<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: traffalo]]></title>
    <link>http://securityratty.com/tag/traffalo</link>
    <description></description>
    <pubDate>Wed, 20 Feb 2008 19:33:33 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Malicious Advertising (Malvertising) Increasing]]></title>
      <link>http://securityratty.com/article/37f3f9caf6504e11892262d9abcaab70</link>
      <guid>http://securityratty.com/article/37f3f9caf6504e11892262d9abcaab70</guid>
      <description><![CDATA[In the wake of the recent malvertising incidents, it's about time we get to the bottom of the campaigns, define the exact hosts and IPs participating, all of their current campaigns, and who's behind...]]></description>
      <content:encoded><![CDATA[<div><a href="http://bp3.blogger.com/_wICHhTiQmrA/R7z0Lqd7luI/AAAAAAAABZA/rrRqUaH-p9k/s1600-h/malvertising_providers.jpg"><img id="BLOGGER_PHOTO_ID_5169274953530054370" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R7z0Lqd7luI/AAAAAAAABZA/rrRqUaH-p9k/s200/malvertising_providers.jpg" border="0" /></a>In the wake of the recent malvertising incidents, it's about time we get to the bottom of the campaigns, define the exact hosts and IPs participating, all of their current campaigns, and who's behind them. Who's been hit at the first place? <a href="http://blog.trendmicro.com/malicious-banners-target-expediacom-and-rhapsodycom/">Expedia</a>, <a href="http://www.theregister.co.uk/2008/01/30/excite_and_rhapsody_rogue_ads/">Excite</a>, <a href="http://campustechnology.com/articles/58272/">Rhapsody</a>, <a href="http://blog.trendmicro.com/myspace-excite-and-blick-serve-up-malicious-banner-ads/">MySpace</a>, all major <a href="http://blog.washingtonpost.com/securityfix/2008/01/malwarelaced_banner_ads_at_mys.html">web properties</a>. Now let's outline the malicious parties involved. These are the currently active domains delivering malicious flash advertisements that were, and still participate in the rogue ads attacks :</div><br /><div></div>01. <span style="font-weight: bold;">quinquecahue.com (190.15.64.190)</span><br />quinquecahue.com/swf/gnida.swf?campaign=tautonymus<br />quinquecahue.com/swf/gnida.swf?campaign=atliverish<br />quinquecahue.com/statsg.php?campaign=meatrichia<br /><div>quinquecahue.com/swf/gnida.swf?campaign=atticismus</div><br /><div></div>02. <span style="font-weight: bold;">akamahi.net (190.15.64.185)</span><br />akamahi.net/swf/gnida.swf?cam<br />akamahi.net/swf/gnida.swf?campaign=innational<br />akamahi.net/swf/gnida.swf?campaign=annalistno<br />akamahi.net/statsg.php?u=1199891594&amp;campaign=annalistno<br /><br /><div></div>03. <span style="font-weight: bold;">thetechnorati.com (190.15.64.191)</span><br />thetechnorati.com/swf/gnida.swf?campaign=ofcavalier<br />thetechnorati.com/swf/gnida.swf?campaign=whoduniton<br />thetechnorati.com/statsg.php?u=1198689218<br /><br /><div></div>04. <span style="font-weight: bold;">vozemiliogaranon.com (190.15.64.192)</span><br />vozemiliogaranon.com/statss.php?campaign=zoolatrymy<br />vozemiliogaranon.com/swf/gnida.swf?campaign=zoolatrymy<br />vozemiliogaranon.com/statss.php?campaign=revenantan<br /><br /><div></div>05. <span style="font-weight: bold;">newbieadguide.com (190.15.64.188)</span><br />newbieadguide.com/statsg.php?campaign=missblue<br />newbieadguide.com/statsg.php?campaign=2rapid1y<br />newbieadguide.com/statsg.php?campaign=missblue<br />newbieadguide.com/statsg.php?campaign=germanit<br />newbieadguide.com/swf/gnida.swf?campaign=ta5temix<br />newbieadguide.com/swf/gnida.swf?campaign=c0pperin<br />newbieadguide.com/swf/gnida.swf?campaign=remain0r<br />newbieadguide.com/swf/gnida.swf?campaign=mi1eroof<br />newbieadguide.com/swf/gnida.swf?campaign=m9in9re9<br /><br /><div></div>06. <span style="font-weight: bold;">traffalo.com (84.243.252.94)</span><br />traffalo.com/swf/gnida.swf?campaign=atekistics<br />traffalo.com/swf/gnida.swf?campaign=byagnostic<br />traffalo.com/statsg.php?u=1201711626<div>traffalo.com/statsg.php?u=1202224809</div><br /><div></div>07. <span style="font-weight: bold;">burnads.com (84.243.252.85)</span><br />burnads.com/swf/gnida.swf?campaign=1akeweak<br />burnads.com/swf/gnida.swf?campaign=flatfootup<br /><br /><div></div>08. <span style="font-weight: bold;">v0zemili0garan0n.com</span><br />v0zemili0garan0n.com/statsg.php?u=1199391035<br /><br /><div></div>09. <span style="font-weight: bold;">adtraff.com (84.243.252.84)</span><br />adtraff.com/swf/gnida.swf?campaign=forcejoe<br />adtraff.com/swf/gnida.swf?campaign=forcejoe<br />adtraff.com/swf/gnida.swf?campaign=forcejoe<br /><div>adtraff.com/swf/gnida.swf?campaign=forcejoe</div>adtraff.com/swf/gnida.swf?campaign=forcejoe<br />adtraff.com/swf/gnida.swf?campaign=weightt0<br /><br /><div></div>10. <span style="font-weight: bold;">mysurvey4u.com (194.110.67.22)</span><br />mysurvey4u.com/swf/gnida.swf?campaign=rubberu5<br /><div>mysurvey4u.com/swf/gnida.swf?campaign=me9ntthe</div><br /><div></div>11. <span style="font-weight: bold;">traveltray.com (194.110.67.23)</span><br />traveltray.com/swf/gnida.swf?campaign=pavoninean<br /><br /><div></div>12. <span style="font-weight: bold;">tds.promoplexer.com (217.20.175.39)</span><br />tds.promoplexer.com/statsg.php<br />adtds2.promoplexer.com/in.cgi?2<br /><div></div><br />Additional domains sharing IPs with some of the domains, ones that will eventually used in upcoming campaigns :<br /><div></div><br /><span style="font-weight: bold;">aboutstat.com</span><br /><span style="font-weight: bold;">newstat.net</span><br /><span style="font-weight: bold;">officialstat.com</span><br /><span style="font-weight: bold;">stathisranch.net</span><br /><div><span style="font-weight: bold;">station-appraisals.net</span><br /></div><br /><div></div>Contact details of the fake new media advertising agencies :<br /><br /><div></div>- Traffalo - "<span style="font-style: italic;">A Leader in Online Behavioral Marketing</span>"<br />Phone: +46-40-627-1655<br />Fax: +46-8-501-09210<br /><br /><div></div>- MyServey4u - "<span style="font-style: italic;">Relax At Home ... And Get Paid For Your Opinion!</span>"<br />mysurvey4u.com<br /><br />- AdTraff - "<span style="font-style: italic;">Leader enterprise in Online Marketing</span>"<p>Phone number: +49-511-26-098-2104<br />Fax: +353-1-633-51-70<br /></p><p><span style="font-weight: bold;">Detection rate :</span><br /></p><p>gnida.swf : Result: 21/32 (65.63%)<br />Trojan-Downloader.SWF.Gida.a; Troj/Gida-A<br /><span style="font-weight: bold;">File size</span>: 3186 bytes<br /><span style="font-weight: bold;">MD5</span>: 015ebcd3ad6fef1cb1b763ccdd63de0c<br /><span style="font-weight: bold;">SHA1</span>: 5150568667809b1443b5187ce922b490fe884349<br />packers: Swf2Swc<br /></p><p>The bottom line - who's behind it? Now that pretty much all the domains involved are known, as well as the structure of the campaign itself, it's interesting to discuss where are all the advertisements pointing to. Can you name a three letter acronym for a cybercrime powerhouse? Yep, RBN's historical customers' base, still using <a href="http://rbnexploit.blogspot.com/2007/11/rbn-pc-hijacking-via-banner-ads-on.html">RBN's infrastructure and services</a>. Here's further analysis of this particular case as well - <a href="http://www.trustedsource.org/download/research_publications/SCJan08.pdf">Inside Rogue Flash Ads</a>, by Dennis Elser and Micha Pekrul, Secure Computing Corporation, Germany, as well as <a href="http://code.google.com/p/erlswf">a tool</a> specifically written to <a href="http://pentaphase.de/index.php?/archives/29-Erlang-unscrables-SWF.html">detect and prevent</a> such types of <a href="http://pentaphase.de/index.php?/archives/28-SWF-in-a-nutshell-and-the-malware-tragedy.html">malvertising practices</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ch36vfE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ch36vfE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dy0A5KE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dy0A5KE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KskYxZe"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KskYxZe" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XzsNCge"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XzsNCge" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=COUE7lE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=COUE7lE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VJBXStE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VJBXStE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZXY4wUe"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZXY4wUe" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/238573685" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 20 Feb 2008 19:33:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/swf">swf</category>
      <category domain="http://securityratty.com/tag/comswfgnida">comswfgnida</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/newbieadguide">newbieadguide</category>
      <category domain="http://securityratty.com/tag/comstatsg">comstatsg</category>
      <category domain="http://securityratty.com/tag/adtraff">adtraff</category>
      <category domain="http://securityratty.com/tag/active domains">active domains</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/traffalo">traffalo</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/238573685/malicious-advertising-malvertising.html">Malicious Advertising (Malvertising) Increasing</source>
    </item>
  </channel>
</rss>
