<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-446873836886549311</id><updated>2012-02-01T07:26:57.042-07:00</updated><category term='crimeware research'/><category term='web'/><category term='siberia exploit pack'/><category term='e-fraud research'/><category term='malware'/><category term='ESET'/><category term='Drive-by-Download'/><category term='cybint'/><category term='IE Defender'/><category term='affiliate program research'/><category term='safety'/><category term='vulnerabilities'/><category term='exploit pack research'/><category term='espionage'/><category term='zeus'/><category term='scareware'/><category term='spam'/><category term='anti-virus live 2010'/><category term='malware intelligence'/><category term='iMunizator'/><category term='Fast-Flux'/><category term='xss'/><category term='luckysploit'/><category term='dos'/><category term='iJAVA'/><category term='elfiesta'/><category term='vulnerabilities researcher'/><category term='fragus'/><category term='whitepapers'/><category term='russkill'/><category term='Unique Sploit Pack'/><category term='attack'/><category term='security'/><category term='MacOS'/><category term='Social Engineering'/><category term='xp police antivirus'/><category term='crimeware'/><category term='Java Drive-by-Download'/><category term='Polymorphic PoisonIvy Builder Online. PoisonIvy'/><category term='waledac'/><category term='ddos'/><category term='desinformation'/><category term='botnet'/><category term='Polymorphic Cryptor Crum'/><category term='denial of service'/><category term='koobface'/><category term='phishing'/><category term='rogue'/><category term='jorge mieres'/><category term='iformation'/><category term='pistus malware intelligence'/><category term='botnet research'/><category term='malware research'/><category term='Drive-by-Update'/><category term='exploit'/><category term='password'/><category term='fragu'/><category term='MaaS'/><title type='text'>Malware Intelligence Blog</title><subtitle type='html'>The information shared on this site is part of several research sessions and, in most textbooks, provides information that can harm your system if handled improperly. The decision to share it's purely investigative and educational, considering also useful for the prevention of attacks by different threats.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default?start-index=101&amp;max-results=100'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>168</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-3097166772282348352</id><published>2012-01-29T09:02:00.000-07:00</published><updated>2012-01-29T09:02:54.656-07:00</updated><title type='text'>Hierarchy Exploit Pack. New crimeware for the cybercriminal gangs</title><summary type='text'>The term "hierarchy" refers to an entity pyramidal action. Judging by the name of this new Exploit Pack of Russian origin, it seems that the author seeks to find its place within the criminal ecosystem, but all point to the feelings behind this is, above all, a beginner who seeks criminal more.


However, despite being a package of more criminal exploitation within a vast range of alternatives, </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/3097166772282348352/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2012/01/hierarchy-exploit-pack-new-crimeware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3097166772282348352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3097166772282348352'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2012/01/hierarchy-exploit-pack-new-crimeware.html' title='Hierarchy Exploit Pack. New crimeware for the cybercriminal gangs'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-i3g97W6Fpkw/TyTez1QJSZI/AAAAAAAAAfQ/dPef4PfzYB0/s72-c/1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-7936268098097864851</id><published>2012-01-24T01:49:00.005-07:00</published><updated>2012-01-27T20:40:47.516-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='affiliate program research'/><title type='text'>Money Racing AV. Tracking a scareware affiliate</title><summary type='text'>Since October 2011 we watch this affiliate system. Money Racing AV, a private PPS (Pay-Per-Sale) affiliate who spread actively fake antispywares (rogue). We have already seen this gang active in August 2009: A recent tour of scareware XII.Advertising can be found on various russian underground communities:



First contact with FTL (6 October 2011):

[14:29:33] Load4sales: hello
[14:30:02] mr: </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/7936268098097864851/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2012/01/money-racing-av-tracking-scareware.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7936268098097864851'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7936268098097864851'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2012/01/money-racing-av-tracking-scareware.html' title='Money Racing AV. Tracking a scareware affiliate'/><author><name>Steven K</name><uri>http://www.blogger.com/profile/00282466473904820396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://1.bp.blogspot.com/-_Qclgt6p4mk/Tgh12tGQG8I/AAAAAAAABi0/CJOudSDSiHc/s220/57932.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-d8ZZCKhJTNk/Tx2VKSm65pI/AAAAAAAAE-s/n-6zxM40cdQ/s72-c/23-01-2012+09-28-16-Money-Racing-AV-FTL.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-266695159668253062</id><published>2011-10-11T22:48:00.000-07:00</published><updated>2011-10-11T22:48:56.237-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Inside Phoenix Exploit’s Kit 2.8 mini version</title><summary type='text'>Phoenix Exploit's Kit is a package with more continuity in crime scene crimeware. After all this tour is currently in the wild version 2.8 that, despite having a low activity since the last half of this year, remains one of the many Exploit Pack with greater preference for cyber-criminals.

Perhaps this "slack time" to have your response in high demand now has another crimeware of this style, </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/266695159668253062/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2011/10/inside-phoenix-exploits-kit-28-mini.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/266695159668253062'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/266695159668253062'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2011/10/inside-phoenix-exploits-kit-28-mini.html' title='Inside Phoenix Exploit’s Kit 2.8 mini version'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-HAdtWKk8Dqc/TpTdjN-dbDI/AAAAAAAAAdw/cspksTd_-Tk/s72-c/1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-5628814096165428551</id><published>2011-09-26T17:34:00.000-07:00</published><updated>2011-09-26T17:34:44.960-07:00</updated><title type='text'>Show me your Kung-Fu. Reversing/Forensic Android</title><summary type='text'>The last week was held in Barcelona the NoConName security conference, and I had the pleasure of attending to give a security conference about Android. It talked about how to perform a dynamic analysis, static and forensic skip protection and release application along with our friend of MalwareIntelligence too, Ehooo, a small PoC reveals a vulnerability of Tap-Jacking.

For those who could not </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/5628814096165428551/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2011/09/show-me-your-kung-fu-reversingforensic.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5628814096165428551'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5628814096165428551'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2011/09/show-me-your-kung-fu-reversingforensic.html' title='Show me your Kung-Fu. Reversing/Forensic Android'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-IY4SfK62YQk/ToEKNuol4mI/AAAAAAAAAds/R92U2S6h-Xg/s72-c/26-09-2011+20-05-24.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-3202169022633593234</id><published>2011-08-18T14:37:00.001-07:00</published><updated>2011-08-18T14:38:57.708-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><title type='text'>Black Hole Exploits Kit 1.1.0 Inside</title><summary type='text'>Since its appearance in September 2010, Black Hole Exploits Kit had a very positive insight into the criminal environment. Their life cycle is not over yet so it has developed a natural evolution, and so far there are three generations that exist "in the wild".

Black Hole Exploits Kit was developed by who is known under the nickname Paunch. The main screen allows viewing of each component of </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/3202169022633593234/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2011/08/black-hole-exploits-kit-110-inside.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3202169022633593234'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3202169022633593234'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2011/08/black-hole-exploits-kit-110-inside.html' title='Black Hole Exploits Kit 1.1.0 Inside'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-ruv4U412oOQ/Tk1rWGU2BgI/AAAAAAAAAdU/e9IZ6SDK3xw/s72-c/1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-7111813513965908398</id><published>2011-06-30T17:45:00.000-07:00</published><updated>2011-06-30T17:45:41.571-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iJAVA'/><category scheme='http://www.blogger.com/atom/ns#' term='Drive-by-Download'/><category scheme='http://www.blogger.com/atom/ns#' term='Java Drive-by-Download'/><title type='text'>JAVA Drive-by [infection] On Demand</title><summary type='text'>JAVA is one of the largest computer technology integration in the field of cybercrime because of its status as a "hybrid". This transforms Java platform in a highly exploited vector for the spread of all types of malicious code.

Even the modern crimeware includes a battery of exploits created to exploit vulnerable versions of JAVA through Exploit Packs, and in fact, together with the PDF files, </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/7111813513965908398/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2011/06/java-drive-by-infection-on-demand.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7111813513965908398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7111813513965908398'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2011/06/java-drive-by-infection-on-demand.html' title='JAVA Drive-by [infection] On Demand'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-q1oIU4yHotw/Tg0OOoKjFoI/AAAAAAAAAc0/rb2YACs23po/s72-c/camera-option.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-3338515853020356956</id><published>2011-06-15T15:29:00.001-07:00</published><updated>2011-06-15T15:32:41.025-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><title type='text'>The Art of the Cyberwar</title><summary type='text'>The development of new technologies, in catching up with military interests and dependence on existing technology by developed countries, sets up a scenario where the cyber war, or war in cyberspace, is becoming more important.

All countries aware of the risks of such dependence developed defense programs against attacks that could jeopardize critical national infrastructure.

On the other hand,</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/3338515853020356956/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2011/06/art-of-cyberwar.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3338515853020356956'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3338515853020356956'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2011/06/art-of-cyberwar.html' title='The Art of the Cyberwar'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-aRH8bnh4SQI/TfkxgKelWOI/AAAAAAAAAcs/BafvgDwMN1o/s72-c/the-art-of-the-cyberwar.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-4627231180423581113</id><published>2011-04-03T14:45:00.000-07:00</published><updated>2011-04-03T14:45:08.180-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><title type='text'>Gangsterware. Stealth Shield of the Malware</title><summary type='text'>A few days ago I watched one of the training of BlackHat Webcast whose title is the same as used for this post, where people of M86Security was assigned to conduct a superficial talking about the main vectors of infection today. Putting focus primarily on Exploit Packs, and emphasizing time on the modus operandi of Phoenix Kit Exploit, Neosploit and Open Source Exploit Kit (a lot of impact </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/4627231180423581113/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2011/04/gangsterware-stealth-shield-of-malware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/4627231180423581113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/4627231180423581113'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2011/04/gangsterware-stealth-shield-of-malware.html' title='Gangsterware. Stealth Shield of the Malware'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-Fyd5MM_Ohfk/TZjiYqdMjQI/AAAAAAAAAcM/2VRGKg1yFV8/s72-c/17-02-2011+06-27-35+p.m..png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-5592985780286652488</id><published>2011-02-22T07:51:00.000-07:00</published><updated>2011-02-22T07:51:26.717-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><title type='text'>See you soon Jorge Mieres!</title><summary type='text'>As many readers know, this means of information read at this time, was founded by Jorge Mieres in 2006. What you may not know is that several months ago, Jorge has decided to move away from the front of MalwareIntelligence, leaving us with complete confidence (one of the many qualities and characteristics of Jorge) the command of his legacy.

For this reason, and through these few words, we want </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/5592985780286652488/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2011/02/see-you-soon-jorge-mieres.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5592985780286652488'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5592985780286652488'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2011/02/see-you-soon-jorge-mieres.html' title='See you soon Jorge Mieres!'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-7093043921136724253</id><published>2011-02-18T21:58:00.000-07:00</published><updated>2011-02-18T21:58:35.166-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><title type='text'>Inside Carberp Botnet</title><summary type='text'>In early 2010, from MalwareIntelligence started researching a new botnet designed to agglutination of sensitive information relating to bank accounts, and theft of credentials to exploit a disturbing list of programs.

NOTE: At the bottom of this article may find the link to download the complete white paper, called "Inside Carberp Botnet", which describes the various internal components that </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/7093043921136724253/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2011/02/inside-carberp-botnet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7093043921136724253'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7093043921136724253'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2011/02/inside-carberp-botnet.html' title='Inside Carberp Botnet'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-4316866949007249493</id><published>2011-02-16T18:57:00.000-07:00</published><updated>2011-02-16T18:57:42.210-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><title type='text'>MalwareIntelligence whitepapers</title><summary type='text'>Botnets Administration. A real case - ZeuS &amp; SpyEye
Malware  networks continue to grow and parallel to, the potential risk of  becoming victims of their criminal activities. Gone are those days where  the main vector for malicious code distribution was made up of pages  that promote pornographic and warez type programs.

Today,  malware is distributed through any kind of website as a key used to</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/4316866949007249493/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2011/02/malwareintelligence-whitepapers.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/4316866949007249493'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/4316866949007249493'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2011/02/malwareintelligence-whitepapers.html' title='MalwareIntelligence whitepapers'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2670256246721800834</id><published>2010-11-07T15:53:00.002-07:00</published><updated>2010-11-07T15:57:33.176-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Crimeware Exposed</title><summary type='text'>Currently, the crimeware is widely exploited by individuals or criminal groups that seek to improve its economy so completely fraudulent using evasive and aggressive strategies.To MalwareIntelligence, the fight against cyber-crime has become his philosophy and primary objective, which make everyday a perfect excuse to address different research then channeled through one of their blogs.That is </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2670256246721800834/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/11/crimeware-exposed.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2670256246721800834'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2670256246721800834'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/11/crimeware-exposed.html' title='Crimeware Exposed'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-381661131650650542</id><published>2010-10-06T09:42:00.000-07:00</published><updated>2010-10-06T09:42:45.967-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Eleonore Exploit Pack. New version</title><summary type='text'>Without functional alternatives to renew in the package, a new version of crimeware Eleonore Exploit Pack. This is the version 1.4.4mod.

Acces panel of Eleonore Exploit Pack 1.4.4mod
While this version of crimeware is positioned as part of a set of alternatives whose number is constantly increasing due to the large range that currently exists in the area of crime, isn't very viable option for </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/381661131650650542/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/10/eleonore-exploit-pack-new-version.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/381661131650650542'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/381661131650650542'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/10/eleonore-exploit-pack-new-version.html' title='Eleonore Exploit Pack. New version'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TKyjAPTvQbI/AAAAAAAAAaM/JG_eK4qx3gY/s72-c/MI_EEP-cpanel.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1552451558103765321</id><published>2010-10-01T05:07:00.003-07:00</published><updated>2011-04-13T10:43:58.996-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Phoenix Exploit’s Kit v2.3 Inside</title><summary type='text'>PEK (Phoenix Exploit's Kit) has become one of the most used by those who flood the Internet every day with different types of malicious code. Currently, a large amount of malware is distributed through this crimeware, which is also widely used for collecting information relevant to a botmaster.

Earlier we mentioned how it looks inside version 2.1 and at the same time we said that from the </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1552451558103765321/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/10/phoenix-exploits-kit-v23-inside.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1552451558103765321'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1552451558103765321'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/10/phoenix-exploits-kit-v23-inside.html' title='Phoenix Exploit’s Kit v2.3 Inside'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TKUn9UEKbdI/AAAAAAAAAZ4/-DZlaZB3FTk/s72-c/MI_PEK23-simple-stat.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-7058038431872049746</id><published>2010-09-30T11:14:00.000-07:00</published><updated>2010-09-30T11:14:48.419-07:00</updated><title type='text'>Black Hole Exploits Kit. Another crimeware in addition to criminal supply</title><summary type='text'>Crimeware industry continues to grow through the development and implementation of new marketing packages pre-compiled exploits add to the supply of alternatives to facilitate criminal maneuvers over the Internet.

In this case, it's Black Hole Exploits Kits, a web application developed in Russia but also incorporates for the English language interface, and the first version (beta at the moment) </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/7058038431872049746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/09/black-hole-exploits-kit-another.html#comment-form' title='23 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7058038431872049746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7058038431872049746'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/09/black-hole-exploits-kit-another.html' title='Black Hole Exploits Kit. Another crimeware in addition to criminal supply'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TKTJMuaaJ0I/AAAAAAAAAZo/B1yeh2dr018/s72-c/MI_BH-stat-traffic.png' height='72' width='72'/><thr:total>23</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-3628683665740031373</id><published>2010-09-09T21:15:00.000-07:00</published><updated>2010-09-09T21:15:27.586-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Black Software. New affiliate business type Pay-per-Install</title><summary type='text'>The business model that represent the affiliate programs through systems of the type Pay-per-Install is in full swing, being a fundamental part of criminal groups seeking to increase their economy.

In this case, we have a new affiliate program called Black Software, which promotes the discharge of malware.
 Black Software Access Panel This is a simple authentication process and conventional and </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/3628683665740031373/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/09/black-software-new-affiliate-business.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3628683665740031373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3628683665740031373'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/09/black-software-new-affiliate-business.html' title='Black Software. New affiliate business type Pay-per-Install'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TImq099xL9I/AAAAAAAAAY8/OxKyqNSalMA/s72-c/MI_BlackSoftware-login.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1626063079646587741</id><published>2010-09-08T12:26:00.000-07:00</published><updated>2010-09-08T12:26:00.631-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Phoenix Exploit’s Kit v2.1 Inside</title><summary type='text'>The crimeware is one of the most used by cyber criminals to gather intelligence enabling the identification of trends and customs around by people who use the Internet daily.

This seeks to obtain relevant information on time and complete details of the victims who, further, they allow criminals to know about which factors to emphasize their "improvements" in the web application, and botmaster </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1626063079646587741/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/09/phoenix-exploits-kit-v21-inside.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1626063079646587741'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1626063079646587741'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/09/phoenix-exploits-kit-v21-inside.html' title='Phoenix Exploit’s Kit v2.1 Inside'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TIfTtZ9pzoI/AAAAAAAAAYE/xjoVSXpUpvk/s72-c/simple-stat.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-3623503879675507200</id><published>2010-09-07T20:58:00.001-07:00</published><updated>2010-09-07T20:59:14.371-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>myLoader C&amp;C Oficla Botnet in BKCNET "SIA" IZZI with the highest infection rate in Brazil</title><summary type='text'>myLoader is a web application that allows offenders to collect statistical information related to different factors and features on each of the infected computers. The crimeware is sold in the underground market at an average cost of $ 700.

The botnet Oficla started their criminal activities at the beginning of 2010 and just the executable binary detected by antivirus engines as Oficla or Sasfis</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/3623503879675507200/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/09/myloader-c-oficla-botnet-in-bkcnet-sia.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3623503879675507200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3623503879675507200'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/09/myloader-c-oficla-botnet-in-bkcnet-sia.html' title='myLoader C&amp;C Oficla Botnet in BKCNET &quot;SIA&quot; IZZI with the highest infection rate in Brazil'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TIbuHF7eKGI/AAAAAAAAAXk/Ewe376uxyjU/s72-c/MI_myloader-statistics.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1799263831423581558</id><published>2010-09-07T20:14:00.000-07:00</published><updated>2010-09-07T20:14:57.754-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><title type='text'>Criminal activities from BKCNET “SIA” IZZI / ATECH-SAGADE - Part one</title><summary type='text'>BKCNET "SIA" IZZI, also known as or simply ATECH-SAGADE is an AS (Autonomous System) numbers in 6851, currently is one of the most active of crimeware through which are distributed daily a large amount of malicious code , besides being the control base for the accommodation of several C&amp;C which feed the underground economy.

Your geolocation is in Latvia and, as I mentioned on another occasion, "</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1799263831423581558/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/09/criminal-activities-from-bkcnet-sia.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1799263831423581558'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1799263831423581558'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/09/criminal-activities-from-bkcnet-sia.html' title='Criminal activities from BKCNET “SIA” IZZI / ATECH-SAGADE - Part one'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TIb_Ev2dNKI/AAAAAAAAAX8/tsdZxXcEEBs/s72-c/bkcnet-sagade.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2065816619688044563</id><published>2010-09-03T18:02:00.000-07:00</published><updated>2010-09-03T18:02:27.256-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><title type='text'>Circuit membership for the dissemination of NoAdware rogue</title><summary type='text'>Malware hides behind a business. Without a doubt, I believe that no one denies this claim. Day by day is an important flow of malicious code that, while general purpose have a story in its activities, seeking final feedback on the business behind through fraudulent mechanisms and strategies.

One of the most popular business models is to pay a percentage of money given to those who successfully </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2065816619688044563/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/09/circuit-membership-for-dissemination-of.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2065816619688044563'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2065816619688044563'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/09/circuit-membership-for-dissemination-of.html' title='Circuit membership for the dissemination of NoAdware rogue'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TIGNrIJ590I/AAAAAAAAAXE/2tWuwui0r0o/s72-c/MI-noadware-page.png' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1357949467807786956</id><published>2010-08-30T19:49:00.000-07:00</published><updated>2010-08-30T19:49:22.891-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><title type='text'>FakeAV via new strategy of deception from BKCNET "SIA" IZZI</title><summary type='text'>Generally cheating strategies designed for the dissemination of false antivirus (AV Rogue) consist of online simulation of a scan for malware, showing an interface that mimics Windows Explorer and which always face the same threats, including when using operating systems other than Windows.
Conventional strategy of deception
This is one of the many templates. It shows a supposed scan to verify </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1357949467807786956/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/08/fakeav-via-new-strategy-of-deception.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1357949467807786956'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1357949467807786956'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/08/fakeav-via-new-strategy-of-deception.html' title='FakeAV via new strategy of deception from BKCNET &quot;SIA&quot; IZZI'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/THxjCdVGshI/AAAAAAAAAVs/TvzzQOOVVu0/s72-c/MI_fakeav.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2705337106315723198</id><published>2010-08-18T10:01:00.000-07:00</published><updated>2010-08-18T10:01:09.308-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><title type='text'>State of the art in Phoenix Exploit's Kit</title><summary type='text'>Criminal alternatives grow very fast in an ecosystem where day to day business opportunities are conceived through fraudulent processes. In this sense, the demand for resources for the cyber criminal isn't expected and is constantly growing.

Generally I find new crimeware looking to get a place and a good acceptance in the virtual streets of the world underground, trying to reflect a balance on </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2705337106315723198/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/08/state-of-art-in-phoenix-exploits-kit.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2705337106315723198'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2705337106315723198'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/08/state-of-art-in-phoenix-exploits-kit.html' title='State of the art in Phoenix Exploit&apos;s Kit'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-6123029315505907497</id><published>2010-08-15T20:37:00.000-07:00</published><updated>2010-08-15T20:37:02.908-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='affiliate program research'/><title type='text'>Pirated Edition. Affiliate program Pay-per-Install</title><summary type='text'>Affiliate programs are a growing business model more profitable for criminals and create a complete circuit of spreading / malware infection among many other alternatives, encouraging its customers with a percentage of money they get in terms of success their own business.

One of the systems with greater uptake in this business model is provided by the facility payment, Pay-per-Install, where </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/6123029315505907497/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/08/pirated-edition-affiliate-program-pay.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/6123029315505907497'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/6123029315505907497'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/08/pirated-edition-affiliate-program-pay.html' title='Pirated Edition. Affiliate program Pay-per-Install'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TGivO6czaQI/AAAAAAAAATs/ggzyCStIhJc/s72-c/MI_pirated-edition-cpanel.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-7620373591619744026</id><published>2010-08-11T17:30:00.002-07:00</published><updated>2010-08-11T17:33:21.230-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Pay-per-Install through VIVA INSTALLS / HAPPY INSTALLS in BKCNET “SIA” IZZI</title><summary type='text'>One of the most profitable businesses in the area computer crime, what are the affiliate programs. These are systems which adhere offenders an economic return for a commission, as in this case, for each successful installation of malware that takes place through the system distributed. 

VIVA INSTALLS, belonging to the same criminal group that is facing HAPPY INSTALLS, is one of them. This system</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/7620373591619744026/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/08/pay-per-install-through-viva-installs.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7620373591619744026'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7620373591619744026'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/08/pay-per-install-through-viva-installs.html' title='Pay-per-Install through VIVA INSTALLS / HAPPY INSTALLS in BKCNET “SIA” IZZI'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TGM3n5q9exI/AAAAAAAAAS8/ngqdV4_jvQY/s72-c/MI_vivainstalls.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-4117310517968865930</id><published>2010-08-09T08:00:00.000-07:00</published><updated>2010-08-09T08:00:35.031-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><title type='text'>Campaign infection through Phoenix Exploit's Pack</title><summary type='text'>Phoenix Exploit's Pack (PEK) is another crimeware programs more widely accepted within the online criminal ecosystem, whose use in the past week massifies spreading a large amount of malware.Executable binaries that are part of the campaign so far is active, spread under the default name of the executable that incorporates the package, called exe.exe. Some of the executables that are part of this</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/4117310517968865930/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/08/campaign-infection-through-phoenix.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/4117310517968865930'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/4117310517968865930'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/08/campaign-infection-through-phoenix.html' title='Campaign infection through Phoenix Exploit&apos;s Pack'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TF2xhzTN3VI/AAAAAAAAARc/ivkYxmzadQc/s72-c/MI_login.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-4835641008452053659</id><published>2010-07-25T10:45:00.000-07:00</published><updated>2010-07-25T10:45:46.871-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><title type='text'>Circuit Koobface from 91.188.59.10 (BKCNET "SIA" IZZI)</title><summary type='text'>After several months without news of Koobface, at least on typical propagation using as cover to attack the classic fake YouTube screen, is back with another season of propagation.

This time, its spread continues through visual social engineering, but not in the template of course YouTube video but uses a page with pornographic content.

As shown in the catch, when you attempt to access any of </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/4835641008452053659/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/07/circuit-koobface-from-911885910-bkcnet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/4835641008452053659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/4835641008452053659'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/07/circuit-koobface-from-911885910-bkcnet.html' title='Circuit Koobface from 91.188.59.10 (BKCNET &quot;SIA&quot; IZZI)'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Mcy4oUq8gAQ/TExsxJqSOiI/AAAAAAAAAQ8/ntXSnhGGH_4/s72-c/MI_porn-koobface.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-7404477385663634297</id><published>2010-07-16T20:30:00.000-07:00</published><updated>2010-07-16T20:30:20.362-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities researcher'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><title type='text'>Defacement by "Exploit Pack's"</title><summary type='text'>Defacing attacks, generally attributed to the activities of hacktivism and often called "script kiddies" (although now I think what best describes this kind of bad guys is: aspirant to criminals), passed the criminal background as a sort of whim or complaint against some exploit's pack who have certain vulnerabilities and has already begun to see some examples. However, this does not cut the </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/7404477385663634297/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/07/defacement-by-exploit-packs.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7404477385663634297'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7404477385663634297'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/07/defacement-by-exploit-packs.html' title='Defacement by &quot;Exploit Pack&apos;s&quot;'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TEEeeG-P2MI/AAAAAAAAAPk/_FbRZpU4RxA/s72-c/MI_Eleonore.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-9159979788699774666</id><published>2010-07-11T15:55:00.004-07:00</published><updated>2010-07-16T20:33:45.821-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><title type='text'>YES Exploit System and Crimeware-as-a-Service</title><summary type='text'>In recent years the phenomenon Cloud Computing has become a real turning point as far as information security is concerned, the main focus of controversy does not pass both protection mechanisms that can reach their architectures implemented on but more round about the lack of trust still exists on who should take the decisions necessary to implement this style services.
However, undoubtedly, for</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/9159979788699774666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/07/yes-exploit-system-and-crimeware-as.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/9159979788699774666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/9159979788699774666'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/07/yes-exploit-system-and-crimeware-as.html' title='YES Exploit System and Crimeware-as-a-Service'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TDpEw_oLaGI/AAAAAAAAAPE/V8vMCvVKwGU/s72-c/MI_YES30-00.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-5210828155496489829</id><published>2010-07-04T08:13:00.002-07:00</published><updated>2010-07-04T15:48:31.312-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>PayPal phishing campaign by "Newbie Hacker Community"</title><summary type='text'>Phishing attacks are increasingly common and are no longer confined as in the beginning to use as cover only banks, and any service offered over the Internet and requires username and password, sooner or later will be grounds target for criminals.

PayPal isn't a new service and was one of the first to offer e-commerce services, whose image is one of the most commonly used for phishing. Starting </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/5210828155496489829/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/07/paypal-phishing-campaign-by-newbie.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5210828155496489829'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5210828155496489829'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/07/paypal-phishing-campaign-by-newbie.html' title='PayPal phishing campaign by &quot;Newbie Hacker Community&quot;'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TDCh8eerWnI/AAAAAAAAAOk/LqEkUc0lnj4/s72-c/phishiing-pp.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-839160729990925180</id><published>2010-07-03T19:17:00.000-07:00</published><updated>2010-07-03T19:17:35.903-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>BOMBA Botnet. New alternative crimeware fuel the economy criminal</title><summary type='text'>In a recent survey, Francisco Ruiz, Crimeware Researcher of MalwareIntelligence, broke through the security barriers of a new recruit crimeware designed to automate the running zombies and mass and scale of cyber crimes that are carried out using a vector of attack committed teams as part of the botnet.

These BOMBA, which is accessed via web and which authentication system is based only on the </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/839160729990925180/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/07/bomba-botnet-new-alternative-crimeware.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/839160729990925180'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/839160729990925180'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/07/bomba-botnet-new-alternative-crimeware.html' title='BOMBA Botnet. New alternative crimeware fuel the economy criminal'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/TC_qcZnr_5I/AAAAAAAAAOE/ECnv-4yPiAA/s72-c/MI_bombastats.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-6277530718313210879</id><published>2010-06-29T21:32:00.000-07:00</published><updated>2010-06-29T21:32:14.583-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>n0ise Bot. Crimeware particular purpose for DDoS attacks</title><summary type='text'>DDoS attacks are not a trivial problem, and various web applications in this style, such as BlackEnergy have been used to run campaigns of massive attacks, in the case of BE during the conflict between Russia and Georgia.

The impact of such threats is extremely critical, and under this flag in the circuit enters the business that is channeled through crimeware, a web application called n0ise Bot</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/6277530718313210879/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/06/n0ise-bot-crimeware-particular-purpose.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/6277530718313210879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/6277530718313210879'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/06/n0ise-bot-crimeware-particular-purpose.html' title='n0ise Bot. Crimeware particular purpose for DDoS attacks'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TCrCqWAllfI/AAAAAAAAANc/fq2akAi2opc/s72-c/MI-n0ise.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-9007518291956952838</id><published>2010-06-26T16:07:00.001-07:00</published><updated>2010-07-03T19:18:33.507-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><title type='text'>Brief review of Passenger Admin Panel</title><summary type='text'>If you 5/6 years ago we were talking about control and centralized management of botnets (C&amp;C) via http, when the massive operating botnets through IRC channels, it was seen as a trend.

After the first appearance of the odd kit, demand began to be high but the supply was poor. However, despite having spent several years, today continue to set trends in crimeware and demand remains high but with </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/9007518291956952838/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/06/brief-review-of-passenger-admin-panel.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/9007518291956952838'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/9007518291956952838'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/06/brief-review-of-passenger-admin-panel.html' title='Brief review of Passenger Admin Panel'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TCaDdDjakhI/AAAAAAAAAM0/HR6sdftDZQw/s72-c/MI-PassengerAP.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-795584869069368895</id><published>2010-06-23T20:27:00.000-07:00</published><updated>2010-06-23T20:27:07.799-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><title type='text'>State of the art in Eleonore Exploit Pack II</title><summary type='text'>Undoubtedly the crimeware rate exploit pack and malware kit, whether these general purpose, such as ZeuS or as RussKill particular purpose, have become the creme de la creme of computer crime and synonymous with the easy for cybercriminals.

Based on this, one of the fastest growing crimeware over the past six months is Eleonore Exploit Pack. He is currently on the lips of many would-be cyber </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/795584869069368895/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/06/state-of-art-in-eleonore-exploit-pack.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/795584869069368895'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/795584869069368895'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/06/state-of-art-in-eleonore-exploit-pack.html' title='State of the art in Eleonore Exploit Pack II'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/TCLHyIoHe5I/AAAAAAAAAMM/P2VkDfYL428/s72-c/MI-os.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-471862525237735312</id><published>2010-05-28T09:32:00.004-07:00</published><updated>2011-04-13T10:44:28.309-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><title type='text'>Intelligence and operational level by Siberia Exploit Pack</title><summary type='text'>Siberia Exploit Pack is a crimeware, evolution of Napoleon Exploit Pack, which we've done a brief description on another occasion. However, since the time of that description to this day, the landscape has expanded its developer.
 
In this regard, and while it ends up being one of the bunch, the interesting thing about this crimeware is information provided by their panel of statistics (</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/471862525237735312/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/05/intelligence-and-operational-level-by.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/471862525237735312'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/471862525237735312'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/05/intelligence-and-operational-level-by.html' title='Intelligence and operational level by Siberia Exploit Pack'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S__mGz5qZDI/AAAAAAAAAK0/1F69wQz0Ats/s72-c/MI-siberia-exp-pack.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2525886511829444306</id><published>2010-05-24T08:46:00.003-07:00</published><updated>2010-05-24T08:48:12.056-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>BlackHat SEO Campaign for the thirtieth anniversary of PAC-MAN</title><summary type='text'>Recently, the legendary video game PAC-MAN has completed 30 years of existence and Google has launched a campaign in his honor by placing a banner that allows even play.

However, Google not only benefits from this but also cyber-criminals, who saw in this campaign a new opportunity to attack and have launched another campaign, but the spread of malware through BlackHat SEO (also called SEO </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2525886511829444306/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/05/blackhat-seo-campaign-for-thirtieth.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2525886511829444306'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2525886511829444306'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/05/blackhat-seo-campaign-for-thirtieth.html' title='BlackHat SEO Campaign for the thirtieth anniversary of PAC-MAN'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/S_qb1n9f9yI/AAAAAAAAAKc/ndv81YChe_A/s72-c/MI_bhseo-pac-man.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-3458237604089643280</id><published>2010-05-19T08:10:00.002-07:00</published><updated>2010-05-19T19:47:07.533-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><title type='text'>State of the art in CRiMEPACK Exploit Pack</title><summary type='text'>CRiMEPACK exploit pack is a widespread and accepted in the crime scene in this area came under the slogan "Highest Lowest rates for the price".

He is currently In-the-Wild 3.0 version is being developed as alpha (the first of this version). That's, is in the middle stage of evaluation, perhaps in the next few days will go on sale in underground forums, at which time it will know your actual cost</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/3458237604089643280/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/05/state-of-art-in-crimepack-exploit-pack.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3458237604089643280'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3458237604089643280'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/05/state-of-art-in-crimepack-exploit-pack.html' title='State of the art in CRiMEPACK Exploit Pack'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S_PpDL6GGGI/AAAAAAAAAKE/QnpEw_nvPXM/s72-c/MI-crimepack.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-9066510330033866699</id><published>2010-05-04T17:13:00.001-07:00</published><updated>2010-05-04T17:24:38.723-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>A recent tour of scareware XXII</title><summary type='text'>A-Fasta Antivirus91.188.59.112a-fast.com         Latvia        Riga        Sagade LtdAS6851 - BKCNET "SIA" IZZI12/40 (30.00%)79.135.152.155sys-defender.comantispyware-system.com                                     Latvia                    Colocation HostingAS2588 - LATNETSERVISS-AS LATNET </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/9066510330033866699/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/05/recent-tour-of-scareware-xxii.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/9066510330033866699'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/9066510330033866699'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/05/recent-tour-of-scareware-xxii.html' title='A recent tour of scareware XXII'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/S-AJBHHoxvI/AAAAAAAACU0/d-O2m1r8EZA/s72-c/afasta.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2239324166597193469</id><published>2010-05-03T07:32:00.000-07:00</published><updated>2010-05-03T07:32:22.594-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Campaign phishing to Claro Argentina</title><summary type='text'>Currently running a major phishing campaign aimed at users in Argentina who use the services of the mobile phone company Claro. The following image is a screenshot of the attack:


The strategy is the user trying to deposit the information in your credit card in the fraudulent when you want to buy credits on your cell phone.

When the user falls into the trap and supposedly when processing the </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2239324166597193469/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/05/campaign-phishing-to-claro-argentina.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2239324166597193469'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2239324166597193469'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/05/campaign-phishing-to-claro-argentina.html' title='Campaign phishing to Claro Argentina'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S97QLHOwLSI/AAAAAAAAAJc/mtTlTNtbQzA/s72-c/claro1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1649370838412407790</id><published>2010-04-30T19:38:00.001-07:00</published><updated>2010-04-30T19:40:01.669-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>A recent tour of scareware XXI</title><summary type='text'>Desktop Security 2010204.12.223.187           United States          Kansas City          Krutik Serversdesktopsecurity2010win.comcertifiedsecureprocessingpayments.comns1.startsecureplace.comns2.startsecureplace.comstartsecureplace.com91.121.45.67         France                Ovh Sasglobal-d-security.comlevel1-antivirus.commax6antispyware.commega1-scanner.commega2-scanner.commega6-</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1649370838412407790/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/04/recent-tour-of-scareware-xxi.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1649370838412407790'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1649370838412407790'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/04/recent-tour-of-scareware-xxi.html' title='A recent tour of scareware XXI'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/S9ZNeGQxsZI/AAAAAAAACUk/WarjmauPywI/s72-c/desktop-security-img.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1862532869285937521</id><published>2010-04-26T14:05:00.001-07:00</published><updated>2010-08-14T10:03:54.879-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Phishing database VI</title><summary type='text'>Financial and banking institutions
HSBC
http://www.publimovilradio.com/modules/IBlogin.html
http://favre-4.fr/xd881/index2.html?hsbc.co.uk/1/2/HSBCINTEGRATION/CAM10;jsessionid=0000GE8AijuUV604QIMQn-iQJDM:11j74lld0?IDV_URL=hsbc.MyHSBC_pib
http://66.179.18.171/lib/support/templates/CVS/1/Login/2/User/ID/HSBC/SessionID/Submit/IBlogin.html

http://mangiaonthird.com/ww/xx/CAM10.php?idv_cmd=idv.Logoff&amp;</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1862532869285937521/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/04/phishing-database-vi.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1862532869285937521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1862532869285937521'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/04/phishing-database-vi.html' title='Phishing database VI'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S9X-GXKUVAI/AAAAAAAAAJE/AaZeNaGiB_U/s72-c/usaa.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1500988325109161231</id><published>2010-04-19T01:30:00.002-07:00</published><updated>2010-04-19T18:02:32.379-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>ZeuS on IRS Scam remains actively exploited</title><summary type='text'>Updated 19.04.2010A new wave of domain scam employed by the IRS ZeuS ahead. So far we have detected only a few, but we believe that in the coming hours will begin to appear much more in the crime scene of this old strategy used by ZeuS.The domains, as usual, have the following structure:irs.gov.rewsserr.eu/fraud.applications/application/statement.phpFrom where you try to download the binary ZeuS </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1500988325109161231/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/02/zeus-on-irs-scam-remains-actively.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1500988325109161231'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1500988325109161231'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/02/zeus-on-irs-scam-remains-actively.html' title='ZeuS on IRS Scam remains actively exploited'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/S7QWyUtLCAI/AAAAAAAACS8/hqytpYmLCvY/s72-c/irs.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1926920033482496310</id><published>2010-04-18T14:10:00.002-07:00</published><updated>2010-04-18T14:53:00.027-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><title type='text'>ad_1_.jpg. More about Aurora Attack</title><summary type='text'>In this post we'll try to run Aurora as non-administrative user, and debug ad_1_.jpg which used by the attackers right after the attack.
Well, I was very curious about other files in the attack, after not able to unpack the msconfig32.sys, and thought, maybe other files will give me clues on msconfig32.sys and might give me a way of unpacking it.
I've looked into USCERT advisory regarding the </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1926920033482496310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/04/ad1jpg-more-about-aurora-attack.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1926920033482496310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1926920033482496310'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/04/ad1jpg-more-about-aurora-attack.html' title='ad_1_.jpg. More about Aurora Attack'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Kde3g35OnUQ/S8njxstzsJI/AAAAAAAAAGo/LRI04scXMPE/s72-c/Screen+shot+2010-04-17+at+7.32.21+PM.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1493492875595119866</id><published>2010-04-03T10:47:00.004-07:00</published><updated>2010-04-04T04:37:24.183-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Phishing Database V</title><summary type='text'>Financial and banking institutionsHSBC (http://www.hsbc.com)http://www.ellerencontre.com//forum/add/verify/HSBCINTEGRATIONCAM10jsessionid=00001DwpIt0wIyX1arHd6K8mQB6URL=hsbc.MyHSBCpib/hsbc/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo:11j71fovq?IDV_URL=hsbc.MyHSBC_pibhttp://www.mygrowshop.com/GiantSolutions/includes/hsbc.co.uk/HSBCINTEGRATIONCAM10;js/Register%20forInternetBanking/</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1493492875595119866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/04/phishing-database-v.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1493492875595119866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1493492875595119866'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/04/phishing-database-v.html' title='Phishing Database V'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/S7dlY52AaLI/AAAAAAAACTk/tfcn2wL1Y2Y/s72-c/hsbc.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-6498414258959487050</id><published>2010-04-02T23:26:00.002-07:00</published><updated>2010-04-02T23:32:47.548-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Besouro film website violated, PayPal phishing attacks</title><summary type='text'>The website of the Brazilian film tells the story of capoeirista Besouro, very good by the way :-), has been violated and contains a clone of the PayPal website.Previously we mentioned that the website Hooters Germany had been the victim of a similar attack.In this case, as we see, the site has set up a blog on WordPress and this is perhaps the weak point through which managed to upload illegal </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/6498414258959487050/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/04/besouro-film-website-violated-paypal.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/6498414258959487050'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/6498414258959487050'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/04/besouro-film-website-violated-paypal.html' title='Besouro film website violated, PayPal phishing attacks'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/S7behVnQ6TI/AAAAAAAACTU/_Q5P4Eg-0AE/s72-c/besouro.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-6218396428045131725</id><published>2010-03-30T20:00:00.002-07:00</published><updated>2010-03-30T20:09:24.512-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Strike Botnet, another crimeware was born</title><summary type='text'>As the Author says "Strike botnet is a new advanced http based botnet with which you can literally control thousands of computers at the same time, without them even noticing."The gradual increment in botnet developing is intresting, and this time "SqUeEzEr" (Scott Van Dinter, a Young boy of 18 years old, as some of his online profiles say) comes into the scene with a botnet developed in VB6, </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/6218396428045131725/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/03/strike-botnet-another-crimeware-was.html#comment-form' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/6218396428045131725'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/6218396428045131725'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/03/strike-botnet-another-crimeware-was.html' title='Strike Botnet, another crimeware was born'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/S7K5GsX6MII/AAAAAAAACSs/Zq8kD8AFMPc/s72-c/strike.png' height='72' width='72'/><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-734197187658831522</id><published>2010-03-28T19:14:00.002-07:00</published><updated>2010-03-28T19:28:56.636-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Web Hooters Germany committed to phishing HSBC</title><summary type='text'>Hooters is a restaurant chain that has branches in a number of countries. At Wikipedia you can read more about what these particular food outlets, who granted one knows what I mean, and who has not had the opportunity to visit a hooters ... don't know what is lost ***comments in parentheses * *** :-)The point is that the website of hooters Germany was committed to a phishing attack against the </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/734197187658831522/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/03/web-hooters-germany-committed-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/734197187658831522'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/734197187658831522'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/03/web-hooters-germany-committed-to.html' title='Web Hooters Germany committed to phishing HSBC'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/S7AKCBe1f2I/AAAAAAAACSE/v9RvwRs0XYg/s72-c/wow-hooters.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1076481458021246380</id><published>2010-03-28T05:56:00.000-07:00</published><updated>2010-03-28T05:56:00.166-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>iPack y GOLOD. New on the scene crimeware criminal</title><summary type='text'>The supply and demand in terms of alternatives crimeware continues to grow, and in recent months some alternatives have emerged, including iPack and GOLOD.GOLOD charger is a resident (resident loader) written in C ++ and of Russian origin who tries to insert into the crime scene at a cost of USD 500 for their implementation in the domain of the buyer, plus USD 675 in case of acquisition with a </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1076481458021246380/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/03/ipack-y-golod-new-on-scene-crimeware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1076481458021246380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1076481458021246380'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/03/ipack-y-golod-new-on-scene-crimeware.html' title='iPack y GOLOD. New on the scene crimeware criminal'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/S66ns1MpMfI/AAAAAAAACRs/PdXTe4oJloY/s72-c/gl1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-691506720274065042</id><published>2010-03-27T07:01:00.001-07:00</published><updated>2010-03-27T07:05:05.279-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Phishing Database IV</title><summary type='text'>Economically-financial and banking institutionsHSBC (http://www.hsbc.com)http://210.116.103.118/~kardex/gnuboard4/bbs//hsbc/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo:11j71fovq?IDV_URL=hsbc.MyHSBC_pibhttp://www.restoretherepublic.com/wp-content/bank/images/online.htmlhttp://72.16.130.62/.www.HSBC.co.uk/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo:11j71fovq?</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/691506720274065042/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/03/phishing-database-iv.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/691506720274065042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/691506720274065042'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/03/phishing-database-iv.html' title='Phishing Database IV'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/S64Ehv2N3FI/AAAAAAAACRk/BK4kSugqkB8/s72-c/lloyds-bank.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1032879617630208803</id><published>2010-03-19T10:36:00.008-07:00</published><updated>2010-03-19T11:29:03.779-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><title type='text'>Aurora .sys file used in the attack - External file analysis</title><summary type='text'>First of all, I'd like to thank MalwareIntelligence where I write as a researcher for getting me this precious file.

In the Aurura attack, 1 .sys file had been used, called : msconfig32.sys.

I was pretty curious about what does this driver do, and why no one else in the world had analyzed it.

It had been a terrible journey to get the file. No one had it. No one wanted to share it. I was pretty</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1032879617630208803/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/03/msconfig32sys-in-scene-aurora-attack.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1032879617630208803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1032879617630208803'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/03/msconfig32sys-in-scene-aurora-attack.html' title='Aurora .sys file used in the attack - External file analysis'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Kde3g35OnUQ/S6OaqDwGm5I/AAAAAAAAAF4/WisoQw6W8Wg/s72-c/Screen+shot+2010-03-03+at+10.21.20+PM.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-3433263046312654144</id><published>2010-03-15T23:12:00.001-07:00</published><updated>2010-03-15T19:18:52.839-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>New phishing campaign against Facebook led by Zeus</title><summary type='text'>Updated 15.03.2010New domains have been released and has multi-stage attack whereby you chain multiple websites with malicious content.The last download a binary called update.exe (19d9cc4d9d512e60f61746ef4c741f09) which is a variant of the trojan ZeuS, which has a high detection rate.The sequence is as follows:Original 14.03.2010At this point the "circus", no doubt, as I always say, that ZeuS is</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/3433263046312654144/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/03/new-phishing-campaign-against-facebook.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3433263046312654144'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3433263046312654144'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/03/new-phishing-campaign-against-facebook.html' title='New phishing campaign against Facebook led by Zeus'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/S57n6bCTY7I/AAAAAAAACQs/tno9u8i_Rzg/s72-c/page-php.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-8230306025563382077</id><published>2010-03-12T19:44:00.001-07:00</published><updated>2010-03-12T19:45:03.152-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Phishing campaign aimed at players Zynga</title><summary type='text'>Zynga is a virtual game developer that has a wide repertoire of games in flash, allowing fun with them even through some social networks like Facebook, MySpace and Tagged, among others.

Recently Zynga image is being used as a phishing campaign animation using as cover some of the games that the company offers.
The domains involved in the campaign are:

claimpokerbonus.t35.com/zynga_poker/
</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/8230306025563382077/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/03/campana-de-phishing-orientada-jugadores.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8230306025563382077'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8230306025563382077'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/03/campana-de-phishing-orientada-jugadores.html' title='Phishing campaign aimed at players Zynga'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S5r2IH8O5XI/AAAAAAAAAHQ/wCoS3e0Pa5s/s72-c/fake-zynga.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-8329609103790432757</id><published>2010-03-07T13:48:00.003-07:00</published><updated>2010-03-07T13:58:07.030-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><title type='text'>Oficla botnet with more than 200,000 zombies recruits</title><summary type='text'>In a recent investigation, we discovered a Oficla botnet, also known as Sasfis in nomenclature of some antivirus companies, with a significant amount of zombies recruited in 48 countries, demonstrating the connotation scale represents the same on stage crimeware.The base command and control (C&amp;C) of this botnet Oficla is maintained through crimeware myLoader (costing in the underground market is </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/8329609103790432757/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/03/oficla-botnet-with-more-than-200000.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8329609103790432757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8329609103790432757'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/03/oficla-botnet-with-more-than-200000.html' title='Oficla botnet with more than 200,000 zombies recruits'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/S5Mcy5ivnkI/AAAAAAAACQU/FBmFBSBQgZQ/s72-c/mi_oficla-botnet-1.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-3555327548736455590</id><published>2010-03-06T19:37:00.003-07:00</published><updated>2010-03-06T19:42:16.430-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><title type='text'>myLoader. Framework for the management of botnets</title><summary type='text'>myLoader is another alternative with which cyber criminals have for the management and administration of botnets. Its lifetime is about one semester, but most activity is being managed in the last month of the first quarter of 2010.It has a minimalist interface but with gathering data that is returned in an orderly manner through intuitive graphical whereby we obtain the state of the controlled </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/3555327548736455590/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/03/myloader-framework-for-management-of.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3555327548736455590'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3555327548736455590'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/03/myloader-framework-for-management-of.html' title='myLoader. Framework for the management of botnets'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/S5MQY0yFt_I/AAAAAAAACQM/WQBCiCXwm1M/s72-c/mi-myloader-stats.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1452372741696758721</id><published>2010-02-28T14:42:00.005-07:00</published><updated>2010-03-01T20:51:23.725-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Phishing database III</title><summary type='text'>Financial &amp; Banking Institutions 
Canada Trusth (http://www.tdcanadatrust.com/)
http://www-tdcanadatrust-com.epage.ru/td-bank-index.html
Citigroup (http://www.citigroup.com)
http://www.alanmetauro.com/home/online.citibank.com/US/JPS/portal/Index.do.htm?F6=1&amp;F7=IB&amp;F21=IB&amp;F22=IB&amp;REQUEST=ClientSignin&amp;LANGUAGE=ENGLISH
CUA - Credit Union Australia (http://www.cua.com.au)
http://www.colconkproducts.com</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1452372741696758721/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/02/financial-banking-institutions-canada.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1452372741696758721'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1452372741696758721'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/02/financial-banking-institutions-canada.html' title='Phishing database III'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/S4rhk_n0vsI/AAAAAAAACOs/RwEAwDowfHI/s72-c/phpshell.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2396957180432118168</id><published>2010-02-23T20:23:00.004-07:00</published><updated>2010-03-01T20:52:59.767-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>New ZeuS phishing campaign against Google and Blogger</title><summary type='text'>A new strategy proposed by ZeuS phishing active. Previously we mentioned that the trusted entities used as part of the plan of Zeus infection and fraud involving the IRS, VISA and Facebook.

Coverage now focuses its efforts on using the name of Google and Blogger. Some of the domains used are:

http://www.google.com/update/VE.php?service=blogger

http://www.google.com/update/VE.php --&gt; annieliu@</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2396957180432118168/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/02/new-zeus-phishing-campaign-against.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2396957180432118168'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2396957180432118168'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/02/new-zeus-phishing-campaign-against.html' title='New ZeuS phishing campaign against Google and Blogger'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-750635490891227653</id><published>2010-02-20T16:18:00.005-07:00</published><updated>2010-03-01T20:53:23.570-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Facebook &amp; VISA phishing campaign proposed by ZeuS</title><summary type='text'>Updated 21.02.2010
More active domains belonging to the same phishing campaign against users of VISA. The domains are:

reports.cforms.visa.com.desz.kr/secureapps/vdir/cholderform.php
reports.cforms.visa.com.desz.ne.kr/secureapps/vdir/cholderform.php
reports.cforms.visa.com.desz.or.kr/secureapps/vdir/cholderform.php
reports.cforms.visa.com.ersm.kr/secureapps/vdir/cholderform.php
</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/750635490891227653/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/02/facebook-phishing-campaign-proposed-by.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/750635490891227653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/750635490891227653'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/02/facebook-phishing-campaign-proposed-by.html' title='Facebook &amp; VISA phishing campaign proposed by ZeuS'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/S4Bsw43GDmI/AAAAAAAACN8/rkI6zUTDE6k/s72-c/zeus-facebook-phish.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-7256124474480747888</id><published>2010-02-19T12:01:00.003-07:00</published><updated>2010-03-01T20:57:11.123-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>SpyEye Bot (Part two). Conversations with the creator of crimeware</title><summary type='text'>In recent weeks, SpyEye (a new financial trojan) has been the talk of many for the positive acceptance was so in the underground scene due to its balance about cost/benefit, and the great impact that achievement to whiten the features in its latest version that allows systems to eliminate the activities of your competition: ZeuS.

Our previous report, “SpyEye. Analysis of a new crimeware </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/7256124474480747888/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/02/spyeye-bot-part-two-conversations-with.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7256124474480747888'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7256124474480747888'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/02/spyeye-bot-part-two-conversations-with.html' title='SpyEye Bot (Part two). Conversations with the creator of crimeware'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Mcy4oUq8gAQ/S37ftXI_oHI/AAAAAAAAAGI/jbfn6Wm2etw/s72-c/spyeye_2.gif' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-5410311833999462735</id><published>2010-02-16T06:00:00.003-07:00</published><updated>2010-03-01T20:54:41.878-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Phishing database II</title><summary type='text'>HSBC
http://www.silverstoneincense.com.au/IBlogin.html
http://www.buyitdirect.co.nz/images/indexx/hsbc/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo:11j71fovq?IDV_URL=hsbc.MyHSBC_pib
http://delthelboi.net/COsutmer/COsutmer/hsbc/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo:11j71fovq?IDV_URL=hsbc.MyHSBC_pib
http://woorizip1004.net/zboard/icon/IBlogin.html
http://</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/5410311833999462735/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/02/phishing-database-ii.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5410311833999462735'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5410311833999462735'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/02/phishing-database-ii.html' title='Phishing database II'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S3VkswawSdI/AAAAAAAAAFg/ly38WLlim8E/s72-c/mi-phish-mc.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-5548424682621307213</id><published>2010-02-13T13:01:00.009-07:00</published><updated>2010-03-01T20:55:15.058-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><title type='text'>Social Engineering exploiting Olympics Games 2010</title><summary type='text'>As usual, the social engineering techniques are a fundamental pattern for attacks of any kind and magnitude.

From this perspective, any news in a few minutes covering the media more important globally, or any event whose importance is known to people from all over the world, is an object in power to exploit his image with fraudulently the intention of spreading malware.

The Olympic Games 2010 </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/5548424682621307213/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/02/social-engineering-exploiting-olympics.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5548424682621307213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5548424682621307213'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/02/social-engineering-exploiting-olympics.html' title='Social Engineering exploiting Olympics Games 2010'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/S3cFbxAE4vI/AAAAAAAACM0/Shp8P6DzpM0/s72-c/mi-is-olimpicgame-real.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-598903360565044770</id><published>2010-02-12T15:32:00.003-07:00</published><updated>2010-03-01T20:55:31.014-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Dissection of a fraudulent package. Wachovia phishing attack</title><summary type='text'>In one of our most recent posts have published a series of links to phishing pages against various entities. Today we will analyze one of them, an attack aimed at Wachovia bank customers.

To this end, we got the full kit and have begun to analyze the files contained in it. Basically there are a few files PHP, HTML, various images and three style sheets.

If we look at one of the php files: </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/598903360565044770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/02/dissection-of-fraudulent-package.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/598903360565044770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/598903360565044770'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/02/dissection-of-fraudulent-package.html' title='Dissection of a fraudulent package. Wachovia phishing attack'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/S3XSH0KSPMI/AAAAAAAACLs/IrTjTM7LWNI/s72-c/wachovia_1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1037372482016100301</id><published>2010-02-10T15:07:00.006-07:00</published><updated>2010-03-01T20:57:24.572-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>SpyEye Bot. Analysis of a new alternative scenario crimeware</title><summary type='text'>Earlier this year saw the light in the underground black market that moves the axes of crimeware, a new application designed to provide feedback for criminal and fraudulent business.

This application, called SpyEye, is aimed at facilitating the recruitment of zombies and managing your network (C&amp;C - Command and Control) through management panel via the web, from which it is possible to process </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1037372482016100301/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/02/spyeye-bot-analysis-of-new-alternative.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1037372482016100301'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1037372482016100301'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/02/spyeye-bot-analysis-of-new-alternative.html' title='SpyEye Bot. Analysis of a new alternative scenario crimeware'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/S3MuzV7hiQI/AAAAAAAACLk/5SIolmgUCQo/s72-c/mi-paper-se-en.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-257348680830460645</id><published>2010-02-08T22:19:00.003-07:00</published><updated>2010-03-01T20:56:19.619-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Phishing database I</title><summary type='text'>Phishing responds to a purely criminal activity, part of the circuit that drives the illegal business of crimeware, designed to steal money using the sensitive and private information from users that criminals obtained through non-sacred activities.

Therefore, as a preventive measure, it's important not to allow access to the domains that host usually banks cloned pages, webmail and any other </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/257348680830460645/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/02/phishing-database-i.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/257348680830460645'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/257348680830460645'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/02/phishing-database-i.html' title='Phishing database I'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/S3Ds39iU0EI/AAAAAAAACLE/JazsHYxiwYg/s72-c/mi-phish-paypal.png' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-4112858172088581387</id><published>2010-02-05T23:21:00.002-07:00</published><updated>2010-03-01T20:56:52.899-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><title type='text'>New personal blog</title><summary type='text'>Jorge Mieres Blog
Research on security, crimeware, botnets, intelligence and criminal activity involving any programs and/or harmful actions.

http://jorgemieresblog.blogspot.com

</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/4112858172088581387/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/02/new-personal-blog.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/4112858172088581387'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/4112858172088581387'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/02/new-personal-blog.html' title='New personal blog'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/S20J3sjgaoI/AAAAAAAACK8/QiKdSWydVf0/s72-c/jmieres-blog.png' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1833909121596440245</id><published>2010-01-28T10:48:00.004-07:00</published><updated>2010-03-01T20:58:13.124-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><title type='text'>Automation in creating exploits II</title><summary type='text'>The exploitation of vulnerability now represents one of the highest infection strategies used in the stage of crimeware and exploits while allowing exploit weaknesses aren't a new concept, the fact is that more and more notorious actions.

In fact now continue to be exploited, especially through exploits pack, a large number of vulnerabilities that many have been settled more than two years ago.
</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1833909121596440245/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/automation-in-creating-exploits-ii.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1833909121596440245'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1833909121596440245'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/automation-in-creating-exploits-ii.html' title='Automation in creating exploits II'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/S2CYw6jUznI/AAAAAAAACKs/IfgIhyZ33v8/s72-c/malware-intelligence_ie-0day-exploit.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2340270855471617410</id><published>2010-01-28T04:00:00.001-07:00</published><updated>2010-03-01T20:59:11.128-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Zeus and the theft of sensitive information</title><summary type='text'>In light of all the recent financal trojans here are two examples of what ZeuS-bots have modules for. These modules are recording form info and keystrokes from user' logging into Bank of America and Paypal. Both of these screenshots are examples of the capabilities of the newer ZeuS-bots out there.

This and keylogging opens the bank vault for these organized groups operating around the world. </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2340270855471617410/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/zeus-and-theft-of-sensitive-information.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2340270855471617410'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2340270855471617410'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/zeus-and-theft-of-sensitive-information.html' title='Zeus and the theft of sensitive information'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/S1-gJoQhGVI/AAAAAAAACKc/sXztqQoJq30/s72-c/malware-intelligence_zeusbank.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2406266892818990145</id><published>2010-01-27T05:46:00.001-07:00</published><updated>2010-03-01T20:59:34.200-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>SpyEye. New bot on the market</title><summary type='text'>SpyEye, a bot which first’s release was on January’s 2 of this year, is a "fresh" malware of interesting features, which has a considerable fast development, being on its 1.0.65 version at the moment.

It was written almost in its entirety on C++, and the binary file has a size of 60kb approximately.
It works from Windows 2000 to Windows 7, and it runs on ring3 (something that possibly makes it </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2406266892818990145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/spyeye-new-bot-on-market.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2406266892818990145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2406266892818990145'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/spyeye-new-bot-on-market.html' title='SpyEye. New bot on the market'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/S1-Nl11PlGI/AAAAAAAACKU/f_7fSjv6-BU/s72-c/malware-intelligence_spyeye6.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1756900106275606024</id><published>2010-01-25T12:49:00.005-07:00</published><updated>2010-03-01T20:59:57.543-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Leveraging ZeuS to send spam through social networks</title><summary type='text'>We were able to analyze a pack to make zombies of ZeuS at spammers through social networks. Specifically, the module is analyzed developed for use in Vkontakte.ru, the Russian clone of Facebook.

This crimeware has been created by someone calling himself Deex of Freedomscripts Team and sold for the modest price of USD 100 (via WebMoney).The pack includes several configuration files, which make it</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1756900106275606024/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/leveraging-zeus-to-send-spam-through.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1756900106275606024'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1756900106275606024'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/leveraging-zeus-to-send-spam-through.html' title='Leveraging ZeuS to send spam through social networks'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/S1nLM7YqalI/AAAAAAAACI0/XQv0cfnvkXU/s72-c/malware-intelligence-vk-1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2361470206014319097</id><published>2010-01-18T06:07:00.003-07:00</published><updated>2010-03-01T21:00:15.406-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Justifying the unjustifiable in a world criminal</title><summary type='text'>As many readers know, since we have been researching Malware Intelligence direct implications of all this new generation of malicious code and criminal activity that daily feed back the business of crimeware.

Under this premise, the researchers focused their efforts on trying to reveal the different branches that are entangled with each other in a tangle of illegal actions aimed mainly to get </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2361470206014319097/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/justifying-unjustifiable-in-world.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2361470206014319097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2361470206014319097'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/justifying-unjustifiable-in-world.html' title='Justifying the unjustifiable in a world criminal'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/S1JbBSJUa5I/AAAAAAAACIk/StMlWMZnIMk/s72-c/malware-intelligence_klesk.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-6174459841584217096</id><published>2010-01-16T17:53:00.004-07:00</published><updated>2010-03-01T21:00:34.874-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>YES Exploit System. Official Business Partner’s</title><summary type='text'>Undoubtedly, the business that is currently crimeware expands every day. Not only this aspect is reflected in the professionalization on the development and operation of various computer applications and technologies used to commit crimes and attacks via web, but also on sales strategies that are used to channel the attention of a greater volume of restless minds, who collect stealing money from </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/6174459841584217096/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/yes-exploit-system-official-business.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/6174459841584217096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/6174459841584217096'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/yes-exploit-system-official-business.html' title='YES Exploit System. Official Business Partner’s'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/S1IBlwV5HKI/AAAAAAAACIM/SkGEjf29Amw/s72-c/malware-intelligence-upack.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-3878607400068140628</id><published>2010-01-09T08:02:00.004-07:00</published><updated>2010-03-01T21:02:08.247-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Napoleon Sploit. Frameware Exploit Pack</title><summary type='text'>This is the first release of an exploit pack to monitor a particular purpose botnets alled Napoleon Sploit, which launched the underground market crimeware in August 2009.

Due to his premature and low status of "complex Exploit Pack" when compared with others of its style, is low cost and in fact had no impact on the underground circuit sales, although it's still for sale at a cost USD 299 can </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/3878607400068140628/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/napoleon-sploit-frameware-exploit-pack.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3878607400068140628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3878607400068140628'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/napoleon-sploit-frameware-exploit-pack.html' title='Napoleon Sploit. Frameware Exploit Pack'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/S0iWkT_iBkI/AAAAAAAACH0/NIUkhFrNeaM/s72-c/login.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-8570029324438671618</id><published>2010-01-09T07:58:00.003-07:00</published><updated>2010-03-01T21:02:29.140-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><title type='text'>A recent tour of scareware XX</title><summary type='text'>Anti-Virus Live 2010 = Anti-Virus Elite 2010, ErrorClean y NoAdware
MD5: c50dc619e13345dec2444b0de371dfd4
IP: 204.232.131.12
204.232.131.14
           United States          Hoboken          Noadware.net 
Domains associated
antivirus-live.com
Result: 9/41 (21.95%)

NoMalware
IP: 88.214.204.221 - 72.9.100.114
           United Kingdom                    Hosting Solutions Ltd  
         United </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/8570029324438671618/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/recent-tour-of-scareware-xx.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8570029324438671618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8570029324438671618'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/recent-tour-of-scareware-xx.html' title='A recent tour of scareware XX'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/SzLLpxGJWBI/AAAAAAAACDw/Za3t71Jkv54/s72-c/avl.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-7122850351873187841</id><published>2010-01-05T04:23:00.003-07:00</published><updated>2010-03-01T21:02:51.548-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><title type='text'>Crimeware in 2009</title><summary type='text'>"Crimeware in 2009" presented in one document all that was channeled through this blog during the year in question on crimeware and associated hazards.

There are a total of 262 pages and is divided by the most relevant topics that describe the criminal activities that were a source of news on this blog. Has two indices for getting the news in a simple (content) and another on the images (image </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/7122850351873187841/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/crimeware-in-2009.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7122850351873187841'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7122850351873187841'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/crimeware-in-2009.html' title='Crimeware in 2009'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/S0DCXc5IbvI/AAAAAAAACHU/1OOgYieB9To/s72-c/malwareint-anual-t.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1570217948492368375</id><published>2010-01-04T04:23:00.002-07:00</published><updated>2010-03-01T21:03:07.343-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>State of the art in Eleonore Exploit Pack</title><summary type='text'>Since launching the first version in June 2009, Eleonore Exploit Pack has a major impact in the criminal field, both from the demand to get the Exploit Pack because of its cost competitive compared to similar web applications, as its high rate of activity.

It currently has a repertoire of 6 (six) versions, the last being 1.3.2, recently appeared on the scene underground at a cost of USD 1000.

</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1570217948492368375/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/state-of-art-in-eleonore-exploit-pack.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1570217948492368375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1570217948492368375'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/state-of-art-in-eleonore-exploit-pack.html' title='State of the art in Eleonore Exploit Pack'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/Sz9nGRIJ8hI/AAAAAAAACHA/2oGTIrUyoDk/s72-c/mipistus-eep-login.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-5930687959201596067</id><published>2010-01-03T04:22:00.001-07:00</published><updated>2010-03-01T21:03:24.488-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Crimeware-as-a-Service and antivirus evasion schemes</title><summary type='text'>The business models offered by cloud computing are not new. Even many services currently offered under this banner have a model already established long ago in the market.

However, the Cloud Computing concept in itself that we know today responds to a sharply inclined orientation to generate business leveraging the Internet as infrastructure, which in a highly competitive market enjoys certain </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/5930687959201596067/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/crimeware-as-service-and-antivirus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5930687959201596067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5930687959201596067'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/crimeware-as-service-and-antivirus.html' title='Crimeware-as-a-Service and antivirus evasion schemes'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sz67MpN4BHI/AAAAAAAACGg/J4komJzW0PE/s72-c/mipistus-pyob.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-8371493556795022188</id><published>2010-01-02T04:59:00.002-07:00</published><updated>2010-03-01T21:03:46.666-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><title type='text'>Waledac. Timeline '07-'09</title><summary type='text'>The trojan waledac in charge of recruiting zombies for a botnet dedicated to feed spam, recently returned to give notice as an excuse to use the new year 2010.

However, their fraudulent activities dating from 2007 when he was known under the nomenclature of storm, and since then, this family of malware has taken advantage of social engineering as the main strategy of propagating different </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/8371493556795022188/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/waledac-timeline-07-09.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8371493556795022188'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8371493556795022188'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/waledac-timeline-07-09.html' title='Waledac. Timeline &apos;07-&apos;09'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/Sz6Lf0GQ0bI/AAAAAAAACGY/iqsnJNGgRG4/s72-c/mipistus-storm-waledac-grap-update+%282%29.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-8196876237767817627</id><published>2010-01-01T16:58:00.004-07:00</published><updated>2010-03-01T21:04:08.005-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet research'/><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><title type='text'>Waledac returns with another attack strategy</title><summary type='text'>After a long period of inactivity, the botnet consisting waledac again deploy a strategy of infection using the pattern that characterizes it: Social Engineering, that this time advantage as cover the beginning of the new year.

Latest waledac campaigns dating from the middle of the year when propagation strategy used pretended to be a video on Independence Day in the U.S., hosted on YouTube. In </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/8196876237767817627/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2010/01/waledac-returns-with-another-attack.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8196876237767817627'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8196876237767817627'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2010/01/waledac-returns-with-another-attack.html' title='Waledac returns with another attack strategy'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sz5oq-1T-GI/AAAAAAAACFg/7ku7v9g2yXg/s72-c/waledac2010.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-7285007803815280290</id><published>2009-12-29T17:51:00.003-07:00</published><updated>2010-03-01T21:04:33.478-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit pack research'/><title type='text'>Exploit packs and their relationship with the rogue</title><summary type='text'>Fraudulent activity they related to each other through "associates" of business in which each cell officiates as an intra-organizational structure, complementing a company engaged in such illegal activities.

In this sense, the rogue (also called scareware), has a significant amount of "affiliates" who are responsible for the distribution of malicious code. In fact, a recent study by the FBI </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/7285007803815280290/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/12/exploit-packs-and-their-relationship.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7285007803815280290'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7285007803815280290'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/12/exploit-packs-and-their-relationship.html' title='Exploit packs and their relationship with the rogue'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/SzZIrV9pQVI/AAAAAAAACEo/AJke22eSmcs/s72-c/mipistus-desktop-hijack.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2043511339613473951</id><published>2009-12-27T17:05:00.002-07:00</published><updated>2009-12-27T17:18:51.322-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><category scheme='http://www.blogger.com/atom/ns#' term='scareware'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>Testimonials scareware and credibility strategy</title><summary type='text'>One of the strategies used by the propagators of scareware (rogue) is trying to attract users' confidence through "evidence" allegedly made by people who have already acquired the "solution" and that they express through his "great satisfaction by the same".Yet we know very well that only part of a scam that seeks to complement the overall strategy of propagation/infection, and that if we install</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2043511339613473951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/12/testimonials-scareware-and-credibility.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2043511339613473951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2043511339613473951'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/12/testimonials-scareware-and-credibility.html' title='Testimonials scareware and credibility strategy'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzLwrGNLB8I/AAAAAAAACD4/VuhRe6zW8BY/s72-c/mipistus-scareware-test.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-7723867130188021352</id><published>2009-12-25T19:44:00.004-07:00</published><updated>2009-12-25T19:59:32.714-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Unique Sploit Pack'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='siberia exploit pack'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>Siberia Exploit Pack. Another package of explois In-the-Wild</title><summary type='text'>Siberia Exploit Pack is a new package designed to exploit vulnerabilities and recruit zombies original, as is easy to deduce from its name and as is customary in this area crimeware clandestine business in Russia. It was released almost together with RussKill, a particular purpose botnet also emerging.For now, the sale of Siberia Exploit Pack is closed. The versions that are shared in some </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/7723867130188021352/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/12/siberia-exploit-pack-another-package-of.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7723867130188021352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7723867130188021352'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/12/siberia-exploit-pack-another-package-of.html' title='Siberia Exploit Pack. Another package of explois In-the-Wild'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzV0zxUpWeI/AAAAAAAACEg/7pBSu-oxKjA/s72-c/mipistus-siberia-pack2.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-3163924231567682284</id><published>2009-12-24T12:02:00.003-07:00</published><updated>2009-12-24T12:20:46.815-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><category scheme='http://www.blogger.com/atom/ns#' term='anti-virus live 2010'/><category scheme='http://www.blogger.com/atom/ns#' term='scareware'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>Anti-Virus Live 2010. Talking with the enemy</title><summary type='text'>Generally one has the false belief that malicious code is trivial that any technical problems solved by just formatting the system or acquire any of the known anti-malware market offers today.However, on the one hand, the reality is that behind the development of malware hides a very large business in which every day must be added more "associates". Moreover, what happens when we plan to buy this</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/3163924231567682284/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/12/anti-virus-live-2010-talking-with-enemy.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3163924231567682284'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3163924231567682284'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/12/anti-virus-live-2010-talking-with-enemy.html' title='Anti-Virus Live 2010. Talking with the enemy'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzL83KVzgWI/AAAAAAAACEA/mwOmbKlY1gc/s72-c/mipistus-av-live2010.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-8813015213819653781</id><published>2009-12-23T22:38:00.002-07:00</published><updated>2009-12-23T22:44:44.413-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><category scheme='http://www.blogger.com/atom/ns#' term='scareware'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>A recent tour of scareware XIX</title><summary type='text'>Doctor AlexMD5: 4f2bdddc4b71a428ec2e964cfed9f11aIP: 69.89.20.48           United States          Provo          Bluehost IncDominios asociadosdoctor-alex.comResult: 7/40 (17.50%)Safety Anti-SpywareMD5: 848aea51e9d26089982c9b820c2ea4baIP: 212.117.177.18           Luxembourg          Luxembourg          Root EsolutionsDominios asociadossafetyantispywareshop.comResult: 1/41 (2.44%)Antivirus </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/8813015213819653781/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/12/recent-tour-of-scareware-xix.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8813015213819653781'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8813015213819653781'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/12/recent-tour-of-scareware-xix.html' title='A recent tour of scareware XIX'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/SxneCftIHzI/AAAAAAAAB_w/5h242Hd86RA/s72-c/doctor-alex.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-91815780246853204</id><published>2009-12-15T20:08:00.003-07:00</published><updated>2009-12-17T18:03:25.245-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ddos'/><category scheme='http://www.blogger.com/atom/ns#' term='dos'/><category scheme='http://www.blogger.com/atom/ns#' term='russkill'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='denial of service'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>RussKill. Application to perform denial of service attacks</title><summary type='text'>Conceptually speaking, a DoS attack (Denial of Service attack) is basically bombarded with requests for a service or computer resource to saturate and the system can not process more data, so those resources and services are inaccessible, "denying" the access to anyone who wants them.From the standpoint of computer security, Denial of Service attacks are a major problem because many botnets are </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/91815780246853204/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/12/russkill-application-to-perform-denial.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/91815780246853204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/91815780246853204'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/12/russkill-application-to-perform-denial.html' title='RussKill. Application to perform denial of service attacks'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/SyrUtMf6WJI/AAAAAAAACDo/XN1z0_GBBjU/s72-c/mipistus-russkill-log-mark.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2749799056261160675</id><published>2009-12-09T10:31:00.000-07:00</published><updated>2009-12-09T10:31:00.236-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='zeus'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='elfiesta'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='fragus'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>Fusion. A concept adopted by the current crimeware II</title><summary type='text'>It's increasingly common for research processes we find that on the same server are housed, "operating" actively, several crimeware Exploit Pack type from which control and manage the zombies that are part of his fraudulent business .A while ago we commented on ElFiesta and ZeuS coexisting in the same environment, and meet the same objectives.This time, the merger is between Fragus (an </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2749799056261160675/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/12/fusion-concept-adopted-by-current.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2749799056261160675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2749799056261160675'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/12/fusion-concept-adopted-by-current.html' title='Fusion. A concept adopted by the current crimeware II'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/SxqXhWOxyCI/AAAAAAAACAI/iVYctkAfHik/s72-c/mipistus-fragus-elfiesta.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-6969824763136964242</id><published>2009-12-05T08:55:00.000-07:00</published><updated>2009-12-05T10:45:45.160-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><category scheme='http://www.blogger.com/atom/ns#' term='desinformation'/><category scheme='http://www.blogger.com/atom/ns#' term='scareware'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>Disinformation campaign to spread malware</title><summary type='text'>Disinformation is basically distort or manipulate the information so that the recipient end believing something completely untrue, and which the originator obtains an advantage. For example, the rumor is a tool used in the campaigns of disinformation. In turn, misinformation is a tool that provides useful information in a timely manner (Intelligence).Transferred this concept to the computer field</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/6969824763136964242/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/12/disinformation-campaign-to-spread.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/6969824763136964242'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/6969824763136964242'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/12/disinformation-campaign-to-spread.html' title='Disinformation campaign to spread malware'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sxp9pegoPcI/AAAAAAAAB_4/3ga5i6Tz5wc/s72-c/mipistus-malware-catcher.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-5592694249386241156</id><published>2009-12-04T19:11:00.003-07:00</published><updated>2009-12-04T19:19:45.115-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilities'/><category scheme='http://www.blogger.com/atom/ns#' term='fragu'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='fragus'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>A brief glance inside Fragus</title><summary type='text'>Fragus is a web application developed for the management of zombies, of Russian origin, who long to live has been inserted crimeware clandestine market with an affordable price (USD 800) if we consider criminal capabilities it offers.The crimeware is basically composed of five sections: Statistics, Files, Sellers, Traffic links and Preferences. Each handles a specific task and they all complement</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/5592694249386241156/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/12/brief-glance-inside-fragus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5592694249386241156'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/5592694249386241156'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/12/brief-glance-inside-fragus.html' title='A brief glance inside Fragus'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxcqfYHNxDI/AAAAAAAAB_Q/7vzgO4yhBOA/s72-c/mipistus-fragus-files.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-7560439620178169270</id><published>2009-12-01T20:07:00.002-07:00</published><updated>2009-12-01T20:12:08.180-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='koobface'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>Koobface campaign spread through Blogspot</title><summary type='text'>A massive campaign to spread the worm is Koobface In-the-Wild using blogs as a strategy generated from the Blogspot service.Koobface has become a nightmare for social networks and even though its propagation strategies do not change, this malware is almost two years of activity with a significant rate of infection, making it one of the largest botnets today.Blogspot domains used as cover for the </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/7560439620178169270/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/12/koobface-campaign-spread-through.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7560439620178169270'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/7560439620178169270'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/12/koobface-campaign-spread-through.html' title='Koobface campaign spread through Blogspot'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxXX6VqPV0I/AAAAAAAAB_A/TfimsRZTbDI/s72-c/mipistus-koobface.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-4271756982355599310</id><published>2009-11-29T17:35:00.005-07:00</published><updated>2009-11-30T11:20:05.910-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>JustExploit. New Exploit kit that uses vulnerabilities in Java</title><summary type='text'>Crimeware industry still rising, and just as illegal marketing of web applications that seek to automate the process of infection through the exploitation of vulnerabilities.

This time, the proposal called JustExploit. This is a new Exploit Pack of Russian origin who has a seasoning that is increasingly being taken into account most heavily crimeware developers: the exploitation of </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/4271756982355599310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/11/justexploit-new-exploit-kit-that-uses.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/4271756982355599310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/4271756982355599310'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/11/justexploit-new-exploit-kit-that-uses.html' title='JustExploit. New Exploit kit that uses vulnerabilities in Java'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/SxMO_UvIAqI/AAAAAAAAB-w/L8oZDgwpDYg/s72-c/mipistus-justexploit.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2649581865593396836</id><published>2009-11-26T04:15:00.003-07:00</published><updated>2009-11-26T04:15:00.176-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>Russian service online to check the detection of malware</title><summary type='text'>One thing of concern to the creators/distributors of malware is whether the virus is able to detect their binary and thus ruin their economic plans.One possible way to test the detection capability of these binary antivirus is up to sites like VirusTotal, which to date, using 41 different antivirus engines.The big problem is that these sites often work in collaboration with antivirus companies, </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2649581865593396836/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/11/russian-service-online-to-check.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2649581865593396836'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2649581865593396836'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/11/russian-service-online-to-check.html' title='Russian service online to check the detection of malware'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/Swx-kKDcfFI/AAAAAAAAB9o/9C7878TMEHM/s72-c/mipistus.virtest.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-3045302273689283496</id><published>2009-11-24T05:25:00.001-07:00</published><updated>2009-11-24T05:26:33.787-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><category scheme='http://www.blogger.com/atom/ns#' term='cybint'/><category scheme='http://www.blogger.com/atom/ns#' term='espionage'/><title type='text'>Espionage by malware</title><summary type='text'>During this month remember having breakfast with a piece of news for many media seem to be new or exclusively connected with some Hollywood films, giving it a connotation of "amazing." I refer to espionage through computerized means. Then leave a screenshot of the news, in which it's evident that the malicious code are also part of the operations of intelligence in different contexts, both from a</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/3045302273689283496/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/11/espionage-by-malware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3045302273689283496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3045302273689283496'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/11/espionage-by-malware.html' title='Espionage by malware'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/SwmWnWHZgaI/AAAAAAAAB9Y/HTiXkioR9_A/s72-c/report-esp-mal.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-9118489679046204328</id><published>2009-11-22T09:18:00.004-07:00</published><updated>2009-11-22T09:44:50.597-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ddos'/><category scheme='http://www.blogger.com/atom/ns#' term='crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='dos'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>DDoS Botnet. New crimeware particular purpose</title><summary type='text'>An attack by Denial of Service (DoS) consists basically of abuse of a service or resource by successive requests, either intentional or negligent, which eventually break the availability of such service or resource temporarily or completely.When this type of attack is performed using the processing power of an important set of computers carrying out the abuse of requests synchronously, we are </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/9118489679046204328/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/11/ddos-botnet-new-crimeware-particular.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/9118489679046204328'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/9118489679046204328'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/11/ddos-botnet-new-crimeware-particular.html' title='DDoS Botnet. New crimeware particular purpose'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/Swi5WK627vI/AAAAAAAAB9A/ZbBCh20LjvY/s72-c/malwareint-ddod-serv.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-3587376011121176123</id><published>2009-11-18T18:18:00.001-07:00</published><updated>2009-11-18T18:18:27.181-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><category scheme='http://www.blogger.com/atom/ns#' term='scareware'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='malware intelligence'/><title type='text'>A recent tour of scareware XVIII</title><summary type='text'>Virus Protector = AntiAID, SystemVeteran, BlockProtector, SystemWarriorIP: 85.12.25.111, 83.233.30.66           Netherlands          Eindhoven          Web10 Ict Services         Sweden        Stockholm        Serverconnect I NorrlandDominios asociadosantiaid.comblockkeeper.comblockprotector.comsystemveteran.comPope Green DefenderIP: 99.198.98.217         United States        Chicago        </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/3587376011121176123/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/11/recent-tour-of-scareware-xviii.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3587376011121176123'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/3587376011121176123'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/11/recent-tour-of-scareware-xviii.html' title='A recent tour of scareware XVIII'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/Sv4I7iv-qEI/AAAAAAAAB64/fUT2mg1Jdc0/s72-c/vp.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-1641981623951339874</id><published>2009-11-15T14:51:00.002-07:00</published><updated>2009-11-15T15:01:31.214-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>T-IFRAMER. Kit for the injection of malware In-the-Wild</title><summary type='text'>T-IFRAMER is a package that allows you to automate, centralize and manage via http the spread of malicious code via code injection sites violated viral techniques using iframe, and feed a botnet. We then see a screen capture of authentication.While there is a complex kit allows computer criminals manage the spread of malware via the http protocol type attacks using Drive-by-Download and </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/1641981623951339874/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/11/t-iframer-kit-for-injection-of-malware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1641981623951339874'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/1641981623951339874'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/11/t-iframer-kit-for-injection-of-malware.html' title='T-IFRAMER. Kit for the injection of malware In-the-Wild'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SwBr95WebMI/AAAAAAAAB7o/rOygOyEJQhI/s72-c/mipistus-tiframer-auth.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-114437271933863887</id><published>2009-11-06T19:44:00.001-07:00</published><updated>2009-11-06T19:45:57.192-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='jorge mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>Open Source Development Botnets. "My last words?</title><summary type='text'>Those who read the post about the project called crimeware Quad System, recall that between paragraphs said not knowing the cost of private version of this application for the control of botnets, for Windows platforms to GNU/Linux platforms.The thing is ... for things of life itself ... the developer of these particular projects designed in Perl, called cross, was finished with his exploits </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/114437271933863887/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/11/open-source-development-botnets-my-last.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/114437271933863887'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/114437271933863887'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/11/open-source-development-botnets-my-last.html' title='Open Source Development Botnets. &quot;My last words?'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/Su4zSxEO-OI/AAAAAAAAB6I/RS_vwy-Xcqg/s72-c/mipistus-os-closed.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-173510237036446487</id><published>2009-08-29T06:57:00.001-07:00</published><updated>2009-08-30T14:32:51.047-07:00</updated><title type='text'>Hybrid Botnet Control System. Development http bot in perl</title><summary type='text'>The development of crimeware is increasingly open. Its creators are constantly searching for malware implement in the evasive mechanisms increasingly effective with minimal resource impact on the team not only arbitrary but also controlled the servers that host them, and there are now a range of alternatives ranging from really important "products" payments to free.

In this sense, at some point </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/173510237036446487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/08/hybrid-botnet-control-system-desarrollo.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/173510237036446487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/173510237036446487'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/08/hybrid-botnet-control-system-desarrollo.html' title='Hybrid Botnet Control System. Development http bot in perl'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SpnHOI0o1-I/AAAAAAAABuA/Z8itKqq_1qg/s72-c/mipistus-client-console.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-616478231777204411</id><published>2009-08-24T07:19:00.005-07:00</published><updated>2009-08-30T14:34:02.895-07:00</updated><title type='text'>A recent tour of  scareware XIII</title><summary type='text'>More domains, IP addresses and related hosting malicious code type scareware (rogue) that during this month are spreading threats. As always, the recommendation is to block these addresses and domains.

Antivirus Security
MD5: db924706a824c5c43feebbe6a781d1ba
IP: 84.16.237.52
         Germany        Berlin        Netdirekt E.k
Domains associated
best-antivirus-security .com

Result: 29/41 (70.73%</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/616478231777204411/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/08/una-recorrida-por-los-ultimos-scareware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/616478231777204411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/616478231777204411'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/08/una-recorrida-por-los-ultimos-scareware.html' title='A recent tour of  scareware XIII'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/SoDPnLt4WcI/AAAAAAAABrw/XppmBRanUbo/s72-c/avsec.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-8479649326891280633</id><published>2009-08-17T14:05:00.046-07:00</published><updated>2009-08-30T14:47:04.986-07:00</updated><title type='text'>Open Source Development crimeware to control and manage botnets</title><summary type='text'>The development of web applications-oriented botnets control and management through the http protocol, is at an advanced level by the underground community of Eastern Europe, particularly from Russia, where cyber criminals constantly flood the market crimeware clandestine marketing packages as Eleonore, ZeuS, ElFiesta, Adrenaline, and many others.

However, this business model that is already </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/8479649326891280633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/08/open-source-development-crimeware-to.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8479649326891280633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8479649326891280633'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/08/open-source-development-crimeware-to.html' title='Open Source Development crimeware to control and manage botnets'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/SoIgAgRKGcI/AAAAAAAABr4/NX0dKj3JCGE/s72-c/mipistus-hybrid-botnet-1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2713336886042096232</id><published>2009-08-15T14:54:00.005-07:00</published><updated>2009-08-30T16:22:19.900-07:00</updated><title type='text'>Fragus. New botnet framework In-the-Wild</title><summary type='text'>A new web application written in php and developed as a delivery system exploits, malware and control spread of botnets, has entered the illegal market in crimeware promising to be one of the most exploited. 

This is Fragus v1.0, which has joined from July 2009 to the long list of applications of this kind that seek to corner the black market. Its development is originated in Russia and is </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2713336886042096232/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/08/fragus-new-botnet-framework-in-wild.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2713336886042096232'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2713336886042096232'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/08/fragus-new-botnet-framework-in-wild.html' title='Fragus. New botnet framework In-the-Wild'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Mcy4oUq8gAQ/SpsFYsq2n-I/AAAAAAAAABA/U68Iqruvh3k/s72-c/mipistus-fragus-login-b.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-805926646511411822</id><published>2009-08-14T16:22:00.001-07:00</published><updated>2009-08-30T16:30:43.905-07:00</updated><title type='text'>Liberty Exploit System. Alternatively crimeware to control botnets</title><summary type='text'>The black market controlled by cyber-criminals continues to create products 'competitive' in a business where the low cost of crimeware mark and justify its widespread use. In this sense, botnets are benefited by the development of web applications designed to make his administration an easy and intuitive; also constantly feed the criminal process to which they belong. 

Another alternative is to</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/805926646511411822/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/08/liberty-exploit-system-alternatively.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/805926646511411822'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/805926646511411822'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/08/liberty-exploit-system-alternatively.html' title='Liberty Exploit System. Alternatively crimeware to control botnets'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SoTJDywiqvI/AAAAAAAABsg/jZlUslwa1wI/s72-c/mipistus-liberty-botnet.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-2340214686597286379</id><published>2009-08-12T16:31:00.002-07:00</published><updated>2009-08-30T16:35:19.839-07:00</updated><title type='text'>Prices of Russian crimeware. Part 2</title><summary type='text'>Criminal activities of which are fed daily cyber criminals through a business model implemented by themselves, are channeled through the underground market that offer "services" more professionals to suit the needs of cyber -organized crime.

Consequently, every day there are new crimeware applications to enhance the economics of cyber-criminals, whatever the role in the criminal chain. Some of </summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/2340214686597286379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/08/prices-of-russian-crimeware-part-2.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2340214686597286379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/2340214686597286379'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/08/prices-of-russian-crimeware-part-2.html' title='Prices of Russian crimeware. Part 2'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sn5Zd9GveOI/AAAAAAAABpg/vWPMwJkhW80/s72-c/mipistus-crum-cryptor.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-446873836886549311.post-8918316831385188535</id><published>2009-08-08T16:34:00.004-07:00</published><updated>2009-08-30T16:42:45.140-07:00</updated><title type='text'>TRiAD Botnet III. Remote administration of multi-platform zombies</title><summary type='text'>TRIAD is a web application designed to monitor and manage botnets by using GNU/Linux and MS Windows via the http protocol and of which we have discussed recently. It's part of an even more ambitious project by its author (who calls himself "cross"), called Hybrid Remote Administration System and which we will talk soon ;P

This time, it's version 3 TRIAD botnet. This web application is still in "</summary><link rel='replies' type='application/atom+xml' href='http://malwareint.blogspot.com/feeds/8918316831385188535/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://malwareint.blogspot.com/2009/08/triad-botnet-iii-remote-administration.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8918316831385188535'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/446873836886549311/posts/default/8918316831385188535'/><link rel='alternate' type='text/html' href='http://malwareint.blogspot.com/2009/08/triad-botnet-iii-remote-administration.html' title='TRiAD Botnet III. Remote administration of multi-platform zombies'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/Sn3IU8hRt8I/AAAAAAAABpI/wu8h7B8yZY8/s72-c/mipistus-triad-help.png' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
