<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Dancho Danchev's Blog - Mind Streams of Information Security Knowledge</title><link>http://ddanchev.blogspot.com/</link><description>In the overwhelming sea of information, access to timely, insightful and independent open-source intelligence (OSINT) analyses is crucial for maintaining the necessary situational awareness to stay on the top of emerging security threats. This blog covers trends and fads, tactics and strategies, intersecting with third-party research, speculations and real-time CYBERINT assessments, all packed with sarcastic attitude</description><language>en</language><managingEditor>noreply@blogger.com (Dancho Danchev)</managingEditor><lastBuildDate>Tue, 14 May 2013 12:22:47 PDT</lastBuildDate><generator>Blogger http://www.blogger.com</generator><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1178</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">25</openSearch:itemsPerPage><feedburner:info uri="danchodanchevonsecurityandnewmedia" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-nc-sa/3.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://ddanchev.blogspot.com/atom.xml" /><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site, subject to copyright and fair use.</feedburner:browserFriendly><item><title>Summarizing Webroot's Threat Blog Posts for April</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/cUJPjaHP7nM/summarizing-webroots-threat-blog-posts.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Wed, 01 May 2013 05:32:59 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-3332115271786917054</guid><description>The following is a brief summary of all of my posts at Webroot's Threat Blog for April, 2013. You can subscribe to Webroot's Threat Blog RSS Feed, or follow me on Twitter:




01. DIY Java-based RAT (Remote Access Tool) spotted in the wild02. Spamvertised ‘Re: Changelog as promised’ themed emails lead to malware03. Cybercrime-friendly service offers access to tens of thousands of compromised&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cUJPjaHP7nM:2xL530I3ha8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cUJPjaHP7nM:2xL530I3ha8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cUJPjaHP7nM:2xL530I3ha8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=cUJPjaHP7nM:2xL530I3ha8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cUJPjaHP7nM:2xL530I3ha8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=cUJPjaHP7nM:2xL530I3ha8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cUJPjaHP7nM:2xL530I3ha8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cUJPjaHP7nM:2xL530I3ha8:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cUJPjaHP7nM:2xL530I3ha8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=cUJPjaHP7nM:2xL530I3ha8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/cUJPjaHP7nM" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-05-01T14:32:59.042+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-u5EB6--XZdo/UYEG8Cv7PmI/AAAAAAAAFl0/baDNqF1wIRc/s72-c/Webroot_Threat_Blog_April_2013.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2013/05/summarizing-webroots-threat-blog-posts.html</feedburner:origLink></item><item><title>What's the ROI on Going to a Virtual Blackhat SEO School?</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/tuzUDKFti3w/whats-roi-on-going-to-virtual-blackhat.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Wed, 17 Apr 2013 14:46:36 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-555654894689466034</guid><description>For years, fraudulent or purely malicious actors have been abusing the online advertising market, by directly hijacking and redirecting the revenue flow, or by successfully and efficiently hijacking as much percentage of legitimate search traffic as possible, and monetizing it through the use of blackhat SEO (search engine optimization) tactics/shady affiliate networks. 

Monetizing the very&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tuzUDKFti3w:XaEtOH7xb6w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tuzUDKFti3w:XaEtOH7xb6w:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tuzUDKFti3w:XaEtOH7xb6w:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tuzUDKFti3w:XaEtOH7xb6w:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tuzUDKFti3w:XaEtOH7xb6w:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tuzUDKFti3w:XaEtOH7xb6w:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tuzUDKFti3w:XaEtOH7xb6w:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tuzUDKFti3w:XaEtOH7xb6w:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tuzUDKFti3w:XaEtOH7xb6w:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tuzUDKFti3w:XaEtOH7xb6w:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/tuzUDKFti3w" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-17T23:46:36.382+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-3xz72uqOGj0/UW2YqqPdmkI/AAAAAAAAFik/-JvWBNaoODc/s72-c/Black_Hat_SEO_Training_School.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2013/04/whats-roi-on-going-to-virtual-blackhat.html</feedburner:origLink></item><item><title>Historical OSINT - The "BadB International" Cybercrime Enterprise</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/1w8G5fqVUMY/historical-osint-badb-international.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Wed, 10 Apr 2013 12:53:30 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-7439199687911381424</guid><description>BadB is the nickname of Vladislav Anatolievich Horohorin, a high profile carder, who eventually got busted in France in 2010. This month, he was sentenced to serve 88 months in prison, ordered to pay $125,739 in restitution, and sentenced to two years of supervised release. 



In the wake of these events, I decided to release some raw OSINT data regarding BadB's official Web site, hxxp://&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=1w8G5fqVUMY:tnvjL3y5Tf0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=1w8G5fqVUMY:tnvjL3y5Tf0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=1w8G5fqVUMY:tnvjL3y5Tf0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=1w8G5fqVUMY:tnvjL3y5Tf0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=1w8G5fqVUMY:tnvjL3y5Tf0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=1w8G5fqVUMY:tnvjL3y5Tf0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=1w8G5fqVUMY:tnvjL3y5Tf0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=1w8G5fqVUMY:tnvjL3y5Tf0:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=1w8G5fqVUMY:tnvjL3y5Tf0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=1w8G5fqVUMY:tnvjL3y5Tf0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/1w8G5fqVUMY" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-10T21:53:30.317+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-5DB_FlGAZH8/UWWy8zi0bjI/AAAAAAAAFh8/TDtW-842EpY/s72-c/bn_badb.gif" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2013/04/historical-osint-badb-international.html</feedburner:origLink></item><item><title>Summarizing Webroot's Threat Blog Posts for March</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/Adf_LtVohS0/summarizing-webroots-threat-blog-posts.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Mon, 01 Apr 2013 12:37:21 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-160570750545584713</guid><description>The following is a brief summary of all of my posts at Webroot's Threat Blog for March, 2013. You can subscribe to Webroot's Threat Blog RSS Feed, or follow me on Twitter:




01. New DIY IRC-based DDoS bot spotted in the wild
02. Cybercriminals release new Java exploits centered exploit kit
03. Segmented Russian “spam leads” offered for sale
04. New DIY hacked email account content grabbing&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Adf_LtVohS0:eSbHl_4t-oI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Adf_LtVohS0:eSbHl_4t-oI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Adf_LtVohS0:eSbHl_4t-oI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=Adf_LtVohS0:eSbHl_4t-oI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Adf_LtVohS0:eSbHl_4t-oI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=Adf_LtVohS0:eSbHl_4t-oI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Adf_LtVohS0:eSbHl_4t-oI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Adf_LtVohS0:eSbHl_4t-oI:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Adf_LtVohS0:eSbHl_4t-oI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=Adf_LtVohS0:eSbHl_4t-oI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/Adf_LtVohS0" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-04-01T21:37:21.733+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-nWosh7pzQvc/UVngakDgo3I/AAAAAAAAFhk/NCSS3DH4-Qc/s72-c/Webroot_Threat_Blog_March_2013.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2013/04/summarizing-webroots-threat-blog-posts.html</feedburner:origLink></item><item><title>Dissecting NBC's Late Night with Jimmy Fallon Web Site Compromise</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/tmDk4G4wWDI/dissecting-nbcs-late-night-with-jimmy.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Wed, 06 Mar 2013 14:52:11 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-8794223618351123073</guid><description>Oops, they did it again!
The official Web site (hxxp://www.latenightwithjimmyfallon.com) of NBC's Late Night With Jimmy Fallon is currently compromised/hacked and is automatically serving multiple Java exploits to its visitors through a tiny iFrame element embedded on the front page. According to Google's Safe Browsing Diagnostic page, the same malicious iFrame domain that affected the Web&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tmDk4G4wWDI:lFG0iJ0fjTo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tmDk4G4wWDI:lFG0iJ0fjTo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tmDk4G4wWDI:lFG0iJ0fjTo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tmDk4G4wWDI:lFG0iJ0fjTo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tmDk4G4wWDI:lFG0iJ0fjTo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tmDk4G4wWDI:lFG0iJ0fjTo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tmDk4G4wWDI:lFG0iJ0fjTo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tmDk4G4wWDI:lFG0iJ0fjTo:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tmDk4G4wWDI:lFG0iJ0fjTo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tmDk4G4wWDI:lFG0iJ0fjTo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/tmDk4G4wWDI" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-06T23:52:11.886+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-EGDTSLHNtfs/UTfFIJvKynI/AAAAAAAAFhU/S7jsNaGvLMc/s72-c/NBC_Hacked_Compromised_Malware_Exploits_March_2013.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2013/03/dissecting-nbcs-late-night-with-jimmy.html</feedburner:origLink></item><item><title>Summarizing Webroot's Threat Blog Posts for February</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/B3uS8KFmW2o/summarizing-webroots-threat-blog-posts.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Mon, 04 Mar 2013 05:31:56 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-8320037094359364349</guid><description>The following is a brief summary of all of my posts at Webroot's Threat Blog for February, 2013. You can subscribe to Webroot's Threat Blog RSS Feed, or follow me on Twitter:



  
01. Fake Booking.com ‘Credit Card was not Accepted’ themed emails lead to malware
02. Fake FedEx ‘Tracking ID/Tracking Number/Tracking Detail’ themed emails lead to malware
03. ‘Your Kindle e-book Amazon receipt’&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=B3uS8KFmW2o:ombkB7433Y0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=B3uS8KFmW2o:ombkB7433Y0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=B3uS8KFmW2o:ombkB7433Y0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=B3uS8KFmW2o:ombkB7433Y0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=B3uS8KFmW2o:ombkB7433Y0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=B3uS8KFmW2o:ombkB7433Y0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=B3uS8KFmW2o:ombkB7433Y0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=B3uS8KFmW2o:ombkB7433Y0:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=B3uS8KFmW2o:ombkB7433Y0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=B3uS8KFmW2o:ombkB7433Y0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/B3uS8KFmW2o" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-04T14:31:56.952+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-iOgAVCGKEh4/UTSe5dU0cfI/AAAAAAAAFg8/rIEVYJDdaQA/s72-c/Webroot_Threat_Blog_February_2013.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2013/03/summarizing-webroots-threat-blog-posts.html</feedburner:origLink></item><item><title>Dissecting NBC's Exploits and Malware Serving Web Site Compromise</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/QSGZC_bTDKY/dissecting-nbcs-exploits-and-malware.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Thu, 21 Feb 2013 12:03:44 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-1160831384514333516</guid><description>The web site of the National Broadcasting Company (NBC), NBC.com, is currently compromised, and is redirecting tens of thousands of legitimate users to multiple exploits serving and malware dropping malicious URLs. The campaign appears to have been launched by the same gang of cybercriminals that's also been recently involved in impersonating Facebook Inc. and Verizon Wireless, in an attempt to&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QSGZC_bTDKY:2hNpiysM5_4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QSGZC_bTDKY:2hNpiysM5_4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QSGZC_bTDKY:2hNpiysM5_4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=QSGZC_bTDKY:2hNpiysM5_4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QSGZC_bTDKY:2hNpiysM5_4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=QSGZC_bTDKY:2hNpiysM5_4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QSGZC_bTDKY:2hNpiysM5_4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QSGZC_bTDKY:2hNpiysM5_4:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QSGZC_bTDKY:2hNpiysM5_4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=QSGZC_bTDKY:2hNpiysM5_4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/QSGZC_bTDKY" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-21T21:03:44.598+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-RUp40iRt7j0/USZ6V8AAd3I/AAAAAAAAFgQ/v1s1aI6yc34/s72-c/NBC_Hacked_Compromised_Exploits_Malware_iFrame.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2013/02/dissecting-nbcs-exploits-and-malware.html</feedburner:origLink></item><item><title>Historical OSINT - Hacked Databases Offered for Sale</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/cDF2VhmWxo8/historical-osint-hacked-databases.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Tue, 05 Feb 2013 16:03:26 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-5676227792847835570</guid><description>In the wake of the recently announced security breaches at the NYTimes, WSJ, and the Washington Post, I decided to shed more light on what happens once a database gets compromised by Russian cybercriminals, compared to (supposedly) Chinese spies, with the idea to provide factual evidence that these breaches are just the tip of the iceberg. 

In this intelligence brief, I'll profile a service that&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDF2VhmWxo8:8qpnWi95O20:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDF2VhmWxo8:8qpnWi95O20:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDF2VhmWxo8:8qpnWi95O20:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=cDF2VhmWxo8:8qpnWi95O20:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDF2VhmWxo8:8qpnWi95O20:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=cDF2VhmWxo8:8qpnWi95O20:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDF2VhmWxo8:8qpnWi95O20:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDF2VhmWxo8:8qpnWi95O20:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDF2VhmWxo8:8qpnWi95O20:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=cDF2VhmWxo8:8qpnWi95O20:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/cDF2VhmWxo8" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-06T01:03:26.332+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-J0WvZII0PM0/URGQRti0XTI/AAAAAAAAFfg/5VN0QqJ_Xto/s72-c/Hacked_Databases_for_Sale_GiveMe_DB_2009_Cybercrime.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2013/02/historical-osint-hacked-databases.html</feedburner:origLink></item><item><title>Summarizing Webroot's Threat Blog Posts for January</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/Lm52RYHWizo/summarizing-webroots-threat-blog-posts.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Mon, 04 Feb 2013 13:14:30 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-399951220713545931</guid><description>The following is a brief summary of all of my posts at Webroot's Threat Blog for January, 2013. You can subscribe to Webroot's Threat Blog RSS Feed, or follow me on Twitter:




01. Spamvertised ‘Your Recent eBill from Verizon Wireless’ themed emails serve client-side exploits and malware02. Fake BBB (Better Business Bureau) Notifications lead to Black Hole Exploit Kit03. ‘Attention! Changes&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Lm52RYHWizo:0YCdF88IJio:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Lm52RYHWizo:0YCdF88IJio:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Lm52RYHWizo:0YCdF88IJio:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=Lm52RYHWizo:0YCdF88IJio:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Lm52RYHWizo:0YCdF88IJio:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=Lm52RYHWizo:0YCdF88IJio:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Lm52RYHWizo:0YCdF88IJio:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Lm52RYHWizo:0YCdF88IJio:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Lm52RYHWizo:0YCdF88IJio:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=Lm52RYHWizo:0YCdF88IJio:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/Lm52RYHWizo" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-04T22:14:30.544+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-tFBhpVeVRqo/URAeICOmOwI/AAAAAAAAFfI/jMEMeB6BBUs/s72-c/Webroot_Threat_Blog_January_2013.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2013/02/summarizing-webroots-threat-blog-posts.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for January</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/IjAbKiGJDIk/summarizing-zdnets-zero-day-posts-for.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Mon, 04 Feb 2013 12:45:01 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-6617359354195520655</guid><description>The following is a brief summary of all of my posts at ZDNet's Zero Day for January, 2013. You can subscribe to Zero Day's main feed, or follow me on Twitter:




01. Dutch security researchers dissect the Pobelka botnet02. ESPN's ScoreCenter for iOS sends passwords in clear-text, susceptible to XSS flaw03. Report: AutoRun malware infections continue topping the charts04. Comparative review:&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IjAbKiGJDIk:OvezEXhK3dw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IjAbKiGJDIk:OvezEXhK3dw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IjAbKiGJDIk:OvezEXhK3dw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=IjAbKiGJDIk:OvezEXhK3dw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IjAbKiGJDIk:OvezEXhK3dw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=IjAbKiGJDIk:OvezEXhK3dw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IjAbKiGJDIk:OvezEXhK3dw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IjAbKiGJDIk:OvezEXhK3dw:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=IjAbKiGJDIk:OvezEXhK3dw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=IjAbKiGJDIk:OvezEXhK3dw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/IjAbKiGJDIk" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-02-04T21:45:01.110+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-7lHW2mRQ9t8/URAbq8kc40I/AAAAAAAAFe4/GMXCcOjLbqA/s72-c/ZDNet_Zero_Day_Blog_January_2013.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2013/02/summarizing-zdnets-zero-day-posts-for.html</feedburner:origLink></item><item><title>Summarizing Webroot's Threat Blog Posts for December</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/hGGLHlbwOUs/summarizing-webroots-threat-blog-posts.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Wed, 09 Jan 2013 09:34:53 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-8065259610824965335</guid><description>The following is a brief summary of all of my posts at Webroot's Threat Blog for December, 2012. You can subscribe to Webroot's Threat Blog RSS Feed, or follow me on Twitter:




01. DIY malicious domain name registering service spotted in the wild
02. Fake ‘FedEx Tracking Number’ themed emails lead to malware
03. Bogus ‘Facebook Account Cancellation Request’ themed emails serve client-side&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGGLHlbwOUs:RfMoOM07C9A:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGGLHlbwOUs:RfMoOM07C9A:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGGLHlbwOUs:RfMoOM07C9A:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=hGGLHlbwOUs:RfMoOM07C9A:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGGLHlbwOUs:RfMoOM07C9A:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=hGGLHlbwOUs:RfMoOM07C9A:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGGLHlbwOUs:RfMoOM07C9A:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGGLHlbwOUs:RfMoOM07C9A:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGGLHlbwOUs:RfMoOM07C9A:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=hGGLHlbwOUs:RfMoOM07C9A:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/hGGLHlbwOUs" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-09T18:34:53.773+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-LxCarvsESA4/UO2nZ4sdXXI/AAAAAAAAFdc/2w2reZgZHPA/s72-c/Webroot_Threat_Blog_Security_December_2012.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2013/01/summarizing-webroots-threat-blog-posts.html</feedburner:origLink></item><item><title>Raw Historical OSINT - Keeping Money Mule Recruiters on a Short Leash - Part Twelve</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/p39qnUpv0f0/raw-historical-osint-keeping-money-mule.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Mon, 07 Jan 2013 12:56:40 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-3925457744360919868</guid><description>In the following (historical) intelligence brief, I'll provide you with some raw domain data of fake companies that are known to have attempted to recruit money mules over the past 2 years.

The domains listed here were registered by the same gang of cybercriminals that I've been extensively profiling in previous "Keeping Money Mule Recruiters on a Short Leash" posts.

Money mule recruitment&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=p39qnUpv0f0:35jZqVkAh3I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=p39qnUpv0f0:35jZqVkAh3I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=p39qnUpv0f0:35jZqVkAh3I:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=p39qnUpv0f0:35jZqVkAh3I:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=p39qnUpv0f0:35jZqVkAh3I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=p39qnUpv0f0:35jZqVkAh3I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=p39qnUpv0f0:35jZqVkAh3I:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=p39qnUpv0f0:35jZqVkAh3I:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=p39qnUpv0f0:35jZqVkAh3I:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=p39qnUpv0f0:35jZqVkAh3I:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/p39qnUpv0f0" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-07T21:56:40.049+01:00</app:edited><feedburner:origLink>http://ddanchev.blogspot.com/2013/01/raw-historical-osint-keeping-money-mule.html</feedburner:origLink></item><item><title>Historical OSINT - Profiling an OPSEC-Unaware Vendor of GSM/USB ATM Skimmers and Pinpads</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/pohIA-Ceo-M/historical-osint-profiling-opsec.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Sat, 05 Jan 2013 11:25:48 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-5329370141619711909</guid><description>On daily basis, I profile over a dozen of newly advertised (verified) vendors of ATM skimmers, indicating that this market segment is still quite successful, thanks to the overall demand for these 'tools-of-the-trade', allowing potential cybercriminals to enter the world of ATM skimming.

In this post part of the "Historical OSINT" series, I'll profile the underground market proposition of a&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=pohIA-Ceo-M:gG06rAsB_ok:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=pohIA-Ceo-M:gG06rAsB_ok:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=pohIA-Ceo-M:gG06rAsB_ok:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=pohIA-Ceo-M:gG06rAsB_ok:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=pohIA-Ceo-M:gG06rAsB_ok:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=pohIA-Ceo-M:gG06rAsB_ok:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=pohIA-Ceo-M:gG06rAsB_ok:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=pohIA-Ceo-M:gG06rAsB_ok:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=pohIA-Ceo-M:gG06rAsB_ok:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=pohIA-Ceo-M:gG06rAsB_ok:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/pohIA-Ceo-M" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2013-01-05T20:25:48.725+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-C4uCqkxz6U0/UOg1NFTVK1I/AAAAAAAAFa8/Mpv-bCbPiTc/s72-c/ATM_Skimmer_Pinpad_USB_GSM_Sale_Vendor_2008.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2013/01/historical-osint-profiling-opsec.html</feedburner:origLink></item><item><title>Dancho Danchev's Blog Most Popular Posts for 2012</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/JFXwjtkn2R4/dancho-danchevs-blog-most-popular-posts.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Thu, 27 Dec 2012 14:26:11 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-6635178918406657798</guid><description>The time has come to reflect on this year's most popular posts, and emphasize on the key points about what made them special.

Who's Behind the Koobface Botnet? - An OSINT Analysis - Indisputably, the exposing of Koobface botnet master KrotReal is this year's most popular blog post. The release of the post, and the New York Times article discussing the case, immediately resulted in the shut down&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JFXwjtkn2R4:xUtJI8wA-uw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JFXwjtkn2R4:xUtJI8wA-uw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JFXwjtkn2R4:xUtJI8wA-uw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=JFXwjtkn2R4:xUtJI8wA-uw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JFXwjtkn2R4:xUtJI8wA-uw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=JFXwjtkn2R4:xUtJI8wA-uw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JFXwjtkn2R4:xUtJI8wA-uw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JFXwjtkn2R4:xUtJI8wA-uw:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JFXwjtkn2R4:xUtJI8wA-uw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=JFXwjtkn2R4:xUtJI8wA-uw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/JFXwjtkn2R4" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-27T23:26:11.005+01:00</app:edited><feedburner:origLink>http://ddanchev.blogspot.com/2012/12/dancho-danchevs-blog-most-popular-posts.html</feedburner:origLink></item><item><title>Upcoming Portfolio of Commercially Available CYBERINT Reports</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/eipHHrQ4LW8/upcoming-portfolio-of-commercially.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Thu, 13 Dec 2012 03:41:09 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-3435175206002579942</guid><description>Valued blog readers,

Over the years, you've been exposed to insightful, in-depth, "God Eye's View" of some of the most prolific, targeted, and trending cyber attacks/cybercriminal schemes, that shaped the way we fight and anticipate cybercrime campaigns throughout the years.

Although the production of such publicly available and socially oriented content at this blog will continue, it's time&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eipHHrQ4LW8:SLZX08PZ4v8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eipHHrQ4LW8:SLZX08PZ4v8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eipHHrQ4LW8:SLZX08PZ4v8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=eipHHrQ4LW8:SLZX08PZ4v8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eipHHrQ4LW8:SLZX08PZ4v8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=eipHHrQ4LW8:SLZX08PZ4v8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eipHHrQ4LW8:SLZX08PZ4v8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eipHHrQ4LW8:SLZX08PZ4v8:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eipHHrQ4LW8:SLZX08PZ4v8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=eipHHrQ4LW8:SLZX08PZ4v8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/eipHHrQ4LW8" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-12-13T12:41:09.009+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-afhxnl3vvE4/UMm854LxKBI/AAAAAAAAFak/jSxiru011gg/s72-c/ddanchev_CYBERINT.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2012/12/upcoming-portfolio-of-commercially.html</feedburner:origLink></item><item><title>Summarizing Webroot's Threat Blog Posts for November</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/JYkTQLYtIdQ/summarizing-webroots-threat-blog-posts_30.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Fri, 30 Nov 2012 14:31:19 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-5586339463036163285</guid><description>The following is a brief summary of all of my posts at Webroot's Threat Blog for November, 2012. You can subscribe to my Webroot's Threat Blog RSS Feed or follow me on Twitter:




01. BofA ‘Online Banking Passcode Reset’ themed emails serve client-side exploits and malware
02. ‘ADP Immediate Notification’ themed emails lead to Black Hole Exploit Kit
03. USPS ‘Postal Notification’ themed&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JYkTQLYtIdQ:ncD0DZPbRuI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JYkTQLYtIdQ:ncD0DZPbRuI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JYkTQLYtIdQ:ncD0DZPbRuI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=JYkTQLYtIdQ:ncD0DZPbRuI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JYkTQLYtIdQ:ncD0DZPbRuI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=JYkTQLYtIdQ:ncD0DZPbRuI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JYkTQLYtIdQ:ncD0DZPbRuI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JYkTQLYtIdQ:ncD0DZPbRuI:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=JYkTQLYtIdQ:ncD0DZPbRuI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=JYkTQLYtIdQ:ncD0DZPbRuI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/JYkTQLYtIdQ" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-30T23:31:19.891+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-bOOj5hrjk0c/ULhUmtaIk4I/AAAAAAAAFaI/bFd_jnQcDr4/s72-c/Webroot_Threat_Blog_Security_November_2012.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2012/11/summarizing-webroots-threat-blog-posts_30.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for November</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/QMXDgWMhnOc/summarizing-zdnets-zero-day-posts-for_30.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Fri, 30 Nov 2012 05:55:18 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-9198794692310679214</guid><description>The following is a brief summary of all of my posts at ZDNet's Zero Day for November, 2012. You can subscribe to Zero Day's main feed, or follow me on Twitter:




01. Opera for Mac OS X patches six security vulnerabilities
02. Cybercriminals start spamvertising Xmas themed scams and malware campaigns
03. Apple releases QuickTime 7.7.3 for Windows, patches critical security vulnerabilities
04.&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QMXDgWMhnOc:nMEqf01Wk8o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QMXDgWMhnOc:nMEqf01Wk8o:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QMXDgWMhnOc:nMEqf01Wk8o:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=QMXDgWMhnOc:nMEqf01Wk8o:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QMXDgWMhnOc:nMEqf01Wk8o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=QMXDgWMhnOc:nMEqf01Wk8o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QMXDgWMhnOc:nMEqf01Wk8o:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QMXDgWMhnOc:nMEqf01Wk8o:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QMXDgWMhnOc:nMEqf01Wk8o:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=QMXDgWMhnOc:nMEqf01Wk8o:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/QMXDgWMhnOc" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-30T14:55:18.794+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-hU-1o0r7k7E/ULhTycXkIjI/AAAAAAAAFaA/bJiX6gKSSzA/s72-c/ZDNet_Zero_Day_Blog_Security_November_2012.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2012/11/summarizing-zdnets-zero-day-posts-for_30.html</feedburner:origLink></item><item><title>Koobface Botnet Master KrotReal Back in Business, Distributes Ransomware And Promotes BHSEO Service/Product</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/jesEGUQfURw/koobface-botnet-master-krotreal-back-in.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Sun, 25 Nov 2012 18:16:59 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-6172388899126147397</guid><description>On January 09, 2012 I exposed Koobface botnet master KrotReal. On January 16, 2012, The New York Times went public with data from Facebook Inc. exposing the identities of the rest of the group. What happened? With the botnet masters still at large, and the Koobface botnet currently offline, a logical question emerges - what are these cybercriminals up to now that they're no longer involved in&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=jesEGUQfURw:NOi24LcvWgU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=jesEGUQfURw:NOi24LcvWgU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=jesEGUQfURw:NOi24LcvWgU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=jesEGUQfURw:NOi24LcvWgU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=jesEGUQfURw:NOi24LcvWgU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=jesEGUQfURw:NOi24LcvWgU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=jesEGUQfURw:NOi24LcvWgU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=jesEGUQfURw:NOi24LcvWgU:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=jesEGUQfURw:NOi24LcvWgU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=jesEGUQfURw:NOi24LcvWgU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/jesEGUQfURw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-26T03:16:59.988+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-ZaJaVOsstZw/ULKzTZHNtqI/AAAAAAAAFY0/4E5Q0R1wyIQ/s72-c/Ransomware_KrotReal_Black_Hat_SEO_Service_English.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2012/11/koobface-botnet-master-krotreal-back-in.html</feedburner:origLink></item><item><title>Summarizing Webroot's Threat Blog Posts for October</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/eK56qLu4F80/summarizing-webroots-threat-blog-posts.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Thu, 01 Nov 2012 17:34:36 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-1232261878250035615</guid><description>The following is a brief summary of all of my posts at Webroot's Threat Blog for October, 2012. You can subscribe to my Webroot's Threat Blog RSS Feed or follow me on Twitter:



  
01. Russian cybercriminals release new DIY SMS flooder
02. Upcoming Webroot presentation on Cyber Jihad and Cyberterrorism at RSA Europe 2012
03. Recently launched E-shop sells access to hundreds of hacked PayPal&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eK56qLu4F80:kXzfRwWAjw4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eK56qLu4F80:kXzfRwWAjw4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eK56qLu4F80:kXzfRwWAjw4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=eK56qLu4F80:kXzfRwWAjw4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eK56qLu4F80:kXzfRwWAjw4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=eK56qLu4F80:kXzfRwWAjw4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eK56qLu4F80:kXzfRwWAjw4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eK56qLu4F80:kXzfRwWAjw4:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=eK56qLu4F80:kXzfRwWAjw4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=eK56qLu4F80:kXzfRwWAjw4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/eK56qLu4F80" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-02T01:34:36.813+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-P892yKs5tFw/UJMGSeMzsJI/AAAAAAAAFYg/HCjsUHOhs30/s72-c/Webroot_Threat_Blog_October_2012.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2012/11/summarizing-webroots-threat-blog-posts.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for October</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/Qb-CCt-T2yQ/summarizing-zdnets-zero-day-posts-for.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Thu, 01 Nov 2012 16:47:05 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-2859138693865967034</guid><description>The following is a brief summary of all of my posts at ZDNet's Zero Day for October, 2012. You can subscribe to Zero Day's main feed, or follow me on Twitter:




01. Report: Large US bank hit by 20 different crimeware families
02. Localized Dorkbot malware variant spreading across Skype
03. Sopelka botnet drops Citadel, Feodo, and Tatanga crimeware variants
04. Adobe patches 6 critical&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Qb-CCt-T2yQ:udDaH9f_TOg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Qb-CCt-T2yQ:udDaH9f_TOg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Qb-CCt-T2yQ:udDaH9f_TOg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=Qb-CCt-T2yQ:udDaH9f_TOg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Qb-CCt-T2yQ:udDaH9f_TOg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=Qb-CCt-T2yQ:udDaH9f_TOg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Qb-CCt-T2yQ:udDaH9f_TOg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Qb-CCt-T2yQ:udDaH9f_TOg:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=Qb-CCt-T2yQ:udDaH9f_TOg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=Qb-CCt-T2yQ:udDaH9f_TOg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/Qb-CCt-T2yQ" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-02T00:47:05.447+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-eXP4IxsCtFA/UJMFVvkWFSI/AAAAAAAAFYQ/nHfUl4kS74k/s72-c/ZDNet_Zero_Day_Blog_October_2012.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2012/11/summarizing-zdnets-zero-day-posts-for.html</feedburner:origLink></item><item><title>Dissecting 'Operation Ababil' - an OSINT Analysis - Part Two</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/K3iGkxWRspw/dissecting-operation-ababil-osint.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Fri, 26 Oct 2012 06:36:47 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-2249472670030808576</guid><description>With more crowdsourced intelligence on "Operation Ababil" published in the recent weeks, it's time to revisit the campaign's core strategy for harnessing enough bandwidth to successfully take down major U.S financial institutions.

As you can remember, in Part One of the OSINT analysis for "Operation Ababil" I emphasized on the crowdsourcing campaign launched by Izz ad-Din al-Qassam a.k.a Qassam&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=K3iGkxWRspw:mM87bW1rGYY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=K3iGkxWRspw:mM87bW1rGYY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=K3iGkxWRspw:mM87bW1rGYY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=K3iGkxWRspw:mM87bW1rGYY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=K3iGkxWRspw:mM87bW1rGYY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=K3iGkxWRspw:mM87bW1rGYY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=K3iGkxWRspw:mM87bW1rGYY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=K3iGkxWRspw:mM87bW1rGYY:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=K3iGkxWRspw:mM87bW1rGYY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=K3iGkxWRspw:mM87bW1rGYY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/K3iGkxWRspw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-10-26T15:36:47.718+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-yykmF165mcU/UInlAVhxJ5I/AAAAAAAAFXQ/RQYt3vu7Q74/s72-c/itsoknoproblembro_DDoS_Script.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2012/10/dissecting-operation-ababil-osint.html</feedburner:origLink></item><item><title>Summarizing Webroot's Threat Blog Posts for September</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/fGBM75oGZxU/summarizing-webroots-threat-blog-posts.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Mon, 01 Oct 2012 05:18:15 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-6200392158236089878</guid><description>The following is a brief summary of all of my posts at Webroot's Threat Blog for September, 2012. You can subscribe to my Webroot's Threat Blog RSS Feed or follow me on Twitter:




01. Spamvertised ‘Wire Transfer Confirmation’ themed emails lead to Black Hole exploit kit
02. Intuit themed ‘QuickBooks Update: Urgent’ emails lead to Black Hole exploit kit
03. Cybercriminals resume spamvertising&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fGBM75oGZxU:5XiY87hkeGs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fGBM75oGZxU:5XiY87hkeGs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fGBM75oGZxU:5XiY87hkeGs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=fGBM75oGZxU:5XiY87hkeGs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fGBM75oGZxU:5XiY87hkeGs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=fGBM75oGZxU:5XiY87hkeGs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fGBM75oGZxU:5XiY87hkeGs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fGBM75oGZxU:5XiY87hkeGs:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fGBM75oGZxU:5XiY87hkeGs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=fGBM75oGZxU:5XiY87hkeGs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/fGBM75oGZxU" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-10-01T14:18:15.230+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-bMMWZE0Em-o/UGjRQorBLoI/AAAAAAAAFW0/AlzoerLh9ss/s72-c/Webroot_Threat_Blog_September_2012.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2012/10/summarizing-webroots-threat-blog-posts.html</feedburner:origLink></item><item><title>Summarizing Webroot's Threat Blog Posts for August</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/dwEGC48BXYw/summarizing-webroots-threat-blog-posts.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Thu, 27 Sep 2012 16:54:38 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-105129634551198824</guid><description>The following is a brief summary of all of my posts at Webroot's Threat Blog for August, 2012. You can subscribe to my Webroot's Threat Blog RSS Feed or follow me on Twitter:




01. Spamvertised AICPA themed emails lead to Black Hole exploit kit
02. Spamvertised ‘PayPal has sent you a bank transfer’ themed emails lead to Black Hole exploit kit
03. Ongoing spam campaign impersonates LinkedIn,&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=dwEGC48BXYw:r9j8xQAbAL8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=dwEGC48BXYw:r9j8xQAbAL8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=dwEGC48BXYw:r9j8xQAbAL8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=dwEGC48BXYw:r9j8xQAbAL8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=dwEGC48BXYw:r9j8xQAbAL8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=dwEGC48BXYw:r9j8xQAbAL8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=dwEGC48BXYw:r9j8xQAbAL8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=dwEGC48BXYw:r9j8xQAbAL8:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=dwEGC48BXYw:r9j8xQAbAL8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=dwEGC48BXYw:r9j8xQAbAL8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/dwEGC48BXYw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-09-28T01:54:38.540+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-Y0xtURplmRo/UGTmGrrjHhI/AAAAAAAAFWY/PFBByMKKiEo/s72-c/Webroot_Threat_Blog_August_2012.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2012/09/summarizing-webroots-threat-blog-posts.html</feedburner:origLink></item><item><title>Summarizing ZDNet's Zero Day Posts for August</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/5cA_WN9WBUI/summarizing-zdnets-zero-day-posts-for.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Thu, 27 Sep 2012 16:43:28 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-4959032876109902077</guid><description>The following is a brief summary of all of my posts at ZDNet's Zero Day for August, 2012. You can subscribe to Zero Day's main feed, or follow me on Twitter:



  
01. BlackBerry users targeted with malware-serving email campaign
02. Java zero day vulnerability actively used in targeted attacks
03. Loozfon Android malware targets Japanese female users
04. Researcher reports a CSRF&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5cA_WN9WBUI:LqVfh1W_sDE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5cA_WN9WBUI:LqVfh1W_sDE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5cA_WN9WBUI:LqVfh1W_sDE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=5cA_WN9WBUI:LqVfh1W_sDE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5cA_WN9WBUI:LqVfh1W_sDE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=5cA_WN9WBUI:LqVfh1W_sDE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5cA_WN9WBUI:LqVfh1W_sDE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5cA_WN9WBUI:LqVfh1W_sDE:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5cA_WN9WBUI:LqVfh1W_sDE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=5cA_WN9WBUI:LqVfh1W_sDE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/5cA_WN9WBUI" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-09-28T01:43:28.470+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-HU6c-EclagI/UGTjyLiywyI/AAAAAAAAFWI/lX_90S_AIbk/s72-c/ZDNet_Zero_Day_August_2012.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2012/09/summarizing-zdnets-zero-day-posts-for.html</feedburner:origLink></item><item><title>Dissecting 'Operation Ababil' - an OSINT Analysis</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/P0j3n6KP95U/dissecting-operation-ababil-osint.html</link><author>noreply@blogger.com (Dancho Danchev)</author><pubDate>Fri, 28 Sep 2012 06:35:09 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-444965256938115843</guid><description>Provoked by a questionable online video posted on YouTube, Muslims from the around the world united in an apparent opt-in botnet crowdsourcing campaign aiming to launch a DDoS (denial of service attack) against YouTube for keeping the video online, and against several major U.S banks and financial institutions.

Dubbed "Operation Ababil", and operated by the Izz ad-Din al-Qassam a.k.a Qassam&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=P0j3n6KP95U:LdqcdkSIGUg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=P0j3n6KP95U:LdqcdkSIGUg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=P0j3n6KP95U:LdqcdkSIGUg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=P0j3n6KP95U:LdqcdkSIGUg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=P0j3n6KP95U:LdqcdkSIGUg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=P0j3n6KP95U:LdqcdkSIGUg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=P0j3n6KP95U:LdqcdkSIGUg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=P0j3n6KP95U:LdqcdkSIGUg:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=P0j3n6KP95U:LdqcdkSIGUg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=P0j3n6KP95U:LdqcdkSIGUg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/P0j3n6KP95U" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2012-09-28T15:35:09.092+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-r3bbnz_FOoM/UGTGl0vkjgI/AAAAAAAAFUA/XdgM1APrl9w/s72-c/Iran_DDoS_YouTube_U.S_Banks_01.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2012/09/dissecting-operation-ababil-osint.html</feedburner:origLink></item></channel></rss>
