<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: exe]]></title>
    <link>http://www.securityratty.com/tag/exe</link>
    <description></description>
    <pubDate>Mon, 14 Jul 2008 07:20:34 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Holy Media Codecs, Batman!]]></title>
      <link>http://www.securityratty.com/article/3d984264f929456ea8e4f274d55394ef</link>
      <guid>http://www.securityratty.com/article/3d984264f929456ea8e4f274d55394ef</guid>
      <description><![CDATA[Batman is still in full swing at the box office - I'm sure me seeing it seven times probably didn't hurt - so with that in mind (and thoughts of the Zango / Dark Knight issue still rattling around my...]]></description>
      <content:encoded><![CDATA[
        Batman is still in full swing at the box office - I'm sure me seeing it seven times probably didn't hurt - so with that in mind (and thoughts of the <a href="http://www.theregister.co.uk/2008/08/18/dark_knight_zango_affiliate_gateway/">Zango / Dark Knight issue</a> still rattling around my brain) I thought it would be fun to see exactly how quickly it can all go wrong when looking for Dark Knight material online.<br /><br />The answer is: extremely quickly.<br /><br />There's a lot of sites out there claiming to carry "full versions" of The Dark Knight, and although they don't offer Zango, they <i>do</i> offer fake media codecs (which usually do all sorts of horrible things to a computer). Let's pull one of these sites apart as an example of how the scam fits together.<br /><br />Here's a typical site pushing what they claim to be The Dark Knight:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman000.html" onclick="window.open('http://blog.spywareguide.com/images/dbman000.html','popup','width=717,height=564,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman000-thumb-317x249.jpg" alt="dbman000.jpg" class="mt-image-none" style="" height="249" width="317" /></a></span><br />Click to Enlarge<br /></div><br />Dijgg(dot)com, an obvious Digg.com knockoff apparently hosting a large streaming window - the movie quality will be awesome, won't it? Well, actually, no it won't.<br /><br />In the middle of the video window is a popup:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman0.jpg" src="http://blog.spywareguide.com/images/dbman0.jpg" class="mt-image-none" style="" height="145" width="399" /></span></div><br /><br /> <div>Install the "codec", and this won't end well. The EXE comes from a site called Favoritetube(dot)com:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman1.jpg" src="http://blog.spywareguide.com/images/dbman1.jpg" class="mt-image-none" style="" height="203" width="348" /></span></div><br /><br />A quick check for the <a href="http://www.siteadvisor.com/sites/favoritetube.net/postid?p=1063293">safety</a> <a href="http://safeweb.norton.com/report/show?name=favoritetube.net">ratings</a> of that website should be enough to tell you this is a scam. Indeed, there isn't even a movie being streamed here (despite it saying "Connecting" at the bottom of the movie player) - because if you right click on the player itself:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman0000.jpg" src="http://blog.spywareguide.com/images/dbman0000.jpg" class="mt-image-none" style="" height="370" width="418" /></span></div><br /></div><div><br />You can see the "player" is actually just a static image (because I'm given the option to "Copy Image Location"). The image is hosted at Favoritetube, just like the "codecs":<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman2.html" onclick="window.open('http://blog.spywareguide.com/images/dbman2.html','popup','width=655,height=570,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman2-thumb-355x308.jpg" alt="dbman2.jpg" class="mt-image-none" style="" height="308" width="355" /></a></span><br /><br />Click to Enlarge<br /></div><br />There are quite a lot of these sites floating around out there at present:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman3.html" onclick="window.open('http://blog.spywareguide.com/images/dbman3.html','popup','width=738,height=532,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman3-thumb-338x243.jpg" alt="dbman3.jpg" class="mt-image-none" style="" height="243" width="338" /></a></span><br /><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman4.html" onclick="window.open('http://blog.spywareguide.com/images/dbman4.html','popup','width=599,height=533,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman4-thumb-399x355.jpg" alt="dbman4.jpg" class="mt-image-none" style="" height="355" width="399" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/dbman100.html" onclick="window.open('http://blog.spywareguide.com/images/dbman100.html','popup','width=625,height=516,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/dbman100-thumb-325x268.jpg" alt="dbman100.jpg" class="mt-image-none" style="" height="268" width="325" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />At this point, it's a given that I'm going to show you what happens if you install one of the files typically pushed from the above sites, right? Well, wait no longer - this....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman7.jpg" src="http://blog.spywareguide.com/images/dbman7.jpg" class="mt-image-none" style="" height="81" width="84" /></span></div><br /></div><div><br />...will deposit a rogue antispyware tool on your desktop (one of more more obnoxious ones that refuses to leave you alone):<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/antispycheck1.html" onclick="window.open('http://blog.spywareguide.com/images/antispycheck1.html','popup','width=877,height=668,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/antispycheck1-thumb-377x287.jpg" alt="antispycheck1.jpg" class="mt-image-none" style="" height="287" width="377" /></a></span><br /><br />Click to Enlarge<br /></div><br />Strange and annoying icons will start to creep across your desktop:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="dbman8.jpg" src="http://blog.spywareguide.com/images/dbman8.jpg" class="mt-image-none" style="" height="82" width="245" /></span></div><br /></div><div><br />....and you'll have more fake system alerts than you can shake a very large stick at:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="antispycheck22.jpg" src="http://blog.spywareguide.com/images/antispycheck22.jpg" class="mt-image-none" style="" height="304" width="273" /></span></div><br /><br />This concludes my public safety announcement. I'm off to see Dark Knight again...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 06:10:53 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/dark knight issue">dark knight issue</category>
      <category domain="http://www.securityratty.com/tag/dark knight">dark knight</category>
      <category domain="http://www.securityratty.com/tag/movie player">movie player</category>
      <category domain="http://www.securityratty.com/tag/click">click</category>
      <category domain="http://www.securityratty.com/tag/player">player</category>
      <category domain="http://www.securityratty.com/tag/enlarge">enlarge</category>
      <category domain="http://www.securityratty.com/tag/image">image</category>
      <category domain="http://www.securityratty.com/tag/copy image location">copy image location</category>
      <category domain="http://www.securityratty.com/tag/movie">movie</category>
      <source url="http://blog.spywareguide.com/2008/08/holy-media-codecs-batman.html">Holy Media Codecs, Batman!</source>
    </item>
    <item>
      <title><![CDATA[Myspace Cracker Steals Firefox Passwords]]></title>
      <link>http://www.securityratty.com/article/1a4072a96ea8dd94eda6fa2169ef914f</link>
      <guid>http://www.securityratty.com/article/1a4072a96ea8dd94eda6fa2169ef914f</guid>
      <description><![CDATA[A &quot;Myspace Cracking tool&quot; has recently come to light, though if you're considering attempting to crack some Myspace accounts with this





then you might want to think again, on account of it not...]]></description>
      <content:encoded><![CDATA[
        A "Myspace Cracking tool" has recently come to light, though if you're considering attempting to crack some Myspace accounts with this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mscrkff1.jpg" src="http://blog.spywareguide.com/images/mscrkff1.jpg" class="mt-image-none" style="" height="87" width="67" /></span></div><br /> <div><br />....then you might want to think again, on account of it not being quite what it seems. This "cracking tool" is only after one persons details: yours. Run it, and you'll see the following (somewhat bizarre) message, which should be your first clue that all is not quite right here:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mscrkff2.jpg" src="http://blog.spywareguide.com/images/mscrkff2.jpg" class="mt-image-none" style="" height="125" width="229" /><br />
  <br />
  <br />
</span></div>
At this point, your CD tray may well pop open - perhaps in tribute to the Trojans of old that did pretty much the same thing. At any rate, you're certainly not cracking any Myspace accounts, and after a faint grinding from your PC you're left to sit and stare at your desktop, wondering what went wrong. Here's a clue - have a poke around inside the EXE, and some lines of code will likely start to give the game away:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mscrkff3.jpg" src="http://blog.spywareguide.com/images/mscrkff3.jpg" class="mt-image-none" style="" height="44" width="308" /></span></div><br /><br />..."Firefox password grabber"? Oh dear.<br /><br />The observant end-user will notice a .txt file appears on their C Drive, and itcontains all the stored passwords saved via Firefox on their computer:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/mscrkff51.html" onclick="window.open('http://blog.spywareguide.com/images/mscrkff51.html','popup','width=563,height=282,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/mscrkff5-thumb-363x181.jpg" alt="mscrkff5.jpg" class="mt-image-none" style="" height="181" width="363" /></a></span><br /><br />Click to Enlarge<br /></div><br />As you can see, the bad guys here seem to be exploiting a well known password recovery tool for nefarious purposes - in this case, <a href="http://www.security-hacks.com/2007/05/01/firepassword-decrypt-firefox-password-manager">Firepassword</a>. You're probably wondering what happens with the stored login details at this point - well, do some more digging in the code and you'll see this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/stolen.html" onclick="window.open('http://blog.spywareguide.com/images/stolen.html','popup','width=574,height=377,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/stolen-thumb-374x245.jpg" alt="stolen.jpg" class="mt-image-none" style="" height="245" width="374" /></a></span><br /><br />Click to Enlarge<br /></div><br />The stolen Firefox passwords are sent to an FTP drop set up by the hacker, and every login you had stored in Firefox at that point is immediately at risk. Of course, if you're foolish enough to play around with hacking tools then there's a good chance you're going to get burned sooner or later...<br /><br />We detect this as <a href="http://www.spywareguide.com/spydet_32576_foxpass.html">FoxPass</a>.<br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 14:49:03 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/firefox">firefox</category>
      <category domain="http://www.securityratty.com/tag/firefox passwords">firefox passwords</category>
      <category domain="http://www.securityratty.com/tag/myspace">myspace</category>
      <category domain="http://www.securityratty.com/tag/tool">tool</category>
      <category domain="http://www.securityratty.com/tag/myspace accounts">myspace accounts</category>
      <category domain="http://www.securityratty.com/tag/firefox password grabber">firefox password grabber</category>
      <category domain="http://www.securityratty.com/tag/password recovery tool">password recovery tool</category>
      <category domain="http://www.securityratty.com/tag/ftp drop set">ftp drop set</category>
      <category domain="http://www.securityratty.com/tag/login details">login details</category>
      <source url="http://blog.spywareguide.com/2008/08/myspace-cracker-steals-firefox.html">Myspace Cracker Steals Firefox Passwords</source>
    </item>
    <item>
      <title><![CDATA[Zero-day Microsoft Windows NSlookup.exe Vulnerability Exploited In The Wild]]></title>
      <link>http://www.securityratty.com/article/611a4500bae5305083aff35d9565bcf9</link>
      <guid>http://www.securityratty.com/article/611a4500bae5305083aff35d9565bcf9</guid>
      <description><![CDATA[According to SecurityFocus, a new public zero-day Windows vulnerability is being exploited in the wild. Microsoft Windows is prone to a remote code-execution vulnerability due to an unspecified error...]]></description>
      <content:encoded><![CDATA[According to SecurityFocus, a new public zero-day Windows vulnerability is being exploited in the wild. Microsoft Windows is prone to a remote code-execution vulnerability due to an unspecified error in &#8216;NSlookup.exe&#8217;. Successfully exploiting this issue would allow the attacker to execute arbitrary code on an affected computer. Failed attacks will cause denial-of-service conditions. Microsoft Windows [...]]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 19:07:46 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/microsoft windows">microsoft windows</category>
      <category domain="http://www.securityratty.com/tag/execute arbitrary code">execute arbitrary code</category>
      <category domain="http://www.securityratty.com/tag/wild">wild</category>
      <category domain="http://www.securityratty.com/tag/nslookup">nslookup</category>
      <category domain="http://www.securityratty.com/tag/exe">exe</category>
      <category domain="http://www.securityratty.com/tag/attacks">attacks</category>
      <category domain="http://www.securityratty.com/tag/prone">prone</category>
      <category domain="http://www.securityratty.com/tag/issue">issue</category>
      <category domain="http://www.securityratty.com/tag/error">error</category>
      <source url="http://cyberinsecure.com/zero-day-microsoft-windows-nslookupexe-vulnerability-exploited-in-the-wild/">Zero-day Microsoft Windows NSlookup.exe Vulnerability Exploited In The Wild</source>
    </item>
    <item>
      <title><![CDATA[Massive Spam Campaign Spreads False CNN News Items With Fake Flash Player Malware]]></title>
      <link>http://www.securityratty.com/article/a225a716b4a000ec8b1b874643067ce6</link>
      <guid>http://www.securityratty.com/article/a225a716b4a000ec8b1b874643067ce6</guid>
      <description><![CDATA[Known social engineering tactic involving Adobe Flash Player is exploited in currently active malware campaign. Spammed user is encouraged to click on a site with a fake news item in order to install...]]></description>
      <content:encoded><![CDATA[Known social engineering tactic involving Adobe Flash Player is exploited in currently active malware campaign. Spammed user is encouraged to click on a site with a fake news item in order to install a fake Flash player update (file names might be flashupdate.exe, get_flash_update.exe, watchmovie.mpg.exe). If user clicks &#8220;Cancel&#8221; in the dialog that prompts for [...]]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 05:28:44 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/flash">flash</category>
      <category domain="http://www.securityratty.com/tag/fake flash player">fake flash player</category>
      <category domain="http://www.securityratty.com/tag/adobe flash player">adobe flash player</category>
      <category domain="http://www.securityratty.com/tag/user">user</category>
      <category domain="http://www.securityratty.com/tag/user clicks cancel">user clicks cancel</category>
      <category domain="http://www.securityratty.com/tag/fake news item">fake news item</category>
      <category domain="http://www.securityratty.com/tag/active malware campaign">active malware campaign</category>
      <category domain="http://www.securityratty.com/tag/exe">exe</category>
      <category domain="http://www.securityratty.com/tag/file names">file names</category>
      <source url="http://cyberinsecure.com/massive-spam-campaign-spreads-false-cnn-news-items-with-fake-flash-player-malware/">Massive Spam Campaign Spreads False CNN News Items With Fake Flash Player Malware</source>
    </item>
    <item>
      <title><![CDATA[MadMACs Ver. 1.2: Update to my MAC address and host name changer / randomizer / spoofer ]]></title>
      <link>http://www.securityratty.com/article/1e47dc41a51dfdc48802f357ad2656b6</link>
      <guid>http://www.securityratty.com/article/1e47dc41a51dfdc48802f357ad2656b6</guid>
      <description><![CDATA[Qwasty let me know that if host name randomization is used with MacMACs, and the host name is over 15 characters (or has certain bad illegal characters) it can cause all sorts of lsass.exe errors on...]]></description>
      <content:encoded><![CDATA[Qwasty let me know that if host name randomization is used with MacMACs, and the host name is over 15 characters (or has certain bad illegal characters) it can cause all sorts of lsass.exe errors on boot up. To fix this, I've updated the code to do some sanity checks on the possible hostnames given to it in dic.txt. Hopefully this fixes the problem. I also compiled it with the newer Autoit3 v3.2.12.1.
<p><a href="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?a=LwV14k"><img src="http://feeds.feedburner.com/~a/IrongeeksSecuritySite?i=LwV14k" border="0"></img></a></p><img src="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~4/358048581" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 20:13:25 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/characters">characters</category>
      <category domain="http://www.securityratty.com/tag/bad illegal characters">bad illegal characters</category>
      <category domain="http://www.securityratty.com/tag/host">host</category>
      <category domain="http://www.securityratty.com/tag/exe errors">exe errors</category>
      <category domain="http://www.securityratty.com/tag/sanity checks">sanity checks</category>
      <category domain="http://www.securityratty.com/tag/txt">txt</category>
      <category domain="http://www.securityratty.com/tag/hostnames">hostnames</category>
      <category domain="http://www.securityratty.com/tag/randomization">randomization</category>
      <category domain="http://www.securityratty.com/tag/macmacs">macmacs</category>
      <source url="http://feeds.feedburner.com/~r/IrongeeksSecuritySite/~3/358048581/i.php">MadMACs Ver. 1.2: Update to my MAC address and host name changer / randomizer / spoofer </source>
    </item>
    <item>
      <title><![CDATA[Compromised Web Servers Serving Fake Flash Players]]></title>
      <link>http://www.securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</link>
      <guid>http://www.securityratty.com/article/df22299b279b6326bc0fb82a62ea61b9</guid>
      <description><![CDATA[The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/SSFpGnP3wvA/s1600-h/fake_flash1.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SJiClCFucVI/AAAAAAAAB_0/qKqvrWeAN3s/s200-R/fake_flash1.png" style="border: 0pt none ;" /></a>The tactic of abusing web servers whose vulnerable web applications allow a malicious attacker to locally host a malicious campaign is nothing new. In fact, malicious attackers have been building so much confidence in this risk-forwarding process of hosting their campaigns, that they would start actively spamming the links residing within low-profile legitimate sites across the web.<br />
<br />
This campaign serving fake flash players is getting so prevalent these days due to the multiple spamming approaches used, that it's hard not to notice it - and expose it. From a strategic perspective, having a legitimate low-profile site -- of course with the obvious exceptions being on purposely registered for malicious purposes within the participating sites -- hosting your malicious campaign is pretty creative in terms of forwarding the responsibility, and the eventual blocking of a legitimate site to the its owner. As far as the owner's are concerned, it appears that some of them are already seeing the malware page popping-up on the top of their daily traffic stats, and have taken measures to remove it.<br />
<br />
Moreover, <a href="http://blogs.adobe.com/psirt/2008/08/verifying_installers.html">Adobe's Product Security Incident Response Team (PSIRT) issued a warning notice about the attack yesterday</a>, which could come handy if the <a href="http://www.infoworld.com/article/08/08/05/Adobe_warns_of_bogus_Flash_Player_installers_1.html">attackers weren't taking advantage of client-side vulnerabilities</a>, putting the unware end user is a situation where he <a href="http://blogs.stopbadware.org/articles/2008/08/05/same-dogs-new-tricks">wouldn't even receive a download dialog</a> :<br />
<br />
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/LuFjz3rFLAc/s1600-h/fake_flash3_exploit.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SJiP_0v81lI/AAAAAAAACAM/GXwA3Ai1LLY/s200-R/fake_flash3_exploit.jpg" style="border: 0pt none ;" /></a>"<i>We have seen coverage from the security community of a worm on popular social networking sites that is using social engineering lures to get users to install a piece of malware. According to the reports, the worm posts comments on these sites that include links to a fake site. If the link is followed, users are told they need to update their Flash Player. The installer, posted on a malicious site, of course installs malware instead of Flash Player.We’d like to take this opportunity to reiterate the importance of validating installers and updates before installing them. First off, do not download Flash Player from a site other than adobe.com – you can find the link for downloading Flash Player here. This goes for any piece of software (Reader, Windows Media Player, Quicktime, etc.) – if you get a notice to update, it’s not a bad idea to go directly to the site of the software vendor and download the update directly from the source. If the download is from an unfamiliar URL or an IP address, you should be suspicious.</i>"<br />
<br />
<a href="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/6PfKZxTNQao/s1600-h/fake_flash2.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SJiGkBrMqII/AAAAAAAAB_8/ADBheDs2hkk/s200-R/fake_flash2.png" style="border: 0pt none ;" /></a>The structure of the malware campaign is pretty static, with several exceptions where they also take advange of client-side vulnerabilities (Real player exploit) attempting to automatically deliver the fake flash update or player depending on the campaign. On each and every site, there are <b>dnd.js</b> and <b>master.js</b> scripts shich serve the rogue download window, and another .html file, where an IFRAME attempts to access the traffic management command and control, in a random URL it was <b>207.10.234.217/cgi-bin/index.cgi?user200</b>. A sample list of participating URLs, most of which are still active and running :<br />
<br />
<div style="text-align: left;"><b>joseantoniobaltanas .com</b></div><b>automoviliaria .es/hotnews.html<br />
risasnc .it/fresh.html<br />
carpe-diem .com.mx/fresh.html<br />
kotilogullari .com.tr/hotnews.html<br />
ferrariclubpesaro .it/hotnews.html<br />
imobiliariacom .com.br/default.html<br />
misoares .com<br />
osniehus .de/fresh.html<br />
mydirecttube .com/1/5098/<br />
madosma .com/default.html<br />
tutotic .com/checkit.html<br />
veit-team .si/default.html<br />
antigewaltkurse .de/stream.html<br />
kwhgs .ca/topnews.html<br />
vorgo .com/stream.html<br />
ankaraspor .com.tr/default.html<br />
xxxdnn0314 .locaweb.com.br/watchit.html<br />
ossuzio .com/watchit.html<br />
cit-inc .net/default.html<br />
negocioindependiente .biz/default.html<br />
ambermarketing .com/topnews.html<br />
web27 .login-7.loginserver.ch/stream.html<br />
moretewebdesign .br-web.com/stream.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/hotnews.html<br />
campodifiori .it/topnews.html<br />
212.50.55.81 /stream.html<br />
logisigns .net/fresh.html<br />
intimaescorts .com/default.html<br />
ghioautotre .it/live.html<br />
geckert .de/stream.html<br />
yuricardinali .com/watchit.html<br />
retder .com/fresh.html<br />
valdaran .es/default.html<br />
getadultaccess .com/movie/?aff=5274<br />
bauelemente-giering .de/stream.html<br />
newyork-hebergement .com/watchit.html<br />
allevatoritrotto .it/live.html<br />
exoss2 .com/hotnews.html<br />
soundandlightkaraoke .com/stream.html<br />
land-kan .com/stream.html<br />
grimaldi.nexenservices .com/watchit.html<br />
inconstancia .com.br/watchit.html <br />
gretelstudio .com/stream.html<br />
sumacyl .com/watchit.html<br />
mysna .net/fresh.html<br />
gimnasioyx .com.ar/watchit.html<br />
lagalbana .com/watchit.html<br />
bielizna.tgory .pl/topnews.html<br />
bcs92.imingo .net/stream.html<br />
lapiramidecoslada .es/topnews.html<br />
raulortega .com/stream.html<br />
go-art-morelli .de/hotnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
dianagraf .es/default.html<br />
komma10-thueringen .de/hotnews.html<br />
miavassilev .com/stream.html<br />
swampgiants .com/watchit.html<br />
compagniedephalsbourg .com/fresh.html<br />
arla-rc .net/hotnews.html<br />
salacopernico .es/watchit.html<br />
drfinster .de/checkit.html<br />
healthylifehypnotherapy .com/stream.html<br />
ecotrike-bg .com/fresh.html<br />
paoepalavra .org/watchit.html<br />
jureplaninc-sp .com/topnews.html<br />
fichte-lintfort .de/default.html<br />
hergert-band .de/checkit.html<br />
izliyorum .org/topnews.html<br />
lideka .com/stream.html<br />
athena-digitaldesign .com.tw/hotnews.html<br />
e-paso .pl/stream.html<br />
colombeblanche .org/stream.html<br />
teatromalasa .es/watchit.html<br />
mesporte.digiweb.com .br/stream.html<br />
bistrodavila.com .br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
jbhumet .com/default.html<br />
gruppouni .com/hotnews.html<br />
francex .net/fresh.html<br />
galvatoledo .com/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
kroenert .name/default.html<br />
textilhogarnovadecor .com/topnews.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
neticon .pl/hotnews.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
easterstreet .de/fresh.html<br />
piogiovannini .com.ar/watchit.html<br />
ser-all .com/topnews.html<br />
petzold-dieter .de/checkit.html<br />
beatmung-brandenburg .de/checkit.html<br />
ossuzio .com/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
zelenaratolest .cz/pornotube/index1.htm<br />
ambulatoriovirtuale .it/topnews.html<br />
10a3 .ru/index1.php<br />
izliyorum .org/topnews.html<br />
collectedthoughts .co.uk/index12.html<br />
afg .es/topnews.html<br />
albertruiz .net/topnews.html<br />
bielizna.tgory .pl/topnews.html<br />
blueseven.com .br/topnews.html<br />
bollettinogiuridicosanitario .it/topnews.html<br />
caprilchamonix.com .br/topnews.html<br />
carlolongarini .it/topnews.html<br />
champimousse .com/topnews.html<br />
cheviot.org .nz/topnews.html<br />
contrapie .com/topnews.html<br />
gruppouni .com/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
herbatele .com/topnews.html<br />
houseincostaricaforsale .com/topnews.html<br />
alim.co .il/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
amafe .org/topnews.html<br />
ambulatoriovirtuale .it/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
automoviliaria .es/topnews.html<br />
autoreserve .fr/topnews.html<br />
izliyorum .org/topnews.html<br />
jureplaninc-sp .com/topnews.html<br />
kwhgs .ca/topnews.html<br />
lapiramidecoslada .es/topnews.html<br />
last-minute-reisen-4u .de/topnews.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
corradiproject .info/topnews.html<br />
dantealighieriasturias .es/topnews.html<br />
deliriuslaspalmas .com/topnews.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/topnews.html<br />
fonavistas .com/topnews.html<br />
fraemma .com/topnews.html<br />
fundmyira .com/topnews.html<br />
galvatoledo .com/topnews.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
markmaverick .com/topnews.html<br />
micela .info/topnews.html<br />
motoclubnosvamos .com/topnews.html<br />
nebottorrella .com/topnews.html<br />
negozistore .it/topnews.html<br />
neticon .pl/topnews.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
segelclub-honau .de/topnews.html<br />
snmobilya .com/topnews.html<br />
splashcor .com.br/topnews.html<br />
stephanmager .gmxhome.de/topnews.html<br />
svcanvas .com/topnews.html<br />
tautau.web .simplesnet.pt/topnews.html<br />
textilhogarnovadecor .com/topnews.html<br />
theflorist4u .com/topnews.html<br />
thewindsorhotel .it/topnews.html<br />
vuelosultimahora .com/topnews.html<br />
aliarzani .de/topnews.html<br />
ambermarketing .com/topnews.html<br />
arnold82.gmxhome .de/topnews.html<br />
ocoartefatos.com .br/topnews.html<br />
omdconsulting .es/topnews.html<br />
parapendiolestreghe .it/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
projetsoft .net/topnews.html<br />
rbc.gmxhome .de/topnews.html<br />
beatmung-sachsen .eu/topnews.html<br />
campodifiori .it/topnews.html<br />
clickjava .net/topnews.html<br />
cmeedilizia .eu/topnews.html<br />
dammer .info/topnews.html<br />
embedded-silicon .de/topnews.html<br />
ferrariclubpesaro .it/topnews.html<br />
fgwiese .de/topnews.html<br />
fswash.site .br.com/topnews.html<br />
fytema .es/topnews.html<br />
gildas-saliou. com/topnews.html<br />
go-art-morelli .de/topnews.html<br />
go-siegmund .de/topnews.html<br />
guerrero-tuning .com/topnews.html<br />
gut-barbarastein .de/topnews.html<br />
japansec .com/topnews.html<br />
komma10-thueringen .de/topnews.html<br />
koon-design .de/topnews.html<br />
lanz-volldiesel .de/topnews.html<br />
lauscher-staat .de/topnews.html<br />
losnaranjos.com .es/topnews.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
nepi.si/topnews .html<br />
radieschenhein. de/topnews.html<br />
residenceflora .it/topnews.html<br />
sabuha .de/topnews.html<br />
ser-all .com/topnews.html<br />
siemieniewicz .de/topnews.html<br />
viajesk .es/topnews.html<br />
allevatoritrotto .it/live.html<br />
bollettinogiuridicosanitario .it/live.html<br />
carlolongarini .it/topnews.html<br />
maremax .it/topnews.html<br />
negozistore .it/topnews.html<br />
parapendiolestreghe .it/live.html<br />
www.donlisander .it/stream.html<br />
aerogenesis .net/watchit.html<br />
allevatoritrotto .it/live.html<br />
atelier-de-loulou .fr/topnews.html<br />
bistrodavila.com .br/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
caprilchamonix.com .br/topnews.html<br />
cheviot.org .nz/live.html<br />
condorautocenter .com.br/watchit.html<br />
dantealighieriasturias .es/live.html<br />
ecchoppers .co.za/topnews.html<br />
elianacaminada .net/live.html<br />
fonavistas .com/topnews.html<br />
fundmyira .com/topnews.html<br />
g6esporte .com.br/stream.html<br />
grafisch-ontwerpburo .nl/topnews.html<br />
gretelstudio .com/stream.html<br />
gutierrezymoralo .com/watchit.html<br />
healthylifehypnotherapy .com/stream.html<br />
herbatele .com/live.html<br />
jureplaninc-sp .com/topnews.html<br />
lacomercialsrl .com.ar/stream.html<br />
lagalbana .com/watchit.html<br />
lapuertaestrecha .com.es/watchit.html<br />
marcadina .fr/topnews.html<br />
maremax .it/topnews.html<br />
myadultcube .com/flash//aff=5176<br />
myadultcube .com/flash//aff=5810<br />
myadultcube .com/movie//aff=5155<br />
newyork-hebergement .com/watchit.html<br />
norbert-leifheit.gmxhome .de/topnews.html<br />
omdconsulting .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
parapendiolestreghe .it/live.html<br />
regesh. co.il/watchit.html<br />
rikkeroenneberg .dk/watchit.html<br />
s215847279 .onlinehome.fr/stream.html<br />
salacopernico .es/watchit.html<br />
seekzones .com/watchit.html<br />
seicomsl .es/watchit.html<br />
sigma-lux .ro/watchit.html<br />
soundandlightkaraoke .com/stream.html<br />
stephanmager.gmxhome .de/topnews.html<br />
tartuinstituut .ca/watchit.html<br />
teatromalasa .es/watchit.html<br />
vuelosultimahora .com/topnews.html<br />
wowhard.baewha .ac.kr/watchit.html<br />
aliarzani .de/topnews.html<br />
ambermarketing. com/live.html<br />
bilbondo .com/watchit.html<br />
bollettinogiuridicosanitario .it/live.html<br />
colombeblanche .org/stream.html<br />
donlisander .it/stream.html<br />
fgwiese .de/topnews.html<br />
geckert .de/stream.html<br />
helene-taucher .de/watchit.html<br />
lanz-volldiesel .de/topnews.html<br />
mairie-margnylescompiegne .fr/watchit.html<br />
medical-service-krause .de/topnews.html<br />
nakedinbed.co .uk/topnews.html<br />
ossuzio .com/watchit.html<br />
piogiovannini .com.ar/watchit.html<br />
sabuha .de/topnews.html<br />
sumacyl .com/watchit.html<br />
swampgiants .com/watchit.html<br />
xn--glland-3ya .de/stream.html<br />
yuricardinali .com/watchit.html</b><br />
<b>nepi .si/topnews.html<br />
dammer .info/topnews.html<br />
atelier-de-loulou .fr/topnews.html<br />
galvatoledo .com/topnews.html<br />
allevatoritrotto .it/topnews.html<br />
hausfeld-solar .de/topnews.html<br />
micela .info/topnews.html<br />
bistrodavila .com.br/watchit.html<br />
hausfeld-solar .de/topnews.html<br />
csr.imb .br/stream.html<br />
herion-architekten .de/default.html<br />
gruppouni .com/hotnews.html<br />
galvatoledo .com/topnews.html<br />
kroenert .name/default.html<br />
keithcrook .com/stream.html<br />
elpatiodejesusmaria .com/checkit.html<br />
malerbetrieb-pelzer .de/hotnews.html<br />
dantealighieriasturias .es/topnews.html<br />
oyakatakent46537 .com/stream.html<br />
89.19.29 .13/stream.html<br />
slobodandjakovic .com/fresh.html<br />
cqcs.com .br/stream.html<br />
seekzones .com/watchit.html<br />
pascosa .it/stream.html<br />
caprilchamonix .com.br/topnews.html<br />
positive-begegnungen .de/topnews.html<br />
ferien-urlaub-lastminute .de/default.html<br />
mueggelpark .info/watchit.html<br />
hillner-online .de/fresh.html<br />
guiasaojose .net/default.html<br />
deliriuslaspalmas .com/topnews.html<br />
fraemma .com/topnews.html<br />
morsbaby .net/default.html<br />
vickywhite .com/fresh.html<br />
micela .info/topnews.html<br />
corradiproject .info/topnews.html<br />
liguehavraise .com/live.html<br />
capacitacaoemlideranca .com.br/fresh.html<br />
materialesyacabados .com.mx/stream.html<br />
208.112.7.68 /checkit.html<br />
152.10.1.37 /1.html<br />
carlolongarini .it/topnews.html<br />
splashcor.com .br/topnews.html<br />
lobpreisstrasse .org/1.html<br />
motoclubnosvamos .com/hotnews.html<br />
hk-rc.com /1.html<br />
taaf.re /stream.html<br />
dulceysalao .com/default.html<br />
amafe .org/topnews.html <br />
</b><br />
<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/MTxnF1XLDCw/s1600-h/fake_flash3_rogue_software.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SJiNeb1AJDI/AAAAAAAACAE/3Dgh4x23dRs/s200-R/fake_flash3_rogue_software.png" style="border: 0pt none ;" /></a>Sample detection rate : <span id="status_nombre">flashupdate.exe</span><br />
<span id="status_nombre"><b>Scanners Result</b>: 35/36 (97.23%)</span><br />
<span id="status_nombre">Trojan-Downloader.Win32.Exchanger.hk; Troj/Cbeplay-A</span><br />
<b>File size</b>: 78848 bytes<br />
<b>MD5</b>...: c81b29a3662b6083e3590939b6793bb8<br />
<b>SHA1</b>..: d513275c276840cb528ce11dd228eae46a74b4b4<br />
<br />
The downloader then "phones back home" at <b>72.9.98.234 port 443 </b>which is responding to the rogue security software AntiSpy Spider (<b>antispyspider.net</b>) :<br />
<br />
"<i>AntiSpy Spider is a cutting-edge anti-spyware solution.This revolutionary anti-spyware program was created by the industry's top spyware experts in order to protect your computer and your privacy.html, while ensuring optimal system performance.With the ability to locate, eliminate and prevent the widest range of spyware threats, AntispyStorm is able to offer its users a safe, spyware-free computing experience; and with it's convenient automatic update feature, AntispyStorm ensures continuous up-to-date protection.</i>" <br />
<br />
Sample detection rate : antispyspider.msi<br />
<b>Scanners Result</b>: 11/35 (31.43%)<br />
FraudTool.Win32.AntiSpySpider.b;&nbsp; <br />
<b>File size</b>: 1851904 bytes<br />
<b>MD5</b>...: 2f1389e445f65e8a9c1a648b42a23827<br />
<b>SHA1</b>..: e32aa6aa791e98fe6fdef451bd3b8a45bad0acd8<br />
<br />
The bottom line - over a thousand domains are participating, with many other apparently joining the party proportionally with the web site owner's actions to get rid of the malware campaign hosted on their servers.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/underground-multitasking-in-action.html">Underground Multitasking in Action</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-celebrity-video-sites-serving.html">Fake Celebrity Video Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html">Blackhat SEO Redirects to Malware and Rogue Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-doorways-redirecting-to.html">Malicious Doorways Redirecting to Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BvcTqK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BvcTqK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=onawHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=onawHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4fa1ek"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4fa1ek" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5nQAgk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5nQAgk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sqdHIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sqdHIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mq3LKK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mq3LKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8zplkk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8zplkk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/356677080" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 05 Aug 2008 10:50:04 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/file">file</category>
      <category domain="http://www.securityratty.com/tag/html file">html file</category>
      <category domain="http://www.securityratty.com/tag/html">html</category>
      <category domain="http://www.securityratty.com/tag/comtopnews">comtopnews</category>
      <category domain="http://www.securityratty.com/tag/detopnews">detopnews</category>
      <category domain="http://www.securityratty.com/tag/windows media player">windows media player</category>
      <category domain="http://www.securityratty.com/tag/player">player</category>
      <category domain="http://www.securityratty.com/tag/web">web</category>
      <category domain="http://www.securityratty.com/tag/real player exploit">real player exploit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/356677080/compromised-web-servers-serving-fake.html">Compromised Web Servers Serving Fake Flash Players</source>
    </item>
    <item>
      <title><![CDATA[Smells Like a Copycat SQL Injection In the Wild]]></title>
      <link>http://www.securityratty.com/article/ae553b37ba0ec150b5a4c344ba27652b</link>
      <guid>http://www.securityratty.com/article/ae553b37ba0ec150b5a4c344ba27652b</guid>
      <description><![CDATA[In between the massive SQL injections , that as a matter of fact remain ongoing, copycats taking advantage of the very same SQL injection tools using public search engine's indexes as a reconnaissance...]]></description>
      <content:encoded><![CDATA[<a href="http://bp0.blogger.com/_wICHhTiQmrA/SI2ac7mO18I/AAAAAAAAB9c/usiNWVgrooU/s1600-h/chinese_sql_injection.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SI2ac7mO18I/AAAAAAAAB9c/97ckqqWaQ14/s200-R/chinese_sql_injection.JPG" style="border: 0pt none ;" /></a>In between the <a href="http://ddanchev.blogspot.com/2008/07/ayyildiz-turkish-hacking-group-vs.html">massive SQL injections</a>, that as a matter of fact remain ongoing, copycats taking advantage of the very same SQL injection tools using public search engine's indexes as a reconnaissance tools, are also starting to take advantage of <a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">localized and targeted attacks</a>, attacking specific online communities. Among these is <b>mx.content-type.cn /day.js </b>using <b>day.js</b> to attempt multiple exploitation using publicly obtainlable exploits such as Adodb.Stream, MPS.StormPlayer, DPClient.Vod, IERPCtl.IERPCtl.1, GLIEDown.IEDown.1, and targeting primarily Chinese web communities.<br />
<br />
Compared to a bit more sophisticated <a href="http://ddanchev.blogspot.com/2008/04/diy-exploit-embedding-tool-proprietary.html">attack tactics applied by Chinese hackers</a>, taking advantage of <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">localized versions</a> of the <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">de facto web malware exploitation kits</a>, those who don't have access to such continue using cybercrime 1.0 <a href="http://ddanchev.blogspot.com/2007/09/diy-exploits-embedding-tools.html">DIY exploit embedding tools</a> at large. The rest of the SQL injected domains as well as the exploits themselves are parked on the same plaee - <b>222.216.28.25</b>, also responding to :<br />
<br />
<b>down.goodnetads .org<br />
ads.goodnetads .org<br />
real.kav2008 .com<br />
hk.www404 .cn<br />
err.www404 .cn<br />
mx.content-type .cn<br />
sun.63afe561 .info<br />
ads.633f94d3 .info<br />
ads.1234214 .info<br />
ad.50db34d5 .info<br />
ads.50db34d5 .info<br />
ad.8d77b42a .info<br />
web.adsidc .info<br />
free.idcads .info<br />
free.cjads .info<br />
ads.adslooks .info<br />
list.adslooks .info<br />
ad.5iyy .info</b><br />
<br />
The SQL injected domains :<br />
<b>ads.633f94d3.info/day .js<br />
ad.8d77b42a.info/day .js<br />
ad.5iyy.info/day .js<br />
free.idcads.info/day .js<br />
efreesky.com/day .js<br />
v.freefl.info/day .js</b><br />
<br />
The internal structure :<br />
<b>free.idcads.info/f/index .htm<br />
free.idcads.info/014 .htm<br />
free.idcads.info/real11 .htm<br />
free.idcads.info/real10 .htm<br />
free.idcads.info/lz .htm<br />
free.idcads.info/bf .htm<br />
free.idcads.info/kong .htm<br />
free.idcads.info/f/swfobject .js<br />
ad.50db34d5.info//rm%5C/rm .exe</b><br />
<br />
Parked domains responding to the command and control locations, <b>60.191.223.76 </b>and <b>222.216.28.100</b> :<br />
<b>ftp.gggjjj .info<br />
live.ads002 .net<br />
log.goodnetads .org<br />
dat.goodnetads .org<br />
root.51113 .com<br />
sun.update999 .cn<br />
abb.633f94d3 .info<br />
up.50db34d5 .info</b><br />
<b>web.cn3721 .org&nbsp;&nbsp;&nbsp; <br />
dat.goodnetads .org<br />
cs.rm510 .com<br />
sb.sb941 .com<br />
k.sb941 .com<br />
info.sb941 .com<br />
day.sb941 .com<br />
post.ad9178 .com<br />
v.91tg .net</b><br />
<br />
Centralizing their scammy ecosystem always makes it easier to monitor, keep track of, and of course, expose. <br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html">SQL Injecting Malicious Doorways to Serve Malware </a><br />
<a href="http://ddanchev.blogspot.com/2008/05/yet-another-massive-sql-injection.html">Yet Another Massive SQL Injection Spotted in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/malware-domains-used-in-sql-injection.html">Malware Domains Used in the SQL Injection Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">SQL Injection Through Search Engines Reconnaissance</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/google-hacking-for-vulnerabilities.html">Google Hacking for Vulnerabilities</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><br />
<a href="http://blogs.zdnet.com/security/?p=1394">Sony PlayStation's site SQL injected, redirecting to rogue security software</a><br />
<a href="http://blogs.zdnet.com/security/?p=1118">Redmond Magazine Successfully SQL Injected by Chinese Hacktivists</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9XdgSJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9XdgSJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3nv7jJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3nv7jJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3DXSvj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3DXSvj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=exadYj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=exadYj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kp9u0J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kp9u0J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=y5pfDJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=y5pfDJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Lkbwwj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Lkbwwj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/348288922" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 01:51:23 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/sql">sql</category>
      <category domain="http://www.securityratty.com/tag/tools">tools</category>
      <category domain="http://www.securityratty.com/tag/sql injection tools">sql injection tools</category>
      <category domain="http://www.securityratty.com/tag/massive sql injections">massive sql injections</category>
      <category domain="http://www.securityratty.com/tag/attacks">attacks</category>
      <category domain="http://www.securityratty.com/tag/sql injection attacks">sql injection attacks</category>
      <category domain="http://www.securityratty.com/tag/sql injection">sql injection</category>
      <category domain="http://www.securityratty.com/tag/massive sql injection">massive sql injection</category>
      <category domain="http://www.securityratty.com/tag/site sql">site sql</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/348288922/smells-like-copycat-sql-injection-in.html">Smells Like a Copycat SQL Injection In the Wild</source>
    </item>
    <item>
      <title><![CDATA[Coding Spyware and Malware for Hire]]></title>
      <link>http://www.securityratty.com/article/1dbd4bddd9e4248009d0273ad7cae5dd</link>
      <guid>http://www.securityratty.com/article/1dbd4bddd9e4248009d0273ad7cae5dd</guid>
      <description><![CDATA[What type of antivirus evasion do you want today? For the past several years, we have been witnessing the emerging customerization applied in malware and spyware for hire services. What used to be a...]]></description>
      <content:encoded><![CDATA[<div class="separator" style="text-align: left; clear: both;"><a href="http://bp2.blogger.com/_wICHhTiQmrA/SIWJkocpGwI/AAAAAAAAB8U/_v3hJOM2k_s/s1600-h/preview_random.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SIWJkocpGwI/AAAAAAAAB8U/15Yc8N_lG74/s200-R/preview_random.jpg" style="border: 0pt none ;" /></a></div>What type of antivirus evasion do you want today? For the past several years, we have been witnessing the emerging customerization applied in malware and spyware for hire services. What used to be a situation where the malware authors would code and then start promoting a piece of malware including features that he thinks his potential customers would want by generalizing a cybercriminal's needs, is today's "listening to the customer" win-win situation that they've reached already. <br />
<br />
The whole maturity from a product concept to customerization is in fact so prevalent these days, that malware authors wanting to preserve their intellectual property are forbidding their customers from reverse engineering their malware modules, presumably fearing that <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">remotely exploitable flaws like this one in one of the most popular Ebanker malwares for the last two yers Zeus</a>, could be discovered due to the malware author's insecure coding practices. Moreover, limiting the distribution of a single license they are given to more than three people will result in the malware author ignoring any future business relationships with the party that ruined the exclusiveness of the malware, thereby leaking it to the public, something that's been happening and will continue happening with web malware exploitation kits.<br />
<br />
What would be the price of a custom malware module coded on demand? How much does it cost to have a built in email harvester that would sniff all the incoming and outgoing email addresses from the infected host to later on include them in upcoming spam and malware campaigns? Would the malware author also provide a managed hosting service for the command and control and the actual binaries on a revenue sharing <br />
<br />
Here's an automatically translated, and fairly easy to understand random proposition for coding spyware and malware for hire, aiming to answer many of these questions, clearly demonstrating that today's malware is coded in exactly the same way the customer wants it to : <br />
<br />
"<i>As you can see in the history of its development turned directly into the combine, while almost no raspuh in weight, full-size pack аж 18 kb and minialno 5 kb, for all nampomnyu again, all descriptions below can be done as otdelnym bot, and any combination of cross except for a few restrictions. This product is targeted at mass-user and will not be all prodavatsya row. So, you can choose from:</i><br />
<br />
<i>Actually loader - is able to load a file from adminki, by country and other characteristics, such as the number of animals on board with a specific bot, a country group of countries, the availability of certain authors or Fire, sredenemu time online, etc. etc.. You can adjust the speed of shipping limits for each file, can load 1 as well as how files simultaneously<br />
300 €</i><br />
<br />
<i><b>FTP and not only Graber</b><br />
Analyzes user traffic and collects from the ftp acclamation, that is ftp acclamation would you regardless of how the customer uses ftp user, thus can be obtained most valuable ftp aka (even those to which the password is not saved), you can also grab other in a way not only acclamation acclamation and other tasty things more)<br />
150 €<b>&nbsp;</b></i><br />
<br />
<i><b>Assembler spam bases</b><br />
Analyzes user traffic and collects from all email, snifit http pop3 smtp protocols, keeps records unikallnosti locally on each boat to reduce the burden on the server as well as globally on a server has 2 mode of operation - ie passive with only collects user to please and active - the very beginning to download the entire inet) in search of soap<br />
220 €<br />
<br />
<b>Socks 4 / 5</b><br />
Normal soks with competently implemented multithreading, is activated only if the user real Ip, otherwise not. And also optional, depending on the connection type and speed ineta.<br />
70 €<br />
<br />
<b>Indicates</b><br />
The primitive method, contamination fleshek avtoranom gives 2-3% increase in the first week and up to 7% in the next, a pleasant trifle)<br />
35 €<br />
<br />
<b>Scripts</b><br />
Loader supports internal scripting language - jscript, to carry out arbitrary actions on the victim machine, whether recording data in the register, setting authentic hon-Pago, opening URL in your browser (it was done so to please with 90% punching)), apload arbitrary files on a server, even theoretically possible to form and grabing inzhekty in IE) has only to write the script zaebetes, vobschem lyuboye actions soul who wish)<br />
70 € basic functionality<br />
<br />
<b>Assembler passwords</b><br />
Collects data such as passwords pstorage IE, MSN, etc., will be added at the request of other sources of passwords<br />
70 €<br />
<br />
<b>Mini-AV</b><br />
When installing loadera wheelbarrows to remove BHO shaped three, zevso-shaped, the majority of shit from all avtoranov, render most keylogerov until all) forward proposals to improve<br />
70 €<br />
<br />
<b>File-default</b><br />
In exe loadera program URL (in adminke) to the file which once progruzit 1 and run at first start loadera on wheelbarrows, while simultaneously helping progruzke Trojan for example, in its entire botnet that does not paired with challenges in adminke, the module operates in 20 seconds after the mini - av which excludes the removal of your Trojan bot, after progruza this exe bot continues to normal activities.<br />
35 €<br />
<br />
<b>Form Graber</b><br />
While in beta version, robbed IE. Sends logs in adminku, folding country. Logs are like logs agent. It consists of:<br />
<br />
<b>Graber certificats</b><br />
On the idea is part formgrabera but could work and of itself, actually there is nothing to describe)<br />
<br />
<b>Injections</b><br />
Literacy sold inzhekty, did not begin work after full progruza pages (as in bolshistve three) and immediately supported injection yavaskript code, which allows avtozalivy and DC inzhekty for data collection. For example not to yuzat acclamation at all is not yet introduce the necessary number of Britain, after which inzhekt ceases to operate. Вобщем mdelat can be anything and in any form) rather than the meager request field pin) And also inzhektov subspecies - a substitute for the issuance of search enginee.<br />
<br />
<b>Graber balances</b><br />
Makes loot aka balances at the entrance to the user acclamation, detail added to the logs.<br />
<br />
<b>Screen</b><br />
Universal method to grab information from absolutely any species and varieties klaiviatur screens, in particular html, flash, in one picture, with a drop-down fields after choosing your encrypted, as well as information such as "enter 3 yu secret letter word" etc. as well as any information which is visible a user but not seen in the logs. Screen settings of adminki, set URL where do screen as well as the type of screen: for virtual keyboard (done several small images of areas around the clique) or to "enter 3 yu secret letter words" (makes 1 full shot). With the withdrawal screen recorded in the log entry with the name of the file to the screen this position.<br />
<br />
<b>Antiabuznost for botneta</b><br />
Feachem adminki, keep botnet enables fast, normal, bezglyuchnyh NEabuzoustoychivyh hosting, with features that you forget what abuzy, nohistory week saporta "abuzoustoychivogo" hosting inaccessibility host to half ineta etc., etc., also with the help of the supplement will be able to keep huge botnety (over SL) at 1 dedike with 512 Lake) and well on the price of hosting a savings, not $ 500 a month and 150. It may use this feature to stroronnim development, Trojans, bots, etc., actually is a separate product. And incidentally, if you do not understand the theory that nenado ask "and how does it work?" imagine that it works and point and neubivaemo in pritsnipe.<br />
600 € +<br />
&nbsp;</i><br />
<i>All prices are in euros, the calculation is made at the rate of CB on the day of purchase. ps I will not disappear as most authors after months of sales, I DONT how to please you get to the assembly ftp, I DONT how many soap collects soap-graber, I DONT what otstuk from loadera, I DONT soksov how many will be from 1 to downloads, and how best To work load a file is not dead quickly, if you are confused my ignorance - that my loader so you do not need more tries)<br />
<br />
Rules / Licence<br />
-- Customer has no right to transfer any of his three 3 persons except options for harmonizing with me<br />
-- Customer does not have the right to make any decompile, research, malicious modification of any three parts<br />
-- Customer has no right where either rasprostanyat information about three and a public discussion with the exception of three entries.<br />
-- For violating the rules - without any license denial manibekov and further conversations</i>" <br />
<br />
This malware coder seems to be participating in an affiliate program with a malicious ISP that is offering hosting services for the entire campaign, not just the malware binaries, so you have a rather good example that incentives and revenue-sharing models result in value-added services, a all-in-one shop for a customer to take advantage of without bothering to approach a third-party.<br />
<br />
Cybercrime is getting even more easier to outsource these days, and with the malicious parties improving their communication and incentives model, the resulting transparency in the underground market<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/russias-fsb-vs-cybercrime.html">Russia's FSB vs Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">Localizing Open Source Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/quality-and-assurance-in-malware.html">Quality and Assurance in Malware Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2006/09/benchmarking-and-optimising-malware.html">Benchmarking and Optimising Malware</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CfEGOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CfEGOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZmZP2J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZmZP2J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3RDQbj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3RDQbj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uN1LUj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uN1LUj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oSzTOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oSzTOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KOIqZJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KOIqZJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8gh7xj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8gh7xj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/342366718" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 23:52:14 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/malware">malware</category>
      <category domain="http://www.securityratty.com/tag/malware author">malware author</category>
      <category domain="http://www.securityratty.com/tag/malware authors">malware authors</category>
      <category domain="http://www.securityratty.com/tag/malware binaries">malware binaries</category>
      <category domain="http://www.securityratty.com/tag/malware attacks">malware attacks</category>
      <category domain="http://www.securityratty.com/tag/ftp">ftp</category>
      <category domain="http://www.securityratty.com/tag/ftp user">ftp user</category>
      <category domain="http://www.securityratty.com/tag/collects">collects</category>
      <category domain="http://www.securityratty.com/tag/malware industry">malware industry</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/342366718/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire</source>
    </item>
    <item>
      <title><![CDATA[Impersonating StopBadware.org to Serve Fake Security Warnings]]></title>
      <link>http://www.securityratty.com/article/f4988806c23605425ad4d4182fb247ad</link>
      <guid>http://www.securityratty.com/article/f4988806c23605425ad4d4182fb247ad</guid>
      <description><![CDATA[Malware is known to have been hijacking search results, take for instance the rogue Antivirus XP 2008 as a recent example, but it's even more interesting to see other rogue security software...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://bp0.blogger.com/_wICHhTiQmrA/SIQdU9Lbl-I/AAAAAAAAB70/IzH5vWjVKfU/s1600-h/fake_security_warning_stopbadware.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIQdU9Lbl-I/AAAAAAAAB70/RZLeI1rUans/s200-R/fake_security_warning_stopbadware.png" style="border: 0pt none ;" /></a>Malware is known to have been hijacking search results, take for instance the <a href="http://sunbeltblog.blogspot.com/2008/06/hijacking-google.html">rogue Antivirus XP 2008</a> as a recent example, but it's even more interesting to see other rogue security software impersonating <a href="http://blogs.stopbadware.org/">Stopbadware.org</a> in order to server fake security warnings that ultimately lead to fake security software.<br />
<br />
<b>stopbadware2008 .com</b> (58.65.238.171) is one of these examples, where <b>stopbadware2008 .com/antivirus.php</b>&nbsp; redirects to <b>infectionscanner .com</b> and attempts to trick the user into installing <b>download.infectionscanner.com /AntvrsInstall.exe</b>.&nbsp; The message used :<br />
<br />
"<i>Reported Insecure Browsing: Navigation blocked. Due to insecure Internet browsing your PC can easily get infected with viruses, worms and trojans without your knowledge, and that can lead to system slowdown, freezes and crashes. Also insecure Internet activity can result in revealing your personal information. To get full advanced real-time protection for PC and Internet activity, register Antivirus 2008. We recommend you to protect your PC now and continue safe Internet browsing.</i>"<br />
<br />
<div class="separator" style="text-align: left; clear: both;"><a href="http://bp2.blogger.com/_wICHhTiQmrA/SIRDWN2opkI/AAAAAAAAB8E/ecjTOaYluzg/s1600-h/infectionscanner_rogue_software.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp2.blogger.com/_wICHhTiQmrA/SIRDWN2opkI/AAAAAAAAB8E/J_AhSquB1dc/s200-R/infectionscanner_rogue_software.png" style="border: 0pt none ;" /></a></div>There's in fact even more rogue software using the same IP (58.65.238.171), <a href="http://ddanchev.blogspot.com/2008/04/hacked-by-rbn.html">courtesy of HostFresh</a> :<br />
<b>virus-scanner-online .com<br />
security-scanner-online .com<br />
viruses-scanonline .com<br />
virus-scanonline .com<br />
antivirus-scanonline .com<br />
download.antivirus-scanonline .com<br />
topantivirus-scan .com<br />
topvirusscan .com<br />
virusbestscan .com<br />
virus-detection-scanner .com<br />
antivirus-scanner .com<br />
infectionscanner .com<br />
virusbestscanner .com<br />
internet-security-antivirus .com</b><br />
<br />
<a href="http://bp3.blogger.com/_wICHhTiQmrA/SIRGRxHueLI/AAAAAAAAB8M/CtKGYf0tD_w/s1600-h/antivirus_2008_rogue.gif" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SIRGRxHueLI/AAAAAAAAB8M/dBOe983G3Ns/s200-R/antivirus_2008_rogue.gif" style="border: 0pt none ;" /></a>It would be interested to monitor whether or not the template for the fake security warning would start getting used on a large scale.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">A Portfolio of Fake Video Codecs</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got Your XPShield up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's Fake Security Software</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=g017OJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=g017OJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2qqOkJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2qqOkJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RWcCDj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RWcCDj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HjGT2j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HjGT2j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3DP0KJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3DP0KJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bLRVbJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bLRVbJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RDkUqj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RDkUqj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/341345275" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 20 Jul 2008 23:30:51 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/fake security">fake security</category>
      <category domain="http://www.securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://www.securityratty.com/tag/insecure internet activity">insecure internet activity</category>
      <category domain="http://www.securityratty.com/tag/internet activity">internet activity</category>
      <category domain="http://www.securityratty.com/tag/insecure internet">insecure internet</category>
      <category domain="http://www.securityratty.com/tag/insecure">insecure</category>
      <category domain="http://www.securityratty.com/tag/lead">lead</category>
      <category domain="http://www.securityratty.com/tag/fake video codecs">fake video codecs</category>
      <category domain="http://www.securityratty.com/tag/portfolio">portfolio</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/341345275/impersonating-stopbadwareorg-to-serve.html">Impersonating StopBadware.org to Serve Fake Security Warnings</source>
    </item>
    <item>
      <title><![CDATA[Malware and Office Documents Joining Forces]]></title>
      <link>http://www.securityratty.com/article/dee3d028ca8134c75e2aec7f397d1493</link>
      <guid>http://www.securityratty.com/article/dee3d028ca8134c75e2aec7f397d1493</guid>
      <description><![CDATA[Common office files as documents, presentations, spreadsheets and PDF files, are the most widely abused ones in targeted attacks, which when backed up with enough personal information and take into...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHtuv_mJSwI/AAAAAAAAB6M/X83g6Zkr9hg/s1600-h/screen1.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHtuv_mJSwI/AAAAAAAAB6M/b0YAu_NWEQk/s200-R/screen1.jpg" style="border: 0pt none ;" /></a>Common office files as documents, presentations, spreadsheets and PDF files, are the most widely abused ones in targeted attacks, which when backed up with enough personal information and take into consideration the time of their attack if the social engineering campaign is either going to be based on a current/upcoming event, or on an event anticipated due to information gathered through open source intelligence, often make it through common signature based scanning solutions.<br />
<br />
Despite the relatively easy to obtain, point'n'click <a href="http://www.f-secure.com/weblog/archives/00001450.html">DIY tools for backdooring common office files</a> are available for the script kiddies to take advantage of, some are <a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">naturally remaining proprietary tools</a>, making them harder to analyze unless a copy is obtained. Like this one, generating "undetected" by signatures based scanning, office documents and spreadsheets that would drop the actual malware on the PC.<br />
<br />
Automatic translation of its description and core features :<br />
<br />
<i>"The program represents a generator OfficeJoiner macros in the language Visual Basic for Application (VBA), for introduction in the document Microsoft Office Word / Microsoft Office Excel executable file (win32 exe), followed by fully automatic recovery and launch, without any&nbsp; additional action by the user. The only requirement that formed in such a way xls / doc files is to support&nbsp; VBA macros on the computer end-user formed file and permission to launch macros.</i><br />
<br />
<i>The program uses NOT a vulnerability (exploit) or macro-virus tools for the introduction, extraction or running embedded files. This means that it has generated macros compatible with ALL versions of Microsoft Office products starting with Microsoft Office 97 package, with any established "patches" and the service pack. Macros generated by this program not detected antivirus, for the simple reason that they are not viruses or macro viruses. The program uses only "established" means products built into Microsoft Excel VBA language to achieve their goals.</i><br />
<br />
<i>- Fully automatic generation of macro for the introduction of documents word / excel any given exe-file with his persistence in the body and subsequent documents automatic recovery and launch, when opening a document word / excel.&nbsp;</i><br />
<br />
<i>- Generated macros are compatible with all versions of ms word / excel since version 97,&nbsp; employments and regardless of the presence / absence of any patches / servicepacs.&nbsp;</i><br />
<br />
<i>- Generated macros are not macro-viruses, exploits do not use and do not contain any malicious code, so do not be detected by any antivirus tools as viruses.&nbsp;</i><br />
<br />
<i>- Conversion body ex-file macro happening in such a way that while in doc / xls file it not detected any antivirus, and can be freely sent by mail safely passed all checks, even if in itself contains viral code defined antivirus. <br />
&nbsp;</i><br />
<i>- Sgenerirovanny and attached to the body of the document macro can be protected with a password or signed certificate, using funds established Microsoft Office, which does not affect him productivity or efficiency (macro, in any case remain fully workable).&nbsp;</i><br />
<br />
<i>- Box macro can be made both in the new document, and in any document containing data and-or other macros. Generated program code is fully compatible with any other embedded in the document macros or entering data, and will not interfere with their work, as well as maintain its efficiency.</i><br />
<br />
<div dir="ltr" id="result_box"><i>- Added auto-finding ways to extract exe-file; <br />
&nbsp;</i></div>
<div dir="ltr" id="result_box"><i>- Added possibility of a macro arbitrary text in the body of the instrument; <br />
&nbsp;</i></div>
<div dir="ltr" id="result_box"><i>- Optimized algorithm macro-generation code; <br />
</i></div>
<div dir="ltr" id="result_box"><i>&nbsp;</i> </div>
<div dir="ltr" id="result_box"></div>
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<div dir="ltr" id="result_box"><a href="http://bp1.blogger.com/_wICHhTiQmrA/SHt7EgPiRwI/AAAAAAAAB6U/BtNJaK_13LM/s1600-h/officedocs_malware_sample.PNG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHt7EgPiRwI/AAAAAAAAB6U/xhaiKacT-eM/s200-R/officedocs_malware_sample.PNG" style="border: 0pt none ;" /></a><i>Enabling this option will lead to the creation macro code, who himself will find a way to unpack and run embedded exe-file. Auto-search finds the current user folder and produces there extraction and launch embedded file. The peculiarity of this method is that this method will work on the computers of users with a limited account, because in its user folder in any case has the right to record / performance. Using this option is justified to improve the "punching" macro on computers with limited account or unknown file structure (let Windows installed on the disk is different from C). <br />
<br />
You can specify a name for final file independently, or leave blank, then the name will be generated automatically.</i> </div>
<div dir="ltr" id="result_box"><i><br />
</i></div>
<div dir="ltr" id="result_box"><i>On this possibility has asked for a user program, its essence is that after running a macro, retrieval and downloading exe-file the document with the introduction of exe-file will be withdrawn posed text. Perhaps in this way can improve the application of social engineering, designed to force the user to allow support for macros. For example, in the text of the document indicate: <br />
<br />
"This document contains hidden text (password, a system of calculation formulas, interactive components, etc.), Which can be viewed only after the inclusion of support macros. Please enable support for macros and re-opening this document ". <br />
<br />
After resolving support macros, and the implementation of embedded exe-file, the document will be withdrawn given a string containing probable "password" or any other textual information.</i>  " </div>
<br />
Despite that the tool is proprietary, the underground economy's leaks are largely driven by bargain hunters who would exchange proprietary tool, whose often biased exclusiveness may increase the profit margins, for a service or a good that may be worthless for them in general, but impossible to obtain and take advantage of in the present. It will not just leak in one way or another, someone will inevitably backdoor the backdooring tool and trick the novice bargain hunters into running it, by having both their host infected and money taken.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/yet-another-diy-proprietary-malware.html">Yet Another DIY Proprietary Malware Builder</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The Small Pack Web Malware Exploitation Kit - Proprietary</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/diy-exploit-embedding-tool-proprietary.html">DIY Exploit Embedding Tool - A Proprietary Release</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/skype-spamming-tool-in-wild.html">Skype Spamming Tool in the Wild - Proprietary Release</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mMDIJJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mMDIJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vtGZUJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vtGZUJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Voeqqj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Voeqqj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QZJLHj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QZJLHj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4VmcIJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4VmcIJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rqLHKJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rqLHKJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LnaC8j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LnaC8j" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/335226251" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 07:20:34 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/document">document</category>
      <category domain="http://www.securityratty.com/tag/document macros">document macros</category>
      <category domain="http://www.securityratty.com/tag/support">support</category>
      <category domain="http://www.securityratty.com/tag/enable support">enable support</category>
      <category domain="http://www.securityratty.com/tag/macro">macro</category>
      <category domain="http://www.securityratty.com/tag/macro viruses">macro viruses</category>
      <category domain="http://www.securityratty.com/tag/support vba macros">support vba macros</category>
      <category domain="http://www.securityratty.com/tag/exe-file">exe-file</category>
      <category domain="http://www.securityratty.com/tag/extract exe-file">extract exe-file</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/335226251/malware-and-office-documents-joining.html">Malware and Office Documents Joining Forces</source>
    </item>
  </channel>
</rss>
