<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Spyware Sucks</title><link>http://msmvps.com/blogs/spywaresucks/default.aspx</link><description>But here is the dirty little secret of browser security: Even if every Internet browser made today were completely bug-free, it wouldn&amp;#39;t stop malicious hackers and malware. Why? Because the vast majority of successful malicious exploits today don&amp;#39;t exploit buggy browsers, but rather unwitting end-users. That is, Web-based malware is successful because end-users are intentionally installing it! Most exploit code doesn&amp;#39;t search for an unpatched vulnerability, but simply asks the user to install. - Roger Grimes, Infoworld
&lt;br /&gt;&lt;br /&gt;
&amp;quot;There is no magic fairy dust protecting Macs&amp;quot; - Dai Zovi, security researcher and co-author of The Mac Hacker&amp;#39;s Handbook.</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/SpywareSucks" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><title>FTC versus Innovative Marketing et al - developments</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/29duN1s3xvo/1740364.aspx</link><pubDate>Tue, 17 Nov 2009 23:58:50 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1740364</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1740364</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/11/18/1740364.aspx#comments</comments><description>&lt;p&gt;As we know, Jain&amp;#39;s legal counsel have applied for leave to withdraw as his attorneys of record.&amp;#160; They have not been given permission to withdraw yet, and the deadline for Jain to respond to the FTC&amp;#39;s renewed motion for sanctions was nigh, therefore Jain&amp;#39;s counsel has filed a document in opposition to the renewed motion. &lt;/p&gt;  &lt;p&gt;Jain&amp;#39;s counsel claims that: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Mr. Jain is not acting in bad faith, but on a well-justified fear that the FTC will attempt to circumvent and undermine his valid Fifth Amendment privilege against self-incrimination&lt;/em&gt;&amp;quot;. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;and &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Regarding deterrence, Mr. Jain is not guilty of a pattern of contumacious behavior; indeed, through counsel, he otherwise has actively participated in this case for almost one year&lt;/em&gt;.&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;and &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Finally, the FTC does not even address the possibility of lesser sanctions against Mr. Jain.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;My immediate reaction, on reading the motion, was “&lt;em&gt;come on, who are they trying to fool?&lt;/em&gt;”. Let&amp;#39;s not forget, when reading the above, that Jain&amp;#39;s legal counsel claim in their motion for leave to withdraw that they have NEVER had direct contact with Jain, and that they have had no indirect contact with him for more than 10 months, and that they have no idea where he is.&amp;#160; Such silence does not equate to &amp;#39;active&amp;#39; participation in my world. &lt;/p&gt;  &lt;p&gt;Not surprisingly, the FTC&amp;#39;s response has been swift and states, in part: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Counsel’s description of Jain’s conduct bears no resemblance to the facts of this case. Jain – a fugitive for nearly a year now – has been toying with this Court and the FTC from the outset of this case. Jain has ignored the Temporary Restraining Order and Preliminary Injunction entered by this Court, and completely disregarded this Court’s most recent command that he appear for deposition.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;and &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Jain has also wasted this Court’s time with a barrage of frivolous motions, which were designed solely to bog down this litigation and delay the FTC’s efforts to obtain redress on behalf of the millions of consumers Jain and his co-defendants have defrauded. Having succeeded in delaying this case for as long as possible, Jain has now disappeared, and left his lawyers behind to craft excuses for his egregious conduct.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;It makes you wonder whether Jain&amp;#39;s lawyers have received, or are going to receive, payment for their hard work over the past year, doesn&amp;#39;t it.&amp;#160; Here&amp;#39;s hoping they received plenty of $$ in advance.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1740364" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=29duN1s3xvo:PWHEEoqJXN4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=29duN1s3xvo:PWHEEoqJXN4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=29duN1s3xvo:PWHEEoqJXN4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/29duN1s3xvo" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/11/18/1740364.aspx</feedburner:origLink></item><item><title>FTC versus Innovative Marketing et al - Sam Jain's legal counsel request leave to withdraw as attorneys of record</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/R4gzdxgEm6s/1739915.aspx</link><pubDate>Mon, 16 Nov 2009 01:49:05 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1739915</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1739915</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/11/16/1739915.aspx#comments</comments><description>&lt;p&gt;In a not unsurprising development, legal counsel for Sam Jain have petitioned the Court for permission to withdraw as attorneys for Sam Jain.&amp;#160; The FTC does not oppose the request, but does object to any further extension of Mr Jain&amp;#39;s time to respond to the FTC&amp;#39;s pending Renewed Motion for Rule 37 Sanctions. &lt;/p&gt;  &lt;p&gt;The reasons Jain&amp;#39;s attorneys ask for permission to withdraw are: &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;They have NEVER communicated directly with Jain.&lt;/li&gt;    &lt;li&gt;Their last indirect communication with Jain was received on January 14, 2009.&lt;/li&gt;    &lt;li&gt;They have not communicated with Jain in more than 10 months, since before the bench warrant was issued for Jain&amp;#39;s arrest by the US District Court for the Northern District of California in an unrelated.&lt;/li&gt;    &lt;li&gt;They claim to have no knowledge of Jain&amp;#39;s whereabouts, and to have no ability to contact him directly. &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Jain&amp;#39;s legal counsel state that &amp;quot;considering the bench warrant in the Northern District of California and the ongoing criminal investigation in the Northern District of Illinois, there is no indication Mr Jain will participate meaningfully in discovery, with or without counsel.&amp;quot;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1739915" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=R4gzdxgEm6s:t6Vfq5ePoBs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=R4gzdxgEm6s:t6Vfq5ePoBs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=R4gzdxgEm6s:t6Vfq5ePoBs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/R4gzdxgEm6s" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/11/16/1739915.aspx</feedburner:origLink></item><item><title>FTC versus Innovative Marketing et al - developments</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/h0d0htO4-QY/1738897.aspx</link><pubDate>Wed, 11 Nov 2009 03:33:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1738897</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1738897</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/11/11/1738897.aspx#comments</comments><description>&lt;p&gt;Innovative Marketing and Daniel Sundin are still unrepresented.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;09/16/2009      &lt;br /&gt;ORDER denying Motion of Marc D&amp;#39;Souza to Dismiss the Complaint. DIRECTING D&amp;#39;Souza to answer the complaint within 20 days. Signed by Judge Richard D Bennett on 9/16/09. &lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Viewing the totality of the allegations through the lens of judicial experience and common sense, this Court finds that the FTC has clearly “plea{d} factual content that allows the court to draw the reasonable inference that the defendant is liable for the misconduct alleged.” Iqbal, 129 S. Ct. at 1949 (citing Twombly, 550 U.S. at 50). Through its extensive factual pleadings, the FTC has positioned its claims against Marc D’Souza safely within the realm of plausibility.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;10/02/2009      &lt;br /&gt;MEMORANDUM ORDER granting Motion for Sanctions against Sam Jain insofar as certain conditions are imposed.&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;“The FTC’s Motion for Rule 37 Sanctions against Defendant Sam Jain (Paper No. 131) is GRANTED insofar as the following conditions are hereby imposed: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;em&gt;“1. the FTC is instructed to re-notice Jain’s deposition for an agreed upon time within the next thirty days of the date hereof;        &lt;br /&gt;2. Jain shall again be offered the opportunity to be deposed by video-conference from a location of his choosing;         &lt;br /&gt;3. Jain is hereby warned that if he fails to attend this upcoming deposition, this Court will consider imposing a default judgment against him pursuant to Federal Rule of Civil Procedure 37(d).”&lt;/em&gt; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;10/06/2009      &lt;br /&gt;ANSWER to FTC Complaint (document 1), by Marc D&amp;#39;Souza&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;A few minor admissions, lots of denials, a claim that &amp;quot;the FTC has authority to seek restitution, consumer redress or disgorgement with respect to conduct that took place outside the United States and that does not affect domestic commerce&amp;quot;, lot of declining to answer under the Fifth Amendment (while at the same time requesting that said refusal be treated as a denial).&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;10/22/2009      &lt;br /&gt;Second MOTION for Sanctions Pursuant to Rule 37 Against Sam Jain by Federal Trade Commission. Responses due by 11/9/2009&lt;/strong&gt; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Sam Jain has made a mockery of this proceeding and has demonstrated nothing but contempt for this Court and the American judicial system as a whole. Together with his codefendants, Jain perpetrated one of the largest online frauds ever prosecuted by the FTC, with a total consumer injury figure that – as the Court will soon hear – exceeds $150 million. After being caught red-handed by the FTC, Jain promptly fled the United States, leaving his lawyers behind to delay the FTC’s efforts to redress the massive consumer injury Jain helped inflict. After nearly a year of delay, Jain has reached the end of the road. Unwilling to comply with this Court’s command that he participate in discovery, Jain has no further ability to stall this litigation. As a result, Jain has washed his hands of this matter, and simply disappeared. Given these facts, it is difficult to imagine a case that better supports the imposition of terminating sanctions, or an individual more deserving of such an outcome than Jain.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;11/02/2009      &lt;br /&gt;MOTION for Extension of Time to File Response/Reply as to Second MOTION for Sanctions Pursuant to Rule 37 Against Sam Jain by Sam Jain. Responses due by 11/19/2009 (unopposed)&lt;/strong&gt; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Mr. Jain respectfully submits that good cause for granting this Motion exists: (1) Mr. Jain has not requested or received from the Court an extension on any other response or reply filed in this case; (2) Logistical obstacles and the important factual and legal issues raised by the FTC’s Renewed Motion necessitate a brief extension of time to respond.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;11/03/2009      &lt;br /&gt;Paperless ORDER granting Defendant Jain&amp;#39;s unopposed Motion for Extension of Time. Response to Second Motion for Sanctions due 11/16/2009 &lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1738897" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=h0d0htO4-QY:C2kNZqTPoVE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=h0d0htO4-QY:C2kNZqTPoVE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=h0d0htO4-QY:C2kNZqTPoVE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/h0d0htO4-QY" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/11/11/1738897.aspx</feedburner:origLink></item><item><title>Ponderings about the incident that hit Gizmodo (courtesy of Gawker)</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/lO8ulIttlEE/1738591.aspx</link><pubDate>Mon, 09 Nov 2009 14:08:09 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1738591</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1738591</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/11/09/1738591.aspx#comments</comments><description>&lt;p&gt;While I was on holidays, a malvertizing incident hit Gizmodo (via advertising sold to Gawker).&amp;#160; The miscreants impersonated the legitimate advertising agency Spark Communications, registering the domain spark-smg.com (the real domain is sparksmg.com) to assist in the impersonation. &lt;/p&gt;  &lt;p&gt;Publicis have since taken over the fraudulent domain spark-smg.com but we still have access to historical information about the domain which is interesting. &lt;/p&gt;  &lt;p&gt;Before we get into the nitty gritty of the domain itself, I have a few observations to make.&amp;#160; In short, the tricks used were not new.&lt;/p&gt;  &lt;p&gt;&amp;quot;Gawker Sales Guy&amp;quot; says on the &lt;a href="http://www.businessinsider.com/henry-blodget-gawker-scammed-by-malware-pretending-to-be-suzuki-2009-10#comment-4ae6400b00000000002367fd" target="_blank"&gt;businessinsider.com web site&lt;/a&gt; that&amp;quot; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;The reason this is news (and the reason we sent it here in the first place) is because these guys were so thorough they managed to fool multiple levels of safeguards we have in place to keep this thing from happening. There was literally NO way for us to know, short of calling the agency and doing background checks on everyone we work with.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Why did nobody notice that the domain spark-smg.com being was used, instead of sparksmg.com.&amp;#160; I concede that the difference between the domains is subtle, but even if&amp;#160; the &amp;quot;Gawker Sales Guy&amp;quot; who was corresponding with the miscreants did not notice the subtle difference in domains at first, I would have expected him to take a closer look when one of his emails bounced on Saturday 28 September. &lt;/p&gt;  &lt;p&gt;The realities of malvertizing *are* well known in the industry nowadays, thanks to all of the publicity that it has received over the past year or so.&amp;#160; Many warnings have been sent out by various parties and there have been many high profile incidents.&amp;#160; The new person approaching Gawker, the bounced email, and the wide variation in time of day when emails were received should have all given the Gawker Sales Guy reason to pause and take a closer look (despite the fraudster claiming, in one email, to be in London).&amp;#160; &amp;quot;Background checks&amp;quot; should be standard operating procedure, and &amp;quot;calling the agency&amp;quot; using their main telephone number (not a direct line) should also be standard operating procedure, even after background checks have been completed, whenever a new name appears. &lt;/p&gt;  &lt;p&gt;Gawker Sales Guy (&lt;a href="http://www.businessinsider.com/henry-blodget-gawker-scammed-by-malware-pretending-to-be-suzuki-2009-10#comment-4ae6561900000000008b1b70)" target="_blank"&gt;http://www.businessinsider.com/henry-blodget-gawker-scammed-by-malware-pretending-to-be-suzuki-2009-10#comment-4ae6561900000000008b1b70)&lt;/a&gt; then goes on to say: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;This was truly damn near impossible to spot as a fake.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;This claim is impossible to judge without specific technical information.&amp;#160; That being said, the ads have to touch something bad as part of the malvertizement process, even if the malicious behaviour itself does not trigger. &lt;/p&gt;  &lt;p&gt;On the BBC web site (&lt;a href="http://news.bbc.co.uk/2/hi/technology/8328399.stm)" target="_blank"&gt;http://news.bbc.co.uk/2/hi/technology/8328399.stm)&lt;/a&gt; it states: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Blaming the fact that staff used Linux operating systems on their production machines for &amp;quot;not noticing sooner&amp;quot;, it advised concerned users to load some up-to-date antivirus software and &amp;quot;make sure your system is clean&lt;/em&gt;&amp;quot;.&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The fact that staff use Linux on their production machines is not why the staff did not see the malvertizements.&amp;#160; As regular readers of this blog know, the miscreants behind malvertizing actively manage their campaigns, deliberately doing all they can to avoid detection by victim web sites via geo-targeting, IP exclusions and whatnot.&amp;#160; I would be *extremely* surprised if the malicious behaviour would have been triggered if the malvertizement was displayed on a computer within an IP range associated with the victim web site, or the infrastructure used to serve the advertisement, even if it were running an old, vulnerable, version of Windows.&amp;#160; The bad guys are not fools – they are not going to allow malicious behaviour to trigger on a computer known to be owned by the very people they are trying to fool and defraud.&lt;/p&gt;  &lt;p&gt;Online Media Daily (&lt;a href="http://www.mediapost.com/publications/?fa=Articles.showArticle&amp;amp;art_aid=116269)" target="_blank"&gt;http://www.mediapost.com/publications/?fa=Articles.showArticle&amp;amp;art_aid=116269)&lt;/a&gt; states that it &amp;quot;&lt;em&gt;is believed to be the first to successfully mimic the identity of a major advertising agency&lt;/em&gt;&amp;quot;. &lt;/p&gt;  &lt;p&gt;Ok, I suppose we can argue about what a &amp;quot;major&amp;quot; advertising agency is, but it certainly is not the first time an advertising agency has been spoofed (or the first time that the bad guys have made preparations to do just that).&amp;#160; Some malicious domains that I have seen, and reported on in the past, that could be used to spoof legitimate ad networks include: &lt;/p&gt;  &lt;p&gt;byronadvertising.eu (used to impersonate the legitimate byronadvertising.com and byronadvertising.co.uk)    &lt;br /&gt;koeppelinteractive.co.uk (impersonating koeppelinteractive.com, redirecting visitors to that domain)     &lt;br /&gt;quigley-simpson.net (impersonating quigleysimpson.com, redirecting visitors to that domain)     &lt;br /&gt;mediavest-corp.com (WHOIS referred to support@us-resources.com, an email address also used with the legitimate mediavest.net)     &lt;br /&gt;posnerpromotion.com (impersonating posneradv.com, redirecting visitors to that domain)     &lt;br /&gt;adconion-inc.com (impersonating adconion.com, redirecting visitors to that domain)     &lt;br /&gt;carat-inc.com (impersonating carat.com, redirecting visitors to that domain)     &lt;br /&gt;pubmatic-inc.com (impersonating pubmatic.com, redirecting visitors to that domain)     &lt;br /&gt;doubleclick-ssl.com (impersonating Doubleclick) &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Then there are the fake sites pretending to sell advertising directly on behalf of large corporations: &lt;/p&gt; nokia-corp.com (shared IP with lacoste-ads for a while - can be assumed to impersonate Nokia)   &lt;br /&gt;foxinteractivemedia-inc.com (impersonating fox.com, redirecting visitors to that domain)   &lt;br /&gt;lacoste-ads.com (impersonating lacoste.com, redirecting visitors to that domain)   &lt;br /&gt;orangeadvertising-inc.com (impersonating orange.com, redirecting visitors to that domain)   &lt;br /&gt;hyundai-inc.com (impersonating hyundai-motor.com, redirecting visitors to that domain)   &lt;br /&gt;singlesnet-inc.com (impersonating singlesnet.com, redirecting visitors to that domain)   &lt;br /&gt;vonage-inc.com (used to impersonate the real Vonage)   &lt;p&gt;Tribalfusion has even been impersonated in a credit reference. &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Anyway, let&amp;#39;s take a look at spark-smg.com and see what danger signs we can find by examining historical data (taken from before Publicis Groupe S.A. took over the domain).&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;spark-smg.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM (a known problem Registrar)     &lt;br /&gt;Created 4 September 2009 (a very new domain, another bad sign) &lt;/p&gt;  &lt;p&gt;IP address (up until on or about 3 October 2009): 212.117.175.6 &lt;/p&gt;  &lt;p&gt;212.117.175.6 = Luxembourg Root Esolutions (another problematic host, too often seen in association with malvertizing). &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Note:&amp;#160; A check of the IP range 212.117.175.% reveals a few domains associated with advertising that should be treated with caution: &lt;/p&gt;  &lt;p&gt;RevolteChMedia.com (claims to have been around since 2004, but the domain was only registered on 13 October 2009 - ICANN Registrar BIZCN.COM, INC)) &lt;/p&gt;  &lt;p&gt;BellWayInteractive.com (registered on 14 September 2009 - ICANN Registrar BIZCN.COM, INC) &lt;/p&gt;  &lt;p&gt;SmartMediaWay.com (registered 14 September 2009 - ICANN Registrar BIZCN.COM, INC) &lt;/p&gt;  &lt;p&gt;GoldBayMedia.com (registered 14 September 2009 - ICANN Registrar BIZCN.COM, INC)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1738591" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=lO8ulIttlEE:IKuUswsVCFY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=lO8ulIttlEE:IKuUswsVCFY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=lO8ulIttlEE:IKuUswsVCFY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/lO8ulIttlEE" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/11/09/1738591.aspx</feedburner:origLink></item><item><title>Six countries, and 3 weeks, later I am back from holidays</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/jzENtjkvbOY/1736792.aspx</link><pubDate>Sun, 01 Nov 2009 15:49:01 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1736792</guid><dc:creator>sandi</dc:creator><slash:comments>4</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1736792</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/11/01/1736792.aspx#comments</comments><description>&lt;p&gt;After exploring the northern hemisphere of our amazing planet and visiting climates as varied as 41 degrees (Celsius) in Egypt and –2 degrees (Celsius) in an ice grotto situated at 3,000 feet above sea level in Switzerland, and flying over the Ukraine at roughly 11,000 feet (yes, malvertizing did cross my mind when I saw where the plane was situated) I am back on duty and ready to resume keeping all of you informed about the latest happenings in the malvertizing world.&lt;/p&gt;  &lt;p&gt;My apologies for not letting my loyal readers know that I would be absent; for obvious reasons I prefer NOT to advertise publicly that I will be away for an extended period until after I return.&lt;/p&gt;  &lt;p&gt;If anybody is interested in photos, I took 600 (and some of them are even pretty good) … :-)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1736792" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=jzENtjkvbOY:jiTkdoHxjmE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=jzENtjkvbOY:jiTkdoHxjmE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=jzENtjkvbOY:jiTkdoHxjmE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/jzENtjkvbOY" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Admin+announcements/default.aspx">Admin announcements</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/11/01/1736792.aspx</feedburner:origLink></item><item><title>And the winner is…</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/BZo-sjl_-rQ/1730437.aspx</link><pubDate>Wed, 07 Oct 2009 06:11:52 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1730437</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1730437</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/10/07/1730437.aspx#comments</comments><description>&lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Better… much better…&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6371.image_5F00_0AC164A7.png" width="307" height="192" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Poll results&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3250.image_5F00_7E10DB3F.png" width="604" height="353" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1730437" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=BZo-sjl_-rQ:a8B-0W08qP0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=BZo-sjl_-rQ:a8B-0W08qP0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=BZo-sjl_-rQ:a8B-0W08qP0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/BZo-sjl_-rQ" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Off+topic/default.aspx">Off topic</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/10/07/1730437.aspx</feedburner:origLink></item><item><title>Would you like to help choose the new Vegemite name?</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/3bJnUAF9wx0/1728979.aspx</link><pubDate>Fri, 02 Oct 2009 13:13:17 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1728979</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1728979</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/10/02/1728979.aspx#comments</comments><description>&lt;p&gt;Kraft have bowed to public pressure, and have scrapped the (dare I say loathed) Vegemite name “iSnack 2.0”.&lt;/p&gt;  &lt;p&gt;And, they have decided that the public will choose the new name, by voting on it.&lt;/p&gt;  &lt;p&gt;Here is the URL if you’re so inclined:   &lt;br /&gt;&lt;a title="http://www.ys2.net.au/surveys/9/y90926.asp" href="http://www.ys2.net.au/surveys/9/y90926.asp" target="_blank"&gt;http://www.ys2.net.au/surveys/9/y90926.asp&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;There are six names to choose from, and sadly you will have to rate them from your first choice, to your last choice.&amp;#160; The choices are:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Vegemite Cheesybite, Vegemite Vegemate, Vegemite Snackmate, Vegemite Smooth, Vegemite Vegemild and Vegemite Creamymate &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Polling starts at 5pm (AEST) on Friday 2 October 2009 and ends at 12 noon (AEDST) on Monday 5 October 2009.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1728979" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=3bJnUAF9wx0:d6BDJF4yWUo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=3bJnUAF9wx0:d6BDJF4yWUo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=3bJnUAF9wx0:d6BDJF4yWUo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/3bJnUAF9wx0" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Off+topic/default.aspx">Off topic</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/10/02/1728979.aspx</feedburner:origLink></item><item><title>I have received the Microsoft MVP Award – for the 11th time</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/DBZCNj4IeuE/1728978.aspx</link><pubDate>Fri, 02 Oct 2009 13:05:22 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1728978</guid><dc:creator>sandi</dc:creator><slash:comments>5</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1728978</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/10/02/1728978.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4721.image_5F00_7C595E5E.png" width="141" height="201" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I received an email today advising me that I have been awarded Microsoft MVP status for the 11th time.&lt;/p&gt;  &lt;p&gt;Unlike my previous 10 awards, this time I have been awarded Microsoft MVP under the specialty “Consumer Security: Training” instead of as an Internet Explorer MVP.&amp;#160; I think that is perfectly appropriate; for years I have focused on Consumer Security from the perspective of an Internet Explorer user, but in recent years my focus has moved to studying malvertizing – what it is, how it works, and who is behind it – and, most importantly, sharing and passing on that knowledge and advising advertising networks and web site owners on how to best avoid the miscreants behind malicious advertising.&lt;/p&gt;  &lt;p&gt;Avoiding the bad guys is NOT easy, and is getting harder all the time.&amp;#160; As the Internet Community as a whole has become more aware, and as people as myself have put so much time and effort into educating the community, the bad guys have had to match our efforts and become sneakier.&amp;#160; The impersonation of legitimate companies has become more common; malicious SWF advertisements seem to be falling out of favor as we get better at detecting them, and the bad guys no longer dump all of their eggs in the one basket.&lt;/p&gt;  &lt;p&gt;The most important thing that any of us can do is complete comprehensive reputational research and background checks into any new advertiser/partner/client.&amp;#160; And, don’t take what is on those credit reference forms at face value.&amp;#160; Double check that the phone number supplied for the credit reference matches the company that he or she claims to work for.&amp;#160; If approached by a well known company, make sure that the domain being used actually belongs to that company.&lt;/p&gt;  &lt;p&gt;If you are approached by a well known company, put the attraction of money aside and ask yourself why they would want to advertise with you, and &lt;u&gt;be honest with yourself in your answers&lt;/u&gt;.&amp;#160; Do you attract enough traffic to make it worth their while? Are you well known enough? Is your target audience appropriate to what they are selling?&amp;#160; Is there a sense of urgency to the sale? Are they contacting you at unusual times of the day or night?&amp;#160; Are they reluctant to speak by telephone?&amp;#160; Does an answering machine pick up too often?&lt;/p&gt;  &lt;p&gt;A good reputation is hard won, and easily lost, and the negative press caused by a malvertizing incident does not go away.&amp;#160; Your web site may be blocked by the various web reputation services that are available nowadays.&amp;#160; Google may block access to your site via web searches.&amp;#160; Eventually there may be a noticeable reduction in advertising income if your visitors take it upon themselves to block all advertising for their own protection, or they may become angry or frustrated and stop visiting at all, especially if there is more than one malvertizing incident.&lt;/p&gt;  &lt;p&gt;Finally – &lt;u&gt;&lt;strong&gt;train your staff&lt;/strong&gt;&lt;/u&gt;. Make &lt;a href="http://www.anti-malvertising.com" target="_blank"&gt;www.anti-malvertising.com&lt;/a&gt; required reading and DO WHAT IS SUGGESTED.&amp;#160; If, despite your best efforts, you receive reports of problems from your visitors, DO NOT assume that your visitor is blaming you unfairly, or that there may be a problem with their computer.&amp;#160; Take *all* reports seriously, and ASK FOR HELP.&amp;#160; It is unlikely that your visitors will be sophisticated enough to be able to gather the evidence you need on their own, and the bad guys are very good at hiding their activities from you using various tricks.&lt;/p&gt;  &lt;p&gt;And keep reading this blog :)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1728978" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=DBZCNj4IeuE:zeP0YrF_Lsk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=DBZCNj4IeuE:zeP0YrF_Lsk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=DBZCNj4IeuE:zeP0YrF_Lsk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/DBZCNj4IeuE" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/General+stuff/default.aspx">General stuff</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/10/02/1728978.aspx</feedburner:origLink></item><item><title>Waiting for an Apple lawsuit….</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/nnmcWg_yOUQ/1727500.aspx</link><pubDate>Sun, 27 Sep 2009 05:19:11 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1727500</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1727500</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/27/1727500.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5807.image_5F00_11DDBCC6.png" width="180" height="246" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;… or maybe a lawsuit by the makers of “&lt;a href="http://www.taquitos.net/snacks.php?snack_code=1760" target="_blank"&gt;iSnack Cyber Chips&lt;/a&gt;” or the “&lt;a href="http://multicoach.co.za/index.php/isnack/" target="_blank"&gt;iSnack Energy Bar&lt;/a&gt;”.&lt;/p&gt;  &lt;p&gt;Yes, Kraft really did choose to name their new Vegemite “&lt;a href="http://vegemite.wunderman.com.au/index_swf.html" target="_blank"&gt;&lt;strong&gt;iSnack 2.0&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;”&lt;/strong&gt;.&amp;#160; The name was “invented” (and I use that term very loosely) by Dean Robbins, a 27 year old West Australian and graphic and web designer.&lt;/p&gt;  &lt;p&gt;What were Kraft thinking…&lt;/p&gt;  &lt;p&gt;So far, the responses I am seeing are overwhelmingly negative, and you can add me to the list of critics.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1727500" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=nnmcWg_yOUQ:2jEmm9hrroo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=nnmcWg_yOUQ:2jEmm9hrroo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=nnmcWg_yOUQ:2jEmm9hrroo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/nnmcWg_yOUQ" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Off+topic/default.aspx">Off topic</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/09/27/1727500.aspx</feedburner:origLink></item><item><title>ALERT: Please treat content from extrabanner.com with extreme caution</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/3qsWZXnmS_A/1725131.aspx</link><pubDate>Sun, 20 Sep 2009 06:39:50 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1725131</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1725131</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/20/1725131.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/1323.image_5F00_5CCBA833.png" width="542" height="110" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Regular readers will recognize the domains t.banner09092.com and blackwater-cuprumworks.net – they were the domains used to attempt infection of computers via various security exploits:    &lt;br /&gt;&lt;a title="http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx" href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Luckily, the domain blackwater-cuprumworks.net is not responding at the moment.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;extrabanner.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: Godaddy.com, Inc     &lt;br /&gt;Created 30 July 2009     &lt;br /&gt;NS47.DOMAINCONTROL.COM     &lt;br /&gt;NS48.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 - Arizona, Scottsdale, Godaddy.com, Inc (shares IP with 11,081,675 other sites) &lt;/p&gt;  &lt;p&gt;Registar:    &lt;br /&gt;Domain Owner (trafficbuyer@gmail.com - the same as pussbanner769.info)     &lt;br /&gt;15156 SW 5th     &lt;br /&gt;Scottsdale, Arizona 85260     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;dullnessfrequenting.info&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: Godaddy.com, Inc     &lt;br /&gt;Created 17 September 2009     &lt;br /&gt;NS57.DOMAINCONTROL.COM     &lt;br /&gt;NS58.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 - same as extrabanner.com &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Domain Owner (trafficbuyer@gmail.com)     &lt;br /&gt;15156 SW 5th     &lt;br /&gt;Scottsdale, Arizona 85260     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;t.banner09092.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: Godaddy.com, Inc     &lt;br /&gt;Created 18 September 2009     &lt;br /&gt;NS57.DOMAINCONTROL.COM     &lt;br /&gt;NS58.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 (again) &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Domain Owner (trafficbuyer@gmail.com)     &lt;br /&gt;15156 SW 5th     &lt;br /&gt;Scottsdale, Arizona 85260     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;blackwater-cuprumworks.net&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: DIRECTI (Registration service &amp;quot;Domain Names Registrar Reg.Ru Ltd&amp;quot;)     &lt;br /&gt;Created 7 September 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 213.155.2.112 - Namibia, Grinvich3, Vladimir Gubarenko &lt;/p&gt;  &lt;p&gt;Shares IP with the domains amateursex-hert.com, aw-work.net, awirons-work.com, blackwater-ironworks.com, blackwater-ironworks.net, blackwater-metalworks.net, blackwater-metalworks.net, sexamateur-hartcore.com and sleazy-dreamers.net &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Eduard Skobelev (eddiscobbi3@gmail.com)     &lt;br /&gt;ul. Starinskaya, d.1, kv. 92     &lt;br /&gt;g. Moskva     &lt;br /&gt;g. Moskva, 107009     &lt;br /&gt;RU     &lt;br /&gt;Tel: +7 4952243948 &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1725131" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=3qsWZXnmS_A:-j_6zxVzmVA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=3qsWZXnmS_A:-j_6zxVzmVA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=3qsWZXnmS_A:-j_6zxVzmVA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/3qsWZXnmS_A" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/09/20/1725131.aspx</feedburner:origLink></item><item><title>Added to the “the Victorian Police are looking for WHAT???” file</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/WmkVRps_rx4/1724278.aspx</link><pubDate>Thu, 17 Sep 2009 09:57:45 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1724278</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1724278</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/17/1724278.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5314.image_5F00_59B5A2A5.png" width="292" height="211" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;“&lt;strong&gt;SOS issued for original ABBA jumpsuit&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;VICTORIA Police have issued an SOS to help find a white jumpsuit originally worn by ABBA songstress Agnetha Faltskog. &lt;/p&gt;  &lt;p&gt;The jumpsuit, which Agnetha is pictured wearing on the cover of the Swedish pop group&amp;#39;s fourth album, Arrival, is believed to have been taken from a Melbourne house and sold at a garage sale. &lt;/p&gt;  &lt;p&gt;The jumpsuit&amp;#39;s owner had leased out the Healesville home with the 1970s jumpsuit still stored in the shed. &lt;/p&gt;  &lt;p&gt;Police believe the figure-hugging suit may have been sold by the tenants in a garage sale. &lt;/p&gt;  &lt;p&gt;The tenants will be interviewed by police, a Victoria Police spokeswoman said. &lt;/p&gt;  &lt;p&gt;Police would like to speak to anyone who may have attended a garage sale at the Don Road property in May this year.”&lt;/p&gt;  &lt;p&gt;Source: &lt;a href="http://www.news.com.au/story/0,27574,26087496-29277,00.html" target="_blank"&gt;http://www.news.com.au/story/0,27574,26087496-29277,00.html&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;(Yes, I know, the graphic I have used is not from the actual “Arrival” album’s front cover, but it does show the jumpsuit properly) ;o)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1724278" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=WmkVRps_rx4:a9DT7bVTkbk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=WmkVRps_rx4:a9DT7bVTkbk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=WmkVRps_rx4:a9DT7bVTkbk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/WmkVRps_rx4" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Off+topic/default.aspx">Off topic</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/09/17/1724278.aspx</feedburner:origLink></item><item><title>Ponderings about the New York Times malvertizing incident</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/D81ji7adztg/1723398.aspx</link><pubDate>Tue, 15 Sep 2009 05:08:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1723398</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1723398</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/15/1723398.aspx#comments</comments><description>&lt;p&gt;It has been all over the popular press – the New York Times web site had been tricked into accepting a malvertizement that was hijacking some visitors to that site and dumping them at a web site touting fake security software.&amp;#160; And, in a move that is kind of unusual, the New York Times web site displayed a warning about the malvertizement.&lt;/p&gt;  &lt;p&gt;It just so happens that over on &lt;a href="http://troy.yort.com/anatomy-of-a-malware-ad-on-nytimes-com" target="_blank"&gt;yort.com&lt;/a&gt; (author: Troy Davis) there is a screenshot demonstrating how the hijack was triggered:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;table border="5" cellspacing="2" cellpadding="5" width="924"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="433"&gt;         &lt;p align="center"&gt;&lt;strong&gt;New York Times incident as &lt;/strong&gt;&lt;strong&gt;reported on yort.com&lt;/strong&gt;&lt;/p&gt;       &lt;/td&gt;        &lt;td valign="top" width="475"&gt;         &lt;p align="center"&gt;&lt;strong&gt;Similar incident as reported on Spyware Sucks&lt;/strong&gt;&lt;/p&gt;       &lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="433"&gt;&lt;img style="border-right-width:0px;display:block;float:none;border-top-width:0px;border-bottom-width:0px;margin-left:auto;border-left-width:0px;margin-right:auto;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6763.image_5F00_76465918.png" width="447" height="460" /&gt; &lt;/td&gt;        &lt;td valign="top" width="475"&gt;&amp;#160;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4705.image_5F00_27FB9365.png" width="626" height="335" /&gt; &lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;As you can see from the screenshots above, the two incidents are very similar, and the important stuff – the stuff that caused the hijack – is the code starting at “var a1” in both screenshots.&amp;#160; Depending on various conditions and controls (geolocation, IP address, time of day etc) some visitors would have received JUST the advertisement – others would have seen **the same advertisement** but would have also received the extra code (as pointed out above, starting at var a1).&lt;/p&gt;  &lt;p&gt;The IP address of the hijacking domain, tradenton.com, is:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;at a known bad IP (as reported on this blog on the 10th of September) &lt;/li&gt;    &lt;li&gt;other bad domains were discovered in the same IP range as far back as 4 September &lt;/li&gt;    &lt;li&gt;was very new (registered just this month) &lt;/li&gt;    &lt;li&gt;was registered using a known problematic Registrar &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;I have said many times on this blog and elsewhere that reputational checks are of CRITICAL IMPORTANCE when accepting advertisements.&amp;#160; Information was available to warn those alert to potential danger that caution was needed as far back as the 4th of September (cite: &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx" target="_blank"&gt;my alert about vonage-inc.com on 4 September 2009&lt;/a&gt;).&lt;/p&gt;  &lt;p&gt;Please… take advantage of services such as &lt;a title="http://www.anti-malvertising.com/" href="http://www.anti-malvertising.com/" target="_blank"&gt;http://www.anti-malvertising.com/&lt;/a&gt; and start conducting indepth research when somebody tries to sell you advertising.&amp;#160; One day, your web site may not be hit by an advertisement that simply redirects your visitors to a fake security website.&amp;#160; Instead, your visitors may be redirected to:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;a p0rn0graphic web site, complete with streaming video and sound on the opening page:      &lt;br /&gt;&lt;a title="http://msmvps.com/blogs/spywaresucks/archive/2007/12/31/1428144.aspx" href="http://msmvps.com/blogs/spywaresucks/archive/2007/12/31/1428144.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2007/12/31/1428144.aspx&lt;/a&gt;       &lt;br /&gt;&lt;/li&gt;    &lt;li&gt;a web site that tries to infect your visitor’s computers using various security exploits:      &lt;br /&gt;      &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx&lt;/a&gt;       &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;img style="border-right-width:0px;margin:10px 0px 0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7345.image_5F00_7C96B0C3.png" width="532" height="140" /&gt;     &lt;br /&gt;&lt;strong&gt;The New York Times hijack in progress, as captured and reported by yort.com…&lt;/strong&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I have been reading the report at &lt;a href="http://www.wired.com/threatlevel/2009/09/nyt-revamps-online-ad-sales-after-malware-scam/" target="_blank"&gt;wired.com&lt;/a&gt; about this incident, and think it is worthwhile pondering some of the points made in the article.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;wired.com: “The move comes after a security loophole allowed scammers over the weekend to swap an innocuous advertisement for one serving a fake virus-warning, and hawking a deceptive scareware product intended to sell bogus security software.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;wired.com: ““Over the weekend, the ad being served up was switched so that an intrusive message, claiming to be a virus warning from the reader’s computer, appeared.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;wired.com are correct when they say that the incident occurred because of a “security loophole” (that is, the New York Times allowed content to be displayed on its web site that was hosted remotely by a domain outside of their direct command and control – an extremely common behavior and certainly not unusual to the New York Times).&amp;#160; &lt;/p&gt;  &lt;p&gt;That being said, I find it interesting that an “innocuous advertisement” would be “swapped out” or “switched”.&amp;#160; Standard modus operandi for incidents such as the one caught by yort.com has always been to simply add additional malicious code when certain conditions were met – the advertisement itself has not changed in previous incidents (except for when there is an industry-standard rotation of advertisements, which is not the same as a deliberate swapping out).&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;wired.com: “Readers &lt;u&gt;who clicked on the ad&lt;/u&gt; found their browsers hijacked while a fake virus-scan was displayed. If they allowed the malicous (sic) website to serve its executable payload, they’d be stuck with a fake scareware program that badgers them into buying supposed anti-virus software.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Wrong.&amp;#160; No user interaction is required for the hijack to occur.&amp;#160; Nobody needed to click on anything.&lt;/p&gt;  &lt;p&gt;Also, as evidenced by the yort.com report, if a person was not hijacked (and therefore had the opportunity to click on the advertisement), then they were redirected to a legitimate website (in the yort.com example, the BVLGARI advertisement was linked to the URL &lt;a title="http://www.bulgari.com/main.php?lang=6/ref=680" href="http://www.bulgari.com/main.php?lang=6/ref=680" target="_blank"&gt;http://www.bulgari.com/main.php?lang=6/ref=680&lt;/a&gt;).&lt;/p&gt;  &lt;p&gt;bulgari.com    &lt;br /&gt;ICANN Registrar: GROUP NBT PLC AKA NETNAMES     &lt;br /&gt;Created 17 February 1998     &lt;br /&gt;AUTH200.NS.UU.NET     &lt;br /&gt;AUTH210.NS.UU.NET     &lt;br /&gt;NS.BULGARI.COM &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Bulgari SpA     &lt;br /&gt;Lungotevere Marzio 11     &lt;br /&gt;Roma     &lt;br /&gt;00186     &lt;br /&gt;IT&lt;/p&gt;  &lt;p&gt;&lt;img style="border-right-width:0px;margin:10px 20px 20px 0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7444.image_5F00_0926EE91.png" width="326" height="276" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;em&gt;wired.com: “The Times declined to identify the “national advertiser” the scammers originally impersonated.”&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Again, let’s refer to yort.com.&amp;#160; From that article I can retrieve the URL of the advertisement used – you can see it to left of screen (I should warn you that there *may* have been more than one advertisement being supplied by the miscreants – we should not assume that this was the only advertisement that a victim may have seen).&lt;/p&gt;  &lt;p&gt;The author also writes:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“A comment gave the campaign ID as Vonage01_1163613_nyt12, though it was obviously unrelated to Vonage.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I wonder if the domain &lt;strong&gt;vonage-inc.com&lt;/strong&gt; was used by whoever it was that sold the malvertizing to the New York Times.&amp;#160; vonage-inc.com used to have the IP address 212.117.166.71, and known to be used by cybercriminals to impersonate the real Vonage.&amp;#160; Thankfully, vonage-inc.com seem to have been handed over to the *real* Vonage on or about 5 September.&lt;/p&gt;  &lt;p&gt;I wrote about vonage-inc.com back on &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx" target="_blank"&gt;4 September 2009&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Edit: I see that the &lt;a href="http://www.nytimes.com/2009/09/15/technology/internet/15adco.html?_r=1" target="_blank"&gt;New York Times has admitted that Vonage was impersonated&lt;/a&gt;:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;“The creator of the malicious ads posed as Vonage, the Internet telephone company, and persuaded NYTimes.com to run ads that initially appeared as real ads for Vonage. At some point, possibly late Friday, the campaign switched to displaying the virus warnings. &lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Because The Times thought the campaign came straight from Vonage, which has advertised on the site before, it allowed the advertiser to use an outside vendor that it had not vetted to actually deliver the ads, Ms. McNulty said. That allowed the switch to take place. “In the future, we will not allow any advertiser to use unfamiliar third-party vendors,” she said.”&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Just to repeat what I said above, information was available on the net, warning that Vonage was being impersonated, as far back as &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx" target="_blank"&gt;4 September&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;So, what do we know about the domains implicated in this latest incident? &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;tradenton.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 2 September 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.69 - Luxembourg, Root Esolutions (a known bad IP address – also, note how close the IP address is to what used to be the IP address for vonage-inc.com)&lt;/p&gt;  &lt;p&gt;Currently shares IP with harlingens.com, kennedales.com, newadsresults.com, relunas.com and waveadvert.com &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Tradenton     &lt;br /&gt;Shawn Brownell (shawn@tradenton.com)     &lt;br /&gt;978-214-3972 fax: 978-214-3972     &lt;br /&gt;3051 Pearlman Avenue     &lt;br /&gt;Wilmington MA 01887     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;harlingens.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 2 September 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;harlingens.com     &lt;br /&gt;Richard Andrew (admin@harlingens.com)     &lt;br /&gt;956-893-2463 fax: 956-893-2463     &lt;br /&gt;4859 Carolina Avenue     &lt;br /&gt;Harlingen TEX 78550 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;sex-and-the-city.cn&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: Chinese     &lt;br /&gt;Created 3 September 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 94.102.48.209 - Noord-holland, Amsterdam, As29073 Ecatel Ltd &lt;/p&gt;  &lt;p&gt;Registrant: oregon.artscomm@state.or.us &lt;/p&gt;  &lt;p&gt;*****&lt;/p&gt;  &lt;p&gt;Finally, yort.com mentions adxbigad - I have found several references to adxbigad in scripts designed to remove advertising from the New York Times web site (cite: &lt;a href="http://userscripts.org/scripts/review/56684)" target="_blank"&gt;http://userscripts.org/scripts/review/56684)&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1723398" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=D81ji7adztg:3NcgvJt3kAo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=D81ji7adztg:3NcgvJt3kAo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=D81ji7adztg:3NcgvJt3kAo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/D81ji7adztg" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/09/15/1723398.aspx</feedburner:origLink></item><item><title>ALERT: Please treat content from trendbanner.com with extreme caution</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/H75p7S7dUcY/1722754.aspx</link><pubDate>Sat, 12 Sep 2009 09:16:19 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1722754</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1722754</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5488.image_5F00_67DFCC06.png" width="550" height="261" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;It has been implicated in the facilitation of malvertizing that attempts to infect computers via PDF exploit&lt;/p&gt;  &lt;p&gt;The way it works is as follows:&lt;/p&gt;  &lt;p&gt;ad.trendbanner.com uses document.write to load the JS content at banner.pushbanner769.info&lt;/p&gt;  &lt;p&gt;banner.pushbanner769.info displays an advertisement, but also loads content from content from t.banner08092.com.&lt;/p&gt;  &lt;p&gt;t.banner08092.com simply redirects to blackwater-cuprumworks.net&lt;/p&gt;  &lt;p&gt;blackwater-cuprumworks.net includes a javascript (valla.js) which loads content from bintus-bahi.cn in a 0x0 iframe&lt;/p&gt;  &lt;p&gt;bintus-bahi.cn uses CVE-2009-0927 (Stack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab object) to infect vulnerable computers, as well as downloading other malware.&lt;/p&gt;  &lt;p&gt;The SWF (oneComesEthics.swf) is suspected to be malicious.&lt;/p&gt;  &lt;p&gt;Virustotal analysis of some content received via bintus-bahi.cn:&lt;/p&gt;  &lt;p&gt;&lt;a title="http://www.virustotal.com/analisis/fbf39bcd9dea6e1233895e391c2d4bab22096cf7b76b8a6b760203f3d0efa76d-1252662476" href="http://www.virustotal.com/analisis/fbf39bcd9dea6e1233895e391c2d4bab22096cf7b76b8a6b760203f3d0efa76d-1252662476" target="_blank"&gt;http://www.virustotal.com/analisis/fbf39bcd9dea6e1233895e391c2d4bab22096cf7b76b8a6b760203f3d0efa76d-1252662476&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domain information&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;ad.trendbanner.com&lt;/strong&gt;    &lt;br /&gt;ICANN REGISTRAR: GODADDY.COM, INC    &lt;br /&gt;Created 30 July 2009    &lt;br /&gt;NS47.DOMAINCONTROL.COM    &lt;br /&gt;NS48.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 161.58.56.25 and 207.57.97.233 &lt;/p&gt;  &lt;p&gt;Shares IP with &lt;strong&gt;doityourselfbuilder.com&lt;/strong&gt; and &lt;strong&gt;banner.islandbanner.com&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;&lt;strong&gt;Modena Inc&lt;/strong&gt; (domains@modenainc.com) (associated with 102 domains)    &lt;br /&gt;921 SW Washington ST    &lt;br /&gt;Suite 228    &lt;br /&gt;Portland, Oregon 97205    &lt;br /&gt;United States &lt;/p&gt;  &lt;p&gt;Modena Inc have a dubious history, with complaints as far back to 2005 about &amp;quot;spyware infested filesharing programs&amp;quot;, site scraping and 302 domain poisoning: &lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.freedomcrowsnest.org/forum/viewtopic.php?t=1416" target="_blank"&gt;http://www.freedomcrowsnest.org/forum/viewtopic.php?t=1416&lt;/a&gt;    &lt;br /&gt;&lt;a href="http://forum.abestweb.com/showthread.php?p=456066&amp;amp;mode=threaded#post456066" target="_blank"&gt;http://forum.abestweb.com/showthread.php?p=456066&amp;amp;mode=threaded#post456066&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Modena Inc domains were also part of the malvertizing incident that his digitalspy.co.uk:   &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;There is also a dishonorable mention at bluetack.co.uk (**10** different security exploits were used in that incident) - domains used were banners.exitexchange.com and count.exit1208.com:   &lt;br /&gt;&lt;a href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=210&amp;amp;p=90509&amp;amp;" target="_blank"&gt;http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=210&amp;amp;p=90509&amp;amp;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;It is interesting that ashoping.com was part of the incident recorded at bluetack.co.uk. The registrant, helen.nikolson@gmail.com, has been seen myriad times, in association with traffichunters.net (which we can tie to Innovative Marketing in the Ukraine):   &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/03/27/1682054.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/03/27/1682054.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;doityourselfbuilder.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: MELBOURNE IT, LTD D/B/A INTERNET NAMES WORLDWIDE    &lt;br /&gt;Created 10 June 2006    &lt;br /&gt;NS1.SECURE.NET    &lt;br /&gt;NS2.SECURE.NET &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Music Unlimited Inc    &lt;br /&gt;PO Box 1200    &lt;br /&gt;Jacksonville 97530 &lt;/p&gt;  &lt;p&gt;Admin Name:   &lt;br /&gt;David Sprunger (pptorders@playpianotoday.com) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;banner.islandbanner.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: GODADDY.COM, INC    &lt;br /&gt;Created 24 July 2009    &lt;br /&gt;NS45.DOMAINCONTROL.COM    &lt;br /&gt;NS46.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 (shares IP with 11,039,738 other sites) &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;&lt;strong&gt;Modena Inc&lt;/strong&gt; (domains@modenainc.com) (associated with 102 domains)    &lt;br /&gt;921 SW Washington Street    &lt;br /&gt;Suite 228    &lt;br /&gt;Portland, Oregon 97205 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;pussbanner769.info&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: GODADDY.COM, INC    &lt;br /&gt;Created 7 August 2009    &lt;br /&gt;NS47.DOMAINCONTROL.COM    &lt;br /&gt;NS48.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 (shares IP with 11,039,738 other sites) &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Domain Owner (trafficbuyer@gmail.com)    &lt;br /&gt;15156 SW 5th    &lt;br /&gt;Scottsdale    &lt;br /&gt;Arizona 85260    &lt;br /&gt;Tel: +1 8005551212 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;blackwater-cuprumworks.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI    &lt;br /&gt;Created 7 September 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 213.155.2.112 - Namibia, Grinvich3, Vladimir Gubarenko &lt;/p&gt;  &lt;p&gt;Shares IP with the domains aw-work.net, awirons-work.com, sexamateur-hartcore.com and sleazy-dreamers.net &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Eduard Skobelev (eddiscobbi3@gmail.com)    &lt;br /&gt;ul. Starinskaya, d.1, kv. 92    &lt;br /&gt;g. Moskva    &lt;br /&gt;g. Moskva, 107009    &lt;br /&gt;RU    &lt;br /&gt;Tel: +7 4952243948 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;masterwood-works.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: NETWORK SOLUTIONS, LLC.    &lt;br /&gt;Created 19 February 1999    &lt;br /&gt;NS.WVT.NET    &lt;br /&gt;NS2.WVT.NET &lt;/p&gt;  &lt;p&gt;IP: 65.36.167.73 - Delaware, Newark, Hostmysite &lt;/p&gt;  &lt;p&gt;Shares IP with 395 other sites &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Master Wood-Works    &lt;br /&gt;4526 Olentangy River Road    &lt;br /&gt;Delaware, OH 43015    &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;Admin:   &lt;br /&gt;Steve Krengel (hostmaster@wvt.net) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;bintus-bahi.cn&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: Chinese    &lt;br /&gt;Created 15 August 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET    &lt;br /&gt;NS3.EVERYDNS.NET    &lt;br /&gt;NS4.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 61.235.117.72 - Guangdong, Shenzen, China Railcom Guangdong Shenzhen Subbranch &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Cehhost, inc (owns about 84 other domains)    &lt;br /&gt;Lucas Steven (steven_lucas_2000@yahoo.com)&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/1565.image_5F00_0E68EB58.png" width="1012" height="462" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1722754" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=H75p7S7dUcY:7LaXbVDozSE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=H75p7S7dUcY:7LaXbVDozSE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=H75p7S7dUcY:7LaXbVDozSE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/H75p7S7dUcY" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx</feedburner:origLink></item><item><title>Alert: please treat content from kennedales.com with extreme caution</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/ZEzoZMaYfuA/1722477.aspx</link><pubDate>Fri, 11 Sep 2009 01:43:01 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1722477</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1722477</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/11/1722477.aspx#comments</comments><description>&lt;p&gt;   &lt;br /&gt;I have received information that kennedales.com has been implicated in a malvertizing incident.&amp;#160; &lt;/p&gt;  &lt;p&gt;I noted in &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/10/1722200.aspx" target="_blank"&gt;my last blog post&lt;/a&gt; that kennedales.com shares IP address with two other domains that have already been caught facilitating malvertizing but at that time had not received intelligence indicating that kennedales.com was also involved.&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;Now we know that it is.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1722477" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=ZEzoZMaYfuA:-5xCvaELaJg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=ZEzoZMaYfuA:-5xCvaELaJg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=ZEzoZMaYfuA:-5xCvaELaJg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/ZEzoZMaYfuA" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/09/11/1722477.aspx</feedburner:origLink></item><item><title>Another two bad domains: newadsresults.com and waveadvert.com</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/b3NKnn6_GcE/1722200.aspx</link><pubDate>Thu, 10 Sep 2009 01:30:20 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1722200</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1722200</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/10/1722200.aspx#comments</comments><description>&lt;p&gt;Seen distributing malvertizing at starnewsonline.com:    &lt;br /&gt;&lt;a title="http://forums.starnewsonline.com/eve/forums/a/tpc/f/6431032365/m/7121097019/r/9841029019" href="http://forums.starnewsonline.com/eve/forums/a/tpc/f/6431032365/m/7121097019/r/9841029019" target="_blank"&gt;http://forums.starnewsonline.com/eve/forums/a/tpc/f/6431032365/m/7121097019/r/9841029019&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;And collegehumor.com:    &lt;br /&gt;&lt;a title="http://www.facebook.co.za/CollegeHumor" href="http://www.facebook.co.za/CollegeHumor" target="_blank"&gt;http://www.facebook.co.za/CollegeHumor&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;And tigerdroppings.com:    &lt;br /&gt;&lt;a href="http://www.tigerdroppings.com/rant/messagetopic.asp?p=14780012&amp;amp;pg=1" target="_blank"&gt;http://www.tigerdroppings.com/rant/messagetopic.asp?p=14780012&amp;amp;pg=1&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;And basilmarket.com (page doesn&amp;#39;t load, but you can find it in Google cache):    &lt;br /&gt;&lt;a href="http://www.basilmarket.com/forum/1184277/2" target="_blank"&gt;http://www.basilmarket.com/forum/1184277/2&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;newadsresults.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC.     &lt;br /&gt;Created 21 July 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.69 (Luxembourg, Root Esolutions) &lt;/p&gt;  &lt;p&gt;Shares IP with two other domains, kennedales.com and waveadvert.com &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;RJ     &lt;br /&gt;Rita Johnson (ritaj@gmail.com)     &lt;br /&gt;4122082301 fax: 4122082301     &lt;br /&gt;101 Bellevue Road     &lt;br /&gt;Pittsburgh PA 15229     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;kennedales.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 14 August 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.69 (Luxembourg, Root Esolutions) &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;kennedales.com     &lt;br /&gt;Jonathan Nelson (admin@kennedales.com)     &lt;br /&gt;812-750-2673 fax: 812-750-2673     &lt;br /&gt;1370 Heliport Loop     &lt;br /&gt;Bloomington IN 47404     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;waveadvert.com      &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: BIZCN.COM, INC.     &lt;br /&gt;Created 4 August 2009     &lt;br /&gt;NS1.EVERYDNS.NET     &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.69 (Luxembourg, Root Esolutions) &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Premier ANC     &lt;br /&gt;Linda Hogan (lindahg@yahoo.com)     &lt;br /&gt;6788081308 fax: 6788081308     &lt;br /&gt;4495 Atlanta Hwy     &lt;br /&gt;Atlanta GA 30052     &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;Note waveadvert.com’s involvement in malvertizing incidents at blogspot.com:    &lt;br /&gt;&lt;a title="http://google.com/safebrowsing/diagnostic?site=waveadvert.com/&amp;amp;hl=en-gb" href="http://google.com/safebrowsing/diagnostic?site=waveadvert.com/&amp;amp;hl=en-gb" target="_blank"&gt;http://google.com/safebrowsing/diagnostic?site=waveadvert.com/&amp;amp;hl=en-gb&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;And a problem at mangafox:    &lt;br /&gt;&lt;a title="http://forums.mangafox.com/showthread.php?p=2507674" href="http://forums.mangafox.com/showthread.php?p=2507674" target="_blank"&gt;http://forums.mangafox.com/showthread.php?p=2507674&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1722200" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=b3NKnn6_GcE:f0GjcwJA070:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=b3NKnn6_GcE:f0GjcwJA070:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=b3NKnn6_GcE:f0GjcwJA070:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/b3NKnn6_GcE" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/09/10/1722200.aspx</feedburner:origLink></item><item><title>ALERT: The gogomediacenter.com incidents continue</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/qp1B9tE9a78/1721130.aspx</link><pubDate>Sun, 06 Sep 2009 09:53:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1721130</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1721130</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/06/1721130.aspx#comments</comments><description>&lt;p&gt;&lt;img height="128" width="585" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7433.image_5F00_22B071D5.png" alt="image" border="0" title="image" style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" /&gt;&lt;img height="508" width="500" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3704.image_5F00_31E96B53.png" align="left" alt="image" border="0" title="image" style="border-bottom:0px;border-left:0px;margin:10px 15px 15px 0px;display:inline;border-top:0px;border-right:0px;" /&gt;&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I have a few more domains for you&amp;hellip;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;mediadison.com &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: BIZCN.COM, INC &lt;br /&gt;Created 6 July 2009 &lt;/p&gt;
&lt;p&gt;IP: 212.117.166.77, Luxembourg, Root Esolutions &lt;/p&gt;
&lt;p&gt;Sharing IP with the following domains, all of which should be treated with extreme caution: &lt;/p&gt;
&lt;p&gt;2ez4clicks.com, denrifiox.com, monsteradhost.com, newage-advertising.com, profitgainerz.com, ranparetc.com, s7atwola.com, scheuvronts.com, smartadvertisment.net, westernadrix.com &lt;/p&gt;
&lt;p&gt;Registrant: &lt;br /&gt;Solaris Co &lt;br /&gt;Jack Thompson (jthompson@yahoo.com) &lt;br /&gt;4049422100 fax: 4049422100 &lt;br /&gt;1921 Monroe Drive &lt;br /&gt;Atlanta GA 30324 &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;stopdrugstoday.cn&lt;/strong&gt; &lt;br /&gt;ICANN Registrar (Chinese) &lt;br /&gt;Created 1 September 2009 &lt;/p&gt;
&lt;p&gt;IP: 83.133.126.155 - Germany, Lncde-greatnet-newmedia &lt;/p&gt;
&lt;p&gt;Registrant administrative email: webmaster@tangodance.cn &lt;/p&gt;
&lt;p&gt;By the way, we should revisit gogomediacenter.com - there have been some changes since I last posted with some new domains appearing at its IP address: &lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;gogomediacenter.com&lt;/strong&gt; &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC &lt;br /&gt;Created 26 August 2008 &lt;/p&gt;
&lt;p&gt;IP: 212.117.166.75 - Luxembourg, Root Esolutions &lt;/p&gt;
&lt;p&gt;Shares IP with the domains bestmediamind.com, fastdns-ms7.com, jetfastads.com, pro-drugstore.com, query2feed.com, tdshosterserv8.com and yakaboopromo.com (all domains should be treated with extreme caution). &lt;/p&gt;
&lt;p&gt;Registrant: &lt;br /&gt;Mediaswan &lt;br /&gt;Frank Roberts (frank@mailqueen.com) &lt;br /&gt;2128054649 fax: 2128054649 &lt;br /&gt;2130 Small Street &lt;br /&gt;New York, NY 10007 &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1721130" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=qp1B9tE9a78:Ffx3WEX4oQY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=qp1B9tE9a78:Ffx3WEX4oQY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=qp1B9tE9a78:Ffx3WEX4oQY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/qp1B9tE9a78" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/09/06/1721130.aspx</feedburner:origLink></item><item><title>What can I say … but…</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/e-y-Zxowvn4/1721123.aspx</link><pubDate>Sun, 06 Sep 2009 08:14:38 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1721123</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1721123</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/06/1721123.aspx#comments</comments><description>&lt;p&gt;Ouch.&amp;#160; I haven’t seen a mess this bad since IE7 first came out in beta… (yes, IE8’s Compatibility View fixes the display issues).&lt;/p&gt;  &lt;p&gt;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8875.image_5F00_50BA020A.png" width="407" height="475" /&gt;&lt;img style="border-right-width:0px;display:inline;border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/1464.image_5F00_5BF3FDDD.png" width="342" height="472" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1721123" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=e-y-Zxowvn4:pgn8T4JwX4E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=e-y-Zxowvn4:pgn8T4JwX4E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=e-y-Zxowvn4:pgn8T4JwX4E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/e-y-Zxowvn4" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Internet+Explorer+8/default.aspx">Internet Explorer 8</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/09/06/1721123.aspx</feedburner:origLink></item><item><title>ALERT: Please treat the domains gogomediacenter.com, sys17media.com and praharesorts.cn with extreme caution</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/isjbwWiWUE4/1720667.aspx</link><pubDate>Fri, 04 Sep 2009 09:15:39 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1720667</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1720667</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720667.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="Sketchers malvertizement" border="0" alt="Sketchers malvertizement" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8037.image_5F00_6931FA63.png" width="749" height="112" /&gt;     &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;It is very interesting to watch the modus operandi that the bad guys are using change.&lt;/p&gt;  &lt;p&gt;This malvertizement was NOT seen on a web page; rather it was being displayed by an advertising supported freeware application.&lt;/p&gt;  &lt;p&gt;The trouble starts when an ad.yieldmanager.com GET retrieves content, in an iframe, from the domain &amp;quot;gogomediacenter.com&amp;quot;.&amp;#160; The content served up by gogomediacenter.com is an innocent &amp;quot;skechers” JPG (which is the advertisement itself), but it also serves up a little something extra...&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/2677.image_5F00_160B7160.png" width="861" height="445" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Note the two areas of code highlighted by the arrows.&amp;#160; I find it interesting that the miscreants are going to the trouble of using some (basic) encoding.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;If we decode the script at the end, we get this:&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6787.image_5F00_667504E6.png" width="242" height="62" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Again, there is a little bit of (basic) encoding to get rid of, which leaves us with this:&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0523.image_5F00_7134ECEC.png" width="896" height="18" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Another interesting thing to note about this particular incident is that the malicious code only seems to appear &lt;strong&gt;&lt;em&gt;once per IP address&lt;/em&gt;&lt;/strong&gt;.&amp;#160; If I nuke the sandbox I am using, the redirect does not recur, but if I change my IP address, then I can reproduce the redirect as often as I wish.&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Ok, so let’s take a look at these new domains, gogomediacenter.com, sys17med.com and praharesorts.cn.&amp;#160; I think we can say that Root Esolutions, Luxembourg is turning into a bit of a cesspool, and yes, it is the same IP range as the domains revealed in &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx" target="_blank"&gt;my earlier blog post&lt;/a&gt; :(&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;gogomediacenter.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 26 August 2008 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.75 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Shares IP with the domains bestmediamind.com, pro-drugstore.com and yakaboopromo.com (all domains should be treated with extreme caution). &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Mediaswan    &lt;br /&gt;Frank Roberts (frank@mailqueen.com)    &lt;br /&gt;2128054649 fax: 2128054649    &lt;br /&gt;2130 Small Street    &lt;br /&gt;New York, NY 10007 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;sys17media.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 2 September 2009 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.70 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Shares IP with the domains doubleclick-ssl.com and verilline.com (both domains should be treated with extreme caution). &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;DNS Admin (d71245@registar.com)    &lt;br /&gt;580-433-9026 fax: 580-433-9026    &lt;br /&gt;2654 Cody Ridge Rd    &lt;br /&gt;Clinton OK 73601 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;praharesorts.cn&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar (Chinese)    &lt;br /&gt;Created 28 August 2009 &lt;/p&gt;  &lt;p&gt;IP: 83.133.126.155 - Lncde-greatnet-newmedia, Germany &lt;/p&gt;  &lt;p&gt;Administrative email: webmaster@seniorstuds.com.ar (no such domain) &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;bestmediamind.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 26 June 2009 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.75 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Bob Robertson (bobrobertsonscmpbst@gmail.com)    &lt;br /&gt;6172679396    &lt;br /&gt;159 Newbury Street    &lt;br /&gt;Boston, MA 02116 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;yakaboopromo.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 26 June 2009 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.75 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;John Robertson (johnrobertsoncmpbst@gmail.com)    &lt;br /&gt;6172679396    &lt;br /&gt;159 Newbury Street    &lt;br /&gt;Boston MA 02116 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;pro-drugstore.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: ENOM, INC    &lt;br /&gt;Created 29 January 2009 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.75 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Registration service contact director@climbing-games.com (regular readers of this blog will recognise that email address) &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Jack Hum (no email)    &lt;br /&gt;208 W. 1st St. CA 90012    &lt;br /&gt;Los Angeles 90012    &lt;br /&gt;Tel: +1 2338824832 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;doubleclick-ssl.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 20 August 2009 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.70 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;doubleclick-ssl.com    &lt;br /&gt;Carolyn Hooley (carolyn@doubleclick-ssl.com)    &lt;br /&gt;845-223-3913 fax: 845-223-3913    &lt;br /&gt;4619 Camdem Place    &lt;br /&gt;Lagrangeville NY 12540 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;verilline.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 29 July 2009 &lt;/p&gt;  &lt;p&gt;IP: 212.117.166.70 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Lithpro Co    &lt;br /&gt;Linda Thompson (info@lithpro.com)    &lt;br /&gt;3037989467 fax: 3037989467    &lt;br /&gt;2600 W 104th Ave    &lt;br /&gt;Boston CO 80234 &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1720667" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=isjbwWiWUE4:-BBa6k7C9fs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=isjbwWiWUE4:-BBa6k7C9fs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=isjbwWiWUE4:-BBa6k7C9fs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/isjbwWiWUE4" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720667.aspx</feedburner:origLink></item><item><title>ALERT: Impersonation of legitimate advertising networks and companies</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/dpu4dQrGCcg/1720609.aspx</link><pubDate>Fri, 04 Sep 2009 03:18:25 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1720609</guid><dc:creator>sandi</dc:creator><slash:comments>3</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1720609</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx#comments</comments><description>&lt;p&gt;This investigation began after I was alerted to the fact that somebody has been posing as a Vonage representative, and using the domain &lt;strong&gt;vonage-inc.com&lt;/strong&gt; while doing so.&lt;/p&gt;  &lt;p&gt;The domain vonage-inc.com was created on 5 August 2009, and the ICANN Registrar is BIZCN.COM, Inc.&amp;#160; It is hosted by Root Esolutions, Luxembourg (IP address 212.117.166.71). &lt;/p&gt;  &lt;p&gt;Registrant details: &lt;/p&gt;  &lt;p&gt;Vonage-Inc    &lt;br /&gt;Domain Administrator (itadmin@vonage-inc.com)     &lt;br /&gt;7322643911 fax 7322643911     &lt;br /&gt;4 South Holmdel Road     &lt;br /&gt;Holmdel NJ 07733&lt;/p&gt;  &lt;p&gt;Interestingly, it looks like Vonage may have already taken control of vonage-inc.com.&amp;#160; This is because domaintools.com reports that vonage-inc.com has an IP address of 212.117.166.71, and that it is using the name servers NS1.EVERYDNS.NET and NS2.EVERYDNS.NET but Robtex, on the other hand, reports that vonage-inc.com no longer has an IP address, and that it is using the name servers dns-auth-00.kewr0.s.vonagenetworks.net. dns-auth-00.kiad0.s.vonagenetworks.net. dns-auth-00.klax1.s.vonagenetworks.net and dns-auth-00.klga1.s.vonagenetworks.net.&lt;/p&gt;  &lt;p&gt;My grateful thanks go to the gentleman who alerted me to the goings-on involving vonage-inc.com.&amp;#160; His alert has led to the exposure of several other domains are could also be used to impersonate legitimate companies.&lt;/p&gt;  &lt;p&gt;Several other domains can be found at same IP address that vonage-inc.com was using (212.117.166.71).&amp;#160; All of the domains should be treated with extreme caution.&amp;#160; When we bear in mind the warning that somebody has been posing as a Vonage representative while using the domain vonage-inc.com, I think it is safe to assume that somebody is planning to pose as (or is already posing as) a representative of Adconion, Carat, Fox Media, Lacoste, Orange or Pubmatic.&lt;/p&gt;  &lt;p&gt;Here are details of other domains at IP 212.117.166.71 as at time of writing.&amp;#160; All but one are redirecting visitors to other, legitimate, domains.&amp;#160; &lt;/p&gt;  &lt;p&gt;You will note that all of the domains, bar one, have the same ICANN Registrar, being BIZCN.COM, INC.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;adconion-inc.com      &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: BIZCN.COM, Inc     &lt;br /&gt;Created 10 Aug 2009     &lt;br /&gt;Registrant:     &lt;br /&gt;adconion-inc.com     &lt;br /&gt;IT Admin (admin@adconion-inc.com)     &lt;br /&gt;498951490701 fax: 498951490701     &lt;br /&gt;Bayerstrasse 41     &lt;br /&gt;Muenchen Bavaria 80335 &lt;/p&gt;  &lt;p&gt;adconion-inc.com is currently redirecting visitors to the legitimate domain adconion.com (IP 89.110.133.18, ICANN Registrar Ascio Technologies, Inc, Registrant address Lindwurmstr.114, Muenchen, Bavaria 80337) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;adjimbo.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, Inc.     &lt;br /&gt;Created 9 June 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Registar services Co     &lt;br /&gt;Jack Omands (jacksosomands@gmail.com)     &lt;br /&gt;352691787     &lt;br /&gt;10 rue Large     &lt;br /&gt;Luxembourg Luxembourg 1918 &lt;/p&gt;  &lt;p&gt;Address as per web site: 260 Peachtree street, Suite 2200, Atlanta, Georgia 30303, US &lt;/p&gt;  &lt;p&gt;Note: 260 Peachtree Street, Suite 2200, is a Regus property.&amp;#160; Regus operates business centres, virtual offices, virtual PA&amp;#39;s etc. &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;carat-inc.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 10 August 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Carat-inc.com     &lt;br /&gt;IT Administrator (admin@carat-inc.com)     &lt;br /&gt;441179045055 fax: 441179045055     &lt;br /&gt;90 Great Portland Street     &lt;br /&gt;London London W1W 5QZ &lt;/p&gt;  &lt;p&gt;carat-inc.com is currently redirecting visitors to the legitimate domain carat.com (IP 91.206.177.56, Aegis Group Plc, UK - ICANN Registrar GROUP NBT PLC AKA NETNAMES, Registrant: Aegis Group plc, 180 Great Portland Street, London W1W 5QZ) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;foxinteractivemedia-inc.com      &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 10 August 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;domain admin (admin@foxinteractivemedia-inc.com)     &lt;br /&gt;3102750087 fax: 3102750087     &lt;br /&gt;424 N. Beverly Dr     &lt;br /&gt;Beverly Hills CA 90210 &lt;/p&gt;  &lt;p&gt;foxinteractivemedia-inc.com is currently redirecting visitors to the legitimate domain fox.com (IP 80.67.66.57, Akamai Technologies, ICANN Registrar MARKMONITOR, INC, Registrant address: Intellectual Property Department, Twentieth Century Fox Film Corporation, PO Box 900, Beverley Hills CA 90213-0900) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;lacoste-ads.com&lt;/strong&gt; (note, we have encountered lacoste-ads.com before, as discussed here:     &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/04/23/1690197.aspx)" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/04/23/1690197.aspx)&lt;/a&gt;     &lt;br /&gt;ICANN Registrar: NETFIRMS, INC     &lt;br /&gt;Created 2 March 2009     &lt;br /&gt;Registrant details hidden behind a WHOIS privacy protection service (Domain Privacy Group) &lt;/p&gt;  &lt;p&gt;lacoste-ads.com is currently redirecting visitors to the legitimate domain lacoste.com (IP 199.93.55.126, ICANN Registrar Core Internet Council of Registrars, Registrant VIAL TRIBOULET catherine, Lacoste S.A., 8 rue de Castiglione, Paris) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;orangeadvertising-inc.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 10 August 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Orangeadvertising     &lt;br /&gt;Network Administrator: admin@orangeadvertising.us     &lt;br /&gt;441179045053 fax: 441179045053     &lt;br /&gt;6400 North Radcliffe St     &lt;br /&gt;Bristol Bristol BS9 4AU     &lt;br /&gt;GB &lt;/p&gt;  &lt;p&gt;orangeadvertising-inc.com is currently redirecting visitors to the legitimate domain orange.com (IP 194.2.208.16, Telecom France, Registrant: Orange Personal Communications Services Limited, St James Court, Great Park Road, Almondbury Park, Bradley Stoke, Bristol, UK, Tel: ) &lt;/p&gt;  &lt;p&gt;Note: the domain orangeadvertising.us (used for the Network Administrator&amp;#39;s contact email address) has never been registered. &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;pubmatic-inc.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 10 August 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;IT Admin (itadmin@pubmatic-inc.com)     &lt;br /&gt;6508562386 fax: 6508562386     &lt;br /&gt;675 El Camino Real     &lt;br /&gt;Palo Alto CA 94301 &lt;/p&gt;  &lt;p&gt;pubmatic-inc.com is currently redirecting visitors to the legitimate pubmatic.com (IP 69.163.146.58, New Dream Network Llc, California, Registrant: Pubmatic, Inc, PO Box 975, Palo Alto, CA 94302)&lt;/p&gt;  &lt;p&gt;*******************************&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Other domains in the same IP range:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;IP: 212.117.166.74&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;brightadsnetwork.com&lt;/strong&gt; (visually almost identical to adjimbo.com – see above)     &lt;br /&gt;Address as per web site: 2115 North Charles Street, North Baltimore     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 14 June 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;RegServ Co     &lt;br /&gt;Norman Jason (normanjason01223@gmail.com)     &lt;br /&gt;2127340192     &lt;br /&gt;20 Washington Street     &lt;br /&gt;New York New York 10006 &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;topleanpro.com&lt;/strong&gt;     &lt;br /&gt;ICANN Registrar: BIZCN.COM, INC     &lt;br /&gt;Created 18 June 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Domains Inform Inc     &lt;br /&gt;Thomas Kleineberg (thomaskleinebergdomains@gmail.com)     &lt;br /&gt;498999216255     &lt;br /&gt;Maximillianstrasse 18     &lt;br /&gt;Munich Munich 80539 &lt;/p&gt;  &lt;p&gt;*****&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;IP: 212.117.166.73&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;ad-advanced.com&lt;/strong&gt; (address as per web site is Suite 300, 8875 Hidden River Parkway, Tampa which is a Regus asset) &lt;/p&gt;  &lt;p&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 1 July 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Norman Sebring (nsebring@rit-consulting.com)     &lt;br /&gt;5116 New Centre Drive     &lt;br /&gt;WILMINGTON NC 28403 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;dnzmg.com&lt;/strong&gt; (web site address Suite 410, 6802 Paragon Place, Richmond, Virginia - another Regus asset) &lt;/p&gt;  &lt;p&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 1 July 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Magnetic Wave     &lt;br /&gt;Daryl Lewis (markstein@mwa.com)     &lt;br /&gt;3035568550 fax: 3035568550     &lt;br /&gt;235 Columbine Street     &lt;br /&gt;Denver CO 80206 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;vertixgroup.com&lt;/strong&gt; (web site address 3525 Piedmont Road, 7 Piedmont Center, Atlanta - this address is for the HP Business Centre, a member of the Regus Group Network) &lt;/p&gt;  &lt;p&gt;ICANN Registrar: BIZCN.COM, INC    &lt;br /&gt;Created 1 July 2009 &lt;/p&gt;  &lt;p&gt;Registrant:    &lt;br /&gt;Mark Stein (pholexkapsilow@gmail.com) (Mark Stein again? See Daryl Lewis email above)     &lt;br /&gt;2158554688 fax: 2158554688     &lt;br /&gt;1202 Market Street     &lt;br /&gt;Philadelphia PA 19107 &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1720609" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=dpu4dQrGCcg:0FoDmAe0bhw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=dpu4dQrGCcg:0FoDmAe0bhw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=dpu4dQrGCcg:0FoDmAe0bhw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/dpu4dQrGCcg" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/09/04/1720609.aspx</feedburner:origLink></item><item><title>ALERT: More malvertizing via Facebook applications?</title><link>http://feedproxy.google.com/~r/SpywareSucks/~3/lv6jY1_3sLU/1718057.aspx</link><pubDate>Tue, 25 Aug 2009 07:37:20 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1718057</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment>http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1718057</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/08/25/1718057.aspx#comments</comments><description>&lt;p&gt;Last time it was “Human Gifts” (aka Owned) that I wrote about on August 3:   &lt;br /&gt;&lt;a title="ALERT- Malvertizing on Facebook and gaiaonline.com" href="http://msmvps.com/blogs/spywaresucks/archive/2009/08/03/1712174.aspx" target="_blank"&gt;ALERT- Malvertizing on Facebook and gaiaonline.com&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;This time it is the “We’re Related” application – an incident reported on August 18   &lt;br /&gt;&lt;a href="http://community.tigranetworks.co.uk/blogs/tim_long/archive/2009/08/18/drive-by-downloads-from-facebook.aspx" target="_blank"&gt;http://community.tigranetworks.co.uk/blogs/tim_long/archive/2009/08/18/drive-by-downloads-from-facebook.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;And, according to a family member, her web browser’s security filter blocked her web browser from accessing something when playing Bubbletown (I quote: “a big red page came up”).&amp;#160; Something was going on there too.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1718057" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=lv6jY1_3sLU:CVPMOXNt3ZI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/SpywareSucks?a=lv6jY1_3sLU:CVPMOXNt3ZI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/SpywareSucks?i=lv6jY1_3sLU:CVPMOXNt3ZI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/lv6jY1_3sLU" height="1" width="1"/&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><feedburner:origLink>http://msmvps.com/blogs/spywaresucks/archive/2009/08/25/1718057.aspx</feedburner:origLink></item></channel></rss>
