<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-10854312</id><updated>2012-02-16T07:04:44.200-05:00</updated><category term='mobile'/><category term='Vista'/><category term='Weekly TechTips'/><category term='batman'/><category term='podcast'/><category term='research'/><category term='spam bot'/><category term='vm'/><category term='rants'/><category term='installs'/><category term='advertising'/><category term='privacy'/><category term='youtube'/><category term='openBTS'/><category term='VIPRE 4.0'/><category term='techtips'/><category term='android'/><category term='Faraday cage'/><category term='Twitter Giveaway'/><category term='fake'/><category term='symbian'/><category term='spam'/><category term='dark knight rises'/><category term='Black Friday'/><category term='spyware'/><category term='marketing'/><category term='vb2011'/><category term='scam'/><category term='replication jail'/><category term='trailers'/><category term='VIPRE'/><title type='text'>GFI LABS Blog</title><subtitle type='html'>A blog about activities, products and ideas at GFI, one of the leading developers of security software to protect against spyware, spam and other threats.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default?start-index=101&amp;max-results=100'/><author><name>Adam</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4049</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-10854312.post-674576695122343283</id><published>2012-01-13T11:05:00.001-05:00</published><updated>2012-01-16T01:33:33.032-05:00</updated><title type='text'>Moving House</title><content type='html'>Yes, we are :)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a alt="Click to visit the new GFI Labs Blog" href="http://www.gfi.com/blog/labs/" title="Click to visit the new GFI Labs Blog"&gt;&lt;span id="goog_160560414"&gt;&lt;/span&gt;&lt;span id="goog_160560418"&gt;&lt;/span&gt;&lt;span id="goog_160560422"&gt;&lt;/span&gt;&lt;span id="goog_160560430"&gt;&lt;/span&gt;&lt;img border="0" height="210" src="http://2.bp.blogspot.com/-Ds94jokxlc0/TxBB1BXXnzI/AAAAAAAAAac/CWvnHVQorIs/s320/NewGFILabsBlog_screen.png" width="320" /&gt;&lt;span id="goog_160560431"&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;i&gt;Click the image to visit the new GFI Labs Blog&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;An inevitable move, this. After all, &lt;a href="http://www.gfi.com/blog/gfi-software-acquires-sunbelt-software/"&gt;Sunbelt Software has been part of GFI Software&lt;/a&gt; for more than a year now.&lt;br /&gt;&lt;br /&gt;This didn't happen overnight, though. We tip our hats to our colleagues in Malta who worked hard to put up our new home and brought the Labs under one domain. At the very least, you, dear Reader, are now spared the confusion of whether to call this website the "Sunbelt Blog" or the "GFI Blog" ;)&lt;br /&gt;&lt;br /&gt;What you're reading here now is our 4,100th published post; it is also our last. We're just glad that our "Goodbye!" is short-lived.&lt;br /&gt;&lt;br /&gt;Moving to a new home is just the start of better changes that are about to take place. To continue receiving the latest research and noteworthy information security news from us, we urge you to update your RSS to point to the &lt;a href="http://feeds.feedburner.com/GFILabs"&gt;new GFI Labs Blog feed&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Cheers to all of our avid readers! Chris and I will see you on the other side :)&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;span id="goog_160560432"&gt;&lt;/span&gt;&lt;span id="goog_160560433"&gt;&lt;/span&gt;&lt;a href="http://draft.blogger.com/"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-674576695122343283?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/674576695122343283/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=674576695122343283&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/674576695122343283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/674576695122343283'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2012/01/moving-house.html' title='Moving House'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-Ds94jokxlc0/TxBB1BXXnzI/AAAAAAAAAac/CWvnHVQorIs/s72-c/NewGFILabsBlog_screen.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-5893260180767847774</id><published>2012-01-12T03:58:00.000-05:00</published><updated>2012-01-12T03:59:51.336-05:00</updated><title type='text'>Phishers Use US-CERT Email Address as Bait</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-yawqq3t4aWU/Tw6f37EBKgI/AAAAAAAAAaQ/TrFbqWsJ7m0/s1600/us-cert_logo.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="68" src="http://2.bp.blogspot.com/-yawqq3t4aWU/Tw6f37EBKgI/AAAAAAAAAaQ/TrFbqWsJ7m0/s400/us-cert_logo.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;The &lt;b&gt;&lt;a href="http://en.wikipedia.org/wiki/United_States_Computer_Emergency_Readiness_Team"&gt;United States Computer Emergency Readiness Team&lt;/a&gt;&amp;nbsp;&lt;/b&gt;(simply known as &lt;a href="http://www.us-cert.gov/" style="font-weight: bold;"&gt;US-CERT&lt;/a&gt;)&amp;nbsp;is the latest bait phishers used to get users to install malware on user systems.&lt;br /&gt;&lt;br /&gt;US-CERT is a highly esteemed and trusted body of security professionals who tackle cybersecurity issues in the United States. They also work with security vendors to address vulnerability issues. With such impressive credentials, it is possible that some private organizations, including federal, state, and local governments, might have fallen prey to this campaign since they appear to be the targets.&lt;br /&gt;&lt;br /&gt;From the &lt;a href="http://www.us-cert.gov/current/index.html#phishing_campaign_using_spoofed_us"&gt;US-CERT website&lt;/a&gt;: &lt;i&gt;"Reports indicate that SOC@US-CERT.GOV is the primary email address being spoofed but other invalid email addresses are also being used.&lt;br /&gt;&lt;br /&gt;"The subject of the phishing email is: "Phishing incident report call number: PH000000XXXXXXX" with the "X" containing an incident report number that varies.&lt;br /&gt;&lt;br /&gt;"The attached zip filed is titled "US-CERT Operation Center Report XXXXXXX.zip", with "X" indicating a random value or string. The zip attachment contains an executable file with the name "US-CERT Operation CENTER Reports.eml.exe", which is a variant of the &lt;b&gt;Zeus/Zbot&lt;/b&gt; Trojan known as &lt;b&gt;Ice-IX&lt;/b&gt;."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;The complete report is found &lt;a href="http://www.us-cert.gov/current/index.html#phishing_campaign_using_spoofed_us"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-5893260180767847774?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/5893260180767847774/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=5893260180767847774&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5893260180767847774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5893260180767847774'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2012/01/phishers-use-us-cert-email-address-as.html' title='Phishers Use US-CERT Email Address as Bait'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-yawqq3t4aWU/Tw6f37EBKgI/AAAAAAAAAaQ/TrFbqWsJ7m0/s72-c/us-cert_logo.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-1380852002348512806</id><published>2012-01-11T23:57:00.002-05:00</published><updated>2012-01-12T00:00:40.695-05:00</updated><title type='text'>StalkTrak App gets Naked, Famous.</title><content type='html'>&lt;iframe allowfullscreen="" frameborder="0" height="315" src="http://www.youtube.com/embed/WkWpx6bi0a8" width="500"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;"No way" indeed.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://en.wikipedia.org/wiki/The_Naked_and_Famous"&gt;The Naked and Famous&lt;/a&gt; were displaying the following Tweet on their &lt;a href="https://twitter.com/#!/tnaf"&gt;feed&lt;/a&gt; earlier:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-znAoKv23BFs/Tw5U7GOmFsI/AAAAAAAAB0E/5845ShUayKw/s1600/TNAF_img1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="145" src="http://4.bp.blogspot.com/-znAoKv23BFs/Tw5U7GOmFsI/AAAAAAAAB0E/5845ShUayKw/s400/TNAF_img1.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Visiting hampaw(dot)ru takes the end-user to&amp;nbsp;tivvitter(dot)com/twitter_stalk-trak_app_user, where they are presented with an application install page for something called "StalkTrak":&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-QgCBP3DjhE0/Tw5nANAVruI/AAAAAAAAB0U/JL1zbKbhlnM/s1600/TNAF_img2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-QgCBP3DjhE0/Tw5nANAVruI/AAAAAAAAB0U/JL1zbKbhlnM/s320/TNAF_img2.jpg" width="297" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-jLxfJsWYiM4/Tw5kc1Q75zI/AAAAAAAAB0M/1AprDvBpKm4/s1600/TNAF_img_2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="225" src="http://4.bp.blogspot.com/-jLxfJsWYiM4/Tw5kc1Q75zI/AAAAAAAAB0M/1AprDvBpKm4/s320/TNAF_img_2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;The end-user can only progress to the next page if they enter both a username and a password - continuing past this screen will result in links to "StalkTrak" being sent to their followers.&lt;br /&gt;&lt;br /&gt;Stalking apps are an old and tired scam dating back to the Myspace days, but unfortunately we continue to fall for them. Please steer clear of the above URL, and think twice before allowing any applications involving "Stalking" to access your Twitter account. You can always clean up your Twitter account &lt;a href="https://twitter.com/settings/applications"&gt;here&lt;/a&gt; by revoking access to unwanted applications.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks to Jovi Umawing for assistance)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-1380852002348512806?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/1380852002348512806/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=1380852002348512806&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1380852002348512806'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1380852002348512806'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2012/01/stalktrak-app-gets-naked-famous.html' title='StalkTrak App gets Naked, Famous.'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/WkWpx6bi0a8/default.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-967651228417274228</id><published>2012-01-11T09:15:00.001-05:00</published><updated>2012-01-11T10:24:30.635-05:00</updated><title type='text'>GFI's Take on What Online Crime Will be Like in 2012</title><content type='html'>In a recent release of GFI Software's VIPRE report, GFI Labs revealed that recycled tactics from cybercriminals will not cease this new year. Modifications on these tactics will only be slight, and will depend greatly on the kind of targets these online criminals are aiming at. To quote Senior Threat Researcher Christopher Boyd:&amp;nbsp;"Most cyber-attacks at any given time rely on old techniques deployed with a new disguise. The reason we see them again and again is quite simply because they work, and we anticipate 2012 to bring many fresh takes on old scams."&lt;br /&gt;&lt;br /&gt;You can read more about this report &lt;a href="http://www.gfi.com/page/107684/gfi-software-warns-2012-will-be-rife-with-familiar-cybercrime-tricks"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-967651228417274228?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/967651228417274228/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=967651228417274228&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/967651228417274228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/967651228417274228'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2012/01/gfis-take-on-what-online-crime-would-be.html' title='GFI&apos;s Take on What Online Crime Will be Like in 2012'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-3635799463156351189</id><published>2012-01-11T00:56:00.001-05:00</published><updated>2012-01-11T01:07:22.390-05:00</updated><title type='text'>Bogus Video Game Crack Leads to Rootkit</title><content type='html'>Matthew, one of our malware researchers at the AV Labs, came upon a &lt;b&gt;&lt;i&gt;MediaFire&lt;/i&gt;&lt;/b&gt; link on a &lt;i&gt;&lt;b&gt;YouTube&lt;/b&gt;&lt;/i&gt; account that purports to direct users to a site where a crack code for the video game &lt;b&gt;&lt;i&gt;&lt;a href="http://en.wikipedia.org/wiki/Pro_Evolution_Soccer_2012"&gt;Pro Evolution Soccer 2012 (PES 2012)&lt;/a&gt;&lt;/i&gt;&lt;/b&gt; (otherwise known as &lt;b&gt;&lt;i&gt;World Soccer: Winning Eleven 2012&lt;/i&gt;&lt;/b&gt;) can be downloaded.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-xFhoYWKTA2o/Tw0ieYYOlaI/AAAAAAAAAZk/Il1_MyWUr18/s1600/YT_ZeroAccess_img01.jpeg" imageanchor="1"&gt;&lt;img border="0" height="263" src="http://3.bp.blogspot.com/-xFhoYWKTA2o/Tw0ieYYOlaI/AAAAAAAAAZk/Il1_MyWUr18/s320/YT_ZeroAccess_img01.jpeg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Of course, one doesn't need to go hunting for a &lt;b&gt;&lt;i&gt;YouTube&lt;/i&gt;&lt;/b&gt; page for the URL. Here it is: &lt;i&gt;http://www(dot)mediafire(dot)com/?i1o0fsa9t5gvpld&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;Users visiting the page can readily download and extract the compressed file &lt;i&gt;Pro Evolution Soccer 2012 Keygen&lt;/i&gt;. In it are three files: an HTML file, a text file, and another compressed file, which contains the key generator application. The text file doesn't actually contain the password it claims to have. Instead, it contains a shortened URL users must visit to get the password from.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-TMJPg8pivMI/Tw0irEHVmRI/AAAAAAAAAZw/2RiznZCtKNw/s1600/YT_ZeroAccess_img02.jpeg" imageanchor="1"&gt;&lt;img border="0" height="214" src="http://1.bp.blogspot.com/-TMJPg8pivMI/Tw0irEHVmRI/AAAAAAAAAZw/2RiznZCtKNw/s320/YT_ZeroAccess_img02.jpeg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;i&gt;http://tinyurl(dot)com/64ad4m&lt;/i&gt; is actually &lt;i&gt;http://lnkgt(dot)com/7RM&lt;/i&gt;, a survey page that users must answer before their password is given to them.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ZA7o1aA1p8k/Tw0izIV8RGI/AAAAAAAAAZ8/geBjaFEhVbs/s1600/YT_ZeroAccess_img03.jpeg" imageanchor="1"&gt;&lt;img border="0" height="234" src="http://4.bp.blogspot.com/-ZA7o1aA1p8k/Tw0izIV8RGI/AAAAAAAAAZ8/geBjaFEhVbs/s320/YT_ZeroAccess_img03.jpeg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Unfortunately, after users fill in the survey, gets the password to be used to run the keygen, they inevitably end up installing malware on their systems. Not just any malware; it's a rootkit: &lt;b&gt;&lt;i&gt;ZeroAccess&lt;/i&gt;&lt;/b&gt;, a sophisticated rootkit known for overwriting critical OS files.&amp;nbsp;Luckily, almost all AV vendors detect this one.&amp;nbsp;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=46ee3ee0ecba97d29506a16c5b624235e2fbfae4ee2557d6754f1b03840dfc9e-1326121487"&gt;Take a look&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Do note that the &lt;i&gt;MediaFire&lt;/i&gt; URL is also mentioned on other website platforms that allow the embedding of video clips (such as the one below).&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-FgmLKoQSWaY/Tw0i83bR07I/AAAAAAAAAaI/XlwxmJl98Ag/s1600/YT_ZeroAccess_img04.jpeg" imageanchor="1"&gt;&lt;img border="0" height="223" src="http://4.bp.blogspot.com/-FgmLKoQSWaY/Tw0i83bR07I/AAAAAAAAAaI/XlwxmJl98Ag/s320/YT_ZeroAccess_img04.jpeg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;The more the URL is out there, the more likely someone can and will install the rootkit onto their systems. Stay safe, everyone!&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks, Matthew)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-3635799463156351189?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/3635799463156351189/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=3635799463156351189&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3635799463156351189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3635799463156351189'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2012/01/bogus-video-game-crack-leads-to-rootkit.html' title='Bogus Video Game Crack Leads to Rootkit'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-xFhoYWKTA2o/Tw0ieYYOlaI/AAAAAAAAAZk/Il1_MyWUr18/s72-c/YT_ZeroAccess_img01.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-7813990119707695691</id><published>2012-01-04T03:53:00.002-05:00</published><updated>2012-01-04T03:53:23.397-05:00</updated><title type='text'>2011: The Year that was for Facebook and Online Threats</title><content type='html'>&lt;b&gt;CommTouch&lt;/b&gt;, an Internet security service provider, has recently released their &lt;b&gt;Internet Threats Trend Report&lt;/b&gt; for 2011. In this report, they have highlighted and analyzed the various threats on &lt;b&gt;&lt;i&gt;Facebook&lt;/i&gt;&lt;/b&gt; that had plagued users for the past year, such as social engineering ploys and common methods of attack used. They also identify three ways on how criminals gain and&amp;nbsp;what these are&amp;nbsp;for targeting &lt;i&gt;Facebook&lt;/i&gt; users. CommTouch provided an infographic (below) to showcase their analysis in a more coherent format.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-jls_Jimo7qs/TwQOCTLtjUI/AAAAAAAAAZY/oC64tq3M3OE/s1600/Infographic-Facebook-attack-trends-in-2011.jpg" imageanchor="1"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-jls_Jimo7qs/TwQOCTLtjUI/AAAAAAAAAZY/oC64tq3M3OE/s320/Infographic-Facebook-attack-trends-in-2011.jpg" width="106" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;The 19-page Internet Threats Trend Report mentions malware and spam trends in Q4 of 2011. It also ranks website categories that are most likely to house malware if compromised—Sites tagged as &lt;i&gt;Pornography&lt;/i&gt; are at #3. Below are other notable finds in summary:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;India, Vietnam, and Pakistan were the top three countries with the most zombie computers.&lt;/li&gt;&lt;li&gt;Phishers mostly targeted sites that were related to &lt;i&gt;Games&lt;/i&gt; and &lt;i&gt;Gaming.&lt;/i&gt;&lt;/li&gt;&lt;li&gt;In Q4, spammers used fake &lt;i&gt;@gmail.com&lt;/i&gt; email addresses to trick users into responding to their spam messages.&lt;/li&gt;&lt;/ul&gt;The report can be downloaded &lt;a href="http://www.commtouch.com/download/2244"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-7813990119707695691?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/7813990119707695691/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=7813990119707695691&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7813990119707695691'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7813990119707695691'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2012/01/2011-year-that-was-for-facebook-and.html' title='2011: The Year that was for Facebook and Online Threats'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-jls_Jimo7qs/TwQOCTLtjUI/AAAAAAAAAZY/oC64tq3M3OE/s72-c/Infographic-Facebook-attack-trends-in-2011.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-560448716101185284</id><published>2012-01-01T21:11:00.002-05:00</published><updated>2012-01-01T21:17:47.227-05:00</updated><title type='text'>Team Meat Spun Right Round</title><content type='html'>&lt;i&gt;"It's fine, trust me. I've done this stuff for a while now."&lt;/i&gt; &lt;a href="https://twitter.com/#!/SuperMeatBoy/status/150072842627710976"&gt;Famous last words&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Team Meat, developers of &lt;a href="https://en.wikipedia.org/wiki/Super_Meat_Boy"&gt;Super Meat Boy&lt;/a&gt;, had a bit of an issue this past week when their Super Meat World database was compromised. This resulted in the game being broken, and all user created levels being deleted.&lt;br /&gt;&lt;br /&gt;They were notified by a person in &lt;a href="http://forums.somethingawful.com/showthread.php?noseen=0&amp;amp;threadid=2803713&amp;amp;pagenumber=258"&gt;this thread&lt;/a&gt; on Twitter that access to their database was wide open, but the responses from the official Meat Boy account seemed to be a bit of a &lt;a href="http://i.imgur.com/eCYSF.png"&gt;brush off&lt;/a&gt; in the eyes of some watching the drama unfold. Before you could say "This is going to go horribly wrong", it all went horribly wrong and login details were posted across various forums.&lt;br /&gt;&lt;br /&gt;The post it notes summary of events can be found &lt;a href="http://forums.steampowered.com/forums/showpost.php?p=27911192&amp;amp;postcount=8"&gt;here&lt;/a&gt;; a thread on the official forums lies &lt;a href="http://supermeatboy.com/forum/index.php/topic,2259.msg28861.html#msg28861"&gt;this way&lt;/a&gt; and if you'd rather take in the full horror of an entire game being put through the wood chipper then check out this &lt;a href="http://img820.imageshack.us/img820/1641/itsfinetrustme.png"&gt;blow by blow account&lt;/a&gt;. The game is now back up and running, but we have what may be the final game developer of 2011 to join the "Whoops, we were hacked" company of Sony, Square Enix, Steam, Nintendo, SEGA, Bethesda, EA, Codemasters, Epic and others.&lt;br /&gt;&lt;br /&gt;Let's see if the trend continues in 2012, assuming the Mayans don't get us all first...&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-560448716101185284?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/560448716101185284/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=560448716101185284&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/560448716101185284'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/560448716101185284'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2012/01/team-meat-spun-right-round.html' title='Team Meat Spun Right Round'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-3023715064694404005</id><published>2011-12-30T05:40:00.000-05:00</published><updated>2011-12-30T05:40:23.936-05:00</updated><title type='text'>Steam: All your coal are belong to us</title><content type='html'>The rather awesome &lt;a href="https://en.wikipedia.org/wiki/Steam_(software)"&gt;Steam&lt;/a&gt; gaming platform has a festive competition running at the moment - perform certain tasks in a selection of games drawn each day (or sign up to a few non gaming activities like join a forum, or link your Steam and Facebook accounts) and receive a free random gift. I have to admit - I'm not doing very well so far.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-_CXHhmeZoDc/Tv2M68nC6zI/AAAAAAAABzY/ezcWNms4MYY/s1600/steamcoal1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="228" src="http://2.bp.blogspot.com/-_CXHhmeZoDc/Tv2M68nC6zI/AAAAAAAABzY/ezcWNms4MYY/s320/steamcoal1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;That gift could be a redeemable coupon for a free game, a discount or...a lump of coal. All is not lost should you be handed a lump of coal - collect seven, and you can craft it into another randomly selected discount or free game.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-jaEw1jiF3KI/Tv2OXrKNQlI/AAAAAAAABzk/dFNKLOBsr6s/s1600/steamcoal2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-jaEw1jiF3KI/Tv2OXrKNQlI/AAAAAAAABzk/dFNKLOBsr6s/s320/steamcoal2.gif" width="262" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;This is, of course, where it all goes horribly wrong.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;1)&lt;/b&gt;&amp;nbsp;Gamers are exploiting the various "Indie Bundle" packs that go on sale periodically. This particular gaming bundle is a "pay what you want" affair, typically stuffed full of great games and additional offers should you pay a little extra (we still need to &lt;a href="https://paperghost.posterous.com/the-humble-indie-bundle-some-interesting-stat"&gt;have that talk&lt;/a&gt;, Windows users). The latest &lt;a href="http://www.joystiq.com/2011/12/25/humble-indie-bundle-4-earns-2-million/"&gt;Humble Indie Bundle&lt;/a&gt; went live not so long ago, and in a mad dash to create as much coal as possible to increase the chances of free games in Steam gamers were &lt;a href="http://www.joystiq.com/2011/12/22/humble-indie-bundle-4-abused-by-scrooge-like-steam-scamming/"&gt;paying the base amount&lt;/a&gt; for Indie Bundles, redeemable against Steam accounts.&lt;br /&gt;&lt;br /&gt;From &lt;a href="http://www.platformnation.com/2011/12/21/humble-indie-bundle-4-adds-precautions-in-response-to-steam-exploiting/"&gt;Platform Nation&lt;/a&gt;: &lt;i&gt;"For just 1 penny you can nab yourself a Steam redeemable key, and make your account valid for entry in the Epic Giveaway and the freebie prizes. That means you can create 100 accounts for just $1"&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Whoops. They must have really gone to town on that one, given that the mass purchasing caused the price of the bundle to drop by more than 25 cents.&lt;br /&gt;&lt;br /&gt;Greedy gamers have also been targeting the "IndieGala Bundle" which gives a&amp;nbsp;separate&amp;nbsp;Steam account for each game - effectively five duplicate accounts for the lowest potential price of a penny. Once you've got your hands on all those wonderful discount coupons and free games, you can potentially gift them to your "main" account and sit upon a throne of murkily acquired titles.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;2)&lt;/b&gt; With shades of &lt;a href="http://www.theregister.co.uk/2010/02/21/xbox_hacking_phishing_analysis/"&gt;Xbox achievement tampering&lt;/a&gt;, people are distributing save files / text files to unlock Steam game achievements needed to win coal / coupons. Here's an &lt;a href="http://www.cheapassgamer.com/forums/showpost.php?p=9250871&amp;amp;postcount=11022"&gt;example&lt;/a&gt; of someone loading up a file not belonging to them, nabbing the required achievement in &lt;a href="http://arstechnica.com/gaming/news/2011/09/the-binding-of-isaac-takes-on-religion-in-a-randomly-generated-zelda-styled-roguelike.ars"&gt;Binding of Isaac&lt;/a&gt; and getting their hands on a free game. That's kind of dreadful, and by "kind of" I mean "completely".&lt;br /&gt;&lt;br /&gt;&lt;b&gt;3)&lt;/b&gt; Gamers are firing up a Steam achievements modding tool, to ensure they nab as much coal as possible.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-O6-TNR_kJug/Tv2SKUVFOZI/AAAAAAAABz8/oegIj-CFfKM/s1600/steamcoal4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="212" src="http://3.bp.blogspot.com/-O6-TNR_kJug/Tv2SKUVFOZI/AAAAAAAABz8/oegIj-CFfKM/s320/steamcoal4.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Here's someone who clearly went on an "unlock all the things" &lt;a href="http://i.imgur.com/F4ojd.jpg"&gt;rampage&lt;/a&gt;. As you can imagine, these antics are &lt;a href="http://forums.steampowered.com/forums/showthread.php?t=2354508"&gt;not proving popular&lt;/a&gt; with non cheating gamers.&lt;br /&gt;&lt;br /&gt;Coal farming isn't going unpunished, and Valve are starting to clamp down on anyone seen to be farming and / or exploiting. You may well be seeing many more examples like the below on forums posted up by vaguely annoyed gamers who want their accounts reactivated:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-3yQWk78Djq0/Tv2O_lAhkLI/AAAAAAAABzw/SL7wB-67CAg/s1600/steamcoal3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="69" src="http://3.bp.blogspot.com/-3yQWk78Djq0/Tv2O_lAhkLI/AAAAAAAABzw/SL7wB-67CAg/s320/steamcoal3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;If Valve catch you being naughty this festive season, they won't even leave you with coal. Top that, Santa...&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-3023715064694404005?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/3023715064694404005/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=3023715064694404005&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3023715064694404005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3023715064694404005'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/12/steam-all-your-coal-are-belong-to-us.html' title='Steam: All your coal are belong to us'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-_CXHhmeZoDc/Tv2M68nC6zI/AAAAAAAABzY/ezcWNms4MYY/s72-c/steamcoal1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4619438660243937806</id><published>2011-12-22T01:50:00.000-05:00</published><updated>2011-12-22T01:50:12.842-05:00</updated><title type='text'>Hobbits and surveys: not a good combination</title><content type='html'>It's not long since &lt;a href="http://www.bbc.co.uk/news/entertainment-arts-16281896"&gt;The Hobbit trailer&lt;/a&gt; made a lot of people very excited, and already we're seeing fake claims of "watch this movie online" leading to surveys.&lt;br /&gt;&lt;br /&gt;For example:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-EDCPukHuqN4/TvLSQrfIvII/AAAAAAAABzA/W0uXJe73dLc/s1600/hobbitfilm1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="202" src="http://4.bp.blogspot.com/-EDCPukHuqN4/TvLSQrfIvII/AAAAAAAABzA/W0uXJe73dLc/s320/hobbitfilm1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-1wU6iqoFhzg/TvLSSg38ItI/AAAAAAAABzI/Ci28tcAy8jk/s1600/hobbitfilm2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="195" src="http://1.bp.blogspot.com/-1wU6iqoFhzg/TvLSSg38ItI/AAAAAAAABzI/Ci28tcAy8jk/s320/hobbitfilm2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;You know the drill - fill in the survey to "view the content", then fail to be impressed by the total lack of content on offer. You'll either see nothing at all, or websites asking you to sign up to monthly fees. Don't fall for it!&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks Robert)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4619438660243937806?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4619438660243937806/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4619438660243937806&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4619438660243937806'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4619438660243937806'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/12/hobbits-and-surveys-not-good.html' title='Hobbits and surveys: not a good combination'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-EDCPukHuqN4/TvLSQrfIvII/AAAAAAAABzA/W0uXJe73dLc/s72-c/hobbitfilm1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-7556582889281461766</id><published>2011-12-20T06:47:00.003-05:00</published><updated>2011-12-20T06:53:52.643-05:00</updated><title type='text'>Phishers are Back to Target Chase Clients</title><content type='html'>Robert Stetson, one of our malware researchers at the AV Labs, found a new phishing scam in the wild.&lt;br /&gt;&lt;br /&gt;The scam arrives as an email that directs users to the URL, &lt;i&gt;data-server(dot)host(dot)org/email/protect/chase/&lt;/i&gt;.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-w2JeFZdsWfw/TvByzeGWrmI/AAAAAAAAAY0/bHwwn_8RKSo/s1600/12202011_chase-phish_img1.jpg" imageanchor="1"&gt;&lt;img border="0" height="184" src="http://2.bp.blogspot.com/-w2JeFZdsWfw/TvByzeGWrmI/AAAAAAAAAY0/bHwwn_8RKSo/s320/12202011_chase-phish_img1.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;After &lt;b&gt;&lt;i&gt;Chase&lt;/i&gt;&lt;/b&gt; clients provide their credentials into the fields of the purported legitimate bank page and click &lt;i&gt;Log on&lt;/i&gt;, they are then directed to another UI where they are to enter their email address and its password.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-yFs7lbNVfX0/TvBy9hlL-TI/AAAAAAAAAZA/KVEQua1bc0E/s1600/12202011_chase-phish_img2.jpg" imageanchor="1"&gt;&lt;img border="0" height="154" src="http://4.bp.blogspot.com/-yFs7lbNVfX0/TvBy9hlL-TI/AAAAAAAAAZA/KVEQua1bc0E/s320/12202011_chase-phish_img2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-o65-ADRJ5NU/TvBzCyAkhlI/AAAAAAAAAZM/4cgBLWTkDuY/s1600/12202011_chase-phish_img3.jpg" imageanchor="1"&gt;&lt;img border="0" height="210" src="http://2.bp.blogspot.com/-o65-ADRJ5NU/TvBzCyAkhlI/AAAAAAAAAZM/4cgBLWTkDuY/s320/12202011_chase-phish_img3.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Chase&lt;/i&gt; clients, please be duly warned about this. For the rest, please delete from your inbox doubtful mails that purport to come from banks (including yours). If you received an email from your bank about your account, confirm with them via customer service.You know what they say: Better safe than sorry.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Robert)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-7556582889281461766?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/7556582889281461766/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=7556582889281461766&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7556582889281461766'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7556582889281461766'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/12/phishers-target-chase.html' title='Phishers are Back to Target Chase Clients'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-w2JeFZdsWfw/TvByzeGWrmI/AAAAAAAAAY0/bHwwn_8RKSo/s72-c/12202011_chase-phish_img1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-5030598324607827222</id><published>2011-12-16T07:15:00.003-05:00</published><updated>2011-12-16T10:26:08.513-05:00</updated><title type='text'>"Curious Who's Stalking You?" - Yes, we've heard it before</title><content type='html'>This social media "stalking" thing, to the best of my knowledge, all began on &lt;i&gt;&lt;b&gt;MySpace&lt;/b&gt;&lt;/i&gt;. We've seen them emerge on &lt;b&gt;&lt;i&gt;Twitter&lt;/i&gt;&lt;/b&gt;, too: our friends at Sophos &lt;a href="http://nakedsecurity.sophos.com/2011/08/12/twitter-finally-released-a-stalkers-app-no-its-a-phishing-scam/"&gt;wrote&lt;/a&gt; a so-called "app" that &lt;i&gt;Twitter&lt;/i&gt; purportedly released to track a user's stalker. Only this time, no such app is ever involved.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-l3lCOPsymiU/Tusx7MHG2KI/AAAAAAAAAYA/ebwXeqY08rE/s1600/twit_spam_img1.jpg" imageanchor="1"&gt;&lt;img border="0" height="114" src="http://4.bp.blogspot.com/-l3lCOPsymiU/Tusx7MHG2KI/AAAAAAAAAYA/ebwXeqY08rE/s320/twit_spam_img1.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;We've seen the tweet above pointing users to the URL, &lt;i&gt;canbin(dot)ru&lt;/i&gt;—a domain created just late last month. Once users click it, they are then directed to &lt;i&gt;twvitter(dot)com/user_login-sessions/?timed_out=1&lt;/i&gt;. It's a phishing page.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-0T8kdbi7keU/Tuti_mMAXNI/AAAAAAAAAYk/OX7C9NmBX9o/s1600/twit_spam_img2.jpg" imageanchor="1"&gt;&lt;img border="0" height="222" src="http://4.bp.blogspot.com/-0T8kdbi7keU/Tuti_mMAXNI/AAAAAAAAAYk/OX7C9NmBX9o/s320/twit_spam_img2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;There are two things we can take note from it: (1) the URL, which clearly tries to play tricks with our eyes (much like &lt;a href="http://blog.trendmicro.com/updating-vvindows/"&gt;this&lt;/a&gt; one), and (2) the purported &lt;i&gt;Twitter&lt;/i&gt; session that has timed out. Naturally, if one is logged onto &lt;i&gt;Twitter&lt;/i&gt; and sees the message, they'll wonder for a second, and then unknowingly key in their user name and password anyway. Perhaps the only "error" we can see in this attack is that the site attempts to access the actual &lt;i&gt;Twitter &lt;/i&gt;site the same way a real third-party app or site would to make everything seem legit. However, &lt;i&gt;Twitter &lt;/i&gt;requires tokens from such apps and sites. Since we know that this is a bogus page, it doesn't have a token; thus, it can't successfully redirect users to their actual accounts as it was supposed to.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-oN_5vsO9ETE/TusyYMCILyI/AAAAAAAAAYY/yR5Maj8N7nA/s1600/twit_spam_img3.jpg" imageanchor="1"&gt;&lt;img border="0" height="159" src="http://2.bp.blogspot.com/-oN_5vsO9ETE/TusyYMCILyI/AAAAAAAAAYY/yR5Maj8N7nA/s320/twit_spam_img3.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;We impore you, Dear Reader, to please exercise caution when clicking links on tweets. Even better: use your better judgment on whether you'd believe a supposedly interesting tweet or not before considering visiting the URL that goes with it. More often than not, scam tweets are designed to sound this way to actually make Internet users click them. Please don't be fooled.&lt;br /&gt;&lt;br /&gt;Just like the "Girl Killed Herself" scam that made rounds within &lt;i&gt;Twitter &lt;/i&gt;not so long ago, this, too, will probably go down in history as a classic attack involving two social networking giants. This is &lt;i&gt;not&lt;/i&gt; a comforting news. As long as user continue to fall for scams, they will just keep coming.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Chris for spotting this)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-5030598324607827222?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/5030598324607827222/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=5030598324607827222&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5030598324607827222'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5030598324607827222'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/12/curious-whos-stalking-you-yes-weve.html' title='&quot;Curious Who&apos;s Stalking You?&quot; - Yes, we&apos;ve heard it before'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-l3lCOPsymiU/Tusx7MHG2KI/AAAAAAAAAYA/ebwXeqY08rE/s72-c/twit_spam_img1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4818680345015309515</id><published>2011-12-14T06:19:00.001-05:00</published><updated>2011-12-14T06:19:27.421-05:00</updated><title type='text'>Protecting Against DDoS is Probably THE Best Holiday Gift to Give Your Company</title><content type='html'>For the lot of us who rely on the Internet to get news updates, we are made familiar with &lt;b&gt;Distributed Denial of System (DDoS)&lt;/b&gt; attacks. Anonymous being on the headlines continuously for months made this kind of online crime&amp;nbsp;conspicuous, even ushering it unexpectedly to the realm of mainstream.&lt;br /&gt;&lt;br /&gt;DDoS attacks have been used not just by the aforementioned group but also by other groups and individuals for various reasons: making a stand for what they believe in, showing support for the beliefs of others, or doing it "just because". We can't deny the fact that names of companies that fell prey on DDoS attacks were huge and they encompass industries, but one cannot totally eliminate the very likely possibility of small- and medium-sized businesses being targeted as well.&lt;br /&gt;&lt;br /&gt;Those whose businesses have an online presence are aware and worried, and if possible, they want to be protected from DDoS attacks. So how can this be done? InfoWorld published an article that tells business people just that. You can check it out &lt;a href="http://podcasts.infoworld.com/d/security/how-deny-ddos-attacks-181523?_kip_ipx=1110830460-1323850097"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4818680345015309515?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4818680345015309515/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4818680345015309515&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4818680345015309515'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4818680345015309515'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/12/protecting-against-ddos-is-probably.html' title='Protecting Against DDoS is Probably THE Best Holiday Gift to Give Your Company'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-400765120887407134</id><published>2011-12-13T13:47:00.000-05:00</published><updated>2011-12-13T13:47:33.293-05:00</updated><title type='text'>Adblock Fuss</title><content type='html'>I'm a big fan of Adblock Plus - it's a great add on if you don't want to be hit over the head with any number of spinning, flashing adverts torn straight from the pages of Dante.&lt;br /&gt;&lt;br /&gt;However, an interesting change has been made to the program with the release of 2.0 and some users are up in arms about it:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-1rEta-ToYb8/TueXanvh1TI/AAAAAAAAByw/YsPR5tMdT2U/s1600/adblckpls1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="113" src="http://1.bp.blogspot.com/-1rEta-ToYb8/TueXanvh1TI/AAAAAAAAByw/YsPR5tMdT2U/s320/adblckpls1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;i&gt;"Adblock Plus has also been configured to allow non-intrusive advertising. You can change this selection at any time in the filter preferences."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Blasphemy? Madness? Sparta? Who knows, but we now have a situation where &lt;a href="https://adblockplus.org/forum/viewtopic.php?f=1&amp;amp;t=8872"&gt;users aren't happy&lt;/a&gt;&amp;nbsp;about the opt in by default setting, or indeed approving adverts in general no matter how limited the scope. There's a page on the Adblock Plus site that outlines &lt;a href="https://adblockplus.org/en/acceptable-ads"&gt;some of the reasons&lt;/a&gt; for this change:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"You can allow some of the advertising that is considered not annoying. By doing this you support websites that rely on advertising but choose to do it in a non-intrusive way...In the long term the web will become a better place for everybody, not only Adblock Plus users. Without this feature we run the danger that increasing Adblock Plus usage will make small websites unsustainable."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;As for why this is set live by default:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"If   we ask users to enable this feature then most of them won't do it&amp;nbsp;— simply because they   never change any settings unless absolutely necessary. However, advertisers will   only be interested in switching to better ways of advertising if the majority of Adblock   Plus users has this feature enabled."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;I'm not entirely convinced that advertisers so fond of flashy, spinning adverts from the back of beyond will tone their adverts down just because of this move - and hey, let's not forget that adverts meeting the requirements to be potentially given the green light ("static ads, text only, no attention grabbing images") can be &lt;a href="http://sunbeltblog.blogspot.com/2011/12/more-bad-ads-in-bing-yahoo-search.html"&gt;just as dangerous&lt;/a&gt; if not more so than the flashy horrors still on the blocklist.&lt;br /&gt;&lt;br /&gt;One good thing that may come out of this move is a possible reduction in infections. No really, hear me out. I know a lot of people who have told me they never installed Adblock Plus or similar programs because their income was primarily driven by dedicated communities, and they wanted to put something back into those communities by not blocking their (static) advertisements. For example, a professional comic artist or writer is supported by their community; as a thank you, they won't block the adverts on the sites belonging to their fans or webcomic rings.&lt;br /&gt;&lt;br /&gt;As a result, quite a few of them were hit by drive by installs and exploits while browsing the web with no ad blockers in place.&lt;br /&gt;&lt;br /&gt;If the Adblock Plus team do a good job of this, it might actually encourage more people to now try the program and let a few (hopefully harmless) adverts through while using their new found installs to block malicious adverts elsewhere with a clean&amp;nbsp;conscience.&lt;br /&gt;&lt;br /&gt;That can only be a good thing. However, much will depend on their examination of the approved advert networks, their advertising methods, the kind of links those advertisers allow (and how they react to the bad apples that slip through the net) and whether or not the userbase approves of the opt in by default setup.&lt;br /&gt;&lt;br /&gt;We'll have to wait and see how this one plays out...&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-400765120887407134?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/400765120887407134/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=400765120887407134&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/400765120887407134'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/400765120887407134'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/12/adblock-fuss.html' title='Adblock Fuss'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-1rEta-ToYb8/TueXanvh1TI/AAAAAAAAByw/YsPR5tMdT2U/s72-c/adblckpls1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-8319625497811796503</id><published>2011-12-13T09:58:00.001-05:00</published><updated>2011-12-13T10:14:35.402-05:00</updated><title type='text'>Blackhole Exploit Hones in on Amazon Users</title><content type='html'>Last week, our friends at ThreatPost &lt;a href="http://threatpost.com/en_us/blogs/carberp-and-black-hole-exploit-kit-wreaking-havoc-120511"&gt;posted&lt;/a&gt; about the ever-growing infection of websites hosting &lt;b&gt;Black Hole Exploit Kits&lt;/b&gt;. A Black Hole exploit takes advantage of unpatched Windows operating systems. It also targets other software, such as &lt;b&gt;&lt;i&gt;Java&lt;/i&gt;&lt;/b&gt;&amp;nbsp;and&amp;nbsp;&lt;b style="font-style: italic;"&gt;Adobe Reader&lt;/b&gt;,&amp;nbsp;that can be installed on Windows platforms, which are &lt;i&gt;a lot&lt;/i&gt;. Since the kits are already available in the black market (for free), we can only expect more infections and news surrounding this particular kit.&lt;br /&gt;&lt;br /&gt;And, oh: &lt;i&gt;&lt;b&gt;Facebook&lt;/b&gt;&lt;/i&gt; users &lt;a href="http://labs.m86security.com/2011/12/cutwail-spam-campaigns-lure-users-to-blackhole-exploit-kit/"&gt;should watch their backs&lt;/a&gt;, too.&lt;br /&gt;&lt;br /&gt;Our malware researchers at the AV Labs, Robert and Matthew, has seen something in the wild that might spoil the holiday spirits a bit. It began as an email message supposedly from &lt;i&gt;Amazon&lt;/i&gt; with the subject &lt;i&gt;"Your Amazon.com order of Omron WXH-108F Fat Loss... has shipped"&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-6-tktbBBQWM/TudkAHYsxnI/AAAAAAAAAXo/olMlxcJ7iw4/s1600/Amazon-blackhole_img1.jpg" imageanchor="1"&gt;&lt;img border="0" height="233" src="http://2.bp.blogspot.com/-6-tktbBBQWM/TudkAHYsxnI/AAAAAAAAAXo/olMlxcJ7iw4/s320/Amazon-blackhole_img1.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Clicking any of the links on the email body directs users to &lt;i&gt;jongerencentrumdebus(dot)nl/wp-content/uploads/fgallery/news.html&lt;/i&gt;, a likely compromised site,&amp;nbsp;and then directs to &lt;i&gt;ageoloft(dot)info/main(dot)php?page=525447c096f8efbf&lt;/i&gt;,&amp;nbsp;a known Black Hole Exploit Kit host.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-AGKkrAK11K0/TudkMrIxD-I/AAAAAAAAAX0/XDqf2aBzJ2g/s1600/Amazon-blackhole_img2.jpg" imageanchor="1"&gt;&lt;img border="0" height="152" src="http://1.bp.blogspot.com/-AGKkrAK11K0/TudkMrIxD-I/AAAAAAAAAX0/XDqf2aBzJ2g/s320/Amazon-blackhole_img2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;The said &lt;i&gt;ageoloft(dot)info &lt;/i&gt;automatically downloads a .PDF file (an exploit) onto systems. This then exploits &lt;i&gt;Adobe Reader &lt;/i&gt;to run malicious executable files on these systems. Furthermore,&amp;nbsp;a worm, which GFI Software detects as &lt;b&gt;Win32.Malware!Drop&lt;/b&gt;,&amp;nbsp;is downloaded onto systems.&lt;br /&gt;&lt;br /&gt;We detect the exploit page as &lt;b&gt;Trojan.JS.Obfuscator.w (v)&lt;/b&gt;; the PDF file that is part of the kit, &lt;b&gt;Exploit.PDF-JS.Gen (v)&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;With the number of Internet users shopping online using services such as &lt;i&gt;Amazon&lt;/i&gt; and &lt;i&gt;&lt;b&gt;eBay&lt;/b&gt;&lt;/i&gt;, it pays to be cautious fourfold, especially at this time of the year. Criminals know when and how users—&lt;i&gt;you&lt;/i&gt;—spend their time there.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Robert and Matthew)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-8319625497811796503?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/8319625497811796503/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=8319625497811796503&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8319625497811796503'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8319625497811796503'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/12/blackhole-exploit-hones-in-on-amazon.html' title='Blackhole Exploit Hones in on Amazon Users'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-6-tktbBBQWM/TudkAHYsxnI/AAAAAAAAAXo/olMlxcJ7iw4/s72-c/Amazon-blackhole_img1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-538670298902368439</id><published>2011-12-09T12:09:00.001-05:00</published><updated>2011-12-09T12:11:28.123-05:00</updated><title type='text'>More bad ads in Bing, Yahoo search</title><content type='html'>Another round of &lt;a href="http://threatpost.com/en_us/blogs/researchers-find-ads-bing-yahoo-leading-malware-downloads-091611"&gt;bad ads in Bing&lt;/a&gt; and Yahoo search are making an unwelcome return. Bing has fake Firefox adverts:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-3nQ_YCuOsO8/TuI4Ko2wg2I/AAAAAAAAByA/zXEPbSzJPCM/s1600/mrebngdec1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-3nQ_YCuOsO8/TuI4Ko2wg2I/AAAAAAAAByA/zXEPbSzJPCM/s320/mrebngdec1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-wN8OJdSNJHo/TuI4MBZIxCI/AAAAAAAAByE/CAkNTq6RmQM/s1600/mrebngdec11.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="214" src="http://1.bp.blogspot.com/-wN8OJdSNJHo/TuI4MBZIxCI/AAAAAAAAByE/CAkNTq6RmQM/s320/mrebngdec11.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Yahoo has fake Adobe Flash adverts instead, located at gripwise(dot)com(dot)au/player/:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ORZTuA1WWUM/TuI4M-qiOJI/AAAAAAAAByM/GHkAA4kU_t4/s1600/mrebngdec2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="270" src="http://4.bp.blogspot.com/-ORZTuA1WWUM/TuI4M-qiOJI/AAAAAAAAByM/GHkAA4kU_t4/s320/mrebngdec2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-vKEJFwKDT-Y/TuI4Nk5fEZI/AAAAAAAAByU/VsMMkzsBgQE/s1600/mrebngdec22.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="261" src="http://3.bp.blogspot.com/-vKEJFwKDT-Y/TuI4Nk5fEZI/AAAAAAAAByU/VsMMkzsBgQE/s320/mrebngdec22.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;As you can see from the below screenshot, the Gripwise URL where this is located appears to have been compromised:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-e43x82Yig_w/TuI4Ohs_kTI/AAAAAAAAByc/Sc1RofKFdQ8/s1600/mrebngdec3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="234" src="http://4.bp.blogspot.com/-e43x82Yig_w/TuI4Ohs_kTI/AAAAAAAAByc/Sc1RofKFdQ8/s320/mrebngdec3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Both sites will give you the &lt;a href="http://malwareprotectioncenter.com/2011/11/06/privacy-protection-rogue-of-the-malware-protection-family/"&gt;Privacy Protection rogue&lt;/a&gt;, and the domain used for the fake Firefox download (ipropertyoffice(dot)com) has active exploits so please steer clear. VirusTotal scores weigh in at &lt;a href="http://www.virustotal.com/file-scan/report.html?id=f96fd4c0f0a04f21a789adf1c825fa66433f766d2943e5b0e27f2082ef3e5756-1323448417"&gt;17/43&lt;/a&gt;, and we detect as Win32.Malware!Drop.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-6PLfIrhNXRY/TuI4PgCWvkI/AAAAAAAAByo/P62kE_4m4Zw/s1600/mrebngdec4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="234" src="http://4.bp.blogspot.com/-6PLfIrhNXRY/TuI4PgCWvkI/AAAAAAAAByo/P62kE_4m4Zw/s320/mrebngdec4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;At time of writing, Microsoft have been notified and have said the adverts have been pulled. All the same, be very careful when clicking on sponsored adverts for common downloads such as Firefox, Flash and others. As we've seen time and time again, scammers are all too eager to push malicious files on unsuspecting users.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks Matthew)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-538670298902368439?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/538670298902368439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=538670298902368439&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/538670298902368439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/538670298902368439'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/12/more-bad-ads-in-bing-yahoo-search.html' title='More bad ads in Bing, Yahoo search'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-3nQ_YCuOsO8/TuI4Ko2wg2I/AAAAAAAAByA/zXEPbSzJPCM/s72-c/mrebngdec1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4204583862795939513</id><published>2011-12-07T20:24:00.000-05:00</published><updated>2011-12-07T20:24:41.449-05:00</updated><title type='text'>Holiday Horrors: food stamps, phish and PDFs</title><content type='html'>Our monthly Top Ten threat detection report for the month of November is now available to take a look at, along with information on some of the scams we've seen these past few weeks including emails tempting users with &lt;a href="http://sunbeltblog.blogspot.com/2011/11/pdf-malware-is-back-in-season.html"&gt;infected PDF files&lt;/a&gt;, &lt;a href="http://sunbeltblog.blogspot.com/2011/11/snap-scam-will-make-you-snap.html"&gt;food stamp shenanigans&lt;/a&gt; involving mobile phone services and phishing emails containing &lt;a href="http://sunbeltblog.blogspot.com/2011/11/phish-for-thanksgiving.html"&gt;HTML form attachments&lt;/a&gt;, some of which are &lt;a href="http://sunbeltblog.blogspot.com/2011/12/for-your-protection-your-barclays.html"&gt;still doing the rounds&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The Top Ten can be viewed &lt;a href="http://www.gfi.com/page/103544/cybercriminals-kick-off-holiday-season-by-spreading-malware-and-phishing-attacks"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4204583862795939513?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4204583862795939513/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4204583862795939513&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4204583862795939513'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4204583862795939513'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/12/holiday-horrors-food-stamps-phish-and.html' title='Holiday Horrors: food stamps, phish and PDFs'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-1074594821933819065</id><published>2011-12-07T20:08:00.000-05:00</published><updated>2011-12-07T20:08:12.962-05:00</updated><title type='text'>"For your protection, your Barclays account has been suspended..."</title><content type='html'>If you see an email arrive in your mailbox with the above title, feel free to discard it - nothing good will come of it, unless your idea of "good" is "filling in all of your personal information into a fake banking webpage then sending it to a scammer."&lt;br /&gt;&lt;br /&gt;The missive is sent from a free Yahoo email address, and works along the same line as &lt;a href="http://sunbeltblog.blogspot.com/2011/11/phish-for-thanksgiving.html"&gt;these scam mails&lt;/a&gt; from a few weeks ago.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-yFHTEpTaXqQ/Tt9Gt5C5QnI/AAAAAAAABxo/gbWN7dGOvIM/s1600/fakebclays000.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="152" src="http://4.bp.blogspot.com/-yFHTEpTaXqQ/Tt9Gt5C5QnI/AAAAAAAABxo/gbWN7dGOvIM/s320/fakebclays000.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;They claim your account has been suspended due to a large number of incorrect login attempts, and reactivation is a case of filling in the attached form before the 9th of December - otherwise your account will be disabled. With a fake time limit imposed on the customer, they open up the attached HTML form and see that it asks for an awful lot of information. Name, membership number, passcode, date of birth, mother's maiden name, address...&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-1Oq0d7MYI04/Tt9Hp4rQtRI/AAAAAAAABxw/v7cmuSjlUrk/s1600/fakebclays1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="209" src="http://2.bp.blogspot.com/-1Oq0d7MYI04/Tt9Hp4rQtRI/AAAAAAAABxw/v7cmuSjlUrk/s320/fakebclays1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Of course it gets worse. Before you know it, our panicked bank customer is filling in their sort code, account number, telephone banking password and the three digit security code from the back of their card.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Rm9VlyGNKZ8/Tt9H8VXw-XI/AAAAAAAABx4/bXx83hhYSP4/s1600/fakebclays2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="118" src="http://3.bp.blogspot.com/-Rm9VlyGNKZ8/Tt9H8VXw-XI/AAAAAAAABx4/bXx83hhYSP4/s320/fakebclays2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Once all of this is done, hitting the "Next" button submits the data to the scammer then redirects to the Barclays website. Please avoid mails such as the above and keep your money where it belongs - your bank will never email you asking for account information (and they certainly won't email you from a free webmail account!)&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-1074594821933819065?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/1074594821933819065/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=1074594821933819065&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1074594821933819065'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1074594821933819065'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/12/for-your-protection-your-barclays.html' title='&quot;For your protection, your Barclays account has been suspended...&quot;'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-yFHTEpTaXqQ/Tt9Gt5C5QnI/AAAAAAAABxo/gbWN7dGOvIM/s72-c/fakebclays000.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-8820233292022828607</id><published>2011-12-05T07:22:00.001-05:00</published><updated>2011-12-05T10:05:26.348-05:00</updated><title type='text'>"Steam Birthday" crashed by party poopers</title><content type='html'>Here's a rather amateur phish targeting &lt;a href="http://en.wikipedia.org/wiki/Steam_(software)"&gt;Steam&lt;/a&gt; users, located at steambirthday(dot)com. No birthday prizes for guessing what this scam is all about:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-QkFUPec38xw/Ttys414-wpI/AAAAAAAABxA/sujka4Iyb_c/s1600/steambday1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="211" src="http://4.bp.blogspot.com/-QkFUPec38xw/Ttys414-wpI/AAAAAAAABxA/sujka4Iyb_c/s320/steambday1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;You know you're dealing with a special kind of phish when the opening ramble begins with "Steam is 3 years old: the Steam project started in 2003" and "In a really short time our servers became more and more and today there are more than a thousand meters of them".&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-qW_qoCHJDy8/TtyxRJMXG_I/AAAAAAAABxI/LZZzockJkHA/s1600/steambday2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-qW_qoCHJDy8/TtyxRJMXG_I/AAAAAAAABxI/LZZzockJkHA/s1600/steambday2.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;According to the website, Valve - the creators of Steam - are giving away "1000 Gold accounts, which will allow you to play all 72 games for free" (Steam actually has 1,400+ titles available for download). Hitting the gold coloured "Upgrade now" button takes the end-user to a brilliantly convincing phish page. Or, to be more accurate, it takes them to missing images and screwed up HTML code:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-YJHLcbsOMVM/TtyzDRBxnnI/AAAAAAAABxQ/RBXOmLzwdP0/s1600/steambday3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="191" src="http://3.bp.blogspot.com/-YJHLcbsOMVM/TtyzDRBxnnI/AAAAAAAABxQ/RBXOmLzwdP0/s320/steambday3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;The site is already flagged in Chrome as a phish page, and hopefully IE and others will follow suit soon. For now, let's hold off on the birthday celebrations.&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-8820233292022828607?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/8820233292022828607/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=8820233292022828607&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8820233292022828607'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8820233292022828607'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/12/steam-birthday-crashed-by-party-poopers.html' title='&quot;Steam Birthday&quot; crashed by party poopers'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-QkFUPec38xw/Ttys414-wpI/AAAAAAAABxA/sujka4Iyb_c/s72-c/steambday1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-721058697218988586</id><published>2011-11-29T05:26:00.001-05:00</published><updated>2011-11-29T05:40:18.935-05:00</updated><title type='text'>New Facebook Worm in the Wild</title><content type='html'>Our friends at &lt;a href="http://www.csis.dk/en/csis/about/"&gt;CSIS&lt;/a&gt;, a Danish security company, has spotted a &lt;b&gt;worm &lt;/b&gt;spreading within the &lt;b&gt;&lt;i&gt;Facebook&lt;/i&gt; &lt;/b&gt;platform. In a &lt;a href="http://www.csis.dk/da/csis/news/3387/"&gt;recent news article&lt;/a&gt;&amp;nbsp;penned by&amp;nbsp;Peter Kruse, the worm is said to be "a classic" one in terms of how it infects Internet users: uses stolen credentials to log in to &lt;i&gt;Facebook&lt;/i&gt; accounts and then spam contacts. The message is said to contain a link to a file purporting to be an image—Screenshot of the file shows it has a .JPG extension—but it's actually a malicious screensaver. Once run, it drops a cocktail of malicious files onto the system, including &lt;b&gt;ZeuS&lt;/b&gt;, a popular Trojan spyware capable of stealing user information from infected systems.&lt;br /&gt;&lt;br /&gt;The worm is also found to have anti-VM capabilities, making it useless to execute and test in a virtual environment, such as &lt;i&gt;Oracle VM VirtualBox&lt;/i&gt; and &lt;i&gt;VMWare&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;Please keep in mind that securing your information, including your social network credentials, is a must. Never unknowingly click links on messages sent over by online contacts. Make sure that they did send messages to you first before doing something; else, it is best if you simply delete them from your message inbox.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-721058697218988586?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/721058697218988586/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=721058697218988586&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/721058697218988586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/721058697218988586'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/new-facebook-worm-in-wild.html' title='New Facebook Worm in the Wild'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-6834763535257193434</id><published>2011-11-28T17:17:00.004-05:00</published><updated>2011-11-28T17:48:11.449-05:00</updated><title type='text'>FakeScanti Rogue Hijacks HOSTS Files</title><content type='html'>Patrick, our resident rogue AV expert from the AV Labs, have his eyes set on one particular family—&lt;b&gt;FakeScanti&lt;/b&gt;. This rogue family first appeared in the first quarter of 2010, and it has been within the radar ever since.&lt;br /&gt;&lt;br /&gt;Enter &lt;a href="http://malwareprotectioncenter.com/2011/11/18/av-protection-2011-rogue-of-the-fakescanti-family/"&gt;&lt;b&gt;&lt;i&gt;AV Protection 2011&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This particular rogue is the latest variant in a handful of noteworthy rogues within the FakeScanti family. What's interesting about it is that it modifies the infected system's &lt;a href="http://en.wikipedia.org/wiki/Hosts_(file)"&gt;HOSTS file&lt;/a&gt; upon execution, a capability common to backdoors and worms. &lt;i&gt;AV Protection 2011&lt;/i&gt; directs users to &lt;i&gt;46(dot)4(dot)179(dot)109&lt;/i&gt;, a malicious IP in Germany where &lt;i&gt;&lt;a href="http://malwareprotectioncenter.com/2011/11/10/av-security-2012-rogue-of-the-fakescanti-family/"&gt;&lt;b&gt;AV Secure 2012&lt;/b&gt;&lt;/a&gt;&lt;/i&gt;, another FakeScanti variant, is housed. It does this when users enter either &lt;i&gt;google.com&lt;/i&gt;, &lt;i&gt;yahoo.com&lt;/i&gt;, &lt;i&gt;bing.com&lt;/i&gt;, or&amp;nbsp;&lt;i&gt;facebook.com&lt;/i&gt; in the Internet browser address bar.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-rZJEHatyOi4/TtQIAntwE9I/AAAAAAAAAXc/g4sX27qjY3E/s1600/avsecure2012.png" imageanchor="1"&gt;&lt;img border="0" height="222" src="http://1.bp.blogspot.com/-rZJEHatyOi4/TtQIAntwE9I/AAAAAAAAAXc/g4sX27qjY3E/s320/avsecure2012.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Internet users can encounter this rogue if they are led to pages via search engine optimization (SEO) technique or via a spammed link where, once visited, downloads a Blackhole exploit kit where this rogue AV is bundled with. We detect&amp;nbsp;&lt;i&gt;AV Protection 2011&lt;/i&gt;&amp;nbsp;as &lt;b&gt;Trojan.Win32.FakeAV.IS (v)&lt;/b&gt;. We can also &lt;a href="http://www.virustotal.com/file-scan/report.html?id=3ebee67bbaf2f84f696ad0085554304c0aaac1fbcc036ace405630e289929b49-1321583947"&gt;detect&lt;/a&gt; and clean the modified HOSTS.&lt;br /&gt;&lt;br /&gt;If you may recall, this isn't the first time HOSTS files are hijacked by criminals to dupe users in so many ways. In &lt;a href="http://sunbeltblog.blogspot.com/2006/01/anatomy-of-malicious-host-file-hijack.html"&gt;this&lt;/a&gt; particular situation, phishers modified the HOSTS to direct users to fake pages of popular banks, such as Bank of America and Citibank, whenever they key in the legitimate bank URLs in the address bar.&lt;br /&gt;&lt;br /&gt;Users are advised to be wary of clicking links in emails. If you didn't contact the party that sent such mails, it's always best to not bother yourself with them and delete them from your inbox. &lt;a href="http://sunbeltblog.blogspot.com/2011/11/with-rogue-av-its-more-than-game-of.html"&gt;Be careful with how you do searches online&lt;/a&gt; as well, since the criminals behind rogue AV are still banking on the old yet very effective SEO technique.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Patrick)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-6834763535257193434?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/6834763535257193434/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=6834763535257193434&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6834763535257193434'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6834763535257193434'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/patrick-our-resident-rogue-av-expert.html' title='FakeScanti Rogue Hijacks HOSTS Files'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-rZJEHatyOi4/TtQIAntwE9I/AAAAAAAAAXc/g4sX27qjY3E/s72-c/avsecure2012.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-8062345970687444209</id><published>2011-11-28T11:05:00.000-05:00</published><updated>2011-11-28T11:05:31.191-05:00</updated><title type='text'>"Così fan tutte"</title><content type='html'>A company who make installers distributing the software of third parties recently contacted us to query a detection. As it turns out, their installer was not the problem - they were partnering with a company whose toolbar continues to have a history of misleading and deceptive installs.&lt;br /&gt;&lt;br /&gt;The interesting part of all this was the discussion over how the programs caught the attention of the end-user in the first place. Here, it was big green download buttons on download sites that looked (for all intents and purposes) like the button the end-user should click on to begin their desired download. Instead, it would take them to vaguely named installer files. Examples of said buttons:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-3SOYmiApB0Q/TtOptqQcjLI/AAAAAAAABwQ/kAJ4zPSnDN0/s1600/cosipost1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="238" src="http://2.bp.blogspot.com/-3SOYmiApB0Q/TtOptqQcjLI/AAAAAAAABwQ/kAJ4zPSnDN0/s320/cosipost1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/--Nl5ErhRHf0/TtOpuLqqnoI/AAAAAAAABwU/FhVXjwBDAfw/s1600/cosipost2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="202" src="http://1.bp.blogspot.com/--Nl5ErhRHf0/TtOpuLqqnoI/AAAAAAAABwU/FhVXjwBDAfw/s320/cosipost2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;As a response, the basic argument set forth was "We want to be clean, but it's so difficult when everybody else is doing whatever they can to snag an install over a company attempting to play by the rules". On the surface of it, this would seem to be the case - pre ticked checkboxes, dubious installers and poor notification inside the programs we download are bad enough, but poor choice of advert placement (and adverts that themselves look like Facebook notification prompts and other elements that would fool a regular web-user) muddy the waters still further.&lt;br /&gt;&lt;br /&gt;You can see these on everything from search engines to garden variety adverts on any number of websites you care to mention, and as social networks continue to grow in influence so too do 2.0 themed adverts continue to vie for your attention.&lt;br /&gt;&lt;br /&gt;Disappointingly, the bulk of the case set forth boils down to "everyone else is doing it". Here are some of the examples they sent over:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-HfEKm6QZm6s/TtOqLIPCOmI/AAAAAAAABwg/IrGQ-r3Fz4s/s1600/cosipost4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="182" src="http://4.bp.blogspot.com/-HfEKm6QZm6s/TtOqLIPCOmI/AAAAAAAABwg/IrGQ-r3Fz4s/s320/cosipost4.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Above you can see a rather large green tick and a "Download now" button which completely overwhelm the simple text link that happens to be the one the end-user is looking for.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-AE6Sc1DKSHo/TtOqMZnGZLI/AAAAAAAABwo/q8jNUqrgUmA/s1600/cosipost3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="282" src="http://3.bp.blogspot.com/-AE6Sc1DKSHo/TtOqMZnGZLI/AAAAAAAABwo/q8jNUqrgUmA/s320/cosipost3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;The above example has a rather prominent (and unrelated) download banner at the top and another download link off to the right - personally I don't feel this has as strong a case as the first example, although three green download buttons on the same page is always going to cause confusion for somebody.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-M_39L38bhdg/TtOqNDGW45I/AAAAAAAABww/WEXar-PiIcU/s1600/cosipost5.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="176" src="http://4.bp.blogspot.com/-M_39L38bhdg/TtOqNDGW45I/AAAAAAAABww/WEXar-PiIcU/s320/cosipost5.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Above, we can see the actual download button fairly dwarfed by a larger one off to the right. Much like the other two, you can bet this has resulted in a number of "Wait, what?" style downloads.&lt;br /&gt;&lt;br /&gt;None of this is new, of course - you can easily jump back to 2008 or earlier and see the same sort of thing taking place on &lt;a href="http://blog.spywareguide.com/images/gview6.html"&gt;Facebook application installer pages&lt;/a&gt;. It's worthwhile advising&amp;nbsp;relatives you suspect will wander into these setups to be on their guard, because as far as many companies out there installing Adware and other products are concerned it's a case of &lt;a href="http://wiki.answers.com/Q/What_is_'Cosi_fan_tutte'_in_English"&gt;Così fan tutte&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks Eric)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-8062345970687444209?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/8062345970687444209/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=8062345970687444209&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8062345970687444209'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8062345970687444209'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/cosi-fan-tutte.html' title='&quot;Così fan tutte&quot;'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-3SOYmiApB0Q/TtOptqQcjLI/AAAAAAAABwQ/kAJ4zPSnDN0/s72-c/cosipost1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-6992502619737180628</id><published>2011-11-24T09:29:00.001-05:00</published><updated>2011-11-24T11:42:59.403-05:00</updated><title type='text'>"Rogue browsers will make a comeback on the mobile platform."</title><content type='html'>We've seen it here first: &lt;a href="http://sunbeltblog.blogspot.com/2011/10/yapbrowser-has-returned.html"&gt;&lt;b&gt;&lt;i&gt;YapBrowser&lt;/i&gt;&lt;/b&gt; has risen after being declared dead five years ago&lt;/a&gt;—and this discovery is by Chris Boyd himself just a day before he presented at &lt;b&gt;VB 2011&lt;/b&gt; to discuss about&amp;nbsp;&lt;b&gt;rogue browsers&lt;/b&gt;, of which &lt;i&gt;YapBrowser&lt;/i&gt; is.&lt;br /&gt;&lt;br /&gt;If you missed the said conference or Chris's presentation, &lt;a href="http://www.net-security.org/article.php?id=1653"&gt;this podcast&lt;/a&gt;&amp;nbsp;hosted by our friends at&amp;nbsp;Help Net Security&amp;nbsp;contains a comprehensive, lightning talk from Chris about rogue browsers, their history, their numerous payloads, and the possibility of them plaguing smartphones.&lt;br /&gt;&lt;br /&gt;Not long ago, our friends at Trend Micro &lt;a href="http://blog.trendmicro.com/malware-found-disguised-as-opera-mini/"&gt;spotted&lt;/a&gt; the first rogue browser for &lt;b&gt;&lt;i&gt;Windows Mobile&lt;/i&gt;&lt;/b&gt;, &lt;b&gt;&lt;i&gt;Symbian OS&lt;/i&gt;&lt;/b&gt;, and &lt;b&gt;&lt;i&gt;Android&lt;/i&gt;&lt;/b&gt; phones, disguising as &lt;i style="font-weight: bold;"&gt;Opera Mini&lt;/i&gt;, a popular Web browser for mobile phones. This could be the start of a new trend. What we're sure of is that fake browsers are still out there, even if under the radar and on different platforms.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-6992502619737180628?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/6992502619737180628/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=6992502619737180628&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6992502619737180628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6992502619737180628'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/rogue-browsers-will-make-comeback-on.html' title='&quot;Rogue browsers will make a comeback on the mobile platform.&quot;'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-6044252047859890824</id><published>2011-11-23T16:51:00.016-05:00</published><updated>2011-11-23T21:00:16.191-05:00</updated><title type='text'>Phish for Thanksgiving?</title><content type='html'>Over the previous few days, our research team here at GFI has noticed an uptick in bank phishes winding up in a few of our spam traps. This particular scam is unique in that it comes with an html file attachment which leads to a form that attempts to steal from the unsuspecting victim all types of identifying information from the standard pin and password to their Driver’s License number and even a (fake) description of the last transaction made on the account.&lt;div&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-KY16P-Lohzg/Ts2fs4hPlTI/AAAAAAAAADQ/VhWRziUCLQ4/s1600/SunTrust_Phish_11_23_2.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 248px; height: 400px;" src="http://2.bp.blogspot.com/-KY16P-Lohzg/Ts2fs4hPlTI/AAAAAAAAADQ/VhWRziUCLQ4/s400/SunTrust_Phish_11_23_2.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5678370298618942770" /&gt;&lt;/a&gt;&lt;br /&gt;As of this posting, we have seen e-mails targeting Bank of America and SunTrust customers and surely more will follow.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-j02i2CO5T1Y/Ts2jqDlow2I/AAAAAAAAADo/aAOHcf0OGc4/s1600/BOA_Phish_11_22_3.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 354px;" src="http://4.bp.blogspot.com/-j02i2CO5T1Y/Ts2jqDlow2I/AAAAAAAAADo/aAOHcf0OGc4/s400/BOA_Phish_11_22_3.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5678374648097063778" /&gt;&lt;/a&gt;&lt;br /&gt;As always, please be wary of e-mails from financial institutions asking for identifying information. When in doubt, call the official phone number listed on the back of your credit card or the known customer service line for your bank.&lt;br /&gt;&lt;br /&gt;So, while "fish" was likely a &lt;a href="http://en.wikipedia.org/wiki/Thanksgiving_dinner#Historical_menus"&gt;staple eaten&lt;/a&gt; during the days of the pilgrams, we here in the lab are going to stick to good ol' turkey this year.&lt;br /&gt;&lt;br /&gt;Stay safe,&lt;br /&gt;&lt;br /&gt;Robert Stetson&lt;br /&gt;Malware Research Team&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-6044252047859890824?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/6044252047859890824/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=6044252047859890824&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6044252047859890824'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6044252047859890824'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/phish-for-thanksgiving.html' title='Phish for Thanksgiving?'/><author><name>Adam</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-KY16P-Lohzg/Ts2fs4hPlTI/AAAAAAAAADQ/VhWRziUCLQ4/s72-c/SunTrust_Phish_11_23_2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-5791442639006750680</id><published>2011-11-22T17:01:00.002-05:00</published><updated>2011-11-25T07:40:00.361-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VIPRE'/><category scheme='http://www.blogger.com/atom/ns#' term='Black Friday'/><title type='text'>VIPRE Black Friday Special</title><content type='html'>&lt;p style="font-family: Georgia, 'Bitstream Charter', serif; font-size: 13px; margin-bottom: 24px; line-height: 18px; text-align: -webkit-auto; "&gt;Here at GFI, we’re dedicated to providing quality antivirus software at exceptional values, and this Black Friday is no exception. Our &lt;span style="color: #0000ff;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.vipreantivirus.com/promos/black-friday/" style="color: rgb(0, 102, 204); "&gt;Black Friday Sale&lt;/a&gt; &lt;/span&gt;&lt;/span&gt;features the biggest discounts of 2011 – up to 75% off.&lt;/p&gt;&lt;p style="font-family: Georgia, 'Bitstream Charter', serif; font-size: 13px; margin-bottom: 24px; line-height: 18px; text-align: -webkit-auto; "&gt;&lt;strong style="font-weight: bold; "&gt;Black Friday Sale&lt;/strong&gt;&lt;/p&gt;&lt;p style="font-family: Georgia, 'Bitstream Charter', serif; font-size: 13px; margin-bottom: 24px; line-height: 18px; text-align: -webkit-auto; "&gt;VIPRE Antivirus 2012 &lt;span style="text-decoration: line-through;"&gt;for $39.95&lt;/span&gt; &lt;span style="color: #ff0000;"&gt;&lt;strong style="font-weight: bold; "&gt;&lt;span class="Apple-style-span" &gt;NOW $9.95!&lt;/span&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;VIPRE Internet Security 2012 &lt;span style="text-decoration: line-through;"&gt;for $49.95&lt;/span&gt; &lt;span style="color: #ff0000;"&gt;&lt;strong style="font-weight: bold; "&gt;&lt;span class="Apple-style-span" &gt;NOW $19.95!&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-family: Georgia, 'Bitstream Charter', serif; font-size: 13px; margin-bottom: 24px; line-height: 18px; text-align: -webkit-auto; "&gt;With prices this low, you can give the gift of PC security to Grandma, your sister, even that crazy uncle. Is Santa bringing a new laptop this year? Make sure he installs VIPRE on it first! It defends against viruses, worms, spyware, Trojans, rootkits and other Internet threats without slowing down your new (or old) PCs. The VIPRE 2012 editions feature the latest threat definitions and are easier to install and use than ever before.&lt;/p&gt;&lt;p style="font-family: Georgia, 'Bitstream Charter', serif; font-size: 13px; margin-bottom: 24px; line-height: 18px; text-align: -webkit-auto; "&gt;This weekend’s VIPRE &lt;span style="color: #0000ff;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;a href="http://www.vipreantivirus.com/promos/black-friday/" style="color: rgb(0, 102, 204); "&gt;Black Friday Sale&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; makes it easy and affordable to keep your family safe online this holiday season (and in years to come). So take advantage of the lowest prices of 2011 while the deals last.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-5791442639006750680?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/5791442639006750680/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=5791442639006750680&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5791442639006750680'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5791442639006750680'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/vipre-black-friday-special.html' title='VIPRE Black Friday Special'/><author><name>Rogue Antispyware</name><uri>http://www.blogger.com/profile/06824519055198949802</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4154112031301276915</id><published>2011-11-22T07:13:00.001-05:00</published><updated>2011-11-22T07:13:34.369-05:00</updated><title type='text'>From porn stars to strippers: careful with name games</title><content type='html'>Way back in 2009, Sophos covered a bit of viral "fun" on Twitter where users of that service revealed their "porn star name" - comprised of your &lt;a href="http://nakedsecurity.sophos.com/2009/05/12/reveal-porn-star-twitter/"&gt;"first pet" and your "first street&lt;/a&gt;".&lt;br /&gt;&lt;br /&gt;Well, &lt;a href="http://paperghost.tumblr.com/post/13155247988/atraeathing-yukidama-goddessofcheese"&gt;look what's back&lt;/a&gt; in marginally altered form and racking up 8,000+ reblogs on Tumblr:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-RbPk4DPJRyM/TsuRN5PVqWI/AAAAAAAABuo/j760h93jr_M/s1600/strippernamewhoops.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="191" src="http://3.bp.blogspot.com/-RbPk4DPJRyM/TsuRN5PVqWI/AAAAAAAABuo/j760h93jr_M/s400/strippernamewhoops.gif" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Or, you know, don't. Stop and think how many services still ask for your pet name and street name on things such as password reset questions. Then pause to consider an email address you use may be public facing, and have just such a question bolted onto it.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;You may want to keep your clothes on and stick to the day job at that point...&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Christopher Boyd&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4154112031301276915?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4154112031301276915/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4154112031301276915&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4154112031301276915'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4154112031301276915'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/from-porn-stars-to-strippers-careful.html' title='From porn stars to strippers: careful with name games'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-RbPk4DPJRyM/TsuRN5PVqWI/AAAAAAAABuo/j760h93jr_M/s72-c/strippernamewhoops.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-3797908062999908930</id><published>2011-11-17T08:07:00.000-05:00</published><updated>2011-11-17T08:07:51.146-05:00</updated><title type='text'>Tumblr typo leads to iPad offers</title><content type='html'>Here's a curious instance of a URL similar to "Tumblr(dot)com that seems to have been around for a while, capitalising on any typo happy Tumblr user eager to post up an image.&lt;br /&gt;&lt;br /&gt;Skyrim - yes, &lt;a href="http://sunbeltblog.blogspot.com/2011/11/skyrim-scammery.html"&gt;this thing&lt;/a&gt; - has been a big deal on Tumblr of late and I noticed when clicking on the below image that it bounced me to an offers page rather than whatever the blogger &lt;i&gt;thought&lt;/i&gt; they'd linked to.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-wUE6d_DB8gM/TsTyIOGWNqI/AAAAAAAABt8/LNgaFS-0EkI/s1600/skytumb0.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="274" src="http://4.bp.blogspot.com/-wUE6d_DB8gM/TsTyIOGWNqI/AAAAAAAABt8/LNgaFS-0EkI/s320/skytumb0.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;You'll note the correct URL - ending in "Tumblr(dot)com" - is in the highlighted blue box on the right. However, the blogger has attempted to enter the same URL in the "image clickthrough" box highlighted in red but managed to type&amp;nbsp;littlemenbeingerased(dot)tumbr(dot)com instead. See that?&lt;br /&gt;&lt;br /&gt;Tumbr(dot)com. One missing "l" makes all the difference!&lt;br /&gt;&lt;br /&gt;An enterprising individual in China is responsible for that domain, and clicking the image makes this happen:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-9B6JDfNwBMg/TsT3ec_s7-I/AAAAAAAABuE/-Pjdzvf70-I/s1600/skytumb2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-9B6JDfNwBMg/TsT3ec_s7-I/AAAAAAAABuE/-Pjdzvf70-I/s1600/skytumb2.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;You're taken from the Tumblr blog to a site called "video-reward(dot)com, via a URL cloak website called "Secredir(dot)com".&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-fi5y0j22u-E/TsT-WWHBdkI/AAAAAAAABuc/Af5E1umO46c/s1600/skytumb5.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="198" src="http://2.bp.blogspot.com/-fi5y0j22u-E/TsT-WWHBdkI/AAAAAAAABuc/Af5E1umO46c/s320/skytumb5.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;At this point, all the free iPads in the World can be yours.&lt;br /&gt;&lt;br /&gt;Sort of.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-OpcJHG7iYTA/TsT5EbBQtyI/AAAAAAAABuM/U4vESPA1aRE/s1600/skytumb3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="179" src="http://1.bp.blogspot.com/-OpcJHG7iYTA/TsT5EbBQtyI/AAAAAAAABuM/U4vESPA1aRE/s320/skytumb3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-zPZvs1QvH1Y/TsT5uql4KTI/AAAAAAAABuU/4d_Q2RxH9CU/s1600/skytumb4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="168" src="http://1.bp.blogspot.com/-zPZvs1QvH1Y/TsT5uql4KTI/AAAAAAAABuU/4d_Q2RxH9CU/s320/skytumb4.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;This one costs "£3 per message", though they go to great pains to point out that this isn't a subscription service. I think I'd still rather skip this one either way.&lt;br /&gt;&lt;br /&gt;The Tumbr URL has been around since 2007, although a quick check of the &lt;a href="http://wayback.archive.org/web/*/http://tumbr.com"&gt;Internet Archive&lt;/a&gt; shows it's been flatlined since creation - nothing but generic landing page adverts for years. It only seems to have been reborn sometime in 2011, redirecting people to the Video-reward site that's been registered since 2011.&lt;br /&gt;&lt;br /&gt;Considering how popular Tumblr is, the owner of Tumbr(dot)com could be coining it in if even a small percentage of users are accidentally filling their blogs with it. Let's be thankful it's just offers and not malware...&lt;br /&gt;&lt;br /&gt;Christopher Boyd and Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-3797908062999908930?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/3797908062999908930/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=3797908062999908930&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3797908062999908930'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3797908062999908930'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/tumblr-typo-leads-to-ipad-offers.html' title='Tumblr typo leads to iPad offers'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-wUE6d_DB8gM/TsTyIOGWNqI/AAAAAAAABt8/LNgaFS-0EkI/s72-c/skytumb0.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-2139933138950302225</id><published>2011-11-14T00:26:00.001-05:00</published><updated>2011-11-14T00:39:56.283-05:00</updated><title type='text'>October Threats Bank on User Inexperience and Carelessness</title><content type='html'>This is what GFI Software Senior Threat Researcher Christopher Boyd &lt;a href="http://www.gfi.com/page/99387/gfi-labs-reports-on-cybercriminals-exploiting-search-engine-ads-and-user-inexperience"&gt;has revealed&lt;/a&gt; on Thursday, November 10, after the &lt;a href="http://sunbeltblog.blogspot.com/2011/11/with-rogue-av-its-more-than-game-of.html"&gt;release&lt;/a&gt; of &lt;a href="http://www.vipreantivirus.com/" style="font-weight: bold;"&gt;VIPRE Antivirus 2012&lt;/a&gt;&amp;nbsp;in the US and UK. He continues: "They count on users being too excited by an exclusive offer or too trusting of online advertisements to do their due diligence. Whether users are downloading software or inputting personal information online, they should always do everything they can to verify that they are visiting a legitimate website and not a well-crafted forgery."&lt;br /&gt;&lt;br /&gt;The complete report on this plus reminders on how to stay safe online as &lt;b&gt;Black Friday&lt;/b&gt; and &lt;b&gt;Cyber Monday&lt;/b&gt; draw near and the top 10 list of binary threats in October is found &lt;a href="http://www.gfi.com/page/99387/gfi-labs-reports-on-cybercriminals-exploiting-search-engine-ads-and-user-inexperience"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-2139933138950302225?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/2139933138950302225/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=2139933138950302225&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2139933138950302225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2139933138950302225'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/october-threats-bank-on-user.html' title='October Threats Bank on User Inexperience and Carelessness'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-3829698049234628372</id><published>2011-11-10T14:38:00.001-05:00</published><updated>2011-11-10T22:27:56.771-05:00</updated><title type='text'>PDF Malware is Back in Season</title><content type='html'>Avid readers of the GFI Labs blog can attest that they're no strangers to this kind of attack: one receives an email purporting to have come from a legitimate company with an attached &lt;b&gt;&lt;i&gt;Adobe&lt;/i&gt;&lt;/b&gt; .PDF file claiming that it's either a receipt, a document, or a ticket. Claims of what the attachment is supposed to be varies, but what remains consistent is that the email always instructs recipients to open it and / or save it on their computer. What happens more often is that systems get infected and users are left wondering what happened.&lt;br /&gt;&lt;br /&gt;Case in point—&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-vr5I7AC0h4o/Trws_Dt8pUI/AAAAAAAAAXA/OyHGCftsLjI/s1600/USPS_email01.png" imageanchor="1"&gt;&lt;img border="0" height="93" src="http://3.bp.blogspot.com/-vr5I7AC0h4o/Trws_Dt8pUI/AAAAAAAAAXA/OyHGCftsLjI/s320/USPS_email01.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i style="text-align: -webkit-auto;"&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Our researchers in the AV Labs have been seeing an uptick of this particular campaign, which pose as a message from the &lt;b&gt;United States Postal Service (USPS)&lt;/b&gt; and bears the subject "Package is was not able to be delivered please print out the attached label". The message body reads as follows:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Hello!&lt;br /&gt;&lt;br /&gt;Unfortunately we failed to deliver the postal package you have sent on the 19th of September in time because the recipient's address is erroneous.&lt;br /&gt;&lt;br /&gt;Please print out the shipment label attached and collect the package at our office.&lt;br /&gt;&lt;br /&gt;United States Postal Service&lt;br /&gt;&lt;br /&gt;{long line of unreadable characters}&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Here is what the attached file looks like once downloaded onto a system:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-wnWFovGk9wY/Trwtr07CJ5I/AAAAAAAAAXM/nw2k_fvlK9E/s1600/USPS_E_Mail_Icon.png" imageanchor="1"&gt;&lt;img border="0" height="67" src="http://4.bp.blogspot.com/-wnWFovGk9wY/Trwtr07CJ5I/AAAAAAAAAXM/nw2k_fvlK9E/s320/USPS_E_Mail_Icon.png" width="133" /&gt;&lt;/a&gt;&lt;/div&gt;When executed, it connects to the IP address, &lt;i&gt;91(dot)221(dot)98(dot)29&lt;/i&gt;, and downloads the file named &lt;i&gt;step.exe&lt;/i&gt;, which is a variant of &lt;b&gt;FakeSysDef&lt;/b&gt;, a rogue malware. It also checks on the following websites, all of which are from Russia:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;followmego12(dot)ru&lt;/li&gt;&lt;li&gt;hidemyfass87111(dot)ru&lt;/li&gt;&lt;li&gt;losokorot7621(dot)ru&lt;/li&gt;&lt;li&gt;mamtumbochka766(dot)ru&lt;/li&gt;&lt;/ul&gt;Doing site checks could mean a lot of potential actions this malware might do, like downloading other binaries / components onto the infected system, updating a copy of itself, posting information to these sites, or waiting for commands from its controller. As of this writing, the file does not download other binaries or additional component files.&amp;nbsp;Fortunately, we detect this malware as &lt;b&gt;Trojan.Win32.Generic!BT&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;As always, steer clear from these kinds of emails, especially if you haven't made transactions with such companies. When in doubt, double check with the supposed sender by calling their office for confirmation, but do not reply to the sender's email address. With Black Friday and Cyber Monday (not to mention Cyber Weekend and the holiday season) just around the corner and majority of the people everywhere are shopping online, it is wise to expect such attacks to multiply further in the coming days and weeks. Such an attack is not new; however, many are still falling for it. It's time to wise up.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Matthew, Robert, and Adam)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-3829698049234628372?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/3829698049234628372/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=3829698049234628372&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3829698049234628372'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3829698049234628372'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/pdf-malware-is-back-in-season.html' title='PDF Malware is Back in Season'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-vr5I7AC0h4o/Trws_Dt8pUI/AAAAAAAAAXA/OyHGCftsLjI/s72-c/USPS_email01.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-2851563704692095953</id><published>2011-11-10T12:34:00.000-05:00</published><updated>2011-11-10T12:34:05.596-05:00</updated><title type='text'>Skyrim Scammery</title><content type='html'>&lt;iframe allowfullscreen="" frameborder="0" height="315" src="http://www.youtube.com/embed/JSRtYpNRoN0" width="500"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;Everybody loves dragons, and everybody really loves hunting these endangered creatures through their natural habitat before plunging about five hundred spears into their evil, cattle stealing hearts.&lt;br /&gt;&lt;br /&gt;And so it came to pass that &lt;a href="http://en.wikipedia.org/wiki/The_Elder_Scrolls_V:_Skyrim"&gt;Skyrim&lt;/a&gt; would be released this weekend. It &lt;i&gt;also&lt;/i&gt; came to pass that people would make fake websites and try to convince Elves, Orcs and vertically challenged guys with axes to fill in surveys and install things in return for free games which never materialise.&amp;nbsp;Hitting the download buttons on all of the following sites will present the end-user with various surveys, offers of Adware and the occasional +10 damage modifier.&lt;br /&gt;&lt;br /&gt;Searching for "Skyrim download" in Google gives us results as early as page one promising riches but delivering bundles of Rocks Fall, Everybody Dies:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-tA5bRXTWs-I/Trv0tPGJncI/AAAAAAAABsc/RNYFlbg-hW8/s1600/skyrimscms1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-tA5bRXTWs-I/Trv0tPGJncI/AAAAAAAABsc/RNYFlbg-hW8/s320/skyrimscms1.png" width="314" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-fdv6Ks3PvxM/Trv0vArGXAI/AAAAAAAABsk/jFj-Fcj80Zw/s1600/skyrimscms2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="232" src="http://2.bp.blogspot.com/-fdv6Ks3PvxM/Trv0vArGXAI/AAAAAAAABsk/jFj-Fcj80Zw/s320/skyrimscms2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;"The Elder Scrolls V: Skyrim full version download for free", claims Mashgaming(dot)com. Hitting the link takes you to another website - links(dot)downloading(dot)im - and serves up Ye Olde Survey Box:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-BOX6ZFi7Cio/TrwAlVl08gI/AAAAAAAABss/Xlk5R_Q-SRc/s1600/skyrimscms8.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="199" src="http://2.bp.blogspot.com/-BOX6ZFi7Cio/TrwAlVl08gI/AAAAAAAABss/Xlk5R_Q-SRc/s320/skyrimscms8.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Here's another example of the same site, but this time presenting an Adware installer:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-n3KDi2Zu02A/TrwCBgBEnGI/AAAAAAAABtM/d9n3auOuK54/s1600/skyrimscms3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img border="0" height="267" src="http://1.bp.blogspot.com/-n3KDi2Zu02A/TrwCBgBEnGI/AAAAAAAABtM/d9n3auOuK54/s320/skyrimscms3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;Elsewhere, there are the typical Youtube scams you've come to know and hate, or at least roll your eyes at:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-YsjM3x5uwvU/TrwBihse1rI/AAAAAAAABs0/YdyhKi8CQnY/s1600/skyrimscms5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="252" src="http://3.bp.blogspot.com/-YsjM3x5uwvU/TrwBihse1rI/AAAAAAAABs0/YdyhKi8CQnY/s320/skyrimscms5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-s7cU_xKfgTo/TrwBkZcp7tI/AAAAAAAABs8/eqmxg__q4mc/s1600/skyrimscms6.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="209" src="http://3.bp.blogspot.com/-s7cU_xKfgTo/TrwBkZcp7tI/AAAAAAAABs8/eqmxg__q4mc/s320/skyrimscms6.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-iUDTMbwNTU8/TrwBlv7-35I/AAAAAAAABtE/mkIyGDJ-PtE/s1600/skyrimscms7.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="245" src="http://2.bp.blogspot.com/-iUDTMbwNTU8/TrwBlv7-35I/AAAAAAAABtE/mkIyGDJ-PtE/s320/skyrimscms7.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;I think they really want you to fill in those surveys. As the launch date for Skyrim is 11/11/11, you can bet there'll be the usual gamut of scams similar to the above doing the rounds - and the Mashgaming site listed above is now the second result in Google UK for "Skyrim download".&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-bCGl0W3tpmQ/TrwGi-MsEOI/AAAAAAAABtc/kaBIZfbEr28/s1600/skyrimscms9.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="207" src="http://4.bp.blogspot.com/-bCGl0W3tpmQ/TrwGi-MsEOI/AAAAAAAABtc/kaBIZfbEr28/s320/skyrimscms9.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Somewhat spectacularly, they nudge an official download site - Direct2drive - into third place with empty promises of games, goblins and gold.&lt;br /&gt;&lt;br /&gt;And you &lt;i&gt;still&lt;/i&gt; won't have killed any Dragons.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks Matthew)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-2851563704692095953?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/2851563704692095953/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=2851563704692095953&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2851563704692095953'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2851563704692095953'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/skyrim-scammery.html' title='Skyrim Scammery'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/JSRtYpNRoN0/default.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-2922687608243209029</id><published>2011-11-07T10:18:00.002-05:00</published><updated>2011-11-07T11:05:50.854-05:00</updated><title type='text'>S.N.A.P. Scam Will Make You Snap</title><content type='html'>It's no real surprise when we see how scammers ply their tricks&amp;nbsp;online&amp;nbsp;in order to dupe practically &lt;i&gt;anyone&lt;/i&gt;. They leave no room for distinction with regard to who they target. And why would they? When it comes to &lt;b&gt;online fraud&lt;/b&gt;, everyone is a cash cow, even those with little to live off of. &lt;br /&gt;&lt;br /&gt;Our AV Labs took a closer look at the website, &lt;i&gt;snap(dash)help(dot)com/step/go/1/0&lt;/i&gt;, that is posing as the domain for &lt;b&gt;Supplemental Nutrition Assistance Program (S.N.A.P.)&lt;/b&gt;,&amp;nbsp;otherwise known as the &lt;b&gt;Food Stamp Program&lt;/b&gt;. It's a "federal-assistance program that provides assistance to low- and no-income people and families living in the U.S. Though the program is administered by the U.S. Department of Agriculture, benefits are distributed by the individual U.S. states." &lt;href="http: en.wikipedia.org="" supplemental_nutrition_assistance_program"="" wiki=""&gt;Here's an &lt;a href="http://en.wikipedia.org/wiki/Supplemental_Nutrition_Assistance_Program"&gt;overview in Wikipedia&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/href="http:&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-x7pKycDV7GE/TrQmRPJ7AFI/AAAAAAAAAV0/q-E5WvHdzAI/s1600/SNAP_img1.png" imageanchor="1"&gt;&lt;img border="0" height="263" src="http://2.bp.blogspot.com/-x7pKycDV7GE/TrQmRPJ7AFI/AAAAAAAAAV0/q-E5WvHdzAI/s320/SNAP_img1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click image to enlarge&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;When Internet users enter a ZIP code in the field provided, they are directed to a page where they can register their details. After this, they are taken to another page, asking for their mobile numbers: &lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-chBawvQefdc/TrQmY8y2UnI/AAAAAAAAAWA/7QqlzsLnBbg/s1600/SNAP_img2.png" imageanchor="1"&gt;&lt;img border="0" height="263" src="http://4.bp.blogspot.com/-chBawvQefdc/TrQmY8y2UnI/AAAAAAAAAWA/7QqlzsLnBbg/s320/SNAP_img2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click image to enlarge&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Users who give out their mobile numbers will be subscribed to a premium SMS service. Should users have skipped entering their details in the registration page, they are then led to this page, which persists on asking for their mobile numbers...&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-MZoZ9400jAA/TrQmhsjjUcI/AAAAAAAAAWM/dhCsQj4LBGM/s1600/SNAP_img3.png" imageanchor="1"&gt;&lt;img border="0" height="263" src="http://4.bp.blogspot.com/-MZoZ9400jAA/TrQmhsjjUcI/AAAAAAAAAWM/dhCsQj4LBGM/s320/SNAP_img3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click image to enlarge&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;...and one can only wonder why this is without informing users why they have to enter this detail or how it will be used.&lt;br /&gt;&lt;br /&gt;"The entity responsible or the cellphone scam ad is &lt;i&gt;gtoffers(dot)com&lt;/i&gt;—GameTheory, LLC, &lt;a href="http://sunbeltblog.blogspot.com/2011/09/charitable-results.html"&gt;the same folks behind &lt;/a&gt;&lt;a href="http://socialribbons.org/wrappers/main.php"&gt;&lt;i&gt;&lt;b&gt;Social Ribbons&lt;/b&gt;&lt;/i&gt;&lt;/a&gt; and &lt;a href="http://www.openinstall.com/"&gt;&lt;b&gt;&lt;i&gt;OpenInstall&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;," said Eric Howes, Security Product Manager at GFI. "GameTheory, LLC is the company responsible for the blitz of &lt;b&gt;Zugo&lt;/b&gt;—installing &lt;i&gt;Zombie Me&lt;/i&gt; / &lt;i&gt;Vampire Me&lt;/i&gt; / &lt;i&gt;Make My Baby&lt;/i&gt; ads on &lt;i&gt;Facebook&lt;/i&gt;...until Matt Cutts &lt;a href="https://plus.google.com/109412257237874861202/posts/FXL1y8qG7YF"&gt;exposed&lt;/a&gt; the operation." &lt;br /&gt;&lt;br /&gt;An insightful exchange regarding the relationships of the&amp;nbsp;above-mentioned&amp;nbsp;companies can also be read and followed in that exposé.&lt;br /&gt;&lt;br /&gt;This is &lt;a href="http://blog.spywareguide.com/2009/01/cashing-in-on-obama-stimulus-p.html"&gt;not the first time&lt;/a&gt; something like this happened and who knows how many more are out there. &lt;br /&gt;&lt;br /&gt;If you want to avail of the SNAP program, visit &lt;a href="http://www.snap-step1.usda.gov/fns/"&gt;this&lt;/a&gt; page instead.&amp;nbsp;Notice the ".gov" extension of the domain? That's the legitimate government site, while the dodgy one is evidently a ".com".&lt;br /&gt;&lt;br /&gt;We implore to users to be careful and be sure that the sites they're visiting should only be legitimate ones. Scam sites are at large in the Net. While scammers will take the deplorable step of targeting those less fortunate, there are plenty of online sources where free advice and assistance can be found.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;Jovi Umawing (Thanks to Eric and Matthew)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-2922687608243209029?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/2922687608243209029/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=2922687608243209029&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2922687608243209029'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2922687608243209029'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/snap-scam-will-make-you-snap.html' title='S.N.A.P. Scam Will Make You Snap'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-x7pKycDV7GE/TrQmRPJ7AFI/AAAAAAAAAV0/q-E5WvHdzAI/s72-c/SNAP_img1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-3164056364583046500</id><published>2011-11-07T08:32:00.002-05:00</published><updated>2011-11-07T08:36:53.855-05:00</updated><title type='text'>Is RiRi in the Headlines Again?</title><content type='html'>Fortunately, this is not the freshest Rihanna scoop you've missed on TMZ.&amp;nbsp;It's a &lt;b&gt;&lt;i&gt;Facebook&lt;/i&gt; &lt;/b&gt;post I just found that set the alarm bells in my head, so I set out to investigate.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-g-F7smCIU7Q/TrfMUJ-XkFI/AAAAAAAAAWk/uoH-u_LVgjY/s1600/ezrealityscam4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="105" src="http://3.bp.blogspot.com/-g-F7smCIU7Q/TrfMUJ-XkFI/AAAAAAAAAWk/uoH-u_LVgjY/s320/ezrealityscam4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Clicking the link of this supposedly scandalous video leads to this page (Note that the URL is already something outside of the said social networking site, which is &lt;i&gt;ezreality(dot)tk/)&lt;/i&gt;:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Z0esuvbnBP8/TrfMJexSOfI/AAAAAAAAAWc/Rd50Hq6EO1I/s1600/ezrealityscam1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-Z0esuvbnBP8/TrfMJexSOfI/AAAAAAAAAWc/Rd50Hq6EO1I/s320/ezrealityscam1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Clicking the play button of the player displays a text on the screen which says:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Restriction: To start the video, please share it again and click the &amp;gt;&amp;gt; play &amp;lt;&amp;lt; button&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;If users click the &lt;i&gt;Share&lt;/i&gt; button, they are sent to the legitimate&amp;nbsp;&lt;i&gt;Facebook&lt;/i&gt; login page where they can enter their credentials if they're not logged in.&lt;i&gt;&amp;nbsp;&lt;/i&gt;If they are, a browser window opens to show them exactly what will be posted on their&amp;nbsp;&lt;i&gt;Facebook&lt;/i&gt; wall.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-4-awKAP39Sk/TrfNrZuTKMI/AAAAAAAAAWs/ZrC1pkhoWog/s1600/ezrealityscam2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="176" src="http://4.bp.blogspot.com/-4-awKAP39Sk/TrfNrZuTKMI/AAAAAAAAAWs/ZrC1pkhoWog/s320/ezrealityscam2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Sharing this video, as it turns out, is not an option. If users ignore the text displayed on the screen and click the play button the second time, a window pops up to remind them that they have to share the video before it can be played. There's no way around this one.&lt;br /&gt;&lt;br /&gt;Once shared and the the play button is hit, users are led to a video of Rihanna overlaid with a survey:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-vPPCGD1WTP8/TrfSQhDf2qI/AAAAAAAAAW0/EBfg8shTQAE/s1600/ezrealityscam3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="225" src="http://1.bp.blogspot.com/-vPPCGD1WTP8/TrfSQhDf2qI/AAAAAAAAAW0/EBfg8shTQAE/s320/ezrealityscam3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Survey scams have been plaguing &lt;i&gt;Facebook &lt;/i&gt;users for the longest time, and scammers never fail to get someone to click on their links—and a lot of users are falling for these. It's not that the scammers' technique is sophisticated enough. It's how they socially engineer scams to make them too interesting for anyone to pass up. Below are a just few of these scams on this social networking site that we've spotted:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://sunbeltblog.blogspot.com/2011/05/to-know-or-not-to-know-that-is-facebook.html"&gt;To Know or Not to Know: That is the Facebook Question&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://sunbeltblog.blogspot.com/2011/09/fake-bbc-video-facebook-scam-returns.html"&gt;The fake BBC video Facebook scam returns&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://sunbeltblog.blogspot.com/2011/03/profile-watch-pops-surveys-on-facebook.html"&gt;Profile Watch pops surveys on Facebook&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;We encourage users to abide by this general safety rule when browsing &lt;i&gt;Facebook&lt;/i&gt;: Refrain from clicking links, especially those that come with a video, from anyone on your stream that has a titillating, if not controversial, hook. More than likely, it's just bait for something nasty in the end.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Chris for the assist)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-3164056364583046500?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/3164056364583046500/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=3164056364583046500&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3164056364583046500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3164056364583046500'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/is-riri-in-headlines-again.html' title='Is RiRi in the Headlines Again?'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-g-F7smCIU7Q/TrfMUJ-XkFI/AAAAAAAAAWk/uoH-u_LVgjY/s72-c/ezrealityscam4.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-2369891452255746907</id><published>2011-11-02T10:49:00.000-04:00</published><updated>2011-11-02T10:49:07.360-04:00</updated><title type='text'>With Rogue AV, It's More Than a Game of "Spot What's Different"</title><content type='html'>&lt;b&gt;Rogue AV&lt;/b&gt; has been one of the biggest profit-generating schemes for cybercriminals since its inception. These past few months, however, our team in the AV Labs has seen a decline, and this is due to a combination of factors, including continued coverage of these scams in non-technical news sources, efforts on the part of the &lt;a href="http://www.zdnet.com/blog/security/microsoft-kills-botnet-that-hosted-macdefender-scareware/9495"&gt;security community&lt;/a&gt;, and &lt;a href="http://www.fbi.gov/news/pressrel/press-releases/department-of-justice-disrupts-international-cybercrime-rings-distributing-scareware"&gt;law enforcement&lt;/a&gt; continuing to combat rogue AV scams around the globe.&lt;br /&gt;&lt;br /&gt;As they have many times before, cybercriminals are changing their tactics, but I doubt they’ll abandon rogue AV entirely. Considering the expertise they’ve developed for &lt;b&gt;black hat SEO (BHSEO)&lt;/b&gt;, it’s wise to always be on the lookout for rogues whenever a hot topic arises.&lt;br /&gt;&lt;br /&gt;Our researchers also are observinge sites distributing fake AV via toolbars, video players and other misleading, fraudulent installers aside from the plain “vanilla” installs we’ve seen in the past, proving as long long as cybercriminals continue to profit from a scheme, &lt;a href="http://www.esecurityplanet.com/trends/article.php/3938581/Rogue-Antivirus-Here-to-Stay.htm"&gt;they will stick with it&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The decrease we’re seeing may very well be temporary, but it’s really too early to say. Remaining vigilant ourselves and aware of what’s new with fake AV is the best way to keep users from falling victim. However, with increased awareness, I believe scammers will be forced to change tactics yet again, potentially in more radical ways than we’ve seen before to ensure end-users continue to be tricked.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-XdfEDv997pQ/TrFQrza5hII/AAAAAAAAAVo/qWCxTSgIQG4/s1600/rogueAV_table.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="282" src="http://2.bp.blogspot.com/-XdfEDv997pQ/TrFQrza5hII/AAAAAAAAAVo/qWCxTSgIQG4/s320/rogueAV_table.png" width="320" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Pretty convincing, right? Are you confident that all the employees in your organization or all the users in your household would know that their PC has been infected and that’s not a legitimate AV program offering them advice and asking for their credit card? &lt;br /&gt;&lt;br /&gt;And remember not everything with a snake logo is legit. Below is an example of a rogue AV trying to mimic VIPRE Antivirus:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-cePM34C_nac/TrEMyET5QiI/AAAAAAAAAUk/SYru3D3d2Ys/s1600/ripoff.bmp" imageanchor="1"&gt;&lt;img border="0" height="246" src="http://1.bp.blogspot.com/-cePM34C_nac/TrEMyET5QiI/AAAAAAAAAUk/SYru3D3d2Ys/s320/ripoff.bmp" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;When it comes to VIPRE, accept no substitute.&lt;br /&gt;&lt;br /&gt;Below is an exclusive first look at &lt;a href="http://www.vipreantivirus.com/"&gt;VIPRE Antivirus 2012 and VIPRE Internet Security 2012&lt;/a&gt;, released today in the U.S. and U.K..&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-wiuOqVKCuzc/TrEOOsr5buI/AAAAAAAAAUw/R52isZP-8Gg/s1600/VIPRE_AV2012.png" imageanchor="1"&gt;&lt;img border="0" height="87" src="http://3.bp.blogspot.com/-wiuOqVKCuzc/TrEOOsr5buI/AAAAAAAAAUw/R52isZP-8Gg/s320/VIPRE_AV2012.png" width="320" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a href="http://4.bp.blogspot.com/-42zeeOugdig/TrEOc1iR5DI/AAAAAAAAAU8/kDy2NmX0ltU/s1600/VIPRE_IS2012.png" imageanchor="1"&gt;&lt;img border="0" height="82" src="http://4.bp.blogspot.com/-42zeeOugdig/TrEOc1iR5DI/AAAAAAAAAU8/kDy2NmX0ltU/s320/VIPRE_IS2012.png" width="320" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-8HlB9WlW82g/TrEOduDfZKI/AAAAAAAAAVk/lkVQw8cI5WI/s1600/VIPRE_console.png" imageanchor="1"&gt;&lt;img border="0" height="232" src="http://1.bp.blogspot.com/-8HlB9WlW82g/TrEOduDfZKI/AAAAAAAAAVk/lkVQw8cI5WI/s320/VIPRE_console.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;Getting familiar with the actual, legitimate names and interfaces of AV software you, your business and your family use is one way for users to spot a fake. And cybercriminals generally target those who are not in the know.&lt;br /&gt;&lt;br /&gt;The fight against online threats is a community and individual effort. GFI Software, together with other AV and security companies, is striving to keep the Internet a safe place. We encourage users to do their part. For users who become infected with rogue AV, GFI tracks the latest variants on its &lt;a href="http://malwareprotectioncenter.com/"&gt;Malware Protection Center blog&lt;/a&gt;. There, users can find more information, screen shots, and removal tips.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-2369891452255746907?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/2369891452255746907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=2369891452255746907&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2369891452255746907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2369891452255746907'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/with-rogue-av-its-more-than-game-of.html' title='With Rogue AV, It&apos;s More Than a Game of &quot;Spot What&apos;s Different&quot;'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-XdfEDv997pQ/TrFQrza5hII/AAAAAAAAAVo/qWCxTSgIQG4/s72-c/rogueAV_table.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-1305203437197366391</id><published>2011-11-02T05:06:00.001-04:00</published><updated>2011-11-02T05:06:23.359-04:00</updated><title type='text'>Arkham Shifty</title><content type='html'>&lt;iframe allowfullscreen="" frameborder="0" height="315" src="http://www.youtube.com/embed/-VaQfsRQ65w" width="500"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;Hey look, a new Batman game. Would it surprise anybody to find Ye Olde Scam Sites touting fake Downloadable Content Generators that want you to fill in a survey before downloading them?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://webcache.googleusercontent.com/search?q=cache:SIRhlIslA7EJ:www.gamespot.com/ps3/action/batman-arkham-city/show_msgs.php%3Fpid%3D981375%26topic_id%3Dm-1-60823708+robincharacterdlcfree.info&amp;amp;cd=10&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;gl=uk"&gt;Not really&lt;/a&gt;, but here's a site claiming to give away free "Play as Robin" codes anyway located at&amp;nbsp;robincharacterdlcfree(dot)info.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-ZYVbkEUz6F0/TrEECzD6EhI/AAAAAAAABr0/pVaAbRdkiHk/s1600/batmanarkhamdlc1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="228" src="http://3.bp.blogspot.com/-ZYVbkEUz6F0/TrEECzD6EhI/AAAAAAAABr0/pVaAbRdkiHk/s320/batmanarkhamdlc1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;As with every type of scam like this ever, you're offered (fake) programs that supposedly unlock download codes for both XBox and PS3 versions.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-t9PA-_nTJH4/TrEEF2lweqI/AAAAAAAABr8/x19duAx2c0c/s1600/batmanarkhamdlc2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="277" src="http://2.bp.blogspot.com/-t9PA-_nTJH4/TrEEF2lweqI/AAAAAAAABr8/x19duAx2c0c/s320/batmanarkhamdlc2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Click the "Download now" button, and you're taken to the below survey offer.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-MTH7jfy1boE/TrEEG-eEH-I/AAAAAAAABsE/0vTSrnFrTTw/s1600/batmanarkhamdlc3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="254" src="http://4.bp.blogspot.com/-MTH7jfy1boE/TrEEG-eEH-I/AAAAAAAABsE/0vTSrnFrTTw/s320/batmanarkhamdlc3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Humorously, this one offers a "PDF download" guide to assist you in redeeming your code - but clicking that link also takes you to survey offers. In all cases, websites such as the above should be avoided - they're just pushing dummy files or infections.&lt;br /&gt;&lt;br /&gt;They're the scams Gotham deserve, but not the ones it needs right now. So we'll hunt the close browser button.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (hat tip to "BatMannon". No, really.)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-1305203437197366391?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/1305203437197366391/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=1305203437197366391&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1305203437197366391'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1305203437197366391'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/11/arkham-shifty.html' title='Arkham Shifty'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/-VaQfsRQ65w/default.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-913217443184817808</id><published>2011-10-31T15:08:00.000-04:00</published><updated>2011-10-31T15:34:15.335-04:00</updated><title type='text'>A little too chatty?</title><content type='html'>There's a program called &lt;b&gt;ChatSend &lt;/b&gt;currently doing the rounds on &lt;b&gt;Facebook&lt;/b&gt;, and at time of writing just over 114,000 people have hit the "Like" button which no doubt means a high proportion of that tally&amp;nbsp;have downloaded and installed it. Including one in my stream—&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-rcJezSfb0F0/Tq7FU_pywVI/AAAAAAAAAT0/FPh4bmuM4WU/s1600/chtsend4.png" imageanchor="1"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-rcJezSfb0F0/Tq7FU_pywVI/AAAAAAAAAT0/FPh4bmuM4WU/s1600/chtsend4.png" /&gt;&lt;/a&gt;&lt;/div&gt;The link directs to the &lt;i&gt;Facebook&lt;/i&gt; page of ChatSend where one can readily download the app. Upon execution, it shows a GUI containing its Terms of Service and Privacy Policy. The GUI, however, is narrow and the text is not wrapped within the width of the text box, which makes it difficult for users to read as they need to scroll from left to the farthest right.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-dFd5zRY94KI/Tq7GjzOoM_I/AAAAAAAAAUA/-bWyziJdyYc/s1600/chtsend1.png" imageanchor="1"&gt;&lt;img border="0" height="311" src="http://4.bp.blogspot.com/-dFd5zRY94KI/Tq7GjzOoM_I/AAAAAAAAAUA/-bWyziJdyYc/s400/chtsend1.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Note the pre-ticked boxes that will install the toolbar in all browsers, set web search as default and change the homepage.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-zxwI01JUreQ/Tq7Go5kx8XI/AAAAAAAAAUM/m4iGHGVUlDY/s1600/chtsend2.png" imageanchor="1"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-zxwI01JUreQ/Tq7Go5kx8XI/AAAAAAAAAUM/m4iGHGVUlDY/s1600/chtsend2.png" /&gt;&lt;/a&gt;&lt;/div&gt;After installing, a window pops up to inform users that there has been an error in installing the program; however, it installs just fine.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-b1K_BeZ9rF8/Tq7ibz3pfbI/AAAAAAAABrc/h6tImdcscYQ/s1600/chtsend3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="187" src="http://3.bp.blogspot.com/-b1K_BeZ9rF8/Tq7ibz3pfbI/AAAAAAAABrc/h6tImdcscYQ/s320/chtsend3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;click to enlarge&lt;/i&gt;&lt;/div&gt;Not only does the program send the message seen in the first screenshot without notification, it also&amp;nbsp;sends the same message via &lt;i&gt;Facebook&lt;/i&gt; chat (if enabled) to all, too.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-JD83G0d-X-4/Tq7nRx3EcYI/AAAAAAAABrk/8T9Dx1F1cog/s1600/chtsend5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-JD83G0d-X-4/Tq7nRx3EcYI/AAAAAAAABrk/8T9Dx1F1cog/s1600/chtsend5.png" /&gt;&lt;/a&gt;&lt;/div&gt;Interestingly, the EULA fails to detail the steps on how to uninstall the application should users change their mind about it when it was clearly stated:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"If you wish to withdraw your consent to any of ChatSend features as described herein, you should uninstall the Software from your computer. Uninstall instructions are detailed above."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;As far as we can see, there are no instructions "detailed above". The uninstall steps are in their &lt;i&gt;Facebook&lt;/i&gt; page (added yesterday) under the &lt;a href="https://www.facebook.com/ChatSend?sk=app_202980683107053&amp;amp;app_data=f138c7d0-87c1-4b95-b3f8-c290f988eb8b%3A0"&gt;FAQ tab&lt;/a&gt; when clearly it should be included in the EULA. Despite this, uninstalling simply requires a visit to Add / Remove programs, or opening up the browser add on tabs in your browser of choice.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-CzSnqKFvAAM/Tq7sBeOJ3rI/AAAAAAAABrs/O-IHB3qiVzk/s1600/fbsendchtsend6.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-CzSnqKFvAAM/Tq7sBeOJ3rI/AAAAAAAABrs/O-IHB3qiVzk/s1600/fbsendchtsend6.png" /&gt;&lt;/a&gt;&lt;/div&gt;Do keep an eye on this one, Dear Reader, because&amp;nbsp;&lt;i&gt;Facebook&lt;/i&gt; blocks any URLs / links related to the ChatSend domain and there's quite a few posts like &lt;a href="https://www.facebook.com/help/community/question/?id=1659498"&gt;this&lt;/a&gt; starting to appear on help pages.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-77zsK7AKKmA/Tq7HXwxI9WI/AAAAAAAAAUY/F_XVHXX9_LE/s1600/fb_block.png" imageanchor="1"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-77zsK7AKKmA/Tq7HXwxI9WI/AAAAAAAAAUY/F_XVHXX9_LE/s1600/fb_block.png" /&gt;&lt;/a&gt;&lt;/div&gt;Jovi Umawing (Thanks to Chris for the assist)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-913217443184817808?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/913217443184817808/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=913217443184817808&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/913217443184817808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/913217443184817808'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/little-too-chatty.html' title='A little too chatty?'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-rcJezSfb0F0/Tq7FU_pywVI/AAAAAAAAAT0/FPh4bmuM4WU/s72-c/chtsend4.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-7862800067041628853</id><published>2011-10-30T17:00:00.000-04:00</published><updated>2011-10-30T17:00:29.478-04:00</updated><title type='text'>Then: "co.cc", Now: "ce.ms"</title><content type='html'>Not all netizens were happy when &lt;a href="http://googleonlinesecurity.blogspot.com/2011/06/protecting-users-from-malware-hosted-on.html"&gt;Google decided to pull the plug on "co.cc" domains&lt;/a&gt; last June, but it's a resounding win for those in the security industry. It had to be done as cybercriminals are creating free domains with the "co.cc" extension by the bulk &lt;a href="http://www.theregister.co.uk/2011/07/06/google_cans_11m_dot_co_dot_cc_sites/"&gt;to house and distribute their nasty binaries and fake AV&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Late last week, our friends at Zscaler &lt;a href="http://research.zscaler.com/2011/10/now-cems-free-domains-are-being-used-to.html"&gt;discovered&lt;/a&gt; that cyberciminals have now moved to hosting their wares on "ce.ms" domains (.ms being&amp;nbsp;the top-level domain for Montserrat, an island in the West Indies).&amp;nbsp;A simple &lt;i&gt;Google&lt;/i&gt; search led me to several forums and personal blog posts as early as June of this year complaining about getting fake AVs from such sites, with the Zscaler discovery looking much more complex.&lt;br /&gt;&lt;br /&gt;Of course, not all websites using free domains are malicious, but they are popular with those looking to infect your PC so please be careful if you see a suspicious looking URL combined with a free domain or you may end up with more than you bargained for.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-7862800067041628853?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/7862800067041628853/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=7862800067041628853&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7862800067041628853'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7862800067041628853'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/then-cocc-now-cems.html' title='Then: &quot;co.cc&quot;, Now: &quot;ce.ms&quot;'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-7458118724541114052</id><published>2011-10-27T12:21:00.002-04:00</published><updated>2011-10-27T12:24:28.377-04:00</updated><title type='text'>Shop 'Till You Realized You Got Dropped On</title><content type='html'>&lt;blockquote&gt;&lt;i&gt;&lt;b&gt;From:&lt;/b&gt; info@eteam.org&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;Subject:&lt;/b&gt; {Definitely Spam?} SECRET SHOPPING JOB AVAILABLE/URGENT REPLY NEEDED&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;Message body:&lt;/b&gt;"We have a mystery shopping assignment in your area and we would like you to participate"&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Secret Shopper(R) is accepting applications for qualified individuals to become mystery shoppers. It's fun and rewarding, and you choose when and where you want to shop. You are never obligated to accept an assignment.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;There is no charge to become a shopper and you do not need previous experience. After you sign up, you will have access to training materials via e-mail, fax or postal mail.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;ABOUT US&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Secret Shopper(R) is the premier mystery shopping company, serving clients across America with over 500,000 shoppers available and ready to help businesses better serve their customers. Continual investment in the latest internet and communication technologies coupled with over 16 years of know-how means working with Secret Shopper(R) is a satisfying and rewarding experience.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Secret shopping as seen on ABC NEWS, NBC NEWS, L.A.TIMES.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Stores and organizations such as The Gap, Walmart, Pizza Hut, and Bank. One amongst many others pay for Secret Shoppers to shop in their establishments and report their experiences. On top of being paid for shopping you are also allowed to keep purchases for free. Secret Shopper(R) NEVER charge fees to the shopper. Training, tips for improvement, and shopping opportunities are provided free to registered shoppers. Mystery shoppers are either paid a pre-arranged fee for a particular shop, a reimbursement for a purchase or a combination of both.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;You will be required to interact with the shop clerk.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;You may conduct the shop alone or as a couple.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;The assignment will pay $200.00/ Assignment&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Kindly Fill Out the application form below and we will get back to you shortly with the assignment to this email&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;PERSONAL INFORMATION:&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;First Name:&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Last Name:&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Street Address:&lt;/i&gt;&lt;br /&gt;&lt;i&gt;City, State, Zip Code:&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Cell Phone Number:&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Home Phone Number:&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;AVAILABILITY:&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Days/Hours Available&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Monday .............................................&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Tuesday .............................................&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Wednesday .............................................&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Thursday .............................................&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Friday .............................................&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Saturday .............................................&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Sunday .............................................&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Hours Available: from _______ to ______&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;We await your urgent response.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Thank you for your help.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;We look forward to working with you.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Sincerely,&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Frank James&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Secret Shopper(R)&lt;/i&gt;&lt;/blockquote&gt;&lt;br /&gt;If you've received the above email in your inbox and thought to yourself, "This is a scam!"—&lt;a href="http://www.419scam.org/emails/2010-08/05/00000864.1.htm"&gt;you are right&lt;/a&gt;. It's a &lt;b&gt;419 scam&lt;/b&gt; that gives off that too-ludicrously-good-to-be-true vibes and doesn't really want you to be a secret shopper but would love to have your money, if not information that personally identifies you, which is exactly the case for this particular scam.&lt;br /&gt;&lt;br /&gt;There's nothing generally new about this one since it began making its rounds in the later part of 2010 apart from the "&lt;i&gt;{Definitely Spam?}&lt;/i&gt;" on the subject line, as if challenging recipients to suddenly question their earlier conclusion of it being something other than legitimate.&lt;br /&gt;&lt;br /&gt;Don't fall for it. Don't fall for it. Don't fall for it.&lt;br /&gt;&lt;br /&gt;Despite the abundant and readily available information on the Web, people are still ending up victims to such scams. And, sadly, the worst thing that could happen is that in the end,&amp;nbsp;&lt;a href="http://consumerist.com/2011/10/womans-late-brother-pays-217000-to-online-scammers-now-shes-facing-foreclosure.html"&gt;someone other than the victim pays the price&lt;/a&gt;. These false promises scammers make may seem&amp;nbsp;irresistible&amp;nbsp;to pass up, but believing an email from someone you don't know who offers to help you make money in exchange for your information (but more often than not, money) should be a cause for alarm.&lt;br /&gt;&lt;br /&gt;So how does one spot a 419 scam? There are a lot of articles available on-line for that, too, but I think &lt;a href="http://ezinearticles.com/?How-to-Spot-a-419-Scam&amp;amp;id=1525979"&gt;this&lt;/a&gt; is more complete than the rest. It's quite an old post but still holds some wisdom. &lt;a href="http://www.419scam.org/419faq.htm"&gt;Here&lt;/a&gt;&amp;nbsp;is a more straight-forward FAQ page.&lt;br /&gt;&lt;br /&gt;If you suspect that you received is a 419 scam mail, ignore or delete it from your inbox. If you want to be more proactive, check out &lt;a href="http://www.419scam.org/419scam.htm#what"&gt;this page&lt;/a&gt; for who to report it to. Most importantly, tell your friends and family members about this scam.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Wendy)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-7458118724541114052?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/7458118724541114052/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=7458118724541114052&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7458118724541114052'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7458118724541114052'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/shop-till-you-realized-you-got-dropped.html' title='Shop &apos;Till You Realized You Got Dropped On'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-6064996760426048135</id><published>2011-10-26T12:50:00.000-04:00</published><updated>2011-10-27T12:32:57.685-04:00</updated><title type='text'>Honing in on Child Security</title><content type='html'>The &lt;a href="http://www.iwf.org.uk/"&gt;Internet Watch Foundation (IWF)&lt;/a&gt; is an organization formed and is based in the UK that basically &lt;a href="http://www.iwf.org.uk/about-iwf/remit-vision-and-mission"&gt;aims&lt;/a&gt; to protect children from "child sexual abuse images online", in partnership with the netizens and the police. Today, October 26 marks the 2011 IWF Awareness Day, a day of taking part in reaching out to people via the Internet and other media to inform people that there &lt;i&gt;is&lt;/i&gt; a contact / hotline they could actually connect with to report "criminal on-line content".&lt;br /&gt;&lt;br /&gt;Organizations, such as IWF, are not the only ones who can do something to keep children safe&amp;nbsp;on-line. Parents and every adult are and should be the prime movers of this great effort. I've listed here other risks and dangers&amp;nbsp;children might encounter whenever they go&amp;nbsp;on-line,&amp;nbsp;apart from the usual age-inappropriate content we're all too familiar with:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;(1) Web threats that are under the radar.&lt;/b&gt; This is especially true in social networking sites that young people frequent to more often. Since such sites are all about socializing and sharing, it is always possible for anyone to share links to locations where children could divulge their personal information or lead them download malware onto the system. The threat may also come in the form of advertisements, widgets, and apps served within a domain.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;(2) Commercialism in its most crude and intrusive way.&lt;/b&gt; A lot of businesses—legitimate or otherwise—now have an online presence. Either way, some of these businesses lure adults and children alike to avail of products and services in exchange for personal information (e.g. filling in an online form) or money. Some of these services may be inappropriate for children, such as dating sites, gambling sites, and the like. The information used in signing up for them can be used for obtrusive advertising via pop-ups, spam, and even identity theft.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;(3) Unwanted attention from others.&lt;/b&gt; Since the internet is just an extension of the real world, children might bump into sexual predators, bullies, and stalkers&amp;nbsp;on-line&amp;nbsp;without them realizing. It is not at all bad to meet new people, but when one is online, anyone could be whoever they want you to be.&lt;br /&gt;&lt;br /&gt;Oh, one more thing: It is also a risk for children to take part or participate in any act of misbehaviour toward others and organizations, and by that we meant (a) they are cyberbullies themselves, (b) they&amp;nbsp;harass other kids, (c) putting up lewd, inept, and generally disrespectful comments, and (d) being themselves the source of&amp;nbsp;on-line&amp;nbsp;threats. These and probably more, they can do because of the&amp;nbsp;anonymity of the Internet. Of course, as we've been seeing in the news, such actions only come back to bite the doers one way or another.&lt;br /&gt;&lt;br /&gt;It is of utmost importance that parents and responsible adults are aware of what these threats are so that they can caution children under their care and educate them on how to respond. It is also important that parents and adults know what their children are doing on-line, because the worst possible danger they could get themselves into could be something self-inflicted.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-6064996760426048135?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/6064996760426048135/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=6064996760426048135&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6064996760426048135'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6064996760426048135'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/honing-in-on-child-security.html' title='Honing in on Child Security'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4042160841629664505</id><published>2011-10-24T15:35:00.000-04:00</published><updated>2011-10-24T22:52:16.239-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mobile'/><category scheme='http://www.blogger.com/atom/ns#' term='vm'/><category scheme='http://www.blogger.com/atom/ns#' term='vb2011'/><category scheme='http://www.blogger.com/atom/ns#' term='research'/><category scheme='http://www.blogger.com/atom/ns#' term='Faraday cage'/><category scheme='http://www.blogger.com/atom/ns#' term='podcast'/><category scheme='http://www.blogger.com/atom/ns#' term='openBTS'/><category scheme='http://www.blogger.com/atom/ns#' term='symbian'/><category scheme='http://www.blogger.com/atom/ns#' term='android'/><category scheme='http://www.blogger.com/atom/ns#' term='replication jail'/><title type='text'>Replication Jails: The Why Before the How</title><content type='html'>&lt;a href="http://net-security.org/article.php?id=1639"&gt;&lt;i&gt;This&lt;/i&gt;&lt;/a&gt; is probably one of the coolest podcasts I've listened to of late.&lt;br /&gt;&lt;br /&gt;It is presented by Axelle Apvrille, Senior Mobile Antivirus Analyst and Researcher at Fortinet and she discussed how security enthusiasts can create or setup a testing environment called a&amp;nbsp;&lt;b&gt;replication jail&lt;/b&gt;&amp;nbsp;for mobile phones while not breaking the bank. To put it simply, a replication jail to a mobile device is what a virtual machine (VM) is to a PC. The similarity between the two ends there, however.&lt;br /&gt;&lt;br /&gt;In the cast, Apvrille pointed out that it is difficult to isolate an environment for testing for mobile phones (for security's sake) while at the same time allowing malware to behave the way it's supposed to behave while inside an infected phone (for veritability's sake). Current methods of isolation—like manually removing the SIM, using emulators, and setting up a &lt;a href="http://www.jeddaniels.com/2007/faraday-cage-part-1/"&gt;Faraday cage&lt;/a&gt;—in order to prevent the threat from spreading to other mobile phones within a network are found to be flawed,&amp;nbsp;Apvrille said. So in keeping with the objectives of what a testing environment should be, she proposed building up an exclusive operator network using &lt;a href="http://en.wikipedia.org/wiki/OpenBTS" style="font-weight: bold;"&gt;OpenBTS&lt;/a&gt;, a free "software-based GSM access point". She explains how this is done &lt;a href="http://net-security.org/article.php?id=1639"&gt;here&lt;/a&gt;. Check. it. Out.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4042160841629664505?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4042160841629664505/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4042160841629664505&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4042160841629664505'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4042160841629664505'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/replication-jails-why-before-how.html' title='Replication Jails: The Why Before the How'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-8895792720044625237</id><published>2011-10-23T08:53:00.000-04:00</published><updated>2011-10-23T08:53:05.915-04:00</updated><title type='text'>Where in the World is Razim Al Hamed?</title><content type='html'>Here's a Spanish language Facebook scam about the "World's richest man" giving away thousand dollar cheques to anybody that wants one.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You could probably write "Oh dear" and leave it at that, but let's take a peek anyway. Scams involving a chap called "Razim&amp;nbsp;Al Hamed" have been bouncing around since at least 2009, and he's quite the subject of intrigue and mystery - or at least posts on &lt;a href="http://answers.yahoo.com/question/index?qid=20110105195540AAeAIh0"&gt;Yahoo Answers&lt;/a&gt;. He pops up on &lt;a href="http://weasdemierda.tumblr.com/post/2193956053/razim-al-hamed-y-facebook"&gt;Tumblr&lt;/a&gt;. He has an &lt;a href="http://3.bp.blogspot.com/_BiLh3Rw-NDc/TRDVATgfPBI/AAAAAAAAAaA/7WQnXB47AUI/s1600/Imagen+2.png"&gt;interesting set of search results&lt;/a&gt; in Google. He's super rich, yet you've seemingly never heard of the guy.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;He's appeared on various "have some free money" sites in the past, and will continue to do so but&amp;nbsp;1000dolares(dot)org is the one we'll look at today.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-PCp16DlZkHY/TqP97urF65I/AAAAAAAABn8/-9oRoapRlaQ/s1600/dyingchequefbscam1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-PCp16DlZkHY/TqP97urF65I/AAAAAAAABn8/-9oRoapRlaQ/s320/dyingchequefbscam1.gif" width="308" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;It'll come as no surprise to you that the&amp;nbsp;"1,374,930 people like this" text is just a faked screenshot. Some of the rest of the page reads as follows (at least according to the nearest translator I ran it through):&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;"Razim Al Hamed, the world's richest man, is nearing the end of his life and his fortune has decided to share with anyone who requests it. His wealth is being distributed in checks of one thousand dollars to anyone who wants it, free!&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;Request your check for a thousand dollars here and receive money in the door of your house. Claim your check NOW!&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;Razim Al Hamed has already sent more than one million checks, hurry to claim yours! Complete all 5 steps are below and receive your check within the next 10 days.&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;Click on the Share button below and this share this message on 5 different walls of your friends on facebook&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;Razim to Hamed is giving away $ 1000 checks and keep sending checks to those who ask him! I am asking for my $ 1000 check now, his advantage and ask you a gift and is easy! Come on: 1000dolares(dot)org&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;i&gt;Once finished entering all steps to collect your check"&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Hitting the "Like" button (or in this case, the Me Gusta button) then hitting the Share button gives us this:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-dwX8Wkq7Zdc/TqP98iFkS_I/AAAAAAAABoE/EaGcOiBmqyE/s1600/dyingchequefbscam2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-dwX8Wkq7Zdc/TqP98iFkS_I/AAAAAAAABoE/EaGcOiBmqyE/s1600/dyingchequefbscam2.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Spread the word, spread the wealth! Or not, as the following popup box puts the brakes on any cash advance from Mr Hamed:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-Igcc2aApZXg/TqP99ue1W4I/AAAAAAAABoM/Bj_pJBCkQiU/s1600/dyingchequefbscam3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-Igcc2aApZXg/TqP99ue1W4I/AAAAAAAABoM/Bj_pJBCkQiU/s1600/dyingchequefbscam3.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span id="goog_526955188"&gt;&lt;/span&gt;&lt;span id="goog_526955189"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Unfortunately, you won't be getting any money out of this one anytime soon. Anything you see with promises of free money from Mr Hamed should be taken with a mountain sized grain of salt, and that includes his appearances on everything from Facebook fakeouts and blogspot pages to finance forums and Youtube videos.&lt;br /&gt;&lt;br /&gt;Now if you'll excuse me, I have a begging letter to write...&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-8895792720044625237?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/8895792720044625237/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=8895792720044625237&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8895792720044625237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8895792720044625237'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/where-in-world-is-razim-al-hamed.html' title='Where in the World is Razim Al Hamed?'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-PCp16DlZkHY/TqP97urF65I/AAAAAAAABn8/-9oRoapRlaQ/s72-c/dyingchequefbscam1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-5717728826502680570</id><published>2011-10-22T22:41:00.001-04:00</published><updated>2011-10-22T22:41:18.458-04:00</updated><title type='text'>VB2011 Presentations</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-1DHb0kLEXQs/TqN8ypVZB6I/AAAAAAAABn0/C8kvUL6c178/s1600/vb2011stage2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="130" src="http://3.bp.blogspot.com/-1DHb0kLEXQs/TqN8ypVZB6I/AAAAAAAABn0/C8kvUL6c178/s320/vb2011stage2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;A few weeks ago we gave a couple of talks at VB2011 in Spain. You can check out PDF versions of the presentations &lt;a href="http://www.virusbtn.com/conference/vb2011/slides/index.xml"&gt;here&lt;/a&gt;. Even without the context of the talks themselves there's quite a bit of content there for you to get your teeth into. Our presentations were "&lt;a href="http://www.virusbtn.com/pdf/conference_slides/2011/Boyd-VB2011.pdf"&gt;Web Browsers: A History of Rogues&lt;/a&gt;" and "&lt;a href="http://www.virusbtn.com/pdf/conference_slides/2011/Purisima-Wolf-VB2011.pdf"&gt;MUTE - Malware URL Tracking and Exchange&lt;/a&gt;", which was a group discussion with Kaspersky, Microsoft and Avira (we also took part in another group discussion, "Operation ShadySHARE - towards better industry collaboration", but the slides for that one aren't online).&lt;br /&gt;&lt;br /&gt;Thanks to everyone who came along and listened, it was a lot of fun.&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-5717728826502680570?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/5717728826502680570/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=5717728826502680570&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5717728826502680570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5717728826502680570'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/vb2011-presentations.html' title='VB2011 Presentations'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-1DHb0kLEXQs/TqN8ypVZB6I/AAAAAAAABn0/C8kvUL6c178/s72-c/vb2011stage2.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-8817331299190482663</id><published>2011-10-21T06:00:00.000-04:00</published><updated>2011-10-21T06:00:36.325-04:00</updated><title type='text'>RBC Royal Bank Phish Wading in the Wild</title><content type='html'>Our researchers at the AV Labs just netted one of the latest phishing attempts that prey on clients of the &lt;b&gt;Royal Bank of Canada (RBC)&lt;/b&gt; or &lt;b&gt;RBC Royal Bank&lt;/b&gt;. Below is the screenshot of the email phish being spammed in the wild:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/--CAHhp9Xmgk/TqEsWNGtk1I/AAAAAAAAASs/fICjrwJDS8Q/s1600/RBCPhish_img01.png" imageanchor="1"&gt;&lt;img border="0" height="143" src="http://1.bp.blogspot.com/--CAHhp9Xmgk/TqEsWNGtk1I/AAAAAAAAASs/fICjrwJDS8Q/s320/RBCPhish_img01.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;This email from "RBC Online"&amp;nbsp;masquerades&amp;nbsp;as an alert notification message regarding a security update. Upon reading the message body, however, it asks the recipient to validate their account with the bank. Like most unsophisticated phishing attempts, this is a bit of an odd one, too, since validating an account has nothing to do with "security updates" or a "scheduled system maintenance". Composition-wise, it doesn't make sense, and it seems that the phishers behind this scam merely used&amp;nbsp;terms and phrases that could get recipients to potentially click their link.&lt;br /&gt;&lt;br /&gt;Clicking &lt;i&gt;"VALIDATE"&lt;/i&gt; in the email body redirects recipients to &lt;i&gt;tipoco(dash)gps(dot)com/tinymce/rbc/&lt;/i&gt;, which should have triggered some alarm bells by now. More than the URL, let us look at the page itself:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-T2FbGWLyHd4/TqEs0TPe3HI/AAAAAAAAAS4/I8app772ptc/s1600/RBCPhish_img02.png" imageanchor="1"&gt;&lt;img border="0" height="260" src="http://3.bp.blogspot.com/-T2FbGWLyHd4/TqEs0TPe3HI/AAAAAAAAAS4/I8app772ptc/s320/RBCPhish_img02.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;It looks like a fill-out form one would normally see when attempting to sign up for an account, doesn't it? And if you find yourself asking this question, you'll realise soon enough that this is not the page you expected where you could normally validate your identity. It is a page that simply asks for &lt;i&gt;a lot&lt;/i&gt; of personal information and begs answers to specific questions one might have used as hints on other accounts. Furthermore, the page claims that it is secure; however, the absence of the URL access method, &lt;i&gt;"https://"&lt;/i&gt;, tells you otherwise. The website icon used for this page does not carry RBC's insignia.&lt;br /&gt;&lt;br /&gt;Recipients of the email phish is then directed to this "thank you!" page after they fill out the form.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;&lt;a href="http://3.bp.blogspot.com/-ko9dtPkOLMU/TqEtEzfwrjI/AAAAAAAAATE/9ExWhNomM8U/s1600/RBCPhish_img03.png" imageanchor="1"&gt;&lt;img border="0" height="237" src="http://3.bp.blogspot.com/-ko9dtPkOLMU/TqEtEzfwrjI/AAAAAAAAATE/9ExWhNomM8U/s320/RBCPhish_img03.png" width="320" /&gt;&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;As of this writing, the phishing pages are still up.&lt;br /&gt;&lt;br /&gt;This isn't the first time RBC Royal Bank is targeted, so never fall for phishing scams such as this one. When in doubt, always look for the telltale signs (the URL, for example) that you might be somewhere you don't want to be in. You might also want to check out this page for &lt;a href="http://www.fraudwatchinternational.com/phishing/individual_alert.php?fa_no=239837&amp;amp;mode=alert"&gt;another variant of this phish&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Wendy for spotting this)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-8817331299190482663?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/8817331299190482663/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=8817331299190482663&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8817331299190482663'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8817331299190482663'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/rbc-royal-bank-phish-wading-in-wild.html' title='RBC Royal Bank Phish Wading in the Wild'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/--CAHhp9Xmgk/TqEsWNGtk1I/AAAAAAAAASs/fICjrwJDS8Q/s72-c/RBCPhish_img01.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-7284546706673088424</id><published>2011-10-20T01:27:00.002-04:00</published><updated>2011-10-20T01:27:42.640-04:00</updated><title type='text'>Phishing page hacked, turned into PSA on the dangers of phishing</title><content type='html'>Here's something you don't see very often. Someone - perhaps the recipient of the below phishing mail while having a Falling Down style day at the office - decided enough was enough and set out to hijack the phishing site they were sent to.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This is the email that started it all:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-KnJSFLpDszk/Tp-s6dGLuxI/AAAAAAAABnQ/3UsrGip5u8w/s1600/hackedphishwrning2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="130" src="http://1.bp.blogspot.com/-KnJSFLpDszk/Tp-s6dGLuxI/AAAAAAAABnQ/3UsrGip5u8w/s320/hackedphishwrning2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;i&gt;"You have exceeded the storage limit on your mailbox.You will not be able&amp;nbsp;to send or receive new mail until you upgrade your email.&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Click the below link and fill the form to upgrade your account.&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;System Administrator"&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Clicking the link would have taken you to the below phishing form that asks for Username, Password and Email address (along with password verification).&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-THmKM50wp14/Tp-s-G9SbcI/AAAAAAAABnY/0pZ3R2tLH5M/s1600/hackedphishwrning1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="102" src="http://2.bp.blogspot.com/-THmKM50wp14/Tp-s-G9SbcI/AAAAAAAABnY/0pZ3R2tLH5M/s320/hackedphishwrning1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Now? Well, it looks a little bit different:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-4sibu3QOAOI/Tp-tAB-FzfI/AAAAAAAABng/W9Qc4sGe6dc/s1600/hackedphishwrning3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="165" src="http://1.bp.blogspot.com/-4sibu3QOAOI/Tp-tAB-FzfI/AAAAAAAABng/W9Qc4sGe6dc/s320/hackedphishwrning3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;The original boxes are gone, replaced by the following message :&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"There is no such thing as a central email service update a stupid criminal created this to steal your email account I have modified it to educate you about online crime he does not like that but that is too damn bad you can submit this form to see a helpful video about phishing stop letting stupid criminals like this one hijack your account have a great day"&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Hitting the submit button takes you to a warning video about Phishing scams on CNET.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-CwTtya9UkP0/Tp-tCS2gHJI/AAAAAAAABno/kwaswd44bVU/s1600/hackedphishwrning4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="185" src="http://1.bp.blogspot.com/-CwTtya9UkP0/Tp-tCS2gHJI/AAAAAAAABno/kwaswd44bVU/s320/hackedphishwrning4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;There's no indication left as to how the person now in control of the site obtained the login credentials.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Phishing the phisher, perhaps? It &lt;a href="http://www.theregister.co.uk/2011/07/22/auto_whaler_tool_trojan/"&gt;does happen&lt;/a&gt; from time to time...&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Christopher Boyd (Thanks to Robert and Wendy for this one)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-7284546706673088424?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/7284546706673088424/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=7284546706673088424&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7284546706673088424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7284546706673088424'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/phishing-page-hacked-turned-into-psa-on.html' title='Phishing page hacked, turned into PSA on the dangers of phishing'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-KnJSFLpDszk/Tp-s6dGLuxI/AAAAAAAABnQ/3UsrGip5u8w/s72-c/hackedphishwrning2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-815102903121858275</id><published>2011-10-19T15:25:00.002-04:00</published><updated>2011-10-19T15:42:54.581-04:00</updated><title type='text'>Moving on</title><content type='html'>After 9 years of building Sunbelt Software, and then working for GFI, I have decided to move on. &lt;br /&gt;&lt;br /&gt;It's been a great adventure. &amp;nbsp;I joined Stu Sjouwerman, who had built a distribution company, to start the "Software" part of Sunbelt Software. &amp;nbsp;We started in 2002 with an antispam product, iHateSpam, for desktops. &amp;nbsp;Then the same technology for Exchange. &amp;nbsp;Along the way, we released other products, but the big change came in 2004, when we released CounterSpy. &lt;br /&gt;&lt;br /&gt;I started the blog with my first post, "&lt;a href="http://sunbeltblog.blogspot.com/2005/02/why-adware-works.html"&gt;Why Adware Works&lt;/a&gt;" (it seems so innocent now...). &amp;nbsp;We got a reputation for publishing our responses to cease and desist letters (as an example, our&amp;nbsp;&lt;a href="http://sunbeltblog.blogspot.com/2005/05/hotbar-goes-after-sunbelt.html"&gt;Hotba&lt;/a&gt;r C&amp;amp;D and our &lt;a href="http://www.sunbelt-software.com/ihs/alex/hotclean.pdf"&gt;response&lt;/a&gt;). &amp;nbsp; Along the way, we did fun things like give away motorcycles &amp;nbsp;(a&amp;nbsp;&lt;a href="http://sunbeltblog.blogspot.com/2005/06/hanging-out-with-10000-it-techies.html"&gt;chopper&lt;/a&gt;&amp;nbsp;and a &lt;a href="http://sunbeltblog.blogspot.com/2010/05/we-got-848-ducati-for-tech-ed.html"&gt;Ducati&lt;/a&gt;), an inspired employee &lt;a href="http://sunbeltblog.blogspot.com/2009/04/getting-vipre-tattoo.html"&gt;tattoed himself with VIPRE&lt;/a&gt;, and much more. &amp;nbsp; It wasn't all about Sunbelt. &amp;nbsp;We worked on &lt;a href="http://sunbeltblog.blogspot.com/2006/03/become-phishing-terminator.html"&gt;PIRT&lt;/a&gt; with Paul and Robin Laudanski (they did all the work, actually). A group of dedicated security researchers and I helped a very nice lady&lt;a href="http://sunbeltblog.blogspot.com/2008/11/julie-amero-forensic-analysis.html"&gt; get out of real trouble&lt;/a&gt;, and then we started a group to help &lt;a href="http://sunbeltblog.blogspot.com/2007/06/making-sure-what-happened-to-juliedoesn.html"&gt;other people in troubl&lt;/a&gt;e. &amp;nbsp;We broke the news on some pretty nasty stuff, like the &lt;a href="http://sunbeltblog.blogspot.com/2005/12/new-exploit-blows-by-fully-patched.html"&gt;infamous WMF exploit&lt;/a&gt;. &amp;nbsp;Sometimes I would get bored and write about &lt;a href="http://sunbeltblog.blogspot.com/2007/06/making-sure-what-happened-to-juliedoesn.html"&gt;something&lt;/a&gt; &lt;a href="http://sunbeltblog.blogspot.com/2008/03/surf-pic-of-day-should-i-or-should-i.html"&gt;else&lt;/a&gt;. &amp;nbsp;People were nice and gave us all&amp;nbsp;&lt;a href="http://www.pcworld.com/article/133119-4/100_blogs_we_love.html"&gt;kinds&amp;nbsp;&lt;/a&gt;of&amp;nbsp;&lt;a href="http://news.cnet.com/CNET-News.coms-Blog-100/2009-12_3-5887900.html"&gt;awards&lt;/a&gt;. &amp;nbsp;And so on.&lt;br /&gt;&lt;br /&gt;Going through the archives of this blog is a virtual history of the industry during one of its more interesting times. &lt;br /&gt;&lt;br /&gt;In 2005, we started working on a new technology, VIPRE, based on a&amp;nbsp;&lt;a href="http://sunbeltblog.blogspot.com/2007/01/evolving-antimalware-technology-model.html"&gt;new philosophy for antimalware products&lt;/a&gt;. In 2008, we released VIPRE and the rest is history.&lt;br /&gt;&lt;br /&gt;But with everything in life, there is a start, a middle and an end. &amp;nbsp; I've turned the reins over to some incredibly capable people here at GFI. &amp;nbsp;Eric Sites, the original Sunbelt Software CTO, is still here as Chief Scientist. &amp;nbsp;Mark Patton, Sunbelt's VP of R&amp;amp;D, is now running global R&amp;amp;D for GFI. &amp;nbsp;The threat team has been getting some great people, and the original team (which we started with Eric Howes, Patrick Jordan, Adam Thomas and a small number of others) has now grown to a large and impressive group. &amp;nbsp;Jovi Umawing and Chris Boyd are now writing the posts for the blog, and doing a great job. &lt;br /&gt;&lt;br /&gt;I'm very proud of the team we built here, and I will certainly miss all&amp;nbsp;the great people I worked with over the past many years. We made great products together and built a wonderful culture.&lt;br /&gt;&lt;br /&gt;Finally, I have to thank you. &amp;nbsp;As a member of this community, you were a key part of this extraordinary experience and I thoroughly enjoyed the interactions I had with many of you.&lt;br /&gt;&lt;br /&gt;Now, I am going to take a bit of time with my family, and discover my next great adventure. &amp;nbsp;Feel free to reach out. &lt;br /&gt;&lt;br /&gt;So long for now,&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Alex Eckelberry&lt;br /&gt;www.eckelberry.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-815102903121858275?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/815102903121858275/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=815102903121858275&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/815102903121858275'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/815102903121858275'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/moving-on.html' title='Moving on'/><author><name>Alex Eckelberry</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-47199950126627024</id><published>2011-10-19T12:30:00.000-04:00</published><updated>2011-10-19T12:30:56.156-04:00</updated><title type='text'>Latest Generation of TDSS Rootkit Gets a Serious "Upgrade"</title><content type='html'>GFI Software made it in the books of Philippine cybersecurity history by taking part in RootCon, the first official security conference in the Philippines, which was held in Cebu City last month. Two of ours—Berman Enconado (Senior Malware Analyst at the Manila Labs) and Christopher Boyd (Batman)—had given talks during this two-day event. One of the topics we discussed was about &lt;a href="http://www.securelist.com/en/analysis/204792157/TDSS_TDL_4"&gt;TDL4&lt;/a&gt;, the fourth generation TDSS rootkit that made waves in June of this year because of its ability to propagate via removable drives / LAN and infect the Master Boot Record (MBR), allowing it to load on infected systems before the OS does.&lt;br /&gt;&lt;br /&gt;Our friends at ESET have in depth analyses of this TDSS rootkit, and &lt;a href="http://blog.eset.com/2011/10/18/tdl4-rebooted"&gt;from what they have observed&lt;/a&gt; as of late, this nasty malware have evolved &lt;i&gt;again;&amp;nbsp;&lt;/i&gt;however, it's not the kind of evolution anyone might have expected:&lt;br /&gt;&lt;blockquote&gt;&lt;i&gt;"Based on the analysis of its components we can say that some of those components have been rewritten from scratch (kernel-mode driver, user-mode payload) while some (specifically, some bootkit components) remain the same as in the previous versions. These changes might suggest one of the following: either the team developing the botnet has been changed, or TDL4 developers have started selling a bootkit builder to other cybercrime groups."&lt;/i&gt;&lt;/blockquote&gt;You can read more about it &lt;a href="http://blog.eset.com/2011/10/18/tdl4-rebooted"&gt;here&lt;/a&gt; on their official blog. By the looks of this, this TDSS is becoming more and more sophisticated the longer its developers continue to improve on it.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-47199950126627024?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/47199950126627024/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=47199950126627024&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/47199950126627024'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/47199950126627024'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/latest-generation-of-tdss-rootkit-gets.html' title='Latest Generation of TDSS Rootkit Gets a Serious &quot;Upgrade&quot;'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-5055650592637792934</id><published>2011-10-19T01:55:00.000-04:00</published><updated>2011-10-19T01:59:48.990-04:00</updated><title type='text'>Twitter phish DMs still very much alive and kicking</title><content type='html'>Just a heads up that a &lt;a href="http://news.softpedia.com/news/The-Difference-Between-Twitter-and-Twittelr-Is-a-Phish-227919.shtml"&gt;popular Twitter phish&lt;/a&gt; is still doing the rounds:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-n44wHM6TGME/Tp5m5lPnUMI/AAAAAAAABnI/Ez5O8tyBUZ0/s1600/twitldmpsh1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="185" src="http://1.bp.blogspot.com/-n44wHM6TGME/Tp5m5lPnUMI/AAAAAAAABnI/Ez5O8tyBUZ0/s320/twitldmpsh1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;i&gt;"Found a funny picture of you! mugweb(dot)ru"&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Clicking the link takes you to&amp;nbsp;twittelr(dot)com/verify-/session/login-/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-wI2Dn1vijq8/Tp5lKJ3C_hI/AAAAAAAABnA/U-CT54Jc0A0/s1600/twitldmpsh2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="172" src="http://2.bp.blogspot.com/-wI2Dn1vijq8/Tp5lKJ3C_hI/AAAAAAAABnA/U-CT54Jc0A0/s320/twitldmpsh2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;If you enter your details at this point, you've been phished and can expect to see your own account spamming junk at some point in the near future.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Christopher Boyd&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-5055650592637792934?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/5055650592637792934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=5055650592637792934&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5055650592637792934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5055650592637792934'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/twitter-phish-dms-still-very-much-alive.html' title='Twitter phish DMs still very much alive and kicking'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-n44wHM6TGME/Tp5m5lPnUMI/AAAAAAAABnI/Ez5O8tyBUZ0/s72-c/twitldmpsh1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-6042254353239533090</id><published>2011-10-18T16:33:00.000-04:00</published><updated>2011-10-18T16:36:36.033-04:00</updated><title type='text'>RSA Europe 2011</title><content type='html'>I'll admit, it's the first time I've stayed in a hotel room where they managed to nail four copies of the same picture to the wall horizontally instead of vertically. Here's one:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-WOhuiweyzjk/Tp3eHTXavjI/AAAAAAAABmI/qlrM_OA7cP0/s1600/rsaeuro20111.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://4.bp.blogspot.com/-WOhuiweyzjk/Tp3eHTXavjI/AAAAAAAABmI/qlrM_OA7cP0/s320/rsaeuro20111.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;The others were just as spectacular. Anyway, RSA Europe took place in London last week and there were a lot of talks to get your teeth into.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ti7d8TNHTA0/Tp3e6ZE3atI/AAAAAAAABmQ/5qyt9b6t1Hs/s1600/rsaeuro20112.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://4.bp.blogspot.com/-ti7d8TNHTA0/Tp3e6ZE3atI/AAAAAAAABmQ/5qyt9b6t1Hs/s320/rsaeuro20112.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-8_DGRHqogwI/Tp3e7LW_FUI/AAAAAAAABmY/R3DiaeHC8aU/s1600/rsaeuro20113.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-8_DGRHqogwI/Tp3e7LW_FUI/AAAAAAAABmY/R3DiaeHC8aU/s320/rsaeuro20113.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Speaking of getting your teeth into, dinner was served in the form of packed lunches.&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-hNMcGV-Mp3g/Tp3e8JRsz0I/AAAAAAAABmg/SMHHJUx40mI/s1600/rsaeuro20114.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://1.bp.blogspot.com/-hNMcGV-Mp3g/Tp3e8JRsz0I/AAAAAAAABmg/SMHHJUx40mI/s320/rsaeuro20114.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;The question I left Tim Berners-Lee was "How do I shot web?"&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-LFaaNO-eNSk/Tp3gNUnCa1I/AAAAAAAABmo/YQV4hbYMMd8/s1600/rsaeuro20115.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-LFaaNO-eNSk/Tp3gNUnCa1I/AAAAAAAABmo/YQV4hbYMMd8/s320/rsaeuro20115.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;I'm almost certain he'll get back to me on it eventually. Here I am talking about threats to workplace security in the form of videogame consoles:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-CB5j3IH4JAU/Tp3gtcR7QgI/AAAAAAAABmw/opMsaNGaMJg/s1600/rsaeuro20116.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-CB5j3IH4JAU/Tp3gtcR7QgI/AAAAAAAABmw/opMsaNGaMJg/s320/rsaeuro20116.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;The talk itself seemed to go well, although there were a &lt;a href="http://paperghost.posterous.com/speaking-at-rsa-europe-i-didnt-ask-for-this"&gt;number of teething troubles and then some&lt;/a&gt; prior to actually getting up and rambling for half an hour. What's most interesting to me is that this is the first time I've submitted a videogaming threat talk to a more corporate event and had it accepted - maybe all those videogame company hacks over the past year have made people think a little more about the possibility of things going horribly wrong in this particular area of (in)security. At any rate, all of the conference presentation material is &lt;a href="http://www.rsaconference.com/2011/europe/index.htm"&gt;available to look at&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Next up is a VB2011 post, as most (if not all) of the conference content is now online...&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-6042254353239533090?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/6042254353239533090/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=6042254353239533090&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6042254353239533090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6042254353239533090'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/rsa-europe-2011.html' title='RSA Europe 2011'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-WOhuiweyzjk/Tp3eHTXavjI/AAAAAAAABmI/qlrM_OA7cP0/s72-c/rsaeuro20111.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-8699137230677458590</id><published>2011-10-18T15:57:00.003-04:00</published><updated>2011-10-18T15:58:53.832-04:00</updated><title type='text'>Another Bing advert to steer clear of...</title><content type='html'>Here's an advert in Bing which wants you to install some adware&amp;nbsp;located at chrome(dot)freewarecentral(dot)net - it was coming up in results when searching for "Chrome download".&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-WOQY1hO4dW8/Tp3UzaxlGmI/AAAAAAAABlo/_Y9LdfwzNXA/s1600/chromebingdld1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="186" src="http://1.bp.blogspot.com/-WOQY1hO4dW8/Tp3UzaxlGmI/AAAAAAAABlo/_Y9LdfwzNXA/s320/chromebingdld1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;As with most of these downloads, the site is reasonably convincing:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-6__2fMqMxSM/Tp3U03n_MuI/AAAAAAAABlw/wPPt-vNIrKk/s1600/chromebingdld2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="257" src="http://3.bp.blogspot.com/-6__2fMqMxSM/Tp3U03n_MuI/AAAAAAAABlw/wPPt-vNIrKk/s320/chromebingdld2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Hit the install button, and you'll be faced with the following Pinball Corp installer:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-pati0h6toLU/Tp3XoD3MKmI/AAAAAAAABl4/VFsOlulO5VE/s1600/chromebingdld3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="260" src="http://1.bp.blogspot.com/-pati0h6toLU/Tp3XoD3MKmI/AAAAAAAABl4/VFsOlulO5VE/s320/chromebingdld3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;After you've installed the adware, you'll be taken to&lt;br /&gt;&lt;br /&gt;chrome(dot)freewarecentral(dot)net/download/?m1vcjhbpqo&lt;br /&gt;&lt;br /&gt;which actually does give you the real Chrome. However, you could just go &lt;a href="http://www.google.com/chrome"&gt;here&lt;/a&gt; and download it without all the additional installs. Microsoft have been notified.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks Matthew)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-8699137230677458590?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/8699137230677458590/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=8699137230677458590&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8699137230677458590'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8699137230677458590'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/another-bing-advert-to-steer-clear-of.html' title='Another Bing advert to steer clear of...'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-WOQY1hO4dW8/Tp3UzaxlGmI/AAAAAAAABlo/_Y9LdfwzNXA/s72-c/chromebingdld1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-1436826752845461623</id><published>2011-10-18T03:13:00.001-04:00</published><updated>2011-10-18T10:35:25.225-04:00</updated><title type='text'>Hot Diamond Organization 419 scam</title><content type='html'>Here's a 419 scam with a little of everything, including a wonderful fake website. First, the email:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-51yIKXhwbdc/Tp0W6Z8EtwI/AAAAAAAABk4/mt72Tkojlg0/s1600/hdiamond4190.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="159" src="http://3.bp.blogspot.com/-51yIKXhwbdc/Tp0W6Z8EtwI/AAAAAAAABk4/mt72Tkojlg0/s320/hdiamond4190.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;In case you don't want to read it - goodness knows, I tried - the "Hot Diamond Organization" have taken time out from selling diamonds and necklaces to give away one million dollars to "help individuals from countries facing terrorist attack and flood". No, none of this makes any sense. Below, you can see the Hot Diamond website located at hdiamond(dot)page(dot)tl which pops adverts asking you to install things. The ads we've seen contain Pinball network installers, which would give the user Real Player, XVID and Blinkx. Here's an example of what happens should you hit the "Install Xvid" prompt :&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-3OZYpnehj-Q/Tp0W9iJnZlI/AAAAAAAABlA/0ao79eNBgJM/s1600/hdiamond4195.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="206" src="http://1.bp.blogspot.com/-3OZYpnehj-Q/Tp0W9iJnZlI/AAAAAAAABlA/0ao79eNBgJM/s320/hdiamond4195.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;If the end user ignores the advert popups, they still have the Hot Diamond website itself to contend with - a classy, sophisticated piece of social engineering that is absolutely not stuffed full of awful logic, stolen screenshots and spinning globes.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-3hiLyYWVyMs/Tp0W-6Xdk5I/AAAAAAAABlI/Y-wSPPgzZAw/s1600/hdiamond4194.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="291" src="http://2.bp.blogspot.com/-3hiLyYWVyMs/Tp0W-6Xdk5I/AAAAAAAABlI/Y-wSPPgzZAw/s320/hdiamond4194.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Or, you know, maybe it is. Anyone with better observation skills than a pet rock will quickly realise that their "Lottery winner pictures" are just hotlinked files for everything from the Euro Lottery to, er, some other lotteries.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-zGWgedPyFYc/Tp0XBdhrwwI/AAAAAAAABlQ/H_pL67X-6Rg/s1600/hdiamond4193.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-zGWgedPyFYc/Tp0XBdhrwwI/AAAAAAAABlQ/H_pL67X-6Rg/s320/hdiamond4193.gif" width="273" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;By the time you get to their CEO / Board of Directors list, you get the distinct impression they're not trying very hard. Case in point, say hello to Mr. James Moore:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-P5C6jXwvtkg/Tp0XCTrlRlI/AAAAAAAABlY/1azbm5Zk8KA/s1600/hdiamond4192.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-P5C6jXwvtkg/Tp0XCTrlRlI/AAAAAAAABlY/1azbm5Zk8KA/s320/hdiamond4192.gif" width="286" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Let's not forget Mrs Caroline and Mrs Mary, either. Finally, we have their "Send me all your money" form, which wants all sorts of personal information including banking details.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-whUDhAdpNLc/Tp0XDKlanpI/AAAAAAAABlg/9AWpDj9qwDA/s1600/hdiamond4191.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-whUDhAdpNLc/Tp0XDKlanpI/AAAAAAAABlg/9AWpDj9qwDA/s320/hdiamond4191.gif" width="253" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;I'm not sure this website hits the heady heights of &lt;a href="http://blog.spywareguide.com/2008/02/beware-fake-419-conference-inv.html"&gt;this fakeout&lt;/a&gt;&amp;nbsp;in terms of sheer dreadfulness, but it&amp;nbsp;certainly&amp;nbsp;comes close. You can happily ignore everything these scammers send to your mailbox.&lt;br /&gt;&lt;br /&gt;Christopher Boyd &lt;br /&gt;&lt;br /&gt;(Thanks to Robert and Wendy for finding this one.)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-1436826752845461623?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/1436826752845461623/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=1436826752845461623&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1436826752845461623'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1436826752845461623'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/hot-diamond-organization-419-scam.html' title='Hot Diamond Organization 419 scam'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-51yIKXhwbdc/Tp0W6Z8EtwI/AAAAAAAABk4/mt72Tkojlg0/s72-c/hdiamond4190.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-7529609710737269945</id><published>2011-10-18T01:17:00.001-04:00</published><updated>2011-10-18T01:27:40.227-04:00</updated><title type='text'>GMail Hacker: D'oh!</title><content type='html'>One of our researchers has come across a supposed hacking tool—&lt;b&gt;&lt;i&gt;GMail Hacker Pro&lt;/i&gt;&lt;/b&gt;—that claims it can compromise GMail accounts. This tool comes with a fairly slick looking website (complete with live chat support) located at &lt;i&gt;gmailhackerpro(dot)com&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-l8xjgNaTnCg/Tpz-IfKQxQI/AAAAAAAABkg/4Nu517NYMdU/s1600/gmailhackerpro00.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="267" src="http://2.bp.blogspot.com/-l8xjgNaTnCg/Tpz-IfKQxQI/AAAAAAAABkg/4Nu517NYMdU/s320/gmailhackerpro00.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&lt;/div&gt;During installation, it shows users a EULA. Let us just quickly point out that a portion of it states that a search bar will be installed with the program. During our tests, however, no search bar is installed.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-EgVa7plz1uM/TpzjDuU__9I/AAAAAAAAARY/dL_wpUOSMJA/s1600/GMailHackingPro_img3.png" imageanchor="1"&gt;&lt;img border="0" height="251" src="http://4.bp.blogspot.com/-EgVa7plz1uM/TpzjDuU__9I/AAAAAAAAARY/dL_wpUOSMJA/s320/GMailHackingPro_img3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&lt;/div&gt;Once fully installed, this tool&amp;nbsp;displays a graphical user interface (GUI) and allows the user to enter a GMail email address in a text box. It then claims to "process" the account.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-i0nyr3NutMY/Tpz0g2vVy2I/AAAAAAAAARw/PQ7fLjhTrww/s1600/GMailHackerPro_01.png" imageanchor="1"&gt;&lt;img border="0" height="168" src="http://3.bp.blogspot.com/-i0nyr3NutMY/Tpz0g2vVy2I/AAAAAAAAARw/PQ7fLjhTrww/s320/GMailHackerPro_01.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Once the progress bar reaches 100%, the user is told the "Password file has been located", but viewing the recovered passwords will require a product key.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-NGPwq29t4NQ/Tpz-KxchL4I/AAAAAAAABko/FiCOL3_iD-c/s1600/gmailhackerpro244.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="107" src="http://3.bp.blogspot.com/-NGPwq29t4NQ/Tpz-KxchL4I/AAAAAAAABko/FiCOL3_iD-c/s320/gmailhackerpro244.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-cie4Z38i9M8/Tpz-MFFzE5I/AAAAAAAABkw/4R9j9WmkNlU/s1600/gmailhackerpro344.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="124" src="http://2.bp.blogspot.com/-cie4Z38i9M8/Tpz-MFFzE5I/AAAAAAAABkw/4R9j9WmkNlU/s320/gmailhackerpro344.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&amp;nbsp;&lt;/div&gt;In order to retrieve a product key, users have to pay 29.99 USD. If they agree to, they are then directed to a &lt;b&gt;ClickBank&lt;/b&gt; website where they can make the purchase.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-50WyvKRSyr4/Tpz1J6UEeQI/AAAAAAAAASU/QTResP6Z69A/s1600/GMailHackerPro_06.png" imageanchor="1"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-50WyvKRSyr4/Tpz1J6UEeQI/AAAAAAAAASU/QTResP6Z69A/s320/GMailHackerPro_06.png" width="282" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&lt;/div&gt;Clearly, this is designed&amp;nbsp;to extract a tidy sum of money from unwitting users, and&amp;nbsp;we'd like to save you, Dear Reader, the trouble of wanting to try it out. We categorize &lt;i&gt;GMail Hacker Pro&lt;/i&gt; as a Trojan under the detection name &lt;b&gt;GmailHackerPro.pj!.1a.&lt;/b&gt;VirusTotal scores currently sit at &lt;a href="http://www.virustotal.com/file-scan/report.html?id=5a51093e601e773e2bbb623f44807292e2c3be7a05e005dd132ff37f42c75eb9-1318886303"&gt;16/43&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;If you happen to lose or forget your GMail password, have GMail reset the password for you so you can access it again and assign a new password for it. Doing so won't cost you anything. That said, steer clear from this one, please.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Patrick for catching this one)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-7529609710737269945?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/7529609710737269945/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=7529609710737269945&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7529609710737269945'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7529609710737269945'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/gmail-hacker-doh.html' title='GMail Hacker: D&apos;oh!'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-l8xjgNaTnCg/Tpz-IfKQxQI/AAAAAAAABkg/4Nu517NYMdU/s72-c/gmailhackerpro00.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-8683625412105565101</id><published>2011-10-17T18:10:00.001-04:00</published><updated>2011-10-17T18:10:04.059-04:00</updated><title type='text'>Interview with Rob Westervelt at Search Security</title><content type='html'>&lt;p&gt;On a recent press tour in Boston, I sat with Rob and chatted about security for small to medium businesses.&amp;nbsp; Audio interview link &lt;a href="http://itknowledgeexchange.techtarget.com/security-wire-weekly/security-for-small-and-midmarket-firms/" target="_blank"&gt;here&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;Alex Eckelberry&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-8683625412105565101?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/8683625412105565101/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=8683625412105565101&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8683625412105565101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8683625412105565101'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/interview-with-rob-westervelt-at-search.html' title='Interview with Rob Westervelt at Search Security'/><author><name>Alex Eckelberry</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-7389925596763589337</id><published>2011-10-17T01:39:00.000-04:00</published><updated>2011-10-17T02:01:19.920-04:00</updated><title type='text'>McDonald's Facebook scam: Happy Birthday to...Donald?</title><content type='html'>I'm sure a McDonald's themed Facebook scam seemed like a good idea to somebody at the time, but wow is this one all over the place. It's your typical "Click here to Like", "Post a spam comment saying how good this is" then "do one of these offers" affair. However, there are many things about it that don't make any sense starting with the URL: macdonalds(dot)in.&lt;br /&gt;&lt;br /&gt;Presumably they were thinking of the guy with the farm? Oh well, it's as close to typosquatting as makes no difference I suppose. Let's take a look:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-7SKrx9KB9SY/Tpur8dI07gI/AAAAAAAABj4/aKpULSY2WVs/s1600/donaldmcd1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-7SKrx9KB9SY/Tpur8dI07gI/AAAAAAAABj4/aKpULSY2WVs/s320/donaldmcd1.gif" width="263" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;"Happy 44th birthday to Donald", they say. Except his name is Ronald and he was created in 1963, which means &lt;a href="http://wiki.answers.com/Q/How_old_is_Ronald_McDonald"&gt;he's actually 48&lt;/a&gt;. However, things quickly become confusing at this point. This scam targets Facebook users in India, yet as far as I can tell &lt;a href="http://www.mcdonaldsindia.com/ronald-mcdonald.html"&gt;he's called Ronald there&lt;/a&gt;. In fact, he's only called &lt;a href="http://en.wikipedia.org/wiki/Ronald_McDonald#International_localization"&gt;Donald McDonald in Japan&lt;/a&gt; and I have no idea how old &lt;i&gt;that&lt;/i&gt; guy is.&lt;br /&gt;&lt;br /&gt;This one claims you can pick up money or coupons (500 rupees or $12 coupons), and all you have to do is jump through some hoops. So far, just under 900 people have hit the "Like" button. The moment you hit it, this will be posted to your Facebook wall:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-iBEEg41bjVs/Tpu6l4pwMII/AAAAAAAABkQ/bZJZk0aTtdk/s1600/donaldmcd6.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-iBEEg41bjVs/Tpu6l4pwMII/AAAAAAAABkQ/bZJZk0aTtdk/s1600/donaldmcd6.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Facebook users are then asked to wish Ronald - sorry, Donald - a "Happy Birthday". Kudos to the chap at the top of the comments box who most definitely is not loving it:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-dU4D0PDg9vw/Tpuxz8o9oeI/AAAAAAAABkA/1lQIzQ_D2YM/s1600/donaldmcd2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-dU4D0PDg9vw/Tpuxz8o9oeI/AAAAAAAABkA/1lQIzQ_D2YM/s320/donaldmcd2.gif" width="243" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;The page says "You will be redirected to the next step", and the next step would be trying to leave the page but being&amp;nbsp;redirected to the following wonderful offer:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-N7sJWkS5204/TpuyRoG6AdI/AAAAAAAABkI/DRMZx60TFpU/s1600/donaldmcd3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="278" src="http://2.bp.blogspot.com/-N7sJWkS5204/TpuyRoG6AdI/AAAAAAAABkI/DRMZx60TFpU/s320/donaldmcd3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Hey look, it's an Unhappy Meal containing one browser hogging spam offer and a distinct lack of plastic toys that you already have six of anyway. All the usual nonsense is onscreen, including the "Do you really want to leave?" popup box and the ludicrous countdown timer.&lt;br /&gt;&lt;br /&gt;No, you do not want to fill any of this in. If you see any other websites out there asking you to fill in offers in return for free money to spend in McDonald's (or even Macdonalds) keep in mind that the site could be stretching the truth a little bit.&lt;br /&gt;&lt;br /&gt;In fact...you might even say...it's a &lt;a href="http://4.bp.blogspot.com/-Nd46jdEO0GI/TpvCuJaTAtI/AAAAAAAABkY/VwCghnfkvqQ/s1600/csmcdons1.gif"&gt;bit of a whopper&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-7389925596763589337?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/7389925596763589337/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=7389925596763589337&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7389925596763589337'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7389925596763589337'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/mcdonalds-facebook-scam-happy-birthday.html' title='McDonald&apos;s Facebook scam: Happy Birthday to...Donald?'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-7SKrx9KB9SY/Tpur8dI07gI/AAAAAAAABj4/aKpULSY2WVs/s72-c/donaldmcd1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-6968062878545663433</id><published>2011-10-17T00:08:00.001-04:00</published><updated>2011-10-17T00:08:27.240-04:00</updated><title type='text'>NoScript for mobile devices</title><content type='html'>There's now a mobile device version of &lt;a href="http://noscript.net/"&gt;NoScript&lt;/a&gt; available for, er, &lt;a href="http://hackademix.net/2011/10/15/noscript-for-mobile-is-complete/"&gt;mobile devices&lt;/a&gt;. If you're not familiar with NoScript, then take it away &lt;a href="http://en.wikipedia.org/wiki/NoScript"&gt;Wikipedia&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;NoScript is a free and open-source extension for Mozilla Firefox, SeaMonkey, and other Mozilla-based web browsers...NoScript allows executable web content such as JavaScript, Java, Flash, Silverlight, and other plugins only if the site hosting it is considered trusted by its user and has been previously added to a whitelist.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;It won't solve all of your problems, but it's most definitely better than nothing and a long time favourite of mine.&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-6968062878545663433?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/6968062878545663433/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=6968062878545663433&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6968062878545663433'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6968062878545663433'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/noscript-for-mobile-devices.html' title='NoScript for mobile devices'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4373107333649376211</id><published>2011-10-16T23:16:00.000-04:00</published><updated>2011-10-16T23:16:06.804-04:00</updated><title type='text'>You lost your Facebook messages!</title><content type='html'>Or, to put it another way, you didn't.&lt;br /&gt;&lt;br /&gt;However, spam mail doing the rounds wants you to think otherwise.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-lA4iFk2wgNw/Tpuaehz8viI/AAAAAAAABjw/AcFp-0i1gMc/s1600/fblostmsgs1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="207" src="http://2.bp.blogspot.com/-lA4iFk2wgNw/Tpuaehz8viI/AAAAAAAABjw/AcFp-0i1gMc/s400/fblostmsgs1.gif" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;i&gt;"You have three lost messages on Facebook, to recover the messages please follow the link below."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;The links just go to the usual advert / viagra junk. What's kind of funny here is that an older version of this campaign claimed you were missing &lt;a href="http://www.zdnet.com/blog/facebook/you-have-1-lost-message-on-facebook-e-mail-scam/3146"&gt;one message&lt;/a&gt;. Obviously the spammers decided to up the ante so now you have a whole &lt;i&gt;three&lt;/i&gt; messages lost to the void.&lt;br /&gt;&lt;br /&gt;If you were really that worried about losing your Facebook messages, I suppose you could just have copies of them all sent to your mailbox. At the very least, hover over the links included in these emails - you'll see that they take you to places that most definitely are not the official Facebook website.&lt;br /&gt;&lt;br /&gt;Coming soon: "You have six lost messages on Facebook..."&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4373107333649376211?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4373107333649376211/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4373107333649376211&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4373107333649376211'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4373107333649376211'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/you-lost-your-facebook-messages.html' title='You lost your Facebook messages!'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-lA4iFk2wgNw/Tpuaehz8viI/AAAAAAAABjw/AcFp-0i1gMc/s72-c/fblostmsgs1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4561401024913367658</id><published>2011-10-14T11:27:00.002-04:00</published><updated>2011-10-14T14:28:37.693-04:00</updated><title type='text'>Everyone loves VIPRE, even those you wouldn't expect...</title><content type='html'>&lt;p&gt;We know people love VIPRE.  But sometimes, we’re suprised that our own competitors love it too!&lt;/p&gt;&lt;p&gt;Symantec loves VIPRE so much, &lt;a href="http://sunbeltblog.blogspot.com/2011/07/symantec-loves-vipre.html" target="_blank"&gt;they’ve used the VIPRE snake&lt;/a&gt;!&lt;/p&gt;&lt;p&gt;Webroot loves VIPRE so much, they are giving out a VIPER scooter. &lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;img border="0" alt="Webroot1238123888" src="http://www.sunbeltsoftware.com/alex/gblog/webroot1238123888.png" /&gt;&lt;/p&gt;&lt;p&gt;We like ours better.  Here’s our VIPRE Ducati:&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://www.sunbeltsoftware.com/alex/gblog/viprebike128318238123138.png"&gt;&lt;img border="0" alt="Viprebike128318238123138" src="http://www.sunbeltsoftware.com/alex/gblog/viprebike128318238123138_thumb.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;(And for a bit of nostalgia, here’s the CounterSpy motorcyle we gave out back in 2005):&lt;/p&gt;&lt;p&gt;&lt;img border="0" alt="Counterspybike123881238p" src="http://www.sunbeltsoftware.com/alex/gblog/counterspybike123881238p.png" /&gt; &lt;/p&gt;&lt;p&gt;Alex Eckelberry&lt;br /&gt;(Thanks Brian)&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4561401024913367658?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4561401024913367658/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4561401024913367658&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4561401024913367658'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4561401024913367658'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/everyone-loves-vipre-even-those-you.html' title='Everyone loves VIPRE, even those you wouldn&amp;#39;t expect...'/><author><name>Alex Eckelberry</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-6158666384906676509</id><published>2011-10-13T20:58:00.008-04:00</published><updated>2011-10-14T10:28:09.771-04:00</updated><title type='text'>The continuation of dangerous rogue ads on Bing (and Yahoo)</title><content type='html'>We've noted this &lt;a href="http://sunbeltblog.blogspot.com/2011/09/more-bad-ads-in-bing.html"&gt;before&lt;/a&gt;, but Microsoft needs to get a handle on ad placements on Bing. Ok, so Bing isn't the most widely used search engine, but remember that Yahoo plays a part here as well.  &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In this case, we're talking Sirefef (ZeroAccess aka Max++), probably the nastiest piece of malware circulating on the 'net right now.  Sirefef kills any attempt to remove it, and is nearly impossible to clean (short of booting onto a rescue disk and performing cleanup actions, or reformatting).&lt;br /&gt;&lt;br /&gt;So just search for "adobe flash", and you might see this ad:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-nIrVzht7h_s/TpeKjeMcWcI/AAAAAAAAAw4/QL4IrGudZl0/s1600/bing2382348888.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 276px;" src="http://3.bp.blogspot.com/-nIrVzht7h_s/TpeKjeMcWcI/AAAAAAAAAw4/QL4IrGudZl0/s400/bing2382348888.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5663147398446995906" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;(That same search term will look identical on Yahoo, since Yahoo displays Bing ads and search results.)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Which leads to an innocent-looking "download flash" page:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/-OS38H6dgEx0/TpeLBsLqSgI/AAAAAAAAAxE/BjNolJEtVXo/s1600/bing2382348888a.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 276px;" src="http://2.bp.blogspot.com/-OS38H6dgEx0/TpeLBsLqSgI/AAAAAAAAAxE/BjNolJEtVXo/s400/bing2382348888a.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5663147917597886978" /&gt;&lt;/a&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Note that the page isn't actually "GetAdobeFlash.com".   Instead, it redirects to a directory on a  compromised trucking site (arulbrothers.com), downloading a file from torreandaluz (dot) com/flash/Flash Player 10 Setup.exe&lt;br /&gt;&lt;br /&gt;So let's download that Flash Player and run it through &lt;a href="http://www.virustotal.com/file-scan/report.html?id=9a94bbce912c9d03b58be5c411d85a49f809e297fe6eee41a54122e0bbe2fac0-1318507455"&gt;VirusTotal&lt;/a&gt;, and no surprise:  It's Sirefef.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;Alex Eckelberry&lt;br /&gt;(Thanks to Matthew)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-6158666384906676509?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/6158666384906676509/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=6158666384906676509&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6158666384906676509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6158666384906676509'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/continuation-of-dangerous-rogue-ads-on.html' title='The continuation of dangerous rogue ads on Bing (and Yahoo)'/><author><name>Rogue Antispyware</name><uri>http://www.blogger.com/profile/06824519055198949802</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-nIrVzht7h_s/TpeKjeMcWcI/AAAAAAAAAw4/QL4IrGudZl0/s72-c/bing2382348888.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-8167748820526162125</id><published>2011-10-13T09:27:00.000-04:00</published><updated>2011-10-13T09:29:54.149-04:00</updated><title type='text'>Microsoft Released Volume 11 of SIR</title><content type='html'>It was early this week when Microsoft released its latest volume of the&amp;nbsp;&lt;a href="http://www.microsoft.com/security/sir/default.aspx"&gt;&lt;b&gt;Security Intelligence Report&lt;/b&gt;&lt;/a&gt;, or &lt;b&gt;SIR&lt;/b&gt;. This report, Microsoft noted, "exposes the threat landscape of exploits, vulnerabilities, and malware", aiming to "help you protect your organization, software, and people."&lt;br /&gt;&lt;br /&gt;SIR&amp;nbsp;volume 11 has a lot more findings, insights, and observations from the the first half of 2011.&amp;nbsp;Below are just some facts and figures from the report that are worth noting for future reference and study:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;More than 1/3 of malware detected (ab)use the &lt;i&gt;AutoRun&lt;/i&gt; feature in Windows. These malware spread via removable drives and network drives.&lt;/li&gt;&lt;li&gt;Exploits that take advantage of flaws in &lt;b&gt;&lt;i&gt;Java&lt;/i&gt;&lt;/b&gt;, the OS itself, and &lt;b&gt;&lt;i&gt;HTML/JScript&lt;/i&gt;&lt;/b&gt; were most prevalent from Q3 of 2010 to Q2 of 2011. The volume of exploits targeting &lt;b&gt;&lt;i&gt;Adobe Flash&lt;/i&gt;&lt;/b&gt; increased by more 40 times compared to the volume seen in Q2 of this year.&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;i&gt;Adobe Reader&lt;/i&gt;&lt;/b&gt; and &lt;b&gt;&lt;i&gt;Acrobat&lt;/i&gt;&lt;/b&gt; are the most affected software for document format exploits. No surprise here.&lt;/li&gt;&lt;li&gt;Windows XP SP3 (client) and Windows Server 2033 SP2 (server) are the OSs with the highest infection rates.&lt;/li&gt;&lt;li&gt;Adware, software that were deemed potentially unsafe, and Trojans are the most prevalent threats that were detected on systems. An example of this threat is &lt;a href="http://sunbeltblog.blogspot.com/2011/06/fakerean-comes-of-age-turns-hard-core.html"&gt;&lt;b&gt;FakeRean&lt;/b&gt;&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;There was a 71.97 percent decrease of spam volume from July 2010 to June 2011 due to the takedowns of the &lt;a href="http://www.scmagazine.com.au/News/230410,spam-volume-plunges-in-wake-of-pushdocutwail-takedown.aspx"&gt;&lt;b&gt;Pushdo/Cutwail&lt;/b&gt;&lt;/a&gt; and &lt;a href="http://blogs.technet.com/b/microsoft_on_the_issues/archive/2011/03/18/taking-down-botnets-microsoft-and-the-rustock-botnet.aspx"&gt;&lt;b&gt;Rustock&lt;/b&gt;&lt;/a&gt; botnets.&lt;/li&gt;&lt;li&gt;Phishers are now targeting social networks more than financial institutes.&lt;/li&gt;&lt;/ul&gt;The .PDF copy of SIR is available and can be downloaded &lt;a href="http://download.microsoft.com/download/0/3/3/0331766E-3FC4-44E5-B1CA-2BDEB58211B8/Microsoft_Security_Intelligence_Report_volume_11_English.pdf"&gt;here&lt;/a&gt;. If you're interested in backtracking previous volumes, Microsoft has made them available in their &lt;a href="http://www.microsoft.com/security/sir/archive/default.aspx"&gt;library page&lt;/a&gt;.&lt;br&gt;&lt;br&gt;Stay informed, everyone!&lt;br&gt;&lt;br&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-8167748820526162125?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/8167748820526162125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=8167748820526162125&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8167748820526162125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8167748820526162125'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/microsoft-released-volume-11-of-sir.html' title='Microsoft Released Volume 11 of SIR'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-1492188609097298556</id><published>2011-10-12T18:06:00.001-04:00</published><updated>2011-10-12T18:06:43.556-04:00</updated><title type='text'>Seen in the wild: Slick new Google Adwords phish</title><content type='html'>&lt;p&gt;This new phishing campaign&amp;nbsp;is trying to get Google credentials and it&amp;rsquo;s quite well executed. &lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;a href="http://www.sunbeltsoftware.com/alex/gblog/adwordw2388123888123b.png"&gt;&lt;img border="0" alt="Adwordw2388123888123b" src="http://www.sunbeltsoftware.com/alex/gblog/adwordw2388123888123b_thumb.jpg" / /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.sunbeltsoftware.com/alex/gblog/adwordw2388123888123a.png"&gt;&lt;img border="0" alt="Adwordw2388123888123a" src="http://www.sunbeltsoftware.com/alex/gblog/adwordw2388123888123a_thumb.jpg" / /&gt;&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;Alex Eckelberry&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-1492188609097298556?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/1492188609097298556/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=1492188609097298556&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1492188609097298556'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1492188609097298556'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/seen-in-wild-slick-new-google-adwords.html' title='Seen in the wild: Slick new Google Adwords phish'/><author><name>Alex Eckelberry</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-3324160478419287151</id><published>2011-10-11T10:07:00.002-04:00</published><updated>2011-10-11T10:11:12.589-04:00</updated><title type='text'>Orkut phish serves up adult content warning</title><content type='html'>Here's an example of the "Content suitable for adults" verification scam &lt;a href="http://sunbeltblog.blogspot.com/2011/06/steer-clear-of-tumblr-hosted-phish.html"&gt;seen over on Tumblr&lt;/a&gt; popping up in the world of Orkut. Clicking through teases the end-user with semi naked body bits flopping about all over the screen, followed by a rather nice looking fake login.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Jb7kQ9oh4sg/TpKIdJYhXyI/AAAAAAAABjU/elLyVWU3tyg/s1600/googverifadult1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="215" src="http://2.bp.blogspot.com/-Jb7kQ9oh4sg/TpKIdJYhXyI/AAAAAAAABjU/elLyVWU3tyg/s320/googverifadult1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-hfuQXXJscFg/TpKIepzmtXI/AAAAAAAABjY/V0E3_9bVy3Q/s1600/googverifadult2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="304" src="http://4.bp.blogspot.com/-hfuQXXJscFg/TpKIepzmtXI/AAAAAAAABjY/V0E3_9bVy3Q/s320/googverifadult2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-mDMoGcRDeBY/TpKIfjO4GWI/AAAAAAAABjc/3Gx58SRyr5E/s1600/googverifadult3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="186" src="http://4.bp.blogspot.com/-mDMoGcRDeBY/TpKIfjO4GWI/AAAAAAAABjc/3Gx58SRyr5E/s320/googverifadult3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Google killed the site quickly, but these things tend to be a little cut and paste (I've seen the above collection of photographs used on many phishing pages, for example). Always use common sense when asked to verify, revalidate or do something else with the letter "v" in it.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Christopher Boyd&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-3324160478419287151?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/3324160478419287151/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=3324160478419287151&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3324160478419287151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3324160478419287151'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/orkut-phish-serves-up-adult-content.html' title='Orkut phish serves up adult content warning'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-Jb7kQ9oh4sg/TpKIdJYhXyI/AAAAAAAABjU/elLyVWU3tyg/s72-c/googverifadult1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-5444353485848564768</id><published>2011-10-10T08:40:00.001-04:00</published><updated>2011-10-11T10:14:57.450-04:00</updated><title type='text'>It's Wardriving Jim, but not as we know it</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-bh28E51RrH8/TpKjna8pZKI/AAAAAAAABjs/JlVPQFKHLAo/s1600/clwardriving.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="217" src="http://3.bp.blogspot.com/-bh28E51RrH8/TpKjna8pZKI/AAAAAAAABjs/JlVPQFKHLAo/s400/clwardriving.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;This is really quite brilliant.&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-5444353485848564768?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/5444353485848564768/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=5444353485848564768&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5444353485848564768'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5444353485848564768'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/its-wardriving-jim-but-not-as-we-know.html' title='It&apos;s Wardriving Jim, but not as we know it'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-bh28E51RrH8/TpKjna8pZKI/AAAAAAAABjs/JlVPQFKHLAo/s72-c/clwardriving.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4969491853989311405</id><published>2011-10-10T02:42:00.001-04:00</published><updated>2011-10-10T02:42:17.510-04:00</updated><title type='text'>Phish falls at last hurdle</title><content type='html'>This is a reasonably convincing "give us your personal details" phish until the last moment when it all goes horribly wrong. The site in the first two screenshots is dead, the form is still live and hosted at&amp;nbsp;palimpalem(dot)com/4/tarjetasprepagas/index(dot)html&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"VISA and your mobile phone provider gives you spectacular prizes."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Reasonably convincing:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-EZAF3p7oLx8/TpKLzhTUHEI/AAAAAAAABjg/ekS9EVFfO_c/s1600/bnkprmo2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="245" src="http://1.bp.blogspot.com/-EZAF3p7oLx8/TpKLzhTUHEI/AAAAAAAABjg/ekS9EVFfO_c/s320/bnkprmo2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Reasonably convincing:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-emM7nmdNEv4/TpKL0hSK_8I/AAAAAAAABjk/N-xUJ12SSKE/s1600/bnkprmo1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="229" src="http://1.bp.blogspot.com/-emM7nmdNEv4/TpKL0hSK_8I/AAAAAAAABjk/N-xUJ12SSKE/s320/bnkprmo1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Full screen scrolling Matrix code background sitting behind a form asking for card details and PIN numbers:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-5ydwsWu-YB8/TpKMDPih_AI/AAAAAAAABjo/MLtQcfr6eNU/s1600/bnkprmo3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="185" src="http://1.bp.blogspot.com/-5ydwsWu-YB8/TpKMDPih_AI/AAAAAAAABjo/MLtQcfr6eNU/s320/bnkprmo3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;....I've seen better.&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4969491853989311405?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4969491853989311405/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4969491853989311405&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4969491853989311405'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4969491853989311405'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/phish-falls-at-last-hurdle.html' title='Phish falls at last hurdle'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-EZAF3p7oLx8/TpKLzhTUHEI/AAAAAAAABjg/ekS9EVFfO_c/s72-c/bnkprmo2.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-8557935470272537075</id><published>2011-10-10T01:40:00.001-04:00</published><updated>2011-10-10T01:40:17.418-04:00</updated><title type='text'>More fake iPad offers</title><content type='html'>No, Apple are &lt;a href="http://facecrooks.com/Safety-Center/Scam-Watch/In-Memory-of-Steve-Jobs-Apple-has-decided-to-give-away-1000-Limited-Edition-iPad-2-s-Facebook-Scam.html?print=1&amp;amp;tmpl=component"&gt;still not giving away iPads&lt;/a&gt;. Here's another Facebook fakeout located at the groanworthy URL stevejobsappleipad2giveway(dot)tk:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-XMpcLWLmJdg/TpKEKGnhBZI/AAAAAAAABjM/0PvR7DKIJSA/s1600/jobsapplescam1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-XMpcLWLmJdg/TpKEKGnhBZI/AAAAAAAABjM/0PvR7DKIJSA/s320/jobsapplescam1.gif" width="254" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Clicking the page elements they want you to click on takes you to the usual collection of offers and other assorted rubbish.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Y_MU-_o9eD4/TpKEk5UDV5I/AAAAAAAABjQ/8YTqceH4hz0/s1600/jobsapplescam2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="189" src="http://1.bp.blogspot.com/-Y_MU-_o9eD4/TpKEk5UDV5I/AAAAAAAABjQ/8YTqceH4hz0/s320/jobsapplescam2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Please don't fall for this nonsense.&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-8557935470272537075?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/8557935470272537075/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=8557935470272537075&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8557935470272537075'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8557935470272537075'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/more-fake-ipad-offers.html' title='More fake iPad offers'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-XMpcLWLmJdg/TpKEKGnhBZI/AAAAAAAABjM/0PvR7DKIJSA/s72-c/jobsapplescam1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-3475412824322459105</id><published>2011-10-10T01:01:00.001-04:00</published><updated>2011-10-10T01:05:12.138-04:00</updated><title type='text'>Another day, another XBox code generator</title><content type='html'>An "XBox code generator" site has been popping up on video sharing websites and elsewhere recently, even though a lot of the content promoting it hawked "Runescape moneymaking". The site is dead now, but the executable it promoted is still doing the rounds so let's take a look.&lt;br /&gt;&lt;br /&gt;First, the sales pitch - "How to make money with Runescape":&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-R_7ttRtlKKM/Tor7TDTNq0I/AAAAAAAABio/UEvdXxttn1Q/s1600/fkxbxgenweeb0.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="278" src="http://2.bp.blogspot.com/-R_7ttRtlKKM/Tor7TDTNq0I/AAAAAAAABio/UEvdXxttn1Q/s320/fkxbxgenweeb0.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Visiting the site would bounce you around a number of different redirects, all of which wanted you to download a program. The example below had some awesome pseudo tech babble:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-e-Mm9UX9o48/Tor7T_bVOgI/AAAAAAAABis/uGLURW1mrl0/s1600/fkxbxgenweeb1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="199" src="http://1.bp.blogspot.com/-e-Mm9UX9o48/Tor7T_bVOgI/AAAAAAAABis/uGLURW1mrl0/s320/fkxbxgenweeb1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;i&gt;"This is a fully employed xbox whippy maker. It cannot move your xbox untaped account - it gives you a cypher".&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Well, as long as it gives you a cypher. Anyway, hitting the "Generate code" button takes you to a download located on a free file hosting website. Like many programs of this nature, it cycles through a collection of (completely useless) fake codes each time you hit the Generate button. Most programs like this would have dropped something nasty on the PC by this point, or have asked for login credentials to email to the attacker behind the scenes. This one tries something a little different.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-SiTGPs90KcQ/Tor7Un_RlBI/AAAAAAAABiw/3Op156uGdMA/s1600/fkxbxgenweeb2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="168" src="http://2.bp.blogspot.com/-SiTGPs90KcQ/Tor7Un_RlBI/AAAAAAAABiw/3Op156uGdMA/s320/fkxbxgenweeb2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;You'll notice some text at the bottom of the program. It says:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"This version uses an outdated formula. The keys generated may not produce correct codes. Upgrade to 1.17"&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;I guess their cypher was faulty. Anyway, hitting the "upgrade button" - which I can't say I've ever seen in one of these things - takes you to a suspiciously named (dot)tk URL: xbox360generator(dot)tk.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-IPj2nNZzDfo/Tor7VXw6qiI/AAAAAAAABi0/epazV4zRNDM/s1600/fkxbxgenweeb3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="253" src="http://2.bp.blogspot.com/-IPj2nNZzDfo/Tor7VXw6qiI/AAAAAAAABi0/epazV4zRNDM/s320/fkxbxgenweeb3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Strangely, it was pointing to a football website - I say "was", because it now leads nowhere. In this case, the scammer was probably worried they'd be shut down and attempted to point the site to somewhere less suspicious (didn't work).&lt;br /&gt;&lt;br /&gt;Given the name of the .tk URL, it's possible that the scammer was attempting to first gain the trust of the user with the program, then direct them a web based equivalent that asked for login credentials. Maybe they just dumped you onto a survey scam instead. There's no real way to know now as all of the sites involved appear to be offline, but we can confirm this program does &lt;i&gt;not&lt;/i&gt; generate anything remotely useful.&lt;br /&gt;&lt;br /&gt;Including cyphers.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks to Alden Baleva for additional research)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-3475412824322459105?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/3475412824322459105/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=3475412824322459105&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3475412824322459105'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3475412824322459105'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/another-day-another-xbox-code-generator.html' title='Another day, another XBox code generator'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-R_7ttRtlKKM/Tor7TDTNq0I/AAAAAAAABio/UEvdXxttn1Q/s72-c/fkxbxgenweeb0.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-8182890701698497388</id><published>2011-10-07T04:04:00.000-04:00</published><updated>2011-10-07T08:26:57.730-04:00</updated><title type='text'>YapBrowser has returned</title><content type='html'>Yesterday I gave a talk at &lt;a href="http://www.virusbtn.com/conference/vb2011/index"&gt;VB 2011&lt;/a&gt; on the history of rogue web browsers - browsers that have been built from the ground up to cause end-users trouble. They often imitate the real thing, use similar logos to legit browsers, claim to be incredibly secure and offer lots of features and functionality. Typically it's all lies, and they're &lt;a href="http://blog.spywareguide.com/2007/03/netbrowserpro_the_porn_browser.html"&gt;dropping rootkits&lt;/a&gt;, &lt;a href="http://www.networkworld.com/news/2006/052206-yahoo-messaging-worm-installs-bogus.html"&gt;hijacking your desktop&lt;/a&gt; or &lt;a href="http://www.pcworld.com/article/126226/free_web_browser_may_give_you_more_than_you_asked_for.html"&gt;clicking invisible links&lt;/a&gt; out of view from the person using it.&lt;br /&gt;&lt;br /&gt;In my humble opinion, the worst of these browsers was something called Yapbrowser. This was a browser from 2006 that you could download, install and run just like any regular browser. Although it bundled with Zango adware, no hijacks were involved and you had the option to back out. Running the browser didn't raise any alarm bells - until you typed in a web address....any web address....and found yourself redirected to places &lt;a href="http://bit.ly/qe4UUn"&gt;you'd rather not go&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://www.sunbelt-software.com/ihs/alex/yapbrowser234081231.JPG"&gt;&lt;img alt="Yapbrowser234081231" border="0" height="314" src="http://www.sunbelt-software.com/ihs/alex/yapbrowser234081231_thumb.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;Redirecting users to &lt;a href="http://sunbeltblog.blogspot.com/2006/04/yapbrowser-getting-yelled-at.html"&gt;content that could send them to jail&lt;/a&gt; wasn't the best way to promote their browser, and it was quickly pulled. Shortly after the browser vanished, it &lt;a href="http://www.pcadvisor.co.uk/news/internet/6280/yapbrowser-reappears-online/"&gt;reappeared&lt;/a&gt; for a few more weeks claiming "full protection from virus attacks" - that didn't last long, and Yapbrowser was finally buried in 2006 after being &lt;a href="http://en.wikipedia.org/wiki/YapBrowser"&gt;acquired&lt;/a&gt;&amp;nbsp;by a company called SearchWebMe - the browser was gone forever, and the site was basically DOA.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Well&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;While giving my slide deck a final runthrough, I noticed a screenshot I was using from the Internet Archive wasn't displaying correctly so I went there to get an image that worked. I'm not sure what happened next - I thought I was looking at the Yapbrowser pages from 2006. Then I saw this:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-AYwPuFCMrh8/To6jLqmvYxI/AAAAAAAABi4/GV_dCPKleAg/s1600/yapisback1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="218" src="http://2.bp.blogspot.com/-AYwPuFCMrh8/To6jLqmvYxI/AAAAAAAABi4/GV_dCPKleAg/s400/yapisback1.gif" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;"July 2011"? Uh oh. Sure enough, visiting the Yapbrowser website right now gives us this:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-wSC3QlE1v90/To6mZLMi9GI/AAAAAAAABi8/zvZoOxON2_s/s1600/yapisback2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="305" src="http://2.bp.blogspot.com/-wSC3QlE1v90/To6mZLMi9GI/AAAAAAAABi8/zvZoOxON2_s/s400/yapisback2.gif" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Not only is there a "2011" notice at the bottom, there's a link to the Yapbrowser executable. The file appears to be the original from 2006, the EULA looks identical (to the extent it lists "yapbrowserATyapsearchDOTcom" as a contact, despite the fact that domain is long dead) and when fired up on a testbox it currently takes the end-user to Yapsearch, which is parked:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-VFqvm6ahgXM/To6qcE7LL2I/AAAAAAAABjA/mk-Ijio_3rg/s1600/yapisback3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="311" src="http://3.bp.blogspot.com/-VFqvm6ahgXM/To6qcE7LL2I/AAAAAAAABjA/mk-Ijio_3rg/s400/yapisback3.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Not only does it appear to be the same old file, the website blurb also makes the same ludicrous promises of security which are optimistic by any stretch of the imagination:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"Your computer will be free from viruses breeding online...There is a 100% guarantee no system infection will occur when using our software."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;When did the site and browser decide to rise from the grave? It's hard to tell, but here's the last Archive snapshot of the Yapbrowser(dot)com site from 2009:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-O_bZQSuTvxk/To6sMbT3xyI/AAAAAAAABjE/ZKzR6w5hsr8/s1600/yaposback4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="277" src="http://2.bp.blogspot.com/-O_bZQSuTvxk/To6sMbT3xyI/AAAAAAAABjE/ZKzR6w5hsr8/s400/yaposback4.gif" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;As you can see, it's still dead. Archive.org don't crawl the site during 2010, but they &lt;a href="http://wayback.archive.org/web/20110415000000*/http://yapbrowser.com"&gt;do revisit in 2011&lt;/a&gt; and at this point (Feburary 9th at the earliest) the site has returned, complete with old page layout, text and file download. One new change is the location of the download - whether clicking the "regular" download or the "adult" version, you're served the EXE from filesurfing(dot)com, which is a site used for "file searching" from download sites such as Rapidshare and Mediafire.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-iYhnuQfAV7k/To6uSxcAxbI/AAAAAAAABjI/hUXHOwXGfxw/s1600/yapisback5.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="228" src="http://4.bp.blogspot.com/-iYhnuQfAV7k/To6uSxcAxbI/AAAAAAAABjI/hUXHOwXGfxw/s400/yapisback5.gif" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Currently, Yapbrowser is &lt;a href="http://who.godaddy.com/whois.aspx?domain=yapbrowser.com&amp;amp;prog_id=GoDaddy"&gt;registered&lt;/a&gt; to what looks like a company registered in the UK. The name of the URL listed as the contact email address differs from SearchWebMe who originally bought the site / program back in 2006, but it's possible they're one and the same.&lt;br /&gt;&lt;br /&gt;Seeing this site lurch back into life, looking identical to how it did back in 2006 &lt;i&gt;and&lt;/i&gt; with the browser download following close behind is quite a shock. I imagine anyone else who researched this one will be feeling much the same, and given the history of this program coupled with the (still) nonsensical claims of security and virus evasion it would be quite the leap of faith to want to download and use this program.&lt;br /&gt;&lt;br /&gt;We'll be keeping a close eye on this one, and if the program starts to do anything beyond point at the parked domain we'll publish an update. For now? Our advice would be to stick with another browser. Like their highly appropriate slogan says: "Don't waste your time".&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks to Matthew and Patrick for additional information)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-8182890701698497388?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/8182890701698497388/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=8182890701698497388&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8182890701698497388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8182890701698497388'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/yapbrowser-has-returned.html' title='YapBrowser has returned'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-AYwPuFCMrh8/To6jLqmvYxI/AAAAAAAABi4/GV_dCPKleAg/s72-c/yapisback1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-2124210602811312152</id><published>2011-10-06T00:53:00.000-04:00</published><updated>2011-10-06T00:53:42.193-04:00</updated><title type='text'>Security Tools and Android Markets: Still Safe</title><content type='html'>Seven months ago, &lt;i&gt;Google&lt;/i&gt; officially released its &lt;i&gt;Android&lt;/i&gt; app, the &lt;a href="https://market.android.com/details?id=com.android.vending.sectool.v1&amp;amp;hl=en"&gt;Android Market Security Tool&lt;/a&gt;, in response to an outbreak of malicious apps being served then on the Android Market website.&amp;nbsp;Just a few days after, a &lt;a href="http://globalthreatcenter.com/?p=2108"&gt;trojanized version&lt;/a&gt;&amp;nbsp;of the said app had been spotted, baiting users into downloading and installing it on their smartphones. This was&amp;nbsp;served on third-party download sites. AV companies already detect the trojanized app.&lt;br /&gt;&lt;br /&gt;If your antivirus software detects the&amp;nbsp;&lt;i&gt;Android Market Security Tool&amp;nbsp;&lt;/i&gt;retrieved from the Android Market as malicious, even up to this point in time, let us reassure you that this app is clean. If you found yours &lt;i&gt;elsewhere&lt;/i&gt;, however, more than likely your app is a fake one. It's best to remove it from your phone (or PC if you have a copy of it in there, too) and get the legitimate copy from the Market.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Dean Bueno)&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-2124210602811312152?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/2124210602811312152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=2124210602811312152&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2124210602811312152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2124210602811312152'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/security-tools-and-android-markets.html' title='Security Tools and Android Markets: Still Safe'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-1143137038747044185</id><published>2011-10-05T21:53:00.001-04:00</published><updated>2011-10-05T21:53:32.507-04:00</updated><title type='text'>Thank you, Steve Jobs</title><content type='html'>I can't speak on behalf of all the folks on this side of the globe who loves technology, specifically from Apple. Who knows how these nifty gadgets have impacted their business and personal lives, but surely, the impact is hugely positive and lasting.&lt;br /&gt;&lt;br /&gt;Thank you, Steve Jobs. You have made an indelible impression not just in the technology sector but also in the hearts and minds of people.&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-1143137038747044185?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/1143137038747044185/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=1143137038747044185&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1143137038747044185'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1143137038747044185'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/thank-you-steve-jobs.html' title='Thank you, Steve Jobs'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-284022421629696820</id><published>2011-10-04T03:02:00.002-04:00</published><updated>2011-10-04T03:02:24.907-04:00</updated><title type='text'>Scammers Bank on Free Flights Before the Holidays</title><content type='html'>Matthew, one of our researchers at the AV Labs, flagged us regarding a &lt;b&gt;&lt;i&gt;Facebook&lt;/i&gt;&lt;/b&gt; scam he spotted late last weekend. And his timing could not have been more impeccable. The scam is about &lt;b&gt;Southwest Airlines&lt;/b&gt; giving away free tickets. Now, as a practical rule of thumb, if something free is given by (a) a non-friend, (b) a non-relative, and (c) a random someone / bot who / that found their way on your social networking feed, you better start thinking twice before clicking that link to accept the freebie. If they're from people you actually know? Double the amount of thinking.Trust me.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-Q1ZX6ZqrB1k/TooK95H4C0I/AAAAAAAAAQg/8ytsVUO_2bU/s1600/southwest_FBscam_01.png" imageanchor="1"&gt;&lt;img border="0" height="101" src="http://4.bp.blogspot.com/-Q1ZX6ZqrB1k/TooK95H4C0I/AAAAAAAAAQg/8ytsVUO_2bU/s320/southwest_FBscam_01.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;What made this particular scam interesting is that the scammers had used and abused a &lt;i&gt;Facebook&lt;/i&gt; &lt;b&gt;token&lt;/b&gt; generator to spread it. A &lt;a href="http://en.wikipedia.org/wiki/Security_token"&gt;token&lt;/a&gt; is basically an electronic key that is used to access something one does not readily have access to. In this case, a token is used to gain rights to post on &lt;i&gt;Facebook&lt;/i&gt; walls.Once users click the link of the scam post, they are directed to &lt;i&gt;www(dot)southwestisbest(dot)com&lt;/i&gt; where an entry box pops up, asking users to "access the offer" by entering a validation code. You can't go around this one, since there is no option to somehow allow a user to decline to do this action.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-OiP_aTflCdI/TooLYAKqRWI/AAAAAAAAAQo/GfESutHktD4/s1600/southwest_FBscam_02.png" imageanchor="1"&gt;&lt;img border="0" height="288" src="http://3.bp.blogspot.com/-OiP_aTflCdI/TooLYAKqRWI/AAAAAAAAAQo/GfESutHktD4/s320/southwest_FBscam_02.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;"Click Here to Generate Your Validation Code"&lt;/i&gt; - and a small browser window, with the URL &lt;i&gt;m(dot)facebook(dot)com/ajax/dtsg(dot)php&lt;/i&gt;, shows to display the code.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-style: normal;"&gt;&lt;a href="http://2.bp.blogspot.com/-I7Ufxo1vWNw/TooLiYfwy7I/AAAAAAAAAQw/QNJTywa_bVc/s1600/southwest_FBscam_03.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://2.bp.blogspot.com/-I7Ufxo1vWNw/TooLiYfwy7I/AAAAAAAAAQw/QNJTywa_bVc/s320/southwest_FBscam_03.png" width="320" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Hitting the &lt;i&gt;Submit&lt;/i&gt; button enables the app to post on the user's &lt;i&gt;Facebook&lt;/i&gt; wall. "But wait!" It doesn't end there though. Users, clearly unbeknownst to the posting done on their walls, are then redirected to a page asking for their email addresses. After this, they will be asked to complete a survey.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-EBHjlnKmRoQ/TooL1obc-zI/AAAAAAAAAQ4/U3Z5rdNoqo4/s1600/southwest_FBscam_04.png" imageanchor="1"&gt;&lt;img border="0" height="233" src="http://3.bp.blogspot.com/-EBHjlnKmRoQ/TooL1obc-zI/AAAAAAAAAQ4/U3Z5rdNoqo4/s320/southwest_FBscam_04.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;Click to enlarge&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;Our experts had already reported this to &lt;i&gt;Facebook&lt;/i&gt; and the sites had been taken down shortly after, in turn also terminating the issuance of tokens.&lt;br /&gt;&lt;br /&gt;There are other Southwest Airline scams that have been making rounds on &lt;i&gt;Facebook&lt;/i&gt;. One such scam &lt;a href="http://nakedsecurity.sophos.com/2011/10/03/freesouthwest-airlines-tickets/"&gt;was found by our friends at Sophos&lt;/a&gt; (Do check out that post, too). So far, however, this is the only one we've seen that uses tokens.&lt;br /&gt;&lt;br /&gt;As the Christmas season draws near, criminals are taking advantage of consumers wanting to grab the cheapest flights towards their destinations. And they have been for the longest time we can all remember. Be prudent and smart when it comes to gimmicks you see online, never click on links that offer things that sound too good to be true, and never give away any information until you know what these companies are going to do with them.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Matthew for spotting this)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-284022421629696820?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/284022421629696820/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=284022421629696820&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/284022421629696820'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/284022421629696820'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/scammers-bank-on-free-flights-before.html' title='Scammers Bank on Free Flights Before the Holidays'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-Q1ZX6ZqrB1k/TooK95H4C0I/AAAAAAAAAQg/8ytsVUO_2bU/s72-c/southwest_FBscam_01.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-6092019584278632159</id><published>2011-10-03T02:15:00.000-04:00</published><updated>2011-10-03T02:15:19.202-04:00</updated><title type='text'>Google Anniversary scam mail gets it horribly wrong</title><content type='html'>It seems scammers need to play a little catch up, or at least read the odd news site occasionally. Here's an email going around trying out the &lt;a href="http://www.hoax-slayer.com/google-anniversary-lottery-scam.shtml"&gt;well worn theme&lt;/a&gt; of "Google Anniversary" 419 scam mails:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-TeFGraMvsS8/TolRn8WS8pI/AAAAAAAABik/xkVRO2FDJww/s1600/fakegoogmail11th.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-TeFGraMvsS8/TolRn8WS8pI/AAAAAAAABik/xkVRO2FDJww/s320/fakegoogmail11th.gif" width="204" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;i&gt;"We are pleased to inform you that your email address has won you an Award in the Google 11th Anniversary Awards as organized by the Anniversary Centre of Google Inc. held on September 28th 2011 in London, United Kingdom."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Humorously, the scammers are sending out 11th anniversary mails when that &lt;a href="http://www.guardian.co.uk/technology/2009/sep/27/google-searchengines"&gt;actually took place in 2009&lt;/a&gt; - we &lt;a href="http://mashable.com/2011/09/27/google-doodles-birthday/"&gt;recently hit number 13&lt;/a&gt;. They don't need your financial details, they need a calendar.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks to Wendy for sending this one over)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-6092019584278632159?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/6092019584278632159/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=6092019584278632159&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6092019584278632159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6092019584278632159'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/10/google-anniversary-scam-mail-gets-it.html' title='Google Anniversary scam mail gets it horribly wrong'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-TeFGraMvsS8/TolRn8WS8pI/AAAAAAAABik/xkVRO2FDJww/s72-c/fakegoogmail11th.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-1955918761774803864</id><published>2011-09-29T13:00:00.000-04:00</published><updated>2011-09-29T13:25:38.858-04:00</updated><title type='text'>Charitable Results</title><content type='html'>One of our researchers noticed that searches in &lt;i&gt;Yahoo!&lt;/i&gt; for popular programs will result in &lt;i&gt;Yahoo!&lt;/i&gt; placing their own link as the first result, effectively bumping the official program links down into second place.&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-nsAOj5to1hs/ToQe7tgGKYI/AAAAAAAABiI/agNjKDAypJk/s1600/yahoadstmvr1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://1.bp.blogspot.com/-nsAOj5to1hs/ToQe7tgGKYI/AAAAAAAABiI/agNjKDAypJk/s320/yahoadstmvr1.gif" width="320" /&gt;&lt;/a&gt;&lt;br&gt;Click to Enlarge&lt;/div&gt;Clicking the first link takes you to the &lt;i&gt;Yahoo! Downloads&lt;/i&gt; portal instead of the official Teamviewer site which is sitting down in the number two spot.&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-VWx2IrF9B5c/ToQjZeepX0I/AAAAAAAABiM/xL0qu8AM0Vo/s1600/yahoadstmvr2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-VWx2IrF9B5c/ToQjZeepX0I/AAAAAAAABiM/xL0qu8AM0Vo/s320/yahoadstmvr2.gif" width="317" /&gt;&lt;/a&gt;&lt;br /&gt;Click to Enlarge&lt;/div&gt;It's the same deal for various other downloads such as Skype:&lt;div style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-t25o84VZuuI/ToQnvhcUwfI/AAAAAAAABiQ/hd9Nn_ijQlI/s1600/yahoadstmvr3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="296" src="http://3.bp.blogspot.com/-t25o84VZuuI/ToQnvhcUwfI/AAAAAAAABiQ/hd9Nn_ijQlI/s320/yahoadstmvr3.gif" width="320" /&gt;&lt;/a&gt;&lt;br /&gt;Click to Enlarge&lt;/div&gt;The downloads come with additional extras that you wouldn't see if you'd grabbed them from the official developer site. Cue GFI Researcher Matthew, who first noticed this:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"If the user runs the download from this page, they will be presented with an offer for the Yahoo toolbar and then either Shop to Win or Social Ribbons add-on. After the user accepts or declines these offers, the installer then downloads the actual Teamviewer installer from Tucows to the user's desktop and and prompts the user to run it."&lt;/i&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-KrthVtkQ0nU/ToRIXTOK5XI/AAAAAAAABiU/bqkKOYYdTOs/s1600/yahoadstmvr4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="251" src="http://3.bp.blogspot.com/-KrthVtkQ0nU/ToRIXTOK5XI/AAAAAAAABiU/bqkKOYYdTOs/s320/yahoadstmvr4.gif" width="320" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-qBkNrX7GyZQ/ToRIYE8dlkI/AAAAAAAABiY/3NaDxQ85m9I/s1600/yahoadstmvr5.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="251" src="http://3.bp.blogspot.com/-qBkNrX7GyZQ/ToRIYE8dlkI/AAAAAAAABiY/3NaDxQ85m9I/s320/yahoadstmvr5.gif" width="320" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-8eDRBGFHEmQ/ToRIYn2VX-I/AAAAAAAABic/9myKpurpR_o/s1600/yahoadstmvr6.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="251" src="http://2.bp.blogspot.com/-8eDRBGFHEmQ/ToRIYn2VX-I/AAAAAAAABic/9myKpurpR_o/s320/yahoadstmvr6.gif" width="320" /&gt;&lt;/a&gt;&lt;br&gt;Click to Enlarge&lt;/div&gt;The SocialRibbons install is interesting - if you're not familiar with it, it's a browser plugin that&amp;nbsp;inserts their affiliate code into the URLs of merchants' sites you happen shop at, then picks up the the affiliate commission when you make purchases at those sites. The idea is that an end-user would install it because Social Ribbons pledges to &lt;a href="http://www.socialribbons.org/wrappers/main.php"&gt;donate&lt;/a&gt; a percentage of that affiliate commission to charities.&lt;br /&gt;&lt;br /&gt;However, the exact percentage of the affiliate commission that is donated to charity is not specified. Just one month ago they claimed that $18,000 had been donated based on 250,000 users - which works out to 8 cents per user.&amp;nbsp;The whole point of this type of program is to drive shoppers to participating merchants' sites, yet no list of participating merchants is available on the Social Ribbons site. In other words, users don't even know where to go to make their shopping dollars count for charities.&lt;br /&gt;&lt;br /&gt;Furthermore, the charities themselves are not specified - there is an example of the below installer mentioning &amp;nbsp;the "Susan G. Kohen Foundation" - did they mean the &lt;a href="http://www.komen.org/"&gt;Susan G. &lt;i&gt;Komen&lt;/i&gt; Foundation&lt;/a&gt;?&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-OtReldVcw68/ToSgzMYVEKI/AAAAAAAABig/iz0CJfFTdGQ/s1600/yahoadstmvr7.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="264" src="http://2.bp.blogspot.com/-OtReldVcw68/ToSgzMYVEKI/AAAAAAAABig/iz0CJfFTdGQ/s320/yahoadstmvr7.gif" width="320" /&gt;&lt;/a&gt;&lt;br&gt;Click to Enlarge&lt;/div&gt;They collect basic demographic information and claim to monitor web surfing behavior for the purposes of targeted advertising, though this is never mentioned in a clear and conspicuous fashion outside of the EULA/&lt;a href="http://www.socialribbons.org/legal/privacy.php"&gt;Privacy Policy&lt;/a&gt; (Section 2, "Use of individual information").&lt;br /&gt;&lt;br /&gt;All in all, there's a fair amount of additional content you're installing via these promoted search links that you wouldn't receive if installing from the sites of the program creators. It would perhaps be worth pointing out to relatives unfamiliar with promoted search engine results that you don't always get the "official" site as the first clickable link at the top of the pile - especially when the search engine you're using is placing links it has a connection with above the rest.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks to Matthew and Eric for additional information)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-1955918761774803864?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/1955918761774803864/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=1955918761774803864&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1955918761774803864'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1955918761774803864'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/charitable-results.html' title='Charitable Results'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-nsAOj5to1hs/ToQe7tgGKYI/AAAAAAAABiI/agNjKDAypJk/s72-c/yahoadstmvr1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-1063840968111630249</id><published>2011-09-29T02:28:00.002-04:00</published><updated>2011-09-29T02:28:36.219-04:00</updated><title type='text'>Green Card Lottery Spam</title><content type='html'>Here's a curious bit of spam mail involving the well worn subject of Green Card Lotteries:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-eOZ0QOakM-o/ToQJWtDLrxI/AAAAAAAABiA/Jf4lVzaTu3A/s1600/usgrncrdlottrspam1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-eOZ0QOakM-o/ToQJWtDLrxI/AAAAAAAABiA/Jf4lVzaTu3A/s320/usgrncrdlottrspam1.gif" width="179" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Did you know the "Department of State" send out random emails from a free MSN address? No, neither did I. This multicoloured monstrosity claims you've won a US green card, then goes on to say you need to stump up $400 to seal the deal anyway.&lt;br /&gt;&lt;br /&gt;Yeah, brilliant. They also claim you'll get a "free airline ticket to the US", use a lesser known &lt;a href="http://en.wikipedia.org/wiki/.hm"&gt;.hm domain&lt;/a&gt; as their contact email address and their website contains the following disclaimer:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"USGreenCardLottery(dot)org is a division of 'US IMMIGRATION CENTER', a private entity not affiliated with the U.S. Government."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;What a great name for a private entity, and not at all confusing. The best is saved for last, which would be the location of the lady who supposedly sent you this ticket to a new way of life in the first place:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-jqZTVkDSxW4/ToQPSotdutI/AAAAAAAABiE/vtfj-U5zbng/s1600/usgrncrdlottrspam2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-jqZTVkDSxW4/ToQPSotdutI/AAAAAAAABiE/vtfj-U5zbng/s1600/usgrncrdlottrspam2.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Poor old Ken.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks Alex)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-1063840968111630249?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/1063840968111630249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=1063840968111630249&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1063840968111630249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1063840968111630249'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/green-card-lottery-spam.html' title='Green Card Lottery Spam'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-eOZ0QOakM-o/ToQJWtDLrxI/AAAAAAAABiA/Jf4lVzaTu3A/s72-c/usgrncrdlottrspam1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-2908121501792777075</id><published>2011-09-29T01:32:00.000-04:00</published><updated>2011-09-29T01:32:02.823-04:00</updated><title type='text'>More bad ads in Bing</title><content type='html'>Bad adverts in Bing leading end-users to Malware downloads first popped up on our radar on the&amp;nbsp;&lt;a href="http://sunbeltblog.blogspot.com/2011/09/bing-yahoo-search-adverts-serve-up.html"&gt;16th of September&lt;/a&gt;, and we covered them again on the &lt;a href="http://sunbeltblog.blogspot.com/2011/09/another-round-of-bad-ads-in-bing.html"&gt;19th&lt;/a&gt;. Well, they're back again - this time promoting fake Firefox downloads whose ads are displayed when searching for....wait for it...."Firefox download":&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-eq-S2HyOYbo/ToP-bHQZhtI/AAAAAAAABh4/3gQP3-bEuXk/s1600/mrbgadsff1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="163" src="http://3.bp.blogspot.com/-eq-S2HyOYbo/ToP-bHQZhtI/AAAAAAAABh4/3gQP3-bEuXk/s320/mrbgadsff1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-Gq68lFlkICo/ToP-eJi3WRI/AAAAAAAABh8/KAnFV7OFLnM/s1600/mrbgadsff2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="206" src="http://4.bp.blogspot.com/-Gq68lFlkICo/ToP-eJi3WRI/AAAAAAAABh8/KAnFV7OFLnM/s320/mrbgadsff2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;You'll notice they missed a trick there, advertising Firefox 6 instead of the freshly minted &lt;a href="http://www.mozilla.org/en-US/firefox/new/"&gt;Firefox 7&lt;/a&gt;. The URLs involved are&amp;nbsp;hotelcrystalpark(dot)com/firefox_1 and&amp;nbsp;firefox(dot)dl-labs(dot)com, with the rogue downloads being hosted at the dl-labs URL. VirusTotal score currently gives us &lt;a href="http://www.virustotal.com/file-scan/report.html?id=1417e815b627d079f3809a941904781b947345e9e5cfd59dd563ebc5c772c285-1317230589"&gt;6/43&lt;/a&gt;, with VIPRE detecting this as&amp;nbsp;Trojan.Win32.Kryptik.cqw (v).&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks to Matthew for finding this one).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-2908121501792777075?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/2908121501792777075/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=2908121501792777075&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2908121501792777075'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2908121501792777075'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/more-bad-ads-in-bing.html' title='More bad ads in Bing'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-eq-S2HyOYbo/ToP-bHQZhtI/AAAAAAAABh4/3gQP3-bEuXk/s72-c/mrbgadsff1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-3885028874742468712</id><published>2011-09-28T20:39:00.000-04:00</published><updated>2011-09-28T20:39:19.138-04:00</updated><title type='text'>Seen in the wild:  419 scammers now using calendar invites</title><content type='html'>Desperate to purloin money out of stupid and desparate people, 419 scammers are now trying Google Calendar invites. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.sunbeltsoftware.com/alex/gblog/419scammer2124654654a.png"&gt;&lt;img alt="419scammer2124654654a" border="0" src="http://www.sunbeltsoftware.com/alex/gblog/419scammer2124654654a_thumb.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.sunbeltsoftware.com/alex/gblog/419scammer2124654654.png"&gt;&lt;img alt="419scammer2124654654" border="0" src="http://www.sunbeltsoftware.com/alex/gblog/419scammer2124654654_thumb1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The pain of it is that if you’re using Outlook, the calendar invite is automatically accepted and you get a reminder popping up.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;img alt="419scammer2124654654c" border="0" src="http://www.sunbeltsoftware.com/alex/gblog/419scammer2124654654c.png" /&gt;&lt;br /&gt;&lt;br /&gt;This has to be the rudest, nastiest spam I’ve seen in a long time. &lt;br /&gt;&lt;br /&gt;Alex Eckelberry&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-3885028874742468712?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/3885028874742468712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=3885028874742468712&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3885028874742468712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3885028874742468712'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/seen-in-wild-419-scammers-now-using.html' title='Seen in the wild:  419 scammers now using calendar invites'/><author><name>Alex Eckelberry</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-89045124859841633</id><published>2011-09-23T03:42:00.000-04:00</published><updated>2011-09-23T09:49:58.979-04:00</updated><title type='text'>The fake BBC video Facebook scam returns</title><content type='html'>It seems scammers have a bit of thing for spoofing BBC websites at the moment. Yesterday it was &lt;a href="http://nakedsecurity.sophos.com/2011/09/22/bbc-news-trust-work-home-scam-spam/"&gt;work from home scams&lt;/a&gt;, and last month it was a Facebook wheeze which (in a nutshell) went like this: &lt;i&gt;"&lt;a href="http://nakedsecurity.sophos.com/2011/08/05/lady-gaga-found-dead-in-hotel-room-beware-facebook-clickjacking-scam/"&gt;Lady Gaga is dead and here's a BBC video to prove it&lt;/a&gt;, also click here."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Maybe the (unrelated) work from home fakeout has inspired scammers into a fresh round of BBC shenanigans, because the phony BBC video rides again on Facebook. As usual, it's surveytacular and is geared around fake Facebook messages promoting the completely fake BBC page:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-5boG91r22v8/Tnw0VciXp4I/AAAAAAAABhs/jdmWOemPSD4/s1600/linkpostedbyrogueapp.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-5boG91r22v8/Tnw0VciXp4I/AAAAAAAABhs/jdmWOemPSD4/s1600/linkpostedbyrogueapp.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;If you believe the hype - and you shouldn't - a girl has "killed herself" due to her dad posting silly things on her wall. Also note that it's been posted via "My Best Stalkers", which sounds exactly like the kind of Facebook app end-users should be avoiding. Sure enough, clicking the link gives you this survey prompt:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-KIMca3E-OZI/Tnw2Yad6HdI/AAAAAAAABhw/wVF9sf61os4/s1600/fakebbcfbscam1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="296" src="http://3.bp.blogspot.com/-KIMca3E-OZI/Tnw2Yad6HdI/AAAAAAAABhw/wVF9sf61os4/s320/fakebbcfbscam1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-RV1goBngrhM/Tnw24zd-mEI/AAAAAAAABh0/XnoJEBGNSCk/s1600/fakebbcfbscam2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="221" src="http://3.bp.blogspot.com/-RV1goBngrhM/Tnw24zd-mEI/AAAAAAAABh0/XnoJEBGNSCk/s320/fakebbcfbscam2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;The site in question is&amp;nbsp;sqvw(dot)myfannso(dot)in/e/, and is still currently live at time of writing. This is one news report you can afford to miss.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks to Matthew for finding this one).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-89045124859841633?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/89045124859841633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=89045124859841633&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/89045124859841633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/89045124859841633'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/fake-bbc-video-facebook-scam-returns.html' title='The fake BBC video Facebook scam returns'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-5boG91r22v8/Tnw0VciXp4I/AAAAAAAABhs/jdmWOemPSD4/s72-c/linkpostedbyrogueapp.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-7927587369376790863</id><published>2011-09-22T02:24:00.001-04:00</published><updated>2011-09-22T02:39:36.430-04:00</updated><title type='text'>Bioshocked</title><content type='html'>Just a quick heads up that there's a Twitter spamrun targeting mentions of the videogame &lt;a href="http://en.wikipedia.org/wiki/BioShock_Infinite"&gt;Bioshock Infinite&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The promise: "My friend got Bioshock Infinite free".&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-z7uz0c4_DVw/TnrTqjihaVI/AAAAAAAABhk/U-32cv_4eFk/s1600/bioshocked1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-z7uz0c4_DVw/TnrTqjihaVI/AAAAAAAABhk/U-32cv_4eFk/s320/bioshocked1.gif" width="111" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;The reality:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-uD9yxmWihHo/TnrTsrAv9qI/AAAAAAAABho/Ovi_7hJ9Ssg/s1600/bioshocked2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="196" src="http://1.bp.blogspot.com/-uD9yxmWihHo/TnrTsrAv9qI/AAAAAAAABho/Ovi_7hJ9Ssg/s320/bioshocked2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;A woman doing aeroplane impressions. Of course, people getting free copies of Bioshock Infinite would be quite a feat in itself, given the thing &lt;a href="http://www.eurogamer.net/articles/2010-08-12-bioshock-infinite-preview?page=3"&gt;won't be released until 2012&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;[Update 1]&lt;/b&gt; It seems numerous games are having the same spammy treatment - we're informed that poor old Batman is having similar problems with spam such as this:&lt;br /&gt;&lt;br /&gt;"This is amazing! Get a FREE copy of the new Batman: Arkham City. Get one here"&lt;br /&gt;"I love batman, I play the video game look at this"&lt;br /&gt;&lt;br /&gt;As before, the URLs lead to linkdumps, spam offers and other assorted junk. Thanks to &lt;a href="https://twitter.com/#!/elwang/status/116760625270636544"&gt;Pete&lt;/a&gt; for the heads up.&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-7927587369376790863?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/7927587369376790863/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=7927587369376790863&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7927587369376790863'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7927587369376790863'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/bioshocked.html' title='Bioshocked'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-z7uz0c4_DVw/TnrTqjihaVI/AAAAAAAABhk/U-32cv_4eFk/s72-c/bioshocked1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4263273038794638683</id><published>2011-09-19T10:26:00.001-04:00</published><updated>2011-09-19T10:26:35.108-04:00</updated><title type='text'>Another round of bad ads in Bing</title><content type='html'>We're seeing &lt;a href="http://sunbeltblog.blogspot.com/2011/09/bing-yahoo-search-adverts-serve-up.html"&gt;some more bad adverts&lt;/a&gt; popping up in Bing - just like the original attack, these results are served with very basic search terms so it's pretty easy to stumble into one of the bad URLs. The results below appear when searching for "Flash player download":&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-AGEruar1Hzs/TndMlemE5RI/AAAAAAAABhc/-8tusBpiOcw/s1600/morebingmalads1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="290" src="http://1.bp.blogspot.com/-AGEruar1Hzs/TndMlemE5RI/AAAAAAAABhc/-8tusBpiOcw/s320/morebingmalads1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;In the below example, the end-user arrives at&amp;nbsp;malaysiaaktif(dot)com/flash and the fake Flash Player file is served up from&amp;nbsp;dl-softonic(dot)net (a slight change from the original URL used to push the files which flatlined a few days ago):&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-SqGFgaPEjEY/TndMmte-OMI/AAAAAAAABhg/eQ4Ji3wBASo/s1600/morebingmalads2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="290" src="http://2.bp.blogspot.com/-SqGFgaPEjEY/TndMmte-OMI/AAAAAAAABhg/eQ4Ji3wBASo/s320/morebingmalads2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;As before, these are not particularly sites you want to be wandering into so please be careful when searching for basic tools, programs and files in Bing until these rogue adverts have a healthy dose of "put in jail and throw away the key" applied to them.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks Matthew)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4263273038794638683?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4263273038794638683/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4263273038794638683&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4263273038794638683'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4263273038794638683'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/another-round-of-bad-ads-in-bing.html' title='Another round of bad ads in Bing'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-AGEruar1Hzs/TndMlemE5RI/AAAAAAAABhc/-8tusBpiOcw/s72-c/morebingmalads1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4740094125703417194</id><published>2011-09-19T03:24:00.001-04:00</published><updated>2011-09-19T05:38:02.056-04:00</updated><title type='text'>Lucas Ex Machina: I never asked for this</title><content type='html'>&lt;iframe allowfullscreen="" frameborder="0" height="315" src="http://www.youtube.com/embed/4FRWYRqaGFE" width="500"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;In-game advertising has been around for a long time (specifically since &lt;a href="http://watchplayread.com/sell-me-something-in-game-advertisements/"&gt;1978&lt;/a&gt;, when the Scott Adams game 'Adventureland' placed a promotional message in the game for his next release '&lt;a href="http://en.wikipedia.org/wiki/Pirate_Adventure"&gt;Pirate Adventure&lt;/a&gt;', which involved crackers, a parrot and dying a lot).&lt;br /&gt;&lt;br /&gt;There are three main types: Static (which as you probably guessed don't do much other than sit there advertising things. They don't change and can't interact with the outside world), Dynamic (which are adverts effectively injected into the game world on the fly, meaning your futuristic shooter can have up to the minute posters on the wall for Pepsi or Alienware or whatever. These can also track gamers with regards successful advertising - for example, length of time spent staring at it when you should have been shooting at other gamers). The final type is 'Advergaming" which would take way too much time to explain, so here's the &lt;a href="http://en.wikipedia.org/wiki/Advergaming"&gt;Wiki page&lt;/a&gt;. Go nuts.&lt;br /&gt;&lt;br /&gt;Attempts at ingame advertising can be successful (Keanu billboards in &lt;a href="http://www.joystiq.com/2006/05/17/study-shows-more-support-for-in-game-ads/"&gt;The Matrix Online&lt;/a&gt;? &lt;i&gt;Meta&lt;/i&gt;), &lt;a href="http://www.joystiq.com/2008/10/14/obama-ad-appears-in-burnout-paradise/"&gt;somewhat innovative&lt;/a&gt; or run into teething troubles - more often than not on consoles where EULAs and other agreements may involve some &lt;a href="http://www.flickr.com/photos/paperghost/4776849864/"&gt;hoop jumping&lt;/a&gt; to read.&lt;br /&gt;&lt;br /&gt;You can see why gamers tend to be irked by advertising in their gaming, and a&amp;nbsp;case in point would be a furore surrounding a&amp;nbsp;&lt;a href="http://www.bit-tech.net/news/gaming/2011/09/16/deus-ex-human-revolution-gets-in-game-adver/1"&gt;recent patch&lt;/a&gt;&amp;nbsp;applied to &lt;a href="http://en.wikipedia.org/wiki/Deus_Ex:_Human_Revolution"&gt;Deus Ex: Human Revolution&lt;/a&gt;&amp;nbsp;(which is apparently&amp;nbsp;&lt;a href="http://www.destructoid.com/deus-ex-human-revolution-adds-star-wars-ads-update--211559.phtml"&gt;not the cause&lt;/a&gt;&amp;nbsp;of said advertising furore, it's just some unfortunate timing.)&amp;nbsp;Gamers are complaining about a somewhat&amp;nbsp;noticeable&amp;nbsp;addition to loading screens: see if you can spot it.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-13u7uaECQLQ/TnbAb6M1Y7I/AAAAAAAABhA/xG45ZIeVaHw/s1600/lucasexmach1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="177" src="http://2.bp.blogspot.com/-13u7uaECQLQ/TnbAb6M1Y7I/AAAAAAAABhA/xG45ZIeVaHw/s320/lucasexmach1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;I'm not sure if it's up there with the Vader "NOOOOOOOOOO", but it certainly gives Midichlorians a run for their money. A rather bright and unavoidable &lt;a href="http://i.imgur.com/wfjKf.png"&gt;Star Wars advert&lt;/a&gt; sits in the bottom right corner of the screen, pleading with you to use the Force and buy the boxset. A few more examples can be seen &lt;a href="http://www.joystiq.com/2011/09/15/star-wars-ads-find-their-way-into-deus-ex-human-revolution-load/"&gt;here&lt;/a&gt; and &lt;a href="http://www.escapistmagazine.com/news/view/113082-Deus-Ex-Gets-Augmented-with-Star-Wars-Advertisements"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;As you may have guessed, people&amp;nbsp;&lt;a href="http://forums.steampowered.com/forums/showthread.php?t=2122019"&gt;aren't&lt;/a&gt; &lt;a href="http://www.neogaf.com/forum/showpost.php?p=31009299&amp;amp;postcount=280"&gt;best&lt;/a&gt; &lt;a href="http://www.pixelitis.net/news/stars-wars-blu-ray-ads-in-my-deus-ex"&gt;pleased&lt;/a&gt;&amp;nbsp;and the inevitable result is users attempting to game the system - you can see what I did there - and kill the ads off. Some are tweaking their &lt;a href="http://en.wikipedia.org/wiki/Hosts_(file)"&gt;Hosts file&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-C3BK6MXNE-c/TnbGmSWb8cI/AAAAAAAABhE/LlzWo6nNPhw/s1600/lucasexmach2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="185" src="http://3.bp.blogspot.com/-C3BK6MXNE-c/TnbGmSWb8cI/AAAAAAAABhE/LlzWo6nNPhw/s320/lucasexmach2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Others are downloading random patches and mods from the internet:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-kV2L36KQojA/TnbKkwEAcDI/AAAAAAAABhI/m8lzdb2bKYk/s1600/lucasexmach3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="216" src="http://2.bp.blogspot.com/-kV2L36KQojA/TnbKkwEAcDI/AAAAAAAABhI/m8lzdb2bKYk/s320/lucasexmach3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;While there aren't any reports of malicious patches compromising systems (though the above popular ad killer currently hits a &lt;a href="http://www.virustotal.com/file-scan/report.html?id=f98f28b413fac516df28831a3d4fabfab1b1d01872f212d452da23274354387f-1316400636"&gt;1/44&lt;/a&gt; detection in VirusTotal which appears to be a "&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2010-051308-1854-99"&gt;Wisdom of the Crowds&lt;/a&gt;" thing), I can't say it's a great idea to be downloading files and hoping they don't blow your PC sky high. Another issue is that the game developers (or whoever is providing you the platform to play your PC game on, such as Steam) may not take kindly to tampering, and could theoretically ban your account / access / some other thing you can't really go without.&lt;br /&gt;&lt;br /&gt;This would not be a good thing.&lt;br /&gt;&lt;br /&gt;Of course, "patches" and cracks are appearing on Youtube and similar sites, all of which result in survey popups and fakeout websites galore - this probably won't matter one jot to anybody &lt;i&gt;really&lt;/i&gt; desperate to hose that Star Wars promo and a clicking they will go:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-8E-DpTlHKR0/TnbfAzBztiI/AAAAAAAABhM/bfLtCUseoYM/s1600/lucasexmach4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="203" src="http://4.bp.blogspot.com/-8E-DpTlHKR0/TnbfAzBztiI/AAAAAAAABhM/bfLtCUseoYM/s320/lucasexmach4.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-sslVsomPXzc/TnbhoZn8mRI/AAAAAAAABhQ/ohRye4yJQBY/s1600/lucasexmach5.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="255" src="http://2.bp.blogspot.com/-sslVsomPXzc/TnbhoZn8mRI/AAAAAAAABhQ/ohRye4yJQBY/s320/lucasexmach5.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/--8s-bpM1FqE/TnbjQpNRxVI/AAAAAAAABhU/vYtiGQPLaaY/s1600/lucasexmach6.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="265" src="http://4.bp.blogspot.com/--8s-bpM1FqE/TnbjQpNRxVI/AAAAAAAABhU/vYtiGQPLaaY/s320/lucasexmach6.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-FTqgsl5i_3E/TnbkeVOqIoI/AAAAAAAABhY/hyy88w-ug7A/s1600/lucasexmach7.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="245" src="http://2.bp.blogspot.com/-FTqgsl5i_3E/TnbkeVOqIoI/AAAAAAAABhY/hyy88w-ug7A/s320/lucasexmach7.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;...and so on. For me, the most interesting thing about this one is that the adverts have gone live a little while after the game has &lt;a href="http://gamrreview.vgchartz.com/sales/43322/deus-ex-human-revolution/"&gt;already sold&lt;/a&gt; a stack of copies - I'm struggling to think of ingame adverts that weren't live from the moment the title was released, and this has contributed toward the negative reaction for what is a small (if distracting) advertisement. At any rate, it's definitely created an opportunity for people with malicious intent to snag some victims, either by survey affiliate moneymaking or the ever present threat of infection files.&lt;br /&gt;&lt;br /&gt;It may well be worth waiting to see if the adverts are pulled due to the negative reaction before deciding to download File X from Site Y while crossing your fingers.&lt;br /&gt;&lt;br /&gt;And Han shot first.&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4740094125703417194?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4740094125703417194/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4740094125703417194&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4740094125703417194'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4740094125703417194'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/lucas-ex-machina-i-never-asked-for-this.html' title='Lucas Ex Machina: I never asked for this'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/4FRWYRqaGFE/default.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-7521341495835681673</id><published>2011-09-16T04:23:00.001-04:00</published><updated>2011-09-16T04:46:26.125-04:00</updated><title type='text'>Bing, Yahoo! Search adverts serve up malware</title><content type='html'>Overnight we saw a number of adverts being displayed in Bing that were directing end-users to malicious content. These adverts were promoting all manner of downloads including Firefox, Skype and uTorrent.&lt;br /&gt;&lt;br /&gt;Some of the search terms used:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;"FireFox Download"&lt;br /&gt;"Download Skype"&lt;br /&gt;"Download Adobe Player"&lt;br /&gt;&lt;br /&gt;As you can see, they're not particularly complicated or unusual searches so you probably wouldn't be jumping through hoops to reach these things.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-vGHLit_HWwA/TnL7R2Wkt1I/AAAAAAAABgo/kA78XdwrvFs/s1600/ronguebingadsmt1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-vGHLit_HWwA/TnL7R2Wkt1I/AAAAAAAABgo/kA78XdwrvFs/s320/ronguebingadsmt1.gif" width="297" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-WL-s30cOoMc/TnL7SgJSq0I/AAAAAAAABgs/mgQqi52ZYLQ/s1600/ronguebingadsmt2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="194" src="http://4.bp.blogspot.com/-WL-s30cOoMc/TnL7SgJSq0I/AAAAAAAABgs/mgQqi52ZYLQ/s320/ronguebingadsmt2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-C0NKyrDlLiE/TnL7TEOQXBI/AAAAAAAABgw/R377m6Y6Tok/s1600/ronguebingadsmt3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="137" src="http://1.bp.blogspot.com/-C0NKyrDlLiE/TnL7TEOQXBI/AAAAAAAABgw/R377m6Y6Tok/s320/ronguebingadsmt3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Clicking the adverts takes end-users to sites such as river-park(dot)net, and they do a pretty good job of convincing visitors that these sites are the real deal (incidentally, you'll notice that some of the ads display the "real" URL of the program mentioned, but take you to a rogue site such as the "Download uTorrent Free" advert above which actually takes you to&amp;nbsp;aciclistaciempozuelos(dot)es/torrent).&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-m4NvsjzaUsw/TnL91ernnJI/AAAAAAAABg0/NY8PXDWb-8M/s1600/ronguebingadsmt4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="202" src="http://4.bp.blogspot.com/-m4NvsjzaUsw/TnL91ernnJI/AAAAAAAABg0/NY8PXDWb-8M/s320/ronguebingadsmt4.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-g6SwMBM6Ng0/TnL92qOErCI/AAAAAAAABg4/WhPZrg71h1g/s1600/ronguebingadsmt5.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="244" src="http://3.bp.blogspot.com/-g6SwMBM6Ng0/TnL92qOErCI/AAAAAAAABg4/WhPZrg71h1g/s320/ronguebingadsmt5.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;All of the malicious downloads are coming from&amp;nbsp;en-softonic(dot)net, and here's their open directory with various files waiting to be launched on unsuspecting end-users:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Q9j0F2xdUmo/TnMAagehreI/AAAAAAAABg8/bgPZwHVbmas/s1600/ronguebingadsmt6.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="204" src="http://1.bp.blogspot.com/-Q9j0F2xdUmo/TnMAagehreI/AAAAAAAABg8/bgPZwHVbmas/s320/ronguebingadsmt6.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;As an example, the fake Firefox file installs a rootkit, runs IE silently in the background attempting clickfraud and also performs Google redirects. Current VirusTotal score for that one is &lt;a href="http://www.virustotal.com/file-scan/report.html?id=d20c12348e014b782234cbff8d282cd9d566c86e6b2cda2cebee44aca43cf7aa-1316154205"&gt;16/44&lt;/a&gt;, and we detect it as Win32.Malware!Drop. These adverts were also appearing in Yahoo search - we notified both Yahoo and Microsoft, and both companies are in the process of killing these things off.&lt;br /&gt;&lt;br /&gt;It's entirely possible these sites will show up somewhere else, so be careful when downloading programs and make sure you're on the official site before grabbing anything. These are definitely not the kind of files you want on your system.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks to Matthew for finding this one).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-7521341495835681673?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/7521341495835681673/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=7521341495835681673&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7521341495835681673'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7521341495835681673'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/bing-yahoo-search-adverts-serve-up.html' title='Bing, Yahoo! Search adverts serve up malware'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-vGHLit_HWwA/TnL7R2Wkt1I/AAAAAAAABgo/kA78XdwrvFs/s72-c/ronguebingadsmt1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-8007403496056253154</id><published>2011-09-15T11:28:00.003-04:00</published><updated>2011-09-15T11:35:24.747-04:00</updated><title type='text'>DeepSafe</title><content type='html'>I keep getting asked for comments on McAfee/Intel’s new Deepsafe. So what the heck, here goes. &lt;br /&gt;&lt;br /&gt;This is a great marketing pitch.&amp;nbsp; But remember that the platform that the technology is based upon, Intel VTx, is an open archictecture that any antivirus company can use.&amp;nbsp;&amp;nbsp;McAfee is innovating but I truly doubt it’s because of any proprietary relationship with Intel.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;I just don’t think there is any secret sauce here.&amp;nbsp; This stuff is available to us all, and if it makes sense to use it, we will. &lt;br /&gt;&lt;br /&gt;Alex Eckelberry&lt;br /&gt;&lt;a href="http://www.sunbeltsoftware.com/alex/gblog/doingstuff.png"&gt;&lt;img alt="Doingstuff" border="0" src="http://www.sunbeltsoftware.com/alex/gblog/doingstuff_thumb.jpg" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-8007403496056253154?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/8007403496056253154/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=8007403496056253154&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8007403496056253154'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8007403496056253154'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/deepsafe.html' title='DeepSafe'/><author><name>Alex Eckelberry</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4577451518913300521</id><published>2011-09-15T05:00:00.000-04:00</published><updated>2011-09-15T11:11:28.015-04:00</updated><title type='text'>Touchpad? Touchbad.</title><content type='html'>Hands up: who wants a cheap HP Touchpad complete with charging dock and bluetooth keyboard?&lt;br /&gt;&lt;br /&gt;Yep, you all do. However, not only does this prospect look a little unlikely due to the ultra scarce stock, you may well find you end up with a little more than you bargained for while searching for one of the few remaining deals knocking around the web.&lt;br /&gt;&lt;br /&gt;Should you visit the rather long web address listed below (which may or may not completely ruin my formatting, cross your fingers), you'll be enticed by the rather awesome offer that includes all of the above for the low, low price of $159.99.&lt;br /&gt;&lt;br /&gt;tigger(dot)horizon-host(dot)com/123/td/applications/SearchTools/touchpad(dot)html&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-We1DnWMTXgk/TnHQWk7NK4I/AAAAAAAABgg/k6yytuYOYKk/s1600/hptpadsurvey1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="224" src="http://4.bp.blogspot.com/-We1DnWMTXgk/TnHQWk7NK4I/AAAAAAAABgg/k6yytuYOYKk/s320/hptpadsurvey1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;It &lt;i&gt;sounds&lt;/i&gt; like a great deal. However,&amp;nbsp;hit the "Buy" button and&amp;nbsp;this website - which was pulling genuine content from a Tiger Direct page - would use some handy Javascript to load up a Survey box populated with data from fileice(dot)net.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-yEp3zf7qw_4/TnHRFTzbhgI/AAAAAAAABgk/tGB1m8bCkaQ/s1600/tpdsurv2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="220" src="http://3.bp.blogspot.com/-yEp3zf7qw_4/TnHRFTzbhgI/AAAAAAAABgk/tGB1m8bCkaQ/s320/tpdsurv2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;I must admit, seeing a survey in this instance is somewhat bizarre as typical survey scams involve the affiliate offering &lt;i&gt;freebies&lt;/i&gt; in return for a completed survey. I guess they're banking on the lure of the cheap touchpad being too much for end-users to resist. An example offer:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-6gRcRlsW3qw/TnG3A6amaxI/AAAAAAAABgc/FL9vO7u7D9E/s1600/hptpad3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="238" src="http://2.bp.blogspot.com/-6gRcRlsW3qw/TnG3A6amaxI/AAAAAAAABgc/FL9vO7u7D9E/s400/hptpad3.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Yeah, that's super. Anyway, at time of writing the site in question appears to be down but I'd imagine others could well be attempting similar scams as stocks dwindle to nothing (assuming that hasn't already happened).&lt;br /&gt;&lt;br /&gt;Time to go back to saving up for an iPad...&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks to Robert Stetson, and a hat-tip to &lt;a href="http://www.stopbadware.org/"&gt;Stopbadware&lt;/a&gt;).&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4577451518913300521?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4577451518913300521/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4577451518913300521&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4577451518913300521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4577451518913300521'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/touchpad-touchbad.html' title='Touchpad? Touchbad.'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-We1DnWMTXgk/TnHQWk7NK4I/AAAAAAAABgg/k6yytuYOYKk/s72-c/hptpadsurvey1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-7951997287413351131</id><published>2011-09-14T02:24:00.000-04:00</published><updated>2011-09-14T02:27:19.629-04:00</updated><title type='text'>Gaming website offers up "FileZilla" and...Jeefo</title><content type='html'>Just a quick heads up that a gaming website is offering up what appears to be a version of FileZilla, but is actually throwing the &lt;a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?name=Virus%3AWin32%2FJeefo.A"&gt;Jeefo Virus&lt;/a&gt; into the mix.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-GaQEuFuB0bk/TnAooWGVfgI/AAAAAAAABgQ/zH3WuOytD-M/s1600/cssitefilezilla1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="152" src="http://2.bp.blogspot.com/-GaQEuFuB0bk/TnAooWGVfgI/AAAAAAAABgQ/zH3WuOytD-M/s400/cssitefilezilla1.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;The site in question is someofcs(dot)com, and (as far as we can tell) it looks as though you may have to be a member of the site to download the file in question. The VirusTotal result right now is sitting at &lt;a href="http://www.virustotal.com/file-scan/report.html?id=937b99f36210a302fca5ea6d0686512120796a98bd9345d45104c4f8b93583da-1315916618"&gt;38/44&lt;/a&gt;, so at least there's decent coverage of this one.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks to Patrick Jordan for sending this over).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-7951997287413351131?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/7951997287413351131/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=7951997287413351131&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7951997287413351131'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7951997287413351131'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/gaming-website-offers-up-filezilla.html' title='Gaming website offers up &quot;FileZilla&quot; and...Jeefo'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-GaQEuFuB0bk/TnAooWGVfgI/AAAAAAAABgQ/zH3WuOytD-M/s72-c/cssitefilezilla1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-5454750700436036655</id><published>2011-09-13T12:01:00.000-04:00</published><updated>2011-09-13T12:27:43.038-04:00</updated><title type='text'>Rootcon 5: A Summary</title><content type='html'>&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-I_FGS3Q8BwY/Tm8WdEq02YI/AAAAAAAABgM/PLBts2YlHpM/s1600/rootconday1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="226" src="http://1.bp.blogspot.com/-I_FGS3Q8BwY/Tm8WdEq02YI/AAAAAAAABgM/PLBts2YlHpM/s400/rootconday1.gif" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;I'm not saying &lt;i&gt;all&lt;/i&gt; of my trips go horribly wrong, but&amp;nbsp;&lt;a href="http://paperghost.tumblr.com/post/7199265581/epic4chan-what-you-always-feared-this"&gt;exploding toilets&lt;/a&gt;,&amp;nbsp;&lt;a href="http://www.flickr.com/photos/paperghost/777091928/in/set-72157600761788702"&gt;1984 style televisions&lt;/a&gt;,&amp;nbsp;&lt;a href="http://www.flickr.com/photos/paperghost/3490862633/in/set-72157617559632836"&gt;badges that make no sense&lt;/a&gt;,&amp;nbsp;&lt;a href="http://www.flickr.com/photos/paperghost/815693553/in/set-72157600831622205"&gt;surprises in alleyways&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="http://www.flickr.com/photos/paperghost/2412996262/in/set-72157604526785192"&gt;emergency fuel dumps&lt;/a&gt;&amp;nbsp;could perhaps convince you otherwise. You'll be pleased to know &lt;a href="http://sunbeltblog.blogspot.com/2011/09/rootcon-5-greetings-from-cebu.html"&gt;Rootcon 5&lt;/a&gt; went off without a hitch (well, besides the &lt;a href="http://paperghost.posterous.com/my-first-earthquake-drill"&gt;earthquake drill&lt;/a&gt;,&amp;nbsp;the &lt;a href="http://paperghost.posterous.com/eleven-hours-of-fun-in-guangzhou-airport"&gt;eleven hours at Guangzhou airport&lt;/a&gt; and the lady with the foot in her face) and a great time was had by all.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Step up, Cebu Parklane International Hotel. Before:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6138941099/" title="Setting the Scene by Paperghost, on Flickr"&gt;&lt;img alt="DSCF0653" height="375" src="http://farm7.static.flickr.com/6151/6138941099_d340888052.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;After (well, during):&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6139706960/" title="Full House by Paperghost, on Flickr"&gt;&lt;img alt="" height="375" src="http://farm7.static.flickr.com/6074/6139706960_bcff04f4d8.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I think something in the region of 200(ish) people turned up to listen to talks on a wide variety of subjects. Ye Olde Cyberterror kept popping up throughout the event, as it's clearly a bit of a hot topic although there were plenty of other things to get your teeth into if you never wanted to hear the word "cyber" attached to anything ever again.&lt;br /&gt;&lt;br /&gt;For the duration of the event, there were fairly spectacular gaming rigs available for people to hop on:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6143292322/" title="Batman, everybody. by Paperghost, on Flickr"&gt;&lt;img alt="Batman, everybody." height="375" src="http://farm7.static.flickr.com/6189/6143292322_c9c79fe379.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6143293016/" title="Those are some big fans by Paperghost, on Flickr"&gt;&lt;img alt="Those are some big fans" height="375" src="http://farm7.static.flickr.com/6183/6143293016_a5934f2d0f.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;When the PC above is turned on it seems to glow brighter than the Sun:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6139710104/" title="White heat by Paperghost, on Flickr"&gt;&lt;img alt="White heat" height="375" src="http://farm7.static.flickr.com/6078/6139710104_91bc6f2c7a.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Of course, this being a hacker con there were various wargames / capture the flag type events taking place too. While it's entirely possible I captured someone below simply wiping their face, I like to imagine the pwnage before her is so amazing that she is straight up shrieking into a napkin.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6139712858/" title="Pwn him! Pwn him good! by Paperghost, on Flickr"&gt;&lt;img alt="Pwn him! Pwn him good!" height="375" src="http://farm7.static.flickr.com/6082/6139712858_2013af4a81.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6139162449/" title="Skills to pay the bills by Paperghost, on Flickr"&gt;&lt;img alt="Skills to pay the bills" height="375" src="http://farm7.static.flickr.com/6086/6139162449_f790e710e4.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Probably not though.&lt;br /&gt;&lt;br /&gt;Anyway, there was also an obligatory tshirt booth and everybody had a badge complete with a QC code or two to crack.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6138942419/" title="Shirts galore by Paperghost, on Flickr"&gt;&lt;img alt="Shirts galore" height="375" src="http://farm7.static.flickr.com/6069/6138942419_129298256a.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6138927133/" title="Badges by Paperghost, on Flickr"&gt;&lt;img alt="Badges" height="500" src="http://farm7.static.flickr.com/6196/6138927133_dd120d0e49.jpg" width="375" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So there we go. As for the talks, they came thick and fast over the two day event. No prizes for guessing that I talked about videogame / PC game hacking and threats, but in addition to that there was a great ZEUS talk by Trend Micro:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6139704962/" title="Zeus toolkit by Paperghost, on Flickr"&gt;&lt;img alt="Zeus toolkit" height="375" src="http://farm7.static.flickr.com/6165/6139704962_4cf23495f8.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Another presentation given by a chap well known for being involved in the legal side of things discussed the topic of whether the Philippines was ready for "cyber terrorism". I must admit, I was curious when I heard that "Cyberterrorism" was a "&lt;a href="https://twitter.com/#!/likke/status/112071490505146368"&gt;convergence of cybernetics and terrorism&lt;/a&gt;". I always thought that was something to do with scary robots, but feel free to plough through &lt;a href="http://en.wikipedia.org/wiki/Cybernetics"&gt;this lot&lt;/a&gt; and make sense of it for me.&lt;br /&gt;&lt;br /&gt;There was also a fairly exciting kerfuffle between him and researchers from a company who gave a talk prior to this then found themselves referenced incorrectly in his own. I missed most of it, but below is some of the drama captured for posterity:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6139719666/" title="Actually... by Paperghost, on Flickr"&gt;&lt;img alt="Actually..." height="375" src="http://farm7.static.flickr.com/6089/6139719666_d05d09342f.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Yeah, that was pretty awesome.&lt;br /&gt;&lt;br /&gt;Something else that was awesome was the TDL 4 talk by my colleague Berman Enconado, which explored the history of TDL 4, what it does and the damage it can cause.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6142751643/" title="TDL4 by Paperghost, on Flickr"&gt;&lt;img alt="TDL4" height="375" src="http://farm7.static.flickr.com/6152/6142751643_e89a151baf.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Now it's time to break for cakes because, well, look at them.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6143300830/" title="Earth to Elvis by Paperghost, on Flickr"&gt;&lt;img alt="Earth to Elvis" height="375" src="http://farm7.static.flickr.com/6161/6143300830_8359d46ac0.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hacker cons tend to have some sort of lockpicking shenanigans taking place in the form of a village, but Rootcon had a one man lockpick village in the form of Jolly Mongrel who went through the various types of lock you could pick, examined a famous bank heist from yesteryear that involved lockpicking galore and also had some fun with handcuffs:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6143298490/" title="Handcuff fun by Paperghost, on Flickr"&gt;&lt;img alt="Handcuff fun" height="500" src="http://farm7.static.flickr.com/6191/6143298490_97e242cfc8.jpg" width="375" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6143064009/" title="I love Batman. Almost. by Paperghost, on Flickr"&gt;&lt;img alt="I love Batman. Almost." height="375" src="http://farm7.static.flickr.com/6087/6143064009_5ed27f917d.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I also thought his tshirt said "I love Batman", which would have been amazing.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6143340474/" title="Fishbowl of doom by Paperghost, on Flickr"&gt;&lt;img alt="Fishbowl of doom" height="375" src="http://farm7.static.flickr.com/6194/6143340474_e9526e6321.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A quick prize draw at the GFI booth later (with a handily swiped fishbowl which I'm sure the fish didn't miss) and it was time for the panel talk including speakers from IBM, Trend Micro, GFI Software, that legal guy and a chap called Sven Herpig who is as awesome as his name suggests. It was about - you've guessed it - cyberterror, along with a bunch of random security questions including ethical vulnerability reporting, Wikileaks and, er, setting up an overseas anonymous security company that quickly wandered into a discussion about tax evasion.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6143570668/" title="Cyberterror panel by Paperghost, on Flickr"&gt;&lt;img alt="Cyberterror panel" height="375" src="http://farm7.static.flickr.com/6156/6143570668_b05dfee242.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Also someone said something pretty funny here, but I have no idea what it was.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/paperghost/6142993509/" title="Someone brought the lulz by Paperghost, on Flickr"&gt;&lt;img alt="Someone brought the lulz" height="375" src="http://farm7.static.flickr.com/6087/6142993509_68fe0aa56f.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;All in all, this was an excellent event - especially as this was the first "official" security conference in the Philippines (despite there being four Rootcons prior to this, which were much smaller in scale). This had numerous speakers (both local and international), talks on a wide range of subjects, PC gaming, hacking events and booths stuffed with products and freebies.&lt;br /&gt;&lt;br /&gt;Plans are already underway for Rootcon 6, so it would probably be wise to pencil in a visit to Cebu sometime next year. Thanks to everyone who organised the event and thanks also to everyone who visited the booth / listened to the talks, we had a great time!&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-5454750700436036655?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/5454750700436036655/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=5454750700436036655&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5454750700436036655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5454750700436036655'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/rootcon-5-summary.html' title='Rootcon 5: A Summary'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-I_FGS3Q8BwY/Tm8WdEq02YI/AAAAAAAABgM/PLBts2YlHpM/s72-c/rootconday1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-3087527817753643971</id><published>2011-09-12T11:19:00.002-04:00</published><updated>2011-09-13T13:13:34.276-04:00</updated><title type='text'>Hijacked sites serve up exploits, SEO poisoning</title><content type='html'>Our research team have discovered a rather nasty SEO poisoning scam over the last few days, targeting 9/11 related search terms (along with anything else they can get their hands on) to attempt the infection of vulnerable PCs. They use a combination of the &lt;strike&gt;&lt;a href="http://community.websense.com/blogs/securitylabs/pages/black-hole-exploit-kit.aspx"&gt;Black Hole Exploit Kit&lt;/a&gt;&lt;/strike&gt; (Correction: &lt;b&gt;&lt;a href="http://www.m86security.com/labs/traceitem.asp?article=1427"&gt;Phoenix Exploit Kit&lt;/a&gt;&lt;/b&gt;) and an interesting "on the fly" SEO poisoning tactic to try and drop infections onto the target PC.&lt;br /&gt;&lt;br /&gt;Shangpalace(dot)com(dot)vn was the initial URL our research team discovered, although there are quite a few others out there right now. It goes without saying that all of these domains should be considered hostile and visited only in a dedicated testing machine.&lt;br /&gt;&lt;br /&gt;authorizationlettersample(dot)org&lt;br /&gt;chiefpricingofficer(dot)com&lt;br /&gt;craftyk9(dot)com&lt;br /&gt;decaci(dot)mmister(dot)com&lt;br /&gt;e-gizmo(dot)com&lt;br /&gt;geekvenues(dot)com&lt;br /&gt;glorioleedu(dot)com&lt;br /&gt;gospeloftruth(dot)net&lt;br /&gt;hotelcatedralvallarta(dot)com&lt;br /&gt;jetpackdreamsthebook(dot)com&lt;br /&gt;maresmortgage(dot)com&lt;br /&gt;marianaemslie(dot)com&lt;br /&gt;megadeth(dot)megawan(dot)com(dot)ar&lt;br /&gt;moorethoughts(dot)com&lt;br /&gt;plusidol(dot)com&lt;br /&gt;rayoverde(dot)com(dot)ar&lt;br /&gt;referencelettersample(dot)org&lt;br /&gt;ritasresources(dot)com&lt;br /&gt;saponifier(dot)com&lt;br /&gt;saprivateschools(dot)co(dot)za&lt;br /&gt;schorrsolutions(dot)com&lt;br /&gt;secondmilecenter(dot)com|&lt;br /&gt;sellbeads(dot)com&lt;br /&gt;studio-r(dot)in&lt;br /&gt;tisztaszenzor(dot)hu&lt;br /&gt;trainerskills(dot)com&lt;br /&gt;winbeforetrial(dot)com&lt;br /&gt;bridging-the-gap(dot)com&lt;br /&gt;ishmaelkhaldi(dot)com&lt;br /&gt;joshtickell(dot)com&lt;br /&gt;sofresh(dot)ro&lt;br /&gt;themetalden(dot)com&lt;br /&gt;&lt;br /&gt;Some example search terms:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-wLnzS-Q9WZY/Tm4oEIg2SlI/AAAAAAAABf4/XGZP9Two8Ms/s1600/9expseokit1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="152" src="http://4.bp.blogspot.com/-wLnzS-Q9WZY/Tm4oEIg2SlI/AAAAAAAABf4/XGZP9Two8Ms/s320/9expseokit1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt; Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-OGRaCkspSUc/Tm4oEuzDNDI/AAAAAAAABf8/ESFDII_mc-U/s1600/9expseokit2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="57" src="http://3.bp.blogspot.com/-OGRaCkspSUc/Tm4oEuzDNDI/AAAAAAAABf8/ESFDII_mc-U/s320/9expseokit2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt; Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;div style="text-align: left;"&gt;If you're unfortunate enough to visit one of these rogue links, then you can look forward to attacks on your PC. Here's what GFI Software Malware Research Supervisor Adam Thomas had to say about it:&lt;br /&gt;&lt;br /&gt;"The server will return a script pointing to a malicious server which is running Phoenix exploit kit...the referral string used when visiting the compromised site must be an approved referral string (e.g. search.google.com). If not, the server will simply re-direct you to anon-malicious page."&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-ALi5ysJG31A/Tm4ok4eOJBI/AAAAAAAABgI/CaChRLyJOHs/s1600/9expseokit4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="60" src="http://1.bp.blogspot.com/-ALi5ysJG31A/Tm4ok4eOJBI/AAAAAAAABgI/CaChRLyJOHs/s320/9expseokit4.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;  &lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;He continues: "The malicious domain ‘nvwjefrzacronyms(dot)info’ appears to be hosted on a server in Germany. Passive DNS data reveals several other likely malicious servers hosted at the same IP address."&lt;br /&gt;&lt;br /&gt;serveruzgdf(dot)info A 109.230.217.113&lt;br /&gt;acronymsoflh(dot)info A 109.230.217.113&lt;br /&gt;zqqhfowhserver(dot)info  A 109.230.217.113&lt;br /&gt;cronymsu(dot)info A 109.230.217.113&lt;br /&gt;aasfhcxserver(dot)info  A 109.230.217.113&lt;br /&gt;bpxtecdacronyms(dot)info  A 109.230.217.113&lt;br /&gt;nvwjefrzacronyms(dot)info  A 109.230.217.113&lt;br /&gt;acronymstxey(dot)info  A 109.230.217.113&lt;br /&gt;&lt;br /&gt;Adam tells me the site is "attempting to load as many exploits as possible in order to drop the payload". This is typically what the user will see while the exploits and files are busy behind the scenes:&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt; &lt;a href="http://3.bp.blogspot.com/-AQfjHClTNR0/Tm4oFEKyBnI/AAAAAAAABgA/NoQexQYOdv0/s1600/9expseokit3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="162" src="http://3.bp.blogspot.com/-AQfjHClTNR0/Tm4oFEKyBnI/AAAAAAAABgA/NoQexQYOdv0/s320/9expseokit3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Here's an example &lt;a href="http://www.virustotal.com/file-scan/report.html?id=25520cb4f0f6a0e6bab5b8970ff4f846729f8aac66271b348e695950ee5b4a7b-1315527862"&gt;VirusTotallink&lt;/a&gt; to one of the pieces of Malware being used - as you can see, 21/44 currently detect it. As with most attacks of this nature, you can expect to see multiple domains, files and search terms used to lure potential victims. Speaking of search terms, the people behind this are doing some interesting things with their poisoned search results. Adam again:&lt;br /&gt;&lt;br /&gt;"The content for SEO poisioning can be generated 'on-the-fly'. To explain further, the owner of this SEO poisoning system can utilize their network of hacked domains to quickly generate any content desired. By simply passing a search criteria to the url 'shangpalace(dot)com(dot)vn/&amp;lt;search-term&amp;gt;', the 'SEO pack' generates relevant content based on the search term."&lt;br /&gt;&lt;br /&gt;As an example, he passed a random search term to the server to see what would happen - "purple-golden-retriever", in thiscase. Sure enough..."Within 2-3 seconds a page complete with keywords, related search phrases and even relevant working images is returned from theserver."&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt; &lt;a href="http://1.bp.blogspot.com/-sK67Ypmh9pQ/Tm4oFwhjiHI/AAAAAAAABgE/7GYhHvmXP8Y/s1600/9expseokit5.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="151" src="http://1.bp.blogspot.com/-sK67Ypmh9pQ/Tm4oFwhjiHI/AAAAAAAABgE/7GYhHvmXP8Y/s320/9expseokit5.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Pretty slick. Keeping your system patched and your security software up to date is a good place to start with regards to avoiding these kinds of attacks, in addition to running a Limited User Account and (perhaps) some browser based script blocking tools such as NoScript. There’s bound to be more domains out there playing host to the kind of badness seen above, and I’m pretty sure you don’t want to be caught out by this one.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Christopher Boyd (Thanks Adam)&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-3087527817753643971?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/3087527817753643971/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=3087527817753643971&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3087527817753643971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3087527817753643971'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/hijacked-sites-serve-up-exploits-seo.html' title='Hijacked sites serve up exploits, SEO poisoning'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-wLnzS-Q9WZY/Tm4oEIg2SlI/AAAAAAAABf4/XGZP9Two8Ms/s72-c/9expseokit1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-6936176163263067083</id><published>2011-09-07T10:52:00.002-04:00</published><updated>2011-09-07T10:52:47.782-04:00</updated><title type='text'>Generating false hope with fake generators</title><content type='html'>Another day, another random website offering up freebies that you'd be better off without. This time around, the site in question is located at freeamazingsoftwares(dot)blogspot(dot)com. The free programs include - stop me if you've heard this one - RuneScape gold generators, iTunes giftcard generators, Amazon Giftcard generators and XBox Live points generators.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-bqw6tPjFqFE/Tmd9EmF2VeI/AAAAAAAABfM/UKx4fkUdOB4/s1600/hcblgam1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="206" src="http://4.bp.blogspot.com/-bqw6tPjFqFE/Tmd9EmF2VeI/AAAAAAAABfM/UKx4fkUdOB4/s320/hcblgam1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Q4NMGfDMvKk/Tmd9FhxcP-I/AAAAAAAABfQ/-5I342z9Fmo/s1600/hcblgam2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="259" src="http://2.bp.blogspot.com/-Q4NMGfDMvKk/Tmd9FhxcP-I/AAAAAAAABfQ/-5I342z9Fmo/s320/hcblgam2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-ehu606cik2M/Tmd9GbCG1_I/AAAAAAAABfU/iZAsfEePok4/s1600/hcblgam3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="177" src="http://3.bp.blogspot.com/-ehu606cik2M/Tmd9GbCG1_I/AAAAAAAABfU/iZAsfEePok4/s320/hcblgam3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Of course, it doesn't matter which program you want to download - your final destination will be this:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-jU96V1DDH1c/TmeCNrfVA7I/AAAAAAAABfY/ZCMWXPAG8TU/s1600/hcblgam4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="154" src="http://4.bp.blogspot.com/-jU96V1DDH1c/TmeCNrfVA7I/AAAAAAAABfY/ZCMWXPAG8TU/s320/hcblgam4.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;"Are you dumb? Find out now!" Never a truer word spoken, courtesy of ye olde survey popup. Assuming the user fills in one of the above quizzes / signs up to a ringtone service, they'll be free to download one of the above programs.&lt;br /&gt;&lt;br /&gt;Will they work as advertised? Given that I've yet to see a working Microsoft points generator - and I've seen a &lt;i&gt;lot&lt;/i&gt; of points generators - my answer would be "nope". Could you take that "nope" and apply it to all the other programs too?&lt;br /&gt;&lt;br /&gt;"Yep". As with so many of these types of website, at best you'll get a non functional dummy download. At worst, you could end up with anything from a phishing tool to a piece of data theft malware. Worth the risk? I think we're back to "nope" again...&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-6936176163263067083?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/6936176163263067083/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=6936176163263067083&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6936176163263067083'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/6936176163263067083'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/generating-false-hope-with-fake.html' title='Generating false hope with fake generators'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-bqw6tPjFqFE/Tmd9EmF2VeI/AAAAAAAABfM/UKx4fkUdOB4/s72-c/hcblgam1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-5057832271299636740</id><published>2011-09-07T07:18:00.000-04:00</published><updated>2011-09-07T07:18:21.046-04:00</updated><title type='text'>Rootcon 5: Greetings from Cebu!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-e6v9qIIh8nQ/TmdLjsTRMqI/AAAAAAAABfE/-HUFDzbR364/s1600/cebu1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-e6v9qIIh8nQ/TmdLjsTRMqI/AAAAAAAABfE/-HUFDzbR364/s320/cebu1.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;This year, &lt;a href="http://en.wikipedia.org/wiki/Cebu_(island)"&gt;Cebu Island&lt;/a&gt; is playing host to the fifth &lt;a href="http://www.rootcon.org/xml/rootcon5/tracks"&gt;Rootcon security conference&lt;/a&gt;, which takes place on the 9th and 10th of September. GFI Software has two standalone talks at this one - "Introducing TDL4, a Sophisticated Fraudster’s Rootkit" by Berman Enconado and "Console (In)Security: The Oncoming Storm" by my good self. Additionally, we're on a panel discussing the threat of "Cyberterrorism" alongside Paul Sabanal (IBM Security Systems) and a chap named Sven Herpig who is both a professor and a PhD student specialising in Cyberwarfare.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-5xOrDyyQQAw/TmdO2MHAyEI/AAAAAAAABfI/o7HTOUWjkcg/s1600/cebu2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="245" src="http://1.bp.blogspot.com/-5xOrDyyQQAw/TmdO2MHAyEI/AAAAAAAABfI/o7HTOUWjkcg/s320/cebu2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;There's a whole bunch of other talks taking place too, on everything from VoIP security and IPv6 to lockpicking, penetration testing and reversing Android applications. If the talks aren't your thing, the event also doubles as a job fair and we will be on the lookout for both fresh and experienced talent.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;If you'd like to listen to me complain endlessly about everything that's gone wrong since I arrived - and who wouldn't - you can do so &lt;a href="http://paperghost.posterous.com/tag/manila"&gt;here&lt;/a&gt; on my personal blog thing. Otherwise, we'll be posting various updates from now until the weekend so roll on Rootcon!&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-5057832271299636740?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/5057832271299636740/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=5057832271299636740&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5057832271299636740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5057832271299636740'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/rootcon-5-greetings-from-cebu.html' title='Rootcon 5: Greetings from Cebu!'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-e6v9qIIh8nQ/TmdLjsTRMqI/AAAAAAAABfE/-HUFDzbR364/s72-c/cebu1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-5934356913483082102</id><published>2011-09-01T02:55:00.001-04:00</published><updated>2011-09-01T03:04:15.144-04:00</updated><title type='text'>Facebook Profile Rollback Phish</title><content type='html'>Here's a phishing scam that lures users with the promise of getting their "old Facebook profile" back. What that means is up for debate - maybe the scammer is harking back to a land of slightly less privacy options, or maybe he just wants you to look like a Geocities page from 1996. Either way, here it is:&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-nuy7G97u-Hc/Tl8bPDr1ANI/AAAAAAAABeY/mdNiHQVLclY/s1600/bringfboldprobck1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="284" src="http://4.bp.blogspot.com/-nuy7G97u-Hc/Tl8bPDr1ANI/AAAAAAAABeY/mdNiHQVLclY/s320/bringfboldprobck1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You too can convert your new Facebook profile into an old one for the low, low cost of your login details.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here is the "Need Old Profile Back" Facebook page:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-ErpMv1YwYLA/Tl8i2Hz2F3I/AAAAAAAABec/wvijjTkrMcE/s1600/bringfboldprobck2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="247" src="http://3.bp.blogspot.com/-ErpMv1YwYLA/Tl8i2Hz2F3I/AAAAAAAABec/wvijjTkrMcE/s320/bringfboldprobck2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;As you can see, it's a fairly typical "Click this...then that...then all of those" page, begging for Likes, Suggests and Invitations from other Facebook users. You don't &lt;i&gt;have&lt;/i&gt; to do this to see the "Profile Converter", but lots of users will jump through the hoops anyway. Here comes the phish itself, in the form of a Google Docs Spreadsheet:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-jnJC62fJNXI/Tl8oUfml8UI/AAAAAAAABeg/zOLNhBEhzbo/s1600/bringfboldprobck3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-jnJC62fJNXI/Tl8oUfml8UI/AAAAAAAABeg/zOLNhBEhzbo/s320/bringfboldprobck3.gif" width="289" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;They claim entering your Facebook login along with your name will mean your profile is converted to "an older version" in 46 hours. Why 46? Why not 48? That's the kind of thing you could distract yourself with for at least, oh, thirty seconds before going back to complaining about things on the Internet.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It's all academic anyway at this point, because those nice people at Google killed it shortly after we reported it to them. Sorry guys, but the changes Facebook have made aren't going away anytime soon so you'd &lt;a href="http://sunbeltblog.blogspot.com/2011/08/facebook-makes-move-toward-security.html"&gt;better get used to it&lt;/a&gt; and steer clear of scams like this one (a scam which, basic as it was, still picked up &lt;a href="https://bitly.com/dHxL3q+"&gt;just over 2,000 clicks from January&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;Hopefully only a small portion of those 2,000 fell for it, but you know how appealing those spinning Geocities gifs can be...&lt;/div&gt;&lt;div&gt;Christopher Boyd&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-5934356913483082102?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/5934356913483082102/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=5934356913483082102&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5934356913483082102'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5934356913483082102'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/09/facebook-profile-rollback-phish.html' title='Facebook Profile Rollback Phish'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-nuy7G97u-Hc/Tl8bPDr1ANI/AAAAAAAABeY/mdNiHQVLclY/s72-c/bringfboldprobck1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-7343523081689519448</id><published>2011-08-30T01:42:00.000-04:00</published><updated>2011-08-30T01:45:54.468-04:00</updated><title type='text'>Northumbria Police Authority website defaced, serving Phish for breakfast</title><content type='html'>It seems the Northumbria Police Authority website (northumbriapoliceauthority(dot)org(dot)uk) was compromised recently to push a "fight the power" message, and it looks like the defacement is the &lt;i&gt;least&lt;/i&gt; of their worries as you'll see shortly.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;What is the Northumbria Police Authority?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;We &lt;i&gt;could&lt;/i&gt; use my wonderful description ("An Authority for the Northumbria Police"), but I think an &lt;a href="http://www.northumbria.police.uk/about_us/organisation/polauth/"&gt;official source&lt;/a&gt; would likely be more informative. According to that handy link they appoint chief constables, make sure the Police are doing their job and listen to locals complaining which is &lt;i&gt;definitely&lt;/i&gt; something I can get behind.&lt;br /&gt;&lt;br /&gt;Unfortunately, this is how the Northumbria Police Authority were rolling earlier today in Google Search:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-cyjQC-bO6UE/Tlxu4q8BngI/AAAAAAAABeM/TmkeVUnPuNI/s1600/nrthumbplcaut1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="126" src="http://1.bp.blogspot.com/-cyjQC-bO6UE/Tlxu4q8BngI/AAAAAAAABeM/TmkeVUnPuNI/s400/nrthumbplcaut1.gif" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;i&gt;"The Northumbria Police Authority website was hacked by&amp;nbsp;lamine Foued ( Dr.F0u3D). F*ck You admin. Freedom For T.H.T Anonymous Tunisia :D."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;This isn't quite a 187 on an undercover cop - in fact, it's nothing like that - but they've still done a number on the website. At time of writing, the hack has been removed though you can still see it basking in, er, glory through the wonders of Google Cache:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-SOYfafJwB-g/Tlxu5laYhnI/AAAAAAAABeQ/QIgzLL6hvEw/s1600/nrthumbplcaut2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-SOYfafJwB-g/Tlxu5laYhnI/AAAAAAAABeQ/QIgzLL6hvEw/s1600/nrthumbplcaut2.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;Well, the defacement may have been cleaned up, but the Northumbria Police Authority have another problem at the scene of the crime. And by "problem", I mean "Paypal phish making a gang sign from the comfort of the Northumbria Police Authority website".&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-FZLDsHHa77s/Tlx1Oz6MyuI/AAAAAAAABeU/k1J8THK4NEA/s1600/nrthumbplcaut3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="256" src="http://1.bp.blogspot.com/-FZLDsHHa77s/Tlx1Oz6MyuI/AAAAAAAABeU/k1J8THK4NEA/s320/nrthumbplcaut3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Call for backup! Anyway, we've reported the phish and hopefully it'll be offline soon enough.&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-7343523081689519448?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/7343523081689519448/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=7343523081689519448&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7343523081689519448'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7343523081689519448'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/08/northumbria-police-authority-website.html' title='Northumbria Police Authority website defaced, serving Phish for breakfast'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-cyjQC-bO6UE/Tlxu4q8BngI/AAAAAAAABeM/TmkeVUnPuNI/s72-c/nrthumbplcaut1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4995273313248247519</id><published>2011-08-29T19:09:00.000-04:00</published><updated>2011-08-29T19:09:52.797-04:00</updated><title type='text'>WARNING: Incoming Hurricane Irene Scams Ahead!</title><content type='html'>As much as we dread hearing about disasters—the natural ones, most especially—happening on certain parts of the globe where most of our families and friends are, we still keep an eye out for what's happening. And as much as we dread remembering that there &lt;i&gt;are&lt;/i&gt; people out there who actually bank on news about such natural disasters to scam others, we continue to remind you about them. If you're that person who wants to give financial aid to those who need them during these trying times, this reminder is for you.  &lt;br /&gt;&lt;br /&gt;A few days back, the FBI &lt;a href="http://www.fbi.gov/scams-safety/e-scams"&gt;issued&lt;/a&gt; a warning to netizens to "beware of fraudulent e-mails and websites claiming to conduct charitable relief efforts". The warning also pointed readers to &lt;a href="http://www.ic3.gov/media/2011/110311.aspx"&gt;the IC3 government Web page&lt;/a&gt; where they can read tips on how to avoid getting entangled into this kind of fiasco. I suggest you visit that page. Also, please tell your friends and family about scams popping not just into their email inboxes but possibly on their social networking streams, too.&lt;br /&gt;&lt;br /&gt;In retrospect, here is a short list of some of the "natural disaster" scams that had been out in the wild:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://sunbeltblog.blogspot.com/2011/03/japan-earthquake-relief-and-young-girl.html"&gt;"Japan Earthquake Relief" and "Young girl commits suicide" Facebook apps&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://sunbeltblog.blogspot.com/2010/01/dangerous-web-search-haiti-earthquake.html"&gt;Dangerous web search: “haiti earthquake donate”&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://sunbeltblog.blogspot.com/2010/01/donations-via-text-messages-will-be.html"&gt;Donations via text messages will be the next spam scam&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://sunbeltblog.blogspot.com/2005/09/hurricane-rita-scams.html"&gt;Hurricane Rita scams&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Stay safe!&lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4995273313248247519?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4995273313248247519/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4995273313248247519&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4995273313248247519'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4995273313248247519'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/08/warning-incoming-hurricane-irene-scams.html' title='WARNING: Incoming Hurricane Irene Scams Ahead!'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-1143424856282228771</id><published>2011-08-29T08:13:00.001-04:00</published><updated>2011-08-29T08:13:39.185-04:00</updated><title type='text'>The Longstanding KVGB Compromise</title><content type='html'>Our friends at Zscaler &lt;a href="http://research.zscaler.com/2011/02/kvgbank-affected-with-malicious.html"&gt;has blogged&lt;/a&gt; about a website compromise involving &lt;b&gt;Karnataka Vikas Grameena Bank (KVGB)&lt;/b&gt;, a prominent regional rural bank in India, last February of this year. It then housed a malicious JavaScript (JS) code that redirects visitors to another domain that was believed to be malicious at one point. The code had been found to be "multilevel obfuscated". Also according to the entry, they have informed the said bank about the code injected on their website.&lt;br /&gt;&lt;br /&gt;As of 11:05PM (GMT–4:00) of August 25,&amp;nbsp;six months after the said blog is published,&amp;nbsp;GFI Senior Exploit Analyst Francesco Benedini is alerted&amp;nbsp;about KVGB still housing obfuscated JS code. Below is the screenshot of the code found on the site:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-UIY2h9juPUQ/Tlt7BjnSHbI/AAAAAAAAAPE/C7QdipsJfy0/s1600/GFI_08262011_img1.png" imageanchor="1"&gt;&lt;img border="0" height="191" src="http://2.bp.blogspot.com/-UIY2h9juPUQ/Tlt7BjnSHbI/AAAAAAAAAPE/C7QdipsJfy0/s320/GFI_08262011_img1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;i&gt;(click to enlarge)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;After deobfuscation,&amp;nbsp;Benedini has determined that&amp;nbsp;the supposedly malicious domain is inactive, thus, poses no threat to bank site visitors. The script, however, is working. We detect the malicious code as &lt;b&gt;Trojan-Downloader.JS.Twettir.a (v)&lt;/b&gt;, and&amp;nbsp;VirusTotal &lt;a href="http://www.virustotal.com/file-scan/report.html?id=bda6de3e31ca6688b1b87e635601cd17bf5ccd383975afa1100c2a3d40526e68-1297056384"&gt;shows&lt;/a&gt; a 24/43 detection ratio across all AV companies.&lt;br /&gt;&lt;br /&gt;Our experts have also pointed out that the attack is related to the &lt;a href="http://sunbeltblog.blogspot.com/2008/01/on-that-mbr-rootkit.html"&gt;MBR&lt;/a&gt; &lt;a href="http://isc.sans.edu/diary.html?storyid=3820"&gt;rootkit&lt;/a&gt;&amp;nbsp;(Trojan-Spy.Madlo) we generally know as Sinowal / Mebroot. This is because (1) the&amp;nbsp;obfuscation technique used in this attack is reminiscent of the technique used by Sinowal, and (2) the structure of the inactive URL follows the one seen in Sinowal infection campaigns.&lt;br /&gt;&lt;br /&gt;GFI is currently attempting to reach KVGB in order to help them clean up their website.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Adam Thomas for additional information)&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-1143424856282228771?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/1143424856282228771/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=1143424856282228771&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1143424856282228771'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1143424856282228771'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/08/longstanding-kvgb-compromise.html' title='The Longstanding KVGB Compromise'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-UIY2h9juPUQ/Tlt7BjnSHbI/AAAAAAAAAPE/C7QdipsJfy0/s72-c/GFI_08262011_img1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-9144839791932198353</id><published>2011-08-25T01:09:00.000-04:00</published><updated>2011-08-25T01:09:16.033-04:00</updated><title type='text'>Facebook Makes a Move Toward Security</title><content type='html'>Facebook recently &lt;a href="https://www.facebook.com/safety/attachment/Guide%20to%20Facebook%20Security.pdf"&gt;published a guide for it's users on how to secure their online accounts&lt;/a&gt; from anything that threatens one's &lt;i&gt;Facebook&lt;/i&gt; security. Among those covered are Wall, Chat, and Comment spams, weak passwords, fake applications, and account hacking. Personally, I'm quite happy that &lt;i&gt;Facebook&lt;/i&gt; is actually doing something that concerns user security, despite it being quite late come to think about it. Still, better to have something than nothing.&lt;br /&gt;&lt;br /&gt;The document guide contains practical tips and cases to illustrate the gravity of the attack if ignored. It also has some great, agreeable points that make it a good reference anyone can recommend to their friends and family who are on &lt;i&gt;Facebook&lt;/i&gt;. Feel free to download&amp;nbsp;&lt;a href="https://www.facebook.com/safety/attachment/Guide%20to%20Facebook%20Security.pdf"&gt;here&lt;/a&gt;&amp;nbsp;and distribute.  &lt;br /&gt;&lt;br /&gt;Jovi Umawing&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-9144839791932198353?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/9144839791932198353/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=9144839791932198353&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/9144839791932198353'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/9144839791932198353'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/08/facebook-makes-move-toward-security.html' title='Facebook Makes a Move Toward Security'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-1024680103375243473</id><published>2011-08-18T12:54:00.000-04:00</published><updated>2011-08-18T12:54:54.003-04:00</updated><title type='text'>Of Spam and Speeding</title><content type='html'>Our engineers over at the AV Labs have spotted recently a deluge of spam about a "traffic ticket" that purports to come from a state department in New York. The said spam has a compressed file attachment that, once extracted, contains a file that bears the icon of a normal &lt;i&gt;Adobe&lt;/i&gt; .PDF file. Mimicing file icons, of course, is a common tactic used by criminals to appease any doubts or worries from recipients of such emails, which are actually malicious in nature.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-BqyxaRbIAWk/Tkz3r-VEyZI/AAAAAAAAAO0/3Zu4kM7L_40/s1600/ticket-spam_fig1.png" imageanchor="1"&gt;&lt;img border="0" height="207" src="http://2.bp.blogspot.com/-BqyxaRbIAWk/Tkz3r-VEyZI/AAAAAAAAAO0/3Zu4kM7L_40/s320/ticket-spam_fig1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-_WBv8kC8xrk/Tkz31JBfzZI/AAAAAAAAAO8/vi_6kKATDgM/s1600/ticket-spam_fig2.png" imageanchor="1"&gt;&lt;img border="0" height="246" src="http://2.bp.blogspot.com/-_WBv8kC8xrk/Tkz31JBfzZI/AAAAAAAAAO8/vi_6kKATDgM/s320/ticket-spam_fig2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;"The malware appears to be sent from a botnet of unknown origin." says GFI Spyware Researcher Adam Thomas.&lt;br /&gt;&lt;br /&gt;When this supposed .PDF file is "opened," it connects to &lt;i&gt;sfkdhjnsfjg(dot)ru&lt;/i&gt; (a server in Ukraine) to download and execute the file, &lt;i&gt;pusk3.exe&lt;/i&gt;. This .EXE file, detected as&amp;nbsp;&lt;b&gt;Trojan.Win32.Generic.pak!cobra&lt;/b&gt;,&amp;nbsp;is a dropper/downloader. As of this writing, it drops/downloads a rogue AV and TDL rootkit variants.&lt;br /&gt;&lt;br /&gt;CNN has written an &lt;a href="http://articles.cnn.com/2011-07-07/us/new.york.hoax.ticket_1_hoax-e-mail-computer-virus-traffic-ticket?_s=PM:US"&gt;article&lt;/a&gt; about this ticket spam early last month. Seeing that it's still getting &lt;a href="http://garwarner.blogspot.com/2011/08/new-york-city-uniform-traffic-ticket.html"&gt;attention&lt;/a&gt;, we can surmise that it still is very much at large.&lt;br /&gt;&lt;br /&gt;VIPRE users are already protected from ever accessing and downloading interesting "goodies" from the .RU site. And you can protect yourself from nasty attachments pretending to be something else by enabling file extension names of all files on your system. It's a simple thing to do, yet it can save you from computer security disasters.&lt;br /&gt;&lt;br /&gt;Jovi Umawing (Thanks to Adam Thomas for the analysis)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-1024680103375243473?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/1024680103375243473/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=1024680103375243473&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1024680103375243473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/1024680103375243473'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/08/of-spam-and-speeding.html' title='Of Spam and Speeding'/><author><name>silvakreuz</name><uri>http://www.blogger.com/profile/10537923376209736885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/-TO3ckHOiGfw/ThB_Whd5JII/AAAAAAAAAEI/T-2mUBWfbRE/s220/alumni_new.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-BqyxaRbIAWk/Tkz3r-VEyZI/AAAAAAAAAO0/3Zu4kM7L_40/s72-c/ticket-spam_fig1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4692074606696430347</id><published>2011-08-11T03:33:00.000-04:00</published><updated>2011-08-11T03:33:06.201-04:00</updated><title type='text'>Phony Mc Bling Sting</title><content type='html'>CCleaner (formerly Crap Cleaner, which is a glorious name) is a handy program used to &lt;a href="http://en.wikipedia.org/wiki/CCleaner"&gt;remove unwanted files&lt;/a&gt;, fix borked registry entries and more besides.&lt;br /&gt;&lt;br /&gt;There's a website located at&amp;nbsp;myccleaner(dot)ru which claims to be offering up multiple versions / builds of CCleaner:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Ur2qqRMdHNU/TkN70xkZv_I/AAAAAAAABWs/8oqZ1FQbp0s/s1600/cclnsmsfke1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-Ur2qqRMdHNU/TkN70xkZv_I/AAAAAAAABWs/8oqZ1FQbp0s/s320/cclnsmsfke1.gif" width="305" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-WI4G69hxDo4/TkN71d4nmtI/AAAAAAAABWw/dQ9wnboUmYc/s1600/cclnsmsfke2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-WI4G69hxDo4/TkN71d4nmtI/AAAAAAAABWw/dQ9wnboUmYc/s320/cclnsmsfke2.gif" width="319" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;It's also offering you the chance to part with your money in various spectacular ways. At time of writing, none of the download links work save for one: "ccsetup303.exe". Unfortunately for us, this is what's known in the business as "a very bad thing". Check it out:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-LL_96R30fV8/TkN_eR1r66I/AAAAAAAABW0/8c82TBe8W-4/s1600/cclnsmsfke3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="247" src="http://4.bp.blogspot.com/-LL_96R30fV8/TkN_eR1r66I/AAAAAAAABW0/8c82TBe8W-4/s320/cclnsmsfke3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Things look reasonably normal at this point, but then it all goes horribly wrong:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-SqYC2icr51Q/TkOATE1FTMI/AAAAAAAABW4/d6kqYEe9iMk/s1600/cclnsmsfke4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="245" src="http://3.bp.blogspot.com/-SqYC2icr51Q/TkOATE1FTMI/AAAAAAAABW4/d6kqYEe9iMk/s320/cclnsmsfke4.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;It's not quite all the tea in China, but it &lt;i&gt;is&lt;/i&gt; every payment method under the Sun. SMS, paid call, credit card, terminals, Paypal, webmoney and so on. Click some of the links, and they show you all the fun ways you can cough up some dough to (theoretically) get your hands on the program up for grabs. Here's an example:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-VdrLIThJDTw/TkODAohRf6I/AAAAAAAABW8/BaALGiCYFhc/s1600/cclnsmsfke5.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-VdrLIThJDTw/TkODAohRf6I/AAAAAAAABW8/BaALGiCYFhc/s320/cclnsmsfke5.gif" width="258" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Most of the payment methods seem to clock in at around $5 USD. Not sure I'd chance it personally - you'd be much better off going to the &lt;a href="http://www.piriform.com/"&gt;official site&lt;/a&gt; and grabbing it there instead. As for ccsetup303.exe, it has a &lt;a href="http://www.virustotal.com/file-scan/report.html?id=1e025f8062942a459963d46c6cf2ddc377e7f5321ce790a8cbef5762dcd14148-1313043729"&gt;29/43 score on VirusTotal&lt;/a&gt; and we detect it as&amp;nbsp;Hoax.Win32.ArchSMS. You also score one whole cool point if you got the Simpsons reference in the title.&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4692074606696430347?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4692074606696430347/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4692074606696430347&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4692074606696430347'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4692074606696430347'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/08/phony-mc-bling-sting.html' title='Phony Mc Bling Sting'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-Ur2qqRMdHNU/TkN70xkZv_I/AAAAAAAABWs/8oqZ1FQbp0s/s72-c/cclnsmsfke1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-3371740053331263050</id><published>2011-08-04T15:27:00.003-04:00</published><updated>2011-08-04T15:30:59.641-04:00</updated><title type='text'>Here's another thing that's scary about Shady RAT</title><content type='html'>A lot of chatter and breathless reporting about &lt;a href="http://www.vanityfair.com/culture/features/2011/09/operation-shady-rat-201109" target="_blank"&gt;Shady RAT&lt;/a&gt;.&amp;nbsp; All the makings of an epically awesome story — the US is being taken down by Chinese interlopers to the nastiest degree, installing keyloggers and other badness on US government computers.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Whatever.&amp;nbsp; Who the heck knows how bad this thing really is (and I am not the &lt;a href="http://www.sci-tech-today.com/news/Researchers-Critical-of-McAfee-Report/story.xhtml?story_id=010001478ELU" target="_blank"&gt;only skeptic&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;But here’s what’s of concern to a lot of security researchers I deal with:&amp;nbsp; It was known by McAfee (and certainly others) but no one apparently ever did anything to take the C&amp;amp;C down, even after knowing about it for months. &lt;br /&gt;&lt;br /&gt;Let’s take a look at this paragraph from the hyperbolic &lt;a href="http://www.vanityfair.com/culture/features/2011/09/operation-shady-rat-201109" target="_blank"&gt;Vanity Fair article &lt;/a&gt;(italics are mine): &lt;br /&gt;&lt;blockquote dir="ltr" style="margin-right: 0px;"&gt;"Alperovitch first picked up the trail of Shady rat in early 2009, when a McAfee client, a U.S. defense contractor, identified suspicious programs running on its network. Forensic investigation revealed that the defense contractor had been hit by a species of malware that had never been seen before: a spear-phishing e-mail containing a link to a Web page that, when clicked, automatically loaded a malicious program—a remote-access tool, or rat—onto the victim’s computer. The rat opened the door for a live intruder to get on the network, escalate user privileges, and begin exfiltrating data. After identifying the command-and-control server, located in a Western country, that operated this piece of malware, &lt;em&gt;McAfee blocked its own clients from connecting to that server. Only this March&lt;/em&gt;, however, did Alperovitch finally discover the logs stored on the attackers’ servers. This allowed McAfee to identify the victims by name (using their Internet Protocol [I.P.] addresses) and to track the pattern of infections in detail."&lt;/blockquote&gt;So McAfee blocked the IPs for its own customers. In &lt;em&gt;March &lt;/em&gt;the C&amp;amp;C was discovered. It’s not clear if it’s still up or finally down (or if it was down by &lt;a href="http://blogs.mcafee.com/wp-content/uploads/2011/08/ShadyRat2011.png" target="_blank"&gt;June&lt;/a&gt;). &lt;br /&gt;&lt;br /&gt;I never saw one mention of this C&amp;amp;C on any of the closed and vetted security lists I’m on.&amp;nbsp; A simple “takedown please” would have generated all the help necessary.&amp;nbsp;&amp;nbsp;This is how a lot of bad stuff gets handled, and&amp;nbsp;the vast majority of internet users are none-the-wiser that there is a&amp;nbsp;large group of very dedicated&amp;nbsp;researchers who are making their lives safer every day.&amp;nbsp;&amp;nbsp;All of the data on the C&amp;amp;C can be put away nicely for post-takedown analysis. &lt;br /&gt;&lt;br /&gt;I’m quite certain that McAfee wasn’t the only organization that knew about this, so it’s not only McAfee who shares the blame here. Furthermore, I am not singling out McAfee (we work with them on other areas and there are many very decent people there). Furthermore, McAfee is being clear that this issue is “&lt;a href="http://blogs.mcafee.com/mcafee-labs/revealed-operation-shady-rat" target="_blank"&gt;old news&lt;/a&gt;”, and McAfee’s Dmitri Alperovitch is not acting the role of the self-aggrandizer, but rather as a researcher sharing some pretty interesting and educational insights.&amp;nbsp; Furthermore, McAfee did reach out to infected victims.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;However, there are many groups or organizations, upon having proof of this C&amp;amp;C, that would have been all over shutting the thing down as fast as possible in coordination with other security organizations. &lt;br /&gt;&lt;br /&gt;The bigger point is this:&amp;nbsp; If you, as a security researcher, discover Really Bad Stuff, you should do everything in your power to get that Really Bad Stuff shut down.&amp;nbsp; The next time you see a killer presentation at Blackhat or RSA, ask “what have you done to solve the problem?”. &lt;br /&gt;&lt;br /&gt;Perhaps we need a volutnary code of ethics for the security industry.&amp;nbsp; It can start with some pretty simple things, like “If I see really bad stuff happening, I will work with others to fix it”.&amp;nbsp; &lt;a href="http://en.wikipedia.org/wiki/Enlightened_self-interest" target="_blank"&gt;Enlightened self interest &lt;/a&gt;and all that. &lt;br /&gt;&lt;br /&gt;Screw NDAs,&amp;nbsp;the fear of competition getting a heads-up on your research, losing a scoopable news story, etc.&lt;br /&gt;&lt;br /&gt;This is not about McAfee. &amp;nbsp;This is about the industry. &amp;nbsp;There are&amp;nbsp;researchers out there who&amp;nbsp;aren’t in a position to share data with competitors due to corporate reasons.&amp;nbsp; They shouldn’t be in that position. &amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Alex Eckelberry&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-3371740053331263050?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/3371740053331263050/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=3371740053331263050&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3371740053331263050'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3371740053331263050'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/08/here-another-thing-that-scary-about.html' title='Here&amp;#39;s another thing that&amp;#39;s scary about Shady RAT'/><author><name>Alex Eckelberry</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-5699853514540782274</id><published>2011-08-04T04:46:00.000-04:00</published><updated>2011-08-04T04:46:13.155-04:00</updated><title type='text'>Pottermore: Expecto Riddikulus!</title><content type='html'>Now that I have Harry Potter fans foaming at the mouth for randomly mashing up two unrelated spells to express the intent of this blog entry, I'll continue.&lt;br /&gt;&lt;br /&gt;Pottermore is - help me out here, &lt;a href="http://en.wikipedia.org/wiki/Pottermore"&gt;Wikipedia&lt;/a&gt; - a site that will sell eBooks of the Harry Potter novels,&amp;nbsp;provide over 18,000 words of additional content including background details and settings and "experience" the events of the books first hand. All I know is, lots of Harry Potter fans are excited.&lt;br /&gt;&lt;br /&gt;Access is currently &lt;a href="http://www.inquisitr.com/130896/pottermore-beta-arrives-with-access-contest-find-the-magic-quill/"&gt;limited for the Beta&lt;/a&gt;, and of course this means ole' lightning forehead has become a prime target for scams and people wanting to turn a quick profit. Things you should be keeping an eye out for, and running away from:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;1)&lt;/b&gt; The Official Blog has listed some things you &lt;a href="http://insider.pottermore.com/2011/07/magical-quill-some-questions-answered.html"&gt;probably shouldn't be getting involved in&lt;/a&gt;. Individuals offering to "register on your behalf, with your details" should be avoided. Buying and / or selling accounts on places such as eBay? Don't go there, Hermione. Not only are you "depriving genuine fans", you're also giving money to random people and hoping they give you access to the accounts they claim they've set up. You have some protection in place should you start dabbling in eBay auctions (though not from the price - $100 for a "Buy it now"? Oh dear):&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://1.bp.blogspot.com/-cNTthofv4Z8/TjpJAlNGASI/AAAAAAAABWY/Lz3Mf_7NvLM/s1600/pottermorebay2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="161" src="http://1.bp.blogspot.com/-cNTthofv4Z8/TjpJAlNGASI/AAAAAAAABWY/Lz3Mf_7NvLM/s320/pottermorebay2.gif" style="cursor: move;" width="320" /&gt;&lt;/a&gt;&lt;br /&gt;Click to Enlarge&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-xzy5yPpy1B8/TjpI-0_b8sI/AAAAAAAABWU/mxe8ycAejUs/s1600/pottermorebay1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="222" src="http://2.bp.blogspot.com/-xzy5yPpy1B8/TjpI-0_b8sI/AAAAAAAABWU/mxe8ycAejUs/s320/pottermorebay1.gif" style="cursor: move;" width="320" /&gt;&lt;/a&gt;&lt;br /&gt;Click to Enlarge&lt;br /&gt;&lt;br /&gt;Go throwing your cash around on "myfakewebsite(dot)whatever" and you may be in a little more trouble.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;2)&lt;/b&gt; Videos on Youtube. I guess if someone is willing to pay up to $100 for Beta access that may not even exist, they'd &lt;i&gt;certainly&lt;/i&gt; be willing to walk right into this "Old as the hills" favourite:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-S_EkgPbA2Hk/TjpOidesHfI/AAAAAAAABWc/e1RPW-Xxv8A/s1600/pottermorebay3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="223" src="http://4.bp.blogspot.com/-S_EkgPbA2Hk/TjpOidesHfI/AAAAAAAABWc/e1RPW-Xxv8A/s320/pottermorebay3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;"Beta access" available for "Download". At the risk of making like Nostradamus, I wonder if we'll see a survey?&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-NUnMwY50is4/TjpOjwBmnRI/AAAAAAAABWg/3O_yKxp0pms/s1600/pottermorebay4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="219" src="http://2.bp.blogspot.com/-NUnMwY50is4/TjpOjwBmnRI/AAAAAAAABWg/3O_yKxp0pms/s320/pottermorebay4.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;A big hand for the most tiresome scam in history, everybody!&lt;br /&gt;&lt;br /&gt;The individual who sent you there will (of course) make some affiliate money should you fill in a survey or enter a competition - meanwhile, after handing over your data to some random marketers you'll be "blessed" with a download which typically turns out to be A) Nothing, or B) Malware.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;3)&lt;/b&gt; Malware and poisoned search results. Another obvious one, but even so here's a random example found after a few minutes digging around:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-6DBJjBgbl5A/TjpZL1dtbKI/AAAAAAAABWk/tIgtF5_HaJM/s1600/pottermorebay5.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-6DBJjBgbl5A/TjpZL1dtbKI/AAAAAAAABWk/tIgtF5_HaJM/s1600/pottermorebay5.gif" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;The Malware diagnosis for that one can be seen &lt;a href="http://www.google.com/safebrowsing/diagnostic?site=http://stevenlouistaylor.com/fefvcm/Pottermore&amp;amp;hl=en"&gt;here&lt;/a&gt;. It seems to be clean at time of writing, but six exploits, five Trojans and two scripting exploits would have been more than enough to give you bad hair day. You can expect more hacked sites serving Malware alongside poisoned search engine results - both text &lt;i&gt;and&lt;/i&gt; image. If your kids are happily babbling on about the joys of Pottermore, it may well be worth sitting down with them and pointing out the types of shenanigans they need to avoid.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Muggles, eh? Can't turn your back on them for more than five minutes...&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Christopher Boyd&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-5699853514540782274?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/5699853514540782274/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=5699853514540782274&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5699853514540782274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5699853514540782274'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/08/pottermore-expecto-riddikulus.html' title='Pottermore: Expecto Riddikulus!'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-cNTthofv4Z8/TjpJAlNGASI/AAAAAAAABWY/Lz3Mf_7NvLM/s72-c/pottermorebay2.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-2698521106818727109</id><published>2011-08-04T02:38:00.004-04:00</published><updated>2011-08-04T02:42:55.376-04:00</updated><title type='text'>Department of Defense 419 Mail...</title><content type='html'>I'm almost certain pretending to be the Department of Defense is not a good idea, but then it's not like a 419 scammer has that many of those in the first place. In fact, they can't even format an email properly so here's my best attempt at getting as much of it into the screenshot as I could:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-ZDbZWh0Ep1s/Tjo9UE9QZXI/AAAAAAAABWQ/aKuuX1WHKsc/s1600/fakebrrmail1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-ZDbZWh0Ep1s/Tjo9UE9QZXI/AAAAAAAABWQ/aKuuX1WHKsc/s320/fakebrrmail1.gif" width="181" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;You're not missing much after the cutoff, really - just a Mr Allen Bickford asking you to send over your name, address, sex, age, occupation, country, mobile number, landline number and a scan of your ID card.&lt;br /&gt;&lt;br /&gt;You know, like you'd do for any random email sent your way. This one does promise you $750,000 in unclaimed funds though. So there's that.&lt;br /&gt;&lt;br /&gt;If you see a "Remittance of Unclaimed Funds" mail arrive in your mailbox from the "Defense&amp;nbsp;Finance and Accounting Services", with one "Mrs. Patricia Smith" acting as your legal representative then you should safely file it under "Fire into the heart of the Sun". In fact, you should do that with &lt;i&gt;any&lt;/i&gt; random email promising you untold riches.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks Wendy)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-2698521106818727109?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/2698521106818727109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=2698521106818727109&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2698521106818727109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/2698521106818727109'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/08/department-of-defense-419-mail.html' title='Department of Defense 419 Mail...'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-ZDbZWh0Ep1s/Tjo9UE9QZXI/AAAAAAAABWQ/aKuuX1WHKsc/s72-c/fakebrrmail1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-3844505488508832380</id><published>2011-08-01T02:01:00.001-04:00</published><updated>2011-08-01T02:01:14.796-04:00</updated><title type='text'>Grinding your (Top) Gears</title><content type='html'>Here's a site called watchtopgear(dot)info that lets you - amazingly enough - watch Top Gear.&lt;br /&gt;&lt;br /&gt;Sort of.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-V1iMoOjmDjQ/TjYajGL0poI/AAAAAAAABVw/mwu1gls9yKo/s1600/topgrdtinfo1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-V1iMoOjmDjQ/TjYajGL0poI/AAAAAAAABVw/mwu1gls9yKo/s320/topgrdtinfo1.gif" width="280" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Series 16 / 17 are yours for the taking. Sounds awesome if you're a Top Gear fan, but of course you need to install something - specifically, one of those FREEzefrog bundles we've &lt;a href="http://sunbeltblog.blogspot.com/2011/06/froggy-fun-with-open-source-software.html"&gt;mentioned previously&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-DBKHsDNvqPQ/TjYakz0E9gI/AAAAAAAABV0/5yornXP_wHQ/s1600/topgrdtinfo2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="225" src="http://2.bp.blogspot.com/-DBKHsDNvqPQ/TjYakz0E9gI/AAAAAAAABV0/5yornXP_wHQ/s320/topgrdtinfo2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Everything seems to be coming up Milhouse for a change, as once the install is complete the website presents you with Top Gear content (instead of the more usual "nothing at all" for a &lt;a href="http://sunbeltblog.blogspot.com/2011/07/batscam.html"&gt;site of this nature&lt;/a&gt;). Feelings of vehicular joy are short lived, however, as the long list of content listed is a little bit inaccurate. And by "little bit", I mean "six videos work and everything else is a hilarious joke at your expense".&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-aL2fuFofRkU/TjYoW1gFRbI/AAAAAAAABV8/7SZKbosqKzU/s1600/topgrdtinfo4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-aL2fuFofRkU/TjYoW1gFRbI/AAAAAAAABV8/7SZKbosqKzU/s320/topgrdtinfo4.gif" width="242" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Click the first six links, and you'll see some Top Gear episodes that have been ripped and placed on random streaming services.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-g0NKo0nzEe8/TjYoVLlPSmI/AAAAAAAABV4/Xe4L5iK7exo/s1600/topgrdtinfo3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="251" src="http://1.bp.blogspot.com/-g0NKo0nzEe8/TjYoVLlPSmI/AAAAAAAABV4/Xe4L5iK7exo/s320/topgrdtinfo3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Click any of the other links, and you'll see the Top Gear team showing off a variety of overly tight jeans and not much else:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-5CtHUnYURz0/TjYogI77PWI/AAAAAAAABWE/TspWYc4zdyU/s1600/topgrdtinfo5.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="292" src="http://1.bp.blogspot.com/-5CtHUnYURz0/TjYogI77PWI/AAAAAAAABWE/TspWYc4zdyU/s320/topgrdtinfo5.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Yes, all of the content is missing. Yes, you just installed a bundle of stuff to watch six videos.&lt;br /&gt;&lt;br /&gt;No, that was not a good idea.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Hat tip to &lt;a href="http://www.it-mate.co.uk/"&gt;Steven Burn&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-3844505488508832380?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/3844505488508832380/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=3844505488508832380&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3844505488508832380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3844505488508832380'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/08/grinding-your-top-gears.html' title='Grinding your (Top) Gears'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-V1iMoOjmDjQ/TjYajGL0poI/AAAAAAAABVw/mwu1gls9yKo/s72-c/topgrdtinfo1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-8145398641104572892</id><published>2011-07-29T16:50:00.002-04:00</published><updated>2011-07-29T16:50:44.980-04:00</updated><title type='text'>Flickr continues to be a haven for porn/malware redirects</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-6GEmY0RpcuM/TjMZ34t0EYI/AAAAAAAABpc/Fkwlxu1CPqk/s1600/flikr12381231238812312390.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://4.bp.blogspot.com/-6GEmY0RpcuM/TjMZ34t0EYI/AAAAAAAABpc/Fkwlxu1CPqk/s320/flikr12381231238812312390.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;A few weeks ago, I &lt;a href="http://sunbeltblog.blogspot.com/2011/07/flickr-hosting-porn-redirects.html"&gt;blogged &lt;/a&gt;about porn/malware redirects being hosted on Flickr. &amp;nbsp;After a brief respite, it's back and strong.&lt;br /&gt;&lt;br /&gt;Just a quick and trivial search shows over hundreds of porn redirect links, pushing "lolita porn" and redirecting to porn and malware sites.&lt;br /&gt;&lt;br /&gt;And again, a list of bad sites is &lt;a href="http://sunbeltsoftware.com/alex/gblog/flickr12810.pdf"&gt;here&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Alex Eckelberry&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-8145398641104572892?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/8145398641104572892/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=8145398641104572892&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8145398641104572892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/8145398641104572892'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/07/flickr-continues-to-be-haven-for.html' title='Flickr continues to be a haven for porn/malware redirects'/><author><name>Alex Eckelberry</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-6GEmY0RpcuM/TjMZ34t0EYI/AAAAAAAABpc/Fkwlxu1CPqk/s72-c/flikr12381231238812312390.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-3343238962734706298</id><published>2011-07-28T04:27:00.006-04:00</published><updated>2011-07-28T04:49:03.808-04:00</updated><title type='text'>"Activate Skype". Or not...</title><content type='html'>Here's something that &lt;i&gt;looks&lt;/i&gt; like Skype, may or may not &lt;i&gt;give&lt;/i&gt; you Skype but certainly wants something in return for it first.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-LLd2fEpWpgM/Ti5myiKp-4I/AAAAAAAABQY/iuepryGBLHc/s1600/fkspesms1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="261" src="http://2.bp.blogspot.com/-LLd2fEpWpgM/Ti5myiKp-4I/AAAAAAAABQY/iuepryGBLHc/s320/fkspesms1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-tOQwUlxq9wo/Ti5mzd7UGfI/AAAAAAAABQc/BOdtP7exwck/s1600/fkspesms2.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="208" src="http://4.bp.blogspot.com/-tOQwUlxq9wo/Ti5mzd7UGfI/AAAAAAAABQc/BOdtP7exwck/s320/fkspesms2.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&amp;nbsp;Click to Enlarge&lt;/div&gt;&lt;br /&gt;So far, so good I guess. It's all in Russian of course, but it looks like it is actually installing Skype.&lt;br /&gt;&lt;br /&gt;Then this happens.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Wrlp4RLdJv8/Ti5m0II3PBI/AAAAAAAABQg/k6lmBMRuRw4/s1600/fkspesms3.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="256" src="http://1.bp.blogspot.com/-Wrlp4RLdJv8/Ti5m0II3PBI/AAAAAAAABQg/k6lmBMRuRw4/s320/fkspesms3.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;As you can see, it's now asking for something - that something presumably being an SMS unlock code, which would likely cost money to obtain (in testing, the dropdown box wasn't available - either because the required site content isn't live at the moment or they're not interested in my IP address).&amp;nbsp;In case you're wondering, the text in the&amp;nbsp;greyed&amp;nbsp;out box says (according to Google translate): "Loading Countries". The other pieces of text say things like "Attention, the program requires activation" and "select your country of residence to receive instructions on how to activate".&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Thanks, but no thanks. Also&amp;nbsp;here's a&amp;nbsp;&lt;a href="http://www.virustotal.com/file-scan/report.html?id=341e0357d2d09e970d02e3ec386a30b8779694e8bb8ee7c89b44c50ee9f9dd5a-1311840543"&gt;27/43 VirusTotal score&lt;/a&gt;.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;The file above (SkypeSetup.exe) comes from a website that doesn't appear to have any frontend to it - d2xx(dot)ru. There's no fancy graphics, no text, nothing. Just the download. The Email address used to register the domain is used elsewhere, however - skype4free(dot)ru. This one has a little more going on:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-GR5A1UKIbBs/TjEV-gPENgI/AAAAAAAABUE/SguRe09tKGI/s1600/fkspesms4.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://1.bp.blogspot.com/-GR5A1UKIbBs/TjEV-gPENgI/AAAAAAAABUE/SguRe09tKGI/s320/fkspesms4.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;My handy Google Translator picked up the word "Free" quite a lot - "also, something about having to activate your copy", not so much. You probably shouldn't bother with any of the above when you can go &lt;a href="http://www.skype.com/"&gt;here&lt;/a&gt; and obtain Skype for free, right now.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Christopher Boyd&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-3343238962734706298?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/3343238962734706298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=3343238962734706298&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3343238962734706298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/3343238962734706298'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/07/activate-skype-or-not.html' title='&quot;Activate Skype&quot;. Or not...'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-LLd2fEpWpgM/Ti5myiKp-4I/AAAAAAAABQY/iuepryGBLHc/s72-c/fkspesms1.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-7414123142756377820</id><published>2011-07-27T16:50:00.000-04:00</published><updated>2011-07-27T16:50:13.543-04:00</updated><title type='text'>The state of Typepad security</title><content type='html'>There are over 3,000 malicious sites on Typepad serving malware.&amp;nbsp;I've put the list of malicious domains &lt;a href="http://sunbeltsoftware.com/alex/gblog/typepad.pdf"&gt;here&lt;/a&gt;. &amp;nbsp;I've also notified Typepad.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-nGtIiBfc2TM/TjB4lKrkGLI/AAAAAAAABpY/qOp0N0T1VAE/s1600/typepadi123881231238.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="172" src="http://4.bp.blogspot.com/-nGtIiBfc2TM/TjB4lKrkGLI/AAAAAAAABpY/qOp0N0T1VAE/s320/typepadi123881231238.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Typepad -- get a clear abuse or security contact on your site, and do some work to police your blogs. &lt;br /&gt;&lt;br /&gt;Alex Eckelberry&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-7414123142756377820?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/7414123142756377820/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=7414123142756377820&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7414123142756377820'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/7414123142756377820'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/07/state-of-typepad-security.html' title='The state of Typepad security'/><author><name>Alex Eckelberry</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-nGtIiBfc2TM/TjB4lKrkGLI/AAAAAAAABpY/qOp0N0T1VAE/s72-c/typepadi123881231238.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-5608592205225221933</id><published>2011-07-25T04:28:00.000-04:00</published><updated>2011-07-25T04:28:58.298-04:00</updated><title type='text'>FakeVimes Infection Offers Up "Home Codec" Packs</title><content type='html'>I don't want your heads to explode with the force of a thousand Suns, but I think we may be looking at a new Rogue AV gimmick - specifically in the area of Codecs. I know, I know. Breathe deeply and take a seat.&lt;br /&gt;&lt;br /&gt;Researcher Adam Thomas was investigating some FakeVimes Rogues, installing one of the fake products from the usual "Your PC has been infected" website:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-y19esnlcwOI/Ti0mK4ufSKI/AAAAAAAABQI/1xhid7nMzuY/s1600/fvimscodmia00.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="191" src="http://2.bp.blogspot.com/-y19esnlcwOI/Ti0mK4ufSKI/AAAAAAAABQI/1xhid7nMzuY/s320/fvimscodmia00.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;He then got ready to take in the sights when this happened: nothing.&lt;br /&gt;&lt;br /&gt;No fake security tool asking for payment or telling you the PC has about a million fictitious infections on it, no flashing lights, nothing at all. He rebooted the test machine - still nothing (sometimes a rogue won't rise from the depths until you restart the machine. Surprise!)&lt;br /&gt;&lt;br /&gt;This is a typical FakeVimes GUI:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-4LEU_y8Teus/Ti0Oc2Oz9ZI/AAAAAAAABPk/HCBWVy7KHzA/s1600/2_Anti-MalwareLab_GUIwm.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="210" src="http://4.bp.blogspot.com/-4LEU_y8Teus/Ti0Oc2Oz9ZI/AAAAAAAABPk/HCBWVy7KHzA/s320/2_Anti-MalwareLab_GUIwm.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;This is not a typical FakeVimes GUI:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-1VhgRksG5mE/Ti0U8GY7OjI/AAAAAAAABPo/j1BZGQxZ3m8/s1600/fvimscodmia0.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="207" src="http://2.bp.blogspot.com/-1VhgRksG5mE/Ti0U8GY7OjI/AAAAAAAABPo/j1BZGQxZ3m8/s320/fvimscodmia0.jpg" style="cursor: move;" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;You can see what I did there. Anyway, this is a sample of some of the files found on the infected machine:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;c:\Documents and Settings\All Users\Application Data\7f0924\VD7f0_2326.exe&lt;br /&gt;c:\Documents and Settings\All Users\Application Data\ip\e.exe&lt;br /&gt;c:\Documents and Settings\All Users\Application Data\ip\FRed32.dll&lt;br /&gt;c:\Documents and Settings\All Users\Application Data\ip\instr.ini&lt;br /&gt;c:\Documents and Settings\All Users\Application Data\ip\SmartGeare.exe&lt;br /&gt;c:\Documents and Settings\All Users\Application Data\ip\spoof.avi&lt;br /&gt;c:\WINDOWS\system32\c_726535.nls&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Adam went off to the main folder where all the nasty things reside, and found something interesting lurking:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-2kJfZi4U1-0/Ti0VuGYvfPI/AAAAAAAABPs/9kC65-02mK8/s1600/fvimscodmia1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="45" src="http://2.bp.blogspot.com/-2kJfZi4U1-0/Ti0VuGYvfPI/AAAAAAAABPs/9kC65-02mK8/s320/fvimscodmia1.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;"Spoof.avi"? Well, hello there. Let's see what you get up to in your spare time:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-5xCXBuwi4G8/Ti0Y84f3fFI/AAAAAAAABPw/bj6ic__FFJY/s1600/fvimscodmia3.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-5xCXBuwi4G8/Ti0Y84f3fFI/AAAAAAAABPw/bj6ic__FFJY/s320/fvimscodmia3.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;A "Your Codec version is too old" &amp;nbsp;message, complete with popup in the bottom right hand corner telling you to "Update your Codec".&lt;br /&gt;&lt;br /&gt;Is this FakeVimes variant designed to prevent you watching movies while making the creator some cash into the bargain? Let's take a look. Opening up a random website to view some files gave some interesting results.&lt;br /&gt;&lt;br /&gt;This is what happened when Adam downloaded a video and tried to play it:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/--3ZR1l5fwTc/Ti0asiqHEaI/AAAAAAAABP0/37u5CqDPNgM/s1600/fvimscodmia4.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="270" src="http://1.bp.blogspot.com/--3ZR1l5fwTc/Ti0asiqHEaI/AAAAAAAABP0/37u5CqDPNgM/s320/fvimscodmia4.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;i&gt;"Windows Media Player cannot find the selected file"&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;Not to be beaten, he tried to stream the file instead. Then they schooled us with science. And a large popup.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-ZrGAXuhwd78/Ti0boVVQaHI/AAAAAAAABP4/sMubmD5ypXU/s1600/fvimscodmia5.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="181" src="http://3.bp.blogspot.com/-ZrGAXuhwd78/Ti0boVVQaHI/AAAAAAAABP4/sMubmD5ypXU/s320/fvimscodmia5.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;&lt;i&gt;"Your player cannot display this video file. Click here to update the Codec".&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;At this point, you might be expecting infection files, but you're &lt;i&gt;already&lt;/i&gt; infected. So what are they going to do?&lt;br /&gt;&lt;br /&gt;This:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-2pNQ2jgvCRI/Ti0caAdkruI/AAAAAAAABQA/jAb5vtAU0Ro/s1600/fvimscodmia6.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://4.bp.blogspot.com/-2pNQ2jgvCRI/Ti0caAdkruI/AAAAAAAABQA/jAb5vtAU0Ro/s320/fvimscodmia6.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;i&gt;"Home Codec pack and video converter suite: This version contains a full package of codecs enabling you to watch video in the best quality possible".&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Yes, and my name is Elvis. Hitting the (extremely large) Purchase buttons will give you this "Show me the money" payment screen, asking you for up to $35.95 for the "Home" version, plus an optional $9.95 to "Protect your purchase" with an extended download service:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-DzXyCFM1_jg/Ti0eY-v0CKI/AAAAAAAABQE/eCTl7ZHi0jw/s1600/fvimscodmia8.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="239" src="http://1.bp.blogspot.com/-DzXyCFM1_jg/Ti0eY-v0CKI/AAAAAAAABQE/eCTl7ZHi0jw/s320/fvimscodmia8.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;Call it a hunch, but I think the best optional extra here is to run in the opposite direction from this particular fiasco. Of course, it makes sense for the people behind these attacks to start mixing things up a little - FakeVimes has been all over the news recently, and not in a "We love you, FakeVimes" kind of fashion. More like a "FakeVimes, we hate you and we want you to die" fashion as Google took the unprecedented step of &lt;a href="http://www.computerworld.com/s/article/9218576/Security_experts_knock_Google_on_PC_infection_warnings?taxonomyId=85"&gt;warning millions of infected users about it&lt;/a&gt; last week. From the &lt;a href="http://www.google.com/support/websearch/bin/answer.py?answer=1182191"&gt;Google help page&lt;/a&gt; on this one:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;A warning appears at the top of the search results page when we believe that the computer you're using is infected with malicious software, also known as "malware." Malware can be used to intercept your computer's connection to Google and other sites. When Google's system detects that a connection has been intercepted, it's likely that the computer was previously infected with malicious software.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;With the heat coming around the corner, the FakeVimes people have decided to diversify into a sort of "Rogue Codec" market instead, and it looks like things could be interesting in Rogue AV land for a while as their otherwise glacier-like tactics ("You're infected, have some Rogue AV, thanks for the money") begin to change.&lt;br /&gt;&lt;br /&gt;We detect this one as&amp;nbsp;VirTool.Win32.Obfuscator.hg!b (v).&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks to Adam Thomas for finding this one)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-5608592205225221933?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/5608592205225221933/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=5608592205225221933&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5608592205225221933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5608592205225221933'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/07/fakevimes-infection-offers-up-home.html' title='FakeVimes Infection Offers Up &quot;Home Codec&quot; Packs'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-y19esnlcwOI/Ti0mK4ufSKI/AAAAAAAABQI/1xhid7nMzuY/s72-c/fvimscodmia00.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-5322640430175921295</id><published>2011-07-22T11:02:00.001-04:00</published><updated>2011-07-22T11:03:02.845-04:00</updated><title type='text'>Correct Version Aversion</title><content type='html'>Here's a site located at&amp;nbsp;buburuzka(dot)com/xhupt/71093(dot)php offering up some fake Flash. Humorously, they don't seem to have taken much notice of the latest Flash Player version - compare and contrast:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-JR_0PzhYfiw/TimQTuCls1I/AAAAAAAABOA/v64tW5lDqlM/s1600/fflswrngvrsn1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="158" src="http://2.bp.blogspot.com/-JR_0PzhYfiw/TimQTuCls1I/AAAAAAAABOA/v64tW5lDqlM/s320/fflswrngvrsn1.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;As you can see, a bit of a difference there. Of course, they're hoping the victims they attract to a scam like this won't pay much attention to what they're clicking on, never mind confirm that the Flash numbering offered matches up with reality.&lt;br /&gt;&lt;br /&gt;We detect this as&amp;nbsp;VirTool.Win32.Obfuscator.hg!b1 (v), another &lt;a href="http://sunbeltblog.blogspot.com/2011/07/update-center-targets-chrome-and.html"&gt;2GCash&lt;/a&gt; clickfraud Trojan, and the VirusTotal score is currently at &lt;a href="http://www.virustotal.com/file-scan/report.html?id=ef8f8dc5bde18e428e9cef1b1293e13f93bf513688631102bab3b07287ccaa77-1311346336"&gt;5/43&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Christopher Boyd (Thanks to Patrick Jordan for finding this one)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-5322640430175921295?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/5322640430175921295/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=5322640430175921295&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5322640430175921295'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/5322640430175921295'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/07/correct-version-aversion.html' title='Correct Version Aversion'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-JR_0PzhYfiw/TimQTuCls1I/AAAAAAAABOA/v64tW5lDqlM/s72-c/fflswrngvrsn1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10854312.post-4762700061047678240</id><published>2011-07-22T10:03:00.000-04:00</published><updated>2011-07-22T10:03:51.744-04:00</updated><title type='text'>.gov.np Site Serves Up Banking Phish</title><content type='html'>This is the National Development Volunteer Service of &lt;a href="http://en.wikipedia.org/wiki/.np"&gt;Nepal&lt;/a&gt; located at &lt;br /&gt;&lt;br /&gt;ndvs(dot)gov(dot)np/_vti_cnf/customer(dot)ibc(dot)htm:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-NGsvos0g2yg/TilogVBGzzI/AAAAAAAABN4/jihELzAbahg/s1600/ndvsphsh0.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="215" src="http://1.bp.blogspot.com/-NGsvos0g2yg/TilogVBGzzI/AAAAAAAABN4/jihELzAbahg/s320/ndvsphsh0.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;This is an unwelcome addition to the website in the form of a Lloyd's TSB Phish.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-9VMlLOOAyRU/TilohtbnF0I/AAAAAAAABN8/XEwuIyEqpkg/s1600/ndvsphsh1.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="188" src="http://4.bp.blogspot.com/-9VMlLOOAyRU/TilohtbnF0I/AAAAAAAABN8/XEwuIyEqpkg/s320/ndvsphsh1.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;Click to Enlarge&lt;/div&gt;&lt;br /&gt;It's still live at time of writing, but it's been reported so let's hope it's taken down and the site is cleaned up soon.&lt;br /&gt;&lt;br /&gt;Christopher Boyd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10854312-4762700061047678240?l=sunbeltblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sunbeltblog.blogspot.com/feeds/4762700061047678240/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10854312&amp;postID=4762700061047678240&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4762700061047678240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10854312/posts/default/4762700061047678240'/><link rel='alternate' type='text/html' href='http://sunbeltblog.blogspot.com/2011/07/govnp-site-serves-up-banking-phish.html' title='.gov.np Site Serves Up Banking Phish'/><author><name>paperghost</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-NGsvos0g2yg/TilogVBGzzI/AAAAAAAABN4/jihELzAbahg/s72-c/ndvsphsh0.gif' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
