Wednesday, January 09, 2008

IM Attacks, Botnet Birth, Banner Ads, Storm Worm & More

Another busy day of security news and other tidbits in the forum.

We'll start off with some stats about IM attacks, from FaceTime. They've come up with some percentages displaying which is the biggest target. Would it be MSN, AIM or YIM?

Sandi over at Spyware Sucks has some good news about rogue banner ads. Seems the offensive server has been firewall blocked. She rocks on these don't she? Heck she rocks on alot of stuff.

The RBN seem to be offering the Storm worm domains for sale or rent. This was not exactly something that wasn't foreseen. I've been keeping track of this and it was previously mentioned as a possibility.

Way back when the SoBig worm came out, it seems this was the birth of the botnet according to these researchers. I wasn't even involved in security back then, but I remember the news about SoBig. It seemed scary at the time. But then once I came to know the slightest bit about worms\spam\emails I realized it was the easiest thing in the world to avoid.

Researchers are saying that the 'shadow economy' of malware is worth about 105bn. Of course no one can really put a figure on this, because no one can know what these guys are actually taking in or spreading around.

ICANN is trying to put an end to domain name tasting in an effort to remove a loophole in the system. Many a poor soul have fallen victim to these asshats. Many people consider them nearly as bad as spammers. Can't say I'd disagree.

Well that's about it for now. That ought to be plenty of reading for you. Please take some time to share your experiences in our forums.

Tuesday, January 08, 2008

MBR Rootkit, BUSTED, Malicious Site, Violence and Crime

In our BUSTED! forum you can read about the longest sentence given to someone for computer sabotage.

Websense posts an alert about an infected\compromised website to be on the watch for.

There is a report that ties watching pr0n and violent movies creates a drop in criminal activity.

Finally from Symantec we have info on the a new MBR rootkit

Storm Variant In Mass Phish

SCMagazine reports that one of the latest Storm variants is being used in an expansive phishing scheme targeting two large banking institutions. No matter the season, there's always another Storm brewing.

New IM Worm

Over at Trend Labs they warn of another IM worm making the rounds. WTF, are people still clicking these unknown links? Wake up people!!

Monday, January 07, 2008

More News In Forums!!

Wow, forum has been busy since my last post. Well busy with me posting more stuff there anyhow. Why don't you all drop in and comment?

There seem to be more states adding laws that restrict computer forensics to 'official' investigators. This I'm sure is an effort to prevent those who 'think' they know what they're doing from actually doing more harm than good.

An opinion from a journalist expresses concerns over new TLDs as they may relate to new areas of spammer exploitation. Certainly a qualified concern. Lord knows we don't need any more areas to worry about. I know I'll be blocking any of those new ones.

Popular site Geek.com got got hacked late last year, having personal info on users who bought from them in the last year or so stolen. Oppss. One would think a site named 'Geek' would keep extra secure software. Just goes to show you.

PG weighs in on what he thinks really happened with the whole Facebook\Zango 'spyware' situation. Reading it might just surprise you.

To finish off this latest entry we have an update on the wonderful gang over at RBN. They have a new set of servers ready to go. Thankfully we get a pretty ecent jump on this info thanks to the tireless efforts of a dedicated group of people.

Vista Nags, Banner Ads, YaHoo! AntiSpam, Ad-Aware SE

The first Monday in 2008 brings us some good reads in the forums.

Got Vista? Then read about stopping those annoying balloon alerts about start up programs. I know this was annoying when I was using Vista....all of 3 minutes at least.

It seems there is a never ending stream of banner ads running on sites everywhere. I ought to just make a 'sticky' post for them already.

Users of YaHoo! based webmail have a new spam defense system which was just rolled out. That's always good news. Die spammers!!

Lastly there may be a reprieve for users of the old Ad-Aware SE. You just might be able to keep using it. But so far we have no idea how long. we'll keep you abreast of things tho.

Sunday, January 06, 2008

Malware On Blogspot....Again!

Well Saturday nite I went cruisin' for malware on Blogspot. And I'll bet ya can't guess what I found there?

Friday, January 04, 2008

MS Bulletin Advance Notification for January 2008

One Critical, one Important

Critical - Remote code execution

Important - Local elevation of privilege

Forum Update- Firday Jan 4

Couple of updates and our first BUSTED! entry in the new forum.

The thing that PG found earlier, thinking it was a MySpace exposure turned out to be the companies hosting company. So no major worries.....we think.

Sears went rather quickly to disable the search function found earlier which exposed everyone's buying history to most anyone. Good work Sears!

Lady Justice is tracking a few scumbag spammers who were involved in a spam\scam\fraud scheme. And one of them is on the run.

And filing under 'embarrassing', a security vendors site was hacked earlier in the week but is ok now. Guess whoever was in charge of maintaining server stability was off drinking eggnog or something. Hope he got some coal for that.

New User, Wi-Fi Virus Outbreak?, IM Attacks, MySpace Controller

We have a new member, so drop in to say 'hello'

Researchers have put forth proof that a virus could spread via wi-fi connections pretty easily.

It seems PG has stumbled across something that could be a MySpace control & command application, but he's not sure!

Finally users of the ever popular IMs need to take heed as the number of attacks has increased recently and more are expected for 2008.

Rogue Domains, Sears, Banner Ads, BUSTED!

Some new info posted in the forums, so I'll summarize here for you.

A new set of rogue domains has been posted, I'm sure all will be added to most hosts files soon enough.

The rogue banner ads thread has an addition, a German sites been hit now and Sandi has details as usual.

As if things were not bad enough, sears has suffered a serious privacy issue. Bought anything there lately? If so I can tell you what it is.

Trend Labs lists their top December threats for those keeping score.

Finally we have a new forum called BUSTED! In there you'll find links and articles of people who've been busted in online related scams. Not so much rogue stuff really, more for actual legal cases.

Thursday, January 03, 2008

Zango Tries Backdooring To Facebook

The gang at Sunbelt alerts us that Fortinet researchers have discovered a widget that tries to installs Zango on Facebook. Check it out and warn your fellow FBers, I know I am.

Busy Day!!

Wow...busy day already.

We have two 'Emerging Security Threats' to post about today. One in Real Player and the other a flash player problem.

Then we have what Kaspersky is calling Diehard virus variants making their top ten list for December and Sunbelt finds a a trojan which requires a phone call to activate a license.

In the Spam\Phish forum we find that users of Facebook are being phished with fake account that is live.

Finally those of you using Ad-Aware SE must upgrade to Ad-Aware 2007 as SE will no longer be supported

Recent Threads In Forum

Been busy the last day or so with the Blogspot malware stuff. I even got a mention on a major new IT site!

Sandi over at Spyware Sucks blog has more rogue banner ads and PG found some MySpace ringtone spammers using Toms profile! Yea, that's real low key.....they may know how to make some money but these malware guys just ain't too bright. Few code lines short of a program.

The good people at F-Secure got their hands on a malware kit and have it dissected. Scary professional looking too.

Finally we have a potential major problem with file identification. There may be a way for the scumbags to avert one of the ways in which a file is specifically ID'd.

Tuesday, January 01, 2008

WOW! 920K Hits For Dec.

Well I have to say I'm pleasantly surprised. I'd expected a good number of hits this month as I watched and tracked. Was figuring I'd get maybe 800K. But lo and behold, you guys got me to over 920,000 hits.

Thanks! Some more stats here....

Monday, December 31, 2007

UPDATED: Blogger\Blogspot Malware Gang

Well I've posted this info about these blogs in several forums, even posted to StopBadware.org. Lets see how long it takes Google to remove these, even if they are not currently spewing malware. My documentation ought to be good enough. Updated Info......

Saturday, December 29, 2007

1-5 PCs Unpatched; Flag Malware Sites

Couple of new links in the forums today.

From security researchers in Denmark comes the stat that 1 in 5 machines are unpatched Windows OSes. This of course could lead to zombie armies that run amok across the Net giving me loads of HijackThis! log files to do. Read on about my hobby-to-be continued-for-the-foreseeable-future

And from a malware specialist who has written some great detailed analysis of RBN comes a challenge for users to ruin a malware gangs holidays

Thursday, December 27, 2007

Malware @ Blogspot Blogs......Again

After a short while of inactivity, it appears the BMG(Blogger Malware Group) are at it again. After reading another security blog, I wandered on over and was not disappointed. Every blog I hit once I saw a pattern delivered a good payload of malware, calling out to the same sites. Read about the details here...

Sunday, December 23, 2007

Merry X-Mas Storm Worm!!

The latest variant of the Storm worm is out and about. Some details can be read here in the forums and that thread is linked to more detailed analysis.

Friday, December 21, 2007

Friday Forum Roundup

Was a busy day and I didn't have time to post these as they were added to the forum so here's the round up.

A security and privacy researcher informs as to the effectiveness of crowd rating phish sites. His discovery may well shock you at how easy the system can be 'gamed'.

PG is out once again, donning his 'Godamm Batman' attire to show a script kiddie how easily they get 0wnd. Always a good read.

Anti-virus vendor AVG has subpoenaed major software and Internet companies to gain counterfeiters info and none of these companies have complied.

And some guys got busted over on MySpace for mass spamming so you know it won't be a very good X-Mas for those guys...I know a tear welled up in my eye too....NOT!!

Then the good folks at eWeek share with us a researchers reverse engineering of malware that showed how very complex and professional it is in it's distribution.

Finally we have some launch dates for F-1 cars in '08 and the hpHosts competition comes to an end.

Thursday, December 20, 2007

Sears.com Installs Spyware & Proxy!

Wow...this sounds really bad. A researcher from CA, formerly PestPatrol joined a community for Sears.com and got something he didn't bargain for....spyware! A proxy was installed and tracked and sent information to a
third party marketing company!
Read on for frightening details.

Teens Cherish Privacy

As more teens blog, IM and create pages on social networks, it has begun to look as tho they cherish their personal info. Most are very selective with whom they share that info with. That can only be a good thing

Kaspersky Update Cripples Boxes

It would seem the latest update from Kaspersky to their anti-virus has caused a few systems to crash, and it's the second time this week. See what happens to systems....

New Version: AVG Anti-Virus Free Edition

The good folks at AVG Grisoft have just updated the free version of their popular free anti-virus program. Details & download link

RBN Business End Examined

Our favorite RBN blog has a look into the business end of getting paid thru rogue installs of the gang most reportedly responsible for all the malware on the Net. Very well detailed with graphics and links.

Wednesday, December 19, 2007

Google Ad Accounts Hijacked

Another problem related to Google ad accounts. It seems they are being hijacked to rogue servers and of course offering users the usual...malware.

Google is aware of the problem and working to eliminate as many of these accounts as possible.

Google Orkut Worm Spreading

Those of you who use the Google Orkut social networking site need to read about the worm spreading which infects you just by viewing it! 400,000 already infected.

Tuesday, December 18, 2007

Tuesday Forum Threads

Tuesday was a busy day in the forums. And I didn't get a chance to post 'as it happened' what with X-Mas stuff to get done still.

Direct Revenue is back in the news, with Dutch firms being fined for unauthorized installs. Who knew? Too bad the gang in the states didn't get what they deserved.

The Zone alarm\Ask.com toolbar thread links to some very interesting ommentary, mostly against, where there is always one guy who see the ruckus over naught. Probably one of the affiliates, they can never see the unethical side of things.

Speaking of Zone Alarm, there seem to be some problems with the latest updated version, so if you have it let us know if you're experiencing troubles.

Got Google's toolbar? Then you'll want to read this about an unpatched hole, leaving users exposed to phish attempts.

Bit Defender released its Top 10 Malware for '07 today as well. I don't suppose anything new will crop up to make the list.

Last but not least, a security researcher thinks Facebook's registration page asks for a little too much info about you and expresses concerns. To be honest, I think he has a point.

Well there you have it, lots of reading to catch up on....enjoy and don't forget to offer your thoughts. The forum only thrives when the people are heard.

Monday, December 17, 2007

Zombie to Botnet to.....?

A security researcher thinks the botnet as it's become to be known as needs to be called something else. Their reasoning is that it no longer properly describes the level of activity that it does. Got any suggestions?

Zone Alarm & Ask.com Toolbar, Money For Them, Annoyance For You

Well Zone Alarm has decided to try and make a few buck off unknowing users.

Following Webroot's lead, they've added a 'spyblocker'\toolbar. Of course the install option is already ticked for your convenience, isn't that nice of them? Ummm...no thanks ZA.

And by pre-ticking that lil box, it almost guarantees many installs, thereby leading to mucho money for ZA and of course Ask.com a well. Vent your
anger here....

Sunday, December 16, 2007

Complex Trojan Stealing Bank Info

A highly crafted trojan is stealing bank account info from certain types of accounts and doing so very quietly. It's one of those types of programs that even tho made by lowlifes, researchers are impressed by the complexity. Lets hope this trend does not take off

Friday, December 14, 2007

RBN: They Can Run, But They Can't Hide

With success comes notoriety. In most cases this is a good thing. Unless of course you're a criminal enterprise. In that case, the more exposure you get the more you increase your chances of getting caught and or having to uproot your operations. This is the challenge facing the Russian Business Network. Read more on RBN tracking

Password Recovery....Too Easy?

A researcher writes about the weakness of password recovery questions and wonders why they are not more complex and or more in number. How hard are your pw questions....?

Thursday, December 13, 2007

Root Kits On One In Five PCs

The folks over at PCWorld have a new set of stats, collected with Prevx that indicates root kits are on 20% of all machines. Read More Here.

Wednesday, December 12, 2007

Hot Phish & Spam Links, Cookie Issues & HP Laptop Security Woes

Once again, the Phish & Spam forum are taking the bustling 'n' hustling title for the day. Symantec has a new trend to speak of, fake newsletters. Anything you can think of, spammers will try. And then some.

From a respected security analysis, we get an overlook of the last year in spam. Trends new and old, site life for phishes and more.

As spam increases each year, it climbs higher as a total amount of email sent. These numbers almost can't be believed, upwards of 90% were spam in '07

Own an HP laptop? It appears some of the software involved exposes users to a risk of getting hijacked

For the last entry into the daily grind we have a couple of tools which may allow some cookie security holes to be exposed or created. There may finally be a reason to fear cookies.

Tuesday, December 11, 2007

Patch Tuesday, Dec '07

Today MS released 7 updates to Windows users. 3 critical, and 4 inportant. Be sure to get yours. Check 'em out.

Trend Micro Monthly Round Up

Well it's time for a monthly round up of what's been hot and popular with the scumbags who make malware and today Trend Micro has Novembers details

Encrypt Your MSN IM Convos

Today we have a small tool which will help keep your MSN IM conversations limited to who you want to receive them. A must have for all those 'personal' IMs we all make eh?? Not to mention it may keep the boss from knowing you're planning to sneak off to a game one afternoon. Check it out now....

Phishing & Spam News Today!!

This morning starts out with a bang in the Phishing and Spam forum, with articles from Symantec referencing credit unions and community banks being targeted, and we have the best and worst domain registrars from Brian Krebs at Security Fix.

Then at Computer World they look at the latest Web 2.0 trends which may affect DNS servers. Finally we have Avert Labs talking about recent trends in spam and phishing campaigns.

Whew....that wore me out, go check 'em out and drop a comment.

Monday, December 10, 2007

Links In The forum Dec 11

It would appear something that's been being talked about has finally come about, malware using RSS feeds to push files to users. Took them long enough, we've been hearing about the possibility for a couple of years, I've got two links related in this latest thread

A phishing campaign that's been going on for a month at least gets some updated info, and of course the home sites are in China, the new play ground for scumbags, go figure

The rogues list from Malwarebytes gets some new additions this last week or so

For a little chuck at the expense of MS, some people have come up with what may or may not be Windows error messages

Symantec Monthly Spam Report

This month Symantec catalogs the holiday spam subjects, looks at the last 12 months of wonderful inbox filling spam and mentions new email harvesting campaign by spammers. See more here...

MS Launches New Password Site

MS has decided to offer users a new way to keep track of their passwords, with a new site. I guess they figure if they make it easy enough, then users won't have so much trouble remembering longer, complex pws and make things a tick safer. Read about it here and comment

Friday, December 07, 2007

Exploits Held In Search Cache

As ever expansive as search is becoming, who would think that you could find all sorts of exploit code hiding where it could circumvent security software? Not me.....

RBN Rogue Spreading Domains

As RBN gets more exposed, so to do their inner workings. One thing that has come to light is their ever increasing amount of rogue spreading domains

Jedi Tool Dissection

Continuing on the George Lucas\StarWars connection, we have a look at the innards of a lightsabre

Dec. 6 Forum Links

It's that time of the month, MS has released Decembers Bulletin Advanced Notice, with 4 critical updates and 3 important one.

In Kaspersky's quarterly malware code analysis we get a break down of the hottest trends in malware. Always interesting stuff there.

Interested in how bots work on the Web? Then this in depth read of an IRC botnet is for you.

For those of us who are true geeks, a look into George Lucas' Skywalker Ranch sound studios will be a pretty cool quick tour.

Wednesday, December 05, 2007

Dec 5 Threads....

Looks like MS pulled out all the stops when it came to naming the next iteration of IE. Probably cost them hundreds of thousands, maybe millions in consumer testing, brand recognition and the like. ....See if it was worth it

It looks like they've found a way to make cookies a bit more of a threat. With new variants, they can circumvent some cookie control apps and anti-spyware tools. Read the crumby details here

With Vistas spiffy aero looks and improved over all display, it appears that MS decided to put a twist on the BSOD....now Vista offers a PSOD.

AV vendors have gathered to see if they can nail down testing guideline that will give users a sense of conformity. Yeah, sure....we all know how well the naming convention meeting went. More here...

Todays Links

There is a new tactic malware scum are trying out. Rather than telling users they need a codec to install, instead they say there is an error with playback to get their crap installed. Found by MS MVP WinHelp2002, Read more about it...

Researchers at F-Secure claim malware has risen 100% over the last 12 months, doubling the amount it took 20 years to get to. Pretty scary....comment here

To soften the bad PR they have gotten, MS has decided to soften their policy on pirated software and re-do the whole set up. See the details here

Come into the forums and meet our latest moderator, he's been with us since the get go....Meet Johnincal

Wednesday, November 28, 2007

RBN Directly Behind Google Search Poisoning

Well as no surprise, the RBN was behind the recent Google search poisoning. Lots of good detailed analysis will keep RBN moving, and that's never good if you're a criminal. Too much time spent on evading the authorities will cause
mistakes.
Read On...

CAPTCHA For $$

Defeating CAPTCHA encoded websites is one malware scumbags biggest problems.

But they have ways of doing, including service that use the human element. Likely some third world country paying absurdly small amounts of money. More Here

Gromozon Gang Turns To Rogues & Social engineering

Looks like the boys behind Gromozon malware have turned to social engineering and rogues to pull in unknowing users. Read All About It!!....

Fake YouTube Links, New Spam Gang?

Well in the phishing and spam forum we have two new items. The first deals with some spam containing fake YouTube links that -GASP!-...re-direct to malware! OMG! Whoda thunk they could do that? Hehe.

Next we have what looks to be some gang trying to reach Storm worm gang notoriety. Using celebs names as bait, they of course get suckers to install their trojans by duping them into opening emails. Uh-Huh...When will people get a clue? Have you been suckered in?

Corrupted Google Searches = Malware

I for one trust Google to provide fairly safe search results. But in this day and age of malware scumbags looking at every vector to infect, they've combined two tactics, a type of 'seeding' of key search words and drive-by downloads.

While doing a search for my son I stumbled upon some odd search results which led to something that has gotten huge and is making alot of news on main media sites. I call it Google Poisoning.

Tuesday, November 27, 2007

More IFRAME Exploited Sites Found

Researchers are finding more malicious hacking of well visited popular sites using IFRAME exploits to take them over. And as usual, these exploits can be traced back to......give ya 2 guesses.

FTC: 8 Mil ID Theft Victims

From the FTC, over 8 million people victims of ID theft. In at least half of the instances less than $500 was pilfered. In 10% of the incidents over $6000 was taken. Read More Here.....

Hotmail & eBay Phish, New Online Bak Threat

This morning PG alerts us to a Hotmail & eBay phish that didn't quite work as well as it could have, but it got at least one poor soul. Be sure to check out the image of the obvious mistake.

And then F-Secure notes that there is a new threat to online banking. They call it 'Man in the browser'. Read on for details on both....

Pr0n Ring Busted, EBook & Equifax Scam?

Couple of interesting reads in our General Software\Internet forums today, first up we have a Mom who helps police in Spain bust a kiddie pr0n ring after she stumbles upon some images. Resulting in 13 arrests. Always a good thing to rid the Net of low life, sick scumbags such as these pedophiles.

Then we have an instance of a blogger who made an innocent post about a charge to his credit card from a company he'd never heard of. Suddenly the post takes on a life of its own as others also complain of the same thing. The link appears to be Equifax. Investigations are of course ongoing.

Offer your opinons here....

Monday, November 26, 2007

MS Learning From WGA Fiascos, To What End?

Based on the last summers fiasco with WGA, MS claims it's learning from those mistakes. Some people would suggest to simply dump it. What do you think?

Windows Bug Found, All OSes Affected

udjitjvqMS has been alerted to a serious bug in all Windows operating systems which could allow malicious code to execute, especially not in the US.Herrre We Go Again......

Tuesday, November 20, 2007

New Spam Campaign w\.scr Files

Two top anti spam companies find new campaign spreading trojan using a .scr file. Y-A-W-N....spam, What, me worry? Nope

WinPatrol 'Top 9 Windows Utilities'

Hot on the heels of WinPatrol's birthday, comes an award as one of 'Top Windows Utilities' by a popular online website. It's almost as if everyone has begun to find out what I've always thought, Scotty is just one of the best pieces of software you can have on your PV. Don't you think so?

3 Good Reads Today

We've got 3 new stories which I think are good reading for all.

First we have RBN involved with a Monster.com hack. The site pages affected have been pulled but those guys get into everything.

Secondly, with holidays around the corner you can bet malware scumbags are spooling up email spam attacks to try and trick users with social engineering tactics. Watch your inbox for those amazing deals which seem to good to be true, because they are.

And lastly, in an effort to curb the malware guys researchers suggest trying to hit them where it hurts, the pocket. Too bad they can't all agree on how to do just that. Then there's the problem of prosecution. The scumbags hide out in countries that don't exactly have any real effectual policy on Net crime.

Read more and add your thoughts.....

Monday, November 19, 2007

Huge China Based Phish Attack On MySpace

Looks like MySpace has fallen victim to a huge China based phish campaign. All domains involved end at that TLD, .cn. I'm sure the MySpace IT staff is on the job tho, all 1-2 of them. Unless it's holiday season. Or after 5PM. Phishing For
IDs @ MySpace

Spell Carefully When You Search

This isn't exactly new information here. Many of you know this, misspell a search, and you can land on some malware site. But for those who don't know.... Get educated some

By 2010, Net Too Clogged

Researchers predict by then we won't be able to use the Net. Too many viral sites, online purchases and search engines will be the end of the Net as we know it. Yeah, yeah sure sure, talk about FUD. The Sky Is Falling....NOT

More Rogue Banner Ads

Yes, this is becoming a more popular trend these days. Seems like every week we find another site with rogue banner ads. Follow The Latest Banner Ad Problem

Sunday, November 18, 2007

New MSN IM Trojan On The Loose

eSafe security researchers have discovered a new MSN trojan spreading thru the Net. It's controlled via an IRC channel. More Here....

Happy Birthday WinPatrol!!

Scotty is 10 years old tomorrow. For ten years BillP has been offering this freeware product which has helped countless Net users regain some control of their machines.

As the Net has become ever more dangerous, Bill has added many security related tools to keep that control. And never has a cooler more concerned guy for the Joe Net user. And it's been free for the basic program, which for each upgrade still includes some neat stuff.

So everyone help Bill blow out the candles and wish for WinPatrol's continued stride to becoming one of the Nets most popular 'must haves' on any system.

HAPPY BIRTHDAY Scotty & Bill! Celebrate here.....

Friday, November 16, 2007

McAfee: Doom & Gloom, or FUD?

The researchers at McAfee are predicting more complex and intelligent bots, as well as attacks of gaming sites and more concentrated effort to breaking Vista in 2008. More here....

Economy Of Malware Tools

Back in October a security researcher had a look into the economy of proprietary tools used and sold by malware authors. It's a pretty interesting read, they really do operate as small, but illegal businesses. Tracking The Tools....

Thursday, November 15, 2007

RBN Not 'Gone' At All

Not that anyone really expected them to fold up and go home, but some further analysis into their core IPs show no changes at all. Follow The Detectives...

Zlob Boys Change Things Up

As opposed to the Storm worm gang, the asshats that push the fake codecs, which turn out to be Zlob infections have finally made a slight change. Instead of tricking users into installing a codec, they're now saying you need to update your flash player. See More here....

Wednesday, November 14, 2007

RBN Into Rogue Ad Serving Too

Well, it's not like this would surprise anyone. The RBN seem to have a hand in just about every illegal operation on the Net. Why not ad serving? There sure is alot of it going on these days. RBN Does Banner Ads....

Y-A-W-N...New Storm Tactic......

Yeah, those boy backing the Storm worm keep coming up with new ways to try and hide. Now they're using re-directs to Geocities web pages. Read on.....

Google BlogSpot:Malware Source Part 2

Yes, that's right, the BMG have recently changed things up for the worse since last time.

Now you can get, along with the latest info in the blog sphere, a Vundo\Virtumondo infection, any form of SDBot variants, RDBot backdoors and Zlob infections. Of and it goes without saying you'll also be able to get the generic annoying type of adware that comes with the previously mentioned goodies.

And I didn't have to do a thing, just land on one of the thousands and thousands splogs which are set up just to do this, spread malware. Google knows about them. Myself and one of the Blog*Stars have communicated information all about this amazing nastiness running around. All you have to do is go 'Next Blog' hunting. But I warn you not to do this unless you have a machine you don't care much about and has no data on it, because these blogs can crush the average machine to bits.

See what I got with no effort at all. And pray you don't ever run into one of these. Google BlogSpot: Great Place For Malware

Tuesday, November 13, 2007

This Weeks Storm Update

This weeks variant is a stock scam and a pop up as well. As per usual, don't open any unknown or even ever so slightly suspicious emails. If you do....well then you sure won't do it a second time now will ya? Storm Worm Update Thread

Nov. MS Updates

This months Microsoft Updates are now available. Only two, one labeled as critical, the other important. Git 'em quick!

RockPhish Spam Gang Using YouTube

Looks like this gang have picked YouTube for a campaign of spam. Naturally, if you open any unwanted emails, you deserve what you get, so pay attention!!
RockPhish Gang Spam Info

ZoneAlarm Anti-Spyware Free!

In an effort to get users protected as well as push their new ForceField virtual browser, CheckPoint software, makers of Zone Alarm security products is offering ZA Anti-Spyware for free. The virtual browser is also free. Check it out here

Monday, November 12, 2007

RBN Setup Shop In India?

Well it looks as tho after running out of China, perhaps due to the quick research of determined security researchers, the RBN boys have popped up in India.

As per usual, screen caps and direct code snippets supply all the info you need to draw your own conclusions. Lets hope India does not become a haven for malware as it has for outsourcing. Follow the bouncing gang....

Sunday, November 11, 2007

MySpace Bands Hacked

If you've got a band on MySpace or have a fav band bookmarked, you're goint to want to read this and learn about this hack. Seems tons of band profiles have been hacked pretty good, and MySpace does not appear to have a handle on it yet.

MySpace Band Hacks Galore

Saturday, November 10, 2007

RBN Moves Off Radar?

The Russian Business Network set up shop in China on approximately Nov. 8. As of late Friday, they have disappeared off the radar.

Could the RBN gang be diversifying their network? Perhaps the publicity has them breaking things up to try and subvert quick attention? Read what the experts think.....

Friday, November 09, 2007

Email Poll In forum

Well I have a new poll in the forum. It's an inquiry into how often you check your email through out the day. Why don't you check it out and vote

Thursday, November 08, 2007

RBN: Whack-A-Mole

Well the boys over at RBN have started what amounts to a shell game of sorts. They have begun to use a different IP than they had previously. This is not anything new or unexpected.

They've been doing this since 2004. What's new is that they are now monitored by a lot of people. People who are just as motivated to exposing them as they are to ripping people off. They keep moving, the security community keeps whacking them down. Watch the shell game

Rogues List Update Info

Well after a long time off I'm back to updating the RogueRemover rogues thread. Far too many for me to list as it's been 10 weeks. See More Here.

Wednesday, November 07, 2007

IEDefender Rogue Devs Try Defending Actions

These rogue developers tried to defend their unethical lowly existence to several seasoned security experts. It was a slaughter. Read On!

Russian Business Network Offline?

UPDATE 12PM MST:

Brian Krebs of Security Fix @ the Washinton Post says it's possible RBN may relocate servers to China.

Well at Trend Labs is reporting that IPs related to RBN are no longer resolving. This could be one of two things, either they have been shut down, or they are re-configuring.

Wanna guess where I'm putting my money? Wait...there's more!!

Sorry, I ain't been posting much

Sorry it's been so long since my last blog. Had a case of the 'blahs' and could not get motivated.

Here is a round up of the last couple of weeks and I promise to blog more regularly.

Child porn websites 'worsening'
Sophos: Top spam-relaying countries - US leads the way
Magazine Sites Serving Malware
Corporate malware on the rise
Bots Rise in the Enterprise
Internet Researchers Discover New Hacking Service Site
FTC: Let us fine spyware operations, already!
New WinPatrol Features: Windows Update & Browser Alerts
Botnet on Demand Service
Storm Worm Updates [Oct 30]
MessageLabs Intelligence Report for October 2007
Whois studies approved, privacy deferred
AOL to let users block targeted Web ads???
Police dismantle global child porn network
Hijacking Flash banner advertisements again...
Do Search Engines Need To Be Regulated?
NOW, A WAY TO STOP ID THEFT
Russian Business Network: Cyber Criminal Haven

Wednesday, October 17, 2007

Been Slow In Forums And I've Been Busy

These last two weeks I've been very busy with a new 'old' PC that's been giving me fits still and working on a series of splog farms right here on Blogger. Stay tuned for more on this, it involves a huge amount of blogs, like over 3000, all of them connected and all pure spam.

This last week or so has been a little quiet tho, here are a couple hi-lights:

New TLD: .asia

Phishtank First Annual Report


Storm Worm Ratchets Up

This latest version is now set up to propagate by looking for address books to cultivate and spam, and also looks for files related to websites, such as .htm, .html, and .php files and inject malicious IFRAME code into them.

This is a big step for this gang and researchers say it's a step that indicates there may be sales on the code soon to come. Read More Here

Tuesday, October 02, 2007

AIM Flaw Exposed, No Fix Yet

Looks like yet another security exploit has been found in AIM. AOL admits so, but no fix in sight. Read & Disucss Here

Sunday, September 30, 2007

Weekly Roundup-Sept 30

Apologies for not blogging the last week or so. I've been involved with a 'donated' Pc for me to play with and it's been giving me fits with every turn.

Here is a round up of the some of the forum topics:
WinPatrol PLUS Data Collection

Radical Rethink Of The Net Under Way

AOL AIM Security Hole

MS Extends XP's Life For OEMs

.Net Domain Becoming Havin For Cyber Criminals

Report: Increase In Phish Attacks, New Techniques

Thursday, September 20, 2007

Spyslay: New Rogue?

Looks like this is a brand new rogue, not much via Google at all. They joined my site and left a link to it in their siggy. Guess that was a bad idea, eh?

When you go to their site you get an immediate re-direct for another known rogue install. Guess who spread the news all over the Net? This will be updated as more info is found. Read More Here

Blogger Malware Gang Update

Well today the Blogger Malware Gang(BMG) changed things up some. I got hit yesterday with a rogue anti-spyware install. But we're onto them, quick as a cobra to a mongoose. Read Details Here

Wednesday, September 19, 2007

Blogger\Blogspot Malware: Reloaded

I got two links yesterday from Chuck, of The Real Blogger Status and boy oh boy, they sure did not disappoint.

After clicking a single link, each leading to an .hk(Hong Kong) domain and sitting there a few minutes while IM'ing Chuck, things started to happen and happen fast.

First hint was Process Explorer activity. I noticed in my task tray it began to get jumpy and was figuring I'd see the same as
last time. But no, this was not the same.....this would turn out to be much worse.

The activity got so crazy I was expecting the machine to freeze up, but it didn't. It maintained a balance of activity with files loading and deleting themselves for at least 45 minutes. In that while I got Drive Cleaner installed as well as a few rootkits too.
See The Carnage Here

Wednesday, September 12, 2007

Gromozon Malaware SSL Certified?

WTF!!!!!!??

How can this happen, a notoriously famous piece of malware gets 'certified' by a popular and well known Internet certificate issuing company. Something is wrong, very wrong.

One would think that they would have this company on a blacklist of sorts yes? Read & Discuss Here

Tuesday, September 11, 2007

MS Windows Monthly Security Updates

MS has released their monthly updates for Windows OSs. One critical and 3 important.

See some details right here

MS Windows Monthly Security Updates

MS has released their monthly updates for Windows OSs. One critical and 3 important.

See some details right here