<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: orthelike]]></title>
    <link>http://securityratty.com/tag/orthelike</link>
    <description></description>
    <pubDate>Tue, 20 May 2008 03:46:40 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[All You Need is Storm Worm's Love]]></title>
      <link>http://securityratty.com/article/3b6740ad1fcc1396cba8a4c6dbd8cb18</link>
      <guid>http://securityratty.com/article/3b6740ad1fcc1396cba8a4c6dbd8cb18</guid>
      <description><![CDATA[The Storm Worm malware launched yet another spam campaign promoting links to malware serving hosts, in between a SQL injection related to Storm Worm

These are Storm Worm's latest domains where the...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SDH2B3tDW_I/AAAAAAAABuA/44BP7CT47ag/s1600-h/storm_worm_latest_obfuscation.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SDH2B3tDW_I/AAAAAAAABuA/44BP7CT47ag/s200/storm_worm_latest_obfuscation.JPG" alt="" id="BLOGGER_PHOTO_ID_5202209556582849522" border="0" /></a>The Storm Worm malware launched yet another spam campaign promoting links to malware serving hosts, in between <a href="http://blogs.zdnet.com/security/?p=1131">a SQL injection related to Storm Worm</a>.<br /><br />These are Storm Worm's latest domains where the infected hosts try to phone back :<br /><br /><span style="font-weight: bold;">cadeaux-avenue.cn</span> (active)<br /><span style="font-weight: bold;">polkerdesign.cn</span> (active)<br /><span style="font-weight: bold;">tellicolakerealty.cn</span> (active and SQL injected at vulnerable sites)<br />Administrative Email for the three emails : glinson156 @ yahoo.com<br /><br />Related DNS servers for the latest campaign :<br /><span style="font-weight: bold;"><br />ns.orthelike.com</span> <span style="font-weight: bold;"><br />ns2.orthelike.com</span> <span style="font-weight: bold;"><br />ns3.orthelike.com</span><br /><span style="font-weight: bold;">ns4.orthelike.com</span> <span style="font-weight: bold;"><br />ns.likenewvideos.com</span><br /><span style="font-weight: bold;">ns2.likenewvideos.com</span> <span style="font-weight: bold;"><br />ns3.likenewvideos.com</span> <span style="font-weight: bold;"><br />ns4.likenewvideos.com</span><br /><br />Storm Worm related domains which are now down :<br /><span style="font-weight: bold;"><br />centerprop.cn</span> <span style="font-weight: bold;"><br />apartment-mall.cn</span> <span style="font-weight: bold;"><br />stateandfed.cn </span> <span style="font-weight: bold;"><br />phillipsdminc.cn</span> <span style="font-weight: bold;"><br />apartment-mall.cn</span> <span style="font-weight: bold;"><br />biggetonething.cn</span> <span style="font-weight: bold;"><br />gasperoblue.cn</span> <span style="font-weight: bold;"><br />giftapplys.cn</span> <span style="font-weight: bold;"><br />gribontruck.cn</span> <span style="font-weight: bold;"><br />ibank-halifax.com</span> <span style="font-weight: bold;"><br />limpodrift.cn</span> <span style="font-weight: bold;"><br />loveinlive.cn</span> <span style="font-weight: bold;"><br />newoneforyou.cn</span> <span style="font-weight: bold;"><br />normocock.cn</span> <span style="font-weight: bold;"><br />orthelike.com</span> <span style="font-weight: bold;"><br />supersameas.com</span> <span style="font-weight: bold;"><br />thingforyoutoo.cn</span><br /><br />One of the domains that is injected as an iFrame is using <span style="font-weight: bold;">ns.likenewvideos.com</span> as DNS server, whereas <span style="font-weight: bold;">likenewvideos.com</span> is currently suspended due to "violating Spam Policy". Precisely.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><a href="http://ddanchev.blogspot.com/2007/01/social-engineering-and-malware.html">Social Engineering and Malware</a><br /><a href="http://ddanchev.blogspot.com/2007/02/storm-worm-switching-propagation.html">Storm Worm Switching Propagation Vectors</a><br /><a href="http://ddanchev.blogspot.com/2007/08/storm-worms-use-of-dropped-domains.html">Storm Worm's use of Dropped Domains</a><br /><a href="http://ddanchev.blogspot.com/2007/08/offensive-storm-worm-obfuscation.html">Offensive Storm Worm Obfuscation</a><br /><a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br /><a href="http://ddanchev.blogspot.com/2008/01/storm-worms-st-valentine-campaign.html">Storm Worm's St. Valentine Campaign</a><br /><a href="http://ddanchev.blogspot.com/2007/09/storm-worms-ddos-attitude.html">Storm Worm's DDoS Attitude</a><br /><a href="http://ddanchev.blogspot.com/2007/12/riders-on-storm-worm.html">Riders on the Storm Worm</a><br /><a href="http://ddanchev.blogspot.com/2007/08/storm-worm-malware-back-in-game.html">The Storm Worm Malware Back in the Game</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xudReH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xudReH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bCsAxH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bCsAxH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=458Tzh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=458Tzh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OyT1lh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OyT1lh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eFEBTH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eFEBTH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bw77nH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bw77nH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=o44Eoh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=o44Eoh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/294253029" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 20 May 2008 03:46:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/storm worm">storm worm</category>
      <category domain="http://securityratty.com/tag/storm worm malware">storm worm malware</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/likenewvideos">likenewvideos</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/valentine campaign">valentine campaign</category>
      <category domain="http://securityratty.com/tag/orthelike">orthelike</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/sql injection">sql injection</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/294253029/all-you-need-is-storm-worms-love.html">All You Need is Storm Worm's Love</source>
    </item>
  </channel>
</rss>
