<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: php]]></title>
    <link>http://securityratty.com/tag/php</link>
    <description></description>
    <pubDate>Wed, 09 Jul 2008 03:42:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Fake Celebrity Video Sites Serving Malware - Part Two]]></title>
      <link>http://securityratty.com/article/c395d54f1c682346aee8b2d88973e345</link>
      <guid>http://securityratty.com/article/c395d54f1c682346aee8b2d88973e345</guid>
      <description><![CDATA[Malicious parties remain busy crunching out domain portfolios of legitimately looking celebrity video sites. The very same templates used on the majority of fake celebrity video sites which I exposed...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SKx9HqDP8dI/AAAAAAAACE8/IGlb0IMf6r0/s1600-h/fake_celebrity_malware.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SKx9HqDP8dI/AAAAAAAACE8/O-KOwx_gTlI/s200-R/fake_celebrity_malware.png" /></a>Malicious parties remain busy crunching out domain portfolios of legitimately looking celebrity video sites. The very same templates used on the majority of <a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">fake celebrity video sites</a> which I exposed in a previous post, remain in circulation with anecdotal situations where they aren't even bothering to match the site's logo with the domain name -- it would ruin the malicious economies of scale approach. And since centralization to some, an laziness to others, remains in tact, the fake security software and fake codecs served remain once parked at the same IP as the fake celebrity sites which I'll expose in this post.<br />
<br />
<b>starfeed1 .com</b> - (85.255.117.218)<br />
<b>codecservice1 .com<br />
siteresults1 .com<br />
codecservice6 .com<br />
celebs69 .com<br />
topdirectdownload .com<br />
sexlookupworld .com<br />
favoredtube .com<br />
yourfavoritetube .com<br />
wwvyoutube .com<br />
celebsnofake .com<br />
celebsvidsonline .com<br />
celebstape .com<br />
freevidshardcore .com<br />
topsoftupdate .com<br />
porndebug .com<br />
newfunnyvideo .com<br />
bestfunnyvids .com<br />
pornmoviestube .net</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: right;"><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKx_zJYKp8I/AAAAAAAACFE/s1Gjxxgtk60/s1600-h/celebrity_fake_windows_player.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKx_zJYKp8I/AAAAAAAACFE/ebj-Ry4Nk8g/s200-R/celebrity_fake_windows_player.JPG" /></a><b>worldstars2008 .com</b> - (79.135.167.54)</div><b>antivirus2008-pro .name<br />
antivirus-2008pro .name<br />
antivirus2008pro .name<br />
antivirus2008pro-download .org<br />
antivirus-2008-pro .org<br />
antivirus2008-pro .org<br />
antivirus-2008pro .org<br />
antivirus2008pro .org<br />
thesoft-portal-08 .com<br />
stars-08 .com<br />
thestars-08 .com<br />
thebigstars-08 .com<br />
funny-08 .com<br />
realonlinevideo-2008 .com<br />
2008-adult-2008 .com<br />
adult18tube2008 .com<br />
adultstreamportal2008 .com<br />
2008-adult-s2008 .com&nbsp;</b><br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SKyBJNS-u7I/AAAAAAAACFU/0QslE2edBHQ/s1600-h/best_celebs_viz.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SKyBJNS-u7I/AAAAAAAACFU/KWv9siOWkAg/s200-R/best_celebs_viz.JPG" /></a><b>new-content-s2008 .com<br />
newcontent-s2008 .com<br />
worldstars2008 .com<br />
thestars2008 .com<br />
thebigstars2008 .com<br />
newcontents2008 .com<br />
18x-adult2008 .com<br />
2008adult2008 .com<br />
adult-x2008 .com<br />
hotadulttube08 .com<br />
adultxx-18 .com<br />
newcontent-s2008a .com<br />
antivirus2008pro-download .com<br />
onlinestreamvide .com<br />
onlinestreamvide .com<br />
ns2.onlinestreamvide .com<br />
xxxstreamonline .com4<br />
supersoft21freeware .com<br />
kvm-secure .com<br />
kvmsecure .com<br />
themusic-08portal .com<br />
adultstreamportal .com<br />
streamxxxvideo .com<br />
antivirus-2008-pro .com<br />
antivirus2008-pro .com<br />
antivirus-2008pro .com<br />
thefunny-08 .com<br />
thestars-08 .com<br />
thestars08 .com <br />
celebsnofake .com<br />
adult-s-portal .com<br />
adultsoftcodec .com<br />
adultstreamportal .com<br />
adultxx-18 .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SKyAwLrICsI/AAAAAAAACFM/qnTzrD0L-ow/s1600-h/fake_celebrity_malware1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SKyAwLrICsI/AAAAAAAACFM/zejNrANC_lc/s200-R/fake_celebrity_malware1.png" /></a>And while none of these seem to be taking advantage of client-side exploits, a Russian celebrity site that seems to by syndicating the malicious redirectors from a legitimate advertising network, is an exception worth point out due to the Adobe Flash player exploit it's attempting to take advantage of. <b>&nbsp;</b><br />
<br />
<b>Bestcelebs .ru</b> javascript redirectors through several different doorways :<br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKyCIPWrPkI/AAAAAAAACFc/1o_3Oou-C9U/s1600-h/best_celebs1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKyCIPWrPkI/AAAAAAAACFc/sp7U9iiSyqg/s200-R/best_celebs1.JPG" /></a><b>crklab .us</b>/index.php =&gt; <b>firstblu .cn</b>/3.php?19383577 =&gt; <b>xanjan .cn</b>/in.cgi?mytraf =&gt; <b>atomakayan .biz</b>/afterftpcheck/2603/index.php =&gt; <br />
<b>toksikoza .net</b>/fi/index.php?mytraf =&gt; <b>toksikoza .net</b>/fi/1.swf<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>What you see is so not what you get.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wHAK8K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wHAK8K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=irKgjK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=irKgjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uNxeIk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uNxeIk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NhDw6k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NhDw6k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wScNuK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wScNuK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=m9soyK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=m9soyK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ISkINk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ISkINk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/370688968" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 21:52:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/celebrity video sites">celebrity video sites</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/net fi1">net fi1</category>
      <category domain="http://securityratty.com/tag/russian celebrity site">russian celebrity site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/net fiindex">net fiindex</category>
      <category domain="http://securityratty.com/tag/previous post">previous post</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/370688968/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware - Part Two</source>
    </item>
    <item>
      <title><![CDATA[Compromised Web Servers Serving Fake Flash Players]]></title>
      <link>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</link>
      <guid>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</guid>
      <description><![CDATA[The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/SSFpGnP3wvA/s1600-h/fake_flash1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/qKqvrWeAN3s/s200-R/fake_flash1.png" style="border: 0pt none ;" /></a>The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so much confidence in this risk-forwarding process of hosting their campaigns, that they would start actively spamming the links residing within low-profile legitimate sites across the web.<br />
<br />
This campaign serving fake flash players is getting so prevalent these days due to the multiple spamming approaches used, that it's hard not to notice it - and expose it. From a strategic perspective, having a legitimate low-profile site -- of course with the obvious exceptions being on purposely registered for malicious purposes within the participating sites -- hosting your malicious campaign is pretty creative in terms of forwarding the responsibility, and the eventual blocking of a legitimate site to the its owner. As far as the owner's are concerned, it appears that some of them are already seeing the malware page popping-up on the top of their daily traffic stats, and have taken measures to remove it.<br />
<br />
Moreover, <a href="http://blogs.adobe.com/psirt/2008/08/verifying_installers.html">Adobe's Product Security Incident Response Team (PSIRT) issued a warning notice about the attack yesterday</a>, which could come handy if the <a href="http://www.infoworld.com/article/08/08/05/Adobe_warns_of_bogus_Flash_Player_installers_1.html">attackers weren't taking advantage of client-side vulnerabilities</a>, putting the unware end user is a situation where he <a href="http://blogs.stopbadware.org/articles/2008/08/05/same-dogs-new-tricks">wouldn't even receive a download dialog</a> :<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/LuFjz3rFLAc/s1600-h/fake_flash3_exploit.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/GXwA3Ai1LLY/s200-R/fake_flash3_exploit.jpg" style="border: 0pt none ;" /></a>"<i>We have seen coverage from the security community of a worm on popular social networking sites that is using social engineering lures to get users to install a piece of malware. According to the reports, the worm posts comments on these sites that include links to a fake site. If the link is followed, users are told they need to update their Flash Player. The installer, posted on a malicious site, of course installs malware instead of Flash Player.We’d like to take this opportunity to reiterate the importance of validating installers and updates before installing them. First off, do not download Flash Player from a site other than adobe.com – you can find the link for downloading Flash Player here. This goes for any piece of software (Reader, Windows Media Player, Quicktime, etc.) – if you get a notice to update, it’s not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious.</i>"<br />
<br />
<a href="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/6PfKZxTNQao/s1600-h/fake_flash2.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/ADBheDs2hkk/s200-R/fake_flash2.png" style="border: 0pt none ;" /></a>The structure of the malware campaign is pretty static, with several exceptions where they also take advange of client-side vulnerabilities (Real player exploit) attempting to automatically deliver the fake flash update or player depending on the campaign. On each and every site, there are <b>dnd.js</b> and <b>master.js</b> scripts shich serve the rogue download window, and another .html file, where an IFRAME attempts to access the traffic management command and control, in a random URL it was <b>207.10.234.217/cgi-bin/index.cgi?user200</b>. A sample list of participating URLs, most of which are still active and running :<br />
<br />
<div style="text-align: left;"><b>joseantoniobaltanas .com</b></div><b>automoviliaria .es/hotnews.html<br />
risasnc .it/fresh.html<br />
carpe-diem .com.mx/fresh.html<br />
kotilogullari .com.tr/hotnews.html<br />
ferrariclubpesaro .it/hotnews.html<br />
imobiliariacom .com.br/default.html<br />
misoares .com<br />
osniehus .de/fresh.html<br />
mydirecttube .com/1/5098/<br />
madosma .com/default.html<br />
tutotic .com/checkit.html<br />
veit-team .si/default.html<br />
antigewaltkurse .de/stream.html<br />
kwhgs .ca/topnews.html<br />
vorgo .com/stream.html<br />
ankaraspor .com.tr/default.html<br />
xxxdnn0314 .locaweb.com.br/watchit.html<br />
ossuzio .com/watchit.html<br />
cit-inc .net/default.html<br />
negocioindependiente .biz/default.html<br />
ambermarketing .com/topnews.html<br />
web27 .login-7.loginserver.ch/stream.html<br />
moretewebdesign .br-web.com/stream.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/hotnews.html<br />
campodifiori .it/topnews.html<br />
212.50.55.81 /stream.html<br />
logisigns .net/fresh.html<br />
intimaescorts .com/default.html<br />
ghioautotre .it/live.html<br />
geckert .de/stream.html<br />
yuricardinali .com/watchit.html<br />
retder .com/fresh.html<br />
valdaran .es/default.html<br />
getadultaccess .com/movie/?aff=5274<br />
bauelemente-giering .de/stream.html<br />
newyork-hebergement .com/watchit.html<br />
allevatoritrotto .it/live.html<br />
exoss2 .com/hotnews.html<br />
soundandlightkaraoke .com/stream.html<br />
land-kan .com/stream.html<br />
grimaldi.nexenservices .com/watchit.html<br />
inconstancia .com.br/watchit.html <br />
gretelstudio .com/stream.html<br />
sumacyl .com/watchit.html<br />
mysna .net/fresh.html<br />
gimnasioyx .com.ar/watchit.html<br />
lagalbana .com/watchit.html<br />
bielizna.tgory .pl/topnews.html<br />
bcs92.imingo .net/stream.html<br />
lapiramidecoslada .es/topnews.html<br />
raulortega .com/stream.html<br />
go-art-morelli .de/hotnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
dianagraf .es/default.html<br />
komma10-thueringen .de/hotnews.html<br />
miavassilev .com/stream.html<br />
swampgiants .com/watchit.html<br />
compagniedephalsbourg .com/fresh.html<br />
arla-rc .net/hotnews.html<br />
salacopernico .es/watchit.html<br />
drfinster .de/checkit.html<br />
healthylifehypnotherapy .com/stream.html<br />
ecotrike-bg .com/fresh.html<br />
paoepalavra .org/watchit.html<br />
jureplaninc-sp .com/topnews.html<br />
fichte-lintfort .de/default.html<br />
hergert-band .de/checkit.html<br />
izliyorum .org/topnews.html<br />
lideka .com/stream.html<br />
athena-digitaldesign .com.tw/hotnews.html<br />
e-paso .pl/stream.html<br />
colombeblanche .org/stream.html<br />
teatromalasa .es/watchit.html<br />
mesporte.digiweb.com .br/stream.html<br />
bistrodavila.com .br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
jbhumet .com/default.html<br />
gruppouni .com/hotnews.html<br />
francex .net/fresh.html<br />
galvatoledo .com/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
kroenert .name/default.html<br />
textilhogarnovadecor .com/topnews.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
neticon .pl/hotnews.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
easterstreet .de/fresh.html<br />
piogiovannini .com.ar/watchit.html<br />
ser-all .com/topnews.html<br />
petzold-dieter .de/checkit.html<br />
beatmung-brandenburg .de/checkit.html<br />
ossuzio .com/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
zelenaratolest .cz/pornotube/index1.htm<br />
ambulatoriovirtuale .it/topnews.html<br />
10a3 .ru/index1.php<br />
izliyorum .org/topnews.html<br />
collectedthoughts .co.uk/index12.html<br />
afg .es/topnews.html<br />
albertruiz .net/topnews.html<br />
bielizna.tgory .pl/topnews.html<br />
blueseven.com .br/topnews.html<br />
bollettinogiuridicosanitario .it/topnews.html<br />
caprilchamonix.com .br/topnews.html<br />
carlolongarini .it/topnews.html<br />
champimousse .com/topnews.html<br />
cheviot.org .nz/topnews.html<br />
contrapie .com/topnews.html<br />
gruppouni .com/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
herbatele .com/topnews.html<br />
houseincostaricaforsale .com/topnews.html<br />
alim.co .il/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
amafe .org/topnews.html<br />
ambulatoriovirtuale .it/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
automoviliaria .es/topnews.html<br />
autoreserve .fr/topnews.html<br />
izliyorum .org/topnews.html<br />
jureplaninc-sp .com/topnews.html<br />
kwhgs .ca/topnews.html<br />
lapiramidecoslada .es/topnews.html<br />
last-minute-reisen-4u .de/topnews.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
corradiproject .info/topnews.html<br />
dantealighieriasturias .es/topnews.html<br />
deliriuslaspalmas .com/topnews.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/topnews.html<br />
fonavistas .com/topnews.html<br />
fraemma .com/topnews.html<br />
fundmyira .com/topnews.html<br />
galvatoledo .com/topnews.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
markmaverick .com/topnews.html<br />
micela .info/topnews.html<br />
motoclubnosvamos .com/topnews.html<br />
nebottorrella .com/topnews.html<br />
negozistore .it/topnews.html<br />
neticon .pl/topnews.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
segelclub-honau .de/topnews.html<br />
snmobilya .com/topnews.html<br />
splashcor .com.br/topnews.html<br />
stephanmager .gmxhome.de/topnews.html<br />
svcanvas .com/topnews.html<br />
tautau.web .simplesnet.pt/topnews.html<br />
textilhogarnovadecor .com/topnews.html<br />
theflorist4u .com/topnews.html<br />
thewindsorhotel .it/topnews.html<br />
vuelosultimahora .com/topnews.html<br />
aliarzani .de/topnews.html<br />
ambermarketing .com/topnews.html<br />
arnold82.gmxhome .de/topnews.html<br />
ocoartefatos.com .br/topnews.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
projetsoft .net/topnews.html<br />
rbc.gmxhome .de/topnews.html<br />
beatmung-sachsen .eu/topnews.html<br />
campodifiori .it/topnews.html<br />
clickjava .net/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
dammer .info/topnews.html<br />
embedded-silicon .de/topnews.html<br />
ferrariclubpesaro .it/topnews.html<br />
fgwiese .de/topnews.html<br />
fswash.site .br.com/topnews.html<br />
fytema .es/topnews.html<br />
gildas-saliou. com/topnews.html<br />
go-art-morelli .de/topnews.html<br />
go-siegmund .de/topnews.html<br />
guerrero-tuning .com/topnews.html<br />
gut-barbarastein .de/topnews.html<br />
japansec .com/topnews.html<br />
komma10-thueringen .de/topnews.html<br />
koon-design .de/topnews.html<br />
lanz-volldiesel .de/topnews.html<br />
lauscher-staat .de/topnews.html<br />
losnaranjos.com .es/topnews.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
nepi.si/topnews .html<br />
radieschenhein. de/topnews.html<br />
residenceflora .it/topnews.html<br />
sabuha .de/topnews.html<br />
ser-all .com/topnews.html<br />
siemieniewicz .de/topnews.html<br />
viajesk .es/topnews.html<br />
allevatoritrotto .it/live.html<br />
bollettinogiuridicosanitario .it/live.html<br />
carlolongarini .it/topnews.html<br />
maremax .it/topnews.html<br />
negozistore .it/topnews.html<br />
parapendiolestreghe .it/live.html<br />
www.donlisander .it/stream.html<br />
aerogenesis .net/watchit.html<br />
allevatoritrotto .it/live.html<br />
atelier-de-loulou .fr/topnews.html<br />
bistrodavila.com .br/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
caprilchamonix.com .br/topnews.html<br />
cheviot.org .nz/live.html<br />
condorautocenter .com.br/watchit.html<br />
dantealighieriasturias .es/live.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/live.html<br />
fonavistas .com/topnews.html<br />
fundmyira .com/topnews.html<br />
g6esporte .com.br/stream.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
gretelstudio .com/stream.html<br />
gutierrezymoralo .com/watchit.html<br />
healthylifehypnotherapy .com/stream.html<br />
herbatele .com/live.html<br />
jureplaninc-sp .com/topnews.html<br />
lacomercialsrl .com.ar/stream.html<br />
lagalbana .com/watchit.html<br />
lapuertaestrecha .com.es/watchit.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
myadultcube .com/flash//aff=5176<br />
myadultcube .com/flash//aff=5810<br />
myadultcube .com/movie//aff=5155<br />
newyork-hebergement .com/watchit.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
omdconsulting .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
parapendiolestreghe .it/live.html<br />
regesh. co.il/watchit.html<br />
rikkeroenneberg .dk/watchit.html<br />
s215847279 .onlinehome.fr/stream.html<br />
salacopernico .es/watchit.html<br />
seekzones .com/watchit.html<br />
seicomsl .es/watchit.html<br />
sigma-lux .ro/watchit.html<br />
soundandlightkaraoke .com/stream.html<br />
stephanmager.gmxhome .de/topnews.html<br />
tartuinstituut .ca/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
aliarzani .de/topnews.html<br />
ambermarketing. com/live.html<br />
bilbondo .com/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
colombeblanche .org/stream.html<br />
donlisander .it/stream.html<br />
fgwiese .de/topnews.html<br />
geckert .de/stream.html<br />
helene-taucher .de/watchit.html<br />
lanz-volldiesel .de/topnews.html<br />
mairie-margnylescompiegne .fr/watchit.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
ossuzio .com/watchit.html<br />
piogiovannini .com.ar/watchit.html<br />
sabuha .de/topnews.html<br />
sumacyl .com/watchit.html<br />
swampgiants .com/watchit.html<br />
xn--glland-3ya .de/stream.html<br />
yuricardinali .com/watchit.html</b><br />
<b>nepi .si/topnews.html<br />
dammer .info/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
galvatoledo .com/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
micela .info/topnews.html<br />
bistrodavila .com.br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
gruppouni .com/hotnews.html<br />
galvatoledo .com/topnews.html<br />
kroenert .name/default.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
dantealighieriasturias .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
89.19.29 .13/stream.html<br />
slobodandjakovic .com/fresh.html<br />
cqcs.com .br/stream.html<br />
seekzones .com/watchit.html<br />
pascosa .it/stream.html<br />
caprilchamonix .com.br/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
ferien-urlaub-lastminute .de/default.html<br />
mueggelpark .info/watchit.html<br />
hillner-online .de/fresh.html<br />
guiasaojose .net/default.html<br />
deliriuslaspalmas .com/topnews.html<br />
fraemma .com/topnews.html<br />
morsbaby .net/default.html<br />
vickywhite .com/fresh.html<br />
micela .info/topnews.html<br />
corradiproject .info/topnews.html<br />
liguehavraise .com/live.html<br />
capacitacaoemlideranca .com.br/fresh.html<br />
materialesyacabados .com.mx/stream.html<br />
208.112.7.68 /checkit.html<br />
152.10.1.37 /1.html<br />
carlolongarini .it/topnews.html<br />
splashcor.com .br/topnews.html<br />
lobpreisstrasse .org/1.html<br />
motoclubnosvamos .com/hotnews.html<br />
hk-rc.com /1.html<br />
taaf.re /stream.html<br />
dulceysalao .com/default.html<br />
amafe .org/topnews.html <br />
</b><br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/MTxnF1XLDCw/s1600-h/fake_flash3_rogue_software.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/3Dgh4x23dRs/s200-R/fake_flash3_rogue_software.png" style="border: 0pt none ;" /></a>Sample detection rate : <span id="status_nombre">flashupdate.exe</span><br />
<span id="status_nombre"><b>Scanners Result</b>: 35/36 (97.23%)</span><br />
<span id="status_nombre">Trojan-Downloader.Win32.Exchanger.hk; Troj/Cbeplay-A</span><br />
<b>File size</b>: 78848 bytes<br />
<b>MD5</b>...: c81b29a3662b6083e3590939b6793bb8<br />
<b>SHA1</b>..: d513275c276840cb528ce11dd228eae46a74b4b4<br />
<br />
The downloader then "phones back home" at <b>72.9.98.234 port 443 </b>which is responding to the rogue security software AntiSpy Spider (<b>antispyspider.net</b>) :<br />
<br />
"<i>AntiSpy Spider is a cutting-edge anti-spyware solution.This revolutionary anti-spyware program was created by the industry's top spyware experts in order to protect your computer and your privacy.html, while ensuring optimal system performance.With the ability to locate, eliminate and prevent the widest range of spyware threats, AntispyStorm is able to offer its users a safe, spyware-free computing experience; and with it's convenient automatic update feature, AntispyStorm ensures continuous up-to-date protection.</i>" <br />
<br />
Sample detection rate : antispyspider.msi<br />
<b>Scanners Result</b>: 11/35 (31.43%)<br />
FraudTool.Win32.AntiSpySpider.b;&nbsp; <br />
<b>File size</b>: 1851904 bytes<br />
<b>MD5</b>...: 2f1389e445f65e8a9c1a648b42a23827<br />
<b>SHA1</b>..: e32aa6aa791e98fe6fdef451bd3b8a45bad0acd8<br />
<br />
The bottom line - over a thousand domains are participating, with many other apparently joining the party proportionally with the web site owner's actions to get rid of the malware campaign hosted on their servers.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BvcTqK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BvcTqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=onawHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=onawHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fa1ek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fa1ek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5nQAgk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5nQAgk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sqdHIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sqdHIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mq3LKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mq3LKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8zplkk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8zplkk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/356677080" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 10:50:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/html file">html file</category>
      <category domain="http://securityratty.com/tag/html">html</category>
      <category domain="http://securityratty.com/tag/comtopnews">comtopnews</category>
      <category domain="http://securityratty.com/tag/detopnews">detopnews</category>
      <category domain="http://securityratty.com/tag/windows media player">windows media player</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/real player exploit">real player exploit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/356677080/compromised-web-servers-serving-fake.html">Compromised Web Servers Serving Fake Flash Players</source>
    </item>
    <item>
      <title><![CDATA[Storm Worm's Lazy Summer Campaigns]]></title>
      <link>http://securityratty.com/article/e155e33c098c672d2c7846d029362254</link>
      <guid>http://securityratty.com/article/e155e33c098c672d2c7846d029362254</guid>
      <description><![CDATA[The Storm Worm-ers seem to be lacking their usual creativity in respect to the usual social engineering attacks taking advantage of the momentum we're used to seeing. These days they're not...]]></description>
      <content:encoded><![CDATA[<div class="separator" style="text-align: left; clear: both;"><a href="http://bp1.blogger.com/_wICHhTiQmrA/SJGcBUK9GWI/AAAAAAAAB-s/q19bj3vUnhc/s1600-h/ff.gif" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJGcBUK9GWI/AAAAAAAAB-s/r6me1CKXkVc/s200-R/ff.gif" style="border: 0pt none ;" /></a></div>The Storm Worm-ers seem to be lacking their usual creativity in respect to the usual social engineering attacks taking advantage of the momentum we're used to seeing. These days they're not piggybacking on real news items, <a href="http://honeyblog.org/archives/197-New-Storm-Campaign-Amero.html">they're starting to come up with new ones</a>.<br />
<br />
Storm's latest "FBI vs Facebook" campaign is an example of very badly executed one, lacking their usual fast-flux, any kind of social engineering common sense,&nbsp; as well as client side exploits next to centralizing all the participating domains on a single nameserver.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div>Domains used :<br />
<b>wapdailynews .com<br />
smartnewsradio .com<br />
bestvaluenews .com<br />
toplessnewsradio .com<br />
companynewsnetwork .com<br />
goodnewsgames .com<br />
marketgoodnews .com<br />
fednewsworld .com<br />
toplessdailynews .com<br />
stocklownews .com</b><br />
<a href="http://bp3.blogger.com/_wICHhTiQmrA/SJGc5mMmHPI/AAAAAAAAB-0/YX-edkoIqeU/s1600-h/stormworm_fbi_facebook.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJGc5mMmHPI/AAAAAAAAB-0/ZkZhjt1csUA/s200-R/stormworm_fbi_facebook.png" style="border: 0pt none ;" /></a><br />
DNS servers :<br />
<b>NS.BRPRBGOK6 .COM</b><br />
<b>NS2.BRPRBGOK6 .COM</b><br />
<b>NS3.BRPRBGOK6 .COM&nbsp;</b><br />
<b>NS4.BRPRBGOK6 .COM</b><br />
<b>NS5.BRPRBGOK6 .COM</b><br />
<b>NS6.BRPRBGOK6 .COM</b><br />
<br />
Strangely, the domain has been registered using an email hosted on a known Storm fast-flux node used in the recent <a href="http://blogs.zdnet.com/security/?p=1440">4th of July campaign</a> and the <a href="http://ddanchev.blogspot.com/2008/07/storm-worms-us-invasion-of-iran.html">U.S's invasion of Iran</a> :<br />
<br />
<i>Administrative Contact:<br />
<b>Lee Chung lee@likethisone1.com</b><br />
+13205897845 fax: <br />
1743, 34<br />
Los-Angeles CA 321458<br />
us</i><br />
<br />
This Storm Worm sample is also "phoning back home" over HTTP next to the P2P traffic, and trying to obtain the rootkit from the now down, <b>policy-studies.cn /getbackup.php</b> using already known Storm nameservers :<br />
<br />
<b>ns2.verynicebank .com</b><br />
<b>ns3.verynicebank .com</b><br />
<b>ns.likethisone1 .com</b><br />
<b>ns2.likethisone1 .com</b><br />
<b>ns3.lollypopycandy .com</b><br />
<b>ns4.lollypopycandy .com</b><br />
<br />
Someone's bored, definitely, making it look like it's almost someone else managing a Storm Worm campaign on behalf of them.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=X5UfaJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=X5UfaJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UdrqvJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UdrqvJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5V52Cj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5V52Cj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vMsoHj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vMsoHj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CVV77J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CVV77J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3J26GJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3J26GJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OzKbLj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OzKbLj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/351463114" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 02:39:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/storm">storm</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/storm worm campaign">storm worm campaign</category>
      <category domain="http://securityratty.com/tag/storm nameservers">storm nameservers</category>
      <category domain="http://securityratty.com/tag/storm worm sample">storm worm sample</category>
      <category domain="http://securityratty.com/tag/storm fast-flux node">storm fast-flux node</category>
      <category domain="http://securityratty.com/tag/brprbgok6">brprbgok6</category>
      <category domain="http://securityratty.com/tag/usual social">usual social</category>
      <category domain="http://securityratty.com/tag/lee chung leelikethisone1">lee chung leelikethisone1</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/351463114/storm-worms-lazy-summer-campaigns.html">Storm Worm's Lazy Summer Campaigns</source>
    </item>
    <item>
      <title><![CDATA[The Bitrix open redirect vulnerability: a lesson in the absurd]]></title>
      <link>http://securityratty.com/article/ba33a71b163a199270da98310b1b1201</link>
      <guid>http://securityratty.com/article/ba33a71b163a199270da98310b1b1201</guid>
      <description><![CDATA[I try to limit my heckling to McYouKnowWho, but I just stumbled across an issue I couldn't leave alone
If you've been keeping up on recent articles I've published, you know open redirect...]]></description>
      <content:encoded><![CDATA[I try to limit my heckling to McYouKnowWho, but I just stumbled across an issue I couldn't leave alone. <br />If you've been keeping up on recent articles I've published, you know open redirect vulnerabilities really bother me; thus <span style="font-style:italic;">Open redirect vulnerabilities: definition and prevention</span> in <a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-17.pdf">(IN)SECURE Issue 17</a>. <br /><span style="font-style:italic;"><span style="font-weight:bold;">Sidebar:</span> I recently spotted a great academic <a href="http://www.cs.indiana.edu/cgi-pub/cshue/research/woot08.pdf" target="_blank">paper</a> on the same issue by Shue, Kalafut, and Gupta at Indian University. Definitive, to say the least.</span><br />Back to the issue at hand. It should have occurred to me to check for this earlier; write it off to being busy. Allow me to spell it out simply.<br /><br />1) On May 2nd, 2008, I <a href="http://holisticinfosec.org/content/view/62/45/" target="_blank">published</a> a open redirect vulnerability in Bitrix Site Manager 6.5, specifically <a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2052" target="_blank">CVE-2008-2052</a>.<br /> <br />2) The vulnerability is a simple one to reproduce, easily exploited by phishers and malware propagators. The issue is still unresolved by the vendor, so here's an example, still available, from their site:<br /><a href="http://www.bitrixsoft.com/bitrix/redirect.php?event1=demo_out&event2=sm_demo&event3=pdemo&goto=http://www.xssed.com/news/29/The_dangers_of_Redirect_vulnerabilities/" target="_blank">http://www.bitrixsoft.com/bitrix/redirect.php?event1=demo_out&event2=<br />sm_demo&event3=pdemo&goto=http://www.xssed.com/news/29/<br />The_dangers_of_Redirect_vulnerabilities</a>/<br />Obviously, the fact that I can send you to XSSed.com's fine explanation of the issue, in the context of the vendor's site, is a no-no in Web App Sec 101. In May, the vendor  responded, saying they'd fix it, but I've not received the promised communication that they have. Their own site certainly hasn't been mitigated, so we'll see.<br /><br />3) One of the sites I found exhibiting this vulnerability while researching the issue via Googledork is <a href="http://en.securitylab.ru" target="_blank">http://en.securitylab.ru</a>.<br /><br />4) The same day, en.securitylab.ru posts their <a href="http://en.securitylab.ru/nvd/352513.php" target="_blank">version</a> of the CVE vulnerability advisory for the Bitrix vulnerability.<br />   <br />5) As a reference, en.securitylab.ru links to my original advisory <span style="font-weight:bold;">USING THE EXACT SAME VULNERABLE REDIRECT SCRIPT!</span><br /><a href="http://en.securitylab.ru/bitrix/redirect.php?event3=352513&goto=http://holisticinfosec.org/content/view/62/45/" target="_blank">http://en.securitylab.ru/bitrix/redirect.php?event3=352513&<br />goto=http://holisticinfosec.org/content/view/62/45/</a><br /><br />To this day, neither the vendor's site, nor Security Lab's site have been mitigated.<br />A malicious attacker could send a "security advisory" in a phishing email, supposedly from Security Lab, and redirect the victim to another web site, likely also somewhere in Russia, and laden with malware.<br />This could be a candidate for <a href="http://pwnie-awards.org/2008/" target="_blank">Pwnie Award</a> 2009. ;-)<br /><br />Common, people...fix it!<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/07/bitrix-open-redirect-vulnerability.html&title=The%20Bitrix%20open%20redirect%20vulnerability:%20a%20lesson%20in%20the%20absurd " title="The Bitrix open redirect vulnerability: a lesson in the absurd ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/07/bitrix-open-redirect-vulnerability.html" title="The Bitrix open redirect vulnerability: a lesson in the absurd ">digg</a>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 19:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/redirect">redirect</category>
      <category domain="http://securityratty.com/tag/redirect vulnerability">redirect vulnerability</category>
      <category domain="http://securityratty.com/tag/cve vulnerability advisory">cve vulnerability advisory</category>
      <category domain="http://securityratty.com/tag/redirect vulnerabilities">redirect vulnerabilities</category>
      <category domain="http://securityratty.com/tag/bitrix site manager">bitrix site manager</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/issue">issue</category>
      <category domain="http://securityratty.com/tag/secure issue">secure issue</category>
      <source url="http://holisticinfosec.blogspot.com/2008/07/bitrix-open-redirect-vulnerability.html">The Bitrix open redirect vulnerability: a lesson in the absurd</source>
    </item>
    <item>
      <title><![CDATA[Lazy Summer Days at UkrTeleGroup Ltd]]></title>
      <link>http://securityratty.com/article/6215851b79c397250e5f1b5a07d047b4</link>
      <guid>http://securityratty.com/article/6215851b79c397250e5f1b5a07d047b4</guid>
      <description><![CDATA[The result of building extra confidence into your malicious hosting provider's ability to remain online , is a scammy ecosystem that's constantly jumping from one netblock to another, whose very...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/SIXAHtEXmGI/AAAAAAAAB8c/T7J6WUyV9a4/s1600-h/avxp08.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIXAHtEXmGI/AAAAAAAAB8c/qDKYv6DcETA/s200-R/avxp08.png" style="border: 0pt none ;" /></a>The result of building extra confidence into your <a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">malicious hosting provider's ability to remain online</a>, is a scammy ecosystem that's constantly jumping from one netblock to another, whose very latest exploit URLs and rogue security software nexto to the codecs served, always represent a decent sample of malicious activities to analyze.<br />
<br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">UkrTeleGroup Ltd</a> (<i>85.255.112.0-85.255.127.255 UkrTeleGroup UkrTeleGroup Ltd. 27595 ASN ATRIVO</i>), a personal favorite due to its historical connection with the Russian Business Network, and hosting provider for a countless of number of injected and malware embedded campaigns during the last two years, is still keeping it as lazy as possible, a laziness allowing you to easily expose a great deal of the malicious activities going on there, and establish the connections between the hosting provider, its current and historical customers.<br />
<br />
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SIXJBRIoucI/AAAAAAAAB8k/r9Y6CPtAE0Y/s1600-h/rogue_software_codecs_UkrTeleGroup.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIXJBRIoucI/AAAAAAAAB8k/cHCoWY8V1RY/s200-R/rogue_software_codecs_UkrTeleGroup.JPG" style="border: 0pt none ;" /></a>Take <b>microsoftcodecs.com</b> (88.214.198.220) for instance, and <b>avxp08.com</b> where it redirects the user into yet another rogue security software. <b>avxp08.com</b> is responding to 194.110.162.114; 216.195.41.11; 216.195.41.11; 216.240.139.169, and to UkrTeleGroup Ltd's 85.255.117.163.<br />
<br />
Each of these IPs are also being shared by other rogue software and fake codecs simultaneously :<br />
<br />
(216.195.41.11)<br />
<b>antivirusxp2008 .com<br />
malwareprotector2008 .com<br />
antivirxp08 .com<br />
antivirusxp08 .com<br />
avxp08 .com<br />
youpornztube .com<br />
winifixer .com<br />
advancedxpfixer .com<br />
encountertracker .ws</b><br />
<br />
It gets even more UkrTeleGroup Ltd related upon the malware (Trojan:Win32/Tibs.HK) served at the <b>avxp08.com </b>gets sandboxed. The malware phones back home <b>stat.avxp08 .com </b>(85.255.118.172)<b> </b>announcing the successful infection <b>winifixer .com/log2.php?affid=980382bdb4e7b779ff6308b0b706571c&amp;uid=06f80eaf-94d7-4b8b-9cf0-5c6f75d2c69f&amp;tm=1211198022</b> (85.255.118.171), and the scammy ecosystem continues using the same hosting provider. The rest of the rogue tools are also using the same subdomain structure, and IP, <b>stat.antivirusxp2008 .com</b> (85.255.118.172), <b>stat.antivirxp08 .com</b> (85.255.118.172), <b>stat.antivirusxp08 .com</b> (85.255.118.172) in order to phone back home.<br />
<br />
<div class="separator" style="text-align: left; clear: both;"><a href="http://bp3.blogger.com/_wICHhTiQmrA/SIXMeEAQTmI/AAAAAAAAB8s/bax-CAw9xJ8/s1600-h/fake_windows_media_player.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SIXMeEAQTmI/AAAAAAAAB8s/_hv8u7SKjP8/s200-R/fake_windows_media_player.JPG" style="border: 0pt none ;" /></a></div><b>winifixer .com</b>, a well known rogue software, is entirely relying on UkrTeleGroup's hosting services hosted at 85.255.117.163; 85.255.118.171; 85.255.120.115; 85.255.120.139; 216.195.41.11 pinpoing several other obvious and well known netblocks hosting anything starting from fake celebrity video sites serving fake Windows Media Player videos, to rogue security software and live exploit URLs. Take for instance their efficiency centered approach to park numerous malicious domains on a single IP, like 85.255.117.218 in this case :<br />
<br />
<b>bestfunnyvids .com<br />
celebs69 .com<br />
celebsnofake .com<br />
celebstape .com<br />
celebsvidsonline .com<br />
codecservice1 .com<br />
freevidshardcore .com<br />
newfunnyvideo .com<br />
sexlookupworld .com<br />
starfeed1 .com<br />
starfeed2 .com<br />
topdirectdownload .com&nbsp;&nbsp;&nbsp; <br />
topsearchresults1 .com<br />
topsoftupdate .com<br />
yourfavoritetube .com</b><br />
<br />
Now that it's becoming clear who's providing the hosting infrastructure, it's perhaps also worth pointing out who's using the hosting infrastructure to serve rogue security software and fake codecs on the basis of participating in an affiliate program? A great number of domains used by the rogue security software are registered by <b>krab@thekrab.com</b> behind which is supposidely Mishakov Viktor Ivanovich <b>support@tobesoftware.com</b>, and ironically <b>tobesoftware.com</b> is again hosting within UkrTeleGroup (85.255.120.115). The personal efforts into the number of the typosquatted domains and the persistence applied when registered and spamming them across the web, is the result of the incentives provided to them by the affiliate program they participate in.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CNeYgJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CNeYgJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UZqVKJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UZqVKJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FhKPZj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FhKPZj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6DFhuj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6DFhuj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pxNm7J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pxNm7J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cYGFFJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cYGFFJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=S2jU9j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=S2jU9j" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/342489167" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 03:12:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ukrtelegroup">ukrtelegroup</category>
      <category domain="http://securityratty.com/tag/codecs">codecs</category>
      <category domain="http://securityratty.com/tag/fake codecs simultaneously">fake codecs simultaneously</category>
      <category domain="http://securityratty.com/tag/rogue security software">rogue security software</category>
      <category domain="http://securityratty.com/tag/ukrtelegroup ukrtelegroup">ukrtelegroup ukrtelegroup</category>
      <category domain="http://securityratty.com/tag/fake codecs">fake codecs</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/home stat">home stat</category>
      <category domain="http://securityratty.com/tag/scammy ecosystem">scammy ecosystem</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/342489167/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</source>
    </item>
    <item>
      <title><![CDATA[Impersonating StopBadware.org to Serve Fake Security Warnings]]></title>
      <link>http://securityratty.com/article/f4988806c23605425ad4d4182fb247ad</link>
      <guid>http://securityratty.com/article/f4988806c23605425ad4d4182fb247ad</guid>
      <description><![CDATA[Malware is known to have been hijacking search results, take for instance the rogue Antivirus XP 2008 as a recent example, but it's even more interesting to see other rogue security software...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SIQdU9Lbl-I/AAAAAAAAB70/IzH5vWjVKfU/s1600-h/fake_security_warning_stopbadware.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIQdU9Lbl-I/AAAAAAAAB70/RZLeI1rUans/s200-R/fake_security_warning_stopbadware.png" style="border: 0pt none ;" /></a>Malware is known to have been hijacking search results, take for instance the <a href="http://sunbeltblog.blogspot.com/2008/06/hijacking-google.html">rogue Antivirus XP 2008</a> as a recent example, but it's even more interesting to see other rogue security software impersonating <a href="http://blogs.stopbadware.org/">Stopbadware.org</a> in order to server fake security warnings that ultimately lead to fake security software.<br />
<br />
<b>stopbadware2008 .com</b> (58.65.238.171) is one of these examples, where <b>stopbadware2008 .com/antivirus.php</b>&nbsp; redirects to <b>infectionscanner .com</b> and attempts to trick the user into installing <b>download.infectionscanner.com /AntvrsInstall.exe</b>.&nbsp; The message used :<br />
<br />
"<i>Reported Insecure Browsing: Navigation blocked. Due to insecure Internet browsing your PC can easily get infected with viruses, worms and trojans without your knowledge, and that can lead to system slowdown, freezes and crashes. Also insecure Internet activity can result in revealing your personal information. To get full advanced real-time protection for PC and Internet activity, register Antivirus 2008. We recommend you to protect your PC now and continue safe Internet browsing.</i>"<br />
<br />
<div class="separator" style="text-align: left; clear: both;"><a href="http://bp2.blogger.com/_wICHhTiQmrA/SIRDWN2opkI/AAAAAAAAB8E/ecjTOaYluzg/s1600-h/infectionscanner_rogue_software.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SIRDWN2opkI/AAAAAAAAB8E/J_AhSquB1dc/s200-R/infectionscanner_rogue_software.png" style="border: 0pt none ;" /></a></div>There's in fact even more rogue software using the same IP (58.65.238.171), <a href="http://ddanchev.blogspot.com/2008/04/hacked-by-rbn.html">courtesy of HostFresh</a> :<br />
<b>virus-scanner-online .com<br />
security-scanner-online .com<br />
viruses-scanonline .com<br />
virus-scanonline .com<br />
antivirus-scanonline .com<br />
download.antivirus-scanonline .com<br />
topantivirus-scan .com<br />
topvirusscan .com<br />
virusbestscan .com<br />
virus-detection-scanner .com<br />
antivirus-scanner .com<br />
infectionscanner .com<br />
virusbestscanner .com<br />
internet-security-antivirus .com</b><br />
<br />
<a href="http://bp3.blogger.com/_wICHhTiQmrA/SIRGRxHueLI/AAAAAAAAB8M/CtKGYf0tD_w/s1600-h/antivirus_2008_rogue.gif" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SIRGRxHueLI/AAAAAAAAB8M/dBOe983G3Ns/s200-R/antivirus_2008_rogue.gif" style="border: 0pt none ;" /></a>It would be interested to monitor whether or not the template for the fake security warning would start getting used on a large scale.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got Your XPShield up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's Fake Security Software</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=g017OJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=g017OJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2qqOkJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2qqOkJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RWcCDj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RWcCDj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HjGT2j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HjGT2j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3DP0KJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3DP0KJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bLRVbJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bLRVbJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RDkUqj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RDkUqj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/341345275" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 20 Jul 2008 23:30:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake security">fake security</category>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/insecure internet activity">insecure internet activity</category>
      <category domain="http://securityratty.com/tag/internet activity">internet activity</category>
      <category domain="http://securityratty.com/tag/insecure internet">insecure internet</category>
      <category domain="http://securityratty.com/tag/insecure">insecure</category>
      <category domain="http://securityratty.com/tag/lead">lead</category>
      <category domain="http://securityratty.com/tag/fake video codecs">fake video codecs</category>
      <category domain="http://securityratty.com/tag/portfolio">portfolio</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/341345275/impersonating-stopbadwareorg-to-serve.html">Impersonating StopBadware.org to Serve Fake Security Warnings</source>
    </item>
    <item>
      <title><![CDATA[SQL Injecting Malicious Doorways to Serve Malware]]></title>
      <link>http://securityratty.com/article/6cec302595fea49e4d1ec4cc6e8a2a25</link>
      <guid>http://securityratty.com/article/6cec302595fea49e4d1ec4cc6e8a2a25</guid>
      <description><![CDATA[Abusing legitimate sites as redirectors to malicious doorways serving malware is becoming increasing common, as is the use of SQL injections in order for the malicious parties to ensure their...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SIQqtdScFcI/AAAAAAAAB78/E-aOhcc0edk/s1600-h/sql_gpamelaaandersona_info.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SIQqtdScFcI/AAAAAAAAB78/DQBfk5L1tng/s200-R/sql_gpamelaaandersona_info.JPG" style="border: 0pt none ;" /></a>Abusing legitimate sites as redirectors to malicious doorways serving malware is becoming increasing common, as is the use of SQL injections in order for the malicious parties to ensure their campaigns will receive enough generic traffic to their redirectors. Excluding the use of the very same traffic management tools, web malware exploitation kits, <a href="http://ddanchev.blogspot.com/2008/07/template-ization-of-malware-serving.html">templates for the rogue adult sites and the rogue security software</a>, perhaps the most important thing to point out regarding all of the previously analyzed such campaigns, is that they are all related to one another, and are operated by the same people, using the very same infrastructure and live exploit URLs most of the time.<br />
<br />
Let's expose yet another such campaign, that has been SQL injected and spammed across a couple of hundred web forums. <b>gpamelaaandersona .info</b> (82.103.129.98) is the typical comprehensive malicious doorway, whose galleries redirect to <b>tds.zbestservice .info/tds/in.cgi?11</b> (85.255.120.45), and from there the following campaigns load on-the-fly :<br />
<br />
<b>porntubev20 .com</b>/viewmovie.php?id=86 (74.50.117.84)<br />
<b>getmyvideonow .com</b>/exclusive2/id/3912999/2/black/white/ - (89.149.194.188)<br />
<b>immenseclips .com</b>/m6/movie1.php?id=1552&amp;n=celebs (85.255.118.156)<br />
<b>movieexternal .com</b>/download.php?id=1552 (77.91.231.201)<br />
<b>2008adults2008a .com</b>/freemovie/144/0/<br />
<b>avwav .com</b>/1931.htm<br />
<b>codecupgrade .com</b> (74.50.117.84)<br />
<b>iwillseethatvideo .com</b> (91.203.92.53)<br />
<b>dciman32 .com</b> (85.255.120.45)<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SIQUGF_f2RI/AAAAAAAAB7s/CABzXB36__M/s1600-h/gpamelaaandersona_blackhat_SEO.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SIQUGF_f2RI/AAAAAAAAB7s/o_DEwW3VrGA/s200-R/gpamelaaandersona_blackhat_SEO.JPG" style="border: 0pt none ;" /></a>Naturally, these are just the tip of the iceberg, and the deeper you go, the more connections with malware gangs and previous campaigns can be established. For instance, here are some more "sleeping beauties" at <b>74.50.117.84</b> :<br />
<br />
&nbsp;<b>winantivirus2008 .org<br />
porntubev20 .com<br />
crack-land .com<br />
just-tube .com&nbsp;&nbsp;&nbsp; <br />
codecupgrade .com<br />
codecupgrade .com<br />
scanner-tool .com<br />
surf-scanner .com<br />
best-cracks .com<br />
updatehost .com<br />
updatehost .com<br />
freemoviesdb .net<br />
megasoftportal .net</b><br />
<br />
And even more malicious doorways, and rogue software at <b>89.149.227.195</b> :<br />
<br />
<b>musicportalfree .com<br />
softportalfree .com<br />
verifiedpaymentsolutionsonline .com<br />
my-adult-catalog .com<br />
indafuckfuck .com<br />
best-porncollection .com<br />
funfuckporn .com<br />
sanxporn .com<br />
dolcevido .com<br />
xiedefender .com<br />
online-malwarescanner .com<br />
easyvideoaccess .com<br />
my-searchresults .com<br />
creatonsoft .com<br />
ihavewetfuckpussy .com</b><br />
<br />
How come none of these are in a fast-flux? Pretty simple. Keeping in mind that they continue using the services of <a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">the ISPs that you rarely see in any report</a>, survivability through fast-flux is irrelevant when <a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">emails sent to abuse@cybercrime.tolerating.isp</a> receive a standard response two weeks later, and when your abuse emails become more persistent, <a href="http://ddanchev.blogspot.com/2008/01/rbns-fake-account-suspended-notices.html">a fake account suspended notice</a> makes it to the front page, whereas the campaigns get automatically updated to redirect to an internal page, again serving the malware and the redirectors.<br />
<br />
<b>Related posts:</b><br />
<b></b><a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oa2OiJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oa2OiJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UeSeaJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UeSeaJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=o3c9tj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=o3c9tj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rln4wj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rln4wj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YfC90J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YfC90J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=21MM8J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=21MM8J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=l631Yj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=l631Yj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/341279604" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 20 Jul 2008 21:45:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malicious doorways">malicious doorways</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/rogue adult sites">rogue adult sites</category>
      <category domain="http://securityratty.com/tag/malware gangs">malware gangs</category>
      <category domain="http://securityratty.com/tag/campaigns load on-the-fly">campaigns load on-the-fly</category>
      <category domain="http://securityratty.com/tag/campaigns">campaigns</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/341279604/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware</source>
    </item>
    <item>
      <title><![CDATA[Monetizing Compromised Web Sites]]></title>
      <link>http://securityratty.com/article/9f7b106457f7cdcbfb11dd8b0b3dd971</link>
      <guid>http://securityratty.com/article/9f7b106457f7cdcbfb11dd8b0b3dd971</guid>
      <description><![CDATA[Despite that pure patriotic hacktivism is still alive and kicking, compromised sites are largely getting monetized these days, starting from hosting blackhat SEO junk pages, to redirecting to live...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHsAOtYiisI/AAAAAAAAB58/CA2dvGI0DL0/s1600-h/Municipal_de_Amparo.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHsAOtYiisI/AAAAAAAAB58/k2bP_iz48tA/s200-R/Municipal_de_Amparo.png" style="border: 0pt none ;" /></a>Despite that pure patriotic hacktivism is still alive and kicking, <a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">compromised sites are largely getting monetized</a> these days, starting from hosting blackhat SEO junk pages, to redirecting to live exploit URLs and fake codecs where revenue is earned through their participation in an affiliate business model.<br />
<br />
With The Africa Middle Market Fund's site monetized by web site defacers who defaced it "in between" the blackhat SEO infrastructure they were hosting internally, in this I'll comment on the currently compromised and redirection to a fake porn sites, Camara Municipal de Amparo (<b>camaraamparo.sp.gov.br/r.html</b>). Basically, it's homepage is heavily linking to the Zlob variant (<b>camaraamparo.sp.gov.br/ video.exe</b>) in between loading an IFRAME to <b>61.162.230.12/ index.php</b>. As always, upon uploading their redirector, they've build enough confidence into their new hosting provider that the link to the redirector was instantly spammed across the web. The site is so heavily linking to the internal redirector itself, that upon clicking on the majority of links the user will inevitably come across it.<br />
<br />
Speaking of fake porn sites redirecting to Zlob variants, here are the very latest additions spammed across the web through blackhat SEO practices :<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHsLbgFp7NI/AAAAAAAAB6E/ZDNLECdRM1U/s1600-h/fake_porn_sites_zlob.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHsLbgFp7NI/AAAAAAAAB6E/TIqQ0wE9bQM/s200-R/fake_porn_sites_zlob.JPG" style="border: 0pt none ;" /></a><b>just-tube .com<br />
mypornmovies .net<br />
moms-galls .net<br />
porntubefilms .com<br />
porntubedot .com<br />
hot-porntube .com<br />
landmovieblog .com<br />
sexvidtube .com<br />
freelifevideo .com<br />
getyourfreemovie .com<br />
iubat .com<br />
sweetyjoly .com<br />
hardbizarre .com<br />
freeworldvideo .net<br />
hot-porntube .net<br />
qualitymovies .net<br />
porntube1con .net<br />
video-info .net<br />
videocityblog .com<br />
fuckedolder&nbsp; .com<br />
highpro1 .com<br />
max-graf.com .pl<br />
grandsupertds .info<br />
hot-porn-tube .net<br />
hot-porntube .com<br />
terryschulz .com<br />
show-sextube .com<br />
qualitymovies .net<br />
clubvideos .net</b><br />
<br />
No matter the high profile site that's been exploited in order to participate in such malicious operations, for the time being, crunching out new domain names and using the hosting services of the well known ISPs neglecting their removal, seems to be the tactic of choice. The long tail of SQL injected sites is however, clearly replacing the plain simple blackhat SEO web spamming, so that traffic to these rogue sites is driven through redirection of the the traffic from legitimate sites.<b><br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cEyKTJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cEyKTJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qsdYjJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qsdYjJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BVongj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BVongj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4DJmRj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4DJmRj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=al8bCJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=al8bCJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nrE7PJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nrE7PJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TCjewj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TCjewj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/334911319" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 13 Jul 2008 23:26:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/rogue sites">rogue sites</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/web site defacers">web site defacers</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/profile site">profile site</category>
      <category domain="http://securityratty.com/tag/redirector">redirector</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/334911319/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</source>
    </item>
    <item>
      <title><![CDATA[The Template-ization of Malware Serving Sites]]></title>
      <link>http://securityratty.com/article/ae9fa7925137e6a71a690ef3b705294d</link>
      <guid>http://securityratty.com/article/ae9fa7925137e6a71a690ef3b705294d</guid>
      <description><![CDATA[Just like web malware exploitation kits and phishing pages turned into a commodity underground good , allowing easy localization to different languages , and of course, the natural lowering of entry...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHZZ6zTOnOI/AAAAAAAAB5c/3Sqe37mACns/s1600-h/fake_video_codec_template.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHZZ6zTOnOI/AAAAAAAAB5c/Rsu1-EiUFlY/s200-R/fake_video_codec_template.JPG" style="border: 0pt none ;" /></a>Just like web <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">malware</a> <a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">exploitation</a> <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">kits</a> and <a href="http://ddanchev.blogspot.com/2008/03/phishing-pages-for-every-bank-are.html">phishing pages turned into a commodity underground good</a>, allowing easy <a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">localization to different languages</a>, and of course, the natural lowering of entry barriers into web malware and phishing in general, the very same thing is happening with fake ActiveX templates like the ones used on <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">the majority of fake porn and celebrity sites I've been assessing recently</a>.<br />
<br />
The increase of these bogus ActiveX templates is due to the fact that despite they are currently available for sale, buyers appear to be leaking them for everyone to use so that they can continue maintaining their current business models, namely, the services they offer with the ActiveX templates. Unethical competitive practices among cybercriminals and scammers are only to starting to take place with one another trying to ruin or extend the lifecycle of their services.<br />
<br />
Talking about prevalence, the <b>TonsOfPorn ActiveX</b> remains the most widely used rogue ActiveX in the majority of fake codec campaigns for the last couple of months. The ActiveX is largely abused by using another <b>fake porn site template for PornTube</b>, which in combination result in nothing more than huge domain portfolios with no content at all if we exclude the Zlob variants.<br />
<br />
And while template-tization means more efficient malware campaigns, it also results in a common pattern for generic detection of such sites. For instance, the folks at <a href="http://www.finjan.com/MCRCblog.aspx?EntryId=1993">Finjan did an experiment by verifying the signature based detection of the common javascript file</a> that was used in the ongoing waves of SQL injection attacks. Their conclusion :<br />
<br />
"<i>Can it be that Anti-virus products are now holding more signatures for domains and URLs rather than trying to identify a malicious code they never inspected before? As my research found, just by changing the domain names, some AVs did not find this code as malicious...... surprisingly enough.</i>"<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHaFBlIm7bI/AAAAAAAAB5k/lXlcCbD2H78/s1600-h/inthecloud3.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHaFBlIm7bI/AAAAAAAAB5k/wABNqH2-Sz0/s200-R/inthecloud3.jpg" style="border: 0pt none ;" /></a>When assessing malware campaigns in general, I usually do the same for the record. Storm Worm's use of <b>ind.php</b> for executing its set of exploits has the same detection rate - <b>scanners result: 10/33 (30.30%)</b> and is detected as JS.Zhelatin.zb.<br />
<br />
Getting back to the <b>TonsOfPorn ActiveX</b>, it's structure is more static than a Red Army statue in Estonia, making it easy to proactively protect against, no matter the domain, no matter the exploits served. It's detection rate is close to the javascript from the SQL injection attacks - <b>Scanners Result: 9/33 (27.28%) </b>and is detected as <b>Trojan.HTML.Zlob.L</b>.<br />
<br />
From my personal experience, blocking an IP address where a couple of hundred malicious domains remain parked, is just as useful as blocking a single domain acting as the main redirector behind a huge domains portfolio of malicious domains. However, the most beneficial approach on a large scale remains the practice of taking care of the most obvious patterns that still remain faily easy to detect, at least for the time being, due to the efficiency the people behind them aim to achieve, making them easily susceptible to generic detection approaches.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=60LvHJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=60LvHJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TvxsiJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TvxsiJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UeK86j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UeK86j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AHP63j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AHP63j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ci9jvJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ci9jvJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mQuV1J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mQuV1J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FGm2Yj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FGm2Yj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/332106839" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 12:59:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious domains remain">malicious domains remain</category>
      <category domain="http://securityratty.com/tag/malicious domains">malicious domains</category>
      <category domain="http://securityratty.com/tag/tonsofporn activex remains">tonsofporn activex remains</category>
      <category domain="http://securityratty.com/tag/tonsofporn activex">tonsofporn activex</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/generic detection approaches">generic detection approaches</category>
      <category domain="http://securityratty.com/tag/generic detection">generic detection</category>
      <category domain="http://securityratty.com/tag/activex">activex</category>
      <category domain="http://securityratty.com/tag/fake activex">fake activex</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/332106839/template-ization-of-malware-serving.html">The Template-ization of Malware Serving Sites</source>
    </item>
    <item>
      <title><![CDATA[Mobile Malware Scam iSexPlayer Wants Your Money]]></title>
      <link>http://securityratty.com/article/2e181320354dd6dbef7263b149510ae5</link>
      <guid>http://securityratty.com/article/2e181320354dd6dbef7263b149510ae5</guid>
      <description><![CDATA[A bogus media player ( iSexPlayer.jar ) targeting Symbian S60 3rd edition devices according to several affected parties, is currently being spammed through blackhat search engine optimization. Once...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp3.blogger.com/_wICHhTiQmrA/SHPPpaT5DsI/AAAAAAAAB4s/DzzzoRm7qQw/s1600-h/iSexPlayer.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SHPPpaT5DsI/AAAAAAAAB4s/RrF0dGd28i8/s200-R/iSexPlayer.png" style="border: 0pt none ;" /></a>A bogus media player (<b>iSexPlayer.jar</b>) targeting Symbian S60 3rd edition devices according to several affected parties, is currently being spammed through blackhat search engine optimization. Once infected upon confirming its execution since it's doesn't seem to be exploiting a specific vulnerability besides "bargain hunters" desire for free adult material, the malware attempts to trick the user into participating by becoming a member, however, a quick peek the source code reveals interesting facts about the scam.<br />
<br />
For instance, once providing them with your credit card details and basically wanting  to try out the service, it appears that there's no way out of it which is a problem since "<b>Trial membership recur at $US 29.95 unless cancelled, Monthly membership recur unless cancelled</b>" and also, "<b>Do you want full access to all pictures and videos? Cost is 2 Euros, charged 100% descreet on your phone bill over SMS. Please allow iSexPlayer to send SMS</b>".<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHPXAdxKXSI/AAAAAAAAB40/lx0NNyGF8DU/s1600-h/iSexPlayer_Malware_Dialer1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHPXAdxKXSI/AAAAAAAAB40/G-ed7CKFn3g/s200-R/iSexPlayer_Malware_Dialer1.JPG" style="border: 0pt none ;" /></a>The spammed through blackhat SEO sites are currently active, and perhaps a bit ironic, once you make any transaction with these people, anything that goes on at a later stage such as automatic calling or sms-sing to squeeze your bill, may be in fact legal since you authorized it. <br />
<br />
<a href="http://www.symbian-freak.com/news/008/07/first_known_s60_3rd_ed_malware.htm">Symbian Freak</a> has some details, as well as <a href="http://www.esato.com/board/viewtopic.php?topic=171238">an affected party</a> :<br />
<br />
"<i>Last week, I had lend my N73 to one of my friends for use as he had lost his phone. <b>I did not know what he did, but I checked my bills today and see some International calls made that amount to around 20USD. That is around 800 Indian rupees</b>. To check, I called the number and learnt that it was a phone sex line. Now it was time for my friend to answer. <b>The thirteen calls were made during a period spanning two days. On an average there were 7 calls a day.</b> <b>Now, the thing that struck me is, going by the call records, the calls on the second day were made when I had the phone with me</b>. I am pretty sure no one dialled the numbers. I called my buddy and asked him if he had downloaded something. He then spilled the beans informing that he did go to some adult website and installed a software (I do not recall the name).</i>"<br />
<br />
<a href="http://bp2.blogger.com/_wICHhTiQmrA/SHPXMcq4MwI/AAAAAAAAB48/xflFOsg6ETM/s1600-h/iSexPlayer_Malware_Dialer2.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SHPXMcq4MwI/AAAAAAAAB48/bwX9gzwKouA/s200-R/iSexPlayer_Malware_Dialer2.JPG" style="border: 0pt none ;" /></a>The name of the "software" as I've already pointed out is iSexPlayer. Let's dissect the scammers and their sites currently spammed across 100,000 sites using blackhat SEO tactics. Related domains sharing the same IP and internal pages :<br />
<br />
<b>3g6.se<br />
3gx.se<br />
conn2.3g6.se<br />
conn2.3g6.se<br />
test.3gx.se</b><br />
<br />
83.241.194.132 (83.241.194.128-83.241.194.191 DGC-DIRECT2-01 Direct2Internet AB - Internet Access Located in Johanneshov, Sweden)<br />
<br />
<b>3g6.se/dstream.php<br />
3g6.se/newplayerdl.php<br />
3g6.se/chrono/callback.php<br />
secure.chronopay.com/index.cgi</b><br />
<br />
The scammer's pitch :<br />
<br />
"<i>Free access to: - 500 Hardcore scenes - 100 Full lenght movies - Picture galleries Important! To install iSexplayer you must be at least 18 years old. You must install and run iSexplayer™ access module to watch the videos on Nintendo DS, You must install and run iSexplayer™ access module to watch the videos on Apple iPhone, Install iSexplayer</i>"<br />
<br />
Upon attempting to download the .jar file from the mobile page, the iSexPlayer.php does the magic like that :<br />
<br />
"<i>MIDlet-1: iSexPlayer,/icon.png,Easyloader<br />
MIDlet-Install-Notify: http://3g6.se/install_notify.php?id=1322451<br />
MIDlet-Jar-Size: 101313<br />
MIDlet-Jar-URL: http://3g6.se/iSexPlayer.jar<br />
MIDlet-Name: iSexPlayer<br />
MIDlet-Vendor: Vendor<br />
MIDlet-Version: 1.0<br />
MicroEdition-Configuration: CLDC-1.0<br />
MicroEdition-Profile: MIDP-2.0<br />
did: 1322451<br />
did2: 9416755</i>"<br />
<br />
Who's behind the scam?<br />
<br />
"<i>c_javax_microedition_lcdui_Form_fld.append("\ni<b>SexPlayer is owned by</b>: ");</i><br />
<i>c_javax_microedition_lcdui_Form_fld.append("\n<b>Enit Invest S.L</b>. ");&nbsp;</i><br />
<i>c_javax_microedition_lcdui_Form_fld.append("\nweb: <b>enitinvest.com</b> ");</i><br />
<i>c_javax_microedition_lcdui_Form_fld.append("\nemail: <b>support@enitinvest.com</b> ");</i><br />
<i>c_javax_microedition_lcdui_Form_fld.append("\nTel: <b>1-800-845-4951</b> ");</i>"<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
Enit Invest S.L.<br />
Av. Machupichu 26, S 18<br />
28043 Madrid<br />
email: support@enitinvest.com<br />
Tel: 1-800-845-4951<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHPjWZtvpNI/AAAAAAAAB5E/GCSyEOFBiOA/s1600-h/iSexPlayer_Malware_Dialer3.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHPjWZtvpNI/AAAAAAAAB5E/82001n4Xv0U/s200-R/iSexPlayer_Malware_Dialer3.JPG" style="border: 0pt none ;" /></a>And since I'm sure that there are more juicy details within the source code further exposing their scammy practices, which you should not authorize in any way, just like you wouldn't really like making a long call on a premium rate number thanks to having a malware infected phone, once more details are gathered, particularly its compatibility with devices, they'll be posted.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wedKOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wedKOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UmSuCJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UmSuCJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VJW47j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VJW47j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fmvyWj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fmvyWj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GPevnJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GPevnJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dDH6aJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dDH6aJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Yi9JAj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Yi9JAj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/330746890" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 03:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/isexplayer">isexplayer</category>
      <category domain="http://securityratty.com/tag/install">install</category>
      <category domain="http://securityratty.com/tag/install isexplayer">install isexplayer</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/internet access">internet access</category>
      <category domain="http://securityratty.com/tag/isexplayer access module">isexplayer access module</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/blackhat seo sites">blackhat seo sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/330746890/mobile-malware-scam-isexplayer-wants.html">Mobile Malware Scam iSexPlayer Wants Your Money</source>
    </item>
  </channel>
</rss>
