<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: zlob]]></title>
    <link>http://securityratty.com/tag/zlob</link>
    <description></description>
    <pubDate>Thu, 05 Jun 2008 03:59:47 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Syndicating Google Trends Keywords for Blackhat SEO]]></title>
      <link>http://securityratty.com/article/c56eb4f87e14b19e95246ca1bd8a55dd</link>
      <guid>http://securityratty.com/article/c56eb4f87e14b19e95246ca1bd8a55dd</guid>
      <description><![CDATA[Several hundred Windows Live Spaces and AOL Journals , are currently syndicating the most popular keywords provided by Google Trends, and are consequently hijacking the top search queries exposing...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOXPRRoj3fI/AAAAAAAACPQ/DGGVEuUQaUc/s1600-h/bogus_blogs_google_trends_malware.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOXPRRoj3fI/AAAAAAAACPQ/fIYx1pvZfIM/s200-R/bogus_blogs_google_trends_malware.JPG" /></a>Several hundred <a href="http://blogs.zdnet.com/security/?p=1995">Windows Live Spaces and AOL Journals</a>, are currently syndicating the most popular keywords provided by Google Trends, and are consequently <a href="http://www.webroot.com/En_US/about-press-room-press-releases-hackers-using-real-headlines.html">hijacking the top search queries</a> exposing users to Zlob codecs.<br />
<br />
Here are some same bogus blogs used in the campaign, naturally pre-registered long before they executed it :<br />
<br />
<b>vinniedigg18 .spaces.live.com</b><br />
<b>journals.aol .com/iolatour16</b><br />
<b>fredabreak02 .spaces.live.com</b><br />
<b>thedaalerts01 .spaces.live.com</b><br />
<b>allisonpolls08 .spaces.live.com</b><br />
<b>rheabreak18 .spaces.live.com</b><br />
<b>racquellog17 .spaces.live.com</b><br />
<b>monikavideo11 .spaces.live.com</b><br />
<b>journals.aol .com/shelvakill27</b><br />
<b>tomekadigg26 .spaces.live.com</b><br />
<b>ivahnet19 .spaces.live.com</b><br />
<b>journals.aol .com/louisathere13</b><br />
<b>allisonpolls08 .spaces.live.com</b><br />
<b>valericatch03 .spaces.live.com</b><br />
<b>journals.aol .com/iolatour16</b><br />
<b>hadleycue01 .spaces.live.com</b><br />
<b>journals.aol .com/staceyliving01</b><br />
<b>collettebreak17 .spaces.live.com</b><br />
<b>journals.aol .com/nataliablog16</b><br />
<b>natalymore26 .spaces.live.com<br />
</b><br />
<br />
<a href="http://www.filefactory.com/file/4faafd/n/rogue_blogs_google_trends_txt">A comprehensive listing of the blogs involved can be downloaded here</a>. <br />
<br />
<div class="separator" style="clear: both; text-align: center;"><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOXYvtGnGWI/AAAAAAAACPY/7WDPIuBn5Eg/s1600-h/google_trends_blackhat_SEO.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOXYvtGnGWI/AAAAAAAACPY/3Ph-I65avew/s200-R/google_trends_blackhat_SEO.png" /></a></div>What do all of these bogus blogs have in common? The fact that they are all being abused by a single malware campaign, and the Keep it Simple Stupid mentality only a lazy malware campaigner can take advantage of. All of the blogs as using a central redirection domain, shutting it down or blocking it renders the number of bogus blogs is circulation irrelevant. In this case, the domain in question is <b>video.xmancer.org</b> (216.195.59.75).<br />
<br />
Here are the the rest of the domains participating in the campaign, as well as the parked ones at the corresponding IPs :<br />
<br />
<b>video.xmancer .org</b> (216.195.59.75)<br />
<b>buynowbe .com<br />
loveniche .com<br />
antivirus-freecheck .com<br />
jetelephone .cn<br />
reducki .cn<br />
woteenhas .cn<br />
lilaloft .cn</b><br />
<br />
<b>clipztimes .com</b> (78.157.143.235)<br />
<b>imagelized .com<br />
vidzdaily .com</b><br />
<br />
<b>gotmovz .com</b> (78.108.177.91) <br />
<b>dwnld-clips .com</b><br />
<br />
<b>movwmstream .com</b> (77.91.231.183)<br />
<b>newwmpupdate .com<br />
zaeplugin .com<br />
movaccelerator .com<br />
optimwares .com<br />
piterserv .com</b><br />
<br />
<b>moviesportal2008p .com</b> (72.232.183.154)<br />
<b>movieportal2008a .com<br />
funnyportal2008l .com<br />
starsportal2008p .com<br />
softportal2008p .com<br />
movieportal2008q .com</b><br />
<br />
In short, despite that the campaign is poised to attract generic search traffic, it's a self-exposing blackhat SEO campaign since each and every blog participating is also linking to the rest of the ones within the ecosystem.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/blackhat-seo-campaign-at-millennium.html">Blackhat SEO Campaign at The Millennium Challenge Corporation</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">Massive IFRAME SEO Poisoning Attack Continuing</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/massive-blackhat-seo-targeting-blogspot.html">Massive  Blackhat SEO Targeting Blogspot</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/invisible-blackhat-seo-campaign.html">The  Invisible Blackhat SEO Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2007/01/attack-of-seo-bots-on-edu-domain.html">Attack  of the SEO Bots on the .EDU Domain</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/p0rngov-ongoing-blackhat-seo-operation.html">p0rn.gov  - The Ongoing Blackhat SEO Operation</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/continuing-gov-blackat-seo-campaign.html">The Continuing .Gov Blackat SEO Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/continuing-gov-blackat-seo-campaign_25.html">The Continuing .Gov Blackhat SEO Campaign - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/compromised-sites-serving-malware-and.html">Compromised Sites Serving Malware and Spam</a><b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uwRsM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uwRsM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LdmhM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LdmhM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eqMbm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eqMbm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=igiam"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=igiam" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iONDM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iONDM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0QewM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0QewM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6xSvm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6xSvm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/410092478" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 03 Oct 2008 00:19:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spaces">spaces</category>
      <category domain="http://securityratty.com/tag/windows live spaces">windows live spaces</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/live">live</category>
      <category domain="http://securityratty.com/tag/single malware campaign">single malware campaign</category>
      <category domain="http://securityratty.com/tag/aol journals">aol journals</category>
      <category domain="http://securityratty.com/tag/journals">journals</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <category domain="http://securityratty.com/tag/blackhat seo campaign">blackhat seo campaign</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/410092478/syndicating-google-trends-keywords-for.html">Syndicating Google Trends Keywords for Blackhat SEO</source>
    </item>
    <item>
      <title><![CDATA[Current List Of Zlob Distributiuon Sites And Rogue Anti-virus Products Domains]]></title>
      <link>http://securityratty.com/article/920dcaaf490ddab376b087b9f06c94ac</link>
      <guid>http://securityratty.com/article/920dcaaf490ddab376b087b9f06c94ac</guid>
      <description><![CDATA[Sunbelt, a developer of protection software known for its Kerio firewall, has been publishing a list of domains which are involved in spreading of Zlob trojan and fake malware anti-virus known as...]]></description>
      <content:encoded><![CDATA[Sunbelt, a developer of protection software known for it&#8217;s Kerio firewall, has been publishing a list of domains which are involved in spreading of Zlob trojan and fake malware anti-virus known as Antivirus XP 2008 (and its clones). Domains from this list might infect visitors, considered malicious and should be added as untrusted into filters.
There [...]]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 12:35:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/fake malware anti-virus">fake malware anti-virus</category>
      <category domain="http://securityratty.com/tag/infect visitors">infect visitors</category>
      <category domain="http://securityratty.com/tag/zlob trojan">zlob trojan</category>
      <category domain="http://securityratty.com/tag/kerio firewall">kerio firewall</category>
      <category domain="http://securityratty.com/tag/protection software">protection software</category>
      <category domain="http://securityratty.com/tag/filters">filters</category>
      <category domain="http://securityratty.com/tag/clones">clones</category>
      <source url="http://cyberinsecure.com/current-list-of-zlob-distributiuon-sites-and-rogue-anti-virus-products-domains/">Current List Of Zlob Distributiuon Sites And Rogue Anti-virus Products Domains</source>
    </item>
    <item>
      <title><![CDATA[Fake Porn Sites Serving Malware - Part Three]]></title>
      <link>http://securityratty.com/article/df6f06139a5c1a6029631a2d5221d428</link>
      <guid>http://securityratty.com/article/df6f06139a5c1a6029631a2d5221d428</guid>
      <description><![CDATA[Continue the Fake Porn Sites Serving Malware and Fake Porn Sites Serving Malware - Part Two series, in part three we'll take a peek at the emerging trend of parking a single domain at up to three...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQENtZvVWI/AAAAAAAACHU/3Th9wGTcre4/s1600-h/fake_porn_zlob_codec_localized.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQENtZvVWI/AAAAAAAACHU/1aZSLqClTi4/s200-R/fake_porn_zlob_codec_localized.JPG" /></a>Continue the <a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a> and <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a> series, in part three we'll take a peek at the emerging trend of parking a single domain at up to three different hosting locations, re-establishing connections between malicious ISPs for yet another time in between exposing the domains and the download locations sharing the same IPs.<br />
<br />
<b>downlfreesexgirlbeach .com</b> first redirects to <b>infodist1 .com/in.cgi?2 </b>then to <b>watchnenjoy.com/index.php?id=1314&amp;style=black</b>, and finally to the front end to the codec's download location <b>handmadeclips .com</b>, where the codec is downloaded from <b>fwlprocedure .com</b>.  Behind these domains, we can easily expose many other fake porn sites and pharmaceutical scams, next to a small portfolio of domains specifically used for hosting the binaries. Due to the obvious rotation I've encountered several times so far, a fake porn site today, is tomorrow's blackhat SEO content farm :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQHSj0XVWI/AAAAAAAACHc/DX-IaOAduVs/s1600-h/fake_porn_august.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SLQHSj0XVWI/AAAAAAAACHc/k9h1_E21wag/s200-R/fake_porn_august.JPG" /></a><b>downlfreesexgirlbeach .com</b> - (88.214.198.25)<br />
<b>vids365 .com<br />
downlfreesexgirlbeach .com<br />
top.only-bi .com<br />
wikiei .com<br />
paysuperporn .com<br />
aboutsexporn .com<br />
freactor .com<br />
cheapofficialpills .com<br />
finance-leaders.comnudenakedboys .com<br />
photosgayboys&nbsp; .com<br />
uniqueincest.com<br />
shyincest .com<br />
banrnd.central-xxx .com<br />
tvisklick .info<br />
thebg .net<br />
termion .net<br />
xoxvids .net<br />
bestpricepills .net<br />
bcodecnow .net</b><br />
<br />
<b>infodist1 .com</b> - (88.214.204.40)<br />
<b>farmasearch2008 .com<br />
flaxxvid .com<br />
xanax777pills .com<br />
18virgingirls .com<br />
girlnudegallaryvideox .com<br />
allxxxpornogerlsx .com<br />
jproshin .info<br />
familytaboo .info<br />
fullsitehost .info<br />
20searchonlinesite .net<br />
add-your-video .net<br />
blogs4y .net</b><br />
<br />
<div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SLQIspjO3tI/AAAAAAAACHs/MaMXiAw02F8/s1600-h/downlfreesexgirlbeach_viz.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SLQIspjO3tI/AAAAAAAACHs/znHGKTmbcHE/s200-R/downlfreesexgirlbeach_viz.JPG" /></a><b>adult-shemale .com</b> - (88.214.198.25)<br />
<b>adult-tranny .com<br />
all-shemale&nbsp; .com&nbsp;&nbsp;&nbsp; <br />
bcodecnow .net<br />
best-tranny .com&nbsp;&nbsp;&nbsp; <br />
bestguyportal .com<br />
bestmoviez .com&nbsp;&nbsp;&nbsp; <br />
central-xxx .com<br />
downlfreesexgirlbeach .com&nbsp;&nbsp;&nbsp; <br />
gallery-boy .com<br />
hiosexywomensxxxgirlsx .com&nbsp;&nbsp;&nbsp; <br />
lady-dick .com<br />
bcodecnow .net<br />
mytoppharmacy .com<br />
nakednudeboys .com&nbsp;&nbsp;&nbsp; <br />
nakednudemen .com<br />
nudenakedboys .com<br />
only-bi .com<br />
only-shemale .com<br />
page-reviews .com<br />
paulaslosingit .com<br />
photosgayboys .com<br />
stud-boys .com&nbsp;&nbsp;&nbsp; <br />
the0download .com<br />
wikiei .com&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; <br />
moviez .com<br />
hiosexywomensxxxgirlsx .com<br />
sexygirlsisuniformh0t .com&nbsp;&nbsp;&nbsp; <br />
the0download .com</b><br />
<br />
<b>flwprocedure .com </b>- (77.91.231.201)<b><br />
movupdate .com<br />
flwupdate .com<br />
formatmpeg .com<br />
movieexternal .com<br />
flwtool .com <br />
aviexecution .com<br />
releasedvideo .com<br />
wmvcompressor .com<br />
movieopens .com<br />
mpegapparatus .com<br />
flwassistant .com<br />
flwinstrument .com<br />
piterserv .com<br />
wovview .com</b><br />
<br />
<b>Some info on a sample codec :</b><br />
Scanners Result: 11/36 (30.56%)<br />
Trojan-Downloader.Win32.Zlob.cos<br />
Trojan.Popuper.7315<br />
File size: 10240 bytes <br />
MD5...: 467e4e78974dc8b2ee5d7da024daf31a <br />
SHA1..: 311e0c710bb15761ef3dace54b55489830cf5803<br />
<br />
Phones back to <b>69.50.164.50</b>/this/is/stereo/music.php?param=0;1314;1550; <b>69.50.164.50</b>/this/is/stereo/jazz.php?param=49325611;2:191:5|7:271:0|6:130:0|9:0:5|34:65536:0 and to <b>85.255.119.244</b>/this/is/stereo/music.php?param=0;4135;1548.<br />
<br />
When <b>Emil Kaperski's</b> owned <a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">InterCage, Inc.</a> (69.50.164.50) meets <a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">UkrTeleGroup Ltd.</a> (85.255.119.244) previously known as <b>Andrei Kislizin's</b> owned InHoster, you know you're on the right track.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kUs27K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kUs27K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sRXTAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sRXTAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sOsoWk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sOsoWk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fnooek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fnooek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R3T9kK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R3T9kK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WaKp6K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WaKp6K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R12pRk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R12pRk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/375241515" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 05:02:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <category domain="http://securityratty.com/tag/codec">codec</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/sample codec">sample codec</category>
      <category domain="http://securityratty.com/tag/locations">locations</category>
      <category domain="http://securityratty.com/tag/fake porn site">fake porn site</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/375241515/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Three</source>
    </item>
    <item>
      <title><![CDATA[Monetizing Compromised Web Sites]]></title>
      <link>http://securityratty.com/article/9f7b106457f7cdcbfb11dd8b0b3dd971</link>
      <guid>http://securityratty.com/article/9f7b106457f7cdcbfb11dd8b0b3dd971</guid>
      <description><![CDATA[Despite that pure patriotic hacktivism is still alive and kicking, compromised sites are largely getting monetized these days, starting from hosting blackhat SEO junk pages, to redirecting to live...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHsAOtYiisI/AAAAAAAAB58/CA2dvGI0DL0/s1600-h/Municipal_de_Amparo.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHsAOtYiisI/AAAAAAAAB58/k2bP_iz48tA/s200-R/Municipal_de_Amparo.png" style="border: 0pt none ;" /></a>Despite that pure patriotic hacktivism is still alive and kicking, <a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">compromised sites are largely getting monetized</a> these days, starting from hosting blackhat SEO junk pages, to redirecting to live exploit URLs and fake codecs where revenue is earned through their participation in an affiliate business model.<br />
<br />
With The Africa Middle Market Fund's site monetized by web site defacers who defaced it "in between" the blackhat SEO infrastructure they were hosting internally, in this I'll comment on the currently compromised and redirection to a fake porn sites, Camara Municipal de Amparo (<b>camaraamparo.sp.gov.br/r.html</b>). Basically, it's homepage is heavily linking to the Zlob variant (<b>camaraamparo.sp.gov.br/ video.exe</b>) in between loading an IFRAME to <b>61.162.230.12/ index.php</b>. As always, upon uploading their redirector, they've build enough confidence into their new hosting provider that the link to the redirector was instantly spammed across the web. The site is so heavily linking to the internal redirector itself, that upon clicking on the majority of links the user will inevitably come across it.<br />
<br />
Speaking of fake porn sites redirecting to Zlob variants, here are the very latest additions spammed across the web through blackhat SEO practices :<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHsLbgFp7NI/AAAAAAAAB6E/ZDNLECdRM1U/s1600-h/fake_porn_sites_zlob.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHsLbgFp7NI/AAAAAAAAB6E/TIqQ0wE9bQM/s200-R/fake_porn_sites_zlob.JPG" style="border: 0pt none ;" /></a><b>just-tube .com<br />
mypornmovies .net<br />
moms-galls .net<br />
porntubefilms .com<br />
porntubedot .com<br />
hot-porntube .com<br />
landmovieblog .com<br />
sexvidtube .com<br />
freelifevideo .com<br />
getyourfreemovie .com<br />
iubat .com<br />
sweetyjoly .com<br />
hardbizarre .com<br />
freeworldvideo .net<br />
hot-porntube .net<br />
qualitymovies .net<br />
porntube1con .net<br />
video-info .net<br />
videocityblog .com<br />
fuckedolder&nbsp; .com<br />
highpro1 .com<br />
max-graf.com .pl<br />
grandsupertds .info<br />
hot-porn-tube .net<br />
hot-porntube .com<br />
terryschulz .com<br />
show-sextube .com<br />
qualitymovies .net<br />
clubvideos .net</b><br />
<br />
No matter the high profile site that's been exploited in order to participate in such malicious operations, for the time being, crunching out new domain names and using the hosting services of the well known ISPs neglecting their removal, seems to be the tactic of choice. The long tail of SQL injected sites is however, clearly replacing the plain simple blackhat SEO web spamming, so that traffic to these rogue sites is driven through redirection of the the traffic from legitimate sites.<b><br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cEyKTJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cEyKTJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qsdYjJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qsdYjJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BVongj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BVongj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4DJmRj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4DJmRj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=al8bCJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=al8bCJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nrE7PJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nrE7PJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TCjewj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TCjewj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/334911319" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 13 Jul 2008 23:26:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/rogue sites">rogue sites</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/web site defacers">web site defacers</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/profile site">profile site</category>
      <category domain="http://securityratty.com/tag/redirector">redirector</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/334911319/monetizing-compromised-web-sites.html">Monetizing Compromised Web Sites</source>
    </item>
    <item>
      <title><![CDATA[The Template-ization of Malware Serving Sites]]></title>
      <link>http://securityratty.com/article/ae9fa7925137e6a71a690ef3b705294d</link>
      <guid>http://securityratty.com/article/ae9fa7925137e6a71a690ef3b705294d</guid>
      <description><![CDATA[Just like web malware exploitation kits and phishing pages turned into a commodity underground good , allowing easy localization to different languages , and of course, the natural lowering of entry...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHZZ6zTOnOI/AAAAAAAAB5c/3Sqe37mACns/s1600-h/fake_video_codec_template.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHZZ6zTOnOI/AAAAAAAAB5c/Rsu1-EiUFlY/s200-R/fake_video_codec_template.JPG" style="border: 0pt none ;" /></a>Just like web <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">malware</a> <a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">exploitation</a> <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">kits</a> and <a href="http://ddanchev.blogspot.com/2008/03/phishing-pages-for-every-bank-are.html">phishing pages turned into a commodity underground good</a>, allowing easy <a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">localization to different languages</a>, and of course, the natural lowering of entry barriers into web malware and phishing in general, the very same thing is happening with fake ActiveX templates like the ones used on <a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">the majority of fake porn and celebrity sites I've been assessing recently</a>.<br />
<br />
The increase of these bogus ActiveX templates is due to the fact that despite they are currently available for sale, buyers appear to be leaking them for everyone to use so that they can continue maintaining their current business models, namely, the services they offer with the ActiveX templates. Unethical competitive practices among cybercriminals and scammers are only to starting to take place with one another trying to ruin or extend the lifecycle of their services.<br />
<br />
Talking about prevalence, the <b>TonsOfPorn ActiveX</b> remains the most widely used rogue ActiveX in the majority of fake codec campaigns for the last couple of months. The ActiveX is largely abused by using another <b>fake porn site template for PornTube</b>, which in combination result in nothing more than huge domain portfolios with no content at all if we exclude the Zlob variants.<br />
<br />
And while template-tization means more efficient malware campaigns, it also results in a common pattern for generic detection of such sites. For instance, the folks at <a href="http://www.finjan.com/MCRCblog.aspx?EntryId=1993">Finjan did an experiment by verifying the signature based detection of the common javascript file</a> that was used in the ongoing waves of SQL injection attacks. Their conclusion :<br />
<br />
"<i>Can it be that Anti-virus products are now holding more signatures for domains and URLs rather than trying to identify a malicious code they never inspected before? As my research found, just by changing the domain names, some AVs did not find this code as malicious...... surprisingly enough.</i>"<br />
<br />
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp0.blogger.com/_wICHhTiQmrA/SHaFBlIm7bI/AAAAAAAAB5k/lXlcCbD2H78/s1600-h/inthecloud3.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SHaFBlIm7bI/AAAAAAAAB5k/wABNqH2-Sz0/s200-R/inthecloud3.jpg" style="border: 0pt none ;" /></a>When assessing malware campaigns in general, I usually do the same for the record. Storm Worm's use of <b>ind.php</b> for executing its set of exploits has the same detection rate - <b>scanners result: 10/33 (30.30%)</b> and is detected as JS.Zhelatin.zb.<br />
<br />
Getting back to the <b>TonsOfPorn ActiveX</b>, it's structure is more static than a Red Army statue in Estonia, making it easy to proactively protect against, no matter the domain, no matter the exploits served. It's detection rate is close to the javascript from the SQL injection attacks - <b>Scanners Result: 9/33 (27.28%) </b>and is detected as <b>Trojan.HTML.Zlob.L</b>.<br />
<br />
From my personal experience, blocking an IP address where a couple of hundred malicious domains remain parked, is just as useful as blocking a single domain acting as the main redirector behind a huge domains portfolio of malicious domains. However, the most beneficial approach on a large scale remains the practice of taking care of the most obvious patterns that still remain faily easy to detect, at least for the time being, due to the efficiency the people behind them aim to achieve, making them easily susceptible to generic detection approaches.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=60LvHJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=60LvHJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TvxsiJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TvxsiJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UeK86j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UeK86j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AHP63j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AHP63j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ci9jvJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ci9jvJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mQuV1J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mQuV1J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FGm2Yj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FGm2Yj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/332106839" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 12:59:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious domains remain">malicious domains remain</category>
      <category domain="http://securityratty.com/tag/malicious domains">malicious domains</category>
      <category domain="http://securityratty.com/tag/tonsofporn activex remains">tonsofporn activex remains</category>
      <category domain="http://securityratty.com/tag/tonsofporn activex">tonsofporn activex</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/generic detection approaches">generic detection approaches</category>
      <category domain="http://securityratty.com/tag/generic detection">generic detection</category>
      <category domain="http://securityratty.com/tag/activex">activex</category>
      <category domain="http://securityratty.com/tag/fake activex">fake activex</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/332106839/template-ization-of-malware-serving.html">The Template-ization of Malware Serving Sites</source>
    </item>
    <item>
      <title><![CDATA[Summarizing June's Threatscape]]></title>
      <link>http://securityratty.com/article/520325188c71fdacd3f86834feb1cdc5</link>
      <guid>http://securityratty.com/article/520325188c71fdacd3f86834feb1cdc5</guid>
      <description><![CDATA[June's threatscape that I'll summarize in this post based on all the research conducted during the month, was a very vibrant one. With the return of GPcode, a remotely exploitable flaw in the Zeus...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"><a href="http://bp3.blogger.com/_wICHhTiQmrA/SGoHvxfg0WI/AAAAAAAAB3M/6CMFS1Q1zGQ/s1600-h/ddanchev.jpg" imageanchor="1" style="clear: left; border-right: 0pt; border-top: 0pt; float: left; margin-bottom: 1em; border-left: 0pt; margin-right: 1em; border-bottom: 0pt; background-color: transparent;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SGoHvxfg0WI/AAAAAAAAB3M/WskmE9LDFvE/s200-R/ddanchev.jpg" style="border-right: 0pt; border-top: 0pt; border-left: 0pt; border-bottom: 0pt;" /></a>June's threatscape that I'll summarize in this post based on all the research conducted during the month, was a very vibrant one. With the return of GPcode, a remotely exploitable flaw in the Zeus crimeware kit allowing both, researchers and malicious parties to assess the severity of a particular banker malware campaign, the increasing use of malicious doorways next to ICANN and IANA's DNS hijacking, all speak for themselves and how diverse the threats and, of course, the abilities to maintain a decent situatiational awareness about what's going on have become.</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>01.</b>&nbsp; <a href="http://ddanchev.blogspot.com/2008/06/uks-crime-reduction-portal-hosting.html">U.K's Crime Reduction Portal Hosting Phishing Pages</a> - nothing new here since vulnerable sites are to be "remotely file included" and SQL injected to locally host anything on behalf of a malicious party. Risk and responsibility forwarding is one thing, but having a crime reduction portal hosting phishing pages is entirely another. The phishing pages was shut down in less than 12 hours upon notification</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>02.</b> <a href="http://ddanchev.blogspot.com/2008/06/price-discrimination-in-market-for.html">Price Discrimination in the Market for Stolen Credit Cards</a> - Tracking down "yet another stolen credit cards for sale" service in the wild, the price discremination that they applied greatly reflects the current lack of transpararency for a potential buyer of stolen credit cards, and how higher profit margins are driving the entire business model. With script kiddies running their own botnets and undermining the sophisticated botnet master's high profit margin business model by undercutting their prices, stolen credit cards are not what they used to be - an exclussive good. Nowadays, they are a commodity good and often a bargain</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>03.</b> <a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a> - Sampling an active blackhat SEO campaign out of the hundreds of thousands currently active online, releaved a large portfolio of domains serving Zlob variants by pitching them as fake codecs that the end user should download if they are to view the non existent adult content at the sites. Where's the OSINT mean? It's in the fact that the codecs and the fake security software phone back to UkrTeleGroup Ltd's network</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>04.</b> <a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a> - With the current oversupply of malware infected hosts, and botnet masters embracing the services model for anything malicious, in this post I discussed the radical security approach of puchasing already infected malware hosts on a per country basis, disinfecting them and forcing them to update all the software on the infected PCs. Of course, on an opt-in basis. The possibility to directly provide incentives for botnet hunters to shut down whatever they come across to on a daily basis, and that's a lot of botnets, is also there</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>05.</b> <a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html">Who's Behind the GPcode Ransomware?</a> - The title speaks for itself, the research with enough actionable intelligence gathered in the shortest timeframe possible is already proving accurate and highly valuable. How come? Stay tuned for more developments</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>06.</b> <a href="http://ddanchev.blogspot.com/2008/06/imageshack-typosquatted-to-serve.html">ImageShack Typosquatted to Serve Malware</a> - In a rare instance of a creative attack combining typosquatting in order to impersonate ImageShack and serve malware by redirecting users to an image file that is actually forwarding to the binary, I was recently tipped by the folks at TrendMicro who are also following this that the site is up and running again. Not for long</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>07.</b> <a href="http://ddanchev.blogspot.com/2008/06/fake-youtube-site-serving-flash.html">Fake YouTube Site Serving Flash Exploits</a> - Next to using the usual set of exploits courtesy of a commodity web malware exploitation kit, this campaign was also using flash exploits. Even more interesting is the fact that the password stealer obtained was attempting to phone back to a misconfigured malware command and control interface, basically allowing you to assess the campaign from the eyes of the "campaigner"</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>08.</b> <a href="http://ddanchev.blogspot.com/2008/06/monetizing-web-site-defacements.html">Monetizing Web Site Defacements</a> - Web site defacements are getting monetized just like SQL injections are in order to locally host a blackhat search engine optimization campaign on a vulnerable site with a high page rank. In this post I've assessed such monetization courtesy of a web site defacer at The Africa Middle Market Fund</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>09.</b> <a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a> - Yet another large domains portfolio exposed though a malicious doorway redirecting to fake porn and video sites serving Zlob variants, tracking down the initial spamming of the malicious doorways across multiple vulnerable forums and guestbooks </div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>10.</b> <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a> - When cyber criminals get advised to patch their vulnerable versons of the Zeus Crimeware Kit, you know there's a monoculture in the crimeware market. This flaw released publicly in May, 2008, not just allows others to hijack someone's ebanking botnet, but also, vendors and researchers to better assess a vulnerable Zeus command and control location</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>11.</b> <a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a> - When templates for fake video and adult sites are just as available as they are now, anyone can take advantage of this cheap social engineering track that seems to work just fine. Compared to relying on blackhat search optimization to acquire traffic, some of the campaigns were SQL injected at vulnerable sites in order to drive traffic to them, next to several other tactics which when combined can result in a lot of people unknowingly visiting the sites </div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>12.</b> <a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">Phishing Campaign Spreading Across Facebook</a> - An internal phishing campaign was circulating across Facebook, which got taken care of thanks to coordinated efforts with Facebook's security folks. There's also an indicating tha they are currently typosquatting other social networking sites like Hi5 for instance</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>13.</b> <a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a> - As a firm believed in taking a random sample for a particular threat segment, this was once of these cases confirming the confidence I've built into anticipating upcoming tactics and strategies to be used </div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<div style="text-align: left;"><b>14.</b> <a href="http://ddanchev.blogspot.com/2008/06/update-to-photobuckets-dns-hijacking.html">An Update to Photobucket's DNS Hijacking</a> - Despite that Photobucket didn't oficially acknowledge the DNS hijacking, the hosting provider the NetDevilz hacking team used issued a statement. Ironically, the Turkish hacking group used the same provider weeks later to redirect ICANN and IANA's domains to Atspace.com</div>
<div style="text-align: left;"><b>15.</b> <a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a> - Among the largest domains portfolio of malware serving porn sites I've exposed in a while, all of them naturally remain active since they are hosted on a partition of RBN's diverse network. Visualizing a malicious doorway or the entire ecosystem provides a better understanding at how structured the ecosystems are</div>
<div style="text-align: left;"></div>
<div style="text-align: left;"></div>
<b>16.</b> <a href="http://ddanchev.blogspot.com/2008/06/backdoording-cyber-jihadist-ebooks-for.html">Backdoording Cyber Jihadist Ebooks for Surveillance Purposes</a> - Despite that in this case we have a cyber jihadist backdoording his own released books, the international intelligence community next to law enforcement are known to have expressed interest in backdooring suspect's PCs, so why not SQL inject the cyber jihadist forums themselves?<br />
<b>17.</b> <a href="http://ddanchev.blogspot.com/2008/06/right-wing-israeli-hackers-deface.html">Right Wing Israeli Hackers Deface Hamas's Site</a> - When you read that Hamas's site is hacked, you ask yourself the following, do they even have a web site that's up the running? The answer to which would be the fact that even Hezbollah has been maintaining an Internet infrastructure since 1998 <br />
<b>18.</b> <a href="http://ddanchev.blogspot.com/2008/06/icann-and-ianas-domain-names-hijacked.html">ICANN and IANA's Domain Names Hijacked by the NetDevilz Hacking Group</a> - A fact is a fact, no comment here, go through all the technical details of the hijacking, including some actionable intelligence on who's behind the hijacking<br />
<b>19.</b> <a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The Malicious ISPs You Rarely See in Any Report</a> - Who's tolerating malicious activities on their network, and how is the RBN related to all this? Well, when combined, the tiny parts of these ISPs represent a tiny part of the Russian Business Network itself<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Arx0SJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Arx0SJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5olcEJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5olcEJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=a2BAsj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=a2BAsj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=H5lz4j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=H5lz4j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MYqzVJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MYqzVJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1PoM3J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1PoM3J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=d9Ilyj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=d9Ilyj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/323996877" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 03:05:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/fake youtube site">fake youtube site</category>
      <category domain="http://securityratty.com/tag/web site defacements">web site defacements</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware hosts">malware hosts</category>
      <category domain="http://securityratty.com/tag/web site defacer">web site defacer</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/vulnerable sites">vulnerable sites</category>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/323996877/summarizing-junes-threatscape.html">Summarizing June's Threatscape</source>
    </item>
    <item>
      <title><![CDATA[Fake Porn Sites Serving Malware]]></title>
      <link>http://securityratty.com/article/5dacf1e5b6c84c1bed4515dca8fc1199</link>
      <guid>http://securityratty.com/article/5dacf1e5b6c84c1bed4515dca8fc1199</guid>
      <description><![CDATA[Ah, that RBN with its centralization mentality for the sake of ease of management and 99.999% uptime. In this very latest example of using malicious doorways redirecting to fake porn sites, consisting...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SGJTBaqN1yI/AAAAAAAAB1k/b9O7PupnB8E/s1600-h/porn_codecs.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SGJTBaqN1yI/AAAAAAAAB1k/b9O7PupnB8E/s200/porn_codecs.JPG" alt="" id="BLOGGER_PHOTO_ID_5215822602249819938" border="0" /></a>Ah, that RBN with its centralization mentality for the sake of ease of management and 99.999% uptime. In this very latest example of using malicious doorways redirecting to fake porn sites, consisting of over twenty different domains serving the usual Zlob malware variants, we have a decent abuse of a template for a porn site.<br /><br />The easy of management of such domain farms and the availability of templates for high trafficked topic segments such as celebrities and pornography, continue contributing to the increasing number of Zlob variants served through fake codecs. Moreover, once set up, the malicious infrastructure starts attracting now just generic search traffic, but also traffic coming from affiliates with whom revenue is shared on the basis of the number of people that downloaded the codec.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGJsP6kwvTI/AAAAAAAAB1s/b0lRo5htJtE/s1600-h/fake_porn_sites_ATRIVO.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGJsP6kwvTI/AAAAAAAAB1s/b0lRo5htJtE/s200/fake_porn_sites_ATRIVO.JPG" alt="" id="BLOGGER_PHOTO_ID_5215850339125738802" border="0" /></a>In this campaign, the malicious doorway that expands the entire ecosystem is located at <span style="font-weight: bold;">search-</span><span style="font-weight: bold;">top.com/in.cgi?5&amp;parameter=drs</span> (66.96.85.113). A redirector that appears to <a href="http://www.lavasoftsupport.com/index.php?showtopic=2662">have been operating since 2006</a>, according to this forum posting.<br /><br />What follows on-the-fly, are all the fake porn sites whose legitimately looking videos attempt to download a Zlob malware variant from a single location - <span style="font-weight: bold;">vipcodec.net</span>. Here are all the fake porn sites, and the associated campaigns in this redirection :<br /><br /><span style="font-weight: bold;">watchnenjoy .com</span>/index.php?id=1287&amp;style=white<br /><span style="font-weight: bold;">craziestclips .com</span>/index.php?id=1287&amp;q=<br /><span style="font-weight: bold;">immensevids .com</span><br /><span style="font-weight: bold;">planetfreepornmovies .com</span>/?t=1&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/edmund/16551689/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/rosalyn/1742941675/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/emiline/108846601/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/inde/964842117/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/elnora/648311952/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/verge/1734135233/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/dal/1663381205/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .ne</span><span style="font-weight: bold;">t</span>/gretchen/515268975/1/&amp;id=1219<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGJ2DJRJgoI/AAAAAAAAB10/0pUS4GVInf4/s1600-h/porn_domainfarm_codecs_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGJ2DJRJgoI/AAAAAAAAB10/0pUS4GVInf4/s200/porn_domainfarm_codecs_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5215861114847986306" border="0" /></a><span style="font-weight: bold;">abc-adult .com</span>/lillah/1467790484/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/jenne/434165228/1/&amp;id=1219<br /><span style="font-weight: bold;">look-adult .net</span>/ette/681831796/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/mime/65729013/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/alfe/550398461/1/&amp;id=1219<br /><span style="font-weight: bold;">group-ad</span><span style="font-weight: bold;">ult .net</span>/demerias/867452637/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/rhode/167691118/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/hephsibah/1254235416/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/hence/1684651134/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/kendra/371598555/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/link/1334727639/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/flo/84660854/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/assene/875893411/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/charlotta/972714195/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/orlando/761508522/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/jemima/1405735776/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/obadiah/263904242/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/douglas/1110779475/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/lydde/1844064103/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/marcia/1627490290/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/cono/295680123/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/wes/1733468207/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/wib/648341815/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/greg/2064937302/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/maris/33184936/1/&amp;id=1219<br /><span style="font-weight: bold;">look-adult .net</span>/regina/1273816838/1/&amp;id=1219<br /><span style="font-weight: bold;">abc-adult .com</span>/gwendolyn/869744046/1/&amp;id=1219<br /><span style="font-weight: bold;">service-porn .com</span>/carthaette/1021629112/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/ninell/1522355420/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/waldo/755290223/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/green/669090607/1/&amp;id=1219<br /><span style="font-weight: bold;">try-adult .com</span>/lula/447057398/1/&amp;id=1219<br /><span style="font-weight: bold;">visit-adult .net</span>/jay/1021153563/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/rosa/849017739/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/hannah/2111126283/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/robin/2114086747/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/geraldine/921262381/1/&amp;id=1219<br /><span style="font-weight: bold;">contact-adult .net</span>/christine/1821111087/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/frederica/364993202/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/kerste/735582753/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/vine/715820953/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-the .net</span>/newt/1835463160/1/&amp;id=1219<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SGJ6ha5cUzI/AAAAAAAAB18/wtJ3aPXos_Q/s1600-h/zlob_codec_setup.png"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SGJ6ha5cUzI/AAAAAAAAB18/wtJ3aPXos_Q/s200/zlob_codec_setup.png" alt="" id="BLOGGER_PHOTO_ID_5215866033022980914" border="0" /></a><span style="font-weight: bold;">try-adult .com</span>/max/602914725/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/cille/1420660046/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/phililpa/178057959/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/lise/1379126759/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/marianne/1083617952/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/emile/1173468576/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/patse/155685496/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/verna/625840253/1/&amp;id=1219<br /><span style="font-weight: bold;">name-adult .net</span>/aubrey/190928373/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .</span><span style="font-weight: bold;">net</span>/alphinias/1345158043/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/rosa/223743611/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/nerva/1509620489/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/leet/1619667733/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/roberta/887345003/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-pleasure .net</span>/tore/1032556395/1/&amp;id=1219<br /><span style="font-weight: bold;">useporn .net</span>/bo/1963737386/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/karon/136085893/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/tense/1523522750/1/&amp;id=1219<br /><span style="font-weight: bold;">poweradult .net</span>/hopp/1955964399/1/&amp;id=1219<br /><span style="font-weight: bold;">scan-porn .net</span>/vanne/350822489/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/deb/1451360694/1/&amp;id=1219<br /><span style="font-weight: bold;">about-adult .net</span>/moll/1511640690/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-popular .com</span>/obediah/562846948/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/tamarra/776122096/1/&amp;id=1219<br /><span style="font-weight: bold;">pleasure-porn .com</span>/aristotle/1046422029/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/titia/158157566/1/&amp;id=1219<br /><span style="font-weight: bold;">group-adult .net</span>/gay/1297835054/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-look .net</span>/katherine/2136357734/1/&amp;id=1219<br /><span style="font-weight: bold;">helpporn .net</span>/azubah/1197502147/1/&amp;id=1219<br /><span style="font-weight: bold;">porn-comp .com</span>/claes/770105101/1/&amp;id=1219<br /><br />Associated fake porn sites :<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SGJ7UYzaZJI/AAAAAAAAB2E/cy7Pijctw-8/s1600-h/fake_porn_sites_ATRIVO1.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SGJ7UYzaZJI/AAAAAAAAB2E/cy7Pijctw-8/s200/fake_porn_sites_ATRIVO1.JPG" alt="" id="BLOGGER_PHOTO_ID_5215866908634145938" border="0" /></a><span style="font-weight: bold;">pornbrake .com</span> <span style="font-weight: bold;"><br />sexnitro .net</span> <span style="font-weight: bold;"><br />brakesex .net</span> <span style="font-weight: bold;"><br />pornnitro .net</span> <span style="font-weight: bold;"><br />adultbookings .com</span> <span style="font-weight: bold;"><br />qazsex .com</span><br /><span style="font-weight: bold;">lightporn .net</span> <span style="font-weight: bold;"><br />delfiporn .net</span> <span style="font-weight: bold;"><br />pornqaz .com</span> <span style="font-weight: bold;"><br />megazporn .com</span> <span style="font-weight: bold;"><br />uinsex .com</span><br /><span style="font-weight: bold;">xerosex .com</span> <span style="font-weight: bold;"><br />serviceporn .com</span> <span style="font-weight: bold;"><br />aboutadultsex .com</span> <span style="font-weight: bold;"><br />superliveporn .com</span> <span style="font-weight: bold;"><br />bestpriceporn .com</span> <span style="font-weight: bold;"><br />contactporn .net</span> <span style="font-weight: bold;"><br />relatedporn .com</span> <span style="font-weight: bold;"><br />landporno .com</span> <span style="font-weight: bold;"><br />adultsper .com</span> <span style="font-weight: bold;"><br />plus-porn .com</span> <span style="font-weight: bold;"><br />adultstarworld .com</span><br /><span style="font-weight: bold;">cutadult .com</span> <span style="font-weight: bold;"><br />moviexxxhotel .com</span> <span style="font-weight: bold;"><br />porno-go .com</span> <span style="font-weight: bold;"><br />pornxxxfilm .com</span> <span style="font-weight: bold;"><br />porn-sea .com</span> <span style="font-weight: bold;"><br />review-sex .com</span> <span style="font-weight: bold;"><br />sureadult .com</span> <span style="font-weight: bold;"><br />browseadult .com</span> <span style="font-weight: bold;"><br />network-adult .com</span> <span style="font-weight: bold;"><br />timeadult .com</span> <span style="font-weight: bold;"><br />virtual-sexy .net</span><br /><span style="font-weight: bold;">funxxxporn .com</span> <span style="font-weight: bold;"><br />loweradult .com</span> <span style="font-weight: bold;"><br />adultfilmsite .com</span> <span style="font-weight: bold;"><br />xxxallvideo .com</span> <span style="font-weight: bold;"><br />custom-sex .com</span> <span style="font-weight: bold;"><br />g</span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SGJ8FOk2RhI/AAAAAAAAB2M/scnBizNZUOA/s1600-h/fake_porn_sites_ATRIVO2.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SGJ8FOk2RhI/AAAAAAAAB2M/scnBizNZUOA/s200/fake_porn_sites_ATRIVO2.JPG" alt="" id="BLOGGER_PHOTO_ID_5215867747702294034" border="0" /></a><span style="font-weight: bold;">allerypictures .net</span> <span style="font-weight: bold;"><br />usaadultvideo .com</span><br /><span style="font-weight: bold;">adultmovieplus .com</span> <span style="font-weight: bold;"><br />porn-cruise .com</span> <span style="font-weight: bold;"><br />clubxxxvideo .com</span> <span style="font-weight: bold;"><br />mitadult .com</span> <span style="font-weight: bold;"><br />galleryalbum .net</span> <span style="font-weight: bold;"><br />xxxteenfilm .com</span> <span style="font-weight: bold;"><br />hardcorevideosite .com</span> <span style="font-weight: bold;"><br />helpadult .com</span> <span style="font-weight: bold;"><br />portaladult .net</span> <span style="font-weight: bold;"><br />service-sex .com</span> <span style="font-weight: bold;"><br />driveadult .com</span> <span style="font-weight: bold;"><br />access-porno .com</span> <span style="font-weight: bold;"><br />time-sex .com</span> <span style="font-weight: bold;"><br />plus-adult .com</span> <span style="font-weight: bold;"><br />worldadultvideo .com</span><br /><span style="font-weight: bold;">key-adult .com</span><br /><span style="font-weight: bold;">estatesex .com</span> <span style="font-weight: bold;"><br />superadultfriend .com</span><br /><span style="font-weight: bold;">superporncity .com</span> <span style="font-weight: bold;"><br />zero-porno .com</span> <span style="font-weight: bold;"><br />scanadult .com</span> <span style="font-weight: bold;"><br />adultsexpro .com</span> <span style="font-weight: bold;"><br />adultzoneworld .com</span> <span style="font-weight: bold;"><br />porntimeguide .com</span> <span style="font-weight: bold;"><br />usbestporn .com</span> <span style="font-weight: bold;"><br />adulttow .com</span> <span style="font-weight: bold;"><br />look-porn .com</span><br /><span style="font-weight: bold;">galleryclick .net</span><br /><span style="font-weight: bold;">micro-sex .com</span> <span style="font-weight: bold;"><br />estatesex .com</span> <span style="font-weight: bold;"><br />try-sex .com</span> <span style="font-weight: bold;"><br />0bucksforpornmovie .com</span> <span style="font-weight: bold;"><br />gays-video-xxx .com</span> <span style="font-weight: bold;"><br />hackthegrid .com</span> <span style="font-weight: bold;"><br />savetop .info</span> <span style="font-weight: bold;"><br />vidsplanet .net</span> <span style="font-weight: bold;"><br />freexxxhere .com</span> <span style="font-weight: bold;"><br />gestkoeporno .com</span><br /><span style="font-weight: bold;">tv-adult .info</span> <span style="font-weight: bold;"><br />gays-adult-video .com</span> <span style="font-weight: bold;"><br />matures-video .com</span> <span style="font-weight: bold;"><br />analcekc .com</span> <span style="font-weight: bold;"><br />tabletskard .in</span> <span style="font-weight: bold;"><br />molodiedevki .com</span> <span style="font-weight: bold;"><br />dom-porno .com</span> <span style="font-weight: bold;"><br />pornoaziatki .com</span> <span style="font-weight: bold;"><br />latinosvideo .com</span> <span style="font-weight: bold;"><br />geiporno .com</span> <span style="font-weight: bold;"><br />sweetfreeporn .com</span><br /><br />If exposing a huge domains portfolio of currently active redirectors has the potential to ruin someone's vacation, then consider someone's vacation ruined already.<br /><br /><span style="font-weight: bold;">Related posts:<br /></span><a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br /><a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br /><a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XlaQvI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XlaQvI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=cI4v2I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=cI4v2I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=U4oTAi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=U4oTAi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LbooCi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LbooCi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MITw1I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MITw1I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nqHRRI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nqHRRI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2sf0Xi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2sf0Xi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/319853315" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 08:16:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/about-adult">about-adult</category>
      <category domain="http://securityratty.com/tag/scan-porn">scan-porn</category>
      <category domain="http://securityratty.com/tag/zlob malware variant">zlob malware variant</category>
      <category domain="http://securityratty.com/tag/name-adult">name-adult</category>
      <category domain="http://securityratty.com/tag/useporn">useporn</category>
      <category domain="http://securityratty.com/tag/porn-the">porn-the</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/319853315/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</source>
    </item>
    <item>
      <title><![CDATA[Fake Celebrity Video Sites Serving Malware]]></title>
      <link>http://securityratty.com/article/e6b6b6bb079e0140b924b302a0f75bb8</link>
      <guid>http://securityratty.com/article/e6b6b6bb079e0140b924b302a0f75bb8</guid>
      <description><![CDATA[With blackhat search engine optimization tactics clearly converging with social engineering , the result of which is the increasing supply of Zlob malware variants served as fake codecs, it's about...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/SFuPgUZ-1iI/AAAAAAAABz0/CfFQY0pYbO4/s1600-h/fake_celebrity_sites_malware1.JPG"><img id="BLOGGER_PHOTO_ID_5213918779007751714" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/SFuPgUZ-1iI/AAAAAAAABz0/CfFQY0pYbO4/s200/fake_celebrity_sites_malware1.JPG" border="0" /></a>With <a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">blackhat search engine optimization tactics clearly converging with social engineering</a>, the result of which is the increasing supply of Zlob malware variants served as fake codecs, it's about time we spill some coffee on several campaigns in order to get a better understanding of the way the campaigns function.<br /><div><br />These campaigns are also starting to get so sophisticated, that analyzing a single one will expose another massive SQL injection, reveal several blackhat SEO domain farms, let you obtain fresh Zlob malware variants, and point you to the very latest and undetected rogue software if you manage to expose the entire scammy ecosystem through all the redirections put in place to make it harder to get to the bottom of it.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFuTjKmVT2I/AAAAAAAAB0M/uoqsc9RfJNU/s1600-h/fake_celebrity_sites_malware2.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFuTjKmVT2I/AAAAAAAAB0M/uoqsc9RfJNU/s200/fake_celebrity_sites_malware2.JPG" alt="" id="BLOGGER_PHOTO_ID_5213923225961320290" border="0" /></a>What's important to keep in mind when assessing and shutting down such comprehensive campaigns is that on the majority of occassions the front end domains as well as the secondary ones are all attempting to download the codecs from hardcoded locations. Consequently, you have 50 front end domains and another 50 as secondary redirection points all attempting to download the codecs from 3 download locations. Once again, the malware authors efficiency centered mentality emphasising on the easy of management for the campaign is making it possible to.<br /><br /><div>Here's are some currently active fake celebrity video sites serving malware including the codec redirectors :<br /><br /><a href="http://bp3.blogger.com/_wICHhTiQmrA/SFuQGWDNAzI/AAAAAAAABz8/V4kNHEWuR0A/s1600-h/fake_celebrity_sites_malware.JPG"><img id="BLOGGER_PHOTO_ID_5213919432284111666" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SFuQGWDNAzI/AAAAAAAABz8/V4kNHEWuR0A/s200/fake_celebrity_sites_malware.JPG" border="0" /></a><span style="font-weight: bold;">stillnaked.net</span> <span style="font-weight: bold;"><br />funkytube.net</span><br /><span style="font-weight: bold;">starvid.info</span> <span style="font-weight: bold;"><br />yetmorefun.net</span> <span style="font-weight: bold;"><br />hotnudity.net</span> <span style="font-weight: bold;"><br />alreadynude.com</span> <span style="font-weight: bold;"><br />celebvids.info</span> <span style="font-weight: bold;"><br />sexystar.name</span> <span style="font-weight: bold;"><br />hotserved.net</span> <span style="font-weight: bold;"><br />thestars2008.com</span><br /><span style="font-weight: bold;">nudde.net</span> <span style="font-weight: bold;"><br />gottabigfuick.com</span> <span style="font-weight: bold;"><br />moviecity.se</span> <span style="font-weight: bold;"><br />gossip-starz.com</span> <span style="font-weight: bold;"><br />tmz-video.com</span><br /><span style="font-weight: bold;">js0.info</span> <span style="font-weight: bold;"><br />superfakamyvideo.com</span> <span style="font-weight: bold;"><br />hdavidz.com</span> <span style="font-weight: bold;"><br /></span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SFuRy8PMNtI/AAAAAAAAB0E/qBrd4frSeM0/s1600-h/thestars2008_com_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SFuRy8PMNtI/AAAAAAAAB0E/qBrd4frSeM0/s200/thestars2008_com_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5213921297960810194" border="0" /></a><span style="font-weight: bold;">blog-x.in</span> <span style="font-weight: bold;"><br /></span><span style="font-weight: bold;">tmz-video.com</span> <span style="font-weight: bold;"><br />newhotpeople.com</span> <span style="font-weight: bold;"><br />dirty-gossips.com</span> <span style="font-weight: bold;"><br />flaxxvid.com</span> <span style="font-weight: bold;"><br />videoid.info</span> <span style="font-weight: bold;"><br />realvideofree.com</span> <span style="font-weight: bold;"><br />yetmorefun.net</span> <span style="font-weight: bold;"><br />popvids.info<br />ihavewetfuckpussy.com<br /></span><span style="font-weight: bold;">virus-scanonline.com</span> <span style="font-weight: bold;"><br />adultx2008.com</span><br /><span style="font-weight: bold;">lux-software2008.com</span><br /><br />As well as some sample subdomains for traffic acquisition purposes, since all of these have already been crawled by search engines :<br /><br /><span style="font-weight: bold;">jodie.popvids.info</span> <span style="font-weight: bold;"><br />jessica.popvids.info</span> <span style="font-weight: bold;"><br />tila.popvids.info</span><br /><span style="font-weight: bold;">paris.celebvids.info</span> <span style="font-weight: bold;"><br />vanessa.celebvids.info</span> <span style="font-weight: bold;"><br />britney.nudde.net</span> <span style="font-weight: bold;"><br />paris.nudde.net</span> <span style="font-weight: bold;"><br />kardashian.nudde.net</span> <span style="font-weight: bold;"><br />vanessahudgens.yetmorefun.net</span> <span style="font-weight: bold;"><br />lindsaylohan.yetmorefun.net</span> <span style="font-weight: bold;"><br />britneyspears.yetmorefun.net</span> <span style="font-weight: bold;"><br />parishilton.yetmorefun.net</span> <span style="font-weight: bold;"><br />kardashian.nudde.net</span><br /><br />We also have embedded IFRAMEs and as well as injected ones into vulnerable sites, acting as redirectors to some of these fake video sites. For instance, at the <span style="font-weight: bold;">pedophilesexstories.blog.com</span> we have an injected redirector - <span style="font-weight: bold;">js0.info/?s=16&amp;k=pedophile+sex+stories&amp;c=5</span> and <span style="font-weight: bold;">js0.info</span> itself is a blackhat SEO operation that's aggregating generic search traffic like this :<br /><br /><span style="font-weight: bold;">js0.info/16/5/ragnarok+hentai</span> <span style="font-weight: bold;"><br />js0.info/15/4/antivirus+characteristic</span><br /><span style="font-weight: bold;">js0.info/16/5/msn+monkey</span><br /><span style="font-weight: bold;">js0.info/15/4/airplus+internet+security</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SFuW_npeNMI/AAAAAAAAB0U/aqnVPUbVWjc/s1600-h/malicious_redirector_script.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SFuW_npeNMI/AAAAAAAAB0U/aqnVPUbVWjc/s200/malicious_redirector_script.JPG" alt="" id="BLOGGER_PHOTO_ID_5213927013330334914" border="0" /></a>Once accessed, you get redirected to through <a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">two separate redirection campaigns</a> at <span style="font-weight: bold;">searchaw.info/sa/in.cgi?16</span>; and <span style="font-weight: bold;">hmel.info/stds13/go.php</span>, until you finally get to the codecs.<br /><br />With blackhat SEO-ers already well developed inventory of topical junk content, and experience in what's popular content and what's not,  the entry barriers for malware authors into the traffic acquisition joys of blackhat SEO has never lower.<br /></div></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WOphoI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WOphoI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W1jLhI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W1jLhI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PO1pbi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PO1pbi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=b0ILEi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=b0ILEi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HEkGpI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HEkGpI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vnYhGI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vnYhGI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1X0RPi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1X0RPi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/316164970" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 20 Jun 2008 02:58:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/blackhat seo-ers">blackhat seo-ers</category>
      <category domain="http://securityratty.com/tag/blackhat seo">blackhat seo</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://securityratty.com/tag/malware authors efficiency">malware authors efficiency</category>
      <category domain="http://securityratty.com/tag/blackhat seo operation">blackhat seo operation</category>
      <category domain="http://securityratty.com/tag/info">info</category>
      <category domain="http://securityratty.com/tag/blackhat">blackhat</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/316164970/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</source>
    </item>
    <item>
      <title><![CDATA[Malicious Doorways Redirecting to Malware]]></title>
      <link>http://securityratty.com/article/fe7f4960d26a3758a81dc861f894e098</link>
      <guid>http://securityratty.com/article/fe7f4960d26a3758a81dc861f894e098</guid>
      <description><![CDATA[Blacklisting malicious sites in times when legitimate ones are starting to compete with bogus .info and .biz ones for the leading position of hosting and serving malicious content, is a bit of an...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SFUBnTCFkwI/AAAAAAAABzE/90Gdkzc04f8/s1600-h/bestxvids_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SFUBnTCFkwI/AAAAAAAABzE/90Gdkzc04f8/s200/bestxvids_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5212073918386770690" border="0" /></a>Blacklisting malicious sites in times when legitimate ones are starting to compete with bogus .info and .biz ones for the leading position of hosting and serving malicious content, is a bit of an outdated and reactive approach for protecting against unknown threats. However, a single malicious domain whose live exploits can be easily detected and consequently blocked, is often just a front end to a large domains portfolio whose malicious content may easily pass through web filtering and on-the-fly malware attempts. Even worse, a malicious domain often exists in multiple "alternate realities" since a single IP is hosting many other unique and related malware domains.<br /><br />In this post, I'll assess <a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">a misconfigured malicious doorway</a>, that is redirecting to ten different malware sites <a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">serving Zlob variants by delivering fake codecs</a> that all the bogus adult sites require. The doorway is misconfigured in the sense of not recording the IP and checking the cookie set, in comparrision to every average web malware exploitation kit out there, which will not serve anything malicious when accessed for a second time since it's hashing the IPs that accessed it already. This is just the tip of the iceberg when it comes to the emerging evasive approaches applied to make the analysis of such doorways a bit more time and resources consuming. In a single sentence - <span style="font-weight: bold;">there's evidence blackhat SEO-ers are starting to exchange crawling manipulation know-how with malware authors</span>.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SFUCCgpQO8I/AAAAAAAABzM/HU4eAtm8bwU/s1600-h/bestxvids_spyshredder_redirection.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/SFUCCgpQO8I/AAAAAAAABzM/HU4eAtm8bwU/s200/bestxvids_spyshredder_redirection.JPG" alt="" id="BLOGGER_PHOTO_ID_5212074385897176002" border="0" /></a>In this example we have <span style="font-weight: bold;">bestxvids.info</span> (87.118.116.11)  which is reditecting to <span style="font-weight: bold;">all-in</span><span style="font-weight: bold;">dex.com/in.cgi?5</span> (87.118.116.11) a URL that's been actively spammed across forums and guestbooks vulnerable to automatic posting vulnerabilities (weak CAPTCHAs and web application vulnerabilities) which is then redirecting to the following fake codec domains on the fly, and since the redirection script isn't hashing my IP like the majority of well configured ones requiring the use of multiple IPs if we're to expose all the campaigns, it makes the investigation easier :<br /><br /><span style="font-weight: bold;">tubeuniverses.com/teen/index.php?id=1883</span> - (78.108.177.99)<br /><span style="font-weight: bold;">new-content-s2008.com/freemovie/938/0/</span> - (72.21.53.218)<br /><span style="font-weight: bold;">teens.0bucksforpornmovie.com/?id=4199</span> - (64.28.181.28)<br /><span style="font-weight: bold;">getadultaccess.com/movie/?aff=5310</span> - (200.63.46.84)<br /><span style="font-weight: bold;">hqtube.com/?7014000000</span> - (88.85.66.116)<br /><span style="font-weight: bold;">supersharebox.com/softw/?aff=5310&amp;saff=0</span> - (200.63.46.84)<br /><span style="font-weight: bold;">scanner.shredderscan.com/5/?advid=4329</span> - (92.241.182.13)<br /><span style="font-weight: bold;">myflydirect.com/1/5310/</span> - (200.63.46.84)<br /><span style="font-weight: bold;">getadultaccess.com/movie/?aff=5310</span> - (200.63.46.84)<br /><span style="font-weight: bold;">hotvidstube.com/teen/index.php?id=1883</span> - (78.108.177.99)<br /><span style="font-weight: bold;">2008-adult-2008.com/freemovie/938/0/</span> - (72.21.53.218)<br /><span style="font-weight: bold;">s-soft08freeware.com/download/502/938/0</span> - (91.203.70.18)<br /><br />Where's the "alternate reality"? All of the following fake codec and adult sites serving Zlob variants, with minor exceptions of course, are also responding to the main IP of the redirector - 87.118.116.11 :<br /><span style="font-weight: bold;"><br /></span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SFYov0Kh3HI/AAAAAAAABzc/70YINcLA_7E/s1600-h/porno_info_visualized.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SFYov0Kh3HI/AAAAAAAABzc/70YINcLA_7E/s200/porno_info_visualized.JPG" alt="" id="BLOGGER_PHOTO_ID_5212398420649696370" border="0" /></a><span style="font-weight: bold;">carsfoto.ru</span> <span style="font-weight: bold;"><br />cheapest-pharmacy.com</span> <span style="font-weight: bold;"><br />coolsexmovies.net</span><br /><span style="font-weight: bold;">free-movie-xxx.net</span> <span style="font-weight: bold;"><br />gold-collection.biz</span> <span style="font-weight: bold;"><br />p-o-r-n-0.com</span> <span style="font-weight: bold;"><br />p-o-r-n-0.info</span> <span style="font-weight: bold;"><br />sexakaporn.com</span> <span style="font-weight: bold;"><br />stred.biz</span> <span style="font-weight: bold;"><br />stred.in</span> <span style="font-weight: bold;"><br />tosserhost.com</span> <span style="font-weight: bold;"><br />west-video-xxx.info</span> <span style="font-weight: bold;"><br />wowtofree.info</span><br /><br />Shall we also expose the entire scammy ecosystem of Zlob variants, as always, sharing the same netblocks in order to keep it simple? But of course :<br /><br /><span style="font-weight: bold;">porn-youtube08.net</span> <span style="font-weight: bold;"><br />sextubecodec55.com</span> <span style="font-weight: bold;"><br />2008adult2008.com</span><br /><span style="font-weight: bold;">adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />newcontent-s2008.com</span> <span style="font-weight: bold;"><br />adultxx-18.com</span> <span style="font-weight: bold;"><br />newcontents2008.com</span> <span style="font-weight: bold;"><br />onlinestreamvide.com</span> <span style="font-weight: bold;"><br />2008adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />newcontents2008.com</span><br /><span style="font-weight: bold;">hot-pornotube2008.com</span> <span style="font-weight: bold;"><br />adult-youtube-8.com</span> <span style="font-weight: bold;"><br /></span><span style="font-weight: bold;">2008adult-s2008.com</span> <span style="font-weight: bold;"><br />2008adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />adult-freetube-8.com</span><br /><span style="font-weight: bold;">adult18tube2008.com</span><br /><span style="font-weight: bold;">adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />free-porntube-8.com</span> <span style="font-weight: bold;"><br /></span><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SFVF_rdlslI/AAAAAAAABzU/Y6DIZmD5gxo/s1600-h/bestxvids_malware_domains.JPG"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SFVF_rdlslI/AAAAAAAABzU/Y6DIZmD5gxo/s200/bestxvids_malware_domains.JPG" alt="" id="BLOGGER_PHOTO_ID_5212149104052122194" border="0" /></a><span style="font-weight: bold;">gt-funny.com    </span> <span style="font-weight: bold;"><br />gt-movies.com</span> <span style="font-weight: bold;"><br />gt-stars.com</span> <span style="font-weight: bold;"><br />hot-sextube.com    </span> <span style="font-weight: bold;"><br />new-content-s2008.com</span> <span style="font-weight: bold;"><br />newcontent-s2008.com</span> <span style="font-weight: bold;"><br />newcontents2008.com</span> <span style="font-weight: bold;"><br />onlinestreamvide.com    </span> <span style="font-weight: bold;"><br />porno-tube20008.com    </span> <span style="font-weight: bold;"><br />pornotube-20008.com        </span> <span style="font-weight: bold;"><br />pornotube20008.com</span> <span style="font-weight: bold;"><br />sex-18tube-2008.com</span><br /><span style="font-weight: bold;">sex-tube-20008.com</span> <span style="font-weight: bold;"><br />sex-tube20008.com</span> <span style="font-weight: bold;"><br />sex18tube2008.com</span> <span style="font-weight: bold;"><br />sexi18tube2008.com</span> <span style="font-weight: bold;"><br />sextube18adult.com</span> <span style="font-weight: bold;"><br />sextube20008.com    </span> <span style="font-weight: bold;"><br />streamadultvideo.com</span> <span style="font-weight: bold;"><br />xxxstreamonline.com</span><br /><br />The bottom line - malicious doorways are slowly starting to emerge thanks to the convergence of traffic redirection and management tools with web malware exploitation kits, and just like we've been seeing the adaptation of spamming tools and approaches for phishing purposes, next we're going to see the development of infrastructure management kits, a feature that <a href="http://ddanchev.blogspot.com/2008/05/diy-phishing-kits-introducing-new.html">DIY phishing kits</a> are starting to take into consideration as well.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8oWxkI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8oWxkI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CSGETI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CSGETI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BOEE6i"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BOEE6i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fIFwTi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fIFwTi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vk30nI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vk30nI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DPXX6I"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DPXX6I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=x8rEEi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=x8rEEi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/312884606" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 15 Jun 2008 23:51:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/doorways">doorways</category>
      <category domain="http://securityratty.com/tag/malicious doorways">malicious doorways</category>
      <category domain="http://securityratty.com/tag/malicious content">malicious content</category>
      <category domain="http://securityratty.com/tag/single sentence">single sentence</category>
      <category domain="http://securityratty.com/tag/single">single</category>
      <category domain="http://securityratty.com/tag/single malicious domain">single malicious domain</category>
      <category domain="http://securityratty.com/tag/doorway">doorway</category>
      <category domain="http://securityratty.com/tag/malicious doorway">malicious doorway</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/312884606/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</source>
    </item>
    <item>
      <title><![CDATA[Blackhat SEO Redirects to Malware and Rogue Software]]></title>
      <link>http://securityratty.com/article/2199017f7c1af4461b71026dc303b308</link>
      <guid>http://securityratty.com/article/2199017f7c1af4461b71026dc303b308</guid>
      <description><![CDATA[A black SEO farm with built-in redirection to a multitude of sites serving rogue codecs (Zlob malware variants) and fake security software phoning back to UkrTeleGroup Ltd's network - could it get...]]></description>
      <content:encoded><![CDATA[<div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SEe1DIDe2DI/AAAAAAAABxI/dNKrE60D00g/s1600-h/pornotubedirect1.JPG"><img id="BLOGGER_PHOTO_ID_5208330559383590962" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SEe1DIDe2DI/AAAAAAAABxI/dNKrE60D00g/s200/pornotubedirect1.JPG" border="0" /></a>A black SEO farm with built-in redirection to a multitude of sites serving rogue codecs (Zlob malware variants) and <a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">fake security software</a> phoning back to <a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">UkrTeleGroup Ltd's</a> network - could it get even more interesting? Of course, as the current state of Zlob malware serving tactics can be seperated in two distinct groups, those abusing the <a href="http://ddanchev.blogspot.com/2008/05/malware-attack-exploiting-flash-zero.html">"sort of" zero day Flash exploit</a>, as the currently <a href="http://ddanchev.blogspot.com/2008/05/yet-another-massive-sql-injection.html">active SQL injection attacks</a> are all taking advantage of it, and those still relying on plain simple redirect to multimedia sites requiring you to install the fake codec.<br /><br /><br /><div><div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SEe3eSO6t8I/AAAAAAAABxQ/GtMaVRNVy4E/s1600-h/blackhat_SEO_visualized.JPG"><img id="BLOGGER_PHOTO_ID_5208333224995633090" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/SEe3eSO6t8I/AAAAAAAABxQ/GtMaVRNVy4E/s200/blackhat_SEO_visualized.JPG" border="0" /></a>While tracking down the <a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">massive blackhat SEO poisoning campaigns</a> that took place in March, 2008, as well as the countless number of embedded/injected malware campaigns targeting high profile sites that we've been seeing recently, it's becoming increasingly common to come across a repeating malicious pattern. Basically, a <a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">domain portfolio of typosquatted domains</a> looking like legitimate codec sites is created, several bogus video, mostly p0rn related sites with no content start acting as a frontend to the codecs, where traffic is driven through blackhat SEO doorways. Moreover, rogue codec sites are increasing because the templates for the p0rn and codec sites are turning into a commodity, just like phishing pages and DIY phishing page generators lowering down the entry barriers into these practices.</div><br /><div><br /></div><div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SEfKn96fT7I/AAAAAAAABxY/kbygMpNzS54/s1600-h/blackhat_seo_codecs3.png"><img id="BLOGGER_PHOTO_ID_5208354282060861362" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SEfKn96fT7I/AAAAAAAABxY/kbygMpNzS54/s200/blackhat_seo_codecs3.png" border="0" /></a>Let's assess a sample redirection doorway, a visualization and sample traffic of which you can see in the attached screenshots. At <strong>porntubedirect.info </strong>we have a fake counter <strong>porntubedirect.info/stat/count.php</strong> loading the redirection script from <strong>216.240.139.234/sutra/in.cgi?3</strong> which is a javascript serving a different site on-the-fly, courtesy of a well known blackhat SEO campaign tool. The output of this redirection is a new domain serving Zlob variants in the form of fake codecs hosted under the following domains :</div><br /><div><strong>antivirus-scanonline.com</strong><br /></div><div><strong>indafuckfuck.com</strong></div><strong>newcontents2008.com</strong><br /><div><strong>avwav.com</strong></div><strong>anykindclips.com</strong><br /><div><strong>dirtyxxxvids.com</strong></div><strong>clipsmachines.com</strong><br /><div><strong>thesoft-portal-08.com</strong></div><br /><div>Sample detecton rates for the codecs obtained :<br /></div><div><br /></div><div>Scanners Result: 8/32 (25%)</div><span style="font-weight: bold;">W32/PolyZlob!tr.dldr; Trojan:Win32/Tibs.gen!lds</span><br /><div>File size: 119296 bytes </div>MD5...: dc5538af557cb4c311cb86d6574400ba<br /><div>SHA1..: 5cf1602db8c4fdd3c5ac5101e5a6c5daa77f5ff1</div><br /><div>Scanners Result: 6/32 (18.75%)<br /></div><div style="font-weight: bold;">Trojan-Downloader.Win32.FraudLoad.axa; Trojan.Dldr.FraudLoad.axa</div>File size: 60416 bytes<br /><div>MD5...: 14938bfe35128687e05f7f8ccbd29c7d </div>SHA1..: cf651e959fff945c9659321e79ba2788062b721d<br /><div><br /></div><div>Scanners Result: 14/32 (43.75%)</div><span style="font-weight: bold;">Trojan-Downloader.Win32.Zlob.lps; TrojanDownloader:Win32/Zlob.IB</span><br /><div>File size: 18432 bytes</div>MD5...: 9b3bbcd4549970a92eb1b11c46a451bb<br /><div>SHA1..: 679508aba4e547935d5e4104a735c754b40de49e</div><br /><div>Scanners Result: 18/32 (56.25%)<br /></div><div style="font-weight: bold;">Trojan-Downloader.Win32.Delf.ilx; TrojanDownloader:Win32/Chengtot.A</div>File size: 91683 bytes<br /><div>MD5...: 727e3f353281229128fdb1728d6ef345</div>SHA1..: 3f9c9000b273e8bf75db322382fbaabf333faf26<br /><div><br />Once we've managed to obtain several of the fake codec domains, passive DNS monitoring and using third-party tools helps us expose a huge portfolio of rogue domains such as :</div><br /><div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SEfM81C3WTI/AAAAAAAABxo/whvBq4dE_sE/s1600-h/blackhat_seo_codecs1.png"><img id="BLOGGER_PHOTO_ID_5208356839480580402" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SEfM81C3WTI/AAAAAAAABxo/whvBq4dE_sE/s200/blackhat_seo_codecs1.png" border="0" /></a><span style="font-weight: bold;">funfuckporn.com</span> <span style="font-weight: bold;"><br />musicpo</span><span style="font-weight: bold;">rtalfree.com</span> <span style="font-weight: bold;"><br />online-dvdrip.com</span> <span style="font-weight: bold;"><br />widget-porn.com</span> <span style="font-weight: bold;"><br />gt-funny.com</span> <span style="font-weight: bold;"><br />gt-movies.com</span><br /><span style="font-weight: bold;">gt-stars.com</span> <span style="font-weight: bold;"><br />hot-sextube.com</span> <span style="font-weight: bold;"><br />hot-pornotube-2008.com</span> <span style="font-weight: bold;"><br />hot-pornotube08.com</span> <span style="font-weight: bold;"><br />hotpornotube08.com</span> <span style="font-weight: bold;"><br />porn-youtube-08.org</span> <span style="font-weight: bold;"><br />uriy.org</span> <span style="font-weight: bold;"><br />sextube20008.com</span> <span style="font-weight: bold;"><br /></span><span style="font-weight: bold;">streamxxxvideo.com</span><br /><span style="font-weight: bold;">xxxgirlsgirls.com</span> <span style="font-weight: bold;"><br />porno-tube20008.com</span> <span style="font-weight: bold;"><br />2008adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />2008adults2008.com</span> <span style="font-weight: bold;"><br />adult18tube2008.com</span> <span style="font-weight: bold;"><br />sextube18adult.com</span> <span style="font-weight: bold;"><br />all-videos-home.com</span><br /><span style="font-weight: bold;">adultstreamportal2008.com</span> <span style="font-weight: bold;"><br />onlinestreamvide.com</span> <span style="font-weight: bold;"><br />adultvideos4all.com</span> <span style="font-weight: bold;"><br />sex18tube2008.com</span> <span style="font-weight: bold;"><br />adultxx-18.com</span> <span style="font-weight: bold;"><br />mymediasex.com</span><br /><span style="font-weight: bold;">ladyxxxworld.com</span><br /><span style="font-weight: bold;">adultstreamportal.com</span> <span style="font-weight: bold;"><br />young-girls-board.com</span> <span style="font-weight: bold;"><br />porn-youtube08.net</span><br /><span style="font-weight: bold;">adultfreemarket.info</span> <span style="font-weight: bold;"><br />adult-codec08.com  </span> <span style="font-weight: bold;"><br />adult-tubecodec08.com   </span> <span style="font-weight: bold;"><br />adult-tubecodec2008.com   </span> <span style="font-weight: bold;"><br />adulthot-codec08.com   </span> <span style="font-weight: bold;"><br />adulttubecodec2008.com </span> <span style="font-weight: bold;"><br />hot-tubecodec20.com </span> <a href="http://bp2.blogger.com/_wICHhTiQmrA/SEfMyTsY63I/AAAAAAAABxg/ZtiCEo6OWi8/s1600-h/blackhat_seo_codecs2.png"><img id="BLOGGER_PHOTO_ID_5208356658729249650" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/SEfMyTsY63I/AAAAAAAABxg/ZtiCEo6OWi8/s200/blackhat_seo_codecs2.png" border="0" /></a><span style="font-weight: bold;"><br />media-tubecodec2008.com </span> <span style="font-weight: bold;"><br />porn-tubecodec20.com</span> <span style="font-weight: bold;"><br />hot-sextubecodec.com</span> <span style="font-weight: bold;"><br />sexporntubecodec14.com </span> <span style="font-weight: bold;"><br />sexporntubecodec32.com</span> <span style="font-weight: bold;"><br />sexporntubecodec77.com </span> <span style="font-weight: bold;"><br />sexporntubecodec98.com </span> <span style="font-weight: bold;"><br />adult-codec08.com</span><br /><span style="font-weight: bold;">adult-codec2008.com</span> <span style="font-weight: bold;"><br />adult-tubecodec08.com</span> <span style="font-weight: bold;"><br />adult-tubecodec2008.com</span> <span style="font-weight: bold;"><br />adulthot-codec08.com</span> <span style="font-weight: bold;"><br />adulthot-codec20008.com</span> <span style="font-weight: bold;"><br />adulthot-codec2008.com</span> <span style="font-weight: bold;"><br />adulthotcodec032008.com</span> <span style="font-weight: bold;"><br />adulthotcodec072008.com</span> <span style="font-weight: bold;"><br />adulthotcodec092008.com</span> <span style="font-weight: bold;"><br />adulthotcodec29018.com</span> <span style="font-weight: bold;"><br />adulthotcodec29098.com</span> <span style="font-weight: bold;"><br />adulttubecodec2008.com</span> <span style="font-weight: bold;"><br />media-tubecodec2008.com</span> <span style="font-weight: bold;"><br />sexhotcodec09.com</span> <span style="font-weight: bold;"><br />sexhotcodec1.com</span> <span style="font-weight: bold;"><br />sexhotcodec11.com</span> <span style="font-weight: bold;"><br />sexhotcodec12.com</span> <span style="font-weight: bold;"><br />sexhotcodec90.com</span> <span style="font-weight: bold;"><br />thehotcodec21.com</span> <span style="font-weight: bold;"><br />thehotcodecgt.com</span> <span style="font-weight: bold;"><br />thehotcodechq.com</span><br /><span style="font-weight: bold;">thehotcodeclk.com</span> <span style="font-weight: bold;"><br />thehotcodecrt.com</span><br /><span style="font-weight: bold;">thehotcodecxx.com</span><br /><span style="font-weight: bold;">thehotcodeczz.com</span><br /><br />What you see is not always what you get online, however, the infrastructure providers in the majority of malware campaigns tend to remain the same.<br /></div><div> </div></div></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NNJ0dI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NNJ0dI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fngtI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fngtI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sC7SZi"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sC7SZi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GqEr0i"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GqEr0i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZhU6uI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZhU6uI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uOADsI"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uOADsI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=337i4i"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=337i4i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/305310836" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 03:59:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/profile sites">profile sites</category>
      <category domain="http://securityratty.com/tag/multimedia sites">multimedia sites</category>
      <category domain="http://securityratty.com/tag/codec sites">codec sites</category>
      <category domain="http://securityratty.com/tag/zlob variants">zlob variants</category>
      <category domain="http://securityratty.com/tag/zlob">zlob</category>
      <category domain="http://securityratty.com/tag/zlob malware variants">zlob malware variants</category>
      <category domain="http://securityratty.com/tag/rogue codec sites">rogue codec sites</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/305310836/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</source>
    </item>
  </channel>
</rss>
