<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: valentine]]></title>
    <link>http://securityratty.com/tag/valentine</link>
    <description></description>
    <pubDate>Tue, 15 Jan 2008 18:01:01 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Over 80 percent of Storm Worm Spam Sent by Pharmaceutical Spam Kings]]></title>
      <link>http://securityratty.com/article/ea68adf4b019a71c0112661ffc8d8bf1</link>
      <guid>http://securityratty.com/article/ea68adf4b019a71c0112661ffc8d8bf1</guid>
      <description><![CDATA[It used to be a case where a botnet would be used for a single purpose, spamming, phishing, or malware spreading. At a later stage, the steady supply of malware infected allowed botnet masters more...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp2.blogger.com/_wICHhTiQmrA/SI3DACirIII/AAAAAAAAB-M/mbToBJwm1uU/s1600-h/storm_pharma.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SI3DACirIII/AAAAAAAAB-M/YWIdXnUoPoU/s200-R/storm_pharma.png" style="border: 0pt none ;" /></a>It used to be a case where a botnet would be used for a single purpose, spamming, phishing, or malware spreading. At a later stage, the steady supply of malware infected allowed botnet masters more opportunities to "sacrifice" the clean IP reputation and engage in several malicious activities simultaneously - <a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">today's underground multitasking</a> improving the monetization of what used to be commodity goods and services.<br />
<br />
Today, a botnet will not only be <a href="http://ddanchev.blogspot.com/2008/02/inside-botnets-phishing-activities.html">sending out phishing emails</a>, automatically <a href="http://blogs.zdnet.com/security/?p=1122">SQL inject vulnerable sites across the web</a>, but also, provide <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">fast-flux infrastructure to money mule recruitment services</a>, all of this for the sake of optimizing the efficiency provided by the botnet in general. This <a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">optimization makes it possible for a single botnet to be partitioned</a> and access it it <a href="http://ddanchev.blogspot.com/2008/03/loadsccs-ddos-for-hire-service.html">sold and resold so many times</a>, that it would be hard to keep track of all the malicious activities it participates in. Cybercrime in between on multiple fronts using a single botnet is only starting to take place as concept.<br />
<br />
That's the case with Stormy Wormy, according to IronPort whose "<a href="http://www.darkreading.com/document.asp?doc_id=156139&amp;WT.svl=news1_1">Researchers Link Storm Botnet to Illegal Pharmaceutical Sales</a>" : <br />
<br />
"<i>Our previous research revealed an extremely sophisticated supply chain behind the illegal pharmacy products shipped after orders were placed on botnet-spammed Canadian pharmacy websites. <b>But the relationship between the technology-focused botnet masters and the global supply chain organizations was murky until now</b>," said Patrick Peterson, vice president of technology at IronPort and a Cisco fellow. "Our research has revealed a smoking gun that shows that Storm and other botnet spam generates commissionable orders, which are then fulfilled by the supply chains, generating revenue in excess of (US)$150 million per year.</i>"<br />
<br />
Murky until now? I can barely see in the room due to all the smoke coming from the smoking guns of who's what, what's when, and who's done what with who, especially in respect to Storm Worm whose multitasking on different fronts in the first stages of their appearance online made it possible to establish links between several different malware groups and the "upstream hosting providers", until the botnet scaled enough making it harder to keep track of all of their activities.<br />
<br />
<a href="http://www.ironport.com/malwaretrends/">The Storm Worm-ers themselves aren't sending out pharma spam</a>, the customers to whom they've sold access to parts of Storm Worm are the ones sending the pharma spam. Here's a brief analysis published in May - "<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a>". What's in it for the scammers? Income based on a revenue-sharing affiliate program, <a href="http://ddanchev.blogspot.com/2007/10/incentives-model-for-pharmaceutical.html">a pharmacy affiliate program</a> has been around for several years :<br />
<br />
"<i>This criminal organization recruits botnet spamming partners to advertise their illegal pharmacy websites, which receive a 40 percent commission on sales orders. The organization offers fulfillment of the pharmaceutical product orders, credit card processing and customer support services</i>" <br />
<br />
What's coming out of Storm Worm's botnet isn't necessarily coming from the hardcore Storm Worm-ers whose job today is more of a campaign-rotation related in order to ensure new bots are added, what's coming out of Storm Worm is coming from those <a href="http://it.slashdot.org/article.pl?sid=07/10/16/155209">using the access they've purchased to a part of the botnet</a>.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/all-you-need-is-storm-worms-love.html">All You Need is Storm Worm's Love</a><br />
<a href="http://ddanchev.blogspot.com/2007/01/social-engineering-and-malware.html">Social Engineering and Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/02/storm-worm-switching-propagation.html">Storm Worm Switching Propagation Vectors</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/storm-worms-use-of-dropped-domains.html">Storm Worm's use of Dropped Domains</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/offensive-storm-worm-obfuscation.html">Offensive Storm Worm Obfuscation</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/storm-worms-st-valentine-campaign.html">Storm Worm's St. Valentine Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-ddos-attitude.html">Storm Worm's DDoS Attitude</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/riders-on-storm-worm.html">Riders on the Storm Worm</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/storm-worm-malware-back-in-game.html">The Storm Worm Malware Back in the Game</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TUN7jJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TUN7jJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QEqwBJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QEqwBJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FeC9Rj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FeC9Rj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=b6c7oj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=b6c7oj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iJ3LCJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iJ3LCJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zhsGWJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zhsGWJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HuQaxj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HuQaxj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/349239892" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 23:29:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/storm worm">storm worm</category>
      <category domain="http://securityratty.com/tag/storm worm malware">storm worm malware</category>
      <category domain="http://securityratty.com/tag/storm">storm</category>
      <category domain="http://securityratty.com/tag/hardcore storm worm-ers">hardcore storm worm-ers</category>
      <category domain="http://securityratty.com/tag/storm worm-ers">storm worm-ers</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/botnet masters">botnet masters</category>
      <category domain="http://securityratty.com/tag/botnet spam">botnet spam</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/349239892/over-80-percent-of-storm-worm-spam-sent.html">Over 80 percent of Storm Worm Spam Sent by Pharmaceutical Spam Kings</source>
    </item>
    <item>
      <title><![CDATA[Storm Worm's U.S Invasion of Iran Campaign]]></title>
      <link>http://securityratty.com/article/686d338a8ac6a206c4c3d47b2722c28e</link>
      <guid>http://securityratty.com/article/686d338a8ac6a206c4c3d47b2722c28e</guid>
      <description><![CDATA[The Storm Worm-ers are keeping themselves busy, with two campaigns in less than a week, following the latest on the 4th of July . Now, they are spreading rumors of a U.S invasion in Iran

Just now US...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHQBeI4jtwI/AAAAAAAAB5M/-nE4lyzJG7A/s1600-h/stormworm_US_Iran.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHQBeI4jtwI/AAAAAAAAB5M/z4nlOvtbAEs/s200-R/stormworm_US_Iran.png" style="border: 0pt none ;" /></a>The Storm Worm-ers are keeping themselves busy, with two campaigns in less than a week, following the latest on <a href="http://blogs.zdnet.com/security/?p=1440">the 4th of July</a>. Now, they are spreading rumors of a U.S invasion in Iran :<br />
<br />
"<i>Just now US Army's Delta Force and U.S. Air Force have invaded Iran. Approximately 20000 soldiers crossed the border into Iran and broke down the Iran's Army resistance. The video made by US soldier was received today morning. Click on the video to see first minutes of the beginning of the World War III. God save us.</i>"<br />
<br />
The campaign is using the following domains :<br />
<b>statenewsworld .com</b><br />
<b>morenewsonline .com</b><br />
<b>dailydotnews .com</b><br />
<b>dotdailynews .com</b><br />
<b>newsworldnow .com</b><br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<b>All registered by the same individual :</b><br />
ONLINE&nbsp; CO REANIMATOR (dfgdgf@gmail.com)<br />
REVA 13-27 Deribaska 3565,198346 DZ Tel. +321.3568872<br />
<br />
<b>Sample detection rate :</b><br />
iran_occupation.exe<br />
Scanners Result: 4/33 (12.13%)<br />
File size: 118273 bytes<br />
MD5...: 19ab8f1dddb743c1dc2924cb61d3f877<br />
SHA1..: e0915f377020479ba95ffed0fcb07a2b2aec72f4<br />
<br />
<a href="http://bp3.blogger.com/_wICHhTiQmrA/SHQKR1MmyrI/AAAAAAAAB5U/ndcj_NbcPYU/s1600-h/storm_worm_likethisone_DNS.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SHQKR1MmyrI/AAAAAAAAB5U/BiXnjiE0FV4/s320-R/storm_worm_likethisone_DNS.png" style="border: 0pt none ;" /></a> Storm Worm domains used in recent campaigns, still parked on infected hosts :<br />
<br />
<b>superlovelyric .com</b><br />
<b>bestlovelyric .com</b><br />
<b>makingloveworld .com</b><br />
<b>statenewsworld .com</b><br />
<b>wholoveguide .com</b><br />
<b>gonelovelife .com</b><br />
<b>loveisknowlege .com</b><br />
<b>lovekingonline .com</b><br />
<b>lovemarkonline .com</b><br />
<b>wholefireworksonline .com</b><br />
<b>morenewsonline .com</b><br />
<b>makingadore .com</b><br />
<b>greatadore .com</b><br />
<b>yourfireworksstore .com</b><br />
<b>loveoursite .com</b><br />
<b>dayfireworkssite .com</b><br />
<b>musiconelove .com</b><br />
<b>knowholove .com</b><br />
<b>whoisknowlove .com</b><br />
<b>theplaylove .com</b><br />
<b>lovelifecash .com</b><br />
<b>wantcherish .com</b><br />
<b>shelovehimtoo .com</b><br />
<b>makeloveforever .com</b><br />
<b>bellestarfireworks .com</b><br />
<b>yourfireworks .com</b><br />
<b>worldbestfireworks .com</b><br />
<b>greatfireworkslaws .com</b><br />
<b>dailydotnews .com</b><br />
<b>dotdailynews .com</b><br />
<b>wholovedirect .com</b><br />
<b>newsworldnow .com</b><br />
<b>thefireworksjuly .com</b><br />
<b>grupogaleria .cn</b><br />
<b>polkerdesign .cn&nbsp;&nbsp;&nbsp; </b><br />
<b>nationwide2u .cn</b><br />
<b>activeware .cn</b><br />
<b>grupogaleria .cn</b><br />
<b>likethisone1 .com</b><br />
<b>lollypopycandy .com</b><br />
<b>nationwide2u .cn</b><br />
<b>polkerdesign .cn</b><br />
<b>verynicebank .com</b><br />
<b>thefireworksjuly .com</b><br />
<b>wholefireworksonline .com</b><br />
<b>worldbestfireworks .com</b><br />
<b>yourfireworks .com</b><br />
<b>bellestarfireworks .com</b><br />
<b>dayfireworkssite .com</b><br />
<b>greatfireworkslaws .com</b><br />
<b>yourfireworksstore .com</b><br />
<br />
The "best" is yet to come.<br />
<br />
<b>Related posts :</b><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/all-you-need-is-storm-worms-love.html">All You Need is Storm Worm's Love</a><br />
<a href="http://ddanchev.blogspot.com/2007/01/social-engineering-and-malware.html">Social Engineering and Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/02/storm-worm-switching-propagation.html">Storm Worm Switching Propagation Vectors</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/storm-worms-use-of-dropped-domains.html">Storm Worm's use of Dropped Domains</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/offensive-storm-worm-obfuscation.html">Offensive Storm Worm Obfuscation</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/storm-worms-st-valentine-campaign.html">Storm Worm's St. Valentine Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-ddos-attitude.html">Storm Worm's DDoS Attitude</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/riders-on-storm-worm.html">Riders on the Storm Worm</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/storm-worm-malware-back-in-game.html">The Storm Worm Malware Back in the Game</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9W9eqJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9W9eqJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ErCYhJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ErCYhJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fhypMj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fhypMj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=l8ef0j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=l8ef0j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mxGwGJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mxGwGJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WvlSXJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WvlSXJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jSALWj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jSALWj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/330319265" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 08 Jul 2008 16:07:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/storm worm">storm worm</category>
      <category domain="http://securityratty.com/tag/storm worm malware">storm worm malware</category>
      <category domain="http://securityratty.com/tag/storm worm-ers">storm worm-ers</category>
      <category domain="http://securityratty.com/tag/storm worm domains">storm worm domains</category>
      <category domain="http://securityratty.com/tag/iran">iran</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/iran occupation">iran occupation</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/330319265/storm-worms-us-invasion-of-iran.html">Storm Worm's U.S Invasion of Iran Campaign</source>
    </item>
    <item>
      <title><![CDATA[Hacker pleads guilty to attacking anti-phishing group]]></title>
      <link>http://securityratty.com/article/b672dc8fd9963474c546570401a895da</link>
      <guid>http://securityratty.com/article/b672dc8fd9963474c546570401a895da</guid>
      <description><![CDATA[A Fairfield, California, hacker has pleaded guilty to launching a Valentine's Day 2007 computer attack that nearly knocked an anti-phishing Web site...]]></description>
      <content:encoded><![CDATA[A Fairfield, California, hacker has pleaded guilty to launching a Valentine's Day 2007 computer attack that nearly knocked an anti-phishing Web site offline.]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web site offline">web site offline</category>
      <category domain="http://securityratty.com/tag/hacker">hacker</category>
      <category domain="http://securityratty.com/tag/guilty">guilty</category>
      <category domain="http://securityratty.com/tag/computer attack">computer attack</category>
      <category domain="http://securityratty.com/tag/valentine">valentine</category>
      <category domain="http://securityratty.com/tag/california">california</category>
      <category domain="http://securityratty.com/tag/fairfield">fairfield</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <source url="http://www.networkworld.com/news/2008/061008-hacker-pleads-guilty-to-attacking.html?fsrc=rss-security">Hacker pleads guilty to attacking anti-phishing group</source>
    </item>
    <item>
      <title><![CDATA[Storm Worm Hosting Pharmaceutical Scams]]></title>
      <link>http://securityratty.com/article/136b48ef6b52e1780fe22ec1ff8f39d6</link>
      <guid>http://securityratty.com/article/136b48ef6b52e1780fe22ec1ff8f39d6</guid>
      <description><![CDATA[With Storm's recent SQL injection and introduction of several new domains within, the very latest additions to their domain portfolio are the following domains (naturally in a fast-flux provided by...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SEBQz-zK7dI/AAAAAAAABwQ/oOQhYkgvYgc/s1600-h/storm_pharma1.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SEBQz-zK7dI/AAAAAAAABwQ/oOQhYkgvYgc/s200/storm_pharma1.JPG" alt="" id="BLOGGER_PHOTO_ID_5206250023201467858" border="0" /></a>With Storm's <a href="http://ddanchev.blogspot.com/2008/05/all-you-need-is-storm-worms-love.html">recent SQL injection</a> and introduction of several new domains within, the very latest additions to their domain portfolio are the following domains (naturally in a fast-flux provided by already infected hosts) hosting pharmaceutical scams :<br /><br /><span style="font-weight: bold;">producemorning.com</span> <span style="font-weight: bold;"><br />pressrose.com</span><br /><span style="font-weight: bold;">posestory.com</span><br /><span style="font-weight: bold;">picturewe</span><span style="font-weight: bold;">st.com</span> <span style="font-weight: bold;"><br />lowsmell.com</span> <span style="font-weight: bold;"><br />catsharp.com</span> <span style="font-weight: bold;"><br />printlength.com</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SEBSduzK7eI/AAAAAAAABwY/FlbHzyx9IC0/s1600-h/storm_pharma.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SEBSduzK7eI/AAAAAAAABwY/FlbHzyx9IC0/s200/storm_pharma.png" alt="" id="BLOGGER_PHOTO_ID_5206251839972634082" border="0" /></a>All of the domain's DNS entries are set to update every 2 minutes, meaning they every 2 minutes another 20 different and infected IPs will be hosting the domains, which on the other hand logically have identical WHOIS entry records :<br /><br /><span style="font-style: italic;">Administrative Contact: </span> <span style="font-style: italic;"><br />WenFeng</span> <span style="font-style: italic;">NO.397,zhuquedadao street,xian<br />City,shanxi Province</span> <span style="font-style: italic;">xi an Shanxi 710061</span> <span style="font-style: italic;">CN</span> <span style="font-style: italic;"><br />tel:  298 5228188 </span> <span style="font-style: italic;"><br />fax:  298 5393585<br /></span> <span style="font-style: italic;">yayun22@163.com</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SEBVNezK7fI/AAAAAAAABwg/MWHZ8wcH2xc/s1600-h/storm_pharma2.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SEBVNezK7fI/AAAAAAAABwg/MWHZ8wcH2xc/s200/storm_pharma2.JPG" alt="" id="BLOGGER_PHOTO_ID_5206254859334643186" border="0" /></a>It's also worth pointing out how they emphasize on the benefits of SSL based transactions, when none of the sites is supporting SSL, but is doing something a great number of phishers do - they've changed the favicon to a key lock looking one, since maintaining a SSL infrastructure on the infected hosts is both, unpragmatic, and a bit unnecessary if they social engineer the visitor :<br /><br />"<span style="font-style: italic;">SSL Encryption or Https is a technique used to safeguard private information which is sent via Internet. To prove the site's legitimacy, the SSL encryption uses a PKI (Public Key Infrastructure) - public/private key, to encrypt IDs, documents, or messages to securely transmit the information in the World Wide Web. In order to show that our transmission is encrypted, most browsers will display a small icon that would look like a pad "lock" or a key and the URL begins with "https" instead of "http". SSL Encryption or https from a digital certification authority will helps the secure web site with confidential information on web. </span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SEBZouzK7gI/AAAAAAAABwo/MgrjqDHT-JI/s1600-h/storm_fake_favicon.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SEBZouzK7gI/AAAAAAAABwo/MgrjqDHT-JI/s200/storm_fake_favicon.JPG" alt="" id="BLOGGER_PHOTO_ID_5206259725532589570" border="0" /></a>With pharma masters increasingly using <a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">fast-flux to increase the survivability of their domains</a> participating in affiliation based <a href="http://ddanchev.blogspot.com/2007/10/incentives-model-for-pharmaceutical.html">pharmaceutical affiliate programs</a>, Storm Worm is anything but lacking behind programs that connect scammers and <a href="http://www.trustedsource.org/TS?do=threats&amp;subdo=storm_tracker">(infected) infrastructure providers</a>.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><a href="http://ddanchev.blogspot.com/2008/05/all-you-need-is-storm-worms-love.html">All You Need is Storm Worm's Love</a><br /><a href="http://ddanchev.blogspot.com/2007/01/social-engineering-and-malware.html">Social Engineering and Malware</a><br /><a href="http://ddanchev.blogspot.com/2007/02/storm-worm-switching-propagation.html">Storm Worm Switching Propagation Vectors</a><br /><a href="http://ddanchev.blogspot.com/2007/08/storm-worms-use-of-dropped-domains.html">Storm Worm's use of Dropped Domains</a><br /><a href="http://ddanchev.blogspot.com/2007/08/offensive-storm-worm-obfuscation.html">Offensive Storm Worm Obfuscation</a><br /><a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br /><a href="http://ddanchev.blogspot.com/2008/01/storm-worms-st-valentine-campaign.html">Storm Worm's St. Valentine Campaign</a><br /><a href="http://ddanchev.blogspot.com/2007/09/storm-worms-ddos-attitude.html">Storm Worm's DDoS Attitude</a><br /><a href="http://ddanchev.blogspot.com/2007/12/riders-on-storm-worm.html">Riders on the Storm Worm</a><br /><a href="http://ddanchev.blogspot.com/2007/08/storm-worm-malware-back-in-game.html">The Storm Worm Malware Back in the Game</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2lfUEH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2lfUEH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dda2QH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dda2QH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uo4vqh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uo4vqh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=SV3dRh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=SV3dRh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fj5WXH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fj5WXH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=w2Y3WH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=w2Y3WH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=N0HUOh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=N0HUOh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/301462281" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 30 May 2008 10:50:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/storm worm">storm worm</category>
      <category domain="http://securityratty.com/tag/storm">storm</category>
      <category domain="http://securityratty.com/tag/storm worm malware">storm worm malware</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/ssl encryption">ssl encryption</category>
      <category domain="http://securityratty.com/tag/ssl">ssl</category>
      <category domain="http://securityratty.com/tag/lock">lock</category>
      <category domain="http://securityratty.com/tag/key lock">key lock</category>
      <category domain="http://securityratty.com/tag/key">key</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/301462281/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</source>
    </item>
    <item>
      <title><![CDATA[All You Need is Storm Worm's Love]]></title>
      <link>http://securityratty.com/article/3b6740ad1fcc1396cba8a4c6dbd8cb18</link>
      <guid>http://securityratty.com/article/3b6740ad1fcc1396cba8a4c6dbd8cb18</guid>
      <description><![CDATA[The Storm Worm malware launched yet another spam campaign promoting links to malware serving hosts, in between a SQL injection related to Storm Worm

These are Storm Worm's latest domains where the...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SDH2B3tDW_I/AAAAAAAABuA/44BP7CT47ag/s1600-h/storm_worm_latest_obfuscation.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SDH2B3tDW_I/AAAAAAAABuA/44BP7CT47ag/s200/storm_worm_latest_obfuscation.JPG" alt="" id="BLOGGER_PHOTO_ID_5202209556582849522" border="0" /></a>The Storm Worm malware launched yet another spam campaign promoting links to malware serving hosts, in between <a href="http://blogs.zdnet.com/security/?p=1131">a SQL injection related to Storm Worm</a>.<br /><br />These are Storm Worm's latest domains where the infected hosts try to phone back :<br /><br /><span style="font-weight: bold;">cadeaux-avenue.cn</span> (active)<br /><span style="font-weight: bold;">polkerdesign.cn</span> (active)<br /><span style="font-weight: bold;">tellicolakerealty.cn</span> (active and SQL injected at vulnerable sites)<br />Administrative Email for the three emails : glinson156 @ yahoo.com<br /><br />Related DNS servers for the latest campaign :<br /><span style="font-weight: bold;"><br />ns.orthelike.com</span> <span style="font-weight: bold;"><br />ns2.orthelike.com</span> <span style="font-weight: bold;"><br />ns3.orthelike.com</span><br /><span style="font-weight: bold;">ns4.orthelike.com</span> <span style="font-weight: bold;"><br />ns.likenewvideos.com</span><br /><span style="font-weight: bold;">ns2.likenewvideos.com</span> <span style="font-weight: bold;"><br />ns3.likenewvideos.com</span> <span style="font-weight: bold;"><br />ns4.likenewvideos.com</span><br /><br />Storm Worm related domains which are now down :<br /><span style="font-weight: bold;"><br />centerprop.cn</span> <span style="font-weight: bold;"><br />apartment-mall.cn</span> <span style="font-weight: bold;"><br />stateandfed.cn </span> <span style="font-weight: bold;"><br />phillipsdminc.cn</span> <span style="font-weight: bold;"><br />apartment-mall.cn</span> <span style="font-weight: bold;"><br />biggetonething.cn</span> <span style="font-weight: bold;"><br />gasperoblue.cn</span> <span style="font-weight: bold;"><br />giftapplys.cn</span> <span style="font-weight: bold;"><br />gribontruck.cn</span> <span style="font-weight: bold;"><br />ibank-halifax.com</span> <span style="font-weight: bold;"><br />limpodrift.cn</span> <span style="font-weight: bold;"><br />loveinlive.cn</span> <span style="font-weight: bold;"><br />newoneforyou.cn</span> <span style="font-weight: bold;"><br />normocock.cn</span> <span style="font-weight: bold;"><br />orthelike.com</span> <span style="font-weight: bold;"><br />supersameas.com</span> <span style="font-weight: bold;"><br />thingforyoutoo.cn</span><br /><br />One of the domains that is injected as an iFrame is using <span style="font-weight: bold;">ns.likenewvideos.com</span> as DNS server, whereas <span style="font-weight: bold;">likenewvideos.com</span> is currently suspended due to "violating Spam Policy". Precisely.<br /><br /><span style="font-weight: bold;">Related posts:</span><br /><a href="http://ddanchev.blogspot.com/2007/01/social-engineering-and-malware.html">Social Engineering and Malware</a><br /><a href="http://ddanchev.blogspot.com/2007/02/storm-worm-switching-propagation.html">Storm Worm Switching Propagation Vectors</a><br /><a href="http://ddanchev.blogspot.com/2007/08/storm-worms-use-of-dropped-domains.html">Storm Worm's use of Dropped Domains</a><br /><a href="http://ddanchev.blogspot.com/2007/08/offensive-storm-worm-obfuscation.html">Offensive Storm Worm Obfuscation</a><br /><a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br /><a href="http://ddanchev.blogspot.com/2008/01/storm-worms-st-valentine-campaign.html">Storm Worm's St. Valentine Campaign</a><br /><a href="http://ddanchev.blogspot.com/2007/09/storm-worms-ddos-attitude.html">Storm Worm's DDoS Attitude</a><br /><a href="http://ddanchev.blogspot.com/2007/12/riders-on-storm-worm.html">Riders on the Storm Worm</a><br /><a href="http://ddanchev.blogspot.com/2007/08/storm-worm-malware-back-in-game.html">The Storm Worm Malware Back in the Game</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xudReH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xudReH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bCsAxH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bCsAxH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=458Tzh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=458Tzh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OyT1lh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OyT1lh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eFEBTH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eFEBTH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bw77nH"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bw77nH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=o44Eoh"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=o44Eoh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/294253029" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 20 May 2008 03:46:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/storm worm">storm worm</category>
      <category domain="http://securityratty.com/tag/storm worm malware">storm worm malware</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/likenewvideos">likenewvideos</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/valentine campaign">valentine campaign</category>
      <category domain="http://securityratty.com/tag/orthelike">orthelike</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/sql injection">sql injection</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/294253029/all-you-need-is-storm-worms-love.html">All You Need is Storm Worm's Love</source>
    </item>
    <item>
      <title><![CDATA[Friday Squid Blogging: Valentine Squidograms in Second Life]]></title>
      <link>http://securityratty.com/article/dd3ab8e7b250dcc13374b975be4c23e2</link>
      <guid>http://securityratty.com/article/dd3ab8e7b250dcc13374b975be4c23e2</guid>
      <description><![CDATA[A day late: Cuddlefish Junction Kissing...]]></description>
      <content:encoded><![CDATA[<p>A day late: <a href="http://koreshan.blogspot.com/2008/02/squid-o-grams.html">Cuddlefish Junction Kissing Squidograms</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=J9nzEtE"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=J9nzEtE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=xTa6iiE"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=xTa6iiE" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 15 Feb 2008 13:53:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cuddlefish junction">cuddlefish junction</category>
      <category domain="http://securityratty.com/tag/squidograms">squidograms</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <source url="http://www.schneier.com/blog/archives/2008/02/friday_squid_bl_114.html">Friday Squid Blogging: Valentine Squidograms in Second Life</source>
    </item>
    <item>
      <title><![CDATA[Fools rush in to virus writers' love trap]]></title>
      <link>http://securityratty.com/article/ba652a4d12c2d9ceaa8d33d6201d65b5</link>
      <guid>http://securityratty.com/article/ba652a4d12c2d9ceaa8d33d6201d65b5</guid>
      <description><![CDATA[Star-crossed lovers have been warned not to lose their heads as well as their hearts on Valentine's Day as virus writers seek to exploit...]]></description>
      <content:encoded><![CDATA[Star-crossed lovers have been warned not to lose their heads as well as their hearts on Valentine's Day as virus writers seek to exploit romantics.]]></content:encoded>
      <pubDate>Thu, 14 Feb 2008 11:24:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virus writers seek">virus writers seek</category>
      <category domain="http://securityratty.com/tag/exploit romantics">exploit romantics</category>
      <category domain="http://securityratty.com/tag/valentine">valentine</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/heads">heads</category>
      <category domain="http://securityratty.com/tag/lovers">lovers</category>
      <category domain="http://securityratty.com/tag/hearts">hearts</category>
      <source url="http://www.enn.ie/article/10123902.html">Fools rush in to virus writers' love trap</source>
    </item>
    <item>
      <title><![CDATA[This Cupid I don't need]]></title>
      <link>http://securityratty.com/article/2d93e511671f1c814b3c3583624f523e</link>
      <guid>http://securityratty.com/article/2d93e511671f1c814b3c3583624f523e</guid>
      <description><![CDATA[With this weeks festive Valentine's Day celebration upon us, the social engineers are back at work. These folks come up with new and innovative ways to get you to open email and then own your machine....]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_hafMI9V8sC8/R7IIKcQGAuI/AAAAAAAAAFM/R-iSsvXh6nE/s1600-h/cupid_tattoo.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_hafMI9V8sC8/R7IIKcQGAuI/AAAAAAAAAFM/R-iSsvXh6nE/s320/cupid_tattoo.jpg" alt="" id="BLOGGER_PHOTO_ID_5166200698022789858" border="0" /></a><br />With this weeks festive Valentine's Day celebration upon us, the social engineers are back at work. These folks come up with new and innovative ways to get you to open email and then own your machine. The payload is usually the eponymous Storm worm, so be on your guard. You can get more details about what the <a href="http://www.networkworld.com/community/node/24930">FBI thinks is in store for the rest of this week</a>.<br /><br />Don't fall for it. By using the tactics discussed in <a href="http://www.securitymike.com">Security Mike's Guide</a> you are reasonably protected, but there is nothing that substitutes for good old common sense.<br /><br />I'm sure you have plenty of secret admirers, hopefully they'll send you flowers. Email solicitations to click on links, you don't need. If it seems too good to be true, it is. If it's a love note from someone that doesn't love you, don't open it.<br /><br />The best way to protect yourself online is constant vigilance. Expect the worst from folks on the Internet, they rarely let you down.<br /><br /><span style="font-size:85%;">Cupid image originally uploaded by <a href="http://www.flickr.com/photos/shoelessjoe/2052098058/">Shoeless Joe/64.</a></span><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/SecurityMike?a=qqgJvfE"><img src="http://feeds.feedburner.com/~f/SecurityMike?i=qqgJvfE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/SecurityMike?a=cWlLdRe"><img src="http://feeds.feedburner.com/~f/SecurityMike?i=cWlLdRe" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/SecurityMike?a=hcPFbSe"><img src="http://feeds.feedburner.com/~f/SecurityMike?i=hcPFbSe" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecurityMike/~4/233957916" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 12 Feb 2008 12:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/email solicitations">email solicitations</category>
      <category domain="http://securityratty.com/tag/love note">love note</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/love">love</category>
      <category domain="http://securityratty.com/tag/weeks festive valentine">weeks festive valentine</category>
      <category domain="http://securityratty.com/tag/eponymous storm worm">eponymous storm worm</category>
      <category domain="http://securityratty.com/tag/day celebration">day celebration</category>
      <category domain="http://securityratty.com/tag/secret admirers">secret admirers</category>
      <category domain="http://securityratty.com/tag/shoeless joe64">shoeless joe64</category>
      <source url="http://feeds.feedburner.com/~r/SecurityMike/~3/233957916/this-cupid-i-dont-need.html">This Cupid I don't need</source>
    </item>
    <item>
      <title><![CDATA[Storm Worm's St. Valentine Campaign]]></title>
      <link>http://securityratty.com/article/57c45e5425e3601a89d313b02adcb94b</link>
      <guid>http://securityratty.com/article/57c45e5425e3601a89d313b02adcb94b</guid>
      <description><![CDATA[The Riders on the Storm Worm started riding on yet another short term window of opportunity as always - St. Valentine's day with a mass mailing email campaign linking to two files with love.exe and...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/R41MIz8-MxI/AAAAAAAABUA/OCd28RWdjqw/s1600-h/storm_worm_valentine_2008.jpg"><img id="BLOGGER_PHOTO_ID_5155860862677693202" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R41MIz8-MxI/AAAAAAAABUA/OCd28RWdjqw/s200/storm_worm_valentine_2008.jpg" border="0" /></a>The <a href="http://ddanchev.blogspot.com/2007/12/riders-on-storm-worm.html">Riders on the Storm Worm</a> started riding on yet another short term window of opportunity as always - St. Valentine's day with a mass mailing email campaign linking to two files <strong>with_love.exe</strong> and <strong>withlove.exe</strong>, using an already infected host as a propagation vector itself in the very same fashion they've been doing so far.<br /><br /><strong>Detection rate</strong> : 3/32 (9.38%)<br /><strong>File size</strong>: 114689 bytes<br /><strong>MD5</strong>: 31ac9582674cad4c8c8068efb173d7c7<br /><strong>SHA1</strong>: cee93d3021318a34e188b8fae812aa929cb2bc9c<br /><br />NOD32v2 - a variant of Win32/Nuwar<br />Prevx1 - Stormy:All Strains-All Variants<br />Webwasher-Gateway - Win32.Malware.gen!88 (suspicious)<br /><br />The binary drops <strong>burito.ini</strong> (MD5 - A65FA0C23B1078B0758B80B5C0FD37F3) and <strong>burito1205-67d5.sys</strong> (MD5 - C4B9DD12714666C0707F5A6E39156C11), and creates the following registry entries :<br /><br />HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BURITO1205-67D5 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BURITO1205-67D5\0000 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\burito1205-67d5 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\burito1205-67d5\Security<br /><br />Surprisingly, there are no client-side vulnerabilities used in last two campaigns.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DRoflUD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DRoflUD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=i8xowyD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=i8xowyD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dOwvfEd"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dOwvfEd" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rUmoS5d"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rUmoS5d" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RgqxgYD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RgqxgYD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=A1Gek7D"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=A1Gek7D" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=EYAUExd"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=EYAUExd" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/217398938" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jan 2008 18:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hkey local">hkey local</category>
      <category domain="http://securityratty.com/tag/burito1205-67d5 hkey local">burito1205-67d5 hkey local</category>
      <category domain="http://securityratty.com/tag/burito1205-67d5">burito1205-67d5</category>
      <category domain="http://securityratty.com/tag/storm worm">storm worm</category>
      <category domain="http://securityratty.com/tag/binary drops burito">binary drops burito</category>
      <category domain="http://securityratty.com/tag/short term window">short term window</category>
      <category domain="http://securityratty.com/tag/md5">md5</category>
      <category domain="http://securityratty.com/tag/propagation vector">propagation vector</category>
      <category domain="http://securityratty.com/tag/email campaign">email campaign</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/217398938/storm-worms-st-valentine-campaign.html">Storm Worm's St. Valentine Campaign</source>
    </item>
  </channel>
</rss>
