<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" version="2.0">

<channel>
	<title>URLVoid Blog</title>
	
	<link>http://blog.urlvoid.com</link>
	<description>Just another WordPress site</description>
	<lastBuildDate>Fri, 25 May 2012 16:00:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/URLVoid" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="urlvoid" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">URLVoid</feedburner:emailServiceId><feedburner:feedburnerHostname xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Phishing: Abbiamo limitato l’accesso visa/mastercard account. (Case # PP-001-546-712-069 – ORM001)</title>
		<link>http://blog.urlvoid.com/phishing-abbiamo-limitato-laccesso-visamastercard-account-case-pp-001-546-712-069-orm001/</link>
		<comments>http://blog.urlvoid.com/phishing-abbiamo-limitato-laccesso-visamastercard-account-case-pp-001-546-712-069-orm001/#comments</comments>
		<pubDate>Fri, 25 May 2012 15:59:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spam email]]></category>
		<category><![CDATA[visa phishing]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1083</guid>
		<description><![CDATA[Another phishing email against Italian users of Mastercard / Visa: Header details: Received: from mail.oceano.hn (mail.oceano.hn [63.161.65.43]) Received: from User ([62.215.140.237]) by oceano.hn with MailEnable ESMTP; Fri, 25 May 2012 08:04:39 -0600 Subject: Abbiamo limitato l'accesso visa/mastercard account. Si prega di attenersi alla seguente procedura per risolvere. (Case # PP-001-546-712-069 - ORM001) Date: Fri, 25 [...]]]></description>
			<content:encoded><![CDATA[<p>Another phishing email against Italian users of Mastercard / Visa:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/25_05_2012-17_47_55.jpeg" alt="Phishing Email" title="Phishing Email" /></p>
<p>Header details:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Received: from mail.oceano.hn (mail.oceano.hn [63.161.65.43])
Received: from User ([62.215.140.237]) by oceano.hn with MailEnable ESMTP; Fri, 25 May 2012 08:04:39 -0600
Subject: Abbiamo limitato l'accesso visa/mastercard account. Si prega di attenersi alla seguente procedura per risolvere. (Case # PP-001-546-712-069 - ORM001)
Date: Fri, 25 May 2012 17:04:41 +0300
To: undisclosed-recipients:;
Content-Type: application/octet-stream; name=&quot;visaita.html&quot;
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename=&quot;visaita.html&quot;</pre></div></div>

<p>There is a .HTML file attached:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">File: visaita.html
Size: 25970 bytes
MD5: C6D16F0B6693AB2831E2BA70534C85BE
SHA1: AB4175E9B97A6E822E3D616BD4DDD5285AC70B39
SHA256: 7B8417D0A420DB5710B44252CF5B4813295EE1B8A51552BD6D5B847AC4AD9E85
SHA384: 4DB62497B232418E708AD8C5278BCDD48DD2E593CAAC01FC0963749EFA3B300BF116A539C222FB389020F61C2A516959
SHA512: 691B828A1FC25EE938114ECA74FFF5690AFE3F8F79AF4D13BB438C064663276CE97D5BED0BDDA3143A9D682FDF67E55C9F46CB1DAE69D5747297C9BF32B491F7</pre></div></div>

]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/phishing-abbiamo-limitato-laccesso-visamastercard-account-case-pp-001-546-712-069-orm001/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing: Periodic Maintenance (PayPal)</title>
		<link>http://blog.urlvoid.com/phishing-periodic-maintenance-paypal/</link>
		<comments>http://blog.urlvoid.com/phishing-periodic-maintenance-paypal/#comments</comments>
		<pubDate>Fri, 18 May 2012 14:59:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[paypal phishing]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spam email]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1080</guid>
		<description><![CDATA[Another phishing email targets PayPal users: Email header details: Received: from mail.artworkdigital.com.br (ns1.artworkdigital.com.br [201.86.117.58]) Received: from User (216-107-107-254.static.networktel.net [216.107.107.254]) by mail.artworkdigital.com.br (Postfix) Subject: Periodic Maintenance Date: Fri, 18 May 2012 06:56:14 -0500 To: undisclosed-recipients:; Content-Disposition: attachment; filename=&#34;PayPal_ReactivationFORMay2012.html&#34; Attached there is a file named: File: PayPal_ReactivationFORMay2012.html Size: 10157 bytes MD5: 9617FF24A5647B20883C7FDA37408156 SHA1: 02C0D8DDEE4AFCC07897A141FFFF7540083B9F44 SHA256: E257318F2B84A08B15F5A431F5A1E1FE112A7D9EF0FBFB3A69AA63784C00F73A SHA384: [...]]]></description>
			<content:encoded><![CDATA[<p>Another phishing email targets PayPal users:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/18_05_2012-16_51_50.jpeg" alt="Phishing Email" /></p>
<p>Email header details:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Received: from mail.artworkdigital.com.br (ns1.artworkdigital.com.br [201.86.117.58])
Received: from User (216-107-107-254.static.networktel.net [216.107.107.254]) by mail.artworkdigital.com.br (Postfix)
Subject: Periodic Maintenance
Date: Fri, 18 May 2012 06:56:14 -0500
To: undisclosed-recipients:;
Content-Disposition: attachment; filename=&quot;PayPal_ReactivationFORMay2012.html&quot;</pre></div></div>

<p>Attached there is a file named:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">File: PayPal_ReactivationFORMay2012.html
Size: 10157 bytes
MD5: 9617FF24A5647B20883C7FDA37408156
SHA1: 02C0D8DDEE4AFCC07897A141FFFF7540083B9F44
SHA256: E257318F2B84A08B15F5A431F5A1E1FE112A7D9EF0FBFB3A69AA63784C00F73A
SHA384: B4C63890B4B001D4B02559C0A75DD0472101FAAB306595AB8ADBEBE71CF4504B9026431A98868B1200FB2A517805447E
SHA512: EC5D11EF6509333C492B54D60D6B5D4E9E1FE26A313EAB28B9ADAF3F6154EB6DAE982D00E66486B44C22E4A0CAB9158ED13B48DB70CEEC33EE4F626FE56D8246</pre></div></div>

<p>Extracted malicious URLs:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// adsl-068-157-210-061.sip.bna.bellsouth .net /~jim/style.css
hxxp:// adsl-068-157-210-061.sip.bna.bellsouth .net /~jim/w.php</pre></div></div>

<p>As we can see, the malicious files are hosted in a DSL hostname:</p>
<p>The website adsl-068-157-210-061.sip.bna.bellsouth.net is hosted at BellSouth.net and its current IP address is 68.157.210.61 (adsl-068-157-210-061.sip.bna.bellsouth.net). The server machine is located in United States (US) and in the same server there are hosted other 0 websites. The domain is registered with the suffix NET and the keyword of the domain is bellsouth. The organization is BellSouth.net.</p>
<p>URLVoid scan report:</p>
<p><a href="http://urlvoid.com/scan/adsl-068-157-210-061.sip.bna.bellsouth.net/" target="_blank">http://urlvoid.com/scan/adsl-068-157-210-061.sip.bna.bellsouth.net/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/phishing-periodic-maintenance-paypal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spam “Your Bill Me Later notice” leads to Incognito exploit kit</title>
		<link>http://blog.urlvoid.com/spam-your-bill-me-later-notice-leads-to-incognito-exploit-kit/</link>
		<comments>http://blog.urlvoid.com/spam-your-bill-me-later-notice-leads-to-incognito-exploit-kit/#comments</comments>
		<pubDate>Thu, 17 May 2012 11:55:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[exploit kit]]></category>
		<category><![CDATA[incognito exploit kit]]></category>
		<category><![CDATA[java applet exploit]]></category>
		<category><![CDATA[java exploit]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1067</guid>
		<description><![CDATA[Users have reported another malicious email message with subject &#8220;Your Bill Me Later notice&#8221; that states you have made a payment over the phone of $60.12 to Bill Me Later website. The email body is full of HREF links that point to a lot of malicious URLs, view a screenshot of the email message: Email [...]]]></description>
			<content:encoded><![CDATA[<p>Users have reported another malicious email message with subject &#8220;Your Bill Me Later notice&#8221; that states you have made a payment over the phone of $60.12 to Bill Me Later website. The email body is full of HREF links that point to a lot of malicious URLs, view a screenshot of the email message:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/17_05_2012-13_28_14.jpeg" alt="Your Bill Me Later notice" /></p>
<p>Email header details:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Received: from server.serverhk.net (69-164-193-60.magicnic.com [69.164.193.60])
Received: from [200.76.191.2] (helo=askokay.com) by server.serverhk.net with esmtpsa
Received: from [192.245.26.33] by m1.gns.snv.thisdomainl.com with SMTP; Wed, 16 May 2012 21:04:47 +1000
Received: from [68.117.211.36] by mailout.endmonthnow.com with NNFMP; Wed, 16 May 2012 20:54:02 +1000
Date: Wed, 16 May 2012 20:50:24 +1000
From: &quot;Advera&quot; askokay@askokay.com
Subject: Your Bill Me Later notice</pre></div></div>

<p>The malicious extracted URLs are:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// www. studiobarsotti .it /3oXGcu61/index.html
hxxp:// www. eventosabsolue .com /qh8xhoi8/index.html
hxxp:// foxpublicidade .com .br /foRzthoD/index.html
hxxp:// www. studiobarsotti .it /GRYYEt3L/index.html
hxxp:// 76.12.158 .176 /3oXGcu61/index.html
hxxp:// 76.12.158 .176 /yWyXU9NU/index.html
hxxp:// www. eventosabsolue .com /ZmUaukzG/index.html
hxxp:// ewaleczek. cal24 .pl /5CY4dSwa/index.html
hxxp:// www. eventosabsolue .com /h03NraKE/index.html
hxxp:// foxpublicidade. com .br/yWyXU9NU/index.html
hxxp:// www. hso. co. jp/yWyXU9NU/index.html
hxxp:// zajacpiotr. hostit .pl /yWyXU9NU/index.html
hxxp:// zajacpiotr. hostit. pl /smWHegmd/index.html
hxxp:// ftp.joblines .sk /ri8ZKUip/index.html
hxxp:// www. sacmilani. com. ar /uvoNJPhk/index.html
hxxp:// foxpublicidade. com. br /smWHegmd/index.html
hxxp:// www. studiobarsotti .it /hTVbWtV1/index.html
hxxp:// jahu. com. br /FW3s2g0r/index.html
hxxp:// onecursos .com .br /foRzthoD/index.html
hxxp:// www. studiobarsotti .it /GRYYEt3L/index.html
hxxp:// www. studiobarsotti .it /yWyXU9NU/index.html
hxxp:// www. kayafamily .it /ZmUaukzG/index.html</pre></td></tr></table></div>

<p>Using <a href="http://www.htmlsniffer.com/" target="_blank">HTMLSniffer</a> we can dump the HTML content:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/17_05_2012-13_37_55.jpeg" alt="Dumped HTML Content" /></p>
<p>From the dumped data, we can see it is the <a href="http://blog.urlvoid.com/tag/incognito-exploit-kit/">Incognito exploit kit</a>.</p>
<p>Extacted malicious URLs:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// bigdeal . my/ZyYJZ7F0/js.js</pre></div></div>

<p>The malicious URLs redirect users to another malicious URL:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// 69.163.34. 134 /showthread.php?t=977334ca118fcb8c</pre></div></div>

<p>If we use <a href="http://www.htmlsniffer.com/" target="_blank">HTMLSniffer</a> and we set the user-agent to Java, when we dump the content of the new malicious URL we can see it recognises from the user-agent that the user is using Java and the exploit tries to serve the infected Java applet:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/17_05_2012-13_44_04.jpeg" alt="Dumped Data" /></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/spam-your-bill-me-later-notice-leads-to-incognito-exploit-kit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More Malicious Links Spammed to Twitter Users</title>
		<link>http://blog.urlvoid.com/more-malicious-links-spammed-to-twitter-users/</link>
		<comments>http://blog.urlvoid.com/more-malicious-links-spammed-to-twitter-users/#comments</comments>
		<pubDate>Fri, 11 May 2012 23:23:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[make money online fake]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[twitter spam]]></category>
		<category><![CDATA[unsafe sites on twitter]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1054</guid>
		<description><![CDATA[Another malicious link received by an user via Twitter: hxxp:// profitscoaching .info /index.php?eVTv=1336686044437 Whois details: Domain Name: profitscoaching .info Registrar: GoDaddy.com LLC (R171-LRMS) Status: CLIENT DELETE PROHIBITED, CLIENT RENEW PROHIBITED, CLIENT TRANSFER PROHIBITED, CLIENT UPDATE PROHIBITED Expiration Date: 2013-03-07 14:59:08 Creation Date: 2012-03-07 14:59:08 Last Update Date: 2012-05-06 20:39:46 Name Servers: ns61.domaincontrol.com ns62.domaincontrol.com &#160; Registrant [...]]]></description>
			<content:encoded><![CDATA[<p>Another malicious link received by an user via Twitter:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// profitscoaching .info /index.php?eVTv=1336686044437</pre></div></div>

<p>Whois details:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Domain Name: profitscoaching .info
Registrar: GoDaddy.com LLC (R171-LRMS)
Status: CLIENT DELETE PROHIBITED, CLIENT RENEW PROHIBITED, CLIENT TRANSFER PROHIBITED, CLIENT UPDATE PROHIBITED
Expiration Date: 2013-03-07 14:59:08
Creation Date: 2012-03-07 14:59:08
Last Update Date: 2012-05-06 20:39:46
Name Servers:
ns61.domaincontrol.com
ns62.domaincontrol.com
&nbsp;
Registrant Contact Information:
Name: Registration Private
Organization: Domains By Proxy, LLC
Address 1: DomainsByProxy.com
Address 2: 15111 N. Hayden Rd., Ste 160, PMB 353
City: Scottsdale
State: Arizona
Zip: 85260
Country: US
Phone: +1.4806242599
Fax: +1.4806242598</pre></div></div>

<p>Hosting details:</p>
<p>The website profitscoaching .info is hosted at WholeSale Internet and its current IP address is 173.208.196.245 (-). The server machine is located in United States (US) and in the same server there are hosted other 0 websites. The domain is registered with the suffix INFO and the keyword of the domain is profitscoaching. The organization is Gold VIP Club.</p>
<p>The malicious link redirects users to another malicious link:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">HTTP/1.1 302 Moved Temporarily
Server: nginx/0.6.32
Date: Fri, 11 May 2012 22:55:44 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
X-Powered-By: PHP/5.2.6-1+lenny16
Set-Cookie: PHPSESSID=1bff1c2b505aa2004bda6028bb28ad0a; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Location: hxxp:// aooale .info /ytb/redirect.php</pre></div></div>

<p>Extracted malicious link:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// aooale .info /ytb/redirect.php</pre></div></div>

<p>Whois details:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Domain Name: aooale .info
Registrar: GoDaddy.com LLC (R171-LRMS)
Status: CLIENT DELETE PROHIBITED, CLIENT RENEW PROHIBITED, CLIENT TRANSFER PROHIBITED, CLIENT UPDATE PROHIBITED
Expiration Date: 2012-09-21 13:41:55
Creation Date: 2011-09-21 13:41:55
Last Update Date: 2011-11-20 20:41:26
Name Servers:
ns49.domaincontrol.com
ns50.domaincontrol.com
&nbsp;
Registrant Contact Information:
Name: Registration Private
Organization: Domains By Proxy, LLC
Address 1: DomainsByProxy.com
Address 2: 15111 N. Hayden Rd., Ste 160, PMB 353
City: Scottsdale
State: Arizona
Zip: 85260
Country: US
Phone: +1.4806242599
Fax: +1.4806242598</pre></div></div>

<p>Hosting details:</p>
<p>The website aooale.info is hosted at DirectSpace Networks, LLC. and its current IP address is 174.140.169.101 (-). The server machine is located in United States (US) and in the same server there are hosted other 0 websites. The domain is registered with the suffix INFO and the keyword of the domain is aooale. The organization is DirectSpace Networks, LLC.</p>
<p>URLVoid scan reports:</p>
<p><a href="http://urlvoid.com/scan/aooale.info/" target="_blank">http://urlvoid.com/scan/aooale .info</a><br />
<a href="http://urlvoid.com/scan/profitscoaching.info/" target="_blank">http://urlvoid.com/scan/profitscoaching .info</a></p>
<p>Other malicious links:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// ioi8 .info /gps
hxxp:// bp9 .info /mobi/redirect.php
hxxp:// iso8 .info /lg
hxxp:// jay8 .info /b2d
hxxp:// saov .info /mobilemoneymachines/</pre></div></div>

<p>The malicious links where users are generally being redirected seem scam pages:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/scam-make-money-propaganda.png" alt="Fake Make Money Sites" /></p>
<p>The scam pages show fake images of people that take in hand a check and promote the &#8220;Work at home mum makes £4,397/month working part-time from home&#8221; slogan. Clearly it is a complete scam and you will never get a cent in your check, you will never receive any check in real.</p>
<p>The &#8220;end of redirections&#8221; is this website:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// x.dotcomsecrets .com /?hop=richmondrw</pre></div></div>

<p>Whois details:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Domain Name: dotcomsecrets .com
Registrar: ENOM, INC.
Whois Server: whois.enom.com
Referral URL: http://www.enom.com
Status: OK
Expiration Date: 2012-10-25
Creation Date: 2000-10-25
Last Update Date: 2012-04-02
Name Servers:
jim.ns.cloudflare.com
ruth.ns.cloudflare.com
&nbsp;
Administrative Contact:
DotComSecrets .com
Russell Brunson
1.2083239451
Fax: 1. 1.2083239451
10280 W. Ustick Rd.
Boise, ID 83704
US</pre></div></div>

<p>A Twitter user that has around 400 tweets related to these malicious links:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/12_05_2012-01_23_39.jpeg" alt="Twitter User" /></p>
<p>Link to suspicious users:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxps:// twitter .com /#!/thainnmwla0
hxxps:// twitter .com /#!/henthorneondt8</pre></div></div>

<p>Most of the time the links are detected by Twitter as unsafe:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/12_05_2012-01_16_14.jpeg" alt="Unsafe Site detected by Twitter" /></p>
<p>We always recommend to check unknown links with <a href="http://www.urlvoid.com/">URLVoid.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/more-malicious-links-spammed-to-twitter-users/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spam link on Twitter leads to Fake Antivirus Rogue Software</title>
		<link>http://blog.urlvoid.com/spam-link-on-twitter-leads-to-fake-antivirus-rogue-software/</link>
		<comments>http://blog.urlvoid.com/spam-link-on-twitter-leads-to-fake-antivirus-rogue-software/#comments</comments>
		<pubDate>Tue, 08 May 2012 21:45:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[on-linepaysafery.info fraud]]></category>
		<category><![CDATA[rogue security software]]></category>
		<category><![CDATA[spywarecleanermicrosoft info]]></category>
		<category><![CDATA[twitter spam]]></category>
		<category><![CDATA[windows antivirus 2012]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1036</guid>
		<description><![CDATA[One user has reported us a malicious URL that is being sent as a private message to the users that are registered on Twitter, the extracted malicious link is: hxxp:// www. delicious-audio .com /wp-content If clicked, it redirects users to a new malicious link: HTTP/1.1 302 Found Date: Tue, 08 May 2012 20:50:06 GMT Server: [...]]]></description>
			<content:encoded><![CDATA[<p>One user has reported us a malicious URL that is being sent as a private message to the users that are registered on Twitter, the extracted malicious link is:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// www. delicious-audio .com /wp-content</pre></div></div>

<p>If clicked, it redirects users to a new malicious link:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">HTTP/1.1 302 Found
Date: Tue, 08 May 2012 20:50:06 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Location: hxxp:// blog.keeples .com /wp-content
Content-Encoding: gzip
Vary: Accept-Encoding
Content-Length: 27
Keep-Alive: timeout=5, max=99
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8</pre></div></div>

<p>Extracted malicious link:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// blog.keeples .com /wp-content</pre></div></div>

<p>Now there is a new redirect to another malicious link:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">HTTP/1.1 302 Found
Date: Tue, 08 May 2012 20:50:13 GMT
Server: Apache/2.2.3 (CentOS)
Location: hxxp:// spywarecleanermicrosoft .info /0520091375cbc551/
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8</pre></div></div>

<p>Extracted malicious link:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// spywarecleanermicrosoft .info /0520091375cbc551/</pre></div></div>

<p>This is the link of the web page of the fake antivirus rogue software.</p>
<p>Whois details:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Domain Name: spywarecleanermicrosoft.info
Registrar: eNom, Inc. (R126-LRMS)
Status: CLIENT TRANSFER PROHIBITED, TRANSFER PROHIBITED, ADDPERIOD
Expiration Date: 2013-05-08 11:32:40
Creation Date: 2012-05-08 11:32:40
Last Update Date: 2012-05-08 11:33:15
&nbsp;
Name Servers:
ns1.dnsexit.com
ns2.dnsexit.com
ns3.dnsexit.com
ns4.dnsexit.com
&nbsp;
Registrant Contact Information:
Name: Gerolamo Genovese
Address 1: Via Bernardino Rota 1
City: Mellana
State: CN
Zip: 12012
Country: IT
Phone: +39.3535605212
Email: kinsman@doramail.com</pre></div></div>

<p>Hosting details:</p>
<p>The website spywarecleanermicrosoft .info is hosted at BurstNET Limited and its current IP address is 31.193.12.3 (31-193-12-3.static.hostnoc.net). The server machine is located in United Kingdom (GB) and in the same server there are hosted other 0 websites. The domain is registered with the suffix INFO and the keyword of the domain is spywarecleanermicrosoft. The organization is BurstNET Limited.</p>
<p>Screenshot of the fake warning message:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/08_05_2012-22_59_41.jpeg" alt="Fake Warning Message" /></p>
<p>Screenshot of the fake scanning web page:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/08_05_2012-22_59_55.jpeg" alt="Fake Scanning Page" /></p>
<p>From the above images we can see that it is distributed the fake rogue security software named Windows Antivirus 2012. After the fake system scanning is finished, the user is prompted to downloaded an executable file named setup.exe:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/08_05_2012-23_04_23.jpeg" alt="Downloaded File" /></p>
<p>The file is downloaded from a new malicious website:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">GET /0520091375cbc551/setup.exe HTTP/1.1
Accept: application/x-ms-application, image/jpeg, application/xaml+xml, image/gif, image/pjpeg, application/x-ms-xbap, */*
Referer: hxxp:// spywarecleanermicrosoft .info /0520091375cbc551/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Host: scannerdatamicrosoft .info</pre></div></div>

<p>Whois Details:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Domain Name: scannerdatamicrosoft .info
Registrar: eNom, Inc. (R126-LRMS)
Status: CLIENT TRANSFER PROHIBITED, TRANSFER PROHIBITED, ADDPERIOD
Expiration Date: 2013-05-08 11:11:28
Creation Date: 2012-05-08 11:11:28
Last Update Date: 2012-05-08 11:12:08
&nbsp;
Name Servers:
ns1.dnsexit.com
ns2.dnsexit.com
ns3.dnsexit.com
ns4.dnsexit.com
&nbsp;
Registrant Contact Information:
Name: Dionisia Barese
Address 1: Corso Porta Borsari 78
City: San Martino Di Castrozza
State: TN
Zip: 38058
Country: IT
Phone: +39.3171462400
Email: milner@snail-mail.net</pre></div></div>

<p>Domains Details:</p>
<p>The website scannerdatamicrosoft .info is hosted at SPLIUS, UAB and its current IP address is 77.79.10.13 (hst-10-13.duomenucentras.lt). The server machine is located in Lithuania (LT) and in the same server there are hosted other 0 websites. The domain is registered with the suffix INFO and the keyword of the domain is scannerdatamicrosoft. The organization is Webhosting, collocation services.</p>
<p>File details:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">File: setup.exe
Size: 2278400 bytes
MD5: EC91E0F31587F6471A4EBCFE2681A45B
SHA1: 0AB7F7253F5CBADF6D664781A73D30A19E251FCA
SHA256: 67DFD917561DF7FE653CE5E0CD7E0688E42B719F1BB475A5EE2819003CE6DC6A
SHA384: 77BB9D7DF670BC9F4C91DED341086C30570E6D9AE14BEE1A172F502CA5C502428FC631B9F88A31CECF290B7CFB1C5FA2
SHA512: 85D1F0608D24DD2B15477EAC540666319831F829B7E8065D9E5B8A2AC5D4860486BCA891FA95DBBBB8EB93834485575108EE957C5AD556EFBA9FDA5824D2C780</pre></div></div>

<p>When executed the file setup.exe, the rogue software drops two .EXE files:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/dropped-files-rs.png" alt="Dropped .EXE files" /></p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">File Modified - %SAMPLE% - %AppData%\Protector-phkm.exe
Process Created - %SAMPLE% - %AppData%\Protector-phkm.exe - Unknown Publisher - EC91E0F31587F6471A4EBCFE2681A45B - 2278400 bytes
File Created - %SAMPLE% - %AppData%\Protector-phkm.exe - EC91E0F31587F6471A4EBCFE2681A45B - 2278400 bytes - attr: [] - PE
Process Created - %SAMPLE% - C:\WINDOWS\system32\cmd.exe - Microsoft Corporation - 6D778E0F95447E6546553EEEA709D03C - 389120 bytes
File Deleted - C:\WINDOWS\system32\cmd.exe - %SAMPLE% - 2278400 bytes
File Modified - %SAMPLE% - %AppData%\Protector-tpqx.exe
Process Created - %SAMPLE% - %AppData%\Protector-tpqx.exe - Unknown Publisher - EC91E0F31587F6471A4EBCFE2681A45B - 2278400 bytes
File Created - %SAMPLE% - %AppData%\Protector-tpqx.exe - EC91E0F31587F6471A4EBCFE2681A45B - 2278400 bytes - attr: [] - PE</pre></div></div>

<p>And this is the screenshot of the splash screen of the rogue software:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/windows-prosecurity-scanner-fake-antivirus.png" alt="windows-prosecurity-scanner-fake-antivirus" /></p>
<p>More screenshots of the rogue software:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/roguesoftware-01.png" alt="GUI" /></p>
<p>When the user click on &#8220;Activate&#8221; button, the rogue software executable opens a new Internet Explorer web page where user is supposed to insert his/her credit card details (that will be stolen by the trojan), here is the screenshot of the malicious web page:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/fraud-page.png" alt="Fraud Page" /></p>
<p>Connections logged:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">GET / HTTP/1.0
Accept: application/x-shockwave-flash, */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: www. cmyip .com
Connection: Keep-Alive
&nbsp;
GET /service/ HTTP/1.0
User-Agent: Mozilla/4.0
Host: 0520091375cbc551 .on-linepaysafery .info
&nbsp;
POST / HTTP/1.0
Accept: application/x-shockwave-flash, */*
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: 0520091375cbc551. on-linepaysafery .info
Content-Length: 109
Connection: Keep-Alive
Pragma: no-cache
Cookie: ct=2011:3:27:23:23; ch=f58320d2a7c79b1a48b7c70a7d2d280a
action=form&amp;projectId=72&amp;partnerId=146&amp;subId=0&amp;install_id=yhstmcvcgj&amp;group_name=2011-3-28_1&amp;reason=errorflash
&nbsp;
GET /payment_forms/default/images/sprite.png HTTP/1.0
Accept: */*
Referer: hxxp://0520091375cbc551 .on-linepaysafery .info /
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: 0520091375cbc551 .on-linepaysafery .info
Connection: Keep-Alive
Cookie: ct=2011:3:27:23:23; ch=f58320d2a7c79b1a48b7c70a7d2d280a</pre></div></div>

<p>Malicious links extracted:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// 0520091375cbc551. on-linepaysafery .info /service/</pre></div></div>

<p>Whois Details:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Domain Name: on-linepaysafery .info
Registrar: eNom, Inc. (R126-LRMS)
Status: CLIENT TRANSFER PROHIBITED, TRANSFER PROHIBITED, ADDPERIOD
Expiration Date: 2013-05-08 08:24:44
Creation Date: 2012-05-08 08:24:44
Last Update Date: 2012-05-08 08:26:02
&nbsp;
Name Servers:
ns1.dnsexit.com
ns2.dnsexit.com
ns3.dnsexit.com
ns4.dnsexit.com
&nbsp;
Registrant Contact Information:
Name: Dionisia Barese
Address 1: Corso Porta Borsari 78
City: San Martino Di Castrozza
State: TN
Zip: 38058
Country: IT
Phone: +39.3171462400
Email: sini@wildmail.com</pre></div></div>

<p>Domain details:</p>
<p>The website www.on-linepaysafery .info is hosted at SPLIUS, UAB and its current IP address is 77.79.10.15 (hst-10-15.duomenucentras.lt). The server machine is located in Lithuania (LT) and in the same server there are hosted other 2 websites. The domain is registered with the suffix INFO and the keyword of the domain is on-linepaysafery. The organization is Webhosting, collocation services.</p>
<p>URLVoid scan reports:</p>
<p><a href="http://www.urlvoid.com/scan/delicious-audio.com" title="View safety report with URLVoid.com" target="_blank">http://www.urlvoid.com/scan/delicious-audio .com</a><br />
<a href="http://www.urlvoid.com/scan/spywarecleanermicrosoft.info" title="View safety report with URLVoid.com" target="_blank">http://www.urlvoid.com/scan/spywarecleanermicrosoft .info</a><br />
<a href="http://www.urlvoid.com/scan/0520091375cbc551.on-linepaysafery.info" title="View safety report with URLVoid.com" target="_blank">http://www.urlvoid.com/scan/0520091375cbc551. on-linepaysafery .info</a><br />
<a href="http://www.urlvoid.com/scan/on-linepaysafery.info" title="View safety report with URLVoid.com" target="_blank">http://www.urlvoid.com/scan/on-linepaysafery .info</a><br />
<a href="http://www.urlvoid.com/scan/blog.keeples.com" title="View safety report with URLVoid.com" target="_blank">http://www.urlvoid.com/scan/blog.keeples .com</a><br />
<a href="http://www.urlvoid.com/scan/scannerdatamicrosoft.info" title="View safety report with URLVoid.com" target="_blank">http://www.urlvoid.com/scan/scannerdatamicrosoft .info</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/spam-link-on-twitter-leads-to-fake-antivirus-rogue-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Link LinkedIn Mail leads to Incognito exploit kit</title>
		<link>http://blog.urlvoid.com/link-linkedin-mail-leads-to-incognito-exploit-kit/</link>
		<comments>http://blog.urlvoid.com/link-linkedin-mail-leads-to-incognito-exploit-kit/#comments</comments>
		<pubDate>Fri, 04 May 2012 23:22:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[72.5.102.224]]></category>
		<category><![CDATA[CVE-2012-0507]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploit kit]]></category>
		<category><![CDATA[incognito exploit kit]]></category>
		<category><![CDATA[java exploit]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1020</guid>
		<description><![CDATA[We have logged a new email that looks like to be sent by LinedIn: The email header info shows it is a scam: Received: from lhost10.forahost.net (server-178.211.48.24.as42926.net [178.211.48.24]) Received: from c9069568.static.spo.virtua.com.br ([201.6.149.104]:49583 helo=fixnot.com.tr) by lhost10.forahost.net Date: Fri, 04 May 2012 08:34:11 -0700 From: &#34;Order&#34; @fixnot.com.tr Subject: Link LinkedIn Mail The email body contains also few [...]]]></description>
			<content:encoded><![CDATA[<p>We have logged a new email that looks like to be sent by LinedIn:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/05_05_2012-01_00_46.jpeg" alt="Scam Email" /></p>
<p>The email header info shows it is a scam:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Received: from lhost10.forahost.net (server-178.211.48.24.as42926.net [178.211.48.24])
Received: from c9069568.static.spo.virtua.com.br ([201.6.149.104]:49583 helo=fixnot.com.tr) by lhost10.forahost.net
Date: Fri, 04 May 2012 08:34:11 -0700
From: &quot;Order&quot; @fixnot.com.tr
Subject: Link LinkedIn Mail</pre></div></div>

<p>The email body contains also few <b><font color="red">malicious links</font></b>:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// gopeshmathur .com/ZgUBqavg/index.html</pre></div></div>

<p>The dumped content of the URL is clear a <a href="http://blog.novirusthanks.org/tag/incognito-exploit-kit/" target="_blank">Incognito exploit kit</a>:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/05_05_2012-01_04_59.jpeg" alt="Incognito exploit kit URLs" /></p>
<p>All the new malicious links are still alive and they redirect users to:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/05_05_2012-01_07_28.jpeg" alt="Incognito exploit kit" /></p>
<p>The Java exploit JAR files are downloaded from:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// 50.116.8. 93 /data/Pol.jar
hxxp:// 69.163.34 .114 /data/Pol.jar</pre></div></div>


<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">File: Pol.jar
Size: 15404 bytes
MD5: 020B0B477706596E71DE25286ED77991
SHA1: C196A7B07BFE3D3593E93F7D98E910FA8E63AFF6
SHA256: F76AC6983135C7A69B5F07BC762F1AA478E2D49489090AC66882BC8065D1862B
SHA384: 9C6BF2971E1F86588A9A08A3F18C096FBC62A42CE6927E0A7D0AFDB56DA01DBC4A6F72F742CC62B510FC1085221753D5
SHA512: 5464424E028620C4821B740B89787C7A75E6A56401F98BD15BA94F1A9268D54411E41E97DAE86468F4BDA54160A023DCC45F134E97BC6655E31C9274F8A21FC0</pre></div></div>

<p>The JAR file exploits the vulnerability in the Java Runtime Environment component of Oracle Java SE (<a href="http://www.oracle.com/technetwork/topics/security/javacpufeb2012verbose-366319.html" target="_blank">CVE-2012-0507</a>), more details from the oracle.com website:</p>
<blockquote><p>
Vulnerability in the Java Runtime Environment component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are 7 Update 2 and before, 6 Update 30 and before and 5.0 Update 33 and before. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability can result in unauthorized update, insert or delete access to some Java Runtime Environment accessible data as well as read access to a subset of Java Runtime Environment accessible data and ability to cause a partial denial of service (partial DOS) of Java Runtime Environment.
</p></blockquote>
<p>Other malicious Incognito exploit kit URLs:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// ftp.coden .com .br /BhxC8VrP/index.html
hxxp:// generalcontractorsnc .com/nUUyHyvy/index.html
hxxp:// mccgedvalenca .com .br/JFs10e34/index.html
hxxp:// radiooisvira .com /mRpNLgWY/index.html
hxxp:// statisticsolympiad .org /gR2aietM/index.html</pre></div></div>

<p>URLVoid scan reports:</p>
<p><a href="http://www.urlvoid.com/scan/gopeshmathur.com" target="_blank">http://www.urlvoid.com/scan/gopeshmathur .com</a><br />
<a href="http://www.urlvoid.com/scan/jombangit.com" target="_blank">http://www.urlvoid.com/scan/jombangit .com</a><br />
<a href="http://www.urlvoid.com/scan/shahinvestment.com" target="_blank">http://www.urlvoid.com/scan/shahinvestment .com</a><br />
<a href="http://www.urlvoid.com/scan/mazyamana.com" target="_blank">http://www.urlvoid.com/scan/mazyamana .com</a><br />
<a href="http://www.ipvoid.com/scan/72.5.102.224" target="_blank">http://www.ipvoid.com/scan/72.5.102.224</a><br />
<a href="http://www.urlvoid.com/scan/ftp.coden.com.br" target="_blank">http://www.urlvoid.com/scan/ftp.coden .com .br</a><br />
<a href="http://www.urlvoid.com/scan/generalcontractorsnc.com" target="_blank">http://www.urlvoid.com/scan/generalcontractorsnc .com</a><br />
<a href="http://www.urlvoid.com/scan/mccgedvalenca.com.br" target="_blank">http://www.urlvoid.com/scan/mccgedvalenca .com .br</a><br />
<a href="http://www.urlvoid.com/scan/statisticsolympiad.org" target="_blank">http://www.urlvoid.com/scan/statisticsolympiad .org</a><br />
<a href="http://www.urlvoid.com/scan/radiooisvira.com" target="_blank">http://www.urlvoid.com/scan/radiooisvira .com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/link-linkedin-mail-leads-to-incognito-exploit-kit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Com.Br Websites Infected with Maliciour JS Code (bylviha .ru/count18.php)</title>
		<link>http://blog.urlvoid.com/com-br-websites-infected-with-maliciour-js-code-bylviha-rucount18-php/</link>
		<comments>http://blog.urlvoid.com/com-br-websites-infected-with-maliciour-js-code-bylviha-rucount18-php/#comments</comments>
		<pubDate>Fri, 27 Apr 2012 13:24:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[bylviha.ru]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[js exploit]]></category>
		<category><![CDATA[obfuscated javascript]]></category>
		<category><![CDATA[website infected]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1011</guid>
		<description><![CDATA[Our sandbox has logged various domains with suffix .COM.BR infected with a malicious obfuscated javascript code, that is injected at begin of the HTML pages of the websites, before the initial &#60;html&#62; tag: The malicious script redirects the users to a malicious URL: hxxp:// bylviha .ru/count18.php An example of websites infected: hxxp:// carboniferacatarinense .com .br/ [...]]]></description>
			<content:encoded><![CDATA[<p>Our sandbox has logged various domains with suffix .COM.BR infected with a malicious obfuscated javascript code, that is injected at begin of the HTML pages of the websites, before the initial &lt;html&gt; tag:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/27_04_2012-14_57_23.jpeg" alt="Obfuscated JS code" /></p>
<p>The malicious script redirects the users to a malicious URL:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// bylviha .ru/count18.php</pre></div></div>

<p>An example of websites infected:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// carboniferacatarinense .com .br/
hxxp:// www. csir-iir. org/
hxxp:// www. terapets .com/</pre></div></div>

<p>Sometimes the malicious script is injected inside the &lt;title&gt; tag:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/27_04_2012-15_29_51.jpeg" alt="JS Injected in Title TAG" /></p>
<p>URLVoid reports of malicious domains:</p>
<p><a href="http://www.urlvoid.com/scan/bylviha.ru">http://www.urlvoid.com/scan/bylviha .ru</a><br />
<a href="http://www.urlvoid.com/scan/carboniferacatarinense.com.br">http://www.urlvoid.com/scan/carboniferacatarinense .com .br</a><br />
<a href="http://www.urlvoid.com/scan/csir-iir.org">http://www.urlvoid.com/scan/csir-iir. org</a><br />
<a href="http://www.urlvoid.com/scan/terapets.com">http://www.urlvoid.com/scan/terapets .com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/com-br-websites-infected-with-maliciour-js-code-bylviha-rucount18-php/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing: A causa del nostro recente aggiornamento. Verified by Visa</title>
		<link>http://blog.urlvoid.com/phishing-a-causa-del-nostro-recente-aggiornamento-verified-by-visa/</link>
		<comments>http://blog.urlvoid.com/phishing-a-causa-del-nostro-recente-aggiornamento-verified-by-visa/#comments</comments>
		<pubDate>Mon, 23 Apr 2012 14:40:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[visa phishing]]></category>
		<category><![CDATA[visaitalia phishing]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1006</guid>
		<description><![CDATA[We have logged other phishing emails used to steal details of Visa users: From - Mon Apr 23 16:04:50 2012 Received: from ser.just3d.tv (unknown [91.227.127.33]) Received: (qmail 23589 invoked by uid 0); 23 Apr 2012 13:21:36 -0000 Received: from unknown (HELO User) (admin@just3d.tv@151.58.16.184) Reply-To: sicurela@visaltalia.it From: &#34;verified by visa&#34; verified@visaitalia.com Subject: A causa del nostro [...]]]></description>
			<content:encoded><![CDATA[<p>We have logged other phishing emails used to steal details of Visa users:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">From - Mon Apr 23 16:04:50 2012
Received: from ser.just3d.tv (unknown [91.227.127.33])
Received: (qmail 23589 invoked by uid 0); 23 Apr 2012 13:21:36 -0000
Received: from unknown (HELO User) (admin@just3d.tv@151.58.16.184)
Reply-To: sicurela@visaltalia.it
From: &quot;verified by visa&quot; verified@visaitalia.com
Subject: A causa del nostro recente aggiornamento.
Date: Mon, 23 Apr 2012 15.21.34 +0200
To: undisclosed-recipients:;</pre></div></div>

<p>Note from the email header the source of the message:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Received: from ser.just3d.tv (unknown [91.227.127.33])</pre></div></div>

<p>It has nothing to do with Visa, and note also the emails:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Reply-To: sicurela@visaltalia.it</pre></div></div>

<p>See the visa<b>l</b>talia.it is a <b>l</b> and not an <b>i</b>.</p>
<p>The message of the email:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Gentile Cliente, 
A causa del nostro recente aggiornamento sui nostri server 
(23/04/2012) e necessario aggiornare il tuo profilo. 
Per una maggiore sicurezza e di accesso, si prega di compilare il 
modulo allegato. 
&nbsp;
Vi ringraziamo della vostra collaborazione. 
&nbsp;
© Copyright Visa Europe 2012. Tutti i diritti riservati</pre></div></div>

<p>There is also an attached file named <b>visaitalia.html</b>:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">File: visaitalia.html
Size: 20015 bytes
MD5: 2C76E9F667E78C8C32C09DBE1129969E
SHA1: 0A30FFC20AC311AF2831086D4B181E0F23483399
SHA256: 1757C6A066E61F1B3E9782570712641FC734E1C6ACCD1DA329F3B10B164136CC
SHA384: BD80E5B8A83A3C00D72B6367421AE85CC6A1FF8981F43D0D6784B52D0AAE58B22DD74293BD8735C8B0E4331C8CCCDA02
SHA512: 4B82AC139180E6B19C58A553456BBE30CE155E22A695E300115CAC5C8BDB3F84A024CCDF104E280162B0C44AF1495C850CA3565533DE62EC6F14EF7754295A30</pre></div></div>

<p>The attached file contains the form used to send the typed details to a remote link. Listed below there are few malicious links extracted from the HTML attached file:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// leonidasvancouver .com /admin/plm/plm.html
hxxp:// rottenfish .de /vbv/plm_files/Logo-Mastercard_Secure_Code.gif
hxxp:// rottenfish .de /vbv/plm_files/fin_VerifiedByVisa_186x79.gif
hxxp:// rottenfish .de /vbv/run.php</pre></div></div>

<p>The malicious websites are classified as detected in URLVoid:</p>
<p><a href="http://www.urlvoid.com/scan/rottenfish.de/" target="_blank">http://www.urlvoid.com/scan/rottenfish .de/</a><br />
<a href="http://www.urlvoid.com/scan/leonidasvancouver.com/" target="_blank">http://www.urlvoid.com/scan/leonidasvancouver .com/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/phishing-a-causa-del-nostro-recente-aggiornamento-verified-by-visa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPVoid v2.0 (BETA3) Changelog</title>
		<link>http://blog.urlvoid.com/ipvoid-v2-0-beta3-changelog/</link>
		<comments>http://blog.urlvoid.com/ipvoid-v2-0-beta3-changelog/#comments</comments>
		<pubDate>Thu, 12 Apr 2012 13:18:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1003</guid>
		<description><![CDATA[New BETA3 of IPVoid service is online. Here is the main changelog: - Service has been rewritten completely - Added other blacklists engines (now 37 in total) - Fixed various blacklists results - View IP addresses related to an ISP - View IP addresses related to an Organization - View IP addresses located in a [...]]]></description>
			<content:encoded><![CDATA[<p>New BETA3 of <a href="http://www.ipvoid.com/" target="_blank">IPVoid</a> service is online.</p>
<p>Here is the main changelog:</p>
<p>- Service has been rewritten completely<br />
- Added other blacklists engines (now 37 in total)<br />
- Fixed various blacklists results<br />
- View IP addresses related to an ISP<br />
- View IP addresses related to an Organization<br />
- View IP addresses located in a Country<br />
- View old reports of an IP address<br />
- Rescan an IP address after 30 minutes<br />
- Scanning time is much faster (around 8 seconds)<br />
- Show how much is old the report (ex: 20 Days Ago)</p>
<p>Want to suggest a feature or report a bug ?<br />
Contact us at info (at) novirusthanks (dot) org</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/ipvoid-v2-0-beta3-changelog/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Express LinkedIn Mail: spread Blackhole Exploit Kit URLs</title>
		<link>http://blog.urlvoid.com/express-linkedin-mail-spread-blackhole-exploit-kit-urls/</link>
		<comments>http://blog.urlvoid.com/express-linkedin-mail-spread-blackhole-exploit-kit-urls/#comments</comments>
		<pubDate>Fri, 30 Mar 2012 22:03:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[blackhole]]></category>
		<category><![CDATA[blackhole exploit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[linkedin exploit email]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=992</guid>
		<description><![CDATA[We have received few emails that looked like to be sent from LinkedIn: But after checking email header details it was clearly a spam: Return-Path: trtro@www.trt.ro Received: from vps136.whmpanels.com (unknown [89.42.219.181]) Received: from [95.6.42.101] (helo=www.trt.ro) by vps136.whmpanels.com Date: Fri, 30 Mar 2012 21:37:47 +0100 From: &#34;Support&#34; trtro@www.trt.ro Subject: Express LinkedIn Mail The A HREF links [...]]]></description>
			<content:encoded><![CDATA[<p>We have received few emails that looked like to be sent from LinkedIn:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/30_03_2012-23_35_46.jpeg" alt="Email" title="Email Message" /></p>
<p>But after checking email header details it was clearly a spam:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Return-Path: trtro@www.trt.ro
Received: from vps136.whmpanels.com (unknown [89.42.219.181])
Received: from [95.6.42.101] (helo=www.trt.ro) by vps136.whmpanels.com
Date: Fri, 30 Mar 2012 21:37:47 +0100
From: &quot;Support&quot; trtro@www.trt.ro
Subject: Express LinkedIn Mail</pre></div></div>

<p>The A HREF links redirect to 3 different malicious URLs:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// groupehydrogaz .com/20sZhJqa/index.html
hxxp:// dealerpos .com/uFj7A93z/index.html
hxxp:// hobbyconcept666.yellis .net/20sZhJqa/index.html</pre></div></div>

<p>URLVoid reports:</p>
<p><a href="http://www.urlvoid.com/scan/groupehydrogaz.com/" target="_blank">http://www.urlvoid.com/scan/groupehydrogaz.com/</a><br />
<a href="http://www.urlvoid.com/scan/dealerpos.com/" target="_blank">http://www.urlvoid.com/scan/dealerpos.com/</a><br />
<a href="http://www.urlvoid.com/scan/hobbyconcept666.yellis.net/" target="_blank">http://www.urlvoid.com/scan/hobbyconcept666.yellis.net/</a></p>
<p>The page content dumped from one of these malicious URLs looks like:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/30_03_2012-23_39_41.jpeg" alt="Dumped Content" title="Dumped Content" /></p>
<p>That content looks like the spread-style of <a href="http://blog.urlvoid.com/index.php?s=exploit">Blackhole Exploit Kit</a>.</p>
<p>Other malicious URLs are:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp:// ftp.planitur .com.br/dyEmcL4N/js.js
hxxp:// quiztown .org/U2iBLpvu/js.js
hxxp:// wap .tl/8M6kMfpV/js.js
hxxp:// laspeziacaritas .it/1M4VoeVe/js.js</pre></div></div>

<p>URLVoid reports:</p>
<p><a href="http://www.urlvoid.com/scan/ftp.planitur.com.br/" target="_blank">http://www.urlvoid.com/scan/ftp.planitur.com.br/</a><br />
<a href="http://www.urlvoid.com/scan/quiztown.org/" target="_blank">http://www.urlvoid.com/scan/quiztown.org/</a><br />
<a href="http://www.urlvoid.com/scan/wap.tl/" target="_blank">http://www.urlvoid.com/scan/wap.tl/</a><br />
<a href="http://www.urlvoid.com/scan/laspeziacaritas.it/" target="_blank">http://www.urlvoid.com/scan/laspeziacaritas.it/</a></p>
<p>Pay always attention when opening <b>known and unknown</b> emails:</p>
<p>1) Always analyze email headers to see who sent the email<br />
2) Scan links with our service <a href="http://www.urlvoid.com/">http://www.urlvoid.com/</a><br />
3) Do not download unknown files<br />
4) Avoid to open emails that have subject related to pharmaceutical products<br />
5) Avoid to open emails that have subject related to sexual content<br />
6) When emails are from your Bank, always call your Bank before open the email</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/express-linkedin-mail-spread-blackhole-exploit-kit-urls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

