<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: xtraff]]></title>
    <link>http://securityratty.com/tag/xtraff</link>
    <description></description>
    <pubDate>Mon, 18 Feb 2008 07:58:53 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Serving Malware Through Advertising Networks]]></title>
      <link>http://securityratty.com/article/611f196eeff4dd95bd37c6eaecb46ad4</link>
      <guid>http://securityratty.com/article/611f196eeff4dd95bd37c6eaecb46ad4</guid>
      <description><![CDATA[In need of fresh binaries and malware serving domains? Start feeding your honeyfarm, or professional interests by participating in an affiliate network -- just like pharmaceutical scammers do --...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/R7m1iqd7loI/AAAAAAAABYQ/4o0oOsOSTkY/s1600-h/xbanners.jpg"><img id="BLOGGER_PHOTO_ID_5168361654504363650" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R7m1iqd7loI/AAAAAAAABYQ/4o0oOsOSTkY/s200/xbanners.jpg" border="0" /></a>In need of fresh binaries and malware serving domains? Start feeding your honeyfarm, or professional interests by participating in an affiliate network -- just like <a href="http://ddanchev.blogspot.com/2007/10/incentives-model-for-pharmaceutical.html">pharmaceutical scammers</a> do -- that's literally serving live exploit URLs and dropping malware in real-time.<br /><br />Upon registering at xbanners.biz, you're enticed to IFRAME your web property, and point to <strong>xtraff.biz/banner.php</strong> (67.228.11.176, also responds to <strong>interace8.com</strong> and <strong>cheap-web-host.net</strong>) and <strong>xtraff.biz/ads2.htm</strong> currently trying to exploit MDAC ActiveX code execution (CVE-2006-0003) through the Neosploit malware kit. <strong>Banner.php</strong> is for the time being loading IFRAMEs to :<br /><br /><strong>funppc.com/cgi-bin/pl/affiliates/referral.cgi?referral=3098</strong> (63.219.176.194)<br /><strong>look.fxlayer.net/hop.php</strong> (87.98.255.2)<br /><strong>hartnetwork.org/cgi-bin/in.cgi?p=1018b</strong> (216.246.31.236) - Neosploit malware kit<br /><br />Moreover, two other IFRAMEs within banner.php attempt to load a multitude of exploit serving URLs. xtraff.biz/ads1.htm loads :<br /><br /><strong>winhex.org/tds/in.cgi?9</strong> (85.255.120.194; the <a href="http://ddanchev.blogspot.com/2007/12/have-your-malware-in-timely-fashion.html">malware embedded attack againt the French government's Lybia site</a>)<br /><strong>195.93.218.25/kam/index.php</strong><br /><br />xtraff.biz/ads2.htm loads :<br /><br /><strong>todub.com/tod.php?username=kamilet</strong> (72.167.54.150)<br /><strong>search-fantasy.info/go.php?u=fxlayer</strong> (208.109.178.115)<br /><strong>netsearch.cc/go.php?u=fxlayer</strong> (208.109.90.122)<br /><strong>upperhits.com/index.php?id=kamilet</strong> (72.52.154.96)<br /><strong>itsptp.com/promote.php?uid=160</strong> (72.232.241.20)<br /><strong>validall.com/portal.php?ref=kamilet</strong> (207.150.179.58)<br /><strong>feisearch.com/portal.php?r=0&amp;username=fxlayer</strong> (63.246.133.63)<br /><strong>g2xml.com/portal.php?r=0&amp;username=kamilet</strong> (74.86.191.98)<br /><br />xtraff.biz/ad3.htm loads :<br /><br /><strong>utracker.pl/stat.php</strong><br /><strong>xtraff.biz/filtercountry.php</strong><br /><br />Upon registering at the second affiliate program, the participant is asked to use the following URL to redirect traffic to <strong>asearchfor.com/search.php</strong> (207.226.164.195); <strong>getmysearch.com/search.php</strong> (207.226.164.195); <strong>merrysearch.com</strong> (207.226.164.194). Known domains/IPs with bad reputation. It gets even more interesting as we try to further expand the affiliate program under the many other different domain names they use such as :<br /><br /><strong>buckspacks.com</strong><br /><strong>serious-partners.com</strong><br /><strong>real-bucks.com</strong><br /><strong>funsempire.com</strong><br /><strong>czcash.com</strong><br /><strong>extreme-traffic.net</strong><br /><strong>funsempire.com</strong><br /><strong>risecash.com<br />favouritecash.com</strong><br /><strong>xxl-cash.com</strong><br /><strong>partner.loveplanet.ru</strong><br /><strong>partner.gameboss.ru</strong><br /><br />Why would they bother sharing the revenues with other parties at the first place? To hedge of risk of getting caught serving malware directly, so what they're basically doing is risk-forwarding the serving process to each and every participant in the affiliate network. The bottom line - <strong>xbanners.biz</strong> is a frontend to <strong>xtraff.biz</strong>'s malicious practices, and <strong>xtraff.biz</strong> itself is a frontend to<strong> FunPPC.com</strong>, among the many affiliate programs that once establishing trust with a web site owner, start abusing it by randomly serving live exploir URLs and dropping malware.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hQHL5dE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hQHL5dE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=I8VCl2E"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=I8VCl2E" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=meXloYe"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=meXloYe" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZiF4Wee"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZiF4Wee" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oWduhSE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oWduhSE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Y3gZhKE"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Y3gZhKE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hOi7mSe"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hOi7mSe" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/237071528" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 18 Feb 2008 07:58:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/php attempt">php attempt</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/neosploit malware kit">neosploit malware kit</category>
      <category domain="http://securityratty.com/tag/xtraff">xtraff</category>
      <category domain="http://securityratty.com/tag/exploit">exploit</category>
      <category domain="http://securityratty.com/tag/live exploit urls">live exploit urls</category>
      <category domain="http://securityratty.com/tag/urls">urls</category>
      <category domain="http://securityratty.com/tag/htm">htm</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/237071528/serving-malware-through-advertising.html">Serving Malware Through Advertising Networks</source>
    </item>
  </channel>
</rss>
