<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Dancho Danchev's Blog - Mind Streams of Information Security Knowledge</title><link>http://ddanchev.blogspot.com/</link><description>In the overwhelming sea of information, access to timely, insightful and independent open-source intelligence (OSINT) analyses is crucial for maintaining the necessary situational awareness to stay on the top of emerging security threats. This blog covers trends and fads, tactics and strategies, intersecting with third-party research, speculations and real-time CYBERINT assessments, all packed with sarcastic attitude</description><language>en</language><managingEditor>noreply@blogger.com (Dancho Danchev)</managingEditor><lastBuildDate>Wed, 01 Feb 2012 15:07:39 PST</lastBuildDate><generator>Blogger http://www.blogger.com</generator><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1140</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">25</openSearch:itemsPerPage><feedburner:info uri="danchodanchevonsecurityandnewmedia" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-nc-sa/3.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://ddanchev.blogspot.com/atom.xml" /><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site, subject to copyright and fair use.</feedburner:browserFriendly><item><title>Summarizing Webroot's Threat Blog Posts for January</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/_daRJJttKEc/summarizing-webroots-threat-blog-posts.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Wed, 01 Feb 2012 15:07:39 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-7093416786154242218</guid><description>The following is a brief summary of all of my posts at Webroot's Threat Blog for January, 2012. You can subscribe to my Webroot's Threat Blog RSS Feed or follow me on Twitter: 



01. Millions of harvested emails offered for sale
02. Email hacking for hire going mainstream
03. Mass SQL injection attack affects over 200,000 URLs
04. A peek inside the PickPocket Botnet
05. A peek inside the&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_daRJJttKEc:9KejYBhuxMU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_daRJJttKEc:9KejYBhuxMU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_daRJJttKEc:9KejYBhuxMU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=_daRJJttKEc:9KejYBhuxMU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_daRJJttKEc:9KejYBhuxMU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=_daRJJttKEc:9KejYBhuxMU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_daRJJttKEc:9KejYBhuxMU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_daRJJttKEc:9KejYBhuxMU:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_daRJJttKEc:9KejYBhuxMU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=_daRJJttKEc:9KejYBhuxMU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/_daRJJttKEc" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-02-02T00:07:39.887+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-eU12GMnVmRs/TynB1n0sKUI/AAAAAAAAFQc/471ORsvtaG8/s72-c/Webroot_Threat_Blog_January_2012.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2012/02/summarizing-webroots-threat-blog-posts.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for January</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/kLiNhZwY9jo/summarizing-zdnets-zero-day-posts-for.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Wed, 01 Feb 2012 14:59:36 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-602196016562853047</guid><description>The following is a brief summary of all of my posts at ZDNet's Zero Day for January, 2012. You can subscribe to my personal RSS feed, Zero Day's main feed, or follow me on Twitter:




01. 'Most beautiful' scams proliferate on Facebook
02. Android users hit by scareware scam
03. 'Remove Facebook Timeline' themed scam circulating on Facebook
04. Fake Kim Jong-il video distributing malware
05.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=kLiNhZwY9jo:ZTrEV7fPBTw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=kLiNhZwY9jo:ZTrEV7fPBTw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=kLiNhZwY9jo:ZTrEV7fPBTw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=kLiNhZwY9jo:ZTrEV7fPBTw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=kLiNhZwY9jo:ZTrEV7fPBTw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=kLiNhZwY9jo:ZTrEV7fPBTw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=kLiNhZwY9jo:ZTrEV7fPBTw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=kLiNhZwY9jo:ZTrEV7fPBTw:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=kLiNhZwY9jo:ZTrEV7fPBTw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=kLiNhZwY9jo:ZTrEV7fPBTw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/kLiNhZwY9jo" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-02-01T23:59:36.396+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-e2_ok9GS7zg/TynBrpuTQFI/AAAAAAAAFQU/sG3YBoOBzzs/s72-c/ZDNet_Zero_Day_January_2012.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2012/02/summarizing-zdnets-zero-day-posts-for.html</feedburner:origLink></item><item><title>Who's Behind the Koobface Botnet? - An OSINT Analysis</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/EvawT7Ph1yk/whos-behind-koobface-botnet-osint.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Tue, 17 Jan 2012 10:58:07 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-2761368693177146196</guid><description>It's full disclosure time.

In this post, I will perform an OSINT analysis, exposing one of the key botnet masters behind the infamous Koobface botnet, that I have been extensively profiling and infiltrating since day one. I will include photos of the botnet master, his telephone numbers, multiple email addresses, license plate for a BMW, and directly connect him with the infrastructure -- now&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=EvawT7Ph1yk:2-d725UjYm4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=EvawT7Ph1yk:2-d725UjYm4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=EvawT7Ph1yk:2-d725UjYm4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=EvawT7Ph1yk:2-d725UjYm4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=EvawT7Ph1yk:2-d725UjYm4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=EvawT7Ph1yk:2-d725UjYm4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=EvawT7Ph1yk:2-d725UjYm4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=EvawT7Ph1yk:2-d725UjYm4:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=EvawT7Ph1yk:2-d725UjYm4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=EvawT7Ph1yk:2-d725UjYm4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/EvawT7Ph1yk" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-17T19:58:07.530+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-69O733usn-M/TwoNpl7P4UI/AAAAAAAAFKk/ACMQAkX3Bds/s72-c/AS42831_koobface.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2012/01/whos-behind-koobface-botnet-osint.html</feedburner:origLink></item><item><title>Profiling a Vendor of Visa/Mastercard Plastics and Holograms</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/iB7bbpTY4Yk/profiling-vendor-of-visamastercard.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Tue, 03 Jan 2012 18:15:29 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-2193781373010042569</guid><description>What is it that cybercriminals needs once they have obtained access to stolen financial data? Next to money mules, that's empty plastic cards in which they will later on embed the stolen financial data.

Let's profile a vendor of empty Visa/Mastercard plastic cards and holograms in order to gain a better picture at just how easy it is to obtain such plastic cards.

Associated nickname: pizzA&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iB7bbpTY4Yk:0pE8UOD1hkg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iB7bbpTY4Yk:0pE8UOD1hkg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iB7bbpTY4Yk:0pE8UOD1hkg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=iB7bbpTY4Yk:0pE8UOD1hkg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iB7bbpTY4Yk:0pE8UOD1hkg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=iB7bbpTY4Yk:0pE8UOD1hkg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iB7bbpTY4Yk:0pE8UOD1hkg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iB7bbpTY4Yk:0pE8UOD1hkg:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iB7bbpTY4Yk:0pE8UOD1hkg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=iB7bbpTY4Yk:0pE8UOD1hkg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/iB7bbpTY4Yk" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-04T03:15:29.153+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-Lm0g4LYvBak/TwMbm4QVt2I/AAAAAAAAFHQ/OHNnOMtpznM/s72-c/ContactSheet-001.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2012/01/profiling-vendor-of-visamastercard.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for December</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/xOrPXtaj4Uo/summarizing-zdnets-zero-day-posts-for_01.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Sun, 01 Jan 2012 11:31:22 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-1896439597791583545</guid><description>The following is a brief summary of all of my posts at ZDNet's Zero Day for December. You can subscribe to my personal RSS feed, Zero Day's main feed, or follow me on Twitter:





01. New study claims that Chrome is the most secure browser
02. FTC issues refunds to scareware victims
03. Yahoo! Mail introduces two factor authentication
04. Web malware exploitation kits updated with new Java&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xOrPXtaj4Uo:osMqn-AX5IM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xOrPXtaj4Uo:osMqn-AX5IM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xOrPXtaj4Uo:osMqn-AX5IM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=xOrPXtaj4Uo:osMqn-AX5IM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xOrPXtaj4Uo:osMqn-AX5IM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=xOrPXtaj4Uo:osMqn-AX5IM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xOrPXtaj4Uo:osMqn-AX5IM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xOrPXtaj4Uo:osMqn-AX5IM:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xOrPXtaj4Uo:osMqn-AX5IM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=xOrPXtaj4Uo:osMqn-AX5IM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/xOrPXtaj4Uo" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-01T20:31:22.585+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-0SbWe19an2I/TwCtVUfp2NI/AAAAAAAAFG4/bbTmJwAZBhI/s72-c/ZDNet_Zero_Day_January_2012.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2012/01/summarizing-zdnets-zero-day-posts-for_01.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for November</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/ZGsnw4sT5QY/summarizing-zdnets-zero-day-posts-for.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Sun, 01 Jan 2012 11:27:54 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-8457346967533289177</guid><description>The following is a brief summary of all of my posts at ZDNet's Zero Day for November. You can subscribe to my personal RSS feed, Zero Day's main feed, or follow me on Twitter:





01. Massive DNS poisoning attack in Brazil serving exploits and malware
02. South Korea to block port 25 as anti-spam countermeasure
03. Researchers spot malware using a stolen government certificate
04. SCADA&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZGsnw4sT5QY:tDQGx9oLRtI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZGsnw4sT5QY:tDQGx9oLRtI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZGsnw4sT5QY:tDQGx9oLRtI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=ZGsnw4sT5QY:tDQGx9oLRtI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZGsnw4sT5QY:tDQGx9oLRtI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=ZGsnw4sT5QY:tDQGx9oLRtI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZGsnw4sT5QY:tDQGx9oLRtI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZGsnw4sT5QY:tDQGx9oLRtI:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZGsnw4sT5QY:tDQGx9oLRtI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=ZGsnw4sT5QY:tDQGx9oLRtI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/ZGsnw4sT5QY" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-01T20:27:54.067+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-YskE0g_qLvY/TwCskhNYgUI/AAAAAAAAFGs/6ipX_evxP5s/s72-c/ZDNet_Zero_Day_January_2012.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2012/01/summarizing-zdnets-zero-day-posts-for.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for October</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/rzhyBJyDtiI/summarizing-zdnets-zero-day-posts-for.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Sun, 04 Dec 2011 11:15:03 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-2335972050981499986</guid><description>The following is a brief summary of all of my posts at ZDNet's Zero Day for October. You can subscribe to my personal      RSS feed, Zero      Day's main feed, or follow me on Twitter:




01. iPhone 5 themed emails serve Windows malware
02. 27 of 100 tested Chrome extensions contain 51 vulnerabilities
03. 37 percent of users browsing the Web with insecure Java versions
04. Google introduces&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rzhyBJyDtiI:z39Xk6zcCiY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rzhyBJyDtiI:z39Xk6zcCiY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rzhyBJyDtiI:z39Xk6zcCiY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=rzhyBJyDtiI:z39Xk6zcCiY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rzhyBJyDtiI:z39Xk6zcCiY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=rzhyBJyDtiI:z39Xk6zcCiY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rzhyBJyDtiI:z39Xk6zcCiY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rzhyBJyDtiI:z39Xk6zcCiY:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rzhyBJyDtiI:z39Xk6zcCiY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=rzhyBJyDtiI:z39Xk6zcCiY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/rzhyBJyDtiI" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-04T20:15:03.334+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-wonhncLQyWI/TtvFFewqI6I/AAAAAAAAFGM/TW-SpYGJw4o/s72-c/ZDNet_Zero_Day_October_2011.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/12/summarizing-zdnets-zero-day-posts-for.html</feedburner:origLink></item><item><title>Exposing the Market for Stolen Credit Cards Data</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/sgMnaFJ_J0w/exposing-market-for-stolen-credit-cards.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Mon, 31 Oct 2011 06:59:03 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-8508938904588594687</guid><description>What's the average price for a stolen credit card? How are prices shaped within the cybercrime ecosystem? Can we talk about price discrimination within the underground marketplace? Just how easy is to purchase stolen credit cards known as dumps or full dumps, nowadays?

In this intelligence brief, I will expose the market for stolen credit cards data, by profiling 20 currently active and&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=sgMnaFJ_J0w:Am94U2TEakA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=sgMnaFJ_J0w:Am94U2TEakA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=sgMnaFJ_J0w:Am94U2TEakA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=sgMnaFJ_J0w:Am94U2TEakA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=sgMnaFJ_J0w:Am94U2TEakA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=sgMnaFJ_J0w:Am94U2TEakA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=sgMnaFJ_J0w:Am94U2TEakA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=sgMnaFJ_J0w:Am94U2TEakA:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=sgMnaFJ_J0w:Am94U2TEakA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=sgMnaFJ_J0w:Am94U2TEakA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/sgMnaFJ_J0w" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-31T14:59:03.087+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-o-hBMbHsl1w/TqWnQEZlmLI/AAAAAAAAE8A/W-Mv4rxaQpM/s72-c/Stolen_Credit_Cards.JPG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/10/exposing-market-for-stolen-credit-cards.html</feedburner:origLink></item><item><title>Dissecting the Ongoing Mass SQL Injection Attack</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/rHh3cXAGqrg/dissecting-ongoing-mass-sql-injection.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Fri, 21 Oct 2011 14:51:33 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-2937085544602995384</guid><description>The ongoing mass SQL injection attack, has already affected over a million web sites. Cybercriminals performing active search engines reconnaissance have managed to inject a malicious script into ASP ASP.NET websites.



From client-side exploits to bogus Adobe Flash players, the campaign is active and ongoing. In this intelligence brief, we'll dissect the campaign and establish a direct&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rHh3cXAGqrg:2zBv7AKq-e4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rHh3cXAGqrg:2zBv7AKq-e4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rHh3cXAGqrg:2zBv7AKq-e4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=rHh3cXAGqrg:2zBv7AKq-e4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rHh3cXAGqrg:2zBv7AKq-e4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=rHh3cXAGqrg:2zBv7AKq-e4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rHh3cXAGqrg:2zBv7AKq-e4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rHh3cXAGqrg:2zBv7AKq-e4:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=rHh3cXAGqrg:2zBv7AKq-e4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=rHh3cXAGqrg:2zBv7AKq-e4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/rHh3cXAGqrg" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-21T23:51:33.278+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-tutjpY1zBL4/TqCPib00XvI/AAAAAAAAE7o/S662V2zNbxg/s72-c/Mass_SQL_Injection_Attack_03.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/10/dissecting-ongoing-mass-sql-injection.html</feedburner:origLink></item><item><title>Spamvertised IRS-themed "Last Notice" Emails Serving Malware</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/g3ii7AwbXIw/spamvertised-irs-themed-last-notice.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Tue, 18 Oct 2011 12:45:13 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-537047482093943149</guid><description>Cybercriminals are once again impersonating the Internal Revenue Service (IRS) for malware-serving purposes. In this intelligence brief, we'll dissect the malware campaign.

Spamvertised attachment: IRS_Calculations_#ID6749.zipSpamvertised message: Notice, There are arrears reckoned on your account over a period of 2010-2011 year. You will find all calculations according to your financial debt&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=g3ii7AwbXIw:iq6QlWeYdOQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=g3ii7AwbXIw:iq6QlWeYdOQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=g3ii7AwbXIw:iq6QlWeYdOQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=g3ii7AwbXIw:iq6QlWeYdOQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=g3ii7AwbXIw:iq6QlWeYdOQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=g3ii7AwbXIw:iq6QlWeYdOQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=g3ii7AwbXIw:iq6QlWeYdOQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=g3ii7AwbXIw:iq6QlWeYdOQ:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=g3ii7AwbXIw:iq6QlWeYdOQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=g3ii7AwbXIw:iq6QlWeYdOQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/g3ii7AwbXIw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-18T21:45:13.907+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-h_lmuWdRVak/Tp3JgVycXpI/AAAAAAAAE7g/rOfUIzGlctg/s72-c/IRS_malware_last_notice.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/10/spamvertised-irs-themed-last-notice.html</feedburner:origLink></item><item><title>Spamvertised "IRS notice" Serving Malware</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/cdZmRU38s5E/spamvertised-irs-notice-serving-malware.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Sun, 09 Oct 2011 10:55:40 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-2900965514000896431</guid><description>Cybercriminals are spamvertising yet another malware-serving campaign. Impersonating the IRS, malicious attackers are attempting to entice end users into downloading and executing a malicious file attachment. 
 
Spamvertised message: Tax notice, There are arrears reckoned on your account over a period of 2010-2011 year. You will find all calculations according to your financial debt, enclosed.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cdZmRU38s5E:mZgXiyqfi9E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cdZmRU38s5E:mZgXiyqfi9E:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cdZmRU38s5E:mZgXiyqfi9E:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=cdZmRU38s5E:mZgXiyqfi9E:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cdZmRU38s5E:mZgXiyqfi9E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=cdZmRU38s5E:mZgXiyqfi9E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cdZmRU38s5E:mZgXiyqfi9E:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cdZmRU38s5E:mZgXiyqfi9E:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cdZmRU38s5E:mZgXiyqfi9E:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=cdZmRU38s5E:mZgXiyqfi9E:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/cdZmRU38s5E" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-09T19:55:40.860+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-uKXzBr4F1p4/TpGQoLomWiI/AAAAAAAAE7c/W_e7RRS90n4/s72-c/IRS_Notice_malware.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/10/spamvertised-irs-notice-serving-malware.html</feedburner:origLink></item><item><title>Spamvertised "NACHA security nitification" Serving Malware - Historical OSINT</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/N0xs4wSlHzM/spamvertised-nacha-security.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Tue, 04 Oct 2011 07:55:33 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-7904058077275736092</guid><description>The following intelligence brief will offer historical OSINT on the "NACHA security nitification" -- the typo is intentionally left as this is how the original campaign was spamvertised -- malware campaign.

Spamvertised body:
Dear Valued Client,We strongly believe that your account may have been compromised. Due to this, we cancelled the last ACH transactions:-(ID: 13104924)-(ID: 04804768)-(&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=N0xs4wSlHzM:hAqYf0MZ11g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=N0xs4wSlHzM:hAqYf0MZ11g:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=N0xs4wSlHzM:hAqYf0MZ11g:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=N0xs4wSlHzM:hAqYf0MZ11g:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=N0xs4wSlHzM:hAqYf0MZ11g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=N0xs4wSlHzM:hAqYf0MZ11g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=N0xs4wSlHzM:hAqYf0MZ11g:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=N0xs4wSlHzM:hAqYf0MZ11g:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=N0xs4wSlHzM:hAqYf0MZ11g:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=N0xs4wSlHzM:hAqYf0MZ11g:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/N0xs4wSlHzM" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-04T16:55:33.555+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-KIyTyriN3Z0/ToqAYziKT8I/AAAAAAAAE7Y/6j22zsNKIkQ/s72-c/nacha_malware.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/10/spamvertised-nacha-security.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for September</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/0Z7G5Ly9Cng/summarizing-zdnets-zero-day-posts-for.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Tue, 04 Oct 2011 05:37:07 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-8334202101470258125</guid><description>The following is a brief summary of all of my posts at ZDNet's Zero Day for September. You can subscribe to my personal      RSS feed, Zero      Day's main feed, or follow me on Twitter:



01. Spamvertised 'Facebook notification' leads to exploits and malware 
02. Google, Mozilla and Microsoft ban the DigiNotar Certificate Authority in their browsers 
03. Microsoft themed ransomware variant&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=0Z7G5Ly9Cng:mDeccwEByfM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=0Z7G5Ly9Cng:mDeccwEByfM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=0Z7G5Ly9Cng:mDeccwEByfM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=0Z7G5Ly9Cng:mDeccwEByfM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=0Z7G5Ly9Cng:mDeccwEByfM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=0Z7G5Ly9Cng:mDeccwEByfM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=0Z7G5Ly9Cng:mDeccwEByfM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=0Z7G5Ly9Cng:mDeccwEByfM:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=0Z7G5Ly9Cng:mDeccwEByfM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=0Z7G5Ly9Cng:mDeccwEByfM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/0Z7G5Ly9Cng" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-04T14:37:07.655+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-MvsrDCRrXPA/Top8aXc2JRI/AAAAAAAAE7Q/DJtoUouqS0k/s72-c/ZDNet_Zero_Day_September.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/10/summarizing-zdnets-zero-day-posts-for.html</feedburner:origLink></item><item><title>Spamvertised 'Uniform Traffic Ticket' and 'FDIC Notifications' Serving Malware - Historical OSINT</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/xdR7715Eb9Q/spamvertised-uniform-traffic-ticket-and.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Wed, 28 Sep 2011 05:43:48 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-857608395885836728</guid><description>The following intelligence brief will summarize the findings from a brief analysis performed on two malware campaigns from August, namely, the spamvertised Uniform Traffic Tickets and the FDIC Notification.



_Uniform Traffic Tickets

Spamvertised attachments - Ticket-728-2011.zip; Ticket-064-211.zip; Ticket-728-2011.zip

Detection rates:
Ticket.exe - Gen:Trojan.Heur.FU.bqW@aK9ebrii -  Detection&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xdR7715Eb9Q:mD-cFG-Ps14:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xdR7715Eb9Q:mD-cFG-Ps14:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xdR7715Eb9Q:mD-cFG-Ps14:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=xdR7715Eb9Q:mD-cFG-Ps14:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xdR7715Eb9Q:mD-cFG-Ps14:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=xdR7715Eb9Q:mD-cFG-Ps14:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xdR7715Eb9Q:mD-cFG-Ps14:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xdR7715Eb9Q:mD-cFG-Ps14:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xdR7715Eb9Q:mD-cFG-Ps14:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=xdR7715Eb9Q:mD-cFG-Ps14:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/xdR7715Eb9Q" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-28T14:43:48.899+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-RhedU84jjx8/ToIFTTDPUOI/AAAAAAAAE7I/rLFavjVbk_w/s72-c/ny-ticket.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/09/spamvertised-uniform-traffic-ticket-and.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for August</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/9KCHscIOKxw/summarizing-zdnets-zero-day-posts-for.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Tue, 27 Sep 2011 10:13:08 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-3882512462149653917</guid><description>The following is a brief summary of all of my posts at ZDNet's Zero Day for August. You can subscribe to my personal      RSS feed, Zero      Day's main feed, or follow me on Twitter:



01. Study: Rootkits target pirated copies of Windows XP 
02. 56 percent of enterprise users using vulnerable Adobe Reader plugins 
03. New malware attack circulating on Facebook 
04. Kaspersky: 12 different&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9KCHscIOKxw:jFmWQH6GxHM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9KCHscIOKxw:jFmWQH6GxHM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9KCHscIOKxw:jFmWQH6GxHM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=9KCHscIOKxw:jFmWQH6GxHM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9KCHscIOKxw:jFmWQH6GxHM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=9KCHscIOKxw:jFmWQH6GxHM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9KCHscIOKxw:jFmWQH6GxHM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9KCHscIOKxw:jFmWQH6GxHM:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9KCHscIOKxw:jFmWQH6GxHM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=9KCHscIOKxw:jFmWQH6GxHM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/9KCHscIOKxw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-27T19:13:08.205+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-j9tlauN0TeQ/ToICnuFMSGI/AAAAAAAAE7A/hKwpqtrd0QY/s72-c/ZDNet_Zero_Day_August_2011.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/09/summarizing-zdnets-zero-day-posts-for.html</feedburner:origLink></item><item><title>Summarizing 3 Years of Research Into Cyber Jihad</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/IHLyLp23BBg/summarizing-3-years-of-research-into.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Sun, 11 Sep 2011 04:34:34 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-4105010951267007123</guid><description>On this very special day, I'd like to honor the fallen by summarizing my research into cyber jihad, a topic I'm still highly passionate about. Enjoy and share it with your social circle!

Tracking Down Internet Terrorist Propaganda
Arabic Extremist Group Forum Messages' Characteristics
Cyber Terrorism Communications and Propaganda
A Cost-Benefit Analysis of Cyber Terrorism
Current State of&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IHLyLp23BBg:08Ni913Gozc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IHLyLp23BBg:08Ni913Gozc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IHLyLp23BBg:08Ni913Gozc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=IHLyLp23BBg:08Ni913Gozc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IHLyLp23BBg:08Ni913Gozc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=IHLyLp23BBg:08Ni913Gozc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IHLyLp23BBg:08Ni913Gozc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IHLyLp23BBg:08Ni913Gozc:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IHLyLp23BBg:08Ni913Gozc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=IHLyLp23BBg:08Ni913Gozc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/IHLyLp23BBg" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-11T13:34:34.289+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-nEUV2KU28Zg/TmyYsSZwA8I/AAAAAAAAE68/6rSEcplvi2A/s72-c/cyber_jihadist_communities.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/09/summarizing-3-years-of-research-into.html</feedburner:origLink></item><item><title>Keeping Money Mule Recruiters on a Short Leash - Part Eleven</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/HVyB2h0z2Ac/keeping-money-mule-recruiters-on-short.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Mon, 29 Aug 2011 06:51:42 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-4419049512412350216</guid><description>The following intelligence brief is part of the Keeping Money Mule Recruiters on a Short Leash series.
 In it, I'll expose currently active money mule recruitment domains, 
their domain registration details, currently responding IPs, and related
 ASs.

Money mule recruitment domains:


ACWOODE-GROUP.COM - 78.46.105.205 - Email: admin@acwoode-group.com    ACWOODE-GROUP.NET - 78.46.105.205 -&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=HVyB2h0z2Ac:HuTqtFLV44U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=HVyB2h0z2Ac:HuTqtFLV44U:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=HVyB2h0z2Ac:HuTqtFLV44U:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=HVyB2h0z2Ac:HuTqtFLV44U:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=HVyB2h0z2Ac:HuTqtFLV44U:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=HVyB2h0z2Ac:HuTqtFLV44U:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=HVyB2h0z2Ac:HuTqtFLV44U:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=HVyB2h0z2Ac:HuTqtFLV44U:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=HVyB2h0z2Ac:HuTqtFLV44U:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=HVyB2h0z2Ac:HuTqtFLV44U:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/HVyB2h0z2Ac" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-29T15:51:42.902+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-B6JItIdHwss/Tlt-EVVmpuI/AAAAAAAAE6s/ZVhCfkQvbgE/s72-c/Money_Mule_Recruitment_August_2011_01.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/08/keeping-money-mule-recruiters-on-short.html</feedburner:origLink></item><item><title>A Peek Inside Web Malware Exploitation Kits</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/aZlKTM9T5fk/peek-inside-web-malware-exploitation.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Mon, 29 Aug 2011 04:30:53 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-7927984124562528615</guid><description>With web malware exploitation kits, continuing to represent the attack method of choice for the majority of cybercriminals thanks to the overall susceptibility of end and enterprise users to client-side exploitation attacks, it's always worth taking a peek inside them from the perspective of the malicious attacker.

In this post, we'll take a peek inside three web malware exploitation kits, and&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=aZlKTM9T5fk:hKnU-BuNqWQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=aZlKTM9T5fk:hKnU-BuNqWQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=aZlKTM9T5fk:hKnU-BuNqWQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=aZlKTM9T5fk:hKnU-BuNqWQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=aZlKTM9T5fk:hKnU-BuNqWQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=aZlKTM9T5fk:hKnU-BuNqWQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=aZlKTM9T5fk:hKnU-BuNqWQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=aZlKTM9T5fk:hKnU-BuNqWQ:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=aZlKTM9T5fk:hKnU-BuNqWQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=aZlKTM9T5fk:hKnU-BuNqWQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/aZlKTM9T5fk" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-29T13:30:53.346+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-bmN4o62dMmw/Tlth60Y7FSI/AAAAAAAAE6U/ZlFYkeRzp5g/s72-c/31372543.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/08/peek-inside-web-malware-exploitation.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for July</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/OWQg9yl0S7c/summarizing-zdnets-zero-day-posts-for.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Mon, 22 Aug 2011 09:06:22 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-3577437484134911644</guid><description>  
The following is a brief summary of all of my posts at ZDNet's Zero Day for July. You can subscribe to my personal      RSS feed, Zero      Day's main feed, or follow me on Twitter:




01.'Leaked Video of Casey Anthony CONFESSING to Lawyer!' scam spreading on Facebook
02. Anonymous leaks 90,000+ emails from compromised military contractor Booz Allen Hamilton
03. 'This girl must be Out of&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=OWQg9yl0S7c:vLT0SAAKTAk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=OWQg9yl0S7c:vLT0SAAKTAk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=OWQg9yl0S7c:vLT0SAAKTAk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=OWQg9yl0S7c:vLT0SAAKTAk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=OWQg9yl0S7c:vLT0SAAKTAk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=OWQg9yl0S7c:vLT0SAAKTAk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=OWQg9yl0S7c:vLT0SAAKTAk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=OWQg9yl0S7c:vLT0SAAKTAk:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=OWQg9yl0S7c:vLT0SAAKTAk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=OWQg9yl0S7c:vLT0SAAKTAk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/OWQg9yl0S7c" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-22T18:06:22.021+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-Ofx1p-jnCxw/TlJ7g2ELUNI/AAAAAAAAE6M/rZvosUvCwIU/s72-c/ZDNet_Zero_Day_August_2011.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://ddanchev.blogspot.com/2011/08/summarizing-zdnets-zero-day-posts-for.html</feedburner:origLink></item><item><title>Keeping Money Mule Recruiters on a Short Leash - Part Ten</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/3SkRjV-T7JM/keeping-money-mule-recruiters-on-short.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Thu, 07 Jul 2011 04:25:57 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-7724354046763947462</guid><description>The following intelligence brief is part of the Keeping Money Mule Recruiters on a Short Leash series. In it, I'll expose currently active money mule recruitment domains, their domain registration details, currently responding IPs, and related ASs.

Currently active money mule recruitment domains:
ACWOODE-GROUP.COM - 184.168.64.173 - Email: admin@acwoode-group.com
ACWOODE-GROUP.NET -&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3SkRjV-T7JM:sg8fbElUdcI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3SkRjV-T7JM:sg8fbElUdcI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3SkRjV-T7JM:sg8fbElUdcI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=3SkRjV-T7JM:sg8fbElUdcI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3SkRjV-T7JM:sg8fbElUdcI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=3SkRjV-T7JM:sg8fbElUdcI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3SkRjV-T7JM:sg8fbElUdcI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3SkRjV-T7JM:sg8fbElUdcI:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3SkRjV-T7JM:sg8fbElUdcI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=3SkRjV-T7JM:sg8fbElUdcI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/3SkRjV-T7JM" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-07T13:25:57.327+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-66RXMJqntSo/ThWKFjK-5KI/AAAAAAAAE6E/NkQJrKWBsqk/s72-c/June_money_mule_recruitment_02.PNG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2011/07/keeping-money-mule-recruiters-on-short.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for June</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/QBGI5YC4omc/summarizing-zdnets-zero-day-posts-for.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Thu, 07 Jul 2011 03:29:13 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-7560496520447147522</guid><description>The following is a brief summary of all of my posts at ZDNet's Zero Day for June. You can subscribe to my personal      RSS feed, Zero      Day's main feed, or follow me on Twitter:



01. 'Hot Lesbian Video - Rihanna and Hayden Panettiere' scam on Facebook leads to Mac malware
02. Sony Europe hacked by Lebanese grey hat hacker 
03. Spamvertised United Parcel Service emails lead to scareware 
04&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QBGI5YC4omc:49G92PmsKWY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QBGI5YC4omc:49G92PmsKWY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QBGI5YC4omc:49G92PmsKWY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=QBGI5YC4omc:49G92PmsKWY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QBGI5YC4omc:49G92PmsKWY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=QBGI5YC4omc:49G92PmsKWY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QBGI5YC4omc:49G92PmsKWY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QBGI5YC4omc:49G92PmsKWY:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QBGI5YC4omc:49G92PmsKWY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=QBGI5YC4omc:49G92PmsKWY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/QBGI5YC4omc" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-07T12:29:13.410+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-usiIv-xyb00/ThWI8NigSuI/AAAAAAAAE6A/DR1ayhMcrRc/s72-c/June_ZDNet_Zero_Day.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2011/07/summarizing-zdnets-zero-day-posts-for.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for May</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/RSnnkSpdkQA/summarizing-zdnets-zero-day-posts-for.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Wed, 08 Jun 2011 07:29:47 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-1853750272932519621</guid><description>The following is a brief summary of all of my posts at ZDNet's Zero Day for May. You can subscribe to my personal      RSS feed, Zero      Day's main feed, or follow me on Twitter:

Recommended reading:
China's Blue Army: When nations harness hacktivists for information warfare
01. Vishing attack on Skype pushing scareware 
02. Commtouch: 71 percent increase in new zombies 
03. Osama execution&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=RSnnkSpdkQA:ZICEZFrBJlo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=RSnnkSpdkQA:ZICEZFrBJlo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=RSnnkSpdkQA:ZICEZFrBJlo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=RSnnkSpdkQA:ZICEZFrBJlo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=RSnnkSpdkQA:ZICEZFrBJlo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=RSnnkSpdkQA:ZICEZFrBJlo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=RSnnkSpdkQA:ZICEZFrBJlo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=RSnnkSpdkQA:ZICEZFrBJlo:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=RSnnkSpdkQA:ZICEZFrBJlo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=RSnnkSpdkQA:ZICEZFrBJlo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/RSnnkSpdkQA" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-08T16:29:47.001+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-SsCOISM2YEY/Te-F3v0QDSI/AAAAAAAAE54/wKZFvr1UtRk/s72-c/a4808f8014d1e345559618b4e27c97f9.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2011/06/summarizing-zdnets-zero-day-posts-for.html</feedburner:origLink></item><item><title>Keeping Money Mule Recruiters on a Short Leash - Part Nine</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/iH9sFuoC3n8/keeping-money-mule-recruiters-on-short_30.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Mon, 30 May 2011 03:09:24 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-3086174675982629189</guid><description>The following brief summarizes currently active money mule recruitment web sites, actively recruiting money mules for the processing of fraudulently obtained funds.

Currently active sites residing within AS42708, PORTLANE Network www.portlane.com; AS29713, INTERPLEXINC Interplex LLC; AS38913, Enter-Net-Team-AS; AS24940, HETZNER-AS Hetzner Online:
ATLANTALTD-UK.CC - 193.105.134.233&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iH9sFuoC3n8:feJemhtd4YQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iH9sFuoC3n8:feJemhtd4YQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iH9sFuoC3n8:feJemhtd4YQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=iH9sFuoC3n8:feJemhtd4YQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iH9sFuoC3n8:feJemhtd4YQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=iH9sFuoC3n8:feJemhtd4YQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iH9sFuoC3n8:feJemhtd4YQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iH9sFuoC3n8:feJemhtd4YQ:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=iH9sFuoC3n8:feJemhtd4YQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=iH9sFuoC3n8:feJemhtd4YQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/iH9sFuoC3n8" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-05-30T12:09:24.781+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-Lo9QziJ68ko/TeNn6eEh-5I/AAAAAAAAE5s/vFpsg4xRqqU/s72-c/May_money_mule_recruitment_01.PNG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2011/05/keeping-money-mule-recruiters-on-short_30.html</feedburner:origLink></item><item><title>A Peek Inside the Vertex Net Loader</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/JzPPN1E9-bc/peek-inside-vertex-net-loader.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Thu, 26 May 2011 07:35:32 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-4584099956684457038</guid><description>It appears that the author of the of the DarkComet RAT has been keeping himself rather busy.

In early-stage development (currently in BETA), the Vertex Net Loader is your typical web-based command and control malware loader, worth keeping an eye on.

More details:
Info on the loader:
This is the small program that will send/retrieve info from/to the web panel , it is like the server part of a&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JzPPN1E9-bc:D-pPVc4QcMw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JzPPN1E9-bc:D-pPVc4QcMw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JzPPN1E9-bc:D-pPVc4QcMw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=JzPPN1E9-bc:D-pPVc4QcMw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JzPPN1E9-bc:D-pPVc4QcMw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=JzPPN1E9-bc:D-pPVc4QcMw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JzPPN1E9-bc:D-pPVc4QcMw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JzPPN1E9-bc:D-pPVc4QcMw:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JzPPN1E9-bc:D-pPVc4QcMw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=JzPPN1E9-bc:D-pPVc4QcMw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/JzPPN1E9-bc" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-05-26T16:35:32.678+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-aAu93De1iFo/TdzraOk-3yI/AAAAAAAAE5I/TQ4UMBOWzm0/s72-c/Vertex_Net_Loader_01.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2011/05/peek-inside-vertex-net-loader.html</feedburner:origLink></item><item><title>Keeping Money Mule Recruiters on a Short Leash - Part Eight - Historical OSINT</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/tzpxX-DHUSw/keeping-money-mule-recruiters-on-short_25.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Wed, 25 May 2011 04:18:16 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-1919823529044152748</guid><description>With money mule recruitment scams continuing to represent an inseparable part of the cybercrime ecosystem, in this post I'll summarize the findings from an assessment I conducted on currently active mule recruitment scams over a month ago. As always, the historical OSINT offered is invaluable in case-building practices in particular a very well segmented group of mule recruiters using identical&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tzpxX-DHUSw:DEmSsi4RciQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tzpxX-DHUSw:DEmSsi4RciQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tzpxX-DHUSw:DEmSsi4RciQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tzpxX-DHUSw:DEmSsi4RciQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tzpxX-DHUSw:DEmSsi4RciQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tzpxX-DHUSw:DEmSsi4RciQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tzpxX-DHUSw:DEmSsi4RciQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tzpxX-DHUSw:DEmSsi4RciQ:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tzpxX-DHUSw:DEmSsi4RciQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tzpxX-DHUSw:DEmSsi4RciQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/tzpxX-DHUSw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2011-05-25T13:18:16.067+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-8D46sf_T778/Tdzj0lTyt0I/AAAAAAAAE5A/u8C64QK1QZI/s72-c/Historical_OSINT_money_mule_recruitment_scams.PNG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2011/05/keeping-money-mule-recruiters-on-short_25.html</feedburner:origLink></item></channel></rss>

