<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-446873836886549311</atom:id><lastBuildDate>Wed, 16 May 2012 17:35:08 +0000</lastBuildDate><category>crimeware research</category><category>web</category><category>siberia exploit pack</category><category>e-fraud research</category><category>malware</category><category>ESET</category><category>Drive-by-Download</category><category>cybint</category><category>IE Defender</category><category>affiliate program research</category><category>safety</category><category>vulnerabilities</category><category>exploit pack research</category><category>espionage</category><category>zeus</category><category>scareware</category><category>spam</category><category>anti-virus live 2010</category><category>malware intelligence</category><category>iMunizator</category><category>Fast-Flux</category><category>xss</category><category>luckysploit</category><category>dos</category><category>iJAVA</category><category>elfiesta</category><category>vulnerabilities researcher</category><category>fragus</category><category>whitepapers</category><category>russkill</category><category>Unique Sploit Pack</category><category>attack</category><category>security</category><category>MacOS</category><category>Social Engineering</category><category>xp police antivirus</category><category>crimeware</category><category>Java Drive-by-Download</category><category>Polymorphic PoisonIvy Builder Online. PoisonIvy</category><category>waledac</category><category>ddos</category><category>desinformation</category><category>botnet</category><category>Polymorphic Cryptor Crum</category><category>denial of service</category><category>koobface</category><category>phishing</category><category>rogue</category><category>jorge mieres</category><category>iformation</category><category>pistus malware intelligence</category><category>botnet research</category><category>malware research</category><category>Drive-by-Update</category><category>exploit</category><category>password</category><category>fragu</category><category>MaaS</category><title>Malware Intelligence Blog</title><description>The information shared on this site is part of several research sessions and, in most textbooks, provides information that can harm your system if handled improperly. The decision to share it's purely investigative and educational, considering also useful for the prevention of attacks by different threats.</description><link>http://malwareint.blogspot.com/</link><managingEditor>noreply@blogger.com (Jorge Mieres)</managingEditor><generator>Blogger</generator><openSearch:totalResults>168</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/blogspot/malwareint" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="blogspot/malwareint" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-3097166772282348352</guid><pubDate>Sun, 29 Jan 2012 16:02:00 +0000</pubDate><atom:updated>2012-01-29T09:02:54.656-07:00</atom:updated><title>Hierarchy Exploit Pack. New crimeware for the cybercriminal gangs</title><atom:summary type="text">The term "hierarchy" refers to an entity pyramidal action. Judging by the name of this new Exploit Pack of Russian origin, it seems that the author seeks to find its place within the criminal ecosystem, but all point to the feelings behind this is, above all, a beginner who seeks criminal more.


However, despite being a package of more criminal exploitation within a vast range of alternatives, </atom:summary><link>http://malwareint.blogspot.com/2012/01/hierarchy-exploit-pack-new-crimeware.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-i3g97W6Fpkw/TyTez1QJSZI/AAAAAAAAAfQ/dPef4PfzYB0/s72-c/1.png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-7936268098097864851</guid><pubDate>Tue, 24 Jan 2012 08:49:00 +0000</pubDate><atom:updated>2012-01-27T20:40:47.516-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">affiliate program research</category><title>Money Racing AV. Tracking a scareware affiliate</title><atom:summary type="text">Since October 2011 we watch this affiliate system. Money Racing AV, a private PPS (Pay-Per-Sale) affiliate who spread actively fake antispywares (rogue). We have already seen this gang active in August 2009: A recent tour of scareware XII.Advertising can be found on various russian underground communities:



First contact with FTL (6 October 2011):

[14:29:33] Load4sales: hello
[14:30:02] mr: </atom:summary><link>http://malwareint.blogspot.com/2012/01/money-racing-av-tracking-scareware.html</link><author>noreply@blogger.com (Steven K)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-d8ZZCKhJTNk/Tx2VKSm65pI/AAAAAAAAE-s/n-6zxM40cdQ/s72-c/23-01-2012+09-28-16-Money-Racing-AV-FTL.png" height="72" width="72" /><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-266695159668253062</guid><pubDate>Wed, 12 Oct 2011 05:48:00 +0000</pubDate><atom:updated>2011-10-11T22:48:56.237-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">exploit pack research</category><category domain="http://www.blogger.com/atom/ns#">crimeware research</category><title>Inside Phoenix Exploit’s Kit 2.8 mini version</title><atom:summary type="text">Phoenix Exploit's Kit is a package with more continuity in crime scene crimeware. After all this tour is currently in the wild version 2.8 that, despite having a low activity since the last half of this year, remains one of the many Exploit Pack with greater preference for cyber-criminals.

Perhaps this "slack time" to have your response in high demand now has another crimeware of this style, </atom:summary><link>http://malwareint.blogspot.com/2011/10/inside-phoenix-exploits-kit-28-mini.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-HAdtWKk8Dqc/TpTdjN-dbDI/AAAAAAAAAdw/cspksTd_-Tk/s72-c/1.png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-5628814096165428551</guid><pubDate>Tue, 27 Sep 2011 00:34:00 +0000</pubDate><atom:updated>2011-09-26T17:34:44.960-07:00</atom:updated><title>Show me your Kung-Fu. Reversing/Forensic Android</title><atom:summary type="text">The last week was held in Barcelona the NoConName security conference, and I had the pleasure of attending to give a security conference about Android. It talked about how to perform a dynamic analysis, static and forensic skip protection and release application along with our friend of MalwareIntelligence too, Ehooo, a small PoC reveals a vulnerability of Tap-Jacking.

For those who could not </atom:summary><link>http://malwareint.blogspot.com/2011/09/show-me-your-kung-fu-reversingforensic.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-IY4SfK62YQk/ToEKNuol4mI/AAAAAAAAAds/R92U2S6h-Xg/s72-c/26-09-2011+20-05-24.png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-3202169022633593234</guid><pubDate>Thu, 18 Aug 2011 21:37:00 +0000</pubDate><atom:updated>2011-08-18T14:38:57.708-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">exploit pack research</category><title>Black Hole Exploits Kit 1.1.0 Inside</title><atom:summary type="text">Since its appearance in September 2010, Black Hole Exploits Kit had a very positive insight into the criminal environment. Their life cycle is not over yet so it has developed a natural evolution, and so far there are three generations that exist "in the wild".

Black Hole Exploits Kit was developed by who is known under the nickname Paunch. The main screen allows viewing of each component of </atom:summary><link>http://malwareint.blogspot.com/2011/08/black-hole-exploits-kit-110-inside.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-ruv4U412oOQ/Tk1rWGU2BgI/AAAAAAAAAdU/e9IZ6SDK3xw/s72-c/1.jpg" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-7111813513965908398</guid><pubDate>Fri, 01 Jul 2011 00:45:00 +0000</pubDate><atom:updated>2011-06-30T17:45:41.571-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">iJAVA</category><category domain="http://www.blogger.com/atom/ns#">Drive-by-Download</category><category domain="http://www.blogger.com/atom/ns#">Java Drive-by-Download</category><title>JAVA Drive-by [infection] On Demand</title><atom:summary type="text">JAVA is one of the largest computer technology integration in the field of cybercrime because of its status as a "hybrid". This transforms Java platform in a highly exploited vector for the spread of all types of malicious code.

Even the modern crimeware includes a battery of exploits created to exploit vulnerable versions of JAVA through Exploit Packs, and in fact, together with the PDF files, </atom:summary><link>http://malwareint.blogspot.com/2011/06/java-drive-by-infection-on-demand.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-q1oIU4yHotw/Tg0OOoKjFoI/AAAAAAAAAc0/rb2YACs23po/s72-c/camera-option.jpg" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-3338515853020356956</guid><pubDate>Wed, 15 Jun 2011 22:29:00 +0000</pubDate><atom:updated>2011-06-15T15:32:41.025-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">whitepapers</category><title>The Art of the Cyberwar</title><atom:summary type="text">The development of new technologies, in catching up with military interests and dependence on existing technology by developed countries, sets up a scenario where the cyber war, or war in cyberspace, is becoming more important.

All countries aware of the risks of such dependence developed defense programs against attacks that could jeopardize critical national infrastructure.

On the other hand,</atom:summary><link>http://malwareint.blogspot.com/2011/06/art-of-cyberwar.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-aRH8bnh4SQI/TfkxgKelWOI/AAAAAAAAAcs/BafvgDwMN1o/s72-c/the-art-of-the-cyberwar.png" height="72" width="72" /><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-4627231180423581113</guid><pubDate>Sun, 03 Apr 2011 21:45:00 +0000</pubDate><atom:updated>2011-04-03T14:45:08.180-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">exploit pack research</category><title>Gangsterware. Stealth Shield of the Malware</title><atom:summary type="text">A few days ago I watched one of the training of BlackHat Webcast whose title is the same as used for this post, where people of M86Security was assigned to conduct a superficial talking about the main vectors of infection today. Putting focus primarily on Exploit Packs, and emphasizing time on the modus operandi of Phoenix Kit Exploit, Neosploit and Open Source Exploit Kit (a lot of impact </atom:summary><link>http://malwareint.blogspot.com/2011/04/gangsterware-stealth-shield-of-malware.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-Fyd5MM_Ohfk/TZjiYqdMjQI/AAAAAAAAAcM/2VRGKg1yFV8/s72-c/17-02-2011+06-27-35+p.m..png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-5592985780286652488</guid><pubDate>Tue, 22 Feb 2011 14:51:00 +0000</pubDate><atom:updated>2011-02-22T07:51:26.717-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">jorge mieres</category><title>See you soon Jorge Mieres!</title><atom:summary type="text">As many readers know, this means of information read at this time, was founded by Jorge Mieres in 2006. What you may not know is that several months ago, Jorge has decided to move away from the front of MalwareIntelligence, leaving us with complete confidence (one of the many qualities and characteristics of Jorge) the command of his legacy.

For this reason, and through these few words, we want </atom:summary><link>http://malwareint.blogspot.com/2011/02/see-you-soon-jorge-mieres.html</link><author>noreply@blogger.com (Jorge Mieres)</author><thr:total>4</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-7093043921136724253</guid><pubDate>Sat, 19 Feb 2011 04:58:00 +0000</pubDate><atom:updated>2011-02-18T21:58:35.166-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">botnet research</category><title>Inside Carberp Botnet</title><atom:summary type="text">In early 2010, from MalwareIntelligence started researching a new botnet designed to agglutination of sensitive information relating to bank accounts, and theft of credentials to exploit a disturbing list of programs.

NOTE: At the bottom of this article may find the link to download the complete white paper, called "Inside Carberp Botnet", which describes the various internal components that </atom:summary><link>http://malwareint.blogspot.com/2011/02/inside-carberp-botnet.html</link><author>noreply@blogger.com (Jorge Mieres)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-4316866949007249493</guid><pubDate>Thu, 17 Feb 2011 01:57:00 +0000</pubDate><atom:updated>2011-02-16T18:57:42.210-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">whitepapers</category><title>MalwareIntelligence whitepapers</title><atom:summary type="text">Botnets Administration. A real case - ZeuS &amp; SpyEye
Malware  networks continue to grow and parallel to, the potential risk of  becoming victims of their criminal activities. Gone are those days where  the main vector for malicious code distribution was made up of pages  that promote pornographic and warez type programs.

Today,  malware is distributed through any kind of website as a key used to</atom:summary><link>http://malwareint.blogspot.com/2011/02/malwareintelligence-whitepapers.html</link><author>noreply@blogger.com (Jorge Mieres)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-2670256246721800834</guid><pubDate>Sun, 07 Nov 2010 22:53:00 +0000</pubDate><atom:updated>2010-11-07T15:57:33.176-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">crimeware research</category><title>Crimeware Exposed</title><atom:summary type="text">Currently, the crimeware is widely exploited by individuals or criminal groups that seek to improve its economy so completely fraudulent using evasive and aggressive strategies.To MalwareIntelligence, the fight against cyber-crime has become his philosophy and primary objective, which make everyday a perfect excuse to address different research then channeled through one of their blogs.That is </atom:summary><link>http://malwareint.blogspot.com/2010/11/crimeware-exposed.html</link><author>noreply@blogger.com (Jorge Mieres)</author><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-381661131650650542</guid><pubDate>Wed, 06 Oct 2010 16:42:00 +0000</pubDate><atom:updated>2010-10-06T09:42:45.967-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">exploit pack research</category><category domain="http://www.blogger.com/atom/ns#">crimeware research</category><title>Eleonore Exploit Pack. New version</title><atom:summary type="text">Without functional alternatives to renew in the package, a new version of crimeware Eleonore Exploit Pack. This is the version 1.4.4mod.

Acces panel of Eleonore Exploit Pack 1.4.4mod
While this version of crimeware is positioned as part of a set of alternatives whose number is constantly increasing due to the large range that currently exists in the area of crime, isn't very viable option for </atom:summary><link>http://malwareint.blogspot.com/2010/10/eleonore-exploit-pack-new-version.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TKyjAPTvQbI/AAAAAAAAAaM/JG_eK4qx3gY/s72-c/MI_EEP-cpanel.png" height="72" width="72" /><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-1552451558103765321</guid><pubDate>Fri, 01 Oct 2010 12:07:00 +0000</pubDate><atom:updated>2011-04-13T10:43:58.996-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">crimeware research</category><title>Phoenix Exploit’s Kit v2.3 Inside</title><atom:summary type="text">PEK (Phoenix Exploit's Kit) has become one of the most used by those who flood the Internet every day with different types of malicious code. Currently, a large amount of malware is distributed through this crimeware, which is also widely used for collecting information relevant to a botmaster.

Earlier we mentioned how it looks inside version 2.1 and at the same time we said that from the </atom:summary><link>http://malwareint.blogspot.com/2010/10/phoenix-exploits-kit-v23-inside.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TKUn9UEKbdI/AAAAAAAAAZ4/-DZlaZB3FTk/s72-c/MI_PEK23-simple-stat.png" height="72" width="72" /><thr:total>3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-7058038431872049746</guid><pubDate>Thu, 30 Sep 2010 18:14:00 +0000</pubDate><atom:updated>2010-09-30T11:14:48.419-07:00</atom:updated><title>Black Hole Exploits Kit. Another crimeware in addition to criminal supply</title><atom:summary type="text">Crimeware industry continues to grow through the development and implementation of new marketing packages pre-compiled exploits add to the supply of alternatives to facilitate criminal maneuvers over the Internet.

In this case, it's Black Hole Exploits Kits, a web application developed in Russia but also incorporates for the English language interface, and the first version (beta at the moment) </atom:summary><link>http://malwareint.blogspot.com/2010/09/black-hole-exploits-kit-another.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TKTJMuaaJ0I/AAAAAAAAAZo/B1yeh2dr018/s72-c/MI_BH-stat-traffic.png" height="72" width="72" /><thr:total>23</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-3628683665740031373</guid><pubDate>Fri, 10 Sep 2010 04:15:00 +0000</pubDate><atom:updated>2010-09-09T21:15:27.586-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">crimeware research</category><title>Black Software. New affiliate business type Pay-per-Install</title><atom:summary type="text">The business model that represent the affiliate programs through systems of the type Pay-per-Install is in full swing, being a fundamental part of criminal groups seeking to increase their economy.

In this case, we have a new affiliate program called Black Software, which promotes the discharge of malware.
 Black Software Access Panel This is a simple authentication process and conventional and </atom:summary><link>http://malwareint.blogspot.com/2010/09/black-software-new-affiliate-business.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TImq099xL9I/AAAAAAAAAY8/OxKyqNSalMA/s72-c/MI_BlackSoftware-login.png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-1626063079646587741</guid><pubDate>Wed, 08 Sep 2010 19:26:00 +0000</pubDate><atom:updated>2010-09-08T12:26:00.631-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">exploit pack research</category><category domain="http://www.blogger.com/atom/ns#">crimeware research</category><title>Phoenix Exploit’s Kit v2.1 Inside</title><atom:summary type="text">The crimeware is one of the most used by cyber criminals to gather intelligence enabling the identification of trends and customs around by people who use the Internet daily.

This seeks to obtain relevant information on time and complete details of the victims who, further, they allow criminals to know about which factors to emphasize their "improvements" in the web application, and botmaster </atom:summary><link>http://malwareint.blogspot.com/2010/09/phoenix-exploits-kit-v21-inside.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TIfTtZ9pzoI/AAAAAAAAAYE/xjoVSXpUpvk/s72-c/simple-stat.png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-3623503879675507200</guid><pubDate>Wed, 08 Sep 2010 03:58:00 +0000</pubDate><atom:updated>2010-09-07T20:59:14.371-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">botnet research</category><category domain="http://www.blogger.com/atom/ns#">crimeware research</category><title>myLoader C&amp;C Oficla Botnet in BKCNET "SIA" IZZI with the highest infection rate in Brazil</title><atom:summary type="text">myLoader is a web application that allows offenders to collect statistical information related to different factors and features on each of the infected computers. The crimeware is sold in the underground market at an average cost of $ 700.

The botnet Oficla started their criminal activities at the beginning of 2010 and just the executable binary detected by antivirus engines as Oficla or Sasfis</atom:summary><link>http://malwareint.blogspot.com/2010/09/myloader-c-oficla-botnet-in-bkcnet-sia.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TIbuHF7eKGI/AAAAAAAAAXk/Ewe376uxyjU/s72-c/MI_myloader-statistics.png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-1799263831423581558</guid><pubDate>Wed, 08 Sep 2010 03:14:00 +0000</pubDate><atom:updated>2010-09-07T20:14:57.754-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">whitepapers</category><title>Criminal activities from BKCNET “SIA” IZZI / ATECH-SAGADE - Part one</title><atom:summary type="text">BKCNET "SIA" IZZI, also known as or simply ATECH-SAGADE is an AS (Autonomous System) numbers in 6851, currently is one of the most active of crimeware through which are distributed daily a large amount of malicious code , besides being the control base for the accommodation of several C&amp;C which feed the underground economy.

Your geolocation is in Latvia and, as I mentioned on another occasion, "</atom:summary><link>http://malwareint.blogspot.com/2010/09/criminal-activities-from-bkcnet-sia.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TIb_Ev2dNKI/AAAAAAAAAX8/tsdZxXcEEBs/s72-c/bkcnet-sagade.png" height="72" width="72" /><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-2065816619688044563</guid><pubDate>Sat, 04 Sep 2010 01:02:00 +0000</pubDate><atom:updated>2010-09-03T18:02:27.256-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware research</category><title>Circuit membership for the dissemination of NoAdware rogue</title><atom:summary type="text">Malware hides behind a business. Without a doubt, I believe that no one denies this claim. Day by day is an important flow of malicious code that, while general purpose have a story in its activities, seeking final feedback on the business behind through fraudulent mechanisms and strategies.

One of the most popular business models is to pay a percentage of money given to those who successfully </atom:summary><link>http://malwareint.blogspot.com/2010/09/circuit-membership-for-dissemination-of.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TIGNrIJ590I/AAAAAAAAAXE/2tWuwui0r0o/s72-c/MI-noadware-page.png" height="72" width="72" /><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-1357949467807786956</guid><pubDate>Tue, 31 Aug 2010 02:49:00 +0000</pubDate><atom:updated>2010-08-30T19:49:22.891-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">malware research</category><title>FakeAV via new strategy of deception from BKCNET "SIA" IZZI</title><atom:summary type="text">Generally cheating strategies designed for the dissemination of false antivirus (AV Rogue) consist of online simulation of a scan for malware, showing an interface that mimics Windows Explorer and which always face the same threats, including when using operating systems other than Windows.
Conventional strategy of deception
This is one of the many templates. It shows a supposed scan to verify </atom:summary><link>http://malwareint.blogspot.com/2010/08/fakeav-via-new-strategy-of-deception.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THxjCdVGshI/AAAAAAAAAVs/TvzzQOOVVu0/s72-c/MI_fakeav.png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-2705337106315723198</guid><pubDate>Wed, 18 Aug 2010 17:01:00 +0000</pubDate><atom:updated>2010-08-18T10:01:09.308-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">whitepapers</category><title>State of the art in Phoenix Exploit's Kit</title><atom:summary type="text">Criminal alternatives grow very fast in an ecosystem where day to day business opportunities are conceived through fraudulent processes. In this sense, the demand for resources for the cyber criminal isn't expected and is constantly growing.

Generally I find new crimeware looking to get a place and a good acceptance in the virtual streets of the world underground, trying to reflect a balance on </atom:summary><link>http://malwareint.blogspot.com/2010/08/state-of-art-in-phoenix-exploits-kit.html</link><author>noreply@blogger.com (Jorge Mieres)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-6123029315505907497</guid><pubDate>Mon, 16 Aug 2010 03:37:00 +0000</pubDate><atom:updated>2010-08-15T20:37:02.908-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">affiliate program research</category><title>Pirated Edition. Affiliate program Pay-per-Install</title><atom:summary type="text">Affiliate programs are a growing business model more profitable for criminals and create a complete circuit of spreading / malware infection among many other alternatives, encouraging its customers with a percentage of money they get in terms of success their own business.

One of the systems with greater uptake in this business model is provided by the facility payment, Pay-per-Install, where </atom:summary><link>http://malwareint.blogspot.com/2010/08/pirated-edition-affiliate-program-pay.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TGivO6czaQI/AAAAAAAAATs/ggzyCStIhJc/s72-c/MI_pirated-edition-cpanel.png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-7620373591619744026</guid><pubDate>Thu, 12 Aug 2010 00:30:00 +0000</pubDate><atom:updated>2010-08-11T17:33:21.230-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">crimeware research</category><title>Pay-per-Install through VIVA INSTALLS / HAPPY INSTALLS in BKCNET “SIA” IZZI</title><atom:summary type="text">One of the most profitable businesses in the area computer crime, what are the affiliate programs. These are systems which adhere offenders an economic return for a commission, as in this case, for each successful installation of malware that takes place through the system distributed. 

VIVA INSTALLS, belonging to the same criminal group that is facing HAPPY INSTALLS, is one of them. This system</atom:summary><link>http://malwareint.blogspot.com/2010/08/pay-per-install-through-viva-installs.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TGM3n5q9exI/AAAAAAAAAS8/ngqdV4_jvQY/s72-c/MI_vivainstalls.png" height="72" width="72" /><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-446873836886549311.post-4117310517968865930</guid><pubDate>Mon, 09 Aug 2010 15:00:00 +0000</pubDate><atom:updated>2010-08-09T08:00:35.031-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">exploit pack research</category><title>Campaign infection through Phoenix Exploit's Pack</title><atom:summary type="text">Phoenix Exploit's Pack (PEK) is another crimeware programs more widely accepted within the online criminal ecosystem, whose use in the past week massifies spreading a large amount of malware.Executable binaries that are part of the campaign so far is active, spread under the default name of the executable that incorporates the package, called exe.exe. Some of the executables that are part of this</atom:summary><link>http://malwareint.blogspot.com/2010/08/campaign-infection-through-phoenix.html</link><author>noreply@blogger.com (Jorge Mieres)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TF2xhzTN3VI/AAAAAAAAARc/ivkYxmzadQc/s72-c/MI_login.png" height="72" width="72" /><thr:total>0</thr:total></item></channel></rss>

