<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: pop3]]></title>
    <link>http://securityratty.com/tag/pop3</link>
    <description></description>
    <pubDate>Thu, 24 Apr 2008 00:37:46 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Coding Spyware and Malware for Hire]]></title>
      <link>http://securityratty.com/article/1dbd4bddd9e4248009d0273ad7cae5dd</link>
      <guid>http://securityratty.com/article/1dbd4bddd9e4248009d0273ad7cae5dd</guid>
      <description><![CDATA[What type of antivirus evasion do you want today? For the past several years, we have been witnessing the emerging customerization applied in malware and spyware for hire services. What used to be a...]]></description>
      <content:encoded><![CDATA[<div class="separator" style="text-align: left; clear: both;"><a href="http://bp2.blogger.com/_wICHhTiQmrA/SIWJkocpGwI/AAAAAAAAB8U/_v3hJOM2k_s/s1600-h/preview_random.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SIWJkocpGwI/AAAAAAAAB8U/15Yc8N_lG74/s200-R/preview_random.jpg" style="border: 0pt none ;" /></a></div>What type of antivirus evasion do you want today? For the past several years, we have been witnessing the emerging customerization applied in malware and spyware for hire services. What used to be a situation where the malware authors would code and then start promoting a piece of malware including features that he thinks his potential customers would want by generalizing a cybercriminal's needs, is today's "listening to the customer" win-win situation that they've reached already. <br />
<br />
The whole maturity from a product concept to customerization is in fact so prevalent these days, that malware authors wanting to preserve their intellectual property are forbidding their customers from reverse engineering their malware modules, presumably fearing that <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">remotely exploitable flaws like this one in one of the most popular Ebanker malwares for the last two yers Zeus</a>, could be discovered due to the malware author's insecure coding practices. Moreover, limiting the distribution of a single license they are given to more than three people will result in the malware author ignoring any future business relationships with the party that ruined the exclusiveness of the malware, thereby leaking it to the public, something that's been happening and will continue happening with web malware exploitation kits.<br />
<br />
What would be the price of a custom malware module coded on demand? How much does it cost to have a built in email harvester that would sniff all the incoming and outgoing email addresses from the infected host to later on include them in upcoming spam and malware campaigns? Would the malware author also provide a managed hosting service for the command and control and the actual binaries on a revenue sharing <br />
<br />
Here's an automatically translated, and fairly easy to understand random proposition for coding spyware and malware for hire, aiming to answer many of these questions, clearly demonstrating that today's malware is coded in exactly the same way the customer wants it to : <br />
<br />
"<i>As you can see in the history of its development turned directly into the combine, while almost no raspuh in weight, full-size pack аж 18 kb and minialno 5 kb, for all nampomnyu again, all descriptions below can be done as otdelnym bot, and any combination of cross except for a few restrictions. This product is targeted at mass-user and will not be all prodavatsya row. So, you can choose from:</i><br />
<br />
<i>Actually loader - is able to load a file from adminki, by country and other characteristics, such as the number of animals on board with a specific bot, a country group of countries, the availability of certain authors or Fire, sredenemu time online, etc. etc.. You can adjust the speed of shipping limits for each file, can load 1 as well as how files simultaneously<br />
300 €</i><br />
<br />
<i><b>FTP and not only Graber</b><br />
Analyzes user traffic and collects from the ftp acclamation, that is ftp acclamation would you regardless of how the customer uses ftp user, thus can be obtained most valuable ftp aka (even those to which the password is not saved), you can also grab other in a way not only acclamation acclamation and other tasty things more)<br />
150 €<b>&nbsp;</b></i><br />
<br />
<i><b>Assembler spam bases</b><br />
Analyzes user traffic and collects from all email, snifit http pop3 smtp protocols, keeps records unikallnosti locally on each boat to reduce the burden on the server as well as globally on a server has 2 mode of operation - ie passive with only collects user to please and active - the very beginning to download the entire inet) in search of soap<br />
220 €<br />
<br />
<b>Socks 4 / 5</b><br />
Normal soks with competently implemented multithreading, is activated only if the user real Ip, otherwise not. And also optional, depending on the connection type and speed ineta.<br />
70 €<br />
<br />
<b>Indicates</b><br />
The primitive method, contamination fleshek avtoranom gives 2-3% increase in the first week and up to 7% in the next, a pleasant trifle)<br />
35 €<br />
<br />
<b>Scripts</b><br />
Loader supports internal scripting language - jscript, to carry out arbitrary actions on the victim machine, whether recording data in the register, setting authentic hon-Pago, opening URL in your browser (it was done so to please with 90% punching)), apload arbitrary files on a server, even theoretically possible to form and grabing inzhekty in IE) has only to write the script zaebetes, vobschem lyuboye actions soul who wish)<br />
70 € basic functionality<br />
<br />
<b>Assembler passwords</b><br />
Collects data such as passwords pstorage IE, MSN, etc., will be added at the request of other sources of passwords<br />
70 €<br />
<br />
<b>Mini-AV</b><br />
When installing loadera wheelbarrows to remove BHO shaped three, zevso-shaped, the majority of shit from all avtoranov, render most keylogerov until all) forward proposals to improve<br />
70 €<br />
<br />
<b>File-default</b><br />
In exe loadera program URL (in adminke) to the file which once progruzit 1 and run at first start loadera on wheelbarrows, while simultaneously helping progruzke Trojan for example, in its entire botnet that does not paired with challenges in adminke, the module operates in 20 seconds after the mini - av which excludes the removal of your Trojan bot, after progruza this exe bot continues to normal activities.<br />
35 €<br />
<br />
<b>Form Graber</b><br />
While in beta version, robbed IE. Sends logs in adminku, folding country. Logs are like logs agent. It consists of:<br />
<br />
<b>Graber certificats</b><br />
On the idea is part formgrabera but could work and of itself, actually there is nothing to describe)<br />
<br />
<b>Injections</b><br />
Literacy sold inzhekty, did not begin work after full progruza pages (as in bolshistve three) and immediately supported injection yavaskript code, which allows avtozalivy and DC inzhekty for data collection. For example not to yuzat acclamation at all is not yet introduce the necessary number of Britain, after which inzhekt ceases to operate. Вобщем mdelat can be anything and in any form) rather than the meager request field pin) And also inzhektov subspecies - a substitute for the issuance of search enginee.<br />
<br />
<b>Graber balances</b><br />
Makes loot aka balances at the entrance to the user acclamation, detail added to the logs.<br />
<br />
<b>Screen</b><br />
Universal method to grab information from absolutely any species and varieties klaiviatur screens, in particular html, flash, in one picture, with a drop-down fields after choosing your encrypted, as well as information such as "enter 3 yu secret letter word" etc. as well as any information which is visible a user but not seen in the logs. Screen settings of adminki, set URL where do screen as well as the type of screen: for virtual keyboard (done several small images of areas around the clique) or to "enter 3 yu secret letter words" (makes 1 full shot). With the withdrawal screen recorded in the log entry with the name of the file to the screen this position.<br />
<br />
<b>Antiabuznost for botneta</b><br />
Feachem adminki, keep botnet enables fast, normal, bezglyuchnyh NEabuzoustoychivyh hosting, with features that you forget what abuzy, nohistory week saporta "abuzoustoychivogo" hosting inaccessibility host to half ineta etc., etc., also with the help of the supplement will be able to keep huge botnety (over SL) at 1 dedike with 512 Lake) and well on the price of hosting a savings, not $ 500 a month and 150. It may use this feature to stroronnim development, Trojans, bots, etc., actually is a separate product. And incidentally, if you do not understand the theory that nenado ask "and how does it work?" imagine that it works and point and neubivaemo in pritsnipe.<br />
600 € +<br />
&nbsp;</i><br />
<i>All prices are in euros, the calculation is made at the rate of CB on the day of purchase. ps I will not disappear as most authors after months of sales, I DONT how to please you get to the assembly ftp, I DONT how many soap collects soap-graber, I DONT what otstuk from loadera, I DONT soksov how many will be from 1 to downloads, and how best To work load a file is not dead quickly, if you are confused my ignorance - that my loader so you do not need more tries)<br />
<br />
Rules / Licence<br />
-- Customer has no right to transfer any of his three 3 persons except options for harmonizing with me<br />
-- Customer does not have the right to make any decompile, research, malicious modification of any three parts<br />
-- Customer has no right where either rasprostanyat information about three and a public discussion with the exception of three entries.<br />
-- For violating the rules - without any license denial manibekov and further conversations</i>" <br />
<br />
This malware coder seems to be participating in an affiliate program with a malicious ISP that is offering hosting services for the entire campaign, not just the malware binaries, so you have a rather good example that incentives and revenue-sharing models result in value-added services, a all-in-one shop for a customer to take advantage of without bothering to approach a third-party.<br />
<br />
Cybercrime is getting even more easier to outsource these days, and with the malicious parties improving their communication and incentives model, the resulting transparency in the underground market<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/russias-fsb-vs-cybercrime.html">Russia's FSB vs Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">Localizing Open Source Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/quality-and-assurance-in-malware.html">Quality and Assurance in Malware Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2006/09/benchmarking-and-optimising-malware.html">Benchmarking and Optimising Malware</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CfEGOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CfEGOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZmZP2J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZmZP2J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3RDQbj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3RDQbj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uN1LUj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uN1LUj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oSzTOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oSzTOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KOIqZJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KOIqZJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8gh7xj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8gh7xj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/342366718" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 23:52:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware author">malware author</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware binaries">malware binaries</category>
      <category domain="http://securityratty.com/tag/malware attacks">malware attacks</category>
      <category domain="http://securityratty.com/tag/ftp">ftp</category>
      <category domain="http://securityratty.com/tag/ftp user">ftp user</category>
      <category domain="http://securityratty.com/tag/collects">collects</category>
      <category domain="http://securityratty.com/tag/malware industry">malware industry</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/342366718/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</source>
    </item>
    <item>
      <title><![CDATA[Crimeware in the Middle - Zeus]]></title>
      <link>http://securityratty.com/article/7031903e13ac81d8b420bb698c242d03</link>
      <guid>http://securityratty.com/article/7031903e13ac81d8b420bb698c242d03</guid>
      <description><![CDATA[Virtual greed, or response rate optimization? The idea of converging phishing emails with embedded exploits and banking malware is nothing new, in fact phishers realizing that combining attack...]]></description>
      <content:encoded><![CDATA[<div><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SBBF9tDpi_I/AAAAAAAABn4/wmeAn27YZ30/s1600-h/zeus_in_the_middle.JPG"><img id="BLOGGER_PHOTO_ID_5192727296727419890" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/SBBF9tDpi_I/AAAAAAAABn4/wmeAn27YZ30/s200/zeus_in_the_middle.JPG" border="0" /></a>Virtual greed, or response rate optimization? The idea of converging phishing emails with embedded exploits and banking malware is nothing new, in fact phishers realizing that combining attack approaches can increase the chance of achieving their objective which in this case is either logging the authentication process or hijacking it, often forget that the phishing email could have succeeded without the embedded malware or exploit, which in many cases would have triggered an alarm.<br /><br />Yesterday, <a href="http://rsa.com/blog/blog_entry.aspx?id=1274">Uriel Maimon posted an overview of the convergence of Rock Phish emails with Zeus</a>, a crimeware kit used to deliver banking trojans :<br /><br />"<span style="font-style: italic;">The Trojan that was used in this attack belonged to the "Zeus" family of malware. Zeus is a nefarious type of Trojan for multiple reasons:</span> <span style="font-style: italic;"><br /><br />1. The Zeus Trojan is a kit for sale: Anyone in the criminal community can purchase it for roughly $700. This means that the Rock group did not need to develop new skill-sets to write Trojan horses; they just purchased it on the open market. In the past 6 months RSA's Anti-Fraud Command Center has detected more than 150 different uses of the Zeus kit, each one infecting on average roughly 4,000 different computers a day.</span> <span style="font-style: italic;"><br /><br />2. Resistance to detection: The kit purchased is a binary generator. Each use creates a new binary file, and these files are radically different from each other -- making them notoriously difficult for anti-virus or security software to detect. To date very few variants have had effective anti-virus signatures against them and each use of the kit usually makes existing signatures ineffective. Just like in most cases, this particular use of the Zeus kit did not have any a</span><span style="font-style: italic;">nti-virus detection (with the popular engines we tested) at the time of this writing.</span> <span style="font-style: italic;"><br /><br />3. Rich feature set: the Zeus Trojan has many startling capabilities. In addition to listening in on the submission of forms in the browser, the Trojan also has advanced capabilities, for instance the ability to take screenshots of a victim's machine, or control it remotely, or add additional pages to a website and monitor it, or steal passwords that have been stored by popular programs (remember when you clicked on the "Remember this password?" checkbox?)... And the features-list goes on.</span> <span style="font-style: italic;">As I look upon this blissful union of fraud and crime technologies, I can only envy the criminals who can find such coupling. Looking forward to my next birthday, I can only hope that I will have the opportunity to find such partnership in my own life (and maybe give my mother one less reason for disappointment).</span>"<br /><br />We cannot talk about Zeus unless we compare it to another such crimeware kit serving banking trojans, in this <a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">the Metaphisher kit</a>. Metaphisher is particularly interested because of its much more customized GUI, it's modular nature, allowing its sellers to lower or increase the price depending on which modules you'd like included, and which ones you'd like excluded, where a module means a preconfigured fakes, TANs, and phishing pages for all the banks in a country of choice. Moreover, despite that both, Zeus and Metaphisher are open source, and therefore malicious parties visionary enough to build communities around their kits in order to enjoy the innovation brought by multiple parties, Metaphisher has a bigger community next to Zeus, considered as the MPack in the web malware exploitations kits, namely a bit of an outdated commodity that is of course still capable of doing what does best - hijacking E-banking sessions and logging them to the level of impersonation.<br /><br />How are the authors of Zeus describing the kit themselves? Here's a description :<br /><br />"<span style="font-style: italic;">ZeuS has the following main features and properties (full list is given here, in your part of assembling this list may not):</span>  <span style="font-style: italic;"><br /><br />Bot:</span> <span style="font-style: italic;">- Written in VC + + 8.0, without the use of RTL, etc., on pure WinAPI, this is achieved at the expense of small size (10-25 Kb, depends on the assembly).</span> <span style="font-style: italic;"><br /><br />- There has its own process, through this can not be detected in the process list.</span> <span style="font-style: italic;"><br />- Workaround most firewall (including the popular Outpost Firewall versions 3, 4, but suschetvuet temporary small problem with antishpionom). Not a guarantee unimpeded reception incoming connections.</span> <span style="font-style: italic;"><br />- Difficult to d</span><span style="font-style: italic;">etect finder / analysis, bot sets the victim and creates a file, the system files and arbitrary size.</span><br /><span style="font-style: italic;">- Works in limited accounts Windows (work in the guest account is not currently supported).</span> <span style="font-style: italic;"><br />- Nevid ekvaristiki for antivirus, Bot body is encrypted.</span> <span style="font-style: italic;"><br />- Some way creates a suspected its presence, if you do not want it. Here is the view of the fact that many authors do love spyware: unloading firewall, antivirus, the ban on their renewal, blocking Ctrl + Alt + Del, etc.</span><br /><span style="font-style: italic;">- Locking Windows Firewall (the feature is required only for the smooth reception incoming connections).</span> <span style="font-style: italic;"><br />- All your settings / logs / team keeps bot / Takes / sends encrypted on HTTP (S) protocol. (ie, in text form data will see only you, everything else bot <-> server will look like garbage).</span> <span style="font-style: italic;"><br />- Detecting NAT through verification of their IP through your preferred site.</span> <span style="font-style: italic;"><br />- A separate configuration file that allows itself to protect against loss in cases of inaccessibility botneta main server. Plus additional (reserve) configuration files, to which the bot will ap</span><span style="font-style: italic;">ply, will not be available when the main configuration file. This system ensures the survival of your botneta in 90% of cases.</span> <span style="font-style: italic;"><br />- Ability to work with any browsers / programs work through wininet.dll (Internet Explorer, AOL, Maxton, etc.):</span> <span style="font-style: italic;"><br />- Intercepting POST-data + interception hitting (including inserted data from the clipboard).</span> <span style="font-style: italic;"><br />- Transparent URL-redirection (at feyk sites, etc.) c task redirect the simplest terms (for example: only when GET or POST request, in the presence or absence of certain data in POST-request).</span> <span style="font-style: italic;"><br />- Transparent HTTP (S) substitution content (Web inzhekt, which allows a substitute for not only HTML pages, but also any other type of data). Substitution of sets with the help of guidance masks substitute.</span><br /><span style="font-style: italic;">- Obtaining the required contents page, with the exception HTML-tags. Based on Web inzhekte.</span> <span style="font-style: italic;"><br />- Custo</span><span style="font-style: italic;">mizable TAN-grabber for any country.</span> <span style="font-style: italic;"><br />- Obtaining a list of questions and answers in the bank "Bank Of America" after successful authentication.</span> <span style="font-style: italic;"><br />- Removing POST-needed data on the right URL.</span> <span style="font-style: italic;"><br />- Ideal Virtual Keylogger solution: After a call to the requested URL, a screenshot happening in the area, where was clicking.</span> <span style="font-style: italic;"><br />- Receiving certificates from the repository "MY" (certificates marked "No exports" are not exported correctly) and its clearance. Following is any imported certificate will be saved on the server.</span> <span style="font-style: italic;"><br />- Intercepting ID / password protocols POP3 and FTP in the independence of the port and its record in the log only with a successful authorise.</span> <span style="font-style: italic;"><br />- Changing the local DNS, removal / appendix records in the file% system32% \ drivers \ etc \ hosts, ie comparison specified domain with the IP for WinSocket.</span> <span style="font-style: italic;"><br />- Keeps c</span><span style="font-style: italic;">ontents Protected Storage at first start the computer.</span> <span style="font-style: italic;"><br />- Removes S ookies from the cache when Internet Explorer first run on a computer.</span> <span style="font-style: italic;"><br />- Search on the logical disk files by mask or download a specific file.</span><br /><span style="font-style: italic;">- Recorded just visited the page at first start the computer. Useful when installing through sployty, if you buy a download service from the suspect, you can see that even loaded in parallel.</span><br /><span style="font-style: italic;">- Getting screenshot with the victim's computer in real time, the computer must be located outside the NAT.</span> <span style="font-style: italic;"><br />- Admission commands from the server and sending reports back on the successful implementation. (There are currently launching a local / remote file an immediate update the configuration file, the destruction OS).</span> <span style="font-style: italic;"><br />- Socks4-server.</span><br /><span style="font-style: italic;">- HTTP (S) PROXY-server.</span> <span style="font-style: italic;"><br />- Bot Upgrading to the latest version (URL new version set in the configuration file).</span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SBBPQdDpjAI/AAAAAAAABoA/2LMvwvtY3uQ/s1600-h/zeus_in_the_middle_fake_injects.JPG"><img id="BLOGGER_PHOTO_ID_5192737514454617090" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/SBBPQdDpjAI/AAAAAAAABoA/2LMvwvtY3uQ/s200/zeus_in_the_middle_fake_injects.JPG" border="0" /></a>What's most important to keep in mind in regarding to these crimeware kits, is that the sellers are shifting from product-centered to service-centered propositions, and while an year ago they would have been selling the kit only, today they've realized that it's the output of the kit in terms of logged stolen accounting data that they're selling. <a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">Committing identity theft and abusing stolen E-banking accounting data is already a service</a>, compared to the product it used to be.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><a href="http://ddanchev.blogspot.com/2007/11/targeted-spamming-of-bankers-malware.html">Targeted Spamming of Bankers Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/03/localized-bankers-malware-campaign.html">Localized Bankers Malware Campaign</a><br /><a href="http://ddanchev.blogspot.com/2007/05/client-application-for-secure-e-banking.html">Client Application for Secure E-banking?</a><br /><a href="http://ddanchev.blogspot.com/2007/05/defeating-virtual-keyboards.html">Defeating Virtual Keyboards</a><br /><a href="http://ddanchev.blogspot.com/2007/08/paypals-security-key.html">PayPal's Security Key</a><br /><a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">Nuclear Grabber Kit</a><br /><a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">Apophis Kit</a> </div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=aTzMwJG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=aTzMwJG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2VBaffG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2VBaffG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TWtWGFg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TWtWGFg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yhZiA5g"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yhZiA5g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QlyIkhG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QlyIkhG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GeVECiG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GeVECiG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8XfDHog"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8XfDHog" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/276786652" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 24 Apr 2008 00:37:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zeus">zeus</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/remote file">remote file</category>
      <category domain="http://securityratty.com/tag/zeus trojan">zeus trojan</category>
      <category domain="http://securityratty.com/tag/binary file">binary file</category>
      <category domain="http://securityratty.com/tag/file system32 drivers">file system32 drivers</category>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/metaphisher kit">metaphisher kit</category>
      <category domain="http://securityratty.com/tag/configuration file">configuration file</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/276786652/crimeware-in-middle-zeus.html">Crimeware in the Middle - Zeus</source>
    </item>
  </channel>
</rss>
