<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Dancho Danchev's Blog - Mind Streams of Information Security Knowledge</title><link>http://ddanchev.blogspot.com/</link><description>In the overwhelming sea of information, access to timely, insightful and independent open-source intelligence (OSINT) analyses is crucial for maintaining the necessary situational awareness to stay on the top of emerging security threats. This blog covers trends and fads, tactics and strategies, intersecting with third-party research, speculations and real-time CYBERINT assessments, all packed with sarcastic attitude</description><language>en</language><managingEditor>dancho.danchev@gmail.com (Dancho Danchev)</managingEditor><lastBuildDate>Thu, 05 Nov 2009 15:03:30 PST</lastBuildDate><generator>Blogger http://www.blogger.com</generator><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1010</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">25</openSearch:itemsPerPage><creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-nc-sa/3.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://ddanchev.blogspot.com/atom.xml" type="application/rss+xml" /><feedburner:browserFriendly>This is an XML content feed. It is intended to be viewed in a newsreader or syndicated to another site, subject to copyright and fair use.</feedburner:browserFriendly><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><title>Pricing Scheme for a DDoS Extortion Attack</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/do98vBzMa9o/pricing-scheme-for-ddos-extortion.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Tue, 03 Nov 2009 04:07:31 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-5818791098274923454</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Su9z-WLCTXI/AAAAAAAAET4/VC8UEIdsae8/s1600-h/bbc_botnet_on_demand.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Su9z-WLCTXI/AAAAAAAAET4/VC8UEIdsae8/s320/bbc_botnet_on_demand.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;With the average price for a DDoS attack on demand decreasing due to the evident over-supply of malware infected hosts, it should be fairly logical to assume that the "on demand DDoS" business model run by the cybercriminals performing such services is blossoming.&lt;br /&gt;
&lt;br /&gt;
Interestingly, what used to be a group that was exclusively specializing in DDoS attacks, is today's cybercrime enterprise "&lt;a href="http://en.wikipedia.org/wiki/Vertical_integration"&gt;vertically integrating&lt;/a&gt;" in order to occupy as many underground market segments as possible, all of which originally developed thanks to the "malicious economies of scale" (&lt;a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html"&gt;massive SQL injections&lt;/a&gt; through &lt;a href="http://ddanchev.blogspot.com/2009/04/massive-sql-injections-through-search.html"&gt;search engines' reconnaissance&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/07/social-engineering-driven-web-malware.html"&gt;standardizing the social engineering process&lt;/a&gt;, the &lt;a href="http://ddanchev.blogspot.com/2009/10/standardizing-money-mule-recruitment.html"&gt;money mule recruitment process&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2007/07/malware-embedded-sites-increasing.html"&gt;diversifying the standardized and well proven propagation/infection vectors&lt;/a&gt; etc.) offered by a botnet.&lt;br /&gt;
&lt;br /&gt;
What if their DDoS for hire business model is experiencing a decline? Would &lt;a href="http://ddanchev.blogspot.com/2008/06/price-discrimination-in-market-for.html"&gt;penetration pricing&lt;/a&gt; save them? What if they start enforcing a &lt;a href="http://en.wikipedia.org/wiki/Price_discrimination#Examples_of_price_discrimination"&gt;differentiated pricing&lt;/a&gt; model for their services through DDoS extortion?&lt;br /&gt;
&lt;br /&gt;
Let's discuss one of those groups that's been actively attempting to extort money from Russian web sites since the middle of this summer. From penalty fees, to 30% discount if they want to request DDoS for hire against their competitors, a discount only available if they've actually paid the 10,000 rubles monthly extortion fee at the first place - this gang is also including links to the web sites of Russian's Federal Security Service (FSB) and Russia's Ministry of the Interior stating "&lt;i&gt;in order to make it easy for the victims to contact law enforcement&lt;/i&gt;".&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Sample DDOS extortion letter:&lt;/b&gt;&lt;br /&gt;
"&lt;i&gt;Hello. If you want to continue having your site operational, you must pay us &lt;/i&gt;&lt;i&gt;10 000 rubles monthly.&lt;/i&gt;&lt;i&gt; Attention! Starting as of DATE your site will be a subject to a DDoS attack. Your site will remain unavailable until you pay us.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;The first attack will involve 2,000 bots. If you contact the companies involved in the protection of DDoS-attacks and they begin to block our bots, we will increase the number of bots to 50 000, and the protection of 50 000 bots is very, very expensive.&lt;br /&gt;
&lt;br /&gt;
1-st payment (10 000 rubles) Must be made no later than DATE. All subsequent payments (10 000 rubles) Must be committed no later than 31 (30) day of each month starting from August 31. Late payment penalties will be charged 100% for each day of delay.&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
For example, if you do not have time to make payment on the last day of the month, then 1 day of you will have to pay a fine 100%, for instance 20 000 rubles. If you pay only the 2 nd date of the month, it will be for 30 000 rubles etc. Please pay on time, and then the initial 10 000 rubles offer will not change. Penalty fees apply to your first payment - no later than DATE"&lt;br /&gt;
&lt;br /&gt;
You will also receive several bonuses.&lt;br /&gt;
1. 30% discount if you request DDoS attack on your competitors/enemies. Fair market value ddos attacks a simple site is about $ 100 per night, for you it will cost only 70 $ per day.&lt;br /&gt;
2. If we turn to your competitors / enemies, to make an attack on your site, then we deny them.&lt;br /&gt;
&lt;br /&gt;
Payment must be done on our purse Yandex-money number 41001474323733. Every month the number will be a new purse, be careful. About how to use Yandex-money read on www.money.yandex.ru. If you want to apply to law enforcement agencies, we will not discourage you. We even give you their contacts: www.fsb.ru, www.mvd.ru&lt;/i&gt;"&lt;br /&gt;
&lt;br /&gt;
It's also worth pointing out that a huge number of "boutique vendors" of DDoS services remain reluctant to initiate DDoS attacks against government or political parties, in an attempt to stay beneath the radar. This mentality prompted the inevitable development of "aggregate-and-forget" type of botnets exclusively aggregated for customer-tailored propositions who would inevitably get detected, shut down, but end up harder to trace back to the original source compared to a situation where they would be DDoS the requested high-profile target from the very same botnet that is closely monitored by the security community.&lt;br /&gt;
&lt;br /&gt;
The future of DDoS extortion attacks, however, looks a bit grey due the numerous monetization models that cybercriminals developed - for instance ransomware, which attempts to scale by extorting significant amounts of money from thousands of infected users in an automated and much more efficient way than the now old-fashioned DDoS extortion model.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2007/03/botnet-communication-platforms.html"&gt;Botnet Communication Platforms&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2007/09/custom-ddos-capabilities-within-malware.html"&gt;Custom DDoS Capabilities Within a Malware&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html"&gt;A New DDoS Malware Kit in the Wild&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html"&gt;Botnet on Demand Service&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html"&gt;The DDoS Attack Against CNN.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/04/botnet-masters-to-do-list.html"&gt;A Botnet Master's To-Do List&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/05/custom-ddos-attacks-within-popular.html"&gt;Custom DDoS Attacks Within Popular Malware Diversifying&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html"&gt;Using Market Forces to Disrupt Botnets&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html"&gt;Web Based Botnet Command and Control Kit 2.0&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/10/ddos-attack-graphs-from-russia-vs.html"&gt;DDoS Attack Graphs from Russia vs Georgia's Cyberattacks&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/11/ddos-attack-against-bobbearcouk.html"&gt;The DDoS Attack Against Bobbear.co.uk&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/03/russian-homosexual-sites-under.html"&gt;Russian Homosexual Sites Under (Commissioned) DDoS Attack&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-5818791098274923454?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=do98vBzMa9o:r8dC0EgRCFk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=do98vBzMa9o:r8dC0EgRCFk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=do98vBzMa9o:r8dC0EgRCFk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=do98vBzMa9o:r8dC0EgRCFk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=do98vBzMa9o:r8dC0EgRCFk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=do98vBzMa9o:r8dC0EgRCFk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=do98vBzMa9o:r8dC0EgRCFk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=do98vBzMa9o:r8dC0EgRCFk:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=do98vBzMa9o:r8dC0EgRCFk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=do98vBzMa9o:r8dC0EgRCFk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/do98vBzMa9o" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-03T13:07:31.269+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_wICHhTiQmrA/Su9z-WLCTXI/AAAAAAAAET4/VC8UEIdsae8/s72-c/bbc_botnet_on_demand.jpg" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/11/pricing-scheme-for-ddos-extortion.html</feedburner:origLink></item><item><title>Summarizing Zero Day's Posts for October</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/6CZ_a14G3zQ/summarizing-zero-days-posts-for-october.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Mon, 02 Nov 2009 13:31:23 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-1952661513261272553</guid><description>&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Su9ORtINUgI/AAAAAAAAETw/gbVG3iJRWOU/s1600-h/ZDNet_ZeroDay_October_2009.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Su9ORtINUgI/AAAAAAAAETw/gbVG3iJRWOU/s200/ZDNet_ZeroDay_October_2009.png" /&gt;&lt;/a&gt;The following is a brief summary of all of my posts at ZDNet's &lt;a href="http://blogs.zdnet.com/security"&gt;Zero Day&lt;/a&gt; for October.&lt;br /&gt;
&lt;br /&gt;
You can also go through &lt;a href="http://ddanchev.blogspot.com/2009/10/summarizing-zero-days-posts-for.html"&gt;previous summaries&lt;/a&gt;, as well as subscribe to my &lt;a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;amp;s=0&amp;amp;o=1&amp;amp;mode=rss"&gt;personal RSS feed&lt;/a&gt; or &lt;a href="http://feeds.feedburner.com/zdnet/security"&gt;Zero Day's main feed&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
Notable articles include: &lt;a href="http://blogs.zdnet.com/security/?p=4605"&gt;Does software piracy lead to higher malware infection rates?&lt;/a&gt; and &lt;a href="http://blogs.zdnet.com/security/?p=4748"&gt;New LoroBot ransomware encrypts files, demands $100 for decryption&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;01.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4512"&gt;MS Security Essentials test shows 98% detection rate for 545k malware samples&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;02.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4538"&gt;Weak passwords dominate statistics for Hotmail's phishing scheme leak&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;03.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4549"&gt;Click fraud facilitating Bahama botnet steals ad revenue from Google&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;04.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4594"&gt;New Koobface campaign spoofs Adobe's Flash updater&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;05.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4605"&gt;Does software piracy lead to higher malware infection rates?&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;06.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4653"&gt;Commonwealth fined $100k for not mandating antivirus software&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;07.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4662"&gt;'Evil Maid' USB stick attack keylogs TrueCrypt passphrases&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;08.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4674"&gt;Fake 'Conflicker.B Infection Alert' spam campaign drops scareware&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;09.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4729"&gt;Gawker Media tricked into featuring malicious Suzuki ads&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;10.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4748"&gt;New LoroBot ransomware encrypts files, demands $100 for decryption&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;11.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4782"&gt;Spooky Halloween - scareware or crimeware?&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;12.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4791"&gt;Phishing experiment sneaks through all anti-spam filters&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-1952661513261272553?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=6CZ_a14G3zQ:HC31UxeAOoU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=6CZ_a14G3zQ:HC31UxeAOoU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=6CZ_a14G3zQ:HC31UxeAOoU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=6CZ_a14G3zQ:HC31UxeAOoU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=6CZ_a14G3zQ:HC31UxeAOoU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=6CZ_a14G3zQ:HC31UxeAOoU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=6CZ_a14G3zQ:HC31UxeAOoU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=6CZ_a14G3zQ:HC31UxeAOoU:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=6CZ_a14G3zQ:HC31UxeAOoU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=6CZ_a14G3zQ:HC31UxeAOoU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/6CZ_a14G3zQ" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-02T22:31:23.224+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_wICHhTiQmrA/Su9ORtINUgI/AAAAAAAAETw/gbVG3iJRWOU/s72-c/ZDNet_ZeroDay_October_2009.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/11/summarizing-zero-days-posts-for-october.html</feedburner:origLink></item><item><title>Ongoing FDIC Spam Campaign Serves Zeus Crimeware</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/3vJauflJy_U/ongoing-fdic-spam-campaign-serves-zeus.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Wed, 28 Oct 2009 12:20:28 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-8543126532939026219</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SuiRneYoD1I/AAAAAAAAETQ/jWsiL0DFndg/s1600-h/facebook_new_login_system_spam_fastflux_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SuiRneYoD1I/AAAAAAAAETQ/jWsiL0DFndg/s200/facebook_new_login_system_spam_fastflux_2.JPG" /&gt;&lt;/a&gt;&lt;b&gt;UPDATED -&lt;/b&gt; &lt;b&gt;Wednesday, October 28, 2009&lt;/b&gt;: A "New Facebook Login System" spam campaign is in circulation, launched by the same botnet. Sampled &lt;a href="http://www.virustotal.com/analisis/2a01152f68fd07fd3c3623c1d640b14384da836bf47fbef5b61ddd14c946bb7e-1256739274"&gt;updatetool.exe&lt;/a&gt; once again interacts with the Zeus command and control at &lt;b&gt;&lt;a href="https://zeustracker.abuse.ch/monitor.php?host=193.104.27.42"&gt;193.104.27.42&lt;/a&gt;.&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Message sample 01:&lt;/b&gt; "&lt;i&gt;In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security. Before you are able to use the new login system, you will be required to update your account. A new Facebook Update Tool has been released for your account. Please download and install the tool using the link below.&lt;/i&gt;"&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Message sample 02:&lt;/b&gt; "&lt;i&gt;Dear Facebook user, In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security. Before you are able to use the new login system, you will be required to update your account. Click here to update your account online now. If you have any questions, reference our New User Guide. Thanks, The Facebook Team&lt;/i&gt;"&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SuiXBjzhKeI/AAAAAAAAETg/FG2QqrGv0Ko/s1600-h/facebook_new_login_system_spam_fastflux_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SuiXBjzhKeI/AAAAAAAAETg/FG2QqrGv0Ko/s200/facebook_new_login_system_spam_fastflux_3.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;Participating fast-fluxed domains include:&lt;br /&gt;
&lt;b&gt;easder1e.co .uk&lt;br /&gt;
easder1g.co .uk&lt;br /&gt;
easder1l.co .uk&lt;br /&gt;
easder1m.co .uk&lt;br /&gt;
easder1q.co .uk&lt;br /&gt;
nytre4rt.co .uk&lt;br /&gt;
nytre4ru.co .uk&lt;br /&gt;
nyuy12qwa.co .uk&lt;br /&gt;
nyuy12qwf.co .uk&lt;br /&gt;
nyuy12qwg.co .uk&lt;br /&gt;
nyuy12qws.co .uk&lt;br /&gt;
nyuy12qwz.co .uk&lt;br /&gt;
ololii.co .uk&lt;br /&gt;
ololiw.co .uk&lt;br /&gt;
ololiy.co .uk&lt;br /&gt;
ololiz.co .uk&lt;br /&gt;
tygerah.co .uk&lt;br /&gt;
tygerak.co .uk&lt;br /&gt;
tygeraw.co .uk&lt;br /&gt;
tygeraz.co .uk&lt;br /&gt;
yh1qak.co .uk&lt;br /&gt;
yh1qal.co .uk&lt;br /&gt;
yh1qao.co .uk&lt;br /&gt;
yhaqwe1a.co .uk&lt;br /&gt;
yhaqwe1q.co .uk&lt;br /&gt;
yhaqwe1r.co .uk&lt;br /&gt;
yhaqwi1g.co .uk&lt;br /&gt;
yhaqwi1h.co .uk&lt;br /&gt;
yhaqwi1l.co .uk&lt;br /&gt;
yhaqwi1m.co .uk&lt;br /&gt;
yhaqwi1p.co .uk&lt;br /&gt;
yhhherasde.co .uk&lt;br /&gt;
yhhherasdp.co .uk&lt;br /&gt;
yhhheraski.co .uk&lt;br /&gt;
yhhheraskog.co .uk&lt;br /&gt;
yhhheraskol.co .uk&lt;br /&gt;
yhhheraskoy.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SuiXNp_rJHI/AAAAAAAAETo/UHsapHi_8Gc/s1600-h/facebook_new_login_system_spam_fastflux_4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SuiXNp_rJHI/AAAAAAAAETo/UHsapHi_8Gc/s200/facebook_new_login_system_spam_fastflux_4.png" /&gt;&lt;/a&gt;&lt;b&gt;n111sae .eu&lt;br /&gt;
n111sak .eu&lt;br /&gt;
n111sap .eu&lt;br /&gt;
n111saq .eu&lt;br /&gt;
n111say .eu&lt;br /&gt;
n111saz .eu&lt;br /&gt;
nyuh1awa .eu&lt;br /&gt;
nyuh1awb .eu&lt;br /&gt;
nyuh1awc .eu&lt;br /&gt;
nyuh1awd .eu&lt;br /&gt;
nyuh1awe .eu&lt;br /&gt;
nyuh1awf .eu&lt;br /&gt;
nyuh1awg .eu&lt;br /&gt;
nyuh1awh .eu&lt;br /&gt;
nyuh1awm .eu&lt;br /&gt;
nyuh1awn .eu&lt;br /&gt;
nyuh1aws .eu&lt;br /&gt;
nyuh1awt .eu&lt;br /&gt;
nyuh1awv .eu&lt;br /&gt;
nyuh1awx .eu&lt;br /&gt;
nyuh1awz .eu&lt;br /&gt;
nyuy12qwf .eu&lt;br /&gt;
nyuy12qwg .eu&lt;br /&gt;
nyuy12qws .eu&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SuiRwMGbzdI/AAAAAAAAETY/eFoHCwFIkL4/s1600-h/facebook_new_login_system_spam_fastflux_1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SuiRwMGbzdI/AAAAAAAAETY/eFoHCwFIkL4/s200/facebook_new_login_system_spam_fastflux_1.png" width="196" /&gt;&lt;/a&gt;&lt;b&gt;nyuy12qws .eu&lt;br /&gt;
ololii .eu&lt;br /&gt;
ololiw .eu&lt;br /&gt;
ololiy .eu&lt;br /&gt;
ololiz .eu&lt;br /&gt;
rrref1aaz .eu&lt;br /&gt;
rrref1akz .eu&lt;br /&gt;
rrref1okz .eu&lt;br /&gt;
rrref1ykz.eu&lt;br /&gt;
rrrefjokz .eu&lt;br /&gt;
saaasak .eu&lt;br /&gt;
saaasav .eu&lt;br /&gt;
tygerah .eu&lt;br /&gt;
tygerak .eu&lt;br /&gt;
tygeraw .eu&lt;br /&gt;
ujihkei .eu&lt;br /&gt;
ujihkni .eu&lt;br /&gt;
ujihkoi .eu&lt;br /&gt;
ujihkui .eu&lt;br /&gt;
yh1qao .eu&lt;br /&gt;
yh1qaz .eu&lt;br /&gt;
yy1azsva .eu&lt;br /&gt;
yy1azsvq .eu&lt;br /&gt;
yy1azsvz .eu&lt;br /&gt;
yyy1asvf .eu&lt;br /&gt;
yyy1azsy .eu&lt;br /&gt;
yyy1azvg .eu&lt;br /&gt;
yyy1zsve .eu&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
New DNS servers of notice:&lt;br /&gt;
&lt;b&gt;ns1.a-recruitmnt .com&lt;br /&gt;
ns1.applesilver .com&lt;br /&gt;
ns1.cheryks .com&lt;br /&gt;
ns1.barbaos .net&lt;br /&gt;
ns1.laktocountry .net&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
An ongoing &lt;a href="http://garwarner.blogspot.com/2009/10/fake-fdic-spam-campaign-spreads-zeus.html"&gt;spam campaign impersonating The Federal Deposit Insurance Corporation&lt;/a&gt;, is attempting to drop zeus samples by enticing users into installing &lt;a href="http://www.virustotal.com/analisis/9c81ead54aeeba88f11c74444c63873f76d6882b265095a94ebdee5c3e7a64a5-1256679122"&gt;pdf.exe&lt;/a&gt; and &lt;a href="http://www.virustotal.com/analisis/02cee27d4fcf8e888329b0d95c923853472cb6acab40e7b076a0c8e6f13eed44-1256678537"&gt;word.exe&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
"&lt;i&gt;&lt;b&gt;Subject:&lt;/b&gt; FDIC has officially named your bank a failed bank&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;&lt;b&gt;Body:&lt;/b&gt; You have received this message because you are a holder of a FDIC-insured bank account. Recently FDIC has officially named the bank you have opened your account with as a failed bank, thus, taking control of its assets. You need to visit the official FDIC website and perform the following steps to check your Deposit Insurance Coverage.&lt;/i&gt;"&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SueM-axHlII/AAAAAAAAES4/-2Q__FWsU5w/s1600-h/FDIC_spam_crimeware.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SueM-axHlII/AAAAAAAAES4/-2Q__FWsU5w/s200/FDIC_spam_crimeware.png" /&gt;&lt;/a&gt;Sampled malware obtains a Zeus crimeware from a known command and control location (&lt;b&gt;193.104.27.42&lt;/b&gt;), already &lt;a href="https://zeustracker.abuse.ch/monitor.php?host=193.104.27.42"&gt;blacklisted by the Zeus Tracker&lt;/a&gt;. The campaign is related to the periodical "Microsoft Outlook Update" campaigns, since both campaigns have been &lt;a href="http://hphosts.blogspot.com/2009/10/warning-update-for-microsoft-outlook.html"&gt;sharing fast-flux infrastructure under the same infected hosts&lt;/a&gt;, using identical domains.&lt;br /&gt;
&lt;br /&gt;
Fast-fluxed domains participating in the FDIC spam campaign:&lt;br /&gt;
&lt;b&gt;bbttyak.co .uk&lt;br /&gt;
bbttyak.org .uk&lt;br /&gt;
bbttyam.co .uk&lt;br /&gt;
bbttyam.me .uk&lt;br /&gt;
bbttyap.co .uk&lt;br /&gt;
bbttyap.me .uk&lt;br /&gt;
bbttyaz.co .uk&lt;br /&gt;
bbttyaz.me .uk&lt;br /&gt;
gerrahawa .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; gerrahowa .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; gerrakawa .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; gerrakowa .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; gerralowa .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; gerraoowa .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; gerraoowa .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; gerrasasa .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; gerrasase .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; gerrasasq .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; h1erfae .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; h1erfai .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; h1erfaj .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; h1erfaq .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; h1erfar .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; h1erfat .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; h1erfau .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; h1erfaw.eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; h1erfay .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; heiiikok .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; heiiikoy .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; heiiikul .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; heiiikum .eu&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SueTQl1hraI/AAAAAAAAETA/ir4MiTGikG4/s1600-h/FDIC_spam_crimeware_2_fast_flux.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SueTQl1hraI/AAAAAAAAETA/ir4MiTGikG4/s200/FDIC_spam_crimeware_2_fast_flux.png" /&gt;&lt;/a&gt;&lt;b&gt;heiiikuv .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; heiiikuy .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; idllsit .com&lt;br /&gt;
ij1tli .net&lt;br /&gt;
immikiut1 .cz&lt;br /&gt;
j1t1iil .com&lt;br /&gt;
j1t1iil .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; j1t1iil .net&lt;br /&gt;
lj1tli .com&lt;br /&gt;
lj1tli .net&lt;br /&gt;
lj1tll .com&lt;br /&gt;
lj1tll .net&lt;br /&gt;
ltlil1 .com&lt;br /&gt;
ltlil1 .net&lt;br /&gt;
modesftp .eu &lt;/b&gt;&lt;br /&gt;
&lt;b&gt; nniuji1 .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; nniujih .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; nniujo1 .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; nniukif .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; nniukih .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; nniukik .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; nniukiw .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; nniukiz .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; nniuxih .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; nniuxiw .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; pouikib .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; pouikic .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; pouikie .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; pouikif .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; pouikig .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; pouikir .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; pouikis .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; pouikit .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; pouikiv .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; pouikiw .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; pouikix .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; pouikiy .eu&lt;/b&gt;&lt;br /&gt;
&lt;b&gt; t1fliil .tc&lt;br /&gt;
tj1fiil.co .nz&lt;br /&gt;
tj1fiil .com&lt;br /&gt;
tj1fiil .net&lt;br /&gt;
tj1fiil .tc&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SueTd8cl0xI/AAAAAAAAETI/WCncKGaDTKc/s1600-h/FDIC_spam_crimeware_1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SueTd8cl0xI/AAAAAAAAETI/WCncKGaDTKc/s200/FDIC_spam_crimeware_1.png" /&gt;&lt;/a&gt;DNS servers of notice:&lt;br /&gt;
&lt;b&gt;ns1.doctor-tomb .com&lt;br /&gt;
ns1.sortyn .com&lt;br /&gt;
ns1.asthomes .com&lt;br /&gt;
ns1.sunriseliny .com&lt;br /&gt;
ns1.racing-space .net&lt;br /&gt;
ns1.cerezit .net&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The phoneback location 193.104.27.42 at AS12604 maintained by Kamushnoy Vladimir Vasulyovich (info@ctgm.info; vla.kam@ctgm.info with ctgm.info responding to 91.213.72.1) is the second Zeus command and control IP within the netblock, &lt;a href="https://zeustracker.abuse.ch/monitor.php?host=193.104.27.90"&gt;followed by 193.104.27.90&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=3648"&gt;Fake Microsoft patches themed malware campaigns spreading&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=3916"&gt;Fake Microsoft patch malware campaign makes a comeback &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/multitasking-fast-flux-botnet-that.html"&gt;The Multitasking Fast-Flux Botnet that Wants to Bank With You &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html"&gt;Money Mule Recruiters use ASProx's Fast Fluxing Services&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html"&gt;Managed Fast Flux Provider - Part Two&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html"&gt;Managed Fast Flux Provider&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html"&gt;Storm Worm's Fast Flux Networks&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html"&gt;Fast Flux Spam and Scams Increasing&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html"&gt;Fast Fluxing Yet Another Pharmacy Spam&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html"&gt;Obfuscating Fast Fluxed SQL Injected Domains&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html"&gt;Storm Worm Hosting Pharmaceutical Scams&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=1122"&gt;Fast-Fluxing SQL injection attacks executed from the Asprox botnet&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-8543126532939026219?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3vJauflJy_U:bbqQSL6uhp0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3vJauflJy_U:bbqQSL6uhp0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3vJauflJy_U:bbqQSL6uhp0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=3vJauflJy_U:bbqQSL6uhp0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3vJauflJy_U:bbqQSL6uhp0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=3vJauflJy_U:bbqQSL6uhp0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3vJauflJy_U:bbqQSL6uhp0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3vJauflJy_U:bbqQSL6uhp0:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3vJauflJy_U:bbqQSL6uhp0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=3vJauflJy_U:bbqQSL6uhp0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/3vJauflJy_U" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-28T20:20:28.818+01:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_wICHhTiQmrA/SuiRneYoD1I/AAAAAAAAETQ/jWsiL0DFndg/s72-c/facebook_new_login_system_spam_fastflux_2.JPG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/10/ongoing-fdic-spam-campaign-serves-zeus.html</feedburner:origLink></item><item><title>Koobface Botnet Redirects Facebook's IP Space to my Blog</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/cDDG_FiiSyM/koobface-botnet-redirects-facebooks-ip.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Wed, 21 Oct 2009 14:18:04 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-3884183967149368547</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/St9uT2urS4I/AAAAAAAAESo/K3tPvZxjx0s/s1600-h/facebook_koobface_referrers_1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/St9uT2urS4I/AAAAAAAAESo/K3tPvZxjx0s/s320/facebook_koobface_referrers_1.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;Love me, love me, say that you love me. You know you're cherished when the Koobface botnet redirects Facebook Inc's entire IP space to your blog using HTTP Error 302 - Moved temporarily messages in an attempt to have Facebook's anti-malware crawlers hit my blog every time they visit a Koobface URL posted on the social networking site.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/St9xkhOgIbI/AAAAAAAAESw/UsRi7YF2LWI/s1600-h/facebook_ip_space_ddanchev_redirection.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/St9xkhOgIbI/AAAAAAAAESw/UsRi7YF2LWI/s320/facebook_ip_space_ddanchev_redirection.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;The result? Earlier this morning, I've noticed over 7,000 unique visits coming from Facebook Inc's IP space using active and automatically blogspot accounts part of the Koobface botnet as http referrers (&lt;a href="http://blogs.zdnet.com/security/?p=4594"&gt;New Koobface campaign spoofs Adobe's Flash updater&lt;/a&gt;), which is now officially &lt;a href="http://www.finjan.com/MCRCblog.aspx?EntryId=2317"&gt;relying on already infected hosts for the CAPTCHA recognition process&lt;/a&gt;. At first, I thought the Koobface gang has embedded an iFrame in order to achieve the effect, but the requests were coming from Facebook's IP space only.&lt;br /&gt;
&lt;br /&gt;
A representative from &lt;b&gt;Facebook's Security Incident Response Team&lt;/b&gt; just confirmed the development, and commented that they've added an exception, which is now visible since IPs from Facebook's IP space are no longer visiting my blog: &lt;br /&gt;
&lt;br /&gt;
"&lt;i&gt;Thanks for bringing this to our attention. I'm on the Security Incident Response team at Facebook and we just finished looking into this issue. We visit all links posted to Facebook as part of our link preview feature. We also take the opportunity to do some additional security screening to filter out bad content. Koobface in particular is fond of redirecting our requests to legitimate websites, and you seem to have done something to piss Koobface off. &lt;b&gt;All visits to Koobface URLs from our IP space are currently being redirected to your blog.&lt;/b&gt;&lt;/i&gt;"&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/St9pMvTG4nI/AAAAAAAAESQ/C1dlgY6304E/s1600-h/facebook_koobface_referrers_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/St9pMvTG4nI/AAAAAAAAESQ/C1dlgY6304E/s200/facebook_koobface_referrers_2.JPG" /&gt;&lt;/a&gt;The compete list of the automatically registered blogspot accounts, of whose existence Google's security team has already been notified are as follows:&lt;br /&gt;
&lt;b&gt;1rykutviklingibtvedmongstad-vgnett .blogspot.com/&lt;br /&gt;
40-nrg .blogspot.com/&lt;br /&gt;
anyauujteykbrlzyt .blogspot.com/&lt;br /&gt;
bctdnvxyubozkute336 .blogspot.com/&lt;br /&gt;
bjfzibzxpjwfsri.blogspot .com/&lt;br /&gt;
bopscfmfdfkdcdk.blogspot .com/&lt;br /&gt;
bpucrtkuigcvuzd.blogspot .com/&lt;br /&gt;
dcljxlmkdpfyadlmk014.blogspot .com/&lt;br /&gt;
driwnhtqcifnewwy.blogspot .com/&lt;br /&gt;
fffgxdpmrhzepmwc172.blogspot .com/&lt;br /&gt;
frjutygrfzkfmumr.blogspot .com/&lt;br /&gt;
gbmasakrnbvduky-mhopomuytpmeo46.blogspot .com/&lt;br /&gt;
hmxmjrdpzncnania.blogspot .com/&lt;br /&gt;
hryuickbrfxpgkiqc-wnyohlytffli526.blogspot .com/&lt;br /&gt;
hxsdrjrbiesmulbp-mp775012.blogspot .com/&lt;br /&gt;
hz560607.blogspot .com/&lt;br /&gt;
irfwgrbghyzrnaajs-npqpnvzqrqqeziywhx8.blogspot .com/&lt;br /&gt;
isaqwpccpkvmmnffx.blogspot .com/&lt;br /&gt;
iunvrafuvbgykpap819.blogspot .com/&lt;br /&gt;
ixqowmtgwfvkaapq.blogspot .com/&lt;br /&gt;
jocdniqudpnszswn936.blogspot .com/&lt;br /&gt;
jxpxhokysarhvnfw-wvtbfawtlocf932 .blogspot.com/&lt;br /&gt;
kayaafwlllybvydpu.blogspot .com/&lt;br /&gt;
kfddbjhalrqkmqtoa.blogspot .com/&lt;br /&gt;
kutlvtfxkxbismwpci.blogspot .com/&lt;br /&gt;
kyqyiplztbsiwogx-hfnrmfxbkjzswjq964.blogspot .com/&lt;/b&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/St9rXn5KChI/AAAAAAAAESY/HX_7jR15W7g/s1600-h/facebook_koobface_referrers_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/St9rXn5KChI/AAAAAAAAESY/HX_7jR15W7g/s200/facebook_koobface_referrers_3.JPG" /&gt;&lt;/a&gt;&lt;b&gt;kzbcbzhlgcnmmaveusdt2.blogspot .com/&lt;br /&gt;
lbwhvnvfmiwqypft-gt34676.blogspot .com/&lt;br /&gt;
lgjxsfcwkviythet.blogspot .com/&lt;br /&gt;
lvlcauoimpklqoj.blogspot .com/&lt;br /&gt;
moruokuamhtobznhwx.blogspot .com/&lt;br /&gt;
nfnnialisemtirdcq.blogspot .com/&lt;br /&gt;
pfmrjjvolrxsthdl.blogspot .com/&lt;br /&gt;
pywkyzxqcslnqyz907.blogspot .com/&lt;br /&gt;
qmhbxydgxfitnaosp.blogspot .com/&lt;br /&gt;
rfsnkstagwfwlkgr.blogspot .com/&lt;br /&gt;
rykutviklingibtvedmongstad-vgnett .blogspot.com/&lt;br /&gt;
scjftnvmcqiarvt-ni242558.blogspot .com/&lt;br /&gt;
skpjwfruzkzujvw.blogspot .com/&lt;br /&gt;
spfymrxnfiotvtrknf.blogspot .com/&lt;br /&gt;
sxcfugyjtvtwgxzvi.blogspot .com/&lt;br /&gt;
tbgkfbllzdtrcslpc741.blogspot .com/&lt;br /&gt;
unrrldfyuanstafa.blogspot .com/&lt;br /&gt;
vstikrflawgquztcn.blogspot .com/&lt;br /&gt;
wjfpuoiolcjvecszeb.blogspot .com/&lt;br /&gt;
wlaafuebvmdkaiavh.blogspot .com/&lt;br /&gt;
wnejhokyqkazwpu898.blogspot.com/&lt;br /&gt;
wqqcknikrlnowgri.blogspot .com/&lt;br /&gt;
xlmwrzdmywbibfwi742.blogspot .com/&lt;br /&gt;
yanksroadwinchangesalcsoutlook-mlbcom .blogspot.com/&lt;br /&gt;
yeqhabdnabhndbt.blogspot .com/&lt;br /&gt;
yzyweidzwor-cxgwufvosfam .blogspot.com/&lt;br /&gt;
zafxzlatzsmwysk.blogspot .com/&lt;br /&gt;
znfnxeaoiqhxldvmqo-atcsqbrkobwi408 .blogspot.com/&lt;br /&gt;
zqsvjeoqccknkfubc.blogspot .com/&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/St9tUiF-y9I/AAAAAAAAESg/u4BGNn_lZas/s1600-h/trendmicro_koobface.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/St9tUiF-y9I/AAAAAAAAESg/u4BGNn_lZas/s200/trendmicro_koobface.JPG" /&gt;&lt;/a&gt;The Koobface gang's use of basic blackhat SEO principles such as content cloaking are identical to their previous attempts to cover-up their malicious activities relying on pre-defined sets of http referrers of public search engines, or particular redirectors in order for their infections to take place. &lt;br /&gt;
&lt;br /&gt;
Stay tuned for more developments on the &lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SrEuy-LR3_I/AAAAAAAAEKY/0MVRFgdlAQM/s1600-h/koobface_scareware_5.png"&gt;&lt;b&gt;Ali Baba and the 40 thieves LLC&lt;/b&gt;&lt;/a&gt; front, a.k.a as &lt;a href="http://ddanchev.blogspot.com/2009/10/koobface-botnet-dissected-in-trendmicro.html"&gt;my Ukrainian "fan club"&lt;/a&gt;. The circle is almost complete, a lot of recent events will be summarized shortly.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/10/koobface-botnet-dissected-in-trendmicro.html"&gt;Koobface Botnet Dissected in a TrendMicro Report&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/09/koobface-botnets-scareware-business.html"&gt;Koobface Botnet's Scareware Business Model&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front-part-two.html"&gt;Movement on the Koobface Front - Part Two&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front.html"&gt;Movement on the Koobface Front&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/koobface-come-out-come-out-wherever-you.html"&gt;Koobface - Come Out, Come Out, Wherever You Are &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/dissecting-koobface-worms-twitter.html"&gt;Dissecting Koobface Worm's Twitter Campaign&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/12/dissecting-koobface-worms-december.html"&gt;Dissecting the Koobface Worm's December Campaign &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/11/dissecting-latest-koobface-facebook.html"&gt;Dissecting the Latest Koobface Facebook Campaign&lt;/a&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/12/koobface-gang-mixing-social-engineering.html"&gt;The Koobface Gang Mixing Social Engineering Vectors&lt;/a&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-3884183967149368547?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDDG_FiiSyM:Z3KViepRcNM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDDG_FiiSyM:Z3KViepRcNM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDDG_FiiSyM:Z3KViepRcNM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=cDDG_FiiSyM:Z3KViepRcNM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDDG_FiiSyM:Z3KViepRcNM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=cDDG_FiiSyM:Z3KViepRcNM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDDG_FiiSyM:Z3KViepRcNM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDDG_FiiSyM:Z3KViepRcNM:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=cDDG_FiiSyM:Z3KViepRcNM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=cDDG_FiiSyM:Z3KViepRcNM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/cDDG_FiiSyM" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-21T23:18:04.200+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_wICHhTiQmrA/St9uT2urS4I/AAAAAAAAESo/K3tPvZxjx0s/s72-c/facebook_koobface_referrers_1.JPG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/10/koobface-botnet-redirects-facebooks-ip.html</feedburner:origLink></item><item><title>Scareware Serving Conficker.B Infection Alerts Spam Campaign</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/ekml5vbHJJ4/scareware-serving-confickerb-infection.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Tue, 20 Oct 2009 09:51:24 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-2643842682906869716</guid><description>&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/St3lUvWZNoI/AAAAAAAAERw/W1Z5wT-3hO0/s1600-h/conficker_alerts_scareware_avpro_2010_1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/St3lUvWZNoI/AAAAAAAAERw/W1Z5wT-3hO0/s200/conficker_alerts_scareware_avpro_2010_1.jpg" /&gt;&lt;/a&gt;A fake &lt;a href="http://blogs.zdnet.com/security/?p=4674"&gt;"conficker.b infection alert" spam campaign&lt;/a&gt; first observed in April, 2009 (using the following scareware domains &lt;b&gt;antivirus-av-ms-check .com&lt;/b&gt;; &lt;b&gt;antivirus-av-ms-checker .com&lt;/b&gt;; &lt;b&gt;ms-anti-vir-scan .com&lt;/b&gt;; &lt;b&gt;mega-antiviral-ms .com&lt;/b&gt; back then) is once again circulating in an attempt to trick users into installing "antispyware application", in this case the &lt;a href="http://www.virustotal.com/analisis/d3d77586778a25be86b5bc30b293b56abc280f22512d725a36f7ee0c5432e6c2-1256051197"&gt;Antivirus Pro 2010 scareware&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
This campaign is directly related to &lt;a href="http://www.trusteer.com/files/Zeus-OWA_Advisory_Oct_2009.pdf"&gt;last week's Microsoft Outlook update campaign&lt;/a&gt;, with both of these using &lt;a href="http://blog.purewire.com/bid/21391/Fake-Microsoft-Outlook-Updates-Spread-Rogue-AV"&gt;identical download locations&lt;/a&gt; for the scareware. &lt;br /&gt;
&lt;br /&gt;
The following is an extensive list of the domains involved in the campaigns:&lt;br /&gt;
&lt;b&gt;abumaso3tkamid .com&lt;/b&gt; - Email: drawn@ml3.ru&lt;br /&gt;
&lt;b&gt;afedodevascevo .com&lt;/b&gt; - Email: sixty@8081.ru&lt;br /&gt;
&lt;b&gt;alertonabert .com&lt;/b&gt; - Email: flop@infotorrent.ru&lt;br /&gt;
&lt;b&gt;alertonbgabert .com&lt;/b&gt; - Email: vale@e2mail.ru&lt;br /&gt;
&lt;b&gt;alioneferkilo .com&lt;/b&gt; - Email: va@blogbuddy.ru&lt;br /&gt;
&lt;b&gt;anobalukager .com&lt;/b&gt; - Email: chalkov@co5.ru&lt;br /&gt;
&lt;b&gt;anobhalukager .com&lt;/b&gt; - Email: humps@infotorrent.ru&lt;br /&gt;
&lt;b&gt;bufertongamoda .com&lt;/b&gt; - Email: kurt@8081.ru&lt;br /&gt;
&lt;b&gt;buhafertadosag .com&lt;/b&gt; - Email: bias@co5.ru&lt;br /&gt;
&lt;b&gt;buhervadonuska .com&lt;/b&gt; - Email: vale@e2mail.ru&lt;br /&gt;
&lt;b&gt;bulakeskatorad .com&lt;/b&gt; - Email: bias@co5.ru&lt;br /&gt;
&lt;b&gt;bulerkoseddasko .com&lt;/b&gt; - Email: bias@co5.ru&lt;br /&gt;
&lt;b&gt;buleropihertan .com&lt;/b&gt; - Email: def@co5.ru&lt;br /&gt;
&lt;b&gt;celiminerkariota .com&lt;/b&gt; - Email: morse@corporatemail.ru&lt;br /&gt;
&lt;b&gt;certovalionas .com&lt;/b&gt; - Email: kurt@8081.ru&lt;br /&gt;
&lt;b&gt;dabertugaburav .com&lt;/b&gt; - Email: def@co5.ru&lt;br /&gt;
&lt;b&gt;elxolisdonave .com&lt;/b&gt; - Email: curb@cheapmail.ru&lt;br /&gt;
&lt;b&gt;enkafuleskohuj .com&lt;/b&gt; - Email: kerry@freemailbox.ru&lt;br /&gt;
&lt;b&gt;ertanueskayert .com&lt;/b&gt; - Email: xmas@co5.ru&lt;br /&gt;
&lt;b&gt;ertonaferdogalo .com&lt;/b&gt; - Email: kerry@freemailbox.ru&lt;br /&gt;
&lt;b&gt;ertu6nagertos .com&lt;/b&gt; - Email: recipe@isprovider.ru&lt;br /&gt;
&lt;b&gt;ertubedewse .com&lt;/b&gt; - Email: weak@infotorrent.ru&lt;br /&gt;
&lt;b&gt;ertugasedumil .com&lt;/b&gt; - Email: chalkov@co5.ru&lt;br /&gt;
&lt;b&gt;ertugaskedumil .com&lt;/b&gt; - Email: humps@infotorrent.ru&lt;br /&gt;
&lt;b&gt;ertunagertos .com&lt;/b&gt; - Email: def@co5.ru&lt;br /&gt;
&lt;b&gt;erubamerkadolo .com&lt;/b&gt; - Email: kerry@freemailbox.ru&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;fedostalonkah .com&lt;/b&gt; - Email: bias@co5.ru&lt;br /&gt;
&lt;b&gt;ftahulabedaso .com&lt;/b&gt; - Email: raced@corporatemail.ru&lt;br /&gt;
&lt;b&gt;gumertagionader .com&lt;/b&gt; - Email: seize@e2mail.ru&lt;br /&gt;
&lt;b&gt;huladopkaert .com&lt;/b&gt; - Email: chute@infotorrent.ru&lt;br /&gt;
&lt;b&gt;iobacebauiler .com&lt;/b&gt; - Email: roy@corporatemail.ru&lt;br /&gt;
&lt;b&gt;itorkalione .com&lt;/b&gt; - Email: pygmy@8081.ru&lt;br /&gt;
&lt;b&gt;julionejurmon .com&lt;/b&gt; - Email: jacob@freemailbox.ru&lt;br /&gt;
&lt;b&gt;julionermon .com&lt;/b&gt; - Email: pygmy@8081.ru&lt;br /&gt;
&lt;b&gt;konitorsabure .com&lt;/b&gt; - Email: chalkov@co5.ru&lt;br /&gt;
&lt;b&gt;konitorswabure .com&lt;/b&gt; - Email: humps@infotorrent.ru &lt;br /&gt;
&lt;b&gt;lersolamaderg .com&lt;/b&gt; - Email: chalkov@co5.ru&lt;br /&gt;
&lt;b&gt;lersolamgaderg .com&lt;/b&gt; - Email: humps@infotorrent.ru&lt;br /&gt;
&lt;b&gt;linkertagubert .com&lt;/b&gt; - Email: kerry@freemailbox.ru&lt;br /&gt;
&lt;b&gt;lionglenhrvoa .com&lt;/b&gt; - Email: sixty@8081.ru&lt;br /&gt;
&lt;b&gt;liposdakoferda .com&lt;/b&gt; - Email: leaf@corporatemail.ru&lt;br /&gt;
&lt;b&gt;lopastionertu .com&lt;/b&gt; - Email: cues@e2mail.ru&lt;br /&gt;
&lt;b&gt;nebrafsofertu .com&lt;/b&gt; - Email: humps@infotorrent.ru&lt;br /&gt;
&lt;b&gt;nuherfodaverta .com&lt;/b&gt; - Email: morse@corporatemail.ru&lt;br /&gt;
&lt;b&gt;nulerotkabelast .com&lt;/b&gt; - Email: dealt@8081.ru&lt;br /&gt;
&lt;b&gt;nulkersonatior .com&lt;/b&gt; - Email: dealt@8081.ru&lt;br /&gt;
&lt;b&gt;obuleskinrodab .com&lt;/b&gt; - Email: xmas@co5.ru&lt;br /&gt;
&lt;b&gt;ofaderhabewuit .com&lt;/b&gt; - Email: kerry@freemailbox.ru&lt;br /&gt;
&lt;b&gt;okavanubares .com&lt;/b&gt; - Email: chalkov@co5.ru&lt;br /&gt;
&lt;b&gt;okaveanubares .com&lt;/b&gt; - Email: humps@infotorrent.ru&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;onagerfadusak .com&lt;/b&gt; - Email: cues@e2mail.ru&lt;br /&gt;
&lt;b&gt;orav4abustorabe .com&lt;/b&gt; - Email: drawn@ml3.ru&lt;br /&gt;
&lt;b&gt;oscaviolaner .com&lt;/b&gt; - Email: larks@freemailbox.ru&lt;br /&gt;
&lt;b&gt;ovuiobvipolak .com&lt;/b&gt; - Email: sixty@8081.ru&lt;br /&gt;
&lt;b&gt;ovuioipolak .com&lt;/b&gt; - Email: bias@co5.ru&lt;br /&gt;
&lt;b&gt;paferbasedos .com&lt;/b&gt; - Email: chalkov@co5.ru&lt;br /&gt;
&lt;b&gt;pafersbasedos .com&lt;/b&gt; - Email: humps@infotorrent.ru&lt;br /&gt;
&lt;b&gt;polanermogalios .com&lt;/b&gt; - Email: dealt@8081.ru&lt;br /&gt;
&lt;b&gt;rdafergfvacex .com&lt;/b&gt; - Email: jacob@freemailbox.ru&lt;br /&gt;
&lt;b&gt;rtugamer5tobes .com&lt;/b&gt; - Email: drawn@ml3.ru&lt;br /&gt;
&lt;b&gt;rtugamertobes .com&lt;/b&gt; - Email: kw@co5.ru&lt;br /&gt;
&lt;b&gt;scukonherproger .com&lt;/b&gt; - Email: kazoo@isprovider.ru&lt;br /&gt;
&lt;b&gt;shuretrobaniso .com&lt;/b&gt; - Email: frail@infotorrent.ru&lt;br /&gt;
&lt;b&gt;tarhujelafert .com&lt;/b&gt; - Email: raced@corporatemail.ru&lt;br /&gt;
&lt;b&gt;tavakulio5nkab .com&lt;/b&gt; - Email: recipe@isprovider.ru&lt;br /&gt;
&lt;b&gt;tavakulionkab .com&lt;/b&gt; - Email: def@co5.ru&lt;br /&gt;
&lt;b&gt;tertunavogav .com&lt;/b&gt; - Email: la@freemailbox.ru&lt;br /&gt;
&lt;b&gt;tertunwavogav .com&lt;/b&gt; - Email: drawn@ml3.ru&lt;br /&gt;
&lt;b&gt;tsabunerkadosa .com&lt;/b&gt; - Email: humps@infotorrent.ru&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/St3nq6kbSzI/AAAAAAAAESA/p3_bN7Ao2MI/s1600-h/conficker_alerts_scareware_avpro_2010.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/St3nq6kbSzI/AAAAAAAAESA/p3_bN7Ao2MI/s200/conficker_alerts_scareware_avpro_2010.jpg" /&gt;&lt;/a&gt;&lt;b&gt;tsarbunerkadosa .com&lt;/b&gt; - Email: humps@infotorrent.ru&lt;br /&gt;
&lt;b&gt;tubanerdavaf .com&lt;/b&gt; - Email: chalkov@co5.ru&lt;br /&gt;
&lt;b&gt;tubanerdavjaf .com&lt;/b&gt; - Email: halkov@co5.ru&lt;br /&gt;
&lt;b&gt;uhajokalesko .com&lt;/b&gt; - Email: flop@infotorrent.ru&lt;br /&gt;
&lt;b&gt;uhajokvfalesko .com&lt;/b&gt; - Email: flop@infotorrent.ru&lt;br /&gt;
&lt;b&gt;ulioperdanogad .com&lt;/b&gt; - Email: vale@e2mail.ru&lt;br /&gt;
&lt;b&gt;uliopewrdanogad .com&lt;/b&gt; - Email: kerry@freemailbox.ru&lt;br /&gt;
&lt;b&gt;uplaserdunavats .com&lt;/b&gt; - Email: dealt@8081.ru&lt;br /&gt;
&lt;b&gt;utka3merdosubor .com&lt;/b&gt; - Email: drawn@ml3.ru&lt;br /&gt;
&lt;b&gt;utkamerdosubor .com&lt;/b&gt; - Email: kw@co5.ru&lt;br /&gt;
&lt;b&gt;utorganedoskaw .com&lt;/b&gt; - Email: kerry@freemailbox.ru&lt;br /&gt;
&lt;b&gt;utorgtanedoskaw .com&lt;/b&gt; - Email: xmas@co5.ru&lt;br /&gt;
&lt;b&gt;uvgaderbotario .com&lt;/b&gt; - Email: def@co5.ru&lt;br /&gt;
&lt;b&gt;vudermaguliermot .com&lt;/b&gt; - Email: leaf@corporatemail.ru&lt;br /&gt;
&lt;b&gt;vuilerdomegase .com&lt;/b&gt; - Email: leaf@corporatemail.ru&lt;br /&gt;
&lt;b&gt;vuilleskomandar .com&lt;/b&gt; - Email: seize@e2mail.ru&lt;br /&gt;
&lt;b&gt;vulertagulermos .com&lt;/b&gt; - Email: dealt@8081.ru&lt;br /&gt;
&lt;b&gt;vuretronulevka .com&lt;/b&gt; - Email: dealt@8081.ru&lt;br /&gt;
&lt;b&gt;weragumasekasuke .com&lt;/b&gt; - Email: kazoo@isprovider.ru&lt;br /&gt;
&lt;b&gt;werynaherdobas .com&lt;/b&gt; - Email: dealt@8081.ru&lt;br /&gt;
&lt;br /&gt;
Despite the comprehensive portfolio of domains used, relying on spam to increase revenue from scareware sales is prone to fail, in this specific case due to the lack of event-based social engineering theme, something that was present in the first campaign.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/04/confickers-scarewarefake-security.html"&gt;Conficker's Scareware/Fake Security Software Business Model &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/09/koobface-botnets-scareware-business.html"&gt;Koobface Botnet's Scareware Business Model&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-2643842682906869716?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ekml5vbHJJ4:AViz74xfi60:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ekml5vbHJJ4:AViz74xfi60:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ekml5vbHJJ4:AViz74xfi60:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=ekml5vbHJJ4:AViz74xfi60:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ekml5vbHJJ4:AViz74xfi60:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=ekml5vbHJJ4:AViz74xfi60:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ekml5vbHJJ4:AViz74xfi60:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ekml5vbHJJ4:AViz74xfi60:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ekml5vbHJJ4:AViz74xfi60:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=ekml5vbHJJ4:AViz74xfi60:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/ekml5vbHJJ4" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-20T18:51:24.296+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_wICHhTiQmrA/St3lUvWZNoI/AAAAAAAAERw/W1Z5wT-3hO0/s72-c/conficker_alerts_scareware_avpro_2010_1.jpg" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/10/scareware-serving-confickerb-infection.html</feedburner:origLink></item><item><title>Koobface Botnet Dissected in a TrendMicro Report</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/VtL2SRnL1w4/koobface-botnet-dissected-in-trendmicro.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Wed, 14 Oct 2009 09:22:42 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-8247501688020671321</guid><description>&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/StXzL5MWBII/AAAAAAAAERY/muXddtmbSqY/s1600-h/trendmicro_koobface.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/StXzL5MWBII/AAAAAAAAERY/muXddtmbSqY/s200/trendmicro_koobface.JPG" /&gt;&lt;/a&gt;I'd like to thank the folks at &lt;a href="http://blog.trendmicro.com/"&gt;TrendMicro&lt;/a&gt; for mentioning the message inserted by the Koobface gang (&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SigkzSv-sLI/AAAAAAAADrw/pPcRifZSU6U/s1600-h/blackhat_seo_ddanchev_love.JPG"&gt;more&lt;/a&gt; love &lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Si0hcLUtElI/AAAAAAAADug/yHBpEfNePuQ/s1600-h/blackhat_seo_ddanchev_more_love_3.JPG"&gt;on a&lt;/a&gt; first-name basis &lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SigncRzz67I/AAAAAAAADr4/JY2mBxIf4Hw/s1600-h/blackhat_seo_ddanchev_more_love.JPG"&gt;from them&lt;/a&gt;) within their command and control infrastructure for nine days, &lt;a href="http://ddanchev.blogspot.com/2009/07/koobface-come-out-come-out-wherever-you.html"&gt;greeting me for&lt;/a&gt; systematically &lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front-part-two.html"&gt;kicking them out of their ISPs&lt;/a&gt;, and suspending their command and control domains, in a new report entitled &lt;a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/the_20heart_20of_20koobface_final_1_.pdf"&gt;The Heart of Koobface - C&amp;amp;C and Social Network Propagation&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
"&lt;i&gt;This simplistic C&amp;amp;C approach is, of course, very vulnerable to takedowns. After several KOOBFACE C&amp;amp;C takedown attempts initiated by Internet service providers (ISPs) and members of the security industry, the KOOBFACE gang realized the need for a more robust C&amp;amp;C infrastructure.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Thus, on July 19, 2009, the KOOBFACE writers implemented a new C&amp;amp;C architecture that involved the use of proxy nodes to provide redundancy and to improve the survivability of their C&amp;amp;C should another takedown be attempted. A few days after the new KOOBFACE C&amp;amp;C infrastructure was implemented, the botnet was seen inserting a message (see below) for one of the security researchers tracking the malware’s domain activities.&lt;br /&gt;
&lt;br /&gt;
This message run lasted nine days from July 22 to July 30, 2009. Based on this incident, we can safely assume that the KOOBFACE gang has been monitoring blogs, articles, write-ups, and analyses about their handiwork and was probably also keeping tabs on the various solutions deployed to counter the botnet’s attacks. Second, these people were thus quick to act and fix their creation’s weaknesses, as evidenced by its change in infrastructure. Finally, the botnet’s creators were bold enough to send taunting messages to security researchers.&lt;/i&gt;"&lt;br /&gt;
&lt;br /&gt;
Having the Koobface gang kicked out of their ISPs in 48 hours through close cooperation with &lt;i&gt;China's CERT; BlueConnex Ltd; PacificRack.com; Oc3 Networks &amp;amp; Web Solutions Llc; Telos-Solutions-AS/Telos Solutions LTD&lt;/i&gt;, resulted in a single command and control domain which was active and using the services of UKSERVERS-MNT (AS42831), &lt;b&gt;78.110.175.15&lt;/b&gt; in particular. Simply put, the Koobface botnet and the hundreds of thousands of infected hosts were not just sitting ducks, but ducks who've fallen asleep in the middle of the hunting season.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/StX3_VgfUbI/AAAAAAAAERg/4SZDzk-jGYs/s1600-h/koobface-thanks-dancho1.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/StX3_VgfUbI/AAAAAAAAERg/4SZDzk-jGYs/s200/koobface-thanks-dancho1.PNG" /&gt;&lt;/a&gt;It's important to point out that the company (UKSERVERS-MNT) on purposely lied that the customer has been taken offline, allowed the Koobface gang to access the server since the gang claimed "&lt;i&gt;it's a compromised customer and needs to clean-up the mess&lt;/i&gt;", then on purposely stopped responding to the smoothly going data sharing process, thereby allowing the Koobface gang to put their contingency plan in place.&lt;br /&gt;
&lt;br /&gt;
The bottom line - based on already published and to-be published assessments of this group's activities, the Koobface botnet &lt;a href="http://blogs.zdnet.com/security/?p=4549"&gt;appears to be only&lt;/a&gt; the &lt;a href="http://ddanchev.blogspot.com/2009/09/ukrainian-fan-club-features.html"&gt;tip of the iceberg&lt;/a&gt; for the &lt;a href="http://en.wikipedia.org/wiki/Ali_Baba_and_the_Forty_Thieves_%281944_film%29"&gt;Ali baba and the 40 thieves&lt;/a&gt; cybercrime enterprise -- a self-describing &lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SrEuy-LR3_I/AAAAAAAAEKY/0MVRFgdlAQM/s1600-h/koobface_scareware_5.png"&gt;message included by the Koobface gang&lt;/a&gt;. Their activities also prove a point - a single cybercrime enterprise can efficiently and automatically dominate the entire Web 2.0 threatscape, if they want to.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/09/koobface-botnets-scareware-business.html"&gt;Koobface Botnet's Scareware Business Model&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front-part-two.html"&gt;Movement on the Koobface Front - Part Two&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front.html"&gt;Movement on the Koobface Front&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/koobface-come-out-come-out-wherever-you.html"&gt;Koobface - Come Out, Come Out, Wherever You Are &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/dissecting-koobface-worms-twitter.html"&gt;Dissecting Koobface Worm's Twitter Campaign&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/12/dissecting-koobface-worms-december.html"&gt;Dissecting the Koobface Worm's December Campaign &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/11/dissecting-latest-koobface-facebook.html"&gt;Dissecting the Latest Koobface Facebook Campaign&lt;/a&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/12/koobface-gang-mixing-social-engineering.html"&gt;The Koobface Gang Mixing Social Engineering Vectors&lt;/a&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-8247501688020671321?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VtL2SRnL1w4:dRSUZGPxsaA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VtL2SRnL1w4:dRSUZGPxsaA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VtL2SRnL1w4:dRSUZGPxsaA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=VtL2SRnL1w4:dRSUZGPxsaA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VtL2SRnL1w4:dRSUZGPxsaA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=VtL2SRnL1w4:dRSUZGPxsaA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VtL2SRnL1w4:dRSUZGPxsaA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VtL2SRnL1w4:dRSUZGPxsaA:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VtL2SRnL1w4:dRSUZGPxsaA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=VtL2SRnL1w4:dRSUZGPxsaA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/VtL2SRnL1w4" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-14T18:22:42.741+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_wICHhTiQmrA/StXzL5MWBII/AAAAAAAAERY/muXddtmbSqY/s72-c/trendmicro_koobface.JPG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/10/koobface-botnet-dissected-in-trendmicro.html</feedburner:origLink></item><item><title>Standardizing the Money Mule Recruitment Process</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/VzCAtmZxRDE/standardizing-money-mule-recruitment.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Tue, 06 Oct 2009 00:23:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-8255511682351722453</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SsIfwn2rTgI/AAAAAAAAEMA/NNL1BkSmTdo/s1600-h/money_mules_syndicate_U.S_U.K.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SsIfwn2rTgI/AAAAAAAAEMA/NNL1BkSmTdo/s320/money_mules_syndicate_U.S_U.K.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://voices.washingtonpost.com/securityfix/2009/09/money_mule_recruitment_101.html"&gt;Ah, deja vu!&lt;/a&gt; How is it possible that the &lt;a href="http://www.bobbear.co.uk/scope-group-inc.html?6a00c340"&gt;Scope Group money mule recruitment group&lt;/a&gt; acting as the employer for the interviewed mule has been "&lt;i&gt;set up in 1990 in New York, the USA by three enthusiasts who have financial education" &lt;/i&gt;just like &lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/ShwQq_kTe6I/AAAAAAAADoo/IXsylpK2QKM/s1600-h/af-group-llc.png"&gt;AF-GROUP LLC&lt;/a&gt; and its portfolio of brands, whose 30k &lt;a href="http://ddanchev.blogspot.com/2009/05/inside-money-laundering-groups-spamming.html"&gt;botnet operations I exposed and took down in May, 2009&lt;/a&gt;, next to establishing a direct connection between the botnet and an &lt;a href="http://ddanchev.blogspot.com/2009/06/dating-spam-campaign-promotes-bogus.html"&gt;Ukrainian dating scam agency known as "Confidential Connections"&lt;/a&gt;?&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Ssp-GnY9EqI/AAAAAAAAEPY/d8zwSLwaq4s/s1600-h/money_mule_recruitment_20.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Ssp-GnY9EqI/AAAAAAAAEPY/d8zwSLwaq4s/s200/money_mule_recruitment_20.png" /&gt;&lt;/a&gt;Pretty simple - just like the efficiency-centered mentality applied in the &lt;a href="http://ddanchev.blogspot.com/2008/07/template-ization-of-malware-serving.html"&gt;template-ization&lt;/a&gt; of &lt;a href="http://ddanchev.blogspot.com/2009/02/template-ization-of-malware-serving.html"&gt;malware&lt;/a&gt;, the ongoing standardization of the money mule recruitment business model is resulting in a bogus brand portfolios using identical web site layouts next to the same copy writing materials offered by a single vendor exclusively working with money mule recruitment organizations only. A couple of years ago, the money mule recruitment process was largely inefficient due to the operational security applied - &lt;a href="http://ddanchev.blogspot.com/2008/10/money-mules-syndicate-actively.html"&gt;not everyone could become a money mule unless certain criteria was met&lt;/a&gt;. A newly launched managed money mule recruitment design agency that I've been monitoring for a while, is poised to help cybercriminals achieve faster recruitment rates based on the cybercriminal-tailored services it's offering.&lt;br /&gt;
&lt;br /&gt;
Whereas it's been operating beneath the radar for several years, exclusively serving known and trusted cybercriminals, it's recent mainstream business model is a great example of a timely underground market proposition due to the fact that the current economic climate best suits the money mule recruitment business model due to its high commissions for processing fraudulently obtained money.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Ssp-MqPhayI/AAAAAAAAEPg/A84EK65wDXA/s1600-h/money_mule_recruitment_21.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Ssp-MqPhayI/AAAAAAAAEPg/A84EK65wDXA/s200/money_mule_recruitment_21.png" /&gt;&lt;/a&gt;Do you infiltrate the entire assembly line, or do you assess the final product? Appreciate my rhetoric as usual, it's full disclosure time, hence infiltrating the assembly line.&lt;br /&gt;
&lt;br /&gt;
In this post, we'll take a look at five templates offered by the managed money mule recruitment vendor, assess several of their customers currently using them to launch targeted and localized to German spam campaigns aiming to recruit new money mules, expose their entire domains portfolio and associated emails used for correspondence with prospective money mules.&lt;br /&gt;
&lt;br /&gt;
Moreover, we'll actually attempt to becoming a money mule by interacting with their market proposition, obtain the financial agent agreements, and expose little known facts about how sophisticated and social-engineering oriented the entire money mule recruitment process really is.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SspJ8A2miwI/AAAAAAAAEMw/y9B_9ll3uSI/s1600-h/money_mule_recruitment_26.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SspJ8A2miwI/AAAAAAAAEMw/y9B_9ll3uSI/s200/money_mule_recruitment_26.jpg" /&gt;&lt;/a&gt;For starters, here's how the service describes itself, and what type of packages it offers to prospective money mule recruiters. The less sophisticated package is offered for $900 and the corporate version goes for $1700.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;The first one offers the following:&lt;/b&gt;&lt;br /&gt;
- fake company site in English&lt;br /&gt;
- template-based correspondence letters for the entire process&lt;br /&gt;
- the entire document required for the process, custom forms, contracts, invoice applications etc.&lt;br /&gt;
- a teach-yourself manual including advice and recommendations - available in English and Russian&lt;br /&gt;
- sample spam letters in TXT and HTML, in English only&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;The corporate version offers the following:&lt;/b&gt;&lt;br /&gt;
- fake company site in several languages, for instance, Dutch, German, Bulgarian, Italian etc.&lt;br /&gt;
- fake signatures representing the CEO, accounts manager etc.&lt;br /&gt;
- multiple spam letters in different languages&lt;br /&gt;
- managed domain hosting&lt;br /&gt;
- answering machine number as well as a paid Skype subscription as a bonus&lt;br /&gt;
&lt;br /&gt;
The following are some of the templates -- blurred by the vendor in order to protect the bogus brands portfolio - currently offered by the service. Three of the templates are already in circulation, that means active spamming in Italian and German "offering the Moon", and asking for your identity and financial reputation:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SspeM57AGPI/AAAAAAAAENA/9q4ophIP9_M/s1600-h/money_mule_recruitment_1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SspeM57AGPI/AAAAAAAAENA/9q4ophIP9_M/s320/money_mule_recruitment_1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SspeVlfpF3I/AAAAAAAAENI/zFzbkFVkrmE/s1600-h/money_mule_recruitment_2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SspeVlfpF3I/AAAAAAAAENI/zFzbkFVkrmE/s320/money_mule_recruitment_2.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SspedPxRPmI/AAAAAAAAENQ/sJIafEgeczk/s1600-h/money_mule_recruitment_3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SspedPxRPmI/AAAAAAAAENQ/sJIafEgeczk/s320/money_mule_recruitment_3.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SspeiXSRwtI/AAAAAAAAENY/J--minlCizE/s1600-h/money_mule_recruitment_4.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SspeiXSRwtI/AAAAAAAAENY/J--minlCizE/s320/money_mule_recruitment_4.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SspeoBdRqgI/AAAAAAAAENg/PHM_R_wHs4Q/s1600-h/money_mule_recruitment_5.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SspeoBdRqgI/AAAAAAAAENg/PHM_R_wHs4Q/s320/money_mule_recruitment_5.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SspeuiiUVDI/AAAAAAAAENo/p6B-Q-zIAmY/s1600-h/money_mule_recruitment_6.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SspeuiiUVDI/AAAAAAAAENo/p6B-Q-zIAmY/s320/money_mule_recruitment_6.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;Upon purchasing any of the packages offered, a custom and non-existent brand logo and related company information will be used on the top of the templates currently offered.&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SsphROCk7pI/AAAAAAAAENw/OQE7-tQk-MY/s1600-h/money_mule_recruitment_7.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SsphROCk7pI/AAAAAAAAENw/OQE7-tQk-MY/s200/money_mule_recruitment_7.jpg" /&gt;&lt;/a&gt;Let's expose some of the bogus brands using these campaigns, whose spamming campaigns have been actively recruiting new money mules over the past couple of months. For instance, the last template -- see attached copy of the original one -- is currently being used by a company known as &lt;i&gt;PanIn Real Estate&lt;/i&gt; - &lt;b&gt;panestate .com&lt;/b&gt; - 194.0.200.15 - Email: disperswave@gmail.com. The site is currently localized to English; Italian (&lt;b&gt;panestate .com/index_it.html&lt;/b&gt;); and Spanish (&lt;b&gt;panestate .com/index_sp.html&lt;/b&gt;).&lt;br /&gt;
&lt;br /&gt;
It gets even more interesting when we start analyzing their spam campaign, currently localized to German. For instance, it appears that the customer of the managed money mule recruitment service is using their basic package, since 99% of their spam emails are using Gmail accounts, in fact, one of the spam campaigns is relying on the very same email that &lt;a href="http://lists.alioth.debian.org/pipermail/pkg-games-devel/2009-April/011121.html"&gt;the domain &lt;b&gt;panestate .com&lt;/b&gt;&lt;/a&gt; has been registered with - disperswave@gmail.com.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SspmxYl0_vI/AAAAAAAAEN4/FJ3_svw_hiE/s1600-h/money_mule_recruitment_16.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SspmxYl0_vI/AAAAAAAAEN4/FJ3_svw_hiE/s200/money_mule_recruitment_16.png" /&gt;&lt;/a&gt;&lt;b&gt;A sample of the spammed recruitment email:&lt;/b&gt;&lt;br /&gt;
"&lt;i&gt;Liebe Bewerber! Sind Sie schon mude von solchen Briefchen, in dem man Ihnen einen Arbeitsplatz anbietet? Ich weiss das. Deshalb mochte ich zuerst Sie um Verzeihung bitten. Ich habe aber eine freie Vakanz und mochte sie Ihnen anbieten.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Wenn Sie noch keinen Arbeitsplatz gefunden haben, schreiben Sie bitte mir an meine E-mail Adresse:&amp;nbsp; &lt;email removed=""&gt; Als eine Bestatigung brauche ich auch CV und Ihre Telefonnummer, damit ich mich mit Ihnen in Verbindung setzen konnte. Vielen Dank fur Ihre Zeit und Ihr Interesse! Alle weiteren Informationen bekommen Sie per E-Mail. Mit freundlichen Grusen&lt;/email&gt;&lt;/i&gt;"&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related Gmail accounts used by &lt;i&gt;PanIn Real Estate &lt;/i&gt;money mule recruitment incorporated:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://forum.computerbetrug.de/finanz-und-warenagenten/56347-finanzagenten-werbemail.html"&gt;pancorporate @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.antispam.de/forum/showthread.php?t=23791&amp;amp;page=2"&gt;paninwork @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://spam.tamagothi.de/2009/03/30/das-ist-esdein-traumjob/"&gt;paninde @ googlemail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://lists.alioth.debian.org/pipermail/reportbug-maint/2009-March/000766.html"&gt;panamajeld @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://lists.debian.org/debian-qt-kde/2009/03/msg00345.html"&gt;paninajob @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://juhuswelt.blogspot.com/2009/03/panamakarriere.html"&gt;pananmakarriere @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;The same spam template localized in German is also known to have been used with the following Gmail accounts, again operated by money-mule recruitment organizations:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://66381.homepagemodules.de/t2932f66-Eine-freie-Vakanz-nur-fuer-Sie.html"&gt;trzzbuded @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://codespeak.net/pipermail/pyrepl-dev/2009-April/008001.html"&gt;robertojens @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.spamarchiv.com/2009/04/05/nach-einer-stelle-gesucht/"&gt;gradtul @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://divinegypsy.20six.co.uk/divinegypsy/art/726546"&gt;hrmiket @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://divinegypsy.20six.co.uk/divinegypsy/art/738174/-CSHSDHSHDHSUPNEWNSSSBJFCSHSDHSHDHSUPNEWNSSSBJF-"&gt;mike.torhr @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://codespeak.net/pipermail/pyrepl-dev/2009-April.txt"&gt;evkoreyds @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://mailman.warwickcompsoc.co.uk/pipermail/compsoc-techteam/2009-April/007682.html"&gt;mike.torhr @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.antispam.de/forum/showthread.php?t=23791"&gt;support @ oplusdevelopment.com&lt;/a&gt; -- the only exception&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;The &lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SspeVlfpF3I/AAAAAAAAENI/zFzbkFVkrmE/s1600-h/money_mule_recruitment_2.jpg"&gt;second template&lt;/a&gt; used in the wild -- the site returns a 404 error message -- is called &lt;i&gt;Green Star Services website&lt;/i&gt;, with the customer apparently still in a testing phrase.&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SspojWe--LI/AAAAAAAAEOA/taM-EF7ML6E/s1600-h/money_mule_recruitment_28.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SspojWe--LI/AAAAAAAAEOA/taM-EF7ML6E/s200/money_mule_recruitment_28.png" /&gt;&lt;/a&gt;This cannot be said for yet another customer of the same service standardizing the money mule recruitment process by template-izing it. &lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SspeoBdRqgI/AAAAAAAAENg/PHM_R_wHs4Q/s1600-h/money_mule_recruitment_5.jpg"&gt;The fifth template&lt;/a&gt;, is actually a bogus company called &lt;i&gt;Brand Image Advertising Agency&lt;/i&gt; (&lt;b&gt;internationalbrandimage .com&lt;/b&gt; - 91.213.72.142 - Email: Sergey Stepanov; userovsky@gmail.com describing itself as:&lt;br /&gt;
&lt;br /&gt;
"&lt;i&gt;Advertising agency “Brand Image” helps its clients to perform their products and services the right way. We never offer you anything additional that we didn’t discuss at the beginning. The motto of our work is honesty and we believe that this is a very important thing in advertising. &lt;br /&gt;
&lt;br /&gt;
We were created to help you in selling products and services. “Brand Image” typically attempts to assist you in building your brand by persuading potential customers to purchase or to consume more of your brand of product or service. It is vivid from the name of our agency that we are doing a lot for your brand. Actually we are constantly working at brand management. It is known that the value of the brand is determined by the amount of profit it generates for the manufacturer. Advertising agency “Brand Image” clearly understands the main principles of brand name and will be glad to help you in choosing the right name for your company. &lt;br /&gt;
&lt;br /&gt;
Advertising agency “Brand Image” proudly presents a great variety of services it provides. The main advantage of our work is that our management staff is always on-line and works 24/7 for your convenience. Moreover, our offices are located all over the Europe and in the USA that makes our work fast and comprehensive. First of all let us introduce you what exactly we offer our clients. However if you happen to have any questions in understanding what this or that service means, you can always find our contacts and use them in communicating with us concerning our advertising offers.&lt;/i&gt;" &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Sample &lt;a href="http://spammit.blogspot.com/2009/09/internationalbrandimagecom.html"&gt;spam message localized in Italian used to recruit for Brand Image Advertising Agency&lt;/a&gt;:&lt;/b&gt;&lt;br /&gt;
"&lt;i&gt;Salary: 4,000 Euro; 10% di ciascuna operazione di pagamento - conto personale 10%; 15% di ciascuna operazione di pagamento - conto corporativo 15%; Location: Italy Accettazione dei pagamenti dai clienti nella vostra zona ? Accepting payments from customers in your area? favorire a realizzare gli obiettivi finanziarie di Compagnia.Le condizioni di lavoro. Il lavoro tranne internet - ufficio, e anche con le banche ei sistemi di trasferimenti veloci. Gli interessati ambosessi possono inviare CV con consenso al trattamento dei dati personali (art.13, d.lgs 196/03) e requisiti di contatto al e-mail. Se a Voi interessa questo lavoro, mandate il curriculum alla nostra: judicialHathawayv?@gmail.com Cordialmente, Sincerely, David De Simone David De Simone&lt;/i&gt;"&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Sspui2UjIuI/AAAAAAAAEOI/gTOom51qkj4/s1600-h/money_mule_recruitment_29.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Sspui2UjIuI/AAAAAAAAEOI/gTOom51qkj4/s200/money_mule_recruitment_29.png" /&gt;&lt;/a&gt;&lt;b&gt;A second template is known known to have been used, this time offering different commission:&lt;/b&gt;&lt;br /&gt;
"&lt;i&gt;Rappresentante finanziario Informazioni di posti di lavoro Post Date: 12/04/2009 Salario: 3.000 EUR/mese + 5% di ciascuna operazione di bonifico Location: Italia Generale Description Accettazione dei pagamenti dai clienti nella vostra zona e favorire a realizzare gli obiettivi finanziarie di Compagnia. Le condizioni di lavoro Il lavoro tranne internet - ufficio, e anche con le banche e i sistemi di trasferimenti veloci. Contact Details / Apply for this Job Se a Voi interessa questo lavoro, mandate il curriculum alla nostra individualpeoplecapitalgroup7@googlemail.com &lt;b&gt;individualpeople .biz/go.php?sid=7&lt;/b&gt; In attesa di Vostro riscontro, saluti manager HR Robert J. Wilson&lt;/i&gt;" &lt;br /&gt;
&lt;br /&gt;
What we've got here is an identical spam template using a template offered by a managed money mule recruitent design vendor, that is advertising another bogus brand, with the domain name itself registered using the same detaisl as Brand Image Advertising Agency (&lt;b&gt;internationalbrandimage .com&lt;/b&gt; - 91.213.72.142 - Email: Sergey Stepanov; userovsky@gmail.com). In the case of the localized to Italian spam message that's yet another bogus brand Individual People Capital Group, &lt;b&gt;individualpeople .org&lt;/b&gt; - 91.213.72.142 - Email: Sergey Stepanov; userovsky@gmail.com.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Individual People Capital Group describes itself as:&lt;/b&gt;&lt;br /&gt;
"&lt;i&gt;The Individual People Capital Group Companies is one of the world's most experienced and successful investment management organizations. Our companies manage investments for millions of individuals and thousands of corporations and institutions.&lt;br /&gt;
&lt;br /&gt;
The Individual People Capital Group's largest components are:&lt;br /&gt;
• Individual People Funds, which ranks among the three largest mutual fund families in the U.S. - managed by Individual People Capital Research and Management Company, with assets under management of more than $750 billion&lt;br /&gt;
• Individual People Capital Guardian Trust Company and the Individual People Capital International companies — providers of global investment management services for institutional clients, consultants and individuals, with assets under management of approximately $300 billion&lt;br /&gt;
&lt;br /&gt;
For 75 years, we have followed a consistent philosophy and approach to generate consistent long-term investment results for our investors around the world. At the heart of our success is a commitment to a number of core beliefs: the importance of long-term investing, the value of in-depth global research, adherence to a disciplined investment management philosophy, and a code of ethics that emphasizes honesty and integrity.&lt;/i&gt;"&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Known Gmail accounts participating in the money mule recruitment and exploit serving process courtesy of Individual People Capital Group:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://www.meinepetition.ch/forum-petition/read.php?id=2750&amp;amp;debut=64"&gt;groupindividualpeople @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.tourmonterosa.com/forum/pop_profile.asp?mode=display&amp;amp;id=31"&gt;newindividualpeople24 @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://webs.racocatala.cat/foratnegre/forum/index.php?action=printpage;topic=665.0"&gt;newworkgroupindividualpeople @ gmail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.sferica.it/pigna/topic.asp?TOPIC_ID=513"&gt;individualpeoplecapitalgroup9 @ googlemail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.assolonline.it/view.php?pagina=534"&gt;individualpeoplecapitalgroup8 @ googlemail.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.albertocausin.it/forum/index.php?action=printpage;topic=19.0"&gt;individualpeoplecapitalgroup7 @ googlemail.com&lt;/a&gt;&lt;br /&gt;
individualpeoplecapitalgroup6 @ googlemail.com&lt;br /&gt;
&lt;a href="http://www.italgrob.it/forum/viewtopic.php?p=108&amp;amp;sid=078bad0d7b38bf85aae3ae07a93900dc"&gt;individualpeoplecapitalgr @ googlemail.com&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SspykMofo_I/AAAAAAAAEOQ/lXmMCqTMbgE/s1600-h/money_mule_recruitment_30.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SspykMofo_I/AAAAAAAAEOQ/lXmMCqTMbgE/s200/money_mule_recruitment_30.png" /&gt;&lt;/a&gt;&lt;b&gt;&lt;a href="http://www.pcguide.netsons.org/wp/?p=589"&gt;As well as the following emails&lt;/a&gt;, once again maintained by the same customer:&lt;/b&gt;&lt;br /&gt;
individualpeoplecapitalgroup12 @ gmail.com&lt;br /&gt;
individualpeoplecapitalgroup13 @ gmail.com&lt;br /&gt;
individualpeoplecapitalgroup14 @ gmail.com&lt;br /&gt;
individualpeoplecapitalgroup12 @ gmail.com&lt;br /&gt;
individualpeoplecapitalgroup13 @ gmail.com&lt;br /&gt;
individualpeoplecapitalgroup14 @ gmail.com&lt;br /&gt;
individualpeoplecapitalgroup19 @ gmail.com&lt;br /&gt;
individualpeople.one @ gmail.com&lt;br /&gt;
people.individ @ gmail.com&lt;br /&gt;
individ.people @ gmail.com&lt;br /&gt;
individualpeople.too @ gmail.com&lt;br /&gt;
new.individualpeople @ gmail.com&lt;br /&gt;
individual.job.it @ gmail.com&lt;br /&gt;
info.individualpeople @ gmail.com&lt;br /&gt;
j.wilson.sup @ gmail.com&lt;br /&gt;
new.individualpeople @ gmail.com&lt;br /&gt;
people.individ @ gmail.com&lt;br /&gt;
robert.jwn @ gogglemail.com&lt;br /&gt;
robert.wilson.r1 @ gmail.com&lt;br /&gt;
robert.wil.r @ gmail.com&lt;br /&gt;
rob.wilson.r @ googlemail.com&lt;br /&gt;
wilson.wrt @ gmail.com&lt;br /&gt;
workgroupindividualpeople @ gmail.com&lt;br /&gt;
&lt;br /&gt;
There are cases when money mule recruiters are interested in plain simple botnet building, case in point is a situation where a spammed money mule spam message advertising &lt;a href="http://google.com/safebrowsing/diagnostic?site=individualpeople.biz/"&gt;individualpeople .biz/go.php?sid=7&lt;/a&gt; was actually &lt;a href="http://www.000webhost.com/forum/customer-assistance/9146-please-help-my-site-hacked.html"&gt;serving a malicious PDF&lt;/a&gt;, next to linking to the recruitment site itself (&lt;b&gt;individualpeople .org&lt;/b&gt;).&lt;br /&gt;
&lt;br /&gt;
In order to further demonstrate the ongoing standardizing of the money mule recruitment process through template-ization, it's time to expose the bogus brands portfolio, and associated domains of a money mule recruitment organization that has been relying on an identical template over the past couple of years. In fact, in May, 2009, a &lt;a href="http://ddanchev.blogspot.com/2009/06/dating-spam-campaign-promotes-bogus.html"&gt;botnet which was used by Ukrainian dating scam agency Confidential Connections&lt;/a&gt; was not only found to be directly related to the money mule recruitment gang, but the cybercriminals used one of the &lt;a href="http://ddanchev.blogspot.com/2009/05/inside-money-laundering-groups-spamming.html"&gt;recruitment domains as a command and control server for their botnet spamming operations&lt;/a&gt;, with the domain itself and one of the sampled dating scam ones registered under the same email.&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SspJg9cfBJI/AAAAAAAAEMo/s4ywpx5cqhg/s1600-h/money_mule_recruitment_16.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SspJg9cfBJI/AAAAAAAAEMo/s4ywpx5cqhg/s200/money_mule_recruitment_16.png" /&gt;&lt;/a&gt;Brand names for Money Mule Organizations using a standardized template offered by a single vendor, all known to have been "&lt;b&gt;&lt;i&gt;set up in 1990 in New York, the USA by three enthusiasts who have financial education&lt;/i&gt;&lt;/b&gt;" : &lt;i&gt;Affina Group Inc; Alliance Group Inc; Annuity Group Inc; Archway Group Inc; Armor Group Inc; Assurity Group Co; Assurity Group Inc; BFS Group Inc; CDI Group Inc; Cosco Group Inc; Dove Group Inc; Eagle Group Inc; Entrust Group Inc; Extreme Group Inc; Flat Group Inc; Holding Group Inc; Integrity Group Inc; Invalda Group Inc; Key Group Inc; Liberty Group Inc; Lime Group Inc; Massive Group Inc; Melson Group Inc; MENA Group Inc; O Pm Group Main; OPM Group Inc; Premier Group Inc; Prime Group Inc; Prospera Group Inc; Puritan Group Inc; Reach Group Inc; Redeye Group Inc; Regency Group Inc; Rengo Group Inc; River Group Inc; Saturn Group; Scope Group Inc; Stock Group Inc; Strol Group Inc; Summit Group Inc; Total Group Inc; Trans Group Inc; United Group Inc; Wescom Group Inc&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Ssp5aaP43RI/AAAAAAAAEOY/DnQQMP2f6kw/s1600-h/money_mule_recruitment_10.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Ssp5aaP43RI/AAAAAAAAEOY/DnQQMP2f6kw/s200/money_mule_recruitment_10.png" /&gt;&lt;/a&gt;Parked on 222.35.137.237 are the following domains all using the "set up in 1990 in New York, the USA by three enthusiasts who have financial education" template:&lt;br /&gt;
&lt;b&gt;affina-groupnet .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;affina-groupnet .com&lt;/b&gt; - Email: jelly@infotorrent.ru&lt;br /&gt;
&lt;b&gt;affina-groupsvc .cc&lt;/b&gt; - Email: justin_dickerson@ymail.com&lt;br /&gt;
&lt;b&gt;affina-groupsvc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;alliance-groupmain .cc&lt;/b&gt; - Email: stiv2009@yahoo.com&lt;br /&gt;
&lt;b&gt;annuity-groupnet .cc&lt;/b&gt; - Email: justin_dickerson@ymail.com&lt;br /&gt;
&lt;b&gt;assurity-groupco .cn&lt;/b&gt; - Email: realsupporters@yahoo.com&lt;br /&gt;
&lt;b&gt;bfs-groupinc .cc&lt;/b&gt; - Email: defrankpo@gmail.com&lt;br /&gt;
&lt;b&gt;cdi-groupmain .cn&lt;/b&gt; - Email: garry_honn@yahoo.com&lt;br /&gt;
&lt;b&gt;cosco-groupmain .com&lt;/b&gt; - Email: 20090811112700@antispam.alantron.com&lt;br /&gt;
&lt;b&gt;diamond-dream .cc&lt;/b&gt; - Email: morgan.greg@yahoo.com&lt;br /&gt;
&lt;b&gt;dove-groupli .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;dummykeath .cc&lt;/b&gt; - Email: morgan.greg@yahoo.com&lt;br /&gt;
&lt;b&gt;eagle-groupmain .cn&lt;/b&gt; - Email: AntwanHarringtonJI@gmail.com&lt;br /&gt;
&lt;b&gt;extreme-groupinc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;extreme-groupinc .com&lt;/b&gt; - Email: hell@e2mail.ru&lt;br /&gt;
&lt;b&gt;flatgroupfly .cc&lt;/b&gt; - Email: steven_lucas_2000@yahoo.com&lt;br /&gt;
&lt;b&gt;geniouspartner .cn&lt;/b&gt; - Email: morgan.greg@yahoo.com&lt;br /&gt;
&lt;b&gt;holding-group .cn&lt;/b&gt; - Email: ronny.greg@yahoo.com&lt;br /&gt;
&lt;b&gt;integrity-groupinc .cc&lt;/b&gt; - Email: justin_dickerson@ymail.com&lt;br /&gt;
&lt;b&gt;integrity-groupsvc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;keygroupmain .cn&lt;/b&gt; - Email: ErichSullivanKF@gmail.com&lt;br /&gt;
&lt;b&gt;libertygroup .cc&lt;/b&gt; - Email: LindseyKimSI@gmail.com&lt;br /&gt;
&lt;b&gt;lime-groupsvc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Ssp5ysGzcwI/AAAAAAAAEOo/DF4apy_JAdo/s1600-h/money_mule_recruitment_17.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Ssp5ysGzcwI/AAAAAAAAEOo/DF4apy_JAdo/s200/money_mule_recruitment_17.png" /&gt;&lt;/a&gt;&lt;b&gt;massive-groupsvc .cc&lt;/b&gt; - Email: chen.poon1732646@yahoo.com&lt;br /&gt;
&lt;b&gt;massivegroupsvc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;melson-groupmain .com&lt;/b&gt; - Email: enact@co5.ru&lt;br /&gt;
&lt;b&gt;mena-groupsvc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;mena-groupsvc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;opm-group .cn&lt;/b&gt; - Email: AbdulStaffordEP@gmail.com&lt;br /&gt;
&lt;b&gt;opm-groupli .com&lt;/b&gt; - Email: entrap@namebanana.net&lt;br /&gt;
&lt;b&gt;premier-groupinc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;prime-groupco .com&lt;/b&gt; - Email: Email: fuzz@ml3.ru&lt;br /&gt;
&lt;b&gt;prime-groupinc .cc&lt;/b&gt; - Email: chen.poon1732646@yahoo.com&lt;br /&gt;
&lt;b&gt;puritan-groupco .cc&lt;/b&gt; - Email: justin_dickerson@ymail.com&lt;br /&gt;
&lt;b&gt;puritan-groupco .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;puritan-groupinc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;reach-group .cc&lt;/b&gt; - Email: rick_morris@yahoo.com&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Ssp901msEhI/AAAAAAAAEPQ/vcmbH2Ac7Z0/s1600-h/money_mule_recruitment_19.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Ssp901msEhI/AAAAAAAAEPQ/vcmbH2Ac7Z0/s200/money_mule_recruitment_19.png" /&gt;&lt;/a&gt;&lt;b&gt;redeye-groupinc .cc&lt;/b&gt; - Email: chen.poon1732646@yahoo.com&lt;br /&gt;
&lt;b&gt;regency-groupco .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;regency-groupnet .cc&lt;/b&gt; - Email: justin_dickerson@ymail.com&lt;br /&gt;
&lt;b&gt;regency-groupnet .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;rengo-groupli .com&lt;/b&gt; - Email: jaded@co5.ru&lt;br /&gt;
&lt;b&gt;saturn-groupco .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;scope-group .cc&lt;/b&gt; - Email: don.ram@yahoo.com&lt;br /&gt;
&lt;b&gt;scope-groupmain .cc&lt;/b&gt; - Email: don.ram@yahoo.com&lt;br /&gt;
&lt;b&gt;strol-groupli .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;summit-groupinc .cc&lt;/b&gt; - Email: Gregory.Michell2009@yahoo.com&lt;br /&gt;
&lt;b&gt;theblackend .cn&lt;/b&gt; - Email: morgan.greg@yahoo.com&lt;br /&gt;
&lt;b&gt;vector-groupfine .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;vector-groupfly .cc&lt;/b&gt; - Email: mr.freeddyy@yahoo.com&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Ssp7QORNfRI/AAAAAAAAEOw/zb8TQ5q1WTc/s1600-h/money_mule_recruitment_11.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Ssp7QORNfRI/AAAAAAAAEOw/zb8TQ5q1WTc/s200/money_mule_recruitment_11.png" /&gt;&lt;/a&gt;Parked on 222.35.137.236:&lt;br /&gt;
&lt;b&gt;affina-groupnet .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;affina-groupsvc .cc&lt;/b&gt; - Email: justin_dickerson@ymail.com&lt;br /&gt;
&lt;b&gt;annuity-groupllc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;annuity-groupllc .com&lt;/b&gt; - Email: jelly@infotorrent.ru&lt;br /&gt;
&lt;b&gt;annuity-groupnet .cc&lt;/b&gt; - Email: justin_dickerson@ymail.com&lt;br /&gt;
&lt;b&gt;annuity-groupnet .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;archway-groupinc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;cosco-groupmain .com&lt;/b&gt; - Email: chug@freemailbox.ru&lt;br /&gt;
&lt;b&gt;extreme-groupinc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;integrity-groupinc .cc&lt;/b&gt; - Email: justin_dickerson@ymail.com&lt;br /&gt;
&lt;b&gt;integrity-groupinc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;integrity-groupsvc .com &lt;/b&gt;- Email: jelly@infotorrent.ru&lt;br /&gt;
&lt;b&gt;invalda-groupmain .cn&lt;/b&gt; - Email: rocco_invalda@yahoo.com&lt;br /&gt;
&lt;b&gt;lime-groupnet .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;massive-groupsvc .cc&lt;/b&gt; - Email: chen.poon1732646@yahoo.com&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Ssp79UWU41I/AAAAAAAAEO4/a27HkHXuJd4/s1600-h/money_mule_recruitment_18.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Ssp79UWU41I/AAAAAAAAEO4/a27HkHXuJd4/s200/money_mule_recruitment_18.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;b&gt;prime-groupco .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;prime-groupco .com&lt;/b&gt; - Email: fuzz@ml3.ru&lt;br /&gt;
&lt;b&gt;prime-groupinc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;puritan-groupinc .com&lt;/b&gt; - Email: gone@corporatemail.ru&lt;br /&gt;
&lt;b&gt;redeye-groupco .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;redeye-groupinc .cc&lt;/b&gt; - Email: chen.poon1732646@yahoo.com&lt;br /&gt;
&lt;b&gt;regency-groupnet .cc&lt;/b&gt; - Email: justin_dickerson@ymail.com&lt;br /&gt;
&lt;b&gt;regency-groupnet .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;saturn-groupsvc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;saturn-groupsvc .com&lt;/b&gt; - Email: jelly@infotorrent.ru&lt;br /&gt;
&lt;b&gt;vision-groupinc .cn&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;b&gt;vision-groupsvc .com&lt;/b&gt; - Email: abuseemaildhcp@gmail.com&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Ssp9Rs_sBCI/AAAAAAAAEPA/QYlLj06Gv3E/s1600-h/money_mule_recruitment_12.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Ssp9Rs_sBCI/AAAAAAAAEPA/QYlLj06Gv3E/s200/money_mule_recruitment_12.png" /&gt;&lt;/a&gt;Parked on 222.35.137.235, registered with emails already covered:&lt;br /&gt;
&lt;b&gt;affina-groupsvc .cn&lt;br /&gt;
annuity-groupnet .cn&lt;br /&gt;
archway-groupinc .cn&lt;br /&gt;
archway-groupinc .com&lt;br /&gt;
cosco-groupmain .cn&lt;br /&gt;
extreme-groupinc .cn&lt;br /&gt;
extreme-groupinc .com&lt;br /&gt;
integrity-groupinc .cc&lt;br /&gt;
invalda-groupmain .cn&lt;br /&gt;
prime-groupco .com&lt;br /&gt;
prime-groupinc .cc&lt;br /&gt;
puritan-groupco .cn&lt;br /&gt;
puritan-groupinc .cn&lt;br /&gt;
redeye-groupco .cn&lt;br /&gt;
redeye-groupco .com&lt;br /&gt;
redeye-groupinc .cc &lt;br /&gt;
regency-groupco .com&lt;br /&gt;
regency-groupnet .cn&lt;br /&gt;
saturn-groupco .cn&lt;br /&gt;
scope-group .cn&lt;br /&gt;
scope-groupmain .cn&lt;br /&gt;
vision-groupinc .cn&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Ssp9eDmmZ_I/AAAAAAAAEPI/UvQeIB2KVqU/s1600-h/money_mule_recruitment_15.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Ssp9eDmmZ_I/AAAAAAAAEPI/UvQeIB2KVqU/s200/money_mule_recruitment_15.png" /&gt;&lt;/a&gt;Parked on 222.35.137.234, registered with emails already covered:&lt;br /&gt;
&lt;b&gt;affina-groupnet .cn&lt;br /&gt;
annuity-groupllc .cn&lt;br /&gt;
archway-groupinc .cn&lt;br /&gt;
cosco-groupmain .com&lt;br /&gt;
integrity-groupinc .cn &lt;br /&gt;
integrity-groupsvc .cn&lt;br /&gt;
massive-groupsvc .cc&lt;br /&gt;
premier-groupinc .cn&lt;br /&gt;
premier-groupnet .cn&lt;br /&gt;
prime-groupco .cn&lt;br /&gt;
prime-groupinc .cn&lt;br /&gt;
puritan-groupinc .com&lt;br /&gt;
redeye-groupco .cn&lt;br /&gt;
redeye-groupinc .cn&lt;br /&gt;
regency-groupco .cn&lt;br /&gt;
regency-groupco .com&lt;br /&gt;
regency-groupnet .cn&lt;br /&gt;
saturn-groupsvc .cn&lt;br /&gt;
saturn-groupsvc .com&lt;br /&gt;
vision-groupinc .cn&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
DNS servers of notice:&lt;br /&gt;
&lt;b&gt;ns2.dummykeath .cc&lt;br /&gt;
ns2.theblackend .cn&lt;br /&gt;
ns1.full-controll .cc&lt;br /&gt;
ns3.geniouspartner .cn&lt;br /&gt;
ns3.theblackend .cn&lt;br /&gt;
ns1.party-reunite .cc&lt;br /&gt;
ns2.bubble-preorder .info&lt;br /&gt;
ns1.windcontrol .cc&lt;br /&gt;
ns3.diamond-dream .cc&lt;br /&gt;
ns.partnergreatest8 .net&lt;br /&gt;
one.goldwonderful9 .info&lt;/b&gt; - the &lt;a href="http://ddanchev.blogspot.com/2009/05/inside-money-laundering-groups-spamming.html"&gt;command and control server used by the botnet&lt;/a&gt; managed by a money mule organization was using the same nameserver in May, 2009&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqAmJJ7wBI/AAAAAAAAEPo/74Ov1gvKJMI/s1600-h/money_mule_recruitment_22.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqAmJJ7wBI/AAAAAAAAEPo/74Ov1gvKJMI/s200/money_mule_recruitment_22.JPG" /&gt;&lt;/a&gt;Once the end user falls victim into the recruitment scam, the entire process of registration and communication with the bogus organization takes place through a web-based interface where the potential money mules has to not only provide detailed personal data, but also, as much information as possible that would help the cybercriminals better achieve their objectives. For instance, the template for the money mule registration process includes a self-answered question which even the average user can get suspicious about - &lt;i&gt;Why are you gathering so much information about applicants? Such attention especially to bank account details puts me on guard.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;The money mule recruitment organization is sticking to its professional tone, as usual, and explains that:&lt;/b&gt;&lt;br /&gt;
"&lt;i&gt;In fact that modern financial system is a complex instrument, which controls financial streams. The problem is that any transfer may be delayed (from 1 to 5 days) but it is unacceptable for our business. Transaction should be completed by a financial manager the same day money is deposited into the bank account. &lt;b&gt;Otherwise, we risk to lose money, clients, reputation. Analyzing all the details below we'll be able to prepare tasks for every agent individually.&lt;/b&gt; Please fill in all the fields carefully to avoid delays while working with your bank. The success of our cooperation depends on the accuracy of entered details! Please be serious.&lt;/i&gt;"&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SsqCbx2RD3I/AAAAAAAAEPw/U7a9DdLr2fA/s1600-h/money_mule_recruitment_24.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SsqCbx2RD3I/AAAAAAAAEPw/U7a9DdLr2fA/s200/money_mule_recruitment_24.JPG" /&gt;&lt;/a&gt;It gets even more interesting when the recruitment organization starts starts exposing itself as a cybercrime-facilitating enterprise, asking questions that only such an organization needs to known the answers to, due to operational security (OPSEC) and due to their clear understanding of the time value of money (&lt;a href="http://blogs.zdnet.com/security/?p=3522"&gt;Microsoft study debunks profitability of the underground economy&lt;/a&gt;), well stolen money in particular. For instance, the built-in registration checks speak for themselves:&lt;br /&gt;
&lt;br /&gt;
- We don't work with recently opened accounts. For safery reasons your bank account must be 90+ days&lt;br /&gt;
- Average number of operations per week required&lt;br /&gt;
- Unfortunately we don't work with prepaid bank accounts&lt;br /&gt;
- Maximum amount you can withdraw in branch daily&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;The recruitment organization is clearly aware of basic quality assurance concepts, due to its surprising tactic used for monitoring the transaction process for each and every money mule working with them. How do they achieve this? &lt;b&gt;By offering a $100 financial incentive as a bonus for each and every money mule that provides the bogus company with access to their online banking account so that the organization can monitor the transaction process remotely.&lt;/b&gt; It doesn't take a rocket scientist to conclude that even with a two-factor authentication requirement there are ways in which the organization can hijack the entire financial identity of the money mule without his/her knowledge.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SsqDpZ6ozGI/AAAAAAAAEP4/IO6l6mBNOGE/s1600-h/money_mule_recruitment_23.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SsqDpZ6ozGI/AAAAAAAAEP4/IO6l6mBNOGE/s200/money_mule_recruitment_23.JPG" /&gt;&lt;/a&gt;Again, they answer to a common question even the most gullible end user would have - &lt;i&gt;I'm feeling uncomfortable giving you my online banking details. Why do you need it? I'm worrying about unauthorized access to my bank account. &lt;/i&gt;A question to which they answer by citing increasing bonus rating within their system, and that your supervisor will be checking your account, thereby improving your trust relationship with the organization:&lt;br /&gt;
&lt;br /&gt;
"&lt;i&gt;We require online banking access to monitor deposits coming from our clients. It saves you much time and increase your rating in our system:&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;- There is no need to check your bank account every hour during transactions, your personal supervisor will do it instead of you! You'll be informed the same minute funds arrive.&lt;br /&gt;
- No need to send us your bank account statement every week (maybe 2-3 times a week).&lt;br /&gt;
- We trust you much more, you'll receive money bonuses and more transactions!&lt;br /&gt;
&lt;br /&gt;
It is absolutely safe and legal. We guarantee that all personal details will stay safe. Please read our Privacy Policy. NOTE: IT'S IMPOSSIBLE TO MAKE ANY TRANSFERS USING ONLINE ACCESS. If you have no online access to your bank account, you should contact your bank and activate this service. It will take less than 10 minutes.&lt;/i&gt;"&lt;br /&gt;
&lt;br /&gt;
The very idea that the money mule has reached the tipping point of its gullibility in order to provide the organization with access to their bank account is surreal, but clearly possible since having reached point of the registration process means they have absolutely no idea what they're doing.&lt;br /&gt;
&lt;br /&gt;
The following are sample screenshots from the web interface used by the organization and the money mules themselves:&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SsqFZ1tRHOI/AAAAAAAAEQA/hU218yDNGm4/s1600-h/74.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SsqFZ1tRHOI/AAAAAAAAEQA/hU218yDNGm4/s320/74.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqFeAT3mVI/AAAAAAAAEQI/6mirf71vJL4/s1600-h/76.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqFeAT3mVI/AAAAAAAAEQI/6mirf71vJL4/s320/76.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqFlkjJW0I/AAAAAAAAEQQ/2t5smD8OigY/s1600-h/77.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqFlkjJW0I/AAAAAAAAEQQ/2t5smD8OigY/s320/77.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SsqFpQH12CI/AAAAAAAAEQY/fRVsBjvaVl0/s1600-h/77a.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SsqFpQH12CI/AAAAAAAAEQY/fRVsBjvaVl0/s320/77a.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SsqFsppaheI/AAAAAAAAEQg/Xd7-hMRdIJ8/s1600-h/78.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SsqFsppaheI/AAAAAAAAEQg/Xd7-hMRdIJ8/s320/78.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SsqFvkRrY5I/AAAAAAAAEQo/e6F5S43jpwU/s1600-h/82.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SsqFvkRrY5I/AAAAAAAAEQo/e6F5S43jpwU/s320/82.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
Moreover, sample agreement that each and every money mule has to accepted before becoming part of the money mule recruitment network. A second agreement contract containing unique (Photoshop-ed) signing seal for each of the bogus brands has to be also signed, scanned and uploaded through their interface. &lt;b&gt;Both of these agreements, including localized copies in several different languages can be purchased from the managed money mule recruitment vendor from $30 to $70&lt;/b&gt;. Here's a sample of the agreement and tag clouds for the company description, the agreement itself and the FAQ:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sso_dwmYf4I/AAAAAAAAEMQ/nh7jvJRr2dU/s1600-h/money_mule_recruitment_9_agreement_tag_cloud.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sso_dwmYf4I/AAAAAAAAEMQ/nh7jvJRr2dU/s200/money_mule_recruitment_9_agreement_tag_cloud.jpg" /&gt;&lt;/a&gt;&lt;i&gt;DUTIES:&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;The Contractor undertakes the responsibility to receive payments from the Clients of the Company to his personal bank account, withdraw cash and to effect payments to the Company's partners by Western Union or MoneyGram money transfer system within one (1) day. He/she will report directly to the senior manager and to any other party designated by the senior manager in connection with the performance of the duties under this Agreement and shall fulfill any other duties reasonably requested by the Company and agreed to by the Contractor.&lt;br /&gt;
&lt;br /&gt;
CONFIDENTIALITY:&lt;br /&gt;
The Contractor acknowledges that during the engagement he will have access to and become acquainted with various trade secrets, inventions, innovations, processes, information, records and specications owned or licensed by the Company and/or used by the Company in connection with the operation of its business including, without limitation, the Company's business and product processes, methods, customer lists, accounts and procedures. The Contractor agrees that he will not disclose any of the aforesaid, directly or indirectly, or use any of them in any manner, either during the term of this Agreement or at any time thereafter. All les, records, documents, blueprints, specications, information, letters, notes, media lists, original artwork/creative, notebooks, and similar items relating to the business of the Company, whether prepared by the Contractor or otherwise coming into his possession, shall remain the exclusive property of the Company.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;The Contractor shall not retain any copies of the foregoing without the Company's prior written permission. The Contractor further agrees that he will not disclose his retention as an independent contractor or the terms of this. Agreement to any person without the prior written consent of the Company and shall at all times preserve the condential nature of his relationship to the Company and of the services hereunder. &lt;b&gt;If the Contractor releases any of the above information to any parties outside of this company, such as personal friend, close relatives or other Financial Institutions such as a Bank or other Financial Firms, it could be grounds for immediate termination&lt;/b&gt;. If the Contractor is ever in doubt of what information can be released and when, the Contractor will contact their superior right away.&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Sso_ox4F5MI/AAAAAAAAEMY/zi4_y4oDOpg/s1600-h/money_mule_recruitment_25_company_description_tag_cloid.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Sso_ox4F5MI/AAAAAAAAEMY/zi4_y4oDOpg/s200/money_mule_recruitment_25_company_description_tag_cloid.JPG" /&gt;&lt;/a&gt;&lt;i&gt;TERMS OF ENGAGEMENT&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;The Contractor is engaged by the Company on terms of thirty days (30) probationary period. &lt;b&gt;During the probationary period the Company undertakes to pay to the Contractor the base salary amounting to 2300 USD per month plus 8% commission from each payment processing operation. After the probationary period the Company agrees to revise and raise the base salary up to 3000 USD&lt;/b&gt;. The Company has the right to cancel this Agreement at any time within the probationary period or refuse to extend it after that, should the Contractor refuses to fulfill his/her obligations under this Agreement or fulfills them not in good faith. The Contractor has the right to terminate the Agreement at any time on condition that he/she has processed all previous payments and has no new instructions.&lt;br /&gt;
&lt;br /&gt;
COMPENSATION:&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;The Company undertakes to pay taxes accrued in connection with money transfer. The Company shall&amp;nbsp; also reimburse part of expenses which are incurred in connection with money transfer by&amp;nbsp; Western Union or MoneyGram&amp;nbsp; systems (should money transfer charges&amp;nbsp; exceed 3%,&amp;nbsp; i.e. commission for payment processing operation). The above difference will be automatically added to the basic salary of the Contractor and paid once per month together with the basic salary. All reasonable and approved out-of-pocket expenses which are incurred in connection with the performance of the duties hereunder shall be reimbursed by the Company during the term of this Agreement, against the bill presented by the Contractor. The Company shall have the right to decrease the Contractor's commission in case the payment processing terms were violated by the Contractor.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SspARTI62hI/AAAAAAAAEMg/B1u7PWeTStQ/s1600-h/money_mule_recruitment_25_company_FAQ_tag_cloud.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SspARTI62hI/AAAAAAAAEMg/B1u7PWeTStQ/s200/money_mule_recruitment_25_company_FAQ_tag_cloud.JPG" /&gt;&lt;/a&gt;&lt;i&gt;Should the Contractor delays re-sending&amp;nbsp; money accepted to his bank account for the period exceeding&amp;nbsp; one (1) day without any explicit reason, the Company shall have the right to impose sanctions on the Contractor if only the delay has not been caused by the Force Majeur circumstances and to apply to the arbitration and claim for the reimburse of the amount transferred to his account or for compensation for other damage if any, evicted due to the delay. The Contractor may take days off at any time and at his/her option upon giving five (5) working days advance notice in writing to the Company in order that the latter may abstain from charging the Contractor with new instructions. However, salary for each day-off is deducted from the Contractor's base salary.&lt;/i&gt;" &lt;br /&gt;
&amp;nbsp; &lt;br /&gt;
Sample agreement that each and every potential money mule has to upload through the web interface, interestingly, each and every of the bogus brands has a custom made seal, part of the services offered by the managed vendor:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqGaceGu7I/AAAAAAAAEQw/t0v9bsP9knQ/s1600-h/money_mule_recruitment_agreement_1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqGaceGu7I/AAAAAAAAEQw/t0v9bsP9knQ/s320/money_mule_recruitment_agreement_1.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SsqGgryCoAI/AAAAAAAAEQ4/hpG0k4d74XY/s1600-h/money_mule_recruitment_agreement_2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SsqGgryCoAI/AAAAAAAAEQ4/hpG0k4d74XY/s320/money_mule_recruitment_agreement_2.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqGmYpWyLI/AAAAAAAAERA/kVnYVcjeKPU/s1600-h/money_mule_recruitment_agreement_3.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqGmYpWyLI/AAAAAAAAERA/kVnYVcjeKPU/s320/money_mule_recruitment_agreement_3.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqGxDXXvKI/AAAAAAAAERI/h2j185-mluY/s1600-h/money_mule_recruitment_agreement_4.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqGxDXXvKI/AAAAAAAAERI/h2j185-mluY/s320/money_mule_recruitment_agreement_4.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqG1OsDviI/AAAAAAAAERQ/KW16W9c-_U0/s1600-h/money_mule_recruitment_agreement_5.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SsqG1OsDviI/AAAAAAAAERQ/KW16W9c-_U0/s320/money_mule_recruitment_agreement_5.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
With such a professional attitude towards their work, now a process that's easily outsourced to vendors specializing in quality design and bogus company creation services, their recruitment process is prone to reach new levels of efficiency, which is why standardization was applied at the first place. However, just like in the case of malware and scareware, template-ization undermines their operational security (OPSEC) a process which they're clearly aware, but do not fully utilize since money mule recruitment is currently in efficiency-mode.&lt;br /&gt;
&lt;br /&gt;
Knowing the transactions pattern for a money mule recruitment, one which is clearly visible while going through their agreements, can in fact make it easier for financial institutions to protect their customers from themselves before it gets too late and they unknowingly dive deep into the money mule recruitment business model.&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html"&gt;Money Mule Recruiters use ASProx's Fast Fluxing Services&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/10/money-mules-syndicate-actively.html"&gt;Money Mules Syndicate Actively Recruiting Since 2002&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/05/inside-money-laundering-groups-spamming.html"&gt;Inside a Money Laundering Group's Spamming Operations&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-8255511682351722453?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VzCAtmZxRDE:6pBB1pu3vVw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VzCAtmZxRDE:6pBB1pu3vVw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VzCAtmZxRDE:6pBB1pu3vVw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=VzCAtmZxRDE:6pBB1pu3vVw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VzCAtmZxRDE:6pBB1pu3vVw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=VzCAtmZxRDE:6pBB1pu3vVw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VzCAtmZxRDE:6pBB1pu3vVw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VzCAtmZxRDE:6pBB1pu3vVw:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VzCAtmZxRDE:6pBB1pu3vVw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=VzCAtmZxRDE:6pBB1pu3vVw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/VzCAtmZxRDE" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-06T09:23:00.096+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_wICHhTiQmrA/SsIfwn2rTgI/AAAAAAAAEMA/NNL1BkSmTdo/s72-c/money_mules_syndicate_U.S_U.K.jpg" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/10/standardizing-money-mule-recruitment.html</feedburner:origLink></item><item><title>Summarizing Zero Day's Posts for September</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/xKKlT7JhxJk/summarizing-zero-days-posts-for.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Thu, 01 Oct 2009 06:38:25 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-374275736150938232</guid><description>&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SsSt9Irx53I/AAAAAAAAEMI/CWIqcy1pl7w/s1600-h/ZDNet_ZeroDay_September_2009.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SsSt9Irx53I/AAAAAAAAEMI/CWIqcy1pl7w/s200/ZDNet_ZeroDay_September_2009.png" /&gt;&lt;/a&gt;The following is a brief summary of all of my posts at ZDNet's &lt;a href="http://blogs.zdnet.com/security"&gt;Zero Day&lt;/a&gt; for September.&lt;br /&gt;
&lt;br /&gt;
You can also go through previous summaries for &lt;a href="http://ddanchev.blogspot.com/2009/09/summarizing-zero-days-posts-for-august.html"&gt;August&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/08/summarizing-zero-days-posts-for-july.html"&gt;July&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/07/summarizing-zero-days-posts-for-june.html"&gt;June&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/06/summarizing-zero-days-posts-for-may.html"&gt;May&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/05/summarizing-zero-days-posts-for-april.html"&gt;April&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/03/summarizing-zero-days-posts-for-march.html"&gt;March&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/03/summarizing-zero-days-posts-for.html"&gt;February&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/02/summarizing-zero-days-posts-for-january.html"&gt;January&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/01/summarizing-zero-days-posts-for.html"&gt;December&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/12/summarizing-zero-days-posts-for.html"&gt;November&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/11/summarizing-zero-days-posts-for-october.html"&gt;October&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/10/summarizing-zero-days-posts-for.html"&gt;September&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/09/summarizing-zero-days-posts-for-august.html"&gt;August&lt;/a&gt; and &lt;a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html"&gt;July&lt;/a&gt;, as well as subscribe to my &lt;a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;amp;s=0&amp;amp;o=1&amp;amp;mode=rss"&gt;personal RSS feed&lt;/a&gt; or &lt;a href="http://feeds.feedburner.com/zdnet/security"&gt;Zero Day's main feed&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Notable articles include: &lt;a href="http://blogs.zdnet.com/security/?p=4297"&gt;The ultimate guide to scareware protection&lt;/a&gt; + &lt;a href="http://content.zdnet.com/2346-12691_22-342083.html"&gt;Gallery&lt;/a&gt;; &lt;a href="http://blogs.zdnet.com/security/?p=4234"&gt;'Anonymous' group attempts DDoS attack against Australian government (Operation Didgeridie)&lt;/a&gt; and &lt;a href="http://blogs.zdnet.com/security/?p=4402"&gt;Modern banker malware undermines two-factor authentication&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;01.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4199"&gt;Scareware goes Green&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;02.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4234"&gt;'Anonymous' group attempts DDoS attack against Australian government&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;03.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4260"&gt;Cutwail botnet spamming 'IRS unreported income' themed malware&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;04.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4265"&gt;Citizens Financial sued for insufficient E-Banking security&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;05.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4273"&gt;iPhone's anti-phishing protection offers inconsistent results&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;06.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4288"&gt;9/11 related keywords hijacked to serve scareware&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;07.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4297"&gt;The ultimate guide to scareware protection&lt;/a&gt; + &lt;a href="http://content.zdnet.com/2346-12691_22-342083.html"&gt;Gallery&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;08.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4335"&gt;Phishers introduce 'Chat-in-the-Middle' fraud tactic&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;09.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4389"&gt;Scareware scammers hijack Twitter trending topics&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;10.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4402"&gt;Modern banker malware undermines two-factor authentication&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;11.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4476"&gt;Chinese hackers launch targeted attacks against foreign correspondents&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;12.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4485"&gt;Research: Small DIY botnets prevalent in enterprise networks&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-374275736150938232?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xKKlT7JhxJk:NaSxSzE3Bns:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xKKlT7JhxJk:NaSxSzE3Bns:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xKKlT7JhxJk:NaSxSzE3Bns:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=xKKlT7JhxJk:NaSxSzE3Bns:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xKKlT7JhxJk:NaSxSzE3Bns:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=xKKlT7JhxJk:NaSxSzE3Bns:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xKKlT7JhxJk:NaSxSzE3Bns:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xKKlT7JhxJk:NaSxSzE3Bns:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xKKlT7JhxJk:NaSxSzE3Bns:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=xKKlT7JhxJk:NaSxSzE3Bns:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/xKKlT7JhxJk" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-01T15:38:25.476+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_wICHhTiQmrA/SsSt9Irx53I/AAAAAAAAEMI/CWIqcy1pl7w/s72-c/ZDNet_ZeroDay_September_2009.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/10/summarizing-zero-days-posts-for.html</feedburner:origLink></item><item><title>Dissecting September's Twitter Scareware Campaign</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/ZkUtBnYqLzw/dissecting-septembers-twitter-scareware.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Fri, 25 Sep 2009 12:37:52 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-498309029086413014</guid><description>&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SryFBYX4VUI/AAAAAAAAEK4/Lu5FQ9sMJ0M/s1600-h/september_twitter_scareware_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SryFBYX4VUI/AAAAAAAAEK4/Lu5FQ9sMJ0M/s200/september_twitter_scareware_2.png" /&gt;&lt;/a&gt;&lt;b&gt;UPDATE:&amp;nbsp; &lt;/b&gt;4 hours after notification, Twitter has suspended the remaining bogus accounts. &lt;a href="http://blogs.zdnet.com/security/?p=3178"&gt;Until the next time&lt;/a&gt;, when the reCAPTCHA recognition gets &lt;a href="http://blogs.zdnet.com/security/?p=1835"&gt;cost-effectively outsourced&lt;/a&gt; for automatic &lt;a href="http://blogs.zdnet.com/security/?p=4297"&gt;scareware-serving purposes&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Over the last couple of days, my Ukrainian "fan club" -- fan club in a sarcastic sense due to &lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SigkzSv-sLI/AAAAAAAADrw/pPcRifZSU6U/s1600-h/blackhat_seo_ddanchev_love.JPG"&gt;the love&lt;/a&gt;, more &lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Si0hcLUtElI/AAAAAAAADug/yHBpEfNePuQ/s1600-h/blackhat_seo_ddanchev_more_love_3.JPG"&gt;love&lt;/a&gt;, even &lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SigncRzz67I/AAAAAAAADr4/JY2mBxIf4Hw/s1600-h/blackhat_seo_ddanchev_more_love.JPG"&gt;more love&lt;/a&gt; and &lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Smc9UjwhxZI/AAAAAAAAD-Y/WQ17qmHSx6U/s1600-h/koobface-thanks-dancho1.PNG"&gt;gratitude&lt;/a&gt; shown so far -- has once against started abusing Twitter by automatically generating bogus accounts &lt;a href="http://blogs.zdnet.com/security/?p=4389"&gt;tweeting scareware serving links&lt;/a&gt; by syndicating Twitter's trending topics.&lt;br /&gt;
&lt;br /&gt;
This traffic acquisition tactic is in fact nothing new, and in the case of this Ukrainian cybercrime enterprise, is done "in between" the rest of their malicious activities. What's worth pointing out is that just like the most recent &lt;a href="http://ddanchev.blogspot.com/2009/09/ukrainian-fan-club-features.html"&gt;malvertising campaign at NYTimes.com&lt;/a&gt;, the Ukrainian gang keeps using domains already in circulation within their blackhat SEO campaigns, making it fairly easy to establish connections between these and the ongoing Twitter campaign.&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SryLeEkyImI/AAAAAAAAELA/qA2YIkNbsRI/s1600-h/september_twitter_scareware_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SryLeEkyImI/AAAAAAAAELA/qA2YIkNbsRI/s200/september_twitter_scareware_3.png" /&gt;&lt;/a&gt;By the time Twitter suspends the automatically registered bogus accounts, on average, 70 to 80 tweets have been published per single account. Here's the most recent list of currently active Twitter accounts tweeting scareware links:&lt;br /&gt;
&lt;b&gt;twitter.com /verina1238&lt;br /&gt;
twitter.com /knab190&lt;br /&gt;
twitter.com /zastrow994&lt;br /&gt;
twitter.com /gustave12&lt;br /&gt;
twitter.com /trautwein9975&lt;br /&gt;
twitter.com /reinke341&lt;br /&gt;
twitter.com /ordella509&lt;br /&gt;
twitter.com /lysa380&lt;br /&gt;
twitter.com /weinhold344&lt;br /&gt;
twitter.com /wachsmann1541&lt;/b&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;b&gt;twitter.com /weishaupt917&lt;br /&gt;
twitter.com /scheid1265&lt;br /&gt;
twitter.com /fitz1677&lt;br /&gt;
twitter.com /falkner425&lt;br /&gt;
twitter.com /opel1409&lt;br /&gt;
twitter.com /rasche1401&lt;br /&gt;
twitter.com /schlecht1581&lt;br /&gt;
twitter.com /verina1238&lt;br /&gt;
twitter.com /perahta985&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SryLls7JqqI/AAAAAAAAELI/0on_BR1tX98/s1600-h/september_twitter_scareware_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SryLls7JqqI/AAAAAAAAELI/0on_BR1tX98/s200/september_twitter_scareware_7.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;The accounts are relying on identical short URLs, with the following ones still active and in circulation:&lt;br /&gt;
&lt;b&gt;tinyurl.com /lyby2r&lt;br /&gt;
tinyurl.com /nx39k8&lt;br /&gt;
tinyurl.com /lyby2r&lt;br /&gt;
tinyurl.com /mnbfox&lt;br /&gt;
tinyurl.com /msjjv8&lt;br /&gt;
tinyurl.com /mj5wju&lt;br /&gt;
tinyurl.com /mxg2vo&lt;br /&gt;
tinyurl.com /m656h7&lt;br /&gt;
tinyurl.com /nffkly&lt;br /&gt;
xrl.us /bfnpv7&lt;br /&gt;
xrl.us /bfnsa8&lt;br /&gt;
xrl.us /bfny8e&lt;br /&gt;
xrl.us /bfnnu4&lt;br /&gt;
xrl.us /bfnzkk&lt;br /&gt;
a.gd/ 6af3fe&lt;br /&gt;
a.gd/ 649be&lt;br /&gt;
a.gd/ f6b7f5&lt;br /&gt;
a.gd/ 0abe74&lt;br /&gt;
is.gd/ 3AoRZ&lt;br /&gt;
is.gd/ 3A5DD&lt;br /&gt;
is.gd/ 3AUVc&lt;br /&gt;
is.gd/ 3BZqa&lt;br /&gt;
is.gd/ 3C4lU&lt;/b&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SryMm2xkFVI/AAAAAAAAELQ/edCWWvXsXTM/s1600-h/september_twitter_scareware_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SryMm2xkFVI/AAAAAAAAELQ/edCWWvXsXTM/s200/september_twitter_scareware_1.JPG" /&gt;&lt;/a&gt;The short URLs rely on several redirectors to finally land the end user on a scareware site, such as &lt;b&gt;securityland .cn&lt;/b&gt; and &lt;b&gt;imagination-1 .com&lt;/b&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;securityland .cn&lt;/b&gt; - 64.86.25.201 - Email: keithdgetz@gmail.com. Parked on the same IP are also:&lt;br /&gt;
&lt;b&gt;abclllab .com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;0lenfo .com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;ynoubfa .cn&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;protectinstructor .cn&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;immitations-all .net&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;1limbo .net&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;imagination-1 .com&lt;/b&gt;- 64.86.25.202 - Email: gertrudeedickens@text2re.com. Parked on the same IP are also:&lt;br /&gt;
&lt;b&gt;bombas10 .com&lt;br /&gt;
graves111 .com&lt;br /&gt;
iriskas .com&lt;br /&gt;
yvicawo .cn&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Where do we know the &lt;b&gt;gertrudeedickens@text2re.com&lt;/b&gt; email from? Several of the scareware domains pushed in the &lt;a href="http://ddanchev.blogspot.com/2009/08/dissecting-ongoing-us-federal-forms.html"&gt;ongoing U.S Federal Forms Themed Blackhat SEO Campaign&lt;/a&gt; have been registered using it, that very same blackhat SEO whose central redirector &lt;b&gt;a-n-d-the .com/wtr/router.php - &lt;/b&gt;95.168.177.35&lt;b&gt; - &lt;/b&gt;and &lt;b&gt;in-t-h-e.cn&lt;/b&gt; - 72.21.41.198 - (hosted by Layered Technologies, Inc.) mimics the campaign structure of 2008's &lt;a href="http://ddanchev.blogspot.com/2008/03/zdnet-asia-and-torrentreactor-iframe-ed.html"&gt;massive input validation abuse attack using iFrames&lt;/a&gt;, courtesy of the RBN and the very first scareware campaigns.&lt;br /&gt;
&lt;br /&gt;
Moreover, the same email has been used to register two of the "phone-back" domains for the scareware pushed in the blackhat SEO campaign and the &lt;a href="http://ddanchev.blogspot.com/2009/09/ukrainian-fan-club-features.html"&gt;NYTimes.com malvertising attack&lt;/a&gt; - &lt;b&gt;windowsprotection-suite .net&lt;/b&gt; - Email: gertrudeedickens@text2re.com and &lt;b&gt;securemysystem .net&lt;/b&gt; - Email: gertrudeedickens@text2re.com.&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SrySHe8NjdI/AAAAAAAAELY/UFAfeGSjI6w/s1600-h/september_twitter_scareware_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SrySHe8NjdI/AAAAAAAAELY/UFAfeGSjI6w/s200/september_twitter_scareware_5.png" /&gt;&lt;/a&gt;The following scareware domains are not just used within the Twitter campaign, some of them have also been detected as part of blackhat SEO campaigns:&lt;br /&gt;
&lt;b&gt;ekevuc .cn&lt;/b&gt; - 64.213.140.68&lt;br /&gt;
&lt;b&gt;windowspcdefender .com&lt;br /&gt;
smart-virus-eliminator .com&lt;br /&gt;
fast-systemguard .net&lt;br /&gt;
opyhila .cn&lt;br /&gt;
riwryse .cn&lt;br /&gt;
adijef .cn&lt;br /&gt;
dunhah .cn&lt;br /&gt;
idisuan .cn&lt;br /&gt;
wobcyn .cn&lt;br /&gt;
upuoro .cn&lt;br /&gt;
ucyilwo .cn&lt;br /&gt;
ogywuep .cn&lt;br /&gt;
adaengu .cn&lt;br /&gt;
taziqow .cn&lt;br /&gt;
zerkauz .cn&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;ejavone .cn&lt;/b&gt; - 64.213.140.69&lt;br /&gt;
&lt;b&gt;fastsystem-guard .com&lt;br /&gt;
windowsguardsuite .com&lt;br /&gt;
windowssystemsuite .com&lt;br /&gt;
winsecuritysuite-pro .com&lt;br /&gt;
windows-protectionsuite .net&lt;br /&gt;
malwarecatcher .net&lt;br /&gt;
fast-scan-protect .net&lt;br /&gt;
fastscansecure .net&lt;br /&gt;
goryhe .cn&lt;br /&gt;
pyzuhme .cn&lt;br /&gt;
zydfaqe .cn&lt;br /&gt;
ahoize .cn&lt;br /&gt;
abonyag .cn&lt;br /&gt;
abenapi .cn&lt;br /&gt;
otobym .cn&lt;br /&gt;
abicoym .cn&lt;br /&gt;
nepsoym .cn&lt;br /&gt;
byzfalo .cn&lt;br /&gt;
pywudar .cn&lt;br /&gt;
qucgyit .cn&lt;br /&gt;
dahokxu .cn&lt;br /&gt;
lylbaov .cn&lt;br /&gt;
cusryw .cn&lt;/b&gt;&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SrySPyKA8rI/AAAAAAAAELg/tBnwPEezcNM/s1600-h/september_twitter_scareware_6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SrySPyKA8rI/AAAAAAAAELg/tBnwPEezcNM/s200/september_twitter_scareware_6.png" /&gt;&lt;/a&gt;&lt;b&gt;fast-scanandprotect .net&lt;br /&gt;
fastscanonline .com&lt;br /&gt;
fastsearch-secure .com&lt;br /&gt;
fast-systemguard .net&lt;br /&gt;
go-scanandsecure .net&lt;br /&gt;
goscan-protect .com&lt;br /&gt;
go-searchandscan .com&lt;br /&gt;
guardmyzone .net&lt;br /&gt;
mynewprotection .net&lt;br /&gt;
my-newprotection .net&lt;br /&gt;
my-officeguard .com&lt;br /&gt;
my-officeguard .net&lt;br /&gt;
myprotectedsystem .com&lt;br /&gt;
myprotected-system .com&lt;br /&gt;
my-protectedzone .net&lt;br /&gt;
myprotectionshield .com&lt;br /&gt;
myprotectionzone .com&lt;br /&gt;
my-protectionzone .com&lt;br /&gt;
my-protectionzone .net&lt;br /&gt;
myprotection-zone .net&lt;br /&gt;
my-saerchsecure .com&lt;br /&gt;
my-safetyprotection .com&lt;br /&gt;
my-systemprotection .net&lt;br /&gt;
mysystemsafety .com&lt;br /&gt;
my-systemscan .com&lt;br /&gt;
my-systemscanner .com&lt;br /&gt;
mysystemsecurity .com&lt;br /&gt;
new-scanandprotect .com&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SrySyPb737I/AAAAAAAAEL4/RFj1y7hZvQg/s1600-h/september_twitter_scareware_4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SrySyPb737I/AAAAAAAAEL4/RFj1y7hZvQg/s200/september_twitter_scareware_4.png" /&gt;&lt;/a&gt;&lt;b&gt;newscan-andprotect .net&lt;br /&gt;
new-systemprotection .com&lt;br /&gt;
online-scanandsecure .net&lt;br /&gt;
online-securescanner .net&lt;br /&gt;
online-systemscan .com&lt;br /&gt;
onlinesystemscan .net&lt;br /&gt;
protectand-secure .com&lt;br /&gt;
protectionsearch .com&lt;br /&gt;
safetyshield .net&lt;br /&gt;
safetysystem-guard .com&lt;br /&gt;
scanonline-protect .com&lt;br /&gt;
scan-system .net&lt;br /&gt;
scanvirus-online .net&lt;br /&gt;
searchandscan .net&lt;br /&gt;
search-scanonline .net&lt;br /&gt;
searchsecureguard .net&lt;br /&gt;
secure-systemguard .net&lt;br /&gt;
system-guard .net&lt;br /&gt;
systemguard-zone .com&lt;br /&gt;
systemguard-zone .net&lt;br /&gt;
systemprotected .net&lt;br /&gt;
systemscan-secure .net&lt;br /&gt;
trust-systemprotect .com&lt;br /&gt;
trust-systemprotect .net&lt;br /&gt;
trustsystem-protection .com&lt;br /&gt;
trust-systemprotection .net&lt;br /&gt;
windows-protectionsuite .net&lt;br /&gt;
windows-systemguard .net&lt;br /&gt;
windows-virusscan .net&lt;br /&gt;
winprotection-suite .com&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.virustotal.com/analisis/425f7045781ca3609eeb17a8a833b5fe9494f2779257451d88f18bc85f59342d-1253865277"&gt;Sampled scareware&lt;/a&gt; also &lt;a href="http://www.virustotal.com/analisis/3b765e9540575b044eccf7aaaa3bdc2c4114ccb206b84aa88e8e02524745fc4a-1253873563"&gt;phones-back&lt;/a&gt; to &lt;b&gt;mysecurityguru .cn&lt;/b&gt; - 64.86.16.170 - Email: andrew.fbecket@gmail.com, the same phone-back domain was used in the scareware sampled from the &lt;a href="http://ddanchev.blogspot.com/2009/09/ukrainian-fan-club-features.html"&gt;NYTimes.com malvertising attack&lt;/a&gt;, with the same email also belonging to a scareware domain (&lt;b&gt;mainsecsys .info&lt;/b&gt;) listed in the &lt;a href="http://ddanchev.blogspot.com/2009/07/diverse-portfolio-of-fake-security.html"&gt;Diverse Portfolio of Fake Security Software - Part Twenty Two for July&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
The cybercrime powerhouse behind all these attacks, continues maintaining the largest market share of &lt;a href="http://ddanchev.blogspot.com/2009/09/koobface-botnets-scareware-business.html"&gt;systematic Web 2.0 abuse&lt;/a&gt;, and that includes their involvement in &lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front-part-two.html"&gt;the Koobface botnet&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/dissecting-koobface-worms-twitter.html"&gt;Dissecting Koobface Worm's Twitter Campaign&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/04/twitter-worm-mikeyy-keywords-hijacked.html"&gt;Twitter Worm Mikeyy Keywords Hijacked to Serve Scareware&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/from-ukraine-with-bogus-twitter.html"&gt;From Ukraine with Bogus Twitter, LinkedIn and Scribd Accounts&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukraine-with-scareware-serving.html"&gt;From Ukraine with Scareware Serving Tweets, Bogus LinkedIn/Scribd Accounts, and Blackhat SEO Farms &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/08/twitter-malware-campaign-wants-to-bank.html"&gt;The Twitter Malware Campaign Wants to Bank With You&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=3872"&gt;Does Twitter’s malware link filter really work?&lt;/a&gt; &lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=2477"&gt;Commercial Twitter spamming tool hits the market&lt;/a&gt; &lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=3549"&gt;Cybercriminals hijack Twitter trending topics to serve malware&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=3402"&gt;Spammers harvesting emails from Twitter - in real time&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=3125"&gt;Twitter hit by multiple variants of XSS worm&lt;/a&gt;&lt;a href="http://blogs.zdnet.com/security/?p=3706"&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-498309029086413014?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZkUtBnYqLzw:wRFkZj8H1IY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZkUtBnYqLzw:wRFkZj8H1IY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZkUtBnYqLzw:wRFkZj8H1IY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=ZkUtBnYqLzw:wRFkZj8H1IY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZkUtBnYqLzw:wRFkZj8H1IY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=ZkUtBnYqLzw:wRFkZj8H1IY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZkUtBnYqLzw:wRFkZj8H1IY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZkUtBnYqLzw:wRFkZj8H1IY:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=ZkUtBnYqLzw:wRFkZj8H1IY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=ZkUtBnYqLzw:wRFkZj8H1IY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/ZkUtBnYqLzw" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-25T21:37:52.459+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_wICHhTiQmrA/SryFBYX4VUI/AAAAAAAAEK4/Lu5FQ9sMJ0M/s72-c/september_twitter_scareware_2.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/09/dissecting-septembers-twitter-scareware.html</feedburner:origLink></item><item><title>The Ultimate Guide to Scareware Protection</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/hGHp0CvrZnY/ultimate-guide-to-scareware-protection.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Fri, 18 Sep 2009 10:03:47 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-173420497068455274</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://content.zdnet.com/2346-12691_22-342083.html" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SrO7xfB5CXI/AAAAAAAAEKw/sWG99PmJuwg/s320/scareware_rogueware_fake_security_software.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
Throughout the last two years, &lt;a href="http://en.wikipedia.org/wiki/Scareware"&gt;scareware (fake security software)&lt;/a&gt;, quickly emerged as the single most profitable monetization strategy for cybercriminals to take advantage of. Due to the aggressive advertising practices applied by the cybercrime gangs, thousands of users fall victim to the scam on a daily basis, with the gangs themselves earning hundreds of thousands of dollars in the process.&lt;br /&gt;
&lt;br /&gt;
This &lt;b&gt;&lt;a href="http://blogs.zdnet.com/security/?p=4297"&gt;end user-friendly guide aims to educate the Internet user on what scareware is&lt;/a&gt;&lt;/b&gt;, the risks posed by installing it, how it looks like, its delivery channels, and most importantly, how to recognize, avoid and report it to the security community taking into consideration the fact that 99% of the current releases rely on social engineering tactics.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-173420497068455274?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGHp0CvrZnY:LHf7aY-vnkA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGHp0CvrZnY:LHf7aY-vnkA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGHp0CvrZnY:LHf7aY-vnkA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=hGHp0CvrZnY:LHf7aY-vnkA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGHp0CvrZnY:LHf7aY-vnkA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=hGHp0CvrZnY:LHf7aY-vnkA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGHp0CvrZnY:LHf7aY-vnkA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGHp0CvrZnY:LHf7aY-vnkA:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=hGHp0CvrZnY:LHf7aY-vnkA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=hGHp0CvrZnY:LHf7aY-vnkA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/hGHp0CvrZnY" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-18T19:03:47.265+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_wICHhTiQmrA/SrO7xfB5CXI/AAAAAAAAEKw/sWG99PmJuwg/s72-c/scareware_rogueware_fake_security_software.jpg" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/09/ultimate-guide-to-scareware-protection.html</feedburner:origLink></item><item><title>Koobface Botnet's Scareware Business Model</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/tDwuijkUtHA/koobface-botnets-scareware-business.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Fri, 25 Sep 2009 03:05:40 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-158358917972057111</guid><description>&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SrEW0bLAB0I/AAAAAAAAEJA/hrrmV4a702k/s1600-h/koobface_scareware_1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SrEW0bLAB0I/AAAAAAAAEJA/hrrmV4a702k/s200/koobface_scareware_1.png" /&gt;&lt;/a&gt;&lt;b&gt;UPDATE1: &lt;/b&gt;TrendMicro just confirmed the ongoing &lt;a href="http://blog.trendmicro.com/pick-your-poison-koobface-or-fakeav/"&gt;double-layer monetization of Koobface&lt;/a&gt;. Meanwhile, the gang is rotating the scareware domains with new ones pushed by popup.php, followd by two recently updated Koobface components.&lt;br /&gt;
&lt;br /&gt;
The &lt;a href="http://www.virustotal.com/analisis/5daf7fb19bea76e5b438b69f72d75b8006ca0dfbfb68a0c43466b3e1bfd0c220-1253290342"&gt;new scareware&lt;/a&gt; domains &lt;b&gt;kjremover .info&lt;/b&gt;; &lt;b&gt;lrxsoft .info&lt;/b&gt; - 212.117.160.21 - Email: niclas@i.ua actually &lt;a href="http://ddanchev.blogspot.com/2009/07/diverse-portfolio-of-fake-security_27.html"&gt;download it from the well known&lt;/a&gt; &lt;b&gt;q2bf0fzvjb5ca .cn&lt;/b&gt; portfolio, which phones back to the same domains listed previously, with only a slight change in the filename - &lt;b&gt;urodinam .net/8732489273.php&lt;/b&gt;. The generic detection rate for the updated components (&lt;b&gt;61.235.117.83 /bin/&lt;a href="http://www.virustotal.com/analisis/7f1a848c42f548715b3ae28a7033c6d9b3dc64630f62ecb8b72b658dfc18f86e-1253289574"&gt;get.exe&lt;/a&gt;&lt;/b&gt;; &lt;b&gt;61.235.117.83 /bin/&lt;a href="http://www.virustotal.com/analisis/8b6b0105d5bd4b374e1fb826ce69874c2c5fc3430507d439547c4a81e0e778db-1253289585"&gt;v2webserver.exe&lt;/a&gt;&lt;/b&gt;) with get.exe phoning back to a domain parked at the takedown-proof, China-based &lt;b&gt;61.235.117.83&lt;/b&gt;, in particular &lt;b&gt;gdehochesh .com/adm/index.php&lt;/b&gt;.&lt;br /&gt;
&amp;nbsp; &lt;br /&gt;
Just like Conficker, the &lt;a href="http://garwarner.blogspot.com/2009/09/koobface-wrecks-search-results.html"&gt;Koobface botnet&lt;/a&gt; is no stranger to the &lt;a href="http://ddanchev.blogspot.com/2009/04/confickers-scarewarefake-security.html"&gt;scareware business model&lt;/a&gt; and the potential for monetization of the hundreds of thousands of infected hosts.&lt;br /&gt;
&lt;br /&gt;
However, changes made in the campaign structure of the Koobface botnet during the last couple of days, indicate that the Koobface gang has embedded a pop-up at each and every host that's automatically rotation different scareware brands. &lt;b&gt;They're now officially monetizing the botnet using a scareware business model&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
Let's analyze the latest changes introduced by the Koobface gang over the last couple of days and emphasize on the monetization tactics introduced by the gang.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SrEY2hoWZKI/AAAAAAAAEJI/xAWFPNgRmz8/s1600-h/koobface_scareware_9.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SrEY2hoWZKI/AAAAAAAAEJI/xAWFPNgRmz8/s200/koobface_scareware_9.JPG" /&gt;&lt;/a&gt;&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;Next&lt;/a&gt; to &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;insulting&lt;/a&gt;, showing &lt;a href="http://ddanchev.blogspot.com/2009/07/koobface-come-out-come-out-wherever-you.html"&gt;gratitude&lt;/a&gt;, the &lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Smc9UjwhxZI/AAAAAAAAD-Y/WQ17qmHSx6U/s1600-h/koobface-thanks-dancho1.PNG"&gt;Koobface gang&lt;/a&gt; also has a (black) sense of humor - within one of the directories at the takedown-proof command and control used by the gang in China (&lt;a href="http://whois.domaintools.com/61.235.117.83"&gt;61.235.117.83&lt;/a&gt;; at &lt;b&gt;61.235.117.83/bin&lt;/b&gt; in particular) they've left the following message "&lt;b&gt;2008 ali baba and 40, LLC&lt;/b&gt;". &lt;a href="http://en.wikipedia.org/wiki/Ali_Baba_and_the_Forty_Thieves_%281944_film%29"&gt;Ali Baba and the Forty Thieves&lt;/a&gt; is a 1944 film based on the original &lt;a href="http://en.wikipedia.org/wiki/Ali_Baba"&gt;Ali Baba character&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;Compared to previous campaigns relying on centralized command and control and redirection points -- making them easy to shut down -- the ongoing Facebook campaigns are dynamically redirecting to IPs within the Koobface network, which combined with their use of compromised legitimate sites is supposed to make the take down of their campaigns a bit more time consuming.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SrEdq6fv0XI/AAAAAAAAEJQ/32tnj7ImUoU/s1600-h/koobface_scareware_3_Safety_Center.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SrEdq6fv0XI/AAAAAAAAEJQ/32tnj7ImUoU/s200/koobface_scareware_3_Safety_Center.gif" /&gt;&lt;/a&gt;That's, of course, not the case since undermining their monetization approaches undermines the monetary value of their campaigns, which is what they're after this time. The Koobface gang has now embedded a single line within each and every infected host used in the campaign, in order to not only attempt to infect new visitors with the Koobface malware itself, but to also trick them into installing the scareware which is rotated as usual.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;dangerWindAdr = 61.235.117.83/ popup.php&lt;/b&gt; loads on each and every Facebook spoof page part of the botnet and is then redirecting the most popular scareware template, the &lt;b&gt;My computer Online Scan&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SrEhPsMbpsI/AAAAAAAAEJY/LIjSefdWU7g/s1600-h/koobface_scareware_14.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SrEhPsMbpsI/AAAAAAAAEJY/LIjSefdWU7g/s200/koobface_scareware_14.png" /&gt;&lt;/a&gt;The first scareware domain used in the last 48 &lt;b&gt;ryacleaner .info/hitin.php?affid=02979&lt;/b&gt; (212.117.160.21l parked there as also &lt;b&gt;eljupdate .info&lt;/b&gt; Email: niclas@i.ua and &lt;b&gt;dercleaner .info&lt;/b&gt; Email: niclas@i.ua) was serving setup.exe which is downloading the actual &lt;a href="http://www.virustotal.com/analisis/f9927cedb08e47c838772a791dd476924c7ca9c9c193ffd7b8b16b99a8455602-1253034136"&gt;scareware executable&lt;/a&gt; from &lt;b&gt;mt3pvkfmpi7de .cn/get.php?id=02979&lt;/b&gt; (220.196.59.23).&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;What's so special about this domain? It was last profiled in the &lt;a href="http://ddanchev.blogspot.com/2009/07/diverse-portfolio-of-fake-security_27.html"&gt;A Diverse Portfolio of Fake Security Software - Part Twenty Three&lt;/a&gt; with the entire portfolio of .cn domains parked at the same IP registered under the same email - robertsimonkroon@gmail.com.&lt;br /&gt;
&lt;br /&gt;
The second scareware domain pushed by the Koobface during the last 24 hours, &lt;b&gt;gotrioscan .com/?uid=13301&lt;/b&gt; - 91.212.107.103 - momorule@gmail.com redirects to &lt;b&gt;plazec .info/22/?uid=13301 - &lt;/b&gt;91.212.107.103 - Email: bebrashe@gmail.com where the &lt;a href="http://www.virustotal.com/analisis/fc49e1fb731ae959262b2237494e0cd39e1c5399f4fd56a1e40276053a0e693f-1253114398"&gt;scareware is served&lt;/a&gt;. Parked at the same IP is the rest of thescareware domains portfolio pushed by Koobface:&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;b&gt;in5id .com&lt;br /&gt;
in5ch .com&lt;br /&gt;
goscanback .com&lt;br /&gt;
goscanlook .com&lt;br /&gt;
gofatescan .com&lt;br /&gt;
goeachscan .com&lt;br /&gt;
gobackscan .com &lt;br /&gt;
goironscan .com&lt;br /&gt;
gotrioscan .com&lt;br /&gt;
ia-pro .com&lt;br /&gt;
iantivirus-pro .com&lt;br /&gt;
iantiviruspro .com&lt;br /&gt;
windoptimizer .com&lt;br /&gt;
woptimizer .com&lt;br /&gt;
in5cs .com&lt;br /&gt;
wopayment .com&lt;br /&gt;
in5st .com&lt;br /&gt;
zussia .info&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SrEnRK4RcAI/AAAAAAAAEJg/gGxSEd_gdEM/s1600-h/koobface_scareware_4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SrEnRK4RcAI/AAAAAAAAEJg/gGxSEd_gdEM/s200/koobface_scareware_4.png" /&gt;&lt;/a&gt;&lt;b&gt;plazec .info&lt;br /&gt;
gaudad .info&lt;br /&gt;
voided .info&lt;br /&gt;
gelded .info&lt;br /&gt;
tithed .info&lt;br /&gt;
botled .info&lt;br /&gt;
tented .info&lt;br /&gt;
fatted .info&lt;br /&gt;
unowed .info&lt;br /&gt;
wzand .info&lt;br /&gt;
searce .info&lt;br /&gt;
prarie .info&lt;br /&gt;
meyrie .info&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;pittie .info&lt;br /&gt;
penvie .info&lt;br /&gt;
figgle .info&lt;br /&gt;
sawme .info&lt;br /&gt;
droope .info&lt;br /&gt;
haere .info&lt;br /&gt;
scarre .info&lt;br /&gt;
undeaf .info&lt;br /&gt;
adjudg .info&lt;br /&gt;
wiving .info&lt;br /&gt;
slatch .info&lt;/b&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SrEofOkB8JI/AAAAAAAAEJo/7rWFA6u2Yco/s1600-h/koobface_scareware_11.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SrEofOkB8JI/AAAAAAAAEJo/7rWFA6u2Yco/s200/koobface_scareware_11.png" /&gt;&lt;/a&gt;&lt;b&gt;bedash .info&lt;br /&gt;
dolchi .info&lt;br /&gt;
sighal .info&lt;br /&gt;
devicel .info&lt;br /&gt;
knivel .info&lt;br /&gt;
freckl .info&lt;br /&gt;
scrowl .info&lt;br /&gt;
usicam .info&lt;br /&gt;
spelem .info&lt;br /&gt;
vagrom .info&lt;br /&gt;
numben .info&lt;br /&gt;
speen .info&lt;br /&gt;
krapen .info&lt;br /&gt;
atwain .info&lt;br /&gt;
declin .info&lt;br /&gt;
inclin .info&lt;br /&gt;
unclin .info&lt;br /&gt;
towton .info&lt;br /&gt;
grumio .info&lt;br /&gt;
stampo .info&lt;br /&gt;
extrip .info&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SrEottOM4xI/AAAAAAAAEJw/oC3v6KzzhZc/s1600-h/koobface_scareware_10.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SrEottOM4xI/AAAAAAAAEJw/oC3v6KzzhZc/s200/koobface_scareware_10.JPG" /&gt;&lt;/a&gt;&lt;b&gt;polear .info&lt;br /&gt;
benber .info&lt;br /&gt;
kedder .info&lt;br /&gt;
erpeer .info&lt;br /&gt;
argier .info &lt;br /&gt;
fulier .info&lt;br /&gt;
lavyer .info&lt;br /&gt;
inquir .info&lt;br /&gt;
orodes .info&lt;br /&gt;
faites .info&lt;br /&gt;
beeves .info&lt;br /&gt;
quoifs .info&lt;br /&gt;
filths .info&lt;br /&gt;
broths .info&lt;br /&gt;
nevils .info&lt;br /&gt;
swoons .info&lt;br /&gt;
sallat .info&lt;br /&gt;
apalet .info&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SrEpB06SZ-I/AAAAAAAAEJ4/oUXxSPjtsUE/s1600-h/koobface_scareware_12.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SrEpB06SZ-I/AAAAAAAAEJ4/oUXxSPjtsUE/s320/koobface_scareware_12.png" /&gt;&lt;/a&gt;&lt;b&gt;reglet .info&lt;br /&gt;
camlet .info&lt;br /&gt;
plamet .info&lt;br /&gt;
hownet .info&lt;br /&gt;
fosset .info&lt;br /&gt;
cuplift .info&lt;br /&gt;
raught .info&lt;br /&gt;
holdit .info&lt;br /&gt;
unroot .info &lt;br /&gt;
unwept .info &lt;br /&gt;
anmast .info&lt;br /&gt;
ticedu .info&lt;br /&gt;
outliv .info&lt;br /&gt;
onclew .info&lt;br /&gt;
froday .info&lt;br /&gt;
mayray .info&lt;br /&gt;
tenshy .info&lt;br /&gt;
steepy .info&lt;br /&gt;
miloty .info&lt;br /&gt;
debuty .info&lt;br /&gt;
fifthz .info&lt;br /&gt;
potinz .info&lt;br /&gt;
caretz .info&lt;br /&gt;
narowz .info&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SrEsZbNCuCI/AAAAAAAAEKI/k9yXPdUljjI/s1600-h/koobface_scareware_13.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SrEsZbNCuCI/AAAAAAAAEKI/k9yXPdUljjI/s320/koobface_scareware_13.JPG" /&gt;&lt;/a&gt;What do these two scareware executables have in common? Its the phone back locations that the Koobface gang is using, reveling its &lt;b&gt;participation in a scareware affiliate network called Crusade Affiliates&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SrEua17QfSI/AAAAAAAAEKQ/bIaR3G-tdGA/s1600-h/koobface_scareware_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SrEua17QfSI/AAAAAAAAEKQ/bIaR3G-tdGA/s200/koobface_scareware_2.png" /&gt;&lt;/a&gt;The first phone back location &lt;b&gt;urodinam.net /dfgsdfsdf .php&lt;/b&gt; - 122.224.9.67 adds a .bat file which would attempt to obtain mshta.exe from &lt;b&gt;urodinam.net/33t .php?stime=1253063118&lt;/b&gt; on hourly basis. The second phone back location is the Crusade Affiliates network that shares revenue with the Koobface gang whenever a scareware pushed by the gang is purchased - &lt;b&gt;crusade-affiliates .com/install.php?id=02979&lt;/b&gt; - 85.17.139.149.&lt;br /&gt;
&lt;br /&gt;
The third phone back location is a direct download attempt of &lt;a href="http://www.virustotal.com/analisis/9c23d2c48bc5912869f2ccee1cf8798cb8b9f466996c96538546c7466ae710ef-1253034570"&gt;FraudTool.Win32.SecretService&lt;/a&gt;; RogueAntiSpyware.PrivacyCenter.AJ from &lt;b&gt;0ni9o1s3feu60 .cn/u4.exe&lt;/b&gt; - 220.196.59.23. It's pretty evident that the Koobface botnet is now relying on multiple layers of monetization approaches.&lt;br /&gt;
&lt;br /&gt;
The Koobface gang has been pretty during the last couple of days. The following list of Koobface malware spreading domains are in circulation across social networking sites since the last 48 hours, consisting of a combination of purely malicious and compromised legitimate sites:&lt;br /&gt;
&lt;b&gt;3sss .com/youtube.com&amp;nbsp; &lt;br /&gt;
4bond .it/youtube.com&amp;nbsp; &lt;br /&gt;
ac2j .com/freeem0vies&lt;br /&gt;
aced1979 .freehostia.com/y0urfi1m&lt;br /&gt;
alexandrialocksmith .net/uncens0redvide0&amp;nbsp; &lt;br /&gt;
alpha.kei .pl/amalzlngfi1ms&lt;br /&gt;
alruwaithy .com/extrlmeperf0rmans&lt;br /&gt;
astoundeddesign .com/privaledem0nstrati0n&lt;br /&gt;
awwfuck .me/fuunnyacti0n&lt;br /&gt;
baddog.me .uk/uncens0redc1ip&lt;br /&gt;
bbckzoo .com/extrlmedwd&amp;nbsp; &lt;br /&gt;
bbckzoo .com/mmyperf0rmans&amp;nbsp; &lt;br /&gt;
be. la/freeefi1ms&lt;br /&gt;
bencaputoprinting .com/c00lfi1m&amp;nbsp; &lt;br /&gt;
bicentenario.sc49 .info/mmyfi1m&lt;br /&gt;
bighornrivercabins .com/c00lvlds&lt;br /&gt;
biskopsto .fo/fantasticm0vie&lt;br /&gt;
bloch-data .dk/c00lvlds&lt;br /&gt;
bokongerslev .dk/amalzlngm0vie&amp;nbsp; &lt;br /&gt;
bokongerslev .dk/extrlmeacti0n&amp;nbsp; &lt;br /&gt;
book-dalmose .dk/extrlmeperf0rmans&lt;br /&gt;
campionariadigalatina .it/youtube.com&amp;nbsp; &lt;br /&gt;
carlamo .com/extrlmec1ip&lt;br /&gt;
centerforyourhealth .com/extrlmem0vies&amp;nbsp; &lt;br /&gt;
centralbaptist.org .au/fantasticvide0&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SrEqBk2QywI/AAAAAAAAEKA/YX6P-ZfY2XU/s1600-h/koobface_scareware_6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SrEqBk2QywI/AAAAAAAAEKA/YX6P-ZfY2XU/s200/koobface_scareware_6.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;b&gt;certtiletechs .com/fuunnym0vies&lt;br /&gt;
cisaimpianti .net/youtube.com&amp;nbsp; &lt;br /&gt;
claykelley .net/extrlmevlds&amp;nbsp; &lt;br /&gt;
claykelley .net/mmyvide0&amp;nbsp; &lt;br /&gt;
clubatleticigualada .com/y0urc1ip&lt;br /&gt;
connoro .com/bestsh0w&lt;br /&gt;
consignbuydesign .com/fuunnyttube&lt;br /&gt;
dkflyt .dk/mmytw &lt;br /&gt;
downingfarms .com/bestacti0n&lt;br /&gt;
eminfinity.com .au/amalzlngc1ips&amp;nbsp; &lt;br /&gt;
eminfinity.com .au/uncens0redsh0w&amp;nbsp; &lt;br /&gt;
endurancesportscar .com/extrlmem0vies&amp;nbsp; &lt;br /&gt;
epicent .dk/pub1icfi1m&amp;nbsp; &lt;br /&gt;
evaracollin .be/mmyfi1ms&lt;br /&gt;
exceleronmedical .com/amalzlngc1ips&amp;nbsp; &lt;br /&gt;
exceleronmedical .com/c00lperf0rmans&amp;nbsp; &lt;br /&gt;
exceleronmedical .com/privalettube/?youtube.com&lt;br /&gt;
finolog .com/privalem0vie&lt;br /&gt;
fitslim .com/fantasticdem0nstrati0n&lt;br /&gt;
gacogop .org/fuunnyc1ips&lt;br /&gt;
gamlabodens .se/privaletw&amp;nbsp; &lt;br /&gt;
garagedoorsnow .com/meggadem0nstrati0n&lt;br /&gt;
garlicworld .com/mmym0vie&amp;nbsp; &lt;br /&gt;
garlicworld .com/uncens0redperf0rmans&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;gcillustration .com/extrlmevide0&amp;nbsp; &lt;br /&gt;
germanamericantax .com/pub1icm0vie&amp;nbsp; &lt;br /&gt;
happyholidaychristmastrees .com/uncens0redperf0rmans&lt;br /&gt;
horaexata.com .br/c00lc1ip&lt;br /&gt;
huffmanfarms .com/fantasticfi1ms&lt;br /&gt;
imagequest360 .com/fantasticm0vies&amp;nbsp; &lt;br /&gt;
inartdesigns .com/extrlmevide0&lt;br /&gt;
interception .dk/mmyttube&lt;br /&gt;
kalender.sttmedia .se/amalzlngdem0nstrati0n&amp;nbsp; &lt;br /&gt;
kartingclubsourdsnamur .be/besttw&lt;br /&gt;
kiding.users.digital-crocus .com/mmym0vies&lt;br /&gt;
kloerfem .dk/amalzlngsh0w&lt;br /&gt;
kracl .com/freeesh0w&lt;br /&gt;
kreativdizajn .com/amalzlngvlds&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;ktvsongs .com/pub1icacti0n&amp;nbsp; &lt;br /&gt;
lonestargcs .com/mmydwd&lt;br /&gt;
losangelesfurniture .com/fantasticdem0nstrati0n&lt;br /&gt;
lr-online .dk/c00lfi1ms&amp;nbsp; &lt;br /&gt;
lr-online .dk/y0ursh0w&amp;nbsp; &lt;br /&gt;
marketmarkj .com/privalem0vies&lt;br /&gt;
martinhorngren .com/privalettube&amp;nbsp; &lt;br /&gt;
meetingpacket .com/youtube.com&amp;nbsp; &lt;br /&gt;
microscoop .net/fantasticttube&lt;br /&gt;
momentsbypat .com/pub1icm0vie&lt;br /&gt;
mtn-ejendomme .dk/mmyacti0n&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SrEuy-LR3_I/AAAAAAAAEKY/0MVRFgdlAQM/s1600-h/koobface_scareware_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SrEuy-LR3_I/AAAAAAAAEKY/0MVRFgdlAQM/s200/koobface_scareware_5.png" /&gt;&lt;/a&gt;&lt;b&gt;nadiottawa .org/pub1icc1ips&lt;br /&gt;
naestved-sportscollege .dk/amalzlngacti0n&lt;br /&gt;
nicalandnow .com/uncens0redvlds&lt;br /&gt;
odyssey-consultants .com/amalzlngvide0&amp;nbsp; &lt;br /&gt;
odyssey-consultants .com/mmym0vie&amp;nbsp; &lt;br /&gt;
onlyfun .se/extrlmec1ip&lt;br /&gt;
pridesoccer .com/privalec1ips&lt;br /&gt;
quicksilver-direct .com/amalzlngfi1m&amp;nbsp; &lt;br /&gt;
reddoorchina .com/mmyvlds&amp;nbsp; &lt;br /&gt;
relivery .com/extrlmesh0w&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;ristorocasanova .it/youtube.com&amp;nbsp; &lt;br /&gt;
sanfranciscocookie .com/fantasticfi1ms&lt;br /&gt;
sarkos .ch/fuunnyperf0rmans&lt;br /&gt;
saudiclubs .org/fantasticvlds&lt;br /&gt;
sauipeswimwear .com/c00lm0vie&lt;br /&gt;
schoolofhiphop .no/freeefi1ms&lt;br /&gt;
senegalinfoservices .com/bestacti0n&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;squashigualada .com/extrlmevlds&lt;br /&gt;
starcraftdream .com/fuunnyvlds&lt;br /&gt;
stm.frihost .org/freeefi1m&lt;br /&gt;
stringer .no/uncens0redacti0n&lt;br /&gt;
sttmedia .se/fantastictw&amp;nbsp; &lt;br /&gt;
taia.com .br/uncens0reddwd&lt;br /&gt;
thefurniturewarehouse .net/mmym0vies&lt;br /&gt;
theidusshop .com/pub1ictw&lt;br /&gt;
thepinflow .com/meggash0w&lt;br /&gt;
thorsen-meyer .dk/bestc1ips&lt;br /&gt;
tivity .dk/amalzlngm0vie&amp;nbsp; &lt;br /&gt;
tivity .dk/fantasticfi1ms&amp;nbsp; &lt;br /&gt;
tizianamaniezzo .com/fantasticc1ips&amp;nbsp; &lt;br /&gt;
tohva .org/bestacti0n&lt;br /&gt;
troop270 .nwsc.org/fuunnydwd&lt;br /&gt;
txmurphys .com/c00lfi1m&amp;nbsp; &lt;br /&gt;
tybjerglillebakkervand .dk/privalem0vie&lt;br /&gt;
vagnpfisk .dk/privalem0vie&lt;br /&gt;
vivaipirovano .com/youtube.com&amp;nbsp; &lt;br /&gt;
xanchise .com/c00lc1ip&lt;br /&gt;
yurafting .com/amalzlngvlds&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.virustotal.com/analisis/15a4092d1af66a5a12655732f5fd3bf77015be8cc334094575222b0b71056e90-1253025400"&gt;Sampled Koobface&lt;/a&gt; binary now phones back to &lt;b&gt;bianca.trinityonline .biz/.sys/?action=ldgen&amp;amp;v=14&lt;/b&gt; and &lt;b&gt;bianca.trinityonline .biz/.sys/?action=ldgen&amp;amp;a=590837698&amp;amp;v=14&amp;amp;l=1000&amp;amp;c_fb=0&amp;amp;c_ms=0&amp;amp;c_hi=0&amp;amp;c_tw=0&amp;amp;c_be=0&amp;amp;c_tg=0&amp;amp;c_nl=0&lt;/b&gt;. 69.163.147.203 - Email: email@darrenjames.net, with the latest Koobfae update modules detected as follows - &lt;b&gt;61.235.117.83 /bin/&lt;a href="http://www.virustotal.com/analisis/4e334d1637ab18624c0c500d77e990470b52254dd73e6e689a89a4238947278e-1253035704"&gt;v2prx.exe&lt;/a&gt;&lt;/b&gt;; &lt;b&gt;61.235.117.83 /bin/&lt;a href="http://www.virustotal.com/analisis/2fb995fc38c855a38e8094c589d58227ac5836956b0d88b0c3a4cdae47f3374e-1253035776"&gt;pp.12.exe&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The "Koobface botnet and the 40 cybercriminals" (&lt;b&gt;2008 ali baba and 40 , LLC&lt;/b&gt;) have not just started monetizing the infected hosts, they're using multiple layers of monetization to do so.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front-part-two.html"&gt;Movement on the Koobface Front - Part Two&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front.html"&gt;Movement on the Koobface Front&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/koobface-come-out-come-out-wherever-you.html"&gt;Koobface - Come Out, Come Out, Wherever You Are &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/dissecting-koobface-worms-twitter.html"&gt;Dissecting Koobface Worm's Twitter Campaign&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/12/dissecting-koobface-worms-december.html"&gt;Dissecting the Koobface Worm's December Campaign &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/11/dissecting-latest-koobface-facebook.html"&gt;Dissecting the Latest Koobface Facebook Campaign&lt;/a&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/12/koobface-gang-mixing-social-engineering.html"&gt;The Koobface Gang Mixing Social Engineering Vectors&lt;/a&gt;&lt;b&gt;&lt;/b&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-158358917972057111?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tDwuijkUtHA:bKq098GmZ9Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tDwuijkUtHA:bKq098GmZ9Q:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tDwuijkUtHA:bKq098GmZ9Q:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tDwuijkUtHA:bKq098GmZ9Q:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tDwuijkUtHA:bKq098GmZ9Q:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tDwuijkUtHA:bKq098GmZ9Q:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tDwuijkUtHA:bKq098GmZ9Q:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tDwuijkUtHA:bKq098GmZ9Q:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tDwuijkUtHA:bKq098GmZ9Q:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tDwuijkUtHA:bKq098GmZ9Q:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/tDwuijkUtHA" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-25T12:05:40.311+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_wICHhTiQmrA/SrEW0bLAB0I/AAAAAAAAEJA/hrrmV4a702k/s72-c/koobface_scareware_1.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/09/koobface-botnets-scareware-business.html</feedburner:origLink></item><item><title>Ukrainian "Fan Club" Features Malvertisement at NYTimes.com</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/8mpUUWVHG2Y/ukrainian-fan-club-features.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Mon, 14 Sep 2009 12:25:21 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-371303462736028317</guid><description>&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Sq52fP2ljQI/AAAAAAAAEIw/DYydCDKs0Pg/s1600-h/NYTimes_malvertising_ukrainian_fan_club.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Sq52fP2ljQI/AAAAAAAAEIw/DYydCDKs0Pg/s200/NYTimes_malvertising_ukrainian_fan_club.png" /&gt;&lt;/a&gt;If my &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;Ukrainian "fan club"&lt;/a&gt; can &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;exploit weaknesses&lt;/a&gt; in the online &lt;a href="http://countermeasures.trendmicro.eu/new-york-times-pushes-fake-av-malvertisement/"&gt;ad publishing model&lt;/a&gt; for scareware &lt;a href="http://www.sophos.com/blogs/sophoslabs/?p=6567"&gt;serving purposes&lt;/a&gt;, anyone else could.&lt;b&gt; &lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Yesterday, the &lt;b&gt;NYTimes.com&lt;/b&gt; posted a &lt;a href="http://www.nytimes.com/2009/09/13/business/media/13note.html"&gt;note to readers&lt;/a&gt;, confirming that a malvertisement campaign somehow made on their web site, resulting in the automatic exposure of users to scareware:&lt;br /&gt;
&lt;br /&gt;
"&lt;i&gt;Some nytimes.com readers have reported seeing a pop-up box warning them about a virus and directing them to a site that claims to offer antivirus software. We believe this was generated by an unauthorized advertisement and are working to prevent the problem from recurring. If you see such a warning, we suggest that you not click on it. Instead, quit and restart your Web browser.&lt;/i&gt;"&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Sq5_4gMDxWI/AAAAAAAAEI4/O3j19taOwTc/s1600-h/NYTimes_malvertising_ukrainian_fan_club_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Sq5_4gMDxWI/AAAAAAAAEI4/O3j19taOwTc/s200/NYTimes_malvertising_ukrainian_fan_club_2.png" /&gt;&lt;/a&gt;Who's behind this malvertising campaign? Let the data speak for itself.&lt;br /&gt;
&lt;br /&gt;
According to &lt;a href="http://troy.yort.com/anatomy-of-a-malware-ad-on-nytimes-com"&gt;a published assessment of the campaign&lt;/a&gt;, the redirector and scareware domains involved in the malvertising incident are also in circulating in &lt;a href="http://ddanchev.blogspot.com/2009/08/dissecting-ongoing-us-federal-forms.html"&gt;blackhat SEO campaigns courtesy of the Ukrainian gang&lt;/a&gt; (the post is updated daily with the very latest redirector and scareware domains pushed by the gang).&lt;br /&gt;
&lt;br /&gt;
In the NYTimes.com malvertising attacks, that's &lt;b&gt;sex-and-the-city .cn&lt;/b&gt; (parked at &lt;a href="http://ddanchev.blogspot.com/2009/08/dissecting-ongoing-us-federal-forms.html"&gt;94.102.48.29&lt;/a&gt; where the rest of their redirectors are) acting as redirector leading to the &lt;b&gt;protection-check07 .com&lt;/b&gt; scareware, parked on the very same IPs (&lt;a href="http://ddanchev.blogspot.com/2009/08/dissecting-ongoing-us-federal-forms.html"&gt;91.212.107.5; 94.102.51.26; 88.198.107.25&lt;/a&gt;) like the rest of the new &lt;a href="http://ddanchev.blogspot.com/2009/09/news-items-themed-blackhat-seo-campaign.html"&gt;scareware domains systematically updated&lt;/a&gt; once or twice during a 24 hours period, again courtesy of the "fan club".&lt;br /&gt;
&lt;br /&gt;
The &lt;a href="http://www.virustotal.com/analisis/46015a6326c1014e321e5f82d21c70aa68a8a233d259134b14d984d6345b15e1-1252938252"&gt;last sample&lt;/a&gt; in circulation, phones back to &lt;b&gt;windowsprotection-suite .net&lt;/b&gt; - Email: gertrudeedickens@text2re.com; &lt;b&gt;mysecurityguru .cn&lt;/b&gt; - 64.86.16.170 - Email: andrew.fbecket@gmail.com also maintains &lt;b&gt;secure-pro .cn&lt;/b&gt;; and to &lt;b&gt;securemysystem .net&lt;/b&gt; - Email: gertrudeedickens@text2re.com&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sq50kuQt4EI/AAAAAAAAEIo/6OMCTuV8eYM/s1600-h/ukrainian_fan_club_NYTimes_malvertising.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sq50kuQt4EI/AAAAAAAAEIo/6OMCTuV8eYM/s200/ukrainian_fan_club_NYTimes_malvertising.png" /&gt;&lt;/a&gt;The &lt;a href="http://troy.yort.com/anatomy-of-a-malware-ad-on-nytimes-com"&gt;NYTimes.com malvertisement assessment&lt;/a&gt; also highlights &lt;b&gt;tradenton .com&lt;/b&gt; - 212.117.166.69 - Email: shawn@tradenton.com as the domain used in the ad rotation. Interestingly, related malvertisement domains managed by the same gang, have already been reported in &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/10/1722200.aspx"&gt;related malvertising attacks&lt;/a&gt;, are also parked on the same IP:&lt;br /&gt;
&lt;b&gt;relunas .com&lt;/b&gt; - Email: admin@relunas.com&lt;br /&gt;
&lt;b&gt;kennedales .com&lt;/b&gt; - Email: admin@kennedales.com&lt;br /&gt;
&lt;b&gt;harlingens .com&lt;/b&gt; - Email: admin@harlingens.com&lt;br /&gt;
&lt;b&gt;newadsresults .com&lt;/b&gt; - Email: ritaj@gmail.com&lt;br /&gt;
&lt;b&gt;waveadvert .com&lt;/b&gt; - Email: lindahg@yahoo.com&lt;br /&gt;
&lt;br /&gt;
As always, what would originally seem as an isolated incident orchestrated by yet to be analyzed cybecrime gang, is in fact a great example of &lt;a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html"&gt;underground multitasking&lt;/a&gt; in action through the convergence of &lt;a href="http://ddanchev.blogspot.com/2009/07/multitasking-fast-flux-botnet-that.html"&gt;different attack tactics&lt;/a&gt;, courtesy of a single cybercrime enterprise.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related malvertising posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/02/malicious-advertising-malvertising.html"&gt;Malicious Advertising (Malvertising) Increasing&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=1815"&gt;MSN Norway serving Flash exploits through malvertising&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=2513"&gt;Fake Antivirus XP pops-up at Cleveland.com&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=3140"&gt;Scareware pops-up at FoxNews&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-371303462736028317?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=8mpUUWVHG2Y:3nVTsR5H2is:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=8mpUUWVHG2Y:3nVTsR5H2is:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=8mpUUWVHG2Y:3nVTsR5H2is:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=8mpUUWVHG2Y:3nVTsR5H2is:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=8mpUUWVHG2Y:3nVTsR5H2is:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=8mpUUWVHG2Y:3nVTsR5H2is:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=8mpUUWVHG2Y:3nVTsR5H2is:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=8mpUUWVHG2Y:3nVTsR5H2is:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=8mpUUWVHG2Y:3nVTsR5H2is:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=8mpUUWVHG2Y:3nVTsR5H2is:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/8mpUUWVHG2Y" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-14T21:25:21.489+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_wICHhTiQmrA/Sq52fP2ljQI/AAAAAAAAEIw/DYydCDKs0Pg/s72-c/NYTimes_malvertising_ukrainian_fan_club.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/09/ukrainian-fan-club-features.html</feedburner:origLink></item><item><title>News Items Themed Blackhat SEO Campaign Still Active</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/_P8JLkHQRuk/news-items-themed-blackhat-seo-campaign.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Mon, 07 Sep 2009 13:42:26 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-3635452862403273266</guid><description>&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SqA_XcuJ3wI/AAAAAAAAEHw/LEJEu4JSnVQ/s1600-h/hot_news_blackhat_seo_ukrainian_4_sample_site.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SqA_XcuJ3wI/AAAAAAAAEHw/LEJEu4JSnVQ/s200/hot_news_blackhat_seo_ukrainian_4_sample_site.png" /&gt;&lt;/a&gt;According to a &lt;a href="http://pandalabs.pandasecurity.com/archive/Be-Careful-With-Your-Search-Results.aspx"&gt;blog post at PandaLabs&lt;/a&gt;, a massive and very persistent blackhat SEO campaign exclusively hijacking "&lt;i&gt;hot BBC and CNN news&lt;/i&gt;" related keywords has once again popped-up on their radars. &lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;The campaign itself has been active since April&lt;/a&gt;, when I last analyzed it.&lt;br /&gt;
&lt;br /&gt;
What has changed?&lt;br /&gt;
&lt;br /&gt;
Instead of relying on purely malicious domains, the &lt;a href="http://ddanchev.blogspot.com/2009/07/koobface-come-out-come-out-wherever-you.html"&gt;Ukrainian fan club, the one with the Koobface connection&lt;/a&gt;, remains the most active blackhat SEO group on the Web, and due to the quality of the historical OSINT making it possible to detect their activity -- &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;practice which&lt;/a&gt; prompts them to &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;insult back&lt;/a&gt; -- they're also starting to put efforts into making it look like it's another group.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SqA_iWTzehI/AAAAAAAAEH4/UHgIq3qq6KY/s1600-h/hot_news_blackhat_seo_ukrainian_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SqA_iWTzehI/AAAAAAAAEH4/UHgIq3qq6KY/s200/hot_news_blackhat_seo_ukrainian_1.JPG" /&gt;&lt;/a&gt;However, knowing&amp;nbsp; the tools and tactics that they use, next to evident efficiency-centered mentality, they continue leaving minor leads that make it possible to establish a direct relationship between the group, the Koobface worm and the majority of blackhat SEO campaigns launched during the last couple of months across the entire Web.&lt;br /&gt;
&lt;br /&gt;
The "News Items" themed blackhat SEO campaign is also serving scareware from the domains already participating in the U.S Federal Forms themed blackhat SEO campaign, what's new is the typical dynamic change of the redirectors in place.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SqU0TaqK_VI/AAAAAAAAEIA/QVa7SHWFCp4/s1600-h/hot_news_blackhat_seo_ukrainian_6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="160" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SqU0TaqK_VI/AAAAAAAAEIA/QVa7SHWFCp4/s200/hot_news_blackhat_seo_ukrainian_6.png" width="200" /&gt;&lt;/a&gt;Let's dissect a sample campaign currently parked at &lt;a href="http://google.com/safebrowsing/diagnostic?site=coolinc.info"&gt;coolinc.info&lt;/a&gt;. Once the http referrer checks are met, &lt;b&gt;bernie-madoff.coolinc .info/fox-25-news.html&lt;/b&gt; executes the campaign through a static images/ads.js located on all of the subdomains participating in campaign (&lt;b&gt;bernie-madoff.coolinc .info/images/ads.js&lt;/b&gt;; &lt;b&gt;eenadu-epaper.hmsite .net/images/ads.js&lt;/b&gt;) with generic detection triggered only by Sophos as Mal/ObfJS-CI.&lt;br /&gt;
&lt;br /&gt;
Through a series of redirectors - &lt;b&gt;usanews2009 .com/index.php&lt;/b&gt; - 78.46.129.170 - Email: derrick2@mail.ru; &lt;b&gt;newscnn2009 .com/index.php&lt;/b&gt; - 193.9.28.62 - Email: derrick2@mail.ru; &lt;b&gt;cnnnews2009 .com/index.php&lt;/b&gt; - 91.203.146.38 - EMail: derrick2@mail.ru; the user is redirected to the scareware domain through &lt;b&gt;justintimberlakestream .com&lt;/b&gt;/?pid=95&amp;amp;sid=4e6ffe - 193.169.12.70; Email: info@zebrainvents.com.&lt;br /&gt;
&lt;br /&gt;
The &lt;a href="http://www.virustotal.com/analisis/81cc29c4490124e8400e67e36ba8e96e1d771e3bb87b4dfa9005f443967792af-1251984522"&gt;scareware&lt;/a&gt; itself (phones back to &lt;b&gt;worldrolemodeling .com/?b=1s1&lt;/b&gt; - 193.169.12.71) is &lt;a href="http://www.virustotal.com/analisis/092d9d9456446a9b3f4638b787b3fc157ec72683d5d7d3bf8f513a9409bd524d-1252014961"&gt;dynamically&lt;/a&gt; served through 78.46.201.89; 193.169.12.70 and 92.241.177.207 with an diverse portfolio of fake security software domains parked there.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SqVGDTHy1DI/AAAAAAAAEII/_JpATKOZkaI/s1600-h/hot_news_blackhat_seo_ukrainian_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SqVGDTHy1DI/AAAAAAAAEII/_JpATKOZkaI/s200/hot_news_blackhat_seo_ukrainian_5.png" /&gt;&lt;/a&gt;Parked at 92.241.177.207 are:&lt;br /&gt;
&lt;b&gt;best-scanpc .com&lt;br /&gt;
bestscanpc .org&lt;br /&gt;
downloadavr2 .com&lt;br /&gt;
downloadavr3 .com&lt;br /&gt;
trucount3005 .com&lt;br /&gt;
antivirus-scan-2009 .com&lt;br /&gt;
antivirusxppro-2009 .com&lt;br /&gt;
advanced-virus-remover-2009 .com&lt;br /&gt;
advanced-virusremover-2009 .com&lt;br /&gt;
advanced-virus-remover2009 .com&lt;br /&gt;
advanced-virusremover2009 .com&lt;br /&gt;
best-scanpc .com&lt;br /&gt;
bestscanpc .com&lt;br /&gt;
xxx-white-tube .com&lt;br /&gt;
rude-xxx-tube .com&lt;br /&gt;
blue-xxx-tube .com&lt;br /&gt;
trucountme .com&lt;br /&gt;
10-open-davinci .com&lt;br /&gt;
vs-codec-pro .com&lt;br /&gt;
vscodec-pro .com&lt;br /&gt;
1-vscodec-pro .com&lt;br /&gt;
download-vscodec-pro .com&lt;br /&gt;
v-s-codecpro .com&lt;br /&gt;
antivirus-2009-ppro .com&lt;br /&gt;
onlinescanxppro .com&lt;br /&gt;
downloadavr .com&lt;br /&gt;
bestscanpc .info &lt;br /&gt;
bestscanpc .net&lt;br /&gt;
ns1.megahostname .biz&lt;br /&gt;
ns2.megahostname .biz&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SqVG-qYdKII/AAAAAAAAEIQ/Ky9gd1tAGLI/s1600-h/hot_news_blackhat_seo_ukrainian_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SqVG-qYdKII/AAAAAAAAEIQ/Ky9gd1tAGLI/s200/hot_news_blackhat_seo_ukrainian_2.png" /&gt;&lt;/a&gt;Parked at 78.46.201.89 (IP used in the &lt;a href="http://ddanchev.blogspot.com/2009/08/dissecting-ongoing-us-federal-forms.html"&gt;U.S Federal Forms themed blackhat SEO campaign&lt;/a&gt;) are also:&lt;br /&gt;
&lt;b&gt;virscan-online1 .com&lt;br /&gt;
virscan-live1 .com&lt;br /&gt;
antivirus-promo-scan1 .com&lt;br /&gt;
valueantivirusshop1 .com&lt;br /&gt;
megaspywarescan2 .com&lt;br /&gt;
worldbestonlinescanner2 .com&lt;br /&gt;
hqvirusscanner2 .com&lt;br /&gt;
warningmalwarealert2 .com&lt;br /&gt;
totalspywarescan3 .com&lt;br /&gt;
antivirus-promo-scanner3 .com&lt;br /&gt;
bewareofvirusattacks3 .com&lt;br /&gt;
totalspywarescan4 .com&lt;br /&gt;
worldbestonlinescan5 .com&lt;br /&gt;
megaspywarescan5 .com&lt;br /&gt;
totalspywarescan5 .com&lt;br /&gt;
hqvirusscanner5 .com&lt;br /&gt;
warningmalwarealert5 .com&lt;br /&gt;
hqvirusscanner8 .com&lt;br /&gt;
antivirus-promo-scan9 .com&lt;br /&gt;
worldbestonlinescan9 .com&lt;br /&gt;
antivir-scan-my-pc .com&lt;br /&gt;
antivir-scan-online .com&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;remove-all-pc-adware .com&lt;br /&gt;
antivir-my-pc-scan .com&lt;br /&gt;
leading-malware-scan .com&lt;br /&gt;
leading-antispyware-scan .com&lt;br /&gt;
antivirus-promo-scan .com&lt;br /&gt;
tryantivir-scan .com&lt;br /&gt;
leading-antivirus-scan .com&lt;br /&gt;
megaspywarescan .com&lt;br /&gt;
totalspywarescan .com&lt;br /&gt;
worldsbestantivirscan .com&lt;br /&gt;
awardantivirusscan .com&lt;br /&gt;
winningantivirusscan .com&lt;br /&gt;
tryantivirusscan .com&lt;br /&gt;
worldsbestscan .com&lt;br /&gt;
tryantivir-scanner .com&lt;br /&gt;
worldbestonlinescanner .com&lt;br /&gt;
tryantivirscanner .com&lt;br /&gt;
tryantivirusscanner .com&lt;br /&gt;
hqvirusscanner .com&lt;br /&gt;
worldsbestscanner .com&lt;br /&gt;
antivirscanmycomputer .com&lt;br /&gt;
warningvirusspreads .com&lt;br /&gt;
bewareofvirusattacks .com&lt;br /&gt;
secure.web-software-payments .com&lt;br /&gt;
warningmalwarealert .com&lt;br /&gt;
warningspywarealert .com&lt;br /&gt;
warningvirusalert .com&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SqVH1ByLpLI/AAAAAAAAEIY/XqiNB-GI_nI/s1600-h/hot_news_blackhat_seo_ukrainian_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SqVH1ByLpLI/AAAAAAAAEIY/XqiNB-GI_nI/s200/hot_news_blackhat_seo_ukrainian_3.png" /&gt;&lt;/a&gt;Parked at 193.169.12.70 are also more scareware domains/payment gateways/malware redirectors used in the campaign:&lt;br /&gt;
&lt;b&gt;colonizemoon2010 .com&lt;br /&gt;
blastertroops2011 .com&lt;br /&gt;
virscan-online1 .com&lt;br /&gt;
virscan-live1 .com&lt;br /&gt;
antivirus-promo-scan1 .com&lt;br /&gt;
valueantivirusshop1 .com&lt;br /&gt;
megaspywarescan2 .com&lt;br /&gt;
worldbestonlinescanner2 .com&lt;br /&gt;
hqvirusscanner2 .com&lt;br /&gt;
warningmalwarealert2 .com&lt;br /&gt;
antivirus-promo-scanner3 .com&lt;br /&gt;
bewareofvirusattacks3 .com&lt;br /&gt;
totalspywarescan4 .com&lt;br /&gt;
worldbestonlinescan5 .com&lt;br /&gt;
megaspywarescan5 .com&lt;br /&gt;
totalspywarescan5 .com&lt;br /&gt;
hqvirusscanner5 .com&lt;br /&gt;
warningmalwarealert5 .com&lt;br /&gt;
hqvirusscanner8 .com&lt;br /&gt;
antivirus-promo-scan9 .com&lt;br /&gt;
worldbestonlinescan9 .com&lt;br /&gt;
antivir-scan-my-pc .com &lt;br /&gt;
becomemybestfriend .com&lt;br /&gt;
bravemousepride .com&lt;br /&gt;
antivir-scan-online .com&lt;br /&gt;
emphasis-online .com&lt;br /&gt;
justseethisonline .com&lt;br /&gt;
futureshortsonline .com&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;remove-all-pc-adware .com&lt;br /&gt;
waitforsunrise .com&lt;br /&gt;
funpictureslive .com&lt;br /&gt;
justintimberlakestream .com&lt;br /&gt;
antivir-my-pc-scan .com&lt;br /&gt;
leading-malware-scan .com&lt;br /&gt;
leading-antispyware-scan .com&lt;br /&gt;
antivirus-promo-scan .com&lt;br /&gt;
tryantivir-scan .com&lt;br /&gt;
leading-antivirus-scan .com&lt;br /&gt;
totalspywarescan .com&lt;br /&gt;
worldsbestantivirscan .com&lt;br /&gt;
awardantivirusscan .com&lt;br /&gt;
winningantivirusscan .com&lt;br /&gt;
tryantivirusscan .com&lt;br /&gt;
worldsbestscan .com&lt;br /&gt;
tryantivir-scanner .com&lt;br /&gt;
worldbestonlinescanner .com&lt;br /&gt;
tryantivirscanner .com&lt;br /&gt;
tryantivirusscanner .com&lt;br /&gt;
hqvirusscanner .com&lt;br /&gt;
worldsbestscanner .com&lt;br /&gt;
antivirscanmycomputer .com&lt;br /&gt;
obbeytheriver .com&lt;br /&gt;
obamanewterror .com&lt;br /&gt;
warningvirusspreads .com&lt;br /&gt;
watch2010movies .com&lt;br /&gt;
primeareanetworks .com&lt;br /&gt;
investmenttooltips .com&lt;br /&gt;
executive-officers .com&lt;br /&gt;
newsoverworldhot .com&lt;br /&gt;
management-overview .com&lt;br /&gt;
justthingsyouneedtoknow .com&lt;br /&gt;
criticalmentality .com&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
In between the central redirectors, counters from known domains affiliated with the Ukrainian fan club are also embedded as iFrames - &lt;b&gt;sexualporno .ru/admin/red/counter2.html&lt;/b&gt; (74.54.176.50; Email: skypixre@nm.ru) leading to &lt;b&gt;sexualporno .ru/admin/red/mwcounter.html&lt;/b&gt;. Parked on &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;74.54.176.50&lt;/a&gt; are related domains that were once using the &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;ddanchev-suck-my-dick.php&lt;/a&gt; redirection, such as &lt;b&gt;sexerotika2009 .ru&lt;/b&gt;; &lt;b&gt;celki2009 .ru&lt;/b&gt;; &lt;b&gt;seximalinki .ru&lt;/b&gt; and &lt;b&gt;videoxporno .ru&lt;/b&gt;, as well as the de-facto counter used by the gang - c.hit.ua/hit?i=6001.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SqVM2mXoCSI/AAAAAAAAEIg/HadP3BfGEhc/s1600-h/hot_news_blackhat_seo_ukrainian_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SqVM2mXoCSI/AAAAAAAAEIg/HadP3BfGEhc/s200/hot_news_blackhat_seo_ukrainian_7.png" /&gt;&lt;/a&gt;Does this admin/red directory structure ring a bell? But, of course. In fact the &lt;b&gt;ddanchev-suck-my-dick&lt;/b&gt; redirectors originally introduced by the Ukrainian fan club are still in circulation - for instance not only is &lt;b&gt;videoxporno .ru/admin/red/ddanchev-suck-my-dick.php&lt;/b&gt; (parked at the very same 74.54.176.50) still active, but the gang has pushed an update to all of their campaigns, once again establishing a direct connection between previous ones and the ongoing "News Items" themed one.&lt;br /&gt;
&lt;br /&gt;
The &lt;b&gt;ddanchev-suck-my-dick.php&lt;/b&gt; file has a similar Mac, Firefox and Chrome check just like the U.S federal forms themed campaign, and the original "Hot News" themed campaigns - &lt;i&gt;if (navigator.appVersion.indexOf("Mac")!=-1) window.location="http://www.zml.com/?did=5663";[&lt;/i&gt;. The script also includes a central iFrame from the now known malicious &lt;b&gt;coolinf .info&lt;/b&gt; - &lt;b&gt;dash-store.coolinc .info/images/levittpedofil.html&lt;/b&gt; which redirects to &lt;b&gt;1008.myhome .tv/888.php&lt;/b&gt;, &lt;b&gt;popoz.wo .tc/p/go.php?sid=4&lt;/b&gt; and &lt;b&gt;1009.wo .tc/8/ss.php&lt;/b&gt; to finally load the now known &lt;b&gt;justintimberlakestream .com/?pid=42&amp;amp;sid=8f68b5&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
The bottom line - the Ukrainian "fan club" is a very decent example of a multitasking cybecrime enterprise that is not only systematically abusing all the major Web 2.0 services, but is also directly involved with &lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front-part-two.html"&gt;the Koobface botnet&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Monitoring of their campaigns, and take down actions would continue. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/dissecting-ongoing-us-federal-forms.html"&gt;Dissecting the Ongoing U.S Federal Forms Themed Blackhat SEO Campaign&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/us-federal-forms-blackhat-seo-themed.html"&gt;U.S Federal Forms Blackhat SEO Themed Scareware Campaign Expanding&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/blackhat-seo-campaign-hijacks-us.html"&gt;Blackhat SEO Campaign Hijacks U.S Federal Form Keywords, Serves Scareware &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/peek-inside-managed-blackhat-seo.html"&gt;A Peek Inside the Managed Blackhat SEO Ecosystem &lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Historical OSINT of the group's blackhat SEO campaigns pushing Koobface samples, and the connections between the campaigns:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front-part-two.html"&gt;Movement on the Koobface Front - Part Two&lt;/a&gt; -- detailed account of the domain suspension and direct ISP take down actions against the gang during the last month&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front.html"&gt;Movement on the Koobface Front&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/koobface-come-out-come-out-wherever-you.html"&gt;Koobface - Come Out, Come Out, Wherever You Are&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/05/dissecting-swine-flu-black-seo-campaign.html"&gt;Dissecting a Swine Flu Black SEO Campaign&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;Massive Blackhat SEO Campaign Serving Scareware&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;From Ukrainian Blackhat SEO Gang With Love&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;From Ukrainian Blackhat SEO Gang With Love - Part Two&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukraine-with-scareware-serving.html"&gt;From Ukraine with Scareware Serving Tweets, Bogus LinkedIn/Scribd Accounts, and Blackhat SEO Farms &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/from-ukraine-with-bogus-twitter.html"&gt;From Ukraine with Bogus Twitter, LinkedIn and Scribd Accounts&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/fake-web-hosting-provider-front-end-to.html"&gt;Fake Web Hosting Provider - Front-end to Scareware Blackhat SEO Campaign at Blogspot&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-3635452862403273266?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_P8JLkHQRuk:2t89uMApI14:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_P8JLkHQRuk:2t89uMApI14:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_P8JLkHQRuk:2t89uMApI14:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=_P8JLkHQRuk:2t89uMApI14:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_P8JLkHQRuk:2t89uMApI14:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=_P8JLkHQRuk:2t89uMApI14:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_P8JLkHQRuk:2t89uMApI14:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_P8JLkHQRuk:2t89uMApI14:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=_P8JLkHQRuk:2t89uMApI14:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=_P8JLkHQRuk:2t89uMApI14:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/_P8JLkHQRuk" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-07T22:42:26.255+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_wICHhTiQmrA/SqA_XcuJ3wI/AAAAAAAAEHw/LEJEu4JSnVQ/s72-c/hot_news_blackhat_seo_ukrainian_4_sample_site.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/09/news-items-themed-blackhat-seo-campaign.html</feedburner:origLink></item><item><title>SMS Ransomware Displays Persistent Inline Ads</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/O8MwxWnaq1U/sms-ransomware-displays-persistent.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Thu, 24 Sep 2009 08:56:38 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-427895641759327948</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sp-zObTJnFI/AAAAAAAAEHg/oXIcu9eOvRk/s1600-h/sms_ransomware_browser_hijack_ads_1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sp-zObTJnFI/AAAAAAAAEHg/oXIcu9eOvRk/s200/sms_ransomware_browser_hijack_ads_1.jpg" /&gt;&lt;/a&gt;SMS-based micro-payments are clearly becoming the monetization channel of choice for the majority of cybercriminals engaging in ransomware campaigns. The logic behind this emerging trend is fairly simple, and as everything else in the cybercrime underground these days, it has to do with efficiency.&lt;br /&gt;
&lt;br /&gt;
Compared to micro-payments, the 2008's &lt;a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html"&gt;monetization channel used by GPcode in terms of E-gold and Liberty Reserve accounts&lt;/a&gt; communicated over email -- with cases where the gang wasn't even bothering to respond to infected victims looking for ways to pay the ransom -- looks like a time-consuming and largely inefficient way to "interact" with the victims.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;Another recently released &lt;a href="http://www.symantec.com/connect/blogs/browsers-and-ransoms"&gt;SMS-based ransomware&lt;/a&gt; showing persistent ads within the &lt;a href="http://www.symantec.com/connect/blogs/layers-trojanransompage"&gt;browser sessions of infected victims&lt;/a&gt;, and demanding a premium-rate SMS for removal, is the very latest indication of the micro-payment monetization channel trend.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Sp-4ei6HEbI/AAAAAAAAEHo/4mSuVifxUUI/s1600-h/sms_ransomware_browser_hijack_ads_2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Sp-4ei6HEbI/AAAAAAAAEHo/4mSuVifxUUI/s200/sms_ransomware_browser_hijack_ads_2.jpg" /&gt;&lt;/a&gt;The DIY ransomware is offered for sale at $100, with the typical "value-added" services in the form of managed undetected binaries through crypting. Since the command and control interface is web based (php+mysql), the author is actively experimenting with new features such as scheduled appearing of the ads, inventory of banners and affiliate program links, and the ability to use multiple SMS numbers next to multiple unlocking codes.&lt;br /&gt;
&lt;br /&gt;
Are the currently active ransomware "vendors" trendsetters or are they still in experimental mode?&lt;br /&gt;
&lt;br /&gt;
The business model of SMS-based ransomware is clearly lucrative, especially in situations where cybercriminals are known to combine two or three different monetization tactics. However, compared to the &lt;a href="http://ddanchev.blogspot.com/2009/04/confickers-scarewarefake-security.html"&gt;high profit-margins which cybecriminals earn through the scareware business model&lt;/a&gt;, SMS-based ransomware remains a developing market segment.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/6th-sms-ransomware-variant-offered-for.html"&gt;6th SMS Ransomware Variant Offered for Sale&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/5th-sms-ransomware-variant-offered-for.html"&gt;5th SMS Ransomware Variant Offered for Sale&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/4th-sms-ransomware-variant-offered-for.html"&gt;4th SMS Ransomware Variant Offered for Sale&lt;/a&gt;&lt;br /&gt;
&lt;b&gt; &lt;/b&gt;&lt;a href="http://ddanchev.blogspot.com/2009/05/3rd-sms-ransomware-variant-offered-for.html"&gt;3rd SMS Ransomware Variant Offered for Sale&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/05/sms-ransomware-source-code-now-offered.html"&gt;SMS Ransomware Source Code Now Offered for Sale&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=3197"&gt;New ransomware locks PCs, demands premium SMS for removal&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html"&gt;Who's Behind the GPcode Ransomware?&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/09/identifying-gpcode-ransomware-author.html"&gt;Identifying the Gpcode Ransomware Author &lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-427895641759327948?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=O8MwxWnaq1U:eS94kn_S5ZE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=O8MwxWnaq1U:eS94kn_S5ZE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=O8MwxWnaq1U:eS94kn_S5ZE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=O8MwxWnaq1U:eS94kn_S5ZE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=O8MwxWnaq1U:eS94kn_S5ZE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=O8MwxWnaq1U:eS94kn_S5ZE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=O8MwxWnaq1U:eS94kn_S5ZE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=O8MwxWnaq1U:eS94kn_S5ZE:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=O8MwxWnaq1U:eS94kn_S5ZE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=O8MwxWnaq1U:eS94kn_S5ZE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/O8MwxWnaq1U" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-24T17:56:38.135+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_wICHhTiQmrA/Sp-zObTJnFI/AAAAAAAAEHg/oXIcu9eOvRk/s72-c/sms_ransomware_browser_hijack_ads_1.jpg" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/09/sms-ransomware-displays-persistent.html</feedburner:origLink></item><item><title>Summarizing Zero Day's Posts for August</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/5LuECLRqvE0/summarizing-zero-days-posts-for-august.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Tue, 01 Sep 2009 06:46:11 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-7238152670410412258</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Sp0iAPpOvPI/AAAAAAAAEHQ/WqEjW4z4LNk/s1600-h/ZDNet_Zero_Day_August_2009.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Sp0iAPpOvPI/AAAAAAAAEHQ/WqEjW4z4LNk/s200/ZDNet_Zero_Day_August_2009.png" /&gt;&lt;/a&gt;The following is a brief summary of all of my posts at ZDNet's &lt;a href="http://blogs.zdnet.com/security"&gt;Zero Day&lt;/a&gt; for August.&lt;br /&gt;
&lt;br /&gt;
You can also go through previous summaries for &lt;a href="http://ddanchev.blogspot.com/2009/08/summarizing-zero-days-posts-for-july.html"&gt;July&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/07/summarizing-zero-days-posts-for-june.html"&gt;June&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/06/summarizing-zero-days-posts-for-may.html"&gt;May&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/05/summarizing-zero-days-posts-for-april.html"&gt;April&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/03/summarizing-zero-days-posts-for-march.html"&gt;March&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/03/summarizing-zero-days-posts-for.html"&gt;February&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/02/summarizing-zero-days-posts-for-january.html"&gt;January&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/01/summarizing-zero-days-posts-for.html"&gt;December&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/12/summarizing-zero-days-posts-for.html"&gt;November&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/11/summarizing-zero-days-posts-for-october.html"&gt;October&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/10/summarizing-zero-days-posts-for.html"&gt;September&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/09/summarizing-zero-days-posts-for-august.html"&gt;August&lt;/a&gt; and &lt;a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html"&gt;July&lt;/a&gt;, as well as subscribe to my &lt;a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;amp;s=0&amp;amp;o=1&amp;amp;mode=rss"&gt;personal RSS feed&lt;/a&gt; or &lt;a href="http://feeds.feedburner.com/zdnet/security"&gt;Zero Day's main feed&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Notable articles include - &lt;a href="http://blogs.zdnet.com/security/?p=3872"&gt;Does Twitter's malware link filter really work?&lt;/a&gt;; &lt;a href="http://blogs.zdnet.com/security/?p=4072"&gt;IE8 outperforms competing browsers in malware protection -- again&lt;/a&gt;, and &lt;a href="http://blogs.zdnet.com/security/?p=4097"&gt;Research: 80% of Web users running unpatched versions of Flash/Acrobat &lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;01.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3834"&gt;Dead-finger tech: 3G USB Modem, Prestigio Powerbank 501&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;02.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3872"&gt;Does Twitter's malware link filter really work?&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;03.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3916"&gt;Fake Microsoft patch malware campaign makes a comeback&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;04.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3923"&gt;Plugins compromised in SquirrelMail's web server hack&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;05.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3936"&gt;Absolute Software downplays BIOS rootkit claims&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;06.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3962"&gt;Federal forms themed blackhat SEO campaign serving scareware&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;07.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3993"&gt;Microsoft's Bing invaded by pharmaceutical scammers&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;08.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4007"&gt;Campaign Monitor hacked, accounts used for spamming&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;09.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4024"&gt;New Mac OS X DNS changer spreads through social engineering&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;10.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4072"&gt;IE8 outperforms competing browsers in malware protection -- again&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;11.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4097"&gt;Research: 80% of Web users running unpatched versions of Flash/Acrobat&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;12.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4116"&gt;The most dangerous celebrities to search for in 2009&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;13.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4133"&gt;Source code for Skype eavesdropping trojan in the wild&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;14.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=4139"&gt;Snow Leopard's malware protection only scans for two trojans&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-7238152670410412258?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5LuECLRqvE0:Ntt3djrnfG4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5LuECLRqvE0:Ntt3djrnfG4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5LuECLRqvE0:Ntt3djrnfG4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=5LuECLRqvE0:Ntt3djrnfG4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5LuECLRqvE0:Ntt3djrnfG4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=5LuECLRqvE0:Ntt3djrnfG4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5LuECLRqvE0:Ntt3djrnfG4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5LuECLRqvE0:Ntt3djrnfG4:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=5LuECLRqvE0:Ntt3djrnfG4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=5LuECLRqvE0:Ntt3djrnfG4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/5LuECLRqvE0" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-01T15:46:11.158+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_wICHhTiQmrA/Sp0iAPpOvPI/AAAAAAAAEHQ/WqEjW4z4LNk/s72-c/ZDNet_Zero_Day_August_2009.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/09/summarizing-zero-days-posts-for-august.html</feedburner:origLink></item><item><title>6th SMS Ransomware Variant Offered for Sale</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/9Nc--v59Zuo/6th-sms-ransomware-variant-offered-for.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Mon, 24 Aug 2009 09:14:06 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-4535958837633517909</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SpKXnnpZI0I/AAAAAAAAEGw/0aBUTzjhFCI/s1600-h/6th_sms_ransomware_DIY.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SpKXnnpZI0I/AAAAAAAAEGw/0aBUTzjhFCI/s200/6th_sms_ransomware_DIY.png" /&gt;&lt;/a&gt;"&lt;i&gt;Your copy of Windows has been blocked! You're using an unlicensed version of it! In order to continue using it, you must receive the unlock key. All you have to do is follow these steps: You must send a SMS message. You will receive an activation code once you do so. Enter the code and unlock your copy of Windows.&lt;/i&gt;"&lt;br /&gt;
&lt;br /&gt;
Anticipating the potential for monetization, cybercriminals are investing more time and resources into coming up with new features for their SMS based ransomware releases. Two of the very latest releases indicate their motivation and long-term ambitions into this newly emerged micro-payment ransomware channel.&lt;br /&gt;
&lt;br /&gt;
What's new, is the social engineering element, the self-replication potential through removable media, and the contingency planning through the use of multiple SMS numbers in case one of the numbers gets shut down. Let's go through some of the features of two newly released SMS ransomware variants offered for $20, and $30 respectively.&lt;br /&gt;
&lt;br /&gt;
What's worth emphasizing on in respect to the first release, is that it's Windows 7 compatible, and is the first SMS ransomware that allows scheduled lock down after infection -- presumably, the author included this feature in order to make it harder for the victim to recognize how he got infected at the first place -- as well as multiple SMS numbers for contingency planning.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Key features include:&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;- &lt;/b&gt;Clean interace&lt;br /&gt;
&lt;b&gt;- &lt;/b&gt;Bypasses Safe Mode&lt;br /&gt;
- Locks down the taskbar or any combination of keys that could allow a user to close the application&lt;br /&gt;
- The error message can be customized&lt;br /&gt;
- Ability to use multiple-unlock codes&lt;br /&gt;
- Ability to use multiple SMS numbers from where the activation code will be obtained&lt;br /&gt;
- Ability to lock the system immediately upon infection, or after a given period of tim &lt;br /&gt;
- Auto-starting features, self-removal upon entering the correct activation code, and ensuring that the victim would no longer be infected with this release through the use of mutex-es.&lt;br /&gt;
- This SMS ransomware is Windows 7 compatible&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SpK4rqT2r8I/AAAAAAAAEG4/qRymMyEo6ow/s1600-h/kaspersky_sms_ransomware.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SpK4rqT2r8I/AAAAAAAAEG4/qRymMyEo6ow/s200/kaspersky_sms_ransomware.jpg" /&gt;&lt;/a&gt;The majority of SMS based ransomware is relying on the "Unlicensed Windows Copy" theme, but the first self-replicating through removable media propagation such ransomware is signaling a trend to come - social engineering throuhg impersonation in a typical scareware style. This release can be easily described as the first scareware with micro-payment ransom element offered for sale.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SpK5skExeTI/AAAAAAAAEHA/9Hw5yy-4eXY/s1600-h/kaspersky_sms_ransomware1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SpK5skExeTI/AAAAAAAAEHA/9Hw5yy-4eXY/s200/kaspersky_sms_ransomware1.jpg" /&gt;&lt;/a&gt;Basically, it attempts to impersonate Kaspersky Lab Antivirus Online and trick the infected user into thinking that Kaspersky has detected a piece of malware, has blocked it but since the malware changes its encryption algorithm the user has to send a SMS costing 150 rubles in order to receive the SMS that will block the malware.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SpK565iZ-PI/AAAAAAAAEHI/vr-kCOKxhuk/s1600-h/kaspersky_sms_ransomware2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SpK565iZ-PI/AAAAAAAAEHI/vr-kCOKxhuk/s200/kaspersky_sms_ransomware2.jpg" /&gt;&lt;/a&gt;This release also includes a timer, and a message explaining that re-installing Windows wouldn't change the situation in an attempt to further trick the user into sending the messsage. The release is exclusively released for Windows XP and is not Windows Vista compatible.&lt;br /&gt;
&lt;br /&gt;
Cybercriminals are known to understand the benefits of converging different successful and well proven tactics across different propagation/infection vectors. Now that we've seen &lt;a href="http://blogs.zdnet.com/security/?p=3014"&gt;scareware with elements of ransomware&lt;/a&gt;, as well as &lt;a href="http://www.symantec.com/connect/blogs/layers-trojanransompage"&gt;hijacking a browser session's&lt;/a&gt; ads and &lt;a href="https://www-secure.symantec.com/connect/blogs/browsers-and-ransoms"&gt;demanding ransom to remove the adult content&lt;/a&gt;, it's only a matter of time to witness a micro-payment driven scareware campaign distributed through blackhat SEO and the usual channels.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/5th-sms-ransomware-variant-offered-for.html"&gt;5th SMS Ransomware Variant Offered for Sale&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/4th-sms-ransomware-variant-offered-for.html"&gt;4th SMS Ransomware Variant Offered for Sale&lt;/a&gt;&lt;br /&gt;
&lt;b&gt; &lt;/b&gt;&lt;a href="http://ddanchev.blogspot.com/2009/05/3rd-sms-ransomware-variant-offered-for.html"&gt;3rd SMS Ransomware Variant Offered for Sale&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/05/sms-ransomware-source-code-now-offered.html"&gt;SMS Ransomware Source Code Now Offered for Sale&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://blogs.zdnet.com/security/?p=3197"&gt;New ransomware locks PCs, demands premium SMS for removal&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-4535958837633517909?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9Nc--v59Zuo:XBG0iPK22Vc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9Nc--v59Zuo:XBG0iPK22Vc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9Nc--v59Zuo:XBG0iPK22Vc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=9Nc--v59Zuo:XBG0iPK22Vc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9Nc--v59Zuo:XBG0iPK22Vc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=9Nc--v59Zuo:XBG0iPK22Vc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9Nc--v59Zuo:XBG0iPK22Vc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9Nc--v59Zuo:XBG0iPK22Vc:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=9Nc--v59Zuo:XBG0iPK22Vc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=9Nc--v59Zuo:XBG0iPK22Vc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/9Nc--v59Zuo" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-24T18:14:06.957+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_wICHhTiQmrA/SpKXnnpZI0I/AAAAAAAAEGw/0aBUTzjhFCI/s72-c/6th_sms_ransomware_DIY.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/08/6th-sms-ransomware-variant-offered-for.html</feedburner:origLink></item><item><title>Movement on the Koobface Front - Part Two</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/3haonJCHz1w/movement-on-koobface-front-part-two.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Mon, 07 Sep 2009 07:06:18 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-3811385190295744741</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;b&gt; &lt;/b&gt;&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SouwEdsFTbI/AAAAAAAAEFU/kElNzIVav0E/s1600-h/koobface_twitter_august_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SouwEdsFTbI/AAAAAAAAEFU/kElNzIVav0E/s200/koobface_twitter_august_1.JPG" /&gt;&lt;/a&gt;&lt;b&gt;UPDATE13&lt;/b&gt;:&lt;b&gt; &lt;/b&gt;The domain &lt;b&gt;snimka31082009 .com &lt;/b&gt;has been suspended. Just like the domains listed in UPDATE11, it's worth pointing out that once the PrivacyProtect.org whois records return to their original state, all of the domains are registered using the name Rancho Ranchev -- from Ukraine with typosquatting.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATE12&lt;/b&gt;: A new Koobface domain is in circulation across Facebook - &lt;b&gt;snimka31082009 .com&lt;/b&gt; -- snimka means photo -- which redirects to the Chinese IP (&lt;i&gt;China Railcom Guangdong Shenzhen Subbranch&lt;/i&gt;) offering hosting services for the Koobface gang as of last week - &lt;b&gt;61.235.117.83 /redirectsoft/go/fb_w.php&lt;/b&gt;. The &lt;b&gt;snimka31082009.com &lt;/b&gt;domain is in a process of getting shut down.&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATE11&lt;/b&gt;: The latest Koobface domains &lt;b&gt;masa31082009 .com&lt;/b&gt; - Email: yxlvpewoztjox@gmail.com; &lt;b&gt;pari270809 .com&lt;/b&gt; - Email: baoyshzrcwmraq@gmail.com; &lt;b&gt;rect08242009 .com&lt;/b&gt; and &lt;b&gt;suz11082009 .com&lt;/b&gt; have been suspended.&lt;br /&gt;
&lt;br /&gt;
The Koobface gang has also changed the C&amp;amp;C domain in their latest updated pushed throughout the past couple of days. Interestingly, it's a &lt;a href="http://ddanchev.blogspot.com/2009/07/dissecting-koobface-worms-twitter.html"&gt;subdomain used in the Twitter campaign&lt;/a&gt; from July - &lt;b&gt;cubman32 .net.ua/.sys/?action=ldgen&amp;amp;v=14&lt;/b&gt; and &lt;b&gt;cubman32 .net.ua/.sys/?action=ldgen&amp;amp;f=0&amp;amp;a=-531027389&amp;amp;lang=&amp;amp;v=14&amp;amp;c=0&amp;amp;s=ld&amp;amp;l=1000&amp;amp;ck=0&amp;amp;c_fb=0&amp;amp;c_ms=0&amp;amp;c_hi=0&amp;amp;c_tw=0&amp;amp;c_be=0&amp;amp;c_fr=-2&amp;amp;c_yb=-2&amp;amp;c_tg=0&amp;amp;c_nl=0&amp;amp;c_fu=-2&lt;/b&gt;.&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATE10&lt;/b&gt;: Two new Koobface domains, and a new redirector are in circulation across Facebook - &lt;b&gt;rect08242009 .com&lt;/b&gt; (61.235.117.83)&lt;b&gt; &lt;/b&gt;and &lt;b&gt;pari270809 .com&lt;/b&gt;, which redirects to &lt;b&gt;masa31082009 .com&lt;/b&gt;/go/fb_w.php. The "&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Smc9UjwhxZI/AAAAAAAAD-Y/WQ17qmHSx6U/s1600-h/koobface-thanks-dancho1.PNG"&gt;fan club&lt;/a&gt;" has also introduced updated the malware - web.reg .md/1/&lt;a href="http://www.virustotal.com/analisis/1239da435a6aa3aacd92c6f9ee7b3f030d6411a6e23dc240b1b41cdfdb998885-1251814818"&gt;v2prx.exe&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
The domains, &lt;b&gt;pari270809 .com, rect08242009 .com &lt;/b&gt;and &lt;b&gt;masa31082009 .com &lt;/b&gt;are in a process of getting shut down.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATE9&lt;/b&gt;: Domain &lt;b&gt;zadnik270809 .com - &lt;/b&gt;Email: baoyshzrcwmraq@gmail.com has been suspended.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Sp6KCYv0_LI/AAAAAAAAEHY/IuqlWQbgeWE/s1600-h/koobface_china_september_2009.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Sp6KCYv0_LI/AAAAAAAAEHY/IuqlWQbgeWE/s200/koobface_china_september_2009.png" /&gt;&lt;/a&gt;&lt;b&gt;UPDATE8&lt;/b&gt;:&amp;nbsp;&lt;b&gt; &lt;/b&gt;Koobface reactivated itself once again at &lt;b&gt;61.235.117.83&lt;/b&gt; - &lt;a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL75001"&gt;China Railcom Guangdong Shenzhen Subbranch&lt;/a&gt; - a well known Zeus crimeware C&amp;amp;C, which is also apparently used for automatic hacking of third-party sites through &lt;a href="http://groups.google.com/group/google-safe-browsing-api/browse_thread/thread/fa300f19e9993d1b#"&gt;compromised FTP accounts&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
The gang has also introduced a new domain, used exclusively for Facebook campaigns - &lt;b&gt;zadnik270809 .com&lt;/b&gt; - in particular &lt;b&gt;zadnik270809 .com/youtube.com/w/?video&lt;/b&gt; which loads &lt;b&gt;zadnik270809 .com/youtube.com/w/ups.php&lt;/b&gt; and redirects to a well known Koobface redirector &lt;b&gt;kiano-180809 .com/go/fb_w.php&lt;/b&gt;. &lt;br /&gt;
&lt;br /&gt;
Zadnik means a**hole. Domain suspension and IP take down are in progress.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATE7&lt;/b&gt;: Earlier today, TelosSolutions confirmed that "&lt;i&gt;this customer has been removed from our network&lt;/i&gt;".&lt;b&gt; &lt;/b&gt;Great news taking into consideration the fact that Directi's Abuse Desk has also suspended &lt;b&gt;boomer-110809 .com&lt;/b&gt;, as well as &lt;b&gt;upr200908013 .com&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
The Koobface gang responded to the take down action by once again moving to China, &lt;a href="http://whois.domaintools.com/61.235.117.83"&gt;61.235.117.83&lt;/a&gt; (China Railcom Guangdong Shenzhen Subbranch) in particular. The IP has been taken care of, with all of Koobface campaigns once again in an "inactive stage". It's worth pointing out that &lt;b&gt;kallagoon13 .cn&lt;/b&gt; and &lt;b&gt;allavers .org&lt;/b&gt; are also parked at this Chinese IP, with &lt;a href="https://zeustracker.abuse.ch/monitor.php?host=kallagoon13.cn"&gt;both domains&lt;/a&gt; clearly involved in &lt;a href="https://zeustracker.abuse.ch/monitor.php?host=allavers.org"&gt;Zeus crimeware campaigns&lt;/a&gt;.&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATE6:&lt;/b&gt;&lt;b&gt; &lt;/b&gt;Following the 24 hours downtime, the Koobface gang has found a new home online, courtesy of Telos-Solutions-AS/Telos Solutions LTD, with an ongoing migration of the Koobface C&amp;amp;C and campaign domains to &lt;a href="http://whois.domaintools.com/91.212.127.140"&gt;91.212.127.140&lt;/a&gt;. Take down activities are in progress.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATE5:&lt;/b&gt; Oc3 Networks &amp;amp; Web Solutions Llc abuse team&lt;b&gt; &lt;/b&gt;took care of &lt;a href="http://whois.domaintools.com/67.215.238.178"&gt;67.215.238.178&lt;/a&gt;. All of Koobface worm's campaigns once again redirect to nowhere.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATE4:&lt;/b&gt;&lt;b&gt; &lt;/b&gt;Koobface has been kicked out of China -- again -- courtesy of China's CERT, and is no longer responding to &lt;b&gt;221.5.74.46. &lt;/b&gt;This is the second time that &lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front.html"&gt;the Koobface gang&lt;/a&gt; is using the same IP for its central campaign domains, clearly indicating an ISP which "reserves its right to offer them services in the future once they stop receiving abuse notifications".&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SpJ5W5GevQI/AAAAAAAAEGo/HbfDX0Oow94/s1600-h/Koobface_botnet_pacificrack.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SpJ5W5GevQI/AAAAAAAAEGo/HbfDX0Oow94/s200/Koobface_botnet_pacificrack.png" /&gt;&lt;/a&gt;So which hosting provider's services is &lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front.html"&gt;the Koobface botnet&lt;/a&gt; using for the time being? It's &lt;a href="http://whois.domaintools.com/67.215.238.178"&gt;67.215.238.178&lt;/a&gt; - AS22298 - Netherlands Distinctio Ltd, which they were also using in the beginning of the month. A &lt;a href="http://www.virustotal.com/analisis/83b3cbb82e7dc78b0911395098b7642f530c7b39fc9666ccf70c77f568561134-1251113842"&gt;new domain&lt;/a&gt; is in circulation across social networks/micro blogging services - &lt;b&gt;kiano-180809 .com/go/fb2.php&lt;/b&gt; (67.215.238.178) Email: bigvillyxxx@gmail.com. Take down activities are in progress.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATE3&lt;/b&gt;:&lt;b&gt; &lt;/b&gt;The entire portfolio of Koobface related domains is now parked at &lt;b&gt;221.5.74.46&lt;/b&gt; - AS17816 - CHINA169-GZ CNCGROUP IP network China169 Guangzhou MAN. For instance, &lt;b&gt;xtsd20090815 .com/youtube.com/xexe.php&lt;/b&gt; redirects to the actual IP &lt;b&gt;221.5.74.46 /redirectsoft/go/fb2.php&lt;/b&gt; with piupiu-110809.com/achcheck.php, &lt;b&gt;web.reg.md /1/&lt;a href="http://www.virustotal.com/analisis/570a0761d7dc3b42e6b812302a97ef16a7df7ab03e3b3e0f3e8df8a98ef8e907-1250777095"&gt;prx90.exe&lt;/a&gt;&lt;/b&gt; and &lt;b&gt;web.reg.md/1 /&lt;a href="http://www.virustotal.com/analisis/ed344b3d75d79f02b59813865ae7c65acdc6c385cc5abcd1c3d95b06753fe1d6-1250777115"&gt;prx90.exe&lt;/a&gt;&lt;/b&gt; as phone back locations. Two new components are dropped &lt;b&gt;DDnsFilter.dll&lt;/b&gt; - MD5: 0x8904BCEBACB2B878FF46C5EB0C5C57EB and &lt;b&gt;DnsFilter.sys&lt;/b&gt; - MD5: 0x30DD915396E46824DA92FE70485F7CF8 which &lt;a href="http://www.lavasoft.com/mylavasoft/securitycenter/blog/koobface-still-causing-problems-for-facebook-users"&gt;prevent infected users&lt;/a&gt; from interacting with antivirus vendor sites.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/So1zsgvbCkI/AAAAAAAAEGY/gW88i5FHPbc/s1600-h/koobface_august_c%26c_china.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/So1zsgvbCkI/AAAAAAAAEGY/gW88i5FHPbc/s200/koobface_august_c%26c_china.png" /&gt;&lt;/a&gt;&lt;b&gt;UPDATE2&lt;/b&gt;:&lt;b&gt; &lt;/b&gt;The gang has responded to the take down activities, by using the only IP that wasn't shut down 221.5.74.46, with &lt;b&gt;piupiu-110809 .com&lt;/b&gt;, &lt;b&gt;upr200908013 .com&lt;/b&gt;, and &lt;b&gt;upr200908013 .com&lt;/b&gt; already moved there.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;Interestingly, now that the gang's centralized domains used in the majority of campaigns are not responding thanks the quick reaction of BlueConnex, they've started embedding up to 15 iFrames directly loading IPs from the Koobface botnet. The script is detected as Trojan-Clicker.HTML.IFrame.a. The pattern? Each and every host is serving the fake Facebook page from a similar directory - /0x3E8/. 221.5.74.46 is in a process of getting shut down.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SoxZC2JVnZI/AAAAAAAAEGI/ivHkT9viXpQ/s1600-h/koob_iframes.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SoxZC2JVnZI/AAAAAAAAEGI/ivHkT9viXpQ/s200/koob_iframes.JPG" /&gt;&lt;/a&gt;&lt;b&gt;UPDATE: &lt;/b&gt;Three hours after notification, Blue Square Data Group Services Limited ensures that "&lt;i&gt;the customer has been disconnected permanently&lt;/i&gt;". It's a fact. All of Koobface worm's campaigns currently redirect to nowhere. Let's see for how long.&lt;br /&gt;
&lt;br /&gt;
Kuku Ruku Koobface! What does Koobface has to do with a legendary cocoa cream wafer &lt;a href="http://cotamagat.files.wordpress.com/2007/11/kukuruku.jpg"&gt;Koukou Roukou&lt;/a&gt; sold in the 90's? It's one of new domains introduced over the past seven days (&lt;b&gt;kukuruku-290709 .com&lt;/b&gt; now offline thanks to community efforts).&lt;br /&gt;
&lt;br /&gt;
What is the &lt;a href="http://www.virustotal.com/analisis/7b64f366eb5eb2befc0c601146cce076af782c5271c84f30593dbe98c84e9e06-1250673890"&gt;Koobface&lt;/a&gt; gang up to &lt;a href="http://www.virustotal.com/analisis/ed344b3d75d79f02b59813865ae7c65acdc6c385cc5abcd1c3d95b06753fe1d6-1250673907"&gt;anyway&lt;/a&gt;? Despite that they've randomized the automatically generated directories on the compromised sites (&lt;b&gt;kimchistory.freevar .com/fantasticfi1ms&lt;/b&gt;; &lt;b&gt;tastemasters .ca/freeem0vie&lt;/b&gt;; &lt;b&gt;simonsoderberg .se/mmym0vies&lt;/b&gt;; &lt;b&gt;ekespangs .se/meggavide0&lt;/b&gt;; &lt;b&gt;akesheronline .com/privalesh0w&lt;/b&gt;; &lt;b&gt;belljarstudio .com/bestttube&lt;/b&gt;), the gang continues relying on centralized hosting for its campaigns.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;During the week, they've migrated from &lt;b&gt;67.215.238 .178/redirectsoft/go/fb_s.php&lt;/b&gt; (PacificRack.com) to &lt;b&gt;85.234.141 .92/redirectsoft/go/fb_s.php&lt;/b&gt; (BlueConnex Ltd), interestingly, they did so with all of the their currently active domains, the ones used as central redirection points on the thousands of legitimate/malicious sites participating in their campaigns. Interestingly, merely suspending a domain name wouldn't get you &lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Smc9UjwhxZI/AAAAAAAAD-Y/WQ17qmHSx6U/s1600-h/koobface-thanks-dancho1.PNG"&gt;a personal greeting from the Koobface gang&lt;/a&gt;, since they'll basically register a new one. Getting them kicked out of several different hosting providers simultaneously would. Upon having their newly pushed domains shut down, the gang stopped using domains and switched to the original IP of their hosting provider, once again requiring a direct ISP action, instead of domain registar's one.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sou9P_i_XQI/AAAAAAAAEFc/VYc5yn7IcZ8/s1600-h/koobface_august_latest1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sou9P_i_XQI/AAAAAAAAEFc/VYc5yn7IcZ8/s200/koobface_august_latest1.png" /&gt;&lt;/a&gt;Koobface C&amp;amp;C, central malware campaign domains suspended through community efforts:&lt;br /&gt;
&lt;b&gt;- glavnij20090809 .com&lt;/b&gt; - Email: bigvillyxxx@gmail.com was parked at 85.234.141.92&lt;br /&gt;
&lt;b&gt;- kukuruku-290709 .com&lt;/b&gt; - Email: kuku.ruku.pam@gmail.com was parked at 85.234.141.92&lt;br /&gt;
&lt;b&gt;- superturbo20090809 .com&lt;/b&gt; - Email: bigvillyxxx@gmail.com was parked at 85.234.141.92 (&lt;a href="http://www.zhelezona.ru/i/uploads/2008_07/zh_turbo_gum_3g2g4f.jpg"&gt;Super Turbo&lt;/a&gt; is yet another legendary product sold in the 90's)&lt;br /&gt;
&lt;b&gt;- bombimbom20090809 .com&lt;/b&gt; - Email: bigvillyxxx@gmail.com was parked at 85.234.141.92 (&lt;a href="http://90ie.ru/wp-content/uploads/2009/05/bombibom.jpg"&gt;Bombi Bom&lt;/a&gt; is also a classic chewing gum sold in the 90's in Europe/Eastern Europe)&lt;br /&gt;
&lt;b&gt;- mishkigammy-060809.com&lt;/b&gt; - Email: kuku.ruku.pam@gmail.com was parked at 85.234.141.92&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SovGQ3PcsOI/AAAAAAAAEFk/20zMO7Nx1Fc/s1600-h/koobface_facebook_new_template_august.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SovGQ3PcsOI/AAAAAAAAEFk/20zMO7Nx1Fc/s200/koobface_facebook_new_template_august.png" /&gt;&lt;/a&gt;Currently active Koobface C&amp;amp;C domains, also participating in the CAPTCHA-solving, malware campaigns:&lt;br /&gt;
&lt;b&gt;- piupiu-110809 .com&lt;/b&gt; - 85.234.141.92&lt;br /&gt;
&lt;b&gt;- xtsd20090815 .com&lt;/b&gt; - 85.234.141.92 - Email: bigvillyxxx@gmail.com&lt;br /&gt;
&lt;b&gt;- boomer-110809 .com&lt;/b&gt; - 85.234.141.92&lt;br /&gt;
&lt;b&gt;- upr200908013 .com&lt;/b&gt; - 85.234.141.92 - Email: kfmnmkswrnkcxlgpfdxb68@gmail.com&lt;br /&gt;
&lt;b&gt;- suz11082009 .com&lt;/b&gt; - 85.234.141.92 - Email: xxmgbtwgdhyv@gmail.com&lt;br /&gt;
&lt;b&gt;- upr0306 .com&lt;/b&gt; - 221.5.74.46 China Unicom Guangdong province network - Email: bigvillyxxx@gmail.com &lt;br /&gt;
- &lt;b&gt;findhereandnow .com&lt;/b&gt; - 85.234.141.92 - Email: bigvillyxxx@gmail.com&lt;br /&gt;
&lt;br /&gt;
The CAPTCHA solving&amp;nbsp; process on behalf of the infected victims, is exclusively targeting Google web properties (&lt;b&gt;piupiu-110809 .com/cap/tempgoo/GOO8cdabdfe8d68013c6217ce754a519194.jpg&lt;/b&gt;). Koobface worm's captcha7.dll module is active at:&lt;br /&gt;
&lt;b&gt;- glavnij20090809 .com/cap/?a=get&amp;amp;i=1&amp;amp;v=7&lt;br /&gt;
- suz11082009 .com/cap/?a=get&amp;amp;i=3&amp;amp;v=7&lt;br /&gt;
- boomer-110809 .com/cap/?a=get&amp;amp;i=4&amp;amp;v=7&lt;br /&gt;
- piupiu-110809 .com/cap/?a=get&amp;amp;i=2&amp;amp;v=7&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
BlueConnex Ltd has been notified. The Koobface gang continues enjoying the largest market share of systematic Web 2.0 abuse&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front.html"&gt;Movement on the Koobface Front&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/koobface-come-out-come-out-wherever-you.html"&gt;Koobface - Come Out, Come Out, Wherever You Are &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/dissecting-koobface-worms-twitter.html"&gt;Dissecting Koobface Worm's Twitter Campaign&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/12/dissecting-koobface-worms-december.html"&gt;Dissecting the Koobface Worm's December Campaign &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/11/dissecting-latest-koobface-facebook.html"&gt;Dissecting the Latest Koobface Facebook Campaign&lt;/a&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/12/koobface-gang-mixing-social-engineering.html"&gt;The Koobface Gang Mixing Social Engineering Vectors&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Ukrainian "fan club" and the Koobface connection: &lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/05/dissecting-swine-flu-black-seo-campaign.html"&gt;Dissecting a Swine Flu Black SEO Campaign&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;Massive Blackhat SEO Campaign Serving Scareware&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;From Ukrainian Blackhat SEO Gang With Love&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;From Ukrainian Blackhat SEO Gang With Love - Part Two&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukraine-with-scareware-serving.html"&gt;From Ukraine with Scareware Serving Tweets, Bogus LinkedIn/Scribd Accounts, and Blackhat SEO Farms&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/from-ukraine-with-bogus-twitter.html"&gt;From Ukraine with Bogus Twitter, LinkedIn and Scribd Accounts&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/fake-web-hosting-provider-front-end-to.html"&gt;Fake Web Hosting Provider - Front-end to Scareware Blackhat SEO Campaign at Blogspot&lt;/a&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-3811385190295744741?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3haonJCHz1w:UErvnavlIF8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3haonJCHz1w:UErvnavlIF8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3haonJCHz1w:UErvnavlIF8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=3haonJCHz1w:UErvnavlIF8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3haonJCHz1w:UErvnavlIF8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=3haonJCHz1w:UErvnavlIF8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3haonJCHz1w:UErvnavlIF8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3haonJCHz1w:UErvnavlIF8:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=3haonJCHz1w:UErvnavlIF8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=3haonJCHz1w:UErvnavlIF8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/3haonJCHz1w" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-07T16:06:18.291+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_wICHhTiQmrA/SouwEdsFTbI/AAAAAAAAEFU/kElNzIVav0E/s72-c/koobface_twitter_august_1.JPG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front-part-two.html</feedburner:origLink></item><item><title>Dissecting the Ongoing U.S Federal Forms Themed Blackhat SEO Campaign</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/xggIcmuAwo4/dissecting-ongoing-us-federal-forms.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Fri, 18 Sep 2009 09:26:09 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-6037640942961164232</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SoqnFDIk0hI/AAAAAAAAEDc/tV6fOcPlQ6U/s1600-h/blackhat_seo_tax_latest2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SoqnFDIk0hI/AAAAAAAAEDc/tV6fOcPlQ6U/s200/blackhat_seo_tax_latest2.png" /&gt;&lt;/a&gt;AltusHost Inc, the company whose services were exclusively used in the &lt;a href="http://ddanchev.blogspot.com/2009/08/blackhat-seo-campaign-hijacks-us.html"&gt;blackhat SEO campaign&lt;/a&gt; using &lt;a href="http://ddanchev.blogspot.com/2009/08/us-federal-forms-blackhat-seo-themed.html"&gt;U.S Federal Forms theme for scareware service purposes&lt;/a&gt;, has finally responded to the abuse notifications sent seven days ago stating that "&lt;i&gt;the sites have been terminated&lt;/i&gt;". Such a slow response once again proves that dysfunctional abuse departments increase the lifecycle of a malware/spam/phishing campaign by not taking it down when it's most actively gaining momentum.&lt;br /&gt;
&lt;br /&gt;
(For historical OSINT research, the following domains not previously listed were in circulating during the past week - &lt;b&gt;thwovretgi .com&lt;/b&gt; - 91.214.44.239 - Email: joby47619@msn.com; &lt;b&gt;shtifobpy .com&lt;/b&gt; - 91.214.44.210 - Email: hiraldo13686@hotmail.com; &lt;b&gt;vodcotha .com&lt;/b&gt; - 91.214.44.203 - Email: jamarcus59884@yahoo.com; &lt;b&gt;stromiko .com&lt;/b&gt; - Email: hyacinthiemccolman@gmail.com; &lt;b&gt;ceslyemsof .com&lt;/b&gt; - 91.214.44.205 - Email: brisco68781@lycos.com;&amp;nbsp; &lt;b&gt;ejeifyevy .com&lt;/b&gt; - 91.214.44.208 - Email: brisco68781@lycos.com; &lt;b&gt;kuhatjidd .com&lt;/b&gt; - 91.214.44.203 - Email: khrista12110@hotmail.com ) &lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SoqpC84K6oI/AAAAAAAAEDk/RjDNNtyA2eg/s1600-h/blackhat_seo_tax_latest5_contigency_hosting.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SoqpC84K6oI/AAAAAAAAEDk/RjDNNtyA2eg/s200/blackhat_seo_tax_latest5_contigency_hosting.png" /&gt;&lt;/a&gt;How did the cybercriminals respond? By proving that this blackhat SEO campaign has been well planed and coordinate a long time before it was executed in the wild. For the time being, it relies on a combination of legitimate U.K based sites, the result of a evident compromise of &lt;a href="http://www.web-mania.com/"&gt;Web Hosting Mania&lt;/a&gt; due to the fact that all the affected legitimate sites are hosted there, a growing portfolio of &lt;b&gt;.cc&lt;/b&gt; tld domains, automatic abuse of free services such as &lt;b&gt;myftpsite.net&lt;/b&gt;; &lt;b&gt;dns2go.com&lt;/b&gt;; &lt;b&gt;dynodns.net&lt;/b&gt;; &lt;b&gt;thebbs.org&lt;/b&gt;, and systematic pushing of new scareware variants/redirector and scareware domains, which explains the low generic detection rate of all the samples obtained.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SoquQLktZwI/AAAAAAAAEDs/mFbh2WiDBf4/s1600-h/blackhat_seo_tax_latest9.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SoquQLktZwI/AAAAAAAAEDs/mFbh2WiDBf4/s200/blackhat_seo_tax_latest9.JPG" /&gt;&lt;/a&gt;Moreover, not only did the blackhat SEO themes expanding in the typical randomly generated junk that has naturally been crawled by public search engines, but also, according to publicly obtainable statistics, millions of users (collectively) have already visited the landing sites, with 42.80% of the referring site for a particular domain coming from &lt;b&gt;thebbs.org&lt;/b&gt; and 31.97% from Google - their tactics are actively hijacking millions of users already.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Soq6gXyvxAI/AAAAAAAAED0/OLtMdWv_3Mg/s1600-h/blackhat_seo_tax_latest15_LIVE_obfuscation.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Soq6gXyvxAI/AAAAAAAAED0/OLtMdWv_3Mg/s200/blackhat_seo_tax_latest15_LIVE_obfuscation.JPG" /&gt;&lt;/a&gt;Let's dissect the latest developments in the ongoing blackhat SEO campaign, list the participating scareware/blackhat SEO/redirection domains, the various monetization tactics going beyond scareware, as well as discuss some of the innovations used in the javascript obfuscation which makes it virtually impossible for a crawler to detect that the site is malicious.&lt;br /&gt;
&lt;br /&gt;
Key summary points:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;U.K based hosting provider Web Mania Hosting appears to be compromised due to the fact that all the abused legitimate sites are hosted there&lt;/li&gt;
&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;the redirection and scareware domain/binary are updated two times during 24 hours period of time&lt;/li&gt;
&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.virustotal.com/analisis/f01203ceee6cd085ef6f9f7bb9b31a9624e3ac896e5ee6b1c7fa0b09fed19e1a-1250697346"&gt;the&lt;/a&gt; &lt;a href="http://www.virustotal.com/analisis/9d6d7da22782cbeb4bc8afb18c3e5cc293d2ab23e789c488e50005ab4e81cd91-1250094783"&gt;scareware&lt;/a&gt; &lt;a href="http://www.virustotal.com/analisis/152e47c96b98c2281cda6f845a7667410c633017202b00c69c53f3e674c4ae3b-1250720818"&gt;has&lt;/a&gt; a &lt;a href="http://www.virustotal.com/analisis/0bdbf0f03582a65cc204f3202dc144c0839ab2674c7dc594bc10efccaf8000ec-1250598668"&gt;very&lt;/a&gt; &lt;a href="http://www.virustotal.com/analisis/89b5dc3be9e117aef82c00170e6bfeb8efd7127f16abdb7b81553fadb19d0b48-1250764517"&gt;low&lt;/a&gt; &lt;a href="http://www.virustotal.com/analisis/681a877090b8e2275d781fadd7b9e1fb7700446365cc528db224d67b94cd548a-1250026869"&gt;generic&lt;/a&gt; &lt;a href="http://www.virustotal.com/analisis/984fc08011e48dc942445725861554b973b1d13e9c6b0911d94336a890bfb7ef-1250668935"&gt;detection&lt;/a&gt; &lt;a href="http://www.virustotal.com/analisis/c9d7622b42687d62d20c06da811a6d86fcde60040e717f8e6dad3df590b8014b-1250698877"&gt;rate&lt;/a&gt; &lt;a href="http://www.virustotal.com/analisis/058a3a3c9cd3be6cbbcfba65f57a81a5310736f8c2e1d7decc4bdb89a4d78df2-1250525395"&gt;due&lt;/a&gt; &lt;a href="http://www.virustotal.com/analisis/e081d27500bb839d337c2a2591b0111adc82fa55aa996d180d7b0989c8d64234-1250793069"&gt;to&lt;/a&gt; their &lt;a href="http://www.virustotal.com/analisis/b931af1b61e92582986106204c9266b18393215ce2ab430463036e6806b85daf-1250622525"&gt;persistence&lt;/a&gt; in &lt;a href="http://www.virustotal.com/analisis/b931af1b61e92582986106204c9266b18393215ce2ab430463036e6806b85daf-1250592698"&gt;updating&lt;/a&gt; it&lt;/li&gt;
&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;all the scareware samples continue phoning back to several domains parked at 78.46.201.90&lt;/li&gt;
&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;the cybercriminals have introduced multiple monetization tactics through pay-per-click malware-friendly search engines&lt;/li&gt;
&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;a central redirection point (&lt;b&gt;a-n-d-the .com/wtr/router.php&lt;/b&gt;) used in this campaign was used by the &lt;a href="http://ddanchev.blogspot.com/2008/03/zdnet-asia-and-torrentreactor-iframe-ed.html"&gt;RBN/customer of the RBN in massive iFrame injection attacks&lt;/a&gt; abusing input validation flaws within high profile sites over an year ago&lt;/li&gt;
&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;sampled scareware adds the following registry entry &lt;i&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\6A36EA6E11EAAECDF5E540DEF2149079] plxxh = "Dujaq!!&lt;/i&gt;" - Dujaq!! means "Bl*w me!!"&lt;br /&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;the blackhat SEO gang is using a unique javascript obfuscation which I originally stumbled upon a couple of months ago while assessing another blackhat SEO courtesy of the &lt;a href="http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front.html"&gt;Ukrainian "fan club", the one with the Koobface connection&lt;/a&gt;. It relies on dynamically generated code spoofing &lt;b&gt;go.live.com&lt;/b&gt; and &lt;b&gt;rds.yahoo.com&lt;/b&gt; random URLs for evasion purposes. The only vendor that detects it is McAfee-GW-Edition as &lt;a href="http://www.virustotal.com/analisis/caaf95642abad63d9e8460a474d0d3c8bbb9c00a683ac7fbbc63e86355183790-1250029889"&gt;Heuristic.BehavesLike.JS.CodeUnfolding.A&lt;/a&gt;&lt;br /&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Soq7ApcupYI/AAAAAAAAED8/RST7n1RQqX0/s1600-h/blackhat_seo_tax_latest12.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Soq7ApcupYI/AAAAAAAAED8/RST7n1RQqX0/s200/blackhat_seo_tax_latest12.JPG" /&gt;&lt;/a&gt;Compromised legitimate domains at &lt;a href="http://www.web-mania.com/"&gt;Web Hosting Mania&lt;/a&gt; currently in circulation:&lt;br /&gt;
&lt;b&gt;ladydestiny .com&lt;br /&gt;
marchbrook.co .uk&lt;br /&gt;
mgwooldridge.co .uk&lt;br /&gt;
midfleet .com&lt;br /&gt;
mikedz.co .uk&lt;br /&gt;
millypeds.co .uk&lt;br /&gt;
mitchameditorial.co .uk&lt;br /&gt;
moddeydhoomcc.co .uk&lt;br /&gt;
monkeyfist.co .uk&lt;br /&gt;
morita.co .uk&lt;br /&gt;
mosoul.co .uk&lt;br /&gt;
mrbuzzhard.co .uk&lt;br /&gt;
mtbpigs.co .uk&lt;br /&gt;
mysticspirals.co .uk&lt;br /&gt;
mythagostudios .com&lt;br /&gt;
neilwebsterhoundtrailing.co .uk&lt;br /&gt;
newmarskecricketclub.co .uk&lt;br /&gt;
oneintenrock.co .uk&lt;br /&gt;
pcook.co .uk&lt;br /&gt;
pengineer.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Soq7vOhPBDI/AAAAAAAAEEE/RrbCtg0RD4Y/s1600-h/blackhat_seo_tax_latest13.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Soq7vOhPBDI/AAAAAAAAEEE/RrbCtg0RD4Y/s200/blackhat_seo_tax_latest13.JPG" /&gt;&lt;/a&gt;Blackhat SEO domains redirecting to scareware, currently in circulation using a .cc tld extension:&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;b&gt;agjjgtfyi .cc&lt;/b&gt; - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;ckckoo .cc&lt;/b&gt; - Email: briettamacpherson@gmail.com&lt;br /&gt;
&lt;b&gt;eunlabkce .cc&lt;/b&gt; - 93.170.134.175 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;ewjwjiavg .cc&lt;/b&gt; - 74.206.242.22 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;fgodvsli .cc&lt;/b&gt; - 93.170.133.205 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;fgodvsli .cc&lt;/b&gt; - 93.170.133.205 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;fyecdizt .cc&lt;/b&gt; 93.170.156.119 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;hgzondsul .cc&lt;/b&gt; - 174.137.171.69 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;iiuuoo .cc&lt;/b&gt; - Email: briettamacpherson@gmail.com&lt;br /&gt;
&lt;b&gt;ijnteqc .cc&lt;/b&gt; - 93.170.130.105 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;irolopl .cc&lt;/b&gt; - 93.170.134.203 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;jglcbngvu .cc&lt;/b&gt; -&amp;nbsp; 93.170.130.217 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;jpydmee .cc&lt;/b&gt; - 93.170.133.247 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;kdwwwwon .cc&lt;/b&gt; - 93.170.134.231 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;kgowncgi .cc&lt;/b&gt; - 93.170.154.179 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;lmhhsnd .cc&lt;/b&gt; - 93.170.156.105 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Soq84tJ2NeI/AAAAAAAAEEU/WyfZKSFp7oM/s1600-h/blackhat_seo_tax_latest8_redirectors.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Soq84tJ2NeI/AAAAAAAAEEU/WyfZKSFp7oM/s200/blackhat_seo_tax_latest8_redirectors.png" /&gt;&lt;/a&gt;&lt;b&gt;mezkopq .cc&lt;/b&gt; - 93.170.129.75 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;mvsoomw .cc&lt;/b&gt; - 93.170.131.66 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;njfgfbd .cc&lt;/b&gt; - 93.170.156.21 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;nsdgkrge .cc&lt;/b&gt; - 93.170.153.98 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;nselkss .cc&lt;/b&gt; - 93.170.130.245 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;owudfnay .cc&lt;/b&gt; - 93.170.131.178 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;pfjfsiunt .cc&lt;/b&gt; - 93.170.151.80 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;piqvrrugd .cc&lt;/b&gt; - 93.170.156.63 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;rroiqbznj .cc&lt;/b&gt; - 93.170.134.35 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;ssyydqyh .cc&lt;/b&gt; - 93.170.131.206 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;sucdugon .cc&lt;/b&gt; - 93.170.154.100 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;tftrwxlg .cc&lt;/b&gt; - 93.170.130.133 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;tirtop .cc&lt;/b&gt; - 188.72.198.21 - Email: elaynedangubic@gmail.com&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Soq9I_Vhk9I/AAAAAAAAEEc/9Cx7eWgPqXQ/s1600-h/blackhat_seo_tax_latest10.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Soq9I_Vhk9I/AAAAAAAAEEc/9Cx7eWgPqXQ/s200/blackhat_seo_tax_latest10.JPG" /&gt;&lt;/a&gt;&lt;b&gt;uclrwpyp .cc&lt;/b&gt; - 93.170.131.38 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;uomfchbj .cc&lt;/b&gt; - 93.170.131.10 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;vrmmnicl .cc&lt;/b&gt; - 93.170.151.10 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;vtgisihjy .cc&lt;/b&gt; - 93.170.133.163 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;vwyldlbe .cc&lt;/b&gt; - 188.72.204.57 - Email: brigidadorion@gmail.com&lt;br /&gt;
&lt;b&gt;vzlbamuvs .cc&lt;/b&gt; - 93.170.130.49 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;wgyxrmtld .cc&lt;/b&gt; - 93.170.152.226 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;xisuuzos .cc&lt;/b&gt; - 93.170.134.77 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;xlkzmqiw .cc&lt;/b&gt; - 93.170.131.234 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;zirtop .cc&lt;/b&gt; - Email: elaynedangubic@gmail.com&lt;br /&gt;
&lt;b&gt;zmtkpugbz .cc&lt;/b&gt; - 93.170.130.189 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;b&gt;zncutvk .cc&lt;/b&gt; - 174.137.171.117 - Email: susan@michiganfarms.com&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Sow3WqLEwVI/AAAAAAAAEFw/ukVVsQH1vfA/s1600-h/blackhat_seo_sample2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Sow3WqLEwVI/AAAAAAAAEFw/ukVVsQH1vfA/s200/blackhat_seo_sample2.JPG" /&gt;&lt;/a&gt;New blackhat SEO domains portfolio using NOC4Hosts Inc's services:&lt;br /&gt;
&lt;b&gt;rebuwe .net&lt;/b&gt; - 206.51.230.97&lt;br /&gt;
&lt;b&gt;sivezo .net&lt;/b&gt; - 206.51.230.98&lt;br /&gt;
&lt;b&gt;mipola .net&lt;/b&gt; - 206.51.230.95&lt;br /&gt;
&lt;b&gt;kowipe .net&lt;/b&gt; - 206.51.230.92&lt;br /&gt;
&lt;b&gt;kerobo .net&lt;/b&gt; - 206.51.230.90&lt;br /&gt;
&lt;b&gt;gelupe .net&lt;/b&gt; - 206.51.230.104&lt;br /&gt;
&lt;b&gt;fuquwe .net&lt;/b&gt; - 206.51.230.103&lt;br /&gt;
&lt;b&gt;hyduve .net&lt;/b&gt; - 206.51.230.200&lt;br /&gt;
&lt;b&gt;bisehu .net&lt;/b&gt; - 206.51.230.99&lt;br /&gt;
&lt;b&gt;wypule .net&lt;/b&gt; - 206.51.230.95&lt;br /&gt;
&lt;b&gt;xylucy .net&lt;/b&gt; - 206.51.230.97&lt;br /&gt;
&lt;b&gt;xulady .net&lt;/b&gt; - 206.51.230.96&lt;br /&gt;
&lt;b&gt;lyqyte .net&lt;/b&gt; - 206.51.230.94&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sow3lmC7yII/AAAAAAAAEF4/nBzUlIIHDds/s1600-h/blackhat_seo_sample1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sow3lmC7yII/AAAAAAAAEF4/nBzUlIIHDds/s200/blackhat_seo_sample1.JPG" /&gt;&lt;/a&gt;&lt;b&gt;nimygu .net &lt;/b&gt;- 206.51.230.96&lt;br /&gt;
&lt;b&gt;zuziki .net &lt;/b&gt;- 206.51.230.98&lt;br /&gt;
&lt;b&gt;symiza .net&lt;/b&gt; - 206.51.230.99&lt;br /&gt;
&lt;b&gt;bisehu .net&lt;/b&gt; - 206.51.230.99&lt;br /&gt;
&lt;b&gt;msrxdk .com &lt;/b&gt;- 188.72.192.78 - Email: charlenecrewshgkn@yahoo.com&lt;br /&gt;
&lt;b&gt;kimuka .net&lt;/b&gt; - 188.72.192.78 - Email: charlenecrewshgkn@yahoo.com&lt;br /&gt;
&lt;b&gt;ylkbin .com&lt;/b&gt; - 188.72.192.81 &lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Soq-xcB2XMI/AAAAAAAAEEk/TvjRSEJ6gjs/s1600-h/blackhat_seo_tax_latest11.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Soq-xcB2XMI/AAAAAAAAEEk/TvjRSEJ6gjs/s200/blackhat_seo_tax_latest11.png" /&gt;&lt;/a&gt;Portfolio of scareware domains participating in the blackhat SEO campaing, parked at 83.133.126.155; 88.198.107.25; 88.198.120.177; 91.212.107.5; 94.102.51.26; 188.40.61.236; 62.90.136.237; 91.212.127.200; 78.46.251.43; 91.212.107.5; 69.4.230.204; 78.46.251.43; 88.198.107.25; 88.198.105.149; 88.198.233.225; 93.158.114.132:&lt;br /&gt;
&lt;b&gt;antispywaretotalscan9 .com&lt;/b&gt; - 213.163.89.60; 89.47.237.55; 89.248.174.61 - Email: info@siggy.com&lt;br /&gt;
&lt;b&gt;antispywaretotalscan5 .com&lt;/b&gt; - Email: info@siggy.com&lt;br /&gt;
&lt;b&gt;antispywaretotalscan6 .com&lt;/b&gt; - Email: info@siggy.com&lt;br /&gt;
&lt;b&gt;antispywaretotalscan8 .com&lt;/b&gt; - Email: info@siggy.com&lt;br /&gt;
&lt;b&gt;antispywaretotalscan9 .com&lt;/b&gt; - Email: info@siggy.com&lt;br /&gt;
&lt;b&gt;delete-all-virus05 .com&lt;/b&gt; - Email: sales@naukrit.com&lt;br /&gt;
&lt;b&gt;delete-all-virus07 .com&lt;/b&gt; - Email: sales@naukrit.com&lt;br /&gt;
&lt;b&gt;delete-all-virus09 .com&lt;/b&gt; - Email: sales@naukrit.com &lt;br /&gt;
&lt;b&gt;delete-all-virus03 .com &lt;/b&gt;- 213.163.89.60; 88.198.233.225; 91.213.126.100; 193.169.12.70 - Email: sales@naukrit.com&lt;br /&gt;
&lt;b&gt;clean-all-spyware10 .com&lt;/b&gt; - Email: crbarnes@uvic.ca&lt;br /&gt;
&lt;b&gt;remove-all-adware01 .com&lt;/b&gt; - Email: info@nco.com.cn&lt;br /&gt;
&lt;b&gt;clean-all-spyware01 .com&lt;/b&gt; - Email: crbarnes@uvic.ca&lt;br /&gt;
&lt;b&gt;fast-virus-scan2 .com&lt;/b&gt; - Email: courseinfo@greenwich.ac.uk&lt;br /&gt;
&lt;b&gt;remove-all-spyware03 .com&lt;/b&gt; - Email: info@nco.com.cn&lt;br /&gt;
&lt;b&gt;fast-virus-scan4 .com&lt;/b&gt; - Email: courseinfo@greenwich.ac.uk&lt;br /&gt;
&lt;b&gt;clean-all-spyware05 .com&lt;/b&gt; - Email: crbarnes@uvic.ca&lt;br /&gt;
&lt;b&gt;best-virus-scanner5 .com&lt;/b&gt; - Email: info@ecomsol.com&lt;br /&gt;
&lt;b&gt;remove-all-spyware07 .com&lt;/b&gt; - Email: info@nco.com.cn&lt;br /&gt;
&lt;b&gt;fast-virus-scan7 .com&lt;/b&gt; - Email: courseinfo@greenwich.ac.uk &lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;005threats-scanner .com &lt;/b&gt;&lt;br /&gt;
&lt;b&gt;09computerquickscan .com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;005yourprivatescanner .com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;online-systemscan .net&lt;/b&gt; - Email: gertrudeedickens@text2re.com&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;best-spyware-scan01 .com&lt;/b&gt; - Email: info@viter-media.com &lt;br /&gt;
&lt;b&gt;online-antivir-scan09 .com&lt;/b&gt; - Email: contacts@stevens-media.com&lt;br /&gt;
&lt;b&gt;checkviruszone .com&lt;/b&gt; - Email: gertrudeedickens@text2re.com&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SrO0C22Vh0I/AAAAAAAAEKo/JCkbrspSDKw/s1600-h/september_ukraine_blackhat_seo.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SrO0C22Vh0I/AAAAAAAAEKo/JCkbrspSDKw/s200/september_ukraine_blackhat_seo.png" /&gt;&lt;/a&gt;&lt;b&gt;guardsearch .net&lt;/b&gt; - Email: gertrudeedickens@text2re.com &lt;br /&gt;
&lt;b&gt;protection-check07 .com&lt;/b&gt; - Email: info@democraticyouth.com &lt;br /&gt;
&lt;b&gt;malwareinternetscanner03 .com&lt;/b&gt; - Email: kathy@nj-steams.com &lt;br /&gt;
&lt;b&gt;best-spyware-scan03 .com&lt;/b&gt; - Email: info@viter-media.com &lt;br /&gt;
&lt;b&gt;antispywarescanner08 .com&lt;/b&gt; - Email: info@cpehn.org &lt;br /&gt;
&lt;b&gt;antivirusonlinescan03 .com&lt;/b&gt; - Email: kathy@nj-steams.com &lt;br /&gt;
&lt;b&gt;quick-virus-scanner02 .com&lt;/b&gt; - Email: info@person.k112.nc.us &lt;br /&gt;
&lt;b&gt;securedlivescan .com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;superb-virus-scan09 .com &lt;/b&gt;- Email: tours@admiralgroup.co.uk&lt;b&gt;&lt;br /&gt;
superb-antivir-scan01 .com &lt;/b&gt;- Email: tours@admiralgroup.co.uk&lt;b&gt;&lt;br /&gt;
intellectual-vir-scan09 .com &lt;/b&gt;- Email: info@worldlifehencey.com&lt;b&gt;&lt;br /&gt;
intellectual-vir-scan08 .com &lt;/b&gt;- Email: info@worldlifehencey.com&lt;b&gt;&lt;br /&gt;
private-antivirus-scannerv2 .com &lt;/b&gt;- Email: webmaster@parun.co.kr&amp;nbsp; &lt;br /&gt;
&lt;b&gt;reliable-scanner01 .com&lt;/b&gt; - Email: info@cansupply.com &lt;br /&gt;
&lt;b&gt;superb-virus-scan07 .com&lt;/b&gt; - Email: tours@admiralgroup.co.uk&lt;br /&gt;
&lt;b&gt;antivirus-online-scan8 .com&lt;/b&gt; - Email: webmaster@TangoDance.cn  &lt;br /&gt;
&lt;b&gt;best-antivirus3 .com&lt;/b&gt; - Email: info@legtimeprime.com&lt;br /&gt;
&lt;b&gt;live-virus-scanner5 .com&lt;/b&gt; - Email: info@infy-tasks.com &lt;br /&gt;
&lt;b&gt;antivirus-online-scan4 .com&lt;/b&gt; - Email: pranky-marie@yahoo.com &lt;br /&gt;
&lt;b&gt;antispyware-scanner5 .com&lt;/b&gt; - Email: janny.mar123@yahoo.com &lt;br /&gt;
&lt;b&gt;antivirus-online-scan5 .com&lt;/b&gt; - Email: pranky-marie@yahoo.com &lt;br /&gt;
&lt;b&gt;live-virus-scanner7 .com&lt;/b&gt; - Email: info@infy-tasks.com&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SrE-Tsf7CyI/AAAAAAAAEKg/InnVJG5sSu8/s1600-h/ukraine_scareware_blackhat_seo_september.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SrE-Tsf7CyI/AAAAAAAAEKg/InnVJG5sSu8/s200/ukraine_scareware_blackhat_seo_september.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;b&gt;clean-all-spyware .com&lt;/b&gt; - Email: jdemagis@rocheste.ganet.com&amp;nbsp; &lt;br /&gt;
&lt;b&gt;getyoursecuritynowv2 .com&lt;/b&gt; - Email: info@meat-beaf.com.cn &lt;br /&gt;
&lt;b&gt;getyourantivirusv3 .com&lt;/b&gt; - Email: info@meat-beaf.com.cn &lt;br /&gt;
&lt;b&gt;getyourpcsecurev3 .com&lt;/b&gt; - Email: info@meat-beaf.com.cn &lt;br /&gt;
&lt;b&gt;antivirus-scannerv12 .com&lt;/b&gt; - Email: info@chinatownnetwork.com.cn &lt;br /&gt;
&lt;b&gt;safeonlinescannerv4 .com&lt;/b&gt; - Email: steg.greg1992@yahoo.com &lt;br /&gt;
&lt;b&gt;check-for-malwarev3 .com&lt;/b&gt; - Email: al@bis-solutions.com &lt;br /&gt;
&lt;b&gt;check-your-pc-onlinev3 .com&lt;/b&gt; - Email: al@bis-solutions.com &lt;br /&gt;
&lt;b&gt;searchurlguide .com&lt;/b&gt; - 64.86.16.9 - Email:powell.john11@gmail.com&lt;br /&gt;
&lt;b&gt;securitypad .net&lt;/b&gt; - 206.53.61.70 - Email: gertrudeedickens@text2re.com&lt;br /&gt;
&lt;b&gt;prestotunerst .cn&lt;/b&gt; - 64.86.16.210 - Email: unitedisystems@gmail.com &lt;br /&gt;
&lt;b&gt;officesecuritysupply .com&lt;/b&gt; - Email: Ronald.T.Samora@spambob.com&lt;br /&gt;
&lt;b&gt;securityread .com&lt;/b&gt; - Email: Anna.R.Helm@dodgit.com&lt;br /&gt;
&lt;b&gt;scanasite .com&lt;/b&gt; - Email: Carol.J.Hipp@mailinator.com&lt;br /&gt;
&lt;b&gt;cheapsecurityscan .com&lt;/b&gt; - Email: Kevin.L.Linkous@trashymail.com&lt;br /&gt;
&lt;b&gt;securitysupplycenter .com&lt;/b&gt; - Email: Janet.R.Vasquez@spambob.com&lt;br /&gt;
&lt;b&gt;best-folder-scanv3 .com&lt;/b&gt; - Email: info@best-util-til.com &lt;br /&gt;
&lt;b&gt;online-best-scanv3 .com&lt;/b&gt; - Email: public@cropfactor.in  &lt;br /&gt;
&lt;b&gt;online-defenderv9 .com&lt;/b&gt; - Email: public@cropfactor.in&lt;br /&gt;
&lt;b&gt;antispyware-live-scanv3 .com&lt;/b&gt; - Email: ervin1981rolf@yahoo.com&lt;br /&gt;
&lt;b&gt;antispywarelivescanv5 .com&lt;/b&gt; - Email: sales.in@bauhmerhhs.com&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SpJ2HPwabMI/AAAAAAAAEGg/fBqLS_xeEGo/s1600-h/seo_tax_forms_scareware.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SpJ2HPwabMI/AAAAAAAAEGg/fBqLS_xeEGo/s200/seo_tax_forms_scareware.png" /&gt;&lt;/a&gt;&lt;b&gt;antispyware-online-scanv7 .com&lt;/b&gt; - Email: ervin1981rolf@yahoo.com&lt;br /&gt;
&lt;b&gt;basicsystemscannerv8 .com&lt;/b&gt; - Email: changhong@corpdefence.cn&lt;br /&gt;
&lt;b&gt;bestpersonalprotectionv2 .com&lt;/b&gt; - Email: cfaa1996@yahoo.com.cn&lt;br /&gt;
&lt;b&gt;bestpersonalprotectionv7 .com&lt;/b&gt; - Email: cfaa1996@yahoo.com.cn&lt;br /&gt;
&lt;b&gt;computer-antivirus-scanv9 .com&lt;/b&gt; - Email: melaniestarmelanie@yahoo.com&lt;br /&gt;
&lt;b&gt;fastvirusscanv6 .com&lt;/b&gt; - Email: info@rasystems.com&lt;br /&gt;
&lt;b&gt;govirusscanner .com&lt;/b&gt; - Email: contact@demoninchina.com&lt;br /&gt;
&lt;b&gt;mysafecomputerscan .com&lt;/b&gt; - Email: acurtis@stevens.com&lt;br /&gt;
&lt;b&gt;onlineantispywarescanv6 .com&lt;/b&gt; - Email: czoao@hotmail.com&lt;br /&gt;
&lt;b&gt;online-antivir-scanv2 .com&lt;/b&gt; - Email: iren.g@sysintern.in&lt;br /&gt;
&lt;b&gt;onlinebestscannerv3 .com&lt;/b&gt; - Email: info@srilanka.cn&lt;br /&gt;
&lt;b&gt;onlinepersonalscanner .com&lt;/b&gt; - Email: info@srilanka.cn&lt;br /&gt;
&lt;b&gt;onlineproantivirusscan .com&lt;/b&gt; - Email: addworld@freebbmail.com&lt;br /&gt;
&lt;b&gt;online-pro-antivirus-scan .com&lt;/b&gt; - Email: findz@freebbmail.com&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Soq-8eIaCCI/AAAAAAAAEEs/-wGR6uKPtOQ/s1600-h/blackhat_seo_tax_latest14_fake_IE_window.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Soq-8eIaCCI/AAAAAAAAEEs/-wGR6uKPtOQ/s200/blackhat_seo_tax_latest14_fake_IE_window.png" /&gt;&lt;/a&gt;&lt;b&gt;onlineproantivirusscanner .com&lt;/b&gt; - Email: findz@freebbmail.com&lt;br /&gt;
&lt;b&gt;online-secure-scannerv2 .com&lt;/b&gt; - Email: iren.g@sysintern.in&lt;br /&gt;
&lt;b&gt;personalantivirusprotection .com&lt;/b&gt; - Email: info@Wholesaler.cn&lt;br /&gt;
&lt;b&gt;personalfolderscanv2 .com&lt;/b&gt; - Email: hfbeauty@yahoo.com&lt;br /&gt;
&lt;b&gt;premium-antispy-scanv3 .com&lt;/b&gt; - Email: Ktrivedi@go2uti.com&lt;br /&gt;
&lt;b&gt;premium-antispy-scanv7 .com&lt;/b&gt; - Email: Ktrivedi@go2uti.com&lt;br /&gt;
&lt;b&gt;premium-antivirus-scanv6 .com&lt;/b&gt; - Email: Ktrivedi@go2uti.com&lt;br /&gt;
&lt;b&gt;private-antivirus-scannerv2 .com&lt;/b&gt; - Email: webmaster@parun.co.kr&lt;br /&gt;
&lt;b&gt;privatevirusscannerv8 .com&lt;/b&gt; - Email: info@rasystems.com&lt;br /&gt;
&lt;b&gt;secure-antispyware-scanv3 .com&lt;/b&gt; - Email: info@prrp.de&lt;br /&gt;
&lt;b&gt;securepersonalscanner .com&lt;/b&gt; - Email: info@prrp.de&lt;br /&gt;
&lt;b&gt;secure-spyware-scannerv3 .com&lt;/b&gt; - Email: info@prrp.de&lt;br /&gt;
&lt;b&gt;secure-virus-scannerv5 .com&lt;/b&gt; - Email: info@prrp.de&lt;br /&gt;
&lt;b&gt;securityfolderprotection .com&lt;/b&gt; - Email: info@Wholesaler.cn&lt;br /&gt;
&lt;b&gt;spyware-scannerv2 .com&lt;/b&gt; - Email: hanan.abdelrazek@bibalexy.org&lt;br /&gt;
&lt;b&gt;spywarescannerv4 .com&lt;/b&gt; - Email: hanan.abdelrazek@bibalexy.org&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Soq_xSN8KKI/AAAAAAAAEE0/FbIHnxkaEbQ/s1600-h/blackhat_seo_tax_latest7_phoneback.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Soq_xSN8KKI/AAAAAAAAEE0/FbIHnxkaEbQ/s200/blackhat_seo_tax_latest7_phoneback.png" /&gt;&lt;/a&gt;Sampled scareware from the last 24 hours phones back to &lt;b&gt;mineralwaterfilter .com&lt;/b&gt; - 78.46.201.90. Parked there are also: &lt;b&gt;june-crossover .com&lt;/b&gt;; &lt;b&gt;goldmine-sachs .com&lt;/b&gt;; &lt;b&gt;momentstohaveyou .cn. &lt;/b&gt;More sampled scareware phones back to a new domain Phones back to &lt;b&gt;pencil-netwok .com&lt;/b&gt; (94.102.48.31), parked there are the rest of the phone back locations for the rest of the scareware such as &lt;b&gt;mineralwaterfilter .com&lt;/b&gt;; &lt;b&gt;june-crossover .com&lt;/b&gt;; &lt;b&gt;goldmine-sachs .com&lt;/b&gt;; &lt;b&gt;bestparishotelsnow .com&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
A second sampled scareware phones back to a different location - 92.241.176.188. Parked there are the rest of the domains in their scareware portfolio:&lt;br /&gt;
&lt;b&gt;bestscanpc .org&lt;br /&gt;
bestscanpc .biz&lt;br /&gt;
downloadavr2 .com&lt;br /&gt;
downloadavr3 .com&lt;br /&gt;
trucount3005 .com&lt;br /&gt;
antivirus-scan-2009 .com&lt;br /&gt;
antivirusxppro-2009 .com&lt;br /&gt;
advanced-virus-remover-2009 .com&lt;br /&gt;
advanced-virus-remover2009 .com&lt;br /&gt;
advanced-virusremover2009 .com&lt;br /&gt;
bestscanpc .com&lt;br /&gt;
xxx-white-tube .com&lt;br /&gt;
blue-xxx-tube .com &lt;br /&gt;
trucountme .com&lt;br /&gt;
10-open-davinci .com&lt;br /&gt;
vs-codec-pro .com&lt;br /&gt;
vscodec-pro .com&lt;br /&gt;
download-vscodec-pro .com&lt;br /&gt;
v-s-codecpro .com&lt;br /&gt;
antivirus-2009-ppro .com&lt;br /&gt;
onlinescanxppro .com&lt;br /&gt;
downloadavr .com&lt;br /&gt;
bestscanpc .info&lt;br /&gt;
bestscanpc .net&lt;br /&gt;
bestscanpc .biz&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Sox7voLELGI/AAAAAAAAEGQ/2mjVKbr97F8/s1600-h/blackhat_seo_compromised_scareware.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Sox7voLELGI/AAAAAAAAEGQ/2mjVKbr97F8/s200/blackhat_seo_compromised_scareware.JPG" /&gt;&lt;/a&gt;New/historical redirection domains used in the campaign, this time parked at 78.46.201.89/94.102.48.29/different locations as noted:&lt;br /&gt;
&lt;b&gt;cnn-bcc2 .com&lt;/b&gt; - 89.248.174.61 - Email: mail@sccits.com.cn&lt;br /&gt;
&lt;b&gt;issuenews1 .com&lt;/b&gt; - Email: mail@sccits.com.cn&lt;br /&gt;
&lt;b&gt;headlinenews2 .com&lt;/b&gt; - Email: mail@sccits.com.cn&lt;br /&gt;
&lt;b&gt;usdisturbed .cn&lt;/b&gt; - Email: info@brandbanks.com&lt;br /&gt;
&lt;b&gt;milesdavisorland .cn&lt;/b&gt; - Email: info@brandbanks.com&lt;br /&gt;
&lt;b&gt;usaworkinghard .cn&lt;/b&gt; - Email: info@brandbanks.com&lt;br /&gt;
&lt;b&gt;nationaltreasure .cn&lt;/b&gt; - Email: info@brandbanks.com &lt;br /&gt;
&lt;b&gt;milesdavisorland .cn&lt;/b&gt; - 91.213.126.101 - Email: info@brandbanks.com&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;we-accepted .cn&lt;/b&gt; - Email: info@rcusan.org &lt;br /&gt;
&lt;b&gt;myth-busters .cn&lt;/b&gt; - Email: info@rcusan.org &lt;br /&gt;
&lt;b&gt;russell-brand .cn&lt;/b&gt; - Email: info@sciencesdemo.com&lt;br /&gt;
&lt;b&gt;willsmithinc .cn&lt;/b&gt; - Email: contact@oregonvma.org&lt;br /&gt;
&lt;b&gt;dirty-dancing .cn&lt;/b&gt; - Email: allisonh@soeconline.org &lt;br /&gt;
&lt;b&gt;sex-and-the-city .cn&lt;/b&gt; - Email: oregon.artscomm@state.or.us&amp;nbsp; &lt;br /&gt;
&lt;b&gt;clicksick .cn&lt;/b&gt; - 67.215.245.187 - Email: webmaster@clicksick.cn&lt;br /&gt;
&lt;b&gt;doubleclicknet .cn&lt;/b&gt; - 67.215.245.187 - Email: webmaster@doubleclicknet.cn&amp;nbsp; &lt;br /&gt;
&lt;b&gt;shrekmovie .cn&lt;/b&gt; - Email: oregon.artscomm@state.or.us &lt;br /&gt;
&lt;b&gt;radioheadicon .cn&lt;/b&gt; - Email: contact@oregonvma.org &lt;br /&gt;
&lt;b&gt;batman-comics .cn&lt;/b&gt; - Email: contact@oregonvma.org &lt;br /&gt;
&lt;b&gt;beststarwars .cn&lt;/b&gt; - Email: allisonh@soeconline.org&lt;br /&gt;
&lt;b&gt;mashroomtheory .cn&lt;/b&gt; - Email: webmaster@TangoDance.cn&lt;br /&gt;
&lt;b&gt;space2009city .cn&lt;/b&gt; - Email: webmaster@TangoDance.cn &lt;br /&gt;
&lt;b&gt;messengerinfo .cn&lt;/b&gt; - Email: allisonh@soeconline.org &lt;br /&gt;
&lt;b&gt;greattime2009 .cn&lt;/b&gt; - Email: webmaster@seniorstuds.com.ar &lt;br /&gt;
&lt;b&gt;iwanttowin .cn&lt;/b&gt; - Email: webmaster@seniorstuds.com.ar &lt;br /&gt;
&lt;b&gt;hardnut .cn&lt;/b&gt; - Email: tan.mei.sie@monash.com.my &lt;br /&gt;
&lt;b&gt;sitemechanics .cn&lt;/b&gt; - info@powertrackers.com&lt;br /&gt;
&lt;b&gt;exceldocumentsinfo .cn&lt;/b&gt; - Email: info@powertrackers.com&lt;br /&gt;
&lt;b&gt;chinafavorites .cn&lt;/b&gt; - Email: cmo@ci.springfields.or.us&lt;br /&gt;
&lt;b&gt;best-live-lottery .cn&lt;/b&gt; - Email: info@powertrackers.com &lt;br /&gt;
&lt;b&gt;adeptofmastery .cn&lt;/b&gt; - Email: info@powertrackers.com &lt;br /&gt;
&lt;b&gt;trytowintoday .cn&lt;/b&gt; - Email: info@powertrackers.com &lt;br /&gt;
&lt;b&gt;bulkdvdreader .cn&lt;/b&gt; - 94.102.48.29 - Email: info@powertrackers.com&lt;br /&gt;
&lt;b&gt;style-everywhere .com&lt;/b&gt; - 88.198.105.145 - Email: angy.helm21@yahoo.com&amp;nbsp; &lt;br /&gt;
&lt;b&gt;clicksick .cn&lt;/b&gt; - 67.215.245.187 - Email: webmaster@clicksick.cn&amp;nbsp; &lt;br /&gt;
&lt;b&gt;supportyourcountry .cn&lt;/b&gt; - Email: cmo@ci.springfields.or.us &lt;br /&gt;
&lt;b&gt;wheels-on-fire .cn&lt;/b&gt; - 94.102.48.29 - Email: epron.sales@epron.com.hk &lt;br /&gt;
&lt;b&gt;stillphotoshots .cn&lt;/b&gt; -&amp;nbsp; 94.102.48.29 - Email: epron.sales@epron.com.hk&lt;br /&gt;
&lt;b&gt;delayyouranswer .cn&lt;/b&gt; - Email: info@globaltechs.com.cn&lt;br /&gt;
&lt;b&gt;getbestsales .cn&lt;/b&gt; - Email: info@globaltechs.com.cn&lt;br /&gt;
&lt;b&gt;library-presents .cn&lt;/b&gt; - Email: hanzellandgretell@googlemail.com&lt;br /&gt;
&lt;b&gt;in-t-h-e .cn&lt;/b&gt; - 72.21.41.198 (Layered Technologies, Inc.) - Email: admin@in-t-h-e.cn &lt;br /&gt;
&lt;b&gt;bestwishestoyou .cn&lt;/b&gt; - 94.102.48.29 - Email: hanzellandgretell@googlemail.com&lt;br /&gt;
&lt;b&gt;library-presents .cn&lt;/b&gt; - 94.102.48.29 - Email: hanzellandgretell@googlemail.com&lt;br /&gt;
&lt;b&gt;getbestsales .cn&lt;/b&gt; - 94.102.48.29 - Email: info@globaltechs.com.cn&amp;nbsp; &lt;br /&gt;
&lt;b&gt;aware-of-future .cn - &lt;/b&gt;Email: info@globaltechs.com.cn&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;nothing-to-wear .cn&lt;/b&gt; - Email: steg.greg1992@yahoo.com &lt;br /&gt;
&lt;b&gt;newsmediaone .com&lt;/b&gt; - 72.21.41.198 - Email: advertizers@newsmediaone.com &lt;br /&gt;
&lt;b&gt;bapoka .net&lt;/b&gt; - 87.118.96.6 &lt;br /&gt;
&lt;b&gt;stylestats1 .net&lt;/b&gt; - 94.102.63.16 - Email: grem@yahoo.com&lt;br /&gt;
&lt;b&gt;luckystats .org&lt;/b&gt; - Email: director@climbing-games.com&lt;br /&gt;
&lt;b&gt;luckystats1 .com&lt;/b&gt; - Email: grem@yahoo.com&lt;br /&gt;
&lt;b&gt;lifewepromote .cn&lt;/b&gt; - Email: ruixiang.guo@yahoo.com &lt;br /&gt;
&lt;b&gt;securecommercialnews .cn&lt;/b&gt; - Email: contacts@swedbank.com.cn &lt;br /&gt;
&lt;b&gt;snowboard2009 .cn&lt;/b&gt; - Email: weinwein2@yahoo.com&lt;br /&gt;
&lt;b&gt;nothern-ireland .cn&lt;/b&gt; - Email: accabj@cn.accaglobal.com&lt;br /&gt;
&lt;b&gt;goldensunshine .cn&lt;/b&gt; - Email: info@tartirtar.com&lt;br /&gt;
&lt;b&gt;steplessculture .cn&lt;/b&gt; - Email: info@myfibernetworks.cn&lt;br /&gt;
&lt;b&gt;vipsoccermanager .cn&lt;/b&gt; - Email: opressor1992@yahoo.com&lt;br /&gt;
&lt;b&gt;b2b-forums .cn&lt;/b&gt; - Email: weinwein2@yahoo.com&lt;br /&gt;
&lt;b&gt;rondo-trips .cn&lt;/b&gt; - Email: acurtis@stevens.com&lt;br /&gt;
&lt;b&gt;mywatermakrs .cn&lt;/b&gt; - Email: shanghaihuny@yahoo.com&lt;br /&gt;
&lt;b&gt;gazsnippets .cn&lt;/b&gt; - Email: acurtis@stevens.com&lt;br /&gt;
&lt;b&gt;bestvanillaresorts .cn&lt;/b&gt; - Email: opressor1992@yahoo.com&lt;br /&gt;
&lt;b&gt;personalrespect .cn&lt;/b&gt; - Email: weinwein2@yahoo.com&lt;br /&gt;
&lt;b&gt;consensualart .cn&lt;/b&gt; - Email: shanghaihuny@yahoo.com&lt;br /&gt;
&lt;b&gt;yourholidaytoday .cn&lt;/b&gt; - Email: opressor1992@yahoo.com&lt;br /&gt;
&lt;b&gt;guidetogalaxy .cn&lt;/b&gt; - Email: stp9014@yahoo.com&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SorBGzGpxhI/AAAAAAAAEE8/ScwxVsU3nww/s1600-h/blackhat_seo_tax_latest3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SorBGzGpxhI/AAAAAAAAEE8/ScwxVsU3nww/s200/blackhat_seo_tax_latest3.png" /&gt;&lt;/a&gt;Among the new monetization tactics used are the typical &lt;a href="http://blogs.zdnet.com/security/?p=3333"&gt;pay-per-click malware-friendly search engines&lt;/a&gt; which act as both, redirectors to phony sites/scams, as well as keyword blackholes which help them assess the popularity for a particular keyword, and therefore start pushing it more aggressively through a process called synonymization. &lt;br /&gt;
&lt;br /&gt;
Interestingly, they're exclusively using the compromised .co.uk, as well as purely malicious blackhat SEO domains for scareware serving purposes, but continue using the ones they operate under the free DNS service providers for &lt;a href="http://blogs.zdnet.com/security/?p=3333"&gt;monetization through the bogus search engines&lt;/a&gt;. The domains used in this monetization approach are as follows:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SorDgjRxBGI/AAAAAAAAEFE/lPvc_y3MH5w/s1600-h/blackhat_seo_tax_latest1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SorDgjRxBGI/AAAAAAAAEFE/lPvc_y3MH5w/s200/blackhat_seo_tax_latest1.png" /&gt;&lt;/a&gt;&lt;b&gt;rivasearchpage .com&lt;/b&gt; - 64.27.21.5 - Email: support@ruler-domains.com&lt;br /&gt;
&lt;b&gt;triwoperl .com&lt;/b&gt; - 95.168.191.19 - Email: florenzaluwemba@gmail.com&lt;br /&gt;
&lt;b&gt;tropysearch .us&lt;/b&gt; - 74.52.216.46 - Email: tech@add-manager.com&lt;br /&gt;
&lt;b&gt;glorys .info&lt;/b&gt; (glorys .info/red/cube.js) - - 78.159.97.186 - Email: kor4seo@rambler.ru&lt;br /&gt;
&lt;b&gt;funnyblogetc .info/go.php&lt;/b&gt; -&amp;nbsp; - Email: tigerwood1@nm.ru&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SorGStRf8UI/AAAAAAAAEFM/TL26Rda_8Vo/s1600-h/ukrainian_blackhat_seo_yahoo_javascript_obfuscation_evasion.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SorGStRf8UI/AAAAAAAAEFM/TL26Rda_8Vo/s200/ukrainian_blackhat_seo_yahoo_javascript_obfuscation_evasion.JPG" /&gt;&lt;/a&gt;&lt;b&gt;triwoperl.com's &lt;/b&gt;front page is currently relying on the &lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Soq6gXyvxAI/AAAAAAAAED0/OLtMdWv_3Mg/s1600-h/blackhat_seo_tax_latest15_LIVE_obfuscation.JPG"&gt;go.live.com javascript obfuscation&lt;/a&gt;. Deobfuscated it redirects to &lt;b&gt;fi97 .net/jsr.php?uid=dir&amp;amp;group=ggl&amp;amp;keyword=&amp;amp;okw=&amp;amp;query="&lt;/b&gt;, deja vu again - &lt;b&gt;fi97 .net&lt;/b&gt; was used in the &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;Ukrainian "fan club's" blackhat SEO campaign in June&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
Monitoring of the campaign and takedown actions would continue, with an emphasis on the RBN connection from a related blackhat SEO campaign from last year. The gang is not going away anytime soon, but their campaigns definitely are.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/peek-inside-managed-blackhat-seo.html"&gt;A Peek Inside the Managed Blackhat SEO Ecosystem &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/05/dissecting-swine-flu-black-seo-campaign.html"&gt;Dissecting a Swine Flu Black SEO Campaign&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;Massive Blackhat SEO Campaign Serving Scareware&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;From Ukrainian Blackhat SEO Gang With Love&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;From Ukrainian Blackhat SEO Gang With Love - Part Two&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukraine-with-scareware-serving.html"&gt;From Ukraine with Scareware Serving Tweets, Bogus LinkedIn/Scribd Accounts, and Blackhat SEO Farms&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/from-ukraine-with-bogus-twitter.html"&gt;From Ukraine with Bogus Twitter, LinkedIn and Scribd Accounts&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/fake-web-hosting-provider-front-end-to.html"&gt;Fake Web Hosting Provider - Front-end to Scareware Blackhat SEO Campaign at Blogspot&lt;/a&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-6037640942961164232?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xggIcmuAwo4:yhk3b-ipafs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xggIcmuAwo4:yhk3b-ipafs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xggIcmuAwo4:yhk3b-ipafs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=xggIcmuAwo4:yhk3b-ipafs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xggIcmuAwo4:yhk3b-ipafs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=xggIcmuAwo4:yhk3b-ipafs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xggIcmuAwo4:yhk3b-ipafs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xggIcmuAwo4:yhk3b-ipafs:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=xggIcmuAwo4:yhk3b-ipafs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=xggIcmuAwo4:yhk3b-ipafs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/xggIcmuAwo4" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-18T18:26:09.806+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_wICHhTiQmrA/SoqnFDIk0hI/AAAAAAAAEDc/tV6fOcPlQ6U/s72-c/blackhat_seo_tax_latest2.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/08/dissecting-ongoing-us-federal-forms.html</feedburner:origLink></item><item><title>U.S Federal Forms Blackhat SEO Themed Scareware Campaign Expanding</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/QAlQV73XjaI/us-federal-forms-blackhat-seo-themed.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Tue, 11 Aug 2009 05:21:43 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-7661862795191926344</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SoBCkotQe_I/AAAAAAAAECk/YErThBkhXqM/s1600-h/blackhat_seo_tax_forums_august_2009_new.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SoBCkotQe_I/AAAAAAAAECk/YErThBkhXqM/s200/blackhat_seo_tax_forums_august_2009_new.JPG" /&gt;&lt;/a&gt;&lt;b&gt;UPDATE2:&lt;/b&gt; New &lt;a href="http://www.virustotal.com/analisis/72b0867470ca6312e0aefa87c4e16e2c44a1c8d3c47d617ba4f09e73a9dbddbb-1249992911"&gt;scareware&lt;/a&gt; domain is in rotation - &lt;b&gt;antispywarelivescanv5 .com&lt;/b&gt; - 83.133.123.174; 83.133.126.155; 91.212.107.5; 94.102.48.29; 94.102.51.26; 188.40.61.236 - Email: sales.in@bauhmerhhs.com. Redirection takes place through &lt;b&gt;consensualart .cn&lt;/b&gt; - 78.46.201.89 - Email: shanghaihuny@yahoo.com.&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATE: &lt;/b&gt;Four new domains have been introduced, again using the services of &lt;a href="http://altushost.com/"&gt;AltusHost Inc&lt;/a&gt;. (AS44042):&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;thwovretgi .com&lt;/b&gt; - 91.214.44.239 - Email: joby47619@msn.com&lt;br /&gt;
&lt;b&gt;hernewdy .com&lt;/b&gt; - 91.214.44.152 - Email: jacub26887@lycos.com&lt;br /&gt;
&lt;b&gt;shtifobpy .com&lt;/b&gt; - 91.214.44.210 - Email: hiraldo13686@hotmail.com&lt;br /&gt;
&lt;b&gt;vodcotha .com&lt;/b&gt; - 91.214.44.203 - Email: jamarcus59884@yahoo.com&lt;br /&gt;
&lt;br /&gt;
The redirection takes place through &lt;b&gt;mywatermakrs .cn&lt;/b&gt; - 78.46.201.89 - Email: shanghaihuny@yahoo.com &lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SoFhwqiUGgI/AAAAAAAAEDU/smMYv4kdD0I/s1600-h/blackhat_seo_tax_forms.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SoFhwqiUGgI/AAAAAAAAEDU/smMYv4kdD0I/s200/blackhat_seo_tax_forms.JPG" /&gt;&lt;/a&gt;In response to the takedown of the &lt;a href="http://ddanchev.blogspot.com/2009/08/blackhat-seo-campaign-hijacks-us.html"&gt;blackhat SEO domains used in the campaign&lt;/a&gt; dissected lat week, the group has responded by introducing new domains next to new redirectors and most interestingly, has started using compromised/mis-configured legitimate sites in an attempt to increase the lifecycle of the campaign by making it takedown-proof.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;New blackhat SEO domains again using AS44042 ROOT-AS root eSolutions/ALTUSHOST-NET/AltusHost Inc hosting services:&lt;br /&gt;
&lt;b&gt;fifiopod .com&lt;/b&gt; - 91.214.44.204 - Email: florenzaluwemba@gmail.com&lt;br /&gt;
&lt;b&gt;trodlocho .com&lt;/b&gt; - 91.214.44.204 - Email: alie57575@lycos.com&lt;br /&gt;
&lt;b&gt;ickgetaph .com&lt;/b&gt; - 91.214.44.209 - Email: alie57575@lycos.com&lt;br /&gt;
&lt;b&gt;igecanneg .com&lt;/b&gt; - 91.214.44.205 - Email: baxter18314@yahoo.com&lt;br /&gt;
&lt;b&gt;somveots .com&lt;/b&gt; - 91.214.44.203 - Email: frieda24482@msn.com&lt;br /&gt;
&lt;b&gt;memodreydi .com&lt;/b&gt; - 91.214.44.240 - Email: frieda24482@msn.com&lt;br /&gt;
&lt;b&gt;jejnahob .com&lt;/b&gt; -&amp;nbsp; 91.214.44.206 - Email: alie57575@lycos.com&lt;br /&gt;
&lt;b&gt;nuwofteuz .com&lt;/b&gt; - 91.214.44.206 - Email: frieda24482@msn.com&lt;br /&gt;
&lt;b&gt;hyhoppeo .com&lt;/b&gt; - 91.214.44.239 - Email: jamarcus59884@yahoo.com&lt;br /&gt;
&lt;b&gt;egnegvufvu .com&lt;/b&gt; - 91.214.44.239 - Email: ehetere29006@yahoo.com&lt;br /&gt;
&lt;b&gt;lauzpeog .com&lt;/b&gt; - 91.214.44.208 - Email: ehetere29006@yahoo.com&lt;br /&gt;
&lt;b&gt;sniozeanvo .com&lt;/b&gt; - 91.214.44.239 - Email: ehetere29006@yahoo.com&lt;br /&gt;
&lt;b&gt;hebmipenn .com&lt;/b&gt; - 91.214.44.207 - Email: adanne43906@rocketmail.com&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SoBFt4jqskI/AAAAAAAAECs/DtfeuZF4P0s/s1600-h/blackhat_seo_tax_forums_august_2009_new_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SoBFt4jqskI/AAAAAAAAECs/DtfeuZF4P0s/s200/blackhat_seo_tax_forums_august_2009_new_2.JPG" /&gt;&lt;/a&gt;The cybercriminals are also attempting to use a well proven tactic - occupying as many search engine results as possible for a particular hijacked word by using identical blackhat SEO junk content at multiple domains. A similar attempt was successfully executed in &lt;a href="http://ddanchev.blogspot.com/2009/01/poisoned-search-queries-at-google-video.html"&gt;January, 2009's search results poisoning campaign at Google Video&lt;/a&gt;, where the first ten results for a particular keyword were all malicious in their nature.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SoBLJBeTi0I/AAAAAAAAEC8/SpENqPAVUZA/s1600-h/blackhat_seo_tax_forums_august_2009_new_4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SoBLJBeTi0I/AAAAAAAAEC8/SpENqPAVUZA/s200/blackhat_seo_tax_forums_august_2009_new_4.JPG" /&gt;&lt;/a&gt; The compromised/misconfigured legitimate sites used in the campaign are serving dynamic javascript obfuscations. Here's a list of ones currently in use:&lt;br /&gt;
&lt;b&gt;ali.zaher.101main .com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;averder.cwsurf .de&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;beaver-cub-scout.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;bebbinbears.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;britishbaits .com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;cancerselfhelp.org .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;carolineengland.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;casanickel.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;catspro-northants.org .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;ceiec.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;cheritontennisclub.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;childrenofthedrone .net&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;chirnside.org .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;chris-hillman .com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;chris-hillman-photography.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;christine-pearson .com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;cicatrixonline.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;cinta.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;classic-pizza.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;crewshillgolfclub.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;cs-photo.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;dak.crep01.linux-site .net&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;darkhorsegraphics.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;divagoddess.co .uk&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;fet.jujas.myftpsite .net&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;tferh.mi-website .es&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The campaign continues switching between different redirectors parked at 83.133.123.113 for instance:&lt;br /&gt;
&lt;b&gt;rondo-trips .cn&lt;br /&gt;
gazsnippets .cn&lt;br /&gt;
besthockeyteams .cn&lt;br /&gt;
allfootballmanager .cn&lt;br /&gt;
rollerskatesadvise .cn&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;honda-recycle .cn&lt;/b&gt; - used in &lt;a href="http://ddanchev.blogspot.com/2009/08/blackhat-seo-campaign-hijacks-us.html"&gt;the previous campaign&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;nothern-ireland .cn&lt;br /&gt;
discovernewchina .cn&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SoBJzS9M74I/AAAAAAAAEC0/NKCYPxSAdc4/s1600-h/blackhat_seo_tax_forums_august_2009_new_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SoBJzS9M74I/AAAAAAAAEC0/NKCYPxSAdc4/s200/blackhat_seo_tax_forums_august_2009_new_3.JPG" /&gt;&lt;/a&gt;An updated portfolio of scareware/fake security software, parked at 94.102.51.26; 188.40.61.236; 83.133.126.155; 91.212.107.5; 94.102.48.29 has been introduced:&lt;br /&gt;
&lt;b&gt;bestpersonalprotectionv2 .com&lt;br /&gt;
onlinesecurescannerv3 .com&lt;br /&gt;
basicsystemscannerv3 .com&lt;br /&gt;
onlinebestscannerv3 .com&lt;br /&gt;
basicsystemscannerv6 .com&lt;br /&gt;
bestpersonalprotectionv7 .com&lt;br /&gt;
basicsystemscannerv8 .com&lt;br /&gt;
thankyouforscan .com&lt;br /&gt;
onlinepersonalscanner .com&lt;br /&gt;
basicsystemscanner .com&lt;br /&gt;
onlineproantivirusscanner .com&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;personalantivirusprotection .com&lt;br /&gt;
internetantivirusscanner .com&lt;br /&gt;
govirusscanner .com&lt;br /&gt;
iwantsweepviruses .com&lt;br /&gt;
personalfoldertest .com&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.virustotal.com/analisis/bd7c135a7657dbb48924f120e8145d5115ae815bb6f5206100e36184ec132df8-1249865192"&gt;Sampled scareware&lt;/a&gt; once again phones back to the &lt;b&gt;thebigben .cn&lt;/b&gt; - Email: chu-thi-huong@giang.com and &lt;b&gt;june-crossover .com&lt;/b&gt; - 78.46.201.90 Email: doru@sattenis.com, with more scareware parked there - &lt;b&gt;purchuase-premium-software .com&lt;/b&gt; - Email: nagappan.krishnan@persons.us; &lt;b&gt;livepaymentssystem .com&lt;/b&gt; - Email: mike12haro@yahoo.com; &lt;b&gt;secure.livepaymentssystem .com&lt;/b&gt; - Email: mike12haro@yahoo.com; &lt;b&gt;purchuasepremiumprotection .com&lt;/b&gt; - Email: Malcolm@partypants.com.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SoBgMvVqzzI/AAAAAAAAEDE/q1-SMAAfTjo/s1600-h/k9_dog_training_blackhat_seo_a-n-d-the_dot_com.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SoBgMvVqzzI/AAAAAAAAEDE/q1-SMAAfTjo/s200/k9_dog_training_blackhat_seo_a-n-d-the_dot_com.png" /&gt;&lt;/a&gt;Evasion techniques are in again in place, however, this time they end up in a &lt;a href="http://ddanchev.blogspot.com/2008/03/zdnet-asia-and-torrentreactor-iframe-ed.html"&gt;Russian Business Network deja vu moment from 2008&lt;/a&gt;. In March, 2008, ZDNet Asia and TorrentReactor followed by a large number of other high profile, high pagerank sites started activing as intermediaries to scareware campaigns, among the first such abuse of legitimate sites for scareware serving purposes.&lt;br /&gt;
&lt;br /&gt;
The compromised/mis-configured web sites participating in this latest blackhat SEO campaign are surprisingly redirecting to &lt;b&gt;a-n-d-the.com /wtr/router.php&lt;/b&gt; - 95.168.177.35 - Email: bulk@spam.lv - AS28753 NETDIRECT AS NETDIRECT Frankfurt, DE if the http referrer condition isn't met. This very same domain -- back then parked at INTERCAGE-NETWORK-GROUP2 -- was also used in the same fashion in March, 2008's &lt;a href="http://ddanchev.blogspot.com/2008/03/zdnet-asia-and-torrentreactor-iframe-ed.html"&gt;massive blackhat SEO campaigns serving scareware&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-7661862795191926344?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QAlQV73XjaI:sOuVkuHJqmg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QAlQV73XjaI:sOuVkuHJqmg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QAlQV73XjaI:sOuVkuHJqmg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=QAlQV73XjaI:sOuVkuHJqmg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QAlQV73XjaI:sOuVkuHJqmg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=QAlQV73XjaI:sOuVkuHJqmg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QAlQV73XjaI:sOuVkuHJqmg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QAlQV73XjaI:sOuVkuHJqmg:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=QAlQV73XjaI:sOuVkuHJqmg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=QAlQV73XjaI:sOuVkuHJqmg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/QAlQV73XjaI" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-11T14:21:43.890+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_wICHhTiQmrA/SoBCkotQe_I/AAAAAAAAECk/YErThBkhXqM/s72-c/blackhat_seo_tax_forums_august_2009_new.JPG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/08/us-federal-forms-blackhat-seo-themed.html</feedburner:origLink></item><item><title>Blackhat SEO Campaign Hijacks U.S Federal Form Keywords, Serves Scareware</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/R9lUFFCZjFU/blackhat-seo-campaign-hijacks-us.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Thu, 06 Aug 2009 12:43:02 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-7768535001529309163</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SnsNmKaI3oI/AAAAAAAAEB0/B11rRczDvOE/s1600-h/blackhat_seo_tax_forums_august_2009_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SnsNmKaI3oI/AAAAAAAAEB0/B11rRczDvOE/s200/blackhat_seo_tax_forums_august_2009_3.JPG" /&gt;&lt;/a&gt;During the past 24 hours, a &lt;a href="http://blogs.zdnet.com/security/?p=3962"&gt;blackhat SEO campaign has been hijacking U.S Federal Forms&lt;/a&gt; related keywords in an attempt to serve scareware.&lt;br /&gt;
&lt;br /&gt;
What's particularly interesting about the campaign is that the Ukrainian fan club behind it -- you didn't even think for a second that there's no connection with their previous campaigns, did you? -- are using basic segmentation principles since the tax form keywords poisoning is attempting to hijack U.S traffic. Evasive practices are also in place through the usual http referrer check, which would only serve the scareware if the visitor is coming from Google.com, if not a 404 error message will appear.&lt;br /&gt;
&lt;br /&gt;
Upon clicking on the link, the user is redirected through a centralized location responsible for managing the traffic from the thousands of subdomains/keywords used - &lt;b&gt;honda-recycle .cn&lt;/b&gt;/go.php?id=2017&amp;amp;key=cbafb5cb2&amp;amp;p=1 - 83.133.123.113 Email: accabj@cn.accaglobal.com. Parked on the same IP are also related malware/scareware domains:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SnsTZCR3AJI/AAAAAAAAEB8/g-d1vjB4Tp0/s1600-h/blackhat_seo_tax_forums_august_2009_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SnsTZCR3AJI/AAAAAAAAEB8/g-d1vjB4Tp0/s200/blackhat_seo_tax_forums_august_2009_1.JPG" /&gt;&lt;/a&gt;&lt;b&gt;winsoftwareupdatev2 .com - &lt;/b&gt;Email: webmaster@kaity.or.kr&lt;br /&gt;
&lt;b&gt;much-in-love .com &lt;/b&gt;- Email: krebikim@kanmail.net&lt;br /&gt;
&lt;b&gt;i-dont-care-much .com - &lt;/b&gt;Email: krebikim@kanmail.net&lt;br /&gt;
&lt;b&gt;malwareurlblock .com &lt;/b&gt;- Email: Qinrui971@hotmail.com&lt;br /&gt;
&lt;b&gt;bennysaintscathedral .com &lt;/b&gt;- Email: gayaomila@yahoo.com&lt;br /&gt;
&lt;b&gt;browsersecurityinfo .com - &lt;/b&gt;Email: visor@elcomtech.com&lt;br /&gt;
&lt;b&gt;windowssecurityinfo .com &lt;/b&gt;- Email: arziw12@freebbmail.com&lt;br /&gt;
&lt;b&gt;ringtone-radio .com &lt;/b&gt;- Email: bobbyer@iofc.org&lt;br /&gt;
&lt;b&gt;events-team-manager .com &lt;/b&gt;- Email: krebikim@kanmail.net&lt;br /&gt;
&lt;b&gt;1worldupdatesserver .com &lt;/b&gt;- Email: tapias.andres@hdtvspain.org&lt;br /&gt;
&lt;b&gt; discovernewchina .cn &lt;/b&gt;- Email: leijun.ma@unifem.org&lt;br /&gt;
&lt;b&gt; rollerskatesadvise .cn &lt;/b&gt;- Email: info@chinaeuropaforum.net&lt;br /&gt;
&lt;b&gt; allfootballmanager .cn &lt;/b&gt;- Email: info@chinaeuropaforum.net&lt;br /&gt;
&lt;b&gt; hardwarefactories .cn &lt;/b&gt;- Email: leijun.ma@unifem.org&lt;br /&gt;
&lt;b&gt; besthockeyteams .cn - &lt;/b&gt;Email: info@chinaeuropaforum.net&lt;br /&gt;
&lt;b&gt; gowildtours .cn - &lt;/b&gt;Email: leijun.ma@unifem.org&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SnsU_ImFQEI/AAAAAAAAECE/SgGsGuyYu28/s1600-h/blackhat_seo_tax_forums_august_2009_4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SnsU_ImFQEI/AAAAAAAAECE/SgGsGuyYu28/s200/blackhat_seo_tax_forums_august_2009_4.JPG" /&gt;&lt;/a&gt;The malicious domains used -- with two exceptions -- are all parked at AltusHost Inc./ALTUSHOST-NET. Here's the complete list:&lt;br /&gt;
&lt;b&gt;tebdigasbi .com&lt;/b&gt; - 91.214.44.205 - Email: martin94304@yahoo.com&lt;br /&gt;
&lt;b&gt;kraijfaw .com&lt;/b&gt; - 91.214.44.240 - Email: argantael31869@msn.com&lt;br /&gt;
&lt;b&gt;reychohica .com&lt;/b&gt; - 91.214.44.209 - Email: martin94304@yahoo.com&lt;br /&gt;
&lt;b&gt;fequervo .com&lt;/b&gt; - 91.214.44.239 - Email: orla53111@hotmail.com&lt;br /&gt;
&lt;b&gt;ukaszohat .com&lt;/b&gt; - 91.214.44.205 - Email: argantael31869@msn.com&lt;br /&gt;
&lt;b&gt;buwrynko .com&lt;/b&gt; -&amp;nbsp; 91.214.44.204 - Email: keallach84256@yahoo.com&lt;br /&gt;
&lt;b&gt;fetholye .com&lt;/b&gt; - 91.214.44.208 - Email: martin94304@yahoo.com&lt;br /&gt;
&lt;b&gt;pasbirrada .com&lt;/b&gt; - 91.214.44.204 - Email: martin94304@yahoo.com&lt;br /&gt;
&lt;b&gt;dynodns.net&lt;/b&gt; - legitimate&lt;br /&gt;
&lt;b&gt;thebbs.org&lt;/b&gt; - legitimate&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SnsWYH5qNCI/AAAAAAAAECM/4q5DPk-UPXc/s1600-h/blackhat_seo_tax_forums_august_2009_8.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SnsWYH5qNCI/AAAAAAAAECM/4q5DPk-UPXc/s200/blackhat_seo_tax_forums_august_2009_8.JPG" /&gt;&lt;/a&gt;The people behind the campaign have also taken contingency planning in mind since &lt;a href="http://www.virustotal.com/analisis/7e8cd272e83020c63f5fdc087fcc03f23c3690fbc66ef9e2c5b10320de0d2225-1249511343"&gt;the scareware&lt;/a&gt; domain &lt;a href="http://www.virustotal.com/analisis/8cdb3d69147640c82c8b1657ba90c5da3ecb1ee0eec5d6fc6ec23c07953f6f6c-1249569677"&gt;portfolio&lt;/a&gt; is parked on five different IPs - &lt;b&gt;no-spyware-thanks .com&lt;/b&gt; - 94.102.48.29; 94.102.51.26; 188.40.61.236; 83.133.126.155; 91.212.107.5 Email: Paul.Saydak@lovellis.com. The complete list:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SnsWhJxAtfI/AAAAAAAAECU/5Sb3PbHC4NU/s1600-h/blackhat_seo_tax_forums_august_2009_7.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SnsWhJxAtfI/AAAAAAAAECU/5Sb3PbHC4NU/s200/blackhat_seo_tax_forums_august_2009_7.JPG" /&gt;&lt;/a&gt;&lt;b&gt;fast-scan-your-pcv3 .com&lt;/b&gt; - Email: info@valeros.com&lt;br /&gt;
&lt;b&gt;basicsystemscannerv3 .com&lt;/b&gt; - Email: changhong@corpdefence.cn&lt;br /&gt;
&lt;b&gt;antivirus-quickscanv5 .com&lt;/b&gt; - Email: diana1982@yahoo.com&lt;br /&gt;
&lt;b&gt;basicsystemscannerv6 .com&lt;/b&gt; - Email: changhong@corpdefence.cn&lt;br /&gt;
&lt;b&gt;basicsystemscannerv8 .com&lt;/b&gt; - Email: changhong@corpdefence.cn&lt;br /&gt;
&lt;b&gt;privatevirusscannerv8 .com&lt;/b&gt; - Email: info@rasystems.com&lt;br /&gt;
&lt;b&gt;spywarefastscannerv9 .com&lt;/b&gt; - Email: info@rasystems.com&lt;br /&gt;
&lt;b&gt;online-pro-antivirus-scan .com&lt;/b&gt; - Email: findz@freebbmail.com&lt;br /&gt;
&lt;b&gt;onlineproscan .com&lt;/b&gt; - Email: addworld@freebbmail.com&lt;br /&gt;
&lt;b&gt;onlineproantivirusscan .com&lt;/b&gt; - Email: addworld@freebbmail.com&lt;br /&gt;
&lt;b&gt;online-pro-scanner .com&lt;/b&gt; - Email: addworld@freebbmail.com&lt;br /&gt;
&lt;b&gt;basicsystemscanner .com&lt;/b&gt; - Email: changhong@corpdefence.cn&lt;br /&gt;
&lt;b&gt;onlineproantivirusscanner .com&lt;/b&gt; - Email: findz@freebbmail.com&lt;br /&gt;
&lt;b&gt;iwantsweepviruses .com&lt;/b&gt; - Email: leesten@fedexnow.com&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SnsZ-S2XYvI/AAAAAAAAECc/7lI2cu8sWro/s1600-h/blackhat_seo_tax_forums_august_2009_6.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SnsZ-S2XYvI/AAAAAAAAECc/7lI2cu8sWro/s200/blackhat_seo_tax_forums_august_2009_6.JPG" /&gt;&lt;/a&gt;Two sampled scareware samples during the past 24 hours phone back to &lt;b&gt;goldmine-sachs .com&lt;/b&gt; (Goldman Sachs typosquatting) - 83.133.122.211; 89.47.237.52 - Email: rodriguez.dallas@romehotels.com and to &lt;b&gt;june-crossover .com&lt;/b&gt; - 83.133.123.109 - Email: doru@sattenis.com. In regard to &lt;a href="http://ddanchev.blogspot.com/2009/06/diverse-portfolio-of-fake-security.html"&gt;89.47.237.52&lt;/a&gt;, the "fan club" used it to &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;host scareware in their June's campaigns&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
AltusHost Inc./ALTUSHOST-NET is expected to take action shortly.&lt;i&gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-7768535001529309163?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=R9lUFFCZjFU:aOlRPGfU3lE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=R9lUFFCZjFU:aOlRPGfU3lE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=R9lUFFCZjFU:aOlRPGfU3lE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=R9lUFFCZjFU:aOlRPGfU3lE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=R9lUFFCZjFU:aOlRPGfU3lE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=R9lUFFCZjFU:aOlRPGfU3lE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=R9lUFFCZjFU:aOlRPGfU3lE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=R9lUFFCZjFU:aOlRPGfU3lE:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=R9lUFFCZjFU:aOlRPGfU3lE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=R9lUFFCZjFU:aOlRPGfU3lE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/R9lUFFCZjFU" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-06T21:43:02.153+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_wICHhTiQmrA/SnsNmKaI3oI/AAAAAAAAEB0/B11rRczDvOE/s72-c/blackhat_seo_tax_forums_august_2009_3.JPG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/08/blackhat-seo-campaign-hijacks-us.html</feedburner:origLink></item><item><title>Scareware Template Localized to Arabic</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/tVZk8jJ1Bvg/scareware-template-localized-to-arabic.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Wed, 05 Aug 2009 13:08:35 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-2764303797941672773</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Snit9jacPaI/AAAAAAAAEBk/dSWilwTMC4k/s1600-h/twitter_scareware_ukrainian_blackhat_seo_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Snit9jacPaI/AAAAAAAAEBk/dSWilwTMC4k/s200/twitter_scareware_ukrainian_blackhat_seo_3.JPG" /&gt;&lt;/a&gt;A "new tactic" is supposedly being used as a &lt;a href="http://sunbeltblog.blogspot.com/2009/07/new-rogue-tactic-blue-screen-of.html"&gt;Blue Screen of Death scareware template&lt;/a&gt; with a single missing fact "for the record" - the template is old, I came across it on &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukraine-with-scareware-serving.html"&gt;June 17th&lt;/a&gt;, with Marshal8e6 featuring it even earlier on the &lt;a href="http://www.marshal8e6.com/trace/i/Scareware-Twitters,trace.1004%7E.asp"&gt;12th of June&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
What's new on the template front in respect to &lt;a href="http://ddanchev.blogspot.com/2009/07/diverse-portfolio-of-fake-security_27.html"&gt;scareware&lt;/a&gt; is what will inevitably start taking place across all the market segments within the underground economy in the long term - &lt;a href="http://blogs.zdnet.com/security/?p=3813"&gt;market segmentation and localization&lt;/a&gt;, namely, translating the malware/spam/phishing templates to the native language of the prospective victims.&lt;br /&gt;
&amp;nbsp; &lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SniwKQUtckI/AAAAAAAAEBs/JKxWb2iByvs/s1600-h/localized_arabic_scareware.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SniwKQUtckI/AAAAAAAAEBs/JKxWb2iByvs/s200/localized_arabic_scareware.JPG" /&gt;&lt;/a&gt;A decent example is the first ever template of the popular "My Computer Online Scan" fake scanning screen localized to Arabic - &lt;b&gt;scan-online .co.cc/arabic.php &lt;/b&gt;(67.222.148.26).&lt;br /&gt;
&lt;br /&gt;
The last time &lt;a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html"&gt;localization of fake security software&lt;/a&gt; was actively taking place was in April, 2008, and the campaigners back then also localized the domain names next to the actual content.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;. &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-2764303797941672773?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tVZk8jJ1Bvg:QLp9eN2O9YY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tVZk8jJ1Bvg:QLp9eN2O9YY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tVZk8jJ1Bvg:QLp9eN2O9YY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tVZk8jJ1Bvg:QLp9eN2O9YY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tVZk8jJ1Bvg:QLp9eN2O9YY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tVZk8jJ1Bvg:QLp9eN2O9YY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tVZk8jJ1Bvg:QLp9eN2O9YY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tVZk8jJ1Bvg:QLp9eN2O9YY:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=tVZk8jJ1Bvg:QLp9eN2O9YY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=tVZk8jJ1Bvg:QLp9eN2O9YY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/tVZk8jJ1Bvg" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-05T22:08:35.293+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_wICHhTiQmrA/Snit9jacPaI/AAAAAAAAEBk/dSWilwTMC4k/s72-c/twitter_scareware_ukrainian_blackhat_seo_3.JPG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/08/scareware-template-localized-to-arabic.html</feedburner:origLink></item><item><title>Movement on the Koobface Front</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/VW9NpTvzpfc/movement-on-koobface-front.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Tue, 04 Aug 2009 15:25:59 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-6462042846718820976</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SniESVZf_TI/AAAAAAAAEBU/mShdZskH_QY/s1600-h/koobface_august_contingency.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SniESVZf_TI/AAAAAAAAEBU/mShdZskH_QY/s200/koobface_august_contingency.JPG" /&gt;&lt;/a&gt;Now that the &lt;a href="http://ddanchev.blogspot.com/2009/07/koobface-come-out-come-out-wherever-you.html"&gt;Koobface gang&lt;/a&gt; is no longer expressing its &lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Smc9UjwhxZI/AAAAAAAAD-Y/WQ17qmHSx6U/s1600-h/koobface-thanks-dancho1.PNG"&gt;gratitude for the takedown of its command and control servers&lt;/a&gt;, the group has put its contingency planning in action thanks to the on purposely slow reaction of&lt;i&gt; UKSERVERS&lt;/i&gt;-MNT's (&lt;a href="http://whois.domaintools.com/78.110.175.15"&gt;78.110.175.15&lt;/a&gt;) abuse department. &lt;br /&gt;
&lt;br /&gt;
Next to the regular updates (&lt;b&gt;web.reg .md&lt;/b&gt;/1/&lt;a href="http://www.virustotal.com/analisis/47ed6dbad1e881980f590ada9cdb13f03435ed61c0f7dd34c8e45df8470d2550-1248891066"&gt;websrvx2.exe&lt;/a&gt;; &lt;b&gt;web.reg.md&lt;/b&gt;/1/ &lt;a href="http://www.virustotal.com/analisis/a0c5554b14d8a552c0ddd5dd0003317737faba73a8158e4fba66d8cfdb5b4f77-1249385724"&gt;prx.exe&lt;/a&gt;), the group introduced two new domains and started taking advantage of two more IPs for its main command and control server. &lt;b&gt;upr0306 .com&lt;/b&gt; now responds to:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://whois.domaintools.com/67.215.238.178"&gt;67.215.238.178&lt;/a&gt; - AS22298 - Netherlands Distinctio Ltd&lt;br /&gt;
&lt;a href="http://whois.domaintools.com/78.110.175.15"&gt;78.110.175.15&lt;/a&gt; - AS42831 UKSERVERS-AS UK Dedicated Servers Limited UK Dedicated Servers&lt;br /&gt;
&lt;a href="http://whois.domaintools.com/221.5.74.46"&gt;221.5.74.46&lt;/a&gt; - AS17816 - CHINA169-GZ CNCGROUP IP network China169 Guangzhou MAN&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SniHQwvbv7I/AAAAAAAAEBc/o03DFyJGt3Y/s1600-h/koobface_august_contingency1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SniHQwvbv7I/AAAAAAAAEBc/o03DFyJGt3Y/s200/koobface_august_contingency1.JPG" /&gt;&lt;/a&gt;and that includes the two new domains introduced - &lt;b&gt;pam-220709 .com&lt;/b&gt;; &lt;b&gt;ram-220709 .com&lt;/b&gt;, with &lt;b&gt;ram-220709 .com/go/?pid=30909&amp;amp;type=videxpgo.php?sid=4&amp;amp;sref=&lt;/b&gt; redirecting to the &lt;a href="http://www.virustotal.com/analisis/0897c3505950a78c8f4558acd9ea62abb692c3d5b962a0a70015234504b1c148-1249385858"&gt;Koobface&lt;/a&gt; botnet.&lt;br /&gt;
&lt;br /&gt;
Interestingly, &lt;b&gt;67.215.238.178&lt;/b&gt; (hosted.by.pacificrack.com) was also used in the blackhat SEO campaigns from June/July, with &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukraine-with-scareware-serving.html"&gt;warwork .info&lt;/a&gt; and &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;tangoing .info&lt;/a&gt; parked there.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/koobface-come-out-come-out-wherever-you.html"&gt;Koobface - Come Out, Come Out, Wherever You Are &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/dissecting-koobface-worms-twitter.html"&gt;Dissecting Koobface Worm's Twitter Campaign&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/12/dissecting-koobface-worms-december.html"&gt;Dissecting the Koobface Worm's December Campaign &lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/11/dissecting-latest-koobface-facebook.html"&gt;Dissecting the Latest Koobface Facebook Campaign&lt;/a&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2008/12/koobface-gang-mixing-social-engineering.html"&gt;The Koobface Gang Mixing Social Engineering Vectors&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Ukrainian "fan club" and the Koobface connection: &lt;/b&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/05/dissecting-swine-flu-black-seo-campaign.html"&gt;Dissecting a Swine Flu Black SEO Campaign&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;Massive Blackhat SEO Campaign Serving Scareware&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;From Ukrainian Blackhat SEO Gang With Love&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;From Ukrainian Blackhat SEO Gang With Love - Part Two&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukraine-with-scareware-serving.html"&gt;From Ukraine with Scareware Serving Tweets, Bogus LinkedIn/Scribd Accounts, and Blackhat SEO Farms&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/07/from-ukraine-with-bogus-twitter.html"&gt;From Ukraine with Bogus Twitter, LinkedIn and Scribd Accounts&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://ddanchev.blogspot.com/2009/06/fake-web-hosting-provider-front-end-to.html"&gt;Fake Web Hosting Provider - Front-end to Scareware Blackhat SEO Campaign at Blogspot&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;. &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-6462042846718820976?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VW9NpTvzpfc:V1oDvVrUMWI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VW9NpTvzpfc:V1oDvVrUMWI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VW9NpTvzpfc:V1oDvVrUMWI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=VW9NpTvzpfc:V1oDvVrUMWI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VW9NpTvzpfc:V1oDvVrUMWI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=VW9NpTvzpfc:V1oDvVrUMWI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VW9NpTvzpfc:V1oDvVrUMWI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VW9NpTvzpfc:V1oDvVrUMWI:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=VW9NpTvzpfc:V1oDvVrUMWI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=VW9NpTvzpfc:V1oDvVrUMWI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/VW9NpTvzpfc" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-05T00:25:59.675+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_wICHhTiQmrA/SniESVZf_TI/AAAAAAAAEBU/mShdZskH_QY/s72-c/koobface_august_contingency.JPG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/08/movement-on-koobface-front.html</feedburner:origLink></item><item><title>Managed Polymorphic Script Obfuscation Services</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/qKSw_El4Y_Y/managed-polymorphic-script-obfuscation.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Tue, 04 Aug 2009 10:32:42 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-8831036196624512823</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SnhkObW1sVI/AAAAAAAAEA0/_1tAyDJdmkQ/s1600-h/managed_malware_service4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SnhkObW1sVI/AAAAAAAAEA0/_1tAyDJdmkQ/s200/managed_malware_service4.JPG" /&gt;&lt;/a&gt;Cybecriminals understand the value of quality assurance, and have been actively running business models on the top of it for &lt;a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html"&gt;the past two years&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
From the &lt;a href="http://ddanchev.blogspot.com/2008/04/quality-and-assurance-in-malware.html"&gt;multiple offline antivirus scanners&lt;/a&gt; using pirated software, the &lt;a href="http://ddanchev.blogspot.com/2008/10/quality-and-assurance-in-malware.html"&gt;online detection rate checking services&lt;/a&gt; allowing scheduled URL scan and notification upon detection by antivirus vendors, to the underground alternatives of VirusTotal in the form of &lt;a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html"&gt;multiple firewalls bypass verification checks&lt;/a&gt; - cybercriminals are actively benchmarking and optimizing their releases before launching yet another campaign.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SnhqeOZqU6I/AAAAAAAAEA8/t7ExkP9h6QU/s1600-h/managed_malware_service3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SnhqeOZqU6I/AAAAAAAAEA8/t7ExkP9h6QU/s200/managed_malware_service3.JPG" /&gt;&lt;/a&gt;A newly launched service aims to port a universal managed malware feature on the web - the polymorphic &lt;a href="http://ddanchev.blogspot.com/2007/08/offensive-storm-worm-obfuscation.html"&gt;obfuscation of malicious scripts&lt;/a&gt; in an attempt to increase &lt;a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html"&gt;the lifecycle of a particular campaign&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Interestingly, due to the obvious software piracy within the cybercrime ecosystem which allowed &lt;a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html"&gt;proprietary malware tools&lt;/a&gt; to leak &lt;a href="http://ddanchev.blogspot.com/2008/04/diy-exploit-embedding-tool-proprietary.html"&gt;in the wild&lt;/a&gt;, the service is using a particular malware kit's javascript obfuscation routines and is running a business model on it.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Snhr8zsrGLI/AAAAAAAAEBE/gCgCxH20CC4/s1600-h/managed_malware_service2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Snhr8zsrGLI/AAAAAAAAEBE/gCgCxH20CC4/s200/managed_malware_service2.jpg" /&gt;&lt;/a&gt;For the time being, it relies on three obfuscation algorithms, &lt;b&gt;HTMLCryptor&lt;/b&gt; olnly - used 56 times, &lt;b&gt;TextUnescape&lt;/b&gt; - used 109 times, and &lt;b&gt;PolyLite&lt;/b&gt; - already used 177 times. The DIY obfuscation service, also checks and notifies the cybercriminal over ICQ in cases when his IPs and domain names have been blacklisted by Google's Safebrowsing, as well as Spamhaus, and more checks against public malware domain/IP databases are on the developer's to-do list.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SnhvjOTCC3I/AAAAAAAAEBM/Jgl82DP9fa8/s1600-h/managed_malware_service6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SnhvjOTCC3I/AAAAAAAAEBM/Jgl82DP9fa8/s200/managed_malware_service6.png" /&gt;&lt;/a&gt;The price? $20 for monthly access and $5 for weekly. Despite the fact that the service is attempting to monetize a commodity feature available to cybecriminals through the managed updates that come with the purchase of a proprietary web malware exploitation kit, it's not a fad since it fills in the DIY niche where the variety of the algorithms offered and their actual quality will either spell the doom or the rise of the service.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-8831036196624512823?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=qKSw_El4Y_Y:6bhXOWOEHzI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=qKSw_El4Y_Y:6bhXOWOEHzI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=qKSw_El4Y_Y:6bhXOWOEHzI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=qKSw_El4Y_Y:6bhXOWOEHzI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=qKSw_El4Y_Y:6bhXOWOEHzI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=qKSw_El4Y_Y:6bhXOWOEHzI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=qKSw_El4Y_Y:6bhXOWOEHzI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=qKSw_El4Y_Y:6bhXOWOEHzI:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=qKSw_El4Y_Y:6bhXOWOEHzI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=qKSw_El4Y_Y:6bhXOWOEHzI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/qKSw_El4Y_Y" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-04T19:32:42.573+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_wICHhTiQmrA/SnhkObW1sVI/AAAAAAAAEA0/_1tAyDJdmkQ/s72-c/managed_malware_service4.JPG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/08/managed-polymorphic-script-obfuscation.html</feedburner:origLink></item><item><title>Summarizing Zero Day's Posts for July</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/fjuqzyF3o4g/summarizing-zero-days-posts-for-july.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Mon, 03 Aug 2009 10:36:08 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-8976592817983726674</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Snb7paXW5uI/AAAAAAAAEAs/-TUljKeSBZY/s1600-h/zdnet_zeroday_july_2009.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Snb7paXW5uI/AAAAAAAAEAs/-TUljKeSBZY/s200/zdnet_zeroday_july_2009.png" /&gt;&lt;/a&gt;The following is a brief summary of all of my posts at ZDNet's &lt;a href="http://blogs.zdnet.com/security"&gt;Zero Day&lt;/a&gt; for July.&lt;br /&gt;
&lt;br /&gt;
You can also go through previous summaries for &lt;a href="http://ddanchev.blogspot.com/2009/07/summarizing-zero-days-posts-for-june.html"&gt;June&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/06/summarizing-zero-days-posts-for-may.html"&gt;May&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/05/summarizing-zero-days-posts-for-april.html"&gt;April&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/03/summarizing-zero-days-posts-for-march.html"&gt;March&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/03/summarizing-zero-days-posts-for.html"&gt;February&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/02/summarizing-zero-days-posts-for-january.html"&gt;January&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/01/summarizing-zero-days-posts-for.html"&gt;December&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/12/summarizing-zero-days-posts-for.html"&gt;November&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/11/summarizing-zero-days-posts-for-october.html"&gt;October&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/10/summarizing-zero-days-posts-for.html"&gt;September&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/09/summarizing-zero-days-posts-for-august.html"&gt;August&lt;/a&gt; and &lt;a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html"&gt;July&lt;/a&gt;, as well as subscribe to my &lt;a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;amp;s=0&amp;amp;o=1&amp;amp;mode=rss"&gt;personal RSS feed&lt;/a&gt; or &lt;a href="http://feeds.feedburner.com/zdnet/security"&gt;Zero Day's main feed&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Notable articles include - &lt;a href="http://blogs.zdnet.com/security/?p=3690"&gt;Manchester City Council pays $2.4m in Conficker clean up costs&lt;/a&gt;; &lt;a href="http://blogs.zdnet.com/security/?p=3713"&gt;Transmitter.C mobile malware spreading in the wild&lt;/a&gt; and &lt;a href="http://blogs.zdnet.com/security/?p=3733"&gt;Does free antivirus offer a false feeling of security?&lt;/a&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;01.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3690"&gt;Manchester City Council pays $2.4m in Conficker clean up costs&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;02.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3694"&gt;EyeWonder malware incident affects popular web sites&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;03.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3706"&gt;Koobface worm joins the Twittersphere&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;04.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3713"&gt;Transmitter.C mobile malware spreading in the wild&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;05.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3725"&gt;ImageShack hacked by anti-full disclosure movement&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;06.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3733"&gt;Does free antivirus offer a false feeling of security?&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;07.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3743"&gt;Remote code execution exploit for Firefox 3.5 in the wild&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;08.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3764"&gt;Adobe ships insecure version of Reader from official site&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;09.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3781"&gt;The future of mobile malware - digitally signed by Symbian?&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;10.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3809"&gt;419 scammers using Dilbert.com&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;11.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3813"&gt;Spammers go multilingual, use automatic translation services&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-8976592817983726674?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fjuqzyF3o4g:YgcWHdARs_Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fjuqzyF3o4g:YgcWHdARs_Q:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fjuqzyF3o4g:YgcWHdARs_Q:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=fjuqzyF3o4g:YgcWHdARs_Q:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fjuqzyF3o4g:YgcWHdARs_Q:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=fjuqzyF3o4g:YgcWHdARs_Q:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fjuqzyF3o4g:YgcWHdARs_Q:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fjuqzyF3o4g:YgcWHdARs_Q:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=fjuqzyF3o4g:YgcWHdARs_Q:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=fjuqzyF3o4g:YgcWHdARs_Q:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/fjuqzyF3o4g" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-03T19:36:08.052+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_wICHhTiQmrA/Snb7paXW5uI/AAAAAAAAEAs/-TUljKeSBZY/s72-c/zdnet_zeroday_july_2009.png" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/08/summarizing-zero-days-posts-for-july.html</feedburner:origLink></item><item><title>Social Engineering Driven Web Malware Exploitation Kit</title><link>http://feedproxy.google.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/D4IEbtMORJo/social-engineering-driven-web-malware.html</link><author>dancho.danchev@gmail.com (Dancho Danchev)</author><pubDate>Thu, 24 Sep 2009 14:03:01 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-18493443.post-5223434556399065399</guid><description>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SnGbqYpyy0I/AAAAAAAAD_8/7-G_nBFhtVE/s1600-h/screenshotz33.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SnGbqYpyy0I/AAAAAAAAD_8/7-G_nBFhtVE/s200/screenshotz33.JPG" /&gt;&lt;/a&gt;The &lt;a href="http://ddanchev.blogspot.com/2009/02/template-ization-of-malware-serving.html"&gt;standardization&lt;/a&gt; through &lt;a href="http://ddanchev.blogspot.com/2008/07/template-ization-of-malware-serving.html"&gt;template-ization of bogus codec/flash player/video pages&lt;/a&gt;, taking place during the past two years, has exponentially increased the &lt;a href="http://ddanchev.blogspot.com/2009/04/bogus-linkedin-profiles-redirect-to.html"&gt;efficiency levels of malware campaigns&lt;/a&gt; relying exclusively on &lt;a href="http://ddanchev.blogspot.com/2009/02/fake-codec-serving-domains-from.html"&gt;social engineering&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SnGfbDID2MI/AAAAAAAAEAE/iK2eqcV9bhA/s1600-h/screenshotz22.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SnGfbDID2MI/AAAAAAAAEAE/iK2eqcV9bhA/s200/screenshotz22.JPG" /&gt;&lt;/a&gt;Just like &lt;a href="http://ddanchev.blogspot.com/2008/03/phishing-pages-for-every-bank-are.html"&gt;phishing pages being commodity&lt;/a&gt;, these commodity spoofs of legitimate software/plugins relying on "visual social engineering" represent a market segment by themselves, one that some cybercriminals have been attempting to monetize for a while.&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;Case in point - their latest attempt to do so comes in the form of the first social engineering driven web malware exploitation kit.&lt;br /&gt;
&amp;nbsp; &lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SnGgmCzpqlI/AAAAAAAAEAM/qCiddQTltAs/s1600-h/screenshotz.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SnGgmCzpqlI/AAAAAAAAEAM/qCiddQTltAs/s200/screenshotz.jpg" /&gt;&lt;/a&gt;Despite that the kit's author has ripped off a well known exploits-serving malware kit's statistics interface, what's unique about this release is the fact that the exploit modules come in the form of "&lt;i&gt;Missing Flash Player&lt;/i&gt;", "&lt;i&gt;Outdated Flash Player&lt;/i&gt;", "&lt;i&gt;Missing Video Codec&lt;/i&gt;", "&lt;i&gt;Outdated Video Codec", "Codec Required"&lt;/i&gt; modules.&lt;br /&gt;
&lt;br /&gt;
These very same modules represent the dominant social engineering attack vector on the Internet due to the quality of the spoofs and the end users' gullibility while self-infecting themselves. For the time being, the author appears to be an opportunist rather than someone interested in setting new benchmarks for standardization social engineering by using the efficiency and delivery methods offered by a web malware exploitation kit.&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SnGh1LYXfoI/AAAAAAAAEAU/YcthtxnZr_Q/s1600-h/screenshotz1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SnGh1LYXfoI/AAAAAAAAEAU/YcthtxnZr_Q/s200/screenshotz1.jpg" /&gt;&lt;/a&gt;Interestingly, a huge number of fake codec serving web sites are already detecting the OS/Browser of the visitor, and serving &lt;a href="http://blogs.zdnet.com/security/?p=3575"&gt;Mac OS X based malware&lt;/a&gt; or Windows based malware based on the detection. This fact, as well as the fact that visual spoofs of OS X like dialogs are also getting template-ized are not a coincidence - it's a signal for an efficient and social engineering driven malware delivery mechanism in the works. The development of the kit will be monitored and updates posted - if any.&lt;br /&gt;
&lt;br /&gt;
Meanwhile, the recent blackhat SEO campaign which attempted to hijack '&lt;i&gt;Harry Potter and the Half-Blood Prince&lt;/i&gt;' related traffic is a good example on how despite the magnitude of the campaign -- hundreds of thousands of indexed and malware serving pages -- due to the manual campaign management, its centralized nature makes it easier to shut down.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SnGpvhXlbQI/AAAAAAAAEAc/uL1jRRDcLOs/s1600-h/fake_codec_harry_potter_blackhat_seo.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SnGpvhXlbQI/AAAAAAAAEAc/uL1jRRDcLOs/s200/fake_codec_harry_potter_blackhat_seo.png" /&gt;&lt;/a&gt; Upon clicking on a link, the end user was redirected to &lt;b&gt;usa-top-news .info&lt;/b&gt; - 67.228.147.71 - Email: fullhdvid@gmail.com, then to &lt;b&gt;world-news-scandals .com&lt;/b&gt; Email: wnscandals@gmail.com, and finally to &lt;b&gt;tubesbargain .com&lt;/b&gt;/xplay.php?id=40018 - 216.240.143.7 - j0cqware@gmail.com where &lt;a href="http://www.virustotal.com/analisis/3f50aa3f6da31c4a93aa6113f927a67e836ee6cd96fdca6a161ab52918468950-1248724591"&gt;the codec was served&lt;/a&gt; from &lt;b&gt;exefreefiles .com&lt;/b&gt; - 95.211.8.20 - Email: case0ns@gmail.com.&amp;nbsp; More coded serving domains are parked on the same IPs:&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;
216.240.143.7&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;sunny-tube-world .com&lt;/b&gt; - Email: briashou@gmail.com&lt;br /&gt;
&lt;b&gt;the-blue-tube&amp;nbsp; .com&lt;/b&gt; - Email: malccrome@gmail.com&lt;br /&gt;
&lt;b&gt;onlysteeltube.com&lt;/b&gt; - Email: briashou@gmail.com&lt;br /&gt;
&lt;b&gt;thecooltube .com&lt;/b&gt; - Email: malccrome@gmail.com&lt;br /&gt;
&lt;b&gt;etesttube .com&lt;/b&gt; - Email: katschezz@gmail.com&lt;br /&gt;
&lt;b&gt;thegrouttube .com&lt;/b&gt; - Email: katschezz@gmail.com&lt;br /&gt;
&lt;b&gt;fllcorp .com&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
95.211.8.20&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;exe-load-2009 .com&lt;/b&gt; - Email: robeshur@gmail.com&lt;br /&gt;
&lt;b&gt;exefiledata .com&lt;/b&gt; - Email: robeshur@gmail.com&lt;br /&gt;
&lt;b&gt;exereload .com&lt;/b&gt; - Email: robeshur@gmail.com&lt;br /&gt;
&lt;b&gt;load-exe-world .com&lt;/b&gt; - Email: robeshur@gmail.com&lt;br /&gt;
&lt;b&gt;cool-exe-file .com&lt;/b&gt; - Email: robeshur@gmail.com&lt;br /&gt;
&lt;b&gt;last-home-exe .com&lt;/b&gt; - Email: robeshur@gmail.com&lt;br /&gt;
&lt;b&gt;exefreefiles .com&lt;/b&gt; - Email: case0ns@gmail.com&lt;br /&gt;
&lt;b&gt;boardexefiles .com&lt;/b&gt; - Email: case0ns@gmail.com&lt;br /&gt;
&lt;b&gt;exeloadsite .com&lt;/b&gt; - Email: j0cqware@gmail.com&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SnGw-1iMnaI/AAAAAAAAEAk/iv6dSt_Dg3Q/s1600-h/mac_os_x_malware_fake_codec_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SnGw-1iMnaI/AAAAAAAAEAk/iv6dSt_Dg3Q/s200/mac_os_x_malware_fake_codec_1.JPG" /&gt;&lt;/a&gt;The gang maintains another domain portfolio with pretty descriptive nature for phone back, direct fake codec serving purposes:&lt;br /&gt;
&lt;/div&gt;&lt;b&gt;agro-files-archive .com&lt;br /&gt;
alkbbs-files .com&lt;br /&gt;
all-tube-world .com&lt;br /&gt;
best-light-search .com&lt;br /&gt;
besttubetech .com&lt;br /&gt;
chamitron .com&lt;br /&gt;
cheappharmaad .com&lt;br /&gt;
dipexe .com&lt;br /&gt;
downloadnativeexe .com&lt;br /&gt;
ebooks-archive .org&lt;br /&gt;
etesttube .com&lt;br /&gt;
exedownloadfull .com&lt;br /&gt;
exefiledata .com&lt;br /&gt;
exe-paste .com&lt;br /&gt;
exe-soft-development .com&lt;br /&gt;
exe-xxx-file .com&lt;br /&gt;
eyeexe .com&lt;br /&gt;
go-exe-go .com&lt;br /&gt;
greattubeamp .com&lt;br /&gt;
green-tube-site .com&lt;br /&gt;
hotexedownload .com&lt;br /&gt;
hot-exe-load .com&lt;br /&gt;
imagescopybetween .com&lt;br /&gt;
isyouimageshere .com&lt;br /&gt;
labsmedcom .com&lt;br /&gt;
last-exe-portal .com&lt;br /&gt;
lost-exe-site .com&lt;br /&gt;
lyy-exe .com&lt;br /&gt;
main-exe-home .com&lt;br /&gt;
mchedlishvili .name&lt;br /&gt;
metro-tube .net&lt;br /&gt;
my-exe-load .com&lt;br /&gt;
newfileexe .com&lt;br /&gt;
protectionimage .com&lt;br /&gt;
robo-exe .com&lt;br /&gt;
rube-exe .com&lt;br /&gt;
securetaxexe .com&lt;br /&gt;
softportal-extrafiles .com&lt;br /&gt;
softportal-files .com&lt;br /&gt;
storeyourimagehere .com&lt;br /&gt;
super0tube .com&lt;br /&gt;
super-exe-home .com&lt;br /&gt;
supertubetop .com&lt;br /&gt;
sysreport1 .com&lt;br /&gt;
sysreport2 .com&lt;br /&gt;
testtubefilms .com&lt;br /&gt;
texasimages2009 .com&lt;br /&gt;
the-blue-tube.com&lt;br /&gt;
thecooltube .com&lt;br /&gt;
thegrouttube .com&lt;br /&gt;
thetubeamps .com&lt;br /&gt;
thetubesmovie .com&lt;br /&gt;
tiaexe .com&lt;br /&gt;
tube-best-4free .com&lt;br /&gt;
tube-collection .com&lt;br /&gt;
tvtesttube .com&lt;br /&gt;
yourtubetop .com&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Who's behind these domains and the Harry Potter blackhat SEO campaign? But, "of course", it's the "&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;fan club&lt;/a&gt;" with the &lt;a href="http://ddanchev.blogspot.com/2009/07/koobface-come-out-come-out-wherever-you.html"&gt;Koobface connection&lt;/a&gt;, continuing to use &lt;a href="http://ddanchev.blogspot.com/2009/07/from-ukraine-with-bogus-twitter.html"&gt;the same phone back locations&lt;/a&gt; that they've been using during &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;the past couple of months&lt;/a&gt; - &lt;b&gt;myart-gallery .com&lt;/b&gt;/senm.php - 64.27.5.202 - Email: jnthndnl@gmail.com; &lt;b&gt;robert-art .com/senm.php&lt;/b&gt; - 66.199.229.229 - Email: robesha@gmail.com; &lt;b&gt;superarthome .com/senm.php&lt;/b&gt; - 216.240.146.119 - Email: chucjack@gmail.com.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt; &lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-5223434556399065399?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=D4IEbtMORJo:mcsOP5xR-d8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=D4IEbtMORJo:mcsOP5xR-d8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=D4IEbtMORJo:mcsOP5xR-d8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=D4IEbtMORJo:mcsOP5xR-d8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=D4IEbtMORJo:mcsOP5xR-d8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=D4IEbtMORJo:mcsOP5xR-d8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=D4IEbtMORJo:mcsOP5xR-d8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=D4IEbtMORJo:mcsOP5xR-d8:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?a=D4IEbtMORJo:mcsOP5xR-d8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/DanchoDanchevOnSecurityAndNewMedia?i=D4IEbtMORJo:mcsOP5xR-d8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/D4IEbtMORJo" height="1" width="1"/&gt;</description><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-24T23:03:01.468+02:00</app:edited><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_wICHhTiQmrA/SnGbqYpyy0I/AAAAAAAAD_8/7-G_nBFhtVE/s72-c/screenshotz33.JPG" height="72" width="72" /><feedburner:origLink>http://ddanchev.blogspot.com/2009/07/social-engineering-driven-web-malware.html</feedburner:origLink></item></channel></rss>
