<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-18493443</id><updated>2009-07-03T18:34:17.200+02:00</updated><title type='text'>Dancho Danchev's Blog - Mind Streams of Information Security Knowledge</title><subtitle type='html'>In the overwhelming sea of information, access to timely, insightful and independent open-source intelligence (OSINT) analyses is crucial for maintaining the necessary situational awareness to stay on the top of emerging security threats. This blog covers trends and fads, tactics and strategies, intersecting with third-party research, speculations and real-time CYBERINT assessments, all packed with sarcastic attitude</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ddanchev.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default?start-index=26&amp;max-results=25'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>976</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-18493443.post-3259935303697716909</id><published>2009-07-03T18:34:00.000+02:00</published><updated>2009-07-03T18:34:17.219+02:00</updated><title type='text'>A Diverse Portfolio of Fake Security Software - Part Twenty Two</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4ydTYuN8I/AAAAAAAAD4I/9iuyw-eGJ7c/s1600-h/ddanchev_scareware.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4ydTYuN8I/AAAAAAAAD4I/9iuyw-eGJ7c/s320/ddanchev_scareware.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;Part twenty two of the diverse portfolio of fake security software series will summarize the typosquatted scareware serving domains currently in circulation, pushed through the usual distribution channels, but will also emphasize on the "money trail", namely the payment processing gateways used in the scareware campaigns.&lt;br /&gt;&lt;br /&gt;In this particular case the scareware front-ends ultimately leading to &lt;b&gt;ChronoPay,&lt;/b&gt; which &lt;a href="http://ddanchev.blogspot.com/2009/06/diverse-portfolio-of-fake-security.html"&gt;Germany-based Pandora Software&lt;/a&gt; has been abusing since 2008 under its countless number of aliases such as &lt;b&gt;Meyrocorp&lt;/b&gt; for instance.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Sk0KxzFCXiI/AAAAAAAAD2w/TQYKFvUqAck/s1600-h/scareware_june_2009_antivirus_agent_pro.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Sk0KxzFCXiI/AAAAAAAAD2w/TQYKFvUqAck/s200/scareware_june_2009_antivirus_agent_pro.jpg" /&gt;&lt;/a&gt;The scareware domains are as follows:&lt;br /&gt;&lt;b&gt;atomscan6 .info&lt;/b&gt; - 38.105.19.27 - Email: donboset@gmail.com&lt;br /&gt;&lt;b&gt;listscan6 .com&lt;/b&gt; - Email: loiskiltz@gmail.com&lt;br /&gt;&lt;b&gt;goscanedge .com&lt;/b&gt; - Email: subtenda@gmail.com&lt;br /&gt;&lt;b&gt;goscanfine. com&lt;/b&gt; - Email: chirelqas@gmail.com&lt;br /&gt;&lt;b&gt;in6ch .com&lt;/b&gt; - Email: relgetn@gmail.com&lt;br /&gt;&lt;b&gt;goscanrich .com&lt;/b&gt; - Email: pathstals@gmail.com&lt;br /&gt;&lt;b&gt;goscanrank .com &lt;/b&gt;- Email: alcnafuch@gmail.com&lt;br /&gt;&lt;b&gt;ina6sk .com&lt;/b&gt; - Email: equatelepi@gmail.com&lt;br /&gt;&lt;b&gt;in6sk .com&lt;/b&gt; - Email: thomas.truby@gmail.com&lt;br /&gt;&lt;b&gt;goscanslim .com&lt;/b&gt; - Email: chinrfi@gmail.com&lt;br /&gt;&lt;b&gt;gowidescan .com&lt;/b&gt; - Email: alcnafuch@gmail.com&lt;br /&gt;&lt;b&gt;goedgescan .com&lt;/b&gt; - Email: subtenda@gmail.com&lt;br /&gt;&lt;b&gt;gofinescan .com &lt;/b&gt;- Email: alcnafuch@gmail.com&lt;br /&gt;&lt;b&gt;goelitescan .com &lt;/b&gt;- Email: funully@gmail.com&lt;br /&gt;&lt;b&gt;gorichscan .com&lt;/b&gt; - Email: pathstals@gmail.com&lt;br /&gt;&lt;b&gt;goslimscan .com&lt;/b&gt; - Email: chinrfi@gmail.com&lt;br /&gt;&lt;b&gt;gosoonscan .com&lt;/b&gt; - Email: aloxier@gmail.com&lt;br /&gt;&lt;b&gt;goironscan .com&lt;/b&gt; - Email: aloxier@gmail.com&lt;br /&gt;&lt;b&gt;goflexscan .com&lt;/b&gt; - Email: alcnafuch@gmail.com&lt;br /&gt;&lt;b&gt;gomanyscan .com&lt;/b&gt; - Email: alcnafuch@gmail.com&lt;br /&gt;&lt;b&gt;goscaniron .com&lt;/b&gt; - Email: aloxier@gmail.com&lt;br /&gt;&lt;b&gt;ina6co .com&lt;/b&gt; - Email: equatelepi@gmail.com&lt;br /&gt;&lt;b&gt;in6co .com&lt;/b&gt; - Email: thomas.truby@gmail.com&lt;br /&gt;&lt;b&gt;goscantop .com&lt;/b&gt; - Email: funully@gmail.com&lt;br /&gt;&lt;b&gt;ina6iq .com &lt;/b&gt;- Email: equatelepi@gmail.com&lt;br /&gt;&lt;b&gt;goscanstar .com&lt;/b&gt; - Email: stgeyman@gmail.com&lt;br /&gt;&lt;b&gt;goscanflex .com&lt;/b&gt; - Email: chirelqas@gmail.com&lt;br /&gt;&lt;b&gt;goscanmany .com&lt;/b&gt; - Email: chirelqas@gmail.com&lt;br /&gt;&lt;b&gt;scantrue6 .info &lt;/b&gt;- Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;scantool6 .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;scanzoom6 .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;litescan6 .info &lt;/b&gt;- Email: litescan6.info&lt;br /&gt;&lt;b&gt;truescan6 .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;toolscan6 .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4wbBlLxvI/AAAAAAAAD3I/uKOYE0L6SlU/s1600-h/scareware_best_detection_rates.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4wbBlLxvI/AAAAAAAAD3I/uKOYE0L6SlU/s200/scareware_best_detection_rates.JPG" /&gt;&lt;/a&gt;&lt;b&gt;atomscan6 .info &lt;/b&gt;- Email: donboset@gmail.com&lt;br /&gt;&lt;b&gt;genscan6 .info&lt;/b&gt; - Email: imendegal@gmail.com&lt;br /&gt;&lt;b&gt;luxscan6 .info&lt;/b&gt; - Email: donboset@gmail.com&lt;br /&gt;&lt;b&gt;wayscan6 .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;scanuser6 .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;scanway6 .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;scan6line .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;scan6note .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;scan6true .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;scan6tool .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;true6scan .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;tool6scan .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;top6scan .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;user6scan .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;list6scan .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;way6scan .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;scan6user .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;scan6list .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;scan6fix .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;b&gt;scan6way .info&lt;/b&gt; - Email: jokinzer@gmail.com&lt;br /&gt;&lt;br /&gt;It's pretty obvious case demonstrating the dynamics of the underground ecosystem. A thousand bogus accounts purchased for $10 used in a bulk registration of scareware serving domains on a revenue sharing affiliate model ends up in a win-win-win situation for the cybercriminals involved in these processes. The practice is becoming rather popular not only due to their interest in less centralization of the domain control under a single email address -- cross checking reveals the entire portfolio managed under it -- but due to the availability of the service.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4wuKsTWHI/AAAAAAAAD3Q/lF2lYwRP6Ds/s1600-h/advanced_virus_remover_june_2009.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4wuKsTWHI/AAAAAAAAD3Q/lF2lYwRP6Ds/s200/advanced_virus_remover_june_2009.jpg" /&gt;&lt;/a&gt;&lt;b&gt;clean-pc-now .net&lt;/b&gt; -&amp;nbsp; 94.75.233.162 - Email: robertsimonkroon@gmail.com&lt;br /&gt;&lt;b&gt;fast-spyware-cleaner .org&lt;/b&gt; - Email: robertsimonkroon@gmail.com&lt;br /&gt;&lt;b&gt;spyware-scaner .com&lt;/b&gt; - Email: robertsimonkroon@gmail.com&lt;br /&gt;&lt;b&gt;scan-pc-now .com&lt;/b&gt; - Email: robertsimonkroon@gmail.com&lt;br /&gt;&lt;b&gt;free-tube-porn .biz&lt;/b&gt; - Email: robertsimonkroon@gmail.com&lt;br /&gt;&lt;b&gt;spyware-killer .biz&lt;/b&gt; - Email: robertsimonkroon@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;b&gt;softportal-extrafiles .com&lt;/b&gt; - 64.20.38.172&lt;br /&gt;&lt;b&gt;exe-profile .com&lt;/b&gt; - Email: kimwerner92@yahoo.com&lt;br /&gt;&lt;b&gt;extrafiles-softportal .com&lt;/b&gt; - Email: opipkl@googlemail.com&lt;br /&gt;&lt;b&gt;softportal-files .com&lt;/b&gt; - Email: kimwerner92@yahoo.com&lt;br /&gt;&lt;b&gt;softportal-extrafiles .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;load-exe-soft .com&lt;/b&gt; - Email: kimwerner92@yahoo.com&lt;br /&gt;&lt;b&gt;exe-box .com&lt;/b&gt; - Email: normtroup@yahoo.com&lt;br /&gt;&lt;b&gt;hot-exe-area .net&lt;/b&gt; - Email: josepetie@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Sk4w7dCfkNI/AAAAAAAAD3Y/pjpXoHvnNoU/s1600-h/scareware_july_2009_base_zero_corp.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Sk4w7dCfkNI/AAAAAAAAD3Y/pjpXoHvnNoU/s200/scareware_july_2009_base_zero_corp.jpg" /&gt;&lt;/a&gt;&lt;b&gt;spywarecomputerscanv2 .com&lt;/b&gt; - 69.10.59.35 - Email: huang@bark.edu.hk&lt;br /&gt;&lt;b&gt;1live-antimalware-pro-scan .com&lt;/b&gt; - Email: hongkong@campusparis.org&lt;br /&gt;&lt;b&gt;1live-antimalware-scanner .com&lt;/b&gt; - Email: hongkong@campusparis.org&lt;br /&gt;&lt;b&gt;folderantispywarescanner .com&lt;/b&gt; - Email: xinhuawuhan@yahoo.com&lt;br /&gt;&lt;b&gt;antivirushelpscanner .com&lt;/b&gt; - Email: info@brandturkey.com&lt;br /&gt;&lt;b&gt;fastfolderscanner .com&lt;/b&gt; - Email: info@brandturkey.com&lt;br /&gt;&lt;b&gt;mycomputerscanner .com&lt;/b&gt; - Email: vanmullem@yahoo.com&lt;br /&gt;&lt;br /&gt;&lt;b&gt;restricteddomainhelp .com&lt;/b&gt; - 83.133.124.81 - Email: franklinnig@yahoo.com&lt;br /&gt;&lt;b&gt;msncoreupdate .com&lt;/b&gt; - Email: jen@parallelslive.cn&lt;br /&gt;&lt;b&gt;world-payment-system .com&lt;/b&gt; - Email: info@yashitaindian.com&lt;br /&gt;&lt;b&gt;liveinternetupdates .com&lt;/b&gt; - Email: kuzya77@freebbmail.com&lt;br /&gt;&lt;b&gt;onlineantivirusmarket .com&lt;/b&gt; Email: podbisb@hotmail.com&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Sk4xIfGU4uI/AAAAAAAAD3g/y1TW-uYpee4/s1600-h/vscodec_pro.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Sk4xIfGU4uI/AAAAAAAAD3g/y1TW-uYpee4/s200/vscodec_pro.jpg" /&gt;&lt;/a&gt;&lt;b&gt;threats-scanner .com&lt;/b&gt; - 69.4.230.204 - Email: vanmullem@yahoo.com&lt;br /&gt;&lt;b&gt;securitypcscanner2 .com&lt;/b&gt; - Email: office@actionaidinusa.org&lt;br /&gt;&lt;b&gt;anti-virussecurity3 .com&lt;/b&gt; - Email:&amp;nbsp; office@actionaidinusa.org &lt;br /&gt;&lt;b&gt;private-online-scan .com&lt;/b&gt; - Email: info@kianah.org&lt;br /&gt;&lt;b&gt;liveantivirusproscan .com&lt;/b&gt; - Email: second@freebbmail.com&lt;br /&gt;&lt;b&gt;no1virusscan .com -&lt;/b&gt; Email: info@kianah.org&lt;br /&gt;&lt;b&gt;my-private-protection .com -&lt;/b&gt; Email: info@kianah.org&lt;br /&gt;&lt;b&gt;scanmyfolders .com&lt;/b&gt; - Email: info@kianah.org&lt;br /&gt;&lt;b&gt;scanmycomputerforvirus .com -&lt;/b&gt; Email: vanmullem@yahoo.com&lt;br /&gt;&lt;br /&gt;&lt;b&gt;onlinescan-ultraantivirus2009&amp;nbsp; .com&lt;/b&gt; - 206.53.61.76&lt;br /&gt;&lt;b&gt;relevantwebsearches .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;virussweeper-scanvirus .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;guardincorp&amp;nbsp; .info&lt;/b&gt;&lt;br /&gt;&lt;b&gt;mainsecsys .info&lt;/b&gt; - Email: andrew.fbecket@gmail.com&lt;br /&gt;&lt;b&gt;guardsecurity .info&lt;/b&gt; - Email: poljaykop@gmail.com&lt;br /&gt;&lt;b&gt;virusalarm-scanvirus .net&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Sk4xY45xXhI/AAAAAAAAD3o/cPIVYilAC9w/s1600-h/antivirus_pro_purchase_form.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Sk4xY45xXhI/AAAAAAAAD3o/cPIVYilAC9w/s200/antivirus_pro_purchase_form.jpg" /&gt;&lt;/a&gt;&lt;b&gt;best-protect .info&lt;/b&gt; - 174.142.113.205 - Email: chainadmin@gmail.com&lt;br /&gt;&lt;b&gt;best-protect-av1 .info&lt;/b&gt; - Email: chainadmin@gmail.com&lt;br /&gt;&lt;b&gt;best-antivirus-pc&amp;nbsp;&amp;nbsp; .info&lt;/b&gt; - Email: chainadmin@gmail.com&lt;br /&gt;&lt;b&gt;best-av1-protect .info&lt;/b&gt; - Email: chainadmin@gmail.com&lt;br /&gt;&lt;b&gt;av1-protect .info&lt;/b&gt; - Email: chainadmin@gmail.com&lt;br /&gt;&lt;b&gt;av1-best-protect .info - &lt;/b&gt;Email: chainadmin@gmail.com&lt;br /&gt;&lt;b&gt;best-protect .info&lt;/b&gt; - Email: chainadmin@gmail.com&lt;br /&gt;&lt;b&gt;best-av .info&lt;/b&gt; - Email: chainadmin@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;b&gt;pay-virusshield .cn&lt;/b&gt; - 64.213.140.70 - Email: unitedisystems@gmail.com&lt;br /&gt;&lt;b&gt;shieldinc .info&lt;br /&gt;systemprotectinc .info&lt;br /&gt;ironshield .info&lt;br /&gt;myofficeguard .info&lt;br /&gt;protectionurl .info&lt;br /&gt;my-protection .info&lt;br /&gt;antivirus09&amp;nbsp; .net&lt;br /&gt;fast-antivirus.net&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4xnyho-NI/AAAAAAAAD3w/h5HTUNBwyS0/s1600-h/virusshield.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4xnyho-NI/AAAAAAAAD3w/h5HTUNBwyS0/s200/virusshield.jpg" /&gt;&lt;/a&gt;&lt;b&gt;virusshieldpro&amp;nbsp; .com&lt;/b&gt; - 64.86.16.127 - Email: unitedisystems@gmail.com&lt;br /&gt;&lt;b&gt;prestotuneup .com&lt;/b&gt; - Email: hycderxvur@whoisservices.cn&lt;br /&gt;&lt;b&gt;virussweeper-scanvirus .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;virusmelt .com&lt;/b&gt; - Email: nuhuarrczq@whoisservices.cn&lt;br /&gt;&lt;b&gt;systemsec .info&lt;br /&gt;shieldinc .info&lt;br /&gt;myofficeguard .info&lt;br /&gt;protect-online .info&lt;br /&gt;protectionlol .info&lt;br /&gt;protectionurl .info&lt;br /&gt;virussweeper-scan .net&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;advanced-virus-remover2009 .com&lt;/b&gt; - 92.241.176.188 - Email: masle@masle.kz &lt;br /&gt;&lt;b&gt;trucount3005 .com&lt;/b&gt; - Email: chen.poon1732646@yahoo.com&lt;br /&gt;&lt;b&gt;antivirus-scan-2009 .com&lt;/b&gt; - Email: cheng2009@yahoo.com &lt;br /&gt;&lt;b&gt;antivirusxppro-2009 .com&lt;/b&gt; - Email: u@sochi.ru&lt;br /&gt;&lt;b&gt;advanced-virusremover2009 .com&lt;/b&gt; - Email: giogr@ua.fm&lt;br /&gt;&lt;b&gt;bestscanpc .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;trucountme .com&lt;/b&gt; - Email: valentin@gergiea.kz&lt;br /&gt;&lt;b&gt;vs-codec-pro .com&lt;/b&gt; - Email:&amp;nbsp; bhtjnjhggn@googlemail.com &lt;br /&gt;&lt;b&gt;vscodec-pro .com&lt;/b&gt; - Email: cyber38462@hotmail.com&lt;br /&gt;&lt;b&gt;antivirus-2009-ppro .com&lt;/b&gt; - Email: cheng2009@yahoo.com&lt;br /&gt;&lt;b&gt;onlinescanxppro .com&lt;/b&gt; - Email: chen.poon1732646@yahoo.com&lt;br /&gt;&lt;b&gt;downloadavr .com&lt;/b&gt; - Email: gorbun@ua.fm&lt;br /&gt;&lt;b&gt;bestscanpc .net&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4x1zZoQUI/AAAAAAAAD34/wtMB_2uR8EA/s1600-h/antivirus_best_july_2009_scareware.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4x1zZoQUI/AAAAAAAAD34/wtMB_2uR8EA/s200/antivirus_best_july_2009_scareware.jpg" /&gt;&lt;/a&gt;&lt;b&gt;activation-antivirus-software .com&lt;/b&gt; - 208.43.124.83 - Email: matlee@fsuk.edu&lt;br /&gt;&lt;b&gt;fxantispy .com&lt;/b&gt; - Email: TycoonMichael@googlemail.com&lt;br /&gt;&lt;b&gt;my-protection .info&lt;/b&gt; - 64.213.140.70 - Email: hop.davis@gmail.com&lt;br /&gt;&lt;b&gt;protectonline .info&lt;/b&gt; - 64.86.17.47 - Email: hop.davis@gmail.com&lt;br /&gt;&lt;b&gt;safetywwwtools .com&lt;/b&gt; - 209.44.126.36 - Email: martin.s.johnson@spambob.com &lt;br /&gt;&lt;b&gt;defenderupdates2 .com&lt;/b&gt; - 89.248.168.46 - Email: china@seban.se&lt;br /&gt;&lt;b&gt;securitytoolsdirect .com&lt;/b&gt; - 209.44.126.22 - Email: RuthMMarcotte@text2re.com&lt;br /&gt;&lt;b&gt;best-antivirus-security .com&lt;/b&gt; - 84.16.237.52 - Email: valentinyermolaev@gmail.com&lt;br /&gt;&lt;b&gt;malwaresdestructor .com&lt;/b&gt; - 206.53.61.74&lt;br /&gt;&lt;b&gt;suprotect .com&lt;/b&gt; - 89.149.212.218 - uuuuu@ua.fm&lt;br /&gt;&lt;b&gt;threatpcscanner .com&lt;/b&gt; - 63.223.110.177 ; 78.47.132.216 ; 78.47.172.66 - Email: vanmullem@yahoo.com&lt;br /&gt;&lt;b&gt;antimalwareliveproscannerv3 .com&lt;/b&gt; - Email: vanmullem@yahoo.com&lt;br /&gt;&lt;b&gt;antivirus-online-pro-scan .com&lt;/b&gt; - Email: vanmullem@yahoo.com&lt;br /&gt;&lt;b&gt;avpro-labs .com&lt;/b&gt; - 213.182.197.229&lt;br /&gt;&lt;b&gt;avprotectionstat .com&lt;/b&gt; - 74.50.99.236&lt;br /&gt;&lt;b&gt;explorerfilescan .com&lt;/b&gt; - 63.223.110.178; 78.47.132.221; 78.47.172.68 Email: xinhuawuhan@yahoo.com&lt;br /&gt;&lt;b&gt;antivirushelpscanner .com&lt;/b&gt;&amp;nbsp; A&amp;nbsp; 83.133.125.116; 69.10.59.35; 83.133.125.116 - Email: info@brandturkey.com&lt;br /&gt;&lt;b&gt;fastfolderscanner .com&lt;/b&gt; - Email: info@brandturkey.com&lt;br /&gt;&lt;b&gt;mycomputerscanner .com&lt;/b&gt; - Email: info@brandturkey.com&lt;br /&gt;&lt;b&gt;mal-warexls .net&lt;/b&gt; - 72.9.108.26 - Email: joehugardo@ya.ru&lt;br /&gt;&lt;b&gt;internetware-safe .com&lt;/b&gt; - Email: candikeller@ya.ru&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4x_4i0BRI/AAAAAAAAD4A/XFS25NPlwR8/s1600-h/chek_right.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4x_4i0BRI/AAAAAAAAD4A/XFS25NPlwR8/s320/chek_right.jpg" /&gt;&lt;/a&gt;&lt;b&gt;scanonlinesite .info&lt;/b&gt; - 66.148.74.126 &lt;br /&gt;&lt;b&gt;scanonlineblog .info&lt;br /&gt;scanonlineshop .info&lt;br /&gt;scanonlinenow .info&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;youravprotection .com&lt;/b&gt; - 74.50.98.162 - Email: armandgregory3@gmail.com &lt;br /&gt;&lt;b&gt;registerantivirus .com&lt;/b&gt; Email: ed.areyra@gmail.com&lt;br /&gt;&lt;b&gt;avprotectionstat .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;avagent-pro .com&lt;/b&gt; - 83.133.126.46 - Email: dwrdcardenas95@gmail.com&lt;br /&gt;&lt;b&gt;downloads-123 .com&lt;/b&gt; - Email: dwrdcardenas95@gmail.com&lt;br /&gt;&lt;b&gt;soft-process .com&lt;/b&gt; - Email: dwrdcardenas95@gmail.com&lt;br /&gt;&lt;b&gt;download-123 .cn&lt;/b&gt; - Email: dwrdcardenas95@gmail.com&lt;br /&gt;&lt;b&gt;actupdate .net&lt;/b&gt; - Email: dwrdcardenas95@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4goHcfiSI/AAAAAAAAD24/5M3Ht9j29TE/s1600-h/scareware_chronopay_pandora_software_meyrocorp.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4goHcfiSI/AAAAAAAAD24/5M3Ht9j29TE/s200/scareware_chronopay_pandora_software_meyrocorp.JPG" /&gt;&lt;/a&gt;Now the emphasis on the payment gateways, currently active and processing the scareware transactions:&lt;br /&gt;&lt;b&gt;softwaresecuredbilling .com&lt;/b&gt; - 209.8.45.122 - TemchenkoViktor@googlemail.com&lt;br /&gt;&lt;b&gt;softsales-discount .com&lt;/b&gt; - Email: daunrwwciq@whoisservices.cn&lt;br /&gt;&lt;b&gt;best-internet-payments&amp;nbsp; .com&lt;/b&gt; - 209.8.45.148 - Email: specsupport@gmail.com&lt;br /&gt;&lt;b&gt;adioro .com&lt;/b&gt; - 213.174.152.32 - Email: xyhsbjlrl@whoisprivacyprotect.com&lt;br /&gt;&lt;b&gt;secure-plus-payments .com&lt;/b&gt; - 209.8.25.204 - Email: sparck000@mail.com&lt;br /&gt;&lt;b&gt;secure.pnm-software .com&lt;/b&gt; - 209.8.45.124 - Email: pnm-software.com@liveinternetmarketingltd.com&lt;br /&gt;&lt;b&gt;soft-process .com&lt;/b&gt; - 83.133.126.46 - Email: XtPbtP@privacypost.com&lt;br /&gt;&lt;b&gt;privatesecuredpayments .com&lt;/b&gt; - 78.46.216.238 - Email: TemchenkoViktor@googlemail.com&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4iBsGtXPI/AAAAAAAAD3A/UEdi5ZSUang/s1600-h/scareware_june_2009_4_pandora_software.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4iBsGtXPI/AAAAAAAAD3A/UEdi5ZSUang/s200/scareware_june_2009_4_pandora_software.png" /&gt;&lt;/a&gt;These payment processing gateways are sometimes front-end to the original and often legitimate payment processors. In this particular case, the the legitimate processor is Netherlands-based &lt;b&gt;ChronoPay&lt;/b&gt;, which is known to have been used in the past by affiliates in the scareware affiliate model in the past, with several complaints for repeated credit card billing, which in reality is included in the scareware's Terms of Service.&lt;br /&gt;&lt;br /&gt;Upon a successful purchase - the customer is told that "&lt;i&gt;&lt;b&gt;This charge will appear on your card statement as CHRPay.com/ducforceide&lt;/b&gt;&lt;/i&gt;". Interestingly, Pandora Software has also been using the following ChronoPay accounts for over an year - &lt;b&gt;Chrpay.com/meyrocorp&lt;/b&gt;; &lt;b&gt;CHrpay.com/pnra&lt;/b&gt; using &lt;a href="http://www.complaintsboard.com/complaints/billed-for-more-than-asked-for-c87068.html#c253625"&gt;disconnected numbers&lt;/a&gt;, CallerID's of &lt;a href="http://www.complaintsboard.com/complaints/chrpaycomducforceide-c221036.html"&gt;scareware operations&lt;/a&gt;, desperate attempts to contact the alias for &lt;a href="http://online.wsj.com/article/SB123976230407519659.html"&gt;the front-end payment processor&lt;/a&gt;, ultimately resulting in &lt;a href="http://www.ripoffreport.com/searchresults.asp?q5=CHRPay.com&amp;amp;q1=ALL&amp;amp;q4=&amp;amp;q6=&amp;amp;q3=&amp;amp;q2=&amp;amp;q7=&amp;amp;searchtype=0&amp;amp;submit2=Search%21"&gt;several hundred ChronoPay related complaints&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Next to scareware, ChronoPay (&lt;b&gt;Pavel Vrublevsky&lt;/b&gt; acting as CEO) is also known to have been used in &lt;a href="http://ddanchev.blogspot.com/2008/07/mobile-malware-scam-isexplayer-wants.html"&gt;a mobile application scam dissected here&lt;/a&gt;, as well as being a victim of &lt;a href="http://www.kommersant.com/p876309/r_500/electronic_payment_processing_/"&gt;a DDoS attack in 2008&lt;/a&gt;, which is pretty logical since if ChronoPay is the payment processor of choice for the hundreds of thousands of scareware generated revenues on daily basis, the commissions ChronoPay takes from cybercriminals would be more than welcome in the competing payment processor's network.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/05/dissecting-swine-flu-black-seo-campaign.html"&gt;Dissecting a Swine Flu Black SEO Campaign&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;Massive Blackhat SEO Campaign Serving Scareware&lt;/a&gt;&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;From Ukrainian Blackhat SEO Gang With Love&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;From Ukrainian Blackhat SEO Gang With Love - Part Two&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukraine-with-scareware-serving.html"&gt;From Ukraine with Scareware Serving Tweets, Bogus LinkedIn/Scribd Accounts, and Blackhat SEO Farms &lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/06/fake-web-hosting-provider-front-end-to.html"&gt;Fake Web Hosting Provider - Front-end to Scareware Blackhat SEO Campaign at Blogspot&lt;/a&gt;&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/06/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Twenty One&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/05/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Twenty&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/04/diverse-portfolio-of-fake-security_16.html"&gt;A Diverse Portfolio of Fake Security Software - Part Nineteen&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/04/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Eighteen&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/03/diverse-portfolio-of-fake-security_31.html"&gt;A Diverse Portfolio of Fake Security Software - Part Seventeen&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/03/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Sixteen&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/02/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Fifteen &lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/01/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Fourteen&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/11/diverse-portfolio-of-fake-security_12.html"&gt;A Diverse Portfolio of Fake Security Software - Part Thirteen&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/11/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Twelve&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_28.html"&gt;A Diverse Portfolio of Fake Security Software - Part Eleven&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_22.html"&gt;A Diverse Portfolio of Fake Security Software - Part Ten&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_16.html"&gt;A Diverse Portfolio of Fake Security Software - Part Nine&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Eight&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html"&gt;A Diverse Portfolio of Fake Security Software - Part Seven&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html"&gt;A Diverse Portfolio of Fake Security Software - Part Six&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html"&gt;A  Diverse Portfolio of Fake Security Software - Part Five&lt;/a&gt; &lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html"&gt;A  Diverse Portfolio of Fake Security Software - Part Four&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html"&gt;A  Diverse Portfolio of Fake Security Software - Part Three&lt;/a&gt; &lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html"&gt;A  Diverse Portfolio of Fake Security Software - Part Two&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html"&gt;Diverse  Portfolio of Fake Security Software&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;. &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-3259935303697716909?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/3259935303697716909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/3259935303697716909'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/07/diverse-portfolio-of-fake-security.html' title='A Diverse Portfolio of Fake Security Software - Part Twenty Two'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wICHhTiQmrA/Sk4ydTYuN8I/AAAAAAAAD4I/9iuyw-eGJ7c/s72-c/ddanchev_scareware.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-1018476450179448003</id><published>2009-07-01T22:26:00.001+02:00</published><updated>2009-07-03T00:09:06.761+02:00</updated><title type='text'>Summarizing Zero Day's Posts for June</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Sku6xtMr2II/AAAAAAAAD2o/mLRdSL1lcMQ/s1600-h/zdnet_zeroday_june_2009.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Sku6xtMr2II/AAAAAAAAD2o/mLRdSL1lcMQ/s200/zdnet_zeroday_june_2009.JPG" /&gt;&lt;/a&gt;The following is a brief summary of all of my posts at ZDNet's &lt;a href="http://blogs.zdnet.com/security"&gt;Zero Day&lt;/a&gt; for June.&lt;br /&gt;&lt;br /&gt;You can also go through previous summaries for &lt;a href="http://ddanchev.blogspot.com/2009/06/summarizing-zero-days-posts-for-may.html"&gt;May&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/05/summarizing-zero-days-posts-for-april.html"&gt;April&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/03/summarizing-zero-days-posts-for-march.html"&gt;March&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/03/summarizing-zero-days-posts-for.html"&gt;February&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/02/summarizing-zero-days-posts-for-january.html"&gt;January&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/01/summarizing-zero-days-posts-for.html"&gt;December&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/12/summarizing-zero-days-posts-for.html"&gt;November&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/11/summarizing-zero-days-posts-for-october.html"&gt;October&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/10/summarizing-zero-days-posts-for.html"&gt;September&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/09/summarizing-zero-days-posts-for-august.html"&gt;August&lt;/a&gt; and &lt;a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html"&gt;July&lt;/a&gt;, as well as subscribe to my &lt;a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;amp;s=0&amp;amp;o=1&amp;amp;mode=rss"&gt;personal RSS feed&lt;/a&gt; or &lt;a href="http://feeds.feedburner.com/zdnet/security"&gt;Zero Day's main feed&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Notable articles include: &lt;a href="http://blogs.zdnet.com/security/?p=3522"&gt;Microsoft study debunks profitability of the underground economy&lt;/a&gt;; &lt;a href="http://blogs.zdnet.com/security/?p=3566"&gt;Overall spam volume unaffected by 3FN/Pricewert's ISP shutdown&lt;/a&gt; and &lt;a href="http://blogs.zdnet.com/security/?p=3613"&gt;Iranian opposition launches organized cyber attack against pro-Ahmadinejad sites&lt;/a&gt;.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;b&gt;01.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3485"&gt;Email service provider: 'Hack into our CEO's email, win $10k'&lt;/a&gt;&lt;br /&gt;&lt;b&gt;02.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3491"&gt;419 scammers using NYTimes.com 'email this feature'&lt;/a&gt;&lt;br /&gt;&lt;b&gt;03.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3522"&gt;Microsoft study debunks profitability of the underground economy&lt;/a&gt;&lt;br /&gt;&lt;b&gt;04.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3533"&gt;Malware poses as fake Yellowsn0w iPhone unlocker&lt;/a&gt;&lt;br /&gt;&lt;b&gt;05.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3549"&gt;Cybercriminals hijack Twitter trending topics to serve malware&lt;/a&gt;&lt;br /&gt;&lt;b&gt;06.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3566"&gt;Overall spam volume unaffected by 3FN/Pricewert's ISP shutdown&lt;/a&gt;&lt;br /&gt;&lt;b&gt;07.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3575"&gt;Mac OS X malware posing as fake video codec discovered&lt;/a&gt;&lt;br /&gt;&lt;b&gt;08.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3597"&gt;Researchers demo wireless keyboard sniffer for Microsoft 27Mhz keyboards&lt;/a&gt;&lt;br /&gt;&lt;b&gt;09.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3606"&gt;China confirms security flaws in Green Dam, rushes to release a patch&lt;/a&gt;&lt;br /&gt;&lt;b&gt;10.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3613"&gt;Iranian opposition launches organized cyber attack against pro-Ahmadinejad sites&lt;/a&gt;&lt;br /&gt;&lt;b&gt;11.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3648"&gt;Fake Microsoft patches themed malware campaigns spreading&lt;/a&gt;&lt;br /&gt;&lt;b&gt;12.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3658"&gt;Remote code execution exploit for Green Dam in the wild&lt;/a&gt;&lt;br /&gt;&lt;b&gt;13.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3673"&gt;Secunia: Average insecure program per PC rate remains high&lt;/a&gt;&lt;br /&gt;&lt;b&gt;14.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3682"&gt;Michael Jackson's death themed malware campaigns spreading&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-1018476450179448003?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/1018476450179448003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/1018476450179448003'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/07/summarizing-zero-days-posts-for-june.html' title='Summarizing Zero Day&apos;s Posts for June'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_wICHhTiQmrA/Sku6xtMr2II/AAAAAAAAD2o/mLRdSL1lcMQ/s72-c/zdnet_zeroday_june_2009.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-639761876014083481</id><published>2009-06-24T14:21:00.002+02:00</published><updated>2009-06-26T17:35:13.605+02:00</updated><title type='text'>A Peek Inside the Managed Blackhat SEO Ecosystem</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SkH5oDc4tJI/AAAAAAAAD0g/BhSv5oqpSoY/s1600-h/black_seo_managed_services.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SkH5oDc4tJI/AAAAAAAAD0g/BhSv5oqpSoY/s200/black_seo_managed_services.JPG" /&gt;&lt;/a&gt;Ever wondered how are thousands of bogus accounts across multiple Web services, automatically generated with built-in monetization channels consisting of scareware, malware to the use of legitimate affiliate links from major ad networks?&lt;br /&gt;&lt;br /&gt;Through several clicks or if complete automation and experience count, through outsourcing the process to a managed blackhat SEO provider that wouldn't charge you for the product, but for the service offered. Let's take a peek at some of the currently available DIY tools, and what a managed blackhat SEO service provider has to offer.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SkH9G89CfmI/AAAAAAAAD0o/5rHA1mq44so/s1600-h/blackhat_seo_hosting_ISP.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SkH9G89CfmI/AAAAAAAAD0o/5rHA1mq44so/s200/blackhat_seo_hosting_ISP.JPG" /&gt;&lt;/a&gt;Take for instance the "professional blackhat SEO" expert featured here. His ongoing &lt;a href="http://blogs.zdnet.com/security/?p=3549"&gt;Twitter spam campaigns&lt;/a&gt; are in fact so successfully &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukraine-with-scareware-serving.html"&gt;hijacking trending topics&lt;/a&gt; that at first they looked like your typical scareware serving campaign. What both sides have in common are spamming techniques used.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SkH9hGoR94I/AAAAAAAAD0w/iePuS1amUh0/s1600-h/blackhat_seo_services_5.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SkH9hGoR94I/AAAAAAAAD0w/iePuS1amUh0/s200/blackhat_seo_services_5.jpg" /&gt;&lt;/a&gt;However, the tactics vary and indicate an interesting shift from the typical &lt;a href="http://blogs.zdnet.com/security/?p=1835"&gt;outsourcing of CAPTCHA recognition&lt;/a&gt; for the purpose of storing the blackhat SEO content on the legitimate provider's services. In order to scale more efficiently, several currently active managed blackhat SEO providers that have vertically integrated to the point where they manage their own blackhat SEO friendly ISP.&lt;br /&gt;&lt;br /&gt;By doing so, their bogus account generating platforms are capable of achieving speeds that would be otherwise either impossible or impractical to set as objectives through outsourced CAPTCHA-recognition - 2,931 bogus Wordpress accounts with template based blackhat SEO content generated in 1 second using their own managed infrastructure. The following screenshots provide an inside peek into one of the products offered by the "professional blackhat SEO expert" :&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SkIAzdDgjJI/AAAAAAAAD04/sYOucZHybmA/s1600-h/blackhat_seo_services_1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SkIAzdDgjJI/AAAAAAAAD04/sYOucZHybmA/s320/blackhat_seo_services_1.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SkIBHPkdJxI/AAAAAAAAD1I/ZOVaiNhiEn4/s1600-h/black_seo_managed_services_1.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SkIBHPkdJxI/AAAAAAAAD1I/ZOVaiNhiEn4/s320/black_seo_managed_services_1.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SkIBAyisTTI/AAAAAAAAD1A/YIOl2jKi9kE/s1600-h/blackhat_seo_services_2.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SkIBAyisTTI/AAAAAAAAD1A/YIOl2jKi9kE/s320/blackhat_seo_services_2.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SkIBhhBco_I/AAAAAAAAD1Q/sTT9rwTadng/s1600-h/blackhat_seo_services_3.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SkIBhhBco_I/AAAAAAAAD1Q/sTT9rwTadng/s320/blackhat_seo_services_3.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SkIByeEU7VI/AAAAAAAAD1g/JaR1TKX0ahM/s1600-h/blackhat_seo_services_4.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SkIByeEU7VI/AAAAAAAAD1g/JaR1TKX0ahM/s320/blackhat_seo_services_4.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SkIB5k9nnyI/AAAAAAAAD1o/xMk_xEG0ycQ/s1600-h/blackhat_seo_services_6.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SkIB5k9nnyI/AAAAAAAAD1o/xMk_xEG0ycQ/s320/blackhat_seo_services_6.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SkICADIMPGI/AAAAAAAAD1w/fvmMH6LlRbo/s1600-h/blackhat_seo_services_7.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SkICADIMPGI/AAAAAAAAD1w/fvmMH6LlRbo/s320/blackhat_seo_services_7.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SkICGV3bJVI/AAAAAAAAD14/CyzDzZOfcns/s1600-h/blackhat_seo_services_8.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SkICGV3bJVI/AAAAAAAAD14/CyzDzZOfcns/s320/blackhat_seo_services_8.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SkICMzb45EI/AAAAAAAAD2A/S_r8am00z10/s1600-h/blackhat_seo_services_9.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SkICMzb45EI/AAAAAAAAD2A/S_r8am00z10/s320/blackhat_seo_services_9.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;What took place in one second, was the generation of thousands of bogus accounts with descriptive blackhat SEO subdomains, with the bogus content pulled/scrapped from legitimate and real-time news providers, with the entire operation run as a managed service, or the tool itself offered for sale. As in every other managed underground service, customization plays a major role that is often the key benchmark for judging a particular product next to another. Customization in respect to this particular tool comes under the form of numerous Wordpress templates that can be randomly used during the registration process:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SkIP9tN-R8I/AAAAAAAAD2I/ZH6Fu91knyM/s1600-h/themes.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SkIP9tN-R8I/AAAAAAAAD2I/ZH6Fu91knyM/s320/themes.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Static customization is one thing, dynamic customization is entirely another. The product, and consequently the managed service are offering the ability to automatically add Ebay and Amazon listings with the user's unique affiliate code posted within the bogus content:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SkIQkvbwvWI/AAAAAAAAD2Q/EogMqWH_eVM/s1600-h/settings_admin.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SkIQkvbwvWI/AAAAAAAAD2Q/EogMqWH_eVM/s320/settings_admin.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SkITOPjk2eI/AAAAAAAAD2Y/1Mez1adVucY/s1600-h/twitter_spam_scheme.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SkITOPjk2eI/AAAAAAAAD2Y/1Mez1adVucY/s320/twitter_spam_scheme.jpg" /&gt;&lt;/a&gt;The practice of &lt;a href="http://www.fairwindspartners.com/en/newsroom/press-releases/june-22-2009"&gt;affiliate network fraud&lt;/a&gt; -- excluding the cybersquatting as a prerequisite for it success -- was recently mentioned as a much more lucrative fraudulent practice than the pay-per-click model, which entirely depends on the fraudster's knowledge of which is the monetization model with the highest pay-out rates:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;"&lt;i&gt;Some companies offer legitimate affiliate programs that allow third-party Web site owners to post links and banners with the company’s branded content on their site or to send traffic to the company’s site directly through domain forwards. In return, the owner of the site hosting the link receives a commission for every click-through that results in a purchase. This lucrative commission structure has enticed cybercriminals to take advantage of affiliate programs by registering typo domains that redirect to legitimate content and enable them to collect affiliate fees.&lt;/i&gt;"&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;Next to the malware/scareware serving Twitter campaigns, affiliate network fraud is also very common at the ever-growing micro-blogging service, whose lack of common sense account registration practices -- Twitter doesn't require a valid email, neither does it require an email confirmation upon registrating an account -- makes the practice of generating bogus accounts a child's play. &lt;br /&gt;&lt;br /&gt;The bottom line - is the managed blackhat SEO hosting service ($500 per month and $5000 for one year for unlimited domains/subdomains/traffic/disk space package) the future, or are we going to continue seeing the systematic abuse of legitimate service's infrastructure through outsourced CAPTCHA recognition? I'd go for the second due to a simple reason - it's more cost-effective than the managed service at least for the time being. In the long term, once it achieves its logical "malicious economies of scale" the hosting and process would become cheaper thereby attracting more customers.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Recommended reading -&lt;/b&gt;&lt;br /&gt;Outsourced CAPTCHA recognition:&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/02/community-driven-revenue-sharing-scheme.html"&gt;Community-driven Revenue Sharing Scheme for CAPTCHA Breaking&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/07/unbreakable-captcha.html"&gt;The Unbreakable CAPTCHA&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=1986"&gt;Spammers attacking Microsoft's CAPTCHA -- again&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=1514"&gt;Spam coming from free email providers increasing &lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=1418"&gt;Gmail, Yahoo and Hotmail’s CAPTCHA broken by spammers&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=1232"&gt;Microsoft’s CAPTCHA successfully broken&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/03/vladuzs-ebay-captcha-populator.html"&gt;Vladuz's Ebay CAPTCHA Populator&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/09/spammers-and-phishers-breaking-captchas.html"&gt;Spammers and Phishers Breaking CAPTCHAs&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/10/diy-captcha-breaking-service.html"&gt;DIY CAPTCHA Breaking Service&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/which-captcha-do-you-want-to-decode.html"&gt;Which CAPTCHA Do You Want to Decode Today?&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Managed Cybercrime-facilitating services/tools:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=2477"&gt;Commercial Twitter spamming tool hits the market&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/12/zeus-crimeware-as-service-going.html"&gt;Zeus Crimeware as a Service Going Mainstream&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html"&gt;Managed Fast-Flux Provider&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html"&gt;Managed Fast Flux Provider - Part Two&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/08/76service-cybercrime-as-service-going.html"&gt;76Service - Cybercrime as a Service Going Mainstream&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/03/inside-yet-another-managed-spam-service.html"&gt;Inside (Yet Another) Managed Spam Service&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/02/inside-diy-image-spam-generating.html"&gt;Inside a DIY Image Spam Generating Traffic Management Kit&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/02/quality-assurance-in-managed-spamming.html"&gt;Quality Assurance in a Managed Spamming Service&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html"&gt;Managed Spamming Appliances - The Future of Spam&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html"&gt;Dissecting a Managed Spamming Service&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/inside-managed-spam-service.html"&gt;Inside a Managed Spam Service&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=1899"&gt;Spamming vendor launches managed spamming service&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Cybersquatting/Per Pay Click Fraud:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/01/exposing-fraudulent-google-adwords.html"&gt;Exposing a Fraudulent Google AdWords Scheme&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=1200"&gt;Botnets committing click fraud observed&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/07/click-fraud-botnets-and-parked-domains.html"&gt;Click Fraud, Botnets and Parked Domains - All Inclusive&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/03/cybersquatting-security-vendors-for.html"&gt;Cybersquatting Security Vendors for Fraudulent Purposes&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/04/cybersquatting-symantecs-norton.html"&gt;Cybersquatting Symantec's Norton AntiVirus&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/state-of-typosquatting-2007.html"&gt;The State of Typosquatting - 2007&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-639761876014083481?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/639761876014083481'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/639761876014083481'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/06/peek-inside-managed-blackhat-seo.html' title='A Peek Inside the Managed Blackhat SEO Ecosystem'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wICHhTiQmrA/SkH5oDc4tJI/AAAAAAAAD0g/BhSv5oqpSoY/s72-c/black_seo_managed_services.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-91254404260654739</id><published>2009-06-17T18:36:00.004+02:00</published><updated>2009-06-17T21:42:11.223+02:00</updated><title type='text'>From Ukraine with Scareware Serving Tweets, Bogus LinkedIn/Scribd Accounts, and Blackhat SEO Farms</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SjjFBS1Rf_I/AAAAAAAADxw/8tX2t9E6GpA/s1600-h/twitter_scareware_ukrainian_blackhat_seo_1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SjjFBS1Rf_I/AAAAAAAADxw/8tX2t9E6GpA/s200/twitter_scareware_ukrainian_blackhat_seo_1.jpg" /&gt;&lt;/a&gt;&lt;b&gt;UPDATE: &lt;/b&gt;In less than half an hour upon notification, Twitter and LinkedIn have already removed the bogus accounts.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;UPDATE2:&lt;/b&gt; Forty five minutes later Scribd removes the bogus accounts.&lt;br /&gt;&lt;br /&gt;As usual, persistence must be met with persistence. A single &lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;blackhat SEO group&lt;/a&gt; -- if well analyzed and monitored -- has the potential to provide an insight into some of the current monetization tactics &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;which cybecriminals use&lt;/a&gt;, as well as directly demonstrate the (automatic) impact they have across different Web 2.0 services.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;What is my "&lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;fan club&lt;/a&gt;" up to anyway? Covering up their weekend's Twitter campaign that was serving scareware by using a new template, and once again diversifying - this time by managing a bogus LinkedIn accounts campaign, another one on Scribd, followed by another another currently active one on Twitter, in between increasing the size of their blackhat SEO farm at &lt;b&gt;is-the-boss.com&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;Moreover, for the first time ever, the group is starting to serve live exploits based on a bit.ly URL shortening service referrer, like the ones used in the latest Twitter campaign. The use of Arbitrary file download via the Microsoft Data Access Components (MDAC) exploits is done to ultimately drop a new &lt;a href="http://www.virustotal.com/analisis/1eb5fc834f22d5f1e5d7d82bf1c7d4df2e584734d19e82f72c7e7d45101143e2-1245245881"&gt;Koobface variant&lt;/a&gt;, making this &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;the second time the group is pushing Koobface variants&lt;/a&gt; beyond Facebook.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SjjFUBWvP1I/AAAAAAAADx4/bu8_TB1aznU/s1600-h/twitter_scareware_ukrainian_blackhat_seo_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SjjFUBWvP1I/AAAAAAAADx4/bu8_TB1aznU/s200/twitter_scareware_ukrainian_blackhat_seo_3.JPG" /&gt;&lt;/a&gt;Let's summarize their activities during the past six days starting with the weekend's campaign across Twitter.&lt;br /&gt;&lt;br /&gt;Upon clicking on the TinyURL, the user is redirected through their well known &lt;b&gt;66.199.229 .253/etds&lt;/b&gt; (&lt;b&gt;66.199.229 .253&lt;/b&gt;/etds/go.php?sid=41; &lt;b&gt;66.199.229 .253&lt;/b&gt;/etds/got.php?sid=41; &lt;b&gt;66.199.229 .253&lt;/b&gt;/etds/go.php?sid=43; &lt;b&gt;66.199.229 .253&lt;/b&gt;/etds/got.php?sid=43) traffic management location, to end up at the scareware &lt;b&gt;av4best .net&lt;/b&gt; (64.86.17.47) with a new template is served (&lt;a href="http://www.virustotal.com/analisis/576f4127e85ab6ce355f0eec612bb0d24355f626e71ab6e2585a596e02563ec1-1244840273"&gt;FakeAlert-EA&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SjjJj7BfL-I/AAAAAAAADyA/OWVeLMKnNRQ/s1600-h/twitter_scareware_ukrainian_blackhat_seo_4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SjjJj7BfL-I/AAAAAAAADyA/OWVeLMKnNRQ/s200/twitter_scareware_ukrainian_blackhat_seo_4.JPG" /&gt;&lt;/a&gt;Parked on the same IP are also well known scareware domains known from their previous campaigns, namely &lt;b&gt;fast-antivirus .com&lt;/b&gt; and &lt;b&gt;viruscatcher .net&lt;/b&gt;. The scareware message used in the new template takes you back to the good old school MS-DOS days :&lt;br /&gt;&lt;br /&gt;"&lt;i&gt;A problem has been detected and windows has been shut down to prevent damage to your computer. &lt;br /&gt;&lt;br /&gt;Initialization_failed C:\WINDOWS\system32\himem.sys&lt;br /&gt;&lt;br /&gt;If this is the first time you've seen this Stop error screen, restart the computer. If this screen appears again, read information below: The reason why this might happen is the newest malicious software which blocks access to the system libraries. Check to make sure any new antivirus software is properly installed. We suggest you to download and install antivirus, new up-to-date software which specializes on detection and removal of malicious and suspicious software.&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;The messaged used in the weekend's Twitter campaign, as well as a graph on the peaks and downds for a particular keyword:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SjjeEFc6eNI/AAAAAAAADyI/etrx6QcrTxs/s1600-h/twitter_scareware_ukrainian_blackhat_seo_4_sample_account_themes_timeframe.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SjjeEFc6eNI/AAAAAAAADyI/etrx6QcrTxs/s200/twitter_scareware_ukrainian_blackhat_seo_4_sample_account_themes_timeframe.JPG" /&gt;&lt;/a&gt;"&lt;i&gt;Competitions video; What do you think about video; I know why Percent Of Accounts; Between food and gay; movie Trailler!; Sun eclipce free; Air France extreem; Tetris long and sweet; Take sex under control; alcohol long and sweet; Between food and SATs; What do you think about Autotune; Gotcha!, Palm Pre!; Goodnight high in the sky; What do you think about Hangover; Death of Autotune crack addict; Amazing. movie from MSFT; Amazing. Air France from MSFT; Sims 3, It's Cool!; video, It's Cool!; Manage Air France; Amazing. porn from MSFT; alcohol unbroken; Them girls Honduras; Between food and phish; Between food and Detroit; Tetris high in the sky; I know why iPhone; Futurama unbroken; Balls to the Woman Who Missed Air; alcohol high in the sky; follow the video&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;Sample (now suspended) automatically registered accounts used in the weekend's campaign:&lt;br /&gt;&lt;b&gt;twitter .com/wenning351&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/ula475&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/escher338&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/ochs40&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/karlen131&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/cordes904&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/hecker905&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/bohl566&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/sattler649&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/hildegard115&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/andreas281&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/wassermann38&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/rummel980&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/guilaine896&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/orlowski781&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/rupette972&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/holzner473&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/dumke576&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/hilgers465&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/heese157&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/meier679&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/habel896&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/holzinger567&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/wilhelm578&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/dearg450&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/habicht717&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/ferde373&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter.com/hass323&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/heckmann918&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/bruna555&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/wilbert25&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/eckart412&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/sperlich374&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/jahn562&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/ludvig30&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/bing274&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/fett628&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/brock93&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/mally981&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/merle752&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/axmann101&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/pelz478&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/renaud687&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/wienke879&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/hartinger619&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/chriselda988&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/kloos267&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/dreyer15&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/herta740&lt;br /&gt;twitter .com/brauer427&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/nadina732&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/wenda245&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/rieken434&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter.com/reinhard192&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/plath132&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/bick497&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/johannsen747&lt;/b&gt;&lt;br /&gt;&lt;b&gt;twitter .com/tacke432&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Besides the TinyURL links used, they've also returned to temporarily using their original .us domains such as &lt;b&gt;twitter .8w8.us&lt;/b&gt; - 82.146.51.126 - Email: ambersurman@gmail.com; &lt;b&gt;5us .us&lt;/b&gt; - 82.146.51.25 - Email: elchip0707@mail.ru, and &lt;b&gt;girlstubes .cn&lt;/b&gt;&amp;nbsp; 82.146.52.158 - Email: alexvasiliev1987@cocainmail.com with Alex Vasiliev's emails first noticed in the &lt;a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_16.html"&gt;Diverse Portfolio of Fake Security Software - Part Nine&lt;/a&gt; and again in &lt;a href="http://ddanchev.blogspot.com/2009/05/diverse-portfolio-of-fake-security.html"&gt;Part Twenty&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SjjCptNXXwI/AAAAAAAADxo/kZhsxN52WfU/s1600-h/twitter_nude_scareware_campaign_ukraine_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SjjCptNXXwI/AAAAAAAADxo/kZhsxN52WfU/s200/twitter_nude_scareware_campaign_ukraine_2.JPG" /&gt;&lt;/a&gt;Now it's time to assess their currently active campaigns across Twitter, LinkedIn and Scribd, and connect the dots in the face of the single URL acting as a counter across all the campaigns - &lt;b&gt;counteringate .com&lt;/b&gt; (194.165.4.77) which has already been profiled in their &lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;original massive blackhat SEO campaign&lt;/a&gt;, and still remains active.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SjjsK2JJxlI/AAAAAAAADyQ/EPyGloyEozE/s1600-h/twitter_nude_scareware_campaign_ukraine_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SjjsK2JJxlI/AAAAAAAADyQ/EPyGloyEozE/s200/twitter_nude_scareware_campaign_ukraine_3.JPG" /&gt;&lt;/a&gt;The automatically registered and currently active Twitter accounts participating in the campaign are as follows, it's also worth pointing out that compared to their previous campaigns, in this way they've included relevant backgrounds and avatars to the Twitter accounts:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;b&gt;twitter .com/AshleyTisdal1&lt;br /&gt;twitter .com/AnnaNicoleSmit&lt;br /&gt;twitter .com/ParisHiltonjpg1&lt;br /&gt;twitter .com/ParisHiltonmov1&lt;br /&gt;twitter .com/ParisHiltonNake&lt;br /&gt;twitter .com/ParisHiltonSex1&lt;br /&gt;twitter .com/ParisHiltonNud2&lt;br /&gt;twitter .com/ParisSexTape2&lt;br /&gt;twitter .com/Britneynipslip1&lt;br /&gt;twitter .com/Britneywomani&lt;br /&gt;twitter .com/Britneystrip1&lt;br /&gt;twitter .com/BritneySex&lt;br /&gt;twitter .com/Britneycomix&lt;br /&gt;twitter .com/Britneywomaniz&lt;br /&gt;twitter .com/BritneyNaked2&lt;br /&gt;twitter .com/britneysextape&lt;br /&gt;twitter .com/BritneyxSpears1&lt;br /&gt;twitter .com/Britneydesnuda1&lt;/b&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SjjspQDJhnI/AAAAAAAADyg/lcpAXv0VrME/s1600-h/twitter_nude_scareware_campaign_ukraine_4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SjjspQDJhnI/AAAAAAAADyg/lcpAXv0VrME/s200/twitter_nude_scareware_campaign_ukraine_4.JPG" /&gt;&lt;/a&gt;&lt;b&gt;&lt;br /&gt;twitter .com/LopezAss&lt;br /&gt;twitter .com/jennifermorriso&lt;br /&gt;twitter .com/JenniferTilly2&lt;br /&gt;twitter .com/AnistonSexscen&lt;br /&gt;twitter .com/AnistonBangs&lt;br /&gt;twitter .com/JenniferTilly1&lt;br /&gt;twitter .com/Jennifernude&lt;br /&gt;twitter .com/JenniferConnel&lt;br /&gt;twitter .com/JenniferGarner1&lt;br /&gt;twitter .com/LopezNaked&lt;br /&gt;twitter .com/AnistonSexiest&lt;br /&gt;twitter .com/JenniferAnisto4&lt;br /&gt;twitter .com/JenniferToastee&lt;/b&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Sjjs8lO0mqI/AAAAAAAADyo/Rkgt21OTTe4/s1600-h/twitter_nude_scareware_campaign_ukraine_5.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Sjjs8lO0mqI/AAAAAAAADyo/Rkgt21OTTe4/s200/twitter_nude_scareware_campaign_ukraine_5.JPG" /&gt;&lt;/a&gt;&lt;b&gt;&lt;br /&gt;twitter .com/JenniferAnisto2&lt;br /&gt;twitter .com/LoveHewitt1&lt;br /&gt;twitter .com/JenniferLoveH1&lt;br /&gt;twitter .com/JenniferGreyn&lt;br /&gt;twitter .com/1JenniferAnisto&lt;br /&gt;twitter .com/2JenniferAnisto&lt;br /&gt;twitter .com/1JenniferLopez&lt;br /&gt;twitter .com/Lopedesnuda1&lt;br /&gt;twitter .com/ElishaCuthbert3&lt;/b&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SjjtJ6EnKLI/AAAAAAAADyw/jhTo5Vf0HM4/s1600-h/twitter_nude_scareware_campaign_ukraine_6.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SjjtJ6EnKLI/AAAAAAAADyw/jhTo5Vf0HM4/s200/twitter_nude_scareware_campaign_ukraine_6.JPG" /&gt;&lt;/a&gt;&lt;b&gt;&lt;br /&gt;twitter .com/ElishaCuthbert1&lt;br /&gt;twitter .com/AlysonHannigan2&lt;br /&gt;twitter .com/AliciaMachado&lt;br /&gt;twitter .com/AliLarterNaked&lt;br /&gt;/twitter .com/AliLarterNude&lt;br /&gt;twitter .com/MelissaJoanha&lt;br /&gt;twitter .com/AishwaryaRaiN1&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SjjwGirzlRI/AAAAAAAADy4/CPioG84qZQ8/s1600-h/twitter_nude_scareware_campaign_ukraine_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SjjwGirzlRI/AAAAAAAADy4/CPioG84qZQ8/s200/twitter_nude_scareware_campaign_ukraine_7.png" /&gt;&lt;/a&gt;Upon clicking on &lt;b&gt;bit .ly/Je2Sd&lt;/b&gt;, the user is redirected to &lt;b&gt;oymomahon .com&lt;/b&gt;/mirolim-video/3.html - 216.32.86.106 Email: StaceyGuerreroSF@gmail.com, redirecting to &lt;b&gt;myhealtharea .cn&lt;/b&gt;/in.cgi?13 and then to &lt;b&gt;oymoma-tube .freehostia.com&lt;/b&gt;/x-tube.htm where the fake codec/scareware is served, downloaded from &lt;b&gt;totalsitesarchive .com&lt;/b&gt;/error.php?id=62 - &lt;a href="http://www.virustotal.com/analisis/d8e886b0f36b03f54a2d5823ecbf4602333f69fb9ce6a5160e003088cc8b2bdb-1245218571"&gt;Trojan.Win32.FakeAV.nz&lt;/a&gt; which once executed phones back to &lt;b&gt;bestyourtrust .com&lt;/b&gt;/in.php?url=5&amp;amp;affid=00262 (209.44.126.241) parked at the same IP are also the following scareware domains:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;uniqtrustedweb .com &lt;br /&gt;hortshieldpc .com&lt;br /&gt;securetopshield .com&lt;br /&gt;gisecurityshield .com&lt;br /&gt;ourbestsecurityshield .com&lt;br /&gt;intellectsecfind .com&lt;br /&gt;thesecuritytree .com&lt;br /&gt;godsecurityarchive .com&lt;br /&gt;besecurityguardian .com&lt;br /&gt;thefirstupper .com&lt;br /&gt;securityshieldcenter .com&lt;br /&gt;bitsecuritycenter .com&lt;br /&gt;joinsecuritytools .com&lt;br /&gt;hupersecuritydot .com&lt;br /&gt;bestyourtrust .com&lt;br /&gt;thetrueshiledsecurity .com&lt;br /&gt;souptotalsecurity .com&lt;br /&gt;scantrustsecurity .com&lt;/b&gt;&lt;br /&gt;&amp;nbsp; &lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SjjA2uHgJMI/AAAAAAAADxg/6TBmqwwm67g/s1600-h/twitter_nude_scareware_campaign_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SjjA2uHgJMI/AAAAAAAADxg/6TBmqwwm67g/s200/twitter_nude_scareware_campaign_1.JPG" /&gt;&lt;/a&gt;The second &lt;b&gt;bit .ly/1a5ZsY&lt;/b&gt; link used in the Twitter campaign, is redirecting to &lt;b&gt;showmealltube .com&lt;/b&gt;/paqi-video/7.html - 64.92.170.135 Email: zbestgotterflythe@gmail.com.&lt;br /&gt;&lt;br /&gt;From there, the redirector &lt;b&gt;myhealtharea .cn&lt;/b&gt;/in.cgi?12 - 216.32.83.110 - zbest2008@mail.ru again loads &lt;b&gt;oymoma-tube.freehostia .com&lt;/b&gt;/tube.htm and most importantly the counter &lt;b&gt;counteringate .com&lt;/b&gt;/count.php?id=186 which is using &lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;an IP known from their previous campaign&lt;/a&gt; (194.165.4.77).&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Sjj7bGF3pgI/AAAAAAAADzA/yhJ0-X6LnZU/s1600-h/linkedin_bogus_malware_player_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Sjj7bGF3pgI/AAAAAAAADzA/yhJ0-X6LnZU/s200/linkedin_bogus_malware_player_2.png" /&gt;&lt;/a&gt;Time to move on to the LinkedIn campaign, and establish a direct connection with the Twitter one, both maintained by the same group of cybercriminals. &lt;br /&gt;&lt;br /&gt;Currently active and participating LinkedIn accounts:&lt;br /&gt;&lt;b&gt;linkedin .com/in/rihannanude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/rihannanude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/nudecelebs&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/britneyspearsnudee&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/pamelaandersonnudee&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/nudepreteen2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/tilatequilanudee&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/pub/beyonce-nude/14/b/952&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/pub/child-nude/13/b4b/a16&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/nudemodels&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Sjj7p2SR_2I/AAAAAAAADzI/n_hwzvKRHu8/s1600-h/linkedin_bogus_malware_player_june_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Sjj7p2SR_2I/AAAAAAAADzI/n_hwzvKRHu8/s200/linkedin_bogus_malware_player_june_3.png" /&gt;&lt;/a&gt;&lt;b&gt;linkedin .com/in/preteennude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/mariahcareynude3&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/nudeboys&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/evamendesnude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/nudebeaches&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/nudebabes&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/in/nudewomen2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/pub/ashley-tisdale-nude/13/b4b/762&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/pub/mila-kunis-nude/13/b4a/b99&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/pub/nude-kids/13/b4b/aa&lt;/b&gt;&lt;br /&gt;&lt;b&gt;linkedin .com/pub/young-nude-girls/13/b4a/6a&lt;/b&gt;&lt;br /&gt;&amp;nbsp; &lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Sjj82UPGCKI/AAAAAAAADzQ/6tZOLjH6hB4/s1600-h/linkedin_bogus_malware_player_june_1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Sjj82UPGCKI/AAAAAAAADzQ/6tZOLjH6hB4/s200/linkedin_bogus_malware_player_june_1.jpg" /&gt;&lt;/a&gt;The LinkedIn campaign is linking to the &lt;b&gt;delshikandco .com&lt;/b&gt;, from where the user is redirected to the same domains used in the Twitter campaign, sharing the same celebrity theme - &lt;b&gt;delshikandco .com&lt;/b&gt;/mirolim-video/3.html/&lt;b&gt;delshikandco .com&lt;/b&gt;/paqi-video/1.html - 216.32.83.104 leads to &lt;b&gt;myhealtharea .cn&lt;/b&gt;/in.cgi?12 to finally serve the codec at &lt;b&gt;ymoma-tube.freehostia.com&lt;/b&gt;/xxxtube.htm or at&lt;b&gt; tubes-portal.com&lt;/b&gt;/xplaymovie.php?id=40012 -  216.240.143.7, another &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html"&gt;IP that has already been profiled part of their previous campaigns&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Yet another nude themed campaign is operated by the same group at Scribd, linking to the already profiled &lt;b&gt;delshikandco .com&lt;/b&gt;, used in both, Twitter's and LinkedIn's campaigns.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Sjj_q-G4bgI/AAAAAAAADzY/gKYleoUf5Y0/s1600-h/scribd_scareware_ukraine_1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Sjj_q-G4bgI/AAAAAAAADzY/gKYleoUf5Y0/s200/scribd_scareware_ukraine_1.png" /&gt;&lt;/a&gt;Currently active and participating Scribd accounts:&lt;br /&gt;&lt;b&gt;scribd .com/Stacy%20Keibler-nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Vanessa_Hudgens%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Jessica%20%20Simpson%20%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/MileyCyrus%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/KimKardashian%20%E2%80%98nude%E2%80%99&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Carmen%20%20Electra%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Jennifer%20Anistonnude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Paris-Hilton-nude3&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Vida%20%20Guerra%20%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Kim%20%20Kardashian%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/ZacEfron%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/BritneySpears%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Hilary-Duff-nude%202&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Angelina-Jolie-nude11&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Vanessa-Hudgens-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Natalie-Portman-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/JessicaAlba%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Jennifer-Love-Hewitt-nude11&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Sjj_y6vv4MI/AAAAAAAADzg/jSJVMCSQ1jY/s1600-h/scribd_scareware_ukraine_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Sjj_y6vv4MI/AAAAAAAADzg/jSJVMCSQ1jY/s200/scribd_scareware_ukraine_2.png" /&gt;&lt;/a&gt;&lt;b&gt;scribd .com/Kim-Kardashian-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Jessica-Alba-nude11s&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/JENNIFER%20LOPEZ%20NUDE3&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Elisha%20%20Cuthbert%20%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Paris-Hilton-nude1&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/HilaryDuff%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Megan-Fox-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Britney-Spears-nude1&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Candice%20%20Michelle%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Lindsay-Lohan-nude3&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Mila-Kunis-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Miley%20Cyrus%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Vanessa%20%20Anne%20%20Hudgens%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/rihanna-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Jenny%20Mccarthy%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Kim%20%20Kardashian%20%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Olsen-Twins-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Brooke-Hogan-nude2&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Sjj_6cmZaeI/AAAAAAAADzo/eb2twG-L5Ds/s1600-h/scribd_scareware_ukraine_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Sjj_6cmZaeI/AAAAAAAADzo/eb2twG-L5Ds/s200/scribd_scareware_ukraine_3.png" /&gt;&lt;/a&gt;&lt;b&gt;scribd .com/DeniseRichardsnude2&lt;br /&gt;scribd .com/Scarlett%20Johansson%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/miley-cyrus-nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Celebrity%20%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Lindsay-Lohan-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Tila%20Tequila%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Ashley%20Tisdale%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd.com/Angelina-Jolie-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Denise-Richards-nude-2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Britney%20Spears%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Hayden%20Panettiere%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Carmen-Electra-nude1&lt;br /&gt;scribd .com/Brooke-Burke-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Megan%20Fox%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/JessicaSimpson%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Kendra-Wilkinson-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/DeniseRichardsnude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd.com/AngelinaJolie%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd.com/Kate%20Mara%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Eva%20Green%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Mariah%20Carey%20nude&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SjkACaccU1I/AAAAAAAADzw/MW9H6vj0CcQ/s1600-h/scribd_scareware_ukraine_4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SjkACaccU1I/AAAAAAAADzw/MW9H6vj0CcQ/s200/scribd_scareware_ukraine_4.png" /&gt;&lt;/a&gt;&lt;b&gt;scribd .com/Britney-Spears-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Paris%20Hilton%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/CHristina%20Applegate%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Billie%20Piper%20nude&lt;br /&gt;scribd .com/Rosario%20Dawson%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Anna%20Kournikova%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Jennifer-Love-Hewitt-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Kate%20Winslet%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Carmen%20Electra%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Jennifer%20Love%20Hewitt%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Vida%20Guerra%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/AnneHathaway%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/JenniferLopez_nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Trish%20Stratus%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Lindsay_Lohannude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Pamela%20Anderson%20nude3&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Jessica-Simpson-nude3&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SjkAH5N9ZyI/AAAAAAAADz4/2iTpog0xn2Y/s1600-h/scribd_scareware_ukraine_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SjkAH5N9ZyI/AAAAAAAADz4/2iTpog0xn2Y/s200/scribd_scareware_ukraine_5.png" /&gt;&lt;/a&gt;&lt;b&gt;scribd .com/JENNIFER%20LOPEZ%20NUDE&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/CHristina%20Aguilera%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/hilary%20duff%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/MariahCarey%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/JohnCena%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Halle%20Berry%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Amanda%20%20Beard%20%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Patricia%20%20Heaton%20%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Madonna%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/JenniferLopez%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/DeniseRichards%20nude&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SjkA9_jbMYI/AAAAAAAAD0A/-OGQt9cH-yo/s1600-h/scribd_scareware_ukraine_6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SjkA9_jbMYI/AAAAAAAAD0A/-OGQt9cH-yo/s200/scribd_scareware_ukraine_6.png" /&gt;&lt;/a&gt;&lt;b&gt;scribd .com/PatriciaHeaton%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Celebrity%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/TilaTequila_nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Hayden-Panettiere-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Brenda-Song-nude2&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Demi%20Moore%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/celebrity%20nude%201&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/JenniferLove%20Hewitt%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Ashley_Harkleroad%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/AudrinaPatridge%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/PamelaAnderson%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Anna%20Nicole%20Smithnude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Meg%20Ryan%20nude&lt;/b&gt;&lt;br /&gt;&lt;b&gt;scribd .com/Kate%20Hudsonnude&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Now that all the campaigns are exposed in the naked fashion of their themes, it's worth emphasizing on the live exploits serving Koobface samples based on a bit.ly referrer - in this case the process takes place through &lt;b&gt;myhealtharea .cn&lt;/b&gt;/in.cgi?13, which instead of redirecting to scareware domain as analyzed above, is redirecting to fast-fluxed set of IPs serving identical &lt;a href="http://www.virustotal.com/analisis/1eb5fc834f22d5f1e5d7d82bf1c7d4df2e584734d19e82f72c7e7d45101143e2-1245253380"&gt;Koobface binary&lt;/a&gt; - &lt;b&gt;myhealtharea .cn&lt;/b&gt;/in.cgi?13 loads &lt;b&gt;r-cg100609 .com&lt;/b&gt;/go/?pid=30455&amp;amp;type=videxp (92.38.0.69) which redirectss to the live exploits/Koobface.&lt;br /&gt;&lt;br /&gt;Parked on 92.38.0.69 are also the following domains:&lt;br /&gt;&lt;b&gt;er20090515 .com&lt;br /&gt;upr0306 .com&lt;br /&gt;cgpay0406 .com&lt;br /&gt;r-cgpay-15062009 .com&lt;br /&gt;r-cg100609 .com&lt;br /&gt;trisem .com&lt;br /&gt;uprtrishest .com&lt;br /&gt;upr15may .com&lt;br /&gt;rd040609-cgpay .net&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Dynamic redirectors from &lt;b&gt;r-cg100609 .com&lt;/b&gt;/go/?pid=30455&amp;amp;type=videxp on per session basis:&lt;br /&gt;&lt;b&gt;92.255.131 .217/pid=30455/type=videxp/?ch=&amp;amp;ea=&lt;br /&gt;92.255.131 .217/pid=30455/type=videxp/setup.exe&lt;br /&gt;76.229.152 .148/pid=30455/type=videxp/?ch=&amp;amp;ea=&lt;br /&gt;76.229.152 .148/pid=30455/type=videxp/?ch=&amp;amp;ea=/setup.exe&lt;br /&gt;189.97.106 .121/pid=30455/type=videxp/?ch=&amp;amp;ea=&lt;br /&gt;189.97.106 .121/pid=30455/type=videxp/setup.exe&lt;br /&gt;117.198.91 .99/pid=30455/type=videxp/?ch=&amp;amp;ea=&lt;br /&gt;117.198.91 .99/pid=30455/type=videxp/setup.exe&lt;br /&gt;79.18.18 .29/pid=30455/type=videxp/?ch=&amp;amp;ea=&lt;br /&gt;79.18.18 .29/pid=30455/type=videxp/setup.exe&lt;br /&gt;85.253.62 .53/pid=30455/type=videxp/?ch=&amp;amp;ea=&lt;br /&gt;85.253.62 .53/pid=30455/type=videxp/setup.exe&lt;br /&gt;79.164.220 .170/pid=30455/type=videxp/?ch=&amp;amp;ea=&lt;br /&gt;79.164.220 .170/pid=30455/type=videxp/setup.exe&lt;br /&gt;59.98.104 .129/pid=30455/type=videxp/?ch=&amp;amp;ea=&lt;br /&gt;59.98.104 .129/pid=30455/type=videxp/setup.exe&lt;br /&gt;78.43.24 .211/pid=30455/type=videxp/?ch=&amp;amp;ea=&lt;br /&gt;78.43.24 .211/pid=30455/type=videxp/setup.exe&lt;br /&gt;62.98.63 .254/pid=30455/type=videxp/?ch=&amp;amp;ea=&lt;br /&gt;62.98.63 .254/pid=30455/type=videxp/setup.exe&lt;br /&gt;84.176.74 .231/pid=30455/type=videxp/?ch=&amp;amp;ea=&lt;br /&gt;84.176.74 .231/pid=30455/type=videxp/setup.exe&lt;/b&gt;&lt;br /&gt;&lt;b&gt;panmap .in&lt;/b&gt;/html/3003/25ee551429fcbfd75fe7bcfeba4a9cb8/ - 114.80.67.32 - charicard@googlemail.com&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SjkRQkjnzTI/AAAAAAAAD0I/aHVDDyuc924/s1600-h/ukraine_blackhat_seo_1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SjkRQkjnzTI/AAAAAAAAD0I/aHVDDyuc924/s200/ukraine_blackhat_seo_1.png" /&gt;&lt;/a&gt;Parked on 114.80.67.32 are also:&lt;br /&gt;&lt;b&gt;managesystem32.com&lt;br /&gt;napipsec.in&lt;br /&gt;trialoc.in&lt;br /&gt;pbcofig.in&lt;br /&gt;pclxl.in&lt;br /&gt;ifxcardm.in&lt;br /&gt;ifmon.in&lt;br /&gt;panmap.in&lt;br /&gt;moricons.in&lt;br /&gt;oeimport.in&lt;br /&gt;ncprov.in&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;The served setup.exe (Win32/Koobface.BC; Worm:Win32/Koobface.gen!D;) samples phone back to a single location:&lt;b&gt;- upr15may .com&lt;/b&gt;/achcheck.php; &lt;b&gt;upr15may .com&lt;/b&gt;/ld/gen.php - 92.38.0.69; &lt;b&gt;61.235.117 .71&lt;/b&gt;/files/pdrv.exe&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SjkRaLF2NXI/AAAAAAAAD0Q/E68yxzmTN4c/s1600-h/ukraine_blackhat_seo_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SjkRaLF2NXI/AAAAAAAAD0Q/E68yxzmTN4c/s200/ukraine_blackhat_seo_2.png" /&gt;&lt;/a&gt;To further demonstrate the group's involvement in these campaigns, two active campaigns at &lt;b&gt;is-the-boss.com&lt;/b&gt; indicate that they're also using the newly introduced counteringate.com, however, parked on the same IP as a previously analyzed redirector maintained bot the group.&lt;br /&gt;&lt;br /&gt;A sample campaign is using the &lt;b&gt;engseo .net&lt;/b&gt;/sutra/in.cgi?4&amp;amp;parameter=bravoerotica - 84.16.230.38 - Email: popkadyp@gmail.com as well as the &lt;b&gt;warwork .info&lt;/b&gt;/cgi-bin/counter?id=945706&amp;amp;k=independent&amp;amp;ref= - 91.207.61.48 redirectors to load &lt;b&gt;free-porn-video-free-porn .com&lt;/b&gt;/1/index.php?q=bravoerotica - 84.16.230.38 - Email: popkadyp@gmail.com serving &lt;a href="http://www.virustotal.com/analisis/81ac44b2150e87850fc28d228f0a7680a1b6d4fd132217288417fed29e1a45ee-1245219986"&gt;a fake codec&lt;/a&gt;, and is also using the universal counter serving maintained by group &lt;b&gt;counteringate .com&lt;/b&gt;/count.php?id=308.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;A second sampled campaign at is-the-boss.com points to a new domain that is once again parked at a well known &lt;a href="http://ddanchev.blogspot.com/2009/05/dissecting-swine-flu-black-seo-campaign.html"&gt;IP mainted by the gang&lt;/a&gt; - &lt;b&gt;goldeninternetsites .com&lt;/b&gt;/go.php?id=2022&amp;amp;key=4c69e59ac&amp;amp;p=1 - 83.133.123.140 - known from &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;previous campaigns&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The redirectors lead to &lt;b&gt;anti-virussecurity3 .com&lt;/b&gt; - 69.4.230.204; 69.10.59.34; 83.133.115.9; 91.212.65.125 with more typosquatted "&lt;a href="http://www.virustotal.com/analisis/50f23f314bd40d05bfed00a042da936f98ffe7af81d52777a795275955a40ec6-1245221372"&gt;Personal Antivirus&lt;/a&gt;" scareware parked at these multiple IPs aimed to increase the life cycle of the campaign:&lt;br /&gt;&lt;b&gt;bestantiviruscheck2 .com&lt;br /&gt;securitypcscanner2 .com&lt;br /&gt;fastpcscan3 .com&lt;br /&gt;goodantivirusprotection3 .com&lt;br /&gt;antimalware-online-scanv3 .com&lt;br /&gt;anti-malware-internet-scanv3 .com&lt;br /&gt;antimalwareinternetproscanv3 .com&lt;br /&gt;antimalwareonlinescannerv3 .com&lt;br /&gt;anti-virussecurity3 .com&lt;br /&gt;bestantispywarescanner4 .com&lt;br /&gt;fastsecurityupdateserver .com&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SjkT5SXm2cI/AAAAAAAAD0Y/WVv6UqYQZ1A/s1600-h/personal_antivirus_scareware.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SjkT5SXm2cI/AAAAAAAAD0Y/WVv6UqYQZ1A/s200/personal_antivirus_scareware.png" /&gt;&lt;/a&gt;Personal Antivirus then phones back to &lt;b&gt;startupupdates .com&lt;/b&gt; - 83.133.123.140 where more scareware is parked, with the domains known from previous campaigns:&lt;br /&gt;&lt;b&gt;bestwebsitesin2009 .com&lt;br /&gt;live-payment-system .com&lt;br /&gt;bestbuysoftwaresystem .com&lt;br /&gt;antiviruspaymentsystem .com&lt;br /&gt;bestbuysystem .com&lt;br /&gt;homeandofficefun .com&lt;br /&gt;advanedmalwarescanner .com&lt;br /&gt;allinternetfreebies .com&lt;br /&gt;goldeninternetsites .com &lt;br /&gt;primetimeworldnews .com&lt;br /&gt;liveavantbrowser2 .cn&lt;br /&gt;momentstohaveyou .cn&lt;br /&gt;worldofwarcry .cn&lt;br /&gt;awardspacelooksbig .us&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The affected services have been notified, blacklisting and take down of the participating domains is in progress.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;This post has been reproduced from &lt;a href="http://ddanchev.blogspot.com/"&gt;Dancho Danchev's blog&lt;/a&gt;. &lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-91254404260654739?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/91254404260654739'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/91254404260654739'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/06/from-ukraine-with-scareware-serving.html' title='From Ukraine with Scareware Serving Tweets, Bogus LinkedIn/Scribd Accounts, and Blackhat SEO Farms'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_wICHhTiQmrA/SjjFBS1Rf_I/AAAAAAAADxw/8tX2t9E6GpA/s72-c/twitter_scareware_ukrainian_blackhat_seo_1.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-242480730804807839</id><published>2009-06-16T12:53:00.003+02:00</published><updated>2009-06-17T05:22:56.327+02:00</updated><title type='text'>Iranian Opposition DDoS-es pro-Ahmadinejad Sites</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sjdpqins2RI/AAAAAAAADwQ/s0_ljGgxMqo/s1600-h/iranian_pro-Ahmadinejad_site_attack_9.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sjdpqins2RI/AAAAAAAADwQ/s0_ljGgxMqo/s200/iranian_pro-Ahmadinejad_site_attack_9.png" /&gt;&lt;/a&gt;By utilizing the people's information warfare concept, Iranian opposition has managed to &lt;b&gt;&lt;a href="http://blogs.zdnet.com/security/?p=3613"&gt;successfully organize a cyber attack against Tehran's regime&lt;/a&gt;&lt;/b&gt; (complete analysis) by using Twitter, web forums, and localization (translation) of the recruitment messages in order to seek assistance from foreigners.&lt;br /&gt;&lt;br /&gt;So far, their rather simplistic denial of service tools has managed to disrupt access to key government web sites, and the intensity of the attacks is prone to increase since the opposition appears to be in a "learning mode".&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SjhhZuV4CiI/AAAAAAAADxY/iR9N4-07Dzc/s1600-h/green_revolution_ddos.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SjhhZuV4CiI/AAAAAAAADxY/iR9N4-07Dzc/s200/green_revolution_ddos.JPG" /&gt;&lt;/a&gt;What does "learning mode" stand for here? It's their current stage of experimentation clearly indicating their inexperience with such campaigns and DDoS attacks in general. The opposition's de-centralized chain of command isn't even speculating on the use of botnets, since the primitive multi-threaded Iranian connections hitting Iranian sites seems to achieve their effect.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Sjdt7xR0lYI/AAAAAAAADwY/PidddcdRtVM/s1600-h/iranian_pro-Ahmadinejad_site_attack_10.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Sjdt7xR0lYI/AAAAAAAADwY/PidddcdRtVM/s200/iranian_pro-Ahmadinejad_site_attack_10.png" /&gt;&lt;/a&gt;From a strategic perspective, this internal unrest resulting in the disruption of key government web sites, the de-facto propaganda vehicles of the current government, is directly denying their ability to influence the population and the media, which on its way to find information is inevitably going to visit the working opposition web sites.&lt;br /&gt;&lt;br /&gt;Moreover, the majority of people's information warfare driven cyber attacks we've seen during the past two years, have all been orbiting around the scenario where a foreign adversary is attacking your infrastructure from all over the world. But in the current situation, it's Iran's internal network that's self-eating itself, where the trade off for denying all the traffic would be the traffic which could be potentially influenced through PSYOPs (psychological operations).&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Sjd3C-GmhpI/AAAAAAAADxA/jvUiTMlm5Yw/s1600-h/page_reboot_iran_ddos_attacks.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Sjd3C-GmhpI/AAAAAAAADxA/jvUiTMlm5Yw/s200/page_reboot_iran_ddos_attacks.png" /&gt;&lt;/a&gt;What has changed since &lt;a href="http://blogs.zdnet.com/security/?p=3613"&gt;yesterday's real-time OSINT analysis&lt;/a&gt;?&amp;nbsp; The web based "Page Rebooter" tool heavily advertised by the opposition has decided to stop offering the service due to the massive abuse:&lt;br /&gt;&lt;br /&gt;"&lt;i&gt;Unfortunately I have had to take the site down temporarily. The site was being used to attack other websites, until I can determine the source of these attacks, I have decided to keep it offline. My apologies to everyone who uses this site for it's intended purpose, hopefully we'll be back soon. I have now received several emails regarding this. Unfortunately, last night's spike in traffic cost me a lot of money in server costs, I therefore cannot afford to keep it online - even if the use is just. I have therefore decided to release the code for this site, so that you may create your own copies.&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;Meanwhile, the opposition has come up with a segmented targets list including hardline news portals, official Ahmadinejad sites, Iranian law enforcement sites, banks, judiciary and transportation sites, aiming to recruit international supporters:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SjdxDA56COI/AAAAAAAADwg/XrT1QGT3L-Y/s1600-h/iranian_pro-Ahmadinejad_site_attack_flood_script.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SjdxDA56COI/AAAAAAAADwg/XrT1QGT3L-Y/s200/iranian_pro-Ahmadinejad_site_attack_flood_script.jpg" /&gt;&lt;/a&gt;"&lt;i&gt;ALL PEOPLE AROUND THE WORLD:&lt;br /&gt;&lt;br /&gt;Please help us in a full-scale cyberwar againts the dictatorial brutal government of Ahmadinjead! Help Iranians to earn back their votes per instructions below:&lt;br /&gt;&amp;nbsp;&lt;/i&gt; &lt;br /&gt;&lt;i&gt;Simply click on few of the following links (better too choose your selections from different categories); it opens the site in a new tab. It will not stop you from browsing but by sending a refresh signal to the target site will saturate it. By doing so, we can block Ahmadinjead's governments flow of information in many of its key components as shown below. Please help us and yourself from this lunatic who will push the world to world war III.&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SjdxuPAvZRI/AAAAAAAADwo/n3GIFiHpPWs/s1600-h/800px_loic_iran_ddos_people_information_warfare.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SjdxuPAvZRI/AAAAAAAADwo/n3GIFiHpPWs/s200/800px_loic_iran_ddos_people_information_warfare.jpg" /&gt;&lt;/a&gt;Following the updated list of targets, a new &lt;span id="status_nombre"&gt;&lt;a href="http://www.virustotal.com/analisis/a37ae63ffb82c3bb6905833470b42e99fea24d60458edfe4907ef17d65fe6fcf-1245147616"&gt;LOIC.exe&lt;/a&gt; DoS tool is being advertised. The tool is however, anything but sophisticated (it's been around since 6 Jul 2008) compared to even the average Russian DDoS bot. Combined, the simplistic nature of the opposition's attack tools indicates the lack of any in-depth understanding of information warfare principles, in times when other countries are already going beyond cyber warfare and aiming for the unrestricted warfare stage. &lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sjd1cu40hjI/AAAAAAAADww/mggsESM98xM/s1600-h/down+with+shi.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sjd1cu40hjI/AAAAAAAADww/mggsESM98xM/s200/down+with+shi.jpg" /&gt;&lt;/a&gt;&lt;b&gt;The Conspiracy Theory and the Facts&lt;/b&gt;&lt;br /&gt;How is the Iranian government/regime responding to these attacks, is it striking back to the fullest extend speculated in a countless number of cyber warfare research papers? Moreover, can it actually attack the "adversaries" which in this case reside within the country's own network? Can we easily compare this unpleasant situation from an information warfare perspective to the ongoing discussions whether or not the &lt;a href="http://news.bbc.co.uk/2/hi/technology/8026964.stm"&gt;Should the US Go Offensive In Cyberwarfare&lt;/a&gt;?, and "go offensive" against who at the first place? The hundreds of thousands of U.S based malware infected hosts operated by a foreign entity as the adversary &lt;a href="http://blogs.zdnet.com/security/?p=1095"&gt;while using the targeted country's infrastructure as a human shield&lt;/a&gt;?&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sjd1mUZtqLI/AAAAAAAADw4/Y_fCUtB7l1M/s1600-h/jt07ww.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sjd1mUZtqLI/AAAAAAAADw4/Y_fCUtB7l1M/s200/jt07ww.jpg" /&gt;&lt;/a&gt;That's a dilemma that Iran's government is currently facing, but let's connect the dots and prove that the &lt;a href="http://en.wikipedia.org/wiki/Fars_News_Agency"&gt;Fars News Agency&lt;/a&gt; which is pro-Ahmadinejad, and maintains ties to the &lt;a href="http://en.wikipedia.org/wiki/Judicial_system_of_Iran" title="Judicial system of Iran"&gt;Iranian judiciary&lt;/a&gt;, has in fact participated in this "&lt;b&gt;cyber warfare attack with sticks and stones&lt;/b&gt;".&lt;br /&gt;&lt;br /&gt;The Fars News Agency has been under attack since the beginning of the campaign, approximately 48 hours ago, prompting the site -- just like many others -- to switch to "lite" versions taking into consideration the ongoing attacks wasting the sites' bandwidth.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Sjd3oMXRvII/AAAAAAAADxI/8XMTLmL7Pcs/s1600-h/capture.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Sjd3oMXRvII/AAAAAAAADxI/8XMTLmL7Pcs/s200/capture.jpg" /&gt;&lt;/a&gt;In a desperate attempt to influence the outcome of the DDoS attack, Fars News included iFrames pointing to opposition and anti-Ahmadinejad news sites (&lt;b&gt;balatarin.com&lt;/b&gt;; &lt;b&gt;ghalamnews.com&lt;/b&gt; and &lt;b&gt;mirhussein.com&lt;/b&gt;) in order to redirect some of the attack traffic to them. The campaigners noticed the change, but upon confirming that the opposition's web sites remain online even with the iFrames in place, decided to continue the attack.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SjeZX-Wl9iI/AAAAAAAADxQ/VN7QX44Slr4/s1600-h/where_is_my_vote_frames_ddos_1sec_refresh_script.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SjeZX-Wl9iI/AAAAAAAADxQ/VN7QX44Slr4/s200/where_is_my_vote_frames_ddos_1sec_refresh_script.JPG" /&gt;&lt;/a&gt;The bottom line - when your very own infrastructure hates you, you become nothing else but an observer to the declining propaganda exposure projections that you've once set, failing to anticipate the fully realistic scenario when the adversary that you've been fortifying to protect from, or have build sophisticated offensive capabilities to deal with, is in fact residing within your own infrastructure. Attempting to attack him or shut him down will only multiply the effect of his original campaign.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.imdb.com/title/tt0113568/quotes"&gt;The net is vast and infinite&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Recommended reading:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/04/ccdcoe-report-on-cyber-attacks-against.html"&gt;A CCDCOE Report on the Cyber Attacks Against Georgia&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/ddos-attack-graphs-from-russia-vs.html"&gt;DDoS Attack Graphs from Russia vs Georgia's Cyberattacks&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/08/russia-vs-georgia-cyber-attack.html"&gt;The Russia vs Georgia Cyber Attack&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/01/pro-israeli-pseudo-cyber-warriors-want.html"&gt;Pro-Israeli (Pseudo) Cyber Warriors Want your Bandwidth&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html"&gt;People's Information Warfare Concept&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/12/combating-unrestricted-warfare.html"&gt;Combating Unrestricted Warfare&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/04/cyber-storm-ii-cyber-exercise.html"&gt;The Cyber Storm II Cyber Exercise&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html"&gt;Chinese Hacktivists Waging People's Information Warfare Against CNN&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html"&gt;The DDoS Attacks Against CNN.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/09/chinas-cyber-espionage-ambitions.html"&gt;China's Cyber Espionage Ambitions&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2006/07/north-koreas-cyber-warfare-unit-121.html"&gt;North Korea's Cyber Warfare Unit 121&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2006/09/chinese-hackers-attacking-us.html"&gt;Chinese Hackers Attacking U.S Department of Defense Networks&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html"&gt;Electronic Jihad v3.0 - What Cyber Jihad Isn't&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/electronic-jihads-targets-list.html"&gt;Electronic Jihad's Targets List&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/08/cyber-jihadist-dos-tool.html"&gt;A Cyber Jihadist DoS Tool &lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/teaching-cyber-jihadists-how-to-hack.html"&gt;Teaching Cyber Jihadists How to Hack&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html"&gt;Empowering the Script Kiddies&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html"&gt;OSINT Through Botnets&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html"&gt;Corporate Espionage Through Botnets&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html"&gt;Malware Infected Hosts as Stepping Stones&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html"&gt;Hacktivism Tensions - Israel vs Palestine Cyberwars&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2006/05/current-emerging-and-future-state-of.html"&gt;The Current, Emerging, and Future State of Hacktivism&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html"&gt;Internet PSYOPS - Psychological Operations&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-242480730804807839?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/242480730804807839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/242480730804807839'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/06/iranian-opposition-ddos-es-pro.html' title='Iranian Opposition DDoS-es pro-Ahmadinejad Sites'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wICHhTiQmrA/Sjdpqins2RI/AAAAAAAADwQ/s0_ljGgxMqo/s72-c/iranian_pro-Ahmadinejad_site_attack_9.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-383702546808606678</id><published>2009-06-09T23:03:00.158+02:00</published><updated>2009-06-10T01:28:58.638+02:00</updated><title type='text'>From Ukrainian Blackhat SEO Gang With Love - Part Two</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Si6l5hqd9vI/AAAAAAAADuo/-EswL3TYvB4/s1600-h/ddanchev_scareware.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Si6l5hqd9vI/AAAAAAAADuo/-EswL3TYvB4/s320/ddanchev_scareware.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;It seems that the portfolio of &lt;a href="http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html"&gt;redirectors using my name&lt;/a&gt; part of an ongoing &lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;Ukrainian blackhat SEO&lt;/a&gt; is expanding, with &lt;b&gt;seximalinki .ru/images/ddanchev-sock-my-dick.php&lt;/b&gt;, as the latest addition. This brings up the number of redirectors to three, at least for the time being:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;seximalinki.ru/images/ddanchev-sock-my-dick.php&lt;/b&gt; - active - 74.54.176.50; Email: Hippacmc@land.ru&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;seo.hostia .ru/ddanchev-sock-my-dick.php&lt;/b&gt; - active - 213.155.2.37&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;HiDancho.mine .nu/login.js&lt;/b&gt; - active - 64.21.86.16&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Si0hcLUtElI/AAAAAAAADug/yHBpEfNePuQ/s1600-h/blackhat_seo_ddanchev_more_love_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Si0hcLUtElI/AAAAAAAADug/yHBpEfNePuQ/s200/blackhat_seo_ddanchev_more_love_3.JPG" /&gt;&lt;/a&gt;Let's dissect the latest campaigns, including several related ones not necessarily serving scareware, moreover, let's also establish a connection between this gang and the &lt;a href="http://blogs.zdnet.com/security/?p=3549"&gt;ongoing hijacking of Twitter trending topics for malware serving purposes&lt;/a&gt;, shall we?&lt;br /&gt;&lt;br /&gt;The redirector takes the user to &lt;b&gt;antimalwareonlinescannerv3 .com&lt;/b&gt; - 83.133.115.9; 91.212.65.125; 69.4.230.204 - Email: immigration.beijing@footer.cn where &lt;a href="http://www.virustotal.com/analisis/b6be40adcd5157dcfbcf8d332179dee6d2f9afb8c9a23457d4e3034f849b9c10-1244322301"&gt;the scareware&lt;/a&gt; is served.&lt;br /&gt;&lt;br /&gt;The campaign is also relying on three more scareware domains &lt;b&gt;antimalware-live-scanv3 .com&lt;/b&gt;; &lt;b&gt;antimalwareliveproscanv3 .com&lt;/b&gt; ;&lt;b&gt;fastsecurityupdateserver .com&lt;/b&gt;, with &lt;b&gt;ns1.futureselfdeeds .com&lt;/b&gt; ensuring that the rest of the portfolio remains in tact :&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Si66jlX5r_I/AAAAAAAADuw/Si07OV4vzRg/s1600-h/blackhat_seo_ddanchev_more_love_2_sitemaps.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Si66jlX5r_I/AAAAAAAADuw/Si07OV4vzRg/s200/blackhat_seo_ddanchev_more_love_2_sitemaps.JPG" /&gt;&lt;/a&gt;&lt;b&gt;premiumlivescanv1 .com &lt;br /&gt;advanedmalwarescanner .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;advanedpromalwarescanner .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;antiviruspcscannerv1 .com &lt;br /&gt;antiviruspremiumscanv2 .com &lt;br /&gt;malware-live-pro-scanv1 .com &lt;br /&gt;malwareliveproscanv1 .com &lt;br /&gt;malwareliveproscannerv1 .com &lt;br /&gt;malwareinternetscannerv1 .com &lt;br /&gt;anti-spyware-scan-v1 .com &lt;br /&gt;antimalwarescanner-v2 .com &lt;br /&gt;freeantispywarescan2 .com &lt;br /&gt;antivirus-scanner-v1 .com &lt;br /&gt;internetotherwise .com &lt;br /&gt;macrosoftwarego .com &lt;br /&gt;world-payment-system .com&lt;/b&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Si66zE88zMI/AAAAAAAADu4/smBz_o_fsHU/s1600-h/blackhat_seo_ddanchev_more_love_3_sitemaps.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Si66zE88zMI/AAAAAAAADu4/smBz_o_fsHU/s200/blackhat_seo_ddanchev_more_love_3_sitemaps.JPG" /&gt;&lt;/a&gt;&lt;b&gt; paymentonlinesystem .com &lt;br /&gt;livewwwupdates .com &lt;br /&gt;liveinternetupdates .com &lt;br /&gt;livesecurityupdate .com &lt;br /&gt;securitysoftwarepayments .com &lt;br /&gt;antiviruspaymentsystem .com &lt;br /&gt;systemsecurityupdates .com &lt;br /&gt;networksecurityadvice .com &lt;br /&gt;systeminternetupdates .com &lt;br /&gt;protectionsystemupdates .com &lt;br /&gt;updateinternetserver2 .com &lt;br /&gt;protectionupdates2 .com &lt;br /&gt;proantivirusscannerv2 .com &lt;br /&gt;proantivirusscanv2 .com &lt;br /&gt;powerantivirusscanv2 .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Si7RNnMUAFI/AAAAAAAADvA/Yr3H2DjVWYo/s1600-h/fake_codec_june_2009_blackhat_seo.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Si7RNnMUAFI/AAAAAAAADvA/Yr3H2DjVWYo/s200/fake_codec_june_2009_blackhat_seo.png" /&gt;&lt;/a&gt;These blackhat SEO-ers&lt;b&gt; &lt;/b&gt;have been actively multitasking during the past couple of months. For instance, another campaign maintained by them at Lycos Tripod's is-the-boss.com is using the redirector &lt;b&gt;ntlligent .info/tds/in.cgi?11&amp;amp;seoref=&amp;amp;parameter=$keyword&amp;amp;se=$se&amp;amp;ur=1&amp;amp;HTTP_REFERER= &lt;/b&gt;(72.232.163.171), hosted by Layered Technologies, Inc., in order to serve a a &lt;a href="http://www.virustotal.com/analisis/c1033da5d371cff01c92ebaa9f3252fe74c4ce9611273747289d803d44688be0-1244445659"&gt;Koobface sample&lt;/a&gt; located at 91.212.65.35/view/1/1416/0, which upon execution phones back to &lt;b&gt;upr15may .com&lt;/b&gt;/achcheck.php; &lt;b&gt;upr15may .com&lt;/b&gt;/ld/gen.php (119.110.107.137) as well as to &lt;b&gt;i-site .ph&lt;/b&gt;/1/6244.exe; &lt;b&gt;i-site .ph&lt;/b&gt;/1/nfr.exe with the second binary phoning back to 85.13.236 .154/v50/?v=71&amp;amp;s=I&amp;amp;uid=1824245000&amp;amp;p=14160&amp;amp;ip=&amp;amp;q=.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Si7Ra9sbfxI/AAAAAAAADvI/6M6gSHfvvrA/s1600-h/porn_tube_june_2009_fake_codec_malware.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Si7Ra9sbfxI/AAAAAAAADvI/6M6gSHfvvrA/s200/porn_tube_june_2009_fake_codec_malware.png" /&gt;&lt;/a&gt;Another campaign maintained by them at is-the-boss.com is using three redirectors &lt;b&gt;kurinah.freehostia .com&lt;/b&gt;/in.cgi?8&amp;amp;seoref=&amp;amp;parameter=$keyword&amp;amp;se=&amp;amp;ur=1&amp;amp;HTTP_REFERER=; &lt;b&gt;promodomain .info&lt;/b&gt;/in.cgi?8&amp;amp;seoref=&amp;amp;parameter=$keyword&amp;amp;se=&amp;amp;ur=1&amp;amp;HTTP_REFERER= - 66.40.52.63 - Email: support@ruler-domains.com and &lt;b&gt;thetrafficcontrol .net&lt;/b&gt;/in.cgi?8&amp;amp;seoref=&amp;amp;parameter=$keyword&amp;amp;se=&amp;amp;ur=1&amp;amp;HTTP_REFERER=, until the user is finally redirected to a fake PornTube portal &lt;b&gt;big-tube-list .com&lt;/b&gt;/teens/xmovie.php?id=45048 - 216.240.143.7 - isaacdonn@gmail.com where malware is served from &lt;b&gt;my-exe-profile .com&lt;/b&gt;/&lt;a href="http://www.virustotal.com/analisis/69ba169d715bb726dcad878de94fe3d6d956bb911672d9b48cbf4d21d5c7d826-1244581451"&gt;streamviewer.45048.exe&lt;/a&gt; - 66.197.171.6 - Email: michalevd@gmail.com. &lt;br /&gt;&lt;br /&gt;Upon execution, streamviewer phones back to &lt;b&gt;reportsystem32 .com&lt;/b&gt;/senm.php?data= - 216.240.146.119 -, &lt;b&gt;terradataweb .com&lt;/b&gt;/senm.php?data=v22 - 66.199.229.229 -, and &lt;b&gt;dvdisorapid .com&lt;/b&gt;/senm.php?data=v22 - 64.27.5.202.&lt;br /&gt;&lt;br /&gt;Several related fake codec serving domains parked at 216.240.143.7 are also currently active:&lt;br /&gt;&lt;b&gt;get-mega-tube .com - &lt;/b&gt;Email: raymgnw95@gmail.com&lt;br /&gt;&lt;b&gt;best-crystal-tube .com - &lt;/b&gt;Email: raymgnw95@gmail.com&lt;br /&gt;&lt;b&gt;the-lost-tube .com - &lt;/b&gt;Email: hilachow@gmail.com&lt;br /&gt;&lt;b&gt;sunny-tube-house .com - &lt;/b&gt;Email: hilachow@gmail.com&lt;br /&gt;&lt;b&gt;proper-tube-site .com - &lt;/b&gt;Email: hilachow@gmail.com&lt;br /&gt;&lt;b&gt;tube-xxx-work .com - &lt;/b&gt;Email: hilachow@gmail.com&lt;br /&gt;&lt;b&gt;big-tube-list .com - &lt;/b&gt;Email: isaacdonn@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Si7Xk5-xC9I/AAAAAAAADvQ/dxGvh76mlQM/s1600-h/scareware_blackhat_seo_june.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Si7Xk5-xC9I/AAAAAAAADvQ/dxGvh76mlQM/s200/scareware_blackhat_seo_june.jpg" /&gt;&lt;/a&gt;A third campaign is using a single redirector to &lt;b&gt;tangoing .info&lt;/b&gt;/cgi-bin/analytics?id=917304&amp;amp;k= - 91.207.61.48 - Email: dophshli@gmail.com to dynamically redirect visitors to pretty much all the scareware domains listed in &lt;a href="http://ddanchev.blogspot.com/2009/06/diverse-portfolio-of-fake-security.html"&gt;part twenty one of the diverse portfolio of fake security software series&lt;/a&gt;. Moreover, the very same email used to register the redirecting domain was also used to register a &lt;a href="http://ddanchev.blogspot.com/2009/01/diverse-portfolio-of-fake-security.html"&gt;payment processing gateway for scareware transactions&lt;/a&gt; in January, 2009.&lt;br /&gt;&lt;br /&gt;Yet another blackhat SEO operation maintained by the same group since February, 2009 is &lt;b&gt;fi97 .net&lt;/b&gt;/jsr.php?uid=dir&amp;amp;group=ggl&amp;amp;keyword=&amp;amp;okw=&amp;amp;query="+query+" referer="+escape(document.referrer)+"&amp;amp;href="+escape(location.href)+"&amp;amp;r="+rzz+"'&amp;gt;&amp;lt;"+"/scr"+"ipt&amp;gt;", which according to publicly obtainable statistics received approximately 138, 000 unique visitors in April, with 30.23% coming from Google.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Si7a3ROVbvI/AAAAAAAADvY/0BnnWI2zt-s/s1600-h/petrenko_massive_blackhat_SEO_may_2009_6.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Si7a3ROVbvI/AAAAAAAADvY/0BnnWI2zt-s/s200/petrenko_massive_blackhat_SEO_may_2009_6.JPG" /&gt;&lt;/a&gt;The &lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;traffic hijacking of for the purpose of serving malware&lt;/a&gt;, using over a hundred different .us domains was in fact so successful that several &lt;a href="http://www.google.com/support/forum/p/Webmasters/thread?tid=67c1f10a8dd9df61&amp;amp;hl=en"&gt;webmasters&lt;/a&gt; reported loosing &lt;a href="http://www.google.com/support/forum/p/Webmasters/thread?tid=4b5cda7d43f10efb&amp;amp;hl=en"&gt;their organic&lt;/a&gt; search traffic due to &lt;a href="http://www.google.com/support/forum/p/Webmasters/thread?tid=4b5cda7d43f10efb&amp;amp;hl=en"&gt;the content&lt;/a&gt; within the sites. The campaign then switched to a pharmaceutical theme using a Google search engine theme, with several static links to pharma scams, once again using the already established traffic redirections tactics.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Si7c6wpgMYI/AAAAAAAADvg/hYUJsStF98o/s1600-h/petrenko_massive_blackhat_SEO_may_2009.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Si7c6wpgMYI/AAAAAAAADvg/hYUJsStF98o/s200/petrenko_massive_blackhat_SEO_may_2009.png" /&gt;&lt;/a&gt;The redirectors in question &lt;b&gt;petrenko .biz&lt;/b&gt; - 88.214.200.150 - Email: olegoff@yandex.ru and &lt;b&gt;myseobiz .net&lt;/b&gt; - 67.225.158.16 - Email: 3bd864dddbe4421ab1112a6ebc6df4fb.protect@whoisguard.com remain in operation. The bogus Google front page is advertising the following pharma domains:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;theusdrugs .com&lt;/b&gt; - 78.140.132.11, parked at the same IP are also more pharma domains:&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Si7nBJwO1FI/AAAAAAAADvo/upTQUnPksqo/s1600-h/petrenko_massive_blackhat_SEO_may_2009_1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Si7nBJwO1FI/AAAAAAAADvo/upTQUnPksqo/s200/petrenko_massive_blackhat_SEO_may_2009_1.png" /&gt;&lt;/a&gt;&lt;b&gt;medscompany .org&lt;br /&gt;canadian-rxpill .com&lt;br /&gt;bestyourpills .com&lt;br /&gt;rx-drugs-support .com&lt;br /&gt;payment-rx .com&lt;br /&gt;genericdrugs .in&lt;/b&gt;&lt;br /&gt;&lt;b&gt;mendrugsshop .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;healthrefill .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Si7pIPCpYZI/AAAAAAAADvw/Jt11nZT1mHE/s1600-h/twitter_fake_codec_trending.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Si7pIPCpYZI/AAAAAAAADvw/Jt11nZT1mHE/s200/twitter_fake_codec_trending.JPG" /&gt;&lt;/a&gt;It gets even more inter-connected and malicious since this very same gang is also the one responsible for the ongoing &lt;a href="http://blogs.zdnet.com/security/?p=3549"&gt;malware campaign spreading scareware by using Twitter's trending topics&lt;/a&gt;. Let's establish a direct connection between the Ukrainian gang and the campaign.&lt;br /&gt;&lt;br /&gt;The TinyURL links used redirect to an identical domain - &lt;b&gt;00freewebhost .cn&lt;/b&gt; - 211.95.79.115 - Email: louisgreenfield@gmail.com, where an iFrame is loading &lt;b&gt;happy-tube-video .com/xplays.php?id=40030&lt;/b&gt; - 216.240.143.7 - Email: isaacdonn@gmail.com where &lt;a href="http://www.virustotal.com/analisis/236930a2bbadb50b8cc29db8658fdc45062d8e67071be541368b02a999b37995-1244492331"&gt;Mal/FakeAV-AY&lt;/a&gt; (streamviewer.40030.exe) is served, this time from &lt;b&gt;exe-soft-files .com&lt;/b&gt;/streamviewer.40030.exe - 66.197.171.6 - Email: michalevd@gmail.com.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Si7uaf-k-JI/AAAAAAAADv4/KjHvkbhBiDo/s1600-h/black_hat_seo_june_malware.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Si7uaf-k-JI/AAAAAAAADv4/KjHvkbhBiDo/s200/black_hat_seo_june_malware.png" /&gt;&lt;/a&gt;This very same domain (&lt;b&gt;happy-tube-video .com &lt;/b&gt;registered to isaacdonn@gmail.com) is part of the second PornTube fake codec campaign which I assessed above, this time pushed through the gang's blackhat SEO campaigns. &lt;br /&gt;&lt;br /&gt;Moreover, in a typical cybercrime-friendly style, the main malicious domain operated by the gang and used in the Twitter campaign -  &lt;b&gt;00freewebhost .cn - &lt;/b&gt;continues to load the malware serving domain despite that it's main index is serving a &lt;a href="http://ddanchev.blogspot.com/2008/01/rbns-fake-account-suspended-notices.html"&gt;fake account suspended notice&lt;/a&gt; - "&lt;i&gt;This Account Has Been Suspended, This includes, but is not limited to overusing server resources, publishing adult content, or unauthorized posting of copyrighted material. Please contact our Support Team for more information.&lt;/i&gt;" Which is pretty amusing, since despite the fact that they're using an iFrame to point to a different location, they've left an animated GIF image of a fake codec hosted there - &lt;b&gt;00freewebhost .cn/shmo/pl.gif&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Si7uoI4UXsI/AAAAAAAADwA/QNKKIYAfOvY/s1600-h/twitter_trending_topics_malware_sample_account.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Si7uoI4UXsI/AAAAAAAADwA/QNKKIYAfOvY/s200/twitter_trending_topics_malware_sample_account.JPG" /&gt;&lt;/a&gt;A second connection between the Ukraininan black SEO gang, Twitter's ongoing campaign and the &lt;a href="http://ddanchev.blogspot.com/2009/06/fake-web-hosting-provider-front-end-to.html"&gt;fake web hosting provider&lt;/a&gt; which I profiled yesterday can also be made.&lt;br /&gt;&lt;br /&gt;For instance, the &lt;a href="http://www.abuse.ch/?p=1495"&gt;URL shortening service used&lt;/a&gt; in last week's campaign at Twitter &lt;b&gt;a.gd/2524d9/&lt;/b&gt; redirects to &lt;b&gt;66.199.229 .253/etds/go.php?sid=43&lt;/b&gt; and then to &lt;b&gt;av-guard .net/?uid=27&amp;amp;pid=3&lt;/b&gt; as well as to &lt;b&gt;fast-antivirus .com&lt;/b&gt; which are the scareware domains exposed in the recent "&lt;a href="http://ddanchev.blogspot.com/2009/06/fake-web-hosting-provider-front-end-to.html"&gt;Fake Web Hosting Provider - Front-end to Scareware Blackhat SEO Campaign at Blogspot&lt;/a&gt;" post. The scareware obtained from it, as well as the scareware from the above-exposed PornTube campaign &lt;b&gt;streamviewer.40030.exe&lt;/b&gt; also share the same phone back locations.&lt;br /&gt;&lt;br /&gt;Coming across yet another operation managed by them, namely, the ongoing Twitter trending topics hijacking attack, clearly demonstrates the impact this single group of individuals can have while multitasking at different fronts. And despite the numerous traffic acquisition tactics used, the monetization approach remains virtually the same - &lt;a href="http://ddanchev.blogspot.com/2009/04/confickers-scarewarefake-security.html"&gt;scareware&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-383702546808606678?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/383702546808606678'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/383702546808606678'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with_09.html' title='From Ukrainian Blackhat SEO Gang With Love - Part Two'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wICHhTiQmrA/Si6l5hqd9vI/AAAAAAAADuo/-EswL3TYvB4/s72-c/ddanchev_scareware.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-6514527694374015290</id><published>2009-06-08T14:28:00.093+02:00</published><updated>2009-06-08T15:48:32.546+02:00</updated><title type='text'>GazTransitStroy/GazTranZitStroy Rubbing Shoulders with Petersburg Internet Network LLC</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Six79RXzvJI/AAAAAAAADto/lPLWOdcZGpo/s1600-h/gaztransitstroyinfo_june_2009_2_petersburg_internet_network_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Six79RXzvJI/AAAAAAAADto/lPLWOdcZGpo/s400/gaztransitstroyinfo_june_2009_2_petersburg_internet_network_3.png" /&gt;&lt;/a&gt;&lt;br /&gt;Following the &lt;a href="http://ddanchev.blogspot.com/2009/05/gaztranzitstroyinfo-fake-russian-gas.html"&gt;GazTransitStroy/GazTranZitStroy&lt;/a&gt; (&lt;b&gt;gaztranzitstroyinfo.ru&lt;/b&gt;; 67.15.253.241) coverage, &lt;a href="http://google.com/safebrowsing/diagnostic?site=AS:29371&amp;amp;hl=en"&gt;the gang&lt;/a&gt; behind the bogus gas company drilling for &lt;a href="http://twitter.com/arbornetworks/status/1873576720"&gt;insecure PCs&lt;/a&gt; across the Web has returned to its roots - St. Petersburg, Russia, with routing services courtesy of PIN-AS Petersburg Internet Network LLC (AS44050) (&lt;b&gt;internet-spb.ru&lt;/b&gt;) :&lt;br /&gt;&lt;br /&gt;"&lt;i&gt;descr: Petersburg Internet Network LLC&lt;br /&gt;address: Sedova 80&lt;br /&gt;address: St.-Petersburg, Russia&lt;br /&gt;e-mail:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; support@internet-spb.ru&lt;br /&gt;phone:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +7 812 4483863&lt;br /&gt;fax-no:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +7 812 4483863&lt;br /&gt;person:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Metluk Nikolay Valeryevich&lt;br /&gt;address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; korp. 1a 40 Slavy ave.,&lt;br /&gt;address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; St.-Petersburg, Russia&lt;br /&gt;e-mail:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nm@internet-spb.ru&lt;br /&gt;phone:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +7 812 4483863&lt;br /&gt;fax-no:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; +7 812 2683113&lt;br /&gt;PIN LLC&lt;br /&gt;Sedova 80&lt;br /&gt;+7 812 4483863&lt;br /&gt;support@internet-spb.ru&lt;br /&gt;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SiyMEktaTmI/AAAAAAAADtw/QGZQdkRvDY4/s1600-h/as44050_PIN_AS_RBN-nish.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SiyMEktaTmI/AAAAAAAADtw/QGZQdkRvDY4/s200/as44050_PIN_AS_RBN-nish.png" /&gt;&lt;/a&gt;&lt;i&gt;Metluk Nikolay Valeryevich&lt;br /&gt;korp. 1a 40 Slavy ave.,&lt;br /&gt;St.-Petersburg, Russia&lt;br /&gt;+7 812 4483863&lt;br /&gt;nm@internet-spb.ru&lt;br /&gt;&lt;br /&gt;Ladoha Anton Vladimirovich&lt;br /&gt;korp. 1a 40 Slavy ave.,&lt;br /&gt;St. Petersburg, Russia&lt;br /&gt;+7 812 4483863&lt;br /&gt;admin@internet-spb.ru&lt;br /&gt;&lt;br /&gt;Strukov Evgeny Olegovich&lt;br /&gt;korp. 1a 40 Slavy ave.,&lt;br /&gt;St.-Petersburg, Russia&lt;br /&gt;+7 812 4483863&lt;br /&gt;admin2@internet-spb.ru&lt;br /&gt;e.strukov@pinspb.ru&lt;br /&gt;&lt;br /&gt;Prefixes 91.212.41.0/24; 95.215.0.0/22; 194.11.16.0/24; 194.11.20.0/23; 195.2.240.0/23&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SiyMRubJwdI/AAAAAAAADt4/sLTG6iXpqps/s1600-h/gaztransitstroyinfo_june_2009_2_petersburg_internet_network_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SiyMRubJwdI/AAAAAAAADt4/sLTG6iXpqps/s200/gaztransitstroyinfo_june_2009_2_petersburg_internet_network_2.JPG" /&gt;&lt;/a&gt;What's also worth pointing out that is a huge number of of domains operated by GazTransitStroy's customers, and, of course, GazTranzitStroy themselves not only traceroute back to Petersburg Internet Network LLC's network, but also, there's an evident migration to the legitimate &lt;b&gt;NETDIRECT-NET - 89.149.206.0 - 89.149.207.255 - AS2875&lt;/b&gt;, as well as to &lt;b&gt;CHINANET-SH CHINANET shanghai province network - 222.64.0.0 - 222.73.255.255&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SiyMfwGnQ5I/AAAAAAAADuA/2poQkcwRJbo/s1600-h/gaztransitstroyinfo_address_june_2009_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SiyMfwGnQ5I/AAAAAAAADuA/2poQkcwRJbo/s200/gaztransitstroyinfo_address_june_2009_1.JPG" /&gt;&lt;/a&gt;Combined with the fact that &lt;b&gt;EUROHOST-NET/Eurohost LLC (eurohost.biz.ua) 91.212.65.0 - 91.212.65.255 - AS48841&lt;/b&gt; remain an inseparable part of GazTransitStroy's info, clearly indicates the presence of a well known cybercrime powerhouse - the RBN itself.&lt;br /&gt;&lt;br /&gt;The following domains (crimeware, live exploits, scareware, you name it they engage in it) maintained by GazTranzitStroy have migrated as follows. From &lt;b&gt;91.212.41.96&lt;/b&gt; to CHINANET-SH CHINANET shanghai province network - 222.64.0.0 - 222.73.255.255:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;loshadinet .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;roselambda .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;use-sena .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;peopleopera .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;forexsec .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;symphonygold .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;dreamlitediamond .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;vilihood .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;bookadorable .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;drawingstyle .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;housedomainname .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;roomsme .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;vilasse .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;workfuse .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;stakeshouse .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;financeimprove .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;lifenaming .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;travetbeach .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;schoolh .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;rainfinish .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;housevisual .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;kvk.housevisual .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;xfln.housevisual .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;worksean .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;blogtransaction .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;liteauction .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;seamodern .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;smilecasino .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;newtransfer .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;oceandealer .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;pub.oceandealer .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;musicdomainer .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;wowregister .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;websiteflower .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;travets .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;designroots .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;teamwows .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;startgetaways .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;moulitehat .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;caxf.moulitehat .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;islandtravet .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;weekendtravet .cn&lt;br /&gt;resorttravet .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;litefront .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;palaceyou .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;youbonusnew .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;clubmillionswow .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;rainjukebox .cn&lt;/b&gt;&lt;br /&gt;&lt;b&gt;xuyxuyxuy .cn&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Si0Wn17SlFI/AAAAAAAADuY/47AAAe25iBI/s1600-h/scareware_total_virus_protection.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Si0Wn17SlFI/AAAAAAAADuY/47AAAe25iBI/s200/scareware_total_virus_protection.png" /&gt;&lt;/a&gt;From 91.212.41.114 to NETDIRECT-NET - 89.149.206.0 - 89.149.207.255 - AS28753, interestingly, the DNS servers for the following domains &lt;b&gt;ns1.pubilcnameserver7.com&lt;/b&gt;/&lt;b&gt;ns1.pubilcnameserver7.com&lt;/b&gt; are diversifying at 89.149.207.56 and 91.212.41.114:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;freeantivirusplus09 .com&lt;br /&gt;realantivirusplus09 .com&lt;br /&gt;getantivirusplus09 .com&lt;br /&gt;smartantivirusplus09 .com &lt;br /&gt;addedantivirusonline .com&lt;br /&gt;addedantivirusstore .com&lt;br /&gt;addedantiviruslive .com&lt;br /&gt;addedantiviruspro .com&lt;br /&gt;countedantiviruspro .com &lt;br /&gt;plusantiviruspro .com&lt;br /&gt;myplusantiviruspro .com&lt;br /&gt;addedantivirus .com&lt;br /&gt;youraddedantivirus .com&lt;br /&gt;bestaddedantivirus .com&lt;br /&gt;easyaddedantivirus .com&lt;br /&gt;yourcountedantivirus .com&lt;br /&gt;bestcountedantivirus .com&lt;br /&gt;yourplusantivirus .com &lt;br /&gt;easyplusantivirus .com&lt;br /&gt;yourguardonline .cn&lt;br /&gt;easydefenseonline .cn&lt;br /&gt;bestprotectiononline .cn&lt;br /&gt;freecoveronline .cn&lt;br /&gt;atioqe .cn&lt;br /&gt;yourguardstore .cn&lt;br /&gt;mycheckdiseasestore .cn&lt;br /&gt;examinepoisonstore .cn&lt;br /&gt;freecoverstore .cn&lt;br /&gt;myexaminevirusstore .cn&lt;br /&gt;bestexaminedisease .cn&lt;br /&gt;yourfriskdisease .cn&lt;br /&gt;easyfriskdisease .cn&lt;br /&gt;friskdiseaselive .cn&lt;br /&gt;bestdefenselive .cn&lt;br /&gt;bigprotectionlive .cn&lt;br /&gt;bigcoverlive .cn&lt;br /&gt;examineillnesslive .cn&lt;br /&gt;exodih .cn&lt;br /&gt;suxpymi .cn&lt;br /&gt;aciazi .cn&lt;br /&gt;yourfriskinfection .cn&lt;br /&gt;easyserviceprotection .cn&lt;br /&gt;easyincomeprotection .cn&lt;br /&gt;easypersonalprotection .cn&lt;br /&gt;easybestprotection .cn&lt;br /&gt;myascertainpoison .cn&lt;br /&gt;yourguardpro .cn&lt;br /&gt;refugepro .cn&lt;br /&gt;mycheckdiseasepro .cn&lt;br /&gt;ascertaindiseasepro .cn&lt;br /&gt;yourcheckpoisonpro .cn&lt;br /&gt;easycheckpoisonpro .cn&lt;br /&gt;yourfriskviruspro .cn&lt;br /&gt;myascertainviruspro .cn&lt;br /&gt;fegbywo .cn&lt;br /&gt;feptuaq .cn&lt;br /&gt;myexamineillness .cn&lt;br /&gt;exousyt .cn&lt;br /&gt;newguard2u .cn&lt;br /&gt;freedefense2u .cn&lt;br /&gt;bigdefense2u .cn&lt;br /&gt;bestcover2u .cn&lt;br /&gt;newguard4u .cn&lt;br /&gt;mydefense4u .cn&lt;br /&gt;bestcover4u .cn&lt;br /&gt;newguard4you .cn&lt;br /&gt;mydefense4you .cn&lt;br /&gt;bestcover4you .cn&lt;br /&gt;yourguardforyou .cn&lt;br /&gt;newguardforyou .cn&lt;br /&gt;myguardforyou .cn&lt;br /&gt;freedefenseforyou .cn&lt;br /&gt;mydefenseforyou .cn&lt;br /&gt;bestcoverforyou .cn&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SiyTFePkX2I/AAAAAAAADuI/BsUNvc0cuQs/s1600-h/gaztransitstroyinfo_june_2009_3_eurohost_llc_ukraine_bogus.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SiyTFePkX2I/AAAAAAAADuI/BsUNvc0cuQs/s200/gaztransitstroyinfo_june_2009_3_eurohost_llc_ukraine_bogus.JPG" /&gt;&lt;/a&gt;The ongoing affiliation with EUROHOST-NET/Eurohost LLC (&lt;b&gt;eurohost.biz.ua&lt;/b&gt;) 91.212.65.0 - 91.212.65.255 - AS48841, and the migration of domains (scareware, live exploits, crimeware etc.) as follows. From 91.212.41.119 to 91.212.65.7 EUROHOST-NET/Eurohost LLC:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;nicdaheb .cn&lt;br /&gt;sehmadac .cn&lt;br /&gt;ralcofic .cn&lt;br /&gt;bikpakoc .cn&lt;br /&gt;xidsasuc .cn&lt;br /&gt;koqsuyod .cn&lt;br /&gt;tozxiqud .cn&lt;br /&gt;bowselaf .cn&lt;br /&gt;cuzlumif .cn&lt;br /&gt;porgacig .cn&lt;br /&gt;hifgejig .cn&lt;br /&gt;rogkadej .cn&lt;br /&gt;sipcojeq .cn&lt;br /&gt;silzefos .cn&lt;br /&gt;popyodiw .cn&lt;br /&gt;hayboxiw .cn&lt;br /&gt;peskufex .cn&lt;br /&gt;ridmoyey .cn&lt;br /&gt;cakpapaz .cn&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SiyTRPf-OQI/AAAAAAAADuQ/YMqGUdaz-BA/s1600-h/eurohost_llc_ukraine.pne.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SiyTRPf-OQI/AAAAAAAADuQ/YMqGUdaz-BA/s200/eurohost_llc_ukraine.pne.png" /&gt;&lt;/a&gt; What kind of an ISP be maintaining a permanent Under Construction page and engage in Zeus and live exploit serving activities on the same IP as its web server? &lt;a href="http://blog.fireeye.com/research/2009/03/bad-actors-part-6-eurohost-llc.html"&gt;EUROHOST-NET/Eurohost LLC&lt;/a&gt; is one of them:&lt;br /&gt;&lt;br /&gt;"&lt;i&gt;person: Mikhail Ignatyev&lt;br /&gt;address: off. 1, 81 Frunze str.,&lt;br /&gt;phone: +38 093 079 00 32&lt;br /&gt;address: Evpatoria, Crimea, Ukraine&lt;br /&gt;e-mail: ipadmin@eurohost.biz.ua&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;At &lt;b&gt;eurohost.biz.ua&lt;/b&gt; (91.212.65.5) we also have parked &lt;a href="http://google.com/safebrowsing/diagnostic?site=123-service.ru"&gt;&lt;b&gt;123-service.ru&lt;/b&gt;&lt;/a&gt;, serving a &lt;a href="http://ddanchev.blogspot.com/2008/01/rbns-fake-account-suspended-notices.html"&gt;deja-vu account suspended message&lt;/a&gt; - "&lt;i&gt;This account has been suspended. Either the domain has been overused, or the reseller ran out of resources.&lt;/i&gt;" as well as &lt;a href="https://zeustracker.abuse.ch/monitor.php?host=ramshanabc.ru"&gt;&lt;b&gt;ramshanabc.ru&lt;/b&gt;&lt;/a&gt;, with another account suspended message despite its previous involvement in Zeus crimeware campaigns in January, 2009 (&lt;b&gt;ramshanabc .ru/ferrari/main.bin&lt;/b&gt;; &lt;b&gt;ramshanabc .ru/ferrari/main.bin&lt;/b&gt;).&lt;br /&gt;&lt;br /&gt;Besides these domains, several others, again registered to &lt;b&gt;kirilboltovnet@yandex.ru&lt;/b&gt; are known to have been maintaining running Zeus crimeware campaigns as well:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;grafjasqq .ru/kiew/kiew.cfg&lt;br /&gt;heliskamm .ru/kiew5.cfg&lt;br /&gt;mamaloki .ru/dir2.cfg489&lt;br /&gt;mamaloki .ru/kiew3.cfg&lt;br /&gt;nionalku .ru/dir5.cfg&lt;br /&gt;nionalku .ru/kiew6.cfg&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;Still not convinced in how malicious their intentions really are? The phone number (+7 928 7867612) used in the registrations of these domains was most recently used in a &lt;a href="http://www.dslreports.com/forum/r22374680-Spam-Western-Union-Transfer-MTCN-1848485571-ZIP-FILE-VIRUS"&gt;spammed Zeus crimeware campaign&lt;/a&gt; impersonating Western Union.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-6514527694374015290?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/6514527694374015290'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/6514527694374015290'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/06/gaztransitstroygaztranzitstroy-rubbing.html' title='GazTransitStroy/GazTranZitStroy Rubbing Shoulders with Petersburg Internet Network LLC'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_wICHhTiQmrA/Six79RXzvJI/AAAAAAAADto/lPLWOdcZGpo/s72-c/gaztransitstroyinfo_june_2009_2_petersburg_internet_network_3.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-1485576042316253271</id><published>2009-06-08T09:37:00.050+02:00</published><updated>2009-06-08T09:37:00.216+02:00</updated><title type='text'>Fake Web Hosting Provider - Front-end to Scareware Blackhat SEO Campaign at Blogspot</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Siw1qG4IaUI/AAAAAAAADs4/i0nzzKcI7bA/s1600-h/life4you_hosting_dirsite.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Siw1qG4IaUI/AAAAAAAADs4/i0nzzKcI7bA/s200/life4you_hosting_dirsite.png" /&gt;&lt;/a&gt;Just like &lt;a href="http://ddanchev.blogspot.com/2009/05/gaztranzitstroyinfo-fake-russian-gas.html"&gt;GazTranzitStroyInfo's case&lt;/a&gt;, what we've got here is failure to understand that the efforts put into building legitimacy of front-ends to cybercrime, is prone to get undermined upon closer examination of the particular web hosting provider.&lt;br /&gt;&lt;br /&gt;Who, and what is &lt;b&gt;Life4you .info&lt;/b&gt; - Free Hosting for Live (&lt;b&gt;dirsite .com&lt;/b&gt;; 65.98.15.80; Dennis Linkor Email: admin@dirsite.com)?&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Siw8PuaZUGI/AAAAAAAADtA/lXnnML-CEEI/s1600-h/life4you_hosting_dirsite_1.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Siw8PuaZUGI/AAAAAAAADtA/lXnnML-CEEI/s320/life4you_hosting_dirsite_1.bmp" /&gt;&lt;/a&gt;"&lt;i&gt;We are pleased to announce the launch of dirsite.com, the best ASP.NET host on the web. We currently offer one plan. This plan is entirely free! Free ASP.NET 2.0 hosting*! Unfortunately we have hit our quota for ad free accounts. Every new signup is now required to display a 460x60 banner ad on their content pages. We will be running another ad free promotion soon, so be sure to check back! We are currently experiencing some technical issues that are out of our control. We are suffering some server problems and as a result, slight delays in processing signups. We are working on it, and will have everything resolved as soon as possible. Thank you for your patience.&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Siw84d-czjI/AAAAAAAADtI/vxLfvPuW3hQ/s1600-h/blogspot_adult_scareware_malware_life4you_dirsite1.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Siw84d-czjI/AAAAAAAADtI/vxLfvPuW3hQ/s200/blogspot_adult_scareware_malware_life4you_dirsite1.PNG" /&gt;&lt;/a&gt;What's so special about them? Well, for starters, they've got no customers but the cybercriminals themselves maintaining a portfolio of over 7,000 adult related keywords which they have been using for blackhat SEO campaigns across thousands of automatically registered -- &lt;a href="http://blogs.zdnet.com/security/?p=1835"&gt;CAPTCHA recognition outsourced&lt;/a&gt; -- Blogspot accounts since February, 2009.&lt;br /&gt;&lt;br /&gt;With the Blogspot campaign still ongoing, let's assess it and expose all the participating scareware domains. Upon automatic generation of the Blogspot accounts, links like the following are included next to the bogus content, all using dirsite.com's pseudo-legitimate hosting services:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;b&gt;goto.dirsite .com/go.php?sid=2&amp;amp;tds-key=erotic+bikini+babes&lt;br /&gt;goto.dirsite .com/go.php?sid=2&amp;amp;tds-key=sexe+amateur+on+my+space&lt;br /&gt;goto.dirsite .com/go.php?sid=2&amp;amp;tds-key=aunt+judy+older+women&lt;br /&gt;goto.dirsite .com/go.php?sid=2&amp;amp;tds-key=view+private+profiles+on+myspace&lt;br /&gt;goto.dirsite .com/go.php?sid=2&amp;amp;tds-key=fullmetal+alchemist+porn&lt;br /&gt;goto.dirsite .com/go.php?sid=2&amp;amp;tds-key=Asian+style+bed+throws&lt;br /&gt;goto.dirsite .com/go.php?sid=2&amp;amp;tds-key=cheerleader+candid+pictures&lt;/b&gt;&lt;br /&gt;&lt;b&gt;goto.dirsite .com/go.php?sid=2&amp;amp;tds-key=desisexstories&lt;/b&gt;&lt;br /&gt;&lt;b&gt;goto.dirsite .com/go.php?sid=2&amp;amp;tds-key=Hey+Arnold+porno&lt;/b&gt;&lt;br /&gt;&lt;b&gt;goto.dirsite .com/go.php?sid=2&amp;amp;tds-key=warcraft+henrai&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SixeAZRoWGI/AAAAAAAADtQ/HbxszQtHugE/s1600-h/blogspot_adult_scareware_malware_life4you_dirsite2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SixeAZRoWGI/AAAAAAAADtQ/HbxszQtHugE/s200/blogspot_adult_scareware_malware_life4you_dirsite2.png" /&gt;&lt;/a&gt;Upon clicking the users are redirected to &lt;b&gt;tdncgo2009 .com/?uid=68&amp;amp;pid=3&lt;/b&gt; (&lt;b&gt;trdatasft .com&lt;/b&gt;; &lt;b&gt;fra22 .net;&lt;/b&gt; Email: ) 64.86.17.47, Email: hmlragnsky@whoisservices.cn, where the scareware domains are randomly loaded:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;virusdoctor-onlinedefender .com&lt;/b&gt; - 64.213.140.69 Email: sebarinvert.ivus@gmail.com&lt;br /&gt;&lt;b&gt;onlinescan-ultraantivirus2009 .com&lt;/b&gt; - 206.53.61.76 &lt;br /&gt;&lt;b&gt;virussweeper-scan .net&lt;/b&gt; - 206.53.61.76 &lt;br /&gt;&lt;b&gt;virusalarm-scanvirus .net&lt;/b&gt; - 206.53.61.76 &lt;br /&gt;&lt;b&gt;viruscatcher .net&lt;/b&gt; - 64.213.140.71 Email: jeannemcpeters@gmail.com&lt;br /&gt;&lt;b&gt;fast-antivirus .com - &lt;/b&gt;64.213.140.68&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://www.virustotal.com/analisis/96ef88149ff92023f6dc8393c547ed3ad5f2938a3018c08a7105c63677ea6391-1244412339"&gt;scareware&lt;/a&gt; attempts to &lt;a href="http://www.virustotal.com/analisis/b56d88ef2aea4c0df0be48a41821becc15b6e2ba9ca7b763726ac67973ce4d5f-1244068810"&gt;phone back&lt;/a&gt; to &lt;b&gt;update1.virusshieldpro .com/ReleaseXP.exe&lt;/b&gt; - 206.53.61.75 - Email: unitedisystems@gmail.com and to &lt;b&gt;updvmfnow .cn&lt;/b&gt; - 64.86.17.9 Email: oijfsd.sd@gmail.com. ReleaseXP.exe then phones back to the following locations, naturally earning profit for the cybecriminal -&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SixfC7dIt4I/AAAAAAAADtY/NIofTkwUImA/s1600-h/crapware_june_2009_blackhat_seo.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SixfC7dIt4I/AAAAAAAADtY/NIofTkwUImA/s200/crapware_june_2009_blackhat_seo.jpg" /&gt;&lt;/a&gt;&lt;b&gt;pay-virusshield .cn&lt;/b&gt; - 64.213.140.70; Email: unitedisystems@gmail.com; Returning the following message: "&lt;i&gt;Sorry, the operation is currently unavailable, please email our support team from product's site (Error Code #150)&lt;/i&gt;"&lt;br /&gt;&lt;b&gt;updvmfnow .cn&lt;/b&gt; - 64.86.17.9&lt;br /&gt;&lt;b&gt;updvmfnow .cn&lt;/b&gt;/reports/install-report.php (64.86.17.9)&lt;br /&gt;&lt;b&gt;updvmfnow .cn&lt;/b&gt;/reports/soft-report.php&lt;br /&gt;&lt;b&gt;updvmfnow .cn&lt;/b&gt;/reports/minstalls.php&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SixhkIv0m_I/AAAAAAAADtg/uJZlMKmDmyo/s1600-h/as30407_Velcom_cybercrime.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SixhkIv0m_I/AAAAAAAADtg/uJZlMKmDmyo/s200/as30407_Velcom_cybercrime.png" /&gt;&lt;/a&gt;The phone back location is also hosting more active scarewaredomains:&lt;br /&gt;&lt;b&gt;ultraantivirus2009 .com&lt;/b&gt; - 64.86.17.9&lt;br /&gt;&lt;b&gt;virusalarmpro .com&lt;br /&gt;vmfastscanner .com&lt;br /&gt;mysuperviser .com&lt;br /&gt;pay-virusdoctor .com&lt;br /&gt;virusmelt .com&lt;br /&gt;payvirusmelt .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Not only is &lt;b&gt;life4info .info&lt;/b&gt; or &lt;b&gt;dirsite .com&lt;/b&gt; a bogus free hosting provider, but the campaigns hosted by them are interacting with our "dear friends" at &lt;a href="http://www.google.com/safebrowsing/diagnostic?site=AS:30407"&gt;AS30407; VELCOM .com&lt;/a&gt; which Spamhaus describes as "&lt;i&gt;N. American base of Ukrainian cybercrime spammers&lt;/i&gt;" - and with a reason.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-1485576042316253271?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/1485576042316253271'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/1485576042316253271'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/06/fake-web-hosting-provider-front-end-to.html' title='Fake Web Hosting Provider - Front-end to Scareware Blackhat SEO Campaign at Blogspot'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_wICHhTiQmrA/Siw1qG4IaUI/AAAAAAAADs4/i0nzzKcI7bA/s72-c/life4you_hosting_dirsite.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-972975727283858850</id><published>2009-06-05T16:37:00.003+02:00</published><updated>2009-06-05T17:25:55.351+02:00</updated><title type='text'>A Diverse Portfolio of Fake Security Software - Part Twenty One</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Siki9WFtJ0I/AAAAAAAADsA/UHlmYh3zIqo/s1600-h/scareware_june_2009_1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Siki9WFtJ0I/AAAAAAAADsA/UHlmYh3zIqo/s200/scareware_june_2009_1.png" /&gt;&lt;/a&gt;The ongoing abuse of AS10929; NETELLIGENT Hosting Services Inc. for scareware distribution purposes is peaking once again, which combined with the well-proven traffic acquisition tactics the campaigners take advantage of, prompts me to proactively undermine the effectiveness of the campaigns by ruining the monetization factor.&lt;br /&gt;&lt;br /&gt;Next to listing the scareware domains currently in circulation, in part twenty one of the &lt;a href="http://ddanchev.blogspot.com/2009/05/diverse-portfolio-of-fake-security.html"&gt;Diverse Portfolio of Fake Security Software series&lt;/a&gt;, it's time we put the spotlight on the so called payment processors mainted by phony in-house operations.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Sikm32F8ijI/AAAAAAAADsI/-FHUkkyj90E/s1600-h/scareware_june_2009_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Sikm32F8ijI/AAAAAAAADsI/-FHUkkyj90E/s200/scareware_june_2009_2.png" /&gt;&lt;/a&gt;The following &lt;a href="http://www.virustotal.com/analisis/dbffd55928c1e8c0441a64ebc2c10785050bb90ce08ae053d2dacb9fa36d9849-1244205554"&gt;scareware&lt;/a&gt; domains are &lt;a href="http://www.virustotal.com/analisis/ecde2d12aafb370b8dea92ba97476d8a032b5bb51ac4aa90cf997af88b1e4cc8-1244205676"&gt;parked&lt;/a&gt; exclusively within AS10929; NETELLIGENT Hosting Services Inc's network, 209.44.126.102&amp;nbsp; in particular :&lt;br /&gt;&lt;br /&gt;&lt;b&gt;fanscan4 .com&lt;/b&gt; 209.44.126.102 Email: brmargul@gmail.com&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;b&gt;rayscan4 .com&lt;/b&gt; Email: brmargul@gmail.com&lt;br /&gt;&lt;b&gt;scantop4 .com&lt;/b&gt; Email: ansouthe@gmail.com&lt;br /&gt;&lt;b&gt;scanlist6 .com&lt;/b&gt; Email: metamant@gmail.com&lt;br /&gt;&lt;b&gt;goscanfine .com&lt;/b&gt; Email: chirelqas@gmail.com&lt;br /&gt;&lt;b&gt;goscanone .com&lt;/b&gt; Email: canrcnad@gmail.com&lt;br /&gt;&lt;b&gt;scan4note .com&lt;/b&gt; Email: ansouthe@gmail.com&lt;br /&gt;&lt;b&gt;in4ck .com&lt;/b&gt; Email: taboussybr@gmail.com&lt;br /&gt;&lt;b&gt;goscanwork .com&lt;/b&gt; Email: govemati@gmail.com&lt;br /&gt;&lt;b&gt;in4tk .com&lt;/b&gt; Email: skeltonrw@gmail.com&lt;br /&gt;&lt;b&gt;goscanatom .com&lt;/b&gt; Email: gleyersth@gmail.com&lt;br /&gt;&lt;b&gt;top4scan .com&lt;/b&gt;&amp;nbsp; Email: ansouthe@gmail.com&lt;br /&gt;&lt;b&gt;slot6scan .com&lt;/b&gt;&amp;nbsp; Email: metamant@gmail.com&lt;br /&gt;&lt;b&gt;gometascan .com&lt;/b&gt;&amp;nbsp; Email: ricboin@gmail.com&lt;br /&gt;&lt;b&gt;gopagescan .com&lt;/b&gt; Email: tanehen@gmail.com&lt;br /&gt;&lt;b&gt;gofinescan .com&lt;/b&gt; Email: alcnafuch@gmail.com&lt;br /&gt;&lt;b&gt;goelitescan .com&lt;/b&gt; Email: funully@gmail.com&lt;br /&gt;&lt;b&gt;gorankscan .com&lt;/b&gt; Email: canrcnad@gmail.com&lt;br /&gt;&lt;b&gt;goworkscan .com&lt;/b&gt; Email: govemati@gmail.com&lt;br /&gt;&lt;b&gt;gogoalscan .com&lt;/b&gt; Email: chinrfi@gmail.com&lt;br /&gt;&lt;b&gt;gogenscan .com&lt;/b&gt;&amp;nbsp; Email: tanehen@gmail.com&lt;br /&gt;&lt;b&gt;goautoscan .com&lt;/b&gt; Email: tanehen@gmail.com&lt;br /&gt;&lt;b&gt;goflexscan .com&lt;/b&gt; Email: alcnafuch@gmail.com&lt;br /&gt;&lt;b&gt;goscanauto .com&lt;/b&gt; Email: canrcnad@gmail.com&lt;br /&gt;&lt;b&gt;scan6slot .com&lt;/b&gt;&amp;nbsp; Emaik: telerdomb@gmail.com&lt;br /&gt;&lt;b&gt;in4st .com&lt;/b&gt; Email: skeltonrw@gmail.com&lt;br /&gt;&lt;b&gt;scan6list .com&lt;/b&gt; Email: telerdomb@gmail.com&lt;br /&gt;&lt;b&gt;goscanflex .com&lt;/b&gt; Email: chirelqas@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SiknWQJcSkI/AAAAAAAADsY/n97fizVI-oU/s1600-h/as10929_NETELLIGENT.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SiknWQJcSkI/AAAAAAAADsY/n97fizVI-oU/s200/as10929_NETELLIGENT.png" /&gt;&lt;/a&gt;&lt;b&gt;goscankey .com&lt;/b&gt; Email: ricboin@gmail.com&lt;br /&gt;&lt;b&gt;scanmeta4 .info&lt;/b&gt; Email: sitintu@gmail.com&lt;br /&gt;&lt;b&gt;scannote4 .info&lt;/b&gt; Email: sitintu@gmail.com&lt;br /&gt;&lt;b&gt;metascan4 .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;zonescan4 .info&lt;/b&gt; Email: mexnacc@gmail.com&lt;br /&gt;&lt;b&gt;notescan4 .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;miniscan4 .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;rankscan4 .info&lt;/b&gt; Email: mexnacc@gmail.com&lt;br /&gt;&lt;b&gt;atomscan4 .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;fanscan4 .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;genscan4 .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;autoscan4 .info&lt;/b&gt; Email: sitintu@gmail.com&lt;br /&gt;&lt;b&gt;topscan4 .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;starscan4 .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;fixscan4 .info&lt;/b&gt; Email: sitintu@gmail.com&lt;br /&gt;&lt;b&gt;mixscan4 .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;luxscan4 .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;rayscan4 .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;keyscan4 .info&lt;/b&gt; Email: sitintu@gmail.com&lt;br /&gt;&lt;b&gt;scangen4 .info&lt;/b&gt; Email: sitintu@gmail.com&lt;br /&gt;&lt;b&gt;scanauto4 .info&lt;/b&gt; Email: mexnacc@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SiknhPlYtmI/AAAAAAAADsg/tmPP7V2tZLM/s1600-h/scareware_june_2009_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SiknhPlYtmI/AAAAAAAADsg/tmPP7V2tZLM/s200/scareware_june_2009_3.png" /&gt;&lt;/a&gt;&lt;b&gt;scantop4 .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;scanflex4 .info&lt;/b&gt; Email: mexnacc@gmail.com&lt;br /&gt;&lt;b&gt;scan4meta .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;scan6meta .info&lt;/b&gt; Email: donboset@gmail.com&lt;br /&gt;&lt;b&gt;scan4fine .info&lt;/b&gt; Email: mexnacc@gmail.com&lt;br /&gt;&lt;b&gt;meta4scan .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;note4scan .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;gen4scan .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;flex4scan .info&lt;/b&gt; Email: mexnacc@gmail.com&lt;br /&gt;&lt;b&gt;fix4scan .info&lt;/b&gt; Email: sitintu@gmail.com&lt;br /&gt;&lt;b&gt;key4scan .info&lt;/b&gt; Email: mexnacc@gmail.com &lt;br /&gt;&lt;b&gt;meta6scan .info&lt;/b&gt; Email: donboset@gmail.com&lt;br /&gt;&lt;b&gt;note6scan .info&lt;/b&gt; Email: donboset@gmail.com&lt;br /&gt;&lt;b&gt;scan4gen .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;scan6gen .info&lt;/b&gt; Email: donboset@gmail.com&lt;br /&gt;&lt;b&gt;scan4auto .info&lt;/b&gt; Email: sitintu@gmail.com&lt;br /&gt;&lt;b&gt;scan4top .info&lt;/b&gt; Email: finewnrk@gmail.com&lt;br /&gt;&lt;b&gt;scan4fix .info&lt;/b&gt; Email: sitintu@gmail.com&lt;br /&gt;&lt;b&gt;scan4key .info&lt;/b&gt; Email: sitintu@gmail.com&lt;br /&gt;&lt;b&gt;fine4scan .info&lt;/b&gt; Email: beelriel@gmail.com&lt;br /&gt;&lt;b&gt;scanmega4 .info&lt;/b&gt; Email: bnntnkmn@gmail.com&lt;br /&gt;&lt;b&gt;zonescan4 .info&lt;/b&gt; Email: mexnacc@gmail.com&lt;br /&gt;&lt;b&gt;rankscan4 .info&lt;/b&gt; Email: mexnacc@gmail.com&lt;br /&gt;&lt;b&gt;scanauto4 .info&lt;/b&gt; Email: mexnacc@gmail.com&lt;br /&gt;&lt;b&gt;scan4fine .info&lt;/b&gt; Email: mexnacc@gmail.com&lt;br /&gt;&lt;b&gt;way4scan .info&lt;/b&gt; Email: bnntnkmn@gmail.com&lt;br /&gt;&lt;b&gt;key4scan .info&lt;/b&gt; Email: mexnacc@gmail.com&lt;br /&gt;&lt;b&gt;scan4fan .info&lt;/b&gt; Email: myscarbe@gmail.com&lt;br /&gt;&lt;br /&gt;Exceptions out of&amp;nbsp; AS10929; NETELLIGENT Hosting Services Inc.:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;ia-pro .com&lt;/b&gt; - 194.165.4.41; 200.63.45.224; 209.44.126.104; 200.63.45.224 Email: abuse@domaincp.net.cn&lt;br /&gt;&lt;b&gt;generalantivirus .com&lt;/b&gt; Email: compalso@gmail.com&lt;br /&gt;&lt;b&gt;genpayment .com&lt;/b&gt; Email: seeingrud@gmail.com&lt;br /&gt;&lt;b&gt;livestopbadware .com&lt;/b&gt; Email: producergrom@gmail.com&lt;br /&gt;&lt;b&gt;av-payment .com&lt;/b&gt; Email: abuse@domaincp.net.cn&lt;br /&gt;&lt;b&gt;antimalware-live-scanv3 .com&lt;/b&gt; - 38.99.170.9; 78.47.91.153; 83.133.115.9; 89.47.237.52;91.212.65.125; Email: immigration.beijing@footer.cn&lt;br /&gt;&lt;b&gt;antivirus-scanner-v1 .com&lt;/b&gt; Email: tareen@yahoo.com&lt;br /&gt;&lt;b&gt;proantivirusscannerv2 .com&lt;/b&gt; Email: ecindia@hotmail.com&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SikrLH0kAII/AAAAAAAADso/nP5k1pG3CSo/s1600-h/scareware_june_2009_4_pandora_software.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SikrLH0kAII/AAAAAAAADso/nP5k1pG3CSo/s200/scareware_june_2009_4_pandora_software.png" /&gt;&lt;/a&gt;Who's processing the payments made by the scammed customers? These are the major payment processors of scareware software that have been changing aliases for a while now, with Pandora Software being the most persistent one:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;easybillhere .com&lt;/b&gt; - 200.63.45.221; Email: myerysin@gmail.com&lt;br /&gt;&lt;b&gt;secure.softwaresecuredbilling .com&lt;/b&gt; - 209.8.45.122; Viktor Temchenko Email: TemchenkoViktor@googlemail.com&lt;br /&gt;&lt;b&gt;secure.propayments .org&lt;/b&gt; - 78.46.152.8; Oleg Bajenov Email: oleg.bajenov@gmail.com&lt;br /&gt;&lt;b&gt;secure.soft-transaction .com&lt;/b&gt; - 77.91.228.155; Riabokon, Igor; rw6rr69n7z2@networksolutionsprivateregistration.com&lt;br /&gt;&lt;b&gt;secure-plus-payments .com&lt;/b&gt; - 209.8.25.204; John Sparck; Email: sparck000@mail.com&lt;br /&gt;&lt;b&gt;secure.pnm-software .com&lt;/b&gt; - 209.8.45.124; Live Internet Marketing Limited; pnm-software.com@liveinternetmarketingltd.com&lt;br /&gt;&lt;b&gt;secure.thepaymentonline .com&lt;/b&gt; Email: Sergey Ryabov director@climbing-games.com&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Sikr91xkmKI/AAAAAAAADsw/UF69K3kjJ2s/s1600-h/scareware_june_2009_5_pandora_software_germany.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Sikr91xkmKI/AAAAAAAADsw/UF69K3kjJ2s/s200/scareware_june_2009_5_pandora_software_germany.JPG" /&gt;&lt;/a&gt;What is Pandoware Software, and who's behind Pandora Software (&lt;b&gt;pandora-software .com&lt;/b&gt;; &lt;b&gt;pandora-software .info&lt;/b&gt;; &lt;b&gt;pandoraxxl .com&lt;/b&gt; - 209.8.45.121; Live Internet Marketing Limited; Email: pandoraxxl.com@liveinternetmarketingltd.com)?&lt;br /&gt;&lt;br /&gt;The payment processor describes itself as :&lt;br /&gt;&lt;br /&gt;"&lt;i&gt;PandoraXXL is a company which provides the best adult entertainment online and is the managing company of the adult websites of the group. The concept itself is the carefull creation of websites which are different from the average vanilla adult production. We create them, we run them and we provide customer care to our customers!If You are a customer and would like to know more about our websites please click on Our Websites above. PandoraXXL.com and all sites which listed on PandoraXXL.com owned by Oleg Dvoretskiy Varzinerstr. 127, 44369 Dortmund, Germany&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;Upon "doing business" with them they include their very latest domain within the the credit card statement:&lt;br /&gt;&lt;br /&gt;"&lt;i&gt;Your credit card statement may show any of the following names: WWW.PANDORAXXL.COM If so , than You have made a purchase on one of our websites! This form on the right will help You to locate these transactions! Absolutely sure You have never ever purchased anything with us? Contact us immediately then! Due to our knowledge we are one of a VERY few adult paysites companies out there providing INHOUSE live support along with telephone support. Please call only when You are sure that this site was not ab to help You with Your transactions. You may call with technical questions as well but You must read all our site's FAQs first.&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;Going through the terms of service for several scareware domains, there's a contact support image saying "&lt;i&gt;Copyright 2008 Oleg Dvorezky, Dortmund, Germany&lt;/i&gt;". Why an image and not a text? Cybercriminals sometimes ensure that sensitive info potentially undermining their OPSEC doesn't get crawled by public search engines. It's gets even more interesting as Oleg Dvorezky, whose activities as payment processor for scareware go beyond the support desk has also included his address - &lt;i&gt;Varzinerstr. 127. 44369 Dortmund, Germany&lt;/i&gt; and another phone, again as an image +1(636)549-8103, followed by two more numbers +18669997851 (USA) +33179972633 (France) listed as contact details.&lt;br /&gt;&lt;br /&gt;Moreover, despite the fact that they've active affiliates distribution scareware and earning money in the process, next to managing the processing of payments, one should not exclude the possibility that they may also be engaging in customer relationship management for other scareware affiliate partners. For instance, the following support emails are all managed by them :&lt;br /&gt;&lt;br /&gt;&lt;b&gt;support@supportdeska.com&lt;br /&gt;support@msantispyware2009.com&lt;br /&gt;support@pandora-software.com&lt;br /&gt;support@pandoraxl.com&lt;br /&gt;support@data-saver.org&lt;br /&gt;support@generalantivirus.com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Fo the time being, scareware remains the single most efficient, managed and high liquidity asset used for monetization cybercrime&lt;b&gt; &lt;/b&gt;campaigns.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-972975727283858850?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/972975727283858850'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/972975727283858850'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/06/diverse-portfolio-of-fake-security.html' title='A Diverse Portfolio of Fake Security Software - Part Twenty One'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_wICHhTiQmrA/Siki9WFtJ0I/AAAAAAAADsA/UHlmYh3zIqo/s72-c/scareware_june_2009_1.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-506723765373841388</id><published>2009-06-04T16:45:00.001+02:00</published><updated>2009-06-04T22:08:07.896+02:00</updated><title type='text'>From Ukrainian Blackhat SEO Gang With Love</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SigncRzz67I/AAAAAAAADr4/JY2mBxIf4Hw/s1600-h/blackhat_seo_ddanchev_more_love.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SigncRzz67I/AAAAAAAADr4/JY2mBxIf4Hw/s200/blackhat_seo_ddanchev_more_love.JPG" /&gt;&lt;/a&gt;&lt;b&gt;UPDATE: &lt;/b&gt;My&lt;b&gt; &lt;/b&gt;name is now an integral part of the &lt;a href="http://ddanchev.blogspot.com/2009/04/confickers-scarewarefake-security.html"&gt;scareware business model&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Yet another redirector used in the ongoing blackhat SEO campaign is using it, this time saying just "hi" - &lt;b&gt;hidancho.mine .nu/login.js &lt;/b&gt;redirects to &lt;b&gt;privateaolemail .cn/go.php?id=2010-10&amp;amp;key=b8c7c33ca&amp;amp;p=1&lt;/b&gt; and then to &lt;b&gt;antimalwareliveproscanv3 .com&lt;/b&gt; where &lt;a href="http://www.virustotal.com/analisis/2e843ef82333acd9c00f2261b7d86e9b50c51e8ac96f8edd45d4bb26730849f2-1244144720"&gt;the scareware&lt;/a&gt; is served -- catch up with the &lt;a href="http://ddanchev.blogspot.com/2009/05/diverse-portfolio-of-fake-security.html"&gt;Diverse Portfolio of Fake Security Software&lt;/a&gt; series.&lt;br /&gt;&lt;br /&gt;What's next? The release of Advanced Pro-Danchev Premium Live Mega Professional Anti-Spyware Online Cleaning Scanner 2010?&lt;br /&gt;&lt;br /&gt;You know you have a fan club, as well as positive ROI out of your research, when one of the &lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;most active blackhat SEO groups&lt;/a&gt; for the time being starts cursing you in its &lt;a href="http://ddanchev.blogspot.com/2009/04/twitter-worm-mikeyy-keywords-hijacked.html"&gt;multiple redirectors&lt;/a&gt;, in this particular case that's &lt;b&gt;seo.hostia .ru/ddanchev-sock-my-dick.php&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SigkzSv-sLI/AAAAAAAADrw/pPcRifZSU6U/s1600-h/blackhat_seo_ddanchev_love.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SigkzSv-sLI/AAAAAAAADrw/pPcRifZSU6U/s200/blackhat_seo_ddanchev_love.JPG" /&gt;&lt;/a&gt;Back in 2007, it used to be the polite form of get lost or "&lt;a href="http://ddanchev.blogspot.com/2007/10/possibility-medias-malware-fiasco.html"&gt;ai siktir vee&lt;/a&gt;" courtesy of the &lt;a href="http://ddanchev.blogspot.com/2008/03/new-media-malware-gang-part-four.html"&gt;New Media Malware Gang&lt;/a&gt;, a customer of the &lt;a href="http://ddanchev.blogspot.com/2009/05/gaztranzitstroyinfo-fake-russian-gas.html"&gt;Russian Business Network&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Upon hijacking legitimate traffic and verifying that the visitor is coming from &lt;i&gt;var se = new Array("google.","msn.","yahoo.","comcast.","aol"&lt;/i&gt;, the redirector then takes us to &lt;b&gt;macrosoftwarego .com&lt;/b&gt;; &lt;b&gt;live-payment-system .com&lt;/b&gt; - 83.133.123.140 Email: fabian@ingenovate.com, and to &lt;b&gt;antimalware-live-scanv3 .com&lt;/b&gt; - 38.99.170.9; 78.47.91.153; 83.133.115.9; 89.47.237.52; 91.212.65.125 Email: immigration.beijing@footer.cn where &lt;a href="http://www.virustotal.com/analisis/91a295eda0c2ed9517d03e17b184f6688d6cef3f1bea2d021370d47f42d97414-1244116737"&gt;the scareware&lt;/a&gt; is served.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Sifdd8zHr_I/AAAAAAAADro/tGvD2DX5z9o/s1600-h/scareware_screencap_crawl.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Sifdd8zHr_I/AAAAAAAADro/tGvD2DX5z9o/s200/scareware_screencap_crawl.JPG" /&gt;&lt;/a&gt;&lt;a href="http://ddanchev.blogspot.com/2009/05/diverse-portfolio-of-fake-security.html"&gt;Scareware domains&lt;/a&gt; (delegated) part of their campaigns which as of recently diversity to Lycos owned &lt;a href="http://google.com/safebrowsing/diagnostic?site=is-the-boss.com/"&gt;is-the-boss.com&lt;/a&gt;:&lt;br /&gt;&lt;b&gt;anti-spyware-scan-v1 .com&lt;/b&gt; - &lt;b&gt;ns1.futureselfdeeds .com&lt;/b&gt; (78.47.88.217)&lt;br /&gt;&lt;b&gt;malware-live-pro-scanv1 .com&lt;br /&gt;premiumlivescanv1 .com&lt;br /&gt;malwareliveproscanv1 .com&lt;br /&gt;antiviruspcscannerv1 .com&lt;br /&gt;malwareliveproscannerv1 .com&lt;br /&gt;freeantispywarescan2 .com&lt;br /&gt;antiviruspremiumscanv2 .com&lt;br /&gt;proantivirusscanv2 .com&lt;br /&gt;antiviruspaymentsystem .com&lt;br /&gt;macrosoftwarego .com&lt;br /&gt;advanedmalwarescanner .com&lt;br /&gt;advanedpromalwarescanner .com&lt;br /&gt;futureselfdeeds .com&lt;br /&gt;allinternetfreebies .com&lt;br /&gt;liveinternetupdates .com&lt;br /&gt;momentstohaveyou .cn&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Rephrasing &lt;a href="http://www.imeem.com/onzeonze/music/vMHfC-nL/the-cardigans-lovefool/"&gt;the Cardigans Love Fool song&lt;/a&gt; - Common sense tells me I shouldn't bother, and I ought to stick to another blackhat SEO campaign, a blackhat SEO campaign that surely deserves me, but I think you folks do. &lt;br /&gt;&lt;br /&gt;Thanks to &lt;a href="http://pandalabs.pandasecurity.com/"&gt;Sean-Paul Correll&lt;/a&gt; from PandaLabs for the tip.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-506723765373841388?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/506723765373841388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/506723765373841388'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/06/from-ukrainian-blackhat-seo-gang-with.html' title='From Ukrainian Blackhat SEO Gang With Love'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_wICHhTiQmrA/SigncRzz67I/AAAAAAAADr4/JY2mBxIf4Hw/s72-c/blackhat_seo_ddanchev_more_love.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-4979515356781645975</id><published>2009-06-02T15:49:00.000+02:00</published><updated>2009-06-02T15:49:49.801+02:00</updated><title type='text'>Summarizing Zero Day's Posts for May</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SiUryuhLMxI/AAAAAAAADrY/QDw3ZrV9uc0/s1600-h/zdnet_zeroday_june.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SiUryuhLMxI/AAAAAAAADrY/QDw3ZrV9uc0/s200/zdnet_zeroday_june.jpg" /&gt;&lt;/a&gt;The following is a brief summary of all of my posts at ZDNet's &lt;a href="http://blogs.zdnet.com/security"&gt;Zero Day&lt;/a&gt; for May.&lt;br /&gt;&lt;br /&gt;You can also go through previous summaries for &lt;a href="http://ddanchev.blogspot.com/2009/05/summarizing-zero-days-posts-for-april.html"&gt;April&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/03/summarizing-zero-days-posts-for-march.html"&gt;March&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/03/summarizing-zero-days-posts-for.html"&gt;February&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/02/summarizing-zero-days-posts-for-january.html"&gt;January&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/01/summarizing-zero-days-posts-for.html"&gt;December&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/12/summarizing-zero-days-posts-for.html"&gt;November&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/11/summarizing-zero-days-posts-for-october.html"&gt;October&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/10/summarizing-zero-days-posts-for.html"&gt;September&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/09/summarizing-zero-days-posts-for-august.html"&gt;August&lt;/a&gt; and &lt;a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html"&gt;July&lt;/a&gt;, as well as subscribe to my &lt;a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;amp;s=0&amp;amp;o=1&amp;amp;mode=rss"&gt;personal RSS feed&lt;/a&gt; or &lt;a href="http://feeds.feedburner.com/zdnet/security"&gt;Zero Day's main feed&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Notable articles include: &lt;a href="http://blogs.zdnet.com/security/?p=3432"&gt;Inside the botnets that never make the news&lt;/a&gt; - a &lt;a href="http://content.zdnet.com/2346-12691_22-303596.html"&gt;gallery&lt;/a&gt;; &lt;a href="http://blogs.zdnet.com/security/?p=3385"&gt;China's 'secure' OS Kylin - a threat to U.S offsensive cyber capabilities?&lt;/a&gt; and &lt;a href="http://blogs.zdnet.com/security/?p=3457"&gt;The Web's most dangerous keywords to search for&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;01.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3333"&gt;Cybercriminals promoting malware-friendly search engines&lt;/a&gt;&lt;br /&gt;&lt;b&gt;02.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3346"&gt;New Mac OS X email worm discovered&lt;/a&gt;&lt;br /&gt;&lt;b&gt;03.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3385"&gt;China's 'secure' OS Kylin - a threat to U.S offsensive cyber capabilities?&lt;/a&gt;&lt;br /&gt;&lt;b&gt;04.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3402"&gt;Spammers harvesting emails from Twitter - in real time&lt;/a&gt;&lt;br /&gt;&lt;b&gt;05.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3414"&gt;56th variant of the Koobface worm detected&lt;/a&gt;&lt;br /&gt;&lt;b&gt;06.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3419"&gt;Study: password resetting 'security questions' easily guessed&lt;/a&gt;&lt;br /&gt;&lt;b&gt;07.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3427"&gt;D-Link router's CAPTCHA flawed, WPA passphrase retrieved&lt;/a&gt;&lt;br /&gt;&lt;b&gt;08.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3432"&gt;Inside the botnets that never make the news - a gallery&lt;/a&gt;&lt;br /&gt;&lt;b&gt;09.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3457"&gt;The Web's most dangerous keywords to search for&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-4979515356781645975?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/4979515356781645975'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/4979515356781645975'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/06/summarizing-zero-days-posts-for-may.html' title='Summarizing Zero Day&apos;s Posts for May'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_wICHhTiQmrA/SiUryuhLMxI/AAAAAAAADrY/QDw3ZrV9uc0/s72-c/zdnet_zeroday_june.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-6893578174727095535</id><published>2009-06-02T15:21:00.000+02:00</published><updated>2009-06-02T15:21:57.417+02:00</updated><title type='text'>Dating Spam Campaign Promotes Bogus Dating Agency - Part Two</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SiUVC3hsw5I/AAAAAAAADqY/wMHYm7Z1O9A/s1600-h/confidential_connections_dating_agency_spam.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SiUVC3hsw5I/AAAAAAAADqY/wMHYm7Z1O9A/s200/confidential_connections_dating_agency_spam.png" /&gt;&lt;/a&gt;Your future template-based wife is here, waiting not only for you, but also, for the hundreds of thousands of spammed gullible future husbands.&lt;br /&gt;&lt;br /&gt;Our "dear friends" at &lt;a href="http://ddanchev.blogspot.com/2009/05/dating-spam-campaign-promotes-bogus.html"&gt;Confidential Connections&lt;/a&gt; are at it again - spamming out bogus dating profiles, introducing new domains and inevitably exposing the phony company's connections with managed spam services operated by money mules, and sharing DNS servers with more cybercrime-facilitating parties.&lt;br /&gt;&lt;br /&gt;As in their previous campaigns, they're spamming from &lt;b&gt;LRouen-152-82-6-202.w80-13.abo.wanadoo.fr&lt;/b&gt; [80.13.101.202], and here's the most recent portfolio of domains used in the spam campaigns parked at 62.90.136.207:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SiUWVwAs2MI/AAAAAAAADqg/uCQb1RW2gWw/s1600-h/confidential_connections_dating_agency_spam_1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SiUWVwAs2MI/AAAAAAAADqg/uCQb1RW2gWw/s200/confidential_connections_dating_agency_spam_1.png" /&gt;&lt;/a&gt;&lt;b&gt;dating-forin-loved .com&lt;/b&gt; - Email: deolserdo@safe-mail.net&lt;br /&gt;&lt;b&gt;matchwithworld .com&lt;/b&gt; - Email: esheodin@safe-mail.net&lt;br /&gt;&lt;b&gt;love-f-emale .com&lt;/b&gt; - Email: lo3664570460504@absolutee.com&lt;br /&gt;&lt;b&gt;i-amsingle .com&lt;/b&gt; - Email: i-3685838623704@absolutee.com&lt;br /&gt;&lt;b&gt;for-you-from-me .com&lt;/b&gt; - Email: PabloStantonXW@gmail.com&lt;br /&gt;&lt;b&gt;love-me-long-time .com&lt;/b&gt; - Email: lo3685839114104@absolutee.com&lt;br /&gt;&lt;b&gt;destinycombine .com&lt;/b&gt; - Email: esheodin@safe-mail.net&lt;br /&gt;&lt;b&gt;you-isnot-alone .com&lt;/b&gt; - Email: SamNilsenson@gmail.com&lt;br /&gt;&lt;b&gt;find-some-love .com&lt;/b&gt; - Email: SamNilsenson@gmail.com&lt;br /&gt;&lt;b&gt;find-thereal-love .com&lt;/b&gt; - Email: deolserdo@safe-mail.net&lt;br /&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SiUnDDJJ88I/AAAAAAAADrA/ZPwvW8Ftzao/s1600-h/ualadys3.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SiUnDDJJ88I/AAAAAAAADrA/ZPwvW8Ftzao/s200/ualadys3.jpg" /&gt;&lt;/a&gt;&lt;b&gt;all-hot-love .com&lt;/b&gt; - Email: sup3portne3west@safe-mail.net&lt;br /&gt;&lt;b&gt;find-the-reallove .com&lt;/b&gt; - Email: fi3653005547304@absolutee.com&lt;br /&gt;&lt;b&gt;sweet-hearts-dating .com&lt;/b&gt; - Email: SamNilsenson@gmail.com&lt;br /&gt;&lt;b&gt;my-great-dating .com&lt;/b&gt; - Email: SamNilsenson@gmail.com&lt;br /&gt;&lt;b&gt;yourmatchwith .com&lt;/b&gt; - Email: esheodin@safe-mail.net&lt;br /&gt;&lt;b&gt;loking-for-aman .com&lt;/b&gt; - Email: lo3653004406804@absolutee.com&lt;br /&gt;&lt;b&gt;myloving-heart .com&lt;/b&gt; - Email: my3685835605504@absolutee.com&lt;br /&gt;&lt;b&gt;beautiful-prettywoman .com&lt;/b&gt; - Email: JosiahMillerTP@gmail.com&lt;br /&gt;&lt;b&gt;buildyour-happylove .net&lt;/b&gt; - Email: bu3664569267104@absolutee.com&lt;br /&gt;&lt;b&gt;adorelovewon .com&lt;/b&gt; - Email: supportnewest@safe-mail.net&lt;br /&gt;&lt;b&gt;andiloveyoutoo .com&lt;/b&gt; - Email: enorst10@yahoo.com&lt;br /&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SiUnLYUp6yI/AAAAAAAADrI/IBLahMKmuqk/s1600-h/ualadys4.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SiUnLYUp6yI/AAAAAAAADrI/IBLahMKmuqk/s200/ualadys4.jpg" /&gt;&lt;/a&gt;&lt;b&gt;myloveamour .com&lt;/b&gt; - Email: supportnewest@safe-mail.net&lt;br /&gt;&lt;b&gt;luckyheatrs .com&lt;/b&gt; - Email: neujelivsamomdeli@gmail.com&lt;br /&gt;&lt;b&gt;just-waiting-foryou .com&lt;/b&gt; - Email: SamNilsenson@gmail.com&lt;br /&gt;&lt;b&gt;dreams-about-lady .com&lt;/b&gt; - Email: JosiahMillerTP@gmail.com&lt;br /&gt;&lt;b&gt;inspiredlove .net&lt;/b&gt; - Email: antonkovalchukk@gmail.com&lt;br /&gt;&lt;b&gt;make-family .net&lt;/b&gt; - Email: JosiahMillerTP@gmail.com&lt;br /&gt;&lt;b&gt;createyourlove .net&lt;/b&gt;&lt;br /&gt;&lt;b&gt;fillinglove .net&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SiUkMl4TqrI/AAAAAAAADqo/k1kr067FzCs/s1600-h/ualadys1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SiUkMl4TqrI/AAAAAAAADqo/k1kr067FzCs/s200/ualadys1.jpg" /&gt;&lt;/a&gt;Let's connect the dots, shall we? Notice some of the registrant's emails, namely &lt;b&gt;supportnewest@safe-mail.net&lt;/b&gt; and &lt;b&gt;sup3portne3west@safe-mail.net&lt;/b&gt;. It gets even more interesting taking into consideration the fact that the &lt;a href="http://ddanchev.blogspot.com/2009/05/inside-money-laundering-groups-spamming.html"&gt;money laundering group's botnet command and control domain&lt;/a&gt; was registered to &lt;b&gt;supp3ortnewest@safe-mail.net&lt;/b&gt;. Moreover, among the unique usernames used exclusively by this botnet, was in fact the one used in Confidential Connections spam campaigns, confirming their connection.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SiUkWyO8uoI/AAAAAAAADqw/_qj0Jve1F3o/s1600-h/ualadys.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SiUkWyO8uoI/AAAAAAAADqw/_qj0Jve1F3o/s200/ualadys.jpg" /&gt;&lt;/a&gt;Naturally, Confidential Connections are also rubbing shoulders with more cybercrime facilitating domains sharing the same DNS infrastructure (&lt;b&gt;ns1.srv .com&lt;/b&gt;).&lt;br /&gt;&lt;br /&gt;For instance, &lt;b&gt;superfuturebiz .com&lt;/b&gt;/&lt;b&gt;maingovermnfer5 .com&lt;/b&gt; (Trojan-Spy.Win32.Zbot.uyn) where a Trojan-Spy.Win32.Zbot.uyn is hosted at &lt;b&gt;maingovermnfer5 .com&lt;/b&gt;/anyfldr/demo.exe which once executed attempts to download &lt;a href="http://www.virustotal.com/analisis/b3dd94141526568d434f413b58f99f5c4b3e011026e7da7e17f5f3816126edbc-1243867781"&gt;Zeus crimeware&lt;/a&gt; from &lt;b&gt;maingovermnfer5 .com/anyfldr/cfg.bin&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SiUlti1KBmI/AAAAAAAADq4/QAZPHSazyP0/s1600-h/ualadys2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SiUlti1KBmI/AAAAAAAADq4/QAZPHSazyP0/s200/ualadys2.jpg" /&gt;&lt;/a&gt;Moreover, &lt;b&gt;carder-shop .com&lt;/b&gt; which is an &lt;a href="http://www.spamhaus.org/archive/evidence/malwarehosts/atrivo.html"&gt;ex-Atrivo darling&lt;/a&gt;, &lt;b&gt;yourmagicpills .com&lt;/b&gt; which is a typical pharmaceutical scam, &lt;b&gt;zaikib .in&lt;/b&gt; a malware command and control, and &lt;b&gt;eefs .info&lt;/b&gt; which is a phony "East Europe Financial System" and looks like a typical money mule recruitment operation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-6893578174727095535?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/6893578174727095535'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/6893578174727095535'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/06/dating-spam-campaign-promotes-bogus.html' title='Dating Spam Campaign Promotes Bogus Dating Agency - Part Two'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_wICHhTiQmrA/SiUVC3hsw5I/AAAAAAAADqY/wMHYm7Z1O9A/s72-c/confidential_connections_dating_agency_spam.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-5190029099433672201</id><published>2009-05-27T19:50:00.001+02:00</published><updated>2009-05-27T19:53:27.673+02:00</updated><title type='text'>3rd SMS Ransomware Variant Offered for Sale</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Sh1yWvvFK2I/AAAAAAAADqQ/CY-STZId1LU/s1600-h/sms_ransomware_windows_may_2009.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Sh1yWvvFK2I/AAAAAAAADqQ/CY-STZId1LU/s200/sms_ransomware_windows_may_2009.jpg" /&gt;&lt;/a&gt;The concept of &lt;a href="http://ddanchev.blogspot.com/2008/06/whos-behind-gpcode-ransomware.html"&gt;ransomware&lt;/a&gt; is clearly making a comeback. During the past two months, scareware met the &lt;a href="http://ddanchev.blogspot.com/2008/09/identifying-gpcode-ransomware-author.html"&gt;ransomware&lt;/a&gt; business model in the face of &lt;a href="http://blogs.zdnet.com/security/?p=3014"&gt;File Fix Professional 2009&lt;/a&gt; and &lt;a href="http://www.avertlabs.com/research/blog/index.php/2009/05/12/fakealert-trojan-holds-systems-for-ransom/"&gt;FakeAlert-CO or System Security&lt;/a&gt;, followed by two separate &lt;a href="http://ddanchev.blogspot.com/2009/05/sms-ransomware-source-code-now-offered.html"&gt;SMS-based ransomware&lt;/a&gt; variants &lt;a href="http://blogs.zdnet.com/security/?p=3197"&gt;Trj/SMSlock.A&lt;/a&gt; and a &lt;a href="http://blog.fireeye.com/research/2009/04/ransomware_on_the_loose.html"&gt;modified version of it&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The very latest one is once again offered for sale, with a social engineering theme attempting to trick the infected user that as of 1st of May Microsoft is launching a new anti-pirates initiative, and that unless a $1 SMS is sent in order to receive the deactivation code back, their copy of Windows will remain locked.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Key features:&lt;/b&gt;&lt;br /&gt;Support for Windows 98/Vista&lt;br /&gt;- Blocks the entire  desktop&lt;br /&gt;- Locks system key combinations attempting to remove it&lt;br /&gt;- Copied to the system folder (the file is almost impossible to find)&lt;br /&gt;-  Can be put in the startup&lt;br /&gt;- Launches the blocking system before the desktop appears upon reboot&amp;nbsp; &lt;br /&gt;- Blocks all windows including the Task Manager&lt;br /&gt;- Upon entering the secret code, the ransomware is removed from the system folder and autorun&lt;br /&gt;&lt;br /&gt;The price for a custom-made version with the customer's own SMS data is $10, with $5 per new (undetected) copy, as well as the complete source code available for $50 again from the same vendor.&lt;br /&gt;&lt;br /&gt;From a "visual social engineering" perspective, the one that make scareware what it is as product -- a product which would have scaled so fast if it wasn't the distribution channel in the form of web site compromises and &lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;blackhat SEO&lt;/a&gt; at the first place -- the latest SMS ransomware variant lacks any significant key visual features which can compete with for instance, the &lt;a href="http://ddanchev.blogspot.com/2008/10/fake-windows-xp-activation-trojan-wants.html"&gt;DIY fake Windows XP activation trojan&lt;/a&gt; and its &lt;a href="http://blogs.zdnet.com/security/?p=2201"&gt;2.0 version&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;With the emerging &lt;a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html"&gt;localization on demand services&lt;/a&gt; offering &lt;a href="http://ddanchev.blogspot.com/2008/11/localizing-cybercrime-cultural.html"&gt;translations for phishing, spam and malware campaigns&lt;/a&gt; into popular international languages, it wouldn't take long before the SMS ransomware starts targeting English-speaking users next to the hardcoded Russian speaking ones for the time being.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-5190029099433672201?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/5190029099433672201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/5190029099433672201'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/05/3rd-sms-ransomware-variant-offered-for.html' title='3rd SMS Ransomware Variant Offered for Sale'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_wICHhTiQmrA/Sh1yWvvFK2I/AAAAAAAADqQ/CY-STZId1LU/s72-c/sms_ransomware_windows_may_2009.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-8568186701086339644</id><published>2009-05-26T18:41:00.002+02:00</published><updated>2009-05-26T22:55:28.821+02:00</updated><title type='text'>Inside a Money Laundering Group's Spamming Operations</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/ShwQq_kTe6I/AAAAAAAADoo/IXsylpK2QKM/s1600-h/af-group-llc.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/ShwQq_kTe6I/AAAAAAAADoo/IXsylpK2QKM/s200/af-group-llc.png" /&gt;&lt;/a&gt;&lt;b&gt;UPDATE: &lt;/b&gt;The command and control domain has been taken care of courtesy of the brisk response of OC3 Networks Abuse Team.&lt;br /&gt;&lt;br /&gt;Next to the efficiency and cost-effectiveness centered cybercriminals having anticipated the &lt;a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html"&gt;outsourcing (Cybercrime-as-a-Service) model&lt;/a&gt; a long time ago, there are those self-serving groups of cybercriminals which engage in literally each and every aspect of cybercrime - &lt;a href="http://ddanchev.blogspot.com/2008/10/money-mules-syndicate-actively.html"&gt;money mule recruiters&lt;/a&gt; in this very specific case.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/ShwRI4XVNBI/AAAAAAAADow/4yWLpKjexzc/s1600-h/value-trans.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/ShwRI4XVNBI/AAAAAAAADow/4yWLpKjexzc/s200/value-trans.png" /&gt;&lt;/a&gt;What do the known money laundering aliases such as Value Trans Financial Group, Inc. (&lt;b&gt;valuetrans.biz&lt;/b&gt;); Advance Finance Group LLC (&lt;b&gt;af-g.net&lt;/b&gt;); ABP Capital (&lt;b&gt;abpcapital.com&lt;/b&gt;); Premium Financial Services (&lt;b&gt;advance-financial-products.org&lt;/b&gt;); eTop Group Inc. (&lt;b&gt;etop-groupli.cc&lt;/b&gt;); Liberty Group Inc. (&lt;b&gt;libertygroup.cc&lt;/b&gt;); Eagle Group Inc. (&lt;b&gt;eaglegroupmain.cn&lt;/b&gt;); Star Group Inc. (&lt;b&gt;eagle-group.net&lt;/b&gt;); DBS Group Inc. (&lt;b&gt;dbs-group.cn&lt;/b&gt;); FB&amp;amp;B Group Inc. (&lt;b&gt;fbb-groupli.cc&lt;/b&gt;); Advance Finance Group LLC (&lt;b&gt;af-g.net&lt;/b&gt;); DC Group Inc. (&lt;b&gt;dc-group.cn&lt;/b&gt;); IBS Group Inc. (&lt;b&gt;ibsgroup.cc&lt;/b&gt;; &lt;b&gt;ibsgroupli.cn&lt;/b&gt;) and FCB Group Inc. (&lt;b&gt;fcb-group.cc&lt;/b&gt;) have in common?&lt;br /&gt;&lt;br /&gt;It's a 31,000 infected hosts botnet which they use exclusively for spamming.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/ShwRwSr7h_I/AAAAAAAADo4/qgAYXp_X_60/s1600-h/lv-finance.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/ShwRwSr7h_I/AAAAAAAADo4/qgAYXp_X_60/s200/lv-finance.png" /&gt;&lt;/a&gt;&lt;b&gt;The money laundering organization describes itself as:&lt;/b&gt;&lt;br /&gt;"&lt;i&gt;The company was set up in 1990 in New York, the USA by three enthusiasts who have financial education. The head of the company was Karl Schick. At the very beginning of its business activity the company provided fairly narrow range of services at the investment market. Within 15 years of hard work the company has acquired international standing and managed to develop into a global financial holding with the staff of 3,000 people and headquarters in more than 100 countries of the world.&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/ShwVhcTRUsI/AAAAAAAADpA/eSPh-HeCsZA/s1600-h/money_mules_botnet_30k_8.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/ShwVhcTRUsI/AAAAAAAADpA/eSPh-HeCsZA/s200/money_mules_botnet_30k_8.png" /&gt;&lt;/a&gt;Interestingly, on the majority of occasions cybercriminals tend to undermine the level of operational security that they could have achieved at the first place, and this is one of those cases where their misconfigured botnet command and control allows other cybercriminals to hijack their botnet, and security researchers to shut it down effectively.&lt;br /&gt;&lt;br /&gt;The people behind this money laundering organization are either lazy, or ignorant to the point where the botnet's command and control interface would be using the very same web server that they use for recruitment purposes.&lt;br /&gt;&lt;br /&gt;Here are some screenshots of their command and control interface used exclusively for spam campaigns:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/ShwWLuS2JkI/AAAAAAAADpI/BR-zD27p-gg/s1600-h/money_mules_botnet_30k_1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/ShwWLuS2JkI/AAAAAAAADpI/BR-zD27p-gg/s320/money_mules_botnet_30k_1.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/ShwWa0ONScI/AAAAAAAADpQ/1fakJoBRWEI/s1600-h/money_mules_botnet_30k_2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/ShwWa0ONScI/AAAAAAAADpQ/1fakJoBRWEI/s320/money_mules_botnet_30k_2.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/ShwYulk4vDI/AAAAAAAADqA/NbMFyvKdPTk/s1600-h/money_mules_botnet_30k_3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/ShwYulk4vDI/AAAAAAAADqA/NbMFyvKdPTk/s320/money_mules_botnet_30k_3.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/ShwWxbcIOOI/AAAAAAAADpg/rDdQ75-FbUo/s1600-h/money_mules_botnet_30k_4.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/ShwWxbcIOOI/AAAAAAAADpg/rDdQ75-FbUo/s320/money_mules_botnet_30k_4.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/ShxXKfwl4nI/AAAAAAAADqI/ogYIdSN_9Xc/s1600-h/money_mules_botnet_30k_5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/ShxXKfwl4nI/AAAAAAAADqI/ogYIdSN_9Xc/s320/money_mules_botnet_30k_5.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/ShwXY09zakI/AAAAAAAADp4/eIucDx9ffZs/s1600-h/money_mules_botnet_30k_7.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/ShwXY09zakI/AAAAAAAADp4/eIucDx9ffZs/s320/money_mules_botnet_30k_7.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/ShwXOKNphlI/AAAAAAAADpw/809eqsCLaIc/s1600-h/money_mules_botnet_30k_6.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/ShwXOKNphlI/AAAAAAAADpw/809eqsCLaIc/s320/money_mules_botnet_30k_6.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;The domain is registered to &lt;b&gt;supp3ortnewest@safe-mail.net&lt;/b&gt; and the DNS services are courtesy of &lt;b&gt;one.goldwonderful9.info&lt;/b&gt;; &lt;b&gt;ns.partnergreatest8.net&lt;/b&gt;; &lt;b&gt;back.partnergreatest8.net&lt;/b&gt;; &lt;b&gt;two.goldwonderful9.info&lt;/b&gt; which are the de-facto DNS servers for a huge number of related and separate &lt;a href="http://www.bobbear.co.uk/"&gt;money laundering brand portfolios&lt;/a&gt; (the quality of the historical CYBERINT on behalf of Bobbear is the main reason why &lt;a href="http://ddanchev.blogspot.com/2008/11/ddos-attack-against-bobbearcouk.html"&gt;commissioned DDoS attacks&lt;/a&gt; were hitting the site last year).&lt;br /&gt;&lt;br /&gt;Taking down the group's command and control domain is in progress.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-8568186701086339644?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/8568186701086339644'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/8568186701086339644'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/05/inside-money-laundering-groups-spamming.html' title='Inside a Money Laundering Group&apos;s Spamming Operations'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_wICHhTiQmrA/ShwQq_kTe6I/AAAAAAAADoo/IXsylpK2QKM/s72-c/af-group-llc.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-1431607932180955353</id><published>2009-05-19T23:37:00.059+02:00</published><updated>2009-05-20T09:10:24.432+02:00</updated><title type='text'>GazTranzitStroyInfo - a Fake Russian Gas Company Facilitating Cybercrime</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/ShKuyTAh7DI/AAAAAAAADoI/1s-i0XqDwyo/s1600-h/gaztranzitstroyinfo.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/ShKuyTAh7DI/AAAAAAAADoI/1s-i0XqDwyo/s200/gaztranzitstroyinfo.png" /&gt;&lt;/a&gt;"&lt;i&gt;In gaz we trust&lt;/i&gt;"? I'd rather change &lt;b&gt;GazTranzitStroyInfo's &lt;/b&gt;vision to &lt;a href="http://ddanchev.blogspot.com/2008/08/76service-cybercrime-as-service-going.html"&gt;HangUp Team&lt;/a&gt;'s infamous - "&lt;i&gt;in fraud we trust&lt;/i&gt;". It is somehow weird to what lengths would certain cybercriminals go to create a feeling of legitimacy of their enterprise.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;AS29371&lt;/b&gt; - gaztranzitstroyinfo LLC - 91.212.41.0/24 based in Russia, Sankt Peterburg, Kropotkina 1, office 299, is one of them. Let's "drill" for some malicious activity at &lt;b&gt;GazTranzitStroyInfo, &lt;/b&gt;and demonstrate how cybercriminals are converging different hosting providers to increase the lifecycle of their campaigns.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/ShMmXA4bvzI/AAAAAAAADoQ/pDHuq1MI5E0/s1600-h/as29371_GazTranzitStroyInfo.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/ShMmXA4bvzI/AAAAAAAADoQ/pDHuq1MI5E0/s200/as29371_GazTranzitStroyInfo.png" /&gt;&lt;/a&gt;The &lt;a href="http://blog.threatfire.com/2009/05/softwarefortubeview-codec-schemes.html"&gt;recent peak of fake codecs&lt;/a&gt; (for instance &lt;b&gt;video-info .info&lt;/b&gt; and &lt;b&gt;sex-tapes-celebs .com&lt;/b&gt; serving &lt;a href="http://www.virustotal.com/analisis/c41a781f59f75e7022ce4bdd165117b0"&gt;softwarefortubeview.40018.exe&lt;/a&gt;) puts the spotlight on &lt;b&gt;GazTranzitStroyInfo &lt;/b&gt;and its connections with another rogue hosting provider in the face of &lt;b&gt;AS48841&lt;/b&gt;, EUROHOST-AS Eurohost LLC, which was providing hosting infrastructure to the scareware domains part of &lt;a href="http://ddanchev.blogspot.com/2009/04/confickers-scarewarefake-security.html"&gt;Conficker's Scareware Monetization strategy&lt;/a&gt;, and continues to do so for a great deal of exploits/malware serving domains, next to &lt;b&gt;AS10929&lt;/b&gt; &lt;a href="http://ddanchev.blogspot.com/2009/05/diverse-portfolio-of-fake-security.html"&gt;NETELLIGENT Hosting Services Inc.&lt;/a&gt; where the infrastructure of the three hosting providers has converged.&lt;br /&gt;&lt;br /&gt;Let's detail some malicious activity found at &lt;b&gt;GazTranzitStroyInfo. &lt;/b&gt;The following are redirectors to live exploits/zeus config files/scareware found within &lt;b&gt;AS29371&lt;/b&gt; and pushed through blackhat SEO and web site compromises:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/ShMmkLbst3I/AAAAAAAADoY/cztpfUDSb6Q/s1600-h/GazTranzitStroyInfo_scareware.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/ShMmkLbst3I/AAAAAAAADoY/cztpfUDSb6Q/s200/GazTranzitStroyInfo_scareware.JPG" /&gt;&lt;/a&gt;&lt;b&gt;peopleopera .cn&lt;/b&gt; - 91.212.41.96&lt;br /&gt;&lt;b&gt;forexsec .cn&lt;br /&gt;vitamingood .cn&lt;br /&gt;bookadorable .cn&lt;br /&gt;drawingstyle .cn&lt;br /&gt;housedomainname .cn&lt;br /&gt;workfuse .cn&lt;br /&gt;schoolh .cn&lt;br /&gt;rainfinish .cn&lt;br /&gt;housevisual .cn&lt;br /&gt;worksean .cn&lt;br /&gt;liteauction .cn&lt;br /&gt;newtransfer .cn&lt;br /&gt;oceandealer .cn&lt;br /&gt;musicdomainer .cn&lt;br /&gt;websiteflower .cn&lt;br /&gt;designroots .cn&lt;br /&gt;islandtravet .cn&lt;br /&gt;litefront .cn&lt;br /&gt;clubmillionswow .cn&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;softwaresupport-group .com&lt;/b&gt; - 91.212.41.91&lt;br /&gt;&lt;b&gt;bestfindahome .cn&lt;br /&gt;dastrealworld .ru&lt;br /&gt;elantrasantrope .ru&lt;br /&gt;borishoffbibi .ru&lt;br /&gt;sandiiegoexpo .ru&lt;br /&gt;nightplayauto .ru&lt;br /&gt;startdontstop .ru&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;nicdaheb .cn - &lt;/b&gt;91.212.41.119 &lt;b&gt;&lt;br /&gt;sehmadac .cn&lt;br /&gt;vavgurac .cn&lt;br /&gt;tixleloc .cn&lt;br /&gt;xidsasuc .cn&lt;br /&gt;cuzlumif .cn&lt;br /&gt;teyrebuf .cn&lt;br /&gt;hifgejig .cn&lt;br /&gt;tukhemaj .cn&lt;br /&gt;rogkadej .cn&lt;br /&gt;wuhwasum .cn&lt;br /&gt;sipcojeq .cn&lt;br /&gt;tixwagoq .cn&lt;br /&gt;silzefos .cn&lt;br /&gt;popyodiw .cn&lt;br /&gt;cakpapaz .cn &lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/ShOl9YUFoJI/AAAAAAAADog/kfHuia1V6Lg/s1600-h/GazTranzitStroyInfo_scareware1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/ShOl9YUFoJI/AAAAAAAADog/kfHuia1V6Lg/s200/GazTranzitStroyInfo_scareware1.jpg" /&gt;&lt;/a&gt;Rogue security software:&lt;br /&gt;&lt;b&gt;addedantivirusonline .com&lt;/b&gt; - 91.212.41.114 &lt;br /&gt;&lt;b&gt;addedantivirusstore .com&lt;br /&gt;addedantiviruslive.com&lt;br /&gt;addedantiviruspro.com&lt;br /&gt;countedantiviruspro.com&lt;br /&gt;myplusantiviruspro.com&lt;br /&gt;easyaddedantivirus.com&lt;br /&gt;yourcountedantivirus.com&lt;br /&gt;bestcountedantivirus.com&lt;br /&gt;yourplusantivirus.com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;For instance, a sampled domain such as &lt;b&gt;housedomainname &lt;/b&gt;&lt;b&gt;.cn/in.cgi?6&lt;/b&gt; redirects us to &lt;b&gt;securityonlinedirect .com&lt;/b&gt;/scan.php?affid=02083 which is &lt;a href="http://www.virustotal.com/analisis/2bfe53d6b4d1457b241a81e684a98ad3"&gt;serving scareware&lt;/a&gt; with hosting courtesy of &lt;b&gt;AS10929 &lt;/b&gt;Netelligent Hosting Services Inc, which in case you remember popped-up in the &lt;a href="http://ddanchev.blogspot.com/2009/05/diverse-portfolio-of-fake-security.html"&gt;Diverse Portfolio of Fake Security Software - Part Twenty&lt;/a&gt;. At &lt;b&gt;securityonlineworld .com&lt;/b&gt; (209.44.126.22) we also have a portfolio of scareware domains:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;thestabilityweb .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;securityonlineworld .com&lt;br /&gt;websecuritypolice .com&lt;br /&gt;wwwsafeexamine .com&lt;br /&gt;dynamicstabilityexamine .com&lt;br /&gt;networkstabilityexamine .com&lt;br /&gt;safetyscansite .com&lt;br /&gt;onlinesafetyscansite .com&lt;br /&gt;securityscansite .com&lt;br /&gt;stabilityonlineskim .com&lt;br /&gt;socialsecurityscan .com&lt;br /&gt;securityexamination .com&lt;br /&gt;internetsecuritymetrics .com&lt;br /&gt;onlinebrandsecuritys .com&lt;br /&gt;securityonlinedirect .com&lt;br /&gt;scanstabilityinternet .com&lt;br /&gt;stabilityaudit .com&lt;br /&gt;websecuritybureau .com&lt;br /&gt;safewebsecurity .com&lt;br /&gt;webbrowsersecurity .com&lt;br /&gt;futureinternetsecurity .com&lt;br /&gt;superiorinternetsecurity .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://www.virustotal.com/analisis/c41a781f59f75e7022ce4bdd165117b0%20"&gt;fake codec&lt;/a&gt; at &lt;b&gt;video-info .info &lt;/b&gt;(&lt;b&gt;AS29371&lt;/b&gt; - gaztranzitstroyinfo LLC) is in fact downloaded from &lt;b&gt;kir-fileplanet .com&lt;/b&gt; - 91.212.65.54 (&lt;b&gt;AS48841&lt;/b&gt;; EUROHOST-NET) where more malicious activity is easily detected at:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;downloadmax .org&lt;/b&gt; - 91.212.65.19&lt;br /&gt;&lt;b&gt;hd-codec .com&lt;br /&gt;shotgol .com&lt;br /&gt;kauitour .com&lt;br /&gt;coecount .com&lt;br /&gt;countbiz .com&lt;br /&gt;videoaaa .net&lt;br /&gt;7stepsmedia .net&lt;br /&gt;ispartof .net&lt;br /&gt;amoretour .net&lt;br /&gt;browardcount .net&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;trucount3000 .com&lt;/b&gt; - 91.212.65.10; 91.212.65.29&lt;br /&gt;&lt;b&gt;trucount3001 .com&lt;br /&gt;trucount3002 .com&lt;br /&gt;antivirus-xppro-2009.com&lt;br /&gt;onlinescanxppp .com&lt;br /&gt;onlinescanxpp .com&lt;br /&gt;onlinescanxp .com&lt;br /&gt;free-webscaners .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;In cybercriminals I don't trust.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/02/fake-codec-serving-domains-from.html"&gt;Fake Codec Serving Domains from Digg.com's Comment Spam Attack&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html"&gt;Lazy Summer Days at UkrTeleGroup Ltd&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/04/bogus-linkedin-profiles-redirect-to.html"&gt;Bogus LinkedIn Profiles Redirect to Malware and Rogue Security Software&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;Massive Blackhat SEO Campaign Serving Scareware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html"&gt;EstDomains and Intercage VS Cybercrime&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/07/template-ization-of-malware-serving.html"&gt;The Template-ization of Malware Serving Sites&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/02/template-ization-of-malware-serving.html"&gt;The Template-ization of Malware Serving Sites - Part Two&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=2695"&gt;Malware campaign at YouTube uses social engineering tricks&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/01/poisoned-search-queries-at-google-video.html"&gt;Poisoned Search Queries at Google Video Serving Malware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/syndicating-google-trends-keywords-for.html"&gt;Syndicating Google Trends Keywords for Blackhat SEO&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related Russian Business Network coverage:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/03/new-media-malware-gang-part-four.html"&gt;The New Media Malware Gang - Part Four&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/02/new-media-malware-gang-part-three.html"&gt;The New Media Malware Gang - Part Three&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/12/new-media-malware-gang-part-two.html"&gt;The New Media Malware Gang - Part Two&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/new-media-malware-gang.html"&gt;The New Media Malware Gang&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/03/rogue-rbn-software-pushed-through.html"&gt;Rogue RBN Software Pushed Through Blackhat SEO&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html"&gt;RBN's Phishing Activities&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/02/rbns-malware-puppets-need-their-master.html"&gt;RBN's Puppets Need Their Master&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/01/rbns-fake-account-suspended-notices.html"&gt;RBN's Fake Account Suspended Notices&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/go-to-sleep-go-to-sleep-my-little-rbn.html"&gt;Go to Sleep, Go to Sleep my Little RBN&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/exposing-russian-business-network.html"&gt;Exposing the Russian Business Network&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/detecting-and-blocking-russian-business.html"&gt;Detecting the Blocking the Russian Business Network&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/10/over-100-malwares-hosted-on-single-rbn.html"&gt;Over 100 Malwares Hosted on a Single RBN IP&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html"&gt;RBN's Fake Security Software&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/10/russian-business-network.html"&gt;The Russian Business Network&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-1431607932180955353?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/1431607932180955353'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/1431607932180955353'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/05/gaztranzitstroyinfo-fake-russian-gas.html' title='GazTranzitStroyInfo - a Fake Russian Gas Company Facilitating Cybercrime'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_wICHhTiQmrA/ShKuyTAh7DI/AAAAAAAADoI/1s-i0XqDwyo/s72-c/gaztranzitstroyinfo.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-4018519210697771610</id><published>2009-05-14T20:30:00.000+02:00</published><updated>2009-05-14T20:30:41.954+02:00</updated><title type='text'>A Diverse Portfolio of Fake Security Software - Part Twenty</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SgxVuxpSZgI/AAAAAAAADno/2sPJUUpJsvs/s1600-h/rogue_security_scareware_may_2009_1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SgxVuxpSZgI/AAAAAAAADno/2sPJUUpJsvs/s200/rogue_security_scareware_may_2009_1.png" /&gt;&lt;/a&gt;Has the cloudy economic climate hit &lt;a href="http://ddanchev.blogspot.com/2009/04/confickers-scarewarefake-security.html"&gt;the scareware business model&lt;/a&gt;, the single most efficient and high-liquidity monetization practice that's driving the majority of blackhat SEO and malware attacks?&amp;nbsp; The affiliate networks are either experiencing a slow Q2, or are basically experimenting with profit optimization strategies.&lt;br /&gt;&lt;br /&gt;Following the "aggressive" piece of &lt;a href="http://blogs.zdnet.com/security/?p=3014"&gt;scareware with elements of ransomware&lt;/a&gt; discovered in March, a new version of the &lt;a href="http://www.avertlabs.com/research/blog/index.php/2009/05/12/fakealert-trojan-holds-systems-for-ransom/"&gt;rogue security software&lt;/a&gt; is once again holding an &lt;a href="http://blog.fireeye.com/research/2009/03/a-new-method-to-monetize-scareware.html"&gt;infected system's assets hostage&lt;/a&gt; until a license is purchased.&lt;br /&gt;&lt;br /&gt;This tactic is however a great example of the dynamics of underground ecosystem (&lt;a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html"&gt;The Dynamics of the Malware Industry - Proprietary Malware Tools&lt;/a&gt;; &lt;a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html"&gt;The Underground Economy's Supply of Goods&lt;/a&gt;; &lt;a href="http://ddanchev.blogspot.com/2008/08/76service-cybercrime-as-service-going.html"&gt;76Service - Cybercrime as a Service Going Mainstream&lt;/a&gt;; &lt;a href="http://ddanchev.blogspot.com/2008/12/zeus-crimeware-as-service-going.html"&gt;Zeus Crimeware as a Service Going Mainstream&lt;/a&gt;; &lt;a href="http://ddanchev.blogspot.com/2008/11/will-code-malware-for-financial.html"&gt;Will Code Malware for Financial Incentives&lt;/a&gt;; &lt;a href="http://ddanchev.blogspot.com/2009/02/cost-of-anonymizing-cybercriminals.html"&gt;The Cost of Anonymizing a Cybercriminal's Internet Activities - Part Two&lt;/a&gt;; &lt;a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html"&gt;Using Market Forces to Disrupt Botnets&lt;/a&gt;; &lt;a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html"&gt;E-crime and Socioeconomic Factors&lt;/a&gt;; &lt;a href="http://ddanchev.blogspot.com/2008/06/price-discrimination-in-market-for.html"&gt;Price Discrimination in the Market for Stolen Credit Cards&lt;/a&gt;; &lt;a href="http://ddanchev.blogspot.com/2008/07/are-stolen-credit-card-details-getting.html"&gt;Are Stolen Credit Card Details Getting Cheaper?&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;Despite the fact that it's the network of cybercriminals that pays and motivates other cybercriminals to SQL inject legitimate sites, send spam, embedd malicious code through compromised accounts and launch blackhat SEO campaigns, it cannot exist without the traffic that they provide, and is therefore competing with other affiliate networks for it.&lt;br /&gt;&lt;br /&gt;For your blacklisting, case-building and cross-checking pleasure, currently active blackhat SEO and Koobface campaigns monetize the traffic through the following rogue domains:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SgxdwSXLW5I/AAAAAAAADnw/9d59XLvkUa8/s1600-h/rogue_security_software_may_2009.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SgxdwSXLW5I/AAAAAAAADnw/9d59XLvkUa8/s200/rogue_security_software_may_2009.png" /&gt;&lt;/a&gt;&lt;b&gt;yourpcshield .com&lt;/b&gt; (209.44.126.14) - AS10929 NETELLIGENT Hosting Services Inc. Email: &lt;b&gt;bershkapull@gmail.com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;virustopshield .com&lt;br /&gt;totalvirushield .com&lt;br /&gt;pcguardscan .com&lt;br /&gt;topwinsystemscan .com&lt;br /&gt;basevirusscan .com&lt;br /&gt;systemvirusscan .com&lt;br /&gt;bastvirusscan .com&lt;br /&gt;myfirstsecurityscan .com&lt;br /&gt;fastviruscleaner .com&lt;br /&gt;allvirusscannow .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;freeforscanpc .com&lt;/b&gt; (209.44.126.241) - AS10929 NETELLIGENT Hosting Services Inc.&lt;br /&gt;&lt;b&gt;truevirusshield .com&lt;br /&gt;totalvirusshield .com&lt;br /&gt;hypersecurityshield .com&lt;br /&gt;scanyourpconline .com&lt;br /&gt;allowedwebsurfing .com&lt;br /&gt;xvirusdescan .com&lt;br /&gt;securitytrustscan .com&lt;br /&gt;fullsecurityaction .com&lt;br /&gt;fullvirusprotection .com&lt;br /&gt;fullsecuritydefender .com&lt;br /&gt;hupersecuritydot .com&lt;br /&gt;trustedwebsecurity .com&lt;br /&gt;greatscansecurity .com&lt;br /&gt;updateyoursecurity .com&lt;/b&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Sgxd3rS6t3I/AAAAAAAADn4/t5dLlDnDktg/s1600-h/rogue_security_scareware_may_2009_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Sgxd3rS6t3I/AAAAAAAADn4/t5dLlDnDktg/s200/rogue_security_scareware_may_2009_2.png" /&gt;&lt;/a&gt;&lt;b&gt;antimalware-scannerv2 .com&lt;/b&gt; (78.46.88.202) - AS16265 LeaseWeb AS Amsterdam, Netherlands Email: &lt;b&gt;basni@lewispr.com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;onlinevirusbusterv2 .com&lt;br /&gt;xpvirusprotection2009 .com&lt;br /&gt;total-malwareprotection .com&lt;br /&gt;total-virusprotection .com&lt;br /&gt;xpvirusprotection .com&lt;br /&gt;bestbillingpro .com&lt;br /&gt;truconv .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;safeinternettoolv1 .com&lt;/b&gt; (212.117.165.126; 38.99.170.9; 69.4.230.204; 78.47.91.153) - AS36351 SOFTLAYER Technologies Inc; AS24940 HETZNER-AS Hetzner Online AG RZ-Nuernberg; AS44042 ROOT-AS root eSolutions; AS174 COGENT /PSI Email: &lt;b&gt;info@dmf.com.tr&lt;/b&gt;&lt;br /&gt;&lt;b&gt;antivirusquickscanv1 .com&lt;br /&gt;computerscanv1 .com&lt;br /&gt;antivirusbestscannerv1 .com&lt;br /&gt;antiviruslivescanv3 .com&lt;br /&gt;proantivirusscanv3 .com&lt;br /&gt;fullantispywarescan .com&lt;br /&gt;webscannertools .com&lt;br /&gt;approved-payments .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SgxeF3wEADI/AAAAAAAADoA/U9bsvWaxm5c/s1600-h/rogue_security_scareware_may_2009_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SgxeF3wEADI/AAAAAAAADoA/U9bsvWaxm5c/s200/rogue_security_scareware_may_2009_3.png" /&gt;&lt;/a&gt;&lt;b&gt;ms-scan .org&lt;/b&gt; (84.19.184.160) - AS31103 KEYWEB-AS Keyweb AG, Email: &lt;b&gt;strider.glider@gmail.com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;system-protector .org&lt;br /&gt;system-protector .net&lt;br /&gt;av-lookup .com&lt;br /&gt;ms-scan .info&lt;br /&gt;srv-scan .us&lt;br /&gt;ms-scan .net&lt;br /&gt;ms-scan .biz&lt;br /&gt;srv-scan .biz&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;bitcoreguard .net&lt;/b&gt; (72.232.187.197) AS22576 LAYEREDTECH Layered Technologies, Email: &lt;b&gt;cbristed1996@gmail.com &lt;/b&gt;&lt;br /&gt;&lt;b&gt;bitcoreguard .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;coreguard2009 .com&lt;/b&gt; (78.46.151.181) - AS24940 HETZNER-AS Hetzner Online AG RZ-Nuernberg Email: &lt;b&gt;iversbradly72@gmail.com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;coreguard2009 .biz&lt;br /&gt;coreguard2009 .net&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;coreguardlab2009 .biz&lt;/b&gt; (95.211.14.161) - AS16265 LeaseWeb AS Amsterdam, Netherlands, Email: &lt;b&gt;stivpanama@gmail.com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;coreguardlab2009 .net&lt;br /&gt;coreguardlab2009 .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;guardlab .com&lt;/b&gt; (72.232.187.198) - AS22576 LAYEREDTECH Layered Technologies Email: &lt;b&gt;alexvasiliev1987@cocainmail.com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;guardav .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;guardlab2009 .biz&lt;/b&gt; (76.76.103.164) - AS21548 MTO Telecom Inc. Email: &lt;b&gt;stivpanama@gmail.com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;guardlab2009 .net&lt;br /&gt;guardlab2009 .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/05/dissecting-swine-flu-black-seo-campaign.html"&gt;Dissecting a Swine Flu Black SEO Campaign&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;Massive Blackhat SEO Campaign Serving Scareware&lt;/a&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;a href="http://ddanchev.blogspot.com/2009/04/diverse-portfolio-of-fake-security_16.html"&gt;A Diverse Portfolio of Fake Security Software - Part Nineteen&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/04/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Eighteen&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/03/diverse-portfolio-of-fake-security_31.html"&gt;A Diverse Portfolio of Fake Security Software - Part Seventeen&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/03/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Sixteen&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/02/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Fifteen &lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/01/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Fourteen&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/11/diverse-portfolio-of-fake-security_12.html"&gt;A Diverse Portfolio of Fake Security Software - Part Thirteen&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/11/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Twelve&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_28.html"&gt;A Diverse Portfolio of Fake Security Software - Part Eleven&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_22.html"&gt;A Diverse Portfolio of Fake Security Software - Part Ten&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security_16.html"&gt;A Diverse Portfolio of Fake Security Software - Part Nine&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/diverse-portfolio-of-fake-security.html"&gt;A Diverse Portfolio of Fake Security Software - Part Eight&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html"&gt;A Diverse Portfolio of Fake Security Software - Part Seven&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html"&gt;A Diverse Portfolio of Fake Security Software - Part Six&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html"&gt;A  Diverse Portfolio of Fake Security Software - Part Five&lt;/a&gt; &lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html"&gt;A  Diverse Portfolio of Fake Security Software - Part Four&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html"&gt;A  Diverse Portfolio of Fake Security Software - Part Three&lt;/a&gt; &lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html"&gt;A  Diverse Portfolio of Fake Security Software - Part Two&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html"&gt;Diverse  Portfolio of Fake Security Software&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-4018519210697771610?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/4018519210697771610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/4018519210697771610'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/05/diverse-portfolio-of-fake-security.html' title='A Diverse Portfolio of Fake Security Software - Part Twenty'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wICHhTiQmrA/SgxVuxpSZgI/AAAAAAAADno/2sPJUUpJsvs/s72-c/rogue_security_scareware_may_2009_1.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-2651208588279576459</id><published>2009-05-12T13:46:00.001+02:00</published><updated>2009-05-13T01:17:14.499+02:00</updated><title type='text'>SMS Ransomware Source Code Now Offered for Sale</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SglXgnSIDXI/AAAAAAAADng/OxiWO4xsm5o/s1600-h/sms_ransomware.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="105" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SglXgnSIDXI/AAAAAAAADng/OxiWO4xsm5o/s200/sms_ransomware.jpg" width="200" /&gt;&lt;/a&gt;Remember the &lt;a href="http://blogs.zdnet.com/security/?p=3197"&gt;ransomware variant that was locking down user's PCs&lt;/a&gt; and demanding a premium SMS in order for them to receive the unlocking code?&lt;br /&gt;&lt;br /&gt;In an attempt to further monetize the "innovative" practice of converging Windows-based malware and premium SMS numbers operated by the cybercriminals, a do-it-yourself version of the ransomware is currently offered for sale for a mere $15.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Here are some of its features:&lt;/b&gt;&lt;br /&gt;- When executed presents the uset with a Blue Screen of Death style error message&lt;br /&gt;- A simple auto-loading feature ensuring it will load every time the host is rebooted, completely disables the startup shell in order to become the first application to appear upon reboot&lt;br /&gt;- Disables Windows Task Manager, Registry Editor, default shortcuts for terminating a program&lt;br /&gt;&lt;br /&gt;The vendor would also like to remind its customers that "the application is for educational purposes only", next to a comment on how all of their current customers are fully satisfied with the money they're making by locking infected user's PCs. This piece of ransomware has been spreading across the Russian web space since April, and with its source code now offered for sale, it's only a matter of time before the error messages get localized to multiple languages courtesy of &lt;a href="http://ddanchev.blogspot.com/2008/11/localizing-cybercrime-cultural.html"&gt;localization on demand cybercrime-friendly services&lt;/a&gt; breaking any language barrier for a spam/malware campaign.&lt;br /&gt;&lt;br /&gt;However, from an operational security (OPSEC) perspective which I often emphasize on in order to demonstrate how efficient cybercrime facilitating tactics increase the probability of successfully tracking down the people behind a particular attack, this premium SMS based ransomware tactic is exposing the people behind the campaign much easily due to its reliance on a mobile operator, compared to GPCode's virtual money exchange approach (&lt;a href="http://blogs.zdnet.com/security/?p=1259"&gt;Who's behind the GPcode ransomware?&lt;/a&gt;) which given they put enought efforts, the process can be virtually untraceable.&lt;br /&gt;&lt;br /&gt;Despite the fact that vendors have already released &lt;a href="http://news.drweb.com/show/?i=304&amp;amp;c=5"&gt;unlock code generators&lt;/a&gt; for the SMS ransomware, taking into consideration the potential for widespread ransomware campaigns through the now ubiqitous revenue generator in the form of scareware (&lt;a href="http://blogs.zdnet.com/security/?p=3014"&gt;Scareware meets ransomware: "Buy our fake product and we'll decrypt the files"&lt;/a&gt;), the concept is not going away anytime soon.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/07/mobile-malware-scam-isexplayer-wants.html"&gt;Mobile Malware Scam iSexPlayer Wants Your Money&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=2415"&gt;New mobile malware silently transfers account credit&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=2617"&gt;New Symbian-based mobile worm circulating in the wild&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-2651208588279576459?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/2651208588279576459'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/2651208588279576459'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/05/sms-ransomware-source-code-now-offered.html' title='SMS Ransomware Source Code Now Offered for Sale'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_wICHhTiQmrA/SglXgnSIDXI/AAAAAAAADng/OxiWO4xsm5o/s72-c/sms_ransomware.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-4606897999653962554</id><published>2009-05-06T19:45:00.003+02:00</published><updated>2009-05-07T15:54:49.977+02:00</updated><title type='text'>Dating Spam Campaign Promotes Bogus Dating Agency</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SgHF6LLQNoI/AAAAAAAADmY/PfxeIIKTJDI/s1600-h/dating_spam_campaign_may_2009.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SgHF6LLQNoI/AAAAAAAADmY/PfxeIIKTJDI/s200/dating_spam_campaign_may_2009.JPG" /&gt;&lt;/a&gt;From Sweet Sugar Anastasia, Svetlana, Angela, Marino4ka, Irina, Hot Julia, Ane4ka, Nastya, and Yulia, to the &lt;a href="http://ddanchev.blogspot.com/2007/11/lonely-polinas-secret.html"&gt;Lonely Polina&lt;/a&gt; and the &lt;a href="http://ddanchev.blogspot.com/2008/04/malware-and-exploits-serving-girls.html"&gt;malware and exploits serving girls&lt;/a&gt;, Russian/Ukrainian dating scams are still pretty active these days.&lt;br /&gt;&lt;br /&gt;A recently spammed dating campaign exposes the fraudulent practices of a well known such agency (&lt;b&gt;Confidential Connections&lt;/b&gt;) that has been &lt;a href="http://agencyscams.com/Why/ConfidentialConnections.html"&gt;changing its name, typosquatting new domains&lt;/a&gt; in order to remain beneath the radar, a bit of an awkward practice given their noisy spamming approach of attracting visitors.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;The spam's message:&lt;/b&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SgHPKulGvBI/AAAAAAAADmw/nK1EggYrgeg/s1600-h/scam_dating_agency_spamvertised1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SgHPKulGvBI/AAAAAAAADmw/nK1EggYrgeg/s200/scam_dating_agency_spamvertised1.png" /&gt;&lt;/a&gt;"&lt;i&gt;Good day, my gentleman!&lt;br /&gt;&lt;br /&gt;All love is probationary, a fact which frightens women and exhilarates men. I believe that unarmed truth and unconditional love will have the final word in reality. I was born in a friendly, cultured family and would like to have the same family in my own life. I love nature, flowers, music, dancing. I like to receive guests at home and spend time with friends. I always try to use opportunity to travel and see new places in the world. I have a good, quite and merry character, don't like argues and rows. I hope to meet a white man, Christian, clever. Besides I would like to meet a good person with a good sense of humor, who wants to create a good strong family. If you would be loved, love and be lovable. I am waiting for you &lt;b&gt;http://iam-waiting4love .com/infinity/&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Waiting for your mail&lt;br /&gt;Sveetlana B.&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;The user is then asked to register at &lt;b&gt;hifor-you .com/register.php&lt;/b&gt; followed by an email confirmation explaining how the agency/scam at &lt;b&gt;ualadys .com&lt;/b&gt; (76.74.250.239 Email: Tyom13@aol.com) works:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SgHPWfWshiI/AAAAAAAADm4/wM0v-IUh6UQ/s1600-h/scam_dating_agency_spamvertised2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SgHPWfWshiI/AAAAAAAADm4/wM0v-IUh6UQ/s200/scam_dating_agency_spamvertised2.png" /&gt;&lt;/a&gt;"&lt;i&gt;We view ourselves as more of MATCHMAKERS than a mere Introduction Company. We DO NOT BUY OR SELL addresses of Ladies from other agents. Rather, we take the time and effort to meet each Lady referred to us in person, interview her at length, checkout her credentials to make sure her intentions are proper, before she gets hosted as our client. It is this knowledge of the Ladies that allows us to select the right persons to introduce to each man.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SgHGQFeHSWI/AAAAAAAADmg/XHap1brZiq8/s1600-h/scam_dating_agency_spamvertised.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SgHGQFeHSWI/AAAAAAAADmg/XHap1brZiq8/s200/scam_dating_agency_spamvertised.png" /&gt;&lt;/a&gt;&lt;i&gt;Compatibility is the KEY. Our formula is simple, yet highly productive: &lt;br /&gt;1. You fill out our profile, same as the Ladies &lt;br /&gt;2. Select the Ladies you would like to meet &lt;br /&gt;3. Until you have a predetermined amount of Ladies reply with a yes &lt;br /&gt;4. During your trip meetings are scheduled on a private, one-on-one setting, with an interpreter to assist you (if you require one) We know that your time is limited when you go on trip. This is a very efficient selections process that saves your time and, in fact, allows you the extra time to really get to know the Ladies.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;All meetings are one-on-one. We do not organize socials that do not work. Our service is usually based upon a male clients access to time and his available budget. The normal procedure is for a client to look through our gallery of Ladies, select the Ladies for pre-qualification, and correspond with them by e-mail or phone, than arrange a one-on-one visit. Still others, after viewing the Ladies, decide that the best overall approach would be to simply go there and meet as many women as we can arrange for them to meet, and spend time with them before making a decision. &lt;br /&gt;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SgHG7d0JOOI/AAAAAAAADmo/4JmuSFsAVGw/s1600-h/scam_dating_agency_spamvertised1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SgHG7d0JOOI/AAAAAAAADmo/4JmuSFsAVGw/s200/scam_dating_agency_spamvertised1.JPG" /&gt;&lt;/a&gt;&lt;i&gt;Also experiencing first-hand their environment and culture gives the man a future understanding of his future bride. OUR PERSONAL INTRODUCTION TRIP HAS BEEN YEILDING A 95% SUCCESS RATE! Again, the reason for this is the growing frustration among the Ladies about the lack of follow through the men, Consequently, many Ladies do not respond to letters, knowing that few ever follow through. They simply wait to meet the men who go there. THUS, THE SITUATION HAS BECOME A DREAM FOR THE MAN WHO ARE SERIOUS. &lt;br /&gt;&lt;br /&gt;During our Special Photoshoot Trips (e-mail for dates); you will get an opportunity to watch and meet new Ladies. Many times, clients pick these new Ladies because they are fresh and no one has ever met them before. We have quite a few Ladies who have never made it to the gallery because they got engaged immediately to the men who went no trips.&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;The agency is also &lt;a href="http://photo.ualadys.com/engl/ladies_antiscam.html"&gt;reserving the right to forward the responsibility for any fraudulent activities to the girls&lt;/a&gt;, the majority of which do not exist at the first place in the following way:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;All scam patterns have similarities that are very easy to spot if you know  what to watch out for:&lt;/b&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Usually the contact originates from a personals site where anyone can place  his/her ad for free. Most often it was not you who initiated the acquaintance;  you received a letter from a lovely Russian female who was interested in you.  *Her* description of the partner is always very broad that will fit anybody -  "kind intelligent man, age and race don't matter".&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Sometimes *she* places a real nice discription and lovely, INNOCENT  pictures, with honest eyes and kind smile. You will initiate the acquaintance.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;It is always email correspondence; and letters are sent regularly, often  every day; a new picture is sent with almost every letter. &lt;/li&gt;&lt;/ul&gt;This is very entertaining since the agency is driving traffic to its domains through spamming. The full list of spammed domains part of the campaign :&lt;br /&gt;&lt;b&gt;love-f-emale .com &lt;/b&gt;- 62.90.136.207 &lt;b&gt;&lt;br /&gt;i-amsingle .com&lt;br /&gt;for-you-from-me .com&lt;br /&gt;destinycombine .com&lt;br /&gt;with-hope-for-love .com&lt;br /&gt;iam-waiting4love .com&lt;br /&gt;allisloveandlove .com&lt;br /&gt;amourwedding .com&lt;br /&gt;adorelovewon .com&lt;br /&gt;andiloveyoutoo .com&lt;br /&gt;attractive-ladies .com&lt;br /&gt;luckyheatrs .com&lt;br /&gt;sunwants .com&lt;br /&gt;myloving-heart .com &lt;br /&gt;touchmy-heart .com&lt;br /&gt;dreams-about-lady .com&lt;br /&gt;fillinglove .net&lt;br /&gt;createyourlove .net&lt;br /&gt;buildyour-happylove .net&lt;br /&gt;tender-woman .net&lt;br /&gt;make-family .net&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SgHPlGWAueI/AAAAAAAADnA/m0HqF8sCi2o/s1600-h/scam_dating_agency_spamvertised3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="160" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SgHPlGWAueI/AAAAAAAADnA/m0HqF8sCi2o/s200/scam_dating_agency_spamvertised3.png" width="200" /&gt;&lt;/a&gt;There's something "ingenious" about this type of dating scams, since the bogus dating agency can forward the scam responsibility to the non-existent girls at the first place. Moreover, despite the countless number of email credits, flowers and photos that you've purchased by using the agency's commercial services, the non-existent girl can always reserve the right not to meet or interact with you in any way. And even if there are actual girls working for the ad agency on a revenue-sharing basis, the agency silently makes money by reserving its right to ruin your return on investment no matter how much and what you spend on their site. &lt;br /&gt;&lt;br /&gt;Now, that's a business model scamming the gullible and the lonely, which from a legal perspective -- excluding the spamming -- can in fact be legal in the country of operation due to the eventual mis-matching of characters.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;UPDATE:&lt;/b&gt;&lt;br /&gt;The people from "&lt;a href="http://www.ualadys.com/engl/welcome_mission.html"&gt;Confidential Connections&lt;/a&gt;" have a long history of spamming/scamming activities. Here are more related resources:&lt;br /&gt;&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;a href="http://www.russianmeetingplace.com/forums/showthread.php?threadid=14715"&gt;A first-person account&lt;/a&gt;:&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SgIUWhAyp6I/AAAAAAAADnI/vD3MCFqV70Q/s1600-h/Mega%2520Centre_Confidential_Connections_office.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SgIUWhAyp6I/AAAAAAAADnI/vD3MCFqV70Q/s200/Mega%2520Centre_Confidential_Connections_office.jpg" /&gt;&lt;/a&gt;"&lt;i&gt;..ualadies... I work as a guide and translator for guys seeking a wife in Ukraine, and a client just came to me who was due to meet a girl from this agency. Im so wound up by the actions of this agency that i am going to post this thread in every scam forum i know about. Here is a short list of what they did:&lt;br /&gt;&lt;br /&gt;1) Put him in a taxi to pick up the girl and take her to the restaurant, then charged him $80 for what should have been a $10 journey&lt;br /&gt;2) Charged him $60 for a one hour translation, saying that they take a minimum charge of 4 hours ($15 an hour)..this they told him only after the meeting&lt;br /&gt;3) After my client had payed (a very steep $50) to meet the girl, he got her address and decided to send her some flowers (at the local rate of 2 dollars for 1 rose, as apposed to 10 dollars a rose at the agency). The agency, upon finding out about this, called him up and shouted at him for daring to send her roses not through them (!)&lt;br /&gt;&amp;nbsp;&lt;/i&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SgLn24iiyFI/AAAAAAAADnQ/cioDg9piQig/s1600-h/Day%25203%2520Restaurant.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SgLn24iiyFI/AAAAAAAADnQ/cioDg9piQig/s200/Day%25203%2520Restaurant.jpg" /&gt;&lt;/a&gt;&lt;i&gt;4) It turned out that the girl hadn't written most of the letters the client had shared with her over a period of a year, and in fact that the agency themselves had written them, earning good money in the proccess!&lt;br /&gt;5) The agency lied about the upper age limit for a guy the girl was willing to meet - they put down 60 when she had indicated 40.&lt;br /&gt;6) There is more!...but i think ive written enough for you to get the idea. &lt;br /&gt;&lt;br /&gt;Be aware of this agency! In all my time as a guide/translator i have never seen an agency that works so shambolicaly. Agencies like this ruin the reputation of the business, in which there are number of hard working honest agencies that suffer as a result.&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.russianwomendiscussion.com/Forum/index.php?topic=4222"&gt;More comments from the same person&lt;/a&gt;, presumably working there:&lt;br /&gt;"&lt;i&gt;Beware of ualadys. I live in Ukraine and know someone who works in one of the branches. Word has it that they churn out letters factory-style and often write themselves. They do not allow their girls to turn down a man who has requested to communicate with them, even if they dont want to. They did not allow me to go to their office to check them out and ask them questions. They scare the girls so that they dont get in personal contact with a guy or go to another agency. Beware!&lt;/i&gt;"&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SgLoBMejnhI/AAAAAAAADnY/xyHvq27wX5w/s1600-h/Day%25203%2520Ring%2520after%2520Restaurant%25202.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SgLoBMejnhI/AAAAAAAADnY/xyHvq27wX5w/s200/Day%25203%2520Ring%2520after%2520Restaurant%25202.jpg" /&gt;&lt;/a&gt;&lt;a href="http://www.ualadyscam.com/photo_gallery/photo_gallery.htm"&gt;Exclusive photo gallery&lt;/a&gt; from what appears to be a scammed customer -- wedding rings are in place. The guy was &lt;a href="http://www.ualadyscam.com/default.htm"&gt;initially spammed&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;"&lt;i&gt;On June 23rd of 2008 (that was 5 months after I gave up my relationship with my ex girlfriend),&amp;nbsp; I received one email from UAladys which stated it was translated for a lady in Ukraine. Her name is Anastasia R. (ID 5008) Her introduction letter went as follows&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;Thankfully, he's preserved &lt;a href="http://www.ualadyscam.com/Correspondences/"&gt;the achive of the correspondence&lt;/a&gt;, exposing their practices.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-4606897999653962554?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/4606897999653962554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/4606897999653962554'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/05/dating-spam-campaign-promotes-bogus.html' title='Dating Spam Campaign Promotes Bogus Dating Agency'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wICHhTiQmrA/SgHF6LLQNoI/AAAAAAAADmY/PfxeIIKTJDI/s72-c/dating_spam_campaign_may_2009.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-440847893545997882</id><published>2009-05-06T16:05:00.000+02:00</published><updated>2009-05-06T16:05:07.845+02:00</updated><title type='text'>Dissecting a Swine Flu Black SEO Campaign</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SgGIdERVfpI/AAAAAAAADlo/TGddvIaK9yM/s1600-h/swine_flu_blackhat_SEO_4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SgGIdERVfpI/AAAAAAAADlo/TGddvIaK9yM/s200/swine_flu_blackhat_SEO_4.JPG" /&gt;&lt;/a&gt;Remember the Ukrainian group of cyber criminals that was responsible for last week's &lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;massive blackhat SEO campaign that was serving scareware&lt;/a&gt;, followed by the &lt;a href="http://ddanchev.blogspot.com/2009/04/twitter-worm-mikeyy-keywords-hijacked.html"&gt;timely hijacking of Mickeyy worm keywords&lt;/a&gt; a week earlier to once again serve rogue security software?&lt;br /&gt;&lt;br /&gt;They are back with new blackhat SEO farms which they continue monetizing through &lt;a href="http://ddanchev.blogspot.com/2009/04/diverse-portfolio-of-fake-security_16.html"&gt;rogue security software&lt;/a&gt;. Time to dissect their latest campaign and expose their malicious practices.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SgGE5Gm5fII/AAAAAAAADlg/OWyMcodlPLY/s1600-h/swine_flu_blackhat_SEO_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SgGE5Gm5fII/AAAAAAAADlg/OWyMcodlPLY/s200/swine_flu_blackhat_SEO_3.JPG" /&gt;&lt;/a&gt;Once having most of their previous domains blacklisted/shut down, the group naturally introduced new ones, and changed the search engine optimization theme to swine flu, in between a variation of their previous one relying on catchy titles such as &lt;i&gt;USA News; BBC News; CNN News as well as Hottest info!; HOT NEWS; Official Website and Official Site&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SgGLimsJxkI/AAAAAAAADl4/DYx_qPgkrSE/s1600-h/swine_flu_blackhat_SEO_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SgGLimsJxkI/AAAAAAAADl4/DYx_qPgkrSE/s200/swine_flu_blackhat_SEO_2.JPG" /&gt;&lt;/a&gt;Upon visiting the site, an obfuscated iFrame statically hosted on all of the participating domains in the form of &lt;b&gt;2qnews.07x .net/images/menu.js&lt;/b&gt; redirects the user to &lt;b&gt;sexerotika2009 .ru/admin/red/en.php&lt;/b&gt; (74.54.176.50; Email: rebsdtis@land.ru). Are you noticing the &lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Se83RHR2GwI/AAAAAAAADkA/-aXt_tCa3_k/s1600-h/blackhat_seo_news_scareware_11.JPG"&gt;directory structure similarities&lt;/a&gt;? Appreciate my rhetoric, it's last month's &lt;a href="http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html"&gt;blackhat SEO gang with a new portfolio of domains&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SgGT_aLXRZI/AAAAAAAADmA/n5mgTRh-AK8/s1600-h/swine_flu_blackhat_SEO.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SgGT_aLXRZI/AAAAAAAADmA/n5mgTRh-AK8/s200/swine_flu_blackhat_SEO.JPG" /&gt;&lt;/a&gt;What follows is the usual referrer check : "&lt;i&gt;var ref,i,is_se=0; var se = new Array("google.","msn.","yahoo.","comcast.","aol.");&lt;/i&gt;" from where the user is redirected to &lt;b&gt;liveavantbrowser2 .cn/go.php?id=2022&amp;amp;key=4c69e59ac&amp;amp;p=1 &lt;/b&gt;(83.133.123.140) acting as central redirection point to the typosquatted portfolio of rogue security software domains.&lt;br /&gt;&lt;br /&gt;The original scareware domain &lt;b&gt;vrusstatuscheck .com/1/?id=2022&amp;amp;smersh=a9fd94859&amp;amp;back=%3DjQ51TT1MUQMMI%3DN&lt;/b&gt; - (69.4.230.204; 38.99.170.209; 78.47.172.66; 78.47.91.153; 94.76.212.239; 94.102.48.28) is exposing the rest of the scareware (&lt;a href="http://www.virustotal.com/analisis/18e8d52529e7f0d58bd706663058d341"&gt;detection rate&lt;/a&gt;) portfolio with the following domains parked at these IPs:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;antivirusbestscannerv1 .com&lt;br /&gt;antivirus-powerful-scanv2 .com&lt;br /&gt;antivirus-powerful-scannerv2 .com&lt;br /&gt;virusinfocheck .com&lt;br /&gt;vrusstatuscheck .com&lt;br /&gt;adware-removal-tool .com&lt;br /&gt;1quickpcscanner .com&lt;br /&gt;1spywareonlinescanner .com&lt;br /&gt;1computeronlinescanner .com&lt;br /&gt;1bestprotectionscanner .com&lt;br /&gt;securityhelpcenter .com&lt;br /&gt;antivirus-online-pro-scan .com&lt;br /&gt;securedonlinecomputerscan .com&lt;br /&gt;antispywarepcscanner .com&lt;br /&gt;securedvirusscanner .com&lt;br /&gt;virusinfocheck .com&lt;br /&gt;antivirusbestscannerv1 .com&lt;br /&gt;antispywareupdateservice .com&lt;br /&gt;platinumsecurityupdate .com&lt;br /&gt;antispywareupdatesystem .com&lt;br /&gt;onlineupdatessystem .com&lt;br /&gt;softwareupdatessystem .com&lt;br /&gt;securedpaymentsystem .com&lt;br /&gt;infosecuritycenter .com&lt;br /&gt;antispywareproupdates .com&lt;br /&gt;securedsoftwareupdate .cn&lt;br /&gt;securedupdateslive .cn&lt;br /&gt;thankyouforinstall .cn&lt;br /&gt;securityupdatessystem .cn&lt;br /&gt;securedsystemresources .cn&lt;br /&gt;securedosupdates .cn&lt;br /&gt;windowssecurityupdates .cn&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Once executed it downloads Microsoft's original thank you note (&lt;b&gt;update.microsoft.com/windowsupdate/v6/thanks.aspx&lt;/b&gt;), and confirms the installation so that the blackhat SEO campaigners will receive a piece of the pie at &lt;b&gt;securedliveuploads .com/?act=fb&amp;amp;1=0&amp;amp;2=0&amp;amp;3=kfddnffaffihlcoemdkedcaefcfaffedhfmdmboc&amp;amp;4=eebajfjafekaifnbddghoclg&amp;amp;5=22&amp;amp;6=1&amp;amp;7=63&amp;amp;8=31&amp;amp;9=0&amp;amp;10=1&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Related phone-back locations:&lt;br /&gt;&lt;b&gt;liveavantbrowser2 .cn&lt;/b&gt; - (83.133.123.140)&lt;br /&gt;&lt;b&gt;securedliveuploads .com&lt;br /&gt;liveavantbrowser2 .cn&lt;br /&gt;awardspacelooksbig .us&lt;br /&gt;crytheriver .biz&lt;br /&gt;softwareupdatessystem .com&lt;br /&gt;securedsoftwareupdate .cn&lt;br /&gt;securedupdateslive .cn&lt;br /&gt;securedosupdates .cn&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SgGWHLSZ-eI/AAAAAAAADmI/7KHVyY08Eew/s1600-h/swine_flu_blackhat_SEO_6.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SgGWHLSZ-eI/AAAAAAAADmI/7KHVyY08Eew/s200/swine_flu_blackhat_SEO_6.JPG" /&gt;&lt;/a&gt;Blackhat SEO subdomains at the free web site hosting services:&lt;br /&gt;&lt;b&gt;2qnews.07x .net&lt;br /&gt;2rnews.07x .net&lt;br /&gt;1news.07x .net&lt;br /&gt;1knews.07x .net&lt;br /&gt;1xnews.07x .net&lt;br /&gt;gerandong.07x .net&lt;br /&gt;kort.07x .net&lt;br /&gt;30newsx.07x .net&lt;br /&gt;4dnews.07x .net&lt;br /&gt;4dnews.07x .net&lt;br /&gt;laptop.07x .net&lt;br /&gt;30newsf.07x .net&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Blackhat SEO domains participating in the second multi-theme campaign:&lt;br /&gt;&lt;b&gt;01may2009 .us&lt;br /&gt;m1m18test .us&lt;br /&gt;m1m17test .us&lt;br /&gt;m1m21test .us&lt;br /&gt;m1m11test .us&lt;br /&gt;m1m16test .us&lt;br /&gt;m1m20test .us&lt;br /&gt;m1m15test .us&lt;br /&gt;m1m14test .us&lt;br /&gt;m1m13test .us&lt;br /&gt;m1m11test .us&lt;br /&gt;m1m15test .us&lt;br /&gt;m1m19test .us&lt;br /&gt;f9o852test .us&lt;br /&gt;f9o851test .us&lt;br /&gt;f9o87test .us&lt;br /&gt;f9o86test .us&lt;br /&gt;f9o5test .us&lt;br /&gt;f9o8test .us&lt;br /&gt;ff7test5 .us&lt;br /&gt;g2g1test .us&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SgGWioGarVI/AAAAAAAADmQ/Y6UXYFcRHSE/s1600-h/swine_flu_blackhat_SEO_5.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SgGWioGarVI/AAAAAAAADmQ/Y6UXYFcRHSE/s200/swine_flu_blackhat_SEO_5.JPG" /&gt;&lt;/a&gt;Blackhat SEO domains participating in the third campaign:&lt;b&gt;&lt;br /&gt;greg-page-boxing.6may2009 .com - &lt;/b&gt;212.95.58.156&lt;b&gt;&lt;br /&gt;dualsaw.06may2009 .com&lt;br /&gt;craigslist-killer.5may2009 .com&lt;br /&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;Upon clicking, the user is redirected to &lt;b&gt;berusimcom .com/t.php?s=18&amp;amp;pk=&lt;/b&gt;, then to the SEO keyword logger at &lt;b&gt;berusimcom .com/in.cgi?18&amp;amp;seoref=&amp;amp;parameter=$keyword&amp;amp;se=$se&amp;amp;ur=1&amp;amp;HTTP_REFERER=nfl-draft.5may2009 .com&amp;amp;ppckey=&lt;/b&gt;, and then exposed to another portfolio of rogue security software (&lt;a href="http://www.virustotal.com/analisis/565faeb69959c4dfa16faa449ebd8a05"&gt;detection rate&lt;/a&gt;) at &lt;b&gt;hot-porn-tubes.com/promo3/?aid=1361&amp;amp;vname=antivirus&lt;/b&gt; - 78.129.166.166; 91.212.132.12, with the following domains parked at the same IPs:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;xxxtube-for-xxxtube .com&lt;br /&gt;youporn-for-free .com&lt;br /&gt;xtube-xmovie .com&lt;br /&gt;free-xxx-central .com&lt;br /&gt;xtube-downloads .com&lt;br /&gt;porn-tube-movies .com&lt;br /&gt;my-fuck-movies .com&lt;br /&gt;niche-tube-videos-here .net &lt;br /&gt;free-tube-video-central .net&lt;br /&gt;tubezzz-boobezzz .net&lt;br /&gt;hot-tube-tuberzzz .net&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Persistence must be met with persistence.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-440847893545997882?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/440847893545997882'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/440847893545997882'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/05/dissecting-swine-flu-black-seo-campaign.html' title='Dissecting a Swine Flu Black SEO Campaign'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_wICHhTiQmrA/SgGIdERVfpI/AAAAAAAADlo/TGddvIaK9yM/s72-c/swine_flu_blackhat_SEO_4.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-906006416833131951</id><published>2009-05-01T10:05:00.038+02:00</published><updated>2009-05-01T10:05:00.383+02:00</updated><title type='text'>Summarizing Zero Day's Posts for April</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SfoFFuFNe-I/AAAAAAAADlA/tx5loef-tcE/s1600-h/zdnet_zeroday_april_2009.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SfoFFuFNe-I/AAAAAAAADlA/tx5loef-tcE/s200/zdnet_zeroday_april_2009.jpg" /&gt;&lt;/a&gt;The following is a brief summary of all of my posts at ZDNet's &lt;a href="http://blogs.zdnet.com/security"&gt;Zero Day&lt;/a&gt; for April. You can also go through previous summaries for &lt;a href="http://ddanchev.blogspot.com/2009/03/summarizing-zero-days-posts-for-march.html"&gt;March&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/03/summarizing-zero-days-posts-for.html"&gt;February&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/02/summarizing-zero-days-posts-for-january.html"&gt;January&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2009/01/summarizing-zero-days-posts-for.html"&gt;December&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/12/summarizing-zero-days-posts-for.html"&gt;November&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/11/summarizing-zero-days-posts-for-october.html"&gt;October&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/10/summarizing-zero-days-posts-for.html"&gt;September&lt;/a&gt;, &lt;a href="http://ddanchev.blogspot.com/2008/09/summarizing-zero-days-posts-for-august.html"&gt;August&lt;/a&gt; and &lt;a href="http://ddanchev.blogspot.com/2008/08/summarizing-zero-days-posts-for-july.html"&gt;July&lt;/a&gt;, as well as subscribe to my &lt;a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;amp;s=0&amp;amp;o=1&amp;amp;mode=rss"&gt;personal RSS feed&lt;/a&gt; or &lt;a href="http://feeds.feedburner.com/zdnet/security"&gt;Zero Day's main feed&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Notable articles include: &lt;a href="http://blogs.zdnet.com/security/?p=3178"&gt;Google's CAPTCHA experiment and the human factor&lt;/a&gt;; &lt;a href="http://blogs.zdnet.com/security/?p=3207"&gt;Conficker's estimated economic cost? $9.1 billion&lt;/a&gt; and &lt;a href="http://blogs.zdnet.com/security/?p=3125"&gt;Twitter hit by multiple variants of XSS worm&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;01.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3093"&gt;Conficker worm's copycat Neeris spreading over IM&lt;/a&gt;&lt;br /&gt;&lt;b&gt;02.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3098"&gt;Paul McCartney's official site serving malware&lt;/a&gt;&lt;br /&gt;&lt;b&gt;03.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3105"&gt;Fake "Conficker Infection Alert" spam campaign circulating&lt;/a&gt;&lt;br /&gt;&lt;b&gt;04.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3125"&gt;Twitter hit by multiple variants of XSS worm&lt;/a&gt;&lt;br /&gt;&lt;b&gt;05.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3140"&gt;Scareware pops-up at FoxNews&lt;/a&gt;&lt;br /&gt;&lt;b&gt;06.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3162"&gt;Waledac botnet spamming fake SMS spying tool&lt;/a&gt;&lt;br /&gt;&lt;b&gt;07.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3170"&gt;Twitter worm author gets a job at exqSoft Solutions&lt;/a&gt;&lt;br /&gt;&lt;b&gt;08.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3178"&gt;Google's CAPTCHA experiment and the human factor&lt;/a&gt;&lt;br /&gt;&lt;b&gt;09.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3185"&gt;Hackers hijack DNS records of high profile New Zealand sites&lt;/a&gt;&lt;br /&gt;&lt;b&gt;10.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3197"&gt;New ransomware locks PCs, demands premium SMS for removal&lt;/a&gt;&lt;br /&gt;&lt;b&gt;11.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3207"&gt;Conficker's estimated economic cost? $9.1 billion&lt;/a&gt;&lt;br /&gt;&lt;b&gt;12.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3233"&gt;Swine flu email scams circulating&lt;/a&gt;&lt;br /&gt;&lt;b&gt;13.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3255"&gt;Online broker CommSec criticised for weak passwords, lack of SSL&lt;/a&gt;&lt;br /&gt;&lt;b&gt;14.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3278"&gt;Survey: 37% of employees would become insiders given the right incentive&lt;/a&gt;&lt;br /&gt;&lt;b&gt;15.&lt;/b&gt; &lt;a href="http://blogs.zdnet.com/security/?p=3292"&gt;French hacker gains access to Twitter's admin panel&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-906006416833131951?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/906006416833131951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/906006416833131951'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/05/summarizing-zero-days-posts-for-april.html' title='Summarizing Zero Day&apos;s Posts for April'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wICHhTiQmrA/SfoFFuFNe-I/AAAAAAAADlA/tx5loef-tcE/s72-c/zdnet_zeroday_april_2009.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-8794093762989596868</id><published>2009-04-30T23:03:00.000+02:00</published><updated>2009-04-30T23:03:48.844+02:00</updated><title type='text'>419 Scam Artists Using NYTimes.com 'Email this' Feature</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SfoJGBi0z9I/AAAAAAAADlI/65A1QjL0Pmc/s1600-h/419_scam_arist_nytimes.bmp" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SfoJGBi0z9I/AAAAAAAADlI/65A1QjL0Pmc/s200/419_scam_arist_nytimes.bmp" /&gt;&lt;/a&gt;In times when more and more &lt;a href="http://ddanchev.blogspot.com/2008/09/spam-campaign-abusing-yahoos-services.html"&gt;scammers/spammers&lt;/a&gt; are getting &lt;a href="http://ddanchev.blogspot.com/2008/09/hijacking-spam-campaigns-click-through.html"&gt;DomainKeys verified&lt;/a&gt;, others are finding adaptive ways to increase the probability of bypassing antispam filters.&lt;br /&gt;&lt;br /&gt;Take for instance this 419s scam artist, that's been pretty active in his scamming attempts as of recently.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SfoM9YRtg6I/AAAAAAAADlQ/FR7GgiyIbFU/s1600-h/scan0001.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SfoM9YRtg6I/AAAAAAAADlQ/FR7GgiyIbFU/s200/scan0001.jpg" /&gt;&lt;/a&gt;Basically, he's exploiting the fact that he's allowed to enter a message within NYTimes.com's 'Email this" feature, whereas it will successfully reach the potential victim based on clean IP reputation of NYTimes - and sadly, he's right since he's already sending scam messages through the following accounts registered at the site:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;douglas_999@live.fr&lt;br /&gt;douglas77@live.fr&lt;br /&gt;mamadou_sanou@live.fr&lt;br /&gt;markkabore0@yahoo.fr&lt;br /&gt;abdelk11@hotmail.fr&lt;br /&gt;sulem_musa@live.fr&lt;br /&gt;davidbchirot@hotmail.com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SfoNLtHbv9I/AAAAAAAADlY/0_sReYkUa80/s1600-h/scan0005.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SfoNLtHbv9I/AAAAAAAADlY/0_sReYkUa80/s200/scan0005.jpg" /&gt;&lt;/a&gt;His excuse for using NYTimes.com? - "&lt;i&gt;Based on the bank high sensitiveness and security i have decided to contact you outside the bank's sever IP for a beneficial transaction.&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;Another scam that I've been tracking for a while is using a new "&lt;b&gt;Hand bag stolen at Barcelona air port&lt;/b&gt;" social engineering attempt, and is attaching scanned copies of real baggage loss documents in order to improve the truthfulness of the scam. Pretty catchy if you don't know what &lt;a href="http://en.wikipedia.org/wiki/Advance_fee_fraud"&gt;advance fee fraud&lt;/a&gt; is.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-8794093762989596868?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/8794093762989596868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/8794093762989596868'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/04/419-scam-artists-using-nytimescom-email.html' title='419 Scam Artists Using NYTimes.com &apos;Email this&apos; Feature'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_wICHhTiQmrA/SfoJGBi0z9I/AAAAAAAADlI/65A1QjL0Pmc/s72-c/419_scam_arist_nytimes.bmp' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-1161970578184043958</id><published>2009-04-29T14:32:00.000+02:00</published><updated>2009-04-29T14:32:29.121+02:00</updated><title type='text'>Massive SQL Injections Through Search Engine's Reconnaissance - Part Two</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Sfg33R1tfZI/AAAAAAAADko/HM3HTRYJlQg/s1600/help1.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Sfg33R1tfZI/AAAAAAAADko/HM3HTRYJlQg/s200/help1.PNG" /&gt;&lt;/a&gt;From the lone Chinese &lt;a href="http://ddanchev.blogspot.com/2007/05/google-hacking-for-vulnerabilities.html"&gt;SQL injectors&lt;/a&gt; empowered with &lt;a href="http://ddanchev.blogspot.com/2008/10/massive-sql-injection-attacks-chinese.html"&gt;point'n'click tools for massive SQL injection attacks&lt;/a&gt;, to the much more efficient and automated botnet approach courtesy of the, for instance, &lt;a href="http://blogs.zdnet.com/security/?p=1122"&gt;ASProx botnet&lt;/a&gt; the process of &lt;a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html"&gt;automatically fetching URLs from public search engines in order to build hit lists&lt;/a&gt; for verifying against remote file inclusion attacks and potential SQL injections, remains a commodity feature in a great number of newly released malware bots.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Sfg6-qL-tKI/AAAAAAAADkw/vQ9A4bK9q1M/s1600-h/schem1.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Sfg6-qL-tKI/AAAAAAAADkw/vQ9A4bK9q1M/s200/schem1.PNG" /&gt;&lt;/a&gt;In 2004, the &lt;a href="http://news.netcraft.com/archives/2004/12/21/santy_worm_spreads_through_phpbb_forums.html"&gt;Santy worm&lt;/a&gt; advertised the feature to the not so efficiently centered hordes of script kiddies back then. Due to its simplicity, but huge potential for abuse, the concept of SQL injections through search engines reconnaissance has not only reached a real-time syndication with the latest remotely exploitable web application vulnerabilities, but has also converged with &lt;a href="http://ddanchev.blogspot.com/2007/04/compilation-of-web-backdoors.html"&gt;remote file inclusion checks&lt;/a&gt;, local file inclusion checks, and ip2geolocation to unethically pen-test a particular country going beyond its designated domain extension.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;A recently released malware bot is once again empowering the average script kiddie with the possibility to take advantage of the window of opportunity for each and every remotely exploitable web application flaw featured at Milworm, based on its real-time syndication of the exploits. Moreover, the IRC based bot is also featuring a console which allows manual exploitation or intelligence gathering for a particular site.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/Sfg9anuabXI/AAAAAAAADk4/66GX2yuYVV0/s1600-h/vulnscanning1.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/Sfg9anuabXI/AAAAAAAADk4/66GX2yuYVV0/s200/vulnscanning1.PNG" /&gt;&lt;/a&gt;Some of the features include:&lt;br /&gt;- Remote file inclusion&lt;br /&gt;- Local file inclusion checks ()&lt;br /&gt;- MySQL database details&lt;br /&gt;- Extract all database names&lt;br /&gt;- Data dumping from column and table&lt;br /&gt;- Notification issued when Google bans the infected host for automatically using it&lt;br /&gt;&lt;br /&gt;The commoditization of these features results in a situation where the window of opportunity for abusing a partcular web application flaw is abused much more efficiently due to the fact that reconnaissance data about its potential exploitability is already crawled by a public search engine - often in real time.&lt;br /&gt;&lt;br /&gt;The concept, as well as the features within the bot are not rocket science - that's what makes it so easy to use.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related posts:&lt;br /&gt;&lt;/b&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/massive-sql-injection-attacks-chinese.html"&gt;Massive SQL Injection Attacks - the Chinese Way&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/05/yet-another-massive-sql-injection.html"&gt;Yet Another Massive SQL Injection Spotted in the Wild&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html"&gt;Obfuscating Fast-fluxed SQL Injected Domains&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/07/smells-like-copycat-sql-injection-in.html"&gt;Smells Like a Copycat SQL Injection In the Wild&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/07/sql-injecting-malicious-doorways-to.html"&gt;SQL Injecting Malicious Doorways to Serve Malware&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html"&gt;SQL Injection Through Search Engines Reconnaissance&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/05/stealing-sensitive-databases-online-sql.html"&gt;Stealing Sensitive Databases Online - the SQL Style&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=1122"&gt;Fast-Fluxing SQL injection attacks executed from the Asprox botnet&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=1394"&gt;Sony PlayStation's site SQL injected, redirecting to rogue security software&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=1118"&gt;Redmond Magazine Successfully SQL Injected by Chinese Hacktivists&lt;/a&gt;&lt;b&gt;&lt;b&gt; &lt;br /&gt;&lt;/b&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-1161970578184043958?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/1161970578184043958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/1161970578184043958'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/04/massive-sql-injections-through-search.html' title='Massive SQL Injections Through Search Engine&apos;s Reconnaissance - Part Two'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_wICHhTiQmrA/Sfg33R1tfZI/AAAAAAAADko/HM3HTRYJlQg/s72-c/help1.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-1966997483812582842</id><published>2009-04-28T22:27:00.001+02:00</published><updated>2009-04-28T22:29:31.140+02:00</updated><title type='text'>Spamvertised Swine Flu Domains</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SfdePHxe5cI/AAAAAAAADkY/v_52xSsK6dA/s1600-h/swine_flu_canadian_pharmacy.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SfdePHxe5cI/AAAAAAAADkY/v_52xSsK6dA/s200/swine_flu_canadian_pharmacy.png" /&gt;&lt;/a&gt;The people behind the ongoing &lt;a href="http://www.avertlabs.com/research/blog/index.php/2009/04/27/swine-flue-spam/"&gt;swine flu spam campaign&lt;/a&gt; have either missed their marketing lectures, haven't been to any at all, or are simply too lazy -- their processing order is not even using SSL -- to fully exploit the marketing window opened by the viral oubreak - the majority of &lt;a href="http://blogs.zdnet.com/security/?p=3233"&gt;spamvertised domains&lt;/a&gt; are redirecting to your typical Canadian Pharmacy scam, instead of &lt;a href="http://www.f-secure.com/weblog/archives/00001668.html"&gt;swine flu related templates&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Swine flu spamvertised domains:&lt;/b&gt;&lt;br /&gt;lijgihab.cn; jihkohab.cn; litgukab.cn; namyalab.cn; waytipab.cn; ritlarab.cn; bersoxab.cn; xaqkabeb.cn; jamnibeb.cn; pahdeheb.cn; qeqyukeb.cn; qiwqoreb.cn; zajbaveb.cn; zacniyeb.cn; baqnubib.cn; zephecib.cn; texlocib.cn; fedpijib.cn;meysujib.cn; qoltujib.cn; mukwujib.cn; buljakib.cn; cutcurib.cn; bejdasib.cn; xikgosib.cn; bacnaxib.cn; kuskuzib.cn; juvyidob.cn; sowgugob.cn; buhbulob.cn; tonjotob.cn; kozgewob.cn; gasfexob.cn; pocdiyob.cn; kujroyob.cn; mirlacub.cn; kixqucub.cn; rovjudub.cn; jokrogub.cn; tusyajub.cn; gixxukub.cn; mospomub.cn; hixmipub.cn; zismerub.cn; cegfasub.cn; dimfevub.cn; qebhuvub.cn; duvlixub.cn; tiqceyub.cn; cogwibac.cn; minkucac.cn; dadwafac.cn; dilpogac.cn; jovsogac.cn; juwcolac.cn; wefmunac.cn; cexfopac.cn; wejpopac.cn; dovniqac.cn; mulsatac.cn; labwewac.cn; lirquwac.cn; latzoyac.cn; tuwbazac.cn; motjudec.cn; jicmefec.cn; qujqugec.cn; fajnahec.cn; wobfojec.cn; saybilec.cn; siyjoqec.cn; gehgixec.cn; gajdezec.cn; sgytubic.cn; cabfecic.cn; nedsicic.cn; xorpilic.cn; bulxopic.cn; kisniric.cn; beszesic.cn; hiwdosic.cn; linrudoc.cn; rijnakoc.cn; mahhekoc.cn; hahwikoc.cn; labniloc.cn; zocwoloc.cn; gommupoc.cn; yubbaqoc.cn; mefbuqoc.cn; xeclaroc.cn; qurburoc.cn; wupqatoc.cn; capjebuc.cn; wofmufuc.cn; boxxiguc.cn; zeffehuc.cn; pegvijuc.cn; bubkenuc.cn; fixfunuc.cn;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SfdecSfs7zI/AAAAAAAADkg/k7OofKkMmko/s1600-h/swine_flu_pharma.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SfdecSfs7zI/AAAAAAAADkg/k7OofKkMmko/s200/swine_flu_pharma.png" /&gt;&lt;/a&gt;&lt;/div&gt;qivbiruc.cn; vahraxuc.cn; camxezuc.cn; tomyubad.cn; sohmifad.cn; sukgogad.cn; kossehad.cn; mopwijad.cn; pagtujad.cn; nohxokad.cn; pugvuqad.cn; bapvusad.cn; wekzetad.cn; lozfoyad.cn; vuppoyad.cn; forvafed.cn; cetcofed.cn; dadrofed.cn; sacvahed.cn; qoqgoled.cn; madwemed.cn; rilgeped.cn; voydewed.cn; liyxozed.cn; regmihid.cn; bujquhid.cn; damtuqid.cn; nifhosid.cn; dapfotid.cn; yofkibod.cn; roghudod.cn; gacpagod.cn; xijhihod.cn; japtikod.cn; meyrilod.cn; patjulod.cn; hixvunod.cn; towqotod.cn; ridnuxod.cn; vevteyod.cn; deqgobud.cn; lilnedud.cn; rusdehud.cn; zidpajud.cn; qibxenud.cn; xixvasud.cn; yapqitud.cn; xuldeyud.cn; nacyeyud.cn; ciknezud.cn; qiwsuzud.cn; leblidaf.cn; timpejaf.cn; vacxamaf.cn; nugnosaf.cn; xawpicef.cn; beqnahef.cn; kumhulef.cn; somnimef.cn; pejyunef.cn; zuwpikif.cn; bixvikif.cn; sajbipif.cn; vikqipif.cn; xotdaxif.cn; qalrezif.cn; xuhkudof.cn; lijsofof.cn; gimvufof.cn; kofgehof.cn; xixgikof.cn; percaqof.cn; nifjarof.cn; xivqirof.cn; rucmusof.cn; yizsatof.cn; qihqutof.cn; devqivof.cn; mijvaxof.cn; kiyvayof.cn; bubduyof.cn; pohfabuf.cn; zudsaduf.cn; tuhfehuf.cn; yaytumuf.cn; fumtinuf.cn; gibkesuf.cn; xaqqivuf.cn; wandawuf.cn; faqloyuf.cn; paqhizuf.cn; nowzacag.cn; xowjicag.cn; nolyodag.cn; tavyafag.cn; lijgihab.cn; jihkohab.cn; litgukab.cn; namyalab.cn;waytipab.cn; ritlarab.cn; bersoxab.cn; xaqkabeb.cn; jamnibeb.cn; pahdeheb.cn; qeqyukeb.cn; qiwqoreb.cn; zajbaveb.cn; zacniyeb.cn; baqnubib.cn; zephecib.cn; texlocib.cn; fedpijib.cn; meysujib.cn; qoltujib.cn; mukwujib.cn; buljakib.cn; cutcurib.cn; bejdasib.cn; xikgosib.cn; bacnaxib.cn; kuskuzib.cn; juvyidob.cn; sowgugob.cn; buhbulob.cn; tonjotob.cn; kozgewob.cn; gasfexob.cn; pocdiyob.cn; kujroyob.cn; mirlacub.cn; kixqucub.cn; rovjudub.cn; jokrogub.cn; tusyajub.cn; gixxukub.cn; mospomub.cn; hixmipub.cn; zismerub.cn; cegfasub.cn; dimfevub.cn; qebhuvub.cn; duvlixub.cn; tiqceyub.cn; cogwibac.cn; minkucac.cn; dadwafac.cn; dilpogac.cn; jovsogac.cn; juwcolac.cn; wefmunac.cn; cexfopac.cn; wejpopac.cn; dovniqac.cn; mulsatac.cn; labwewac.cn; lirquwac.cn; latzoyac.cn; tuwbazac.cn; motjudec.cn; jicmefec.cn; qujqugec.cn; fajnahec.cn; wobfojec.cn; saybilec.cn; siyjoqec.cn; gehgixec.cn; gajdezec.cn; sgytubic.cn; cabfecic.cn; nedsicic.cn; xorpilic.cn; bulxopic.cn; kisniric.cn; beszesic.cn; hiwdosic.cn; linrudoc.cn; rijnakoc.cn; mahhekoc.cn; hahwikoc.cn; labniloc.cn; zocwoloc.cn; gommupoc.cn; yubbaqoc.cn; mefbuqoc.cn; xeclaroc.cn; qurburoc.cn; wupqatoc.cn; capjebuc.cn; wofmufuc.cn; boxxiguc.cn; zeffehuc.cn; pegvijuc.cn; bubkenuc.cn; fixfunuc.cn; qivbiruc.cn; vahraxuc.cn; camxezuc.cn; tomyubad.cn; sohmifad.cn; sukgogad.cn; kossehad.cn; mopwijad.cn; pagtujad.cn; nohxokad.cn; pugvuqad.cn; bapvusad.cn; wekzetad.cn; lozfoyad.cn; vuppoyad.cn; forvafed.cn; cetcofed.cn; dadrofed.cn; sacvahed.cn; qoqgoled.cn; madwemed.cn; rilgeped.cn; voydewed.cn; liyxozed.cn; regmihid.cn; bujquhid.cn; damtuqid.cn; nifhosid.cn; dapfotid.cn; yofkibod.cn; roghudod.cn; gacpagod.cn; xijhihod.cn; japtikod.cn; meyrilod.cn; patjulod.cn; hixvunod.cn; towqotod.cn; ridnuxod.cn; vevteyod.cn; deqgobud.cn; lilnedud.cn; rusdehud.cn; zidpajud.cn; qibxenud.cn; xixvasud.cn; yapqitud.cn; xuldeyud.cn; nacyeyud.cn; ciknezud.cn; qiwsuzud.cn; leblidaf.cn; timpejaf.cn; vacxamaf.cn; nugnosaf.cn; xawpicef.cn; beqnahef.cn; kumhulef.cn; somnimef.cn; pejyunef.cn; zuwpikif.cn; bixvikif.cn; sajbipif.cn; vikqipif.cn; xotdaxif.cn; qalrezif.cn; xuhkudof.cn; lijsofof.cn; gimvufof.cn; kofgehof.cn; xixgikof.cn; percaqof.cn; nifjarof.cn; xivqirof.cn; rucmusof.cn; yizsatof.cn; qihqutof.cn; devqivof.cn; mijvaxof.cn; kiyvayof.cn; bubduyof.cn; pohfabuf.cn; zudsaduf.cn; tuhfehuf.cn; yaytumuf.cn; fumtinuf.cn; gibkesuf.cn; xaqqivuf.cn; wandawuf.cn; faqloyuf.cn; paqhizuf.cn; nowzacag.cn; xowjicag.cn; nolyodag.cn; tavyafag.cn; hujrulag.cn; sodbenag.cn; gafkiqag.cn; lijgihab.cn; jihkohab.cn; litgukab.cn; namyalab.cn; waytipab.cn; ritlarab.cn; bersoxab.cn; xaqkabeb.cn; jamnibeb.cn; pahdeheb.cn; qeqyukeb.cn; qiwqoreb.cn; zajbaveb.cn; zacniyeb.cn; baqnubib.cn; zephecib.cn; texlocib.cn; fedpijib.cn; meysujib.cn; qoltujib.cn; mukwujib.cn; buljakib.cn; cutcurib.cn; bejdasib.cn; xikgosib.cn; bacnaxib.cn; kuskuzib.cn; juvyidob.cn; sowgugob.cn; buhbulob.cn; tonjotob.cn; kozgewob.cn; gasfexob.cn; pocdiyob.cn; kujroyob.cn; mirlacub.cn; kixqucub.cn; rovjudub.cn; jokrogub.cn; tusyajub.cn; gixxukub.cn; mospomub.cn; hixmipub.cn; zismerub.cn; cegfasub.cn; dimfevub.cn; qebhuvub.cn; duvlixub.cn; tiqceyub.cn; cogwibac.cn; minkucac.cn; dadwafac.cn; dilpogac.cn; jovsogac.cn; juwcolac.cn; wefmunac.cn; cexfopac.cn; wejpopac.cn; dovniqac.cn; mulsatac.cn; labwewac.cn; lirquwac.cn; latzoyac.cn; tuwbazac.cn; motjudec.cn; jicmefec.cn; qujqugec.cn; fajnahec.cn; wobfojec.cn; saybilec.cn; siyjoqec.cn; gehgixec.cn; gajdezec.cn; sgytubic.cn; cabfecic.cn; nedsicic.cn; xorpilic.cn; bulxopic.cn; kisniric.cn; beszesic.cn; hiwdosic.cn; linrudoc.cn; rijnakoc.cn; mahhekoc.cn; hahwikoc.cn; labniloc.cn; zocwoloc.cn; gommupoc.cn; yubbaqoc.cn; mefbuqoc.cn; xeclaroc.cn; qurburoc.cn; wupqatoc.cn; capjebuc.cn; wofmufuc.cn; boxxiguc.cn; zeffehuc.cn; pegvijuc.cn; bubkenuc.cn; fixfunuc.cn; qivbiruc.cn; vahraxuc.cn; camxezuc.cn; tomyubad.cn; sohmifad.cn; sukgogad.cn; kossehad.cn; mopwijad.cn; pagtujad.cn; nohxokad.cn; pugvuqad.cn; bapvusad.cn; wekzetad.cn; lozfoyad.cn; vuppoyad.cn; forvafed.cn; cetcofed.cn; dadrofed.cn; sacvahed.cn; qoqgoled.cn; madwemed.cn; rilgeped.cn; voydewed.cn; liyxozed.cn; regmihid.cn; bujquhid.cn; damtuqid.cn; nifhosid.cn; dapfotid.cn; yofkibod.cn; roghudod.cn; gacpagod.cn; xijhihod.cn; japtikod.cn; meyrilod.cn; patjulod.cn; hixvunod.cn; towqotod.cn; ridnuxod.cn; vevteyod.cn; deqgobud.cn; lilnedud.cn; rusdehud.cn; zidpajud.cn; qibxenud.cn; xixvasud.cn; yapqitud.cn; xuldeyud.cn; nacyeyud.cn; ciknezud.cn; qiwsuzud.cn; leblidaf.cn; timpejaf.cn; vacxamaf.cn; nugnosaf.cn; xawpicef.cn; beqnahef.cn; kumhulef.cn; somnimef.cn; pejyunef.cn; zuwpikif.cn; bixvikif.cn; sajbipif.cn; vikqipif.cn; xotdaxif.cn; qalrezif.cn; xuhkudof.cn; lijsofof.cn; gimvufof.cn; kofgehof.cn; xixgikof.cn; percaqof.cn; nifjarof.cn; xivqirof.cn; rucmusof.cn; yizsatof.cn; qihqutof.cn; devqivof.cn; mijvaxof.cn; kiyvayof.cn; bubduyof.cn; pohfabuf.cn; zudsaduf.cn; tuhfehuf.cn; yaytumuf.cn; fumtinuf.cn; gibkesuf.cn; xaqqivuf.cn; wandawuf.cn; faqloyuf.cn; paqhizuf.cn; nowzacag.cn; xowjicag.cn; nolyodag.cn; tavyafag.cn; hujrulag.cn; sodbenag.cn; gafkiqag.cn; remqavag.cn&lt;br /&gt;&lt;br /&gt;Happy blacklisting/cross-checking!&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://blogs.zdnet.com/security/?p=2054"&gt;Inside an Affiliate Spam Program for Pharmaceuticals&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/10/love-is-psychedelic-too.html"&gt;Love is a Psychedelic, Too&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/02/pharmaceutical-spammers-targeting.html"&gt;Pharmaceutical Spammers Targeting LinkedIn&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html"&gt;Fast-Flux Spam and Scams Increasing&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html"&gt;Storm Worm Hosting Pharmaceutical Scams&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/07/over-80-percent-of-storm-worm-spam-sent.html"&gt;Over 80 percent of Storm Worm Spam Sent by Pharmaceutical Spam Kings&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/10/incentives-model-for-pharmaceutical.html"&gt;Incentives Model for Pharmaceutical Scams&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-1966997483812582842?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/1966997483812582842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/1966997483812582842'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/04/spamvertised-swine-flu-domains.html' title='Spamvertised Swine Flu Domains'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wICHhTiQmrA/SfdePHxe5cI/AAAAAAAADkY/v_52xSsK6dA/s72-c/swine_flu_canadian_pharmacy.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-963901623095927861</id><published>2009-04-22T19:57:00.000+02:00</published><updated>2009-04-22T19:57:34.721+02:00</updated><title type='text'>Massive Blackhat SEO Campaign Serving Scareware</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Se8tgVsF1vI/AAAAAAAADjo/cKSpLlWuJKs/s1600-h/blackhat_seo_news_scareware_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Se8tgVsF1vI/AAAAAAAADjo/cKSpLlWuJKs/s200/blackhat_seo_news_scareware_3.JPG" /&gt;&lt;/a&gt;Over the past couple of days, I've been monitoring yet another massive blackhat SEO campaign consisting of the typical hundreds of thousands of already crawled bogus pages serving &lt;a href="http://ddanchev.blogspot.com/2009/04/diverse-portfolio-of-fake-security_16.html"&gt;scareware/fake security software&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Se8t9TSXpwI/AAAAAAAADjw/1d2OggNZqsc/s1600-h/blackhat_seo_news_scareware_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Se8t9TSXpwI/AAAAAAAADjw/1d2OggNZqsc/s200/blackhat_seo_news_scareware_2.JPG" /&gt;&lt;/a&gt;Later on Google detected the campaign and removed all the blackhat SEO farms from its index, which during the time of assessment were close to a hundred domains with hundreds of subdomains, and thousands of pages within.&lt;br /&gt;&lt;br /&gt;And despite that the abuse notifications for some of the central redirection domains proved effective,&amp;nbsp; it took the cybercriminals approximately 24 hours to catch up, and once again start hijacking search queries, in a combination of scareware, and pay per click redirections.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Se8yArOcbEI/AAAAAAAADj4/4lH37vJH46E/s1600-h/blackhat_seo_news_scareware_4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Se8yArOcbEI/AAAAAAAADj4/4lH37vJH46E/s200/blackhat_seo_news_scareware_4.JPG" /&gt;&lt;/a&gt;It's worth pointing out that this very latest campaign is directly related to &lt;a href="http://ddanchev.blogspot.com/2009/04/twitter-worm-mikeyy-keywords-hijacked.html"&gt;last's week's keywords hijacking blackhat SEO campaign&lt;/a&gt;, with both campaigns relying on identical redirection domains, and serving the same malware. Who's behind these search engine poisoning attacks? An Ukranian gang monetizing the hijacked traffic through the usual channels - scareware and reselling of the anticipated traffic.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;The first stage of the campaign was relying on mainstream media titles within its pages such as&lt;b&gt; USA News&lt;/b&gt;; &lt;b&gt;BBC News&lt;/b&gt;; &lt;b&gt;CNN News&lt;/b&gt; as well as &lt;b&gt;Hottest info!&lt;/b&gt;; &lt;b&gt;HOT NEWS&lt;/b&gt;; &lt;b&gt;Official Website&lt;/b&gt; and &lt;b&gt;Official Site&lt;/b&gt;, thereby making it fairly easy to expose their portfolio of domains.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Se83RHR2GwI/AAAAAAAADkA/-aXt_tCa3_k/s1600-h/blackhat_seo_news_scareware_11.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Se83RHR2GwI/AAAAAAAADkA/-aXt_tCa3_k/s200/blackhat_seo_news_scareware_11.JPG" /&gt;&lt;/a&gt;Interestingly, the cybercriminals appear to have detected the activity -- certain traffic management kits can log attempts of wandering around -- and removed the titles, which combined with the typical referrer checking made the campaign a bit more evasive :&lt;br /&gt;&lt;br /&gt;""&lt;i&gt;var ref,i,is_se=0; var se = new Array("&lt;b&gt;google.&lt;/b&gt;","&lt;b&gt;msn.&lt;/b&gt;","&lt;b&gt;yahoo.&lt;/b&gt;","&lt;b&gt;comcast.&lt;/b&gt;","&lt;b&gt;aol.&lt;/b&gt;","&lt;b&gt;dead&lt;/b&gt;"); if(document.referrer)ref=document.referrer; else ref=""; for(i=0;i&amp;lt;5;i++"&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;Once the user visits any of the domains within the portfolio, with a referrer check confirming he used a search engine to do so, two javascripts load, one dynamically redirecting to the portfolio of fake security software, and the other logging the visit using an Ukrainian web site counter service (&lt;b&gt;c.hit.ua/hit?i=6058&amp;amp;g=0&amp;amp;x=2&amp;amp;s=1&amp;amp;c=1&amp;amp;t=420&amp;amp;w=1024&amp;amp;h=768&amp;amp;d=24&amp;amp;0.5505934176708958&amp;amp;r=&amp;amp;u=http%3A//13news.hobby-site.com/counter.js'&lt;/b&gt;)&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/_wICHhTiQmrA/Se879vdx3BI/AAAAAAAADkI/ElKFOx1JVC8/s1600-h/blackhat_seo_news_scareware_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/Se879vdx3BI/AAAAAAAADkI/ElKFOx1JVC8/s200/blackhat_seo_news_scareware_2.png" /&gt;&lt;/a&gt;&lt;br /&gt;The most recent list of of domains on popular DNS services is as follows. Sub-domains within are excluded since there are several hundred currently active per domain:&lt;br /&gt;&lt;b&gt;0kfzzl .us -&lt;/b&gt; 95.168.172.202 -&amp;nbsp; Email: diannefostergcei@yahoo.com&lt;br /&gt;&lt;b&gt;52ubih .us - &lt;/b&gt;95.168.172.198 - Email: joeminoryhjb@yahoo.com &lt;br /&gt;&lt;b&gt;5nw8b3 .us - &lt;/b&gt;95.168.172.193 - Email: carolynfosteruwwi@yahoo.com&lt;br /&gt;&lt;b&gt;60mptk .us - &lt;/b&gt;95.168.172.192 - Email: bernadettehockadayfedt@yahoo.com&lt;br /&gt;&lt;b&gt;6ry4nv .us - &lt;/b&gt;95.168.172.191 - Email: markpackvesa@yahoo.com&lt;br /&gt;&lt;b&gt;77m8uh .us - &lt;/b&gt;95.168.172.190 - Email: miguelbellhyes@yahoo.com&lt;br /&gt;&lt;b&gt;axnwpy .us - &lt;/b&gt;95.168.172.204 - Email: hungsandfordoehx@yahoo.com&lt;br /&gt;&lt;b&gt;bumgli .us - &lt;/b&gt;Email: coobybrown3@gmail.com &lt;br /&gt;&lt;b&gt;cqxuhk .us - &lt;/b&gt;95.168.172.203 - Email: michaelkoontzutae@yahoo.com &lt;br /&gt;&lt;b&gt;dfkghdf .us -&lt;/b&gt; 212.95.58.49 - Email: umora@live.com &lt;br /&gt;&lt;b&gt;dfwdowrly .us - &lt;/b&gt;Email: orest@hotmail.ru&lt;br /&gt;&lt;b&gt;edtbcm .us - &lt;/b&gt;95.168.172.198 - Email: warrenskinnerumpi@yahoo.com &lt;br /&gt;&lt;b&gt;edu4life .us - &lt;/b&gt;Email - joh.n.ebrilo@gmail.com &lt;br /&gt;&lt;br /&gt;&lt;b&gt;fc4oih .us -&amp;nbsp; &lt;/b&gt;95.168.172.187 - Email: florencemclaughlinovpp@yahoo.com &lt;br /&gt;&lt;b&gt;fcbcwo .us - &lt;/b&gt;89.149.216.146 - Email: dorisnaupkou@yahoo.com &lt;br /&gt;&lt;b&gt;fpq58z .us - &lt;/b&gt;95.168.172.205 - Email: thomassoileautysz@yahoo.com &lt;br /&gt;&lt;b&gt;fzjt82 .us -&amp;nbsp; &lt;/b&gt;95.168.172.188 - maryevansarpl@yahoo.com &lt;br /&gt;&lt;b&gt;gfor8g .us - &lt;/b&gt;Email: christopherdockinsptdg@yahoo.com &lt;br /&gt;&lt;b&gt;gotpig .us - &lt;/b&gt;Email:&amp;nbsp;BeatriceJBrown@text2re.com  &lt;br /&gt;&lt;b&gt;hhjsuuy .us - &lt;/b&gt;217.20.117.198 -&lt;b&gt; &lt;/b&gt;Email: jarovv@gmail.com &lt;br /&gt;&lt;b&gt;hk2april .us - &lt;/b&gt;78.159.122.123 - Email: zainez@gmail.com &lt;br /&gt;&lt;b&gt;hk3april .us - &lt;/b&gt;78.159.122.137 - Email: zainez@gmail.com &lt;br /&gt;&lt;b&gt;hno6sh .us - &lt;/b&gt;89.149.238.12 - Email: alfredmeadenzcy@yahoo.com &lt;br /&gt;&lt;b&gt;i2u6nr .us -&amp;nbsp; &lt;/b&gt;95.168.172.202 - Email: jameshendricksxuwg@yahoo.com &lt;br /&gt;&lt;b&gt;ik3trends .us -&amp;nbsp; &lt;/b&gt;88.214.198.14 - Email: akililewis@gmail.com &lt;br /&gt;&lt;b&gt;itn92j .us -&amp;nbsp; &lt;/b&gt;Email: nicholasmanoicdmg@yahoo.com &lt;br /&gt;&lt;b&gt;j4vre4 .us -&amp;nbsp; &lt;/b&gt;bettyfavorsiqzv@yahoo.com &lt;br /&gt;&lt;b&gt;kzq2i2 .us - &lt;/b&gt;89.149.229.157 - Email: robertmitchellrswv@yahoo.com &lt;br /&gt;&lt;br /&gt;&lt;b&gt;l5ykp6 .us - &lt;/b&gt;95.168.172.195 - Email: chrishuntpjzc@yahoo.com &lt;br /&gt;&lt;b&gt;lh85uk .us - &lt;/b&gt;95.168.172.200 - Email: susannelsonggyp@yahoo.com &lt;br /&gt;&lt;b&gt;lp24april .us - &lt;/b&gt;89.149.228.129 - Email: ramerod@gmail.com&lt;br /&gt;&lt;b&gt;m9nvzp .us -&amp;nbsp; &lt;/b&gt;89.149.216.50 - Email: jenniferduncanakcq@yahoo.com &lt;br /&gt;&lt;b&gt;mm00april .us - &lt;/b&gt;212.95.55.115 - Email: brevno3@gmail.com &lt;br /&gt;&lt;b&gt;mm99april .us - &lt;/b&gt;78.159.122.91 - Email: brevno3@gmail.com&lt;br /&gt;&lt;b&gt;n5y3m8 .us - &lt;/b&gt;89.149.243.86 - Email: imogenegreenrqqr@yahoo.com &lt;br /&gt;&lt;b&gt;na8nw2 .us - &lt;/b&gt;89.149.216.146 - Email: jeremyfitchcupl@yahoo.com &lt;br /&gt;&lt;b&gt;oag3h8 .us - &lt;/b&gt;95.168.172.200 - Email: susanspidelesig@yahoo.com &lt;br /&gt;&lt;b&gt;po1april .us - &lt;/b&gt;212.95.55.138 - Email: preadzz@gmail.com &lt;br /&gt;&lt;b&gt;po3april .us - &lt;/b&gt;78.159.122.93 - Email: preadzz@gmail.com &lt;br /&gt;&lt;b&gt;pp6sqo .us - &lt;/b&gt;95.168.172.197 - Email: connierobertsolni@yahoo.com &lt;br /&gt;&lt;b&gt;pr061r .us - &lt;/b&gt;89.149.216.146 - Email: shirleywardauof@yahoo.com &lt;br /&gt;&lt;b&gt;qdhccy .us - &lt;/b&gt;Email: shark@nightmail.ru &lt;br /&gt;&lt;b&gt;qq338p .us &lt;/b&gt;- 89.149.221.36 - Email: debragonzalezyplu@yahoo.com &lt;br /&gt;&lt;br /&gt;&lt;b&gt;repszp .us - &lt;/b&gt;89.149.221.36 - Email: christinamerrillzzhd@yahoo.com&lt;br /&gt;&lt;b&gt;rrgtnm .us - &lt;/b&gt;95.168.172.203 - Email: josephelliskozc@yahoo.com&lt;br /&gt;&lt;b&gt;rt658y .us -&lt;/b&gt; 89.149.207.33 - Email: luannamcgeeiqwb@yahoo.com&lt;br /&gt;&lt;b&gt;rzi6rj .us - &lt;/b&gt;95.168.172.189 - Email: leatriceporterlhbz@yahoo.com&lt;br /&gt;&lt;b&gt;scsrn8 .us - &lt;/b&gt;95.168.172.201 - Email: donnabrownpgpa@yahoo.com&lt;br /&gt;&lt;b&gt;t9xu44 .us - &lt;/b&gt;95.168.172.194 - Email: robertbissettezeub@yahoo.com&lt;br /&gt;&lt;b&gt;trfddp .us - &lt;/b&gt;89.149.243.89 - Email: davidwilliamsqljt@yahoo.com&lt;br /&gt;&lt;b&gt;up3xv7 .us - &lt;/b&gt;Email: dennismontantecoco@yahoo.com&lt;br /&gt;&lt;b&gt;vecy5r .us - &lt;/b&gt;Email: merlynsmithsqxm@yahoo.com&lt;br /&gt;&lt;b&gt;vlj5jn .us - &lt;/b&gt;95.168.172.196 - Email: angelostewartqfoq@yahoo.com&lt;br /&gt;&lt;b&gt;vr31qo .us - &lt;/b&gt;95.168.172.199 - Email: christinearcherzhqz@yahoo.com&lt;br /&gt;&lt;b&gt;wk7iie .us - &lt;/b&gt;95.168.172.204 - Email: jewellnakashimalgny@yahoo.com&lt;br /&gt;&lt;b&gt;x2ar3e .us - &lt;/b&gt;Email: bobbielopezeits@yahoo.com&lt;br /&gt;&lt;b&gt;xe24py .us - &lt;/b&gt;89.149.243.138 - Email: johnbarberprfi@yahoo.com&lt;br /&gt;&lt;b&gt;xecuk8 .us - &lt;/b&gt;95.168.172.194 - Email: lutheralfaronloz@yahoo.com&lt;br /&gt;&lt;b&gt;yl8ais .us - &lt;/b&gt;89.149.216.147 - Email: meredithflackflub@yahoo.com&lt;br /&gt;&lt;b&gt;yqfvp4 .us - &lt;/b&gt;78.159.96.84 - Email: julierussellnnro@yahoo.com&lt;br /&gt;&lt;b&gt;zvlewrms .us - &lt;/b&gt;Email: ygovoruhin@list.ru&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;zxe11d .us -&amp;nbsp; &lt;/b&gt;95.168.172.195 - Email: christopherlewisxghb@yahoo.com&lt;b&gt; &lt;/b&gt;&lt;br /&gt;&lt;b&gt;zy7itf .us -&lt;/b&gt; 89.149.207.244 - Email: cindyruizixqr@yahoo.com&lt;br /&gt;&lt;br /&gt;&lt;b&gt;13news.doesntexist .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;13news.hobby-site .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;17news.endofinternet .net&lt;/b&gt;&lt;br /&gt;&lt;b&gt;18news.homeftp .org&lt;/b&gt;&lt;br /&gt;&lt;b&gt;19news.blogdns .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;19news.dnsdojo .org&lt;/b&gt;&lt;br /&gt;&lt;b&gt;19news.gotdns .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;19news.kicks-ass .org&lt;/b&gt;&lt;br /&gt;&lt;b&gt;19news.servebbs .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;22news.blogdns .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;creditratingguide. hobby-site.com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;disneyearrings .hobby-site.com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;flatbellydiet .hobby-site.com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;hydrangacutflowers .hobby-site.com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;isa-geek .org&lt;/b&gt;&lt;br /&gt;&lt;b&gt;mxzsaw .hobby-site.com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;mysteryterms .hobby-site.com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The rotated scareware/fake security software domains include:&lt;b&gt; scan-antispyware-4pc .com - &lt;/b&gt;parked at 195.88.81.93 the same &lt;a href="http://ddanchev.blogspot.com/2009/04/diverse-portfolio-of-fake-security_16.html"&gt;portfolio of fake security software domains&lt;/a&gt; which I warned that by blocking you would proactively protect your customers from black hat SEO campaigns - like this one for instance&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;pcvistaxpcodec .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;onlinevirus-scannerv2 .com&lt;br /&gt;av-antispyware .com&lt;br /&gt;scan-antispy-4pc .com&lt;br /&gt;fastviruscleaner .com&lt;br /&gt;securityhelpcenter .com&lt;br /&gt;scan-antispy-4pc .com&lt;br /&gt;scanner-work-av .com&lt;br /&gt;scanner-antispy-av-files .com&lt;br /&gt;adwarealert .com&lt;br /&gt;proantispyware .com&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_wICHhTiQmrA/Se9NPxSv7hI/AAAAAAAADkQ/LkoTGojTeoE/s1600-h/blackhat_seo_news_scareware_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/Se9NPxSv7hI/AAAAAAAADkQ/LkoTGojTeoE/s200/blackhat_seo_news_scareware_5.png" /&gt;&lt;/a&gt;Download locations/related fake codec redirections:&lt;br /&gt;&lt;b&gt;winpcdown10 .com&lt;/b&gt; (194.165.4.77)&lt;br /&gt;&lt;b&gt;suckitnow1 .com&lt;br /&gt;winpcdown99 .com&lt;br /&gt;loyaldown99 .com&lt;br /&gt;codecxpvista .com&lt;br /&gt;wincodecupdate .com&lt;br /&gt;velzevuladmin .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;tubeloyaln .com&lt;br /&gt;wedare.tubeloyaln .com&lt;br /&gt;lamer.tubeloyaln .com&lt;br /&gt;billingpayment.netcodecs.tubeloyaln .com&lt;br /&gt;videosz.tubeloyaln .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;loyal-porno .com&lt;/b&gt; - the same domain was recently exposed in &lt;a href="http://www.f-secure.com/weblog/archives/00001656.html"&gt;the same blackhat&amp;nbsp; SEO campaign&lt;/a&gt;&lt;br /&gt;&lt;b&gt;win-pc-defender .com&lt;/b&gt; &lt;br /&gt;&lt;b&gt;codecvistaz .com&lt;/b&gt;&lt;br /&gt;&lt;b&gt;loyalvideoz .com&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;Sample detection rates:&lt;br /&gt;&lt;b&gt;litetubevideoz .net/codec/277.exe&lt;/b&gt; - &lt;a href="http://www.virustotal.com/analisis/57b478ca7ad6e6c74d8b39d599d3e5ba"&gt;detection rate&lt;/a&gt;&lt;br /&gt;&lt;b&gt;winpcdown99 .com/pcdef.exe - &lt;/b&gt;&lt;a href="http://www.virustotal.com/analisis/e3c36c1b59a35b3fb32728ee7e0a4232"&gt;detection rate&lt;/a&gt;&lt;br /&gt;&lt;b&gt;winpcdown99 .com/file.exe&lt;/b&gt; - &lt;a href="http://www.virustotal.com/analisis/59ffb26d6d696a4282eca4cb717d6c50"&gt;detection rate&lt;/a&gt;&lt;br /&gt;&lt;b&gt;setup.adwarealert .com/setupxv.exe&lt;/b&gt; - &lt;a href="http://www.virustotal.com/analisis/0579761c88ede033558782c65db3ee72"&gt;detection rate&lt;/a&gt;&lt;br /&gt;&lt;b&gt;files.scanner-antispy-av-files .com/exe/setup_200093_1_1.exe&lt;/b&gt; - &lt;a href="http://www.virustotal.com/analisis/0093105181f2d7030998c0d36f02ed51"&gt;detection rate&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;Monitoring of the campaign would continue.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related posts:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/01/dissecting-bogus-linkedin-profiles.html"&gt;Dissecting the Bogus LinkedIn Profiles Malware Campaign &lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/04/bogus-linkedin-profiles-redirect-to.html"&gt;Bogus LinkedIn Profiles Redirect to Malware and Rogue Security Software &lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/06/blackhat-seo-redirects-to-malware-and.html"&gt;Blackhat SEO Redirects to Malware and Rogue Software&lt;/a&gt;&lt;br /&gt;&lt;b&gt; &lt;/b&gt;&lt;a href="http://ddanchev.blogspot.com/2008/01/invisible-blackhat-seo-campaign.html"&gt;The Invisible Blackhat SEO Campaign&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/01/attack-of-seo-bots-on-edu-domain.html"&gt;Attack of the SEO Bots on the .EDU Domain&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/p0rngov-ongoing-blackhat-seo-operation.html"&gt;p0rn.gov - The Ongoing Blackhat SEO Operation&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/02/continuing-gov-blackat-seo-campaign.html"&gt;The Continuing .Gov Blackat SEO Campaign&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/02/continuing-gov-blackat-seo-campaign_25.html"&gt;The Continuing .Gov Blackhat SEO Campaign - Part Two&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/03/rogue-rbn-software-pushed-through.html"&gt;Rogue RBN Software Pushed Through Blackhat SEO&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/02/massive-blackhat-seo-targeting-blogspot.html"&gt;Massive Blackhat SEO Targeting Blogspot &lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/05/blackhat-seo-campaign-at-millennium.html"&gt;Blackhat SEO Campaign at The Millennium Challenge Corporation&lt;/a&gt;&lt;b&gt; &lt;br /&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-963901623095927861?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/963901623095927861'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/963901623095927861'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/04/massive-blackhat-seo-campaign-serving.html' title='Massive Blackhat SEO Campaign Serving Scareware'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_wICHhTiQmrA/Se8tgVsF1vI/AAAAAAAADjo/cKSpLlWuJKs/s72-c/blackhat_seo_news_scareware_3.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-18493443.post-5372569013626553656</id><published>2009-04-16T19:20:00.000+02:00</published><updated>2009-04-16T19:20:10.153+02:00</updated><title type='text'>A CCDCOE Report on the Cyber Attacks Against Georgia</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/_wICHhTiQmrA/Sedia6oJDiI/AAAAAAAADjY/FC1wz5EdZ48/s1600-h/ccdcoe_russia_georgia_report.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/Sedia6oJDiI/AAAAAAAADjY/FC1wz5EdZ48/s200/ccdcoe_russia_georgia_report.JPG" /&gt;&lt;/a&gt;Following the coverage of my "&lt;a href="http://blogs.zdnet.com/security/?p=1670"&gt;Coordinated Russia vs Georgia cyber attack in progress&lt;/a&gt;" research in the &lt;a href="http://ddanchev.blogspot.com/2008/10/ddos-attack-graphs-from-russia-vs.html"&gt;Georgian government's&lt;/a&gt; official report "&lt;a href="http://georgiaupdate.gov.ge/doc/10006744/CYBERWAR-%20fd_2_new.pdf"&gt;Russian Cyberwar on Georgia&lt;/a&gt;" (on page 4), I was very excited to find out that a report by &lt;a href="http://transnet.act.nato.int/WISE/TNCC/CentresofE/CCD"&gt;NATO's Cooperative Cyber Defense Centre of Excellence&lt;/a&gt; entitled "&lt;a href="http://www.carlisle.army.mil/DIME/documents/Georgia%201%200.pdf"&gt;Cyber Attacks Against Georgia: Legal Lessons Identified&lt;/a&gt;" and authored by Eneken Tikk, Kadri Kaska, Kristel Rünnimeri, Mari Kert, Anna-Maria Talihärm, Liis Vihul, is not only &lt;a href="http://www.army.mil/-news/2009/04/07/19351-georgias-cyber-left-hook/"&gt;quoting me&lt;/a&gt; extensively, but&amp;nbsp; has also reproduced the entire research within the Annexes.&lt;br /&gt;&lt;br /&gt;Looks great!&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Recommended reading:&lt;/b&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/10/ddos-attack-graphs-from-russia-vs.html"&gt;DDoS Attack Graphs from Russia vs Georgia's Cyberattacks&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/08/russia-vs-georgia-cyber-attack.html"&gt;The Russia vs Georgia Cyber Attack&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2009/01/pro-israeli-pseudo-cyber-warriors-want.html"&gt;Pro-Israeli (Pseudo) Cyber Warriors Want your Bandwidth&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html"&gt;People's Information Warfare Concept&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/12/combating-unrestricted-warfare.html"&gt;Combating Unrestricted Warfare&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/04/cyber-storm-ii-cyber-exercise.html"&gt;The Cyber Storm II Cyber Exercise&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html"&gt;Chinese Hacktivists Waging People's Information Warfare Against CNN&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html"&gt;The DDoS Attacks Against CNN.com&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2007/09/chinas-cyber-espionage-ambitions.html"&gt;China's Cyber Espionage Ambitions&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2006/07/north-koreas-cyber-warfare-unit-121.html"&gt;North Korea's Cyber Warfare Unit 121&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ddanchev.blogspot.com/2006/09/chinese-hackers-attacking-us.html"&gt;Chinese Hackers Attacking U.S Department of Defense Networks&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html"&gt;Electronic Jihad v3.0 - What Cyber Jihad Isn't&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/electronic-jihads-targets-list.html"&gt;Electronic Jihad's Targets List&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/08/cyber-jihadist-dos-tool.html"&gt;A Cyber Jihadist DoS Tool &lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/11/teaching-cyber-jihadists-how-to-hack.html"&gt;Teaching Cyber Jihadists How to Hack&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html"&gt;Empowering the Script Kiddies&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html"&gt;OSINT Through Botnets&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html"&gt;Corporate Espionage Through Botnets&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html"&gt;Malware Infected Hosts as Stepping Stones&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html"&gt;Hacktivism Tensions - Israel vs Palestine Cyberwars&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2006/05/current-emerging-and-future-state-of.html"&gt;The Current, Emerging, and Future State of Hacktivism&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html"&gt;Internet PSYOPS - Psychological Operations&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18493443-5372569013626553656?l=ddanchev.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/5372569013626553656'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18493443/posts/default/5372569013626553656'/><link rel='alternate' type='text/html' href='http://ddanchev.blogspot.com/2009/04/ccdcoe-report-on-cyber-attacks-against.html' title='A CCDCOE Report on the Cyber Attacks Against Georgia'/><author><name>Dancho Danchev</name><uri>http://www.blogger.com/profile/09989733095447891258</uri><email>dancho.danchev@gmail.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07286589691027614216'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_wICHhTiQmrA/Sedia6oJDiI/AAAAAAAADjY/FC1wz5EdZ48/s72-c/ccdcoe_russia_georgia_report.JPG' height='72' width='72'/></entry></feed>