<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Evil Fingers - The Blog</title>
	<atom:link href="http://ef.kaffenews.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://ef.kaffenews.com</link>
	<description>Security @ its best...</description>
	<lastBuildDate>Thu, 27 May 2010 14:04:22 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>State of the art in CRiMEPACK Exploit Pack</title>
		<link>http://ef.kaffenews.com/?p=1315</link>
		<comments>http://ef.kaffenews.com/?p=1315#comments</comments>
		<pubDate>Thu, 27 May 2010 14:04:22 +0000</pubDate>
		<dc:creator>Jorge Mieres</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Jorge Mieres]]></category>
		<category><![CDATA[MalwareIntelligence]]></category>

		<guid isPermaLink="false">http://ef.kaffenews.com/?p=1315</guid>
		<description><![CDATA[
CRiMEPACK exploit pack is a  widespread and accepted in the crime scene in this area came under the  slogan &#8220;Highest Lowest rates for the price&#8220;.
He is currently In-the-Wild 3.0 version is being developed as alpha (the  first of this version). That&#8217;s, is in the middle stage of evaluation,  perhaps in the ]]></description>
			<content:encoded><![CDATA[<div>
<p><strong>CRiMEPACK</strong> exploit pack is a  widespread and accepted in the crime scene in this area came under the  slogan &#8220;<em>Highest Lowest rates for the price</em>&#8220;.</p>
<p>He is currently In-the-Wild 3.0 version is being developed as alpha (the  first of this version). That&#8217;s, is in the middle stage of evaluation,  perhaps in the next few days will go on sale in underground forums, at  which time it will know your actual cost.</p>
</div>
<p style="text-align: center"><img src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S_PpDL6GGGI/AAAAAAAAAKE/QnpEw_nvPXM/s320/MI-crimepack.png" border="0" alt="" /></p>
<div>
<p>Like any pack  exploit, it also consists of a set of pre-compiled exploits to take  advantage of a number of vulnerabilities in systems with weaknesses in  some of its applications, then download and run (<em>Drive-by-Download  &amp; Execute</em>) codes malicious and convert that system into a  zombie, and therefore part of the apparatus crime.</p>
<p>And I mean &#8230; &#8220;criminal&#8221; because those behind the development of this  type of crimeware do for this purpose. And judging by the pictures (a  washcloth, a handgun, a wallet, money and what appears to be cocaine,  own scenario of all mafia) observed in the authentication interface your  control panel, this definition is very evident.</p>
<p>The first time <a href="http://www.malwareint.com/docs/MalwareInt-anual-2009.pdf">I found  this package was in 2009</a>, when version In-the-Wild was version 2.1  and later expressed his &#8220;great leap&#8221; to one of the most popular: version  2.8 (still active) which in early 2010 had incorporated into its  portfolio of exploits <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0188">CVE-2010-0188</a> y <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0806">CVE-2010-0806</a>; in addition to adding an <a href="http://malwareint.blogspot.com/2009/11/t-iframer-kit-for-injection-of-malware.html">iframe generator</a> and function &#8220;<em>Kaspersky  Anti-emulation</em>&#8220;, at a cost of <strong>USD 400</strong>.</p>
<p>In this first stage of the evaluation version 3, <strong>CRiMEPACK</strong> incorporates a total of 14 exploits, which are:</p>
</div>
<ul>
<li>name=&#8221;mdac&#8221;</li>
<p>desc=&#8221;IE6 COM CreateObject Code Execution&#8221; <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0003">CVE-2006-0003</a></p>
<li>name=&#8221;msiemc&#8221;</li>
<p>desc=&#8221;IE7 Uninitialized Memory Corruption&#8221; <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0806">CVE-2010-0806</a></p>
<li>name=&#8221;java&#8221;</li>
<p>desc=&#8221;JRE getSoundBank Stack BOF&#8221; <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3867">CVE-2009-3867</a></p>
<li>name=&#8221;iepeers&#8221;</li>
<p>desc=&#8221;IEPeers Remote Code Execution&#8221; <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0806">CVE-2010-0806</a></p>
<li>name=&#8221;pdfexpl&#8221;</li>
<p>desc=&#8221;PDF Exploits [collectEmailInfo (<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5659">CVE-2007-5659</a>), getIcon (<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0927">CVE-2009-0927</a>), util.printf (<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-2992">CVE-2008-2992</a>)]&#8221;</p>
<li>name=&#8221;opera&#8221;</li>
<p>desc=&#8221;Opera TN3270&#8243; <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3269">CVE-2009-3269</a></p>
<li>name=&#8221;aol&#8221;</li>
<p>desc=&#8221;AOL Radio AmpX Buffer Overflow&#8221; <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5755">CVE-2007-5755</a></p>
<li>name=&#8221;iexml&#8221;</li>
<p>desc=&#8221;Internet Explorer 7 XML Exploit&#8221; <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4844">CVE-2008-4844</a></p>
<li>name=&#8221;firefoxdiffer&#8221;</li>
<p>desc=&#8221;Firefox 3.5/1.4/1.5 exploits&#8221; <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-355">CVE-2009-355</a></p>
<li>name=&#8221;libtiff&#8221;</li>
<p>desc=&#8221;Adobe Acrobat LibTIFF Integer Overflow&#8221; <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0188">CVE-2010-0188</a></p>
<li>name=&#8221;spreadsheet&#8221;</li>
<p>desc=&#8221;OWC Spreadsheet Memory Corruption&#8221; <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1136">CVE-2009-1136</a></p>
<li>name=&#8221;activexbundle&#8221;</li>
<p>desc=&#8221;Bundle of ActiveX exploits&#8221; <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2463">CVE-2008-2463</a></ul>
<div>
<p>For all the exploits incorporates a  feature that can be enabled or disabled from the control panel called &#8220;<strong>Aggressive  Mode</strong>&#8220;, which is a JAVA Applet that emerge through a <em>pop-up</em> window asking the victim whether to accept potential the applet. If so,  reload the payload (the malware).</p>
<p>Furthermore, within the constantly evolving experience this type of  crimeware, incorporates self-defensive measures such as avoiding  desofuscación scripts and techniques anti <strong>Wepawet</strong> and <strong>Jsunpack</strong>.</p>
</div>
<p style="text-align: center"><img src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S_Pp1YQib8I/AAAAAAAAAKM/X24EkNAp14Q/s320/MI-anti.png" border="0" alt="" /></p>
<p>In addition to automatically check if the domain  used is listed in the services:</p>
<ul>
<li>Norton SafeWeb</li>
<li>My WebOfTrust</li>
<li>Malc0de</li>
<li>Google Safe Browsing</li>
<li>MDL</li>
<li>McAfee SiteAdvisor</li>
<li>HpHosts</li>
<li>MalwareURL</li>
</ul>
<p style="text-align: center"><img src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S_PqDHufdkI/AAAAAAAAAKU/2Oq6SfzdgRY/s320/MI-blcheck.jpg" border="0" alt="" /></p>
<div>
<p><strong>Brian Kreb</strong> few days ago on his blog <a href="http://krebsonsecurity.com/2010/04/unpatched-java-exploit-spotted-in-the-wild/">an article about the implication that this package</a> was in the process of propagation and exploitation of a vulnerability,  so far, the <a href="http://seclists.org/fulldisclosure/2010/Apr/119">type 0-Day through JAVA</a>, and certainly was  exploited vulnerability through a class.</p>
<p>However, it was also associated with another exploit pack called <strong>SEO  Sploit Pack </strong>and although it is not the same once more evidence is in  complete business processes representing crimeware has a very high  demand, offering low-applications costs within a competitive business  model &#8230; and increasingly aggressive!</p>
</div>
<p><strong>Related information</strong><br />
<a href="http://malwareint.blogspot.com/2010/01/state-of-art-in-eleonore-exploit-pack.html">State of the art in Eleonore Exploit Pack</a><br />
<a href="http://malwareint.blogspot.com/2009/12/siberia-exploit-pack-another-package-of.html">Siberia  Exploit Pack. Another package  of explois I&#8230;</a><br />
<a href="http://malwareint.blogspot.com/2009/12/russkill-application-to-perform-denial.html">RussKill.  Application to perform  denial of service&#8230;</a><br />
<a href="http://malwareint.blogspot.com/2009/11/justexploit-new-exploit-kit-that-uses.html">JustExploit.  New Exploit kit that  uses vulnerabili&#8230;</a><br />
<a href="http://malwareint.blogspot.com/2009/11/ddos-botnet-new-crimeware-particular.html">DDoS  Botnet. New crimeware particular  purpose</a><br />
<a href="http://malwareint.blogspot.com/2009/11/t-iframer-kit-for-injection-of-malware.html">T-IFRAMER.  Kit for the injection of  malware In-the&#8230;</a><br />
<a href="http://malwareint.blogspot.com/2009/08/fragus-new-botnet-framework-in-wild.html">Fragus.  New botnet framework  In-the-Wild</a><br />
<a href="http://malwareint.blogspot.com/2009/08/liberty-exploit-system-alternatively.html">Liberty  Exploit System. Alternatively  crimeware to&#8230;</a><br />
<a href="http://malwareint.blogspot.com/2009/08/triad-botnet-iii-remote-administration.html">TRiAD  Botnet III. Remote  administration of multi-p&#8230;</a></p>
<p><a href="http://malwareint.blogspot.com">MalwareIntelligence</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ef.kaffenews.com/?feed=rss2&amp;p=1315</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BlackHat SEO Campaign for the thirtieth anniversary of PAC-MAN</title>
		<link>http://ef.kaffenews.com/?p=1311</link>
		<comments>http://ef.kaffenews.com/?p=1311#comments</comments>
		<pubDate>Mon, 24 May 2010 21:01:59 +0000</pubDate>
		<dc:creator>Jorge Mieres</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[MalwareIntelligence]]></category>

		<guid isPermaLink="false">http://ef.kaffenews.com/?p=1311</guid>
		<description><![CDATA[
Recently, the legendary video game  PAC-MAN has completed 30 years of existence and Google has launched a  campaign in his honor by placing a banner that allows even play.
However, Google not only benefits from this but also cyber-criminals,  who saw in this campaign a new opportunity to attack and have launched  ]]></description>
			<content:encoded><![CDATA[<div>
<p>Recently, the legendary video game  PAC-MAN has completed 30 years of existence and Google has launched a  campaign in his honor by placing a banner that allows even play.</p>
<p>However, Google not only benefits from this but also cyber-criminals,  who saw in this campaign a new opportunity to attack and have launched  another campaign, but the spread of malware through B<strong>lackHat SEO</strong> (also called <strong>SEO Poisoning</strong>).</p>
</div>
<div><a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/S_qb1n9f9yI/AAAAAAAAAKc/ndv81YChe_A/s1600/MI_bhseo-pac-man.png"></a></div>
<p style="text-align: center"><img src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/S_qb1n9f9yI/AAAAAAAAAKc/ndv81YChe_A/s400/MI_bhseo-pac-man.png" border="0" alt="" width="385" height="400" /></p>
<p>Some other search parameters may include:</p>
<p>pac man 30th anniversary game<br />
pac man 30th anniversary games<br />
pac man 30th anniversary google<br />
pac man 30th anniversary high score<br />
pac man 30th anniversary play<br />
pacman free online 3d<br />
pacman free online addicting games<br />
pacman free online download<br />
pacman free online game for kids<br />
pacman free online game<br />
pacman free online no sound<br />
pacman free online play<br />
pacman free online with no sound<br />
pacman game download<br />
pacman game flash<br />
pacman game for kids<br />
pacman game for wii<br />
pacman game free download<br />
pacman game full screen</p>
<p>Traffic redirected to the download of scareware. In this case, a binary  md5 4c9ac21a2730a5e6d8c8018afb517d5e  which has a very low detection rate: <a href="http://www.virustotal.com/analisis/2977592967540ea17c5e85084f9d177f2e530a4932c684e7f6f876c21ec241e2-1274704363">6/41 (14.63%)</a>.</p>
<div><a href="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S_qcCiP6T5I/AAAAAAAAAKk/QwdcvAECz04/s1600/MI_scareware-av.png"><img src="http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S_qcCiP6T5I/AAAAAAAAAKk/QwdcvAECz04/s640/MI_scareware-av.png" border="0" alt="" width="640" height="308" /></a></div>
<p>Among the domains that involves the campaign are:</p>
<p>accu-riteaccounting.com<br />
africanbynature.com<br />
allisonleach.com<br />
bobsclamhut.com<br />
carolfleming.org<br />
carolinasystemsinc.com<br />
d3-store.com<br />
delta-electronic.com<br />
diningbythesea.com<br />
drakeleisure.co.nz<br />
fastripsnackatak.com<br />
fbgartschool.com<br />
gas-consult.com<br />
generationbass.com<br />
gjsdesigns.com<br />
goedkopepc.net<br />
hkiarchitects.com<br />
houndshaveninc.com<br />
hst1066.com<br />
itech-on.pt<br />
jaszmetal.hu<br />
larsonguitar.com<br />
nsc.eypgreece.org<br />
okidouki.com<br />
olivermurr.com<br />
oneaccordclass.org<br />
partrade.net<br />
redhanded.ca<br />
red-partner.com<br />
regionalportauthorityofnwo.org<br />
reillocile.com<br />
reillychiro.com<br />
reynared.com<br />
roseguggenheimer.com<br />
ruders.com<br />
rufiocreative.com<br />
runawaysnail.com<br />
ryangruhn.com<br />
ryanroghaar.com<br />
sacredhaven.com<br />
saevar.com<br />
scxdigitalslots.com<br />
seastromlaw.com<br />
shop.infytel.com<br />
sor-d2.com<br />
s-teamexpert.com<br />
tcgpage.com<br />
tuneoutdropin.com<br />
turtlesplayground.com<br />
william-heise.com</p>
<div>To achieve massify the campaign and  get a good PageRank in Google, criminals violated a server hosted on a  list of web pages with the titles which make up words that are the  subject of regular search. These files are located in a hidden folder,  often called the &#8220;<em>.files</em>&#8220;</div>
<div></div>
<div><a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S_qcIuD0PNI/AAAAAAAAAKs/y-O0A8EPf3c/s1600/MI-files.png"><img src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S_qcIuD0PNI/AAAAAAAAAKs/y-O0A8EPf3c/s640/MI-files.png" border="0" alt="" width="640" height="280" /></a></div>
<div></div>
<div>Under this scenario, taking into  account that these strategies are widely used for the propagation of  malware, a good practice is to verify at the root of posting the  existence of hidden folders.</div>
<p><strong>Related information</strong><br />
<a href="http://mipistus.blogspot.com/2009/05/estrategia-black-hat-seo-propuesta-por.html">Estrategia BlackHat SEO propuesta por Waledac</a><br />
<a href="http://malwareint.blogspot.com/2009/07/malware-propagation-through-blogging.html">Malware propagation through blogging sites format  and BlackHat SEO</a><br />
<a href="http://mipistus.blogspot.com/2009/05/campana-de-propagacion-del-scareware.html">Campaña de propagación del scareware  MalwareRemovalBot</a></p>
<p><a href="http://malwareint.blogspot.com">MalwareIntelligence</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ef.kaffenews.com/?feed=rss2&amp;p=1311</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Announcement: New Media Partner &#8211; CONFidence</title>
		<link>http://ef.kaffenews.com/?p=1309</link>
		<comments>http://ef.kaffenews.com/?p=1309#comments</comments>
		<pubDate>Sun, 25 Apr 2010 23:06:33 +0000</pubDate>
		<dc:creator>BigBrother</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://ef.kaffenews.com/?p=1309</guid>
		<description><![CDATA[We are happy to announce our partnership with CONFidence, one of the leading conferences in the InfoSec community. They are conducting their 7th Conference next month. Check it out at: http://2010.confidence.org.pl/
We encourage all our users to attend CONFidence, and if you do please do contact us to receive 10% discount on the conference registration.
Read more ]]></description>
			<content:encoded><![CDATA[<p>We are happy to announce our partnership with CONFidence, one of the leading conferences in the InfoSec community. They are conducting their 7th Conference next month. Check it out at: <a href="http://2010.confidence.org.pl/">http://2010.confidence.org.pl/</a></p>
<p>We encourage all our users to attend CONFidence, and if you do<strong> please do contact us to receive 10% discount on the conference registration</strong>.</p>
<p>Read more about our Media partnership with CONFidence at <a href="https://www.evilfingers.com/about/Publicity.php">https://www.evilfingers.com/about/Publicity.php</a></p>
<p>Thank you for supporting InfoSec Community!</p>
]]></content:encoded>
			<wfw:commentRss>http://ef.kaffenews.com/?feed=rss2&amp;p=1309</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SPAM looks so real</title>
		<link>http://ef.kaffenews.com/?p=1306</link>
		<comments>http://ef.kaffenews.com/?p=1306#comments</comments>
		<pubDate>Wed, 17 Mar 2010 15:44:01 +0000</pubDate>
		<dc:creator>BigBrother</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://ef.kaffenews.com/?p=1306</guid>
		<description><![CDATA[Just received an email for Wordpress blog of a comment to our Botnet Analytics Blog post, that looks so real:


&#60;for security reasons, the header info has been truncated&#62;
To: contact.fingers@gmail.com
Subject: [Botnet Analytics Blog] Please moderate: &#8220;Commercializing Botnets&#8221;
X-PHP-Script: botnet.kaffenews.com/wp-comments-post.php for xxxxxxx
Date: Wed, 17 Mar 2010 10:01:00 -0400
From: xxxxxx&#60;xxxxxxx@botnet.kaffenews.com&#62;
Message-ID: &#60;62e98c7537ee322c81e19df5ca2d12bd@botnet.kaffenews.com&#62;
X-Priority: 3
X-Mailer: xxxxxx (xxxxxxxxxxxxxxxxx) [version xxxxx]
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; ]]></description>
			<content:encoded><![CDATA[<p>Just received an email for Wordpress blog of a comment to our Botnet Analytics Blog post, that looks so real:<br />
<strong><br />
</strong></p>
<blockquote><p>&lt;for security reasons, the header info has been truncated&gt;</p>
<p>To: contact.fingers@gmail.com<br />
Subject: [Botnet Analytics Blog] Please moderate: &#8220;Commercializing Botnets&#8221;<br />
X-PHP-Script: botnet.kaffenews.com/wp-comments-post.php for xxxxxxx<br />
Date: Wed, 17 Mar 2010 10:01:00 -0400<br />
From: xxxxxx&lt;xxxxxxx@botnet.kaffenews.com&gt;<br />
Message-ID: &lt;62e98c7537ee322c81e19df5ca2d12bd@botnet.kaffenews.com&gt;<br />
X-Priority: 3<br />
X-Mailer: xxxxxx (xxxxxxxxxxxxxxxxx) [version xxxxx]<br />
MIME-Version: 1.0<br />
Content-Transfer-Encoding: 8bit<br />
Content-Type: text/plain; charset=&#8221;UTF-8&#8243;<br />
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report<br />
X-AntiAbuse: Primary Hostname &#8211; xxxxxxx.hostgator.com<br />
X-AntiAbuse: Original Domain &#8211; gmail.com<br />
X-AntiAbuse: Originator/Caller UID/GID &#8211; [597 597] / [47 12]<br />
X-AntiAbuse: Sender Address Domain &#8211; xxxxxx.hostgator.com</p>
<p>A new comment on the post #218 &#8220;Commercializing Botnets&#8221; is waiting for your approval</p>
<p>http://botnet.kaffenews.com/?p=218</p>
<p><strong>Author : herbal ecstacy (IP: 173.234.19.194 , 173.234.19.194.rdns.ubiquityservers.com)<br />
E-mail : Raulnab@gmail.com<br />
URL    : http://bit.ly/herbalecstacy<br />
Whois  : http://ws.arin.net/cgi-bin/whois.pl?queryinput=173.234.19.194<br />
Comment:<br />
Hi all, i just found this here after an good google search. Neat blog you got here! Keep it up!</strong></p>
<p>Approve it: http://botnet.kaffenews.com/wp-admin/comment.php?action=approve&amp;c=57<br />
Trash it: http://botnet.kaffenews.com/wp-admin/comment.php?action=trash&amp;c=57<br />
Spam it: http://botnet.kaffenews.com/wp-admin/comment.php?action=spam&amp;c=57<br />
Currently 1 comment is waiting for approval. Please visit the moderation panel:</p>
<p>http://botnet.kaffenews.com/wp-admin/edit-comments.php?comment_status=moderated</p></blockquote>
<p><strong><br />
</strong><br />
In here, the thing that looks real according to us is the comment: <strong>&#8220;Hi all, i just found this here after an good google search. Neat blog you got here! Keep it up!&#8221;.</strong></p>
<p>The other details in the comment indicated that this is a SPAM comment:</p>
<p><strong>Author : herbal ecstacy (IP: 173.234.19.194 , 173.234.19.194.rdns.ubiquityservers.com)</strong> &#8212;&gt; Ubiquity Servers[Dedicated hosts] are damn cheap compared to other dedicated server accounts [am not comparing with Cloud services], and hence we have been seeing the increase in Botnets &amp; SPAM accounts from there more often. It is not completely true, as in we cannot determine something like that based on hosting provider, although your antennas would turn on[sense of suspicion] and you would start looking for more info.</p>
<p>IP queries on the above IP[<strong>173.234.19.194</strong>]:</p>
<blockquote><p><span style="color: #ffffff;"><strong><span style="color: black;">Block Lists </span></strong>&#8230;<br />
</span></p>
<pre>asiaspam.spamblocked.com: <strong><span style="color: red;">Listed! </span></strong>
</pre>
<pre>bl.deadbeef.com: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>bl.emailbasura.org: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>bl.spamcop.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>blackholes.five-ten-sg.com: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>blacklist.woody.ch: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>bogons.cymru.com: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>cbl.abuseat.org: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>cdl.anti-spam.org.cn: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>combined.abuse.ch: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>combined.rbl.msrbl.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>db.wpbl.info: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dnsbl-1.uceprotect.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dnsbl-2.uceprotect.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dnsbl-3.uceprotect.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dnsbl.abuse.ch: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dnsbl.ahbl.org: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dnsbl.cyberlogic.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dnsbl.inps.de: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dnsbl.njabl.org: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dnsbl.sorbs.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>drone.abuse.ch: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>duinv.aupads.org: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dul.dnsbl.sorbs.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dul.ru: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dyna.spamrats.com: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>dynip.rothen.com: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>eurospam.spamblocked.com: <strong><span style="color: red;">Listed! </span></strong>
</pre>
<pre>fl.chickenboner.biz: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>http.dnsbl.sorbs.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>images.rbl.msrbl.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>ips.backscatterer.org: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>isps.spamblocked.com: <strong><span style="color: red;">Listed! </span></strong>
</pre>
<pre>ix.dnsbl.manitu.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>korea.services.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>lacnic.spamblocked.com: <strong><span style="color: red;">Listed! </span></strong>
</pre>
<pre>misc.dnsbl.sorbs.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>noptr.spamrats.com: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>ohps.dnsbl.net.au: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>omrs.dnsbl.net.au: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>orvedb.aupads.org: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>osps.dnsbl.net.au: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>osrs.dnsbl.net.au: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>owfs.dnsbl.net.au: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>owps.dnsbl.net.au: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>pbl.spamhaus.org: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>phishing.rbl.msrbl.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>probes.dnsbl.net.au: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>proxy.bl.gweep.ca: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>proxy.block.transip.nl: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>psbl.surriel.com: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>rbl.interserver.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>rdts.dnsbl.net.au: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>relays.bl.gweep.ca: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>relays.bl.kundenserver.de: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>relays.nether.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>residential.block.transip.nl: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>ricn.dnsbl.net.au: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>rmst.dnsbl.net.au: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>sbl.spamhaus.org: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>short.rbl.jp: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>smtp.dnsbl.sorbs.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>socks.dnsbl.sorbs.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>spam.dnsbl.sorbs.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>spam.rbl.msrbl.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>spam.spamrats.com: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>spamlist.or.kr: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>spamrbl.imp.ch: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>t3direct.dnsbl.net.au: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>tor.ahbl.org: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>tor.dnsbl.sectoor.de: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>torserver.tor.dnsbl.sectoor.de: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>ubl.lashback.com: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>ubl.unsubscore.com: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>virbl.bit.nl: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>virus.rbl.jp: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>virus.rbl.msrbl.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>web.dnsbl.sorbs.net: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>wormrbl.imp.ch: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>xbl.spamhaus.org: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>zen.spamhaus.org: <span style="color: blue;">Not Listed!  </span>
</pre>
<p><strong><span style="color: white;">Reverse DNS/Canonical name Info </span></strong>&#8230;</p>
<p>Host  IP  :  173.234.19.194<br />
Canonical Name  :   173.234.19.194.rdns.ubiquityservers.com</p>
<pre><strong><span style="color: black;">Whois Info </span></strong>... 

GeekTools Whois Proxy v5.0.4 Ready.
Checking access for 74.220.215.117... ok.
Final results obtained from whois.arin.net.
Results:
Nobis Technology Group, LLC NETBLK-NOBIS-TECHNOLOGY-GROUP-08 (NET-173-234-0-0-1)
                                  173.234.0.0 - 173.234.255.255
Ubiquity Server Solutions Dallas NETBLK-UBIQUITY-DALLAS-173-234-16-0 (NET-173-234-16-0-1)
                                  173.234.16.0 - 173.234.19.255

# ARIN WHOIS database, last updated 2010-03-16 20:00
# Enter ? for additional hints on searching ARIN's WHOIS database.
#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at https://www.arin.net/whois_tou.html

Results brought to you by the GeekTools WHOIS Proxy
Server results may be copyrighted and are used with permission.
Your host (74.220.215.117) has visited 1 times today.
</pre>
</blockquote>
<p>Though few of the above listed RBL&#8217;s listed that it was LISTED in them, Senderbase.org did not have any records of it since the following block lists that are used by many websites because of their true positive nature has not LISTED the SPAMMING IP/site &#8220;yet&#8221;:</p>
<blockquote>
<pre>AbuseAT CBL........................: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>AHBL DNSBL.........................: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>China Anti-Spam Alliance CBL.......: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>China Anti-Spam Alliance CBLLESS...: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>China Anti-Spam Alliance CBLPLUS...: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>EFNet RBL..........................: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>Manitu DNSBL.......................: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>NJABL DNSBL........................: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>Sorbs web..........................: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>Sorbs DNSBL........................: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>Spamcop BL.........................: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>SURBL Multi........................: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>Surriel PSBL.......................: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>UCEPROTECT DNSBL Level 1...........: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>UCEPROTECT DNSBL Level 2...........: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>UCEPROTECT DNSBL Level 3...........: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>UCEPROTECT DNSBL BackScatterer.....: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>URIBL Multi........................: <span style="color: blue;">Not Listed!  </span>
</pre>
<pre>WPBL DNSBL.........................: <span style="color: blue;">Not Listed!  </span></pre>
</blockquote>
<p><strong>E-mail : Raulnab@gmail.com</strong> &#8212;&gt; Did not find any records for this email.<br />
URL    : http://bit.ly/herbalecstacy &#8212;&gt; This takes you to http://www.herbal-ecstacy.com/. Watch out for such TINY URL&#8217;s. Bit.ly &amp; TinyURL does a great job of shrinking URL&#8217;s although this remains a threat to home users who click on URL&#8217;s without knowing where they are really taken to. JSunpack results can be viewed at:</p>
<p><a href="http://jsunpack.jeek.org/dec/go?report=413fe49475b141fba1ed79768a64bd3b375385bf">http://jsunpack.jeek.org/dec/go?report=413fe49475b141fba1ed79768a64bd3b375385bf</a></p>
<p>In the above report, the following are listed suspicious:</p>
<blockquote><p>suspicious: MSIEUseAfterFree CVE-2010-0249 detected<br />
<a name="www.herbal-ecstacy.com/js/prototype.js"></a><strong>www.herbal-ecstacy.com/js/prototype.js suspicious</strong><br />
[<span>suspicious</span>:5]  (script) www.herbal-ecstacy.com/js/prototype.js<br />
<span>suspicious</span>: MSIEUseAfterFree CVE-2010-0249  detected<br />
<span>info</span>:  ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP<br />
<span>info</span>: ObfuscationPattern detected location eval  String.fromCharCode<br />
<span>info</span>: [script  http] :<br />
<span>info</span>: [decodingLevel=0] found  JavaScript<br />
<span>info</span>: [decodingLevel=0]  decoded 542 bytes (decoding_467bcc4d36c9ddf09f15dac1e9e767806b4e4d66)<br />
<span>info</span>: [decodingLevel=1] found JavaScript<br />
<span>info</span>: [file] saved  www.herbal-ecstacy.com/js/prototype.js to  (original_1703adc185bd3af6e8dec62e343907805fdf342f)</p>
<p><strong>www.herbal-ecstacy.com/ suspicious</strong><br />
[nothing detected]  www.herbal-ecstacy.com/<br />
<span>info</span>: [script  .] www.herbal-ecstacy.com/products.js<br />
<span>info</span>:  [script .] www.herbal-ecstacy.com/js/prototype.js<br />
<span>info</span>: [script .]  www.herbal-ecstacy.com/js/scriptaculous.js?load=effects,builder<br />
<span>info</span>: [script .]  www.herbal-ecstacy.com/js/lightbox.js<br />
<span>info</span>:  [img http] www.herbal-ecstacy.com/images/help.jpg<br />
<span>info</span>: [img .]  www.herbal-ecstacy.com/images/hyperdrive-herbal-ecstacy.jpg<br />
<span>info</span>: [img .]  www.herbal-ecstacy.com/images/neuro-herbal-ecstacy.jpg<br />
<span>info</span>: [img .]  www.herbal-ecstacy.com/images/slowdown-herbal-ecstacy.jpg<br />
<span>info</span>: [img .]  www.herbal-ecstacy.com/images/sextreme-herbal-extacy.jpg<br />
<span>info</span>: [img http]  www.herbal-ecstacy.com/images/creditcard.jpg<br />
<span>info</span>:  [img http]  cashburners.com/click.php?id=secureserver&amp;group=3&amp;referer=http://www.google.com/trends/hottrends<br />
<span>info</span>: [decodingLevel=0] found JavaScript</p></blockquote>
<p>Whois  : <a href="http://ws.arin.net/cgi-bin/whois.pl?queryinput=173.234.19.194">http://ws.arin.net/cgi-bin/whois.pl?queryinput=173.234.19.194</a> &#8212;&gt; If you would like to view the Whois info.</p>
<p>This shows that SPAMMERs are taking steps to ensure that they look legit and hide among the &#8220;NORMAL&#8221; category of responses, although the Security Analysts out there aren&#8217;t going to give up either. Hope this helps. Thank you for choosing EvilFingers!</p>
]]></content:encoded>
			<wfw:commentRss>http://ef.kaffenews.com/?feed=rss2&amp;p=1306</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IRS Scam Campaign on proposal by Zeus</title>
		<link>http://ef.kaffenews.com/?p=1299</link>
		<comments>http://ef.kaffenews.com/?p=1299#comments</comments>
		<pubDate>Sat, 20 Feb 2010 19:44:29 +0000</pubDate>
		<dc:creator>Jorge Mieres</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://ef.kaffenews.com/?p=1299</guid>
		<description><![CDATA[In the last hours has launched a new campaign as an excuse ZeuS a scam using the IRS (Internal Revenue Service) by which propagates its trojan.
ZeuS trojan variant in this case has the MD5 14FBCE4A3F67E46B18308AC6824B2A00 under the name tax-statement.exe, whose detection rate is high.
In addition, the person entering this page, in a transparent manner will ]]></description>
			<content:encoded><![CDATA[<p>In the last hours has launched a new campaign as an excuse ZeuS a scam using the IRS (Internal Revenue Service) by which propagates its trojan.</p>
<p>ZeuS trojan variant in this case has the MD5 14FBCE4A3F67E46B18308AC6824B2A00 under the name tax-statement.exe, whose detection rate is high.</p>
<p>In addition, the person entering this page, in a transparent manner will be routed through an iframe tag injected into the HTML source code, to an attack type Drive-by-Infection from hxxp://109.95.114.251/usa50/in.php.</p>
<p>The domains involved in this new campaign are:</p>
<p><a href="http://www.irs.gov.desa.ne.kr/fraud.applications/application/statement.php">http://www.irs.gov.desa.ne.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.desa.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.desa.or.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.desa.kr/fraud.applications/application/statement.php">http://www.irs.gov.desa.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.desa.co.kr/fraud.applications/application/statement.php">http://www.irs.gov.desa.co.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.desz.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.desz.or.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.desz.ne.kr/fraud.applications/application/statement.php">http://www.irs.gov.desz.ne.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.desz.kr/fraud.applications/application/statement.php">http://www.irs.gov.desz.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.desz.co.kr/fraud.applications/application/statement.php">http://www.irs.gov.desz.co.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.desv.kr/fraud.applications/application/statement.php">http://www.irs.gov.desv.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.deso.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.deso.or.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.deso.kr/fraud.applications/application/statement.php">http://www.irs.gov.deso.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.desb.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.desb.or.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.desb.ne.kr/fraud.applications/application/statement.php">http://www.irs.gov.desb.ne.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.desb.kr/fraud.applications/application/statement.php">http://www.irs.gov.desb.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.desb.co.kr/fraud.applications/application/statement.php">http://www.irs.gov.desb.co.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edase.kr/fraud.applications/application/statement.php">http://www.irs.gov.edase.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edasa.kr/fraud.applications/application/statement.php">http://www.irs.gov.edasa.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edasa.co.kr/fraud.applications/application/statement.php">http://www.irs.gov.edasa.co.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edasa.ne.kr/fraud.applications/application/statement.php">http://www.irs.gov.edasa.ne.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edase.ne.kr/fraud.applications/application/statement.php">http://www.irs.gov.edase.ne.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edasq.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.edasq.or.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edasq.co.kr/fraud.applications/application/statement.php">http://www.irs.gov.edasq.co.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edasq.ne.kr/fraud.applications/application/statement.php">http://www.irs.gov.edasq.ne.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.ersm.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.ersm.or.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edasn.kr/fraud.applications/application/statement.php">http://www.irs.gov.edasn.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.ersa.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.ersa.or.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.ersm.co.kr/fraud.applications/application/statement.php">http://www.irs.gov.ersm.co.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edasq.kr/fraud.applications/application/statement.php">http://www.irs.gov.edasq.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.ersq.co.kr/fraud.applications/application/statement.php">http://www.irs.gov.ersq.co.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edase.co.kr/fraud.applications/application/statement.php">http://www.irs.gov.edase.co.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edasn.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.edasn.or.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.ersq.kr/fraud.applications/application/statement.php">http://www.irs.gov.ersq.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edasa.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.edasa.or.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.ersm.ne.kr/fraud.applications/application/statement.php">http://www.irs.gov.ersm.ne.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edase.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.edase.or.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.ersm.kr/fraud.applications/application/statement.php">http://www.irs.gov.ersm.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.edasn.ne.kr/fraud.applications/application/statement.php">http://www.irs.gov.edasn.ne.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.ersw.kr/fraud.applications/application/statement.php">http://www.irs.gov.ersw.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.erst.ne.kr/fraud.applications/application/statement.php">http://www.irs.gov.erst.ne.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.ersw.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.ersw.or.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.erst.kr/fraud.applications/application/statement.php">http://www.irs.gov.erst.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.erst.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.erst.or.kr/fraud.applications/application/statement.php</a><br />
<a href="http://www.irs.gov.ersq.or.kr/fraud.applications/application/statement.php">http://www.irs.gov.ersq.or.kr/fraud.applications/application/statement.php</a></p>
<p>Jorge Mieres</p>
<p>Source: Malware Intelligence</p>
<p>=====================<br />
Jorge Mieres<br />
Malware Intelligence</p>
]]></content:encoded>
			<wfw:commentRss>http://ef.kaffenews.com/?feed=rss2&amp;p=1299</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apologies for any inconvenience</title>
		<link>http://ef.kaffenews.com/?p=1297</link>
		<comments>http://ef.kaffenews.com/?p=1297#comments</comments>
		<pubDate>Mon, 15 Feb 2010 02:58:41 +0000</pubDate>
		<dc:creator>BigBrother</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://ef.kaffenews.com/?p=1297</guid>
		<description><![CDATA[Just noticed that there were duplicate posts of every single post that has been imported from our blogspot account. I have removed the duplocates now. Also, noticed that the old images were removed before we transferred the account from the old to new. This will not happen again. Thank you for your patience and sorry ]]></description>
			<content:encoded><![CDATA[<p>Just noticed that there were duplicate posts of every single post that has been imported from our blogspot account. I have removed the duplocates now. Also, noticed that the old images were removed before we transferred the account from the old to new. This will not happen again. Thank you for your patience and sorry for any inconvenience.</p>
<p>Thank you for choosing EvilFingers!</p>
]]></content:encoded>
			<wfw:commentRss>http://ef.kaffenews.com/?feed=rss2&amp;p=1297</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SpyEye Bot. Analysis of a new alternative scenario crimeware</title>
		<link>http://ef.kaffenews.com/?p=873</link>
		<comments>http://ef.kaffenews.com/?p=873#comments</comments>
		<pubDate>Thu, 11 Feb 2010 14:49:41 +0000</pubDate>
		<dc:creator>Jorge Mieres</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://ef.kaffenews.com/?p=873</guid>
		<description><![CDATA[Earlier this year saw the light in the underground black market that moves the axes of crimeware, a new application designed to provide feedback for criminal and fraudulent business.

This application, called SpyEye, is aimed at facilitating the recruitment of zombies and managing your network (C&#38;C &#8211; Command and Control) through management panel via the web, ]]></description>
			<content:encoded><![CDATA[<div style="text-align: justify"><a href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/S3MuzV7hiQI/AAAAAAAACLk/5SIolmgUCQo/s1600-h/mi-paper-se-en.png"><img style="margin: 0pt 10px 10px 0pt;float: left;height: 200px;width: 139px" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/S3MuzV7hiQI/AAAAAAAACLk/5SIolmgUCQo/s200/mi-paper-se-en.png" border="0" alt="" /></a>Earlier this year saw the light in the underground black market that moves the axes of <span style="font-weight: bold">crimeware</span>, a new application designed to provide feedback for criminal and fraudulent business.</div>
<div style="text-align: justify">
<p>This application, called <a href="http://malwareint.blogspot.com/2010/01/spyeye-new-bot-on-market.html">SpyEye</a>, is aimed at facilitating the recruitment of zombies and managing your network (<span style="font-weight: bold">C&amp;C</span> &#8211; <span style="font-weight: bold">Command and Control</span>) through management panel via the web, from which it is possible to process the information obtained (<a href="http://mipistus.blogspot.com/2009/09/inteligencia-informatica-seguridad-de.html">intelligence</a>) and stored in statistics, a common activity of criminal packages today.</p>
<p>Depending on their characteristics, very similar to those proposed by his counterpart <a href="http://malwareint.blogspot.com/2010/01/zeus-and-theft-of-sensitive-information.html">ZeuS</a>, <span style="font-weight: bold">SpyEye</span> is presented as a potential successor to this within the scenario crimeware. Furthermore, it is evident that the criminal activities now represent a large business where cyber criminals and would-be cyber criminals abuse their &#8220;kindness&#8221;.</p>
<p>This document describes the activities of <span style="font-weight: bold">SpyEye</span> from the stage of infection giving relevant information about their purpose.</p>
</div>
<p>The full document can be downloaded from:</p>
<p><a href="http://www.malwareint.com/docs/spyeye-analysis-es.pdf">Spanish version</a><br />
<a href="http://www.malwareint.com/docs/spyeye-analysis-en.pdf">English version</a></p>
<p><span style="font-weight: bold">Related information</span><br />
<a href="http://mipistus.blogspot.com/2010/01/el-crimeware-durante-el-2009.html">Compendio Anual de Información. El crimeware durante el 2009</a><br />
<a href="http://malwareint.blogspot.com/2010/01/spyeye-new-bot-on-market.html">SpyEye Bot. New bot on the market</a></p>
<p>Jorge Mieres<br />
<a href="http://malwareint.blogspot.com">Malware Intelligence</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ef.kaffenews.com/?feed=rss2&amp;p=873</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New personal blog</title>
		<link>http://ef.kaffenews.com/?p=870</link>
		<comments>http://ef.kaffenews.com/?p=870#comments</comments>
		<pubDate>Thu, 11 Feb 2010 14:46:48 +0000</pubDate>
		<dc:creator>Jorge Mieres</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://ef.kaffenews.com/?p=870</guid>
		<description><![CDATA[Jorge Mieres Blog
Research on security, crimeware, botnets, intelligence and criminal activity involving any programs and/or harmful actions.
http://jorgemieresblog.blogspot.com

Jorge Mieres
Malware Intelligence
]]></description>
			<content:encoded><![CDATA[<p><strong>Jorge Mieres Blog</strong></p>
<p>Research on security, crimeware, botnets, intelligence and criminal activity involving any programs and/or harmful actions.</p>
<p><a href="http://jorgemieresblog.blogspot.com/">http://jorgemieresblog.blogspot.com</a></p>
<p style="text-align: center"><a href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S20J3sjgaoI/AAAAAAAACK8/QiKdSWydVf0/s1600-h/jmieres-blog.png"><img class="aligncenter" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S20J3sjgaoI/AAAAAAAACK8/QiKdSWydVf0/s400/jmieres-blog.png" border="0" alt="" /></a></p>
<p>Jorge Mieres<br />
<a href="http://malwareint.blogspot.com">Malware Intelligence</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ef.kaffenews.com/?feed=rss2&amp;p=870</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Automation in creating exploits II</title>
		<link>http://ef.kaffenews.com/?p=868</link>
		<comments>http://ef.kaffenews.com/?p=868#comments</comments>
		<pubDate>Thu, 11 Feb 2010 14:32:40 +0000</pubDate>
		<dc:creator>Jorge Mieres</dc:creator>
				<category><![CDATA[0-day]]></category>

		<guid isPermaLink="false">http://ef.kaffenews.com/?p=868</guid>
		<description><![CDATA[
The exploitation of vulnerability now represents one of the highest infection strategies used in the stage of crimeware and exploits while allowing exploit weaknesses aren&#8217;t a new concept, the fact is that more and more notorious actions.
In fact now continue to be exploited, especially through exploits pack, a large number of vulnerabilities that many have ]]></description>
			<content:encoded><![CDATA[<div>
<p>The exploitation of <span>vulnerability</span> now represents one of the highest infection strategies used in the stage of <span>crimeware</span> and <span>exploits</span> while allowing exploit weaknesses aren&#8217;t a new concept, the fact is that more and more notorious actions.</p>
<p>In fact now continue to be exploited, especially through <a href="http://malwareint.blogspot.com/2010/01/state-of-art-in-eleonore-exploit-pack.html">exploits pack</a>, a large number of vulnerabilities that many have been settled more than two years ago.</p>
<p>However, when these vulnerabilities are of type <span>0-Day</span>, the problem is power. Cases such as &#8220;<a href="http://blogs.eset-la.com/laboratorio/2010/01/21/que-es-operacion-aurora/">Operation Aurora</a>&#8221; which has recently been bandied about by exploiting a vulnerability in the type 0-Day Internet Explorer 6. Yes, you read that right &#8230; Internet Explorer 6 and currently is being used to spread malware mass but only through version 6, but also on the 7 and 8.</p>
<p>The vulnerability is identified as <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0249">CVE-2010-0249</a>, and as was the case with the vulnerability exploited by the worm <span>conficker</span> (<span>MS08-067</span>) where automated creation, has recently met a builder that automates the creation of the exploit for Internet Explorer in an extremely simple question that is common in such applications.</p>
</div>
<div>
<p style="text-align: center"><a href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S2CYw6jUznI/AAAAAAAACKs/IfgIhyZ33v8/s1600-h/malware-intelligence_ie-0day-exploit.png"><img class="aligncenter" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S2CYw6jUznI/AAAAAAAACKs/IfgIhyZ33v8/s400/malware-intelligence_ie-0day-exploit.png" border="0" alt="" /></a></p>
<p>This application is Chinese and only lets you configure the web address from where you try to exploit the weakness in the browser. Then generates a file called <span>IE.html </span>containing the exploit code and the url used for the attack, which is obfuscated.</p>
</div>
<div>
<p style="text-align: center"><a href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/S2CY4JOaBzI/AAAAAAAACK0/U05QEs8wW74/s1600-h/malware-intelligence_script.png"><img class="aligncenter" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/S2CY4JOaBzI/AAAAAAAACK0/U05QEs8wW74/s400/malware-intelligence_script.png" border="0" alt="" /></a></p>
<p>As condiments relevant subject, the exploit generated (embedded in the html) <a href="http://www.virustotal.com/analisis/563ca812869aff67ef28de2d50fbe538ddb5b941d2930d4ed90d38bcd7990f38-1264581975">is detected by less than 40%</a> of companies reporting according to antivirus virutotal. While the builder is detected, by far, at <a href="http://www.virustotal.com/analisis/badd2016bd45e2de920e7673107823ed89d53dd2366f8399e3a85abb341d2a3c-1264584030">least 25%</a>.</p>
<p>On the other hand, exploits automation generates a gap, revealing that many operations &#8220;disguised&#8221; as part of campaign of distraction after simple attacks, are closely related to <a href="http://malwareint.blogspot.com/2009/11/espionage-by-malware.html">intelligence affairs</a>.</p>
</div>
<p><strong><span>Related Information</span></strong><br />
<a href="http://mipistus.blogspot.com/2009/10/automatizacion-en-la-creacion-de.html">Automatización en la creación de exploits</a><br />
<a href="http://malwareint.blogspot.com/2009/07/process-automation-anti-analysis-ii.html">Process Automation anti-analysis II</a><br />
<a href="http://malwareint.blogspot.com/2009/03/automating-processes-anti-analysis.html">Automating processes anti-analysis through of crimeware</a></p>
<p>Jorge Mieres<br />
<a href="http://www.malwareint.blogspot.com">Malware Intelligence</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ef.kaffenews.com/?feed=rss2&amp;p=868</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Justifying the unjustifiable in a world criminal</title>
		<link>http://ef.kaffenews.com/?p=863</link>
		<comments>http://ef.kaffenews.com/?p=863#comments</comments>
		<pubDate>Mon, 25 Jan 2010 16:56:36 +0000</pubDate>
		<dc:creator>Jorge Mieres</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://ef.kaffenews.com/?p=863</guid>
		<description><![CDATA[As many readers know, since we have been researching Malware Intelligence direct implications of all this new generation of malicious code and criminal activity that daily feed back the business of crimeware.
Under this premise, the researchers focused their efforts on trying to reveal the different branches that are entangled with each other in a tangle ]]></description>
			<content:encoded><![CDATA[<p>As many readers know, since we have been researching Malware Intelligence direct implications of all this new generation of malicious code and criminal activity that daily feed back the business of crimeware.</p>
<p>Under this premise, the researchers focused their efforts on trying to reveal the different branches that are entangled with each other in a tangle of illegal actions aimed mainly to get money from users through unethical techniques. And according to this &#8230; there are still doubts that we are facing a big business that profit through illegal activities that rub? (obviously, always according to the laws of each country). I think the unanimous answer is NO.</p>
<p>Saved this assessment after exposing both content around the state of the art of crimeware, including relevant data yet unexposed to not hamper the continuity of investigations, and has become a common aspect receive messages and comments, most aggressive, those responsible for the development or commercialization of certain applications crimeware.</p>
<p>Under this scenario, and although I&#8217;m not giving explanations on the research we perform, this time an exception will expose two of the last comments we have received from those who are part of the business of crimeware.</p>
<p>Especially because in some way reflect the philosophy (of life and mental) who operate from the underground, but lately things are changing.</p>
<p>The first case is an anonymous, non-aggressive that I personally must confess that &#8230; very nice:) left by one of the Partners, which markets the crimeware YES Exploit System. The comment was made in the article that talks about this exploit pack, and which also find my answer. The comment is as follows:</p>
<blockquote><p><em><strong>YES, We are the blackhats <img src='http://ef.kaffenews.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
Thanks for small review, but why do ppl think that blackhats are poor guyz?<br />
It&#8217;s just a business, no less, no more <img src='http://ef.kaffenews.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Do you wanna buy our excellent product? &#8211; there is discounts for you <img src='http://ef.kaffenews.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </strong></em></p></blockquote>
<p>As they say my &#8220;friends&#8221; to them is &#8220;just a business, neither more nor less.&#8221; However, let us agree that, besides not being a conventional business, represents a business model that directly and actively collaborates with criminal activities, which isn&#8217;t so funny.</p>
<p>Now, YES Exploit System is a crimeware development that has much in your code and whose market value is USD 800. And the one thing is funny (as last sentence of the comet) is knowing that I will not get any discount on crimeware <img src='http://ef.kaffenews.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>The second case I want to present is a bit more aggressive in terms of what was written in the report on the Russian service to test the detection of malware, it can read the comment and my response, which does not transcribe here because of its length. The message reads:</p>
<blockquote><p><strong><em>&#8220;In summary, further evidence that not only the exploitation of malware generates profits but also moves parallel money on services to<br />
this industry. And in some cases like the present one, have to see if you can consider this service as a criminal act or not.&#8221;</em></strong></p>
<p><strong><em>Wow and why would this service be criminal act?</em></strong></p>
<p><strong><em>It&#8217;s clear to me that someone has a year work in a software like this scanner and he want to make money with it.<br />
If you don&#8217;t like it don&#8217;t use it. Noone forces you to pay for it or submit files there but since I see you are a little wanker<br />
blogger who does not respect others work I giving it to you straight.</em></strong></p>
<p><strong><em>You have no inside experience in the antivirus industry whatsoever otherwise you would know that VirusTotal distributes 200K files/day<br />
to antivirus companies for FREE. AV companies are shit on online scanners, they wouldn&#8217;t even contact you if you would ask them about file<br />
distribution and they definately wouldn&#8217;t support an online scanner so what else can these services do to remain online?</em></strong></p>
<p><strong><em>Before you criticizing others work put something down on the table little frustrated shit&#8230;&#8221;</em></strong></p></blockquote>
<p>Regardless of the aggressive connotation that presents this second point, it&#8217;s interesting who comes. Someone who uses the word as a nickname &#8220;KLESK&#8221; and host of an &#8220;attempt by business&#8221; completely unlawful, in which page one of the first things we read is &#8220;<span>Selling corporate data, trade secrets</span>&#8220;.</p>
<div>
<p style="text-align: center;"><a href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S1JbBSJUa5I/AAAAAAAACIk/StMlWMZnIMk/s1600-h/malware-intelligence_klesk.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5427500578543790994" class="aligncenter" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S1JbBSJUa5I/AAAAAAAACIk/StMlWMZnIMk/s400/malware-intelligence_klesk.png" border="0" alt="" /></a></p>
<p>&#8220;<span>We sell corporate data and trade secrets</span>&#8220;, continues the propaganda. Clarify further what type of information supposedly &#8220;steal&#8221; companies, and topped with something very interesting:</p>
<blockquote><p>&#8220;<span>Please losers/asszors stay away, all the data bids start on 5 figures</span>&#8221; :: Without words… <img src='http://ef.kaffenews.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p></blockquote>
<p>In order, particularly the latter case represents a good opportunity to analyze the psychology of a prospectus to cyber-criminal whose attempt to &#8220;negotiate&#8221; not only leaves much to be desired but can not even be rated as a possibility to be considered as an object research.</p>
<p><strong><span>Related Information</span></strong><br />
<a href="http://malwareint.blogspot.com/2009/11/russian-service-online-to-check.html">Russian service online to check the detection of malware</a><br />
<a href="http://mipistus.blogspot.com/2009/04/yes-exploit-system-otro-crimeware-made.html">YES Exploit System. Otro crimeware made in Rusia</a></p>
</div>
<p>Jorge Mieres<br />
<a href="http://www.malwareint.com">Malware Intelligence</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ef.kaffenews.com/?feed=rss2&amp;p=863</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
