<?xml version='1.0' encoding='UTF-8'?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-804714437673009003</id><updated>2008-10-10T14:11:11.485+01:00</updated><title type='text'>Dynamoo's Blog</title><subtitle type='html'>Spam, security, scams, spin and stuff.</subtitle><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/index.htm'/><link rel='next' type='application/atom+xml' href='http://www.dynamoo.com/blog/atom.xml?start-index=26&amp;max-results=25'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.dynamoo.com/blog/atom.xml'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>200</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-8905340124920283162</id><published>2008-10-10T10:51:00.003+01:00</published><updated>2008-10-10T10:58:26.103+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Banking'/><category scheme='http://www.blogger.com/atom/ns#' term='Scams'/><title type='text'>FTC: Bank Failures, Mergers and Takeovers: A "Phish-erman's Special"</title><content type='html'>A &lt;a href="http://www.ftc.gov/bcp/edu/pubs/consumer/alerts/alt089.shtm"&gt;timely warning&lt;/a&gt; from the FTC on the threat of criminals using the worldwide financial crisis to obtain banking details.. although as &lt;a href="http://www.dynamoo.com/blog/2008/10/citigroupwachovia-security-certificates.html"&gt;seen recently&lt;/a&gt; the payload could also be a trojan rather than a phishing attempt.&lt;br /&gt;&lt;br /&gt;The FTC say:&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;If the recent changes in the financial marketplace have you confused, you’re not alone. The financial institution where you did business last week may have a new name today, and your checks and statements may come with a new look tomorrow. A new lender may have acquired your mortgage, and you could be mailing your payments to a new servicer. Procedures for the banking you do online also may have changed. According to the Federal Trade Commission (FTC), the nation’s consumer protection agency, the upheaval in the financial marketplace may spur scam artists to phish for your personal information.&lt;/blockquote&gt;They then go on to offer some &lt;a href="http://www.ftc.gov/bcp/edu/pubs/consumer/alerts/alt089.shtm"&gt;excellent tips and examples&lt;/a&gt; of what to look out for. As I said before, it's worth warning any end-users you support of this risk because it would be relatively trivial to come up with a scam that looks very convincing indeed, and including a reference to the FTC warning might get at least &lt;span style="font-style: italic;"&gt;some&lt;/span&gt; of them taking the threat seriously.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/8905340124920283162/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=8905340124920283162' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8905340124920283162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8905340124920283162'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/10/ftc-bank-failures-mergers-and-takeovers.html' title='FTC: Bank Failures, Mergers and Takeovers: A &quot;Phish-erman&apos;s Special&quot;'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-5858182087855732907</id><published>2008-10-09T22:00:00.008+01:00</published><updated>2008-10-10T14:11:11.571+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><title type='text'>securityassurance@microsoft.com - "Security Update for OS Microsoft Windows"</title><content type='html'>A malicious EXE file is doing the rounds, pretending to be an update from Microsoft and including some social engineering such as a fake PGP signature. The payload is an executable called KB960312.exe. &lt;a href="http://www.virustotal.com/analisis/54388941cc157091f8ef25a8547962a1"&gt;Detection rates are poor&lt;/a&gt;, but it's clearly some hideous piece of malware that you really don't want anywhere near your PC.&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;&lt;br /&gt;Subject:       Security Update for OS Microsoft Windows&lt;br /&gt;From:       "Microsoft Official Update Center" &lt;securityassurance@microsoft.com&gt;&lt;br /&gt;&lt;br /&gt;Dear Microsoft Customer,&lt;br /&gt;&lt;br /&gt;Please notice that Microsoft company has recently issued a Security Update for OS&lt;br /&gt;Microsoft Windows. The update applies to the following OS versions: Microsoft&lt;br /&gt;Windows 98, Microsoft Windows 2000, Microsoft Windows Millenium, Microsoft Windows&lt;br /&gt;XP, Microsoft Windows Vista.&lt;br /&gt;&lt;br /&gt;Please notice, that present update applies to high-priority updates category. In&lt;br /&gt;order to help protect your computer against security threats and performance&lt;br /&gt;problems, we strongly recommend you to install this update.&lt;br /&gt;&lt;br /&gt;Since public distribution of this Update through the official website&lt;br /&gt;http://www.microsoft.com would have result in efficient creation of a malicious&lt;br /&gt;software, we made a decision to issue an experimental private version of an update&lt;br /&gt;for all Microsoft Windows OS users.&lt;br /&gt;&lt;br /&gt;As your computer is set to receive notifications when new updates are available, you&lt;br /&gt;have received this notice.&lt;br /&gt;&lt;br /&gt;In order to start the update, please follow the step-by-step instruction:&lt;br /&gt;1. Run the file, that you have received along with this message.&lt;br /&gt;2. Carefully follow all the instructions you see on the screen.&lt;br /&gt;&lt;br /&gt;If nothing changes after you have run the file, probably in the settings of your OS&lt;br /&gt;you have an indication to run all the updates at a background routine. In that case,&lt;br /&gt;at this point the upgrade of your OS will be finished.&lt;br /&gt;&lt;br /&gt;We apologize for any inconvenience this back order may be causing you.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thank you,&lt;br /&gt;&lt;br /&gt;Steve Lipner&lt;br /&gt;Director of Security Assurance&lt;br /&gt;Microsoft Corp.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;-----BEGIN PGP SIGNATURE-----&lt;br /&gt;Version: PGP 7.1&lt;br /&gt;&lt;br /&gt;3L0SDPQYESHKTVB7P898LE266163YL9LZQ6AU3LYK9JFM85HDX4S5FG0PEUY5HXP0&lt;br /&gt;31Q8WAOREI4H0A7OF4UDTOG8HAXPAZMV91DI6B8XJEQ0636ND3XAWTCOOSNLIGHUN&lt;br /&gt;ZSDHKKLZ099I6Y03BO91DGUTQMMFT0CWMCZQ4G0R0EYMNN199IEG0PKA6CE3ZPAB6&lt;br /&gt;EJ4UN52NIIB4VF78224S7BCNFH3NP9V91T66QV0RKA2KOG0RA0EUM5VY17P41G016&lt;br /&gt;I2YU34EL9XJQGS7C5GMDU4FJUIC3M3ZIAU6==&lt;br /&gt;-----END PGP SIGNATURE-----&lt;br /&gt;&lt;br /&gt;&lt;/securityassurance@microsoft.com&gt;&lt;hr /&gt;&lt;br /&gt;&lt;br /&gt;Update: KB231660.exe has also been spotted with a different PGP signature, although &lt;span style="font-weight: bold;"&gt;securityassurance@microsoft.com&lt;/span&gt; remains the same. Also KB986008.exe, KB415282.exe, KB985274.exe, KB166277.exe  .. probably a load more will be sent out over the next few hours.&lt;br /&gt;&lt;br /&gt;Update 2: This has now been &lt;a href="http://isc.sans.org/diary.html?storyid=5159"&gt;picked up&lt;/a&gt; by the folks at the &lt;a href="http://isc.sans.org/"&gt;ISC&lt;/a&gt;.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/5858182087855732907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=5858182087855732907' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/5858182087855732907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/5858182087855732907'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/10/kb948652exe-security-update-for-os.html' title='securityassurance@microsoft.com - &quot;Security Update for OS Microsoft Windows&quot;'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-2954236010071264002</id><published>2008-10-09T17:00:00.003+01:00</published><updated>2008-10-09T17:21:37.651+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Banking'/><title type='text'>Citigroup/Wachovia "Security Certificates" trojan</title><content type='html'>These fake "security certificates" have been around for a while, but it has taken a little time for the Bad Guys to leverage the recent worldwide banking crisis. Expect to see a LOT more of these as more banks struggle or are taken over.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;WACHOVIA CORPORATION NOTICE.&lt;br /&gt;&lt;br /&gt;Citigroup announced a buyout of Wachovia brokered by the FDIC moments ago.&lt;br /&gt;All Wachovia bank locations will be in the Citigroup merger to prevent failure of Wachovia.&lt;br /&gt;The Citigroup/Wachovia would focus on upgrading banks' security certificates.&lt;br /&gt;All Wachovia customers must fill the forms and complete installation of new Citigroup Standard digital signatures during 48 hours.&lt;br /&gt;Please follow the installation steps below:&lt;br /&gt;&lt;br /&gt;Read more here&gt;&gt;&lt;br /&gt;&lt;br /&gt;Sincerely, Sophie Burkett.&lt;br /&gt;2008 Wachovia Corporation.&lt;br /&gt;All rights reserved.&lt;/blockquote&gt;&lt;br /&gt;The link goes to the insanely named domain commercial [dot] wachovia [dot] online [dot] financial [dot] service [dot] onlineupdate.iawyvy9gcv.bankonline.doexte.gbiexsse.com which is hosted on a fast-flux botnet. The target executable is &lt;span style="font-weight: bold;"&gt;InstallationPackWachovia.exe&lt;/span&gt; located in the root directory which triggers just a few heuristic scanners or generic detections &lt;a href="http://www.virustotal.com/analisis/9e462443c1b28bb7577536490b1d3dbe"&gt;according to VirusTotal&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/wachovia-792612.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.dynamoo.com/blog/uploaded_images/wachovia-792608.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;If you work in IT in any kind of organisation, it is worth sending out a warning to end users to ensure that they are aware of these emails, either at work or at home. The current batch are not particularly credible, but the Bad Guys will probably keep working on their social engineering skills.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/2954236010071264002/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=2954236010071264002' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/2954236010071264002'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/2954236010071264002'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/10/citigroupwachovia-security-certificates.html' title='Citigroup/Wachovia &quot;Security Certificates&quot; trojan'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-5562018565873908980</id><published>2008-10-09T13:08:00.003+01:00</published><updated>2008-10-09T13:32:58.165+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Money Mule'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Scams'/><title type='text'>Fake "VM-Soft" job offer</title><content type='html'>&lt;a href="http://www.vm-soft.com.ua/home_en.htm"&gt;VM-SOFT&lt;/a&gt;  (&lt;span style="font-weight: bold;"&gt;www.vm-soft.com.ua&lt;/span&gt;) is a wholly legitimate Ukranian software developer, whose corporate identity is being used by a third party to perpetrate an apparent &lt;a href="http://www.dynamoo.com/blog/labels/Money%20Mule.html"&gt;Money Mule&lt;/a&gt; scam, in an approach almost identical to this &lt;a href="http://www.dynamoo.com/blog/2008/07/infopulse-ukraine-ltd-money-mule-scam.html"&gt;earlier fake&lt;/a&gt; email for another Ukranian company.&lt;br /&gt;&lt;br /&gt;The email copies the name of the director, Viktor Marchenko, and even uses a very similar Gmail address (see the &lt;a href="http://www.vm-soft.com.ua/contacts_en.htm"&gt;genuine contact page&lt;/a&gt; for the real one).&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;span style="font-style: italic;"&gt; Hello Sir/Madam.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;I Viktor Marchenko,  I introduce VM-Soft specializes  in innovative IT solutions and&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;complex software projects development.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;My company based in Ukraine. We've earned ourselves a reputation of a reliable and&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;trustworthy partner working successfully with a number of West European companies&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;and providing them with reliable software development services in financial and&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;media sectors. Unfortunately we are currently facing some difficulties with&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;receiving payments for our services. It usually takes us 10-30 days to receive a&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;payment and clearing from your country and such delays are harmful to our business.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;We do not have so much time to accept every wire transfer.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;That's why we are  currently looking for partners in your country to help us accept&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;and process these payments faster. If you are looking for a chance to make an&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;additional profit you can become our representative in your country. As our&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;representative you will receive 8% of every deal we conduct. Your job will be&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;accepting funds in the form of wire transfers and forwarding them to us. It is not a&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;full-time job, but rather a very convenient and fast way to  receive additional&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;income. We also consider opening an office in your country in the nearest future and&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;you will then have certain privileges should you decide to apply for a full-time&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;job. Please if you are interested in transacting business with us we will be very&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;glad.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Please contact me for more information via email: offer.job.vmsoft.ua@gmail.com&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;and send us the following information about yourself:&lt;/span&gt;&lt;br /&gt;   &lt;br /&gt;&lt;span style="font-style: italic;"&gt;            Your Full Name as it appears on your resume.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;                Education.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;                Your Contact Address.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;                Telephone/Fax number.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;        Your present Occupation and Position  currently held.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;        Your Age&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Please respond and we will provide you with additional details on how you can become&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;our representative. Joining us and starting business today will cost you nothing and&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; you will be able to earn a bit of extra money fast and easy. Should you have any&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;questions, please feel free to contact us with all your questions.&lt;/span&gt;&lt;br /&gt;   &lt;br /&gt;&lt;span style="font-style: italic;"&gt;Sincerely,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Viktor Marchenko  ,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;VM-Soft&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;If you're not familiar with this type of scam, then basically it amounts to laundering stolen money.&lt;br /&gt;&lt;br /&gt;One important tip usually is that legitimate companies tend not to use free email addresses, but in this case the genuine VM-SOFT does, instead of using its own vm-soft.com.ua domain which is not so helpful.&lt;br /&gt;&lt;br /&gt;Increasingly, the scammers use names of genuine companies and even genuine directors. They may register domain names that look confusingly similar to the real thing, so sometimes the only concrete thing that you have to go on is common sense: if it looks too good to be true, then it probably &lt;span style="font-style: italic;"&gt;isn't&lt;/span&gt; true.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/5562018565873908980/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=5562018565873908980' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/5562018565873908980'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/5562018565873908980'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/10/fake-vm-soft-job-offer.html' title='Fake &quot;VM-Soft&quot; job offer'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-6698704460359616803</id><published>2008-10-09T09:22:00.003+01:00</published><updated>2008-10-09T09:50:21.438+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Dating Scams'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Scams'/><title type='text'>Dating scams, onlineflh.com and 79.135.167.*</title><content type='html'>I have covered this particular group of &lt;a href="http://www.dynamoo.com/blog/2008/09/dating-scams.html"&gt;dating scam sites before&lt;/a&gt;, but this time there's a slight shift in the way that it works. In this case, the parenthesis-laded email looks something like:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt; hey^) how are you?) do you have  a girlfriend?)... i have not boyfriend((  I very&lt;br /&gt;want to meet real men...which will know woman's need ...like in a cinema ... you&lt;br /&gt;know))))lets chat!) i am pretty girl)) I have a lot of time for meetings and if you&lt;br /&gt;have any ideas how to spend it with me... just email me back at&lt;br /&gt;CAROLINE@onlineflh.com and i will reply back with some nice ;) photos with me&lt;br /&gt;...and maybe, you will want to write me again))) CAROLINE@onlineflh.com &lt;/blockquote&gt;&lt;br /&gt;Perhaps "Caroline" is trying to data a &lt;a href="http://en.wikiquote.org/wiki/Lisp_programming_language#Parentheses"&gt;LISP programmer&lt;/a&gt;? There's no website for onlineflh.com, but mail is handled by 79.135.167.51 which is &lt;a href="http://www.dynamoo.com/blog/2008/09/dating-scams.html"&gt;the same as before&lt;/a&gt;.. although now the only two websites on that server are Ammae.com and Amnocx.com.&lt;br /&gt;&lt;br /&gt;In these circumstances, a tool like Robtex can be useful. It turns out that 79.135.167.51 is a infrastructure server for a &lt;a href="http://www.robtex.com/ip/79.135.167.51.html"&gt;number of domains&lt;/a&gt;. The IP address noted as belonging to a &lt;a href="http://www.spamhaus.org/Rokso/"&gt;ROKSO &lt;/a&gt;listed spammer, most likely some affiliate of the Russian Business Network (RBN).&lt;br /&gt;&lt;br /&gt;Supported domains are:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;alllam.com&lt;/li&gt;&lt;li&gt;cardrealc.com&lt;/li&gt;&lt;li&gt;ezshl.com&lt;/li&gt;&lt;li&gt;famplayfit.cn&lt;/li&gt;&lt;li&gt;firstlam.com&lt;/li&gt;&lt;li&gt;flasheon.com&lt;/li&gt;&lt;li&gt;gosfordw.com&lt;/li&gt;&lt;li&gt;llcam.com&lt;/li&gt;&lt;li&gt;morerd.com&lt;/li&gt;&lt;li&gt;onlineflh.com&lt;/li&gt;&lt;li&gt;onlineshl.com&lt;/li&gt;&lt;li&gt;planetflh.com&lt;/li&gt;&lt;li&gt;rdplanet.com&lt;/li&gt;&lt;li&gt;towadapointhalf.cn&lt;/li&gt;&lt;li&gt;virtuellmal.com&lt;/li&gt;&lt;/ul&gt;The whole 79.135.167.* block is a complete sewer of fake antivirus, dating, medication and codec sites. The netblock is registered to "TTNet Autonomous System Turk Telekom A S Aydinlikevler ANKARA 06103 TURKEY", but most likely under the control of the RBN. There's an interesting writeup about this netblock &lt;a href="http://securehomenetwork.blogspot.com/2008/08/rbn-operatives-who-attacked-georgia.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://www.spamhaus.org/drop/"&gt;Spamhaus DROP&lt;/a&gt; list goes further and lists the entire 79.135.160.0/19 block (79.135.160.0 - 79.135.191.255) as being rogue. That's probably overkill as there do seem to be some legitimate (mostly Turkish) websites hosted in that range.&lt;br /&gt;&lt;br /&gt;These were more fun when they had a picture of a &lt;a href="http://www.dynamoo.com/blog/2008/02/another-dating-scam.html"&gt;pretty girl attached&lt;/a&gt;.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/6698704460359616803/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=6698704460359616803' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/6698704460359616803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/6698704460359616803'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/10/dating-scams-onlineflhcom-and-79135167.html' title='Dating scams, onlineflh.com and 79.135.167.*'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-5563772949360741814</id><published>2008-10-06T10:26:00.004+01:00</published><updated>2008-10-06T10:51:51.796+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Asprox'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>Asprox: deryv.ru still active</title><content type='html'>The Asprox botnet is still active but has been remarkable stable with no new domains in the past week, and 88% of the traffic going to &lt;span style="font-weight: bold;"&gt;deryv.ru&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;ctiry.ru (3%)&lt;/li&gt;&lt;li&gt;deryv.ru (88%)&lt;/li&gt;&lt;li&gt;mentoe.ru (4%)&lt;/li&gt;&lt;li&gt;mheop.ru (3%)&lt;/li&gt;&lt;li&gt;pormce.ru (2%)&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Consistently, the malware code is encrypted with &lt;span style="font-weight: bold;"&gt;eval(function(p,a,c,k,e,d) &lt;/span&gt;presumably to avoid detection by anti-virus software. So, if you only check your logs for / block ONE Asprox domain, then deryv.ru seems to be the one to look at.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/5563772949360741814/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=5563772949360741814' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/5563772949360741814'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/5563772949360741814'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/10/asprox-deryvru-still-active.html' title='Asprox: deryv.ru still active'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-8644524180323918219</id><published>2008-09-29T17:33:00.003+01:00</published><updated>2008-09-29T17:36:00.313+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Phones'/><title type='text'>Nokia's first touchscreen phone....?</title><content type='html'>There are plenty of rumours that Nokia will announce their "first" touchscreen phone sometime this week.. except that it &lt;span style="font-style: italic;"&gt;won't&lt;/span&gt; be their first touchscreen phone. Here's a look at &lt;a href="http://www.mobilegazette.com/nokia-first-touchscreen-08x09x29.htm"&gt;previous Nokia touchscreen&lt;/a&gt; devices which have mostly been forgotten.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/8644524180323918219/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=8644524180323918219' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8644524180323918219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8644524180323918219'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/nokias-first-touchscreen-phone.html' title='Nokia&apos;s first touchscreen phone....?'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-1367509693951819759</id><published>2008-09-29T17:21:00.001+01:00</published><updated>2008-09-29T17:28:57.069+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Asprox'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>Asprox: ctiry.ru, deryv.ru, mentoe.ru, mheop.ru, pormce.ru and xenbv.ru</title><content type='html'>Another bunch of Asprox domains that have been active over the past few days are listed below. As usual, block these or check your logs for activity.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;ctiry.ru&lt;/li&gt;&lt;li&gt;deryv.ru&lt;/li&gt;&lt;li&gt;mentoe.ru&lt;/li&gt;&lt;li&gt;mheop.ru&lt;/li&gt;&lt;li&gt;pormce.ru&lt;/li&gt;&lt;li&gt;xenbv.ru&lt;/li&gt;&lt;/ul&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/1367509693951819759/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=1367509693951819759' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/1367509693951819759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/1367509693951819759'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/asprox-ctiryru-deryvru-mentoeru-mheopru.html' title='Asprox: ctiry.ru, deryv.ru, mentoe.ru, mheop.ru, pormce.ru and xenbv.ru'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-286249958925568465</id><published>2008-09-25T09:58:00.002+01:00</published><updated>2008-09-25T10:21:43.560+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Asprox'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>Asprox: "eval(function(p,a,c,k,e,r)"</title><content type='html'>There has been a slight shift in tactics by the Asprox gang in their SQL Injection Attacks in that they are now using a packer on their javascript. This doesn't seem to be for obfuscation reasons, as the script is relatively easy to decode. Presumably it's a way to get around virus and link scanners. (Click the image below for an example)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/asprox-707302.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://www.dynamoo.com/blog/uploaded_images/asprox-707297.png" alt="" border="0" /&gt;&lt;/a&gt;You can decode it easily enough by adding &lt;span style="font-weight: bold;"&gt;eval=alert;&lt;/span&gt; to the start of the script (follow the instructions &lt;a href="http://my.opera.com/hallvors/blog/2007/09/21/function-p-a-c-k-e-r-de-mystify-trick"&gt;here&lt;/a&gt;), but &lt;span style="font-weight: bold;"&gt;never&lt;/span&gt; mess around with malware scripts on a vulnerable production system because it is very easy to get infected.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;mnicbre.ru&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;vtg43.ru&lt;/span&gt; seem to be two active domains, although perhaps check for all the ones on &lt;a href="http://www.dynamoo.com/blog/2008/09/asprox-mnbenioru.html"&gt;this list&lt;/a&gt; to be safe.&lt;br /&gt;&lt;br /&gt;Packing tools &lt;span style="font-style: italic;"&gt;are&lt;/span&gt; an easy way to avoid detection.. at least temporarily. But given the prevalence&lt;br /&gt; of Javascript-based malware and the ever-increasing availability of bandwidth, Javascript packing is becoming an increasingly bad practice. There have been a couple of high-profile cases where a packing tool has effectively been blacklisted by anti-virus products (&lt;a href="http://www.dynamoo.com/blog/2007/12/jssnza-likely-false-positive-in-etrust.html"&gt;here&lt;/a&gt; and &lt;a href="http://www.dynamoo.com/blog/2008/01/jsexploit-bo-false-positive-in-mcafee.html"&gt;here&lt;/a&gt;), so perhaps if you use Javascript extensive &lt;span style="font-style: italic;"&gt;and&lt;/span&gt; use a packing tool you might want to reconsider how you deploy Javascript on your site.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/286249958925568465/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=286249958925568465' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/286249958925568465'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/286249958925568465'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/asprox-evalfunctionpacker.html' title='Asprox: &quot;eval(function(p,a,c,k,e,r)&quot;'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-5586044982460166776</id><published>2008-09-24T10:27:00.002+01:00</published><updated>2008-09-24T11:07:27.562+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PDFs'/><category scheme='http://www.blogger.com/atom/ns#' term='Asprox'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>Asprox: h3x.info</title><content type='html'>Briefly popping up on the Asprox SQL Injection radar yesterday was h3x.info, specifically a call to &lt;span style="font-weight: bold;"&gt;h3x.info/index.php&lt;/span&gt;  [dangerous site, do not visit].&lt;br /&gt;&lt;br /&gt;h3x.info doesn't fit the normal pattern, perhaps it has been rotated in as a test. What's certain is that this &lt;span style="font-style: italic;"&gt;is&lt;/span&gt; a malware distribution site.. and a pretty scary one at that.&lt;br /&gt;&lt;br /&gt;Let's look at the domain details first of all. As you might expect, they're mostly bogus:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Domain ID&lt;br /&gt;    D23859712-LRMS&lt;br /&gt;Domain Name&lt;br /&gt;    H3X.INFO&lt;br /&gt;Created On&lt;br /&gt;    19-Feb-2008 22:04:56 UTC&lt;br /&gt;Last Updated On&lt;br /&gt;    27-Aug-2008 12:38:06 UTC&lt;br /&gt;Expiration Date&lt;br /&gt;    19-Feb-2009 22:04:56 UTC&lt;br /&gt;Sponsoring Registrar&lt;br /&gt;    Registrar Company, INC (R315-LRMS)&lt;br /&gt;Status&lt;br /&gt;    OK&lt;br /&gt;Registrant ID&lt;br /&gt;     DI_7764637&lt;br /&gt;Registrant Name&lt;br /&gt;    Alex&lt;br /&gt;Registrant Organization&lt;br /&gt;    Vteam&lt;br /&gt;Registrant Street1&lt;br /&gt;    vol. str. 221-122, 12&lt;br /&gt;Registrant Street2&lt;br /&gt;  &lt;br /&gt;Registrant Street3&lt;br /&gt;  &lt;br /&gt;Registrant City&lt;br /&gt;    Novie&lt;br /&gt;Registrant State/Province&lt;br /&gt;    Aveiro&lt;br /&gt;Registrant Postal Code&lt;br /&gt;    19923&lt;br /&gt;Registrant Country&lt;br /&gt;    PT&lt;br /&gt;Registrant Phone&lt;br /&gt;    +12.56231321&lt;br /&gt;Registrant Phone Ext.&lt;br /&gt;  &lt;br /&gt;Registrant FAX&lt;br /&gt;  &lt;br /&gt;Registrant FAX Ext.&lt;br /&gt;  &lt;br /&gt;Registrant Email&lt;br /&gt;    cy@bk.ru&lt;br /&gt;&lt;br /&gt;[..snip..]&lt;br /&gt;&lt;br /&gt;Name Server&lt;br /&gt;    ns1.mbhost.ru&lt;br /&gt;Name Server&lt;br /&gt;    ns2.mbhost.ru&lt;/blockquote&gt;The domain itself is on          &lt;span style="font-weight: bold;"&gt;80.90.114.13&lt;/span&gt; which appears to be a general purpose server belonging to Smartlogic Ltd in Moscow. There's no evidence to connect Smartlogic to this site, other than it belongs to a customer.. overall they seem to be a pretty clean outfit.&lt;br /&gt;&lt;br /&gt;Visiting the top level of the h3x.info site (or the index.php page) reveals a very impressive bit of obfuscated scripting (a copy is here - &lt;a href="http://www.dynamoo.com/blog/h3x-info.zip"&gt;h3x-info.zip&lt;/a&gt; - ZIP password is &lt;span style="font-weight: bold;"&gt;virus&lt;/span&gt;).  There are some recognisable references to Outlook Express, Snapshot (probably &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-041.mspx"&gt;MS08-041&lt;/a&gt;), Apple QuickTime (&lt;a href="http://secunia.com/advisories/product/5090/?task=advisories"&gt;take your pick&lt;/a&gt;),  plus an infected PDF (from hxxp:||h3x.info|cache|doc.pdf) variously identified as Exploit.HTML.Agent.AO [BitDefender] and Mal/JSShell-B [Sophos] (full VirusTotal report &lt;a href="http://www.virustotal.com/analisis/7ed7d31f470aa023616ea7602d2c4996"&gt;here&lt;/a&gt;) but otherwise detection rates are very poor.&lt;br /&gt;&lt;br /&gt;Looking at the WHOIS history, it's quite possible that the h3x.info domain has been hijacked, so perhaps it will be cleaned up in the future. At the moment it does seem to be an interesting repository of malware if you're a researcher.&lt;br /&gt;&lt;br /&gt;It was only active for a short while at about 1000 UTC (1100 BST, 1200 CET) on 23rd September before reverting to the &lt;a href="http://www.dynamoo.com/blog/2008/09/asprox-mnicbreru-pkseioru-and-vtg43ru.html"&gt;same .ru domains&lt;/a&gt; that have been active for a few days.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.dynamoo.com/blog/h3x-info.zip"&gt;&lt;br /&gt;&lt;/a&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/5586044982460166776/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=5586044982460166776' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/5586044982460166776'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/5586044982460166776'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/asprox-h3xinfo.html' title='Asprox: h3x.info'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-5720186787534688117</id><published>2008-09-23T22:07:00.003+01:00</published><updated>2008-09-23T22:14:22.205+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Android'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='Phones'/><title type='text'>T-Mobile G1</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.mobilegazette.com/handsets/t-mobile/t-mobile-g1/t-mobile-g1-open-2.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px;" src="http://www.mobilegazette.com/handsets/t-mobile/t-mobile-g1/t-mobile-g1-open-2.jpg" alt="" border="0" /&gt;&lt;/a&gt;It's kind of hard to tell if the &lt;a href="http://www.mobilegazette.com/t-mobile-g1-08x09x23.htm"&gt;T-Mobile G1&lt;/a&gt; is the next big thing or just some sort of damp squib. It may not look as impressive as the iPhone on the top, but underneath the G1's &lt;a href="http://en.wikipedia.org/wiki/Android_OS"&gt;Android&lt;/a&gt; operating system looks promising.&lt;br /&gt;&lt;br /&gt;Oddly enough, it got me thinking about how I use my own phone.. and I tend to use web access more than anything else, but make only a couple of phone calls on it a week, sometimes I will listed to music or snap a photograph. I think I tried video calling &lt;span style="font-style: italic;"&gt;once&lt;/span&gt;. So perhaps this G1 thingie is actually more in line with what a lot of sad geeky people like me actually &lt;span style="font-style: italic;"&gt;want.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Anyway, this comes out in October in the US, November in the UK and early next year for other T-Mobile customers. Some more pictures are &lt;a href="http://www.mobilegazette.com/t-mobile-g1-gallery.htm"&gt;here&lt;/a&gt;. &lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/5720186787534688117/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=5720186787534688117' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/5720186787534688117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/5720186787534688117'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/t-mobile-g1.html' title='T-Mobile G1'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-400423587090595068</id><published>2008-09-18T09:09:00.002+01:00</published><updated>2008-09-18T09:14:37.654+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Asprox'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>Asprox: mnbenio.ru</title><content type='html'>&lt;span style="font-weight: bold;"&gt;mnbenio.ru&lt;/span&gt; is a new Asprox SQL injection domain that has been active in the past 24 hours, the following four domains are the most active:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li style="font-weight: bold;"&gt;mnbenio.ru&lt;/li&gt;&lt;li&gt;mnicbre.ru&lt;/li&gt;&lt;li&gt;pkseio.ru&lt;/li&gt;&lt;li&gt;vtg43.ru&lt;/li&gt;&lt;/ul&gt;It does seem that the SQL injection attacks are becoming less widespread, probably partly because SQL servers are being hardened, but some vulnerable SQL servers have remained untouched by the latest round of attacks. Possibly the SQL injection gangs are concentrating on bigger fish? Like the recent &lt;a href="http://www.sophos.com/blogs/gc/g/2008/09/15/hackers-infect-businessweek-website-via-sql-injection-attack/"&gt;attack on BusinessWeek.com&lt;/a&gt; perhaps?</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/400423587090595068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=400423587090595068' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/400423587090595068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/400423587090595068'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/asprox-mnbenioru.html' title='Asprox: mnbenio.ru'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-4378828837455325340</id><published>2008-09-17T09:25:00.002+01:00</published><updated>2008-09-17T09:44:41.594+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Asprox'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>Asprox: mnicbre.ru, pkseio.ru and vtg43.ru</title><content type='html'>The domains used in the Asprox SQL Injection attacks have been stable for a few days now, but yesterday some new .ru domains appeared: mnicbre.ru, pkseio.ru and vtg43.ru. The domains are registered through NAUNET again with the following registation details:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;domain:     MNICBRE.RU&lt;br /&gt;type:       CORPORATE&lt;br /&gt;nserver:    ns2.mnicbre.ru. 75.181.3.122&lt;br /&gt;nserver:    ns3.mnicbre.ru. 68.197.137.239&lt;br /&gt;nserver:    ns1.mnicbre.ru. 76.240.151.177&lt;br /&gt;state:      REGISTERED, DELEGATED&lt;br /&gt;person:     Private Person&lt;br /&gt;phone:      +7 772 7727091&lt;br /&gt;fax-no:     +7 772 7727091&lt;br /&gt;e-mail:     retyi1111@yahoo.com&lt;br /&gt;registrar:  NAUNET-REG-RIPN&lt;br /&gt;created:    2008.09.16&lt;br /&gt;paid-till:  2009.09.16&lt;br /&gt;source:     TC-RIPN&lt;/blockquote&gt;The following domains have been active over the past 24 hours. Block these or check your logs for them (new ones are in bold):&lt;br /&gt;&lt;ul&gt;&lt;li&gt;22net.ru&lt;/li&gt;&lt;li&gt;64asp.ru&lt;/li&gt;&lt;li&gt;92prt.ru&lt;/li&gt;&lt;li&gt;acr34.ru&lt;/li&gt;&lt;li&gt;asl39.ru&lt;/li&gt;&lt;li&gt;fst9.ru&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;mnicbre.ru&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;pkseio.ru&lt;/li&gt;&lt;li&gt;sel92.ru&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;vtg43.ru&lt;/li&gt;&lt;/ul&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/4378828837455325340/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=4378828837455325340' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/4378828837455325340'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/4378828837455325340'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/asprox-mnicbreru-pkseioru-and-vtg43ru.html' title='Asprox: mnicbre.ru, pkseio.ru and vtg43.ru'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-1543970242916451826</id><published>2008-09-13T15:43:00.002+01:00</published><updated>2008-09-13T16:13:39.940+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Comedy'/><title type='text'>Doug Stanhope</title><content type='html'>I first stumbled across US stand-up comic &lt;a href="http://www.dougstanhope.com/"&gt;Doug Stanhope&lt;/a&gt; [link probably &lt;a href="http://en.wiktionary.org/wiki/NSFW"&gt;NSFW&lt;/a&gt;] some years ago and was in equal parts horrified and amused by his work. By chance, I found out that he was in the UK (at the &lt;a href="http://www.leicestersquaretheatre.com/"&gt;Leicester Square Theatre&lt;/a&gt;) so Mrs Dynamoo and myself booked some tickets to go and see him live.&lt;br /&gt;&lt;br /&gt;You have to understand that Stanhope is pretty much the definition of "edgy". He seems to have no taboos and no fear.. as long as he's had some beer. Understand that some of his topics include suicide, gynaecology, death, drug abuse, overpopulation, abortion and Sarah Palin.  Sometimes &lt;a href="http://www.savingbristol.com/"&gt;combined&lt;/a&gt; (don't click if you are offended by.. well, offensive stuff).&lt;br /&gt;&lt;br /&gt;Even people who aren't easily offended are likely to be offended by &lt;span style="font-style: italic;"&gt;something&lt;/span&gt; he will say. But on the other hand, perhaps some of those observations on the human condition are more profound than you would think.&lt;br /&gt;&lt;br /&gt;So, Stanhope was on form and really, really funny. And yes.. there were several times when I thought "no.. he can't be saying that!".  I could go into details, but if you like this kind of thing then it would spoil the surprise... I think it's the first time I've ever had to watch a gig like this from between my fingers.&lt;br /&gt;&lt;br /&gt;Anyway, Stanhope is in London and Manchester for most of September, and then back in the US doing a tour for October and November (itinerary &lt;a href="http://www.dougstanhope.com/html/road-dates.php"&gt;here&lt;/a&gt;).  Or you could purvey yourself one of his fine DVDs on Amazon.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/1543970242916451826/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=1543970242916451826' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/1543970242916451826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/1543970242916451826'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/doug-stanhope.html' title='Doug Stanhope'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-3272508739016015877</id><published>2008-09-11T10:20:00.002+01:00</published><updated>2008-09-11T10:36:02.279+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Dating Scams'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Scams'/><title type='text'>Dating scams</title><content type='html'>Dating scams are usually a variant of the advanced fee fraud - some pretty girl (probably some ugly bloke in reality)  sends you some random photos and explains that they want to move to your country and move in with you.. but can they have some money first? The basic operation of these scams is described &lt;a href="http://www.hoax-slayer.com/internet-dating-scams.shtml"&gt;here&lt;/a&gt;.  To make it look more credible, sometimes fake dating sites are set up to give the whole thing an air of legitimacy.&lt;br /&gt;&lt;br /&gt;This current batch of fake sites is being advertised with an email similar to the following:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;i need you&lt;br /&gt;&lt;br /&gt;i am Nice Girl good looking girl who is looking to chat with you.&lt;br /&gt;e-mail me back at UcWkS@lam2you.com&lt;br /&gt;&lt;br /&gt;i will reply back with some really nice pictures.&lt;/blockquote&gt;&lt;br /&gt;The domain lam2you.com has a corresponding web site on 79.135.167.51 calling itself "Online sexiest dating site".  As it happens, there are a whole bunch of other domains on the same server, also describing themselves as "Online sexiest dating site", all best avoided.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Amnocx.com&lt;/li&gt;&lt;li&gt;Anandaperumal.com&lt;/li&gt;&lt;li&gt;Bardline.com&lt;/li&gt;&lt;li&gt;Benrd.com&lt;/li&gt;&lt;li&gt;Bestdre.info&lt;/li&gt;&lt;li&gt;Cardrealc.com&lt;/li&gt;&lt;li&gt;Centralrd.com&lt;/li&gt;&lt;li&gt;Cowarddean.com&lt;/li&gt;&lt;li&gt;Direktmal.com&lt;/li&gt;&lt;li&gt;Dracingsite.info&lt;/li&gt;&lt;li&gt;Dracingworld.info&lt;/li&gt;&lt;li&gt;Draic.info&lt;/li&gt;&lt;li&gt;Dreguide.info&lt;/li&gt;&lt;li&gt;Drkin.info&lt;/li&gt;&lt;li&gt;Drmarksite.info&lt;/li&gt;&lt;li&gt;Drmarkworld.info&lt;/li&gt;&lt;li&gt;Drseusssite.info&lt;/li&gt;&lt;li&gt;Equipyard.com&lt;/li&gt;&lt;li&gt;Evram.info&lt;/li&gt;&lt;li&gt;Ezelive.info&lt;/li&gt;&lt;li&gt;Ezrdhome.com&lt;/li&gt;&lt;li&gt;Firstlam.com&lt;/li&gt;&lt;li&gt;Fordhx.com&lt;/li&gt;&lt;li&gt;Frcis.info&lt;/li&gt;&lt;li&gt;Freegbl.info&lt;/li&gt;&lt;li&gt;Freeksite.info&lt;/li&gt;&lt;li&gt;Freeldp.info&lt;/li&gt;&lt;li&gt;Friguide.info&lt;/li&gt;&lt;li&gt;Frutis-basket.info&lt;/li&gt;&lt;li&gt;Gardevin.com&lt;/li&gt;&lt;li&gt;Gbbed.info&lt;/li&gt;&lt;li&gt;Gbizc.info&lt;/li&gt;&lt;li&gt;Gbladx.info&lt;/li&gt;&lt;li&gt;Gblhome.info&lt;/li&gt;&lt;li&gt;Gblwizard.info&lt;/li&gt;&lt;li&gt;Gbowrxx.info&lt;/li&gt;&lt;li&gt;Glocentral.info&lt;/li&gt;&lt;li&gt;Gloplanet.info&lt;/li&gt;&lt;li&gt;Gobobrom.com&lt;/li&gt;&lt;li&gt;Gocarthq.com&lt;/li&gt;&lt;li&gt;Gocartutah.com&lt;/li&gt;&lt;li&gt;Goldpug.info&lt;/li&gt;&lt;li&gt;Gosfordw.com&lt;/li&gt;&lt;li&gt;Greatrom.com&lt;/li&gt;&lt;li&gt;Guyvr.info&lt;/li&gt;&lt;li&gt;Hardjam.com&lt;/li&gt;&lt;li&gt;Hote2youx.info&lt;/li&gt;&lt;li&gt;Hyperlam.com&lt;/li&gt;&lt;li&gt;Imalonline.com&lt;/li&gt;&lt;li&gt;Justgbl.info&lt;/li&gt;&lt;li&gt;Justrd.com&lt;/li&gt;&lt;li&gt;Justvre.info&lt;/li&gt;&lt;li&gt;Ldphome.info&lt;/li&gt;&lt;li&gt;Ldpwizard.info&lt;/li&gt;&lt;li&gt;Lesdv.com&lt;/li&gt;&lt;li&gt;Lesjr.com&lt;/li&gt;&lt;li&gt;Letsgocart.com&lt;/li&gt;&lt;li&gt;Lgbidxx.info&lt;/li&gt;&lt;li&gt;Maldirekt.com&lt;/li&gt;&lt;li&gt;Malkostenlos.com&lt;/li&gt;&lt;li&gt;Malplatz.com&lt;/li&gt;&lt;li&gt;Malprojekt.com&lt;/li&gt;&lt;li&gt;Malwelt.com&lt;/li&gt;&lt;li&gt;Malzentrale.com&lt;/li&gt;&lt;li&gt;Mediagocart.com&lt;/li&gt;&lt;li&gt;Medmallist.com&lt;/li&gt;&lt;li&gt;Meinmal.com&lt;/li&gt;&lt;li&gt;Menziesmalvern.com&lt;/li&gt;&lt;li&gt;Moonboardm.com&lt;/li&gt;&lt;li&gt;Morerd.com&lt;/li&gt;&lt;li&gt;Mygbl.info&lt;/li&gt;&lt;li&gt;Nitgbx.info&lt;/li&gt;&lt;li&gt;Nvromx.info&lt;/li&gt;&lt;li&gt;Officialgbl.info&lt;/li&gt;&lt;li&gt;Officialldp.info&lt;/li&gt;&lt;li&gt;Officialrd.com&lt;/li&gt;&lt;li&gt;Oldpee.info&lt;/li&gt;&lt;li&gt;Onlinegbl.info&lt;/li&gt;&lt;li&gt;Ovrom.info&lt;/li&gt;&lt;li&gt;Pacanimal.com&lt;/li&gt;&lt;li&gt;Phillymedicalmal.com&lt;/li&gt;&lt;li&gt;Qualitaetmal.com&lt;/li&gt;&lt;li&gt;Razales.com&lt;/li&gt;&lt;li&gt;Rd2you.com&lt;/li&gt;&lt;li&gt;Rdnation.com&lt;/li&gt;&lt;li&gt;Rdplanet.com&lt;/li&gt;&lt;li&gt;Saravanaperumal.com&lt;/li&gt;&lt;li&gt;Searchesrom.com&lt;/li&gt;&lt;li&gt;Shemalglobal.com&lt;/li&gt;&lt;li&gt;Supergbl.info&lt;/li&gt;&lt;li&gt;Superldp.info&lt;/li&gt;&lt;li&gt;Superrd.com&lt;/li&gt;&lt;li&gt;Superromics.com&lt;/li&gt;&lt;li&gt;Tomalonline.com&lt;/li&gt;&lt;li&gt;Topeguidex.info&lt;/li&gt;&lt;li&gt;Virtualgbl.info&lt;/li&gt;&lt;li&gt;Virtualglo.info&lt;/li&gt;&lt;li&gt;Virtualldp.info&lt;/li&gt;&lt;li&gt;Virtuellmal.com&lt;/li&gt;&lt;li&gt;Vrehome.info&lt;/li&gt;&lt;li&gt;Warmalonline.com&lt;/li&gt;&lt;li&gt;Wildpin.info&lt;/li&gt;&lt;li&gt;Wirelesamerica.com&lt;/li&gt;&lt;li&gt;Wizardrd.com&lt;/li&gt;&lt;li&gt;Worldpivot.info&lt;/li&gt;&lt;li&gt;Worldplayservices.info&lt;/li&gt;&lt;li&gt;Yourfr.info&lt;/li&gt;&lt;li&gt;Yourgbl.info&lt;/li&gt;&lt;li&gt;Yourldp.info&lt;/li&gt;&lt;li&gt;Capvr.info&lt;/li&gt;&lt;li&gt;Davidre.info&lt;/li&gt;&lt;li&gt;Virtualvre.info&lt;/li&gt;&lt;li&gt;Vreproject.info&lt;/li&gt;&lt;li&gt;Vrewizard.info&lt;/li&gt;&lt;/ul&gt;One thing of note is that the name servers used here are ns1.droreal.com and ns2.droreal.com which &lt;a href="http://www.google.com/search?num=100&amp;amp;hl=en&amp;amp;c2coff=1&amp;amp;q=DROREAL.%2BCOM+spam&amp;amp;btnG=Search&amp;amp;meta="&gt;appears to be&lt;/a&gt; a domain name used to support other dating scam sites.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/3272508739016015877/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=3272508739016015877' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/3272508739016015877'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/3272508739016015877'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/dating-scams.html' title='Dating scams'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-8072143821174687910</id><published>2008-09-11T09:14:00.003+01:00</published><updated>2008-09-11T09:18:41.187+01:00</updated><title type='text'>Asprox: 22net.ru, 4net9.ru, 64asp.ru, 92prt.ru and fst9.ru</title><content type='html'>These are the domains active in the Asprox SQL Injection attack in the past 24 hours, new ones are in bold. Block these and/or check your logs for them.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li style="font-weight: bold;"&gt;22net.ru&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;4net9.ru&lt;/li&gt;&lt;li&gt;51com.ru&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;64asp.ru&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;92prt.ru&lt;/li&gt;&lt;li&gt;acr34.ru&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;fst9.ru&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;sel92.ru&lt;/li&gt;&lt;/ul&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/8072143821174687910/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=8072143821174687910' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8072143821174687910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8072143821174687910'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/asprox-22netru-4net9ru-64aspru-92prtru.html' title='Asprox: 22net.ru, 4net9.ru, 64asp.ru, 92prt.ru and fst9.ru'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-6438919683168299595</id><published>2008-09-10T17:11:00.002+01:00</published><updated>2008-09-10T17:18:37.379+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Scams'/><title type='text'>SpamCop phish</title><content type='html'>Some people will phish for anything - in this case they are trying to get access to &lt;a href="http://spamcop.net/"&gt;SpamCop accounts&lt;/a&gt;. Go figure. Reply to address is 2020sarah@live.com.&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;&lt;br /&gt;Subject:       UPDATE YOUR ACCOUNT / SPAMCOP.NET&lt;br /&gt;From:       "Admin@spamcop.net" &lt;pjf2442@adelphia.net&gt;&lt;br /&gt;Date:       Wed, September 10, 2008 4:54 pm&lt;br /&gt;Cc:       recipient list not shown:;&lt;br /&gt;Priority:       Normal&lt;br /&gt;&lt;br /&gt;This is a WebNews Email Account Update&lt;br /&gt;Please see the bottom of this mailing on this information.&lt;br /&gt;-----------------------------------------------------------&lt;br /&gt;SPAMCOP.NET WEBMAIL&lt;br /&gt;INTERNET SERVICE WEBSITE WISH TO INFORM YOU THAT WE HAVE&lt;br /&gt;SOME PROBLEMS ABOUT EACH CUSTOMER ACCOUNT EMAIL. DUE TO&lt;br /&gt;ERROR CODE 334409.&lt;br /&gt;&lt;br /&gt;WE DISCOVERD THAT IN FEW DAYS FROM NOW EACH CUSTOMER WILL&lt;br /&gt;NOT BE ABLE TO ACCESS HIS OR HER EMAIL ACCOUNT. IN THAT&lt;br /&gt;REGARD,YOU ARE REQUIRED TO SEND YOUR EMAIL ADDRESS AND&lt;br /&gt;PASSWORD FOR A NEW ACCOUNT UPDATE.&lt;br /&gt;&lt;br /&gt;YOU ARE ADVISED TO IMMEDIATELY SEND US THE REQUIRED&lt;br /&gt;INFORMATION SO AS TO ENABLE US IMMEDIATELY UPDATE YOUR&lt;br /&gt;ACCOUNT.&lt;br /&gt;&lt;br /&gt;Note:You have to understand that the reason why we are not&lt;br /&gt;sending this message from our own private account.This is&lt;br /&gt;due to some technical problem we are having right now.&lt;br /&gt;&lt;br /&gt;BELOW THE INFORMATION RQRUIRED FOR ACCOUT UPDATE&lt;br /&gt;&lt;br /&gt;1)Full Email Address:&lt;br /&gt;2)password:&lt;br /&gt;3)date of birth:&lt;br /&gt;&lt;br /&gt;Thanks for your understanding.&lt;br /&gt;&lt;br /&gt;SPAMCOP.NET WEBMAIL INTERNET SERVICE&lt;br /&gt;&lt;br /&gt;&lt;/pjf2442@adelphia.net&gt;&lt;hr /&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/6438919683168299595/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=6438919683168299595' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/6438919683168299595'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/6438919683168299595'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/spamcop-phish.html' title='SpamCop phish'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-8545691588776992063</id><published>2008-09-10T15:56:00.004+01:00</published><updated>2008-09-10T16:01:33.971+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CA'/><category scheme='http://www.blogger.com/atom/ns#' term='False Positive'/><category scheme='http://www.blogger.com/atom/ns#' term='PestPatrol'/><title type='text'>PestPatrol: SillyDl FFL in wuauclt.exe</title><content type='html'>It looks like CA PestPatrol might have a false positive, detecting &lt;span style="font-weight: bold;"&gt;SillyDl FFL&lt;/span&gt; in &lt;span style="font-weight: bold;"&gt;C:\windows\system32\wuauclt.exe&lt;/span&gt;. This is a component of Windows Update, and in the case of the false positive it is a 124,184 byte file with an internal version number of 5.8.0.2469.&lt;br /&gt;&lt;br /&gt;PestPatrol does not appear to be trying to delete the file, it is merely blocking access to it. Updating your &lt;a href="http://windowsupdate.microsoft.com/"&gt;Windows Update&lt;/a&gt; components should clear the problem. CA usually fix these false positives in a day or so.&lt;br /&gt;&lt;br /&gt;The current signature version is 2008.9.9.15. Note that the PestPatrol engine is used in some other products, not all of which have the CA name on them.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/8545691588776992063/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=8545691588776992063' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8545691588776992063'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8545691588776992063'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/pestpatrol-sillydl-ffl-in-wuaucltexe.html' title='PestPatrol: SillyDl FFL in wuauclt.exe'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-1166882858951708039</id><published>2008-09-10T09:04:00.002+01:00</published><updated>2008-09-10T09:10:39.338+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Asprox'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>Asprox: net83.ru, acr34.ru, asl39.ru and net83.ru</title><content type='html'>Another bunch of very fresh Asprox domains being used in the Asprox SQL Injection attack, registered at Naunet to email address retyi111@yahoo.com. Check your logs or block access to these sites.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;51com.ru&lt;/li&gt;&lt;li&gt;acr34.ru&lt;/li&gt;&lt;li&gt;asl39.ru&lt;/li&gt;&lt;li&gt;net83.ru&lt;/li&gt;&lt;/ul&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/1166882858951708039/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=1166882858951708039' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/1166882858951708039'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/1166882858951708039'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/asprox-net83ru-acr34ru-asl39ru-and.html' title='Asprox: net83.ru, acr34.ru, asl39.ru and net83.ru'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-4933191232564446674</id><published>2008-09-09T14:26:00.002+01:00</published><updated>2008-09-09T14:41:14.624+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>SQL Injection: ave2.cn / %61%76%65%32%2E%63%6E</title><content type='html'>This SQL Injection attack seems to be aimed at Chinese language sites. The code injected points to &lt;span style="font-weight: bold;"&gt;http://%61%76%65%32%2E%63%6E&lt;/span&gt; which is trivially encoded and is a reference to &lt;span style="font-weight: bold;"&gt;ave2.cn&lt;/span&gt; hosted on          219.129.239.251.&lt;br /&gt;&lt;br /&gt;ave2.cn then calls &lt;span style="font-weight: bold;"&gt;asp-18.cn&lt;/span&gt;, &lt;span style="font-weight: bold;"&gt;asp-12.cn&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;www.hxg006.cn &lt;/span&gt;(all hosted on 219.129.239.251).&lt;br /&gt;&lt;br /&gt;Between them, these sites carry a VERY wide variety of exploits, including MS06-014, GLIEDown (for the Baofeng Storm StormPlayer),  MS snpvw.Snapshot viewer (Outlook Express), DPClient.Vod (Xunlei Thunder DapPlayer), Flash Player and RealPlayer. There are possibly other exploits mixed in, so I would regard &lt;span style="font-weight: bold;"&gt;ave2.cn&lt;/span&gt; as being VERY dangerous.&lt;br /&gt;&lt;br /&gt;Robtex &lt;a href="http://www.robtex.com/ip/219.129.239.251.html"&gt;reports&lt;/a&gt; the following domains on 219.129.239.251, all of which are probably worth avoiding:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;hs7yue.cn&lt;/li&gt;&lt;li&gt;hxg008.cn&lt;/li&gt;&lt;li&gt;jzm015.cn&lt;/li&gt;&lt;li&gt;doups.cn&lt;/li&gt;&lt;li&gt;hxg008.cn&lt;/li&gt;&lt;li&gt;jzm013.cn&lt;/li&gt;&lt;li&gt;jzm014.cn&lt;/li&gt;&lt;li&gt;jzm015.cn&lt;/li&gt;&lt;li&gt;qingfeng01.cn&lt;/li&gt;&lt;/ul&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/4933191232564446674/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=4933191232564446674' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/4933191232564446674'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/4933191232564446674'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/sql-injection-ave2cn-617665322e636e.html' title='SQL Injection: ave2.cn / %61%76%65%32%2E%63%6E'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-8058718383409904979</id><published>2008-09-08T17:09:00.001+01:00</published><updated>2008-09-08T17:10:41.613+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Asprox'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>Asprox: 64do.com</title><content type='html'>Possibly the final Asprox domain on the day in &lt;span style="font-weight: bold;"&gt;64do.com&lt;/span&gt; - add this to your block or scan list.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/8058718383409904979/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=8058718383409904979' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8058718383409904979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8058718383409904979'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/asprox-64docom.html' title='Asprox: 64do.com'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-374699894320174261</id><published>2008-09-08T10:46:00.002+01:00</published><updated>2008-09-08T10:48:43.592+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Asprox'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><category scheme='http://www.blogger.com/atom/ns#' term='Domains'/><title type='text'>Asprox: "aspx" domains</title><content type='html'>Keep an eye out for these following Asprox domains, all recently registered to the email address druid00091@aol.com. Block them or scan your logs for them.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;24aspx.com&lt;/li&gt;&lt;li&gt;2aspx.net&lt;/li&gt;&lt;li&gt;6aspx.com&lt;/li&gt;&lt;li&gt;9aspx.net&lt;/li&gt;&lt;li&gt;aspx46.com&lt;/li&gt;&lt;/ul&gt;These domains follow the same pattern as &lt;a href="http://www.dynamoo.com/blog/2008/09/asprox-24aspxcom.html"&gt;this one&lt;/a&gt; and &lt;a href="http://www.dynamoo.com/blog/2008/09/asprox-19sslnet.html"&gt;this one&lt;/a&gt;.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/374699894320174261/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=374699894320174261' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/374699894320174261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/374699894320174261'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/asprox-aspx-domains.html' title='Asprox: &quot;aspx&quot; domains'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-3526110874053397894</id><published>2008-09-08T10:00:00.002+01:00</published><updated>2008-09-08T10:03:51.236+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Asprox'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>Asprox: 19ssl.net</title><content type='html'>Another "druid00091@aol.com" domain (following on from &lt;a href="http://www.dynamoo.com/blog/2008/09/asprox-24aspxcom.html"&gt;this one&lt;/a&gt; and &lt;a href="http://www.dynamoo.com/blog/2008/09/job-opportunity-at-luksus-luksus.html"&gt;this one&lt;/a&gt;) , this type 19ssl.net, which is being actively used as part of the SQL injection attacks. The top level of this domain also has a copy of the (presumably legitimate) &lt;span style="font-weight: bold;"&gt;nescodirect.com&lt;/span&gt; site (this behavious is &lt;a href="http://www.matchent.com/wpress/index.php?q=node/374"&gt;noted elsewhere&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Domain name: 19ssl.net&lt;br /&gt;&lt;br /&gt;Registrant Contact:&lt;br /&gt;   City22 llc&lt;br /&gt;   Alex Williamos druid00091@aol.com&lt;br /&gt;   +1.8827721124 fax: +1.8827721124&lt;br /&gt;   321113 po box&lt;br /&gt;   New York NY 12131&lt;br /&gt;   us&lt;br /&gt;&lt;br /&gt;Administrative Contact:&lt;br /&gt;   Alex Williamos druid00091@aol.com&lt;br /&gt;   +1.8827721124 fax: +1.8827721124&lt;br /&gt;   321113 po box&lt;br /&gt;   New York NY 12131&lt;br /&gt;   us&lt;br /&gt;&lt;br /&gt;Technical Contact:&lt;br /&gt;   Alex Williamos druid00091@aol.com&lt;br /&gt;   +1.8827721124 fax: +1.8827721124&lt;br /&gt;   321113 po box&lt;br /&gt;   New York NY 12131&lt;br /&gt;   us&lt;br /&gt;&lt;br /&gt;Billing Contact:&lt;br /&gt;   Alex Williamos druid00091@aol.com&lt;br /&gt;   +1.8827721124 fax: +1.8827721124&lt;br /&gt;   321113 po box&lt;br /&gt;   New York NY 12131&lt;br /&gt;   us&lt;br /&gt;&lt;br /&gt;DNS:&lt;br /&gt;ns1.19ssl.net&lt;br /&gt;ns2.19ssl.net&lt;br /&gt;ns3.19ssl.net&lt;/blockquote&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/3526110874053397894/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=3526110874053397894' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/3526110874053397894'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/3526110874053397894'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/asprox-19sslnet.html' title='Asprox: 19ssl.net'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-4786281788763101607</id><published>2008-09-08T09:39:00.004+01:00</published><updated>2008-09-08T09:46:36.089+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Asprox'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Injection'/><title type='text'>Asprox: 24aspx.com</title><content type='html'>The latest domain name used in the recent Asprox SQL Injection attacks appears to be &lt;span style="font-weight: bold;"&gt;24aspx.com.&lt;/span&gt; Perhaps the Asprox guys are boasting a little with the domain name? Certainly these SQL injection attacks still seem to serve a useful purpose for them, although the number of vulnerable servers keeps dropping. Anyway, block this one or check your logs for it.&lt;br /&gt;&lt;br /&gt;The email addressed used to register this domain is identical to the one used for the "&lt;a href="http://www.dynamoo.com/blog/2008/09/job-opportunity-at-luksus-luksus.html"&gt;Luksus Jobs&lt;/a&gt;" scam email. No big news here, the Asprox botnet is used for a wide variety of things, it's just odd to see  druid00091@aol.com come up twice in such a short period.&lt;br /&gt;&lt;br /&gt;It's also notable that they've switched back to .com from .ru, but this time registered through Chinese registrar BIZCN.COM.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Domain name: 24aspx.com&lt;br /&gt;&lt;br /&gt;Registrant Contact:&lt;br /&gt;   City22 llc&lt;br /&gt;   Alex Williamos druid00091@aol.com&lt;br /&gt;   +1.8827721124 fax: +1.8827721124&lt;br /&gt;   321113 po box&lt;br /&gt;   New York NY 12131&lt;br /&gt;   us&lt;br /&gt;&lt;br /&gt;Administrative Contact:&lt;br /&gt;   Alex Williamos druid00091@aol.com&lt;br /&gt;   +1.8827721124 fax: +1.8827721124&lt;br /&gt;   321113 po box&lt;br /&gt;   New York NY 12131&lt;br /&gt;   us&lt;br /&gt;&lt;br /&gt;Technical Contact:&lt;br /&gt;   Alex Williamos druid00091@aol.com&lt;br /&gt;   +1.8827721124 fax: +1.8827721124&lt;br /&gt;   321113 po box&lt;br /&gt;   New York NY 12131&lt;br /&gt;   us&lt;br /&gt;&lt;br /&gt;Billing Contact:&lt;br /&gt;   Alex Williamos druid00091@aol.com&lt;br /&gt;   +1.8827721124 fax: +1.8827721124&lt;br /&gt;   321113 po box&lt;br /&gt;   New York NY 12131&lt;br /&gt;   us&lt;br /&gt;&lt;br /&gt;DNS:&lt;br /&gt;ns1.24aspx.com&lt;br /&gt;ns2.24aspx.com&lt;br /&gt;ns3.24aspx.com&lt;br /&gt;&lt;br /&gt;Created: 2008-09-06&lt;br /&gt;Expires: 2009-09-06&lt;/blockquote&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/4786281788763101607/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=4786281788763101607' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/4786281788763101607'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/4786281788763101607'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/asprox-24aspxcom.html' title='Asprox: 24aspx.com'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-8528875357319020571</id><published>2008-09-08T09:22:00.002+01:00</published><updated>2008-09-08T09:37:02.647+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Asprox'/><category scheme='http://www.blogger.com/atom/ns#' term='Money Mule'/><category scheme='http://www.blogger.com/atom/ns#' term='Scams'/><title type='text'>"Job Opportunity at Luksus" / luksus-jobs.org scam</title><content type='html'>&lt;a href="http://www.luksusmedia.com/"&gt;Luksus Media&lt;/a&gt; is a wholly legitimate Finnish company, but this attempt to recruit a &lt;a href="http://en.wikipedia.org/wiki/Money_mule"&gt;money mule&lt;/a&gt; does not come from Luksus, just from a company trying to trade on its name.&lt;br /&gt;&lt;br /&gt;This scam is being run by the same people behind the Asprox SQL injection attacks that have been doing to rounds (more information after the email).&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;&lt;br /&gt;Subject:       Job Opportunity at Luksus&lt;br /&gt;&lt;br /&gt;We have reviewed your resume and would like to introduce you to our&lt;br /&gt;current vacancy.&lt;br /&gt;Luksus, with headquarters in Helsinki, Finland, serves the luxury&lt;br /&gt;lifestyle and offers unparalleled access to the finest luxury&lt;br /&gt;goods. We offer a unique mix of brands, partnerships, and product&lt;br /&gt;expertise. We are currently hiring, work at home positions, to&lt;br /&gt;provide administrative assistance with sales in North America.&lt;br /&gt;Candidates for the job should possess excellent organizational&lt;br /&gt;skills as well as the ability to efficiently multi-task. Ideal&lt;br /&gt;candidates have a strong focus on day-to-day operational&lt;br /&gt;excellence. The candidate should be motivated, proactive, be able&lt;br /&gt;to learn and adapt quickly.&lt;br /&gt;&lt;br /&gt;Other duties include, but are not limited to:&lt;br /&gt;&lt;br /&gt;* Incorporating effective priorities for the virtual office function&lt;br /&gt;* Administer day-to-day financial responsibilities for clients&lt;br /&gt;* Reporting online daily&lt;br /&gt;* Preparing brief summary reports, and weekly financial reports&lt;br /&gt;&lt;br /&gt;Salary part-time (3 hours per day, Monday-Friday): $1,200/month,&lt;br /&gt;plus commission.&lt;br /&gt;&lt;br /&gt;If you are interested in this position please send us an email to&lt;br /&gt;Sandra.Collins@luksus-jobs.org expressing your interest and we will&lt;br /&gt;forward you the detailed job description and the working agreement.&lt;br /&gt;&lt;br /&gt;Thank You,&lt;br /&gt;Luksus Team&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;Normally, WHOIS data is pretty useless, but sometimes the email address can give a clue:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Domain ID:  D153950800-LROR&lt;br /&gt;Domain Name:  LUKSUS-JOBS.ORG&lt;br /&gt;Created On:  28-Aug-2008 11:  34:  57 UTC&lt;br /&gt;Last Updated On:  28-Aug-2008 14:  23:  25 UTC&lt;br /&gt;Expiration Date:  28-Aug-2009 11:  34:  57 UTC&lt;br /&gt;Sponsoring Registrar:  Bizcn.com, Inc. (R1248-LROR)&lt;br /&gt;Status:  CLIENT TRANSFER PROHIBITED&lt;br /&gt;Status:  TRANSFER PROHIBITED&lt;br /&gt;Registrant ID:  orgfm19923291709&lt;br /&gt;Registrant Name:  Fero Muia&lt;br /&gt;Registrant Organization:  Fero Muia&lt;br /&gt;Registrant Street1:  3213 po box&lt;br /&gt;Registrant Street2: &lt;br /&gt;Registrant Street3: &lt;br /&gt;Registrant City:  New York&lt;br /&gt;Registrant State/Province:  NY&lt;br /&gt;Registrant Postal Code:  12310&lt;br /&gt;Registrant Country:  US&lt;br /&gt;Registrant Phone:  +1.9917721121&lt;br /&gt;Registrant Phone Ext.: &lt;br /&gt;Registrant FAX:  +1.9917721121&lt;br /&gt;Registrant FAX Ext.: &lt;br /&gt;Registrant Email:  druid00091@aol.com&lt;br /&gt;Admin ID:  orgfm19923292728&lt;br /&gt;Admin Name:  Fero Muia&lt;br /&gt;Admin Organization:  Fero Muia&lt;br /&gt;Admin Street1:  3213 po box&lt;br /&gt;Admin Street2: &lt;br /&gt;Admin Street3: &lt;br /&gt;Admin City:  New York&lt;br /&gt;Admin State/Province:  NY&lt;br /&gt;Admin Postal Code:  12310&lt;br /&gt;Admin Country:  US&lt;br /&gt;Admin Phone:  +1.9917721121&lt;br /&gt;Admin Phone Ext.: &lt;br /&gt;Admin FAX:  +1.9917721121&lt;br /&gt;Admin FAX Ext.: &lt;br /&gt;Admin Email:  druid00091@aol.com&lt;br /&gt;Tech ID:  orgfm19923293349&lt;br /&gt;Tech Name:  Fero Muia&lt;br /&gt;Tech Organization:  Fero Muia&lt;br /&gt;Tech Street1:  3213 po box&lt;br /&gt;Tech Street2: &lt;br /&gt;Tech Street3: &lt;br /&gt;Tech City:  New York&lt;br /&gt;Tech State/Province:  NY&lt;br /&gt;Tech Postal Code:  12310&lt;br /&gt;Tech Country:  US&lt;br /&gt;Tech Phone:  +1.9917721121&lt;br /&gt;Tech Phone Ext.: &lt;br /&gt;Tech FAX:  +1.9917721121&lt;br /&gt;Tech FAX Ext.: &lt;br /&gt;Tech Email:  druid00091@aol.com&lt;br /&gt;Name Server:  NS1.RELEASEBPB.COM&lt;br /&gt;Name Server:  NS2.RELEASEBPB.COM &lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;druid00091@aol.com&lt;/span&gt; is an address being used to register today's latest SQL injection domains too, proving that they are linked. &lt;span style="font-weight: bold;"&gt;releasebpb.com&lt;/span&gt; is a set of name servers which are only associated with malware domains, ns1.releasebpb.com is on 194.150.120.47 on ns2.releasebpb.com is on 20.31.85.15.&lt;br /&gt;&lt;br /&gt;This type of fraud doesn't use a website to entice people, but it is looking for an email response. In this case, email is delivered to mx.luksus-jobs.org on 12.192.82.225 which is on the AT&amp;amp;T network.&lt;br /&gt;&lt;br /&gt;It's hard to tell which of these IPs are part of the Asprox botnet and which ones are rented (usually with fake credit card details). Nonetheless, it gives a glimpse into just how large and efficient these operations can be.</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/8528875357319020571/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=8528875357319020571' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8528875357319020571'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8528875357319020571'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2008/09/job-opportunity-at-luksus-luksus.html' title='&quot;Job Opportunity at Luksus&quot; / luksus-jobs.org scam'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author></entry></feed>