<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7509741368295633849</id><updated>2011-07-08T09:56:39.872-03:00</updated><category term='crimeware research'/><category term='security research'/><category term='e-fraud research'/><category term='whitepapers'/><title type='text'>SecurityIntelligence</title><subtitle type='html'>&lt;b&gt;A division of Malware Intelligence&lt;/b&gt;</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>12</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7509741368295633849.post-4416696744849680985</id><published>2011-06-15T19:29:00.001-03:00</published><updated>2011-06-15T19:31:56.632-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><title type='text'>The Art of the Cyberwar</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-aRH8bnh4SQI/TfkxgKelWOI/AAAAAAAAAcs/BafvgDwMN1o/s1600/the-art-of-the-cyberwar.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://4.bp.blogspot.com/-aRH8bnh4SQI/TfkxgKelWOI/AAAAAAAAAcs/BafvgDwMN1o/s200/the-art-of-the-cyberwar.png" width="141" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;The development of new technologies, in catching up with military interests and dependence on existing technology by developed countries, sets up a scenario where the cyber war, or war in cyberspace, is becoming more important.&lt;br /&gt;&lt;br /&gt;All countries aware of the risks of such dependence developed defense programs against attacks that could jeopardize critical national infrastructure.&lt;br /&gt;&lt;br /&gt;On the other hand, developing countries and major world powers are training computer security experts in various techniques of hacking, cracking, virology, etc.., forming true experts in cyber warfare, called cyberwarriors.&lt;br /&gt;&lt;br /&gt;That does not fit anyone doubt that the future wars will not be determined or land or sea or air, but in cyberspace. The soldiers do not carry weapons or shields, but knowledge and deploy applications that war virus, disabling the enemy's critical systems that are technologically dependent.&lt;br /&gt;&lt;br /&gt;This is the scenario where the world is moving now, a scenario of technological dependence, where countries with more traditional military strength will be losing ability to war for countries with highly qualified in computer security and cyber techniques.&lt;br /&gt;&lt;br /&gt;This essay is intended as a point of reflection and knowledge about cyber warfare, on the present philosophy of Sun Tzu in the Art of War, and adapt their knowledge to technological scenario which we live and live, so we can get a modern compendium: The Art of Cyberwar.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.malwareint.com/docs/the-art-of-the-cyberwar-en.pdf" style="color: blue;"&gt;Version in english&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.malwareint.com/docs/el-arte-de-la-ciberguerra-es.pdf" style="color: blue;"&gt;Version in spanish&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7509741368295633849-4416696744849680985?l=securityint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/4416696744849680985/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securityint.blogspot.com/2011/06/art-of-cyberwar.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/4416696744849680985'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/4416696744849680985'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/2011/06/art-of-cyberwar.html' title='The Art of the Cyberwar'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-aRH8bnh4SQI/TfkxgKelWOI/AAAAAAAAAcs/BafvgDwMN1o/s72-c/the-art-of-the-cyberwar.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7509741368295633849.post-8222356415477116802</id><published>2011-02-21T08:12:00.001-03:00</published><updated>2011-02-21T08:12:00.758-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><title type='text'>New whitepaper about Carberp Botnet</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-YTDEO3DuLQc/TWE8PvEFz_I/AAAAAAAAAb8/0uJEfYLuNr0/s1600/inside-carberp-botnet-en.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/-YTDEO3DuLQc/TWE8PvEFz_I/AAAAAAAAAb8/0uJEfYLuNr0/s200/inside-carberp-botnet-en.png" width="141" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Is available a &lt;a href="http://www.malwareint.com/docs.html" style="color: #990000;"&gt;new whitepaper&lt;/a&gt; that describes the operation of one of the botnets "wanted" by the security community:&lt;b&gt; Carberp&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;The article, called &lt;b&gt;Inside Carberp Botnet&lt;/b&gt; and written by Francisco Ruiz, Crimeware Research of &lt;b&gt;Malware&lt;span style="color: blue;"&gt;Intelligence&lt;/span&gt;&lt;/b&gt;, details the different parts of this crimeware, leaving evidence of its full operating mode.&lt;br /&gt;&lt;br /&gt;In recent weeks, has returned to Carberp impact due to the revival of several of his former C&amp;amp;C. However, experts believe &lt;b&gt;Malware&lt;span style="color: blue;"&gt;Intelligence&lt;/span&gt;&lt;/b&gt; have concrete evidence that would demonstrate that in fact the original group that was behind the first generation of Carberp is broken, and that some of the new botnets that spread banking trojan Carberp are managed through a modified version of the original.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Malware&lt;span style="color: blue;"&gt;Intelligence&lt;/span&gt;&lt;/b&gt; have a &lt;b&gt;Carberp Working Group&lt;/b&gt;, responsible for private research and demand of this particular threat. &lt;a href="http://malwareint.blogspot.com/2011/02/inside-carberp-botnet.html" style="color: #990000;"&gt;In the main blog&lt;/a&gt;, Ruiz also said that a botnet Carberp private market in a very closed environment, but since a few days ago, the marketing model has been released, giving some details of its current features and costs.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7509741368295633849-8222356415477116802?l=securityint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/8222356415477116802/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securityint.blogspot.com/2011/02/new-whitepaper-about-carberp-botnet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/8222356415477116802'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/8222356415477116802'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/2011/02/new-whitepaper-about-carberp-botnet.html' title='New whitepaper about Carberp Botnet'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-YTDEO3DuLQc/TWE8PvEFz_I/AAAAAAAAAb8/0uJEfYLuNr0/s72-c/inside-carberp-botnet-en.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7509741368295633849.post-6845476383045926445</id><published>2010-08-31T23:59:00.000-03:00</published><updated>2010-08-31T23:59:54.335-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><title type='text'>Computer Attacks. Security weaknesses that are commonly exploited</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TH3A1GOPkxI/AAAAAAAAAWs/BKcgY3T2jnA/s1600/attack.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TH3A1GOPkxI/AAAAAAAAAWs/BKcgY3T2jnA/s200/attack.png" width="143" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;A computer attack is to exploit any weakness or failure (vulnerability) exists in a program (operating systems and applications on this) in the physical components that make up the information environment, and even in people who use these resources.&lt;br /&gt;&lt;br /&gt;The aim is, somehow, get information that can then be used for fraudulent purposes to benefit themselves from the offender. In general the benefit sought is economic in nature, causing a negative effect on the safety critical system, which then directly affects the organization's assets and result in loss of money.&lt;br /&gt;&lt;br /&gt;This document provides a quick overview on these weaknesses, combined with possible countermeasures under which you may invoke to prevent effectively the different types of attacks that a system receives daily.&lt;/div&gt;&lt;br /&gt;&lt;a href="http://www.malwareint.com/docs/attack-en.pdf" style="color: #660000;"&gt;English version&lt;/a&gt; | &lt;a href="http://www.malwareint.com/docs/attack-es.pdf" style="color: #660000;"&gt;Spanish version&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;More &lt;a href="http://www.malwareint.com/docs.html" style="color: #660000;"&gt;White papers&lt;/a&gt; in &lt;b&gt;&lt;a href="http://www.malwareint.com/"&gt;&lt;span style="color: black;"&gt;Malware&lt;/span&gt;&lt;span style="color: blue;"&gt;Intelligence&lt;/span&gt;&lt;/a&gt;&lt;/b&gt; web site.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7509741368295633849-6845476383045926445?l=securityint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/6845476383045926445/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securityint.blogspot.com/2010/08/computer-attacks-security-weaknesses.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/6845476383045926445'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/6845476383045926445'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/2010/08/computer-attacks-security-weaknesses.html' title='Computer Attacks. Security weaknesses that are commonly exploited'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Mcy4oUq8gAQ/TH3A1GOPkxI/AAAAAAAAAWs/BKcgY3T2jnA/s72-c/attack.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7509741368295633849.post-8927769205062622235</id><published>2010-06-10T05:14:00.000-03:00</published><updated>2010-06-10T11:37:54.751-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security research'/><title type='text'>Computer Security or Information Security? What are we talking about?</title><content type='html'>&lt;div style="text-align: justify;"&gt;Usually receive consultations in which, conceptually speaking, there is a notable confusion about the difference between computer security and information security. Therefore, we will try to clarify the issue in question.&lt;br /&gt;&lt;br /&gt;While both issues are complementary and interact constantly in computer systems, the truth is that they have different aims. For one thing, computer security is responsible for protecting computer systems, the latter being understood as a combination of information, computers information and support people who use it. Basically, everything is in a computer environment.&lt;br /&gt;&lt;br /&gt;While, Information Security is a much broader process involving not only the protection of information stored in computer systems but also ensures the information without discrimination where it's. In other words, information security goes far beyond its purpose is to safeguard the information, regardless of the means by which circulates or the place where it's stored.&lt;br /&gt;&lt;br /&gt;Information is a "significant" assets that can be stored in different ways, in different ways and through different channels, not only can be stored digitally it can also be printed, written on paper in hand.&lt;br /&gt;&lt;br /&gt;Not limited to these forms but can also be found in films, recordings, using the spoken language (conversational) and even the memory of people. Besides being able to be transmitted through various means, be they conventional communication channels (analog) or late-generation (digital).&lt;br /&gt;&lt;br /&gt;Regardless of the character to take the information, it collects or spreading, should be adequately protected to ensure at all times the confidentiality, integrity and availability of data.&lt;br /&gt;&lt;br /&gt;Therefore, the main goal in information security is just a way appropriate to protect the information, preserving a number of basic parameters for the assets (anything that can be measured through a cost) can be considered safe and secure, minimizing potential damage from any eventuality that may impede the normal operation of the organization.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7509741368295633849-8927769205062622235?l=securityint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/8927769205062622235/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securityint.blogspot.com/2010/06/computer-security-or-information.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/8927769205062622235'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/8927769205062622235'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/2010/06/computer-security-or-information.html' title='Computer Security or Information Security? What are we talking about?'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7509741368295633849.post-948148124326721649</id><published>2010-06-06T17:07:00.000-03:00</published><updated>2010-06-06T17:07:29.842-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security research'/><title type='text'>Some words about Information Security</title><content type='html'>&lt;div style="text-align: justify;"&gt;Organizations are increasingly dependent on their computer networks and a problem affecting them, no matter how small, can compromise the continuity of operations, a situation which inevitably results in economic loss.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;An increasing number and complexity of new computer attacks, becoming more specialized skills whose goals are an economic nature for the benefit of the attackers also in the midst of this variety, have been increasing disrespectful actions of privacy.&lt;br /&gt;&lt;br /&gt;In addressing the issue on Information Security, a common tendency to scan only the aspects of computer media (backups, maintenance of computers, servers, networks, etc.), All aimed at ensuring that information is available, ignoring other aspects that must be addressed because they keep the same level of criticality, such as confidentiality and integrity of data and services.&lt;br /&gt;&lt;br /&gt;It's important to note that the human factor covers over 90% of security and that the remainder consists of the technological aspect. Therefore, overconfidence and lack of awareness are the main problems.&lt;br /&gt;&lt;br /&gt;Keep the information protected is equivalent to keeping it safe to threats to its functionality, either corrupt, improperly accessed, removing, and even stealing information.&lt;br /&gt;&lt;br /&gt;Therefore, information security is to protect the information of an organization preserving and protecting three basic parameters: confidentiality, integrity and availability.&lt;br /&gt;&lt;br /&gt;In the first of which seeks to ensure that only authorized persons have access to information. If the information is confidential should not be disclosed because the loss of confidentiality equivalent to the loss of secrecy. Furthermore, the more valuable the more information should be its degree of confidentiality and the greater the degree of confidentiality, the higher the level of security that must be implemented.&lt;br /&gt;&lt;br /&gt;For its part, the integrity of the information ensures that data will not be altered, removed or destroyed by unauthorized entities, preserving completely with the methods used for processing. If the information is altered then it loses integrity.&lt;br /&gt;&lt;br /&gt;Instead availability ensures that authorized persons have access to information, and its associated resources whenever they need it. The availability involves not only information but also all the physical and technological structure that allows access, transit and storage to ensure it arrives in a timely manner.&lt;br /&gt;&lt;br /&gt;These three key areas form the main column of information security, and constitutes the essential mechanisms to ensure confidence in the business processes so they have the desirable situation for any organization.&lt;br /&gt;&lt;br /&gt;"The information security is achieved by implementing a set of controls that include policies, practices, procedures, organizational structures ... depending on what you are trying to protect."&amp;nbsp;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;However, every implementation must provide a balance between use and transparent maximum safety, all at a reasonable cost.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7509741368295633849-948148124326721649?l=securityint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/948148124326721649/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securityint.blogspot.com/2010/06/some-words-about-information-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/948148124326721649'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/948148124326721649'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/2010/06/some-words-about-information-security.html' title='Some words about Information Security'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7509741368295633849.post-5941844413289424611</id><published>2010-03-27T10:56:00.002-03:00</published><updated>2010-03-27T11:00:38.273-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Phishing Database IV</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Economically-financial and banking institutions&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(153, 0, 0);"&gt;HSBC&lt;/span&gt; (http://www.hsbc.com)&lt;br /&gt;http://210.116.103.118/~kardex/gnuboard4/bbs//hsbc/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo:11j71fovq?IDV_URL=hsbc.MyHSBC_pib&lt;br /&gt;http://www.restoretherepublic.com/wp-content/bank/images/online.html&lt;br /&gt;http://72.16.130.62/.www.HSBC.co.uk/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo:11j71fovq?IDV_URL=hsbc.MyHSBC_pib&lt;br /&gt;http://www.update-hsbc-co-uk.aux3erables.com/www9.hsbc.co.uk/www9.hsbc.co.uk/1/2/HSBCINTEGRATION/CAM10;jsessionid=0000UyzfmbnkvKfK9fLILUpaTgF14et5m1u3IDV_URL=hsbc.MyHSBC_pib/www.hsbc.co.uk/IBlogin.html&lt;br /&gt;http://www.absolute-basketball-chaoten.de/language/008/update/HSBCINTEGRATIONCAM10jsessionid=00001DwpIt0wIyX1arHd6K8mQB6URL=hsbc.MyHSBCpib/hsbc/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo:11j71fovq?IDV_URL=hsbc.MyHSBC_pib&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(153, 0, 0);"&gt;VISA&lt;/span&gt;  (http://www.visa.com)&lt;br /&gt;http://195.140.132.196/~dan12794/visa/master/www.vbv.fr/images/fr/authentication.php&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(153, 0, 0);"&gt;Lloyds TSB&lt;/span&gt;  (http://www.lloydstsb.com)&lt;br /&gt;http://blog.romanjewelers.com/wp-content/lloydsts/customer.php?ibc=customer.ibc&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/S64Ehv2N3FI/AAAAAAAACRk/BK4kSugqkB8/s1600/lloyds-bank.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 201px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/S64Ehv2N3FI/AAAAAAAACRk/BK4kSugqkB8/s400/lloyds-bank.png" alt="" id="BLOGGER_PHOTO_ID_5453301176618310738" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; color: rgb(153, 0, 0);"&gt;BMO - Bank of Montreal&lt;/span&gt;  (www.bmo.com)&lt;br /&gt;http://www.noo.cl/wp-content/uploads/2009/09/update/SA%60Absa/SECURE/update/images/bmo.com/BMO/BMO/BMO/BMO/BMO/BMO/BMO/BMO/bmo/index.htm&lt;br /&gt;&lt;br /&gt;Continue reading the original post &lt;a style="color: rgb(153, 0, 0);" href="http://mipistus.blogspot.com/2010/03/phishing-database-iv.html"&gt;MalwareIntelligence Blog&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7509741368295633849-5941844413289424611?l=securityint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/5941844413289424611/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securityint.blogspot.com/2010/03/phishing-database-iv.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/5941844413289424611'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/5941844413289424611'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/2010/03/phishing-database-iv.html' title='Phishing Database IV'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/S64Ehv2N3FI/AAAAAAAACRk/BK4kSugqkB8/s72-c/lloyds-bank.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7509741368295633849.post-2428970813130466260</id><published>2010-03-07T22:47:00.000-03:00</published><updated>2010-03-07T22:47:10.926-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><title type='text'>myLoader. Base C&amp;C to manage Oficla/Sasfis Botnet</title><content type='html'>&lt;h1&gt;&lt;/h1&gt;&lt;div id="mainabout"&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://www.malwareint.com/images/ml-t.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5422537882371524274" src="http://www.malwareint.com/images/ml-t.png" style="cursor: pointer; float: left; height: 200px; margin: 0pt 10px 10px 0pt; width: 146px;" /&gt;&lt;/a&gt; myLoader a particular purpose Framework developed to manage the activities of a botnet. The data reflected in this report were collected based on the study of the criminal activities of a botnet containing a quantity of more than 210,000 zombies zombies.&lt;br /&gt;&lt;br /&gt;We describe the potential threat of this crime through the breakdown of the modules comprising the package that allows the management of the botnet ophicleide / Sasfis. Also presents some information that helps explain his behavior both in propagation strategy as in the processes of infection and prevention to help counteract their actions.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.malwareint.com/docs/myloader-oficla-analysis-es.pdf" style="color: #3333ff;"&gt;&lt;b&gt;Spanish&lt;/b&gt;&lt;/a&gt; |  &lt;a href="http://www.malwareint.com/docs/myloader-oficla-analysis-en.pdf" style="color: #3333ff;"&gt;&lt;b&gt;English&lt;/b&gt;&lt;/a&gt; | Author: Jorge Mieres | &lt;b&gt;Malware &lt;span class="blue"&gt;Intelligence&lt;/span&gt;&lt;/b&gt; | 2010, March &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7509741368295633849-2428970813130466260?l=securityint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/2428970813130466260/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securityint.blogspot.com/2010/03/myloader-base-c-to-manage-oficlasasfis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/2428970813130466260'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/2428970813130466260'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/2010/03/myloader-base-c-to-manage-oficlasasfis.html' title='myLoader. Base C&amp;C to manage Oficla/Sasfis Botnet'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7509741368295633849.post-7602585025797757689</id><published>2010-02-28T23:50:00.007-03:00</published><updated>2010-03-01T00:11:23.136-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Phishing database III</title><content type='html'>&lt;span style="font-size: 130%;"&gt;&lt;span style="font-weight: bold;"&gt;Financial &amp;amp; Banking Institutions &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Canada Trusth&lt;/span&gt;&lt;span style="color: #660000;"&gt; &lt;/span&gt;(http://www.tdcanadatrust.com/)&lt;br /&gt;http://www-tdcanadatrust-com.epage.ru/td-bank-index.html&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Citigroup&lt;/span&gt; (http://www.citigroup.com)&lt;br /&gt;http://www.alanmetauro.com/home/online.citibank.com/US/JPS/portal/Index.do.htm?F6=1&amp;amp;F7=IB&amp;amp;F21=IB&amp;amp;F22=IB&amp;amp;REQUEST=ClientSignin&amp;amp;LANGUAGE=ENGLISH&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;CUA - Credit Union Australia&lt;/span&gt;&lt;span style="color: #660000;"&gt; &lt;/span&gt;(http://www.cua.com.au)&lt;br /&gt;http://www.colconkproducts.com/pub/your-account-is-locked-cua-com-au/&lt;br /&gt;http://173-11-85-81-sfba.hfc.comcastbusiness.net/images/webbanker.cua.com.au/webbanker/CUA/&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;UniCredit Banca&lt;/span&gt;&lt;span style="color: #660000;"&gt; &lt;/span&gt;(http://www.unicreditbanca.it)&lt;br /&gt;http://161.58.125.218/uc/index.html&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Grupo Banca Carige&lt;/span&gt; (http://www.gruppocarige.it/ws/gruppo/jsp/index.jsp)&lt;br /&gt;http://www.iadr.or.kr/bbs/data/gruppocarige/it/grp/ws/gruppo/jsp/banca_carige/index.html&lt;div style="color: #660000;"&gt;&lt;span style="font-weight: bold;"&gt;Grupo Banca Popolare Di Bari&lt;/span&gt;&lt;/div&gt;http://www.georgiakoreans.com/bbs/data/bpr/index.html&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Banca Cesare Ponti&lt;/span&gt;&lt;span style="color: #660000;"&gt; &lt;/span&gt;(http://www.gruppocarige.it/grp/bponti/html/ita/index.htm)&lt;br /&gt;http://www.iadr.or.kr/bbs/data/gruppocarige/it/grp/ws/gruppo/jsp/banca_cesare_ponti/index.html&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Banca Del Monte Di Luccia&lt;/span&gt; (http://www.gruppocarige.it/ws/bmlucca/jsp/index.jsp)&lt;br /&gt;http://www.iadr.or.kr/bbs/data/gruppocarige/it/grp/ws/gruppo/jsp/banca_del_monte_di_lucca/index.html&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;CRS - Cassa di Risparmio di Savona&lt;/span&gt; (http://www.gruppocarige.it/ws/carisa/jsp/index.jsp)&lt;br /&gt;http://www.iadr.or.kr/bbs/data/gruppocarige/it/grp/ws/gruppo/jsp/cassa_di_risparmio_di_savona/index.html&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Cassa di Risparmio di Carrara&lt;/span&gt; (http://www.gruppocarige.it/ws/crcarrara/jsp/index.jsp)&lt;br /&gt;http://www.iadr.or.kr/bbs/data/gruppocarige/it/grp/ws/gruppo/jsp/cassa_di_risparmio_di_carrara/index.html&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Poste Italiane&lt;/span&gt; (http://www.poste.it)&lt;br /&gt;http://posteitalianeonlinebpolcarteprestafgfdf.pcriot.com/posteitaliane/bpol/cartepre/formslogin.aspx.php?TYPE=33554433&amp;amp;REALMOID=06-b5208d98-1e41-108b-b247-8392a717ff3e&amp;amp;GUID=&amp;amp;SMAUTHREASON=0&amp;amp;METHOD=GET&amp;amp;SMAGENTNAME&lt;br /&gt;http://www.ynzal.com/catalog/images/bpol/bancoposta/index.php?MfcISAPICommand=SignInFPP&amp;amp;UsingSSL=1&amp;amp;email=&amp;amp;userid&lt;br /&gt;http://www.yelin.ru/wm/bancopostaonline.poste.it/bpol/CARTEPRE/index.php?MfcISAPICommand=SignInFPP&amp;amp;UsingSSL=1&amp;amp;email=&amp;amp;userid&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Santander&lt;/span&gt; (www.santander.com)&lt;br /&gt;http://slarrauri.com/tusitioweb/demo/BentoBox/modules/Logon.html&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;&lt;span style="color: #660000;"&gt;ABSA&lt;/span&gt; &lt;/span&gt;(http://www.absa.co.za)&lt;br /&gt;http://markostoreltd.com/account.log/index.php&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;HSBC&lt;/span&gt; (http://www.hsbc.com)&lt;br /&gt;http://worldviba.org/hboard3/bbs/indexx/hsbc/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo:11j71fovq?IDV_URL=hsbc.MyHSBC_pib&lt;br /&gt;http://www.ss4net.com/flash/IBlogin.html&lt;br /&gt;http://www.tricitypt.com/photos/pediatrics/hsbcsecure/IBlogin.html&lt;br /&gt;http://in2pool.com/Sources/.x/IBlogin.html&lt;br /&gt;http://erethizon.net/pomocne/hibernace/IBlogin.php&lt;br /&gt;http://cs.kku.ac.kr/data/file/alumnus/hsbconline/HSBC/index.php&lt;br /&gt;http://etechsol.pk/cp/IBlogin.html&lt;br /&gt;http://www.fsk-squad.eu/stats/IBlogin.html&lt;br /&gt;http://www.goldenstwarriors.com/boxes/IBlogin.html&lt;br /&gt;http://singaporeluggagestorage.info/modules/foles/kmg/www.hsbc.co.uk/CAM10-jsessionid=000026MQ7KnXUxsKmiYKszFUkGJ12c58ti63.htm&lt;br /&gt;&lt;br /&gt;In the domain &lt;span style="font-style: italic;"&gt;singaporeluggagestorage.info&lt;/span&gt; climbed several packages of phishing through a shell. Besides HSBC phishing pack, found others to CIBS and ING Direct.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/S4rhk_n0vsI/AAAAAAAACOs/RwEAwDowfHI/s1600-h/phpshell.gif" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5443411125300674242" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/S4rhk_n0vsI/AAAAAAAACOs/RwEAwDowfHI/s400/phpshell.gif" style="cursor: pointer; display: block; height: 305px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;ING Direct&lt;/span&gt;&lt;span style="color: #660000;"&gt; &lt;/span&gt;(http://www.ing.com)&lt;br /&gt;http://singaporeluggagestorage.info/modules/foles/mijn.ing.htm&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;&lt;span style="color: #660000;"&gt;Lloyds TSB&lt;/span&gt; &lt;/span&gt;(http://www.lloydstsb.com)&lt;br /&gt;http://cjuckett.com/gallery/include/login/online.lloydstsb.co.uk/online.lloydstsb.co.uk/online.lloydstsb.co.uk/online.lloydstsb.co.uk/customer.ibc/&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Wachovia&lt;/span&gt; (http://www.wachovia.com)&lt;br /&gt;http://202.111.173.205/.../wachovia/AuthService.php?action=presentLogin&amp;amp;url=https://onlineservices.wachovia.com/NASApp/NavApp/Titanium?action=returnHome&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Bank of America&lt;/span&gt; (http://www.bankofamerica.com)&lt;br /&gt;http://210.116.103.118/~kardex/gnuboard4/bbs/Languages/&lt;br /&gt;http://ahuarqalliance.com/~ahuarqal/Pringles/www.bankofamerica.com/bofa-update/bofa-update/bofa/&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;J.P.Morgan&lt;/span&gt; (http://www.jpmorgan.com)&lt;br /&gt;http://martindlk.ie/pdf_files/10/c/ch.htm?customerid=&amp;amp;co_partnerId=2&amp;amp;siteid=0&amp;amp;ru=&amp;amp;PageName=login_run&amp;amp;pp=pass&amp;amp;pageType=708XeMWZllWXS3AlBX+VShqAhQRfhgTDrf&amp;amp;co_partnerId=2&amp;amp;siteid=0&amp;amp;ru=&amp;amp;pp=&amp;amp;pageType=708&amp;amp;MfcISAPICommand=ConfirmRegistration&amp;amp;708XeMWZllWXS3AlBXVShqAhQRfhgTDrfQRfhgTDrfA&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;egg&lt;/span&gt; (http://www.egg.com)&lt;br /&gt;http://www.extv.co.kr/data/file/s_tag08/819,00.html&lt;br /&gt;http://www.wrpt.us/fireworks/Egg-Login.htm&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;InterSwitch&lt;/span&gt; (http://www.interswitchng.com)&lt;br /&gt;http://2009_securityupdate1.t35.com/Nigeria_interSwitch.htm&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;MoneyGram&lt;/span&gt; (http://www.moneygram.com)&lt;br /&gt;http://121.11.253.235/.cgi-bin/mg/MoneyGram/eMoneyTransfer/&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Discover&lt;/span&gt; (http://www.discovercard.com)&lt;br /&gt;https://www.discovercard.com/cardmembersvcs/loginlogout/app/ac_main&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;VISA&lt;/span&gt; (http://www.visa.com)&lt;br /&gt;http://intersecure.fr/security/verified/cards/unlock/ssl/Deutschland/&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 130%;"&gt;&lt;span style="font-weight: bold;"&gt;Electronic Commerce&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Amazon&lt;/span&gt; (http://www.amazon.com) http://digiplan.nl/img/xzf5465x6z4f56xz4fx5z64f5645z4x5z64f556xf4z56x4z5f45z6x4f56f4z5xf45zx64f/cxz4564z56z4z6c54cx54xc545c46z54c4zxzxfx5fz4z65f454xz5f45zx45xz64f/&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;PayPal&lt;/span&gt;&lt;span style="color: #660000;"&gt; &lt;/span&gt;(https://www.paypal.com)&lt;br /&gt;http://www.revenueirish.net/~gustavo/mongis/webscrcmd=_login-submit&amp;amp;dispatch=5885d80a13c0db1fc53a056acd1538879f614231735d88db02692aa5ce177197.php&lt;br /&gt;http://8shagyasser.com/.cc/pp/us/&lt;br /&gt;http://www.revenueirish.net/~gustavo/mongis/index4.php&lt;br /&gt;http://allmedwholesale.com/cache/paypal/index.htm&lt;br /&gt;http://www.skizo123.com/update/&lt;br /&gt;http://francomm.org/worldsecure/&lt;br /&gt;http://carinethomas10.net/www.PayPal.Com22/webscrcmd=_login-done&amp;amp;login_access=1190737782.htm&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Capitalone&lt;/span&gt; (http://www.capitalone.com)&lt;br /&gt;http://allmedwholesale.com/cache/c/e/capitalOne/login.aspx.htm&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 130%;"&gt;&lt;span style="font-weight: bold;"&gt;Government Services&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;IRS - Internal Revenue Service&lt;/span&gt; (www.irs.gov)&lt;br /&gt;http://www.budgetcirkus.dk/irs.gov/IRS/irs-refund-account.html&lt;br /&gt;http://195.140.132.196/~dan10417/irs.gov/IRS/irs-refund-account.html&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;HMRC - HM Revenue &amp;amp; Customs&lt;/span&gt; (http://www.hmrc.gov.uk)&lt;br /&gt;http://www.hmrc.ukonlinerefund.com/refund.php?item=1928381240348811&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 130%;"&gt; &lt;span style="font-weight: bold;"&gt;Online Games&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;World of Warcraft&lt;/span&gt; (http://www.worldofwarcraft.com)&lt;br /&gt;http://www.worldofwarcraft-account-instrcationcheck.com/login.asp?app=wam&amp;amp;ref=https://www.worldofwarcraft.com/account/&amp;amp;eor=0&amp;amp;app=bam&lt;br /&gt;http://www.review-billing-worldofwarcraft.com/&lt;br /&gt;http://nm-jk-gh.worldofwarcraftftc.com/&lt;br /&gt;http://check.worldofwarcraftfts.com/&lt;br /&gt;http://account.worldofwarcraftfta.com/&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/S4rcb2SdtdI/AAAAAAAACOc/mPeZzwyDMok/s1600-h/wc.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5443405470618203602" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/S4rcb2SdtdI/AAAAAAAACOc/mPeZzwyDMok/s400/wc.png" style="cursor: pointer; display: block; height: 301px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Zynga Poker&lt;/span&gt; (http://www.zynga.com)&lt;br /&gt;http://admin_zynga_security.t35.com/&lt;br /&gt;http://administrator-poker.t35.com/security/account_verification/&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 130%;"&gt;&lt;span style="font-weight: bold;"&gt;Social Networking&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Hi5&lt;/span&gt; (http://www.hi5.com)&lt;br /&gt;http://aipoise.t35.com/frienddisplayHomePage.do.html&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;&lt;span style="color: #660000;"&gt;MySpace&lt;/span&gt; &lt;/span&gt;(http://www.myspace.com)&lt;br /&gt;http://210.51.184.12/myspace.com&amp;amp;session_timed_out.php&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Orkut&lt;/span&gt; (http://www.orkut.com)&lt;br /&gt;http://orkutfunky2008.50webs.com/index.HTML&lt;br /&gt;http://orkutf.50webs.com/Orkut/&lt;br /&gt;http://lanhousemv.t35.com/&lt;br /&gt;http://abhijaan.justfree.com/2009.html&lt;br /&gt;http://guuhrox.galeon.com/&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Facebook&lt;/span&gt; (http://www.facebook.com)&lt;br /&gt;http://admin_tools_zynga.t35.com/&lt;br /&gt;http://admin_zynga.t35.com/&lt;br /&gt;http://admin_zynga_poker.t35.com/&lt;br /&gt;http://admin_zyngapokergames.t35.com/&lt;br /&gt;http://adminbanned.t35.com/Zinga.Terms/&lt;br /&gt;http://adminfacebookz.t35.com/Facebook.htm&lt;br /&gt;http://adminforu.t35.com/facebook/facebook.php&lt;br /&gt;http://ak-sdk-fbsdk-conf.t35.com/&lt;br /&gt;http://funnymoneygame.t35.com/&lt;br /&gt;http://facebooknewlog.t35.com/Facebook.php&lt;br /&gt;http://apps-facebook-poker.t35.com/&lt;br /&gt;http://newfoundsite.t35.com/facebook/Facebook.htm&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;&lt;span style="color: #660000;"&gt;Xbox Live&lt;/span&gt; &lt;/span&gt;(http://www.xbox.com)&lt;br /&gt;http://anythingmicrosoft.t35.com/&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/S4rcuVVeeNI/AAAAAAAACOk/MnVdOSDuJow/s1600-h/xbox.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5443405788189980882" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/S4rcuVVeeNI/AAAAAAAACOk/MnVdOSDuJow/s400/xbox.png" style="cursor: pointer; display: block; height: 301px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;span style="font-size: 130%;"&gt;&lt;span style="font-weight: bold;"&gt;WebMail&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Yahoo&lt;/span&gt; (http://www.yahoo.com)&lt;br /&gt;https://marketingsolutions.login.yahoo.com/adui/signin/displaySignin.do?d=U2FsdGVkX19cY56F3r1QvfGtU0XVsveCoTYWNnRpvZ4bILechNLfZTHvHIOFjqsAa77VmsuwGDHOvNJSa0FuwZgPFc6s8evu39eeQ.zeRGM1OZ4zVBg-&amp;amp;m=0&amp;amp;l=en_US&amp;amp;=&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Windows Live&lt;/span&gt; (http://login.live.com)&lt;br /&gt;http://account_validation.t35.com/Windows%20live.php&lt;br /&gt;http://alw7dany.tripod.com/hotmail.htm&lt;br /&gt;http://wiwaxiaa.tripod.com/&lt;br /&gt;http://girl.q8sex.tripod.com/hotmail/login.srf.htm&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;&lt;span style="color: #660000;"&gt;AOL Mail&lt;/span&gt; &lt;/span&gt;(http://www.webmail.aol.com)&lt;br /&gt;http://aolz.t35.com/Webmail/&lt;br /&gt;http://aoltosbillingcenter.t35.com/&lt;br /&gt;http://aolsn.t35.com/&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;AIM Express&lt;/span&gt; (http://www.aim.com/aimexpress.adp)&lt;br /&gt;http://aoldashboard02.t35.com/aimexpress.html&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 130%;"&gt;&lt;span style="font-weight: bold;"&gt;File Hosting&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;Rapidshare&lt;/span&gt; (http://rapidshare.com)&lt;br /&gt;http://2993amit.justfree.com/Rapidshare/files.php&lt;br /&gt;http://www.rapidfree.za.pl/#200&lt;br /&gt;http://easy.justfree.com/index1.php&lt;br /&gt;http://willgax.justfree.com/rp/indir.php&lt;br /&gt;http://babalar2.justfree.com/rp/indir.php&lt;br /&gt;http://rsmany.t35.com/premiumzone.php&lt;br /&gt;http://rapid24.blackapplehost.com/files.php&lt;br /&gt;http://rapid24.blackapplehost.com/logon.php&lt;br /&gt;http://www.phish.yoyo.pl/index.php&lt;br /&gt;http://hotfilm.xaa.pl/rs/index.php&lt;br /&gt;http://chronoshon.t35.com/files.php&lt;br /&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;&lt;span style="color: #660000;"&gt;Hotfile&lt;/span&gt; &lt;/span&gt;(http://www.hotfile.com)&lt;br /&gt;http://hotfiles.justfree.com/?f=295/dl/4629684/01bd28f/Boob-E_CD1_chunk_1.rar.html&lt;br /&gt;http://zsah.justfree.com/hotfile/index.php&lt;br /&gt;http://indigo2.justfree.com/&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;information&lt;/span&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;a href="http://malwareint.blogspot.com/2010/02/phishing-database-ii.html"&gt;Phishing database II&lt;/a&gt;&lt;/div&gt;&lt;div style="color: #660000;"&gt;&lt;a href="http://malwareint.blogspot.com/2010/02/phishing-database-i.html"&gt;Phishing database I&lt;/a&gt;&lt;/div&gt;&lt;div style="color: #660000;"&gt;&lt;a href="http://malwareint.blogspot.com/2010/02/zeus-on-irs-scam-remains-actively.html"&gt;ZeuS on IRS Scam remains actively exploited&lt;/a&gt;&lt;/div&gt;&lt;div style="color: #660000;"&gt;&lt;a href="http://malwareint.blogspot.com/2010/02/new-zeus-phishing-campaign-against.html"&gt;New ZeuS phishing campaign against Google and Blogger&lt;/a&gt;&lt;/div&gt;&lt;div style="color: #660000;"&gt;&lt;a href="http://malwareint.blogspot.com/2010/02/facebook-phishing-campaign-proposed-by.html"&gt;Facebook &amp;amp; VISA phishing campaign proposed by ZeuS&lt;/a&gt;&lt;/div&gt;&lt;div style="color: #660000;"&gt;&lt;a href="http://malwareint.blogspot.com/2010/02/dissection-of-fraudulent-package.html"&gt;Dissection of a fraudulent package. Wachovia phishing attack&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7509741368295633849-7602585025797757689?l=securityint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/7602585025797757689/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securityint.blogspot.com/2010/02/phishing-database-iii.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/7602585025797757689'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/7602585025797757689'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/2010/02/phishing-database-iii.html' title='Phishing database III'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/S4rhk_n0vsI/AAAAAAAACOs/RwEAwDowfHI/s72-c/phpshell.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7509741368295633849.post-8274793362372565403</id><published>2010-02-16T23:52:00.005-03:00</published><updated>2010-03-01T00:15:59.658-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Phishing database II</title><content type='html'>&lt;span style="font-size: 130%;"&gt;&lt;span style="font-weight: bold;"&gt;Financial &amp;amp; Banking Institutions&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;Bank of America&lt;/b&gt;&lt;/div&gt;http://i37.tinypic.com/1zo957a.jpg&lt;br /&gt;http://i35.tinypic.com/20tp4t0.jpg&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;Banco do Brasil&lt;/b&gt;&lt;/div&gt;http://www.ricklegrandphotography.com/own/index.htm?portalbb&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;BBVA&lt;/b&gt;&lt;/div&gt;http://87.225.254.21/vendors/shells/templates/verificacion/index.html&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S3ne6ZKDN5I/AAAAAAAAAF4/T11ERgtnVkQ/s1600-h/bbva.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S3ne6ZKDN5I/AAAAAAAAAF4/T11ERgtnVkQ/s320/bbva.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;HSBC&lt;/b&gt;&lt;/div&gt;http://www.silverstoneincense.com.au/IBlogin.html&lt;br /&gt;http://www.buyitdirect.co.nz/images/indexx/hsbc/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo:11j71fovq?IDV_URL=hsbc.MyHSBC_pib&lt;br /&gt;http://delthelboi.net/COsutmer/COsutmer/hsbc/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo:11j71fovq?IDV_URL=hsbc.MyHSBC_pib&lt;br /&gt;http://woorizip1004.net/zboard/icon/IBlogin.html&lt;br /&gt;http://www.ceipmiraflores.com/inc/ceip/IBlogin.html&lt;br /&gt;http://www.lbirelandftp.com/e-card/IBlogin.html&lt;br /&gt;http://www.galilee.cc/zeroboard/data/rr/CAM10.php?idv_cmd=idv.Logoff&amp;amp;nextPage=IDV_CAM10_AUTHENTICATION=2178611a6f5b6d7d722eacaa9c0a1f52LogonBy=Connect2178611a6f5b6d7d722eacaa9c0a1f52&lt;br /&gt;http://www.officeresourcegroup.com/_analog/hsbc.co.uk/IBlogin.html&lt;br /&gt;http://host24-128-static.39-79-b.business.telecomitalia.it/.personal/www.HSBC.Co.Uk/1/2/1.php?jsessionid=CAM10:jsessionid=0000RcSVT4vYF7HNB8AsppR8HRo:11j71fovq?IDV_URL=hsbc.MyHSBC_pib&lt;br /&gt;http://www.officeresourcegroup.com/_analog/hsbc.co.uk/1/2/IBlogin.html&lt;br /&gt;http://www.sinhvienqb.com/gallery/images/admin/IBlogin.html&lt;br /&gt;http://egg-inter.com/upload/www.hsbc.co.uk/1/IBlogin.html&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt; Poste italiane&lt;/b&gt;&lt;/div&gt;http://gerfdsafsd.pochta.ru/posste.html&lt;br /&gt;http://vaguematch.com/ioncube/_/https/www.poste.it/bancoposta/online/_private/bpol/CARTEPRE/index.php?MfcISAPICommand=SignInFPP&amp;amp;UsingSSL=1&amp;amp;email=&amp;amp;userid=&lt;br /&gt;http://www.postevita.it/postevitaTFR.fcc?TYPE=33554433&amp;amp;REALMOID=06-bed2d688-fca1-10a2-bc8e-8392a717ff3e&amp;amp;GUID=&amp;amp;SMAUTHREASON=0&amp;amp;METHOD=GET&amp;amp;SMAGENTNAME=$SM$ZEj9fNrjJTQ1UbgR9hbQoqbSyCYN9lBONkWfqG8%2fz9C7F9%2bG8tRBmA%3d%3d&amp;amp;TARGET=$SM$http%3a%2f%2fwww.postevita.it%3a85%2fgestionetfr%2findex.shtml&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;CartaSi&lt;/b&gt;&lt;/div&gt;http://aviso-utente.rbcmail.ru/utente-cartaSI.html &lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;ABSA&lt;/b&gt;&lt;/div&gt;http://www.technicalconsultants.gr/images/oziogallery2/ib.html&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;HaliFax&lt;/b&gt;&lt;/div&gt;http://www.lechateauedizioni.it//components/com_performs/halifax_mail_form/index.php &lt;br /&gt;&lt;b&gt; &lt;/b&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;Regions&lt;/b&gt;&lt;/div&gt;http://www.lbirelandftp.com/content/Regions/Regions/&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;CUA (Credit Union Australia)&lt;/b&gt;&lt;/div&gt;http://www.cua-web-banker.com/098237409823749802378905/&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;Citigroup&lt;/b&gt;&lt;/div&gt;http://www.naturalcurves.com//wp-content/themes/blueberry-boat/online-citi-cards/citi%20card/citi%20card/update.html&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt; &lt;/b&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;CajaMadrid&lt;/b&gt;&lt;/div&gt;http://oi-cajamadrid.com.es/CajaMadrid/oi/pt_oi/Login/&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;Orange&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;http://92.243.8.56/Orange/info-online-verification.php&lt;br /&gt;http://adminpanel.net/xcart/images/cartpictures/http-id.orange.fr-auth_user-bin-authNuser.cgidate=1266009664=skey=3a347076d2326ec771ebe84a8de131fc=service=communiquer=url=http:webmail1eb.orange.fr*webmail*fr_FR/&lt;b&gt; &lt;/b&gt;&lt;br /&gt;&lt;b&gt; &lt;/b&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;VISA&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;http://alerts.cforms.visa.com.rep021.kr/secureapps/vdir/cholderform.php&lt;br /&gt;http://92.243.8.56/VerifiedByVisa/visa/error_info.php?cmd=_login-run&amp;amp;dispatch=5885d80a13c0db1f1ff80d546411d7f84f1036d8f209d3d19ebb6f4eeec8bd0ef1b64e562942814a64d80bf24862819bf1b64e562942814a64d80bf24862819b?cmd=_login-run&amp;amp;dispatch=5885d80a13c0db1f1ff80d546411d7f84f1036d8f209d3d19ebb6f4eeec8bd0ef1b64e562942814a64d80bf24862819bf1b64e562942814a64d80bf24862819b&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;MasterCard&lt;/b&gt;&lt;/div&gt;http://www.roxanalatorre.com/panel/mastercard/&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S3VkswawSdI/AAAAAAAAAFg/ly38WLlim8E/s1600-h/mi-phish-mc.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_Mcy4oUq8gAQ/S3VkswawSdI/AAAAAAAAAFg/ly38WLlim8E/s320/mi-phish-mc.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: 130%;"&gt;&lt;span style="font-weight: bold;"&gt;Electronic Commerce&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;PayPal&lt;/b&gt;&lt;/div&gt;http://74.86.158.3/~bigbigca/uc/Activation/paypal/&lt;br /&gt;http://french-kiss.org/~o103594/paypal.com/wwwpaypalcompaypalloginukusupdateinfo/webscr.php?cmd=_login-run&amp;amp;dispatch=2e310e6fd3c468fe3657669af990d4912e310e6fd3c468fe3657669af990d491&lt;br /&gt;http://exorh.com/~o103594/paypal.com/wwwpaypalcompaypalloginukusupdateinfo/webscr.php?cmd=_login-run&amp;amp;dispatch=2e310e6fd3c468fe3657669af990d4912e310e6fd3c468fe3657669af990d491&lt;br /&gt;http://calvarychapelabuja.com/users/barbara/account/?cmd=_login-run&lt;br /&gt;http://adcomphelp.com/tutorials/cam/paypal.com/fr/cmd=_registration-run/webscr.php?cmd=_login-run&amp;amp;dispatch=9cf470a1ba43eb481569e296a16bd15d9cf470a1ba43eb481569e296a16bd15d&lt;br /&gt;http://aempresarial.com/admin/www.PayPal.Com22/webscrcmd=_login-done&amp;amp;login_access=1190737782.htm&lt;br /&gt;http://paypol.tk/fr/&lt;br /&gt;http://is250.internetdsl.tpnet.pl/FRS/&lt;br /&gt;http://office.supportacct.operaunite.com/webserver/content/?cmd=_login-run&amp;amp;session-redirect=noCookie&lt;br /&gt;http://www.yoville.justfree.com/&lt;br /&gt;http://www.anassoft.net/webscr.php&lt;br /&gt;http://paypal-ag.de/see/&lt;br /&gt;http://www.coinentertainment.com/images/www.paypal.com/management/financial/login.html&lt;br /&gt;http://paypal-uk.webcindario.com/ &lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;eBay&lt;/b&gt;&lt;/div&gt;http://rahasiabisnis21.com/_space/apache_module.php?customerid=hemi2u2@yahoo.com&amp;amp;co_partnerId=2&amp;amp;siteid=0&amp;amp;ru=&amp;amp;PageName=login_run&amp;amp;pp=pass&amp;amp;pageType=signin.ebay.com.ws.eBayISAPI.dll.fxHVPoQCOORAlDQoKlPMCP&lt;br /&gt;http://webproxy.go2myspace.com/sell.ebay.ie/ws/eBayISAPI.dll?SellItem&lt;br /&gt;http://www.vietwebdisk.com/signin.ebay.com/ws/eBayISAPI.dll?SignIn&amp;amp;ru=www.ebay.com&lt;br /&gt;http://cosmo.genusis.com/images/icons/eee/login.html#ws/eBayISAPI.dll?SignIn&amp;amp;ru=http://www.ebay.com/&lt;br /&gt;http://sangelecaiolor.czechian.net/polaris-rzr-W0QQitemZ250328176800QQcmdZViewItemQQptZ-logan-hash0item3a48b8d8a00_trksidsp32860c0023/z.php&lt;br /&gt;http://personal-pontoon-ebay.xf.cz/2006%20Lowe%20SUNCRUISER%20BIMINI/ebaymotorsW0QQitemZ180405328696QQcmdZViewItemQQptZboat_pontoonhash=item2a00fedb38&amp;amp;_trksid=p4/index.php&lt;br /&gt;http://www.normans.dk/catalog/images/AllinformationfromWHOISserviceisprovided.html &lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 130%;"&gt;&lt;span style="font-weight: bold;"&gt;File Hosting&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;MegaUpload&lt;/b&gt;&lt;/div&gt;http://www.nakudashi.blors.com/Akina/?active.to=http://www.megaupload.com/?c=login&amp;amp;next=d%3DPV1ZQAIJ&lt;br /&gt;http://www.sweetlife.iamspace.com/jav/asia.htm&lt;br /&gt;http://www.karina.blors.com/Sasaki/Studio.htm?to.url=http://www.megaupload.com/?d=RZXZ8YZ5&lt;br /&gt;http://www.nakudashi.blors.com/Akina/&lt;br /&gt;http://www.cocomisakura.blors.com/Sakura/cool.htm?url.active=http://www.megaupload.com/?d=HWDZS4OM&lt;br /&gt;http://www.shokoakiya.blors.com/Akiyama/asiacool.htm?url.active=http://www.megaupload.com/?d=5Y6402AH&lt;br /&gt;http://www.ramunagasuki.blors.com/asia/&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt; Rapidshare&lt;/b&gt;&lt;/div&gt;http://raapidshare.ugu.pl/premiumzone.php&lt;br /&gt;http://rapidshare-premium2011.tk/&lt;br /&gt;http://rs786.t35.com/logon.php&lt;br /&gt;http://rapidshare-premium2011.tk/&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: 130%;"&gt;&lt;span style="font-weight: bold;"&gt;Social Networking&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;Facebook&lt;/b&gt;&lt;/div&gt;http://www.rep021.kr/usersdirectory/LoginFacebook.php&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;YouTube&lt;/b&gt;&lt;/div&gt;http://youtube-view-all.tk/&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S3GLsgaWN2I/AAAAAAAAAFY/8hPvTly_3zY/s1600-h/mi-phish-youtube.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S3GLsgaWN2I/AAAAAAAAAFY/8hPvTly_3zY/s320/mi-phish-youtube.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;Telephone services &amp;amp; others&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;Walmart&lt;/b&gt;&lt;/div&gt;http://75.32.55.145/walmart/actpatriot/walmart/details.html&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;Telcel&lt;/b&gt;&lt;/div&gt;http://itelcel.byethost13.com/home_telcel/?_ideastelcel2010&amp;amp;_servlet_Controller_EVENT=RECARGA_PROMOCION&amp;amp;rnd=0.15117657&lt;br /&gt;http://www.rosalux.org.mx/logs/cgi_bin-ssl/com_notes/register2.html&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;Kijiji&lt;/b&gt;&lt;/div&gt;http://kijiji-ca.wz.cz/cSignInrups-ConfirmAccount-ruq-re-direct&amp;amp;Dwws.html&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="font-size: 130%;"&gt;&lt;span style="font-weight: bold;"&gt;WebMail&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;Windows Live Hotmail&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/S3VqNrPQ4nI/AAAAAAAAAFw/nWW-PKrlYNI/s1600-h/windows-live.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://2.bp.blogspot.com/_Mcy4oUq8gAQ/S3VqNrPQ4nI/AAAAAAAAAFw/nWW-PKrlYNI/s200/windows-live.png" width="113" /&gt;&lt;/a&gt;&lt;/div&gt;http://www.windowslivemail.tk/&lt;br /&gt;http://so7ba7elwa.ibda3.org/&lt;br /&gt;http://itelcel.byethost13.com/msn.html&lt;br /&gt;https://www.windowslive.co.uk/hotmailstories/ &lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;En este caso, en el mismo servidor se aloja otro phishing pero hacia la compañía Telcel, y se almacena toda la información robada: la relacionada a las tarjetas de crédito (correspondientes a TelCel) y las credenciales de acceso al webmail de Microsoft. Además de la descarga de un falso Windows Messenger 2010 que es un malware. A continuación se observa una captura del almacenamiento de credenciales.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S3Vnfx8FXeI/AAAAAAAAAFo/4lsBu6GOBoI/s1600-h/phish-logs.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S3Vnfx8FXeI/AAAAAAAAAFo/4lsBu6GOBoI/s320/phish-logs.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size: 130%;"&gt; &lt;span style="font-weight: bold;"&gt;Online Games&lt;/span&gt;&lt;/span&gt;&lt;b&gt; &lt;/b&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;World of Warcraft&lt;/b&gt;&lt;/div&gt;http://www.blizzard-account-review-blizzard.com/&lt;br /&gt;http://us.bettls.net/login/login.htm?ref=https://www.worldofwarcraft.com/account/&amp;amp;app=wam&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;b&gt;Tibia&lt;/b&gt;&lt;/div&gt;http://clanprem.atspace.com/&lt;br /&gt;http://clanbrazukas.atspace.com/&lt;br /&gt;http://clandemonsforlite.atspace.com/&lt;br /&gt;http://clanakimichi-join.atspace.com/&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related Information&lt;/b&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;a href="http://malwareint.blogspot.com/2010/02/phishing-database-i.html"&gt;Phishing database I&lt;/a&gt;&lt;/div&gt;&lt;div style="color: #660000;"&gt;&lt;a href="http://malwareint.blogspot.com/2010/02/dissection-of-fraudulent-package.html"&gt;Dissection of a fraudulent package. Wachovia phishing attack&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7509741368295633849-8274793362372565403?l=securityint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/8274793362372565403/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securityint.blogspot.com/2010/02/phishing-database-ii.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/8274793362372565403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/8274793362372565403'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/2010/02/phishing-database-ii.html' title='Phishing database II'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Mcy4oUq8gAQ/S3ne6ZKDN5I/AAAAAAAAAF4/T11ERgtnVkQ/s72-c/bbva.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7509741368295633849.post-4453172869013188900</id><published>2010-02-09T00:16:00.001-03:00</published><updated>2010-03-01T00:26:23.328-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='e-fraud research'/><title type='text'>Phishing database I</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Phishing&lt;/span&gt; responds to a purely criminal activity, part of the circuit that drives the illegal business of &lt;span style="font-weight: bold;"&gt;crimeware&lt;/span&gt;, designed to steal money using the sensitive and private information from users that criminals obtained through non-sacred activities.&lt;br /&gt;&lt;br /&gt;Therefore, as a preventive measure, it's important not to allow access to the domains that host usually banks cloned pages, webmail and any other Internet service through a process that requires authentication.&lt;br /&gt;&lt;br /&gt;To that end, born Phishing database, a compendium of fraudulent domains for implementing a plunger of phishing, which can be used to create the block lists.&lt;/div&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;span style="font-weight: bold;"&gt;Wachovia Corporation&lt;/span&gt;&lt;/div&gt;http://www.stc.lk/it/home/online.wachovia.com/accountupdate/AuthService.php?action=presentLogin&amp;amp;url=https%3a//onlineservices.wachovia.com/NASApp/NavApp/Titanium%3faction%3dreturnHome &lt;br /&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;span style="font-weight: bold;"&gt;PayPal&lt;/span&gt;&lt;/div&gt;aurelie-et-arnaud.me/img/paypal/verify/login.php&lt;br /&gt;www.yvescochet.net/.secure.paypal.fr/verified_by_paypal/webscrcmd=_login-run/cgi-bin/_login/ &lt;br /&gt;dz-tero.com/paypal/&lt;br /&gt;www.paypal.com.0ytyz0oxg18bu.124nruo3kb3j903ers01.com/cgi-bin/webscr/?login-dispatch&amp;amp;login_email=unnimay@aol.com&amp;amp;ref=pp&amp;amp;login-processing=ok&lt;br /&gt;www.124nruo3kb3j903ers01.com/cgi-bin/webscr/   &lt;br /&gt;www.syrianaction.com/data/.confirm/paypal/&lt;br /&gt;www.paypalcomservupdate.intl-paypal1.com/us/cgi-bin/?cmd=_login-run&lt;br /&gt;ukghd.com/images/www.paypal.com/cgi-bin/webscr.htm?cmd=_login-run&lt;br /&gt;203.101.73.204/www.paypal.com.au/security/cgi-bin/webscr.htm?cmd=_login-run &lt;br /&gt;52274548.es.strato-hosting.eu/lol/webscr.php?cmd=LogIn&amp;nbsp;   &lt;br /&gt;www.kules.knows.nl/cgi/ &lt;br /&gt;lejournalduthesard.info/help/css/update/online-information/fr/verefication-compte/online-update/webscr.php?cmd=_login-run&amp;amp;dispatch=5885d80a13c0db1f1ff80d546411d7f84f1036d8f209d3d19ebb6f4eeec8bd0e57b2ad7d754c297ea32a3580bcf6dcb357b2ad7d754c297ea32a3580bcf6dcb3&lt;br /&gt;208.101.19.98/~mikorg/ &lt;br /&gt;iwww.cz.cc/PayPal.fr/paypal/fr/webscr.php?cmd=_login-run&amp;amp;dispatch=5885d80a13c0db1f998ca054efbdf2c29878a435fe324eec2511727fbf3e9efc0779736997661668caf8ff5d99e81fe40779736997661668caf8ff5d99e81fe4&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S3Ds39iU0EI/AAAAAAAACLE/JazsHYxiwYg/s1600-h/mi-phish-paypal.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5436105196391682114" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S3Ds39iU0EI/AAAAAAAACLE/JazsHYxiwYg/s400/mi-phish-paypal.png" style="cursor: pointer; display: block; height: 301px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;egg&lt;/span&gt;&lt;br /&gt;www.luxor2020.com/about/files/Image/jpg/txt/neweggcom/security/customer/index.html &lt;br /&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;span style="font-weight: bold;"&gt;CUA&lt;/span&gt;&lt;/div&gt;www.zoi-creation.com/customers.cua.com.au/webbanker/CUA/2/notice.htm&lt;br /&gt;www.zoi-creation.com/customers.cua.com.au/webbanker/CUA/&amp;nbsp;     &lt;br /&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;span style="font-weight: bold;"&gt;HSBC&lt;/span&gt;&lt;/div&gt;cmodz-hosting.com/upload/cache/IBlogin.html &lt;br /&gt;www.w650-france.com//forum/modules/index.html &lt;br /&gt;www.ifsb.co.kr/bbs/data/guest/gold/folder/folder/New%20Folder/United2/Folder/Folder/Folder/Folder/Folder/Folder/Folder/empty/empty/empty/United2/United/United/United/HSBC/index.html&lt;br /&gt;dodongminhhien.com/modules/pib-home/2/1/personal/hsbc.co.uk/IBlogin.html &lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/S3DtrXqtgnI/AAAAAAAACLM/J9XKppvfsno/s1600-h/mi-phish-hsbc.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5436106079579505266" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/S3DtrXqtgnI/AAAAAAAACLM/J9XKppvfsno/s400/mi-phish-hsbc.png" style="cursor: pointer; display: block; height: 301px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;&lt;span style="color: #660000; font-weight: bold;"&gt;eBay&lt;/span&gt;&lt;br /&gt;rahasiabisnis21.com/_space/apache_module.php &lt;br /&gt;www.ebay.motors-cgi-items.com/cars-trucks_2003-BMW330I_W0QQitemZ15982632345413QQihZ012QQcategory-cars-trucksZ21983317QQssPageNameZWDVWQQrdZ1QQcmdZViewItems/index2.php &lt;br /&gt;190-13-160-211.bk14-ipfija.surnet.cl/.ws-cgi/index.php &lt;br /&gt;7beginnings.com/~sothebys/assets/profile/ws/login.html&amp;nbsp;      &lt;br /&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;span style="font-weight: bold;"&gt;JPMorgan Chase Bank&lt;/span&gt;&lt;/div&gt;7beginnings.com/~sothebys/assets/profile/auth/secure/chase-sec/onlinebanking.chase.com=logon_confirm/ &lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;In this case, in the same living space there is a breach against eBay phishing and another against JPMorgan Chase Bank in the IP address 203.211.129.222. The site is controlled by a shell in php call &lt;span style="font-weight: bold;"&gt;!islamicshell v. edition ADVANCED!&lt;/span&gt;.&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/S3DuRx2Bp-I/AAAAAAAACLU/Uadp8A6SbRE/s1600-h/mi-shell.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5436106739441313762" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/S3DuRx2Bp-I/AAAAAAAACLU/Uadp8A6SbRE/s400/mi-shell.png" style="cursor: pointer; display: block; height: 301px; margin: 0px auto 10px; text-align: center; width: 400px;" /&gt;&lt;/a&gt;The truth is that in addition to web upload cloned, the attacker can quietly, such as spreading malware of any type hosted on the server which hosts the site, including (a very common and which tend to be used the shell php) defacing.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;span style="font-weight: bold;"&gt;Lloyds TSB Bank&lt;/span&gt;&lt;/div&gt;www.ifsb.co.kr/bbs/data/guest/gold/folder/folder/New%20Folder/United2/Folder/Folder/Folder/Folder/Folder/Folder/Folder/empty/empty/empty/United2/United/United/United/Lloyds/customer.php &lt;br /&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;span style="font-weight: bold;"&gt;Barclays&lt;/span&gt;&lt;/div&gt;www.ifsb.co.kr/bbs/data/guest/gold/folder/folder/New%20Folder/United2/Folder/Folder/Folder/Folder/Folder/Folder/Folder/empty/empty/empty/United2/United/United/United/Barclays/LoginMember.login.htm &lt;br /&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;span style="font-weight: bold;"&gt;Canada Revenue Agency&lt;/span&gt;&lt;/div&gt;221.134.144.147/cra-arc.gc.ca/esrvc-srvce/tx/ndvdls/myrefund/getStatus_en.htm&lt;br /&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;span style="font-weight: bold;"&gt;Poste italiane&lt;/span&gt;&lt;/div&gt;fgewfgewdfsa.pochta.ru/posste.html &lt;br /&gt;mesagio-postepay.xaker.ru/postpayleg-clientesdasdhit.html&lt;br /&gt;&lt;br /&gt;&lt;div style="color: #660000;"&gt;&lt;span style="font-weight: bold;"&gt;Abbey&lt;/span&gt;&lt;/div&gt;www.velositas.com/update/myonlineacounts2.abbeynational.co.uk/Logonaction=prepared/Logonaction=prepare/&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7509741368295633849-4453172869013188900?l=securityint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/4453172869013188900/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securityint.blogspot.com/2010/02/phishing-database-i.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/4453172869013188900'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/4453172869013188900'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/2010/02/phishing-database-i.html' title='Phishing database I'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/S3Ds39iU0EI/AAAAAAAACLE/JazsHYxiwYg/s72-c/mi-phish-paypal.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7509741368295633849.post-6379279915431436332</id><published>2010-02-06T15:30:00.002-03:00</published><updated>2010-03-01T00:27:23.967-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='crimeware research'/><title type='text'>Justifying the unjustifiable in a world criminal</title><content type='html'>&lt;b&gt;&lt;/b&gt;&lt;div style="text-align: justify;"&gt;As many readers know, since we have been researching &lt;span style="font-weight: bold;"&gt;Malware Intelligence&lt;/span&gt; direct implications of all this new generation of malicious code and criminal activity that daily feed back the business of &lt;span style="font-weight: bold;"&gt;crimeware&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Under this premise, the researchers focused their efforts on trying to reveal the different branches that are entangled with each other in a tangle of illegal actions aimed mainly to get money from users through unethical techniques. And according to this ... there are still doubts that we are facing a big business that profit through illegal activities that rub? (obviously, always according to the laws of each country). I think the unanimous answer is NO.&lt;br /&gt;&lt;br /&gt;Saved this assessment after exposing both content around the state of the art of crimeware, including relevant data yet unexposed to not hamper the continuity of investigations, and has become a common aspect receive messages and comments, most aggressive, those responsible for the development or commercialization of certain applications crimeware.&lt;br /&gt;&lt;br /&gt;Under this scenario, and although I'm not giving explanations on the research we perform, this time an exception will expose two of the last comments we have received from those who are part of the business of crimeware.&lt;br /&gt;&lt;br /&gt;Especially because in some way reflect the philosophy (of life and mental) who operate from the underground, &lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2010/01/yes-exploit-system-official-business.html"&gt;but lately things are changing&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The first case is an anonymous, non-aggressive that I personally must confess that ... very nice:) left by one of the Partners, which markets the crimeware YES Exploit System. The comment was made in the article that talks about &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/04/yes-exploit-system-otro-crimeware-made.html"&gt;this exploit pack&lt;/a&gt;, and which also find my answer. The comment is as follows:&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;YES, We are the blackhats :)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Thanks for small review, but why do ppl think that blackhats are poor guyz?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;It's just a business, no less, no more :) Do you wanna buy our excellent product? - there is discounts for you ;)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;As they say my "friends" to them is "&lt;span style="font-weight: bold; font-style: italic;"&gt;just a business, neither more nor less.&lt;/span&gt;" However, let us agree that, besides not being a conventional business, represents a business model that directly and actively collaborates with criminal activities, which isn't so funny.&lt;br /&gt;&lt;br /&gt;Now, &lt;span style="font-weight: bold;"&gt;YES Exploit System&lt;/span&gt; is a crimeware development that has much in your code and whose market value is &lt;span style="font-weight: bold;"&gt;USD 800&lt;/span&gt;. And the one thing is funny (as last sentence of the comet) is knowing that I will not get any discount on crimeware ;)&lt;br /&gt;&lt;br /&gt;The second case I want to present is a bit more aggressive in terms of what was written in the report on the &lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/11/russian-service-online-to-check.html"&gt;Russian service to test the detection of malware&lt;/a&gt;, it can read the comment and my response, which does not transcribe here because of its length. The message reads:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;"In summary, further evidence that not only the exploitation of malware generates profits but also moves parallel money on services to&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;this industry. And in some cases like the present one, have to see if you can consider this service as a criminal act or not."&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;br /&gt;Wow and why would this service be criminal act?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;It's clear to me that someone has a year work in a software like this scanner and he want to make money with it.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;If you don't like it don't use it. Noone forces you to pay for it or submit files there but since I see you are a little wanker&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;blogger who does not respect others work I giving it to you straight.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;You have no inside experience in the antivirus industry whatsoever otherwise you would know that VirusTotal distributes 200K files/day&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;to antivirus companies for FREE. AV companies are shit on online scanners, they wouldn't even contact you if you would ask them about file&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;distribution and they definately wouldn't support an online scanner so what else can these services do to remain online?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Before you criticizing others work put something down on the table little frustrated shit...&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;"&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;Regardless of the aggressive connotation that presents this second point, it's interesting who comes. Someone who uses the word as a nickname "KLESK" and host of an "attempt by business" completely unlawful, in which page one of the first things we read is "&lt;span style="font-weight: bold; font-style: italic;"&gt;Selling corporate data, trade secrets&lt;/span&gt;".&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S1JbBSJUa5I/AAAAAAAACIk/StMlWMZnIMk/s1600-h/malware-intelligence_klesk.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 301px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/S1JbBSJUa5I/AAAAAAAACIk/StMlWMZnIMk/s400/malware-intelligence_klesk.png" alt="" id="BLOGGER_PHOTO_ID_5427500578543790994" border="0" /&gt;&lt;/a&gt;"&lt;span style="font-weight: bold; font-style: italic;"&gt;We sell corporate data and trade secrets&lt;/span&gt;", continues the propaganda. Clarify further what type of information supposedly "steal" companies, and topped with something very interesting:&lt;br /&gt;&lt;br /&gt;"&lt;span style="font-weight: bold; font-style: italic;"&gt;Please losers/asszors stay away, all the data bids start on 5 figures&lt;/span&gt;" :: Without words… :)&lt;br /&gt;&lt;br /&gt;In order, particularly the latter case represents a good opportunity to analyze the psychology of a prospectus to cyber-criminal whose attempt to "negotiate" not only leaves much to be desired but can not even be rated as a possibility to be considered as an object research.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related Information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: #660000;" href="http://malwareint.blogspot.com/2009/11/russian-service-online-to-check.html"&gt;Russian service online to check the detection of malware&lt;/a&gt;&lt;br /&gt;&lt;a style="color: #660000;" href="http://mipistus.blogspot.com/2009/04/yes-exploit-system-otro-crimeware-made.html"&gt;YES Exploit System. Otro crimeware made in Rusia&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7509741368295633849-6379279915431436332?l=securityint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/6379279915431436332/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securityint.blogspot.com/2010/02/justificando-lo-injustificable-de-un.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/6379279915431436332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/6379279915431436332'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/2010/02/justificando-lo-injustificable-de-un.html' title='Justifying the unjustifiable in a world criminal'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/S1JbBSJUa5I/AAAAAAAACIk/StMlWMZnIMk/s72-c/malware-intelligence_klesk.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7509741368295633849.post-8470520912756057032</id><published>2010-01-05T01:00:00.001-03:00</published><updated>2010-03-01T01:13:43.209-03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitepapers'/><title type='text'>Crimeware in 2009</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/S0DCXc5IbvI/AAAAAAAACHU/1OOgYieB9To/s1600-h/malwareint-anual-t.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 146px; height: 200px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/S0DCXc5IbvI/AAAAAAAACHU/1OOgYieB9To/s200/malwareint-anual-t.png" alt="" id="BLOGGER_PHOTO_ID_5422547659502677746" border="0" /&gt;&lt;/a&gt;"&lt;span style="font-weight: bold;"&gt;Crimeware in 2009&lt;/span&gt;" presented in one document all that was channeled through this blog during the year in question on &lt;span style="font-weight: bold;"&gt;crimeware &lt;/span&gt;and associated hazards.&lt;br /&gt;&lt;br /&gt;There are a total of 262 pages and is divided by the most relevant topics that describe the criminal activities that were a source of news on this blog. Has two indices for getting the news in a simple (content) and another on the images (image index).&lt;br /&gt;&lt;br /&gt;Then let some of the themes they found in the document in question:&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Current business outlook caused by crimeware&lt;/li&gt;&lt;li&gt;Framework Exploit Pack for botnets general purpose&lt;/li&gt;&lt;li&gt;Framework Exploit Pack for botnets particular purpose&lt;/li&gt;&lt;li&gt;Services associated with crimeware&lt;/li&gt;&lt;li&gt;Intelligence in the fight against crimeware&lt;/li&gt;&lt;li&gt;Campaigns of spread and infection&lt;/li&gt;&lt;li&gt;Other Exploits packs that were investigated&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Short information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: #660000;" href="http://www.malwareint.com/"&gt;Malware Intelligence&lt;/a&gt;&lt;br /&gt;Annual compendium of information. Crimeware in 2009&lt;br /&gt;262 pages&lt;br /&gt;Spanish language&lt;br /&gt;&lt;a style="color: #660000;" href="http://www.malwareint.com/docs/MalwareInt-anual-2009.pdf"&gt;&lt;br /&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7509741368295633849-8470520912756057032?l=securityint.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityint.blogspot.com/feeds/8470520912756057032/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securityint.blogspot.com/2010/01/crimeware-in-2009.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/8470520912756057032'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7509741368295633849/posts/default/8470520912756057032'/><link rel='alternate' type='text/html' href='http://securityint.blogspot.com/2010/01/crimeware-in-2009.html' title='Crimeware in 2009'/><author><name>Jorge Mieres</name><uri>http://www.blogger.com/profile/01799574410927169333</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/S0DCXc5IbvI/AAAAAAAACHU/1OOgYieB9To/s72-c/malwareint-anual-t.png' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
