tag:blogger.com,1999:blog-8047144376730090032009-07-04T09:58:31.335+01:00Dynamoo's BlogSpam, security, scams, spin and stuff.Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.comBlogger329125tag:blogger.com,1999:blog-804714437673009003.post-86278958055714906772009-07-04T08:25:00.002+01:002009-07-04T09:53:42.459+01:00Piradius.net / Yohost.org - black hat hosting?<span style="font-weight: bold;">Piradius.net</span> is a web host in Malaysia that has cropped up a few times as hosts for <a href="http://www.dynamoo.com/blog/2009/06/flyappraisalscom-scam.html">this long-running scam</a>.<br /><br />It seems that this isn't an isolated case. Looking <span style="font-style: italic;">just one </span>server at gives us a number of other fraudulent domains:<br /><br /><ul><li><span style="font-weight: bold;">bestcrisisprices.com</span> - fake ecommerce site registered to Michell.Gregory2009@yahoo.com that has been used for <a href="http://www.dynamoo.com/blog/2009/05/mig-designcom-fraudulent-job-offer.html">this fraud</a>, <a href="http://www.dynamoo.com/blog/2009/04/luxgroupnzcom-luxgroup-scam.html">this fraud</a> and <a href="http://www.google.com/search?hl=en&amp;q=Michell.Gregory2009%40yahoo.com&amp;btnG=Search&amp;meta=">many others</a>.<br /></li><li><span style="font-weight: bold;">blizzard-battle.net</span> - fake "World of Warcraft" login page, presumably designed to harvest usernames and passwords.<br /></li><li><span style="font-weight: bold;">europemedicalnet.com</span> - claims to be a German medical company, in reality it isn't. Purpose unclear, probably run by <a href="http://www.dynamoo.com/blog/2009/03/pedmacom-domain-appraisals.html">Manuel Fichter</a>.<br /></li><li><span style="font-weight: bold;">everyhit.info</span> - front-end for the registry-cleaner-comparisons.com <a href="http://www.mywot.com/en/scorecard/registry-cleaner-comparisons.com">fraudware</a> site.</li><li><span style="font-weight: bold;">evilcheats.org</span> - registered to kingstonsmith@hushmail.com who is c<a href="http://www.google.com/search?sourceid=mozclient&amp;ie=utf-8&amp;oe=utf-8&amp;q=kingstonsmith%40hushmail.com">onnected</a> with many fraudulent and/or suspect sites.</li><li><span style="font-weight: bold;">excelcapitals.com</span> - smart looking but suspect "get rich quick" site, apparently based in Panama.<br /></li><li><span style="font-weight: bold;">flyappraisals.com</span> - <a href="http://www.dynamoo.com/blog/2009/06/flyappraisalscom-scam.html">fake domain appraisals</a>.</li><li><span style="font-weight: bold;">flyrating.com</span> - <a href="http://www.dynamoo.com/blog/2009/06/flyratingscom-scam.html">fake domain appraisals</a>.</li><li><span style="font-weight: bold;">germanymedicalnet.com</span> - currently displaying text from the <a href="http://www.dynamoo.com/blog/2009/03/pozdecom-domain-valuation-scam.html">Pozde.com</a> domain scam.</li><li><span style="font-weight: bold;">gooogled.com</span> - appears to sell knock-off designer goods.</li><li><span style="font-weight: bold;">hellas-warez.com</span> - "Warez" as in illegal software downloads.</li><li><span style="font-weight: bold;">hygetropin-hgh.com</span> - Claims to export prescription drugs from China.</li><li><span style="font-weight: bold;">indigo-net.org </span>- another "Kingston Smith" domain.</li><li><span style="font-weight: bold;">jessicassoftware.com</span> - suspiciously cheap software.</li><li><span style="font-weight: bold;">maximizedlivingscam.com</span> - another "Kingston Smith" domain.</li><li><span style="font-weight: bold;">nameorange.com</span> - <a href="http://www.dynamoo.com/blog/2009/05/nameorange-nameorangecom-scam.html">fake domain appraisals</a>.</li><li><span style="font-weight: bold;">nextdayrelief.com </span>- unconvincing "pharmacy" that claims to be in the US, but hosts in Malaysia<br /></li><li><span style="font-weight: bold;">pedma.com</span> - <a href="http://www.dynamoo.com/blog/2009/03/pedmacom-domain-appraisals.html">fake domain appraisals</a>.</li><li><span style="font-weight: bold;">podzz.com</span> - <a href="http://www.dynamoo.com/blog/2009/05/podzzcom-domain-scam.html">fake domain appraisals</a>.<br /></li><li><span style="font-weight: bold;">poker-bonus-codes.de</span> - Kingston Smith again.</li><li><span style="font-weight: bold;">pozde.com</span> - <a href="http://www.dynamoo.com/blog/2009/03/pozdecom-domain-valuation-scam.html">fake domain appraisals</a>.</li><li><span style="font-weight: bold;">r4ishop.com</span> - with prices in pounds sterling, it appears to be passing itself off as a UK-based electronics retailer. In reality, everything is anonymised and it could be based anywhere.</li><li><span style="font-weight: bold;">rc-chem.net</span> - claims to be a Canadian supplier of steroids, a <a href="http://www.google.com/search?hl=en&amp;q=%22rc-chem.net%22&amp;btnG=Search&amp;meta=">Google search</a> on the domain is enlightening.</li><li><span style="font-weight: bold;">replica-prestigious-watches.com</span> - fake designer watches.</li><li><span style="font-weight: bold;">tropicalnames.com</span> - <a href="http://www.dynamoo.com/blog/2009/04/tropicalnamescom-scam.html">fake domain appraisals</a>.</li><li><span style="font-weight: bold;">yohost.org</span> - anonymous hosting.</li></ul>In fact, it's the last domain "yohost.org" which gives a clue as to what is really going on. <span style="font-weight: bold;">Yohost.org</span> looks like a reseller of Piradius.net's hosting and it advertises itself as "100% anonymous hosting and anonymous DNS and domain name services" which is "beyond the reach of virtually any government or law enforcement agency."<br /><br />If you Google for "anonymous hosting" then Yohost.org comes up as #4. So you can see where their customers are coming from.<br /><br />Yohost.org also rents other servers from Piradius.net, and they show a mix of sites that appear to be very dodgy indeed, through to sites that appear legitimate.<br /><br />They appear to run the following IPs and probably others too:<br /><br />124.217.231.173<br />124.217.231.209<br />124.217.250.102<br />124.217.250.106<br /><br />Hosting rubbish like this does not enhanced Piradius.net's reputation, they would really be better off booting Yohost.org in order to clean up their IP range.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-8627895805571490677?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-61520970930634414252009-07-02T08:56:00.003+01:002009-07-02T09:03:44.859+01:00Domain scam: ntwifinetwork.com / js-wifi.cnThe old Chinese domain scam has been around for years, but these guys are getting lazy because they haven't changed their domains for months, this is esentially <a href="http://www.dynamoo.com/blog/2009/04/yadu-investment-co-ltd-ntwifinetworkcom.html">unchanged from April</a>.<br /><br /><blockquote style="font-style: italic;">Subject: Domain Dispute and Registration<br />From: "Sunny" <sunny@ntwifinetwork.com><br />Date: Thu, July 2, 2009 4:07 am<br /><br /> To whom it may concern: 2009-7-2<br /><br />We are a domain name registration service company in Asia,<br /><br />Last week we received a formal application submited by Justin Lin who wanted to use the keyword "REDACTED" to register the Internet Brand and with suffix such as .cn /.com.cn /.net.cn/.hk/ .asia/ domain names.<br /><br />After our initial examination, we found that these domain names to be applied for registration are same as your domain name and trademark. We aren¡¯t sure whether you have any relation with him. Because these domain names would produce possible dispute, now we have hold down his registration, but if we do not get your company¡¯s an reply in the next 5 working days, we will approve his company's application<br /><br />In order to handle this issue better, Please contact us by Fax ,Telephone or Email as soon as possible.<br /><br /><br /><br />Yours sincerely<br /><br />Sunny<br /><br />Checking Department<br /><br />Tel: 86 513 8532 1087<br />Fax: 86 513 8532 2065<br />Email:Sunny@ntwifinetwork.com<br />Website: www.js-wifi.cn<br /><br />Our File No.:2272363</sunny@ntwifinetwork.com></blockquote><br />Originating IP is 122.193.216.10.<br /><br />As ever, legitimate domain registrars do not send out this type of email because they are NOT responsible for this activity. Sometimes the Chinese domains get registered, sometimes they are ALREADY registered, and often they never get registered. But before you panic and pay money to these scammers, consider this: there are hundreds of top-level domains in the world. Do you really want to buy your domain for all of them? The answer is probably "no".<br /><br />The best advice is to ignore this email completely.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-6152097093063441425?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-1949260859144404082009-06-30T14:53:00.004+01:002009-06-30T14:57:49.073+01:00%SI_subj: miserable spam failurePossibly one of the most miserable spam failures I have ever seen - the idiot spammer somehow forgot to populate the % fields with actual data. It just goes to reinforce that spammers are stupid.<br /><br /><blockquote style="font-style: italic;">Subject: %SI_subj<br />From: "Lily Lovett"<br />Date: Tue, June 30, 2009 2:47 pm<br /><br />You don’t need to %SI3_rnd10<br />rod’s %SI3_rnd11 and %SI3_rnd12 %SI3_rnd13’ jokes!<br /><br />This is a %SI3_rnd14 for<br />%SI3_rnd15 your<br />%SI3_rnd16! It will<br />%SI3_rnd17 in seconds after she %SI3_rnd18 and %SI3_rnd19 as good as if it was<br />a %SI3_rnd20 rod!<br /><br /> No more jokes – you will always get %SI3_rnd21 and moans! The huge pack<br />costs less than 30 %SI3_rnd22!<br /><br />%SI3_rnd23 can be a %SI3_rnd24! No one will know about your %SI3_rnd25!<br /><br />%SI3_rnd26 now and save more than $10 regardless of<br />your order’s size!</blockquote><br />The hypertext link goes to <span style="font-weight: bold;">%SI_link3</span> rather than a valid address.<br /><br />Presumably this is a penile enhancement product. By the looks of it, the spammer you do with an intelligence enhancement product.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-194926085914440408?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-47844634587931892322009-06-30T11:14:00.002+01:002009-06-30T11:26:56.314+01:00Password masking facepalmA bizarre shot in the security vs usability argument, as reported by El Reg: <a href="http://www.theregister.co.uk/2009/06/30/masked_passwords_usability/">Masked passwords must go</a> which reports on research saying that masked passwords are more trouble than they are worth.<br /><br />A key bit of the argument? "Shoulder surfing is largely a phantom problem".. umm yeah, because people's passwords usually just show as blobs or stars so there's no point. If your damned password comes up as plaintext then you can betcha that it WILL be a problem.<br /><br /><a href="http://images.google.co.uk/images?hl=en&amp;q=facepalm&amp;um=1&amp;ie=UTF-8&amp;sa=N&amp;tab=wi">Facepalm</a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-4784463458793189232?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-75750266256721262682009-06-27T22:10:00.003+01:002009-06-27T22:39:41.311+01:00flyrating.com scam<span style="font-weight: bold;">Flyrating.com</span> is a re-run of the <a href="http://www.dynamoo.com/blog/2009/06/flyappraisalscom-scam.html">flyappraisals.com scam</a> - a fake domain name evaluation service that is spamvertised through a bogus offer to buy a domain.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/flyrating-714320.png"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 320px;" src="http://www.dynamoo.com/blog/uploaded_images/flyrating-714317.png" alt="" border="0" /></a><br />Although the servers are hosted in Malaysia, there is strong evidence linking these to a person of German origin living in Canada. More information <a href="http://www.dynamoo.com/blog/2009/06/flyappraisalscom-scam.html">here</a>.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-7575026625672126268?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-3377965042176636362009-06-20T22:50:00.003+01:002009-06-20T23:37:12.152+01:00Mystery mibug-credit.com / wiremouse.com spamThis is one of those "wft" spams.<br /><br /><blockquote style="font-style: italic;">Subject: Refund of Duplicate Payment<br />From: "Customer Care Center" <2712@mibug-credit.com><br />Date: Sat, June 20, 2009 8:12 pm<br /><br />Dear Business Partner!<br /><br />Enclosed is our e-check in the amount of EURO 1,750.00 which represents a refund for your inadvertent duplicate<br />remittance for payment of transaction no. 267.<br /><br />We are pleased that our bookkeeping department discovered this overpayment so quickly.<br /><br />Thank you.<br /><br />Instant Number Accounts<br />Credit Cards Bulk and Wholesale<br />http://mibug-credit.com</blockquote><br />Yes, you'd think that there's a malware payload or something, but there isn't. Let's check out the domain registrations details - hosted at 213.208.134.154 in Austria:<br /><br />owner-contact: P-GFB634<br />owner-organization: MIBUG CREDIT UG<br />owner-fname: Georg<br />owner-lname: BENDL<br />owner-street: Menzingerstrasse 130<br />owner-city: MUENCHEN<br />owner-zip: D80997<br />owner-country: DE<br />owner-phone: +49.180523363313143<br />owner-email: wmt18703@kunde.webmachine.eu<br /><br />This is meant to be some sort of financial services site, but it was only registered on 8th June 2009.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/mibug-798805.png"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 189px;" src="http://www.dynamoo.com/blog/uploaded_images/mibug-798799.png" alt="" border="0" /></a><br />The site does very little, you can try to open an account (which requires you handing over a bunch of personal information), but there's no way of getting this "refund". There are a few links to <span style="font-weight: bold;">wiremouse.com </span><span>on the site, something that's hosted on the same server.. so let's have a look at what else is on 213.208.134.154:<br /><br /><ul><li>Afrohair.at</li><li>Altkatholiken.net</li><li>Bankparadies.com</li><li>Bmc-london.co.uk</li><li>Bmc-shop.co.uk</li><li>Cocodonia.com</li><li>Firmenparadies.com</li><li>Jr-austria.com</li><li>Mibug-credit.com</li><li>Quotum.at</li><li>Schmeissfliegen.com</li><li>Server1.biz</li><li>Sofortbetrieb.com</li><li>Tiefpreiszentrum.com</li><li>Turi-landhaus.com</li><li>Wiremouse.com</li></ul>The server identifies itself as Server1.biz, also registered to Georg Bendl, but this time in Aust<br /><br />Registrant ID: C6565959-B-CO<br />Registrant Name: Georg BENDL<br />Registrant Address1: Bacherstrasse 7<br />Registrant City: GRIES<br />Registrant Postal Code: A5662<br />Registrant Country: Austria<br />Registrant Country Code: AT<br />Registrant Phone Number: +43.66492436352<br />Registrant Email: WMT5549@kunde.wmtech.net<br /><br />Hmmm.. OK, well what about wiremouse.com?<br /><br />owner-contact: P-NVM192<br />owner-organization: Managed Offshore Payment Services Limited<br />owner-fname: Nikolas owner-lname: MAKIN<br />owner-street: Cariocca Business Park 2 Sawley Road<br />owner-city: MANCHESTER<br />owner-zip: GM40 8BB<br />owner-country: GB<br />owner-phone: +44.7031887152<br />owner-email: wmt8464@kunde.webmachine.eu<br /><br />So, it's based in the UK? Well, the postcode is incorrect.. but in fact, Companies House <span style="font-style: italic;">does</span><span> have a firm of the name Managed Offshore Payment Services Limited <a href="http://wck2.companieshouse.gov.uk/3d80d9de6141b6d632064ad50c5a0920/compdetails">registered</a>. But its accounts are overdue and there is a proposal to "strike off" the firm:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/managed-offshore-744547.png"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 279px;" src="http://www.dynamoo.com/blog/uploaded_images/managed-offshore-744545.png" alt="" border="0" /></a>Let's look at bmc-london.co.uk on the same server:<br /><br />Domain name:<br /> bmc-london.co.uk<br /><br /> Registrant:<br /> Bendl Georg<br /><br /> Registrant type:<br /> Unknown<br /><br /> Registrant's address:<br /> 38 Homer Street<br /> LONDON<br /> GW1H 4NH<br /> GB<br /><br /> Registrar:<br /> Key-Systems GmbH [Tag = KEY-SYSTEMS-DE]<br /> URL: http://www.Key-Systems.net<br /><br /> Relevant dates:<br /> Registered on: 04-Sep-2008<br /> Renewal date: 04-Sep-2010<br /><br /> Registration status:<br /> Registered until renewal date.<br /><br /> Name servers:<br /> ns1.webmachine.at<br /> ns2.webmachine.at<br /><br />This Georg Bendl chap moves around a lot. The address is valid although it's hard to verify if there's a real company operating from that address.<br /><br />In fact, most domains seem to be registered to "Georg Bendl", but the address is different in almost every case (although Salzburg features more than once).<br /><br />It's hard to fathom what this spam is about, although these sites do consistently link back to wiremouse.com. Some sort of SEO? A Joe Job? A phish? Email marketing gone horribly wrong? I don't know.<br /><br />The final clue is the the sending IP address is 62.47.184.176 which is an ADSL subscriber in Austria. Draw your own conclusions, but I would be tempted to give all of these domains a wide berth.</span></span><span style="font-weight: bold;"><span style="font-style: italic;"><br /></span></span><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-337796504217663636?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-12611194349997877042009-06-19T09:50:00.002+01:002009-06-19T10:03:48.747+01:00FAIL: "Microsoft has released an update for Microsoft Outlook"This email looks like it's from Microsoft, but it is really intended to load a trojan onto your PC:<br /><br /><blockquote style="font-style: italic;">From: Microsoft Customer Support [mailto:no-reply@microsoft.com]<br />Sent: 18 June 2009 22:47<br />Subject: Microsoft has released an update for Microsoft Outlook<br /><br />Critical Update<br /><br />Update for Microsoft Outlook / Outlook Express (KB910721)<br />Brief Description<br />Microsoft has released an update for Microsoft Outlook / Outlook Express. This update is critical and provides you with the latest version of the Microsoft Outlook / Outlook Express and offers the highest levels of stability and security.<br />Instructions<br />• To install Update for Microsoft Outlook / Outlook Express (KB910721) please visit Microsoft Update Center:<br />http://update.microsoft.com/microsoftofficeupdate/isapdl/default.aspx?ln=en-us&amp;id=[redacted]<br />Quick Details<br />• File Name: officexp-KB910721-FullFile-ENU.exe<br />• Version: 1.4<br />• Date Published: Thu, 18 Jun 2009 16:46:55 -0500<br />• Language: English<br />• File Size: 81 KB<br />System Requirements<br />• Supported Operating Systems: Windows 2000; Windows 98; Windows ME; Windows NT; Windows Server 2003; Windows XP; Windows Vista<br />• This update applies to the following product: Microsoft Outlook / Outlook Express<br />Contact Us<br />© 2009 Microsoft Corporation. All rights reserved. Contact Us |Terms of Use |Trademarks |Privacy Statement</blockquote><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/fake-ms-736968.png"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 289px;" src="http://www.dynamoo.com/blog/uploaded_images/fake-ms-736965.png" alt="" border="0" /></a>Although the link <span style="font-style: italic;">appears</span> to be for the Microsoft web site, underneath is a hidden URL which is quite different. From samples I have plus some scraped from teh interwebs, I came up with the following samples:<br /><br />hxxp:||update.microsoft.com.ijlijji.com/microsoftofficeupdate/isapdl/default.aspx?ln=en-us&amp;id=[redacted]<br />hxxp:||update.microsoft.com.ijj1hjf.com/microsoftofficeupdate/isapdl/default.aspx?ln=en-us&amp;id=[redacted]<br />hxxp:||update.microsoft.com.ijlijjh.net/microsoftofficeupdate/isapdl/default.aspx?ln=en-us&amp;id=[redacted]<br />hxxp:||update.microsoft.com.ijlijj1.com/microsoftofficeupdate/isapdl/default.aspx?ln=en-us&amp;id=[redacted]<br />hxxp:||update.microsoft.com.ijlijji.net/microsoftofficeupdate/isapdl/default.aspx?ln=en-us&amp;id=[redacted]<br />hxxp:||update.microsoft.com.il1if1.com.mx/microsoftofficeupdate/isapdl/default.aspx?ln=en-us&amp;id=[redacted]<br /><br />The reason why this is a FAIL? None of the domains are registered apart from the .com.mx one, so clicking the links will do precisely nothing. il1if1.com.mx is hosted on a botnet with presumably fake registration details, but it seems to be quite unreliable.<br /><br />Even though this attack doesn't work, it might be a good idea to keep an eye out for it and advise any end users you have. Also checking your proxy logs for <span style="font-weight: bold;">update.microsoft.com.i</span> may well be useful.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-1261119434999787704?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com1tag:blogger.com,1999:blog-804714437673009003.post-16342784562297701452009-06-16T10:21:00.003+01:002009-06-16T10:34:11.530+01:00WebTrends just doesn't get itWebTrends is a service I used to run a few years ago for web analytics, until the hundreds of dollars per month it was charging for analytics which I could get cheaper elsewere (or now even free) became ridiculous.<br /><br />So, I stopped using the service and opted out of all email communications as I was no longer interested. So, this bizarre email from WebTrends plops into my mailbox today:<br /><br /><span style="font-style: italic;"><blockquote>Thank you for taking a moment to look at this email. We know you've unsubscribed from Marketing Communications from us and respect your request, but wanted to let you know that we're making some much-needed changes to our email programming. Our new approach lets you tell us what messages you want. Tell us which of these topics are most valuable to you and we'll limit what we send to what you're interested in. Simply click on the link below to personalise your email subscription. Still not interested? Ignore this message, it'll be the last email you receive from us.</blockquote></span>Let's read that again.. "<span style="font-style: italic;">We know you've unsubscribed from Marketing Communications from us and respect your request</span>".. well, clearly you bloody aren't respecting my request, are you?<br /><br />WebTrends is not the worst offender - some companies simply do not understand the meaning of the word "unsubscribe". Doesn't it mean "don't send me anything unless I change my mind"? It seems it now means "don't send me anything unless you really want to" instead.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-1634278456229770145?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-37156057602579763842009-06-11T17:17:00.002+01:002009-06-11T17:20:10.711+01:00Personal Computer World to closeNoooo! According to the Guardian, <a href="http://www.guardian.co.uk/media/2009/jun/08/personal-computer-world-closure-incisive-media">Personal Computer World is to close</a> after 31 years of publication. I've read it for 29 of those 31 years. A damned shame, and the only paper-based IT magazine I still read.<br /><br />Mind you, I'm still upset about <a href="http://en.wikipedia.org/wiki/Byte_magazine">BYTE</a> closing and <span style="font-style: italic;">that</span> was 11 years ago!<br /><br />The last issue of PCW is out on the 18th June. Sniff.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-3715605760257976384?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-54269204657366005752009-06-03T12:42:00.003+01:002009-06-03T13:27:17.100+01:00mediahousenamemartmovie.cn / nonfathighestlocate.cn injection attackAnother set of injection attacks seem to be doing the rounds, possibly related to the <a href="http://www.martinsecurity.net/2009/05/20/inside-the-massive-gumblar-attacka-dentro-del-enorme-ataque-gumblar/">recent Gumblar attack</a>.<br /><br />In this case, the injected code is an IFRAME pointing to <span style="font-weight: bold;">hxxp:||mediahousenamemartmovie.cn:8080/ts/in.cgi?pepsi27</span> and redirecting to <span style="font-weight: bold;">hxxp:||nonfathighestlocate.cn:8080/index.php</span> which attempts to load a Flash exploit (<a href="http://www.virustotal.com/analisis/5378ecbabad28154db0a224897d2f429a950009bd63b29a6e95ae00dec8fe522-1243950980">VirusTotal results</a>) and PDF exploit (<a href="http://www.virustotal.com/analisis/fec9baf3c6c0ae49a3002bc766a2cdd27c92f71a63a368dc59615c04fee6feca-1244023874">VirusTotal results</a>). The payload includes a DLL (perhaps C:\WindowsSystem32\1028T.DLL although it may vary) that offers some sort of backdoor functionality (<a href="http://www.virustotal.com/analisis/dd940eb4e228e68e5b628c1a5f1013d49991cb4d0a9174bbac6c3247de06422d-1244017403">VirusTotal results</a>).<br /><br />The malware domains are on 89.149.240.64 in Germany, all domains on that server seem to be malware related and should be blocked. The server identifies itself via RDNS as "fuckingl33t.eu" although that proves nothing.<br /><ul><li>Autobestwestern.cn</li><li>Bestlitediscover.cn</li><li>Bestwebfind.cn</li><li>Bigbestfind.cn</li><li>Bigtopartists.cn<br /></li><li>Giantnonfat.cn</li><li>Greatbethere.cn<br /></li><li>Homenameworld.cn</li><li>Hugebest.cn</li><li>Hugebestbuys.cn</li><li>Hugepremium.cn</li><li>Hugetopdiscover.cn</li><li>Litepremium.cn</li><li>Litetopfinddirect.cn<br /></li><li>Litetopseeksite.cn</li><li>Lotbetsite.cn</li><li>Mediahomenameshoppicture.cn</li><li>Mediahousenamemartmovie.cn</li><li>Nameforshop.cn</li><li>Nanotopdiscover.cn<br /></li><li>Nonfathighestlocate.cn</li><li>Thebestyoucanfind.cn</li><li>Topfindworld.cn</li><li>Toplitesite.cn</li><li>Tvnameshop.cn</li><li>Yourlitetopfind.cn</li></ul>Nonfathighestlocate.cn was on 89.149.240.64, but then pointed at to 82.208.58.199 in the Czech Republic.<br /><br />If this is related to Gumblar, then the problem could be down to compromised FTP passwords. If your site has been infected with this attack, then you need to carefully check each machine that has FTP access to your website, clean them up and then change your FTP password to something secure.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-5426920465736600575?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-18066778138814816742009-06-01T09:57:00.003+01:002009-06-01T10:07:19.958+01:00flyappraisals.com scamPart of an ongoing domain name scam, <span style="font-weight: bold;">flyappraisals.com </span>is a fake domain name appraisal used in conjunction with a bogus unsolicited offer to buy a domain, similar to the following:<br /><br /><blockquote>We are interested to buy your domain name [redacted] and offer to buy it from you for 65% of the appraised market value.<br /><br />As of now we accept appraisals from either one of the following leading appraisal companies:<br /><br />sedo.com<br />flyappraisals.com<br />accuratedomains.com<br /><br /><br />If you already have an appraisal please forward it to us.<br /><br />As soon as we have received your appraisal we will send you our payment (we use Paypal for amounts less than $2,000 and escrow.com for amounts above $2,000) as well as further instructions on how to complete the transfer of the domain name.<br /><br />We appreciate your business,</blockquote>Out of these three "appraisal" companies, flyappraisals.com is the cheapest. So, naturally a lot of people will part with some money for an appraisal. Of course, the offer to buy the domain name never comes through and the domain name owner is out of pocket.<br /><br />It looks like this scam is being run out of Canada, and we have covered it many times before: <a href="http://www.dynamoo.com/blog/2009/05/podzzcom-domain-scam.html">here</a>, <a href="http://www.dynamoo.com/blog/2009/05/nameorange-nameorangecom-scam.html">here</a>, <a href="http://www.dynamoo.com/blog/2009/03/pedmacom-domain-appraisals.html">here</a> and <a href="http://www.dynamoo.com/blog/2009/04/tropicalnamescom-scam.html">here</a>. If you live in Canada and have been ripped off, then reporting it to the RCMP may get some results. You should also raise a dispute with PayPal to get a refund.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/flyappraisals-721484.jpg"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 297px;" src="http://www.dynamoo.com/blog/uploaded_images/flyappraisals-721481.jpg" alt="" border="0" /></a><br />This particular site has a jolly bit of flash on it, unlike the plain HTML of the old sites. It is hosted on 124.217.231.209 in Malaysia.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-1806677813881481674?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com2tag:blogger.com,1999:blog-804714437673009003.post-76230976070949661312009-05-29T13:36:00.003+01:002009-05-29T13:49:13.807+01:00Bing.com is coming. W00t!Microsoft is launching a new search engine called <a href="http://www.bing.com/">bing.com</a> on Monday. Given the current fashion for "reboots" in movies and TV shows, bing.com can be considered a reboot of live.com which is turn was a reboot of MSN Search, and it follows in the great traditions of <span style="font-weight: bold;">Google Killers</span> such as.. errr... <a href="http://www.cuil.com/">Cuil</a>.<br /><br />Microsoft say:<br /><blockquote style="font-style: italic;">We took a new approach to go beyond search to build what we call a decision engine. With a powerful set of intuitive tools on top of a world class search service, Bing will help you make smarter, faster decisions. We included features that deliver the best results, presented in a more organized way to simplify key tasks and help you make important decisions faster.<br /><br />And features like cashback, where we actually give you money back on great products, and Price Predictor, which actually tells you when to buy an airline ticket in order to help get you the best price — help you make smarter decisions, and put money back in your pocket.</blockquote>I say:<br /><blockquote style="font-style: italic;">Meh.</blockquote>Microsoft have never been any good at search, and it's hard to see how this will beat Google when all people want to do is find stuff and move on. Heck, even Google struggles to get people to use more than search - according to <a href="http://www.alexa.com/siteinfo/google.com">Alexa</a>, 90% of Google traffic is for search, image search and mail. If people really wanted more, they would probably use it.<br /><br />Anyway, we fixed Bing's logo for them.<br /><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/bing-fail-735998.png"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 316px; height: 160px;" src="http://www.dynamoo.com/blog/uploaded_images/bing-fail-735996.png" alt="" border="0" /></a><br />According the the Internet Archive, the bing.com domain already has a <a href="http://web.archive.org/web/*/http://www.bing.com/">substantial history of fail</a>. Including a bizarre scheme to turn email messages into snail mail post. Hmmmm.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-7623097607094966131?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com1tag:blogger.com,1999:blog-804714437673009003.post-71242969498335197602009-05-28T11:05:00.003+01:002009-05-28T11:12:10.901+01:00Podzz.com domain scam<span style="font-weight: bold;">Podzz.com</span> is the latest incarnation of a fraudulent domain appraisal scam being run out of Canada. The basic pitch is that you receive an unsolicited offer for a domain name, with a list of three or more possible appraisal services to evaluate it. In this case, podzz.com is the cheapest, and the most likely for the victim to choose.<br /><br />Of course, what then happens is that the offer disappears and the victim is out of pocket. We have covered this scam and the people behind it <a href="http://www.dynamoo.com/blog/2009/05/nameorange-nameorangecom-scam.html">here</a>, <a href="http://www.dynamoo.com/blog/2009/03/pedmacom-domain-appraisals.html">here</a> and <a href="http://www.dynamoo.com/blog/2009/04/tropicalnamescom-scam.html">here</a>. Avoid.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/podzz-777975.jpg"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 285px; height: 320px;" src="http://www.dynamoo.com/blog/uploaded_images/podzz-777971.jpg" alt="" border="0" /></a><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-7124296949833519760?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-45511678010072765392009-05-27T11:39:00.003+01:002009-05-27T11:43:19.898+01:00"Dealer warning as police investigate security imposters"I don't usually recycle press releases, but this one is of interest. It's really aimed at mobile phone dealers and details the possibility of customer poaching through stolen paperwork, but it seems to have good general guidance that applies to most companies.<br /><br /><blockquote><span style="font-weight: bold;">Dealer warning as police investigate security imposters</span><br />CRIMINAL gangs posing as security staff are targeting mobile phone dealers, according to experts.<br /><br />Scammers are trying to trick staff into handing over confidential data by pretending to be from shredding companies according to one of the UK’s largest operators.<br /><br />Competitors are even reported to be raiding the bins of dealer with lax security at their premises to uncover useful details about contract expiry dates.<br /><br />Jim Watson, managing director of Shred Easy, which destroys confidential data for mobile phone dealers, said:<br /><br />“Scammers are targeting dealers to get their hands on valuable paperwork. There has been a spate of people pretending to be working for Shred Easy and our competitors by trying to trick staff into handing over bags of confidential data that has been safely kept within a store.<br /><br /><br />“Mobile phone dealers are vigilant in terms of securely storing their data but when it comes to the disposal of that information they must be alert to con artists trying to trick them into handing it over.<br /><br /><br />“Major operators will suffer dearly and some independent dealers could even be put out of business if the data fell into the wrong hands. The loss of confidential phone numbers, contact details as well as details about contracts and customers would be devastating.<br /><br /><br />“We have already been in contact with the police and made them aware of the details. I can’t go into details about who was targeted for legal reasons but it was a major mobile phone retailer and we’ve ensured their staff are alert and follow the official policy for dealing with confidential waste.<br /><br /><br />“Dealers must be also be alert to the fact that their competitors are fighting tooth and nail to get their hands on data and in some cases we’ve heard reports of competitors sifting the bins outside dealerships to get confidential customer details so they can be poached at a later date”<br /><br />Shred Easy offers five top tips for mobile phone dealers: <br /><br />1) Always ask for identification<br />2) Only deal with an accredited shredding company<br />3) Make use of professional ‘onsite shredding vehicles’<br />4) Store confidential data securely in store<br />5) Don’t throw paperwork in the bin<br /><br /><br />See <a href="http://www.shredeasy.com/">www.shreadeasy.com</a> </blockquote><br />While you might think to challenge someone coming into your business premises, how often do you check that people taking waste away are really who they say they are?<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-4551167801007276539?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-20179752565681323212009-05-26T22:03:00.002+01:002009-05-26T22:12:16.610+01:00"Norton Finance" fraudulent loan offer<a href="http://www.nortonfinance.co.uk/">Norton Finance</a> are a real company that offers loans, typically to people with poor credit ratings. This lazy scam email is <span style="font-style: italic;">not</span> from Norton Finance, but is instead is a scam, routed through IP address 209.226.175.134 in Canada which is <a href="http://www.google.com/search?&amp;ie=utf-8&amp;oe=utf-8&amp;q=209.226.175.134">well known</a> for fraudulent emails. Avoid.<br /><br /><blockquote>Subject: home loan or loan for any legitimate reason<br />From: "NORTON FINANCE COMPANY" bengalfinancial@bellnet.ca<br />Date: Tue, May 26, 2009 9:48 pm<br /><br />For further enquires and to apply for a loan from us,please feel free to contact our application desk with details.Send us an email<br />Mr. Tony White<br />norton.finance@btinternet.com<br />Regards,<br />Stanke Kathryn<br />(Online Advertiser)<br />NORTON FINANCE COMPANY (NFC)</blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-2017975256568132321?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-59724358514713535072009-05-24T00:24:00.003+01:002009-05-24T00:47:32.360+01:00Nadine Dorries vs The Daily Telegraph<a href="http://www.dorries.org.uk/">Nadine Dorries</a> is my MP. On many things, I do not agree with her. I certainly would not vote for her, but as an elected member of parliament she is entitled to express her opinion within reason.<br /><br />The <a href="http://www.telegraph.co.uk/">Daily Telegraph</a> is a national newspaper. On many things, I do not agree with it. I certainly would not buy it, but as a newspaper in an (allegedly) free country, it is entitled to express its opinion within reason.<br /><br />Surely our democratic system allows for people to express different opinions and for voters to make up their own mind. So, why is it that the Daily Telegraph feels that it is entitled to try to get Ms Dorries blog shut down, according to <a href="http://www.bedsonsunday.com/bedsonsunday/DisplayArticle.asp?ID=419734">Bedfordshire on Sunday</a>. Is it that she chose to question the motives of the Barclay brothers who own the Daily Telegraph?<br /><br />Ms Dorries' blog is offline at the moment, but it is still available in the <a href="http://www.google.co.uk/search?hl=en&amp;q=nadine+dorries+blog&amp;btnG=Search&amp;meta=">Google Cache</a> if you want to try to work out what may have offended this newspaper and its billionaire owners.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-5972435851471353507?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-20512543046051593822009-05-20T22:15:00.003+01:002009-05-20T22:36:28.698+01:00mig-design.com fraudulent job offerA straightforward pitch for what is probably a <a href="http://www.bobbear.co.uk/#1">money mule</a> operation.<br /><br /><blockquote>Subject: Looking for a job? More info here<br />From: "Shirley Schafer" boss@adabillur.com<br /><br />Greetings,<br /><br />If you are still looking for a well-paid part time job (2-4 hours a day) with possible full-time promotion opportunities at one of top-echelon Management Companies, please e-mail your resume/CV or a short description of your former activities.<br /><br />Use ONLY corporative e-mail address below for all further correspondence:<br />office@mig-design.com<br /><br />Necessary information concerning working and cooperation opportunities, financial benefits and advantages is sent by your request.<br /><br />Yours faithfully,<br />Recruiting Office,<br />MIG Management and Design</blockquote><br />Let's look at mig-design.com.. actually, <span style="font-style: italic;">don't</span> - it's never a good idea to poke at spamvertised sites unless you know what you are doing. There's not much to see apart from a snazzy logo saying "MIG International Design Group".<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/mig-design-766791.png"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 121px;" src="http://www.dynamoo.com/blog/uploaded_images/mig-design-766789.png" alt="" border="0" /></a>The logo has clearly been professionally designed. But it also appears to have been stolen from <a href="http://www.migmbh.com/">this site</a> although amusingly the spammers have corrected the obvious spelling error.<br /><br />Let's check out the WHOIS details:<br /><br /><span style="font-family:courier new;"> Name : Michell</span><br /><span style="font-family:courier new;"> Organization : Michell</span><br /><span style="font-family:courier new;"> Address : 56/2 Sun str.</span><br /><span style="font-family:courier new;"> City : Dallas</span><br /><span style="font-family:courier new;"> Province/State : beijing</span><br /><span style="font-family:courier new;"> Country : </span><br /><span style="font-family:courier new;"> Postal Code : 85230</span><br /><span style="font-family:courier new;"> Phone Number : 86--56343365</span><br /><span style="font-family:courier new;"> Fax : 86--56343365</span><br /><span style="font-family:courier new;"> Email : Michell.Gregory2009@yahoo.com<br /></span><br /><br />A quick <a href="http://www.google.com/search?hl=en&amp;q=%22Michell.Gregory2009%40yahoo.com%22&amp;btnG=Search&amp;meta=">Google search</a> for that email address shows several hits.. indeed, it has been used before for the <a href="http://www.dynamoo.com/blog/2009/04/luxgroupnzcom-luxgroup-scam.html">luxgroupnz.com scam</a>.<br /><br />The IP address of the site is 61.150.91.136 in China and usually in these circumstances it is safe to assume that ALL sites on the same server are suspect:<br /><br /><ul><li>Bsi-investment.com</li><li>Bsibanksingapore.com</li><li>Ckinter.cn</li><li>Ckinter.ru</li><li>Freeadulttube.com.cn</li><li>Importfinanceinc.com</li><li>Intdgroup.com</li><li>Lloydsinsurer.com</li><li>Luxgroupww.com</li><li>Majordesigngroup.net</li><li>Medikmenty.com</li><li>Mens-health.com.cn</li><li>Mig-design.com</li><li>Mig-disign.com</li><li>Teentube.com.cn</li><li>Vsehorosho.info</li><li>W-trabajo.com</li><li>Wploy-empleo.com</li><li>Wtrabajo.com</li></ul>In this case the email originates from 117.197.0.23 in India.<br /><br />A flashy logo does not mean that it's a legitimate site. In this case the spammers have just ripped off someone else's identity. Avoid.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-2051254304605159382?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com2tag:blogger.com,1999:blog-804714437673009003.post-1212839927940720332009-05-19T15:51:00.003+01:002009-05-19T16:04:14.271+01:00Phorm WhitewashThe British government's stance on <a href="http://en.wikipedia.org/wiki/Phorm">Phorm</a> has always been pretty supine. Despite serious allegation of criminal misconduct by Phorm and BT, the Government has again decided to whitewash the issue after politely ignoring the <a href="http://petitions.pm.gov.uk/ispphorm">latest anti-phorm petition</a>.<br /><blockquote><br />Thank you for the e-petition on internet advertising technologies and customer privacy.<br /><br />As your petition states, some Internet Service Providers (ISPs) have been looking at the use of Phorm’s Webwise and Open Internet Exchange (OIX) products. However, the only use of the technology so far has been the trials conducted by BT.<br /><br />Advertisers and ISPs need to ensure that they comply with all relevant data protection and privacy laws. It is also important that consumers’ privacy is protected and that they are given sufficient information and opportunity to make a clear and informed decision whether to participate in services such as Phorm.<br /><br />The Government is committed to ensuring that people’s privacy is fully protected. Legislation is in place for this purpose and is enforced by the Information Commissioner’s Office (ICO). ICO looked at this technology, to ensure that any use of Phorm or similar technology is compatible with the relevant privacy legislation. ICO has published its view on Phorm on its website:<br /><br /><a href="http://www.ico.gov.uk/upload/documents/pressreleases/2008/new_phorm_statement_040408.pdf">[link]</a><br /><br />ICO is an independent body, and it would not be appropriate for the Government to second guess its decisions. However, ICO has been clear that it will be monitoring closely all progress on this issue, and in particular any future use of Phorm’s technology. They will ensure that any such future use is done in a lawful, appropriate and transparent manner, and that consumers’ rights are fully protected.</blockquote>In other words - private companies unlawfully spying on citizens is no concern of the government.<br /><br />Conspiracy theorist like to point out that Phorm's web monitoring technology is <span style="font-style: italic;">exactly</span> the sort of thing that the government <a href="http://www.timesonline.co.uk/tol/news/uk/article4882600.ece">wants to do</a>. Fortunately, it looks like Phorm is <span style="font-style: italic;">perhaps</span> on their last legs after launch of this <a href="http://www.stopphoulplay.com/">bizarre foaming-at-the-mouth blog</a> that they started recently.<br /><br />The government's complete disdain for British citizens is astonishing, and will probably be reflected in a humiliating result in next month's European and local elections. But then if voting really changed anything, this government probably <span style="font-style: italic;">would</span> make it illegal.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-121283992794072033?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-6108083789461255752009-05-18T11:16:00.004+01:002009-05-18T11:22:48.406+01:00NameOrange / nameorange.com scamAnother variant of <a href="http://www.dynamoo.com/blog/2009/03/pedmacom-domain-appraisals.html">this scam</a> and <a href="http://www.dynamoo.com/blog/2009/04/tropicalnamescom-scam.html">this scam</a> linked to a guy called Manuel Fichter - the basic pitch is that you get an email offering to buy your domain name which lists a number of "approved" domain appraisers, the one that appears to be cheapest is actually run by the scammer.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/nameorange-749378.jpg"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 286px; height: 320px;" src="http://www.dynamoo.com/blog/uploaded_images/nameorange-749374.jpg" alt="" border="0" /></a><br /><br />Avoid this one. If you live in Canada and believe that you have been defrauded, then contact your local RCMP and make a complaint about:<br /><br />Manuel Fichter<br />38 Matthew Drive<br />Hammonds Plains, NS B4B 1T8<br />Canada<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-610808378946125575?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-35273208223326652842009-05-18T10:32:00.003+01:002009-05-18T10:50:36.697+01:00martuz.cn injection attackIn the past couple of weeks, thousands of websites were hit with an injection attack pointing to gumblar.cn.. this week it has changed to martuz.cn. It's not a SQL injection attack as far as I can tell, the smart money is that it is using compromised FTP credentials, possibly harvested from end-user PCs rather than a problem with the web server itself.<br /><br />A typical attack is that JS files on the victim's server are altered with an obfuscated (i.e. partly encrypted) script which might vector through <span style="font-weight: bold;">martuz.cn/vid/?id=5718066</span> or <span style="font-weight: bold;">martuz.cn/vid/?id=575730</span> or something similar, then leading to <span style="font-weight: bold;">martuz.cn/vid/?id=3</span> or another similarly named page (the exact URLs may vary depending on the client software).<br /><br />There's a writeup about martuz.cn <a href="http://www.malwaredomainlist.com/forums/index.php?topic=2892.0">here</a> and <a href="http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/">here</a>, in the meantime blocking traffic to the domain and the IP address 95.129.145.58 will probably be a good idea.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-3527320822332665284?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-70800119878126406002009-05-13T18:50:00.003+01:002009-05-13T18:57:18.543+01:00419ers hit by the downturn?A strangely worded <a href="http://en.wikipedia.org/wiki/Advance_fee_fraud">419 scam</a> arrived today in a format I haven't seen before. Perhaps the economic downturn is having an effect on the supply of gullible people?<br /><br /><blockquote style="font-style: italic;">Subject: THAT IS ALL I CAN DO FOR YOU<br />From: "RICHARD GOZNEY" bhcommission1@mail2consultant.com<br />Date: Tue, May 12, 2009 6:56 pm<br /><br />BRITISH HIGH COMMISSION<br />DANGOTE HOUSE,<br />AGUYI IRONSI STREET, MAITAMA DISTRICT,<br />ABUJA,NIGERIA..<br />TEL: +234-8039672472<br /><br /><br />Attention<br /><br />After long silence from you we came to realize that you may have given up your compensation due to lack of money for the Certificates.<br /><br />I have been able to settle for the Certificates which amounts to US$1800 so i expect you to pay me back once you receive your card.<br /><br />You have to reconfirm your delivery address for the EMS courier company to mail your ATM card to you without delay. Note that you are entitled to settle for their safe keeping fee of $250.<br /><br />Make haste to send down your address and i shall provide you with the information of their cashier for you to send the safe keeping fee of $250 to her.<br />I am looking forward to your immediate response.<br /><br />Yours in Service,<br /><br />Mr. Richard Gozney</blockquote><br />Despite the Nigerian address the email originates from 200.7.198.3 in Ecuador, although the phone number is definitely Nigerian and has been used for this type of scam many times before.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-7080011987812640600?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-36122395577253200232009-05-12T22:08:00.003+01:002009-05-12T22:17:22.848+01:00"Western Union Transfer MTCN: 2474153681" trojanAnother EXE-in-ZIP trojan, this time disguised as an Excel spreadsheet. The pitch is:<br /><br /><blockquote style="font-style: italic;">Subject: Western Union Transfer MTCN: 2474153681<br />From: "Western Union Support Team" support@westernunion.com<br />Date: Tue, May 12, 2009 11:00 pm<br /><br />Dear Customer!<br /><br />The money transfer you have sent on the 22nd of April was not collected by the<br />recipient.<br />According to the Western Union contract the transfers which are not received in 15<br />days are to be returned to sender.<br />To collect cash you need to print the invoice attached to this email and visit the<br />nearest Western Union agency.<br /><br />Thank you!</blockquote>In this case there was an attachment called Invoice_8773.zip containing a file named Invoice_8773.exe. Because of the really stupid way that Windows (by default) hides the file extensions and the fact that the bad guys have given this executable a convincing icon, it will look something like this when unzipped:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/invoice-trojan-728635.gif"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 129px; height: 58px;" src="http://www.dynamoo.com/blog/uploaded_images/invoice-trojan-728634.gif" alt="" border="0" /></a>VirusTotal identifies is as a <a href="http://www.virustotal.com/analisis/972488f1ed177b7f93674d7c363db464">variant of Zbot</a>, the <a href="http://www.threatexpert.com/report.aspx?md5=fa491105bd5c3baedad78f28586ff91e">ThreatExpert prognosis</a> has more details in case you are trying to clean it up.<br /><br />If you can block EXE-in-ZIP files at your mail perimeter, then that is always the best defence against this kind of attack.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-3612239557725320023?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-78587089605153981492009-05-11T14:27:00.005+01:002009-05-11T15:06:56.787+01:00Michael Price / BizSummits.org unsolicited bulk emailI've had a few of these in the past, but this time my spidey sense was tingling.<br /><br /><span style="font-style: italic;">Subject: Roger, Website discussion on April 21st.<br />From: "Pat Weller" pat@mktgalliance.org<br />Date: Mon, May 11, 2009 1:49 pm<br /><br />Hi Roger, let me know if you might be interested in attending our<br />upcoming program, "Does Your Website Produce the Results You Want? How to<br />Drive Conversions by Writing Better Content" on Monday, April 27th. You<br />can view the complete details at www.mktgalliance.org/webconversations<br /><br />Businesses of all sizes can benefit greatly from these ideas that have<br />proven to work based on experiences with hundreds of websites. Thomas<br />Young, Internet Marketing Consultant and CEO with Intuitive Websites,<br />will be making the presentation. He will review conversion strategies,<br />effective taglines, using captions on photos, how to avoid blocks of text,<br />bullet items in web copy, how to avoid brochure copy and marketing-speak,<br />calls to action and more. I hope you and your team will join us.<br /><br />Best regards,<br /><br />Pat Weller<br />Program Director<br />Marketing Alliance<br />600 North Park Centre<br />Seventeenth Floor<br />Mail back to decline further<br />Atlanta, GA 30328<br />www.mktgalliance.org/webconversations</span><br /><br />Well, I'm not called "Roger" and I can't quite figure out where that came from. The email came from 66.232.113.10 which is the same IP as mktgalliance.org, so that really confirms it as genuine.<br /><br />A look at the WHOIS details are interesting:<br /><br /> BizSummits<br /> Michael Price (MPrice@BizSummits.org)<br /> +1.8006003389<br /> Fax:<br /> 1200 Abernathy Rd, 17th Floor<br /> Atlanta, GA 30328<br /> US<br /><br />Alright, ten points for having (apparently) genuine contact details (it matches their <a href="http://www.bbb.org/atlanta/business-reviews/business-promotions-general/bizsummits-in-atlanta-ga-27255671">BBB report</a>), minus several million points for blasting out unsolicited emails to random addresses.<br /><br />Is it spam? Well, it's certainly unsolicited commercial email and in this case it was sent to an email address that didn't actually exist. Annoyingly, it could well be CAN SPAM compliant. But it falls within the scope of the <a href="http://en.wikipedia.org/wiki/Roger_Ebert#Boulder_Pledge">Boulder Pledge</a> so best avoided.<br /><br />Here are some other domains associated with BizSummits:<br /><ul><li>mybizteleseminars.net</li><li>customerservicesummit.net</li><li>theopsbenchmarkalliance.com</li><li>associationgrowthsummit.net</li><li>mktgalliance.org<br /></li></ul>DavesPlanet.net has more information <a href="http://www.davesplanet.net/MichaelPrice/bizsummits.org.htm">here</a>, the Other Librarian blog indicates that it has been going on for years <a href="http://otherlibrarian.wordpress.com/2006/08/16/invitation-only-summits-with-major-executives-eh/">here</a>, and a <a href="http://www.google.com/search?hl=en&amp;ie=UTF-8&amp;q=%22Atlanta%2C%20GA%2030328%22%20%20%22Mail%20back%20to%20decline%20further%22&amp;sa=N&amp;tab=gw">Google Search</a> shows just how widespread these unsolicited emails are. Do you really want to do business with a company like this?<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-7858708960515398149?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com5tag:blogger.com,1999:blog-804714437673009003.post-9327176641678446202009-05-11T10:51:00.003+01:002009-05-11T11:34:41.197+01:00Underwater mobile phoneNeed a phone that works under water? Well, the Samsung B2100 Solid Extreme does. But as they used to say on TV.. "kids, don't try this at home".<br /><br /><br /><object width="480" height="295"><param name="movie" value="http://www.youtube.com/v/EYNf00A1QSc&hl=en&fs=1&hd=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/EYNf00A1QSc&hl=en&fs=1&hd=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="400" height="246"></embed></object><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-932717664167844620?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0tag:blogger.com,1999:blog-804714437673009003.post-20496165301459256532009-05-01T18:14:00.004+01:002009-05-02T11:45:58.033+01:00webmail.upgrade@spamcop.net phishA fairly lazy attempt to phish SpamCop accounts, originating from 200.85.160.12 in Nicaragua. If you're a SpamCop subscriber, then report it via the usual mechanism. The Reply-To address is <span style="font-weight: bold;">webmailupgrader@consultant.com</span>, so you should be able to tell that it is a fake.<br /><br /><blockquote>Subject: Spamcop Email Verification<br />From: "Spamcop Webmail Notice" webmail.upgrade@spamcop.net<br />Date: Fri, May 1, 2009 5:11 pm<br />To: webmail.upgrade@spamcop.net<br /><br />Dear Spamcop Webmail Account Owner,<br />We are currently performing maintenance for Our Spamcop<br />Digital Webmail Customers.We intend upgrading our Digital<br />Webmail Security Server for better online services. We are<br />canceling unused Spamcop webmail email account to create<br />more space for new accounts.To prevent your account from<br />closing you will have to update it below to know it's status<br />as a currently used account.<br /><br />CONFIRM YOUR EMAIL IDENTITY BELOW<br />Email Username :=====================================<br />Email Password :=====================================<br />Date of Birth :======================================<br /><br />Warning!!! Any account owner that refuses to update his/her<br />webmail account within three (3) days of this update<br />notification will loose his/her account permanently.<br /><br />Thank You For Your Support</blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-2049616530145925653?l=www.dynamoo.com%2Fblog%2Findex.htm'/></div>Conrad Longmorehttp://www.blogger.com/profile/11751822299235747323noreply@blogger.com0