<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: scammy]]></title>
    <link>http://securityratty.com/tag/scammy</link>
    <description></description>
    <pubDate>Wed, 16 Apr 2008 11:21:03 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Managed Fast Flux Provider - Part Two]]></title>
      <link>http://securityratty.com/article/210da9c1b19bf76a539ca28b24edc989</link>
      <guid>http://securityratty.com/article/210da9c1b19bf76a539ca28b24edc989</guid>
      <description><![CDATA[We're slowly entering into a stage where RBN bullet proof hosting franchises are vertically integrating, and due to the requests from their customers are starting to offer that they refer to as...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQymgVga0I/AAAAAAAACOw/geleqRWDOE0/s1600-h/pharma_spam_fastflux.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOQymgVga0I/AAAAAAAACOw/8PTQr8G6mBM/s200-R/pharma_spam_fastflux.png" /></a>We're slowly entering into a stage where <a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html">RBN bullet proof hosting franchises</a> are vertically integrating, and due to the requests from their customers are starting to offer that they refer to as "mirrored hosting" which in practice is plain simple fast flux network consisting of RBN-alike purchased netblocks, and naturally, botnet infected hosts.<br />
<br />
Managed fast-fluxing is only starting to go mainstream, for instance, in July I found evidence that <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">money mule recruiters were using ASProx's infected hosts as hosting infrastructure</a>, and in November, 2007, <a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">an infamous spamming software vendor</a> was also found to have been offering fast-flux services in the past.<br />
<br />
In this most recent fast-flux service, we have a known spammer and botnet master that in between self-serving himself on is way to ensure his portfolio of scammy domains remains online for a "little longer", is commercializing fast-fluxing and is offered a DIY service :<br />
<br />
"<i>Finally after hardwork and great appreciation from our normal bullet proof  hosting/server clients we are able to launch Mirrored hosting. What is </i><i>Mirrored hosting</i><i> ?</i><br />
<i><br />
================<br />
</i><i>Mirrored hosting</i><i> is a powerful mirrored  web hosting management, uses multiple Virtual servers to host  website with 100% uptime. </i><i>Mirrored hosting </i><i>is a combination of two things, which  are:<br />
<br />
1. Specially Designed Virtual Servers</i><br />
<i> 2. Powerful  Automated Control Panel</i><br />
<br />
<i>How does it work ?<br />
===============&nbsp;</i><br />
<br />
<i>Mirrored hosting</i><i> uses specially configured Virtual Servers making them link with the </i><i>Mirrored hosting</i><i> Control Panel  which is then controlled by our own control panel allowing us to provide smooth  streamline hosting with no downtime. No one is able to trace original IP of the  server or the place where the files are hosted so the websites/domains hosted  have a 100% Uptime. This is achieved by unique customisation of our Virtual Servers.<br />
<br />
<b>Actually, it takes ips around the world and our  powerful control panel just rotates the ips every 15 minutes. though all these  ips you will see will be fake no one can trace the orignal ip where files are  hosted. Sometimes the ip is from China, Korea, USA, UK, Japan, Lithuania etc.</b></i>"<br />
<br />
The concept has always been there for cybercriminals to take advantage of, but once it matures into a managed service it would undoubtedly lower down the entry barriers allowing yesterday's average phishers to take advantage of what only the "pros" were used to.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AO71M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AO71M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xZIrM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xZIrM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZGgOm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZGgOm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=e7OAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=e7OAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BVPbM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BVPbM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iS1HM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iS1HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iQOUm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iQOUm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409475392" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 08:39:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/recent fast-flux service">recent fast-flux service</category>
      <category domain="http://securityratty.com/tag/powerful control panel">powerful control panel</category>
      <category domain="http://securityratty.com/tag/control panel">control panel</category>
      <category domain="http://securityratty.com/tag/virtual servers">virtual servers</category>
      <category domain="http://securityratty.com/tag/multiple virtual servers">multiple virtual servers</category>
      <category domain="http://securityratty.com/tag/fast flux spam">fast flux spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409475392/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</source>
    </item>
    <item>
      <title><![CDATA[Summarizing July's Threatscape]]></title>
      <link>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</link>
      <guid>http://securityratty.com/article/2860027a1eaa69350d814429c3bf6070</guid>
      <description><![CDATA[July's threatscape -- consider going through June's summary as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/WogqT88LBdc/s1600-h/ddanchev_july.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJLdSTaizDI/AAAAAAAAB_E/Bb9z-K3ib7c/s200-R/ddanchev_july.jpg" style="border: 0pt none ;" /></a>July's threatscape -- consider going through <a href="http://ddanchev.blogspot.com/2008/07/summarizing-junes-threatscape.html">June's summary</a> as well -- once again demonstrated that nothing is impossible, the impossible just takes a little longer where the incentive would be the ultimate monetization of the process.<br />
<br />
Russian hacktivists attacking Lithuania and Georgia, several Storm Worm campaigns, a couple of new malware tools, Neosploit team abandoning support for their web malware exploitation kit, CAPTCHA for several of the most popular free email providers getting efficiently attacked in order to resell the bogus accounts registered in the process, several copycat SQL injects next to the evasion techniques applied by the copycats, botnets continuing to commit click fraud and generate revenue for those who own or have rented them, an infamous money mule recruitment service taking advantage of the fast-fluxed network provided by the ASProx botnet - pretty interesting month indeed.<br />
<br />
<b>01.</b> <a href="http://ddanchev.blogspot.com/2008/07/decrypting-and-restoring-gpcode.html">Decrypting and Restoring GPcode Encrypted Files</a> -<br />
The GPcode authors read the news too, and are catching up with the major weaknesses pointed out in their previous release in order to come with a virtually unbreakable algorithm. And since more evidence of <a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html">who's behind the GPcode ransomware</a> was gathered, vendors and independent researchers realized that the latest release is also susceptible to a plain simple flaw, namely the encrypted files were basically getting deleting and not securely erased making them fairly easy to recover.<br />
<br />
<b>02.</b> <a href="http://ddanchev.blogspot.com/2008/07/chinese-bloggers-bypassing-censorship.html">Chinese Bloggers Bypassing Censorship by Blogging Backward</a> -<br />
When you know how it works, you can either improve, abuse or destroy it in that very particular order. Chinese bloggers are always very adaptive in respect to spreading their message by obfuscating their messages in a way that common keywords filtering software wouldn't be able to pick them.<br />
<br />
<b>03.</b> <a href="http://ddanchev.blogspot.com/2008/07/gmail-yahoo-and-hotmails-captcha-broken.html">Gmail, Yahoo and Hotmail’s CAPTCHA Broken</a> -<br />
This has been an urban legend for a while, but with more services starting to offer hundreds of thousands of pre-registered accounts at these providers, it's surprising that <a href="http://blogs.zdnet.com/security/?p=1514">spam and phishing emails coming from legitimate email providers is increasing</a>. The "vendors" behind these propositions are naturally starting to "vertically integrate" by offering value-added services for extra payments, namely, scripts to automatically abuse the pre-registered accounts for automatic registration of splogs and anything else malicious or blackhat SEO related.<br />
<br />
<b>04.</b> <a href="http://ddanchev.blogspot.com/2008/07/antivirus-industry-in-2008.html">The Antivirus Industry in 2008</a> -<br />
If it were anyone else but a security vendor to come up with such a realistic cartoon aiming to stimulate innovation by emphasizing on how prolific and sophisticated malware groups have become, it would have been a biased cartoon. However, this one is courtesy of a security vendor, and it's pretty objective.<br />
<br />
<b>05.</b> <a href="http://ddanchev.blogspot.com/2008/07/lithuania-attacked-by-russian.html">Lithuania Attacked by Russian Hacktivists, 300 Sites Defaced</a> -<br />
This attack is a good example of a decent PSYOPS operation. Of course they have already build the capabilities to deface and even execute DDoS attacks against Lithuania, so why not put them in a "stay tuned" mode, by speculating on the upcoming attack and then executing it making it look like they delived what they've promised? This a lone gunman mass defacement given that the sites were all hosted on a single ISP, with no indication of any kind of coordination whatsoever. The same for the <a href="http://blogs.zdnet.com/security/?p=1533">Georgia President’s web site which was under DDoS attack from Russian hackers</a> later this month. Despite that the hacktivists behind it dedicated a separate C&amp;C for the attack, one that hasn't been used in any type of previous attacks so far, they did a minor mistake by using a secondary command and control location that's known to have been connected with a particular "botnet on demand" service in the past. The second attack once again proves that you don't need to build capacity when you can basically outsource the process to someone else.<br />
<br />
<b>06.</b> <a href="http://ddanchev.blogspot.com/2008/07/icann-responds-to-dns-hijacking-its.html">The ICANN Responds to the DNS Hijacking, Its Blog Under Attack</a> -<br />
The ICANN finally issued a statement concerning the DNS hijacking of some of their domains, which is in fact what Comcast.net and Photobucket.com should have done as well, next to stating it was a "glitch". The ICANN also took advantage of the moment and also pointed out that their blog has also been under attack during the month. There's no better example of how the combination of <a href="http://ddanchev.blogspot.com/2008/06/icann-and-ianas-domain-names-hijacked.html"> tactics can result in the hijacking of the domains</a> of the organizations implementing procedures aiming to protect against these very same attacks. And while Photobucket.com remained silent during the entire incident, the hosting provider that was used by the Netdevilz team in the two attacks, since they were also responsible for the ICANN and IANA DNS hijackings, <a href="http://ddanchev.blogspot.com/2008/06/update-to-photobuckets-dns-hijacking.html">technological and social engineeringissued a statement</a>.<br />
<br />
<b>07.</b> <a href="http://ddanchev.blogspot.com/2008/07/risks-of-outdated-situational-awareness.html">The Risks of Outdated Situational Awareness</a> -<br />
Security vendors are often in a "catch-up mode" and if I were an average Internet user not knowing that real-time situational awareness speaks for the degree to which my vendor knows what going on online, I'd be pretty excited. However, I'm not. <a href="http://blogs.zdnet.com/security/?p=1085">Prevx were catching up with a service which I covered approximately two months ago</a>, I even had the chance to constructively confront with one of the affected sites on how despite their security measures in place, this attack was still possible. Recently <a href="http://www.theregister.co.uk/2008/07/18/limbo_trojan/">Prevx have once again demonstrated an outdated situational awareness</a> by coming across a banking malware in July 2008, whereas the malware has been around since July 2007, and earlier depending on which version you're referring to.<br />
<br />
<b>08.</b> <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a> -<br />
Yet another domain portfolio of fake porn sites serving rogue codecs and live exploit URLs, just the tip of the iceberg as usual, however their centralization is greatly assisting in tracking them down.<br />
<br />
<b>09.</b> <a href="http://ddanchev.blogspot.com/2008/07/storm-worms-us-invasion-of-iran.html">Storm Worm's U.S Invasion of Iran Campaign</a> -<br />
Stormy Wormy is once again making the headlines with their ability to actually make up the headlines on their own.<br />
<br />
<b>10.</b> <a href="http://ddanchev.blogspot.com/2008/07/mobile-malware-scam-isexplayer-wants.html">Mobile Malware Scam iSexPlayer Wants Your Money</a> -<br />
The best scams are the ones to which you've personally agreed to be scammed with without even knowing it. Like this one, which was tracked down and analyzed a couple of hours once a uset tipped on it.<br />
<br />
<b>11.</b> <a href="http://ddanchev.blogspot.com/2008/07/template-ization-of-malware-serving.html">The Template-ization of Malware Serving Sites</a> -<br />
The increase of fake porn and celebrity sites is due to the overall template-ization of these, with the people behind them basically implementing several malicious doorways to ensure that the domains get rotated on the fly. Despite that they all look the same, they all sever different type of malware, and zero porn of celebrity content at all except the thumbnails.<br />
<br />
<b>12.</b> <a href="http://ddanchev.blogspot.com/2008/07/violating-opsec-for-increasing.html">Violating OPSEC for Increasing the Probability of Malware Infection</a> -<br />
No better way to expose your affiliations and several unknown bad netblocks so far, by adding the netblocks and the malicious domains as trusted sites upon infecting a PC with the malware. Of course, the usual suspects lead the "trusted netblocks".<br />
<br />
<b>13.</b> <a href="http://ddanchev.blogspot.com/2008/07/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</a> -<br />
Several years ago, a script kiddie would install Apache on a mail server, they claim that they defaced it. Today, these amusing situations are replaced by monetization of the compromised sites, by reselling the access to them to blackhat SEO-ers, malware authors, phishers, or personally starting to manage a scammy infrastructure on them, by earning money on an affiliate based model, like this particular attack.<br />
<br />
<b>14.</b> <a href="http://ddanchev.blogspot.com/2008/07/malware-and-office-documents-joining.html">Malware and Office Documents Joining Forces</a> -<br />
A recent DIY malware kit, sold as a proprietary tool basically crunching out malware infected office documents, whose built-in obfuscation makes them harder to detect. It will sooner or later leak out, turning into a commodity tool, a process that's been pretty evident for web malware exploitation kits as well.<br />
<br />
<b>15.</b> <a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</a> -<br />
Depends on who you're buying them from, and whether or not they offer discounts on a volume basis, namely the more you buy the cheaper the price of a card is supposed to get. With the current oversupply of stolen credit card details, what used to be an exclusive good once where they could enjoy a higher profit-margin, is today's commodity good.<br />
<br />
<b>16.</b> <a href="http://ddanchev.blogspot.com/2008/07/neosploit-malware-kit-updated-with.html">The Neosploit Malware Kit Updated with Snapshot ActiveX Exploit</a> -<br />
Since alll the web malware exploitation kits are open source, and leaked in the wild at large, their modularity allows everyone to easily embed any type of exploit that they want to, resulting in Neosploit's single most beneficial feature, the fact that certain versions include all the publicly available exploits targeting Internet Explorer, Firefox and Opera. Moreover, the open source nature of the kit is resulting in a countless number of modified versions yet to be detected and analyzed, therefore keeping track of the exploits included in a malware kit can only be realistic if you take into considered the exploits that come with the default installation.<br />
<br />
<b>17.</b> <a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast-fluxed SQL Injected Domains</a> -<br />
Now that's a very good example of different tactics combined to attack, ensure survivability, and apply a certain degree of evasion in between.<br />
<br />
<b>18.</b> <a href="http://ddanchev.blogspot.com/2008/07/unbreakable-captcha.html">The Unbreakable CAPTCHA</a> -<br />
There's never been a shortage of ideas, there's always been an issue of usability.<br />
<br />
<b>19.</b> <a href="http://ddanchev.blogspot.com/2008/07/ayyildiz-turkish-hacking-group-vs.html">The Ayyildiz Turkish Hacking Group VS Everyone</a> -<br />
That's a pretty inspiring mission if you are to ensure your future in the next couple of years, by targeting everyone, everywhere that has ever publicly stated their disagreement with the Turkish foreign policy.<br />
<br />
<b>20.</b> <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast Fluxing Services</a> -<br />
A true multitasking in action with a botnet that's been crunching out phishing emails, SQL injecting and now hosting a well known money mule recruitment service. <br />
<br />
<b>21.</b> <a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware</a> -<br />
Constantly switching tactics and combining different ones to achive an objective that used to be accomplished by plain simple techniques, is only starting to take place. In this case, instead of a hard coded SQL injected domain, we have the typical malicious doorways the result of the converging traffic management tools with web malware exploitation kits.<br />
<br />
<b>22.</b> <a href="http://ddanchev.blogspot.com/2008/07/impersonating-stopbadwareorg-to-serve.html">Impersonating StopBadware.org to Serve Fake Security Warnings</a> -<br />
Typosquatting popular security vendors and services is nothing new, by having HostFresh providing the hosting for the parked domains promoting the rogue security software, is a privilege and flattery for the success of the Stopbadware initiative.<br />
<br />
<b>23.</b> <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</a> -<br />
Customerization -- not customization -- has been taking place for a while, that's the process of tailoring your upcoming products to the needs of your future customers, compared to the product concept myopia where the malware coder would code something that he believes would be valuable to the potential customers. End user agreements, issuing licenses for the malware tool, as well as forbidding the reverse engineering of the malware so that no remotely exploitable flaws could be, are among the requirements the coder assists on.<br />
<br />
<b>24. </b><a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><b> -</b><br />
Taking a random snapshot of the current malicious activity at a well known provider of hosting services for rogue security applications, live exploit URLs and botnet command&amp;control locations, always provides an insight into what are their customers up to. In this case, centralization of their scammy ecosystem, and parking a countless number of rogue domains on the same server.<br />
<br />
<b>25. </b><a href="http://ddanchev.blogspot.com/2008/07/email-hacking-going-commercial.html">Email Hacking Going Commercial</a> -<br />
Cybercrime is in fact getting easier to outsource, and while the number of scammers trying to offer non-existent services, or at least services where they cannot deliver the goods, the business model of this service that is that you only pay once they show you a proof that they've managed to hack the email address you game them. How are they doing it? Social engineering and enticing the user to click on live exploit URL from where they'll infect the PC and obtain the email password, of course, next to definitely abusing it for many other purposes in the process.<br />
<br />
<b>26.</b> <a href="http://ddanchev.blogspot.com/2008/07/vulnerabilities-in-antivirus-software.html">Vulnerabilities in Antivirus Software - Conflict of Interest</a> -<br />
You can easily twist the number of vulnerabilities found in your antivirus solution, but not recognizing them as vulnerabilities at the first place. It's all a matter of what you define as a vulnerability, or perhaps what you admit as a serious vulnerability - remote code execution through a security software, or a flaw that's allowing malware to bypass the security solution itself.<br />
<br />
<b>27. </b><a href="http://ddanchev.blogspot.com/2008/07/counting-bullets-on-malware-front.html">Counting the Bullets on the (Malware) Front</a> -<br />
Emphasizing on the number of malware/threats/viruses/worms/slugs your solution detects may be marketable in the short-term, but is damaging the end user's understanding of the threatscape in the long-term. So, by the time he catches up with what exactly is going on, he'll recall the moment in time where he was using the number of threats his solution was detecting as the main benchmark for its usefulness. In reality through, the number is irrelevant from a pro-active point of view, with zero day malware like the one coded for hire undermining the signatures based scanning model.<br />
<br />
<b>28. </b><a href="http://ddanchev.blogspot.com/2008/07/smells-like-copycat-sql-injection-in.html">Smells Like a Copycat SQL Injection In the Wild</a> -<br />
It was pretty obvious that copycats seeing the success of SQL injections the the huge number of sites susceptible to exploitation, would also starting taking advantage of the practice. Some are, however, targeting local communities and trying to avoid detection by using targeted SQL injections.<br />
<br />
<b>29. </b><a href="http://ddanchev.blogspot.com/2008/07/click-fraud-botnets-and-parked-domains.html">Click Fraud, Botnets and Parked Domains - All Inclusive</a> -<br />
The scheme is nothing new, what's new is that the botnet masters are trying to limit the revenues that used to go out to affiliate networks they were participating in, and are trying to own or rent the entire infrastructure on their own.<br />
<br />
<b>30. </b><a href="http://ddanchev.blogspot.com/2008/07/over-80-percent-of-storm-worm-spam-sent.html">Over 80 percent of Storm Worm Spam Sent by Pharmaceutical Spam Kings</a><b> -</b><br />
With access to Storm Worm sold and resold, and new malware introduced on Storm Worm infected hosts used as foundation for the propagation of the new malware in this case, it's questionable whether or not the Storm Worm-ers themselves are sending out the junk emails, or are they people who've rented access to the botnet doing it. <br />
<br />
<b>31. </b><a href="http://ddanchev.blogspot.com/2008/07/neosploit-team-leaving-it-underground.html">Neosploit Team Leaving the IT Underground</a> -<br />
Pretty surprising at the first place, but in reality it clearly demonstrates that when you cannot enforce the end user agreement on your crimeware kit, but continue seeing it used in a very profitable malware operations, you basically shut down the support for the public version. The team is not going to stop innovating for their own purposes, and in the long-term they may in fact re-appear with an updated malware kit that's converging different services next to the product itself.<br />
<br />
<b>32. </b><a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Dissecting a Managed Spamming Service</a> - <br />
Managed spamming services using botnets as the foundation for the campaigns are starting to introduce improved metrics for the delivery, as well as experienced customer support ensuring the spam messages make it through spam filters, or at least increase the probability of making the happen. This is an example of a random service emphasizing on the improved metrics they're capable of delivering.<br />
<br />
<b>33. </b><a href="http://ddanchev.blogspot.com/2008/07/storm-worms-lazy-summer-campaigns.html">Storm Worm's Lazy Summer Campaigns</a> -<br />
Looks like a "cybercrime intern" launched this campaign, lacking any of the usual Storm Worm evasive practices, no exploitation of client side vulnerabilities, as well as no survivability offered by their usual fast-flux nodes.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dMjxcK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dMjxcK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IC3AVK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IC3AVK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=d2XWZk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=d2XWZk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vRFZyk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vRFZyk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6ZdeKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6ZdeKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jVlXIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jVlXIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W4mAWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W4mAWk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/352993637" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 12:08:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/profitable malware operations">profitable malware operations</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware tools">malware tools</category>
      <category domain="http://securityratty.com/tag/malware coder">malware coder</category>
      <category domain="http://securityratty.com/tag/malware kit">malware kit</category>
      <category domain="http://securityratty.com/tag/malware infection">malware infection</category>
      <category domain="http://securityratty.com/tag/neosploit malware kit">neosploit malware kit</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/352993637/summarizing-julys-threatscape.html">Summarizing July's Threatscape</source>
    </item>
    <item>
      <title><![CDATA[Smells Like a Copycat SQL Injection In the Wild]]></title>
      <link>http://securityratty.com/article/ae553b37ba0ec150b5a4c344ba27652b</link>
      <guid>http://securityratty.com/article/ae553b37ba0ec150b5a4c344ba27652b</guid>
      <description><![CDATA[In between the massive SQL injections , that as a matter of fact remain ongoing, copycats taking advantage of the very same SQL injection tools using public search engine's indexes as a reconnaissance...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/SI2ac7mO18I/AAAAAAAAB9c/usiNWVgrooU/s1600-h/chinese_sql_injection.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SI2ac7mO18I/AAAAAAAAB9c/97ckqqWaQ14/s200-R/chinese_sql_injection.JPG" style="border: 0pt none ;" /></a>In between the <a href="http://ddanchev.blogspot.com/2008/07/ayyildiz-turkish-hacking-group-vs.html">massive SQL injections</a>, that as a matter of fact remain ongoing, copycats taking advantage of the very same SQL injection tools using public search engine's indexes as a reconnaissance tools, are also starting to take advantage of <a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">localized and targeted attacks</a>, attacking specific online communities. Among these is <b>mx.content-type.cn /day.js </b>using <b>day.js</b> to attempt multiple exploitation using publicly obtainlable exploits such as Adodb.Stream, MPS.StormPlayer, DPClient.Vod, IERPCtl.IERPCtl.1, GLIEDown.IEDown.1, and targeting primarily Chinese web communities.<br />
<br />
Compared to a bit more sophisticated <a href="http://ddanchev.blogspot.com/2008/04/diy-exploit-embedding-tool-proprietary.html">attack tactics applied by Chinese hackers</a>, taking advantage of <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">localized versions</a> of the <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">de facto web malware exploitation kits</a>, those who don't have access to such continue using cybercrime 1.0 <a href="http://ddanchev.blogspot.com/2007/09/diy-exploits-embedding-tools.html">DIY exploit embedding tools</a> at large. The rest of the SQL injected domains as well as the exploits themselves are parked on the same plaee - <b>222.216.28.25</b>, also responding to :<br />
<br />
<b>down.goodnetads .org<br />
ads.goodnetads .org<br />
real.kav2008 .com<br />
hk.www404 .cn<br />
err.www404 .cn<br />
mx.content-type .cn<br />
sun.63afe561 .info<br />
ads.633f94d3 .info<br />
ads.1234214 .info<br />
ad.50db34d5 .info<br />
ads.50db34d5 .info<br />
ad.8d77b42a .info<br />
web.adsidc .info<br />
free.idcads .info<br />
free.cjads .info<br />
ads.adslooks .info<br />
list.adslooks .info<br />
ad.5iyy .info</b><br />
<br />
The SQL injected domains :<br />
<b>ads.633f94d3.info/day .js<br />
ad.8d77b42a.info/day .js<br />
ad.5iyy.info/day .js<br />
free.idcads.info/day .js<br />
efreesky.com/day .js<br />
v.freefl.info/day .js</b><br />
<br />
The internal structure :<br />
<b>free.idcads.info/f/index .htm<br />
free.idcads.info/014 .htm<br />
free.idcads.info/real11 .htm<br />
free.idcads.info/real10 .htm<br />
free.idcads.info/lz .htm<br />
free.idcads.info/bf .htm<br />
free.idcads.info/kong .htm<br />
free.idcads.info/f/swfobject .js<br />
ad.50db34d5.info//rm%5C/rm .exe</b><br />
<br />
Parked domains responding to the command and control locations, <b>60.191.223.76 </b>and <b>222.216.28.100</b> :<br />
<b>ftp.gggjjj .info<br />
live.ads002 .net<br />
log.goodnetads .org<br />
dat.goodnetads .org<br />
root.51113 .com<br />
sun.update999 .cn<br />
abb.633f94d3 .info<br />
up.50db34d5 .info</b><br />
<b>web.cn3721 .org&nbsp;&nbsp;&nbsp; <br />
dat.goodnetads .org<br />
cs.rm510 .com<br />
sb.sb941 .com<br />
k.sb941 .com<br />
info.sb941 .com<br />
day.sb941 .com<br />
post.ad9178 .com<br />
v.91tg .net</b><br />
<br />
Centralizing their scammy ecosystem always makes it easier to monitor, keep track of, and of course, expose. <br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware </a><br />
<a href="http://ddanchev.blogspot.com/2008/05/yet-another-massive-sql-injection.html">Yet Another Massive SQL Injection Spotted in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/malware-domains-used-in-sql-injection.html">Malware Domains Used in the SQL Injection Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">SQL Injection Through Search Engines Reconnaissance</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/google-hacking-for-vulnerabilities.html">Google Hacking for Vulnerabilities</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><br />
<a href="http://blogs.zdnet.com/security/?p=1394">Sony PlayStation's site SQL injected, redirecting to rogue security software</a><br />
<a href="http://blogs.zdnet.com/security/?p=1118">Redmond Magazine Successfully SQL Injected by Chinese Hacktivists</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9XdgSJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9XdgSJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3nv7jJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3nv7jJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3DXSvj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3DXSvj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=exadYj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=exadYj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kp9u0J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kp9u0J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=y5pfDJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=y5pfDJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Lkbwwj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Lkbwwj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/348288922" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 01:51:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/sql injection tools">sql injection tools</category>
      <category domain="http://securityratty.com/tag/massive sql injections">massive sql injections</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/sql injection attacks">sql injection attacks</category>
      <category domain="http://securityratty.com/tag/sql injection">sql injection</category>
      <category domain="http://securityratty.com/tag/massive sql injection">massive sql injection</category>
      <category domain="http://securityratty.com/tag/site sql">site sql</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/348288922/smells-like-copycat-sql-injection-in.html">Smells Like a Copycat SQL Injection In the Wild</source>
    </item>
    <item>
      <title><![CDATA[Lazy Summer Days at UkrTeleGroup Ltd]]></title>
      <link>http://securityratty.com/article/6215851b79c397250e5f1b5a07d047b4</link>
      <guid>http://securityratty.com/article/6215851b79c397250e5f1b5a07d047b4</guid>
      <description><![CDATA[The result of building extra confidence into your malicious hosting provider's ability to remain online , is a scammy ecosystem that's constantly jumping from one netblock to another, whose very...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/SIXAHtEXmGI/AAAAAAAAB8c/T7J6WUyV9a4/s1600-h/avxp08.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIXAHtEXmGI/AAAAAAAAB8c/qDKYv6DcETA/s200-R/avxp08.png" style="border: 0pt none ;" /></a>The result of building extra confidence into your <a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">malicious hosting provider's ability to remain online</a>, is a scammy ecosystem that's constantly jumping from one netblock to another, whose very latest exploit URLs and rogue security software nexto to the codecs served, always represent a decent sample of malicious activities to analyze.<br />
<br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">UkrTeleGroup Ltd</a> (<i>85.255.112.0-85.255.127.255 UkrTeleGroup UkrTeleGroup Ltd. 27595 ASN ATRIVO</i>), a personal favorite due to its historical connection with the Russian Business Network, and hosting provider for a countless of number of injected and malware embedded campaigns during the last two years, is still keeping it as lazy as possible, a laziness allowing you to easily expose a great deal of the malicious activities going on there, and establish the connections between the hosting provider, its current and historical customers.<br />
<br />
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SIXJBRIoucI/AAAAAAAAB8k/r9Y6CPtAE0Y/s1600-h/rogue_software_codecs_UkrTeleGroup.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIXJBRIoucI/AAAAAAAAB8k/cHCoWY8V1RY/s200-R/rogue_software_codecs_UkrTeleGroup.JPG" style="border: 0pt none ;" /></a>Take <b>microsoftcodecs.com</b> (88.214.198.220) for instance, and <b>avxp08.com</b> where it redirects the user into yet another rogue security software. <b>avxp08.com</b> is responding to 194.110.162.114; 216.195.41.11; 216.195.41.11; 216.240.139.169, and to UkrTeleGroup Ltd's 85.255.117.163.<br />
<br />
Each of these IPs are also being shared by other rogue software and fake codecs simultaneously :<br />
<br />
(216.195.41.11)<br />
<b>antivirusxp2008 .com<br />
malwareprotector2008 .com<br />
antivirxp08 .com<br />
antivirusxp08 .com<br />
avxp08 .com<br />
youpornztube .com<br />
winifixer .com<br />
advancedxpfixer .com<br />
encountertracker .ws</b><br />
<br />
It gets even more UkrTeleGroup Ltd related upon the malware (Trojan:Win32/Tibs.HK) served at the <b>avxp08.com </b>gets sandboxed. The malware phones back home <b>stat.avxp08 .com </b>(85.255.118.172)<b> </b>announcing the successful infection <b>winifixer .com/log2.php?affid=980382bdb4e7b779ff6308b0b706571c&amp;uid=06f80eaf-94d7-4b8b-9cf0-5c6f75d2c69f&amp;tm=1211198022</b> (85.255.118.171), and the scammy ecosystem continues using the same hosting provider. The rest of the rogue tools are also using the same subdomain structure, and IP, <b>stat.antivirusxp2008 .com</b> (85.255.118.172), <b>stat.antivirxp08 .com</b> (85.255.118.172), <b>stat.antivirusxp08 .com</b> (85.255.118.172) in order to phone back home.<br />
<br />
<div class="separator" style="text-align: left; clear: both;"><a href="http://bp3.blogger.com/_wICHhTiQmrA/SIXMeEAQTmI/AAAAAAAAB8s/bax-CAw9xJ8/s1600-h/fake_windows_media_player.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SIXMeEAQTmI/AAAAAAAAB8s/_hv8u7SKjP8/s200-R/fake_windows_media_player.JPG" style="border: 0pt none ;" /></a></div><b>winifixer .com</b>, a well known rogue software, is entirely relying on UkrTeleGroup's hosting services hosted at 85.255.117.163; 85.255.118.171; 85.255.120.115; 85.255.120.139; 216.195.41.11 pinpoing several other obvious and well known netblocks hosting anything starting from fake celebrity video sites serving fake Windows Media Player videos, to rogue security software and live exploit URLs. Take for instance their efficiency centered approach to park numerous malicious domains on a single IP, like 85.255.117.218 in this case :<br />
<br />
<b>bestfunnyvids .com<br />
celebs69 .com<br />
celebsnofake .com<br />
celebstape .com<br />
celebsvidsonline .com<br />
codecservice1 .com<br />
freevidshardcore .com<br />
newfunnyvideo .com<br />
sexlookupworld .com<br />
starfeed1 .com<br />
starfeed2 .com<br />
topdirectdownload .com&nbsp;&nbsp;&nbsp; <br />
topsearchresults1 .com<br />
topsoftupdate .com<br />
yourfavoritetube .com</b><br />
<br />
Now that it's becoming clear who's providing the hosting infrastructure, it's perhaps also worth pointing out who's using the hosting infrastructure to serve rogue security software and fake codecs on the basis of participating in an affiliate program? A great number of domains used by the rogue security software are registered by <b>krab@thekrab.com</b> behind which is supposidely Mishakov Viktor Ivanovich <b>support@tobesoftware.com</b>, and ironically <b>tobesoftware.com</b> is again hosting within UkrTeleGroup (85.255.120.115). The personal efforts into the number of the typosquatted domains and the persistence applied when registered and spamming them across the web, is the result of the incentives provided to them by the affiliate program they participate in.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CNeYgJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CNeYgJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UZqVKJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UZqVKJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FhKPZj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FhKPZj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6DFhuj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6DFhuj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pxNm7J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pxNm7J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cYGFFJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cYGFFJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=S2jU9j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=S2jU9j" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/342489167" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 03:12:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ukrtelegroup">ukrtelegroup</category>
      <category domain="http://securityratty.com/tag/codecs">codecs</category>
      <category domain="http://securityratty.com/tag/fake codecs simultaneously">fake codecs simultaneously</category>
      <category domain="http://securityratty.com/tag/rogue security software">rogue security software</category>
      <category domain="http://securityratty.com/tag/ukrtelegroup ukrtelegroup">ukrtelegroup ukrtelegroup</category>
      <category domain="http://securityratty.com/tag/fake codecs">fake codecs</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/home stat">home stat</category>
      <category domain="http://securityratty.com/tag/scammy ecosystem">scammy ecosystem</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/342489167/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</source>
    </item>
    <item>
      <title><![CDATA[The Ayyildiz Turkish Hacking Group VS Everyone]]></title>
      <link>http://securityratty.com/article/e5949393a0e7be6e2ea6b20dadaba58c</link>
      <guid>http://securityratty.com/article/e5949393a0e7be6e2ea6b20dadaba58c</guid>
      <description><![CDATA[Certain hacktivist groups often come and go by the time the momentum of their particular cause is long gone. Excluding the hardcore hacktivists who are obliged to defend their country's infrastructure...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><div style="text-align: left;"></div><div class="" style="clear: both;"><a href="http://bp0.blogger.com/_wICHhTiQmrA/SH-6Lbjq6XI/AAAAAAAAB7M/dn0skav9XIg/s1600-h/AYYILDIZ_TEAM.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SH-6Lbjq6XI/AAAAAAAAB7M/mYlVgqX-mVU/s200-R/AYYILDIZ_TEAM.jpg" style="border: 0pt none ;" /></a>Certain hacktivist groups often come and go by the time the momentum of their particular cause is long gone. Excluding the hardcore hacktivists who are obliged to defend their country's infrastructure and reputation on the international scene, smart enough to do on one front, there are certain hacktivist groups who ensure their future existence by declaring war and every single country that has ever made statements in contradiction with their vision. Quite a stimulating factor for ensuring the future of your script kiddies group, isn't it?<br />
<br />
One of these groups is the AYYILDIZ TEAM, a group of Turkish script kiddies who've been pretty active as of recently, targeting everyone, everywhere, leaving statements like the following :</div><br />
"<i>Me, as AYT-Admin Barbaros, swear to everything which is lovely and holy to me, that you will pay for your actions. We, AYT, as a Cyber Attacking Army will make it sure. Read right, what will we do:<br />
<br />
* The government websites will be inaccessible an all lawsuits will be manipulated</i><br />
<i>* We will infiltrate the server of inland revenues for the manipulation of the data which are there.</i><br />
<i>* At the same time we will insist into the server of banks and will care for chaos</i><br />
<i>* Websites of the press will be extinguished.</i><br />
<i>* If the offence of our prophet (s.a.v.) called your press freedom, we will show you this press freedom</i><br />
<i>* Websites of divers shops will be hacked. Databank information's and the dates which are there, for example credit card dates, will be policed in this page. (Don't worry, we wouldn't taste one cent of your moneys, we aren't thieves like you. However we don't take care of what happens, if other hackers see this dates and empty your account)</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SIBtXRQhuII/AAAAAAAAB7U/WwX3npoBZvI/s1600-h/SQL_turkz.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIBtXRQhuII/AAAAAAAAB7U/saIYE3fxpdA/s200-R/SQL_turkz.JPG" style="border: 0pt none ;" /></a>While this may sound inspiring, <b>some of the group's members are also involved in SQL injections in between the web site defacements</b>, which are naturally done by exploiting web application vulnerabilities. For instance, right after the defacement messages, they are also injecting the following fast-fluxed domains, part of the latest wave of SQL injections attacks.<b></b><br />
<br />
<b>bkpadd.mobi /ngg.js<br />
usaadw.com /ngg.js<br />
cliprts.com /ngg.js</b><br />
<br />
They are monetizing their defacements by either compiling lists of sites known to be SQL injectable since they've managed to defaced them, then reselling these to the SQL injectors, or are in fact part of the whole process in this scammy ecosystem. Speaking of SQL injections, here's the most recent list of fast-fluxed SQL injected domains participating in the last wave that I've been keeping track of for a while :<br />
<br />
<b>pyttco .com/ngg.js<br />
butdrv .com/ngg.js<br />
gitporg .com/ngg.js<br />
brcporb .ru/ngg.js<br />
korfd .ru/ngg.js<br />
adwnetw .com/ngg.js<br />
wowofmusiopl .com.cn/456.js<br />
adwbn .ru/ngg.js<br />
btoperc .ru/ngg.js<br />
nudk .ru/ngg.js<br />
bkpadd .mobi/ngg.js<br />
cliprts .com/ngg.js<br />
adwr .ru/ngg.js<br />
bnrc .ru/ngg.js<br />
adpzo .com/ngg.js<br />
iogp .ru/ngg.js<br />
lodse .ru/ngg.js<br />
usabnr .com/ngg.js<br />
vcre .ru/ngg.js<br />
sdkj .ru/ngg.js<br />
rcdplc .ru/ngg.js<br />
7maigol .cn/ri.js<br />
j8heisi .cn/ri.js<br />
usaadp .com/ngg.js<br />
gbradp .com/ngg.js<br />
cdrpoex .com/ngg.js<br />
rrcs .ru/ngg.js<br />
gbradw .com/ngg.js<br />
hiwowpp .cn/ri.js<br />
cdport .eu/ngg.js<br />
nopcls .com/ngg.js<br />
loopadd .com/ngg.js<br />
tertad .mobi/ngg.js<br />
gbradde .tk/ngg.js<br />
tctcow .com/ngg.js<br />
ausbnr .com/ngg.js<br />
movaddw .com/ngg.js<br />
grtsel .ru/ngg.js<br />
sslwer .ru/ngg.js<br />
destad .mobi/ngg.js<br />
hdrcom .com/ngg.js<br />
addrl .com/ngg.js<br />
porttw .mobi/ngg.js<br />
bnsdrv .com/ngg.js<br />
drvadw .com/ngg.js<br />
crtbond .com/ngg.js<br />
usaadw .com/ngg.js</b><br />
<br />
What used to be plain simple cooperating among every single participant in the underground marketplace, seems to be evolving into long-term business relationships.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/right-wing-israeli-hackers-deface.html">Right Wing Israeli Hackers Deface Hamas's Site</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/pro-serbian-hacktivists-attacking.html">Pro-Serbian Hacktivists Attacking Albanian Web Sites</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/rise-of-kosovo-defacement-groups.html">The Rise of Kosovo Defacement Groups</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/commercial-web-site-defacement-tool.html">A Commercial Web Site Defacement Tool</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/phishing-tactics-evolving.html">Phishing Tactics Evolving</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/web-site-defacement-groups-going.html">Web Site Defacement Groups Going Phishing</a><br />
<a href="http://ddanchev.blogspot.com/2006/02/hacktivism-tensions.html">Hacktivism Tensions</a><br />
<a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/mass-defacement-by-turkish-hacktivists.html">Mass Defacement by Turkish Hacktivists</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/overperforming-turkish-hacktivists.html">Overperforming Turkish Hacktivists</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=727PxJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=727PxJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JwIAWJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JwIAWJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RvHRWj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RvHRWj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZamBlj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZamBlj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YzU9yJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YzU9yJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2kBf4J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2kBf4J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LV5ldj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LV5ldj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/338894561" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 01:48:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/comngg">comngg</category>
      <category domain="http://securityratty.com/tag/sql injections attacks">sql injections attacks</category>
      <category domain="http://securityratty.com/tag/sql injections">sql injections</category>
      <category domain="http://securityratty.com/tag/rungg">rungg</category>
      <category domain="http://securityratty.com/tag/sql">sql</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/web site defacement">web site defacement</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/338894561/ayyildiz-turkish-hacking-group-vs.html">The Ayyildiz Turkish Hacking Group VS Everyone</source>
    </item>
    <item>
      <title><![CDATA[Violating OPSEC for Increasing the Probability of Malware Infection]]></title>
      <link>http://securityratty.com/article/a8772335cd8deda2e5469b0533d7c817</link>
      <guid>http://securityratty.com/article/a8772335cd8deda2e5469b0533d7c817</guid>
      <description><![CDATA[Are malware authors and the rest of the participants in fact willing to violate their OPSEC (operational security) for the sake of increasing the probability of successful malware infection by on...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHf46B4X8KI/AAAAAAAAB5s/bNsyTU1Vchg/s1600-h/smitfraud_PC_hijacker.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHf46B4X8KI/AAAAAAAAB5s/ansREl9cVe0/s200-R/smitfraud_PC_hijacker.jpg" style="border: 0pt none ;" /></a>Are malware authors and the rest of the participants in fact willing to violate their OPSEC (operational security) for the sake of increasing the probability of successful malware infection by on purposely lowering down the security settings of Internet Explorer, by adding their malicious netblocks and domains into "Trusted Sites"? You bet.<br />
<br />
<div style="text-align: left;">The infamous Smitfraud or PSGuard Desktop Hijacker, has been cooperating with known malicious parties for over an year now, a cooperation which exposes interesting relatinships between the usual suspects. Starting from the basic fact that a malware infected host is infected with many other totally unrelated to one another pieces of malware, Smitfraud's "pre-infection foreplay" demonstrates that they are willing to sacrifice operational security in order to increaes the probabilty of future infections on the same host.</div>
<div class="separator" style="text-align: center; clear: both;"></div>
<br />
Rogue software added as trusted sites upon Smitfraud infection :<br />
<b>about-adult .net<br />
antivirus-scanner .com<br />
best-porncollection .com<br />
getadultaccess .com<br />
getavideonow .com<br />
ieantivirus .com<br />
malwarebell .com<br />
mega-soft-2008 .com<br />
mooncodec .com<br />
movsonline .com<br />
ruler-cash .com<br />
s-freeware .com<br />
sexysoftwaredom .com<br />
supersoft21freeware .com<br />
the-programsportal .com<br />
vwwredtube .com<br />
wetsoftwares .com<br />
youpornztube .com<br />
securewebinfo .com<br />
safetyincludes .com<br />
securemanaging .com<br />
myflydirect .com<br />
onlinevideosoftex .com<br />
scanner.malwscan .com<br />
scanner.shredderscan .com<br />
sex18tube2008 .com<br />
spywareisolator .com<br />
virus-scanner-online .com<br />
security-scanner-online .com<br />
virus-scanonline .com<br />
antivirus-scanonline .com<br />
topantivirus-scan .com<br />
topvirusscan .com<br />
virus-detection-scanner .com<br />
antivirus-scanner .com<br />
infectionscanner .com<br />
internet-security-antivirus .com&nbsp;&nbsp;&nbsp; <br />
hotvid44 .com<br />
opaadownload .com<br />
somenudefuck .com</b><br />
<br />
Rogue netblocks and IPs added as trusted IP ranges upon Smitfraud infection :<br />
<b>"69.50.*.*"<br />
"69.31.*.*"<br />
"66.235.*.*"<br />
"66.230.*.*"<br />
"216.239.*.*"<br />
"205.188.*.*"<br />
"205.177.*.*"<br />
"195.225.*.*"<br />
"216.195.*.*"<br />
"82.179.*.*"<br />
"81.95.*.*"<br />
"70.84.*.*"<br />
"195.95.*.*"<br />
"194.187.*.*"<br />
"78.129.158.*"<br />
"78.129.166.*"<br />
"89.149.226.*"<br />
"195.93.218.*"<br />
"72.21.53.*<br />
"81.9.3.*"<br />
"213.189.27.*"<br />
"88.255.74.*"<br />
"79.143.178.*"<br />
"202.71.102.*"<br />
"64.202.189.170"<br />
"217.170.77.150"</b><br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
The second hardcoded trusted IP is also responding to :<br />
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHf8FAKzs7I/AAAAAAAAB50/ZR2egkY7iLY/s1600-h/ie7_trusted_sites.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHf8FAKzs7I/AAAAAAAAB50/6CEouhwdlio/s200-R/ie7_trusted_sites.png" style="border: 0pt none ;" /></a><b>virusisolator .com<br />
virus-isolator .org<br />
virus-isolator .net<br />
soft-collections .com<br />
viruswebprotect .com<br />
virus-isolator .us<br />
codecvideo2008-18 .com<br />
sextubecodec55 .com<br />
sextubecodec67 .com<br />
soft-archives .com<br />
soft-collections .com<br />
codecreviews .com<br />
codecvideo2008-18 .com</b><br />
<br />
Such practices leave a great deal of malicious creativity, for instance, once rented a botnet's already infected malware PCs could start trusting the majority of sites in their scammy ecosystem. What's great is that by doing this they expose their affiliations with these affiliate based rogue security software programs, next to their infrastructure on which they may be that easily claiming ownership.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sBfhZJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sBfhZJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sLbEyJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sLbEyJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4lt2Sj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4lt2Sj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ds4Mej"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ds4Mej" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pPLe4J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pPLe4J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hYS1aJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hYS1aJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MqymEj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MqymEj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/333145852" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 11 Jul 2008 15:39:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/smitfraud">smitfraud</category>
      <category domain="http://securityratty.com/tag/smitfraud infection">smitfraud infection</category>
      <category domain="http://securityratty.com/tag/successful malware infection">successful malware infection</category>
      <category domain="http://securityratty.com/tag/sacrifice operational security">sacrifice operational security</category>
      <category domain="http://securityratty.com/tag/operational security">operational security</category>
      <category domain="http://securityratty.com/tag/malware pcs">malware pcs</category>
      <category domain="http://securityratty.com/tag/infamous smitfraud">infamous smitfraud</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/333145852/violating-opsec-for-increasing.html">Violating OPSEC for Increasing the Probability of Malware Infection</source>
    </item>
    <item>
      <title><![CDATA[Mobile Malware Scam iSexPlayer Wants Your Money]]></title>
      <link>http://securityratty.com/article/2e181320354dd6dbef7263b149510ae5</link>
      <guid>http://securityratty.com/article/2e181320354dd6dbef7263b149510ae5</guid>
      <description><![CDATA[A bogus media player ( iSexPlayer.jar ) targeting Symbian S60 3rd edition devices according to several affected parties, is currently being spammed through blackhat search engine optimization. Once...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp3.blogger.com/_wICHhTiQmrA/SHPPpaT5DsI/AAAAAAAAB4s/DzzzoRm7qQw/s1600-h/iSexPlayer.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SHPPpaT5DsI/AAAAAAAAB4s/RrF0dGd28i8/s200-R/iSexPlayer.png" style="border: 0pt none ;" /></a>A bogus media player (<b>iSexPlayer.jar</b>) targeting Symbian S60 3rd edition devices according to several affected parties, is currently being spammed through blackhat search engine optimization. Once infected upon confirming its execution since it's doesn't seem to be exploiting a specific vulnerability besides "bargain hunters" desire for free adult material, the malware attempts to trick the user into participating by becoming a member, however, a quick peek the source code reveals interesting facts about the scam.<br />
<br />
For instance, once providing them with your credit card details and basically wanting  to try out the service, it appears that there's no way out of it which is a problem since "<b>Trial membership recur at $US 29.95 unless cancelled, Monthly membership recur unless cancelled</b>" and also, "<b>Do you want full access to all pictures and videos? Cost is 2 Euros, charged 100% descreet on your phone bill over SMS. Please allow iSexPlayer to send SMS</b>".<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHPXAdxKXSI/AAAAAAAAB40/lx0NNyGF8DU/s1600-h/iSexPlayer_Malware_Dialer1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHPXAdxKXSI/AAAAAAAAB40/G-ed7CKFn3g/s200-R/iSexPlayer_Malware_Dialer1.JPG" style="border: 0pt none ;" /></a>The spammed through blackhat SEO sites are currently active, and perhaps a bit ironic, once you make any transaction with these people, anything that goes on at a later stage such as automatic calling or sms-sing to squeeze your bill, may be in fact legal since you authorized it. <br />
<br />
<a href="http://www.symbian-freak.com/news/008/07/first_known_s60_3rd_ed_malware.htm">Symbian Freak</a> has some details, as well as <a href="http://www.esato.com/board/viewtopic.php?topic=171238">an affected party</a> :<br />
<br />
"<i>Last week, I had lend my N73 to one of my friends for use as he had lost his phone. <b>I did not know what he did, but I checked my bills today and see some International calls made that amount to around 20USD. That is around 800 Indian rupees</b>. To check, I called the number and learnt that it was a phone sex line. Now it was time for my friend to answer. <b>The thirteen calls were made during a period spanning two days. On an average there were 7 calls a day.</b> <b>Now, the thing that struck me is, going by the call records, the calls on the second day were made when I had the phone with me</b>. I am pretty sure no one dialled the numbers. I called my buddy and asked him if he had downloaded something. He then spilled the beans informing that he did go to some adult website and installed a software (I do not recall the name).</i>"<br />
<br />
<a href="http://bp2.blogger.com/_wICHhTiQmrA/SHPXMcq4MwI/AAAAAAAAB48/xflFOsg6ETM/s1600-h/iSexPlayer_Malware_Dialer2.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SHPXMcq4MwI/AAAAAAAAB48/bwX9gzwKouA/s200-R/iSexPlayer_Malware_Dialer2.JPG" style="border: 0pt none ;" /></a>The name of the "software" as I've already pointed out is iSexPlayer. Let's dissect the scammers and their sites currently spammed across 100,000 sites using blackhat SEO tactics. Related domains sharing the same IP and internal pages :<br />
<br />
<b>3g6.se<br />
3gx.se<br />
conn2.3g6.se<br />
conn2.3g6.se<br />
test.3gx.se</b><br />
<br />
83.241.194.132 (83.241.194.128-83.241.194.191 DGC-DIRECT2-01 Direct2Internet AB - Internet Access Located in Johanneshov, Sweden)<br />
<br />
<b>3g6.se/dstream.php<br />
3g6.se/newplayerdl.php<br />
3g6.se/chrono/callback.php<br />
secure.chronopay.com/index.cgi</b><br />
<br />
The scammer's pitch :<br />
<br />
"<i>Free access to: - 500 Hardcore scenes - 100 Full lenght movies - Picture galleries Important! To install iSexplayer you must be at least 18 years old. You must install and run iSexplayer™ access module to watch the videos on Nintendo DS, You must install and run iSexplayer™ access module to watch the videos on Apple iPhone, Install iSexplayer</i>"<br />
<br />
Upon attempting to download the .jar file from the mobile page, the iSexPlayer.php does the magic like that :<br />
<br />
"<i>MIDlet-1: iSexPlayer,/icon.png,Easyloader<br />
MIDlet-Install-Notify: http://3g6.se/install_notify.php?id=1322451<br />
MIDlet-Jar-Size: 101313<br />
MIDlet-Jar-URL: http://3g6.se/iSexPlayer.jar<br />
MIDlet-Name: iSexPlayer<br />
MIDlet-Vendor: Vendor<br />
MIDlet-Version: 1.0<br />
MicroEdition-Configuration: CLDC-1.0<br />
MicroEdition-Profile: MIDP-2.0<br />
did: 1322451<br />
did2: 9416755</i>"<br />
<br />
Who's behind the scam?<br />
<br />
"<i>c_javax_microedition_lcdui_Form_fld.append("\ni<b>SexPlayer is owned by</b>: ");</i><br />
<i>c_javax_microedition_lcdui_Form_fld.append("\n<b>Enit Invest S.L</b>. ");&nbsp;</i><br />
<i>c_javax_microedition_lcdui_Form_fld.append("\nweb: <b>enitinvest.com</b> ");</i><br />
<i>c_javax_microedition_lcdui_Form_fld.append("\nemail: <b>support@enitinvest.com</b> ");</i><br />
<i>c_javax_microedition_lcdui_Form_fld.append("\nTel: <b>1-800-845-4951</b> ");</i>"<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
Enit Invest S.L.<br />
Av. Machupichu 26, S 18<br />
28043 Madrid<br />
email: support@enitinvest.com<br />
Tel: 1-800-845-4951<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHPjWZtvpNI/AAAAAAAAB5E/GCSyEOFBiOA/s1600-h/iSexPlayer_Malware_Dialer3.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHPjWZtvpNI/AAAAAAAAB5E/82001n4Xv0U/s200-R/iSexPlayer_Malware_Dialer3.JPG" style="border: 0pt none ;" /></a>And since I'm sure that there are more juicy details within the source code further exposing their scammy practices, which you should not authorize in any way, just like you wouldn't really like making a long call on a premium rate number thanks to having a malware infected phone, once more details are gathered, particularly its compatibility with devices, they'll be posted.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wedKOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wedKOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UmSuCJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UmSuCJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VJW47j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VJW47j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fmvyWj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fmvyWj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GPevnJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GPevnJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dDH6aJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dDH6aJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Yi9JAj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Yi9JAj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/330746890" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 03:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/isexplayer">isexplayer</category>
      <category domain="http://securityratty.com/tag/install">install</category>
      <category domain="http://securityratty.com/tag/install isexplayer">install isexplayer</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/internet access">internet access</category>
      <category domain="http://securityratty.com/tag/isexplayer access module">isexplayer access module</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/blackhat seo sites">blackhat seo sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/330746890/mobile-malware-scam-isexplayer-wants.html">Mobile Malware Scam iSexPlayer Wants Your Money</source>
    </item>
    <item>
      <title><![CDATA[Fake Celebrity Video Sites Serving Malware]]></title>
      <link>http://securityratty.com/article/e6b6b6bb079e0140b924b302a0f75bb8</link>
      <guid>http://securityratty.com/article/e6b6b6bb079e0140b924b302a0f75bb8</guid>
      <description><![CDATA[With blackhat search engine optimization tactics clearly converging with social engineering , the result of which is the increasing supply of Zlob malware variants served as fake codecs, it's about...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/SFuPgUZ-1iI/AAAAAAAABz0/CfFQY0pYbO4/s1600-h/fake_celebrity_sites_malware1.JPG"><img id="BLOGGER_PHOTO_ID_5213918779007751714" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/SFuPgUZ-1iI/AAAAAAAABz0/CfFQY0pYbO4/s200/fake_celebrity_sites_malware1.JPG" border="0" /></a>With <a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">blackhat search engine optimization tactics clearly converging with social engineering</a>, the result of which is the increasing supply of Zlob malware variants served as fake codecs, it's about time we spill some coffee on several campaigns in order to get a better understanding of the way the campaigns function.<br /><div><br />These campaigns are also starting to get so sophisticated, that analyzing a single one will expose another massive SQL injection, reveal several blackhat SEO domain farms, let you obtain fresh Zlob malware variants, and point you to the very latest and undetected rogue software if you manage to expose the entire scammy ecosystem through all the redirections put in place to make it harder to get to the bottom of it.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFuTjKmVT2I/AAAAAAAAB0M/uoqsc9RfJNU/s1600-h/fake_celebrity_sites_malware2.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFuTjKmVT2I/AAAAAAAAB0M/uoqsc9RfJNU/s200/fake_celebrity_sites_malware2.JPG" alt="" id="BLOGGER_PHOTO_ID_5213923225961320290" border="0" /></a>What's important to keep in mind when assessing and shutting down such comprehensive campaigns is that on the majority of occassions the front end domains as well as the secondary ones are all attempting to download the codecs from hardcoded locations. Consequently, you have 50 front end domains and another 50 as secondary redirection points all attempting to download the codecs from 3 download locations. Once again, the malware authors efficiency centered mentality emphasising on the easy of management for the campaign is making it possible to.<br /><br /><div>Here's are some currently active fake celebrity video sites serving malware including the codec redirectors :<br /><br /><a href="http://bp3.blogger.com/_wICHhTiQmrA/SFuQGWDNAzI/AAAAAAAABz8/V4kNHEWuR0A/s1600-h/fake_celebrity_sites_malware.JPG"><img id="BLOGGER_PHOTO_ID_5213919432284111666" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SFuQGWDNAzI/AAAAAAAABz8/V4kNHEWuR0A/s200/fake_celebrity_sites_malware.JPG" border="0" /></a><span style="font-weight: bold;">stillnaked.net</span> <span style="font-weight: bold;"><br />funkytube.net</span><br /><span style="font-weight: bold;">starvid.info</span> <span style="font-weight: bold;"><br />yetmorefun.net</span> <span style="font-weight: bold;"><br />hotnudity.net</span> <span style="font-weight: bold;"><br />alreadynude.com</span> <span style="font-weight: bold;"><br />celebvids.info</span> <span style="font-weight: bold;"><br />sexystar.name</span> <span style="font-weight: bold;"><br />hotserved.net</span> <span style="font-weight: bold;"><br />thestars2008.com</span><br /><span style="font-weight: bold;">nudde.net</span> <span style="font-weight: bold;"><br />gottabigfuick.com</span> <span style="font-weight: bold;"><br />moviecity.se</span> <span style="font-weight: bold;"><br />gossip-starz.com</span> <span style="font-weight: bold;"><br />tmz-video.com</span><br /><span style="font-weight: bold;">js0.info</span> <span style="font-weight: bold;"><br />superfakamyvideo.com</span> <span style="font-weight: bold;"><br />hdavidz.com</span> <span style="font-weight: bold;"><br /></span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SFuRy8PMNtI/AAAAAAAAB0E/qBrd4frSeM0/s1600-h/thestars2008_com_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SFuRy8PMNtI/AAAAAAAAB0E/qBrd4frSeM0/s200/thestars2008_com_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5213921297960810194" border="0" /></a><span style="font-weight: bold;">blog-x.in</span> <span style="font-weight: bold;"><br /></span><span style="font-weight: bold;">tmz-video.com</span> <span style="font-weight: bold;"><br />newhotpeople.com</span> <span style="font-weight: bold;"><br />dirty-gossips.com</span> <span style="font-weight: bold;"><br />flaxxvid.com</span> <span style="font-weight: bold;"><br />videoid.info</span> <span style="font-weight: bold;"><br />realvideofree.com</span> <span style="font-weight: bold;"><br />yetmorefun.net</span> <span style="font-weight: bold;"><br />popvids.info<br />ihavewetfuckpussy.com<br /></span><span style="font-weight: bold;">virus-scanonline.com</span> <span style="font-weight: bold;"><br />adultx2008.com</span><br /><span style="font-weight: bold;">lux-software2008.com</span><br /><br />As well as some sample subdomains for traffic acquisition purposes, since all of these have already been crawled by search engines :<br /><br /><span style="font-weight: bold;">jodie.popvids.info</span> <span style="font-weight: bold;"><br />jessica.popvids.info</span> <span style="font-weight: bold;"><br />tila.popvids.info</span><br /><span style="font-weight: bold;">paris.celebvids.info</span> <span style="font-weight: bold;"><br />vanessa.celebvids.info</span> <span style="font-weight: bold;"><br />britney.nudde.net</span> <span style="font-weight: bold;"><br />paris.nudde.net</span> <span style="font-weight: bold;"><br />kardashian.nudde.net</span> <span style="font-weight: bold;"><br />vanessahudgens.yetmorefun.net</span> <span style="font-weight: bold;"><br />lindsaylohan.yetmorefun.net</span> <span style="font-weight: bold;"><br />britneyspears.yetmorefun.net</span> <span style="font-weight: bold;"><br />parishilton.yetmorefun.net</span> <span style="font-weight: bold;"><br />kardashian.nudde.net</span><br /><br />We also have embedded IFRAMEs and as well as injected ones into vulnerable sites, acting as redirectors to some of these fake video sites. For instance, at the <span style="font-weight: bold;">pedophilesexstories.blog.com</span> we have an injected redirector - <span style="font-weight: bold;">js0.info/?s=16&amp;k=pedophile+sex+stories&amp;c=5</span> and <span style="font-weight: bold;">js0.info</span> itself is a blackhat SEO operation that's aggregating generic search traffic like this :<br /><br /><span style="font-weight: bold;">js0.info/16/5/ragnarok+hentai</span> <span style="font-weight: bold;"><br />js0.info/15/4/antivirus+characteristic</span><br /><span style="font-weight: bold;">js0.info/16/5/msn+monkey</span><br /><span style="font-weight: bold;">js0.info/15/4/airplus+internet+security</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SFuW_npeNMI/AAAAAAAAB0U/aqnVPUbVWjc/s1600-h/malicious_redirector_script.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SFuW_npeNMI/AAAAAAAAB0U/aqnVPUbVWjc/s200/malicious_redirector_script.JPG" alt="" id="BLOGGER_PHOTO_ID_5213927013330334914" border="0" /></a>Once accessed, you get redirected to through <a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">two separate redirection campaigns</a> at <span style="font-weight: bold;">searchaw.info/sa/in.cgi?16</span>; and <span style="font-weight: bold;">hmel.info/stds13/go.php</span>, until you finally get to the codecs.<br /><br />With blackhat SEO-ers already well developed inventory of topical junk content, and experience in what's popular content and what's not,  the entry barriers for malware authors into the traffic acquisition joys of blackhat SEO has never lower.<br /></div></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WOphoI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WOphoI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W1jLhI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W1jLhI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PO1pbi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PO1pbi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=b0ILEi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=b0ILEi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HEkGpI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HEkGpI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vnYhGI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vnYhGI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1X0RPi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1X0RPi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/316164970" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 20 Jun 2008 02:58:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/blackhat seo-ers">blackhat seo-ers</category>
      <category domain="http://securityratty.com/tag/blackhat seo">blackhat seo</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware authors efficiency">malware authors efficiency</category>
      <category domain="http://securityratty.com/tag/blackhat seo operation">blackhat seo operation</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <category domain="http://securityratty.com/tag/blackhat">blackhat</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/316164970/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</source>
    </item>
    <item>
      <title><![CDATA[Malicious Doorways Redirecting to Malware]]></title>
      <link>http://securityratty.com/article/fe7f4960d26a3758a81dc861f894e098</link>
      <guid>http://securityratty.com/article/fe7f4960d26a3758a81dc861f894e098</guid>
      <description><![CDATA[Blacklisting malicious sites in times when legitimate ones are starting to compete with bogus .info and .biz ones for the leading position of hosting and serving malicious content, is a bit of an...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SFUBnTCFkwI/AAAAAAAABzE/90Gdkzc04f8/s1600-h/bestxvids_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SFUBnTCFkwI/AAAAAAAABzE/90Gdkzc04f8/s200/bestxvids_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5212073918386770690" border="0" /></a>Blacklisting malicious sites in times when legitimate ones are starting to compete with bogus .info and .biz ones for the leading position of hosting and serving malicious content, is a bit of an outdated and reactive approach for protecting against unknown threats. However, a single malicious domain whose live exploits can be easily detected and consequently blocked, is often just a front end to a large domains portfolio whose malicious content may easily pass through web filtering and on-the-fly malware attempts. Even worse, a malicious domain often exists in multiple "alternate realities" since a single IP is hosting many other unique and related malware domains.<br /><br />In this post, I'll assess <a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">a misconfigured malicious doorway</a>, that is redirecting to ten different malware sites <a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">serving Zlob variants by delivering fake codecs</a> that all the bogus adult sites require. The doorway is misconfigured in the sense of not recording the IP and checking the cookie set, in comparrision to every average web malware exploitation kit out there, which will not serve anything malicious when accessed for a second time since it's hashing the IPs that accessed it already. This is just the tip of the iceberg when it comes to the emerging evasive approaches applied to make the analysis of such doorways a bit more time and resources consuming. In a single sentence - <span style="font-weight: bold;">there's evidence blackhat SEO-ers are starting to exchange crawling manipulation know-how with malware authors</span>.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SFUCCgpQO8I/AAAAAAAABzM/HU4eAtm8bwU/s1600-h/bestxvids_spyshredder_redirection.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SFUCCgpQO8I/AAAAAAAABzM/HU4eAtm8bwU/s200/bestxvids_spyshredder_redirection.JPG" alt="" id="BLOGGER_PHOTO_ID_5212074385897176002" border="0" /></a>In this example we have <span style="font-weight: bold;">bestxvids.info</span> (87.118.116.11)  which is reditecting to <span style="font-weight: bold;">all-in</span><span style="font-weight: bold;">dex.com/in.cgi?5</span> (87.118.116.11) a URL that's been actively spammed across forums and guestbooks vulnerable to automatic posting vulnerabilities (weak CAPTCHAs and web application vulnerabilities) which is then redirecting to the following fake codec domains on the fly, and since the redirection script isn't hashing my IP like the majority of well configured ones requiring the use of multiple IPs if we're to expose all the campaigns, it makes the investigation easier :<br /><br /><span style="font-weight: bold;">tubeuniverses.com/teen/index.php?id=1883</span> - (78.108.177.99)<br /><span style="font-weight: bold;">new-content-s2008.com/freemovie/938/0/</span> - (72.21.53.218)<br /><span style="font-weight: bold;">teens.0bucksforpornmovie.com/?id=4199</span> - (64.28.181.28)<br /><span style="font-weight: bold;">getadultaccess.com/movie/?aff=5310</span> - (200.63.46.84)<br /><span style="font-weight: bold;">hqtube.com/?7014000000</span> - (88.85.66.116)<br /><span style="font-weight: bold;">supersharebox.com/softw/?aff=5310&amp;saff=0</span> - (200.63.46.84)<br /><span style="font-weight: bold;">scanner.shredderscan.com/5/?advid=4329</span> - (92.241.182.13)<br /><span style="font-weight: bold;">myflydirect.com/1/5310/</span> - (200.63.46.84)<br /><span style="font-weight: bold;">getadultaccess.com/movie/?aff=5310</span> - (200.63.46.84)<br /><span style="font-weight: bold;">hotvidstube.com/teen/index.php?id=1883</span> - (78.108.177.99)<br /><span style="font-weight: bold;">2008-adult-2008.com/freemovie/938/0/</span> - (72.21.53.218)<br /><span style="font-weight: bold;">s-soft08freeware.com/download/502/938/0</span> - (91.203.70.18)<br /><br />Where's the "alternate reality"? All of the following fake codec and adult sites serving Zlob variants, with minor exceptions of course, are also responding to the main IP of the redirector - 87.118.116.11 :<br /><span style="font-weight: bold;"><br /></span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SFYov0Kh3HI/AAAAAAAABzc/70YINcLA_7E/s1600-h/porno_info_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SFYov0Kh3HI/AAAAAAAABzc/70YINcLA_7E/s200/porno_info_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5212398420649696370" border="0" /></a><span style="font-weight: bold;">carsfoto.ru</span> <span style="font-weight: bold;"><br />cheapest-pharmacy.com</span> <span style="font-weight: bold;"><br />coolsexmovies.net</span><br /><span style="font-weight: bold;">free-movie-xxx.net</span> <span style="font-weight: bold;"><br />gold-collection.biz</span> <span style="font-weight: bold;"><br />p-o-r-n-0.com</span> <span style="font-weight: bold;"><br />p-o-r-n-0.info</span> <span style="font-weight: bold;"><br />sexakaporn.com</span> <span style="font-weight: bold;"><br />stred.biz</span> <span style="font-weight: bold;"><br />stred.in</span> <span style="font-weight: bold;"><br />tosserhost.com</span> <span style="font-weight: bold;"><br />west-video-xxx.info</span> <span style="font-weight: bold;"><br />wowtofree.info</span><br /><br />Shall we also expose the entire scammy ecosystem of Zlob variants, as always, sharing the same netblocks in order to keep it simple? But of course :<br /><br /><span style="font-weight: bold;">porn-youtube08.net</span> <span style="font-weight: bold;"><br />sextubecodec55.com</span> <span style="font-weight: bold;"><br />2008adult2008.com</span><br /><span style="font-weight: bold;">adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />newcontent-s2008.com</span> <span style="font-weight: bold;"><br />adultxx-18.com</span> <span style="font-weight: bold;"><br />newcontents2008.com</span> <span style="font-weight: bold;"><br />onlinestreamvide.com</span> <span style="font-weight: bold;"><br />2008adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />newcontents2008.com</span><br /><span style="font-weight: bold;">hot-pornotube2008.com</span> <span style="font-weight: bold;"><br />adult-youtube-8.com</span> <span style="font-weight: bold;"><br /></span><span style="font-weight: bold;">2008adult-s2008.com</span> <span style="font-weight: bold;"><br />2008adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />adult-freetube-8.com</span><br /><span style="font-weight: bold;">adult18tube2008.com</span><br /><span style="font-weight: bold;">adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />free-porntube-8.com</span> <span style="font-weight: bold;"><br /></span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFVF_rdlslI/AAAAAAAABzU/Y6DIZmD5gxo/s1600-h/bestxvids_malware_domains.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFVF_rdlslI/AAAAAAAABzU/Y6DIZmD5gxo/s200/bestxvids_malware_domains.JPG" alt="" id="BLOGGER_PHOTO_ID_5212149104052122194" border="0" /></a><span style="font-weight: bold;">gt-funny.com    </span> <span style="font-weight: bold;"><br />gt-movies.com</span> <span style="font-weight: bold;"><br />gt-stars.com</span> <span style="font-weight: bold;"><br />hot-sextube.com    </span> <span style="font-weight: bold;"><br />new-content-s2008.com</span> <span style="font-weight: bold;"><br />newcontent-s2008.com</span> <span style="font-weight: bold;"><br />newcontents2008.com</span> <span style="font-weight: bold;"><br />onlinestreamvide.com    </span> <span style="font-weight: bold;"><br />porno-tube20008.com    </span> <span style="font-weight: bold;"><br />pornotube-20008.com        </span> <span style="font-weight: bold;"><br />pornotube20008.com</span> <span style="font-weight: bold;"><br />sex-18tube-2008.com</span><br /><span style="font-weight: bold;">sex-tube-20008.com</span> <span style="font-weight: bold;"><br />sex-tube20008.com</span> <span style="font-weight: bold;"><br />sex18tube2008.com</span> <span style="font-weight: bold;"><br />sexi18tube2008.com</span> <span style="font-weight: bold;"><br />sextube18adult.com</span> <span style="font-weight: bold;"><br />sextube20008.com    </span> <span style="font-weight: bold;"><br />streamadultvideo.com</span> <span style="font-weight: bold;"><br />xxxstreamonline.com</span><br /><br />The bottom line - malicious doorways are slowly starting to emerge thanks to the convergence of traffic redirection and management tools with web malware exploitation kits, and just like we've been seeing the adaptation of spamming tools and approaches for phishing purposes, next we're going to see the development of infrastructure management kits, a feature that <a href="http://ddanchev.blogspot.com/2008/05/diy-phishing-kits-introducing-new.html">DIY phishing kits</a> are starting to take into consideration as well.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8oWxkI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8oWxkI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CSGETI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CSGETI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BOEE6i"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BOEE6i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fIFwTi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fIFwTi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vk30nI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vk30nI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DPXX6I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DPXX6I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=x8rEEi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=x8rEEi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/312884606" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 15 Jun 2008 23:51:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/doorways">doorways</category>
      <category domain="http://securityratty.com/tag/malicious doorways">malicious doorways</category>
      <category domain="http://securityratty.com/tag/malicious content">malicious content</category>
      <category domain="http://securityratty.com/tag/single sentence">single sentence</category>
      <category domain="http://securityratty.com/tag/single">single</category>
      <category domain="http://securityratty.com/tag/single malicious domain">single malicious domain</category>
      <category domain="http://securityratty.com/tag/doorway">doorway</category>
      <category domain="http://securityratty.com/tag/malicious doorway">malicious doorway</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/312884606/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</source>
    </item>
    <item>
      <title><![CDATA[Fake Yahoo Greetings Malware Campaign Circulating]]></title>
      <link>http://securityratty.com/article/98394f8647f39640dd8f329684f01992</link>
      <guid>http://securityratty.com/article/98394f8647f39640dd8f329684f01992</guid>
      <description><![CDATA[The persistence of certain botnet masters cannot remain unnoticed even if you're used to going through over a dozen active malware campaigns per day, in this case it's their persistence that makes...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/SAZWvmORGaI/AAAAAAAABkg/vlOBQ_RCWOw/s1600-h/yahoo_greetings_malware_campaign.jpg"><img id="BLOGGER_PHOTO_ID_5189930996305303970" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SAZWvmORGaI/AAAAAAAABkg/vlOBQ_RCWOw/s200/yahoo_greetings_malware_campaign.jpg" border="0" /></a>The persistence of certain botnet masters cannot remain unnoticed even if you're used to going through over a dozen active malware campaigns per day, in this case it's their persistence that makes them worth assessing and profiling. <a href="http://ddanchev.blogspot.com/2008/02/inside-botnets-phishing-activities.html">The botnet which I assesed in February</a>, the one that was crunching out phishing emails and using the infected hosts for hosting the pages, and parking the phishing domains, is still operational this time starting a fake Yahoo Greetings malware campaign by spamming the cybersquatted domains and enticing the user into updating their flash player with a copy of Backdoor.Agent.AJU.<br /><br />Upon visiting <strong>www4.yahoo.american-greeting.com.tag38.com/ecards/view.pd.htm</strong> it redirects to <strong>www3.yahoo.americangreetings.com.id759.com/ecards/view.pd.htm</strong><br /><br /><strong>id759.com</strong> is currently responding to <strong>24.161.232.218; 24.192.140.204; 68.36.236.67; 76.230.108.105; 83.5.203.163; 85.109.42.164; 216.170.109.206</strong> and also to <strong>set45.net</strong>; <strong>service28.biz</strong>; <strong>setup36.com</strong> and serves the Backdoor.Agent :<br /><br /><strong>www3.yahoo.americangreetings.com.id759.com/ecards/get_new_flashplayer .exe</strong><br /><br />Scanners Result : 12/31 (38.71%)<br />Suspicious:W32/Malware!Gemini; W32/Agent.Q.gen!Eldorado<br />File size: 44544 bytes<br />MD5...: fe97eb8c0518005075fd638b33d5b165<br />SHA1..: d7a4258e37ce0dab0f7d770d1a9d979e921be07b<br />SHA256: 138d31ae1bbdec215d980c7b57be6e624c2f2e1cacd3934b77f50be8adabfb97<br /><br />"<em>Backdoor.Agent.AJU is a malicious backdoor trojan that is capable to run and open random TCP port in a multiple instances attempting to connect to its predefined public SMTP servers. It then spams itself in email with a file attached in zip and password protected format. Furthermore, the password is included in the body of the email.</em>"<br /><br /><strong>tag38.com</strong> is responding to <strong>211.142.23.21</strong>, and is a part of a scammy ecosystem of other phishing and malware related domains responding to the same IP. And these are the related subdomains impersonating Yahoo Greetings within :<br /><br /><strong>american-greeting.ca.xml52.com</strong><br /><strong>www5.yahoo.american-greeting.ca.xml52.com</strong><br /><strong>www9.yahoo.americangreeting.ca.www05.net</strong><br /><strong>yahoo.americangreetings.com.droeang.net</strong><br /><strong>yahoo.americangreetings.com.s8a1.psmtp.com</strong><br /><strong>yahoo.americangreetings.com.s8a2.psmtp.com</strong><br /><strong>yahoo.americangreetings.com.s8b1.psmtp.com</strong><br /><strong>yahoo.americangreetings.com.s8b2.psmtp.com</strong><br /><strong>yahoo.americangreetings.droeang.net</strong><br /><strong>yahoo.americangreeting.ca.www05.net</strong><br /><strong>www6.yahoo.american-greetings.com.www05.net</strong><br /><br />What you see when in a hurry is not what you get when you got time to look at it twice. This and the previous campaign launched by the same party is a great example of risk and responsibility forwarding, in this case to the infected party, so what used to be a situation where an infected host was sending spamming and phishing emails only, is today's malicious hosting infrastructure on demand.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PovknFG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PovknFG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IzPjd8G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IzPjd8G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cCTfbcg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cCTfbcg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZMmXs1g"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZMmXs1g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2fTFppG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2fTFppG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UubKf1G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UubKf1G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fMCLMrg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fMCLMrg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/271673133" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 16 Apr 2008 11:21:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/yahoo">yahoo</category>
      <category domain="http://securityratty.com/tag/fake yahoo">fake yahoo</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/malicious backdoor trojan">malicious backdoor trojan</category>
      <category domain="http://securityratty.com/tag/backdoor">backdoor</category>
      <category domain="http://securityratty.com/tag/malware campaign">malware campaign</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/active malware campaigns">active malware campaigns</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/271673133/fake-yahoo-greetings-malware-campaign.html">Fake Yahoo Greetings Malware Campaign Circulating</source>
    </item>
  </channel>
</rss>
