<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sha1]]></title>
    <link>http://securityratty.com/tag/sha1</link>
    <description></description>
    <pubDate>Thu, 05 Jun 2008 03:59:47 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The opt-out from hell]]></title>
      <link>http://securityratty.com/article/e2ac86231138c2d34a97b7acfc4cd2ec</link>
      <guid>http://securityratty.com/article/e2ac86231138c2d34a97b7acfc4cd2ec</guid>
      <description><![CDATA[One problem with making your email address available (which I will continue to do, don't worry) is that folks with something to sell assume you're interested in their stuff. To wit, let's consider an...]]></description>
      <content:encoded><![CDATA[<p>One problem with making your email address available (which I will continue to do, don't worry) is that folks with something to sell assume you're interested in their stuff. To wit, let's consider an email I received today (copied, headers and all, after my griping).</p>  <p>Note that if I want to opt out of further communications, I have to do <em>two separate things</em> -- which actually becomes three things.</p>  <ul>   <li>First I have to click the last link to opt out of future TechTarget spam. (Yes, I deleted the actual links. But certainly none of <em>my</em> trustworthy readers would attempt to re-subscribe me, right...? &lt;g&gt; </li>    <li>But that isn't enough -- I <em>also</em> have to separately opt out of future Avaya spam! (Why does the no-more-from-Avaya link live on a techtargetmail.com server? Whatever.) Clicking on that link eventually does land me on an avaya.com page, where I have to confirm my email address and indicate they don't have my permission to send me spam. Hmm, too difficult to embed my email in that link, when the other techtargetmail.com link <em>did</em> embed my email? </li>    <li>Then after submitting it, another page pops up telling me that I'll soon receive an email with <em>additional</em> instructions! In this email there's a link -- to avaya.com with my email address embedded -- that I must click, I guess to double plus confirm that yes, I really really really do wish never to hear from you again. Clicking that link takes me to a page that promises my &quot;permissions have successfully been set. Thank you.&quot; </li> </ul>  <p>A pox on both your houses, TechTarget and Avaya. I never asked for your stuff. Go away.</p>  <p>Spam, my friends, is only going to <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/09/12/AR2008091201211.html?hpid=topnews" target="_blank">get</a> <a href="http://voices.washingtonpost.com/securityfix/2008/09/virginia_anti-spam_law_overtur.html?hpid=news-col-blogs" target="_blank">worse</a>. It was so easy to <a href="http://en.wikipedia.org/wiki/Junk_fax" target="_blank">ban junk faxes</a> in 1991. But even those regulations were <a href="http://en.wikipedia.org/wiki/Junk_Fax_Prevention_Act_of_2005" target="_blank">weakened in 2005</a>. So do you really think we'll see anything even remotely logical for outlawing spam? I doubt it, unless we the citizens foment a revolt. Let's get cracking! </p>  <p>&#160;</p>  <hr />  <p><font face="Courier New" size="2">Received: from SVC-EXGWY-E801.partners.extranet.microsoft.com (10.251.24.242)      <br />by tk5-exhub-c102.redmond.corp.microsoft.com (157.54.18.53) with Microsoft       <br />SMTP Server (TLS) id 8.1.291.1; Tue, 16 Sep 2008 11:27:56 -0700       <br />Received: from mail139-wa4-R.bigfish.com (216.32.181.113) by       <br />mail04.microsoft.com (10.253.160.184) with Microsoft SMTP Server (TLS) id       <br />8.1.291.1; Tue, 16 Sep 2008 11:27:55 -0700       <br />Received: from mail139-wa4 (localhost.localdomain [127.0.0.1])&#160;&#160;&#160; by       <br />mail139-wa4-R.bigfish.com (Postfix) with ESMTP id 018C11184C2&#160;&#160;&#160; for       <br />&lt;steriley@microsoft.com&gt;; Tue, 16 Sep 2008 18:27:50 +0000 (UTC)       <br />X-BigFish: ps16(zz18c1K1936K2b7wcak69jzzzz2af1jz2fh6bh5eh65h)       <br />X-Spam-TCS-SCL: 4:0       <br />Received: by mail139-wa4 (MessageSwitch) id 1221589667478982_28100; Tue, 16       <br />Sep 2008 18:27:47 +0000 (UCT)       <br />Received: from pp.techtargetmail.com (pp.techtargetmail.com [65.211.80.227])       <br />&#160;&#160;&#160; by mail139-wa4.bigfish.com (Postfix) with SMTP id 46566978071&#160;&#160;&#160; for       <br />&lt;steriley@microsoft.com&gt;; Tue, 16 Sep 2008 18:27:47 +0000 (UTC)       <br />DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=pp.techtargetmail.com; b=iOmibOrM91/1Ugy2gj3QbWo74T2m3GuhmwxZCXJQpFT+nwRES8QKg+4vjt48SNp7WWJExG61Ge+DtnKD3KVI3KwqTKzkPRVrEBF0DCHhYot6VAG/EyEr5vb5RhBz+91yvNhbIqITzGnuQ+uBDJzyc6gU0FHfBl0Fa3S/phcPELM=;       <br />Message-ID: &lt;a818b044.724694.236c8ee748f7dd97.1.n.4.2971370188@pp.techtargetmail.com&gt;       <br />Date: Tue, 16 Sep 2008 14:27:47 -0400       <br />thread-index: a818b044.724694.236c8ee748f7dd97.1.n.4       <br />Reply-To: Avaya &lt;a818b044.724694.236c8ee748f7dd97.1.n.4@pp.techtargetmail.com&gt;       <br />From: Avaya &lt;Avaya@pp.techtargetmail.com&gt;       <br />To: Steve Riley &lt;steriley@microsoft.com&gt;       <br />Subject: 7 Tips to Ensure Readiness for UC Deployment       <br />MIME-Version: 1.0       <br />Content-Type: text/plain       <br />Content-Transfer-Encoding: 7bit       <br />Content-Class: urn:content-classes:message       <br />Importance: normal       <br />Priority: normal       <br />X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.4133       <br />Return-Path: a818b044.724694.236c8ee748f7dd97.1.n.4@pp.techtargetmail.com       <br />X-MS-Exchange-Organization-PRD: pp.techtargetmail.com       <br />Received-SPF: Pass (SVC-EXGWY-E801.partners.extranet.microsoft.com: domain       <br />of Avaya@pp.techtargetmail.com designates 65.211.80.227 as permitted sender)       <br />receiver=SVC-EXGWY-E801.partners.extranet.microsoft.com;       <br />client-ip=65.211.80.227; helo=mail139-wa4-R.bigfish.com;       <br />X-MS-Exchange-Organization-PCL: 2       <br />X-MS-Exchange-Organization-Antispam-Report: DV:3.3.6916.600;SV:3.3.6916.813;SID:SenderIDStatus Pass;OrigIP:65.211.80.227       <br />X-MS-Exchange-Organization-SCL: 2       <br />X-MS-Exchange-Organization-SenderIdResult: PASS</font></p>  <p><font face="Courier New" size="2">The following message was sent to you as a subscriber to third party offers from a TechTarget property, including our network of Search sites, Bitpipe.com, CIO Decisions Magazine, Information Security Magazine, Storage Magazine, KnowledgeStorm, TheServerSide.com and/or TheServerSide.NET. To unsubscribe, see below.      <br />____________________________________________________________ </font></p>  <p><font face="Courier New" size="2">How should you evaluate the move to unified communications (UC)? Who within which parts of an organization will benefit? Will UC reduce the time to market? Read this E-Guide for answers to these questions and a better look at how the value of UC will, at first, be less of a financial issue and more of a productivity improvement issue that translates into financial benefits. Download this white paper now: </font><a href="http://pp.techtargetmail.com/c.asp?724694&amp;236c8ee748f7dd97&amp;1"><font face="Courier New" size="2">http://pp.techtargetmail.com/c.asp?724694&amp;236c8ee748f7dd97&amp;1</font></a></p>  <p><font face="Courier New" size="2">When implementing unified communications, there are a number of important issues to think about and questions to ask. This E-Guide analyzes seven phases to ensure you reap the full benefits of UC in each. If you're ready to take the plunge but you're not sure your business or your infrastructure is - download this E-Guide now. </font></p>  <p><font face="Courier New" size="2">Click here to learn more: </font><a href="http://pp.techtargetmail.com/c.asp?724694&amp;236c8ee748f7dd97&amp;1"><font face="Courier New" size="2">http://pp.techtargetmail.com/c.asp?724694&amp;236c8ee748f7dd97&amp;1</font></a></p>  <p><font face="Courier New" size="2">&quot;If you do not wish to receive future promotions directly from Avaya please forward this e-mail to <u>{link removed}</u> ; please note that there is a separate opt-out procedure below to be removed from the list from which this email originated.&quot;       <br />____________________________________________________________ </font></p>  <p><font face="Courier New" size="2">Please do not reply to this email.&#160; To unsubscribe from all future third party offers from all TechTarget properties, simply click here: <u>{link removed}</u></font></a></p>  <p><font face="Courier New" size="2">TechTarget | 117 Kendrick Street, Suite 800 | Needham, MA 02494</font> </p>  <hr /><img src="http://blogs.technet.com/aggbug.aspx?PostID=3124873" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 15:22:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/smtp server">smtp server</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/smtp">smtp</category>
      <category domain="http://securityratty.com/tag/x-spam-tcs-scl">x-spam-tcs-scl</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/future avaya spam">future avaya spam</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/microsoft smtp server">microsoft smtp server</category>
      <category domain="http://securityratty.com/tag/avaya">avaya</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/09/16/the-opt-out-from-hell.aspx">The opt-out from hell</source>
    </item>
    <item>
      <title><![CDATA[Fake Porn Sites Serving Malware - Part Three]]></title>
      <link>http://securityratty.com/article/df6f06139a5c1a6029631a2d5221d428</link>
      <guid>http://securityratty.com/article/df6f06139a5c1a6029631a2d5221d428</guid>
      <description><![CDATA[Continue the Fake Porn Sites Serving Malware and Fake Porn Sites Serving Malware - Part Two series, in part three we'll take a peek at the emerging trend of parking a single domain at up to three...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQENtZvVWI/AAAAAAAACHU/3Th9wGTcre4/s1600-h/fake_porn_zlob_codec_localized.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQENtZvVWI/AAAAAAAACHU/1aZSLqClTi4/s200-R/fake_porn_zlob_codec_localized.JPG" /></a>Continue the <a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a> and <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a> series, in part three we'll take a peek at the emerging trend of parking a single domain at up to three different hosting locations, re-establishing connections between malicious ISPs for yet another time in between exposing the domains and the download locations sharing the same IPs.<br />
<br />
<b>downlfreesexgirlbeach .com</b> first redirects to <b>infodist1 .com/in.cgi?2 </b>then to <b>watchnenjoy.com/index.php?id=1314&amp;style=black</b>, and finally to the front end to the codec's download location <b>handmadeclips .com</b>, where the codec is downloaded from <b>fwlprocedure .com</b>.  Behind these domains, we can easily expose many other fake porn sites and pharmaceutical scams, next to a small portfolio of domains specifically used for hosting the binaries. Due to the obvious rotation I've encountered several times so far, a fake porn site today, is tomorrow's blackhat SEO content farm :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQHSj0XVWI/AAAAAAAACHc/DX-IaOAduVs/s1600-h/fake_porn_august.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQHSj0XVWI/AAAAAAAACHc/k9h1_E21wag/s200-R/fake_porn_august.JPG" /></a><b>downlfreesexgirlbeach .com</b> - (88.214.198.25)<br />
<b>vids365 .com<br />
downlfreesexgirlbeach .com<br />
top.only-bi .com<br />
wikiei .com<br />
paysuperporn .com<br />
aboutsexporn .com<br />
freactor .com<br />
cheapofficialpills .com<br />
finance-leaders.comnudenakedboys .com<br />
photosgayboys&nbsp; .com<br />
uniqueincest.com<br />
shyincest .com<br />
banrnd.central-xxx .com<br />
tvisklick .info<br />
thebg .net<br />
termion .net<br />
xoxvids .net<br />
bestpricepills .net<br />
bcodecnow .net</b><br />
<br />
<b>infodist1 .com</b> - (88.214.204.40)<br />
<b>farmasearch2008 .com<br />
flaxxvid .com<br />
xanax777pills .com<br />
18virgingirls .com<br />
girlnudegallaryvideox .com<br />
allxxxpornogerlsx .com<br />
jproshin .info<br />
familytaboo .info<br />
fullsitehost .info<br />
20searchonlinesite .net<br />
add-your-video .net<br />
blogs4y .net</b><br />
<br />
<div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SLQIspjO3tI/AAAAAAAACHs/MaMXiAw02F8/s1600-h/downlfreesexgirlbeach_viz.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SLQIspjO3tI/AAAAAAAACHs/znHGKTmbcHE/s200-R/downlfreesexgirlbeach_viz.JPG" /></a><b>adult-shemale .com</b> - (88.214.198.25)<br />
<b>adult-tranny .com<br />
all-shemale&nbsp; .com&nbsp;&nbsp;&nbsp; <br />
bcodecnow .net<br />
best-tranny .com&nbsp;&nbsp;&nbsp; <br />
bestguyportal .com<br />
bestmoviez .com&nbsp;&nbsp;&nbsp; <br />
central-xxx .com<br />
downlfreesexgirlbeach .com&nbsp;&nbsp;&nbsp; <br />
gallery-boy .com<br />
hiosexywomensxxxgirlsx .com&nbsp;&nbsp;&nbsp; <br />
lady-dick .com<br />
bcodecnow .net<br />
mytoppharmacy .com<br />
nakednudeboys .com&nbsp;&nbsp;&nbsp; <br />
nakednudemen .com<br />
nudenakedboys .com<br />
only-bi .com<br />
only-shemale .com<br />
page-reviews .com<br />
paulaslosingit .com<br />
photosgayboys .com<br />
stud-boys .com&nbsp;&nbsp;&nbsp; <br />
the0download .com<br />
wikiei .com&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; <br />
moviez .com<br />
hiosexywomensxxxgirlsx .com<br />
sexygirlsisuniformh0t .com&nbsp;&nbsp;&nbsp; <br />
the0download .com</b><br />
<br />
<b>flwprocedure .com </b>- (77.91.231.201)<b><br />
movupdate .com<br />
flwupdate .com<br />
formatmpeg .com<br />
movieexternal .com<br />
flwtool .com <br />
aviexecution .com<br />
releasedvideo .com<br />
wmvcompressor .com<br />
movieopens .com<br />
mpegapparatus .com<br />
flwassistant .com<br />
flwinstrument .com<br />
piterserv .com<br />
wovview .com</b><br />
<br />
<b>Some info on a sample codec :</b><br />
Scanners Result: 11/36 (30.56%)<br />
Trojan-Downloader.Win32.Zlob.cos<br />
Trojan.Popuper.7315<br />
File size: 10240 bytes <br />
MD5...: 467e4e78974dc8b2ee5d7da024daf31a <br />
SHA1..: 311e0c710bb15761ef3dace54b55489830cf5803<br />
<br />
Phones back to <b>69.50.164.50</b>/this/is/stereo/music.php?param=0;1314;1550; <b>69.50.164.50</b>/this/is/stereo/jazz.php?param=49325611;2:191:5|7:271:0|6:130:0|9:0:5|34:65536:0 and to <b>85.255.119.244</b>/this/is/stereo/music.php?param=0;4135;1548.<br />
<br />
When <b>Emil Kaperski's</b> owned <a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">InterCage, Inc.</a> (69.50.164.50) meets <a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">UkrTeleGroup Ltd.</a> (85.255.119.244) previously known as <b>Andrei Kislizin's</b> owned InHoster, you know you're on the right track.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kUs27K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kUs27K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sRXTAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sRXTAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sOsoWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sOsoWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fnooek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fnooek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R3T9kK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R3T9kK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WaKp6K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WaKp6K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R12pRk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R12pRk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/375241515" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 05:02:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <category domain="http://securityratty.com/tag/codec">codec</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/sample codec">sample codec</category>
      <category domain="http://securityratty.com/tag/locations">locations</category>
      <category domain="http://securityratty.com/tag/fake porn site">fake porn site</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/375241515/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Three</source>
    </item>
    <item>
      <title><![CDATA[Is this a Series Global Cyber Attack Occurring Before Us?]]></title>
      <link>http://securityratty.com/article/e5de544cb3f504ed8c567849f5577cde</link>
      <guid>http://securityratty.com/article/e5de544cb3f504ed8c567849f5577cde</guid>
      <description><![CDATA[BEGIN PGP SIGNED MESSAGE Hash: SHA1 Ok, so to sum up the two emails below: 1. Fedoras package signing box was compromised by unknown parties. Fedora does not think the keys passphrase was compromised...]]></description>
      <content:encoded><![CDATA[&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;
Hash: SHA1
Ok, so to sum up the two emails below:
1. Fedora&#8217;s package signing box was compromised by unknown parties.
Fedora does not think the key&#8217;s passphrase was compromised however. They are changing their keys.
2. RedHat&#8217;s package signing key was used to sign trojaned OpenSSH packages. RedHat does not think these were distributed via [...]]]></content:encoded>
      <pubDate>Fri, 22 Aug 2008 13:06:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/keys">keys</category>
      <category domain="http://securityratty.com/tag/keys passphrase">keys passphrase</category>
      <category domain="http://securityratty.com/tag/unknown parties">unknown parties</category>
      <category domain="http://securityratty.com/tag/redhats package">redhats package</category>
      <category domain="http://securityratty.com/tag/message hash">message hash</category>
      <category domain="http://securityratty.com/tag/fedoras package">fedoras package</category>
      <category domain="http://securityratty.com/tag/openssh packages">openssh packages</category>
      <category domain="http://securityratty.com/tag/sha1">sha1</category>
      <category domain="http://securityratty.com/tag/key">key</category>
      <source url="http://securitybuddha.com/2008/08/22/is-this-a-series-global-cyber-attack-occurring-before-us/">Is this a Series Global Cyber Attack Occurring Before Us?</source>
    </item>
    <item>
      <title><![CDATA[Compromised Web Servers Serving Fake Flash Players]]></title>
      <link>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</link>
      <guid>http://securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</guid>
      <description><![CDATA[The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/SSFpGnP3wvA/s1600-h/fake_flash1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/qKqvrWeAN3s/s200-R/fake_flash1.png" style="border: 0pt none ;" /></a>The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so much confidence in this risk-forwarding process of hosting their campaigns, that they would start actively spamming the links residing within low-profile legitimate sites across the web.<br />
<br />
This campaign serving fake flash players is getting so prevalent these days due to the multiple spamming approaches used, that it's hard not to notice it - and expose it. From a strategic perspective, having a legitimate low-profile site -- of course with the obvious exceptions being on purposely registered for malicious purposes within the participating sites -- hosting your malicious campaign is pretty creative in terms of forwarding the responsibility, and the eventual blocking of a legitimate site to the its owner. As far as the owner's are concerned, it appears that some of them are already seeing the malware page popping-up on the top of their daily traffic stats, and have taken measures to remove it.<br />
<br />
Moreover, <a href="http://blogs.adobe.com/psirt/2008/08/verifying_installers.html">Adobe's Product Security Incident Response Team (PSIRT) issued a warning notice about the attack yesterday</a>, which could come handy if the <a href="http://www.infoworld.com/article/08/08/05/Adobe_warns_of_bogus_Flash_Player_installers_1.html">attackers weren't taking advantage of client-side vulnerabilities</a>, putting the unware end user is a situation where he <a href="http://blogs.stopbadware.org/articles/2008/08/05/same-dogs-new-tricks">wouldn't even receive a download dialog</a> :<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/LuFjz3rFLAc/s1600-h/fake_flash3_exploit.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/GXwA3Ai1LLY/s200-R/fake_flash3_exploit.jpg" style="border: 0pt none ;" /></a>"<i>We have seen coverage from the security community of a worm on popular social networking sites that is using social engineering lures to get users to install a piece of malware. According to the reports, the worm posts comments on these sites that include links to a fake site. If the link is followed, users are told they need to update their Flash Player. The installer, posted on a malicious site, of course installs malware instead of Flash Player.We’d like to take this opportunity to reiterate the importance of validating installers and updates before installing them. First off, do not download Flash Player from a site other than adobe.com – you can find the link for downloading Flash Player here. This goes for any piece of software (Reader, Windows Media Player, Quicktime, etc.) – if you get a notice to update, it’s not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious.</i>"<br />
<br />
<a href="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/6PfKZxTNQao/s1600-h/fake_flash2.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/ADBheDs2hkk/s200-R/fake_flash2.png" style="border: 0pt none ;" /></a>The structure of the malware campaign is pretty static, with several exceptions where they also take advange of client-side vulnerabilities (Real player exploit) attempting to automatically deliver the fake flash update or player depending on the campaign. On each and every site, there are <b>dnd.js</b> and <b>master.js</b> scripts shich serve the rogue download window, and another .html file, where an IFRAME attempts to access the traffic management command and control, in a random URL it was <b>207.10.234.217/cgi-bin/index.cgi?user200</b>. A sample list of participating URLs, most of which are still active and running :<br />
<br />
<div style="text-align: left;"><b>joseantoniobaltanas .com</b></div><b>automoviliaria .es/hotnews.html<br />
risasnc .it/fresh.html<br />
carpe-diem .com.mx/fresh.html<br />
kotilogullari .com.tr/hotnews.html<br />
ferrariclubpesaro .it/hotnews.html<br />
imobiliariacom .com.br/default.html<br />
misoares .com<br />
osniehus .de/fresh.html<br />
mydirecttube .com/1/5098/<br />
madosma .com/default.html<br />
tutotic .com/checkit.html<br />
veit-team .si/default.html<br />
antigewaltkurse .de/stream.html<br />
kwhgs .ca/topnews.html<br />
vorgo .com/stream.html<br />
ankaraspor .com.tr/default.html<br />
xxxdnn0314 .locaweb.com.br/watchit.html<br />
ossuzio .com/watchit.html<br />
cit-inc .net/default.html<br />
negocioindependiente .biz/default.html<br />
ambermarketing .com/topnews.html<br />
web27 .login-7.loginserver.ch/stream.html<br />
moretewebdesign .br-web.com/stream.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/hotnews.html<br />
campodifiori .it/topnews.html<br />
212.50.55.81 /stream.html<br />
logisigns .net/fresh.html<br />
intimaescorts .com/default.html<br />
ghioautotre .it/live.html<br />
geckert .de/stream.html<br />
yuricardinali .com/watchit.html<br />
retder .com/fresh.html<br />
valdaran .es/default.html<br />
getadultaccess .com/movie/?aff=5274<br />
bauelemente-giering .de/stream.html<br />
newyork-hebergement .com/watchit.html<br />
allevatoritrotto .it/live.html<br />
exoss2 .com/hotnews.html<br />
soundandlightkaraoke .com/stream.html<br />
land-kan .com/stream.html<br />
grimaldi.nexenservices .com/watchit.html<br />
inconstancia .com.br/watchit.html <br />
gretelstudio .com/stream.html<br />
sumacyl .com/watchit.html<br />
mysna .net/fresh.html<br />
gimnasioyx .com.ar/watchit.html<br />
lagalbana .com/watchit.html<br />
bielizna.tgory .pl/topnews.html<br />
bcs92.imingo .net/stream.html<br />
lapiramidecoslada .es/topnews.html<br />
raulortega .com/stream.html<br />
go-art-morelli .de/hotnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
dianagraf .es/default.html<br />
komma10-thueringen .de/hotnews.html<br />
miavassilev .com/stream.html<br />
swampgiants .com/watchit.html<br />
compagniedephalsbourg .com/fresh.html<br />
arla-rc .net/hotnews.html<br />
salacopernico .es/watchit.html<br />
drfinster .de/checkit.html<br />
healthylifehypnotherapy .com/stream.html<br />
ecotrike-bg .com/fresh.html<br />
paoepalavra .org/watchit.html<br />
jureplaninc-sp .com/topnews.html<br />
fichte-lintfort .de/default.html<br />
hergert-band .de/checkit.html<br />
izliyorum .org/topnews.html<br />
lideka .com/stream.html<br />
athena-digitaldesign .com.tw/hotnews.html<br />
e-paso .pl/stream.html<br />
colombeblanche .org/stream.html<br />
teatromalasa .es/watchit.html<br />
mesporte.digiweb.com .br/stream.html<br />
bistrodavila.com .br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
jbhumet .com/default.html<br />
gruppouni .com/hotnews.html<br />
francex .net/fresh.html<br />
galvatoledo .com/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
kroenert .name/default.html<br />
textilhogarnovadecor .com/topnews.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
neticon .pl/hotnews.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
easterstreet .de/fresh.html<br />
piogiovannini .com.ar/watchit.html<br />
ser-all .com/topnews.html<br />
petzold-dieter .de/checkit.html<br />
beatmung-brandenburg .de/checkit.html<br />
ossuzio .com/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
zelenaratolest .cz/pornotube/index1.htm<br />
ambulatoriovirtuale .it/topnews.html<br />
10a3 .ru/index1.php<br />
izliyorum .org/topnews.html<br />
collectedthoughts .co.uk/index12.html<br />
afg .es/topnews.html<br />
albertruiz .net/topnews.html<br />
bielizna.tgory .pl/topnews.html<br />
blueseven.com .br/topnews.html<br />
bollettinogiuridicosanitario .it/topnews.html<br />
caprilchamonix.com .br/topnews.html<br />
carlolongarini .it/topnews.html<br />
champimousse .com/topnews.html<br />
cheviot.org .nz/topnews.html<br />
contrapie .com/topnews.html<br />
gruppouni .com/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
herbatele .com/topnews.html<br />
houseincostaricaforsale .com/topnews.html<br />
alim.co .il/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
amafe .org/topnews.html<br />
ambulatoriovirtuale .it/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
automoviliaria .es/topnews.html<br />
autoreserve .fr/topnews.html<br />
izliyorum .org/topnews.html<br />
jureplaninc-sp .com/topnews.html<br />
kwhgs .ca/topnews.html<br />
lapiramidecoslada .es/topnews.html<br />
last-minute-reisen-4u .de/topnews.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
corradiproject .info/topnews.html<br />
dantealighieriasturias .es/topnews.html<br />
deliriuslaspalmas .com/topnews.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/topnews.html<br />
fonavistas .com/topnews.html<br />
fraemma .com/topnews.html<br />
fundmyira .com/topnews.html<br />
galvatoledo .com/topnews.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
markmaverick .com/topnews.html<br />
micela .info/topnews.html<br />
motoclubnosvamos .com/topnews.html<br />
nebottorrella .com/topnews.html<br />
negozistore .it/topnews.html<br />
neticon .pl/topnews.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
segelclub-honau .de/topnews.html<br />
snmobilya .com/topnews.html<br />
splashcor .com.br/topnews.html<br />
stephanmager .gmxhome.de/topnews.html<br />
svcanvas .com/topnews.html<br />
tautau.web .simplesnet.pt/topnews.html<br />
textilhogarnovadecor .com/topnews.html<br />
theflorist4u .com/topnews.html<br />
thewindsorhotel .it/topnews.html<br />
vuelosultimahora .com/topnews.html<br />
aliarzani .de/topnews.html<br />
ambermarketing .com/topnews.html<br />
arnold82.gmxhome .de/topnews.html<br />
ocoartefatos.com .br/topnews.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
projetsoft .net/topnews.html<br />
rbc.gmxhome .de/topnews.html<br />
beatmung-sachsen .eu/topnews.html<br />
campodifiori .it/topnews.html<br />
clickjava .net/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
dammer .info/topnews.html<br />
embedded-silicon .de/topnews.html<br />
ferrariclubpesaro .it/topnews.html<br />
fgwiese .de/topnews.html<br />
fswash.site .br.com/topnews.html<br />
fytema .es/topnews.html<br />
gildas-saliou. com/topnews.html<br />
go-art-morelli .de/topnews.html<br />
go-siegmund .de/topnews.html<br />
guerrero-tuning .com/topnews.html<br />
gut-barbarastein .de/topnews.html<br />
japansec .com/topnews.html<br />
komma10-thueringen .de/topnews.html<br />
koon-design .de/topnews.html<br />
lanz-volldiesel .de/topnews.html<br />
lauscher-staat .de/topnews.html<br />
losnaranjos.com .es/topnews.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
nepi.si/topnews .html<br />
radieschenhein. de/topnews.html<br />
residenceflora .it/topnews.html<br />
sabuha .de/topnews.html<br />
ser-all .com/topnews.html<br />
siemieniewicz .de/topnews.html<br />
viajesk .es/topnews.html<br />
allevatoritrotto .it/live.html<br />
bollettinogiuridicosanitario .it/live.html<br />
carlolongarini .it/topnews.html<br />
maremax .it/topnews.html<br />
negozistore .it/topnews.html<br />
parapendiolestreghe .it/live.html<br />
www.donlisander .it/stream.html<br />
aerogenesis .net/watchit.html<br />
allevatoritrotto .it/live.html<br />
atelier-de-loulou .fr/topnews.html<br />
bistrodavila.com .br/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
caprilchamonix.com .br/topnews.html<br />
cheviot.org .nz/live.html<br />
condorautocenter .com.br/watchit.html<br />
dantealighieriasturias .es/live.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/live.html<br />
fonavistas .com/topnews.html<br />
fundmyira .com/topnews.html<br />
g6esporte .com.br/stream.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
gretelstudio .com/stream.html<br />
gutierrezymoralo .com/watchit.html<br />
healthylifehypnotherapy .com/stream.html<br />
herbatele .com/live.html<br />
jureplaninc-sp .com/topnews.html<br />
lacomercialsrl .com.ar/stream.html<br />
lagalbana .com/watchit.html<br />
lapuertaestrecha .com.es/watchit.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
myadultcube .com/flash//aff=5176<br />
myadultcube .com/flash//aff=5810<br />
myadultcube .com/movie//aff=5155<br />
newyork-hebergement .com/watchit.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
omdconsulting .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
parapendiolestreghe .it/live.html<br />
regesh. co.il/watchit.html<br />
rikkeroenneberg .dk/watchit.html<br />
s215847279 .onlinehome.fr/stream.html<br />
salacopernico .es/watchit.html<br />
seekzones .com/watchit.html<br />
seicomsl .es/watchit.html<br />
sigma-lux .ro/watchit.html<br />
soundandlightkaraoke .com/stream.html<br />
stephanmager.gmxhome .de/topnews.html<br />
tartuinstituut .ca/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
aliarzani .de/topnews.html<br />
ambermarketing. com/live.html<br />
bilbondo .com/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
colombeblanche .org/stream.html<br />
donlisander .it/stream.html<br />
fgwiese .de/topnews.html<br />
geckert .de/stream.html<br />
helene-taucher .de/watchit.html<br />
lanz-volldiesel .de/topnews.html<br />
mairie-margnylescompiegne .fr/watchit.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
ossuzio .com/watchit.html<br />
piogiovannini .com.ar/watchit.html<br />
sabuha .de/topnews.html<br />
sumacyl .com/watchit.html<br />
swampgiants .com/watchit.html<br />
xn--glland-3ya .de/stream.html<br />
yuricardinali .com/watchit.html</b><br />
<b>nepi .si/topnews.html<br />
dammer .info/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
galvatoledo .com/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
micela .info/topnews.html<br />
bistrodavila .com.br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
gruppouni .com/hotnews.html<br />
galvatoledo .com/topnews.html<br />
kroenert .name/default.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
dantealighieriasturias .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
89.19.29 .13/stream.html<br />
slobodandjakovic .com/fresh.html<br />
cqcs.com .br/stream.html<br />
seekzones .com/watchit.html<br />
pascosa .it/stream.html<br />
caprilchamonix .com.br/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
ferien-urlaub-lastminute .de/default.html<br />
mueggelpark .info/watchit.html<br />
hillner-online .de/fresh.html<br />
guiasaojose .net/default.html<br />
deliriuslaspalmas .com/topnews.html<br />
fraemma .com/topnews.html<br />
morsbaby .net/default.html<br />
vickywhite .com/fresh.html<br />
micela .info/topnews.html<br />
corradiproject .info/topnews.html<br />
liguehavraise .com/live.html<br />
capacitacaoemlideranca .com.br/fresh.html<br />
materialesyacabados .com.mx/stream.html<br />
208.112.7.68 /checkit.html<br />
152.10.1.37 /1.html<br />
carlolongarini .it/topnews.html<br />
splashcor.com .br/topnews.html<br />
lobpreisstrasse .org/1.html<br />
motoclubnosvamos .com/hotnews.html<br />
hk-rc.com /1.html<br />
taaf.re /stream.html<br />
dulceysalao .com/default.html<br />
amafe .org/topnews.html <br />
</b><br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/MTxnF1XLDCw/s1600-h/fake_flash3_rogue_software.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/3Dgh4x23dRs/s200-R/fake_flash3_rogue_software.png" style="border: 0pt none ;" /></a>Sample detection rate : <span id="status_nombre">flashupdate.exe</span><br />
<span id="status_nombre"><b>Scanners Result</b>: 35/36 (97.23%)</span><br />
<span id="status_nombre">Trojan-Downloader.Win32.Exchanger.hk; Troj/Cbeplay-A</span><br />
<b>File size</b>: 78848 bytes<br />
<b>MD5</b>...: c81b29a3662b6083e3590939b6793bb8<br />
<b>SHA1</b>..: d513275c276840cb528ce11dd228eae46a74b4b4<br />
<br />
The downloader then "phones back home" at <b>72.9.98.234 port 443 </b>which is responding to the rogue security software AntiSpy Spider (<b>antispyspider.net</b>) :<br />
<br />
"<i>AntiSpy Spider is a cutting-edge anti-spyware solution.This revolutionary anti-spyware program was created by the industry's top spyware experts in order to protect your computer and your privacy.html, while ensuring optimal system performance.With the ability to locate, eliminate and prevent the widest range of spyware threats, AntispyStorm is able to offer its users a safe, spyware-free computing experience; and with it's convenient automatic update feature, AntispyStorm ensures continuous up-to-date protection.</i>" <br />
<br />
Sample detection rate : antispyspider.msi<br />
<b>Scanners Result</b>: 11/35 (31.43%)<br />
FraudTool.Win32.AntiSpySpider.b;&nbsp; <br />
<b>File size</b>: 1851904 bytes<br />
<b>MD5</b>...: 2f1389e445f65e8a9c1a648b42a23827<br />
<b>SHA1</b>..: e32aa6aa791e98fe6fdef451bd3b8a45bad0acd8<br />
<br />
The bottom line - over a thousand domains are participating, with many other apparently joining the party proportionally with the web site owner's actions to get rid of the malware campaign hosted on their servers.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BvcTqK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BvcTqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=onawHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=onawHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fa1ek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fa1ek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5nQAgk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5nQAgk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sqdHIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sqdHIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mq3LKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mq3LKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8zplkk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8zplkk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/356677080" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 10:50:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/html file">html file</category>
      <category domain="http://securityratty.com/tag/html">html</category>
      <category domain="http://securityratty.com/tag/comtopnews">comtopnews</category>
      <category domain="http://securityratty.com/tag/detopnews">detopnews</category>
      <category domain="http://securityratty.com/tag/windows media player">windows media player</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/real player exploit">real player exploit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/356677080/compromised-web-servers-serving-fake.html">Compromised Web Servers Serving Fake Flash Players</source>
    </item>
    <item>
      <title><![CDATA[The Twitter Malware Campaign Wants to Bank With You]]></title>
      <link>http://securityratty.com/article/0a86c9e6b40c8995b8c3f84a2d12480a</link>
      <guid>http://securityratty.com/article/0a86c9e6b40c8995b8c3f84a2d12480a</guid>
      <description><![CDATA[In what appears to be a lone gunman malware campaign -- where the malware spreader even left his email address within the binary - the now down Twitter malware campaign managed to attract only 69...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJgk-RghwII/AAAAAAAAB_c/xbrYBDO4K9Q/s1600-h/twitter_malware1.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJgk-RghwII/AAAAAAAAB_c/om2-uxKUmR4/s200-R/twitter_malware1.JPG" style="border: 0pt none ;" /></a>In <a href="http://www.twitpwn.com/2008/08/coming-up-malware-on-twitter.html">what appears to</a> be a lone gunman <a href="http://www.viruslist.com/en/weblog?weblogid=208187551">malware campaign</a> -- where the malware spreader even left his email address within the binary - the now down <a href="http://blogs.guardian.co.uk/technology/2008/08/05/twiters_trojan_problem.html">Twitter malware campaign</a> managed to attract only 69 followers before it has shut down, <a href="http://www.techcrunch.com/2008/07/27/who-is-johng77536-and-how-did-he-game-twitter/">using a trivial approach</a> for launching an XSS worm - <a href="http://en.wikipedia.org/wiki/Cross-site_request_forgery">Cross-site request forgery</a> (CSRF). More info :<br />
<br />
"<i>This week it’s Twitter’s turn to host an attack - one that is targeting both Twitter users and the Internet community at large. In this case it's a malicious Twitter profile twitter.com/[skip]/ with a name that is Portuguese for ‘pretty rabbit’ which has a photo advertising a video with girls posted.&nbsp;</i><br />
<br />
<i>This profile has obviously been created especially for infecting users, as there is no other data except the photo, which contains the link to the video. If you click on the link, you get a window that shows the progress of an automatic download of a so-called new version of Adobe Flash which is supposedly required to watch the video. You end up with a file labeled Adobe Flash (it’s a fake) on your machine; a technique that is currently very popular.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJg7qxrXS-I/AAAAAAAAB_k/X5JjQEBfcgc/s1600-h/twitter_malware.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJg7qxrXS-I/AAAAAAAAB_k/tnrV5eIbz1M/s200-R/twitter_malware.JPG" style="border: 0pt none ;" /></a>Let's analyze the campaign before it was shut down. The original Twitter account used <b>twitter.com/video_kelly_key</b> basically included a link to <b>player-video-youtube.sytes.net</b> (204.16.252.98) which was using a URL shortening service <b>fly2.ws/NilOMN3</b> in order to redirect to the banker malware located at <b>freewebtown.com/construimagens/ Play-video-youtube.kelly-key.com</b>. It's detection rate is as follows :<br />
<br />
<b>Scanners Result</b>: 14/36 (38.89%)<br />
Trojan-Spy.Win32.Banker.caw <br />
<b>File size</b>: 88064 bytes<br />
<b>MD5</b>...: 25600af502758ca992b9e7fff3739def<br />
<b>SHA1</b>..: 9262ca501ef388e0fe42c50a3d002ddbd6e254f2<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJg8dgf3PnI/AAAAAAAAB_s/zemAG6fn3rM/s1600-h/xss_csrfworm.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJg8dgf3PnI/AAAAAAAAB_s/lOjia4dpUaw/s200-R/xss_csrfworm.png" style="border: 0pt none ;" /></a>Twitter isn't an exception to the realistic potential for <a href="http://0x000000.com/index.php?i=512&amp;bin=1000000000">XSS worms though CSRF that could affect each and every Web 2.0 service</a>, which as a matter of fact have all suffered such attempts, namely, <a href="http://ha.ckers.org/blog/20071220/orkut-xss-worm" title="Orkut XSS Worm">Orkut</a>, <a href="http://en.wikipedia.org/wiki/Samy_%28XSS%29" title="Samy MySpace XSS Worm">MySpace</a> (as well as the <a href="http://securitylabs.websense.com/content/Alerts/1319.aspx" title="MySpace QuickTime XSS Flaw">QuickTime XSS flaw</a>), <a href="http://blogs.securiteam.com/index.php/archives/786" title="GaiaOnline XSS Worm">GaiaOnline</a>, <a href="http://sirdarckcat.blogspot.com/2007/12/making-social-network-xss-worm-hi5com.html" title="Hi5 XSS Worm">Hi5</a>, and most recently the <a href="http://blogs.zdnet.com/security/?p=1487">XSS worm at Justin.tv</a>, demonstrate that trivial vulnerabilities come handy for what's to turn into a major security incident if not taken care of promptly.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/05/xss-planet.html">XSS The Planet</a><br />
<a href="http://ddanchev.blogspot.com/2007/02/xss-vulnerabilities-in-e-banking-sites.html">XSS Vulnerabilities in E-banking Sites</a><br />
<a href="http://ddanchev.blogspot.com/2006/05/current-state-of-web-application-worms.html">The Current State of Web Application Worms</a><br />
<a href="http://ddanchev.blogspot.com/2007/06/g0t-xssed.html">g0t XSSed?</a><br />
<a href="http://ddanchev.blogspot.com/2006/06/web-application-email-harvesting-worm.html">Web Application Email Harvesting Worm </a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oWAtgK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oWAtgK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=L5UJoK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=L5UJoK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dlgqak"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dlgqak" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3uAsZk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3uAsZk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=YHdd5K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=YHdd5K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AezGSK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AezGSK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JZQeBk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JZQeBk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/356281978" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 03:14:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/twitter">twitter</category>
      <category domain="http://securityratty.com/tag/twitter malware campaign">twitter malware campaign</category>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <category domain="http://securityratty.com/tag/xss vulnerabilities">xss vulnerabilities</category>
      <category domain="http://securityratty.com/tag/original twitter account">original twitter account</category>
      <category domain="http://securityratty.com/tag/xss worms">xss worms</category>
      <category domain="http://securityratty.com/tag/xss worm">xss worm</category>
      <category domain="http://securityratty.com/tag/twitter users">twitter users</category>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/356281978/twitter-malware-campaign-wants-to-bank.html">The Twitter Malware Campaign Wants to Bank With You</source>
    </item>
    <item>
      <title><![CDATA[Storm Worm's U.S Invasion of Iran Campaign]]></title>
      <link>http://securityratty.com/article/686d338a8ac6a206c4c3d47b2722c28e</link>
      <guid>http://securityratty.com/article/686d338a8ac6a206c4c3d47b2722c28e</guid>
      <description><![CDATA[The Storm Worm-ers are keeping themselves busy, with two campaigns in less than a week, following the latest on the 4th of July . Now, they are spreading rumors of a U.S invasion in Iran

Just now US...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHQBeI4jtwI/AAAAAAAAB5M/-nE4lyzJG7A/s1600-h/stormworm_US_Iran.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHQBeI4jtwI/AAAAAAAAB5M/z4nlOvtbAEs/s200-R/stormworm_US_Iran.png" style="border: 0pt none ;" /></a>The Storm Worm-ers are keeping themselves busy, with two campaigns in less than a week, following the latest on <a href="http://blogs.zdnet.com/security/?p=1440">the 4th of July</a>. Now, they are spreading rumors of a U.S invasion in Iran :<br />
<br />
"<i>Just now US Army's Delta Force and U.S. Air Force have invaded Iran. Approximately 20000 soldiers crossed the border into Iran and broke down the Iran's Army resistance. The video made by US soldier was received today morning. Click on the video to see first minutes of the beginning of the World War III. God save us.</i>"<br />
<br />
The campaign is using the following domains :<br />
<b>statenewsworld .com</b><br />
<b>morenewsonline .com</b><br />
<b>dailydotnews .com</b><br />
<b>dotdailynews .com</b><br />
<b>newsworldnow .com</b><br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<b>All registered by the same individual :</b><br />
ONLINE&nbsp; CO REANIMATOR (dfgdgf@gmail.com)<br />
REVA 13-27 Deribaska 3565,198346 DZ Tel. +321.3568872<br />
<br />
<b>Sample detection rate :</b><br />
iran_occupation.exe<br />
Scanners Result: 4/33 (12.13%)<br />
File size: 118273 bytes<br />
MD5...: 19ab8f1dddb743c1dc2924cb61d3f877<br />
SHA1..: e0915f377020479ba95ffed0fcb07a2b2aec72f4<br />
<br />
<a href="http://bp3.blogger.com/_wICHhTiQmrA/SHQKR1MmyrI/AAAAAAAAB5U/ndcj_NbcPYU/s1600-h/storm_worm_likethisone_DNS.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SHQKR1MmyrI/AAAAAAAAB5U/BiXnjiE0FV4/s320-R/storm_worm_likethisone_DNS.png" style="border: 0pt none ;" /></a> Storm Worm domains used in recent campaigns, still parked on infected hosts :<br />
<br />
<b>superlovelyric .com</b><br />
<b>bestlovelyric .com</b><br />
<b>makingloveworld .com</b><br />
<b>statenewsworld .com</b><br />
<b>wholoveguide .com</b><br />
<b>gonelovelife .com</b><br />
<b>loveisknowlege .com</b><br />
<b>lovekingonline .com</b><br />
<b>lovemarkonline .com</b><br />
<b>wholefireworksonline .com</b><br />
<b>morenewsonline .com</b><br />
<b>makingadore .com</b><br />
<b>greatadore .com</b><br />
<b>yourfireworksstore .com</b><br />
<b>loveoursite .com</b><br />
<b>dayfireworkssite .com</b><br />
<b>musiconelove .com</b><br />
<b>knowholove .com</b><br />
<b>whoisknowlove .com</b><br />
<b>theplaylove .com</b><br />
<b>lovelifecash .com</b><br />
<b>wantcherish .com</b><br />
<b>shelovehimtoo .com</b><br />
<b>makeloveforever .com</b><br />
<b>bellestarfireworks .com</b><br />
<b>yourfireworks .com</b><br />
<b>worldbestfireworks .com</b><br />
<b>greatfireworkslaws .com</b><br />
<b>dailydotnews .com</b><br />
<b>dotdailynews .com</b><br />
<b>wholovedirect .com</b><br />
<b>newsworldnow .com</b><br />
<b>thefireworksjuly .com</b><br />
<b>grupogaleria .cn</b><br />
<b>polkerdesign .cn&nbsp;&nbsp;&nbsp; </b><br />
<b>nationwide2u .cn</b><br />
<b>activeware .cn</b><br />
<b>grupogaleria .cn</b><br />
<b>likethisone1 .com</b><br />
<b>lollypopycandy .com</b><br />
<b>nationwide2u .cn</b><br />
<b>polkerdesign .cn</b><br />
<b>verynicebank .com</b><br />
<b>thefireworksjuly .com</b><br />
<b>wholefireworksonline .com</b><br />
<b>worldbestfireworks .com</b><br />
<b>yourfireworks .com</b><br />
<b>bellestarfireworks .com</b><br />
<b>dayfireworkssite .com</b><br />
<b>greatfireworkslaws .com</b><br />
<b>yourfireworksstore .com</b><br />
<br />
The "best" is yet to come.<br />
<br />
<b>Related posts :</b><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/all-you-need-is-storm-worms-love.html">All You Need is Storm Worm's Love</a><br />
<a href="http://ddanchev.blogspot.com/2007/01/social-engineering-and-malware.html">Social Engineering and Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/02/storm-worm-switching-propagation.html">Storm Worm Switching Propagation Vectors</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/storm-worms-use-of-dropped-domains.html">Storm Worm's use of Dropped Domains</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/offensive-storm-worm-obfuscation.html">Offensive Storm Worm Obfuscation</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/storm-worms-st-valentine-campaign.html">Storm Worm's St. Valentine Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-ddos-attitude.html">Storm Worm's DDoS Attitude</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/riders-on-storm-worm.html">Riders on the Storm Worm</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/storm-worm-malware-back-in-game.html">The Storm Worm Malware Back in the Game</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9W9eqJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9W9eqJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ErCYhJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ErCYhJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fhypMj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fhypMj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=l8ef0j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=l8ef0j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mxGwGJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mxGwGJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WvlSXJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WvlSXJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jSALWj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jSALWj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/330319265" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 08 Jul 2008 16:07:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/storm worm">storm worm</category>
      <category domain="http://securityratty.com/tag/storm worm malware">storm worm malware</category>
      <category domain="http://securityratty.com/tag/storm worm-ers">storm worm-ers</category>
      <category domain="http://securityratty.com/tag/storm worm domains">storm worm domains</category>
      <category domain="http://securityratty.com/tag/iran">iran</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/iran occupation">iran occupation</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/330319265/storm-worms-us-invasion-of-iran.html">Storm Worm's U.S Invasion of Iran Campaign</source>
    </item>
    <item>
      <title><![CDATA[Underground Multitasking in Action]]></title>
      <link>http://securityratty.com/article/d7eefca5971c1beea7b12dfcdf31c358</link>
      <guid>http://securityratty.com/article/d7eefca5971c1beea7b12dfcdf31c358</guid>
      <description><![CDATA[How many ways in which a malicious party can abuse its unauthorized access to a host, can you think of? In this example of remotely file included web backdoor (web shell) , we have a malicious party...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SF1jzlKDFtI/AAAAAAAAB0s/E7VTlqUqrbM/s1600-h/underground_multitasking.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SF1jzlKDFtI/AAAAAAAAB0s/E7VTlqUqrbM/s200/underground_multitasking.png" alt="" id="BLOGGER_PHOTO_ID_5214433681363637970" border="0" /></a>How many ways in which a malicious party can abuse its unauthorized access to a host, can you think of? In this example of <a href="http://ddanchev.blogspot.com/2007/04/compilation-of-web-backdoors.html">remotely file included web backdoor (web shell)</a>, we have a malicious party that's hosting a web spammer, planning to launch a phishing attack impersonating Halifax, locally hosting blackhat SEO junk pages redirecting to rogue security software, redirecting to multiple live exploit URLs through javascript obfuscations, as well as to fake casinos and fake celebrity video sites - all from a single location.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SF-VmM2nMKI/AAAAAAAAB08/tqCHh34BklY/s1600-h/trru.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SF-VmM2nMKI/AAAAAAAAB08/tqCHh34BklY/s200/trru.jpg" alt="" id="BLOGGER_PHOTO_ID_5215051377036177570" border="0" /></a>This risk-forwarding process for all the malicious and criminal activities to the owner of the compromised web server is something usual, what's more interesting in this case is the number and diversity of the affiliations this guy has set up in order to monetize the unauthorized access by using all the possible sources of revenues like the ones I pointed on in a previous post regarding <a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">increasing monetization of web site defacements</a>.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SF-Wf9Qc2ZI/AAAAAAAAB1E/MzTQWzhYmlM/s1600-h/webshell_local_blackhat_pages.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SF-Wf9Qc2ZI/AAAAAAAAB1E/MzTQWzhYmlM/s200/webshell_local_blackhat_pages.JPG" alt="" id="BLOGGER_PHOTO_ID_5215052369281997202" border="0" /></a>In fact, he seems to have built enough confidence in the new "hosting provider", that he's even hosting his blackhat SEO advetising services there. The multiple javascript obfuscations hosted locally, point to the following malicious domains which expose all the revenue generating affiliations, and even more malicious doorways :<br /><br /><span style="font-weight: bold;">analytics-google .info</span><span style="font-weight: bold;">/q/urchin.js</span> <span style="font-weight: bold;"><br />209.205.196.16/freehost22/paula2/index.php?id=0271</span> <span style="font-weight: bold;"><br />209.205.196.16/freehost22/paula2/exxe.php?id=0271</span> <span style="font-weight: bold;"><br />crklab .us/index.php</span> <span style="font-weight: bold;"><br />my-page-de .info/in.cgi?2&amp;1400397</span> <span style="font-weight: bold;"><br />tapki .cn/1.html?92465</span> <span style="font-weight: bold;"><br />dificalgot .net/s/in.cgi?2?1121268b0d022308</span><span style="font-weight: bold;"><br />my-page-de .info?default.cgi</span> <span style="font-weight: bold;"><br />magichotgaming .net</span><br /><span style="font-weight: bold;">allextra .com/best/go.php?sid=2&amp;tds-parametr1=Taryn+Manning</span> <span style="font-weight: bold;"><br />newextra .com/in.cgi?19&amp;group=allextra</span> <span style="font-weight: bold;"><br />drivemedirect .com/soft.php?aid=0358&amp;d=3&amp;product=XPA</span> <span style="font-weight: bold;">securityscannersite .com/2008/3/freescan.php?aid=880358</span><br /><br />Sampe detection rate for the <a href="http://ddanchev.blogspot.com/2007/11/malware-serving-online-casinos.html">casino adware</a>, a reminder on why you shouldn't <a href="http://ddanchev.blogspot.com/2007/09/dont-play-poker-on-infected-table.html">play poker on an infected table</a> :<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SF-U6RowtHI/AAAAAAAAB00/vHw6HTi6XUo/s1600-h/gold_vip_casino_adware.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SF-U6RowtHI/AAAAAAAAB00/vHw6HTi6XUo/s200/gold_vip_casino_adware.JPG" alt="" id="BLOGGER_PHOTO_ID_5215050622406014066" border="0" /></a>Scanners result : 7/33 (21.22%)<br />Trojan.Casino.466752; W32/Casino.A.gen!Eldorado; Adware.Casino-18<br />File size: 466752 bytes<br />MD5...: b0f70441dde5c2b82ba5388f3d566576<br />SHA1..: 5603b1b972e2cff99d6339fbd8970278f5ff371d<br /><br /><br />To sum up - with the overall availability of <a href="http://ddanchev.blogspot.com/2008/03/phishing-pages-for-every-bank-are.html">templates for phishing sites</a>, fake video sites, <a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">fake security software</a>, as well as the ongoing traffic management tool's convergence with web malware exploitation kits, the opportunity for a malicious party to participate in different <a href="http://ddanchev.blogspot.com/2007/10/incentives-model-for-pharmaceutical.html">affiliate based scams on revenue sharing basis</a>, increases. Therefore, what looked like an isolated attack, is slowly becoming an "attack in between" the rest of the malicious activities lunched by the same party.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KXKt5I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KXKt5I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f8500I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f8500I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NFnQOi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NFnQOi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xXyrgi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xXyrgi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TN7skI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TN7skI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=P5KP1I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=P5KP1I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=H4J7gi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=H4J7gi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/318122235" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 23 Jun 2008 05:20:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/malicious domains">malicious domains</category>
      <category domain="http://securityratty.com/tag/party">party</category>
      <category domain="http://securityratty.com/tag/malicious party">malicious party</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/multiple javascript obfuscations">multiple javascript obfuscations</category>
      <category domain="http://securityratty.com/tag/javascript obfuscations">javascript obfuscations</category>
      <category domain="http://securityratty.com/tag/malicious activities">malicious activities</category>
      <category domain="http://securityratty.com/tag/casino adware">casino adware</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/318122235/underground-multitasking-in-action.html">Underground Multitasking in Action</source>
    </item>
    <item>
      <title><![CDATA[Fake YouTube Site Serving Flash Exploits]]></title>
      <link>http://securityratty.com/article/05a0a3aecae41b8680c264c36b2e1800</link>
      <guid>http://securityratty.com/article/05a0a3aecae41b8680c264c36b2e1800</guid>
      <description><![CDATA[Originally mentioned by the folks at Sunbelt, this fake YouTube site happens to be a bit more interesting than it seems at the first place

Clicking on that link then redirects to a different site,...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SFEJJvf6l-I/AAAAAAAAByI/TqpRO54ISd0/s1600-h/fake_youtube_flash_exploits.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SFEJJvf6l-I/AAAAAAAAByI/TqpRO54ISd0/s200/fake_youtube_flash_exploits.png" alt="" id="BLOGGER_PHOTO_ID_5210956306818176994" border="0" /></a>Originally mentioned by the folks at Sunbelt, this <a href="http://sunbeltblog.blogspot.com/2008/06/dangerous-youtube-spoof.html">fake YouTube site</a> happens to be a bit more interesting than it seems at the first place :<br /><br />"<span style="font-style: italic;">Clicking on that link then redirects to a different site, youtube-s, which serves exploits to attempt to infect your system.  Then, if your browser hasn’t completely crashed at that point, you may ultimately get redirected to the real YouTube, displaying some idiotic video (he</span><span style="font-style: italic;">nce, possibly even helping to continue the infection, by having users forward the spam above)</span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFEOU1gg68I/AAAAAAAAByQ/i2QPNRQY56U/s1600-h/fake_youtube_obfuscated.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFEOU1gg68I/AAAAAAAAByQ/i2QPNRQY56U/s200/fake_youtube_obfuscated.JPG" alt="" id="BLOGGER_PHOTO_ID_5210961994968001474" border="0" /></a>Interesting mostly because it not just attempts to serve a online games password stealer through exploiting the ubiquitous MDAC exploit, but is <a href="http://ddanchev.blogspot.com/2008/05/malware-attack-exploiting-flash-zero.html">also serving a flash exploit</a> which when analyzed leads us to a web based C&amp;C of new malware kit. And although I've been aware of its existence for a while now, it's the first time I see it in action.<br /><br />Upon analyzing <span style="font-weight: bold;">yout</span><span style="font-weight: bold;">ube-r.com</span> (211.95.79.57) a couple of days ago, it's now returning a 403 forbidden message, however, copies of the malware have already been obtained and analyzed. In between attempting to infect with MDAC at <span style="font-weight: bold;">youtube-s.com/load.php?id=912</span>;  the flash exploit loads from <span style="font-weight: bold;">a9rhiwa.cn/update_files/1.swf</span>, and while this is happening the end user is redirected to the real YouTube site. Some sample detection rates :<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFEOeW_qEyI/AAAAAAAAByY/3WrhqBeFukY/s1600-h/fake_youtube_deobfuscated.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFEOeW_qEyI/AAAAAAAAByY/3WrhqBeFukY/s200/fake_youtube_deobfuscated.JPG" alt="" id="BLOGGER_PHOTO_ID_5210962158575817506" border="0" /></a>Scanners result : 7/32 (21.88%)<br /><span style="font-weight: bold;">TR/Crypt.ULPM.Gen; Mal/EncPk-CO</span><br />File size: 8704 bytes<br />MD5...: cb8611db343067e1fb663ab6ee671114<br />SHA1..: 4497715e0a365863d6ca41ab12254bf591118ed7<br /><br />Scanners result : 10/32 (31.25%)<br /><span style="font-weight: bold;">SWF:CVE-2007-0071; Exploit:Win32/APSB08-11.gen!A</span><br />File size: 593 bytes<br />MD5...: 5b6b28d4de3df92f48fbe5e8bd565cda<br />SHA1..: 3123d357d2080d1ee09ee67203275d51332e3397<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFEPvXtqFmI/AAAAAAAAByg/6P2dXgo0944/s1600-h/web_based_malware_CC.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFEPvXtqFmI/AAAAAAAAByg/6P2dXgo0944/s200/web_based_malware_CC.JPG" alt="" id="BLOGGER_PHOTO_ID_5210963550338160226" border="0" /></a>The password stealer than connects to the C&amp;C, from where an unknown for the time being number of campaigns are coordinated. What's a useless virtual good such as passwords for MMORPGs for malware gangs aiming to steal Ebanking details through banking malware for instance, is <a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">a precious and valuable good for others</a> operating on the other side of the world, where a virtual item is <a href="http://ddanchev.blogspot.com/2008/06/price-discrimination-in-market-for.html">more expensive than access to a Ebanking account</a>.<br /><span id="porcentaje"><span style="color:red;"></span></span><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7LxtgI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7LxtgI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9Rfx6I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9Rfx6I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=p6iizi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=p6iizi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mV3P0i"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mV3P0i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IJqqqI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IJqqqI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qrV0SI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qrV0SI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uiOjVi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uiOjVi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/310357579" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 03:12:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/fake youtube site">fake youtube site</category>
      <category domain="http://securityratty.com/tag/flash exploit loads">flash exploit loads</category>
      <category domain="http://securityratty.com/tag/flash exploit">flash exploit</category>
      <category domain="http://securityratty.com/tag/mdac">mdac</category>
      <category domain="http://securityratty.com/tag/ubiquitous mdac exploit">ubiquitous mdac exploit</category>
      <category domain="http://securityratty.com/tag/exploit">exploit</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/real youtube site">real youtube site</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/310357579/fake-youtube-site-serving-flash.html">Fake YouTube Site Serving Flash Exploits</source>
    </item>
    <item>
      <title><![CDATA[ImageShack Typosquatted to Serve Malware]]></title>
      <link>http://securityratty.com/article/c7b2b825a97f2f3aeed2e7cd75c2794a</link>
      <guid>http://securityratty.com/article/c7b2b825a97f2f3aeed2e7cd75c2794a</guid>
      <description><![CDATA[This is ironic because you have one of the most popular image sharing sites typosquatted, and malware served by copying ImageShack's directory structure, next using spoofed image files which are the...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SE_SBqvkqKI/AAAAAAAAByA/qlePOMkslgM/s1600-h/Imageshack.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SE_SBqvkqKI/AAAAAAAAByA/qlePOMkslgM/s320/Imageshack.png" alt="" id="BLOGGER_PHOTO_ID_5210614219986479266" border="0" /></a>This is ironic because you have one of the most popular image sharing sites typosquatted, and malware served by copying ImageShack's directory structure, next using spoofed image files which are the actual executables - "<a href="http://blogs.zdnet.com/security/?p=1266">Fake ImageShack site serving malware, links distributed over IM</a>"<br /><br />"<span style="font-style: italic;">The real ImageShack site is </span><strong style="font-style: italic;">imageshack.us</strong><span style="font-style: italic;">, however, the malware authors are impersonating ImageShack and using </span><strong style="font-style: italic;">imageshaack.org</strong><span style="font-style: italic;"> </span><strong style="font-style: italic;">(64.74.125.21)</strong><span style="font-style: italic;">, in particular<span style="font-weight: bold;"> </span></span><strong style="font-style: italic;">imageshaack.org/img/Picture275.jpg,</strong><span style="font-style: italic;"> which is where the malware is. Once the user gets infected with the malware, Backdoor.Win32.SdBot.eiu in this case, the host joins an IRC channel where the botnet masters continue issuing commands for the campaign to spread</span>"<br /><br />Scanners Results : 14/32 (43.75%)<br />Backdoor.Win32.SdBot.eiu; a variant of Win32/Injector.AV<br />File size: 31040 bytes<br />MD5...: eef33ca4036a5bf709f62098c55fb751<br />SHA1..: 5e7bdde09c760031c0a29cc0bb2ee2503aff3bf3<br /><br />The malware then connects to <span style="font-weight: bold;">simplythebest.mydyn.net:6532</span> (81.169.171.145) joining channel <span style="font-weight: bold;">#99993333</span> with password <span style="font-weight: bold;">plasma1991</span>, acting as the C&amp;C for this campaign spreading over MSN.<br /><span id="porcentaje"><span style="color:red;"></span></span><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jgLraI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jgLraI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3ALlOI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3ALlOI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7f36Gi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7f36Gi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rHLCDi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rHLCDi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7ueTJI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7ueTJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=V52gJI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=V52gJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fZVHhi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fZVHhi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/309635933" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 11 Jun 2008 04:47:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/imageshack">imageshack</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/fake imageshack site">fake imageshack site</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/real imageshack site">real imageshack site</category>
      <category domain="http://securityratty.com/tag/irc channel">irc channel</category>
      <category domain="http://securityratty.com/tag/channel">channel</category>
      <category domain="http://securityratty.com/tag/botnet masters continue">botnet masters continue</category>
      <category domain="http://securityratty.com/tag/scanners results">scanners results</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/309635933/imageshack-typosquatted-to-serve.html">ImageShack Typosquatted to Serve Malware</source>
    </item>
    <item>
      <title><![CDATA[Blackhat SEO Redirects to Malware and Rogue Software]]></title>
      <link>http://securityratty.com/article/2199017f7c1af4461b71026dc303b308</link>
      <guid>http://securityratty.com/article/2199017f7c1af4461b71026dc303b308</guid>
      <description><![CDATA[A black SEO farm with built-in redirection to a multitude of sites serving rogue codecs (Zlob malware variants) and fake security software phoning back to UkrTeleGroup Ltd's network - could it get...]]></description>
      <content:encoded><![CDATA[<div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SEe1DIDe2DI/AAAAAAAABxI/dNKrE60D00g/s1600-h/pornotubedirect1.JPG"><img id="BLOGGER_PHOTO_ID_5208330559383590962" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SEe1DIDe2DI/AAAAAAAABxI/dNKrE60D00g/s200/pornotubedirect1.JPG" border="0" /></a>A black SEO farm with built-in redirection to a multitude of sites serving rogue codecs (Zlob malware variants) and <a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">fake security software</a> phoning back to <a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">UkrTeleGroup Ltd's</a> network - could it get even more interesting? Of course, as the current state of Zlob malware serving tactics can be seperated in two distinct groups, those abusing the <a href="http://ddanchev.blogspot.com/2008/05/malware-attack-exploiting-flash-zero.html">"sort of" zero day Flash exploit</a>, as the currently <a href="http://ddanchev.blogspot.com/2008/05/yet-another-massive-sql-injection.html">active SQL injection attacks</a> are all taking advantage of it, and those still relying on plain simple redirect to multimedia sites requiring you to install the fake codec.<br /><br /><br /><div><div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SEe3eSO6t8I/AAAAAAAABxQ/GtMaVRNVy4E/s1600-h/blackhat_SEO_visualized.JPG"><img id="BLOGGER_PHOTO_ID_5208333224995633090" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/SEe3eSO6t8I/AAAAAAAABxQ/GtMaVRNVy4E/s200/blackhat_SEO_visualized.JPG" border="0" /></a>While tracking down the <a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">massive blackhat SEO poisoning campaigns</a> that took place in March, 2008, as well as the countless number of embedded/injected malware campaigns targeting high profile sites that we've been seeing recently, it's becoming increasingly common to come across a repeating malicious pattern. Basically, a <a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">domain portfolio of typosquatted domains</a> looking like legitimate codec sites is created, several bogus video, mostly p0rn related sites with no content start acting as a frontend to the codecs, where traffic is driven through blackhat SEO doorways. Moreover, rogue codec sites are increasing because the templates for the p0rn and codec sites are turning into a commodity, just like phishing pages and DIY phishing page generators lowering down the entry barriers into these practices.</div><br /><div><br /></div><div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SEfKn96fT7I/AAAAAAAABxY/kbygMpNzS54/s1600-h/blackhat_seo_codecs3.png"><img id="BLOGGER_PHOTO_ID_5208354282060861362" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SEfKn96fT7I/AAAAAAAABxY/kbygMpNzS54/s200/blackhat_seo_codecs3.png" border="0" /></a>Let's assess a sample redirection doorway, a visualization and sample traffic of which you can see in the attached screenshots. At <strong>porntubedirect.info </strong>we have a fake counter <strong>porntubedirect.info/stat/count.php</strong> loading the redirection script from <strong>216.240.139.234/sutra/in.cgi?3</strong> which is a javascript serving a different site on-the-fly, courtesy of a well known blackhat SEO campaign tool. The output of this redirection is a new domain serving Zlob variants in the form of fake codecs hosted under the following domains :</div><br /><div><strong>antivirus-scanonline.com</strong><br /></div><div><strong>indafuckfuck.com</strong></div><strong>newcontents2008.com</strong><br /><div><strong>avwav.com</strong></div><strong>anykindclips.com</strong><br /><div><strong>dirtyxxxvids.com</strong></div><strong>clipsmachines.com</strong><br /><div><strong>thesoft-portal-08.com</strong></div><br /><div>Sample detecton rates for the codecs obtained :<br /></div><div><br /></div><div>Scanners Result: 8/32 (25%)</div><span style="font-weight: bold;">W32/PolyZlob!tr.dldr; Trojan:Win32/Tibs.gen!lds</span><br /><div>File size: 119296 bytes </div>MD5...: dc5538af557cb4c311cb86d6574400ba<br /><div>SHA1..: 5cf1602db8c4fdd3c5ac5101e5a6c5daa77f5ff1</div><br /><div>Scanners Result: 6/32 (18.75%)<br /></div><div style="font-weight: bold;">Trojan-Downloader.Win32.FraudLoad.axa; Trojan.Dldr.FraudLoad.axa</div>File size: 60416 bytes<br /><div>MD5...: 14938bfe35128687e05f7f8ccbd29c7d </div>SHA1..: cf651e959fff945c9659321e79ba2788062b721d<br /><div><br /></div><div>Scanners Result: 14/32 (43.75%)</div><span style="font-weight: bold;">Trojan-Downloader.Win32.Zlob.lps; TrojanDownloader:Win32/Zlob.IB</span><br /><div>File size: 18432 bytes</div>MD5...: 9b3bbcd4549970a92eb1b11c46a451bb<br /><div>SHA1..: 679508aba4e547935d5e4104a735c754b40de49e</div><br /><div>Scanners Result: 18/32 (56.25%)<br /></div><div style="font-weight: bold;">Trojan-Downloader.Win32.Delf.ilx; TrojanDownloader:Win32/Chengtot.A</div>File size: 91683 bytes<br /><div>MD5...: 727e3f353281229128fdb1728d6ef345</div>SHA1..: 3f9c9000b273e8bf75db322382fbaabf333faf26<br /><div><br />Once we've managed to obtain several of the fake codec domains, passive DNS monitoring and using third-party tools helps us expose a huge portfolio of rogue domains such as :</div><br /><div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SEfM81C3WTI/AAAAAAAABxo/whvBq4dE_sE/s1600-h/blackhat_seo_codecs1.png"><img id="BLOGGER_PHOTO_ID_5208356839480580402" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SEfM81C3WTI/AAAAAAAABxo/whvBq4dE_sE/s200/blackhat_seo_codecs1.png" border="0" /></a><span style="font-weight: bold;">funfuckporn.com</span> <span style="font-weight: bold;"><br />musicpo</span><span style="font-weight: bold;">rtalfree.com</span> <span style="font-weight: bold;"><br />online-dvdrip.com</span> <span style="font-weight: bold;"><br />widget-porn.com</span> <span style="font-weight: bold;"><br />gt-funny.com</span> <span style="font-weight: bold;"><br />gt-movies.com</span><br /><span style="font-weight: bold;">gt-stars.com</span> <span style="font-weight: bold;"><br />hot-sextube.com</span> <span style="font-weight: bold;"><br />hot-pornotube-2008.com</span> <span style="font-weight: bold;"><br />hot-pornotube08.com</span> <span style="font-weight: bold;"><br />hotpornotube08.com</span> <span style="font-weight: bold;"><br />porn-youtube-08.org</span> <span style="font-weight: bold;"><br />uriy.org</span> <span style="font-weight: bold;"><br />sextube20008.com</span> <span style="font-weight: bold;"><br /></span><span style="font-weight: bold;">streamxxxvideo.com</span><br /><span style="font-weight: bold;">xxxgirlsgirls.com</span> <span style="font-weight: bold;"><br />porno-tube20008.com</span> <span style="font-weight: bold;"><br />2008adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />2008adults2008.com</span> <span style="font-weight: bold;"><br />adult18tube2008.com</span> <span style="font-weight: bold;"><br />sextube18adult.com</span> <span style="font-weight: bold;"><br />all-videos-home.com</span><br /><span style="font-weight: bold;">adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />onlinestreamvide.com</span> <span style="font-weight: bold;"><br />adultvideos4all.com</span> <span style="font-weight: bold;"><br />sex18tube2008.com</span> <span style="font-weight: bold;"><br />adultxx-18.com</span> <span style="font-weight: bold;"><br />mymediasex.com</span><br /><span style="font-weight: bold;">ladyxxxworld.com</span><br /><span style="font-weight: bold;">adultstreamportal.com</span> <span style="font-weight: bold;"><br />young-girls-board.com</span> <span style="font-weight: bold;"><br />porn-youtube08.net</span><br /><span style="font-weight: bold;">adultfreemarket.info</span> <span style="font-weight: bold;"><br />adult-codec08.com  </span> <span style="font-weight: bold;"><br />adult-tubecodec08.com   </span> <span style="font-weight: bold;"><br />adult-tubecodec2008.com   </span> <span style="font-weight: bold;"><br />adulthot-codec08.com   </span> <span style="font-weight: bold;"><br />adulttubecodec2008.com </span> <span style="font-weight: bold;"><br />hot-tubecodec20.com </span> <a href="http://bp2.blogger.com/_wICHhTiQmrA/SEfMyTsY63I/AAAAAAAABxg/ZtiCEo6OWi8/s1600-h/blackhat_seo_codecs2.png"><img id="BLOGGER_PHOTO_ID_5208356658729249650" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/SEfMyTsY63I/AAAAAAAABxg/ZtiCEo6OWi8/s200/blackhat_seo_codecs2.png" border="0" /></a><span style="font-weight: bold;"><br />media-tubecodec2008.com </span> <span style="font-weight: bold;"><br />porn-tubecodec20.com</span> <span style="font-weight: bold;"><br />hot-sextubecodec.com</span> <span style="font-weight: bold;"><br />sexporntubecodec14.com </span> <span style="font-weight: bold;"><br />sexporntubecodec32.com</span> <span style="font-weight: bold;"><br />sexporntubecodec77.com </span> <span style="font-weight: bold;"><br />sexporntubecodec98.com </span> <span style="font-weight: bold;"><br />adult-codec08.com</span><br /><span style="font-weight: bold;">adult-codec2008.com</span> <span style="font-weight: bold;"><br />adult-tubecodec08.com</span> <span style="font-weight: bold;"><br />adult-tubecodec2008.com</span> <span style="font-weight: bold;"><br />adulthot-codec08.com</span> <span style="font-weight: bold;"><br />adulthot-codec20008.com</span> <span style="font-weight: bold;"><br />adulthot-codec2008.com</span> <span style="font-weight: bold;"><br />adulthotcodec032008.com</span> <span style="font-weight: bold;"><br />adulthotcodec072008.com</span> <span style="font-weight: bold;"><br />adulthotcodec092008.com</span> <span style="font-weight: bold;"><br />adulthotcodec29018.com</span> <span style="font-weight: bold;"><br />adulthotcodec29098.com</span> <span style="font-weight: bold;"><br />adulttubecodec2008.com</span> <span style="font-weight: bold;"><br />media-tubecodec2008.com</span> <span style="font-weight: bold;"><br />sexhotcodec09.com</span> <span style="font-weight: bold;"><br />sexhotcodec1.com</span> <span style="font-weight: bold;"><br />sexhotcodec11.com</span> <span style="font-weight: bold;"><br />sexhotcodec12.com</span> <span style="font-weight: bold;"><br />sexhotcodec90.com</span> <span style="font-weight: bold;"><br />thehotcodec21.com</span> <span style="font-weight: bold;"><br />thehotcodecgt.com</span> <span style="font-weight: bold;"><br />thehotcodechq.com</span><br /><span style="font-weight: bold;">thehotcodeclk.com</span> <span style="font-weight: bold;"><br />thehotcodecrt.com</span><br /><span style="font-weight: bold;">thehotcodecxx.com</span><br /><span style="font-weight: bold;">thehotcodeczz.com</span><br /><br />What you see is not always what you get online, however, the infrastructure providers in the majority of malware campaigns tend to remain the same.<br /></div><div> </div></div></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NNJ0dI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NNJ0dI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fngtI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fngtI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sC7SZi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sC7SZi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GqEr0i"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GqEr0i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZhU6uI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZhU6uI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uOADsI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uOADsI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=337i4i"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=337i4i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/305310836" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 03:59:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/profile sites">profile sites</category>
      <category domain="http://securityratty.com/tag/multimedia sites">multimedia sites</category>
      <category domain="http://securityratty.com/tag/codec sites">codec sites</category>
      <category domain="http://securityratty.com/tag/zlob variants">zlob variants</category>
      <category domain="http://securityratty.com/tag/zlob">zlob</category>
      <category domain="http://securityratty.com/tag/zlob malware variants">zlob malware variants</category>
      <category domain="http://securityratty.com/tag/rogue codec sites">rogue codec sites</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/305310836/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</source>
    </item>
  </channel>
</rss>
