<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: embassy]]></title>
    <link>http://securityratty.com/tag/embassy</link>
    <description></description>
    <pubDate>Wed, 12 Mar 2008 15:36:48 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Embassy of Brazil in India Compromised]]></title>
      <link>http://securityratty.com/article/d16a985654ea698c4e0d3ab5e394be74</link>
      <guid>http://securityratty.com/article/d16a985654ea698c4e0d3ab5e394be74</guid>
      <description><![CDATA[Only an amateur or unethical competition would embedd malicious links at the Embassy of Brazil in India's site , referencing their online community. With the chances of an Embassy involvement into the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SRxJCIZifgI/AAAAAAAACc0/7XHc2f7BAQo/s1600-h/brazil_embassy_india_compromised_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SRxJCIZifgI/AAAAAAAACc0/7XHc2f7BAQo/s200/brazil_embassy_india_compromised_1.JPG" /></a>Only an amateur or unethical competition would embedd <a href="http://securitylabs.websense.com/content/Alerts/3228.aspx">malicious links at the Embassy of Brazil in India's site</a>, referencing their online community. With the chances of <a href="http://www.brazilembassy.in/">an Embassy</a> involvement into the fake antivirus software industry close to zero,<br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SRxE9OAVBCI/AAAAAAAACck/u5qhnNXJyoE/s1600-h/brazil_embassy_free_web_space_rogue.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SRxE9OAVBCI/AAAAAAAACck/u5qhnNXJyoE/s200/brazil_embassy_free_web_space_rogue.JPG" /></a>The compromise is a great example of a mixed use of pure malicious domains in a combination with compromised legitimate ones and on purposely registered accounts at free web space providers, hosting the blackhat SEO content. However, digging deeper we expose the entire malicious doorways ecosystem pushing PDF exploits, banker malware and Zlob variants. The malicious attackers embedded links to their blackhat SEO farms advertising fake security software, and also a link to a traffic redirection doorway<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><b>epmwckme.dex1.com</b><br />
<b>htkobaf.dex1.com</b><br />
<b>ogbucof.dex1.com</b><br />
<b>segundomuelle.com/mex/antivirus</b><br />
<b>jgzleaa.dex1.com</b><br />
<b>igpran.ru/services/tolstye</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SRxFRKFC0LI/AAAAAAAACcs/hsjTDmrLtbo/s1600-h/obfuscation_brazil_embassy.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SRxFRKFC0LI/AAAAAAAACcs/hsjTDmrLtbo/s200/obfuscation_brazil_embassy.JPG" /></a>The active and redirecting <b>traff .asia</b> (89.149.251.203) is currently serving a fake account suspended notice - "<i>This account has been suspended. Either the domain has been overused, or the reseller ran out of resources.</i>" but is whatsoever redirecting us to <b>antimalware09 .net</b>. This particular traffic redirection doorway is actively redirecting us to a command and control server running a well known web malware exploitation kit which is currently serving PDF exploits. <b>&nbsp;</b><br />
<br />
<b>google-analyze .com/socket/index.php</b> (216.195.59.77) from where we're redirected to <b>google-analyze.com/tracker/load.php</b> which is serving system.exe (Trojan-Spy.Win32.Zbot.ehk; Win32.TrojanSpy.Zbot.gen!C.5), and <b>google-analyze .com/tracker/pdf.php</b> (Exploit:Win32/Pdfjsc.G; Exploit.JS.Pdfka.w; Bloodhound.Exploit.196). Naturally, within the live exploit URLs there are multiple IFRAMEs redirecting us to more of this group's campaigns. <b>google-analyze .com</b>&nbsp; has multiple IFRAMEs pointing to <b>google-analystic .net</b> (209.160.67.56), yet another traffic redirection doorway further exposing their campaigns.<br />
<br />
For instance, <b>google-analystic .net/in.cgi?20</b> loads <b>google-analystic.net/tea.php</b> (209.160.67.56) where <b>google-analystic .net/in.cgi?8</b> is redirecting to <b>91.203.93.61 /in.cgi?2</b> taking us to <b>91.203.93.61 /25/2/</b> where we deobfuscate the javascript leading us to the exact location of the PDF exploit - <b>91.203.93.61 /25/2/getfile.php?f=pdf</b>. This is just for starters. <b>google-analystic .net/in.cgi?9</b> redirects to <b>mangust32 .cn/pod/index.php</b> (218.93.202.102) where they serve load.exe (Backdoor:Win32/Koceg.gen!A) at <br />
<b>mangust32 .cn/pod2/load.php</b> and load.exe at <b>mangust32 .cn/eto2/load.php</b>, moreover, <b>google-analystic .net/in.cgi?10</b> leads us to <b>mmcounter .com/in.cgi?id194</b> (94.102.50.130) a traffic management login which is no longer responding. The last IFRAME found within google-analystic points to <b>busyhere .ru/in.cgi?pipka</b> which redirects to <b>beshragos .com/work/index.php</b> (79.135.187.38) where once we<br />
deobfuscate the script, we get to see the PDF exploit location <b>beshragos.com /work/getfile.php?f=pdf</b>.<br />
<br />
What's contributing to the increase of PDF exploits durin the last month? It's an updated version of a web based malware exploitation tool, which despite the fact that it remains proprietary for the time being, will leak in the next couple of weeks causing the usual short-lived epidemic.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/01/dutch-embassy-in-moscow-serving-malware.html">The Dutch Embassy in Moscow Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/us-consulate-st-petersburg-serving.html">U.S Consulate in St. Petersburg Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/syrian-embassy-in-london-serving.html">Syrian Embassy in London Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/have-your-malware-in-timely-fashion.html">French Embassy in Libya Serving Malware</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GVhoN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GVhoN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1M6tN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1M6tN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BksVn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BksVn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=u03In"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=u03In" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HzjZN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HzjZN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9KBON"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9KBON" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2Qbtn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2Qbtn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/451892286" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 06:47:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/embassy">embassy</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/traffic redirection doorway">traffic redirection doorway</category>
      <category domain="http://securityratty.com/tag/syrian embassy">syrian embassy</category>
      <category domain="http://securityratty.com/tag/exploit">exploit</category>
      <category domain="http://securityratty.com/tag/live exploit urls">live exploit urls</category>
      <category domain="http://securityratty.com/tag/cgi">cgi</category>
      <category domain="http://securityratty.com/tag/pdf exploits durin">pdf exploits durin</category>
      <category domain="http://securityratty.com/tag/pdf exploits">pdf exploits</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/451892286/embassy-of-brazil-in-india-compromised.html">Embassy of Brazil in India Compromised</source>
    </item>
    <item>
      <title><![CDATA[on HITB 2008 Conference]]></title>
      <link>http://securityratty.com/article/7182dd4ae495366352b2abc23339e496</link>
      <guid>http://securityratty.com/article/7182dd4ae495366352b2abc23339e496</guid>
      <description><![CDATA[Not to pretend to steal Halvar Flake's glory , but I just got my own &quot;fun&quot; international travel story, which also spells bad news to those who wanted to hear my fun keynote at Hack In The Box 2008 in...]]></description>
      <content:encoded><![CDATA[Not to pretend to <a href="http://it.slashdot.org/it/07/07/29/2057243.shtml">steal Halvar Flake's glory</a>, but I just got my own "fun" international travel story, which also spells bad news to those who wanted to hear <a href="http://conference.hackinthebox.org/hitbsecconf2008kl/?page_id=59">my fun keynote at Hack In The Box 2008</a> in Kuala Lumpur, Malaysia.<br /><br />To make the short story ... even shorter :-), I got kicked off my flight since my passport is only valid 5.5 months in the future and Malaysia requires that visitors' passports are valid for 6 months from the date of arrival (not that they make it anywhere near clear on their embassy website or anything :-)). <br /><br />What makes it funnier is that I got so used to US dates of <span style="font-style: italic;">month/day/year </span>that I actually was genuinely shocked when they said "you passport is not valid for 6 months" while it clearly said "Expires on 8/4/2009" ...<br /><br />So much for Kuala Lumpur :-(  Back to work now.<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=FdDIM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=FdDIM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=VJ6HM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=VJ6HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=0BdyM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=0BdyM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/433838238" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 27 Oct 2008 07:48:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kuala lumpur">kuala lumpur</category>
      <category domain="http://securityratty.com/tag/malaysia requires">malaysia requires</category>
      <category domain="http://securityratty.com/tag/fun keynote">fun keynote</category>
      <category domain="http://securityratty.com/tag/fun">fun</category>
      <category domain="http://securityratty.com/tag/valid">valid</category>
      <category domain="http://securityratty.com/tag/malaysia">malaysia</category>
      <category domain="http://securityratty.com/tag/international travel story">international travel story</category>
      <category domain="http://securityratty.com/tag/spells bad news">spells bad news</category>
      <category domain="http://securityratty.com/tag/months">months</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/433838238/on-hitb-2008-conference.html">on HITB 2008 Conference</source>
    </item>
    <item>
      <title><![CDATA[U.S. Consulate in Northern Mexico attacked with guns and grenade]]></title>
      <link>http://securityratty.com/article/1679d95f1b37d95c0532f78afa7fbd73</link>
      <guid>http://securityratty.com/article/1679d95f1b37d95c0532f78afa7fbd73</guid>
      <description><![CDATA[The motive for last week's attack on the U.S. consulate in Mexico is being investigated but there is still no clear cut reason for the unprovoked attack

The attack had more in common with what we...]]></description>
      <content:encoded><![CDATA[The motive for last week's attack on the  U.S. consulate in Mexico is being investigated but there is still no clear cut reason for the unprovoked attack. <br /><span id="fullpost"><br />The attack had more in common with what we have come to expect in Iraq than from just below the Southern States of the U.S.  News of the attack is making me think more about the article I read in one of the Gulf papers here in the Middle East a couple of days ago.<br /></span><br />The article read; "Mexican workers leave the U.S. disllusioned with the American Dream".  The story, like so many others these days, focused on the worsening U.S. economy.  That made me think; could a returning mexican worker have launched the attack on the embassy due to his frustration at not being able to do as well as he had expected North of the border?<br /><br />I hope for Mexcio's sake this is not the case.  Mexico's dangerous crime rate is already a concern for many people deciding where to go to spend their holiday dollars.  <br /><br />In this current economic climate, visitors need to be encouraged and given a reason to spend their hard earned money in your country, not made to feel like targets.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 19 Oct 2008 14:53:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/mexico">mexico</category>
      <category domain="http://securityratty.com/tag/days ago">days ago</category>
      <category domain="http://securityratty.com/tag/cut reason">cut reason</category>
      <category domain="http://securityratty.com/tag/reason">reason</category>
      <category domain="http://securityratty.com/tag/days">days</category>
      <category domain="http://securityratty.com/tag/gulf papers">gulf papers</category>
      <category domain="http://securityratty.com/tag/middle east">middle east</category>
      <category domain="http://securityratty.com/tag/dangerous crime">dangerous crime</category>
      <source url="http://www.thebulletproofblog.com/2008/10/us-consulate-in-northern-mexico.html">U.S. Consulate in Northern Mexico attacked with guns and grenade</source>
    </item>
    <item>
      <title><![CDATA[The Langley Files]]></title>
      <link>http://securityratty.com/article/1d86287caa54b846b08a3d1020799d36</link>
      <guid>http://securityratty.com/article/1d86287caa54b846b08a3d1020799d36</guid>
      <description><![CDATA[The Central Intelligence Agency doesn't like to talk about its mistakes. It's not just embarrassing, but officials believe exposing details about how an operation went wrong reveals too much about how...]]></description>
      <content:encoded><![CDATA[The Central Intelligence Agency doesn't like to talk about its mistakes. It's not just embarrassing, but officials believe exposing details about how an operation went wrong reveals too much about how it captures enemy secrets. But published statements and news reports suggest one recent error-the U.S. bombing of the Chinese embassy in Belgrade during the Kosovo war last year, which killed three and injured 20-happened in part because CIA officers targeted what they thought was a Yugoslav Army warehouse based on outdated maps, and others failed to catch the mistake before the proposal was passed to the military.]]></content:encoded>
      <pubDate>Sun, 20 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/central intelligence agency">central intelligence agency</category>
      <category domain="http://securityratty.com/tag/captures enemy secrets">captures enemy secrets</category>
      <category domain="http://securityratty.com/tag/cia officers">cia officers</category>
      <category domain="http://securityratty.com/tag/recent error-the">recent error-the</category>
      <category domain="http://securityratty.com/tag/kosovo war">kosovo war</category>
      <category domain="http://securityratty.com/tag/wrong reveals">wrong reveals</category>
      <category domain="http://securityratty.com/tag/news reports">news reports</category>
      <category domain="http://securityratty.com/tag/chinese embassy">chinese embassy</category>
      <category domain="http://securityratty.com/tag/statements">statements</category>
      <source url="http://www.networkworld.com/news/2008/072108-the-langley.html?fsrc=rss-security">The Langley Files</source>
    </item>
    <item>
      <title><![CDATA[What do High School Killers and Terrorists Have in Common?]]></title>
      <link>http://securityratty.com/article/5ca944b7ef73adcbc2fee5dec5e44847</link>
      <guid>http://securityratty.com/article/5ca944b7ef73adcbc2fee5dec5e44847</guid>
      <description><![CDATA[Department of Homeland Security studies show that the Columbine High School killers and the Virginia Tech gunman planned those attacks using the same techniques used by terrorists

The study talks...]]></description>
      <content:encoded><![CDATA[<a href="http://www.dchieftain.com/news/81029-06-18-08.html">Department of Homeland Security studies</a> show that the Columbine High School killers and the Virginia Tech gunman planned those attacks using the same techniques used by terrorists.<br /><span id="fullpost"><br />The study talks about the "7 steps" that terrorists take prior to executing an attack.  The steps begin with; Surveillance, Acquiring information, Testing security, Acquiring supplies, Appearance of being "out of place", Test run and putting everything into position for the planned attack/strike.<br /><br /></span><br />Is there much that ordinary civilians can do to thwart a Terrorist attack or High School killing spree?  The answer is; MOST DEFINITELY.  DHS advises that 25 possible school attacks have been prevented this year so far, due to attentive citizens noticing something that seemed unusual and then reporting it to Law Enforcement.<br /><br />We should not be reluctant to report suspicious persons or circumstances.  Every once in a while the media will run a story about a suspicious package being left behind in a taxi or public place.  Many people will be afraid to report something like that in case it turns out to be a hoax.  BUT YOU SHOULD REPORT IT, NEVERTHELESS.  That "hoax" might very well be a "test/dry run" by terrorists to see if what they leave behind will be detected, or how long it will take to be reported.  The terrorist/bad guy will most likely be timing the reponse as well.<br /><br />Those of us who travel regularly can tell you how long an unattended backpack or shopping bag would be allowed to sit unattended in London or parts of the Middle East.  A Police officer would never get angry at having to respond because; 1)they are happy to see it does not contain a life threatening device (that would threaten their life as well as the lives of the general public) and 2)they know that one day it will be the real thing and when that time arrives, they will be glad of the practice and the fact that the public are helping them to identify danger.<br /><br />In these dangerous times, we should never forget that we are all in this together.  There is no room for complacancy.  Just because you think you are safe and on holiday - remember what happened in Bali.  If you think you are safe because you are in a secured facility or an Embassy overseas, remember Oklahoma and the countless Embassies and Consulates where deadly attacks are becomming a daily occurance.  <br /><br />If something doesn't look or feel right to you, there is a reason that you feel that way.  Like the animals in the jungle, we are able to sense fear/danger in order to assist us with survival.  The next time you report a suspicious activity, the life you save just might be your own.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 20 Jul 2008 16:37:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/school">school</category>
      <category domain="http://securityratty.com/tag/school killers">school killers</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/school attacks">school attacks</category>
      <category domain="http://securityratty.com/tag/report">report</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/report suspicious persons">report suspicious persons</category>
      <category domain="http://securityratty.com/tag/homeland security studies">homeland security studies</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://www.thebulletproofblog.com/2008/07/what-do-high-school-killers-and.html">What do High School Killers and Terrorists Have in Common?</source>
    </item>
    <item>
      <title><![CDATA[Your 419 Mail Roundup]]></title>
      <link>http://securityratty.com/article/cac739eb23af3ee3d5ecd500b5815c6f</link>
      <guid>http://securityratty.com/article/cac739eb23af3ee3d5ecd500b5815c6f</guid>
      <description><![CDATA[A handful of scam mails currently in circulation, including one mention of &quot;groundnut oil&quot; that seems so bizarre I had to highlight it in bold text. All this and more, after the jump
Subject
FROM THE...]]></description>
      <content:encoded><![CDATA[
        A handful of scam mails currently in circulation, including one mention of "groundnut oil" that seems so bizarre I had to highlight it in bold text. All this and more, after the jump...<br />  
        Subject:<br />FROM THE DESK OF MR. STEVEN JAMES<br />From:<br />"Steven James"&lt;steven@fristbnkngplc.net&gt;<br />Date:<br />Mon, 30 Jun 2008 19:17:03 +0100<br />BCC:<br /><br />FROM THE DESK OF MR. STEVEN JAMES<br />CHAIRMAN INTERNATIONAL RELATION<br />FIRST BANK OF NIGERIA PLC<br /># 1 BANK ROAD WUSE FCT <br />ABUJA-NIGERIA.<br />PHONE: +234-80-66520277<br />Email: stevenjames809@live.co.uk&nbsp; <br /><br /><br />Very Urgent Attention,<br /><br />Please permit me to introduce my humble self to you, my name is Mr. Steven James, I am the Manager of International Relation with First Bank of Nigeria Plc, I 'm 38yrs old, and I got your email address from a friend of mine, and my confidence reposed on you. I hope you read this message carefully and reply me immediately. Although we have not met before, but I suggest that this transaction will bring us together.<br /><br />My dear, we had a customer, a foreigner but base here in Nigeria, his Name was Mr. Hamilton Creek. He is from Atlanta Georgia United State of America, but based here with his wife and his two children, Mr. Hamilton has being banking with us for the past 4yrs and some time in August 2002, Mr. Hamilton was on his way to his house, and <b>unfortunately ran into a Trailer load of Groundnut Oil, and died&nbsp;&nbsp; immediately, Their car got burnt, no single soul was saved, Mr. Hamilton Creek and His entire family was confirmed dead.</b><br /><br />My Board of Directors and the Management of First Bank has mandated and instructed me to look for Mr. Hamilton Creek? Relation(s) and his Next of&nbsp; Kin to come and claim his fund, Since August 2003 till date, I have been looking for his relation's or his next of Kin to come and claim his fund which he Deposited with our bank, I have contacted his Embassy and after 3days, his Ambassador told me that Mr. Hamilton Creek has no relation and no next of Kin, their Ambassador told me that he used his first son as His next of kin, but it is quite unfortunate that Mr. Hamilton Creek Died with all his family members.<br /><br />The reason why I contacted you is thus, Mr. Hamilton is dead, and his only son who supposed to inherit his properties and money also died with him. As at this moment, nobody or person[s] is coming to&nbsp;&nbsp; claim this Money from our bank. The Board of Directors and management of our bank told me that if nobody or person[s] apply for the claim of Mr. Hamilton Fund, the bank will return the entire Fund into our Federal reserve. In the Light of the above, I want you to stand as the next of kin to Late Mr. Hamilton Creek; it might interest you to know that he had a Domiciliary Bank Account with our Bank and he has a total sum of US$9.2M Nine Million Two Hundred thousand Dollars, this is the exact amount which he had in his domiciliary account before the ugly incident occurred, and this money is still in his account as unclaimed money.<br /><br />This transaction is very easy and simple, and it is 100% risk free, I'm the Manager for International Relations with First Bank of Nigeria Plc, and the Management and Board of Directors of the Bank are waiting for me to provide to them the Relation or next of Kin to late Mr. Hamilton Creek, of which I told them that I am still searching the next of kin to the deceased. Finally, if you are interested with this transaction, I will front you to the bank as the only next of kin to late Mr. Hamilton Creek, and I will let the bank know that you are the only right person to inherit Late Mr. Hamilton Funds and properties. If you are interested, just email me or call me on my&nbsp;&nbsp; direct and private line#: +234-80-27536038 and late Mr. Hamilton's Funds will be credited into your account and all his Properties will be released to you either through Courier Services or the Bank will Cargo all his properties to you in any were you want it.<br /><br />So reply me immediately and feel free to ask any question with regards to this transaction. You will take 50% of the US$9.2M. Which is? US$4.600, 000.00 Four Million Six Hundred Thousand Dollars, while the Balance of the same amount will be mine.<br /><br />Your swift response will be highly appreciated.<br /><br />Thanks and have a nice day.<br /><br />Friendly Regards<br /><br />Mr. Steven James<br /><br />*******************************************************************************************<br /><br />Subject:<br />REPRESENTATIVE NEEDED<br />From:<br />DFS SALES LTD UK &lt;info@dfs.net&gt;<br />Date:<br />Tue, 01 Jul 2008 23:00:55 +0800<br />To:<br />undisclosed-recipients: ;<br /><br /><br />COMPLIMENT OF THE DAY TO YOU.<br /><br />I am PETER WOODS from DFS SALES LTD UK.(<br />Website: www.dfs-online.co.uk ) Visit our site<br /><br />We are into&nbsp; furnitures and we sell shares to people in<br />Canada,America, Australia and Europe.<br /><br />We are in need of a book keeper. someone who can represent our company<br />in his/her country.<br /><br />Our client in your location will contact you and make the company<br />payment to you.<br /><br />You will be entitle to 11% of every payment been made out to you.<br /><br />This is because most of our officer are from china and they do not<br /><br />understand english very well.its hard for them to contact our<br />customers.<br /><br />Our head office is located in CHINA. But we have a sub-office in the<br />uk.<br /><br />If you are interested, Kindly send the entries for more understanding.<br /><br />NAME IN FULL :.........<br />COMPANY NAME: .....<br />POSITION:......<br />FULL ADDRESS: .......<br />CITY/TOWN:........<br />STATE:............<br />ZIP CODE:........<br />COUNTRY:.......<br />MOBILE:.......<br />HOME TEL: .....<br />EMAIL ADDRESS: ........<br />OCCUPATION: ...........<br />BANK NAME :.......<br />AGE:............<br /><br />You are to send the above details to<br /><br />NAME : PETER WOODS.<br />EMAIL : dfs_woods@yahoo.co.uk<br />PHONE NUMBER : +44-704-575-0212<br /><br />HOPE TO HEAR FROM YOU<br /><br /><br />*****************************************************************************************<br /><br />To:<br />undisclosed-recipients:;<br /><br />Good day!!!<br /><br />&nbsp;We have been waiting for you since to contact me for your Confirmable Bank Draft of ?18 Million (Eighteen Million Pounds sterling) but we did not hear from you since for a couple of weeks now. Then we went to the bank to confirm if the draft that expired or getting near to expire and Metropolitan Police Uk told us that before the funds will get to your hand that it will expire.So I told him to cash the ?18 Million (Eighteen Million Pounds sterling) to cash payment to avoid losing this fund under expiration as I will be out of the country for a 6 Months Course.<br /><br />&nbsp;What you have to do now is to contact FED EX COURIER SERVICES as soon as possible to know when they will deliver of your funds to you because of the expiring date. For your information we have paid for the delivering Charge Insurance premium. The only money you will send to the FED EX COURIER SERVICES to deliver your cheque direct to your postal Address in your country is ?250.00 being Security Keeping Fee of the Courier Company so far. Again don't be deceived by anybody to pay any other money except ?250.00 for the Security Keeping Fee.We would have paid that but they said no because they don't know when you will contact them and in case of demurrage. You have to contact FED EX COURIER SERVICES now for the delivery of your Draft with this<br />information below:<br /><br />&nbsp;CONTROLLER: Mrs.Helen Williams<br />&nbsp;NAME: FED EX COURIER SERVICES<br />&nbsp;ADDRESS: fedexofficeuk@gmail.com<br />&nbsp;PHONE NUMBER: +447024080684<br /><br />&nbsp;IF YOU ARE THE OWENER OF THE FUNDS AND YOU WILL SEND YOUR INFORMATION TO US SO THAT WE CAN DELIVERY YOUR FUNDS TO YOU WITHIN THE NEXT 84HRS TIME.IF YOU DO NOT RECEIVED YOUR FUNDS WITHIN THE NEXT 72HRS TIME AND YOU REPORT US THE UK FBI AND THE METROPOLITAN POLICE (SCOTLAND YARD) or YOU CONTACT YOUR LAWYER TO TAKE UP PROCEDURES AGAINST US.<br /><br />&nbsp;Let me repeat again try to contact them as soon as you receive this mail to avoid any further delay and remember to pay them their Security keeping fee of ?250.00 for their immediate action. The FED EX COURIER SERVICES don't know the contents of the funds. This is to avoid them delaying with the funds.<br /><br />&nbsp;Thanks as you contact them today.<br /><br />&nbsp;Yours Faithfully<br /><br />&nbsp;Mrs Helen Williams.<br /><br /><b>(The above actually comes with a nifty graphic that they've thrown in, thinking it makes it all look more legitimate. It doesn't, but here it is anyway):</b><br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fedx1.jpg" src="http://blog.spywareguide.com/images/fedx1.jpg" class="mt-image-none" style="" height="64" width="472" /></span>
<br /><br />....altogether now: oooooh. A slightly shorter 419 roundup than usual, but I'm sure I'll have piles of the things next week.<br /><br /><br /><div class="moz-text-plain" wrap="true" graphical-quote="true" style="font-family: -moz-fixed; font-size: 13px;" lang="x-cyrillic"><pre wrap=""><br /><br /><br /><br /><br /></pre></div><div><br /></div>
    ]]></content:encoded>
      <pubDate>Wed, 02 Jul 2008 13:11:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hamilton fund">hamilton fund</category>
      <category domain="http://securityratty.com/tag/hamilton">hamilton</category>
      <category domain="http://securityratty.com/tag/hamilton creek">hamilton creek</category>
      <category domain="http://securityratty.com/tag/draft">draft</category>
      <category domain="http://securityratty.com/tag/confirmable bank draft">confirmable bank draft</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/domiciliary bank account">domiciliary bank account</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/hamilton funds">hamilton funds</category>
      <source url="http://blog.spywareguide.com/2008/07/your-419-mail-roundup-1.html">Your 419 Mail Roundup</source>
    </item>
    <item>
      <title><![CDATA[Tourists, Not Terrorists]]></title>
      <link>http://securityratty.com/article/05e7775b13e4f8f380eba023e8a30a04</link>
      <guid>http://securityratty.com/article/05e7775b13e4f8f380eba023e8a30a04</guid>
      <description><![CDATA[Remember the two men who were exhibiting &quot;unusual behavior&quot; on a Washington-state ferry last summer? The agency's Seattle field office, along with the Washington Joint Analytical Center, was still...]]></description>
      <content:encoded><![CDATA[<p>Remember the two men who were <a href="http://www.foxnews.com/story/0,2933,294065,00.html">exhibiting "unusual behavior"</a> on a Washington-state ferry last summer?</p>

<blockquote>The agency's Seattle field office, along with the Washington Joint Analytical Center, was still seeking the men's identities and whereabouts Wednesday as ferry service was temporarily shutdown when a suspicious package was found in a ferry bathroom and taken away by authorities.

<p>"We had various independent reports from passengers and ferry employees that these two guys were engaging in what they described as unusual activities on the ferries," Special Agent Robbie Burroughs, a spokeswoman for the FBI in Washington state, told FOXNews.com.</p>

<p>"They felt that these guys were showing an undue interest in the boat itself, in the layout, the workers and the terminal, and it caused them enough concern that they contacted law enforcement about it," she told FOXNews.com.</p>

<p>The two were photographed by a ferry employee about a month ago, and those photographs were distributed to ferry employees three weeks ago by local law enforcement.</blockquote></p>

<p>Turns out they were <a href="http://seattletimes.nwsource.com/html/localnews/2004394642_fbi06m.html">tourists</a>, not terrorists:</p>

<blockquote>Turns out the men, both citizens of a European Union nation, were captivated by the car-carrying capacity of local ferries.

<p>"Where these gentlemen live, they don't have vehicle ferries. They were fascinated that a ferry could hold that many cars and wanted to show folks back home," FBI Special Agent Robbie Burroughs said Monday.</p>

<p>[...]</p>

<p>Two weeks ago, the men appeared at a U.S. Embassy and identified themselves as the men in the photo released to the media in August, a couple of weeks after they took a ferry from Seattle to Vashon Island during a business trip, Burroughs said.</p>

<p>They came forward because they worried they'd be arrested if they traveled to the U.S. and so provided proof of their identities, employment and the reason for their July trip to Seattle, according to the FBI.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=wK3AfH"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=wK3AfH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=WZmAJH"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=WZmAJH" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 08 May 2008 03:32:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ferry">ferry</category>
      <category domain="http://securityratty.com/tag/ferry bathroom">ferry bathroom</category>
      <category domain="http://securityratty.com/tag/ferry employee">ferry employee</category>
      <category domain="http://securityratty.com/tag/ferry employees">ferry employees</category>
      <category domain="http://securityratty.com/tag/law enforcement">law enforcement</category>
      <category domain="http://securityratty.com/tag/ferries">ferries</category>
      <category domain="http://securityratty.com/tag/local law enforcement">local law enforcement</category>
      <category domain="http://securityratty.com/tag/seattle field office">seattle field office</category>
      <category domain="http://securityratty.com/tag/weeks ago">weeks ago</category>
      <source url="http://www.schneier.com/blog/archives/2008/05/tourists_not_te_1.html">Tourists, Not Terrorists</source>
    </item>
    <item>
      <title><![CDATA[The United Nations Serving Malware]]></title>
      <link>http://securityratty.com/article/d1d822ed6374f6c7f294fed616ac7d76</link>
      <guid>http://securityratty.com/article/d1d822ed6374f6c7f294fed616ac7d76</guid>
      <description><![CDATA[Yet another massive SQL injection attack is making its rounds online, and this time without the SEO poisoning as an attack tactic , has managed to successfully infect the United Nations events page,...]]></description>
      <content:encoded><![CDATA[<div><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SA5b7NDpi2I/AAAAAAAABm4/XilLYHXJoSs/s1600-h/united_nations_malicious_injection.JPG"><img id="BLOGGER_PHOTO_ID_5192188493080136546" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/SA5b7NDpi2I/AAAAAAAABm4/XilLYHXJoSs/s200/united_nations_malicious_injection.JPG" border="0" /></a>Yet another massive SQL injection attack is making its rounds online, and this time without the <a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">SEO poisoning as an attack tactic</a>, has managed to successfully infect the United Nations events page, which is now also marked as malware infected page, and with a reason since both the malicious URl and the injection are still active. <a href="http://securitylabs.websense.com/content/Alerts/3070.aspx">According to WebSense</a> :<br /><br />"<span style="font-style: italic;">This mass injection is remarkably similar to the attack we saw earlier this month. When a </span><span style="font-style: italic;">user browses to a compromised site, the injected JavaScript loads a file named 1.js which is ho</span><span style="font-style: italic;">sted on http://www.nihao[removed].com The JavaScript code then redirects the user to 1.htm (also hosted on the same server). Once loaded, the file attempts 8 different exploits (the attack last April utilised 12). The exploits target Microsoft applications, specifically browsers not patched against the VML exploit MS07-004 as well as other applications. Ominously files named McAfee.htm and Yahoo.php are also called by 1.htm but are no longer active at the time of writing. There are further similarities too between the two mass attacks. Resident on the latest malici</span><span style="font-style: italic;">ous domain is a tool used in the execution of the attack. An analysis of that tool can be found in the ISC diary entry here. Mentioned in that diary entry is http://www.2117[removed].net. Our blog on that attack can be found here. It appears that same tool was used to orchestrate this attack too. </span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SA5rltDpi6I/AAAAAAAABnQ/73aOsN1uYy0/s1600-h/another_massive_injection.JPG"><img id="BLOGGER_PHOTO_ID_5192205715898993570" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SA5rltDpi6I/AAAAAAAABnQ/73aOsN1uYy0/s200/another_massive_injection.JPG" border="0" /></a>Let's assess the malicious injection. <span style="font-weight: bold;">nihaorr1.com/ 1.js</span> (219.153.46.28) is attempting to load <span style="font-weight: bold;">nihaorr1.com/ 1.htm</span>, where several other internal exploit serving URLs and javascript obfuscations load through IFRAMES, such as :<br /><br /><span style="font-weight: bold;">nihaorr1.com/ Real.gif</span> <span style="font-weight: bold;"><br />niha</span><span style="font-weight: bold;">orr1.com/ Yahoo.php</span> <span style="font-weight: bold;"><br />nihaorr1.com/ cuteqq.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ms07055.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ms07033.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ms07018.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ms07004.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ajax.htm</span> <span style="font-weight: bold;"><br />nihaorr1</span><span style="font-weight: bold;">.com/ Ms06014.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Bfyy.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Lz.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Pps.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ XunLei.htm</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SA5rwtDpi7I/AAAAAAAABnY/BGvEieF0v0s/s1600-h/another_massive_injection_2.JPG"><img id="BLOGGER_PHOTO_ID_5192205904877554610" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SA5rwtDpi7I/AAAAAAAABnY/BGvEieF0v0s/s200/another_massive_injection_2.JPG" border="0" /></a>and finally serve the malware, by also taking us out of the point and loading another malicious IFRAME farm at <span style="font-weight: bold;">gg.haoliuliang.net/one/ hao8.htm?036</span> (222.73.44.162) :<br /><br />Scanners Result: 18/<span id="porcentaje"><span style="color:red;"></span>32 (56.25%) :<br />W32/PWStealer1!Generic; PWS:Win32/Lineage.WI.dr<br /></span>File size: 24667 bytes<br />MD5...: 4b913be127d648373e511974351ff04e<br />SHA1..: 0ab703c93e3ad7c03d1aae5ea394d7db3b89bfd2<br /><span id="porcentaje"><br />Another internal IFRAME serving exploits is also loading at </span><span style="font-weight: bold;">haoliuliang.net</span>, <span style="font-weight: bold;">gg.haoliuliang.net/wmwm/ new.htm</span> where a new piece of malware is served :<br /><br />Scanners Result: 26/32 (81.25%)<br />Trojan-PSW.Win32.OnLineGames.ppu; Trojan.PSW.Win32.OnlineGames.GEN<br />File size: 7205 bytes<br />MD5...: af05c777700b338f428463e56f316a05<br />SHA1..: bd68f621ec6c9796afa8b766c6cf4167afbd4703<br /><br />As it appears, everyone's a victim of web application vulnerabilities discovered automatically, and either filtered based on high-page rank, or trying to take advantage of the long-tail of SQL injected sites to compensate for the lack of vulnerable high profile sites.<br /><br /><strong>Related posts:</strong><br /><a href="http://ddanchev.blogspot.com/2008/04/unicef-too-iframe-injected-and-seo.html">UNICEF Too IFRAME Injected and SEO Poisoned</a><br /><a href="http://ddanchev.blogspot.com/2008/03/embedded-malware-at-bloggies-awards.html">Embedded Malware at Bloggies Awards Site</a><br /><a href="http://ddanchev.blogspot.com/2008/03/embedding-malicious-iframes-through.html">Embedding Malicious IFRAMEs Through Stolen FTP Accounts</a><br /><a href="http://ddanchev.blogspot.com/2008/02/yet-another-massive-embedded-malware.html">Yet Another Massive Embedded Malware Attack</a><br /><a href="http://ddanchev.blogspot.com/2007/12/mdac-activex-code-execution-exploit.html">MDAC ActiveX Code Execution Exploit Still in the Wild</a><br /><a href="http://ddanchev.blogspot.com/2008/01/malware-serving-exploits-embedded-sites.html">Malware Serving Exploits Embedded Sites as Usual</a><br /><a href="http://ddanchev.blogspot.com/2008/01/massive-realplayer-exploit-embedded.html">Massive RealPlayer Exploit Embedded Attack</a><br /><a href="http://ddanchev.blogspot.com/2007/09/syrian-embassy-in-london-serving.html">Syrian Embassy in London Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2007/08/bank-of-india-serving-malware.html">Bank of India Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2007/09/us-consulate-st-petersburg-serving.html">U.S Consulate St. Petersburg Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/01/dutch-embassy-in-moscow-serving-malware.html">The Dutch Embassy in Moscow Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/02/uks-feta-serving-malware.html">U.K's FETA Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/02/anti-malware-vendors-site-serving.html">Anti-Malware Vendor's Site Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/02/new-media-malware-gang-part-three.html">The New Media Malware Gang - Part Three</a><br /><a href="http://ddanchev.blogspot.com/2007/12/new-media-malware-gang-part-two.html">The New Media Malware Gang - Part Two</a><br /><a href="http://ddanchev.blogspot.com/2007/11/new-media-malware-gang.html">The New Media Malware Gang</a><br /><a href="http://ddanchev.blogspot.com/2007/10/portfolio-of-malware-embedded-magazines.html">A Portfolio of Malware Embedded Magazines</a><br /><a href="http://ddanchev.blogspot.com/2007/11/another-massive-embedded-malware-attack.html">Another Massive Embedded Malware Attack</a><br /><a href="http://ddanchev.blogspot.com/2007/11/i-see-alive-iframes-everywhere.html">I See Alive IFRAMEs Everywhere</a><br /><a href="http://ddanchev.blogspot.com/2007/11/i-see-alive-iframes-everywhere-part-two.html">I See Alive IFRAMEs Everywhere - Part Two</a></div><br /><div> </div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=h2szloG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=h2szloG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Jh8d9YG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Jh8d9YG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TZyIhPg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TZyIhPg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DQqL6Mg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DQqL6Mg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=tPC4aNG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=tPC4aNG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nWuC8GG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nWuC8GG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3djJeCg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3djJeCg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/276225903" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Apr 2008 06:13:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/malware attack">malware attack</category>
      <category domain="http://securityratty.com/tag/anti-malware vendor">anti-malware vendor</category>
      <category domain="http://securityratty.com/tag/media malware gang">media malware gang</category>
      <category domain="http://securityratty.com/tag/htm">htm</category>
      <category domain="http://securityratty.com/tag/nihaorr1">nihaorr1</category>
      <category domain="http://securityratty.com/tag/load nihaorr1">load nihaorr1</category>
      <category domain="http://securityratty.com/tag/attack tactic">attack tactic</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/276225903/united-nations-serving-malware.html">The United Nations Serving Malware</source>
    </item>
    <item>
      <title><![CDATA[Phishing Tactics Evolving]]></title>
      <link>http://securityratty.com/article/30ee59a46d8acb7f8fa8466791f3491d</link>
      <guid>http://securityratty.com/article/30ee59a46d8acb7f8fa8466791f3491d</guid>
      <description><![CDATA[Malware authors, phishers and spammers have been actively consolidating for the past couple of years, and until they figure out to to vertically integrate and limit the participation of other pa rties...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SAwAZhnVfUI/AAAAAAAABl4/OMpqebw9CrM/s1600-h/malware_infected_host_phishing.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SAwAZhnVfUI/AAAAAAAABl4/OMpqebw9CrM/s200/malware_infected_host_phishing.jpg" alt="" id="BLOGGER_PHOTO_ID_5191524908971425090" border="0" /></a><a href="http://ddanchev.blogspot.com/2007/12/phishers-spammers-and-malware-authors.html">Malware authors, phishers and spammers have been actively consolidating</a> for the past couple of years, and until they figure out to to vertically integrate and limit the participation of other pa<a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html">rties in their activities, this development will continue to remain so. Malware infected hosts are not getting used as stepping stones</a> these days, for <a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html">OSINT</a> or <a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html">cyber espionage</a> purposes, but also, for sending and hosting phishing pages, a tactic in which I'm seeing an increased interest as of recently.  Here are some example of recently spammed phishing campaigns hosting the phishing pages on end user's PCs :<br /><br />- <span style="font-weight: bold;">pool-71-116-244-232.lsanca.dsl-w.verizon.net</span><br />- <span style="font-weight: bold;">user-142o3ds.cable.mindspring.com</span>/online.lloydstsb.co.uk/customer.ibc/logon.html<br />- <span style="font-weight: bold;">user-142o3ds.cable.mindspring.com</span>/onlineid/cgi-bin/onlineid.bankofamerica/sso.login.controller<br />- <span style="font-weight: bold;">user-142o3ds.cable.mindspring.com</span>/halifax-online.co.uk/_mem_bin/halifax_LogIn/formslogin.aspsource=halifaxcouk<br />-<span style="font-weight: bold;"> stolnick-8marta-8b-r1-c1-45.ekb.unitline.ru</span>/halifax-online.co.uk/_mem_bin<br />- <span style="font-weight: bold;">zux006-052-125.adsl.green.c</span>h/onlineid/cgi-bin/onlineid.bankofamerica/sso.login.controller<br />- <span style="font-weight: bold;">rrcs-74-218-5-6.central.biz.rr.com</span>/webview/files//onlineid/cgi-bin/onlineid.bankofamerica/sso.login.controller<br />- <span style="font-weight: bold;">user-0c93qog.cable.mindspring.com</span>/onlineid/cgi-bin/onlineid.bankofamerica/sso.login.controller<br /><br />The second tactic that I've been researching for a while is that of remotely SQL injecting or remotely file including phishing pages on vulnerable sites, as for instance, someone's actively abusing vulnerable sites, which are apparently noticing this malicious activities and taking care of their web application vulnerabilities. Some recent examples include :<br /><br />- <span style="font-weight: bold;">kclmc.org</span>/components/www.halifax.co.uk/_mem_bin/FormsLogin.aspsource=halifaxcouk/Index.PHP<br />- <span style="font-weight: bold;">citrusfsc.org</span>/templates_c/www.halifax-online.co.uk/_mem_bin/halifax_LogIn/formslogin.aspsource=halifaxcouk/index.html<br />- <span style="font-weight: bold;">agentur-schneckenreither.com</span>/administrator/components/com_joomfish/help/www.halifax.co.uk/_mem_bin/formslogin.asp/index.php<br />-<span style="font-weight: bold;"> dziswesele.pl</span>/media/www.halifax.co.uk/_mem_bin/formslogin.asp/<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SAwF4xnVfVI/AAAAAAAABmA/5wNw0ziCkX0/s1600-h/equidi_hacked_phishing_hosting.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SAwF4xnVfVI/AAAAAAAABmA/5wNw0ziCkX0/s200/equidi_hacked_phishing_hosting.jpg" alt="" id="BLOGGER_PHOTO_ID_5191530943400475986" border="0" /></a>In November, 2007, I started making the connecting between a Turkish defacement group that wasn't just defacing the web sites it was coming across, but was also <a href="http://ddanchev.blogspot.com/2007/11/i-see-alive-iframes-everywhere.html">hosting malware on the vulnerable sites</a> :<br /><br />"<span style="font-style: italic;">It gets even more interesting, as it appears that a Turkish defacer like the  ones </span><a style="font-style: italic;" href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">I  blogged about yesterday</a><span style="font-style: italic;"> is somehow connected with the group behind the  recent Possibility Media's Attack, and the Syrian Embassy Hack as some of his  IFRAMES are using the exact urls in the previous attacks.</span>"<br /><br />As of recently, I'm starting to see more such activity, with various defacing groups realizing that monetizing their defacements can indeed improve their revenue streams. For instance, <span style="font-weight: bold;">findaswap.co.uk/administrator/components/com_extplorer/www.Halifax.co.uk/_mem_bin/formslogin.asp/</span>was serving a phishing page, and was also recently <a href="http://www.turk-h.org/defacement/view/268495/findaswap.co.uk/modules">hacked by a Turkish defacement group</a>. Moreover, <span style="font-weight: bold;">equidi.com</span> which is currently defaced is also hosting the following phishing pages within its directory structure, namely, <span style="font-weight: bold;">equidi.com/New2008/Orange</span>; <span style="font-weight: bold;">equidi.com/New2008/www.bankofamerica.com</span>; <span style="font-weight: bold;">equidi.com/New2008/www.halifax.co.uk</span><br /><br />Why are all of these tactics so smart? Mainly because they forward the responsibility to the infected party, and I can reasonably argue that a phishing page hosted at a .biz or .info tld will get shut down faster than the one hosted at a home user's PC. As for the SQL injections, the RFI, and the consolidation between defacers and phishers if it's not defacers actually phishing for themselves, what we might witness anytime now is a vulnerable financial institutions web sites' hosting phishing page, or its web application vulnerabilities used against itself in a social engineering attempt.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UDiiO1G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UDiiO1G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VHJ21hG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VHJ21hG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XCSx1Tg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XCSx1Tg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NlLC6ug"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NlLC6ug" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6vWhX8G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6vWhX8G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=je1QVMG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=je1QVMG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1a1eW8g"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1a1eW8g" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/274774878" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Apr 2008 07:18:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/halifax-online">halifax-online</category>
      <category domain="http://securityratty.com/tag/halifax">halifax</category>
      <category domain="http://securityratty.com/tag/mem binformslogin">mem binformslogin</category>
      <category domain="http://securityratty.com/tag/user">user</category>
      <category domain="http://securityratty.com/tag/user-142o3ds">user-142o3ds</category>
      <category domain="http://securityratty.com/tag/web application vulnerabilities">web application vulnerabilities</category>
      <category domain="http://securityratty.com/tag/mem binhalifax loginformslogin">mem binhalifax loginformslogin</category>
      <category domain="http://securityratty.com/tag/vulnerable sites">vulnerable sites</category>
      <category domain="http://securityratty.com/tag/turkish defacement">turkish defacement</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/274774878/phishing-tactics-evolving.html">Phishing Tactics Evolving</source>
    </item>
    <item>
      <title><![CDATA[Embedded Malware at Bloggies Awards Site]]></title>
      <link>http://securityratty.com/article/2d70cdf7c3222d6baa33fd53c95733f6</link>
      <guid>http://securityratty.com/article/2d70cdf7c3222d6baa33fd53c95733f6</guid>
      <description><![CDATA[The &quot;window of opportunity&quot; for traffic acquisition by taking advantage of a huge anticipated traffic is something malicious parties always find adaptive ways to take advantage of. Back in December,...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/R9hnJ0-0GJI/AAAAAAAABeI/-8N1oPmt4co/s1600-h/bloggie_awards_malware_iframe.jpg"><img id="BLOGGER_PHOTO_ID_5177001190200973458" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/R9hnJ0-0GJI/AAAAAAAABeI/-8N1oPmt4co/s200/bloggie_awards_malware_iframe.jpg" border="0" /></a>The "window of opportunity" for traffic acquisition by taking advantage of a huge anticipated traffic is something malicious parties always find adaptive ways to take advantage of. Back in December, 2007, the same event based <a href="http://ddanchev.blogspot.com/2007/12/have-your-malware-in-timely-fashion.html">malware embedded attack appeared at a French government's site covering France/Libya relations</a> right in the middle of Libya's leader visit in the country. My detailed analysis back then revealed details of the usual RBN connection, with IFRAME hosts switchng between <a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">HostFresh, Ukrtelegroup Ltd, and Turkey Abdallah Internet Hizmetleri</a>, to surprisingly end up to <a href="http://ddanchev.blogspot.com/2008/03/new-media-malware-gang-part-four.html">the New Media Malware Gang</a> original IP, futher confirming the existence of what's now a diverse ecosystem.<br /><br />The same <a href="http://www.news.com.au/technology/story/0,25642,23345956-5014239,00.html">timely malware embedded attack</a> happened at the top of the Annual Weblog Awards site - The Bloggies as <a href="http://blog.trendmicro.com/bloggies-gives-out-malware-before-awards/">TrendMicro assessed on Monday</a> :<br /><br />"<em>The Web site of the Annual Weblogs Awards — more informally known as the Bloggies — was hacked recently, serving up a malicious Javascript to its visitors. This happened on the eve of the award ceremony, as reported in NEWS.com.au.</em>"<br /><br />An embedded malware screenshot is worth a thousand words, so here it goes attached, and IcePack's now easily detectable module :<br /><br /><strong>Scanner results</strong> : 47% Scanner(17/36) found malware!<br /><strong>File Size</strong> : 10666 byte<br /><strong>MD5</strong> : 0860a1f5f1b27db14fedbfc979399fa4<br /><strong>SHA1</strong> : 81c4ca763850fd3d675a0955ee6885ce83db53a5<br />HTML/Psyme.Gen; Trojan-Downloader.JS.Agent.et<br /><br />Moreover, <strong>wilicenwww.biz/1/1/ice-pack/index.php </strong>is currently responding to <strong>202.75.38.150</strong>, and besides the descriptive IcePack host, the IP also responds to the following domains :<br /><br /><strong>bigsavingpharmacy.com</strong><br /><strong>infosecurestatus.com</strong><br /><strong>pharmacysuperdiscount.com</strong><br /><strong>rspectrum.name</strong><br /><strong>sicil.info</strong><br /><strong>sicil256.info</strong><br /><strong>superdiscountpills.com</strong><br /><strong>mydnsweb.net</strong><br /><strong>thegogosearch.com</strong><br /><br />So what? Historical CYBERINT untimately improves your situational awareness. <strong>Sicil.info</strong> was the main domain behind the <a href="http://ddanchev.blogspot.com/2007/09/syrian-embassy-in-london-serving.html">Syrian Embassy in the U.K malware embedded attack</a>. Back then, <strong>sicil.info</strong> was responding to <strong>203.121.79.71</strong>, and now to <strong>202.75.38.150</strong>, switching locations doesn't mean a clean domain reputation anyway.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qpRP4WF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qpRP4WF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KZltAAF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KZltAAF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=We7ROjf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=We7ROjf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TXX6J1f"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TXX6J1f" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=72aFSqF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=72aFSqF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uRuRq5F"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uRuRq5F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hYB17zf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hYB17zf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/250422746" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 12 Mar 2008 15:36:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/timely malware">timely malware</category>
      <category domain="http://securityratty.com/tag/event based malware">event based malware</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/malware screenshot">malware screenshot</category>
      <category domain="http://securityratty.com/tag/icepack">icepack</category>
      <category domain="http://securityratty.com/tag/descriptive icepack host">descriptive icepack host</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <category domain="http://securityratty.com/tag/bloggies">bloggies</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/250422746/embedded-malware-at-bloggies-awards.html">Embedded Malware at Bloggies Awards Site</source>
    </item>
  </channel>
</rss>
