<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sex]]></title>
    <link>http://securityratty.com/tag/sex</link>
    <description></description>
    <pubDate>Sun, 15 Jun 2008 23:51:11 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[MySpace, Facebook show tools to ward off child predators]]></title>
      <link>http://securityratty.com/article/3b99ddfd1e988afdbfdd259b5671e6fe</link>
      <guid>http://securityratty.com/article/3b99ddfd1e988afdbfdd259b5671e6fe</guid>
      <description><![CDATA[MySpace is using technology to analyze whether potential users trying to sign up for the social network may be registered sex offenders, the company's chief security officer said...]]></description>
      <content:encoded><![CDATA[MySpace is using technology to analyze whether potential users trying to sign up for the social network may be registered sex offenders, the company's chief security officer said Wednesday.]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/chief security officer">chief security officer</category>
      <category domain="http://securityratty.com/tag/social network">social network</category>
      <category domain="http://securityratty.com/tag/potential users">potential users</category>
      <category domain="http://securityratty.com/tag/sex offenders">sex offenders</category>
      <category domain="http://securityratty.com/tag/myspace">myspace</category>
      <category domain="http://securityratty.com/tag/analyze">analyze</category>
      <category domain="http://securityratty.com/tag/wednesday">wednesday</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <source url="http://www.networkworld.com/news/2008/092408-myspace-facebook-show-tools-to.html?fsrc=rss-security">MySpace, Facebook show tools to ward off child predators</source>
    </item>
    <item>
      <title><![CDATA[Fake Sex Scandal Spam Campaign Involving Barack Obama Spreads Malware]]></title>
      <link>http://securityratty.com/article/7ce95483b16e4bb114531f1eaca12924</link>
      <guid>http://securityratty.com/article/7ce95483b16e4bb114531f1eaca12924</guid>
      <description><![CDATA[Websense Security Labs reports a new spam campaign that uses the US presidential election as a social engineering mechanism to install information-stealing code on a victims machine. Emails are...]]></description>
      <content:encoded><![CDATA[Websense Security Labs reports a new spam campaign that uses the US presidential election as a social engineering mechanism to install information-stealing code on a victim&#8217;s machine. Emails are circulating with fake news of a sex scandal affecting one of the candidates. Recipients of the email are encouraged to view a video supposedly involving the [...]]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 15:17:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam campaign">spam campaign</category>
      <category domain="http://securityratty.com/tag/sex scandal">sex scandal</category>
      <category domain="http://securityratty.com/tag/victims machine">victims machine</category>
      <category domain="http://securityratty.com/tag/presidential election">presidential election</category>
      <category domain="http://securityratty.com/tag/video supposedly">video supposedly</category>
      <category domain="http://securityratty.com/tag/fake news">fake news</category>
      <category domain="http://securityratty.com/tag/mechanism">mechanism</category>
      <category domain="http://securityratty.com/tag/install">install</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <source url="http://cyberinsecure.com/fake-sex-scandal-spam-campaign-involving-barack-obama-spreads-malware/">Fake Sex Scandal Spam Campaign Involving Barack Obama Spreads Malware</source>
    </item>
    <item>
      <title><![CDATA[Malware Lurks Behind Obama Sex Video Spam]]></title>
      <link>http://securityratty.com/article/4362a119fa1aba083732a697fc756cfd</link>
      <guid>http://securityratty.com/article/4362a119fa1aba083732a697fc756cfd</guid>
      <description><![CDATA[The latest e-mail spam infecting computers with malware is one that purports to have a pornographic video of Sen. Barack Obama having sex with Ukrainian girls. The video is so good that those watching...]]></description>
      <content:encoded><![CDATA[The latest e-mail spam infecting computers with malware is one that purports to have a pornographic video of Sen. Barack Obama having sex with Ukrainian girls. The video is so good that those watching it get screwed. The video unleashes a trojan and those watching the video get their data hijacked to Finland.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=fe1cf8d8ce3866c7f6b891e766b77484"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=fe1cf8d8ce3866c7f6b891e766b77484"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=fe1cf8d8ce3866c7f6b891e766b77484" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=RTPCL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=RTPCL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=C33dl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=C33dl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=rwVjl"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=rwVjl" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=LSoPL"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=LSoPL" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=HC6bL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=HC6bL" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=oRlKl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=oRlKl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=sWtnl"><img src="http://feeds.wired.com/~f/wired/politics/security?i=sWtnl" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=QpjyL"><img src="http://feeds.wired.com/~f/wired/politics/security?i=QpjyL" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/388014315" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/388014319" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 09 Sep 2008 14:56:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/pornographic video">pornographic video</category>
      <category domain="http://securityratty.com/tag/video unleashes">video unleashes</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/ukrainian girls">ukrainian girls</category>
      <category domain="http://securityratty.com/tag/barack obama">barack obama</category>
      <category domain="http://securityratty.com/tag/sex">sex</category>
      <category domain="http://securityratty.com/tag/e-mail spam">e-mail spam</category>
      <category domain="http://securityratty.com/tag/trojan">trojan</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/388014319/barack-obama-se.html">Malware Lurks Behind Obama Sex Video Spam</source>
    </item>
    <item>
      <title><![CDATA[In the News: Cloudburst, Black Hat Hack, Sex Drugs and Software]]></title>
      <link>http://securityratty.com/article/b824c0b40977a0631cff5e27a56d12b5</link>
      <guid>http://securityratty.com/article/b824c0b40977a0631cff5e27a56d12b5</guid>
      <description><![CDATA[Forget Your Password! Think your online passwords are secure? Think again. Not long ago, author Herbert H. Thompson asked some of his friends for their permission to let him break into their...]]></description>
      <content:encoded><![CDATA[Forget Your Password!&nbsp;Think your online passwords are secure? Think again. Not long ago, author Herbert H. Thompson asked some of his friends for their permission to let him break into their onli...]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 10:06:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/online passwords">online passwords</category>
      <category domain="http://securityratty.com/tag/author herbert">author herbert</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <category domain="http://securityratty.com/tag/permission">permission</category>
      <category domain="http://securityratty.com/tag/thompson">thompson</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/ago">ago</category>
      <category domain="http://securityratty.com/tag/onli">onli</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/382697978/">In the News: Cloudburst, Black Hat Hack, Sex Drugs and Software</source>
    </item>
    <item>
      <title><![CDATA[Hacker Sentenced to Two Years For MySpace Cyber Stalking]]></title>
      <link>http://securityratty.com/article/c9e890c52b58f1f80575cb3cfaab86fc</link>
      <guid>http://securityratty.com/article/c9e890c52b58f1f80575cb3cfaab86fc</guid>
      <description><![CDATA[Jeffrey Robert Weinberg, aka V.I.P., is shipped off to a California state prison after being arrested for allegedly trying to extort phone sex from a teenage internet video...]]></description>
      <content:encoded><![CDATA[Jeffrey Robert Weinberg, aka V.I.P., is shipped off to a California state prison after being arrested for allegedly trying to extort phone sex from a teenage internet video star.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=3ae43f0286572cf0a9a250e19aedac54" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=3ae43f0286572cf0a9a250e19aedac54" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=ckJTzJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=ckJTzJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=FY1wGj"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=FY1wGj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=AxXe0j"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=AxXe0j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=unxWmJ"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=unxWmJ" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=ia2QcJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=ia2QcJ" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=pj4fJj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=pj4fJj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=6WOYSj"><img src="http://feeds.wired.com/~f/wired/politics/security?i=6WOYSj" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=b43TXJ"><img src="http://feeds.wired.com/~f/wired/politics/security?i=b43TXJ" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/332155448" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/332155453" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 17:48:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/extort phone sex">extort phone sex</category>
      <category domain="http://securityratty.com/tag/jeffrey robert weinberg">jeffrey robert weinberg</category>
      <category domain="http://securityratty.com/tag/california">california</category>
      <category domain="http://securityratty.com/tag/prison">prison</category>
      <category domain="http://securityratty.com/tag/aka">aka</category>
      <category domain="http://securityratty.com/tag/allegedly">allegedly</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/332155453/accused-myspace.html">Hacker Sentenced to Two Years For MySpace Cyber Stalking</source>
    </item>
    <item>
      <title><![CDATA[Mobile Malware Scam iSexPlayer Wants Your Money]]></title>
      <link>http://securityratty.com/article/2e181320354dd6dbef7263b149510ae5</link>
      <guid>http://securityratty.com/article/2e181320354dd6dbef7263b149510ae5</guid>
      <description><![CDATA[A bogus media player ( iSexPlayer.jar ) targeting Symbian S60 3rd edition devices according to several affected parties, is currently being spammed through blackhat search engine optimization. Once...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp3.blogger.com/_wICHhTiQmrA/SHPPpaT5DsI/AAAAAAAAB4s/DzzzoRm7qQw/s1600-h/iSexPlayer.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SHPPpaT5DsI/AAAAAAAAB4s/RrF0dGd28i8/s200-R/iSexPlayer.png" style="border: 0pt none ;" /></a>A bogus media player (<b>iSexPlayer.jar</b>) targeting Symbian S60 3rd edition devices according to several affected parties, is currently being spammed through blackhat search engine optimization. Once infected upon confirming its execution since it's doesn't seem to be exploiting a specific vulnerability besides "bargain hunters" desire for free adult material, the malware attempts to trick the user into participating by becoming a member, however, a quick peek the source code reveals interesting facts about the scam.<br />
<br />
For instance, once providing them with your credit card details and basically wanting  to try out the service, it appears that there's no way out of it which is a problem since "<b>Trial membership recur at $US 29.95 unless cancelled, Monthly membership recur unless cancelled</b>" and also, "<b>Do you want full access to all pictures and videos? Cost is 2 Euros, charged 100% descreet on your phone bill over SMS. Please allow iSexPlayer to send SMS</b>".<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHPXAdxKXSI/AAAAAAAAB40/lx0NNyGF8DU/s1600-h/iSexPlayer_Malware_Dialer1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHPXAdxKXSI/AAAAAAAAB40/G-ed7CKFn3g/s200-R/iSexPlayer_Malware_Dialer1.JPG" style="border: 0pt none ;" /></a>The spammed through blackhat SEO sites are currently active, and perhaps a bit ironic, once you make any transaction with these people, anything that goes on at a later stage such as automatic calling or sms-sing to squeeze your bill, may be in fact legal since you authorized it. <br />
<br />
<a href="http://www.symbian-freak.com/news/008/07/first_known_s60_3rd_ed_malware.htm">Symbian Freak</a> has some details, as well as <a href="http://www.esato.com/board/viewtopic.php?topic=171238">an affected party</a> :<br />
<br />
"<i>Last week, I had lend my N73 to one of my friends for use as he had lost his phone. <b>I did not know what he did, but I checked my bills today and see some International calls made that amount to around 20USD. That is around 800 Indian rupees</b>. To check, I called the number and learnt that it was a phone sex line. Now it was time for my friend to answer. <b>The thirteen calls were made during a period spanning two days. On an average there were 7 calls a day.</b> <b>Now, the thing that struck me is, going by the call records, the calls on the second day were made when I had the phone with me</b>. I am pretty sure no one dialled the numbers. I called my buddy and asked him if he had downloaded something. He then spilled the beans informing that he did go to some adult website and installed a software (I do not recall the name).</i>"<br />
<br />
<a href="http://bp2.blogger.com/_wICHhTiQmrA/SHPXMcq4MwI/AAAAAAAAB48/xflFOsg6ETM/s1600-h/iSexPlayer_Malware_Dialer2.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SHPXMcq4MwI/AAAAAAAAB48/bwX9gzwKouA/s200-R/iSexPlayer_Malware_Dialer2.JPG" style="border: 0pt none ;" /></a>The name of the "software" as I've already pointed out is iSexPlayer. Let's dissect the scammers and their sites currently spammed across 100,000 sites using blackhat SEO tactics. Related domains sharing the same IP and internal pages :<br />
<br />
<b>3g6.se<br />
3gx.se<br />
conn2.3g6.se<br />
conn2.3g6.se<br />
test.3gx.se</b><br />
<br />
83.241.194.132 (83.241.194.128-83.241.194.191 DGC-DIRECT2-01 Direct2Internet AB - Internet Access Located in Johanneshov, Sweden)<br />
<br />
<b>3g6.se/dstream.php<br />
3g6.se/newplayerdl.php<br />
3g6.se/chrono/callback.php<br />
secure.chronopay.com/index.cgi</b><br />
<br />
The scammer's pitch :<br />
<br />
"<i>Free access to: - 500 Hardcore scenes - 100 Full lenght movies - Picture galleries Important! To install iSexplayer you must be at least 18 years old. You must install and run iSexplayer™ access module to watch the videos on Nintendo DS, You must install and run iSexplayer™ access module to watch the videos on Apple iPhone, Install iSexplayer</i>"<br />
<br />
Upon attempting to download the .jar file from the mobile page, the iSexPlayer.php does the magic like that :<br />
<br />
"<i>MIDlet-1: iSexPlayer,/icon.png,Easyloader<br />
MIDlet-Install-Notify: http://3g6.se/install_notify.php?id=1322451<br />
MIDlet-Jar-Size: 101313<br />
MIDlet-Jar-URL: http://3g6.se/iSexPlayer.jar<br />
MIDlet-Name: iSexPlayer<br />
MIDlet-Vendor: Vendor<br />
MIDlet-Version: 1.0<br />
MicroEdition-Configuration: CLDC-1.0<br />
MicroEdition-Profile: MIDP-2.0<br />
did: 1322451<br />
did2: 9416755</i>"<br />
<br />
Who's behind the scam?<br />
<br />
"<i>c_javax_microedition_lcdui_Form_fld.append("\ni<b>SexPlayer is owned by</b>: ");</i><br />
<i>c_javax_microedition_lcdui_Form_fld.append("\n<b>Enit Invest S.L</b>. ");&nbsp;</i><br />
<i>c_javax_microedition_lcdui_Form_fld.append("\nweb: <b>enitinvest.com</b> ");</i><br />
<i>c_javax_microedition_lcdui_Form_fld.append("\nemail: <b>support@enitinvest.com</b> ");</i><br />
<i>c_javax_microedition_lcdui_Form_fld.append("\nTel: <b>1-800-845-4951</b> ");</i>"<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
Enit Invest S.L.<br />
Av. Machupichu 26, S 18<br />
28043 Madrid<br />
email: support@enitinvest.com<br />
Tel: 1-800-845-4951<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHPjWZtvpNI/AAAAAAAAB5E/GCSyEOFBiOA/s1600-h/iSexPlayer_Malware_Dialer3.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHPjWZtvpNI/AAAAAAAAB5E/82001n4Xv0U/s200-R/iSexPlayer_Malware_Dialer3.JPG" style="border: 0pt none ;" /></a>And since I'm sure that there are more juicy details within the source code further exposing their scammy practices, which you should not authorize in any way, just like you wouldn't really like making a long call on a premium rate number thanks to having a malware infected phone, once more details are gathered, particularly its compatibility with devices, they'll be posted.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wedKOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wedKOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UmSuCJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UmSuCJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VJW47j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VJW47j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fmvyWj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fmvyWj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GPevnJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GPevnJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dDH6aJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dDH6aJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Yi9JAj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Yi9JAj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/330746890" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 03:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/isexplayer">isexplayer</category>
      <category domain="http://securityratty.com/tag/install">install</category>
      <category domain="http://securityratty.com/tag/install isexplayer">install isexplayer</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/internet access">internet access</category>
      <category domain="http://securityratty.com/tag/isexplayer access module">isexplayer access module</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/blackhat seo sites">blackhat seo sites</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/330746890/mobile-malware-scam-isexplayer-wants.html">Mobile Malware Scam iSexPlayer Wants Your Money</source>
    </item>
    <item>
      <title><![CDATA[Your 419 Mail Roundup]]></title>
      <link>http://securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</link>
      <guid>http://securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</guid>
      <description><![CDATA[Are you ready for more 419 missives

Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick &quot;Robert Mugabe&quot; themed mail and, er, someone called &quot;Captain Frank Bojo&quot;...]]></description>
      <content:encoded><![CDATA[
        Are you ready for more 419 missives?<br /><br />Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick "Robert Mugabe" themed mail and, er, someone called "Captain Frank Bojo" after the jump...<br /> 
        Subject:<br />HELLO DEAR<br />From:<br />"abavanagift13 Gazeta.pl" &lt;abavanagift13@gazeta.pl&gt;<br />Date:<br />Sat, 21 Jun 2008 12:26:24 +0000<br />BCC:<br /><br />Hello Dear,<br />&nbsp;<br />&nbsp;My name is Blessing Abavana, the elder daughter of Mr. paul Abavana of Zimbabwe, I am 17 years old with my younger brother (Micheal), we are in Ghana as refuge/asylum since we lost our parents because of the recent war that occurred in our country.please do go through this web page for better understanding with full details:<br />&nbsp;<br />&nbsp;http://www.rte.ie/news/2000/0418/zimbabwe.html<br />&nbsp;<br />&nbsp;I am looking for one&nbsp; who will honestly assist my younger brother and I to realize our inherited funds into your account and as well as invest it into a lucrative business.<br />&nbsp;<br />During the recent war against the farmers in Zimbabwe from the supporters of our President, Robert Mugabe to claim all the white -owned farms to his party members and his followers, he ordered all the white farmers to surrender all their farms to his party members and his followers.<br />&nbsp;<br />&nbsp;My father being one of the few rich and successful black farmers in our country was also victimized because of his opposition to Mugabe's policies. And because he did not support Mugabe's ideas, Mugabe's supporters invaded my father's farm and burnt everything in the farm, killed my father and made away with a lot of items in my father's farm. This action was taken because my late father felt the growing tension on the farm issue, but I guess he never anticipated the tragedy that brought their brutal and sudden death.<br />&nbsp;<br />&nbsp;However with the benefit of hindsight, owing to the looming but deteriorating crisis in my country, Zimbabwe, my father, before his unfortunate death deposited with International Commercial Bank (ICB) here in Accra Ghana the sum of US$ 35MUsd (Thirty Five Million United States Dollars), with the sole aim of acquiring and buying some dredging equipments in setting up of a dredging firm with his partner. With his death and all his assets seized at home and accounts frozen, the family is now in a very difficult situation.<br />&nbsp;<br />&nbsp;After the death of my father, my brother and I escaped to the Republic of Ghana where he had deposited the money in the Bank . And we were permitted to reside here as Political Refugees.<br />&nbsp;<br />&nbsp;So Because of our present and unpleasant status here we decided to contact an overseas firm / individual that can assist us to move this money out Of Ghana because, as asylum seekers, we are not allowed to operate any financial transaction of such amount within Ghana and also to assist in providing me and my brother a permanent residential permit in your country after the money must have been transferred to your account.<br />&nbsp;<br />We have agreed to offer you 30% of the total sum for your assistance, and the rest will be for my brother and I, to Invest in your country under your assistant<br />&nbsp;<br />All I want you to do is to furnish me with the below information including your readiness to assist me achieve this transaction for investment purposes in your country under your supervision. Kindly re-confirm to me the followings:<br /><br />1) Your Full Name:<br />2) Phone, Fax and Mobile<br />3) Profession, Age and Marital Status.<br />4) Nationality<br />&nbsp;<br />&nbsp;I have to re-assure you that this transaction is 100% risk free and should be treated with absolute confidentiality. All the vital documentation/certification that has to do with the origin of the fund is with me for the security reasons.And I will send them to you when we progress.And I guarantee you that this fund is not government fund, drug money, or from arms deals.<br />&nbsp;<br />&nbsp;I will detail you more about&nbsp; the bank&nbsp; immediately I receive your acceptance response. I hope this is the beginning of a prosperous relationship between us.Thanks and God bless you<br />&nbsp;<br />Regards<br /><br />Blessing/Micheal Abavana<br /><br /><b>(Wow, spectacularly sick. Not that we're expecting scammers to have any morals, of course).</b><br /><br />*********************************************************************************************<br /><br /><br />Subject:<br />Lycos Online Lottery Notification<br />From:<br />"LHOUTY MOHAMMED HASSANE" &lt;mhlhouty@menara.ma&gt;<br />Date:<br />Sun, 22 Jun 2008 02:42:53 -0000<br />BCC:<br /><br />LYCOS LOTTERY ONLINE<br />8th Floor<br />1 Stephen Street<br />London<br />W1T 1AL<br />&nbsp;<br />WINNING NOTIFICATION<br />This is to inform you that your email address has won the Lycos Lottery for the year 2008. your email has won you the sum of ?952,350.00 (Nine Hundred And Fifty Two Thousand, Three Hundred And Fifty pounds sterling).<br />You are advised to keep this notice confidential to avoid misinterpretation of funds and unauthorize claims, cheating or fraud.<br />To claim your funds please contact us with the information below.<br />Name: Dr. George Stevenson<br />Tel:+447031991681<br />Email:lycosclaimsdpt@gmail.com<br />&nbsp;<br />It is mandatory that you send us your full names, address, phone number,<br />age, sex and occupation to enable us arrange your claim.<br />&nbsp;<br />Note: Winners were selected through a computer ballot system drawn from Microsoft users from company and individual email addresse users. All winning must be claimed not later than 21 working days from the time of notification. After this date all unclaimed funds will be returned to European Union Treasury as unclaimed funds.<br />&nbsp;<br />Congratulations from mambers and staff of Lycos<br />Lhouty Mohammed Hassane.<br />Lycos Lottery Co-ordinator<br /><br /><b>(A "Lycos Lottery" and they're using a GMail address? Doh).</b><br /><br />*********************************************************************************************<br /><br />Subject:<br />Yukos Oil<br />From:<br />Mr. Timinskiy Vladimir &lt;grooves@bellnet.ca&gt;<br />Date:<br />Wed, 25 Jun 2008 5:38:17 -0400<br />To:<br />&lt;info@yukos.org&gt;<br /><br />I have a profiling amount in an excess of US$100.5M, which I seek you in accommodating for me. You will be rewarded with 4% .If intrested, please reply me for moredetails...&lt;tvlad4@gmail.com&gt;<br />Regards<br />Mr. Timinskiy Vladimir<br /><br /><b>(Short. Sweet. Pointlessly fake).</b><br /><br />*******************************************************************************<br /><br />Subject:<br />Immediate Release of Your FUND Via ATM CARD<br />From:<br />"Mr. Mark Louis" &lt;francois.lapeyronie@wanadoo.fr&gt;<br />Date:<br />Wed, 25 Jun 2008 01:45:09 -0700<br />To:<br />undisclosed-recipients:;<br /><br />SUBJECT: Immediate Release of Your FUND Via ATM CARD<br /><br />Attention: ATM Card Beneficiary,<br /><br />I wish to use this medium to inform you that your CONTRACT/INHERITANCE Paymen of USD$10,000,000.00 (Ten Million United States Dollars) from CENTRAL BANK<br />OF NIGERIA have been RELEASED and APPROVED for onward transfer to you via an ATM CARD which you will use to withdraw all the USD$10,000,000.00 in any<br />ATM SERVICE MACHINE in any part of the world, but the maximum you can withdraw in a day is USD$10,000.00 Only.<br /><br />We have mandated IBTC CHARTERED BANK PLC, to send you the ATM CARD and PIN NUMBER which you will use to withdraw all your USD$10 Million Dollars in<br />any ATM SERVICE MACHINE in any part of the world. You are therefore advice to contact the Head of ATM CARD Department of IBTC CHARTERED BANK PLC;<br /><br />Contact Person: Dr. Olu James<br />Office email address:&nbsp;&nbsp; pcfc_nigeria@yahoo.com<br />Private: +2347084501007<br />Office:018969906<br /><br />Tell Dr. Olu James that you received a message from the CENTRAL BANK OF NIGERIA. Instructing him to send you the ATM CARD and PIN NUMBER which you will use<br />to withdraw your USD$10 Million Dollars in any ATM SERVICE MACHINE in any part of the world, also send him your direct phone number and contact address<br />where you want him to send the ATM CARD and PIN NUMBER to you. We are very sorry for the plight you have gone through in the past years. Thanks for adhering to this instruction and once again accept our congratulations.<br /><br />Best Regards.<br />Mr. Mark Louis.<br />Executive Governor,<br /><br />Central Bank of Nigeria {CBN}.<br /><br /><b>(Ah, the old "Let's lure them in with the magical bank card" trick).</b><br /><br /><br />******************************************************************************************<br /><br />Subject:<br />CONTACT THE FEDEX COMPANY FOR YOUR FUNDS<br />From:<br />"SAMUEL DUNBAR" &lt;samuel_dunbar0013@ig.com.br&gt;<br />Date:<br />Fri, 20 Jun 2008 12:33:43 +0100<br />BCC:<br /><br />Dear Friend,<br /><br />Compliment of the new year, I have been waiting for you since to come down here and pick your Bank Draft which my boss left with me before he travelled to England but I did not hear from you since that time till today. I went to the bank to confirm whether the draft is getting close to expire as it had been long time my boss issued the draft. The director of the bank told me that before the draft will get to you, that it will expire. Then I told him to help me and cash the cashier bank draft of $1,500.000.00 to cash payment.<br /><br />However, I have successfully cashed the draft and packaged it in a box and have registered it in the Fedex Express Company Service here in Benin Republic because I will travell to see my boss in England and will not come back till August 20th 2008. You have to contact the Fedex Express Company Service to know when they will deliver your package to your address. I have paid for the delivering charges and insurance fees. The only money you have to send to them is their security keeping feeswhich is USD$135.00 USD to receive your package. Don't be deceived by any body.<br /><br />This is their Contact Address;<br />Attn: Cheif Mr. George Kobra (Director)<br />Tel:&nbsp; +229-9799 2240<br />E-mail: fc.bj@sify.com<br /><br />Send them your contacts information to enable them locate you<br />&nbsp;immediately they arrived in your country with your package.<br /><br />This is the information they needed from you.<br /><br />1. Your full name:.....<br />2. Your shipping/home address:.....<br />3. Your tel no #......<br />4. Your current office tel no #<br />5. A copy of your passport.<br /><br />Try to contact them as soon as possible to avoid increasement of the security keeping fees Note; I didn't tell the Fedex Express Company Service that it's money inside the box, I registered it as a church of a Church Minister Materials. This is to avoid delay or any upfront problem during the delivery. So, do not let them know that the package contents money. Do let me know as soon as you received your package. You will contact&nbsp; me only through e-mail as my phone is no longe available now that I am out from our country. Contact me at samdunbar1986@yahoo.com and I will reply as soon as I can.<br />I wish you and your family Long Life,<br />Prosperity and Happy 2008.<br /><br />Thanks and Remain Blessed.<br /><br />Yours sincerely,<br />Mr.Samuel Dunbar<br />(Secretary)<br /><br /><b>(Honestly, if you contact FedEx they'll give you tons of money....)</b><br /><br />****************************************************************************************<br /><br />That's your lot for another week....<br />
    ]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 09:29:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/central bank">central bank</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/magical bank card">magical bank card</category>
      <category domain="http://securityratty.com/tag/bank draft">bank draft</category>
      <category domain="http://securityratty.com/tag/email address">email address</category>
      <category domain="http://securityratty.com/tag/office email address">office email address</category>
      <category domain="http://securityratty.com/tag/bank immediately">bank immediately</category>
      <category domain="http://securityratty.com/tag/lycos lottery">lycos lottery</category>
      <category domain="http://securityratty.com/tag/office">office</category>
      <source url="http://blog.spywareguide.com/2008/06/your-419-mail-roundup.html">Your 419 Mail Roundup</source>
    </item>
    <item>
      <title><![CDATA[Fake Porn Sites Serving Malware]]></title>
      <link>http://securityratty.com/article/5dacf1e5b6c84c1bed4515dca8fc1199</link>
      <guid>http://securityratty.com/article/5dacf1e5b6c84c1bed4515dca8fc1199</guid>
      <description><![CDATA[Ah, that RBN with its centralization mentality for the sake of ease of management and 99.999% uptime. In this very latest example of using malicious doorways redirecting to fake porn sites, consisting...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SGJTBaqN1yI/AAAAAAAAB1k/b9O7PupnB8E/s1600-h/porn_codecs.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SGJTBaqN1yI/AAAAAAAAB1k/b9O7PupnB8E/s200/porn_codecs.JPG" alt="" id="BLOGGER_PHOTO_ID_5215822602249819938" border="0" /></a>Ah, that RBN with its centralization mentality for the sake of ease of management and 99.999% uptime. In this very latest example of using malicious doorways redirecting to fake porn sites, consisting of over twenty different domains serving the usual Zlob malware variants, we have a decent abuse of a template for a porn site.<br /><br />The easy of management of such domain farms and the availability of templates for high trafficked topic segments such as celebrities and pornography, continue contributing to the increasing number of Zlob variants served through fake codecs. Moreover, once set up, the malicious infrastructure starts attracting now just generic search traffic, but also traffic coming from affiliates with whom revenue is shared on the basis of the number of people that downloaded the codec.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGJsP6kwvTI/AAAAAAAAB1s/b0lRo5htJtE/s1600-h/fake_porn_sites_ATRIVO.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGJsP6kwvTI/AAAAAAAAB1s/b0lRo5htJtE/s200/fake_porn_sites_ATRIVO.JPG" alt="" id="BLOGGER_PHOTO_ID_5215850339125738802" border="0" /></a>In this campaign, the malicious doorway that expands the entire ecosystem is located at <span style="font-weight: bold;">search-</span><span style="font-weight: bold;">top.com/in.cgi?5&amp;parameter=drs</span> (66.96.85.113). A redirector that appears to <a href="http://www.lavasoftsupport.com/index.php?showtopic=2662">have been operating since 2006</a>, according to this forum posting.<br /><br />What follows on-the-fly, are all the fake porn sites whose legitimately looking videos attempt to download a Zlob malware variant from a single location - <span style="font-weight: bold;">vipcodec.net</span>. Here are all the fake porn sites, and the associated campaigns in this redirection :<br /><br /><span style="font-weight: bold;">watchnenjoy .com</span>/index.php?id=1287&amp;style=white<br /><span style="font-weight: bold;">craziestclips .com</span>/index.php?id=1287&amp;q=<br /><span style="font-weight: bold;">immensevids .com</span><br /><span style="font-weight: bold;">planetfreepornmovies .com</span>/?t=1&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/edmund/16551689/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/rosalyn/1742941675/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/emiline/108846601/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/inde/964842117/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/elnora/648311952/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/verge/1734135233/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/dal/1663381205/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .ne</span><span style="font-weight: bold;">t</span>/gretchen/515268975/1/&amp;id=1219<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGJ2DJRJgoI/AAAAAAAAB10/0pUS4GVInf4/s1600-h/porn_domainfarm_codecs_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGJ2DJRJgoI/AAAAAAAAB10/0pUS4GVInf4/s200/porn_domainfarm_codecs_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5215861114847986306" border="0" /></a><span style="font-weight: bold;">abc-adult .com</span>/lillah/1467790484/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/jenne/434165228/1/&amp;id=1219<br /><span style="font-weight: bold;">look-adult .net</span>/ette/681831796/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/mime/65729013/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/alfe/550398461/1/&amp;id=1219<br /><span style="font-weight: bold;">group-ad</span><span style="font-weight: bold;">ult .net</span>/demerias/867452637/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/rhode/167691118/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/hephsibah/1254235416/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/hence/1684651134/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/kendra/371598555/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/link/1334727639/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/flo/84660854/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/assene/875893411/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/charlotta/972714195/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/orlando/761508522/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/jemima/1405735776/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/obadiah/263904242/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/douglas/1110779475/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/lydde/1844064103/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/marcia/1627490290/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/cono/295680123/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/wes/1733468207/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/wib/648341815/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/greg/2064937302/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/maris/33184936/1/&amp;id=1219<br /><span style="font-weight: bold;">look-adult .net</span>/regina/1273816838/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/gwendolyn/869744046/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/carthaette/1021629112/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/ninell/1522355420/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/waldo/755290223/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/green/669090607/1/&amp;id=1219<br /><span style="font-weight: bold;">try-adult .com</span>/lula/447057398/1/&amp;id=1219<br /><span style="font-weight: bold;">visit-adult .net</span>/jay/1021153563/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/rosa/849017739/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/hannah/2111126283/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/robin/2114086747/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/geraldine/921262381/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/christine/1821111087/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/frederica/364993202/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/kerste/735582753/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/vine/715820953/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/newt/1835463160/1/&amp;id=1219<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGJ6ha5cUzI/AAAAAAAAB18/wtJ3aPXos_Q/s1600-h/zlob_codec_setup.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGJ6ha5cUzI/AAAAAAAAB18/wtJ3aPXos_Q/s200/zlob_codec_setup.png" alt="" id="BLOGGER_PHOTO_ID_5215866033022980914" border="0" /></a><span style="font-weight: bold;">try-adult .com</span>/max/602914725/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/cille/1420660046/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/phililpa/178057959/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/lise/1379126759/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/marianne/1083617952/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/emile/1173468576/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/patse/155685496/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/verna/625840253/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/aubrey/190928373/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .</span><span style="font-weight: bold;">net</span>/alphinias/1345158043/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/rosa/223743611/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/nerva/1509620489/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/leet/1619667733/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/roberta/887345003/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/tore/1032556395/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/bo/1963737386/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/karon/136085893/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/tense/1523522750/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/hopp/1955964399/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/vanne/350822489/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/deb/1451360694/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/moll/1511640690/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/obediah/562846948/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/tamarra/776122096/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/aristotle/1046422029/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/titia/158157566/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/gay/1297835054/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/katherine/2136357734/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/azubah/1197502147/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/claes/770105101/1/&amp;id=1219<br /><br />Associated fake porn sites :<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGJ7UYzaZJI/AAAAAAAAB2E/cy7Pijctw-8/s1600-h/fake_porn_sites_ATRIVO1.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGJ7UYzaZJI/AAAAAAAAB2E/cy7Pijctw-8/s200/fake_porn_sites_ATRIVO1.JPG" alt="" id="BLOGGER_PHOTO_ID_5215866908634145938" border="0" /></a><span style="font-weight: bold;">pornbrake .com</span> <span style="font-weight: bold;"><br />sexnitro .net</span> <span style="font-weight: bold;"><br />brakesex .net</span> <span style="font-weight: bold;"><br />pornnitro .net</span> <span style="font-weight: bold;"><br />adultbookings .com</span> <span style="font-weight: bold;"><br />qazsex .com</span><br /><span style="font-weight: bold;">lightporn .net</span> <span style="font-weight: bold;"><br />delfiporn .net</span> <span style="font-weight: bold;"><br />pornqaz .com</span> <span style="font-weight: bold;"><br />megazporn .com</span> <span style="font-weight: bold;"><br />uinsex .com</span><br /><span style="font-weight: bold;">xerosex .com</span> <span style="font-weight: bold;"><br />serviceporn .com</span> <span style="font-weight: bold;"><br />aboutadultsex .com</span> <span style="font-weight: bold;"><br />superliveporn .com</span> <span style="font-weight: bold;"><br />bestpriceporn .com</span> <span style="font-weight: bold;"><br />contactporn .net</span> <span style="font-weight: bold;"><br />relatedporn .com</span> <span style="font-weight: bold;"><br />landporno .com</span> <span style="font-weight: bold;"><br />adultsper .com</span> <span style="font-weight: bold;"><br />plus-porn .com</span> <span style="font-weight: bold;"><br />adultstarworld .com</span><br /><span style="font-weight: bold;">cutadult .com</span> <span style="font-weight: bold;"><br />moviexxxhotel .com</span> <span style="font-weight: bold;"><br />porno-go .com</span> <span style="font-weight: bold;"><br />pornxxxfilm .com</span> <span style="font-weight: bold;"><br />porn-sea .com</span> <span style="font-weight: bold;"><br />review-sex .com</span> <span style="font-weight: bold;"><br />sureadult .com</span> <span style="font-weight: bold;"><br />browseadult .com</span> <span style="font-weight: bold;"><br />network-adult .com</span> <span style="font-weight: bold;"><br />timeadult .com</span> <span style="font-weight: bold;"><br />virtual-sexy .net</span><br /><span style="font-weight: bold;">funxxxporn .com</span> <span style="font-weight: bold;"><br />loweradult .com</span> <span style="font-weight: bold;"><br />adultfilmsite .com</span> <span style="font-weight: bold;"><br />xxxallvideo .com</span> <span style="font-weight: bold;"><br />custom-sex .com</span> <span style="font-weight: bold;"><br />g</span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SGJ8FOk2RhI/AAAAAAAAB2M/scnBizNZUOA/s1600-h/fake_porn_sites_ATRIVO2.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SGJ8FOk2RhI/AAAAAAAAB2M/scnBizNZUOA/s200/fake_porn_sites_ATRIVO2.JPG" alt="" id="BLOGGER_PHOTO_ID_5215867747702294034" border="0" /></a><span style="font-weight: bold;">allerypictures .net</span> <span style="font-weight: bold;"><br />usaadultvideo .com</span><br /><span style="font-weight: bold;">adultmovieplus .com</span> <span style="font-weight: bold;"><br />porn-cruise .com</span> <span style="font-weight: bold;"><br />clubxxxvideo .com</span> <span style="font-weight: bold;"><br />mitadult .com</span> <span style="font-weight: bold;"><br />galleryalbum .net</span> <span style="font-weight: bold;"><br />xxxteenfilm .com</span> <span style="font-weight: bold;"><br />hardcorevideosite .com</span> <span style="font-weight: bold;"><br />helpadult .com</span> <span style="font-weight: bold;"><br />portaladult .net</span> <span style="font-weight: bold;"><br />service-sex .com</span> <span style="font-weight: bold;"><br />driveadult .com</span> <span style="font-weight: bold;"><br />access-porno .com</span> <span style="font-weight: bold;"><br />time-sex .com</span> <span style="font-weight: bold;"><br />plus-adult .com</span> <span style="font-weight: bold;"><br />worldadultvideo .com</span><br /><span style="font-weight: bold;">key-adult .com</span><br /><span style="font-weight: bold;">estatesex .com</span> <span style="font-weight: bold;"><br />superadultfriend .com</span><br /><span style="font-weight: bold;">superporncity .com</span> <span style="font-weight: bold;"><br />zero-porno .com</span> <span style="font-weight: bold;"><br />scanadult .com</span> <span style="font-weight: bold;"><br />adultsexpro .com</span> <span style="font-weight: bold;"><br />adultzoneworld .com</span> <span style="font-weight: bold;"><br />porntimeguide .com</span> <span style="font-weight: bold;"><br />usbestporn .com</span> <span style="font-weight: bold;"><br />adulttow .com</span> <span style="font-weight: bold;"><br />look-porn .com</span><br /><span style="font-weight: bold;">galleryclick .net</span><br /><span style="font-weight: bold;">micro-sex .com</span> <span style="font-weight: bold;"><br />estatesex .com</span> <span style="font-weight: bold;"><br />try-sex .com</span> <span style="font-weight: bold;"><br />0bucksforpornmovie .com</span> <span style="font-weight: bold;"><br />gays-video-xxx .com</span> <span style="font-weight: bold;"><br />hackthegrid .com</span> <span style="font-weight: bold;"><br />savetop .info</span> <span style="font-weight: bold;"><br />vidsplanet .net</span> <span style="font-weight: bold;"><br />freexxxhere .com</span> <span style="font-weight: bold;"><br />gestkoeporno .com</span><br /><span style="font-weight: bold;">tv-adult .info</span> <span style="font-weight: bold;"><br />gays-adult-video .com</span> <span style="font-weight: bold;"><br />matures-video .com</span> <span style="font-weight: bold;"><br />analcekc .com</span> <span style="font-weight: bold;"><br />tabletskard .in</span> <span style="font-weight: bold;"><br />molodiedevki .com</span> <span style="font-weight: bold;"><br />dom-porno .com</span> <span style="font-weight: bold;"><br />pornoaziatki .com</span> <span style="font-weight: bold;"><br />latinosvideo .com</span> <span style="font-weight: bold;"><br />geiporno .com</span> <span style="font-weight: bold;"><br />sweetfreeporn .com</span><br /><br />If exposing a huge domains portfolio of currently active redirectors has the potential to ruin someone's vacation, then consider someone's vacation ruined already.<br /><br /><span style="font-weight: bold;">Related posts:<br /></span><a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br /><a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br /><a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XlaQvI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XlaQvI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cI4v2I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cI4v2I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=U4oTAi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=U4oTAi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LbooCi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LbooCi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MITw1I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MITw1I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nqHRRI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nqHRRI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2sf0Xi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2sf0Xi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/319853315" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 08:16:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/about-adult">about-adult</category>
      <category domain="http://securityratty.com/tag/scan-porn">scan-porn</category>
      <category domain="http://securityratty.com/tag/zlob malware variant">zlob malware variant</category>
      <category domain="http://securityratty.com/tag/name-adult">name-adult</category>
      <category domain="http://securityratty.com/tag/useporn">useporn</category>
      <category domain="http://securityratty.com/tag/porn-the">porn-the</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/319853315/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</source>
    </item>
    <item>
      <title><![CDATA[Fake Celebrity Video Sites Serving Malware]]></title>
      <link>http://securityratty.com/article/e6b6b6bb079e0140b924b302a0f75bb8</link>
      <guid>http://securityratty.com/article/e6b6b6bb079e0140b924b302a0f75bb8</guid>
      <description><![CDATA[With blackhat search engine optimization tactics clearly converging with social engineering , the result of which is the increasing supply of Zlob malware variants served as fake codecs, it's about...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/SFuPgUZ-1iI/AAAAAAAABz0/CfFQY0pYbO4/s1600-h/fake_celebrity_sites_malware1.JPG"><img id="BLOGGER_PHOTO_ID_5213918779007751714" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/SFuPgUZ-1iI/AAAAAAAABz0/CfFQY0pYbO4/s200/fake_celebrity_sites_malware1.JPG" border="0" /></a>With <a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">blackhat search engine optimization tactics clearly converging with social engineering</a>, the result of which is the increasing supply of Zlob malware variants served as fake codecs, it's about time we spill some coffee on several campaigns in order to get a better understanding of the way the campaigns function.<br /><div><br />These campaigns are also starting to get so sophisticated, that analyzing a single one will expose another massive SQL injection, reveal several blackhat SEO domain farms, let you obtain fresh Zlob malware variants, and point you to the very latest and undetected rogue software if you manage to expose the entire scammy ecosystem through all the redirections put in place to make it harder to get to the bottom of it.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFuTjKmVT2I/AAAAAAAAB0M/uoqsc9RfJNU/s1600-h/fake_celebrity_sites_malware2.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFuTjKmVT2I/AAAAAAAAB0M/uoqsc9RfJNU/s200/fake_celebrity_sites_malware2.JPG" alt="" id="BLOGGER_PHOTO_ID_5213923225961320290" border="0" /></a>What's important to keep in mind when assessing and shutting down such comprehensive campaigns is that on the majority of occassions the front end domains as well as the secondary ones are all attempting to download the codecs from hardcoded locations. Consequently, you have 50 front end domains and another 50 as secondary redirection points all attempting to download the codecs from 3 download locations. Once again, the malware authors efficiency centered mentality emphasising on the easy of management for the campaign is making it possible to.<br /><br /><div>Here's are some currently active fake celebrity video sites serving malware including the codec redirectors :<br /><br /><a href="http://bp3.blogger.com/_wICHhTiQmrA/SFuQGWDNAzI/AAAAAAAABz8/V4kNHEWuR0A/s1600-h/fake_celebrity_sites_malware.JPG"><img id="BLOGGER_PHOTO_ID_5213919432284111666" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SFuQGWDNAzI/AAAAAAAABz8/V4kNHEWuR0A/s200/fake_celebrity_sites_malware.JPG" border="0" /></a><span style="font-weight: bold;">stillnaked.net</span> <span style="font-weight: bold;"><br />funkytube.net</span><br /><span style="font-weight: bold;">starvid.info</span> <span style="font-weight: bold;"><br />yetmorefun.net</span> <span style="font-weight: bold;"><br />hotnudity.net</span> <span style="font-weight: bold;"><br />alreadynude.com</span> <span style="font-weight: bold;"><br />celebvids.info</span> <span style="font-weight: bold;"><br />sexystar.name</span> <span style="font-weight: bold;"><br />hotserved.net</span> <span style="font-weight: bold;"><br />thestars2008.com</span><br /><span style="font-weight: bold;">nudde.net</span> <span style="font-weight: bold;"><br />gottabigfuick.com</span> <span style="font-weight: bold;"><br />moviecity.se</span> <span style="font-weight: bold;"><br />gossip-starz.com</span> <span style="font-weight: bold;"><br />tmz-video.com</span><br /><span style="font-weight: bold;">js0.info</span> <span style="font-weight: bold;"><br />superfakamyvideo.com</span> <span style="font-weight: bold;"><br />hdavidz.com</span> <span style="font-weight: bold;"><br /></span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SFuRy8PMNtI/AAAAAAAAB0E/qBrd4frSeM0/s1600-h/thestars2008_com_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SFuRy8PMNtI/AAAAAAAAB0E/qBrd4frSeM0/s200/thestars2008_com_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5213921297960810194" border="0" /></a><span style="font-weight: bold;">blog-x.in</span> <span style="font-weight: bold;"><br /></span><span style="font-weight: bold;">tmz-video.com</span> <span style="font-weight: bold;"><br />newhotpeople.com</span> <span style="font-weight: bold;"><br />dirty-gossips.com</span> <span style="font-weight: bold;"><br />flaxxvid.com</span> <span style="font-weight: bold;"><br />videoid.info</span> <span style="font-weight: bold;"><br />realvideofree.com</span> <span style="font-weight: bold;"><br />yetmorefun.net</span> <span style="font-weight: bold;"><br />popvids.info<br />ihavewetfuckpussy.com<br /></span><span style="font-weight: bold;">virus-scanonline.com</span> <span style="font-weight: bold;"><br />adultx2008.com</span><br /><span style="font-weight: bold;">lux-software2008.com</span><br /><br />As well as some sample subdomains for traffic acquisition purposes, since all of these have already been crawled by search engines :<br /><br /><span style="font-weight: bold;">jodie.popvids.info</span> <span style="font-weight: bold;"><br />jessica.popvids.info</span> <span style="font-weight: bold;"><br />tila.popvids.info</span><br /><span style="font-weight: bold;">paris.celebvids.info</span> <span style="font-weight: bold;"><br />vanessa.celebvids.info</span> <span style="font-weight: bold;"><br />britney.nudde.net</span> <span style="font-weight: bold;"><br />paris.nudde.net</span> <span style="font-weight: bold;"><br />kardashian.nudde.net</span> <span style="font-weight: bold;"><br />vanessahudgens.yetmorefun.net</span> <span style="font-weight: bold;"><br />lindsaylohan.yetmorefun.net</span> <span style="font-weight: bold;"><br />britneyspears.yetmorefun.net</span> <span style="font-weight: bold;"><br />parishilton.yetmorefun.net</span> <span style="font-weight: bold;"><br />kardashian.nudde.net</span><br /><br />We also have embedded IFRAMEs and as well as injected ones into vulnerable sites, acting as redirectors to some of these fake video sites. For instance, at the <span style="font-weight: bold;">pedophilesexstories.blog.com</span> we have an injected redirector - <span style="font-weight: bold;">js0.info/?s=16&amp;k=pedophile+sex+stories&amp;c=5</span> and <span style="font-weight: bold;">js0.info</span> itself is a blackhat SEO operation that's aggregating generic search traffic like this :<br /><br /><span style="font-weight: bold;">js0.info/16/5/ragnarok+hentai</span> <span style="font-weight: bold;"><br />js0.info/15/4/antivirus+characteristic</span><br /><span style="font-weight: bold;">js0.info/16/5/msn+monkey</span><br /><span style="font-weight: bold;">js0.info/15/4/airplus+internet+security</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SFuW_npeNMI/AAAAAAAAB0U/aqnVPUbVWjc/s1600-h/malicious_redirector_script.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SFuW_npeNMI/AAAAAAAAB0U/aqnVPUbVWjc/s200/malicious_redirector_script.JPG" alt="" id="BLOGGER_PHOTO_ID_5213927013330334914" border="0" /></a>Once accessed, you get redirected to through <a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">two separate redirection campaigns</a> at <span style="font-weight: bold;">searchaw.info/sa/in.cgi?16</span>; and <span style="font-weight: bold;">hmel.info/stds13/go.php</span>, until you finally get to the codecs.<br /><br />With blackhat SEO-ers already well developed inventory of topical junk content, and experience in what's popular content and what's not,  the entry barriers for malware authors into the traffic acquisition joys of blackhat SEO has never lower.<br /></div></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WOphoI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WOphoI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W1jLhI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W1jLhI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PO1pbi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PO1pbi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=b0ILEi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=b0ILEi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HEkGpI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HEkGpI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vnYhGI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vnYhGI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1X0RPi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1X0RPi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/316164970" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 20 Jun 2008 02:58:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/blackhat seo-ers">blackhat seo-ers</category>
      <category domain="http://securityratty.com/tag/blackhat seo">blackhat seo</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware authors efficiency">malware authors efficiency</category>
      <category domain="http://securityratty.com/tag/blackhat seo operation">blackhat seo operation</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <category domain="http://securityratty.com/tag/blackhat">blackhat</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/316164970/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</source>
    </item>
    <item>
      <title><![CDATA[Malicious Doorways Redirecting to Malware]]></title>
      <link>http://securityratty.com/article/fe7f4960d26a3758a81dc861f894e098</link>
      <guid>http://securityratty.com/article/fe7f4960d26a3758a81dc861f894e098</guid>
      <description><![CDATA[Blacklisting malicious sites in times when legitimate ones are starting to compete with bogus .info and .biz ones for the leading position of hosting and serving malicious content, is a bit of an...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SFUBnTCFkwI/AAAAAAAABzE/90Gdkzc04f8/s1600-h/bestxvids_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SFUBnTCFkwI/AAAAAAAABzE/90Gdkzc04f8/s200/bestxvids_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5212073918386770690" border="0" /></a>Blacklisting malicious sites in times when legitimate ones are starting to compete with bogus .info and .biz ones for the leading position of hosting and serving malicious content, is a bit of an outdated and reactive approach for protecting against unknown threats. However, a single malicious domain whose live exploits can be easily detected and consequently blocked, is often just a front end to a large domains portfolio whose malicious content may easily pass through web filtering and on-the-fly malware attempts. Even worse, a malicious domain often exists in multiple "alternate realities" since a single IP is hosting many other unique and related malware domains.<br /><br />In this post, I'll assess <a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">a misconfigured malicious doorway</a>, that is redirecting to ten different malware sites <a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">serving Zlob variants by delivering fake codecs</a> that all the bogus adult sites require. The doorway is misconfigured in the sense of not recording the IP and checking the cookie set, in comparrision to every average web malware exploitation kit out there, which will not serve anything malicious when accessed for a second time since it's hashing the IPs that accessed it already. This is just the tip of the iceberg when it comes to the emerging evasive approaches applied to make the analysis of such doorways a bit more time and resources consuming. In a single sentence - <span style="font-weight: bold;">there's evidence blackhat SEO-ers are starting to exchange crawling manipulation know-how with malware authors</span>.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SFUCCgpQO8I/AAAAAAAABzM/HU4eAtm8bwU/s1600-h/bestxvids_spyshredder_redirection.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SFUCCgpQO8I/AAAAAAAABzM/HU4eAtm8bwU/s200/bestxvids_spyshredder_redirection.JPG" alt="" id="BLOGGER_PHOTO_ID_5212074385897176002" border="0" /></a>In this example we have <span style="font-weight: bold;">bestxvids.info</span> (87.118.116.11)  which is reditecting to <span style="font-weight: bold;">all-in</span><span style="font-weight: bold;">dex.com/in.cgi?5</span> (87.118.116.11) a URL that's been actively spammed across forums and guestbooks vulnerable to automatic posting vulnerabilities (weak CAPTCHAs and web application vulnerabilities) which is then redirecting to the following fake codec domains on the fly, and since the redirection script isn't hashing my IP like the majority of well configured ones requiring the use of multiple IPs if we're to expose all the campaigns, it makes the investigation easier :<br /><br /><span style="font-weight: bold;">tubeuniverses.com/teen/index.php?id=1883</span> - (78.108.177.99)<br /><span style="font-weight: bold;">new-content-s2008.com/freemovie/938/0/</span> - (72.21.53.218)<br /><span style="font-weight: bold;">teens.0bucksforpornmovie.com/?id=4199</span> - (64.28.181.28)<br /><span style="font-weight: bold;">getadultaccess.com/movie/?aff=5310</span> - (200.63.46.84)<br /><span style="font-weight: bold;">hqtube.com/?7014000000</span> - (88.85.66.116)<br /><span style="font-weight: bold;">supersharebox.com/softw/?aff=5310&amp;saff=0</span> - (200.63.46.84)<br /><span style="font-weight: bold;">scanner.shredderscan.com/5/?advid=4329</span> - (92.241.182.13)<br /><span style="font-weight: bold;">myflydirect.com/1/5310/</span> - (200.63.46.84)<br /><span style="font-weight: bold;">getadultaccess.com/movie/?aff=5310</span> - (200.63.46.84)<br /><span style="font-weight: bold;">hotvidstube.com/teen/index.php?id=1883</span> - (78.108.177.99)<br /><span style="font-weight: bold;">2008-adult-2008.com/freemovie/938/0/</span> - (72.21.53.218)<br /><span style="font-weight: bold;">s-soft08freeware.com/download/502/938/0</span> - (91.203.70.18)<br /><br />Where's the "alternate reality"? All of the following fake codec and adult sites serving Zlob variants, with minor exceptions of course, are also responding to the main IP of the redirector - 87.118.116.11 :<br /><span style="font-weight: bold;"><br /></span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SFYov0Kh3HI/AAAAAAAABzc/70YINcLA_7E/s1600-h/porno_info_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SFYov0Kh3HI/AAAAAAAABzc/70YINcLA_7E/s200/porno_info_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5212398420649696370" border="0" /></a><span style="font-weight: bold;">carsfoto.ru</span> <span style="font-weight: bold;"><br />cheapest-pharmacy.com</span> <span style="font-weight: bold;"><br />coolsexmovies.net</span><br /><span style="font-weight: bold;">free-movie-xxx.net</span> <span style="font-weight: bold;"><br />gold-collection.biz</span> <span style="font-weight: bold;"><br />p-o-r-n-0.com</span> <span style="font-weight: bold;"><br />p-o-r-n-0.info</span> <span style="font-weight: bold;"><br />sexakaporn.com</span> <span style="font-weight: bold;"><br />stred.biz</span> <span style="font-weight: bold;"><br />stred.in</span> <span style="font-weight: bold;"><br />tosserhost.com</span> <span style="font-weight: bold;"><br />west-video-xxx.info</span> <span style="font-weight: bold;"><br />wowtofree.info</span><br /><br />Shall we also expose the entire scammy ecosystem of Zlob variants, as always, sharing the same netblocks in order to keep it simple? But of course :<br /><br /><span style="font-weight: bold;">porn-youtube08.net</span> <span style="font-weight: bold;"><br />sextubecodec55.com</span> <span style="font-weight: bold;"><br />2008adult2008.com</span><br /><span style="font-weight: bold;">adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />newcontent-s2008.com</span> <span style="font-weight: bold;"><br />adultxx-18.com</span> <span style="font-weight: bold;"><br />newcontents2008.com</span> <span style="font-weight: bold;"><br />onlinestreamvide.com</span> <span style="font-weight: bold;"><br />2008adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />newcontents2008.com</span><br /><span style="font-weight: bold;">hot-pornotube2008.com</span> <span style="font-weight: bold;"><br />adult-youtube-8.com</span> <span style="font-weight: bold;"><br /></span><span style="font-weight: bold;">2008adult-s2008.com</span> <span style="font-weight: bold;"><br />2008adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />adult-freetube-8.com</span><br /><span style="font-weight: bold;">adult18tube2008.com</span><br /><span style="font-weight: bold;">adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />free-porntube-8.com</span> <span style="font-weight: bold;"><br /></span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFVF_rdlslI/AAAAAAAABzU/Y6DIZmD5gxo/s1600-h/bestxvids_malware_domains.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFVF_rdlslI/AAAAAAAABzU/Y6DIZmD5gxo/s200/bestxvids_malware_domains.JPG" alt="" id="BLOGGER_PHOTO_ID_5212149104052122194" border="0" /></a><span style="font-weight: bold;">gt-funny.com    </span> <span style="font-weight: bold;"><br />gt-movies.com</span> <span style="font-weight: bold;"><br />gt-stars.com</span> <span style="font-weight: bold;"><br />hot-sextube.com    </span> <span style="font-weight: bold;"><br />new-content-s2008.com</span> <span style="font-weight: bold;"><br />newcontent-s2008.com</span> <span style="font-weight: bold;"><br />newcontents2008.com</span> <span style="font-weight: bold;"><br />onlinestreamvide.com    </span> <span style="font-weight: bold;"><br />porno-tube20008.com    </span> <span style="font-weight: bold;"><br />pornotube-20008.com        </span> <span style="font-weight: bold;"><br />pornotube20008.com</span> <span style="font-weight: bold;"><br />sex-18tube-2008.com</span><br /><span style="font-weight: bold;">sex-tube-20008.com</span> <span style="font-weight: bold;"><br />sex-tube20008.com</span> <span style="font-weight: bold;"><br />sex18tube2008.com</span> <span style="font-weight: bold;"><br />sexi18tube2008.com</span> <span style="font-weight: bold;"><br />sextube18adult.com</span> <span style="font-weight: bold;"><br />sextube20008.com    </span> <span style="font-weight: bold;"><br />streamadultvideo.com</span> <span style="font-weight: bold;"><br />xxxstreamonline.com</span><br /><br />The bottom line - malicious doorways are slowly starting to emerge thanks to the convergence of traffic redirection and management tools with web malware exploitation kits, and just like we've been seeing the adaptation of spamming tools and approaches for phishing purposes, next we're going to see the development of infrastructure management kits, a feature that <a href="http://ddanchev.blogspot.com/2008/05/diy-phishing-kits-introducing-new.html">DIY phishing kits</a> are starting to take into consideration as well.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8oWxkI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8oWxkI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CSGETI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CSGETI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BOEE6i"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BOEE6i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fIFwTi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fIFwTi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vk30nI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vk30nI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DPXX6I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DPXX6I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=x8rEEi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=x8rEEi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/312884606" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 15 Jun 2008 23:51:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/doorways">doorways</category>
      <category domain="http://securityratty.com/tag/malicious doorways">malicious doorways</category>
      <category domain="http://securityratty.com/tag/malicious content">malicious content</category>
      <category domain="http://securityratty.com/tag/single sentence">single sentence</category>
      <category domain="http://securityratty.com/tag/single">single</category>
      <category domain="http://securityratty.com/tag/single malicious domain">single malicious domain</category>
      <category domain="http://securityratty.com/tag/doorway">doorway</category>
      <category domain="http://securityratty.com/tag/malicious doorway">malicious doorway</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/312884606/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</source>
    </item>
  </channel>
</rss>
