<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Crescent City Networking &#187; Security</title>
	<atom:link href="http://ccnetworking.com/wordpress/archives/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://ccnetworking.com/wordpress</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 06:08:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Message of Safety for Ladies on Facebook is a Hoax</title>
		<link>http://feedproxy.google.com/~r/SunbeltBlog/~3/g2bQ4iea0Ng/</link>
		<comments>http://feedproxy.google.com/~r/SunbeltBlog/~3/g2bQ4iea0Ng/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 06:08:40 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[GFI Labs]]></category>
		<category><![CDATA[hoax]]></category>
		<category><![CDATA[kidnap]]></category>
		<category><![CDATA[new gang tactic]]></category>
		<category><![CDATA[rape]]></category>
		<category><![CDATA[steal]]></category>

		<guid isPermaLink="false">http://www.gfi.com/blog/?p=8080</guid>
		<description><![CDATA[I encountered this &#8220;new way for rapists to lure girls&#8221; story years ago from another social networking site. I&#8217;m quite sad yet generally not surprised that it has already made its way to Facebook. click to enlarge The message goes: &#8230;]]></description>
			<content:encoded><![CDATA[<p>I encountered this &#8220;new way for rapists to lure girls&#8221; story years ago from another social networking site. I&#8217;m quite sad yet generally not surprised that it has already made its way to <em><strong>Facebook</strong></em>.</p>
<p style="text-align: center;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/02/girls-warned_FBscam.jpg"><img class="size-medium wp-image-8081" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Screenshot of hoax on a Facebook Wall" src="http://www.gfi.com/blog/wp-content/uploads/2012/02/girls-warned_FBscam-284x300.jpg" alt="" width="284" height="300" /></a><br />
<em>click to enlarge</em></p>
<p>The message goes: <em>PLEASE READ CAREFULLY</em></p>
<p><em>This message is for every Girl Who Goes to college or office alone. If u find any child carrying on road showing his/her address n asking u to take him/her to that address,take that child to police station n plz don&#8217;t take it to that address . IT IS A NEW WAY GANGS TO STEAL, RAPE, and KIDNAP GIRLS . plz circulate to all .don&#8217;t feel shy to copy This as ur status .</em></p>
<p><em> OUR ONE MESSAGE MAY SAVE A GIRL</em></p>
<p>This <em>Facebook</em> wall post has been live in public since Q4 of last year, so before it picks up steam and encourage more sharing within the platform, please do realize, dear Reader, that this is a <strong>hoax</strong>—all fake, from the image to the story behind this message.</p>
<p><a href="http://www.snopes.com/crime/warnings/childlure.asp">Variations of this hoax</a> have been circulating the Internet for years. Would you believe that the lure tactic—about children being used to lead women to their prey—might have stemed from an urban legend set in World War II decades ago?</p>
<p style="text-align: left;">Helping people on <em>Facebook </em>by sharing things that you deem important is a good cause; however, spreading hoaxes such as this one can only lead people to needless worrying and panic. That said, I implore you not to share this further, within <em>Facebook</em> and outside it. Before you click &#8220;Share&#8221;, research.</p>
<p style="text-align: left;">Also, please do not be alarmed (much less believe) if you see something like this on the Internet:</p>
<p style="text-align: center;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/02/girls-warned_FBscam2.jpg"><img class="aligncenter size-medium wp-image-8082" title="A plea?" src="http://www.gfi.com/blog/wp-content/uploads/2012/02/girls-warned_FBscam2-300x76.jpg" alt="" width="300" height="76" /></a> <em>click to enlarge</em></p>
<p>Jovi Umawing (Hat tip: <a href="http://facecrooks.com/">Facecrooks.com</a>)</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=g2bQ4iea0Ng:EW1AFT-pegc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=yIl2AUoC8zA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=g2bQ4iea0Ng:EW1AFT-pegc:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=7Q72WNTAKBA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=g2bQ4iea0Ng:EW1AFT-pegc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=g2bQ4iea0Ng:EW1AFT-pegc:V_sGLiPBpWU" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=g2bQ4iea0Ng:EW1AFT-pegc:wF9xT3WuBAs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=g2bQ4iea0Ng:EW1AFT-pegc:wF9xT3WuBAs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=g2bQ4iea0Ng:EW1AFT-pegc:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=g2bQ4iea0Ng:EW1AFT-pegc:F7zBnMyn0Lo" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=g2bQ4iea0Ng:EW1AFT-pegc:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=qj6IDK7rITs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=g2bQ4iea0Ng:EW1AFT-pegc:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=g2bQ4iea0Ng:EW1AFT-pegc:gIN9vFwOqvQ" border="0"/></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://feedproxy.google.com/~r/SunbeltBlog/~3/g2bQ4iea0Ng/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kelihos Botnet Gaining Momentum</title>
		<link>http://feedproxy.google.com/~r/SunbeltBlog/~3/NIjYNztGMNg/</link>
		<comments>http://feedproxy.google.com/~r/SunbeltBlog/~3/NIjYNztGMNg/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 02:12:40 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnet takedown]]></category>
		<category><![CDATA[fake pharma]]></category>
		<category><![CDATA[GFI Labs]]></category>
		<category><![CDATA[Kelihos]]></category>
		<category><![CDATA[Kelihos Botnet]]></category>
		<category><![CDATA[MS]]></category>
		<category><![CDATA[pornography]]></category>
		<category><![CDATA[sinkholes]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spammer]]></category>
		<category><![CDATA[spamming]]></category>
		<category><![CDATA[takedown]]></category>
		<category><![CDATA[viagra]]></category>

		<guid isPermaLink="false">http://www.gfi.com/blog/?p=8078</guid>
		<description><![CDATA[Last September of 2011, Microsoft and an anti-malware security company had joined forces to take down Kelihos, a botnet capable of sending out billions of spam in a day. These spam are related to pornography, Viagra, and fake pharmaceutical companies &#8230;]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/02/kelihos-spam.jpg"><img class="size-medium wp-image-8079 alignright" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Kelihos is spamming again" src="http://www.gfi.com/blog/wp-content/uploads/2012/02/kelihos-spam-300x270.jpg" alt="" width="300" height="270" /></a>Last September of 2011, <strong>Microsoft</strong> and an anti-malware security company had joined forces to take down <strong>Kelihos</strong>, a <strong>botnet</strong> capable of sending out billions of <strong>spam</strong> in a day. These spam are related to <strong>pornography</strong>, <strong>Viagra</strong>, and <strong><a href="http://www.gfi.com/blog/what%E2%80%99s-really-in-the-drugs-you-buy-over-the-internet/">fake pharmaceutical companies</a></strong> to name a few. Now, there is reason to believe that machines once infected by the Kelihos bot are, once again, <a href="http://arstechnica.com/business/news/2012/02/slain-kelihos-botnet-still-spams-from-beyond-the-grave.ars">back in their old spamming routine</a>.</p>
<p>&#8220;The resurrection highlights the difficulty of permanently severing botnets from the Internet.&#8221; writes Dan Goodin of <em>Ars Technica</em>. &#8220;Because Kelihos used <strong>peer-to-peer</strong> technology, it was disrupted—or &#8220;sinkholed,&#8221; in takedown parlance—by seeding the network with machines that caused their peers to take orders from benign channels under the control of white hats. The takedown process never actually removed the underlying malware from infected machines, making it possible for the attackers to one day regain control of them.&#8221;</p>
<p>You can read more about it <a href="http://arstechnica.com/business/news/2012/02/slain-kelihos-botnet-still-spams-from-beyond-the-grave.ars">here</a>. Take note of the <strong>Update</strong> section at the end of the article.</p>
<p><em>Related article:</em></p>
<ul>
<li><a title="The Microsoft-Kelihos Tango Continues" href="http://www.gfi.com/blog/the-microsoft-kelihos-tango-continues/">The Microsoft-Kelihos Tango Continues</a></li>
</ul>
<p>Jovi Umawing</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=NIjYNztGMNg:TJZmhu77Dcs:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=yIl2AUoC8zA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=NIjYNztGMNg:TJZmhu77Dcs:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=7Q72WNTAKBA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=NIjYNztGMNg:TJZmhu77Dcs:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=NIjYNztGMNg:TJZmhu77Dcs:V_sGLiPBpWU" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=NIjYNztGMNg:TJZmhu77Dcs:wF9xT3WuBAs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=NIjYNztGMNg:TJZmhu77Dcs:wF9xT3WuBAs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=NIjYNztGMNg:TJZmhu77Dcs:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=NIjYNztGMNg:TJZmhu77Dcs:F7zBnMyn0Lo" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=NIjYNztGMNg:TJZmhu77Dcs:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=qj6IDK7rITs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=NIjYNztGMNg:TJZmhu77Dcs:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=NIjYNztGMNg:TJZmhu77Dcs:gIN9vFwOqvQ" border="0"/></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://feedproxy.google.com/~r/SunbeltBlog/~3/NIjYNztGMNg/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Need Proof?</title>
		<link>http://feedproxy.google.com/~r/SunbeltBlog/~3/5rdTUvcH8ao/</link>
		<comments>http://feedproxy.google.com/~r/SunbeltBlog/~3/5rdTUvcH8ao/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 06:15:17 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[games]]></category>
		<category><![CDATA[GFI Labs]]></category>
		<category><![CDATA[phish]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[proof]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[steam]]></category>

		<guid isPermaLink="false">http://www.gfi.com/blog/?p=8052</guid>
		<description><![CDATA[I saw a thread over on Reddit regarding the &#8220;Funniest scam I&#8217;ve ever seen&#8221;. Unfortunately the main linked screenshot of the scam site is now offline, but someone provided the URL of the website in the comments so I thought &#8230;]]></description>
			<content:encoded><![CDATA[<p>I saw a thread over on <a href="http://www.reddit.com/r/gaming/comments/p4r7t/this_is_the_funniest_scam_ive_ever_seen_need_proof/">Reddit</a> regarding the &#8220;Funniest scam I&#8217;ve ever seen&#8221;. Unfortunately the main linked screenshot of the scam site is now offline, but someone provided the URL of the website in the comments so I thought I&#8217;d take a look.</p>
<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/02/steamfakesiteproof1.jpg"><img class="aligncenter size-medium wp-image-8053" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Steam gifts website" src="http://www.gfi.com/blog/wp-content/uploads/2012/02/steamfakesiteproof1-300x185.jpg" alt="" width="300" height="185" /></a>Click to Enlarge</p>
<p>It&#8217;s a typical &#8220;Get free <a href="http://en.wikipedia.org/wiki/Steam_(software)">Steam</a> games by giving us your login&#8221; site, distracting users by asking them to select the games they think they&#8217;re going to receive for free. It also goes one step further by claiming that 490, 682, 111 people &#8220;Already get gift&#8221;. If visitors to the website have <a href="http://store.steampowered.com/news/5123/">Steam Guard</a> enabled, they advise those users to &#8220;just turn off Steam Guard&#8221; which is up there with the author of some Malware advising somebody to turn off their security tools before running fakefile.exe.</p>
<p><em>Never turn off Steam Guard</em>. If someone manages to grab your Steam login credentials, they&#8217;ll still need to access your email to input the one time use code into the Steam application to steal your account. Steam Guard is such a big deal where protecting accounts is concerned that in a recent Christmas competition one of the reward objectives was <a href="https://twitter.com/#!/paperghost/media/slideshow?url=pic.twitter.com%2F8pWE1p9V">enabling Steam Guard</a> protection.</p>
<p>Anyway, this is supposed to be the funny part. You know how sometimes a scam website will try to convince you that what they&#8217;re offering up is the real deal? Well, this is what passes for the truth, the whole truth and nothing but the truth in fake free games land:</p>
<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/02/proof1.jpg"><img class="size-full wp-image-8055 aligncenter" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Proof? Proof." src="http://www.gfi.com/blog/wp-content/uploads/2012/02/proof1.jpg" alt="" width="317" height="142" /></a></p>
<p style="text-align: left;">Amazing. I smell a meme in the making&#8230;</p>
<p style="text-align: left;">Christopher Boyd</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=5rdTUvcH8ao:Rv6zr5OGXcE:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=yIl2AUoC8zA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=5rdTUvcH8ao:Rv6zr5OGXcE:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=7Q72WNTAKBA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=5rdTUvcH8ao:Rv6zr5OGXcE:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=5rdTUvcH8ao:Rv6zr5OGXcE:V_sGLiPBpWU" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=5rdTUvcH8ao:Rv6zr5OGXcE:wF9xT3WuBAs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=5rdTUvcH8ao:Rv6zr5OGXcE:wF9xT3WuBAs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=5rdTUvcH8ao:Rv6zr5OGXcE:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=5rdTUvcH8ao:Rv6zr5OGXcE:F7zBnMyn0Lo" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=5rdTUvcH8ao:Rv6zr5OGXcE:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=qj6IDK7rITs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=5rdTUvcH8ao:Rv6zr5OGXcE:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=5rdTUvcH8ao:Rv6zr5OGXcE:gIN9vFwOqvQ" border="0"/></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://feedproxy.google.com/~r/SunbeltBlog/~3/5rdTUvcH8ao/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tumblr Staff Blog Fakeouts Continue</title>
		<link>http://feedproxy.google.com/~r/SunbeltBlog/~3/XaoOYOzuwxA/</link>
		<comments>http://feedproxy.google.com/~r/SunbeltBlog/~3/XaoOYOzuwxA/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 04:55:57 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[GFI Labs]]></category>
		<category><![CDATA[offer]]></category>
		<category><![CDATA[southwest airlines]]></category>
		<category><![CDATA[tumblr]]></category>

		<guid isPermaLink="false">http://www.gfi.com/blog/?p=8035</guid>
		<description><![CDATA[Hot on the heels of the &#8220;free Starbucks giftcards&#8221; nonsense from last week comes a number of Tumblr accounts compromised and serving up &#8220;Free Southwest Airlines tickets&#8221; posts. Click to Enlarge The Tumblr user is promised &#8220;2 free Southwest tickets&#8221; &#8230;]]></description>
			<content:encoded><![CDATA[<p>Hot on the heels of the &#8220;free Starbucks giftcards&#8221; nonsense from <a href="http://www.gfi.com/blog/fake-tumblr-staff-blog-leads-to-starbucks-gift-cards/">last week</a> comes a number of Tumblr accounts compromised and serving up &#8220;Free Southwest Airlines tickets&#8221; posts.</p>
<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/tumblrswairlines1.jpg"><img class="aligncenter size-medium wp-image-8036" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Fake Tumblr staff blog" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/tumblrswairlines1-294x300.jpg" alt="" width="294" height="300" /></a>Click to Enlarge</p>
<p>The Tumblr user is promised &#8220;2 free Southwest tickets&#8221; via a fake &#8220;Tumblr Staff Blog&#8221;, and everyone affected has this written underneath the image file:</p>
<p><em>&#8220;Just printed out my tickets to California!! WoooHoo!!! heres the link!!!&#8221;</em></p>
<p>The link in question will take you to various offers depending on which region the end-user is located in, but this would be the ideal match:</p>
<p style="text-align: center;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/tumblrswairlines21.jpg"><img class="aligncenter size-medium wp-image-8038" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="airlines offer" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/tumblrswairlines21-300x217.jpg" alt="" width="300" height="217" /></a></p>
<p>Click to Enlarge</p>
<p style="text-align: left;"> As before, the end-user is required to fill in<em> &#8220;two reward offers from each of the silver and gold page options and nine reward offers from the platinum reward page and refer three friends to do the same&#8221;.</em></p>
<p style="text-align: left;">Good luck with that.</p>
<p style="text-align: left;">Tumblr users should avoid any and all instances where an &#8220;Adult Verification&#8221; popup asks for login credentials, and removing popups from their own compromised Tumblrs can be done by following <a href="http://30.media.tumblr.com/tumblr_lybkquTMmJ1r3xfsko1_500.jpg">these simple steps</a>.</p>
<p style="text-align: left;">Christopher Boyd</p>
<p style="text-align: center;">
</p><p style="text-align: center;">
</p><p style="text-align: center;">
</p><p style="text-align: center;">
</p><p style="text-align: center;">
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=XaoOYOzuwxA:hFe49ubok8E:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=yIl2AUoC8zA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=XaoOYOzuwxA:hFe49ubok8E:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=7Q72WNTAKBA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=XaoOYOzuwxA:hFe49ubok8E:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=XaoOYOzuwxA:hFe49ubok8E:V_sGLiPBpWU" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=XaoOYOzuwxA:hFe49ubok8E:wF9xT3WuBAs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=XaoOYOzuwxA:hFe49ubok8E:wF9xT3WuBAs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=XaoOYOzuwxA:hFe49ubok8E:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=XaoOYOzuwxA:hFe49ubok8E:F7zBnMyn0Lo" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=XaoOYOzuwxA:hFe49ubok8E:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=qj6IDK7rITs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=XaoOYOzuwxA:hFe49ubok8E:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=XaoOYOzuwxA:hFe49ubok8E:gIN9vFwOqvQ" border="0"/></a>
</div></p>]]></content:encoded>
			<wfw:commentRss>http://feedproxy.google.com/~r/SunbeltBlog/~3/XaoOYOzuwxA/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Criminals Serve Bogus Browser Updates</title>
		<link>http://feedproxy.google.com/~r/SunbeltBlog/~3/9t2jgLfAB_g/</link>
		<comments>http://feedproxy.google.com/~r/SunbeltBlog/~3/9t2jgLfAB_g/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 08:11:38 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[app.exe]]></category>
		<category><![CDATA[aveonix.org]]></category>
		<category><![CDATA[driver]]></category>
		<category><![CDATA[fake browser]]></category>
		<category><![CDATA[GFI Labs]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[smolvell.org]]></category>
		<category><![CDATA[stocknick.org]]></category>
		<category><![CDATA[survey scam]]></category>
		<category><![CDATA[Trojan-Spy.MSIL.Popclik.A]]></category>
		<category><![CDATA[Trojan.Win32.Generic!BT]]></category>
		<category><![CDATA[typosquatting]]></category>
		<category><![CDATA[update.exe]]></category>
		<category><![CDATA[url hijacking]]></category>
		<category><![CDATA[url jacking]]></category>
		<category><![CDATA[Vipre]]></category>
		<category><![CDATA[Vkernel.org]]></category>

		<guid isPermaLink="false">http://www.gfi.com/blog/?p=8024</guid>
		<description><![CDATA[Matthew, one of our malware researchers analyzed a Web threat that recently came to our attention thanks to a report from one of our VIPRE clients. Vkernel(dot)org (not to be mistaken with vkernel.com) is found to be a scam launchpad &#8230;]]></description>
			<content:encoded><![CDATA[<p>Matthew, one of our malware researchers analyzed a Web threat that recently came to our attention thanks to a report from one of our VIPRE clients. <em>Vkernel(dot)org</em> (not to be mistaken with <em>vkernel.com</em>) is found to be a scam launchpad and houses a malicious file.</p>
<p>When a user visits the said dot-org site, they see this:</p>
<p style="text-align: center;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/fake-browser_img01.png"><img class="size-medium wp-image-8025 aligncenter" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Screenshot of &quot;vkernel.org&quot;" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/fake-browser_img01-300x176.png" alt="" width="300" height="176" /></a><em style="text-align: left;">click to enlarge</em></p>
<p style="text-align: left;">Notice that it notifies users/visitors that their &#8220;&#8230;browser is out of date. We recommend to update it. The new browser version will protect your computer from different internet-dangers and make it safer&#8221;. With this notice comes the Firefox logo and the all-too-familiar &#8220;webpage supposedly scanning your system&#8221; splash, which we commonly see on rogue AV pages.</p>
<p>It then prompts users to install the <a href="https://www.virustotal.com/file/1aa80f99b4fb8f6cccefb8bf6d6ee0cc659f0ba21d8f9d2163a7360edf95ca8a/analysis/">malicious file</a>, <em>update.exe</em>, which we detect as <strong>Trojan.Win32.Generic!BT</strong>. Running this executable allows the download and installation of a program called <em>Driver</em>, which creates a folder named <em>Driver</em> before dropping two files in it: <em>uninstall.exe</em> and <em>app.exe</em>. The latter file is also <a href="https://www.virustotal.com/file/504cee746ec9f67054135851338c5a0fd01634fb0e27fbef1340165a99ee9f50/analysis/">malicious</a>; we detect it as <strong>Trojan-Spy.MSIL.Popclik.A</strong>.</p>
<div align="center"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/fake-browser_img02.png"><img title="Screenshot of downloaded application" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/fake-browser_img02-300x234.png" alt="" width="300" height="234" /></a> <a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/fake-browser_img03.png"><img title="Screenshot of downloaded application's ToS" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/fake-browser_img03-300x234.png" alt="" width="300" height="234" /></a><br />
<em>click to enlarge images</em></div>
<p>When <em>app.exe</em> runs, an Internet browser window/tab opens in order to direct users to various survey page:</p>
<p style="text-align: center;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/fake-browser_img04.png"><img class="aligncenter size-medium wp-image-8028" title="Screenshot of phishing page" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/fake-browser_img04-300x239.png" alt="" width="300" height="239" /></a><em>click to enlarge</em></p>
<p style="text-align: center;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/fake-browser_img05.png"><img class="aligncenter size-medium wp-image-8029" title="Screenshot of survey scam" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/fake-browser_img05-300x173.png" alt="" width="300" height="173" /></a><em>click to enlarge</em></p>
<p>Based on multiple tests, minutes after the said pages load, this executable connects to various websites to download and install random programs, some of which may be legitimate.</p>
<p><em>app.exe</em> executes whenever the infected system starts Windows, enabling it to download and install new programs that are potentially harmful to the already infected system.</p>
<p>Other that <em>vkernel(dot)org</em>, here are more sites that appear to house fake browser updates:</p>
<ul>
<li><strong>aveonix(dot)org</strong></li>
<li><strong>smolvell(dot)org</strong></li>
<li><strong>stocknick(dot)org</strong></li>
</ul>
<p>Stay safe!</p>
<p>Jovi Umawing (Thanks, Matthew)</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=9t2jgLfAB_g:Rh0Gxyr6lGc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=yIl2AUoC8zA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=9t2jgLfAB_g:Rh0Gxyr6lGc:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=7Q72WNTAKBA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=9t2jgLfAB_g:Rh0Gxyr6lGc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=9t2jgLfAB_g:Rh0Gxyr6lGc:V_sGLiPBpWU" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=9t2jgLfAB_g:Rh0Gxyr6lGc:wF9xT3WuBAs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=9t2jgLfAB_g:Rh0Gxyr6lGc:wF9xT3WuBAs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=9t2jgLfAB_g:Rh0Gxyr6lGc:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=9t2jgLfAB_g:Rh0Gxyr6lGc:F7zBnMyn0Lo" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=9t2jgLfAB_g:Rh0Gxyr6lGc:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=qj6IDK7rITs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=9t2jgLfAB_g:Rh0Gxyr6lGc:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=9t2jgLfAB_g:Rh0Gxyr6lGc:gIN9vFwOqvQ" border="0"/></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://feedproxy.google.com/~r/SunbeltBlog/~3/9t2jgLfAB_g/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Tumblr Staff Blog Leads to Starbucks Gift Cards</title>
		<link>http://feedproxy.google.com/~r/SunbeltBlog/~3/--ewbsLwozI/</link>
		<comments>http://feedproxy.google.com/~r/SunbeltBlog/~3/--ewbsLwozI/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 08:44:43 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[GFI Labs]]></category>
		<category><![CDATA[phish]]></category>
		<category><![CDATA[starbucks gift card]]></category>
		<category><![CDATA[tumblr]]></category>

		<guid isPermaLink="false">http://www.gfi.com/blog/?p=8017</guid>
		<description><![CDATA[We&#8217;re seeing a lot of freshly compromised Tumblr accounts, all of which are posting up an image file located here that claims to be a &#8220;Tumblr Staff Blog&#8221; (it isn&#8217;t), proclaiming the joys of &#8220;Free $50 Starbucks gift cards&#8221;. Here&#8217;s an &#8230;]]></description>
			<content:encoded><![CDATA[<p>We&#8217;re seeing a lot of freshly compromised Tumblr accounts, all of which are posting up an image file located <a href="http://s3.amazonaws.com/data.tumblr.com/tumblr_lye7ugSq521qgeaffo1_1280.jpg?">here</a> that claims to be a &#8220;Tumblr Staff Blog&#8221; (it isn&#8217;t), proclaiming the joys of &#8220;Free $50 Starbucks gift cards&#8221;.</p>
<p>Here&#8217;s an example of a site compromised in the last hour or so:</p>
<p style="text-align: center;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/faketumblrstarbucks.jpg"><img class="aligncenter size-medium wp-image-8018" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Fake Tumblr Staff Blog" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/faketumblrstarbucks-300x259.jpg" alt="" width="300" height="259" /></a></p>
<p>Click to Enlarge</p>
<p><em>&#8220;We are happy to announce that Tumblr and Starbucks have joined together in a promotion to give away FREE $50 Starbucks gift cards to each of our users.</em></p>
<p><em>CLICK ON THE LINK BELOW TO GET YOUR OWN</em></p>
<p><em>Be sure to reblog this post so that others will have the same opportunity to get their own card. Nothing better than starting 2012 off with a blast of frappucino. We hope you enjoy!&#8221;</em></p>
<p>&#8230;oh dear.</p>
<p>Clicking the link takes the user to a site offering up gift cards in return for email addresses and the promise that they&#8217;ll complete &#8220;two reward offers from each of the silver and gold page options and nine reward offers from the platinum reward page and refer three friends to do the same&#8221;.</p>
<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/faketumblrstarbucks2.jpg"><img class="aligncenter size-medium wp-image-8019" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Starbucks offer page" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/faketumblrstarbucks2-300x252.jpg" alt="" width="300" height="252" /></a>Click to Enlarge</p>
<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/faketumblrstarbucks3.jpg"><img class="aligncenter size-medium wp-image-8020" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Congratulations! Now fill in your info." src="http://www.gfi.com/blog/wp-content/uploads/2012/01/faketumblrstarbucks3-300x278.jpg" alt="" width="300" height="278" /></a>Click to Enlarge</p>
<p>I think I could probably busk $50 worth of Starbucks in half the time, but whatever.</p>
<p>At this point, there&#8217;s no clear indication as to how these Tumblr accounts are being hijacked, but throughout the 1,000 or so Google results for one of the t.co URLs used, we can see this:</p>
<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/faketumblrstarbucks4.jpg"><img class="aligncenter size-medium wp-image-8021" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Tumblr phishing prompt" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/faketumblrstarbucks4-300x266.jpg" alt="" width="300" height="266" /></a>Click to Enlarge</p>
<p>Look familiar? It should, because someone took the full screen &#8220;Adult Verification&#8221; splashpage from the last successful bout of <a href="http://www.gfi.com/blog/thousands-of-tumblr-logins-stolen-in-phishing-attack/">Tumblr phishing in June</a> and turned it into a nifty scrolling overlay which nags you regardless of how far you scroll down the page.</p>
<p>Tumblr users should steer clear of free Starbuck gift card claims &#8211; there&#8217;s absolutely no mention of it on the <a href="http://staff.tumblr.com/">Official Tumblr Staff Blog</a> which should be the first clue that something <a href="http://shortformblog.tumblr.com/post/16252198471/tumblr-phishing-warning">isn&#8217;t quite right here</a>.</p>
<p>If you wake up to find your Tumblr has a collection of posts about Starbucks stretching back at least nine hours that you didn&#8217;t make, be sure to change your login details and check your <a href="http://30.media.tumblr.com/tumblr_lybkquTMmJ1r3xfsko1_500.jpg">custom page code</a> in case the attackers have overlaid what I like to call &#8220;garbage&#8221; over your spangly hipster background.</p>
<p>Christopher Boyd</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=--ewbsLwozI:ZmBNT-i7gwg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=yIl2AUoC8zA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=--ewbsLwozI:ZmBNT-i7gwg:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=7Q72WNTAKBA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=--ewbsLwozI:ZmBNT-i7gwg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=--ewbsLwozI:ZmBNT-i7gwg:V_sGLiPBpWU" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=--ewbsLwozI:ZmBNT-i7gwg:wF9xT3WuBAs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=--ewbsLwozI:ZmBNT-i7gwg:wF9xT3WuBAs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=--ewbsLwozI:ZmBNT-i7gwg:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=--ewbsLwozI:ZmBNT-i7gwg:F7zBnMyn0Lo" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=--ewbsLwozI:ZmBNT-i7gwg:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=qj6IDK7rITs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=--ewbsLwozI:ZmBNT-i7gwg:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=--ewbsLwozI:ZmBNT-i7gwg:gIN9vFwOqvQ" border="0"/></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://feedproxy.google.com/~r/SunbeltBlog/~3/--ewbsLwozI/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Megaup…d’oh.</title>
		<link>http://feedproxy.google.com/~r/SunbeltBlog/~3/TOTqon49APo/</link>
		<comments>http://feedproxy.google.com/~r/SunbeltBlog/~3/TOTqon49APo/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 09:25:56 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[.cm]]></category>
		<category><![CDATA[GFI Labs]]></category>
		<category><![CDATA[megaupload]]></category>
		<category><![CDATA[offers]]></category>
		<category><![CDATA[surveys]]></category>

		<guid isPermaLink="false">http://www.gfi.com/blog/?p=8007</guid>
		<description><![CDATA[You&#8217;re probably aware that Megaupload has wandered into what can only be described as a bit of a pickle, assuming said pickle is roughly the size of a Vogon Constructor Fleet. Given that lots of people probably want to take &#8230;]]></description>
			<content:encoded><![CDATA[<p>You&#8217;re probably aware that Megaupload has wandered into what can only be described as a <a href="http://www.bloomberg.com/news/2012-01-24/megaupload-s-dotcom-in-custody-as-new-zealand-awaits-extradition-request.html">bit of a pickle</a>, assuming said pickle is roughly the size of a Vogon Constructor Fleet.</p>
<p>Given that lots of people probably want to take a peek at the FBI Anti-Warning currently pasted across the front of Megaupload.com (or maybe even just see if the site is back online), it&#8217;s a fair bet that Ye Olde Typo Fairy will be called into action and some of them will end up going to Megaupload(dot)cm.</p>
<p>You can see what they did there.</p>
<p>On the basis that Wikipedia hasn&#8217;t gone dark for a day or covered itself in pictures of Jimmy Wales, we can see that the <a href="https://en.wikipedia.org/wiki/.cm">.cm TLD</a> is intended for domains connected with Cameroon. Typosquatting seems to be a bit of a thing:</p>
<blockquote><p> In a report published in December 2009 by McAfee, &#8220;Mapping the Mal Web &#8211; The world&#8217;s riskiest domain&#8221;, .cm was reportedly the riskiest domain in the world, with 36.7% of the sites posing a security risk to PCs. [<a href="http://news.cnet.com/8301-1009_3-10407530-83.html">5</a>] It is widely assumed that malicious domain programmers rely on inadvertent misspellings of well-trafficked websites ending in &#8220;.com&#8221; to lure unsuspecting users to their domains.</p></blockquote>
<p>Registered back in 2009, Megaupload(dot)cm takes you a site located at surveytakelive(dot)com, which tells us via the method of popup box that there are prizes up for grabs and you&#8217;ll have to fill in some personal information.</p>
<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/megauploadcm1.jpg"><img class="aligncenter size-medium wp-image-8008" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Megauploaddotcm landing page" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/megauploadcm1-300x220.jpg" alt="" width="300" height="220" /></a>Click to Enlarge</p>
<p>Next up, you have to pick one of the three options presented. I went with the Love Thermometer, mainly because it&#8217;s called the Love Thermometer and also has a graphic of a baseball bat.</p>
<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/megauploadcm2.jpg"><img class="aligncenter size-medium wp-image-8009" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Choose your prize" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/megauploadcm2-300x274.jpg" alt="" width="300" height="274" /></a>Click to Enlarge</p>
<p style="text-align: left;">Hitting the Love Thermometer button takes us to a promo located at enterfactory(dot)com, which turns out to be a mobile phone promotion costing various amounts of cash per day until the user unsubscribes.</p>
<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/megauploadcm3.jpg"><img class="aligncenter size-medium wp-image-8010" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="mobile phone sign up service" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/megauploadcm3-300x205.jpg" alt="" width="300" height="205" /></a>Click to Enlarge</p>
<p style="text-align: left;">The adverts served are region specific &#8211; the above are what you&#8217;ll see if in the Philippines, whereas visiting from the US will result in iPad, Walmart and Visa giftcard offers instead.</p>
<p style="text-align: left;">Be mindful of what you&#8217;re typing into the URL bar, and let me know if you discover what the Love Thermometer actually does&#8230;</p>
<p style="text-align: left;">Christopher Boyd</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=TOTqon49APo:DhRkFDxOnug:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=yIl2AUoC8zA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=TOTqon49APo:DhRkFDxOnug:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=7Q72WNTAKBA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=TOTqon49APo:DhRkFDxOnug:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=TOTqon49APo:DhRkFDxOnug:V_sGLiPBpWU" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=TOTqon49APo:DhRkFDxOnug:wF9xT3WuBAs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=TOTqon49APo:DhRkFDxOnug:wF9xT3WuBAs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=TOTqon49APo:DhRkFDxOnug:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=TOTqon49APo:DhRkFDxOnug:F7zBnMyn0Lo" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=TOTqon49APo:DhRkFDxOnug:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=qj6IDK7rITs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=TOTqon49APo:DhRkFDxOnug:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=TOTqon49APo:DhRkFDxOnug:gIN9vFwOqvQ" border="0"/></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://feedproxy.google.com/~r/SunbeltBlog/~3/TOTqon49APo/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Microsoft-Kelihos Tango Continues</title>
		<link>http://feedproxy.google.com/~r/SunbeltBlog/~3/gqSFtDBYU0E/</link>
		<comments>http://feedproxy.google.com/~r/SunbeltBlog/~3/gqSFtDBYU0E/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 07:21:34 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[botmaster]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[C&C]]></category>
		<category><![CDATA[command and control]]></category>
		<category><![CDATA[fast flux]]></category>
		<category><![CDATA[GFI Labs]]></category>
		<category><![CDATA[Kelihos]]></category>
		<category><![CDATA[MS]]></category>
		<category><![CDATA[sabelnikov]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Waledac]]></category>

		<guid isPermaLink="false">http://www.gfi.com/blog/?p=8004</guid>
		<description><![CDATA[Microsoft is going all out on hammering the last nail on Kelihos&#8217;s coffin. The takedown that took place 4 months ago is just the beginning. The software giant filed a complaint on Monday, January 23, against Andrey N. Sabelnikov for &#8230;]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/kelihos_botnet.jpg"><img class="alignright size-medium wp-image-8005" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Botnet" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/kelihos_botnet-300x225.jpg" alt="" width="300" height="225" /></a><strong>Microsoft</strong> is going all out on hammering the last nail on Kelihos&#8217;s coffin. The <a href="https://blogs.technet.com/b/microsoft_blog/archive/2011/09/27/microsoft-neutralizes-kelihos-botnet-names-defendant-in-case.aspx">takedown</a> that took place 4 months ago is just the beginning.</p>
<p>The software giant filed <a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-80-54/6180.Kelihos-Botnet-_2D00_-Amended-Complaint.pdf">a complaint</a> on Monday, January 23, against Andrey N. Sabelnikov for &#8220;controlling the &#8216;Kelihos&#8217; botnet using twenty-one (21) Internet domain names &#8230; including, in particular, the 3,723 &#8216;cz.cc&#8217; Internet sub-domains&#8230;&#8221;. Also according to the said report, Sabelnikov &#8220;worked as a software engineer and project manager at a company that provided firewall, antivirus and security software.&#8221; You can read more <a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-80-54/6180.Kelihos-Botnet-_2D00_-Amended-Complaint.pdf">here</a>.</p>
<p><strong>Kelihos</strong>—otherwise known as <strong>Waledac</strong>—is a botnet capable of sending out 3.8 billion spam emails each day. The botnet was also used for other malicious acts while leveraging the &#8220;<strong>fast flux</strong>&#8221; hosting method to hide locations of infected machines, including the command and control (C&amp;C) center of the botnet.</p>
<p>Despite the botnet being inactive, Richard Boscovich, Senior Attorney at the Microsoft Digital Crimes Unit, asserts that &#8220;thousands of computers are still infected with its malware.&#8221; If you think that your system might be one of the millions infected, make sure that you have an antivirus software installed on your system to clean off the infection. If you already do, make sure that the software is updated to its latest security pattern and engine. Most importantly, be wary of certain emails in your inbox that might have escaped your spam catcher. Never open its attachment or click links on its message body.</p>
<p>Jovi Umawing</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=gqSFtDBYU0E:kvn3yINW1u8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=yIl2AUoC8zA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=gqSFtDBYU0E:kvn3yINW1u8:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=7Q72WNTAKBA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=gqSFtDBYU0E:kvn3yINW1u8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=gqSFtDBYU0E:kvn3yINW1u8:V_sGLiPBpWU" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=gqSFtDBYU0E:kvn3yINW1u8:wF9xT3WuBAs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=gqSFtDBYU0E:kvn3yINW1u8:wF9xT3WuBAs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=gqSFtDBYU0E:kvn3yINW1u8:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=gqSFtDBYU0E:kvn3yINW1u8:F7zBnMyn0Lo" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=gqSFtDBYU0E:kvn3yINW1u8:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=qj6IDK7rITs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=gqSFtDBYU0E:kvn3yINW1u8:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=gqSFtDBYU0E:kvn3yINW1u8:gIN9vFwOqvQ" border="0"/></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://feedproxy.google.com/~r/SunbeltBlog/~3/gqSFtDBYU0E/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Halo 4 Beta Invites? Nope.</title>
		<link>http://feedproxy.google.com/~r/SunbeltBlog/~3/eyroFoz5nMo/</link>
		<comments>http://feedproxy.google.com/~r/SunbeltBlog/~3/eyroFoz5nMo/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 05:41:34 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[4]]></category>
		<category><![CDATA[GFI Labs]]></category>
		<category><![CDATA[halo]]></category>
		<category><![CDATA[master chief]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[survey]]></category>
		<category><![CDATA[survey scam]]></category>
		<category><![CDATA[xbox]]></category>

		<guid isPermaLink="false">http://www.gfi.com/blog/?p=7998</guid>
		<description><![CDATA[There have been warnings over the last few days regarding a Halo 4 Beta invite scam. Information was pretty thin on the ground, however, so I decided to take a look &#8211; especially as there were reports of phishing. Here&#8217;s &#8230;]]></description>
			<content:encoded><![CDATA[<p>There have been <a href="http://feedproxy.google.com/~r/SunbeltBlog/~3/eyroFoz5nMo/www.computerandvideogames.com/332748/microsoft-warns-of-fake-halo-4-beta-invites/">warnings</a> over the last few days regarding a <a href="https://en.wikipedia.org/wiki/Halo_4">Halo 4</a> Beta invite scam. Information was pretty thin on the ground, however, so I decided to take a look &#8211; especially as there were reports of <a href="http://www.metro.co.uk/tech/games/887820-halo-4-beta-invites-are-phishing-scam-says-microsoft">phishing</a>.</p>
<p>Here&#8217;s the site in question &#8211; halo4beta(dot)net:</p>
<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/halo4scam1.jpg"><img class="aligncenter size-medium wp-image-7999" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Halo Beta Invites" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/halo4scam1-300x170.jpg" alt="" width="300" height="170" /></a>Click to Enlarge</p>
<p>I mean, as fake Beta invite sites go it certainly looks nice. &#8220;Get your Halo 4 Beta key and installer now&#8221;, they say. They also wave a &#8220;Get your code&#8221; button at you, so it&#8217;d be rude not click it. Right?</p>
<p style="text-align: center;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/halo4scam2.jpg"><img class="aligncenter size-medium wp-image-8000" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Complete the following steps" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/halo4scam2-300x238.jpg" alt="" width="300" height="238" /></a></p>
<p style="text-align: left;">Click to Enlarge</p>
<p style="text-align: left;">You have to &#8220;Like&#8221; the page, share it with your friends and even give it a +1 on Google Plus. Way to increase those verticals or whatever. What is your reward for jumping through rings of Social Networking fire?</p>
<p style="text-align: left;">I&#8217;ll tell you this much, it isn&#8217;t a Halo 4 Beta invite. But there isn&#8217;t anything phishy taking place either.</p>
<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/halo4scam3.jpg"><img class="aligncenter size-medium wp-image-8001" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Halo 4 survey popup" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/halo4scam3-300x243.jpg" alt="" width="300" height="243" /></a>Click to Enlarge</p>
<p style="text-align: left;">Yes, it&#8217;s a survey because &#8220;This Beta key has been temporarily locked&#8221;. You know the drill: select one, fill it in, send your info to some random marketing guy and get your hands on absolutely nothing at all.</p>
<p style="text-align: left;">Don&#8217;t bother with sites claiming to offer up Halo 4 beta keys &#8211; when the time comes, it&#8217;ll be Microsoft you hear it from and not a random website asking for likes, linkbacks and survey submission. At least you won&#8217;t be troubled by the example above, because the poor thing succumbed  to an inevitable Boom, Headshot fatality:</p>
<p style="text-align: left;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/halo4scam4.jpg"><img class="aligncenter size-medium wp-image-8002" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="Halo beta site suspended" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/halo4scam4-300x181.jpg" alt="" width="300" height="181" /></a>Click to Enlarge</p>
<p style="text-align: left;">No Recon Armour for you.</p>
<p style="text-align: left;">Christopher Boyd</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=eyroFoz5nMo:UE2jT8Zbswk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=yIl2AUoC8zA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=eyroFoz5nMo:UE2jT8Zbswk:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=7Q72WNTAKBA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=eyroFoz5nMo:UE2jT8Zbswk:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=eyroFoz5nMo:UE2jT8Zbswk:V_sGLiPBpWU" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=eyroFoz5nMo:UE2jT8Zbswk:wF9xT3WuBAs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=eyroFoz5nMo:UE2jT8Zbswk:wF9xT3WuBAs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=eyroFoz5nMo:UE2jT8Zbswk:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=eyroFoz5nMo:UE2jT8Zbswk:F7zBnMyn0Lo" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=eyroFoz5nMo:UE2jT8Zbswk:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=qj6IDK7rITs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=eyroFoz5nMo:UE2jT8Zbswk:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=eyroFoz5nMo:UE2jT8Zbswk:gIN9vFwOqvQ" border="0"/></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://feedproxy.google.com/~r/SunbeltBlog/~3/eyroFoz5nMo/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BBB Scam Returns</title>
		<link>http://feedproxy.google.com/~r/SunbeltBlog/~3/KEvYWZV1NRE/</link>
		<comments>http://feedproxy.google.com/~r/SunbeltBlog/~3/KEvYWZV1NRE/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 04:32:33 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[BBB]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[GFI Labs]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://www.gfi.com/blog/?p=7995</guid>
		<description><![CDATA[You may well have read about the BBB phish / exploit emails doing the rounds last week. It&#8217;s worth noting that these are still in circulation &#8211; we&#8217;ve seen five of these in the last two days linking to exploits &#8230;]]></description>
			<content:encoded><![CDATA[<p>You may well have read about the <a href="http://newjersey.bbb.org/article/bbb-is-not-sending-this-email-30880">BBB phish / exploit emails</a> doing the rounds last week. It&#8217;s worth noting that these are still in circulation &#8211; we&#8217;ve seen five of these in the last two days linking to exploits provided by the <a href="http://www.webopedia.com/TERM/B/blackhole_exploit_kit.html">Blackhole exploit kit</a>.</p>
<p>They follow the same pattern as before &#8211; claiming the recipient of the mail has had complaints from a customer, with a link provided to see what all the fuss is about.</p>
<p style="text-align: center;"><a href="http://www.gfi.com/blog/wp-content/uploads/2012/01/BBB_Phish.png"><img class="aligncenter size-medium wp-image-7996" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px; margin: 10px;" title="BBB exploit mail" src="http://www.gfi.com/blog/wp-content/uploads/2012/01/BBB_Phish-300x129.png" alt="" width="300" height="129" /></a></p>
<p>Click to Enlarge</p>
<p>End-users should continue to be vigilant and steer clear of these scam mails. If in doubt, contact the BBB directly and establish if what you&#8217;ve been sent is the real thing.</p>
<p>Christopher Boyd (Thanks Robert)</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=KEvYWZV1NRE:3cNW4ltSqRQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=yIl2AUoC8zA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=KEvYWZV1NRE:3cNW4ltSqRQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=7Q72WNTAKBA" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=KEvYWZV1NRE:3cNW4ltSqRQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=KEvYWZV1NRE:3cNW4ltSqRQ:V_sGLiPBpWU" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=KEvYWZV1NRE:3cNW4ltSqRQ:wF9xT3WuBAs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=KEvYWZV1NRE:3cNW4ltSqRQ:wF9xT3WuBAs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=KEvYWZV1NRE:3cNW4ltSqRQ:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=KEvYWZV1NRE:3cNW4ltSqRQ:F7zBnMyn0Lo" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=KEvYWZV1NRE:3cNW4ltSqRQ:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?d=qj6IDK7rITs" border="0"/></a> <a href="http://feeds.feedburner.com/~ff/SunbeltBlog?a=KEvYWZV1NRE:3cNW4ltSqRQ:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/SunbeltBlog?i=KEvYWZV1NRE:3cNW4ltSqRQ:gIN9vFwOqvQ" border="0"/></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://feedproxy.google.com/~r/SunbeltBlog/~3/KEvYWZV1NRE/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

