br /><strong>infosecurestatus.com</strong><br /><strong>pharmacysuperdiscount.com</strong><br /><strong>rspectrum.name</strong><br /><strong>sicil.info</strong><br /><strong>sicil256.info</strong><br /><strong>superdiscountpills.com</strong><br /><strong>mydnsweb.net</strong><br /><strong>thegogosearch.com</strong><br /><br />So what? Historical CYBERINT untimately improves your situational awareness. <strong>Sicil.info</strong> was the main domain behind the <a href="http://ddanchev.blogspot.com/2007/09/syrian-embassy-in-london-serving.html">Syrian Embassy in the U.K malware embedded attack</a>. Back then, <strong>sicil.info</strong> was responding to <strong>203.121.79.71</strong>, and now to <strong>202.75.38.150</strong>, switching locations doesn't mean a clean domain reputation anyway.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qpRP4WF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qpRP4WF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KZltAAF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KZltAAF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=We7ROjf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=We7ROjf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TXX6J1f"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TXX6J1f" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=72aFSqF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=72aFSqF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uRuRq5F"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uRuRq5F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hYB17zf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hYB17zf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/250422746" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 12 Mar 2008 15:36:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/timely malware">timely malware</category>
      <category domain="http://securityratty.com/tag/event based malware">event based malware</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/malware screenshot">malware screenshot</category>
      <category domain="http://securityratty.com/tag/icepack">icepack</category>
      <category domain="http://securityratty.com/tag/descriptive icepack host">descriptive icepack host</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <category domain="http://securityratty.com/tag/bloggies">bloggies</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/250422746/embedded-malware-at-bloggies-awards.html">Embedded Malware at Bloggies Awards Site</source>
    </item>
    <item>
      <title><![CDATA[More High Profile Sites IFRAME Injected]]></title>
      <link>http://securityratty.com/article/97c88216eb87a2fbc044f1786b1d6ce8</link>
      <guid>http://securityratty.com/article/97c88216eb87a2fbc044f1786b1d6ce8</guid>
      <description><![CDATA[The ongoing monitoring of this campaign reveals that the group is continuing to expand the campaign, introducing over a hundred new bogus .info domains acting as traffic redirection points to the...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/R9fVaE-0GFI/AAAAAAAABdo/lBbPf6NfozM/s1600-h/iframe_injection_CSO.jpg"><img id="BLOGGER_PHOTO_ID_5176840940676192338" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/R9fVaE-0GFI/AAAAAAAABdo/lBbPf6NfozM/s200/iframe_injection_CSO.jpg" border="0" /></a>The <a href="http://ddanchev.blogspot.com/2008/03/wiredcom-and-historycom-getting-rbn-ed.html">ongoing monitoring</a> of this <a href="http://ddanchev.blogspot.com/2008/03/more-cnet-sites-under-iframe-attack.html">campaign reveals</a> that <a href="http://ddanchev.blogspot.com/2008/03/zdnet-asia-and-torrentreactor-iframe-ed.html">the group</a> is continuing <a href="http://ddanchev.blogspot.com/2008/03/rogue-rbn-software-pushed-through.html">to expand</a> the campaign, <a href="http://ddanchev.blogspot.com/2008/03/injecting-iframes-by-abusing-input.html">introducing over</a> a hundred new bogus .info domains acting as traffic redirection points to the campaigns hardcoded within the secondary redirection point, in this case <strong>radt.info</strong> where a new malware variant of Zlob is attempting to install though an ActiveX object. These are the high profile sites targeted by the same group within the past 48 hours, with number of locally cached and IFRAME injected pages within their search engines :<br /><div><br />NCSU Libraries - <span style="font-weight: bold;">lib.ncsu.edu</span> - 372,000 pages<br />FullDownloads.us - <span style="font-weight: bold;">fulldownloads.us</span> - 13,000 pages<br />Central Statistics Office Ireland - <span style="font-weight: bold;">cso.ie</span> - 10,300 pages<br />DBLife Frontpage - <span style="font-weight: bold;">dblife.cs.wisc.edu</span> - 1,130 pages<br />School of Mathematics and Statistics - <span style="font-weight: bold;">www-history.mcs.st-andrews.ac.uk</span> - 1040 pages<br />eHawaii Portal - <span style="font-weight: bold;">ehawaii.gov</span> - 992 pages<br />The World Clock - <span style="font-weight: bold;">timeanddate.com</span> - 944 pages<br />Boise State University - <span style="font-weight: bold;">boisestate.edu</span> - 471 pages<br />The U.S. Administration on Aging (AoA) - <span style="font-weight: bold;">aoa.gov</span> - 425 pages<br />Gustavus Adolphus College - <span style="font-weight: bold;">gustavus.edu</span> - 312 pages<br />Internet Archive - <span style="font-weight: bold;">archive.org</span> - 261 pages<br />Stanford Business School Alumni Association - <span style="font-weight: bold;">gsbapps.stanford.edu</span> - 157 pages<br />BushTorrent -<span style="font-weight: bold;"> bushtorrent.com</span> - 147 pages<br />ChildCareExchange - <span style="font-weight: bold;">ccie.com</span> - 131 pages<br />The University of Vermont - <span style="font-weight: bold;">uvm.edu</span> - 120 pages<br />Hippodrome State Theatre - Gainesville, FL - <span style="font-weight: bold;">thehipp.org</span> - 112 pages<br />Minnesota State University Mankato - <span style="font-weight: bold;">mnsu.edu</span> - 94 pages<br />The California Majority Report - <span style="font-weight: bold;">camajorityreport.com</span> - 16 pages<br />Medicare.gov - <span style="font-weight: bold;">medicare.gov</span> - 12 pages<br />USAMRIID - <span style="font-weight: bold;">usamriid.army.mil</span> - 3 pages<br /><br /><a href="http://bp2.blogger.com/_wICHhTiQmrA/R9fZaU-0GGI/AAAAAAAABdw/gAd8mQtOdtM/s1600-h/iframe_injection_ncsu.jpg"><img id="BLOGGER_PHOTO_ID_5176845343017670754" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/R9fZaU-0GGI/AAAAAAAABdw/gAd8mQtOdtM/s200/iframe_injection_ncsu.jpg" border="0" /></a>This sample of the newly introduced .info domains reside on the same netblock as the previous ones - <strong>75.125.181.0/255</strong> a KISS strategy making it easier to respond to this incident. Best of all, they further expand the campaign since they're injected in plain text, next to javascript obfuscated, this time embedded malware :<br /><br /><div> </div><strong>hickey.info</strong><br /><div><strong>kbst.info</strong></div><strong>sezejc.info</strong><br /><div><strong>mloqrd.info</strong></div><strong>mqghrd.info</strong><br /><div><strong>ymrxwd.info</strong></div><strong>fsqpsm.info</strong><br /><div><strong>haxkwd.info</strong></div><strong>aagpcw.info</strong><br /><div><strong>zdksgj.info</strong></div><strong>cgjttz.info</strong><br /><div><strong>hkedny.info</strong></div><strong>kbsxet.info</strong><br /><div><strong>wapdjw.info</strong></div><strong>kbsxet.info</strong><br /><div><strong>tdwham.info</strong></div><strong>mqghrd.info</strong><br /><div><strong>dhqjdz.info</strong></div><strong>bhrsaa.info</strong><br /><div><strong>jramae.info</strong></div><strong>wmtwes.info</strong><br /><div><strong>tacpmh.info</strong></div><strong>qwhhxq.info</strong><br /><div><strong>gmjett.info</strong></div><strong>hkedny.info</strong><br /><div><strong>rerkqz.info<br />bhrsaa.info</strong></div><strong>txmwxb.info</strong><br /><div><strong>psyckr.info</strong></div><strong>jramae.info</strong><br /><div><strong>nhwdrh.info</strong></div><span style="font-weight: bold;">cqqxkh.info</span><br /><div><strong>stysqf.info</strong></div><strong>tgzyqz.info</strong><br /><div><strong>kbsxet.info</strong></div><strong>cgjttz.info</strong><br /><div><strong>tazbhk.info</strong></div><strong>kbsxet.info</strong><br /><div> </div><br /><div>Each of the these is loading a secondary domain, which is then taking us to two more before finally reaching the Zlob variant. In this case it's <strong>radt.info </strong><strong style="font-weight: normal;">(75.125.208.243)</strong> with several campaigns currently up and running, pointing to the same fake codec. And the samples redirects upon visiting these as follows :<br /></div><div> </div><strong><br />seivomerutam.info/Free-Paris-Hilton-Nude-Pics/<br /></strong><strong>seivomerutam.info/spam/</strong><br /><div> </div><br />all of which ultimately redirect to :<br /><div> </div><strong><br />porn-popular.com</strong> (64.28.185.78) where the Zlob variant in the face of a fake codec, is downloaded from <strong>democodec.com/download/ democodec1292.exe</strong> (64.28.184.168) via an Active X object.<br /><br /><div> </div><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/R9fem0-0GHI/AAAAAAAABd4/HHD-sHBpx_k/s1600-h/iframe_input_validation_active_X.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/R9fem0-0GHI/AAAAAAAABd4/HHD-sHBpx_k/s200/iframe_input_validation_active_X.jpg" alt="" id="BLOGGER_PHOTO_ID_5176851055324174450" border="0" /></a><strong>Scanner results</strong> : 22% Scanner(8/36) found malware!<br /><div>File Name : democodec1292.exe</div><strong>File Size</strong> : 74823 byte<br /><div><strong>MD5</strong> : 30965fdbd893990dd24abda2285d9edc</div><strong>SHA1</strong> : 53eacbb9cdf42394bd455d9bd2275f05730332f7<br /><div>Downloader.Zlob.ZV; Trojan-Downloader.Win32.Zlob.eie; TrojanDownloader.Zlob.epx</div><br /><div> </div>It gets even more interesting as according to <a href="http://ca.com/us/securityadvisor/pest/pest.aspx?id=453119651">Computer Associates</a> :<br /><div> </div><br /><div>"<em>This fake codec is actually a hijacker that will change your DNS settings whether you are aquire your IP settings through DHCP or set your IP information manually. <span style="font-weight: bold;">This hijacker will attempt to re-route all your DNS queries through 85.255.x.29 or 85.255.x.121.</span> If you use a static IP address, CA AntiSpyware will set your DNS server to 198.6.1.1 to prevent your DNS queries from continuing to go through the rogue DNS servers. Please change your DNS server to the DNS server provided by your IP or Network Administrator.</em>"</div><div> </div><br /><div><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/R9ffVU-0GII/AAAAAAAABeA/Ghf8PbhPtqI/s1600-h/zlob_variant_codec_IFRAME.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/R9ffVU-0GII/AAAAAAAABeA/Ghf8PbhPtqI/s200/zlob_variant_codec_IFRAME.jpg" alt="" id="BLOGGER_PHOTO_ID_5176851854188091522" border="0" /></a>What this means is that <a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">known Russian Business Network netblocks</a> are receiving all the re-routed DNS queries from infected hosts, thereby setting up the foundations for a large scale pharming attack by infecting the weakest link, the end user from the perspective of using rogue DNS servers, a much more effective but noisy approach.</div><br /><div> </div>To sum up - it's a mess that I'll continue trying to structure, and it's a single group exploiting input validation capability within the sites' search engines we're talking about. With this segmented targeting of sites with high page ranks, and their persistance, is already positioning hundreds of thousands of keywords within the top search results, with the targeted sites are acting as the redirectors to the malware locations.</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HfotYvF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HfotYvF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UFAs33F"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UFAs33F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jrG9vvf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jrG9vvf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dDM9F6f"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dDM9F6f" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=isZ3yzF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=isZ3yzF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f8lRmjF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f8lRmjF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=h8KWZCf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=h8KWZCf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/250167533" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 12 Mar 2008 06:49:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/info">info</category>
      <category domain="http://securityratty.com/tag/info txmwxb">info txmwxb</category>
      <category domain="http://securityratty.com/tag/info kbsxet">info kbsxet</category>
      <category domain="http://securityratty.com/tag/info bhrsaa">info bhrsaa</category>
      <category domain="http://securityratty.com/tag/info sezejc">info sezejc</category>
      <category domain="http://securityratty.com/tag/info cgjttz">info cgjttz</category>
      <category domain="http://securityratty.com/tag/info wmtwes">info wmtwes</category>
      <category domain="http://securityratty.com/tag/info cqqxkh">info cqqxkh</category>
      <category domain="http://securityratty.com/tag/info qwhhxq">info qwhhxq</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/250167533/more-high-profile-sites-iframe-injected.html">More High Profile Sites IFRAME Injected</source>
    </item>
    <item>
      <title><![CDATA[More CNET Sites Under IFRAME Attack]]></title>
      <link>http://securityratty.com/article/61e2c6b0ce33b5f59ce105fe2092ba00</link>
      <guid>http://securityratty.com/article/61e2c6b0ce33b5f59ce105fe2092ba00</guid>
      <description><![CDATA[News is spreading fast, appropriate credit is given , but not as fast as the IFRAME campaign targeting several more CNET Networks' web properties besides ZDNet Asia , namely, TV.com , News.com and...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/R8_5QMHWvLI/AAAAAAAABbg/CQIhd-i9vrA/s1600-h/TV_com_IFRAME.jpg"><img id="BLOGGER_PHOTO_ID_5174628553397288114" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R8_5QMHWvLI/AAAAAAAABbg/CQIhd-i9vrA/s200/TV_com_IFRAME.jpg" border="0" /></a>News is <a href="http://www.theregister.co.uk/2008/03/06/googe_iframe_piggybacking/">spreading</a> fast, <a href="http://www.f-secure.com/weblog/archives/00001396.html">appropriate credit</a> is <a href="http://www.itwire.com/content/view/16981/53/">given</a>, but <a href="http://www.idg.se/2.1085/1.148922">not as</a> fast <a href="http://securite.reseaux-telecoms.net/actualites/lire-attaque-par-moteur-de-recherche-interpose-17788.html">as the</a> IFRAME <a href="http://www.securityfocus.com/brief/695">campaign targeting</a> several more <a href="http://www.cnetnetworks.com/company/brands.html">CNET Networks' web properties</a> besides <strong>ZDNet Asia</strong>, namely, <strong>TV.com</strong>, <strong>News.com</strong> and <strong>MySimon.com</strong> which I'll assess in this post. In the time of posting this, no other CNET sites are involved in the campaign, including ZDNet's international sites such as, ZDNet India, ZDNet U.K, and ZDNet Australia, but the abovementioned ones. And so, we have three more sites part of CNET Networks' portfolio, getting injected with more IFRAMEs, <a href="http://ddanchev.blogspot.com/2008/03/zdnet-asia-and-torrentreactor-iframe-ed.html">abusing their search engine's local caching, and storing of any keyword feature</a>, in a combination with a loadable IFRAME.<br /><br />What has changed for the past 24 hours, despite that the now over <strong>51,900 pages at zdnetasia.com</strong> continue to be indexed by search engines? The folks at ZDNet Asia have taken care of the IFRAME issue, so that such injection is no longer possible. However, the same IPs used in this IFRAME campaign, including two new domains introduced have been injected, and are loading at <strong>TV.com, News.com and MySimon.com</strong>, again <a href="http://ddanchev.blogspot.com/2008/03/rogue-rbn-software-pushed-through.html">pushing the rogue XP AntiVirus</a>, the rogue Spyshredderscanner, as well as another fake codec <strong>MediaTubeCodec.exe</strong>, hosted and distributed under two new domains.<br /><br /><a href="http://bp0.blogger.com/_wICHhTiQmrA/R9ANnMHWvMI/AAAAAAAABbo/MvOYgEYbUQ8/s1600-h/news_com_IFRAME.jpg"><img id="BLOGGER_PHOTO_ID_5174650938766834882" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R9ANnMHWvMI/AAAAAAAABbo/MvOYgEYbUQ8/s200/news_com_IFRAME.jpg" border="0" /></a><strong>Which sites are currently targeted?</strong><br />ZDNet Asia - currently has 51,900 injected pages<br />TV.com - 49,600 locally hosted IFRAME injected pages<br />News.com - 167 locally hosted pages, injection is ongoing<br />MySimon.com - currently 4 pages, the campaign is ongoing<br /><br /><strong>Which domains and IPs are behind the IFRAMEs?</strong><br />do-t-h-e.com (69.50.167.166)<br />rx-pharmacy.cn (82.103.140.65)<br />m5b.info (124.217.253.6)<br />89.149.243.201<br />89.149.243.202<br />72.232.39.252<br />195.225.178.21<br /><br /><strong>Where's the malware?</strong><br />It's there, you just have to triple check different IFRAME-ed search results and finally you'll get to install XP AntiVirus 2008 and a fake codec, the only two pieces of malware currently served. What's important to note is that this is the current state of the campaign, and with the huge number of IFRAME-ed pages in such a way, targeted attacks on a per keyword basis are possible, and since they ensure you're served on the basis of where you're coming from, things can change pretty fast. These are all of the domains that follow after the IFRAME redirects for all the campaigns currently detected, and the detection rates for the malware from the last campaign :<br /><br />hotpornotube08.com (206.51.229.67)<br />hot-pornotube-2008.com (206.51.229.67)<br />hot-pornotube08.com (206.51.229.67)<br />adult-tubecodec2008.com (195.93.218.43)<br />adulttubecodec2008.com (195.93.218.43)<br />hot-tubecodec20.com (195.93.218.43)<br />media-tubecodec2008.com (195.93.218.43)<br />porn-tubecodec20.com (195.93.218.43)<br />scanner.spyshredderscanner.com (77.91.229.106)<br />xpantivirus2008.com (69.50.173.10)<br />xpantivirus.com (72.36.198.2)<br />bestsexworld.info (72.232.224.154)<br />requestedlinks.com (216.255.185.82)<br /><br />MediaTubeCodec.com<br /><strong>Scanner results</strong> : 11% Scanner(4/36) found malware!<br /><strong>Time</strong> : 2008/03/06 16:38:39 (EET)<br /><strong>File Size</strong> : 85520 byte<br /><strong>MD5</strong> : 25708e1168e0e5dae87851ec24c6e9f7<br /><strong>SHA1</strong> : 33b502b13cab7a34bb959d363ae4b7afd23919a6<br />AVG - I-Worm/Nuwar.P<br />Fortinet - Suspicious<br />Prevx - TROJAN.DOWNLOADER.GEN<br />Quick Heal - Suspicious - DNAScan<br /><br />Tries to connect to <strong>websoftcodecdriver.com</strong>; <strong>websoftcodecdriver2.com</strong> and <strong>77.91.227.179</strong>, in between listening on local port 1034. The downloader tries to drop <strong>Adware.Agent.BN</strong> - "<em>Adware.Agent.BN is an adware program that displays pop-up advertisements and adds a runkey to run at startup, and also modifies Windows system configuration in order to download more malwares on to infected computer.</em>" and <strong>RogueAntiSpyware.AntiVirusPro</strong> - "<em>RogueAntiSpyware.AntiVirusPro is a Rogue Anti-Spyware product which comes bundled along with a malicious downloader. It is downloaded and installed without the users consent.</em>"<br /><br />Spyshredderscanner.exe<br /><strong>Scanner results</strong> : 42% Scanner(15/36) found malware!<br /><strong>Time</strong> : 2008/03/06 17:02:23 (EET)<br /><strong>File Size</strong> : 33224 byte<br /><strong>MD5</strong> : bc232dbd6b75cc020af1fcf7cee5f018<br /><strong>SHA1</strong> : fc2f70fd9ce76fe2e1fe157c6d2d8ba015ad099f<br /><strong>Detected as</strong> : Win32.FraudTool.SpyShredder; Downloader.MisleadApp<br /><br />Again opening local port 1034 and tries to connect to <strong>69.50.168.51</strong>, ATRIVO = RBN's well known netblock.<br /><br /><strong>Who's behind it?</strong><br />It's all a matter of perspective, if you look at the IPs used in the IFRAMEs, these are the front-end to rogue anti virus and anti spyware tools that were using RBN's infrastructure before it went dark, and continue using some of the new netblocks acquired by the RBN. However as <a href="http://ddanchev.blogspot.com/2007/11/new-media-malware-gang.html">I've once</a> pointed out <a href="http://ddanchev.blogspot.com/2007/12/new-media-malware-gang-part-two.html">in respect</a> to the <a href="http://ddanchev.blogspot.com/2008/02/new-media-malware-gang-part-three.html">New Media Malware Gang</a> and its connection with the RBN and Storm Worm, for the time being it's unclear which one of these is the operational department if any, of the RBN is vertically integrating to provide more than the hosting infrastructure, and diversify to malware, or spyware installation on a revenue-sharing basis participating in an affiliate program.<br /><br />This malicious campaign will continue to be monitored, particularly the RBN connection, and whether or not they will start targeting CNET's other sites.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KG97XiF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KG97XiF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VAUfO3F"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VAUfO3F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pNjCArf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pNjCArf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1s55Bnf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1s55Bnf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Hi3WNPF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Hi3WNPF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3at6HBF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3at6HBF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=u4b2kkf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=u4b2kkf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/246820135" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 06 Mar 2008 07:50:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/iframe">iframe</category>
      <category domain="http://securityratty.com/tag/cnet sites">cnet sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/iframe-ed pages">iframe-ed pages</category>
      <category domain="http://securityratty.com/tag/pages">pages</category>
      <category domain="http://securityratty.com/tag/cnet">cnet</category>
      <category domain="http://securityratty.com/tag/iframe redirects">iframe redirects</category>
      <category domain="http://securityratty.com/tag/iframe campaign">iframe campaign</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/246820135/more-cnet-sites-under-iframe-attack.html">More CNET Sites Under IFRAME Attack</source>
    </item>
  </channel>
</rss>
