<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: zombies]]></title>
    <link>http://securityratty.com/tag/zombies</link>
    <description></description>
    <pubDate>Thu, 03 Apr 2008 00:30:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[IT Security In The News: DLP, Zombies And Busted Myths]]></title>
      <link>http://securityratty.com/article/851eadf0ed57d455694ab0fabbcb50cf</link>
      <guid>http://securityratty.com/article/851eadf0ed57d455694ab0fabbcb50cf</guid>
      <description><![CDATA[Zombie Jamboree Are you 'fraid of zombies? You should be! According to the Shadowserver Foundation, which tracks zombie numbers worldwide, in the last three months a plague has broken out - a...]]></description>
      <content:encoded><![CDATA[Zombie Jamboree Are you 'fraid of zombies? You should be! According to the Shadowserver Foundation, which tracks zombie numbers worldwide, in the last three months a plague has broken out - a thre...]]></content:encoded>
      <pubDate>Wed, 10 Sep 2008 14:26:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zombies">zombies</category>
      <category domain="http://securityratty.com/tag/zombie jamboree">zombie jamboree</category>
      <category domain="http://securityratty.com/tag/tracks zombie">tracks zombie</category>
      <category domain="http://securityratty.com/tag/shadowserver foundation">shadowserver foundation</category>
      <category domain="http://securityratty.com/tag/fraid">fraid</category>
      <category domain="http://securityratty.com/tag/worldwide">worldwide</category>
      <category domain="http://securityratty.com/tag/thre">thre</category>
      <category domain="http://securityratty.com/tag/plague">plague</category>
      <category domain="http://securityratty.com/tag/months">months</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/389231455/">IT Security In The News: DLP, Zombies And Busted Myths</source>
    </item>
    <item>
      <title><![CDATA[Obama, Al Qaeda recruit for Rustock]]></title>
      <link>http://securityratty.com/article/8286e69ac6ebc34a10c2ba854cbe4a8f</link>
      <guid>http://securityratty.com/article/8286e69ac6ebc34a10c2ba854cbe4a8f</guid>
      <description><![CDATA[Barack Obama has left the presidential campaign trail and joined George W Bush, Al Qaeda and Microsoft to recruit zombies for the world's second largest botnet,...]]></description>
      <content:encoded><![CDATA[Barack Obama has left the presidential campaign trail and joined George W Bush, Al Qaeda and Microsoft to recruit zombies for the world's second largest botnet, Rustock.]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/presidential campaign trail">presidential campaign trail</category>
      <category domain="http://securityratty.com/tag/barack obama">barack obama</category>
      <category domain="http://securityratty.com/tag/recruit zombies">recruit zombies</category>
      <category domain="http://securityratty.com/tag/rustock">rustock</category>
      <category domain="http://securityratty.com/tag/qaeda">qaeda</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/bush">bush</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <source url="http://www.networkworld.com/news/2008/072508-obama-al-qaeda-recruit-for.html?fsrc=rss-security">Obama, Al Qaeda recruit for Rustock</source>
    </item>
    <item>
      <title><![CDATA[Baby Bubba Finds A New Mummy: A Zombie Children's Book]]></title>
      <link>http://securityratty.com/article/e537279946128bfced9d242bf8a098a3</link>
      <guid>http://securityratty.com/article/e537279946128bfced9d242bf8a098a3</guid>
      <description><![CDATA[Ok, this one is not security related, but those of you who know me know I have a thing for zombie movies. See my LAN Of The Dead article on computer zombies to see what I mean. Pascalle Ballard and I...]]></description>
      <content:encoded><![CDATA[Ok, this one is not security related, but those of you who know me know I have a thing for zombie movies. See my <a href="http://www.irongeek.com/i.php?page=security/computerzombies">LAN Of The Dead article on computer zombies</a> to see what I mean. Pascalle Ballard and I started to work on our own children's book, with a baby zombie as the lead character. Follow the link, I hope you will enjoy it.
<p><a href="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?a=VrH05f"><img src="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?i=VrH05f" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/343176692" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 19:53:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/baby zombie">baby zombie</category>
      <category domain="http://securityratty.com/tag/dead article">dead article</category>
      <category domain="http://securityratty.com/tag/computer zombies">computer zombies</category>
      <category domain="http://securityratty.com/tag/lead character">lead character</category>
      <category domain="http://securityratty.com/tag/pascalle ballard">pascalle ballard</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/zombie movies">zombie movies</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/follow">follow</category>
      <source url="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~3/343176692/baby-bubba">Baby Bubba Finds A New Mummy: A Zombie Children's Book</source>
    </item>
    <item>
      <title><![CDATA[Baby Bubba Finds A New Mummy: A Zombie Children's Book]]></title>
      <link>http://securityratty.com/article/bd59ab49794dfea3d8f83d23dad462c4</link>
      <guid>http://securityratty.com/article/bd59ab49794dfea3d8f83d23dad462c4</guid>
      <description><![CDATA[Ok, this one is not security related, but those of you who know me know I have a thing for zombie movies. See my LAN Of The Dead article on computer zombies to see what I mean. Pascalle Ballard and I...]]></description>
      <content:encoded><![CDATA[Ok, this one is not security related, but those of you who know me know I have a thing for zombie movies. See my <a href="http://www.irongeek.com/i.php?page=security/computerzombies">LAN Of The Dead article on computer zombies</a> to see what I mean. Pascalle Ballard and I started to work on our own children's book, with a baby zombie as the lead character. Follow the link, I hope you will enjoy it.<img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/MwfZD9__tMc" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 19:53:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/baby zombie">baby zombie</category>
      <category domain="http://securityratty.com/tag/dead article">dead article</category>
      <category domain="http://securityratty.com/tag/computer zombies">computer zombies</category>
      <category domain="http://securityratty.com/tag/lead character">lead character</category>
      <category domain="http://securityratty.com/tag/pascalle ballard">pascalle ballard</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/zombie movies">zombie movies</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/follow">follow</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/MwfZD9__tMc/baby-bubba">Baby Bubba Finds A New Mummy: A Zombie Children's Book</source>
    </item>
    <item>
      <title><![CDATA[Baby Bubba Finds A New Mummy: A Zombie Children's Book]]></title>
      <link>http://securityratty.com/article/17148a795076d89b03d973b2770c1a07</link>
      <guid>http://securityratty.com/article/17148a795076d89b03d973b2770c1a07</guid>
      <description><![CDATA[Ok, this one is not security related, but those of you who know me know I have a thing for zombie movies. See my LAN Of The Dead article on computer zombies to see what I mean. Pascalle Ballard and I...]]></description>
      <content:encoded><![CDATA[Ok, this one is not security related, but those of you who know me know I have a thing for zombie movies. See my <a href="http://www.irongeek.com/i.php?page=security/computerzombies">LAN Of The Dead article on computer zombies</a> to see what I mean. Pascalle Ballard and I started to work on our own children's book, with a baby zombie as the lead character. Follow the link, I hope you will enjoy it.]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 19:53:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/baby zombie">baby zombie</category>
      <category domain="http://securityratty.com/tag/dead article">dead article</category>
      <category domain="http://securityratty.com/tag/computer zombies">computer zombies</category>
      <category domain="http://securityratty.com/tag/lead character">lead character</category>
      <category domain="http://securityratty.com/tag/pascalle ballard">pascalle ballard</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/zombie movies">zombie movies</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/follow">follow</category>
      <source url="http://horrorhype.com/baby-bubba">Baby Bubba Finds A New Mummy: A Zombie Children's Book</source>
    </item>
    <item>
      <title><![CDATA[Engate sniffs bots with new mail rules]]></title>
      <link>http://securityratty.com/article/e3317c2a4b4236e8cd69014633498ffc</link>
      <guid>http://securityratty.com/article/e3317c2a4b4236e8cd69014633498ffc</guid>
      <description><![CDATA[ISPs and large enterprises are being offered a novel way to stop spam that goes beyond the mere filtering of e-mail messages - detect and block the botnet zombies that generate much of the problem in...]]></description>
      <content:encoded><![CDATA[ISPs and large enterprises are being offered a novel way to stop spam that goes beyond the mere filtering of e-mail messages - detect and block the botnet zombies that generate much of the problem in the first place.]]></content:encoded>
      <pubDate>Wed, 02 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/botnet zombies">botnet zombies</category>
      <category domain="http://securityratty.com/tag/stop spam">stop spam</category>
      <category domain="http://securityratty.com/tag/e-mail messages">e-mail messages</category>
      <category domain="http://securityratty.com/tag/isps">isps</category>
      <category domain="http://securityratty.com/tag/mere">mere</category>
      <category domain="http://securityratty.com/tag/enterprises">enterprises</category>
      <category domain="http://securityratty.com/tag/detect">detect</category>
      <category domain="http://securityratty.com/tag/block">block</category>
      <source url="http://www.networkworld.com/news/2008/070308-engate-sniffs-bots-with-new.html?fsrc=rss-security">Engate sniffs bots with new mail rules</source>
    </item>
    <item>
      <title><![CDATA[Wednesday Zombie PostNerd Zombies]]></title>
      <link>http://securityratty.com/article/93c72850d4eba1486c4e951e460dfb43</link>
      <guid>http://securityratty.com/article/93c72850d4eba1486c4e951e460dfb43</guid>
      <description><![CDATA[Fantastic cartoon strip and maybe a future movie at zombiesdontrun.com
If vulcans are driven solely by logic, how come TPol has a boob job
Bookmark...]]></description>
      <content:encoded><![CDATA[<p>Fantastic cartoon strip and maybe a future movie at <a href="http://www.zombiesdontrun.com/" target="_blank">zombiesdontrun.com</a>.</p>
<p style="padding-left: 30px;"><em>&#8220;If vulcans are driven solely by logic, how come T&#8217;Pol has a boob job?&#8221;</em></p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/401&amp;title=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Del.icio.us" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/401&amp;title=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to digg" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/401&amp;title=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to reddit" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies&amp;url=http://www.guerilla-ciso.com/archives/401&amp;version=0.7" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Feed Me Links" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/401" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Technorati" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/401&amp;t=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Yahoo My Web" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/401&amp;title=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Stumble Upon" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/401&amp;title=Wednesday+Zombie+Post%26%238211%3BNerd+Zombies" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Google Bookmarks" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/401" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Squidoo" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/401" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Bloglines" alt="Add 'Wednesday Zombie Post&#8211;Nerd Zombies' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=iiab5I"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=iiab5I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=31p1yi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=31p1yi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/295210547" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 21 May 2008 13:49:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fantastic cartoon strip">fantastic cartoon strip</category>
      <category domain="http://securityratty.com/tag/future movie">future movie</category>
      <category domain="http://securityratty.com/tag/boob job">boob job</category>
      <category domain="http://securityratty.com/tag/tpol">tpol</category>
      <category domain="http://securityratty.com/tag/solely">solely</category>
      <category domain="http://securityratty.com/tag/zombiesdontrun">zombiesdontrun</category>
      <category domain="http://securityratty.com/tag/bookmark">bookmark</category>
      <category domain="http://securityratty.com/tag/vulcans">vulcans</category>
      <category domain="http://securityratty.com/tag/logic">logic</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/295210547/401">Wednesday Zombie PostNerd Zombies</source>
    </item>
    <item>
      <title><![CDATA[Phishing Emails Generating Botnet Scaling]]></title>
      <link>http://securityratty.com/article/caa4f5eb8aeecfeaf3f29dd2781e5b66</link>
      <guid>http://securityratty.com/article/caa4f5eb8aeecfeaf3f29dd2781e5b66</guid>
      <description><![CDATA[A bigger and much more detailed picture is starting to emerge, with yet another spammed malware campaign courtesy of the botnet that is so far responsible for a massive flood of fake Windows updates ,...]]></description>
      <content:encoded><![CDATA[<div><a href="http://bp2.blogger.com/_wICHhTiQmrA/SAj0b2ORGbI/AAAAAAAABko/5lHZN8L0gdc/s1600-h/id759_phishing_botnet.png"><img id="BLOGGER_PHOTO_ID_5190667329793497522" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/SAj0b2ORGbI/AAAAAAAABko/5lHZN8L0gdc/s200/id759_phishing_botnet.png" border="0" /></a>A bigger and much more detailed picture is starting to emerge, with yet another spammed malware campaign courtesy of the botnet that is so far responsible for a <a href="http://ddanchev.blogspot.com/2008/02/inside-botnets-phishing-activities.html">massive flood of fake Windows updates</a>, phishing emails targeting the usual diverse set of brands, <a href="http://ddanchev.blogspot.com/2008/04/fake-yahoo-greetings-malware-campaign.html">fake yahoo greeting cards</a>, and most recently delivering "executable news items", through Backdoor.Agent.AJU malware infected hosts.<br /><br />Within the first five minutes, thirty three (33) phishing emails attempted to be delivered out of a sample infected host, all of them targeting NatWest or The National Westminster Bank Plc. Here are some samples, that of course never made it out to their recipient :<br /><div><div><br /><div>-<span style="font-style: italic;"> Sender Address: "NatWest Internet Banking '2008" </span><customer-support_reference_94ue@natwest.com style="font-style: italic;"> to Recipient: <@fs1.ge.man.ac.uk>Subject: Natwest Bank Bankline: Confirm Your Login Email Content: //ver2.natwest-commercial3.com/customerupdate?tag=3D19ecygtKZDzrozrznhOzn These directives are to be sent and followed by all members of the NatWest Private and Corporate Natwest does apologize for any problems caused, and is very thankful for your cooperation. If you are not client of Natwest OnLine Banking please ignore this notice! *** This is robot generated message please do not reply *** (C) 2008 Natwest Bankline. All Rights Reserved. Attached File: "ods096.gif" (image/gif)</customer-support_reference_94ue@natwest.com></div><br /><div><br /></div><div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SAj15WORGcI/AAAAAAAABkw/ShMwD7YF1HI/s1600-h/id759_phishing_botnet_nameservers.png"><img id="BLOGGER_PHOTO_ID_5190668936111266242" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/SAj15WORGcI/AAAAAAAABkw/ShMwD7YF1HI/s200/id759_phishing_botnet_nameservers.png" border="0" /></a>- <span style="font-style: italic;">Sender Address: "NatWest Bank On-line Banking'2008" </span><customers-support-id-49eio@natwest.com style="font-style: italic;"> to Recipient: <@bbc.co.uk> Subject: Natwest OnLine Banking Important Notice From Technical Department Id: 9044 Email Content: //ver2.natwest-commercial3.com/customerupdate?tag=3D15urOBFDffkOkhOvp These directives are to be sent and followed by all members of the NatWest Private and Corporate Natwest does apologize for any problems caused, and is very thankful for your cooperation. If you are not client of Natwest OnLine Banking please ignore this notice! *** This is robot generated message please do not reply *** (C) 2008 Natwest Bankline. All Rights Reserved. Attached File: "ods096.gif" (image/gif)</customers-support-id-49eio@natwest.com></div><br />- <span style="font-style: italic;">Sender Address: "Natwest Bank Internet Banking Support" </span><customer-department-num_509auq@natwest.com style="font-style: italic;"> to Recipient: <@yahoo.co.uk> Subject: NatWest Private and Corporate: Confirm Your Login Password Email Content: //ver2.natwest-commercial3.com/customerupdate?tag=3D24ecyuczfscwzbDtcwhhOkhOvp These directives are to be sent and followed by all members of the NatWest Private and Corporate Natwest does apologize for any problems caused, and is very thankful for your cooperation. If you are not client of Natwest OnLine Banking please ignore this notice! *** This is robot generated message please do not reply *** (C) 2008 Natwest Bankline. All Rights Reserved.</customer-department-num_509auq@natwest.com><br /><br />- <span style="font-style: italic;">Sender Address: "Natwest Private and Corporate Support" </span><reference_ref-59gs@natwest.co.uk style="font-style: italic;"> to Recipient: <@yahoo.co.uk> Subject: Natwest Bankline Internet Banking Important: Submit Your Records id: 1191 Email Content: //pool32-nwolb20.com/customerupdate?cid=3D27kwszewcenzdFECKDtcwhhOkhOvp These directives are to be sent and followed by all customers of the Natwest On-line Banking NatWest Bank does apologize for the troubles caused to you, and is very thankful for your collaboration. If you are not user of NatWest Bank Digital Banking please delete this letter! *** This is automatically generated message please do not reply *** (C) 2008 Natwest Bank On-line Banking. All Rights Reserved. Attached File: "rwu909.gif" (image/gif)</reference_ref-59gs@natwest.co.uk></div><br /><div><br /><div><a href="http://bp1.blogger.com/_wICHhTiQmrA/SAj2ImORGdI/AAAAAAAABk4/px7As682AnU/s1600-h/id759_phishing_botnet_nameservers_2.png"><img id="BLOGGER_PHOTO_ID_5190669198104271314" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/SAj2ImORGdI/AAAAAAAABk4/px7As682AnU/s200/id759_phishing_botnet_nameservers_2.png" border="0" /></a>- <span style="font-style: italic;">Sender Address: "Natwest Private and Corporate Support" </span><dontreply_num_34lkz@natwest.co.uk style="font-style: italic;"> to Recipient: <@56bridgwater.fsnet.co.uk> Subject: Natwest Internet Banking: Please Update Your Internet Banking Details Email Content: //pool32-nwolb20.com/customerupdate?cid=3D37kwszewcnnhrrDRCfszlaucndsOoerdnOkhOvp These directives are to be sent and followed by all customers of the Natwest On-line Banking NatWest Bank does apologize for the troubles caused to you, and is very thankful for your collaboration. If you are not user of NatWest Bank Digital Banking please delete this letter! *** This is automatically generated message please do not reply *** (C) 2008 Natwest Bank On-line Banking. All Rights Reserved. Attached File: "rwu909.gif" (image/gif)</dontreply_num_34lkz@natwest.co.uk></div><br />What is making an impression besides the malicious economies of scale achieved on behalf of the malware infected hosts used for sending, and as we've already seen, hosting and phishing pages and the malware itslef? <a href="http://ddanchev.blogspot.com/2007/07/targeted-extortion-attacks-at.html">It's the</a> campaing's <a href="http://ddanchev.blogspot.com/2007/11/targeted-spamming-of-bankers-malware.html">targeted nature</a> in respect to the <a href="http://ddanchev.blogspot.com/2008/03/localized-bankers-malware-campaign.html">segmented emails</a> database used for achieving a better response rate. The National Westminster Bank Plcis a U.K bank, and 10 out of 15 email recepient are of U.K citizens, the rest are targeting Italian users. Malware variants signal their presence to <strong>66.199.241.98/forum.php</strong> and try to obtain campaigns to participate in, this is a sample detection rate for the latest fake news items one, and more details on the domains and nameservers used in the latest campaign :<br /><br /><div>news_report-pdf_content.exe</div>Scanners result : 14/31 (45.17%)<br /><div>Backdoor.Win32.Agent.gvk; Backdoor:Win32/Agent.ACG</div>File size: 45056 bytes<br /><div>MD5...: c4849207a94d1db4a0211f88e84b0b59</div>SHA1..: 32ef2a074d563370f46738565ecf9bb53c75909c<br /><div>SHA256: 12a124cc2352f3ef68ddf06e0ed111c617d95cffd807dc502ae474960a60411c</div><br /><div><a href="http://bp2.blogger.com/_wICHhTiQmrA/SAj3y2ORGeI/AAAAAAAABlA/w42Ct-k0dxM/s1600-h/phishing_botnet_subdomains.JPG"><img id="BLOGGER_PHOTO_ID_5190671023465372130" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/SAj3y2ORGeI/AAAAAAAABlA/w42Ct-k0dxM/s200/phishing_botnet_subdomains.JPG" border="0" /></a>An internal nameservers ecosystem within the botnet, active and resolving :</div><br /><strong>ns1.ns4.ns2.ns3.id759.com</strong><br /><div><strong>ns3.ns1.id759.com</strong></div><strong>ns1.ns2.ns1.ns4.ns2.ns3.id759.com</strong><br /><div><strong>ns1.ns2.ns3.id759.com</strong></div><strong>ns1.ns2.ns4.id759.com</strong><br /><div><strong>ns1.ns4.ns4.ns2.ns3.id759.com</strong></div><strong>ns2.id759.com</strong><br /><div><strong>ns2.ns1.ns2.ns3.id759.com</strong></div><strong>ns2.ns1.ns2.ns4.id759.com</strong><br /><div><strong>ns3.ns2.ns1.ns2.ns3.id759.com</strong></div><strong>ns4.ns1.ns1.ns2.ns3.id759.com</strong><br /><br /><div></div>Yet another internal nameservers ecosystem within the botnet :<br /><br /><div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SAj4VGORGfI/AAAAAAAABlI/7_gbSyw-cZ8/s1600-h/phishing_botnet_subdomains_2.JPG"><img id="BLOGGER_PHOTO_ID_5190671611875891698" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SAj4VGORGfI/AAAAAAAABlI/7_gbSyw-cZ8/s200/phishing_botnet_subdomains_2.JPG" border="0" /></a><strong>ns1.serial43.in</strong></div><strong>ns2.serial43.in</strong><br /><div><strong>ns3.serial43.in</strong></div><strong>ns4.serial43.in</strong><br /><div><strong>ns1.ns1.ns1.serial43.in</strong></div><strong>ns1.ns2.ns1.ns1.serial43.in</strong><br /><div><strong>ns1.ns2.ns2.serial43.in</strong></div><strong>ns1.ns4.ns1.ns1.serial43.in</strong><br /><div><strong>ns2.ns1.ns2.serial43.in</strong></div><strong>ns2.ns1.ns4.ns1.ns1.serial43.in</strong><br /><div><strong>ns2.ns2.ns1.ns1.serial43.in</strong></div><div> </div><br /><div> </div>To sum up - these are all of the domains currently active and used for the malware/spam/phishing campaigns on behalf of this botnet :<br /><div> </div><br /><div><strong>server52.org</strong></div><strong>set45.net</strong><br /><div><strong>site83.net</strong></div><strong>sid95.com</strong><br /><div><strong>shell54.com</strong></div><strong>siteid64.com</strong><br /><div><strong>setup36.com</strong></div><strong>share73.com</strong><br /><div><strong>service28.biz</strong></div><br /><div> </div>There are several scenarious related to this particular botnet. Despite that it's the same piece of malware that's successfully adding new zombies to the infected population, the diversity of the campaigns, as well as the fact that for instance share73.com is registered by casta4000 @ mail.ru and is into the "reklama uslug" business which translates to advertising services, in this case spam and phishing emails sending on demand, <a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">access to the botnet could be either offered on demand</a>, or the service itself performed in a typical <a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">managed spamming appliance</a> outsourced business model. Are they also vertically integrating in respect to the fast-fluxing? Yes they are, since they're achieving it without the need to <a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">hire a managed fast-flux provider</a>, which isn't excluding the possibility that they aren't in fact one themselves, as it's evident they've got the capability to become one.</div></div></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UMu0XzG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UMu0XzG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ghlTsaG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ghlTsaG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f0vCgsg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f0vCgsg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pf6BKTg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pf6BKTg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rupM8OG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rupM8OG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gveeK5G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gveeK5G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hl5L8og"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hl5L8og" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/273112081" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Apr 2008 10:57:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/bank digital">bank digital</category>
      <category domain="http://securityratty.com/tag/ns1">ns1</category>
      <category domain="http://securityratty.com/tag/bank bankline">bank bankline</category>
      <category domain="http://securityratty.com/tag/ns2">ns2</category>
      <category domain="http://securityratty.com/tag/bank internet">bank internet</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware variants signal">malware variants signal</category>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/273112081/phishing-emails-generating-botnet.html">Phishing Emails Generating Botnet Scaling</source>
    </item>
    <item>
      <title><![CDATA[Romanian Script Kiddies and the Screensavers Botnet]]></title>
      <link>http://securityratty.com/article/5b5c2da1c83dfe7fd39c5e9ccf463c0b</link>
      <guid>http://securityratty.com/article/5b5c2da1c83dfe7fd39c5e9ccf463c0b</guid>
      <description><![CDATA[Shall we turn into zombies, and peek into the modest botnet courtesy of Romanian script kiddies, that are currently spamming postcard.scr greeting cards? Meet the script kiddies. This botnet is going...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/R_oeXF281TI/AAAAAAAABio/QsYu3itLwtk/s1600-h/romania_malware_screensaver_botnet.jpg"><img id="BLOGGER_PHOTO_ID_5186491302929028402" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R_oeXF281TI/AAAAAAAABio/QsYu3itLwtk/s200/romania_malware_screensaver_botnet.jpg" border="0" /></a>Shall we turn into zombies, and peek into the modest botnet courtesy of Romanian script kiddies, that are currently spamming postcard.scr greeting cards? Meet the script kiddies. This botnet is going nowhere mostly because knowing how to compile an IRC bot doesn't necessarily mean you posses a certain know-how, a know-how that <a href="http://ddanchev.blogspot.com/2008/03/loadsccs-ddos-for-hire-service.html">experienced botnet masters have been outsourcing for years</a>. Malware is obtained through links pointing to :<br /><br /><strong>xhost.ro/filehost/phrame.php?action=saveDownload&amp;fileId=15735</strong><br /><strong>xhost.ro/filehost/phrame.php?action=editDownload&amp;fileId=12923</strong><br /><strong>xhost.ro/filehost/phrame.php?action=saveDownload&amp;fileId=3656</strong><br /><strong>xhost.ro/filehost/phrame.php?action=editDownload&amp;fileId=10936</strong><br /><br /><strong>Scanners result</strong> : Result: 22/32 (68.75%)<br />Trojan.Zapchas.F; IRC/BackDoor.Flood; Backdoor.IRC.Zapchast<br /><strong>File size:</strong> 735139 bytes<br /><strong>MD5</strong>...: 015e5826084f2302b4b2c3237a62e244<br /><strong>SHA1</strong>..: 7d05949f6dfffdc58033c9d8b86210a9bd34897c<br /><br /><a href="http://bp3.blogger.com/_wICHhTiQmrA/R_ssml281WI/AAAAAAAABjA/DrdQlceTJq8/s1600-h/romania_malware_screensaver_botnet2.jpg"><img id="BLOGGER_PHOTO_ID_5186788437356500322" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R_ssml281WI/AAAAAAAABjA/DrdQlceTJq8/s200/romania_malware_screensaver_botnet2.jpg" border="0" /></a><strong>Sample traffic output :</strong><br />"NICK Mq2kC01<br />USER las "" "pic.kauko.lt" :Px7aW6<br />USER las "" "Helsinki.FI.EU.Undernet.org" :Px7aW6<br />USERHOST Mq2kC01<br />NICK :Rk1zK50<br />AWAY :Eu te scuip in cap si'n gura, tu ma pupi in cur si'n pula =))!<br />MODE Mq2kC01 +i<br />ISON loverboy loveru SirDulce<br />JOIN #madarfakar<br />USER kzg "" "Helsinki.FI.EU.Undernet.org" :Ho5xI1<br />NICK :Vm3uF52<br />MODE Mq2kC01 +wx"<br /><br />And in next couple of hours, the most interesting domain that joined the IRC channel was :<br /><br />Ny2fW15 is <a href="mailto:fwuser@mails.legislature.maine.gov">fwuser@mails.legislature.maine.gov</a> * Kg1jT7<br />Ny2fW15 on #madarfakar<br />Ny2fW15 using Noteam.Vs.undernet.org I'm too lazy to edit ircd.conf<br />Ny2fW15 is away: Eu te scuip in cap si'n gura, tu ma pupi in cur si'n pula =))!<br />Ny2fW15 has been idle 1min 31secs, signed on Fri Apr 04 12:05:17<br />Ny2fW15 End of /WHOIS list.<br /><br />This botnet's futile attempt to scale is a great example of the growing importance of <a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">knowlege and experience empowered botnet masters</a>, as a key success factor for sustainability, and also, basic understanding of economic forces, namely, when they're not making an investment there cannot be a return on investment on their efforts at the first place. Take a peek at <a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">the efficiency level of remote file inclusion</a> achieved by another botnet, and at <a href="http://ddanchev.blogspot.com/2007/03/botnet-communication-platforms.html">alternative botnet C&amp;C channels</a> courtesy of botnet masters realizing that diversity is vital.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ly3a6VG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ly3a6VG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Y7KiH0G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Y7KiH0G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4BP9Gvg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4BP9Gvg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gvREVog"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gvREVog" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wpJ8ZTG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wpJ8ZTG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=EpMGHOG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=EpMGHOG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bpwnKNg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bpwnKNg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/266216944" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 07 Apr 2008 23:48:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/botnet">botnet</category>
      <category domain="http://securityratty.com/tag/botnet masters">botnet masters</category>
      <category domain="http://securityratty.com/tag/script kiddies">script kiddies</category>
      <category domain="http://securityratty.com/tag/romanian script kiddies">romanian script kiddies</category>
      <category domain="http://securityratty.com/tag/botnet courtesy">botnet courtesy</category>
      <category domain="http://securityratty.com/tag/ny2fw15">ny2fw15</category>
      <category domain="http://securityratty.com/tag/alternative botnet">alternative botnet</category>
      <category domain="http://securityratty.com/tag/irc">irc</category>
      <category domain="http://securityratty.com/tag/irc bot">irc bot</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/266216944/romanian-script-kiddies-and.html">Romanian Script Kiddies and the Screensavers Botnet</source>
    </item>
    <item>
      <title><![CDATA[How to Survive a Zombie Apocalypse]]></title>
      <link>http://securityratty.com/article/515c88aec91184df75bad8dcd3819981</link>
      <guid>http://securityratty.com/article/515c88aec91184df75bad8dcd3819981</guid>
      <description><![CDATA[What happens when zombies try to take over the world? Here's what you should...]]></description>
      <content:encoded><![CDATA[What happens when zombies try to take over the world? Here's what you should know.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=aaf691ffab8a961291dfabcaa545318b" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=aaf691ffab8a961291dfabcaa545318b" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=HbGKkvG"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=HbGKkvG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=xD1obxg"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=xD1obxg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=80TXnag"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=80TXnag" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=hEz3CeG"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=hEz3CeG" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=lGhd6hG"><img src="http://feeds.wired.com/~f/wired/politics/security?i=lGhd6hG" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=OcO7leg"><img src="http://feeds.wired.com/~f/wired/politics/security?i=OcO7leg" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=xuCk3Tg"><img src="http://feeds.wired.com/~f/wired/politics/security?i=xuCk3Tg" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=gXmpSBG"><img src="http://feeds.wired.com/~f/wired/politics/security?i=gXmpSBG" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/263482032" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/263482033" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 03 Apr 2008 00:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/zombies">zombies</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/263482033/how-to-battle-z.html">How to Survive a Zombie Apocalypse</source>
    </item>
  </channel>
</rss>
